162306a36Sopenharmony_ci// SPDX-License-Identifier: GPL-2.0
262306a36Sopenharmony_ci/*
362306a36Sopenharmony_ci * cfg80211 MLME SAP interface
462306a36Sopenharmony_ci *
562306a36Sopenharmony_ci * Copyright (c) 2009, Jouni Malinen <j@w1.fi>
662306a36Sopenharmony_ci * Copyright (c) 2015		Intel Deutschland GmbH
762306a36Sopenharmony_ci * Copyright (C) 2019-2020, 2022 Intel Corporation
862306a36Sopenharmony_ci */
962306a36Sopenharmony_ci
1062306a36Sopenharmony_ci#include <linux/kernel.h>
1162306a36Sopenharmony_ci#include <linux/module.h>
1262306a36Sopenharmony_ci#include <linux/etherdevice.h>
1362306a36Sopenharmony_ci#include <linux/netdevice.h>
1462306a36Sopenharmony_ci#include <linux/nl80211.h>
1562306a36Sopenharmony_ci#include <linux/slab.h>
1662306a36Sopenharmony_ci#include <linux/wireless.h>
1762306a36Sopenharmony_ci#include <net/cfg80211.h>
1862306a36Sopenharmony_ci#include <net/iw_handler.h>
1962306a36Sopenharmony_ci#include "core.h"
2062306a36Sopenharmony_ci#include "nl80211.h"
2162306a36Sopenharmony_ci#include "rdev-ops.h"
2262306a36Sopenharmony_ci
2362306a36Sopenharmony_ci
2462306a36Sopenharmony_civoid cfg80211_rx_assoc_resp(struct net_device *dev,
2562306a36Sopenharmony_ci			    struct cfg80211_rx_assoc_resp *data)
2662306a36Sopenharmony_ci{
2762306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
2862306a36Sopenharmony_ci	struct wiphy *wiphy = wdev->wiphy;
2962306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
3062306a36Sopenharmony_ci	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)data->buf;
3162306a36Sopenharmony_ci	struct cfg80211_connect_resp_params cr = {
3262306a36Sopenharmony_ci		.timeout_reason = NL80211_TIMEOUT_UNSPECIFIED,
3362306a36Sopenharmony_ci		.req_ie = data->req_ies,
3462306a36Sopenharmony_ci		.req_ie_len = data->req_ies_len,
3562306a36Sopenharmony_ci		.resp_ie = mgmt->u.assoc_resp.variable,
3662306a36Sopenharmony_ci		.resp_ie_len = data->len -
3762306a36Sopenharmony_ci			       offsetof(struct ieee80211_mgmt,
3862306a36Sopenharmony_ci					u.assoc_resp.variable),
3962306a36Sopenharmony_ci		.status = le16_to_cpu(mgmt->u.assoc_resp.status_code),
4062306a36Sopenharmony_ci		.ap_mld_addr = data->ap_mld_addr,
4162306a36Sopenharmony_ci	};
4262306a36Sopenharmony_ci	unsigned int link_id;
4362306a36Sopenharmony_ci
4462306a36Sopenharmony_ci	for (link_id = 0; link_id < ARRAY_SIZE(data->links); link_id++) {
4562306a36Sopenharmony_ci		cr.links[link_id].status = data->links[link_id].status;
4662306a36Sopenharmony_ci		cr.links[link_id].bss = data->links[link_id].bss;
4762306a36Sopenharmony_ci
4862306a36Sopenharmony_ci		WARN_ON_ONCE(cr.links[link_id].status != WLAN_STATUS_SUCCESS &&
4962306a36Sopenharmony_ci			     (!cr.ap_mld_addr || !cr.links[link_id].bss));
5062306a36Sopenharmony_ci
5162306a36Sopenharmony_ci		if (!cr.links[link_id].bss)
5262306a36Sopenharmony_ci			continue;
5362306a36Sopenharmony_ci		cr.links[link_id].bssid = data->links[link_id].bss->bssid;
5462306a36Sopenharmony_ci		cr.links[link_id].addr = data->links[link_id].addr;
5562306a36Sopenharmony_ci		/* need to have local link addresses for MLO connections */
5662306a36Sopenharmony_ci		WARN_ON(cr.ap_mld_addr &&
5762306a36Sopenharmony_ci			!is_valid_ether_addr(cr.links[link_id].addr));
5862306a36Sopenharmony_ci
5962306a36Sopenharmony_ci		BUG_ON(!cr.links[link_id].bss->channel);
6062306a36Sopenharmony_ci
6162306a36Sopenharmony_ci		if (cr.links[link_id].bss->channel->band == NL80211_BAND_S1GHZ) {
6262306a36Sopenharmony_ci			WARN_ON(link_id);
6362306a36Sopenharmony_ci			cr.resp_ie = (u8 *)&mgmt->u.s1g_assoc_resp.variable;
6462306a36Sopenharmony_ci			cr.resp_ie_len = data->len -
6562306a36Sopenharmony_ci					 offsetof(struct ieee80211_mgmt,
6662306a36Sopenharmony_ci						  u.s1g_assoc_resp.variable);
6762306a36Sopenharmony_ci		}
6862306a36Sopenharmony_ci
6962306a36Sopenharmony_ci		if (cr.ap_mld_addr)
7062306a36Sopenharmony_ci			cr.valid_links |= BIT(link_id);
7162306a36Sopenharmony_ci	}
7262306a36Sopenharmony_ci
7362306a36Sopenharmony_ci	trace_cfg80211_send_rx_assoc(dev, data);
7462306a36Sopenharmony_ci
7562306a36Sopenharmony_ci	/*
7662306a36Sopenharmony_ci	 * This is a bit of a hack, we don't notify userspace of
7762306a36Sopenharmony_ci	 * a (re-)association reply if we tried to send a reassoc
7862306a36Sopenharmony_ci	 * and got a reject -- we only try again with an assoc
7962306a36Sopenharmony_ci	 * frame instead of reassoc.
8062306a36Sopenharmony_ci	 */
8162306a36Sopenharmony_ci	if (cfg80211_sme_rx_assoc_resp(wdev, cr.status)) {
8262306a36Sopenharmony_ci		for (link_id = 0; link_id < ARRAY_SIZE(data->links); link_id++) {
8362306a36Sopenharmony_ci			struct cfg80211_bss *bss = data->links[link_id].bss;
8462306a36Sopenharmony_ci
8562306a36Sopenharmony_ci			if (!bss)
8662306a36Sopenharmony_ci				continue;
8762306a36Sopenharmony_ci
8862306a36Sopenharmony_ci			cfg80211_unhold_bss(bss_from_pub(bss));
8962306a36Sopenharmony_ci			cfg80211_put_bss(wiphy, bss);
9062306a36Sopenharmony_ci		}
9162306a36Sopenharmony_ci		return;
9262306a36Sopenharmony_ci	}
9362306a36Sopenharmony_ci
9462306a36Sopenharmony_ci	nl80211_send_rx_assoc(rdev, dev, data);
9562306a36Sopenharmony_ci	/* update current_bss etc., consumes the bss reference */
9662306a36Sopenharmony_ci	__cfg80211_connect_result(dev, &cr, cr.status == WLAN_STATUS_SUCCESS);
9762306a36Sopenharmony_ci}
9862306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_rx_assoc_resp);
9962306a36Sopenharmony_ci
10062306a36Sopenharmony_cistatic void cfg80211_process_auth(struct wireless_dev *wdev,
10162306a36Sopenharmony_ci				  const u8 *buf, size_t len)
10262306a36Sopenharmony_ci{
10362306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
10462306a36Sopenharmony_ci
10562306a36Sopenharmony_ci	nl80211_send_rx_auth(rdev, wdev->netdev, buf, len, GFP_KERNEL);
10662306a36Sopenharmony_ci	cfg80211_sme_rx_auth(wdev, buf, len);
10762306a36Sopenharmony_ci}
10862306a36Sopenharmony_ci
10962306a36Sopenharmony_cistatic void cfg80211_process_deauth(struct wireless_dev *wdev,
11062306a36Sopenharmony_ci				    const u8 *buf, size_t len,
11162306a36Sopenharmony_ci				    bool reconnect)
11262306a36Sopenharmony_ci{
11362306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
11462306a36Sopenharmony_ci	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)buf;
11562306a36Sopenharmony_ci	const u8 *bssid = mgmt->bssid;
11662306a36Sopenharmony_ci	u16 reason_code = le16_to_cpu(mgmt->u.deauth.reason_code);
11762306a36Sopenharmony_ci	bool from_ap = !ether_addr_equal(mgmt->sa, wdev->netdev->dev_addr);
11862306a36Sopenharmony_ci
11962306a36Sopenharmony_ci	nl80211_send_deauth(rdev, wdev->netdev, buf, len, reconnect, GFP_KERNEL);
12062306a36Sopenharmony_ci
12162306a36Sopenharmony_ci	if (!wdev->connected || !ether_addr_equal(wdev->u.client.connected_addr, bssid))
12262306a36Sopenharmony_ci		return;
12362306a36Sopenharmony_ci
12462306a36Sopenharmony_ci	__cfg80211_disconnected(wdev->netdev, NULL, 0, reason_code, from_ap);
12562306a36Sopenharmony_ci	cfg80211_sme_deauth(wdev);
12662306a36Sopenharmony_ci}
12762306a36Sopenharmony_ci
12862306a36Sopenharmony_cistatic void cfg80211_process_disassoc(struct wireless_dev *wdev,
12962306a36Sopenharmony_ci				      const u8 *buf, size_t len,
13062306a36Sopenharmony_ci				      bool reconnect)
13162306a36Sopenharmony_ci{
13262306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
13362306a36Sopenharmony_ci	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)buf;
13462306a36Sopenharmony_ci	const u8 *bssid = mgmt->bssid;
13562306a36Sopenharmony_ci	u16 reason_code = le16_to_cpu(mgmt->u.disassoc.reason_code);
