Linux 3.1-rc7
[pandora-kernel.git] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006-2010  Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/slab.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <linux/etherdevice.h>
18 #include <net/net_namespace.h>
19 #include <net/genetlink.h>
20 #include <net/cfg80211.h>
21 #include <net/sock.h>
22 #include "core.h"
23 #include "nl80211.h"
24 #include "reg.h"
25
26 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27                             struct genl_info *info);
28 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29                               struct genl_info *info);
30
31 /* the netlink family */
32 static struct genl_family nl80211_fam = {
33         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34         .name = "nl80211",      /* have users key off the name instead */
35         .hdrsize = 0,           /* no private header */
36         .version = 1,           /* no particular meaning now */
37         .maxattr = NL80211_ATTR_MAX,
38         .netnsok = true,
39         .pre_doit = nl80211_pre_doit,
40         .post_doit = nl80211_post_doit,
41 };
42
43 /* internal helper: get rdev and dev */
44 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
45                                        struct cfg80211_registered_device **rdev,
46                                        struct net_device **dev)
47 {
48         struct nlattr **attrs = info->attrs;
49         int ifindex;
50
51         if (!attrs[NL80211_ATTR_IFINDEX])
52                 return -EINVAL;
53
54         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
55         *dev = dev_get_by_index(genl_info_net(info), ifindex);
56         if (!*dev)
57                 return -ENODEV;
58
59         *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
60         if (IS_ERR(*rdev)) {
61                 dev_put(*dev);
62                 return PTR_ERR(*rdev);
63         }
64
65         return 0;
66 }
67
68 /* policy for the attributes */
69 static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
70         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
72                                       .len = 20-1 },
73         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
74         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
75         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
76         [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77         [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78         [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79         [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
80         [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
81
82         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
85
86         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
87         [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
88
89         [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
90         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91                                     .len = WLAN_MAX_KEY_LEN },
92         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
95         [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
96         [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
97
98         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101                                        .len = IEEE80211_MAX_DATA_LEN },
102         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103                                        .len = IEEE80211_MAX_DATA_LEN },
104         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108                                                .len = NL80211_MAX_SUPP_RATES },
109         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
110         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
111         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
112         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113                                 .len = IEEE80211_MAX_MESH_ID_LEN },
114         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
115
116         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
119         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
122         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123                                            .len = NL80211_MAX_SUPP_RATES },
124         [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
125
126         [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
127         [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
128
129         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
130                                          .len = NL80211_HT_CAPABILITY_LEN },
131
132         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
133         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
134                               .len = IEEE80211_MAX_DATA_LEN },
135         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
136         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
137
138         [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
139                                 .len = IEEE80211_MAX_SSID_LEN },
140         [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
141         [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
142         [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
143         [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
144         [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
145         [NL80211_ATTR_STA_FLAGS2] = {
146                 .len = sizeof(struct nl80211_sta_flag_update),
147         },
148         [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
149         [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
150         [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
151         [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
152         [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
153         [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
154         [NL80211_ATTR_PID] = { .type = NLA_U32 },
155         [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
156         [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
157                                  .len = WLAN_PMKID_LEN },
158         [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
159         [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
160         [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
161         [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
162                                  .len = IEEE80211_MAX_DATA_LEN },
163         [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
164         [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
165         [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
166         [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
167         [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
168         [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
169         [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
170         [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
171         [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
172         [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
173         [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
174         [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
175         [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
176         [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
177         [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
178         [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
179         [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
180         [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
181 };
182
183 /* policy for the key attributes */
184 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
185         [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
186         [NL80211_KEY_IDX] = { .type = NLA_U8 },
187         [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
188         [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
189         [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
190         [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
191         [NL80211_KEY_TYPE] = { .type = NLA_U32 },
192         [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
193 };
194
195 /* policy for the key default flags */
196 static const struct nla_policy
197 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
198         [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
199         [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
200 };
201
202 /* policy for WoWLAN attributes */
203 static const struct nla_policy
204 nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
205         [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
206         [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
207         [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
208         [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
209         [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
210         [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
211         [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
212         [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
213 };
214
215 /* policy for GTK rekey offload attributes */
216 static const struct nla_policy
217 nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
218         [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
219         [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
220         [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
221 };
222
223 /* ifidx get helper */
224 static int nl80211_get_ifidx(struct netlink_callback *cb)
225 {
226         int res;
227
228         res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
229                           nl80211_fam.attrbuf, nl80211_fam.maxattr,
230                           nl80211_policy);
231         if (res)
232                 return res;
233
234         if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
235                 return -EINVAL;
236
237         res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
238         if (!res)
239                 return -EINVAL;
240         return res;
241 }
242
243 static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
244                                        struct netlink_callback *cb,
245                                        struct cfg80211_registered_device **rdev,
246                                        struct net_device **dev)
247 {
248         int ifidx = cb->args[0];
249         int err;
250
251         if (!ifidx)
252                 ifidx = nl80211_get_ifidx(cb);
253         if (ifidx < 0)
254                 return ifidx;
255
256         cb->args[0] = ifidx;
257
258         rtnl_lock();
259
260         *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
261         if (!*dev) {
262                 err = -ENODEV;
263                 goto out_rtnl;
264         }
265
266         *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
267         if (IS_ERR(*rdev)) {
268                 err = PTR_ERR(*rdev);
269                 goto out_rtnl;
270         }
271
272         return 0;
273  out_rtnl:
274         rtnl_unlock();
275         return err;
276 }
277
278 static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
279 {
280         cfg80211_unlock_rdev(rdev);
281         rtnl_unlock();
282 }
283
284 /* IE validation */
285 static bool is_valid_ie_attr(const struct nlattr *attr)
286 {
287         const u8 *pos;
288         int len;
289
290         if (!attr)
291                 return true;
292
293         pos = nla_data(attr);
294         len = nla_len(attr);
295
296         while (len) {
297                 u8 elemlen;
298
299                 if (len < 2)
300                         return false;
301                 len -= 2;
302
303                 elemlen = pos[1];
304                 if (elemlen > len)
305                         return false;
306
307                 len -= elemlen;
308                 pos += 2 + elemlen;
309         }
310
311         return true;
312 }
313
314 /* message building helper */
315 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
316                                    int flags, u8 cmd)
317 {
318         /* since there is no private header just add the generic one */
319         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
320 }
321
322 static int nl80211_msg_put_channel(struct sk_buff *msg,
323                                    struct ieee80211_channel *chan)
324 {
325         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
326                     chan->center_freq);
327
328         if (chan->flags & IEEE80211_CHAN_DISABLED)
329                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
330         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
331                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
332         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
333                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
334         if (chan->flags & IEEE80211_CHAN_RADAR)
335                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
336
337         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
338                     DBM_TO_MBM(chan->max_power));
339
340         return 0;
341
342  nla_put_failure:
343         return -ENOBUFS;
344 }
345
346 /* netlink command implementations */
347
348 struct key_parse {
349         struct key_params p;
350         int idx;
351         int type;
352         bool def, defmgmt;
353         bool def_uni, def_multi;
354 };
355
356 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
357 {
358         struct nlattr *tb[NL80211_KEY_MAX + 1];
359         int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
360                                    nl80211_key_policy);
361         if (err)
362                 return err;
363
364         k->def = !!tb[NL80211_KEY_DEFAULT];
365         k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
366
367         if (k->def) {
368                 k->def_uni = true;
369                 k->def_multi = true;
370         }
371         if (k->defmgmt)
372                 k->def_multi = true;
373
374         if (tb[NL80211_KEY_IDX])
375                 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
376
377         if (tb[NL80211_KEY_DATA]) {
378                 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
379                 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
380         }
381
382         if (tb[NL80211_KEY_SEQ]) {
383                 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
384                 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
385         }
386
387         if (tb[NL80211_KEY_CIPHER])
388                 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
389
390         if (tb[NL80211_KEY_TYPE]) {
391                 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
392                 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
393                         return -EINVAL;
394         }
395
396         if (tb[NL80211_KEY_DEFAULT_TYPES]) {
397                 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
398                 int err = nla_parse_nested(kdt,
399                                            NUM_NL80211_KEY_DEFAULT_TYPES - 1,
400                                            tb[NL80211_KEY_DEFAULT_TYPES],
401                                            nl80211_key_default_policy);
402                 if (err)
403                         return err;
404
405                 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
406                 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
407         }
408
