1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006-2010	Johannes Berg <johannes@sipsolutions.net>
5  */
6 
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/slab.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <linux/etherdevice.h>
18 #include <net/net_namespace.h>
19 #include <net/genetlink.h>
20 #include <net/cfg80211.h>
21 #include <net/sock.h>
22 #include "core.h"
23 #include "nl80211.h"
24 #include "reg.h"
25 
26 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 				   struct genl_info *info,
29 				   struct cfg80211_crypto_settings *settings,
30 				   int cipher_limit);
31 
32 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 			    struct genl_info *info);
34 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 			      struct genl_info *info);
36 
37 /* the netlink family */
38 static struct genl_family nl80211_fam = {
39 	.id = GENL_ID_GENERATE,	/* don't bother with a hardcoded ID */
40 	.name = "nl80211",	/* have users key off the name instead */
41 	.hdrsize = 0,		/* no private header */
42 	.version = 1,		/* no particular meaning now */
43 	.maxattr = NL80211_ATTR_MAX,
44 	.netnsok = true,
45 	.pre_doit = nl80211_pre_doit,
46 	.post_doit = nl80211_post_doit,
47 };
48 
49 /* internal helper: get rdev and dev */
get_rdev_dev_by_ifindex(struct net * netns,struct nlattr ** attrs,struct cfg80211_registered_device ** rdev,struct net_device ** dev)50 static int get_rdev_dev_by_ifindex(struct net *netns, struct nlattr **attrs,
51 				   struct cfg80211_registered_device **rdev,
52 				   struct net_device **dev)
53 {
54 	int ifindex;
55 
56 	if (!attrs[NL80211_ATTR_IFINDEX])
57 		return -EINVAL;
58 
59 	ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
60 	*dev = dev_get_by_index(netns, ifindex);
61 	if (!*dev)
62 		return -ENODEV;
63 
64 	*rdev = cfg80211_get_dev_from_ifindex(netns, ifindex);
65 	if (IS_ERR(*rdev)) {
66 		dev_put(*dev);
67 		return PTR_ERR(*rdev);
68 	}
69 
70 	return 0;
71 }
72 
73 /* policy for the attributes */
74 static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
75 	[NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
76 	[NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
77 				      .len = 20-1 },
78 	[NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
79 	[NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
80 	[NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
81 	[NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
82 	[NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
83 	[NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
84 	[NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
85 	[NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
86 
87 	[NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
88 	[NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
89 	[NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
90 
91 	[NL80211_ATTR_MAC] = { .len = ETH_ALEN },
92 	[NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
93 
94 	[NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
95 	[NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
96 				    .len = WLAN_MAX_KEY_LEN },
97 	[NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
98 	[NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
99 	[NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
100 	[NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
101 	[NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
102 
103 	[NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
104 	[NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
105 	[NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
106 				       .len = IEEE80211_MAX_DATA_LEN },
107 	[NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
108 				       .len = IEEE80211_MAX_DATA_LEN },
109 	[NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
110 	[NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
111 	[NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
112 	[NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
113 					       .len = NL80211_MAX_SUPP_RATES },
114 	[NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
115 	[NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
116 	[NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
117 	[NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
118 				.len = IEEE80211_MAX_MESH_ID_LEN },
119 	[NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
120 
121 	[NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
122 	[NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
123 
124 	[NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
125 	[NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
126 	[NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
127 	[NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
128 					   .len = NL80211_MAX_SUPP_RATES },
129 	[NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
130 
131 	[NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
132 	[NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
133 
134 	[NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
135 
136 	[NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
137 	[NL80211_ATTR_IE] = { .type = NLA_BINARY,
138 			      .len = IEEE80211_MAX_DATA_LEN },
139 	[NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
140 	[NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
141 
142 	[NL80211_ATTR_SSID] = { .type = NLA_BINARY,
143 				.len = IEEE80211_MAX_SSID_LEN },
144 	[NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
145 	[NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
146 	[NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
147 	[NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
148 	[NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
149 	[NL80211_ATTR_STA_FLAGS2] = {
150 		.len = sizeof(struct nl80211_sta_flag_update),
151 	},
152 	[NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
153 	[NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
154 	[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
155 	[NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
156 	[NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
157 	[NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
158 	[NL80211_ATTR_PID] = { .type = NLA_U32 },
159 	[NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
160 	[NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
161 				 .len = WLAN_PMKID_LEN },
162 	[NL80211_ATTR_DURATION] = { .type = NLA_U32 },
163 	[NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
164 	[NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
165 	[NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
166 				 .len = IEEE80211_MAX_DATA_LEN },
167 	[NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
168 	[NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
169 	[NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
170 	[NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
171 	[NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
172 	[NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
173 	[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
174 	[NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
175 	[NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
176 	[NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
177 	[NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
178 	[NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
179 	[NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
180 	[NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
181 	[NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
182 	[NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
183 	[NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
184 	[NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
185 	[NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
186 	[NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
187 					 .len = IEEE80211_MAX_DATA_LEN },
188 	[NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
189 					 .len = IEEE80211_MAX_DATA_LEN },
190 	[NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
191 	[NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
192 	[NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
193 	[NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
194 	[NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
195 	[NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
196 	[NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
197 	[NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
198 	[NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
199 	[NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
200 				      .len = IEEE80211_MAX_DATA_LEN },
201 	[NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
202 	[NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
203 	[NL80211_ATTR_HT_CAPABILITY_MASK] = {
204 		.len = NL80211_HT_CAPABILITY_LEN
205 	},
206 	[NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
207 	[NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
208 	[NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
209 };
210 
211 /* policy for the key attributes */
212 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
213 	[NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
214 	[NL80211_KEY_IDX] = { .type = NLA_U8 },
215 	[NL80211_KEY_CIPHER] = { .type = NLA_U32 },
216 	[NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
217 	[NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
218 	[NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
219 	[NL80211_KEY_TYPE] = { .type = NLA_U32 },
220 	[NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
221 };
222 
223 /* policy for the key default flags */
224 static const struct nla_policy
225 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
226 	[NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
227 	[NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
228 };
229 
230 /* policy for WoWLAN attributes */
231 static const struct nla_policy
232 nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
233 	[NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
234 	[NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
235 	[NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
236 	[NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
237 	[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
238 	[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
239 	[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
240 	[NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
241 };
242 
243 /* policy for GTK rekey offload attributes */
244 static const struct nla_policy
245 nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
246 	[NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
247 	[NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
248 	[NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
249 };
250 
251 static const struct nla_policy
252 nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
253 	[NL80211_ATTR_SCHED_SCAN_MATCH_SSID] = { .type = NLA_BINARY,
254 						 .len = IEEE80211_MAX_SSID_LEN },
255 };
256 
257 /* ifidx get helper */
nl80211_get_ifidx(struct netlink_callback * cb)258 static int nl80211_get_ifidx(struct netlink_callback *cb)
259 {
260 	int res;
261 
262 	res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
263 			  nl80211_fam.attrbuf, nl80211_fam.maxattr,
264 			  nl80211_policy);
265 	if (res)
266 		return res;
267 
268 	if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
269 		return -EINVAL;
270 
271 	res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
272 	if (!res)
273 		return -EINVAL;
274 	return res;
275 }
276 
nl80211_prepare_netdev_dump(struct sk_buff * skb,struct netlink_callback * cb,struct cfg80211_registered_device ** rdev,struct net_device ** dev)277 static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
278 				       struct netlink_callback *cb,
279 				       struct cfg80211_registered_device **rdev,
280 				       struct net_device **dev)
281 {
282 	int ifidx = cb->args[0];
283 	int err;
284 
285 	if (!ifidx)
286 		ifidx = nl80211_get_ifidx(cb);
287 	if (ifidx < 0)
288 		return ifidx;
289 
290 	cb->args[0] = ifidx;
291 
292 	rtnl_lock();
293 
294 	*dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
295 	if (!*dev) {
296 		err = -ENODEV;
297 		goto out_rtnl;
298 	}
299 
300 	*rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
301 	if (IS_ERR(*rdev)) {
302 		err = PTR_ERR(*rdev);
303 		goto out_rtnl;
304 	}
305 
306 	return 0;
307  out_rtnl:
308 	rtnl_unlock();
309 	return err;
310 }
311 
nl80211_finish_netdev_dump(struct cfg80211_registered_device * rdev)312 static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
313 {
314 	cfg80211_unlock_rdev(rdev);
315 	rtnl_unlock();
316 }
317 
318 /* IE validation */
is_valid_ie_attr(const struct nlattr * attr)319 static bool is_valid_ie_attr(const struct nlattr *attr)
320 {
321 	const u8 *pos;
322 	int len;
323 
324 	if (!attr)
325 		return true;
326 
327 	pos = nla_data(attr);
328 	len = nla_len(attr);
329 
330 	while (len) {
331 		u8 elemlen;
332 
333 		if (len < 2)
334 			return false;
335 		len -= 2;
336 
337 		elemlen = pos[1];
338 		if (elemlen > len)
339 			return false;
340 
341 		len -= elemlen;
342 		pos += 2 + elemlen;
343 	}
344 
345 	return true;
346 }
347 
348 /* message building helper */
nl80211hdr_put(struct sk_buff * skb,u32 pid,u32 seq,int flags,u8 cmd)349 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
350 				   int flags, u8 cmd)
351 {
352 	/* since there is no private header just add the generic one */
353 	return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
354 }
355 
nl80211_msg_put_channel(struct sk_buff * msg,struct ieee80211_channel * chan)356 static int nl80211_msg_put_channel(struct sk_buff *msg,
357 				   struct ieee80211_channel *chan)
358 {
359 	NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
360 		    chan->center_freq);
361 
362 	if (chan->flags & IEEE80211_CHAN_DISABLED)
363 		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
364 	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
365 		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
366 	if (chan->flags & IEEE80211_CHAN_NO_IBSS)
367 		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
368 	if (chan->flags & IEEE80211_CHAN_RADAR)
369 		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
370 
371 	NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
372 		    DBM_TO_MBM(chan->max_power));
373 
374 	return 0;
375 
376  nla_put_failure:
377 	return -ENOBUFS;
378 }
379 
380 /* netlink command implementations */
381 
382 struct key_parse {
383 	struct key_params p;
384 	int idx;
385 	int type;
386 	bool def, defmgmt;
387 	bool def_uni, def_multi;
388 };
389 
nl80211_parse_key_new(struct nlattr * key,struct key_parse * k)390 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
391 {
392 	struct nlattr *tb[NL80211_KEY_MAX + 1];
393 	int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
394 				   nl80211_key_policy);
395 	if (err)
396 		return err;
397 
398 	k->def = !!tb[NL80211_KEY_DEFAULT];
399 	k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
400 
401 	if (k->def) {
402 		k->def_uni = true;
403 		k->def_multi = true;
404 	}
405 	if (k->defmgmt)
406 		k->def_multi = true;
407 
408 	if (tb[NL80211_KEY_IDX])
409 		k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
410 
411 	if (tb[NL80211_KEY_DATA]) {
412 		k->p.key = nla_data(tb[NL80211_KEY_DATA]);
413 		k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
414 	}
415 
416 	if (tb[NL80211_KEY_SEQ]) {
417 		k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
418 		k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
419 	}
420 
421 	if (tb[NL80211_KEY_CIPHER])
422 		k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
423 
424 	if (tb[NL80211_KEY_TYPE]) {
425 		k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
426 		if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
427 			return -EINVAL;
428 	}
429 
430 	if (tb[NL80211_KEY_DEFAULT_TYPES]) {
431 		struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
432 		err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
433 				       tb[NL80211_KEY_DEFAULT_TYPES],
434 				       nl80211_key_default_policy);
435 		if (err)
436 			return err;
437 
438 		k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
439 		k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
440 	}
441 
442 	return 0;
443 }
444 
nl80211_parse_key_old(struct genl_info * info,struct key_parse * k)445 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
446 {
447 	if (info->attrs[NL80211_ATTR_KEY_DATA]) {
448 		k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
449 		k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
450 	}
451 
452 	if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
453 		k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
454 		k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
455 	}
456 
457 	if (info->attrs[NL80211_ATTR_KEY_IDX])
458 		k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
459 
460 	if (info->attrs[NL80211_ATTR_KEY_CIPHER])
461 		k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
462 
463 	k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
464 	k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
465 
466 	if (k->def) {
467 		k->def_uni = true;
468 		k->def_multi = true;
469 	}
470 	if (k->defmgmt)
471 		k->def_multi = true;
472 
473 	if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
474 		k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
475 		if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
476 			return -EINVAL;
477 	}
478 
479 	if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
480 		struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
481 		int err = nla_parse_nested(
482 				kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
483 				info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
484 				nl80211_key_default_policy);
485 		if (err)
486 			return err;
487 
488 		k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
489 		k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
490 	}
491 
492 	return 0;
493 }
494 
nl80211_parse_key(struct genl_info * info,struct key_parse * k)495 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
496 {
497 	int err;
498 
499 	memset(k, 0, sizeof(*k));
500 	k->idx = -1;
501 	k->type = -1;
502 
503 	if (info->attrs[NL80211_ATTR_KEY])
504 		err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
505 	else
506 		err = nl80211_parse_key_old(info, k);
507 
508 	if (err)
509 		return err;
510 
511 	if (k->def && k->defmgmt)
512 		return -EINVAL;
513 
514 	if (k->defmgmt) {
515 		if (k->def_uni || !k->def_multi)
516 			return -EINVAL;
517 	}
518 
519 	if (k->idx != -1) {
520 		if (k->defmgmt) {
521 			if (k->idx < 4 || k->idx > 5)
522 				return -EINVAL;
523 		} else if (k->def) {
524 			if (k->idx < 0 || k->idx > 3)
525 				return -EINVAL;
526 		} else {
527 			if (k->idx < 0 || k->idx > 5)
528 				return -EINVAL;
529 		}
530 	}
531 
532 	return 0;
533 }
534 
535 static struct cfg80211_cached_keys *
nl80211_parse_connkeys(struct cfg80211_registered_device * rdev,struct nlattr * keys)536 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
537 		       struct nlattr *keys)
538 {
539 	struct key_parse parse;
540 	struct nlattr *key;
541 	struct cfg80211_cached_keys *result;
542 	int rem, err, def = 0;
543 
544 	result = kzalloc(sizeof(*result), GFP_KERNEL);
545 	if (!result)
546 		return ERR_PTR(-ENOMEM);
547 
548 	result->def = -1;
549 	result->defmgmt = -1;
550 
551 	nla_for_each_nested(key, keys, rem) {
552 		memset(&parse, 0, sizeof(parse));
553 		parse.idx = -1;
554 
555 		err = nl80211_parse_key_new(key, &parse);
556 		if (err)
557 			goto error;
558 		err = -EINVAL;
559 		if (!parse.p.key)
560 			goto error;
561 		if (parse.idx < 0 || parse.idx > 4)
562 			goto error;
563 		if (parse.def) {
564 			if (def)
565 				goto error;
566 			def = 1;
567 			result->def = parse.idx;
568 			if (!parse.def_uni || !parse.def_multi)
569 				goto error;
570 		} else if (parse.defmgmt)
571 			goto error;
572 		err = cfg80211_validate_key_settings(rdev, &parse.p,
573 						     parse.idx, false, NULL);
574 		if (err)
575 			goto error;
576 		result->params[parse.idx].cipher = parse.p.cipher;
577 		result->params[parse.idx].key_len = parse.p.key_len;
578 		result->params[parse.idx].key = result->data[parse.idx];
579 		memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
580 	}
581 
582 	return result;
583  error:
584 	kfree(result);
585 	return ERR_PTR(err);
586 }
587 
nl80211_key_allowed(struct wireless_dev * wdev)588 static int nl80211_key_allowed(struct wireless_dev *wdev)
589 {
590 	ASSERT_WDEV_LOCK(wdev);
591 
592 	switch (wdev->iftype) {
593 	case NL80211_IFTYPE_AP:
594 	case NL80211_IFTYPE_AP_VLAN:
595 	case NL80211_IFTYPE_P2P_GO:
596 	case NL80211_IFTYPE_MESH_POINT:
597 		break;
598 	case NL80211_IFTYPE_ADHOC:
599 		if (!wdev->current_bss)
600 			return -ENOLINK;
601 		break;
602 	case NL80211_IFTYPE_STATION:
603 	case NL80211_IFTYPE_P2P_CLIENT:
604 		if (wdev->sme_state != CFG80211_SME_CONNECTED)
605 			return -ENOLINK;
606 		break;
607 	default:
608 		return -EINVAL;
609 	}
610 
611 	return 0;
612 }
613 
nl80211_put_iftypes(struct sk_buff * msg,u32 attr,u16 ifmodes)614 static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
615 {
616 	struct nlattr *nl_modes = nla_nest_start(msg, attr);
617 	int i;
618 
619 	if (!nl_modes)
620 		goto nla_put_failure;
621 
622 	i = 0;
623 	while (ifmodes) {
624 		if (ifmodes & 1)
625 			NLA_PUT_FLAG(msg, i);
626 		ifmodes >>= 1;
627 		i++;
628 	}
629 
630 	nla_nest_end(msg, nl_modes);
631 	return 0;
632 
633 nla_put_failure:
634 	return -ENOBUFS;
635 }
636 
nl80211_put_iface_combinations(struct wiphy * wiphy,struct sk_buff * msg)637 static int nl80211_put_iface_combinations(struct wiphy *wiphy,
638 					  struct sk_buff *msg)
639 {
640 	struct nlattr *nl_combis;
641 	int i, j;
642 
643 	nl_combis = nla_nest_start(msg,
644 				NL80211_ATTR_INTERFACE_COMBINATIONS);
645 	if (!nl_combis)
646 		goto nla_put_failure;
647 
648 	for (i = 0; i < wiphy->n_iface_combinations; i++) {
649 		const struct ieee80211_iface_combination *c;
650 		struct nlattr *nl_combi, *nl_limits;
651 
652 		c = &wiphy->iface_combinations[i];
653 
654 		nl_combi = nla_nest_start(msg, i + 1);
655 		if (!nl_combi)
656 			goto nla_put_failure;
657 
658 		nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
659 		if (!nl_limits)
660 			goto nla_put_failure;
661 
662 		for (j = 0; j < c->n_limits; j++) {
663 			struct nlattr *nl_limit;
664 
665 			nl_limit = nla_nest_start(msg, j + 1);
666 			if (!nl_limit)
667 				goto nla_put_failure;
668 			NLA_PUT_U32(msg, NL80211_IFACE_LIMIT_MAX,
669 				    c->limits[j].max);
670 			if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
671 						c->limits[j].types))
672 				goto nla_put_failure;
673 			nla_nest_end(msg, nl_limit);
674 		}
675 
676 		nla_nest_end(msg, nl_limits);
677 
678 		if (c->beacon_int_infra_match)
679 			NLA_PUT_FLAG(msg,
680 				NL80211_IFACE_COMB_STA_AP_BI_MATCH);
681 		NLA_PUT_U32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
682 			    c->num_different_channels);
683 		NLA_PUT_U32(msg, NL80211_IFACE_COMB_MAXNUM,
684 			    c->max_interfaces);
685 
686 		nla_nest_end(msg, nl_combi);
687 	}
688 
689 	nla_nest_end(msg, nl_combis);
690 
691 	return 0;
692 nla_put_failure:
693 	return -ENOBUFS;
694 }
695 
nl80211_send_wiphy(struct sk_buff * msg,u32 pid,u32 seq,int flags,struct cfg80211_registered_device * dev)696 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
697 			      struct cfg80211_registered_device *dev)
698 {
699 	void *hdr;
700 	struct nlattr *nl_bands, *nl_band;
701 	struct nlattr *nl_freqs, *nl_freq;
702 	struct nlattr *nl_rates, *nl_rate;
703 	struct nlattr *nl_cmds;
704 	enum ieee80211_band band;
705 	struct ieee80211_channel *chan;
706 	struct ieee80211_rate *rate;
707 	int i;
708 	const struct ieee80211_txrx_stypes *mgmt_stypes =
709 				dev->wiphy.mgmt_stypes;
710 
711 	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
712 	if (!hdr)
713 		return -1;
714 
715 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
716 	NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
717 
718 	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
719 		    cfg80211_rdev_list_generation);
720 
721 	NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
722 		   dev->wiphy.retry_short);
723 	NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
724 		   dev->wiphy.retry_long);
725 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
726 		    dev->wiphy.frag_threshold);
727 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
728 		    dev->wiphy.rts_threshold);
729 	NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
730 		    dev->wiphy.coverage_class);
731 	NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
732 		   dev->wiphy.max_scan_ssids);
733 	NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
734 		   dev->wiphy.max_sched_scan_ssids);
735 	NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
736 		    dev->wiphy.max_scan_ie_len);
737 	NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
738 		    dev->wiphy.max_sched_scan_ie_len);
739 	NLA_PUT_U8(msg, NL80211_ATTR_MAX_MATCH_SETS,
740 		   dev->wiphy.max_match_sets);
741 
742 	if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
743 		NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
744 	if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
745 		NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
746 	if (dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD)
747 		NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_AP_UAPSD);
748 	if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)
749 		NLA_PUT_FLAG(msg, NL80211_ATTR_ROAM_SUPPORT);
750 	if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)
751 		NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_SUPPORT);
752 	if (dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)
753 		NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP);
754 
755 	NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
756 		sizeof(u32) * dev->wiphy.n_cipher_suites,
757 		dev->wiphy.cipher_suites);
758 
759 	NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
760 		   dev->wiphy.max_num_pmkids);
761 
762 	if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
763 		NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
764 
765 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
766 		    dev->wiphy.available_antennas_tx);
767 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
768 		    dev->wiphy.available_antennas_rx);
769 
770 	if (dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD)
771 		NLA_PUT_U32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
772 			    dev->wiphy.probe_resp_offload);
773 
774 	if ((dev->wiphy.available_antennas_tx ||
775 	     dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
776 		u32 tx_ant = 0, rx_ant = 0;
777 		int res;
778 		res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
779 		if (!res) {
780 			NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
781 			NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
782 		}
783 	}
784 
785 	if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
786 				dev->wiphy.interface_modes))
787 		goto nla_put_failure;
788 
789 	nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
790 	if (!nl_bands)
791 		goto nla_put_failure;
792 
793 	for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
794 		if (!dev->wiphy.bands[band])
795 			continue;
796 
797 		nl_band = nla_nest_start(msg, band);
798 		if (!nl_band)
799 			goto nla_put_failure;
800 
801 		/* add HT info */
802 		if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
803 			NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
804 				sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
805 				&dev->wiphy.bands[band]->ht_cap.mcs);
806 			NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
807 				dev->wiphy.bands[band]->ht_cap.cap);
808 			NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
809 				dev->wiphy.bands[band]->ht_cap.ampdu_factor);
810 			NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
811 				dev->wiphy.bands[band]->ht_cap.ampdu_density);
812 		}
813 
814 		/* add frequencies */
815 		nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
816 		if (!nl_freqs)
817 			goto nla_put_failure;
818 
819 		for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
820 			nl_freq = nla_nest_start(msg, i);
821 			if (!nl_freq)
822 				goto nla_put_failure;
823 
824 			chan = &dev->wiphy.bands[band]->channels[i];
825 
826 			if (nl80211_msg_put_channel(msg, chan))
827 				goto nla_put_failure;
828 
829 			nla_nest_end(msg, nl_freq);
830 		}
831 
832 		nla_nest_end(msg, nl_freqs);
833 
834 		/* add bitrates */
835 		nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
836 		if (!nl_rates)
837 			goto nla_put_failure;
838 
839 		for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
840 			nl_rate = nla_nest_start(msg, i);
841 			if (!nl_rate)
842 				goto nla_put_failure;
843 
844 			rate = &dev->wiphy.bands[band]->bitrates[i];
845 			NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
846 				    rate->bitrate);
847 			if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
848 				NLA_PUT_FLAG(msg,
849 					NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
850 
851 			nla_nest_end(msg, nl_rate);
852 		}
853 
854 		nla_nest_end(msg, nl_rates);
855 
856 		nla_nest_end(msg, nl_band);
857 	}
858 	nla_nest_end(msg, nl_bands);
859 
860 	nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
861 	if (!nl_cmds)
862 		goto nla_put_failure;
863 
864 	i = 0;
865 #define CMD(op, n)						\
866 	 do {							\
867 		if (dev->ops->op) {				\
868 			i++;					\
869 			NLA_PUT_U32(msg, i, NL80211_CMD_ ## n);	\
870 		}						\
871 	} while (0)
872 
873 	CMD(add_virtual_intf, NEW_INTERFACE);
874 	CMD(change_virtual_intf, SET_INTERFACE);
875 	CMD(add_key, NEW_KEY);
876 	CMD(start_ap, START_AP);
877 	CMD(add_station, NEW_STATION);
878 	CMD(add_mpath, NEW_MPATH);
879 	CMD(update_mesh_config, SET_MESH_CONFIG);
880 	CMD(change_bss, SET_BSS);
881 	CMD(auth, AUTHENTICATE);
882 	CMD(assoc, ASSOCIATE);
883 	CMD(deauth, DEAUTHENTICATE);
884 	CMD(disassoc, DISASSOCIATE);
885 	CMD(join_ibss, JOIN_IBSS);
886 	CMD(join_mesh, JOIN_MESH);
887 	CMD(set_pmksa, SET_PMKSA);
888 	CMD(del_pmksa, DEL_PMKSA);
889 	CMD(flush_pmksa, FLUSH_PMKSA);
890 	if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
891 		CMD(remain_on_channel, REMAIN_ON_CHANNEL);
892 	CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
893 	CMD(mgmt_tx, FRAME);
894 	CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
895 	if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
896 		i++;
897 		NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
898 	}
899 	CMD(set_channel, SET_CHANNEL);
900 	CMD(set_wds_peer, SET_WDS_PEER);
901 	if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
902 		CMD(tdls_mgmt, TDLS_MGMT);
903 		CMD(tdls_oper, TDLS_OPER);
904 	}
905 	if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
906 		CMD(sched_scan_start, START_SCHED_SCAN);
907 	CMD(probe_client, PROBE_CLIENT);
908 	CMD(set_noack_map, SET_NOACK_MAP);
909 	if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
910 		i++;
911 		NLA_PUT_U32(msg, i, NL80211_CMD_REGISTER_BEACONS);
912 	}
913 
914 #ifdef CONFIG_NL80211_TESTMODE
915 	CMD(testmode_cmd, TESTMODE);
916 #endif
917 
918 #undef CMD
919 
920 	if (dev->ops->connect || dev->ops->auth) {
921 		i++;
922 		NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
923 	}
924 
925 	if (dev->ops->disconnect || dev->ops->deauth) {
926 		i++;
927 		NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
928 	}
929 
930 	nla_nest_end(msg, nl_cmds);
931 
932 	if (dev->ops->remain_on_channel &&
933 	    dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
934 		NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
935 			    dev->wiphy.max_remain_on_channel_duration);
936 
937 	if (dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)
938 		NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
939 
940 	if (mgmt_stypes) {
941 		u16 stypes;
942 		struct nlattr *nl_ftypes, *nl_ifs;
943 		enum nl80211_iftype ift;
944 
945 		nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
946 		if (!nl_ifs)
947 			goto nla_put_failure;
948 
949 		for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
950 			nl_ftypes = nla_nest_start(msg, ift);
951 			if (!nl_ftypes)
952 				goto nla_put_failure;
953 			i = 0;
954 			stypes = mgmt_stypes[ift].tx;
955 			while (stypes) {
956 				if (stypes & 1)
957 					NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
958 						    (i << 4) | IEEE80211_FTYPE_MGMT);
959 				stypes >>= 1;
960 				i++;
961 			}
962 			nla_nest_end(msg, nl_ftypes);
963 		}
964 
965 		nla_nest_end(msg, nl_ifs);
966 
967 		nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
968 		if (!nl_ifs)
969 			goto nla_put_failure;
970 
971 		for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
972 			nl_ftypes = nla_nest_start(msg, ift);
973 			if (!nl_ftypes)
974 				goto nla_put_failure;
975 			i = 0;
976 			stypes = mgmt_stypes[ift].rx;
977 			while (stypes) {
978 				if (stypes & 1)
979 					NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
980 						    (i << 4) | IEEE80211_FTYPE_MGMT);
981 				stypes >>= 1;
982 				i++;
983 			}
984 			nla_nest_end(msg, nl_ftypes);
985 		}
986 		nla_nest_end(msg, nl_ifs);
987 	}
988 
989 	if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
990 		struct nlattr *nl_wowlan;
991 
992 		nl_wowlan = nla_nest_start(msg,
993 				NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
994 		if (!nl_wowlan)
995 			goto nla_put_failure;
996 
997 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
998 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
999 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
1000 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
1001 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
1002 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
1003 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)
1004 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED);
1005 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)
1006 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
1007 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)
1008 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
1009 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)
1010 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
1011 		if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE)
1012 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
1013 		if (dev->wiphy.wowlan.n_patterns) {
1014 			struct nl80211_wowlan_pattern_support pat = {
1015 				.max_patterns = dev->wiphy.wowlan.n_patterns,
1016 				.min_pattern_len =
1017 					dev->wiphy.wowlan.pattern_min_len,
1018 				.max_pattern_len =
1019 					dev->wiphy.wowlan.pattern_max_len,
1020 			};
1021 			NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1022 				sizeof(pat), &pat);
1023 		}
1024 
1025 		nla_nest_end(msg, nl_wowlan);
1026 	}
1027 
1028 	if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1029 				dev->wiphy.software_iftypes))
1030 		goto nla_put_failure;
1031 
1032 	if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1033 		goto nla_put_failure;
1034 
1035 	if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME)
1036 		NLA_PUT_U32(msg, NL80211_ATTR_DEVICE_AP_SME,
1037 			    dev->wiphy.ap_sme_capa);
1038 
1039 	NLA_PUT_U32(msg, NL80211_ATTR_FEATURE_FLAGS, dev->wiphy.features);
1040 
1041 	if (dev->wiphy.ht_capa_mod_mask)
1042 		NLA_PUT(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1043 			sizeof(*dev->wiphy.ht_capa_mod_mask),
1044 			dev->wiphy.ht_capa_mod_mask);
1045 
1046 	return genlmsg_end(msg, hdr);
1047 
1048  nla_put_failure:
1049 	genlmsg_cancel(msg, hdr);
1050 	return -EMSGSIZE;
1051 }
1052 
nl80211_dump_wiphy(struct sk_buff * skb,struct netlink_callback * cb)1053 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1054 {
1055 	int idx = 0;
1056 	int start = cb->args[0];
1057 	struct cfg80211_registered_device *dev;
1058 
1059 	mutex_lock(&cfg80211_mutex);
1060 	list_for_each_entry(dev, &cfg80211_rdev_list, list) {
1061 		if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1062 			continue;
1063 		if (++idx <= start)
1064 			continue;
1065 		if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1066 				       cb->nlh->nlmsg_seq, NLM_F_MULTI,
1067 				       dev) < 0) {
1068 			idx--;
1069 			break;
1070 		}
1071 	}
1072 	mutex_unlock(&cfg80211_mutex);
1073 
1074 	cb->args[0] = idx;
1075 
1076 	return skb->len;
1077 }
1078 
nl80211_get_wiphy(struct sk_buff * skb,struct genl_info * info)1079 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1080 {
1081 	struct sk_buff *msg;
1082 	struct cfg80211_registered_device *dev = info->user_ptr[0];
1083 
1084 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1085 	if (!msg)
1086 		return -ENOMEM;
1087 
1088 	if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1089 		nlmsg_free(msg);
1090 		return -ENOBUFS;
1091 	}
1092 
1093 	return genlmsg_reply(msg, info);
1094 }
1095 
1096 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1097 	[NL80211_TXQ_ATTR_QUEUE]		= { .type = NLA_U8 },
1098 	[NL80211_TXQ_ATTR_TXOP]			= { .type = NLA_U16 },
1099 	[NL80211_TXQ_ATTR_CWMIN]		= { .type = NLA_U16 },
1100 	[NL80211_TXQ_ATTR_CWMAX]		= { .type = NLA_U16 },
1101 	[NL80211_TXQ_ATTR_AIFS]			= { .type = NLA_U8 },
1102 };
1103 
parse_txq_params(struct nlattr * tb[],struct ieee80211_txq_params * txq_params)1104 static int parse_txq_params(struct nlattr *tb[],
1105 			    struct ieee80211_txq_params *txq_params)
1106 {
1107 	if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
1108 	    !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1109 	    !tb[NL80211_TXQ_ATTR_AIFS])
1110 		return -EINVAL;
1111 
1112 	txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
1113 	txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1114 	txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1115 	txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1116 	txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1117 
1118 	return 0;
1119 }
1120 
nl80211_can_set_dev_channel(struct wireless_dev * wdev)1121 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1122 {
1123 	/*
1124 	 * You can only set the channel explicitly for AP, mesh
1125 	 * and WDS type interfaces; all others have their channel
1126 	 * managed via their respective "establish a connection"
1127 	 * command (connect, join, ...)