13662306a36Sopenharmony_ci	bool from_ap = !ether_addr_equal(mgmt->sa, wdev->netdev->dev_addr);
13762306a36Sopenharmony_ci
13862306a36Sopenharmony_ci	nl80211_send_disassoc(rdev, wdev->netdev, buf, len, reconnect,
13962306a36Sopenharmony_ci			      GFP_KERNEL);
14062306a36Sopenharmony_ci
14162306a36Sopenharmony_ci	if (WARN_ON(!wdev->connected ||
14262306a36Sopenharmony_ci		    !ether_addr_equal(wdev->u.client.connected_addr, bssid)))
14362306a36Sopenharmony_ci		return;
14462306a36Sopenharmony_ci
14562306a36Sopenharmony_ci	__cfg80211_disconnected(wdev->netdev, NULL, 0, reason_code, from_ap);
14662306a36Sopenharmony_ci	cfg80211_sme_disassoc(wdev);
14762306a36Sopenharmony_ci}
14862306a36Sopenharmony_ci
14962306a36Sopenharmony_civoid cfg80211_rx_mlme_mgmt(struct net_device *dev, const u8 *buf, size_t len)
15062306a36Sopenharmony_ci{
15162306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
15262306a36Sopenharmony_ci	struct ieee80211_mgmt *mgmt = (void *)buf;
15362306a36Sopenharmony_ci
15462306a36Sopenharmony_ci	ASSERT_WDEV_LOCK(wdev);
15562306a36Sopenharmony_ci
15662306a36Sopenharmony_ci	trace_cfg80211_rx_mlme_mgmt(dev, buf, len);
15762306a36Sopenharmony_ci
15862306a36Sopenharmony_ci	if (WARN_ON(len < 2))
15962306a36Sopenharmony_ci		return;
16062306a36Sopenharmony_ci
16162306a36Sopenharmony_ci	if (ieee80211_is_auth(mgmt->frame_control))
16262306a36Sopenharmony_ci		cfg80211_process_auth(wdev, buf, len);
16362306a36Sopenharmony_ci	else if (ieee80211_is_deauth(mgmt->frame_control))
16462306a36Sopenharmony_ci		cfg80211_process_deauth(wdev, buf, len, false);
16562306a36Sopenharmony_ci	else if (ieee80211_is_disassoc(mgmt->frame_control))
16662306a36Sopenharmony_ci		cfg80211_process_disassoc(wdev, buf, len, false);
16762306a36Sopenharmony_ci}
16862306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_rx_mlme_mgmt);
16962306a36Sopenharmony_ci
17062306a36Sopenharmony_civoid cfg80211_auth_timeout(struct net_device *dev, const u8 *addr)
17162306a36Sopenharmony_ci{
17262306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
17362306a36Sopenharmony_ci	struct wiphy *wiphy = wdev->wiphy;
17462306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
17562306a36Sopenharmony_ci
17662306a36Sopenharmony_ci	trace_cfg80211_send_auth_timeout(dev, addr);
17762306a36Sopenharmony_ci
17862306a36Sopenharmony_ci	nl80211_send_auth_timeout(rdev, dev, addr, GFP_KERNEL);
17962306a36Sopenharmony_ci	cfg80211_sme_auth_timeout(wdev);
18062306a36Sopenharmony_ci}
18162306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_auth_timeout);
18262306a36Sopenharmony_ci
18362306a36Sopenharmony_civoid cfg80211_assoc_failure(struct net_device *dev,
18462306a36Sopenharmony_ci			    struct cfg80211_assoc_failure *data)
18562306a36Sopenharmony_ci{
18662306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
18762306a36Sopenharmony_ci	struct wiphy *wiphy = wdev->wiphy;
18862306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
18962306a36Sopenharmony_ci	const u8 *addr = data->ap_mld_addr ?: data->bss[0]->bssid;
19062306a36Sopenharmony_ci	int i;
19162306a36Sopenharmony_ci
19262306a36Sopenharmony_ci	trace_cfg80211_send_assoc_failure(dev, data);
19362306a36Sopenharmony_ci
19462306a36Sopenharmony_ci	if (data->timeout) {
19562306a36Sopenharmony_ci		nl80211_send_assoc_timeout(rdev, dev, addr, GFP_KERNEL);
19662306a36Sopenharmony_ci		cfg80211_sme_assoc_timeout(wdev);
19762306a36Sopenharmony_ci	} else {
19862306a36Sopenharmony_ci		cfg80211_sme_abandon_assoc(wdev);
19962306a36Sopenharmony_ci	}
20062306a36Sopenharmony_ci
20162306a36Sopenharmony_ci	for (i = 0; i < ARRAY_SIZE(data->bss); i++) {
20262306a36Sopenharmony_ci		struct cfg80211_bss *bss = data->bss[i];
20362306a36Sopenharmony_ci
20462306a36Sopenharmony_ci		if (!bss)
20562306a36Sopenharmony_ci			continue;
20662306a36Sopenharmony_ci
20762306a36Sopenharmony_ci		cfg80211_unhold_bss(bss_from_pub(bss));
20862306a36Sopenharmony_ci		cfg80211_put_bss(wiphy, bss);
20962306a36Sopenharmony_ci	}
21062306a36Sopenharmony_ci}
21162306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_assoc_failure);
21262306a36Sopenharmony_ci
21362306a36Sopenharmony_civoid cfg80211_tx_mlme_mgmt(struct net_device *dev, const u8 *buf, size_t len,
21462306a36Sopenharmony_ci			   bool reconnect)
21562306a36Sopenharmony_ci{
21662306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
21762306a36Sopenharmony_ci	struct ieee80211_mgmt *mgmt = (void *)buf;
21862306a36Sopenharmony_ci
21962306a36Sopenharmony_ci	ASSERT_WDEV_LOCK(wdev);
22062306a36Sopenharmony_ci
22162306a36Sopenharmony_ci	trace_cfg80211_tx_mlme_mgmt(dev, buf, len, reconnect);
22262306a36Sopenharmony_ci
22362306a36Sopenharmony_ci	if (WARN_ON(len < 2))
22462306a36Sopenharmony_ci		return;
22562306a36Sopenharmony_ci
22662306a36Sopenharmony_ci	if (ieee80211_is_deauth(mgmt->frame_control))
22762306a36Sopenharmony_ci		cfg80211_process_deauth(wdev, buf, len, reconnect);
22862306a36Sopenharmony_ci	else
22962306a36Sopenharmony_ci		cfg80211_process_disassoc(wdev, buf, len, reconnect);
23062306a36Sopenharmony_ci}
23162306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_tx_mlme_mgmt);
23262306a36Sopenharmony_ci
23362306a36Sopenharmony_civoid cfg80211_michael_mic_failure(struct net_device *dev, const u8 *addr,
23462306a36Sopenharmony_ci				  enum nl80211_key_type key_type, int key_id,
23562306a36Sopenharmony_ci				  const u8 *tsc, gfp_t gfp)
23662306a36Sopenharmony_ci{
23762306a36Sopenharmony_ci	struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
23862306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
23962306a36Sopenharmony_ci#ifdef CONFIG_CFG80211_WEXT
24062306a36Sopenharmony_ci	union iwreq_data wrqu;
24162306a36Sopenharmony_ci	char *buf = kmalloc(128, gfp);
24262306a36Sopenharmony_ci
24362306a36Sopenharmony_ci	if (buf) {
24462306a36Sopenharmony_ci		sprintf(buf, "MLME-MICHAELMICFAILURE.indication("
24562306a36Sopenharmony_ci			"keyid=%d %scast addr=%pM)", key_id,
24662306a36Sopenharmony_ci			key_type == NL80211_KEYTYPE_GROUP ? "broad" : "uni",
24762306a36Sopenharmony_ci			addr);
24862306a36Sopenharmony_ci		memset(&wrqu, 0, sizeof(wrqu));
24962306a36Sopenharmony_ci		wrqu.data.length = strlen(buf);
25062306a36Sopenharmony_ci		wireless_send_event(dev, IWEVCUSTOM, &wrqu, buf);
25162306a36Sopenharmony_ci		kfree(buf);
25262306a36Sopenharmony_ci	}
25362306a36Sopenharmony_ci#endif
25462306a36Sopenharmony_ci
25562306a36Sopenharmony_ci	trace_cfg80211_michael_mic_failure(dev, addr, key_type, key_id, tsc);
25662306a36Sopenharmony_ci	nl80211_michael_mic_failure(rdev, dev, addr, key_type, key_id, tsc, gfp);
25762306a36Sopenharmony_ci}
25862306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_michael_mic_failure);
25962306a36Sopenharmony_ci
26062306a36Sopenharmony_ci/* some MLME handling for userspace SME */
26162306a36Sopenharmony_ciint cfg80211_mlme_auth(struct cfg80211_registered_device *rdev,
26262306a36Sopenharmony_ci		       struct net_device *dev,
26362306a36Sopenharmony_ci		       struct cfg80211_auth_request *req)
26462306a36Sopenharmony_ci{
26562306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
26662306a36Sopenharmony_ci
26762306a36Sopenharmony_ci	ASSERT_WDEV_LOCK(wdev);
26862306a36Sopenharmony_ci
26962306a36Sopenharmony_ci	if (!req->bss)
27062306a36Sopenharmony_ci		return -ENOENT;
27162306a36Sopenharmony_ci
27262306a36Sopenharmony_ci	if (req->link_id >= 0 &&
27362306a36Sopenharmony_ci	    !(wdev->wiphy->flags & WIPHY_FLAG_SUPPORTS_MLO))
27462306a36Sopenharmony_ci		return -EINVAL;
27562306a36Sopenharmony_ci
27662306a36Sopenharmony_ci	if (req->auth_type == NL80211_AUTHTYPE_SHARED_KEY) {
