]> pilppa.org Git - linux-2.6-omap-h63xx.git/blob - net/wireless/nl80211.c
Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/linville/wirel...
[linux-2.6-omap-h63xx.git] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006, 2007 Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/mutex.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <net/genetlink.h>
18 #include <net/cfg80211.h>
19 #include "core.h"
20 #include "nl80211.h"
21 #include "reg.h"
22
23 /* the netlink family */
24 static struct genl_family nl80211_fam = {
25         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
26         .name = "nl80211",      /* have users key off the name instead */
27         .hdrsize = 0,           /* no private header */
28         .version = 1,           /* no particular meaning now */
29         .maxattr = NL80211_ATTR_MAX,
30 };
31
32 /* internal helper: get drv and dev */
33 static int get_drv_dev_by_info_ifindex(struct nlattr **attrs,
34                                        struct cfg80211_registered_device **drv,
35                                        struct net_device **dev)
36 {
37         int ifindex;
38
39         if (!attrs[NL80211_ATTR_IFINDEX])
40                 return -EINVAL;
41
42         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
43         *dev = dev_get_by_index(&init_net, ifindex);
44         if (!*dev)
45                 return -ENODEV;
46
47         *drv = cfg80211_get_dev_from_ifindex(ifindex);
48         if (IS_ERR(*drv)) {
49                 dev_put(*dev);
50                 return PTR_ERR(*drv);
51         }
52
53         return 0;
54 }
55
56 /* policy for the attributes */
57 static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
58         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
59         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
60                                       .len = BUS_ID_SIZE-1 },
61         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
62         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
63         [NL80211_ATTR_WIPHY_SEC_CHAN_OFFSET] = { .type = NLA_U32 },
64
65         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
66         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
67         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
68
69         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
70
71         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
72                                     .len = WLAN_MAX_KEY_LEN },
73         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
74         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
75         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
76
77         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
78         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
79         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
80                                        .len = IEEE80211_MAX_DATA_LEN },
81         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
82                                        .len = IEEE80211_MAX_DATA_LEN },
83         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
84         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
85         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
86         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
87                                                .len = NL80211_MAX_SUPP_RATES },
88         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
89         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
90         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
91         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
92                                 .len = IEEE80211_MAX_MESH_ID_LEN },
93         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
94
95         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
96         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
97
98         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
99         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
100         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
101         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
102                                            .len = NL80211_MAX_SUPP_RATES },
103
104         [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
105
106         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
107                                          .len = NL80211_HT_CAPABILITY_LEN },
108 };
109
110 /* message building helper */
111 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
112                                    int flags, u8 cmd)
113 {
114         /* since there is no private header just add the generic one */
115         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
116 }
117
118 /* netlink command implementations */
119
120 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
121                               struct cfg80211_registered_device *dev)
122 {
123         void *hdr;
124         struct nlattr *nl_bands, *nl_band;
125         struct nlattr *nl_freqs, *nl_freq;
126         struct nlattr *nl_rates, *nl_rate;
127         struct nlattr *nl_modes;
128         enum ieee80211_band band;
129         struct ieee80211_channel *chan;
130         struct ieee80211_rate *rate;
131         int i;
132         u16 ifmodes = dev->wiphy.interface_modes;
133
134         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
135         if (!hdr)
136                 return -1;
137
138         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->idx);
139         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
140
141         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
142         if (!nl_modes)
143                 goto nla_put_failure;
144
145         i = 0;
146         while (ifmodes) {
147                 if (ifmodes & 1)
148                         NLA_PUT_FLAG(msg, i);
149                 ifmodes >>= 1;
150                 i++;
151         }
152
153         nla_nest_end(msg, nl_modes);
154
155         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
156         if (!nl_bands)
157                 goto nla_put_failure;
158
159         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
160                 if (!dev->wiphy.bands[band])
161                         continue;
162
163                 nl_band = nla_nest_start(msg, band);
164                 if (!nl_band)
165                         goto nla_put_failure;
166
167                 /* add HT info */
168                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
169                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
170                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
171                                 &dev->wiphy.bands[band]->ht_cap.mcs);
172                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
173                                 dev->wiphy.bands[band]->ht_cap.cap);
174                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
175                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
176                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
177                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
178                 }
179
180                 /* add frequencies */
181                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
182                 if (!nl_freqs)
183                         goto nla_put_failure;
184
185                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
186                         nl_freq = nla_nest_start(msg, i);
187                         if (!nl_freq)
188                                 goto nla_put_failure;
189
190                         chan = &dev->wiphy.bands[band]->channels[i];
191                         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
192                                     chan->center_freq);
193
194                         if (chan->flags & IEEE80211_CHAN_DISABLED)
195                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
196                         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
197                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
198                         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
199                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
200                         if (chan->flags & IEEE80211_CHAN_RADAR)
201                                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
202
203                         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
204                                     DBM_TO_MBM(chan->max_power));
205
206                         nla_nest_end(msg, nl_freq);
207                 }
208
209                 nla_nest_end(msg, nl_freqs);
210
211                 /* add bitrates */
212                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
213                 if (!nl_rates)
214                         goto nla_put_failure;
215
216                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
217                         nl_rate = nla_nest_start(msg, i);
218                         if (!nl_rate)
219                                 goto nla_put_failure;
220
221                         rate = &dev->wiphy.bands[band]->bitrates[i];
222                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
223                                     rate->bitrate);
224                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
225                                 NLA_PUT_FLAG(msg,
226                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
227
228                         nla_nest_end(msg, nl_rate);
229                 }
230
231                 nla_nest_end(msg, nl_rates);
232
233                 nla_nest_end(msg, nl_band);
234         }
235         nla_nest_end(msg, nl_bands);
236
237         return genlmsg_end(msg, hdr);
238
239  nla_put_failure:
240         genlmsg_cancel(msg, hdr);
241         return -EMSGSIZE;
242 }
243
244 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
245 {
246         int idx = 0;
247         int start = cb->args[0];
248         struct cfg80211_registered_device *dev;
249
250         mutex_lock(&cfg80211_drv_mutex);
251         list_for_each_entry(dev, &cfg80211_drv_list, list) {
252                 if (++idx <= start)
253                         continue;
254                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
255                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
256                                        dev) < 0) {
257                         idx--;
258                         break;
259                 }
260         }
261         mutex_unlock(&cfg80211_drv_mutex);
262
263         cb->args[0] = idx;
264
265         return skb->len;
266 }
267
268 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
269 {
270         struct sk_buff *msg;
271         struct cfg80211_registered_device *dev;
272
273         dev = cfg80211_get_dev_from_info(info);
274         if (IS_ERR(dev))
275                 return PTR_ERR(dev);
276
277         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
