nl80211: Add event for authentication/association timeout
[safe/jmp/linux-2.6] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006, 2007 Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/list.h>
11 #include <linux/if_ether.h>
12 #include <linux/ieee80211.h>
13 #include <linux/nl80211.h>
14 #include <linux/rtnetlink.h>
15 #include <linux/netlink.h>
16 #include <linux/etherdevice.h>
17 #include <net/genetlink.h>
18 #include <net/cfg80211.h>
19 #include "core.h"
20 #include "nl80211.h"
21 #include "reg.h"
22
23 /* the netlink family */
24 static struct genl_family nl80211_fam = {
25         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
26         .name = "nl80211",      /* have users key off the name instead */
27         .hdrsize = 0,           /* no private header */
28         .version = 1,           /* no particular meaning now */
29         .maxattr = NL80211_ATTR_MAX,
30 };
31
32 /* internal helper: get drv and dev */
33 static int get_drv_dev_by_info_ifindex(struct nlattr **attrs,
34                                        struct cfg80211_registered_device **drv,
35                                        struct net_device **dev)
36 {
37         int ifindex;
38
39         if (!attrs[NL80211_ATTR_IFINDEX])
40                 return -EINVAL;
41
42         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
43         *dev = dev_get_by_index(&init_net, ifindex);
44         if (!*dev)
45                 return -ENODEV;
46
47         *drv = cfg80211_get_dev_from_ifindex(ifindex);
48         if (IS_ERR(*drv)) {
49                 dev_put(*dev);
50                 return PTR_ERR(*drv);
51         }
52
53         return 0;
54 }
55
56 /* policy for the attributes */
57 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
58         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
59         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
60                                       .len = BUS_ID_SIZE-1 },
61         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
62         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
63         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
64         [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
65         [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
66         [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
67         [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
68
69         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
70         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
71         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
72
73         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
74
75         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
76                                     .len = WLAN_MAX_KEY_LEN },
77         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
78         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
79         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
80
81         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
82         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
83         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
84                                        .len = IEEE80211_MAX_DATA_LEN },
85         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
86                                        .len = IEEE80211_MAX_DATA_LEN },
87         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
88         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
89         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
90         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
91                                                .len = NL80211_MAX_SUPP_RATES },
92         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
93         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
94         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
95         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
96                                 .len = IEEE80211_MAX_MESH_ID_LEN },
97         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
98
99         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
100         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
101
102         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
103         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
104         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
105         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
106                                            .len = NL80211_MAX_SUPP_RATES },
107
108         [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
109
110         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
111                                          .len = NL80211_HT_CAPABILITY_LEN },
112
113         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
114         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
115                               .len = IEEE80211_MAX_DATA_LEN },
116         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
117         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
118
119         [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
120                                 .len = IEEE80211_MAX_SSID_LEN },
121         [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
122         [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
123         [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
124         [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
125 };
126
127 /* IE validation */
128 static bool is_valid_ie_attr(const struct nlattr *attr)
129 {
130         const u8 *pos;
131         int len;
132
133         if (!attr)
134                 return true;
135
136         pos = nla_data(attr);
137         len = nla_len(attr);
138
139         while (len) {
140                 u8 elemlen;
141
142                 if (len < 2)
143                         return false;
144                 len -= 2;
145
146                 elemlen = pos[1];
147                 if (elemlen > len)
148                         return false;
149
150                 len -= elemlen;
151                 pos += 2 + elemlen;
152         }
153
154         return true;
155 }
156
157 /* message building helper */
158 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
159                                    int flags, u8 cmd)
160 {
161         /* since there is no private header just add the generic one */
162         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
163 }
164
165 static int nl80211_msg_put_channel(struct sk_buff *msg,
166                                    struct ieee80211_channel *chan)
167 {
168         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
169                     chan->center_freq);
170
171         if (chan->flags & IEEE80211_CHAN_DISABLED)
172                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
173         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
174                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
175         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
176                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
177         if (chan->flags & IEEE80211_CHAN_RADAR)
178                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
179
180         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
181                     DBM_TO_MBM(chan->max_power));
182
183         return 0;
184
185  nla_put_failure:
186         return -ENOBUFS;
187 }
188
189 /* netlink command implementations */
190
191 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
192                               struct cfg80211_registered_device *dev)
193 {
194         void *hdr;
195         struct nlattr *nl_bands, *nl_band;
196         struct nlattr *nl_freqs, *nl_freq;
197         struct nlattr *nl_rates, *nl_rate;
198         struct nlattr *nl_modes;
199         struct nlattr *nl_cmds;
200         enum ieee80211_band band;
201         struct ieee80211_channel *chan;
202         struct ieee80211_rate *rate;
203         int i;
204         u16 ifmodes = dev->wiphy.interface_modes;
205
206         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
207         if (!hdr)
208                 return -1;
209
210         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
211         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
212
213         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
214                    dev->wiphy.retry_short);
215         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
216                    dev->wiphy.retry_long);
217         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
218                     dev->wiphy.frag_threshold);
219         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
220                     dev->wiphy.rts_threshold);
221
222         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
223                    dev->wiphy.max_scan_ssids);
224         NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
225                     dev->wiphy.max_scan_ie_len);
226
227         NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
228                 sizeof(u32) * dev->wiphy.n_cipher_suites,
229                 dev->wiphy.cipher_suites);
230
231         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
232         if (!nl_modes)
233                 goto nla_put_failure;
234
235         i = 0;
236         while (ifmodes) {
237                 if (ifmodes & 1)
238                         NLA_PUT_FLAG(msg, i);
239                 ifmodes >>= 1;
240                 i++;
241         }
242
243         nla_nest_end(msg, nl_modes);
244
245         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
246         if (!nl_bands)
247                 goto nla_put_failure;
248
249         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
250                 if (!dev->wiphy.bands[band])
251                         continue;
252
253                 nl_band = nla_nest_start(msg, band);
254                 if (!nl_band)
255                         goto nla_put_failure;
256
257                 /* add HT info */
258                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
259                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
260                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
261                                 &dev->wiphy.bands[band]->ht_cap.mcs);
262                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
263                                 dev->wiphy.bands[band]->ht_cap.cap);
264                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
265                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
266                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
267                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
268                 }
269
270                 /* add frequencies */
271                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
272                 if (!nl_freqs)
273                         goto nla_put_failure;
274
275                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
276                         nl_freq = nla_nest_start(msg, i);
277                         if (!nl_freq)
278                                 goto nla_put_failure;
279
280                         chan = &dev->wiphy.bands[band]->channels[i];
281
282                         if (nl80211_msg_put_channel(msg, chan))
283                                 goto nla_put_failure;
284
285                         nla_nest_end(msg, nl_freq);
286                 }
287
288                 nla_nest_end(msg, nl_freqs);
289
290                 /* add bitrates */
291                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
292                 if (!nl_rates)
293                         goto nla_put_failure;
294
295                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
296                         nl_rate = nla_nest_start(msg, i);
297                         if (!nl_rate)
298                                 goto nla_put_failure;
299
300                         rate = &dev->wiphy.bands[band]->bitrates[i];
301                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
302                                     rate->bitrate);
303                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
304                                 NLA_PUT_FLAG(msg,
305                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
306
307                         nla_nest_end(msg, nl_rate);
308                 }
309
310                 nla_nest_end(msg, nl_rates);
311
312                 nla_nest_end(msg, nl_band);
313         }
314         nla_nest_end(msg, nl_bands);
315
316         nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
317         if (!nl_cmds)
318                 goto nla_put_failure;
319
320         i = 0;
321 #define CMD(op, n)                                              \
322          do {                                                   \
323                 if (dev->ops->op) {                             \
324                         i++;                                    \
325                         NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
326                 }                                               \
327         } while (0)
328
329         CMD(add_virtual_intf, NEW_INTERFACE);
330         CMD(change_virtual_intf, SET_INTERFACE);
331         CMD(add_key, NEW_KEY);
332         CMD(add_beacon, NEW_BEACON);
333         CMD(add_station, NEW_STATION);
334         CMD(add_mpath, NEW_MPATH);
335         CMD(set_mesh_params, SET_MESH_PARAMS);
336         CMD(change_bss, SET_BSS);
337         CMD(auth, AUTHENTICATE);
338         CMD(assoc, ASSOCIATE);
339         CMD(deauth, DEAUTHENTICATE);
340         CMD(disassoc, DISASSOCIATE);
341         CMD(join_ibss, JOIN_IBSS);
342
343 #undef CMD
344         nla_nest_end(msg, nl_cmds);
345
346         return genlmsg_end(msg, hdr);
347
348  nla_put_failure:
349         genlmsg_cancel(msg, hdr);
350         return -EMSGSIZE;
351 }
352
353 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
354 {
355         int idx = 0;
356         int start = cb->args[0];
357         struct cfg80211_registered_device *dev;
358
359         mutex_lock(&cfg80211_mutex);
360         list_for_each_entry(dev, &cfg80211_drv_list, list) {
361                 if (++idx <= start)
362                         continue;
363                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
364                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
365                                        dev) < 0) {
366                         idx--;
367                         break;
368                 }
369         }
370         mutex_unlock(&cfg80211_mutex);
371
372         cb->args[0] = idx;
373
374         return skb->len;
375 }
376
377 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
378 {
379         struct sk_buff *msg;
380         struct cfg80211_registered_device *dev;
381
382         dev = cfg80211_get_dev_from_info(info);
383         if (IS_ERR(dev))
384                 return PTR_ERR(dev);
385
386         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
387         if (!msg)
388                 goto out_err;
389
390         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
391                 goto out_free;
392
393         cfg80211_put_dev(dev);
394
395         return genlmsg_unicast(msg, info->snd_pid);
396
397  out_free:
398         nlmsg_free(msg);
399  out_err:
400         cfg80211_put_dev(dev);
401         return -ENOBUFS;
402 }
403
404 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
405         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
406         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
407         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
408         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
409         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
410 };
411
412 static int parse_txq_params(struct nlattr *tb[],
413                             struct ieee80211_txq_params *txq_params)
414 {
415         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
416             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
417             !tb[NL80211_TXQ_ATTR_AIFS])
418                 return -EINVAL;
419
420         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
421         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
422         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
423         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
424         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
425
426         return 0;
427 }
428
429 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
430 {
431         struct cfg80211_registered_device *rdev;
432         int result = 0, rem_txq_params = 0;
433         struct nlattr *nl_txq_params;
434         u32 changed;
435         u8 retry_short = 0, retry_long = 0;
436         u32 frag_threshold = 0, rts_threshold = 0;
437
438         rtnl_lock();
439
440         mutex_lock(&cfg80211_mutex);
441
442         rdev = __cfg80211_drv_from_info(info);
443         if (IS_ERR(rdev)) {
444                 result = PTR_ERR(rdev);
445                 goto unlock;
446         }
447
448         mutex_lock(&rdev->mtx);
449
450         if (info->attrs[NL80211_ATTR_WIPHY_NAME])
451                 result = cfg80211_dev_rename(
452                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
453
454         mutex_unlock(&cfg80211_mutex);
455
456         if (result)
457                 goto bad_res;
458
459         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
460                 struct ieee80211_txq_params txq_params;
461                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
462
463                 if (!rdev->ops->set_txq_params) {
464                         result = -EOPNOTSUPP;
465                         goto bad_res;
466                 }
467
468                 nla_for_each_nested(nl_txq_params,
469                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
470                                     rem_txq_params) {
471                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
472                                   nla_data(nl_txq_params),
473                                   nla_len(nl_txq_params),
474                                   txq_params_policy);
475                         result = parse_txq_params(tb, &txq_params);
476                         if (result)
477                                 goto bad_res;
478
479                         result = rdev->ops->set_txq_params(&rdev->wiphy,
480                                                            &txq_params);
481                         if (result)
482                                 goto bad_res;
483                 }
484         }
485
486         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
487                 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
488                 struct ieee80211_channel *chan;
489                 struct ieee80211_sta_ht_cap *ht_cap;
490                 u32 freq, sec_freq;
491
492                 if (!rdev->ops->set_channel) {
493                         result = -EOPNOTSUPP;
494                         goto bad_res;
495                 }
496
497                 result = -EINVAL;
498
499                 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
500                         channel_type = nla_get_u32(info->attrs[
501                                            NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
502                         if (channel_type != NL80211_CHAN_NO_HT &&
503                             channel_type != NL80211_CHAN_HT20 &&
504                             channel_type != NL80211_CHAN_HT40PLUS &&
505                             channel_type != NL80211_CHAN_HT40MINUS)
506                                 goto bad_res;
507                 }
508
509                 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
510                 chan = ieee80211_get_channel(&rdev->wiphy, freq);
511
512                 /* Primary channel not allowed */
513                 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
514                         goto bad_res;
515
516                 if (channel_type == NL80211_CHAN_HT40MINUS)
517                         sec_freq = freq - 20;
518                 else if (channel_type == NL80211_CHAN_HT40PLUS)
519                         sec_freq = freq + 20;
520                 else
521                         sec_freq = 0;
522
523                 ht_cap = &rdev->wiphy.bands[chan->band]->ht_cap;
524
525                 /* no HT capabilities */
526                 if (channel_type != NL80211_CHAN_NO_HT &&
527                     !ht_cap->ht_supported)
528                         goto bad_res;
529
530                 if (sec_freq) {
531                         struct ieee80211_channel *schan;
532
533                         /* no 40 MHz capabilities */
534                         if (!(ht_cap->cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40) ||
535                             (ht_cap->cap & IEEE80211_HT_CAP_40MHZ_INTOLERANT))
536                                 goto bad_res;
537
538                         schan = ieee80211_get_channel(&rdev->wiphy, sec_freq);
539
540                         /* Secondary channel not allowed */
541                         if (!schan || schan->flags & IEEE80211_CHAN_DISABLED)
542                                 goto bad_res;
543                 }
544
545                 result = rdev->ops->set_channel(&rdev->wiphy, chan,
546                                                 channel_type);
547                 if (result)
548                         goto bad_res;
549         }
550
551         changed = 0;
552
553         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
554                 retry_short = nla_get_u8(
555                         info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
556                 if (retry_short == 0) {
557                         result = -EINVAL;
558                         goto bad_res;
559                 }
560                 changed |= WIPHY_PARAM_RETRY_SHORT;
561         }
562
563         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
564                 retry_long = nla_get_u8(
565                         info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
566                 if (retry_long == 0) {
567                         result = -EINVAL;
568                         goto bad_res;
569                 }
570                 changed |= WIPHY_PARAM_RETRY_LONG;
571         }
572
573         if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
574                 frag_threshold = nla_get_u32(
575                         info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
576                 if (frag_threshold < 256) {
577                         result = -EINVAL;
578                         goto bad_res;
579                 }
580                 if (frag_threshold != (u32) -1) {
581                         /*
582                          * Fragments (apart from the last one) are required to
583                          * have even length. Make the fragmentation code
584                          * simpler by stripping LSB should someone try to use
585                          * odd threshold value.