27762306a36Sopenharmony_ci		if (!req->key || !req->key_len ||
27862306a36Sopenharmony_ci		    req->key_idx < 0 || req->key_idx > 3)
27962306a36Sopenharmony_ci			return -EINVAL;
28062306a36Sopenharmony_ci	}
28162306a36Sopenharmony_ci
28262306a36Sopenharmony_ci	if (wdev->connected &&
28362306a36Sopenharmony_ci	    ether_addr_equal(req->bss->bssid, wdev->u.client.connected_addr))
28462306a36Sopenharmony_ci		return -EALREADY;
28562306a36Sopenharmony_ci
28662306a36Sopenharmony_ci	if (ether_addr_equal(req->bss->bssid, dev->dev_addr) ||
28762306a36Sopenharmony_ci	    (req->link_id >= 0 &&
28862306a36Sopenharmony_ci	     ether_addr_equal(req->ap_mld_addr, dev->dev_addr)))
28962306a36Sopenharmony_ci		return -EINVAL;
29062306a36Sopenharmony_ci
29162306a36Sopenharmony_ci	return rdev_auth(rdev, dev, req);
29262306a36Sopenharmony_ci}
29362306a36Sopenharmony_ci
29462306a36Sopenharmony_ci/*  Do a logical ht_capa &= ht_capa_mask.  */
29562306a36Sopenharmony_civoid cfg80211_oper_and_ht_capa(struct ieee80211_ht_cap *ht_capa,
29662306a36Sopenharmony_ci			       const struct ieee80211_ht_cap *ht_capa_mask)
29762306a36Sopenharmony_ci{
29862306a36Sopenharmony_ci	int i;
29962306a36Sopenharmony_ci	u8 *p1, *p2;
30062306a36Sopenharmony_ci	if (!ht_capa_mask) {
30162306a36Sopenharmony_ci		memset(ht_capa, 0, sizeof(*ht_capa));
30262306a36Sopenharmony_ci		return;
30362306a36Sopenharmony_ci	}
30462306a36Sopenharmony_ci
30562306a36Sopenharmony_ci	p1 = (u8*)(ht_capa);
30662306a36Sopenharmony_ci	p2 = (u8*)(ht_capa_mask);
30762306a36Sopenharmony_ci	for (i = 0; i < sizeof(*ht_capa); i++)
30862306a36Sopenharmony_ci		p1[i] &= p2[i];
30962306a36Sopenharmony_ci}
31062306a36Sopenharmony_ci
31162306a36Sopenharmony_ci/*  Do a logical vht_capa &= vht_capa_mask.  */
31262306a36Sopenharmony_civoid cfg80211_oper_and_vht_capa(struct ieee80211_vht_cap *vht_capa,
31362306a36Sopenharmony_ci				const struct ieee80211_vht_cap *vht_capa_mask)
31462306a36Sopenharmony_ci{
31562306a36Sopenharmony_ci	int i;
31662306a36Sopenharmony_ci	u8 *p1, *p2;
31762306a36Sopenharmony_ci	if (!vht_capa_mask) {
31862306a36Sopenharmony_ci		memset(vht_capa, 0, sizeof(*vht_capa));
31962306a36Sopenharmony_ci		return;
32062306a36Sopenharmony_ci	}
32162306a36Sopenharmony_ci
32262306a36Sopenharmony_ci	p1 = (u8*)(vht_capa);
32362306a36Sopenharmony_ci	p2 = (u8*)(vht_capa_mask);
32462306a36Sopenharmony_ci	for (i = 0; i < sizeof(*vht_capa); i++)
32562306a36Sopenharmony_ci		p1[i] &= p2[i];
32662306a36Sopenharmony_ci}
32762306a36Sopenharmony_ci
32862306a36Sopenharmony_ci/* Note: caller must cfg80211_put_bss() regardless of result */
32962306a36Sopenharmony_ciint cfg80211_mlme_assoc(struct cfg80211_registered_device *rdev,
33062306a36Sopenharmony_ci			struct net_device *dev,
33162306a36Sopenharmony_ci			struct cfg80211_assoc_request *req)
33262306a36Sopenharmony_ci{
33362306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
33462306a36Sopenharmony_ci	int err, i, j;
33562306a36Sopenharmony_ci
33662306a36Sopenharmony_ci	ASSERT_WDEV_LOCK(wdev);
33762306a36Sopenharmony_ci
33862306a36Sopenharmony_ci	for (i = 1; i < ARRAY_SIZE(req->links); i++) {
33962306a36Sopenharmony_ci		if (!req->links[i].bss)
34062306a36Sopenharmony_ci			continue;
34162306a36Sopenharmony_ci		for (j = 0; j < i; j++) {
34262306a36Sopenharmony_ci			if (req->links[i].bss == req->links[j].bss)
34362306a36Sopenharmony_ci				return -EINVAL;
34462306a36Sopenharmony_ci		}
34562306a36Sopenharmony_ci
34662306a36Sopenharmony_ci		if (ether_addr_equal(req->links[i].bss->bssid, dev->dev_addr))
34762306a36Sopenharmony_ci			return -EINVAL;
34862306a36Sopenharmony_ci	}
34962306a36Sopenharmony_ci
35062306a36Sopenharmony_ci	if (wdev->connected &&
35162306a36Sopenharmony_ci	    (!req->prev_bssid ||
35262306a36Sopenharmony_ci	     !ether_addr_equal(wdev->u.client.connected_addr, req->prev_bssid)))
35362306a36Sopenharmony_ci		return -EALREADY;
35462306a36Sopenharmony_ci
35562306a36Sopenharmony_ci	if ((req->bss && ether_addr_equal(req->bss->bssid, dev->dev_addr)) ||
35662306a36Sopenharmony_ci	    (req->link_id >= 0 &&
35762306a36Sopenharmony_ci	     ether_addr_equal(req->ap_mld_addr, dev->dev_addr)))
35862306a36Sopenharmony_ci		return -EINVAL;
35962306a36Sopenharmony_ci
36062306a36Sopenharmony_ci	cfg80211_oper_and_ht_capa(&req->ht_capa_mask,
36162306a36Sopenharmony_ci				  rdev->wiphy.ht_capa_mod_mask);
36262306a36Sopenharmony_ci	cfg80211_oper_and_vht_capa(&req->vht_capa_mask,
36362306a36Sopenharmony_ci				   rdev->wiphy.vht_capa_mod_mask);
36462306a36Sopenharmony_ci
36562306a36Sopenharmony_ci	err = rdev_assoc(rdev, dev, req);
36662306a36Sopenharmony_ci	if (!err) {
36762306a36Sopenharmony_ci		int link_id;
36862306a36Sopenharmony_ci
36962306a36Sopenharmony_ci		if (req->bss) {
37062306a36Sopenharmony_ci			cfg80211_ref_bss(&rdev->wiphy, req->bss);
37162306a36Sopenharmony_ci			cfg80211_hold_bss(bss_from_pub(req->bss));
37262306a36Sopenharmony_ci		}
37362306a36Sopenharmony_ci
37462306a36Sopenharmony_ci		for (link_id = 0; link_id < ARRAY_SIZE(req->links); link_id++) {
37562306a36Sopenharmony_ci			if (!req->links[link_id].bss)
37662306a36Sopenharmony_ci				continue;
37762306a36Sopenharmony_ci			cfg80211_ref_bss(&rdev->wiphy, req->links[link_id].bss);
37862306a36Sopenharmony_ci			cfg80211_hold_bss(bss_from_pub(req->links[link_id].bss));
37962306a36Sopenharmony_ci		}
38062306a36Sopenharmony_ci	}
38162306a36Sopenharmony_ci	return err;
38262306a36Sopenharmony_ci}
38362306a36Sopenharmony_ci
38462306a36Sopenharmony_ciint cfg80211_mlme_deauth(struct cfg80211_registered_device *rdev,
38562306a36Sopenharmony_ci			 struct net_device *dev, const u8 *bssid,
38662306a36Sopenharmony_ci			 const u8 *ie, int ie_len, u16 reason,
38762306a36Sopenharmony_ci			 bool local_state_change)
38862306a36Sopenharmony_ci{
38962306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
39062306a36Sopenharmony_ci	struct cfg80211_deauth_request req = {
39162306a36Sopenharmony_ci		.bssid = bssid,
39262306a36Sopenharmony_ci		.reason_code = reason,
39362306a36Sopenharmony_ci		.ie = ie,
39462306a36Sopenharmony_ci		.ie_len = ie_len,
39562306a36Sopenharmony_ci		.local_state_change = local_state_change,
39662306a36Sopenharmony_ci	};
39762306a36Sopenharmony_ci
39862306a36Sopenharmony_ci	ASSERT_WDEV_LOCK(wdev);
39962306a36Sopenharmony_ci
40062306a36Sopenharmony_ci	if (local_state_change &&
40162306a36Sopenharmony_ci	    (!wdev->connected ||
40262306a36Sopenharmony_ci	     !ether_addr_equal(wdev->u.client.connected_addr, bssid)))
40362306a36Sopenharmony_ci		return 0;
40462306a36Sopenharmony_ci
40562306a36Sopenharmony_ci	if (ether_addr_equal(wdev->disconnect_bssid, bssid) ||
40662306a36Sopenharmony_ci	    (wdev->connected &&
40762306a36Sopenharmony_ci	     ether_addr_equal(wdev->u.client.connected_addr, bssid)))
40862306a36Sopenharmony_ci		wdev->conn_owner_nlportid = 0;
40962306a36Sopenharmony_ci
41062306a36Sopenharmony_ci	return rdev_deauth(rdev, dev, &req);
41162306a36Sopenharmony_ci}
41262306a36Sopenharmony_ci
41362306a36Sopenharmony_ciint cfg80211_mlme_disassoc(struct cfg80211_registered_device *rdev,
41462306a36Sopenharmony_ci			   struct net_device *dev, const u8 *ap_addr,
41562306a36Sopenharmony_ci			   const u8 *ie, int ie_len, u16 reason,
41662306a36Sopenharmony_ci			   bool local_state_change)
41762306a36Sopenharmony_ci{
41862306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
41962306a36Sopenharmony_ci	struct cfg80211_disassoc_request req = {
42062306a36Sopenharmony_ci		.reason_code = reason,
42162306a36Sopenharmony_ci		.local_state_change = local_state_change,
42262306a36Sopenharmony_ci		.ie = ie,
