blob: f101a6460b44b07e09a2328423aed5535d978913 [file] [log] [blame]
xjb04a4022021-11-25 15:01:52 +08001/*
2 * Copyright 2002-2005, Instant802 Networks, Inc.
3 * Copyright 2005-2006, Devicescape Software, Inc.
4 * Copyright 2006-2007 Jiri Benc <jbenc@suse.cz>
5 * Copyright 2007 Johannes Berg <johannes@sipsolutions.net>
6 * Copyright 2013-2014 Intel Mobile Communications GmbH
7 * Copyright (C) 2015-2017 Intel Deutschland GmbH
8 * Copyright (C) 2018-2019 Intel Corporation
9 *
10 * This program is free software; you can redistribute it and/or modify
11 * it under the terms of the GNU General Public License version 2 as
12 * published by the Free Software Foundation.
13 *
14 * utilities for mac80211
15 */
16
17#include <net/mac80211.h>
18#include <linux/netdevice.h>
19#include <linux/export.h>
20#include <linux/types.h>
21#include <linux/slab.h>
22#include <linux/skbuff.h>
23#include <linux/etherdevice.h>
24#include <linux/if_arp.h>
25#include <linux/bitmap.h>
26#include <linux/crc32.h>
27#include <net/net_namespace.h>
28#include <net/cfg80211.h>
29#include <net/rtnetlink.h>
30
31#include "ieee80211_i.h"
32#include "driver-ops.h"
33#include "rate.h"
34#include "mesh.h"
35#include "wme.h"
36#include "led.h"
37#include "wep.h"
38
39/* privid for wiphys to determine whether they belong to us or not */
40const void *const mac80211_wiphy_privid = &mac80211_wiphy_privid;
41
42struct ieee80211_hw *wiphy_to_ieee80211_hw(struct wiphy *wiphy)
43{
44 struct ieee80211_local *local;
45 BUG_ON(!wiphy);
46
47 local = wiphy_priv(wiphy);
48 return &local->hw;
49}
50EXPORT_SYMBOL(wiphy_to_ieee80211_hw);
51
52void ieee80211_tx_set_protected(struct ieee80211_tx_data *tx)
53{
54 struct sk_buff *skb;
55 struct ieee80211_hdr *hdr;
56
57 skb_queue_walk(&tx->skbs, skb) {
58 hdr = (struct ieee80211_hdr *) skb->data;
59 hdr->frame_control |= cpu_to_le16(IEEE80211_FCTL_PROTECTED);
60 }
61}
62
63int ieee80211_frame_duration(enum nl80211_band band, size_t len,
64 int rate, int erp, int short_preamble,
65 int shift)
66{
67 int dur;
68
69 /* calculate duration (in microseconds, rounded up to next higher
70 * integer if it includes a fractional microsecond) to send frame of
71 * len bytes (does not include FCS) at the given rate. Duration will
72 * also include SIFS.
73 *
74 * rate is in 100 kbps, so divident is multiplied by 10 in the
75 * DIV_ROUND_UP() operations.
76 *
77 * shift may be 2 for 5 MHz channels or 1 for 10 MHz channels, and
78 * is assumed to be 0 otherwise.
79 */
80
81 if (band == NL80211_BAND_5GHZ || erp) {
82 /*
83 * OFDM:
84 *
85 * N_DBPS = DATARATE x 4
86 * N_SYM = Ceiling((16+8xLENGTH+6) / N_DBPS)
87 * (16 = SIGNAL time, 6 = tail bits)
88 * TXTIME = T_PREAMBLE + T_SIGNAL + T_SYM x N_SYM + Signal Ext
89 *
90 * T_SYM = 4 usec
91 * 802.11a - 18.5.2: aSIFSTime = 16 usec
92 * 802.11g - 19.8.4: aSIFSTime = 10 usec +
93 * signal ext = 6 usec
94 */
95 dur = 16; /* SIFS + signal ext */
96 dur += 16; /* IEEE 802.11-2012 18.3.2.4: T_PREAMBLE = 16 usec */
97 dur += 4; /* IEEE 802.11-2012 18.3.2.4: T_SIGNAL = 4 usec */
98
99 /* IEEE 802.11-2012 18.3.2.4: all values above are:
100 * * times 4 for 5 MHz
101 * * times 2 for 10 MHz
102 */
103 dur *= 1 << shift;
104
105 /* rates should already consider the channel bandwidth,
106 * don't apply divisor again.
107 */
108 dur += 4 * DIV_ROUND_UP((16 + 8 * (len + 4) + 6) * 10,
109 4 * rate); /* T_SYM x N_SYM */
110 } else {
111 /*
112 * 802.11b or 802.11g with 802.11b compatibility:
113 * 18.3.4: TXTIME = PreambleLength + PLCPHeaderTime +
114 * Ceiling(((LENGTH+PBCC)x8)/DATARATE). PBCC=0.
115 *
116 * 802.11 (DS): 15.3.3, 802.11b: 18.3.4
117 * aSIFSTime = 10 usec
118 * aPreambleLength = 144 usec or 72 usec with short preamble
119 * aPLCPHeaderLength = 48 usec or 24 usec with short preamble
120 */
121 dur = 10; /* aSIFSTime = 10 usec */
122 dur += short_preamble ? (72 + 24) : (144 + 48);
123
124 dur += DIV_ROUND_UP(8 * (len + 4) * 10, rate);
125 }
126
127 return dur;
128}
129
130/* Exported duration function for driver use */
131__le16 ieee80211_generic_frame_duration(struct ieee80211_hw *hw,
132 struct ieee80211_vif *vif,
133 enum nl80211_band band,
134 size_t frame_len,
135 struct ieee80211_rate *rate)
136{
137 struct ieee80211_sub_if_data *sdata;
138 u16 dur;
139 int erp, shift = 0;
140 bool short_preamble = false;
141
142 erp = 0;
143 if (vif) {
144 sdata = vif_to_sdata(vif);
145 short_preamble = sdata->vif.bss_conf.use_short_preamble;
146 if (sdata->flags & IEEE80211_SDATA_OPERATING_GMODE)
147 erp = rate->flags & IEEE80211_RATE_ERP_G;
148 shift = ieee80211_vif_get_shift(vif);
149 }
150
151 dur = ieee80211_frame_duration(band, frame_len, rate->bitrate, erp,
152 short_preamble, shift);
153
154 return cpu_to_le16(dur);
155}
156EXPORT_SYMBOL(ieee80211_generic_frame_duration);
157
158__le16 ieee80211_rts_duration(struct ieee80211_hw *hw,
159 struct ieee80211_vif *vif, size_t frame_len,
160 const struct ieee80211_tx_info *frame_txctl)
161{
162 struct ieee80211_local *local = hw_to_local(hw);
163 struct ieee80211_rate *rate;
164 struct ieee80211_sub_if_data *sdata;
165 bool short_preamble;
166 int erp, shift = 0, bitrate;
167 u16 dur;
168 struct ieee80211_supported_band *sband;
169
170 sband = local->hw.wiphy->bands[frame_txctl->band];
171
172 short_preamble = false;
173
174 rate = &sband->bitrates[frame_txctl->control.rts_cts_rate_idx];
175
176 erp = 0;
177 if (vif) {
178 sdata = vif_to_sdata(vif);
179 short_preamble = sdata->vif.bss_conf.use_short_preamble;
180 if (sdata->flags & IEEE80211_SDATA_OPERATING_GMODE)
181 erp = rate->flags & IEEE80211_RATE_ERP_G;
182 shift = ieee80211_vif_get_shift(vif);
183 }
184
185 bitrate = DIV_ROUND_UP(rate->bitrate, 1 << shift);
186
187 /* CTS duration */
188 dur = ieee80211_frame_duration(sband->band, 10, bitrate,
189 erp, short_preamble, shift);
190 /* Data frame duration */
191 dur += ieee80211_frame_duration(sband->band, frame_len, bitrate,
192 erp, short_preamble, shift);
193 /* ACK duration */
194 dur += ieee80211_frame_duration(sband->band, 10, bitrate,
195 erp, short_preamble, shift);
196
197 return cpu_to_le16(dur);
198}
199EXPORT_SYMBOL(ieee80211_rts_duration);
200
201__le16 ieee80211_ctstoself_duration(struct ieee80211_hw *hw,
202 struct ieee80211_vif *vif,
203 size_t frame_len,
204 const struct ieee80211_tx_info *frame_txctl)
205{
206 struct ieee80211_local *local = hw_to_local(hw);
207 struct ieee80211_rate *rate;
208 struct ieee80211_sub_if_data *sdata;
209 bool short_preamble;
210 int erp, shift = 0, bitrate;
211 u16 dur;
212 struct ieee80211_supported_band *sband;
213
214 sband = local->hw.wiphy->bands[frame_txctl->band];
215
216 short_preamble = false;
217
218 rate = &sband->bitrates[frame_txctl->control.rts_cts_rate_idx];
219 erp = 0;
220 if (vif) {
221 sdata = vif_to_sdata(vif);
222 short_preamble = sdata->vif.bss_conf.use_short_preamble;
223 if (sdata->flags & IEEE80211_SDATA_OPERATING_GMODE)
224 erp = rate->flags & IEEE80211_RATE_ERP_G;
225 shift = ieee80211_vif_get_shift(vif);
226 }
227
228 bitrate = DIV_ROUND_UP(rate->bitrate, 1 << shift);
229
230 /* Data frame duration */
231 dur = ieee80211_frame_duration(sband->band, frame_len, bitrate,
232 erp, short_preamble, shift);
233 if (!(frame_txctl->flags & IEEE80211_TX_CTL_NO_ACK)) {
234 /* ACK duration */
235 dur += ieee80211_frame_duration(sband->band, 10, bitrate,
236 erp, short_preamble, shift);
237 }
238
239 return cpu_to_le16(dur);
240}
241EXPORT_SYMBOL(ieee80211_ctstoself_duration);
242
243void ieee80211_propagate_queue_wake(struct ieee80211_local *local, int queue)
244{
245 struct ieee80211_sub_if_data *sdata;
246 int n_acs = IEEE80211_NUM_ACS;
247
248 if (local->ops->wake_tx_queue)
249 return;
250
251 if (local->hw.queues < IEEE80211_NUM_ACS)
252 n_acs = 1;
253
254 list_for_each_entry_rcu(sdata, &local->interfaces, list) {
255 int ac;
256
257 if (!sdata->dev)
258 continue;
259
260 if (sdata->vif.cab_queue != IEEE80211_INVAL_HW_QUEUE &&
261 local->queue_stop_reasons[sdata->vif.cab_queue] != 0)
262 continue;
263
264 for (ac = 0; ac < n_acs; ac++) {
265 int ac_queue = sdata->vif.hw_queue[ac];
266
267 if (ac_queue == queue ||
268 (sdata->vif.cab_queue == queue &&
269 local->queue_stop_reasons[ac_queue] == 0 &&
270 skb_queue_empty(&local->pending[ac_queue])))
271 netif_wake_subqueue(sdata->dev, ac);
272 }
273 }
274}
275
276static void __ieee80211_wake_queue(struct ieee80211_hw *hw, int queue,
277 enum queue_stop_reason reason,
278 bool refcounted)
279{
280 struct ieee80211_local *local = hw_to_local(hw);
281
282 trace_wake_queue(local, queue, reason);
283
284 if (WARN_ON(queue >= hw->queues))
285 return;
286
287 if (!test_bit(reason, &local->queue_stop_reasons[queue]))
288 return;
289
290 if (!refcounted) {
291 local->q_stop_reasons[queue][reason] = 0;
292 } else {
293 local->q_stop_reasons[queue][reason]--;
294 if (WARN_ON(local->q_stop_reasons[queue][reason] < 0))
295 local->q_stop_reasons[queue][reason] = 0;
296 }
297
298 if (local->q_stop_reasons[queue][reason] == 0)
299 __clear_bit(reason, &local->queue_stop_reasons[queue]);
300
301 if (local->queue_stop_reasons[queue] != 0)
302 /* someone still has this queue stopped */
303 return;
304
305 if (skb_queue_empty(&local->pending[queue])) {
306 rcu_read_lock();
307 ieee80211_propagate_queue_wake(local, queue);
308 rcu_read_unlock();
309 } else
310 tasklet_schedule(&local->tx_pending_tasklet);
311}
312
313void ieee80211_wake_queue_by_reason(struct ieee80211_hw *hw, int queue,
314 enum queue_stop_reason reason,
315 bool refcounted)
316{
317 struct ieee80211_local *local = hw_to_local(hw);
318 unsigned long flags;
319
320 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
321 __ieee80211_wake_queue(hw, queue, reason, refcounted);
322 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
323}
324
325void ieee80211_wake_queue(struct ieee80211_hw *hw, int queue)
326{
327 ieee80211_wake_queue_by_reason(hw, queue,
328 IEEE80211_QUEUE_STOP_REASON_DRIVER,
329 false);
330}
331EXPORT_SYMBOL(ieee80211_wake_queue);
332
333static void __ieee80211_stop_queue(struct ieee80211_hw *hw, int queue,
334 enum queue_stop_reason reason,
335 bool refcounted)
336{
337 struct ieee80211_local *local = hw_to_local(hw);
338 struct ieee80211_sub_if_data *sdata;
339 int n_acs = IEEE80211_NUM_ACS;
340
341 trace_stop_queue(local, queue, reason);
342
343 if (WARN_ON(queue >= hw->queues))
344 return;
345
346 if (!refcounted)
347 local->q_stop_reasons[queue][reason] = 1;
348 else
349 local->q_stop_reasons[queue][reason]++;
350
351 if (__test_and_set_bit(reason, &local->queue_stop_reasons[queue]))
352 return;
353
354 if (local->ops->wake_tx_queue)
355 return;
356
357 if (local->hw.queues < IEEE80211_NUM_ACS)
358 n_acs = 1;
359
360 rcu_read_lock();
361 list_for_each_entry_rcu(sdata, &local->interfaces, list) {
362 int ac;
363
364 if (!sdata->dev)
365 continue;
366
367 for (ac = 0; ac < n_acs; ac++) {
368 if (sdata->vif.hw_queue[ac] == queue ||
369 sdata->vif.cab_queue == queue)
370 netif_stop_subqueue(sdata->dev, ac);
371 }
372 }
373 rcu_read_unlock();
374}
375
376void ieee80211_stop_queue_by_reason(struct ieee80211_hw *hw, int queue,
377 enum queue_stop_reason reason,
378 bool refcounted)
379{
380 struct ieee80211_local *local = hw_to_local(hw);
381 unsigned long flags;
382
383 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
384 __ieee80211_stop_queue(hw, queue, reason, refcounted);
385 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
386}
387
388void ieee80211_stop_queue(struct ieee80211_hw *hw, int queue)
389{
390 ieee80211_stop_queue_by_reason(hw, queue,
391 IEEE80211_QUEUE_STOP_REASON_DRIVER,
392 false);
393}
394EXPORT_SYMBOL(ieee80211_stop_queue);
395
396void ieee80211_add_pending_skb(struct ieee80211_local *local,
397 struct sk_buff *skb)
398{
399 struct ieee80211_hw *hw = &local->hw;
400 unsigned long flags;
401 struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
402 int queue = info->hw_queue;
403
404 if (WARN_ON(!info->control.vif)) {
405 ieee80211_free_txskb(&local->hw, skb);
406 return;
407 }
408
409 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
410 __ieee80211_stop_queue(hw, queue, IEEE80211_QUEUE_STOP_REASON_SKB_ADD,
411 false);
412 __skb_queue_tail(&local->pending[queue], skb);
413 __ieee80211_wake_queue(hw, queue, IEEE80211_QUEUE_STOP_REASON_SKB_ADD,
414 false);
415 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
416}
417
418void ieee80211_add_pending_skbs(struct ieee80211_local *local,
419 struct sk_buff_head *skbs)
420{
421 struct ieee80211_hw *hw = &local->hw;
422 struct sk_buff *skb;
423 unsigned long flags;
424 int queue, i;
425
426 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
427 while ((skb = skb_dequeue(skbs))) {
428 struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
429
430 if (WARN_ON(!info->control.vif)) {
431 ieee80211_free_txskb(&local->hw, skb);
432 continue;
433 }
434
435 queue = info->hw_queue;
436
437 __ieee80211_stop_queue(hw, queue,
438 IEEE80211_QUEUE_STOP_REASON_SKB_ADD,
439 false);
440
441 __skb_queue_tail(&local->pending[queue], skb);
442 }
443
444 for (i = 0; i < hw->queues; i++)
445 __ieee80211_wake_queue(hw, i,
446 IEEE80211_QUEUE_STOP_REASON_SKB_ADD,
447 false);
448 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
449}
450
451void ieee80211_stop_queues_by_reason(struct ieee80211_hw *hw,
452 unsigned long queues,
453 enum queue_stop_reason reason,
454 bool refcounted)
455{
456 struct ieee80211_local *local = hw_to_local(hw);
457 unsigned long flags;
458 int i;
459
460 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
461
462 for_each_set_bit(i, &queues, hw->queues)
463 __ieee80211_stop_queue(hw, i, reason, refcounted);
464
465 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
466}
467
468void ieee80211_stop_queues(struct ieee80211_hw *hw)
469{
470 ieee80211_stop_queues_by_reason(hw, IEEE80211_MAX_QUEUE_MAP,
471 IEEE80211_QUEUE_STOP_REASON_DRIVER,
472 false);
473}
474EXPORT_SYMBOL(ieee80211_stop_queues);
475
476int ieee80211_queue_stopped(struct ieee80211_hw *hw, int queue)
477{
478 struct ieee80211_local *local = hw_to_local(hw);
479 unsigned long flags;
480 int ret;
481
482 if (WARN_ON(queue >= hw->queues))
483 return true;
484
485 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
486 ret = test_bit(IEEE80211_QUEUE_STOP_REASON_DRIVER,
487 &local->queue_stop_reasons[queue]);
488 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
489 return ret;
490}
491EXPORT_SYMBOL(ieee80211_queue_stopped);
492
493void ieee80211_wake_queues_by_reason(struct ieee80211_hw *hw,
494 unsigned long queues,
495 enum queue_stop_reason reason,
496 bool refcounted)
497{
498 struct ieee80211_local *local = hw_to_local(hw);
499 unsigned long flags;
500 int i;
501
502 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
