cfg80211: add assert_cfg80211_lock() to ensure proper protection
[safe/jmp/linux-2.6] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006, 2007 Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/list.h>
11 #include <linux/if_ether.h>
12 #include <linux/ieee80211.h>
13 #include <linux/nl80211.h>
14 #include <linux/rtnetlink.h>
15 #include <linux/netlink.h>
16 #include <linux/etherdevice.h>
17 #include <net/genetlink.h>
18 #include <net/cfg80211.h>
19 #include "core.h"
20 #include "nl80211.h"
21 #include "reg.h"
22
23 /* the netlink family */
24 static struct genl_family nl80211_fam = {
25         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
26         .name = "nl80211",      /* have users key off the name instead */
27         .hdrsize = 0,           /* no private header */
28         .version = 1,           /* no particular meaning now */
29         .maxattr = NL80211_ATTR_MAX,
30 };
31
32 /* internal helper: get drv and dev */
33 static int get_drv_dev_by_info_ifindex(struct nlattr **attrs,
34                                        struct cfg80211_registered_device **drv,
35                                        struct net_device **dev)
36 {
37         int ifindex;
38
39         if (!attrs[NL80211_ATTR_IFINDEX])
40                 return -EINVAL;
41
42         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
43         *dev = dev_get_by_index(&init_net, ifindex);
44         if (!*dev)
45                 return -ENODEV;
46
47         *drv = cfg80211_get_dev_from_ifindex(ifindex);
48         if (IS_ERR(*drv)) {
49                 dev_put(*dev);
50                 return PTR_ERR(*drv);
51         }
52
53         return 0;
54 }
55
56 /* policy for the attributes */
57 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
58         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
59         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
60                                       .len = BUS_ID_SIZE-1 },
61         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
62         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
63         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
64
65         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
66         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
67         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
68
69         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
70
71         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
72                                     .len = WLAN_MAX_KEY_LEN },
73         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
74         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
75         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
76
77         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
78         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
79         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
80                                        .len = IEEE80211_MAX_DATA_LEN },
81         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
82                                        .len = IEEE80211_MAX_DATA_LEN },
83         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
84         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
85         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
86         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
87                                                .len = NL80211_MAX_SUPP_RATES },
88         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
89         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
90         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
91         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
92                                 .len = IEEE80211_MAX_MESH_ID_LEN },
93         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
94
95         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
96         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
97
98         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
99         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
100         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
101         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
102                                            .len = NL80211_MAX_SUPP_RATES },
103
104         [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
105
106         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
107                                          .len = NL80211_HT_CAPABILITY_LEN },
108
109         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
110         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
111                               .len = IEEE80211_MAX_DATA_LEN },
112         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
113         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
114 };
115
116 /* message building helper */
117 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
118                                    int flags, u8 cmd)
119 {
120         /* since there is no private header just add the generic one */
121         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
122 }
123
124 /* netlink command implementations */
125
126 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
127                               struct cfg80211_registered_device *dev)
128 {
129         void *hdr;
130         struct nlattr *nl_bands, *nl_band;
131         struct nlattr *nl_freqs, *nl_freq;
132         struct nlattr *nl_rates, *nl_rate;
133         struct nlattr *nl_modes;
134         enum ieee80211_band band;
135         struct ieee80211_channel *chan;
136         struct ieee80211_rate *rate;
137         int i;
138         u16 ifmodes = dev->wiphy.interface_modes;
139
140         assert_cfg80211_lock();
141
142         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
143         if (!hdr)
144                 return -1;
145
146         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
147         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
148         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
149                    dev->wiphy.max_scan_ssids);
150
151         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
152         if (!nl_modes)
153                 goto nla_put_failure;
154
155         i = 0;
156         while (ifmodes) {
157                 if (ifmodes & 1)
158                         NLA_PUT_FLAG(msg, i);
159                 ifmodes >>= 1;
160                 i++;
161         }
162
163         nla_nest_end(msg, nl_modes);
164
165         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
166         if (!nl_bands)
167                 goto nla_put_failure;
168
169         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
170                 if (!dev->wiphy.bands[band])
171                         continue;
172
173                 nl_band = nla_nest_start(msg, band);
174                 if (!nl_band)
175                         goto nla_put_failure;
176
177                 /* add HT info */
178                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
179                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
180                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
181                                 &dev->wiphy.bands[band]->ht_cap.mcs);
182                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
183                                 dev->wiphy.bands[band]->ht_cap.cap);
184                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
185                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
186                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
187                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
188                 }
189
190                 /* add frequencies */
191                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
192                 if (!nl_freqs)
193                         goto nla_put_failure;
194
195                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
196                         nl_freq = nla_nest_start(msg, i);
197                         if (!nl_freq)
198                                 goto nla_put_failure;
199
200                         chan = &dev->wiphy.bands[band]->channels[i];
201                         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
202                                     chan->center_freq);
203
204                         if (chan->flags & IEEE80211_CHAN_DISABLED)
205                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
206                         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
207                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
208                         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
209                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
210                         if (chan->flags & IEEE80211_CHAN_RADAR)
211                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
212
213                         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
214                                     DBM_TO_MBM(chan->max_power));
215
216                         nla_nest_end(msg, nl_freq);
217                 }
218
219                 nla_nest_end(msg, nl_freqs);
220
221                 /* add bitrates */
222                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
223                 if (!nl_rates)
224                         goto nla_put_failure;
225
226                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
227                         nl_rate = nla_nest_start(msg, i);
228                         if (!nl_rate)
229                                 goto nla_put_failure;
230
231                         rate = &dev->wiphy.bands[band]->bitrates[i];
232                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
233                                     rate->bitrate);
234                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
235                                 NLA_PUT_FLAG(msg,
236                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
237
238                         nla_nest_end(msg, nl_rate);
239                 }
240
241                 nla_nest_end(msg, nl_rates);
242
243                 nla_nest_end(msg, nl_band);
244         }
245         nla_nest_end(msg, nl_bands);
246
247         return genlmsg_end(msg, hdr);
248
249  nla_put_failure:
250         genlmsg_cancel(msg, hdr);
251         return -EMSGSIZE;
252 }
253
254 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
255 {
256         int idx = 0;
257         int start = cb->args[0];
258         struct cfg80211_registered_device *dev;
259
260         mutex_lock(&cfg80211_mutex);
261         list_for_each_entry(dev, &cfg80211_drv_list, list) {
262                 if (++idx <= start)
263                         continue;
264                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
265                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
266                                        dev) < 0) {
267                         idx--;
268                         break;
269                 }
270         }
271         mutex_unlock(&cfg80211_mutex);
272
273         cb->args[0] = idx;
274
275         return skb->len;
276 }
277
278 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
279 {
280         struct sk_buff *msg;
281         struct cfg80211_registered_device *dev;
282
283         dev = cfg80211_get_dev_from_info(info);
284         if (IS_ERR(dev))
285                 return PTR_ERR(dev);
286
287         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
288         if (!msg)
289                 goto out_err;
290
291         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
292                 goto out_free;
293
294         cfg80211_put_dev(dev);
295
296         return genlmsg_unicast(msg, info->snd_pid);
297
298  out_free:
299         nlmsg_free(msg);
300  out_err:
301         cfg80211_put_dev(dev);
302         return -ENOBUFS;
303 }
304
305 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
306         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
307         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
308         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
309         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
310         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
311 };
312
313 static int parse_txq_params(struct nlattr *tb[],
314                             struct ieee80211_txq_params *txq_params)
315 {
316         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
317             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
318             !tb[NL80211_TXQ_ATTR_AIFS])
319                 return -EINVAL;
320
321         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
322         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
323         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
324         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
325         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
326
327         return 0;
328 }
329
330 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
331 {
332         struct cfg80211_registered_device *rdev;
333         int result = 0, rem_txq_params = 0;
334         struct nlattr *nl_txq_params;
335
336         rdev = cfg80211_get_dev_from_info(info);
337         if (IS_ERR(rdev))
338                 return PTR_ERR(rdev);
339
340         if (info->attrs[NL80211_ATTR_WIPHY_NAME]) {
341                 result = cfg80211_dev_rename(