409         return 0;
410 }
411
412 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
413 {
414         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
415                 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
416                 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
417         }
418
419         if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
420                 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
421                 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
422         }
423
424         if (info->attrs[NL80211_ATTR_KEY_IDX])
425                 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
426
427         if (info->attrs[NL80211_ATTR_KEY_CIPHER])
428                 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
429
430         k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
431         k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
432
433         if (k->def) {
434                 k->def_uni = true;
435                 k->def_multi = true;
436         }
437         if (k->defmgmt)
438                 k->def_multi = true;
439
440         if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
441                 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
442                 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
443                         return -EINVAL;
444         }
445
446         if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
447                 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
448                 int err = nla_parse_nested(
449                                 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
450                                 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
451                                 nl80211_key_default_policy);
452                 if (err)
453                         return err;
454
455                 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
456                 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
457         }
458
459         return 0;
460 }
461
462 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
463 {
464         int err;
465
466         memset(k, 0, sizeof(*k));
467         k->idx = -1;
468         k->type = -1;
469
470         if (info->attrs[NL80211_ATTR_KEY])
471                 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
472         else
473                 err = nl80211_parse_key_old(info, k);
474
475         if (err)
476                 return err;
477
478         if (k->def && k->defmgmt)
479                 return -EINVAL;
480
481         if (k->defmgmt) {
482                 if (k->def_uni || !k->def_multi)
483                         return -EINVAL;
484         }
485
486         if (k->idx != -1) {
487                 if (k->defmgmt) {
488                         if (k->idx < 4 || k->idx > 5)
489                                 return -EINVAL;
490                 } else if (k->def) {
491                         if (k->idx < 0 || k->idx > 3)
492                                 return -EINVAL;
493                 } else {
494                         if (k->idx < 0 || k->idx > 5)
495                                 return -EINVAL;
496                 }
497         }
498
499         return 0;
500 }
501
502 static struct cfg80211_cached_keys *
503 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
504                        struct nlattr *keys)
505 {
506         struct key_parse parse;
507         struct nlattr *key;
508         struct cfg80211_cached_keys *result;
509         int rem, err, def = 0;
510
511         result = kzalloc(sizeof(*result), GFP_KERNEL);
512         if (!result)
513                 return ERR_PTR(-ENOMEM);
514
515         result->def = -1;
516         result->defmgmt = -1;
517
518         nla_for_each_nested(key, keys, rem) {
519                 memset(&parse, 0, sizeof(parse));
520                 parse.idx = -1;
521
522                 err = nl80211_parse_key_new(key, &parse);
523                 if (err)
524                         goto error;
525                 err = -EINVAL;
526                 if (!parse.p.key)
527                         goto error;
528                 if (parse.idx < 0 || parse.idx > 4)
529                         goto error;
530                 if (parse.def) {
531                         if (def)
532                                 goto error;
533                         def = 1;
534                         result->def = parse.idx;
535                         if (!parse.def_uni || !parse.def_multi)
536                                 goto error;
537                 } else if (parse.defmgmt)
538                         goto error;
539                 err = cfg80211_validate_key_settings(rdev, &parse.p,
540                                                      parse.idx, false, NULL);
541                 if (err)
542                         goto error;
543                 result->params[parse.idx].cipher = parse.p.cipher;
544                 result->params[parse.idx].key_len = parse.p.key_len;
545                 result->params[parse.idx].key = result->data[parse.idx];
546                 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
547         }
548
549         return result;
550  error:
551         kfree(result);
552         return ERR_PTR(err);
553 }
554
555 static int nl80211_key_allowed(struct wireless_dev *wdev)
556 {
557         ASSERT_WDEV_LOCK(wdev);
558
559         switch (wdev->iftype) {
560         case NL80211_IFTYPE_AP:
561         case NL80211_IFTYPE_AP_VLAN:
562         case NL80211_IFTYPE_P2P_GO:
563         case NL80211_IFTYPE_MESH_POINT:
564                 break;
565         case NL80211_IFTYPE_ADHOC:
566                 if (!wdev->current_bss)
567                         return -ENOLINK;
568                 break;
569         case NL80211_IFTYPE_STATION:
570         case NL80211_IFTYPE_P2P_CLIENT:
571                 if (wdev->sme_state != CFG80211_SME_CONNECTED)
572                         return -ENOLINK;
573                 break;
574         default:
575                 return -EINVAL;
576         }
577
578         return 0;
579 }
580
581 static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
582 {
583         struct nlattr *nl_modes = nla_nest_start(msg, attr);
584         int i;
585
586         if (!nl_modes)
587                 goto nla_put_failure;
588
589         i = 0;
590         while (ifmodes) {
591                 if (ifmodes & 1)
592                         NLA_PUT_FLAG(msg, i);
593                 ifmodes >>= 1;
594                 i++;
595         }
596
597         nla_nest_end(msg, nl_modes);
598         return 0;
599
600 nla_put_failure:
601         return -ENOBUFS;
602 }
603
604 static int nl80211_put_iface_combinations(struct wiphy *wiphy,
605                                           struct sk_buff *msg)
606 {
607         struct nlattr *nl_combis;
608         int i, j;
609
610         nl_combis = nla_nest_start(msg,
611                                 NL80211_ATTR_INTERFACE_COMBINATIONS);
612         if (!nl_combis)
613                 goto nla_put_failure;
614
615         for (i = 0; i < wiphy->n_iface_combinations; i++) {
616                 const struct ieee80211_iface_combination *c;
617                 struct nlattr *nl_combi, *nl_limits;
618
619                 c = &wiphy->iface_combinations[i];
620
621                 nl_combi = nla_nest_start(msg, i + 1);
622                 if (!nl_combi)
623                         goto nla_put_failure;
624
625                 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
626                 if (!nl_limits)
627                         goto nla_put_failure;
628
629                 for (j = 0; j < c->n_limits; j++) {
630                         struct nlattr *nl_limit;
631
632                         nl_limit = nla_nest_start(msg, j + 1);
633                         if (!nl_limit)
634                                 goto nla_put_failure;
635                         NLA_PUT_U32(msg, NL80211_IFACE_LIMIT_MAX,
636                                     c->limits[j].max);
637                         if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
638                                                 c->limits[j].types))
639                                 goto nla_put_failure;
640                         nla_nest_end(msg, nl_limit);
641                 }
642
643                 nla_nest_end(msg, nl_limits);
644
645                 if (c->beacon_int_infra_match)
646                         NLA_PUT_FLAG(msg,
647                                 NL80211_IFACE_COMB_STA_AP_BI_MATCH);
648                 NLA_PUT_U32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
649                             c->num_different_channels);
650                 NLA_PUT_U32(msg, NL80211_IFACE_COMB_MAXNUM,
651                             c->max_interfaces);
652
653                 nla_nest_end(msg, nl_combi);
654         }
655
656         nla_nest_end(msg, nl_combis);
657
658         return 0;
659 nla_put_failure:
660         return -ENOBUFS;
661 }
662
663 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
664                               struct cfg80211_registered_device *dev)
665 {
666         void *hdr;
667         struct nlattr *nl_bands, *nl_band;
668         struct nlattr *nl_freqs, *nl_freq;
669         struct nlattr *nl_rates, *nl_rate;
670         struct nlattr *nl_cmds;
671         enum ieee80211_band band;
672         struct ieee80211_channel *chan;
673         struct ieee80211_rate *rate;
674         int i;
675         const struct ieee80211_txrx_stypes *mgmt_stypes =
676                                 dev->wiphy.mgmt_stypes;
677
678         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
679         if (!hdr)
680                 return -1;
681
682         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
683         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
684
685         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
686                     cfg80211_rdev_list_generation);
687
688         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
689                    dev->wiphy.retry_short);
690         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
691                    dev->wiphy.retry_long);
692         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
693                     dev->wiphy.frag_threshold);
694         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
695                     dev->wiphy.rts_threshold);
696         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
697                     dev->wiphy.coverage_class);
698         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
699                    dev->wiphy.max_scan_ssids);
700         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
701                    dev->wiphy.max_sched_scan_ssids);
702         NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
703                     dev->wiphy.max_scan_ie_len);
704         NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
705                     dev->wiphy.max_sched_scan_ie_len);
706
707         if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
708                 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
709         if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
710                 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
711
712         NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
713                 sizeof(u32) * dev->wiphy.n_cipher_suites,
714                 dev->wiphy.cipher_suites);
715
716         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
717                    dev->wiphy.max_num_pmkids);
718
719         if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
720                 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
721
722         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
723                     dev->wiphy.available_antennas_tx);
724         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
725                     dev->wiphy.available_antennas_rx);
726
727         if ((dev->wiphy.available_antennas_tx ||
728              dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
729                 u32 tx_ant = 0, rx_ant = 0;
730                 int res;
731                 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
732                 if (!res) {
733                         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
734                         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
735                 }
736         }
737
738         if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
739                                 dev->wiphy.interface_modes))
740                 goto nla_put_failure;
741
742         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
743         if (!nl_bands)
744                 goto nla_put_failure;
745
746         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
747                 if (!dev->wiphy.bands[band])
748                         continue;
749
750                 nl_band = nla_nest_start(msg, band);
751                 if (!nl_band)
752                         goto nla_put_failure;
753
754                 /* add HT info */
755                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
756                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
757                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
758                                 &dev->wiphy.bands[band]->ht_cap.mcs);
759                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
760                                 dev->wiphy.bands[band]->ht_cap.cap);
761                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
762                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
763                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
764                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
765                 }
766
767                 /* add frequencies */
768                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
769                 if (!nl_freqs)
770                         goto nla_put_failure;
771
772                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
773                         nl_freq = nla_nest_start(msg, i);
774                         if (!nl_freq)
775                                 goto nla_put_failure;
776
777                         chan = &dev->wiphy.bands[band]->channels[i];
778
779                         if (nl80211_msg_put_channel(msg, chan))
780                                 goto nla_put_failure;
781
782                         nla_nest_end(msg, nl_freq);
783                 }
784
785                 nla_nest_end(msg, nl_freqs);
786
787                 /* add bitrates */
788                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
789                 if (!nl_rates)
790                         goto nla_put_failure;
791
792                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
793                         nl_rate = nla_nest_start(msg, i);
794                         if (!nl_rate)
795                                 goto nla_put_failure;
796
797                         rate = &dev->wiphy.bands[band]->bitrates[i];
798                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
799                                     rate->bitrate);
800                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
801                                 NLA_PUT_FLAG(msg,
802                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
803
804                         nla_nest_end(msg, nl_rate);
805                 }
806
807                 nla_nest_end(msg, nl_rates);
808
809                 nla_nest_end(msg, nl_band);
810         }
811         nla_nest_end(msg, nl_bands);
812
813         nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
814         if (!nl_cmds)