503
504 for_each_set_bit(i, &queues, hw->queues)
505 __ieee80211_wake_queue(hw, i, reason, refcounted);
506
507 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
508}
509
510void ieee80211_wake_queues(struct ieee80211_hw *hw)
511{
512 ieee80211_wake_queues_by_reason(hw, IEEE80211_MAX_QUEUE_MAP,
513 IEEE80211_QUEUE_STOP_REASON_DRIVER,
514 false);
515}
516EXPORT_SYMBOL(ieee80211_wake_queues);
517
518static unsigned int
519ieee80211_get_vif_queues(struct ieee80211_local *local,
520 struct ieee80211_sub_if_data *sdata)
521{
522 unsigned int queues;
523
524 if (sdata && ieee80211_hw_check(&local->hw, QUEUE_CONTROL)) {
525 int ac;
526
527 queues = 0;
528
529 for (ac = 0; ac < IEEE80211_NUM_ACS; ac++)
530 queues |= BIT(sdata->vif.hw_queue[ac]);
531 if (sdata->vif.cab_queue != IEEE80211_INVAL_HW_QUEUE)
532 queues |= BIT(sdata->vif.cab_queue);
533 } else {
534 /* all queues */
535 queues = BIT(local->hw.queues) - 1;
536 }
537
538 return queues;
539}
540
541void __ieee80211_flush_queues(struct ieee80211_local *local,
542 struct ieee80211_sub_if_data *sdata,
543 unsigned int queues, bool drop)
544{
545 if (!local->ops->flush)
546 return;
547
548 /*
549 * If no queue was set, or if the HW doesn't support
550 * IEEE80211_HW_QUEUE_CONTROL - flush all queues
551 */
552 if (!queues || !ieee80211_hw_check(&local->hw, QUEUE_CONTROL))
553 queues = ieee80211_get_vif_queues(local, sdata);
554
555 ieee80211_stop_queues_by_reason(&local->hw, queues,
556 IEEE80211_QUEUE_STOP_REASON_FLUSH,
557 false);
558
559 drv_flush(local, sdata, queues, drop);
560
561 ieee80211_wake_queues_by_reason(&local->hw, queues,
562 IEEE80211_QUEUE_STOP_REASON_FLUSH,
563 false);
564}
565
566void ieee80211_flush_queues(struct ieee80211_local *local,
567 struct ieee80211_sub_if_data *sdata, bool drop)
568{
569 __ieee80211_flush_queues(local, sdata, 0, drop);
570}
571
572void ieee80211_stop_vif_queues(struct ieee80211_local *local,
573 struct ieee80211_sub_if_data *sdata,
574 enum queue_stop_reason reason)
575{
576 ieee80211_stop_queues_by_reason(&local->hw,
577 ieee80211_get_vif_queues(local, sdata),
578 reason, true);
579}
580
581void ieee80211_wake_vif_queues(struct ieee80211_local *local,
582 struct ieee80211_sub_if_data *sdata,
583 enum queue_stop_reason reason)
584{
585 ieee80211_wake_queues_by_reason(&local->hw,
586 ieee80211_get_vif_queues(local, sdata),
587 reason, true);
588}
589
590static void __iterate_interfaces(struct ieee80211_local *local,
591 u32 iter_flags,
592 void (*iterator)(void *data, u8 *mac,
593 struct ieee80211_vif *vif),
594 void *data)
595{
596 struct ieee80211_sub_if_data *sdata;
597 bool active_only = iter_flags & IEEE80211_IFACE_ITER_ACTIVE;
598
599 list_for_each_entry_rcu(sdata, &local->interfaces, list) {
600 switch (sdata->vif.type) {
601 case NL80211_IFTYPE_MONITOR:
602 if (!(sdata->u.mntr.flags & MONITOR_FLAG_ACTIVE))
603 continue;
604 break;
605 case NL80211_IFTYPE_AP_VLAN:
606 continue;
607 default:
608 break;
609 }
610 if (!(iter_flags & IEEE80211_IFACE_ITER_RESUME_ALL) &&
611 active_only && !(sdata->flags & IEEE80211_SDATA_IN_DRIVER))
612 continue;
613 if (ieee80211_sdata_running(sdata) || !active_only)
614 iterator(data, sdata->vif.addr,
615 &sdata->vif);
616 }
617
618 sdata = rcu_dereference_check(local->monitor_sdata,
619 lockdep_is_held(&local->iflist_mtx) ||
620 lockdep_rtnl_is_held());
621 if (sdata &&
622 (iter_flags & IEEE80211_IFACE_ITER_RESUME_ALL || !active_only ||
623 sdata->flags & IEEE80211_SDATA_IN_DRIVER))
624 iterator(data, sdata->vif.addr, &sdata->vif);
625}
626
627void ieee80211_iterate_interfaces(
628 struct ieee80211_hw *hw, u32 iter_flags,
629 void (*iterator)(void *data, u8 *mac,
630 struct ieee80211_vif *vif),
631 void *data)
632{
633 struct ieee80211_local *local = hw_to_local(hw);
634
635 mutex_lock(&local->iflist_mtx);
636 __iterate_interfaces(local, iter_flags, iterator, data);
637 mutex_unlock(&local->iflist_mtx);
638}
639EXPORT_SYMBOL_GPL(ieee80211_iterate_interfaces);
640
641void ieee80211_iterate_active_interfaces_atomic(
642 struct ieee80211_hw *hw, u32 iter_flags,
643 void (*iterator)(void *data, u8 *mac,
644 struct ieee80211_vif *vif),
645 void *data)
646{
647 struct ieee80211_local *local = hw_to_local(hw);
648
649 rcu_read_lock();
650 __iterate_interfaces(local, iter_flags | IEEE80211_IFACE_ITER_ACTIVE,
651 iterator, data);
652 rcu_read_unlock();
653}
654EXPORT_SYMBOL_GPL(ieee80211_iterate_active_interfaces_atomic);
655
656void ieee80211_iterate_active_interfaces_rtnl(
657 struct ieee80211_hw *hw, u32 iter_flags,
658 void (*iterator)(void *data, u8 *mac,
659 struct ieee80211_vif *vif),
660 void *data)
661{
662 struct ieee80211_local *local = hw_to_local(hw);
663
664 ASSERT_RTNL();
665
666 __iterate_interfaces(local, iter_flags | IEEE80211_IFACE_ITER_ACTIVE,
667 iterator, data);
668}
669EXPORT_SYMBOL_GPL(ieee80211_iterate_active_interfaces_rtnl);
670
671static void __iterate_stations(struct ieee80211_local *local,
672 void (*iterator)(void *data,
673 struct ieee80211_sta *sta),
674 void *data)
675{
676 struct sta_info *sta;
677
678 list_for_each_entry_rcu(sta, &local->sta_list, list) {
679 if (!sta->uploaded)
680 continue;
681
682 iterator(data, &sta->sta);
683 }
684}
685
686void ieee80211_iterate_stations_atomic(struct ieee80211_hw *hw,
687 void (*iterator)(void *data,
688 struct ieee80211_sta *sta),
689 void *data)
690{
691 struct ieee80211_local *local = hw_to_local(hw);
692
693 rcu_read_lock();
694 __iterate_stations(local, iterator, data);
695 rcu_read_unlock();
696}
697EXPORT_SYMBOL_GPL(ieee80211_iterate_stations_atomic);
698
699struct ieee80211_vif *wdev_to_ieee80211_vif(struct wireless_dev *wdev)
700{
701 struct ieee80211_sub_if_data *sdata = IEEE80211_WDEV_TO_SUB_IF(wdev);
702
703 if (!ieee80211_sdata_running(sdata) ||
704 !(sdata->flags & IEEE80211_SDATA_IN_DRIVER))
705 return NULL;
706 return &sdata->vif;
707}
708EXPORT_SYMBOL_GPL(wdev_to_ieee80211_vif);
709
710struct wireless_dev *ieee80211_vif_to_wdev(struct ieee80211_vif *vif)
711{
712 struct ieee80211_sub_if_data *sdata;
713
714 if (!vif)
715 return NULL;
716
717 sdata = vif_to_sdata(vif);
718
719 if (!ieee80211_sdata_running(sdata) ||
720 !(sdata->flags & IEEE80211_SDATA_IN_DRIVER))
721 return NULL;
722
723 return &sdata->wdev;
724}
725EXPORT_SYMBOL_GPL(ieee80211_vif_to_wdev);
726
727/*
728 * Nothing should have been stuffed into the workqueue during
729 * the suspend->resume cycle. Since we can't check each caller
730 * of this function if we are already quiescing / suspended,
731 * check here and don't WARN since this can actually happen when
732 * the rx path (for example) is racing against __ieee80211_suspend
733 * and suspending / quiescing was set after the rx path checked
734 * them.
735 */
736static bool ieee80211_can_queue_work(struct ieee80211_local *local)
737{
738 if (local->quiescing || (local->suspended && !local->resuming)) {
739 pr_warn("queueing ieee80211 work while going to suspend\n");
740 return false;
741 }
742
743 return true;
744}
745
746void ieee80211_queue_work(struct ieee80211_hw *hw, struct work_struct *work)
747{
748 struct ieee80211_local *local = hw_to_local(hw);
749
750 if (!ieee80211_can_queue_work(local))
751 return;
752
753 queue_work(local->workqueue, work);
754}
755EXPORT_SYMBOL(ieee80211_queue_work);
756
757void ieee80211_queue_delayed_work(struct ieee80211_hw *hw,
758 struct delayed_work *dwork,
759 unsigned long delay)
760{
761 struct ieee80211_local *local = hw_to_local(hw);
762
763 if (!ieee80211_can_queue_work(local))
764 return;
765
766 queue_delayed_work(local->workqueue, dwork, delay);
767}
768EXPORT_SYMBOL(ieee80211_queue_delayed_work);
769
770u32 ieee802_11_parse_elems_crc(const u8 *start, size_t len, bool action,
771 struct ieee802_11_elems *elems,
772 u64 filter, u32 crc)
773{
774 size_t left = len;
775 const u8 *pos = start;
776 bool calc_crc = filter != 0;
777 DECLARE_BITMAP(seen_elems, 256);
778 const u8 *ie;
779
780 bitmap_zero(seen_elems, 256);
781 memset(elems, 0, sizeof(*elems));
782 elems->ie_start = start;
783 elems->total_len = len;
784
785 while (left >= 2) {
786 u8 id, elen;
787 bool elem_parse_failed;
788
789 id = *pos++;
790 elen = *pos++;
791 left -= 2;
792
793 if (elen > left) {
794 elems->parse_error = true;
795 break;
796 }
797
798 switch (id) {
799 case WLAN_EID_SSID:
800 case WLAN_EID_SUPP_RATES:
801 case WLAN_EID_FH_PARAMS:
802 case WLAN_EID_DS_PARAMS:
803 case WLAN_EID_CF_PARAMS:
804 case WLAN_EID_TIM:
805 case WLAN_EID_IBSS_PARAMS:
806 case WLAN_EID_CHALLENGE:
807 case WLAN_EID_RSN:
808 case WLAN_EID_ERP_INFO:
809 case WLAN_EID_EXT_SUPP_RATES:
810 case WLAN_EID_HT_CAPABILITY:
811 case WLAN_EID_HT_OPERATION:
812 case WLAN_EID_VHT_CAPABILITY:
813 case WLAN_EID_VHT_OPERATION:
814 case WLAN_EID_MESH_ID:
815 case WLAN_EID_MESH_CONFIG:
816 case WLAN_EID_PEER_MGMT:
817 case WLAN_EID_PREQ:
818 case WLAN_EID_PREP:
819 case WLAN_EID_PERR:
820 case WLAN_EID_RANN:
821 case WLAN_EID_CHANNEL_SWITCH:
822 case WLAN_EID_EXT_CHANSWITCH_ANN:
823 case WLAN_EID_COUNTRY:
824 case WLAN_EID_PWR_CONSTRAINT:
825 case WLAN_EID_TIMEOUT_INTERVAL:
826 case WLAN_EID_SECONDARY_CHANNEL_OFFSET:
827 case WLAN_EID_WIDE_BW_CHANNEL_SWITCH:
828 case WLAN_EID_CHAN_SWITCH_PARAM:
829 case WLAN_EID_EXT_CAPABILITY:
830 case WLAN_EID_CHAN_SWITCH_TIMING:
831 case WLAN_EID_LINK_ID:
832 case WLAN_EID_BSS_MAX_IDLE_PERIOD:
833 /*
834 * not listing WLAN_EID_CHANNEL_SWITCH_WRAPPER -- it seems possible
835 * that if the content gets bigger it might be needed more than once
836 */
837 if (test_bit(id, seen_elems)) {
838 elems->parse_error = true;
839 left -= elen;
840 pos += elen;
841 continue;
842 }
843 break;
844 }
845
846 if (calc_crc && id < 64 && (filter & (1ULL << id)))
847 crc = crc32_be(crc, pos - 2, elen + 2);
848
849 elem_parse_failed = false;
850
851 switch (id) {
852 case WLAN_EID_LINK_ID:
853 if (elen + 2 != sizeof(struct ieee80211_tdls_lnkie)) {
854 elem_parse_failed = true;
855 break;
856 }
857 elems->lnk_id = (void *)(pos - 2);
858 break;
859 case WLAN_EID_CHAN_SWITCH_TIMING:
860 if (elen != sizeof(struct ieee80211_ch_switch_timing)) {
861 elem_parse_failed = true;
862 break;
863 }
864 elems->ch_sw_timing = (void *)pos;
865 break;
866 case WLAN_EID_EXT_CAPABILITY:
867 elems->ext_capab = pos;
868 elems->ext_capab_len = elen;
869 break;
870 case WLAN_EID_SSID:
871 elems->ssid = pos;
872 elems->ssid_len = elen;
873 break;
874 case WLAN_EID_SUPP_RATES:
875 elems->supp_rates = pos;
876 elems->supp_rates_len = elen;
877 break;
878 case WLAN_EID_DS_PARAMS:
879 if (elen >= 1)
880 elems->ds_params = pos;
881 else
882 elem_parse_failed = true;
883 break;
884 case WLAN_EID_TIM:
885 if (elen >= sizeof(struct ieee80211_tim_ie)) {
886 elems->tim = (void *)pos;
887 elems->tim_len = elen;
888 } else
889 elem_parse_failed = true;
890 break;
891 case WLAN_EID_CHALLENGE:
892 elems->challenge = pos;
893 elems->challenge_len = elen;
894 break;
895 case WLAN_EID_VENDOR_SPECIFIC:
896 if (elen >= 4 && pos[0] == 0x00 && pos[1] == 0x50 &&
897 pos[2] == 0xf2) {
898 /* Microsoft OUI (00:50:F2) */
899
900 if (calc_crc)
901 crc = crc32_be(crc, pos - 2, elen + 2);
902
903 if (elen >= 5 && pos[3] == 2) {
904 /* OUI Type 2 - WMM IE */
905 if (pos[4] == 0) {
906 elems->wmm_info = pos;
907 elems->wmm_info_len = elen;
908 } else if (pos[4] == 1) {
909 elems->wmm_param = pos;
910 elems->wmm_param_len = elen;
911 }
912 }
913 }
914 break;
915 case WLAN_EID_RSN:
916 elems->rsn = pos;
917 elems->rsn_len = elen;
918 break;
919 case WLAN_EID_ERP_INFO:
920 if (elen >= 1)
921 elems->erp_info = pos;
922 else
923 elem_parse_failed = true;
924 break;
925 case WLAN_EID_EXT_SUPP_RATES:
926 elems->ext_supp_rates = pos;
927 elems->ext_supp_rates_len = elen;
928 break;
929 case WLAN_EID_HT_CAPABILITY:
930 if (elen >= sizeof(struct ieee80211_ht_cap))
931 elems->ht_cap_elem = (void *)pos;
932 else
933 elem_parse_failed = true;
934 break;
935 case WLAN_EID_HT_OPERATION:
936 if (elen >= sizeof(struct ieee80211_ht_operation))
937 elems->ht_operation = (void *)pos;
938 else
939 elem_parse_failed = true;
940 break;
941 case WLAN_EID_VHT_CAPABILITY:
942 if (elen >= sizeof(struct ieee80211_vht_cap))
943 elems->vht_cap_elem = (void *)pos;
944 else
945 elem_parse_failed = true;
946 break;
947 case WLAN_EID_VHT_OPERATION:
948 if (elen >= sizeof(struct ieee80211_vht_operation))
949 elems->vht_operation = (void *)pos;
950 else
951 elem_parse_failed = true;
952 break;
953 case WLAN_EID_OPMODE_NOTIF:
954 if (elen > 0)
955 elems->opmode_notif = pos;
956 else
957 elem_parse_failed = true;
958 break;
959 case WLAN_EID_MESH_ID:
960 elems->mesh_id = pos;
961 elems->mesh_id_len = elen;
962 break;
963 case WLAN_EID_MESH_CONFIG:
964 if (elen >= sizeof(struct ieee80211_meshconf_ie))
965 elems->mesh_config = (void *)pos;
966 else
967 elem_parse_failed = true;
968 break;
969 case WLAN_EID_PEER_MGMT:
970 elems->peering = pos;
971 elems->peering_len = elen;
972 break;
973 case WLAN_EID_MESH_AWAKE_WINDOW:
974 if (elen >= 2)
975 elems->awake_window = (void *)pos;
976 break;
977 case WLAN_EID_PREQ:
978 elems->preq = pos;
979 elems->preq_len = elen;
980 break;
981 case WLAN_EID_PREP:
982 elems->prep = pos;
983 elems->prep_len = elen;
984 break;
985 case WLAN_EID_PERR:
986 elems->perr = pos;
987 elems->perr_len = elen;
988 break;
989 case WLAN_EID_RANN:
990 if (elen >= sizeof(struct ieee80211_rann_ie))
991 elems->rann = (void *)pos;
992 else
993 elem_parse_failed = true;
994 break;
995 case WLAN_EID_CHANNEL_SWITCH:
996 if (elen != sizeof(struct ieee80211_channel_sw_ie)) {
997 elem_parse_failed = true;
998 break;
999 }
1000 elems->ch_switch_ie = (void *)pos;
1001 break;
1002 case WLAN_EID_EXT_CHANSWITCH_ANN:
1003 if (elen != sizeof(struct ieee80211_ext_chansw_ie)) {
1004 elem_parse_failed = true;
1005 break;
1006 }
1007 elems->ext_chansw_ie = (void *)pos;
1008 break;
1009 case WLAN_EID_SECONDARY_CHANNEL_OFFSET:
1010 if (elen != sizeof(struct ieee80211_sec_chan_offs_ie)) {
1011 elem_parse_failed = true;
1012 break;
1013 }
1014 elems->sec_chan_offs = (void *)pos;
1015 break;
1016 case WLAN_EID_CHAN_SWITCH_PARAM:
1017 if (elen !=
1018 sizeof(*elems->mesh_chansw_params_ie)) {
1019 elem_parse_failed = true;
1020 break;
1021 }
1022 elems->mesh_chansw_params_ie = (void *)pos;
1023 break;
1024 case WLAN_EID_WIDE_BW_CHANNEL_SWITCH:
1025 if (!action ||
1026 elen != sizeof(*elems->wide_bw_chansw_ie)) {
1027 elem_parse_failed = true;
1028 break;
1029 }
1030 elems->wide_bw_chansw_ie = (void *)pos;
1031 break;
1032 case WLAN_EID_CHANNEL_SWITCH_WRAPPER:
1033 if (action) {
1034 elem_parse_failed = true;
1035 break;
1036 }
1037 /*
1038 * This is a bit tricky, but as we only care about
1039 * the wide bandwidth channel switch element, so
1040 * just parse it out manually.