342                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
343                 if (result)
344                         goto bad_res;
345         }
346
347         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
348                 struct ieee80211_txq_params txq_params;
349                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
350
351                 if (!rdev->ops->set_txq_params) {
352                         result = -EOPNOTSUPP;
353                         goto bad_res;
354                 }
355
356                 nla_for_each_nested(nl_txq_params,
357                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
358                                     rem_txq_params) {
359                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
360                                   nla_data(nl_txq_params),
361                                   nla_len(nl_txq_params),
362                                   txq_params_policy);
363                         result = parse_txq_params(tb, &txq_params);
364                         if (result)
365                                 goto bad_res;
366
367                         result = rdev->ops->set_txq_params(&rdev->wiphy,
368                                                            &txq_params);
369                         if (result)
370                                 goto bad_res;
371                 }
372         }
373
374         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
375                 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
376                 struct ieee80211_channel *chan;
377                 struct ieee80211_sta_ht_cap *ht_cap;
378                 u32 freq, sec_freq;
379
380                 if (!rdev->ops->set_channel) {
381                         result = -EOPNOTSUPP;
382                         goto bad_res;
383                 }
384
385                 result = -EINVAL;
386
387                 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
388                         channel_type = nla_get_u32(info->attrs[
389                                            NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
390                         if (channel_type != NL80211_CHAN_NO_HT &&
391                             channel_type != NL80211_CHAN_HT20 &&
392                             channel_type != NL80211_CHAN_HT40PLUS &&
393                             channel_type != NL80211_CHAN_HT40MINUS)
394                                 goto bad_res;
395                 }
396
397                 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
398                 chan = ieee80211_get_channel(&rdev->wiphy, freq);
399
400                 /* Primary channel not allowed */
401                 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
402                         goto bad_res;
403
404                 if (channel_type == NL80211_CHAN_HT40MINUS)
405                         sec_freq = freq - 20;
406                 else if (channel_type == NL80211_CHAN_HT40PLUS)
407                         sec_freq = freq + 20;
408                 else
409                         sec_freq = 0;
410
411                 ht_cap = &rdev->wiphy.bands[chan->band]->ht_cap;
412
413                 /* no HT capabilities */
414                 if (channel_type != NL80211_CHAN_NO_HT &&
415                     !ht_cap->ht_supported)
416                         goto bad_res;
417
418                 if (sec_freq) {
419                         struct ieee80211_channel *schan;
420
421                         /* no 40 MHz capabilities */
422                         if (!(ht_cap->cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40) ||
423                             (ht_cap->cap & IEEE80211_HT_CAP_40MHZ_INTOLERANT))
424                                 goto bad_res;
425
426                         schan = ieee80211_get_channel(&rdev->wiphy, sec_freq);
427
428                         /* Secondary channel not allowed */
429                         if (!schan || schan->flags & IEEE80211_CHAN_DISABLED)
430                                 goto bad_res;
431                 }
432
433                 result = rdev->ops->set_channel(&rdev->wiphy, chan,
434                                                 channel_type);
435                 if (result)
436                         goto bad_res;
437         }
438
439
440  bad_res:
441         cfg80211_put_dev(rdev);
442         return result;
443 }
444
445
446 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
447                               struct net_device *dev)
448 {
449         void *hdr;
450
451         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
452         if (!hdr)
453                 return -1;
454
455         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
456         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
457         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
458         return genlmsg_end(msg, hdr);
459
460  nla_put_failure:
461         genlmsg_cancel(msg, hdr);
462         return -EMSGSIZE;
463 }
464
465 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
466 {
467         int wp_idx = 0;
468         int if_idx = 0;
469         int wp_start = cb->args[0];
470         int if_start = cb->args[1];
471         struct cfg80211_registered_device *dev;
472         struct wireless_dev *wdev;
473
474         mutex_lock(&cfg80211_mutex);
475         list_for_each_entry(dev, &cfg80211_drv_list, list) {
476                 if (wp_idx < wp_start) {
477                         wp_idx++;
478                         continue;
479                 }
480                 if_idx = 0;
481
482                 mutex_lock(&dev->devlist_mtx);
483                 list_for_each_entry(wdev, &dev->netdev_list, list) {
484                         if (if_idx < if_start) {
485                                 if_idx++;
486                                 continue;
487                         }
488                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
489                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
490                                                wdev->netdev) < 0) {
491                                 mutex_unlock(&dev->devlist_mtx);
492                                 goto out;
493                         }
494                         if_idx++;
495                 }
496                 mutex_unlock(&dev->devlist_mtx);
497
498                 wp_idx++;
499         }
500  out:
501         mutex_unlock(&cfg80211_mutex);
502
503         cb->args[0] = wp_idx;
504         cb->args[1] = if_idx;
505
506         return skb->len;
507 }
508
509 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
510 {
511         struct sk_buff *msg;
512         struct cfg80211_registered_device *dev;
513         struct net_device *netdev;
514         int err;
515
516         err = get_drv_dev_by_info_ifindex(info->attrs, &dev, &netdev);
517         if (err)
518                 return err;
519
520         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
521         if (!msg)
522                 goto out_err;
523
524         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0, netdev) < 0)
525                 goto out_free;
526
527         dev_put(netdev);
528         cfg80211_put_dev(dev);
529
530         return genlmsg_unicast(msg, info->snd_pid);
531
532  out_free:
533         nlmsg_free(msg);
534  out_err:
535         dev_put(netdev);
536         cfg80211_put_dev(dev);
537         return -ENOBUFS;
538 }
539
540 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
541         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
542         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
543         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
544         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
545         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
546 };
547
548 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
549 {
550         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
551         int flag;
552
553         *mntrflags = 0;
554
555         if (!nla)
556                 return -EINVAL;
557
558         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
559                              nla, mntr_flags_policy))
560                 return -EINVAL;
561
562         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
563                 if (flags[flag])
564                         *mntrflags |= (1<<flag);
565
566         return 0;
567 }
568
569 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
570 {
571         struct cfg80211_registered_device *drv;
572         struct vif_params params;
573         int err, ifindex;
574         enum nl80211_iftype type;
575         struct net_device *dev;
576         u32 _flags, *flags = NULL;
577
578         memset(&params, 0, sizeof(params));
579
580         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
581         if (err)
582                 return err;
583         ifindex = dev->ifindex;
584         type = dev->ieee80211_ptr->iftype;
585         dev_put(dev);
586
587         err = -EINVAL;
588         if (info->attrs[NL80211_ATTR_IFTYPE]) {
589                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
590                 if (type > NL80211_IFTYPE_MAX)
591                         goto unlock;
592         }
593
594         if (!drv->ops->change_virtual_intf ||
595             !(drv->wiphy.interface_modes & (1 << type))) {
596                 err = -EOPNOTSUPP;
597                 goto unlock;
598         }
599
600         if (info->attrs[NL80211_ATTR_MESH_ID]) {
601                 if (type != NL80211_IFTYPE_MESH_POINT) {
602                         err = -EINVAL;
603                         goto unlock;
604                 }
605                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
606                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
607         }
608
609         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
610                 if (type != NL80211_IFTYPE_MONITOR) {
611                         err = -EINVAL;
612                         goto unlock;
613                 }
614                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
615                                           &_flags);
616                 if (!err)
617                         flags = &_flags;
618         }
619         rtnl_lock();
620         err = drv->ops->change_virtual_intf(&drv->wiphy, ifindex,
621                                             type, flags, &params);
622
623         dev = __dev_get_by_index(&init_net, ifindex);
624         WARN_ON(!dev || (!err && dev->ieee80211_ptr->iftype != type));
625
626         rtnl_unlock();
627
628  unlock:
629         cfg80211_put_dev(drv);
630         return err;
631 }
632
633 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
634 {
635         struct cfg80211_registered_device *drv;
636         struct vif_params params;
637         int err;
638         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
639         u32 flags;
640
641         memset(&params, 0, sizeof(params));
642
643         if (!info->attrs[NL80211_ATTR_IFNAME])
644                 return -EINVAL;
645
646         if (info->attrs[NL80211_ATTR_IFTYPE]) {
647                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
648                 if (type > NL80211_IFTYPE_MAX)
649                         return -EINVAL;
650         }
651
652         drv = cfg80211_get_dev_from_info(info);
653         if (IS_ERR(drv))
654                 return PTR_ERR(drv);
655
656         if (!drv->ops->add_virtual_intf ||
657             !(drv->wiphy.interface_modes & (1 << type))) {
658                 err = -EOPNOTSUPP;
659                 goto unlock;
660         }
661
662         if (type == NL80211_IFTYPE_MESH_POINT &&
663             info->attrs[NL80211_ATTR_MESH_ID]) {
664                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
665                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
666         }
667
668         rtnl_lock();
669         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
670                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
671                                   &flags);
672         err = drv->ops->add_virtual_intf(&drv->wiphy,
673                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
674                 type, err ? NULL : &flags, &params);
675         rtnl_unlock();
676
677
678  unlock:
679         cfg80211_put_dev(drv);
680         return err;
681 }
682
683 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
684 {
685         struct cfg80211_registered_device *drv;
686         int ifindex, err;
687         struct net_device *dev;
688
689         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
690         if (err)
691                 return err;
692         ifindex = dev->ifindex;
693         dev_put(dev);
694
695         if (!drv->ops->del_virtual_intf) {
696                 err = -EOPNOTSUPP;
697                 goto out;
698         }
699
700         rtnl_lock();
701         err = drv->ops->del_virtual_intf(&drv->wiphy, ifindex);
702         rtnl_unlock();
703
704  out:
705         cfg80211_put_dev(drv);
706         return err;
707 }
708
709 struct get_key_cookie {
710         struct sk_buff *msg;
711         int error;
712 };
713
714 static void get_key_callback(void *c, struct key_params *params)
715 {
716         struct get_key_cookie *cookie = c;
717
718         if (params->key)
719                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
720                         params->key_len, params->key);
721
722         if (params->seq)
723                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