815                 goto nla_put_failure;
816
817         i = 0;
818 #define CMD(op, n)                                              \
819          do {                                                   \
820                 if (dev->ops->op) {                             \
821                         i++;                                    \
822                         NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
823                 }                                               \
824         } while (0)
825
826         CMD(add_virtual_intf, NEW_INTERFACE);
827         CMD(change_virtual_intf, SET_INTERFACE);
828         CMD(add_key, NEW_KEY);
829         CMD(add_beacon, NEW_BEACON);
830         CMD(add_station, NEW_STATION);
831         CMD(add_mpath, NEW_MPATH);
832         CMD(update_mesh_config, SET_MESH_CONFIG);
833         CMD(change_bss, SET_BSS);
834         CMD(auth, AUTHENTICATE);
835         CMD(assoc, ASSOCIATE);
836         CMD(deauth, DEAUTHENTICATE);
837         CMD(disassoc, DISASSOCIATE);
838         CMD(join_ibss, JOIN_IBSS);
839         CMD(join_mesh, JOIN_MESH);
840         CMD(set_pmksa, SET_PMKSA);
841         CMD(del_pmksa, DEL_PMKSA);
842         CMD(flush_pmksa, FLUSH_PMKSA);
843         CMD(remain_on_channel, REMAIN_ON_CHANNEL);
844         CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
845         CMD(mgmt_tx, FRAME);
846         CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
847         if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
848                 i++;
849                 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
850         }
851         CMD(set_channel, SET_CHANNEL);
852         CMD(set_wds_peer, SET_WDS_PEER);
853         if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
854                 CMD(sched_scan_start, START_SCHED_SCAN);
855
856 #undef CMD
857
858         if (dev->ops->connect || dev->ops->auth) {
859                 i++;
860                 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
861         }
862
863         if (dev->ops->disconnect || dev->ops->deauth) {
864                 i++;
865                 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
866         }
867
868         nla_nest_end(msg, nl_cmds);
869
870         if (dev->ops->remain_on_channel)
871                 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
872                             dev->wiphy.max_remain_on_channel_duration);
873
874         /* for now at least assume all drivers have it */
875         if (dev->ops->mgmt_tx)
876                 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
877
878         if (mgmt_stypes) {
879                 u16 stypes;
880                 struct nlattr *nl_ftypes, *nl_ifs;
881                 enum nl80211_iftype ift;
882
883                 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
884                 if (!nl_ifs)
885                         goto nla_put_failure;
886
887                 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
888                         nl_ftypes = nla_nest_start(msg, ift);
889                         if (!nl_ftypes)
890                                 goto nla_put_failure;
891                         i = 0;
892                         stypes = mgmt_stypes[ift].tx;
893                         while (stypes) {
894                                 if (stypes & 1)
895                                         NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
896                                                     (i << 4) | IEEE80211_FTYPE_MGMT);
897                                 stypes >>= 1;
898                                 i++;
899                         }
900                         nla_nest_end(msg, nl_ftypes);
901                 }
902
903                 nla_nest_end(msg, nl_ifs);
904
905                 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
906                 if (!nl_ifs)
907                         goto nla_put_failure;
908
909                 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
910                         nl_ftypes = nla_nest_start(msg, ift);
911                         if (!nl_ftypes)
912                                 goto nla_put_failure;
913                         i = 0;
914                         stypes = mgmt_stypes[ift].rx;
915                         while (stypes) {
916                                 if (stypes & 1)
917                                         NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
918                                                     (i << 4) | IEEE80211_FTYPE_MGMT);
919                                 stypes >>= 1;
920                                 i++;
921                         }
922                         nla_nest_end(msg, nl_ftypes);
923                 }
924                 nla_nest_end(msg, nl_ifs);
925         }
926
927         if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
928                 struct nlattr *nl_wowlan;
929
930                 nl_wowlan = nla_nest_start(msg,
931                                 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
932                 if (!nl_wowlan)
933                         goto nla_put_failure;
934
935                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
936                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
937                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
938                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
939                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
940                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
941                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)
942                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED);
943                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)
944                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
945                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)
946                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
947                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)
948                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
949                 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE)
950                         NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
951                 if (dev->wiphy.wowlan.n_patterns) {
952                         struct nl80211_wowlan_pattern_support pat = {
953                                 .max_patterns = dev->wiphy.wowlan.n_patterns,
954                                 .min_pattern_len =
955                                         dev->wiphy.wowlan.pattern_min_len,
956                                 .max_pattern_len =
957                                         dev->wiphy.wowlan.pattern_max_len,
958                         };
959                         NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
960                                 sizeof(pat), &pat);
961                 }
962
963                 nla_nest_end(msg, nl_wowlan);
964         }
965
966         if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
967                                 dev->wiphy.software_iftypes))
968                 goto nla_put_failure;
969
970         if (nl80211_put_iface_combinations(&dev->wiphy, msg))
971                 goto nla_put_failure;
972
973         return genlmsg_end(msg, hdr);
974
975  nla_put_failure:
976         genlmsg_cancel(msg, hdr);
977         return -EMSGSIZE;
978 }
979
980 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
981 {
982         int idx = 0;
983         int start = cb->args[0];
984         struct cfg80211_registered_device *dev;
985
986         mutex_lock(&cfg80211_mutex);
987         list_for_each_entry(dev, &cfg80211_rdev_list, list) {
988                 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
989                         continue;
990                 if (++idx <= start)
991                         continue;
992                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
993                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
994                                        dev) < 0) {
995                         idx--;
996                         break;
997                 }
998         }
999         mutex_unlock(&cfg80211_mutex);
1000
1001         cb->args[0] = idx;
1002
1003         return skb->len;
1004 }
1005
1006 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1007 {
1008         struct sk_buff *msg;
1009         struct cfg80211_registered_device *dev = info->user_ptr[0];
1010
1011         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1012         if (!msg)
1013                 return -ENOMEM;
1014
1015         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1016                 nlmsg_free(msg);
1017                 return -ENOBUFS;
1018         }
1019
1020         return genlmsg_reply(msg, info);
1021 }
1022
1023 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1024         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
1025         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
1026         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
1027         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
1028         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
1029 };
1030
1031 static int parse_txq_params(struct nlattr *tb[],
1032                             struct ieee80211_txq_params *txq_params)
1033 {
1034         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
1035             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1036             !tb[NL80211_TXQ_ATTR_AIFS])
1037                 return -EINVAL;
1038
1039         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
1040         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1041         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1042         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1043         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1044
1045         return 0;
1046 }
1047
1048 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1049 {
1050         /*
1051          * You can only set the channel explicitly for AP, mesh
1052          * and WDS type interfaces; all others have their channel
1053          * managed via their respective "establish a connection"
1054          * command (connect, join, ...)
1055          *
1056          * Monitors are special as they are normally slaved to
1057          * whatever else is going on, so they behave as though
1058          * you tried setting the wiphy channel itself.
1059          */
1060         return !wdev ||
1061                 wdev->iftype == NL80211_IFTYPE_AP ||
1062                 wdev->iftype == NL80211_IFTYPE_WDS ||
1063                 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
1064                 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1065                 wdev->iftype == NL80211_IFTYPE_P2P_GO;
1066 }
1067
1068 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1069                                  struct wireless_dev *wdev,
1070                                  struct genl_info *info)
1071 {
1072         enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1073         u32 freq;
1074         int result;
1075
1076         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1077                 return -EINVAL;
1078
1079         if (!nl80211_can_set_dev_channel(wdev))
1080                 return -EOPNOTSUPP;
1081
1082         if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1083                 channel_type = nla_get_u32(info->attrs[
1084                                    NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1085                 if (channel_type != NL80211_CHAN_NO_HT &&
1086                     channel_type != NL80211_CHAN_HT20 &&
1087                     channel_type != NL80211_CHAN_HT40PLUS &&
1088                     channel_type != NL80211_CHAN_HT40MINUS)
1089                         return -EINVAL;
1090         }
1091
1092         freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1093
1094         mutex_lock(&rdev->devlist_mtx);
1095         if (wdev) {
1096                 wdev_lock(wdev);
1097                 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
1098                 wdev_unlock(wdev);
1099         } else {
1100                 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
1101         }
1102         mutex_unlock(&rdev->devlist_mtx);
1103
1104         return result;
1105 }
1106
1107 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1108 {
1109         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1110         struct net_device *netdev = info->user_ptr[1];
1111
1112         return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
1113 }
1114
1115 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1116 {
1117         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1118         struct net_device *dev = info->user_ptr[1];
1119         struct wireless_dev *wdev = dev->ieee80211_ptr;
1120         const u8 *bssid;
1121
1122         if (!info->attrs[NL80211_ATTR_MAC])
1123                 return -EINVAL;
1124
1125         if (netif_running(dev))
1126                 return -EBUSY;
1127
1128         if (!rdev->ops->set_wds_peer)
1129                 return -EOPNOTSUPP;
1130
1131         if (wdev->iftype != NL80211_IFTYPE_WDS)
1132                 return -EOPNOTSUPP;
1133
1134         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1135         return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
1136 }
1137
1138
1139 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1140 {
1141         struct cfg80211_registered_device *rdev;
1142         struct net_device *netdev = NULL;
1143         struct wireless_dev *wdev;
1144         int result = 0, rem_txq_params = 0;
1145         struct nlattr *nl_txq_params;
1146         u32 changed;
1147         u8 retry_short = 0, retry_long = 0;
1148         u32 frag_threshold = 0, rts_threshold = 0;
1149         u8 coverage_class = 0;
1150
1151         /*
1152          * Try to find the wiphy and netdev. Normally this
1153          * function shouldn't need the netdev, but this is
1154          * done for backward compatibility -- previously
1155          * setting the channel was done per wiphy, but now
1156          * it is per netdev. Previous userland like hostapd
1157          * also passed a netdev to set_wiphy, so that it is
1158          * possible to let that go to the right netdev!
1159          */
1160         mutex_lock(&cfg80211_mutex);
1161
1162         if (info->attrs[NL80211_ATTR_IFINDEX]) {
1163                 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1164
1165                 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1166                 if (netdev && netdev->ieee80211_ptr) {
1167                         rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1168                         mutex_lock(&rdev->mtx);
1169                 } else
1170                         netdev = NULL;
1171         }
1172
1173         if (!netdev) {
1174                 rdev = __cfg80211_rdev_from_info(info);
1175                 if (IS_ERR(rdev)) {
1176                         mutex_unlock(&cfg80211_mutex);
1177                         return PTR_ERR(rdev);
1178                 }
1179                 wdev = NULL;
1180                 netdev = NULL;
1181                 result = 0;
1182
1183                 mutex_lock(&rdev->mtx);
1184         } else if (netif_running(netdev) &&
1185                    nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1186                 wdev = netdev->ieee80211_ptr;
1187         else
1188                 wdev = NULL;
1189
1190         /*
1191          * end workaround code, by now the rdev is available
1192          * and locked, and wdev may or may not be NULL.