278         if (!msg)
279                 goto out_err;
280
281         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
282                 goto out_free;
283
284         cfg80211_put_dev(dev);
285
286         return genlmsg_unicast(msg, info->snd_pid);
287
288  out_free:
289         nlmsg_free(msg);
290  out_err:
291         cfg80211_put_dev(dev);
292         return -ENOBUFS;
293 }
294
295 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
296         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
297         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
298         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
299         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
300         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
301 };
302
303 static int parse_txq_params(struct nlattr *tb[],
304                             struct ieee80211_txq_params *txq_params)
305 {
306         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
307             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
308             !tb[NL80211_TXQ_ATTR_AIFS])
309                 return -EINVAL;
310
311         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
312         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
313         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
314         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
315         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
316
317         return 0;
318 }
319
320 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
321 {
322         struct cfg80211_registered_device *rdev;
323         int result = 0, rem_txq_params = 0;
324         struct nlattr *nl_txq_params;
325
326         rdev = cfg80211_get_dev_from_info(info);
327         if (IS_ERR(rdev))
328                 return PTR_ERR(rdev);
329
330         if (info->attrs[NL80211_ATTR_WIPHY_NAME]) {
331                 result = cfg80211_dev_rename(
332                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
333                 if (result)
334                         goto bad_res;
335         }
336
337         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
338                 struct ieee80211_txq_params txq_params;
339                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
340
341                 if (!rdev->ops->set_txq_params) {
342                         result = -EOPNOTSUPP;
343                         goto bad_res;
344                 }
345
346                 nla_for_each_nested(nl_txq_params,
347                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
348                                     rem_txq_params) {
349                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
350                                   nla_data(nl_txq_params),
351                                   nla_len(nl_txq_params),
352                                   txq_params_policy);
353                         result = parse_txq_params(tb, &txq_params);
354                         if (result)
355                                 goto bad_res;
356
357                         result = rdev->ops->set_txq_params(&rdev->wiphy,
358                                                            &txq_params);
359                         if (result)
360                                 goto bad_res;
361                 }
362         }
363
364         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
365                 enum nl80211_sec_chan_offset sec_chan_offset =
366                         NL80211_SEC_CHAN_NO_HT;
367                 struct ieee80211_channel *chan;
368                 struct ieee80211_sta_ht_cap *ht_cap;
369                 u32 freq, sec_freq;
370
371                 if (!rdev->ops->set_channel) {
372                         result = -EOPNOTSUPP;
373                         goto bad_res;
374                 }
375
376                 result = -EINVAL;
377
378                 if (info->attrs[NL80211_ATTR_WIPHY_SEC_CHAN_OFFSET]) {
379                         sec_chan_offset = nla_get_u32(info->attrs[
380                                         NL80211_ATTR_WIPHY_SEC_CHAN_OFFSET]);
381                         if (sec_chan_offset != NL80211_SEC_CHAN_NO_HT &&
382                             sec_chan_offset != NL80211_SEC_CHAN_DISABLED &&
383                             sec_chan_offset != NL80211_SEC_CHAN_BELOW &&
384                             sec_chan_offset != NL80211_SEC_CHAN_ABOVE)
385                                 goto bad_res;
386                 }
387
388                 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
389                 chan = ieee80211_get_channel(&rdev->wiphy, freq);
390
391                 /* Primary channel not allowed */
392                 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
393                         goto bad_res;
394
395                 if (sec_chan_offset == NL80211_SEC_CHAN_BELOW)
396                         sec_freq = freq - 20;
397                 else if (sec_chan_offset == NL80211_SEC_CHAN_ABOVE)
398                         sec_freq = freq + 20;
399                 else
400                         sec_freq = 0;
401
402                 ht_cap = &rdev->wiphy.bands[chan->band]->ht_cap;
403
404                 /* no HT capabilities */
405                 if (sec_chan_offset != NL80211_SEC_CHAN_NO_HT &&
406                     !ht_cap->ht_supported)
407                         goto bad_res;
408
409                 if (sec_freq) {
410                         struct ieee80211_channel *schan;
411
412                         /* no 40 MHz capabilities */
413                         if (!(ht_cap->cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40) ||
414                             (ht_cap->cap & IEEE80211_HT_CAP_40MHZ_INTOLERANT))
415                                 goto bad_res;
416
417                         schan = ieee80211_get_channel(&rdev->wiphy, sec_freq);
418
419                         /* Secondary channel not allowed */
420                         if (!schan || schan->flags & IEEE80211_CHAN_DISABLED)
421                                 goto bad_res;
422                 }
423
424                 result = rdev->ops->set_channel(&rdev->wiphy, chan,
425                                                 sec_chan_offset);
426                 if (result)
427                         goto bad_res;
428         }
429
430
431  bad_res:
432         cfg80211_put_dev(rdev);
433         return result;
434 }
435
436
437 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
438                               struct net_device *dev)
439 {
440         void *hdr;
441
442         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
443         if (!hdr)
444                 return -1;
445
446         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
447         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
448         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
449         return genlmsg_end(msg, hdr);
450
451  nla_put_failure:
452         genlmsg_cancel(msg, hdr);
453         return -EMSGSIZE;
454 }
455
456 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
457 {
458         int wp_idx = 0;
459         int if_idx = 0;
460         int wp_start = cb->args[0];
461         int if_start = cb->args[1];
462         struct cfg80211_registered_device *dev;
463         struct wireless_dev *wdev;
464
465         mutex_lock(&cfg80211_drv_mutex);
466         list_for_each_entry(dev, &cfg80211_drv_list, list) {
467                 if (wp_idx < wp_start) {
468                         wp_idx++;
469                         continue;
470                 }
471                 if_idx = 0;
472
473                 mutex_lock(&dev->devlist_mtx);
474                 list_for_each_entry(wdev, &dev->netdev_list, list) {
475                         if (if_idx < if_start) {
476                                 if_idx++;
477                                 continue;
478                         }
479                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
480                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
481                                                wdev->netdev) < 0) {
482                                 mutex_unlock(&dev->devlist_mtx);
483                                 goto out;
484                         }
485                         if_idx++;
486                 }
487                 mutex_unlock(&dev->devlist_mtx);
488
489                 wp_idx++;
490         }
491  out:
492         mutex_unlock(&cfg80211_drv_mutex);
493
494         cb->args[0] = wp_idx;
495         cb->args[1] = if_idx;
496
497         return skb->len;
498 }
499
500 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
501 {
502         struct sk_buff *msg;
503         struct cfg80211_registered_device *dev;
504         struct net_device *netdev;
505         int err;
506
507         err = get_drv_dev_by_info_ifindex(info->attrs, &dev, &netdev);
508         if (err)
509                 return err;
510
511         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
512         if (!msg)
513                 goto out_err;
514
515         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0, netdev) < 0)
516                 goto out_free;
517
518         dev_put(netdev);
519         cfg80211_put_dev(dev);
520
521         return genlmsg_unicast(msg, info->snd_pid);
522
523  out_free:
524         nlmsg_free(msg);
525  out_err:
526         dev_put(netdev);
527         cfg80211_put_dev(dev);
528         return -ENOBUFS;
529 }
530
531 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
532         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
533         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
534         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
535         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
536         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
537 };
538
539 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
540 {
541         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
542         int flag;
543
544         *mntrflags = 0;
545
546         if (!nla)
547                 return -EINVAL;
548
549         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
550                              nla, mntr_flags_policy))
551                 return -EINVAL;
552
553         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
554                 if (flags[flag])
555                         *mntrflags |= (1<<flag);
556
557         return 0;
558 }
559
560 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
561 {
562         struct cfg80211_registered_device *drv;
563         struct vif_params params;
564         int err, ifindex;
565         enum nl80211_iftype type;
566         struct net_device *dev;
567         u32 _flags, *flags = NULL;
568
569         memset(&params, 0, sizeof(params));
570
571         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
572         if (err)
573                 return err;
574         ifindex = dev->ifindex;
575         type = dev->ieee80211_ptr->iftype;
576         dev_put(dev);
577
578         err = -EINVAL;
579         if (info->attrs[NL80211_ATTR_IFTYPE]) {
580                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
