149539ade15e42f5ac137f13146d7cdc72d2a152
[pandora-kernel.git] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006-2009  Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/list.h>
11 #include <linux/if_ether.h>
12 #include <linux/ieee80211.h>
13 #include <linux/nl80211.h>
14 #include <linux/rtnetlink.h>
15 #include <linux/netlink.h>
16 #include <linux/etherdevice.h>
17 #include <net/net_namespace.h>
18 #include <net/genetlink.h>
19 #include <net/cfg80211.h>
20 #include <net/sock.h>
21 #include "core.h"
22 #include "nl80211.h"
23 #include "reg.h"
24
25 /* the netlink family */
26 static struct genl_family nl80211_fam = {
27         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
28         .name = "nl80211",      /* have users key off the name instead */
29         .hdrsize = 0,           /* no private header */
30         .version = 1,           /* no particular meaning now */
31         .maxattr = NL80211_ATTR_MAX,
32         .netnsok = true,
33 };
34
35 /* internal helper: get rdev and dev */
36 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
37                                        struct cfg80211_registered_device **rdev,
38                                        struct net_device **dev)
39 {
40         struct nlattr **attrs = info->attrs;
41         int ifindex;
42
43         if (!attrs[NL80211_ATTR_IFINDEX])
44                 return -EINVAL;
45
46         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
47         *dev = dev_get_by_index(genl_info_net(info), ifindex);
48         if (!*dev)
49                 return -ENODEV;
50
51         *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
52         if (IS_ERR(*rdev)) {
53                 dev_put(*dev);
54                 return PTR_ERR(*rdev);
55         }
56
57         return 0;
58 }
59
60 /* policy for the attributes */
61 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
62         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
63         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
64                                       .len = 20-1 },
65         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
66         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
67         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
68         [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
69         [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
70         [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
71         [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
72
73         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
74         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
75         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
76
77         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
78         [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
79
80         [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
81         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
82                                     .len = WLAN_MAX_KEY_LEN },
83         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
84         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
85         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
86         [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
87
88         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
89         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
90         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
91                                        .len = IEEE80211_MAX_DATA_LEN },
92         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
93                                        .len = IEEE80211_MAX_DATA_LEN },
94         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
95         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
96         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
97         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
98                                                .len = NL80211_MAX_SUPP_RATES },
99         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
100         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
101         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
102         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
103                                 .len = IEEE80211_MAX_MESH_ID_LEN },
104         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
105
106         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
107         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
108
109         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
110         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
111         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
112         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
113                                            .len = NL80211_MAX_SUPP_RATES },
114
115         [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
116
117         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
118                                          .len = NL80211_HT_CAPABILITY_LEN },
119
120         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
121         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
122                               .len = IEEE80211_MAX_DATA_LEN },
123         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
124         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
125
126         [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
127                                 .len = IEEE80211_MAX_SSID_LEN },
128         [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
129         [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
130         [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
131         [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
132         [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
133         [NL80211_ATTR_STA_FLAGS2] = {
134                 .len = sizeof(struct nl80211_sta_flag_update),
135         },
136         [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
137         [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
138         [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
139         [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
140         [NL80211_ATTR_PID] = { .type = NLA_U32 },
141         [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
142 };
143
144 /* policy for the attributes */
145 static struct nla_policy
146 nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
147         [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
148         [NL80211_KEY_IDX] = { .type = NLA_U8 },
149         [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
150         [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
151         [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
152         [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
153 };
154
155 /* ifidx get helper */
156 static int nl80211_get_ifidx(struct netlink_callback *cb)
157 {
158         int res;
159
160         res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
161                           nl80211_fam.attrbuf, nl80211_fam.maxattr,
162                           nl80211_policy);
163         if (res)
164                 return res;
165
166         if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
167                 return -EINVAL;
168
169         res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
170         if (!res)
171                 return -EINVAL;
172         return res;
173 }
174
175 /* IE validation */
176 static bool is_valid_ie_attr(const struct nlattr *attr)
177 {
178         const u8 *pos;
179         int len;
180
181         if (!attr)
182                 return true;
183
184         pos = nla_data(attr);
185         len = nla_len(attr);
186
187         while (len) {
188                 u8 elemlen;
189
190                 if (len < 2)
191                         return false;
192                 len -= 2;
193
194                 elemlen = pos[1];
195                 if (elemlen > len)
196                         return false;
197
198                 len -= elemlen;
199                 pos += 2 + elemlen;
200         }
201
202         return true;
203 }
204
205 /* message building helper */
206 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
207                                    int flags, u8 cmd)
208 {
209         /* since there is no private header just add the generic one */
210         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
211 }
212
213 static int nl80211_msg_put_channel(struct sk_buff *msg,
214                                    struct ieee80211_channel *chan)
215 {
216         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
217                     chan->center_freq);
218
219         if (chan->flags & IEEE80211_CHAN_DISABLED)
220                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
221         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
222                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
223         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
224                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
225         if (chan->flags & IEEE80211_CHAN_RADAR)
226                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
227
228         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
229                     DBM_TO_MBM(chan->max_power));
230
231         return 0;
232
233  nla_put_failure:
234         return -ENOBUFS;
235 }
236
237 /* netlink command implementations */
238
239 struct key_parse {
240         struct key_params p;
241         int idx;
242         bool def, defmgmt;
243 };
244
245 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
246 {
247         struct nlattr *tb[NL80211_KEY_MAX + 1];
248         int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
249                                    nl80211_key_policy);
250         if (err)
251                 return err;
252
253         k->def = !!tb[NL80211_KEY_DEFAULT];
254         k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
255
256         if (tb[NL80211_KEY_IDX])
257                 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
258
259         if (tb[NL80211_KEY_DATA]) {
260                 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
261                 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
262         }
263
264         if (tb[NL80211_KEY_SEQ]) {
265                 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
266                 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
267         }
268
269         if (tb[NL80211_KEY_CIPHER])
270                 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
271
272         return 0;
273 }
274
275 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
276 {
277         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
278                 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
279                 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
280         }
281
282         if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
283                 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
284                 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
285         }
286
287         if (info->attrs[NL80211_ATTR_KEY_IDX])
288                 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
289
290         if (info->attrs[NL80211_ATTR_KEY_CIPHER])
291                 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
292
293         k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
294         k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
295
296         return 0;
297 }
298
299 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
300 {
301         int err;
302
303         memset(k, 0, sizeof(*k));
304         k->idx = -1;
305
306         if (info->attrs[NL80211_ATTR_KEY])
307                 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
308         else
309                 err = nl80211_parse_key_old(info, k);
310
311         if (err)
312                 return err;
313
314         if (k->def && k->defmgmt)
315                 return -EINVAL;
316
317         if (k->idx != -1) {
318                 if (k->defmgmt) {
319                         if (k->idx < 4 || k->idx > 5)
320                                 return -EINVAL;
321                 } else if (k->def) {
322                         if (k->idx < 0 || k->idx > 3)
323                                 return -EINVAL;
324                 } else {
325                         if (k->idx < 0 || k->idx > 5)
326                                 return -EINVAL;
327                 }
328         }
329
330         return 0;
331 }
332
333 static struct cfg80211_cached_keys *
334 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
335                        struct nlattr *keys)
336 {
337         struct key_parse parse;
338         struct nlattr *key;
339         struct cfg80211_cached_keys *result;
340         int rem, err, def = 0;
341
342         result = kzalloc(sizeof(*result), GFP_KERNEL);
343         if (!result)
344                 return ERR_PTR(-ENOMEM);
345
346         result->def = -1;
347         result->defmgmt = -1;
348
349         nla_for_each_nested(key, keys, rem) {
350                 memset(&parse, 0, sizeof(parse));
351                 parse.idx = -1;
352
353                 err = nl80211_parse_key_new(key, &parse);
354                 if (err)
355                         goto error;
356                 err = -EINVAL;
357                 if (!parse.p.key)
358                         goto error;
359                 if (parse.idx < 0 || parse.idx > 4)
360                         goto error;
361                 if (parse.def) {
362                         if (def)
363                                 goto error;
364                         def = 1;
365                         result->def = parse.idx;
366                 } else if (parse.defmgmt)
367                         goto error;
368                 err = cfg80211_validate_key_settings(rdev, &parse.p,
369                                                      parse.idx, NULL);
370                 if (err)
371                         goto error;
372                 result->params[parse.idx].cipher = parse.p.cipher;
373                 result->params[parse.idx].key_len = parse.p.key_len;
374                 result->params[parse.idx].key = result->data[parse.idx];
375                 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
376         }
377
378         return result;
379  error:
380         kfree(result);
381         return ERR_PTR(err);
382 }
383
384 static int nl80211_key_allowed(struct wireless_dev *wdev)
385 {
386         ASSERT_WDEV_LOCK(wdev);
387
388         if (!netif_running(wdev->netdev))
389                 return -ENETDOWN;
390
391         switch (wdev->iftype) {
392         case NL80211_IFTYPE_AP:
393         case NL80211_IFTYPE_AP_VLAN:
394                 break;
395         case NL80211_IFTYPE_ADHOC:
396                 if (!wdev->current_bss)
397                         return -ENOLINK;
398                 break;
399         case NL80211_IFTYPE_STATION:
400                 if (wdev->sme_state != CFG80211_SME_CONNECTED)
401                         return -ENOLINK;
402                 break;
403         default:
404                 return -EINVAL;
405         }
406
407         return 0;
408 }
409
410 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
411                               struct cfg80211_registered_device *dev)
412 {
413         void *hdr;
414         struct nlattr *nl_bands, *nl_band;
415         struct nlattr *nl_freqs, *nl_freq;
416         struct nlattr *nl_rates, *nl_rate;
417         struct nlattr *nl_modes;
418         struct nlattr *nl_cmds;
419         enum ieee80211_band band;
420         struct ieee80211_channel *chan;
421         struct ieee80211_rate *rate;
422         int i;
423         u16 ifmodes = dev->wiphy.interface_modes;
424
425         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
426         if (!hdr)
427                 return -1;
428
429         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
430         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
431
432         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
433                     cfg80211_rdev_list_generation);
434
435         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
436                    dev->wiphy.retry_short);
437         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
438                    dev->wiphy.retry_long);
439         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
440                     dev->wiphy.frag_threshold);
441         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
442                     dev->wiphy.rts_threshold);
443
444         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
445                    dev->wiphy.max_scan_ssids);
446         NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
447                     dev->wiphy.max_scan_ie_len);
448
449         NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
450                 sizeof(u32) * dev->wiphy.n_cipher_suites,
451                 dev->wiphy.cipher_suites);
452
453         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
454         if (!nl_modes)
455                 goto nla_put_failure;
456
457         i = 0;
458         while (ifmodes) {
459                 if (ifmodes & 1)
460                         NLA_PUT_FLAG(msg, i);
461                 ifmodes >>= 1;
462                 i++;
463         }
464
465         nla_nest_end(msg, nl_modes);
466
467         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
468         if (!nl_bands)
469                 goto nla_put_failure;
470
471         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
472                 if (!dev->wiphy.bands[band])
473                         continue;
474
475                 nl_band = nla_nest_start(msg, band);
476                 if (!nl_band)
477                         goto nla_put_failure;
478
479                 /* add HT info */
480                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
481                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
482                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
483                                 &dev->wiphy.bands[band]->ht_cap.mcs);
484                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
485                                 dev->wiphy.bands[band]->ht_cap.cap);
486                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
487                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
488                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
489                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
490                 }
491
492                 /* add frequencies */
493                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
494                 if (!nl_freqs)
495                         goto nla_put_failure;
496
497                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
498                         nl_freq = nla_nest_start(msg, i);
499                         if (!nl_freq)
500                                 goto nla_put_failure;
501
502                         chan = &dev->wiphy.bands[band]->channels[i];
503
504                         if (nl80211_msg_put_channel(msg, chan))
505                                 goto nla_put_failure;
506
507                         nla_nest_end(msg, nl_freq);
508                 }
509
510                 nla_nest_end(msg, nl_freqs);
511
512                 /* add bitrates */
513                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
514                 if (!nl_rates)
515                         goto nla_put_failure;
516
517                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
518                         nl_rate = nla_nest_start(msg, i);
519                         if (!nl_rate)
520                                 goto nla_put_failure;
521
522                         rate = &dev->wiphy.bands[band]->bitrates[i];
523                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
524                                     rate->bitrate);
525                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
526                                 NLA_PUT_FLAG(msg,
527                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
528
529                         nla_nest_end(msg, nl_rate);
530                 }
531
532                 nla_nest_end(msg, nl_rates);
533
534                 nla_nest_end(msg, nl_band);
535         }
536         nla_nest_end(msg, nl_bands);
537
538         nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
539         if (!nl_cmds)
540                 goto nla_put_failure;
541
542         i = 0;
543 #define CMD(op, n)                                              \
544          do {                                                   \
545                 if (dev->ops->op) {                             \
546                         i++;                                    \
547                         NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
548                 }                                               \
549         } while (0)
550
551         CMD(add_virtual_intf, NEW_INTERFACE);
552         CMD(change_virtual_intf, SET_INTERFACE);
553         CMD(add_key, NEW_KEY);
554         CMD(add_beacon, NEW_BEACON);
555         CMD(add_station, NEW_STATION);
556         CMD(add_mpath, NEW_MPATH);
557         CMD(set_mesh_params, SET_MESH_PARAMS);
558         CMD(change_bss, SET_BSS);
559         CMD(auth, AUTHENTICATE);
560         CMD(assoc, ASSOCIATE);
561         CMD(deauth, DEAUTHENTICATE);
562         CMD(disassoc, DISASSOCIATE);
563         CMD(join_ibss, JOIN_IBSS);
564         if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
565                 i++;
566                 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
567         }
568
569 #undef CMD
570
571         if (dev->ops->connect || dev->ops->auth) {
572                 i++;
573                 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
574         }
575
576         if (dev->ops->disconnect || dev->ops->deauth) {
577                 i++;
578                 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
579         }
580
581         nla_nest_end(msg, nl_cmds);
582
583         return genlmsg_end(msg, hdr);
584
585  nla_put_failure:
586         genlmsg_cancel(msg, hdr);
587         return -EMSGSIZE;
588 }
589
590 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
591 {
592         int idx = 0;
593         int start = cb->args[0];
594         struct cfg80211_registered_device *dev;
595
596         mutex_lock(&cfg80211_mutex);
597         list_for_each_entry(dev, &cfg80211_rdev_list, list) {
598                 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
599                         continue;
600                 if (++idx <= start)
601                         continue;
602                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
603                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
604                                        dev) < 0) {
605                         idx--;
606                         break;
607                 }
608         }
609         mutex_unlock(&cfg80211_mutex);
610
611         cb->args[0] = idx;
612
613         return skb->len;
614 }
615
616 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
617 {
618         struct sk_buff *msg;
619         struct cfg80211_registered_device *dev;
620
621         dev = cfg80211_get_dev_from_info(info);
622         if (IS_ERR(dev))
623                 return PTR_ERR(dev);
624
625         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
626         if (!msg)
627                 goto out_err;
628
629         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
630                 goto out_free;
631
632         cfg80211_unlock_rdev(dev);
633
634         return genlmsg_reply(msg, info);
635
636  out_free:
637         nlmsg_free(msg);
638  out_err:
639         cfg80211_unlock_rdev(dev);
640         return -ENOBUFS;
641 }
642
643 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
644         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
645         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
646         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
647         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
648         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
649 };
650
651 static int parse_txq_params(struct nlattr *tb[],
652                             struct ieee80211_txq_params *txq_params)
653 {
654         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
655             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
656             !tb[NL80211_TXQ_ATTR_AIFS])
657                 return -EINVAL;
658
659         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
660         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
661         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
662         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
663         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
664
665         return 0;
666 }
667
668 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
669 {
670         struct cfg80211_registered_device *rdev;
671         int result = 0, rem_txq_params = 0;
672         struct nlattr *nl_txq_params;
673         u32 changed;
674         u8 retry_short = 0, retry_long = 0;
675         u32 frag_threshold = 0, rts_threshold = 0;
676
677         rtnl_lock();
678
679         mutex_lock(&cfg80211_mutex);
680
681         rdev = __cfg80211_rdev_from_info(info);
682         if (IS_ERR(rdev)) {
683                 mutex_unlock(&cfg80211_mutex);
684                 result = PTR_ERR(rdev);
685                 goto unlock;
686         }
687
688         mutex_lock(&rdev->mtx);
689
690         if (info->attrs[NL80211_ATTR_WIPHY_NAME])
691                 result = cfg80211_dev_rename(
692                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
693
694         mutex_unlock(&cfg80211_mutex);
695
696         if (result)
697                 goto bad_res;
698
699         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
700                 struct ieee80211_txq_params txq_params;
701                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
702
703                 if (!rdev->ops->set_txq_params) {
704                         result = -EOPNOTSUPP;
705                         goto bad_res;
706                 }
707
708                 nla_for_each_nested(nl_txq_params,
709                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
710                                     rem_txq_params) {
711                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
712                                   nla_data(nl_txq_params),
713                                   nla_len(nl_txq_params),
714                                   txq_params_policy);
715                         result = parse_txq_params(tb, &txq_params);
716                         if (result)
717                                 goto bad_res;
718
719                         result = rdev->ops->set_txq_params(&rdev->wiphy,
720                                                            &txq_params);
721                         if (result)
722                                 goto bad_res;
723                 }
724         }
725
726         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
727                 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
728                 u32 freq;
729
730                 result = -EINVAL;
731
732                 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
733                         channel_type = nla_get_u32(info->attrs[
734                                            NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
735                         if (channel_type != NL80211_CHAN_NO_HT &&
736                             channel_type != NL80211_CHAN_HT20 &&
737                             channel_type != NL80211_CHAN_HT40PLUS &&
738                             channel_type != NL80211_CHAN_HT40MINUS)
739                                 goto bad_res;
740                 }
741
742                 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
743
744                 mutex_lock(&rdev->devlist_mtx);
745                 result = rdev_set_freq(rdev, NULL, freq, channel_type);
746                 mutex_unlock(&rdev->devlist_mtx);
747                 if (result)
748                         goto bad_res;
749         }
750
751         changed = 0;
752
753         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
754                 retry_short = nla_get_u8(
755                         info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
756                 if (retry_short == 0) {
757                         result = -EINVAL;
758                         goto bad_res;
759                 }
760                 changed |= WIPHY_PARAM_RETRY_SHORT;
761         }
762
763         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
764                 retry_long = nla_get_u8(
765                         info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
766                 if (retry_long == 0) {
767                         result = -EINVAL;
768                         goto bad_res;
769                 }
770                 changed |= WIPHY_PARAM_RETRY_LONG;
771         }
772
773         if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
774                 frag_threshold = nla_get_u32(
775                         info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
776                 if (frag_threshold < 256) {
777                         result = -EINVAL;
778                         goto bad_res;
779                 }
780                 if (frag_threshold != (u32) -1) {
781                         /*
782                          * Fragments (apart from the last one) are required to
783                          * have even length. Make the fragmentation code
784                          * simpler by stripping LSB should someone try to use
785                          * odd threshold value.