1193          */
1194
1195         if (info->attrs[NL80211_ATTR_WIPHY_NAME])
1196                 result = cfg80211_dev_rename(
1197                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
1198
1199         mutex_unlock(&cfg80211_mutex);
1200
1201         if (result)
1202                 goto bad_res;
1203
1204         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1205                 struct ieee80211_txq_params txq_params;
1206                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1207
1208                 if (!rdev->ops->set_txq_params) {
1209                         result = -EOPNOTSUPP;
1210                         goto bad_res;
1211                 }
1212
1213                 nla_for_each_nested(nl_txq_params,
1214                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1215                                     rem_txq_params) {
1216                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1217                                   nla_data(nl_txq_params),
1218                                   nla_len(nl_txq_params),
1219                                   txq_params_policy);
1220                         result = parse_txq_params(tb, &txq_params);
1221                         if (result)
1222                                 goto bad_res;
1223
1224                         result = rdev->ops->set_txq_params(&rdev->wiphy,
1225                                                            &txq_params);
1226                         if (result)
1227                                 goto bad_res;
1228                 }
1229         }
1230
1231         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
1232                 result = __nl80211_set_channel(rdev, wdev, info);
1233                 if (result)
1234                         goto bad_res;
1235         }
1236
1237         if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1238                 enum nl80211_tx_power_setting type;
1239                 int idx, mbm = 0;
1240
1241                 if (!rdev->ops->set_tx_power) {
1242                         result = -EOPNOTSUPP;
1243                         goto bad_res;
1244                 }
1245
1246                 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1247                 type = nla_get_u32(info->attrs[idx]);
1248
1249                 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1250                     (type != NL80211_TX_POWER_AUTOMATIC)) {
1251                         result = -EINVAL;
1252                         goto bad_res;
1253                 }
1254
1255                 if (type != NL80211_TX_POWER_AUTOMATIC) {
1256                         idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1257                         mbm = nla_get_u32(info->attrs[idx]);
1258                 }
1259
1260                 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1261                 if (result)
1262                         goto bad_res;
1263         }
1264
1265         if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1266             info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1267                 u32 tx_ant, rx_ant;
1268                 if ((!rdev->wiphy.available_antennas_tx &&
1269                      !rdev->wiphy.available_antennas_rx) ||
1270                     !rdev->ops->set_antenna) {
1271                         result = -EOPNOTSUPP;
1272                         goto bad_res;
1273                 }
1274
1275                 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1276                 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1277
1278                 /* reject antenna configurations which don't match the
1279                  * available antenna masks, except for the "all" mask */
1280                 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1281                     (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
1282                         result = -EINVAL;
1283                         goto bad_res;
1284                 }
1285
1286                 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1287                 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
1288
1289                 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1290                 if (result)
1291                         goto bad_res;
1292         }
1293
1294         changed = 0;
1295
1296         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1297                 retry_short = nla_get_u8(
1298                         info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1299                 if (retry_short == 0) {
1300                         result = -EINVAL;
1301                         goto bad_res;
1302                 }
1303                 changed |= WIPHY_PARAM_RETRY_SHORT;
1304         }
1305
1306         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1307                 retry_long = nla_get_u8(
1308                         info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1309                 if (retry_long == 0) {
1310                         result = -EINVAL;
1311                         goto bad_res;
1312                 }
1313                 changed |= WIPHY_PARAM_RETRY_LONG;
1314         }
1315
1316         if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1317                 frag_threshold = nla_get_u32(
1318                         info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1319                 if (frag_threshold < 256) {
1320                         result = -EINVAL;
1321                         goto bad_res;
1322                 }
1323                 if (frag_threshold != (u32) -1) {
1324                         /*
1325                          * Fragments (apart from the last one) are required to
1326                          * have even length. Make the fragmentation code
1327                          * simpler by stripping LSB should someone try to use
1328                          * odd threshold value.
1329                          */
1330                         frag_threshold &= ~0x1;
1331                 }
1332                 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1333         }
1334
1335         if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1336                 rts_threshold = nla_get_u32(
1337                         info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1338                 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1339         }
1340
1341         if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1342                 coverage_class = nla_get_u8(
1343                         info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1344                 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1345         }
1346
1347         if (changed) {
1348                 u8 old_retry_short, old_retry_long;
1349                 u32 old_frag_threshold, old_rts_threshold;
1350                 u8 old_coverage_class;
1351
1352                 if (!rdev->ops->set_wiphy_params) {
1353                         result = -EOPNOTSUPP;
1354                         goto bad_res;
1355                 }
1356
1357                 old_retry_short = rdev->wiphy.retry_short;
1358                 old_retry_long = rdev->wiphy.retry_long;
1359                 old_frag_threshold = rdev->wiphy.frag_threshold;
1360                 old_rts_threshold = rdev->wiphy.rts_threshold;
1361                 old_coverage_class = rdev->wiphy.coverage_class;
1362
1363                 if (changed & WIPHY_PARAM_RETRY_SHORT)
1364                         rdev->wiphy.retry_short = retry_short;
1365                 if (changed & WIPHY_PARAM_RETRY_LONG)
1366                         rdev->wiphy.retry_long = retry_long;
1367                 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1368                         rdev->wiphy.frag_threshold = frag_threshold;
1369                 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1370                         rdev->wiphy.rts_threshold = rts_threshold;
1371                 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1372                         rdev->wiphy.coverage_class = coverage_class;
1373
1374                 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1375                 if (result) {
1376                         rdev->wiphy.retry_short = old_retry_short;
1377                         rdev->wiphy.retry_long = old_retry_long;
1378                         rdev->wiphy.frag_threshold = old_frag_threshold;
1379                         rdev->wiphy.rts_threshold = old_rts_threshold;
1380                         rdev->wiphy.coverage_class = old_coverage_class;
1381                 }
1382         }
1383
1384  bad_res:
1385         mutex_unlock(&rdev->mtx);
1386         if (netdev)
1387                 dev_put(netdev);
1388         return result;
1389 }
1390
1391
1392 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
1393                               struct cfg80211_registered_device *rdev,
1394                               struct net_device *dev)
1395 {
1396         void *hdr;
1397
1398         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1399         if (!hdr)
1400                 return -1;
1401
1402         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1403         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
1404         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
1405         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
1406
1407         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1408                     rdev->devlist_generation ^
1409                         (cfg80211_rdev_list_generation << 2));
1410
1411         return genlmsg_end(msg, hdr);
1412
1413  nla_put_failure:
1414         genlmsg_cancel(msg, hdr);
1415         return -EMSGSIZE;
1416 }
1417
1418 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1419 {
1420         int wp_idx = 0;
1421         int if_idx = 0;
1422         int wp_start = cb->args[0];
1423         int if_start = cb->args[1];
1424         struct cfg80211_registered_device *rdev;
1425         struct wireless_dev *wdev;
1426
1427         mutex_lock(&cfg80211_mutex);
1428         list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1429                 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
1430                         continue;
1431                 if (wp_idx < wp_start) {
1432                         wp_idx++;
1433                         continue;
1434                 }
1435                 if_idx = 0;
1436
1437                 mutex_lock(&rdev->devlist_mtx);
1438                 list_for_each_entry(wdev, &rdev->netdev_list, list) {
1439                         if (if_idx < if_start) {
1440                                 if_idx++;
1441                                 continue;
1442                         }
1443                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1444                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
1445                                                rdev, wdev->netdev) < 0) {
1446                                 mutex_unlock(&rdev->devlist_mtx);
1447                                 goto out;
1448                         }
1449                         if_idx++;
1450                 }
1451                 mutex_unlock(&rdev->devlist_mtx);
1452
1453                 wp_idx++;
1454         }
1455  out:
1456         mutex_unlock(&cfg80211_mutex);
1457
1458         cb->args[0] = wp_idx;
1459         cb->args[1] = if_idx;
1460
1461         return skb->len;
1462 }
1463
1464 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1465 {
1466         struct sk_buff *msg;
1467         struct cfg80211_registered_device *dev = info->user_ptr[0];
1468         struct net_device *netdev = info->user_ptr[1];
1469
1470         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1471         if (!msg)
1472                 return -ENOMEM;
1473
1474         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1475                                dev, netdev) < 0) {
1476                 nlmsg_free(msg);
1477                 return -ENOBUFS;
1478         }
1479
1480         return genlmsg_reply(msg, info);
1481 }
1482
1483 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1484         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1485         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1486         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1487         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1488         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1489 };
1490
1491 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1492 {
1493         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1494         int flag;
1495
1496         *mntrflags = 0;
1497
1498         if (!nla)
1499                 return -EINVAL;
1500
1501         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1502                              nla, mntr_flags_policy))
1503                 return -EINVAL;
1504
1505         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1506                 if (flags[flag])
1507                         *mntrflags |= (1<<flag);
1508
1509         return 0;
1510 }
1511
1512 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
1513                                struct net_device *netdev, u8 use_4addr,
1514                                enum nl80211_iftype iftype)
1515 {
1516         if (!use_4addr) {
1517                 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
1518                         return -EBUSY;
1519                 return 0;
1520         }
1521
1522         switch (iftype) {
1523         case NL80211_IFTYPE_AP_VLAN:
1524                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1525                         return 0;
1526                 break;
1527         case NL80211_IFTYPE_STATION:
1528                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1529                         return 0;
1530                 break;
1531         default:
1532                 break;
1533         }
1534
1535         return -EOPNOTSUPP;
1536 }
1537
1538 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1539 {
1540         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1541         struct vif_params params;
1542         int err;
1543         enum nl80211_iftype otype, ntype;
1544         struct net_device *dev = info->user_ptr[1];
1545         u32 _flags, *flags = NULL;
1546         bool change = false;
1547
1548         memset(&params, 0, sizeof(params));
1549
1550         otype = ntype = dev->ieee80211_ptr->iftype;
1551
1552         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1553                 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1554                 if (otype != ntype)
1555                         change = true;