1128 	 *
1129 	 * Monitors are special as they are normally slaved to
1130 	 * whatever else is going on, so they behave as though
1131 	 * you tried setting the wiphy channel itself.
1132 	 */
1133 	return !wdev ||
1134 		wdev->iftype == NL80211_IFTYPE_AP ||
1135 		wdev->iftype == NL80211_IFTYPE_WDS ||
1136 		wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
1137 		wdev->iftype == NL80211_IFTYPE_MONITOR ||
1138 		wdev->iftype == NL80211_IFTYPE_P2P_GO;
1139 }
1140 
__nl80211_set_channel(struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,struct genl_info * info)1141 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1142 				 struct wireless_dev *wdev,
1143 				 struct genl_info *info)
1144 {
1145 	enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1146 	u32 freq;
1147 	int result;
1148 
1149 	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1150 		return -EINVAL;
1151 
1152 	if (!nl80211_can_set_dev_channel(wdev))
1153 		return -EOPNOTSUPP;
1154 
1155 	if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1156 		channel_type = nla_get_u32(info->attrs[
1157 				   NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1158 		if (channel_type != NL80211_CHAN_NO_HT &&
1159 		    channel_type != NL80211_CHAN_HT20 &&
1160 		    channel_type != NL80211_CHAN_HT40PLUS &&
1161 		    channel_type != NL80211_CHAN_HT40MINUS)
1162 			return -EINVAL;
1163 	}
1164 
1165 	freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1166 
1167 	mutex_lock(&rdev->devlist_mtx);
1168 	if (wdev) {
1169 		wdev_lock(wdev);
1170 		result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
1171 		wdev_unlock(wdev);
1172 	} else {
1173 		result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
1174 	}
1175 	mutex_unlock(&rdev->devlist_mtx);
1176 
1177 	return result;
1178 }
1179 
nl80211_set_channel(struct sk_buff * skb,struct genl_info * info)1180 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1181 {
1182 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1183 	struct net_device *netdev = info->user_ptr[1];
1184 
1185 	return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
1186 }
1187 
nl80211_set_wds_peer(struct sk_buff * skb,struct genl_info * info)1188 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1189 {
1190 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1191 	struct net_device *dev = info->user_ptr[1];
1192 	struct wireless_dev *wdev = dev->ieee80211_ptr;
1193 	const u8 *bssid;
1194 
1195 	if (!info->attrs[NL80211_ATTR_MAC])
1196 		return -EINVAL;
1197 
1198 	if (netif_running(dev))
1199 		return -EBUSY;
1200 
1201 	if (!rdev->ops->set_wds_peer)
1202 		return -EOPNOTSUPP;
1203 
1204 	if (wdev->iftype != NL80211_IFTYPE_WDS)
1205 		return -EOPNOTSUPP;
1206 
1207 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1208 	return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
1209 }
1210 
1211 
nl80211_set_wiphy(struct sk_buff * skb,struct genl_info * info)1212 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1213 {
1214 	struct cfg80211_registered_device *rdev;
1215 	struct net_device *netdev = NULL;
1216 	struct wireless_dev *wdev;
1217 	int result = 0, rem_txq_params = 0;
1218 	struct nlattr *nl_txq_params;
1219 	u32 changed;
1220 	u8 retry_short = 0, retry_long = 0;
1221 	u32 frag_threshold = 0, rts_threshold = 0;
1222 	u8 coverage_class = 0;
1223 
1224 	/*
1225 	 * Try to find the wiphy and netdev. Normally this
1226 	 * function shouldn't need the netdev, but this is
1227 	 * done for backward compatibility -- previously
1228 	 * setting the channel was done per wiphy, but now
1229 	 * it is per netdev. Previous userland like hostapd
1230 	 * also passed a netdev to set_wiphy, so that it is
1231 	 * possible to let that go to the right netdev!
1232 	 */
1233 	mutex_lock(&cfg80211_mutex);
1234 
1235 	if (info->attrs[NL80211_ATTR_IFINDEX]) {
1236 		int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1237 
1238 		netdev = dev_get_by_index(genl_info_net(info), ifindex);
1239 		if (netdev && netdev->ieee80211_ptr) {
1240 			rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1241 			mutex_lock(&rdev->mtx);
1242 		} else
1243 			netdev = NULL;
1244 	}
1245 
1246 	if (!netdev) {
1247 		rdev = __cfg80211_rdev_from_info(info);
1248 		if (IS_ERR(rdev)) {
1249 			mutex_unlock(&cfg80211_mutex);
1250 			return PTR_ERR(rdev);
1251 		}
1252 		wdev = NULL;
1253 		netdev = NULL;
1254 		result = 0;
1255 
1256 		mutex_lock(&rdev->mtx);
1257 	} else if (netif_running(netdev) &&
1258 		   nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1259 		wdev = netdev->ieee80211_ptr;
1260 	else
1261 		wdev = NULL;
1262 
1263 	/*
1264 	 * end workaround code, by now the rdev is available
1265 	 * and locked, and wdev may or may not be NULL.
1266 	 */
1267 
1268 	if (info->attrs[NL80211_ATTR_WIPHY_NAME])
1269 		result = cfg80211_dev_rename(
1270 			rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
1271 
1272 	mutex_unlock(&cfg80211_mutex);
1273 
1274 	if (result)
1275 		goto bad_res;
1276 
1277 	if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1278 		struct ieee80211_txq_params txq_params;
1279 		struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1280 
1281 		if (!rdev->ops->set_txq_params) {
1282 			result = -EOPNOTSUPP;
1283 			goto bad_res;
1284 		}
1285 
1286 		if (!netdev) {
1287 			result = -EINVAL;
1288 			goto bad_res;
1289 		}
1290 
1291 		if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1292 		    netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1293 			result = -EINVAL;
1294 			goto bad_res;
1295 		}
1296 
1297 		if (!netif_running(netdev)) {
1298 			result = -ENETDOWN;
1299 			goto bad_res;
1300 		}
1301 
1302 		nla_for_each_nested(nl_txq_params,
1303 				    info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1304 				    rem_txq_params) {
1305 			nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1306 				  nla_data(nl_txq_params),
1307 				  nla_len(nl_txq_params),
1308 				  txq_params_policy);
1309 			result = parse_txq_params(tb, &txq_params);
1310 			if (result)
1311 				goto bad_res;
1312 
1313 			result = rdev->ops->set_txq_params(&rdev->wiphy,
1314 							   netdev,
1315 							   &txq_params);
1316 			if (result)
1317 				goto bad_res;
1318 		}
1319 	}
1320 
1321 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
1322 		result = __nl80211_set_channel(rdev, wdev, info);
1323 		if (result)
1324 			goto bad_res;
1325 	}
1326 
1327 	if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1328 		enum nl80211_tx_power_setting type;
1329 		int idx, mbm = 0;
1330 
1331 		if (!rdev->ops->set_tx_power) {
1332 			result = -EOPNOTSUPP;
1333 			goto bad_res;
1334 		}
1335 
1336 		idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1337 		type = nla_get_u32(info->attrs[idx]);
1338 
1339 		if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1340 		    (type != NL80211_TX_POWER_AUTOMATIC)) {
1341 			result = -EINVAL;
1342 			goto bad_res;
1343 		}
1344 
1345 		if (type != NL80211_TX_POWER_AUTOMATIC) {
1346 			idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1347 			mbm = nla_get_u32(info->attrs[idx]);
1348 		}
1349 
1350 		result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1351 		if (result)
1352 			goto bad_res;
1353 	}
1354 
1355 	if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1356 	    info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1357 		u32 tx_ant, rx_ant;
1358 		if ((!rdev->wiphy.available_antennas_tx &&
1359 		     !rdev->wiphy.available_antennas_rx) ||
1360 		    !rdev->ops->set_antenna) {
1361 			result = -EOPNOTSUPP;
1362 			goto bad_res;
1363 		}
1364 
1365 		tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1366 		rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1367 
1368 		/* reject antenna configurations which don't match the
1369 		 * available antenna masks, except for the "all" mask */
1370 		if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1371 		    (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
1372 			result = -EINVAL;
1373 			goto bad_res;
1374 		}
1375 
1376 		tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1377 		rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
1378 
1379 		result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1380 		if (result)
1381 			goto bad_res;
1382 	}
1383 
1384 	changed = 0;
1385 
1386 	if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1387 		retry_short = nla_get_u8(
1388 			info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1389 		if (retry_short == 0) {
1390 			result = -EINVAL;
1391 			goto bad_res;
1392 		}
1393 		changed |= WIPHY_PARAM_RETRY_SHORT;
1394 	}
1395 
1396 	if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1397 		retry_long = nla_get_u8(
1398 			info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1399 		if (retry_long == 0) {
1400 			result = -EINVAL;
1401 			goto bad_res;
1402 		}
1403 		changed |= WIPHY_PARAM_RETRY_LONG;
1404 	}
1405 
1406 	if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1407 		frag_threshold = nla_get_u32(
1408 			info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1409 		if (frag_threshold < 256) {
1410 			result = -EINVAL;
1411 			goto bad_res;
1412 		}
1413 		if (frag_threshold != (u32) -1) {
1414 			/*
1415 			 * Fragments (apart from the last one) are required to
1416 			 * have even length. Make the fragmentation code
1417 			 * simpler by stripping LSB should someone try to use
1418 			 * odd threshold value.
1419 			 */
1420 			frag_threshold &= ~0x1;
1421 		}
1422 		changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1423 	}
1424 
1425 	if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1426 		rts_threshold = nla_get_u32(
1427 			info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1428 		changed |= WIPHY_PARAM_RTS_THRESHOLD;
1429 	}
1430 
1431 	if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1432 		coverage_class = nla_get_u8(
1433 			info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1434 		changed |= WIPHY_PARAM_COVERAGE_CLASS;
1435 	}
1436 
1437 	if (changed) {
1438 		u8 old_retry_short, old_retry_long;
1439 		u32 old_frag_threshold, old_rts_threshold;
1440 		u8 old_coverage_class;
1441 
1442 		if (!rdev->ops->set_wiphy_params) {
1443 			result = -EOPNOTSUPP;
1444 			goto bad_res;
1445 		}
1446 
1447 		old_retry_short = rdev->wiphy.retry_short;
1448 		old_retry_long = rdev->wiphy.retry_long;
1449 		old_frag_threshold = rdev->wiphy.frag_threshold;
1450 		old_rts_threshold = rdev->wiphy.rts_threshold;
1451 		old_coverage_class = rdev->wiphy.coverage_class;
1452 
1453 		if (changed & WIPHY_PARAM_RETRY_SHORT)
1454 			rdev->wiphy.retry_short = retry_short;
1455 		if (changed & WIPHY_PARAM_RETRY_LONG)
1456 			rdev->wiphy.retry_long = retry_long;
1457 		if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1458 			rdev->wiphy.frag_threshold = frag_threshold;
1459 		if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1460 			rdev->wiphy.rts_threshold = rts_threshold;
1461 		if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1462 			rdev->wiphy.coverage_class = coverage_class;
1463 
1464 		result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1465 		if (result) {
1466 			rdev->wiphy.retry_short = old_retry_short;
1467 			rdev->wiphy.retry_long = old_retry_long;
1468 			rdev->wiphy.frag_threshold = old_frag_threshold;
1469 			rdev->wiphy.rts_threshold = old_rts_threshold;
1470 			rdev->wiphy.coverage_class = old_coverage_class;
1471 		}
1472 	}
1473 
1474  bad_res:
1475 	mutex_unlock(&rdev->mtx);
1476 	if (netdev)
1477 		dev_put(netdev);
1478 	return result;
1479 }
1480 
1481 
nl80211_send_iface(struct sk_buff * msg,u32 pid,u32 seq,int flags,struct cfg80211_registered_device * rdev,struct net_device * dev)1482 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
1483 			      struct cfg80211_registered_device *rdev,
1484 			      struct net_device *dev)
1485 {
1486 	void *hdr;
1487 
1488 	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1489 	if (!hdr)
1490 		return -1;
1491 
1492 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1493 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
1494 	NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
1495 	NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
1496 
1497 	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1498 		    rdev->devlist_generation ^
1499 			(cfg80211_rdev_list_generation << 2));
1500 
1501 	return genlmsg_end(msg, hdr);
1502 
1503  nla_put_failure:
1504 	genlmsg_cancel(msg, hdr);
1505 	return -EMSGSIZE;
1506 }
1507 
nl80211_dump_interface(struct sk_buff * skb,struct netlink_callback * cb)1508 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1509 {
1510 	int wp_idx = 0;
1511 	int if_idx = 0;
1512 	int wp_start = cb->args[0];
1513 	int if_start = cb->args[1];
1514 	struct cfg80211_registered_device *rdev;
1515 	struct wireless_dev *wdev;
1516 
1517 	mutex_lock(&cfg80211_mutex);
1518 	list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1519 		if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
1520 			continue;
1521 		if (wp_idx < wp_start) {
1522 			wp_idx++;
1523 			continue;
1524 		}
1525 		if_idx = 0;
1526 
1527 		mutex_lock(&rdev->devlist_mtx);
1528 		list_for_each_entry(wdev, &rdev->netdev_list, list) {
1529 			if (if_idx < if_start) {
1530 				if_idx++;
1531 				continue;
1532 			}
1533 			if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1534 					       cb->nlh->nlmsg_seq, NLM_F_MULTI,
1535 					       rdev, wdev->netdev) < 0) {
1536 				mutex_unlock(&rdev->devlist_mtx);
1537 				goto out;
1538 			}
1539 			if_idx++;
1540 		}
1541 		mutex_unlock(&rdev->devlist_mtx);
1542 
1543 		wp_idx++;
1544 	}
1545  out:
1546 	mutex_unlock(&cfg80211_mutex);
1547 
1548 	cb->args[0] = wp_idx;
1549 	cb->args[1] = if_idx;
1550 
1551 	return skb->len;
1552 }
1553 
nl80211_get_interface(struct sk_buff * skb,struct genl_info * info)1554 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1555 {
1556 	struct sk_buff *msg;
1557 	struct cfg80211_registered_device *dev = info->user_ptr[0];
1558 	struct net_device *netdev = info->user_ptr[1];
1559 
1560 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1561 	if (!msg)
1562 		return -ENOMEM;
1563 
1564 	if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1565 			       dev, netdev) < 0) {
1566 		nlmsg_free(msg);
1567 		return -ENOBUFS;
1568 	}
1569 
1570 	return genlmsg_reply(msg, info);
1571 }
1572 
1573 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1574 	[NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1575 	[NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1576 	[NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1577 	[NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1578 	[NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1579 };
1580 
parse_monitor_flags(struct nlattr * nla,u32 * mntrflags)1581 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1582 {
1583 	struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1584 	int flag;
1585 
1586 	*mntrflags = 0;
1587 
1588 	if (!nla)
1589 		return -EINVAL;
1590 
1591 	if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1592 			     nla, mntr_flags_policy))
1593 		return -EINVAL;
1594 
1595 	for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1596 		if (flags[flag])
1597 			*mntrflags |= (1<<flag);
1598 
1599 	return 0;
1600 }
1601 
nl80211_valid_4addr(struct cfg80211_registered_device * rdev,struct net_device * netdev,u8 use_4addr,enum nl80211_iftype iftype)1602 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
1603 			       struct net_device *netdev, u8 use_4addr,
1604 			       enum nl80211_iftype iftype)
1605 {
1606 	if (!use_4addr) {
1607 		if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
1608 			return -EBUSY;
1609 		return 0;
1610 	}
1611 
1612 	switch (iftype) {
1613 	case NL80211_IFTYPE_AP_VLAN:
1614 		if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1615 			return 0;
1616 		break;
1617 	case NL80211_IFTYPE_STATION:
1618 		if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1619 			return 0;
1620 		break;
1621 	default:
1622 		break;
1623 	}
1624 
1625 	return -EOPNOTSUPP;
1626 }
1627 
nl80211_set_interface(struct sk_buff * skb,struct genl_info * info)1628 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1629 {
1630 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1631 	struct vif_params params;
1632 	int err;
1633 	enum nl80211_iftype otype, ntype;
1634 	struct net_device *dev = info->user_ptr[1];
1635 	u32 _flags, *flags = NULL;
1636 	bool change = false;
1637 
1638 	memset(&params, 0, sizeof(params));
1639 
1640 	otype = ntype = dev->ieee80211_ptr->iftype;
1641 
1642 	if (info->attrs[NL80211_ATTR_IFTYPE]) {
1643 		ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1644 		if (otype != ntype)
1645 			change = true;
1646 		if (ntype > NL80211_IFTYPE_MAX)
1647 			return -EINVAL;
1648 	}
1649 
1650 	if (info->attrs[NL80211_ATTR_MESH_ID]) {
1651 		struct wireless_dev *wdev = dev->ieee80211_ptr;
1652 
1653 		if (ntype != NL80211_IFTYPE_MESH_POINT)
1654 			return -EINVAL;
1655 		if (netif_running(dev))
1656 			return -EBUSY;
1657 
1658 		wdev_lock(wdev);
1659 		BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1660 			     IEEE80211_MAX_MESH_ID_LEN);
1661 		wdev->mesh_id_up_len =
1662 			nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1663 		memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1664 		       wdev->mesh_id_up_len);
1665 		wdev_unlock(wdev);
1666 	}
1667 
1668 	if (info->attrs[NL80211_ATTR_4ADDR]) {
1669 		params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1670 		change = true;
1671 		err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1672 		if (err)
1673 			return err;
1674 	} else {
1675 		params.use_4addr = -1;
1676 	}
1677 
1678 	if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1679 		if (ntype != NL80211_IFTYPE_MONITOR)
1680 			return -EINVAL;
1681 		err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1682 					  &_flags);
1683 		if (err)
1684 			return err;
1685 
1686 		flags = &_flags;
1687 		change = true;
1688 	}
1689 
1690 	if (change)
1691 		err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1692 	else
1693 		err = 0;
1694 
1695 	if (!err && params.use_4addr != -1)
1696 		dev->ieee80211_ptr->use_4addr = params.use_4addr;
1697 
1698 	return err;
1699 }
1700 
nl80211_new_interface(struct sk_buff * skb,struct genl_info * info)1701 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1702 {
1703 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1704 	struct vif_params params;
1705 	struct net_device *dev;
1706 	int err;
1707 	enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1708 	u32 flags;
1709 
1710 	memset(&params, 0, sizeof(params));
1711 
1712 	if (!info->attrs[NL80211_ATTR_IFNAME])
1713 		return -EINVAL;
1714 
1715 	if (info->attrs[NL80211_ATTR_IFTYPE]) {
1716 		type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1717 		if (type > NL80211_IFTYPE_MAX)
1718 			return -EINVAL;
1719 	}
1720 
1721 	if (!rdev->ops->add_virtual_intf ||
1722 	    !(rdev->wiphy.interface_modes & (1 << type)))
1723 		return -EOPNOTSUPP;
1724 
1725 	if (info->attrs[NL80211_ATTR_4ADDR]) {
1726 		params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1727 		err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1728 		if (err)
1729 			return err;
1730 	}
1731 
1732 	err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1733 				  info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1734 				  &flags);
1735 	dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
1736 		nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1737 		type, err ? NULL : &flags, &params);
1738 	if (IS_ERR(dev))
1739 		return PTR_ERR(dev);
1740 
1741 	if (type == NL80211_IFTYPE_MESH_POINT &&
1742 	    info->attrs[NL80211_ATTR_MESH_ID]) {
1743 		struct wireless_dev *wdev = dev->ieee80211_ptr;
1744 
1745 		wdev_lock(wdev);
1746 		BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1747 			     IEEE80211_MAX_MESH_ID_LEN);
1748 		wdev->mesh_id_up_len =
1749 			nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1750 		memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1751 		       wdev->mesh_id_up_len);
1752 		wdev_unlock(wdev);
1753 	}
1754 
1755 	return 0;
1756 }
1757 
nl80211_del_interface(struct sk_buff * skb,struct genl_info * info)1758 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1759 {
1760 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1761 	struct net_device *dev = info->user_ptr[1];
1762 
1763 	if (!rdev->ops->del_virtual_intf)
1764 		return -EOPNOTSUPP;
1765 
1766 	return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1767 }
1768 
nl80211_set_noack_map(struct sk_buff * skb,struct genl_info * info)1769 static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
1770 {
1771 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1772 	struct net_device *dev = info->user_ptr[1];
1773 	u16 noack_map;
1774 
1775 	if (!info->attrs[NL80211_ATTR_NOACK_MAP])
1776 		return -EINVAL;
1777 
1778 	if (!rdev->ops->set_noack_map)
1779 		return -EOPNOTSUPP;
1780 
1781 	noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
1782 
1783 	return rdev->ops->set_noack_map(&rdev->wiphy, dev, noack_map);
1784 }
1785 
1786 struct get_key_cookie {
1787 	struct sk_buff *msg;
1788 	int error;
1789 	int idx;
1790 };
1791 
get_key_callback(void * c,struct key_params * params)1792 static void get_key_callback(void *c, struct key_params *params)
1793 {
1794 	struct nlattr *key;
1795 	struct get_key_cookie *cookie = c;
1796 
1797 	if (params->key)
1798 		NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1799 			params->key_len, params->key);
1800 
1801 	if (params->seq)
1802 		NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1803 			params->seq_len, params->seq);
1804 
1805 	if (params->cipher)
1806 		NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1807 			    params->cipher);
1808 
1809 	key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1810 	if (!key)
1811 		goto nla_put_failure;
1812 
1813 	if (params->key)
1814 		NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1815 			params->key_len, params->key);
1816 
1817 	if (params->seq)
1818 		NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1819 			params->seq_len, params->seq);
1820 
1821 	if (params->cipher)
1822 		NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1823 			    params->cipher);
1824 
1825 	NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1826 
1827 	nla_nest_end(cookie->msg, key);
1828 
1829 	return;
1830  nla_put_failure:
1831 	cookie->error = 1;
1832 }
1833 
nl80211_get_key(struct sk_buff * skb,struct genl_info * info)1834 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1835 {
1836 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1837 	int err;
1838 	struct net_device *dev = info->user_ptr[1];
1839 	u8 key_idx = 0;
1840 	const u8 *mac_addr = NULL;
1841 	bool pairwise;
1842 	struct get_key_cookie cookie = {
1843 		.error = 0,
1844 	};
1845 	void *hdr;
1846 	struct sk_buff *msg;
1847 
1848 	if (info->attrs[NL80211_ATTR_KEY_IDX])
1849 		key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1850 
1851 	if (key_idx > 5)
1852 		return -EINVAL;
1853 
1854 	if (info->attrs[NL80211_ATTR_MAC])
1855 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1856 
1857 	pairwise = !!mac_addr;
1858 	if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1859 		u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1860 		if (kt >= NUM_NL80211_KEYTYPES)
1861 			return -EINVAL;
1862 		if (kt != NL80211_KEYTYPE_GROUP &&
1863 		    kt != NL80211_KEYTYPE_PAIRWISE)
1864 			return -EINVAL;
1865 		pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1866 	}
1867 
1868 	if (!rdev->ops->get_key)
1869 		return -EOPNOTSUPP;
1870 
1871 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1872 	if (!msg)
1873 		return -ENOMEM;
1874 
1875 	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1876 			     NL80211_CMD_NEW_KEY);
1877 	if (IS_ERR(hdr))
1878 		return PTR_ERR(hdr);
1879 
1880 	cookie.msg = msg;
1881 	cookie.idx = key_idx;
1882 
1883 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1884 	NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1885 	if (mac_addr)
1886 		NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1887 
1888 	if (pairwise && mac_addr &&
1889 	    !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1890 		return -ENOENT;
1891 
1892 	err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1893 				 mac_addr, &cookie, get_key_callback);
1894 
1895 	if (err)
1896 		goto free_msg;
1897 
1898 	if (cookie.error)
1899 		goto nla_put_failure;
1900 
1901 	genlmsg_end(msg, hdr);
1902 	return genlmsg_reply(msg, info);
1903 
1904  nla_put_failure:
1905 	err = -ENOBUFS;
1906  free_msg:
1907 	nlmsg_free(msg);
1908 	return err;
1909 }
1910 
nl80211_set_key(struct sk_buff * skb,struct genl_info * info)1911 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1912 {
1913 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1914 	struct key_parse key;
1915 	int err;
1916 	struct net_device *dev = info->user_ptr[1];
1917 
1918 	err = nl80211_parse_key(info, &key);
1919 	if (err)
1920 		return err;
1921 
1922 	if (key.idx < 0)
1923 		return -EINVAL;
1924 
1925 	/* only support setting default key */
1926 	if (!key.def && !key.defmgmt)
1927 		return -EINVAL;
1928 
1929 	wdev_lock(dev->ieee80211_ptr);
1930 
1931 	if (key.def) {
1932 		if (!rdev->ops->set_default_key) {
1933 			err = -EOPNOTSUPP;
1934 			goto out;
1935 		}
1936 
1937 		err = nl80211_key_allowed(dev->ieee80211_ptr);
1938 		if (err)
1939 			goto out;
1940 
1941 		err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1942 						 key.def_uni, key.def_multi);
1943 
1944 		if (err)
1945 			goto out;
1946 
1947 #ifdef CONFIG_CFG80211_WEXT
1948 		dev->ieee80211_ptr->wext.default_key = key.idx;
1949 #endif
1950 	} else {
1951 		if (key.def_uni || !key.def_multi) {
1952 			err = -EINVAL;
1953 			goto out;
1954 		}
1955 
1956 		if (!rdev->ops->set_default_mgmt_key) {
1957 			err = -EOPNOTSUPP;
1958 			goto out;
1959 		}
1960 
1961 		err = nl80211_key_allowed(dev->ieee80211_ptr);
1962 		if (err)
1963 			goto out;
1964 
1965 		err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1966 						      dev, key.idx);
1967 		if (err)
1968 			goto out;
1969 
1970 #ifdef CONFIG_CFG80211_WEXT
1971 		dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1972 #endif
1973 	}
1974 
1975  out:
1976 	wdev_unlock(dev->ieee80211_ptr);
1977 
1978 	return err;
1979 }
1980 
nl80211_new_key(struct sk_buff * skb,struct genl_info * info)1981 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1982 {
1983 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
1984 	int err;
1985 	struct net_device *dev = info->user_ptr[1];
1986 	struct key_parse key;
1987 	const u8 *mac_addr = NULL;
1988 
1989 	err = nl80211_parse_key(info, &key);
1990 	if (err)
1991 		return err;
1992 
1993 	if (!key.p.key)
1994 		return -EINVAL;
1995 
1996 	if (info->attrs[NL80211_ATTR_MAC])
1997 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1998 
1999 	if (key.type == -1) {
2000 		if (mac_addr)
2001 			key.type = NL80211_KEYTYPE_PAIRWISE;
2002 		else
2003 			key.type = NL80211_KEYTYPE_GROUP;
2004 	}
2005 
2006 	/* for now */
2007 	if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2008 	    key.type != NL80211_KEYTYPE_GROUP)
2009 		return -EINVAL;
2010 
2011 	if (!rdev->ops->add_key)
2012 		return -EOPNOTSUPP;
2013 
2014 	if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2015 					   key.type == NL80211_KEYTYPE_PAIRWISE,
2016 					   mac_addr))
2017 		return -EINVAL;
2018 
2019 	wdev_lock(dev->ieee80211_ptr);
2020 	err = nl80211_key_allowed(dev->ieee80211_ptr);
2021 	if (!err)
2022 		err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
2023 					 key.type == NL80211_KEYTYPE_PAIRWISE,
2024 					 mac_addr, &key.p);
2025 	wdev_unlock(dev->ieee80211_ptr);
2026 
2027 	return err;
2028 }
2029 
nl80211_del_key(struct sk_buff * skb,struct genl_info * info)2030 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2031 {
2032 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2033 	int err;
2034 	struct net_device *dev = info->user_ptr[1];
2035 	u8 *mac_addr = NULL;
2036 	struct key_parse key;
2037 
2038 	err = nl80211_parse_key(info, &key);
2039 	if (err)
2040 		return err;
2041 
2042 	if (info->attrs[NL80211_ATTR_MAC])
2043 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2044 
2045 	if (key.type == -1) {
2046 		if (mac_addr)
2047 			key.type = NL80211_KEYTYPE_PAIRWISE;
2048 		else
2049 			key.type = NL80211_KEYTYPE_GROUP;
2050 	}
2051 
2052 	/* for now */
2053 	if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2054 	    key.type != NL80211_KEYTYPE_GROUP)
2055 		return -EINVAL;
2056 
2057 	if (!rdev->ops->del_key)
2058 		return -EOPNOTSUPP;
2059 
2060 	wdev_lock(dev->ieee80211_ptr);
2061 	err = nl80211_key_allowed(dev->ieee80211_ptr);
2062 
2063 	if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2064 	    !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2065 		err = -ENOENT;
2066 
2067 	if (!err)
2068 		err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2069 					 key.type == NL80211_KEYTYPE_PAIRWISE,
2070 					 mac_addr);
2071 
2072 #ifdef CONFIG_CFG80211_WEXT
2073 	if (!err) {
2074 		if (key.idx == dev->ieee80211_ptr->wext.default_key)
2075 			dev->ieee80211_ptr->wext.default_key = -1;
2076 		else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
2077 			dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2078 	}
2079 #endif
2080 	wdev_unlock(dev->ieee80211_ptr);
2081 
2082 	return err;
2083 }
2084 
nl80211_parse_beacon(struct genl_info * info,struct cfg80211_beacon_data * bcn)2085 static int nl80211_parse_beacon(struct genl_info *info,
2086 				struct cfg80211_beacon_data *bcn)
2087 {
2088 	bool haveinfo = false;
2089 
2090 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2091 	    !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2092 	    !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2093 	    !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
2094 		return -EINVAL;
2095 
2096 	memset(bcn, 0, sizeof(*bcn));
2097 
2098 	if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
2099 		bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2100 		bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2101 		if (!bcn->head_len)
2102 			return -EINVAL;
2103 		haveinfo = true;
2104 	}
2105 
2106 	if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
2107 		bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2108 		bcn->tail_len =
2109 		    nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2110 		haveinfo = true;
2111 	}
2112 
2113 	if (!haveinfo)
2114 		return -EINVAL;
2115 
2116 	if (info->attrs[NL80211_ATTR_IE]) {
2117 		bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2118 		bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2119 	}
2120 
2121 	if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
2122 		bcn->proberesp_ies =
2123 			nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2124 		bcn->proberesp_ies_len =
2125 			nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2126 	}
2127 
2128 	if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
2129 		bcn->assocresp_ies =
2130 			nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2131 		bcn->assocresp_ies_len =
2132 			nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2133 	}
2134 
2135 	if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
2136 		bcn->probe_resp =
2137 			nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
2138 		bcn->probe_resp_len =
2139 			nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2140 	}
2141 
2142 	return 0;
2143 }
2144 
nl80211_start_ap(struct sk_buff * skb,struct genl_info * info)2145 static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2146 {
2147 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2148 	struct net_device *dev = info->user_ptr[1];
2149 	struct wireless_dev *wdev = dev->ieee80211_ptr;
2150 	struct cfg80211_ap_settings params;
2151 	int err;
2152 
2153 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2154 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2155 		return -EOPNOTSUPP;
2156 
2157 	if (!rdev->ops->start_ap)
2158 		return -EOPNOTSUPP;
2159 
2160 	if (wdev->beacon_interval)
2161 		return -EALREADY;
2162 
2163 	memset(&params, 0, sizeof(params));
2164 
2165 	/* these are required for START_AP */
2166 	if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2167 	    !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2168 	    !info->attrs[NL80211_ATTR_BEACON_HEAD])
2169 		return -EINVAL;
2170 
2171 	err = nl80211_parse_beacon(info, &params.beacon);
2172 	if (err)
2173 		return err;
2174 
2175 	params.beacon_interval =
2176 		nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2177 	params.dtim_period =
2178 		nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2179 
2180 	err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2181 	if (err)
2182 		return err;
2183 
2184 	/*
2185 	 * In theory, some of these attributes should be required here
2186 	 * but since they were not used when the command was originally
2187 	 * added, keep them optional for old user space programs to let
2188 	 * them continue to work with drivers that do not need the
2189 	 * additional information -- drivers must check!
