nl80211: disallow user requests prior to regulatory_init()
[safe/jmp/linux-2.6] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006, 2007 Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/mutex.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <linux/etherdevice.h>
18 #include <net/genetlink.h>
19 #include <net/cfg80211.h>
20 #include "core.h"
21 #include "nl80211.h"
22 #include "reg.h"
23
24 /* the netlink family */
25 static struct genl_family nl80211_fam = {
26         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
27         .name = "nl80211",      /* have users key off the name instead */
28         .hdrsize = 0,           /* no private header */
29         .version = 1,           /* no particular meaning now */
30         .maxattr = NL80211_ATTR_MAX,
31 };
32
33 /* internal helper: get drv and dev */
34 static int get_drv_dev_by_info_ifindex(struct nlattr **attrs,
35                                        struct cfg80211_registered_device **drv,
36                                        struct net_device **dev)
37 {
38         int ifindex;
39
40         if (!attrs[NL80211_ATTR_IFINDEX])
41                 return -EINVAL;
42
43         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
44         *dev = dev_get_by_index(&init_net, ifindex);
45         if (!*dev)
46                 return -ENODEV;
47
48         *drv = cfg80211_get_dev_from_ifindex(ifindex);
49         if (IS_ERR(*drv)) {
50                 dev_put(*dev);
51                 return PTR_ERR(*drv);
52         }
53
54         return 0;
55 }
56
57 /* policy for the attributes */
58 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
59         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
60         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
61                                       .len = BUS_ID_SIZE-1 },
62         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
63         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
64         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
65
66         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
67         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
68         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
69
70         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
71
72         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
73                                     .len = WLAN_MAX_KEY_LEN },
74         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
75         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
76         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
77
78         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
79         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
80         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
81                                        .len = IEEE80211_MAX_DATA_LEN },
82         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
83                                        .len = IEEE80211_MAX_DATA_LEN },
84         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
85         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
86         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
87         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
88                                                .len = NL80211_MAX_SUPP_RATES },
89         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
90         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
91         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
92         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
93                                 .len = IEEE80211_MAX_MESH_ID_LEN },
94         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
95
96         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
97         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
98
99         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
100         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
101         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
102         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
103                                            .len = NL80211_MAX_SUPP_RATES },
104
105         [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
106
107         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
108                                          .len = NL80211_HT_CAPABILITY_LEN },
109
110         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
111         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
112                               .len = IEEE80211_MAX_DATA_LEN },
113         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
114         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
115 };
116
117 /* message building helper */
118 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
119                                    int flags, u8 cmd)
120 {
121         /* since there is no private header just add the generic one */
122         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
123 }
124
125 /* netlink command implementations */
126
127 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
128                               struct cfg80211_registered_device *dev)
129 {
130         void *hdr;
131         struct nlattr *nl_bands, *nl_band;
132         struct nlattr *nl_freqs, *nl_freq;
133         struct nlattr *nl_rates, *nl_rate;
134         struct nlattr *nl_modes;
135         enum ieee80211_band band;
136         struct ieee80211_channel *chan;
137         struct ieee80211_rate *rate;
138         int i;
139         u16 ifmodes = dev->wiphy.interface_modes;
140
141         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
142         if (!hdr)
143                 return -1;
144
145         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
146         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
147         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
148                    dev->wiphy.max_scan_ssids);
149
150         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
151         if (!nl_modes)
152                 goto nla_put_failure;
153
154         i = 0;
155         while (ifmodes) {
156                 if (ifmodes & 1)
157                         NLA_PUT_FLAG(msg, i);
158                 ifmodes >>= 1;
159                 i++;
160         }
161
162         nla_nest_end(msg, nl_modes);
163
164         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
165         if (!nl_bands)
166                 goto nla_put_failure;
167
168         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
169                 if (!dev->wiphy.bands[band])
170                         continue;
171
172                 nl_band = nla_nest_start(msg, band);
173                 if (!nl_band)
174                         goto nla_put_failure;
175
176                 /* add HT info */
177                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
178                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
179                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
180                                 &dev->wiphy.bands[band]->ht_cap.mcs);
181                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
182                                 dev->wiphy.bands[band]->ht_cap.cap);
183                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
184                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
185                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
186                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
187                 }
188
189                 /* add frequencies */
190                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
191                 if (!nl_freqs)
192                         goto nla_put_failure;
193
194                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
195                         nl_freq = nla_nest_start(msg, i);
196                         if (!nl_freq)
197                                 goto nla_put_failure;
198
199                         chan = &dev->wiphy.bands[band]->channels[i];
200                         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
201                                     chan->center_freq);
202
203                         if (chan->flags & IEEE80211_CHAN_DISABLED)
204                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
205                         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
206                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
207                         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
208                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
209                         if (chan->flags & IEEE80211_CHAN_RADAR)
210                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
211
212                         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
213                                     DBM_TO_MBM(chan->max_power));
214
215                         nla_nest_end(msg, nl_freq);
216                 }
217
218                 nla_nest_end(msg, nl_freqs);
219
220                 /* add bitrates */
221                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
222                 if (!nl_rates)
223                         goto nla_put_failure;
224
225                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
226                         nl_rate = nla_nest_start(msg, i);
227                         if (!nl_rate)
228                                 goto nla_put_failure;
229
230                         rate = &dev->wiphy.bands[band]->bitrates[i];
231                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
232                                     rate->bitrate);
233                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
234                                 NLA_PUT_FLAG(msg,
235                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
236
237                         nla_nest_end(msg, nl_rate);
238                 }
239
240                 nla_nest_end(msg, nl_rates);
241
242                 nla_nest_end(msg, nl_band);
243         }
244         nla_nest_end(msg, nl_bands);
245
246         return genlmsg_end(msg, hdr);
247
248  nla_put_failure:
249         genlmsg_cancel(msg, hdr);
250         return -EMSGSIZE;
251 }
252
253 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
254 {
255         int idx = 0;
256         int start = cb->args[0];
257         struct cfg80211_registered_device *dev;
258
259         mutex_lock(&cfg80211_mutex);
260         list_for_each_entry(dev, &cfg80211_drv_list, list) {
261                 if (++idx <= start)
262                         continue;
263                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
264                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
265                                        dev) < 0) {
266                         idx--;
267                         break;
268                 }
269         }
270         mutex_unlock(&cfg80211_mutex);
271
272         cb->args[0] = idx;
273
274         return skb->len;
275 }
276
277 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
278 {
279         struct sk_buff *msg;
280         struct cfg80211_registered_device *dev;
281
282         dev = cfg80211_get_dev_from_info(info);
283         if (IS_ERR(dev))
284                 return PTR_ERR(dev);
285
286         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
287         if (!msg)
288                 goto out_err;
289
290         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
291                 goto out_free;
292
293         cfg80211_put_dev(dev);
294
295         return genlmsg_unicast(msg, info->snd_pid);
296
297  out_free:
298         nlmsg_free(msg);
299  out_err:
300         cfg80211_put_dev(dev);
301         return -ENOBUFS;
302 }
303
304 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
305         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
306         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
307         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
308         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
309         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
310 };
311
312 static int parse_txq_params(struct nlattr *tb[],
313                             struct ieee80211_txq_params *txq_params)
314 {
315         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
316             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
317             !tb[NL80211_TXQ_ATTR_AIFS])
318                 return -EINVAL;
319
320         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
321         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
322         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
323         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
324         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
325
326         return 0;
327 }
328
329 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
330 {
331         struct cfg80211_registered_device *rdev;
332         int result = 0, rem_txq_params = 0;
333         struct nlattr *nl_txq_params;
334
335         rdev = cfg80211_get_dev_from_info(info);
336         if (IS_ERR(rdev))
337                 return PTR_ERR(rdev);
338
339         if (info->attrs[NL80211_ATTR_WIPHY_NAME]) {
340                 result = cfg80211_dev_rename(
341                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
342                 if (result)
343                         goto bad_res;
