mac80211: add nl80211/cfg80211 handling of the new mesh root mode option.
[safe/jmp/linux-2.6] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006-2009  Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/list.h>
11 #include <linux/if_ether.h>
12 #include <linux/ieee80211.h>
13 #include <linux/nl80211.h>
14 #include <linux/rtnetlink.h>
15 #include <linux/netlink.h>
16 #include <linux/etherdevice.h>
17 #include <net/net_namespace.h>
18 #include <net/genetlink.h>
19 #include <net/cfg80211.h>
20 #include <net/sock.h>
21 #include "core.h"
22 #include "nl80211.h"
23 #include "reg.h"
24
25 /* the netlink family */
26 static struct genl_family nl80211_fam = {
27         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
28         .name = "nl80211",      /* have users key off the name instead */
29         .hdrsize = 0,           /* no private header */
30         .version = 1,           /* no particular meaning now */
31         .maxattr = NL80211_ATTR_MAX,
32         .netnsok = true,
33 };
34
35 /* internal helper: get rdev and dev */
36 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
37                                        struct cfg80211_registered_device **rdev,
38                                        struct net_device **dev)
39 {
40         struct nlattr **attrs = info->attrs;
41         int ifindex;
42
43         if (!attrs[NL80211_ATTR_IFINDEX])
44                 return -EINVAL;
45
46         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
47         *dev = dev_get_by_index(genl_info_net(info), ifindex);
48         if (!*dev)
49                 return -ENODEV;
50
51         *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
52         if (IS_ERR(*rdev)) {
53                 dev_put(*dev);
54                 return PTR_ERR(*rdev);
55         }
56
57         return 0;
58 }
59
60 /* policy for the attributes */
61 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
62         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
63         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
64                                       .len = 20-1 },
65         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
66         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
67         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
68         [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
69         [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
70         [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
71         [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
72
73         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
74         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
75         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
76
77         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
78         [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
79
80         [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
81         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
82                                     .len = WLAN_MAX_KEY_LEN },
83         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
84         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
85         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
86         [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
87
88         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
89         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
90         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
91                                        .len = IEEE80211_MAX_DATA_LEN },
92         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
93                                        .len = IEEE80211_MAX_DATA_LEN },
94         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
95         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
96         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
97         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
98                                                .len = NL80211_MAX_SUPP_RATES },
99         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
100         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
101         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
102         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
103                                 .len = IEEE80211_MAX_MESH_ID_LEN },
104         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
105
106         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
107         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
108
109         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
110         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
111         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
112         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
113                                            .len = NL80211_MAX_SUPP_RATES },
114
115         [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
116
117         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
118                                          .len = NL80211_HT_CAPABILITY_LEN },
119
120         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
121         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
122                               .len = IEEE80211_MAX_DATA_LEN },
123         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
124         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
125
126         [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
127                                 .len = IEEE80211_MAX_SSID_LEN },
128         [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
129         [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
130         [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
131         [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
132         [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
133         [NL80211_ATTR_STA_FLAGS2] = {
134                 .len = sizeof(struct nl80211_sta_flag_update),
135         },
136         [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
137         [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
138         [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
139         [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
140         [NL80211_ATTR_PID] = { .type = NLA_U32 },
141         [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
142 };
143
144 /* policy for the attributes */
145 static struct nla_policy
146 nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
147         [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
148         [NL80211_KEY_IDX] = { .type = NLA_U8 },
149         [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
150         [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
151         [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
152         [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
153 };
154
155 /* IE validation */
156 static bool is_valid_ie_attr(const struct nlattr *attr)
157 {
158         const u8 *pos;
159         int len;
160
161         if (!attr)
162                 return true;
163
164         pos = nla_data(attr);
165         len = nla_len(attr);
166
167         while (len) {
168                 u8 elemlen;
169
170                 if (len < 2)
171                         return false;
172                 len -= 2;
173
174                 elemlen = pos[1];
175                 if (elemlen > len)
176                         return false;
177
178                 len -= elemlen;
179                 pos += 2 + elemlen;
180         }
181
182         return true;
183 }
184
185 /* message building helper */
186 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
187                                    int flags, u8 cmd)
188 {
189         /* since there is no private header just add the generic one */
190         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
191 }
192
193 static int nl80211_msg_put_channel(struct sk_buff *msg,
194                                    struct ieee80211_channel *chan)
195 {
196         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
197                     chan->center_freq);
198
199         if (chan->flags & IEEE80211_CHAN_DISABLED)
200                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
201         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
202                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
203         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
204                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
205         if (chan->flags & IEEE80211_CHAN_RADAR)
206                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
207
208         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
209                     DBM_TO_MBM(chan->max_power));
210
211         return 0;
212
213  nla_put_failure:
214         return -ENOBUFS;
215 }
216
217 /* netlink command implementations */
218
219 struct key_parse {
220         struct key_params p;
221         int idx;
222         bool def, defmgmt;
223 };
224
225 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
226 {
227         struct nlattr *tb[NL80211_KEY_MAX + 1];
228         int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
229                                    nl80211_key_policy);
230         if (err)
231                 return err;
232
233         k->def = !!tb[NL80211_KEY_DEFAULT];
234         k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
235
236         if (tb[NL80211_KEY_IDX])
237                 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
238
239         if (tb[NL80211_KEY_DATA]) {
240                 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
241                 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
242         }
243
244         if (tb[NL80211_KEY_SEQ]) {
245                 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
246                 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
247         }
248
249         if (tb[NL80211_KEY_CIPHER])
250                 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
251
252         return 0;
253 }
254
255 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
256 {
257         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
258                 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
259                 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
260         }
261
262         if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
263                 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
264                 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
265         }
266
267         if (info->attrs[NL80211_ATTR_KEY_IDX])
268                 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
269
270         if (info->attrs[NL80211_ATTR_KEY_CIPHER])
271                 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
272
273         k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
274         k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
275
276         return 0;
277 }
278
279 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
280 {
281         int err;
282
283         memset(k, 0, sizeof(*k));
284         k->idx = -1;
285
286         if (info->attrs[NL80211_ATTR_KEY])
287                 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
288         else
289                 err = nl80211_parse_key_old(info, k);
290
291         if (err)
292                 return err;
293
294         if (k->def && k->defmgmt)
295                 return -EINVAL;
296
297         if (k->idx != -1) {
298                 if (k->defmgmt) {
299                         if (k->idx < 4 || k->idx > 5)
300                                 return -EINVAL;
301                 } else if (k->def) {
302                         if (k->idx < 0 || k->idx > 3)
303                                 return -EINVAL;
304                 } else {
305                         if (k->idx < 0 || k->idx > 5)
306                                 return -EINVAL;
307                 }
308         }
309
310         return 0;
311 }
312
313 static struct cfg80211_cached_keys *
314 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
315                        struct nlattr *keys)
316 {
317         struct key_parse parse;
318         struct nlattr *key;
319         struct cfg80211_cached_keys *result;
320         int rem, err, def = 0;
321
322         result = kzalloc(sizeof(*result), GFP_KERNEL);
323         if (!result)
324                 return ERR_PTR(-ENOMEM);
325
326         result->def = -1;
327         result->defmgmt = -1;
328
329         nla_for_each_nested(key, keys, rem) {
330                 memset(&parse, 0, sizeof(parse));
331                 parse.idx = -1;
332
333                 err = nl80211_parse_key_new(key, &parse);
334                 if (err)
335                         goto error;
336                 err = -EINVAL;
337                 if (!parse.p.key)
338                         goto error;
339                 if (parse.idx < 0 || parse.idx > 4)
340                         goto error;
341                 if (parse.def) {
342                         if (def)
343                                 goto error;
344                         def = 1;
345                         result->def = parse.idx;
346                 } else if (parse.defmgmt)
347                         goto error;
348                 err = cfg80211_validate_key_settings(rdev, &parse.p,
349                                                      parse.idx, NULL);
350                 if (err)
351                         goto error;
352                 result->params[parse.idx].cipher = parse.p.cipher;
353                 result->params[parse.idx].key_len = parse.p.key_len;
354                 result->params[parse.idx].key = result->data[parse.idx];
355                 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
356         }
357
358         return result;
359  error:
360         kfree(result);
361         return ERR_PTR(err);
362 }
363
364 static int nl80211_key_allowed(struct wireless_dev *wdev)
365 {
366         ASSERT_WDEV_LOCK(wdev);
367
368         if (!netif_running(wdev->netdev))
369                 return -ENETDOWN;
370
371         switch (wdev->iftype) {
372         case NL80211_IFTYPE_AP:
373         case NL80211_IFTYPE_AP_VLAN:
374                 break;
375         case NL80211_IFTYPE_ADHOC:
376                 if (!wdev->current_bss)
377                         return -ENOLINK;
378                 break;
379         case NL80211_IFTYPE_STATION:
380                 if (wdev->sme_state != CFG80211_SME_CONNECTED)
381                         return -ENOLINK;
382                 break;
383         default:
384                 return -EINVAL;
385         }
386
387         return 0;
388 }
389
390 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
391                               struct cfg80211_registered_device *dev)
392 {
393         void *hdr;
394         struct nlattr *nl_bands, *nl_band;
395         struct nlattr *nl_freqs, *nl_freq;
396         struct nlattr *nl_rates, *nl_rate;
397         struct nlattr *nl_modes;
398         struct nlattr *nl_cmds;
399         enum ieee80211_band band;
400         struct ieee80211_channel *chan;
401         struct ieee80211_rate *rate;
402         int i;
403         u16 ifmodes = dev->wiphy.interface_modes;
404
405         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
406         if (!hdr)
407                 return -1;
408
409         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
410         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
411
412         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
413                     cfg80211_rdev_list_generation);
414
415         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
416                    dev->wiphy.retry_short);
417         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
418                    dev->wiphy.retry_long);
419         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
420                     dev->wiphy.frag_threshold);
421         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
422                     dev->wiphy.rts_threshold);
423
424         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
425                    dev->wiphy.max_scan_ssids);
426         NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
427                     dev->wiphy.max_scan_ie_len);
428
429         NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
430                 sizeof(u32) * dev->wiphy.n_cipher_suites,
431                 dev->wiphy.cipher_suites);
432
433         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
434         if (!nl_modes)
435                 goto nla_put_failure;
436
437         i = 0;
438         while (ifmodes) {
439                 if (ifmodes & 1)
440                         NLA_PUT_FLAG(msg, i);
441                 ifmodes >>= 1;
442                 i++;
443         }
444
445         nla_nest_end(msg, nl_modes);
446
447         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
448         if (!nl_bands)
449                 goto nla_put_failure;
450
451         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
452                 if (!dev->wiphy.bands[band])
453                         continue;
454
455                 nl_band = nla_nest_start(msg, band);
456                 if (!nl_band)
457                         goto nla_put_failure;
458
459                 /* add HT info */
460                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
461                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
462                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
463                                 &dev->wiphy.bands[band]->ht_cap.mcs);
464                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
465                                 dev->wiphy.bands[band]->ht_cap.cap);
466                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
467                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
468                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
469                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
470                 }
471
472                 /* add frequencies */
473                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
474                 if (!nl_freqs)
475                         goto nla_put_failure;
476
477                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
478                         nl_freq = nla_nest_start(msg, i);
479                         if (!nl_freq)
480                                 goto nla_put_failure;
481
482                         chan = &dev->wiphy.bands[band]->channels[i];
483
484                         if (nl80211_msg_put_channel(msg, chan))
485                                 goto nla_put_failure;
486
487                         nla_nest_end(msg, nl_freq);
488                 }
489
490                 nla_nest_end(msg, nl_freqs);
491
492                 /* add bitrates */
493                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
494                 if (!nl_rates)
495                         goto nla_put_failure;
496
497                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
498                         nl_rate = nla_nest_start(msg, i);
499                         if (!nl_rate)
500                                 goto nla_put_failure;
501
502                         rate = &dev->wiphy.bands[band]->bitrates[i];
503                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
504                                     rate->bitrate);
505                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
506                                 NLA_PUT_FLAG(msg,
507                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
508
509                         nla_nest_end(msg, nl_rate);
510                 }
511
512                 nla_nest_end(msg, nl_rates);
513
514                 nla_nest_end(msg, nl_band);
515         }
516         nla_nest_end(msg, nl_bands);
517
518         nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
519         if (!nl_cmds)
520                 goto nla_put_failure;
521
522         i = 0;
523 #define CMD(op, n)                                              \
524          do {                                                   \
525                 if (dev->ops->op) {                             \
526                         i++;                                    \
527                         NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
528                 }                                               \
529         } while (0)
530
531         CMD(add_virtual_intf, NEW_INTERFACE);
532         CMD(change_virtual_intf, SET_INTERFACE);
533         CMD(add_key, NEW_KEY);
534         CMD(add_beacon, NEW_BEACON);
535         CMD(add_station, NEW_STATION);
536         CMD(add_mpath, NEW_MPATH);
537         CMD(set_mesh_params, SET_MESH_PARAMS);
538         CMD(change_bss, SET_BSS);
539         CMD(auth, AUTHENTICATE);
540         CMD(assoc, ASSOCIATE);
541         CMD(deauth, DEAUTHENTICATE);
542         CMD(disassoc, DISASSOCIATE);
543         CMD(join_ibss, JOIN_IBSS);
544         if (dev->wiphy.netnsok) {
545                 i++;
546                 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
547         }
548
549 #undef CMD
550
551         if (dev->ops->connect || dev->ops->auth) {
552                 i++;
553                 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
554         }
555
556         if (dev->ops->disconnect || dev->ops->deauth) {
557                 i++;
558                 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
559         }
560
561         nla_nest_end(msg, nl_cmds);
562
563         return genlmsg_end(msg, hdr);
564
565  nla_put_failure:
566         genlmsg_cancel(msg, hdr);
567         return -EMSGSIZE;
568 }
569
570 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
571 {
572         int idx = 0;
573         int start = cb->args[0];
574         struct cfg80211_registered_device *dev;
575
576         mutex_lock(&cfg80211_mutex);
577         list_for_each_entry(dev, &cfg80211_rdev_list, list) {
578                 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
579                         continue;
580                 if (++idx <= start)
581                         continue;
582                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
583                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
584                                        dev) < 0) {
585                         idx--;
586                         break;
587                 }
588         }
589         mutex_unlock(&cfg80211_mutex);
590
591         cb->args[0] = idx;
592
593         return skb->len;
594 }
595
596 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
597 {
598         struct sk_buff *msg;
599         struct cfg80211_registered_device *dev;
600
601         dev = cfg80211_get_dev_from_info(info);
602         if (IS_ERR(dev))
603                 return PTR_ERR(dev);
604
605         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
606         if (!msg)
607                 goto out_err;
608
609         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
610                 goto out_free;
611
612         cfg80211_unlock_rdev(dev);
613
614         return genlmsg_reply(msg, info);
615
616  out_free:
617         nlmsg_free(msg);
618  out_err:
619         cfg80211_unlock_rdev(dev);
620         return -ENOBUFS;
621 }
622
623 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
624         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
625         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
626         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
627         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
628         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
629 };
630
631 static int parse_txq_params(struct nlattr *tb[],
632                             struct ieee80211_txq_params *txq_params)
633 {
634         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
635             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
636             !tb[NL80211_TXQ_ATTR_AIFS])
637                 return -EINVAL;
638
639         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
640         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
641         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
642         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
643         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
644
645         return 0;
646 }
647
648 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
649 {
650         struct cfg80211_registered_device *rdev;
651         int result = 0, rem_txq_params = 0;
652         struct nlattr *nl_txq_params;
653         u32 changed;
654         u8 retry_short = 0, retry_long = 0;
655         u32 frag_threshold = 0, rts_threshold = 0;
656
657         rtnl_lock();
658
659         mutex_lock(&cfg80211_mutex);
660
661         rdev = __cfg80211_rdev_from_info(info);
662         if (IS_ERR(rdev)) {
663                 mutex_unlock(&cfg80211_mutex);
664                 result = PTR_ERR(rdev);
665                 goto unlock;
666         }
667
668         mutex_lock(&rdev->mtx);
669
670         if (info->attrs[NL80211_ATTR_WIPHY_NAME])
671                 result = cfg80211_dev_rename(
672                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
673
674         mutex_unlock(&cfg80211_mutex);
675
676         if (result)
677                 goto bad_res;
678
679         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
680                 struct ieee80211_txq_params txq_params;
681                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
682
683                 if (!rdev->ops->set_txq_params) {
684                         result = -EOPNOTSUPP;
685                         goto bad_res;
686                 }
687
688                 nla_for_each_nested(nl_txq_params,
689                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
690                                     rem_txq_params) {
691                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
692                                   nla_data(nl_txq_params),
693                                   nla_len(nl_txq_params),
694                                   txq_params_policy);
695                         result = parse_txq_params(tb, &txq_params);
696                         if (result)
697                                 goto bad_res;
698
699                         result = rdev->ops->set_txq_params(&rdev->wiphy,
700                                                            &txq_params);
701                         if (result)
702                                 goto bad_res;
703                 }
704         }
705
706         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
707                 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
708                 u32 freq;
709
710                 result = -EINVAL;
711
712                 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
713                         channel_type = nla_get_u32(info->attrs[
714                                            NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
715                         if (channel_type != NL80211_CHAN_NO_HT &&
716                             channel_type != NL80211_CHAN_HT20 &&
717                             channel_type != NL80211_CHAN_HT40PLUS &&
718                             channel_type != NL80211_CHAN_HT40MINUS)
719                                 goto bad_res;
720                 }
721
722                 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
723
724                 mutex_lock(&rdev->devlist_mtx);
725                 result = rdev_set_freq(rdev, NULL, freq, channel_type);
726                 mutex_unlock(&rdev->devlist_mtx);
727                 if (result)
728                         goto bad_res;
729         }
730
731         changed = 0;
732
733         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
734                 retry_short = nla_get_u8(
735                         info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
736                 if (retry_short == 0) {
737                         result = -EINVAL;
738                         goto bad_res;
739                 }
740                 changed |= WIPHY_PARAM_RETRY_SHORT;
741         }
742
743         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
744                 retry_long = nla_get_u8(
745                         info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
746                 if (retry_long == 0) {
747                         result = -EINVAL;
748                         goto bad_res;
749                 }
750                 changed |= WIPHY_PARAM_RETRY_LONG;
751         }
752
753         if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
754                 frag_threshold = nla_get_u32(
755                         info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
756                 if (frag_threshold < 256) {
757                         result = -EINVAL;
758                         goto bad_res;
759                 }
760                 if (frag_threshold != (u32) -1) {
761                         /*
762                          * Fragments (apart from the last one) are required to
763                          * have even length. Make the fragmentation code
764                          * simpler by stripping LSB should someone try to use
765                          * odd threshold value.