581                 if (type > NL80211_IFTYPE_MAX)
582                         goto unlock;
583         }
584
585         if (!drv->ops->change_virtual_intf ||
586             !(drv->wiphy.interface_modes & (1 << type))) {
587                 err = -EOPNOTSUPP;
588                 goto unlock;
589         }
590
591         if (info->attrs[NL80211_ATTR_MESH_ID]) {
592                 if (type != NL80211_IFTYPE_MESH_POINT) {
593                         err = -EINVAL;
594                         goto unlock;
595                 }
596                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
597                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
598         }
599
600         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
601                 if (type != NL80211_IFTYPE_MONITOR) {
602                         err = -EINVAL;
603                         goto unlock;
604                 }
605                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
606                                           &_flags);
607                 if (!err)
608                         flags = &_flags;
609         }
610         rtnl_lock();
611         err = drv->ops->change_virtual_intf(&drv->wiphy, ifindex,
612                                             type, flags, &params);
613
614         dev = __dev_get_by_index(&init_net, ifindex);
615         WARN_ON(!dev || (!err && dev->ieee80211_ptr->iftype != type));
616
617         rtnl_unlock();
618
619  unlock:
620         cfg80211_put_dev(drv);
621         return err;
622 }
623
624 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
625 {
626         struct cfg80211_registered_device *drv;
627         struct vif_params params;
628         int err;
629         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
630         u32 flags;
631
632         memset(&params, 0, sizeof(params));
633
634         if (!info->attrs[NL80211_ATTR_IFNAME])
635                 return -EINVAL;
636
637         if (info->attrs[NL80211_ATTR_IFTYPE]) {
638                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
639                 if (type > NL80211_IFTYPE_MAX)
640                         return -EINVAL;
641         }
642
643         drv = cfg80211_get_dev_from_info(info);
644         if (IS_ERR(drv))
645                 return PTR_ERR(drv);
646
647         if (!drv->ops->add_virtual_intf ||
648             !(drv->wiphy.interface_modes & (1 << type))) {
649                 err = -EOPNOTSUPP;
650                 goto unlock;
651         }
652
653         if (type == NL80211_IFTYPE_MESH_POINT &&
654             info->attrs[NL80211_ATTR_MESH_ID]) {
655                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
656                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
657         }
658
659         rtnl_lock();
660         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
661                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
662                                   &flags);
663         err = drv->ops->add_virtual_intf(&drv->wiphy,
664                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
665                 type, err ? NULL : &flags, &params);
666         rtnl_unlock();
667
668
669  unlock:
670         cfg80211_put_dev(drv);
671         return err;
672 }
673
674 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
675 {
676         struct cfg80211_registered_device *drv;
677         int ifindex, err;
678         struct net_device *dev;
679
680         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
681         if (err)
682                 return err;
683         ifindex = dev->ifindex;
684         dev_put(dev);
685
686         if (!drv->ops->del_virtual_intf) {
687                 err = -EOPNOTSUPP;
688                 goto out;
689         }
690
691         rtnl_lock();
692         err = drv->ops->del_virtual_intf(&drv->wiphy, ifindex);
693         rtnl_unlock();
694
695  out:
696         cfg80211_put_dev(drv);
697         return err;
698 }
699
700 struct get_key_cookie {
701         struct sk_buff *msg;
702         int error;
703 };
704
705 static void get_key_callback(void *c, struct key_params *params)
706 {
707         struct get_key_cookie *cookie = c;
708
709         if (params->key)
710                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
711                         params->key_len, params->key);
712
713         if (params->seq)
714                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
715                         params->seq_len, params->seq);
716
717         if (params->cipher)
718                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
719                             params->cipher);
720
721         return;
722  nla_put_failure:
723         cookie->error = 1;
724 }
725
726 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
727 {
728         struct cfg80211_registered_device *drv;
729         int err;
730         struct net_device *dev;
731         u8 key_idx = 0;
732         u8 *mac_addr = NULL;
733         struct get_key_cookie cookie = {
734                 .error = 0,
735         };
736         void *hdr;
737         struct sk_buff *msg;
738
739         if (info->attrs[NL80211_ATTR_KEY_IDX])
740                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
741
742         if (key_idx > 3)
743                 return -EINVAL;
744
745         if (info->attrs[NL80211_ATTR_MAC])
746                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
747
748         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
749         if (err)
750                 return err;
751
752         if (!drv->ops->get_key) {
753                 err = -EOPNOTSUPP;
754                 goto out;
755         }
756
757         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
758         if (!msg) {
759                 err = -ENOMEM;
760                 goto out;
761         }
762
763         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
764                              NL80211_CMD_NEW_KEY);
765
766         if (IS_ERR(hdr)) {
767                 err = PTR_ERR(hdr);
768                 goto out;
769         }
770
771         cookie.msg = msg;
772
773         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
774         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
775         if (mac_addr)
776                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
777
778         rtnl_lock();
779         err = drv->ops->get_key(&drv->wiphy, dev, key_idx, mac_addr,
780                                 &cookie, get_key_callback);
781         rtnl_unlock();
782
783         if (err)
784                 goto out;
785
786         if (cookie.error)
787                 goto nla_put_failure;
788
789         genlmsg_end(msg, hdr);
790         err = genlmsg_unicast(msg, info->snd_pid);
791         goto out;
792
793  nla_put_failure:
794         err = -ENOBUFS;
795         nlmsg_free(msg);
796  out:
797         cfg80211_put_dev(drv);
798         dev_put(dev);
799         return err;
800 }
801
802 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
803 {
804         struct cfg80211_registered_device *drv;
805         int err;
806         struct net_device *dev;
807         u8 key_idx;
808
809         if (!info->attrs[NL80211_ATTR_KEY_IDX])
810                 return -EINVAL;
811
812         key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
813
814         if (key_idx > 3)
815                 return -EINVAL;
816
817         /* currently only support setting default key */
818         if (!info->attrs[NL80211_ATTR_KEY_DEFAULT])
819                 return -EINVAL;
820
821         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
822         if (err)
823                 return err;
824
825         if (!drv->ops->set_default_key) {
826                 err = -EOPNOTSUPP;
827                 goto out;
828         }
829
830         rtnl_lock();
831         err = drv->ops->set_default_key(&drv->wiphy, dev, key_idx);
832         rtnl_unlock();
833
834  out:
835         cfg80211_put_dev(drv);
836         dev_put(dev);
837         return err;
838 }
839
840 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
841 {
842         struct cfg80211_registered_device *drv;
843         int err;
844         struct net_device *dev;
845         struct key_params params;
846         u8 key_idx = 0;
847         u8 *mac_addr = NULL;
848
849         memset(&params, 0, sizeof(params));
850
851         if (!info->attrs[NL80211_ATTR_KEY_CIPHER])
852                 return -EINVAL;
853
854         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
855                 params.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
856                 params.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
857         }
858
859         if (info->attrs[NL80211_ATTR_KEY_IDX])
860                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
861
862         params.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
863
864         if (info->attrs[NL80211_ATTR_MAC])
865                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
866
867         if (key_idx > 3)
868                 return -EINVAL;
869
870         /*
871          * Disallow pairwise keys with non-zero index unless it's WEP
872          * (because current deployments use pairwise WEP keys with
873          * non-zero indizes but 802.11i clearly specifies to use zero)
874          */
875         if (mac_addr && key_idx &&
876             params.cipher != WLAN_CIPHER_SUITE_WEP40 &&
877             params.cipher != WLAN_CIPHER_SUITE_WEP104)
878                 return -EINVAL;
879
880         /* TODO: add definitions for the lengths to linux/ieee80211.h */
881         switch (params.cipher) {
882         case WLAN_CIPHER_SUITE_WEP40:
883                 if (params.key_len != 5)
884                         return -EINVAL;
885                 break;
886         case WLAN_CIPHER_SUITE_TKIP:
887                 if (params.key_len != 32)
888                         return -EINVAL;
889                 break;
890         case WLAN_CIPHER_SUITE_CCMP:
891                 if (params.key_len != 16)
892                         return -EINVAL;
893                 break;
894         case WLAN_CIPHER_SUITE_WEP104:
895                 if (params.key_len != 13)
896                         return -EINVAL;
897                 break;
898         default:
899                 return -EINVAL;
900         }
901
902         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
903         if (err)
904                 return err;
905
906         if (!drv->ops->add_key) {
907                 err = -EOPNOTSUPP;
908                 goto out;
909         }
910
911         rtnl_lock();
912         err = drv->ops->add_key(&drv->wiphy, dev, key_idx, mac_addr, &params);
913         rtnl_unlock();
914
915  out:
916         cfg80211_put_dev(drv);
917         dev_put(dev);
918         return err;
919 }
920
921 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
922 {
923         struct cfg80211_registered_device *drv;
924         int err;
925         struct net_device *dev;
926         u8 key_idx = 0;
927         u8 *mac_addr = NULL;
928
929         if (info->attrs[NL80211_ATTR_KEY_IDX])