586                          */
587                         frag_threshold &= ~0x1;
588                 }
589                 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
590         }
591
592         if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
593                 rts_threshold = nla_get_u32(
594                         info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
595                 changed |= WIPHY_PARAM_RTS_THRESHOLD;
596         }
597
598         if (changed) {
599                 u8 old_retry_short, old_retry_long;
600                 u32 old_frag_threshold, old_rts_threshold;
601
602                 if (!rdev->ops->set_wiphy_params) {
603                         result = -EOPNOTSUPP;
604                         goto bad_res;
605                 }
606
607                 old_retry_short = rdev->wiphy.retry_short;
608                 old_retry_long = rdev->wiphy.retry_long;
609                 old_frag_threshold = rdev->wiphy.frag_threshold;
610                 old_rts_threshold = rdev->wiphy.rts_threshold;
611
612                 if (changed & WIPHY_PARAM_RETRY_SHORT)
613                         rdev->wiphy.retry_short = retry_short;
614                 if (changed & WIPHY_PARAM_RETRY_LONG)
615                         rdev->wiphy.retry_long = retry_long;
616                 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
617                         rdev->wiphy.frag_threshold = frag_threshold;
618                 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
619                         rdev->wiphy.rts_threshold = rts_threshold;
620
621                 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
622                 if (result) {
623                         rdev->wiphy.retry_short = old_retry_short;
624                         rdev->wiphy.retry_long = old_retry_long;
625                         rdev->wiphy.frag_threshold = old_frag_threshold;
626                         rdev->wiphy.rts_threshold = old_rts_threshold;
627                 }
628         }
629
630  bad_res:
631         mutex_unlock(&rdev->mtx);
632  unlock:
633         rtnl_unlock();
634         return result;
635 }
636
637
638 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
639                               struct cfg80211_registered_device *rdev,
640                               struct net_device *dev)
641 {
642         void *hdr;
643
644         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
645         if (!hdr)
646                 return -1;
647
648         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
649         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
650         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
651         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
652         return genlmsg_end(msg, hdr);
653
654  nla_put_failure:
655         genlmsg_cancel(msg, hdr);
656         return -EMSGSIZE;
657 }
658
659 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
660 {
661         int wp_idx = 0;
662         int if_idx = 0;
663         int wp_start = cb->args[0];
664         int if_start = cb->args[1];
665         struct cfg80211_registered_device *dev;
666         struct wireless_dev *wdev;
667
668         mutex_lock(&cfg80211_mutex);
669         list_for_each_entry(dev, &cfg80211_drv_list, list) {
670                 if (wp_idx < wp_start) {
671                         wp_idx++;
672                         continue;
673                 }
674                 if_idx = 0;
675
676                 mutex_lock(&dev->devlist_mtx);
677                 list_for_each_entry(wdev, &dev->netdev_list, list) {
678                         if (if_idx < if_start) {
679                                 if_idx++;
680                                 continue;
681                         }
682                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
683                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
684                                                dev, wdev->netdev) < 0) {
685                                 mutex_unlock(&dev->devlist_mtx);
686                                 goto out;
687                         }
688                         if_idx++;
689                 }
690                 mutex_unlock(&dev->devlist_mtx);
691
692                 wp_idx++;
693         }
694  out:
695         mutex_unlock(&cfg80211_mutex);
696
697         cb->args[0] = wp_idx;
698         cb->args[1] = if_idx;
699
700         return skb->len;
701 }
702
703 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
704 {
705         struct sk_buff *msg;
706         struct cfg80211_registered_device *dev;
707         struct net_device *netdev;
708         int err;
709
710         err = get_drv_dev_by_info_ifindex(info->attrs, &dev, &netdev);
711         if (err)
712                 return err;
713
714         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
715         if (!msg)
716                 goto out_err;
717
718         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
719                                dev, netdev) < 0)
720                 goto out_free;
721
722         dev_put(netdev);
723         cfg80211_put_dev(dev);
724
725         return genlmsg_unicast(msg, info->snd_pid);
726
727  out_free:
728         nlmsg_free(msg);
729  out_err:
730         dev_put(netdev);
731         cfg80211_put_dev(dev);
732         return -ENOBUFS;
733 }
734
735 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
736         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
737         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
738         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
739         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
740         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
741 };
742
743 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
744 {
745         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
746         int flag;
747
748         *mntrflags = 0;
749
750         if (!nla)
751                 return -EINVAL;
752
753         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
754                              nla, mntr_flags_policy))
755                 return -EINVAL;
756
757         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
758                 if (flags[flag])
759                         *mntrflags |= (1<<flag);
760
761         return 0;
762 }
763
764 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
765 {
766         struct cfg80211_registered_device *drv;
767         struct vif_params params;
768         int err, ifindex;
769         enum nl80211_iftype otype, ntype;
770         struct net_device *dev;
771         u32 _flags, *flags = NULL;
772         bool change = false;
773
774         memset(&params, 0, sizeof(params));
775
776         rtnl_lock();
777
778         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
779         if (err)
780                 goto unlock_rtnl;
781
782         ifindex = dev->ifindex;
783         otype = ntype = dev->ieee80211_ptr->iftype;
784         dev_put(dev);
785
786         if (info->attrs[NL80211_ATTR_IFTYPE]) {
787                 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
788                 if (otype != ntype)
789                         change = true;
790                 if (ntype > NL80211_IFTYPE_MAX) {
791                         err = -EINVAL;
792                         goto unlock;
793                 }
794         }
795
796         if (!drv->ops->change_virtual_intf ||
797             !(drv->wiphy.interface_modes & (1 << ntype))) {
798                 err = -EOPNOTSUPP;
799                 goto unlock;
800         }
801
802         if (info->attrs[NL80211_ATTR_MESH_ID]) {
803                 if (ntype != NL80211_IFTYPE_MESH_POINT) {
804                         err = -EINVAL;
805                         goto unlock;
806                 }
807                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
808                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
809                 change = true;
810         }
811
812         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
813                 if (ntype != NL80211_IFTYPE_MONITOR) {
814                         err = -EINVAL;
815                         goto unlock;
816                 }
817                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
818                                           &_flags);
819                 if (err)
820                         goto unlock;
821
822                 flags = &_flags;
823                 change = true;
824         }
825
826         if (change)
827                 err = drv->ops->change_virtual_intf(&drv->wiphy, ifindex,
828                                                     ntype, flags, &params);
829         else
830                 err = 0;
831
832         dev = __dev_get_by_index(&init_net, ifindex);
833         WARN_ON(!dev || (!err && dev->ieee80211_ptr->iftype != ntype));
834
835         if (dev && !err && (ntype != otype)) {
836                 if (otype == NL80211_IFTYPE_ADHOC)
837                         cfg80211_clear_ibss(dev, false);
838         }
839
840  unlock:
841         cfg80211_put_dev(drv);
842  unlock_rtnl:
843         rtnl_unlock();
844         return err;
845 }
846
847 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
848 {
849         struct cfg80211_registered_device *drv;
850         struct vif_params params;
851         int err;
852         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
853         u32 flags;
854
855         memset(&params, 0, sizeof(params));
856
857         if (!info->attrs[NL80211_ATTR_IFNAME])
858                 return -EINVAL;
859
860         if (info->attrs[NL80211_ATTR_IFTYPE]) {
861                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
862                 if (type > NL80211_IFTYPE_MAX)
863                         return -EINVAL;
864         }
865
866         rtnl_lock();
867
868         drv = cfg80211_get_dev_from_info(info);
869         if (IS_ERR(drv)) {
870                 err = PTR_ERR(drv);
871                 goto unlock_rtnl;
872         }
873
874         if (!drv->ops->add_virtual_intf ||
875             !(drv->wiphy.interface_modes & (1 << type))) {
876                 err = -EOPNOTSUPP;
877                 goto unlock;
878         }
879
880         if (type == NL80211_IFTYPE_MESH_POINT &&
881             info->attrs[NL80211_ATTR_MESH_ID]) {
882                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
883                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
884         }
885
886         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
887                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
888                                   &flags);
889         err = drv->ops->add_virtual_intf(&drv->wiphy,
890                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
891                 type, err ? NULL : &flags, &params);
892
893  unlock:
894         cfg80211_put_dev(drv);
895  unlock_rtnl:
896         rtnl_unlock();
897         return err;
898 }
899
900 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
901 {
902         struct cfg80211_registered_device *drv;
903         int ifindex, err;
904         struct net_device *dev;
905
906         rtnl_lock();
907
908         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
909         if (err)
910                 goto unlock_rtnl;
911         ifindex = dev->ifindex;
912         dev_put(dev);
913
914         if (!drv->ops->del_virtual_intf) {
915                 err = -EOPNOTSUPP;
916                 goto out;
917         }
918
919         err = drv->ops->del_virtual_intf(&drv->wiphy, ifindex);
920
921  out:
922         cfg80211_put_dev(drv);
923  unlock_rtnl:
924         rtnl_unlock();
925         return err;
926 }
927
928 struct get_key_cookie {
929         struct sk_buff *msg;
930         int error;
931 };
932
933 static void get_key_callback(void *c, struct key_params *params)
934 {
935         struct get_key_cookie *cookie = c;
936
937         if (params->key)
938                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
939                         params->key_len, params->key);
940
941         if (params->seq)
942                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
943                         params->seq_len, params->seq);
944
945         if (params->cipher)
946                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
947                             params->cipher);
948
949         return;
950  nla_put_failure:
951         cookie->error = 1;
952 }
953
954 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
955 {
956         struct cfg80211_registered_device *drv;
957         int err;
958         struct net_device *dev;
959         u8 key_idx = 0;
960         u8 *mac_addr = NULL;
961         struct get_key_cookie cookie = {
962                 .error = 0,
963         };
964         void *hdr;
965         struct sk_buff *msg;
966
967         if (info->attrs[NL80211_ATTR_KEY_IDX])
968                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
969
970         if (key_idx > 5)
971                 return -EINVAL;
972
973         if (info->attrs[NL80211_ATTR_MAC])
974                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
975
976         rtnl_lock();
977
978         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
979         if (err)
980                 goto unlock_rtnl;
981
982         if (!drv->ops->get_key) {
983                 err = -EOPNOTSUPP;
984                 goto out;
985         }
986
987         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
988         if (!msg) {
989                 err = -ENOMEM;
990                 goto out;
991         }
992
993         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
994                              NL80211_CMD_NEW_KEY);
995
996         if (IS_ERR(hdr)) {
997                 err = PTR_ERR(hdr);
998                 goto out;
999         }
1000
1001         cookie.msg = msg;
1002
1003         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1004         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1005         if (mac_addr)
1006                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1007
1008         err = drv->ops->get_key(&drv->wiphy, dev, key_idx, mac_addr,
1009                                 &cookie, get_key_callback);
1010
1011         if (err)
1012                 goto out;
1013
1014         if (cookie.error)
1015                 goto nla_put_failure;
1016
1017         genlmsg_end(msg, hdr);
1018         err = genlmsg_unicast(msg, info->snd_pid);
1019         goto out;
1020
1021  nla_put_failure:
1022         err = -ENOBUFS;
1023         nlmsg_free(msg);
1024  out:
1025         cfg80211_put_dev(drv);
1026         dev_put(dev);
1027  unlock_rtnl:
1028         rtnl_unlock();
1029
1030         return err;
1031 }
1032
1033 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1034 {
1035         struct cfg80211_registered_device *drv;
1036         int err;
1037         struct net_device *dev;
1038         u8 key_idx;
1039         int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1040                     u8 key_index);
1041
1042         if (!info->attrs[NL80211_ATTR_KEY_IDX])
1043                 return -EINVAL;
1044
1045         key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1046
1047         if (info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT]) {
1048                 if (key_idx < 4 || key_idx > 5)
1049                         return -EINVAL;
1050         } else if (key_idx > 3)
1051                 return -EINVAL;
1052
1053         /* currently only support setting default key */
1054         if (!info->attrs[NL80211_ATTR_KEY_DEFAULT] &&
1055             !info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT])
1056                 return -EINVAL;
1057
1058         rtnl_lock();
1059
1060         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1061         if (err)
1062                 goto unlock_rtnl;
1063
1064         if (info->attrs[NL80211_ATTR_KEY_DEFAULT])
1065                 func = drv->ops->set_default_key;
1066         else
1067                 func = drv->ops->set_default_mgmt_key;
1068
1069         if (!func) {
1070                 err = -EOPNOTSUPP;
1071                 goto out;
1072         }
1073
1074         err = func(&drv->wiphy, dev, key_idx);
1075
1076  out:
1077         cfg80211_put_dev(drv);
1078         dev_put(dev);
1079
1080  unlock_rtnl:
1081         rtnl_unlock();
1082
1083         return err;
1084 }
1085
1086 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1087 {
1088         struct cfg80211_registered_device *drv;
1089         int err, i;
1090         struct net_device *dev;
1091         struct key_params params;
1092         u8 key_idx = 0;
1093         u8 *mac_addr = NULL;
1094
1095         memset(&params, 0, sizeof(params));
1096
1097         if (!info->attrs[NL80211_ATTR_KEY_CIPHER])
1098                 return -EINVAL;
1099
1100         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
1101                 params.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
1102                 params.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
1103         }
1104
1105         if (info->attrs[NL80211_ATTR_KEY_IDX])
1106                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1107