1041 */
1042 ie = cfg80211_find_ie(WLAN_EID_WIDE_BW_CHANNEL_SWITCH,
1043 pos, elen);
1044 if (ie) {
1045 if (ie[1] == sizeof(*elems->wide_bw_chansw_ie))
1046 elems->wide_bw_chansw_ie =
1047 (void *)(ie + 2);
1048 else
1049 elem_parse_failed = true;
1050 }
1051 break;
1052 case WLAN_EID_COUNTRY:
1053 elems->country_elem = pos;
1054 elems->country_elem_len = elen;
1055 break;
1056 case WLAN_EID_PWR_CONSTRAINT:
1057 if (elen != 1) {
1058 elem_parse_failed = true;
1059 break;
1060 }
1061 elems->pwr_constr_elem = pos;
1062 break;
1063 case WLAN_EID_CISCO_VENDOR_SPECIFIC:
1064 /* Lots of different options exist, but we only care
1065 * about the Dynamic Transmit Power Control element.
1066 * First check for the Cisco OUI, then for the DTPC
1067 * tag (0x00).
1068 */
1069 if (elen < 4) {
1070 elem_parse_failed = true;
1071 break;
1072 }
1073
1074 if (pos[0] != 0x00 || pos[1] != 0x40 ||
1075 pos[2] != 0x96 || pos[3] != 0x00)
1076 break;
1077
1078 if (elen != 6) {
1079 elem_parse_failed = true;
1080 break;
1081 }
1082
1083 if (calc_crc)
1084 crc = crc32_be(crc, pos - 2, elen + 2);
1085
1086 elems->cisco_dtpc_elem = pos;
1087 break;
1088 case WLAN_EID_TIMEOUT_INTERVAL:
1089 if (elen >= sizeof(struct ieee80211_timeout_interval_ie))
1090 elems->timeout_int = (void *)pos;
1091 else
1092 elem_parse_failed = true;
1093 break;
1094 case WLAN_EID_BSS_MAX_IDLE_PERIOD:
1095 if (elen >= sizeof(*elems->max_idle_period_ie))
1096 elems->max_idle_period_ie = (void *)pos;
1097 break;
1098 case WLAN_EID_EXTENSION:
1099 if (pos[0] == WLAN_EID_EXT_HE_MU_EDCA &&
1100 elen >= (sizeof(*elems->mu_edca_param_set) + 1)) {
1101 elems->mu_edca_param_set = (void *)&pos[1];
1102 } else if (pos[0] == WLAN_EID_EXT_HE_CAPABILITY) {
1103 elems->he_cap = (void *)&pos[1];
1104 elems->he_cap_len = elen - 1;
1105 } else if (pos[0] == WLAN_EID_EXT_HE_OPERATION &&
1106 elen >= sizeof(*elems->he_operation) &&
1107 elen >= ieee80211_he_oper_size(&pos[1])) {
1108 elems->he_operation = (void *)&pos[1];
1109 } else if (pos[0] == WLAN_EID_EXT_UORA && elen >= 1) {
1110 elems->uora_element = (void *)&pos[1];
1111 }
1112 break;
1113 default:
1114 break;
1115 }
1116
1117 if (elem_parse_failed)
1118 elems->parse_error = true;
1119 else
1120 __set_bit(id, seen_elems);
1121
1122 left -= elen;
1123 pos += elen;
1124 }
1125
1126 if (left != 0)
1127 elems->parse_error = true;
1128
1129 return crc;
1130}
1131
1132void ieee80211_regulatory_limit_wmm_params(struct ieee80211_sub_if_data *sdata,
1133 struct ieee80211_tx_queue_params
1134 *qparam, int ac)
1135{
1136 struct ieee80211_chanctx_conf *chanctx_conf;
1137 const struct ieee80211_reg_rule *rrule;
1138 const struct ieee80211_wmm_ac *wmm_ac;
1139 u16 center_freq = 0;
1140
1141 if (sdata->vif.type != NL80211_IFTYPE_AP &&
1142 sdata->vif.type != NL80211_IFTYPE_STATION)
1143 return;
1144
1145 rcu_read_lock();
1146 chanctx_conf = rcu_dereference(sdata->vif.chanctx_conf);
1147 if (chanctx_conf)
1148 center_freq = chanctx_conf->def.chan->center_freq;
1149
1150 if (!center_freq) {
1151 rcu_read_unlock();
1152 return;
1153 }
1154
1155 rrule = freq_reg_info(sdata->wdev.wiphy, MHZ_TO_KHZ(center_freq));
1156
1157 if (IS_ERR_OR_NULL(rrule) || !rrule->has_wmm) {
1158 rcu_read_unlock();
1159 return;
1160 }
1161
1162 if (sdata->vif.type == NL80211_IFTYPE_AP)
1163 wmm_ac = &rrule->wmm_rule.ap[ac];
1164 else
1165 wmm_ac = &rrule->wmm_rule.client[ac];
1166 qparam->cw_min = max_t(u16, qparam->cw_min, wmm_ac->cw_min);
1167 qparam->cw_max = max_t(u16, qparam->cw_max, wmm_ac->cw_max);
1168 qparam->aifs = max_t(u8, qparam->aifs, wmm_ac->aifsn);
1169 qparam->txop = min_t(u16, qparam->txop, wmm_ac->cot / 32);
1170 rcu_read_unlock();
1171}
1172
1173void ieee80211_set_wmm_default(struct ieee80211_sub_if_data *sdata,
1174 bool bss_notify, bool enable_qos)
1175{
1176 struct ieee80211_local *local = sdata->local;
1177 struct ieee80211_tx_queue_params qparam;
1178 struct ieee80211_chanctx_conf *chanctx_conf;
1179 int ac;
1180 bool use_11b;
1181 bool is_ocb; /* Use another EDCA parameters if dot11OCBActivated=true */
1182 int aCWmin, aCWmax;
1183
1184 if (!local->ops->conf_tx)
1185 return;
1186
1187 if (local->hw.queues < IEEE80211_NUM_ACS)
1188 return;
1189
1190 memset(&qparam, 0, sizeof(qparam));
1191
1192 rcu_read_lock();
1193 chanctx_conf = rcu_dereference(sdata->vif.chanctx_conf);
1194 use_11b = (chanctx_conf &&
1195 chanctx_conf->def.chan->band == NL80211_BAND_2GHZ) &&
1196 !(sdata->flags & IEEE80211_SDATA_OPERATING_GMODE);
1197 rcu_read_unlock();
1198
1199 is_ocb = (sdata->vif.type == NL80211_IFTYPE_OCB);
1200
1201 /* Set defaults according to 802.11-2007 Table 7-37 */
1202 aCWmax = 1023;
1203 if (use_11b)
1204 aCWmin = 31;
1205 else
1206 aCWmin = 15;
1207
1208 /* Confiure old 802.11b/g medium access rules. */
1209 qparam.cw_max = aCWmax;
1210 qparam.cw_min = aCWmin;
1211 qparam.txop = 0;
1212 qparam.aifs = 2;
1213
1214 for (ac = 0; ac < IEEE80211_NUM_ACS; ac++) {
1215 /* Update if QoS is enabled. */
1216 if (enable_qos) {
1217 switch (ac) {
1218 case IEEE80211_AC_BK:
1219 qparam.cw_max = aCWmax;
1220 qparam.cw_min = aCWmin;
1221 qparam.txop = 0;
1222 if (is_ocb)
1223 qparam.aifs = 9;
1224 else
1225 qparam.aifs = 7;
1226 break;
1227 /* never happens but let's not leave undefined */
1228 default:
1229 case IEEE80211_AC_BE:
1230 qparam.cw_max = aCWmax;
1231 qparam.cw_min = aCWmin;
1232 qparam.txop = 0;
1233 if (is_ocb)
1234 qparam.aifs = 6;
1235 else
1236 qparam.aifs = 3;
1237 break;
1238 case IEEE80211_AC_VI:
1239 qparam.cw_max = aCWmin;
1240 qparam.cw_min = (aCWmin + 1) / 2 - 1;
1241 if (is_ocb)
1242 qparam.txop = 0;
1243 else if (use_11b)
1244 qparam.txop = 6016/32;
1245 else
1246 qparam.txop = 3008/32;
1247
1248 if (is_ocb)
1249 qparam.aifs = 3;
1250 else
1251 qparam.aifs = 2;
1252 break;
1253 case IEEE80211_AC_VO:
1254 qparam.cw_max = (aCWmin + 1) / 2 - 1;
1255 qparam.cw_min = (aCWmin + 1) / 4 - 1;
1256 if (is_ocb)
1257 qparam.txop = 0;
1258 else if (use_11b)
1259 qparam.txop = 3264/32;
1260 else
1261 qparam.txop = 1504/32;
1262 qparam.aifs = 2;
1263 break;
1264 }
1265 }
1266 ieee80211_regulatory_limit_wmm_params(sdata, &qparam, ac);
1267
1268 qparam.uapsd = false;
1269
1270 sdata->tx_conf[ac] = qparam;
1271 drv_conf_tx(local, sdata, ac, &qparam);
1272 }
1273
1274 if (sdata->vif.type != NL80211_IFTYPE_MONITOR &&
1275 sdata->vif.type != NL80211_IFTYPE_P2P_DEVICE &&
1276 sdata->vif.type != NL80211_IFTYPE_NAN) {
1277 sdata->vif.bss_conf.qos = enable_qos;
1278 if (bss_notify)
1279 ieee80211_bss_info_change_notify(sdata,
1280 BSS_CHANGED_QOS);
1281 }
1282}
1283
1284void ieee80211_send_auth(struct ieee80211_sub_if_data *sdata,
1285 u16 transaction, u16 auth_alg, u16 status,
1286 const u8 *extra, size_t extra_len, const u8 *da,
1287 const u8 *bssid, const u8 *key, u8 key_len, u8 key_idx,
1288 u32 tx_flags)
1289{
1290 struct ieee80211_local *local = sdata->local;
1291 struct sk_buff *skb;
1292 struct ieee80211_mgmt *mgmt;
1293 int err;
1294
1295 /* 24 + 6 = header + auth_algo + auth_transaction + status_code */
1296 skb = dev_alloc_skb(local->hw.extra_tx_headroom + IEEE80211_WEP_IV_LEN +
1297 24 + 6 + extra_len + IEEE80211_WEP_ICV_LEN);
1298 if (!skb)
1299 return;
1300
1301 skb_reserve(skb, local->hw.extra_tx_headroom + IEEE80211_WEP_IV_LEN);
1302
1303 mgmt = skb_put_zero(skb, 24 + 6);
1304 mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
1305 IEEE80211_STYPE_AUTH);
1306 memcpy(mgmt->da, da, ETH_ALEN);
1307 memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
1308 memcpy(mgmt->bssid, bssid, ETH_ALEN);
1309 mgmt->u.auth.auth_alg = cpu_to_le16(auth_alg);
1310 mgmt->u.auth.auth_transaction = cpu_to_le16(transaction);
1311 mgmt->u.auth.status_code = cpu_to_le16(status);
1312 if (extra)
1313 skb_put_data(skb, extra, extra_len);
1314
1315 if (auth_alg == WLAN_AUTH_SHARED_KEY && transaction == 3) {
1316 mgmt->frame_control |= cpu_to_le16(IEEE80211_FCTL_PROTECTED);
1317 err = ieee80211_wep_encrypt(local, skb, key, key_len, key_idx);
1318 WARN_ON(err);
1319 }
1320
1321 IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT |
1322 tx_flags;
1323 ieee80211_tx_skb(sdata, skb);
1324}
1325
1326void ieee80211_send_deauth_disassoc(struct ieee80211_sub_if_data *sdata,
1327 const u8 *bssid, u16 stype, u16 reason,
1328 bool send_frame, u8 *frame_buf)
1329{
1330 struct ieee80211_local *local = sdata->local;
1331 struct sk_buff *skb;
1332 struct ieee80211_mgmt *mgmt = (void *)frame_buf;
1333
1334 /* build frame */
1335 mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT | stype);
1336 mgmt->duration = 0; /* initialize only */
1337 mgmt->seq_ctrl = 0; /* initialize only */
1338 memcpy(mgmt->da, bssid, ETH_ALEN);
1339 memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
1340 memcpy(mgmt->bssid, bssid, ETH_ALEN);
1341 /* u.deauth.reason_code == u.disassoc.reason_code */
1342 mgmt->u.deauth.reason_code = cpu_to_le16(reason);
1343
1344 if (send_frame) {
1345 skb = dev_alloc_skb(local->hw.extra_tx_headroom +
1346 IEEE80211_DEAUTH_FRAME_LEN);
1347 if (!skb)
1348 return;
1349
1350 skb_reserve(skb, local->hw.extra_tx_headroom);
1351
1352 /* copy in frame */
1353 skb_put_data(skb, mgmt, IEEE80211_DEAUTH_FRAME_LEN);
1354
1355 if (sdata->vif.type != NL80211_IFTYPE_STATION ||
1356 !(sdata->u.mgd.flags & IEEE80211_STA_MFP_ENABLED))
1357 IEEE80211_SKB_CB(skb)->flags |=
1358 IEEE80211_TX_INTFL_DONT_ENCRYPT;
1359
1360 ieee80211_tx_skb(sdata, skb);
1361 }
1362}
1363
1364static int ieee80211_build_preq_ies_band(struct ieee80211_local *local,
1365 u8 *buffer, size_t buffer_len,
1366 const u8 *ie, size_t ie_len,
1367 enum nl80211_band band,
1368 u32 rate_mask,
1369 struct cfg80211_chan_def *chandef,
1370 size_t *offset, u32 flags)
1371{
1372 struct ieee80211_supported_band *sband;
1373 const struct ieee80211_sta_he_cap *he_cap;
1374 u8 *pos = buffer, *end = buffer + buffer_len;
1375 size_t noffset;
1376 int supp_rates_len, i;
1377 u8 rates[32];
1378 int num_rates;
1379 int ext_rates_len;
1380 int shift;
1381 u32 rate_flags;
1382 bool have_80mhz = false;
1383
1384 *offset = 0;
1385
1386 sband = local->hw.wiphy->bands[band];
1387 if (WARN_ON_ONCE(!sband))
1388 return 0;
1389
1390 rate_flags = ieee80211_chandef_rate_flags(chandef);
1391 shift = ieee80211_chandef_get_shift(chandef);
1392
1393 num_rates = 0;
1394 for (i = 0; i < sband->n_bitrates; i++) {
1395 if ((BIT(i) & rate_mask) == 0)
1396 continue; /* skip rate */
1397 if ((rate_flags & sband->bitrates[i].flags) != rate_flags)
1398 continue;
1399
1400 rates[num_rates++] =
1401 (u8) DIV_ROUND_UP(sband->bitrates[i].bitrate,
1402 (1 << shift) * 5);
1403 }
1404
1405 supp_rates_len = min_t(int, num_rates, 8);
1406
1407 if (end - pos < 2 + supp_rates_len)
1408 goto out_err;
1409 *pos++ = WLAN_EID_SUPP_RATES;
1410 *pos++ = supp_rates_len;
1411 memcpy(pos, rates, supp_rates_len);
1412 pos += supp_rates_len;
1413
1414 /* insert "request information" if in custom IEs */
1415 if (ie && ie_len) {
1416 static const u8 before_extrates[] = {
1417 WLAN_EID_SSID,
1418 WLAN_EID_SUPP_RATES,
1419 WLAN_EID_REQUEST,
1420 };
1421 noffset = ieee80211_ie_split(ie, ie_len,
1422 before_extrates,
1423 ARRAY_SIZE(before_extrates),
1424 *offset);
1425 if (end - pos < noffset - *offset)
1426 goto out_err;
1427 memcpy(pos, ie + *offset, noffset - *offset);
1428 pos += noffset - *offset;
1429 *offset = noffset;
1430 }
1431
1432 ext_rates_len = num_rates - supp_rates_len;
1433 if (ext_rates_len > 0) {
1434 if (end - pos < 2 + ext_rates_len)
1435 goto out_err;
1436 *pos++ = WLAN_EID_EXT_SUPP_RATES;
1437 *pos++ = ext_rates_len;
1438 memcpy(pos, rates + supp_rates_len, ext_rates_len);
1439 pos += ext_rates_len;
1440 }
1441
1442 if (chandef->chan && sband->band == NL80211_BAND_2GHZ) {
1443 if (end - pos < 3)
1444 goto out_err;
1445 *pos++ = WLAN_EID_DS_PARAMS;
1446 *pos++ = 1;
1447 *pos++ = ieee80211_frequency_to_channel(
1448 chandef->chan->center_freq);
1449 }
1450
1451 if (flags & IEEE80211_PROBE_FLAG_MIN_CONTENT)
1452 goto done;
1453
1454 /* insert custom IEs that go before HT */
1455 if (ie && ie_len) {
1456 static const u8 before_ht[] = {
1457 /*
1458 * no need to list the ones split off already
1459 * (or generated here)
1460 */
1461 WLAN_EID_DS_PARAMS,
1462 WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
1463 };
1464 noffset = ieee80211_ie_split(ie, ie_len,
1465 before_ht, ARRAY_SIZE(before_ht),
1466 *offset);
1467 if (end - pos < noffset - *offset)
1468 goto out_err;
1469 memcpy(pos, ie + *offset, noffset - *offset);
1470 pos += noffset - *offset;
1471 *offset = noffset;
1472 }
1473
1474 if (sband->ht_cap.ht_supported) {
1475 if (end - pos < 2 + sizeof(struct ieee80211_ht_cap))
1476 goto out_err;
1477 pos = ieee80211_ie_build_ht_cap(pos, &sband->ht_cap,
1478 sband->ht_cap.cap);
1479 }
1480
1481 /* insert custom IEs that go before VHT */
1482 if (ie && ie_len) {
1483 static const u8 before_vht[] = {
1484 /*
1485 * no need to list the ones split off already
1486 * (or generated here)
1487 */
1488 WLAN_EID_BSS_COEX_2040,
1489 WLAN_EID_EXT_CAPABILITY,
1490 WLAN_EID_SSID_LIST,
1491 WLAN_EID_CHANNEL_USAGE,
1492 WLAN_EID_INTERWORKING,
1493 WLAN_EID_MESH_ID,
1494 /* 60 GHz (Multi-band, DMG, MMS) can't happen */
1495 };
1496 noffset = ieee80211_ie_split(ie, ie_len,
1497 before_vht, ARRAY_SIZE(before_vht),
1498 *offset);
1499 if (end - pos < noffset - *offset)
1500 goto out_err;
1501 memcpy(pos, ie + *offset, noffset - *offset);
1502 pos += noffset - *offset;
1503 *offset = noffset;
1504 }
1505
1506 /* Check if any channel in this sband supports at least 80 MHz */
1507 for (i = 0; i < sband->n_channels; i++) {
1508 if (sband->channels[i].flags & (IEEE80211_CHAN_DISABLED |
1509 IEEE80211_CHAN_NO_80MHZ))
1510 continue;
1511
1512 have_80mhz = true;
1513 break;
1514 }
1515
1516 if (sband->vht_cap.vht_supported && have_80mhz) {
1517 if (end - pos < 2 + sizeof(struct ieee80211_vht_cap))
1518 goto out_err;
1519 pos = ieee80211_ie_build_vht_cap(pos, &sband->vht_cap,
1520 sband->vht_cap.cap);
1521 }
1522
1523 /* insert custom IEs that go before HE */
1524 if (ie && ie_len) {
1525 static const u8 before_he[] = {
1526 /*
1527 * no need to list the ones split off before VHT
1528 * or generated here
1529 */
1530 WLAN_EID_EXTENSION, WLAN_EID_EXT_FILS_REQ_PARAMS,
1531 WLAN_EID_AP_CSN,
1532 /* TODO: add 11ah/11aj/11ak elements */
1533 };
1534 noffset = ieee80211_ie_split(ie, ie_len,
1535 before_he, ARRAY_SIZE(before_he),
1536 *offset);
1537 if (end - pos < noffset - *offset)
1538 goto out_err;
1539 memcpy(pos, ie + *offset, noffset - *offset);
1540 pos += noffset - *offset;
1541 *offset = noffset;
1542 }
1543
1544 he_cap = ieee80211_get_he_sta_cap(sband);
1545 if (he_cap) {
1546 pos = ieee80211_ie_build_he_cap(pos, he_cap, end);
1547 if (!pos)
1548 goto out_err;
1549 }
1550
1551 /*
1552 * If adding more here, adjust code in main.c
1553 * that calculates local->scan_ies_len.