930                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
931
932         if (key_idx > 3)
933                 return -EINVAL;
934
935         if (info->attrs[NL80211_ATTR_MAC])
936                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
937
938         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
939         if (err)
940                 return err;
941
942         if (!drv->ops->del_key) {
943                 err = -EOPNOTSUPP;
944                 goto out;
945         }
946
947         rtnl_lock();
948         err = drv->ops->del_key(&drv->wiphy, dev, key_idx, mac_addr);
949         rtnl_unlock();
950
951  out:
952         cfg80211_put_dev(drv);
953         dev_put(dev);
954         return err;
955 }
956
957 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
958 {
959         int (*call)(struct wiphy *wiphy, struct net_device *dev,
960                     struct beacon_parameters *info);
961         struct cfg80211_registered_device *drv;
962         int err;
963         struct net_device *dev;
964         struct beacon_parameters params;
965         int haveinfo = 0;
966
967         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
968         if (err)
969                 return err;
970
971         switch (info->genlhdr->cmd) {
972         case NL80211_CMD_NEW_BEACON:
973                 /* these are required for NEW_BEACON */
974                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
975                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
976                     !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
977                         err = -EINVAL;
978                         goto out;
979                 }
980
981                 call = drv->ops->add_beacon;
982                 break;
983         case NL80211_CMD_SET_BEACON:
984                 call = drv->ops->set_beacon;
985                 break;
986         default:
987                 WARN_ON(1);
988                 err = -EOPNOTSUPP;
989                 goto out;
990         }
991
992         if (!call) {
993                 err = -EOPNOTSUPP;
994                 goto out;
995         }
996
997         memset(&params, 0, sizeof(params));
998
999         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1000                 params.interval =
1001                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1002                 haveinfo = 1;
1003         }
1004
1005         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1006                 params.dtim_period =
1007                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1008                 haveinfo = 1;
1009         }
1010
1011         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1012                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1013                 params.head_len =
1014                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1015                 haveinfo = 1;
1016         }
1017
1018         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1019                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1020                 params.tail_len =
1021                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1022                 haveinfo = 1;
1023         }
1024
1025         if (!haveinfo) {
1026                 err = -EINVAL;
1027                 goto out;
1028         }
1029
1030         rtnl_lock();
1031         err = call(&drv->wiphy, dev, &params);
1032         rtnl_unlock();
1033
1034  out:
1035         cfg80211_put_dev(drv);
1036         dev_put(dev);
1037         return err;
1038 }
1039
1040 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1041 {
1042         struct cfg80211_registered_device *drv;
1043         int err;
1044         struct net_device *dev;
1045
1046         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1047         if (err)
1048                 return err;
1049
1050         if (!drv->ops->del_beacon) {
1051                 err = -EOPNOTSUPP;
1052                 goto out;
1053         }
1054
1055         rtnl_lock();
1056         err = drv->ops->del_beacon(&drv->wiphy, dev);
1057         rtnl_unlock();
1058
1059  out:
1060         cfg80211_put_dev(drv);
1061         dev_put(dev);
1062         return err;
1063 }
1064
1065 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1066         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1067         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1068         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1069 };
1070
1071 static int parse_station_flags(struct nlattr *nla, u32 *staflags)
1072 {
1073         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1074         int flag;
1075
1076         *staflags = 0;
1077
1078         if (!nla)
1079                 return 0;
1080
1081         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1082                              nla, sta_flags_policy))
1083                 return -EINVAL;
1084
1085         *staflags = STATION_FLAG_CHANGED;
1086
1087         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1088                 if (flags[flag])
1089                         *staflags |= (1<<flag);
1090
1091         return 0;
1092 }
1093
1094 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1095                                 int flags, struct net_device *dev,
1096                                 u8 *mac_addr, struct station_info *sinfo)
1097 {
1098         void *hdr;
1099         struct nlattr *sinfoattr;
1100
1101         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1102         if (!hdr)
1103                 return -1;
1104
1105         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1106         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1107
1108         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1109         if (!sinfoattr)
1110                 goto nla_put_failure;
1111         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1112                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1113                             sinfo->inactive_time);
1114         if (sinfo->filled & STATION_INFO_RX_BYTES)
1115                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1116                             sinfo->rx_bytes);
1117         if (sinfo->filled & STATION_INFO_TX_BYTES)
1118                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1119                             sinfo->tx_bytes);
1120         if (sinfo->filled & STATION_INFO_LLID)
1121                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1122                             sinfo->llid);
1123         if (sinfo->filled & STATION_INFO_PLID)
1124                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1125                             sinfo->plid);
1126         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1127                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1128                             sinfo->plink_state);
1129
1130         nla_nest_end(msg, sinfoattr);
1131
1132         return genlmsg_end(msg, hdr);
1133
1134  nla_put_failure:
1135         genlmsg_cancel(msg, hdr);
1136         return -EMSGSIZE;
1137 }
1138
1139 static int nl80211_dump_station(struct sk_buff *skb,
1140                                 struct netlink_callback *cb)
1141 {
1142         struct station_info sinfo;
1143         struct cfg80211_registered_device *dev;
1144         struct net_device *netdev;
1145         u8 mac_addr[ETH_ALEN];
1146         int ifidx = cb->args[0];
1147         int sta_idx = cb->args[1];
1148         int err;
1149
1150         if (!ifidx) {
1151                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1152                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1153                                   nl80211_policy);
1154                 if (err)
1155                         return err;
1156
1157                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1158                         return -EINVAL;
1159
1160                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1161                 if (!ifidx)
1162                         return -EINVAL;
1163         }
1164
1165         netdev = dev_get_by_index(&init_net, ifidx);
1166         if (!netdev)
1167                 return -ENODEV;
1168
1169         dev = cfg80211_get_dev_from_ifindex(ifidx);
1170         if (IS_ERR(dev)) {
1171                 err = PTR_ERR(dev);
1172                 goto out_put_netdev;
1173         }
1174
1175         if (!dev->ops->dump_station) {
1176                 err = -ENOSYS;
1177                 goto out_err;
1178         }
1179
1180         rtnl_lock();
1181
1182         while (1) {
1183                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1184                                              mac_addr, &sinfo);
1185                 if (err == -ENOENT)
1186                         break;
1187                 if (err)
1188                         goto out_err_rtnl;
1189
1190                 if (nl80211_send_station(skb,
1191                                 NETLINK_CB(cb->skb).pid,
1192                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1193                                 netdev, mac_addr,
1194                                 &sinfo) < 0)
1195                         goto out;
1196
1197                 sta_idx++;
1198         }
1199
1200
1201  out:
1202         cb->args[1] = sta_idx;
1203         err = skb->len;
1204  out_err_rtnl:
1205         rtnl_unlock();
1206  out_err:
1207         cfg80211_put_dev(dev);
1208  out_put_netdev:
1209         dev_put(netdev);
1210
1211         return err;
1212 }
1213
1214 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1215 {
1216         struct cfg80211_registered_device *drv;
1217         int err;
1218         struct net_device *dev;
1219         struct station_info sinfo;
1220         struct sk_buff *msg;
1221         u8 *mac_addr = NULL;
1222
1223         memset(&sinfo, 0, sizeof(sinfo));
1224
1225         if (!info->attrs[NL80211_ATTR_MAC])
1226                 return -EINVAL;
1227
1228         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1229
1230         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1231         if (err)
1232                 return err;
1233
1234         if (!drv->ops->get_station) {
1235                 err = -EOPNOTSUPP;
1236                 goto out;
1237         }
1238
1239         rtnl_lock();
1240         err = drv->ops->get_station(&drv->wiphy, dev, mac_addr, &sinfo);
1241         rtnl_unlock();
1242
1243         if (err)
1244                 goto out;
1245
1246         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1247         if (!msg)
1248                 goto out;
1249
1250         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1251                                  dev, mac_addr, &sinfo) < 0)
1252                 goto out_free;
1253
1254         err = genlmsg_unicast(msg, info->snd_pid);
1255         goto out;
1256
1257  out_free:
1258         nlmsg_free(msg);
1259
1260  out:
1261         cfg80211_put_dev(drv);
1262         dev_put(dev);
1263         return err;
1264 }
1265
1266 /*
1267  * Get vlan interface making sure it is on the right wiphy.