786                          */
787                         frag_threshold &= ~0x1;
788                 }
789                 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
790         }
791
792         if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
793                 rts_threshold = nla_get_u32(
794                         info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
795                 changed |= WIPHY_PARAM_RTS_THRESHOLD;
796         }
797
798         if (changed) {
799                 u8 old_retry_short, old_retry_long;
800                 u32 old_frag_threshold, old_rts_threshold;
801
802                 if (!rdev->ops->set_wiphy_params) {
803                         result = -EOPNOTSUPP;
804                         goto bad_res;
805                 }
806
807                 old_retry_short = rdev->wiphy.retry_short;
808                 old_retry_long = rdev->wiphy.retry_long;
809                 old_frag_threshold = rdev->wiphy.frag_threshold;
810                 old_rts_threshold = rdev->wiphy.rts_threshold;
811
812                 if (changed & WIPHY_PARAM_RETRY_SHORT)
813                         rdev->wiphy.retry_short = retry_short;
814                 if (changed & WIPHY_PARAM_RETRY_LONG)
815                         rdev->wiphy.retry_long = retry_long;
816                 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
817                         rdev->wiphy.frag_threshold = frag_threshold;
818                 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
819                         rdev->wiphy.rts_threshold = rts_threshold;
820
821                 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
822                 if (result) {
823                         rdev->wiphy.retry_short = old_retry_short;
824                         rdev->wiphy.retry_long = old_retry_long;
825                         rdev->wiphy.frag_threshold = old_frag_threshold;
826                         rdev->wiphy.rts_threshold = old_rts_threshold;
827                 }
828         }
829
830  bad_res:
831         mutex_unlock(&rdev->mtx);
832  unlock:
833         rtnl_unlock();
834         return result;
835 }
836
837
838 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
839                               struct cfg80211_registered_device *rdev,
840                               struct net_device *dev)
841 {
842         void *hdr;
843
844         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
845         if (!hdr)
846                 return -1;
847
848         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
849         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
850         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
851         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
852
853         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
854                     rdev->devlist_generation ^
855                         (cfg80211_rdev_list_generation << 2));
856
857         return genlmsg_end(msg, hdr);
858
859  nla_put_failure:
860         genlmsg_cancel(msg, hdr);
861         return -EMSGSIZE;
862 }
863
864 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
865 {
866         int wp_idx = 0;
867         int if_idx = 0;
868         int wp_start = cb->args[0];
869         int if_start = cb->args[1];
870         struct cfg80211_registered_device *rdev;
871         struct wireless_dev *wdev;
872
873         mutex_lock(&cfg80211_mutex);
874         list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
875                 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
876                         continue;
877                 if (wp_idx < wp_start) {
878                         wp_idx++;
879                         continue;
880                 }
881                 if_idx = 0;
882
883                 mutex_lock(&rdev->devlist_mtx);
884                 list_for_each_entry(wdev, &rdev->netdev_list, list) {
885                         if (if_idx < if_start) {
886                                 if_idx++;
887                                 continue;
888                         }
889                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
890                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
891                                                rdev, wdev->netdev) < 0) {
892                                 mutex_unlock(&rdev->devlist_mtx);
893                                 goto out;
894                         }
895                         if_idx++;
896                 }
897                 mutex_unlock(&rdev->devlist_mtx);
898
899                 wp_idx++;
900         }
901  out:
902         mutex_unlock(&cfg80211_mutex);
903
904         cb->args[0] = wp_idx;
905         cb->args[1] = if_idx;
906
907         return skb->len;
908 }
909
910 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
911 {
912         struct sk_buff *msg;
913         struct cfg80211_registered_device *dev;
914         struct net_device *netdev;
915         int err;
916
917         err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
918         if (err)
919                 return err;
920
921         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
922         if (!msg)
923                 goto out_err;
924
925         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
926                                dev, netdev) < 0)
927                 goto out_free;
928
929         dev_put(netdev);
930         cfg80211_unlock_rdev(dev);
931
932         return genlmsg_reply(msg, info);
933
934  out_free:
935         nlmsg_free(msg);
936  out_err:
937         dev_put(netdev);
938         cfg80211_unlock_rdev(dev);
939         return -ENOBUFS;
940 }
941
942 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
943         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
944         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
945         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
946         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
947         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
948 };
949
950 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
951 {
952         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
953         int flag;
954
955         *mntrflags = 0;
956
957         if (!nla)
958                 return -EINVAL;
959
960         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
961                              nla, mntr_flags_policy))
962                 return -EINVAL;
963
964         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
965                 if (flags[flag])
966                         *mntrflags |= (1<<flag);
967
968         return 0;
969 }
970
971 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
972                                struct net_device *netdev, u8 use_4addr,
973                                enum nl80211_iftype iftype)
974 {
975         if (!use_4addr) {
976                 if (netdev && netdev->br_port)
977                         return -EBUSY;
978                 return 0;
979         }
980
981         switch (iftype) {
982         case NL80211_IFTYPE_AP_VLAN:
983                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
984                         return 0;
985                 break;
986         case NL80211_IFTYPE_STATION:
987                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
988                         return 0;
989                 break;
990         default:
991                 break;
992         }
993
994         return -EOPNOTSUPP;
995 }
996
997 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
998 {
999         struct cfg80211_registered_device *rdev;
1000         struct vif_params params;
1001         int err;
1002         enum nl80211_iftype otype, ntype;
1003         struct net_device *dev;
1004         u32 _flags, *flags = NULL;
1005         bool change = false;
1006
1007         memset(&params, 0, sizeof(params));
1008
1009         rtnl_lock();
1010
1011         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1012         if (err)
1013                 goto unlock_rtnl;
1014
1015         otype = ntype = dev->ieee80211_ptr->iftype;
1016
1017         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1018                 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1019                 if (otype != ntype)
1020                         change = true;
1021                 if (ntype > NL80211_IFTYPE_MAX) {
1022                         err = -EINVAL;
1023                         goto unlock;
1024                 }
1025         }
1026
1027         if (info->attrs[NL80211_ATTR_MESH_ID]) {
1028                 if (ntype != NL80211_IFTYPE_MESH_POINT) {
1029                         err = -EINVAL;
1030                         goto unlock;
1031                 }
1032                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1033                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1034                 change = true;
1035         }
1036
1037         if (info->attrs[NL80211_ATTR_4ADDR]) {
1038                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1039                 change = true;
1040                 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1041                 if (err)
1042                         goto unlock;
1043         } else {
1044                 params.use_4addr = -1;
1045         }
1046
1047         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1048                 if (ntype != NL80211_IFTYPE_MONITOR) {
1049                         err = -EINVAL;
1050                         goto unlock;
1051                 }
1052                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1053                                           &_flags);
1054                 if (err)
1055                         goto unlock;
1056
1057                 flags = &_flags;
1058                 change = true;
1059         }
1060
1061         if (change)
1062                 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1063         else
1064                 err = 0;
1065
1066         if (!err && params.use_4addr != -1)
1067                 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1068
1069  unlock:
1070         dev_put(dev);
1071         cfg80211_unlock_rdev(rdev);
1072  unlock_rtnl:
1073         rtnl_unlock();
1074         return err;
1075 }
1076
1077 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1078 {
1079         struct cfg80211_registered_device *rdev;
1080         struct vif_params params;
1081         int err;
1082         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1083         u32 flags;
1084
1085         memset(&params, 0, sizeof(params));
1086
1087         if (!info->attrs[NL80211_ATTR_IFNAME])
1088                 return -EINVAL;
1089
1090         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1091                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1092                 if (type > NL80211_IFTYPE_MAX)
1093                         return -EINVAL;
1094         }
1095
1096         rtnl_lock();
1097
1098         rdev = cfg80211_get_dev_from_info(info);
1099         if (IS_ERR(rdev)) {
1100                 err = PTR_ERR(rdev);
1101                 goto unlock_rtnl;
1102         }
1103
1104         if (!rdev->ops->add_virtual_intf ||
1105             !(rdev->wiphy.interface_modes & (1 << type))) {
1106                 err = -EOPNOTSUPP;
1107                 goto unlock;
1108         }
1109
1110         if (type == NL80211_IFTYPE_MESH_POINT &&
1111             info->attrs[NL80211_ATTR_MESH_ID]) {
1112                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1113                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1114         }
1115
1116         if (info->attrs[NL80211_ATTR_4ADDR]) {
1117                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1118                 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1119                 if (err)
1120                         goto unlock;
1121         }
1122
1123         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1124                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1125                                   &flags);
1126         err = rdev->ops->add_virtual_intf(&rdev->wiphy,
1127                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1128                 type, err ? NULL : &flags, &params);
1129
1130  unlock:
1131         cfg80211_unlock_rdev(rdev);
1132  unlock_rtnl:
1133         rtnl_unlock();
1134         return err;
1135 }
1136
1137 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1138 {
1139         struct cfg80211_registered_device *rdev;
1140         int err;
1141         struct net_device *dev;
1142
1143         rtnl_lock();
1144
1145         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1146         if (err)
1147                 goto unlock_rtnl;
1148
1149         if (!rdev->ops->del_virtual_intf) {
1150                 err = -EOPNOTSUPP;
1151                 goto out;
1152         }
1153
1154         err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1155
1156  out:
1157         cfg80211_unlock_rdev(rdev);
1158         dev_put(dev);
1159  unlock_rtnl:
1160         rtnl_unlock();
1161         return err;
1162 }
1163
1164 struct get_key_cookie {
1165         struct sk_buff *msg;
1166         int error;
1167         int idx;
1168 };
1169
1170 static void get_key_callback(void *c, struct key_params *params)
1171 {
1172         struct nlattr *key;
1173         struct get_key_cookie *cookie = c;
1174
1175         if (params->key)
1176                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1177                         params->key_len, params->key);
1178
1179         if (params->seq)
1180                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1181                         params->seq_len, params->seq);
1182
1183         if (params->cipher)
1184                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1185                             params->cipher);
1186
1187         key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1188         if (!key)
1189                 goto nla_put_failure;
1190
1191         if (params->key)
1192                 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1193                         params->key_len, params->key);
1194
1195         if (params->seq)
1196                 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1197                         params->seq_len, params->seq);
1198
1199         if (params->cipher)
1200                 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1201                             params->cipher);
1202
1203         NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1204
1205         nla_nest_end(cookie->msg, key);
1206
1207         return;
1208  nla_put_failure:
1209         cookie->error = 1;
1210 }
1211
1212 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1213 {
1214         struct cfg80211_registered_device *rdev;
1215         int err;
1216         struct net_device *dev;
1217         u8 key_idx = 0;
1218         u8 *mac_addr = NULL;
1219         struct get_key_cookie cookie = {
1220                 .error = 0,
1221         };
1222         void *hdr;
1223         struct sk_buff *msg;
1224
1225         if (info->attrs[NL80211_ATTR_KEY_IDX])
1226                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1227
1228         if (key_idx > 5)
1229                 return -EINVAL;
1230
1231         if (info->attrs[NL80211_ATTR_MAC])
1232                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1233
1234         rtnl_lock();
1235
1236         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1237         if (err)
1238                 goto unlock_rtnl;
1239
1240         if (!rdev->ops->get_key) {
1241                 err = -EOPNOTSUPP;
1242                 goto out;
1243         }
1244
1245         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1246         if (!msg) {
1247                 err = -ENOMEM;
1248                 goto out;
1249         }
1250
1251         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1252                              NL80211_CMD_NEW_KEY);
1253
1254         if (IS_ERR(hdr)) {
1255                 err = PTR_ERR(hdr);
1256                 goto free_msg;
1257         }
1258
1259         cookie.msg = msg;
1260         cookie.idx = key_idx;
1261
1262         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1263         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1264         if (mac_addr)
1265                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1266
1267         err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
1268                                 &cookie, get_key_callback);
1269
1270         if (err)
1271                 goto free_msg;
1272
1273         if (cookie.error)
1274                 goto nla_put_failure;
1275
1276         genlmsg_end(msg, hdr);
1277         err = genlmsg_reply(msg, info);
1278         goto out;
1279
1280  nla_put_failure:
1281         err = -ENOBUFS;
1282  free_msg:
1283         nlmsg_free(msg);
1284  out:
1285         cfg80211_unlock_rdev(rdev);
1286         dev_put(dev);
1287  unlock_rtnl:
1288         rtnl_unlock();
1289
1290         return err;
1291 }
1292
1293 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1294 {
1295         struct cfg80211_registered_device *rdev;
1296         struct key_parse key;
1297         int err;
1298         struct net_device *dev;
1299         int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1300                     u8 key_index);
1301
1302         err = nl80211_parse_key(info, &key);
1303         if (err)
1304                 return err;
1305
1306         if (key.idx < 0)
1307                 return -EINVAL;
1308
1309         /* only support setting default key */
1310         if (!key.def && !key.defmgmt)
1311                 return -EINVAL;
1312
1313         rtnl_lock();
1314
1315         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1316         if (err)
1317                 goto unlock_rtnl;
1318
1319         if (key.def)
1320                 func = rdev->ops->set_default_key;
1321         else
1322                 func = rdev->ops->set_default_mgmt_key;
1323
1324         if (!func) {
1325                 err = -EOPNOTSUPP;