724                         params->seq_len, params->seq);
725
726         if (params->cipher)
727                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
728                             params->cipher);
729
730         return;
731  nla_put_failure:
732         cookie->error = 1;
733 }
734
735 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
736 {
737         struct cfg80211_registered_device *drv;
738         int err;
739         struct net_device *dev;
740         u8 key_idx = 0;
741         u8 *mac_addr = NULL;
742         struct get_key_cookie cookie = {
743                 .error = 0,
744         };
745         void *hdr;
746         struct sk_buff *msg;
747
748         if (info->attrs[NL80211_ATTR_KEY_IDX])
749                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
750
751         if (key_idx > 5)
752                 return -EINVAL;
753
754         if (info->attrs[NL80211_ATTR_MAC])
755                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
756
757         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
758         if (err)
759                 return err;
760
761         if (!drv->ops->get_key) {
762                 err = -EOPNOTSUPP;
763                 goto out;
764         }
765
766         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
767         if (!msg) {
768                 err = -ENOMEM;
769                 goto out;
770         }
771
772         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
773                              NL80211_CMD_NEW_KEY);
774
775         if (IS_ERR(hdr)) {
776                 err = PTR_ERR(hdr);
777                 goto out;
778         }
779
780         cookie.msg = msg;
781
782         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
783         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
784         if (mac_addr)
785                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
786
787         rtnl_lock();
788         err = drv->ops->get_key(&drv->wiphy, dev, key_idx, mac_addr,
789                                 &cookie, get_key_callback);
790         rtnl_unlock();
791
792         if (err)
793                 goto out;
794
795         if (cookie.error)
796                 goto nla_put_failure;
797
798         genlmsg_end(msg, hdr);
799         err = genlmsg_unicast(msg, info->snd_pid);
800         goto out;
801
802  nla_put_failure:
803         err = -ENOBUFS;
804         nlmsg_free(msg);
805  out:
806         cfg80211_put_dev(drv);
807         dev_put(dev);
808         return err;
809 }
810
811 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
812 {
813         struct cfg80211_registered_device *drv;
814         int err;
815         struct net_device *dev;
816         u8 key_idx;
817         int (*func)(struct wiphy *wiphy, struct net_device *netdev,
818                     u8 key_index);
819
820         if (!info->attrs[NL80211_ATTR_KEY_IDX])
821                 return -EINVAL;
822
823         key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
824
825         if (info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT]) {
826                 if (key_idx < 4 || key_idx > 5)
827                         return -EINVAL;
828         } else if (key_idx > 3)
829                 return -EINVAL;
830
831         /* currently only support setting default key */
832         if (!info->attrs[NL80211_ATTR_KEY_DEFAULT] &&
833             !info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT])
834                 return -EINVAL;
835
836         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
837         if (err)
838                 return err;
839
840         if (info->attrs[NL80211_ATTR_KEY_DEFAULT])
841                 func = drv->ops->set_default_key;
842         else
843                 func = drv->ops->set_default_mgmt_key;
844
845         if (!func) {
846                 err = -EOPNOTSUPP;
847                 goto out;
848         }
849
850         rtnl_lock();
851         err = func(&drv->wiphy, dev, key_idx);
852         rtnl_unlock();
853
854  out:
855         cfg80211_put_dev(drv);
856         dev_put(dev);
857         return err;
858 }
859
860 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
861 {
862         struct cfg80211_registered_device *drv;
863         int err;
864         struct net_device *dev;
865         struct key_params params;
866         u8 key_idx = 0;
867         u8 *mac_addr = NULL;
868
869         memset(&params, 0, sizeof(params));
870
871         if (!info->attrs[NL80211_ATTR_KEY_CIPHER])
872                 return -EINVAL;
873
874         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
875                 params.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
876                 params.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
877         }
878
879         if (info->attrs[NL80211_ATTR_KEY_IDX])
880                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
881
882         params.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
883
884         if (info->attrs[NL80211_ATTR_MAC])
885                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
886
887         if (key_idx > 5)
888                 return -EINVAL;
889
890         /*
891          * Disallow pairwise keys with non-zero index unless it's WEP
892          * (because current deployments use pairwise WEP keys with
893          * non-zero indizes but 802.11i clearly specifies to use zero)
894          */
895         if (mac_addr && key_idx &&
896             params.cipher != WLAN_CIPHER_SUITE_WEP40 &&
897             params.cipher != WLAN_CIPHER_SUITE_WEP104)
898                 return -EINVAL;
899
900         /* TODO: add definitions for the lengths to linux/ieee80211.h */
901         switch (params.cipher) {
902         case WLAN_CIPHER_SUITE_WEP40:
903                 if (params.key_len != 5)
904                         return -EINVAL;
905                 break;
906         case WLAN_CIPHER_SUITE_TKIP:
907                 if (params.key_len != 32)
908                         return -EINVAL;
909                 break;
910         case WLAN_CIPHER_SUITE_CCMP:
911                 if (params.key_len != 16)
912                         return -EINVAL;
913                 break;
914         case WLAN_CIPHER_SUITE_WEP104:
915                 if (params.key_len != 13)
916                         return -EINVAL;
917                 break;
918         case WLAN_CIPHER_SUITE_AES_CMAC:
919                 if (params.key_len != 16)
920                         return -EINVAL;
921                 break;
922         default:
923                 return -EINVAL;
924         }
925
926         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
927         if (err)
928                 return err;
929
930         if (!drv->ops->add_key) {
931                 err = -EOPNOTSUPP;
932                 goto out;
933         }
934
935         rtnl_lock();
936         err = drv->ops->add_key(&drv->wiphy, dev, key_idx, mac_addr, &params);
937         rtnl_unlock();
938
939  out:
940         cfg80211_put_dev(drv);
941         dev_put(dev);
942         return err;
943 }
944
945 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
946 {
947         struct cfg80211_registered_device *drv;
948         int err;
949         struct net_device *dev;
950         u8 key_idx = 0;
951         u8 *mac_addr = NULL;
952
953         if (info->attrs[NL80211_ATTR_KEY_IDX])
954                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
955
956         if (key_idx > 5)
957                 return -EINVAL;
958
959         if (info->attrs[NL80211_ATTR_MAC])
960                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
961
962         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
963         if (err)
964                 return err;
965
966         if (!drv->ops->del_key) {
967                 err = -EOPNOTSUPP;
968                 goto out;
969         }
970
971         rtnl_lock();
972         err = drv->ops->del_key(&drv->wiphy, dev, key_idx, mac_addr);
973         rtnl_unlock();
974
975  out:
976         cfg80211_put_dev(drv);
977         dev_put(dev);
978         return err;
979 }
980
981 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
982 {
983         int (*call)(struct wiphy *wiphy, struct net_device *dev,
984                     struct beacon_parameters *info);
985         struct cfg80211_registered_device *drv;
986         int err;
987         struct net_device *dev;
988         struct beacon_parameters params;
989         int haveinfo = 0;
990
991         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
992         if (err)
993                 return err;
994
995         switch (info->genlhdr->cmd) {
996         case NL80211_CMD_NEW_BEACON:
997                 /* these are required for NEW_BEACON */
998                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
999                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1000                     !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1001                         err = -EINVAL;
1002                         goto out;
1003                 }
1004
1005                 call = drv->ops->add_beacon;
1006                 break;
1007         case NL80211_CMD_SET_BEACON:
1008                 call = drv->ops->set_beacon;
1009                 break;
1010         default:
1011                 WARN_ON(1);
1012                 err = -EOPNOTSUPP;
1013                 goto out;
1014         }
1015
1016         if (!call) {
1017                 err = -EOPNOTSUPP;
1018                 goto out;
1019         }
1020
1021         memset(&params, 0, sizeof(params));
1022
1023         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1024                 params.interval =
1025                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1026                 haveinfo = 1;
1027         }
1028
1029         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1030                 params.dtim_period =
1031                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1032                 haveinfo = 1;
1033         }
1034
1035         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1036                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1037                 params.head_len =
1038                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1039                 haveinfo = 1;
1040         }
1041
1042         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1043                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1044                 params.tail_len =
1045                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1046                 haveinfo = 1;
1047         }
1048
1049         if (!haveinfo) {
1050                 err = -EINVAL;
1051                 goto out;
1052         }
1053
1054         rtnl_lock();
1055         err = call(&drv->wiphy, dev, &params);
1056         rtnl_unlock();
1057
1058  out:
1059         cfg80211_put_dev(drv);
1060         dev_put(dev);
1061         return err;
1062 }
1063
1064 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1065 {
1066         struct cfg80211_registered_device *drv;
1067         int err;
1068         struct net_device *dev;
1069
1070         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1071         if (err)
1072                 return err;
1073
1074         if (!drv->ops->del_beacon) {
1075                 err = -EOPNOTSUPP;
1076                 goto out;
1077         }
1078
1079         rtnl_lock();
1080         err = drv->ops->del_beacon(&drv->wiphy, dev);
1081         rtnl_unlock();
1082
1083  out:
1084         cfg80211_put_dev(drv);
1085         dev_put(dev);
1086         return err;
1087 }
1088
1089 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1090         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1091         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1092         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1093 };
1094
1095 static int parse_station_flags(struct nlattr *nla, u32 *staflags)
1096 {
1097         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1098         int flag;
1099
1100         *staflags = 0;
1101
1102         if (!nla)
1103                 return 0;
1104
1105         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1106                              nla, sta_flags_policy))
1107                 return -EINVAL;
1108
1109         *staflags = STATION_FLAG_CHANGED;
1110
1111         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1112                 if (flags[flag])
1113                         *staflags |= (1<<flag);
1114
1115         return 0;
1116 }
1117
1118 static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1119 {
1120         int modulation, streams, bitrate;
1121
1122         if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1123                 return rate->legacy;
1124
1125         /* the formula below does only work for MCS values smaller than 32 */
1126         if (rate->mcs >= 32)
1127                 return 0;
1128
1129         modulation = rate->mcs & 7;
1130         streams = (rate->mcs >> 3) + 1;
1131
1132         bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1133                         13500000 : 6500000;
1134
1135         if (modulation < 4)
1136                 bitrate *= (modulation + 1);
1137         else if (modulation == 4)
1138                 bitrate *= (modulation + 2);
1139         else
1140                 bitrate *= (modulation + 3);
1141
1142         bitrate *= streams;
1143
1144         if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1145                 bitrate = (bitrate / 9) * 10;
1146