2190 	 */
2191 	if (info->attrs[NL80211_ATTR_SSID]) {
2192 		params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2193 		params.ssid_len =
2194 			nla_len(info->attrs[NL80211_ATTR_SSID]);
2195 		if (params.ssid_len == 0 ||
2196 		    params.ssid_len > IEEE80211_MAX_SSID_LEN)
2197 			return -EINVAL;
2198 	}
2199 
2200 	if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2201 		params.hidden_ssid = nla_get_u32(
2202 			info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2203 		if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2204 		    params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2205 		    params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2206 			return -EINVAL;
2207 	}
2208 
2209 	params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2210 
2211 	if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2212 		params.auth_type = nla_get_u32(
2213 			info->attrs[NL80211_ATTR_AUTH_TYPE]);
2214 		if (!nl80211_valid_auth_type(params.auth_type))
2215 			return -EINVAL;
2216 	} else
2217 		params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2218 
2219 	err = nl80211_crypto_settings(rdev, info, &params.crypto,
2220 				      NL80211_MAX_NR_CIPHER_SUITES);
2221 	if (err)
2222 		return err;
2223 
2224 	if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2225 		if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2226 			return -EOPNOTSUPP;
2227 		params.inactivity_timeout = nla_get_u16(
2228 			info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2229 	}
2230 
2231 	err = rdev->ops->start_ap(&rdev->wiphy, dev, &params);
2232 	if (!err)
2233 		wdev->beacon_interval = params.beacon_interval;
2234 	return err;
2235 }
2236 
nl80211_set_beacon(struct sk_buff * skb,struct genl_info * info)2237 static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2238 {
2239 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2240 	struct net_device *dev = info->user_ptr[1];
2241 	struct wireless_dev *wdev = dev->ieee80211_ptr;
2242 	struct cfg80211_beacon_data params;
2243 	int err;
2244 
2245 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2246 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2247 		return -EOPNOTSUPP;
2248 
2249 	if (!rdev->ops->change_beacon)
2250 		return -EOPNOTSUPP;
2251 
2252 	if (!wdev->beacon_interval)
2253 		return -EINVAL;
2254 
2255 	err = nl80211_parse_beacon(info, &params);
2256 	if (err)
2257 		return err;
2258 
2259 	return rdev->ops->change_beacon(&rdev->wiphy, dev, &params);
2260 }
2261 
nl80211_stop_ap(struct sk_buff * skb,struct genl_info * info)2262 static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
2263 {
2264 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2265 	struct net_device *dev = info->user_ptr[1];
2266 	struct wireless_dev *wdev = dev->ieee80211_ptr;
2267 	int err;
2268 
2269 	if (!rdev->ops->stop_ap)
2270 		return -EOPNOTSUPP;
2271 
2272 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2273 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2274 		return -EOPNOTSUPP;
2275 
2276 	if (!wdev->beacon_interval)
2277 		return -ENOENT;
2278 
2279 	err = rdev->ops->stop_ap(&rdev->wiphy, dev);
2280 	if (!err)
2281 		wdev->beacon_interval = 0;
2282 	return err;
2283 }
2284 
2285 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2286 	[NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2287 	[NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2288 	[NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
2289 	[NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
2290 	[NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
2291 	[NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
2292 };
2293 
parse_station_flags(struct genl_info * info,enum nl80211_iftype iftype,struct station_parameters * params)2294 static int parse_station_flags(struct genl_info *info,
2295 			       enum nl80211_iftype iftype,
2296 			       struct station_parameters *params)
2297 {
2298 	struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
2299 	struct nlattr *nla;
2300 	int flag;
2301 
2302 	/*
2303 	 * Try parsing the new attribute first so userspace
2304 	 * can specify both for older kernels.
2305 	 */
2306 	nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2307 	if (nla) {
2308 		struct nl80211_sta_flag_update *sta_flags;
2309 
2310 		sta_flags = nla_data(nla);
2311 		params->sta_flags_mask = sta_flags->mask;
2312 		params->sta_flags_set = sta_flags->set;
2313 		if ((params->sta_flags_mask |
2314 		     params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2315 			return -EINVAL;
2316 		return 0;
2317 	}
2318 
2319 	/* if present, parse the old attribute */
2320 
2321 	nla = info->attrs[NL80211_ATTR_STA_FLAGS];
2322 	if (!nla)
2323 		return 0;
2324 
2325 	if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2326 			     nla, sta_flags_policy))
2327 		return -EINVAL;
2328 
2329 	/*
2330 	 * Only allow certain flags for interface types so that
2331 	 * other attributes are silently ignored. Remember that
2332 	 * this is backward compatibility code with old userspace
2333 	 * and shouldn't be hit in other cases anyway.
2334 	 */
2335 	switch (iftype) {
2336 	case NL80211_IFTYPE_AP:
2337 	case NL80211_IFTYPE_AP_VLAN:
2338 	case NL80211_IFTYPE_P2P_GO:
2339 		params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2340 					 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2341 					 BIT(NL80211_STA_FLAG_WME) |
2342 					 BIT(NL80211_STA_FLAG_MFP);
2343 		break;
2344 	case NL80211_IFTYPE_P2P_CLIENT:
2345 	case NL80211_IFTYPE_STATION:
2346 		params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2347 					 BIT(NL80211_STA_FLAG_TDLS_PEER);
2348 		break;
2349 	case NL80211_IFTYPE_MESH_POINT:
2350 		params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2351 					 BIT(NL80211_STA_FLAG_MFP) |
2352 					 BIT(NL80211_STA_FLAG_AUTHORIZED);
2353 	default:
2354 		return -EINVAL;
2355 	}
2356 
2357 	for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2358 		if (flags[flag])
2359 			params->sta_flags_set |= (1<<flag);
2360 
2361 	return 0;
2362 }
2363 
nl80211_put_sta_rate(struct sk_buff * msg,struct rate_info * info,int attr)2364 static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2365 				 int attr)
2366 {
2367 	struct nlattr *rate;
2368 	u16 bitrate;
2369 
2370 	rate = nla_nest_start(msg, attr);
2371 	if (!rate)
2372 		goto nla_put_failure;
2373 
2374 	/* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2375 	bitrate = cfg80211_calculate_bitrate(info);
2376 	if (bitrate > 0)
2377 		NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2378 
2379 	if (info->flags & RATE_INFO_FLAGS_MCS)
2380 		NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2381 	if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2382 		NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2383 	if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2384 		NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2385 
2386 	nla_nest_end(msg, rate);
2387 	return true;
2388 
2389 nla_put_failure:
2390 	return false;
2391 }
2392 
nl80211_send_station(struct sk_buff * msg,u32 pid,u32 seq,int flags,struct cfg80211_registered_device * rdev,struct net_device * dev,const u8 * mac_addr,struct station_info * sinfo)2393 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2394 				int flags,
2395 				struct cfg80211_registered_device *rdev,
2396 				struct net_device *dev,
2397 				const u8 *mac_addr, struct station_info *sinfo)
2398 {
2399 	void *hdr;
2400 	struct nlattr *sinfoattr, *bss_param;
2401 
2402 	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2403 	if (!hdr)
2404 		return -1;
2405 
2406 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2407 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2408 
2409 	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2410 
2411 	sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2412 	if (!sinfoattr)
2413 		goto nla_put_failure;
2414 	if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2415 		NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2416 			    sinfo->connected_time);
2417 	if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2418 		NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2419 			    sinfo->inactive_time);
2420 	if (sinfo->filled & STATION_INFO_RX_BYTES)
2421 		NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2422 			    sinfo->rx_bytes);
2423 	if (sinfo->filled & STATION_INFO_TX_BYTES)
2424 		NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2425 			    sinfo->tx_bytes);
2426 	if (sinfo->filled & STATION_INFO_LLID)
2427 		NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2428 			    sinfo->llid);
2429 	if (sinfo->filled & STATION_INFO_PLID)
2430 		NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2431 			    sinfo->plid);
2432 	if (sinfo->filled & STATION_INFO_PLINK_STATE)
2433 		NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2434 			    sinfo->plink_state);
2435 	switch (rdev->wiphy.signal_type) {
2436 	case CFG80211_SIGNAL_TYPE_MBM:
2437 		if (sinfo->filled & STATION_INFO_SIGNAL)
2438 			NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2439 				   sinfo->signal);
2440 		if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2441 			NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2442 				   sinfo->signal_avg);
2443 		break;
2444 	default:
2445 		break;
2446 	}
2447 	if (sinfo->filled & STATION_INFO_TX_BITRATE) {
2448 		if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2449 					  NL80211_STA_INFO_TX_BITRATE))
2450 			goto nla_put_failure;
2451 	}
2452 	if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2453 		if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2454 					  NL80211_STA_INFO_RX_BITRATE))
2455 			goto nla_put_failure;
2456 	}
2457 	if (sinfo->filled & STATION_INFO_RX_PACKETS)
2458 		NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2459 			    sinfo->rx_packets);
2460 	if (sinfo->filled & STATION_INFO_TX_PACKETS)
2461 		NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2462 			    sinfo->tx_packets);
2463 	if (sinfo->filled & STATION_INFO_TX_RETRIES)
2464 		NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2465 			    sinfo->tx_retries);
2466 	if (sinfo->filled & STATION_INFO_TX_FAILED)
2467 		NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2468 			    sinfo->tx_failed);
2469 	if (sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT)
2470 		NLA_PUT_U32(msg, NL80211_STA_INFO_BEACON_LOSS,
2471 			    sinfo->beacon_loss_count);
2472 	if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2473 		bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2474 		if (!bss_param)
2475 			goto nla_put_failure;
2476 
2477 		if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2478 			NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2479 		if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2480 			NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2481 		if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2482 			NLA_PUT_FLAG(msg,
2483 				     NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2484 		NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2485 			   sinfo->bss_param.dtim_period);
2486 		NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2487 			    sinfo->bss_param.beacon_interval);
2488 
2489 		nla_nest_end(msg, bss_param);
2490 	}
2491 	if (sinfo->filled & STATION_INFO_STA_FLAGS)
2492 		NLA_PUT(msg, NL80211_STA_INFO_STA_FLAGS,
2493 			sizeof(struct nl80211_sta_flag_update),
2494 			&sinfo->sta_flags);
2495 	nla_nest_end(msg, sinfoattr);
2496 
2497 	if (sinfo->filled & STATION_INFO_ASSOC_REQ_IES)
2498 		NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2499 			sinfo->assoc_req_ies);
2500 
2501 	return genlmsg_end(msg, hdr);
2502 
2503  nla_put_failure:
2504 	genlmsg_cancel(msg, hdr);
2505 	return -EMSGSIZE;
2506 }
2507 
nl80211_dump_station(struct sk_buff * skb,struct netlink_callback * cb)2508 static int nl80211_dump_station(struct sk_buff *skb,
2509 				struct netlink_callback *cb)
2510 {
2511 	struct station_info sinfo;
2512 	struct cfg80211_registered_device *dev;
2513 	struct net_device *netdev;
2514 	u8 mac_addr[ETH_ALEN];
2515 	int sta_idx = cb->args[1];
2516 	int err;
2517 
2518 	err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2519 	if (err)
2520 		return err;
2521 
2522 	if (!dev->ops->dump_station) {
2523 		err = -EOPNOTSUPP;
2524 		goto out_err;
2525 	}
2526 
2527 	while (1) {
2528 		memset(&sinfo, 0, sizeof(sinfo));
2529 		err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2530 					     mac_addr, &sinfo);
2531 		if (err == -ENOENT)
2532 			break;
2533 		if (err)
2534 			goto out_err;
2535 
2536 		if (nl80211_send_station(skb,
2537 				NETLINK_CB(cb->skb).pid,
2538 				cb->nlh->nlmsg_seq, NLM_F_MULTI,
2539 				dev, netdev, mac_addr,
2540 				&sinfo) < 0)
2541 			goto out;
2542 
2543 		sta_idx++;
2544 	}
2545 
2546 
2547  out:
2548 	cb->args[1] = sta_idx;
2549 	err = skb->len;
2550  out_err:
2551 	nl80211_finish_netdev_dump(dev);
2552 
2553 	return err;
2554 }
2555 
nl80211_get_station(struct sk_buff * skb,struct genl_info * info)2556 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2557 {
2558 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2559 	struct net_device *dev = info->user_ptr[1];
2560 	struct station_info sinfo;
2561 	struct sk_buff *msg;
2562 	u8 *mac_addr = NULL;
2563 	int err;
2564 
2565 	memset(&sinfo, 0, sizeof(sinfo));
2566 
2567 	if (!info->attrs[NL80211_ATTR_MAC])
2568 		return -EINVAL;
2569 
2570 	mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2571 
2572 	if (!rdev->ops->get_station)
2573 		return -EOPNOTSUPP;
2574 
2575 	err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2576 	if (err)
2577 		return err;
2578 
2579 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2580 	if (!msg)
2581 		return -ENOMEM;
2582 
2583 	if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2584 				 rdev, dev, mac_addr, &sinfo) < 0) {
2585 		nlmsg_free(msg);
2586 		return -ENOBUFS;
2587 	}
2588 
2589 	return genlmsg_reply(msg, info);
2590 }
2591 
2592 /*
2593  * Get vlan interface making sure it is running and on the right wiphy.
2594  */
get_vlan(struct genl_info * info,struct cfg80211_registered_device * rdev)2595 static struct net_device *get_vlan(struct genl_info *info,
2596 				   struct cfg80211_registered_device *rdev)
2597 {
2598 	struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
2599 	struct net_device *v;
2600 	int ret;
2601 
2602 	if (!vlanattr)
2603 		return NULL;
2604 
2605 	v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
2606 	if (!v)
2607 		return ERR_PTR(-ENODEV);
2608 
2609 	if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
2610 		ret = -EINVAL;
2611 		goto error;
2612 	}
2613 
2614 	if (!netif_running(v)) {
2615 		ret = -ENETDOWN;
2616 		goto error;
2617 	}
2618 
2619 	return v;
2620  error:
2621 	dev_put(v);
2622 	return ERR_PTR(ret);
2623 }
2624 
nl80211_set_station(struct sk_buff * skb,struct genl_info * info)2625 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2626 {
2627 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2628 	int err;
2629 	struct net_device *dev = info->user_ptr[1];
2630 	struct station_parameters params;
2631 	u8 *mac_addr = NULL;
2632 
2633 	memset(&params, 0, sizeof(params));
2634 
2635 	params.listen_interval = -1;
2636 	params.plink_state = -1;
2637 
2638 	if (info->attrs[NL80211_ATTR_STA_AID])
2639 		return -EINVAL;
2640 
2641 	if (!info->attrs[NL80211_ATTR_MAC])
2642 		return -EINVAL;
2643 
2644 	mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2645 
2646 	if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2647 		params.supported_rates =
2648 			nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2649 		params.supported_rates_len =
2650 			nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2651 	}
2652 
2653 	if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2654 		params.listen_interval =
2655 		    nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2656 
2657 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2658 		params.ht_capa =
2659 			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2660 
2661 	if (!rdev->ops->change_station)
2662 		return -EOPNOTSUPP;
2663 
2664 	if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
2665 		return -EINVAL;
2666 
2667 	if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2668 		params.plink_action =
2669 		    nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2670 
2671 	if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2672 		params.plink_state =
2673 		    nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2674 
2675 	switch (dev->ieee80211_ptr->iftype) {
2676 	case NL80211_IFTYPE_AP:
2677 	case NL80211_IFTYPE_AP_VLAN:
2678 	case NL80211_IFTYPE_P2P_GO:
2679 		/* disallow mesh-specific things */
2680 		if (params.plink_action)
2681 			return -EINVAL;
2682 
2683 		/* TDLS can't be set, ... */
2684 		if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2685 			return -EINVAL;
2686 		/*
2687 		 * ... but don't bother the driver with it. This works around
2688 		 * a hostapd/wpa_supplicant issue -- it always includes the
2689 		 * TLDS_PEER flag in the mask even for AP mode.
2690 		 */
2691 		params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2692 
2693 		/* accept only the listed bits */
2694 		if (params.sta_flags_mask &
2695 				~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2696 				  BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2697 				  BIT(NL80211_STA_FLAG_WME) |
2698 				  BIT(NL80211_STA_FLAG_MFP)))
2699 			return -EINVAL;
2700 
2701 		/* must be last in here for error handling */
2702 		params.vlan = get_vlan(info, rdev);
2703 		if (IS_ERR(params.vlan))
2704 			return PTR_ERR(params.vlan);
2705 		break;
2706 	case NL80211_IFTYPE_P2P_CLIENT:
2707 	case NL80211_IFTYPE_STATION:
2708 		/*
2709 		 * Don't allow userspace to change the TDLS_PEER flag,
2710 		 * but silently ignore attempts to change it since we
2711 		 * don't have state here to verify that it doesn't try
2712 		 * to change the flag.
2713 		 */
2714 		params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2715 		/* fall through */
2716 	case NL80211_IFTYPE_ADHOC:
2717 		/* disallow things sta doesn't support */
2718 		if (params.plink_action)
2719 			return -EINVAL;
2720 		if (params.ht_capa)
2721 			return -EINVAL;
2722 		if (params.listen_interval >= 0)
2723 			return -EINVAL;
2724 		/* reject any changes other than AUTHORIZED */
2725 		if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2726 			return -EINVAL;
2727 		break;
2728 	case NL80211_IFTYPE_MESH_POINT:
2729 		/* disallow things mesh doesn't support */
2730 		if (params.vlan)
2731 			return -EINVAL;
2732 		if (params.ht_capa)
2733 			return -EINVAL;
2734 		if (params.listen_interval >= 0)
2735 			return -EINVAL;
2736 		/*
2737 		 * No special handling for TDLS here -- the userspace
2738 		 * mesh code doesn't have this bug.
2739 		 */
2740 		if (params.sta_flags_mask &
2741 				~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2742 				  BIT(NL80211_STA_FLAG_MFP) |
2743 				  BIT(NL80211_STA_FLAG_AUTHORIZED)))
2744 			return -EINVAL;
2745 		break;
2746 	default:
2747 		return -EOPNOTSUPP;
2748 	}
2749 
2750 	/* be aware of params.vlan when changing code here */
2751 
2752 	err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
2753 
2754 	if (params.vlan)
2755 		dev_put(params.vlan);
2756 
2757 	return err;
2758 }
2759 
2760 static struct nla_policy
2761 nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2762 	[NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2763 	[NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2764 };
2765 
nl80211_new_station(struct sk_buff * skb,struct genl_info * info)2766 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2767 {
2768 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2769 	int err;
2770 	struct net_device *dev = info->user_ptr[1];
2771 	struct station_parameters params;
2772 	u8 *mac_addr = NULL;
2773 
2774 	memset(&params, 0, sizeof(params));
2775 
2776 	if (!info->attrs[NL80211_ATTR_MAC])
2777 		return -EINVAL;
2778 
2779 	if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2780 		return -EINVAL;
2781 
2782 	if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2783 		return -EINVAL;
2784 
2785 	if (!info->attrs[NL80211_ATTR_STA_AID])
2786 		return -EINVAL;
2787 
2788 	mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2789 	params.supported_rates =
2790 		nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2791 	params.supported_rates_len =
2792 		nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2793 	params.listen_interval =
2794 		nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2795 
2796 	params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2797 	if (!params.aid || params.aid > IEEE80211_MAX_AID)
2798 		return -EINVAL;
2799 
2800 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2801 		params.ht_capa =
2802 			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2803 
2804 	if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2805 		params.plink_action =
2806 		    nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2807 
2808 	if (!rdev->ops->add_station)
2809 		return -EOPNOTSUPP;
2810 
2811 	if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
2812 		return -EINVAL;
2813 
2814 	switch (dev->ieee80211_ptr->iftype) {
2815 	case NL80211_IFTYPE_AP:
2816 	case NL80211_IFTYPE_AP_VLAN:
2817 	case NL80211_IFTYPE_P2P_GO:
2818 		/* parse WME attributes if sta is WME capable */
2819 		if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
2820 		    (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
2821 		    info->attrs[NL80211_ATTR_STA_WME]) {
2822 			struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2823 			struct nlattr *nla;
2824 
2825 			nla = info->attrs[NL80211_ATTR_STA_WME];
2826 			err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2827 					       nl80211_sta_wme_policy);
2828 			if (err)
2829 				return err;
2830 
2831 			if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2832 				params.uapsd_queues =
2833 				     nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
2834 			if (params.uapsd_queues &
2835 					~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2836 				return -EINVAL;
2837 
2838 			if (tb[NL80211_STA_WME_MAX_SP])
2839 				params.max_sp =
2840 				     nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
2841 
2842 			if (params.max_sp &
2843 					~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2844 				return -EINVAL;
2845 
2846 			params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
2847 		}
2848 		/* TDLS peers cannot be added */
2849 		if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2850 			return -EINVAL;
2851 		/* but don't bother the driver with it */
2852 		params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2853 
2854 		/* must be last in here for error handling */
2855 		params.vlan = get_vlan(info, rdev);
2856 		if (IS_ERR(params.vlan))
2857 			return PTR_ERR(params.vlan);
2858 		break;
2859 	case NL80211_IFTYPE_MESH_POINT:
2860 		/* TDLS peers cannot be added */
2861 		if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2862 			return -EINVAL;
2863 		break;
2864 	case NL80211_IFTYPE_STATION:
2865 		/* Only TDLS peers can be added */
2866 		if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
2867 			return -EINVAL;
2868 		/* Can only add if TDLS ... */
2869 		if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
2870 			return -EOPNOTSUPP;
2871 		/* ... with external setup is supported */
2872 		if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
2873 			return -EOPNOTSUPP;
2874 		break;
2875 	default:
2876 		return -EOPNOTSUPP;
2877 	}
2878 
2879 	/* be aware of params.vlan when changing code here */
2880 
2881 	err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2882 
2883 	if (params.vlan)
2884 		dev_put(params.vlan);
2885 	return err;
2886 }
2887 
nl80211_del_station(struct sk_buff * skb,struct genl_info * info)2888 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2889 {
2890 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
2891 	struct net_device *dev = info->user_ptr[1];
2892 	u8 *mac_addr = NULL;
2893 
2894 	if (info->attrs[NL80211_ATTR_MAC])
2895 		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2896 
2897 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2898 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2899 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2900 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2901 		return -EINVAL;
2902 
2903 	if (!rdev->ops->del_station)
2904 		return -EOPNOTSUPP;
2905 
2906 	return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2907 }
2908 
nl80211_send_mpath(struct sk_buff * msg,u32 pid,u32 seq,int flags,struct net_device * dev,u8 * dst,u8 * next_hop,struct mpath_info * pinfo)2909 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2910 				int flags, struct net_device *dev,
2911 				u8 *dst, u8 *next_hop,
2912 				struct mpath_info *pinfo)
2913 {
2914 	void *hdr;
2915 	struct nlattr *pinfoattr;
2916 
2917 	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2918 	if (!hdr)
2919 		return -1;
2920 
2921 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2922 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2923 	NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2924 
2925 	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2926 
2927 	pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2928 	if (!pinfoattr)
2929 		goto nla_put_failure;
2930 	if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2931 		NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2932 			    pinfo->frame_qlen);
2933 	if (pinfo->filled & MPATH_INFO_SN)
2934 		NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2935 			    pinfo->sn);
2936 	if (pinfo->filled & MPATH_INFO_METRIC)
2937 		NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2938 			    pinfo->metric);
2939 	if (pinfo->filled & MPATH_INFO_EXPTIME)
2940 		NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2941 			    pinfo->exptime);
2942 	if (pinfo->filled & MPATH_INFO_FLAGS)
2943 		NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2944 			    pinfo->flags);
2945 	if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2946 		NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2947 			    pinfo->discovery_timeout);
2948 	if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2949 		NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2950 			    pinfo->discovery_retries);
2951 
2952 	nla_nest_end(msg, pinfoattr);
2953 
2954 	return genlmsg_end(msg, hdr);
2955 
2956  nla_put_failure:
2957 	genlmsg_cancel(msg, hdr);
2958 	return -EMSGSIZE;
2959 }
2960 
nl80211_dump_mpath(struct sk_buff * skb,struct netlink_callback * cb)2961 static int nl80211_dump_mpath(struct sk_buff *skb,
2962 			      struct netlink_callback *cb)
2963 {
2964 	struct mpath_info pinfo;
2965 	struct cfg80211_registered_device *dev;
2966 	struct net_device *netdev;
2967 	u8 dst[ETH_ALEN];
2968 	u8 next_hop[ETH_ALEN];
2969 	int path_idx = cb->args[1];
2970 	int err;
2971 
2972 	err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2973 	if (err)
2974 		return err;
2975 
2976 	if (!dev->ops->dump_mpath) {
2977 		err = -EOPNOTSUPP;
2978 		goto out_err;
2979 	}
2980 
2981 	if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2982 		err = -EOPNOTSUPP;
2983 		goto out_err;
2984 	}
2985 
2986 	while (1) {
2987 		err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2988 					   dst, next_hop, &pinfo);
2989 		if (err == -ENOENT)
2990 			break;
2991 		if (err)
2992 			goto out_err;
2993 
2994 		if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2995 				       cb->nlh->nlmsg_seq, NLM_F_MULTI,
2996 				       netdev, dst, next_hop,
2997 				       &pinfo) < 0)
2998 			goto out;
2999 
3000 		path_idx++;
3001 	}
3002 
3003 
3004  out:
3005 	cb->args[1] = path_idx;
3006 	err = skb->len;
3007  out_err:
3008 	nl80211_finish_netdev_dump(dev);
3009 	return err;
3010 }
3011 
nl80211_get_mpath(struct sk_buff * skb,struct genl_info * info)3012 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3013 {
3014 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3015 	int err;
3016 	struct net_device *dev = info->user_ptr[1];
3017 	struct mpath_info pinfo;
3018 	struct sk_buff *msg;
3019 	u8 *dst = NULL;
3020 	u8 next_hop[ETH_ALEN];
3021 
3022 	memset(&pinfo, 0, sizeof(pinfo));
3023 
3024 	if (!info->attrs[NL80211_ATTR_MAC])
3025 		return -EINVAL;
3026 
3027 	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3028 
3029 	if (!rdev->ops->get_mpath)
3030 		return -EOPNOTSUPP;
3031 
3032 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3033 		return -EOPNOTSUPP;
3034 
3035 	err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
3036 	if (err)
3037 		return err;
3038 
3039 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3040 	if (!msg)
3041 		return -ENOMEM;
3042 
3043 	if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
3044 				 dev, dst, next_hop, &pinfo) < 0) {
3045 		nlmsg_free(msg);
3046 		return -ENOBUFS;
3047 	}
3048 
3049 	return genlmsg_reply(msg, info);
3050 }
3051 
nl80211_set_mpath(struct sk_buff * skb,struct genl_info * info)3052 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3053 {
3054 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3055 	struct net_device *dev = info->user_ptr[1];
3056 	u8 *dst = NULL;
3057 	u8 *next_hop = NULL;
3058 
3059 	if (!info->attrs[NL80211_ATTR_MAC])
3060 		return -EINVAL;
3061 
3062 	if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3063 		return -EINVAL;
3064 
3065 	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3066 	next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3067 
3068 	if (!rdev->ops->change_mpath)
3069 		return -EOPNOTSUPP;
3070 
3071 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3072 		return -EOPNOTSUPP;
3073 
3074 	return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
3075 }
3076 
nl80211_new_mpath(struct sk_buff * skb,struct genl_info * info)3077 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3078 {
3079 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3080 	struct net_device *dev = info->user_ptr[1];
3081 	u8 *dst = NULL;
3082 	u8 *next_hop = NULL;
3083 
3084 	if (!info->attrs[NL80211_ATTR_MAC])
3085 		return -EINVAL;
3086 
3087 	if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3088 		return -EINVAL;
3089 
3090 	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3091 	next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3092 
3093 	if (!rdev->ops->add_mpath)
3094 		return -EOPNOTSUPP;
3095 
3096 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3097 		return -EOPNOTSUPP;
3098 
3099 	return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
3100 }
3101 
nl80211_del_mpath(struct sk_buff * skb,struct genl_info * info)3102 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3103 {
3104 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3105 	struct net_device *dev = info->user_ptr[1];
3106 	u8 *dst = NULL;
3107 
3108 	if (info->attrs[NL80211_ATTR_MAC])
3109 		dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3110 
3111 	if (!rdev->ops->del_mpath)
3112 		return -EOPNOTSUPP;
3113 
3114 	return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
3115 }
3116 
nl80211_set_bss(struct sk_buff * skb,struct genl_info * info)3117 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3118 {
3119 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3120 	struct net_device *dev = info->user_ptr[1];
3121 	struct bss_parameters params;
3122 
3123 	memset(&params, 0, sizeof(params));
3124 	/* default to not changing parameters */
3125 	params.use_cts_prot = -1;
3126 	params.use_short_preamble = -1;
3127 	params.use_short_slot_time = -1;
3128 	params.ap_isolate = -1;
3129 	params.ht_opmode = -1;
3130 
3131 	if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3132 		params.use_cts_prot =
3133 		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3134 	if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3135 		params.use_short_preamble =
3136 		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3137 	if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3138 		params.use_short_slot_time =
3139 		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
3140 	if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3141 		params.basic_rates =
3142 			nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3143 		params.basic_rates_len =
3144 			nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3145 	}
3146 	if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3147 		params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
3148 	if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3149 		params.ht_opmode =
3150 			nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
3151 
3152 	if (!rdev->ops->change_bss)
3153 		return -EOPNOTSUPP;
3154 
3155 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3156 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3157 		return -EOPNOTSUPP;
3158 
3159 	return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
3160 }
3161 
3162 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
3163 	[NL80211_ATTR_REG_RULE_FLAGS]		= { .type = NLA_U32 },
3164 	[NL80211_ATTR_FREQ_RANGE_START]		= { .type = NLA_U32 },
3165 	[NL80211_ATTR_FREQ_RANGE_END]		= { .type = NLA_U32 },
3166 	[NL80211_ATTR_FREQ_RANGE_MAX_BW]	= { .type = NLA_U32 },
3167 	[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]	= { .type = NLA_U32 },
3168 	[NL80211_ATTR_POWER_RULE_MAX_EIRP]	= { .type = NLA_U32 },
3169 };
3170 
parse_reg_rule(struct nlattr * tb[],struct ieee80211_reg_rule * reg_rule)3171 static int parse_reg_rule(struct nlattr *tb[],
3172 	struct ieee80211_reg_rule *reg_rule)
3173 {
3174 	struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3175 	struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3176 
3177 	if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3178 		return -EINVAL;
3179 	if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3180 		return -EINVAL;
3181 	if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3182 		return -EINVAL;
3183 	if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3184 		return -EINVAL;
3185 	if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3186 		return -EINVAL;
3187 
3188 	reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3189 
3190 	freq_range->start_freq_khz =
3191 		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3192 	freq_range->end_freq_khz =
3193 		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3194 	freq_range->max_bandwidth_khz =
3195 		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3196 
3197 	power_rule->max_eirp =
3198 		nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3199 
3200 	if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3201 		power_rule->max_antenna_gain =
3202 			nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3203 
3204 	return 0;
3205 }
3206 
nl80211_req_set_reg(struct sk_buff * skb,struct genl_info * info)3207 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3208 {
3209 	int r;
3210 	char *data = NULL;
3211 
3212 	/*
3213 	 * You should only get this when cfg80211 hasn't yet initialized
3214 	 * completely when built-in to the kernel right between the time
3215 	 * window between nl80211_init() and regulatory_init(), if that is
3216 	 * even possible.