42362306a36Sopenharmony_ci		.ie_len = ie_len,
42462306a36Sopenharmony_ci		.ap_addr = ap_addr,
42562306a36Sopenharmony_ci	};
42662306a36Sopenharmony_ci	int err;
42762306a36Sopenharmony_ci
42862306a36Sopenharmony_ci	ASSERT_WDEV_LOCK(wdev);
42962306a36Sopenharmony_ci
43062306a36Sopenharmony_ci	if (!wdev->connected)
43162306a36Sopenharmony_ci		return -ENOTCONN;
43262306a36Sopenharmony_ci
43362306a36Sopenharmony_ci	if (memcmp(wdev->u.client.connected_addr, ap_addr, ETH_ALEN))
43462306a36Sopenharmony_ci		return -ENOTCONN;
43562306a36Sopenharmony_ci
43662306a36Sopenharmony_ci	err = rdev_disassoc(rdev, dev, &req);
43762306a36Sopenharmony_ci	if (err)
43862306a36Sopenharmony_ci		return err;
43962306a36Sopenharmony_ci
44062306a36Sopenharmony_ci	/* driver should have reported the disassoc */
44162306a36Sopenharmony_ci	WARN_ON(wdev->connected);
44262306a36Sopenharmony_ci	return 0;
44362306a36Sopenharmony_ci}
44462306a36Sopenharmony_ci
44562306a36Sopenharmony_civoid cfg80211_mlme_down(struct cfg80211_registered_device *rdev,
44662306a36Sopenharmony_ci			struct net_device *dev)
44762306a36Sopenharmony_ci{
44862306a36Sopenharmony_ci	struct wireless_dev *wdev = dev->ieee80211_ptr;
44962306a36Sopenharmony_ci	u8 bssid[ETH_ALEN];
45062306a36Sopenharmony_ci
45162306a36Sopenharmony_ci	ASSERT_WDEV_LOCK(wdev);
45262306a36Sopenharmony_ci
45362306a36Sopenharmony_ci	if (!rdev->ops->deauth)
45462306a36Sopenharmony_ci		return;
45562306a36Sopenharmony_ci
45662306a36Sopenharmony_ci	if (!wdev->connected)
45762306a36Sopenharmony_ci		return;
45862306a36Sopenharmony_ci
45962306a36Sopenharmony_ci	memcpy(bssid, wdev->u.client.connected_addr, ETH_ALEN);
46062306a36Sopenharmony_ci	cfg80211_mlme_deauth(rdev, dev, bssid, NULL, 0,
46162306a36Sopenharmony_ci			     WLAN_REASON_DEAUTH_LEAVING, false);
46262306a36Sopenharmony_ci}
46362306a36Sopenharmony_ci
46462306a36Sopenharmony_cistruct cfg80211_mgmt_registration {
46562306a36Sopenharmony_ci	struct list_head list;
46662306a36Sopenharmony_ci	struct wireless_dev *wdev;
46762306a36Sopenharmony_ci
46862306a36Sopenharmony_ci	u32 nlportid;
46962306a36Sopenharmony_ci
47062306a36Sopenharmony_ci	int match_len;
47162306a36Sopenharmony_ci
47262306a36Sopenharmony_ci	__le16 frame_type;
47362306a36Sopenharmony_ci
47462306a36Sopenharmony_ci	bool multicast_rx;
47562306a36Sopenharmony_ci
47662306a36Sopenharmony_ci	u8 match[];
47762306a36Sopenharmony_ci};
47862306a36Sopenharmony_ci
47962306a36Sopenharmony_cistatic void cfg80211_mgmt_registrations_update(struct wireless_dev *wdev)
48062306a36Sopenharmony_ci{
48162306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
48262306a36Sopenharmony_ci	struct wireless_dev *tmp;
48362306a36Sopenharmony_ci	struct cfg80211_mgmt_registration *reg;
48462306a36Sopenharmony_ci	struct mgmt_frame_regs upd = {};
48562306a36Sopenharmony_ci
48662306a36Sopenharmony_ci	lockdep_assert_held(&rdev->wiphy.mtx);
48762306a36Sopenharmony_ci
48862306a36Sopenharmony_ci	spin_lock_bh(&rdev->mgmt_registrations_lock);
48962306a36Sopenharmony_ci	if (!wdev->mgmt_registrations_need_update) {
49062306a36Sopenharmony_ci		spin_unlock_bh(&rdev->mgmt_registrations_lock);
49162306a36Sopenharmony_ci		return;
49262306a36Sopenharmony_ci	}
49362306a36Sopenharmony_ci
49462306a36Sopenharmony_ci	rcu_read_lock();
49562306a36Sopenharmony_ci	list_for_each_entry_rcu(tmp, &rdev->wiphy.wdev_list, list) {
49662306a36Sopenharmony_ci		list_for_each_entry(reg, &tmp->mgmt_registrations, list) {
49762306a36Sopenharmony_ci			u32 mask = BIT(le16_to_cpu(reg->frame_type) >> 4);
49862306a36Sopenharmony_ci			u32 mcast_mask = 0;
49962306a36Sopenharmony_ci
50062306a36Sopenharmony_ci			if (reg->multicast_rx)
50162306a36Sopenharmony_ci				mcast_mask = mask;
50262306a36Sopenharmony_ci
50362306a36Sopenharmony_ci			upd.global_stypes |= mask;
50462306a36Sopenharmony_ci			upd.global_mcast_stypes |= mcast_mask;
50562306a36Sopenharmony_ci
50662306a36Sopenharmony_ci			if (tmp == wdev) {
50762306a36Sopenharmony_ci				upd.interface_stypes |= mask;
50862306a36Sopenharmony_ci				upd.interface_mcast_stypes |= mcast_mask;
50962306a36Sopenharmony_ci			}
51062306a36Sopenharmony_ci		}
51162306a36Sopenharmony_ci	}
51262306a36Sopenharmony_ci	rcu_read_unlock();
51362306a36Sopenharmony_ci
51462306a36Sopenharmony_ci	wdev->mgmt_registrations_need_update = 0;
51562306a36Sopenharmony_ci	spin_unlock_bh(&rdev->mgmt_registrations_lock);
51662306a36Sopenharmony_ci
51762306a36Sopenharmony_ci	rdev_update_mgmt_frame_registrations(rdev, wdev, &upd);
51862306a36Sopenharmony_ci}
51962306a36Sopenharmony_ci
52062306a36Sopenharmony_civoid cfg80211_mgmt_registrations_update_wk(struct work_struct *wk)
52162306a36Sopenharmony_ci{
52262306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev;
52362306a36Sopenharmony_ci	struct wireless_dev *wdev;
52462306a36Sopenharmony_ci
52562306a36Sopenharmony_ci	rdev = container_of(wk, struct cfg80211_registered_device,
52662306a36Sopenharmony_ci			    mgmt_registrations_update_wk);
52762306a36Sopenharmony_ci
52862306a36Sopenharmony_ci	wiphy_lock(&rdev->wiphy);
52962306a36Sopenharmony_ci	list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list)
53062306a36Sopenharmony_ci		cfg80211_mgmt_registrations_update(wdev);
53162306a36Sopenharmony_ci	wiphy_unlock(&rdev->wiphy);
53262306a36Sopenharmony_ci}
53362306a36Sopenharmony_ci
53462306a36Sopenharmony_ciint cfg80211_mlme_register_mgmt(struct wireless_dev *wdev, u32 snd_portid,
53562306a36Sopenharmony_ci				u16 frame_type, const u8 *match_data,
53662306a36Sopenharmony_ci				int match_len, bool multicast_rx,
53762306a36Sopenharmony_ci				struct netlink_ext_ack *extack)
53862306a36Sopenharmony_ci{
53962306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
54062306a36Sopenharmony_ci	struct cfg80211_mgmt_registration *reg, *nreg;
54162306a36Sopenharmony_ci	int err = 0;
54262306a36Sopenharmony_ci	u16 mgmt_type;
54362306a36Sopenharmony_ci	bool update_multicast = false;
54462306a36Sopenharmony_ci
54562306a36Sopenharmony_ci	if (!wdev->wiphy->mgmt_stypes)
54662306a36Sopenharmony_ci		return -EOPNOTSUPP;
54762306a36Sopenharmony_ci
54862306a36Sopenharmony_ci	if ((frame_type & IEEE80211_FCTL_FTYPE) != IEEE80211_FTYPE_MGMT) {
54962306a36Sopenharmony_ci		NL_SET_ERR_MSG(extack, "frame type not management");
55062306a36Sopenharmony_ci		return -EINVAL;
55162306a36Sopenharmony_ci	}
55262306a36Sopenharmony_ci
55362306a36Sopenharmony_ci	if (frame_type & ~(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE)) {
55462306a36Sopenharmony_ci		NL_SET_ERR_MSG(extack, "Invalid frame type");
55562306a36Sopenharmony_ci		return -EINVAL;
55662306a36Sopenharmony_ci	}
55762306a36Sopenharmony_ci
55862306a36Sopenharmony_ci	mgmt_type = (frame_type & IEEE80211_FCTL_STYPE) >> 4;
55962306a36Sopenharmony_ci	if (!(wdev->wiphy->mgmt_stypes[wdev->iftype].rx & BIT(mgmt_type))) {
56062306a36Sopenharmony_ci		NL_SET_ERR_MSG(extack,
56162306a36Sopenharmony_ci			       "Registration to specific type not supported");
56262306a36Sopenharmony_ci		return -EINVAL;
56362306a36Sopenharmony_ci	}
56462306a36Sopenharmony_ci
56562306a36Sopenharmony_ci	/*
56662306a36Sopenharmony_ci	 * To support Pre Association Security Negotiation (PASN), registration
56762306a36Sopenharmony_ci	 * for authentication frames should be supported. However, as some
56862306a36Sopenharmony_ci	 * versions of the user space daemons wrongly register to all types of
56962306a36Sopenharmony_ci	 * authentication frames (which might result in unexpected behavior)
57062306a36Sopenharmony_ci	 * allow such registration if the request is for a specific
57162306a36Sopenharmony_ci	 * authentication algorithm number.