1147         /* do NOT round down here */
1148         return (bitrate + 50000) / 100000;
1149 }
1150
1151 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1152                                 int flags, struct net_device *dev,
1153                                 u8 *mac_addr, struct station_info *sinfo)
1154 {
1155         void *hdr;
1156         struct nlattr *sinfoattr, *txrate;
1157         u16 bitrate;
1158
1159         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1160         if (!hdr)
1161                 return -1;
1162
1163         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1164         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1165
1166         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1167         if (!sinfoattr)
1168                 goto nla_put_failure;
1169         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1170                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1171                             sinfo->inactive_time);
1172         if (sinfo->filled & STATION_INFO_RX_BYTES)
1173                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1174                             sinfo->rx_bytes);
1175         if (sinfo->filled & STATION_INFO_TX_BYTES)
1176                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1177                             sinfo->tx_bytes);
1178         if (sinfo->filled & STATION_INFO_LLID)
1179                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1180                             sinfo->llid);
1181         if (sinfo->filled & STATION_INFO_PLID)
1182                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1183                             sinfo->plid);
1184         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1185                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1186                             sinfo->plink_state);
1187         if (sinfo->filled & STATION_INFO_SIGNAL)
1188                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1189                            sinfo->signal);
1190         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1191                 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1192                 if (!txrate)
1193                         goto nla_put_failure;
1194
1195                 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1196                 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1197                 if (bitrate > 0)
1198                         NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1199
1200                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1201                         NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1202                                     sinfo->txrate.mcs);
1203                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1204                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1205                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1206                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1207
1208                 nla_nest_end(msg, txrate);
1209         }
1210         if (sinfo->filled & STATION_INFO_RX_PACKETS)
1211                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1212                             sinfo->rx_packets);
1213         if (sinfo->filled & STATION_INFO_TX_PACKETS)
1214                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1215                             sinfo->tx_packets);
1216         nla_nest_end(msg, sinfoattr);
1217
1218         return genlmsg_end(msg, hdr);
1219
1220  nla_put_failure:
1221         genlmsg_cancel(msg, hdr);
1222         return -EMSGSIZE;
1223 }
1224
1225 static int nl80211_dump_station(struct sk_buff *skb,
1226                                 struct netlink_callback *cb)
1227 {
1228         struct station_info sinfo;
1229         struct cfg80211_registered_device *dev;
1230         struct net_device *netdev;
1231         u8 mac_addr[ETH_ALEN];
1232         int ifidx = cb->args[0];
1233         int sta_idx = cb->args[1];
1234         int err;
1235
1236         if (!ifidx) {
1237                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1238                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1239                                   nl80211_policy);
1240                 if (err)
1241                         return err;
1242
1243                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1244                         return -EINVAL;
1245
1246                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1247                 if (!ifidx)
1248                         return -EINVAL;
1249         }
1250
1251         netdev = dev_get_by_index(&init_net, ifidx);
1252         if (!netdev)
1253                 return -ENODEV;
1254
1255         dev = cfg80211_get_dev_from_ifindex(ifidx);
1256         if (IS_ERR(dev)) {
1257                 err = PTR_ERR(dev);
1258                 goto out_put_netdev;
1259         }
1260
1261         if (!dev->ops->dump_station) {
1262                 err = -ENOSYS;
1263                 goto out_err;
1264         }
1265
1266         rtnl_lock();
1267
1268         while (1) {
1269                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1270                                              mac_addr, &sinfo);
1271                 if (err == -ENOENT)
1272                         break;
1273                 if (err)
1274                         goto out_err_rtnl;
1275
1276                 if (nl80211_send_station(skb,
1277                                 NETLINK_CB(cb->skb).pid,
1278                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1279                                 netdev, mac_addr,
1280                                 &sinfo) < 0)
1281                         goto out;
1282
1283                 sta_idx++;
1284         }
1285
1286
1287  out:
1288         cb->args[1] = sta_idx;
1289         err = skb->len;
1290  out_err_rtnl:
1291         rtnl_unlock();
1292  out_err:
1293         cfg80211_put_dev(dev);
1294  out_put_netdev:
1295         dev_put(netdev);
1296
1297         return err;
1298 }
1299
1300 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1301 {
1302         struct cfg80211_registered_device *drv;
1303         int err;
1304         struct net_device *dev;
1305         struct station_info sinfo;
1306         struct sk_buff *msg;
1307         u8 *mac_addr = NULL;
1308
1309         memset(&sinfo, 0, sizeof(sinfo));
1310
1311         if (!info->attrs[NL80211_ATTR_MAC])
1312                 return -EINVAL;
1313
1314         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1315
1316         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1317         if (err)
1318                 return err;
1319
1320         if (!drv->ops->get_station) {
1321                 err = -EOPNOTSUPP;
1322                 goto out;
1323         }
1324
1325         rtnl_lock();
1326         err = drv->ops->get_station(&drv->wiphy, dev, mac_addr, &sinfo);
1327         rtnl_unlock();
1328
1329         if (err)
1330                 goto out;
1331
1332         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1333         if (!msg)
1334                 goto out;
1335
1336         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1337                                  dev, mac_addr, &sinfo) < 0)
1338                 goto out_free;
1339
1340         err = genlmsg_unicast(msg, info->snd_pid);
1341         goto out;
1342
1343  out_free:
1344         nlmsg_free(msg);
1345
1346  out:
1347         cfg80211_put_dev(drv);
1348         dev_put(dev);
1349         return err;
1350 }
1351
1352 /*
1353  * Get vlan interface making sure it is on the right wiphy.
1354  */
1355 static int get_vlan(struct nlattr *vlanattr,
1356                     struct cfg80211_registered_device *rdev,
1357                     struct net_device **vlan)
1358 {
1359         *vlan = NULL;
1360
1361         if (vlanattr) {
1362                 *vlan = dev_get_by_index(&init_net, nla_get_u32(vlanattr));
1363                 if (!*vlan)
1364                         return -ENODEV;
1365                 if (!(*vlan)->ieee80211_ptr)
1366                         return -EINVAL;
1367                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1368                         return -EINVAL;
1369         }
1370         return 0;
1371 }
1372
1373 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1374 {
1375         struct cfg80211_registered_device *drv;
1376         int err;
1377         struct net_device *dev;
1378         struct station_parameters params;
1379         u8 *mac_addr = NULL;
1380
1381         memset(&params, 0, sizeof(params));
1382
1383         params.listen_interval = -1;
1384
1385         if (info->attrs[NL80211_ATTR_STA_AID])
1386                 return -EINVAL;
1387
1388         if (!info->attrs[NL80211_ATTR_MAC])
1389                 return -EINVAL;
1390
1391         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1392
1393         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1394                 params.supported_rates =
1395                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1396                 params.supported_rates_len =
1397                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1398         }
1399
1400         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1401                 params.listen_interval =
1402                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1403
1404         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1405                 params.ht_capa =
1406                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1407
1408         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1409                                 &params.station_flags))
1410                 return -EINVAL;
1411
1412         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1413                 params.plink_action =
1414                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1415
1416         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1417         if (err)
1418                 return err;
1419
1420         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1421         if (err)
1422                 goto out;
1423
1424         if (!drv->ops->change_station) {
1425                 err = -EOPNOTSUPP;
1426                 goto out;
1427         }
1428
1429         rtnl_lock();
1430         err = drv->ops->change_station(&drv->wiphy, dev, mac_addr, &params);
1431         rtnl_unlock();
1432
1433  out:
1434         if (params.vlan)
1435                 dev_put(params.vlan);
1436         cfg80211_put_dev(drv);
1437         dev_put(dev);
1438         return err;
1439 }
1440
1441 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1442 {
1443         struct cfg80211_registered_device *drv;
1444         int err;
1445         struct net_device *dev;
1446         struct station_parameters params;
1447         u8 *mac_addr = NULL;
1448
1449         memset(&params, 0, sizeof(params));
1450
1451         if (!info->attrs[NL80211_ATTR_MAC])
1452                 return -EINVAL;
1453
1454         if (!info->attrs[NL80211_ATTR_STA_AID])
1455                 return -EINVAL;
1456
1457         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1458                 return -EINVAL;
1459
1460         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1461                 return -EINVAL;
1462
1463         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1464         params.supported_rates =
1465                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1466         params.supported_rates_len =
1467                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1468         params.listen_interval =
1469                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1470         params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1471         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1472                 params.ht_capa =
1473                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1474
1475         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1476                                 &params.station_flags))
1477                 return -EINVAL;
1478
1479         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1480         if (err)
1481                 return err;
1482
1483         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1484         if (err)
1485                 goto out;
1486
1487         if (!drv->ops->add_station) {
1488                 err = -EOPNOTSUPP;
1489                 goto out;
1490         }
1491
1492         rtnl_lock();
1493         err = drv->ops->add_station(&drv->wiphy, dev, mac_addr, &params);
1494         rtnl_unlock();
1495
1496  out:
1497         if (params.vlan)
1498                 dev_put(params.vlan);
1499         cfg80211_put_dev(drv);
1500         dev_put(dev);
1501         return err;
1502 }
1503
1504 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
1505 {
1506         struct cfg80211_registered_device *drv;
1507         int err;
1508         struct net_device *dev;
1509         u8 *mac_addr = NULL;
1510
1511         if (info->attrs[NL80211_ATTR_MAC])
1512                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1513
1514         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1515         if (err)
1516                 return err;
1517
1518         if (!drv->ops->del_station) {
1519                 err = -EOPNOTSUPP;
1520                 goto out;
1521         }
1522
1523         rtnl_lock();
1524         err = drv->ops->del_station(&drv->wiphy, dev, mac_addr);
