xref: /netbsd-src/external/bsd/wpa/dist/src/drivers/driver_nl80211.c (revision bdc22b2e01993381dcefeff2bc9b56ca75a4235c)
1 /*
2  * Driver interaction with Linux nl80211/cfg80211
3  * Copyright (c) 2002-2015, Jouni Malinen <j@w1.fi>
4  * Copyright (c) 2003-2004, Instant802 Networks, Inc.
5  * Copyright (c) 2005-2006, Devicescape Software, Inc.
6  * Copyright (c) 2007, Johannes Berg <johannes@sipsolutions.net>
7  * Copyright (c) 2009-2010, Atheros Communications
8  *
9  * This software may be distributed under the terms of the BSD license.
10  * See README for more details.
11  */
12 
13 #include "includes.h"
14 #include <sys/types.h>
15 #include <fcntl.h>
16 #include <net/if.h>
17 #include <netlink/genl/genl.h>
18 #include <netlink/genl/ctrl.h>
19 #ifdef CONFIG_LIBNL3_ROUTE
20 #include <netlink/route/neighbour.h>
21 #endif /* CONFIG_LIBNL3_ROUTE */
22 #include <linux/rtnetlink.h>
23 #include <netpacket/packet.h>
24 #include <linux/errqueue.h>
25 
26 #include "common.h"
27 #include "eloop.h"
28 #include "common/qca-vendor.h"
29 #include "common/qca-vendor-attr.h"
30 #include "common/ieee802_11_defs.h"
31 #include "common/ieee802_11_common.h"
32 #include "l2_packet/l2_packet.h"
33 #include "netlink.h"
34 #include "linux_defines.h"
35 #include "linux_ioctl.h"
36 #include "radiotap.h"
37 #include "radiotap_iter.h"
38 #include "rfkill.h"
39 #include "driver_nl80211.h"
40 
41 
42 #ifndef CONFIG_LIBNL20
43 /*
44  * libnl 1.1 has a bug, it tries to allocate socket numbers densely
45  * but when you free a socket again it will mess up its bitmap and
46  * and use the wrong number the next time it needs a socket ID.
47  * Therefore, we wrap the handle alloc/destroy and add our own pid
48  * accounting.
49  */
50 static uint32_t port_bitmap[32] = { 0 };
51 
52 static struct nl_handle *nl80211_handle_alloc(void *cb)
53 {
54 	struct nl_handle *handle;
55 	uint32_t pid = getpid() & 0x3FFFFF;
56 	int i;
57 
58 	handle = nl_handle_alloc_cb(cb);
59 
60 	for (i = 0; i < 1024; i++) {
61 		if (port_bitmap[i / 32] & (1 << (i % 32)))
62 			continue;
63 		port_bitmap[i / 32] |= 1 << (i % 32);
64 		pid += i << 22;
65 		break;
66 	}
67 
68 	nl_socket_set_local_port(handle, pid);
69 
70 	return handle;
71 }
72 
73 static void nl80211_handle_destroy(struct nl_handle *handle)
74 {
75 	uint32_t port = nl_socket_get_local_port(handle);
76 
77 	port >>= 22;
78 	port_bitmap[port / 32] &= ~(1 << (port % 32));
79 
80 	nl_handle_destroy(handle);
81 }
82 #endif /* CONFIG_LIBNL20 */
83 
84 
85 #ifdef ANDROID
86 /* system/core/libnl_2 does not include nl_socket_set_nonblocking() */
87 #undef nl_socket_set_nonblocking
88 #define nl_socket_set_nonblocking(h) android_nl_socket_set_nonblocking(h)
89 
90 #endif /* ANDROID */
91 
92 
93 static struct nl_handle * nl_create_handle(struct nl_cb *cb, const char *dbg)
94 {
95 	struct nl_handle *handle;
96 
97 	handle = nl80211_handle_alloc(cb);
98 	if (handle == NULL) {
99 		wpa_printf(MSG_ERROR, "nl80211: Failed to allocate netlink "
100 			   "callbacks (%s)", dbg);
101 		return NULL;
102 	}
103 
104 	if (genl_connect(handle)) {
105 		wpa_printf(MSG_ERROR, "nl80211: Failed to connect to generic "
106 			   "netlink (%s)", dbg);
107 		nl80211_handle_destroy(handle);
108 		return NULL;
109 	}
110 
111 	return handle;
112 }
113 
114 
115 static void nl_destroy_handles(struct nl_handle **handle)
116 {
117 	if (*handle == NULL)
118 		return;
119 	nl80211_handle_destroy(*handle);
120 	*handle = NULL;
121 }
122 
123 
124 #if __WORDSIZE == 64
125 #define ELOOP_SOCKET_INVALID	(intptr_t) 0x8888888888888889ULL
126 #else
127 #define ELOOP_SOCKET_INVALID	(intptr_t) 0x88888889ULL
128 #endif
129 
130 static void nl80211_register_eloop_read(struct nl_handle **handle,
131 					eloop_sock_handler handler,
132 					void *eloop_data)
133 {
134 #ifdef CONFIG_LIBNL20
135 	/*
136 	 * libnl uses a pretty small buffer (32 kB that gets converted to 64 kB)
137 	 * by default. It is possible to hit that limit in some cases where
138 	 * operations are blocked, e.g., with a burst of Deauthentication frames
139 	 * to hostapd and STA entry deletion. Try to increase the buffer to make
140 	 * this less likely to occur.
141 	 */
142 	if (nl_socket_set_buffer_size(*handle, 262144, 0) < 0) {
143 		wpa_printf(MSG_DEBUG,
144 			   "nl80211: Could not set nl_socket RX buffer size: %s",
145 			   strerror(errno));
146 		/* continue anyway with the default (smaller) buffer */
147 	}
148 #endif /* CONFIG_LIBNL20 */
149 
150 	nl_socket_set_nonblocking(*handle);
151 	eloop_register_read_sock(nl_socket_get_fd(*handle), handler,
152 				 eloop_data, *handle);
153 	*handle = (void *) (((intptr_t) *handle) ^ ELOOP_SOCKET_INVALID);
154 }
155 
156 
157 static void nl80211_destroy_eloop_handle(struct nl_handle **handle)
158 {
159 	*handle = (void *) (((intptr_t) *handle) ^ ELOOP_SOCKET_INVALID);
160 	eloop_unregister_read_sock(nl_socket_get_fd(*handle));
161 	nl_destroy_handles(handle);
162 }
163 
164 
165 static void nl80211_global_deinit(void *priv);
166 static void nl80211_check_global(struct nl80211_global *global);
167 
168 static void wpa_driver_nl80211_deinit(struct i802_bss *bss);
169 static int wpa_driver_nl80211_set_mode_ibss(struct i802_bss *bss,
170 					    struct hostapd_freq_params *freq);
171 
172 static int
173 wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data *drv,
174 				   const u8 *set_addr, int first,
175 				   const char *driver_params);
176 static int nl80211_send_frame_cmd(struct i802_bss *bss,
177 				  unsigned int freq, unsigned int wait,
178 				  const u8 *buf, size_t buf_len, u64 *cookie,
179 				  int no_cck, int no_ack, int offchanok,
180 				  const u16 *csa_offs, size_t csa_offs_len);
181 static int wpa_driver_nl80211_probe_req_report(struct i802_bss *bss,
182 					       int report);
183 
184 #define IFIDX_ANY -1
185 
186 static void add_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx,
187 		      int ifidx_reason);
188 static void del_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx,
189 		      int ifidx_reason);
190 static int have_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx,
191 		      int ifidx_reason);
192 
193 static int nl80211_set_channel(struct i802_bss *bss,
194 			       struct hostapd_freq_params *freq, int set_chan);
195 static int nl80211_disable_11b_rates(struct wpa_driver_nl80211_data *drv,
196 				     int ifindex, int disabled);
197 
198 static int nl80211_leave_ibss(struct wpa_driver_nl80211_data *drv,
199 			      int reset_mode);
200 
201 static int i802_set_iface_flags(struct i802_bss *bss, int up);
202 static int nl80211_set_param(void *priv, const char *param);
203 #ifdef CONFIG_MESH
204 static int nl80211_put_mesh_config(struct nl_msg *msg,
205 				   struct wpa_driver_mesh_bss_params *params);
206 #endif /* CONFIG_MESH */
207 
208 
209 /* Converts nl80211_chan_width to a common format */
210 enum chan_width convert2width(int width)
211 {
212 	switch (width) {
213 	case NL80211_CHAN_WIDTH_20_NOHT:
214 		return CHAN_WIDTH_20_NOHT;
215 	case NL80211_CHAN_WIDTH_20:
216 		return CHAN_WIDTH_20;
217 	case NL80211_CHAN_WIDTH_40:
218 		return CHAN_WIDTH_40;
219 	case NL80211_CHAN_WIDTH_80:
220 		return CHAN_WIDTH_80;
221 	case NL80211_CHAN_WIDTH_80P80:
222 		return CHAN_WIDTH_80P80;
223 	case NL80211_CHAN_WIDTH_160:
224 		return CHAN_WIDTH_160;
225 	}
226 	return CHAN_WIDTH_UNKNOWN;
227 }
228 
229 
230 int is_ap_interface(enum nl80211_iftype nlmode)
231 {
232 	return nlmode == NL80211_IFTYPE_AP ||
233 		nlmode == NL80211_IFTYPE_P2P_GO;
234 }
235 
236 
237 int is_sta_interface(enum nl80211_iftype nlmode)
238 {
239 	return nlmode == NL80211_IFTYPE_STATION ||
240 		nlmode == NL80211_IFTYPE_P2P_CLIENT;
241 }
242 
243 
244 static int is_p2p_net_interface(enum nl80211_iftype nlmode)
245 {
246 	return nlmode == NL80211_IFTYPE_P2P_CLIENT ||
247 		nlmode == NL80211_IFTYPE_P2P_GO;
248 }
249 
250 
251 struct i802_bss * get_bss_ifindex(struct wpa_driver_nl80211_data *drv,
252 				  int ifindex)
253 {
254 	struct i802_bss *bss;
255 
256 	for (bss = drv->first_bss; bss; bss = bss->next) {
257 		if (bss->ifindex == ifindex)
258 			return bss;
259 	}
260 
261 	return NULL;
262 }
263 
264 
265 static int is_mesh_interface(enum nl80211_iftype nlmode)
266 {
267 	return nlmode == NL80211_IFTYPE_MESH_POINT;
268 }
269 
270 
271 void nl80211_mark_disconnected(struct wpa_driver_nl80211_data *drv)
272 {
273 	if (drv->associated)
274 		os_memcpy(drv->prev_bssid, drv->bssid, ETH_ALEN);
275 	drv->associated = 0;
276 	os_memset(drv->bssid, 0, ETH_ALEN);
277 }
278 
279 
280 /* nl80211 code */
281 static int ack_handler(struct nl_msg *msg, void *arg)
282 {
283 	int *err = arg;
284 	*err = 0;
285 	return NL_STOP;
286 }
287 
288 static int finish_handler(struct nl_msg *msg, void *arg)
289 {
290 	int *ret = arg;
291 	*ret = 0;
292 	return NL_SKIP;
293 }
294 
295 static int error_handler(struct sockaddr_nl *nla, struct nlmsgerr *err,
296 			 void *arg)
297 {
298 	int *ret = arg;
299 	*ret = err->error;
300 	return NL_SKIP;
301 }
302 
303 
304 static int no_seq_check(struct nl_msg *msg, void *arg)
305 {
306 	return NL_OK;
307 }
308 
309 
310 static void nl80211_nlmsg_clear(struct nl_msg *msg)
311 {
312 	/*
313 	 * Clear nlmsg data, e.g., to make sure key material is not left in
314 	 * heap memory for unnecessarily long time.
315 	 */
316 	if (msg) {
317 		struct nlmsghdr *hdr = nlmsg_hdr(msg);
318 		void *data = nlmsg_data(hdr);
319 		/*
320 		 * This would use nlmsg_datalen() or the older nlmsg_len() if
321 		 * only libnl were to maintain a stable API.. Neither will work
322 		 * with all released versions, so just calculate the length
323 		 * here.
324 		 */
325 		int len = hdr->nlmsg_len - NLMSG_HDRLEN;
326 
327 		os_memset(data, 0, len);
328 	}
329 }
330 
331 
332 static int send_and_recv(struct nl80211_global *global,
333 			 struct nl_handle *nl_handle, struct nl_msg *msg,
334 			 int (*valid_handler)(struct nl_msg *, void *),
335 			 void *valid_data)
336 {
337 	struct nl_cb *cb;
338 	int err = -ENOMEM;
339 
340 	if (!msg)
341 		return -ENOMEM;
342 
343 	cb = nl_cb_clone(global->nl_cb);
344 	if (!cb)
345 		goto out;
346 
347 	err = nl_send_auto_complete(nl_handle, msg);
348 	if (err < 0)
349 		goto out;
350 
351 	err = 1;
352 
353 	nl_cb_err(cb, NL_CB_CUSTOM, error_handler, &err);
354 	nl_cb_set(cb, NL_CB_FINISH, NL_CB_CUSTOM, finish_handler, &err);
355 	nl_cb_set(cb, NL_CB_ACK, NL_CB_CUSTOM, ack_handler, &err);
356 
357 	if (valid_handler)
358 		nl_cb_set(cb, NL_CB_VALID, NL_CB_CUSTOM,
359 			  valid_handler, valid_data);
360 
361 	while (err > 0) {
362 		int res = nl_recvmsgs(nl_handle, cb);
363 		if (res < 0) {
364 			wpa_printf(MSG_INFO,
365 				   "nl80211: %s->nl_recvmsgs failed: %d",
366 				   __func__, res);
367 		}
368 	}
369  out:
370 	nl_cb_put(cb);
371 	if (!valid_handler && valid_data == (void *) -1)
372 		nl80211_nlmsg_clear(msg);
373 	nlmsg_free(msg);
374 	return err;
375 }
376 
377 
378 int send_and_recv_msgs(struct wpa_driver_nl80211_data *drv,
379 		       struct nl_msg *msg,
380 		       int (*valid_handler)(struct nl_msg *, void *),
381 		       void *valid_data)
382 {
383 	return send_and_recv(drv->global, drv->global->nl, msg,
384 			     valid_handler, valid_data);
385 }
386 
387 
388 struct family_data {
389 	const char *group;
390 	int id;
391 };
392 
393 
394 static int family_handler(struct nl_msg *msg, void *arg)
395 {
396 	struct family_data *res = arg;
397 	struct nlattr *tb[CTRL_ATTR_MAX + 1];
398 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
399 	struct nlattr *mcgrp;
400 	int i;
401 
402 	nla_parse(tb, CTRL_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
403 		  genlmsg_attrlen(gnlh, 0), NULL);
404 	if (!tb[CTRL_ATTR_MCAST_GROUPS])
405 		return NL_SKIP;
406 
407 	nla_for_each_nested(mcgrp, tb[CTRL_ATTR_MCAST_GROUPS], i) {
408 		struct nlattr *tb2[CTRL_ATTR_MCAST_GRP_MAX + 1];
409 		nla_parse(tb2, CTRL_ATTR_MCAST_GRP_MAX, nla_data(mcgrp),
410 			  nla_len(mcgrp), NULL);
411 		if (!tb2[CTRL_ATTR_MCAST_GRP_NAME] ||
412 		    !tb2[CTRL_ATTR_MCAST_GRP_ID] ||
413 		    os_strncmp(nla_data(tb2[CTRL_ATTR_MCAST_GRP_NAME]),
414 			       res->group,
415 			       nla_len(tb2[CTRL_ATTR_MCAST_GRP_NAME])) != 0)
416 			continue;
417 		res->id = nla_get_u32(tb2[CTRL_ATTR_MCAST_GRP_ID]);
418 		break;
419 	};
420 
421 	return NL_SKIP;
422 }
423 
424 
425 static int nl_get_multicast_id(struct nl80211_global *global,
426 			       const char *family, const char *group)
427 {
428 	struct nl_msg *msg;
429 	int ret;
430 	struct family_data res = { group, -ENOENT };
431 
432 	msg = nlmsg_alloc();
433 	if (!msg)
434 		return -ENOMEM;
435 	if (!genlmsg_put(msg, 0, 0, genl_ctrl_resolve(global->nl, "nlctrl"),
436 			 0, 0, CTRL_CMD_GETFAMILY, 0) ||
437 	    nla_put_string(msg, CTRL_ATTR_FAMILY_NAME, family)) {
438 		nlmsg_free(msg);
439 		return -1;
440 	}
441 
442 	ret = send_and_recv(global, global->nl, msg, family_handler, &res);
443 	if (ret == 0)
444 		ret = res.id;
445 	return ret;
446 }
447 
448 
449 void * nl80211_cmd(struct wpa_driver_nl80211_data *drv,
450 		   struct nl_msg *msg, int flags, uint8_t cmd)
451 {
452 	if (TEST_FAIL())
453 		return NULL;
454 	return genlmsg_put(msg, 0, 0, drv->global->nl80211_id,
455 			   0, flags, cmd, 0);
456 }
457 
458 
459 static int nl80211_set_iface_id(struct nl_msg *msg, struct i802_bss *bss)
460 {
461 	if (bss->wdev_id_set)
462 		return nla_put_u64(msg, NL80211_ATTR_WDEV, bss->wdev_id);
463 	return nla_put_u32(msg, NL80211_ATTR_IFINDEX, bss->ifindex);
464 }
465 
466 
467 struct nl_msg * nl80211_cmd_msg(struct i802_bss *bss, int flags, uint8_t cmd)
468 {
469 	struct nl_msg *msg;
470 
471 	msg = nlmsg_alloc();
472 	if (!msg)
473 		return NULL;
474 
475 	if (!nl80211_cmd(bss->drv, msg, flags, cmd) ||
476 	    nl80211_set_iface_id(msg, bss) < 0) {
477 		nlmsg_free(msg);
478 		return NULL;
479 	}
480 
481 	return msg;
482 }
483 
484 
485 static struct nl_msg *
486 nl80211_ifindex_msg(struct wpa_driver_nl80211_data *drv, int ifindex,
487 		    int flags, uint8_t cmd)
488 {
489 	struct nl_msg *msg;
490 
491 	msg = nlmsg_alloc();
492 	if (!msg)
493 		return NULL;
494 
495 	if (!nl80211_cmd(drv, msg, flags, cmd) ||
496 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, ifindex)) {
497 		nlmsg_free(msg);
498 		return NULL;
499 	}
500 
501 	return msg;
502 }
503 
504 
505 struct nl_msg * nl80211_drv_msg(struct wpa_driver_nl80211_data *drv, int flags,
506 				uint8_t cmd)
507 {
508 	return nl80211_ifindex_msg(drv, drv->ifindex, flags, cmd);
509 }
510 
511 
512 struct nl_msg * nl80211_bss_msg(struct i802_bss *bss, int flags, uint8_t cmd)
513 {
514 	return nl80211_ifindex_msg(bss->drv, bss->ifindex, flags, cmd);
515 }
516 
517 
518 struct wiphy_idx_data {
519 	int wiphy_idx;
520 	enum nl80211_iftype nlmode;
521 	u8 *macaddr;
522 };
523 
524 
525 static int netdev_info_handler(struct nl_msg *msg, void *arg)
526 {
527 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
528 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
529 	struct wiphy_idx_data *info = arg;
530 
531 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
532 		  genlmsg_attrlen(gnlh, 0), NULL);
533 
534 	if (tb[NL80211_ATTR_WIPHY])
535 		info->wiphy_idx = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
536 
537 	if (tb[NL80211_ATTR_IFTYPE])
538 		info->nlmode = nla_get_u32(tb[NL80211_ATTR_IFTYPE]);
539 
540 	if (tb[NL80211_ATTR_MAC] && info->macaddr)
541 		os_memcpy(info->macaddr, nla_data(tb[NL80211_ATTR_MAC]),
542 			  ETH_ALEN);
543 
544 	return NL_SKIP;
545 }
546 
547 
548 int nl80211_get_wiphy_index(struct i802_bss *bss)
549 {
550 	struct nl_msg *msg;
551 	struct wiphy_idx_data data = {
552 		.wiphy_idx = -1,
553 		.macaddr = NULL,
554 	};
555 
556 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_GET_INTERFACE)))
557 		return -1;
558 
559 	if (send_and_recv_msgs(bss->drv, msg, netdev_info_handler, &data) == 0)
560 		return data.wiphy_idx;
561 	return -1;
562 }
563 
564 
565 static enum nl80211_iftype nl80211_get_ifmode(struct i802_bss *bss)
566 {
567 	struct nl_msg *msg;
568 	struct wiphy_idx_data data = {
569 		.nlmode = NL80211_IFTYPE_UNSPECIFIED,
570 		.macaddr = NULL,
571 	};
572 
573 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_GET_INTERFACE)))
574 		return NL80211_IFTYPE_UNSPECIFIED;
575 
576 	if (send_and_recv_msgs(bss->drv, msg, netdev_info_handler, &data) == 0)
577 		return data.nlmode;
578 	return NL80211_IFTYPE_UNSPECIFIED;
579 }
580 
581 
582 static int nl80211_get_macaddr(struct i802_bss *bss)
583 {
584 	struct nl_msg *msg;
585 	struct wiphy_idx_data data = {
586 		.macaddr = bss->addr,
587 	};
588 
589 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_GET_INTERFACE)))
590 		return -1;
591 
592 	return send_and_recv_msgs(bss->drv, msg, netdev_info_handler, &data);
593 }
594 
595 
596 static int nl80211_register_beacons(struct wpa_driver_nl80211_data *drv,
597 				    struct nl80211_wiphy_data *w)
598 {
599 	struct nl_msg *msg;
600 	int ret;
601 
602 	msg = nlmsg_alloc();
603 	if (!msg)
604 		return -1;
605 
606 	if (!nl80211_cmd(drv, msg, 0, NL80211_CMD_REGISTER_BEACONS) ||
607 	    nla_put_u32(msg, NL80211_ATTR_WIPHY, w->wiphy_idx)) {
608 		nlmsg_free(msg);
609 		return -1;
610 	}
611 
612 	ret = send_and_recv(drv->global, w->nl_beacons, msg, NULL, NULL);
613 	if (ret) {
614 		wpa_printf(MSG_DEBUG, "nl80211: Register beacons command "
615 			   "failed: ret=%d (%s)",
616 			   ret, strerror(-ret));
617 	}
618 	return ret;
619 }
620 
621 
622 static void nl80211_recv_beacons(int sock, void *eloop_ctx, void *handle)
623 {
624 	struct nl80211_wiphy_data *w = eloop_ctx;
625 	int res;
626 
627 	wpa_printf(MSG_EXCESSIVE, "nl80211: Beacon event message available");
628 
629 	res = nl_recvmsgs(handle, w->nl_cb);
630 	if (res < 0) {
631 		wpa_printf(MSG_INFO, "nl80211: %s->nl_recvmsgs failed: %d",
632 			   __func__, res);
633 	}
634 }
635 
636 
637 static int process_beacon_event(struct nl_msg *msg, void *arg)
638 {
639 	struct nl80211_wiphy_data *w = arg;
640 	struct wpa_driver_nl80211_data *drv;
641 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
642 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
643 	union wpa_event_data event;
644 
645 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
646 		  genlmsg_attrlen(gnlh, 0), NULL);
647 
648 	if (gnlh->cmd != NL80211_CMD_FRAME) {
649 		wpa_printf(MSG_DEBUG, "nl80211: Unexpected beacon event? (%d)",
650 			   gnlh->cmd);
651 		return NL_SKIP;
652 	}
653 
654 	if (!tb[NL80211_ATTR_FRAME])
655 		return NL_SKIP;
656 
657 	dl_list_for_each(drv, &w->drvs, struct wpa_driver_nl80211_data,
658 			 wiphy_list) {
659 		os_memset(&event, 0, sizeof(event));
660 		event.rx_mgmt.frame = nla_data(tb[NL80211_ATTR_FRAME]);
661 		event.rx_mgmt.frame_len = nla_len(tb[NL80211_ATTR_FRAME]);
662 		wpa_supplicant_event(drv->ctx, EVENT_RX_MGMT, &event);
663 	}
664 
665 	return NL_SKIP;
666 }
667 
668 
669 static struct nl80211_wiphy_data *
670 nl80211_get_wiphy_data_ap(struct i802_bss *bss)
671 {
672 	static DEFINE_DL_LIST(nl80211_wiphys);
673 	struct nl80211_wiphy_data *w;
674 	int wiphy_idx, found = 0;
675 	struct i802_bss *tmp_bss;
676 
677 	if (bss->wiphy_data != NULL)
678 		return bss->wiphy_data;
679 
680 	wiphy_idx = nl80211_get_wiphy_index(bss);
681 
682 	dl_list_for_each(w, &nl80211_wiphys, struct nl80211_wiphy_data, list) {
683 		if (w->wiphy_idx == wiphy_idx)
684 			goto add;
685 	}
686 
687 	/* alloc new one */
688 	w = os_zalloc(sizeof(*w));
689 	if (w == NULL)
690 		return NULL;
691 	w->wiphy_idx = wiphy_idx;
692 	dl_list_init(&w->bsss);
693 	dl_list_init(&w->drvs);
694 
695 	w->nl_cb = nl_cb_alloc(NL_CB_DEFAULT);
696 	if (!w->nl_cb) {
697 		os_free(w);
698 		return NULL;
699 	}
700 	nl_cb_set(w->nl_cb, NL_CB_SEQ_CHECK, NL_CB_CUSTOM, no_seq_check, NULL);
701 	nl_cb_set(w->nl_cb, NL_CB_VALID, NL_CB_CUSTOM, process_beacon_event,
702 		  w);
703 
704 	w->nl_beacons = nl_create_handle(bss->drv->global->nl_cb,
705 					 "wiphy beacons");
706 	if (w->nl_beacons == NULL) {
707 		os_free(w);
708 		return NULL;
709 	}
710 
711 	if (nl80211_register_beacons(bss->drv, w)) {
712 		nl_destroy_handles(&w->nl_beacons);
713 		os_free(w);
714 		return NULL;
715 	}
716 
717 	nl80211_register_eloop_read(&w->nl_beacons, nl80211_recv_beacons, w);
718 
719 	dl_list_add(&nl80211_wiphys, &w->list);
720 
721 add:
722 	/* drv entry for this bss already there? */
723 	dl_list_for_each(tmp_bss, &w->bsss, struct i802_bss, wiphy_list) {
724 		if (tmp_bss->drv == bss->drv) {
725 			found = 1;
726 			break;
727 		}
728 	}
729 	/* if not add it */
730 	if (!found)
731 		dl_list_add(&w->drvs, &bss->drv->wiphy_list);
732 
733 	dl_list_add(&w->bsss, &bss->wiphy_list);
734 	bss->wiphy_data = w;
735 	return w;
736 }
737 
738 
739 static void nl80211_put_wiphy_data_ap(struct i802_bss *bss)
740 {
741 	struct nl80211_wiphy_data *w = bss->wiphy_data;
742 	struct i802_bss *tmp_bss;
743 	int found = 0;
744 
745 	if (w == NULL)
746 		return;
747 	bss->wiphy_data = NULL;
748 	dl_list_del(&bss->wiphy_list);
749 
750 	/* still any for this drv present? */
751 	dl_list_for_each(tmp_bss, &w->bsss, struct i802_bss, wiphy_list) {
752 		if (tmp_bss->drv == bss->drv) {
753 			found = 1;
754 			break;
755 		}
756 	}
757 	/* if not remove it */
758 	if (!found)
759 		dl_list_del(&bss->drv->wiphy_list);
760 
761 	if (!dl_list_empty(&w->bsss))
762 		return;
763 
764 	nl80211_destroy_eloop_handle(&w->nl_beacons);
765 
766 	nl_cb_put(w->nl_cb);
767 	dl_list_del(&w->list);
768 	os_free(w);
769 }
770 
771 
772 static unsigned int nl80211_get_ifindex(void *priv)
773 {
774 	struct i802_bss *bss = priv;
775 	struct wpa_driver_nl80211_data *drv = bss->drv;
776 
777 	return drv->ifindex;
778 }
779 
780 
781 static int wpa_driver_nl80211_get_bssid(void *priv, u8 *bssid)
782 {
783 	struct i802_bss *bss = priv;
784 	struct wpa_driver_nl80211_data *drv = bss->drv;
785 	if (!drv->associated)
786 		return -1;
787 	os_memcpy(bssid, drv->bssid, ETH_ALEN);
788 	return 0;
789 }
790 
791 
792 static int wpa_driver_nl80211_get_ssid(void *priv, u8 *ssid)
793 {
794 	struct i802_bss *bss = priv;
795 	struct wpa_driver_nl80211_data *drv = bss->drv;
796 	if (!drv->associated)
797 		return -1;
798 	os_memcpy(ssid, drv->ssid, drv->ssid_len);
799 	return drv->ssid_len;
800 }
801 
802 
803 static void wpa_driver_nl80211_event_newlink(
804 	struct nl80211_global *global, struct wpa_driver_nl80211_data *drv,
805 	int ifindex, const char *ifname)
806 {
807 	union wpa_event_data event;
808 
809 	if (drv && os_strcmp(drv->first_bss->ifname, ifname) == 0) {
810 		if (if_nametoindex(drv->first_bss->ifname) == 0) {
811 			wpa_printf(MSG_DEBUG, "nl80211: Interface %s does not exist - ignore RTM_NEWLINK",
812 				   drv->first_bss->ifname);
813 			return;
814 		}
815 		if (!drv->if_removed)
816 			return;
817 		wpa_printf(MSG_DEBUG, "nl80211: Mark if_removed=0 for %s based on RTM_NEWLINK event",
818 			   drv->first_bss->ifname);
819 		drv->if_removed = 0;
820 	}
821 
822 	os_memset(&event, 0, sizeof(event));
823 	event.interface_status.ifindex = ifindex;
824 	os_strlcpy(event.interface_status.ifname, ifname,
825 		   sizeof(event.interface_status.ifname));
826 	event.interface_status.ievent = EVENT_INTERFACE_ADDED;