1326                 goto out;
1327         }
1328
1329         wdev_lock(dev->ieee80211_ptr);
1330         err = nl80211_key_allowed(dev->ieee80211_ptr);
1331         if (!err)
1332                 err = func(&rdev->wiphy, dev, key.idx);
1333
1334 #ifdef CONFIG_CFG80211_WEXT
1335         if (!err) {
1336                 if (func == rdev->ops->set_default_key)
1337                         dev->ieee80211_ptr->wext.default_key = key.idx;
1338                 else
1339                         dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1340         }
1341 #endif
1342         wdev_unlock(dev->ieee80211_ptr);
1343
1344  out:
1345         cfg80211_unlock_rdev(rdev);
1346         dev_put(dev);
1347
1348  unlock_rtnl:
1349         rtnl_unlock();
1350
1351         return err;
1352 }
1353
1354 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1355 {
1356         struct cfg80211_registered_device *rdev;
1357         int err;
1358         struct net_device *dev;
1359         struct key_parse key;
1360         u8 *mac_addr = NULL;
1361
1362         err = nl80211_parse_key(info, &key);
1363         if (err)
1364                 return err;
1365
1366         if (!key.p.key)
1367                 return -EINVAL;
1368
1369         if (info->attrs[NL80211_ATTR_MAC])
1370                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1371
1372         rtnl_lock();
1373
1374         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1375         if (err)
1376                 goto unlock_rtnl;
1377
1378         if (!rdev->ops->add_key) {
1379                 err = -EOPNOTSUPP;
1380                 goto out;
1381         }
1382
1383         if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1384                 err = -EINVAL;
1385                 goto out;
1386         }
1387
1388         wdev_lock(dev->ieee80211_ptr);
1389         err = nl80211_key_allowed(dev->ieee80211_ptr);
1390         if (!err)
1391                 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1392                                          mac_addr, &key.p);
1393         wdev_unlock(dev->ieee80211_ptr);
1394
1395  out:
1396         cfg80211_unlock_rdev(rdev);
1397         dev_put(dev);
1398  unlock_rtnl:
1399         rtnl_unlock();
1400
1401         return err;
1402 }
1403
1404 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1405 {
1406         struct cfg80211_registered_device *rdev;
1407         int err;
1408         struct net_device *dev;
1409         u8 *mac_addr = NULL;
1410         struct key_parse key;
1411
1412         err = nl80211_parse_key(info, &key);
1413         if (err)
1414                 return err;
1415
1416         if (info->attrs[NL80211_ATTR_MAC])
1417                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1418
1419         rtnl_lock();
1420
1421         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1422         if (err)
1423                 goto unlock_rtnl;
1424
1425         if (!rdev->ops->del_key) {
1426                 err = -EOPNOTSUPP;
1427                 goto out;
1428         }
1429
1430         wdev_lock(dev->ieee80211_ptr);
1431         err = nl80211_key_allowed(dev->ieee80211_ptr);
1432         if (!err)
1433                 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
1434
1435 #ifdef CONFIG_CFG80211_WEXT
1436         if (!err) {
1437                 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1438                         dev->ieee80211_ptr->wext.default_key = -1;
1439                 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1440                         dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1441         }
1442 #endif
1443         wdev_unlock(dev->ieee80211_ptr);
1444
1445  out:
1446         cfg80211_unlock_rdev(rdev);
1447         dev_put(dev);
1448
1449  unlock_rtnl:
1450         rtnl_unlock();
1451
1452         return err;
1453 }
1454
1455 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1456 {
1457         int (*call)(struct wiphy *wiphy, struct net_device *dev,
1458                     struct beacon_parameters *info);
1459         struct cfg80211_registered_device *rdev;
1460         int err;
1461         struct net_device *dev;
1462         struct beacon_parameters params;
1463         int haveinfo = 0;
1464
1465         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1466                 return -EINVAL;
1467
1468         rtnl_lock();
1469
1470         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1471         if (err)
1472                 goto unlock_rtnl;
1473
1474         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1475                 err = -EOPNOTSUPP;
1476                 goto out;
1477         }
1478
1479         switch (info->genlhdr->cmd) {
1480         case NL80211_CMD_NEW_BEACON:
1481                 /* these are required for NEW_BEACON */
1482                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1483                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1484                     !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1485                         err = -EINVAL;
1486                         goto out;
1487                 }
1488
1489                 call = rdev->ops->add_beacon;
1490                 break;
1491         case NL80211_CMD_SET_BEACON:
1492                 call = rdev->ops->set_beacon;
1493                 break;
1494         default:
1495                 WARN_ON(1);
1496                 err = -EOPNOTSUPP;
1497                 goto out;
1498         }
1499
1500         if (!call) {
1501                 err = -EOPNOTSUPP;
1502                 goto out;
1503         }
1504
1505         memset(&params, 0, sizeof(params));
1506
1507         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1508                 params.interval =
1509                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1510                 haveinfo = 1;
1511         }
1512
1513         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1514                 params.dtim_period =
1515                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1516                 haveinfo = 1;
1517         }
1518
1519         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1520                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1521                 params.head_len =
1522                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1523                 haveinfo = 1;
1524         }
1525
1526         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1527                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1528                 params.tail_len =
1529                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1530                 haveinfo = 1;
1531         }
1532
1533         if (!haveinfo) {
1534                 err = -EINVAL;
1535                 goto out;
1536         }
1537
1538         err = call(&rdev->wiphy, dev, &params);
1539
1540  out:
1541         cfg80211_unlock_rdev(rdev);
1542         dev_put(dev);
1543  unlock_rtnl:
1544         rtnl_unlock();
1545
1546         return err;
1547 }
1548
1549 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1550 {
1551         struct cfg80211_registered_device *rdev;
1552         int err;
1553         struct net_device *dev;
1554
1555         rtnl_lock();
1556
1557         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1558         if (err)
1559                 goto unlock_rtnl;
1560
1561         if (!rdev->ops->del_beacon) {
1562                 err = -EOPNOTSUPP;
1563                 goto out;
1564         }
1565
1566         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1567                 err = -EOPNOTSUPP;
1568                 goto out;
1569         }
1570         err = rdev->ops->del_beacon(&rdev->wiphy, dev);
1571
1572  out:
1573         cfg80211_unlock_rdev(rdev);
1574         dev_put(dev);
1575  unlock_rtnl:
1576         rtnl_unlock();
1577
1578         return err;
1579 }
1580
1581 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1582         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1583         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1584         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1585         [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1586 };
1587
1588 static int parse_station_flags(struct genl_info *info,
1589                                struct station_parameters *params)
1590 {
1591         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1592         struct nlattr *nla;
1593         int flag;
1594
1595         /*
1596          * Try parsing the new attribute first so userspace
1597          * can specify both for older kernels.
1598          */
1599         nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1600         if (nla) {
1601                 struct nl80211_sta_flag_update *sta_flags;
1602
1603                 sta_flags = nla_data(nla);
1604                 params->sta_flags_mask = sta_flags->mask;
1605                 params->sta_flags_set = sta_flags->set;
1606                 if ((params->sta_flags_mask |
1607                      params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1608                         return -EINVAL;
1609                 return 0;
1610         }
1611
1612         /* if present, parse the old attribute */
1613
1614         nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1615         if (!nla)
1616                 return 0;
1617
1618         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1619                              nla, sta_flags_policy))
1620                 return -EINVAL;
1621
1622         params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1623         params->sta_flags_mask &= ~1;
1624
1625         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1626                 if (flags[flag])
1627                         params->sta_flags_set |= (1<<flag);
1628
1629         return 0;
1630 }
1631
1632 static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1633 {
1634         int modulation, streams, bitrate;
1635
1636         if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1637                 return rate->legacy;
1638
1639         /* the formula below does only work for MCS values smaller than 32 */
1640         if (rate->mcs >= 32)
1641                 return 0;
1642
1643         modulation = rate->mcs & 7;
1644         streams = (rate->mcs >> 3) + 1;
1645
1646         bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1647                         13500000 : 6500000;
1648
1649         if (modulation < 4)
1650                 bitrate *= (modulation + 1);
1651         else if (modulation == 4)
1652                 bitrate *= (modulation + 2);
1653         else
1654                 bitrate *= (modulation + 3);
1655
1656         bitrate *= streams;
1657
1658         if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1659                 bitrate = (bitrate / 9) * 10;
1660
1661         /* do NOT round down here */
1662         return (bitrate + 50000) / 100000;
1663 }
1664
1665 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1666                                 int flags, struct net_device *dev,
1667                                 u8 *mac_addr, struct station_info *sinfo)
1668 {
1669         void *hdr;
1670         struct nlattr *sinfoattr, *txrate;
1671         u16 bitrate;
1672
1673         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1674         if (!hdr)
1675                 return -1;
1676
1677         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1678         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1679
1680         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1681
1682         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1683         if (!sinfoattr)
1684                 goto nla_put_failure;
1685         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1686                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1687                             sinfo->inactive_time);
1688         if (sinfo->filled & STATION_INFO_RX_BYTES)
1689                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1690                             sinfo->rx_bytes);
1691         if (sinfo->filled & STATION_INFO_TX_BYTES)
1692                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1693                             sinfo->tx_bytes);
1694         if (sinfo->filled & STATION_INFO_LLID)
1695                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1696                             sinfo->llid);
1697         if (sinfo->filled & STATION_INFO_PLID)
1698                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1699                             sinfo->plid);
1700         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1701                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1702                             sinfo->plink_state);
1703         if (sinfo->filled & STATION_INFO_SIGNAL)
1704                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1705                            sinfo->signal);
1706         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1707                 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1708                 if (!txrate)
1709                         goto nla_put_failure;
1710
1711                 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1712                 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1713                 if (bitrate > 0)
1714                         NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1715
1716                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1717                         NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1718                                     sinfo->txrate.mcs);
1719                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1720                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1721                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1722                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1723
1724                 nla_nest_end(msg, txrate);
1725         }
1726         if (sinfo->filled & STATION_INFO_RX_PACKETS)
1727                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1728                             sinfo->rx_packets);
1729         if (sinfo->filled & STATION_INFO_TX_PACKETS)
1730                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1731                             sinfo->tx_packets);
1732         nla_nest_end(msg, sinfoattr);
1733
1734         return genlmsg_end(msg, hdr);
1735
1736  nla_put_failure:
1737         genlmsg_cancel(msg, hdr);
1738         return -EMSGSIZE;
1739 }
1740
1741 static int nl80211_dump_station(struct sk_buff *skb,
1742                                 struct netlink_callback *cb)
1743 {
1744         struct station_info sinfo;
1745         struct cfg80211_registered_device *dev;
1746         struct net_device *netdev;
1747         u8 mac_addr[ETH_ALEN];
1748         int ifidx = cb->args[0];
1749         int sta_idx = cb->args[1];
1750         int err;
1751
1752         if (!ifidx)
1753                 ifidx = nl80211_get_ifidx(cb);
1754         if (ifidx < 0)
1755                 return ifidx;
1756
1757         rtnl_lock();
1758
1759         netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
1760         if (!netdev) {
1761                 err = -ENODEV;
1762                 goto out_rtnl;
1763         }
1764
1765         dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
1766         if (IS_ERR(dev)) {
1767                 err = PTR_ERR(dev);
1768                 goto out_rtnl;
1769         }
1770
1771         if (!dev->ops->dump_station) {
1772                 err = -EOPNOTSUPP;
1773                 goto out_err;
1774         }
1775
1776         while (1) {
1777                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1778                                              mac_addr, &sinfo);
1779                 if (err == -ENOENT)
1780                         break;
1781                 if (err)
1782                         goto out_err;
1783
1784                 if (nl80211_send_station(skb,
1785                                 NETLINK_CB(cb->skb).pid,
1786                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1787                                 netdev, mac_addr,
1788                                 &sinfo) < 0)
1789                         goto out;
1790
1791                 sta_idx++;
1792         }
1793
1794
1795  out:
1796         cb->args[1] = sta_idx;
1797         err = skb->len;
1798  out_err:
1799         cfg80211_unlock_rdev(dev);
1800  out_rtnl:
1801         rtnl_unlock();
1802
1803         return err;
1804 }
1805
1806 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1807 {
1808         struct cfg80211_registered_device *rdev;
1809         int err;
1810         struct net_device *dev;
1811         struct station_info sinfo;
1812         struct sk_buff *msg;
1813         u8 *mac_addr = NULL;
1814
1815         memset(&sinfo, 0, sizeof(sinfo));
1816
1817         if (!info->attrs[NL80211_ATTR_MAC])
1818                 return -EINVAL;
1819
1820         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1821
1822         rtnl_lock();
1823
1824         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1825         if (err)
1826                 goto out_rtnl;
1827
1828         if (!rdev->ops->get_station) {
1829                 err = -EOPNOTSUPP;
1830                 goto out;
1831         }
1832
1833         err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
1834         if (err)
1835                 goto out;
1836
1837         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1838         if (!msg)
1839                 goto out;
1840
1841         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1842                                  dev, mac_addr, &sinfo) < 0)
1843                 goto out_free;
1844
1845         err = genlmsg_reply(msg, info);
1846         goto out;
1847
1848  out_free:
1849         nlmsg_free(msg);
1850  out:
1851         cfg80211_unlock_rdev(rdev);
1852         dev_put(dev);
1853  out_rtnl:
1854         rtnl_unlock();
1855
1856         return err;
1857 }
1858
1859 /*
1860  * Get vlan interface making sure it is running and on the right wiphy.