1525         rtnl_unlock();
1526
1527  out:
1528         cfg80211_put_dev(drv);
1529         dev_put(dev);
1530         return err;
1531 }
1532
1533 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
1534                                 int flags, struct net_device *dev,
1535                                 u8 *dst, u8 *next_hop,
1536                                 struct mpath_info *pinfo)
1537 {
1538         void *hdr;
1539         struct nlattr *pinfoattr;
1540
1541         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1542         if (!hdr)
1543                 return -1;
1544
1545         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1546         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
1547         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
1548
1549         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
1550         if (!pinfoattr)
1551                 goto nla_put_failure;
1552         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
1553                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
1554                             pinfo->frame_qlen);
1555         if (pinfo->filled & MPATH_INFO_DSN)
1556                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
1557                             pinfo->dsn);
1558         if (pinfo->filled & MPATH_INFO_METRIC)
1559                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
1560                             pinfo->metric);
1561         if (pinfo->filled & MPATH_INFO_EXPTIME)
1562                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
1563                             pinfo->exptime);
1564         if (pinfo->filled & MPATH_INFO_FLAGS)
1565                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
1566                             pinfo->flags);
1567         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
1568                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
1569                             pinfo->discovery_timeout);
1570         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
1571                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
1572                             pinfo->discovery_retries);
1573
1574         nla_nest_end(msg, pinfoattr);
1575
1576         return genlmsg_end(msg, hdr);
1577
1578  nla_put_failure:
1579         genlmsg_cancel(msg, hdr);
1580         return -EMSGSIZE;
1581 }
1582
1583 static int nl80211_dump_mpath(struct sk_buff *skb,
1584                               struct netlink_callback *cb)
1585 {
1586         struct mpath_info pinfo;
1587         struct cfg80211_registered_device *dev;
1588         struct net_device *netdev;
1589         u8 dst[ETH_ALEN];
1590         u8 next_hop[ETH_ALEN];
1591         int ifidx = cb->args[0];
1592         int path_idx = cb->args[1];
1593         int err;
1594
1595         if (!ifidx) {
1596                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1597                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1598                                   nl80211_policy);
1599                 if (err)
1600                         return err;
1601
1602                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1603                         return -EINVAL;
1604
1605                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1606                 if (!ifidx)
1607                         return -EINVAL;
1608         }
1609
1610         netdev = dev_get_by_index(&init_net, ifidx);
1611         if (!netdev)
1612                 return -ENODEV;
1613
1614         dev = cfg80211_get_dev_from_ifindex(ifidx);
1615         if (IS_ERR(dev)) {
1616                 err = PTR_ERR(dev);
1617                 goto out_put_netdev;
1618         }
1619
1620         if (!dev->ops->dump_mpath) {
1621                 err = -ENOSYS;
1622                 goto out_err;
1623         }
1624
1625         rtnl_lock();
1626
1627         while (1) {
1628                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
1629                                            dst, next_hop, &pinfo);
1630                 if (err == -ENOENT)
1631                         break;
1632                 if (err)
1633                         goto out_err_rtnl;
1634
1635                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
1636                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
1637                                        netdev, dst, next_hop,
1638                                        &pinfo) < 0)
1639                         goto out;
1640
1641                 path_idx++;
1642         }
1643
1644
1645  out:
1646         cb->args[1] = path_idx;
1647         err = skb->len;
1648  out_err_rtnl:
1649         rtnl_unlock();
1650  out_err:
1651         cfg80211_put_dev(dev);
1652  out_put_netdev:
1653         dev_put(netdev);
1654
1655         return err;
1656 }
1657
1658 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
1659 {
1660         struct cfg80211_registered_device *drv;
1661         int err;
1662         struct net_device *dev;
1663         struct mpath_info pinfo;
1664         struct sk_buff *msg;
1665         u8 *dst = NULL;
1666         u8 next_hop[ETH_ALEN];
1667
1668         memset(&pinfo, 0, sizeof(pinfo));
1669
1670         if (!info->attrs[NL80211_ATTR_MAC])
1671                 return -EINVAL;
1672
1673         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1674
1675         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1676         if (err)
1677                 return err;
1678
1679         if (!drv->ops->get_mpath) {
1680                 err = -EOPNOTSUPP;
1681                 goto out;
1682         }
1683
1684         rtnl_lock();
1685         err = drv->ops->get_mpath(&drv->wiphy, dev, dst, next_hop, &pinfo);
1686         rtnl_unlock();
1687
1688         if (err)
1689                 goto out;
1690
1691         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1692         if (!msg)
1693                 goto out;
1694
1695         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
1696                                  dev, dst, next_hop, &pinfo) < 0)
1697                 goto out_free;
1698
1699         err = genlmsg_unicast(msg, info->snd_pid);
1700         goto out;
1701
1702  out_free:
1703         nlmsg_free(msg);
1704
1705  out:
1706         cfg80211_put_dev(drv);
1707         dev_put(dev);
1708         return err;
1709 }
1710
1711 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
1712 {
1713         struct cfg80211_registered_device *drv;
1714         int err;
1715         struct net_device *dev;
1716         u8 *dst = NULL;
1717         u8 *next_hop = NULL;
1718
1719         if (!info->attrs[NL80211_ATTR_MAC])
1720                 return -EINVAL;
1721
1722         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
1723                 return -EINVAL;
1724
1725         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1726         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
1727
1728         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1729         if (err)
1730                 return err;
1731
1732         if (!drv->ops->change_mpath) {
1733                 err = -EOPNOTSUPP;
1734                 goto out;
1735         }
1736
1737         rtnl_lock();
1738         err = drv->ops->change_mpath(&drv->wiphy, dev, dst, next_hop);
1739         rtnl_unlock();
1740
1741  out:
1742         cfg80211_put_dev(drv);
1743         dev_put(dev);
1744         return err;
1745 }
1746 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
1747 {
1748         struct cfg80211_registered_device *drv;
1749         int err;
1750         struct net_device *dev;
1751         u8 *dst = NULL;
1752         u8 *next_hop = NULL;
1753
1754         if (!info->attrs[NL80211_ATTR_MAC])
1755                 return -EINVAL;
1756
1757         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
1758                 return -EINVAL;
1759
1760         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1761         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
1762
1763         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1764         if (err)
1765                 return err;
1766
1767         if (!drv->ops->add_mpath) {
1768                 err = -EOPNOTSUPP;
1769                 goto out;
1770         }
1771
1772         rtnl_lock();
1773         err = drv->ops->add_mpath(&drv->wiphy, dev, dst, next_hop);
1774         rtnl_unlock();
1775
1776  out:
1777         cfg80211_put_dev(drv);
1778         dev_put(dev);
1779         return err;
1780 }
1781
1782 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
1783 {
1784         struct cfg80211_registered_device *drv;
1785         int err;
1786         struct net_device *dev;
1787         u8 *dst = NULL;
1788
1789         if (info->attrs[NL80211_ATTR_MAC])
1790                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1791
1792         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1793         if (err)
1794                 return err;
1795
1796         if (!drv->ops->del_mpath) {
1797                 err = -EOPNOTSUPP;
1798                 goto out;
1799         }
1800
1801         rtnl_lock();
1802         err = drv->ops->del_mpath(&drv->wiphy, dev, dst);
1803         rtnl_unlock();
1804
1805  out:
1806         cfg80211_put_dev(drv);
1807         dev_put(dev);
1808         return err;
1809 }
1810
1811 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
1812 {
1813         struct cfg80211_registered_device *drv;
1814         int err;
1815         struct net_device *dev;
1816         struct bss_parameters params;
1817
1818         memset(&params, 0, sizeof(params));
1819         /* default to not changing parameters */
1820         params.use_cts_prot = -1;
1821         params.use_short_preamble = -1;
1822         params.use_short_slot_time = -1;
1823
1824         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
1825                 params.use_cts_prot =
1826                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
1827         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
1828                 params.use_short_preamble =
1829                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
1830         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
1831                 params.use_short_slot_time =
1832                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
1833         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
1834                 params.basic_rates =
1835                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
1836                 params.basic_rates_len =
1837                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
1838         }
1839
1840         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1841         if (err)
1842                 return err;
1843
1844         if (!drv->ops->change_bss) {
1845                 err = -EOPNOTSUPP;
1846                 goto out;
1847         }
1848
1849         rtnl_lock();
1850         err = drv->ops->change_bss(&drv->wiphy, dev, &params);
1851         rtnl_unlock();
1852
1853  out:
1854         cfg80211_put_dev(drv);
1855         dev_put(dev);
1856         return err;
1857 }
1858
1859 static const struct nla_policy
1860         reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
1861         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
1862         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
1863         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
1864         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
1865         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
1866         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
1867 };
1868
1869 static int parse_reg_rule(struct nlattr *tb[],
1870         struct ieee80211_reg_rule *reg_rule)
1871 {
1872         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
1873         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
1874
1875         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
1876                 return -EINVAL;
1877         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
1878                 return -EINVAL;
1879         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
1880                 return -EINVAL;
1881         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
1882                 return -EINVAL;
1883         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
1884                 return -EINVAL;
1885
1886         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
1887
1888         freq_range->start_freq_khz =
1889                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
1890         freq_range->end_freq_khz =
1891                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
1892         freq_range->max_bandwidth_khz =
1893                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
1894
1895         power_rule->max_eirp =
1896                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
1897
1898         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
1899                 power_rule->max_antenna_gain =
1900                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
1901
1902         return 0;
1903 }
1904
1905 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
1906 {
1907         int r;
1908         char *data = NULL;
1909
1910         /*
1911          * You should only get this when cfg80211 hasn't yet initialized
1912          * completely when built-in to the kernel right between the time
1913          * window between nl80211_init() and regulatory_init(), if that is
1914          * even possible.