1108         params.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
1109
1110         if (info->attrs[NL80211_ATTR_MAC])
1111                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1112
1113         if (key_idx > 5)
1114                 return -EINVAL;
1115
1116         /*
1117          * Disallow pairwise keys with non-zero index unless it's WEP
1118          * (because current deployments use pairwise WEP keys with
1119          * non-zero indizes but 802.11i clearly specifies to use zero)
1120          */
1121         if (mac_addr && key_idx &&
1122             params.cipher != WLAN_CIPHER_SUITE_WEP40 &&
1123             params.cipher != WLAN_CIPHER_SUITE_WEP104)
1124                 return -EINVAL;
1125
1126         /* TODO: add definitions for the lengths to linux/ieee80211.h */
1127         switch (params.cipher) {
1128         case WLAN_CIPHER_SUITE_WEP40:
1129                 if (params.key_len != 5)
1130                         return -EINVAL;
1131                 break;
1132         case WLAN_CIPHER_SUITE_TKIP:
1133                 if (params.key_len != 32)
1134                         return -EINVAL;
1135                 break;
1136         case WLAN_CIPHER_SUITE_CCMP:
1137                 if (params.key_len != 16)
1138                         return -EINVAL;
1139                 break;
1140         case WLAN_CIPHER_SUITE_WEP104:
1141                 if (params.key_len != 13)
1142                         return -EINVAL;
1143                 break;
1144         case WLAN_CIPHER_SUITE_AES_CMAC:
1145                 if (params.key_len != 16)
1146                         return -EINVAL;
1147                 break;
1148         default:
1149                 return -EINVAL;
1150         }
1151
1152         rtnl_lock();
1153
1154         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1155         if (err)
1156                 goto unlock_rtnl;
1157
1158         for (i = 0; i < drv->wiphy.n_cipher_suites; i++)
1159                 if (params.cipher == drv->wiphy.cipher_suites[i])
1160                         break;
1161         if (i == drv->wiphy.n_cipher_suites) {
1162                 err = -EINVAL;
1163                 goto out;
1164         }
1165
1166         if (!drv->ops->add_key) {
1167                 err = -EOPNOTSUPP;
1168                 goto out;
1169         }
1170
1171         err = drv->ops->add_key(&drv->wiphy, dev, key_idx, mac_addr, &params);
1172
1173  out:
1174         cfg80211_put_dev(drv);
1175         dev_put(dev);
1176  unlock_rtnl:
1177         rtnl_unlock();
1178
1179         return err;
1180 }
1181
1182 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1183 {
1184         struct cfg80211_registered_device *drv;
1185         int err;
1186         struct net_device *dev;
1187         u8 key_idx = 0;
1188         u8 *mac_addr = NULL;
1189
1190         if (info->attrs[NL80211_ATTR_KEY_IDX])
1191                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1192
1193         if (key_idx > 5)
1194                 return -EINVAL;
1195
1196         if (info->attrs[NL80211_ATTR_MAC])
1197                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1198
1199         rtnl_lock();
1200
1201         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1202         if (err)
1203                 goto unlock_rtnl;
1204
1205         if (!drv->ops->del_key) {
1206                 err = -EOPNOTSUPP;
1207                 goto out;
1208         }
1209
1210         err = drv->ops->del_key(&drv->wiphy, dev, key_idx, mac_addr);
1211
1212  out:
1213         cfg80211_put_dev(drv);
1214         dev_put(dev);
1215
1216  unlock_rtnl:
1217         rtnl_unlock();
1218
1219         return err;
1220 }
1221
1222 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1223 {
1224         int (*call)(struct wiphy *wiphy, struct net_device *dev,
1225                     struct beacon_parameters *info);
1226         struct cfg80211_registered_device *drv;
1227         int err;
1228         struct net_device *dev;
1229         struct beacon_parameters params;
1230         int haveinfo = 0;
1231
1232         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1233                 return -EINVAL;
1234
1235         rtnl_lock();
1236
1237         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1238         if (err)
1239                 goto unlock_rtnl;
1240
1241         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1242                 err = -EOPNOTSUPP;
1243                 goto out;
1244         }
1245
1246         switch (info->genlhdr->cmd) {
1247         case NL80211_CMD_NEW_BEACON:
1248                 /* these are required for NEW_BEACON */
1249                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1250                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1251                     !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1252                         err = -EINVAL;
1253                         goto out;
1254                 }
1255
1256                 call = drv->ops->add_beacon;
1257                 break;
1258         case NL80211_CMD_SET_BEACON:
1259                 call = drv->ops->set_beacon;
1260                 break;
1261         default:
1262                 WARN_ON(1);
1263                 err = -EOPNOTSUPP;
1264                 goto out;
1265         }
1266
1267         if (!call) {
1268                 err = -EOPNOTSUPP;
1269                 goto out;
1270         }
1271
1272         memset(&params, 0, sizeof(params));
1273
1274         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1275                 params.interval =
1276                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1277                 haveinfo = 1;
1278         }
1279
1280         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1281                 params.dtim_period =
1282                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1283                 haveinfo = 1;
1284         }
1285
1286         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1287                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1288                 params.head_len =
1289                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1290                 haveinfo = 1;
1291         }
1292
1293         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1294                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1295                 params.tail_len =
1296                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1297                 haveinfo = 1;
1298         }
1299
1300         if (!haveinfo) {
1301                 err = -EINVAL;
1302                 goto out;
1303         }
1304
1305         err = call(&drv->wiphy, dev, &params);
1306
1307  out:
1308         cfg80211_put_dev(drv);
1309         dev_put(dev);
1310  unlock_rtnl:
1311         rtnl_unlock();
1312
1313         return err;
1314 }
1315
1316 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1317 {
1318         struct cfg80211_registered_device *drv;
1319         int err;
1320         struct net_device *dev;
1321
1322         rtnl_lock();
1323
1324         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1325         if (err)
1326                 goto unlock_rtnl;
1327
1328         if (!drv->ops->del_beacon) {
1329                 err = -EOPNOTSUPP;
1330                 goto out;
1331         }
1332
1333         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1334                 err = -EOPNOTSUPP;
1335                 goto out;
1336         }
1337         err = drv->ops->del_beacon(&drv->wiphy, dev);
1338
1339  out:
1340         cfg80211_put_dev(drv);
1341         dev_put(dev);
1342  unlock_rtnl:
1343         rtnl_unlock();
1344
1345         return err;
1346 }
1347
1348 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1349         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1350         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1351         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1352 };
1353
1354 static int parse_station_flags(struct nlattr *nla, u32 *staflags)
1355 {
1356         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1357         int flag;
1358
1359         *staflags = 0;
1360
1361         if (!nla)
1362                 return 0;
1363
1364         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1365                              nla, sta_flags_policy))
1366                 return -EINVAL;
1367
1368         *staflags = STATION_FLAG_CHANGED;
1369
1370         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1371                 if (flags[flag])
1372                         *staflags |= (1<<flag);
1373
1374         return 0;
1375 }
1376
1377 static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1378 {
1379         int modulation, streams, bitrate;
1380
1381         if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1382                 return rate->legacy;
1383
1384         /* the formula below does only work for MCS values smaller than 32 */
1385         if (rate->mcs >= 32)
1386                 return 0;
1387
1388         modulation = rate->mcs & 7;
1389         streams = (rate->mcs >> 3) + 1;
1390
1391         bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1392                         13500000 : 6500000;
1393
1394         if (modulation < 4)
1395                 bitrate *= (modulation + 1);
1396         else if (modulation == 4)
1397                 bitrate *= (modulation + 2);
1398         else
1399                 bitrate *= (modulation + 3);
1400
1401         bitrate *= streams;
1402
1403         if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1404                 bitrate = (bitrate / 9) * 10;
1405
1406         /* do NOT round down here */
1407         return (bitrate + 50000) / 100000;
1408 }
1409
1410 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1411                                 int flags, struct net_device *dev,
1412                                 u8 *mac_addr, struct station_info *sinfo)
1413 {
1414         void *hdr;
1415         struct nlattr *sinfoattr, *txrate;
1416         u16 bitrate;
1417
1418         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1419         if (!hdr)
1420                 return -1;
1421
1422         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1423         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1424
1425         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1426         if (!sinfoattr)
1427                 goto nla_put_failure;
1428         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1429                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1430                             sinfo->inactive_time);
1431         if (sinfo->filled & STATION_INFO_RX_BYTES)
1432                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1433                             sinfo->rx_bytes);
1434         if (sinfo->filled & STATION_INFO_TX_BYTES)
1435                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1436                             sinfo->tx_bytes);
1437         if (sinfo->filled & STATION_INFO_LLID)
1438                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1439                             sinfo->llid);
1440         if (sinfo->filled & STATION_INFO_PLID)
1441                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1442                             sinfo->plid);
1443         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1444                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1445                             sinfo->plink_state);
1446         if (sinfo->filled & STATION_INFO_SIGNAL)
1447                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1448                            sinfo->signal);
1449         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1450                 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1451                 if (!txrate)
1452                         goto nla_put_failure;
1453
1454                 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1455                 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1456                 if (bitrate > 0)
1457                         NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1458
1459                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1460                         NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1461                                     sinfo->txrate.mcs);
1462                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1463                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1464                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1465                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1466
1467                 nla_nest_end(msg, txrate);
1468         }
1469         if (sinfo->filled & STATION_INFO_RX_PACKETS)
1470                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1471                             sinfo->rx_packets);
1472         if (sinfo->filled & STATION_INFO_TX_PACKETS)
1473                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1474                             sinfo->tx_packets);
1475         nla_nest_end(msg, sinfoattr);
1476
1477         return genlmsg_end(msg, hdr);
1478
1479  nla_put_failure:
1480         genlmsg_cancel(msg, hdr);
1481         return -EMSGSIZE;
1482 }
1483
1484 static int nl80211_dump_station(struct sk_buff *skb,
1485                                 struct netlink_callback *cb)
1486 {
1487         struct station_info sinfo;
1488         struct cfg80211_registered_device *dev;
1489         struct net_device *netdev;
1490         u8 mac_addr[ETH_ALEN];
1491         int ifidx = cb->args[0];
1492         int sta_idx = cb->args[1];
1493         int err;
1494
1495         if (!ifidx) {
1496                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1497                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1498                                   nl80211_policy);
1499                 if (err)
1500                         return err;
1501
1502                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1503                         return -EINVAL;
1504
1505                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1506                 if (!ifidx)
1507                         return -EINVAL;
1508         }
1509
1510         rtnl_lock();
1511
1512         netdev = __dev_get_by_index(&init_net, ifidx);
1513         if (!netdev) {
1514                 err = -ENODEV;
1515                 goto out_rtnl;
1516         }
1517
1518         dev = cfg80211_get_dev_from_ifindex(ifidx);
1519         if (IS_ERR(dev)) {
1520                 err = PTR_ERR(dev);
1521                 goto out_rtnl;
1522         }
1523
1524         if (!dev->ops->dump_station) {
1525                 err = -EOPNOTSUPP;
1526                 goto out_err;
1527         }
1528
1529         while (1) {
1530                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1531                                              mac_addr, &sinfo);
1532                 if (err == -ENOENT)
1533                         break;
1534                 if (err)
1535                         goto out_err;
1536
1537                 if (nl80211_send_station(skb,
1538                                 NETLINK_CB(cb->skb).pid,
1539                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1540                                 netdev, mac_addr,
1541                                 &sinfo) < 0)
1542                         goto out;
1543
1544                 sta_idx++;
1545         }
1546
1547
1548  out:
1549         cb->args[1] = sta_idx;
1550         err = skb->len;
1551  out_err:
1552         cfg80211_put_dev(dev);
1553  out_rtnl:
1554         rtnl_unlock();
1555
1556         return err;
1557 }
1558
1559 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1560 {
1561         struct cfg80211_registered_device *drv;
1562         int err;
1563         struct net_device *dev;
1564         struct station_info sinfo;
1565         struct sk_buff *msg;
1566         u8 *mac_addr = NULL;
1567
1568         memset(&sinfo, 0, sizeof(sinfo));
1569
1570         if (!info->attrs[NL80211_ATTR_MAC])
1571                 return -EINVAL;
1572
1573         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1574
1575         rtnl_lock();
1576
1577         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1578         if (err)
1579                 goto out_rtnl;
1580
1581         if (!drv->ops->get_station) {
1582                 err = -EOPNOTSUPP;
1583                 goto out;
1584         }
1585
1586         err = drv->ops->get_station(&drv->wiphy, dev, mac_addr, &sinfo);
1587         if (err)
1588                 goto out;
1589
1590         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1591         if (!msg)
1592                 goto out;
1593
1594         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1595                                  dev, mac_addr, &sinfo) < 0)
1596                 goto out_free;
1597
1598         err = genlmsg_unicast(msg, info->snd_pid);
1599         goto out;
1600
1601  out_free:
1602         nlmsg_free(msg);
1603  out:
1604         cfg80211_put_dev(drv);
1605         dev_put(dev);
1606  out_rtnl:
1607         rtnl_unlock();
1608
1609         return err;
1610 }
1611
1612 /*
1613  * Get vlan interface making sure it is on the right wiphy.