1556                 if (ntype > NL80211_IFTYPE_MAX)
1557                         return -EINVAL;
1558         }
1559
1560         if (info->attrs[NL80211_ATTR_MESH_ID]) {
1561                 struct wireless_dev *wdev = dev->ieee80211_ptr;
1562
1563                 if (ntype != NL80211_IFTYPE_MESH_POINT)
1564                         return -EINVAL;
1565                 if (netif_running(dev))
1566                         return -EBUSY;
1567
1568                 wdev_lock(wdev);
1569                 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1570                              IEEE80211_MAX_MESH_ID_LEN);
1571                 wdev->mesh_id_up_len =
1572                         nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1573                 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1574                        wdev->mesh_id_up_len);
1575                 wdev_unlock(wdev);
1576         }
1577
1578         if (info->attrs[NL80211_ATTR_4ADDR]) {
1579                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1580                 change = true;
1581                 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1582                 if (err)
1583                         return err;
1584         } else {
1585                 params.use_4addr = -1;
1586         }
1587
1588         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1589                 if (ntype != NL80211_IFTYPE_MONITOR)
1590                         return -EINVAL;
1591                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1592                                           &_flags);
1593                 if (err)
1594                         return err;
1595
1596                 flags = &_flags;
1597                 change = true;
1598         }
1599
1600         if (change)
1601                 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1602         else
1603                 err = 0;
1604
1605         if (!err && params.use_4addr != -1)
1606                 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1607
1608         return err;
1609 }
1610
1611 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1612 {
1613         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1614         struct vif_params params;
1615         struct net_device *dev;
1616         int err;
1617         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1618         u32 flags;
1619
1620         memset(&params, 0, sizeof(params));
1621
1622         if (!info->attrs[NL80211_ATTR_IFNAME])
1623                 return -EINVAL;
1624
1625         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1626                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1627                 if (type > NL80211_IFTYPE_MAX)
1628                         return -EINVAL;
1629         }
1630
1631         if (!rdev->ops->add_virtual_intf ||
1632             !(rdev->wiphy.interface_modes & (1 << type)))
1633                 return -EOPNOTSUPP;
1634
1635         if (info->attrs[NL80211_ATTR_4ADDR]) {
1636                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1637                 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1638                 if (err)
1639                         return err;
1640         }
1641
1642         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1643                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1644                                   &flags);
1645         dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
1646                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1647                 type, err ? NULL : &flags, &params);
1648         if (IS_ERR(dev))
1649                 return PTR_ERR(dev);
1650
1651         if (type == NL80211_IFTYPE_MESH_POINT &&
1652             info->attrs[NL80211_ATTR_MESH_ID]) {
1653                 struct wireless_dev *wdev = dev->ieee80211_ptr;
1654
1655                 wdev_lock(wdev);
1656                 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1657                              IEEE80211_MAX_MESH_ID_LEN);
1658                 wdev->mesh_id_up_len =
1659                         nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1660                 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1661                        wdev->mesh_id_up_len);
1662                 wdev_unlock(wdev);
1663         }
1664
1665         return 0;
1666 }
1667
1668 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1669 {
1670         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1671         struct net_device *dev = info->user_ptr[1];
1672
1673         if (!rdev->ops->del_virtual_intf)
1674                 return -EOPNOTSUPP;
1675
1676         return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1677 }
1678
1679 struct get_key_cookie {
1680         struct sk_buff *msg;
1681         int error;
1682         int idx;
1683 };
1684
1685 static void get_key_callback(void *c, struct key_params *params)
1686 {
1687         struct nlattr *key;
1688         struct get_key_cookie *cookie = c;
1689
1690         if (params->key)
1691                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1692                         params->key_len, params->key);
1693
1694         if (params->seq)
1695                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1696                         params->seq_len, params->seq);
1697
1698         if (params->cipher)
1699                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1700                             params->cipher);
1701
1702         key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1703         if (!key)
1704                 goto nla_put_failure;
1705
1706         if (params->key)
1707                 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1708                         params->key_len, params->key);
1709
1710         if (params->seq)
1711                 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1712                         params->seq_len, params->seq);
1713
1714         if (params->cipher)
1715                 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1716                             params->cipher);
1717
1718         NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1719
1720         nla_nest_end(cookie->msg, key);
1721
1722         return;
1723  nla_put_failure:
1724         cookie->error = 1;
1725 }
1726
1727 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1728 {
1729         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1730         int err;
1731         struct net_device *dev = info->user_ptr[1];
1732         u8 key_idx = 0;
1733         const u8 *mac_addr = NULL;
1734         bool pairwise;
1735         struct get_key_cookie cookie = {
1736                 .error = 0,
1737         };
1738         void *hdr;
1739         struct sk_buff *msg;
1740
1741         if (info->attrs[NL80211_ATTR_KEY_IDX])
1742                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1743
1744         if (key_idx > 5)
1745                 return -EINVAL;
1746
1747         if (info->attrs[NL80211_ATTR_MAC])
1748                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1749
1750         pairwise = !!mac_addr;
1751         if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1752                 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1753                 if (kt >= NUM_NL80211_KEYTYPES)
1754                         return -EINVAL;
1755                 if (kt != NL80211_KEYTYPE_GROUP &&
1756                     kt != NL80211_KEYTYPE_PAIRWISE)
1757                         return -EINVAL;
1758                 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1759         }
1760
1761         if (!rdev->ops->get_key)
1762                 return -EOPNOTSUPP;
1763
1764         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1765         if (!msg)
1766                 return -ENOMEM;
1767
1768         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1769                              NL80211_CMD_NEW_KEY);
1770         if (IS_ERR(hdr))
1771                 return PTR_ERR(hdr);
1772
1773         cookie.msg = msg;
1774         cookie.idx = key_idx;
1775
1776         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1777         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1778         if (mac_addr)
1779                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1780
1781         if (pairwise && mac_addr &&
1782             !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1783                 return -ENOENT;
1784
1785         err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1786                                  mac_addr, &cookie, get_key_callback);
1787
1788         if (err)
1789                 goto free_msg;
1790
1791         if (cookie.error)
1792                 goto nla_put_failure;
1793
1794         genlmsg_end(msg, hdr);
1795         return genlmsg_reply(msg, info);
1796
1797  nla_put_failure:
1798         err = -ENOBUFS;
1799  free_msg:
1800         nlmsg_free(msg);
1801         return err;
1802 }
1803
1804 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1805 {
1806         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1807         struct key_parse key;
1808         int err;
1809         struct net_device *dev = info->user_ptr[1];
1810
1811         err = nl80211_parse_key(info, &key);
1812         if (err)
1813                 return err;
1814
1815         if (key.idx < 0)
1816                 return -EINVAL;
1817
1818         /* only support setting default key */
1819         if (!key.def && !key.defmgmt)
1820                 return -EINVAL;
1821
1822         wdev_lock(dev->ieee80211_ptr);
1823
1824         if (key.def) {
1825                 if (!rdev->ops->set_default_key) {
1826                         err = -EOPNOTSUPP;
1827                         goto out;
1828                 }
1829
1830                 err = nl80211_key_allowed(dev->ieee80211_ptr);
1831                 if (err)
1832                         goto out;
1833
1834                 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1835                                                  key.def_uni, key.def_multi);
1836
1837                 if (err)
1838                         goto out;
1839
1840 #ifdef CONFIG_CFG80211_WEXT
1841                 dev->ieee80211_ptr->wext.default_key = key.idx;
1842 #endif
1843         } else {
1844                 if (key.def_uni || !key.def_multi) {
1845                         err = -EINVAL;
1846                         goto out;
1847                 }
1848
1849                 if (!rdev->ops->set_default_mgmt_key) {
1850                         err = -EOPNOTSUPP;
1851                         goto out;
1852                 }
1853
1854                 err = nl80211_key_allowed(dev->ieee80211_ptr);
1855                 if (err)
1856                         goto out;
1857
1858                 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1859                                                       dev, key.idx);
1860                 if (err)
1861                         goto out;
1862
1863 #ifdef CONFIG_CFG80211_WEXT
1864                 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1865 #endif
1866         }
1867
1868  out:
1869         wdev_unlock(dev->ieee80211_ptr);
1870
1871         return err;
1872 }
1873
1874 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1875 {
1876         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1877         int err;
1878         struct net_device *dev = info->user_ptr[1];
1879         struct key_parse key;
1880         const u8 *mac_addr = NULL;
1881
1882         err = nl80211_parse_key(info, &key);
1883         if (err)
1884                 return err;
1885
1886         if (!key.p.key)
1887                 return -EINVAL;
1888
1889         if (info->attrs[NL80211_ATTR_MAC])
1890                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1891
1892         if (key.type == -1) {
1893                 if (mac_addr)
1894                         key.type = NL80211_KEYTYPE_PAIRWISE;
1895                 else
1896                         key.type = NL80211_KEYTYPE_GROUP;
1897         }
1898
1899         /* for now */
1900         if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1901             key.type != NL80211_KEYTYPE_GROUP)
1902                 return -EINVAL;
1903
1904         if (!rdev->ops->add_key)
1905                 return -EOPNOTSUPP;
1906
1907         if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1908                                            key.type == NL80211_KEYTYPE_PAIRWISE,
1909                                            mac_addr))
1910                 return -EINVAL;
1911
1912         wdev_lock(dev->ieee80211_ptr);
1913         err = nl80211_key_allowed(dev->ieee80211_ptr);
1914         if (!err)
1915                 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1916                                          key.type == NL80211_KEYTYPE_PAIRWISE,
1917                                          mac_addr, &key.p);
1918         wdev_unlock(dev->ieee80211_ptr);
1919
1920         return err;
1921 }
1922
1923 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1924 {
1925         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1926         int err;
1927         struct net_device *dev = info->user_ptr[1];
1928         u8 *mac_addr = NULL;
1929         struct key_parse key;
1930
1931         err = nl80211_parse_key(info, &key);
1932         if (err)
1933                 return err;
1934
1935         if (info->attrs[NL80211_ATTR_MAC])
1936                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1937
1938         if (key.type == -1) {
1939                 if (mac_addr)
1940                         key.type = NL80211_KEYTYPE_PAIRWISE;
1941                 else
1942                         key.type = NL80211_KEYTYPE_GROUP;
1943         }
1944
1945         /* for now */
1946         if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1947             key.type != NL80211_KEYTYPE_GROUP)
1948                 return -EINVAL;
1949
1950         if (!rdev->ops->del_key)
1951                 return -EOPNOTSUPP;
1952
1953         wdev_lock(dev->ieee80211_ptr);
1954         err = nl80211_key_allowed(dev->ieee80211_ptr);
1955
1956         if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1957             !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1958                 err = -ENOENT;
1959
1960         if (!err)
1961                 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1962                                          key.type == NL80211_KEYTYPE_PAIRWISE,
1963                                          mac_addr);
1964
1965 #ifdef CONFIG_CFG80211_WEXT
1966         if (!err) {