827 	if (drv)
828 		wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_STATUS, &event);
829 	else
830 		wpa_supplicant_event_global(global->ctx, EVENT_INTERFACE_STATUS,
831 					    &event);
832 }
833 
834 
835 static void wpa_driver_nl80211_event_dellink(
836 	struct nl80211_global *global, struct wpa_driver_nl80211_data *drv,
837 	int ifindex, const char *ifname)
838 {
839 	union wpa_event_data event;
840 
841 	if (drv && os_strcmp(drv->first_bss->ifname, ifname) == 0) {
842 		if (drv->if_removed) {
843 			wpa_printf(MSG_DEBUG, "nl80211: if_removed already set - ignore RTM_DELLINK event for %s",
844 				   ifname);
845 			return;
846 		}
847 		wpa_printf(MSG_DEBUG, "RTM_DELLINK: Interface '%s' removed - mark if_removed=1",
848 			   ifname);
849 		drv->if_removed = 1;
850 	} else {
851 		wpa_printf(MSG_DEBUG, "RTM_DELLINK: Interface '%s' removed",
852 			   ifname);
853 	}
854 
855 	os_memset(&event, 0, sizeof(event));
856 	event.interface_status.ifindex = ifindex;
857 	os_strlcpy(event.interface_status.ifname, ifname,
858 		   sizeof(event.interface_status.ifname));
859 	event.interface_status.ievent = EVENT_INTERFACE_REMOVED;
860 	if (drv)
861 		wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_STATUS, &event);
862 	else
863 		wpa_supplicant_event_global(global->ctx, EVENT_INTERFACE_STATUS,
864 					    &event);
865 }
866 
867 
868 static int wpa_driver_nl80211_own_ifname(struct wpa_driver_nl80211_data *drv,
869 					 u8 *buf, size_t len)
870 {
871 	int attrlen, rta_len;
872 	struct rtattr *attr;
873 
874 	attrlen = len;
875 	attr = (struct rtattr *) buf;
876 
877 	rta_len = RTA_ALIGN(sizeof(struct rtattr));
878 	while (RTA_OK(attr, attrlen)) {
879 		if (attr->rta_type == IFLA_IFNAME) {
880 			if (os_strcmp(((char *) attr) + rta_len,
881 				      drv->first_bss->ifname) == 0)
882 				return 1;
883 			else
884 				break;
885 		}
886 		attr = RTA_NEXT(attr, attrlen);
887 	}
888 
889 	return 0;
890 }
891 
892 
893 static int wpa_driver_nl80211_own_ifindex(struct wpa_driver_nl80211_data *drv,
894 					  int ifindex, u8 *buf, size_t len)
895 {
896 	if (drv->ifindex == ifindex)
897 		return 1;
898 
899 	if (drv->if_removed && wpa_driver_nl80211_own_ifname(drv, buf, len)) {
900 		nl80211_check_global(drv->global);
901 		wpa_printf(MSG_DEBUG, "nl80211: Update ifindex for a removed "
902 			   "interface");
903 		wpa_driver_nl80211_finish_drv_init(drv, NULL, 0, NULL);
904 		return 1;
905 	}
906 
907 	return 0;
908 }
909 
910 
911 static struct wpa_driver_nl80211_data *
912 nl80211_find_drv(struct nl80211_global *global, int idx, u8 *buf, size_t len)
913 {
914 	struct wpa_driver_nl80211_data *drv;
915 	dl_list_for_each(drv, &global->interfaces,
916 			 struct wpa_driver_nl80211_data, list) {
917 		if (wpa_driver_nl80211_own_ifindex(drv, idx, buf, len) ||
918 		    have_ifidx(drv, idx, IFIDX_ANY))
919 			return drv;
920 	}
921 	return NULL;
922 }
923 
924 
925 static void wpa_driver_nl80211_event_rtm_newlink(void *ctx,
926 						 struct ifinfomsg *ifi,
927 						 u8 *buf, size_t len)
928 {
929 	struct nl80211_global *global = ctx;
930 	struct wpa_driver_nl80211_data *drv;
931 	int attrlen;
932 	struct rtattr *attr;
933 	u32 brid = 0;
934 	char namebuf[IFNAMSIZ];
935 	char ifname[IFNAMSIZ + 1];
936 	char extra[100], *pos, *end;
937 
938 	extra[0] = '\0';
939 	pos = extra;
940 	end = pos + sizeof(extra);
941 	ifname[0] = '\0';
942 
943 	attrlen = len;
944 	attr = (struct rtattr *) buf;
945 	while (RTA_OK(attr, attrlen)) {
946 		switch (attr->rta_type) {
947 		case IFLA_IFNAME:
948 			if (RTA_PAYLOAD(attr) >= IFNAMSIZ)
949 				break;
950 			os_memcpy(ifname, RTA_DATA(attr), RTA_PAYLOAD(attr));
951 			ifname[RTA_PAYLOAD(attr)] = '\0';
952 			break;
953 		case IFLA_MASTER:
954 			brid = nla_get_u32((struct nlattr *) attr);
955 			pos += os_snprintf(pos, end - pos, " master=%u", brid);
956 			break;
957 		case IFLA_WIRELESS:
958 			pos += os_snprintf(pos, end - pos, " wext");
959 			break;
960 		case IFLA_OPERSTATE:
961 			pos += os_snprintf(pos, end - pos, " operstate=%u",
962 					   nla_get_u32((struct nlattr *) attr));
963 			break;
964 		case IFLA_LINKMODE:
965 			pos += os_snprintf(pos, end - pos, " linkmode=%u",
966 					   nla_get_u32((struct nlattr *) attr));
967 			break;
968 		}
969 		attr = RTA_NEXT(attr, attrlen);
970 	}
971 	extra[sizeof(extra) - 1] = '\0';
972 
973 	wpa_printf(MSG_DEBUG, "RTM_NEWLINK: ifi_index=%d ifname=%s%s ifi_family=%d ifi_flags=0x%x (%s%s%s%s)",
974 		   ifi->ifi_index, ifname, extra, ifi->ifi_family,
975 		   ifi->ifi_flags,
976 		   (ifi->ifi_flags & IFF_UP) ? "[UP]" : "",
977 		   (ifi->ifi_flags & IFF_RUNNING) ? "[RUNNING]" : "",
978 		   (ifi->ifi_flags & IFF_LOWER_UP) ? "[LOWER_UP]" : "",
979 		   (ifi->ifi_flags & IFF_DORMANT) ? "[DORMANT]" : "");
980 
981 	drv = nl80211_find_drv(global, ifi->ifi_index, buf, len);
982 	if (!drv)
983 		goto event_newlink;
984 
985 	if (!drv->if_disabled && !(ifi->ifi_flags & IFF_UP)) {
986 		namebuf[0] = '\0';
987 		if (if_indextoname(ifi->ifi_index, namebuf) &&
988 		    linux_iface_up(drv->global->ioctl_sock, namebuf) > 0) {
989 			wpa_printf(MSG_DEBUG, "nl80211: Ignore interface down "
990 				   "event since interface %s is up", namebuf);
991 			drv->ignore_if_down_event = 0;
992 			return;
993 		}
994 		wpa_printf(MSG_DEBUG, "nl80211: Interface down (%s/%s)",
995 			   namebuf, ifname);
996 		if (os_strcmp(drv->first_bss->ifname, ifname) != 0) {
997 			wpa_printf(MSG_DEBUG,
998 				   "nl80211: Not the main interface (%s) - do not indicate interface down",
999 				   drv->first_bss->ifname);
1000 		} else if (drv->ignore_if_down_event) {
1001 			wpa_printf(MSG_DEBUG, "nl80211: Ignore interface down "
1002 				   "event generated by mode change");
1003 			drv->ignore_if_down_event = 0;
1004 		} else {
1005 			drv->if_disabled = 1;
1006 			wpa_supplicant_event(drv->ctx,
1007 					     EVENT_INTERFACE_DISABLED, NULL);
1008 
1009 			/*
1010 			 * Try to get drv again, since it may be removed as
1011 			 * part of the EVENT_INTERFACE_DISABLED handling for
1012 			 * dynamic interfaces
1013 			 */
1014 			drv = nl80211_find_drv(global, ifi->ifi_index,
1015 					       buf, len);
1016 			if (!drv)
1017 				return;
1018 		}
1019 	}
1020 
1021 	if (drv->if_disabled && (ifi->ifi_flags & IFF_UP)) {
1022 		if (if_indextoname(ifi->ifi_index, namebuf) &&
1023 		    linux_iface_up(drv->global->ioctl_sock, namebuf) == 0) {
1024 			wpa_printf(MSG_DEBUG, "nl80211: Ignore interface up "
1025 				   "event since interface %s is down",
1026 				   namebuf);
1027 		} else if (if_nametoindex(drv->first_bss->ifname) == 0) {
1028 			wpa_printf(MSG_DEBUG, "nl80211: Ignore interface up "
1029 				   "event since interface %s does not exist",
1030 				   drv->first_bss->ifname);
1031 		} else if (drv->if_removed) {
1032 			wpa_printf(MSG_DEBUG, "nl80211: Ignore interface up "
1033 				   "event since interface %s is marked "
1034 				   "removed", drv->first_bss->ifname);
1035 		} else {
1036 			struct i802_bss *bss;
1037 			u8 addr[ETH_ALEN];
1038 
1039 			/* Re-read MAC address as it may have changed */
1040 			bss = get_bss_ifindex(drv, ifi->ifi_index);
1041 			if (bss &&
1042 			    linux_get_ifhwaddr(drv->global->ioctl_sock,
1043 					       bss->ifname, addr) < 0) {
1044 				wpa_printf(MSG_DEBUG,
1045 					   "nl80211: %s: failed to re-read MAC address",
1046 					   bss->ifname);
1047 			} else if (bss &&
1048 				   os_memcmp(addr, bss->addr, ETH_ALEN) != 0) {
1049 				wpa_printf(MSG_DEBUG,
1050 					   "nl80211: Own MAC address on ifindex %d (%s) changed from "
1051 					   MACSTR " to " MACSTR,
1052 					   ifi->ifi_index, bss->ifname,
1053 					   MAC2STR(bss->addr),
1054 					   MAC2STR(addr));
1055 				os_memcpy(bss->addr, addr, ETH_ALEN);
1056 			}
1057 
1058 			wpa_printf(MSG_DEBUG, "nl80211: Interface up");
1059 			drv->if_disabled = 0;
1060 			wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_ENABLED,
1061 					     NULL);
1062 		}
1063 	}
1064 
1065 	/*
1066 	 * Some drivers send the association event before the operup event--in
1067 	 * this case, lifting operstate in wpa_driver_nl80211_set_operstate()
1068 	 * fails. This will hit us when wpa_supplicant does not need to do
1069 	 * IEEE 802.1X authentication
1070 	 */
1071 	if (drv->operstate == 1 &&
1072 	    (ifi->ifi_flags & (IFF_LOWER_UP | IFF_DORMANT)) == IFF_LOWER_UP &&
1073 	    !(ifi->ifi_flags & IFF_RUNNING)) {
1074 		wpa_printf(MSG_DEBUG, "nl80211: Set IF_OPER_UP again based on ifi_flags and expected operstate");
1075 		netlink_send_oper_ifla(drv->global->netlink, drv->ifindex,
1076 				       -1, IF_OPER_UP);
1077 	}
1078 
1079 event_newlink:
1080 	if (ifname[0])
1081 		wpa_driver_nl80211_event_newlink(global, drv, ifi->ifi_index,
1082 						 ifname);
1083 
1084 	if (ifi->ifi_family == AF_BRIDGE && brid && drv) {
1085 		struct i802_bss *bss;
1086 
1087 		/* device has been added to bridge */
1088 		if (!if_indextoname(brid, namebuf)) {
1089 			wpa_printf(MSG_DEBUG,
1090 				   "nl80211: Could not find bridge ifname for ifindex %u",
1091 				   brid);
1092 			return;
1093 		}
1094 		wpa_printf(MSG_DEBUG, "nl80211: Add ifindex %u for bridge %s",
1095 			   brid, namebuf);
1096 		add_ifidx(drv, brid, ifi->ifi_index);
1097 
1098 		for (bss = drv->first_bss; bss; bss = bss->next) {
1099 			if (os_strcmp(ifname, bss->ifname) == 0) {
1100 				os_strlcpy(bss->brname, namebuf, IFNAMSIZ);
1101 				break;
1102 			}
1103 		}
1104 	}
1105 }
1106 
1107 
1108 static void wpa_driver_nl80211_event_rtm_dellink(void *ctx,
1109 						 struct ifinfomsg *ifi,
1110 						 u8 *buf, size_t len)
1111 {
1112 	struct nl80211_global *global = ctx;
1113 	struct wpa_driver_nl80211_data *drv;
1114 	int attrlen;
1115 	struct rtattr *attr;
1116 	u32 brid = 0;
1117 	char ifname[IFNAMSIZ + 1];
1118 	char extra[100], *pos, *end;
1119 
1120 	extra[0] = '\0';
1121 	pos = extra;
1122 	end = pos + sizeof(extra);
1123 	ifname[0] = '\0';
1124 
1125 	attrlen = len;
1126 	attr = (struct rtattr *) buf;
1127 	while (RTA_OK(attr, attrlen)) {
1128 		switch (attr->rta_type) {
1129 		case IFLA_IFNAME:
1130 			if (RTA_PAYLOAD(attr) >= IFNAMSIZ)
1131 				break;
1132 			os_memcpy(ifname, RTA_DATA(attr), RTA_PAYLOAD(attr));
1133 			ifname[RTA_PAYLOAD(attr)] = '\0';
1134 			break;
1135 		case IFLA_MASTER:
1136 			brid = nla_get_u32((struct nlattr *) attr);
1137 			pos += os_snprintf(pos, end - pos, " master=%u", brid);
1138 			break;
1139 		case IFLA_OPERSTATE:
1140 			pos += os_snprintf(pos, end - pos, " operstate=%u",
1141 					   nla_get_u32((struct nlattr *) attr));
1142 			break;
1143 		case IFLA_LINKMODE:
1144 			pos += os_snprintf(pos, end - pos, " linkmode=%u",
1145 					   nla_get_u32((struct nlattr *) attr));
1146 			break;
1147 		}
1148 		attr = RTA_NEXT(attr, attrlen);
1149 	}
1150 	extra[sizeof(extra) - 1] = '\0';
1151 
1152 	wpa_printf(MSG_DEBUG, "RTM_DELLINK: ifi_index=%d ifname=%s%s ifi_family=%d ifi_flags=0x%x (%s%s%s%s)",
1153 		   ifi->ifi_index, ifname, extra, ifi->ifi_family,
1154 		   ifi->ifi_flags,
1155 		   (ifi->ifi_flags & IFF_UP) ? "[UP]" : "",
1156 		   (ifi->ifi_flags & IFF_RUNNING) ? "[RUNNING]" : "",
1157 		   (ifi->ifi_flags & IFF_LOWER_UP) ? "[LOWER_UP]" : "",
1158 		   (ifi->ifi_flags & IFF_DORMANT) ? "[DORMANT]" : "");
1159 
1160 	drv = nl80211_find_drv(global, ifi->ifi_index, buf, len);
1161 
1162 	if (ifi->ifi_family == AF_BRIDGE && brid && drv) {
1163 		/* device has been removed from bridge */
1164 		char namebuf[IFNAMSIZ];
1165 
1166 		if (!if_indextoname(brid, namebuf)) {
1167 			wpa_printf(MSG_DEBUG,
1168 				   "nl80211: Could not find bridge ifname for ifindex %u",
1169 				   brid);
1170 		} else {
1171 			wpa_printf(MSG_DEBUG,
1172 				   "nl80211: Remove ifindex %u for bridge %s",
1173 				   brid, namebuf);
1174 		}
1175 		del_ifidx(drv, brid, ifi->ifi_index);
1176 	}
1177 
1178 	if (ifi->ifi_family != AF_BRIDGE || !brid)
1179 		wpa_driver_nl80211_event_dellink(global, drv, ifi->ifi_index,
1180 						 ifname);
1181 }
1182 
1183 
1184 unsigned int nl80211_get_assoc_freq(struct wpa_driver_nl80211_data *drv)
1185 {
1186 	struct nl_msg *msg;
1187 	int ret;
1188 	struct nl80211_bss_info_arg arg;
1189 
1190 	msg = nl80211_drv_msg(drv, NLM_F_DUMP, NL80211_CMD_GET_SCAN);
1191 	os_memset(&arg, 0, sizeof(arg));
1192 	arg.drv = drv;
1193 	ret = send_and_recv_msgs(drv, msg, bss_info_handler, &arg);
1194 	if (ret == 0) {
1195 		unsigned int freq = drv->nlmode == NL80211_IFTYPE_ADHOC ?
1196 			arg.ibss_freq : arg.assoc_freq;
1197 		wpa_printf(MSG_DEBUG, "nl80211: Operating frequency for the "
1198 			   "associated BSS from scan results: %u MHz", freq);
1199 		if (freq)
1200 			drv->assoc_freq = freq;
1201 		return drv->assoc_freq;
1202 	}
1203 	wpa_printf(MSG_DEBUG, "nl80211: Scan result fetch failed: ret=%d "
1204 		   "(%s)", ret, strerror(-ret));
1205 	return drv->assoc_freq;
1206 }
1207 
1208 
1209 static int get_link_signal(struct nl_msg *msg, void *arg)
1210 {
1211 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
1212 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
1213 	struct nlattr *sinfo[NL80211_STA_INFO_MAX + 1];
1214 	static struct nla_policy policy[NL80211_STA_INFO_MAX + 1] = {
1215 		[NL80211_STA_INFO_SIGNAL] = { .type = NLA_U8 },
1216 		[NL80211_STA_INFO_SIGNAL_AVG] = { .type = NLA_U8 },
1217 		[NL80211_STA_INFO_BEACON_SIGNAL_AVG] = { .type = NLA_U8 },
1218 	};
1219 	struct nlattr *rinfo[NL80211_RATE_INFO_MAX + 1];
1220 	static struct nla_policy rate_policy[NL80211_RATE_INFO_MAX + 1] = {
1221 		[NL80211_RATE_INFO_BITRATE] = { .type = NLA_U16 },
1222 		[NL80211_RATE_INFO_MCS] = { .type = NLA_U8 },
1223 		[NL80211_RATE_INFO_40_MHZ_WIDTH] = { .type = NLA_FLAG },
1224 		[NL80211_RATE_INFO_SHORT_GI] = { .type = NLA_FLAG },
1225 	};
1226 	struct wpa_signal_info *sig_change = arg;
1227 
1228 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
1229 		  genlmsg_attrlen(gnlh, 0), NULL);
1230 	if (!tb[NL80211_ATTR_STA_INFO] ||
1231 	    nla_parse_nested(sinfo, NL80211_STA_INFO_MAX,
1232 			     tb[NL80211_ATTR_STA_INFO], policy))
1233 		return NL_SKIP;
1234 	if (!sinfo[NL80211_STA_INFO_SIGNAL])
1235 		return NL_SKIP;
1236 
1237 	sig_change->current_signal =
1238 		(s8) nla_get_u8(sinfo[NL80211_STA_INFO_SIGNAL]);
1239 
1240 	if (sinfo[NL80211_STA_INFO_SIGNAL_AVG])
1241 		sig_change->avg_signal =
1242 			(s8) nla_get_u8(sinfo[NL80211_STA_INFO_SIGNAL_AVG]);
1243 	else
1244 		sig_change->avg_signal = 0;
1245 
1246 	if (sinfo[NL80211_STA_INFO_BEACON_SIGNAL_AVG])
1247 		sig_change->avg_beacon_signal =
1248 			(s8)
1249 			nla_get_u8(sinfo[NL80211_STA_INFO_BEACON_SIGNAL_AVG]);
1250 	else
1251 		sig_change->avg_beacon_signal = 0;
1252 
1253 	if (sinfo[NL80211_STA_INFO_TX_BITRATE]) {
1254 		if (nla_parse_nested(rinfo, NL80211_RATE_INFO_MAX,
1255 				     sinfo[NL80211_STA_INFO_TX_BITRATE],
1256 				     rate_policy)) {
1257 			sig_change->current_txrate = 0;
1258 		} else {
1259 			if (rinfo[NL80211_RATE_INFO_BITRATE]) {
1260 				sig_change->current_txrate =
1261 					nla_get_u16(rinfo[
1262 					     NL80211_RATE_INFO_BITRATE]) * 100;
1263 			}
1264 		}
1265 	}
1266 
1267 	return NL_SKIP;
1268 }
1269 
1270 
1271 int nl80211_get_link_signal(struct wpa_driver_nl80211_data *drv,
1272 			    struct wpa_signal_info *sig)
1273 {
1274 	struct nl_msg *msg;
1275 
1276 	sig->current_signal = -9999;
1277 	sig->current_txrate = 0;
1278 
1279 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_GET_STATION)) ||
1280 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, drv->bssid)) {
1281 		nlmsg_free(msg);
1282 		return -ENOBUFS;
1283 	}
1284 
1285 	return send_and_recv_msgs(drv, msg, get_link_signal, sig);
1286 }
1287 
1288 
1289 static int get_link_noise(struct nl_msg *msg, void *arg)
1290 {
1291 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
1292 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
1293 	struct nlattr *sinfo[NL80211_SURVEY_INFO_MAX + 1];
1294 	static struct nla_policy survey_policy[NL80211_SURVEY_INFO_MAX + 1] = {
1295 		[NL80211_SURVEY_INFO_FREQUENCY] = { .type = NLA_U32 },
1296 		[NL80211_SURVEY_INFO_NOISE] = { .type = NLA_U8 },
1297 	};
1298 	struct wpa_signal_info *sig_change = arg;
1299 
1300 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
1301 		  genlmsg_attrlen(gnlh, 0), NULL);
1302 
1303 	if (!tb[NL80211_ATTR_SURVEY_INFO]) {
1304 		wpa_printf(MSG_DEBUG, "nl80211: survey data missing!");
1305 		return NL_SKIP;
1306 	}
1307 
1308 	if (nla_parse_nested(sinfo, NL80211_SURVEY_INFO_MAX,
1309 			     tb[NL80211_ATTR_SURVEY_INFO],
1310 			     survey_policy)) {
1311 		wpa_printf(MSG_DEBUG, "nl80211: failed to parse nested "
1312 			   "attributes!");
1313 		return NL_SKIP;
1314 	}
1315 
1316 	if (!sinfo[NL80211_SURVEY_INFO_FREQUENCY])
1317 		return NL_SKIP;
1318 
1319 	if (nla_get_u32(sinfo[NL80211_SURVEY_INFO_FREQUENCY]) !=
1320 	    sig_change->frequency)
1321 		return NL_SKIP;
1322 
1323 	if (!sinfo[NL80211_SURVEY_INFO_NOISE])
1324 		return NL_SKIP;
1325 
1326 	sig_change->current_noise =
1327 		(s8) nla_get_u8(sinfo[NL80211_SURVEY_INFO_NOISE]);
1328 
1329 	return NL_SKIP;
1330 }
1331 
1332 
1333 int nl80211_get_link_noise(struct wpa_driver_nl80211_data *drv,
1334 			   struct wpa_signal_info *sig_change)
1335 {
1336 	struct nl_msg *msg;
1337 
1338 	sig_change->current_noise = 9999;
1339 	sig_change->frequency = drv->assoc_freq;
1340 
1341 	msg = nl80211_drv_msg(drv, NLM_F_DUMP, NL80211_CMD_GET_SURVEY);
1342 	return send_and_recv_msgs(drv, msg, get_link_noise, sig_change);
1343 }
1344 
1345 
1346 static void wpa_driver_nl80211_event_receive(int sock, void *eloop_ctx,
1347 					     void *handle)
1348 {
1349 	struct nl_cb *cb = eloop_ctx;
1350 	int res;
1351 
1352 	wpa_printf(MSG_MSGDUMP, "nl80211: Event message available");
1353 
1354 	res = nl_recvmsgs(handle, cb);
1355 	if (res < 0) {
1356 		wpa_printf(MSG_INFO, "nl80211: %s->nl_recvmsgs failed: %d",
1357 			   __func__, res);
1358 	}
1359 }
1360 
1361 
1362 /**
1363  * wpa_driver_nl80211_set_country - ask nl80211 to set the regulatory domain
1364  * @priv: driver_nl80211 private data
1365  * @alpha2_arg: country to which to switch to
1366  * Returns: 0 on success, -1 on failure
1367  *
1368  * This asks nl80211 to set the regulatory domain for given
1369  * country ISO / IEC alpha2.
1370  */
1371 static int wpa_driver_nl80211_set_country(void *priv, const char *alpha2_arg)
1372 {
1373 	struct i802_bss *bss = priv;
1374 	struct wpa_driver_nl80211_data *drv = bss->drv;
1375 	char alpha2[3];
1376 	struct nl_msg *msg;
1377 
1378 	msg = nlmsg_alloc();
1379 	if (!msg)
1380 		return -ENOMEM;
1381 
1382 	alpha2[0] = alpha2_arg[0];
1383 	alpha2[1] = alpha2_arg[1];
1384 	alpha2[2] = '\0';
1385 
1386 	if (!nl80211_cmd(drv, msg, 0, NL80211_CMD_REQ_SET_REG) ||
1387 	    nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, alpha2)) {
1388 		nlmsg_free(msg);
1389 		return -EINVAL;
1390 	}
1391 	if (send_and_recv_msgs(drv, msg, NULL, NULL))
1392 		return -EINVAL;
1393 	return 0;
1394 }
1395 
1396 
1397 static int nl80211_get_country(struct nl_msg *msg, void *arg)
1398 {
1399 	char *alpha2 = arg;
1400 	struct nlattr *tb_msg[NL80211_ATTR_MAX + 1];
1401 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
1402 
1403 	nla_parse(tb_msg, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
1404 		  genlmsg_attrlen(gnlh, 0), NULL);
1405 	if (!tb_msg[NL80211_ATTR_REG_ALPHA2]) {
1406 		wpa_printf(MSG_DEBUG, "nl80211: No country information available");
1407 		return NL_SKIP;
1408 	}
1409 	os_strlcpy(alpha2, nla_data(tb_msg[NL80211_ATTR_REG_ALPHA2]), 3);
1410 	return NL_SKIP;
1411 }
1412 
1413 
1414 static int wpa_driver_nl80211_get_country(void *priv, char *alpha2)
1415 {
1416 	struct i802_bss *bss = priv;
1417 	struct wpa_driver_nl80211_data *drv = bss->drv;
1418 	struct nl_msg *msg;
1419 	int ret;
1420 
1421 	msg = nlmsg_alloc();
1422 	if (!msg)
1423 		return -ENOMEM;
1424 
1425 	nl80211_cmd(drv, msg, 0, NL80211_CMD_GET_REG);
1426 	alpha2[0] = '\0';
1427 	ret = send_and_recv_msgs(drv, msg, nl80211_get_country, alpha2);
1428 	if (!alpha2[0])
1429 		ret = -1;
1430 
1431 	return ret;
1432 }
1433 
1434 
1435 static int wpa_driver_nl80211_init_nl_global(struct nl80211_global *global)
1436 {
1437 	int ret;
1438 
1439 	global->nl_cb = nl_cb_alloc(NL_CB_DEFAULT);
1440 	if (global->nl_cb == NULL) {
1441 		wpa_printf(MSG_ERROR, "nl80211: Failed to allocate netlink "
1442 			   "callbacks");
1443 		return -1;
1444 	}
1445 
1446 	global->nl = nl_create_handle(global->nl_cb, "nl");
1447 	if (global->nl == NULL)
1448 		goto err;
1449 
1450 	global->nl80211_id = genl_ctrl_resolve(global->nl, "nl80211");
1451 	if (global->nl80211_id < 0) {
1452 		wpa_printf(MSG_ERROR, "nl80211: 'nl80211' generic netlink not "
1453 			   "found");
1454 		goto err;
1455 	}
1456 
1457 	global->nl_event = nl_create_handle(global->nl_cb, "event");
1458 	if (global->nl_event == NULL)
1459 		goto err;
1460 
1461 	ret = nl_get_multicast_id(global, "nl80211", "scan");
1462 	if (ret >= 0)
1463 		ret = nl_socket_add_membership(global->nl_event, ret);
1464 	if (ret < 0) {
1465 		wpa_printf(MSG_ERROR, "nl80211: Could not add multicast "
1466 			   "membership for scan events: %d (%s)",
1467 			   ret, strerror(-ret));
1468 		goto err;
1469 	}
1470 
1471 	ret = nl_get_multicast_id(global, "nl80211", "mlme");
1472 	if (ret >= 0)
1473 		ret = nl_socket_add_membership(global->nl_event, ret);
1474 	if (ret < 0) {
1475 		wpa_printf(MSG_ERROR, "nl80211: Could not add multicast "
1476 			   "membership for mlme events: %d (%s)",
1477 			   ret, strerror(-ret));
1478 		goto err;
1479 	}
1480 
1481 	ret = nl_get_multicast_id(global, "nl80211", "regulatory");
1482 	if (ret >= 0)
1483 		ret = nl_socket_add_membership(global->nl_event, ret);
1484 	if (ret < 0) {
1485 		wpa_printf(MSG_DEBUG, "nl80211: Could not add multicast "
1486 			   "membership for regulatory events: %d (%s)",
1487 			   ret, strerror(-ret));
1488 		/* Continue without regulatory events */
1489 	}
1490 
1491 	ret = nl_get_multicast_id(global, "nl80211", "vendor");
1492 	if (ret >= 0)
1493 		ret = nl_socket_add_membership(global->nl_event, ret);
1494 	if (ret < 0) {
1495 		wpa_printf(MSG_DEBUG, "nl80211: Could not add multicast "
1496 			   "membership for vendor events: %d (%s)",
1497 			   ret, strerror(-ret));
1498 		/* Continue without vendor events */
1499 	}
1500 
1501 	nl_cb_set(global->nl_cb, NL_CB_SEQ_CHECK, NL_CB_CUSTOM,
1502 		  no_seq_check, NULL);
1503 	nl_cb_set(global->nl_cb, NL_CB_VALID, NL_CB_CUSTOM,
1504 		  process_global_event, global);
1505 
1506 	nl80211_register_eloop_read(&global->nl_event,
1507 				    wpa_driver_nl80211_event_receive,
1508 				    global->nl_cb);
1509 
1510 	return 0;
1511 
1512 err:
1513 	nl_destroy_handles(&global->nl_event);
1514 	nl_destroy_handles(&global->nl);
1515 	nl_cb_put(global->nl_cb);
1516 	global->nl_cb = NULL;
1517 	return -1;
1518 }
1519 
1520 
1521 static void nl80211_check_global(struct nl80211_global *global)
1522 {
1523 	struct nl_handle *handle;
1524 	const char *groups[] = { "scan", "mlme", "regulatory", "vendor", NULL };
1525 	int ret;
1526 	unsigned int i;
1527 
1528 	/*
1529 	 * Try to re-add memberships to handle case of cfg80211 getting reloaded
1530 	 * and all registration having been cleared.