1915          */
1916         mutex_lock(&cfg80211_mutex);
1917         if (unlikely(!cfg80211_regdomain)) {
1918                 r = -EINPROGRESS;
1919                 goto out;
1920         }
1921
1922         if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) {
1923                 r = -EINVAL;
1924                 goto out;
1925         }
1926
1927         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
1928
1929 #ifdef CONFIG_WIRELESS_OLD_REGULATORY
1930         /* We ignore world regdom requests with the old regdom setup */
1931         if (is_world_regdom(data)) {
1932                 r = -EINVAL;
1933                 goto out;
1934         }
1935 #endif
1936         r = __regulatory_hint(NULL, REGDOM_SET_BY_USER, data, 0, ENVIRON_ANY);
1937         /*
1938          * This means the regulatory domain was already set, however
1939          * we don't want to confuse userspace with a "successful error"
1940          * message so lets just treat it as a success
1941          */
1942         if (r == -EALREADY)
1943                 r = 0;
1944 out:
1945         mutex_unlock(&cfg80211_mutex);
1946         return r;
1947 }
1948
1949 static int nl80211_get_mesh_params(struct sk_buff *skb,
1950         struct genl_info *info)
1951 {
1952         struct cfg80211_registered_device *drv;
1953         struct mesh_config cur_params;
1954         int err;
1955         struct net_device *dev;
1956         void *hdr;
1957         struct nlattr *pinfoattr;
1958         struct sk_buff *msg;
1959
1960         /* Look up our device */
1961         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1962         if (err)
1963                 return err;
1964
1965         /* Get the mesh params */
1966         rtnl_lock();
1967         err = drv->ops->get_mesh_params(&drv->wiphy, dev, &cur_params);
1968         rtnl_unlock();
1969         if (err)
1970                 goto out;
1971
1972         /* Draw up a netlink message to send back */
1973         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1974         if (!msg) {
1975                 err = -ENOBUFS;
1976                 goto out;
1977         }
1978         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1979                              NL80211_CMD_GET_MESH_PARAMS);
1980         if (!hdr)
1981                 goto nla_put_failure;
1982         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
1983         if (!pinfoattr)
1984                 goto nla_put_failure;
1985         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1986         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
1987                         cur_params.dot11MeshRetryTimeout);
1988         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
1989                         cur_params.dot11MeshConfirmTimeout);
1990         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
1991                         cur_params.dot11MeshHoldingTimeout);
1992         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
1993                         cur_params.dot11MeshMaxPeerLinks);
1994         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
1995                         cur_params.dot11MeshMaxRetries);
1996         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
1997                         cur_params.dot11MeshTTL);
1998         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
1999                         cur_params.auto_open_plinks);
2000         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2001                         cur_params.dot11MeshHWMPmaxPREQretries);
2002         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2003                         cur_params.path_refresh_time);
2004         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2005                         cur_params.min_discovery_timeout);
2006         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2007                         cur_params.dot11MeshHWMPactivePathTimeout);
2008         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2009                         cur_params.dot11MeshHWMPpreqMinInterval);
2010         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2011                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2012         nla_nest_end(msg, pinfoattr);
2013         genlmsg_end(msg, hdr);
2014         err = genlmsg_unicast(msg, info->snd_pid);
2015         goto out;
2016
2017 nla_put_failure:
2018         genlmsg_cancel(msg, hdr);
2019         err = -EMSGSIZE;
2020 out:
2021         /* Cleanup */
2022         cfg80211_put_dev(drv);
2023         dev_put(dev);
2024         return err;
2025 }
2026
2027 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2028 do {\
2029         if (table[attr_num]) {\
2030                 cfg.param = nla_fn(table[attr_num]); \
2031                 mask |= (1 << (attr_num - 1)); \
2032         } \
2033 } while (0);\
2034
2035 static struct nla_policy
2036 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2037         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2038         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2039         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2040         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2041         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2042         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2043         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2044
2045         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2046         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2047         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2048         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2049         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2050         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2051 };
2052
2053 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2054 {
2055         int err;
2056         u32 mask;
2057         struct cfg80211_registered_device *drv;
2058         struct net_device *dev;
2059         struct mesh_config cfg;
2060         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2061         struct nlattr *parent_attr;
2062
2063         parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2064         if (!parent_attr)
2065                 return -EINVAL;
2066         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2067                         parent_attr, nl80211_meshconf_params_policy))
2068                 return -EINVAL;
2069
2070         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2071         if (err)
2072                 return err;
2073
2074         /* This makes sure that there aren't more than 32 mesh config
2075          * parameters (otherwise our bitfield scheme would not work.) */
2076         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2077
2078         /* Fill in the params struct */
2079         mask = 0;
2080         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2081                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2082         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2083                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2084         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2085                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2086         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2087                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2088         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2089                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2090         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2091                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
2092         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2093                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2094         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2095                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2096                         nla_get_u8);
2097         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2098                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2099         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2100                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2101                         nla_get_u16);
2102         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2103                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2104                         nla_get_u32);
2105         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2106                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2107                         nla_get_u16);
2108         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2109                         dot11MeshHWMPnetDiameterTraversalTime,
2110                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2111                         nla_get_u16);
2112
2113         /* Apply changes */
2114         rtnl_lock();
2115         err = drv->ops->set_mesh_params(&drv->wiphy, dev, &cfg, mask);
2116         rtnl_unlock();
2117
2118         /* cleanup */
2119         cfg80211_put_dev(drv);
2120         dev_put(dev);
2121         return err;
2122 }
2123
2124 #undef FILL_IN_MESH_PARAM_IF_SET
2125
2126 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2127 {
2128         struct sk_buff *msg;
2129         void *hdr = NULL;
2130         struct nlattr *nl_reg_rules;
2131         unsigned int i;
2132         int err = -EINVAL;
2133
2134         mutex_lock(&cfg80211_mutex);
2135
2136         if (!cfg80211_regdomain)
2137                 goto out;
2138
2139         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2140         if (!msg) {
2141                 err = -ENOBUFS;
2142                 goto out;
2143         }
2144
2145         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2146                              NL80211_CMD_GET_REG);
2147         if (!hdr)
2148                 goto nla_put_failure;
2149
2150         NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2151                 cfg80211_regdomain->alpha2);
2152
2153         nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2154         if (!nl_reg_rules)
2155                 goto nla_put_failure;
2156
2157         for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2158                 struct nlattr *nl_reg_rule;
2159                 const struct ieee80211_reg_rule *reg_rule;
2160                 const struct ieee80211_freq_range *freq_range;
2161                 const struct ieee80211_power_rule *power_rule;
2162
2163                 reg_rule = &cfg80211_regdomain->reg_rules[i];
2164                 freq_range = &reg_rule->freq_range;
2165                 power_rule = &reg_rule->power_rule;
2166
2167                 nl_reg_rule = nla_nest_start(msg, i);
2168                 if (!nl_reg_rule)
2169                         goto nla_put_failure;
2170
2171                 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2172                         reg_rule->flags);
2173                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2174                         freq_range->start_freq_khz);
2175                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2176                         freq_range->end_freq_khz);
2177                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2178                         freq_range->max_bandwidth_khz);
2179                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2180                         power_rule->max_antenna_gain);
2181                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2182                         power_rule->max_eirp);
2183
2184                 nla_nest_end(msg, nl_reg_rule);
2185         }
2186
2187         nla_nest_end(msg, nl_reg_rules);
2188
2189         genlmsg_end(msg, hdr);
2190         err = genlmsg_unicast(msg, info->snd_pid);
2191         goto out;
2192
2193 nla_put_failure:
2194         genlmsg_cancel(msg, hdr);
2195         err = -EMSGSIZE;
2196 out:
2197         mutex_unlock(&cfg80211_mutex);