1967                 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1968                         dev->ieee80211_ptr->wext.default_key = -1;
1969                 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1970                         dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1971         }
1972 #endif
1973         wdev_unlock(dev->ieee80211_ptr);
1974
1975         return err;
1976 }
1977
1978 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1979 {
1980         int (*call)(struct wiphy *wiphy, struct net_device *dev,
1981                     struct beacon_parameters *info);
1982         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1983         struct net_device *dev = info->user_ptr[1];
1984         struct wireless_dev *wdev = dev->ieee80211_ptr;
1985         struct beacon_parameters params;
1986         int haveinfo = 0, err;
1987
1988         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1989                 return -EINVAL;
1990
1991         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1992             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1993                 return -EOPNOTSUPP;
1994
1995         memset(&params, 0, sizeof(params));
1996
1997         switch (info->genlhdr->cmd) {
1998         case NL80211_CMD_NEW_BEACON:
1999                 /* these are required for NEW_BEACON */
2000                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2001                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2002                     !info->attrs[NL80211_ATTR_BEACON_HEAD])
2003                         return -EINVAL;
2004
2005                 params.interval =
2006                         nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2007                 params.dtim_period =
2008                         nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2009
2010                 err = cfg80211_validate_beacon_int(rdev, params.interval);
2011                 if (err)
2012                         return err;
2013
2014                 call = rdev->ops->add_beacon;
2015                 break;
2016         case NL80211_CMD_SET_BEACON:
2017                 call = rdev->ops->set_beacon;
2018                 break;
2019         default:
2020                 WARN_ON(1);
2021                 return -EOPNOTSUPP;
2022         }
2023
2024         if (!call)
2025                 return -EOPNOTSUPP;
2026
2027         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
2028                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2029                 params.head_len =
2030                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2031                 haveinfo = 1;
2032         }
2033
2034         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
2035                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2036                 params.tail_len =
2037                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2038                 haveinfo = 1;
2039         }
2040
2041         if (!haveinfo)
2042                 return -EINVAL;
2043
2044         err = call(&rdev->wiphy, dev, &params);
2045         if (!err && params.interval)
2046                 wdev->beacon_interval = params.interval;
2047         return err;
2048 }
2049
2050 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
2051 {
2052         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2053         struct net_device *dev = info->user_ptr[1];
2054         struct wireless_dev *wdev = dev->ieee80211_ptr;
2055         int err;
2056
2057         if (!rdev->ops->del_beacon)
2058                 return -EOPNOTSUPP;
2059
2060         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2061             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2062                 return -EOPNOTSUPP;
2063
2064         err = rdev->ops->del_beacon(&rdev->wiphy, dev);
2065         if (!err)
2066                 wdev->beacon_interval = 0;
2067         return err;
2068 }
2069
2070 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2071         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2072         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2073         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
2074         [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
2075         [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
2076 };
2077
2078 static int parse_station_flags(struct genl_info *info,
2079                                struct station_parameters *params)
2080 {
2081         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
2082         struct nlattr *nla;
2083         int flag;
2084
2085         /*
2086          * Try parsing the new attribute first so userspace
2087          * can specify both for older kernels.
2088          */
2089         nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2090         if (nla) {
2091                 struct nl80211_sta_flag_update *sta_flags;
2092
2093                 sta_flags = nla_data(nla);
2094                 params->sta_flags_mask = sta_flags->mask;
2095                 params->sta_flags_set = sta_flags->set;
2096                 if ((params->sta_flags_mask |
2097                      params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2098                         return -EINVAL;
2099                 return 0;
2100         }
2101
2102         /* if present, parse the old attribute */
2103
2104         nla = info->attrs[NL80211_ATTR_STA_FLAGS];
2105         if (!nla)
2106                 return 0;
2107
2108         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2109                              nla, sta_flags_policy))
2110                 return -EINVAL;
2111
2112         params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
2113         params->sta_flags_mask &= ~1;
2114
2115         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2116                 if (flags[flag])
2117                         params->sta_flags_set |= (1<<flag);
2118
2119         return 0;
2120 }
2121
2122 static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2123                                  int attr)
2124 {
2125         struct nlattr *rate;
2126         u16 bitrate;
2127
2128         rate = nla_nest_start(msg, attr);
2129         if (!rate)
2130                 goto nla_put_failure;
2131
2132         /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2133         bitrate = cfg80211_calculate_bitrate(info);
2134         if (bitrate > 0)
2135                 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2136
2137         if (info->flags & RATE_INFO_FLAGS_MCS)
2138                 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2139         if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2140                 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2141         if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2142                 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2143
2144         nla_nest_end(msg, rate);
2145         return true;
2146
2147 nla_put_failure:
2148         return false;
2149 }
2150
2151 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2152                                 int flags, struct net_device *dev,
2153                                 const u8 *mac_addr, struct station_info *sinfo)
2154 {
2155         void *hdr;
2156         struct nlattr *sinfoattr, *bss_param;
2157
2158         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2159         if (!hdr)
2160                 return -1;
2161
2162         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2163         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2164
2165         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2166
2167         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2168         if (!sinfoattr)
2169                 goto nla_put_failure;
2170         if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2171                 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2172                             sinfo->connected_time);
2173         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2174                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2175                             sinfo->inactive_time);
2176         if (sinfo->filled & STATION_INFO_RX_BYTES)
2177                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2178                             sinfo->rx_bytes);
2179         if (sinfo->filled & STATION_INFO_TX_BYTES)
2180                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2181                             sinfo->tx_bytes);
2182         if (sinfo->filled & STATION_INFO_LLID)
2183                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2184                             sinfo->llid);
2185         if (sinfo->filled & STATION_INFO_PLID)
2186                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2187                             sinfo->plid);
2188         if (sinfo->filled & STATION_INFO_PLINK_STATE)
2189                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2190                             sinfo->plink_state);
2191         if (sinfo->filled & STATION_INFO_SIGNAL)
2192                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2193                            sinfo->signal);
2194         if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2195                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2196                            sinfo->signal_avg);
2197         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
2198                 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2199                                           NL80211_STA_INFO_TX_BITRATE))
2200                         goto nla_put_failure;
2201         }
2202         if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2203                 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2204                                           NL80211_STA_INFO_RX_BITRATE))
2205                         goto nla_put_failure;
2206         }
2207         if (sinfo->filled & STATION_INFO_RX_PACKETS)
2208                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2209                             sinfo->rx_packets);
2210         if (sinfo->filled & STATION_INFO_TX_PACKETS)
2211                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2212                             sinfo->tx_packets);
2213         if (sinfo->filled & STATION_INFO_TX_RETRIES)
2214                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2215                             sinfo->tx_retries);
2216         if (sinfo->filled & STATION_INFO_TX_FAILED)
2217                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2218                             sinfo->tx_failed);
2219         if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2220                 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2221                 if (!bss_param)
2222                         goto nla_put_failure;
2223
2224                 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2225                         NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2226                 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2227                         NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2228                 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2229                         NLA_PUT_FLAG(msg,
2230                                      NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2231                 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2232                            sinfo->bss_param.dtim_period);
2233                 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2234                             sinfo->bss_param.beacon_interval);
2235
2236                 nla_nest_end(msg, bss_param);
2237         }
2238         nla_nest_end(msg, sinfoattr);
2239
2240         return genlmsg_end(msg, hdr);
2241
2242  nla_put_failure:
2243         genlmsg_cancel(msg, hdr);
2244         return -EMSGSIZE;
2245 }
2246
2247 static int nl80211_dump_station(struct sk_buff *skb,
2248                                 struct netlink_callback *cb)
2249 {
2250         struct station_info sinfo;
2251         struct cfg80211_registered_device *dev;
2252         struct net_device *netdev;
2253         u8 mac_addr[ETH_ALEN];
2254         int sta_idx = cb->args[1];
2255         int err;
2256
2257         err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2258         if (err)
2259                 return err;
2260
2261         if (!dev->ops->dump_station) {
2262                 err = -EOPNOTSUPP;
2263                 goto out_err;
2264         }
2265
2266         while (1) {
2267                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2268                                              mac_addr, &sinfo);
2269                 if (err == -ENOENT)
2270                         break;
2271                 if (err)
2272                         goto out_err;
2273
2274                 if (nl80211_send_station(skb,
2275                                 NETLINK_CB(cb->skb).pid,
2276                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2277                                 netdev, mac_addr,
2278                                 &sinfo) < 0)
2279                         goto out;
2280
2281                 sta_idx++;
2282         }
2283
2284
2285  out:
2286         cb->args[1] = sta_idx;
2287         err = skb->len;
2288  out_err:
2289         nl80211_finish_netdev_dump(dev);
2290
2291         return err;
2292 }
2293
2294 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2295 {
2296         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2297         struct net_device *dev = info->user_ptr[1];
2298         struct station_info sinfo;
2299         struct sk_buff *msg;
2300         u8 *mac_addr = NULL;
2301         int err;
2302
2303         memset(&sinfo, 0, sizeof(sinfo));
2304
2305         if (!info->attrs[NL80211_ATTR_MAC])
2306                 return -EINVAL;
2307
2308         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2309
2310         if (!rdev->ops->get_station)
2311                 return -EOPNOTSUPP;
2312
2313         err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2314         if (err)
2315                 return err;
2316
2317         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2318         if (!msg)
2319                 return -ENOMEM;
2320
2321         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2322                                  dev, mac_addr, &sinfo) < 0) {
2323                 nlmsg_free(msg);
2324                 return -ENOBUFS;
2325         }
2326
2327         return genlmsg_reply(msg, info);
2328 }
2329
2330 /*
2331  * Get vlan interface making sure it is running and on the right wiphy.