1861  */
1862 static int get_vlan(struct genl_info *info,
1863                     struct cfg80211_registered_device *rdev,
1864                     struct net_device **vlan)
1865 {
1866         struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
1867         *vlan = NULL;
1868
1869         if (vlanattr) {
1870                 *vlan = dev_get_by_index(genl_info_net(info),
1871                                          nla_get_u32(vlanattr));
1872                 if (!*vlan)
1873                         return -ENODEV;
1874                 if (!(*vlan)->ieee80211_ptr)
1875                         return -EINVAL;
1876                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1877                         return -EINVAL;
1878                 if (!netif_running(*vlan))
1879                         return -ENETDOWN;
1880         }
1881         return 0;
1882 }
1883
1884 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1885 {
1886         struct cfg80211_registered_device *rdev;
1887         int err;
1888         struct net_device *dev;
1889         struct station_parameters params;
1890         u8 *mac_addr = NULL;
1891
1892         memset(&params, 0, sizeof(params));
1893
1894         params.listen_interval = -1;
1895
1896         if (info->attrs[NL80211_ATTR_STA_AID])
1897                 return -EINVAL;
1898
1899         if (!info->attrs[NL80211_ATTR_MAC])
1900                 return -EINVAL;
1901
1902         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1903
1904         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1905                 params.supported_rates =
1906                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1907                 params.supported_rates_len =
1908                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1909         }
1910
1911         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1912                 params.listen_interval =
1913                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1914
1915         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1916                 params.ht_capa =
1917                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1918
1919         if (parse_station_flags(info, &params))
1920                 return -EINVAL;
1921
1922         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1923                 params.plink_action =
1924                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1925
1926         rtnl_lock();
1927
1928         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1929         if (err)
1930                 goto out_rtnl;
1931
1932         err = get_vlan(info, rdev, &params.vlan);
1933         if (err)
1934                 goto out;
1935
1936         /* validate settings */
1937         err = 0;
1938
1939         switch (dev->ieee80211_ptr->iftype) {
1940         case NL80211_IFTYPE_AP:
1941         case NL80211_IFTYPE_AP_VLAN:
1942                 /* disallow mesh-specific things */
1943                 if (params.plink_action)
1944                         err = -EINVAL;
1945                 break;
1946         case NL80211_IFTYPE_STATION:
1947                 /* disallow everything but AUTHORIZED flag */
1948                 if (params.plink_action)
1949                         err = -EINVAL;
1950                 if (params.vlan)
1951                         err = -EINVAL;
1952                 if (params.supported_rates)
1953                         err = -EINVAL;
1954                 if (params.ht_capa)
1955                         err = -EINVAL;
1956                 if (params.listen_interval >= 0)
1957                         err = -EINVAL;
1958                 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1959                         err = -EINVAL;
1960                 break;
1961         case NL80211_IFTYPE_MESH_POINT:
1962                 /* disallow things mesh doesn't support */
1963                 if (params.vlan)
1964                         err = -EINVAL;
1965                 if (params.ht_capa)
1966                         err = -EINVAL;
1967                 if (params.listen_interval >= 0)
1968                         err = -EINVAL;
1969                 if (params.supported_rates)
1970                         err = -EINVAL;
1971                 if (params.sta_flags_mask)
1972                         err = -EINVAL;
1973                 break;
1974         default:
1975                 err = -EINVAL;
1976         }
1977
1978         if (err)
1979                 goto out;
1980
1981         if (!rdev->ops->change_station) {
1982                 err = -EOPNOTSUPP;
1983                 goto out;
1984         }
1985
1986         err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
1987
1988  out:
1989         if (params.vlan)
1990                 dev_put(params.vlan);
1991         cfg80211_unlock_rdev(rdev);
1992         dev_put(dev);
1993  out_rtnl:
1994         rtnl_unlock();
1995
1996         return err;
1997 }
1998
1999 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2000 {
2001         struct cfg80211_registered_device *rdev;
2002         int err;
2003         struct net_device *dev;
2004         struct station_parameters params;
2005         u8 *mac_addr = NULL;
2006
2007         memset(&params, 0, sizeof(params));
2008
2009         if (!info->attrs[NL80211_ATTR_MAC])
2010                 return -EINVAL;
2011
2012         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2013                 return -EINVAL;
2014
2015         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2016                 return -EINVAL;
2017
2018         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2019         params.supported_rates =
2020                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2021         params.supported_rates_len =
2022                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2023         params.listen_interval =
2024                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2025
2026         if (info->attrs[NL80211_ATTR_STA_AID]) {
2027                 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2028                 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2029                         return -EINVAL;
2030         }
2031
2032         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2033                 params.ht_capa =
2034                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2035
2036         if (parse_station_flags(info, &params))
2037                 return -EINVAL;
2038
2039         rtnl_lock();
2040
2041         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2042         if (err)
2043                 goto out_rtnl;
2044
2045         err = get_vlan(info, rdev, &params.vlan);
2046         if (err)
2047                 goto out;
2048
2049         /* validate settings */
2050         err = 0;
2051
2052         switch (dev->ieee80211_ptr->iftype) {
2053         case NL80211_IFTYPE_AP:
2054         case NL80211_IFTYPE_AP_VLAN:
2055                 /* all ok but must have AID */
2056                 if (!params.aid)
2057                         err = -EINVAL;
2058                 break;
2059         case NL80211_IFTYPE_MESH_POINT:
2060                 /* disallow things mesh doesn't support */
2061                 if (params.vlan)
2062                         err = -EINVAL;
2063                 if (params.aid)
2064                         err = -EINVAL;
2065                 if (params.ht_capa)
2066                         err = -EINVAL;
2067                 if (params.listen_interval >= 0)
2068                         err = -EINVAL;
2069                 if (params.supported_rates)
2070                         err = -EINVAL;
2071                 if (params.sta_flags_mask)
2072                         err = -EINVAL;
2073                 break;
2074         default:
2075                 err = -EINVAL;
2076         }
2077
2078         if (err)
2079                 goto out;
2080
2081         if (!rdev->ops->add_station) {
2082                 err = -EOPNOTSUPP;
2083                 goto out;
2084         }
2085
2086         if (!netif_running(dev)) {
2087                 err = -ENETDOWN;
2088                 goto out;
2089         }
2090
2091         err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2092
2093  out:
2094         if (params.vlan)
2095                 dev_put(params.vlan);
2096         cfg80211_unlock_rdev(rdev);
2097         dev_put(dev);
2098  out_rtnl:
2099         rtnl_unlock();
2100
2101         return err;
2102 }
2103
2104 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2105 {
2106         struct cfg80211_registered_device *rdev;
2107         int err;
2108         struct net_device *dev;
2109         u8 *mac_addr = NULL;
2110
2111         if (info->attrs[NL80211_ATTR_MAC])
2112                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2113
2114         rtnl_lock();
2115
2116         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2117         if (err)
2118                 goto out_rtnl;
2119
2120         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2121             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2122             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2123                 err = -EINVAL;
2124                 goto out;
2125         }
2126
2127         if (!rdev->ops->del_station) {
2128                 err = -EOPNOTSUPP;
2129                 goto out;
2130         }
2131
2132         err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2133
2134  out:
2135         cfg80211_unlock_rdev(rdev);
2136         dev_put(dev);
2137  out_rtnl:
2138         rtnl_unlock();
2139
2140         return err;
2141 }
2142
2143 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2144                                 int flags, struct net_device *dev,
2145                                 u8 *dst, u8 *next_hop,
2146                                 struct mpath_info *pinfo)
2147 {
2148         void *hdr;
2149         struct nlattr *pinfoattr;
2150
2151         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2152         if (!hdr)
2153                 return -1;
2154
2155         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2156         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2157         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2158
2159         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2160
2161         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2162         if (!pinfoattr)
2163                 goto nla_put_failure;
2164         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2165                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2166                             pinfo->frame_qlen);
2167         if (pinfo->filled & MPATH_INFO_SN)
2168                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2169                             pinfo->sn);
2170         if (pinfo->filled & MPATH_INFO_METRIC)
2171                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2172                             pinfo->metric);
2173         if (pinfo->filled & MPATH_INFO_EXPTIME)
2174                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2175                             pinfo->exptime);
2176         if (pinfo->filled & MPATH_INFO_FLAGS)
2177                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2178                             pinfo->flags);
2179         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2180                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2181                             pinfo->discovery_timeout);
2182         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2183                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2184                             pinfo->discovery_retries);
2185
2186         nla_nest_end(msg, pinfoattr);
2187
2188         return genlmsg_end(msg, hdr);
2189
2190  nla_put_failure:
2191         genlmsg_cancel(msg, hdr);
2192         return -EMSGSIZE;
2193 }
2194
2195 static int nl80211_dump_mpath(struct sk_buff *skb,
2196                               struct netlink_callback *cb)
2197 {
2198         struct mpath_info pinfo;
2199         struct cfg80211_registered_device *dev;
2200         struct net_device *netdev;
2201         u8 dst[ETH_ALEN];
2202         u8 next_hop[ETH_ALEN];
2203         int ifidx = cb->args[0];
2204         int path_idx = cb->args[1];
2205         int err;
2206
2207         if (!ifidx)
2208                 ifidx = nl80211_get_ifidx(cb);
2209         if (ifidx < 0)
2210                 return ifidx;
2211
2212         rtnl_lock();
2213
2214         netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
2215         if (!netdev) {
2216                 err = -ENODEV;
2217                 goto out_rtnl;
2218         }
2219
2220         dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
2221         if (IS_ERR(dev)) {
2222                 err = PTR_ERR(dev);
2223                 goto out_rtnl;
2224         }
2225
2226         if (!dev->ops->dump_mpath) {
2227                 err = -EOPNOTSUPP;
2228                 goto out_err;
2229         }
2230
2231         if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2232                 err = -EOPNOTSUPP;
2233                 goto out_err;
2234         }
2235
2236         while (1) {
2237                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2238                                            dst, next_hop, &pinfo);
2239                 if (err == -ENOENT)
2240                         break;
2241                 if (err)
2242                         goto out_err;
2243
2244                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2245                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
2246                                        netdev, dst, next_hop,
2247                                        &pinfo) < 0)
2248                         goto out;
2249
2250                 path_idx++;
2251         }
2252
2253
2254  out:
2255         cb->args[1] = path_idx;
2256         err = skb->len;
2257  out_err:
2258         cfg80211_unlock_rdev(dev);
2259  out_rtnl:
2260         rtnl_unlock();
2261
2262         return err;
2263 }
2264
2265 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2266 {
2267         struct cfg80211_registered_device *rdev;
2268         int err;
2269         struct net_device *dev;
2270         struct mpath_info pinfo;
2271         struct sk_buff *msg;
2272         u8 *dst = NULL;
2273         u8 next_hop[ETH_ALEN];
2274
2275         memset(&pinfo, 0, sizeof(pinfo));
2276
2277         if (!info->attrs[NL80211_ATTR_MAC])
2278                 return -EINVAL;
2279
2280         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2281
2282         rtnl_lock();
2283
2284         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2285         if (err)
2286                 goto out_rtnl;
2287
2288         if (!rdev->ops->get_mpath) {
2289                 err = -EOPNOTSUPP;
2290                 goto out;
2291         }
2292
2293         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2294                 err = -EOPNOTSUPP;
2295                 goto out;
2296         }
2297
2298         err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2299         if (err)
2300                 goto out;
2301
2302         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2303         if (!msg)
2304                 goto out;
2305
2306         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2307                                  dev, dst, next_hop, &pinfo) < 0)
2308                 goto out_free;
2309
2310         err = genlmsg_reply(msg, info);
2311         goto out;
2312
2313  out_free:
2314         nlmsg_free(msg);
2315  out:
2316         cfg80211_unlock_rdev(rdev);
2317         dev_put(dev);
2318  out_rtnl:
2319         rtnl_unlock();
2320
2321         return err;
2322 }
2323
2324 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2325 {
2326         struct cfg80211_registered_device *rdev;
2327         int err;
2328         struct net_device *dev;
2329         u8 *dst = NULL;
2330         u8 *next_hop = NULL;
2331
2332         if (!info->attrs[NL80211_ATTR_MAC])
2333                 return -EINVAL;
2334
2335         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2336                 return -EINVAL;
2337
2338         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2339         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2340
2341         rtnl_lock();
2342
2343         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2344         if (err)
2345                 goto out_rtnl;
2346
2347         if (!rdev->ops->change_mpath) {
2348                 err = -EOPNOTSUPP;
2349                 goto out;
2350         }
2351
2352         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2353                 err = -EOPNOTSUPP;
2354                 goto out;
2355         }
2356
2357         if (!netif_running(dev)) {
2358                 err = -ENETDOWN;
2359                 goto out;
2360         }
2361
2362         err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2363
2364  out:
2365         cfg80211_unlock_rdev(rdev);
2366         dev_put(dev);
2367  out_rtnl:
2368         rtnl_unlock();
2369
2370         return err;
2371 }
2372 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2373 {
2374         struct cfg80211_registered_device *rdev;
2375         int err;
2376         struct net_device *dev;
2377         u8 *dst = NULL;
2378         u8 *next_hop = NULL;
2379
2380         if (!info->attrs[NL80211_ATTR_MAC])
2381                 return -EINVAL;
2382
2383         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2384                 return -EINVAL;
2385
2386         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2387         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2388
2389         rtnl_lock();
2390
2391         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2392         if (err)
2393                 goto out_rtnl;
2394
2395         if (!rdev->ops->add_mpath) {
2396                 err = -EOPNOTSUPP;
2397                 goto out;
2398         }
2399
2400         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2401                 err = -EOPNOTSUPP;
2402                 goto out;
2403         }
2404
2405         if (!netif_running(dev)) {
2406                 err = -ENETDOWN;
2407                 goto out;
2408         }
2409
2410         err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2411
2412  out:
2413         cfg80211_unlock_rdev(rdev);
2414         dev_put(dev);
2415  out_rtnl:
2416         rtnl_unlock();
2417
2418         return err;
2419 }
2420
2421 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2422 {
2423         struct cfg80211_registered_device *rdev;
2424         int err;
2425         struct net_device *dev;
2426         u8 *dst = NULL;
2427
2428         if (info->attrs[NL80211_ATTR_MAC])
2429                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2430
2431         rtnl_lock();
2432
2433         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2434         if (err)
2435                 goto out_rtnl;
2436
2437         if (!rdev->ops->del_mpath) {
2438                 err = -EOPNOTSUPP;
2439                 goto out;
2440         }
2441
2442         err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2443
2444  out:
2445         cfg80211_unlock_rdev(rdev);
2446         dev_put(dev);
2447  out_rtnl:
2448         rtnl_unlock();
2449
2450         return err;
2451 }
2452
2453 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2454 {
2455         struct cfg80211_registered_device *rdev;
2456         int err;
2457         struct net_device *dev;
2458         struct bss_parameters params;
2459
2460         memset(&params, 0, sizeof(params));
2461         /* default to not changing parameters */
2462         params.use_cts_prot = -1;
2463         params.use_short_preamble = -1;
2464         params.use_short_slot_time = -1;
2465
2466         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2467                 params.use_cts_prot =
2468                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2469         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2470                 params.use_short_preamble =
2471                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2472         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2473                 params.use_short_slot_time =
2474                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2475         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2476                 params.basic_rates =
2477                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2478                 params.basic_rates_len =
2479                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2480         }
2481
2482         rtnl_lock();
2483
2484         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2485         if (err)
2486                 goto out_rtnl;
2487
2488         if (!rdev->ops->change_bss) {
2489                 err = -EOPNOTSUPP;
2490                 goto out;
2491         }
2492
2493         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2494                 err = -EOPNOTSUPP;
2495                 goto out;
2496         }
2497
2498         err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2499
2500  out:
2501         cfg80211_unlock_rdev(rdev);
2502         dev_put(dev);
2503  out_rtnl:
2504         rtnl_unlock();
2505
2506         return err;
2507 }
2508
2509 static const struct nla_policy
2510         reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2511         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
2512         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
2513         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
2514         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
2515         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
2516         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
2517 };
2518
2519 static int parse_reg_rule(struct nlattr *tb[],
2520         struct ieee80211_reg_rule *reg_rule)
2521 {
2522         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2523         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2524
2525         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2526                 return -EINVAL;
2527         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2528                 return -EINVAL;
2529         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2530                 return -EINVAL;
2531         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2532                 return -EINVAL;
2533         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2534                 return -EINVAL;
2535
2536         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2537
2538         freq_range->start_freq_khz =
2539                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2540         freq_range->end_freq_khz =
2541                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2542         freq_range->max_bandwidth_khz =
2543                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2544
2545         power_rule->max_eirp =
2546                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2547
2548         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2549                 power_rule->max_antenna_gain =
2550                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2551
2552         return 0;
2553 }
2554
2555 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2556 {
2557         int r;
2558         char *data = NULL;
2559
2560         /*
2561          * You should only get this when cfg80211 hasn't yet initialized
2562          * completely when built-in to the kernel right between the time
2563          * window between nl80211_init() and regulatory_init(), if that is
2564          * even possible.