344         }
345
346         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
347                 struct ieee80211_txq_params txq_params;
348                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
349
350                 if (!rdev->ops->set_txq_params) {
351                         result = -EOPNOTSUPP;
352                         goto bad_res;
353                 }
354
355                 nla_for_each_nested(nl_txq_params,
356                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
357                                     rem_txq_params) {
358                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
359                                   nla_data(nl_txq_params),
360                                   nla_len(nl_txq_params),
361                                   txq_params_policy);
362                         result = parse_txq_params(tb, &txq_params);
363                         if (result)
364                                 goto bad_res;
365
366                         result = rdev->ops->set_txq_params(&rdev->wiphy,
367                                                            &txq_params);
368                         if (result)
369                                 goto bad_res;
370                 }
371         }
372
373         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
374                 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
375                 struct ieee80211_channel *chan;
376                 struct ieee80211_sta_ht_cap *ht_cap;
377                 u32 freq, sec_freq;
378
379                 if (!rdev->ops->set_channel) {
380                         result = -EOPNOTSUPP;
381                         goto bad_res;
382                 }
383
384                 result = -EINVAL;
385
386                 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
387                         channel_type = nla_get_u32(info->attrs[
388                                            NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
389                         if (channel_type != NL80211_CHAN_NO_HT &&
390                             channel_type != NL80211_CHAN_HT20 &&
391                             channel_type != NL80211_CHAN_HT40PLUS &&
392                             channel_type != NL80211_CHAN_HT40MINUS)
393                                 goto bad_res;
394                 }
395
396                 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
397                 chan = ieee80211_get_channel(&rdev->wiphy, freq);
398
399                 /* Primary channel not allowed */
400                 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
401                         goto bad_res;
402
403                 if (channel_type == NL80211_CHAN_HT40MINUS)
404                         sec_freq = freq - 20;
405                 else if (channel_type == NL80211_CHAN_HT40PLUS)
406                         sec_freq = freq + 20;
407                 else
408                         sec_freq = 0;
409
410                 ht_cap = &rdev->wiphy.bands[chan->band]->ht_cap;
411
412                 /* no HT capabilities */
413                 if (channel_type != NL80211_CHAN_NO_HT &&
414                     !ht_cap->ht_supported)
415                         goto bad_res;
416
417                 if (sec_freq) {
418                         struct ieee80211_channel *schan;
419
420                         /* no 40 MHz capabilities */
421                         if (!(ht_cap->cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40) ||
422                             (ht_cap->cap & IEEE80211_HT_CAP_40MHZ_INTOLERANT))
423                                 goto bad_res;
424
425                         schan = ieee80211_get_channel(&rdev->wiphy, sec_freq);
426
427                         /* Secondary channel not allowed */
428                         if (!schan || schan->flags & IEEE80211_CHAN_DISABLED)
429                                 goto bad_res;
430                 }
431
432                 result = rdev->ops->set_channel(&rdev->wiphy, chan,
433                                                 channel_type);
434                 if (result)
435                         goto bad_res;
436         }
437
438
439  bad_res:
440         cfg80211_put_dev(rdev);
441         return result;
442 }
443
444
445 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
446                               struct net_device *dev)
447 {
448         void *hdr;
449
450         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
451         if (!hdr)
452                 return -1;
453
454         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
455         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
456         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
457         return genlmsg_end(msg, hdr);
458
459  nla_put_failure:
460         genlmsg_cancel(msg, hdr);
461         return -EMSGSIZE;
462 }
463
464 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
465 {
466         int wp_idx = 0;
467         int if_idx = 0;
468         int wp_start = cb->args[0];
469         int if_start = cb->args[1];
470         struct cfg80211_registered_device *dev;
471         struct wireless_dev *wdev;
472
473         mutex_lock(&cfg80211_mutex);
474         list_for_each_entry(dev, &cfg80211_drv_list, list) {
475                 if (wp_idx < wp_start) {
476                         wp_idx++;
477                         continue;
478                 }
479                 if_idx = 0;
480
481                 mutex_lock(&dev->devlist_mtx);
482                 list_for_each_entry(wdev, &dev->netdev_list, list) {
483                         if (if_idx < if_start) {
484                                 if_idx++;
485                                 continue;
486                         }
487                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
488                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
489                                                wdev->netdev) < 0) {
490                                 mutex_unlock(&dev->devlist_mtx);
491                                 goto out;
492                         }
493                         if_idx++;
494                 }
495                 mutex_unlock(&dev->devlist_mtx);
496
497                 wp_idx++;
498         }
499  out:
500         mutex_unlock(&cfg80211_mutex);
501
502         cb->args[0] = wp_idx;
503         cb->args[1] = if_idx;
504
505         return skb->len;
506 }
507
508 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
509 {
510         struct sk_buff *msg;
511         struct cfg80211_registered_device *dev;
512         struct net_device *netdev;
513         int err;
514
515         err = get_drv_dev_by_info_ifindex(info->attrs, &dev, &netdev);
516         if (err)
517                 return err;
518
519         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
520         if (!msg)
521                 goto out_err;
522
523         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0, netdev) < 0)
524                 goto out_free;
525
526         dev_put(netdev);
527         cfg80211_put_dev(dev);
528
529         return genlmsg_unicast(msg, info->snd_pid);
530
531  out_free:
532         nlmsg_free(msg);
533  out_err:
534         dev_put(netdev);
535         cfg80211_put_dev(dev);
536         return -ENOBUFS;
537 }
538
539 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
540         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
541         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
542         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
543         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
544         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
545 };
546
547 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
548 {
549         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
550         int flag;
551
552         *mntrflags = 0;
553
554         if (!nla)
555                 return -EINVAL;
556
557         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
558                              nla, mntr_flags_policy))
559                 return -EINVAL;
560
561         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
562                 if (flags[flag])
563                         *mntrflags |= (1<<flag);
564
565         return 0;
566 }
567
568 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
569 {
570         struct cfg80211_registered_device *drv;
571         struct vif_params params;
572         int err, ifindex;
573         enum nl80211_iftype type;
574         struct net_device *dev;
575         u32 _flags, *flags = NULL;
576
577         memset(&params, 0, sizeof(params));
578
579         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
580         if (err)
581                 return err;
582         ifindex = dev->ifindex;
583         type = dev->ieee80211_ptr->iftype;
584         dev_put(dev);
585
586         err = -EINVAL;
587         if (info->attrs[NL80211_ATTR_IFTYPE]) {
588                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
589                 if (type > NL80211_IFTYPE_MAX)
590                         goto unlock;
591         }
592
593         if (!drv->ops->change_virtual_intf ||
594             !(drv->wiphy.interface_modes & (1 << type))) {
595                 err = -EOPNOTSUPP;
596                 goto unlock;
597         }
598
599         if (info->attrs[NL80211_ATTR_MESH_ID]) {
600                 if (type != NL80211_IFTYPE_MESH_POINT) {
601                         err = -EINVAL;
602                         goto unlock;
603                 }
604                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
605                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
606         }
607
608         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
609                 if (type != NL80211_IFTYPE_MONITOR) {
610                         err = -EINVAL;
611                         goto unlock;
612                 }
613                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
614                                           &_flags);
615                 if (!err)
616                         flags = &_flags;
617         }
618         rtnl_lock();
619         err = drv->ops->change_virtual_intf(&drv->wiphy, ifindex,
620                                             type, flags, &params);
621
622         dev = __dev_get_by_index(&init_net, ifindex);
623         WARN_ON(!dev || (!err && dev->ieee80211_ptr->iftype != type));
624
625         rtnl_unlock();
626
627  unlock:
628         cfg80211_put_dev(drv);
629         return err;
630 }
631
632 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
633 {
634         struct cfg80211_registered_device *drv;
635         struct vif_params params;
636         int err;
637         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
638         u32 flags;
639
640         memset(&params, 0, sizeof(params));
641
642         if (!info->attrs[NL80211_ATTR_IFNAME])
643                 return -EINVAL;
644
645         if (info->attrs[NL80211_ATTR_IFTYPE]) {
646                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
647                 if (type > NL80211_IFTYPE_MAX)
648                         return -EINVAL;
649         }
650
651         drv = cfg80211_get_dev_from_info(info);
652         if (IS_ERR(drv))
653                 return PTR_ERR(drv);
654
655         if (!drv->ops->add_virtual_intf ||
656             !(drv->wiphy.interface_modes & (1 << type))) {
657                 err = -EOPNOTSUPP;
658                 goto unlock;
659         }
660
661         if (type == NL80211_IFTYPE_MESH_POINT &&
662             info->attrs[NL80211_ATTR_MESH_ID]) {
663                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
664                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
665         }
666
667         rtnl_lock();
668         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
669                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
670                                   &flags);
671         err = drv->ops->add_virtual_intf(&drv->wiphy,
672                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
673                 type, err ? NULL : &flags, &params);
674         rtnl_unlock();
675
676
677  unlock:
678         cfg80211_put_dev(drv);
679         return err;
680 }
681
682 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
683 {
684         struct cfg80211_registered_device *drv;
685         int ifindex, err;
686         struct net_device *dev;
687
688         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
689         if (err)
690                 return err;
691         ifindex = dev->ifindex;
692         dev_put(dev);
693
694         if (!drv->ops->del_virtual_intf) {
695                 err = -EOPNOTSUPP;
696                 goto out;
697         }
698
699         rtnl_lock();
700         err = drv->ops->del_virtual_intf(&drv->wiphy, ifindex);
701         rtnl_unlock();
702
703  out:
704         cfg80211_put_dev(drv);
705         return err;
706 }
707
708 struct get_key_cookie {
709         struct sk_buff *msg;
710         int error;
711 };
712
713 static void get_key_callback(void *c, struct key_params *params)
714 {
715         struct get_key_cookie *cookie = c;
716
717         if (params->key)
718                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
719                         params->key_len, params->key);
720
721         if (params->seq)
722                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
723                         params->seq_len, params->seq);
724