57262306a36Sopenharmony_ci	 */
57362306a36Sopenharmony_ci	if (wdev->iftype == NL80211_IFTYPE_STATION &&
57462306a36Sopenharmony_ci	    (frame_type & IEEE80211_FCTL_STYPE) == IEEE80211_STYPE_AUTH &&
57562306a36Sopenharmony_ci	    !(match_data && match_len >= 2)) {
57662306a36Sopenharmony_ci		NL_SET_ERR_MSG(extack,
57762306a36Sopenharmony_ci			       "Authentication algorithm number required");
57862306a36Sopenharmony_ci		return -EINVAL;
57962306a36Sopenharmony_ci	}
58062306a36Sopenharmony_ci
58162306a36Sopenharmony_ci	nreg = kzalloc(sizeof(*reg) + match_len, GFP_KERNEL);
58262306a36Sopenharmony_ci	if (!nreg)
58362306a36Sopenharmony_ci		return -ENOMEM;
58462306a36Sopenharmony_ci
58562306a36Sopenharmony_ci	spin_lock_bh(&rdev->mgmt_registrations_lock);
58662306a36Sopenharmony_ci
58762306a36Sopenharmony_ci	list_for_each_entry(reg, &wdev->mgmt_registrations, list) {
58862306a36Sopenharmony_ci		int mlen = min(match_len, reg->match_len);
58962306a36Sopenharmony_ci
59062306a36Sopenharmony_ci		if (frame_type != le16_to_cpu(reg->frame_type))
59162306a36Sopenharmony_ci			continue;
59262306a36Sopenharmony_ci
59362306a36Sopenharmony_ci		if (memcmp(reg->match, match_data, mlen) == 0) {
59462306a36Sopenharmony_ci			if (reg->multicast_rx != multicast_rx) {
59562306a36Sopenharmony_ci				update_multicast = true;
59662306a36Sopenharmony_ci				reg->multicast_rx = multicast_rx;
59762306a36Sopenharmony_ci				break;
59862306a36Sopenharmony_ci			}
59962306a36Sopenharmony_ci			NL_SET_ERR_MSG(extack, "Match already configured");
60062306a36Sopenharmony_ci			err = -EALREADY;
60162306a36Sopenharmony_ci			break;
60262306a36Sopenharmony_ci		}
60362306a36Sopenharmony_ci	}
60462306a36Sopenharmony_ci
60562306a36Sopenharmony_ci	if (err)
60662306a36Sopenharmony_ci		goto out;
60762306a36Sopenharmony_ci
60862306a36Sopenharmony_ci	if (update_multicast) {
60962306a36Sopenharmony_ci		kfree(nreg);
61062306a36Sopenharmony_ci	} else {
61162306a36Sopenharmony_ci		memcpy(nreg->match, match_data, match_len);
61262306a36Sopenharmony_ci		nreg->match_len = match_len;
61362306a36Sopenharmony_ci		nreg->nlportid = snd_portid;
61462306a36Sopenharmony_ci		nreg->frame_type = cpu_to_le16(frame_type);
61562306a36Sopenharmony_ci		nreg->wdev = wdev;
61662306a36Sopenharmony_ci		nreg->multicast_rx = multicast_rx;
61762306a36Sopenharmony_ci		list_add(&nreg->list, &wdev->mgmt_registrations);
61862306a36Sopenharmony_ci	}
61962306a36Sopenharmony_ci	wdev->mgmt_registrations_need_update = 1;
62062306a36Sopenharmony_ci	spin_unlock_bh(&rdev->mgmt_registrations_lock);
62162306a36Sopenharmony_ci
62262306a36Sopenharmony_ci	cfg80211_mgmt_registrations_update(wdev);
62362306a36Sopenharmony_ci
62462306a36Sopenharmony_ci	return 0;
62562306a36Sopenharmony_ci
62662306a36Sopenharmony_ci out:
62762306a36Sopenharmony_ci	kfree(nreg);
62862306a36Sopenharmony_ci	spin_unlock_bh(&rdev->mgmt_registrations_lock);
62962306a36Sopenharmony_ci
63062306a36Sopenharmony_ci	return err;
63162306a36Sopenharmony_ci}
63262306a36Sopenharmony_ci
63362306a36Sopenharmony_civoid cfg80211_mlme_unregister_socket(struct wireless_dev *wdev, u32 nlportid)
63462306a36Sopenharmony_ci{
63562306a36Sopenharmony_ci	struct wiphy *wiphy = wdev->wiphy;
63662306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
63762306a36Sopenharmony_ci	struct cfg80211_mgmt_registration *reg, *tmp;
63862306a36Sopenharmony_ci
63962306a36Sopenharmony_ci	spin_lock_bh(&rdev->mgmt_registrations_lock);
64062306a36Sopenharmony_ci
64162306a36Sopenharmony_ci	list_for_each_entry_safe(reg, tmp, &wdev->mgmt_registrations, list) {
64262306a36Sopenharmony_ci		if (reg->nlportid != nlportid)
64362306a36Sopenharmony_ci			continue;
64462306a36Sopenharmony_ci
64562306a36Sopenharmony_ci		list_del(&reg->list);
64662306a36Sopenharmony_ci		kfree(reg);
64762306a36Sopenharmony_ci
64862306a36Sopenharmony_ci		wdev->mgmt_registrations_need_update = 1;
64962306a36Sopenharmony_ci		schedule_work(&rdev->mgmt_registrations_update_wk);
65062306a36Sopenharmony_ci	}
65162306a36Sopenharmony_ci
65262306a36Sopenharmony_ci	spin_unlock_bh(&rdev->mgmt_registrations_lock);
65362306a36Sopenharmony_ci
65462306a36Sopenharmony_ci	if (nlportid && rdev->crit_proto_nlportid == nlportid) {
65562306a36Sopenharmony_ci		rdev->crit_proto_nlportid = 0;
65662306a36Sopenharmony_ci		rdev_crit_proto_stop(rdev, wdev);
65762306a36Sopenharmony_ci	}
65862306a36Sopenharmony_ci
65962306a36Sopenharmony_ci	if (nlportid == wdev->ap_unexpected_nlportid)
66062306a36Sopenharmony_ci		wdev->ap_unexpected_nlportid = 0;
66162306a36Sopenharmony_ci}
66262306a36Sopenharmony_ci
66362306a36Sopenharmony_civoid cfg80211_mlme_purge_registrations(struct wireless_dev *wdev)
66462306a36Sopenharmony_ci{
66562306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
66662306a36Sopenharmony_ci	struct cfg80211_mgmt_registration *reg, *tmp;
66762306a36Sopenharmony_ci
66862306a36Sopenharmony_ci	spin_lock_bh(&rdev->mgmt_registrations_lock);
66962306a36Sopenharmony_ci	list_for_each_entry_safe(reg, tmp, &wdev->mgmt_registrations, list) {
67062306a36Sopenharmony_ci		list_del(&reg->list);
67162306a36Sopenharmony_ci		kfree(reg);
67262306a36Sopenharmony_ci	}
67362306a36Sopenharmony_ci	wdev->mgmt_registrations_need_update = 1;
67462306a36Sopenharmony_ci	spin_unlock_bh(&rdev->mgmt_registrations_lock);
67562306a36Sopenharmony_ci
67662306a36Sopenharmony_ci	cfg80211_mgmt_registrations_update(wdev);
67762306a36Sopenharmony_ci}
67862306a36Sopenharmony_ci
67962306a36Sopenharmony_cistatic bool cfg80211_allowed_address(struct wireless_dev *wdev, const u8 *addr)
68062306a36Sopenharmony_ci{
68162306a36Sopenharmony_ci	int i;
68262306a36Sopenharmony_ci
68362306a36Sopenharmony_ci	for_each_valid_link(wdev, i) {
68462306a36Sopenharmony_ci		if (ether_addr_equal(addr, wdev->links[i].addr))
68562306a36Sopenharmony_ci			return true;
68662306a36Sopenharmony_ci	}
68762306a36Sopenharmony_ci
68862306a36Sopenharmony_ci	return ether_addr_equal(addr, wdev_address(wdev));
68962306a36Sopenharmony_ci}
69062306a36Sopenharmony_ci
69162306a36Sopenharmony_cistatic bool cfg80211_allowed_random_address(struct wireless_dev *wdev,
69262306a36Sopenharmony_ci					    const struct ieee80211_mgmt *mgmt)
69362306a36Sopenharmony_ci{
69462306a36Sopenharmony_ci	if (ieee80211_is_auth(mgmt->frame_control) ||
69562306a36Sopenharmony_ci	    ieee80211_is_deauth(mgmt->frame_control)) {
69662306a36Sopenharmony_ci		/* Allow random TA to be used with authentication and
69762306a36Sopenharmony_ci		 * deauthentication frames if the driver has indicated support.
69862306a36Sopenharmony_ci		 */
69962306a36Sopenharmony_ci		if (wiphy_ext_feature_isset(
70062306a36Sopenharmony_ci			    wdev->wiphy,
70162306a36Sopenharmony_ci			    NL80211_EXT_FEATURE_AUTH_AND_DEAUTH_RANDOM_TA))
70262306a36Sopenharmony_ci			return true;
70362306a36Sopenharmony_ci	} else if (ieee80211_is_action(mgmt->frame_control) &&
70462306a36Sopenharmony_ci		   mgmt->u.action.category == WLAN_CATEGORY_PUBLIC) {
70562306a36Sopenharmony_ci		/* Allow random TA to be used with Public Action frames if the
70662306a36Sopenharmony_ci		 * driver has indicated support.