2565          */
2566         mutex_lock(&cfg80211_mutex);
2567         if (unlikely(!cfg80211_regdomain)) {
2568                 mutex_unlock(&cfg80211_mutex);
2569                 return -EINPROGRESS;
2570         }
2571         mutex_unlock(&cfg80211_mutex);
2572
2573         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2574                 return -EINVAL;
2575
2576         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2577
2578 #ifdef CONFIG_WIRELESS_OLD_REGULATORY
2579         /* We ignore world regdom requests with the old regdom setup */
2580         if (is_world_regdom(data))
2581                 return -EINVAL;
2582 #endif
2583
2584         r = regulatory_hint_user(data);
2585
2586         return r;
2587 }
2588
2589 static int nl80211_get_mesh_params(struct sk_buff *skb,
2590         struct genl_info *info)
2591 {
2592         struct cfg80211_registered_device *rdev;
2593         struct mesh_config cur_params;
2594         int err;
2595         struct net_device *dev;
2596         void *hdr;
2597         struct nlattr *pinfoattr;
2598         struct sk_buff *msg;
2599
2600         rtnl_lock();
2601
2602         /* Look up our device */
2603         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2604         if (err)
2605                 goto out_rtnl;
2606
2607         if (!rdev->ops->get_mesh_params) {
2608                 err = -EOPNOTSUPP;
2609                 goto out;
2610         }
2611
2612         /* Get the mesh params */
2613         err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
2614         if (err)
2615                 goto out;
2616
2617         /* Draw up a netlink message to send back */
2618         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2619         if (!msg) {
2620                 err = -ENOBUFS;
2621                 goto out;
2622         }
2623         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2624                              NL80211_CMD_GET_MESH_PARAMS);
2625         if (!hdr)
2626                 goto nla_put_failure;
2627         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2628         if (!pinfoattr)
2629                 goto nla_put_failure;
2630         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2631         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2632                         cur_params.dot11MeshRetryTimeout);
2633         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2634                         cur_params.dot11MeshConfirmTimeout);
2635         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2636                         cur_params.dot11MeshHoldingTimeout);
2637         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2638                         cur_params.dot11MeshMaxPeerLinks);
2639         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2640                         cur_params.dot11MeshMaxRetries);
2641         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2642                         cur_params.dot11MeshTTL);
2643         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2644                         cur_params.auto_open_plinks);
2645         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2646                         cur_params.dot11MeshHWMPmaxPREQretries);
2647         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2648                         cur_params.path_refresh_time);
2649         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2650                         cur_params.min_discovery_timeout);
2651         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2652                         cur_params.dot11MeshHWMPactivePathTimeout);
2653         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2654                         cur_params.dot11MeshHWMPpreqMinInterval);
2655         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2656                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2657         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2658                         cur_params.dot11MeshHWMPRootMode);
2659         nla_nest_end(msg, pinfoattr);
2660         genlmsg_end(msg, hdr);
2661         err = genlmsg_reply(msg, info);
2662         goto out;
2663
2664  nla_put_failure:
2665         genlmsg_cancel(msg, hdr);
2666         err = -EMSGSIZE;
2667  out:
2668         /* Cleanup */
2669         cfg80211_unlock_rdev(rdev);
2670         dev_put(dev);
2671  out_rtnl:
2672         rtnl_unlock();
2673
2674         return err;
2675 }
2676
2677 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2678 do {\
2679         if (table[attr_num]) {\
2680                 cfg.param = nla_fn(table[attr_num]); \
2681                 mask |= (1 << (attr_num - 1)); \
2682         } \
2683 } while (0);\
2684
2685 static struct nla_policy
2686 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2687         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2688         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2689         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2690         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2691         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2692         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2693         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2694
2695         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2696         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2697         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2698         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2699         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2700         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2701 };
2702
2703 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2704 {
2705         int err;
2706         u32 mask;
2707         struct cfg80211_registered_device *rdev;
2708         struct net_device *dev;
2709         struct mesh_config cfg;
2710         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2711         struct nlattr *parent_attr;
2712
2713         parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2714         if (!parent_attr)
2715                 return -EINVAL;
2716         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2717                         parent_attr, nl80211_meshconf_params_policy))
2718                 return -EINVAL;
2719
2720         rtnl_lock();
2721
2722         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2723         if (err)
2724                 goto out_rtnl;
2725
2726         if (!rdev->ops->set_mesh_params) {
2727                 err = -EOPNOTSUPP;
2728                 goto out;
2729         }
2730
2731         /* This makes sure that there aren't more than 32 mesh config
2732          * parameters (otherwise our bitfield scheme would not work.) */
2733         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2734
2735         /* Fill in the params struct */
2736         mask = 0;
2737         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2738                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2739         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2740                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2741         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2742                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2743         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2744                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2745         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2746                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2747         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2748                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
2749         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2750                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2751         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2752                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2753                         nla_get_u8);
2754         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2755                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2756         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2757                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2758                         nla_get_u16);
2759         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2760                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2761                         nla_get_u32);
2762         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2763                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2764                         nla_get_u16);
2765         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2766                         dot11MeshHWMPnetDiameterTraversalTime,
2767                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2768                         nla_get_u16);
2769         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2770                         dot11MeshHWMPRootMode, mask,
2771                         NL80211_MESHCONF_HWMP_ROOTMODE,
2772                         nla_get_u8);
2773
2774         /* Apply changes */
2775         err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
2776
2777  out:
2778         /* cleanup */
2779         cfg80211_unlock_rdev(rdev);
2780         dev_put(dev);
2781  out_rtnl:
2782         rtnl_unlock();
2783
2784         return err;
2785 }
2786
2787 #undef FILL_IN_MESH_PARAM_IF_SET
2788
2789 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2790 {
2791         struct sk_buff *msg;
2792         void *hdr = NULL;
2793         struct nlattr *nl_reg_rules;
2794         unsigned int i;
2795         int err = -EINVAL;
2796
2797         mutex_lock(&cfg80211_mutex);
2798
2799         if (!cfg80211_regdomain)
2800                 goto out;
2801
2802         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2803         if (!msg) {
2804                 err = -ENOBUFS;
2805                 goto out;
2806         }
2807
2808         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2809                              NL80211_CMD_GET_REG);
2810         if (!hdr)
2811                 goto nla_put_failure;
2812
2813         NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2814                 cfg80211_regdomain->alpha2);
2815
2816         nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2817         if (!nl_reg_rules)
2818                 goto nla_put_failure;
2819
2820         for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2821                 struct nlattr *nl_reg_rule;
2822                 const struct ieee80211_reg_rule *reg_rule;
2823                 const struct ieee80211_freq_range *freq_range;
2824                 const struct ieee80211_power_rule *power_rule;
2825
2826                 reg_rule = &cfg80211_regdomain->reg_rules[i];
2827                 freq_range = &reg_rule->freq_range;
2828                 power_rule = &reg_rule->power_rule;
2829
2830                 nl_reg_rule = nla_nest_start(msg, i);
2831                 if (!nl_reg_rule)
2832                         goto nla_put_failure;
2833
2834                 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2835                         reg_rule->flags);
2836                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2837                         freq_range->start_freq_khz);
2838                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2839                         freq_range->end_freq_khz);
2840                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2841                         freq_range->max_bandwidth_khz);
2842                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2843                         power_rule->max_antenna_gain);
2844                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2845                         power_rule->max_eirp);
2846
2847                 nla_nest_end(msg, nl_reg_rule);
2848         }
2849
2850         nla_nest_end(msg, nl_reg_rules);
2851
2852         genlmsg_end(msg, hdr);
2853         err = genlmsg_reply(msg, info);
2854         goto out;
2855
2856 nla_put_failure:
2857         genlmsg_cancel(msg, hdr);
2858         err = -EMSGSIZE;
2859 out:
2860         mutex_unlock(&cfg80211_mutex);
2861         return err;
2862 }
2863
2864 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2865 {
2866         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2867         struct nlattr *nl_reg_rule;
2868         char *alpha2 = NULL;
2869         int rem_reg_rules = 0, r = 0;
2870         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2871         struct ieee80211_regdomain *rd = NULL;
2872
2873         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2874                 return -EINVAL;
2875
2876         if (!info->attrs[NL80211_ATTR_REG_RULES])
2877                 return -EINVAL;
2878
2879         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2880
2881         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2882                         rem_reg_rules) {
2883                 num_rules++;
2884                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2885                         return -EINVAL;
2886         }
2887
2888         mutex_lock(&cfg80211_mutex);
2889
2890         if (!reg_is_valid_request(alpha2)) {
2891                 r = -EINVAL;
2892                 goto bad_reg;
2893         }
2894
2895         size_of_regd = sizeof(struct ieee80211_regdomain) +
2896                 (num_rules * sizeof(struct ieee80211_reg_rule));
2897
2898         rd = kzalloc(size_of_regd, GFP_KERNEL);
2899         if (!rd) {
2900                 r = -ENOMEM;
2901                 goto bad_reg;
2902         }
2903
2904         rd->n_reg_rules = num_rules;
2905         rd->alpha2[0] = alpha2[0];
2906         rd->alpha2[1] = alpha2[1];
2907
2908         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2909                         rem_reg_rules) {
2910                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2911                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2912                         reg_rule_policy);
2913                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2914                 if (r)
2915                         goto bad_reg;
2916
2917                 rule_idx++;
2918
2919                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2920                         r = -EINVAL;
2921                         goto bad_reg;
2922                 }
2923         }
2924
2925         BUG_ON(rule_idx != num_rules);
2926
2927         r = set_regdom(rd);
2928
2929         mutex_unlock(&cfg80211_mutex);
2930
2931         return r;
2932
2933  bad_reg:
2934         mutex_unlock(&cfg80211_mutex);
2935         kfree(rd);
2936         return r;
2937 }
2938
2939 static int validate_scan_freqs(struct nlattr *freqs)
2940 {
2941         struct nlattr *attr1, *attr2;
2942         int n_channels = 0, tmp1, tmp2;
2943
2944         nla_for_each_nested(attr1, freqs, tmp1) {
2945                 n_channels++;
2946                 /*
2947                  * Some hardware has a limited channel list for
2948                  * scanning, and it is pretty much nonsensical
2949                  * to scan for a channel twice, so disallow that
2950                  * and don't require drivers to check that the
2951                  * channel list they get isn't longer than what
2952                  * they can scan, as long as they can scan all
2953                  * the channels they registered at once.
2954                  */
2955                 nla_for_each_nested(attr2, freqs, tmp2)
2956                         if (attr1 != attr2 &&
2957                             nla_get_u32(attr1) == nla_get_u32(attr2))
2958                                 return 0;
2959         }
2960
2961         return n_channels;
2962 }
2963
2964 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2965 {
2966         struct cfg80211_registered_device *rdev;
2967         struct net_device *dev;
2968         struct cfg80211_scan_request *request;
2969         struct cfg80211_ssid *ssid;
2970         struct ieee80211_channel *channel;
2971         struct nlattr *attr;
2972         struct wiphy *wiphy;
2973         int err, tmp, n_ssids = 0, n_channels, i;
2974         enum ieee80211_band band;
2975         size_t ie_len;
2976
2977         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2978                 return -EINVAL;
2979
2980         rtnl_lock();
2981
2982         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2983         if (err)
2984                 goto out_rtnl;
2985
2986         wiphy = &rdev->wiphy;
2987
2988         if (!rdev->ops->scan) {
2989                 err = -EOPNOTSUPP;
2990                 goto out;
2991         }
2992
2993         if (!netif_running(dev)) {
2994                 err = -ENETDOWN;
2995                 goto out;
2996         }
2997
2998         if (rdev->scan_req) {
2999                 err = -EBUSY;
3000                 goto out;
3001         }
3002
3003         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3004                 n_channels = validate_scan_freqs(
3005                                 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3006                 if (!n_channels) {
3007                         err = -EINVAL;
3008                         goto out;
3009                 }
3010         } else {
3011                 n_channels = 0;
3012
3013                 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3014                         if (wiphy->bands[band])
3015                                 n_channels += wiphy->bands[band]->n_channels;
3016         }
3017
3018         if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3019                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3020                         n_ssids++;
3021
3022         if (n_ssids > wiphy->max_scan_ssids) {
3023                 err = -EINVAL;
3024                 goto out;
3025         }
3026
3027         if (info->attrs[NL80211_ATTR_IE])
3028                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3029         else
3030                 ie_len = 0;
3031
3032         if (ie_len > wiphy->max_scan_ie_len) {
3033                 err = -EINVAL;
3034                 goto out;
3035         }
3036
3037         request = kzalloc(sizeof(*request)
3038                         + sizeof(*ssid) * n_ssids
3039                         + sizeof(channel) * n_channels
3040                         + ie_len, GFP_KERNEL);
3041         if (!request) {
3042                 err = -ENOMEM;
3043                 goto out;
3044         }
3045
3046         if (n_ssids)
3047                 request->ssids = (void *)&request->channels[n_channels];
3048         request->n_ssids = n_ssids;
3049         if (ie_len) {
3050                 if (request->ssids)
3051                         request->ie = (void *)(request->ssids + n_ssids);
3052                 else
3053                         request->ie = (void *)(request->channels + n_channels);
3054         }
3055
3056         i = 0;
3057         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3058                 /* user specified, bail out if channel not found */
3059                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3060                         struct ieee80211_channel *chan;
3061
3062                         chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3063
3064                         if (!chan) {
3065                                 err = -EINVAL;
3066                                 goto out_free;
3067                         }
3068
3069                         /* ignore disabled channels */
3070                         if (chan->flags & IEEE80211_CHAN_DISABLED)
3071                                 continue;
3072
3073                         request->channels[i] = chan;
3074                         i++;
3075                 }
3076         } else {
3077                 /* all channels */
3078                 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3079                         int j;
3080                         if (!wiphy->bands[band])
3081                                 continue;
3082                         for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3083                                 struct ieee80211_channel *chan;
3084
3085                                 chan = &wiphy->bands[band]->channels[j];
3086
3087                                 if (chan->flags & IEEE80211_CHAN_DISABLED)
3088                                         continue;
3089
3090                                 request->channels[i] = chan;
3091                                 i++;
3092                         }
3093                 }
3094         }
3095
3096         if (!i) {
3097                 err = -EINVAL;
3098                 goto out_free;
3099         }
3100
3101         request->n_channels = i;
3102
3103         i = 0;
3104         if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3105                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3106                         if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3107                                 err = -EINVAL;
3108                                 goto out_free;
3109                         }
3110                         memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3111                         request->ssids[i].ssid_len = nla_len(attr);
3112                         i++;
3113                 }
3114         }
3115
3116         if (info->attrs[NL80211_ATTR_IE]) {
3117                 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3118                 memcpy((void *)request->ie,
3119                        nla_data(info->attrs[NL80211_ATTR_IE]),
3120                        request->ie_len);
3121         }
3122
3123         request->dev = dev;
3124         request->wiphy = &rdev->wiphy;
3125
3126         rdev->scan_req = request;
3127         err = rdev->ops->scan(&rdev->wiphy, dev, request);
3128
3129         if (!err) {
3130                 nl80211_send_scan_start(rdev, dev);
3131                 dev_hold(dev);
3132         }
3133
3134  out_free:
3135         if (err) {
3136                 rdev->scan_req = NULL;
3137                 kfree(request);
3138         }
3139  out:
3140         cfg80211_unlock_rdev(rdev);
3141         dev_put(dev);
3142  out_rtnl:
3143         rtnl_unlock();
3144
3145         return err;
3146 }
3147
3148 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3149                             struct cfg80211_registered_device *rdev,
3150                             struct wireless_dev *wdev,