725         if (params->cipher)
726                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
727                             params->cipher);
728
729         return;
730  nla_put_failure:
731         cookie->error = 1;
732 }
733
734 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
735 {
736         struct cfg80211_registered_device *drv;
737         int err;
738         struct net_device *dev;
739         u8 key_idx = 0;
740         u8 *mac_addr = NULL;
741         struct get_key_cookie cookie = {
742                 .error = 0,
743         };
744         void *hdr;
745         struct sk_buff *msg;
746
747         if (info->attrs[NL80211_ATTR_KEY_IDX])
748                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
749
750         if (key_idx > 5)
751                 return -EINVAL;
752
753         if (info->attrs[NL80211_ATTR_MAC])
754                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
755
756         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
757         if (err)
758                 return err;
759
760         if (!drv->ops->get_key) {
761                 err = -EOPNOTSUPP;
762                 goto out;
763         }
764
765         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
766         if (!msg) {
767                 err = -ENOMEM;
768                 goto out;
769         }
770
771         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
772                              NL80211_CMD_NEW_KEY);
773
774         if (IS_ERR(hdr)) {
775                 err = PTR_ERR(hdr);
776                 goto out;
777         }
778
779         cookie.msg = msg;
780
781         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
782         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
783         if (mac_addr)
784                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
785
786         rtnl_lock();
787         err = drv->ops->get_key(&drv->wiphy, dev, key_idx, mac_addr,
788                                 &cookie, get_key_callback);
789         rtnl_unlock();
790
791         if (err)
792                 goto out;
793
794         if (cookie.error)
795                 goto nla_put_failure;
796
797         genlmsg_end(msg, hdr);
798         err = genlmsg_unicast(msg, info->snd_pid);
799         goto out;
800
801  nla_put_failure:
802         err = -ENOBUFS;
803         nlmsg_free(msg);
804  out:
805         cfg80211_put_dev(drv);
806         dev_put(dev);
807         return err;
808 }
809
810 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
811 {
812         struct cfg80211_registered_device *drv;
813         int err;
814         struct net_device *dev;
815         u8 key_idx;
816         int (*func)(struct wiphy *wiphy, struct net_device *netdev,
817                     u8 key_index);
818
819         if (!info->attrs[NL80211_ATTR_KEY_IDX])
820                 return -EINVAL;
821
822         key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
823
824         if (info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT]) {
825                 if (key_idx < 4 || key_idx > 5)
826                         return -EINVAL;
827         } else if (key_idx > 3)
828                 return -EINVAL;
829
830         /* currently only support setting default key */
831         if (!info->attrs[NL80211_ATTR_KEY_DEFAULT] &&
832             !info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT])
833                 return -EINVAL;
834
835         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
836         if (err)
837                 return err;
838
839         if (info->attrs[NL80211_ATTR_KEY_DEFAULT])
840                 func = drv->ops->set_default_key;
841         else
842                 func = drv->ops->set_default_mgmt_key;
843
844         if (!func) {
845                 err = -EOPNOTSUPP;
846                 goto out;
847         }
848
849         rtnl_lock();
850         err = func(&drv->wiphy, dev, key_idx);
851         rtnl_unlock();
852
853  out:
854         cfg80211_put_dev(drv);
855         dev_put(dev);
856         return err;
857 }
858
859 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
860 {
861         struct cfg80211_registered_device *drv;
862         int err;
863         struct net_device *dev;
864         struct key_params params;
865         u8 key_idx = 0;
866         u8 *mac_addr = NULL;
867
868         memset(&params, 0, sizeof(params));
869
870         if (!info->attrs[NL80211_ATTR_KEY_CIPHER])
871                 return -EINVAL;
872
873         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
874                 params.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
875                 params.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
876         }
877
878         if (info->attrs[NL80211_ATTR_KEY_IDX])
879                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
880
881         params.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
882
883         if (info->attrs[NL80211_ATTR_MAC])
884                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
885
886         if (key_idx > 5)
887                 return -EINVAL;
888
889         /*
890          * Disallow pairwise keys with non-zero index unless it's WEP
891          * (because current deployments use pairwise WEP keys with
892          * non-zero indizes but 802.11i clearly specifies to use zero)
893          */
894         if (mac_addr && key_idx &&
895             params.cipher != WLAN_CIPHER_SUITE_WEP40 &&
896             params.cipher != WLAN_CIPHER_SUITE_WEP104)
897                 return -EINVAL;
898
899         /* TODO: add definitions for the lengths to linux/ieee80211.h */
900         switch (params.cipher) {
901         case WLAN_CIPHER_SUITE_WEP40:
902                 if (params.key_len != 5)
903                         return -EINVAL;
904                 break;
905         case WLAN_CIPHER_SUITE_TKIP:
906                 if (params.key_len != 32)
907                         return -EINVAL;
908                 break;
909         case WLAN_CIPHER_SUITE_CCMP:
910                 if (params.key_len != 16)
911                         return -EINVAL;
912                 break;
913         case WLAN_CIPHER_SUITE_WEP104:
914                 if (params.key_len != 13)
915                         return -EINVAL;
916                 break;
917         case WLAN_CIPHER_SUITE_AES_CMAC:
918                 if (params.key_len != 16)
919                         return -EINVAL;
920                 break;
921         default:
922                 return -EINVAL;
923         }
924
925         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
926         if (err)
927                 return err;
928
929         if (!drv->ops->add_key) {
930                 err = -EOPNOTSUPP;
931                 goto out;
932         }
933
934         rtnl_lock();
935         err = drv->ops->add_key(&drv->wiphy, dev, key_idx, mac_addr, &params);
936         rtnl_unlock();
937
938  out:
939         cfg80211_put_dev(drv);
940         dev_put(dev);
941         return err;
942 }
943
944 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
945 {
946         struct cfg80211_registered_device *drv;
947         int err;
948         struct net_device *dev;
949         u8 key_idx = 0;
950         u8 *mac_addr = NULL;
951
952         if (info->attrs[NL80211_ATTR_KEY_IDX])
953                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
954
955         if (key_idx > 5)
956                 return -EINVAL;
957
958         if (info->attrs[NL80211_ATTR_MAC])
959                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
960
961         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
962         if (err)
963                 return err;
964
965         if (!drv->ops->del_key) {
966                 err = -EOPNOTSUPP;
967                 goto out;
968         }
969
970         rtnl_lock();
971         err = drv->ops->del_key(&drv->wiphy, dev, key_idx, mac_addr);
972         rtnl_unlock();
973
974  out:
975         cfg80211_put_dev(drv);
976         dev_put(dev);
977         return err;
978 }
979
980 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
981 {
982         int (*call)(struct wiphy *wiphy, struct net_device *dev,
983                     struct beacon_parameters *info);
984         struct cfg80211_registered_device *drv;
985         int err;
986         struct net_device *dev;
987         struct beacon_parameters params;
988         int haveinfo = 0;
989
990         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
991         if (err)
992                 return err;
993
994         switch (info->genlhdr->cmd) {
995         case NL80211_CMD_NEW_BEACON:
996                 /* these are required for NEW_BEACON */
997                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
998                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
999                     !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1000                         err = -EINVAL;
1001                         goto out;
1002                 }
1003
1004                 call = drv->ops->add_beacon;
1005                 break;
1006         case NL80211_CMD_SET_BEACON:
1007                 call = drv->ops->set_beacon;
1008                 break;
1009         default:
1010                 WARN_ON(1);
1011                 err = -EOPNOTSUPP;
1012                 goto out;
1013         }
1014
1015         if (!call) {
1016                 err = -EOPNOTSUPP;
1017                 goto out;
1018         }
1019
1020         memset(&params, 0, sizeof(params));
1021
1022         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1023                 params.interval =
1024                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1025                 haveinfo = 1;
1026         }
1027
1028         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1029                 params.dtim_period =
1030                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1031                 haveinfo = 1;
1032         }
1033
1034         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1035                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1036                 params.head_len =
1037                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1038                 haveinfo = 1;
1039         }
1040
1041         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1042                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1043                 params.tail_len =
1044                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1045                 haveinfo = 1;
1046         }
1047
1048         if (!haveinfo) {
1049                 err = -EINVAL;
1050                 goto out;
1051         }
1052
1053         rtnl_lock();
1054         err = call(&drv->wiphy, dev, &params);
1055         rtnl_unlock();
1056
1057  out:
1058         cfg80211_put_dev(drv);
1059         dev_put(dev);
1060         return err;
1061 }
1062
1063 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1064 {
1065         struct cfg80211_registered_device *drv;
1066         int err;
1067         struct net_device *dev;
1068
1069         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1070         if (err)
1071                 return err;
1072
1073         if (!drv->ops->del_beacon) {
1074                 err = -EOPNOTSUPP;
1075                 goto out;
1076         }
1077
1078         rtnl_lock();
1079         err = drv->ops->del_beacon(&drv->wiphy, dev);
1080         rtnl_unlock();
1081
1082  out:
1083         cfg80211_put_dev(drv);
1084         dev_put(dev);
1085         return err;
1086 }
1087
1088 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1089         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1090         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1091         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1092 };
1093
1094 static int parse_station_flags(struct nlattr *nla, u32 *staflags)
1095 {
1096         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1097         int flag;
1098
1099         *staflags = 0;
1100
1101         if (!nla)
1102                 return 0;
1103
1104         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1105                              nla, sta_flags_policy))
1106                 return -EINVAL;
1107
1108         *staflags = STATION_FLAG_CHANGED;
1109
1110         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1111                 if (flags[flag])
1112                         *staflags |= (1<<flag);
1113
1114         return 0;
1115 }
1116
1117 static u16 nl80211_calculate_bitrate(struct rate_info *rate)
1118 {
1119         int modulation, streams, bitrate;
1120
1121         if (!(rate->flags & RATE_INFO_FLAGS_MCS))
1122                 return rate->legacy;
1123
1124         /* the formula below does only work for MCS values smaller than 32 */
1125         if (rate->mcs >= 32)
1126                 return 0;
1127
1128         modulation = rate->mcs & 7;
1129         streams = (rate->mcs >> 3) + 1;
1130
1131         bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
1132                         13500000 : 6500000;
1133
1134         if (modulation < 4)
1135                 bitrate *= (modulation + 1);
1136         else if (modulation == 4)
1137                 bitrate *= (modulation + 2);
1138         else
1139                 bitrate *= (modulation + 3);
1140
1141         bitrate *= streams;
1142
1143         if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
1144                 bitrate = (bitrate / 9) * 10;
1145
1146         /* do NOT round down here */
1147         return (bitrate + 50000) / 100000;