70762306a36Sopenharmony_ci		 */
70862306a36Sopenharmony_ci		if (!wdev->connected &&
70962306a36Sopenharmony_ci		    wiphy_ext_feature_isset(
71062306a36Sopenharmony_ci			    wdev->wiphy,
71162306a36Sopenharmony_ci			    NL80211_EXT_FEATURE_MGMT_TX_RANDOM_TA))
71262306a36Sopenharmony_ci			return true;
71362306a36Sopenharmony_ci
71462306a36Sopenharmony_ci		if (wdev->connected &&
71562306a36Sopenharmony_ci		    wiphy_ext_feature_isset(
71662306a36Sopenharmony_ci			    wdev->wiphy,
71762306a36Sopenharmony_ci			    NL80211_EXT_FEATURE_MGMT_TX_RANDOM_TA_CONNECTED))
71862306a36Sopenharmony_ci			return true;
71962306a36Sopenharmony_ci	}
72062306a36Sopenharmony_ci
72162306a36Sopenharmony_ci	return false;
72262306a36Sopenharmony_ci}
72362306a36Sopenharmony_ci
72462306a36Sopenharmony_ciint cfg80211_mlme_mgmt_tx(struct cfg80211_registered_device *rdev,
72562306a36Sopenharmony_ci			  struct wireless_dev *wdev,
72662306a36Sopenharmony_ci			  struct cfg80211_mgmt_tx_params *params, u64 *cookie)
72762306a36Sopenharmony_ci{
72862306a36Sopenharmony_ci	const struct ieee80211_mgmt *mgmt;
72962306a36Sopenharmony_ci	u16 stype;
73062306a36Sopenharmony_ci
73162306a36Sopenharmony_ci	if (!wdev->wiphy->mgmt_stypes)
73262306a36Sopenharmony_ci		return -EOPNOTSUPP;
73362306a36Sopenharmony_ci
73462306a36Sopenharmony_ci	if (!rdev->ops->mgmt_tx)
73562306a36Sopenharmony_ci		return -EOPNOTSUPP;
73662306a36Sopenharmony_ci
73762306a36Sopenharmony_ci	if (params->len < 24 + 1)
73862306a36Sopenharmony_ci		return -EINVAL;
73962306a36Sopenharmony_ci
74062306a36Sopenharmony_ci	mgmt = (const struct ieee80211_mgmt *)params->buf;
74162306a36Sopenharmony_ci
74262306a36Sopenharmony_ci	if (!ieee80211_is_mgmt(mgmt->frame_control))
74362306a36Sopenharmony_ci		return -EINVAL;
74462306a36Sopenharmony_ci
74562306a36Sopenharmony_ci	stype = le16_to_cpu(mgmt->frame_control) & IEEE80211_FCTL_STYPE;
74662306a36Sopenharmony_ci	if (!(wdev->wiphy->mgmt_stypes[wdev->iftype].tx & BIT(stype >> 4)))
74762306a36Sopenharmony_ci		return -EINVAL;
74862306a36Sopenharmony_ci
74962306a36Sopenharmony_ci	if (ieee80211_is_action(mgmt->frame_control) &&
75062306a36Sopenharmony_ci	    mgmt->u.action.category != WLAN_CATEGORY_PUBLIC) {
75162306a36Sopenharmony_ci		int err = 0;
75262306a36Sopenharmony_ci
75362306a36Sopenharmony_ci		wdev_lock(wdev);
75462306a36Sopenharmony_ci
75562306a36Sopenharmony_ci		switch (wdev->iftype) {
75662306a36Sopenharmony_ci		case NL80211_IFTYPE_ADHOC:
75762306a36Sopenharmony_ci			/*
75862306a36Sopenharmony_ci			 * check for IBSS DA must be done by driver as
75962306a36Sopenharmony_ci			 * cfg80211 doesn't track the stations
76062306a36Sopenharmony_ci			 */
76162306a36Sopenharmony_ci			if (!wdev->u.ibss.current_bss ||
76262306a36Sopenharmony_ci			    !ether_addr_equal(wdev->u.ibss.current_bss->pub.bssid,
76362306a36Sopenharmony_ci					      mgmt->bssid)) {
76462306a36Sopenharmony_ci				err = -ENOTCONN;
76562306a36Sopenharmony_ci				break;
76662306a36Sopenharmony_ci			}
76762306a36Sopenharmony_ci			break;
76862306a36Sopenharmony_ci		case NL80211_IFTYPE_STATION:
76962306a36Sopenharmony_ci		case NL80211_IFTYPE_P2P_CLIENT:
77062306a36Sopenharmony_ci			if (!wdev->connected) {
77162306a36Sopenharmony_ci				err = -ENOTCONN;
77262306a36Sopenharmony_ci				break;
77362306a36Sopenharmony_ci			}
77462306a36Sopenharmony_ci
77562306a36Sopenharmony_ci			/* FIXME: MLD may address this differently */
77662306a36Sopenharmony_ci
77762306a36Sopenharmony_ci			if (!ether_addr_equal(wdev->u.client.connected_addr,
77862306a36Sopenharmony_ci					      mgmt->bssid)) {
77962306a36Sopenharmony_ci				err = -ENOTCONN;
78062306a36Sopenharmony_ci				break;
78162306a36Sopenharmony_ci			}
78262306a36Sopenharmony_ci
78362306a36Sopenharmony_ci			/* for station, check that DA is the AP */
78462306a36Sopenharmony_ci			if (!ether_addr_equal(wdev->u.client.connected_addr,
78562306a36Sopenharmony_ci					      mgmt->da)) {
78662306a36Sopenharmony_ci				err = -ENOTCONN;
78762306a36Sopenharmony_ci				break;
78862306a36Sopenharmony_ci			}
78962306a36Sopenharmony_ci			break;
79062306a36Sopenharmony_ci		case NL80211_IFTYPE_AP:
79162306a36Sopenharmony_ci		case NL80211_IFTYPE_P2P_GO:
79262306a36Sopenharmony_ci		case NL80211_IFTYPE_AP_VLAN:
79362306a36Sopenharmony_ci			if (!ether_addr_equal(mgmt->bssid, wdev_address(wdev)) &&
79462306a36Sopenharmony_ci			    (params->link_id < 0 ||
79562306a36Sopenharmony_ci			     !ether_addr_equal(mgmt->bssid,
79662306a36Sopenharmony_ci					       wdev->links[params->link_id].addr)))
79762306a36Sopenharmony_ci				err = -EINVAL;
79862306a36Sopenharmony_ci			break;
79962306a36Sopenharmony_ci		case NL80211_IFTYPE_MESH_POINT:
80062306a36Sopenharmony_ci			if (!ether_addr_equal(mgmt->sa, mgmt->bssid)) {
80162306a36Sopenharmony_ci				err = -EINVAL;
80262306a36Sopenharmony_ci				break;
80362306a36Sopenharmony_ci			}
80462306a36Sopenharmony_ci			/*
80562306a36Sopenharmony_ci			 * check for mesh DA must be done by driver as
80662306a36Sopenharmony_ci			 * cfg80211 doesn't track the stations
80762306a36Sopenharmony_ci			 */
80862306a36Sopenharmony_ci			break;
80962306a36Sopenharmony_ci		case NL80211_IFTYPE_P2P_DEVICE:
81062306a36Sopenharmony_ci			/*
81162306a36Sopenharmony_ci			 * fall through, P2P device only supports
81262306a36Sopenharmony_ci			 * public action frames
81362306a36Sopenharmony_ci			 */
81462306a36Sopenharmony_ci		case NL80211_IFTYPE_NAN:
81562306a36Sopenharmony_ci		default:
81662306a36Sopenharmony_ci			err = -EOPNOTSUPP;
81762306a36Sopenharmony_ci			break;
81862306a36Sopenharmony_ci		}
81962306a36Sopenharmony_ci		wdev_unlock(wdev);
82062306a36Sopenharmony_ci
82162306a36Sopenharmony_ci		if (err)
82262306a36Sopenharmony_ci			return err;
82362306a36Sopenharmony_ci	}
82462306a36Sopenharmony_ci
82562306a36Sopenharmony_ci	if (!cfg80211_allowed_address(wdev, mgmt->sa) &&
82662306a36Sopenharmony_ci	    !cfg80211_allowed_random_address(wdev, mgmt))
82762306a36Sopenharmony_ci		return -EINVAL;
82862306a36Sopenharmony_ci
82962306a36Sopenharmony_ci	/* Transmit the management frame as requested by user space */
83062306a36Sopenharmony_ci	return rdev_mgmt_tx(rdev, wdev, params, cookie);
83162306a36Sopenharmony_ci}
83262306a36Sopenharmony_ci
83362306a36Sopenharmony_cibool cfg80211_rx_mgmt_ext(struct wireless_dev *wdev,
83462306a36Sopenharmony_ci			  struct cfg80211_rx_info *info)
83562306a36Sopenharmony_ci{
83662306a36Sopenharmony_ci	struct wiphy *wiphy = wdev->wiphy;
83762306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
83862306a36Sopenharmony_ci	struct cfg80211_mgmt_registration *reg;
83962306a36Sopenharmony_ci	const struct ieee80211_txrx_stypes *stypes =
84062306a36Sopenharmony_ci		&wiphy->mgmt_stypes[wdev->iftype];
84162306a36Sopenharmony_ci	struct ieee80211_mgmt *mgmt = (void *)info->buf;
84262306a36Sopenharmony_ci	const u8 *data;
84362306a36Sopenharmony_ci	int data_len;
84462306a36Sopenharmony_ci	bool result = false;
84562306a36Sopenharmony_ci	__le16 ftype = mgmt->frame_control &
84662306a36Sopenharmony_ci		cpu_to_le16(IEEE80211_FCTL_FTYPE | IEEE80211_FCTL_STYPE);
84762306a36Sopenharmony_ci	u16 stype;
84862306a36Sopenharmony_ci
84962306a36Sopenharmony_ci	trace_cfg80211_rx_mgmt(wdev, info);
85062306a36Sopenharmony_ci	stype = (le16_to_cpu(mgmt->frame_control) & IEEE80211_FCTL_STYPE) >> 4;
85162306a36Sopenharmony_ci
85262306a36Sopenharmony_ci	if (!(stypes->rx & BIT(stype))) {
85362306a36Sopenharmony_ci		trace_cfg80211_return_bool(false);
85462306a36Sopenharmony_ci		return false;
85562306a36Sopenharmony_ci	}
85662306a36Sopenharmony_ci
85762306a36Sopenharmony_ci	data = info->buf + ieee80211_hdrlen(mgmt->frame_control);
85862306a36Sopenharmony_ci	data_len = info->len - ieee80211_hdrlen(mgmt->frame_control);
85962306a36Sopenharmony_ci
86062306a36Sopenharmony_ci	spin_lock_bh(&rdev->mgmt_registrations_lock);
86162306a36Sopenharmony_ci
86262306a36Sopenharmony_ci	list_for_each_entry(reg, &wdev->mgmt_registrations, list) {
86362306a36Sopenharmony_ci		if (reg->frame_type != ftype)
86462306a36Sopenharmony_ci			continue;
86562306a36Sopenharmony_ci
86662306a36Sopenharmony_ci		if (reg->match_len > data_len)
86762306a36Sopenharmony_ci			continue;
86862306a36Sopenharmony_ci
86962306a36Sopenharmony_ci		if (memcmp(reg->match, data, reg->match_len))
87062306a36Sopenharmony_ci			continue;
87162306a36Sopenharmony_ci
87262306a36Sopenharmony_ci		/* found match! */
87362306a36Sopenharmony_ci
87462306a36Sopenharmony_ci		/* Indicate the received Action frame to user space */