766                          */
767                         frag_threshold &= ~0x1;
768                 }
769                 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
770         }
771
772         if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
773                 rts_threshold = nla_get_u32(
774                         info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
775                 changed |= WIPHY_PARAM_RTS_THRESHOLD;
776         }
777
778         if (changed) {
779                 u8 old_retry_short, old_retry_long;
780                 u32 old_frag_threshold, old_rts_threshold;
781
782                 if (!rdev->ops->set_wiphy_params) {
783                         result = -EOPNOTSUPP;
784                         goto bad_res;
785                 }
786
787                 old_retry_short = rdev->wiphy.retry_short;
788                 old_retry_long = rdev->wiphy.retry_long;
789                 old_frag_threshold = rdev->wiphy.frag_threshold;
790                 old_rts_threshold = rdev->wiphy.rts_threshold;
791
792                 if (changed & WIPHY_PARAM_RETRY_SHORT)
793                         rdev->wiphy.retry_short = retry_short;
794                 if (changed & WIPHY_PARAM_RETRY_LONG)
795                         rdev->wiphy.retry_long = retry_long;
796                 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
797                         rdev->wiphy.frag_threshold = frag_threshold;
798                 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
799                         rdev->wiphy.rts_threshold = rts_threshold;
800
801                 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
802                 if (result) {
803                         rdev->wiphy.retry_short = old_retry_short;
804                         rdev->wiphy.retry_long = old_retry_long;
805                         rdev->wiphy.frag_threshold = old_frag_threshold;
806                         rdev->wiphy.rts_threshold = old_rts_threshold;
807                 }
808         }
809
810  bad_res:
811         mutex_unlock(&rdev->mtx);
812  unlock:
813         rtnl_unlock();
814         return result;
815 }
816
817
818 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
819                               struct cfg80211_registered_device *rdev,
820                               struct net_device *dev)
821 {
822         void *hdr;
823
824         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
825         if (!hdr)
826                 return -1;
827
828         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
829         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
830         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
831         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
832
833         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
834                     rdev->devlist_generation ^
835                         (cfg80211_rdev_list_generation << 2));
836
837         return genlmsg_end(msg, hdr);
838
839  nla_put_failure:
840         genlmsg_cancel(msg, hdr);
841         return -EMSGSIZE;
842 }
843
844 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
845 {
846         int wp_idx = 0;
847         int if_idx = 0;
848         int wp_start = cb->args[0];
849         int if_start = cb->args[1];
850         struct cfg80211_registered_device *rdev;
851         struct wireless_dev *wdev;
852
853         mutex_lock(&cfg80211_mutex);
854         list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
855                 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
856                         continue;
857                 if (wp_idx < wp_start) {
858                         wp_idx++;
859                         continue;
860                 }
861                 if_idx = 0;
862
863                 mutex_lock(&rdev->devlist_mtx);
864                 list_for_each_entry(wdev, &rdev->netdev_list, list) {
865                         if (if_idx < if_start) {
866                                 if_idx++;
867                                 continue;
868                         }
869                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
870                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
871                                                rdev, wdev->netdev) < 0) {
872                                 mutex_unlock(&rdev->devlist_mtx);
873                                 goto out;
874                         }
875                         if_idx++;
876                 }
877                 mutex_unlock(&rdev->devlist_mtx);
878
879                 wp_idx++;
880         }
881  out:
882         mutex_unlock(&cfg80211_mutex);
883
884         cb->args[0] = wp_idx;
885         cb->args[1] = if_idx;
886
887         return skb->len;
888 }
889
890 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
891 {
892         struct sk_buff *msg;
893         struct cfg80211_registered_device *dev;
894         struct net_device *netdev;
895         int err;
896
897         err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
898         if (err)
899                 return err;
900
901         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
902         if (!msg)
903                 goto out_err;
904
905         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
906                                dev, netdev) < 0)
907                 goto out_free;
908
909         dev_put(netdev);
910         cfg80211_unlock_rdev(dev);
911
912         return genlmsg_reply(msg, info);
913
914  out_free:
915         nlmsg_free(msg);
916  out_err:
917         dev_put(netdev);
918         cfg80211_unlock_rdev(dev);
919         return -ENOBUFS;
920 }
921
922 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
923         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
924         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
925         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
926         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
927         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
928 };
929
930 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
931 {
932         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
933         int flag;
934
935         *mntrflags = 0;
936
937         if (!nla)
938                 return -EINVAL;
939
940         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
941                              nla, mntr_flags_policy))
942                 return -EINVAL;
943
944         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
945                 if (flags[flag])
946                         *mntrflags |= (1<<flag);
947
948         return 0;
949 }
950
951 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
952 {
953         struct cfg80211_registered_device *rdev;
954         struct vif_params params;
955         int err;
956         enum nl80211_iftype otype, ntype;
957         struct net_device *dev;
958         u32 _flags, *flags = NULL;
959         bool change = false;
960
961         memset(&params, 0, sizeof(params));
962
963         rtnl_lock();
964
965         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
966         if (err)
967                 goto unlock_rtnl;
968
969         otype = ntype = dev->ieee80211_ptr->iftype;
970
971         if (info->attrs[NL80211_ATTR_IFTYPE]) {
972                 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
973                 if (otype != ntype)
974                         change = true;
975                 if (ntype > NL80211_IFTYPE_MAX) {
976                         err = -EINVAL;
977                         goto unlock;
978                 }
979         }
980
981         if (info->attrs[NL80211_ATTR_MESH_ID]) {
982                 if (ntype != NL80211_IFTYPE_MESH_POINT) {
983                         err = -EINVAL;
984                         goto unlock;
985                 }
986                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
987                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
988                 change = true;
989         }
990
991         if (info->attrs[NL80211_ATTR_4ADDR]) {
992                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
993                 change = true;
994         } else {
995                 params.use_4addr = -1;
996         }
997
998         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
999                 if (ntype != NL80211_IFTYPE_MONITOR) {
1000                         err = -EINVAL;
1001                         goto unlock;
1002                 }
1003                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1004                                           &_flags);
1005                 if (err)
1006                         goto unlock;
1007
1008                 flags = &_flags;
1009                 change = true;
1010         }
1011
1012         if (change)
1013                 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1014         else
1015                 err = 0;
1016
1017  unlock:
1018         dev_put(dev);
1019         cfg80211_unlock_rdev(rdev);
1020  unlock_rtnl:
1021         rtnl_unlock();
1022         return err;
1023 }
1024
1025 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1026 {
1027         struct cfg80211_registered_device *rdev;
1028         struct vif_params params;
1029         int err;
1030         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1031         u32 flags;
1032
1033         memset(&params, 0, sizeof(params));
1034
1035         if (!info->attrs[NL80211_ATTR_IFNAME])
1036                 return -EINVAL;
1037
1038         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1039                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1040                 if (type > NL80211_IFTYPE_MAX)
1041                         return -EINVAL;
1042         }
1043
1044         rtnl_lock();
1045
1046         rdev = cfg80211_get_dev_from_info(info);
1047         if (IS_ERR(rdev)) {
1048                 err = PTR_ERR(rdev);
1049                 goto unlock_rtnl;
1050         }
1051
1052         if (!rdev->ops->add_virtual_intf ||
1053             !(rdev->wiphy.interface_modes & (1 << type))) {
1054                 err = -EOPNOTSUPP;
1055                 goto unlock;
1056         }
1057
1058         if (type == NL80211_IFTYPE_MESH_POINT &&
1059             info->attrs[NL80211_ATTR_MESH_ID]) {
1060                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1061                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1062         }
1063
1064         if (info->attrs[NL80211_ATTR_4ADDR])
1065                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1066
1067         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1068                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1069                                   &flags);
1070         err = rdev->ops->add_virtual_intf(&rdev->wiphy,
1071                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1072                 type, err ? NULL : &flags, &params);
1073
1074  unlock:
1075         cfg80211_unlock_rdev(rdev);
1076  unlock_rtnl:
1077         rtnl_unlock();
1078         return err;
1079 }
1080
1081 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1082 {
1083         struct cfg80211_registered_device *rdev;
1084         int err;
1085         struct net_device *dev;
1086
1087         rtnl_lock();
1088
1089         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1090         if (err)
1091                 goto unlock_rtnl;
1092
1093         if (!rdev->ops->del_virtual_intf) {
1094                 err = -EOPNOTSUPP;
1095                 goto out;
1096         }
1097
1098         err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1099
1100  out:
1101         cfg80211_unlock_rdev(rdev);
1102         dev_put(dev);
1103  unlock_rtnl:
1104         rtnl_unlock();
1105         return err;
1106 }
1107
1108 struct get_key_cookie {
1109         struct sk_buff *msg;
1110         int error;
1111         int idx;
1112 };
1113
1114 static void get_key_callback(void *c, struct key_params *params)
1115 {
1116         struct nlattr *key;
1117         struct get_key_cookie *cookie = c;
1118
1119         if (params->key)
1120                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1121                         params->key_len, params->key);
1122
1123         if (params->seq)
1124                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1125                         params->seq_len, params->seq);
1126
1127         if (params->cipher)
1128                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1129                             params->cipher);
1130
1131         key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1132         if (!key)
1133                 goto nla_put_failure;
1134
1135         if (params->key)
1136                 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1137                         params->key_len, params->key);
1138
1139         if (params->seq)
1140                 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1141                         params->seq_len, params->seq);
1142
1143         if (params->cipher)
1144                 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1145                             params->cipher);
1146
1147         NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1148
1149         nla_nest_end(cookie->msg, key);
1150
1151         return;
1152  nla_put_failure:
1153         cookie->error = 1;
1154 }
1155
1156 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1157 {
1158         struct cfg80211_registered_device *rdev;
1159         int err;
1160         struct net_device *dev;
1161         u8 key_idx = 0;
1162         u8 *mac_addr = NULL;
1163         struct get_key_cookie cookie = {
1164                 .error = 0,
1165         };
1166         void *hdr;
1167         struct sk_buff *msg;
1168
1169         if (info->attrs[NL80211_ATTR_KEY_IDX])
1170                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1171
1172         if (key_idx > 5)
1173                 return -EINVAL;
1174
1175         if (info->attrs[NL80211_ATTR_MAC])
1176                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1177
1178         rtnl_lock();
1179
1180         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1181         if (err)
1182                 goto unlock_rtnl;
1183
1184         if (!rdev->ops->get_key) {
1185                 err = -EOPNOTSUPP;
1186                 goto out;
1187         }
1188
1189         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1190         if (!msg) {
1191                 err = -ENOMEM;
1192                 goto out;
1193         }
1194
1195         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1196                              NL80211_CMD_NEW_KEY);
1197
1198         if (IS_ERR(hdr)) {
1199                 err = PTR_ERR(hdr);
1200                 goto free_msg;
1201         }
1202
1203         cookie.msg = msg;
1204         cookie.idx = key_idx;
1205
1206         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1207         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1208         if (mac_addr)
1209                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1210
1211         err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
1212                                 &cookie, get_key_callback);
1213
1214         if (err)
1215                 goto free_msg;
1216
1217         if (cookie.error)
1218                 goto nla_put_failure;
1219
1220         genlmsg_end(msg, hdr);
1221         err = genlmsg_reply(msg, info);
1222         goto out;
1223
1224  nla_put_failure:
1225         err = -ENOBUFS;
1226  free_msg:
1227         nlmsg_free(msg);
1228  out:
1229         cfg80211_unlock_rdev(rdev);
1230         dev_put(dev);
1231  unlock_rtnl:
1232         rtnl_unlock();
1233
1234         return err;
1235 }
1236
1237 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1238 {
1239         struct cfg80211_registered_device *rdev;
1240         struct key_parse key;
1241         int err;
1242         struct net_device *dev;
1243         int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1244                     u8 key_index);
1245
1246         err = nl80211_parse_key(info, &key);
1247         if (err)
1248                 return err;
1249
1250         if (key.idx < 0)
1251                 return -EINVAL;
1252
1253         /* only support setting default key */
1254         if (!key.def && !key.defmgmt)
1255                 return -EINVAL;
1256
1257         rtnl_lock();
1258
1259         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1260         if (err)
1261                 goto unlock_rtnl;
1262
1263         if (key.def)
1264                 func = rdev->ops->set_default_key;
1265         else
1266                 func = rdev->ops->set_default_mgmt_key;
1267
1268         if (!func) {
1269                 err = -EOPNOTSUPP;
1270                 goto out;
1271         }
1272
1273         wdev_lock(dev->ieee80211_ptr);
1274         err = nl80211_key_allowed(dev->ieee80211_ptr);
1275         if (!err)
1276                 err = func(&rdev->wiphy, dev, key.idx);
1277
1278 #ifdef CONFIG_CFG80211_WEXT
1279         if (!err) {
1280                 if (func == rdev->ops->set_default_key)
1281                         dev->ieee80211_ptr->wext.default_key = key.idx;
1282                 else
1283                         dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1284         }
1285 #endif
1286         wdev_unlock(dev->ieee80211_ptr);
1287
1288  out:
1289         cfg80211_unlock_rdev(rdev);
1290         dev_put(dev);
1291
1292  unlock_rtnl:
1293         rtnl_unlock();
1294
1295         return err;
1296 }
1297
1298 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1299 {
1300         struct cfg80211_registered_device *rdev;