1554 */
1555
1556 return pos - buffer;
1557 out_err:
1558 WARN_ONCE(1, "not enough space for preq IEs\n");
1559 done:
1560 return pos - buffer;
1561}
1562
1563int ieee80211_build_preq_ies(struct ieee80211_local *local, u8 *buffer,
1564 size_t buffer_len,
1565 struct ieee80211_scan_ies *ie_desc,
1566 const u8 *ie, size_t ie_len,
1567 u8 bands_used, u32 *rate_masks,
1568 struct cfg80211_chan_def *chandef,
1569 u32 flags)
1570{
1571 size_t pos = 0, old_pos = 0, custom_ie_offset = 0;
1572 int i;
1573
1574 memset(ie_desc, 0, sizeof(*ie_desc));
1575
1576 for (i = 0; i < NUM_NL80211_BANDS; i++) {
1577 if (bands_used & BIT(i)) {
1578 pos += ieee80211_build_preq_ies_band(local,
1579 buffer + pos,
1580 buffer_len - pos,
1581 ie, ie_len, i,
1582 rate_masks[i],
1583 chandef,
1584 &custom_ie_offset,
1585 flags);
1586 ie_desc->ies[i] = buffer + old_pos;
1587 ie_desc->len[i] = pos - old_pos;
1588 old_pos = pos;
1589 }
1590 }
1591
1592 /* add any remaining custom IEs */
1593 if (ie && ie_len) {
1594 if (WARN_ONCE(buffer_len - pos < ie_len - custom_ie_offset,
1595 "not enough space for preq custom IEs\n"))
1596 return pos;
1597 memcpy(buffer + pos, ie + custom_ie_offset,
1598 ie_len - custom_ie_offset);
1599 ie_desc->common_ies = buffer + pos;
1600 ie_desc->common_ie_len = ie_len - custom_ie_offset;
1601 pos += ie_len - custom_ie_offset;
1602 }
1603
1604 return pos;
1605};
1606
1607struct sk_buff *ieee80211_build_probe_req(struct ieee80211_sub_if_data *sdata,
1608 const u8 *src, const u8 *dst,
1609 u32 ratemask,
1610 struct ieee80211_channel *chan,
1611 const u8 *ssid, size_t ssid_len,
1612 const u8 *ie, size_t ie_len,
1613 u32 flags)
1614{
1615 struct ieee80211_local *local = sdata->local;
1616 struct cfg80211_chan_def chandef;
1617 struct sk_buff *skb;
1618 struct ieee80211_mgmt *mgmt;
1619 int ies_len;
1620 u32 rate_masks[NUM_NL80211_BANDS] = {};
1621 struct ieee80211_scan_ies dummy_ie_desc;
1622
1623 /*
1624 * Do not send DS Channel parameter for directed probe requests
1625 * in order to maximize the chance that we get a response. Some
1626 * badly-behaved APs don't respond when this parameter is included.
1627 */
1628 chandef.width = sdata->vif.bss_conf.chandef.width;
1629 if (flags & IEEE80211_PROBE_FLAG_DIRECTED)
1630 chandef.chan = NULL;
1631 else
1632 chandef.chan = chan;
1633
1634 skb = ieee80211_probereq_get(&local->hw, src, ssid, ssid_len,
1635 100 + ie_len);
1636 if (!skb)
1637 return NULL;
1638
1639 rate_masks[chan->band] = ratemask;
1640 ies_len = ieee80211_build_preq_ies(local, skb_tail_pointer(skb),
1641 skb_tailroom(skb), &dummy_ie_desc,
1642 ie, ie_len, BIT(chan->band),
1643 rate_masks, &chandef, flags);
1644 skb_put(skb, ies_len);
1645
1646 if (dst) {
1647 mgmt = (struct ieee80211_mgmt *) skb->data;
1648 memcpy(mgmt->da, dst, ETH_ALEN);
1649 memcpy(mgmt->bssid, dst, ETH_ALEN);
1650 }
1651
1652 IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT;
1653
1654 return skb;
1655}
1656
1657u32 ieee80211_sta_get_rates(struct ieee80211_sub_if_data *sdata,
1658 struct ieee802_11_elems *elems,
1659 enum nl80211_band band, u32 *basic_rates)
1660{
1661 struct ieee80211_supported_band *sband;
1662 size_t num_rates;
1663 u32 supp_rates, rate_flags;
1664 int i, j, shift;
1665
1666 sband = sdata->local->hw.wiphy->bands[band];
1667 if (WARN_ON(!sband))
1668 return 1;
1669
1670 rate_flags = ieee80211_chandef_rate_flags(&sdata->vif.bss_conf.chandef);
1671 shift = ieee80211_vif_get_shift(&sdata->vif);
1672
1673 num_rates = sband->n_bitrates;
1674 supp_rates = 0;
1675 for (i = 0; i < elems->supp_rates_len +
1676 elems->ext_supp_rates_len; i++) {
1677 u8 rate = 0;
1678 int own_rate;
1679 bool is_basic;
1680 if (i < elems->supp_rates_len)
1681 rate = elems->supp_rates[i];
1682 else if (elems->ext_supp_rates)
1683 rate = elems->ext_supp_rates
1684 [i - elems->supp_rates_len];
1685 own_rate = 5 * (rate & 0x7f);
1686 is_basic = !!(rate & 0x80);
1687
1688 if (is_basic && (rate & 0x7f) == BSS_MEMBERSHIP_SELECTOR_HT_PHY)
1689 continue;
1690
1691 for (j = 0; j < num_rates; j++) {
1692 int brate;
1693 if ((rate_flags & sband->bitrates[j].flags)
1694 != rate_flags)
1695 continue;
1696
1697 brate = DIV_ROUND_UP(sband->bitrates[j].bitrate,
1698 1 << shift);
1699
1700 if (brate == own_rate) {
1701 supp_rates |= BIT(j);
1702 if (basic_rates && is_basic)
1703 *basic_rates |= BIT(j);
1704 }
1705 }
1706 }
1707 return supp_rates;
1708}
1709
1710void ieee80211_stop_device(struct ieee80211_local *local)
1711{
1712 ieee80211_led_radio(local, false);
1713 ieee80211_mod_tpt_led_trig(local, 0, IEEE80211_TPT_LEDTRIG_FL_RADIO);
1714
1715 cancel_work_sync(&local->reconfig_filter);
1716
1717 flush_workqueue(local->workqueue);
1718 drv_stop(local);
1719}
1720
1721static void ieee80211_flush_completed_scan(struct ieee80211_local *local,
1722 bool aborted)
1723{
1724 /* It's possible that we don't handle the scan completion in
1725 * time during suspend, so if it's still marked as completed
1726 * here, queue the work and flush it to clean things up.
1727 * Instead of calling the worker function directly here, we
1728 * really queue it to avoid potential races with other flows
1729 * scheduling the same work.
1730 */
1731 if (test_bit(SCAN_COMPLETED, &local->scanning)) {
1732 /* If coming from reconfiguration failure, abort the scan so
1733 * we don't attempt to continue a partial HW scan - which is
1734 * possible otherwise if (e.g.) the 2.4 GHz portion was the
1735 * completed scan, and a 5 GHz portion is still pending.
1736 */
1737 if (aborted)
1738 set_bit(SCAN_ABORTED, &local->scanning);
1739 ieee80211_queue_delayed_work(&local->hw, &local->scan_work, 0);
1740 flush_delayed_work(&local->scan_work);
1741 }
1742}
1743
1744static void ieee80211_handle_reconfig_failure(struct ieee80211_local *local)
1745{
1746 struct ieee80211_sub_if_data *sdata;
1747 struct ieee80211_chanctx *ctx;
1748
1749 /*
1750 * We get here if during resume the device can't be restarted properly.
1751 * We might also get here if this happens during HW reset, which is a
1752 * slightly different situation and we need to drop all connections in
1753 * the latter case.
1754 *
1755 * Ask cfg80211 to turn off all interfaces, this will result in more
1756 * warnings but at least we'll then get into a clean stopped state.
1757 */
1758
1759 local->resuming = false;
1760 local->suspended = false;
1761 local->in_reconfig = false;
1762
1763 ieee80211_flush_completed_scan(local, true);
1764
1765 /* scheduled scan clearly can't be running any more, but tell
1766 * cfg80211 and clear local state
1767 */
1768 ieee80211_sched_scan_end(local);
1769
1770 list_for_each_entry(sdata, &local->interfaces, list)
1771 sdata->flags &= ~IEEE80211_SDATA_IN_DRIVER;
1772
1773 /* Mark channel contexts as not being in the driver any more to avoid
1774 * removing them from the driver during the shutdown process...
1775 */
1776 mutex_lock(&local->chanctx_mtx);
1777 list_for_each_entry(ctx, &local->chanctx_list, list)
1778 ctx->driver_present = false;
1779 mutex_unlock(&local->chanctx_mtx);
1780
1781 cfg80211_shutdown_all_interfaces(local->hw.wiphy);
1782}
1783
1784static void ieee80211_assign_chanctx(struct ieee80211_local *local,
1785 struct ieee80211_sub_if_data *sdata)
1786{
1787 struct ieee80211_chanctx_conf *conf;
1788 struct ieee80211_chanctx *ctx;
1789
1790 if (!local->use_chanctx)
1791 return;
1792
1793 mutex_lock(&local->chanctx_mtx);
1794 conf = rcu_dereference_protected(sdata->vif.chanctx_conf,
1795 lockdep_is_held(&local->chanctx_mtx));
1796 if (conf) {
1797 ctx = container_of(conf, struct ieee80211_chanctx, conf);
1798 drv_assign_vif_chanctx(local, sdata, ctx);
1799 }
1800 mutex_unlock(&local->chanctx_mtx);
1801}
1802
1803static void ieee80211_reconfig_stations(struct ieee80211_sub_if_data *sdata)
1804{
1805 struct ieee80211_local *local = sdata->local;
1806 struct sta_info *sta;
1807
1808 /* add STAs back */
1809 mutex_lock(&local->sta_mtx);
1810 list_for_each_entry(sta, &local->sta_list, list) {
1811 enum ieee80211_sta_state state;
1812
1813 if (!sta->uploaded || sta->sdata != sdata)
1814 continue;
1815
1816 for (state = IEEE80211_STA_NOTEXIST;
1817 state < sta->sta_state; state++)
1818 WARN_ON(drv_sta_state(local, sta->sdata, sta, state,
1819 state + 1));
1820 }
1821 mutex_unlock(&local->sta_mtx);
1822}
1823
1824static int ieee80211_reconfig_nan(struct ieee80211_sub_if_data *sdata)
1825{
1826 struct cfg80211_nan_func *func, **funcs;
1827 int res, id, i = 0;
1828
1829 res = drv_start_nan(sdata->local, sdata,
1830 &sdata->u.nan.conf);
1831 if (WARN_ON(res))
1832 return res;
1833
1834 funcs = kcalloc(sdata->local->hw.max_nan_de_entries + 1,
1835 sizeof(*funcs),
1836 GFP_KERNEL);
1837 if (!funcs)
1838 return -ENOMEM;
1839
1840 /* Add all the functions:
1841 * This is a little bit ugly. We need to call a potentially sleeping
1842 * callback for each NAN function, so we can't hold the spinlock.
1843 */
1844 spin_lock_bh(&sdata->u.nan.func_lock);
1845
1846 idr_for_each_entry(&sdata->u.nan.function_inst_ids, func, id)
1847 funcs[i++] = func;
1848
1849 spin_unlock_bh(&sdata->u.nan.func_lock);
1850
1851 for (i = 0; funcs[i]; i++) {
1852 res = drv_add_nan_func(sdata->local, sdata, funcs[i]);
1853 if (WARN_ON(res))
1854 ieee80211_nan_func_terminated(&sdata->vif,
1855 funcs[i]->instance_id,
1856 NL80211_NAN_FUNC_TERM_REASON_ERROR,
1857 GFP_KERNEL);
1858 }
1859
1860 kfree(funcs);
1861
1862 return 0;
1863}
1864
1865int ieee80211_reconfig(struct ieee80211_local *local)
1866{
1867 struct ieee80211_hw *hw = &local->hw;
1868 struct ieee80211_sub_if_data *sdata;
1869 struct ieee80211_chanctx *ctx;
1870 struct sta_info *sta;
1871 int res, i;
1872 bool reconfig_due_to_wowlan = false;
1873 struct ieee80211_sub_if_data *sched_scan_sdata;
1874 struct cfg80211_sched_scan_request *sched_scan_req;
1875 bool sched_scan_stopped = false;
1876 bool suspended = local->suspended;
1877
1878 /* nothing to do if HW shouldn't run */
1879 if (!local->open_count)
1880 goto wake_up;
1881
1882#ifdef CONFIG_PM
1883 if (suspended)
1884 local->resuming = true;
1885
1886 if (local->wowlan) {
1887 /*
1888 * In the wowlan case, both mac80211 and the device
1889 * are functional when the resume op is called, so
1890 * clear local->suspended so the device could operate
1891 * normally (e.g. pass rx frames).