2332  */
2333 static int get_vlan(struct genl_info *info,
2334                     struct cfg80211_registered_device *rdev,
2335                     struct net_device **vlan)
2336 {
2337         struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
2338         *vlan = NULL;
2339
2340         if (vlanattr) {
2341                 *vlan = dev_get_by_index(genl_info_net(info),
2342                                          nla_get_u32(vlanattr));
2343                 if (!*vlan)
2344                         return -ENODEV;
2345                 if (!(*vlan)->ieee80211_ptr)
2346                         return -EINVAL;
2347                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2348                         return -EINVAL;
2349                 if (!netif_running(*vlan))
2350                         return -ENETDOWN;
2351         }
2352         return 0;
2353 }
2354
2355 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2356 {
2357         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2358         int err;
2359         struct net_device *dev = info->user_ptr[1];
2360         struct station_parameters params;
2361         u8 *mac_addr = NULL;
2362
2363         memset(&params, 0, sizeof(params));
2364
2365         params.listen_interval = -1;
2366         params.plink_state = -1;
2367
2368         if (info->attrs[NL80211_ATTR_STA_AID])
2369                 return -EINVAL;
2370
2371         if (!info->attrs[NL80211_ATTR_MAC])
2372                 return -EINVAL;
2373
2374         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2375
2376         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2377                 params.supported_rates =
2378                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2379                 params.supported_rates_len =
2380                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2381         }
2382
2383         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2384                 params.listen_interval =
2385                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2386
2387         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2388                 params.ht_capa =
2389                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2390
2391         if (parse_station_flags(info, &params))
2392                 return -EINVAL;
2393
2394         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2395                 params.plink_action =
2396                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2397
2398         if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2399                 params.plink_state =
2400                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2401
2402         err = get_vlan(info, rdev, &params.vlan);
2403         if (err)
2404                 goto out;
2405
2406         /* validate settings */
2407         err = 0;
2408
2409         switch (dev->ieee80211_ptr->iftype) {
2410         case NL80211_IFTYPE_AP:
2411         case NL80211_IFTYPE_AP_VLAN:
2412         case NL80211_IFTYPE_P2P_GO:
2413                 /* disallow mesh-specific things */
2414                 if (params.plink_action)
2415                         err = -EINVAL;
2416                 break;
2417         case NL80211_IFTYPE_P2P_CLIENT:
2418         case NL80211_IFTYPE_STATION:
2419                 /* disallow everything but AUTHORIZED flag */
2420                 if (params.plink_action)
2421                         err = -EINVAL;
2422                 if (params.vlan)
2423                         err = -EINVAL;
2424                 if (params.supported_rates)
2425                         err = -EINVAL;
2426                 if (params.ht_capa)
2427                         err = -EINVAL;
2428                 if (params.listen_interval >= 0)
2429                         err = -EINVAL;
2430                 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2431                         err = -EINVAL;
2432                 break;
2433         case NL80211_IFTYPE_MESH_POINT:
2434                 /* disallow things mesh doesn't support */
2435                 if (params.vlan)
2436                         err = -EINVAL;
2437                 if (params.ht_capa)
2438                         err = -EINVAL;
2439                 if (params.listen_interval >= 0)
2440                         err = -EINVAL;
2441                 if (params.sta_flags_mask &
2442                                 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2443                                   BIT(NL80211_STA_FLAG_MFP) |
2444                                   BIT(NL80211_STA_FLAG_AUTHORIZED)))
2445                         err = -EINVAL;
2446                 break;
2447         default:
2448                 err = -EINVAL;
2449         }
2450
2451         if (err)
2452                 goto out;
2453
2454         if (!rdev->ops->change_station) {
2455                 err = -EOPNOTSUPP;
2456                 goto out;
2457         }
2458
2459         err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
2460
2461  out:
2462         if (params.vlan)
2463                 dev_put(params.vlan);
2464
2465         return err;
2466 }
2467
2468 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2469 {
2470         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2471         int err;
2472         struct net_device *dev = info->user_ptr[1];
2473         struct station_parameters params;
2474         u8 *mac_addr = NULL;
2475
2476         memset(&params, 0, sizeof(params));
2477
2478         if (!info->attrs[NL80211_ATTR_MAC])
2479                 return -EINVAL;
2480
2481         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2482                 return -EINVAL;
2483
2484         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2485                 return -EINVAL;
2486
2487         if (!info->attrs[NL80211_ATTR_STA_AID])
2488                 return -EINVAL;
2489
2490         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2491         params.supported_rates =
2492                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2493         params.supported_rates_len =
2494                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2495         params.listen_interval =
2496                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2497
2498         params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2499         if (!params.aid || params.aid > IEEE80211_MAX_AID)
2500                 return -EINVAL;
2501
2502         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2503                 params.ht_capa =
2504                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2505
2506         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2507                 params.plink_action =
2508                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2509
2510         if (parse_station_flags(info, &params))
2511                 return -EINVAL;
2512
2513         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2514             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2515             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2516             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2517                 return -EINVAL;
2518
2519         err = get_vlan(info, rdev, &params.vlan);
2520         if (err)
2521                 goto out;
2522
2523         /* validate settings */
2524         err = 0;
2525
2526         if (!rdev->ops->add_station) {
2527                 err = -EOPNOTSUPP;
2528                 goto out;
2529         }
2530
2531         err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2532
2533  out:
2534         if (params.vlan)
2535                 dev_put(params.vlan);
2536         return err;
2537 }
2538
2539 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2540 {
2541         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2542         struct net_device *dev = info->user_ptr[1];
2543         u8 *mac_addr = NULL;
2544
2545         if (info->attrs[NL80211_ATTR_MAC])
2546                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2547
2548         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2549             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2550             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2551             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2552                 return -EINVAL;
2553
2554         if (!rdev->ops->del_station)
2555                 return -EOPNOTSUPP;
2556
2557         return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2558 }
2559
2560 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2561                                 int flags, struct net_device *dev,
2562                                 u8 *dst, u8 *next_hop,
2563                                 struct mpath_info *pinfo)
2564 {
2565         void *hdr;
2566         struct nlattr *pinfoattr;
2567
2568         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2569         if (!hdr)
2570                 return -1;
2571
2572         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2573         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2574         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2575
2576         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2577
2578         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2579         if (!pinfoattr)
2580                 goto nla_put_failure;
2581         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2582                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2583                             pinfo->frame_qlen);
2584         if (pinfo->filled & MPATH_INFO_SN)
2585                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2586                             pinfo->sn);
2587         if (pinfo->filled & MPATH_INFO_METRIC)
2588                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2589                             pinfo->metric);
2590         if (pinfo->filled & MPATH_INFO_EXPTIME)
2591                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2592                             pinfo->exptime);
2593         if (pinfo->filled & MPATH_INFO_FLAGS)
2594                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2595                             pinfo->flags);
2596         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2597                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2598                             pinfo->discovery_timeout);
2599         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2600                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2601                             pinfo->discovery_retries);
2602
2603         nla_nest_end(msg, pinfoattr);
2604
2605         return genlmsg_end(msg, hdr);
2606
2607  nla_put_failure:
2608         genlmsg_cancel(msg, hdr);
2609         return -EMSGSIZE;
2610 }
2611
2612 static int nl80211_dump_mpath(struct sk_buff *skb,
2613                               struct netlink_callback *cb)
2614 {
2615         struct mpath_info pinfo;
2616         struct cfg80211_registered_device *dev;
2617         struct net_device *netdev;
2618         u8 dst[ETH_ALEN];
2619         u8 next_hop[ETH_ALEN];
2620         int path_idx = cb->args[1];
2621         int err;
2622
2623         err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2624         if (err)
2625                 return err;
2626
2627         if (!dev->ops->dump_mpath) {
2628                 err = -EOPNOTSUPP;
2629                 goto out_err;
2630         }
2631
2632         if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2633                 err = -EOPNOTSUPP;
2634                 goto out_err;
2635         }
2636
2637         while (1) {
2638                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2639                                            dst, next_hop, &pinfo);
2640                 if (err == -ENOENT)
2641                         break;
2642                 if (err)
2643                         goto out_err;
2644
2645                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2646                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
2647                                        netdev, dst, next_hop,
2648                                        &pinfo) < 0)
2649                         goto out;
2650
2651                 path_idx++;
2652         }
2653
2654
2655  out:
2656         cb->args[1] = path_idx;
2657         err = skb->len;
2658  out_err:
2659         nl80211_finish_netdev_dump(dev);
2660         return err;
2661 }
2662
2663 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2664 {
2665         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2666         int err;
2667         struct net_device *dev = info->user_ptr[1];
2668         struct mpath_info pinfo;
2669         struct sk_buff *msg;
2670         u8 *dst = NULL;
2671         u8 next_hop[ETH_ALEN];
2672
2673         memset(&pinfo, 0, sizeof(pinfo));
2674
2675         if (!info->attrs[NL80211_ATTR_MAC])
2676                 return -EINVAL;
2677
2678         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2679
2680         if (!rdev->ops->get_mpath)
2681                 return -EOPNOTSUPP;
2682
2683         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2684                 return -EOPNOTSUPP;
2685
2686         err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2687         if (err)
2688                 return err;
2689
2690         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2691         if (!msg)
2692                 return -ENOMEM;
2693
2694         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2695                                  dev, dst, next_hop, &pinfo) < 0) {
2696                 nlmsg_free(msg);
2697                 return -ENOBUFS;
2698         }
2699
2700         return genlmsg_reply(msg, info);
2701 }
2702
2703 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2704 {
2705         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2706         struct net_device *dev = info->user_ptr[1];
2707         u8 *dst = NULL;
2708         u8 *next_hop = NULL;
2709
2710         if (!info->attrs[NL80211_ATTR_MAC])
2711                 return -EINVAL;
2712
2713         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2714                 return -EINVAL;
2715
2716         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2717         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2718
2719         if (!rdev->ops->change_mpath)
2720                 return -EOPNOTSUPP;
2721
2722         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2723                 return -EOPNOTSUPP;
2724
2725         return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2726 }
2727
2728 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2729 {
2730         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2731         struct net_device *dev = info->user_ptr[1];
2732         u8 *dst = NULL;
2733         u8 *next_hop = NULL;
2734
2735         if (!info->attrs[NL80211_ATTR_MAC])
2736                 return -EINVAL;
2737
2738         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2739                 return -EINVAL;
2740
2741         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2742         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2743
2744         if (!rdev->ops->add_mpath)
2745                 return -EOPNOTSUPP;
2746
2747         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2748                 return -EOPNOTSUPP;
2749
2750         return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2751 }
2752
2753 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2754 {
2755         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2756         struct net_device *dev = info->user_ptr[1];
2757         u8 *dst = NULL;
2758
2759         if (info->attrs[NL80211_ATTR_MAC])
2760                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2761
2762         if (!rdev->ops->del_mpath)
2763                 return -EOPNOTSUPP;
2764
2765         return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2766 }
2767
2768 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2769 {
2770         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2771         struct net_device *dev = info->user_ptr[1];
2772         struct bss_parameters params;
2773
2774         memset(&params, 0, sizeof(params));
2775         /* default to not changing parameters */
2776         params.use_cts_prot = -1;
2777         params.use_short_preamble = -1;
2778         params.use_short_slot_time = -1;
2779         params.ap_isolate = -1;
2780         params.ht_opmode = -1;
2781
2782         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2783                 params.use_cts_prot =
2784                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2785         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2786                 params.use_short_preamble =
2787                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2788         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2789                 params.use_short_slot_time =
2790                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2791         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2792                 params.basic_rates =
2793                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2794                 params.basic_rates_len =
2795                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2796         }
2797         if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2798                 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
2799         if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2800                 params.ht_opmode =
2801                         nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
2802
2803         if (!rdev->ops->change_bss)
2804                 return -EOPNOTSUPP;
2805
2806         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2807             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2808                 return -EOPNOTSUPP;
2809
2810         return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2811 }
2812
2813 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2814         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
2815         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
2816         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
2817         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
2818         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
2819         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
2820 };
2821
2822 static int parse_reg_rule(struct nlattr *tb[],
2823         struct ieee80211_reg_rule *reg_rule)
2824 {
2825         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2826         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2827
2828         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2829                 return -EINVAL;
2830         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2831                 return -EINVAL;
2832         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2833                 return -EINVAL;
2834         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2835                 return -EINVAL;
2836         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2837                 return -EINVAL;
2838
2839         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2840
2841         freq_range->start_freq_khz =
2842                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2843         freq_range->end_freq_khz =
2844                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2845         freq_range->max_bandwidth_khz =
2846                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2847
2848         power_rule->max_eirp =
2849                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2850
2851         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2852                 power_rule->max_antenna_gain =
2853                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2854
2855         return 0;
2856 }
2857
2858 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2859 {
2860         int r;
2861         char *data = NULL;
2862
2863         /*
2864          * You should only get this when cfg80211 hasn't yet initialized
2865          * completely when built-in to the kernel right between the time
2866          * window between nl80211_init() and regulatory_init(), if that is
2867          * even possible.