1301         int err;
1302         struct net_device *dev;
1303         struct key_parse key;
1304         u8 *mac_addr = NULL;
1305
1306         err = nl80211_parse_key(info, &key);
1307         if (err)
1308                 return err;
1309
1310         if (!key.p.key)
1311                 return -EINVAL;
1312
1313         if (info->attrs[NL80211_ATTR_MAC])
1314                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1315
1316         rtnl_lock();
1317
1318         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1319         if (err)
1320                 goto unlock_rtnl;
1321
1322         if (!rdev->ops->add_key) {
1323                 err = -EOPNOTSUPP;
1324                 goto out;
1325         }
1326
1327         if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1328                 err = -EINVAL;
1329                 goto out;
1330         }
1331
1332         wdev_lock(dev->ieee80211_ptr);
1333         err = nl80211_key_allowed(dev->ieee80211_ptr);
1334         if (!err)
1335                 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1336                                          mac_addr, &key.p);
1337         wdev_unlock(dev->ieee80211_ptr);
1338
1339  out:
1340         cfg80211_unlock_rdev(rdev);
1341         dev_put(dev);
1342  unlock_rtnl:
1343         rtnl_unlock();
1344
1345         return err;
1346 }
1347
1348 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1349 {
1350         struct cfg80211_registered_device *rdev;
1351         int err;
1352         struct net_device *dev;
1353         u8 *mac_addr = NULL;
1354         struct key_parse key;
1355
1356         err = nl80211_parse_key(info, &key);
1357         if (err)
1358                 return err;
1359
1360         if (info->attrs[NL80211_ATTR_MAC])
1361                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1362
1363         rtnl_lock();
1364
1365         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1366         if (err)
1367                 goto unlock_rtnl;
1368
1369         if (!rdev->ops->del_key) {
1370                 err = -EOPNOTSUPP;
1371                 goto out;
1372         }
1373
1374         wdev_lock(dev->ieee80211_ptr);
1375         err = nl80211_key_allowed(dev->ieee80211_ptr);
1376         if (!err)
1377                 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
1378
1379 #ifdef CONFIG_CFG80211_WEXT
1380         if (!err) {
1381                 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1382                         dev->ieee80211_ptr->wext.default_key = -1;
1383                 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1384                         dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1385         }
1386 #endif
1387         wdev_unlock(dev->ieee80211_ptr);
1388
1389  out:
1390         cfg80211_unlock_rdev(rdev);
1391         dev_put(dev);
1392
1393  unlock_rtnl:
1394         rtnl_unlock();
1395
1396         return err;
1397 }
1398
1399 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1400 {
1401         int (*call)(struct wiphy *wiphy, struct net_device *dev,
1402                     struct beacon_parameters *info);
1403         struct cfg80211_registered_device *rdev;
1404         int err;
1405         struct net_device *dev;
1406         struct beacon_parameters params;
1407         int haveinfo = 0;
1408
1409         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1410                 return -EINVAL;
1411
1412         rtnl_lock();
1413
1414         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1415         if (err)
1416                 goto unlock_rtnl;
1417
1418         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1419                 err = -EOPNOTSUPP;
1420                 goto out;
1421         }
1422
1423         switch (info->genlhdr->cmd) {
1424         case NL80211_CMD_NEW_BEACON:
1425                 /* these are required for NEW_BEACON */
1426                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1427                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1428                     !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1429                         err = -EINVAL;
1430                         goto out;
1431                 }
1432
1433                 call = rdev->ops->add_beacon;
1434                 break;
1435         case NL80211_CMD_SET_BEACON:
1436                 call = rdev->ops->set_beacon;
1437                 break;
1438         default:
1439                 WARN_ON(1);
1440                 err = -EOPNOTSUPP;
1441                 goto out;
1442         }
1443
1444         if (!call) {
1445                 err = -EOPNOTSUPP;
1446                 goto out;
1447         }
1448
1449         memset(&params, 0, sizeof(params));
1450
1451         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1452                 params.interval =
1453                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1454                 haveinfo = 1;
1455         }
1456
1457         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1458                 params.dtim_period =
1459                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1460                 haveinfo = 1;
1461         }
1462
1463         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1464                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1465                 params.head_len =
1466                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1467                 haveinfo = 1;
1468         }
1469
1470         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1471                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1472                 params.tail_len =
1473                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1474                 haveinfo = 1;
1475         }
1476
1477         if (!haveinfo) {
1478                 err = -EINVAL;
1479                 goto out;
1480         }
1481
1482         err = call(&rdev->wiphy, dev, &params);
1483
1484  out:
1485         cfg80211_unlock_rdev(rdev);
1486         dev_put(dev);
1487  unlock_rtnl:
1488         rtnl_unlock();
1489
1490         return err;
1491 }
1492
1493 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1494 {
1495         struct cfg80211_registered_device *rdev;
1496         int err;
1497         struct net_device *dev;
1498
1499         rtnl_lock();
1500
1501         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1502         if (err)
1503                 goto unlock_rtnl;
1504
1505         if (!rdev->ops->del_beacon) {
1506                 err = -EOPNOTSUPP;
1507                 goto out;
1508         }
1509
1510         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1511                 err = -EOPNOTSUPP;
1512                 goto out;
1513         }
1514         err = rdev->ops->del_beacon(&rdev->wiphy, dev);
1515
1516  out:
1517         cfg80211_unlock_rdev(rdev);
1518         dev_put(dev);
1519  unlock_rtnl:
1520         rtnl_unlock();
1521
1522         return err;
1523 }
1524
1525 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1526         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1527         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1528         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1529         [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1530 };
1531
1532 static int parse_station_flags(struct genl_info *info,
1533                                struct station_parameters *params)
1534 {
1535         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1536         struct nlattr *nla;
1537         int flag;
1538
1539         /*
1540          * Try parsing the new attribute first so userspace
1541          * can specify both for older kernels.
1542          */
1543         nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1544         if (nla) {
1545                 struct nl80211_sta_flag_update *sta_flags;
1546
1547                 sta_flags = nla_data(nla);
1548                 params->sta_flags_mask = sta_flags->mask;
1549                 params->sta_flags_set = sta_flags->set;
1550                 if ((params->sta_flags_mask |
1551                      params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1552                         return -EINVAL;
1553                 return 0;
1554         }
1555
1556         /* if present, parse the old attribute */
1557
1558         nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1559         if (!nla)
1560                 return 0;
1561
1562         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1563                              nla, sta_flags_policy))
1564                 return -EINVAL;
1565
1566         params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1567         params->sta_flags_mask &= ~1;
1568
1569         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1570                 if (flags[flag])
1571                         params->sta_flags_set |= (1<<flag);
1572
1573         return 0;
1574 }
1575
1576 static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1577 {
1578         int modulation, streams, bitrate;
1579
1580         if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1581                 return rate->legacy;
1582
1583         /* the formula below does only work for MCS values smaller than 32 */
1584         if (rate->mcs >= 32)
1585                 return 0;
1586
1587         modulation = rate->mcs & 7;
1588         streams = (rate->mcs >> 3) + 1;
1589
1590         bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1591                         13500000 : 6500000;
1592
1593         if (modulation < 4)
1594                 bitrate *= (modulation + 1);
1595         else if (modulation == 4)
1596                 bitrate *= (modulation + 2);
1597         else
1598                 bitrate *= (modulation + 3);
1599
1600         bitrate *= streams;
1601
1602         if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1603                 bitrate = (bitrate / 9) * 10;
1604
1605         /* do NOT round down here */
1606         return (bitrate + 50000) / 100000;
1607 }
1608
1609 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1610                                 int flags, struct net_device *dev,
1611                                 u8 *mac_addr, struct station_info *sinfo)
1612 {
1613         void *hdr;
1614         struct nlattr *sinfoattr, *txrate;
1615         u16 bitrate;
1616
1617         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1618         if (!hdr)
1619                 return -1;
1620
1621         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1622         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1623
1624         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1625
1626         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1627         if (!sinfoattr)
1628                 goto nla_put_failure;
1629         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1630                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1631                             sinfo->inactive_time);
1632         if (sinfo->filled & STATION_INFO_RX_BYTES)
1633                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1634                             sinfo->rx_bytes);
1635         if (sinfo->filled & STATION_INFO_TX_BYTES)
1636                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1637                             sinfo->tx_bytes);
1638         if (sinfo->filled & STATION_INFO_LLID)
1639                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1640                             sinfo->llid);
1641         if (sinfo->filled & STATION_INFO_PLID)
1642                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1643                             sinfo->plid);
1644         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1645                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1646                             sinfo->plink_state);
1647         if (sinfo->filled & STATION_INFO_SIGNAL)
1648                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1649                            sinfo->signal);
1650         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1651                 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1652                 if (!txrate)
1653                         goto nla_put_failure;
1654
1655                 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1656                 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1657                 if (bitrate > 0)
1658                         NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1659
1660                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1661                         NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1662                                     sinfo->txrate.mcs);
1663                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1664                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1665                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1666                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1667
1668                 nla_nest_end(msg, txrate);
1669         }
1670         if (sinfo->filled & STATION_INFO_RX_PACKETS)
1671                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1672                             sinfo->rx_packets);
1673         if (sinfo->filled & STATION_INFO_TX_PACKETS)
1674                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1675                             sinfo->tx_packets);
1676         nla_nest_end(msg, sinfoattr);
1677
1678         return genlmsg_end(msg, hdr);
1679
1680  nla_put_failure:
1681         genlmsg_cancel(msg, hdr);
1682         return -EMSGSIZE;
1683 }
1684
1685 static int nl80211_dump_station(struct sk_buff *skb,
1686                                 struct netlink_callback *cb)
1687 {
1688         struct station_info sinfo;
1689         struct cfg80211_registered_device *dev;
1690         struct net_device *netdev;
1691         u8 mac_addr[ETH_ALEN];
1692         int ifidx = cb->args[0];
1693         int sta_idx = cb->args[1];
1694         int err;
1695
1696         if (!ifidx) {
1697                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1698                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1699                                   nl80211_policy);
1700                 if (err)
1701                         return err;
1702
1703                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1704                         return -EINVAL;
1705
1706                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1707                 if (!ifidx)
1708                         return -EINVAL;
1709         }
1710
1711         rtnl_lock();
1712
1713         netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
1714         if (!netdev) {
1715                 err = -ENODEV;
1716                 goto out_rtnl;
1717         }
1718
1719         dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
1720         if (IS_ERR(dev)) {
1721                 err = PTR_ERR(dev);
1722                 goto out_rtnl;
1723         }
1724
1725         if (!dev->ops->dump_station) {
1726                 err = -EOPNOTSUPP;
1727                 goto out_err;
1728         }
1729
1730         while (1) {
1731                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1732                                              mac_addr, &sinfo);
1733                 if (err == -ENOENT)
1734                         break;
1735                 if (err)
1736                         goto out_err;
1737
1738                 if (nl80211_send_station(skb,
1739                                 NETLINK_CB(cb->skb).pid,
1740                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1741                                 netdev, mac_addr,
1742                                 &sinfo) < 0)
1743                         goto out;
1744
1745                 sta_idx++;
1746         }
1747
1748
1749  out:
1750         cb->args[1] = sta_idx;
1751         err = skb->len;
1752  out_err:
1753         cfg80211_unlock_rdev(dev);
1754  out_rtnl:
1755         rtnl_unlock();
1756
1757         return err;
1758 }
1759
1760 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1761 {
1762         struct cfg80211_registered_device *rdev;
1763         int err;
1764         struct net_device *dev;
1765         struct station_info sinfo;
1766         struct sk_buff *msg;
1767         u8 *mac_addr = NULL;
1768
1769         memset(&sinfo, 0, sizeof(sinfo));
1770
1771         if (!info->attrs[NL80211_ATTR_MAC])
1772                 return -EINVAL;
1773
1774         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1775
1776         rtnl_lock();
1777
1778         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1779         if (err)
1780                 goto out_rtnl;
1781
1782         if (!rdev->ops->get_station) {
1783                 err = -EOPNOTSUPP;
1784                 goto out;
1785         }
1786
1787         err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
1788         if (err)
1789                 goto out;
1790
1791         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1792         if (!msg)
1793                 goto out;
1794
1795         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1796                                  dev, mac_addr, &sinfo) < 0)
1797                 goto out_free;
1798
1799         err = genlmsg_reply(msg, info);
1800         goto out;
1801
1802  out_free:
1803         nlmsg_free(msg);
1804  out:
1805         cfg80211_unlock_rdev(rdev);
1806         dev_put(dev);
1807  out_rtnl:
1808         rtnl_unlock();
1809
1810         return err;
1811 }
1812
1813 /*
1814  * Get vlan interface making sure it is on the right wiphy.