1531 	 */
1532 	handle = (void *) (((intptr_t) global->nl_event) ^
1533 			   ELOOP_SOCKET_INVALID);
1534 
1535 	for (i = 0; groups[i]; i++) {
1536 		ret = nl_get_multicast_id(global, "nl80211", groups[i]);
1537 		if (ret >= 0)
1538 			ret = nl_socket_add_membership(handle, ret);
1539 		if (ret < 0) {
1540 			wpa_printf(MSG_INFO,
1541 				   "nl80211: Could not re-add multicast membership for %s events: %d (%s)",
1542 				   groups[i], ret, strerror(-ret));
1543 		}
1544 	}
1545 }
1546 
1547 
1548 static void wpa_driver_nl80211_rfkill_blocked(void *ctx)
1549 {
1550 	struct wpa_driver_nl80211_data *drv = ctx;
1551 
1552 	wpa_printf(MSG_DEBUG, "nl80211: RFKILL blocked");
1553 
1554 	/*
1555 	 * rtnetlink ifdown handler will report interfaces other than the P2P
1556 	 * Device interface as disabled.
1557 	 */
1558 	if (drv->nlmode == NL80211_IFTYPE_P2P_DEVICE)
1559 		wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_DISABLED, NULL);
1560 }
1561 
1562 
1563 static void wpa_driver_nl80211_rfkill_unblocked(void *ctx)
1564 {
1565 	struct wpa_driver_nl80211_data *drv = ctx;
1566 	wpa_printf(MSG_DEBUG, "nl80211: RFKILL unblocked");
1567 	if (i802_set_iface_flags(drv->first_bss, 1)) {
1568 		wpa_printf(MSG_DEBUG, "nl80211: Could not set interface UP "
1569 			   "after rfkill unblock");
1570 		return;
1571 	}
1572 
1573 	if (is_p2p_net_interface(drv->nlmode))
1574 		nl80211_disable_11b_rates(drv, drv->ifindex, 1);
1575 
1576 	/*
1577 	 * rtnetlink ifup handler will report interfaces other than the P2P
1578 	 * Device interface as enabled.
1579 	 */
1580 	if (drv->nlmode == NL80211_IFTYPE_P2P_DEVICE)
1581 		wpa_supplicant_event(drv->ctx, EVENT_INTERFACE_ENABLED, NULL);
1582 }
1583 
1584 
1585 static void wpa_driver_nl80211_handle_eapol_tx_status(int sock,
1586 						      void *eloop_ctx,
1587 						      void *handle)
1588 {
1589 	struct wpa_driver_nl80211_data *drv = eloop_ctx;
1590 	u8 data[2048];
1591 	struct msghdr msg;
1592 	struct iovec entry;
1593 	u8 control[512];
1594 	struct cmsghdr *cmsg;
1595 	int res, found_ee = 0, found_wifi = 0, acked = 0;
1596 	union wpa_event_data event;
1597 
1598 	memset(&msg, 0, sizeof(msg));
1599 	msg.msg_iov = &entry;
1600 	msg.msg_iovlen = 1;
1601 	entry.iov_base = data;
1602 	entry.iov_len = sizeof(data);
1603 	msg.msg_control = &control;
1604 	msg.msg_controllen = sizeof(control);
1605 
1606 	res = recvmsg(sock, &msg, MSG_ERRQUEUE);
1607 	/* if error or not fitting 802.3 header, return */
1608 	if (res < 14)
1609 		return;
1610 
1611 	for (cmsg = CMSG_FIRSTHDR(&msg); cmsg; cmsg = CMSG_NXTHDR(&msg, cmsg))
1612 	{
1613 		if (cmsg->cmsg_level == SOL_SOCKET &&
1614 		    cmsg->cmsg_type == SCM_WIFI_STATUS) {
1615 			int *ack;
1616 
1617 			found_wifi = 1;
1618 			ack = (void *)CMSG_DATA(cmsg);
1619 			acked = *ack;
1620 		}
1621 
1622 		if (cmsg->cmsg_level == SOL_PACKET &&
1623 		    cmsg->cmsg_type == PACKET_TX_TIMESTAMP) {
1624 			struct sock_extended_err *err =
1625 				(struct sock_extended_err *)CMSG_DATA(cmsg);
1626 
1627 			if (err->ee_origin == SO_EE_ORIGIN_TXSTATUS)
1628 				found_ee = 1;
1629 		}
1630 	}
1631 
1632 	if (!found_ee || !found_wifi)
1633 		return;
1634 
1635 	memset(&event, 0, sizeof(event));
1636 	event.eapol_tx_status.dst = data;
1637 	event.eapol_tx_status.data = data + 14;
1638 	event.eapol_tx_status.data_len = res - 14;
1639 	event.eapol_tx_status.ack = acked;
1640 	wpa_supplicant_event(drv->ctx, EVENT_EAPOL_TX_STATUS, &event);
1641 }
1642 
1643 
1644 static int nl80211_init_bss(struct i802_bss *bss)
1645 {
1646 	bss->nl_cb = nl_cb_alloc(NL_CB_DEFAULT);
1647 	if (!bss->nl_cb)
1648 		return -1;
1649 
1650 	nl_cb_set(bss->nl_cb, NL_CB_SEQ_CHECK, NL_CB_CUSTOM,
1651 		  no_seq_check, NULL);
1652 	nl_cb_set(bss->nl_cb, NL_CB_VALID, NL_CB_CUSTOM,
1653 		  process_bss_event, bss);
1654 
1655 	return 0;
1656 }
1657 
1658 
1659 static void nl80211_destroy_bss(struct i802_bss *bss)
1660 {
1661 	nl_cb_put(bss->nl_cb);
1662 	bss->nl_cb = NULL;
1663 }
1664 
1665 
1666 static void
1667 wpa_driver_nl80211_drv_init_rfkill(struct wpa_driver_nl80211_data *drv)
1668 {
1669 	struct rfkill_config *rcfg;
1670 
1671 	if (drv->rfkill)
1672 		return;
1673 
1674 	rcfg = os_zalloc(sizeof(*rcfg));
1675 	if (!rcfg)
1676 		return;
1677 
1678 	rcfg->ctx = drv;
1679 
1680 	/* rfkill uses netdev sysfs for initialization. However, P2P Device is
1681 	 * not associated with a netdev, so use the name of some other interface
1682 	 * sharing the same wiphy as the P2P Device interface.
1683 	 *
1684 	 * Note: This is valid, as a P2P Device interface is always dynamically
1685 	 * created and is created only once another wpa_s interface was added.
1686 	 */
1687 	if (drv->nlmode == NL80211_IFTYPE_P2P_DEVICE) {
1688 		struct nl80211_global *global = drv->global;
1689 		struct wpa_driver_nl80211_data *tmp1;
1690 
1691 		dl_list_for_each(tmp1, &global->interfaces,
1692 				 struct wpa_driver_nl80211_data, list) {
1693 			if (drv == tmp1 || drv->wiphy_idx != tmp1->wiphy_idx ||
1694 			    !tmp1->rfkill)
1695 				continue;
1696 
1697 			wpa_printf(MSG_DEBUG,
1698 				   "nl80211: Use (%s) to initialize P2P Device rfkill",
1699 				   tmp1->first_bss->ifname);
1700 			os_strlcpy(rcfg->ifname, tmp1->first_bss->ifname,
1701 				   sizeof(rcfg->ifname));
1702 			break;
1703 		}
1704 	} else {
1705 		os_strlcpy(rcfg->ifname, drv->first_bss->ifname,
1706 			   sizeof(rcfg->ifname));
1707 	}
1708 
1709 	rcfg->blocked_cb = wpa_driver_nl80211_rfkill_blocked;
1710 	rcfg->unblocked_cb = wpa_driver_nl80211_rfkill_unblocked;
1711 	drv->rfkill = rfkill_init(rcfg);
1712 	if (!drv->rfkill) {
1713 		wpa_printf(MSG_DEBUG, "nl80211: RFKILL status not available");
1714 		os_free(rcfg);
1715 	}
1716 }
1717 
1718 
1719 static void * wpa_driver_nl80211_drv_init(void *ctx, const char *ifname,
1720 					  void *global_priv, int hostapd,
1721 					  const u8 *set_addr,
1722 					  const char *driver_params)
1723 {
1724 	struct wpa_driver_nl80211_data *drv;
1725 	struct i802_bss *bss;
1726 
1727 	if (global_priv == NULL)
1728 		return NULL;
1729 	drv = os_zalloc(sizeof(*drv));
1730 	if (drv == NULL)
1731 		return NULL;
1732 	drv->global = global_priv;
1733 	drv->ctx = ctx;
1734 	drv->hostapd = !!hostapd;
1735 	drv->eapol_sock = -1;
1736 
1737 	/*
1738 	 * There is no driver capability flag for this, so assume it is
1739 	 * supported and disable this on first attempt to use if the driver
1740 	 * rejects the command due to missing support.
1741 	 */
1742 	drv->set_rekey_offload = 1;
1743 
1744 	drv->num_if_indices = sizeof(drv->default_if_indices) / sizeof(int);
1745 	drv->if_indices = drv->default_if_indices;
1746 	drv->if_indices_reason = drv->default_if_indices_reason;
1747 
1748 	drv->first_bss = os_zalloc(sizeof(*drv->first_bss));
1749 	if (!drv->first_bss) {
1750 		os_free(drv);
1751 		return NULL;
1752 	}
1753 	bss = drv->first_bss;
1754 	bss->drv = drv;
1755 	bss->ctx = ctx;
1756 
1757 	os_strlcpy(bss->ifname, ifname, sizeof(bss->ifname));
1758 	drv->monitor_ifidx = -1;
1759 	drv->monitor_sock = -1;
1760 	drv->eapol_tx_sock = -1;
1761 	drv->ap_scan_as_station = NL80211_IFTYPE_UNSPECIFIED;
1762 
1763 	if (nl80211_init_bss(bss))
1764 		goto failed;
1765 
1766 	if (wpa_driver_nl80211_finish_drv_init(drv, set_addr, 1, driver_params))
1767 		goto failed;
1768 
1769 	drv->eapol_tx_sock = socket(PF_PACKET, SOCK_DGRAM, 0);
1770 	if (drv->eapol_tx_sock < 0)
1771 		goto failed;
1772 
1773 	if (drv->data_tx_status) {
1774 		int enabled = 1;
1775 
1776 		if (setsockopt(drv->eapol_tx_sock, SOL_SOCKET, SO_WIFI_STATUS,
1777 			       &enabled, sizeof(enabled)) < 0) {
1778 			wpa_printf(MSG_DEBUG,
1779 				"nl80211: wifi status sockopt failed\n");
1780 			drv->data_tx_status = 0;
1781 			if (!drv->use_monitor)
1782 				drv->capa.flags &=
1783 					~WPA_DRIVER_FLAGS_EAPOL_TX_STATUS;
1784 		} else {
1785 			eloop_register_read_sock(drv->eapol_tx_sock,
1786 				wpa_driver_nl80211_handle_eapol_tx_status,
1787 				drv, NULL);
1788 		}
1789 	}
1790 
1791 	if (drv->global) {
1792 		nl80211_check_global(drv->global);
1793 		dl_list_add(&drv->global->interfaces, &drv->list);
1794 		drv->in_interface_list = 1;
1795 	}
1796 
1797 	return bss;
1798 
1799 failed:
1800 	wpa_driver_nl80211_deinit(bss);
1801 	return NULL;
1802 }
1803 
1804 
1805 /**
1806  * wpa_driver_nl80211_init - Initialize nl80211 driver interface
1807  * @ctx: context to be used when calling wpa_supplicant functions,
1808  * e.g., wpa_supplicant_event()
1809  * @ifname: interface name, e.g., wlan0
1810  * @global_priv: private driver global data from global_init()
1811  * Returns: Pointer to private data, %NULL on failure
1812  */
1813 static void * wpa_driver_nl80211_init(void *ctx, const char *ifname,
1814 				      void *global_priv)
1815 {
1816 	return wpa_driver_nl80211_drv_init(ctx, ifname, global_priv, 0, NULL,
1817 					   NULL);
1818 }
1819 
1820 
1821 static int nl80211_register_frame(struct i802_bss *bss,
1822 				  struct nl_handle *nl_handle,
1823 				  u16 type, const u8 *match, size_t match_len)
1824 {
1825 	struct wpa_driver_nl80211_data *drv = bss->drv;
1826 	struct nl_msg *msg;
1827 	int ret;
1828 	char buf[30];
1829 
1830 	buf[0] = '\0';
1831 	wpa_snprintf_hex(buf, sizeof(buf), match, match_len);
1832 	wpa_printf(MSG_DEBUG, "nl80211: Register frame type=0x%x (%s) nl_handle=%p match=%s",
1833 		   type, fc2str(type), nl_handle, buf);
1834 
1835 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_REGISTER_ACTION)) ||
1836 	    nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE, type) ||
1837 	    nla_put(msg, NL80211_ATTR_FRAME_MATCH, match_len, match)) {
1838 		nlmsg_free(msg);
1839 		return -1;
1840 	}
1841 
1842 	ret = send_and_recv(drv->global, nl_handle, msg, NULL, NULL);
1843 	if (ret) {
1844 		wpa_printf(MSG_DEBUG, "nl80211: Register frame command "
1845 			   "failed (type=%u): ret=%d (%s)",
1846 			   type, ret, strerror(-ret));
1847 		wpa_hexdump(MSG_DEBUG, "nl80211: Register frame match",
1848 			    match, match_len);
1849 	}
1850 	return ret;
1851 }
1852 
1853 
1854 static int nl80211_alloc_mgmt_handle(struct i802_bss *bss)
1855 {
1856 	if (bss->nl_mgmt) {
1857 		wpa_printf(MSG_DEBUG, "nl80211: Mgmt reporting "
1858 			   "already on! (nl_mgmt=%p)", bss->nl_mgmt);
1859 		return -1;
1860 	}
1861 
1862 	bss->nl_mgmt = nl_create_handle(bss->nl_cb, "mgmt");
1863 	if (bss->nl_mgmt == NULL)
1864 		return -1;
1865 
1866 	return 0;
1867 }
1868 
1869 
1870 static void nl80211_mgmt_handle_register_eloop(struct i802_bss *bss)
1871 {
1872 	nl80211_register_eloop_read(&bss->nl_mgmt,
1873 				    wpa_driver_nl80211_event_receive,
1874 				    bss->nl_cb);
1875 }
1876 
1877 
1878 static int nl80211_register_action_frame(struct i802_bss *bss,
1879 					 const u8 *match, size_t match_len)
1880 {
1881 	u16 type = (WLAN_FC_TYPE_MGMT << 2) | (WLAN_FC_STYPE_ACTION << 4);
1882 	return nl80211_register_frame(bss, bss->nl_mgmt,
1883 				      type, match, match_len);
1884 }
1885 
1886 
1887 static int nl80211_mgmt_subscribe_non_ap(struct i802_bss *bss)
1888 {
1889 	struct wpa_driver_nl80211_data *drv = bss->drv;
1890 	int ret = 0;
1891 
1892 	if (nl80211_alloc_mgmt_handle(bss))
1893 		return -1;
1894 	wpa_printf(MSG_DEBUG, "nl80211: Subscribe to mgmt frames with non-AP "
1895 		   "handle %p", bss->nl_mgmt);
1896 
1897 	if (drv->nlmode == NL80211_IFTYPE_ADHOC) {
1898 		u16 type = (WLAN_FC_TYPE_MGMT << 2) | (WLAN_FC_STYPE_AUTH << 4);
1899 
1900 		/* register for any AUTH message */
1901 		nl80211_register_frame(bss, bss->nl_mgmt, type, NULL, 0);
1902 	}
1903 
1904 #ifdef CONFIG_INTERWORKING
1905 	/* QoS Map Configure */
1906 	if (nl80211_register_action_frame(bss, (u8 *) "\x01\x04", 2) < 0)
1907 		ret = -1;
1908 #endif /* CONFIG_INTERWORKING */
1909 #if defined(CONFIG_P2P) || defined(CONFIG_INTERWORKING)
1910 	/* GAS Initial Request */
1911 	if (nl80211_register_action_frame(bss, (u8 *) "\x04\x0a", 2) < 0)
1912 		ret = -1;
1913 	/* GAS Initial Response */
1914 	if (nl80211_register_action_frame(bss, (u8 *) "\x04\x0b", 2) < 0)
1915 		ret = -1;
1916 	/* GAS Comeback Request */
1917 	if (nl80211_register_action_frame(bss, (u8 *) "\x04\x0c", 2) < 0)
1918 		ret = -1;
1919 	/* GAS Comeback Response */
1920 	if (nl80211_register_action_frame(bss, (u8 *) "\x04\x0d", 2) < 0)
1921 		ret = -1;
1922 	/* Protected GAS Initial Request */
1923 	if (nl80211_register_action_frame(bss, (u8 *) "\x09\x0a", 2) < 0)
1924 		ret = -1;
1925 	/* Protected GAS Initial Response */
1926 	if (nl80211_register_action_frame(bss, (u8 *) "\x09\x0b", 2) < 0)
1927 		ret = -1;
1928 	/* Protected GAS Comeback Request */
1929 	if (nl80211_register_action_frame(bss, (u8 *) "\x09\x0c", 2) < 0)
1930 		ret = -1;
1931 	/* Protected GAS Comeback Response */
1932 	if (nl80211_register_action_frame(bss, (u8 *) "\x09\x0d", 2) < 0)
1933 		ret = -1;
1934 #endif /* CONFIG_P2P || CONFIG_INTERWORKING */
1935 #ifdef CONFIG_P2P
1936 	/* P2P Public Action */
1937 	if (nl80211_register_action_frame(bss,
1938 					  (u8 *) "\x04\x09\x50\x6f\x9a\x09",
1939 					  6) < 0)
1940 		ret = -1;
1941 	/* P2P Action */
1942 	if (nl80211_register_action_frame(bss,
1943 					  (u8 *) "\x7f\x50\x6f\x9a\x09",
1944 					  5) < 0)
1945 		ret = -1;
1946 #endif /* CONFIG_P2P */
1947 #ifdef CONFIG_IEEE80211W
1948 	/* SA Query Response */
1949 	if (nl80211_register_action_frame(bss, (u8 *) "\x08\x01", 2) < 0)
1950 		ret = -1;
1951 #endif /* CONFIG_IEEE80211W */
1952 #ifdef CONFIG_TDLS
1953 	if ((drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_SUPPORT)) {
1954 		/* TDLS Discovery Response */
1955 		if (nl80211_register_action_frame(bss, (u8 *) "\x04\x0e", 2) <
1956 		    0)
1957 			ret = -1;
1958 	}
1959 #endif /* CONFIG_TDLS */
1960 #ifdef CONFIG_FST
1961 	/* FST Action frames */
1962 	if (nl80211_register_action_frame(bss, (u8 *) "\x12", 1) < 0)
1963 		ret = -1;
1964 #endif /* CONFIG_FST */
1965 
1966 	/* FT Action frames */
1967 	if (nl80211_register_action_frame(bss, (u8 *) "\x06", 1) < 0)
1968 		ret = -1;
1969 	else
1970 		drv->capa.key_mgmt |= WPA_DRIVER_CAPA_KEY_MGMT_FT |
1971 			WPA_DRIVER_CAPA_KEY_MGMT_FT_PSK;
1972 
1973 	/* WNM - BSS Transition Management Request */
1974 	if (nl80211_register_action_frame(bss, (u8 *) "\x0a\x07", 2) < 0)
1975 		ret = -1;
1976 	/* WNM-Sleep Mode Response */
1977 	if (nl80211_register_action_frame(bss, (u8 *) "\x0a\x11", 2) < 0)
1978 		ret = -1;
1979 
1980 #ifdef CONFIG_HS20
1981 	/* WNM-Notification */
1982 	if (nl80211_register_action_frame(bss, (u8 *) "\x0a\x1a", 2) < 0)
1983 		ret = -1;
1984 #endif /* CONFIG_HS20 */
1985 
1986 	/* WMM-AC ADDTS Response */
1987 	if (nl80211_register_action_frame(bss, (u8 *) "\x11\x01", 2) < 0)
1988 		ret = -1;
1989 
1990 	/* WMM-AC DELTS */
1991 	if (nl80211_register_action_frame(bss, (u8 *) "\x11\x02", 2) < 0)
1992 		ret = -1;
1993 
1994 	/* Radio Measurement - Neighbor Report Response */
1995 	if (nl80211_register_action_frame(bss, (u8 *) "\x05\x05", 2) < 0)
1996 		ret = -1;
1997 
1998 	/* Radio Measurement - Radio Measurement Request */
1999 	if (nl80211_register_action_frame(bss, (u8 *) "\x05\x00", 2) < 0)
2000 		ret = -1;
2001 
2002 	/* Radio Measurement - Link Measurement Request */
2003 	if ((drv->capa.rrm_flags & WPA_DRIVER_FLAGS_TX_POWER_INSERTION) &&
2004 	    (nl80211_register_action_frame(bss, (u8 *) "\x05\x02", 2) < 0))
2005 		ret = -1;
2006 
2007 	nl80211_mgmt_handle_register_eloop(bss);
2008 
2009 	return ret;
2010 }
2011 
2012 
2013 static int nl80211_mgmt_subscribe_mesh(struct i802_bss *bss)
2014 {
2015 	int ret = 0;
2016 
2017 	if (nl80211_alloc_mgmt_handle(bss))
2018 		return -1;
2019 
2020 	wpa_printf(MSG_DEBUG,
2021 		   "nl80211: Subscribe to mgmt frames with mesh handle %p",
2022 		   bss->nl_mgmt);
2023 
2024 	/* Auth frames for mesh SAE */
2025 	if (nl80211_register_frame(bss, bss->nl_mgmt,
2026 				   (WLAN_FC_TYPE_MGMT << 2) |
2027 				   (WLAN_FC_STYPE_AUTH << 4),
2028 				   NULL, 0) < 0)
2029 		ret = -1;
2030 
2031 	/* Mesh peering open */
2032 	if (nl80211_register_action_frame(bss, (u8 *) "\x0f\x01", 2) < 0)
2033 		ret = -1;
2034 	/* Mesh peering confirm */
2035 	if (nl80211_register_action_frame(bss, (u8 *) "\x0f\x02", 2) < 0)
2036 		ret = -1;
2037 	/* Mesh peering close */
2038 	if (nl80211_register_action_frame(bss, (u8 *) "\x0f\x03", 2) < 0)
2039 		ret = -1;
2040 
2041 	nl80211_mgmt_handle_register_eloop(bss);
2042 
2043 	return ret;
2044 }
2045 
2046 
2047 static int nl80211_register_spurious_class3(struct i802_bss *bss)
2048 {
2049 	struct nl_msg *msg;
2050 	int ret;
2051 
2052 	msg = nl80211_bss_msg(bss, 0, NL80211_CMD_UNEXPECTED_FRAME);
2053 	ret = send_and_recv(bss->drv->global, bss->nl_mgmt, msg, NULL, NULL);
2054 	if (ret) {
2055 		wpa_printf(MSG_DEBUG, "nl80211: Register spurious class3 "
2056 			   "failed: ret=%d (%s)",
2057 			   ret, strerror(-ret));
2058 	}
2059 	return ret;
2060 }
2061 
2062 
2063 static int nl80211_action_subscribe_ap(struct i802_bss *bss)
2064 {
2065 	int ret = 0;
2066 
2067 	/* Public Action frames */
2068 	if (nl80211_register_action_frame(bss, (u8 *) "\x04", 1) < 0)
2069 		ret = -1;
2070 	/* RRM Measurement Report */
2071 	if (nl80211_register_action_frame(bss, (u8 *) "\x05\x01", 2) < 0)
2072 		ret = -1;
2073 	/* RRM Neighbor Report Request */
2074 	if (nl80211_register_action_frame(bss, (u8 *) "\x05\x04", 2) < 0)
2075 		ret = -1;
2076 	/* FT Action frames */
2077 	if (nl80211_register_action_frame(bss, (u8 *) "\x06", 1) < 0)
2078 		ret = -1;
2079 #ifdef CONFIG_IEEE80211W
2080 	/* SA Query */
2081 	if (nl80211_register_action_frame(bss, (u8 *) "\x08", 1) < 0)
2082 		ret = -1;
2083 #endif /* CONFIG_IEEE80211W */
2084 	/* Protected Dual of Public Action */
2085 	if (nl80211_register_action_frame(bss, (u8 *) "\x09", 1) < 0)
2086 		ret = -1;
2087 	/* WNM */
2088 	if (nl80211_register_action_frame(bss, (u8 *) "\x0a", 1) < 0)
2089 		ret = -1;
2090 	/* WMM */
2091 	if (nl80211_register_action_frame(bss, (u8 *) "\x11", 1) < 0)
2092 		ret = -1;
2093 #ifdef CONFIG_FST
2094 	/* FST Action frames */
2095 	if (nl80211_register_action_frame(bss, (u8 *) "\x12", 1) < 0)
2096 		ret = -1;
2097 #endif /* CONFIG_FST */
2098 	/* Vendor-specific */
2099 	if (nl80211_register_action_frame(bss, (u8 *) "\x7f", 1) < 0)
2100 		ret = -1;
2101 
2102 	return ret;
2103 }
2104 
2105 
2106 static int nl80211_mgmt_subscribe_ap(struct i802_bss *bss)
2107 {
2108 	static const int stypes[] = {
2109 		WLAN_FC_STYPE_AUTH,
2110 		WLAN_FC_STYPE_ASSOC_REQ,
2111 		WLAN_FC_STYPE_REASSOC_REQ,
2112 		WLAN_FC_STYPE_DISASSOC,
2113 		WLAN_FC_STYPE_DEAUTH,
2114 		WLAN_FC_STYPE_PROBE_REQ,
2115 /* Beacon doesn't work as mac80211 doesn't currently allow
2116  * it, but it wouldn't really be the right thing anyway as
2117  * it isn't per interface ... maybe just dump the scan
2118  * results periodically for OLBC?