2198         return err;
2199 }
2200
2201 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2202 {
2203         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2204         struct nlattr *nl_reg_rule;
2205         char *alpha2 = NULL;
2206         int rem_reg_rules = 0, r = 0;
2207         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2208         struct ieee80211_regdomain *rd = NULL;
2209
2210         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2211                 return -EINVAL;
2212
2213         if (!info->attrs[NL80211_ATTR_REG_RULES])
2214                 return -EINVAL;
2215
2216         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2217
2218         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2219                         rem_reg_rules) {
2220                 num_rules++;
2221                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2222                         goto bad_reg;
2223         }
2224
2225         if (!reg_is_valid_request(alpha2))
2226                 return -EINVAL;
2227
2228         size_of_regd = sizeof(struct ieee80211_regdomain) +
2229                 (num_rules * sizeof(struct ieee80211_reg_rule));
2230
2231         rd = kzalloc(size_of_regd, GFP_KERNEL);
2232         if (!rd)
2233                 return -ENOMEM;
2234
2235         rd->n_reg_rules = num_rules;
2236         rd->alpha2[0] = alpha2[0];
2237         rd->alpha2[1] = alpha2[1];
2238
2239         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2240                         rem_reg_rules) {
2241                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2242                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2243                         reg_rule_policy);
2244                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2245                 if (r)
2246                         goto bad_reg;
2247
2248                 rule_idx++;
2249
2250                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES)
2251                         goto bad_reg;
2252         }
2253
2254         BUG_ON(rule_idx != num_rules);
2255
2256         mutex_lock(&cfg80211_mutex);
2257         r = set_regdom(rd);
2258         mutex_unlock(&cfg80211_mutex);
2259         return r;
2260
2261  bad_reg:
2262         kfree(rd);
2263         return -EINVAL;
2264 }
2265
2266 static int nl80211_set_mgmt_extra_ie(struct sk_buff *skb,
2267                                      struct genl_info *info)
2268 {
2269         struct cfg80211_registered_device *drv;
2270         int err;
2271         struct net_device *dev;
2272         struct mgmt_extra_ie_params params;
2273
2274         memset(&params, 0, sizeof(params));
2275
2276         if (!info->attrs[NL80211_ATTR_MGMT_SUBTYPE])
2277                 return -EINVAL;
2278         params.subtype = nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
2279         if (params.subtype > 15)
2280                 return -EINVAL; /* FC Subtype field is 4 bits (0..15) */
2281
2282         if (info->attrs[NL80211_ATTR_IE]) {
2283                 params.ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2284                 params.ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2285         }
2286
2287         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2288         if (err)
2289                 return err;
2290
2291         if (drv->ops->set_mgmt_extra_ie) {
2292                 rtnl_lock();
2293                 err = drv->ops->set_mgmt_extra_ie(&drv->wiphy, dev, &params);
2294                 rtnl_unlock();
2295         } else
2296                 err = -EOPNOTSUPP;
2297
2298         cfg80211_put_dev(drv);
2299         dev_put(dev);
2300         return err;
2301 }
2302
2303 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2304 {
2305         struct cfg80211_registered_device *drv;
2306         struct net_device *dev;
2307         struct cfg80211_scan_request *request;
2308         struct cfg80211_ssid *ssid;
2309         struct ieee80211_channel *channel;
2310         struct nlattr *attr;
2311         struct wiphy *wiphy;
2312         int err, tmp, n_ssids = 0, n_channels = 0, i;
2313         enum ieee80211_band band;
2314         size_t ie_len;
2315
2316         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2317         if (err)
2318                 return err;
2319
2320         wiphy = &drv->wiphy;
2321
2322         if (!drv->ops->scan) {
2323                 err = -EOPNOTSUPP;
2324                 goto out;
2325         }
2326
2327         rtnl_lock();
2328
2329         if (drv->scan_req) {
2330                 err = -EBUSY;
2331                 goto out_unlock;
2332         }
2333
2334         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2335                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp)
2336                         n_channels++;
2337                 if (!n_channels) {
2338                         err = -EINVAL;
2339                         goto out_unlock;
2340                 }
2341         } else {
2342                 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2343                         if (wiphy->bands[band])
2344                                 n_channels += wiphy->bands[band]->n_channels;
2345         }
2346
2347         if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2348                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2349                         n_ssids++;
2350
2351         if (n_ssids > wiphy->max_scan_ssids) {
2352                 err = -EINVAL;
2353                 goto out_unlock;
2354         }
2355
2356         if (info->attrs[NL80211_ATTR_IE])
2357                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2358         else
2359                 ie_len = 0;
2360
2361         request = kzalloc(sizeof(*request)
2362                         + sizeof(*ssid) * n_ssids
2363                         + sizeof(channel) * n_channels
2364                         + ie_len, GFP_KERNEL);
2365         if (!request) {
2366                 err = -ENOMEM;
2367                 goto out_unlock;
2368         }
2369
2370         request->channels = (void *)((char *)request + sizeof(*request));
2371         request->n_channels = n_channels;
2372         if (n_ssids)
2373                 request->ssids = (void *)(request->channels + n_channels);
2374         request->n_ssids = n_ssids;
2375         if (ie_len) {
2376                 if (request->ssids)
2377                         request->ie = (void *)(request->ssids + n_ssids);
2378                 else
2379                         request->ie = (void *)(request->channels + n_channels);
2380         }
2381
2382         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2383                 /* user specified, bail out if channel not found */
2384                 request->n_channels = n_channels;
2385                 i = 0;
2386                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
2387                         request->channels[i] = ieee80211_get_channel(wiphy, nla_get_u32(attr));
2388                         if (!request->channels[i]) {
2389                                 err = -EINVAL;
2390                                 goto out_free;
2391                         }
2392                         i++;
2393                 }
2394         } else {
2395                 /* all channels */
2396                 i = 0;
2397                 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
2398                         int j;
2399                         if (!wiphy->bands[band])
2400                                 continue;
2401                         for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
2402                                 request->channels[i] = &wiphy->bands[band]->channels[j];
2403                                 i++;
2404                         }
2405                 }
2406         }
2407
2408         i = 0;
2409         if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
2410                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
2411                         if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
2412                                 err = -EINVAL;
2413                                 goto out_free;
2414                         }
2415                         memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2416                         request->ssids[i].ssid_len = nla_len(attr);
2417                         i++;
2418                 }
2419         }
2420
2421         if (info->attrs[NL80211_ATTR_IE]) {
2422                 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2423                 memcpy(request->ie, nla_data(info->attrs[NL80211_ATTR_IE]),
2424                        request->ie_len);
2425         }
2426
2427         request->ifidx = dev->ifindex;
2428         request->wiphy = &drv->wiphy;
2429
2430         drv->scan_req = request;
2431         err = drv->ops->scan(&drv->wiphy, dev, request);
2432
2433  out_free:
2434         if (err) {
2435                 drv->scan_req = NULL;
2436                 kfree(request);
2437         }
2438  out_unlock:
2439         rtnl_unlock();
2440  out:
2441         cfg80211_put_dev(drv);
2442         dev_put(dev);
2443         return err;
2444 }
2445
2446 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
2447                             struct cfg80211_registered_device *rdev,
2448                             struct net_device *dev,
2449                             struct cfg80211_bss *res)
2450 {
2451         void *hdr;
2452         struct nlattr *bss;
2453
2454         hdr = nl80211hdr_put(msg, pid, seq, flags,
2455                              NL80211_CMD_NEW_SCAN_RESULTS);
2456         if (!hdr)
2457                 return -1;
2458
2459         NLA_PUT_U32(msg, NL80211_ATTR_SCAN_GENERATION,
2460                     rdev->bss_generation);
2461         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2462
2463         bss = nla_nest_start(msg, NL80211_ATTR_BSS);
2464         if (!bss)
2465                 goto nla_put_failure;
2466         if (!is_zero_ether_addr(res->bssid))
2467                 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
2468         if (res->information_elements && res->len_information_elements)
2469                 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
2470                         res->len_information_elements,
2471                         res->information_elements);
2472         if (res->tsf)
2473                 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
2474         if (res->beacon_interval)
2475                 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
2476         NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
2477         NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
2478
2479         switch (rdev->wiphy.signal_type) {
2480         case CFG80211_SIGNAL_TYPE_MBM:
2481                 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
2482                 break;
2483         case CFG80211_SIGNAL_TYPE_UNSPEC:
2484                 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
2485                 break;
2486         default:
2487                 break;
2488         }
2489
2490         nla_nest_end(msg, bss);
2491
2492         return genlmsg_end(msg, hdr);
2493
2494  nla_put_failure:
2495         genlmsg_cancel(msg, hdr);
2496         return -EMSGSIZE;
2497 }
2498
2499 static int nl80211_dump_scan(struct sk_buff *skb,
2500                              struct netlink_callback *cb)
2501 {
2502         struct cfg80211_registered_device *dev;
2503         struct net_device *netdev;
2504         struct cfg80211_internal_bss *scan;
2505         int ifidx = cb->args[0];
2506         int start = cb->args[1], idx = 0;
2507         int err;
2508
2509         if (!ifidx) {
2510                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2511                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
2512                                   nl80211_policy);
2513                 if (err)
2514                         return err;
2515
2516                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2517                         return -EINVAL;