1815  */
1816 static int get_vlan(struct genl_info *info,
1817                     struct cfg80211_registered_device *rdev,
1818                     struct net_device **vlan)
1819 {
1820         struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
1821         *vlan = NULL;
1822
1823         if (vlanattr) {
1824                 *vlan = dev_get_by_index(genl_info_net(info),
1825                                          nla_get_u32(vlanattr));
1826                 if (!*vlan)
1827                         return -ENODEV;
1828                 if (!(*vlan)->ieee80211_ptr)
1829                         return -EINVAL;
1830                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1831                         return -EINVAL;
1832         }
1833         return 0;
1834 }
1835
1836 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1837 {
1838         struct cfg80211_registered_device *rdev;
1839         int err;
1840         struct net_device *dev;
1841         struct station_parameters params;
1842         u8 *mac_addr = NULL;
1843
1844         memset(&params, 0, sizeof(params));
1845
1846         params.listen_interval = -1;
1847
1848         if (info->attrs[NL80211_ATTR_STA_AID])
1849                 return -EINVAL;
1850
1851         if (!info->attrs[NL80211_ATTR_MAC])
1852                 return -EINVAL;
1853
1854         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1855
1856         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1857                 params.supported_rates =
1858                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1859                 params.supported_rates_len =
1860                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1861         }
1862
1863         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1864                 params.listen_interval =
1865                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1866
1867         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1868                 params.ht_capa =
1869                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1870
1871         if (parse_station_flags(info, &params))
1872                 return -EINVAL;
1873
1874         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1875                 params.plink_action =
1876                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1877
1878         rtnl_lock();
1879
1880         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1881         if (err)
1882                 goto out_rtnl;
1883
1884         err = get_vlan(info, rdev, &params.vlan);
1885         if (err)
1886                 goto out;
1887
1888         /* validate settings */
1889         err = 0;
1890
1891         switch (dev->ieee80211_ptr->iftype) {
1892         case NL80211_IFTYPE_AP:
1893         case NL80211_IFTYPE_AP_VLAN:
1894                 /* disallow mesh-specific things */
1895                 if (params.plink_action)
1896                         err = -EINVAL;
1897                 break;
1898         case NL80211_IFTYPE_STATION:
1899                 /* disallow everything but AUTHORIZED flag */
1900                 if (params.plink_action)
1901                         err = -EINVAL;
1902                 if (params.vlan)
1903                         err = -EINVAL;
1904                 if (params.supported_rates)
1905                         err = -EINVAL;
1906                 if (params.ht_capa)
1907                         err = -EINVAL;
1908                 if (params.listen_interval >= 0)
1909                         err = -EINVAL;
1910                 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1911                         err = -EINVAL;
1912                 break;
1913         case NL80211_IFTYPE_MESH_POINT:
1914                 /* disallow things mesh doesn't support */
1915                 if (params.vlan)
1916                         err = -EINVAL;
1917                 if (params.ht_capa)
1918                         err = -EINVAL;
1919                 if (params.listen_interval >= 0)
1920                         err = -EINVAL;
1921                 if (params.supported_rates)
1922                         err = -EINVAL;
1923                 if (params.sta_flags_mask)
1924                         err = -EINVAL;
1925                 break;
1926         default:
1927                 err = -EINVAL;
1928         }
1929
1930         if (err)
1931                 goto out;
1932
1933         if (!rdev->ops->change_station) {
1934                 err = -EOPNOTSUPP;
1935                 goto out;
1936         }
1937
1938         err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
1939
1940  out:
1941         if (params.vlan)
1942                 dev_put(params.vlan);
1943         cfg80211_unlock_rdev(rdev);
1944         dev_put(dev);
1945  out_rtnl:
1946         rtnl_unlock();
1947
1948         return err;
1949 }
1950
1951 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1952 {
1953         struct cfg80211_registered_device *rdev;
1954         int err;
1955         struct net_device *dev;
1956         struct station_parameters params;
1957         u8 *mac_addr = NULL;
1958
1959         memset(&params, 0, sizeof(params));
1960
1961         if (!info->attrs[NL80211_ATTR_MAC])
1962                 return -EINVAL;
1963
1964         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1965                 return -EINVAL;
1966
1967         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1968                 return -EINVAL;
1969
1970         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1971         params.supported_rates =
1972                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1973         params.supported_rates_len =
1974                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1975         params.listen_interval =
1976                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1977
1978         if (info->attrs[NL80211_ATTR_STA_AID]) {
1979                 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1980                 if (!params.aid || params.aid > IEEE80211_MAX_AID)
1981                         return -EINVAL;
1982         }
1983
1984         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1985                 params.ht_capa =
1986                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1987
1988         if (parse_station_flags(info, &params))
1989                 return -EINVAL;
1990
1991         rtnl_lock();
1992
1993         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1994         if (err)
1995                 goto out_rtnl;
1996
1997         err = get_vlan(info, rdev, &params.vlan);
1998         if (err)
1999                 goto out;
2000
2001         /* validate settings */
2002         err = 0;
2003
2004         switch (dev->ieee80211_ptr->iftype) {
2005         case NL80211_IFTYPE_AP:
2006         case NL80211_IFTYPE_AP_VLAN:
2007                 /* all ok but must have AID */
2008                 if (!params.aid)
2009                         err = -EINVAL;
2010                 break;
2011         case NL80211_IFTYPE_MESH_POINT:
2012                 /* disallow things mesh doesn't support */
2013                 if (params.vlan)
2014                         err = -EINVAL;
2015                 if (params.aid)
2016                         err = -EINVAL;
2017                 if (params.ht_capa)
2018                         err = -EINVAL;
2019                 if (params.listen_interval >= 0)
2020                         err = -EINVAL;
2021                 if (params.supported_rates)
2022                         err = -EINVAL;
2023                 if (params.sta_flags_mask)
2024                         err = -EINVAL;
2025                 break;
2026         default:
2027                 err = -EINVAL;
2028         }
2029
2030         if (err)
2031                 goto out;
2032
2033         if (!rdev->ops->add_station) {
2034                 err = -EOPNOTSUPP;
2035                 goto out;
2036         }
2037
2038         if (!netif_running(dev)) {
2039                 err = -ENETDOWN;
2040                 goto out;
2041         }
2042
2043         err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2044
2045  out:
2046         if (params.vlan)
2047                 dev_put(params.vlan);
2048         cfg80211_unlock_rdev(rdev);
2049         dev_put(dev);
2050  out_rtnl:
2051         rtnl_unlock();
2052
2053         return err;
2054 }
2055
2056 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2057 {
2058         struct cfg80211_registered_device *rdev;
2059         int err;
2060         struct net_device *dev;
2061         u8 *mac_addr = NULL;
2062
2063         if (info->attrs[NL80211_ATTR_MAC])
2064                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2065
2066         rtnl_lock();
2067
2068         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2069         if (err)
2070                 goto out_rtnl;
2071
2072         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2073             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2074             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2075                 err = -EINVAL;
2076                 goto out;
2077         }
2078
2079         if (!rdev->ops->del_station) {
2080                 err = -EOPNOTSUPP;
2081                 goto out;
2082         }
2083
2084         err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2085
2086  out:
2087         cfg80211_unlock_rdev(rdev);
2088         dev_put(dev);
2089  out_rtnl:
2090         rtnl_unlock();
2091
2092         return err;
2093 }
2094
2095 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2096                                 int flags, struct net_device *dev,
2097                                 u8 *dst, u8 *next_hop,
2098                                 struct mpath_info *pinfo)
2099 {
2100         void *hdr;
2101         struct nlattr *pinfoattr;
2102
2103         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2104         if (!hdr)
2105                 return -1;
2106
2107         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2108         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2109         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2110
2111         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2112
2113         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2114         if (!pinfoattr)
2115                 goto nla_put_failure;
2116         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2117                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2118                             pinfo->frame_qlen);
2119         if (pinfo->filled & MPATH_INFO_SN)
2120                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2121                             pinfo->sn);
2122         if (pinfo->filled & MPATH_INFO_METRIC)
2123                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2124                             pinfo->metric);
2125         if (pinfo->filled & MPATH_INFO_EXPTIME)
2126                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2127                             pinfo->exptime);
2128         if (pinfo->filled & MPATH_INFO_FLAGS)
2129                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2130                             pinfo->flags);
2131         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2132                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2133                             pinfo->discovery_timeout);
2134         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2135                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2136                             pinfo->discovery_retries);
2137
2138         nla_nest_end(msg, pinfoattr);
2139
2140         return genlmsg_end(msg, hdr);
2141
2142  nla_put_failure:
2143         genlmsg_cancel(msg, hdr);
2144         return -EMSGSIZE;
2145 }
2146
2147 static int nl80211_dump_mpath(struct sk_buff *skb,
2148                               struct netlink_callback *cb)
2149 {
2150         struct mpath_info pinfo;
2151         struct cfg80211_registered_device *dev;
2152         struct net_device *netdev;
2153         u8 dst[ETH_ALEN];
2154         u8 next_hop[ETH_ALEN];
2155         int ifidx = cb->args[0];
2156         int path_idx = cb->args[1];
2157         int err;
2158
2159         if (!ifidx) {
2160                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2161                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
2162                                   nl80211_policy);
2163                 if (err)
2164                         return err;
2165
2166                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2167                         return -EINVAL;
2168
2169                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2170                 if (!ifidx)
2171                         return -EINVAL;
2172         }
2173
2174         rtnl_lock();
2175
2176         netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
2177         if (!netdev) {
2178                 err = -ENODEV;
2179                 goto out_rtnl;
2180         }
2181
2182         dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
2183         if (IS_ERR(dev)) {
2184                 err = PTR_ERR(dev);
2185                 goto out_rtnl;
2186         }
2187
2188         if (!dev->ops->dump_mpath) {
2189                 err = -EOPNOTSUPP;
2190                 goto out_err;
2191         }
2192
2193         if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2194                 err = -EOPNOTSUPP;
2195                 goto out_err;
2196         }
2197
2198         while (1) {
2199                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2200                                            dst, next_hop, &pinfo);
2201                 if (err == -ENOENT)
2202                         break;
2203                 if (err)
2204                         goto out_err;
2205
2206                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2207                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
2208                                        netdev, dst, next_hop,
2209                                        &pinfo) < 0)
2210                         goto out;
2211
2212                 path_idx++;
2213         }
2214
2215
2216  out:
2217         cb->args[1] = path_idx;
2218         err = skb->len;
2219  out_err:
2220         cfg80211_unlock_rdev(dev);
2221  out_rtnl:
2222         rtnl_unlock();
2223
2224         return err;
2225 }
2226
2227 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2228 {
2229         struct cfg80211_registered_device *rdev;
2230         int err;
2231         struct net_device *dev;
2232         struct mpath_info pinfo;
2233         struct sk_buff *msg;
2234         u8 *dst = NULL;
2235         u8 next_hop[ETH_ALEN];
2236
2237         memset(&pinfo, 0, sizeof(pinfo));
2238
2239         if (!info->attrs[NL80211_ATTR_MAC])
2240                 return -EINVAL;
2241
2242         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2243
2244         rtnl_lock();
2245
2246         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2247         if (err)
2248                 goto out_rtnl;
2249
2250         if (!rdev->ops->get_mpath) {
2251                 err = -EOPNOTSUPP;
2252                 goto out;
2253         }
2254
2255         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2256                 err = -EOPNOTSUPP;
2257                 goto out;
2258         }
2259
2260         err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2261         if (err)
2262                 goto out;
2263
2264         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2265         if (!msg)
2266                 goto out;
2267
2268         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2269                                  dev, dst, next_hop, &pinfo) < 0)
2270                 goto out_free;
2271
2272         err = genlmsg_reply(msg, info);
2273         goto out;
2274
2275  out_free:
2276         nlmsg_free(msg);
2277  out:
2278         cfg80211_unlock_rdev(rdev);
2279         dev_put(dev);
2280  out_rtnl:
2281         rtnl_unlock();
2282
2283         return err;
2284 }
2285
2286 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2287 {
2288         struct cfg80211_registered_device *rdev;
2289         int err;
2290         struct net_device *dev;
2291         u8 *dst = NULL;
2292         u8 *next_hop = NULL;
2293
2294         if (!info->attrs[NL80211_ATTR_MAC])
2295                 return -EINVAL;
2296
2297         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2298                 return -EINVAL;
2299
2300         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2301         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2302
2303         rtnl_lock();
2304
2305         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2306         if (err)
2307                 goto out_rtnl;
2308
2309         if (!rdev->ops->change_mpath) {
2310                 err = -EOPNOTSUPP;
2311                 goto out;
2312         }
2313
2314         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2315                 err = -EOPNOTSUPP;
2316                 goto out;
2317         }
2318
2319         if (!netif_running(dev)) {
2320                 err = -ENETDOWN;
2321                 goto out;
2322         }
2323
2324         err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2325
2326  out:
2327         cfg80211_unlock_rdev(rdev);
2328         dev_put(dev);
2329  out_rtnl:
2330         rtnl_unlock();
2331
2332         return err;
2333 }
2334 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2335 {
2336         struct cfg80211_registered_device *rdev;
2337         int err;
2338         struct net_device *dev;
2339         u8 *dst = NULL;
2340         u8 *next_hop = NULL;
2341
2342         if (!info->attrs[NL80211_ATTR_MAC])
2343                 return -EINVAL;
2344
2345         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2346                 return -EINVAL;
2347
2348         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2349         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2350
2351         rtnl_lock();
2352
2353         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2354         if (err)
2355                 goto out_rtnl;
2356
2357         if (!rdev->ops->add_mpath) {
2358                 err = -EOPNOTSUPP;
2359                 goto out;
2360         }
2361
2362         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2363                 err = -EOPNOTSUPP;
2364                 goto out;
2365         }
2366
2367         if (!netif_running(dev)) {
2368                 err = -ENETDOWN;
2369                 goto out;
2370         }
2371
2372         err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2373
2374  out:
2375         cfg80211_unlock_rdev(rdev);
2376         dev_put(dev);
2377  out_rtnl:
2378         rtnl_unlock();
2379
2380         return err;
2381 }
2382
2383 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2384 {
2385         struct cfg80211_registered_device *rdev;
2386         int err;
2387         struct net_device *dev;
2388         u8 *dst = NULL;
2389
2390         if (info->attrs[NL80211_ATTR_MAC])
2391                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2392
2393         rtnl_lock();
2394
2395         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2396         if (err)
2397                 goto out_rtnl;
2398
2399         if (!rdev->ops->del_mpath) {
2400                 err = -EOPNOTSUPP;
2401                 goto out;
2402         }
2403
2404         err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2405
2406  out:
2407         cfg80211_unlock_rdev(rdev);
2408         dev_put(dev);
2409  out_rtnl:
2410         rtnl_unlock();
2411
2412         return err;
2413 }
2414
2415 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2416 {
2417         struct cfg80211_registered_device *rdev;
2418         int err;
2419         struct net_device *dev;
2420         struct bss_parameters params;
2421
2422         memset(&params, 0, sizeof(params));
2423         /* default to not changing parameters */
2424         params.use_cts_prot = -1;
2425         params.use_short_preamble = -1;
2426         params.use_short_slot_time = -1;
2427
2428         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2429                 params.use_cts_prot =
2430                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2431         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2432                 params.use_short_preamble =
2433                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2434         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2435                 params.use_short_slot_time =
2436                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2437         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2438                 params.basic_rates =
2439                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2440                 params.basic_rates_len =
2441                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2442         }
2443
2444         rtnl_lock();
2445
2446         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2447         if (err)
2448                 goto out_rtnl;
2449
2450         if (!rdev->ops->change_bss) {
2451                 err = -EOPNOTSUPP;
2452                 goto out;
2453         }
2454
2455         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2456                 err = -EOPNOTSUPP;
2457                 goto out;
2458         }
2459
2460         err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2461
2462  out:
2463         cfg80211_unlock_rdev(rdev);
2464         dev_put(dev);
2465  out_rtnl:
2466         rtnl_unlock();
2467
2468         return err;
2469 }
2470
2471 static const struct nla_policy
2472         reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2473         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
2474         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
2475         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
2476         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
2477         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
2478         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
2479 };
2480
2481 static int parse_reg_rule(struct nlattr *tb[],
2482         struct ieee80211_reg_rule *reg_rule)
2483 {
2484         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2485         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2486
2487         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2488                 return -EINVAL;
2489         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2490                 return -EINVAL;
2491         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2492                 return -EINVAL;
2493         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2494                 return -EINVAL;
2495         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2496                 return -EINVAL;
2497
2498         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2499
2500         freq_range->start_freq_khz =
2501                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2502         freq_range->end_freq_khz =
2503                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2504         freq_range->max_bandwidth_khz =
2505                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2506
2507         power_rule->max_eirp =
2508                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2509
2510         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2511                 power_rule->max_antenna_gain =
2512                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2513
2514         return 0;
2515 }
2516
2517 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2518 {
2519         int r;
2520         char *data = NULL;
2521
2522         /*
2523          * You should only get this when cfg80211 hasn't yet initialized
2524          * completely when built-in to the kernel right between the time
2525          * window between nl80211_init() and regulatory_init(), if that is
2526          * even possible.