2119  */
2120 		/* WLAN_FC_STYPE_BEACON, */
2121 	};
2122 	unsigned int i;
2123 
2124 	if (nl80211_alloc_mgmt_handle(bss))
2125 		return -1;
2126 	wpa_printf(MSG_DEBUG, "nl80211: Subscribe to mgmt frames with AP "
2127 		   "handle %p", bss->nl_mgmt);
2128 
2129 	for (i = 0; i < ARRAY_SIZE(stypes); i++) {
2130 		if (nl80211_register_frame(bss, bss->nl_mgmt,
2131 					   (WLAN_FC_TYPE_MGMT << 2) |
2132 					   (stypes[i] << 4),
2133 					   NULL, 0) < 0) {
2134 			goto out_err;
2135 		}
2136 	}
2137 
2138 	if (nl80211_action_subscribe_ap(bss))
2139 		goto out_err;
2140 
2141 	if (nl80211_register_spurious_class3(bss))
2142 		goto out_err;
2143 
2144 	if (nl80211_get_wiphy_data_ap(bss) == NULL)
2145 		goto out_err;
2146 
2147 	nl80211_mgmt_handle_register_eloop(bss);
2148 	return 0;
2149 
2150 out_err:
2151 	nl_destroy_handles(&bss->nl_mgmt);
2152 	return -1;
2153 }
2154 
2155 
2156 static int nl80211_mgmt_subscribe_ap_dev_sme(struct i802_bss *bss)
2157 {
2158 	if (nl80211_alloc_mgmt_handle(bss))
2159 		return -1;
2160 	wpa_printf(MSG_DEBUG, "nl80211: Subscribe to mgmt frames with AP "
2161 		   "handle %p (device SME)", bss->nl_mgmt);
2162 
2163 	if (nl80211_action_subscribe_ap(bss))
2164 		goto out_err;
2165 
2166 	nl80211_mgmt_handle_register_eloop(bss);
2167 	return 0;
2168 
2169 out_err:
2170 	nl_destroy_handles(&bss->nl_mgmt);
2171 	return -1;
2172 }
2173 
2174 
2175 static void nl80211_mgmt_unsubscribe(struct i802_bss *bss, const char *reason)
2176 {
2177 	if (bss->nl_mgmt == NULL)
2178 		return;
2179 	wpa_printf(MSG_DEBUG, "nl80211: Unsubscribe mgmt frames handle %p "
2180 		   "(%s)", bss->nl_mgmt, reason);
2181 	nl80211_destroy_eloop_handle(&bss->nl_mgmt);
2182 
2183 	nl80211_put_wiphy_data_ap(bss);
2184 }
2185 
2186 
2187 static void wpa_driver_nl80211_send_rfkill(void *eloop_ctx, void *timeout_ctx)
2188 {
2189 	wpa_supplicant_event(timeout_ctx, EVENT_INTERFACE_DISABLED, NULL);
2190 }
2191 
2192 
2193 static void nl80211_del_p2pdev(struct i802_bss *bss)
2194 {
2195 	struct nl_msg *msg;
2196 	int ret;
2197 
2198 	msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_DEL_INTERFACE);
2199 	ret = send_and_recv_msgs(bss->drv, msg, NULL, NULL);
2200 
2201 	wpa_printf(MSG_DEBUG, "nl80211: Delete P2P Device %s (0x%llx): %s",
2202 		   bss->ifname, (long long unsigned int) bss->wdev_id,
2203 		   strerror(-ret));
2204 }
2205 
2206 
2207 static int nl80211_set_p2pdev(struct i802_bss *bss, int start)
2208 {
2209 	struct nl_msg *msg;
2210 	int ret;
2211 
2212 	msg = nl80211_cmd_msg(bss, 0, start ? NL80211_CMD_START_P2P_DEVICE :
2213 			      NL80211_CMD_STOP_P2P_DEVICE);
2214 	ret = send_and_recv_msgs(bss->drv, msg, NULL, NULL);
2215 
2216 	wpa_printf(MSG_DEBUG, "nl80211: %s P2P Device %s (0x%llx): %s",
2217 		   start ? "Start" : "Stop",
2218 		   bss->ifname, (long long unsigned int) bss->wdev_id,
2219 		   strerror(-ret));
2220 	return ret;
2221 }
2222 
2223 
2224 static int i802_set_iface_flags(struct i802_bss *bss, int up)
2225 {
2226 	enum nl80211_iftype nlmode;
2227 
2228 	nlmode = nl80211_get_ifmode(bss);
2229 	if (nlmode != NL80211_IFTYPE_P2P_DEVICE) {
2230 		return linux_set_iface_flags(bss->drv->global->ioctl_sock,
2231 					     bss->ifname, up);
2232 	}
2233 
2234 	/* P2P Device has start/stop which is equivalent */
2235 	return nl80211_set_p2pdev(bss, up);
2236 }
2237 
2238 
2239 #ifdef CONFIG_TESTING_OPTIONS
2240 static int qca_vendor_test_cmd_handler(struct nl_msg *msg, void *arg)
2241 {
2242 	/* struct wpa_driver_nl80211_data *drv = arg; */
2243 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
2244 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
2245 
2246 
2247 	wpa_printf(MSG_DEBUG,
2248 		   "nl80211: QCA vendor test command response received");
2249 
2250 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
2251 		  genlmsg_attrlen(gnlh, 0), NULL);
2252 	if (!tb[NL80211_ATTR_VENDOR_DATA]) {
2253 		wpa_printf(MSG_DEBUG, "nl80211: No vendor data attribute");
2254 		return NL_SKIP;
2255 	}
2256 
2257 	wpa_hexdump(MSG_DEBUG,
2258 		    "nl80211: Received QCA vendor test command response",
2259 		    nla_data(tb[NL80211_ATTR_VENDOR_DATA]),
2260 		    nla_len(tb[NL80211_ATTR_VENDOR_DATA]));
2261 
2262 	return NL_SKIP;
2263 }
2264 #endif /* CONFIG_TESTING_OPTIONS */
2265 
2266 
2267 static void qca_vendor_test(struct wpa_driver_nl80211_data *drv)
2268 {
2269 #ifdef CONFIG_TESTING_OPTIONS
2270 	struct nl_msg *msg;
2271 	struct nlattr *params;
2272 	int ret;
2273 
2274 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
2275 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
2276 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
2277 			QCA_NL80211_VENDOR_SUBCMD_TEST) ||
2278 	    !(params = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA)) ||
2279 	    nla_put_u32(msg, QCA_WLAN_VENDOR_ATTR_TEST, 123)) {
2280 		nlmsg_free(msg);
2281 		return;
2282 	}
2283 	nla_nest_end(msg, params);
2284 
2285 	ret = send_and_recv_msgs(drv, msg, qca_vendor_test_cmd_handler, drv);
2286 	wpa_printf(MSG_DEBUG,
2287 		   "nl80211: QCA vendor test command returned %d (%s)",
2288 		   ret, strerror(-ret));
2289 #endif /* CONFIG_TESTING_OPTIONS */
2290 }
2291 
2292 
2293 static int
2294 wpa_driver_nl80211_finish_drv_init(struct wpa_driver_nl80211_data *drv,
2295 				   const u8 *set_addr, int first,
2296 				   const char *driver_params)
2297 {
2298 	struct i802_bss *bss = drv->first_bss;
2299 	int send_rfkill_event = 0;
2300 	enum nl80211_iftype nlmode;
2301 
2302 	drv->ifindex = if_nametoindex(bss->ifname);
2303 	bss->ifindex = drv->ifindex;
2304 	bss->wdev_id = drv->global->if_add_wdevid;
2305 	bss->wdev_id_set = drv->global->if_add_wdevid_set;
2306 
2307 	bss->if_dynamic = drv->ifindex == drv->global->if_add_ifindex;
2308 	bss->if_dynamic = bss->if_dynamic || drv->global->if_add_wdevid_set;
2309 	drv->global->if_add_wdevid_set = 0;
2310 
2311 	if (!bss->if_dynamic && nl80211_get_ifmode(bss) == NL80211_IFTYPE_AP)
2312 		bss->static_ap = 1;
2313 
2314 	if (first &&
2315 	    nl80211_get_ifmode(bss) != NL80211_IFTYPE_P2P_DEVICE &&
2316 	    linux_iface_up(drv->global->ioctl_sock, bss->ifname) > 0)
2317 		drv->start_iface_up = 1;
2318 
2319 	if (wpa_driver_nl80211_capa(drv))
2320 		return -1;
2321 
2322 	if (driver_params && nl80211_set_param(bss, driver_params) < 0)
2323 		return -1;
2324 
2325 	wpa_printf(MSG_DEBUG, "nl80211: interface %s in phy %s",
2326 		   bss->ifname, drv->phyname);
2327 
2328 	if (set_addr &&
2329 	    (linux_set_iface_flags(drv->global->ioctl_sock, bss->ifname, 0) ||
2330 	     linux_set_ifhwaddr(drv->global->ioctl_sock, bss->ifname,
2331 				set_addr)))
2332 		return -1;
2333 
2334 	if (first && nl80211_get_ifmode(bss) == NL80211_IFTYPE_AP)
2335 		drv->start_mode_ap = 1;
2336 
2337 	if (drv->hostapd || bss->static_ap)
2338 		nlmode = NL80211_IFTYPE_AP;
2339 	else if (bss->if_dynamic ||
2340 		 nl80211_get_ifmode(bss) == NL80211_IFTYPE_MESH_POINT)
2341 		nlmode = nl80211_get_ifmode(bss);
2342 	else
2343 		nlmode = NL80211_IFTYPE_STATION;
2344 
2345 	if (wpa_driver_nl80211_set_mode(bss, nlmode) < 0) {
2346 		wpa_printf(MSG_ERROR, "nl80211: Could not configure driver mode");
2347 		return -1;
2348 	}
2349 
2350 	if (nlmode == NL80211_IFTYPE_P2P_DEVICE)
2351 		nl80211_get_macaddr(bss);
2352 
2353 	wpa_driver_nl80211_drv_init_rfkill(drv);
2354 
2355 	if (!rfkill_is_blocked(drv->rfkill)) {
2356 		int ret = i802_set_iface_flags(bss, 1);
2357 		if (ret) {
2358 			wpa_printf(MSG_ERROR, "nl80211: Could not set "
2359 				   "interface '%s' UP", bss->ifname);
2360 			return ret;
2361 		}
2362 
2363 		if (is_p2p_net_interface(nlmode))
2364 			nl80211_disable_11b_rates(bss->drv,
2365 						  bss->drv->ifindex, 1);
2366 
2367 		if (nlmode == NL80211_IFTYPE_P2P_DEVICE)
2368 			return ret;
2369 	} else {
2370 		wpa_printf(MSG_DEBUG, "nl80211: Could not yet enable "
2371 			   "interface '%s' due to rfkill", bss->ifname);
2372 		if (nlmode != NL80211_IFTYPE_P2P_DEVICE)
2373 			drv->if_disabled = 1;
2374 
2375 		send_rfkill_event = 1;
2376 	}
2377 
2378 	if (!drv->hostapd && nlmode != NL80211_IFTYPE_P2P_DEVICE)
2379 		netlink_send_oper_ifla(drv->global->netlink, drv->ifindex,
2380 				       1, IF_OPER_DORMANT);
2381 
2382 	if (nlmode != NL80211_IFTYPE_P2P_DEVICE) {
2383 		if (linux_get_ifhwaddr(drv->global->ioctl_sock, bss->ifname,
2384 				       bss->addr))
2385 			return -1;
2386 		os_memcpy(drv->perm_addr, bss->addr, ETH_ALEN);
2387 	}
2388 
2389 	if (send_rfkill_event) {
2390 		eloop_register_timeout(0, 0, wpa_driver_nl80211_send_rfkill,
2391 				       drv, drv->ctx);
2392 	}
2393 
2394 	if (drv->vendor_cmd_test_avail)
2395 		qca_vendor_test(drv);
2396 
2397 	return 0;
2398 }
2399 
2400 
2401 static int wpa_driver_nl80211_del_beacon(struct wpa_driver_nl80211_data *drv)
2402 {
2403 	struct nl_msg *msg;
2404 
2405 	wpa_printf(MSG_DEBUG, "nl80211: Remove beacon (ifindex=%d)",
2406 		   drv->ifindex);
2407 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_DEL_BEACON);
2408 	return send_and_recv_msgs(drv, msg, NULL, NULL);
2409 }
2410 
2411 
2412 /**
2413  * wpa_driver_nl80211_deinit - Deinitialize nl80211 driver interface
2414  * @bss: Pointer to private nl80211 data from wpa_driver_nl80211_init()
2415  *
2416  * Shut down driver interface and processing of driver events. Free
2417  * private data buffer if one was allocated in wpa_driver_nl80211_init().
2418  */
2419 static void wpa_driver_nl80211_deinit(struct i802_bss *bss)
2420 {
2421 	struct wpa_driver_nl80211_data *drv = bss->drv;
2422 	unsigned int i;
2423 
2424 	wpa_printf(MSG_INFO, "nl80211: deinit ifname=%s disabled_11b_rates=%d",
2425 		   bss->ifname, drv->disabled_11b_rates);
2426 
2427 	bss->in_deinit = 1;
2428 	if (drv->data_tx_status)
2429 		eloop_unregister_read_sock(drv->eapol_tx_sock);
2430 	if (drv->eapol_tx_sock >= 0)
2431 		close(drv->eapol_tx_sock);
2432 
2433 	if (bss->nl_preq)
2434 		wpa_driver_nl80211_probe_req_report(bss, 0);
2435 	if (bss->added_if_into_bridge) {
2436 		if (linux_br_del_if(drv->global->ioctl_sock, bss->brname,
2437 				    bss->ifname) < 0)
2438 			wpa_printf(MSG_INFO, "nl80211: Failed to remove "
2439 				   "interface %s from bridge %s: %s",
2440 				   bss->ifname, bss->brname, strerror(errno));
2441 		if (drv->rtnl_sk)
2442 			nl80211_handle_destroy(drv->rtnl_sk);
2443 	}
2444 	if (bss->added_bridge) {
2445 		if (linux_set_iface_flags(drv->global->ioctl_sock, bss->brname,
2446 					  0) < 0)
2447 			wpa_printf(MSG_INFO,
2448 				   "nl80211: Could not set bridge %s down",
2449 				   bss->brname);
2450 		if (linux_br_del(drv->global->ioctl_sock, bss->brname) < 0)
2451 			wpa_printf(MSG_INFO, "nl80211: Failed to remove "
2452 				   "bridge %s: %s",
2453 				   bss->brname, strerror(errno));
2454 	}
2455 
2456 	nl80211_remove_monitor_interface(drv);
2457 
2458 	if (is_ap_interface(drv->nlmode))
2459 		wpa_driver_nl80211_del_beacon(drv);
2460 
2461 	if (drv->eapol_sock >= 0) {
2462 		eloop_unregister_read_sock(drv->eapol_sock);
2463 		close(drv->eapol_sock);
2464 	}
2465 
2466 	if (drv->if_indices != drv->default_if_indices)
2467 		os_free(drv->if_indices);
2468 
2469 	if (drv->if_indices_reason != drv->default_if_indices_reason)
2470 		os_free(drv->if_indices_reason);
2471 
2472 	if (drv->disabled_11b_rates)
2473 		nl80211_disable_11b_rates(drv, drv->ifindex, 0);
2474 
2475 	netlink_send_oper_ifla(drv->global->netlink, drv->ifindex, 0,
2476 			       IF_OPER_UP);
2477 	eloop_cancel_timeout(wpa_driver_nl80211_send_rfkill, drv, drv->ctx);
2478 	rfkill_deinit(drv->rfkill);
2479 
2480 	eloop_cancel_timeout(wpa_driver_nl80211_scan_timeout, drv, drv->ctx);
2481 
2482 	if (!drv->start_iface_up)
2483 		(void) i802_set_iface_flags(bss, 0);
2484 
2485 	if (drv->addr_changed) {
2486 		if (linux_set_iface_flags(drv->global->ioctl_sock, bss->ifname,
2487 					  0) < 0) {
2488 			wpa_printf(MSG_DEBUG,
2489 				   "nl80211: Could not set interface down to restore permanent MAC address");
2490 		}
2491 		if (linux_set_ifhwaddr(drv->global->ioctl_sock, bss->ifname,
2492 				       drv->perm_addr) < 0) {
2493 			wpa_printf(MSG_DEBUG,
2494 				   "nl80211: Could not restore permanent MAC address");
2495 		}
2496 	}
2497 
2498 	if (drv->nlmode != NL80211_IFTYPE_P2P_DEVICE) {
2499 		if (!drv->hostapd || !drv->start_mode_ap)
2500 			wpa_driver_nl80211_set_mode(bss,
2501 						    NL80211_IFTYPE_STATION);
2502 		nl80211_mgmt_unsubscribe(bss, "deinit");
2503 	} else {
2504 		nl80211_mgmt_unsubscribe(bss, "deinit");
2505 		nl80211_del_p2pdev(bss);
2506 	}
2507 
2508 	nl80211_destroy_bss(drv->first_bss);
2509 
2510 	os_free(drv->filter_ssids);
2511 
2512 	os_free(drv->auth_ie);
2513 
2514 	if (drv->in_interface_list)
2515 		dl_list_del(&drv->list);
2516 
2517 	os_free(drv->extended_capa);
2518 	os_free(drv->extended_capa_mask);
2519 	for (i = 0; i < drv->num_iface_ext_capa; i++) {
2520 		os_free(drv->iface_ext_capa[i].ext_capa);
2521 		os_free(drv->iface_ext_capa[i].ext_capa_mask);
2522 	}
2523 	os_free(drv->first_bss);
2524 	os_free(drv);
2525 }
2526 
2527 
2528 static u32 wpa_alg_to_cipher_suite(enum wpa_alg alg, size_t key_len)
2529 {
2530 	switch (alg) {
2531 	case WPA_ALG_WEP:
2532 		if (key_len == 5)
2533 			return WLAN_CIPHER_SUITE_WEP40;
2534 		return WLAN_CIPHER_SUITE_WEP104;
2535 	case WPA_ALG_TKIP:
2536 		return WLAN_CIPHER_SUITE_TKIP;
2537 	case WPA_ALG_CCMP:
2538 		return WLAN_CIPHER_SUITE_CCMP;
2539 	case WPA_ALG_GCMP:
2540 		return WLAN_CIPHER_SUITE_GCMP;
2541 	case WPA_ALG_CCMP_256:
2542 		return WLAN_CIPHER_SUITE_CCMP_256;
2543 	case WPA_ALG_GCMP_256:
2544 		return WLAN_CIPHER_SUITE_GCMP_256;
2545 	case WPA_ALG_IGTK:
2546 		return WLAN_CIPHER_SUITE_AES_CMAC;
2547 	case WPA_ALG_BIP_GMAC_128:
2548 		return WLAN_CIPHER_SUITE_BIP_GMAC_128;
2549 	case WPA_ALG_BIP_GMAC_256:
2550 		return WLAN_CIPHER_SUITE_BIP_GMAC_256;
2551 	case WPA_ALG_BIP_CMAC_256:
2552 		return WLAN_CIPHER_SUITE_BIP_CMAC_256;
2553 	case WPA_ALG_SMS4:
2554 		return WLAN_CIPHER_SUITE_SMS4;
2555 	case WPA_ALG_KRK:
2556 		return WLAN_CIPHER_SUITE_KRK;
2557 	case WPA_ALG_NONE:
2558 	case WPA_ALG_PMK:
2559 		wpa_printf(MSG_ERROR, "nl80211: Unexpected encryption algorithm %d",
2560 			   alg);
2561 		return 0;
2562 	}
2563 
2564 	wpa_printf(MSG_ERROR, "nl80211: Unsupported encryption algorithm %d",
2565 		   alg);
2566 	return 0;
2567 }
2568 
2569 
2570 static u32 wpa_cipher_to_cipher_suite(unsigned int cipher)
2571 {
2572 	switch (cipher) {
2573 	case WPA_CIPHER_CCMP_256:
2574 		return WLAN_CIPHER_SUITE_CCMP_256;
2575 	case WPA_CIPHER_GCMP_256:
2576 		return WLAN_CIPHER_SUITE_GCMP_256;
2577 	case WPA_CIPHER_CCMP:
2578 		return WLAN_CIPHER_SUITE_CCMP;
2579 	case WPA_CIPHER_GCMP:
2580 		return WLAN_CIPHER_SUITE_GCMP;
2581 	case WPA_CIPHER_TKIP:
2582 		return WLAN_CIPHER_SUITE_TKIP;
2583 	case WPA_CIPHER_WEP104:
2584 		return WLAN_CIPHER_SUITE_WEP104;
2585 	case WPA_CIPHER_WEP40:
2586 		return WLAN_CIPHER_SUITE_WEP40;
2587 	case WPA_CIPHER_GTK_NOT_USED:
2588 		return WLAN_CIPHER_SUITE_NO_GROUP_ADDR;
2589 	}
2590 
2591 	return 0;
2592 }
2593 
2594 
2595 static int wpa_cipher_to_cipher_suites(unsigned int ciphers, u32 suites[],
2596 				       int max_suites)
2597 {
2598 	int num_suites = 0;
2599 
2600 	if (num_suites < max_suites && ciphers & WPA_CIPHER_CCMP_256)
2601 		suites[num_suites++] = WLAN_CIPHER_SUITE_CCMP_256;
2602 	if (num_suites < max_suites && ciphers & WPA_CIPHER_GCMP_256)
2603 		suites[num_suites++] = WLAN_CIPHER_SUITE_GCMP_256;
2604 	if (num_suites < max_suites && ciphers & WPA_CIPHER_CCMP)
2605 		suites[num_suites++] = WLAN_CIPHER_SUITE_CCMP;
2606 	if (num_suites < max_suites && ciphers & WPA_CIPHER_GCMP)
2607 		suites[num_suites++] = WLAN_CIPHER_SUITE_GCMP;
2608 	if (num_suites < max_suites && ciphers & WPA_CIPHER_TKIP)
2609 		suites[num_suites++] = WLAN_CIPHER_SUITE_TKIP;
2610 	if (num_suites < max_suites && ciphers & WPA_CIPHER_WEP104)
2611 		suites[num_suites++] = WLAN_CIPHER_SUITE_WEP104;
2612 	if (num_suites < max_suites && ciphers & WPA_CIPHER_WEP40)
2613 		suites[num_suites++] = WLAN_CIPHER_SUITE_WEP40;
2614 
2615 	return num_suites;
2616 }
2617 
2618 
2619 #ifdef CONFIG_DRIVER_NL80211_QCA
2620 static int issue_key_mgmt_set_key(struct wpa_driver_nl80211_data *drv,
2621 				  const u8 *key, size_t key_len)
2622 {
2623 	struct nl_msg *msg;
2624 	int ret;
2625 
2626 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_KEY_MGMT_OFFLOAD))
2627 		return 0;
2628 
2629 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
2630 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
2631 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
2632 			QCA_NL80211_VENDOR_SUBCMD_KEY_MGMT_SET_KEY) ||
2633 	    nla_put(msg, NL80211_ATTR_VENDOR_DATA, key_len, key)) {
2634 		nl80211_nlmsg_clear(msg);
2635 		nlmsg_free(msg);
2636 		return -1;
2637 	}
2638 	ret = send_and_recv_msgs(drv, msg, NULL, (void *) -1);
2639 	if (ret) {
2640 		wpa_printf(MSG_DEBUG,
2641 			   "nl80211: Key management set key failed: ret=%d (%s)",
2642 			   ret, strerror(-ret));
2643 	}
2644 
2645 	return ret;
2646 }
2647 #endif /* CONFIG_DRIVER_NL80211_QCA */
2648 
2649 
2650 static int wpa_driver_nl80211_set_key(const char *ifname, struct i802_bss *bss,
2651 				      enum wpa_alg alg, const u8 *addr,
2652 				      int key_idx, int set_tx,
2653 				      const u8 *seq, size_t seq_len,
2654 				      const u8 *key, size_t key_len)
2655 {
2656 	struct wpa_driver_nl80211_data *drv = bss->drv;
2657 	int ifindex;
2658 	struct nl_msg *msg = NULL;
2659 	int ret;
2660 	int tdls = 0;
2661 
2662 	/* Ignore for P2P Device */
2663 	if (drv->nlmode == NL80211_IFTYPE_P2P_DEVICE)
2664 		return 0;
2665 
2666 	ifindex = if_nametoindex(ifname);
2667 	wpa_printf(MSG_DEBUG, "%s: ifindex=%d (%s) alg=%d addr=%p key_idx=%d "
2668 		   "set_tx=%d seq_len=%lu key_len=%lu",
2669 		   __func__, ifindex, ifname, alg, addr, key_idx, set_tx,
2670 		   (unsigned long) seq_len, (unsigned long) key_len);
2671 #ifdef CONFIG_TDLS
2672 	if (key_idx == -1) {
2673 		key_idx = 0;
2674 		tdls = 1;
2675 	}
2676 #endif /* CONFIG_TDLS */
2677 
2678 #ifdef CONFIG_DRIVER_NL80211_QCA
2679 	if (alg == WPA_ALG_PMK &&
2680 	    (drv->capa.flags & WPA_DRIVER_FLAGS_KEY_MGMT_OFFLOAD)) {
2681 		wpa_printf(MSG_DEBUG, "%s: calling issue_key_mgmt_set_key",
2682 			   __func__);
2683 		ret = issue_key_mgmt_set_key(drv, key, key_len);
2684 		return ret;
2685 	}
2686 #endif /* CONFIG_DRIVER_NL80211_QCA */
2687 
2688 	if (alg == WPA_ALG_NONE) {
2689 		msg = nl80211_ifindex_msg(drv, ifindex, 0, NL80211_CMD_DEL_KEY);
2690 		if (!msg)
2691 			return -ENOBUFS;
2692 	} else {
2693 		u32 suite;
2694 
2695 		suite = wpa_alg_to_cipher_suite(alg, key_len);
2696 		if (!suite)
2697 			goto fail;
2698 		msg = nl80211_ifindex_msg(drv, ifindex, 0, NL80211_CMD_NEW_KEY);
2699 		if (!msg ||
2700 		    nla_put(msg, NL80211_ATTR_KEY_DATA, key_len, key) ||
2701 		    nla_put_u32(msg, NL80211_ATTR_KEY_CIPHER, suite))
2702 			goto fail;
2703 		wpa_hexdump_key(MSG_DEBUG, "nl80211: KEY_DATA", key, key_len);
2704 	}
2705 
2706 	if (seq && seq_len) {
2707 		if (nla_put(msg, NL80211_ATTR_KEY_SEQ, seq_len, seq))
2708 			goto fail;
2709 		wpa_hexdump(MSG_DEBUG, "nl80211: KEY_SEQ", seq, seq_len);
2710 	}
2711 
2712 	if (addr && !is_broadcast_ether_addr(addr)) {
2713 		wpa_printf(MSG_DEBUG, "   addr=" MACSTR, MAC2STR(addr));
2714 		if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
2715 			goto fail;
2716 
2717 		if (alg != WPA_ALG_WEP && key_idx && !set_tx) {
2718 			wpa_printf(MSG_DEBUG, "   RSN IBSS RX GTK");
2719 			if (nla_put_u32(msg, NL80211_ATTR_KEY_TYPE,
2720 					NL80211_KEYTYPE_GROUP))
2721 				goto fail;
2722 		}
2723 	} else if (addr && is_broadcast_ether_addr(addr)) {
2724 		struct nlattr *types;
2725 
2726 		wpa_printf(MSG_DEBUG, "   broadcast key");
2727 
2728 		types = nla_nest_start(msg, NL80211_ATTR_KEY_DEFAULT_TYPES);
2729 		if (!types ||
2730 		    nla_put_flag(msg, NL80211_KEY_DEFAULT_TYPE_MULTICAST))
2731 			goto fail;
2732 		nla_nest_end(msg, types);
2733 	}
2734 	if (nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2735 		goto fail;
2736 
2737 	ret = send_and_recv_msgs(drv, msg, NULL, key ? (void *) -1 : NULL);
2738 	if ((ret == -ENOENT || ret == -ENOLINK) && alg == WPA_ALG_NONE)
2739 		ret = 0;
2740 	if (ret)
2741 		wpa_printf(MSG_DEBUG, "nl80211: set_key failed; err=%d %s)",
2742 			   ret, strerror(-ret));
2743 
2744 	/*
2745 	 * If we failed or don't need to set the default TX key (below),
2746 	 * we're done here.
2747 	 */
2748 	if (ret || !set_tx || alg == WPA_ALG_NONE || tdls)
2749 		return ret;
2750 	if (is_ap_interface(drv->nlmode) && addr &&
2751 	    !is_broadcast_ether_addr(addr))
2752 		return ret;
2753 
2754 	msg = nl80211_ifindex_msg(drv, ifindex, 0, NL80211_CMD_SET_KEY);
2755 	if (!msg ||
2756 	    nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx) ||
2757 	    nla_put_flag(msg, (alg == WPA_ALG_IGTK ||
2758 			       alg == WPA_ALG_BIP_GMAC_128 ||
2759 			       alg == WPA_ALG_BIP_GMAC_256 ||
2760 			       alg == WPA_ALG_BIP_CMAC_256) ?
2761 			 NL80211_ATTR_KEY_DEFAULT_MGMT :
2762 			 NL80211_ATTR_KEY_DEFAULT))
2763 		goto fail;
2764 	if (addr && is_broadcast_ether_addr(addr)) {
2765 		struct nlattr *types;
2766 
2767 		types = nla_nest_start(msg, NL80211_ATTR_KEY_DEFAULT_TYPES);
2768 		if (!types ||
2769 		    nla_put_flag(msg, NL80211_KEY_DEFAULT_TYPE_MULTICAST))
2770 			goto fail;
2771 		nla_nest_end(msg, types);
2772 	} else if (addr) {
2773 		struct nlattr *types;
2774 
2775 		types = nla_nest_start(msg, NL80211_ATTR_KEY_DEFAULT_TYPES);
2776 		if (!types ||
2777 		    nla_put_flag(msg, NL80211_KEY_DEFAULT_TYPE_UNICAST))
2778 			goto fail;
2779 		nla_nest_end(msg, types);
2780 	}
2781 
2782 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2783 	if (ret == -ENOENT)
2784 		ret = 0;
2785 	if (ret)
2786 		wpa_printf(MSG_DEBUG, "nl80211: set_key default failed; "
2787 			   "err=%d %s)", ret, strerror(-ret));
2788 	return ret;
2789 
2790 fail:
2791 	nl80211_nlmsg_clear(msg);
2792 	nlmsg_free(msg);
2793 	return -ENOBUFS;
2794 }
2795 
2796 
2797 static int nl_add_key(struct nl_msg *msg, enum wpa_alg alg,
2798 		      int key_idx, int defkey,
2799 		      const u8 *seq, size_t seq_len,
2800 		      const u8 *key, size_t key_len)
2801 {
2802 	struct nlattr *key_attr = nla_nest_start(msg, NL80211_ATTR_KEY);
2803 	u32 suite;
2804 
2805 	if (!key_attr)
2806 		return -1;
2807 
2808 	suite = wpa_alg_to_cipher_suite(alg, key_len);
2809 	if (!suite)
2810 		return -1;
2811 
2812 	if (defkey && alg == WPA_ALG_IGTK) {
2813 		if (nla_put_flag(msg, NL80211_KEY_DEFAULT_MGMT))
2814 			return -1;
2815 	} else if (defkey) {
2816 		if (nla_put_flag(msg, NL80211_KEY_DEFAULT))
2817 			return -1;
2818 	}
2819 
2820 	if (nla_put_u8(msg, NL80211_KEY_IDX, key_idx) ||
2821 	    nla_put_u32(msg, NL80211_KEY_CIPHER, suite) ||
2822 	    (seq && seq_len &&
2823 	     nla_put(msg, NL80211_KEY_SEQ, seq_len, seq)) ||
2824 	    nla_put(msg, NL80211_KEY_DATA, key_len, key))
2825 		return -1;
2826 
2827 	nla_nest_end(msg, key_attr);
2828 
2829 	return 0;
2830 }
2831 
2832 
2833 static int nl80211_set_conn_keys(struct wpa_driver_associate_params *params,
2834 				 struct nl_msg *msg)
2835 {
2836 	int i, privacy = 0;
2837 	struct nlattr *nl_keys, *nl_key;
2838 
2839 	for (i = 0; i < 4; i++) {
2840 		if (!params->wep_key[i])
2841 			continue;
2842 		privacy = 1;
2843 		break;
2844 	}
2845 	if (params->wps == WPS_MODE_PRIVACY)
2846 		privacy = 1;
2847 	if (params->pairwise_suite &&
2848 	    params->pairwise_suite != WPA_CIPHER_NONE)
2849 		privacy = 1;
2850 
2851 	if (!privacy)
2852 		return 0;
2853 
2854 	if (nla_put_flag(msg, NL80211_ATTR_PRIVACY))
2855 		return -ENOBUFS;
2856 
2857 	nl_keys = nla_nest_start(msg, NL80211_ATTR_KEYS);
2858 	if (!nl_keys)
2859 		return -ENOBUFS;
2860 
2861 	for (i = 0; i < 4; i++) {
2862 		if (!params->wep_key[i])
2863 			continue;
2864 
2865 		nl_key = nla_nest_start(msg, i);
2866 		if (!nl_key ||
2867 		    nla_put(msg, NL80211_KEY_DATA, params->wep_key_len[i],
2868 			    params->wep_key[i]) ||
2869 		    nla_put_u32(msg, NL80211_KEY_CIPHER,
2870 				params->wep_key_len[i] == 5 ?
2871 				WLAN_CIPHER_SUITE_WEP40 :
2872 				WLAN_CIPHER_SUITE_WEP104) ||
2873 		    nla_put_u8(msg, NL80211_KEY_IDX, i) ||
2874 		    (i == params->wep_tx_keyidx &&
2875 		     nla_put_flag(msg, NL80211_KEY_DEFAULT)))
2876 			return -ENOBUFS;
2877 
2878 		nla_nest_end(msg, nl_key);
2879 	}
2880 	nla_nest_end(msg, nl_keys);
2881 
2882 	return 0;
2883 }
2884 
2885 
2886 int wpa_driver_nl80211_mlme(struct wpa_driver_nl80211_data *drv,
2887 			    const u8 *addr, int cmd, u16 reason_code,
2888 			    int local_state_change)
2889 {
2890 	int ret;
2891 	struct nl_msg *msg;
2892 
2893 	if (!(msg = nl80211_drv_msg(drv, 0, cmd)) ||
2894 	    nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code) ||
2895 	    (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
2896 	    (local_state_change &&
2897 	     nla_put_flag(msg, NL80211_ATTR_LOCAL_STATE_CHANGE))) {
2898 		nlmsg_free(msg);
2899 		return -1;
2900 	}
2901 
2902 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
2903 	if (ret) {
2904 		wpa_dbg(drv->ctx, MSG_DEBUG,
2905 			"nl80211: MLME command failed: reason=%u ret=%d (%s)",
2906 			reason_code, ret, strerror(-ret));
2907 	}
2908 	return ret;
2909 }
2910 
2911 
2912 static int wpa_driver_nl80211_disconnect(struct wpa_driver_nl80211_data *drv,
2913 					 int reason_code)
2914 {
2915 	int ret;
2916 
2917 	wpa_printf(MSG_DEBUG, "%s(reason_code=%d)", __func__, reason_code);
2918 	nl80211_mark_disconnected(drv);
2919 	/* Disconnect command doesn't need BSSID - it uses cached value */
2920 	ret = wpa_driver_nl80211_mlme(drv, NULL, NL80211_CMD_DISCONNECT,
2921 				      reason_code, 0);
2922 	/*
2923 	 * For locally generated disconnect, supplicant already generates a
2924 	 * DEAUTH event, so ignore the event from NL80211.