1892 */
1893 local->suspended = false;
1894 res = drv_resume(local);
1895 local->wowlan = false;
1896 if (res < 0) {
1897 local->resuming = false;
1898 return res;
1899 }
1900 if (res == 0)
1901 goto wake_up;
1902 WARN_ON(res > 1);
1903 /*
1904 * res is 1, which means the driver requested
1905 * to go through a regular reset on wakeup.
1906 * restore local->suspended in this case.
1907 */
1908 reconfig_due_to_wowlan = true;
1909 local->suspended = true;
1910 }
1911#endif
1912
1913 /*
1914 * In case of hw_restart during suspend (without wowlan),
1915 * cancel restart work, as we are reconfiguring the device
1916 * anyway.
1917 * Note that restart_work is scheduled on a frozen workqueue,
1918 * so we can't deadlock in this case.
1919 */
1920 if (suspended && local->in_reconfig && !reconfig_due_to_wowlan)
1921 cancel_work_sync(&local->restart_work);
1922
1923 local->started = false;
1924
1925 /*
1926 * Upon resume hardware can sometimes be goofy due to
1927 * various platform / driver / bus issues, so restarting
1928 * the device may at times not work immediately. Propagate
1929 * the error.
1930 */
1931 res = drv_start(local);
1932 if (res) {
1933 if (suspended)
1934 WARN(1, "Hardware became unavailable upon resume. This could be a software issue prior to suspend or a hardware issue.\n");
1935 else
1936 WARN(1, "Hardware became unavailable during restart.\n");
1937 ieee80211_handle_reconfig_failure(local);
1938 return res;
1939 }
1940
1941 /* setup fragmentation threshold */
1942 drv_set_frag_threshold(local, hw->wiphy->frag_threshold);
1943
1944 /* setup RTS threshold */
1945 drv_set_rts_threshold(local, hw->wiphy->rts_threshold);
1946
1947 /* reset coverage class */
1948 drv_set_coverage_class(local, hw->wiphy->coverage_class);
1949
1950 ieee80211_led_radio(local, true);
1951 ieee80211_mod_tpt_led_trig(local,
1952 IEEE80211_TPT_LEDTRIG_FL_RADIO, 0);
1953
1954 /* add interfaces */
1955 sdata = rtnl_dereference(local->monitor_sdata);
1956 if (sdata) {
1957 /* in HW restart it exists already */
1958 WARN_ON(local->resuming);
1959 res = drv_add_interface(local, sdata);
1960 if (WARN_ON(res)) {
1961 RCU_INIT_POINTER(local->monitor_sdata, NULL);
1962 synchronize_net();
1963 kfree(sdata);
1964 }
1965 }
1966
1967 list_for_each_entry(sdata, &local->interfaces, list) {
1968 if (sdata->vif.type != NL80211_IFTYPE_AP_VLAN &&
1969 sdata->vif.type != NL80211_IFTYPE_MONITOR &&
1970 ieee80211_sdata_running(sdata)) {
1971 res = drv_add_interface(local, sdata);
1972 if (WARN_ON(res))
1973 break;
1974 }
1975 }
1976
1977 /* If adding any of the interfaces failed above, roll back and
1978 * report failure.
1979 */
1980 if (res) {
1981 list_for_each_entry_continue_reverse(sdata, &local->interfaces,
1982 list)
1983 if (sdata->vif.type != NL80211_IFTYPE_AP_VLAN &&
1984 sdata->vif.type != NL80211_IFTYPE_MONITOR &&
1985 ieee80211_sdata_running(sdata))
1986 drv_remove_interface(local, sdata);
1987 ieee80211_handle_reconfig_failure(local);
1988 return res;
1989 }
1990
1991 /* add channel contexts */
1992 if (local->use_chanctx) {
1993 mutex_lock(&local->chanctx_mtx);
1994 list_for_each_entry(ctx, &local->chanctx_list, list)
1995 if (ctx->replace_state !=
1996 IEEE80211_CHANCTX_REPLACES_OTHER)
1997 WARN_ON(drv_add_chanctx(local, ctx));
1998 mutex_unlock(&local->chanctx_mtx);
1999
2000 sdata = rtnl_dereference(local->monitor_sdata);
2001 if (sdata && ieee80211_sdata_running(sdata))
2002 ieee80211_assign_chanctx(local, sdata);
2003 }
2004
2005 /* reconfigure hardware */
2006 ieee80211_hw_config(local, ~0);
2007
2008 ieee80211_configure_filter(local);
2009
2010 /* Finally also reconfigure all the BSS information */
2011 list_for_each_entry(sdata, &local->interfaces, list) {
2012 u32 changed;
2013
2014 if (!ieee80211_sdata_running(sdata))
2015 continue;
2016
2017 ieee80211_assign_chanctx(local, sdata);
2018
2019 switch (sdata->vif.type) {
2020 case NL80211_IFTYPE_AP_VLAN:
2021 case NL80211_IFTYPE_MONITOR:
2022 break;
2023 case NL80211_IFTYPE_ADHOC:
2024 if (sdata->vif.bss_conf.ibss_joined)
2025 WARN_ON(drv_join_ibss(local, sdata));
2026 /* fall through */
2027 default:
2028 ieee80211_reconfig_stations(sdata);
2029 /* fall through */
2030 case NL80211_IFTYPE_AP: /* AP stations are handled later */
2031 for (i = 0; i < IEEE80211_NUM_ACS; i++)
2032 drv_conf_tx(local, sdata, i,
2033 &sdata->tx_conf[i]);
2034 break;
2035 }
2036
2037 /* common change flags for all interface types */
2038 changed = BSS_CHANGED_ERP_CTS_PROT |
2039 BSS_CHANGED_ERP_PREAMBLE |
2040 BSS_CHANGED_ERP_SLOT |
2041 BSS_CHANGED_HT |
2042 BSS_CHANGED_BASIC_RATES |
2043 BSS_CHANGED_BEACON_INT |
2044 BSS_CHANGED_BSSID |
2045 BSS_CHANGED_CQM |
2046 BSS_CHANGED_QOS |
2047 BSS_CHANGED_IDLE |
2048 BSS_CHANGED_TXPOWER |
2049 BSS_CHANGED_MCAST_RATE;
2050
2051 if (sdata->vif.mu_mimo_owner)
2052 changed |= BSS_CHANGED_MU_GROUPS;
2053
2054 switch (sdata->vif.type) {
2055 case NL80211_IFTYPE_STATION:
2056 changed |= BSS_CHANGED_ASSOC |
2057 BSS_CHANGED_ARP_FILTER |
2058 BSS_CHANGED_PS;
2059
2060 /* Re-send beacon info report to the driver */
2061 if (sdata->u.mgd.have_beacon)
2062 changed |= BSS_CHANGED_BEACON_INFO;
2063
2064 if (sdata->vif.bss_conf.max_idle_period ||
2065 sdata->vif.bss_conf.protected_keep_alive)
2066 changed |= BSS_CHANGED_KEEP_ALIVE;
2067
2068 sdata_lock(sdata);
2069 ieee80211_bss_info_change_notify(sdata, changed);
2070 sdata_unlock(sdata);
2071 break;
2072 case NL80211_IFTYPE_OCB:
2073 changed |= BSS_CHANGED_OCB;
2074 ieee80211_bss_info_change_notify(sdata, changed);
2075 break;
2076 case NL80211_IFTYPE_ADHOC:
2077 changed |= BSS_CHANGED_IBSS;
2078 /* fall through */
2079 case NL80211_IFTYPE_AP:
2080 changed |= BSS_CHANGED_SSID | BSS_CHANGED_P2P_PS;
2081
2082 if (sdata->vif.type == NL80211_IFTYPE_AP) {
2083 changed |= BSS_CHANGED_AP_PROBE_RESP;
2084
2085 if (rcu_access_pointer(sdata->u.ap.beacon))
2086 drv_start_ap(local, sdata);
2087 }
2088
2089 /* fall through */
2090 case NL80211_IFTYPE_MESH_POINT:
2091 if (sdata->vif.bss_conf.enable_beacon) {
2092 changed |= BSS_CHANGED_BEACON |
2093 BSS_CHANGED_BEACON_ENABLED;
2094 ieee80211_bss_info_change_notify(sdata, changed);
2095 }
2096 break;
2097 case NL80211_IFTYPE_NAN:
2098 res = ieee80211_reconfig_nan(sdata);
2099 if (res < 0) {
2100 ieee80211_handle_reconfig_failure(local);
2101 return res;
2102 }
2103 break;
2104 case NL80211_IFTYPE_WDS:
2105 case NL80211_IFTYPE_AP_VLAN:
2106 case NL80211_IFTYPE_MONITOR:
2107 case NL80211_IFTYPE_P2P_DEVICE:
2108 /* nothing to do */
2109 break;
2110 case NL80211_IFTYPE_UNSPECIFIED:
2111 case NUM_NL80211_IFTYPES:
2112 case NL80211_IFTYPE_P2P_CLIENT:
2113 case NL80211_IFTYPE_P2P_GO:
2114 WARN_ON(1);
2115 break;
2116 }
2117 }
2118
2119 ieee80211_recalc_ps(local);
2120
2121 /*
2122 * The sta might be in psm against the ap (e.g. because
2123 * this was the state before a hw restart), so we
2124 * explicitly send a null packet in order to make sure
2125 * it'll sync against the ap (and get out of psm).
2126 */
2127 if (!(local->hw.conf.flags & IEEE80211_CONF_PS)) {
2128 list_for_each_entry(sdata, &local->interfaces, list) {
2129 if (sdata->vif.type != NL80211_IFTYPE_STATION)
2130 continue;
2131 if (!sdata->u.mgd.associated)
2132 continue;
2133
2134 ieee80211_send_nullfunc(local, sdata, false);
2135 }
2136 }
2137
2138 /* APs are now beaconing, add back stations */
2139 mutex_lock(&local->sta_mtx);
2140 list_for_each_entry(sta, &local->sta_list, list) {
2141 enum ieee80211_sta_state state;
2142
2143 if (!sta->uploaded)
2144 continue;
2145
2146 if (sta->sdata->vif.type != NL80211_IFTYPE_AP &&
2147 sta->sdata->vif.type != NL80211_IFTYPE_AP_VLAN)
2148 continue;
2149
2150 for (state = IEEE80211_STA_NOTEXIST;
2151 state < sta->sta_state; state++)
2152 WARN_ON(drv_sta_state(local, sta->sdata, sta, state,
2153 state + 1));
2154 }
2155 mutex_unlock(&local->sta_mtx);
2156
2157 /* add back keys */
2158 list_for_each_entry(sdata, &local->interfaces, list)
2159 ieee80211_reset_crypto_tx_tailroom(sdata);
2160
2161 list_for_each_entry(sdata, &local->interfaces, list)
2162 if (ieee80211_sdata_running(sdata))
2163 ieee80211_enable_keys(sdata);
2164
2165 /* Reconfigure sched scan if it was interrupted by FW restart */
2166 mutex_lock(&local->mtx);
2167 sched_scan_sdata = rcu_dereference_protected(local->sched_scan_sdata,
2168 lockdep_is_held(&local->mtx));
2169 sched_scan_req = rcu_dereference_protected(local->sched_scan_req,
2170 lockdep_is_held(&local->mtx));
2171 if (sched_scan_sdata && sched_scan_req)
2172 /*
2173 * Sched scan stopped, but we don't want to report it. Instead,
2174 * we're trying to reschedule. However, if more than one scan
2175 * plan was set, we cannot reschedule since we don't know which
2176 * scan plan was currently running (and some scan plans may have
2177 * already finished).
2178 */
2179 if (sched_scan_req->n_scan_plans > 1 ||
2180 __ieee80211_request_sched_scan_start(sched_scan_sdata,
2181 sched_scan_req)) {
2182 RCU_INIT_POINTER(local->sched_scan_sdata, NULL);
2183 RCU_INIT_POINTER(local->sched_scan_req, NULL);
2184 sched_scan_stopped = true;
2185 }
2186 mutex_unlock(&local->mtx);
2187
2188 if (sched_scan_stopped)
2189 cfg80211_sched_scan_stopped_rtnl(local->hw.wiphy, 0);
2190
2191 wake_up:
2192
2193 if (local->monitors == local->open_count && local->monitors > 0)
2194 ieee80211_add_virtual_monitor(local);
2195
2196 /*
2197 * Clear the WLAN_STA_BLOCK_BA flag so new aggregation
2198 * sessions can be established after a resume.
2199 *
2200 * Also tear down aggregation sessions since reconfiguring
2201 * them in a hardware restart scenario is not easily done
2202 * right now, and the hardware will have lost information
2203 * about the sessions, but we and the AP still think they
2204 * are active. This is really a workaround though.
2205 */
2206 if (ieee80211_hw_check(hw, AMPDU_AGGREGATION)) {
2207 mutex_lock(&local->sta_mtx);
2208
2209 list_for_each_entry(sta, &local->sta_list, list) {
2210 if (!local->resuming)
2211 ieee80211_sta_tear_down_BA_sessions(
2212 sta, AGG_STOP_LOCAL_REQUEST);
2213 clear_sta_flag(sta, WLAN_STA_BLOCK_BA);
2214 }
2215
2216 mutex_unlock(&local->sta_mtx);
2217 }
2218
2219 if (local->in_reconfig) {
2220 local->in_reconfig = false;
2221 barrier();
2222
2223 /* Restart deferred ROCs */
2224 mutex_lock(&local->mtx);
2225 ieee80211_start_next_roc(local);
2226 mutex_unlock(&local->mtx);
2227
2228 /* Requeue all works */
2229 list_for_each_entry(sdata, &local->interfaces, list)
2230 ieee80211_queue_work(&local->hw, &sdata->work);
2231 }
2232
2233 ieee80211_wake_queues_by_reason(hw, IEEE80211_MAX_QUEUE_MAP,
2234 IEEE80211_QUEUE_STOP_REASON_SUSPEND,
2235 false);
2236
2237 /*
2238 * If this is for hw restart things are still running.
2239 * We may want to change that later, however.
2240 */
2241 if (local->open_count && (!suspended || reconfig_due_to_wowlan))
2242 drv_reconfig_complete(local, IEEE80211_RECONFIG_TYPE_RESTART);
2243
2244 if (!suspended)
2245 return 0;
2246
2247#ifdef CONFIG_PM
2248 /* first set suspended false, then resuming */
2249 local->suspended = false;
2250 mb();
2251 local->resuming = false;
2252
2253 ieee80211_flush_completed_scan(local, false);
2254
2255 if (local->open_count && !reconfig_due_to_wowlan)
2256 drv_reconfig_complete(local, IEEE80211_RECONFIG_TYPE_SUSPEND);
2257
2258 list_for_each_entry(sdata, &local->interfaces, list) {
2259 if (!ieee80211_sdata_running(sdata))
2260 continue;
2261 if (sdata->vif.type == NL80211_IFTYPE_STATION)
2262 ieee80211_sta_restart(sdata);
2263 }
2264
2265 mod_timer(&local->sta_cleanup, jiffies + 1);
2266#else
2267 WARN_ON(1);
2268#endif
2269
2270 return 0;
2271}
2272
2273void ieee80211_resume_disconnect(struct ieee80211_vif *vif)
2274{
2275 struct ieee80211_sub_if_data *sdata;
2276 struct ieee80211_local *local;
2277 struct ieee80211_key *key;
2278
2279 if (WARN_ON(!vif))
2280 return;
2281
2282 sdata = vif_to_sdata(vif);
2283 local = sdata->local;
2284
2285 if (WARN_ON(!local->resuming))
2286 return;
2287
2288 if (WARN_ON(vif->type != NL80211_IFTYPE_STATION))
2289 return;
2290
2291 sdata->flags |= IEEE80211_SDATA_DISCONNECT_RESUME;
2292
2293 mutex_lock(&local->key_mtx);
2294 list_for_each_entry(key, &sdata->key_list, list)
2295 key->flags |= KEY_FLAG_TAINTED;
2296 mutex_unlock(&local->key_mtx);
2297}
2298EXPORT_SYMBOL_GPL(ieee80211_resume_disconnect);
2299
2300void ieee80211_recalc_smps(struct ieee80211_sub_if_data *sdata)
2301{
2302 struct ieee80211_local *local = sdata->local;
2303 struct ieee80211_chanctx_conf *chanctx_conf;
2304 struct ieee80211_chanctx *chanctx;
2305
2306 mutex_lock(&local->chanctx_mtx);
2307
2308 chanctx_conf = rcu_dereference_protected(sdata->vif.chanctx_conf,
2309 lockdep_is_held(&local->chanctx_mtx));
2310
2311 /*
2312 * This function can be called from a work, thus it may be possible
2313 * that the chanctx_conf is removed (due to a disconnection, for
2314 * example).
2315 * So nothing should be done in such case.