2527          */
2528         mutex_lock(&cfg80211_mutex);
2529         if (unlikely(!cfg80211_regdomain)) {
2530                 mutex_unlock(&cfg80211_mutex);
2531                 return -EINPROGRESS;
2532         }
2533         mutex_unlock(&cfg80211_mutex);
2534
2535         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2536                 return -EINVAL;
2537
2538         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2539
2540 #ifdef CONFIG_WIRELESS_OLD_REGULATORY
2541         /* We ignore world regdom requests with the old regdom setup */
2542         if (is_world_regdom(data))
2543                 return -EINVAL;
2544 #endif
2545
2546         r = regulatory_hint_user(data);
2547
2548         return r;
2549 }
2550
2551 static int nl80211_get_mesh_params(struct sk_buff *skb,
2552         struct genl_info *info)
2553 {
2554         struct cfg80211_registered_device *rdev;
2555         struct mesh_config cur_params;
2556         int err;
2557         struct net_device *dev;
2558         void *hdr;
2559         struct nlattr *pinfoattr;
2560         struct sk_buff *msg;
2561
2562         rtnl_lock();
2563
2564         /* Look up our device */
2565         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2566         if (err)
2567                 goto out_rtnl;
2568
2569         if (!rdev->ops->get_mesh_params) {
2570                 err = -EOPNOTSUPP;
2571                 goto out;
2572         }
2573
2574         /* Get the mesh params */
2575         err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
2576         if (err)
2577                 goto out;
2578
2579         /* Draw up a netlink message to send back */
2580         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2581         if (!msg) {
2582                 err = -ENOBUFS;
2583                 goto out;
2584         }
2585         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2586                              NL80211_CMD_GET_MESH_PARAMS);
2587         if (!hdr)
2588                 goto nla_put_failure;
2589         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2590         if (!pinfoattr)
2591                 goto nla_put_failure;
2592         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2593         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2594                         cur_params.dot11MeshRetryTimeout);
2595         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2596                         cur_params.dot11MeshConfirmTimeout);
2597         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2598                         cur_params.dot11MeshHoldingTimeout);
2599         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2600                         cur_params.dot11MeshMaxPeerLinks);
2601         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2602                         cur_params.dot11MeshMaxRetries);
2603         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2604                         cur_params.dot11MeshTTL);
2605         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2606                         cur_params.auto_open_plinks);
2607         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2608                         cur_params.dot11MeshHWMPmaxPREQretries);
2609         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2610                         cur_params.path_refresh_time);
2611         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2612                         cur_params.min_discovery_timeout);
2613         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2614                         cur_params.dot11MeshHWMPactivePathTimeout);
2615         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2616                         cur_params.dot11MeshHWMPpreqMinInterval);
2617         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2618                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2619         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2620                         cur_params.dot11MeshHWMPRootMode);
2621         nla_nest_end(msg, pinfoattr);
2622         genlmsg_end(msg, hdr);
2623         err = genlmsg_reply(msg, info);
2624         goto out;
2625
2626  nla_put_failure:
2627         genlmsg_cancel(msg, hdr);
2628         err = -EMSGSIZE;
2629  out:
2630         /* Cleanup */
2631         cfg80211_unlock_rdev(rdev);
2632         dev_put(dev);
2633  out_rtnl:
2634         rtnl_unlock();
2635
2636         return err;
2637 }
2638
2639 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2640 do {\
2641         if (table[attr_num]) {\
2642                 cfg.param = nla_fn(table[attr_num]); \
2643                 mask |= (1 << (attr_num - 1)); \
2644         } \
2645 } while (0);\
2646
2647 static struct nla_policy
2648 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2649         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2650         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2651         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2652         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2653         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2654         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2655         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2656
2657         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2658         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2659         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2660         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2661         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2662         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2663 };
2664
2665 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2666 {
2667         int err;
2668         u32 mask;
2669         struct cfg80211_registered_device *rdev;
2670         struct net_device *dev;
2671         struct mesh_config cfg;
2672         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2673         struct nlattr *parent_attr;
2674
2675         parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2676         if (!parent_attr)
2677                 return -EINVAL;
2678         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2679                         parent_attr, nl80211_meshconf_params_policy))
2680                 return -EINVAL;
2681
2682         rtnl_lock();
2683
2684         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2685         if (err)
2686                 goto out_rtnl;
2687
2688         if (!rdev->ops->set_mesh_params) {
2689                 err = -EOPNOTSUPP;
2690                 goto out;
2691         }
2692
2693         /* This makes sure that there aren't more than 32 mesh config
2694          * parameters (otherwise our bitfield scheme would not work.) */
2695         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2696
2697         /* Fill in the params struct */
2698         mask = 0;
2699         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2700                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2701         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2702                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2703         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2704                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2705         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2706                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2707         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2708                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2709         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2710                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
2711         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2712                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2713         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2714                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2715                         nla_get_u8);
2716         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2717                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2718         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2719                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2720                         nla_get_u16);
2721         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2722                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2723                         nla_get_u32);
2724         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2725                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2726                         nla_get_u16);
2727         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2728                         dot11MeshHWMPnetDiameterTraversalTime,
2729                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2730                         nla_get_u16);
2731         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2732                         dot11MeshHWMPRootMode, mask,
2733                         NL80211_MESHCONF_HWMP_ROOTMODE,
2734                         nla_get_u8);
2735
2736         /* Apply changes */
2737         err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
2738
2739  out:
2740         /* cleanup */
2741         cfg80211_unlock_rdev(rdev);
2742         dev_put(dev);
2743  out_rtnl:
2744         rtnl_unlock();
2745
2746         return err;
2747 }
2748
2749 #undef FILL_IN_MESH_PARAM_IF_SET
2750
2751 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2752 {
2753         struct sk_buff *msg;
2754         void *hdr = NULL;
2755         struct nlattr *nl_reg_rules;
2756         unsigned int i;
2757         int err = -EINVAL;
2758
2759         mutex_lock(&cfg80211_mutex);
2760
2761         if (!cfg80211_regdomain)
2762                 goto out;
2763
2764         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2765         if (!msg) {
2766                 err = -ENOBUFS;
2767                 goto out;
2768         }
2769
2770         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2771                              NL80211_CMD_GET_REG);
2772         if (!hdr)
2773                 goto nla_put_failure;
2774
2775         NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2776                 cfg80211_regdomain->alpha2);
2777
2778         nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2779         if (!nl_reg_rules)
2780                 goto nla_put_failure;
2781
2782         for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2783                 struct nlattr *nl_reg_rule;
2784                 const struct ieee80211_reg_rule *reg_rule;
2785                 const struct ieee80211_freq_range *freq_range;
2786                 const struct ieee80211_power_rule *power_rule;
2787
2788                 reg_rule = &cfg80211_regdomain->reg_rules[i];
2789                 freq_range = &reg_rule->freq_range;
2790                 power_rule = &reg_rule->power_rule;
2791
2792                 nl_reg_rule = nla_nest_start(msg, i);
2793                 if (!nl_reg_rule)
2794                         goto nla_put_failure;
2795
2796                 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2797                         reg_rule->flags);
2798                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2799                         freq_range->start_freq_khz);
2800                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2801                         freq_range->end_freq_khz);
2802                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2803                         freq_range->max_bandwidth_khz);
2804                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2805                         power_rule->max_antenna_gain);
2806                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2807                         power_rule->max_eirp);
2808
2809                 nla_nest_end(msg, nl_reg_rule);
2810         }
2811
2812         nla_nest_end(msg, nl_reg_rules);
2813
2814         genlmsg_end(msg, hdr);
2815         err = genlmsg_reply(msg, info);
2816         goto out;
2817
2818 nla_put_failure:
2819         genlmsg_cancel(msg, hdr);
2820         err = -EMSGSIZE;
2821 out:
2822         mutex_unlock(&cfg80211_mutex);
2823         return err;
2824 }
2825
2826 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2827 {
2828         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2829         struct nlattr *nl_reg_rule;
2830         char *alpha2 = NULL;
2831         int rem_reg_rules = 0, r = 0;
2832         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2833         struct ieee80211_regdomain *rd = NULL;
2834
2835         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2836                 return -EINVAL;
2837
2838         if (!info->attrs[NL80211_ATTR_REG_RULES])
2839                 return -EINVAL;
2840
2841         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2842
2843         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2844                         rem_reg_rules) {
2845                 num_rules++;
2846                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2847                         return -EINVAL;
2848         }
2849
2850         mutex_lock(&cfg80211_mutex);
2851
2852         if (!reg_is_valid_request(alpha2)) {
2853                 r = -EINVAL;
2854                 goto bad_reg;
2855         }
2856
2857         size_of_regd = sizeof(struct ieee80211_regdomain) +
2858                 (num_rules * sizeof(struct ieee80211_reg_rule));
2859
2860         rd = kzalloc(size_of_regd, GFP_KERNEL);
2861         if (!rd) {
2862                 r = -ENOMEM;
2863                 goto bad_reg;
2864         }
2865
2866         rd->n_reg_rules = num_rules;
2867         rd->alpha2[0] = alpha2[0];
2868         rd->alpha2[1] = alpha2[1];
2869
2870         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2871                         rem_reg_rules) {
2872                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2873                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2874                         reg_rule_policy);
2875                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2876                 if (r)
2877                         goto bad_reg;
2878
2879                 rule_idx++;
2880
2881                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2882                         r = -EINVAL;
2883                         goto bad_reg;
2884                 }
2885         }
2886
2887         BUG_ON(rule_idx != num_rules);
2888
2889         r = set_regdom(rd);
2890
2891         mutex_unlock(&cfg80211_mutex);
2892
2893         return r;
2894
2895  bad_reg:
2896         mutex_unlock(&cfg80211_mutex);
2897         kfree(rd);
2898         return r;
2899 }
2900
2901 static int validate_scan_freqs(struct nlattr *freqs)
2902 {
2903         struct nlattr *attr1, *attr2;
2904         int n_channels = 0, tmp1, tmp2;
2905
2906         nla_for_each_nested(attr1, freqs, tmp1) {
2907                 n_channels++;
2908                 /*
2909                  * Some hardware has a limited channel list for
2910                  * scanning, and it is pretty much nonsensical
2911                  * to scan for a channel twice, so disallow that
2912                  * and don't require drivers to check that the
2913                  * channel list they get isn't longer than what
2914                  * they can scan, as long as they can scan all
2915                  * the channels they registered at once.
2916                  */
2917                 nla_for_each_nested(attr2, freqs, tmp2)
2918                         if (attr1 != attr2 &&
2919                             nla_get_u32(attr1) == nla_get_u32(attr2))
2920                                 return 0;
2921         }
2922
2923         return n_channels;
2924 }
2925
2926 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2927 {
2928         struct cfg80211_registered_device *rdev;
2929         struct net_device *dev;
2930         struct cfg80211_scan_request *request;
2931         struct cfg80211_ssid *ssid;
2932         struct ieee80211_channel *channel;
2933         struct nlattr *attr;
2934         struct wiphy *wiphy;
2935         int err, tmp, n_ssids = 0, n_channels, i;
2936         enum ieee80211_band band;
2937         size_t ie_len;
2938
2939         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2940                 return -EINVAL;
2941
2942         rtnl_lock();
2943
2944         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2945         if (err)
2946                 goto out_rtnl;
2947
2948         wiphy = &rdev->wiphy;
2949
2950         if (!rdev->ops->scan) {
2951                 err = -EOPNOTSUPP;
2952                 goto out;
2953         }
2954
2955         if (!netif_running(dev)) {
2956                 err = -ENETDOWN;
2957                 goto out;
2958         }
2959
2960         if (rdev->scan_req) {
2961                 err = -EBUSY;
2962                 goto out;
2963         }
2964
2965         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2966                 n_channels = validate_scan_freqs(
2967                                 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2968                 if (!n_channels) {
2969                         err = -EINVAL;
2970                         goto out;
2971                 }
2972         } else {
2973                 n_channels = 0;
2974
2975                 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2976                         if (wiphy->bands[band])
2977                                 n_channels += wiphy->bands[band]->n_channels;
2978         }
2979
2980         if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2981                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2982                         n_ssids++;
2983
2984         if (n_ssids > wiphy->max_scan_ssids) {
2985                 err = -EINVAL;
2986                 goto out;
2987         }
2988
2989         if (info->attrs[NL80211_ATTR_IE])
2990                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2991         else
2992                 ie_len = 0;
2993
2994         if (ie_len > wiphy->max_scan_ie_len) {
2995                 err = -EINVAL;
2996                 goto out;
2997         }
2998
2999         request = kzalloc(sizeof(*request)
3000                         + sizeof(*ssid) * n_ssids
3001                         + sizeof(channel) * n_channels
3002                         + ie_len, GFP_KERNEL);
3003         if (!request) {
3004                 err = -ENOMEM;
3005                 goto out;
3006         }
3007
3008         if (n_ssids)
3009                 request->ssids = (void *)&request->channels[n_channels];
3010         request->n_ssids = n_ssids;
3011         if (ie_len) {
3012                 if (request->ssids)
3013                         request->ie = (void *)(request->ssids + n_ssids);
3014                 else
3015                         request->ie = (void *)(request->channels + n_channels);
3016         }
3017
3018         i = 0;
3019         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3020                 /* user specified, bail out if channel not found */
3021                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3022                         struct ieee80211_channel *chan;
3023
3024                         chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3025
3026                         if (!chan) {
3027                                 err = -EINVAL;
3028                                 goto out_free;
3029                         }
3030
3031                         /* ignore disabled channels */
3032                         if (chan->flags & IEEE80211_CHAN_DISABLED)
3033                                 continue;
3034
3035                         request->channels[i] = chan;
3036                         i++;
3037                 }
3038         } else {
3039                 /* all channels */
3040                 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3041                         int j;
3042                         if (!wiphy->bands[band])
3043                                 continue;
3044                         for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3045                                 struct ieee80211_channel *chan;
3046
3047                                 chan = &wiphy->bands[band]->channels[j];
3048
3049                                 if (chan->flags & IEEE80211_CHAN_DISABLED)
3050                                         continue;
3051
3052                                 request->channels[i] = chan;
3053                                 i++;
3054                         }
3055                 }
3056         }
3057
3058         if (!i) {
3059                 err = -EINVAL;
3060                 goto out_free;
3061         }
3062
3063         request->n_channels = i;
3064
3065         i = 0;
3066         if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3067                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3068                         if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3069                                 err = -EINVAL;
3070                                 goto out_free;
3071                         }
3072                         memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3073                         request->ssids[i].ssid_len = nla_len(attr);
3074                         i++;
3075                 }
3076         }
3077
3078         if (info->attrs[NL80211_ATTR_IE]) {
3079                 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3080                 memcpy((void *)request->ie,
3081                        nla_data(info->attrs[NL80211_ATTR_IE]),
3082                        request->ie_len);
3083         }
3084
3085         request->dev = dev;
3086         request->wiphy = &rdev->wiphy;
3087
3088         rdev->scan_req = request;
3089         err = rdev->ops->scan(&rdev->wiphy, dev, request);
3090
3091         if (!err) {
3092                 nl80211_send_scan_start(rdev, dev);
3093                 dev_hold(dev);
3094         }
3095
3096  out_free:
3097         if (err) {
3098                 rdev->scan_req = NULL;
3099                 kfree(request);
3100         }
3101  out:
3102         cfg80211_unlock_rdev(rdev);
3103         dev_put(dev);
3104  out_rtnl:
3105         rtnl_unlock();
3106
3107         return err;
3108 }
3109
3110 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3111                             struct cfg80211_registered_device *rdev,
3112                             struct wireless_dev *wdev,
3113                             struct cfg80211_internal_bss *intbss)
3114 {
3115         struct cfg80211_bss *res = &intbss->pub;
3116         void *hdr;
3117         struct nlattr *bss;
3118         int i;
3119
3120         ASSERT_WDEV_LOCK(wdev);
3121
3122         hdr = nl80211hdr_put(msg, pid, seq, flags,
3123                              NL80211_CMD_NEW_SCAN_RESULTS);
3124         if (!hdr)
3125                 return -1;
3126
3127         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3128         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3129
3130         bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3131         if (!bss)
3132                 goto nla_put_failure;
3133         if (!is_zero_ether_addr(res->bssid))
3134                 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3135         if (res->information_elements && res->len_information_elements)
3136                 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3137                         res->len_information_elements,