3217 	 */
3218 	mutex_lock(&cfg80211_mutex);
3219 	if (unlikely(!cfg80211_regdomain)) {
3220 		mutex_unlock(&cfg80211_mutex);
3221 		return -EINPROGRESS;
3222 	}
3223 	mutex_unlock(&cfg80211_mutex);
3224 
3225 	if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3226 		return -EINVAL;
3227 
3228 	data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3229 
3230 	r = regulatory_hint_user(data);
3231 
3232 	return r;
3233 }
3234 
nl80211_get_mesh_config(struct sk_buff * skb,struct genl_info * info)3235 static int nl80211_get_mesh_config(struct sk_buff *skb,
3236 				   struct genl_info *info)
3237 {
3238 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3239 	struct net_device *dev = info->user_ptr[1];
3240 	struct wireless_dev *wdev = dev->ieee80211_ptr;
3241 	struct mesh_config cur_params;
3242 	int err = 0;
3243 	void *hdr;
3244 	struct nlattr *pinfoattr;
3245 	struct sk_buff *msg;
3246 
3247 	if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3248 		return -EOPNOTSUPP;
3249 
3250 	if (!rdev->ops->get_mesh_config)
3251 		return -EOPNOTSUPP;
3252 
3253 	wdev_lock(wdev);
3254 	/* If not connected, get default parameters */
3255 	if (!wdev->mesh_id_len)
3256 		memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3257 	else
3258 		err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
3259 						 &cur_params);
3260 	wdev_unlock(wdev);
3261 
3262 	if (err)
3263 		return err;
3264 
3265 	/* Draw up a netlink message to send back */
3266 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3267 	if (!msg)
3268 		return -ENOMEM;
3269 	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3270 			     NL80211_CMD_GET_MESH_CONFIG);
3271 	if (!hdr)
3272 		goto out;
3273 	pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
3274 	if (!pinfoattr)
3275 		goto nla_put_failure;
3276 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3277 	NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3278 			cur_params.dot11MeshRetryTimeout);
3279 	NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3280 			cur_params.dot11MeshConfirmTimeout);
3281 	NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3282 			cur_params.dot11MeshHoldingTimeout);
3283 	NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3284 			cur_params.dot11MeshMaxPeerLinks);
3285 	NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
3286 			cur_params.dot11MeshMaxRetries);
3287 	NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
3288 			cur_params.dot11MeshTTL);
3289 	NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3290 			cur_params.element_ttl);
3291 	NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3292 			cur_params.auto_open_plinks);
3293 	NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3294 			cur_params.dot11MeshHWMPmaxPREQretries);
3295 	NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3296 			cur_params.path_refresh_time);
3297 	NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3298 			cur_params.min_discovery_timeout);
3299 	NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3300 			cur_params.dot11MeshHWMPactivePathTimeout);
3301 	NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3302 			cur_params.dot11MeshHWMPpreqMinInterval);
3303 	NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3304 			cur_params.dot11MeshHWMPperrMinInterval);
3305 	NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3306 			cur_params.dot11MeshHWMPnetDiameterTraversalTime);
3307 	NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3308 			cur_params.dot11MeshHWMPRootMode);
3309 	NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3310 			cur_params.dot11MeshHWMPRannInterval);
3311 	NLA_PUT_U8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3312 			cur_params.dot11MeshGateAnnouncementProtocol);
3313 	NLA_PUT_U8(msg, NL80211_MESHCONF_FORWARDING,
3314 			cur_params.dot11MeshForwarding);
3315 	NLA_PUT_U32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
3316 			cur_params.rssi_threshold);
3317 	nla_nest_end(msg, pinfoattr);
3318 	genlmsg_end(msg, hdr);
3319 	return genlmsg_reply(msg, info);
3320 
3321  nla_put_failure:
3322 	genlmsg_cancel(msg, hdr);
3323  out:
3324 	nlmsg_free(msg);
3325 	return -ENOBUFS;
3326 }
3327 
3328 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
3329 	[NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3330 	[NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3331 	[NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3332 	[NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3333 	[NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3334 	[NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
3335 	[NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
3336 	[NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
3337 
3338 	[NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3339 	[NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3340 	[NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3341 	[NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3342 	[NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
3343 	[NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
3344 	[NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
3345 	[NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
3346 	[NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
3347 	[NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
3348 	[NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
3349 	[NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32},
3350 };
3351 
3352 static const struct nla_policy
3353 	nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
3354 	[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3355 	[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
3356 	[NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
3357 	[NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
3358 		.len = IEEE80211_MAX_DATA_LEN },
3359 	[NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
3360 };
3361 
nl80211_parse_mesh_config(struct genl_info * info,struct mesh_config * cfg,u32 * mask_out)3362 static int nl80211_parse_mesh_config(struct genl_info *info,
3363 				     struct mesh_config *cfg,
3364 				     u32 *mask_out)
3365 {
3366 	struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
3367 	u32 mask = 0;
3368 
3369 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3370 do {\
3371 	if (table[attr_num]) {\
3372 		cfg->param = nla_fn(table[attr_num]); \
3373 		mask |= (1 << (attr_num - 1)); \
3374 	} \
3375 } while (0);\
3376 
3377 
3378 	if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
3379 		return -EINVAL;
3380 	if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
3381 			     info->attrs[NL80211_ATTR_MESH_CONFIG],
3382 			     nl80211_meshconf_params_policy))
3383 		return -EINVAL;
3384 
3385 	/* This makes sure that there aren't more than 32 mesh config
3386 	 * parameters (otherwise our bitfield scheme would not work.) */
3387 	BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3388 
3389 	/* Fill in the params struct */
3390 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
3391 			mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
3392 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
3393 			mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
3394 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
3395 			mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
3396 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
3397 			mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
3398 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
3399 			mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
3400 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
3401 			mask, NL80211_MESHCONF_TTL, nla_get_u8);
3402 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
3403 			mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
3404 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
3405 			mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
3406 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
3407 			mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3408 			nla_get_u8);
3409 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
3410 			mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
3411 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
3412 			mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3413 			nla_get_u16);
3414 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
3415 			mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3416 			nla_get_u32);
3417 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
3418 			mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3419 			nla_get_u16);
3420 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
3421 			mask, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3422 			nla_get_u16);
3423 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3424 			dot11MeshHWMPnetDiameterTraversalTime,
3425 			mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3426 			nla_get_u16);
3427 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3428 			dot11MeshHWMPRootMode, mask,
3429 			NL80211_MESHCONF_HWMP_ROOTMODE,
3430 			nla_get_u8);
3431 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3432 			dot11MeshHWMPRannInterval, mask,
3433 			NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3434 			nla_get_u16);
3435 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3436 			dot11MeshGateAnnouncementProtocol, mask,
3437 			NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3438 			nla_get_u8);
3439 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding,
3440 			mask, NL80211_MESHCONF_FORWARDING, nla_get_u8);
3441 	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold,
3442 			mask, NL80211_MESHCONF_RSSI_THRESHOLD, nla_get_u32);
3443 	if (mask_out)
3444 		*mask_out = mask;
3445 
3446 	return 0;
3447 
3448 #undef FILL_IN_MESH_PARAM_IF_SET
3449 }
3450 
nl80211_parse_mesh_setup(struct genl_info * info,struct mesh_setup * setup)3451 static int nl80211_parse_mesh_setup(struct genl_info *info,
3452 				     struct mesh_setup *setup)
3453 {
3454 	struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3455 
3456 	if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3457 		return -EINVAL;
3458 	if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3459 			     info->attrs[NL80211_ATTR_MESH_SETUP],
3460 			     nl80211_mesh_setup_params_policy))
3461 		return -EINVAL;
3462 
3463 	if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3464 		setup->path_sel_proto =
3465 		(nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3466 		 IEEE80211_PATH_PROTOCOL_VENDOR :
3467 		 IEEE80211_PATH_PROTOCOL_HWMP;
3468 
3469 	if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3470 		setup->path_metric =
3471 		(nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3472 		 IEEE80211_PATH_METRIC_VENDOR :
3473 		 IEEE80211_PATH_METRIC_AIRTIME;
3474 
3475 
3476 	if (tb[NL80211_MESH_SETUP_IE]) {
3477 		struct nlattr *ieattr =
3478 			tb[NL80211_MESH_SETUP_IE];
3479 		if (!is_valid_ie_attr(ieattr))
3480 			return -EINVAL;
3481 		setup->ie = nla_data(ieattr);
3482 		setup->ie_len = nla_len(ieattr);
3483 	}
3484 	setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3485 	setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
3486 
3487 	return 0;
3488 }
3489 
nl80211_update_mesh_config(struct sk_buff * skb,struct genl_info * info)3490 static int nl80211_update_mesh_config(struct sk_buff *skb,
3491 				      struct genl_info *info)
3492 {
3493 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3494 	struct net_device *dev = info->user_ptr[1];
3495 	struct wireless_dev *wdev = dev->ieee80211_ptr;
3496 	struct mesh_config cfg;
3497 	u32 mask;
3498 	int err;
3499 
3500 	if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3501 		return -EOPNOTSUPP;
3502 
3503 	if (!rdev->ops->update_mesh_config)
3504 		return -EOPNOTSUPP;
3505 
3506 	err = nl80211_parse_mesh_config(info, &cfg, &mask);
3507 	if (err)
3508 		return err;
3509 
3510 	wdev_lock(wdev);
3511 	if (!wdev->mesh_id_len)
3512 		err = -ENOLINK;
3513 
3514 	if (!err)
3515 		err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
3516 						    mask, &cfg);
3517 
3518 	wdev_unlock(wdev);
3519 
3520 	return err;
3521 }
3522 
nl80211_get_reg(struct sk_buff * skb,struct genl_info * info)3523 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3524 {
3525 	struct sk_buff *msg;
3526 	void *hdr = NULL;
3527 	struct nlattr *nl_reg_rules;
3528 	unsigned int i;
3529 	int err = -EINVAL;
3530 
3531 	mutex_lock(&cfg80211_mutex);
3532 
3533 	if (!cfg80211_regdomain)
3534 		goto out;
3535 
3536 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3537 	if (!msg) {
3538 		err = -ENOBUFS;
3539 		goto out;
3540 	}
3541 
3542 	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3543 			     NL80211_CMD_GET_REG);
3544 	if (!hdr)
3545 		goto put_failure;
3546 
3547 	NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3548 		cfg80211_regdomain->alpha2);
3549 	if (cfg80211_regdomain->dfs_region)
3550 		NLA_PUT_U8(msg, NL80211_ATTR_DFS_REGION,
3551 			   cfg80211_regdomain->dfs_region);
3552 
3553 	nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3554 	if (!nl_reg_rules)
3555 		goto nla_put_failure;
3556 
3557 	for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3558 		struct nlattr *nl_reg_rule;
3559 		const struct ieee80211_reg_rule *reg_rule;
3560 		const struct ieee80211_freq_range *freq_range;
3561 		const struct ieee80211_power_rule *power_rule;
3562 
3563 		reg_rule = &cfg80211_regdomain->reg_rules[i];
3564 		freq_range = &reg_rule->freq_range;
3565 		power_rule = &reg_rule->power_rule;
3566 
3567 		nl_reg_rule = nla_nest_start(msg, i);
3568 		if (!nl_reg_rule)
3569 			goto nla_put_failure;
3570 
3571 		NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3572 			reg_rule->flags);
3573 		NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3574 			freq_range->start_freq_khz);
3575 		NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3576 			freq_range->end_freq_khz);
3577 		NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3578 			freq_range->max_bandwidth_khz);
3579 		NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3580 			power_rule->max_antenna_gain);
3581 		NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3582 			power_rule->max_eirp);
3583 
3584 		nla_nest_end(msg, nl_reg_rule);
3585 	}
3586 
3587 	nla_nest_end(msg, nl_reg_rules);
3588 
3589 	genlmsg_end(msg, hdr);
3590 	err = genlmsg_reply(msg, info);
3591 	goto out;
3592 
3593 nla_put_failure:
3594 	genlmsg_cancel(msg, hdr);
3595 put_failure:
3596 	nlmsg_free(msg);
3597 	err = -EMSGSIZE;
3598 out:
3599 	mutex_unlock(&cfg80211_mutex);
3600 	return err;
3601 }
3602 
nl80211_set_reg(struct sk_buff * skb,struct genl_info * info)3603 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3604 {
3605 	struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3606 	struct nlattr *nl_reg_rule;
3607 	char *alpha2 = NULL;
3608 	int rem_reg_rules = 0, r = 0;
3609 	u32 num_rules = 0, rule_idx = 0, size_of_regd;
3610 	u8 dfs_region = 0;
3611 	struct ieee80211_regdomain *rd = NULL;
3612 
3613 	if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3614 		return -EINVAL;
3615 
3616 	if (!info->attrs[NL80211_ATTR_REG_RULES])
3617 		return -EINVAL;
3618 
3619 	alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3620 
3621 	if (info->attrs[NL80211_ATTR_DFS_REGION])
3622 		dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
3623 
3624 	nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3625 			rem_reg_rules) {
3626 		num_rules++;
3627 		if (num_rules > NL80211_MAX_SUPP_REG_RULES)
3628 			return -EINVAL;
3629 	}
3630 
3631 	mutex_lock(&cfg80211_mutex);
3632 
3633 	if (!reg_is_valid_request(alpha2)) {
3634 		r = -EINVAL;
3635 		goto bad_reg;
3636 	}
3637 
3638 	size_of_regd = sizeof(struct ieee80211_regdomain) +
3639 		(num_rules * sizeof(struct ieee80211_reg_rule));
3640 
3641 	rd = kzalloc(size_of_regd, GFP_KERNEL);
3642 	if (!rd) {
3643 		r = -ENOMEM;
3644 		goto bad_reg;
3645 	}
3646 
3647 	rd->n_reg_rules = num_rules;
3648 	rd->alpha2[0] = alpha2[0];
3649 	rd->alpha2[1] = alpha2[1];
3650 
3651 	/*
3652 	 * Disable DFS master mode if the DFS region was
3653 	 * not supported or known on this kernel.
3654 	 */
3655 	if (reg_supported_dfs_region(dfs_region))
3656 		rd->dfs_region = dfs_region;
3657 
3658 	nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3659 			rem_reg_rules) {
3660 		nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3661 			nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3662 			reg_rule_policy);
3663 		r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3664 		if (r)
3665 			goto bad_reg;
3666 
3667 		rule_idx++;
3668 
3669 		if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3670 			r = -EINVAL;
3671 			goto bad_reg;
3672 		}
3673 	}
3674 
3675 	BUG_ON(rule_idx != num_rules);
3676 
3677 	r = set_regdom(rd);
3678 
3679 	mutex_unlock(&cfg80211_mutex);
3680 
3681 	return r;
3682 
3683  bad_reg:
3684 	mutex_unlock(&cfg80211_mutex);
3685 	kfree(rd);
3686 	return r;
3687 }
3688 
validate_scan_freqs(struct nlattr * freqs)3689 static int validate_scan_freqs(struct nlattr *freqs)
3690 {
3691 	struct nlattr *attr1, *attr2;
3692 	int n_channels = 0, tmp1, tmp2;
3693 
3694 	nla_for_each_nested(attr1, freqs, tmp1) {
3695 		n_channels++;
3696 		/*
3697 		 * Some hardware has a limited channel list for
3698 		 * scanning, and it is pretty much nonsensical
3699 		 * to scan for a channel twice, so disallow that
3700 		 * and don't require drivers to check that the
3701 		 * channel list they get isn't longer than what
3702 		 * they can scan, as long as they can scan all
3703 		 * the channels they registered at once.
3704 		 */
3705 		nla_for_each_nested(attr2, freqs, tmp2)
3706 			if (attr1 != attr2 &&
3707 			    nla_get_u32(attr1) == nla_get_u32(attr2))
3708 				return 0;
3709 	}
3710 
3711 	return n_channels;
3712 }
3713 
nl80211_trigger_scan(struct sk_buff * skb,struct genl_info * info)3714 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3715 {
3716 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3717 	struct net_device *dev = info->user_ptr[1];
3718 	struct cfg80211_scan_request *request;
3719 	struct nlattr *attr;
3720 	struct wiphy *wiphy;
3721 	int err, tmp, n_ssids = 0, n_channels, i;
3722 	size_t ie_len;
3723 
3724 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3725 		return -EINVAL;
3726 
3727 	wiphy = &rdev->wiphy;
3728 
3729 	if (!rdev->ops->scan)
3730 		return -EOPNOTSUPP;
3731 
3732 	if (rdev->scan_req)
3733 		return -EBUSY;
3734 
3735 	if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3736 		n_channels = validate_scan_freqs(
3737 				info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3738 		if (!n_channels)
3739 			return -EINVAL;
3740 	} else {
3741 		enum ieee80211_band band;
3742 		n_channels = 0;
3743 
3744 		for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3745 			if (wiphy->bands[band])
3746 				n_channels += wiphy->bands[band]->n_channels;
3747 	}
3748 
3749 	if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3750 		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3751 			n_ssids++;
3752 
3753 	if (n_ssids > wiphy->max_scan_ssids)
3754 		return -EINVAL;
3755 
3756 	if (info->attrs[NL80211_ATTR_IE])
3757 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3758 	else
3759 		ie_len = 0;
3760 
3761 	if (ie_len > wiphy->max_scan_ie_len)
3762 		return -EINVAL;
3763 
3764 	request = kzalloc(sizeof(*request)
3765 			+ sizeof(*request->ssids) * n_ssids
3766 			+ sizeof(*request->channels) * n_channels
3767 			+ ie_len, GFP_KERNEL);
3768 	if (!request)
3769 		return -ENOMEM;
3770 
3771 	if (n_ssids)
3772 		request->ssids = (void *)&request->channels[n_channels];
3773 	request->n_ssids = n_ssids;
3774 	if (ie_len) {
3775 		if (request->ssids)
3776 			request->ie = (void *)(request->ssids + n_ssids);
3777 		else
3778 			request->ie = (void *)(request->channels + n_channels);
3779 	}
3780 
3781 	i = 0;
3782 	if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3783 		/* user specified, bail out if channel not found */
3784 		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3785 			struct ieee80211_channel *chan;
3786 
3787 			chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3788 
3789 			if (!chan) {
3790 				err = -EINVAL;
3791 				goto out_free;
3792 			}
3793 
3794 			/* ignore disabled channels */
3795 			if (chan->flags & IEEE80211_CHAN_DISABLED)
3796 				continue;
3797 
3798 			request->channels[i] = chan;
3799 			i++;
3800 		}
3801 	} else {
3802 		enum ieee80211_band band;
3803 
3804 		/* all channels */
3805 		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3806 			int j;
3807 			if (!wiphy->bands[band])
3808 				continue;
3809 			for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3810 				struct ieee80211_channel *chan;
3811 
3812 				chan = &wiphy->bands[band]->channels[j];
3813 
3814 				if (chan->flags & IEEE80211_CHAN_DISABLED)
3815 					continue;
3816 
3817 				request->channels[i] = chan;
3818 				i++;
3819 			}
3820 		}
3821 	}
3822 
3823 	if (!i) {
3824 		err = -EINVAL;
3825 		goto out_free;
3826 	}
3827 
3828 	request->n_channels = i;
3829 
3830 	i = 0;
3831 	if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3832 		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3833 			if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
3834 				err = -EINVAL;
3835 				goto out_free;
3836 			}
3837 			request->ssids[i].ssid_len = nla_len(attr);
3838 			memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3839 			i++;
3840 		}
3841 	}
3842 
3843 	if (info->attrs[NL80211_ATTR_IE]) {
3844 		request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3845 		memcpy((void *)request->ie,
3846 		       nla_data(info->attrs[NL80211_ATTR_IE]),
3847 		       request->ie_len);
3848 	}
3849 
3850 	for (i = 0; i < IEEE80211_NUM_BANDS; i++)
3851 		if (wiphy->bands[i])
3852 			request->rates[i] =
3853 				(1 << wiphy->bands[i]->n_bitrates) - 1;
3854 
3855 	if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
3856 		nla_for_each_nested(attr,
3857 				    info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
3858 				    tmp) {
3859 			enum ieee80211_band band = nla_type(attr);
3860 
3861 			if (band < 0 || band >= IEEE80211_NUM_BANDS) {
3862 				err = -EINVAL;
3863 				goto out_free;
3864 			}
3865 			err = ieee80211_get_ratemask(wiphy->bands[band],
3866 						     nla_data(attr),
3867 						     nla_len(attr),
3868 						     &request->rates[band]);
3869 			if (err)
3870 				goto out_free;
3871 		}
3872 	}
3873 
3874 	request->no_cck =
3875 		nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
3876 
3877 	request->dev = dev;
3878 	request->wiphy = &rdev->wiphy;
3879 
3880 	rdev->scan_req = request;
3881 	err = rdev->ops->scan(&rdev->wiphy, dev, request);
3882 
3883 	if (!err) {
3884 		nl80211_send_scan_start(rdev, dev);
3885 		dev_hold(dev);
3886 	} else {
3887  out_free:
3888 		rdev->scan_req = NULL;
3889 		kfree(request);
3890 	}
3891 
3892 	return err;
3893 }
3894 
nl80211_start_sched_scan(struct sk_buff * skb,struct genl_info * info)3895 static int nl80211_start_sched_scan(struct sk_buff *skb,
3896 				    struct genl_info *info)
3897 {
3898 	struct cfg80211_sched_scan_request *request;
3899 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
3900 	struct net_device *dev = info->user_ptr[1];
3901 	struct nlattr *attr;
3902 	struct wiphy *wiphy;
3903 	int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
3904 	u32 interval;
3905 	enum ieee80211_band band;
3906 	size_t ie_len;
3907 	struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
3908 
3909 	if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3910 	    !rdev->ops->sched_scan_start)
3911 		return -EOPNOTSUPP;
3912 
3913 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3914 		return -EINVAL;
3915 
3916 	if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
3917 		return -EINVAL;
3918 
3919 	interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
3920 	if (interval == 0)
3921 		return -EINVAL;
3922 
3923 	wiphy = &rdev->wiphy;
3924 
3925 	if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3926 		n_channels = validate_scan_freqs(
3927 				info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3928 		if (!n_channels)
3929 			return -EINVAL;
3930 	} else {
3931 		n_channels = 0;
3932 
3933 		for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3934 			if (wiphy->bands[band])
3935 				n_channels += wiphy->bands[band]->n_channels;
3936 	}
3937 
3938 	if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3939 		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3940 				    tmp)
3941 			n_ssids++;
3942 
3943 	if (n_ssids > wiphy->max_sched_scan_ssids)
3944 		return -EINVAL;
3945 
3946 	if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
3947 		nla_for_each_nested(attr,
3948 				    info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3949 				    tmp)
3950 			n_match_sets++;
3951 
3952 	if (n_match_sets > wiphy->max_match_sets)
3953 		return -EINVAL;
3954 
3955 	if (info->attrs[NL80211_ATTR_IE])
3956 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3957 	else
3958 		ie_len = 0;
3959 
3960 	if (ie_len > wiphy->max_sched_scan_ie_len)
3961 		return -EINVAL;
3962 
3963 	mutex_lock(&rdev->sched_scan_mtx);
3964 
3965 	if (rdev->sched_scan_req) {
3966 		err = -EINPROGRESS;
3967 		goto out;
3968 	}
3969 
3970 	request = kzalloc(sizeof(*request)
3971 			+ sizeof(*request->ssids) * n_ssids
3972 			+ sizeof(*request->match_sets) * n_match_sets
3973 			+ sizeof(*request->channels) * n_channels
3974 			+ ie_len, GFP_KERNEL);
3975 	if (!request) {
3976 		err = -ENOMEM;
3977 		goto out;
3978 	}
3979 
3980 	if (n_ssids)
3981 		request->ssids = (void *)&request->channels[n_channels];
3982 	request->n_ssids = n_ssids;
3983 	if (ie_len) {
3984 		if (request->ssids)
3985 			request->ie = (void *)(request->ssids + n_ssids);
3986 		else
3987 			request->ie = (void *)(request->channels + n_channels);
3988 	}
3989 
3990 	if (n_match_sets) {
3991 		if (request->ie)
3992 			request->match_sets = (void *)(request->ie + ie_len);
3993 		else if (request->ssids)
3994 			request->match_sets =
3995 				(void *)(request->ssids + n_ssids);
3996 		else
3997 			request->match_sets =
3998 				(void *)(request->channels + n_channels);
3999 	}
4000 	request->n_match_sets = n_match_sets;
4001 
4002 	i = 0;
4003 	if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4004 		/* user specified, bail out if channel not found */
4005 		nla_for_each_nested(attr,
4006 				    info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4007 				    tmp) {
4008 			struct ieee80211_channel *chan;
4009 
4010 			chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4011 
4012 			if (!chan) {
4013 				err = -EINVAL;
4014 				goto out_free;
4015 			}
4016 
4017 			/* ignore disabled channels */
4018 			if (chan->flags & IEEE80211_CHAN_DISABLED)
4019 				continue;
4020 
4021 			request->channels[i] = chan;
4022 			i++;
4023 		}
4024 	} else {
4025 		/* all channels */
4026 		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4027 			int j;
4028 			if (!wiphy->bands[band])
4029 				continue;
4030 			for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4031 				struct ieee80211_channel *chan;
4032 
4033 				chan = &wiphy->bands[band]->channels[j];
4034 
4035 				if (chan->flags & IEEE80211_CHAN_DISABLED)
4036 					continue;
4037 
4038 				request->channels[i] = chan;
4039 				i++;
4040 			}
4041 		}
4042 	}
4043 
4044 	if (!i) {
4045 		err = -EINVAL;
4046 		goto out_free;
4047 	}
4048 
4049 	request->n_channels = i;
4050 
4051 	i = 0;
4052 	if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4053 		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4054 				    tmp) {
4055 			if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
4056 				err = -EINVAL;
4057 				goto out_free;
4058 			}
4059 			request->ssids[i].ssid_len = nla_len(attr);
4060 			memcpy(request->ssids[i].ssid, nla_data(attr),
4061 			       nla_len(attr));
4062 			i++;
4063 		}
4064 	}
4065 
4066 	i = 0;
4067 	if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4068 		nla_for_each_nested(attr,
4069 				    info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4070 				    tmp) {
4071 			struct nlattr *ssid;
4072 
4073 			nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4074 				  nla_data(attr), nla_len(attr),
4075 				  nl80211_match_policy);
4076 			ssid = tb[NL80211_ATTR_SCHED_SCAN_MATCH_SSID];
4077 			if (ssid) {
4078 				if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4079 					err = -EINVAL;
4080 					goto out_free;
4081 				}
4082 				memcpy(request->match_sets[i].ssid.ssid,
4083 				       nla_data(ssid), nla_len(ssid));
4084 				request->match_sets[i].ssid.ssid_len =
4085 					nla_len(ssid);
4086 			}
4087 			i++;
4088 		}
4089 	}
4090 
4091 	if (info->attrs[NL80211_ATTR_IE]) {
4092 		request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4093 		memcpy((void *)request->ie,
4094 		       nla_data(info->attrs[NL80211_ATTR_IE]),
4095 		       request->ie_len);
4096 	}
4097 
4098 	request->dev = dev;
4099 	request->wiphy = &rdev->wiphy;
4100 	request->interval = interval;
4101 
4102 	err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
4103 	if (!err) {
4104 		rdev->sched_scan_req = request;
4105 		nl80211_send_sched_scan(rdev, dev,
4106 					NL80211_CMD_START_SCHED_SCAN);
4107 		goto out;
4108 	}
4109 
4110 out_free:
4111 	kfree(request);
4112 out:
4113 	mutex_unlock(&rdev->sched_scan_mtx);
4114 	return err;
4115 }
4116 
nl80211_stop_sched_scan(struct sk_buff * skb,struct genl_info * info)4117 static int nl80211_stop_sched_scan(struct sk_buff *skb,
4118 				   struct genl_info *info)
4119 {
4120 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4121 	int err;
4122 
4123 	if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4124 	    !rdev->ops->sched_scan_stop)
4125 		return -EOPNOTSUPP;
4126 
4127 	mutex_lock(&rdev->sched_scan_mtx);
4128 	err = __cfg80211_stop_sched_scan(rdev, false);
4129 	mutex_unlock(&rdev->sched_scan_mtx);
4130 
4131 	return err;
4132 }
4133 
nl80211_send_bss(struct sk_buff * msg,struct netlink_callback * cb,u32 seq,int flags,struct cfg80211_registered_device * rdev,struct wireless_dev * wdev,struct cfg80211_internal_bss * intbss)4134 static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4135 			    u32 seq, int flags,
4136 			    struct cfg80211_registered_device *rdev,
4137 			    struct wireless_dev *wdev,
4138 			    struct cfg80211_internal_bss *intbss)
4139 {
4140 	struct cfg80211_bss *res = &intbss->pub;
4141 	void *hdr;
4142 	struct nlattr *bss;
4143 
4144 	ASSERT_WDEV_LOCK(wdev);
4145 
4146 	hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
4147 			     NL80211_CMD_NEW_SCAN_RESULTS);
4148 	if (!hdr)
4149 		return -1;
4150 
4151 	genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4152 
4153 	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
4154 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
4155 
4156 	bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4157 	if (!bss)
4158 		goto nla_put_failure;
4159 	if (!is_zero_ether_addr(res->bssid))
4160 		NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
4161 	if (res->information_elements && res->len_information_elements)
4162 		NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4163 			res->len_information_elements,
4164 			res->information_elements);
4165 	if (res->beacon_ies && res->len_beacon_ies &&
4166 	    res->beacon_ies != res->information_elements)
4167 		NLA_PUT(msg, NL80211_BSS_BEACON_IES,
4168 			res->len_beacon_ies, res->beacon_ies);
4169 	if (res->tsf)
4170 		NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
4171 	if (res->beacon_interval)
4172 		NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
4173 	NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
4174 	NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
4175 	NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
4176 		jiffies_to_msecs(jiffies - intbss->ts));
4177 
4178 	switch (rdev->wiphy.signal_type) {
4179 	case CFG80211_SIGNAL_TYPE_MBM:
4180 		NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
4181 		break;
4182 	case CFG80211_SIGNAL_TYPE_UNSPEC:
4183 		NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
4184 		break;
4185 	default:
4186 		break;
4187 	}
4188 
4189 	switch (wdev->iftype) {
4190 	case NL80211_IFTYPE_P2P_CLIENT:
4191 	case NL80211_IFTYPE_STATION:
4192 		if (intbss == wdev->current_bss)
4193 			NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4194 				    NL80211_BSS_STATUS_ASSOCIATED);
4195 		break;
4196 	case NL80211_IFTYPE_ADHOC:
4197 		if (intbss == wdev->current_bss)
4198 			NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4199 				    NL80211_BSS_STATUS_IBSS_JOINED);
4200 		break;
4201 	default:
4202 		break;
4203 	}
4204 
4205 	nla_nest_end(msg, bss);
4206 
4207 	return genlmsg_end(msg, hdr);
4208 
4209  nla_put_failure:
4210 	genlmsg_cancel(msg, hdr);
4211 	return -EMSGSIZE;
4212 }
4213 
nl80211_dump_scan(struct sk_buff * skb,struct netlink_callback * cb)4214 static int nl80211_dump_scan(struct sk_buff *skb,
4215 			     struct netlink_callback *cb)
4216 {
4217 	struct cfg80211_registered_device *rdev;
4218 	struct net_device *dev;
4219 	struct cfg80211_internal_bss *scan;
4220 	struct wireless_dev *wdev;
4221 	int start = cb->args[1], idx = 0;
4222 	int err;
4223 
4224 	err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4225 	if (err)
4226 		return err;
4227 
4228 	wdev = dev->ieee80211_ptr;
4229 
4230 	wdev_lock(wdev);
4231 	spin_lock_bh(&rdev->bss_lock);
4232 	cfg80211_bss_expire(rdev);
4233 
4234 	cb->seq = rdev->bss_generation;
4235 
4236 	list_for_each_entry(scan, &rdev->bss_list, list) {
4237 		if (++idx <= start)
4238 			continue;
4239 		if (nl80211_send_bss(skb, cb,
4240 				cb->nlh->nlmsg_seq, NLM_F_MULTI,
4241 				rdev, wdev, scan) < 0) {
4242 			idx--;
4243 			break;
4244 		}
4245 	}
4246 
4247 	spin_unlock_bh(&rdev->bss_lock);
4248 	wdev_unlock(wdev);
4249 
4250 	cb->args[1] = idx;
4251 	nl80211_finish_netdev_dump(rdev);
4252 
4253 	return skb->len;
4254 }
4255 
nl80211_send_survey(struct sk_buff * msg,u32 pid,u32 seq,int flags,struct net_device * dev,struct survey_info * survey)4256 static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4257 				int flags, struct net_device *dev,
4258 				struct survey_info *survey)
4259 {
4260 	void *hdr;
4261 	struct nlattr *infoattr;
4262 
4263 	hdr = nl80211hdr_put(msg, pid, seq, flags,
4264 			     NL80211_CMD_NEW_SURVEY_RESULTS);
4265 	if (!hdr)
4266 		return -ENOMEM;
4267 
4268 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
4269 
4270 	infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4271 	if (!infoattr)
4272 		goto nla_put_failure;
4273 
4274 	NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4275 		    survey->channel->center_freq);
4276 	if (survey->filled & SURVEY_INFO_NOISE_DBM)
4277 		NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
4278 			    survey->noise);
4279 	if (survey->filled & SURVEY_INFO_IN_USE)
4280 		NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
4281 	if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
4282 		NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4283 			    survey->channel_time);
4284 	if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