1614  */
1615 static int get_vlan(struct nlattr *vlanattr,
1616                     struct cfg80211_registered_device *rdev,
1617                     struct net_device **vlan)
1618 {
1619         *vlan = NULL;
1620
1621         if (vlanattr) {
1622                 *vlan = dev_get_by_index(&init_net, nla_get_u32(vlanattr));
1623                 if (!*vlan)
1624                         return -ENODEV;
1625                 if (!(*vlan)->ieee80211_ptr)
1626                         return -EINVAL;
1627                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1628                         return -EINVAL;
1629         }
1630         return 0;
1631 }
1632
1633 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1634 {
1635         struct cfg80211_registered_device *drv;
1636         int err;
1637         struct net_device *dev;
1638         struct station_parameters params;
1639         u8 *mac_addr = NULL;
1640
1641         memset(&params, 0, sizeof(params));
1642
1643         params.listen_interval = -1;
1644
1645         if (info->attrs[NL80211_ATTR_STA_AID])
1646                 return -EINVAL;
1647
1648         if (!info->attrs[NL80211_ATTR_MAC])
1649                 return -EINVAL;
1650
1651         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1652
1653         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1654                 params.supported_rates =
1655                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1656                 params.supported_rates_len =
1657                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1658         }
1659
1660         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1661                 params.listen_interval =
1662                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1663
1664         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1665                 params.ht_capa =
1666                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1667
1668         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1669                                 &params.station_flags))
1670                 return -EINVAL;
1671
1672         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1673                 params.plink_action =
1674                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1675
1676         rtnl_lock();
1677
1678         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1679         if (err)
1680                 goto out_rtnl;
1681
1682         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1683         if (err)
1684                 goto out;
1685
1686         if (!drv->ops->change_station) {
1687                 err = -EOPNOTSUPP;
1688                 goto out;
1689         }
1690
1691         err = drv->ops->change_station(&drv->wiphy, dev, mac_addr, &params);
1692
1693  out:
1694         if (params.vlan)
1695                 dev_put(params.vlan);
1696         cfg80211_put_dev(drv);
1697         dev_put(dev);
1698  out_rtnl:
1699         rtnl_unlock();
1700
1701         return err;
1702 }
1703
1704 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1705 {
1706         struct cfg80211_registered_device *drv;
1707         int err;
1708         struct net_device *dev;
1709         struct station_parameters params;
1710         u8 *mac_addr = NULL;
1711
1712         memset(&params, 0, sizeof(params));
1713
1714         if (!info->attrs[NL80211_ATTR_MAC])
1715                 return -EINVAL;
1716
1717         if (!info->attrs[NL80211_ATTR_STA_AID])
1718                 return -EINVAL;
1719
1720         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1721                 return -EINVAL;
1722
1723         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1724                 return -EINVAL;
1725
1726         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1727         params.supported_rates =
1728                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1729         params.supported_rates_len =
1730                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1731         params.listen_interval =
1732                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1733         params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1734         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1735                 params.ht_capa =
1736                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1737
1738         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1739                                 &params.station_flags))
1740                 return -EINVAL;
1741
1742         rtnl_lock();
1743
1744         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1745         if (err)
1746                 goto out_rtnl;
1747
1748         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1749         if (err)
1750                 goto out;
1751
1752         if (!drv->ops->add_station) {
1753                 err = -EOPNOTSUPP;
1754                 goto out;
1755         }
1756
1757         if (!netif_running(dev)) {
1758                 err = -ENETDOWN;
1759                 goto out;
1760         }
1761
1762         err = drv->ops->add_station(&drv->wiphy, dev, mac_addr, &params);
1763
1764  out:
1765         if (params.vlan)
1766                 dev_put(params.vlan);
1767         cfg80211_put_dev(drv);
1768         dev_put(dev);
1769  out_rtnl:
1770         rtnl_unlock();
1771
1772         return err;
1773 }
1774
1775 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
1776 {
1777         struct cfg80211_registered_device *drv;
1778         int err;
1779         struct net_device *dev;
1780         u8 *mac_addr = NULL;
1781
1782         if (info->attrs[NL80211_ATTR_MAC])
1783                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1784
1785         rtnl_lock();
1786
1787         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1788         if (err)
1789                 goto out_rtnl;
1790
1791         if (!drv->ops->del_station) {
1792                 err = -EOPNOTSUPP;
1793                 goto out;
1794         }
1795
1796         err = drv->ops->del_station(&drv->wiphy, dev, mac_addr);
1797
1798  out:
1799         cfg80211_put_dev(drv);
1800         dev_put(dev);
1801  out_rtnl:
1802         rtnl_unlock();
1803
1804         return err;
1805 }
1806
1807 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
1808                                 int flags, struct net_device *dev,
1809                                 u8 *dst, u8 *next_hop,
1810                                 struct mpath_info *pinfo)
1811 {
1812         void *hdr;
1813         struct nlattr *pinfoattr;
1814
1815         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1816         if (!hdr)
1817                 return -1;
1818
1819         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1820         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
1821         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
1822
1823         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
1824         if (!pinfoattr)
1825                 goto nla_put_failure;
1826         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
1827                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
1828                             pinfo->frame_qlen);
1829         if (pinfo->filled & MPATH_INFO_DSN)
1830                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
1831                             pinfo->dsn);
1832         if (pinfo->filled & MPATH_INFO_METRIC)
1833                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
1834                             pinfo->metric);
1835         if (pinfo->filled & MPATH_INFO_EXPTIME)
1836                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
1837                             pinfo->exptime);
1838         if (pinfo->filled & MPATH_INFO_FLAGS)
1839                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
1840                             pinfo->flags);
1841         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
1842                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
1843                             pinfo->discovery_timeout);
1844         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
1845                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
1846                             pinfo->discovery_retries);
1847
1848         nla_nest_end(msg, pinfoattr);
1849
1850         return genlmsg_end(msg, hdr);
1851
1852  nla_put_failure:
1853         genlmsg_cancel(msg, hdr);
1854         return -EMSGSIZE;
1855 }
1856
1857 static int nl80211_dump_mpath(struct sk_buff *skb,
1858                               struct netlink_callback *cb)
1859 {
1860         struct mpath_info pinfo;
1861         struct cfg80211_registered_device *dev;
1862         struct net_device *netdev;
1863         u8 dst[ETH_ALEN];
1864         u8 next_hop[ETH_ALEN];
1865         int ifidx = cb->args[0];
1866         int path_idx = cb->args[1];
1867         int err;
1868
1869         if (!ifidx) {
1870                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1871                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1872                                   nl80211_policy);
1873                 if (err)
1874                         return err;
1875
1876                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1877                         return -EINVAL;
1878
1879                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1880                 if (!ifidx)
1881                         return -EINVAL;
1882         }
1883
1884         rtnl_lock();
1885
1886         netdev = __dev_get_by_index(&init_net, ifidx);
1887         if (!netdev) {
1888                 err = -ENODEV;
1889                 goto out_rtnl;
1890         }
1891
1892         dev = cfg80211_get_dev_from_ifindex(ifidx);
1893         if (IS_ERR(dev)) {
1894                 err = PTR_ERR(dev);
1895                 goto out_rtnl;
1896         }
1897
1898         if (!dev->ops->dump_mpath) {
1899                 err = -EOPNOTSUPP;
1900                 goto out_err;
1901         }
1902
1903         if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
1904                 err = -EOPNOTSUPP;
1905                 goto out;
1906         }
1907
1908         while (1) {
1909                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
1910                                            dst, next_hop, &pinfo);
1911                 if (err == -ENOENT)
1912                         break;
1913                 if (err)
1914                         goto out_err;
1915
1916                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
1917                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
1918                                        netdev, dst, next_hop,
1919                                        &pinfo) < 0)
1920                         goto out;
1921
1922                 path_idx++;
1923         }
1924
1925
1926  out:
1927         cb->args[1] = path_idx;
1928         err = skb->len;
1929  out_err:
1930         cfg80211_put_dev(dev);
1931  out_rtnl:
1932         rtnl_unlock();
1933
1934         return err;
1935 }
1936
1937 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
1938 {
1939         struct cfg80211_registered_device *drv;
1940         int err;
1941         struct net_device *dev;
1942         struct mpath_info pinfo;
1943         struct sk_buff *msg;
1944         u8 *dst = NULL;
1945         u8 next_hop[ETH_ALEN];
1946
1947         memset(&pinfo, 0, sizeof(pinfo));
1948
1949         if (!info->attrs[NL80211_ATTR_MAC])
1950                 return -EINVAL;
1951
1952         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1953
1954         rtnl_lock();
1955
1956         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1957         if (err)
1958                 goto out_rtnl;
1959
1960         if (!drv->ops->get_mpath) {
1961                 err = -EOPNOTSUPP;
1962                 goto out;
1963         }
1964
1965         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
1966                 err = -EOPNOTSUPP;
1967                 goto out;
1968         }
1969
1970         err = drv->ops->get_mpath(&drv->wiphy, dev, dst, next_hop, &pinfo);
1971         if (err)
1972                 goto out;
1973
1974         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1975         if (!msg)
1976                 goto out;
1977
1978         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
1979                                  dev, dst, next_hop, &pinfo) < 0)
1980                 goto out_free;
1981
1982         err = genlmsg_unicast(msg, info->snd_pid);
1983         goto out;
1984
1985  out_free:
1986         nlmsg_free(msg);
1987  out:
1988         cfg80211_put_dev(drv);
1989         dev_put(dev);
1990  out_rtnl:
1991         rtnl_unlock();
1992
1993         return err;
1994 }
1995
1996 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
1997 {
1998         struct cfg80211_registered_device *drv;
1999         int err;
2000         struct net_device *dev;
2001         u8 *dst = NULL;
2002         u8 *next_hop = NULL;
2003
2004         if (!info->attrs[NL80211_ATTR_MAC])
2005                 return -EINVAL;
2006
2007         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2008                 return -EINVAL;
2009
2010         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2011         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2012
2013         rtnl_lock();
2014
2015         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2016         if (err)
2017                 goto out_rtnl;
2018
2019         if (!drv->ops->change_mpath) {
2020                 err = -EOPNOTSUPP;
2021                 goto out;
2022         }
2023
2024         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2025                 err = -EOPNOTSUPP;
2026                 goto out;
2027         }
2028
2029         if (!netif_running(dev)) {
2030                 err = -ENETDOWN;
2031                 goto out;
2032         }
2033
2034         err = drv->ops->change_mpath(&drv->wiphy, dev, dst, next_hop);
2035
2036  out:
2037         cfg80211_put_dev(drv);
2038         dev_put(dev);
2039  out_rtnl:
2040         rtnl_unlock();
2041
2042         return err;
2043 }
2044 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2045 {
2046         struct cfg80211_registered_device *drv;
2047         int err;
2048         struct net_device *dev;
2049         u8 *dst = NULL;
2050         u8 *next_hop = NULL;
2051
2052         if (!info->attrs[NL80211_ATTR_MAC])
2053                 return -EINVAL;
2054
2055         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2056                 return -EINVAL;
2057
2058         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2059         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2060
2061         rtnl_lock();
2062
2063         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2064         if (err)
2065                 goto out_rtnl;
2066
2067         if (!drv->ops->add_mpath) {
2068                 err = -EOPNOTSUPP;
2069                 goto out;
2070         }
2071
2072         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2073                 err = -EOPNOTSUPP;
2074                 goto out;
2075         }
2076
2077         if (!netif_running(dev)) {
2078                 err = -ENETDOWN;
2079                 goto out;
2080         }
2081
2082         err = drv->ops->add_mpath(&drv->wiphy, dev, dst, next_hop);
2083
2084  out:
2085         cfg80211_put_dev(drv);
2086         dev_put(dev);
2087  out_rtnl:
2088         rtnl_unlock();
2089
2090         return err;
2091 }
2092
2093 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2094 {
2095         struct cfg80211_registered_device *drv;
2096         int err;
2097         struct net_device *dev;
2098         u8 *dst = NULL;
2099
2100         if (info->attrs[NL80211_ATTR_MAC])
2101                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2102
2103         rtnl_lock();
2104
2105         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2106         if (err)
2107                 goto out_rtnl;
2108
2109         if (!drv->ops->del_mpath) {
2110                 err = -EOPNOTSUPP;