87562306a36Sopenharmony_ci		if (nl80211_send_mgmt(rdev, wdev, reg->nlportid, info,
87662306a36Sopenharmony_ci				      GFP_ATOMIC))
87762306a36Sopenharmony_ci			continue;
87862306a36Sopenharmony_ci
87962306a36Sopenharmony_ci		result = true;
88062306a36Sopenharmony_ci		break;
88162306a36Sopenharmony_ci	}
88262306a36Sopenharmony_ci
88362306a36Sopenharmony_ci	spin_unlock_bh(&rdev->mgmt_registrations_lock);
88462306a36Sopenharmony_ci
88562306a36Sopenharmony_ci	trace_cfg80211_return_bool(result);
88662306a36Sopenharmony_ci	return result;
88762306a36Sopenharmony_ci}
88862306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_rx_mgmt_ext);
88962306a36Sopenharmony_ci
89062306a36Sopenharmony_civoid cfg80211_sched_dfs_chan_update(struct cfg80211_registered_device *rdev)
89162306a36Sopenharmony_ci{
89262306a36Sopenharmony_ci	cancel_delayed_work(&rdev->dfs_update_channels_wk);
89362306a36Sopenharmony_ci	queue_delayed_work(cfg80211_wq, &rdev->dfs_update_channels_wk, 0);
89462306a36Sopenharmony_ci}
89562306a36Sopenharmony_ci
89662306a36Sopenharmony_civoid cfg80211_dfs_channels_update_work(struct work_struct *work)
89762306a36Sopenharmony_ci{
89862306a36Sopenharmony_ci	struct delayed_work *delayed_work = to_delayed_work(work);
89962306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev;
90062306a36Sopenharmony_ci	struct cfg80211_chan_def chandef;
90162306a36Sopenharmony_ci	struct ieee80211_supported_band *sband;
90262306a36Sopenharmony_ci	struct ieee80211_channel *c;
90362306a36Sopenharmony_ci	struct wiphy *wiphy;
90462306a36Sopenharmony_ci	bool check_again = false;
90562306a36Sopenharmony_ci	unsigned long timeout, next_time = 0;
90662306a36Sopenharmony_ci	unsigned long time_dfs_update;
90762306a36Sopenharmony_ci	enum nl80211_radar_event radar_event;
90862306a36Sopenharmony_ci	int bandid, i;
90962306a36Sopenharmony_ci
91062306a36Sopenharmony_ci	rdev = container_of(delayed_work, struct cfg80211_registered_device,
91162306a36Sopenharmony_ci			    dfs_update_channels_wk);
91262306a36Sopenharmony_ci	wiphy = &rdev->wiphy;
91362306a36Sopenharmony_ci
91462306a36Sopenharmony_ci	rtnl_lock();
91562306a36Sopenharmony_ci	for (bandid = 0; bandid < NUM_NL80211_BANDS; bandid++) {
91662306a36Sopenharmony_ci		sband = wiphy->bands[bandid];
91762306a36Sopenharmony_ci		if (!sband)
91862306a36Sopenharmony_ci			continue;
91962306a36Sopenharmony_ci
92062306a36Sopenharmony_ci		for (i = 0; i < sband->n_channels; i++) {
92162306a36Sopenharmony_ci			c = &sband->channels[i];
92262306a36Sopenharmony_ci
92362306a36Sopenharmony_ci			if (!(c->flags & IEEE80211_CHAN_RADAR))
92462306a36Sopenharmony_ci				continue;
92562306a36Sopenharmony_ci
92662306a36Sopenharmony_ci			if (c->dfs_state != NL80211_DFS_UNAVAILABLE &&
92762306a36Sopenharmony_ci			    c->dfs_state != NL80211_DFS_AVAILABLE)
92862306a36Sopenharmony_ci				continue;
92962306a36Sopenharmony_ci
93062306a36Sopenharmony_ci			if (c->dfs_state == NL80211_DFS_UNAVAILABLE) {
93162306a36Sopenharmony_ci				time_dfs_update = IEEE80211_DFS_MIN_NOP_TIME_MS;
93262306a36Sopenharmony_ci				radar_event = NL80211_RADAR_NOP_FINISHED;
93362306a36Sopenharmony_ci			} else {
93462306a36Sopenharmony_ci				if (regulatory_pre_cac_allowed(wiphy) ||
93562306a36Sopenharmony_ci				    cfg80211_any_wiphy_oper_chan(wiphy, c))
93662306a36Sopenharmony_ci					continue;
93762306a36Sopenharmony_ci
93862306a36Sopenharmony_ci				time_dfs_update = REG_PRE_CAC_EXPIRY_GRACE_MS;
93962306a36Sopenharmony_ci				radar_event = NL80211_RADAR_PRE_CAC_EXPIRED;
94062306a36Sopenharmony_ci			}
94162306a36Sopenharmony_ci
94262306a36Sopenharmony_ci			timeout = c->dfs_state_entered +
94362306a36Sopenharmony_ci				  msecs_to_jiffies(time_dfs_update);
94462306a36Sopenharmony_ci
94562306a36Sopenharmony_ci			if (time_after_eq(jiffies, timeout)) {
94662306a36Sopenharmony_ci				c->dfs_state = NL80211_DFS_USABLE;
94762306a36Sopenharmony_ci				c->dfs_state_entered = jiffies;
94862306a36Sopenharmony_ci
94962306a36Sopenharmony_ci				cfg80211_chandef_create(&chandef, c,
95062306a36Sopenharmony_ci							NL80211_CHAN_NO_HT);
95162306a36Sopenharmony_ci
95262306a36Sopenharmony_ci				nl80211_radar_notify(rdev, &chandef,
95362306a36Sopenharmony_ci						     radar_event, NULL,
95462306a36Sopenharmony_ci						     GFP_ATOMIC);
95562306a36Sopenharmony_ci
95662306a36Sopenharmony_ci				regulatory_propagate_dfs_state(wiphy, &chandef,
95762306a36Sopenharmony_ci							       c->dfs_state,
95862306a36Sopenharmony_ci							       radar_event);
95962306a36Sopenharmony_ci				continue;
96062306a36Sopenharmony_ci			}
96162306a36Sopenharmony_ci
96262306a36Sopenharmony_ci			if (!check_again)
96362306a36Sopenharmony_ci				next_time = timeout - jiffies;
96462306a36Sopenharmony_ci			else
96562306a36Sopenharmony_ci				next_time = min(next_time, timeout - jiffies);
96662306a36Sopenharmony_ci			check_again = true;
96762306a36Sopenharmony_ci		}
96862306a36Sopenharmony_ci	}
96962306a36Sopenharmony_ci	rtnl_unlock();
97062306a36Sopenharmony_ci
97162306a36Sopenharmony_ci	/* reschedule if there are other channels waiting to be cleared again */
97262306a36Sopenharmony_ci	if (check_again)
97362306a36Sopenharmony_ci		queue_delayed_work(cfg80211_wq, &rdev->dfs_update_channels_wk,
97462306a36Sopenharmony_ci				   next_time);
97562306a36Sopenharmony_ci}
97662306a36Sopenharmony_ci
97762306a36Sopenharmony_ci
97862306a36Sopenharmony_civoid __cfg80211_radar_event(struct wiphy *wiphy,
97962306a36Sopenharmony_ci			    struct cfg80211_chan_def *chandef,
98062306a36Sopenharmony_ci			    bool offchan, gfp_t gfp)
98162306a36Sopenharmony_ci{
98262306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
98362306a36Sopenharmony_ci
98462306a36Sopenharmony_ci	trace_cfg80211_radar_event(wiphy, chandef, offchan);
98562306a36Sopenharmony_ci
98662306a36Sopenharmony_ci	/* only set the chandef supplied channel to unavailable, in
98762306a36Sopenharmony_ci	 * case the radar is detected on only one of multiple channels
98862306a36Sopenharmony_ci	 * spanned by the chandef.
98962306a36Sopenharmony_ci	 */
99062306a36Sopenharmony_ci	cfg80211_set_dfs_state(wiphy, chandef, NL80211_DFS_UNAVAILABLE);
99162306a36Sopenharmony_ci
99262306a36Sopenharmony_ci	if (offchan)
99362306a36Sopenharmony_ci		queue_work(cfg80211_wq, &rdev->background_cac_abort_wk);
99462306a36Sopenharmony_ci
99562306a36Sopenharmony_ci	cfg80211_sched_dfs_chan_update(rdev);
99662306a36Sopenharmony_ci
99762306a36Sopenharmony_ci	nl80211_radar_notify(rdev, chandef, NL80211_RADAR_DETECTED, NULL, gfp);
99862306a36Sopenharmony_ci
99962306a36Sopenharmony_ci	memcpy(&rdev->radar_chandef, chandef, sizeof(struct cfg80211_chan_def));
100062306a36Sopenharmony_ci	queue_work(cfg80211_wq, &rdev->propagate_radar_detect_wk);
100162306a36Sopenharmony_ci}
100262306a36Sopenharmony_ciEXPORT_SYMBOL(__cfg80211_radar_event);
100362306a36Sopenharmony_ci
100462306a36Sopenharmony_civoid cfg80211_cac_event(struct net_device *netdev,
100562306a36Sopenharmony_ci			const struct cfg80211_chan_def *chandef,
100662306a36Sopenharmony_ci			enum nl80211_radar_event event, gfp_t gfp)
100762306a36Sopenharmony_ci{
100862306a36Sopenharmony_ci	struct wireless_dev *wdev = netdev->ieee80211_ptr;
100962306a36Sopenharmony_ci	struct wiphy *wiphy = wdev->wiphy;
101062306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
101162306a36Sopenharmony_ci	unsigned long timeout;
101262306a36Sopenharmony_ci
101362306a36Sopenharmony_ci	/* not yet supported */
101462306a36Sopenharmony_ci	if (wdev->valid_links)
101562306a36Sopenharmony_ci		return;
101662306a36Sopenharmony_ci
101762306a36Sopenharmony_ci	trace_cfg80211_cac_event(netdev, event);
101862306a36Sopenharmony_ci
101962306a36Sopenharmony_ci	if (WARN_ON(!wdev->cac_started && event != NL80211_RADAR_CAC_STARTED))
102062306a36Sopenharmony_ci		return;
102162306a36Sopenharmony_ci
102262306a36Sopenharmony_ci	switch (event) {
102362306a36Sopenharmony_ci	case NL80211_RADAR_CAC_FINISHED:
102462306a36Sopenharmony_ci		timeout = wdev->cac_start_time +
102562306a36Sopenharmony_ci			  msecs_to_jiffies(wdev->cac_time_ms);
102662306a36Sopenharmony_ci		WARN_ON(!time_after_eq(jiffies, timeout));
102762306a36Sopenharmony_ci		cfg80211_set_dfs_state(wiphy, chandef, NL80211_DFS_AVAILABLE);
102862306a36Sopenharmony_ci		memcpy(&rdev->cac_done_chandef, chandef,
102962306a36Sopenharmony_ci		       sizeof(struct cfg80211_chan_def));
103062306a36Sopenharmony_ci		queue_work(cfg80211_wq, &rdev->propagate_cac_done_wk);
103162306a36Sopenharmony_ci		cfg80211_sched_dfs_chan_update(rdev);