1148 }
1149
1150 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1151                                 int flags, struct net_device *dev,
1152                                 u8 *mac_addr, struct station_info *sinfo)
1153 {
1154         void *hdr;
1155         struct nlattr *sinfoattr, *txrate;
1156         u16 bitrate;
1157
1158         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1159         if (!hdr)
1160                 return -1;
1161
1162         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1163         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1164
1165         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1166         if (!sinfoattr)
1167                 goto nla_put_failure;
1168         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1169                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1170                             sinfo->inactive_time);
1171         if (sinfo->filled & STATION_INFO_RX_BYTES)
1172                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1173                             sinfo->rx_bytes);
1174         if (sinfo->filled & STATION_INFO_TX_BYTES)
1175                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1176                             sinfo->tx_bytes);
1177         if (sinfo->filled & STATION_INFO_LLID)
1178                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1179                             sinfo->llid);
1180         if (sinfo->filled & STATION_INFO_PLID)
1181                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1182                             sinfo->plid);
1183         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1184                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1185                             sinfo->plink_state);
1186         if (sinfo->filled & STATION_INFO_SIGNAL)
1187                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1188                            sinfo->signal);
1189         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1190                 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1191                 if (!txrate)
1192                         goto nla_put_failure;
1193
1194                 /* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
1195                 bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
1196                 if (bitrate > 0)
1197                         NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1198
1199                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1200                         NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1201                                     sinfo->txrate.mcs);
1202                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1203                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1204                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1205                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1206
1207                 nla_nest_end(msg, txrate);
1208         }
1209         if (sinfo->filled & STATION_INFO_RX_PACKETS)
1210                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1211                             sinfo->rx_packets);
1212         if (sinfo->filled & STATION_INFO_TX_PACKETS)
1213                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1214                             sinfo->tx_packets);
1215         nla_nest_end(msg, sinfoattr);
1216
1217         return genlmsg_end(msg, hdr);
1218
1219  nla_put_failure:
1220         genlmsg_cancel(msg, hdr);
1221         return -EMSGSIZE;
1222 }
1223
1224 static int nl80211_dump_station(struct sk_buff *skb,
1225                                 struct netlink_callback *cb)
1226 {
1227         struct station_info sinfo;
1228         struct cfg80211_registered_device *dev;
1229         struct net_device *netdev;
1230         u8 mac_addr[ETH_ALEN];
1231         int ifidx = cb->args[0];
1232         int sta_idx = cb->args[1];
1233         int err;
1234
1235         if (!ifidx) {
1236                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1237                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1238                                   nl80211_policy);
1239                 if (err)
1240                         return err;
1241
1242                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1243                         return -EINVAL;
1244
1245                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1246                 if (!ifidx)
1247                         return -EINVAL;
1248         }
1249
1250         netdev = dev_get_by_index(&init_net, ifidx);
1251         if (!netdev)
1252                 return -ENODEV;
1253
1254         dev = cfg80211_get_dev_from_ifindex(ifidx);
1255         if (IS_ERR(dev)) {
1256                 err = PTR_ERR(dev);
1257                 goto out_put_netdev;
1258         }
1259
1260         if (!dev->ops->dump_station) {
1261                 err = -ENOSYS;
1262                 goto out_err;
1263         }
1264
1265         rtnl_lock();
1266
1267         while (1) {
1268                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1269                                              mac_addr, &sinfo);
1270                 if (err == -ENOENT)
1271                         break;
1272                 if (err)
1273                         goto out_err_rtnl;
1274
1275                 if (nl80211_send_station(skb,
1276                                 NETLINK_CB(cb->skb).pid,
1277                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1278                                 netdev, mac_addr,
1279                                 &sinfo) < 0)
1280                         goto out;
1281
1282                 sta_idx++;
1283         }
1284
1285
1286  out:
1287         cb->args[1] = sta_idx;
1288         err = skb->len;
1289  out_err_rtnl:
1290         rtnl_unlock();
1291  out_err:
1292         cfg80211_put_dev(dev);
1293  out_put_netdev:
1294         dev_put(netdev);
1295
1296         return err;
1297 }
1298
1299 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1300 {
1301         struct cfg80211_registered_device *drv;
1302         int err;
1303         struct net_device *dev;
1304         struct station_info sinfo;
1305         struct sk_buff *msg;
1306         u8 *mac_addr = NULL;
1307
1308         memset(&sinfo, 0, sizeof(sinfo));
1309
1310         if (!info->attrs[NL80211_ATTR_MAC])
1311                 return -EINVAL;
1312
1313         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1314
1315         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1316         if (err)
1317                 return err;
1318
1319         if (!drv->ops->get_station) {
1320                 err = -EOPNOTSUPP;
1321                 goto out;
1322         }
1323
1324         rtnl_lock();
1325         err = drv->ops->get_station(&drv->wiphy, dev, mac_addr, &sinfo);
1326         rtnl_unlock();
1327
1328         if (err)
1329                 goto out;
1330
1331         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1332         if (!msg)
1333                 goto out;
1334
1335         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1336                                  dev, mac_addr, &sinfo) < 0)
1337                 goto out_free;
1338
1339         err = genlmsg_unicast(msg, info->snd_pid);
1340         goto out;
1341
1342  out_free:
1343         nlmsg_free(msg);
1344
1345  out:
1346         cfg80211_put_dev(drv);
1347         dev_put(dev);
1348         return err;
1349 }
1350
1351 /*
1352  * Get vlan interface making sure it is on the right wiphy.
1353  */
1354 static int get_vlan(struct nlattr *vlanattr,
1355                     struct cfg80211_registered_device *rdev,
1356                     struct net_device **vlan)
1357 {
1358         *vlan = NULL;
1359
1360         if (vlanattr) {
1361                 *vlan = dev_get_by_index(&init_net, nla_get_u32(vlanattr));
1362                 if (!*vlan)
1363                         return -ENODEV;
1364                 if (!(*vlan)->ieee80211_ptr)
1365                         return -EINVAL;
1366                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1367                         return -EINVAL;
1368         }
1369         return 0;
1370 }
1371
1372 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1373 {
1374         struct cfg80211_registered_device *drv;
1375         int err;
1376         struct net_device *dev;
1377         struct station_parameters params;
1378         u8 *mac_addr = NULL;
1379
1380         memset(&params, 0, sizeof(params));
1381
1382         params.listen_interval = -1;
1383
1384         if (info->attrs[NL80211_ATTR_STA_AID])
1385                 return -EINVAL;
1386
1387         if (!info->attrs[NL80211_ATTR_MAC])
1388                 return -EINVAL;
1389
1390         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1391
1392         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1393                 params.supported_rates =
1394                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1395                 params.supported_rates_len =
1396                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1397         }
1398
1399         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1400                 params.listen_interval =
1401                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1402
1403         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1404                 params.ht_capa =
1405                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1406
1407         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1408                                 &params.station_flags))
1409                 return -EINVAL;
1410
1411         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1412                 params.plink_action =
1413                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1414
1415         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1416         if (err)
1417                 return err;
1418
1419         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1420         if (err)
1421                 goto out;
1422
1423         if (!drv->ops->change_station) {
1424                 err = -EOPNOTSUPP;
1425                 goto out;
1426         }
1427
1428         rtnl_lock();
1429         err = drv->ops->change_station(&drv->wiphy, dev, mac_addr, &params);
1430         rtnl_unlock();
1431
1432  out:
1433         if (params.vlan)
1434                 dev_put(params.vlan);
1435         cfg80211_put_dev(drv);
1436         dev_put(dev);
1437         return err;
1438 }
1439
1440 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1441 {
1442         struct cfg80211_registered_device *drv;
1443         int err;
1444         struct net_device *dev;
1445         struct station_parameters params;
1446         u8 *mac_addr = NULL;
1447
1448         memset(&params, 0, sizeof(params));
1449
1450         if (!info->attrs[NL80211_ATTR_MAC])
1451                 return -EINVAL;
1452
1453         if (!info->attrs[NL80211_ATTR_STA_AID])
1454                 return -EINVAL;
1455
1456         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1457                 return -EINVAL;
1458
1459         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1460                 return -EINVAL;
1461
1462         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1463         params.supported_rates =
1464                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1465         params.supported_rates_len =
1466                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1467         params.listen_interval =
1468                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1469         params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1470         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1471                 params.ht_capa =
1472                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1473
1474         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1475                                 &params.station_flags))
1476                 return -EINVAL;
1477
1478         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1479         if (err)
1480                 return err;
1481
1482         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1483         if (err)
1484                 goto out;
1485
1486         if (!drv->ops->add_station) {
1487                 err = -EOPNOTSUPP;
1488                 goto out;
1489         }
1490
1491         rtnl_lock();
1492         err = drv->ops->add_station(&drv->wiphy, dev, mac_addr, &params);
1493         rtnl_unlock();
1494
1495  out:
1496         if (params.vlan)
1497                 dev_put(params.vlan);
1498         cfg80211_put_dev(drv);
1499         dev_put(dev);
1500         return err;
1501 }
1502
1503 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
1504 {
1505         struct cfg80211_registered_device *drv;
1506         int err;
1507         struct net_device *dev;
1508         u8 *mac_addr = NULL;
1509
1510         if (info->attrs[NL80211_ATTR_MAC])
1511                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1512
1513         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1514         if (err)
1515                 return err;
1516
1517         if (!drv->ops->del_station) {
1518                 err = -EOPNOTSUPP;
1519                 goto out;
1520         }
1521
1522         rtnl_lock();
1523         err = drv->ops->del_station(&drv->wiphy, dev, mac_addr);
1524         rtnl_unlock();
1525
1526  out:
1527         cfg80211_put_dev(drv);
1528         dev_put(dev);
1529         return err;
1530 }
1531
1532 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
1533                                 int flags, struct net_device *dev,
1534                                 u8 *dst, u8 *next_hop,
1535                                 struct mpath_info *pinfo)
1536 {
1537         void *hdr;
1538         struct nlattr *pinfoattr;
1539
1540         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1541         if (!hdr)
1542                 return -1;
1543
1544         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1545         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
1546         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
1547
1548         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
1549         if (!pinfoattr)
1550                 goto nla_put_failure;
1551         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
1552                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
1553                             pinfo->frame_qlen);
1554         if (pinfo->filled & MPATH_INFO_DSN)
1555                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
1556                             pinfo->dsn);
1557         if (pinfo->filled & MPATH_INFO_METRIC)
1558                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
1559                             pinfo->metric);
1560         if (pinfo->filled & MPATH_INFO_EXPTIME)
1561                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
1562                             pinfo->exptime);
1563         if (pinfo->filled & MPATH_INFO_FLAGS)
1564                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
1565                             pinfo->flags);
1566         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
1567                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
1568                             pinfo->discovery_timeout);
1569         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
1570                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
1571                             pinfo->discovery_retries);
1572
1573         nla_nest_end(msg, pinfoattr);
1574
1575         return genlmsg_end(msg, hdr);
1576
1577  nla_put_failure:
1578         genlmsg_cancel(msg, hdr);
1579         return -EMSGSIZE;
1580 }
1581
1582 static int nl80211_dump_mpath(struct sk_buff *skb,
1583                               struct netlink_callback *cb)
1584 {
1585         struct mpath_info pinfo;
1586         struct cfg80211_registered_device *dev;
1587         struct net_device *netdev;
1588         u8 dst[ETH_ALEN];
1589         u8 next_hop[ETH_ALEN];
1590         int ifidx = cb->args[0];
1591         int path_idx = cb->args[1];
1592         int err;
1593
1594         if (!ifidx) {
1595                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1596                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1597                                   nl80211_policy);
1598                 if (err)
1599                         return err;
1600
1601                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1602                         return -EINVAL;
1603
1604                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1605                 if (!ifidx)
1606                         return -EINVAL;
1607         }
1608
1609         netdev = dev_get_by_index(&init_net, ifidx);
1610         if (!netdev)
1611                 return -ENODEV;
1612
1613         dev = cfg80211_get_dev_from_ifindex(ifidx);
1614         if (IS_ERR(dev)) {
1615                 err = PTR_ERR(dev);
1616                 goto out_put_netdev;
1617         }
1618
1619         if (!dev->ops->dump_mpath) {
1620                 err = -ENOSYS;
1621                 goto out_err;
1622         }
1623
1624         rtnl_lock();
1625
1626         while (1) {
1627                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
1628                                            dst, next_hop, &pinfo);
1629                 if (err == -ENOENT)
1630                         break;
1631                 if (err)
1632                         goto out_err_rtnl;
1633
1634                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
1635                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
1636                                        netdev, dst, next_hop,
1637                                        &pinfo) < 0)
1638                         goto out;
1639
1640                 path_idx++;
1641         }
1642
1643
1644  out:
1645         cb->args[1] = path_idx;
1646         err = skb->len;
1647  out_err_rtnl:
1648         rtnl_unlock();
1649  out_err:
1650         cfg80211_put_dev(dev);
1651  out_put_netdev:
1652         dev_put(netdev);
1653
1654         return err;
1655 }
1656
1657 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
1658 {
1659         struct cfg80211_registered_device *drv;
1660         int err;
1661         struct net_device *dev;
1662         struct mpath_info pinfo;
1663         struct sk_buff *msg;
1664         u8 *dst = NULL;
1665         u8 next_hop[ETH_ALEN];
1666
1667         memset(&pinfo, 0, sizeof(pinfo));
1668
1669         if (!info->attrs[NL80211_ATTR_MAC])
1670                 return -EINVAL;
1671
1672         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1673
1674         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1675         if (err)
1676                 return err;
1677
1678         if (!drv->ops->get_mpath) {
1679                 err = -EOPNOTSUPP;
1680                 goto out;
1681         }
1682
1683         rtnl_lock();
1684         err = drv->ops->get_mpath(&drv->wiphy, dev, dst, next_hop, &pinfo);
1685         rtnl_unlock();
1686
1687         if (err)
1688                 goto out;
1689
1690         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1691         if (!msg)
1692                 goto out;
1693
1694         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
1695                                  dev, dst, next_hop, &pinfo) < 0)
1696                 goto out_free;
1697
1698         err = genlmsg_unicast(msg, info->snd_pid);
1699         goto out;
1700
1701  out_free:
1702         nlmsg_free(msg);
1703
1704  out:
1705         cfg80211_put_dev(drv);
1706         dev_put(dev);
1707         return err;
1708 }
1709
1710 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
1711 {
1712         struct cfg80211_registered_device *drv;
1713         int err;
1714         struct net_device *dev;
1715         u8 *dst = NULL;
1716         u8 *next_hop = NULL;
1717
1718         if (!info->attrs[NL80211_ATTR_MAC])
1719                 return -EINVAL;
1720
1721         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
1722                 return -EINVAL;
1723
1724         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1725         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
1726
1727         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1728         if (err)
1729                 return err;
1730
1731         if (!drv->ops->change_mpath) {
1732                 err = -EOPNOTSUPP;
1733                 goto out;
1734         }
1735
1736         rtnl_lock();
1737         err = drv->ops->change_mpath(&drv->wiphy, dev, dst, next_hop);
1738         rtnl_unlock();
1739
1740  out:
1741         cfg80211_put_dev(drv);
1742         dev_put(dev);
1743         return err;
1744 }
1745 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
1746 {
1747         struct cfg80211_registered_device *drv;
1748         int err;
1749         struct net_device *dev;
1750         u8 *dst = NULL;
1751         u8 *next_hop = NULL;
1752
1753         if (!info->attrs[NL80211_ATTR_MAC])
1754                 return -EINVAL;
1755
1756         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
1757                 return -EINVAL;
1758
1759         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1760         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
1761
1762         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1763         if (err)
1764                 return err;
1765
1766         if (!drv->ops->add_mpath) {
1767                 err = -EOPNOTSUPP;
1768                 goto out;
1769         }
1770
1771         rtnl_lock();
1772         err = drv->ops->add_mpath(&drv->wiphy, dev, dst, next_hop);
1773         rtnl_unlock();
1774
1775  out:
1776         cfg80211_put_dev(drv);
1777         dev_put(dev);
1778         return err;
1779 }
1780
1781 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
1782 {
1783         struct cfg80211_registered_device *drv;
1784         int err;
1785         struct net_device *dev;
1786         u8 *dst = NULL;
1787
1788         if (info->attrs[NL80211_ATTR_MAC])
1789                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1790
1791         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1792         if (err)
1793                 return err;
1794
1795         if (!drv->ops->del_mpath) {
1796                 err = -EOPNOTSUPP;
1797                 goto out;
1798         }
1799
1800         rtnl_lock();
1801         err = drv->ops->del_mpath(&drv->wiphy, dev, dst);
1802         rtnl_unlock();
1803
1804  out:
1805         cfg80211_put_dev(drv);
1806         dev_put(dev);
1807         return err;
1808 }
1809
1810 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
1811 {
1812         struct cfg80211_registered_device *drv;
1813         int err;
1814         struct net_device *dev;
1815         struct bss_parameters params;
1816
1817         memset(&params, 0, sizeof(params));
1818         /* default to not changing parameters */
1819         params.use_cts_prot = -1;
1820         params.use_short_preamble = -1;
1821         params.use_short_slot_time = -1;
1822
1823         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
1824                 params.use_cts_prot =
1825                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
1826         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
1827                 params.use_short_preamble =
1828                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
1829         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
1830                 params.use_short_slot_time =
1831                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
1832         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
1833                 params.basic_rates =
1834                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
1835                 params.basic_rates_len =
1836                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
1837         }
1838
1839         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1840         if (err)
1841                 return err;
1842
1843         if (!drv->ops->change_bss) {
1844                 err = -EOPNOTSUPP;
1845                 goto out;
1846         }
1847
1848         rtnl_lock();
1849         err = drv->ops->change_bss(&drv->wiphy, dev, &params);
1850         rtnl_unlock();
1851
1852  out:
1853         cfg80211_put_dev(drv);
1854         dev_put(dev);
1855         return err;
1856 }
1857
1858 static const struct nla_policy
1859         reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
1860         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
1861         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
1862         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
1863         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
1864         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
1865         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
1866 };
1867
1868 static int parse_reg_rule(struct nlattr *tb[],
1869         struct ieee80211_reg_rule *reg_rule)
1870 {
1871         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
1872         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
1873
1874         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
1875                 return -EINVAL;
1876         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
1877                 return -EINVAL;
1878         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
1879                 return -EINVAL;
1880         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
1881                 return -EINVAL;
1882         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
1883                 return -EINVAL;
1884
1885         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
1886
1887         freq_range->start_freq_khz =
1888                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
1889         freq_range->end_freq_khz =
1890                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
1891         freq_range->max_bandwidth_khz =
1892                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
1893
1894         power_rule->max_eirp =
1895                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
1896
1897         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
1898                 power_rule->max_antenna_gain =
1899                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
1900
1901         return 0;
1902 }
1903
1904 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
1905 {
1906         int r;
1907         char *data = NULL;
1908
1909         /*
1910          * You should only get this when cfg80211 hasn't yet initialized
1911          * completely when built-in to the kernel right between the time
1912          * window between nl80211_init() and regulatory_init(), if that is
1913          * even possible.