2111                 goto out;
2112         }
2113
2114         err = drv->ops->del_mpath(&drv->wiphy, dev, dst);
2115
2116  out:
2117         cfg80211_put_dev(drv);
2118         dev_put(dev);
2119  out_rtnl:
2120         rtnl_unlock();
2121
2122         return err;
2123 }
2124
2125 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2126 {
2127         struct cfg80211_registered_device *drv;
2128         int err;
2129         struct net_device *dev;
2130         struct bss_parameters params;
2131
2132         memset(&params, 0, sizeof(params));
2133         /* default to not changing parameters */
2134         params.use_cts_prot = -1;
2135         params.use_short_preamble = -1;
2136         params.use_short_slot_time = -1;
2137
2138         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2139                 params.use_cts_prot =
2140                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2141         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2142                 params.use_short_preamble =
2143                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2144         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2145                 params.use_short_slot_time =
2146                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2147         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2148                 params.basic_rates =
2149                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2150                 params.basic_rates_len =
2151                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2152         }
2153
2154         rtnl_lock();
2155
2156         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2157         if (err)
2158                 goto out_rtnl;
2159
2160         if (!drv->ops->change_bss) {
2161                 err = -EOPNOTSUPP;
2162                 goto out;
2163         }
2164
2165         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2166                 err = -EOPNOTSUPP;
2167                 goto out;
2168         }
2169
2170         err = drv->ops->change_bss(&drv->wiphy, dev, &params);
2171
2172  out:
2173         cfg80211_put_dev(drv);
2174         dev_put(dev);
2175  out_rtnl:
2176         rtnl_unlock();
2177
2178         return err;
2179 }
2180
2181 static const struct nla_policy
2182         reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2183         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
2184         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
2185         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
2186         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
2187         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
2188         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
2189 };
2190
2191 static int parse_reg_rule(struct nlattr *tb[],
2192         struct ieee80211_reg_rule *reg_rule)
2193 {
2194         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2195         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2196
2197         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2198                 return -EINVAL;
2199         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2200                 return -EINVAL;
2201         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2202                 return -EINVAL;
2203         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2204                 return -EINVAL;
2205         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2206                 return -EINVAL;
2207
2208         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2209
2210         freq_range->start_freq_khz =
2211                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2212         freq_range->end_freq_khz =
2213                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2214         freq_range->max_bandwidth_khz =
2215                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2216
2217         power_rule->max_eirp =
2218                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2219
2220         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2221                 power_rule->max_antenna_gain =
2222                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2223
2224         return 0;
2225 }
2226
2227 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2228 {
2229         int r;
2230         char *data = NULL;
2231
2232         /*
2233          * You should only get this when cfg80211 hasn't yet initialized
2234          * completely when built-in to the kernel right between the time
2235          * window between nl80211_init() and regulatory_init(), if that is
2236          * even possible.
2237          */
2238         mutex_lock(&cfg80211_mutex);
2239         if (unlikely(!cfg80211_regdomain)) {
2240                 mutex_unlock(&cfg80211_mutex);
2241                 return -EINPROGRESS;
2242         }
2243         mutex_unlock(&cfg80211_mutex);
2244
2245         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2246                 return -EINVAL;
2247
2248         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2249
2250 #ifdef CONFIG_WIRELESS_OLD_REGULATORY
2251         /* We ignore world regdom requests with the old regdom setup */
2252         if (is_world_regdom(data))
2253                 return -EINVAL;
2254 #endif
2255
2256         r = regulatory_hint_user(data);
2257
2258         return r;
2259 }
2260
2261 static int nl80211_get_mesh_params(struct sk_buff *skb,
2262         struct genl_info *info)
2263 {
2264         struct cfg80211_registered_device *drv;
2265         struct mesh_config cur_params;
2266         int err;
2267         struct net_device *dev;
2268         void *hdr;
2269         struct nlattr *pinfoattr;
2270         struct sk_buff *msg;
2271
2272         rtnl_lock();
2273
2274         /* Look up our device */
2275         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2276         if (err)
2277                 goto out_rtnl;
2278
2279         if (!drv->ops->get_mesh_params) {
2280                 err = -EOPNOTSUPP;
2281                 goto out;
2282         }
2283
2284         /* Get the mesh params */
2285         err = drv->ops->get_mesh_params(&drv->wiphy, dev, &cur_params);
2286         if (err)
2287                 goto out;
2288
2289         /* Draw up a netlink message to send back */
2290         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2291         if (!msg) {
2292                 err = -ENOBUFS;
2293                 goto out;
2294         }
2295         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2296                              NL80211_CMD_GET_MESH_PARAMS);
2297         if (!hdr)
2298                 goto nla_put_failure;
2299         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2300         if (!pinfoattr)
2301                 goto nla_put_failure;
2302         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2303         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2304                         cur_params.dot11MeshRetryTimeout);
2305         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2306                         cur_params.dot11MeshConfirmTimeout);
2307         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2308                         cur_params.dot11MeshHoldingTimeout);
2309         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2310                         cur_params.dot11MeshMaxPeerLinks);
2311         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2312                         cur_params.dot11MeshMaxRetries);
2313         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2314                         cur_params.dot11MeshTTL);
2315         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2316                         cur_params.auto_open_plinks);
2317         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2318                         cur_params.dot11MeshHWMPmaxPREQretries);
2319         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2320                         cur_params.path_refresh_time);
2321         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2322                         cur_params.min_discovery_timeout);
2323         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2324                         cur_params.dot11MeshHWMPactivePathTimeout);
2325         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2326                         cur_params.dot11MeshHWMPpreqMinInterval);
2327         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2328                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2329         nla_nest_end(msg, pinfoattr);
2330         genlmsg_end(msg, hdr);
2331         err = genlmsg_unicast(msg, info->snd_pid);
2332         goto out;
2333
2334  nla_put_failure:
2335         genlmsg_cancel(msg, hdr);
2336         err = -EMSGSIZE;
2337  out:
2338         /* Cleanup */
2339         cfg80211_put_dev(drv);
2340         dev_put(dev);
2341  out_rtnl:
2342         rtnl_unlock();
2343
2344         return err;
2345 }
2346
2347 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2348 do {\
2349         if (table[attr_num]) {\
2350                 cfg.param = nla_fn(table[attr_num]); \
2351                 mask |= (1 << (attr_num - 1)); \
2352         } \
2353 } while (0);\
2354
2355 static struct nla_policy
2356 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2357         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2358         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2359         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2360         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2361         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2362         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2363         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2364
2365         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2366         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2367         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2368         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2369         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2370         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2371 };
2372
2373 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2374 {
2375         int err;
2376         u32 mask;
2377         struct cfg80211_registered_device *drv;
2378         struct net_device *dev;
2379         struct mesh_config cfg;
2380         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2381         struct nlattr *parent_attr;
2382
2383         parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2384         if (!parent_attr)
2385                 return -EINVAL;
2386         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2387                         parent_attr, nl80211_meshconf_params_policy))
2388                 return -EINVAL;
2389
2390         rtnl_lock();
2391
2392         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2393         if (err)
2394                 goto out_rtnl;
2395
2396         if (!drv->ops->set_mesh_params) {
2397                 err = -EOPNOTSUPP;
2398                 goto out;
2399         }
2400
2401         /* This makes sure that there aren't more than 32 mesh config
2402          * parameters (otherwise our bitfield scheme would not work.) */
2403         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2404
2405         /* Fill in the params struct */
2406         mask = 0;
2407         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2408                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2409         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2410                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2411         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2412                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2413         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2414                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2415         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2416                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2417         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2418                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
2419         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2420                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2421         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2422                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2423                         nla_get_u8);
2424         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2425                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2426         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2427                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2428                         nla_get_u16);
2429         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2430                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2431                         nla_get_u32);
2432         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2433                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2434                         nla_get_u16);
2435         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2436                         dot11MeshHWMPnetDiameterTraversalTime,
2437                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2438                         nla_get_u16);
2439
2440         /* Apply changes */
2441         err = drv->ops->set_mesh_params(&drv->wiphy, dev, &cfg, mask);
2442
2443  out:
2444         /* cleanup */
2445         cfg80211_put_dev(drv);
2446         dev_put(dev);
2447  out_rtnl:
2448         rtnl_unlock();
2449
2450         return err;
2451 }
2452
2453 #undef FILL_IN_MESH_PARAM_IF_SET
2454
2455 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2456 {
2457         struct sk_buff *msg;
2458         void *hdr = NULL;
2459         struct nlattr *nl_reg_rules;
2460         unsigned int i;
2461         int err = -EINVAL;
2462
2463         mutex_lock(&cfg80211_mutex);
2464
2465         if (!cfg80211_regdomain)
2466                 goto out;
2467
2468         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2469         if (!msg) {
2470                 err = -ENOBUFS;
2471                 goto out;
2472         }
2473
2474         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2475                              NL80211_CMD_GET_REG);
2476         if (!hdr)
2477                 goto nla_put_failure;
2478
2479         NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2480                 cfg80211_regdomain->alpha2);
2481
2482         nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2483         if (!nl_reg_rules)
2484                 goto nla_put_failure;
2485
2486         for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2487                 struct nlattr *nl_reg_rule;
2488                 const struct ieee80211_reg_rule *reg_rule;
2489                 const struct ieee80211_freq_range *freq_range;
2490                 const struct ieee80211_power_rule *power_rule;
2491
2492                 reg_rule = &cfg80211_regdomain->reg_rules[i];
2493                 freq_range = &reg_rule->freq_range;
2494                 power_rule = &reg_rule->power_rule;
2495
2496                 nl_reg_rule = nla_nest_start(msg, i);
2497                 if (!nl_reg_rule)
2498                         goto nla_put_failure;
2499
2500                 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2501                         reg_rule->flags);
2502                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2503                         freq_range->start_freq_khz);
2504                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2505                         freq_range->end_freq_khz);
2506                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2507                         freq_range->max_bandwidth_khz);
2508                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2509                         power_rule->max_antenna_gain);