103262306a36Sopenharmony_ci		fallthrough;
103362306a36Sopenharmony_ci	case NL80211_RADAR_CAC_ABORTED:
103462306a36Sopenharmony_ci		wdev->cac_started = false;
103562306a36Sopenharmony_ci		break;
103662306a36Sopenharmony_ci	case NL80211_RADAR_CAC_STARTED:
103762306a36Sopenharmony_ci		wdev->cac_started = true;
103862306a36Sopenharmony_ci		break;
103962306a36Sopenharmony_ci	default:
104062306a36Sopenharmony_ci		WARN_ON(1);
104162306a36Sopenharmony_ci		return;
104262306a36Sopenharmony_ci	}
104362306a36Sopenharmony_ci
104462306a36Sopenharmony_ci	nl80211_radar_notify(rdev, chandef, event, netdev, gfp);
104562306a36Sopenharmony_ci}
104662306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_cac_event);
104762306a36Sopenharmony_ci
104862306a36Sopenharmony_cistatic void
104962306a36Sopenharmony_ci__cfg80211_background_cac_event(struct cfg80211_registered_device *rdev,
105062306a36Sopenharmony_ci				struct wireless_dev *wdev,
105162306a36Sopenharmony_ci				const struct cfg80211_chan_def *chandef,
105262306a36Sopenharmony_ci				enum nl80211_radar_event event)
105362306a36Sopenharmony_ci{
105462306a36Sopenharmony_ci	struct wiphy *wiphy = &rdev->wiphy;
105562306a36Sopenharmony_ci	struct net_device *netdev;
105662306a36Sopenharmony_ci
105762306a36Sopenharmony_ci	lockdep_assert_wiphy(&rdev->wiphy);
105862306a36Sopenharmony_ci
105962306a36Sopenharmony_ci	if (!cfg80211_chandef_valid(chandef))
106062306a36Sopenharmony_ci		return;
106162306a36Sopenharmony_ci
106262306a36Sopenharmony_ci	if (!rdev->background_radar_wdev)
106362306a36Sopenharmony_ci		return;
106462306a36Sopenharmony_ci
106562306a36Sopenharmony_ci	switch (event) {
106662306a36Sopenharmony_ci	case NL80211_RADAR_CAC_FINISHED:
106762306a36Sopenharmony_ci		cfg80211_set_dfs_state(wiphy, chandef, NL80211_DFS_AVAILABLE);
106862306a36Sopenharmony_ci		memcpy(&rdev->cac_done_chandef, chandef, sizeof(*chandef));
106962306a36Sopenharmony_ci		queue_work(cfg80211_wq, &rdev->propagate_cac_done_wk);
107062306a36Sopenharmony_ci		cfg80211_sched_dfs_chan_update(rdev);
107162306a36Sopenharmony_ci		wdev = rdev->background_radar_wdev;
107262306a36Sopenharmony_ci		break;
107362306a36Sopenharmony_ci	case NL80211_RADAR_CAC_ABORTED:
107462306a36Sopenharmony_ci		if (!cancel_delayed_work(&rdev->background_cac_done_wk))
107562306a36Sopenharmony_ci			return;
107662306a36Sopenharmony_ci		wdev = rdev->background_radar_wdev;
107762306a36Sopenharmony_ci		break;
107862306a36Sopenharmony_ci	case NL80211_RADAR_CAC_STARTED:
107962306a36Sopenharmony_ci		break;
108062306a36Sopenharmony_ci	default:
108162306a36Sopenharmony_ci		return;
108262306a36Sopenharmony_ci	}
108362306a36Sopenharmony_ci
108462306a36Sopenharmony_ci	netdev = wdev ? wdev->netdev : NULL;
108562306a36Sopenharmony_ci	nl80211_radar_notify(rdev, chandef, event, netdev, GFP_KERNEL);
108662306a36Sopenharmony_ci}
108762306a36Sopenharmony_ci
108862306a36Sopenharmony_cistatic void
108962306a36Sopenharmony_cicfg80211_background_cac_event(struct cfg80211_registered_device *rdev,
109062306a36Sopenharmony_ci			      const struct cfg80211_chan_def *chandef,
109162306a36Sopenharmony_ci			      enum nl80211_radar_event event)
109262306a36Sopenharmony_ci{
109362306a36Sopenharmony_ci	wiphy_lock(&rdev->wiphy);
109462306a36Sopenharmony_ci	__cfg80211_background_cac_event(rdev, rdev->background_radar_wdev,
109562306a36Sopenharmony_ci					chandef, event);
109662306a36Sopenharmony_ci	wiphy_unlock(&rdev->wiphy);
109762306a36Sopenharmony_ci}
109862306a36Sopenharmony_ci
109962306a36Sopenharmony_civoid cfg80211_background_cac_done_wk(struct work_struct *work)
110062306a36Sopenharmony_ci{
110162306a36Sopenharmony_ci	struct delayed_work *delayed_work = to_delayed_work(work);
110262306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev;
110362306a36Sopenharmony_ci
110462306a36Sopenharmony_ci	rdev = container_of(delayed_work, struct cfg80211_registered_device,
110562306a36Sopenharmony_ci			    background_cac_done_wk);
110662306a36Sopenharmony_ci	cfg80211_background_cac_event(rdev, &rdev->background_radar_chandef,
110762306a36Sopenharmony_ci				      NL80211_RADAR_CAC_FINISHED);
110862306a36Sopenharmony_ci}
110962306a36Sopenharmony_ci
111062306a36Sopenharmony_civoid cfg80211_background_cac_abort_wk(struct work_struct *work)
111162306a36Sopenharmony_ci{
111262306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev;
111362306a36Sopenharmony_ci
111462306a36Sopenharmony_ci	rdev = container_of(work, struct cfg80211_registered_device,
111562306a36Sopenharmony_ci			    background_cac_abort_wk);
111662306a36Sopenharmony_ci	cfg80211_background_cac_event(rdev, &rdev->background_radar_chandef,
111762306a36Sopenharmony_ci				      NL80211_RADAR_CAC_ABORTED);
111862306a36Sopenharmony_ci}
111962306a36Sopenharmony_ci
112062306a36Sopenharmony_civoid cfg80211_background_cac_abort(struct wiphy *wiphy)
112162306a36Sopenharmony_ci{
112262306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
112362306a36Sopenharmony_ci
112462306a36Sopenharmony_ci	queue_work(cfg80211_wq, &rdev->background_cac_abort_wk);
112562306a36Sopenharmony_ci}
112662306a36Sopenharmony_ciEXPORT_SYMBOL(cfg80211_background_cac_abort);
112762306a36Sopenharmony_ci
112862306a36Sopenharmony_ciint
112962306a36Sopenharmony_cicfg80211_start_background_radar_detection(struct cfg80211_registered_device *rdev,
113062306a36Sopenharmony_ci					  struct wireless_dev *wdev,
113162306a36Sopenharmony_ci					  struct cfg80211_chan_def *chandef)
113262306a36Sopenharmony_ci{
113362306a36Sopenharmony_ci	unsigned int cac_time_ms;
113462306a36Sopenharmony_ci	int err;
113562306a36Sopenharmony_ci
113662306a36Sopenharmony_ci	lockdep_assert_wiphy(&rdev->wiphy);
113762306a36Sopenharmony_ci
113862306a36Sopenharmony_ci	if (!wiphy_ext_feature_isset(&rdev->wiphy,
113962306a36Sopenharmony_ci				     NL80211_EXT_FEATURE_RADAR_BACKGROUND))
114062306a36Sopenharmony_ci		return -EOPNOTSUPP;
114162306a36Sopenharmony_ci
114262306a36Sopenharmony_ci	/* Offchannel chain already locked by another wdev */
114362306a36Sopenharmony_ci	if (rdev->background_radar_wdev && rdev->background_radar_wdev != wdev)
114462306a36Sopenharmony_ci		return -EBUSY;
114562306a36Sopenharmony_ci
114662306a36Sopenharmony_ci	/* CAC already in progress on the offchannel chain */
114762306a36Sopenharmony_ci	if (rdev->background_radar_wdev == wdev &&
114862306a36Sopenharmony_ci	    delayed_work_pending(&rdev->background_cac_done_wk))
114962306a36Sopenharmony_ci		return -EBUSY;
115062306a36Sopenharmony_ci
115162306a36Sopenharmony_ci	err = rdev_set_radar_background(rdev, chandef);
115262306a36Sopenharmony_ci	if (err)
115362306a36Sopenharmony_ci		return err;
115462306a36Sopenharmony_ci
115562306a36Sopenharmony_ci	cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, chandef);
115662306a36Sopenharmony_ci	if (!cac_time_ms)
115762306a36Sopenharmony_ci		cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS;
115862306a36Sopenharmony_ci
115962306a36Sopenharmony_ci	rdev->background_radar_chandef = *chandef;
116062306a36Sopenharmony_ci	rdev->background_radar_wdev = wdev; /* Get offchain ownership */
116162306a36Sopenharmony_ci
116262306a36Sopenharmony_ci	__cfg80211_background_cac_event(rdev, wdev, chandef,
116362306a36Sopenharmony_ci					NL80211_RADAR_CAC_STARTED);
116462306a36Sopenharmony_ci	queue_delayed_work(cfg80211_wq, &rdev->background_cac_done_wk,
116562306a36Sopenharmony_ci			   msecs_to_jiffies(cac_time_ms));
116662306a36Sopenharmony_ci
116762306a36Sopenharmony_ci	return 0;
116862306a36Sopenharmony_ci}
116962306a36Sopenharmony_ci
117062306a36Sopenharmony_civoid cfg80211_stop_background_radar_detection(struct wireless_dev *wdev)
117162306a36Sopenharmony_ci{
117262306a36Sopenharmony_ci	struct wiphy *wiphy = wdev->wiphy;
117362306a36Sopenharmony_ci	struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
117462306a36Sopenharmony_ci
117562306a36Sopenharmony_ci	lockdep_assert_wiphy(wiphy);
117662306a36Sopenharmony_ci
117762306a36Sopenharmony_ci	if (wdev != rdev->background_radar_wdev)
117862306a36Sopenharmony_ci		return;
117962306a36Sopenharmony_ci
118062306a36Sopenharmony_ci	rdev_set_radar_background(rdev, NULL);
118162306a36Sopenharmony_ci	rdev->background_radar_wdev = NULL; /* Release offchain ownership */
118262306a36Sopenharmony_ci
118362306a36Sopenharmony_ci	__cfg80211_background_cac_event(rdev, wdev,
118462306a36Sopenharmony_ci					&rdev->background_radar_chandef,
118562306a36Sopenharmony_ci					NL80211_RADAR_CAC_ABORTED);
118662306a36Sopenharmony_ci}
1187