2925 	 */
2926 	drv->ignore_next_local_disconnect = ret == 0;
2927 
2928 	return ret;
2929 }
2930 
2931 
2932 static int wpa_driver_nl80211_deauthenticate(struct i802_bss *bss,
2933 					     const u8 *addr, int reason_code)
2934 {
2935 	struct wpa_driver_nl80211_data *drv = bss->drv;
2936 	int ret;
2937 
2938 	if (drv->nlmode == NL80211_IFTYPE_ADHOC) {
2939 		nl80211_mark_disconnected(drv);
2940 		return nl80211_leave_ibss(drv, 1);
2941 	}
2942 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME))
2943 		return wpa_driver_nl80211_disconnect(drv, reason_code);
2944 	wpa_printf(MSG_DEBUG, "%s(addr=" MACSTR " reason_code=%d)",
2945 		   __func__, MAC2STR(addr), reason_code);
2946 	nl80211_mark_disconnected(drv);
2947 	ret = wpa_driver_nl80211_mlme(drv, addr, NL80211_CMD_DEAUTHENTICATE,
2948 				      reason_code, 0);
2949 	/*
2950 	 * For locally generated deauthenticate, supplicant already generates a
2951 	 * DEAUTH event, so ignore the event from NL80211.
2952 	 */
2953 	drv->ignore_next_local_deauth = ret == 0;
2954 	return ret;
2955 }
2956 
2957 
2958 static void nl80211_copy_auth_params(struct wpa_driver_nl80211_data *drv,
2959 				     struct wpa_driver_auth_params *params)
2960 {
2961 	int i;
2962 
2963 	drv->auth_freq = params->freq;
2964 	drv->auth_alg = params->auth_alg;
2965 	drv->auth_wep_tx_keyidx = params->wep_tx_keyidx;
2966 	drv->auth_local_state_change = params->local_state_change;
2967 	drv->auth_p2p = params->p2p;
2968 
2969 	if (params->bssid)
2970 		os_memcpy(drv->auth_bssid_, params->bssid, ETH_ALEN);
2971 	else
2972 		os_memset(drv->auth_bssid_, 0, ETH_ALEN);
2973 
2974 	if (params->ssid) {
2975 		os_memcpy(drv->auth_ssid, params->ssid, params->ssid_len);
2976 		drv->auth_ssid_len = params->ssid_len;
2977 	} else
2978 		drv->auth_ssid_len = 0;
2979 
2980 
2981 	os_free(drv->auth_ie);
2982 	drv->auth_ie = NULL;
2983 	drv->auth_ie_len = 0;
2984 	if (params->ie) {
2985 		drv->auth_ie = os_malloc(params->ie_len);
2986 		if (drv->auth_ie) {
2987 			os_memcpy(drv->auth_ie, params->ie, params->ie_len);
2988 			drv->auth_ie_len = params->ie_len;
2989 		}
2990 	}
2991 
2992 	for (i = 0; i < 4; i++) {
2993 		if (params->wep_key[i] && params->wep_key_len[i] &&
2994 		    params->wep_key_len[i] <= 16) {
2995 			os_memcpy(drv->auth_wep_key[i], params->wep_key[i],
2996 				  params->wep_key_len[i]);
2997 			drv->auth_wep_key_len[i] = params->wep_key_len[i];
2998 		} else
2999 			drv->auth_wep_key_len[i] = 0;
3000 	}
3001 }
3002 
3003 
3004 static void nl80211_unmask_11b_rates(struct i802_bss *bss)
3005 {
3006 	struct wpa_driver_nl80211_data *drv = bss->drv;
3007 
3008 	if (is_p2p_net_interface(drv->nlmode) || !drv->disabled_11b_rates)
3009 		return;
3010 
3011 	/*
3012 	 * Looks like we failed to unmask 11b rates previously. This could
3013 	 * happen, e.g., if the interface was down at the point in time when a
3014 	 * P2P group was terminated.
3015 	 */
3016 	wpa_printf(MSG_DEBUG,
3017 		   "nl80211: Interface %s mode is for non-P2P, but 11b rates were disabled - re-enable them",
3018 		   bss->ifname);
3019 	nl80211_disable_11b_rates(drv, drv->ifindex, 0);
3020 }
3021 
3022 
3023 static int wpa_driver_nl80211_authenticate(
3024 	struct i802_bss *bss, struct wpa_driver_auth_params *params)
3025 {
3026 	struct wpa_driver_nl80211_data *drv = bss->drv;
3027 	int ret = -1, i;
3028 	struct nl_msg *msg;
3029 	enum nl80211_auth_type type;
3030 	enum nl80211_iftype nlmode;
3031 	int count = 0;
3032 	int is_retry;
3033 
3034 	nl80211_unmask_11b_rates(bss);
3035 
3036 	is_retry = drv->retry_auth;
3037 	drv->retry_auth = 0;
3038 	drv->ignore_deauth_event = 0;
3039 
3040 	nl80211_mark_disconnected(drv);
3041 	os_memset(drv->auth_bssid, 0, ETH_ALEN);
3042 	if (params->bssid)
3043 		os_memcpy(drv->auth_attempt_bssid, params->bssid, ETH_ALEN);
3044 	else
3045 		os_memset(drv->auth_attempt_bssid, 0, ETH_ALEN);
3046 	/* FIX: IBSS mode */
3047 	nlmode = params->p2p ?
3048 		NL80211_IFTYPE_P2P_CLIENT : NL80211_IFTYPE_STATION;
3049 	if (drv->nlmode != nlmode &&
3050 	    wpa_driver_nl80211_set_mode(bss, nlmode) < 0)
3051 		return -1;
3052 
3053 retry:
3054 	wpa_printf(MSG_DEBUG, "nl80211: Authenticate (ifindex=%d)",
3055 		   drv->ifindex);
3056 
3057 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_AUTHENTICATE);
3058 	if (!msg)
3059 		goto fail;
3060 
3061 	for (i = 0; i < 4; i++) {
3062 		if (!params->wep_key[i])
3063 			continue;
3064 		wpa_driver_nl80211_set_key(bss->ifname, bss, WPA_ALG_WEP,
3065 					   NULL, i,
3066 					   i == params->wep_tx_keyidx, NULL, 0,
3067 					   params->wep_key[i],
3068 					   params->wep_key_len[i]);
3069 		if (params->wep_tx_keyidx != i)
3070 			continue;
3071 		if (nl_add_key(msg, WPA_ALG_WEP, i, 1, NULL, 0,
3072 			       params->wep_key[i], params->wep_key_len[i]))
3073 			goto fail;
3074 	}
3075 
3076 	if (params->bssid) {
3077 		wpa_printf(MSG_DEBUG, "  * bssid=" MACSTR,
3078 			   MAC2STR(params->bssid));
3079 		if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, params->bssid))
3080 			goto fail;
3081 	}
3082 	if (params->freq) {
3083 		wpa_printf(MSG_DEBUG, "  * freq=%d", params->freq);
3084 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, params->freq))
3085 			goto fail;
3086 	}
3087 	if (params->ssid) {
3088 		wpa_hexdump_ascii(MSG_DEBUG, "  * SSID",
3089 				  params->ssid, params->ssid_len);
3090 		if (nla_put(msg, NL80211_ATTR_SSID, params->ssid_len,
3091 			    params->ssid))
3092 			goto fail;
3093 	}
3094 	wpa_hexdump(MSG_DEBUG, "  * IEs", params->ie, params->ie_len);
3095 	if (params->ie &&
3096 	    nla_put(msg, NL80211_ATTR_IE, params->ie_len, params->ie))
3097 		goto fail;
3098 	if (params->sae_data) {
3099 		wpa_hexdump(MSG_DEBUG, "  * SAE data", params->sae_data,
3100 			    params->sae_data_len);
3101 		if (nla_put(msg, NL80211_ATTR_SAE_DATA, params->sae_data_len,
3102 			    params->sae_data))
3103 			goto fail;
3104 	}
3105 	if (params->auth_alg & WPA_AUTH_ALG_OPEN)
3106 		type = NL80211_AUTHTYPE_OPEN_SYSTEM;
3107 	else if (params->auth_alg & WPA_AUTH_ALG_SHARED)
3108 		type = NL80211_AUTHTYPE_SHARED_KEY;
3109 	else if (params->auth_alg & WPA_AUTH_ALG_LEAP)
3110 		type = NL80211_AUTHTYPE_NETWORK_EAP;
3111 	else if (params->auth_alg & WPA_AUTH_ALG_FT)
3112 		type = NL80211_AUTHTYPE_FT;
3113 	else if (params->auth_alg & WPA_AUTH_ALG_SAE)
3114 		type = NL80211_AUTHTYPE_SAE;
3115 	else
3116 		goto fail;
3117 	wpa_printf(MSG_DEBUG, "  * Auth Type %d", type);
3118 	if (nla_put_u32(msg, NL80211_ATTR_AUTH_TYPE, type))
3119 		goto fail;
3120 	if (params->local_state_change) {
3121 		wpa_printf(MSG_DEBUG, "  * Local state change only");
3122 		if (nla_put_flag(msg, NL80211_ATTR_LOCAL_STATE_CHANGE))
3123 			goto fail;
3124 	}
3125 
3126 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3127 	msg = NULL;
3128 	if (ret) {
3129 		wpa_dbg(drv->ctx, MSG_DEBUG,
3130 			"nl80211: MLME command failed (auth): ret=%d (%s)",
3131 			ret, strerror(-ret));
3132 		count++;
3133 		if (ret == -EALREADY && count == 1 && params->bssid &&
3134 		    !params->local_state_change) {
3135 			/*
3136 			 * mac80211 does not currently accept new
3137 			 * authentication if we are already authenticated. As a
3138 			 * workaround, force deauthentication and try again.
3139 			 */
3140 			wpa_printf(MSG_DEBUG, "nl80211: Retry authentication "
3141 				   "after forced deauthentication");
3142 			drv->ignore_deauth_event = 1;
3143 			wpa_driver_nl80211_deauthenticate(
3144 				bss, params->bssid,
3145 				WLAN_REASON_PREV_AUTH_NOT_VALID);
3146 			nlmsg_free(msg);
3147 			goto retry;
3148 		}
3149 
3150 		if (ret == -ENOENT && params->freq && !is_retry) {
3151 			/*
3152 			 * cfg80211 has likely expired the BSS entry even
3153 			 * though it was previously available in our internal
3154 			 * BSS table. To recover quickly, start a single
3155 			 * channel scan on the specified channel.
3156 			 */
3157 			struct wpa_driver_scan_params scan;
3158 			int freqs[2];
3159 
3160 			os_memset(&scan, 0, sizeof(scan));
3161 			scan.num_ssids = 1;
3162 			if (params->ssid) {
3163 				scan.ssids[0].ssid = params->ssid;
3164 				scan.ssids[0].ssid_len = params->ssid_len;
3165 			}
3166 			freqs[0] = params->freq;
3167 			freqs[1] = 0;
3168 			scan.freqs = freqs;
3169 			wpa_printf(MSG_DEBUG, "nl80211: Trigger single "
3170 				   "channel scan to refresh cfg80211 BSS "
3171 				   "entry");
3172 			ret = wpa_driver_nl80211_scan(bss, &scan);
3173 			if (ret == 0) {
3174 				nl80211_copy_auth_params(drv, params);
3175 				drv->scan_for_auth = 1;
3176 			}
3177 		} else if (is_retry) {
3178 			/*
3179 			 * Need to indicate this with an event since the return
3180 			 * value from the retry is not delivered to core code.
3181 			 */
3182 			union wpa_event_data event;
3183 			wpa_printf(MSG_DEBUG, "nl80211: Authentication retry "
3184 				   "failed");
3185 			os_memset(&event, 0, sizeof(event));
3186 			os_memcpy(event.timeout_event.addr, drv->auth_bssid_,
3187 				  ETH_ALEN);
3188 			wpa_supplicant_event(drv->ctx, EVENT_AUTH_TIMED_OUT,
3189 					     &event);
3190 		}
3191 	} else {
3192 		wpa_printf(MSG_DEBUG,
3193 			   "nl80211: Authentication request send successfully");
3194 	}
3195 
3196 fail:
3197 	nlmsg_free(msg);
3198 	return ret;
3199 }
3200 
3201 
3202 int wpa_driver_nl80211_authenticate_retry(struct wpa_driver_nl80211_data *drv)
3203 {
3204 	struct wpa_driver_auth_params params;
3205 	struct i802_bss *bss = drv->first_bss;
3206 	int i;
3207 
3208 	wpa_printf(MSG_DEBUG, "nl80211: Try to authenticate again");
3209 
3210 	os_memset(&params, 0, sizeof(params));
3211 	params.freq = drv->auth_freq;
3212 	params.auth_alg = drv->auth_alg;
3213 	params.wep_tx_keyidx = drv->auth_wep_tx_keyidx;
3214 	params.local_state_change = drv->auth_local_state_change;
3215 	params.p2p = drv->auth_p2p;
3216 
3217 	if (!is_zero_ether_addr(drv->auth_bssid_))
3218 		params.bssid = drv->auth_bssid_;
3219 
3220 	if (drv->auth_ssid_len) {
3221 		params.ssid = drv->auth_ssid;
3222 		params.ssid_len = drv->auth_ssid_len;
3223 	}
3224 
3225 	params.ie = drv->auth_ie;
3226 	params.ie_len = drv->auth_ie_len;
3227 
3228 	for (i = 0; i < 4; i++) {
3229 		if (drv->auth_wep_key_len[i]) {
3230 			params.wep_key[i] = drv->auth_wep_key[i];
3231 			params.wep_key_len[i] = drv->auth_wep_key_len[i];
3232 		}
3233 	}
3234 
3235 	drv->retry_auth = 1;
3236 	return wpa_driver_nl80211_authenticate(bss, &params);
3237 }
3238 
3239 
3240 static int wpa_driver_nl80211_send_frame(struct i802_bss *bss,
3241 					 const void *data, size_t len,
3242 					 int encrypt, int noack,
3243 					 unsigned int freq, int no_cck,
3244 					 int offchanok, unsigned int wait_time,
3245 					 const u16 *csa_offs,
3246 					 size_t csa_offs_len)
3247 {
3248 	struct wpa_driver_nl80211_data *drv = bss->drv;
3249 	u64 cookie;
3250 	int res;
3251 
3252 	if (freq == 0 && drv->nlmode == NL80211_IFTYPE_ADHOC) {
3253 		freq = nl80211_get_assoc_freq(drv);
3254 		wpa_printf(MSG_DEBUG,
3255 			   "nl80211: send_frame - Use assoc_freq=%u for IBSS",
3256 			   freq);
3257 	}
3258 	if (freq == 0) {
3259 		wpa_printf(MSG_DEBUG, "nl80211: send_frame - Use bss->freq=%u",
3260 			   bss->freq);
3261 		freq = bss->freq;
3262 	}
3263 
3264 	if (drv->use_monitor) {
3265 		wpa_printf(MSG_DEBUG, "nl80211: send_frame(freq=%u bss->freq=%u) -> send_monitor",
3266 			   freq, bss->freq);
3267 		return nl80211_send_monitor(drv, data, len, encrypt, noack);
3268 	}
3269 
3270 	wpa_printf(MSG_DEBUG, "nl80211: send_frame -> send_frame_cmd");
3271 	res = nl80211_send_frame_cmd(bss, freq, wait_time, data, len,
3272 				     &cookie, no_cck, noack, offchanok,
3273 				     csa_offs, csa_offs_len);
3274 	if (res == 0 && !noack) {
3275 		const struct ieee80211_mgmt *mgmt;
3276 		u16 fc;
3277 
3278 		mgmt = (const struct ieee80211_mgmt *) data;
3279 		fc = le_to_host16(mgmt->frame_control);
3280 		if (WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
3281 		    WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_ACTION) {
3282 			wpa_printf(MSG_MSGDUMP,
3283 				   "nl80211: Update send_action_cookie from 0x%llx to 0x%llx",
3284 				   (long long unsigned int)
3285 				   drv->send_action_cookie,
3286 				   (long long unsigned int) cookie);
3287 			drv->send_action_cookie = cookie;
3288 		}
3289 	}
3290 
3291 	return res;
3292 }
3293 
3294 
3295 static int wpa_driver_nl80211_send_mlme(struct i802_bss *bss, const u8 *data,
3296 					size_t data_len, int noack,
3297 					unsigned int freq, int no_cck,
3298 					int offchanok,
3299 					unsigned int wait_time,
3300 					const u16 *csa_offs,
3301 					size_t csa_offs_len)
3302 {
3303 	struct wpa_driver_nl80211_data *drv = bss->drv;
3304 	struct ieee80211_mgmt *mgmt;
3305 	int encrypt = 1;
3306 	u16 fc;
3307 
3308 	mgmt = (struct ieee80211_mgmt *) data;
3309 	fc = le_to_host16(mgmt->frame_control);
3310 	wpa_printf(MSG_DEBUG, "nl80211: send_mlme - da= " MACSTR
3311 		   " noack=%d freq=%u no_cck=%d offchanok=%d wait_time=%u fc=0x%x (%s) nlmode=%d",
3312 		   MAC2STR(mgmt->da), noack, freq, no_cck, offchanok, wait_time,
3313 		   fc, fc2str(fc), drv->nlmode);
3314 
3315 	if ((is_sta_interface(drv->nlmode) ||
3316 	     drv->nlmode == NL80211_IFTYPE_P2P_DEVICE) &&
3317 	    WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
3318 	    WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_PROBE_RESP) {
3319 		/*
3320 		 * The use of last_mgmt_freq is a bit of a hack,
3321 		 * but it works due to the single-threaded nature
3322 		 * of wpa_supplicant.
3323 		 */
3324 		if (freq == 0) {
3325 			wpa_printf(MSG_DEBUG, "nl80211: Use last_mgmt_freq=%d",
3326 				   drv->last_mgmt_freq);
3327 			freq = drv->last_mgmt_freq;
3328 		}
3329 		return nl80211_send_frame_cmd(bss, freq, 0,
3330 					      data, data_len, NULL, 1, noack,
3331 					      1, csa_offs, csa_offs_len);
3332 	}
3333 
3334 	if (drv->device_ap_sme && is_ap_interface(drv->nlmode)) {
3335 		if (freq == 0) {
3336 			wpa_printf(MSG_DEBUG, "nl80211: Use bss->freq=%d",
3337 				   bss->freq);
3338 			freq = bss->freq;
3339 		}
3340 		return nl80211_send_frame_cmd(bss, freq,
3341 					      (int) freq == bss->freq ? 0 :
3342 					      wait_time,
3343 					      data, data_len,
3344 					      &drv->send_action_cookie,
3345 					      no_cck, noack, offchanok,
3346 					      csa_offs, csa_offs_len);
3347 	}
3348 
3349 	if (WLAN_FC_GET_TYPE(fc) == WLAN_FC_TYPE_MGMT &&
3350 	    WLAN_FC_GET_STYPE(fc) == WLAN_FC_STYPE_AUTH) {
3351 		/*
3352 		 * Only one of the authentication frame types is encrypted.
3353 		 * In order for static WEP encryption to work properly (i.e.,
3354 		 * to not encrypt the frame), we need to tell mac80211 about
3355 		 * the frames that must not be encrypted.
3356 		 */
3357 		u16 auth_alg = le_to_host16(mgmt->u.auth.auth_alg);
3358 		u16 auth_trans = le_to_host16(mgmt->u.auth.auth_transaction);
3359 		if (auth_alg != WLAN_AUTH_SHARED_KEY || auth_trans != 3)
3360 			encrypt = 0;
3361 	}
3362 
3363 	wpa_printf(MSG_DEBUG, "nl80211: send_mlme -> send_frame");
3364 	return wpa_driver_nl80211_send_frame(bss, data, data_len, encrypt,
3365 					     noack, freq, no_cck, offchanok,
3366 					     wait_time, csa_offs,
3367 					     csa_offs_len);
3368 }
3369 
3370 
3371 static int nl80211_put_basic_rates(struct nl_msg *msg, const int *basic_rates)
3372 {
3373 	u8 rates[NL80211_MAX_SUPP_RATES];
3374 	u8 rates_len = 0;
3375 	int i;
3376 
3377 	if (!basic_rates)
3378 		return 0;
3379 
3380 	for (i = 0; i < NL80211_MAX_SUPP_RATES && basic_rates[i] >= 0; i++)
3381 		rates[rates_len++] = basic_rates[i] / 5;
3382 
3383 	return nla_put(msg, NL80211_ATTR_BSS_BASIC_RATES, rates_len, rates);
3384 }
3385 
3386 
3387 static int nl80211_set_bss(struct i802_bss *bss, int cts, int preamble,
3388 			   int slot, int ht_opmode, int ap_isolate,
3389 			   const int *basic_rates)
3390 {
3391 	struct wpa_driver_nl80211_data *drv = bss->drv;
3392 	struct nl_msg *msg;
3393 
3394 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_BSS)) ||
3395 	    (cts >= 0 &&
3396 	     nla_put_u8(msg, NL80211_ATTR_BSS_CTS_PROT, cts)) ||
3397 	    (preamble >= 0 &&
3398 	     nla_put_u8(msg, NL80211_ATTR_BSS_SHORT_PREAMBLE, preamble)) ||
3399 	    (slot >= 0 &&
3400 	     nla_put_u8(msg, NL80211_ATTR_BSS_SHORT_SLOT_TIME, slot)) ||
3401 	    (ht_opmode >= 0 &&
3402 	     nla_put_u16(msg, NL80211_ATTR_BSS_HT_OPMODE, ht_opmode)) ||
3403 	    (ap_isolate >= 0 &&
3404 	     nla_put_u8(msg, NL80211_ATTR_AP_ISOLATE, ap_isolate)) ||
3405 	    nl80211_put_basic_rates(msg, basic_rates)) {
3406 		nlmsg_free(msg);
3407 		return -ENOBUFS;
3408 	}
3409 
3410 	return send_and_recv_msgs(drv, msg, NULL, NULL);
3411 }
3412 
3413 
3414 static int wpa_driver_nl80211_set_acl(void *priv,
3415 				      struct hostapd_acl_params *params)
3416 {
3417 	struct i802_bss *bss = priv;
3418 	struct wpa_driver_nl80211_data *drv = bss->drv;
3419 	struct nl_msg *msg;
3420 	struct nl_msg *acl;
3421 	unsigned int i;
3422 	int ret;
3423 
3424 	if (!(drv->capa.max_acl_mac_addrs))
3425 		return -ENOTSUP;
3426 
3427 	if (params->num_mac_acl > drv->capa.max_acl_mac_addrs)
3428 		return -ENOTSUP;
3429 
3430 	wpa_printf(MSG_DEBUG, "nl80211: Set %s ACL (num_mac_acl=%u)",
3431 		   params->acl_policy ? "Accept" : "Deny", params->num_mac_acl);
3432 
3433 	acl = nlmsg_alloc();
3434 	if (!acl)
3435 		return -ENOMEM;
3436 	for (i = 0; i < params->num_mac_acl; i++) {
3437 		if (nla_put(acl, i + 1, ETH_ALEN, params->mac_acl[i].addr)) {
3438 			nlmsg_free(acl);
3439 			return -ENOMEM;
3440 		}
3441 	}
3442 
3443 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_SET_MAC_ACL)) ||
3444 	    nla_put_u32(msg, NL80211_ATTR_ACL_POLICY, params->acl_policy ?
