bpf: Prevent memory disambiguation attack
[linux/fpc-iii.git] / net / wireless / ibss.c
bloba1d10993d08a7e306ce5fe2c39ac7bf9444de2ba
1 // SPDX-License-Identifier: GPL-2.0
2 /*
3 * Some IBSS support code for cfg80211.
5 * Copyright 2009 Johannes Berg <johannes@sipsolutions.net>
6 */
8 #include <linux/etherdevice.h>
9 #include <linux/if_arp.h>
10 #include <linux/slab.h>
11 #include <linux/export.h>
12 #include <net/cfg80211.h>
13 #include "wext-compat.h"
14 #include "nl80211.h"
15 #include "rdev-ops.h"
18 void __cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
19 struct ieee80211_channel *channel)
21 struct wireless_dev *wdev = dev->ieee80211_ptr;
22 struct cfg80211_bss *bss;
23 #ifdef CONFIG_CFG80211_WEXT
24 union iwreq_data wrqu;
25 #endif
27 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
28 return;
30 if (!wdev->ssid_len)
31 return;
33 bss = cfg80211_get_bss(wdev->wiphy, channel, bssid, NULL, 0,
34 IEEE80211_BSS_TYPE_IBSS, IEEE80211_PRIVACY_ANY);
36 if (WARN_ON(!bss))
37 return;
39 if (wdev->current_bss) {
40 cfg80211_unhold_bss(wdev->current_bss);
41 cfg80211_put_bss(wdev->wiphy, &wdev->current_bss->pub);
44 cfg80211_hold_bss(bss_from_pub(bss));
45 wdev->current_bss = bss_from_pub(bss);
47 if (!(wdev->wiphy->flags & WIPHY_FLAG_HAS_STATIC_WEP))
48 cfg80211_upload_connect_keys(wdev);
50 nl80211_send_ibss_bssid(wiphy_to_rdev(wdev->wiphy), dev, bssid,
51 GFP_KERNEL);
52 #ifdef CONFIG_CFG80211_WEXT
53 memset(&wrqu, 0, sizeof(wrqu));
54 memcpy(wrqu.ap_addr.sa_data, bssid, ETH_ALEN);
55 wireless_send_event(dev, SIOCGIWAP, &wrqu, NULL);
56 #endif
59 void cfg80211_ibss_joined(struct net_device *dev, const u8 *bssid,
60 struct ieee80211_channel *channel, gfp_t gfp)
62 struct wireless_dev *wdev = dev->ieee80211_ptr;
63 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
64 struct cfg80211_event *ev;
65 unsigned long flags;
67 trace_cfg80211_ibss_joined(dev, bssid, channel);
69 if (WARN_ON(!channel))
70 return;
72 ev = kzalloc(sizeof(*ev), gfp);
73 if (!ev)
74 return;
76 ev->type = EVENT_IBSS_JOINED;
77 memcpy(ev->ij.bssid, bssid, ETH_ALEN);
78 ev->ij.channel = channel;
80 spin_lock_irqsave(&wdev->event_lock, flags);
81 list_add_tail(&ev->list, &wdev->event_list);
82 spin_unlock_irqrestore(&wdev->event_lock, flags);
83 queue_work(cfg80211_wq, &rdev->event_work);
85 EXPORT_SYMBOL(cfg80211_ibss_joined);
87 static int __cfg80211_join_ibss(struct cfg80211_registered_device *rdev,
88 struct net_device *dev,
89 struct cfg80211_ibss_params *params,
90 struct cfg80211_cached_keys *connkeys)
92 struct wireless_dev *wdev = dev->ieee80211_ptr;
93 int err;
95 ASSERT_WDEV_LOCK(wdev);
97 if (wdev->ssid_len)
98 return -EALREADY;
100 if (!params->basic_rates) {
102 * If no rates were explicitly configured,
103 * use the mandatory rate set for 11b or
104 * 11a for maximum compatibility.
106 struct ieee80211_supported_band *sband =
107 rdev->wiphy.bands[params->chandef.chan->band];
108 int j;
109 u32 flag = params->chandef.chan->band == NL80211_BAND_5GHZ ?