2510                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2511                         power_rule->max_eirp);
2512
2513                 nla_nest_end(msg, nl_reg_rule);
2514         }
2515
2516         nla_nest_end(msg, nl_reg_rules);
2517
2518         genlmsg_end(msg, hdr);
2519         err = genlmsg_unicast(msg, info->snd_pid);
2520         goto out;
2521
2522 nla_put_failure:
2523         genlmsg_cancel(msg, hdr);
2524         err = -EMSGSIZE;
2525 out:
2526         mutex_unlock(&cfg80211_mutex);
2527         return err;
2528 }
2529
2530 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2531 {
2532         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2533         struct nlattr *nl_reg_rule;
2534         char *alpha2 = NULL;
2535         int rem_reg_rules = 0, r = 0;
2536         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2537         struct ieee80211_regdomain *rd = NULL;
2538
2539         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2540                 return -EINVAL;
2541
2542         if (!info->attrs[NL80211_ATTR_REG_RULES])
2543                 return -EINVAL;
2544
2545         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2546
2547         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2548                         rem_reg_rules) {
2549                 num_rules++;
2550                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2551                         goto bad_reg;
2552         }
2553
2554         if (!reg_is_valid_request(alpha2))
2555                 return -EINVAL;
2556
2557         size_of_regd = sizeof(struct ieee80211_regdomain) +
2558                 (num_rules * sizeof(struct ieee80211_reg_rule));
2559
2560         rd = kzalloc(size_of_regd, GFP_KERNEL);
2561         if (!rd)
2562                 return -ENOMEM;
2563
2564         rd->n_reg_rules = num_rules;
2565         rd->alpha2[0] = alpha2[0];
2566         rd->alpha2[1] = alpha2[1];
2567
2568         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2569                         rem_reg_rules) {
2570                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2571                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2572                         reg_rule_policy);
2573                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2574                 if (r)
2575                         goto bad_reg;
2576
2577                 rule_idx++;
2578
2579                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES)
2580                         goto bad_reg;
2581         }
2582
2583         BUG_ON(rule_idx != num_rules);
2584
2585         mutex_lock(&cfg80211_mutex);
2586         r = set_regdom(rd);
2587         mutex_unlock(&cfg80211_mutex);
2588         return r;
2589
2590  bad_reg:
2591         kfree(rd);
2592         return -EINVAL;
2593 }
2594
2595 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2596 {
2597         struct cfg80211_registered_device *drv;
2598         struct net_device *dev;
2599         struct cfg80211_scan_request *request;
2600         struct cfg80211_ssid *ssid;
2601         struct ieee80211_channel *channel;
2602         struct nlattr *attr;
2603         struct wiphy *wiphy;
2604         int err, tmp, n_ssids = 0, n_channels = 0, i;
2605         enum ieee80211_band band;
2606         size_t ie_len;
2607
2608         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2609                 return -EINVAL;
2610
2611         rtnl_lock();
2612
2613         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2614         if (err)
2615                 goto out_rtnl;
2616
2617         wiphy = &drv->wiphy;
2618
2619         if (!drv->ops->scan) {
2620                 err = -EOPNOTSUPP;
2621                 goto out;
2622         }
2623
2624         if (!netif_running(dev)) {
2625                 err = -ENETDOWN;
2626                 goto out;
2627         }
2628
2629         if (drv->scan_req) {
2630                 err = -EBUSY;
2631                 goto out;
2632         }
2633
2634         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2635                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp)
2636                         n_channels++;
2637                 if (!n_channels) {
2638                         err = -EINVAL;
2639                         goto out;
2640                 }
2641         } else {
2642                 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2643                         if (wiphy->bands[band])
2644                                 n_channels += wiphy->bands[band]->n_channels;
2645         }
2646
2647         if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2648                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2649                         n_ssids++;
2650
2651         if (n_ssids > wiphy->max_scan_ssids) {
2652                 err = -EINVAL;
2653                 goto out;
2654         }
2655
2656         if (info->attrs[NL80211_ATTR_IE])
2657                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2658         else
2659                 ie_len = 0;
2660
2661         if (ie_len > wiphy->max_scan_ie_len) {
2662                 err = -EINVAL;
2663                 goto out;
2664         }
2665
2666         request = kzalloc(sizeof(*request)
2667                         + sizeof(*ssid) * n_ssids
2668                         + sizeof(channel) * n_channels
2669                         + ie_len, GFP_KERNEL);
2670         if (!request) {
2671                 err = -ENOMEM;
2672                 goto out;
2673         }
2674
2675         request->channels = (void *)((char *)request + sizeof(*request));
2676         request->n_channels = n_channels;
2677         if (n_ssids)
2678                 request->ssids = (void *)(request->channels + n_channels);
2679         request->n_ssids = n_ssids;
2680         if (ie_len) {
2681                 if (request->ssids)
2682                         request->ie = (void *)(request->ssids + n_ssids);
2683                 else
2684                         request->ie = (void *)(request->channels + n_channels);
2685         }
2686
2687         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2688                 /* user specified, bail out if channel not found */
2689                 request->n_channels = n_channels;
2690                 i = 0;
2691                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
2692                         request->channels[i] = ieee80211_get_channel(wiphy, nla_get_u32(attr));
2693                         if (!request->channels[i]) {
2694                                 err = -EINVAL;
2695                                 goto out_free;
2696                         }
2697                         i++;
2698                 }
2699         } else {
2700                 /* all channels */
2701                 i = 0;
2702                 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
2703                         int j;
2704                         if (!wiphy->bands[band])
2705                                 continue;
2706                         for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
2707                                 request->channels[i] = &wiphy->bands[band]->channels[j];
2708                                 i++;
2709                         }
2710                 }
2711         }
2712
2713         i = 0;
2714         if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
2715                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
2716                         if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
2717                                 err = -EINVAL;
2718                                 goto out_free;
2719                         }
2720                         memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2721                         request->ssids[i].ssid_len = nla_len(attr);
2722                         i++;
2723                 }
2724         }
2725
2726         if (info->attrs[NL80211_ATTR_IE]) {
2727                 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2728                 memcpy((void *)request->ie,
2729                        nla_data(info->attrs[NL80211_ATTR_IE]),
2730                        request->ie_len);
2731         }
2732
2733         request->ifidx = dev->ifindex;
2734         request->wiphy = &drv->wiphy;
2735
2736         drv->scan_req = request;
2737         err = drv->ops->scan(&drv->wiphy, dev, request);
2738
2739  out_free:
2740         if (err) {
2741                 drv->scan_req = NULL;
2742                 kfree(request);
2743         }
2744  out:
2745         cfg80211_put_dev(drv);
2746         dev_put(dev);
2747  out_rtnl:
2748         rtnl_unlock();
2749
2750         return err;
2751 }
2752
2753 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
2754                             struct cfg80211_registered_device *rdev,
2755                             struct net_device *dev,
2756                             struct cfg80211_bss *res)
2757 {
2758         void *hdr;
2759         struct nlattr *bss;
2760
2761         hdr = nl80211hdr_put(msg, pid, seq, flags,
2762                              NL80211_CMD_NEW_SCAN_RESULTS);
2763         if (!hdr)
2764                 return -1;
2765
2766         NLA_PUT_U32(msg, NL80211_ATTR_SCAN_GENERATION,
2767                     rdev->bss_generation);
2768         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2769
2770         bss = nla_nest_start(msg, NL80211_ATTR_BSS);
2771         if (!bss)
2772                 goto nla_put_failure;
2773         if (!is_zero_ether_addr(res->bssid))
2774                 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
2775         if (res->information_elements && res->len_information_elements)
2776                 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
2777                         res->len_information_elements,
2778                         res->information_elements);
2779         if (res->tsf)
2780                 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
2781         if (res->beacon_interval)
2782                 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
2783         NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
2784         NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
2785
2786         switch (rdev->wiphy.signal_type) {
2787         case CFG80211_SIGNAL_TYPE_MBM:
2788                 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
2789                 break;
2790         case CFG80211_SIGNAL_TYPE_UNSPEC:
2791                 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
2792                 break;
2793         default:
2794                 break;
2795         }
2796
2797         nla_nest_end(msg, bss);
2798
2799         return genlmsg_end(msg, hdr);
2800
2801  nla_put_failure:
2802         genlmsg_cancel(msg, hdr);
2803         return -EMSGSIZE;
2804 }
2805
2806 static int nl80211_dump_scan(struct sk_buff *skb,
2807                              struct netlink_callback *cb)
2808 {
2809         struct cfg80211_registered_device *dev;
2810         struct net_device *netdev;
2811         struct cfg80211_internal_bss *scan;
2812         int ifidx = cb->args[0];
2813         int start = cb->args[1], idx = 0;
2814         int err;
2815
2816         if (!ifidx) {
2817                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2818                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
2819                                   nl80211_policy);
2820                 if (err)
2821                         return err;
2822
2823                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2824                         return -EINVAL;
2825
2826                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2827                 if (!ifidx)
2828                         return -EINVAL;
2829                 cb->args[0] = ifidx;
2830         }
2831
2832         netdev = dev_get_by_index(&init_net, ifidx);
2833         if (!netdev)
2834                 return -ENODEV;
2835
2836         dev = cfg80211_get_dev_from_ifindex(ifidx);
2837         if (IS_ERR(dev)) {
2838                 err = PTR_ERR(dev);
2839                 goto out_put_netdev;
2840         }
2841
2842         spin_lock_bh(&dev->bss_lock);
2843         cfg80211_bss_expire(dev);
2844
2845         list_for_each_entry(scan, &dev->bss_list, list) {
2846                 if (++idx <= start)
2847                         continue;
2848                 if (nl80211_send_bss(skb,
2849                                 NETLINK_CB(cb->skb).pid,
2850                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2851                                 dev, netdev, &scan->pub) < 0) {
2852                         idx--;
2853                         goto out;
2854                 }
2855         }
2856
2857  out:
2858         spin_unlock_bh(&dev->bss_lock);
2859
2860         cb->args[1] = idx;
2861         err = skb->len;
2862         cfg80211_put_dev(dev);
2863  out_put_netdev:
2864         dev_put(netdev);
2865
2866         return err;
2867 }
2868
2869 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
2870 {
2871         return auth_type == NL80211_AUTHTYPE_OPEN_SYSTEM ||
2872                 auth_type == NL80211_AUTHTYPE_SHARED_KEY ||
2873                 auth_type == NL80211_AUTHTYPE_FT ||
2874                 auth_type == NL80211_AUTHTYPE_NETWORK_EAP;
2875 }
2876
2877 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
2878 {
2879         struct cfg80211_registered_device *drv;
2880         struct net_device *dev;
2881         struct cfg80211_auth_request req;
2882         struct wiphy *wiphy;
2883         int err;
2884
2885         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2886                 return -EINVAL;
2887
2888         if (!info->attrs[NL80211_ATTR_MAC])
2889                 return -EINVAL;
2890
2891         if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
2892                 return -EINVAL;
2893
2894         rtnl_lock();
2895
2896         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2897         if (err)
2898                 goto unlock_rtnl;
2899
2900         if (!drv->ops->auth) {
2901                 err = -EOPNOTSUPP;
2902                 goto out;
2903         }
2904
2905         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
2906                 err = -EOPNOTSUPP;
2907                 goto out;
2908         }
2909
2910         if (!netif_running(dev)) {
2911                 err = -ENETDOWN;
2912                 goto out;
2913         }
2914
2915         wiphy = &drv->wiphy;
2916         memset(&req, 0, sizeof(req));
2917
2918         req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2919
2920         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
2921                 req.chan = ieee80211_get_channel(
2922                         wiphy,
2923                         nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
2924                 if (!req.chan) {
2925                         err = -EINVAL;
2926                         goto out;
2927                 }
2928         }
2929
2930         if (info->attrs[NL80211_ATTR_SSID]) {
2931                 req.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2932                 req.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
2933         }
2934
2935         if (info->attrs[NL80211_ATTR_IE]) {
2936                 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
2937                 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2938         }
2939
2940         req.auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
2941         if (!nl80211_valid_auth_type(req.auth_type)) {
2942                 err = -EINVAL;
2943                 goto out;
2944         }
2945
2946         err = drv->ops->auth(&drv->wiphy, dev, &req);
2947
2948 out:
2949         cfg80211_put_dev(drv);
2950         dev_put(dev);
2951 unlock_rtnl:
2952         rtnl_unlock();
2953         return err;
2954 }
2955
2956 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
2957 {
2958         struct cfg80211_registered_device *drv;
2959         struct net_device *dev;
2960         struct cfg80211_assoc_request req;
2961         struct wiphy *wiphy;
2962         int err;
2963