3138                         res->information_elements);
3139         if (res->tsf)
3140                 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3141         if (res->beacon_interval)
3142                 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3143         NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3144         NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3145         NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3146                 jiffies_to_msecs(jiffies - intbss->ts));
3147
3148         switch (rdev->wiphy.signal_type) {
3149         case CFG80211_SIGNAL_TYPE_MBM:
3150                 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3151                 break;
3152         case CFG80211_SIGNAL_TYPE_UNSPEC:
3153                 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3154                 break;
3155         default:
3156                 break;
3157         }
3158
3159         switch (wdev->iftype) {
3160         case NL80211_IFTYPE_STATION:
3161                 if (intbss == wdev->current_bss)
3162                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3163                                     NL80211_BSS_STATUS_ASSOCIATED);
3164                 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3165                         if (intbss != wdev->auth_bsses[i])
3166                                 continue;
3167                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3168                                     NL80211_BSS_STATUS_AUTHENTICATED);
3169                         break;
3170                 }
3171                 break;
3172         case NL80211_IFTYPE_ADHOC:
3173                 if (intbss == wdev->current_bss)
3174                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3175                                     NL80211_BSS_STATUS_IBSS_JOINED);
3176                 break;
3177         default:
3178                 break;
3179         }
3180
3181         nla_nest_end(msg, bss);
3182
3183         return genlmsg_end(msg, hdr);
3184
3185  nla_put_failure:
3186         genlmsg_cancel(msg, hdr);
3187         return -EMSGSIZE;
3188 }
3189
3190 static int nl80211_dump_scan(struct sk_buff *skb,
3191                              struct netlink_callback *cb)
3192 {
3193         struct cfg80211_registered_device *rdev;
3194         struct net_device *dev;
3195         struct cfg80211_internal_bss *scan;
3196         struct wireless_dev *wdev;
3197         int ifidx = cb->args[0];
3198         int start = cb->args[1], idx = 0;
3199         int err;
3200
3201         if (!ifidx) {
3202                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
3203                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
3204                                   nl80211_policy);
3205                 if (err)
3206                         return err;
3207
3208                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
3209                         return -EINVAL;
3210
3211                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
3212                 if (!ifidx)
3213                         return -EINVAL;
3214                 cb->args[0] = ifidx;
3215         }
3216
3217         dev = dev_get_by_index(sock_net(skb->sk), ifidx);
3218         if (!dev)
3219                 return -ENODEV;
3220
3221         rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3222         if (IS_ERR(rdev)) {
3223                 err = PTR_ERR(rdev);
3224                 goto out_put_netdev;
3225         }
3226
3227         wdev = dev->ieee80211_ptr;
3228
3229         wdev_lock(wdev);
3230         spin_lock_bh(&rdev->bss_lock);
3231         cfg80211_bss_expire(rdev);
3232
3233         list_for_each_entry(scan, &rdev->bss_list, list) {
3234                 if (++idx <= start)
3235                         continue;
3236                 if (nl80211_send_bss(skb,
3237                                 NETLINK_CB(cb->skb).pid,
3238                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3239                                 rdev, wdev, scan) < 0) {
3240                         idx--;
3241                         goto out;
3242                 }
3243         }
3244
3245  out:
3246         spin_unlock_bh(&rdev->bss_lock);
3247         wdev_unlock(wdev);
3248
3249         cb->args[1] = idx;
3250         err = skb->len;
3251         cfg80211_unlock_rdev(rdev);
3252  out_put_netdev:
3253         dev_put(dev);
3254
3255         return err;
3256 }
3257
3258 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3259 {
3260         return auth_type <= NL80211_AUTHTYPE_MAX;
3261 }
3262
3263 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3264 {
3265         return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3266                                   NL80211_WPA_VERSION_2));
3267 }
3268
3269 static bool nl80211_valid_akm_suite(u32 akm)
3270 {
3271         return akm == WLAN_AKM_SUITE_8021X ||
3272                 akm == WLAN_AKM_SUITE_PSK;
3273 }
3274
3275 static bool nl80211_valid_cipher_suite(u32 cipher)
3276 {
3277         return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3278                 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3279                 cipher == WLAN_CIPHER_SUITE_TKIP ||
3280                 cipher == WLAN_CIPHER_SUITE_CCMP ||
3281                 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3282 }
3283
3284
3285 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3286 {
3287         struct cfg80211_registered_device *rdev;
3288         struct net_device *dev;
3289         struct ieee80211_channel *chan;
3290         const u8 *bssid, *ssid, *ie = NULL;
3291         int err, ssid_len, ie_len = 0;
3292         enum nl80211_auth_type auth_type;
3293         struct key_parse key;
3294
3295         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3296                 return -EINVAL;
3297
3298         if (!info->attrs[NL80211_ATTR_MAC])
3299                 return -EINVAL;
3300
3301         if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3302                 return -EINVAL;
3303
3304         if (!info->attrs[NL80211_ATTR_SSID])
3305                 return -EINVAL;
3306
3307         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3308                 return -EINVAL;
3309
3310         err = nl80211_parse_key(info, &key);
3311         if (err)
3312                 return err;
3313
3314         if (key.idx >= 0) {
3315                 if (!key.p.key || !key.p.key_len)
3316                         return -EINVAL;
3317                 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3318                      key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3319                     (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3320                      key.p.key_len != WLAN_KEY_LEN_WEP104))
3321                         return -EINVAL;
3322                 if (key.idx > 4)
3323                         return -EINVAL;
3324         } else {
3325                 key.p.key_len = 0;
3326                 key.p.key = NULL;
3327         }
3328
3329         rtnl_lock();
3330
3331         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3332         if (err)
3333                 goto unlock_rtnl;
3334
3335         if (!rdev->ops->auth) {
3336                 err = -EOPNOTSUPP;
3337                 goto out;
3338         }
3339
3340         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3341                 err = -EOPNOTSUPP;
3342                 goto out;
3343         }
3344
3345         if (!netif_running(dev)) {
3346                 err = -ENETDOWN;
3347                 goto out;
3348         }
3349
3350         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3351         chan = ieee80211_get_channel(&rdev->wiphy,
3352                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3353         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3354                 err = -EINVAL;
3355                 goto out;
3356         }
3357
3358         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3359         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3360
3361         if (info->attrs[NL80211_ATTR_IE]) {
3362                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3363                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3364         }
3365
3366         auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3367         if (!nl80211_valid_auth_type(auth_type)) {
3368                 err = -EINVAL;
3369                 goto out;
3370         }
3371
3372         err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3373                                  ssid, ssid_len, ie, ie_len,
3374                                  key.p.key, key.p.key_len, key.idx);
3375
3376 out:
3377         cfg80211_unlock_rdev(rdev);
3378         dev_put(dev);
3379 unlock_rtnl:
3380         rtnl_unlock();
3381         return err;
3382 }
3383
3384 static int nl80211_crypto_settings(struct genl_info *info,
3385                                    struct cfg80211_crypto_settings *settings,
3386                                    int cipher_limit)
3387 {
3388         memset(settings, 0, sizeof(*settings));
3389
3390         settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3391
3392         if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3393                 void *data;
3394                 int len, i;
3395
3396                 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3397                 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3398                 settings->n_ciphers_pairwise = len / sizeof(u32);
3399
3400                 if (len % sizeof(u32))
3401                         return -EINVAL;
3402
3403                 if (settings->n_ciphers_pairwise > cipher_limit)
3404                         return -EINVAL;
3405
3406                 memcpy(settings->ciphers_pairwise, data, len);
3407
3408                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3409                         if (!nl80211_valid_cipher_suite(
3410                                         settings->ciphers_pairwise[i]))
3411                                 return -EINVAL;
3412         }
3413
3414         if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3415                 settings->cipher_group =
3416                         nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3417                 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3418                         return -EINVAL;
3419         }
3420
3421         if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3422                 settings->wpa_versions =
3423                         nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3424                 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3425                         return -EINVAL;
3426         }
3427
3428         if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3429                 void *data;
3430                 int len, i;
3431
3432                 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3433                 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3434                 settings->n_akm_suites = len / sizeof(u32);
3435
3436                 if (len % sizeof(u32))
3437                         return -EINVAL;
3438
3439                 memcpy(settings->akm_suites, data, len);
3440
3441                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3442                         if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3443                                 return -EINVAL;
3444         }
3445
3446         return 0;
3447 }
3448
3449 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3450 {
3451         struct cfg80211_registered_device *rdev;
3452         struct net_device *dev;
3453         struct cfg80211_crypto_settings crypto;
3454         struct ieee80211_channel *chan, *fixedchan;
3455         const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
3456         int err, ssid_len, ie_len = 0;
3457         bool use_mfp = false;
3458
3459         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3460                 return -EINVAL;
3461
3462         if (!info->attrs[NL80211_ATTR_MAC] ||
3463             !info->attrs[NL80211_ATTR_SSID] ||
3464             !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3465                 return -EINVAL;
3466
3467         rtnl_lock();
3468
3469         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3470         if (err)
3471                 goto unlock_rtnl;
3472
3473         if (!rdev->ops->assoc) {
3474                 err = -EOPNOTSUPP;
3475                 goto out;
3476         }
3477
3478         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3479                 err = -EOPNOTSUPP;
3480                 goto out;
3481         }
3482
3483         if (!netif_running(dev)) {
3484                 err = -ENETDOWN;
3485                 goto out;
3486         }
3487
3488         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3489
3490         chan = ieee80211_get_channel(&rdev->wiphy,
3491                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3492         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3493                 err = -EINVAL;
3494                 goto out;
3495         }
3496
3497         mutex_lock(&rdev->devlist_mtx);
3498         fixedchan = rdev_fixed_channel(rdev, NULL);
3499         if (fixedchan && chan != fixedchan) {
3500                 err = -EBUSY;
3501                 mutex_unlock(&rdev->devlist_mtx);
3502                 goto out;
3503         }
3504         mutex_unlock(&rdev->devlist_mtx);
3505
3506         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3507         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3508
3509         if (info->attrs[NL80211_ATTR_IE]) {
3510                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3511                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3512         }
3513
3514         if (info->attrs[NL80211_ATTR_USE_MFP]) {
3515                 enum nl80211_mfp mfp =
3516                         nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3517                 if (mfp == NL80211_MFP_REQUIRED)
3518                         use_mfp = true;
3519                 else if (mfp != NL80211_MFP_NO) {
3520                         err = -EINVAL;
3521                         goto out;
3522                 }
3523         }
3524
3525         if (info->attrs[NL80211_ATTR_PREV_BSSID])
3526                 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3527
3528         err = nl80211_crypto_settings(info, &crypto, 1);
3529         if (!err)
3530                 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3531                                           ssid, ssid_len, ie, ie_len, use_mfp,
3532                                           &crypto);
3533
3534 out:
3535         cfg80211_unlock_rdev(rdev);
3536         dev_put(dev);
3537 unlock_rtnl:
3538         rtnl_unlock();
3539         return err;
3540 }
3541
3542 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3543 {
3544         struct cfg80211_registered_device *rdev;
3545         struct net_device *dev;
3546         const u8 *ie = NULL, *bssid;
3547         int err, ie_len = 0;
3548         u16 reason_code;
3549
3550         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3551                 return -EINVAL;
3552
3553         if (!info->attrs[NL80211_ATTR_MAC])
3554                 return -EINVAL;
3555
3556         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3557                 return -EINVAL;
3558
3559         rtnl_lock();
3560
3561         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3562         if (err)
3563                 goto unlock_rtnl;
3564
3565         if (!rdev->ops->deauth) {
3566                 err = -EOPNOTSUPP;
3567                 goto out;
3568         }
3569
3570         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3571                 err = -EOPNOTSUPP;
3572                 goto out;
3573         }
3574
3575         if (!netif_running(dev)) {
3576                 err = -ENETDOWN;
3577                 goto out;
3578         }
3579
3580         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3581
3582         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3583         if (reason_code == 0) {
3584                 /* Reason Code 0 is reserved */
3585                 err = -EINVAL;
3586                 goto out;
3587         }
3588
3589         if (info->attrs[NL80211_ATTR_IE]) {
3590                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3591                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3592         }
3593
3594         err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
3595
3596 out:
3597         cfg80211_unlock_rdev(rdev);
3598         dev_put(dev);
3599 unlock_rtnl:
3600         rtnl_unlock();
3601         return err;
3602 }
3603
3604 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3605 {
3606         struct cfg80211_registered_device *rdev;
3607         struct net_device *dev;
3608         const u8 *ie = NULL, *bssid;
3609         int err, ie_len = 0;
3610         u16 reason_code;
3611
3612         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3613                 return -EINVAL;
3614
3615         if (!info->attrs[NL80211_ATTR_MAC])
3616                 return -EINVAL;
3617
3618         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3619                 return -EINVAL;
3620
3621         rtnl_lock();
3622
3623         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3624         if (err)
3625                 goto unlock_rtnl;
3626
3627         if (!rdev->ops->disassoc) {
3628                 err = -EOPNOTSUPP;
3629                 goto out;
3630         }
3631
3632         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3633                 err = -EOPNOTSUPP;
3634                 goto out;
3635         }
3636
3637         if (!netif_running(dev)) {
3638                 err = -ENETDOWN;
3639                 goto out;
3640         }
3641
3642         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3643
3644         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3645         if (reason_code == 0) {
3646                 /* Reason Code 0 is reserved */
3647                 err = -EINVAL;
3648                 goto out;
3649         }
3650
3651         if (info->attrs[NL80211_ATTR_IE]) {
3652                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3653                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3654         }
3655
3656         err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
3657
3658 out:
3659         cfg80211_unlock_rdev(rdev);
3660         dev_put(dev);
3661 unlock_rtnl:
3662         rtnl_unlock();
3663         return err;
3664 }
3665
3666 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3667 {
3668         struct cfg80211_registered_device *rdev;
3669         struct net_device *dev;
3670         struct cfg80211_ibss_params ibss;
3671         struct wiphy *wiphy;
3672         struct cfg80211_cached_keys *connkeys = NULL;
3673         int err;
3674
3675         memset(&ibss, 0, sizeof(ibss));
3676
3677         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3678                 return -EINVAL;
3679
3680         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3681             !info->attrs[NL80211_ATTR_SSID] ||
3682             !nla_len(info->attrs[NL80211_ATTR_SSID]))
3683                 return -EINVAL;
3684
3685         ibss.beacon_interval = 100;
3686
3687         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3688                 ibss.beacon_interval =
3689                         nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3690                 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3691                         return -EINVAL;
3692         }
3693
3694         rtnl_lock();
3695
3696         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3697         if (err)
3698                 goto unlock_rtnl;
3699
3700         if (!rdev->ops->join_ibss) {
3701                 err = -EOPNOTSUPP;
3702                 goto out;
3703         }
3704
3705         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3706                 err = -EOPNOTSUPP;
3707                 goto out;
3708         }
3709
3710         if (!netif_running(dev)) {
3711                 err = -ENETDOWN;
3712                 goto out;
3713         }
3714
3715         wiphy = &rdev->wiphy;
3716
3717         if (info->attrs[NL80211_ATTR_MAC])
3718                 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3719         ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3720         ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3721
3722         if (info->attrs[NL80211_ATTR_IE]) {
3723                 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3724                 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3725         }
3726
3727         ibss.channel = ieee80211_get_channel(wiphy,
3728                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3729         if (!ibss.channel ||
3730             ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3731             ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3732                 err = -EINVAL;
3733                 goto out;
3734         }
3735
3736         ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3737         ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3738
3739         if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3740                 connkeys = nl80211_parse_connkeys(rdev,
3741                                         info->attrs[NL80211_ATTR_KEYS]);
3742                 if (IS_ERR(connkeys)) {
3743                         err = PTR_ERR(connkeys);
3744                         connkeys = NULL;
3745                         goto out;
3746                 }
3747         }
3748
3749         err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
3750
3751 out:
3752         cfg80211_unlock_rdev(rdev);
3753         dev_put(dev);
3754 unlock_rtnl:
3755         if (err)
3756                 kfree(connkeys);
3757         rtnl_unlock();
3758         return err;
3759 }
3760
3761 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3762 {
3763         struct cfg80211_registered_device *rdev;
3764         struct net_device *dev;
3765         int err;
3766
3767         rtnl_lock();
3768
3769         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3770         if (err)
3771                 goto unlock_rtnl;
3772
3773         if (!rdev->ops->leave_ibss) {
3774                 err = -EOPNOTSUPP;
3775                 goto out;
3776         }
3777
3778         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3779                 err = -EOPNOTSUPP;
3780                 goto out;
3781         }
3782
3783         if (!netif_running(dev)) {
3784                 err = -ENETDOWN;
3785                 goto out;
3786         }
3787
3788         err = cfg80211_leave_ibss(rdev, dev, false);
3789
3790 out:
3791         cfg80211_unlock_rdev(rdev);
3792         dev_put(dev);
3793 unlock_rtnl:
3794         rtnl_unlock();
3795         return err;
3796 }
3797
3798 #ifdef CONFIG_NL80211_TESTMODE
3799 static struct genl_multicast_group nl80211_testmode_mcgrp = {
3800         .name = "testmode",
3801 };
3802
3803 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3804 {
3805         struct cfg80211_registered_device *rdev;
3806         int err;
3807
3808         if (!info->attrs[NL80211_ATTR_TESTDATA])
3809                 return -EINVAL;
3810
3811         rtnl_lock();
3812