4285 		NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4286 			    survey->channel_time_busy);
4287 	if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
4288 		NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4289 			    survey->channel_time_ext_busy);
4290 	if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
4291 		NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4292 			    survey->channel_time_rx);
4293 	if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
4294 		NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4295 			    survey->channel_time_tx);
4296 
4297 	nla_nest_end(msg, infoattr);
4298 
4299 	return genlmsg_end(msg, hdr);
4300 
4301  nla_put_failure:
4302 	genlmsg_cancel(msg, hdr);
4303 	return -EMSGSIZE;
4304 }
4305 
nl80211_dump_survey(struct sk_buff * skb,struct netlink_callback * cb)4306 static int nl80211_dump_survey(struct sk_buff *skb,
4307 			struct netlink_callback *cb)
4308 {
4309 	struct survey_info survey;
4310 	struct cfg80211_registered_device *dev;
4311 	struct net_device *netdev;
4312 	int survey_idx = cb->args[1];
4313 	int res;
4314 
4315 	res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4316 	if (res)
4317 		return res;
4318 
4319 	if (!dev->ops->dump_survey) {
4320 		res = -EOPNOTSUPP;
4321 		goto out_err;
4322 	}
4323 
4324 	while (1) {
4325 		struct ieee80211_channel *chan;
4326 
4327 		res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4328 					    &survey);
4329 		if (res == -ENOENT)
4330 			break;
4331 		if (res)
4332 			goto out_err;
4333 
4334 		/* Survey without a channel doesn't make sense */
4335 		if (!survey.channel) {
4336 			res = -EINVAL;
4337 			goto out;
4338 		}
4339 
4340 		chan = ieee80211_get_channel(&dev->wiphy,
4341 					     survey.channel->center_freq);
4342 		if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4343 			survey_idx++;
4344 			continue;
4345 		}
4346 
4347 		if (nl80211_send_survey(skb,
4348 				NETLINK_CB(cb->skb).pid,
4349 				cb->nlh->nlmsg_seq, NLM_F_MULTI,
4350 				netdev,
4351 				&survey) < 0)
4352 			goto out;
4353 		survey_idx++;
4354 	}
4355 
4356  out:
4357 	cb->args[1] = survey_idx;
4358 	res = skb->len;
4359  out_err:
4360 	nl80211_finish_netdev_dump(dev);
4361 	return res;
4362 }
4363 
nl80211_valid_auth_type(enum nl80211_auth_type auth_type)4364 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4365 {
4366 	return auth_type <= NL80211_AUTHTYPE_MAX;
4367 }
4368 
nl80211_valid_wpa_versions(u32 wpa_versions)4369 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4370 {
4371 	return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4372 				  NL80211_WPA_VERSION_2));
4373 }
4374 
nl80211_authenticate(struct sk_buff * skb,struct genl_info * info)4375 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4376 {
4377 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4378 	struct net_device *dev = info->user_ptr[1];
4379 	struct ieee80211_channel *chan;
4380 	const u8 *bssid, *ssid, *ie = NULL;
4381 	int err, ssid_len, ie_len = 0;
4382 	enum nl80211_auth_type auth_type;
4383 	struct key_parse key;
4384 	bool local_state_change;
4385 
4386 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4387 		return -EINVAL;
4388 
4389 	if (!info->attrs[NL80211_ATTR_MAC])
4390 		return -EINVAL;
4391 
4392 	if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4393 		return -EINVAL;
4394 
4395 	if (!info->attrs[NL80211_ATTR_SSID])
4396 		return -EINVAL;
4397 
4398 	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4399 		return -EINVAL;
4400 
4401 	err = nl80211_parse_key(info, &key);
4402 	if (err)
4403 		return err;
4404 
4405 	if (key.idx >= 0) {
4406 		if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4407 			return -EINVAL;
4408 		if (!key.p.key || !key.p.key_len)
4409 			return -EINVAL;
4410 		if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4411 		     key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4412 		    (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4413 		     key.p.key_len != WLAN_KEY_LEN_WEP104))
4414 			return -EINVAL;
4415 		if (key.idx > 4)
4416 			return -EINVAL;
4417 	} else {
4418 		key.p.key_len = 0;
4419 		key.p.key = NULL;
4420 	}
4421 
4422 	if (key.idx >= 0) {
4423 		int i;
4424 		bool ok = false;
4425 		for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4426 			if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4427 				ok = true;
4428 				break;
4429 			}
4430 		}
4431 		if (!ok)
4432 			return -EINVAL;
4433 	}
4434 
4435 	if (!rdev->ops->auth)
4436 		return -EOPNOTSUPP;
4437 
4438 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4439 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4440 		return -EOPNOTSUPP;
4441 
4442 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4443 	chan = ieee80211_get_channel(&rdev->wiphy,
4444 		nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4445 	if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4446 		return -EINVAL;
4447 
4448 	ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4449 	ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4450 
4451 	if (info->attrs[NL80211_ATTR_IE]) {
4452 		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4453 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4454 	}
4455 
4456 	auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4457 	if (!nl80211_valid_auth_type(auth_type))
4458 		return -EINVAL;
4459 
4460 	local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4461 
4462 	/*
4463 	 * Since we no longer track auth state, ignore
4464 	 * requests to only change local state.
4465 	 */
4466 	if (local_state_change)
4467 		return 0;
4468 
4469 	return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4470 				  ssid, ssid_len, ie, ie_len,
4471 				  key.p.key, key.p.key_len, key.idx);
4472 }
4473 
nl80211_crypto_settings(struct cfg80211_registered_device * rdev,struct genl_info * info,struct cfg80211_crypto_settings * settings,int cipher_limit)4474 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4475 				   struct genl_info *info,
4476 				   struct cfg80211_crypto_settings *settings,
4477 				   int cipher_limit)
4478 {
4479 	memset(settings, 0, sizeof(*settings));
4480 
4481 	settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4482 
4483 	if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4484 		u16 proto;
4485 		proto = nla_get_u16(
4486 			info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4487 		settings->control_port_ethertype = cpu_to_be16(proto);
4488 		if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4489 		    proto != ETH_P_PAE)
4490 			return -EINVAL;
4491 		if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4492 			settings->control_port_no_encrypt = true;
4493 	} else
4494 		settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4495 
4496 	if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4497 		void *data;
4498 		int len, i;
4499 
4500 		data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4501 		len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4502 		settings->n_ciphers_pairwise = len / sizeof(u32);
4503 
4504 		if (len % sizeof(u32))
4505 			return -EINVAL;
4506 
4507 		if (settings->n_ciphers_pairwise > cipher_limit)
4508 			return -EINVAL;
4509 
4510 		memcpy(settings->ciphers_pairwise, data, len);
4511 
4512 		for (i = 0; i < settings->n_ciphers_pairwise; i++)
4513 			if (!cfg80211_supported_cipher_suite(
4514 					&rdev->wiphy,
4515 					settings->ciphers_pairwise[i]))
4516 				return -EINVAL;
4517 	}
4518 
4519 	if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4520 		settings->cipher_group =
4521 			nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
4522 		if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4523 						     settings->cipher_group))
4524 			return -EINVAL;
4525 	}
4526 
4527 	if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4528 		settings->wpa_versions =
4529 			nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4530 		if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4531 			return -EINVAL;
4532 	}
4533 
4534 	if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4535 		void *data;
4536 		int len;
4537 
4538 		data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4539 		len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4540 		settings->n_akm_suites = len / sizeof(u32);
4541 
4542 		if (len % sizeof(u32))
4543 			return -EINVAL;
4544 
4545 		if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4546 			return -EINVAL;
4547 
4548 		memcpy(settings->akm_suites, data, len);
4549 	}
4550 
4551 	return 0;
4552 }
4553 
nl80211_associate(struct sk_buff * skb,struct genl_info * info)4554 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4555 {
4556 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4557 	struct net_device *dev = info->user_ptr[1];
4558 	struct cfg80211_crypto_settings crypto;
4559 	struct ieee80211_channel *chan;
4560 	const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
4561 	int err, ssid_len, ie_len = 0;
4562 	bool use_mfp = false;
4563 	u32 flags = 0;
4564 	struct ieee80211_ht_cap *ht_capa = NULL;
4565 	struct ieee80211_ht_cap *ht_capa_mask = NULL;
4566 
4567 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4568 		return -EINVAL;
4569 
4570 	if (!info->attrs[NL80211_ATTR_MAC] ||
4571 	    !info->attrs[NL80211_ATTR_SSID] ||
4572 	    !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4573 		return -EINVAL;
4574 
4575 	if (!rdev->ops->assoc)
4576 		return -EOPNOTSUPP;
4577 
4578 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4579 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4580 		return -EOPNOTSUPP;
4581 
4582 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4583 
4584 	chan = ieee80211_get_channel(&rdev->wiphy,
4585 		nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4586 	if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4587 		return -EINVAL;
4588 
4589 	ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4590 	ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4591 
4592 	if (info->attrs[NL80211_ATTR_IE]) {
4593 		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4594 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4595 	}
4596 
4597 	if (info->attrs[NL80211_ATTR_USE_MFP]) {
4598 		enum nl80211_mfp mfp =
4599 			nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4600 		if (mfp == NL80211_MFP_REQUIRED)
4601 			use_mfp = true;
4602 		else if (mfp != NL80211_MFP_NO)
4603 			return -EINVAL;
4604 	}
4605 
4606 	if (info->attrs[NL80211_ATTR_PREV_BSSID])
4607 		prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4608 
4609 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
4610 		flags |= ASSOC_REQ_DISABLE_HT;
4611 
4612 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
4613 		ht_capa_mask =
4614 			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
4615 
4616 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
4617 		if (!ht_capa_mask)
4618 			return -EINVAL;
4619 		ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4620 	}
4621 
4622 	err = nl80211_crypto_settings(rdev, info, &crypto, 1);
4623 	if (!err)
4624 		err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4625 					  ssid, ssid_len, ie, ie_len, use_mfp,
4626 					  &crypto, flags, ht_capa,
4627 					  ht_capa_mask);
4628 
4629 	return err;
4630 }
4631 
nl80211_deauthenticate(struct sk_buff * skb,struct genl_info * info)4632 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4633 {
4634 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4635 	struct net_device *dev = info->user_ptr[1];
4636 	const u8 *ie = NULL, *bssid;
4637 	int ie_len = 0;
4638 	u16 reason_code;
4639 	bool local_state_change;
4640 
4641 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4642 		return -EINVAL;
4643 
4644 	if (!info->attrs[NL80211_ATTR_MAC])
4645 		return -EINVAL;
4646 
4647 	if (!info->attrs[NL80211_ATTR_REASON_CODE])
4648 		return -EINVAL;
4649 
4650 	if (!rdev->ops->deauth)
4651 		return -EOPNOTSUPP;
4652 
4653 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4654 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4655 		return -EOPNOTSUPP;
4656 
4657 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4658 
4659 	reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4660 	if (reason_code == 0) {
4661 		/* Reason Code 0 is reserved */
4662 		return -EINVAL;
4663 	}
4664 
4665 	if (info->attrs[NL80211_ATTR_IE]) {
4666 		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4667 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4668 	}
4669 
4670 	local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4671 
4672 	return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4673 				    local_state_change);
4674 }
4675 
nl80211_disassociate(struct sk_buff * skb,struct genl_info * info)4676 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4677 {
4678 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4679 	struct net_device *dev = info->user_ptr[1];
4680 	const u8 *ie = NULL, *bssid;
4681 	int ie_len = 0;
4682 	u16 reason_code;
4683 	bool local_state_change;
4684 
4685 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4686 		return -EINVAL;
4687 
4688 	if (!info->attrs[NL80211_ATTR_MAC])
4689 		return -EINVAL;
4690 
4691 	if (!info->attrs[NL80211_ATTR_REASON_CODE])
4692 		return -EINVAL;
4693 
4694 	if (!rdev->ops->disassoc)
4695 		return -EOPNOTSUPP;
4696 
4697 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4698 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4699 		return -EOPNOTSUPP;
4700 
4701 	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4702 
4703 	reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4704 	if (reason_code == 0) {
4705 		/* Reason Code 0 is reserved */
4706 		return -EINVAL;
4707 	}
4708 
4709 	if (info->attrs[NL80211_ATTR_IE]) {
4710 		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4711 		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4712 	}
4713 
4714 	local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4715 
4716 	return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4717 				      local_state_change);
4718 }
4719 
4720 static bool
nl80211_parse_mcast_rate(struct cfg80211_registered_device * rdev,int mcast_rate[IEEE80211_NUM_BANDS],int rateval)4721 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4722 			 int mcast_rate[IEEE80211_NUM_BANDS],
4723 			 int rateval)
4724 {
4725 	struct wiphy *wiphy = &rdev->wiphy;
4726 	bool found = false;
4727 	int band, i;
4728 
4729 	for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4730 		struct ieee80211_supported_band *sband;
4731 
4732 		sband = wiphy->bands[band];
4733 		if (!sband)
4734 			continue;
4735 
4736 		for (i = 0; i < sband->n_bitrates; i++) {
4737 			if (sband->bitrates[i].bitrate == rateval) {
4738 				mcast_rate[band] = i + 1;
4739 				found = true;
4740 				break;
4741 			}
4742 		}
4743 	}
4744 
4745 	return found;
4746 }
4747 
nl80211_join_ibss(struct sk_buff * skb,struct genl_info * info)4748 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4749 {
4750 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4751 	struct net_device *dev = info->user_ptr[1];
4752 	struct cfg80211_ibss_params ibss;
4753 	struct wiphy *wiphy;
4754 	struct cfg80211_cached_keys *connkeys = NULL;
4755 	int err;
4756 
4757 	memset(&ibss, 0, sizeof(ibss));
4758 
4759 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4760 		return -EINVAL;
4761 
4762 	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4763 	    !info->attrs[NL80211_ATTR_SSID] ||
4764 	    !nla_len(info->attrs[NL80211_ATTR_SSID]))
4765 		return -EINVAL;
4766 
4767 	ibss.beacon_interval = 100;
4768 
4769 	if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4770 		ibss.beacon_interval =
4771 			nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4772 		if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4773 			return -EINVAL;
4774 	}
4775 
4776 	if (!rdev->ops->join_ibss)
4777 		return -EOPNOTSUPP;
4778 
4779 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4780 		return -EOPNOTSUPP;
4781 
4782 	wiphy = &rdev->wiphy;
4783 
4784 	if (info->attrs[NL80211_ATTR_MAC]) {
4785 		ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4786 
4787 		if (!is_valid_ether_addr(ibss.bssid))
4788 			return -EINVAL;
4789 	}
4790 	ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4791 	ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4792 
4793 	if (info->attrs[NL80211_ATTR_IE]) {
4794 		ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4795 		ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4796 	}
4797 
4798 	if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4799 		enum nl80211_channel_type channel_type;
4800 
4801 		channel_type = nla_get_u32(
4802 				info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4803 		if (channel_type != NL80211_CHAN_NO_HT &&
4804 		    channel_type != NL80211_CHAN_HT20 &&
4805 		    channel_type != NL80211_CHAN_HT40MINUS &&
4806 		    channel_type != NL80211_CHAN_HT40PLUS)
4807 			return -EINVAL;
4808 
4809 		if (channel_type != NL80211_CHAN_NO_HT &&
4810 		    !(wiphy->features & NL80211_FEATURE_HT_IBSS))
4811 			return -EINVAL;
4812 
4813 		ibss.channel_type = channel_type;
4814 	} else {
4815 		ibss.channel_type = NL80211_CHAN_NO_HT;
4816 	}
4817 
4818 	ibss.channel = rdev_freq_to_chan(rdev,
4819 		nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
4820 		ibss.channel_type);
4821 	if (!ibss.channel ||
4822 	    ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4823 	    ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4824 		return -EINVAL;
4825 
4826 	/* Both channels should be able to initiate communication */
4827 	if ((ibss.channel_type == NL80211_CHAN_HT40PLUS ||
4828 	     ibss.channel_type == NL80211_CHAN_HT40MINUS) &&
4829 	    !cfg80211_can_beacon_sec_chan(&rdev->wiphy, ibss.channel,
4830 					  ibss.channel_type))
4831 		return -EINVAL;
4832 
4833 	ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
4834 	ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4835 
4836 	if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4837 		u8 *rates =
4838 			nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4839 		int n_rates =
4840 			nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4841 		struct ieee80211_supported_band *sband =
4842 			wiphy->bands[ibss.channel->band];
4843 
4844 		err = ieee80211_get_ratemask(sband, rates, n_rates,
4845 					     &ibss.basic_rates);
4846 		if (err)
4847 			return err;
4848 	}
4849 
4850 	if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4851 	    !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4852 			nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4853 		return -EINVAL;
4854 
4855 	if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4856 		connkeys = nl80211_parse_connkeys(rdev,
4857 					info->attrs[NL80211_ATTR_KEYS]);
4858 		if (IS_ERR(connkeys))
4859 			return PTR_ERR(connkeys);
4860 	}
4861 
4862 	ibss.control_port =
4863 		nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
4864 
4865 	err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
4866 	if (err)
4867 		kfree(connkeys);
4868 	return err;
4869 }
4870 
nl80211_leave_ibss(struct sk_buff * skb,struct genl_info * info)4871 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4872 {
4873 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4874 	struct net_device *dev = info->user_ptr[1];
4875 
4876 	if (!rdev->ops->leave_ibss)
4877 		return -EOPNOTSUPP;
4878 
4879 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4880 		return -EOPNOTSUPP;
4881 
4882 	return cfg80211_leave_ibss(rdev, dev, false);
4883 }
4884 
4885 #ifdef CONFIG_NL80211_TESTMODE
4886 static struct genl_multicast_group nl80211_testmode_mcgrp = {
4887 	.name = "testmode",
4888 };
4889 
nl80211_testmode_do(struct sk_buff * skb,struct genl_info * info)4890 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4891 {
4892 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
4893 	int err;
4894 
4895 	if (!info->attrs[NL80211_ATTR_TESTDATA])
4896 		return -EINVAL;
4897 
4898 	err = -EOPNOTSUPP;
4899 	if (rdev->ops->testmode_cmd) {
4900 		rdev->testmode_info = info;
4901 		err = rdev->ops->testmode_cmd(&rdev->wiphy,
4902 				nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4903 				nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4904 		rdev->testmode_info = NULL;
4905 	}
4906 
4907 	return err;
4908 }
4909 
nl80211_testmode_dump(struct sk_buff * skb,struct netlink_callback * cb)4910 static int nl80211_testmode_dump(struct sk_buff *skb,
4911 				 struct netlink_callback *cb)
4912 {
4913 	struct cfg80211_registered_device *rdev;
4914 	int err;
4915 	long phy_idx;
4916 	void *data = NULL;
4917 	int data_len = 0;
4918 
4919 	if (cb->args[0]) {
4920 		/*
4921 		 * 0 is a valid index, but not valid for args[0],
4922 		 * so we need to offset by 1.
4923 		 */
4924 		phy_idx = cb->args[0] - 1;
4925 	} else {
4926 		err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
4927 				  nl80211_fam.attrbuf, nl80211_fam.maxattr,
4928 				  nl80211_policy);
4929 		if (err)
4930 			return err;
4931 		if (nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]) {
4932 			phy_idx = nla_get_u32(
4933 				nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
4934 		} else {
4935 			struct net_device *netdev;
4936 
4937 			err = get_rdev_dev_by_ifindex(sock_net(skb->sk),
4938 						      nl80211_fam.attrbuf,
4939 						      &rdev, &netdev);
4940 			if (err)
4941 				return err;
4942 			dev_put(netdev);
4943 			phy_idx = rdev->wiphy_idx;
4944 			cfg80211_unlock_rdev(rdev);
4945 		}
4946 		if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
4947 			cb->args[1] =
4948 				(long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
4949 	}
4950 
4951 	if (cb->args[1]) {
4952 		data = nla_data((void *)cb->args[1]);
4953 		data_len = nla_len((void *)cb->args[1]);
4954 	}
4955 
4956 	mutex_lock(&cfg80211_mutex);
4957 	rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
4958 	if (!rdev) {
4959 		mutex_unlock(&cfg80211_mutex);
4960 		return -ENOENT;
4961 	}
4962 	cfg80211_lock_rdev(rdev);
4963 	mutex_unlock(&cfg80211_mutex);
4964 
4965 	if (!rdev->ops->testmode_dump) {
4966 		err = -EOPNOTSUPP;
4967 		goto out_err;
4968 	}
4969 
4970 	while (1) {
4971 		void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
4972 					   cb->nlh->nlmsg_seq, NLM_F_MULTI,
4973 					   NL80211_CMD_TESTMODE);
4974 		struct nlattr *tmdata;
4975 
4976 		if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx) < 0) {
4977 			genlmsg_cancel(skb, hdr);
4978 			break;
4979 		}
4980 
4981 		tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4982 		if (!tmdata) {
4983 			genlmsg_cancel(skb, hdr);
4984 			break;
4985 		}
4986 		err = rdev->ops->testmode_dump(&rdev->wiphy, skb, cb,
4987 					       data, data_len);
4988 		nla_nest_end(skb, tmdata);
4989 
4990 		if (err == -ENOBUFS || err == -ENOENT) {
4991 			genlmsg_cancel(skb, hdr);
4992 			break;
4993 		} else if (err) {
4994 			genlmsg_cancel(skb, hdr);
4995 			goto out_err;
4996 		}
4997 
4998 		genlmsg_end(skb, hdr);
4999 	}
5000 
5001 	err = skb->len;
5002 	/* see above */
5003 	cb->args[0] = phy_idx + 1;
5004  out_err:
5005 	cfg80211_unlock_rdev(rdev);
5006 	return err;
5007 }
5008 
5009 static struct sk_buff *
__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device * rdev,int approxlen,u32 pid,u32 seq,gfp_t gfp)5010 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
5011 			      int approxlen, u32 pid, u32 seq, gfp_t gfp)
5012 {
5013 	struct sk_buff *skb;
5014 	void *hdr;
5015 	struct nlattr *data;
5016 
5017 	skb = nlmsg_new(approxlen + 100, gfp);
5018 	if (!skb)
5019 		return NULL;
5020 
5021 	hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
5022 	if (!hdr) {
5023 		kfree_skb(skb);
5024 		return NULL;
5025 	}
5026 
5027 	NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5028 	data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5029 
5030 	((void **)skb->cb)[0] = rdev;
5031 	((void **)skb->cb)[1] = hdr;
5032 	((void **)skb->cb)[2] = data;
5033 
5034 	return skb;
5035 
5036  nla_put_failure:
5037 	kfree_skb(skb);
5038 	return NULL;
5039 }
5040 
cfg80211_testmode_alloc_reply_skb(struct wiphy * wiphy,int approxlen)5041 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5042 						  int approxlen)
5043 {
5044 	struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5045 
5046 	if (WARN_ON(!rdev->testmode_info))
5047 		return NULL;
5048 
5049 	return __cfg80211_testmode_alloc_skb(rdev, approxlen,
5050 				rdev->testmode_info->snd_pid,
5051 				rdev->testmode_info->snd_seq,
5052 				GFP_KERNEL);
5053 }
5054 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5055 
cfg80211_testmode_reply(struct sk_buff * skb)5056 int cfg80211_testmode_reply(struct sk_buff *skb)
5057 {
5058 	struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5059 	void *hdr = ((void **)skb->cb)[1];
5060 	struct nlattr *data = ((void **)skb->cb)[2];
5061 
5062 	if (WARN_ON(!rdev->testmode_info)) {
5063 		kfree_skb(skb);
5064 		return -EINVAL;
5065 	}
5066 
5067 	nla_nest_end(skb, data);
5068 	genlmsg_end(skb, hdr);
5069 	return genlmsg_reply(skb, rdev->testmode_info);
5070 }
5071 EXPORT_SYMBOL(cfg80211_testmode_reply);
5072 
cfg80211_testmode_alloc_event_skb(struct wiphy * wiphy,int approxlen,gfp_t gfp)5073 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5074 						  int approxlen, gfp_t gfp)
5075 {
5076 	struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5077 
5078 	return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5079 }
5080 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5081 
cfg80211_testmode_event(struct sk_buff * skb,gfp_t gfp)5082 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5083 {
5084 	struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5085 	void *hdr = ((void **)skb->cb)[1];
5086 	struct nlattr *data = ((void **)skb->cb)[2];
5087 
5088 	nla_nest_end(skb, data);
5089 	genlmsg_end(skb, hdr);
5090 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), skb, 0,
5091 				nl80211_testmode_mcgrp.id, gfp);
5092 }
5093 EXPORT_SYMBOL(cfg80211_testmode_event);
5094 #endif
5095 
nl80211_connect(struct sk_buff * skb,struct genl_info * info)5096 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5097 {
5098 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5099 	struct net_device *dev = info->user_ptr[1];
5100 	struct cfg80211_connect_params connect;
5101 	struct wiphy *wiphy;
5102 	struct cfg80211_cached_keys *connkeys = NULL;
5103 	int err;
5104 
5105 	memset(&connect, 0, sizeof(connect));
5106 
5107 	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5108 		return -EINVAL;
5109 
5110 	if (!info->attrs[NL80211_ATTR_SSID] ||
5111 	    !nla_len(info->attrs[NL80211_ATTR_SSID]))
5112 		return -EINVAL;
5113 
5114 	if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5115 		connect.auth_type =
5116 			nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
5117 		if (!nl80211_valid_auth_type(connect.auth_type))
5118 			return -EINVAL;
5119 	} else
5120 		connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5121 
5122 	connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5123 
5124 	err = nl80211_crypto_settings(rdev, info, &connect.crypto,
5125 				      NL80211_MAX_NR_CIPHER_SUITES);
5126 	if (err)
5127 		return err;
5128 
5129 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5130 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5131 		return -EOPNOTSUPP;
5132 
5133 	wiphy = &rdev->wiphy;
5134 
5135 	connect.bg_scan_period = -1;
5136 	if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
5137 		(wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
5138 		connect.bg_scan_period =
5139 			nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
5140 	}
5141 
5142 	if (info->attrs[NL80211_ATTR_MAC])
5143 		connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5144 	connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5145 	connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5146 
5147 	if (info->attrs[NL80211_ATTR_IE]) {
5148 		connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5149 		connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5150 	}
5151 
5152 	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5153 		connect.channel =
5154 			ieee80211_get_channel(wiphy,
5155 			    nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5156 		if (!connect.channel ||
5157 		    connect.channel->flags & IEEE80211_CHAN_DISABLED)
5158 			return -EINVAL;
5159 	}
5160 
5161 	if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5162 		connkeys = nl80211_parse_connkeys(rdev,
5163 					info->attrs[NL80211_ATTR_KEYS]);
5164 		if (IS_ERR(connkeys))
5165 			return PTR_ERR(connkeys);
5166 	}
5167 
5168 	if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5169 		connect.flags |= ASSOC_REQ_DISABLE_HT;
5170 
5171 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5172 		memcpy(&connect.ht_capa_mask,
5173 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5174 		       sizeof(connect.ht_capa_mask));
5175 
5176 	if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5177 		if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5178 			return -EINVAL;
5179 		memcpy(&connect.ht_capa,
5180 		       nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5181 		       sizeof(connect.ht_capa));
5182 	}
5183 
5184 	err = cfg80211_connect(rdev, dev, &connect, connkeys);
5185 	if (err)
5186 		kfree(connkeys);
5187 	return err;
5188 }
5189 
nl80211_disconnect(struct sk_buff * skb,struct genl_info * info)5190 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5191 {
5192 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5193 	struct net_device *dev = info->user_ptr[1];
5194 	u16 reason;
5195 
5196 	if (!info->attrs[NL80211_ATTR_REASON_CODE])
5197 		reason = WLAN_REASON_DEAUTH_LEAVING;
5198 	else
5199 		reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5200 
5201 	if (reason == 0)
5202 		return -EINVAL;
5203 
5204 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5205 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5206 		return -EOPNOTSUPP;
5207 
5208 	return cfg80211_disconnect(rdev, dev, reason, true);
5209 }
5210 
nl80211_wiphy_netns(struct sk_buff * skb,struct genl_info * info)5211 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
5212 {
5213 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5214 	struct net *net;
5215 	int err;
5216 	u32 pid;
5217 
5218 	if (!info->attrs[NL80211_ATTR_PID])
5219 		return -EINVAL;
5220 
5221 	pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
5222 
5223 	net = get_net_ns_by_pid(pid);
5224 	if (IS_ERR(net))
5225 		return PTR_ERR(net);
5226 
5227 	err = 0;
5228 
5229 	/* check if anything to do */
5230 	if (!net_eq(wiphy_net(&rdev->wiphy), net))
5231 		err = cfg80211_switch_netns(rdev, net);
5232 
5233 	put_net(net);
5234 	return err;
5235 }
5236 
nl80211_setdel_pmksa(struct sk_buff * skb,struct genl_info * info)5237 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
5238 {
5239 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5240 	int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
5241 			struct cfg80211_pmksa *pmksa) = NULL;
5242 	struct net_device *dev = info->user_ptr[1];
5243 	struct cfg80211_pmksa pmksa;
5244 
5245 	memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
5246 
5247 	if (!info->attrs[NL80211_ATTR_MAC])
5248 		return -EINVAL;
5249 
5250 	if (!info->attrs[NL80211_ATTR_PMKID])
5251 		return -EINVAL;
5252 
5253 	pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
5254 	pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5255 
5256 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5257 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5258 		return -EOPNOTSUPP;
5259 
5260 	switch (info->genlhdr->cmd) {
5261 	case NL80211_CMD_SET_PMKSA:
5262 		rdev_ops = rdev->ops->set_pmksa;
5263 		break;
5264 	case NL80211_CMD_DEL_PMKSA:
5265 		rdev_ops = rdev->ops->del_pmksa;
5266 		break;
5267 	default:
5268 		WARN_ON(1);
5269 		break;
5270 	}
5271 
5272 	if (!rdev_ops)
5273 		return -EOPNOTSUPP;
5274 
5275 	return rdev_ops(&rdev->wiphy, dev, &pmksa);
5276 }
5277 
nl80211_flush_pmksa(struct sk_buff * skb,struct genl_info * info)5278 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5279 {
5280 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5281 	struct net_device *dev = info->user_ptr[1];
5282 
5283 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5284 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5285 		return -EOPNOTSUPP;
5286 
5287 	if (!rdev->ops->flush_pmksa)
5288 		return -EOPNOTSUPP;
5289 
5290 	return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
5291 }
5292 
nl80211_tdls_mgmt(struct sk_buff * skb,struct genl_info * info)5293 static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5294 {
5295 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5296 	struct net_device *dev = info->user_ptr[1];
5297 	u8 action_code, dialog_token;
5298 	u16 status_code;
5299 	u8 *peer;
5300 
5301 	if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5302 	    !rdev->ops->tdls_mgmt)
5303 		return -EOPNOTSUPP;
5304 
5305 	if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5306 	    !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5307 	    !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5308 	    !info->attrs[NL80211_ATTR_IE] ||
5309 	    !info->attrs[NL80211_ATTR_MAC])
5310 		return -EINVAL;
5311 
5312 	peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5313 	action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5314 	status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5315 	dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5316 
5317 	return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5318 				    dialog_token, status_code,
5319 				    nla_data(info->attrs[NL80211_ATTR_IE]),
5320 				    nla_len(info->attrs[NL80211_ATTR_IE]));
5321 }
5322 
nl80211_tdls_oper(struct sk_buff * skb,struct genl_info * info)5323 static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5324 {
5325 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5326 	struct net_device *dev = info->user_ptr[1];
5327 	enum nl80211_tdls_operation operation;
5328 	u8 *peer;
5329 
5330 	if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5331 	    !rdev->ops->tdls_oper)
5332 		return -EOPNOTSUPP;
5333 
5334 	if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5335 	    !info->attrs[NL80211_ATTR_MAC])
5336 		return -EINVAL;
5337 
5338 	operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5339 	peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5340 
5341 	return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5342 }
5343 
nl80211_remain_on_channel(struct sk_buff * skb,struct genl_info * info)5344 static int nl80211_remain_on_channel(struct sk_buff *skb,
5345 				     struct genl_info *info)
5346 {
5347 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5348 	struct net_device *dev = info->user_ptr[1];
5349 	struct ieee80211_channel *chan;
5350 	struct sk_buff *msg;
5351 	void *hdr;
5352 	u64 cookie;
5353 	enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5354 	u32 freq, duration;
5355 	int err;
5356 
5357 	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5358 	    !info->attrs[NL80211_ATTR_DURATION])
5359 		return -EINVAL;
5360 
5361 	duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5362 
5363 	/*
5364 	 * We should be on that channel for at least one jiffie,
5365 	 * and more than 5 seconds seems excessive.