1268  */
1269 static int get_vlan(struct nlattr *vlanattr,
1270                     struct cfg80211_registered_device *rdev,
1271                     struct net_device **vlan)
1272 {
1273         *vlan = NULL;
1274
1275         if (vlanattr) {
1276                 *vlan = dev_get_by_index(&init_net, nla_get_u32(vlanattr));
1277                 if (!*vlan)
1278                         return -ENODEV;
1279                 if (!(*vlan)->ieee80211_ptr)
1280                         return -EINVAL;
1281                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1282                         return -EINVAL;
1283         }
1284         return 0;
1285 }
1286
1287 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1288 {
1289         struct cfg80211_registered_device *drv;
1290         int err;
1291         struct net_device *dev;
1292         struct station_parameters params;
1293         u8 *mac_addr = NULL;
1294
1295         memset(&params, 0, sizeof(params));
1296
1297         params.listen_interval = -1;
1298
1299         if (info->attrs[NL80211_ATTR_STA_AID])
1300                 return -EINVAL;
1301
1302         if (!info->attrs[NL80211_ATTR_MAC])
1303                 return -EINVAL;
1304
1305         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1306
1307         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1308                 params.supported_rates =
1309                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1310                 params.supported_rates_len =
1311                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1312         }
1313
1314         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1315                 params.listen_interval =
1316                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1317
1318         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1319                 params.ht_capa =
1320                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1321
1322         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1323                                 &params.station_flags))
1324                 return -EINVAL;
1325
1326         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1327                 params.plink_action =
1328                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1329
1330         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1331         if (err)
1332                 return err;
1333
1334         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1335         if (err)
1336                 goto out;
1337
1338         if (!drv->ops->change_station) {
1339                 err = -EOPNOTSUPP;
1340                 goto out;
1341         }
1342
1343         rtnl_lock();
1344         err = drv->ops->change_station(&drv->wiphy, dev, mac_addr, &params);
1345         rtnl_unlock();
1346
1347  out:
1348         if (params.vlan)
1349                 dev_put(params.vlan);
1350         cfg80211_put_dev(drv);
1351         dev_put(dev);
1352         return err;
1353 }
1354
1355 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1356 {
1357         struct cfg80211_registered_device *drv;
1358         int err;
1359         struct net_device *dev;
1360         struct station_parameters params;
1361         u8 *mac_addr = NULL;
1362
1363         memset(&params, 0, sizeof(params));
1364
1365         if (!info->attrs[NL80211_ATTR_MAC])
1366                 return -EINVAL;
1367
1368         if (!info->attrs[NL80211_ATTR_STA_AID])
1369                 return -EINVAL;
1370
1371         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1372                 return -EINVAL;
1373
1374         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
1375                 return -EINVAL;
1376
1377         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1378         params.supported_rates =
1379                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1380         params.supported_rates_len =
1381                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1382         params.listen_interval =
1383                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1384         params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
1385         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1386                 params.ht_capa =
1387                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1388
1389         if (parse_station_flags(info->attrs[NL80211_ATTR_STA_FLAGS],
1390                                 &params.station_flags))
1391                 return -EINVAL;
1392
1393         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1394         if (err)
1395                 return err;
1396
1397         err = get_vlan(info->attrs[NL80211_ATTR_STA_VLAN], drv, &params.vlan);
1398         if (err)
1399                 goto out;
1400
1401         if (!drv->ops->add_station) {
1402                 err = -EOPNOTSUPP;
1403                 goto out;
1404         }
1405
1406         rtnl_lock();
1407         err = drv->ops->add_station(&drv->wiphy, dev, mac_addr, &params);
1408         rtnl_unlock();
1409
1410  out:
1411         if (params.vlan)
1412                 dev_put(params.vlan);
1413         cfg80211_put_dev(drv);
1414         dev_put(dev);
1415         return err;
1416 }
1417
1418 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
1419 {
1420         struct cfg80211_registered_device *drv;
1421         int err;
1422         struct net_device *dev;
1423         u8 *mac_addr = NULL;
1424
1425         if (info->attrs[NL80211_ATTR_MAC])
1426                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1427
1428         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1429         if (err)
1430                 return err;
1431
1432         if (!drv->ops->del_station) {
1433                 err = -EOPNOTSUPP;
1434                 goto out;
1435         }
1436
1437         rtnl_lock();
1438         err = drv->ops->del_station(&drv->wiphy, dev, mac_addr);
1439         rtnl_unlock();
1440
1441  out:
1442         cfg80211_put_dev(drv);
1443         dev_put(dev);
1444         return err;
1445 }
1446
1447 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
1448                                 int flags, struct net_device *dev,
1449                                 u8 *dst, u8 *next_hop,
1450                                 struct mpath_info *pinfo)
1451 {
1452         void *hdr;
1453         struct nlattr *pinfoattr;
1454
1455         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1456         if (!hdr)
1457                 return -1;
1458
1459         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1460         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
1461         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
1462
1463         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
1464         if (!pinfoattr)
1465                 goto nla_put_failure;
1466         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
1467                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
1468                             pinfo->frame_qlen);
1469         if (pinfo->filled & MPATH_INFO_DSN)
1470                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DSN,
1471                             pinfo->dsn);
1472         if (pinfo->filled & MPATH_INFO_METRIC)
1473                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
1474                             pinfo->metric);
1475         if (pinfo->filled & MPATH_INFO_EXPTIME)
1476                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
1477                             pinfo->exptime);
1478         if (pinfo->filled & MPATH_INFO_FLAGS)
1479                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
1480                             pinfo->flags);
1481         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
1482                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
1483                             pinfo->discovery_timeout);
1484         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
1485                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
1486                             pinfo->discovery_retries);
1487
1488         nla_nest_end(msg, pinfoattr);
1489
1490         return genlmsg_end(msg, hdr);
1491
1492  nla_put_failure:
1493         genlmsg_cancel(msg, hdr);
1494         return -EMSGSIZE;
1495 }
1496
1497 static int nl80211_dump_mpath(struct sk_buff *skb,
1498                               struct netlink_callback *cb)
1499 {
1500         struct mpath_info pinfo;
1501         struct cfg80211_registered_device *dev;
1502         struct net_device *netdev;
1503         u8 dst[ETH_ALEN];
1504         u8 next_hop[ETH_ALEN];
1505         int ifidx = cb->args[0];
1506         int path_idx = cb->args[1];
1507         int err;
1508
1509         if (!ifidx) {
1510                 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
1511                                   nl80211_fam.attrbuf, nl80211_fam.maxattr,
1512                                   nl80211_policy);
1513                 if (err)
1514                         return err;
1515
1516                 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
1517                         return -EINVAL;
1518
1519                 ifidx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
1520                 if (!ifidx)
1521                         return -EINVAL;
1522         }
1523
1524         netdev = dev_get_by_index(&init_net, ifidx);
1525         if (!netdev)