110 IEEE80211_RATE_MANDATORY_A :
111 IEEE80211_RATE_MANDATORY_B;
113 for (j = 0; j < sband->n_bitrates; j++) {
114 if (sband->bitrates[j].flags & flag)
115 params->basic_rates |= BIT(j);
119 if (WARN_ON(connkeys && connkeys->def < 0))
120 return -EINVAL;
122 if (WARN_ON(wdev->connect_keys))
123 kzfree(wdev->connect_keys);
124 wdev->connect_keys = connkeys;
126 wdev->ibss_fixed = params->channel_fixed;
127 wdev->ibss_dfs_possible = params->userspace_handles_dfs;
128 wdev->chandef = params->chandef;
129 if (connkeys) {
130 params->wep_keys = connkeys->params;
131 params->wep_tx_key = connkeys->def;
134 #ifdef CONFIG_CFG80211_WEXT
135 wdev->wext.ibss.chandef = params->chandef;
136 #endif
137 err = rdev_join_ibss(rdev, dev, params);
138 if (err) {
139 wdev->connect_keys = NULL;
140 return err;
143 memcpy(wdev->ssid, params->ssid, params->ssid_len);
144 wdev->ssid_len = params->ssid_len;
146 return 0;
149 int cfg80211_join_ibss(struct cfg80211_registered_device *rdev,
150 struct net_device *dev,
151 struct cfg80211_ibss_params *params,
152 struct cfg80211_cached_keys *connkeys)
154 struct wireless_dev *wdev = dev->ieee80211_ptr;
155 int err;
157 ASSERT_RTNL();
159 wdev_lock(wdev);
160 err = __cfg80211_join_ibss(rdev, dev, params, connkeys);
161 wdev_unlock(wdev);
163 return err;
166 static void __cfg80211_clear_ibss(struct net_device *dev, bool nowext)
168 struct wireless_dev *wdev = dev->ieee80211_ptr;
169 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
170 int i;
172 ASSERT_WDEV_LOCK(wdev);
174 kzfree(wdev->connect_keys);
175 wdev->connect_keys = NULL;
177 rdev_set_qos_map(rdev, dev, NULL);
180 * Delete all the keys ... pairwise keys can't really
181 * exist any more anyway, but default keys might.
183 if (rdev->ops->del_key)
184 for (i = 0; i < 6; i++)
185 rdev_del_key(rdev, dev, i, false, NULL);
187 if (wdev->current_bss) {
188 cfg80211_unhold_bss(wdev->current_bss);
189 cfg80211_put_bss(wdev->wiphy, &wdev->current_bss->pub);
192 wdev->current_bss = NULL;
193 wdev->ssid_len = 0;
194 memset(&wdev->chandef, 0, sizeof(wdev->chandef));
195 #ifdef CONFIG_CFG80211_WEXT
196 if (!nowext)
197 wdev->wext.ibss.ssid_len = 0;
198 #endif
199 cfg80211_sched_dfs_chan_update(rdev);
202 void cfg80211_clear_ibss(struct net_device *dev, bool nowext)
204 struct wireless_dev *wdev = dev->ieee80211_ptr;
206 wdev_lock(wdev);
207 __cfg80211_clear_ibss(dev, nowext);
208 wdev_unlock(wdev);
211 int __cfg80211_leave_ibss(struct cfg80211_registered_device *rdev,
212 struct net_device *dev, bool nowext)
214 struct wireless_dev *wdev = dev->ieee80211_ptr;
215 int err;
217 ASSERT_WDEV_LOCK(wdev);
219 if (!wdev->ssid_len)
220 return -ENOLINK;
222 err = rdev_leave_ibss(rdev, dev);
224 if (err)
225 return err;
227 __cfg80211_clear_ibss(dev, nowext);
229 return 0;
232 int cfg80211_leave_ibss(struct cfg80211_registered_device *rdev,
233 struct net_device *dev, bool nowext)
235 struct wireless_dev *wdev = dev->ieee80211_ptr;
236 int err;
238 wdev_lock(wdev);
239 err = __cfg80211_leave_ibss(rdev, dev, nowext);
240 wdev_unlock(wdev);
242 return err;
245 #ifdef CONFIG_CFG80211_WEXT
246 int cfg80211_ibss_wext_join(struct cfg80211_registered_device *rdev,
247 struct wireless_dev *wdev)
249 struct cfg80211_cached_keys *ck = NULL;
250 enum nl80211_band band;
251 int i, err;
253 ASSERT_WDEV_LOCK(wdev);
255 if (!wdev->wext.ibss.beacon_interval)
256 wdev->wext.ibss.beacon_interval = 100;
258 /* try to find an IBSS channel if none requested ... */