2316 */
2317 if (!chanctx_conf)
2318 goto unlock;
2319
2320 chanctx = container_of(chanctx_conf, struct ieee80211_chanctx, conf);
2321 ieee80211_recalc_smps_chanctx(local, chanctx);
2322 unlock:
2323 mutex_unlock(&local->chanctx_mtx);
2324}
2325
2326void ieee80211_recalc_min_chandef(struct ieee80211_sub_if_data *sdata)
2327{
2328 struct ieee80211_local *local = sdata->local;
2329 struct ieee80211_chanctx_conf *chanctx_conf;
2330 struct ieee80211_chanctx *chanctx;
2331
2332 mutex_lock(&local->chanctx_mtx);
2333
2334 chanctx_conf = rcu_dereference_protected(sdata->vif.chanctx_conf,
2335 lockdep_is_held(&local->chanctx_mtx));
2336
2337 if (WARN_ON_ONCE(!chanctx_conf))
2338 goto unlock;
2339
2340 chanctx = container_of(chanctx_conf, struct ieee80211_chanctx, conf);
2341 ieee80211_recalc_chanctx_min_def(local, chanctx);
2342 unlock:
2343 mutex_unlock(&local->chanctx_mtx);
2344}
2345
2346size_t ieee80211_ie_split_vendor(const u8 *ies, size_t ielen, size_t offset)
2347{
2348 size_t pos = offset;
2349
2350 while (pos < ielen && ies[pos] != WLAN_EID_VENDOR_SPECIFIC)
2351 pos += 2 + ies[pos + 1];
2352
2353 return pos;
2354}
2355
2356static void _ieee80211_enable_rssi_reports(struct ieee80211_sub_if_data *sdata,
2357 int rssi_min_thold,
2358 int rssi_max_thold)
2359{
2360 trace_api_enable_rssi_reports(sdata, rssi_min_thold, rssi_max_thold);
2361
2362 if (WARN_ON(sdata->vif.type != NL80211_IFTYPE_STATION))
2363 return;
2364
2365 /*
2366 * Scale up threshold values before storing it, as the RSSI averaging
2367 * algorithm uses a scaled up value as well. Change this scaling
2368 * factor if the RSSI averaging algorithm changes.
2369 */
2370 sdata->u.mgd.rssi_min_thold = rssi_min_thold*16;
2371 sdata->u.mgd.rssi_max_thold = rssi_max_thold*16;
2372}
2373
2374void ieee80211_enable_rssi_reports(struct ieee80211_vif *vif,
2375 int rssi_min_thold,
2376 int rssi_max_thold)
2377{
2378 struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
2379
2380 WARN_ON(rssi_min_thold == rssi_max_thold ||
2381 rssi_min_thold > rssi_max_thold);
2382
2383 _ieee80211_enable_rssi_reports(sdata, rssi_min_thold,
2384 rssi_max_thold);
2385}
2386EXPORT_SYMBOL(ieee80211_enable_rssi_reports);
2387
2388void ieee80211_disable_rssi_reports(struct ieee80211_vif *vif)
2389{
2390 struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
2391
2392 _ieee80211_enable_rssi_reports(sdata, 0, 0);
2393}
2394EXPORT_SYMBOL(ieee80211_disable_rssi_reports);
2395
2396u8 *ieee80211_ie_build_ht_cap(u8 *pos, struct ieee80211_sta_ht_cap *ht_cap,
2397 u16 cap)
2398{
2399 __le16 tmp;
2400
2401 *pos++ = WLAN_EID_HT_CAPABILITY;
2402 *pos++ = sizeof(struct ieee80211_ht_cap);
2403 memset(pos, 0, sizeof(struct ieee80211_ht_cap));
2404
2405 /* capability flags */
2406 tmp = cpu_to_le16(cap);
2407 memcpy(pos, &tmp, sizeof(u16));
2408 pos += sizeof(u16);
2409
2410 /* AMPDU parameters */
2411 *pos++ = ht_cap->ampdu_factor |
2412 (ht_cap->ampdu_density <<
2413 IEEE80211_HT_AMPDU_PARM_DENSITY_SHIFT);
2414
2415 /* MCS set */
2416 memcpy(pos, &ht_cap->mcs, sizeof(ht_cap->mcs));
2417 pos += sizeof(ht_cap->mcs);
2418
2419 /* extended capabilities */
2420 pos += sizeof(__le16);
2421
2422 /* BF capabilities */
2423 pos += sizeof(__le32);
2424
2425 /* antenna selection */
2426 pos += sizeof(u8);
2427
2428 return pos;
2429}
2430
2431u8 *ieee80211_ie_build_vht_cap(u8 *pos, struct ieee80211_sta_vht_cap *vht_cap,
2432 u32 cap)
2433{
2434 __le32 tmp;
2435
2436 *pos++ = WLAN_EID_VHT_CAPABILITY;
2437 *pos++ = sizeof(struct ieee80211_vht_cap);
2438 memset(pos, 0, sizeof(struct ieee80211_vht_cap));
2439
2440 /* capability flags */
2441 tmp = cpu_to_le32(cap);
2442 memcpy(pos, &tmp, sizeof(u32));
2443 pos += sizeof(u32);
2444
2445 /* VHT MCS set */
2446 memcpy(pos, &vht_cap->vht_mcs, sizeof(vht_cap->vht_mcs));
2447 pos += sizeof(vht_cap->vht_mcs);
2448
2449 return pos;
2450}
2451
2452u8 *ieee80211_ie_build_he_cap(u8 *pos,
2453 const struct ieee80211_sta_he_cap *he_cap,
2454 u8 *end)
2455{
2456 u8 n;
2457 u8 ie_len;
2458 u8 *orig_pos = pos;
2459
2460 /* Make sure we have place for the IE */
2461 /*
2462 * TODO: the 1 added is because this temporarily is under the EXTENSION
2463 * IE. Get rid of it when it moves.
2464 */
2465 if (!he_cap)
2466 return orig_pos;
2467
2468 n = ieee80211_he_mcs_nss_size(&he_cap->he_cap_elem);
2469 ie_len = 2 + 1 +
2470 sizeof(he_cap->he_cap_elem) + n +
2471 ieee80211_he_ppe_size(he_cap->ppe_thres[0],
2472 he_cap->he_cap_elem.phy_cap_info);
2473
2474 if ((end - pos) < ie_len)
2475 return orig_pos;
2476
2477 *pos++ = WLAN_EID_EXTENSION;
2478 pos++; /* We'll set the size later below */
2479 *pos++ = WLAN_EID_EXT_HE_CAPABILITY;
2480
2481 /* Fixed data */
2482 memcpy(pos, &he_cap->he_cap_elem, sizeof(he_cap->he_cap_elem));
2483 pos += sizeof(he_cap->he_cap_elem);
2484
2485 memcpy(pos, &he_cap->he_mcs_nss_supp, n);
2486 pos += n;
2487
2488 /* Check if PPE Threshold should be present */
2489 if ((he_cap->he_cap_elem.phy_cap_info[6] &
2490 IEEE80211_HE_PHY_CAP6_PPE_THRESHOLD_PRESENT) == 0)
2491 goto end;
2492
2493 /*
2494 * Calculate how many PPET16/PPET8 pairs are to come. Algorithm:
2495 * (NSS_M1 + 1) x (num of 1 bits in RU_INDEX_BITMASK)
2496 */
2497 n = hweight8(he_cap->ppe_thres[0] &
2498 IEEE80211_PPE_THRES_RU_INDEX_BITMASK_MASK);
2499 n *= (1 + ((he_cap->ppe_thres[0] & IEEE80211_PPE_THRES_NSS_MASK) >>
2500 IEEE80211_PPE_THRES_NSS_POS));
2501
2502 /*
2503 * Each pair is 6 bits, and we need to add the 7 "header" bits to the
2504 * total size.
2505 */
2506 n = (n * IEEE80211_PPE_THRES_INFO_PPET_SIZE * 2) + 7;
2507 n = DIV_ROUND_UP(n, 8);
2508
2509 /* Copy PPE Thresholds */
2510 memcpy(pos, &he_cap->ppe_thres, n);
2511 pos += n;
2512
2513end:
2514 orig_pos[1] = (pos - orig_pos) - 2;
2515 return pos;
2516}
2517
2518u8 *ieee80211_ie_build_ht_oper(u8 *pos, struct ieee80211_sta_ht_cap *ht_cap,
2519 const struct cfg80211_chan_def *chandef,
2520 u16 prot_mode, bool rifs_mode)
2521{
2522 struct ieee80211_ht_operation *ht_oper;
2523 /* Build HT Information */
2524 *pos++ = WLAN_EID_HT_OPERATION;
2525 *pos++ = sizeof(struct ieee80211_ht_operation);
2526 ht_oper = (struct ieee80211_ht_operation *)pos;
2527 ht_oper->primary_chan = ieee80211_frequency_to_channel(
2528 chandef->chan->center_freq);
2529 switch (chandef->width) {
2530 case NL80211_CHAN_WIDTH_160:
2531 case NL80211_CHAN_WIDTH_80P80:
2532 case NL80211_CHAN_WIDTH_80:
2533 case NL80211_CHAN_WIDTH_40:
2534 if (chandef->center_freq1 > chandef->chan->center_freq)
2535 ht_oper->ht_param = IEEE80211_HT_PARAM_CHA_SEC_ABOVE;
2536 else
2537 ht_oper->ht_param = IEEE80211_HT_PARAM_CHA_SEC_BELOW;
2538 break;
2539 default:
2540 ht_oper->ht_param = IEEE80211_HT_PARAM_CHA_SEC_NONE;
2541 break;
2542 }
2543 if (ht_cap->cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40 &&
2544 chandef->width != NL80211_CHAN_WIDTH_20_NOHT &&
2545 chandef->width != NL80211_CHAN_WIDTH_20)
2546 ht_oper->ht_param |= IEEE80211_HT_PARAM_CHAN_WIDTH_ANY;
2547
2548 if (rifs_mode)
2549 ht_oper->ht_param |= IEEE80211_HT_PARAM_RIFS_MODE;
2550
2551 ht_oper->operation_mode = cpu_to_le16(prot_mode);
2552 ht_oper->stbc_param = 0x0000;
2553
2554 /* It seems that Basic MCS set and Supported MCS set
2555 are identical for the first 10 bytes */
2556 memset(&ht_oper->basic_set, 0, 16);
2557 memcpy(&ht_oper->basic_set, &ht_cap->mcs, 10);
2558
2559 return pos + sizeof(struct ieee80211_ht_operation);
2560}
2561
2562void ieee80211_ie_build_wide_bw_cs(u8 *pos,
2563 const struct cfg80211_chan_def *chandef)
2564{
2565 *pos++ = WLAN_EID_WIDE_BW_CHANNEL_SWITCH; /* EID */
2566 *pos++ = 3; /* IE length */
2567 /* New channel width */
2568 switch (chandef->width) {
2569 case NL80211_CHAN_WIDTH_80:
2570 *pos++ = IEEE80211_VHT_CHANWIDTH_80MHZ;
2571 break;
2572 case NL80211_CHAN_WIDTH_160:
2573 *pos++ = IEEE80211_VHT_CHANWIDTH_160MHZ;
2574 break;
2575 case NL80211_CHAN_WIDTH_80P80:
2576 *pos++ = IEEE80211_VHT_CHANWIDTH_80P80MHZ;
2577 break;
2578 default:
2579 *pos++ = IEEE80211_VHT_CHANWIDTH_USE_HT;
2580 }
2581
2582 /* new center frequency segment 0 */
2583 *pos++ = ieee80211_frequency_to_channel(chandef->center_freq1);
2584 /* new center frequency segment 1 */
2585 if (chandef->center_freq2)
2586 *pos++ = ieee80211_frequency_to_channel(chandef->center_freq2);
2587 else
2588 *pos++ = 0;
2589}
2590
2591u8 *ieee80211_ie_build_vht_oper(u8 *pos, struct ieee80211_sta_vht_cap *vht_cap,
2592 const struct cfg80211_chan_def *chandef)
2593{
2594 struct ieee80211_vht_operation *vht_oper;
2595
2596 *pos++ = WLAN_EID_VHT_OPERATION;
2597 *pos++ = sizeof(struct ieee80211_vht_operation);
2598 vht_oper = (struct ieee80211_vht_operation *)pos;
2599 vht_oper->center_freq_seg0_idx = ieee80211_frequency_to_channel(
2600 chandef->center_freq1);
2601 if (chandef->center_freq2)
2602 vht_oper->center_freq_seg1_idx =
2603 ieee80211_frequency_to_channel(chandef->center_freq2);
2604 else
2605 vht_oper->center_freq_seg1_idx = 0x00;
2606
2607 switch (chandef->width) {
2608 case NL80211_CHAN_WIDTH_160:
2609 /*
2610 * Convert 160 MHz channel width to new style as interop
2611 * workaround.
2612 */
2613 vht_oper->chan_width = IEEE80211_VHT_CHANWIDTH_80MHZ;
2614 vht_oper->center_freq_seg1_idx = vht_oper->center_freq_seg0_idx;
2615 if (chandef->chan->center_freq < chandef->center_freq1)
2616 vht_oper->center_freq_seg0_idx -= 8;
2617 else
2618 vht_oper->center_freq_seg0_idx += 8;
2619 break;
2620 case NL80211_CHAN_WIDTH_80P80:
2621 /*
2622 * Convert 80+80 MHz channel width to new style as interop
2623 * workaround.
2624 */
2625 vht_oper->chan_width = IEEE80211_VHT_CHANWIDTH_80MHZ;
2626 break;
2627 case NL80211_CHAN_WIDTH_80:
2628 vht_oper->chan_width = IEEE80211_VHT_CHANWIDTH_80MHZ;
2629 break;
2630 default:
2631 vht_oper->chan_width = IEEE80211_VHT_CHANWIDTH_USE_HT;
2632 break;
2633 }
2634
2635 /* don't require special VHT peer rates */
2636 vht_oper->basic_mcs_set = cpu_to_le16(0xffff);
2637
2638 return pos + sizeof(struct ieee80211_vht_operation);
2639}
2640
2641bool ieee80211_chandef_ht_oper(const struct ieee80211_ht_operation *ht_oper,
2642 struct cfg80211_chan_def *chandef)
2643{
2644 enum nl80211_channel_type channel_type;
2645
2646 if (!ht_oper)
2647 return false;
2648
2649 switch (ht_oper->ht_param & IEEE80211_HT_PARAM_CHA_SEC_OFFSET) {
2650 case IEEE80211_HT_PARAM_CHA_SEC_NONE:
2651 channel_type = NL80211_CHAN_HT20;
2652 break;
2653 case IEEE80211_HT_PARAM_CHA_SEC_ABOVE:
2654 channel_type = NL80211_CHAN_HT40PLUS;
2655 break;
2656 case IEEE80211_HT_PARAM_CHA_SEC_BELOW:
2657 channel_type = NL80211_CHAN_HT40MINUS;
2658 break;
2659 default:
2660 channel_type = NL80211_CHAN_NO_HT;
2661 return false;
2662 }
2663
2664 cfg80211_chandef_create(chandef, chandef->chan, channel_type);
2665 return true;
2666}
2667
2668bool ieee80211_chandef_vht_oper(const struct ieee80211_vht_operation *oper,
2669 struct cfg80211_chan_def *chandef)
2670{
2671 struct cfg80211_chan_def new = *chandef;
2672 int cf1, cf2;
2673
2674 if (!oper)
2675 return false;
2676
2677 cf1 = ieee80211_channel_to_frequency(oper->center_freq_seg0_idx,
2678 chandef->chan->band);
2679 cf2 = ieee80211_channel_to_frequency(oper->center_freq_seg1_idx,
2680 chandef->chan->band);
2681
2682 switch (oper->chan_width) {
2683 case IEEE80211_VHT_CHANWIDTH_USE_HT:
2684 break;
2685 case IEEE80211_VHT_CHANWIDTH_80MHZ:
2686 new.width = NL80211_CHAN_WIDTH_80;
2687 new.center_freq1 = cf1;
2688 /* If needed, adjust based on the newer interop workaround. */
2689 if (oper->center_freq_seg1_idx) {
2690 unsigned int diff;
2691
2692 diff = abs(oper->center_freq_seg1_idx -
2693 oper->center_freq_seg0_idx);
2694 if (diff == 8) {
2695 new.width = NL80211_CHAN_WIDTH_160;
2696 new.center_freq1 = cf2;
2697 } else if (diff > 8) {
2698 new.width = NL80211_CHAN_WIDTH_80P80;
2699 new.center_freq2 = cf2;
2700 }
2701 }
2702 break;
2703 case IEEE80211_VHT_CHANWIDTH_160MHZ:
2704 new.width = NL80211_CHAN_WIDTH_160;
2705 new.center_freq1 = cf1;
2706 break;
2707 case IEEE80211_VHT_CHANWIDTH_80P80MHZ:
2708 new.width = NL80211_CHAN_WIDTH_80P80;
2709 new.center_freq1 = cf1;
2710 new.center_freq2 = cf2;
2711 break;
2712 default:
2713 return false;
2714 }
2715
2716 if (!cfg80211_chandef_valid(&new))
2717 return false;
2718
2719 *chandef = new;
2720 return true;
2721}
2722
2723int ieee80211_parse_bitrates(struct cfg80211_chan_def *chandef,
2724 const struct ieee80211_supported_band *sband,
2725 const u8 *srates, int srates_len, u32 *rates)
2726{
2727 u32 rate_flags = ieee80211_chandef_rate_flags(chandef);
2728 int shift = ieee80211_chandef_get_shift(chandef);
2729 struct ieee80211_rate *br;
2730 int brate, rate, i, j, count = 0;
2731
2732 *rates = 0;
2733
2734 for (i = 0; i < srates_len; i++) {
2735 rate = srates[i] & 0x7f;
2736
2737 for (j = 0; j < sband->n_bitrates; j++) {
2738 br = &sband->bitrates[j];
2739 if ((rate_flags & br->flags) != rate_flags)
2740 continue;
2741
2742 brate = DIV_ROUND_UP(br->bitrate, (1 << shift) * 5);
2743 if (brate == rate) {
2744 *rates |= BIT(j);
2745 count++;
2746 break;
2747 }
2748 }
2749 }
2750 return count;
2751}
2752
2753int ieee80211_add_srates_ie(struct ieee80211_sub_if_data *sdata,
2754 struct sk_buff *skb, bool need_basic,
2755 enum nl80211_band band)
2756{
2757 struct ieee80211_local *local = sdata->local;
2758 struct ieee80211_supported_band *sband;
2759 int rate, shift;
2760 u8 i, rates, *pos;
2761 u32 basic_rates = sdata->vif.bss_conf.basic_rates;
2762 u32 rate_flags;
2763
2764 shift = ieee80211_vif_get_shift(&sdata->vif);
2765 rate_flags = ieee80211_chandef_rate_flags(&sdata->vif.bss_conf.chandef);
2766 sband = local->hw.wiphy->bands[band];
2767 rates = 0;
2768 for (i = 0; i < sband->n_bitrates; i++) {
2769 if ((rate_flags & sband->bitrates[i].flags) != rate_flags)
2770 continue;
2771 rates++;
2772 }
2773 if (rates > 8)
2774 rates = 8;
2775
2776 if (skb_tailroom(skb) < rates + 2)
2777 return -ENOMEM;
2778
2779 pos = skb_put(skb, rates + 2);
2780 *pos++ = WLAN_EID_SUPP_RATES;
2781 *pos++ = rates;
2782 for (i = 0; i < rates; i++) {
2783 u8 basic = 0;
2784 if ((rate_flags & sband->bitrates[i].flags) != rate_flags)
2785 continue;
2786
2787 if (need_basic && basic_rates & BIT(i))
2788 basic = 0x80;
2789 rate = DIV_ROUND_UP(sband->bitrates[i].bitrate,
2790 5 * (1 << shift));
2791 *pos++ = basic | (u8) rate;
2792 }
2793
2794 return 0;
2795}
2796
2797int ieee80211_add_ext_srates_ie(struct ieee80211_sub_if_data *sdata,
2798 struct sk_buff *skb, bool need_basic,
2799 enum nl80211_band band)
2800{
2801 struct ieee80211_local *local = sdata->local;
2802 struct ieee80211_supported_band *sband;
2803 int rate, shift;
2804 u8 i, exrates, *pos;
2805 u32 basic_rates = sdata->vif.bss_conf.basic_rates;
2806 u32 rate_flags;
2807
2808 rate_flags = ieee80211_chandef_rate_flags(&sdata->vif.bss_conf.chandef);
2809 shift = ieee80211_vif_get_shift(&sdata->vif);
2810
2811 sband = local->hw.wiphy->bands[band];
2812 exrates = 0;
2813 for (i = 0; i < sband->n_bitrates; i++) {
2814 if ((rate_flags & sband->bitrates[i].flags) != rate_flags)
2815 continue;
2816 exrates++;
2817 }
2818
2819 if (exrates > 8)
2820 exrates -= 8;
2821 else
2822 exrates = 0;
2823
2824 if (skb_tailroom(skb) < exrates + 2)
2825 return -ENOMEM;
2826
2827 if (exrates) {
2828 pos = skb_put(skb, exrates + 2);
2829 *pos++ = WLAN_EID_EXT_SUPP_RATES;
2830 *pos++ = exrates;
2831 for (i = 8; i < sband->n_bitrates; i++) {
2832 u8 basic = 0;
2833 if ((rate_flags & sband->bitrates[i].flags)
2834 != rate_flags)
2835 continue;
2836 if (need_basic && basic_rates & BIT(i))
2837 basic = 0x80;
2838 rate = DIV_ROUND_UP(sband->bitrates[i].bitrate,
2839 5 * (1 << shift));
2840 *pos++ = basic | (u8) rate;
2841 }
2842 }
2843 return 0;
2844}
2845
2846int ieee80211_ave_rssi(struct ieee80211_vif *vif)
2847{
2848 struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
2849 struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
2850
2851 if (WARN_ON_ONCE(sdata->vif.type != NL80211_IFTYPE_STATION)) {
2852 /* non-managed type inferfaces */
2853 return 0;
2854 }
2855 return -ewma_beacon_signal_read(&ifmgd->ave_beacon_signal);
2856}
2857EXPORT_SYMBOL_GPL(ieee80211_ave_rssi);
2858
2859u8 ieee80211_mcs_to_chains(const struct ieee80211_mcs_info *mcs)
2860{
2861 if (!mcs)
2862 return 1;
2863
2864 /* TODO: consider rx_highest */
2865
2866 if (mcs->rx_mask[3])
2867 return 4;
2868 if (mcs->rx_mask[2])
2869 return 3;
2870 if (mcs->rx_mask[1])
2871 return 2;
2872 return 1;
2873}
2874
2875/**
2876 * ieee80211_calculate_rx_timestamp - calculate timestamp in frame
2877 * @local: mac80211 hw info struct
2878 * @status: RX status
2879 * @mpdu_len: total MPDU length (including FCS)
2880 * @mpdu_offset: offset into MPDU to calculate timestamp at
2881 *
2882 * This function calculates the RX timestamp at the given MPDU offset, taking
2883 * into account what the RX timestamp was. An offset of 0 will just normalize
2884 * the timestamp to TSF at beginning of MPDU reception.