3813         rdev = cfg80211_get_dev_from_info(info);
3814         if (IS_ERR(rdev)) {
3815                 err = PTR_ERR(rdev);
3816                 goto unlock_rtnl;
3817         }
3818
3819         err = -EOPNOTSUPP;
3820         if (rdev->ops->testmode_cmd) {
3821                 rdev->testmode_info = info;
3822                 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3823                                 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3824                                 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3825                 rdev->testmode_info = NULL;
3826         }
3827
3828         cfg80211_unlock_rdev(rdev);
3829
3830  unlock_rtnl:
3831         rtnl_unlock();
3832         return err;
3833 }
3834
3835 static struct sk_buff *
3836 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3837                               int approxlen, u32 pid, u32 seq, gfp_t gfp)
3838 {
3839         struct sk_buff *skb;
3840         void *hdr;
3841         struct nlattr *data;
3842
3843         skb = nlmsg_new(approxlen + 100, gfp);
3844         if (!skb)
3845                 return NULL;
3846
3847         hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3848         if (!hdr) {
3849                 kfree_skb(skb);
3850                 return NULL;
3851         }
3852
3853         NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3854         data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3855
3856         ((void **)skb->cb)[0] = rdev;
3857         ((void **)skb->cb)[1] = hdr;
3858         ((void **)skb->cb)[2] = data;
3859
3860         return skb;
3861
3862  nla_put_failure:
3863         kfree_skb(skb);
3864         return NULL;
3865 }
3866
3867 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3868                                                   int approxlen)
3869 {
3870         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3871
3872         if (WARN_ON(!rdev->testmode_info))
3873                 return NULL;
3874
3875         return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3876                                 rdev->testmode_info->snd_pid,
3877                                 rdev->testmode_info->snd_seq,
3878                                 GFP_KERNEL);
3879 }
3880 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3881
3882 int cfg80211_testmode_reply(struct sk_buff *skb)
3883 {
3884         struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3885         void *hdr = ((void **)skb->cb)[1];
3886         struct nlattr *data = ((void **)skb->cb)[2];
3887
3888         if (WARN_ON(!rdev->testmode_info)) {
3889                 kfree_skb(skb);
3890                 return -EINVAL;
3891         }
3892
3893         nla_nest_end(skb, data);
3894         genlmsg_end(skb, hdr);
3895         return genlmsg_reply(skb, rdev->testmode_info);
3896 }
3897 EXPORT_SYMBOL(cfg80211_testmode_reply);
3898
3899 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3900                                                   int approxlen, gfp_t gfp)
3901 {
3902         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3903
3904         return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3905 }
3906 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3907
3908 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3909 {
3910         void *hdr = ((void **)skb->cb)[1];
3911         struct nlattr *data = ((void **)skb->cb)[2];
3912
3913         nla_nest_end(skb, data);
3914         genlmsg_end(skb, hdr);
3915         genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
3916 }
3917 EXPORT_SYMBOL(cfg80211_testmode_event);
3918 #endif
3919
3920 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
3921 {
3922         struct cfg80211_registered_device *rdev;
3923         struct net_device *dev;
3924         struct cfg80211_connect_params connect;
3925         struct wiphy *wiphy;
3926         struct cfg80211_cached_keys *connkeys = NULL;
3927         int err;
3928
3929         memset(&connect, 0, sizeof(connect));
3930
3931         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3932                 return -EINVAL;
3933
3934         if (!info->attrs[NL80211_ATTR_SSID] ||
3935             !nla_len(info->attrs[NL80211_ATTR_SSID]))
3936                 return -EINVAL;
3937
3938         if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3939                 connect.auth_type =
3940                         nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3941                 if (!nl80211_valid_auth_type(connect.auth_type))
3942                         return -EINVAL;
3943         } else
3944                 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3945
3946         connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
3947
3948         err = nl80211_crypto_settings(info, &connect.crypto,
3949                                       NL80211_MAX_NR_CIPHER_SUITES);
3950         if (err)
3951                 return err;
3952         rtnl_lock();
3953
3954         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3955         if (err)
3956                 goto unlock_rtnl;
3957
3958         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3959                 err = -EOPNOTSUPP;
3960                 goto out;
3961         }
3962
3963         if (!netif_running(dev)) {
3964                 err = -ENETDOWN;
3965                 goto out;
3966         }
3967
3968         wiphy = &rdev->wiphy;
3969
3970         if (info->attrs[NL80211_ATTR_MAC])
3971                 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3972         connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3973         connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3974
3975         if (info->attrs[NL80211_ATTR_IE]) {
3976                 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3977                 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3978         }
3979
3980         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3981                 connect.channel =
3982                         ieee80211_get_channel(wiphy,
3983                             nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3984                 if (!connect.channel ||
3985                     connect.channel->flags & IEEE80211_CHAN_DISABLED) {
3986                         err = -EINVAL;
3987                         goto out;
3988                 }
3989         }
3990
3991         if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3992                 connkeys = nl80211_parse_connkeys(rdev,
3993                                         info->attrs[NL80211_ATTR_KEYS]);
3994                 if (IS_ERR(connkeys)) {
3995                         err = PTR_ERR(connkeys);
3996                         connkeys = NULL;
3997                         goto out;
3998                 }
3999         }
4000
4001         err = cfg80211_connect(rdev, dev, &connect, connkeys);
4002
4003 out:
4004         cfg80211_unlock_rdev(rdev);
4005         dev_put(dev);
4006 unlock_rtnl:
4007         if (err)
4008                 kfree(connkeys);
4009         rtnl_unlock();
4010         return err;
4011 }
4012
4013 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4014 {
4015         struct cfg80211_registered_device *rdev;
4016         struct net_device *dev;
4017         int err;
4018         u16 reason;
4019
4020         if (!info->attrs[NL80211_ATTR_REASON_CODE])
4021                 reason = WLAN_REASON_DEAUTH_LEAVING;
4022         else
4023                 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4024
4025         if (reason == 0)
4026                 return -EINVAL;
4027
4028         rtnl_lock();
4029
4030         err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4031         if (err)
4032                 goto unlock_rtnl;
4033
4034         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4035                 err = -EOPNOTSUPP;
4036                 goto out;
4037         }
4038
4039         if (!netif_running(dev)) {
4040                 err = -ENETDOWN;
4041                 goto out;
4042         }
4043
4044         err = cfg80211_disconnect(rdev, dev, reason, true);
4045
4046 out:
4047         cfg80211_unlock_rdev(rdev);
4048         dev_put(dev);
4049 unlock_rtnl:
4050         rtnl_unlock();
4051         return err;
4052 }
4053
4054 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4055 {
4056         struct cfg80211_registered_device *rdev;
4057         struct net *net;
4058         int err;
4059         u32 pid;
4060
4061         if (!info->attrs[NL80211_ATTR_PID])
4062                 return -EINVAL;
4063
4064         pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4065
4066         rtnl_lock();
4067
4068         rdev = cfg80211_get_dev_from_info(info);
4069         if (IS_ERR(rdev)) {
4070                 err = PTR_ERR(rdev);
4071                 goto out_rtnl;
4072         }
4073
4074         net = get_net_ns_by_pid(pid);
4075         if (IS_ERR(net)) {
4076                 err = PTR_ERR(net);
4077                 goto out;
4078         }
4079
4080         err = 0;
4081
4082         /* check if anything to do */
4083         if (net_eq(wiphy_net(&rdev->wiphy), net))
4084                 goto out_put_net;
4085
4086         err = cfg80211_switch_netns(rdev, net);
4087  out_put_net:
4088         put_net(net);
4089  out:
4090         cfg80211_unlock_rdev(rdev);
4091  out_rtnl:
4092         rtnl_unlock();
4093         return err;
4094 }
4095
4096 static struct genl_ops nl80211_ops[] = {
4097         {
4098                 .cmd = NL80211_CMD_GET_WIPHY,
4099                 .doit = nl80211_get_wiphy,
4100                 .dumpit = nl80211_dump_wiphy,
4101                 .policy = nl80211_policy,
4102                 /* can be retrieved by unprivileged users */
4103         },
4104         {
4105                 .cmd = NL80211_CMD_SET_WIPHY,
4106                 .doit = nl80211_set_wiphy,
4107                 .policy = nl80211_policy,
4108                 .flags = GENL_ADMIN_PERM,
4109         },
4110         {
4111                 .cmd = NL80211_CMD_GET_INTERFACE,
4112                 .doit = nl80211_get_interface,
4113                 .dumpit = nl80211_dump_interface,
4114                 .policy = nl80211_policy,
4115                 /* can be retrieved by unprivileged users */
4116         },
4117         {
4118                 .cmd = NL80211_CMD_SET_INTERFACE,
4119                 .doit = nl80211_set_interface,
4120                 .policy = nl80211_policy,
4121                 .flags = GENL_ADMIN_PERM,
4122         },
4123         {
4124                 .cmd = NL80211_CMD_NEW_INTERFACE,
4125                 .doit = nl80211_new_interface,
4126                 .policy = nl80211_policy,
4127                 .flags = GENL_ADMIN_PERM,
4128         },
4129         {
4130                 .cmd = NL80211_CMD_DEL_INTERFACE,
4131                 .doit = nl80211_del_interface,
4132                 .policy = nl80211_policy,
4133                 .flags = GENL_ADMIN_PERM,
4134         },
4135         {
4136                 .cmd = NL80211_CMD_GET_KEY,
4137                 .doit = nl80211_get_key,
4138                 .policy = nl80211_policy,
4139                 .flags = GENL_ADMIN_PERM,
4140         },
4141         {
4142                 .cmd = NL80211_CMD_SET_KEY,
4143                 .doit = nl80211_set_key,
4144                 .policy = nl80211_policy,
4145                 .flags = GENL_ADMIN_PERM,
4146         },
4147         {
4148                 .cmd = NL80211_CMD_NEW_KEY,
4149                 .doit = nl80211_new_key,
4150                 .policy = nl80211_policy,
4151                 .flags = GENL_ADMIN_PERM,
4152         },
4153         {
4154                 .cmd = NL80211_CMD_DEL_KEY,
4155                 .doit = nl80211_del_key,
4156                 .policy = nl80211_policy,
4157                 .flags = GENL_ADMIN_PERM,
4158         },
4159         {
4160                 .cmd = NL80211_CMD_SET_BEACON,
4161                 .policy = nl80211_policy,
4162                 .flags = GENL_ADMIN_PERM,
4163                 .doit = nl80211_addset_beacon,
4164         },
4165         {
4166                 .cmd = NL80211_CMD_NEW_BEACON,
4167                 .policy = nl80211_policy,
4168                 .flags = GENL_ADMIN_PERM,
4169                 .doit = nl80211_addset_beacon,
4170         },
4171         {
4172                 .cmd = NL80211_CMD_DEL_BEACON,
4173                 .policy = nl80211_policy,
4174                 .flags = GENL_ADMIN_PERM,
4175                 .doit = nl80211_del_beacon,
4176         },
4177         {
4178                 .cmd = NL80211_CMD_GET_STATION,
4179                 .doit = nl80211_get_station,
4180                 .dumpit = nl80211_dump_station,
4181                 .policy = nl80211_policy,
4182         },
4183         {
4184                 .cmd = NL80211_CMD_SET_STATION,
4185                 .doit = nl80211_set_station,
4186                 .policy = nl80211_policy,
4187                 .flags = GENL_ADMIN_PERM,
4188         },
4189         {
4190                 .cmd = NL80211_CMD_NEW_STATION,
4191                 .doit = nl80211_new_station,
4192                 .policy = nl80211_policy,
4193                 .flags = GENL_ADMIN_PERM,
4194         },
4195         {
4196                 .cmd = NL80211_CMD_DEL_STATION,
4197                 .doit = nl80211_del_station,
4198                 .policy = nl80211_policy,
4199                 .flags = GENL_ADMIN_PERM,
4200         },
4201         {
4202                 .cmd = NL80211_CMD_GET_MPATH,
4203                 .doit = nl80211_get_mpath,
4204                 .dumpit = nl80211_dump_mpath,
4205                 .policy = nl80211_policy,
4206                 .flags = GENL_ADMIN_PERM,
4207         },
4208         {
4209                 .cmd = NL80211_CMD_SET_MPATH,
4210                 .doit = nl80211_set_mpath,
4211                 .policy = nl80211_policy,
4212                 .flags = GENL_ADMIN_PERM,
4213         },
4214         {
4215                 .cmd = NL80211_CMD_NEW_MPATH,
4216                 .doit = nl80211_new_mpath,
4217                 .policy = nl80211_policy,
4218                 .flags = GENL_ADMIN_PERM,
4219         },
4220         {
4221                 .cmd = NL80211_CMD_DEL_MPATH,
4222                 .doit = nl80211_del_mpath,
4223                 .policy = nl80211_policy,
4224                 .flags = GENL_ADMIN_PERM,
4225         },
4226         {
4227                 .cmd = NL80211_CMD_SET_BSS,
4228                 .doit = nl80211_set_bss,
4229                 .policy = nl80211_policy,
4230                 .flags = GENL_ADMIN_PERM,
4231         },
4232         {
4233                 .cmd = NL80211_CMD_GET_REG,
4234                 .doit = nl80211_get_reg,
4235                 .policy = nl80211_policy,
4236                 /* can be retrieved by unprivileged users */
4237         },
4238         {
4239                 .cmd = NL80211_CMD_SET_REG,
4240                 .doit = nl80211_set_reg,
4241                 .policy = nl80211_policy,
4242                 .flags = GENL_ADMIN_PERM,
4243         },
4244         {
4245                 .cmd = NL80211_CMD_REQ_SET_REG,
4246                 .doit = nl80211_req_set_reg,
4247                 .policy = nl80211_policy,
4248                 .flags = GENL_ADMIN_PERM,
4249         },
4250         {
4251                 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4252                 .doit = nl80211_get_mesh_params,
4253                 .policy = nl80211_policy,
4254                 /* can be retrieved by unprivileged users */
4255         },
4256         {
4257                 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4258                 .doit = nl80211_set_mesh_params,
4259                 .policy = nl80211_policy,
4260                 .flags = GENL_ADMIN_PERM,
4261         },
4262         {
4263                 .cmd = NL80211_CMD_TRIGGER_SCAN,
4264                 .doit = nl80211_trigger_scan,
4265                 .policy = nl80211_policy,
4266                 .flags = GENL_ADMIN_PERM,
4267         },
4268         {
4269                 .cmd = NL80211_CMD_GET_SCAN,
4270                 .policy = nl80211_policy,
4271                 .dumpit = nl80211_dump_scan,
4272         },
4273         {
4274                 .cmd = NL80211_CMD_AUTHENTICATE,
4275                 .doit = nl80211_authenticate,
4276                 .policy = nl80211_policy,
4277                 .flags = GENL_ADMIN_PERM,
4278         },
4279         {
4280                 .cmd = NL80211_CMD_ASSOCIATE,
4281                 .doit = nl80211_associate,
4282                 .policy = nl80211_policy,
4283                 .flags = GENL_ADMIN_PERM,
4284         },
4285         {
4286                 .cmd = NL80211_CMD_DEAUTHENTICATE,
4287                 .doit = nl80211_deauthenticate,
4288                 .policy = nl80211_policy,
4289                 .flags = GENL_ADMIN_PERM,
4290         },
4291         {
4292                 .cmd = NL80211_CMD_DISASSOCIATE,
4293                 .doit = nl80211_disassociate,
4294                 .policy = nl80211_policy,
4295                 .flags = GENL_ADMIN_PERM,
4296         },
4297         {
4298                 .cmd = NL80211_CMD_JOIN_IBSS,
4299                 .doit = nl80211_join_ibss,
4300                 .policy = nl80211_policy,
4301                 .flags = GENL_ADMIN_PERM,
4302         },
4303         {
4304                 .cmd = NL80211_CMD_LEAVE_IBSS,
4305                 .doit = nl80211_leave_ibss,
4306                 .policy = nl80211_policy,
4307                 .flags = GENL_ADMIN_PERM,
4308         },
4309 #ifdef CONFIG_NL80211_TESTMODE
4310         {
4311                 .cmd = NL80211_CMD_TESTMODE,
4312                 .doit = nl80211_testmode_do,
4313                 .policy = nl80211_policy,
4314                 .flags = GENL_ADMIN_PERM,
4315         },
4316 #endif
4317         {
4318                 .cmd = NL80211_CMD_CONNECT,
4319                 .doit = nl80211_connect,
4320                 .policy = nl80211_policy,
4321                 .flags = GENL_ADMIN_PERM,
4322         },
4323         {
4324                 .cmd = NL80211_CMD_DISCONNECT,
4325                 .doit = nl80211_disconnect,
4326                 .policy = nl80211_policy,
4327                 .flags = GENL_ADMIN_PERM,
4328         },
4329         {
4330                 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4331                 .doit = nl80211_wiphy_netns,
4332                 .policy = nl80211_policy,
4333                 .flags = GENL_ADMIN_PERM,
4334         },
4335 };
4336 static struct genl_multicast_group nl80211_mlme_mcgrp = {
4337         .name = "mlme",
4338 };
4339
4340 /* multicast groups */
4341 static struct genl_multicast_group nl80211_config_mcgrp = {
4342         .name = "config",
4343 };
4344 static struct genl_multicast_group nl80211_scan_mcgrp = {
4345         .name = "scan",
4346 };
4347 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4348         .name = "regulatory",
4349 };
4350
4351 /* notification functions */
4352
4353 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4354 {
4355         struct sk_buff *msg;
4356
4357         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4358         if (!msg)
4359                 return;
4360
4361         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4362                 nlmsg_free(msg);
4363                 return;
4364         }
4365
4366         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4367                                 nl80211_config_mcgrp.id, GFP_KERNEL);
4368 }
4369
4370 static int nl80211_add_scan_req(struct sk_buff *msg,
4371                                 struct cfg80211_registered_device *rdev)
4372 {
4373         struct cfg80211_scan_request *req = rdev->scan_req;
4374         struct nlattr *nest;
4375         int i;
4376
4377         ASSERT_RDEV_LOCK(rdev);
4378
4379         if (WARN_ON(!req))
4380                 return 0;
4381
4382         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4383         if (!nest)
4384                 goto nla_put_failure;
4385         for (i = 0; i < req->n_ssids; i++)
4386                 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4387         nla_nest_end(msg, nest);
4388
4389         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4390         if (!nest)
4391                 goto nla_put_failure;
4392         for (i = 0; i < req->n_channels; i++)
4393                 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4394         nla_nest_end(msg, nest);
4395
4396         if (req->ie)
4397                 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4398
4399         return 0;
4400  nla_put_failure:
4401         return -ENOBUFS;
4402 }
4403
4404 static int nl80211_send_scan_msg(struct sk_buff *msg,
4405                                  struct cfg80211_registered_device *rdev,
4406                                  struct net_device *netdev,
4407                                  u32 pid, u32 seq, int flags,
4408                                  u32 cmd)
4409 {
4410         void *hdr;
4411
4412         hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4413         if (!hdr)
4414                 return -1;
4415
4416         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4417         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4418
4419         /* ignore errors and send incomplete event anyway */
4420         nl80211_add_scan_req(msg, rdev);
4421
4422         return genlmsg_end(msg, hdr);
4423
4424  nla_put_failure:
4425         genlmsg_cancel(msg, hdr);
4426         return -EMSGSIZE;
4427 }
4428
4429 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4430                              struct net_device *netdev)
4431 {
4432         struct sk_buff *msg;
4433
4434         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4435         if (!msg)
4436                 return;
4437
4438         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4439                                   NL80211_CMD_TRIGGER_SCAN) < 0) {
4440                 nlmsg_free(msg);
4441                 return;
4442         }
4443
4444         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4445                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
4446 }
4447
4448 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4449                             struct net_device *netdev)
4450 {
4451         struct sk_buff *msg;
4452
4453         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4454         if (!msg)
4455                 return;
4456
4457         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4458                                   NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
4459                 nlmsg_free(msg);
4460                 return;
4461         }
4462
4463         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4464                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
4465 }
4466
4467 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4468                                struct net_device *netdev)
4469 {
4470         struct sk_buff *msg;
4471
4472         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4473         if (!msg)
4474                 return;
4475
4476         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4477                                   NL80211_CMD_SCAN_ABORTED) < 0) {
4478                 nlmsg_free(msg);
4479                 return;
4480         }
4481
4482         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4483                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
4484 }
4485
4486 /*
4487  * This can happen on global regulatory changes or device specific settings
4488  * based on custom world regulatory domains.