259 if (!wdev->wext.ibss.chandef.chan) {
260 struct ieee80211_channel *new_chan = NULL;
262 for (band = 0; band < NUM_NL80211_BANDS; band++) {
263 struct ieee80211_supported_band *sband;
264 struct ieee80211_channel *chan;
266 sband = rdev->wiphy.bands[band];
267 if (!sband)
268 continue;
270 for (i = 0; i < sband->n_channels; i++) {
271 chan = &sband->channels[i];
272 if (chan->flags & IEEE80211_CHAN_NO_IR)
273 continue;
274 if (chan->flags & IEEE80211_CHAN_DISABLED)
275 continue;
276 new_chan = chan;
277 break;
280 if (new_chan)
281 break;
284 if (!new_chan)
285 return -EINVAL;
287 cfg80211_chandef_create(&wdev->wext.ibss.chandef, new_chan,
288 NL80211_CHAN_NO_HT);
291 /* don't join -- SSID is not there */
292 if (!wdev->wext.ibss.ssid_len)
293 return 0;
295 if (!netif_running(wdev->netdev))
296 return 0;
298 if (wdev->wext.keys)
299 wdev->wext.keys->def = wdev->wext.default_key;
301 wdev->wext.ibss.privacy = wdev->wext.default_key != -1;
303 if (wdev->wext.keys && wdev->wext.keys->def != -1) {
304 ck = kmemdup(wdev->wext.keys, sizeof(*ck), GFP_KERNEL);
305 if (!ck)
306 return -ENOMEM;
307 for (i = 0; i < CFG80211_MAX_WEP_KEYS; i++)
308 ck->params[i].key = ck->data[i];
310 err = __cfg80211_join_ibss(rdev, wdev->netdev,
311 &wdev->wext.ibss, ck);
312 if (err)
313 kfree(ck);
315 return err;
318 int cfg80211_ibss_wext_siwfreq(struct net_device *dev,
319 struct iw_request_info *info,
320 struct iw_freq *wextfreq, char *extra)
322 struct wireless_dev *wdev = dev->ieee80211_ptr;
323 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
324 struct ieee80211_channel *chan = NULL;
325 int err, freq;
327 /* call only for ibss! */
328 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
329 return -EINVAL;
331 if (!rdev->ops->join_ibss)
332 return -EOPNOTSUPP;
334 freq = cfg80211_wext_freq(wextfreq);
335 if (freq < 0)
336 return freq;
338 if (freq) {
339 chan = ieee80211_get_channel(wdev->wiphy, freq);
340 if (!chan)
341 return -EINVAL;
342 if (chan->flags & IEEE80211_CHAN_NO_IR ||
343 chan->flags & IEEE80211_CHAN_DISABLED)
344 return -EINVAL;
347 if (wdev->wext.ibss.chandef.chan == chan)
348 return 0;
350 wdev_lock(wdev);
351 err = 0;
352 if (wdev->ssid_len)
353 err = __cfg80211_leave_ibss(rdev, dev, true);
354 wdev_unlock(wdev);
356 if (err)
357 return err;
359 if (chan) {
360 cfg80211_chandef_create(&wdev->wext.ibss.chandef, chan,
361 NL80211_CHAN_NO_HT);
362 wdev->wext.ibss.channel_fixed = true;
363 } else {
364 /* cfg80211_ibss_wext_join will pick one if needed */
365 wdev->wext.ibss.channel_fixed = false;
368 wdev_lock(wdev);
369 err = cfg80211_ibss_wext_join(rdev, wdev);
370 wdev_unlock(wdev);
372 return err;
375 int cfg80211_ibss_wext_giwfreq(struct net_device *dev,
376 struct iw_request_info *info,
377 struct iw_freq *freq, char *extra)
379 struct wireless_dev *wdev = dev->ieee80211_ptr;
380 struct ieee80211_channel *chan = NULL;
382 /* call only for ibss! */
383 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
384 return -EINVAL;
386 wdev_lock(wdev);
387 if (wdev->current_bss)
388 chan = wdev->current_bss->pub.channel;
389 else if (wdev->wext.ibss.chandef.chan)
390 chan = wdev->wext.ibss.chandef.chan;
391 wdev_unlock(wdev);
393 if (chan) {
394 freq->m = chan->center_freq;
395 freq->e = 6;
396 return 0;
399 /* no channel if not joining */
400 return -EINVAL;
403 int cfg80211_ibss_wext_siwessid(struct net_device *dev,
404 struct iw_request_info *info,
405 struct iw_point *data, char *ssid)