3445 			NL80211_ACL_POLICY_DENY_UNLESS_LISTED :
3446 			NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED) ||
3447 	    nla_put_nested(msg, NL80211_ATTR_MAC_ADDRS, acl)) {
3448 		nlmsg_free(msg);
3449 		nlmsg_free(acl);
3450 		return -ENOMEM;
3451 	}
3452 	nlmsg_free(acl);
3453 
3454 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3455 	if (ret) {
3456 		wpa_printf(MSG_DEBUG, "nl80211: Failed to set MAC ACL: %d (%s)",
3457 			   ret, strerror(-ret));
3458 	}
3459 
3460 	return ret;
3461 }
3462 
3463 
3464 static int nl80211_put_beacon_int(struct nl_msg *msg, int beacon_int)
3465 {
3466 	if (beacon_int > 0) {
3467 		wpa_printf(MSG_DEBUG, "  * beacon_int=%d", beacon_int);
3468 		return nla_put_u32(msg, NL80211_ATTR_BEACON_INTERVAL,
3469 				   beacon_int);
3470 	}
3471 
3472 	return 0;
3473 }
3474 
3475 
3476 static int nl80211_put_dtim_period(struct nl_msg *msg, int dtim_period)
3477 {
3478 	if (dtim_period > 0) {
3479 		wpa_printf(MSG_DEBUG, "  * dtim_period=%d", dtim_period);
3480 		return nla_put_u32(msg, NL80211_ATTR_DTIM_PERIOD, dtim_period);
3481 	}
3482 
3483 	return 0;
3484 }
3485 
3486 
3487 #ifdef CONFIG_MESH
3488 static int nl80211_set_mesh_config(void *priv,
3489 				   struct wpa_driver_mesh_bss_params *params)
3490 {
3491 	struct i802_bss *bss = priv;
3492 	struct wpa_driver_nl80211_data *drv = bss->drv;
3493 	struct nl_msg *msg;
3494 	int ret;
3495 
3496 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_SET_MESH_CONFIG);
3497 	if (!msg)
3498 		return -1;
3499 
3500 	ret = nl80211_put_mesh_config(msg, params);
3501 	if (ret < 0) {
3502 		nlmsg_free(msg);
3503 		return ret;
3504 	}
3505 
3506 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3507 	if (ret) {
3508 		wpa_printf(MSG_ERROR,
3509 			   "nl80211: Mesh config set failed: %d (%s)",
3510 			   ret, strerror(-ret));
3511 		return ret;
3512 	}
3513 	return 0;
3514 }
3515 #endif /* CONFIG_MESH */
3516 
3517 
3518 static int wpa_driver_nl80211_set_ap(void *priv,
3519 				     struct wpa_driver_ap_params *params)
3520 {
3521 	struct i802_bss *bss = priv;
3522 	struct wpa_driver_nl80211_data *drv = bss->drv;
3523 	struct nl_msg *msg;
3524 	u8 cmd = NL80211_CMD_NEW_BEACON;
3525 	int ret;
3526 	int beacon_set;
3527 	int num_suites;
3528 	int smps_mode;
3529 	u32 suites[10], suite;
3530 	u32 ver;
3531 #ifdef CONFIG_MESH
3532 	struct wpa_driver_mesh_bss_params mesh_params;
3533 #endif /* CONFIG_MESH */
3534 
3535 	beacon_set = params->reenable ? 0 : bss->beacon_set;
3536 
3537 	wpa_printf(MSG_DEBUG, "nl80211: Set beacon (beacon_set=%d)",
3538 		   beacon_set);
3539 	if (beacon_set)
3540 		cmd = NL80211_CMD_SET_BEACON;
3541 
3542 	wpa_hexdump(MSG_DEBUG, "nl80211: Beacon head",
3543 		    params->head, params->head_len);
3544 	wpa_hexdump(MSG_DEBUG, "nl80211: Beacon tail",
3545 		    params->tail, params->tail_len);
3546 	wpa_printf(MSG_DEBUG, "nl80211: ifindex=%d", bss->ifindex);
3547 	wpa_printf(MSG_DEBUG, "nl80211: beacon_int=%d", params->beacon_int);
3548 	wpa_printf(MSG_DEBUG, "nl80211: dtim_period=%d", params->dtim_period);
3549 	wpa_hexdump_ascii(MSG_DEBUG, "nl80211: ssid",
3550 			  params->ssid, params->ssid_len);
3551 	if (!(msg = nl80211_bss_msg(bss, 0, cmd)) ||
3552 	    nla_put(msg, NL80211_ATTR_BEACON_HEAD, params->head_len,
3553 		    params->head) ||
3554 	    nla_put(msg, NL80211_ATTR_BEACON_TAIL, params->tail_len,
3555 		    params->tail) ||
3556 	    nl80211_put_beacon_int(msg, params->beacon_int) ||
3557 	    nl80211_put_dtim_period(msg, params->dtim_period) ||
3558 	    nla_put(msg, NL80211_ATTR_SSID, params->ssid_len, params->ssid))
3559 		goto fail;
3560 	if (params->proberesp && params->proberesp_len) {
3561 		wpa_hexdump(MSG_DEBUG, "nl80211: proberesp (offload)",
3562 			    params->proberesp, params->proberesp_len);
3563 		if (nla_put(msg, NL80211_ATTR_PROBE_RESP, params->proberesp_len,
3564 			    params->proberesp))
3565 			goto fail;
3566 	}
3567 	switch (params->hide_ssid) {
3568 	case NO_SSID_HIDING:
3569 		wpa_printf(MSG_DEBUG, "nl80211: hidden SSID not in use");
3570 		if (nla_put_u32(msg, NL80211_ATTR_HIDDEN_SSID,
3571 				NL80211_HIDDEN_SSID_NOT_IN_USE))
3572 			goto fail;
3573 		break;
3574 	case HIDDEN_SSID_ZERO_LEN:
3575 		wpa_printf(MSG_DEBUG, "nl80211: hidden SSID zero len");
3576 		if (nla_put_u32(msg, NL80211_ATTR_HIDDEN_SSID,
3577 				NL80211_HIDDEN_SSID_ZERO_LEN))
3578 			goto fail;
3579 		break;
3580 	case HIDDEN_SSID_ZERO_CONTENTS:
3581 		wpa_printf(MSG_DEBUG, "nl80211: hidden SSID zero contents");
3582 		if (nla_put_u32(msg, NL80211_ATTR_HIDDEN_SSID,
3583 				NL80211_HIDDEN_SSID_ZERO_CONTENTS))
3584 			goto fail;
3585 		break;
3586 	}
3587 	wpa_printf(MSG_DEBUG, "nl80211: privacy=%d", params->privacy);
3588 	if (params->privacy &&
3589 	    nla_put_flag(msg, NL80211_ATTR_PRIVACY))
3590 		goto fail;
3591 	wpa_printf(MSG_DEBUG, "nl80211: auth_algs=0x%x", params->auth_algs);
3592 	if ((params->auth_algs & (WPA_AUTH_ALG_OPEN | WPA_AUTH_ALG_SHARED)) ==
3593 	    (WPA_AUTH_ALG_OPEN | WPA_AUTH_ALG_SHARED)) {
3594 		/* Leave out the attribute */
3595 	} else if (params->auth_algs & WPA_AUTH_ALG_SHARED) {
3596 		if (nla_put_u32(msg, NL80211_ATTR_AUTH_TYPE,
3597 				NL80211_AUTHTYPE_SHARED_KEY))
3598 			goto fail;
3599 	} else {
3600 		if (nla_put_u32(msg, NL80211_ATTR_AUTH_TYPE,
3601 				NL80211_AUTHTYPE_OPEN_SYSTEM))
3602 			goto fail;
3603 	}
3604 
3605 	wpa_printf(MSG_DEBUG, "nl80211: wpa_version=0x%x", params->wpa_version);
3606 	ver = 0;
3607 	if (params->wpa_version & WPA_PROTO_WPA)
3608 		ver |= NL80211_WPA_VERSION_1;
3609 	if (params->wpa_version & WPA_PROTO_RSN)
3610 		ver |= NL80211_WPA_VERSION_2;
3611 	if (ver &&
3612 	    nla_put_u32(msg, NL80211_ATTR_WPA_VERSIONS, ver))
3613 		goto fail;
3614 
3615 	wpa_printf(MSG_DEBUG, "nl80211: key_mgmt_suites=0x%x",
3616 		   params->key_mgmt_suites);
3617 	num_suites = 0;
3618 	if (params->key_mgmt_suites & WPA_KEY_MGMT_IEEE8021X)
3619 		suites[num_suites++] = WLAN_AKM_SUITE_8021X;
3620 	if (params->key_mgmt_suites & WPA_KEY_MGMT_PSK)
3621 		suites[num_suites++] = WLAN_AKM_SUITE_PSK;
3622 	if (num_suites &&
3623 	    nla_put(msg, NL80211_ATTR_AKM_SUITES, num_suites * sizeof(u32),
3624 		    suites))
3625 		goto fail;
3626 
3627 	if (params->key_mgmt_suites & WPA_KEY_MGMT_IEEE8021X_NO_WPA &&
3628 	    (!params->pairwise_ciphers ||
3629 	     params->pairwise_ciphers & (WPA_CIPHER_WEP104 | WPA_CIPHER_WEP40)) &&
3630 	    (nla_put_u16(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE, ETH_P_PAE) ||
3631 	     nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT)))
3632 		goto fail;
3633 
3634 	wpa_printf(MSG_DEBUG, "nl80211: pairwise_ciphers=0x%x",
3635 		   params->pairwise_ciphers);
3636 	num_suites = wpa_cipher_to_cipher_suites(params->pairwise_ciphers,
3637 						 suites, ARRAY_SIZE(suites));
3638 	if (num_suites &&
3639 	    nla_put(msg, NL80211_ATTR_CIPHER_SUITES_PAIRWISE,
3640 		    num_suites * sizeof(u32), suites))
3641 		goto fail;
3642 
3643 	wpa_printf(MSG_DEBUG, "nl80211: group_cipher=0x%x",
3644 		   params->group_cipher);
3645 	suite = wpa_cipher_to_cipher_suite(params->group_cipher);
3646 	if (suite &&
3647 	    nla_put_u32(msg, NL80211_ATTR_CIPHER_SUITE_GROUP, suite))
3648 		goto fail;
3649 
3650 	if (params->ht_opmode != -1) {
3651 		switch (params->smps_mode) {
3652 		case HT_CAP_INFO_SMPS_DYNAMIC:
3653 			wpa_printf(MSG_DEBUG, "nl80211: SMPS mode - dynamic");
3654 			smps_mode = NL80211_SMPS_DYNAMIC;
3655 			break;
3656 		case HT_CAP_INFO_SMPS_STATIC:
3657 			wpa_printf(MSG_DEBUG, "nl80211: SMPS mode - static");
3658 			smps_mode = NL80211_SMPS_STATIC;
3659 			break;
3660 		default:
3661 			/* invalid - fallback to smps off */
3662 		case HT_CAP_INFO_SMPS_DISABLED:
3663 			wpa_printf(MSG_DEBUG, "nl80211: SMPS mode - off");
3664 			smps_mode = NL80211_SMPS_OFF;
3665 			break;
3666 		}
3667 		if (nla_put_u32(msg, NL80211_ATTR_SMPS_MODE, smps_mode))
3668 			goto fail;
3669 	}
3670 
3671 	if (params->beacon_ies) {
3672 		wpa_hexdump_buf(MSG_DEBUG, "nl80211: beacon_ies",
3673 				params->beacon_ies);
3674 		if (nla_put(msg, NL80211_ATTR_IE,
3675 			    wpabuf_len(params->beacon_ies),
3676 			    wpabuf_head(params->beacon_ies)))
3677 			goto fail;
3678 	}
3679 	if (params->proberesp_ies) {
3680 		wpa_hexdump_buf(MSG_DEBUG, "nl80211: proberesp_ies",
3681 				params->proberesp_ies);
3682 		if (nla_put(msg, NL80211_ATTR_IE_PROBE_RESP,
3683 			    wpabuf_len(params->proberesp_ies),
3684 			    wpabuf_head(params->proberesp_ies)))
3685 			goto fail;
3686 	}
3687 	if (params->assocresp_ies) {
3688 		wpa_hexdump_buf(MSG_DEBUG, "nl80211: assocresp_ies",
3689 				params->assocresp_ies);
3690 		if (nla_put(msg, NL80211_ATTR_IE_ASSOC_RESP,
3691 			    wpabuf_len(params->assocresp_ies),
3692 			    wpabuf_head(params->assocresp_ies)))
3693 			goto fail;
3694 	}
3695 
3696 	if (drv->capa.flags & WPA_DRIVER_FLAGS_INACTIVITY_TIMER)  {
3697 		wpa_printf(MSG_DEBUG, "nl80211: ap_max_inactivity=%d",
3698 			   params->ap_max_inactivity);
3699 		if (nla_put_u16(msg, NL80211_ATTR_INACTIVITY_TIMEOUT,
3700 				params->ap_max_inactivity))
3701 			goto fail;
3702 	}
3703 
3704 #ifdef CONFIG_P2P
3705 	if (params->p2p_go_ctwindow > 0) {
3706 		if (drv->p2p_go_ctwindow_supported) {
3707 			wpa_printf(MSG_DEBUG, "nl80211: P2P GO ctwindow=%d",
3708 				   params->p2p_go_ctwindow);
3709 			if (nla_put_u8(msg, NL80211_ATTR_P2P_CTWINDOW,
3710 				       params->p2p_go_ctwindow))
3711 				goto fail;
3712 		} else {
3713 			wpa_printf(MSG_INFO,
3714 				   "nl80211: Driver does not support CTWindow configuration - ignore this parameter");
3715 		}
3716 	}
3717 #endif /* CONFIG_P2P */
3718 
3719 	if (params->pbss) {
3720 		wpa_printf(MSG_DEBUG, "nl80211: PBSS");
3721 		if (nla_put_flag(msg, NL80211_ATTR_PBSS))
3722 			goto fail;
3723 	}
3724 
3725 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3726 	if (ret) {
3727 		wpa_printf(MSG_DEBUG, "nl80211: Beacon set failed: %d (%s)",
3728 			   ret, strerror(-ret));
3729 	} else {
3730 		bss->beacon_set = 1;
3731 		nl80211_set_bss(bss, params->cts_protect, params->preamble,
3732 				params->short_slot_time, params->ht_opmode,
3733 				params->isolate, params->basic_rates);
3734 		if (beacon_set && params->freq &&
3735 		    params->freq->bandwidth != bss->bandwidth) {
3736 			wpa_printf(MSG_DEBUG,
3737 				   "nl80211: Update BSS %s bandwidth: %d -> %d",
3738 				   bss->ifname, bss->bandwidth,
3739 				   params->freq->bandwidth);
3740 			ret = nl80211_set_channel(bss, params->freq, 1);
3741 			if (ret) {
3742 				wpa_printf(MSG_DEBUG,
3743 					   "nl80211: Frequency set failed: %d (%s)",
3744 					   ret, strerror(-ret));
3745 			} else {
3746 				wpa_printf(MSG_DEBUG,
3747 					   "nl80211: Frequency set succeeded for ht2040 coex");
3748 				bss->bandwidth = params->freq->bandwidth;
3749 			}
3750 		} else if (!beacon_set && params->freq) {
3751 			/*
3752 			 * cfg80211 updates the driver on frequence change in AP
3753 			 * mode only at the point when beaconing is started, so
3754 			 * set the initial value here.
3755 			 */
3756 			bss->bandwidth = params->freq->bandwidth;
3757 		}
3758 	}
3759 
3760 #ifdef CONFIG_MESH
3761 	if (is_mesh_interface(drv->nlmode) && params->ht_opmode != -1) {
3762 		os_memset(&mesh_params, 0, sizeof(mesh_params));
3763 		mesh_params.flags |= WPA_DRIVER_MESH_CONF_FLAG_HT_OP_MODE;
3764 		mesh_params.ht_opmode = params->ht_opmode;
3765 		ret = nl80211_set_mesh_config(priv, &mesh_params);
3766 		if (ret < 0)
3767 			return ret;
3768 	}
3769 #endif /* CONFIG_MESH */
3770 
3771 	return ret;
3772 fail:
3773 	nlmsg_free(msg);
3774 	return -ENOBUFS;
3775 }
3776 
3777 
3778 static int nl80211_put_freq_params(struct nl_msg *msg,
3779 				   const struct hostapd_freq_params *freq)
3780 {
3781 	wpa_printf(MSG_DEBUG, "  * freq=%d", freq->freq);
3782 	if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq->freq))
3783 		return -ENOBUFS;
3784 
3785 	wpa_printf(MSG_DEBUG, "  * vht_enabled=%d", freq->vht_enabled);
3786 	wpa_printf(MSG_DEBUG, "  * ht_enabled=%d", freq->ht_enabled);
3787 
3788 	if (freq->vht_enabled) {
3789 		enum nl80211_chan_width cw;
3790 
3791 		wpa_printf(MSG_DEBUG, "  * bandwidth=%d", freq->bandwidth);
3792 		switch (freq->bandwidth) {
3793 		case 20:
3794 			cw = NL80211_CHAN_WIDTH_20;
3795 			break;
3796 		case 40:
3797 			cw = NL80211_CHAN_WIDTH_40;
3798 			break;
3799 		case 80:
3800 			if (freq->center_freq2)
3801 				cw = NL80211_CHAN_WIDTH_80P80;
3802 			else
3803 				cw = NL80211_CHAN_WIDTH_80;
3804 			break;
3805 		case 160:
3806 			cw = NL80211_CHAN_WIDTH_160;
3807 			break;
3808 		default:
3809 			return -EINVAL;
3810 		}
3811 
3812 		wpa_printf(MSG_DEBUG, "  * channel_width=%d", cw);
3813 		wpa_printf(MSG_DEBUG, "  * center_freq1=%d",
3814 			   freq->center_freq1);
3815 		wpa_printf(MSG_DEBUG, "  * center_freq2=%d",
3816 			   freq->center_freq2);
3817 		if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, cw) ||
3818 		    nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1,
3819 				freq->center_freq1) ||
3820 		    (freq->center_freq2 &&
3821 		     nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2,
3822 				 freq->center_freq2)))
3823 			return -ENOBUFS;
3824 	} else if (freq->ht_enabled) {
3825 		enum nl80211_channel_type ct;
3826 
3827 		wpa_printf(MSG_DEBUG, "  * sec_channel_offset=%d",
3828 			   freq->sec_channel_offset);
3829 		switch (freq->sec_channel_offset) {
3830 		case -1:
3831 			ct = NL80211_CHAN_HT40MINUS;
3832 			break;
3833 		case 1:
3834 			ct = NL80211_CHAN_HT40PLUS;
3835 			break;
3836 		default:
3837 			ct = NL80211_CHAN_HT20;
3838 			break;
3839 		}
3840 
3841 		wpa_printf(MSG_DEBUG, "  * channel_type=%d", ct);
3842 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, ct))
3843 			return -ENOBUFS;
3844 	} else {
3845 		wpa_printf(MSG_DEBUG, "  * channel_type=%d",
3846 			   NL80211_CHAN_NO_HT);
3847 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
3848 				NL80211_CHAN_NO_HT))
3849 			return -ENOBUFS;
3850 	}
3851 	return 0;
3852 }
3853 
3854 
3855 static int nl80211_set_channel(struct i802_bss *bss,
3856 			       struct hostapd_freq_params *freq, int set_chan)
3857 {
3858 	struct wpa_driver_nl80211_data *drv = bss->drv;
3859 	struct nl_msg *msg;
3860 	int ret;
3861 
3862 	wpa_printf(MSG_DEBUG,
3863 		   "nl80211: Set freq %d (ht_enabled=%d, vht_enabled=%d, bandwidth=%d MHz, cf1=%d MHz, cf2=%d MHz)",
3864 		   freq->freq, freq->ht_enabled, freq->vht_enabled,
3865 		   freq->bandwidth, freq->center_freq1, freq->center_freq2);
3866 
3867 	msg = nl80211_drv_msg(drv, 0, set_chan ? NL80211_CMD_SET_CHANNEL :
3868 			      NL80211_CMD_SET_WIPHY);
3869 	if (!msg || nl80211_put_freq_params(msg, freq) < 0) {
3870 		nlmsg_free(msg);
3871 		return -1;
3872 	}
3873 
3874 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
3875 	if (ret == 0) {
3876 		bss->freq = freq->freq;
3877 		return 0;
3878 	}
3879 	wpa_printf(MSG_DEBUG, "nl80211: Failed to set channel (freq=%d): "
3880 		   "%d (%s)", freq->freq, ret, strerror(-ret));
3881 	return -1;
3882 }
3883 
3884 
3885 static u32 sta_flags_nl80211(int flags)
3886 {
3887 	u32 f = 0;
3888 
3889 	if (flags & WPA_STA_AUTHORIZED)
3890 		f |= BIT(NL80211_STA_FLAG_AUTHORIZED);
3891 	if (flags & WPA_STA_WMM)
3892 		f |= BIT(NL80211_STA_FLAG_WME);
3893 	if (flags & WPA_STA_SHORT_PREAMBLE)
3894 		f |= BIT(NL80211_STA_FLAG_SHORT_PREAMBLE);
3895 	if (flags & WPA_STA_MFP)
3896 		f |= BIT(NL80211_STA_FLAG_MFP);
3897 	if (flags & WPA_STA_TDLS_PEER)
3898 		f |= BIT(NL80211_STA_FLAG_TDLS_PEER);
3899 	if (flags & WPA_STA_AUTHENTICATED)
3900 		f |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
3901 	if (flags & WPA_STA_ASSOCIATED)
3902 		f |= BIT(NL80211_STA_FLAG_ASSOCIATED);
3903 
3904 	return f;
3905 }
3906 
3907 
3908 #ifdef CONFIG_MESH
3909 static u32 sta_plink_state_nl80211(enum mesh_plink_state state)
3910 {
3911 	switch (state) {
3912 	case PLINK_IDLE:
3913 		return NL80211_PLINK_LISTEN;
3914 	case PLINK_OPN_SNT:
3915 		return NL80211_PLINK_OPN_SNT;
3916 	case PLINK_OPN_RCVD:
3917 		return NL80211_PLINK_OPN_RCVD;
3918 	case PLINK_CNF_RCVD:
3919 		return NL80211_PLINK_CNF_RCVD;
3920 	case PLINK_ESTAB:
3921 		return NL80211_PLINK_ESTAB;
3922 	case PLINK_HOLDING:
3923 		return NL80211_PLINK_HOLDING;
3924 	case PLINK_BLOCKED:
3925 		return NL80211_PLINK_BLOCKED;
3926 	default:
3927 		wpa_printf(MSG_ERROR, "nl80211: Invalid mesh plink state %d",
3928 			   state);
3929 	}
3930 	return -1;
3931 }
3932 #endif /* CONFIG_MESH */
3933 
3934 
3935 static int wpa_driver_nl80211_sta_add(void *priv,
3936 				      struct hostapd_sta_add_params *params)
3937 {
3938 	struct i802_bss *bss = priv;
3939 	struct wpa_driver_nl80211_data *drv = bss->drv;
3940 	struct nl_msg *msg;
3941 	struct nl80211_sta_flag_update upd;
3942 	int ret = -ENOBUFS;
3943 
3944 	if ((params->flags & WPA_STA_TDLS_PEER) &&
3945 	    !(drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_SUPPORT))
3946 		return -EOPNOTSUPP;
3947 
3948 	wpa_printf(MSG_DEBUG, "nl80211: %s STA " MACSTR,
3949 		   params->set ? "Set" : "Add", MAC2STR(params->addr));
3950 	msg = nl80211_bss_msg(bss, 0, params->set ? NL80211_CMD_SET_STATION :
3951 			      NL80211_CMD_NEW_STATION);
3952 	if (!msg || nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, params->addr))
3953 		goto fail;
3954 
3955 	/*
3956 	 * Set the below properties only in one of the following cases:
3957 	 * 1. New station is added, already associated.
3958 	 * 2. Set WPA_STA_TDLS_PEER station.
3959 	 * 3. Set an already added unassociated station, if driver supports
3960 	 * full AP client state. (Set these properties after station became
3961 	 * associated will be rejected by the driver).
3962 	 */
3963 	if (!params->set || (params->flags & WPA_STA_TDLS_PEER) ||
3964 	    (params->set && FULL_AP_CLIENT_STATE_SUPP(drv->capa.flags) &&
3965 	     (params->flags & WPA_STA_ASSOCIATED))) {
3966 		wpa_hexdump(MSG_DEBUG, "  * supported rates",
3967 			    params->supp_rates, params->supp_rates_len);
3968 		wpa_printf(MSG_DEBUG, "  * capability=0x%x",
3969 			   params->capability);
3970 		if (nla_put(msg, NL80211_ATTR_STA_SUPPORTED_RATES,
3971 			    params->supp_rates_len, params->supp_rates) ||
3972 		    nla_put_u16(msg, NL80211_ATTR_STA_CAPABILITY,
3973 				params->capability))
3974 			goto fail;
3975 
3976 		if (params->ht_capabilities) {
3977 			wpa_hexdump(MSG_DEBUG, "  * ht_capabilities",
3978 				    (u8 *) params->ht_capabilities,
3979 				    sizeof(*params->ht_capabilities));
3980 			if (nla_put(msg, NL80211_ATTR_HT_CAPABILITY,
3981 				    sizeof(*params->ht_capabilities),
3982 				    params->ht_capabilities))
3983 				goto fail;
3984 		}
3985 
3986 		if (params->vht_capabilities) {
3987 			wpa_hexdump(MSG_DEBUG, "  * vht_capabilities",
3988 				    (u8 *) params->vht_capabilities,
3989 				    sizeof(*params->vht_capabilities));
3990 			if (nla_put(msg, NL80211_ATTR_VHT_CAPABILITY,
3991 				    sizeof(*params->vht_capabilities),
3992 				    params->vht_capabilities))
3993 				goto fail;
3994 		}
3995 
3996 		if (params->ext_capab) {
3997 			wpa_hexdump(MSG_DEBUG, "  * ext_capab",
3998 				    params->ext_capab, params->ext_capab_len);
3999 			if (nla_put(msg, NL80211_ATTR_STA_EXT_CAPABILITY,
4000 				    params->ext_capab_len, params->ext_capab))
4001 				goto fail;
4002 		}
4003 
4004 		if (is_ap_interface(drv->nlmode) &&
4005 		    nla_put_u8(msg, NL80211_ATTR_STA_SUPPORT_P2P_PS,
4006 			       params->support_p2p_ps ?
4007 			       NL80211_P2P_PS_SUPPORTED :
4008 			       NL80211_P2P_PS_UNSUPPORTED))
4009 			goto fail;
4010 	}
4011 	if (!params->set) {
4012 		if (params->aid) {
4013 			wpa_printf(MSG_DEBUG, "  * aid=%u", params->aid);
4014 			if (nla_put_u16(msg, NL80211_ATTR_STA_AID, params->aid))
4015 				goto fail;
4016 		} else {
4017 			/*
4018 			 * cfg80211 validates that AID is non-zero, so we have
4019 			 * to make this a non-zero value for the TDLS case where
4020 			 * a dummy STA entry is used for now and for a station
4021 			 * that is still not associated.
4022 			 */
4023 			wpa_printf(MSG_DEBUG, "  * aid=1 (%s workaround)",
4024 				   (params->flags & WPA_STA_TDLS_PEER) ?
4025 				   "TDLS" : "UNASSOC_STA");
4026 			if (nla_put_u16(msg, NL80211_ATTR_STA_AID, 1))
4027 				goto fail;
4028 		}
4029 		wpa_printf(MSG_DEBUG, "  * listen_interval=%u",
4030 			   params->listen_interval);
4031 		if (nla_put_u16(msg, NL80211_ATTR_STA_LISTEN_INTERVAL,
4032 				params->listen_interval))
4033 			goto fail;
4034 	} else if (params->aid && (params->flags & WPA_STA_TDLS_PEER)) {
4035 		wpa_printf(MSG_DEBUG, "  * peer_aid=%u", params->aid);
4036 		if (nla_put_u16(msg, NL80211_ATTR_PEER_AID, params->aid))
4037 			goto fail;
4038 	} else if (FULL_AP_CLIENT_STATE_SUPP(drv->capa.flags) &&
4039 		   (params->flags & WPA_STA_ASSOCIATED)) {
4040 		wpa_printf(MSG_DEBUG, "  * aid=%u", params->aid);
4041 		wpa_printf(MSG_DEBUG, "  * listen_interval=%u",
4042 			   params->listen_interval);
4043 		if (nla_put_u16(msg, NL80211_ATTR_STA_AID, params->aid) ||
4044 		    nla_put_u16(msg, NL80211_ATTR_STA_LISTEN_INTERVAL,
4045 				params->listen_interval))
4046 			goto fail;
4047 	}
4048 
4049 	if (params->vht_opmode_enabled) {
4050 		wpa_printf(MSG_DEBUG, "  * opmode=%u", params->vht_opmode);
4051 		if (nla_put_u8(msg, NL80211_ATTR_OPMODE_NOTIF,
4052 			       params->vht_opmode))
4053 			goto fail;
4054 	}
4055 
4056 	if (params->supp_channels) {
4057 		wpa_hexdump(MSG_DEBUG, "  * supported channels",
4058 			    params->supp_channels, params->supp_channels_len);
4059 		if (nla_put(msg, NL80211_ATTR_STA_SUPPORTED_CHANNELS,
4060 			    params->supp_channels_len, params->supp_channels))
4061 			goto fail;
4062 	}
4063 
4064 	if (params->supp_oper_classes) {
4065 		wpa_hexdump(MSG_DEBUG, "  * supported operating classes",
4066 			    params->supp_oper_classes,
4067 			    params->supp_oper_classes_len);
4068 		if (nla_put(msg, NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES,
4069 			    params->supp_oper_classes_len,
4070 			    params->supp_oper_classes))
4071 			goto fail;
4072 	}
4073 
4074 	os_memset(&upd, 0, sizeof(upd));
4075 	upd.set = sta_flags_nl80211(params->flags);
4076 	upd.mask = upd.set | sta_flags_nl80211(params->flags_mask);
4077 
4078 	/*
4079 	 * If the driver doesn't support full AP client state, ignore ASSOC/AUTH
4080 	 * flags, as nl80211 driver moves a new station, by default, into
4081 	 * associated state.
4082 	 *
4083 	 * On the other hand, if the driver supports that feature and the
4084 	 * station is added in unauthenticated state, set the
4085 	 * authenticated/associated bits in the mask to prevent moving this
4086 	 * station to associated state before it is actually associated.
4087 	 *
4088 	 * This is irrelevant for mesh mode where the station is added to the
4089 	 * driver as authenticated already, and ASSOCIATED isn't part of the
4090 	 * nl80211 API.
4091 	 */
4092 	if (!is_mesh_interface(drv->nlmode)) {
4093 		if (!FULL_AP_CLIENT_STATE_SUPP(drv->capa.flags)) {
4094 			wpa_printf(MSG_DEBUG,
4095 				   "nl80211: Ignore ASSOC/AUTH flags since driver doesn't support full AP client state");
4096 			upd.mask &= ~(BIT(NL80211_STA_FLAG_ASSOCIATED) |
4097 				      BIT(NL80211_STA_FLAG_AUTHENTICATED));
4098 		} else if (!params->set &&
4099 			   !(params->flags & WPA_STA_TDLS_PEER)) {
4100 			if (!(params->flags & WPA_STA_AUTHENTICATED))
4101 				upd.mask |= BIT(NL80211_STA_FLAG_AUTHENTICATED);
4102 			if (!(params->flags & WPA_STA_ASSOCIATED))
4103 				upd.mask |= BIT(NL80211_STA_FLAG_ASSOCIATED);
4104 		}
4105 #ifdef CONFIG_MESH
4106 	} else {
4107 		if (params->plink_state == PLINK_ESTAB && params->peer_aid) {
4108 			ret = nla_put_u16(msg, NL80211_ATTR_MESH_PEER_AID,
4109 					  params->peer_aid);
4110 			if (ret)
4111 				goto fail;
4112 		}
4113 #endif /* CONFIG_MESH */
4114 	}
4115 
4116 	wpa_printf(MSG_DEBUG, "  * flags set=0x%x mask=0x%x",
4117 		   upd.set, upd.mask);
4118 	if (nla_put(msg, NL80211_ATTR_STA_FLAGS2, sizeof(upd), &upd))
4119 		goto fail;
4120 
4121 #ifdef CONFIG_MESH
4122 	if (params->plink_state &&
4123 	    nla_put_u8(msg, NL80211_ATTR_STA_PLINK_STATE,
4124 		       sta_plink_state_nl80211(params->plink_state)))
4125 		goto fail;
4126 #endif /* CONFIG_MESH */
4127 
4128 	if (params->flags & WPA_STA_WMM) {
4129 		struct nlattr *wme = nla_nest_start(msg, NL80211_ATTR_STA_WME);
4130 
4131 		wpa_printf(MSG_DEBUG, "  * qosinfo=0x%x", params->qosinfo);
4132 		if (!wme ||
4133 		    nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES,
4134 			       params->qosinfo & WMM_QOSINFO_STA_AC_MASK) ||
4135 		    nla_put_u8(msg, NL80211_STA_WME_MAX_SP,
4136 			       (params->qosinfo >> WMM_QOSINFO_STA_SP_SHIFT) &
4137 			       WMM_QOSINFO_STA_SP_MASK))
4138 			goto fail;
4139 		nla_nest_end(msg, wme);
4140 	}
4141 
4142 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
4143 	msg = NULL;
4144 	if (ret)
4145 		wpa_printf(MSG_DEBUG, "nl80211: NL80211_CMD_%s_STATION "
4146 			   "result: %d (%s)", params->set ? "SET" : "NEW", ret,
4147 			   strerror(-ret));
4148 	if (ret == -EEXIST)
4149 		ret = 0;
4150 fail:
4151 	nlmsg_free(msg);
4152 	return ret;
4153 }
4154 
4155 
4156 static void rtnl_neigh_delete_fdb_entry(struct i802_bss *bss, const u8 *addr)
4157 {
4158 #ifdef CONFIG_LIBNL3_ROUTE
4159 	struct wpa_driver_nl80211_data *drv = bss->drv;
4160 	struct rtnl_neigh *rn;
4161 	struct nl_addr *nl_addr;
4162 	int err;
4163 
4164 	rn = rtnl_neigh_alloc();
4165 	if (!rn)
4166 		return;
4167 
4168 	rtnl_neigh_set_family(rn, AF_BRIDGE);
4169 	rtnl_neigh_set_ifindex(rn, bss->ifindex);
4170 	nl_addr = nl_addr_build(AF_BRIDGE, (void *) addr, ETH_ALEN);
4171 	if (!nl_addr) {
4172 		rtnl_neigh_put(rn);
4173 		return;
4174 	}
4175 	rtnl_neigh_set_lladdr(rn, nl_addr);
4176 
4177 	err = rtnl_neigh_delete(drv->rtnl_sk, rn, 0);
4178 	if (err < 0) {
4179 		wpa_printf(MSG_DEBUG, "nl80211: bridge FDB entry delete for "
4180 			   MACSTR " ifindex=%d failed: %s", MAC2STR(addr),
4181 			   bss->ifindex, nl_geterror(err));
4182 	} else {
4183 		wpa_printf(MSG_DEBUG, "nl80211: deleted bridge FDB entry for "
4184 			   MACSTR, MAC2STR(addr));
4185 	}
4186 
4187 	nl_addr_put(nl_addr);
4188 	rtnl_neigh_put(rn);
4189 #endif /* CONFIG_LIBNL3_ROUTE */
4190 }
4191 
4192 
4193 static int wpa_driver_nl80211_sta_remove(struct i802_bss *bss, const u8 *addr,
4194 					 int deauth, u16 reason_code)
4195 {
4196 	struct wpa_driver_nl80211_data *drv = bss->drv;
4197 	struct nl_msg *msg;
4198 	int ret;
4199 
4200 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_DEL_STATION)) ||
4201 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
4202 	    (deauth == 0 &&
4203 	     nla_put_u8(msg, NL80211_ATTR_MGMT_SUBTYPE,
4204 			WLAN_FC_STYPE_DISASSOC)) ||
4205 	    (deauth == 1 &&
4206 	     nla_put_u8(msg, NL80211_ATTR_MGMT_SUBTYPE,
4207 			WLAN_FC_STYPE_DEAUTH)) ||
4208 	    (reason_code &&
4209 	     nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code))) {
4210 		nlmsg_free(msg);
4211 		return -ENOBUFS;
4212 	}
4213 
4214 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
4215 	wpa_printf(MSG_DEBUG, "nl80211: sta_remove -> DEL_STATION %s " MACSTR
4216 		   " --> %d (%s)",
4217 		   bss->ifname, MAC2STR(addr), ret, strerror(-ret));
4218 
4219 	if (drv->rtnl_sk)
4220 		rtnl_neigh_delete_fdb_entry(bss, addr);
4221 
4222 	if (ret == -ENOENT)
4223 		return 0;
4224 	return ret;
4225 }
4226 
4227 
4228 void nl80211_remove_iface(struct wpa_driver_nl80211_data *drv, int ifidx)
4229 {
4230 	struct nl_msg *msg;
4231 	struct wpa_driver_nl80211_data *drv2;
4232 
4233 	wpa_printf(MSG_DEBUG, "nl80211: Remove interface ifindex=%d", ifidx);
4234 
4235 	/* stop listening for EAPOL on this interface */
4236 	dl_list_for_each(drv2, &drv->global->interfaces,
4237 			 struct wpa_driver_nl80211_data, list)
4238 	{
4239 		del_ifidx(drv2, ifidx, IFIDX_ANY);
4240 		/* Remove all bridges learned for this iface */
4241 		del_ifidx(drv2, IFIDX_ANY, ifidx);
4242 	}
4243 
4244 	msg = nl80211_ifindex_msg(drv, ifidx, 0, NL80211_CMD_DEL_INTERFACE);
4245 	if (send_and_recv_msgs(drv, msg, NULL, NULL) == 0)
4246 		return;
4247 	wpa_printf(MSG_ERROR, "Failed to remove interface (ifidx=%d)", ifidx);
4248 }
4249 
4250 
4251 const char * nl80211_iftype_str(enum nl80211_iftype mode)
4252 {
4253 	switch (mode) {
4254 	case NL80211_IFTYPE_ADHOC:
4255 		return "ADHOC";
4256 	case NL80211_IFTYPE_STATION:
4257 		return "STATION";
4258 	case NL80211_IFTYPE_AP:
4259 		return "AP";
4260 	case NL80211_IFTYPE_AP_VLAN:
4261 		return "AP_VLAN";
4262 	case NL80211_IFTYPE_WDS:
4263 		return "WDS";
4264 	case NL80211_IFTYPE_MONITOR:
4265 		return "MONITOR";
4266 	case NL80211_IFTYPE_MESH_POINT:
4267 		return "MESH_POINT";
4268 	case NL80211_IFTYPE_P2P_CLIENT:
4269 		return "P2P_CLIENT";
4270 	case NL80211_IFTYPE_P2P_GO:
4271 		return "P2P_GO";
4272 	case NL80211_IFTYPE_P2P_DEVICE:
4273 		return "P2P_DEVICE";
4274 	default:
4275 		return "unknown";
4276 	}
4277 }
4278 
4279 
4280 static int nl80211_create_iface_once(struct wpa_driver_nl80211_data *drv,
4281 				     const char *ifname,
4282 				     enum nl80211_iftype iftype,
4283 				     const u8 *addr, int wds,
4284 				     int (*handler)(struct nl_msg *, void *),
4285 				     void *arg)
4286 {
4287 	struct nl_msg *msg;
4288 	int ifidx;
4289 	int ret = -ENOBUFS;
4290 
4291 	wpa_printf(MSG_DEBUG, "nl80211: Create interface iftype %d (%s)",
4292 		   iftype, nl80211_iftype_str(iftype));
4293 
4294 	msg = nl80211_cmd_msg(drv->first_bss, 0, NL80211_CMD_NEW_INTERFACE);
4295 	if (!msg ||
4296 	    nla_put_string(msg, NL80211_ATTR_IFNAME, ifname) ||
4297 	    nla_put_u32(msg, NL80211_ATTR_IFTYPE, iftype))
4298 		goto fail;
4299 
4300 	if (iftype == NL80211_IFTYPE_MONITOR) {
4301 		struct nlattr *flags;
4302 
4303 		flags = nla_nest_start(msg, NL80211_ATTR_MNTR_FLAGS);
4304 		if (!flags ||
4305 		    nla_put_flag(msg, NL80211_MNTR_FLAG_COOK_FRAMES))
4306 			goto fail;
4307 
4308 		nla_nest_end(msg, flags);
4309 	} else if (wds) {
4310 		if (nla_put_u8(msg, NL80211_ATTR_4ADDR, wds))
4311 			goto fail;
4312 	}
4313 
4314 	/*
4315 	 * Tell cfg80211 that the interface belongs to the socket that created
4316 	 * it, and the interface should be deleted when the socket is closed.