1914          */
1915         mutex_lock(&cfg80211_mutex);
1916         if (unlikely(!cfg80211_regdomain)) {
1917                 r = -EINPROGRESS;
1918                 goto out;
1919         }
1920
1921         if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) {
1922                 r = -EINVAL;
1923                 goto out;
1924         }
1925
1926         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
1927
1928 #ifdef CONFIG_WIRELESS_OLD_REGULATORY
1929         /* We ignore world regdom requests with the old regdom setup */
1930         if (is_world_regdom(data)) {
1931                 r = -EINVAL;
1932                 goto out;
1933         }
1934 #endif
1935         r = __regulatory_hint(NULL, REGDOM_SET_BY_USER, data, 0, ENVIRON_ANY);
1936         /*
1937          * This means the regulatory domain was already set, however
1938          * we don't want to confuse userspace with a "successful error"
1939          * message so lets just treat it as a success
1940          */
1941         if (r == -EALREADY)
1942                 r = 0;
1943 out:
1944         mutex_unlock(&cfg80211_mutex);
1945         return r;
1946 }
1947
1948 static int nl80211_get_mesh_params(struct sk_buff *skb,
1949         struct genl_info *info)
1950 {
1951         struct cfg80211_registered_device *drv;
1952         struct mesh_config cur_params;
1953         int err;
1954         struct net_device *dev;
1955         void *hdr;
1956         struct nlattr *pinfoattr;
1957         struct sk_buff *msg;
1958
1959         /* Look up our device */
1960         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1961         if (err)
1962                 return err;
1963
1964         /* Get the mesh params */
1965         rtnl_lock();
1966         err = drv->ops->get_mesh_params(&drv->wiphy, dev, &cur_params);
1967         rtnl_unlock();
1968         if (err)
1969                 goto out;
1970
1971         /* Draw up a netlink message to send back */
1972         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1973         if (!msg) {
1974                 err = -ENOBUFS;
1975                 goto out;
1976         }
1977         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1978                              NL80211_CMD_GET_MESH_PARAMS);
1979         if (!hdr)
1980                 goto nla_put_failure;
1981         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
1982         if (!pinfoattr)
1983                 goto nla_put_failure;
1984         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1985         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
1986                         cur_params.dot11MeshRetryTimeout);
1987         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
1988                         cur_params.dot11MeshConfirmTimeout);
1989         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
1990                         cur_params.dot11MeshHoldingTimeout);
1991         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
1992                         cur_params.dot11MeshMaxPeerLinks);
1993         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
1994                         cur_params.dot11MeshMaxRetries);
1995         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
1996                         cur_params.dot11MeshTTL);
1997         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
1998                         cur_params.auto_open_plinks);
1999         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2000                         cur_params.dot11MeshHWMPmaxPREQretries);
2001         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2002                         cur_params.path_refresh_time);
2003         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2004                         cur_params.min_discovery_timeout);
2005         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2006                         cur_params.dot11MeshHWMPactivePathTimeout);
2007         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2008                         cur_params.dot11MeshHWMPpreqMinInterval);
2009         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2010                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2011         nla_nest_end(msg, pinfoattr);
2012         genlmsg_end(msg, hdr);
2013         err = genlmsg_unicast(msg, info->snd_pid);
2014         goto out;
2015
2016 nla_put_failure:
2017         genlmsg_cancel(msg, hdr);
2018         err = -EMSGSIZE;
2019 out:
2020         /* Cleanup */
2021         cfg80211_put_dev(drv);
2022         dev_put(dev);
2023         return err;
2024 }
2025
2026 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2027 do {\
2028         if (table[attr_num]) {\
2029                 cfg.param = nla_fn(table[attr_num]); \
2030                 mask |= (1 << (attr_num - 1)); \
2031         } \
2032 } while (0);\
2033
2034 static struct nla_policy
2035 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2036         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2037         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2038         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2039         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2040         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2041         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2042         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2043
2044         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2045         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2046         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2047         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2048         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2049         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2050 };
2051
2052 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2053 {
2054         int err;
2055         u32 mask;
2056         struct cfg80211_registered_device *drv;
2057         struct net_device *dev;
2058         struct mesh_config cfg;
2059         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2060         struct nlattr *parent_attr;
2061
2062         parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2063         if (!parent_attr)
2064                 return -EINVAL;
2065         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2066                         parent_attr, nl80211_meshconf_params_policy))
2067                 return -EINVAL;
2068
2069         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2070         if (err)
2071                 return err;
2072
2073         /* This makes sure that there aren't more than 32 mesh config
2074          * parameters (otherwise our bitfield scheme would not work.) */
2075         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2076
2077         /* Fill in the params struct */
2078         mask = 0;
2079         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2080                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2081         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2082                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2083         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2084                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2085         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2086                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2087         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2088                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2089         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2090                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
2091         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2092                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2093         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2094                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2095                         nla_get_u8);
2096         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2097                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2098         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2099                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2100                         nla_get_u16);
2101         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2102                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2103                         nla_get_u32);
2104         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2105                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2106                         nla_get_u16);
2107         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2108                         dot11MeshHWMPnetDiameterTraversalTime,
2109                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2110                         nla_get_u16);
2111
2112         /* Apply changes */
2113         rtnl_lock();
2114         err = drv->ops->set_mesh_params(&drv->wiphy, dev, &cfg, mask);
2115         rtnl_unlock();
2116
2117         /* cleanup */
2118         cfg80211_put_dev(drv);
2119         dev_put(dev);
2120         return err;
2121 }
2122
2123 #undef FILL_IN_MESH_PARAM_IF_SET
2124
2125 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2126 {
2127         struct sk_buff *msg;
2128         void *hdr = NULL;
2129         struct nlattr *nl_reg_rules;
2130         unsigned int i;
2131         int err = -EINVAL;
2132
2133         mutex_lock(&cfg80211_mutex);
2134
2135         if (!cfg80211_regdomain)
2136                 goto out;
2137
2138         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2139         if (!msg) {
2140                 err = -ENOBUFS;
2141                 goto out;
2142         }
2143
2144         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2145                              NL80211_CMD_GET_REG);
2146         if (!hdr)
2147                 goto nla_put_failure;
2148
2149         NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2150                 cfg80211_regdomain->alpha2);
2151
2152         nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2153         if (!nl_reg_rules)
2154                 goto nla_put_failure;
2155
2156         for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2157                 struct nlattr *nl_reg_rule;
2158                 const struct ieee80211_reg_rule *reg_rule;
2159                 const struct ieee80211_freq_range *freq_range;
2160                 const struct ieee80211_power_rule *power_rule;
2161
2162                 reg_rule = &cfg80211_regdomain->reg_rules[i];
2163                 freq_range = &reg_rule->freq_range;
2164                 power_rule = &reg_rule->power_rule;
2165
2166                 nl_reg_rule = nla_nest_start(msg, i);
2167                 if (!nl_reg_rule)
2168                         goto nla_put_failure;
2169
2170                 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2171                         reg_rule->flags);
2172                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2173                         freq_range->start_freq_khz);
2174                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2175                         freq_range->end_freq_khz);
2176                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2177                         freq_range->max_bandwidth_khz);
2178                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2179                         power_rule->max_antenna_gain);
2180                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2181                         power_rule->max_eirp);
2182
2183                 nla_nest_end(msg, nl_reg_rule);
2184         }
2185
2186         nla_nest_end(msg, nl_reg_rules);
2187
2188         genlmsg_end(msg, hdr);
2189         err = genlmsg_unicast(msg, info->snd_pid);
2190         goto out;
2191
2192 nla_put_failure:
2193         genlmsg_cancel(msg, hdr);
2194         err = -EMSGSIZE;
2195 out:
2196         mutex_unlock(&cfg80211_mutex);