407 struct wireless_dev *wdev = dev->ieee80211_ptr;
408 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
409 size_t len = data->length;
410 int err;
412 /* call only for ibss! */
413 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
414 return -EINVAL;
416 if (!rdev->ops->join_ibss)
417 return -EOPNOTSUPP;
419 wdev_lock(wdev);
420 err = 0;
421 if (wdev->ssid_len)
422 err = __cfg80211_leave_ibss(rdev, dev, true);
423 wdev_unlock(wdev);
425 if (err)
426 return err;
428 /* iwconfig uses nul termination in SSID.. */
429 if (len > 0 && ssid[len - 1] == '\0')
430 len--;
432 memcpy(wdev->ssid, ssid, len);
433 wdev->wext.ibss.ssid = wdev->ssid;
434 wdev->wext.ibss.ssid_len = len;
436 wdev_lock(wdev);
437 err = cfg80211_ibss_wext_join(rdev, wdev);
438 wdev_unlock(wdev);
440 return err;
443 int cfg80211_ibss_wext_giwessid(struct net_device *dev,
444 struct iw_request_info *info,
445 struct iw_point *data, char *ssid)
447 struct wireless_dev *wdev = dev->ieee80211_ptr;
449 /* call only for ibss! */
450 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
451 return -EINVAL;
453 data->flags = 0;
455 wdev_lock(wdev);
456 if (wdev->ssid_len) {
457 data->flags = 1;
458 data->length = wdev->ssid_len;
459 memcpy(ssid, wdev->ssid, data->length);
460 } else if (wdev->wext.ibss.ssid && wdev->wext.ibss.ssid_len) {
461 data->flags = 1;
462 data->length = wdev->wext.ibss.ssid_len;
463 memcpy(ssid, wdev->wext.ibss.ssid, data->length);
465 wdev_unlock(wdev);
467 return 0;
470 int cfg80211_ibss_wext_siwap(struct net_device *dev,
471 struct iw_request_info *info,
472 struct sockaddr *ap_addr, char *extra)
474 struct wireless_dev *wdev = dev->ieee80211_ptr;
475 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
476 u8 *bssid = ap_addr->sa_data;
477 int err;
479 /* call only for ibss! */
480 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
481 return -EINVAL;
483 if (!rdev->ops->join_ibss)
484 return -EOPNOTSUPP;
486 if (ap_addr->sa_family != ARPHRD_ETHER)
487 return -EINVAL;
489 /* automatic mode */
490 if (is_zero_ether_addr(bssid) || is_broadcast_ether_addr(bssid))
491 bssid = NULL;
493 if (bssid && !is_valid_ether_addr(bssid))
494 return -EINVAL;
496 /* both automatic */
497 if (!bssid && !wdev->wext.ibss.bssid)
498 return 0;
500 /* fixed already - and no change */
501 if (wdev->wext.ibss.bssid && bssid &&
502 ether_addr_equal(bssid, wdev->wext.ibss.bssid))
503 return 0;
505 wdev_lock(wdev);
506 err = 0;
507 if (wdev->ssid_len)
508 err = __cfg80211_leave_ibss(rdev, dev, true);
509 wdev_unlock(wdev);
511 if (err)
512 return err;
514 if (bssid) {
515 memcpy(wdev->wext.bssid, bssid, ETH_ALEN);
516 wdev->wext.ibss.bssid = wdev->wext.bssid;
517 } else
518 wdev->wext.ibss.bssid = NULL;
520 wdev_lock(wdev);
521 err = cfg80211_ibss_wext_join(rdev, wdev);
522 wdev_unlock(wdev);
524 return err;
527 int cfg80211_ibss_wext_giwap(struct net_device *dev,
528 struct iw_request_info *info,
529 struct sockaddr *ap_addr, char *extra)
531 struct wireless_dev *wdev = dev->ieee80211_ptr;
533 /* call only for ibss! */
534 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_ADHOC))
535 return -EINVAL;
537 ap_addr->sa_family = ARPHRD_ETHER;
539 wdev_lock(wdev);
540 if (wdev->current_bss)
541 memcpy(ap_addr->sa_data, wdev->current_bss->pub.bssid, ETH_ALEN);
542 else if (wdev->wext.ibss.bssid)
543 memcpy(ap_addr->sa_data, wdev->wext.ibss.bssid, ETH_ALEN);
544 else
545 eth_zero_addr(ap_addr->sa_data);
547 wdev_unlock(wdev);
549 return 0;
551 #endif