5366 	 */
5367 	if (!duration || !msecs_to_jiffies(duration) ||
5368 	    duration > rdev->wiphy.max_remain_on_channel_duration)
5369 		return -EINVAL;
5370 
5371 	if (!rdev->ops->remain_on_channel ||
5372 	    !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
5373 		return -EOPNOTSUPP;
5374 
5375 	if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5376 		channel_type = nla_get_u32(
5377 			info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5378 		if (channel_type != NL80211_CHAN_NO_HT &&
5379 		    channel_type != NL80211_CHAN_HT20 &&
5380 		    channel_type != NL80211_CHAN_HT40PLUS &&
5381 		    channel_type != NL80211_CHAN_HT40MINUS)
5382 			return -EINVAL;
5383 	}
5384 
5385 	freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5386 	chan = rdev_freq_to_chan(rdev, freq, channel_type);
5387 	if (chan == NULL)
5388 		return -EINVAL;
5389 
5390 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5391 	if (!msg)
5392 		return -ENOMEM;
5393 
5394 	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5395 			     NL80211_CMD_REMAIN_ON_CHANNEL);
5396 
5397 	if (IS_ERR(hdr)) {
5398 		err = PTR_ERR(hdr);
5399 		goto free_msg;
5400 	}
5401 
5402 	err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5403 					   channel_type, duration, &cookie);
5404 
5405 	if (err)
5406 		goto free_msg;
5407 
5408 	NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5409 
5410 	genlmsg_end(msg, hdr);
5411 
5412 	return genlmsg_reply(msg, info);
5413 
5414  nla_put_failure:
5415 	err = -ENOBUFS;
5416  free_msg:
5417 	nlmsg_free(msg);
5418 	return err;
5419 }
5420 
nl80211_cancel_remain_on_channel(struct sk_buff * skb,struct genl_info * info)5421 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5422 					    struct genl_info *info)
5423 {
5424 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5425 	struct net_device *dev = info->user_ptr[1];
5426 	u64 cookie;
5427 
5428 	if (!info->attrs[NL80211_ATTR_COOKIE])
5429 		return -EINVAL;
5430 
5431 	if (!rdev->ops->cancel_remain_on_channel)
5432 		return -EOPNOTSUPP;
5433 
5434 	cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5435 
5436 	return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
5437 }
5438 
rateset_to_mask(struct ieee80211_supported_band * sband,u8 * rates,u8 rates_len)5439 static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5440 			   u8 *rates, u8 rates_len)
5441 {
5442 	u8 i;
5443 	u32 mask = 0;
5444 
5445 	for (i = 0; i < rates_len; i++) {
5446 		int rate = (rates[i] & 0x7f) * 5;
5447 		int ridx;
5448 		for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5449 			struct ieee80211_rate *srate =
5450 				&sband->bitrates[ridx];
5451 			if (rate == srate->bitrate) {
5452 				mask |= 1 << ridx;
5453 				break;
5454 			}
5455 		}
5456 		if (ridx == sband->n_bitrates)
5457 			return 0; /* rate not found */
5458 	}
5459 
5460 	return mask;
5461 }
5462 
ht_rateset_to_mask(struct ieee80211_supported_band * sband,u8 * rates,u8 rates_len,u8 mcs[IEEE80211_HT_MCS_MASK_LEN])5463 static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
5464 			       u8 *rates, u8 rates_len,
5465 			       u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
5466 {
5467 	u8 i;
5468 
5469 	memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
5470 
5471 	for (i = 0; i < rates_len; i++) {
5472 		int ridx, rbit;
5473 
5474 		ridx = rates[i] / 8;
5475 		rbit = BIT(rates[i] % 8);
5476 
5477 		/* check validity */
5478 		if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
5479 			return false;
5480 
5481 		/* check availability */
5482 		if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
5483 			mcs[ridx] |= rbit;
5484 		else
5485 			return false;
5486 	}
5487 
5488 	return true;
5489 }
5490 
5491 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
5492 	[NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5493 				    .len = NL80211_MAX_SUPP_RATES },
5494 	[NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
5495 				 .len = NL80211_MAX_SUPP_HT_RATES },
5496 };
5497 
nl80211_set_tx_bitrate_mask(struct sk_buff * skb,struct genl_info * info)5498 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5499 				       struct genl_info *info)
5500 {
5501 	struct nlattr *tb[NL80211_TXRATE_MAX + 1];
5502 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5503 	struct cfg80211_bitrate_mask mask;
5504 	int rem, i;
5505 	struct net_device *dev = info->user_ptr[1];
5506 	struct nlattr *tx_rates;
5507 	struct ieee80211_supported_band *sband;
5508 
5509 	if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5510 		return -EINVAL;
5511 
5512 	if (!rdev->ops->set_bitrate_mask)
5513 		return -EOPNOTSUPP;
5514 
5515 	memset(&mask, 0, sizeof(mask));
5516 	/* Default to all rates enabled */
5517 	for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5518 		sband = rdev->wiphy.bands[i];
5519 		mask.control[i].legacy =
5520 			sband ? (1 << sband->n_bitrates) - 1 : 0;
5521 		if (sband)
5522 			memcpy(mask.control[i].mcs,
5523 			       sband->ht_cap.mcs.rx_mask,
5524 			       sizeof(mask.control[i].mcs));
5525 		else
5526 			memset(mask.control[i].mcs, 0,
5527 			       sizeof(mask.control[i].mcs));
5528 	}
5529 
5530 	/*
5531 	 * The nested attribute uses enum nl80211_band as the index. This maps
5532 	 * directly to the enum ieee80211_band values used in cfg80211.
5533 	 */
5534 	BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
5535 	nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5536 	{
5537 		enum ieee80211_band band = nla_type(tx_rates);
5538 		if (band < 0 || band >= IEEE80211_NUM_BANDS)
5539 			return -EINVAL;
5540 		sband = rdev->wiphy.bands[band];
5541 		if (sband == NULL)
5542 			return -EINVAL;
5543 		nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5544 			  nla_len(tx_rates), nl80211_txattr_policy);
5545 		if (tb[NL80211_TXRATE_LEGACY]) {
5546 			mask.control[band].legacy = rateset_to_mask(
5547 				sband,
5548 				nla_data(tb[NL80211_TXRATE_LEGACY]),
5549 				nla_len(tb[NL80211_TXRATE_LEGACY]));
5550 		}
5551 		if (tb[NL80211_TXRATE_MCS]) {
5552 			if (!ht_rateset_to_mask(
5553 					sband,
5554 					nla_data(tb[NL80211_TXRATE_MCS]),
5555 					nla_len(tb[NL80211_TXRATE_MCS]),
5556 					mask.control[band].mcs))
5557 				return -EINVAL;
5558 		}
5559 
5560 		if (mask.control[band].legacy == 0) {
5561 			/* don't allow empty legacy rates if HT
5562 			 * is not even supported. */
5563 			if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
5564 				return -EINVAL;
5565 
5566 			for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
5567 				if (mask.control[band].mcs[i])
5568 					break;
5569 
5570 			/* legacy and mcs rates may not be both empty */
5571 			if (i == IEEE80211_HT_MCS_MASK_LEN)
5572 				return -EINVAL;
5573 		}
5574 	}
5575 
5576 	return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
5577 }
5578 
nl80211_register_mgmt(struct sk_buff * skb,struct genl_info * info)5579 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
5580 {
5581 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5582 	struct net_device *dev = info->user_ptr[1];
5583 	u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
5584 
5585 	if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5586 		return -EINVAL;
5587 
5588 	if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5589 		frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
5590 
5591 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5592 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5593 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5594 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5595 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5596 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
5597 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5598 		return -EOPNOTSUPP;
5599 
5600 	/* not much point in registering if we can't reply */
5601 	if (!rdev->ops->mgmt_tx)
5602 		return -EOPNOTSUPP;
5603 
5604 	return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
5605 			frame_type,
5606 			nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5607 			nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
5608 }
5609 
nl80211_tx_mgmt(struct sk_buff * skb,struct genl_info * info)5610 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
5611 {
5612 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5613 	struct net_device *dev = info->user_ptr[1];
5614 	struct ieee80211_channel *chan;
5615 	enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5616 	bool channel_type_valid = false;
5617 	u32 freq;
5618 	int err;
5619 	void *hdr = NULL;
5620 	u64 cookie;
5621 	struct sk_buff *msg = NULL;
5622 	unsigned int wait = 0;
5623 	bool offchan, no_cck, dont_wait_for_ack;
5624 
5625 	dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
5626 
5627 	if (!info->attrs[NL80211_ATTR_FRAME] ||
5628 	    !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5629 		return -EINVAL;
5630 
5631 	if (!rdev->ops->mgmt_tx)
5632 		return -EOPNOTSUPP;
5633 
5634 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5635 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5636 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5637 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5638 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5639 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
5640 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5641 		return -EOPNOTSUPP;
5642 
5643 	if (info->attrs[NL80211_ATTR_DURATION]) {
5644 		if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
5645 			return -EINVAL;
5646 		wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5647 	}
5648 
5649 	if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5650 		channel_type = nla_get_u32(
5651 			info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5652 		if (channel_type != NL80211_CHAN_NO_HT &&
5653 		    channel_type != NL80211_CHAN_HT20 &&
5654 		    channel_type != NL80211_CHAN_HT40PLUS &&
5655 		    channel_type != NL80211_CHAN_HT40MINUS)
5656 			return -EINVAL;
5657 		channel_type_valid = true;
5658 	}
5659 
5660 	offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5661 
5662 	if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
5663 		return -EINVAL;
5664 
5665 	no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5666 
5667 	freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5668 	chan = rdev_freq_to_chan(rdev, freq, channel_type);
5669 	if (chan == NULL)
5670 		return -EINVAL;
5671 
5672 	if (!dont_wait_for_ack) {
5673 		msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5674 		if (!msg)
5675 			return -ENOMEM;
5676 
5677 		hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5678 				     NL80211_CMD_FRAME);
5679 
5680 		if (IS_ERR(hdr)) {
5681 			err = PTR_ERR(hdr);
5682 			goto free_msg;
5683 		}
5684 	}
5685 
5686 	err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5687 				    channel_type_valid, wait,
5688 				    nla_data(info->attrs[NL80211_ATTR_FRAME]),
5689 				    nla_len(info->attrs[NL80211_ATTR_FRAME]),
5690 				    no_cck, dont_wait_for_ack, &cookie);
5691 	if (err)
5692 		goto free_msg;
5693 
5694 	if (msg) {
5695 		NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5696 
5697 		genlmsg_end(msg, hdr);
5698 		return genlmsg_reply(msg, info);
5699 	}
5700 
5701 	return 0;
5702 
5703  nla_put_failure:
5704 	err = -ENOBUFS;
5705  free_msg:
5706 	nlmsg_free(msg);
5707 	return err;
5708 }
5709 
nl80211_tx_mgmt_cancel_wait(struct sk_buff * skb,struct genl_info * info)5710 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5711 {
5712 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5713 	struct net_device *dev = info->user_ptr[1];
5714 	u64 cookie;
5715 
5716 	if (!info->attrs[NL80211_ATTR_COOKIE])
5717 		return -EINVAL;
5718 
5719 	if (!rdev->ops->mgmt_tx_cancel_wait)
5720 		return -EOPNOTSUPP;
5721 
5722 	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5723 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5724 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5725 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5726 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5727 	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5728 		return -EOPNOTSUPP;
5729 
5730 	cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5731 
5732 	return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5733 }
5734 
nl80211_set_power_save(struct sk_buff * skb,struct genl_info * info)5735 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5736 {
5737 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5738 	struct wireless_dev *wdev;
5739 	struct net_device *dev = info->user_ptr[1];
5740 	u8 ps_state;
5741 	bool state;
5742 	int err;
5743 
5744 	if (!info->attrs[NL80211_ATTR_PS_STATE])
5745 		return -EINVAL;
5746 
5747 	ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5748 
5749 	if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5750 		return -EINVAL;
5751 
5752 	wdev = dev->ieee80211_ptr;
5753 
5754 	if (!rdev->ops->set_power_mgmt)
5755 		return -EOPNOTSUPP;
5756 
5757 	state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5758 
5759 	if (state == wdev->ps)
5760 		return 0;
5761 
5762 	err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5763 					wdev->ps_timeout);
5764 	if (!err)
5765 		wdev->ps = state;
5766 	return err;
5767 }
5768 
nl80211_get_power_save(struct sk_buff * skb,struct genl_info * info)5769 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5770 {
5771 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5772 	enum nl80211_ps_state ps_state;
5773 	struct wireless_dev *wdev;
5774 	struct net_device *dev = info->user_ptr[1];
5775 	struct sk_buff *msg;
5776 	void *hdr;
5777 	int err;
5778 
5779 	wdev = dev->ieee80211_ptr;
5780 
5781 	if (!rdev->ops->set_power_mgmt)
5782 		return -EOPNOTSUPP;
5783 
5784 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5785 	if (!msg)
5786 		return -ENOMEM;
5787 
5788 	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5789 			     NL80211_CMD_GET_POWER_SAVE);
5790 	if (!hdr) {
5791 		err = -ENOBUFS;
5792 		goto free_msg;
5793 	}
5794 
5795 	if (wdev->ps)
5796 		ps_state = NL80211_PS_ENABLED;
5797 	else
5798 		ps_state = NL80211_PS_DISABLED;
5799 
5800 	NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5801 
5802 	genlmsg_end(msg, hdr);
5803 	return genlmsg_reply(msg, info);
5804 
5805  nla_put_failure:
5806 	err = -ENOBUFS;
5807  free_msg:
5808 	nlmsg_free(msg);
5809 	return err;
5810 }
5811 
5812 static struct nla_policy
5813 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5814 	[NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5815 	[NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5816 	[NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5817 };
5818 
nl80211_set_cqm_rssi(struct genl_info * info,s32 threshold,u32 hysteresis)5819 static int nl80211_set_cqm_rssi(struct genl_info *info,
5820 				s32 threshold, u32 hysteresis)
5821 {
5822 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5823 	struct wireless_dev *wdev;
5824 	struct net_device *dev = info->user_ptr[1];
5825 
5826 	if (threshold > 0)
5827 		return -EINVAL;
5828 
5829 	wdev = dev->ieee80211_ptr;
5830 
5831 	if (!rdev->ops->set_cqm_rssi_config)
5832 		return -EOPNOTSUPP;
5833 
5834 	if (wdev->iftype != NL80211_IFTYPE_STATION &&
5835 	    wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
5836 		return -EOPNOTSUPP;
5837 
5838 	return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5839 					      threshold, hysteresis);
5840 }
5841 
nl80211_set_cqm(struct sk_buff * skb,struct genl_info * info)5842 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5843 {
5844 	struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5845 	struct nlattr *cqm;
5846 	int err;
5847 
5848 	cqm = info->attrs[NL80211_ATTR_CQM];
5849 	if (!cqm) {
5850 		err = -EINVAL;
5851 		goto out;
5852 	}
5853 
5854 	err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5855 			       nl80211_attr_cqm_policy);
5856 	if (err)
5857 		goto out;
5858 
5859 	if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5860 	    attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5861 		s32 threshold;
5862 		u32 hysteresis;
5863 		threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5864 		hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5865 		err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5866 	} else
5867 		err = -EINVAL;
5868 
5869 out:
5870 	return err;
5871 }
5872 
nl80211_join_mesh(struct sk_buff * skb,struct genl_info * info)5873 static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
5874 {
5875 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5876 	struct net_device *dev = info->user_ptr[1];
5877 	struct mesh_config cfg;
5878 	struct mesh_setup setup;
5879 	int err;
5880 
5881 	/* start with default */
5882 	memcpy(&cfg, &default_mesh_config, sizeof(cfg));
5883 	memcpy(&setup, &default_mesh_setup, sizeof(setup));
5884 
5885 	if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
5886 		/* and parse parameters if given */
5887 		err = nl80211_parse_mesh_config(info, &cfg, NULL);
5888 		if (err)
5889 			return err;
5890 	}
5891 
5892 	if (!info->attrs[NL80211_ATTR_MESH_ID] ||
5893 	    !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
5894 		return -EINVAL;
5895 
5896 	setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
5897 	setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
5898 
5899 	if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5900 	    !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
5901 			    nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5902 			return -EINVAL;
5903 
5904 	if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
5905 		/* parse additional setup parameters if given */
5906 		err = nl80211_parse_mesh_setup(info, &setup);
5907 		if (err)
5908 			return err;
5909 	}
5910 
5911 	return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
5912 }
5913 
nl80211_leave_mesh(struct sk_buff * skb,struct genl_info * info)5914 static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
5915 {
5916 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5917 	struct net_device *dev = info->user_ptr[1];
5918 
5919 	return cfg80211_leave_mesh(rdev, dev);
5920 }
5921 
nl80211_get_wowlan(struct sk_buff * skb,struct genl_info * info)5922 static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
5923 {
5924 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
5925 	struct sk_buff *msg;
5926 	void *hdr;
5927 
5928 	if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5929 		return -EOPNOTSUPP;
5930 
5931 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5932 	if (!msg)
5933 		return -ENOMEM;
5934 
5935 	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5936 			     NL80211_CMD_GET_WOWLAN);
5937 	if (!hdr)
5938 		goto nla_put_failure;
5939 
5940 	if (rdev->wowlan) {
5941 		struct nlattr *nl_wowlan;
5942 
5943 		nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
5944 		if (!nl_wowlan)
5945 			goto nla_put_failure;
5946 
5947 		if (rdev->wowlan->any)
5948 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
5949 		if (rdev->wowlan->disconnect)
5950 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
5951 		if (rdev->wowlan->magic_pkt)
5952 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
5953 		if (rdev->wowlan->gtk_rekey_failure)
5954 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
5955 		if (rdev->wowlan->eap_identity_req)
5956 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
5957 		if (rdev->wowlan->four_way_handshake)
5958 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
5959 		if (rdev->wowlan->rfkill_release)
5960 			NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
5961 		if (rdev->wowlan->n_patterns) {
5962 			struct nlattr *nl_pats, *nl_pat;
5963 			int i, pat_len;
5964 
5965 			nl_pats = nla_nest_start(msg,
5966 					NL80211_WOWLAN_TRIG_PKT_PATTERN);
5967 			if (!nl_pats)
5968 				goto nla_put_failure;
5969 
5970 			for (i = 0; i < rdev->wowlan->n_patterns; i++) {
5971 				nl_pat = nla_nest_start(msg, i + 1);
5972 				if (!nl_pat)
5973 					goto nla_put_failure;
5974 				pat_len = rdev->wowlan->patterns[i].pattern_len;
5975 				NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
5976 					DIV_ROUND_UP(pat_len, 8),
5977 					rdev->wowlan->patterns[i].mask);
5978 				NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
5979 					pat_len,
5980 					rdev->wowlan->patterns[i].pattern);
5981 				nla_nest_end(msg, nl_pat);
5982 			}
5983 			nla_nest_end(msg, nl_pats);
5984 		}
5985 
5986 		nla_nest_end(msg, nl_wowlan);
5987 	}
5988 
5989 	genlmsg_end(msg, hdr);
5990 	return genlmsg_reply(msg, info);
5991 
5992 nla_put_failure:
5993 	nlmsg_free(msg);
5994 	return -ENOBUFS;
5995 }
5996 
nl80211_set_wowlan(struct sk_buff * skb,struct genl_info * info)5997 static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
5998 {
5999 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
6000 	struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
6001 	struct cfg80211_wowlan no_triggers = {};
6002 	struct cfg80211_wowlan new_triggers = {};
6003 	struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6004 	int err, i;
6005 
6006 	if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6007 		return -EOPNOTSUPP;
6008 
6009 	if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
6010 		goto no_triggers;
6011 
6012 	err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6013 			nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6014 			nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6015 			nl80211_wowlan_policy);
6016 	if (err)
6017 		return err;
6018 
6019 	if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6020 		if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6021 			return -EINVAL;
6022 		new_triggers.any = true;
6023 	}
6024 
6025 	if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6026 		if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6027 			return -EINVAL;
6028 		new_triggers.disconnect = true;
6029 	}
6030 
6031 	if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6032 		if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6033 			return -EINVAL;
6034 		new_triggers.magic_pkt = true;
6035 	}
6036 
6037 	if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6038 		return -EINVAL;
6039 
6040 	if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6041 		if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6042 			return -EINVAL;
6043 		new_triggers.gtk_rekey_failure = true;
6044 	}
6045 
6046 	if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6047 		if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6048 			return -EINVAL;
6049 		new_triggers.eap_identity_req = true;
6050 	}
6051 
6052 	if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6053 		if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6054 			return -EINVAL;
6055 		new_triggers.four_way_handshake = true;
6056 	}
6057 
6058 	if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6059 		if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6060 			return -EINVAL;
6061 		new_triggers.rfkill_release = true;
6062 	}
6063 
6064 	if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6065 		struct nlattr *pat;
6066 		int n_patterns = 0;
6067 		int rem, pat_len, mask_len;
6068 		struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6069 
6070 		nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6071 				    rem)
6072 			n_patterns++;
6073 		if (n_patterns > wowlan->n_patterns)
6074 			return -EINVAL;
6075 
6076 		new_triggers.patterns = kcalloc(n_patterns,
6077 						sizeof(new_triggers.patterns[0]),
6078 						GFP_KERNEL);
6079 		if (!new_triggers.patterns)
6080 			return -ENOMEM;
6081 
6082 		new_triggers.n_patterns = n_patterns;
6083 		i = 0;
6084 
6085 		nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6086 				    rem) {
6087 			nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6088 				  nla_data(pat), nla_len(pat), NULL);
6089 			err = -EINVAL;
6090 			if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6091 			    !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6092 				goto error;
6093 			pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6094 			mask_len = DIV_ROUND_UP(pat_len, 8);
6095 			if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6096 			    mask_len)
6097 				goto error;
6098 			if (pat_len > wowlan->pattern_max_len ||
6099 			    pat_len < wowlan->pattern_min_len)
6100 				goto error;
6101 
6102 			new_triggers.patterns[i].mask =
6103 				kmalloc(mask_len + pat_len, GFP_KERNEL);
6104 			if (!new_triggers.patterns[i].mask) {
6105 				err = -ENOMEM;
6106 				goto error;
6107 			}
6108 			new_triggers.patterns[i].pattern =
6109 				new_triggers.patterns[i].mask + mask_len;
6110 			memcpy(new_triggers.patterns[i].mask,
6111 			       nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6112 			       mask_len);
6113 			new_triggers.patterns[i].pattern_len = pat_len;
6114 			memcpy(new_triggers.patterns[i].pattern,
6115 			       nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6116 			       pat_len);
6117 			i++;
6118 		}
6119 	}
6120 
6121 	if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
6122 		struct cfg80211_wowlan *ntrig;
6123 		ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
6124 				GFP_KERNEL);
6125 		if (!ntrig) {
6126 			err = -ENOMEM;
6127 			goto error;
6128 		}
6129 		cfg80211_rdev_free_wowlan(rdev);
6130 		rdev->wowlan = ntrig;
6131 	} else {
6132  no_triggers:
6133 		cfg80211_rdev_free_wowlan(rdev);
6134 		rdev->wowlan = NULL;
6135 	}
6136 
6137 	return 0;
6138  error:
6139 	for (i = 0; i < new_triggers.n_patterns; i++)
6140 		kfree(new_triggers.patterns[i].mask);
6141 	kfree(new_triggers.patterns);
6142 	return err;
6143 }
6144 
nl80211_set_rekey_data(struct sk_buff * skb,struct genl_info * info)6145 static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
6146 {
6147 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
6148 	struct net_device *dev = info->user_ptr[1];
6149 	struct wireless_dev *wdev = dev->ieee80211_ptr;
6150 	struct nlattr *tb[NUM_NL80211_REKEY_DATA];
6151 	struct cfg80211_gtk_rekey_data rekey_data;
6152 	int err;
6153 
6154 	if (!info->attrs[NL80211_ATTR_REKEY_DATA])
6155 		return -EINVAL;
6156 
6157 	err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
6158 			nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
6159 			nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
6160 			nl80211_rekey_policy);
6161 	if (err)
6162 		return err;
6163 
6164 	if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
6165 		return -ERANGE;
6166 	if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
6167 		return -ERANGE;
6168 	if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
6169 		return -ERANGE;
6170 
6171 	memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
6172 	       NL80211_KEK_LEN);
6173 	memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
6174 	       NL80211_KCK_LEN);
6175 	memcpy(rekey_data.replay_ctr,
6176 	       nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
6177 	       NL80211_REPLAY_CTR_LEN);
6178 
6179 	wdev_lock(wdev);
6180 	if (!wdev->current_bss) {
6181 		err = -ENOTCONN;
6182 		goto out;
6183 	}
6184 
6185 	if (!rdev->ops->set_rekey_data) {
6186 		err = -EOPNOTSUPP;
6187 		goto out;
6188 	}
6189 
6190 	err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
6191  out:
6192 	wdev_unlock(wdev);
6193 	return err;
6194 }
6195 
nl80211_register_unexpected_frame(struct sk_buff * skb,struct genl_info * info)6196 static int nl80211_register_unexpected_frame(struct sk_buff *skb,