2197         return err;
2198 }
2199
2200 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2201 {
2202         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2203         struct nlattr *nl_reg_rule;
2204         char *alpha2 = NULL;
2205         int rem_reg_rules = 0, r = 0;
2206         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2207         struct ieee80211_regdomain *rd = NULL;
2208
2209         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2210                 return -EINVAL;
2211
2212         if (!info->attrs[NL80211_ATTR_REG_RULES])
2213                 return -EINVAL;
2214
2215         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2216
2217         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2218                         rem_reg_rules) {
2219                 num_rules++;
2220                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2221                         goto bad_reg;
2222         }
2223
2224         if (!reg_is_valid_request(alpha2))
2225                 return -EINVAL;
2226
2227         size_of_regd = sizeof(struct ieee80211_regdomain) +
2228                 (num_rules * sizeof(struct ieee80211_reg_rule));
2229
2230         rd = kzalloc(size_of_regd, GFP_KERNEL);
2231         if (!rd)
2232                 return -ENOMEM;
2233
2234         rd->n_reg_rules = num_rules;
2235         rd->alpha2[0] = alpha2[0];
2236         rd->alpha2[1] = alpha2[1];
2237
2238         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2239                         rem_reg_rules) {
2240                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2241                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2242                         reg_rule_policy);
2243                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2244                 if (r)
2245                         goto bad_reg;
2246
2247                 rule_idx++;
2248
2249                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES)
2250                         goto bad_reg;
2251         }
2252
2253         BUG_ON(rule_idx != num_rules);
2254
2255         mutex_lock(&cfg80211_mutex);
2256         r = set_regdom(rd);
2257         mutex_unlock(&cfg80211_mutex);
2258         return r;
2259
2260  bad_reg:
2261         kfree(rd);
2262         return -EINVAL;
2263 }
2264
2265 static int nl80211_set_mgmt_extra_ie(struct sk_buff *skb,
2266                                      struct genl_info *info)
2267 {
2268         struct cfg80211_registered_device *drv;
2269         int err;
2270         struct net_device *dev;
2271         struct mgmt_extra_ie_params params;
2272
2273         memset(&params, 0, sizeof(params));
2274
2275         if (!info->attrs[NL80211_ATTR_MGMT_SUBTYPE])
2276                 return -EINVAL;
2277         params.subtype = nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
2278         if (params.subtype > 15)
2279                 return -EINVAL; /* FC Subtype field is 4 bits (0..15) */
2280
2281         if (info->attrs[NL80211_ATTR_IE]) {
2282                 params.ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2283                 params.ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2284         }
2285
2286         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2287         if (err)
2288                 return err;
2289
2290         if (drv->ops->set_mgmt_extra_ie) {
2291                 rtnl_lock();
2292                 err = drv->ops->set_mgmt_extra_ie(&drv->wiphy, dev, &params);
2293                 rtnl_unlock();
2294         } else
2295                 err = -EOPNOTSUPP;
2296
2297         cfg80211_put_dev(drv);
2298         dev_put(dev);
2299         return err;
2300 }
2301
2302 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2303 {
2304         struct cfg80211_registered_device *drv;
2305         struct net_device *dev;
2306         struct cfg80211_scan_request *request;
2307         struct cfg80211_ssid *ssid;
2308         struct ieee80211_channel *channel;
2309         struct nlattr *attr;
2310         struct wiphy *wiphy;
2311         int err, tmp, n_ssids = 0, n_channels = 0, i;
2312         enum ieee80211_band band;
2313         size_t ie_len;
2314
2315         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
2316         if (err)
2317                 return err;
2318
2319         wiphy = &drv->wiphy;
2320
2321         if (!drv->ops->scan) {
2322                 err = -EOPNOTSUPP;
2323                 goto out;
2324         }
2325
2326         rtnl_lock();
2327
2328         if (drv->scan_req) {
2329                 err = -EBUSY;
2330                 goto out_unlock;
2331         }
2332
2333         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2334                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp)
2335                         n_channels++;
2336                 if (!n_channels) {
2337                         err = -EINVAL;
2338                         goto out_unlock;
2339                 }
2340         } else {
2341                 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2342                         if (wiphy->bands[band])
2343                                 n_channels += wiphy->bands[band]->n_channels;
2344         }
2345
2346         if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2347                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2348                         n_ssids++;
2349
2350         if (n_ssids > wiphy->max_scan_ssids) {
2351                 err = -EINVAL;
2352                 goto out_unlock;
2353         }
2354
2355         if (info->attrs[NL80211_ATTR_IE])
2356                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2357         else
2358                 ie_len = 0;
2359
2360         request = kzalloc(sizeof(*request)
2361                         + sizeof(*ssid) * n_ssids
2362                         + sizeof(channel) * n_channels
2363                         + ie_len, GFP_KERNEL);
2364         if (!request) {
2365                 err = -ENOMEM;
2366                 goto out_unlock;
2367         }
2368
2369         request->channels = (void *)((char *)request + sizeof(*request));
2370         request->n_channels = n_channels;
2371         if (n_ssids)
2372                 request->ssids = (void *)(request->channels + n_channels);
2373         request->n_ssids = n_ssids;
2374         if (ie_len) {
2375                 if (request->ssids)
2376                         request->ie = (void *)(request->ssids + n_ssids);
2377                 else
2378                         request->ie = (void *)(request->channels + n_channels);
2379         }
2380
2381         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2382                 /* user specified, bail out if channel not found */
2383                 request->n_channels = n_channels;
2384                 i = 0;
2385                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
2386                         request->channels[i] = ieee80211_get_channel(wiphy, nla_get_u32(attr));
2387                         if (!request->channels[i]) {
2388                                 err = -EINVAL;
2389                                 goto out_free;
2390                         }
2391                         i++;
2392                 }
2393         } else {
2394                 /* all channels */
2395                 i = 0;
2396                 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
2397                         int j;
2398                         if (!wiphy->bands[band])
2399                                 continue;
2400                         for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
2401                                 request->channels[i] = &wiphy->bands[band]->channels[j];
2402                                 i++;
2403                         }
2404                 }
2405         }
2406
2407         i = 0;
2408         if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
2409                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
2410                         if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
2411                                 err = -EINVAL;
2412                                 goto out_free;
2413                         }
2414                         memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2415                         request->ssids[i].ssid_len = nla_len(attr);
2416                         i++;
2417                 }
2418         }
2419
2420         if (info->attrs[NL80211_ATTR_IE]) {
2421                 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2422                 memcpy(request->ie, nla_data(info->attrs[NL80211_ATTR_IE]),
2423                        request->ie_len);
2424         }
2425
2426         request->ifidx = dev->ifindex;
2427         request->wiphy = &drv->wiphy;
2428
2429         drv->scan_req = request;
2430         err = drv->ops->scan(&drv->wiphy, dev, request);
2431
2432  out_free:
2433         if (err) {
2434                 drv->scan_req = NULL;
2435                 kfree(request);
2436         }
2437  out_unlock:
2438         rtnl_unlock();
2439  out:
2440         cfg80211_put_dev(drv);
2441         dev_put(dev);
2442         return err;
2443 }
2444
2445 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
2446                             struct cfg80211_registered_device *rdev,
2447                             struct net_device *dev,
2448                             struct cfg80211_bss *res)
2449 {
2450         void *hdr;
2451         struct nlattr *bss;
2452
2453         hdr = nl80211hdr_put(msg, pid, seq, flags,
2454                              NL80211_CMD_NEW_SCAN_RESULTS);
2455         if (!hdr)
2456                 return -1;
2457
2458         NLA_PUT_U32(msg, NL80211_ATTR_SCAN_GENERATION,
2459                     rdev->bss_generation);
2460         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2461
2462         bss = nla_nest_start(msg, NL80211_ATTR_BSS);
2463         if (!bss)
2464                 goto nla_put_failure;
2465         if (!is_zero_ether_addr(res->bssid))
2466                 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
2467         if (res->information_elements && res->len_information_elements)
2468                 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
2469                         res->len_information_elements,
2470                         res->information_elements);
2471         if (res->tsf)
2472                 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
2473         if (res->beacon_interval)
2474                 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
2475         NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
2476         NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
2477
2478         switch (rdev->wiphy.signal_type) {
2479         case CFG80211_SIGNAL_TYPE_MBM:
2480                 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
2481                 break;
2482         case CFG80211_SIGNAL_TYPE_UNSPEC:
2483                 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
2484                 break;
2485         default:
2486                 break;
2487         }
2488
2489         nla_nest_end(msg, bss);
2490
2491         return genlmsg_end(msg, hdr);
2492
2493  nla_put_failure:
2494         genlmsg_cancel(msg, hdr);
2495         return -EMSGSIZE;
2496 }
2497
2498 static int nl80211_dump_scan(struct sk_buff *skb,
2499                              struct netlink_callback *cb)
2500 {
2501         struct cfg80211_registered_device *dev;
2502         struct net_device *netdev;
2503         struct cfg80211_internal_bss *scan;
2504         int ifidx = cb->args[0];
2505         int start = cb->args[1], idx = 0;
2506         int err;
2507
2508         if (!ifidx) {
2509                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
2510                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
2511                                   nl80211_policy);
2512                 if (err)
2513                         return err;
2514
2515                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
2516                         return -EINVAL;