2964         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2965                 return -EINVAL;
2966
2967         if (!info->attrs[NL80211_ATTR_MAC] ||
2968             !info->attrs[NL80211_ATTR_SSID])
2969                 return -EINVAL;
2970
2971         rtnl_lock();
2972
2973         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2974         if (err)
2975                 goto unlock_rtnl;
2976
2977         if (!drv->ops->assoc) {
2978                 err = -EOPNOTSUPP;
2979                 goto out;
2980         }
2981
2982         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
2983                 err = -EOPNOTSUPP;
2984                 goto out;
2985         }
2986
2987         if (!netif_running(dev)) {
2988                 err = -ENETDOWN;
2989                 goto out;
2990         }
2991
2992         wiphy = &drv->wiphy;
2993         memset(&req, 0, sizeof(req));
2994
2995         req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2996
2997         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
2998                 req.chan = ieee80211_get_channel(
2999                         wiphy,
3000                         nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3001                 if (!req.chan) {
3002                         err = -EINVAL;
3003                         goto out;
3004                 }
3005         }
3006
3007         req.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3008         req.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3009
3010         if (info->attrs[NL80211_ATTR_IE]) {
3011                 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3012                 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3013         }
3014
3015         err = drv->ops->assoc(&drv->wiphy, dev, &req);
3016
3017 out:
3018         cfg80211_put_dev(drv);
3019         dev_put(dev);
3020 unlock_rtnl:
3021         rtnl_unlock();
3022         return err;
3023 }
3024
3025 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3026 {
3027         struct cfg80211_registered_device *drv;
3028         struct net_device *dev;
3029         struct cfg80211_deauth_request req;
3030         struct wiphy *wiphy;
3031         int err;
3032
3033         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3034                 return -EINVAL;
3035
3036         if (!info->attrs[NL80211_ATTR_MAC])
3037                 return -EINVAL;
3038
3039         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3040                 return -EINVAL;
3041
3042         rtnl_lock();
3043
3044         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3045         if (err)
3046                 goto unlock_rtnl;
3047
3048         if (!drv->ops->deauth) {
3049                 err = -EOPNOTSUPP;
3050                 goto out;
3051         }
3052
3053         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3054                 err = -EOPNOTSUPP;
3055                 goto out;
3056         }
3057
3058         if (!netif_running(dev)) {
3059                 err = -ENETDOWN;
3060                 goto out;
3061         }
3062
3063         wiphy = &drv->wiphy;
3064         memset(&req, 0, sizeof(req));
3065
3066         req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3067
3068         req.reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3069         if (req.reason_code == 0) {
3070                 /* Reason Code 0 is reserved */
3071                 err = -EINVAL;
3072                 goto out;
3073         }
3074
3075         if (info->attrs[NL80211_ATTR_IE]) {
3076                 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3077                 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3078         }
3079
3080         err = drv->ops->deauth(&drv->wiphy, dev, &req);
3081
3082 out:
3083         cfg80211_put_dev(drv);
3084         dev_put(dev);
3085 unlock_rtnl:
3086         rtnl_unlock();
3087         return err;
3088 }
3089
3090 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3091 {
3092         struct cfg80211_registered_device *drv;
3093         struct net_device *dev;
3094         struct cfg80211_disassoc_request req;
3095         struct wiphy *wiphy;
3096         int err;
3097
3098         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3099                 return -EINVAL;
3100
3101         if (!info->attrs[NL80211_ATTR_MAC])
3102                 return -EINVAL;
3103
3104         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3105                 return -EINVAL;
3106
3107         rtnl_lock();
3108
3109         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3110         if (err)
3111                 goto unlock_rtnl;
3112
3113         if (!drv->ops->disassoc) {
3114                 err = -EOPNOTSUPP;
3115                 goto out;
3116         }
3117
3118         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3119                 err = -EOPNOTSUPP;
3120                 goto out;
3121         }
3122
3123         if (!netif_running(dev)) {
3124                 err = -ENETDOWN;
3125                 goto out;
3126         }
3127
3128         wiphy = &drv->wiphy;
3129         memset(&req, 0, sizeof(req));
3130
3131         req.peer_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3132
3133         req.reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3134         if (req.reason_code == 0) {
3135                 /* Reason Code 0 is reserved */
3136                 err = -EINVAL;
3137                 goto out;
3138         }
3139
3140         if (info->attrs[NL80211_ATTR_IE]) {
3141                 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3142                 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3143         }
3144
3145         err = drv->ops->disassoc(&drv->wiphy, dev, &req);
3146
3147 out:
3148         cfg80211_put_dev(drv);
3149         dev_put(dev);
3150 unlock_rtnl:
3151         rtnl_unlock();
3152         return err;
3153 }
3154
3155 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3156 {
3157         struct cfg80211_registered_device *drv;
3158         struct net_device *dev;
3159         struct cfg80211_ibss_params ibss;
3160         struct wiphy *wiphy;
3161         int err;
3162
3163         memset(&ibss, 0, sizeof(ibss));
3164
3165         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3166                 return -EINVAL;
3167
3168         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3169             !info->attrs[NL80211_ATTR_SSID] ||
3170             !nla_len(info->attrs[NL80211_ATTR_SSID]))
3171                 return -EINVAL;
3172
3173         ibss.beacon_interval = 100;
3174
3175         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3176                 ibss.beacon_interval =
3177                         nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3178                 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3179                         return -EINVAL;
3180         }
3181
3182         rtnl_lock();
3183
3184         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3185         if (err)
3186                 goto unlock_rtnl;
3187
3188         if (!drv->ops->join_ibss) {
3189                 err = -EOPNOTSUPP;
3190                 goto out;
3191         }
3192
3193         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3194                 err = -EOPNOTSUPP;
3195                 goto out;
3196         }
3197
3198         if (!netif_running(dev)) {
3199                 err = -ENETDOWN;
3200                 goto out;
3201         }
3202
3203         wiphy = &drv->wiphy;
3204
3205         if (info->attrs[NL80211_ATTR_MAC])
3206                 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3207         ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3208         ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3209
3210         if (info->attrs[NL80211_ATTR_IE]) {
3211                 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3212                 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3213         }
3214
3215         ibss.channel = ieee80211_get_channel(wiphy,
3216                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3217         if (!ibss.channel ||
3218             ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3219             ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3220                 err = -EINVAL;
3221                 goto out;
3222         }
3223
3224         ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3225
3226         err = cfg80211_join_ibss(drv, dev, &ibss);
3227
3228 out:
3229         cfg80211_put_dev(drv);
3230         dev_put(dev);
3231 unlock_rtnl:
3232         rtnl_unlock();
3233         return err;
3234 }
3235
3236 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3237 {
3238         struct cfg80211_registered_device *drv;
3239         struct net_device *dev;
3240         int err;
3241
3242         rtnl_lock();
3243
3244         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
3245         if (err)
3246                 goto unlock_rtnl;
3247
3248         if (!drv->ops->leave_ibss) {
3249                 err = -EOPNOTSUPP;
3250                 goto out;
3251         }
3252
3253         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3254                 err = -EOPNOTSUPP;
3255                 goto out;
3256         }
3257
3258         if (!netif_running(dev)) {
3259                 err = -ENETDOWN;
3260                 goto out;
3261         }
3262
3263         err = cfg80211_leave_ibss(drv, dev, false);
3264
3265 out:
3266         cfg80211_put_dev(drv);
3267         dev_put(dev);
3268 unlock_rtnl:
3269         rtnl_unlock();
3270         return err;
3271 }
3272
3273 static struct genl_ops nl80211_ops[] = {
3274         {
3275                 .cmd = NL80211_CMD_GET_WIPHY,
3276                 .doit = nl80211_get_wiphy,
3277                 .dumpit = nl80211_dump_wiphy,
3278                 .policy = nl80211_policy,
3279                 /* can be retrieved by unprivileged users */
3280         },
3281         {
3282                 .cmd = NL80211_CMD_SET_WIPHY,
3283                 .doit = nl80211_set_wiphy,
3284                 .policy = nl80211_policy,
3285                 .flags = GENL_ADMIN_PERM,
3286         },
3287         {
3288                 .cmd = NL80211_CMD_GET_INTERFACE,
3289                 .doit = nl80211_get_interface,
3290                 .dumpit = nl80211_dump_interface,
3291                 .policy = nl80211_policy,
3292                 /* can be retrieved by unprivileged users */
3293         },
3294         {
3295                 .cmd = NL80211_CMD_SET_INTERFACE,
3296                 .doit = nl80211_set_interface,
3297                 .policy = nl80211_policy,
3298                 .flags = GENL_ADMIN_PERM,
3299         },
3300         {
3301                 .cmd = NL80211_CMD_NEW_INTERFACE,
3302                 .doit = nl80211_new_interface,
3303                 .policy = nl80211_policy,
3304                 .flags = GENL_ADMIN_PERM,
3305         },
3306         {
3307                 .cmd = NL80211_CMD_DEL_INTERFACE,
3308                 .doit = nl80211_del_interface,
3309                 .policy = nl80211_policy,
3310                 .flags = GENL_ADMIN_PERM,
3311         },
3312         {
3313                 .cmd = NL80211_CMD_GET_KEY,
3314                 .doit = nl80211_get_key,
3315                 .policy = nl80211_policy,
3316                 .flags = GENL_ADMIN_PERM,
3317         },
3318         {
3319                 .cmd = NL80211_CMD_SET_KEY,
3320                 .doit = nl80211_set_key,
3321                 .policy = nl80211_policy,
3322                 .flags = GENL_ADMIN_PERM,
3323         },
3324         {
3325                 .cmd = NL80211_CMD_NEW_KEY,
3326                 .doit = nl80211_new_key,
3327                 .policy = nl80211_policy,
3328                 .flags = GENL_ADMIN_PERM,
3329         },
3330         {
3331                 .cmd = NL80211_CMD_DEL_KEY,
3332                 .doit = nl80211_del_key,
3333                 .policy = nl80211_policy,
3334                 .flags = GENL_ADMIN_PERM,
3335         },
3336         {
3337                 .cmd = NL80211_CMD_SET_BEACON,
3338                 .policy = nl80211_policy,
3339                 .flags = GENL_ADMIN_PERM,
3340                 .doit = nl80211_addset_beacon,
3341         },
3342         {
3343                 .cmd = NL80211_CMD_NEW_BEACON,
3344                 .policy = nl80211_policy,
3345                 .flags = GENL_ADMIN_PERM,
3346                 .doit = nl80211_addset_beacon,
3347         },
3348         {
3349                 .cmd = NL80211_CMD_DEL_BEACON,
3350                 .policy = nl80211_policy,
3351                 .flags = GENL_ADMIN_PERM,
3352                 .doit = nl80211_del_beacon,
3353         },
3354         {
3355                 .cmd = NL80211_CMD_GET_STATION,
3356                 .doit = nl80211_get_station,
3357                 .dumpit = nl80211_dump_station,
3358                 .policy = nl80211_policy,
3359         },
3360         {
3361                 .cmd = NL80211_CMD_SET_STATION,
3362                 .doit = nl80211_set_station,
3363                 .policy = nl80211_policy,
3364                 .flags = GENL_ADMIN_PERM,
3365         },
3366         {
3367                 .cmd = NL80211_CMD_NEW_STATION,
3368                 .doit = nl80211_new_station,
3369                 .policy = nl80211_policy,
3370                 .flags = GENL_ADMIN_PERM,
3371         },
3372         {
3373                 .cmd = NL80211_CMD_DEL_STATION,
3374                 .doit = nl80211_del_station,
3375                 .policy = nl80211_policy,
3376                 .flags = GENL_ADMIN_PERM,
3377         },
3378         {
3379                 .cmd = NL80211_CMD_GET_MPATH,
3380                 .doit = nl80211_get_mpath,
3381                 .dumpit = nl80211_dump_mpath,
3382                 .policy = nl80211_policy,
3383                 .flags = GENL_ADMIN_PERM,
3384         },
3385         {
3386                 .cmd = NL80211_CMD_SET_MPATH,
3387                 .doit = nl80211_set_mpath,
3388                 .policy = nl80211_policy,
3389                 .flags = GENL_ADMIN_PERM,
3390         },
3391         {
3392                 .cmd = NL80211_CMD_NEW_MPATH,
3393                 .doit = nl80211_new_mpath,
3394                 .policy = nl80211_policy,
3395                 .flags = GENL_ADMIN_PERM,
3396         },
3397         {
3398                 .cmd = NL80211_CMD_DEL_MPATH,
3399                 .doit = nl80211_del_mpath,
3400                 .policy = nl80211_policy,
3401                 .flags = GENL_ADMIN_PERM,
3402         },
3403         {
3404                 .cmd = NL80211_CMD_SET_BSS,
3405                 .doit = nl80211_set_bss,
3406                 .policy = nl80211_policy,
3407                 .flags = GENL_ADMIN_PERM,
3408         },
3409         {
3410                 .cmd = NL80211_CMD_GET_REG,
3411                 .doit = nl80211_get_reg,
3412                 .policy = nl80211_policy,
3413                 /* can be retrieved by unprivileged users */
3414         },
3415         {
3416                 .cmd = NL80211_CMD_SET_REG,
3417                 .doit = nl80211_set_reg,
3418                 .policy = nl80211_policy,
3419                 .flags = GENL_ADMIN_PERM,
3420         },
3421         {
3422                 .cmd = NL80211_CMD_REQ_SET_REG,
3423                 .doit = nl80211_req_set_reg,
3424                 .policy = nl80211_policy,
3425                 .flags = GENL_ADMIN_PERM,
3426         },
3427         {
3428                 .cmd = NL80211_CMD_GET_MESH_PARAMS,
3429                 .doit = nl80211_get_mesh_params,
3430                 .policy = nl80211_policy,
3431                 /* can be retrieved by unprivileged users */
3432         },
3433         {
3434                 .cmd = NL80211_CMD_SET_MESH_PARAMS,
3435                 .doit = nl80211_set_mesh_params,
3436                 .policy = nl80211_policy,
3437                 .flags = GENL_ADMIN_PERM,
3438         },
3439         {
3440                 .cmd = NL80211_CMD_TRIGGER_SCAN,
3441                 .doit = nl80211_trigger_scan,
3442                 .policy = nl80211_policy,
3443                 .flags = GENL_ADMIN_PERM,
3444         },
3445         {