6197 					     struct genl_info *info)
6198 {
6199 	struct net_device *dev = info->user_ptr[1];
6200 	struct wireless_dev *wdev = dev->ieee80211_ptr;
6201 
6202 	if (wdev->iftype != NL80211_IFTYPE_AP &&
6203 	    wdev->iftype != NL80211_IFTYPE_P2P_GO)
6204 		return -EINVAL;
6205 
6206 	if (wdev->ap_unexpected_nlpid)
6207 		return -EBUSY;
6208 
6209 	wdev->ap_unexpected_nlpid = info->snd_pid;
6210 	return 0;
6211 }
6212 
nl80211_probe_client(struct sk_buff * skb,struct genl_info * info)6213 static int nl80211_probe_client(struct sk_buff *skb,
6214 				struct genl_info *info)
6215 {
6216 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
6217 	struct net_device *dev = info->user_ptr[1];
6218 	struct wireless_dev *wdev = dev->ieee80211_ptr;
6219 	struct sk_buff *msg;
6220 	void *hdr;
6221 	const u8 *addr;
6222 	u64 cookie;
6223 	int err;
6224 
6225 	if (wdev->iftype != NL80211_IFTYPE_AP &&
6226 	    wdev->iftype != NL80211_IFTYPE_P2P_GO)
6227 		return -EOPNOTSUPP;
6228 
6229 	if (!info->attrs[NL80211_ATTR_MAC])
6230 		return -EINVAL;
6231 
6232 	if (!rdev->ops->probe_client)
6233 		return -EOPNOTSUPP;
6234 
6235 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6236 	if (!msg)
6237 		return -ENOMEM;
6238 
6239 	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6240 			     NL80211_CMD_PROBE_CLIENT);
6241 
6242 	if (IS_ERR(hdr)) {
6243 		err = PTR_ERR(hdr);
6244 		goto free_msg;
6245 	}
6246 
6247 	addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6248 
6249 	err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
6250 	if (err)
6251 		goto free_msg;
6252 
6253 	NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6254 
6255 	genlmsg_end(msg, hdr);
6256 
6257 	return genlmsg_reply(msg, info);
6258 
6259  nla_put_failure:
6260 	err = -ENOBUFS;
6261  free_msg:
6262 	nlmsg_free(msg);
6263 	return err;
6264 }
6265 
nl80211_register_beacons(struct sk_buff * skb,struct genl_info * info)6266 static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
6267 {
6268 	struct cfg80211_registered_device *rdev = info->user_ptr[0];
6269 
6270 	if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
6271 		return -EOPNOTSUPP;
6272 
6273 	if (rdev->ap_beacons_nlpid)
6274 		return -EBUSY;
6275 
6276 	rdev->ap_beacons_nlpid = info->snd_pid;
6277 
6278 	return 0;
6279 }
6280 
6281 #define NL80211_FLAG_NEED_WIPHY		0x01
6282 #define NL80211_FLAG_NEED_NETDEV	0x02
6283 #define NL80211_FLAG_NEED_RTNL		0x04
6284 #define NL80211_FLAG_CHECK_NETDEV_UP	0x08
6285 #define NL80211_FLAG_NEED_NETDEV_UP	(NL80211_FLAG_NEED_NETDEV |\
6286 					 NL80211_FLAG_CHECK_NETDEV_UP)
6287 
nl80211_pre_doit(struct genl_ops * ops,struct sk_buff * skb,struct genl_info * info)6288 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
6289 			    struct genl_info *info)
6290 {
6291 	struct cfg80211_registered_device *rdev;
6292 	struct net_device *dev;
6293 	int err;
6294 	bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
6295 
6296 	if (rtnl)
6297 		rtnl_lock();
6298 
6299 	if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
6300 		rdev = cfg80211_get_dev_from_info(info);
6301 		if (IS_ERR(rdev)) {
6302 			if (rtnl)
6303 				rtnl_unlock();
6304 			return PTR_ERR(rdev);
6305 		}
6306 		info->user_ptr[0] = rdev;
6307 	} else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
6308 		err = get_rdev_dev_by_ifindex(genl_info_net(info), info->attrs,
6309 					      &rdev, &dev);
6310 		if (err) {
6311 			if (rtnl)
6312 				rtnl_unlock();
6313 			return err;
6314 		}
6315 		if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
6316 		    !netif_running(dev)) {
6317 			cfg80211_unlock_rdev(rdev);
6318 			dev_put(dev);
6319 			if (rtnl)
6320 				rtnl_unlock();
6321 			return -ENETDOWN;
6322 		}
6323 		info->user_ptr[0] = rdev;
6324 		info->user_ptr[1] = dev;
6325 	}
6326 
6327 	return 0;
6328 }
6329 
nl80211_post_doit(struct genl_ops * ops,struct sk_buff * skb,struct genl_info * info)6330 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
6331 			      struct genl_info *info)
6332 {
6333 	if (info->user_ptr[0])
6334 		cfg80211_unlock_rdev(info->user_ptr[0]);
6335 	if (info->user_ptr[1])
6336 		dev_put(info->user_ptr[1]);
6337 	if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
6338 		rtnl_unlock();
6339 }
6340 
6341 static struct genl_ops nl80211_ops[] = {
6342 	{
6343 		.cmd = NL80211_CMD_GET_WIPHY,
6344 		.doit = nl80211_get_wiphy,
6345 		.dumpit = nl80211_dump_wiphy,
6346 		.policy = nl80211_policy,
6347 		/* can be retrieved by unprivileged users */
6348 		.internal_flags = NL80211_FLAG_NEED_WIPHY,
6349 	},
6350 	{
6351 		.cmd = NL80211_CMD_SET_WIPHY,
6352 		.doit = nl80211_set_wiphy,
6353 		.policy = nl80211_policy,
6354 		.flags = GENL_ADMIN_PERM,
6355 		.internal_flags = NL80211_FLAG_NEED_RTNL,
6356 	},
6357 	{
6358 		.cmd = NL80211_CMD_GET_INTERFACE,
6359 		.doit = nl80211_get_interface,
6360 		.dumpit = nl80211_dump_interface,
6361 		.policy = nl80211_policy,
6362 		/* can be retrieved by unprivileged users */
6363 		.internal_flags = NL80211_FLAG_NEED_NETDEV,
6364 	},
6365 	{
6366 		.cmd = NL80211_CMD_SET_INTERFACE,
6367 		.doit = nl80211_set_interface,
6368 		.policy = nl80211_policy,
6369 		.flags = GENL_ADMIN_PERM,
6370 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6371 				  NL80211_FLAG_NEED_RTNL,
6372 	},
6373 	{
6374 		.cmd = NL80211_CMD_NEW_INTERFACE,
6375 		.doit = nl80211_new_interface,
6376 		.policy = nl80211_policy,
6377 		.flags = GENL_ADMIN_PERM,
6378 		.internal_flags = NL80211_FLAG_NEED_WIPHY |
6379 				  NL80211_FLAG_NEED_RTNL,
6380 	},
6381 	{
6382 		.cmd = NL80211_CMD_DEL_INTERFACE,
6383 		.doit = nl80211_del_interface,
6384 		.policy = nl80211_policy,
6385 		.flags = GENL_ADMIN_PERM,
6386 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6387 				  NL80211_FLAG_NEED_RTNL,
6388 	},
6389 	{
6390 		.cmd = NL80211_CMD_GET_KEY,
6391 		.doit = nl80211_get_key,
6392 		.policy = nl80211_policy,
6393 		.flags = GENL_ADMIN_PERM,
6394 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6395 				  NL80211_FLAG_NEED_RTNL,
6396 	},
6397 	{
6398 		.cmd = NL80211_CMD_SET_KEY,
6399 		.doit = nl80211_set_key,
6400 		.policy = nl80211_policy,
6401 		.flags = GENL_ADMIN_PERM,
6402 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6403 				  NL80211_FLAG_NEED_RTNL,
6404 	},
6405 	{
6406 		.cmd = NL80211_CMD_NEW_KEY,
6407 		.doit = nl80211_new_key,
6408 		.policy = nl80211_policy,
6409 		.flags = GENL_ADMIN_PERM,
6410 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6411 				  NL80211_FLAG_NEED_RTNL,
6412 	},
6413 	{
6414 		.cmd = NL80211_CMD_DEL_KEY,
6415 		.doit = nl80211_del_key,
6416 		.policy = nl80211_policy,
6417 		.flags = GENL_ADMIN_PERM,
6418 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6419 				  NL80211_FLAG_NEED_RTNL,
6420 	},
6421 	{
6422 		.cmd = NL80211_CMD_SET_BEACON,
6423 		.policy = nl80211_policy,
6424 		.flags = GENL_ADMIN_PERM,
6425 		.doit = nl80211_set_beacon,
6426 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6427 				  NL80211_FLAG_NEED_RTNL,
6428 	},
6429 	{
6430 		.cmd = NL80211_CMD_START_AP,
6431 		.policy = nl80211_policy,
6432 		.flags = GENL_ADMIN_PERM,
6433 		.doit = nl80211_start_ap,
6434 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6435 				  NL80211_FLAG_NEED_RTNL,
6436 	},
6437 	{
6438 		.cmd = NL80211_CMD_STOP_AP,
6439 		.policy = nl80211_policy,
6440 		.flags = GENL_ADMIN_PERM,
6441 		.doit = nl80211_stop_ap,
6442 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6443 				  NL80211_FLAG_NEED_RTNL,
6444 	},
6445 	{
6446 		.cmd = NL80211_CMD_GET_STATION,
6447 		.doit = nl80211_get_station,
6448 		.dumpit = nl80211_dump_station,
6449 		.policy = nl80211_policy,
6450 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6451 				  NL80211_FLAG_NEED_RTNL,
6452 	},
6453 	{
6454 		.cmd = NL80211_CMD_SET_STATION,
6455 		.doit = nl80211_set_station,
6456 		.policy = nl80211_policy,
6457 		.flags = GENL_ADMIN_PERM,
6458 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6459 				  NL80211_FLAG_NEED_RTNL,
6460 	},
6461 	{
6462 		.cmd = NL80211_CMD_NEW_STATION,
6463 		.doit = nl80211_new_station,
6464 		.policy = nl80211_policy,
6465 		.flags = GENL_ADMIN_PERM,
6466 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6467 				  NL80211_FLAG_NEED_RTNL,
6468 	},
6469 	{
6470 		.cmd = NL80211_CMD_DEL_STATION,
6471 		.doit = nl80211_del_station,
6472 		.policy = nl80211_policy,
6473 		.flags = GENL_ADMIN_PERM,
6474 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6475 				  NL80211_FLAG_NEED_RTNL,
6476 	},
6477 	{
6478 		.cmd = NL80211_CMD_GET_MPATH,
6479 		.doit = nl80211_get_mpath,
6480 		.dumpit = nl80211_dump_mpath,
6481 		.policy = nl80211_policy,
6482 		.flags = GENL_ADMIN_PERM,
6483 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6484 				  NL80211_FLAG_NEED_RTNL,
6485 	},
6486 	{
6487 		.cmd = NL80211_CMD_SET_MPATH,
6488 		.doit = nl80211_set_mpath,
6489 		.policy = nl80211_policy,
6490 		.flags = GENL_ADMIN_PERM,
6491 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6492 				  NL80211_FLAG_NEED_RTNL,
6493 	},
6494 	{
6495 		.cmd = NL80211_CMD_NEW_MPATH,
6496 		.doit = nl80211_new_mpath,
6497 		.policy = nl80211_policy,
6498 		.flags = GENL_ADMIN_PERM,
6499 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6500 				  NL80211_FLAG_NEED_RTNL,
6501 	},
6502 	{
6503 		.cmd = NL80211_CMD_DEL_MPATH,
6504 		.doit = nl80211_del_mpath,
6505 		.policy = nl80211_policy,
6506 		.flags = GENL_ADMIN_PERM,
6507 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6508 				  NL80211_FLAG_NEED_RTNL,
6509 	},
6510 	{
6511 		.cmd = NL80211_CMD_SET_BSS,
6512 		.doit = nl80211_set_bss,
6513 		.policy = nl80211_policy,
6514 		.flags = GENL_ADMIN_PERM,
6515 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6516 				  NL80211_FLAG_NEED_RTNL,
6517 	},
6518 	{
6519 		.cmd = NL80211_CMD_GET_REG,
6520 		.doit = nl80211_get_reg,
6521 		.policy = nl80211_policy,
6522 		/* can be retrieved by unprivileged users */
6523 	},
6524 	{
6525 		.cmd = NL80211_CMD_SET_REG,
6526 		.doit = nl80211_set_reg,
6527 		.policy = nl80211_policy,
6528 		.flags = GENL_ADMIN_PERM,
6529 	},
6530 	{
6531 		.cmd = NL80211_CMD_REQ_SET_REG,
6532 		.doit = nl80211_req_set_reg,
6533 		.policy = nl80211_policy,
6534 		.flags = GENL_ADMIN_PERM,
6535 	},
6536 	{
6537 		.cmd = NL80211_CMD_GET_MESH_CONFIG,
6538 		.doit = nl80211_get_mesh_config,
6539 		.policy = nl80211_policy,
6540 		/* can be retrieved by unprivileged users */
6541 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6542 				  NL80211_FLAG_NEED_RTNL,
6543 	},
6544 	{
6545 		.cmd = NL80211_CMD_SET_MESH_CONFIG,
6546 		.doit = nl80211_update_mesh_config,
6547 		.policy = nl80211_policy,
6548 		.flags = GENL_ADMIN_PERM,
6549 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6550 				  NL80211_FLAG_NEED_RTNL,
6551 	},
6552 	{
6553 		.cmd = NL80211_CMD_TRIGGER_SCAN,
6554 		.doit = nl80211_trigger_scan,
6555 		.policy = nl80211_policy,
6556 		.flags = GENL_ADMIN_PERM,
6557 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6558 				  NL80211_FLAG_NEED_RTNL,
6559 	},
6560 	{
6561 		.cmd = NL80211_CMD_GET_SCAN,
6562 		.policy = nl80211_policy,
6563 		.dumpit = nl80211_dump_scan,
6564 	},
6565 	{
6566 		.cmd = NL80211_CMD_START_SCHED_SCAN,
6567 		.doit = nl80211_start_sched_scan,
6568 		.policy = nl80211_policy,
6569 		.flags = GENL_ADMIN_PERM,
6570 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6571 				  NL80211_FLAG_NEED_RTNL,
6572 	},
6573 	{
6574 		.cmd = NL80211_CMD_STOP_SCHED_SCAN,
6575 		.doit = nl80211_stop_sched_scan,
6576 		.policy = nl80211_policy,
6577 		.flags = GENL_ADMIN_PERM,
6578 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6579 				  NL80211_FLAG_NEED_RTNL,
6580 	},
6581 	{
6582 		.cmd = NL80211_CMD_AUTHENTICATE,
6583 		.doit = nl80211_authenticate,
6584 		.policy = nl80211_policy,
6585 		.flags = GENL_ADMIN_PERM,
6586 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6587 				  NL80211_FLAG_NEED_RTNL,
6588 	},
6589 	{
6590 		.cmd = NL80211_CMD_ASSOCIATE,
6591 		.doit = nl80211_associate,
6592 		.policy = nl80211_policy,
6593 		.flags = GENL_ADMIN_PERM,
6594 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6595 				  NL80211_FLAG_NEED_RTNL,
6596 	},
6597 	{
6598 		.cmd = NL80211_CMD_DEAUTHENTICATE,
6599 		.doit = nl80211_deauthenticate,
6600 		.policy = nl80211_policy,
6601 		.flags = GENL_ADMIN_PERM,
6602 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6603 				  NL80211_FLAG_NEED_RTNL,
6604 	},
6605 	{
6606 		.cmd = NL80211_CMD_DISASSOCIATE,
6607 		.doit = nl80211_disassociate,
6608 		.policy = nl80211_policy,
6609 		.flags = GENL_ADMIN_PERM,
6610 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6611 				  NL80211_FLAG_NEED_RTNL,
6612 	},
6613 	{
6614 		.cmd = NL80211_CMD_JOIN_IBSS,
6615 		.doit = nl80211_join_ibss,
6616 		.policy = nl80211_policy,
6617 		.flags = GENL_ADMIN_PERM,
6618 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6619 				  NL80211_FLAG_NEED_RTNL,
6620 	},
6621 	{
6622 		.cmd = NL80211_CMD_LEAVE_IBSS,
6623 		.doit = nl80211_leave_ibss,
6624 		.policy = nl80211_policy,
6625 		.flags = GENL_ADMIN_PERM,
6626 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6627 				  NL80211_FLAG_NEED_RTNL,
6628 	},
6629 #ifdef CONFIG_NL80211_TESTMODE
6630 	{
6631 		.cmd = NL80211_CMD_TESTMODE,
6632 		.doit = nl80211_testmode_do,
6633 		.dumpit = nl80211_testmode_dump,
6634 		.policy = nl80211_policy,
6635 		.flags = GENL_ADMIN_PERM,
6636 		.internal_flags = NL80211_FLAG_NEED_WIPHY |
6637 				  NL80211_FLAG_NEED_RTNL,
6638 	},
6639 #endif
6640 	{
6641 		.cmd = NL80211_CMD_CONNECT,
6642 		.doit = nl80211_connect,
6643 		.policy = nl80211_policy,
6644 		.flags = GENL_ADMIN_PERM,
6645 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6646 				  NL80211_FLAG_NEED_RTNL,
6647 	},
6648 	{
6649 		.cmd = NL80211_CMD_DISCONNECT,
6650 		.doit = nl80211_disconnect,
6651 		.policy = nl80211_policy,
6652 		.flags = GENL_ADMIN_PERM,
6653 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6654 				  NL80211_FLAG_NEED_RTNL,
6655 	},
6656 	{
6657 		.cmd = NL80211_CMD_SET_WIPHY_NETNS,
6658 		.doit = nl80211_wiphy_netns,
6659 		.policy = nl80211_policy,
6660 		.flags = GENL_ADMIN_PERM,
6661 		.internal_flags = NL80211_FLAG_NEED_WIPHY |
6662 				  NL80211_FLAG_NEED_RTNL,
6663 	},
6664 	{
6665 		.cmd = NL80211_CMD_GET_SURVEY,
6666 		.policy = nl80211_policy,
6667 		.dumpit = nl80211_dump_survey,
6668 	},
6669 	{
6670 		.cmd = NL80211_CMD_SET_PMKSA,
6671 		.doit = nl80211_setdel_pmksa,
6672 		.policy = nl80211_policy,
6673 		.flags = GENL_ADMIN_PERM,
6674 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6675 				  NL80211_FLAG_NEED_RTNL,
6676 	},
6677 	{
6678 		.cmd = NL80211_CMD_DEL_PMKSA,
6679 		.doit = nl80211_setdel_pmksa,
6680 		.policy = nl80211_policy,
6681 		.flags = GENL_ADMIN_PERM,
6682 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6683 				  NL80211_FLAG_NEED_RTNL,
6684 	},
6685 	{
6686 		.cmd = NL80211_CMD_FLUSH_PMKSA,
6687 		.doit = nl80211_flush_pmksa,
6688 		.policy = nl80211_policy,
6689 		.flags = GENL_ADMIN_PERM,
6690 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6691 				  NL80211_FLAG_NEED_RTNL,
6692 	},
6693 	{
6694 		.cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6695 		.doit = nl80211_remain_on_channel,
6696 		.policy = nl80211_policy,
6697 		.flags = GENL_ADMIN_PERM,
6698 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6699 				  NL80211_FLAG_NEED_RTNL,
6700 	},
6701 	{
6702 		.cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6703 		.doit = nl80211_cancel_remain_on_channel,
6704 		.policy = nl80211_policy,
6705 		.flags = GENL_ADMIN_PERM,
6706 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6707 				  NL80211_FLAG_NEED_RTNL,
6708 	},
6709 	{
6710 		.cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6711 		.doit = nl80211_set_tx_bitrate_mask,
6712 		.policy = nl80211_policy,
6713 		.flags = GENL_ADMIN_PERM,
6714 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6715 				  NL80211_FLAG_NEED_RTNL,
6716 	},
6717 	{
6718 		.cmd = NL80211_CMD_REGISTER_FRAME,
6719 		.doit = nl80211_register_mgmt,
6720 		.policy = nl80211_policy,
6721 		.flags = GENL_ADMIN_PERM,
6722 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6723 				  NL80211_FLAG_NEED_RTNL,
6724 	},
6725 	{
6726 		.cmd = NL80211_CMD_FRAME,
6727 		.doit = nl80211_tx_mgmt,
6728 		.policy = nl80211_policy,
6729 		.flags = GENL_ADMIN_PERM,
6730 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6731 				  NL80211_FLAG_NEED_RTNL,
6732 	},
6733 	{
6734 		.cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6735 		.doit = nl80211_tx_mgmt_cancel_wait,
6736 		.policy = nl80211_policy,
6737 		.flags = GENL_ADMIN_PERM,
6738 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6739 				  NL80211_FLAG_NEED_RTNL,
6740 	},
6741 	{
6742 		.cmd = NL80211_CMD_SET_POWER_SAVE,
6743 		.doit = nl80211_set_power_save,
6744 		.policy = nl80211_policy,
6745 		.flags = GENL_ADMIN_PERM,
6746 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6747 				  NL80211_FLAG_NEED_RTNL,
6748 	},
6749 	{
6750 		.cmd = NL80211_CMD_GET_POWER_SAVE,
6751 		.doit = nl80211_get_power_save,
6752 		.policy = nl80211_policy,
6753 		/* can be retrieved by unprivileged users */
6754 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6755 				  NL80211_FLAG_NEED_RTNL,
6756 	},
6757 	{
6758 		.cmd = NL80211_CMD_SET_CQM,
6759 		.doit = nl80211_set_cqm,
6760 		.policy = nl80211_policy,
6761 		.flags = GENL_ADMIN_PERM,
6762 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6763 				  NL80211_FLAG_NEED_RTNL,
6764 	},
6765 	{
6766 		.cmd = NL80211_CMD_SET_CHANNEL,
6767 		.doit = nl80211_set_channel,
6768 		.policy = nl80211_policy,
6769 		.flags = GENL_ADMIN_PERM,
6770 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6771 				  NL80211_FLAG_NEED_RTNL,
6772 	},
6773 	{
6774 		.cmd = NL80211_CMD_SET_WDS_PEER,
6775 		.doit = nl80211_set_wds_peer,
6776 		.policy = nl80211_policy,
6777 		.flags = GENL_ADMIN_PERM,
6778 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6779 				  NL80211_FLAG_NEED_RTNL,
6780 	},
6781 	{
6782 		.cmd = NL80211_CMD_JOIN_MESH,
6783 		.doit = nl80211_join_mesh,
6784 		.policy = nl80211_policy,
6785 		.flags = GENL_ADMIN_PERM,
6786 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6787 				  NL80211_FLAG_NEED_RTNL,
6788 	},
6789 	{
6790 		.cmd = NL80211_CMD_LEAVE_MESH,
6791 		.doit = nl80211_leave_mesh,
6792 		.policy = nl80211_policy,
6793 		.flags = GENL_ADMIN_PERM,
6794 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6795 				  NL80211_FLAG_NEED_RTNL,
6796 	},
6797 	{
6798 		.cmd = NL80211_CMD_GET_WOWLAN,
6799 		.doit = nl80211_get_wowlan,
6800 		.policy = nl80211_policy,
6801 		/* can be retrieved by unprivileged users */
6802 		.internal_flags = NL80211_FLAG_NEED_WIPHY |
6803 				  NL80211_FLAG_NEED_RTNL,
6804 	},
6805 	{
6806 		.cmd = NL80211_CMD_SET_WOWLAN,
6807 		.doit = nl80211_set_wowlan,
6808 		.policy = nl80211_policy,
6809 		.flags = GENL_ADMIN_PERM,
6810 		.internal_flags = NL80211_FLAG_NEED_WIPHY |
6811 				  NL80211_FLAG_NEED_RTNL,
6812 	},
6813 	{
6814 		.cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
6815 		.doit = nl80211_set_rekey_data,
6816 		.policy = nl80211_policy,
6817 		.flags = GENL_ADMIN_PERM,
6818 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6819 				  NL80211_FLAG_NEED_RTNL,
6820 	},
6821 	{
6822 		.cmd = NL80211_CMD_TDLS_MGMT,
6823 		.doit = nl80211_tdls_mgmt,
6824 		.policy = nl80211_policy,
6825 		.flags = GENL_ADMIN_PERM,
6826 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6827 				  NL80211_FLAG_NEED_RTNL,
6828 	},
6829 	{
6830 		.cmd = NL80211_CMD_TDLS_OPER,
6831 		.doit = nl80211_tdls_oper,
6832 		.policy = nl80211_policy,
6833 		.flags = GENL_ADMIN_PERM,
6834 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6835 				  NL80211_FLAG_NEED_RTNL,
6836 	},
6837 	{
6838 		.cmd = NL80211_CMD_UNEXPECTED_FRAME,
6839 		.doit = nl80211_register_unexpected_frame,
6840 		.policy = nl80211_policy,
6841 		.flags = GENL_ADMIN_PERM,
6842 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6843 				  NL80211_FLAG_NEED_RTNL,
6844 	},
6845 	{
6846 		.cmd = NL80211_CMD_PROBE_CLIENT,
6847 		.doit = nl80211_probe_client,
6848 		.policy = nl80211_policy,
6849 		.flags = GENL_ADMIN_PERM,
6850 		.internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6851 				  NL80211_FLAG_NEED_RTNL,
6852 	},
6853 	{
6854 		.cmd = NL80211_CMD_REGISTER_BEACONS,
6855 		.doit = nl80211_register_beacons,
6856 		.policy = nl80211_policy,
6857 		.flags = GENL_ADMIN_PERM,
6858 		.internal_flags = NL80211_FLAG_NEED_WIPHY |
6859 				  NL80211_FLAG_NEED_RTNL,
6860 	},
6861 	{
6862 		.cmd = NL80211_CMD_SET_NOACK_MAP,
6863 		.doit = nl80211_set_noack_map,
6864 		.policy = nl80211_policy,
6865 		.flags = GENL_ADMIN_PERM,
6866 		.internal_flags = NL80211_FLAG_NEED_NETDEV |
6867 				  NL80211_FLAG_NEED_RTNL,
6868 	},
6869 
6870 };
6871 
6872 static struct genl_multicast_group nl80211_mlme_mcgrp = {
6873 	.name = "mlme",
6874 };
6875 
6876 /* multicast groups */
6877 static struct genl_multicast_group nl80211_config_mcgrp = {
6878 	.name = "config",
6879 };
6880 static struct genl_multicast_group nl80211_scan_mcgrp = {
6881 	.name = "scan",
6882 };
6883 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
6884 	.name = "regulatory",
6885 };
6886 
6887 /* notification functions */
6888 
nl80211_notify_dev_rename(struct cfg80211_registered_device * rdev)6889 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
6890 {
6891 	struct sk_buff *msg;
6892 
6893 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6894 	if (!msg)
6895 		return;
6896 
6897 	if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
6898 		nlmsg_free(msg);
6899 		return;
6900 	}
6901 
6902 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6903 				nl80211_config_mcgrp.id, GFP_KERNEL);
6904 }
6905 
nl80211_add_scan_req(struct sk_buff * msg,struct cfg80211_registered_device * rdev)6906 static int nl80211_add_scan_req(struct sk_buff *msg,
6907 				struct cfg80211_registered_device *rdev)
6908 {
6909 	struct cfg80211_scan_request *req = rdev->scan_req;
6910 	struct nlattr *nest;
6911 	int i;
6912 
6913 	ASSERT_RDEV_LOCK(rdev);
6914 
6915 	if (WARN_ON(!req))
6916 		return 0;
6917 
6918 	nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
6919 	if (!nest)
6920 		goto nla_put_failure;
6921 	for (i = 0; i < req->n_ssids; i++)
6922 		NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
6923 	nla_nest_end(msg, nest);
6924 
6925 	nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
6926 	if (!nest)
6927 		goto nla_put_failure;
6928 	for (i = 0; i < req->n_channels; i++)
6929 		NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
6930 	nla_nest_end(msg, nest);
6931 
6932 	if (req->ie)
6933 		NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
6934 
6935 	return 0;
6936  nla_put_failure:
6937 	return -ENOBUFS;
6938 }
6939 
nl80211_send_scan_msg(struct sk_buff * msg,struct cfg80211_registered_device * rdev,struct net_device * netdev,u32 pid,u32 seq,int flags,u32 cmd)6940 static int nl80211_send_scan_msg(struct sk_buff *msg,
6941 				 struct cfg80211_registered_device *rdev,
6942 				 struct net_device *netdev,
6943 				 u32 pid, u32 seq, int flags,
6944 				 u32 cmd)
6945 {
6946 	void *hdr;
6947 
6948 	hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6949 	if (!hdr)
6950 		return -1;
6951 
6952 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6953 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6954 
6955 	/* ignore errors and send incomplete event anyway */
6956 	nl80211_add_scan_req(msg, rdev);
6957 
6958 	return genlmsg_end(msg, hdr);
6959 
6960  nla_put_failure:
6961 	genlmsg_cancel(msg, hdr);
6962 	return -EMSGSIZE;
6963 }
6964 
6965 static int
nl80211_send_sched_scan_msg(struct sk_buff * msg,struct cfg80211_registered_device * rdev,struct net_device * netdev,u32 pid,u32 seq,int flags,u32 cmd)6966 nl80211_send_sched_scan_msg(struct sk_buff *msg,
6967 			    struct cfg80211_registered_device *rdev,
6968 			    struct net_device *netdev,
6969 			    u32 pid, u32 seq, int flags, u32 cmd)
6970 {
6971 	void *hdr;
6972 
6973 	hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6974 	if (!hdr)
6975 		return -1;
6976 
6977 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6978 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6979 
6980 	return genlmsg_end(msg, hdr);
6981 
6982  nla_put_failure:
6983 	genlmsg_cancel(msg, hdr);
6984 	return -EMSGSIZE;
6985 }
6986 
nl80211_send_scan_start(struct cfg80211_registered_device * rdev,struct net_device * netdev)6987 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
6988 			     struct net_device *netdev)
6989 {
6990 	struct sk_buff *msg;
6991 
6992 	msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6993 	if (!msg)
6994 		return;
6995 
6996 	if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6997 				  NL80211_CMD_TRIGGER_SCAN) < 0) {
6998 		nlmsg_free(msg);
6999 		return;
7000 	}
7001 
7002 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7003 				nl80211_scan_mcgrp.id, GFP_KERNEL);
7004 }
7005 
nl80211_send_scan_done(struct cfg80211_registered_device * rdev,struct net_device * netdev)7006 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
7007 			    struct net_device *netdev)
7008 {
7009 	struct sk_buff *msg;
7010 
7011 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7012 	if (!msg)
7013 		return;
7014 
7015 	if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7016 				  NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
7017 		nlmsg_free(msg);
7018 		return;
7019 	}
7020 
7021 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7022 				nl80211_scan_mcgrp.id, GFP_KERNEL);
7023 }
7024 
nl80211_send_scan_aborted(struct cfg80211_registered_device * rdev,struct net_device * netdev)7025 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
7026 			       struct net_device *netdev)
7027 {
7028 	struct sk_buff *msg;
7029 
7030 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7031 	if (!msg)
7032 		return;
7033 
7034 	if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7035 				  NL80211_CMD_SCAN_ABORTED) < 0) {
7036 		nlmsg_free(msg);
7037 		return;
7038 	}
7039 
7040 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7041 				nl80211_scan_mcgrp.id, GFP_KERNEL);
7042 }
7043 
nl80211_send_sched_scan_results(struct cfg80211_registered_device * rdev,struct net_device * netdev)7044 void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
7045 				     struct net_device *netdev)
7046 {
7047 	struct sk_buff *msg;
7048 
7049 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7050 	if (!msg)
7051 		return;
7052 
7053 	if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
7054 					NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
7055 		nlmsg_free(msg);
7056 		return;
7057 	}
7058 
7059 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7060 				nl80211_scan_mcgrp.id, GFP_KERNEL);
7061 }
7062 
nl80211_send_sched_scan(struct cfg80211_registered_device * rdev,struct net_device * netdev,u32 cmd)7063 void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
7064 			     struct net_device *netdev, u32 cmd)
7065 {
7066 	struct sk_buff *msg;
7067 
7068 	msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7069 	if (!msg)
7070 		return;
7071 
7072 	if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
7073 		nlmsg_free(msg);
7074 		return;
7075 	}
7076 
7077 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7078 				nl80211_scan_mcgrp.id, GFP_KERNEL);
7079 }
7080 
7081 /*
7082  * This can happen on global regulatory changes or device specific settings
7083  * based on custom world regulatory domains.