4317 	 */
4318 	if (nla_put_flag(msg, NL80211_ATTR_IFACE_SOCKET_OWNER))
4319 		goto fail;
4320 
4321 	ret = send_and_recv_msgs(drv, msg, handler, arg);
4322 	msg = NULL;
4323 	if (ret) {
4324 	fail:
4325 		nlmsg_free(msg);
4326 		wpa_printf(MSG_ERROR, "Failed to create interface %s: %d (%s)",
4327 			   ifname, ret, strerror(-ret));
4328 		return ret;
4329 	}
4330 
4331 	if (iftype == NL80211_IFTYPE_P2P_DEVICE)
4332 		return 0;
4333 
4334 	ifidx = if_nametoindex(ifname);
4335 	wpa_printf(MSG_DEBUG, "nl80211: New interface %s created: ifindex=%d",
4336 		   ifname, ifidx);
4337 
4338 	if (ifidx <= 0)
4339 		return -1;
4340 
4341 	/*
4342 	 * Some virtual interfaces need to process EAPOL packets and events on
4343 	 * the parent interface. This is used mainly with hostapd.
4344 	 */
4345 	if (drv->hostapd ||
4346 	    iftype == NL80211_IFTYPE_AP_VLAN ||
4347 	    iftype == NL80211_IFTYPE_WDS ||
4348 	    iftype == NL80211_IFTYPE_MONITOR) {
4349 		/* start listening for EAPOL on this interface */
4350 		add_ifidx(drv, ifidx, IFIDX_ANY);
4351 	}
4352 
4353 	if (addr && iftype != NL80211_IFTYPE_MONITOR &&
4354 	    linux_set_ifhwaddr(drv->global->ioctl_sock, ifname, addr)) {
4355 		nl80211_remove_iface(drv, ifidx);
4356 		return -1;
4357 	}
4358 
4359 	return ifidx;
4360 }
4361 
4362 
4363 int nl80211_create_iface(struct wpa_driver_nl80211_data *drv,
4364 			 const char *ifname, enum nl80211_iftype iftype,
4365 			 const u8 *addr, int wds,
4366 			 int (*handler)(struct nl_msg *, void *),
4367 			 void *arg, int use_existing)
4368 {
4369 	int ret;
4370 
4371 	ret = nl80211_create_iface_once(drv, ifname, iftype, addr, wds, handler,
4372 					arg);
4373 
4374 	/* if error occurred and interface exists already */
4375 	if (ret == -ENFILE && if_nametoindex(ifname)) {
4376 		if (use_existing) {
4377 			wpa_printf(MSG_DEBUG, "nl80211: Continue using existing interface %s",
4378 				   ifname);
4379 			if (addr && iftype != NL80211_IFTYPE_MONITOR &&
4380 			    linux_set_ifhwaddr(drv->global->ioctl_sock, ifname,
4381 					       addr) < 0 &&
4382 			    (linux_set_iface_flags(drv->global->ioctl_sock,
4383 						   ifname, 0) < 0 ||
4384 			     linux_set_ifhwaddr(drv->global->ioctl_sock, ifname,
4385 						addr) < 0 ||
4386 			     linux_set_iface_flags(drv->global->ioctl_sock,
4387 						   ifname, 1) < 0))
4388 					return -1;
4389 			return -ENFILE;
4390 		}
4391 		wpa_printf(MSG_INFO, "Try to remove and re-create %s", ifname);
4392 
4393 		/* Try to remove the interface that was already there. */
4394 		nl80211_remove_iface(drv, if_nametoindex(ifname));
4395 
4396 		/* Try to create the interface again */
4397 		ret = nl80211_create_iface_once(drv, ifname, iftype, addr,
4398 						wds, handler, arg);
4399 	}
4400 
4401 	if (ret >= 0 && is_p2p_net_interface(iftype)) {
4402 		wpa_printf(MSG_DEBUG,
4403 			   "nl80211: Interface %s created for P2P - disable 11b rates",
4404 			   ifname);
4405 		nl80211_disable_11b_rates(drv, ret, 1);
4406 	}
4407 
4408 	return ret;
4409 }
4410 
4411 
4412 static int nl80211_setup_ap(struct i802_bss *bss)
4413 {
4414 	struct wpa_driver_nl80211_data *drv = bss->drv;
4415 
4416 	wpa_printf(MSG_DEBUG, "nl80211: Setup AP(%s) - device_ap_sme=%d use_monitor=%d",
4417 		   bss->ifname, drv->device_ap_sme, drv->use_monitor);
4418 
4419 	/*
4420 	 * Disable Probe Request reporting unless we need it in this way for
4421 	 * devices that include the AP SME, in the other case (unless using
4422 	 * monitor iface) we'll get it through the nl_mgmt socket instead.
4423 	 */
4424 	if (!drv->device_ap_sme)
4425 		wpa_driver_nl80211_probe_req_report(bss, 0);
4426 
4427 	if (!drv->device_ap_sme && !drv->use_monitor)
4428 		if (nl80211_mgmt_subscribe_ap(bss))
4429 			return -1;
4430 
4431 	if (drv->device_ap_sme && !drv->use_monitor)
4432 		if (nl80211_mgmt_subscribe_ap_dev_sme(bss))
4433 			wpa_printf(MSG_DEBUG,
4434 				   "nl80211: Failed to subscribe for mgmt frames from SME driver - trying to run without it");
4435 
4436 	if (!drv->device_ap_sme && drv->use_monitor &&
4437 	    nl80211_create_monitor_interface(drv) &&
4438 	    !drv->device_ap_sme)
4439 		return -1;
4440 
4441 	if (drv->device_ap_sme &&
4442 	    wpa_driver_nl80211_probe_req_report(bss, 1) < 0) {
4443 		wpa_printf(MSG_DEBUG, "nl80211: Failed to enable "
4444 			   "Probe Request frame reporting in AP mode");
4445 		/* Try to survive without this */
4446 	}
4447 
4448 	return 0;
4449 }
4450 
4451 
4452 static void nl80211_teardown_ap(struct i802_bss *bss)
4453 {
4454 	struct wpa_driver_nl80211_data *drv = bss->drv;
4455 
4456 	wpa_printf(MSG_DEBUG, "nl80211: Teardown AP(%s) - device_ap_sme=%d use_monitor=%d",
4457 		   bss->ifname, drv->device_ap_sme, drv->use_monitor);
4458 	if (drv->device_ap_sme) {
4459 		wpa_driver_nl80211_probe_req_report(bss, 0);
4460 		if (!drv->use_monitor)
4461 			nl80211_mgmt_unsubscribe(bss, "AP teardown (dev SME)");
4462 	} else if (drv->use_monitor)
4463 		nl80211_remove_monitor_interface(drv);
4464 	else
4465 		nl80211_mgmt_unsubscribe(bss, "AP teardown");
4466 
4467 	bss->beacon_set = 0;
4468 }
4469 
4470 
4471 static int nl80211_send_eapol_data(struct i802_bss *bss,
4472 				   const u8 *addr, const u8 *data,
4473 				   size_t data_len)
4474 {
4475 	struct sockaddr_ll ll;
4476 	int ret;
4477 
4478 	if (bss->drv->eapol_tx_sock < 0) {
4479 		wpa_printf(MSG_DEBUG, "nl80211: No socket to send EAPOL");
4480 		return -1;
4481 	}
4482 
4483 	os_memset(&ll, 0, sizeof(ll));
4484 	ll.sll_family = AF_PACKET;
4485 	ll.sll_ifindex = bss->ifindex;
4486 	ll.sll_protocol = htons(ETH_P_PAE);
4487 	ll.sll_halen = ETH_ALEN;
4488 	os_memcpy(ll.sll_addr, addr, ETH_ALEN);
4489 	ret = sendto(bss->drv->eapol_tx_sock, data, data_len, 0,
4490 		     (struct sockaddr *) &ll, sizeof(ll));
4491 	if (ret < 0)
4492 		wpa_printf(MSG_ERROR, "nl80211: EAPOL TX: %s",
4493 			   strerror(errno));
4494 
4495 	return ret;
4496 }
4497 
4498 
4499 static const u8 rfc1042_header[6] = { 0xaa, 0xaa, 0x03, 0x00, 0x00, 0x00 };
4500 
4501 static int wpa_driver_nl80211_hapd_send_eapol(
4502 	void *priv, const u8 *addr, const u8 *data,
4503 	size_t data_len, int encrypt, const u8 *own_addr, u32 flags)
4504 {
4505 	struct i802_bss *bss = priv;
4506 	struct wpa_driver_nl80211_data *drv = bss->drv;
4507 	struct ieee80211_hdr *hdr;
4508 	size_t len;
4509 	u8 *pos;
4510 	int res;
4511 	int qos = flags & WPA_STA_WMM;
4512 
4513 	if (drv->device_ap_sme || !drv->use_monitor)
4514 		return nl80211_send_eapol_data(bss, addr, data, data_len);
4515 
4516 	len = sizeof(*hdr) + (qos ? 2 : 0) + sizeof(rfc1042_header) + 2 +
4517 		data_len;
4518 	hdr = os_zalloc(len);
4519 	if (hdr == NULL) {
4520 		wpa_printf(MSG_INFO, "nl80211: Failed to allocate EAPOL buffer(len=%lu)",
4521 			   (unsigned long) len);
4522 		return -1;
4523 	}
4524 
4525 	hdr->frame_control =
4526 		IEEE80211_FC(WLAN_FC_TYPE_DATA, WLAN_FC_STYPE_DATA);
4527 	hdr->frame_control |= host_to_le16(WLAN_FC_FROMDS);
4528 	if (encrypt)
4529 		hdr->frame_control |= host_to_le16(WLAN_FC_ISWEP);
4530 	if (qos) {
4531 		hdr->frame_control |=
4532 			host_to_le16(WLAN_FC_STYPE_QOS_DATA << 4);
4533 	}
4534 
4535 	memcpy(hdr->IEEE80211_DA_FROMDS, addr, ETH_ALEN);
4536 	memcpy(hdr->IEEE80211_BSSID_FROMDS, own_addr, ETH_ALEN);
4537 	memcpy(hdr->IEEE80211_SA_FROMDS, own_addr, ETH_ALEN);
4538 	pos = (u8 *) (hdr + 1);
4539 
4540 	if (qos) {
4541 		/* Set highest priority in QoS header */
4542 		pos[0] = 7;
4543 		pos[1] = 0;
4544 		pos += 2;
4545 	}
4546 
4547 	memcpy(pos, rfc1042_header, sizeof(rfc1042_header));
4548 	pos += sizeof(rfc1042_header);
4549 	WPA_PUT_BE16(pos, ETH_P_PAE);
4550 	pos += 2;
4551 	memcpy(pos, data, data_len);
4552 
4553 	res = wpa_driver_nl80211_send_frame(bss, (u8 *) hdr, len, encrypt, 0,
4554 					    0, 0, 0, 0, NULL, 0);
4555 	if (res < 0) {
4556 		wpa_printf(MSG_ERROR, "i802_send_eapol - packet len: %lu - "
4557 			   "failed: %d (%s)",
4558 			   (unsigned long) len, errno, strerror(errno));
4559 	}
4560 	os_free(hdr);
4561 
4562 	return res;
4563 }
4564 
4565 
4566 static int wpa_driver_nl80211_sta_set_flags(void *priv, const u8 *addr,
4567 					    unsigned int total_flags,
4568 					    unsigned int flags_or,
4569 					    unsigned int flags_and)
4570 {
4571 	struct i802_bss *bss = priv;
4572 	struct nl_msg *msg;
4573 	struct nlattr *flags;
4574 	struct nl80211_sta_flag_update upd;
4575 
4576 	wpa_printf(MSG_DEBUG, "nl80211: Set STA flags - ifname=%s addr=" MACSTR
4577 		   " total_flags=0x%x flags_or=0x%x flags_and=0x%x authorized=%d",
4578 		   bss->ifname, MAC2STR(addr), total_flags, flags_or, flags_and,
4579 		   !!(total_flags & WPA_STA_AUTHORIZED));
4580 
4581 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_STATION)) ||
4582 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
4583 		goto fail;
4584 
4585 	/*
4586 	 * Backwards compatibility version using NL80211_ATTR_STA_FLAGS. This
4587 	 * can be removed eventually.
4588 	 */
4589 	flags = nla_nest_start(msg, NL80211_ATTR_STA_FLAGS);
4590 	if (!flags ||
4591 	    ((total_flags & WPA_STA_AUTHORIZED) &&
4592 	     nla_put_flag(msg, NL80211_STA_FLAG_AUTHORIZED)) ||
4593 	    ((total_flags & WPA_STA_WMM) &&
4594 	     nla_put_flag(msg, NL80211_STA_FLAG_WME)) ||
4595 	    ((total_flags & WPA_STA_SHORT_PREAMBLE) &&
4596 	     nla_put_flag(msg, NL80211_STA_FLAG_SHORT_PREAMBLE)) ||
4597 	    ((total_flags & WPA_STA_MFP) &&
4598 	     nla_put_flag(msg, NL80211_STA_FLAG_MFP)) ||
4599 	    ((total_flags & WPA_STA_TDLS_PEER) &&
4600 	     nla_put_flag(msg, NL80211_STA_FLAG_TDLS_PEER)))
4601 		goto fail;
4602 
4603 	nla_nest_end(msg, flags);
4604 
4605 	os_memset(&upd, 0, sizeof(upd));
4606 	upd.mask = sta_flags_nl80211(flags_or | ~flags_and);
4607 	upd.set = sta_flags_nl80211(flags_or);
4608 	if (nla_put(msg, NL80211_ATTR_STA_FLAGS2, sizeof(upd), &upd))
4609 		goto fail;
4610 
4611 	return send_and_recv_msgs(bss->drv, msg, NULL, NULL);
4612 fail:
4613 	nlmsg_free(msg);
4614 	return -ENOBUFS;
4615 }
4616 
4617 
4618 static int wpa_driver_nl80211_ap(struct wpa_driver_nl80211_data *drv,
4619 				 struct wpa_driver_associate_params *params)
4620 {
4621 	enum nl80211_iftype nlmode, old_mode;
4622 
4623 	if (params->p2p) {
4624 		wpa_printf(MSG_DEBUG, "nl80211: Setup AP operations for P2P "
4625 			   "group (GO)");
4626 		nlmode = NL80211_IFTYPE_P2P_GO;
4627 	} else
4628 		nlmode = NL80211_IFTYPE_AP;
4629 
4630 	old_mode = drv->nlmode;
4631 	if (wpa_driver_nl80211_set_mode(drv->first_bss, nlmode)) {
4632 		nl80211_remove_monitor_interface(drv);
4633 		return -1;
4634 	}
4635 
4636 	if (params->freq.freq &&
4637 	    nl80211_set_channel(drv->first_bss, &params->freq, 0)) {
4638 		if (old_mode != nlmode)
4639 			wpa_driver_nl80211_set_mode(drv->first_bss, old_mode);
4640 		nl80211_remove_monitor_interface(drv);
4641 		return -1;
4642 	}
4643 
4644 	return 0;
4645 }
4646 
4647 
4648 static int nl80211_leave_ibss(struct wpa_driver_nl80211_data *drv,
4649 			      int reset_mode)
4650 {
4651 	struct nl_msg *msg;
4652 	int ret;
4653 
4654 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_LEAVE_IBSS);
4655 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
4656 	if (ret) {
4657 		wpa_printf(MSG_DEBUG, "nl80211: Leave IBSS failed: ret=%d "
4658 			   "(%s)", ret, strerror(-ret));
4659 	} else {
4660 		wpa_printf(MSG_DEBUG,
4661 			   "nl80211: Leave IBSS request sent successfully");
4662 	}
4663 
4664 	if (reset_mode &&
4665 	    wpa_driver_nl80211_set_mode(drv->first_bss,
4666 					NL80211_IFTYPE_STATION)) {
4667 		wpa_printf(MSG_INFO, "nl80211: Failed to set interface into "
4668 			   "station mode");
4669 	}
4670 
4671 	return ret;
4672 }
4673 
4674 
4675 static int nl80211_ht_vht_overrides(struct nl_msg *msg,
4676 				    struct wpa_driver_associate_params *params)
4677 {
4678 	if (params->disable_ht && nla_put_flag(msg, NL80211_ATTR_DISABLE_HT))
4679 		return -1;
4680 
4681 	if (params->htcaps && params->htcaps_mask) {
4682 		int sz = sizeof(struct ieee80211_ht_capabilities);
4683 		wpa_hexdump(MSG_DEBUG, "  * htcaps", params->htcaps, sz);
4684 		wpa_hexdump(MSG_DEBUG, "  * htcaps_mask",
4685 			    params->htcaps_mask, sz);
4686 		if (nla_put(msg, NL80211_ATTR_HT_CAPABILITY, sz,
4687 			    params->htcaps) ||
4688 		    nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK, sz,
4689 			    params->htcaps_mask))
4690 			return -1;
4691 	}
4692 
4693 #ifdef CONFIG_VHT_OVERRIDES
4694 	if (params->disable_vht) {
4695 		wpa_printf(MSG_DEBUG, "  * VHT disabled");
4696 		if (nla_put_flag(msg, NL80211_ATTR_DISABLE_VHT))
4697 			return -1;
4698 	}
4699 
4700 	if (params->vhtcaps && params->vhtcaps_mask) {
4701 		int sz = sizeof(struct ieee80211_vht_capabilities);
4702 		wpa_hexdump(MSG_DEBUG, "  * vhtcaps", params->vhtcaps, sz);
4703 		wpa_hexdump(MSG_DEBUG, "  * vhtcaps_mask",
4704 			    params->vhtcaps_mask, sz);
4705 		if (nla_put(msg, NL80211_ATTR_VHT_CAPABILITY, sz,
4706 			    params->vhtcaps) ||
4707 		    nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK, sz,
4708 			    params->vhtcaps_mask))
4709 			return -1;
4710 	}
4711 #endif /* CONFIG_VHT_OVERRIDES */
4712 
4713 	return 0;
4714 }
4715 
4716 
4717 static int wpa_driver_nl80211_ibss(struct wpa_driver_nl80211_data *drv,
4718 				   struct wpa_driver_associate_params *params)
4719 {
4720 	struct nl_msg *msg;
4721 	int ret = -1;
4722 	int count = 0;
4723 
4724 	wpa_printf(MSG_DEBUG, "nl80211: Join IBSS (ifindex=%d)", drv->ifindex);
4725 
4726 	if (wpa_driver_nl80211_set_mode_ibss(drv->first_bss, &params->freq)) {
4727 		wpa_printf(MSG_INFO, "nl80211: Failed to set interface into "
4728 			   "IBSS mode");
4729 		return -1;
4730 	}
4731 
4732 retry:
4733 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_JOIN_IBSS)) ||
4734 	    params->ssid == NULL || params->ssid_len > sizeof(drv->ssid))
4735 		goto fail;
4736 
4737 	wpa_hexdump_ascii(MSG_DEBUG, "  * SSID",
4738 			  params->ssid, params->ssid_len);
4739 	if (nla_put(msg, NL80211_ATTR_SSID, params->ssid_len, params->ssid))
4740 		goto fail;
4741 	os_memcpy(drv->ssid, params->ssid, params->ssid_len);
4742 	drv->ssid_len = params->ssid_len;
4743 
4744 	if (nl80211_put_freq_params(msg, &params->freq) < 0 ||
4745 	    nl80211_put_beacon_int(msg, params->beacon_int))
4746 		goto fail;
4747 
4748 	ret = nl80211_set_conn_keys(params, msg);
4749 	if (ret)
4750 		goto fail;
4751 
4752 	if (params->bssid && params->fixed_bssid) {
4753 		wpa_printf(MSG_DEBUG, "  * BSSID=" MACSTR,
4754 			   MAC2STR(params->bssid));
4755 		if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, params->bssid))
4756 			goto fail;
4757 	}
4758 
4759 	if (params->fixed_freq) {
4760 		wpa_printf(MSG_DEBUG, "  * fixed_freq");
4761 		if (nla_put_flag(msg, NL80211_ATTR_FREQ_FIXED))
4762 			goto fail;
4763 	}
4764 
4765 	if (params->key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X ||
4766 	    params->key_mgmt_suite == WPA_KEY_MGMT_PSK ||
4767 	    params->key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SHA256 ||
4768 	    params->key_mgmt_suite == WPA_KEY_MGMT_PSK_SHA256) {
4769 		wpa_printf(MSG_DEBUG, "  * control port");
4770 		if (nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT))
4771 			goto fail;
4772 	}
4773 
4774 	if (params->wpa_ie) {
4775 		wpa_hexdump(MSG_DEBUG,
4776 			    "  * Extra IEs for Beacon/Probe Response frames",
4777 			    params->wpa_ie, params->wpa_ie_len);
4778 		if (nla_put(msg, NL80211_ATTR_IE, params->wpa_ie_len,
4779 			    params->wpa_ie))
4780 			goto fail;
4781 	}
4782 
4783 	ret = nl80211_ht_vht_overrides(msg, params);
4784 	if (ret < 0)
4785 		goto fail;
4786 
4787 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
4788 	msg = NULL;
4789 	if (ret) {
4790 		wpa_printf(MSG_DEBUG, "nl80211: Join IBSS failed: ret=%d (%s)",
4791 			   ret, strerror(-ret));
4792 		count++;
4793 		if (ret == -EALREADY && count == 1) {
4794 			wpa_printf(MSG_DEBUG, "nl80211: Retry IBSS join after "
4795 				   "forced leave");
4796 			nl80211_leave_ibss(drv, 0);
4797 			nlmsg_free(msg);
4798 			goto retry;
4799 		}
4800 	} else {
4801 		wpa_printf(MSG_DEBUG,
4802 			   "nl80211: Join IBSS request sent successfully");
4803 	}
4804 
4805 fail:
4806 	nlmsg_free(msg);
4807 	return ret;
4808 }
4809 
4810 
4811 static int nl80211_connect_common(struct wpa_driver_nl80211_data *drv,
4812 				  struct wpa_driver_associate_params *params,
4813 				  struct nl_msg *msg)
4814 {
4815 	if (params->bssid) {
4816 		wpa_printf(MSG_DEBUG, "  * bssid=" MACSTR,
4817 			   MAC2STR(params->bssid));
4818 		if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, params->bssid))
4819 			return -1;
4820 	}
4821 
4822 	if (params->bssid_hint) {
4823 		wpa_printf(MSG_DEBUG, "  * bssid_hint=" MACSTR,
4824 			   MAC2STR(params->bssid_hint));
4825 		if (nla_put(msg, NL80211_ATTR_MAC_HINT, ETH_ALEN,
4826 			    params->bssid_hint))
4827 			return -1;
4828 	}
4829 
4830 	if (params->freq.freq) {
4831 		wpa_printf(MSG_DEBUG, "  * freq=%d", params->freq.freq);
4832 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
4833 				params->freq.freq))
4834 			return -1;
4835 		drv->assoc_freq = params->freq.freq;
4836 	} else
4837 		drv->assoc_freq = 0;
4838 
4839 	if (params->freq_hint) {
4840 		wpa_printf(MSG_DEBUG, "  * freq_hint=%d", params->freq_hint);
4841 		if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ_HINT,
4842 				params->freq_hint))
4843 			return -1;
4844 	}
4845 
4846 	if (params->bg_scan_period >= 0) {
4847 		wpa_printf(MSG_DEBUG, "  * bg scan period=%d",
4848 			   params->bg_scan_period);
4849 		if (nla_put_u16(msg, NL80211_ATTR_BG_SCAN_PERIOD,
4850 				params->bg_scan_period))
4851 			return -1;
4852 	}
4853 
4854 	if (params->ssid) {
4855 		wpa_hexdump_ascii(MSG_DEBUG, "  * SSID",
4856 				  params->ssid, params->ssid_len);
4857 		if (nla_put(msg, NL80211_ATTR_SSID, params->ssid_len,
4858 			    params->ssid))
4859 			return -1;
4860 		if (params->ssid_len > sizeof(drv->ssid))
4861 			return -1;
4862 		os_memcpy(drv->ssid, params->ssid, params->ssid_len);
4863 		drv->ssid_len = params->ssid_len;
4864 	}
4865 
4866 	wpa_hexdump(MSG_DEBUG, "  * IEs", params->wpa_ie, params->wpa_ie_len);
4867 	if (params->wpa_ie &&
4868 	    nla_put(msg, NL80211_ATTR_IE, params->wpa_ie_len, params->wpa_ie))
4869 		return -1;
4870 
4871 	if (params->wpa_proto) {
4872 		enum nl80211_wpa_versions ver = 0;
4873 
4874 		if (params->wpa_proto & WPA_PROTO_WPA)
4875 			ver |= NL80211_WPA_VERSION_1;
4876 		if (params->wpa_proto & WPA_PROTO_RSN)
4877 			ver |= NL80211_WPA_VERSION_2;
4878 
4879 		wpa_printf(MSG_DEBUG, "  * WPA Versions 0x%x", ver);
4880 		if (nla_put_u32(msg, NL80211_ATTR_WPA_VERSIONS, ver))
4881 			return -1;
4882 	}
4883 
4884 	if (params->pairwise_suite != WPA_CIPHER_NONE) {
4885 		u32 cipher = wpa_cipher_to_cipher_suite(params->pairwise_suite);
4886 		wpa_printf(MSG_DEBUG, "  * pairwise=0x%x", cipher);
4887 		if (nla_put_u32(msg, NL80211_ATTR_CIPHER_SUITES_PAIRWISE,
4888 				cipher))
4889 			return -1;
4890 	}
4891 
4892 	if (params->group_suite == WPA_CIPHER_GTK_NOT_USED &&
4893 	    !(drv->capa.enc & WPA_DRIVER_CAPA_ENC_GTK_NOT_USED)) {
4894 		/*
4895 		 * This is likely to work even though many drivers do not
4896 		 * advertise support for operations without GTK.