3446                 .cmd = NL80211_CMD_GET_SCAN,
3447                 .policy = nl80211_policy,
3448                 .dumpit = nl80211_dump_scan,
3449         },
3450         {
3451                 .cmd = NL80211_CMD_AUTHENTICATE,
3452                 .doit = nl80211_authenticate,
3453                 .policy = nl80211_policy,
3454                 .flags = GENL_ADMIN_PERM,
3455         },
3456         {
3457                 .cmd = NL80211_CMD_ASSOCIATE,
3458                 .doit = nl80211_associate,
3459                 .policy = nl80211_policy,
3460                 .flags = GENL_ADMIN_PERM,
3461         },
3462         {
3463                 .cmd = NL80211_CMD_DEAUTHENTICATE,
3464                 .doit = nl80211_deauthenticate,
3465                 .policy = nl80211_policy,
3466                 .flags = GENL_ADMIN_PERM,
3467         },
3468         {
3469                 .cmd = NL80211_CMD_DISASSOCIATE,
3470                 .doit = nl80211_disassociate,
3471                 .policy = nl80211_policy,
3472                 .flags = GENL_ADMIN_PERM,
3473         },
3474         {
3475                 .cmd = NL80211_CMD_JOIN_IBSS,
3476                 .doit = nl80211_join_ibss,
3477                 .policy = nl80211_policy,
3478                 .flags = GENL_ADMIN_PERM,
3479         },
3480         {
3481                 .cmd = NL80211_CMD_LEAVE_IBSS,
3482                 .doit = nl80211_leave_ibss,
3483                 .policy = nl80211_policy,
3484                 .flags = GENL_ADMIN_PERM,
3485         },
3486 };
3487 static struct genl_multicast_group nl80211_mlme_mcgrp = {
3488         .name = "mlme",
3489 };
3490
3491 /* multicast groups */
3492 static struct genl_multicast_group nl80211_config_mcgrp = {
3493         .name = "config",
3494 };
3495 static struct genl_multicast_group nl80211_scan_mcgrp = {
3496         .name = "scan",
3497 };
3498 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
3499         .name = "regulatory",
3500 };
3501
3502 /* notification functions */
3503
3504 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
3505 {
3506         struct sk_buff *msg;
3507
3508         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
3509         if (!msg)
3510                 return;
3511
3512         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
3513                 nlmsg_free(msg);
3514                 return;
3515         }
3516
3517         genlmsg_multicast(msg, 0, nl80211_config_mcgrp.id, GFP_KERNEL);
3518 }
3519
3520 static int nl80211_send_scan_donemsg(struct sk_buff *msg,
3521                                     struct cfg80211_registered_device *rdev,
3522                                     struct net_device *netdev,
3523                                     u32 pid, u32 seq, int flags,
3524                                     u32 cmd)
3525 {
3526         void *hdr;
3527
3528         hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
3529         if (!hdr)
3530                 return -1;
3531
3532         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3533         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
3534
3535         /* XXX: we should probably bounce back the request? */
3536
3537         return genlmsg_end(msg, hdr);
3538
3539  nla_put_failure:
3540         genlmsg_cancel(msg, hdr);
3541         return -EMSGSIZE;
3542 }
3543
3544 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
3545                             struct net_device *netdev)
3546 {
3547         struct sk_buff *msg;
3548
3549         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
3550         if (!msg)
3551                 return;
3552
3553         if (nl80211_send_scan_donemsg(msg, rdev, netdev, 0, 0, 0,
3554                                       NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
3555                 nlmsg_free(msg);
3556                 return;
3557         }
3558
3559         genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
3560 }
3561
3562 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
3563                                struct net_device *netdev)
3564 {
3565         struct sk_buff *msg;
3566
3567         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
3568         if (!msg)
3569                 return;
3570
3571         if (nl80211_send_scan_donemsg(msg, rdev, netdev, 0, 0, 0,
3572                                       NL80211_CMD_SCAN_ABORTED) < 0) {
3573                 nlmsg_free(msg);
3574                 return;
3575         }
3576
3577         genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
3578 }
3579
3580 /*
3581  * This can happen on global regulatory changes or device specific settings
3582  * based on custom world regulatory domains.
3583  */
3584 void nl80211_send_reg_change_event(struct regulatory_request *request)
3585 {
3586         struct sk_buff *msg;
3587         void *hdr;
3588
3589         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
3590         if (!msg)
3591                 return;
3592
3593         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
3594         if (!hdr) {
3595                 nlmsg_free(msg);
3596                 return;
3597         }
3598
3599         /* Userspace can always count this one always being set */
3600         NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
3601
3602         if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
3603                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
3604                            NL80211_REGDOM_TYPE_WORLD);
3605         else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
3606                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
3607                            NL80211_REGDOM_TYPE_CUSTOM_WORLD);
3608         else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
3609                  request->intersect)
3610                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
3611                            NL80211_REGDOM_TYPE_INTERSECTION);
3612         else {
3613                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
3614                            NL80211_REGDOM_TYPE_COUNTRY);
3615                 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
3616         }
3617
3618         if (wiphy_idx_valid(request->wiphy_idx))
3619                 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
3620
3621         if (genlmsg_end(msg, hdr) < 0) {
3622                 nlmsg_free(msg);
3623                 return;
3624         }
3625
3626         genlmsg_multicast(msg, 0, nl80211_regulatory_mcgrp.id, GFP_KERNEL);
3627
3628         return;
3629
3630 nla_put_failure:
3631         genlmsg_cancel(msg, hdr);
3632         nlmsg_free(msg);
3633 }
3634
3635 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
3636                                     struct net_device *netdev,
3637                                     const u8 *buf, size_t len,
3638                                     enum nl80211_commands cmd)
3639 {
3640         struct sk_buff *msg;
3641         void *hdr;
3642
3643         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_ATOMIC);
3644         if (!msg)
3645                 return;
3646
3647         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
3648         if (!hdr) {
3649                 nlmsg_free(msg);
3650                 return;
3651         }
3652
3653         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3654         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
3655         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
3656
3657         if (genlmsg_end(msg, hdr) < 0) {
3658                 nlmsg_free(msg);
3659                 return;
3660         }
3661
3662         genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, GFP_ATOMIC);
3663         return;
3664
3665  nla_put_failure:
3666         genlmsg_cancel(msg, hdr);
3667         nlmsg_free(msg);
3668 }
3669
3670 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
3671                           struct net_device *netdev, const u8 *buf, size_t len)
3672 {
3673         nl80211_send_mlme_event(rdev, netdev, buf, len,
3674                                 NL80211_CMD_AUTHENTICATE);
3675 }
3676
3677 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
3678                            struct net_device *netdev, const u8 *buf,
3679                            size_t len)
3680 {
3681         nl80211_send_mlme_event(rdev, netdev, buf, len, NL80211_CMD_ASSOCIATE);
3682 }
3683
3684 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
3685                          struct net_device *netdev, const u8 *buf, size_t len)
3686 {
3687         nl80211_send_mlme_event(rdev, netdev, buf, len,
3688                                 NL80211_CMD_DEAUTHENTICATE);
3689 }
3690
3691 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
3692                            struct net_device *netdev, const u8 *buf,
3693                            size_t len)
3694 {
3695         nl80211_send_mlme_event(rdev, netdev, buf, len,
3696                                 NL80211_CMD_DISASSOCIATE);
3697 }
3698
3699 void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
3700                                struct net_device *netdev, int cmd,
3701                                const u8 *addr)
3702 {
3703         struct sk_buff *msg;
3704         void *hdr;
3705
3706         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_ATOMIC);
3707         if (!msg)
3708                 return;
3709
3710         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
3711         if (!hdr) {
3712                 nlmsg_free(msg);
3713                 return;
3714         }
3715
3716         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3717         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
3718         NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
3719         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
3720
3721         if (genlmsg_end(msg, hdr) < 0) {
3722                 nlmsg_free(msg);
3723                 return;
3724         }
3725
3726         genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, GFP_ATOMIC);
3727         return;
3728
3729  nla_put_failure:
3730         genlmsg_cancel(msg, hdr);
3731         nlmsg_free(msg);
3732 }
3733
3734 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
3735                                struct net_device *netdev, const u8 *addr)
3736 {
3737         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
3738                                   addr);
3739 }
3740
3741 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
3742                                 struct net_device *netdev, const u8 *addr)
3743 {
3744         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE, addr);
3745 }
3746
3747 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
3748                              struct net_device *netdev, const u8 *bssid,
3749                              gfp_t gfp)
3750 {
3751         struct sk_buff *msg;
3752         void *hdr;
3753
3754         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
3755         if (!msg)
3756                 return;
3757
3758         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
3759         if (!hdr) {
3760                 nlmsg_free(msg);
3761                 return;
3762         }
3763
3764         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3765         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
3766         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
3767
3768         if (genlmsg_end(msg, hdr) < 0) {
3769                 nlmsg_free(msg);
3770                 return;
3771         }
3772
3773         genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
3774         return;
3775
3776  nla_put_failure:
3777         genlmsg_cancel(msg, hdr);
3778         nlmsg_free(msg);
3779 }
3780
3781 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
3782                                  struct net_device *netdev, const u8 *addr,
3783                                  enum nl80211_key_type key_type, int key_id,
3784                                  const u8 *tsc)
3785 {
3786         struct sk_buff *msg;
3787         void *hdr;
3788
3789         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
3790         if (!msg)
3791                 return;
3792
3793         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
3794         if (!hdr) {
3795                 nlmsg_free(msg);
3796                 return;
3797         }
3798
3799         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3800         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
3801         if (addr)
3802                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
3803         NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
3804         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
3805         if (tsc)
3806                 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
3807
3808         if (genlmsg_end(msg, hdr) < 0) {
3809                 nlmsg_free(msg);
3810                 return;
3811         }
3812
3813         genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, GFP_KERNEL);
3814         return;
3815
3816  nla_put_failure:
3817         genlmsg_cancel(msg, hdr);
3818         nlmsg_free(msg);
3819 }
3820
3821 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
3822                                     struct ieee80211_channel *channel_before,
3823                                     struct ieee80211_channel *channel_after)
3824 {
3825         struct sk_buff *msg;
3826         void *hdr;
3827         struct nlattr *nl_freq;
3828
3829         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_ATOMIC);
3830         if (!msg)
3831                 return;
3832
3833         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
3834         if (!hdr) {
3835                 nlmsg_free(msg);
3836                 return;
3837         }
3838
3839         /*
3840          * Since we are applying the beacon hint to a wiphy we know its
3841          * wiphy_idx is valid
3842          */
3843         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
3844
3845         /* Before */
3846         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
3847         if (!nl_freq)
3848                 goto nla_put_failure;
3849         if (nl80211_msg_put_channel(msg, channel_before))
3850                 goto nla_put_failure;
3851         nla_nest_end(msg, nl_freq);
3852
3853         /* After */
3854         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
3855         if (!nl_freq)
3856                 goto nla_put_failure;
3857         if (nl80211_msg_put_channel(msg, channel_after))
3858                 goto nla_put_failure;
3859         nla_nest_end(msg, nl_freq);
3860
3861         if (genlmsg_end(msg, hdr) < 0) {
3862                 nlmsg_free(msg);
3863                 return;
3864         }
3865
3866         genlmsg_multicast(msg, 0, nl80211_regulatory_mcgrp.id, GFP_ATOMIC);
3867
3868         return;
3869
3870 nla_put_failure:
3871         genlmsg_cancel(msg, hdr);
3872         nlmsg_free(msg);
3873 }
3874
3875 /* initialisation/exit functions */
3876
3877 int nl80211_init(void)
3878 {
3879         int err, i;
3880
3881         err = genl_register_family(&nl80211_fam);
3882         if (err)
3883                 return err;
3884
3885         for (i = 0; i < ARRAY_SIZE(nl80211_ops); i++) {
3886                 err = genl_register_ops(&nl80211_fam, &nl80211_ops[i]);
3887                 if (err)
3888                         goto err_out;
3889         }
3890
3891         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
3892         if (err)
3893                 goto err_out;
3894
3895         err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
3896         if (err)
3897                 goto err_out;
3898
3899         err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
3900         if (err)
3901                 goto err_out;
3902
3903         err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
3904         if (err)
3905                 goto err_out;
3906
3907         return 0;
3908  err_out:
3909         genl_unregister_family(&nl80211_fam);
3910         return err;
3911 }
3912
3913 void nl80211_exit(void)
3914 {
3915         genl_unregister_family(&nl80211_fam);
3916 }