1526                 return -ENODEV;
1527
1528         dev = cfg80211_get_dev_from_ifindex(ifidx);
1529         if (IS_ERR(dev)) {
1530                 err = PTR_ERR(dev);
1531                 goto out_put_netdev;
1532         }
1533
1534         if (!dev->ops->dump_mpath) {
1535                 err = -ENOSYS;
1536                 goto out_err;
1537         }
1538
1539         rtnl_lock();
1540
1541         while (1) {
1542                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
1543                                            dst, next_hop, &pinfo);
1544                 if (err == -ENOENT)
1545                         break;
1546                 if (err)
1547                         goto out_err_rtnl;
1548
1549                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
1550                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
1551                                        netdev, dst, next_hop,
1552                                        &pinfo) < 0)
1553                         goto out;
1554
1555                 path_idx++;
1556         }
1557
1558
1559  out:
1560         cb->args[1] = path_idx;
1561         err = skb->len;
1562  out_err_rtnl:
1563         rtnl_unlock();
1564  out_err:
1565         cfg80211_put_dev(dev);
1566  out_put_netdev:
1567         dev_put(netdev);
1568
1569         return err;
1570 }
1571
1572 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
1573 {
1574         struct cfg80211_registered_device *drv;
1575         int err;
1576         struct net_device *dev;
1577         struct mpath_info pinfo;
1578         struct sk_buff *msg;
1579         u8 *dst = NULL;
1580         u8 next_hop[ETH_ALEN];
1581
1582         memset(&pinfo, 0, sizeof(pinfo));
1583
1584         if (!info->attrs[NL80211_ATTR_MAC])
1585                 return -EINVAL;
1586
1587         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1588
1589         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1590         if (err)
1591                 return err;
1592
1593         if (!drv->ops->get_mpath) {
1594                 err = -EOPNOTSUPP;
1595                 goto out;
1596         }
1597
1598         rtnl_lock();
1599         err = drv->ops->get_mpath(&drv->wiphy, dev, dst, next_hop, &pinfo);
1600         rtnl_unlock();
1601
1602         if (err)
1603                 goto out;
1604
1605         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1606         if (!msg)
1607                 goto out;
1608
1609         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
1610                                  dev, dst, next_hop, &pinfo) < 0)
1611                 goto out_free;
1612
1613         err = genlmsg_unicast(msg, info->snd_pid);
1614         goto out;
1615
1616  out_free:
1617         nlmsg_free(msg);
1618
1619  out:
1620         cfg80211_put_dev(drv);
1621         dev_put(dev);
1622         return err;
1623 }
1624
1625 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
1626 {
1627         struct cfg80211_registered_device *drv;
1628         int err;
1629         struct net_device *dev;
1630         u8 *dst = NULL;
1631         u8 *next_hop = NULL;
1632
1633         if (!info->attrs[NL80211_ATTR_MAC])
1634                 return -EINVAL;
1635
1636         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
1637                 return -EINVAL;
1638
1639         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1640         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
1641
1642         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1643         if (err)
1644                 return err;
1645
1646         if (!drv->ops->change_mpath) {
1647                 err = -EOPNOTSUPP;
1648                 goto out;
1649         }
1650
1651         rtnl_lock();
1652         err = drv->ops->change_mpath(&drv->wiphy, dev, dst, next_hop);
1653         rtnl_unlock();
1654
1655  out:
1656         cfg80211_put_dev(drv);
1657         dev_put(dev);
1658         return err;
1659 }
1660 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
1661 {
1662         struct cfg80211_registered_device *drv;
1663         int err;
1664         struct net_device *dev;
1665         u8 *dst = NULL;
1666         u8 *next_hop = NULL;
1667
1668         if (!info->attrs[NL80211_ATTR_MAC])
1669                 return -EINVAL;
1670
1671         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
1672                 return -EINVAL;
1673
1674         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1675         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
1676
1677         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1678         if (err)
1679                 return err;
1680
1681         if (!drv->ops->add_mpath) {
1682                 err = -EOPNOTSUPP;
1683                 goto out;
1684         }
1685
1686         rtnl_lock();
1687         err = drv->ops->add_mpath(&drv->wiphy, dev, dst, next_hop);
1688         rtnl_unlock();
1689
1690  out:
1691         cfg80211_put_dev(drv);
1692         dev_put(dev);
1693         return err;
1694 }
1695
1696 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
1697 {
1698         struct cfg80211_registered_device *drv;
1699         int err;
1700         struct net_device *dev;
1701         u8 *dst = NULL;
1702
1703         if (info->attrs[NL80211_ATTR_MAC])
1704                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
1705
1706         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1707         if (err)
1708                 return err;
1709
1710         if (!drv->ops->del_mpath) {
1711                 err = -EOPNOTSUPP;
1712                 goto out;
1713         }
1714
1715         rtnl_lock();
1716         err = drv->ops->del_mpath(&drv->wiphy, dev, dst);
1717         rtnl_unlock();
1718
1719  out:
1720         cfg80211_put_dev(drv);
1721         dev_put(dev);
1722         return err;
1723 }
1724
1725 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
1726 {
1727         struct cfg80211_registered_device *drv;
1728         int err;
1729         struct net_device *dev;
1730         struct bss_parameters params;
1731
1732         memset(&params, 0, sizeof(params));
1733         /* default to not changing parameters */
1734         params.use_cts_prot = -1;
1735         params.use_short_preamble = -1;
1736         params.use_short_slot_time = -1;
1737
1738         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
1739                 params.use_cts_prot =
1740                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
1741         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
1742                 params.use_short_preamble =
1743                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
1744         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
1745                 params.use_short_slot_time =
1746                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
1747         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
1748                 params.basic_rates =
1749                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
1750                 params.basic_rates_len =
1751                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
1752         }
1753
1754         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1755         if (err)
1756                 return err;
1757
1758         if (!drv->ops->change_bss) {
1759                 err = -EOPNOTSUPP;
1760                 goto out;
1761         }
1762
1763         rtnl_lock();
1764         err = drv->ops->change_bss(&drv->wiphy, dev, &params);
1765         rtnl_unlock();
1766
1767  out:
1768         cfg80211_put_dev(drv);
1769         dev_put(dev);
1770         return err;
1771 }
1772
1773 static const struct nla_policy
1774         reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
1775         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
1776         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
1777         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
1778         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
1779         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
1780         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
1781 };
1782
1783 static int parse_reg_rule(struct nlattr *tb[],
1784         struct ieee80211_reg_rule *reg_rule)
1785 {
1786         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
1787         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
1788
1789         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
1790                 return -EINVAL;
1791         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
1792                 return -EINVAL;
1793         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
1794                 return -EINVAL;
1795         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
1796                 return -EINVAL;
1797         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
1798                 return -EINVAL;
1799
1800         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
1801
1802         freq_range->start_freq_khz =
1803                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
1804         freq_range->end_freq_khz =
1805                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
1806         freq_range->max_bandwidth_khz =
1807                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
1808
1809         power_rule->max_eirp =
1810                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
1811