2885 */
2886u64 ieee80211_calculate_rx_timestamp(struct ieee80211_local *local,
2887 struct ieee80211_rx_status *status,
2888 unsigned int mpdu_len,
2889 unsigned int mpdu_offset)
2890{
2891 u64 ts = status->mactime;
2892 struct rate_info ri;
2893 u16 rate;
2894
2895 if (WARN_ON(!ieee80211_have_rx_timestamp(status)))
2896 return 0;
2897
2898 memset(&ri, 0, sizeof(ri));
2899
2900 ri.bw = status->bw;
2901
2902 /* Fill cfg80211 rate info */
2903 switch (status->encoding) {
2904 case RX_ENC_HT:
2905 ri.mcs = status->rate_idx;
2906 ri.flags |= RATE_INFO_FLAGS_MCS;
2907 if (status->enc_flags & RX_ENC_FLAG_SHORT_GI)
2908 ri.flags |= RATE_INFO_FLAGS_SHORT_GI;
2909 break;
2910 case RX_ENC_VHT:
2911 ri.flags |= RATE_INFO_FLAGS_VHT_MCS;
2912 ri.mcs = status->rate_idx;
2913 ri.nss = status->nss;
2914 if (status->enc_flags & RX_ENC_FLAG_SHORT_GI)
2915 ri.flags |= RATE_INFO_FLAGS_SHORT_GI;
2916 break;
2917 default:
2918 WARN_ON(1);
2919 /* fall through */
2920 case RX_ENC_LEGACY: {
2921 struct ieee80211_supported_band *sband;
2922 int shift = 0;
2923 int bitrate;
2924
2925 switch (status->bw) {
2926 case RATE_INFO_BW_10:
2927 shift = 1;
2928 break;
2929 case RATE_INFO_BW_5:
2930 shift = 2;
2931 break;
2932 }
2933
2934 sband = local->hw.wiphy->bands[status->band];
2935 bitrate = sband->bitrates[status->rate_idx].bitrate;
2936 ri.legacy = DIV_ROUND_UP(bitrate, (1 << shift));
2937
2938 if (status->flag & RX_FLAG_MACTIME_PLCP_START) {
2939 /* TODO: handle HT/VHT preambles */
2940 if (status->band == NL80211_BAND_5GHZ) {
2941 ts += 20 << shift;
2942 mpdu_offset += 2;
2943 } else if (status->enc_flags & RX_ENC_FLAG_SHORTPRE) {
2944 ts += 96;
2945 } else {
2946 ts += 192;
2947 }
2948 }
2949 break;
2950 }
2951 }
2952
2953 rate = cfg80211_calculate_bitrate(&ri);
2954 if (WARN_ONCE(!rate,
2955 "Invalid bitrate: flags=0x%llx, idx=%d, vht_nss=%d\n",
2956 (unsigned long long)status->flag, status->rate_idx,
2957 status->nss))
2958 return 0;
2959
2960 /* rewind from end of MPDU */
2961 if (status->flag & RX_FLAG_MACTIME_END)
2962 ts -= mpdu_len * 8 * 10 / rate;
2963
2964 ts += mpdu_offset * 8 * 10 / rate;
2965
2966 return ts;
2967}
2968
2969void ieee80211_dfs_cac_cancel(struct ieee80211_local *local)
2970{
2971 struct ieee80211_sub_if_data *sdata;
2972 struct cfg80211_chan_def chandef;
2973
2974 /* for interface list, to avoid linking iflist_mtx and chanctx_mtx */
2975 ASSERT_RTNL();
2976
2977 mutex_lock(&local->mtx);
2978 list_for_each_entry(sdata, &local->interfaces, list) {
2979 /* it might be waiting for the local->mtx, but then
2980 * by the time it gets it, sdata->wdev.cac_started
2981 * will no longer be true
2982 */
2983 cancel_delayed_work(&sdata->dfs_cac_timer_work);
2984
2985 if (sdata->wdev.cac_started) {
2986 chandef = sdata->vif.bss_conf.chandef;
2987 ieee80211_vif_release_channel(sdata);
2988 cfg80211_cac_event(sdata->dev,
2989 &chandef,
2990 NL80211_RADAR_CAC_ABORTED,
2991 GFP_KERNEL);
2992 }
2993 }
2994 mutex_unlock(&local->mtx);
2995}
2996
2997void ieee80211_dfs_radar_detected_work(struct work_struct *work)
2998{
2999 struct ieee80211_local *local =
3000 container_of(work, struct ieee80211_local, radar_detected_work);
3001 struct cfg80211_chan_def chandef = local->hw.conf.chandef;
3002 struct ieee80211_chanctx *ctx;
3003 int num_chanctx = 0;
3004
3005 mutex_lock(&local->chanctx_mtx);
3006 list_for_each_entry(ctx, &local->chanctx_list, list) {
3007 if (ctx->replace_state == IEEE80211_CHANCTX_REPLACES_OTHER)
3008 continue;
3009
3010 num_chanctx++;
3011 chandef = ctx->conf.def;
3012 }
3013 mutex_unlock(&local->chanctx_mtx);
3014
3015 rtnl_lock();
3016 ieee80211_dfs_cac_cancel(local);
3017 rtnl_unlock();
3018
3019 if (num_chanctx > 1)
3020 /* XXX: multi-channel is not supported yet */
3021 WARN_ON(1);
3022 else
3023 cfg80211_radar_event(local->hw.wiphy, &chandef, GFP_KERNEL);
3024}
3025
3026void ieee80211_radar_detected(struct ieee80211_hw *hw)
3027{
3028 struct ieee80211_local *local = hw_to_local(hw);
3029
3030 trace_api_radar_detected(local);
3031
3032 schedule_work(&local->radar_detected_work);
3033}
3034EXPORT_SYMBOL(ieee80211_radar_detected);
3035
3036u32 ieee80211_chandef_downgrade(struct cfg80211_chan_def *c)
3037{
3038 u32 ret;
3039 int tmp;
3040
3041 switch (c->width) {
3042 case NL80211_CHAN_WIDTH_20:
3043 c->width = NL80211_CHAN_WIDTH_20_NOHT;
3044 ret = IEEE80211_STA_DISABLE_HT | IEEE80211_STA_DISABLE_VHT;
3045 break;
3046 case NL80211_CHAN_WIDTH_40:
3047 c->width = NL80211_CHAN_WIDTH_20;
3048 c->center_freq1 = c->chan->center_freq;
3049 ret = IEEE80211_STA_DISABLE_40MHZ |
3050 IEEE80211_STA_DISABLE_VHT;
3051 break;
3052 case NL80211_CHAN_WIDTH_80:
3053 tmp = (30 + c->chan->center_freq - c->center_freq1)/20;
3054 /* n_P40 */
3055 tmp /= 2;
3056 /* freq_P40 */
3057 c->center_freq1 = c->center_freq1 - 20 + 40 * tmp;
3058 c->width = NL80211_CHAN_WIDTH_40;
3059 ret = IEEE80211_STA_DISABLE_VHT;
3060 break;
3061 case NL80211_CHAN_WIDTH_80P80:
3062 c->center_freq2 = 0;
3063 c->width = NL80211_CHAN_WIDTH_80;
3064 ret = IEEE80211_STA_DISABLE_80P80MHZ |
3065 IEEE80211_STA_DISABLE_160MHZ;
3066 break;
3067 case NL80211_CHAN_WIDTH_160:
3068 /* n_P20 */
3069 tmp = (70 + c->chan->center_freq - c->center_freq1)/20;
3070 /* n_P80 */
3071 tmp /= 4;
3072 c->center_freq1 = c->center_freq1 - 40 + 80 * tmp;
3073 c->width = NL80211_CHAN_WIDTH_80;
3074 ret = IEEE80211_STA_DISABLE_80P80MHZ |
3075 IEEE80211_STA_DISABLE_160MHZ;
3076 break;
3077 default:
3078 case NL80211_CHAN_WIDTH_20_NOHT:
3079 WARN_ON_ONCE(1);
3080 c->width = NL80211_CHAN_WIDTH_20_NOHT;
3081 ret = IEEE80211_STA_DISABLE_HT | IEEE80211_STA_DISABLE_VHT;
3082 break;
3083 case NL80211_CHAN_WIDTH_5:
3084 case NL80211_CHAN_WIDTH_10:
3085 WARN_ON_ONCE(1);
3086 /* keep c->width */
3087 ret = IEEE80211_STA_DISABLE_HT | IEEE80211_STA_DISABLE_VHT;
3088 break;
3089 }
3090
3091 WARN_ON_ONCE(!cfg80211_chandef_valid(c));
3092
3093 return ret;
3094}
3095
3096/*
3097 * Returns true if smps_mode_new is strictly more restrictive than
3098 * smps_mode_old.
3099 */
3100bool ieee80211_smps_is_restrictive(enum ieee80211_smps_mode smps_mode_old,
3101 enum ieee80211_smps_mode smps_mode_new)
3102{
3103 if (WARN_ON_ONCE(smps_mode_old == IEEE80211_SMPS_AUTOMATIC ||
3104 smps_mode_new == IEEE80211_SMPS_AUTOMATIC))
3105 return false;
3106
3107 switch (smps_mode_old) {
3108 case IEEE80211_SMPS_STATIC:
3109 return false;
3110 case IEEE80211_SMPS_DYNAMIC:
3111 return smps_mode_new == IEEE80211_SMPS_STATIC;
3112 case IEEE80211_SMPS_OFF:
3113 return smps_mode_new != IEEE80211_SMPS_OFF;
3114 default:
3115 WARN_ON(1);
3116 }
3117
3118 return false;
3119}
3120
3121int ieee80211_send_action_csa(struct ieee80211_sub_if_data *sdata,
3122 struct cfg80211_csa_settings *csa_settings)
3123{
3124 struct sk_buff *skb;
3125 struct ieee80211_mgmt *mgmt;
3126 struct ieee80211_local *local = sdata->local;
3127 int freq;
3128 int hdr_len = offsetofend(struct ieee80211_mgmt,
3129 u.action.u.chan_switch);
3130 u8 *pos;
3131
3132 if (sdata->vif.type != NL80211_IFTYPE_ADHOC &&
3133 sdata->vif.type != NL80211_IFTYPE_MESH_POINT)
3134 return -EOPNOTSUPP;
3135
3136 skb = dev_alloc_skb(local->tx_headroom + hdr_len +
3137 5 + /* channel switch announcement element */
3138 3 + /* secondary channel offset element */
3139 5 + /* wide bandwidth channel switch announcement */
3140 8); /* mesh channel switch parameters element */
3141 if (!skb)
3142 return -ENOMEM;
3143
3144 skb_reserve(skb, local->tx_headroom);
3145 mgmt = skb_put_zero(skb, hdr_len);
3146 mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
3147 IEEE80211_STYPE_ACTION);
3148
3149 eth_broadcast_addr(mgmt->da);
3150 memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
3151 if (ieee80211_vif_is_mesh(&sdata->vif)) {
3152 memcpy(mgmt->bssid, sdata->vif.addr, ETH_ALEN);
3153 } else {
3154 struct ieee80211_if_ibss *ifibss = &sdata->u.ibss;
3155 memcpy(mgmt->bssid, ifibss->bssid, ETH_ALEN);
3156 }
3157 mgmt->u.action.category = WLAN_CATEGORY_SPECTRUM_MGMT;
3158 mgmt->u.action.u.chan_switch.action_code = WLAN_ACTION_SPCT_CHL_SWITCH;
3159 pos = skb_put(skb, 5);
3160 *pos++ = WLAN_EID_CHANNEL_SWITCH; /* EID */
3161 *pos++ = 3; /* IE length */
3162 *pos++ = csa_settings->block_tx ? 1 : 0; /* CSA mode */
3163 freq = csa_settings->chandef.chan->center_freq;
3164 *pos++ = ieee80211_frequency_to_channel(freq); /* channel */
3165 *pos++ = csa_settings->count; /* count */
3166
3167 if (csa_settings->chandef.width == NL80211_CHAN_WIDTH_40) {
3168 enum nl80211_channel_type ch_type;
3169
3170 skb_put(skb, 3);
3171 *pos++ = WLAN_EID_SECONDARY_CHANNEL_OFFSET; /* EID */
3172 *pos++ = 1; /* IE length */
3173 ch_type = cfg80211_get_chandef_type(&csa_settings->chandef);
3174 if (ch_type == NL80211_CHAN_HT40PLUS)
3175 *pos++ = IEEE80211_HT_PARAM_CHA_SEC_ABOVE;
3176 else
3177 *pos++ = IEEE80211_HT_PARAM_CHA_SEC_BELOW;
3178 }
3179
3180 if (ieee80211_vif_is_mesh(&sdata->vif)) {
3181 struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
3182
3183 skb_put(skb, 8);
3184 *pos++ = WLAN_EID_CHAN_SWITCH_PARAM; /* EID */
3185 *pos++ = 6; /* IE length */
3186 *pos++ = sdata->u.mesh.mshcfg.dot11MeshTTL; /* Mesh TTL */
3187 *pos = 0x00; /* Mesh Flag: Tx Restrict, Initiator, Reason */
3188 *pos |= WLAN_EID_CHAN_SWITCH_PARAM_INITIATOR;
3189 *pos++ |= csa_settings->block_tx ?