3151                             struct cfg80211_internal_bss *intbss)
3152 {
3153         struct cfg80211_bss *res = &intbss->pub;
3154         void *hdr;
3155         struct nlattr *bss;
3156         int i;
3157
3158         ASSERT_WDEV_LOCK(wdev);
3159
3160         hdr = nl80211hdr_put(msg, pid, seq, flags,
3161                              NL80211_CMD_NEW_SCAN_RESULTS);
3162         if (!hdr)
3163                 return -1;
3164
3165         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3166         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3167
3168         bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3169         if (!bss)
3170                 goto nla_put_failure;
3171         if (!is_zero_ether_addr(res->bssid))
3172                 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3173         if (res->information_elements && res->len_information_elements)
3174                 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3175                         res->len_information_elements,
3176                         res->information_elements);
3177         if (res->tsf)
3178                 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3179         if (res->beacon_interval)
3180                 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3181         NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3182         NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3183         NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3184                 jiffies_to_msecs(jiffies - intbss->ts));
3185
3186         switch (rdev->wiphy.signal_type) {
3187         case CFG80211_SIGNAL_TYPE_MBM:
3188                 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3189                 break;
3190         case CFG80211_SIGNAL_TYPE_UNSPEC:
3191                 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3192                 break;
3193         default:
3194                 break;
3195         }
3196
3197         switch (wdev->iftype) {
3198         case NL80211_IFTYPE_STATION:
3199                 if (intbss == wdev->current_bss)
3200                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3201                                     NL80211_BSS_STATUS_ASSOCIATED);
3202                 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3203                         if (intbss != wdev->auth_bsses[i])
3204                                 continue;
3205                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3206                                     NL80211_BSS_STATUS_AUTHENTICATED);
3207                         break;
3208                 }
3209                 break;
3210         case NL80211_IFTYPE_ADHOC:
3211                 if (intbss == wdev->current_bss)
3212                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3213                                     NL80211_BSS_STATUS_IBSS_JOINED);
3214                 break;
3215         default:
3216                 break;
3217         }
3218
3219         nla_nest_end(msg, bss);
3220
3221         return genlmsg_end(msg, hdr);
3222
3223  nla_put_failure:
3224         genlmsg_cancel(msg, hdr);
3225         return -EMSGSIZE;
3226 }
3227
3228 static int nl80211_dump_scan(struct sk_buff *skb,
3229                              struct netlink_callback *cb)
3230 {
3231         struct cfg80211_registered_device *rdev;
3232         struct net_device *dev;
3233         struct cfg80211_internal_bss *scan;
3234         struct wireless_dev *wdev;
3235         int ifidx = cb->args[0];
3236         int start = cb->args[1], idx = 0;
3237         int err;
3238
3239         if (!ifidx)
3240                 ifidx = nl80211_get_ifidx(cb);
3241         if (ifidx < 0)
3242                 return ifidx;
3243         cb->args[0] = ifidx;
3244
3245         dev = dev_get_by_index(sock_net(skb->sk), ifidx);
3246         if (!dev)
3247                 return -ENODEV;
3248
3249         rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3250         if (IS_ERR(rdev)) {
3251                 err = PTR_ERR(rdev);
3252                 goto out_put_netdev;
3253         }
3254
3255         wdev = dev->ieee80211_ptr;
3256
3257         wdev_lock(wdev);
3258         spin_lock_bh(&rdev->bss_lock);
3259         cfg80211_bss_expire(rdev);
3260
3261         list_for_each_entry(scan, &rdev->bss_list, list) {
3262                 if (++idx <= start)
3263                         continue;
3264                 if (nl80211_send_bss(skb,
3265                                 NETLINK_CB(cb->skb).pid,
3266                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3267                                 rdev, wdev, scan) < 0) {
3268                         idx--;
3269                         goto out;
3270                 }
3271         }
3272
3273  out:
3274         spin_unlock_bh(&rdev->bss_lock);
3275         wdev_unlock(wdev);
3276
3277         cb->args[1] = idx;
3278         err = skb->len;
3279         cfg80211_unlock_rdev(rdev);
3280  out_put_netdev:
3281         dev_put(dev);
3282
3283         return err;
3284 }
3285
3286 static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3287                                 int flags, struct net_device *dev,
3288                                 struct survey_info *survey)
3289 {
3290         void *hdr;
3291         struct nlattr *infoattr;
3292
3293         /* Survey without a channel doesn't make sense */
3294         if (!survey->channel)
3295                 return -EINVAL;
3296
3297         hdr = nl80211hdr_put(msg, pid, seq, flags,
3298                              NL80211_CMD_NEW_SURVEY_RESULTS);
3299         if (!hdr)
3300                 return -ENOMEM;
3301
3302         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3303
3304         infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3305         if (!infoattr)
3306                 goto nla_put_failure;
3307
3308         NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3309                     survey->channel->center_freq);
3310         if (survey->filled & SURVEY_INFO_NOISE_DBM)
3311                 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3312                             survey->noise);
3313
3314         nla_nest_end(msg, infoattr);
3315
3316         return genlmsg_end(msg, hdr);
3317
3318  nla_put_failure:
3319         genlmsg_cancel(msg, hdr);
3320         return -EMSGSIZE;
3321 }
3322
3323 static int nl80211_dump_survey(struct sk_buff *skb,
3324                         struct netlink_callback *cb)
3325 {
3326         struct survey_info survey;
3327         struct cfg80211_registered_device *dev;
3328         struct net_device *netdev;
3329         int ifidx = cb->args[0];
3330         int survey_idx = cb->args[1];
3331         int res;
3332
3333         if (!ifidx)
3334                 ifidx = nl80211_get_ifidx(cb);
3335         if (ifidx < 0)
3336                 return ifidx;
3337         cb->args[0] = ifidx;
3338
3339         rtnl_lock();
3340
3341         netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3342         if (!netdev) {
3343                 res = -ENODEV;
3344                 goto out_rtnl;
3345         }
3346
3347         dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3348         if (IS_ERR(dev)) {
3349                 res = PTR_ERR(dev);
3350                 goto out_rtnl;
3351         }
3352
3353         if (!dev->ops->dump_survey) {
3354                 res = -EOPNOTSUPP;
3355                 goto out_err;
3356         }
3357
3358         while (1) {
3359                 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3360                                             &survey);
3361                 if (res == -ENOENT)
3362                         break;
3363                 if (res)
3364                         goto out_err;
3365
3366                 if (nl80211_send_survey(skb,
3367                                 NETLINK_CB(cb->skb).pid,
3368                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3369                                 netdev,
3370                                 &survey) < 0)
3371                         goto out;
3372                 survey_idx++;
3373         }
3374
3375  out:
3376         cb->args[1] = survey_idx;
3377         res = skb->len;
3378  out_err:
3379         cfg80211_unlock_rdev(dev);
3380  out_rtnl:
3381         rtnl_unlock();
3382
3383         return res;
3384 }
3385
3386 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3387 {
3388         return auth_type <= NL80211_AUTHTYPE_MAX;
3389 }
3390
3391 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3392 {
3393         return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3394                                   NL80211_WPA_VERSION_2));
3395 }
3396
3397 static bool nl80211_valid_akm_suite(u32 akm)
3398 {
3399         return akm == WLAN_AKM_SUITE_8021X ||
3400                 akm == WLAN_AKM_SUITE_PSK;
3401 }
3402
3403 static bool nl80211_valid_cipher_suite(u32 cipher)
3404 {
3405         return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3406                 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3407                 cipher == WLAN_CIPHER_SUITE_TKIP ||
3408                 cipher == WLAN_CIPHER_SUITE_CCMP ||
3409                 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3410 }
3411
3412
3413 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3414 {
3415         struct cfg80211_registered_device *rdev;
3416         struct net_device *dev;
3417         struct ieee80211_channel *chan;
3418         const u8 *bssid, *ssid, *ie = NULL;
3419         int err, ssid_len, ie_len = 0;
3420         enum nl80211_auth_type auth_type;
3421         struct key_parse key;
3422
3423         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3424                 return -EINVAL;
3425
3426         if (!info->attrs[NL80211_ATTR_MAC])
3427                 return -EINVAL;
3428
3429         if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3430                 return -EINVAL;
3431
3432         if (!info->attrs[NL80211_ATTR_SSID])
3433                 return -EINVAL;
3434
3435         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3436                 return -EINVAL;
3437
3438         err = nl80211_parse_key(info, &key);
3439         if (err)
3440                 return err;
3441
3442         if (key.idx >= 0) {
3443                 if (!key.p.key || !key.p.key_len)
3444                         return -EINVAL;
3445                 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3446                      key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3447                     (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3448                      key.p.key_len != WLAN_KEY_LEN_WEP104))
3449                         return -EINVAL;
3450                 if (key.idx > 4)
3451                         return -EINVAL;
3452         } else {
3453                 key.p.key_len = 0;
3454                 key.p.key = NULL;
3455         }
3456
3457         rtnl_lock();
3458
3459         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3460         if (err)
3461                 goto unlock_rtnl;
3462
3463         if (!rdev->ops->auth) {
3464                 err = -EOPNOTSUPP;
3465                 goto out;
3466         }
3467
3468         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3469                 err = -EOPNOTSUPP;
3470                 goto out;
3471         }
3472
3473         if (!netif_running(dev)) {
3474                 err = -ENETDOWN;
3475                 goto out;
3476         }
3477
3478         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3479         chan = ieee80211_get_channel(&rdev->wiphy,
3480                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3481         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3482                 err = -EINVAL;
3483                 goto out;
3484         }
3485
3486         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3487         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3488
3489         if (info->attrs[NL80211_ATTR_IE]) {
3490                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3491                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3492         }
3493
3494         auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3495         if (!nl80211_valid_auth_type(auth_type)) {
3496                 err = -EINVAL;
3497                 goto out;
3498         }
3499
3500         err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3501                                  ssid, ssid_len, ie, ie_len,
3502                                  key.p.key, key.p.key_len, key.idx);
3503
3504 out:
3505         cfg80211_unlock_rdev(rdev);
3506         dev_put(dev);
3507 unlock_rtnl:
3508         rtnl_unlock();
3509         return err;
3510 }
3511
3512 static int nl80211_crypto_settings(struct genl_info *info,
3513                                    struct cfg80211_crypto_settings *settings,
3514                                    int cipher_limit)
3515 {
3516         memset(settings, 0, sizeof(*settings));
3517
3518         settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3519
3520         if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3521                 void *data;
3522                 int len, i;
3523
3524                 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3525                 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3526                 settings->n_ciphers_pairwise = len / sizeof(u32);
3527
3528                 if (len % sizeof(u32))
3529                         return -EINVAL;
3530
3531                 if (settings->n_ciphers_pairwise > cipher_limit)
3532                         return -EINVAL;
3533
3534                 memcpy(settings->ciphers_pairwise, data, len);
3535
3536                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3537                         if (!nl80211_valid_cipher_suite(
3538                                         settings->ciphers_pairwise[i]))
3539                                 return -EINVAL;
3540         }
3541
3542         if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3543                 settings->cipher_group =
3544                         nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3545                 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3546                         return -EINVAL;
3547         }
3548
3549         if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3550                 settings->wpa_versions =
3551                         nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3552                 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3553                         return -EINVAL;
3554         }
3555
3556         if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3557                 void *data;
3558                 int len, i;
3559
3560                 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3561                 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3562                 settings->n_akm_suites = len / sizeof(u32);
3563
3564                 if (len % sizeof(u32))
3565                         return -EINVAL;
3566
3567                 memcpy(settings->akm_suites, data, len);
3568
3569                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3570                         if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3571                                 return -EINVAL;
3572         }
3573
3574         return 0;
3575 }
3576
3577 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3578 {
3579         struct cfg80211_registered_device *rdev;
3580         struct net_device *dev;
3581         struct cfg80211_crypto_settings crypto;
3582         struct ieee80211_channel *chan, *fixedchan;
3583         const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
3584         int err, ssid_len, ie_len = 0;
3585         bool use_mfp = false;
3586
3587         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3588                 return -EINVAL;
3589
3590         if (!info->attrs[NL80211_ATTR_MAC] ||
3591             !info->attrs[NL80211_ATTR_SSID] ||
3592             !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3593                 return -EINVAL;
3594
3595         rtnl_lock();
3596
3597         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3598         if (err)
3599                 goto unlock_rtnl;
3600
3601         if (!rdev->ops->assoc) {
3602                 err = -EOPNOTSUPP;
3603                 goto out;
3604         }
3605
3606         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3607                 err = -EOPNOTSUPP;
3608                 goto out;
3609         }
3610
3611         if (!netif_running(dev)) {
3612                 err = -ENETDOWN;
3613                 goto out;
3614         }
3615
3616         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3617
3618         chan = ieee80211_get_channel(&rdev->wiphy,
3619                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3620         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3621                 err = -EINVAL;
3622                 goto out;
3623         }
3624
3625         mutex_lock(&rdev->devlist_mtx);
3626         fixedchan = rdev_fixed_channel(rdev, NULL);
3627         if (fixedchan && chan != fixedchan) {
3628                 err = -EBUSY;
3629                 mutex_unlock(&rdev->devlist_mtx);
3630                 goto out;
3631         }
3632         mutex_unlock(&rdev->devlist_mtx);
3633
3634         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3635         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3636
3637         if (info->attrs[NL80211_ATTR_IE]) {
3638                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3639                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3640         }
3641
3642         if (info->attrs[NL80211_ATTR_USE_MFP]) {
3643                 enum nl80211_mfp mfp =
3644                         nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3645                 if (mfp == NL80211_MFP_REQUIRED)
3646                         use_mfp = true;
3647                 else if (mfp != NL80211_MFP_NO) {
3648                         err = -EINVAL;
3649                         goto out;
3650                 }
3651         }
3652
3653         if (info->attrs[NL80211_ATTR_PREV_BSSID])
3654                 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3655
3656         err = nl80211_crypto_settings(info, &crypto, 1);
3657         if (!err)
3658                 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3659                                           ssid, ssid_len, ie, ie_len, use_mfp,
3660                                           &crypto);
3661
3662 out:
3663         cfg80211_unlock_rdev(rdev);
3664         dev_put(dev);
3665 unlock_rtnl:
3666         rtnl_unlock();
3667         return err;
3668 }
3669
3670 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3671 {
3672         struct cfg80211_registered_device *rdev;
3673         struct net_device *dev;
3674         const u8 *ie = NULL, *bssid;
3675         int err, ie_len = 0;
3676         u16 reason_code;
3677
3678         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3679                 return -EINVAL;
3680
3681         if (!info->attrs[NL80211_ATTR_MAC])
3682                 return -EINVAL;
3683
3684         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3685                 return -EINVAL;
3686
3687         rtnl_lock();
3688
3689         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3690         if (err)
3691                 goto unlock_rtnl;
3692
3693         if (!rdev->ops->deauth) {
3694                 err = -EOPNOTSUPP;
3695                 goto out;
3696         }
3697
3698         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3699                 err = -EOPNOTSUPP;
3700                 goto out;
3701         }
3702
3703         if (!netif_running(dev)) {
3704                 err = -ENETDOWN;
3705                 goto out;
3706         }
3707
3708         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3709
3710         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3711         if (reason_code == 0) {
3712                 /* Reason Code 0 is reserved */
3713                 err = -EINVAL;
3714                 goto out;
3715         }
3716
3717         if (info->attrs[NL80211_ATTR_IE]) {
3718                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3719                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3720         }
3721
3722         err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
3723
3724 out:
3725         cfg80211_unlock_rdev(rdev);
3726         dev_put(dev);
3727 unlock_rtnl:
3728         rtnl_unlock();
3729         return err;
3730 }
3731
3732 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3733 {
3734         struct cfg80211_registered_device *rdev;
3735         struct net_device *dev;
3736         const u8 *ie = NULL, *bssid;
3737         int err, ie_len = 0;
3738         u16 reason_code;
3739
3740         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3741                 return -EINVAL;
3742
3743         if (!info->attrs[NL80211_ATTR_MAC])
3744                 return -EINVAL;
3745
3746         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3747                 return -EINVAL;
3748
3749         rtnl_lock();
3750
3751         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3752         if (err)
3753                 goto unlock_rtnl;
3754
3755         if (!rdev->ops->disassoc) {
3756                 err = -EOPNOTSUPP;
3757                 goto out;
3758         }
3759
3760         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3761                 err = -EOPNOTSUPP;
3762                 goto out;
3763         }
3764
3765         if (!netif_running(dev)) {
3766                 err = -ENETDOWN;
3767                 goto out;
3768         }
3769
3770         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3771
3772         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3773         if (reason_code == 0) {
3774                 /* Reason Code 0 is reserved */
3775                 err = -EINVAL;
3776                 goto out;
3777         }
3778
3779         if (info->attrs[NL80211_ATTR_IE]) {
3780                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3781                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3782         }
3783
3784         err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
3785
3786 out:
3787         cfg80211_unlock_rdev(rdev);
3788         dev_put(dev);
3789 unlock_rtnl:
3790         rtnl_unlock();
3791         return err;