1812         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
1813                 power_rule->max_antenna_gain =
1814                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
1815
1816         return 0;
1817 }
1818
1819 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
1820 {
1821         int r;
1822         char *data = NULL;
1823
1824         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
1825                 return -EINVAL;
1826
1827         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
1828
1829 #ifdef CONFIG_WIRELESS_OLD_REGULATORY
1830         /* We ignore world regdom requests with the old regdom setup */
1831         if (is_world_regdom(data))
1832                 return -EINVAL;
1833 #endif
1834         mutex_lock(&cfg80211_drv_mutex);
1835         r = __regulatory_hint(NULL, REGDOM_SET_BY_USER, data, 0, ENVIRON_ANY);
1836         mutex_unlock(&cfg80211_drv_mutex);
1837         return r;
1838 }
1839
1840 static int nl80211_get_mesh_params(struct sk_buff *skb,
1841         struct genl_info *info)
1842 {
1843         struct cfg80211_registered_device *drv;
1844         struct mesh_config cur_params;
1845         int err;
1846         struct net_device *dev;
1847         void *hdr;
1848         struct nlattr *pinfoattr;
1849         struct sk_buff *msg;
1850
1851         /* Look up our device */
1852         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1853         if (err)
1854                 return err;
1855
1856         /* Get the mesh params */
1857         rtnl_lock();
1858         err = drv->ops->get_mesh_params(&drv->wiphy, dev, &cur_params);
1859         rtnl_unlock();
1860         if (err)
1861                 goto out;
1862
1863         /* Draw up a netlink message to send back */
1864         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
1865         if (!msg) {
1866                 err = -ENOBUFS;
1867                 goto out;
1868         }
1869         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1870                              NL80211_CMD_GET_MESH_PARAMS);
1871         if (!hdr)
1872                 goto nla_put_failure;
1873         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
1874         if (!pinfoattr)
1875                 goto nla_put_failure;
1876         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1877         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
1878                         cur_params.dot11MeshRetryTimeout);
1879         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
1880                         cur_params.dot11MeshConfirmTimeout);
1881         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
1882                         cur_params.dot11MeshHoldingTimeout);
1883         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
1884                         cur_params.dot11MeshMaxPeerLinks);
1885         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
1886                         cur_params.dot11MeshMaxRetries);
1887         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
1888                         cur_params.dot11MeshTTL);
1889         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
1890                         cur_params.auto_open_plinks);
1891         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
1892                         cur_params.dot11MeshHWMPmaxPREQretries);
1893         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
1894                         cur_params.path_refresh_time);
1895         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
1896                         cur_params.min_discovery_timeout);
1897         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
1898                         cur_params.dot11MeshHWMPactivePathTimeout);
1899         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
1900                         cur_params.dot11MeshHWMPpreqMinInterval);
1901         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
1902                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
1903         nla_nest_end(msg, pinfoattr);
1904         genlmsg_end(msg, hdr);
1905         err = genlmsg_unicast(msg, info->snd_pid);
1906         goto out;
1907
1908 nla_put_failure:
1909         genlmsg_cancel(msg, hdr);
1910         err = -EMSGSIZE;
1911 out:
1912         /* Cleanup */
1913         cfg80211_put_dev(drv);
1914         dev_put(dev);
1915         return err;
1916 }
1917
1918 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
1919 do {\
1920         if (table[attr_num]) {\
1921                 cfg.param = nla_fn(table[attr_num]); \
1922                 mask |= (1 << (attr_num - 1)); \
1923         } \
1924 } while (0);\
1925
1926 static struct nla_policy
1927 nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
1928         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
1929         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
1930         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
1931         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
1932         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
1933         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
1934         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
1935
1936         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
1937         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
1938         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
1939         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
1940         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
1941         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
1942 };
1943
1944 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
1945 {
1946         int err;
1947         u32 mask;
1948         struct cfg80211_registered_device *drv;
1949         struct net_device *dev;
1950         struct mesh_config cfg;
1951         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
1952         struct nlattr *parent_attr;
1953
1954         parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
1955         if (!parent_attr)
1956                 return -EINVAL;
1957         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
1958                         parent_attr, nl80211_meshconf_params_policy))
1959                 return -EINVAL;
1960
1961         err = get_drv_dev_by_info_ifindex(info->attrs, &drv, &dev);
1962         if (err)
1963                 return err;
1964
1965         /* This makes sure that there aren't more than 32 mesh config
1966          * parameters (otherwise our bitfield scheme would not work.) */
1967         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
1968
1969         /* Fill in the params struct */
1970         mask = 0;
1971         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
1972                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
1973         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
1974                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
1975         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
1976                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
1977         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
1978                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
1979         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
1980                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
1981         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
1982                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
1983         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
1984                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
1985         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
1986                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
1987                         nla_get_u8);
1988         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
1989                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
1990         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
1991                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
1992                         nla_get_u16);
1993         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
1994                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
1995                         nla_get_u32);
1996         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
1997                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
1998                         nla_get_u16);
1999         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2000                         dot11MeshHWMPnetDiameterTraversalTime,
2001                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2002                         nla_get_u16);
2003
2004         /* Apply changes */
2005         rtnl_lock();
2006         err = drv->ops->set_mesh_params(&drv->wiphy, dev, &cfg, mask);
2007         rtnl_unlock();
2008
2009         /* cleanup */
2010         cfg80211_put_dev(drv);
2011         dev_put(dev);
2012         return err;
2013 }
2014
2015 #undef FILL_IN_MESH_PARAM_IF_SET
2016
2017 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2018 {
2019         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2020         struct nlattr *nl_reg_rule;
2021         char *alpha2 = NULL;
2022         int rem_reg_rules = 0, r = 0;
2023         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2024         struct ieee80211_regdomain *rd = NULL;
2025