3190 WLAN_EID_CHAN_SWITCH_PARAM_TX_RESTRICT : 0x00;
3191 put_unaligned_le16(WLAN_REASON_MESH_CHAN, pos); /* Reason Cd */
3192 pos += 2;
3193 put_unaligned_le16(ifmsh->pre_value, pos);/* Precedence Value */
3194 pos += 2;
3195 }
3196
3197 if (csa_settings->chandef.width == NL80211_CHAN_WIDTH_80 ||
3198 csa_settings->chandef.width == NL80211_CHAN_WIDTH_80P80 ||
3199 csa_settings->chandef.width == NL80211_CHAN_WIDTH_160) {
3200 skb_put(skb, 5);
3201 ieee80211_ie_build_wide_bw_cs(pos, &csa_settings->chandef);
3202 }
3203
3204 ieee80211_tx_skb(sdata, skb);
3205 return 0;
3206}
3207
3208bool ieee80211_cs_valid(const struct ieee80211_cipher_scheme *cs)
3209{
3210 return !(cs == NULL || cs->cipher == 0 ||
3211 cs->hdr_len < cs->pn_len + cs->pn_off ||
3212 cs->hdr_len <= cs->key_idx_off ||
3213 cs->key_idx_shift > 7 ||
3214 cs->key_idx_mask == 0);
3215}
3216
3217bool ieee80211_cs_list_valid(const struct ieee80211_cipher_scheme *cs, int n)
3218{
3219 int i;
3220
3221 /* Ensure we have enough iftype bitmap space for all iftype values */
3222 WARN_ON((NUM_NL80211_IFTYPES / 8 + 1) > sizeof(cs[0].iftype));
3223
3224 for (i = 0; i < n; i++)
3225 if (!ieee80211_cs_valid(&cs[i]))
3226 return false;
3227
3228 return true;
3229}
3230
3231const struct ieee80211_cipher_scheme *
3232ieee80211_cs_get(struct ieee80211_local *local, u32 cipher,
3233 enum nl80211_iftype iftype)
3234{
3235 const struct ieee80211_cipher_scheme *l = local->hw.cipher_schemes;
3236 int n = local->hw.n_cipher_schemes;
3237 int i;
3238 const struct ieee80211_cipher_scheme *cs = NULL;
3239
3240 for (i = 0; i < n; i++) {
3241 if (l[i].cipher == cipher) {
3242 cs = &l[i];
3243 break;
3244 }
3245 }
3246
3247 if (!cs || !(cs->iftype & BIT(iftype)))
3248 return NULL;
3249
3250 return cs;
3251}
3252
3253int ieee80211_cs_headroom(struct ieee80211_local *local,
3254 struct cfg80211_crypto_settings *crypto,
3255 enum nl80211_iftype iftype)
3256{
3257 const struct ieee80211_cipher_scheme *cs;
3258 int headroom = IEEE80211_ENCRYPT_HEADROOM;
3259 int i;
3260
3261 for (i = 0; i < crypto->n_ciphers_pairwise; i++) {
3262 cs = ieee80211_cs_get(local, crypto->ciphers_pairwise[i],
3263 iftype);
3264
3265 if (cs && headroom < cs->hdr_len)
3266 headroom = cs->hdr_len;
3267 }
3268
3269 cs = ieee80211_cs_get(local, crypto->cipher_group, iftype);
3270 if (cs && headroom < cs->hdr_len)
3271 headroom = cs->hdr_len;
3272
3273 return headroom;
3274}
3275
3276static bool
3277ieee80211_extend_noa_desc(struct ieee80211_noa_data *data, u32 tsf, int i)
3278{
3279 s32 end = data->desc[i].start + data->desc[i].duration - (tsf + 1);
3280 int skip;
3281
3282 if (end > 0)
3283 return false;
3284
3285 /* One shot NOA */
3286 if (data->count[i] == 1)
3287 return false;
3288
3289 if (data->desc[i].interval == 0)
3290 return false;
3291
3292 /* End time is in the past, check for repetitions */
3293 skip = DIV_ROUND_UP(-end, data->desc[i].interval);
3294 if (data->count[i] < 255) {
3295 if (data->count[i] <= skip) {
3296 data->count[i] = 0;
3297 return false;
3298 }
3299
3300 data->count[i] -= skip;
3301 }
3302
3303 data->desc[i].start += skip * data->desc[i].interval;
3304
3305 return true;
3306}
3307
3308static bool
3309ieee80211_extend_absent_time(struct ieee80211_noa_data *data, u32 tsf,
3310 s32 *offset)
3311{
3312 bool ret = false;
3313 int i;
3314
3315 for (i = 0; i < IEEE80211_P2P_NOA_DESC_MAX; i++) {
3316 s32 cur;
3317
3318 if (!data->count[i])
3319 continue;
3320
3321 if (ieee80211_extend_noa_desc(data, tsf + *offset, i))
3322 ret = true;
3323
3324 cur = data->desc[i].start - tsf;
3325 if (cur > *offset)
3326 continue;
3327
3328 cur = data->desc[i].start + data->desc[i].duration - tsf;
3329 if (cur > *offset)
3330 *offset = cur;
3331 }
3332
3333 return ret;
3334}
3335
3336static u32
3337ieee80211_get_noa_absent_time(struct ieee80211_noa_data *data, u32 tsf)
3338{
3339 s32 offset = 0;
3340 int tries = 0;
3341 /*
3342 * arbitrary limit, used to avoid infinite loops when combined NoA
3343 * descriptors cover the full time period.
3344 */
3345 int max_tries = 5;
3346
3347 ieee80211_extend_absent_time(data, tsf, &offset);
3348 do {
3349 if (!ieee80211_extend_absent_time(data, tsf, &offset))
3350 break;
3351
3352 tries++;
3353 } while (tries < max_tries);
3354
3355 return offset;
3356}
3357
3358void ieee80211_update_p2p_noa(struct ieee80211_noa_data *data, u32 tsf)
3359{
3360 u32 next_offset = BIT(31) - 1;
3361 int i;
3362
3363 data->absent = 0;
3364 data->has_next_tsf = false;
3365 for (i = 0; i < IEEE80211_P2P_NOA_DESC_MAX; i++) {
3366 s32 start;
3367
3368 if (!data->count[i])
3369 continue;
3370
3371 ieee80211_extend_noa_desc(data, tsf, i);
3372 start = data->desc[i].start - tsf;
3373 if (start <= 0)
3374 data->absent |= BIT(i);
3375
3376 if (next_offset > start)
3377 next_offset = start;
3378
3379 data->has_next_tsf = true;
3380 }
3381
3382 if (data->absent)
3383 next_offset = ieee80211_get_noa_absent_time(data, tsf);
3384
3385 data->next_tsf = tsf + next_offset;
3386}
3387EXPORT_SYMBOL(ieee80211_update_p2p_noa);
3388
3389int ieee80211_parse_p2p_noa(const struct ieee80211_p2p_noa_attr *attr,
3390 struct ieee80211_noa_data *data, u32 tsf)
3391{
3392 int ret = 0;
3393 int i;
3394
3395 memset(data, 0, sizeof(*data));
3396
3397 for (i = 0; i < IEEE80211_P2P_NOA_DESC_MAX; i++) {
3398 const struct ieee80211_p2p_noa_desc *desc = &attr->desc[i];
3399
3400 if (!desc->count || !desc->duration)
3401 continue;
3402
3403 data->count[i] = desc->count;
3404 data->desc[i].start = le32_to_cpu(desc->start_time);
3405 data->desc[i].duration = le32_to_cpu(desc->duration);
3406 data->desc[i].interval = le32_to_cpu(desc->interval);
3407
3408 if (data->count[i] > 1 &&
3409 data->desc[i].interval < data->desc[i].duration)
3410 continue;
3411
3412 ieee80211_extend_noa_desc(data, tsf, i);
3413 ret++;
3414 }
3415
3416 if (ret)
3417 ieee80211_update_p2p_noa(data, tsf);
3418
3419 return ret;
3420}
3421EXPORT_SYMBOL(ieee80211_parse_p2p_noa);
3422
3423void ieee80211_recalc_dtim(struct ieee80211_local *local,
3424 struct ieee80211_sub_if_data *sdata)
3425{
3426 u64 tsf = drv_get_tsf(local, sdata);
3427 u64 dtim_count = 0;
3428 u16 beacon_int = sdata->vif.bss_conf.beacon_int * 1024;
3429 u8 dtim_period = sdata->vif.bss_conf.dtim_period;
3430 struct ps_data *ps;
3431 u8 bcns_from_dtim;
3432
3433 if (tsf == -1ULL || !beacon_int || !dtim_period)
3434 return;
3435
3436 if (sdata->vif.type == NL80211_IFTYPE_AP ||
3437 sdata->vif.type == NL80211_IFTYPE_AP_VLAN) {
3438 if (!sdata->bss)
3439 return;
3440
3441 ps = &sdata->bss->ps;
3442 } else if (ieee80211_vif_is_mesh(&sdata->vif)) {
3443 ps = &sdata->u.mesh.ps;
3444 } else {
3445 return;
3446 }
3447
3448 /*
3449 * actually finds last dtim_count, mac80211 will update in
3450 * __beacon_add_tim().
3451 * dtim_count = dtim_period - (tsf / bcn_int) % dtim_period
3452 */
3453 do_div(tsf, beacon_int);
3454 bcns_from_dtim = do_div(tsf, dtim_period);
3455 /* just had a DTIM */
3456 if (!bcns_from_dtim)
3457 dtim_count = 0;
3458 else
3459 dtim_count = dtim_period - bcns_from_dtim;
3460
3461 ps->dtim_count = dtim_count;
3462}
3463
3464static u8 ieee80211_chanctx_radar_detect(struct ieee80211_local *local,
3465 struct ieee80211_chanctx *ctx)
3466{
3467 struct ieee80211_sub_if_data *sdata;
3468 u8 radar_detect = 0;
3469
3470 lockdep_assert_held(&local->chanctx_mtx);
3471
3472 if (WARN_ON(ctx->replace_state == IEEE80211_CHANCTX_WILL_BE_REPLACED))
3473 return 0;
3474
3475 list_for_each_entry(sdata, &ctx->reserved_vifs, reserved_chanctx_list)
3476 if (sdata->reserved_radar_required)
3477 radar_detect |= BIT(sdata->reserved_chandef.width);
3478
3479 /*
3480 * An in-place reservation context should not have any assigned vifs
3481 * until it replaces the other context.
3482 */
3483 WARN_ON(ctx->replace_state == IEEE80211_CHANCTX_REPLACES_OTHER &&
3484 !list_empty(&ctx->assigned_vifs));
3485
3486 list_for_each_entry(sdata, &ctx->assigned_vifs, assigned_chanctx_list)
3487 if (sdata->radar_required)
3488 radar_detect |= BIT(sdata->vif.bss_conf.chandef.width);
3489
3490 return radar_detect;
3491}
3492
3493int ieee80211_check_combinations(struct ieee80211_sub_if_data *sdata,
3494 const struct cfg80211_chan_def *chandef,
3495 enum ieee80211_chanctx_mode chanmode,
3496 u8 radar_detect)
3497{
3498 struct ieee80211_local *local = sdata->local;
3499 struct ieee80211_sub_if_data *sdata_iter;
3500 enum nl80211_iftype iftype = sdata->wdev.iftype;
3501 struct ieee80211_chanctx *ctx;
3502 int total = 1;
3503 struct iface_combination_params params = {
3504 .radar_detect = radar_detect,
3505 };
3506
3507 lockdep_assert_held(&local->chanctx_mtx);
3508
3509 if (WARN_ON(hweight32(radar_detect) > 1))
3510 return -EINVAL;
3511
3512 if (WARN_ON(chandef && chanmode == IEEE80211_CHANCTX_SHARED &&
3513 !chandef->chan))
3514 return -EINVAL;
3515
3516 if (WARN_ON(iftype >= NUM_NL80211_IFTYPES))
3517 return -EINVAL;
3518
3519 if (sdata->vif.type == NL80211_IFTYPE_AP ||
3520 sdata->vif.type == NL80211_IFTYPE_MESH_POINT) {
3521 /*
3522 * always passing this is harmless, since it'll be the
3523 * same value that cfg80211 finds if it finds the same
3524 * interface ... and that's always allowed
3525 */
3526 params.new_beacon_int = sdata->vif.bss_conf.beacon_int;
3527 }
3528
3529 /* Always allow software iftypes */
3530 if (cfg80211_iftype_allowed(local->hw.wiphy, iftype, 0, 1)) {
3531 if (radar_detect)
3532 return -EINVAL;
3533 return 0;
3534 }
3535
3536 if (chandef)
3537 params.num_different_channels = 1;
3538
3539 if (iftype != NL80211_IFTYPE_UNSPECIFIED)
3540 params.iftype_num[iftype] = 1;
3541
3542 list_for_each_entry(ctx, &local->chanctx_list, list) {
3543 if (ctx->replace_state == IEEE80211_CHANCTX_WILL_BE_REPLACED)
3544 continue;
3545 params.radar_detect |=
3546 ieee80211_chanctx_radar_detect(local, ctx);
3547 if (ctx->mode == IEEE80211_CHANCTX_EXCLUSIVE) {
3548 params.num_different_channels++;
3549 continue;
3550 }
3551 if (chandef && chanmode == IEEE80211_CHANCTX_SHARED &&
3552 cfg80211_chandef_compatible(chandef,
3553 &ctx->conf.def))
3554 continue;
3555 params.num_different_channels++;
3556 }
3557
3558 list_for_each_entry_rcu(sdata_iter, &local->interfaces, list) {
3559 struct wireless_dev *wdev_iter;
3560
3561 wdev_iter = &sdata_iter->wdev;
3562
3563 if (sdata_iter == sdata ||
3564 !ieee80211_sdata_running(sdata_iter) ||
3565 cfg80211_iftype_allowed(local->hw.wiphy,
3566 wdev_iter->iftype, 0, 1))
3567 continue;
3568
3569 params.iftype_num[wdev_iter->iftype]++;
3570 total++;
3571 }
3572
3573 if (total == 1 && !params.radar_detect)
3574 return 0;
3575
3576 return cfg80211_check_combinations(local->hw.wiphy, &params);
3577}
3578
3579static void
3580ieee80211_iter_max_chans(const struct ieee80211_iface_combination *c,
3581 void *data)
3582{
3583 u32 *max_num_different_channels = data;
3584
3585 *max_num_different_channels = max(*max_num_different_channels,
3586 c->num_different_channels);
3587}
3588
3589int ieee80211_max_num_channels(struct ieee80211_local *local)
3590{
3591 struct ieee80211_sub_if_data *sdata;
3592 struct ieee80211_chanctx *ctx;
3593 u32 max_num_different_channels = 1;
3594 int err;
3595 struct iface_combination_params params = {0};
3596
3597 lockdep_assert_held(&local->chanctx_mtx);
3598
3599 list_for_each_entry(ctx, &local->chanctx_list, list) {
3600 if (ctx->replace_state == IEEE80211_CHANCTX_WILL_BE_REPLACED)
3601 continue;
3602
3603 params.num_different_channels++;
3604
3605 params.radar_detect |=
3606 ieee80211_chanctx_radar_detect(local, ctx);
3607 }
3608
3609 list_for_each_entry_rcu(sdata, &local->interfaces, list)
3610 params.iftype_num[sdata->wdev.iftype]++;
3611
3612 err = cfg80211_iter_combinations(local->hw.wiphy, &params,
3613 ieee80211_iter_max_chans,
3614 &max_num_different_channels);
3615 if (err < 0)
3616 return err;
3617
3618 return max_num_different_channels;
3619}
3620
3621u8 *ieee80211_add_wmm_info_ie(u8 *buf, u8 qosinfo)
3622{
3623 *buf++ = WLAN_EID_VENDOR_SPECIFIC;
3624 *buf++ = 7; /* len */
3625 *buf++ = 0x00; /* Microsoft OUI 00:50:F2 */
3626 *buf++ = 0x50;
3627 *buf++ = 0xf2;
3628 *buf++ = 2; /* WME */
3629 *buf++ = 0; /* WME info */
3630 *buf++ = 1; /* WME ver */
3631 *buf++ = qosinfo; /* U-APSD no in use */
3632
3633 return buf;
3634}
3635
3636void ieee80211_txq_get_depth(struct ieee80211_txq *txq,
3637 unsigned long *frame_cnt,
3638 unsigned long *byte_cnt)
3639{
3640 struct txq_info *txqi = to_txq_info(txq);
3641 u32 frag_cnt = 0, frag_bytes = 0;
3642 struct sk_buff *skb;
3643
3644 skb_queue_walk(&txqi->frags, skb) {
3645 frag_cnt++;
3646 frag_bytes += skb->len;
3647 }
3648
3649 if (frame_cnt)
3650 *frame_cnt = txqi->tin.backlog_packets + frag_cnt;
3651
3652 if (byte_cnt)
3653 *byte_cnt = txqi->tin.backlog_bytes + frag_bytes;
3654}
3655EXPORT_SYMBOL(ieee80211_txq_get_depth);
3656
3657const u8 ieee80211_ac_to_qos_mask[IEEE80211_NUM_ACS] = {
3658 IEEE80211_WMM_IE_STA_QOSINFO_AC_VO,
3659 IEEE80211_WMM_IE_STA_QOSINFO_AC_VI,
3660 IEEE80211_WMM_IE_STA_QOSINFO_AC_BE,
3661 IEEE80211_WMM_IE_STA_QOSINFO_AC_BK
3662};