2518
2519                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2520                 if (!ifidx)
2521                         return -EINVAL;
2522                 cb->args[0] = ifidx;
2523         }
2524
2525         netdev = dev_get_by_index(&init_net, ifidx);
2526         if (!netdev)
2527                 return -ENODEV;
2528
2529         dev = cfg80211_get_dev_from_ifindex(ifidx);
2530         if (IS_ERR(dev)) {
2531                 err = PTR_ERR(dev);
2532                 goto out_put_netdev;
2533         }
2534
2535         spin_lock_bh(&dev->bss_lock);
2536         cfg80211_bss_expire(dev);
2537
2538         list_for_each_entry(scan, &dev->bss_list, list) {
2539                 if (++idx <= start)
2540                         continue;
2541                 if (nl80211_send_bss(skb,
2542                                 NETLINK_CB(cb->skb).pid,
2543                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2544                                 dev, netdev, &scan->pub) < 0) {
2545                         idx--;
2546                         goto out;
2547                 }
2548         }
2549
2550  out:
2551         spin_unlock_bh(&dev->bss_lock);
2552
2553         cb->args[1] = idx;
2554         err = skb->len;
2555         cfg80211_put_dev(dev);
2556  out_put_netdev:
2557         dev_put(netdev);
2558
2559         return err;
2560 }
2561
2562 static struct genl_ops nl80211_ops[] = {
2563         {
2564                 .cmd = NL80211_CMD_GET_WIPHY,
2565                 .doit = nl80211_get_wiphy,
2566                 .dumpit = nl80211_dump_wiphy,
2567                 .policy = nl80211_policy,
2568                 /* can be retrieved by unprivileged users */
2569         },
2570         {
2571                 .cmd = NL80211_CMD_SET_WIPHY,
2572                 .doit = nl80211_set_wiphy,
2573                 .policy = nl80211_policy,
2574                 .flags = GENL_ADMIN_PERM,
2575         },
2576         {
2577                 .cmd = NL80211_CMD_GET_INTERFACE,
2578                 .doit = nl80211_get_interface,
2579                 .dumpit = nl80211_dump_interface,
2580                 .policy = nl80211_policy,
2581                 /* can be retrieved by unprivileged users */
2582         },
2583         {
2584                 .cmd = NL80211_CMD_SET_INTERFACE,
2585                 .doit = nl80211_set_interface,
2586                 .policy = nl80211_policy,
2587                 .flags = GENL_ADMIN_PERM,
2588         },
2589         {
2590                 .cmd = NL80211_CMD_NEW_INTERFACE,
2591                 .doit = nl80211_new_interface,
2592                 .policy = nl80211_policy,
2593                 .flags = GENL_ADMIN_PERM,
2594         },
2595         {
2596                 .cmd = NL80211_CMD_DEL_INTERFACE,
2597                 .doit = nl80211_del_interface,
2598                 .policy = nl80211_policy,
2599                 .flags = GENL_ADMIN_PERM,
2600         },
2601         {
2602                 .cmd = NL80211_CMD_GET_KEY,
2603                 .doit = nl80211_get_key,
2604                 .policy = nl80211_policy,
2605                 .flags = GENL_ADMIN_PERM,
2606         },
2607         {
2608                 .cmd = NL80211_CMD_SET_KEY,
2609                 .doit = nl80211_set_key,
2610                 .policy = nl80211_policy,
2611                 .flags = GENL_ADMIN_PERM,
2612         },
2613         {
2614                 .cmd = NL80211_CMD_NEW_KEY,
2615                 .doit = nl80211_new_key,
2616                 .policy = nl80211_policy,
2617                 .flags = GENL_ADMIN_PERM,
2618         },
2619         {
2620                 .cmd = NL80211_CMD_DEL_KEY,
2621                 .doit = nl80211_del_key,
2622                 .policy = nl80211_policy,
2623                 .flags = GENL_ADMIN_PERM,
2624         },
2625         {
2626                 .cmd = NL80211_CMD_SET_BEACON,
2627                 .policy = nl80211_policy,
2628                 .flags = GENL_ADMIN_PERM,
2629                 .doit = nl80211_addset_beacon,
2630         },
2631         {
2632                 .cmd = NL80211_CMD_NEW_BEACON,
2633                 .policy = nl80211_policy,
2634                 .flags = GENL_ADMIN_PERM,
2635                 .doit = nl80211_addset_beacon,
2636         },
2637         {
2638                 .cmd = NL80211_CMD_DEL_BEACON,
2639                 .policy = nl80211_policy,
2640                 .flags = GENL_ADMIN_PERM,
2641                 .doit = nl80211_del_beacon,
2642         },
2643         {
2644                 .cmd = NL80211_CMD_GET_STATION,
2645                 .doit = nl80211_get_station,
2646                 .dumpit = nl80211_dump_station,
2647                 .policy = nl80211_policy,
2648         },
2649         {
2650                 .cmd = NL80211_CMD_SET_STATION,
2651                 .doit = nl80211_set_station,
2652                 .policy = nl80211_policy,
2653                 .flags = GENL_ADMIN_PERM,
2654         },
2655         {
2656                 .cmd = NL80211_CMD_NEW_STATION,
2657                 .doit = nl80211_new_station,
2658                 .policy = nl80211_policy,
2659                 .flags = GENL_ADMIN_PERM,
2660         },
2661         {
2662                 .cmd = NL80211_CMD_DEL_STATION,
2663                 .doit = nl80211_del_station,
2664                 .policy = nl80211_policy,
2665                 .flags = GENL_ADMIN_PERM,
2666         },
2667         {
2668                 .cmd = NL80211_CMD_GET_MPATH,
2669                 .doit = nl80211_get_mpath,
2670                 .dumpit = nl80211_dump_mpath,
2671                 .policy = nl80211_policy,
2672                 .flags = GENL_ADMIN_PERM,
2673         },
2674         {
2675                 .cmd = NL80211_CMD_SET_MPATH,
2676                 .doit = nl80211_set_mpath,
2677                 .policy = nl80211_policy,
2678                 .flags = GENL_ADMIN_PERM,
2679         },
2680         {
2681                 .cmd = NL80211_CMD_NEW_MPATH,
2682                 .doit = nl80211_new_mpath,
2683                 .policy = nl80211_policy,
2684                 .flags = GENL_ADMIN_PERM,
2685         },
2686         {
2687                 .cmd = NL80211_CMD_DEL_MPATH,
2688                 .doit = nl80211_del_mpath,
2689                 .policy = nl80211_policy,
2690                 .flags = GENL_ADMIN_PERM,
2691         },
2692         {
2693                 .cmd = NL80211_CMD_SET_BSS,
2694                 .doit = nl80211_set_bss,
2695                 .policy = nl80211_policy,
2696                 .flags = GENL_ADMIN_PERM,
2697         },
2698         {
2699                 .cmd = NL80211_CMD_GET_REG,
2700                 .doit = nl80211_get_reg,
2701                 .policy = nl80211_policy,
2702                 /* can be retrieved by unprivileged users */
2703         },
2704         {
2705                 .cmd = NL80211_CMD_SET_REG,
2706                 .doit = nl80211_set_reg,
2707                 .policy = nl80211_policy,
2708                 .flags = GENL_ADMIN_PERM,
2709         },
2710         {
2711                 .cmd = NL80211_CMD_REQ_SET_REG,
2712                 .doit = nl80211_req_set_reg,
2713                 .policy = nl80211_policy,
2714                 .flags = GENL_ADMIN_PERM,
2715         },
2716         {
2717                 .cmd = NL80211_CMD_GET_MESH_PARAMS,
2718                 .doit = nl80211_get_mesh_params,
2719                 .policy = nl80211_policy,
2720                 /* can be retrieved by unprivileged users */
2721         },
2722         {
2723                 .cmd = NL80211_CMD_SET_MESH_PARAMS,
2724                 .doit = nl80211_set_mesh_params,
2725                 .policy = nl80211_policy,
2726                 .flags = GENL_ADMIN_PERM,
2727         },
2728         {
2729                 .cmd = NL80211_CMD_SET_MGMT_EXTRA_IE,
2730                 .doit = nl80211_set_mgmt_extra_ie,
2731                 .policy = nl80211_policy,
2732                 .flags = GENL_ADMIN_PERM,
2733         },
2734         {
2735                 .cmd = NL80211_CMD_TRIGGER_SCAN,
2736                 .doit = nl80211_trigger_scan,
2737                 .policy = nl80211_policy,
2738                 .flags = GENL_ADMIN_PERM,
2739         },
2740         {
2741                 .cmd = NL80211_CMD_GET_SCAN,
2742                 .policy = nl80211_policy,
2743                 .dumpit = nl80211_dump_scan,
2744         },
2745 };
2746
2747 /* multicast groups */
2748 static struct genl_multicast_group nl80211_config_mcgrp = {
2749         .name = "config",
2750 };
2751 static struct genl_multicast_group nl80211_scan_mcgrp = {
2752         .name = "scan",
2753 };
2754
2755 /* notification functions */
2756
2757 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
2758 {
2759         struct sk_buff *msg;
2760
2761         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2762         if (!msg)
2763                 return;
2764
2765         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
2766                 nlmsg_free(msg);
2767                 return;
2768         }
2769
2770         genlmsg_multicast(msg, 0, nl80211_config_mcgrp.id, GFP_KERNEL);
2771 }
2772
2773 static int nl80211_send_scan_donemsg(struct sk_buff *msg,
2774                                     struct cfg80211_registered_device *rdev,
2775                                     struct net_device *netdev,
2776                                     u32 pid, u32 seq, int flags,
2777                                     u32 cmd)
2778 {
2779         void *hdr;
2780
2781         hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
2782         if (!hdr)
2783                 return -1;
2784
2785         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2786         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
2787
2788         /* XXX: we should probably bounce back the request? */
2789
2790         return genlmsg_end(msg, hdr);
2791
2792  nla_put_failure:
2793         genlmsg_cancel(msg, hdr);
2794         return -EMSGSIZE;
2795 }
2796
2797 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
2798                             struct net_device *netdev)
2799 {
2800         struct sk_buff *msg;
2801
2802         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2803         if (!msg)
2804                 return;
2805
2806         if (nl80211_send_scan_donemsg(msg, rdev, netdev, 0, 0, 0,
2807                                       NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2808                 nlmsg_free(msg);
2809                 return;
2810         }
2811
2812         genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
2813 }
2814
2815 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
2816                                struct net_device *netdev)
2817 {
2818         struct sk_buff *msg;
2819
2820         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2821         if (!msg)
2822                 return;
2823
2824         if (nl80211_send_scan_donemsg(msg, rdev, netdev, 0, 0, 0,
2825                                       NL80211_CMD_SCAN_ABORTED) < 0) {
2826                 nlmsg_free(msg);
2827                 return;
2828         }
2829
2830         genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
2831 }
2832
2833 /* initialisation/exit functions */
2834
2835 int nl80211_init(void)
2836 {
2837         int err, i;
2838
2839         err = genl_register_family(&nl80211_fam);
2840         if (err)
2841                 return err;
2842
2843         for (i = 0; i < ARRAY_SIZE(nl80211_ops); i++) {
2844                 err = genl_register_ops(&nl80211_fam, &nl80211_ops[i]);
2845                 if (err)
2846                         goto err_out;
2847         }
2848
2849         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
2850         if (err)
2851                 goto err_out;
2852
2853         err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
2854         if (err)
2855                 goto err_out;
2856
2857         return 0;
2858  err_out:
2859         genl_unregister_family(&nl80211_fam);
2860         return err;
2861 }
2862
2863 void nl80211_exit(void)
2864 {
2865         genl_unregister_family(&nl80211_fam);
2866 }