2026         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2027                 return -EINVAL;
2028
2029         if (!info->attrs[NL80211_ATTR_REG_RULES])
2030                 return -EINVAL;
2031
2032         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2033
2034         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2035                         rem_reg_rules) {
2036                 num_rules++;
2037                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2038                         goto bad_reg;
2039         }
2040
2041         if (!reg_is_valid_request(alpha2))
2042                 return -EINVAL;
2043
2044         size_of_regd = sizeof(struct ieee80211_regdomain) +
2045                 (num_rules * sizeof(struct ieee80211_reg_rule));
2046
2047         rd = kzalloc(size_of_regd, GFP_KERNEL);
2048         if (!rd)
2049                 return -ENOMEM;
2050
2051         rd->n_reg_rules = num_rules;
2052         rd->alpha2[0] = alpha2[0];
2053         rd->alpha2[1] = alpha2[1];
2054
2055         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2056                         rem_reg_rules) {
2057                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2058                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2059                         reg_rule_policy);
2060                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2061                 if (r)
2062                         goto bad_reg;
2063
2064                 rule_idx++;
2065
2066                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES)
2067                         goto bad_reg;
2068         }
2069
2070         BUG_ON(rule_idx != num_rules);
2071
2072         mutex_lock(&cfg80211_drv_mutex);
2073         r = set_regdom(rd);
2074         mutex_unlock(&cfg80211_drv_mutex);
2075         return r;
2076
2077  bad_reg:
2078         kfree(rd);
2079         return -EINVAL;
2080 }
2081
2082 static struct genl_ops nl80211_ops[] = {
2083         {
2084                 .cmd = NL80211_CMD_GET_WIPHY,
2085                 .doit = nl80211_get_wiphy,
2086                 .dumpit = nl80211_dump_wiphy,
2087                 .policy = nl80211_policy,
2088                 /* can be retrieved by unprivileged users */
2089         },
2090         {
2091                 .cmd = NL80211_CMD_SET_WIPHY,
2092                 .doit = nl80211_set_wiphy,
2093                 .policy = nl80211_policy,
2094                 .flags = GENL_ADMIN_PERM,
2095         },
2096         {
2097                 .cmd = NL80211_CMD_GET_INTERFACE,
2098                 .doit = nl80211_get_interface,
2099                 .dumpit = nl80211_dump_interface,
2100                 .policy = nl80211_policy,
2101                 /* can be retrieved by unprivileged users */
2102         },
2103         {
2104                 .cmd = NL80211_CMD_SET_INTERFACE,
2105                 .doit = nl80211_set_interface,
2106                 .policy = nl80211_policy,
2107                 .flags = GENL_ADMIN_PERM,
2108         },
2109         {
2110                 .cmd = NL80211_CMD_NEW_INTERFACE,
2111                 .doit = nl80211_new_interface,
2112                 .policy = nl80211_policy,
2113                 .flags = GENL_ADMIN_PERM,
2114         },
2115         {
2116                 .cmd = NL80211_CMD_DEL_INTERFACE,
2117                 .doit = nl80211_del_interface,
2118                 .policy = nl80211_policy,
2119                 .flags = GENL_ADMIN_PERM,
2120         },
2121         {
2122                 .cmd = NL80211_CMD_GET_KEY,
2123                 .doit = nl80211_get_key,
2124                 .policy = nl80211_policy,
2125                 .flags = GENL_ADMIN_PERM,
2126         },
2127         {
2128                 .cmd = NL80211_CMD_SET_KEY,
2129                 .doit = nl80211_set_key,
2130                 .policy = nl80211_policy,
2131                 .flags = GENL_ADMIN_PERM,
2132         },
2133         {
2134                 .cmd = NL80211_CMD_NEW_KEY,
2135                 .doit = nl80211_new_key,
2136                 .policy = nl80211_policy,
2137                 .flags = GENL_ADMIN_PERM,
2138         },
2139         {
2140                 .cmd = NL80211_CMD_DEL_KEY,
2141                 .doit = nl80211_del_key,
2142                 .policy = nl80211_policy,
2143                 .flags = GENL_ADMIN_PERM,
2144         },
2145         {
2146                 .cmd = NL80211_CMD_SET_BEACON,
2147                 .policy = nl80211_policy,
2148                 .flags = GENL_ADMIN_PERM,
2149                 .doit = nl80211_addset_beacon,
2150         },
2151         {
2152                 .cmd = NL80211_CMD_NEW_BEACON,
2153                 .policy = nl80211_policy,
2154                 .flags = GENL_ADMIN_PERM,
2155                 .doit = nl80211_addset_beacon,
2156         },
2157         {
2158                 .cmd = NL80211_CMD_DEL_BEACON,
2159                 .policy = nl80211_policy,
2160                 .flags = GENL_ADMIN_PERM,
2161                 .doit = nl80211_del_beacon,
2162         },
2163         {
2164                 .cmd = NL80211_CMD_GET_STATION,
2165                 .doit = nl80211_get_station,
2166                 .dumpit = nl80211_dump_station,
2167                 .policy = nl80211_policy,
2168                 .flags = GENL_ADMIN_PERM,
2169         },
2170         {
2171                 .cmd = NL80211_CMD_SET_STATION,
2172                 .doit = nl80211_set_station,
2173                 .policy = nl80211_policy,
2174                 .flags = GENL_ADMIN_PERM,
2175         },
2176         {
2177                 .cmd = NL80211_CMD_NEW_STATION,
2178                 .doit = nl80211_new_station,
2179                 .policy = nl80211_policy,
2180                 .flags = GENL_ADMIN_PERM,
2181         },
2182         {
2183                 .cmd = NL80211_CMD_DEL_STATION,
2184                 .doit = nl80211_del_station,
2185                 .policy = nl80211_policy,
2186                 .flags = GENL_ADMIN_PERM,
2187         },
2188         {
2189                 .cmd = NL80211_CMD_GET_MPATH,
2190                 .doit = nl80211_get_mpath,
2191                 .dumpit = nl80211_dump_mpath,
2192                 .policy = nl80211_policy,
2193                 .flags = GENL_ADMIN_PERM,
2194         },
2195         {
2196                 .cmd = NL80211_CMD_SET_MPATH,
2197                 .doit = nl80211_set_mpath,
2198                 .policy = nl80211_policy,
2199                 .flags = GENL_ADMIN_PERM,
2200         },
2201         {
2202                 .cmd = NL80211_CMD_NEW_MPATH,
2203                 .doit = nl80211_new_mpath,
2204                 .policy = nl80211_policy,
2205                 .flags = GENL_ADMIN_PERM,
2206         },
2207         {
2208                 .cmd = NL80211_CMD_DEL_MPATH,
2209                 .doit = nl80211_del_mpath,
2210                 .policy = nl80211_policy,
2211                 .flags = GENL_ADMIN_PERM,
2212         },
2213         {
2214                 .cmd = NL80211_CMD_SET_BSS,
2215                 .doit = nl80211_set_bss,
2216                 .policy = nl80211_policy,
2217                 .flags = GENL_ADMIN_PERM,
2218         },
2219         {
2220                 .cmd = NL80211_CMD_SET_REG,
2221                 .doit = nl80211_set_reg,
2222                 .policy = nl80211_policy,
2223                 .flags = GENL_ADMIN_PERM,
2224         },
2225         {
2226                 .cmd = NL80211_CMD_REQ_SET_REG,
2227                 .doit = nl80211_req_set_reg,
2228                 .policy = nl80211_policy,
2229                 .flags = GENL_ADMIN_PERM,
2230         },
2231         {
2232                 .cmd = NL80211_CMD_GET_MESH_PARAMS,
2233                 .doit = nl80211_get_mesh_params,
2234                 .policy = nl80211_policy,
2235                 /* can be retrieved by unprivileged users */
2236         },
2237         {
2238                 .cmd = NL80211_CMD_SET_MESH_PARAMS,
2239                 .doit = nl80211_set_mesh_params,
2240                 .policy = nl80211_policy,
2241                 .flags = GENL_ADMIN_PERM,
2242         },
2243 };
2244
2245 /* multicast groups */
2246 static struct genl_multicast_group nl80211_config_mcgrp = {
2247         .name = "config",
2248 };
2249
2250 /* notification functions */
2251
2252 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
2253 {
2254         struct sk_buff *msg;
2255
2256         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
2257         if (!msg)
2258                 return;
2259
2260         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
2261                 nlmsg_free(msg);
2262                 return;
2263         }
2264
2265         genlmsg_multicast(msg, 0, nl80211_config_mcgrp.id, GFP_KERNEL);
2266 }
2267
2268 /* initialisation/exit functions */
2269
2270 int nl80211_init(void)
2271 {
2272         int err, i;
2273
2274         err = genl_register_family(&nl80211_fam);
2275         if (err)
2276                 return err;
2277
2278         for (i = 0; i < ARRAY_SIZE(nl80211_ops); i++) {
2279                 err = genl_register_ops(&nl80211_fam, &nl80211_ops[i]);
2280                 if (err)
2281                         goto err_out;
2282         }
2283
2284         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
2285         if (err)
2286                 goto err_out;
2287
2288         return 0;
2289  err_out:
2290         genl_unregister_family(&nl80211_fam);
2291         return err;
2292 }
2293
2294 void nl80211_exit(void)
2295 {
2296         genl_unregister_family(&nl80211_fam);
2297 }