4489  */
4490 void nl80211_send_reg_change_event(struct regulatory_request *request)
4491 {
4492         struct sk_buff *msg;
4493         void *hdr;
4494
4495         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4496         if (!msg)
4497                 return;
4498
4499         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4500         if (!hdr) {
4501                 nlmsg_free(msg);
4502                 return;
4503         }
4504
4505         /* Userspace can always count this one always being set */
4506         NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
4507
4508         if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
4509                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4510                            NL80211_REGDOM_TYPE_WORLD);
4511         else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
4512                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4513                            NL80211_REGDOM_TYPE_CUSTOM_WORLD);
4514         else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
4515                  request->intersect)
4516                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4517                            NL80211_REGDOM_TYPE_INTERSECTION);
4518         else {
4519                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
4520                            NL80211_REGDOM_TYPE_COUNTRY);
4521                 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
4522         }
4523
4524         if (wiphy_idx_valid(request->wiphy_idx))
4525                 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
4526
4527         if (genlmsg_end(msg, hdr) < 0) {
4528                 nlmsg_free(msg);
4529                 return;
4530         }
4531
4532         rcu_read_lock();
4533         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4534                                 GFP_ATOMIC);
4535         rcu_read_unlock();
4536
4537         return;
4538
4539 nla_put_failure:
4540         genlmsg_cancel(msg, hdr);
4541         nlmsg_free(msg);
4542 }
4543
4544 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
4545                                     struct net_device *netdev,
4546                                     const u8 *buf, size_t len,
4547                                     enum nl80211_commands cmd, gfp_t gfp)
4548 {
4549         struct sk_buff *msg;
4550         void *hdr;
4551
4552         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4553         if (!msg)
4554                 return;
4555
4556         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4557         if (!hdr) {
4558                 nlmsg_free(msg);
4559                 return;
4560         }
4561
4562         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4563         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4564         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
4565
4566         if (genlmsg_end(msg, hdr) < 0) {
4567                 nlmsg_free(msg);
4568                 return;
4569         }
4570
4571         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4572                                 nl80211_mlme_mcgrp.id, gfp);
4573         return;
4574
4575  nla_put_failure:
4576         genlmsg_cancel(msg, hdr);
4577         nlmsg_free(msg);
4578 }
4579
4580 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
4581                           struct net_device *netdev, const u8 *buf,
4582                           size_t len, gfp_t gfp)
4583 {
4584         nl80211_send_mlme_event(rdev, netdev, buf, len,
4585                                 NL80211_CMD_AUTHENTICATE, gfp);
4586 }
4587
4588 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
4589                            struct net_device *netdev, const u8 *buf,
4590                            size_t len, gfp_t gfp)
4591 {
4592         nl80211_send_mlme_event(rdev, netdev, buf, len,
4593                                 NL80211_CMD_ASSOCIATE, gfp);
4594 }
4595
4596 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
4597                          struct net_device *netdev, const u8 *buf,
4598                          size_t len, gfp_t gfp)
4599 {
4600         nl80211_send_mlme_event(rdev, netdev, buf, len,
4601                                 NL80211_CMD_DEAUTHENTICATE, gfp);
4602 }
4603
4604 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
4605                            struct net_device *netdev, const u8 *buf,
4606                            size_t len, gfp_t gfp)
4607 {
4608         nl80211_send_mlme_event(rdev, netdev, buf, len,
4609                                 NL80211_CMD_DISASSOCIATE, gfp);
4610 }
4611
4612 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
4613                                       struct net_device *netdev, int cmd,
4614                                       const u8 *addr, gfp_t gfp)
4615 {
4616         struct sk_buff *msg;
4617         void *hdr;
4618
4619         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4620         if (!msg)
4621                 return;
4622
4623         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
4624         if (!hdr) {
4625                 nlmsg_free(msg);
4626                 return;
4627         }
4628
4629         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4630         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4631         NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
4632         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4633
4634         if (genlmsg_end(msg, hdr) < 0) {
4635                 nlmsg_free(msg);
4636                 return;
4637         }
4638
4639         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4640                                 nl80211_mlme_mcgrp.id, gfp);
4641         return;
4642
4643  nla_put_failure:
4644         genlmsg_cancel(msg, hdr);
4645         nlmsg_free(msg);
4646 }
4647
4648 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
4649                                struct net_device *netdev, const u8 *addr,
4650                                gfp_t gfp)
4651 {
4652         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
4653                                   addr, gfp);
4654 }
4655
4656 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
4657                                 struct net_device *netdev, const u8 *addr,
4658                                 gfp_t gfp)
4659 {
4660         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
4661                                   addr, gfp);
4662 }
4663
4664 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
4665                                  struct net_device *netdev, const u8 *bssid,
4666                                  const u8 *req_ie, size_t req_ie_len,
4667                                  const u8 *resp_ie, size_t resp_ie_len,
4668                                  u16 status, gfp_t gfp)
4669 {
4670         struct sk_buff *msg;
4671         void *hdr;
4672
4673         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4674         if (!msg)
4675                 return;
4676
4677         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
4678         if (!hdr) {
4679                 nlmsg_free(msg);
4680                 return;
4681         }
4682
4683         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4684         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4685         if (bssid)
4686                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4687         NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
4688         if (req_ie)
4689                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4690         if (resp_ie)
4691                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4692
4693         if (genlmsg_end(msg, hdr) < 0) {
4694                 nlmsg_free(msg);
4695                 return;
4696         }
4697
4698         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4699                                 nl80211_mlme_mcgrp.id, gfp);
4700         return;
4701
4702  nla_put_failure:
4703         genlmsg_cancel(msg, hdr);
4704         nlmsg_free(msg);
4705
4706 }
4707
4708 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
4709                          struct net_device *netdev, const u8 *bssid,
4710                          const u8 *req_ie, size_t req_ie_len,
4711                          const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
4712 {
4713         struct sk_buff *msg;
4714         void *hdr;
4715
4716         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
4717         if (!msg)
4718                 return;
4719
4720         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
4721         if (!hdr) {
4722                 nlmsg_free(msg);
4723                 return;
4724         }
4725
4726         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4727         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4728         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4729         if (req_ie)
4730                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
4731         if (resp_ie)
4732                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
4733
4734         if (genlmsg_end(msg, hdr) < 0) {
4735                 nlmsg_free(msg);
4736                 return;
4737         }
4738
4739         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4740                                 nl80211_mlme_mcgrp.id, gfp);
4741         return;
4742
4743  nla_put_failure:
4744         genlmsg_cancel(msg, hdr);
4745         nlmsg_free(msg);
4746
4747 }
4748
4749 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
4750                                struct net_device *netdev, u16 reason,
4751                                const u8 *ie, size_t ie_len, bool from_ap)
4752 {
4753         struct sk_buff *msg;
4754         void *hdr;
4755
4756         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4757         if (!msg)
4758                 return;
4759
4760         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
4761         if (!hdr) {
4762                 nlmsg_free(msg);
4763                 return;
4764         }
4765
4766         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4767         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4768         if (from_ap && reason)
4769                 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
4770         if (from_ap)
4771                 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
4772         if (ie)
4773                 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
4774
4775         if (genlmsg_end(msg, hdr) < 0) {
4776                 nlmsg_free(msg);
4777                 return;
4778         }
4779
4780         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4781                                 nl80211_mlme_mcgrp.id, GFP_KERNEL);
4782         return;
4783
4784  nla_put_failure:
4785         genlmsg_cancel(msg, hdr);
4786         nlmsg_free(msg);
4787
4788 }
4789
4790 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
4791                              struct net_device *netdev, const u8 *bssid,
4792                              gfp_t gfp)
4793 {
4794         struct sk_buff *msg;
4795         void *hdr;
4796
4797         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4798         if (!msg)
4799                 return;
4800
4801         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
4802         if (!hdr) {
4803                 nlmsg_free(msg);
4804                 return;
4805         }
4806
4807         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4808         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4809         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
4810
4811         if (genlmsg_end(msg, hdr) < 0) {
4812                 nlmsg_free(msg);
4813                 return;
4814         }
4815
4816         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4817                                 nl80211_mlme_mcgrp.id, gfp);
4818         return;
4819
4820  nla_put_failure:
4821         genlmsg_cancel(msg, hdr);
4822         nlmsg_free(msg);
4823 }
4824
4825 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
4826                                  struct net_device *netdev, const u8 *addr,
4827                                  enum nl80211_key_type key_type, int key_id,
4828                                  const u8 *tsc, gfp_t gfp)
4829 {
4830         struct sk_buff *msg;
4831         void *hdr;
4832
4833         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4834         if (!msg)
4835                 return;
4836
4837         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
4838         if (!hdr) {
4839                 nlmsg_free(msg);
4840                 return;
4841         }
4842
4843         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4844         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4845         if (addr)
4846                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
4847         NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
4848         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
4849         if (tsc)
4850                 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
4851
4852         if (genlmsg_end(msg, hdr) < 0) {
4853                 nlmsg_free(msg);
4854                 return;
4855         }
4856
4857         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4858                                 nl80211_mlme_mcgrp.id, gfp);
4859         return;
4860
4861  nla_put_failure:
4862         genlmsg_cancel(msg, hdr);
4863         nlmsg_free(msg);
4864 }
4865
4866 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
4867                                     struct ieee80211_channel *channel_before,
4868                                     struct ieee80211_channel *channel_after)
4869 {
4870         struct sk_buff *msg;
4871         void *hdr;
4872         struct nlattr *nl_freq;
4873
4874         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
4875         if (!msg)
4876                 return;
4877
4878         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
4879         if (!hdr) {
4880                 nlmsg_free(msg);
4881                 return;
4882         }
4883
4884         /*
4885          * Since we are applying the beacon hint to a wiphy we know its
4886          * wiphy_idx is valid
4887          */
4888         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
4889
4890         /* Before */
4891         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
4892         if (!nl_freq)
4893                 goto nla_put_failure;
4894         if (nl80211_msg_put_channel(msg, channel_before))
4895                 goto nla_put_failure;
4896         nla_nest_end(msg, nl_freq);
4897
4898         /* After */
4899         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
4900         if (!nl_freq)
4901                 goto nla_put_failure;
4902         if (nl80211_msg_put_channel(msg, channel_after))
4903                 goto nla_put_failure;
4904         nla_nest_end(msg, nl_freq);
4905
4906         if (genlmsg_end(msg, hdr) < 0) {
4907                 nlmsg_free(msg);
4908                 return;
4909         }
4910
4911         rcu_read_lock();
4912         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4913                                 GFP_ATOMIC);
4914         rcu_read_unlock();
4915
4916         return;
4917
4918 nla_put_failure:
4919         genlmsg_cancel(msg, hdr);
4920         nlmsg_free(msg);
4921 }
4922
4923 /* initialisation/exit functions */
4924
4925 int nl80211_init(void)
4926 {
4927         int err;
4928
4929         err = genl_register_family_with_ops(&nl80211_fam,
4930                 nl80211_ops, ARRAY_SIZE(nl80211_ops));
4931         if (err)
4932                 return err;
4933
4934         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
4935         if (err)
4936                 goto err_out;
4937
4938         err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
4939         if (err)
4940                 goto err_out;
4941
4942         err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
4943         if (err)
4944                 goto err_out;
4945
4946         err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
4947         if (err)
4948                 goto err_out;
4949
4950 #ifdef CONFIG_NL80211_TESTMODE
4951         err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
4952         if (err)
4953                 goto err_out;
4954 #endif
4955
4956         return 0;
4957  err_out:
4958         genl_unregister_family(&nl80211_fam);
4959         return err;
4960 }
4961
4962 void nl80211_exit(void)
4963 {
4964         genl_unregister_family(&nl80211_fam);
4965 }