7084  */
nl80211_send_reg_change_event(struct regulatory_request * request)7085 void nl80211_send_reg_change_event(struct regulatory_request *request)
7086 {
7087 	struct sk_buff *msg;
7088 	void *hdr;
7089 
7090 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7091 	if (!msg)
7092 		return;
7093 
7094 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
7095 	if (!hdr) {
7096 		nlmsg_free(msg);
7097 		return;
7098 	}
7099 
7100 	/* Userspace can always count this one always being set */
7101 	NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
7102 
7103 	if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
7104 		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7105 			   NL80211_REGDOM_TYPE_WORLD);
7106 	else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
7107 		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7108 			   NL80211_REGDOM_TYPE_CUSTOM_WORLD);
7109 	else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
7110 		 request->intersect)
7111 		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7112 			   NL80211_REGDOM_TYPE_INTERSECTION);
7113 	else {
7114 		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7115 			   NL80211_REGDOM_TYPE_COUNTRY);
7116 		NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
7117 	}
7118 
7119 	if (wiphy_idx_valid(request->wiphy_idx))
7120 		NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
7121 
7122 	genlmsg_end(msg, hdr);
7123 
7124 	rcu_read_lock();
7125 	genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7126 				GFP_ATOMIC);
7127 	rcu_read_unlock();
7128 
7129 	return;
7130 
7131 nla_put_failure:
7132 	genlmsg_cancel(msg, hdr);
7133 	nlmsg_free(msg);
7134 }
7135 
nl80211_send_mlme_event(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,enum nl80211_commands cmd,gfp_t gfp)7136 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
7137 				    struct net_device *netdev,
7138 				    const u8 *buf, size_t len,
7139 				    enum nl80211_commands cmd, gfp_t gfp)
7140 {
7141 	struct sk_buff *msg;
7142 	void *hdr;
7143 
7144 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7145 	if (!msg)
7146 		return;
7147 
7148 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7149 	if (!hdr) {
7150 		nlmsg_free(msg);
7151 		return;
7152 	}
7153 
7154 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7155 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7156 	NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7157 
7158 	genlmsg_end(msg, hdr);
7159 
7160 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7161 				nl80211_mlme_mcgrp.id, gfp);
7162 	return;
7163 
7164  nla_put_failure:
7165 	genlmsg_cancel(msg, hdr);
7166 	nlmsg_free(msg);
7167 }
7168 
nl80211_send_rx_auth(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,gfp_t gfp)7169 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
7170 			  struct net_device *netdev, const u8 *buf,
7171 			  size_t len, gfp_t gfp)
7172 {
7173 	nl80211_send_mlme_event(rdev, netdev, buf, len,
7174 				NL80211_CMD_AUTHENTICATE, gfp);
7175 }
7176 
nl80211_send_rx_assoc(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,gfp_t gfp)7177 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
7178 			   struct net_device *netdev, const u8 *buf,
7179 			   size_t len, gfp_t gfp)
7180 {
7181 	nl80211_send_mlme_event(rdev, netdev, buf, len,
7182 				NL80211_CMD_ASSOCIATE, gfp);
7183 }
7184 
nl80211_send_deauth(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,gfp_t gfp)7185 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
7186 			 struct net_device *netdev, const u8 *buf,
7187 			 size_t len, gfp_t gfp)
7188 {
7189 	nl80211_send_mlme_event(rdev, netdev, buf, len,
7190 				NL80211_CMD_DEAUTHENTICATE, gfp);
7191 }
7192 
nl80211_send_disassoc(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,gfp_t gfp)7193 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
7194 			   struct net_device *netdev, const u8 *buf,
7195 			   size_t len, gfp_t gfp)
7196 {
7197 	nl80211_send_mlme_event(rdev, netdev, buf, len,
7198 				NL80211_CMD_DISASSOCIATE, gfp);
7199 }
7200 
nl80211_send_unprot_deauth(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,gfp_t gfp)7201 void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
7202 				struct net_device *netdev, const u8 *buf,
7203 				size_t len, gfp_t gfp)
7204 {
7205 	nl80211_send_mlme_event(rdev, netdev, buf, len,
7206 				NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
7207 }
7208 
nl80211_send_unprot_disassoc(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * buf,size_t len,gfp_t gfp)7209 void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
7210 				  struct net_device *netdev, const u8 *buf,
7211 				  size_t len, gfp_t gfp)
7212 {
7213 	nl80211_send_mlme_event(rdev, netdev, buf, len,
7214 				NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
7215 }
7216 
nl80211_send_mlme_timeout(struct cfg80211_registered_device * rdev,struct net_device * netdev,int cmd,const u8 * addr,gfp_t gfp)7217 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
7218 				      struct net_device *netdev, int cmd,
7219 				      const u8 *addr, gfp_t gfp)
7220 {
7221 	struct sk_buff *msg;
7222 	void *hdr;
7223 
7224 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7225 	if (!msg)
7226 		return;
7227 
7228 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7229 	if (!hdr) {
7230 		nlmsg_free(msg);
7231 		return;
7232 	}
7233 
7234 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7235 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7236 	NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
7237 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7238 
7239 	genlmsg_end(msg, hdr);
7240 
7241 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7242 				nl80211_mlme_mcgrp.id, gfp);
7243 	return;
7244 
7245  nla_put_failure:
7246 	genlmsg_cancel(msg, hdr);
7247 	nlmsg_free(msg);
7248 }
7249 
nl80211_send_auth_timeout(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * addr,gfp_t gfp)7250 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
7251 			       struct net_device *netdev, const u8 *addr,
7252 			       gfp_t gfp)
7253 {
7254 	nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
7255 				  addr, gfp);
7256 }
7257 
nl80211_send_assoc_timeout(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * addr,gfp_t gfp)7258 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
7259 				struct net_device *netdev, const u8 *addr,
7260 				gfp_t gfp)
7261 {
7262 	nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
7263 				  addr, gfp);
7264 }
7265 
nl80211_send_connect_result(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * bssid,const u8 * req_ie,size_t req_ie_len,const u8 * resp_ie,size_t resp_ie_len,u16 status,gfp_t gfp)7266 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
7267 				 struct net_device *netdev, const u8 *bssid,
7268 				 const u8 *req_ie, size_t req_ie_len,
7269 				 const u8 *resp_ie, size_t resp_ie_len,
7270 				 u16 status, gfp_t gfp)
7271 {
7272 	struct sk_buff *msg;
7273 	void *hdr;
7274 
7275 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7276 	if (!msg)
7277 		return;
7278 
7279 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
7280 	if (!hdr) {
7281 		nlmsg_free(msg);
7282 		return;
7283 	}
7284 
7285 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7286 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7287 	if (bssid)
7288 		NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7289 	NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
7290 	if (req_ie)
7291 		NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
7292 	if (resp_ie)
7293 		NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
7294 
7295 	genlmsg_end(msg, hdr);
7296 
7297 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7298 				nl80211_mlme_mcgrp.id, gfp);
7299 	return;
7300 
7301  nla_put_failure:
7302 	genlmsg_cancel(msg, hdr);
7303 	nlmsg_free(msg);
7304 
7305 }
7306 
nl80211_send_roamed(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * bssid,const u8 * req_ie,size_t req_ie_len,const u8 * resp_ie,size_t resp_ie_len,gfp_t gfp)7307 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
7308 			 struct net_device *netdev, const u8 *bssid,
7309 			 const u8 *req_ie, size_t req_ie_len,
7310 			 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
7311 {
7312 	struct sk_buff *msg;
7313 	void *hdr;
7314 
7315 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7316 	if (!msg)
7317 		return;
7318 
7319 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
7320 	if (!hdr) {
7321 		nlmsg_free(msg);
7322 		return;
7323 	}
7324 
7325 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7326 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7327 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7328 	if (req_ie)
7329 		NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
7330 	if (resp_ie)
7331 		NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
7332 
7333 	genlmsg_end(msg, hdr);
7334 
7335 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7336 				nl80211_mlme_mcgrp.id, gfp);
7337 	return;
7338 
7339  nla_put_failure:
7340 	genlmsg_cancel(msg, hdr);
7341 	nlmsg_free(msg);
7342 
7343 }
7344 
nl80211_send_disconnected(struct cfg80211_registered_device * rdev,struct net_device * netdev,u16 reason,const u8 * ie,size_t ie_len,bool from_ap)7345 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
7346 			       struct net_device *netdev, u16 reason,
7347 			       const u8 *ie, size_t ie_len, bool from_ap)
7348 {
7349 	struct sk_buff *msg;
7350 	void *hdr;
7351 
7352 	msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7353 	if (!msg)
7354 		return;
7355 
7356 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
7357 	if (!hdr) {
7358 		nlmsg_free(msg);
7359 		return;
7360 	}
7361 
7362 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7363 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7364 	if (from_ap && reason)
7365 		NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
7366 	if (from_ap)
7367 		NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
7368 	if (ie)
7369 		NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
7370 
7371 	genlmsg_end(msg, hdr);
7372 
7373 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7374 				nl80211_mlme_mcgrp.id, GFP_KERNEL);
7375 	return;
7376 
7377  nla_put_failure:
7378 	genlmsg_cancel(msg, hdr);
7379 	nlmsg_free(msg);
7380 
7381 }
7382 
nl80211_send_ibss_bssid(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * bssid,gfp_t gfp)7383 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7384 			     struct net_device *netdev, const u8 *bssid,
7385 			     gfp_t gfp)
7386 {
7387 	struct sk_buff *msg;
7388 	void *hdr;
7389 
7390 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7391 	if (!msg)
7392 		return;
7393 
7394 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7395 	if (!hdr) {
7396 		nlmsg_free(msg);
7397 		return;
7398 	}
7399 
7400 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7401 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7402 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7403 
7404 	genlmsg_end(msg, hdr);
7405 
7406 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7407 				nl80211_mlme_mcgrp.id, gfp);
7408 	return;
7409 
7410  nla_put_failure:
7411 	genlmsg_cancel(msg, hdr);
7412 	nlmsg_free(msg);
7413 }
7414 
nl80211_send_new_peer_candidate(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * macaddr,const u8 * ie,u8 ie_len,gfp_t gfp)7415 void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7416 		struct net_device *netdev,
7417 		const u8 *macaddr, const u8* ie, u8 ie_len,
7418 		gfp_t gfp)
7419 {
7420 	struct sk_buff *msg;
7421 	void *hdr;
7422 
7423 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7424 	if (!msg)
7425 		return;
7426 
7427 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7428 	if (!hdr) {
7429 		nlmsg_free(msg);
7430 		return;
7431 	}
7432 
7433 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7434 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7435 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
7436 	if (ie_len && ie)
7437 		NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
7438 
7439 	genlmsg_end(msg, hdr);
7440 
7441 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7442 				nl80211_mlme_mcgrp.id, gfp);
7443 	return;
7444 
7445  nla_put_failure:
7446 	genlmsg_cancel(msg, hdr);
7447 	nlmsg_free(msg);
7448 }
7449 
nl80211_michael_mic_failure(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * addr,enum nl80211_key_type key_type,int key_id,const u8 * tsc,gfp_t gfp)7450 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7451 				 struct net_device *netdev, const u8 *addr,
7452 				 enum nl80211_key_type key_type, int key_id,
7453 				 const u8 *tsc, gfp_t gfp)
7454 {
7455 	struct sk_buff *msg;
7456 	void *hdr;
7457 
7458 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7459 	if (!msg)
7460 		return;
7461 
7462 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7463 	if (!hdr) {
7464 		nlmsg_free(msg);
7465 		return;
7466 	}
7467 
7468 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7469 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7470 	if (addr)
7471 		NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7472 	NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
7473 	if (key_id != -1)
7474 		NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
7475 	if (tsc)
7476 		NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
7477 
7478 	genlmsg_end(msg, hdr);
7479 
7480 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7481 				nl80211_mlme_mcgrp.id, gfp);
7482 	return;
7483 
7484  nla_put_failure:
7485 	genlmsg_cancel(msg, hdr);
7486 	nlmsg_free(msg);
7487 }
7488 
nl80211_send_beacon_hint_event(struct wiphy * wiphy,struct ieee80211_channel * channel_before,struct ieee80211_channel * channel_after)7489 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7490 				    struct ieee80211_channel *channel_before,
7491 				    struct ieee80211_channel *channel_after)
7492 {
7493 	struct sk_buff *msg;
7494 	void *hdr;
7495 	struct nlattr *nl_freq;
7496 
7497 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
7498 	if (!msg)
7499 		return;
7500 
7501 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7502 	if (!hdr) {
7503 		nlmsg_free(msg);
7504 		return;
7505 	}
7506 
7507 	/*
7508 	 * Since we are applying the beacon hint to a wiphy we know its
7509 	 * wiphy_idx is valid
7510 	 */
7511 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
7512 
7513 	/* Before */
7514 	nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7515 	if (!nl_freq)
7516 		goto nla_put_failure;
7517 	if (nl80211_msg_put_channel(msg, channel_before))
7518 		goto nla_put_failure;
7519 	nla_nest_end(msg, nl_freq);
7520 
7521 	/* After */
7522 	nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7523 	if (!nl_freq)
7524 		goto nla_put_failure;
7525 	if (nl80211_msg_put_channel(msg, channel_after))
7526 		goto nla_put_failure;
7527 	nla_nest_end(msg, nl_freq);
7528 
7529 	genlmsg_end(msg, hdr);
7530 
7531 	rcu_read_lock();
7532 	genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7533 				GFP_ATOMIC);
7534 	rcu_read_unlock();
7535 
7536 	return;
7537 
7538 nla_put_failure:
7539 	genlmsg_cancel(msg, hdr);
7540 	nlmsg_free(msg);
7541 }
7542 
nl80211_send_remain_on_chan_event(int cmd,struct cfg80211_registered_device * rdev,struct net_device * netdev,u64 cookie,struct ieee80211_channel * chan,enum nl80211_channel_type channel_type,unsigned int duration,gfp_t gfp)7543 static void nl80211_send_remain_on_chan_event(
7544 	int cmd, struct cfg80211_registered_device *rdev,
7545 	struct net_device *netdev, u64 cookie,
7546 	struct ieee80211_channel *chan,
7547 	enum nl80211_channel_type channel_type,
7548 	unsigned int duration, gfp_t gfp)
7549 {
7550 	struct sk_buff *msg;
7551 	void *hdr;
7552 
7553 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7554 	if (!msg)
7555 		return;
7556 
7557 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7558 	if (!hdr) {
7559 		nlmsg_free(msg);
7560 		return;
7561 	}
7562 
7563 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7564 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7565 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
7566 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
7567 	NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7568 
7569 	if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
7570 		NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
7571 
7572 	genlmsg_end(msg, hdr);
7573 
7574 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7575 				nl80211_mlme_mcgrp.id, gfp);
7576 	return;
7577 
7578  nla_put_failure:
7579 	genlmsg_cancel(msg, hdr);
7580 	nlmsg_free(msg);
7581 }
7582 
nl80211_send_remain_on_channel(struct cfg80211_registered_device * rdev,struct net_device * netdev,u64 cookie,struct ieee80211_channel * chan,enum nl80211_channel_type channel_type,unsigned int duration,gfp_t gfp)7583 void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7584 				    struct net_device *netdev, u64 cookie,
7585 				    struct ieee80211_channel *chan,
7586 				    enum nl80211_channel_type channel_type,
7587 				    unsigned int duration, gfp_t gfp)
7588 {
7589 	nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7590 					  rdev, netdev, cookie, chan,
7591 					  channel_type, duration, gfp);
7592 }
7593 
nl80211_send_remain_on_channel_cancel(struct cfg80211_registered_device * rdev,struct net_device * netdev,u64 cookie,struct ieee80211_channel * chan,enum nl80211_channel_type channel_type,gfp_t gfp)7594 void nl80211_send_remain_on_channel_cancel(
7595 	struct cfg80211_registered_device *rdev, struct net_device *netdev,
7596 	u64 cookie, struct ieee80211_channel *chan,
7597 	enum nl80211_channel_type channel_type, gfp_t gfp)
7598 {
7599 	nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7600 					  rdev, netdev, cookie, chan,
7601 					  channel_type, 0, gfp);
7602 }
7603 
nl80211_send_sta_event(struct cfg80211_registered_device * rdev,struct net_device * dev,const u8 * mac_addr,struct station_info * sinfo,gfp_t gfp)7604 void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7605 			    struct net_device *dev, const u8 *mac_addr,
7606 			    struct station_info *sinfo, gfp_t gfp)
7607 {
7608 	struct sk_buff *msg;
7609 
7610 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7611 	if (!msg)
7612 		return;
7613 
7614 	if (nl80211_send_station(msg, 0, 0, 0,
7615 				 rdev, dev, mac_addr, sinfo) < 0) {
7616 		nlmsg_free(msg);
7617 		return;
7618 	}
7619 
7620 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7621 				nl80211_mlme_mcgrp.id, gfp);
7622 }
7623 
nl80211_send_sta_del_event(struct cfg80211_registered_device * rdev,struct net_device * dev,const u8 * mac_addr,gfp_t gfp)7624 void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7625 				struct net_device *dev, const u8 *mac_addr,
7626 				gfp_t gfp)
7627 {
7628 	struct sk_buff *msg;
7629 	void *hdr;
7630 
7631 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7632 	if (!msg)
7633 		return;
7634 
7635 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7636 	if (!hdr) {
7637 		nlmsg_free(msg);
7638 		return;
7639 	}
7640 
7641 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7642 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
7643 
7644 	genlmsg_end(msg, hdr);
7645 
7646 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7647 				nl80211_mlme_mcgrp.id, gfp);
7648 	return;
7649 
7650  nla_put_failure:
7651 	genlmsg_cancel(msg, hdr);
7652 	nlmsg_free(msg);
7653 }
7654 
__nl80211_unexpected_frame(struct net_device * dev,u8 cmd,const u8 * addr,gfp_t gfp)7655 static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
7656 				       const u8 *addr, gfp_t gfp)
7657 {
7658 	struct wireless_dev *wdev = dev->ieee80211_ptr;
7659 	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7660 	struct sk_buff *msg;
7661 	void *hdr;
7662 	int err;
7663 	u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7664 
7665 	if (!nlpid)
7666 		return false;
7667 
7668 	msg = nlmsg_new(100, gfp);
7669 	if (!msg)
7670 		return true;
7671 
7672 	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7673 	if (!hdr) {
7674 		nlmsg_free(msg);
7675 		return true;
7676 	}
7677 
7678 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7679 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7680 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7681 
7682 	err = genlmsg_end(msg, hdr);
7683 	if (err < 0) {
7684 		nlmsg_free(msg);
7685 		return true;
7686 	}
7687 
7688 	genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7689 	return true;
7690 
7691  nla_put_failure:
7692 	genlmsg_cancel(msg, hdr);
7693 	nlmsg_free(msg);
7694 	return true;
7695 }
7696 
nl80211_unexpected_frame(struct net_device * dev,const u8 * addr,gfp_t gfp)7697 bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7698 {
7699 	return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
7700 					  addr, gfp);
7701 }
7702 
nl80211_unexpected_4addr_frame(struct net_device * dev,const u8 * addr,gfp_t gfp)7703 bool nl80211_unexpected_4addr_frame(struct net_device *dev,
7704 				    const u8 *addr, gfp_t gfp)
7705 {
7706 	return __nl80211_unexpected_frame(dev,
7707 					  NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
7708 					  addr, gfp);
7709 }
7710 
nl80211_send_mgmt(struct cfg80211_registered_device * rdev,struct net_device * netdev,u32 nlpid,int freq,int sig_dbm,const u8 * buf,size_t len,gfp_t gfp)7711 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7712 		      struct net_device *netdev, u32 nlpid,
7713 		      int freq, int sig_dbm,
7714 		      const u8 *buf, size_t len, gfp_t gfp)
7715 {
7716 	struct sk_buff *msg;
7717 	void *hdr;
7718 
7719 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7720 	if (!msg)
7721 		return -ENOMEM;
7722 
7723 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
7724 	if (!hdr) {
7725 		nlmsg_free(msg);
7726 		return -ENOMEM;
7727 	}
7728 
7729 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7730 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7731 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7732 	if (sig_dbm)
7733 		NLA_PUT_U32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm);
7734 	NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7735 
7736 	genlmsg_end(msg, hdr);
7737 
7738 	return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7739 
7740  nla_put_failure:
7741 	genlmsg_cancel(msg, hdr);
7742 	nlmsg_free(msg);
7743 	return -ENOBUFS;
7744 }
7745 
nl80211_send_mgmt_tx_status(struct cfg80211_registered_device * rdev,struct net_device * netdev,u64 cookie,const u8 * buf,size_t len,bool ack,gfp_t gfp)7746 void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
7747 				 struct net_device *netdev, u64 cookie,
7748 				 const u8 *buf, size_t len, bool ack,
7749 				 gfp_t gfp)
7750 {
7751 	struct sk_buff *msg;
7752 	void *hdr;
7753 
7754 	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7755 	if (!msg)
7756 		return;
7757 
7758 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
7759 	if (!hdr) {
7760 		nlmsg_free(msg);
7761 		return;
7762 	}
7763 
7764 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7765 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7766 	NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7767 	NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7768 	if (ack)
7769 		NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7770 
7771 	genlmsg_end(msg, hdr);
7772 
7773 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7774 				nl80211_mlme_mcgrp.id, gfp);
7775 	return;
7776 
7777  nla_put_failure:
7778 	genlmsg_cancel(msg, hdr);
7779 	nlmsg_free(msg);
7780 }
7781 
7782 void
nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device * rdev,struct net_device * netdev,enum nl80211_cqm_rssi_threshold_event rssi_event,gfp_t gfp)7783 nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
7784 			     struct net_device *netdev,
7785 			     enum nl80211_cqm_rssi_threshold_event rssi_event,
7786 			     gfp_t gfp)
7787 {
7788 	struct sk_buff *msg;
7789 	struct nlattr *pinfoattr;
7790 	void *hdr;
7791 
7792 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7793 	if (!msg)
7794 		return;
7795 
7796 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7797 	if (!hdr) {
7798 		nlmsg_free(msg);
7799 		return;
7800 	}
7801 
7802 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7803 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7804 
7805 	pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7806 	if (!pinfoattr)
7807 		goto nla_put_failure;
7808 
7809 	NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
7810 		    rssi_event);
7811 
7812 	nla_nest_end(msg, pinfoattr);
7813 
7814 	genlmsg_end(msg, hdr);
7815 
7816 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7817 				nl80211_mlme_mcgrp.id, gfp);
7818 	return;
7819 
7820  nla_put_failure:
7821 	genlmsg_cancel(msg, hdr);
7822 	nlmsg_free(msg);
7823 }
7824 
nl80211_gtk_rekey_notify(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * bssid,const u8 * replay_ctr,gfp_t gfp)7825 void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
7826 			      struct net_device *netdev, const u8 *bssid,
7827 			      const u8 *replay_ctr, gfp_t gfp)
7828 {
7829 	struct sk_buff *msg;
7830 	struct nlattr *rekey_attr;
7831 	void *hdr;
7832 
7833 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7834 	if (!msg)
7835 		return;
7836 
7837 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
7838 	if (!hdr) {
7839 		nlmsg_free(msg);
7840 		return;
7841 	}
7842 
7843 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7844 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7845 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7846 
7847 	rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
7848 	if (!rekey_attr)
7849 		goto nla_put_failure;
7850 
7851 	NLA_PUT(msg, NL80211_REKEY_DATA_REPLAY_CTR,
7852 		NL80211_REPLAY_CTR_LEN, replay_ctr);
7853 
7854 	nla_nest_end(msg, rekey_attr);
7855 
7856 	genlmsg_end(msg, hdr);
7857 
7858 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7859 				nl80211_mlme_mcgrp.id, gfp);
7860 	return;
7861 
7862  nla_put_failure:
7863 	genlmsg_cancel(msg, hdr);
7864 	nlmsg_free(msg);
7865 }
7866 
nl80211_pmksa_candidate_notify(struct cfg80211_registered_device * rdev,struct net_device * netdev,int index,const u8 * bssid,bool preauth,gfp_t gfp)7867 void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
7868 				    struct net_device *netdev, int index,
7869 				    const u8 *bssid, bool preauth, gfp_t gfp)
7870 {
7871 	struct sk_buff *msg;
7872 	struct nlattr *attr;
7873 	void *hdr;
7874 
7875 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7876 	if (!msg)
7877 		return;
7878 
7879 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
7880 	if (!hdr) {
7881 		nlmsg_free(msg);
7882 		return;
7883 	}
7884 
7885 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7886 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7887 
7888 	attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
7889 	if (!attr)
7890 		goto nla_put_failure;
7891 
7892 	NLA_PUT_U32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index);
7893 	NLA_PUT(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid);
7894 	if (preauth)
7895 		NLA_PUT_FLAG(msg, NL80211_PMKSA_CANDIDATE_PREAUTH);
7896 
7897 	nla_nest_end(msg, attr);
7898 
7899 	genlmsg_end(msg, hdr);
7900 
7901 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7902 				nl80211_mlme_mcgrp.id, gfp);
7903 	return;
7904 
7905  nla_put_failure:
7906 	genlmsg_cancel(msg, hdr);
7907 	nlmsg_free(msg);
7908 }
7909 
7910 void
nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device * rdev,struct net_device * netdev,const u8 * peer,u32 num_packets,gfp_t gfp)7911 nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
7912 				struct net_device *netdev, const u8 *peer,
7913 				u32 num_packets, gfp_t gfp)
7914 {
7915 	struct sk_buff *msg;
7916 	struct nlattr *pinfoattr;
7917 	void *hdr;
7918 
7919 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7920 	if (!msg)
7921 		return;
7922 
7923 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7924 	if (!hdr) {
7925 		nlmsg_free(msg);
7926 		return;
7927 	}
7928 
7929 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7930 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7931 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
7932 
7933 	pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7934 	if (!pinfoattr)
7935 		goto nla_put_failure;
7936 
7937 	NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
7938 
7939 	nla_nest_end(msg, pinfoattr);
7940 
7941 	genlmsg_end(msg, hdr);
7942 
7943 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7944 				nl80211_mlme_mcgrp.id, gfp);
7945 	return;
7946 
7947  nla_put_failure:
7948 	genlmsg_cancel(msg, hdr);
7949 	nlmsg_free(msg);
7950 }
7951 
cfg80211_probe_status(struct net_device * dev,const u8 * addr,u64 cookie,bool acked,gfp_t gfp)7952 void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
7953 			   u64 cookie, bool acked, gfp_t gfp)
7954 {
7955 	struct wireless_dev *wdev = dev->ieee80211_ptr;
7956 	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7957 	struct sk_buff *msg;
7958 	void *hdr;
7959 	int err;
7960 
7961 	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7962 	if (!msg)
7963 		return;
7964 
7965 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
7966 	if (!hdr) {
7967 		nlmsg_free(msg);
7968 		return;
7969 	}
7970 
7971 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7972 	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7973 	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7974 	NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7975 	if (acked)
7976 		NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7977 
7978 	err = genlmsg_end(msg, hdr);
7979 	if (err < 0) {
7980 		nlmsg_free(msg);
7981 		return;
7982 	}
7983 
7984 	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7985 				nl80211_mlme_mcgrp.id, gfp);
7986 	return;
7987 
7988  nla_put_failure:
7989 	genlmsg_cancel(msg, hdr);
7990 	nlmsg_free(msg);
7991 }
7992 EXPORT_SYMBOL(cfg80211_probe_status);
7993 
cfg80211_report_obss_beacon(struct wiphy * wiphy,const u8 * frame,size_t len,int freq,int sig_dbm,gfp_t gfp)7994 void cfg80211_report_obss_beacon(struct wiphy *wiphy,
7995 				 const u8 *frame, size_t len,
7996 				 int freq, int sig_dbm, gfp_t gfp)
7997 {
7998 	struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
7999 	struct sk_buff *msg;
8000 	void *hdr;
8001 	u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
8002 
8003 	if (!nlpid)
8004 		return;
8005 
8006 	msg = nlmsg_new(len + 100, gfp);
8007 	if (!msg)
8008 		return;
8009 
8010 	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
8011 	if (!hdr) {
8012 		nlmsg_free(msg);
8013 		return;
8014 	}
8015 
8016 	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
8017 	if (freq)
8018 		NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
8019 	if (sig_dbm)
8020 		NLA_PUT_U32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm);
8021 	NLA_PUT(msg, NL80211_ATTR_FRAME, len, frame);
8022 
8023 	genlmsg_end(msg, hdr);
8024 
8025 	genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
8026 	return;
8027 
8028  nla_put_failure:
8029 	genlmsg_cancel(msg, hdr);
8030 	nlmsg_free(msg);
8031 }
8032 EXPORT_SYMBOL(cfg80211_report_obss_beacon);
8033 
nl80211_netlink_notify(struct notifier_block * nb,unsigned long state,void * _notify)8034 static int nl80211_netlink_notify(struct notifier_block * nb,
8035 				  unsigned long state,
8036 				  void *_notify)
8037 {
8038 	struct netlink_notify *notify = _notify;
8039 	struct cfg80211_registered_device *rdev;
8040 	struct wireless_dev *wdev;
8041 
8042 	if (state != NETLINK_URELEASE)
8043 		return NOTIFY_DONE;
8044 
8045 	rcu_read_lock();
8046 
8047 	list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
8048 		list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
8049 			cfg80211_mlme_unregister_socket(wdev, notify->pid);
8050 		if (rdev->ap_beacons_nlpid == notify->pid)
8051 			rdev->ap_beacons_nlpid = 0;
8052 	}
8053 
8054 	rcu_read_unlock();
8055 
8056 	return NOTIFY_DONE;
8057 }
8058 
8059 static struct notifier_block nl80211_netlink_notifier = {
8060 	.notifier_call = nl80211_netlink_notify,
8061 };
8062 
8063 /* initialisation/exit functions */
8064 
nl80211_init(void)8065 int nl80211_init(void)
8066 {
8067 	int err;
8068 
8069 	err = genl_register_family_with_ops(&nl80211_fam,
8070 		nl80211_ops, ARRAY_SIZE(nl80211_ops));
8071 	if (err)
8072 		return err;
8073 
8074 	err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
8075 	if (err)
8076 		goto err_out;
8077 
8078 	err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
8079 	if (err)
8080 		goto err_out;
8081 
8082 	err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
8083 	if (err)
8084 		goto err_out;
8085 
8086 	err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
8087 	if (err)
8088 		goto err_out;
8089 
8090 #ifdef CONFIG_NL80211_TESTMODE
8091 	err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
8092 	if (err)
8093 		goto err_out;
8094 #endif
8095 
8096 	err = netlink_register_notifier(&nl80211_netlink_notifier);
8097 	if (err)
8098 		goto err_out;
8099 
8100 	return 0;
8101  err_out:
8102 	genl_unregister_family(&nl80211_fam);
8103 	return err;
8104 }
8105 
nl80211_exit(void)8106 void nl80211_exit(void)
8107 {
8108 	netlink_unregister_notifier(&nl80211_netlink_notifier);
8109 	genl_unregister_family(&nl80211_fam);
8110 }
8111