2517
2518                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
2519                 if (!ifidx)
2520                         return -EINVAL;
2521                 cb->args[0] = ifidx;
2522         }
2523
2524         netdev = dev_get_by_index(&init_net, ifidx);
2525         if (!netdev)
2526                 return -ENODEV;
2527
2528         dev = cfg80211_get_dev_from_ifindex(ifidx);
2529         if (IS_ERR(dev)) {
2530                 err = PTR_ERR(dev);
2531                 goto out_put_netdev;
2532         }
2533
2534         spin_lock_bh(&dev->bss_lock);
2535         cfg80211_bss_expire(dev);
2536
2537         list_for_each_entry(scan, &dev->bss_list, list) {
2538                 if (++idx <= start)
2539                         continue;
2540                 if (nl80211_send_bss(skb,
2541                                 NETLINK_CB(cb->skb).pid,
2542                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2543                                 dev, netdev, &scan->pub) < 0) {
2544                         idx--;
2545                         goto out;
2546                 }
2547         }
2548
2549  out:
2550         spin_unlock_bh(&dev->bss_lock);
2551
2552         cb->args[1] = idx;
2553         err = skb->len;
2554         cfg80211_put_dev(dev);
2555  out_put_netdev:
2556         dev_put(netdev);
2557
2558         return err;
2559 }
2560
2561 static struct genl_ops nl80211_ops[] = {
2562         {
2563                 .cmd = NL80211_CMD_GET_WIPHY,
2564                 .doit = nl80211_get_wiphy,
2565                 .dumpit = nl80211_dump_wiphy,
2566                 .policy = nl80211_policy,
2567                 /* can be retrieved by unprivileged users */
2568         },
2569         {
2570                 .cmd = NL80211_CMD_SET_WIPHY,
2571                 .doit = nl80211_set_wiphy,
2572                 .policy = nl80211_policy,
2573                 .flags = GENL_ADMIN_PERM,
2574         },
2575         {
2576                 .cmd = NL80211_CMD_GET_INTERFACE,
2577                 .doit = nl80211_get_interface,
2578                 .dumpit = nl80211_dump_interface,
2579                 .policy = nl80211_policy,
2580                 /* can be retrieved by unprivileged users */
2581         },
2582         {
2583                 .cmd = NL80211_CMD_SET_INTERFACE,
2584                 .doit = nl80211_set_interface,
2585                 .policy = nl80211_policy,
2586                 .flags = GENL_ADMIN_PERM,
2587         },
2588         {
2589                 .cmd = NL80211_CMD_NEW_INTERFACE,
2590                 .doit = nl80211_new_interface,
2591                 .policy = nl80211_policy,
2592                 .flags = GENL_ADMIN_PERM,
2593         },
2594         {
2595                 .cmd = NL80211_CMD_DEL_INTERFACE,
2596                 .doit = nl80211_del_interface,
2597                 .policy = nl80211_policy,
2598                 .flags = GENL_ADMIN_PERM,
2599         },
2600         {
2601                 .cmd = NL80211_CMD_GET_KEY,
2602                 .doit = nl80211_get_key,
2603                 .policy = nl80211_policy,
2604                 .flags = GENL_ADMIN_PERM,
2605         },
2606         {
2607                 .cmd = NL80211_CMD_SET_KEY,
2608                 .doit = nl80211_set_key,
2609                 .policy = nl80211_policy,
2610                 .flags = GENL_ADMIN_PERM,
2611         },
2612         {
2613                 .cmd = NL80211_CMD_NEW_KEY,
2614                 .doit = nl80211_new_key,
2615                 .policy = nl80211_policy,
2616                 .flags = GENL_ADMIN_PERM,
2617         },
2618         {
2619                 .cmd = NL80211_CMD_DEL_KEY,
2620                 .doit = nl80211_del_key,
2621                 .policy = nl80211_policy,
2622                 .flags = GENL_ADMIN_PERM,
2623         },
2624         {
2625                 .cmd = NL80211_CMD_SET_BEACON,
2626                 .policy = nl80211_policy,
2627                 .flags = GENL_ADMIN_PERM,
2628                 .doit = nl80211_addset_beacon,
2629         },
2630         {
2631                 .cmd = NL80211_CMD_NEW_BEACON,
2632                 .policy = nl80211_policy,
2633                 .flags = GENL_ADMIN_PERM,
2634                 .doit = nl80211_addset_beacon,
2635         },
2636         {
2637                 .cmd = NL80211_CMD_DEL_BEACON,
2638                 .policy = nl80211_policy,
2639                 .flags = GENL_ADMIN_PERM,
2640                 .doit = nl80211_del_beacon,
2641         },
2642         {
2643                 .cmd = NL80211_CMD_GET_STATION,
2644                 .doit = nl80211_get_station,
2645                 .dumpit = nl80211_dump_station,
2646                 .policy = nl80211_policy,
2647         },
2648         {
2649                 .cmd = NL80211_CMD_SET_STATION,
2650                 .doit = nl80211_set_station,
2651                 .policy = nl80211_policy,
2652                 .flags = GENL_ADMIN_PERM,
2653         },
2654         {
2655                 .cmd = NL80211_CMD_NEW_STATION,
2656                 .doit = nl80211_new_station,
2657                 .policy = nl80211_policy,
2658                 .flags = GENL_ADMIN_PERM,
2659         },
2660         {
2661                 .cmd = NL80211_CMD_DEL_STATION,
2662                 .doit = nl80211_del_station,
2663                 .policy = nl80211_policy,
2664                 .flags = GENL_ADMIN_PERM,
2665         },
2666         {
2667                 .cmd = NL80211_CMD_GET_MPATH,
2668                 .doit = nl80211_get_mpath,
2669                 .dumpit = nl80211_dump_mpath,
2670                 .policy = nl80211_policy,
2671                 .flags = GENL_ADMIN_PERM,
2672         },
2673         {
2674                 .cmd = NL80211_CMD_SET_MPATH,
2675                 .doit = nl80211_set_mpath,
2676                 .policy = nl80211_policy,
2677                 .flags = GENL_ADMIN_PERM,
2678         },
2679         {
2680                 .cmd = NL80211_CMD_NEW_MPATH,
2681                 .doit = nl80211_new_mpath,
2682                 .policy = nl80211_policy,
2683                 .flags = GENL_ADMIN_PERM,
2684         },
2685         {
2686                 .cmd = NL80211_CMD_DEL_MPATH,
2687                 .doit = nl80211_del_mpath,
2688                 .policy = nl80211_policy,
2689                 .flags = GENL_ADMIN_PERM,
2690         },
2691         {
2692                 .cmd = NL80211_CMD_SET_BSS,
2693                 .doit = nl80211_set_bss,
2694                 .policy = nl80211_policy,
2695                 .flags = GENL_ADMIN_PERM,
2696         },
2697         {
2698                 .cmd = NL80211_CMD_GET_REG,
2699                 .doit = nl80211_get_reg,
2700                 .policy = nl80211_policy,
2701                 /* can be retrieved by unprivileged users */
2702         },
2703         {
2704                 .cmd = NL80211_CMD_SET_REG,
2705                 .doit = nl80211_set_reg,
2706                 .policy = nl80211_policy,
2707                 .flags = GENL_ADMIN_PERM,
2708         },
2709         {
2710                 .cmd = NL80211_CMD_REQ_SET_REG,
2711                 .doit = nl80211_req_set_reg,
2712                 .policy = nl80211_policy,
2713                 .flags = GENL_ADMIN_PERM,
2714         },
2715         {
2716                 .cmd = NL80211_CMD_GET_MESH_PARAMS,
2717                 .doit = nl80211_get_mesh_params,
2718                 .policy = nl80211_policy,
2719                 /* can be retrieved by unprivileged users */
2720         },
2721         {
2722                 .cmd = NL80211_CMD_SET_MESH_PARAMS,
2723                 .doit = nl80211_set_mesh_params,
2724                 .policy = nl80211_policy,
2725                 .flags = GENL_ADMIN_PERM,
2726         },
2727         {
2728                 .cmd = NL80211_CMD_SET_MGMT_EXTRA_IE,
2729                 .doit = nl80211_set_mgmt_extra_ie,
2730                 .policy = nl80211_policy,
2731                 .flags = GENL_ADMIN_PERM,
2732         },
2733         {
2734                 .cmd = NL80211_CMD_TRIGGER_SCAN,
2735                 .doit = nl80211_trigger_scan,
2736                 .policy = nl80211_policy,
2737                 .flags = GENL_ADMIN_PERM,
2738         },
2739         {
2740                 .cmd = NL80211_CMD_GET_SCAN,
2741                 .policy = nl80211_policy,
2742                 .dumpit = nl80211_dump_scan,
2743         },
2744 };
2745
2746 /* multicast groups */
2747 static struct genl_multicast_group nl80211_config_mcgrp = {
2748         .name = "config",
2749 };
2750 static struct genl_multicast_group nl80211_scan_mcgrp = {
2751         .name = "scan",
2752 };
2753
2754 /* notification functions */
2755
2756 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
2757 {
2758         struct sk_buff *msg;
2759
2760         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2761         if (!msg)
2762                 return;
2763
2764         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
2765                 nlmsg_free(msg);
2766                 return;
2767         }
2768
2769         genlmsg_multicast(msg, 0, nl80211_config_mcgrp.id, GFP_KERNEL);
2770 }
2771
2772 static int nl80211_send_scan_donemsg(struct sk_buff *msg,
2773                                     struct cfg80211_registered_device *rdev,
2774                                     struct net_device *netdev,
2775                                     u32 pid, u32 seq, int flags,
2776                                     u32 cmd)
2777 {
2778         void *hdr;
2779
2780         hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
2781         if (!hdr)
2782                 return -1;
2783
2784         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2785         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
2786
2787         /* XXX: we should probably bounce back the request? */
2788
2789         return genlmsg_end(msg, hdr);
2790
2791  nla_put_failure:
2792         genlmsg_cancel(msg, hdr);
2793         return -EMSGSIZE;
2794 }
2795
2796 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
2797                             struct net_device *netdev)
2798 {
2799         struct sk_buff *msg;
2800
2801         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2802         if (!msg)
2803                 return;
2804
2805         if (nl80211_send_scan_donemsg(msg, rdev, netdev, 0, 0, 0,
2806                                       NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2807                 nlmsg_free(msg);
2808                 return;
2809         }
2810
2811         genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
2812 }
2813
2814 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
2815                                struct net_device *netdev)
2816 {
2817         struct sk_buff *msg;
2818
2819         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2820         if (!msg)
2821                 return;
2822
2823         if (nl80211_send_scan_donemsg(msg, rdev, netdev, 0, 0, 0,
2824                                       NL80211_CMD_SCAN_ABORTED) < 0) {
2825                 nlmsg_free(msg);
2826                 return;
2827         }
2828
2829         genlmsg_multicast(msg, 0, nl80211_scan_mcgrp.id, GFP_KERNEL);
2830 }
2831
2832 /* initialisation/exit functions */
2833
2834 int nl80211_init(void)
2835 {
2836         int err, i;
2837
2838         err = genl_register_family(&nl80211_fam);
2839         if (err)
2840                 return err;
2841
2842         for (i = 0; i < ARRAY_SIZE(nl80211_ops); i++) {
2843                 err = genl_register_ops(&nl80211_fam, &nl80211_ops[i]);
2844                 if (err)
2845                         goto err_out;
2846         }
2847
2848         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
2849         if (err)
2850                 goto err_out;
2851
2852         err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
2853         if (err)
2854                 goto err_out;
2855
2856         return 0;
2857  err_out:
2858         genl_unregister_family(&nl80211_fam);
2859         return err;
2860 }
2861
2862 void nl80211_exit(void)
2863 {
2864         genl_unregister_family(&nl80211_fam);
2865 }