3792 }
3793
3794 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3795 {
3796         struct cfg80211_registered_device *rdev;
3797         struct net_device *dev;
3798         struct cfg80211_ibss_params ibss;
3799         struct wiphy *wiphy;
3800         struct cfg80211_cached_keys *connkeys = NULL;
3801         int err;
3802
3803         memset(&ibss, 0, sizeof(ibss));
3804
3805         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3806                 return -EINVAL;
3807
3808         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3809             !info->attrs[NL80211_ATTR_SSID] ||
3810             !nla_len(info->attrs[NL80211_ATTR_SSID]))
3811                 return -EINVAL;
3812
3813         ibss.beacon_interval = 100;
3814
3815         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3816                 ibss.beacon_interval =
3817                         nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3818                 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3819                         return -EINVAL;
3820         }
3821
3822         rtnl_lock();
3823
3824         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3825         if (err)
3826                 goto unlock_rtnl;
3827
3828         if (!rdev->ops->join_ibss) {
3829                 err = -EOPNOTSUPP;
3830                 goto out;
3831         }
3832
3833         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3834                 err = -EOPNOTSUPP;
3835                 goto out;
3836         }
3837
3838         if (!netif_running(dev)) {
3839                 err = -ENETDOWN;
3840                 goto out;
3841         }
3842
3843         wiphy = &rdev->wiphy;
3844
3845         if (info->attrs[NL80211_ATTR_MAC])
3846                 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3847         ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3848         ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3849
3850         if (info->attrs[NL80211_ATTR_IE]) {
3851                 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3852                 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3853         }
3854
3855         ibss.channel = ieee80211_get_channel(wiphy,
3856                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3857         if (!ibss.channel ||
3858             ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3859             ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3860                 err = -EINVAL;
3861                 goto out;
3862         }
3863
3864         ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3865         ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3866
3867         if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3868                 connkeys = nl80211_parse_connkeys(rdev,
3869                                         info->attrs[NL80211_ATTR_KEYS]);
3870                 if (IS_ERR(connkeys)) {
3871                         err = PTR_ERR(connkeys);
3872                         connkeys = NULL;
3873                         goto out;
3874                 }
3875         }
3876
3877         err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
3878
3879 out:
3880         cfg80211_unlock_rdev(rdev);
3881         dev_put(dev);
3882 unlock_rtnl:
3883         if (err)
3884                 kfree(connkeys);
3885         rtnl_unlock();
3886         return err;
3887 }
3888
3889 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3890 {
3891         struct cfg80211_registered_device *rdev;
3892         struct net_device *dev;
3893         int err;
3894
3895         rtnl_lock();
3896
3897         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3898         if (err)
3899                 goto unlock_rtnl;
3900
3901         if (!rdev->ops->leave_ibss) {
3902                 err = -EOPNOTSUPP;
3903                 goto out;
3904         }
3905
3906         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3907                 err = -EOPNOTSUPP;
3908                 goto out;
3909         }
3910
3911         if (!netif_running(dev)) {
3912                 err = -ENETDOWN;
3913                 goto out;
3914         }
3915
3916         err = cfg80211_leave_ibss(rdev, dev, false);
3917
3918 out:
3919         cfg80211_unlock_rdev(rdev);
3920         dev_put(dev);
3921 unlock_rtnl:
3922         rtnl_unlock();
3923         return err;
3924 }
3925
3926 #ifdef CONFIG_NL80211_TESTMODE
3927 static struct genl_multicast_group nl80211_testmode_mcgrp = {
3928         .name = "testmode",
3929 };
3930
3931 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3932 {
3933         struct cfg80211_registered_device *rdev;
3934         int err;
3935
3936         if (!info->attrs[NL80211_ATTR_TESTDATA])
3937                 return -EINVAL;
3938
3939         rtnl_lock();
3940
3941         rdev = cfg80211_get_dev_from_info(info);
3942         if (IS_ERR(rdev)) {
3943                 err = PTR_ERR(rdev);
3944                 goto unlock_rtnl;
3945         }
3946
3947         err = -EOPNOTSUPP;
3948         if (rdev->ops->testmode_cmd) {
3949                 rdev->testmode_info = info;
3950                 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3951                                 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3952                                 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3953                 rdev->testmode_info = NULL;
3954         }
3955
3956         cfg80211_unlock_rdev(rdev);
3957
3958  unlock_rtnl:
3959         rtnl_unlock();
3960         return err;
3961 }
3962
3963 static struct sk_buff *
3964 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3965                               int approxlen, u32 pid, u32 seq, gfp_t gfp)
3966 {
3967         struct sk_buff *skb;
3968         void *hdr;
3969         struct nlattr *data;
3970
3971         skb = nlmsg_new(approxlen + 100, gfp);
3972         if (!skb)
3973                 return NULL;
3974
3975         hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3976         if (!hdr) {
3977                 kfree_skb(skb);
3978                 return NULL;
3979         }
3980
3981         NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3982         data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3983
3984         ((void **)skb->cb)[0] = rdev;
3985         ((void **)skb->cb)[1] = hdr;
3986         ((void **)skb->cb)[2] = data;
3987
3988         return skb;
3989
3990  nla_put_failure:
3991         kfree_skb(skb);
3992         return NULL;
3993 }
3994
3995 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3996                                                   int approxlen)
3997 {
3998         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3999
4000         if (WARN_ON(!rdev->testmode_info))
4001                 return NULL;
4002
4003         return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4004                                 rdev->testmode_info->snd_pid,
4005                                 rdev->testmode_info->snd_seq,
4006                                 GFP_KERNEL);
4007 }
4008 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4009
4010 int cfg80211_testmode_reply(struct sk_buff *skb)
4011 {
4012         struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4013         void *hdr = ((void **)skb->cb)[1];
4014         struct nlattr *data = ((void **)skb->cb)[2];
4015
4016         if (WARN_ON(!rdev->testmode_info)) {
4017                 kfree_skb(skb);
4018                 return -EINVAL;
4019         }
4020
4021         nla_nest_end(skb, data);
4022         genlmsg_end(skb, hdr);
4023         return genlmsg_reply(skb, rdev->testmode_info);
4024 }
4025 EXPORT_SYMBOL(cfg80211_testmode_reply);
4026
4027 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4028                                                   int approxlen, gfp_t gfp)
4029 {
4030         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4031
4032         return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4033 }
4034 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4035
4036 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4037 {
4038         void *hdr = ((void **)skb->cb)[1];
4039         struct nlattr *data = ((void **)skb->cb)[2];
4040
4041         nla_nest_end(skb, data);
4042         genlmsg_end(skb, hdr);
4043         genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4044 }
4045 EXPORT_SYMBOL(cfg80211_testmode_event);
4046 #endif
4047
4048 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4049 {
4050         struct cfg80211_registered_device *rdev;
4051         struct net_device *dev;
4052         struct cfg80211_connect_params connect;
4053         struct wiphy *wiphy;
4054         struct cfg80211_cached_keys *connkeys = NULL;
4055         int err;
4056
4057         memset(&connect, 0, sizeof(connect));
4058
4059         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4060                 return -EINVAL;
4061
4062         if (!info->attrs[NL80211_ATTR_SSID] ||
4063             !nla_len(info->attrs[NL80211_ATTR_SSID]))
4064                 return -EINVAL;
4065
4066         if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4067                 connect.auth_type =
4068                         nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4069                 if (!nl80211_valid_auth_type(connect.auth_type))
4070                         return -EINVAL;
4071         } else
4072                 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4073
4074         connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4075
4076         err = nl80211_crypto_settings(info, &connect.crypto,
4077                                       NL80211_MAX_NR_CIPHER_SUITES);
4078         if (err)
4079                 return err;
4080         rtnl_lock();
4081
4082         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4083         if (err)
4084                 goto unlock_rtnl;
4085
4086         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4087                 err = -EOPNOTSUPP;
4088                 goto out;
4089         }
4090
4091         if (!netif_running(dev)) {
4092                 err = -ENETDOWN;
4093                 goto out;
4094         }
4095
4096         wiphy = &rdev->wiphy;
4097
4098         if (info->attrs[NL80211_ATTR_MAC])
4099                 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4100         connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4101         connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4102
4103         if (info->attrs[NL80211_ATTR_IE]) {
4104                 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4105                 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4106         }
4107
4108         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4109                 connect.channel =
4110                         ieee80211_get_channel(wiphy,
4111                             nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4112                 if (!connect.channel ||
4113                     connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4114                         err = -EINVAL;
4115                         goto out;
4116                 }
4117         }
4118
4119         if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4120                 connkeys = nl80211_parse_connkeys(rdev,
4121                                         info->attrs[NL80211_ATTR_KEYS]);
4122                 if (IS_ERR(connkeys)) {
4123                         err = PTR_ERR(connkeys);
4124                         connkeys = NULL;
4125                         goto out;
4126                 }
4127         }
4128
4129         err = cfg80211_connect(rdev, dev, &connect, connkeys);
4130
4131 out:
4132         cfg80211_unlock_rdev(rdev);
4133         dev_put(dev);
4134 unlock_rtnl:
4135         if (err)
4136                 kfree(connkeys);
4137         rtnl_unlock();
4138         return err;
4139 }
4140
4141 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4142 {
4143         struct cfg80211_registered_device *rdev;
4144         struct net_device *dev;
4145         int err;
4146         u16 reason;
4147
4148         if (!info->attrs[NL80211_ATTR_REASON_CODE])
4149                 reason = WLAN_REASON_DEAUTH_LEAVING;
4150         else
4151                 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4152
4153         if (reason == 0)
4154                 return -EINVAL;
4155
4156         rtnl_lock();
4157
4158         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4159         if (err)
4160                 goto unlock_rtnl;
4161
4162         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4163                 err = -EOPNOTSUPP;
4164                 goto out;
4165         }
4166
4167         if (!netif_running(dev)) {
4168                 err = -ENETDOWN;
4169                 goto out;
4170         }
4171
4172         err = cfg80211_disconnect(rdev, dev, reason, true);
4173
4174 out:
4175         cfg80211_unlock_rdev(rdev);
4176         dev_put(dev);
4177 unlock_rtnl:
4178         rtnl_unlock();
4179         return err;
4180 }
4181
4182 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4183 {
4184         struct cfg80211_registered_device *rdev;
4185         struct net *net;
4186         int err;
4187         u32 pid;
4188
4189         if (!info->attrs[NL80211_ATTR_PID])
4190                 return -EINVAL;
4191
4192         pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4193
4194         rtnl_lock();
4195
4196         rdev = cfg80211_get_dev_from_info(info);
4197         if (IS_ERR(rdev)) {
4198                 err = PTR_ERR(rdev);
4199                 goto out_rtnl;
4200         }
4201
4202         net = get_net_ns_by_pid(pid);
4203         if (IS_ERR(net)) {
4204                 err = PTR_ERR(net);
4205                 goto out;
4206         }
4207
4208         err = 0;
4209
4210         /* check if anything to do */
4211         if (net_eq(wiphy_net(&rdev->wiphy), net))
4212                 goto out_put_net;
4213
4214         err = cfg80211_switch_netns(rdev, net);
4215  out_put_net:
4216         put_net(net);
4217  out:
4218         cfg80211_unlock_rdev(rdev);
4219  out_rtnl:
4220         rtnl_unlock();
4221         return err;
4222 }
4223
4224 static struct genl_ops nl80211_ops[] = {
4225         {
4226                 .cmd = NL80211_CMD_GET_WIPHY,
4227                 .doit = nl80211_get_wiphy,
4228                 .dumpit = nl80211_dump_wiphy,
4229                 .policy = nl80211_policy,
4230                 /* can be retrieved by unprivileged users */
4231         },
4232         {
4233                 .cmd = NL80211_CMD_SET_WIPHY,
4234                 .doit = nl80211_set_wiphy,
4235                 .policy = nl80211_policy,
4236                 .flags = GENL_ADMIN_PERM,
4237         },
4238         {
4239                 .cmd = NL80211_CMD_GET_INTERFACE,
4240                 .doit = nl80211_get_interface,
4241                 .dumpit = nl80211_dump_interface,
4242                 .policy = nl80211_policy,
4243                 /* can be retrieved by unprivileged users */
4244         },
4245         {
4246                 .cmd = NL80211_CMD_SET_INTERFACE,
4247                 .doit = nl80211_set_interface,
4248                 .policy = nl80211_policy,
4249                 .flags = GENL_ADMIN_PERM,
4250         },
4251         {
4252                 .cmd = NL80211_CMD_NEW_INTERFACE,
4253                 .doit = nl80211_new_interface,
4254                 .policy = nl80211_policy,
4255                 .flags = GENL_ADMIN_PERM,
4256         },
4257         {
4258                 .cmd = NL80211_CMD_DEL_INTERFACE,
4259                 .doit = nl80211_del_interface,
4260                 .policy = nl80211_policy,
4261                 .flags = GENL_ADMIN_PERM,
4262         },
4263         {
4264                 .cmd = NL80211_CMD_GET_KEY,
4265                 .doit = nl80211_get_key,
4266                 .policy = nl80211_policy,
4267                 .flags = GENL_ADMIN_PERM,
4268         },
4269         {
4270                 .cmd = NL80211_CMD_SET_KEY,
4271                 .doit = nl80211_set_key,
4272                 .policy = nl80211_policy,
4273                 .flags = GENL_ADMIN_PERM,
4274         },
4275         {
4276                 .cmd = NL80211_CMD_NEW_KEY,
4277                 .doit = nl80211_new_key,
4278                 .policy = nl80211_policy,
4279                 .flags = GENL_ADMIN_PERM,
4280         },
4281         {
4282                 .cmd = NL80211_CMD_DEL_KEY,
4283                 .doit = nl80211_del_key,
4284                 .policy = nl80211_policy,
4285                 .flags = GENL_ADMIN_PERM,
4286         },
4287         {
4288                 .cmd = NL80211_CMD_SET_BEACON,
4289                 .policy = nl80211_policy,
4290                 .flags = GENL_ADMIN_PERM,
4291                 .doit = nl80211_addset_beacon,
4292         },
4293         {
4294                 .cmd = NL80211_CMD_NEW_BEACON,
4295                 .policy = nl80211_policy,
4296                 .flags = GENL_ADMIN_PERM,
4297                 .doit = nl80211_addset_beacon,
4298         },
4299         {
4300                 .cmd = NL80211_CMD_DEL_BEACON,
4301                 .policy = nl80211_policy,
4302                 .flags = GENL_ADMIN_PERM,
4303                 .doit = nl80211_del_beacon,
4304         },
4305         {
4306                 .cmd = NL80211_CMD_GET_STATION,
4307                 .doit = nl80211_get_station,
4308                 .dumpit = nl80211_dump_station,
4309                 .policy = nl80211_policy,
4310         },
4311         {
4312                 .cmd = NL80211_CMD_SET_STATION,
4313                 .doit = nl80211_set_station,
4314                 .policy = nl80211_policy,
4315                 .flags = GENL_ADMIN_PERM,
4316         },
4317         {
4318                 .cmd = NL80211_CMD_NEW_STATION,
4319                 .doit = nl80211_new_station,
4320                 .policy = nl80211_policy,
4321                 .flags = GENL_ADMIN_PERM,
4322         },
4323         {
4324                 .cmd = NL80211_CMD_DEL_STATION,
4325                 .doit = nl80211_del_station,
4326                 .policy = nl80211_policy,
4327                 .flags = GENL_ADMIN_PERM,
4328         },
4329         {
4330                 .cmd = NL80211_CMD_GET_MPATH,
4331                 .doit = nl80211_get_mpath,
4332                 .dumpit = nl80211_dump_mpath,
4333                 .policy = nl80211_policy,
4334                 .flags = GENL_ADMIN_PERM,
4335         },
4336         {
4337                 .cmd = NL80211_CMD_SET_MPATH,
4338                 .doit = nl80211_set_mpath,
4339                 .policy = nl80211_policy,
4340                 .flags = GENL_ADMIN_PERM,
4341         },
4342         {
4343                 .cmd = NL80211_CMD_NEW_MPATH,
4344                 .doit = nl80211_new_mpath,
4345                 .policy = nl80211_policy,
4346                 .flags = GENL_ADMIN_PERM,
4347         },
4348         {
4349                 .cmd = NL80211_CMD_DEL_MPATH,
4350                 .doit = nl80211_del_mpath,
4351                 .policy = nl80211_policy,
4352                 .flags = GENL_ADMIN_PERM,
4353         },
4354         {
4355                 .cmd = NL80211_CMD_SET_BSS,
4356                 .doit = nl80211_set_bss,
4357                 .policy = nl80211_policy,
4358                 .flags = GENL_ADMIN_PERM,
4359         },
4360         {
4361                 .cmd = NL80211_CMD_GET_REG,
4362                 .doit = nl80211_get_reg,
4363                 .policy = nl80211_policy,
4364                 /* can be retrieved by unprivileged users */
4365         },
4366         {
4367                 .cmd = NL80211_CMD_SET_REG,
4368                 .doit = nl80211_set_reg,
4369                 .policy = nl80211_policy,
4370                 .flags = GENL_ADMIN_PERM,
4371         },
4372         {
4373                 .cmd = NL80211_CMD_REQ_SET_REG,
4374                 .doit = nl80211_req_set_reg,
4375                 .policy = nl80211_policy,
4376                 .flags = GENL_ADMIN_PERM,
4377         },
4378         {
4379                 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4380                 .doit = nl80211_get_mesh_params,
4381                 .policy = nl80211_policy,
4382                 /* can be retrieved by unprivileged users */
4383         },
4384         {
4385                 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4386                 .doit = nl80211_set_mesh_params,
4387                 .policy = nl80211_policy,
4388                 .flags = GENL_ADMIN_PERM,
4389         },
4390         {
4391                 .cmd = NL80211_CMD_TRIGGER_SCAN,
4392                 .doit = nl80211_trigger_scan,
4393                 .policy = nl80211_policy,
4394                 .flags = GENL_ADMIN_PERM,
4395         },
4396         {
4397                 .cmd = NL80211_CMD_GET_SCAN,
4398                 .policy = nl80211_policy,
4399                 .dumpit = nl80211_dump_scan,
4400         },
4401         {
4402                 .cmd = NL80211_CMD_AUTHENTICATE,
4403                 .doit = nl80211_authenticate,
4404                 .policy = nl80211_policy,
4405                 .flags = GENL_ADMIN_PERM,
4406         },
4407         {
4408                 .cmd = NL80211_CMD_ASSOCIATE,
4409                 .doit = nl80211_associate,
4410                 .policy = nl80211_policy,
4411                 .flags = GENL_ADMIN_PERM,
4412         },
4413         {
4414                 .cmd = NL80211_CMD_DEAUTHENTICATE,
4415                 .doit = nl80211_deauthenticate,
4416                 .policy = nl80211_policy,
4417                 .flags = GENL_ADMIN_PERM,
4418         },
4419         {
4420                 .cmd = NL80211_CMD_DISASSOCIATE,
4421                 .doit = nl80211_disassociate,
4422                 .policy = nl80211_policy,
4423                 .flags = GENL_ADMIN_PERM,
4424         },
4425         {
4426                 .cmd = NL80211_CMD_JOIN_IBSS,
4427                 .doit = nl80211_join_ibss,
4428                 .policy = nl80211_policy,
4429                 .flags = GENL_ADMIN_PERM,
4430         },
4431         {
4432                 .cmd = NL80211_CMD_LEAVE_IBSS,
4433                 .doit = nl80211_leave_ibss,
4434                 .policy = nl80211_policy,
4435                 .flags = GENL_ADMIN_PERM,
4436         },
4437 #ifdef CONFIG_NL80211_TESTMODE
4438         {
4439                 .cmd = NL80211_CMD_TESTMODE,
4440                 .doit = nl80211_testmode_do,
4441                 .policy = nl80211_policy,
4442                 .flags = GENL_ADMIN_PERM,
4443         },
4444 #endif
4445         {
4446                 .cmd = NL80211_CMD_CONNECT,