2868          */
2869         mutex_lock(&cfg80211_mutex);
2870         if (unlikely(!cfg80211_regdomain)) {
2871                 mutex_unlock(&cfg80211_mutex);
2872                 return -EINPROGRESS;
2873         }
2874         mutex_unlock(&cfg80211_mutex);
2875
2876         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2877                 return -EINVAL;
2878
2879         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2880
2881         r = regulatory_hint_user(data);
2882
2883         return r;
2884 }
2885
2886 static int nl80211_get_mesh_config(struct sk_buff *skb,
2887                                    struct genl_info *info)
2888 {
2889         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2890         struct net_device *dev = info->user_ptr[1];
2891         struct wireless_dev *wdev = dev->ieee80211_ptr;
2892         struct mesh_config cur_params;
2893         int err = 0;
2894         void *hdr;
2895         struct nlattr *pinfoattr;
2896         struct sk_buff *msg;
2897
2898         if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2899                 return -EOPNOTSUPP;
2900
2901         if (!rdev->ops->get_mesh_config)
2902                 return -EOPNOTSUPP;
2903
2904         wdev_lock(wdev);
2905         /* If not connected, get default parameters */
2906         if (!wdev->mesh_id_len)
2907                 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2908         else
2909                 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
2910                                                  &cur_params);
2911         wdev_unlock(wdev);
2912
2913         if (err)
2914                 return err;
2915
2916         /* Draw up a netlink message to send back */
2917         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2918         if (!msg)
2919                 return -ENOMEM;
2920         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2921                              NL80211_CMD_GET_MESH_CONFIG);
2922         if (!hdr)
2923                 goto out;
2924         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
2925         if (!pinfoattr)
2926                 goto nla_put_failure;
2927         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2928         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2929                         cur_params.dot11MeshRetryTimeout);
2930         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2931                         cur_params.dot11MeshConfirmTimeout);
2932         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2933                         cur_params.dot11MeshHoldingTimeout);
2934         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2935                         cur_params.dot11MeshMaxPeerLinks);
2936         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2937                         cur_params.dot11MeshMaxRetries);
2938         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2939                         cur_params.dot11MeshTTL);
2940         NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2941                         cur_params.element_ttl);
2942         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2943                         cur_params.auto_open_plinks);
2944         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2945                         cur_params.dot11MeshHWMPmaxPREQretries);
2946         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2947                         cur_params.path_refresh_time);
2948         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2949                         cur_params.min_discovery_timeout);
2950         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2951                         cur_params.dot11MeshHWMPactivePathTimeout);
2952         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2953                         cur_params.dot11MeshHWMPpreqMinInterval);
2954         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2955                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2956         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2957                         cur_params.dot11MeshHWMPRootMode);
2958         nla_nest_end(msg, pinfoattr);
2959         genlmsg_end(msg, hdr);
2960         return genlmsg_reply(msg, info);
2961
2962  nla_put_failure:
2963         genlmsg_cancel(msg, hdr);
2964  out:
2965         nlmsg_free(msg);
2966         return -ENOBUFS;
2967 }
2968
2969 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
2970         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2971         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2972         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2973         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2974         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2975         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2976         [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
2977         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2978
2979         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2980         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2981         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2982         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2983         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2984         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2985 };
2986
2987 static const struct nla_policy
2988         nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
2989         [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
2990         [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
2991         [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
2992         [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
2993                 .len = IEEE80211_MAX_DATA_LEN },
2994         [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
2995 };
2996
2997 static int nl80211_parse_mesh_config(struct genl_info *info,
2998                                      struct mesh_config *cfg,
2999                                      u32 *mask_out)
3000 {
3001         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
3002         u32 mask = 0;
3003
3004 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3005 do {\
3006         if (table[attr_num]) {\
3007                 cfg->param = nla_fn(table[attr_num]); \
3008                 mask |= (1 << (attr_num - 1)); \
3009         } \
3010 } while (0);\
3011
3012
3013         if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
3014                 return -EINVAL;
3015         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
3016                              info->attrs[NL80211_ATTR_MESH_CONFIG],
3017                              nl80211_meshconf_params_policy))
3018                 return -EINVAL;
3019
3020         /* This makes sure that there aren't more than 32 mesh config
3021          * parameters (otherwise our bitfield scheme would not work.) */
3022         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3023
3024         /* Fill in the params struct */
3025         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
3026                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
3027         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
3028                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
3029         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
3030                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
3031         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
3032                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
3033         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
3034                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
3035         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
3036                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
3037         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
3038                         mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
3039         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
3040                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
3041         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
3042                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3043                         nla_get_u8);
3044         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
3045                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
3046         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
3047                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3048                         nla_get_u16);
3049         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
3050                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3051                         nla_get_u32);
3052         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
3053                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3054                         nla_get_u16);
3055         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3056                         dot11MeshHWMPnetDiameterTraversalTime,
3057                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3058                         nla_get_u16);
3059         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3060                         dot11MeshHWMPRootMode, mask,
3061                         NL80211_MESHCONF_HWMP_ROOTMODE,
3062                         nla_get_u8);
3063         if (mask_out)
3064                 *mask_out = mask;
3065
3066         return 0;
3067
3068 #undef FILL_IN_MESH_PARAM_IF_SET
3069 }
3070
3071 static int nl80211_parse_mesh_setup(struct genl_info *info,
3072                                      struct mesh_setup *setup)
3073 {
3074         struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3075
3076         if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3077                 return -EINVAL;
3078         if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3079                              info->attrs[NL80211_ATTR_MESH_SETUP],
3080                              nl80211_mesh_setup_params_policy))
3081                 return -EINVAL;
3082
3083         if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3084                 setup->path_sel_proto =
3085                 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3086                  IEEE80211_PATH_PROTOCOL_VENDOR :
3087                  IEEE80211_PATH_PROTOCOL_HWMP;
3088
3089         if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3090                 setup->path_metric =
3091                 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3092                  IEEE80211_PATH_METRIC_VENDOR :
3093                  IEEE80211_PATH_METRIC_AIRTIME;
3094
3095
3096         if (tb[NL80211_MESH_SETUP_IE]) {
3097                 struct nlattr *ieattr =
3098                         tb[NL80211_MESH_SETUP_IE];
3099                 if (!is_valid_ie_attr(ieattr))
3100                         return -EINVAL;
3101                 setup->ie = nla_data(ieattr);
3102                 setup->ie_len = nla_len(ieattr);
3103         }
3104         setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3105         setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
3106
3107         return 0;
3108 }
3109
3110 static int nl80211_update_mesh_config(struct sk_buff *skb,
3111                                       struct genl_info *info)
3112 {
3113         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3114         struct net_device *dev = info->user_ptr[1];
3115         struct wireless_dev *wdev = dev->ieee80211_ptr;
3116         struct mesh_config cfg;
3117         u32 mask;
3118         int err;
3119
3120         if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3121                 return -EOPNOTSUPP;
3122
3123         if (!rdev->ops->update_mesh_config)
3124                 return -EOPNOTSUPP;
3125
3126         err = nl80211_parse_mesh_config(info, &cfg, &mask);
3127         if (err)
3128                 return err;
3129
3130         wdev_lock(wdev);
3131         if (!wdev->mesh_id_len)