4447                 .doit = nl80211_connect,
4448                 .policy = nl80211_policy,
4449                 .flags = GENL_ADMIN_PERM,
4450         },
4451         {
4452                 .cmd = NL80211_CMD_DISCONNECT,
4453                 .doit = nl80211_disconnect,
4454                 .policy = nl80211_policy,
4455                 .flags = GENL_ADMIN_PERM,
4456         },
4457         {
4458                 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4459                 .doit = nl80211_wiphy_netns,
4460                 .policy = nl80211_policy,
4461                 .flags = GENL_ADMIN_PERM,
4462         },
4463         {
4464                 .cmd = NL80211_CMD_GET_SURVEY,
4465                 .policy = nl80211_policy,
4466                 .dumpit = nl80211_dump_survey,
4467         },
4468 };
4469 static struct genl_multicast_group nl80211_mlme_mcgrp = {
4470         .name = "mlme",
4471 };
4472
4473 /* multicast groups */
4474 static struct genl_multicast_group nl80211_config_mcgrp = {
4475         .name = "config",
4476 };
4477 static struct genl_multicast_group nl80211_scan_mcgrp = {
4478         .name = "scan",
4479 };
4480 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4481         .name = "regulatory",
4482 };
4483
4484 /* notification functions */
4485
4486 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4487 {
4488         struct sk_buff *msg;
4489
4490         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4491         if (!msg)
4492                 return;
4493
4494         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4495                 nlmsg_free(msg);
4496                 return;
4497         }
4498
4499         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4500                                 nl80211_config_mcgrp.id, GFP_KERNEL);
4501 }
4502
4503 static int nl80211_add_scan_req(struct sk_buff *msg,
4504                                 struct cfg80211_registered_device *rdev)
4505 {
4506         struct cfg80211_scan_request *req = rdev->scan_req;
4507         struct nlattr *nest;
4508         int i;
4509
4510         ASSERT_RDEV_LOCK(rdev);
4511
4512         if (WARN_ON(!req))
4513                 return 0;
4514
4515         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4516         if (!nest)
4517                 goto nla_put_failure;
4518         for (i = 0; i < req->n_ssids; i++)
4519                 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4520         nla_nest_end(msg, nest);
4521
4522         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4523         if (!nest)
4524                 goto nla_put_failure;
4525         for (i = 0; i < req->n_channels; i++)
4526                 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4527         nla_nest_end(msg, nest);
4528
4529         if (req->ie)
4530                 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4531
4532         return 0;
4533  nla_put_failure:
4534         return -ENOBUFS;
4535 }
4536
4537 static int nl80211_send_scan_msg(struct sk_buff *msg,
4538                                  struct cfg80211_registered_device *rdev,
4539                                  struct net_device *netdev,
4540                                  u32 pid, u32 seq, int flags,
4541                                  u32 cmd)
4542 {
4543         void *hdr;
4544
4545         hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4546         if (!hdr)
4547                 return -1;
4548
4549         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4550         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4551
4552         /* ignore errors and send incomplete event anyway */
4553         nl80211_add_scan_req(msg, rdev);
4554
4555         return genlmsg_end(msg, hdr);
4556
4557  nla_put_failure:
4558         genlmsg_cancel(msg, hdr);
4559         return -EMSGSIZE;
4560 }
4561
4562 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4563                              struct net_device *netdev)
4564 {
4565         struct sk_buff *msg;
4566
4567         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4568         if (!msg)
4569                 return;
4570
4571         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4572                                   NL80211_CMD_TRIGGER_SCAN) < 0) {
4573                 nlmsg_free(msg);
4574                 return;
4575         }
4576
4577         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4578                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
4579 }
4580
4581 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4582                             struct net_device *netdev)
4583 {
4584         struct sk_buff *msg;
4585
4586         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4587         if (!msg)
4588                 return;
4589
4590         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4591                                   NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
4592                 nlmsg_free(msg);
4593                 return;
4594         }
4595
4596         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4597                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
4598 }
4599
4600 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4601                                struct net_device *netdev)
4602 {
4603         struct sk_buff *msg;
4604
4605         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4606         if (!msg)
4607                 return;
4608
4609         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4610                                   NL80211_CMD_SCAN_ABORTED) < 0) {
4611                 nlmsg_free(msg);
4612                 return;
4613         }
4614
4615         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4616                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
4617 }
4618
4619 /*
4620  * This can happen on global regulatory changes or device specific settings
4621  * based on custom world regulatory domains.
4622  */
4623 void nl80211_send_reg_change_event(struct regulatory_request *request)
4624 {
4625         struct sk_buff *msg;
4626         void *hdr;
4627
4628         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4629         if (!msg)
4630                 return;
4631
4632         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4633         if (!hdr) {
4634                 nlmsg_free(msg);
4635                 return;
4636         }
4637
4638         /* Userspace can always count this one always being set */
4639         NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4640
4641         if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4642                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4643                            NL80211_REGDOM_TYPE_WORLD);
4644         else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4645                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4646                            NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4647         else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4648                  request->intersect)
4649                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4650                            NL80211_REGDOM_TYPE_INTERSECTION);
4651         else {
4652                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4653                            NL80211_REGDOM_TYPE_COUNTRY);
4654                 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4655         }
4656
4657         if (wiphy_idx_valid(request->wiphy_idx))
4658                 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4659
4660         if (genlmsg_end(msg, hdr) < 0) {
4661                 nlmsg_free(msg);
4662                 return;
4663         }
4664
4665         rcu_read_lock();
4666         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4667                                 GFP_ATOMIC);
4668         rcu_read_unlock();
4669
4670         return;
4671
4672 nla_put_failure:
4673         genlmsg_cancel(msg, hdr);
4674         nlmsg_free(msg);
4675 }
4676
4677 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4678                                     struct net_device *netdev,
4679                                     const u8 *buf, size_t len,
4680                                     enum nl80211_commands cmd, gfp_t gfp)
4681 {
4682         struct sk_buff *msg;
4683         void *hdr;
4684
4685         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4686         if (!msg)
4687                 return;
4688
4689         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4690         if (!hdr) {
4691                 nlmsg_free(msg);
4692                 return;
4693         }
4694
4695         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4696         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4697         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4698
4699         if (genlmsg_end(msg, hdr) < 0) {
4700                 nlmsg_free(msg);
4701                 return;
4702         }
4703
4704         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4705                                 nl80211_mlme_mcgrp.id, gfp);
4706         return;
4707
4708  nla_put_failure:
4709         genlmsg_cancel(msg, hdr);
4710         nlmsg_free(msg);
4711 }
4712
4713 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
4714                           struct net_device *netdev, const u8 *buf,
4715                           size_t len, gfp_t gfp)
4716 {
4717         nl80211_send_mlme_event(rdev, netdev, buf, len,
4718                                 NL80211_CMD_AUTHENTICATE, gfp);
4719 }
4720
4721 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4722                            struct net_device *netdev, const u8 *buf,
4723                            size_t len, gfp_t gfp)
4724 {
4725         nl80211_send_mlme_event(rdev, netdev, buf, len,
4726                                 NL80211_CMD_ASSOCIATE, gfp);
4727 }
4728
4729 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
4730                          struct net_device *netdev, const u8 *buf,
4731                          size_t len, gfp_t gfp)
4732 {
4733         nl80211_send_mlme_event(rdev, netdev, buf, len,
4734                                 NL80211_CMD_DEAUTHENTICATE, gfp);
4735 }
4736
4737 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4738                            struct net_device *netdev, const u8 *buf,
4739                            size_t len, gfp_t gfp)
4740 {
4741         nl80211_send_mlme_event(rdev, netdev, buf, len,
4742                                 NL80211_CMD_DISASSOCIATE, gfp);
4743 }
4744
4745 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4746                                       struct net_device *netdev, int cmd,
4747                                       const u8 *addr, gfp_t gfp)
4748 {
4749         struct sk_buff *msg;
4750         void *hdr;
4751
4752         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4753         if (!msg)
4754                 return;
4755
4756         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4757         if (!hdr) {
4758                 nlmsg_free(msg);
4759                 return;
4760         }
4761
4762         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4763         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4764         NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4765         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4766
4767         if (genlmsg_end(msg, hdr) < 0) {
4768                 nlmsg_free(msg);
4769                 return;
4770         }
4771
4772         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4773                                 nl80211_mlme_mcgrp.id, gfp);
4774         return;
4775
4776  nla_put_failure:
4777         genlmsg_cancel(msg, hdr);
4778         nlmsg_free(msg);
4779 }
4780
4781 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
4782                                struct net_device *netdev, const u8 *addr,
4783                                gfp_t gfp)
4784 {
4785         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
4786                                   addr, gfp);
4787 }
4788
4789 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
4790                                 struct net_device *netdev, const u8 *addr,
4791                                 gfp_t gfp)
4792 {
4793         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4794                                   addr, gfp);
4795 }
4796
4797 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4798                                  struct net_device *netdev, const u8 *bssid,
4799                                  const u8 *req_ie, size_t req_ie_len,
4800                                  const u8 *resp_ie, size_t resp_ie_len,
4801                                  u16 status, gfp_t gfp)
4802 {
4803         struct sk_buff *msg;
4804         void *hdr;
4805
4806         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4807         if (!msg)
4808                 return;
4809
4810         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4811         if (!hdr) {
4812                 nlmsg_free(msg);
4813                 return;
4814         }
4815
4816         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4817         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4818         if (bssid)
4819                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4820         NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4821         if (req_ie)
4822                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4823         if (resp_ie)
4824                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4825
4826         if (genlmsg_end(msg, hdr) < 0) {
4827                 nlmsg_free(msg);
4828                 return;
4829         }
4830
4831         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4832                                 nl80211_mlme_mcgrp.id, gfp);
4833         return;
4834
4835  nla_put_failure:
4836         genlmsg_cancel(msg, hdr);
4837         nlmsg_free(msg);
4838
4839 }
4840
4841 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4842                          struct net_device *netdev, const u8 *bssid,
4843                          const u8 *req_ie, size_t req_ie_len,
4844                          const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4845 {
4846         struct sk_buff *msg;
4847         void *hdr;
4848
4849         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4850         if (!msg)
4851                 return;
4852
4853         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4854         if (!hdr) {
4855                 nlmsg_free(msg);
4856                 return;
4857         }
4858
4859         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4860         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4861         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4862         if (req_ie)
4863                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4864         if (resp_ie)
4865                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4866
4867         if (genlmsg_end(msg, hdr) < 0) {
4868                 nlmsg_free(msg);
4869                 return;
4870         }
4871
4872         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4873                                 nl80211_mlme_mcgrp.id, gfp);
4874         return;
4875
4876  nla_put_failure:
4877         genlmsg_cancel(msg, hdr);
4878         nlmsg_free(msg);
4879
4880 }
4881
4882 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4883                                struct net_device *netdev, u16 reason,
4884                                const u8 *ie, size_t ie_len, bool from_ap)
4885 {
4886         struct sk_buff *msg;
4887         void *hdr;
4888
4889         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4890         if (!msg)
4891                 return;
4892
4893         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4894         if (!hdr) {
4895                 nlmsg_free(msg);
4896                 return;
4897         }
4898
4899         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4900         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4901         if (from_ap && reason)
4902                 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4903         if (from_ap)
4904                 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4905         if (ie)
4906                 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4907
4908         if (genlmsg_end(msg, hdr) < 0) {
4909                 nlmsg_free(msg);
4910                 return;
4911         }
4912
4913         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4914                                 nl80211_mlme_mcgrp.id, GFP_KERNEL);
4915         return;
4916
4917  nla_put_failure:
4918         genlmsg_cancel(msg, hdr);
4919         nlmsg_free(msg);
4920
4921 }
4922
4923 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
4924                              struct net_device *netdev, const u8 *bssid,
4925                              gfp_t gfp)
4926 {
4927         struct sk_buff *msg;
4928         void *hdr;
4929
4930         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4931         if (!msg)
4932                 return;
4933
4934         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
4935         if (!hdr) {
4936                 nlmsg_free(msg);
4937                 return;
4938         }
4939
4940         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4941         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4942         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4943
4944         if (genlmsg_end(msg, hdr) < 0) {
4945                 nlmsg_free(msg);
4946                 return;
4947         }
4948
4949         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4950                                 nl80211_mlme_mcgrp.id, gfp);
4951         return;
4952
4953  nla_put_failure:
4954         genlmsg_cancel(msg, hdr);
4955         nlmsg_free(msg);
4956 }
4957
4958 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
4959                                  struct net_device *netdev, const u8 *addr,
4960                                  enum nl80211_key_type key_type, int key_id,
4961                                  const u8 *tsc, gfp_t gfp)
4962 {
4963         struct sk_buff *msg;
4964         void *hdr;
4965
4966         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4967         if (!msg)
4968                 return;
4969
4970         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
4971         if (!hdr) {
4972                 nlmsg_free(msg);
4973                 return;
4974         }
4975
4976         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4977         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4978         if (addr)
4979                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4980         NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
4981         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
4982         if (tsc)
4983                 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
4984
4985         if (genlmsg_end(msg, hdr) < 0) {
4986                 nlmsg_free(msg);
4987                 return;
4988         }
4989
4990         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4991                                 nl80211_mlme_mcgrp.id, gfp);
4992         return;
4993
4994  nla_put_failure:
4995         genlmsg_cancel(msg, hdr);
4996         nlmsg_free(msg);
4997 }
4998
4999 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5000                                     struct ieee80211_channel *channel_before,
5001                                     struct ieee80211_channel *channel_after)
5002 {
5003         struct sk_buff *msg;
5004         void *hdr;
5005         struct nlattr *nl_freq;
5006
5007         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
5008         if (!msg)
5009                 return;
5010
5011         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5012         if (!hdr) {
5013                 nlmsg_free(msg);
5014                 return;
5015         }
5016
5017         /*
5018          * Since we are applying the beacon hint to a wiphy we know its
5019          * wiphy_idx is valid
5020          */
5021         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5022
5023         /* Before */
5024         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5025         if (!nl_freq)
5026                 goto nla_put_failure;
5027         if (nl80211_msg_put_channel(msg, channel_before))
5028                 goto nla_put_failure;
5029         nla_nest_end(msg, nl_freq);
5030
5031         /* After */
5032         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5033         if (!nl_freq)
5034                 goto nla_put_failure;
5035         if (nl80211_msg_put_channel(msg, channel_after))
5036                 goto nla_put_failure;
5037         nla_nest_end(msg, nl_freq);
5038
5039         if (genlmsg_end(msg, hdr) < 0) {
5040                 nlmsg_free(msg);
5041                 return;
5042         }
5043
5044         rcu_read_lock();
5045         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5046                                 GFP_ATOMIC);
5047         rcu_read_unlock();
5048
5049         return;
5050
5051 nla_put_failure:
5052         genlmsg_cancel(msg, hdr);
5053         nlmsg_free(msg);
5054 }
5055
5056 /* initialisation/exit functions */
5057
5058 int nl80211_init(void)
5059 {
5060         int err;
5061
5062         err = genl_register_family_with_ops(&nl80211_fam,
5063                 nl80211_ops, ARRAY_SIZE(nl80211_ops));
5064         if (err)
5065                 return err;
5066
5067         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
5068         if (err)
5069                 goto err_out;
5070
5071         err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
5072         if (err)
5073                 goto err_out;
5074
5075         err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
5076         if (err)
5077                 goto err_out;
5078
5079         err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
5080         if (err)
5081                 goto err_out;
5082
5083 #ifdef CONFIG_NL80211_TESTMODE
5084         err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
5085         if (err)
5086                 goto err_out;
5087 #endif
5088
5089         return 0;
5090  err_out:
5091         genl_unregister_family(&nl80211_fam);
5092         return err;
5093 }
5094
5095 void nl80211_exit(void)
5096 {
5097         genl_unregister_family(&nl80211_fam);
5098 }