4897 		 */
4898 		wpa_printf(MSG_DEBUG, "  * skip group cipher configuration for GTK_NOT_USED due to missing driver support advertisement");
4899 	} else if (params->group_suite != WPA_CIPHER_NONE) {
4900 		u32 cipher = wpa_cipher_to_cipher_suite(params->group_suite);
4901 		wpa_printf(MSG_DEBUG, "  * group=0x%x", cipher);
4902 		if (nla_put_u32(msg, NL80211_ATTR_CIPHER_SUITE_GROUP, cipher))
4903 			return -1;
4904 	}
4905 
4906 	if (params->key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X ||
4907 	    params->key_mgmt_suite == WPA_KEY_MGMT_PSK ||
4908 	    params->key_mgmt_suite == WPA_KEY_MGMT_FT_IEEE8021X ||
4909 	    params->key_mgmt_suite == WPA_KEY_MGMT_FT_PSK ||
4910 	    params->key_mgmt_suite == WPA_KEY_MGMT_CCKM ||
4911 	    params->key_mgmt_suite == WPA_KEY_MGMT_OSEN ||
4912 	    params->key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SHA256 ||
4913 	    params->key_mgmt_suite == WPA_KEY_MGMT_PSK_SHA256 ||
4914 	    params->key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SUITE_B ||
4915 	    params->key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_SUITE_B_192) {
4916 		int mgmt = WLAN_AKM_SUITE_PSK;
4917 
4918 		switch (params->key_mgmt_suite) {
4919 		case WPA_KEY_MGMT_CCKM:
4920 			mgmt = WLAN_AKM_SUITE_CCKM;
4921 			break;
4922 		case WPA_KEY_MGMT_IEEE8021X:
4923 			mgmt = WLAN_AKM_SUITE_8021X;
4924 			break;
4925 		case WPA_KEY_MGMT_FT_IEEE8021X:
4926 			mgmt = WLAN_AKM_SUITE_FT_8021X;
4927 			break;
4928 		case WPA_KEY_MGMT_FT_PSK:
4929 			mgmt = WLAN_AKM_SUITE_FT_PSK;
4930 			break;
4931 		case WPA_KEY_MGMT_IEEE8021X_SHA256:
4932 			mgmt = WLAN_AKM_SUITE_8021X_SHA256;
4933 			break;
4934 		case WPA_KEY_MGMT_PSK_SHA256:
4935 			mgmt = WLAN_AKM_SUITE_PSK_SHA256;
4936 			break;
4937 		case WPA_KEY_MGMT_OSEN:
4938 			mgmt = WLAN_AKM_SUITE_OSEN;
4939 			break;
4940 		case WPA_KEY_MGMT_IEEE8021X_SUITE_B:
4941 			mgmt = WLAN_AKM_SUITE_8021X_SUITE_B;
4942 			break;
4943 		case WPA_KEY_MGMT_IEEE8021X_SUITE_B_192:
4944 			mgmt = WLAN_AKM_SUITE_8021X_SUITE_B_192;
4945 			break;
4946 		case WPA_KEY_MGMT_PSK:
4947 		default:
4948 			mgmt = WLAN_AKM_SUITE_PSK;
4949 			break;
4950 		}
4951 		wpa_printf(MSG_DEBUG, "  * akm=0x%x", mgmt);
4952 		if (nla_put_u32(msg, NL80211_ATTR_AKM_SUITES, mgmt))
4953 			return -1;
4954 	}
4955 
4956 	if (nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT))
4957 		return -1;
4958 
4959 	if (params->key_mgmt_suite == WPA_KEY_MGMT_IEEE8021X_NO_WPA &&
4960 	    (params->pairwise_suite == WPA_CIPHER_NONE ||
4961 	     params->pairwise_suite == WPA_CIPHER_WEP104 ||
4962 	     params->pairwise_suite == WPA_CIPHER_WEP40) &&
4963 	    (nla_put_u16(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE, ETH_P_PAE) ||
4964 	     nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT)))
4965 		return -1;
4966 
4967 	if (params->mgmt_frame_protection == MGMT_FRAME_PROTECTION_REQUIRED &&
4968 	    nla_put_u32(msg, NL80211_ATTR_USE_MFP, NL80211_MFP_REQUIRED))
4969 		return -1;
4970 
4971 	if (params->rrm_used) {
4972 		u32 drv_rrm_flags = drv->capa.rrm_flags;
4973 		if ((!((drv_rrm_flags &
4974 			WPA_DRIVER_FLAGS_DS_PARAM_SET_IE_IN_PROBES) &&
4975 		       (drv_rrm_flags & WPA_DRIVER_FLAGS_QUIET)) &&
4976 		     !(drv_rrm_flags & WPA_DRIVER_FLAGS_SUPPORT_RRM)) ||
4977 		    nla_put_flag(msg, NL80211_ATTR_USE_RRM))
4978 			return -1;
4979 	}
4980 
4981 	if (nl80211_ht_vht_overrides(msg, params) < 0)
4982 		return -1;
4983 
4984 	if (params->p2p)
4985 		wpa_printf(MSG_DEBUG, "  * P2P group");
4986 
4987 	if (params->pbss) {
4988 		wpa_printf(MSG_DEBUG, "  * PBSS");
4989 		if (nla_put_flag(msg, NL80211_ATTR_PBSS))
4990 			return -1;
4991 	}
4992 
4993 	drv->connect_reassoc = 0;
4994 	if (params->prev_bssid) {
4995 		wpa_printf(MSG_DEBUG, "  * prev_bssid=" MACSTR,
4996 			   MAC2STR(params->prev_bssid));
4997 		if (nla_put(msg, NL80211_ATTR_PREV_BSSID, ETH_ALEN,
4998 			    params->prev_bssid))
4999 			return -1;
5000 		drv->connect_reassoc = 1;
5001 	}
5002 
5003 	return 0;
5004 }
5005 
5006 
5007 static int wpa_driver_nl80211_try_connect(
5008 	struct wpa_driver_nl80211_data *drv,
5009 	struct wpa_driver_associate_params *params)
5010 {
5011 	struct nl_msg *msg;
5012 	enum nl80211_auth_type type;
5013 	int ret;
5014 	int algs;
5015 
5016 #ifdef CONFIG_DRIVER_NL80211_QCA
5017 	if (params->req_key_mgmt_offload && params->psk &&
5018 	    (params->key_mgmt_suite == WPA_KEY_MGMT_PSK ||
5019 	     params->key_mgmt_suite == WPA_KEY_MGMT_PSK_SHA256 ||
5020 	     params->key_mgmt_suite == WPA_KEY_MGMT_FT_PSK)) {
5021 		wpa_printf(MSG_DEBUG, "nl80211: Key management set PSK");
5022 		ret = issue_key_mgmt_set_key(drv, params->psk, 32);
5023 		if (ret)
5024 			return ret;
5025 	}
5026 #endif /* CONFIG_DRIVER_NL80211_QCA */
5027 
5028 	wpa_printf(MSG_DEBUG, "nl80211: Connect (ifindex=%d)", drv->ifindex);
5029 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_CONNECT);
5030 	if (!msg)
5031 		return -1;
5032 
5033 	ret = nl80211_connect_common(drv, params, msg);
5034 	if (ret)
5035 		goto fail;
5036 
5037 	algs = 0;
5038 	if (params->auth_alg & WPA_AUTH_ALG_OPEN)
5039 		algs++;
5040 	if (params->auth_alg & WPA_AUTH_ALG_SHARED)
5041 		algs++;
5042 	if (params->auth_alg & WPA_AUTH_ALG_LEAP)
5043 		algs++;
5044 	if (algs > 1) {
5045 		wpa_printf(MSG_DEBUG, "  * Leave out Auth Type for automatic "
5046 			   "selection");
5047 		goto skip_auth_type;
5048 	}
5049 
5050 	if (params->auth_alg & WPA_AUTH_ALG_OPEN)
5051 		type = NL80211_AUTHTYPE_OPEN_SYSTEM;
5052 	else if (params->auth_alg & WPA_AUTH_ALG_SHARED)
5053 		type = NL80211_AUTHTYPE_SHARED_KEY;
5054 	else if (params->auth_alg & WPA_AUTH_ALG_LEAP)
5055 		type = NL80211_AUTHTYPE_NETWORK_EAP;
5056 	else if (params->auth_alg & WPA_AUTH_ALG_FT)
5057 		type = NL80211_AUTHTYPE_FT;
5058 	else
5059 		goto fail;
5060 
5061 	wpa_printf(MSG_DEBUG, "  * Auth Type %d", type);
5062 	if (nla_put_u32(msg, NL80211_ATTR_AUTH_TYPE, type))
5063 		goto fail;
5064 
5065 skip_auth_type:
5066 	ret = nl80211_set_conn_keys(params, msg);
5067 	if (ret)
5068 		goto fail;
5069 
5070 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5071 	msg = NULL;
5072 	if (ret) {
5073 		wpa_printf(MSG_DEBUG, "nl80211: MLME connect failed: ret=%d "
5074 			   "(%s)", ret, strerror(-ret));
5075 	} else {
5076 		wpa_printf(MSG_DEBUG,
5077 			   "nl80211: Connect request send successfully");
5078 	}
5079 
5080 fail:
5081 	nlmsg_free(msg);
5082 	return ret;
5083 
5084 }
5085 
5086 
5087 static int wpa_driver_nl80211_connect(
5088 	struct wpa_driver_nl80211_data *drv,
5089 	struct wpa_driver_associate_params *params)
5090 {
5091 	int ret;
5092 
5093 	/* Store the connection attempted bssid for future use */
5094 	if (params->bssid)
5095 		os_memcpy(drv->auth_attempt_bssid, params->bssid, ETH_ALEN);
5096 	else
5097 		os_memset(drv->auth_attempt_bssid, 0, ETH_ALEN);
5098 
5099 	ret = wpa_driver_nl80211_try_connect(drv, params);
5100 	if (ret == -EALREADY) {
5101 		/*
5102 		 * cfg80211 does not currently accept new connections if
5103 		 * we are already connected. As a workaround, force
5104 		 * disconnection and try again.
5105 		 */
5106 		wpa_printf(MSG_DEBUG, "nl80211: Explicitly "
5107 			   "disconnecting before reassociation "
5108 			   "attempt");
5109 		if (wpa_driver_nl80211_disconnect(
5110 			    drv, WLAN_REASON_PREV_AUTH_NOT_VALID))
5111 			return -1;
5112 		ret = wpa_driver_nl80211_try_connect(drv, params);
5113 	}
5114 	return ret;
5115 }
5116 
5117 
5118 static int wpa_driver_nl80211_associate(
5119 	void *priv, struct wpa_driver_associate_params *params)
5120 {
5121 	struct i802_bss *bss = priv;
5122 	struct wpa_driver_nl80211_data *drv = bss->drv;
5123 	int ret = -1;
5124 	struct nl_msg *msg;
5125 
5126 	nl80211_unmask_11b_rates(bss);
5127 
5128 	if (params->mode == IEEE80211_MODE_AP)
5129 		return wpa_driver_nl80211_ap(drv, params);
5130 
5131 	if (params->mode == IEEE80211_MODE_IBSS)
5132 		return wpa_driver_nl80211_ibss(drv, params);
5133 
5134 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_SME)) {
5135 		enum nl80211_iftype nlmode = params->p2p ?
5136 			NL80211_IFTYPE_P2P_CLIENT : NL80211_IFTYPE_STATION;
5137 
5138 		if (wpa_driver_nl80211_set_mode(priv, nlmode) < 0)
5139 			return -1;
5140 		return wpa_driver_nl80211_connect(drv, params);
5141 	}
5142 
5143 	nl80211_mark_disconnected(drv);
5144 
5145 	wpa_printf(MSG_DEBUG, "nl80211: Associate (ifindex=%d)",
5146 		   drv->ifindex);
5147 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_ASSOCIATE);
5148 	if (!msg)
5149 		return -1;
5150 
5151 	ret = nl80211_connect_common(drv, params, msg);
5152 	if (ret)
5153 		goto fail;
5154 
5155 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5156 	msg = NULL;
5157 	if (ret) {
5158 		wpa_dbg(drv->ctx, MSG_DEBUG,
5159 			"nl80211: MLME command failed (assoc): ret=%d (%s)",
5160 			ret, strerror(-ret));
5161 		nl80211_dump_scan(drv);
5162 	} else {
5163 		wpa_printf(MSG_DEBUG,
5164 			   "nl80211: Association request send successfully");
5165 	}
5166 
5167 fail:
5168 	nlmsg_free(msg);
5169 	return ret;
5170 }
5171 
5172 
5173 static int nl80211_set_mode(struct wpa_driver_nl80211_data *drv,
5174 			    int ifindex, enum nl80211_iftype mode)
5175 {
5176 	struct nl_msg *msg;
5177 	int ret = -ENOBUFS;
5178 
5179 	wpa_printf(MSG_DEBUG, "nl80211: Set mode ifindex %d iftype %d (%s)",
5180 		   ifindex, mode, nl80211_iftype_str(mode));
5181 
5182 	msg = nl80211_cmd_msg(drv->first_bss, 0, NL80211_CMD_SET_INTERFACE);
5183 	if (!msg || nla_put_u32(msg, NL80211_ATTR_IFTYPE, mode))
5184 		goto fail;
5185 
5186 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5187 	msg = NULL;
5188 	if (!ret)
5189 		return 0;
5190 fail:
5191 	nlmsg_free(msg);
5192 	wpa_printf(MSG_DEBUG, "nl80211: Failed to set interface %d to mode %d:"
5193 		   " %d (%s)", ifindex, mode, ret, strerror(-ret));
5194 	return ret;
5195 }
5196 
5197 
5198 static int wpa_driver_nl80211_set_mode_impl(
5199 		struct i802_bss *bss,
5200 		enum nl80211_iftype nlmode,
5201 		struct hostapd_freq_params *desired_freq_params)
5202 {
5203 	struct wpa_driver_nl80211_data *drv = bss->drv;
5204 	int ret = -1;
5205 	int i;
5206 	int was_ap = is_ap_interface(drv->nlmode);
5207 	int res;
5208 	int mode_switch_res;
5209 
5210 	if (TEST_FAIL())
5211 		return -1;
5212 
5213 	mode_switch_res = nl80211_set_mode(drv, drv->ifindex, nlmode);
5214 	if (mode_switch_res && nlmode == nl80211_get_ifmode(bss))
5215 		mode_switch_res = 0;
5216 
5217 	if (mode_switch_res == 0) {
5218 		drv->nlmode = nlmode;
5219 		ret = 0;
5220 		goto done;
5221 	}
5222 
5223 	if (mode_switch_res == -ENODEV)
5224 		return -1;
5225 
5226 	if (nlmode == drv->nlmode) {
5227 		wpa_printf(MSG_DEBUG, "nl80211: Interface already in "
5228 			   "requested mode - ignore error");
5229 		ret = 0;
5230 		goto done; /* Already in the requested mode */
5231 	}
5232 
5233 	/* mac80211 doesn't allow mode changes while the device is up, so
5234 	 * take the device down, try to set the mode again, and bring the
5235 	 * device back up.
5236 	 */
5237 	wpa_printf(MSG_DEBUG, "nl80211: Try mode change after setting "
5238 		   "interface down");
5239 	for (i = 0; i < 10; i++) {
5240 		res = i802_set_iface_flags(bss, 0);
5241 		if (res == -EACCES || res == -ENODEV)
5242 			break;
5243 		if (res != 0) {
5244 			wpa_printf(MSG_DEBUG, "nl80211: Failed to set "
5245 				   "interface down");
5246 			os_sleep(0, 100000);
5247 			continue;
5248 		}
5249 
5250 		/*
5251 		 * Setting the mode will fail for some drivers if the phy is
5252 		 * on a frequency that the mode is disallowed in.
5253 		 */
5254 		if (desired_freq_params) {
5255 			res = nl80211_set_channel(bss, desired_freq_params, 0);
5256 			if (res) {
5257 				wpa_printf(MSG_DEBUG,
5258 					   "nl80211: Failed to set frequency on interface");
5259 			}
5260 		}
5261 
5262 		/* Try to set the mode again while the interface is down */
5263 		mode_switch_res = nl80211_set_mode(drv, drv->ifindex, nlmode);
5264 		if (mode_switch_res == -EBUSY) {
5265 			wpa_printf(MSG_DEBUG,
5266 				   "nl80211: Delaying mode set while interface going down");
5267 			os_sleep(0, 100000);
5268 			continue;
5269 		}
5270 		ret = mode_switch_res;
5271 		break;
5272 	}
5273 
5274 	if (!ret) {
5275 		wpa_printf(MSG_DEBUG, "nl80211: Mode change succeeded while "
5276 			   "interface is down");
5277 		drv->nlmode = nlmode;
5278 		drv->ignore_if_down_event = 1;
5279 	}
5280 
5281 	/* Bring the interface back up */
5282 	res = linux_set_iface_flags(drv->global->ioctl_sock, bss->ifname, 1);
5283 	if (res != 0) {
5284 		wpa_printf(MSG_DEBUG,
5285 			   "nl80211: Failed to set interface up after switching mode");
5286 		ret = -1;
5287 	}
5288 
5289 done:
5290 	if (ret) {
5291 		wpa_printf(MSG_DEBUG, "nl80211: Interface mode change to %d "
5292 			   "from %d failed", nlmode, drv->nlmode);
5293 		return ret;
5294 	}
5295 
5296 	if (is_p2p_net_interface(nlmode)) {
5297 		wpa_printf(MSG_DEBUG,
5298 			   "nl80211: Interface %s mode change to P2P - disable 11b rates",
5299 			   bss->ifname);
5300 		nl80211_disable_11b_rates(drv, drv->ifindex, 1);
5301 	} else if (drv->disabled_11b_rates) {
5302 		wpa_printf(MSG_DEBUG,
5303 			   "nl80211: Interface %s mode changed to non-P2P - re-enable 11b rates",
5304 			   bss->ifname);
5305 		nl80211_disable_11b_rates(drv, drv->ifindex, 0);
5306 	}
5307 
5308 	if (is_ap_interface(nlmode)) {
5309 		nl80211_mgmt_unsubscribe(bss, "start AP");
5310 		/* Setup additional AP mode functionality if needed */
5311 		if (nl80211_setup_ap(bss))
5312 			return -1;
5313 	} else if (was_ap) {
5314 		/* Remove additional AP mode functionality */
5315 		nl80211_teardown_ap(bss);
5316 	} else {
5317 		nl80211_mgmt_unsubscribe(bss, "mode change");
5318 	}
5319 
5320 	if (is_mesh_interface(nlmode) &&
5321 	    nl80211_mgmt_subscribe_mesh(bss))
5322 		return -1;
5323 
5324 	if (!bss->in_deinit && !is_ap_interface(nlmode) &&
5325 	    !is_mesh_interface(nlmode) &&
5326 	    nl80211_mgmt_subscribe_non_ap(bss) < 0)
5327 		wpa_printf(MSG_DEBUG, "nl80211: Failed to register Action "
5328 			   "frame processing - ignore for now");
5329 
5330 	return 0;
5331 }
5332 
5333 
5334 int wpa_driver_nl80211_set_mode(struct i802_bss *bss,
5335 				enum nl80211_iftype nlmode)
5336 {
5337 	return wpa_driver_nl80211_set_mode_impl(bss, nlmode, NULL);
5338 }
5339 
5340 
5341 static int wpa_driver_nl80211_set_mode_ibss(struct i802_bss *bss,
5342 					    struct hostapd_freq_params *freq)
5343 {
5344 	return wpa_driver_nl80211_set_mode_impl(bss, NL80211_IFTYPE_ADHOC,
5345 						freq);
5346 }
5347 
5348 
5349 static int wpa_driver_nl80211_get_capa(void *priv,
5350 				       struct wpa_driver_capa *capa)
5351 {
5352 	struct i802_bss *bss = priv;
5353 	struct wpa_driver_nl80211_data *drv = bss->drv;
5354 
5355 	if (!drv->has_capability)
5356 		return -1;
5357 	os_memcpy(capa, &drv->capa, sizeof(*capa));
5358 	if (drv->extended_capa && drv->extended_capa_mask) {
5359 		capa->extended_capa = drv->extended_capa;
5360 		capa->extended_capa_mask = drv->extended_capa_mask;
5361 		capa->extended_capa_len = drv->extended_capa_len;
5362 	}
5363 
5364 	return 0;
5365 }
5366 
5367 
5368 static int wpa_driver_nl80211_set_operstate(void *priv, int state)
5369 {
5370 	struct i802_bss *bss = priv;
5371 	struct wpa_driver_nl80211_data *drv = bss->drv;
5372 
5373 	wpa_printf(MSG_DEBUG, "nl80211: Set %s operstate %d->%d (%s)",
5374 		   bss->ifname, drv->operstate, state,
5375 		   state ? "UP" : "DORMANT");
5376 	drv->operstate = state;
5377 	return netlink_send_oper_ifla(drv->global->netlink, drv->ifindex, -1,
5378 				      state ? IF_OPER_UP : IF_OPER_DORMANT);
5379 }
5380 
5381 
5382 static int wpa_driver_nl80211_set_supp_port(void *priv, int authorized)
5383 {
5384 	struct i802_bss *bss = priv;
5385 	struct wpa_driver_nl80211_data *drv = bss->drv;
5386 	struct nl_msg *msg;
5387 	struct nl80211_sta_flag_update upd;
5388 	int ret;
5389 
5390 	if (!drv->associated && is_zero_ether_addr(drv->bssid) && !authorized) {
5391 		wpa_printf(MSG_DEBUG, "nl80211: Skip set_supp_port(unauthorized) while not associated");
5392 		return 0;
5393 	}
5394 
5395 	wpa_printf(MSG_DEBUG, "nl80211: Set supplicant port %sauthorized for "
5396 		   MACSTR, authorized ? "" : "un", MAC2STR(drv->bssid));
5397 
5398 	os_memset(&upd, 0, sizeof(upd));
5399 	upd.mask = BIT(NL80211_STA_FLAG_AUTHORIZED);
5400 	if (authorized)
5401 		upd.set = BIT(NL80211_STA_FLAG_AUTHORIZED);
5402 
5403 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_STATION)) ||
5404 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, drv->bssid) ||
5405 	    nla_put(msg, NL80211_ATTR_STA_FLAGS2, sizeof(upd), &upd)) {
5406 		nlmsg_free(msg);
5407 		return -ENOBUFS;
5408 	}
5409 
5410 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5411 	if (!ret)
5412 		return 0;
5413 	wpa_printf(MSG_DEBUG, "nl80211: Failed to set STA flag: %d (%s)",
5414 		   ret, strerror(-ret));
5415 	return ret;
5416 }
5417 
5418 
5419 /* Set kernel driver on given frequency (MHz) */
5420 static int i802_set_freq(void *priv, struct hostapd_freq_params *freq)
5421 {
5422 	struct i802_bss *bss = priv;
5423 	return nl80211_set_channel(bss, freq, 0);
5424 }
5425 
5426 
5427 static inline int min_int(int a, int b)
5428 {
5429 	if (a < b)
5430 		return a;
5431 	return b;
5432 }
5433 
5434 
5435 static int get_key_handler(struct nl_msg *msg, void *arg)
5436 {
5437 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
5438 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
5439 
5440 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
5441 		  genlmsg_attrlen(gnlh, 0), NULL);
5442 
5443 	/*
5444 	 * TODO: validate the key index and mac address!
5445 	 * Otherwise, there's a race condition as soon as
5446 	 * the kernel starts sending key notifications.
5447 	 */
5448 
5449 	if (tb[NL80211_ATTR_KEY_SEQ])
5450 		memcpy(arg, nla_data(tb[NL80211_ATTR_KEY_SEQ]),
5451 		       min_int(nla_len(tb[NL80211_ATTR_KEY_SEQ]), 6));
5452 	return NL_SKIP;
5453 }
5454 
5455 
5456 static int i802_get_seqnum(const char *iface, void *priv, const u8 *addr,
5457 			   int idx, u8 *seq)
5458 {
5459 	struct i802_bss *bss = priv;
5460 	struct wpa_driver_nl80211_data *drv = bss->drv;
5461 	struct nl_msg *msg;
5462 
5463 	msg = nl80211_ifindex_msg(drv, if_nametoindex(iface), 0,
5464 				  NL80211_CMD_GET_KEY);
5465 	if (!msg ||
5466 	    (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
5467 	    nla_put_u8(msg, NL80211_ATTR_KEY_IDX, idx)) {
5468 		nlmsg_free(msg);
5469 		return -ENOBUFS;
5470 	}
5471 
5472 	memset(seq, 0, 6);
5473 
5474 	return send_and_recv_msgs(drv, msg, get_key_handler, seq);
5475 }
5476 
5477 
5478 static int i802_set_rts(void *priv, int rts)
5479 {
5480 	struct i802_bss *bss = priv;
5481 	struct wpa_driver_nl80211_data *drv = bss->drv;
5482 	struct nl_msg *msg;
5483 	int ret;
5484 	u32 val;
5485 
5486 	if (rts >= 2347)
5487 		val = (u32) -1;
5488 	else
5489 		val = rts;
5490 
5491 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_SET_WIPHY)) ||
5492 	    nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD, val)) {
5493 		nlmsg_free(msg);
5494 		return -ENOBUFS;
5495 	}
5496 
5497 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5498 	if (!ret)
5499 		return 0;
5500 	wpa_printf(MSG_DEBUG, "nl80211: Failed to set RTS threshold %d: "
5501 		   "%d (%s)", rts, ret, strerror(-ret));
5502 	return ret;
5503 }
5504 
5505 
5506 static int i802_set_frag(void *priv, int frag)
5507 {
5508 	struct i802_bss *bss = priv;
5509 	struct wpa_driver_nl80211_data *drv = bss->drv;
5510 	struct nl_msg *msg;
5511 	int ret;
5512 	u32 val;
5513 
5514 	if (frag >= 2346)
5515 		val = (u32) -1;
5516 	else
5517 		val = frag;
5518 
5519 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_SET_WIPHY)) ||
5520 	    nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD, val)) {
5521 		nlmsg_free(msg);
5522 		return -ENOBUFS;
5523 	}
5524 
5525 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5526 	if (!ret)
5527 		return 0;
5528 	wpa_printf(MSG_DEBUG, "nl80211: Failed to set fragmentation threshold "
5529 		   "%d: %d (%s)", frag, ret, strerror(-ret));
5530 	return ret;
5531 }
5532 
5533 
5534 static int i802_flush(void *priv)
5535 {
5536 	struct i802_bss *bss = priv;
5537 	struct nl_msg *msg;
5538 	int res;
5539 
5540 	wpa_printf(MSG_DEBUG, "nl80211: flush -> DEL_STATION %s (all)",
5541 		   bss->ifname);
5542 
5543 	/*
5544 	 * XXX: FIX! this needs to flush all VLANs too
5545 	 */
5546 	msg = nl80211_bss_msg(bss, 0, NL80211_CMD_DEL_STATION);
5547 	res = send_and_recv_msgs(bss->drv, msg, NULL, NULL);
5548 	if (res) {
5549 		wpa_printf(MSG_DEBUG, "nl80211: Station flush failed: ret=%d "
5550 			   "(%s)", res, strerror(-res));
5551 	}
5552 	return res;
5553 }
5554 
5555 
5556 static int get_sta_handler(struct nl_msg *msg, void *arg)
5557 {
5558 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
5559 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
5560 	struct hostap_sta_driver_data *data = arg;
5561 	struct nlattr *stats[NL80211_STA_INFO_MAX + 1];
5562 	static struct nla_policy stats_policy[NL80211_STA_INFO_MAX + 1] = {
5563 		[NL80211_STA_INFO_INACTIVE_TIME] = { .type = NLA_U32 },
5564 		[NL80211_STA_INFO_RX_BYTES] = { .type = NLA_U32 },
5565 		[NL80211_STA_INFO_TX_BYTES] = { .type = NLA_U32 },
5566 		[NL80211_STA_INFO_RX_PACKETS] = { .type = NLA_U32 },
5567 		[NL80211_STA_INFO_TX_PACKETS] = { .type = NLA_U32 },
5568 		[NL80211_STA_INFO_TX_FAILED] = { .type = NLA_U32 },
5569 		[NL80211_STA_INFO_RX_BYTES64] = { .type = NLA_U64 },
5570 		[NL80211_STA_INFO_TX_BYTES64] = { .type = NLA_U64 },
5571 	};
5572 
5573 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
5574 		  genlmsg_attrlen(gnlh, 0), NULL);
5575 
5576 	/*
5577 	 * TODO: validate the interface and mac address!
5578 	 * Otherwise, there's a race condition as soon as
5579 	 * the kernel starts sending station notifications.
5580 	 */
5581 
5582 	if (!tb[NL80211_ATTR_STA_INFO]) {
5583 		wpa_printf(MSG_DEBUG, "sta stats missing!");
5584 		return NL_SKIP;
5585 	}
5586 	if (nla_parse_nested(stats, NL80211_STA_INFO_MAX,
5587 			     tb[NL80211_ATTR_STA_INFO],
5588 			     stats_policy)) {
5589 		wpa_printf(MSG_DEBUG, "failed to parse nested attributes!");
5590 		return NL_SKIP;
5591 	}
5592 
5593 	if (stats[NL80211_STA_INFO_INACTIVE_TIME])
5594 		data->inactive_msec =
5595 			nla_get_u32(stats[NL80211_STA_INFO_INACTIVE_TIME]);
5596 	/* For backwards compatibility, fetch the 32-bit counters first. */
5597 	if (stats[NL80211_STA_INFO_RX_BYTES])
5598 		data->rx_bytes = nla_get_u32(stats[NL80211_STA_INFO_RX_BYTES]);
5599 	if (stats[NL80211_STA_INFO_TX_BYTES])
5600 		data->tx_bytes = nla_get_u32(stats[NL80211_STA_INFO_TX_BYTES]);
5601 	if (stats[NL80211_STA_INFO_RX_BYTES64] &&
5602 	    stats[NL80211_STA_INFO_TX_BYTES64]) {
5603 		/*
5604 		 * The driver supports 64-bit counters, so use them to override
5605 		 * the 32-bit values.
5606 		 */
5607 		data->rx_bytes =
5608 			nla_get_u64(stats[NL80211_STA_INFO_RX_BYTES64]);
5609 		data->tx_bytes =
5610 			nla_get_u64(stats[NL80211_STA_INFO_TX_BYTES64]);
5611 		data->bytes_64bit = 1;
5612 	}
5613 	if (stats[NL80211_STA_INFO_RX_PACKETS])
5614 		data->rx_packets =
5615 			nla_get_u32(stats[NL80211_STA_INFO_RX_PACKETS]);
5616 	if (stats[NL80211_STA_INFO_TX_PACKETS])
5617 		data->tx_packets =
5618 			nla_get_u32(stats[NL80211_STA_INFO_TX_PACKETS]);
5619 	if (stats[NL80211_STA_INFO_TX_FAILED])
5620 		data->tx_retry_failed =
5621 			nla_get_u32(stats[NL80211_STA_INFO_TX_FAILED]);
5622 
5623 	return NL_SKIP;
5624 }
5625 
5626 static int i802_read_sta_data(struct i802_bss *bss,
5627 			      struct hostap_sta_driver_data *data,
5628 			      const u8 *addr)
5629 {
5630 	struct nl_msg *msg;
5631 
5632 	os_memset(data, 0, sizeof(*data));
5633 
5634 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_GET_STATION)) ||
5635 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) {
5636 		nlmsg_free(msg);
5637 		return -ENOBUFS;
5638 	}
5639 
5640 	return send_and_recv_msgs(bss->drv, msg, get_sta_handler, data);
5641 }
5642 
5643 
5644 static int i802_set_tx_queue_params(void *priv, int queue, int aifs,
5645 				    int cw_min, int cw_max, int burst_time)
5646 {
5647 	struct i802_bss *bss = priv;
5648 	struct wpa_driver_nl80211_data *drv = bss->drv;
5649 	struct nl_msg *msg;
5650 	struct nlattr *txq, *params;
5651 
5652 	msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_WIPHY);
5653 	if (!msg)
5654 		return -1;
5655 
5656 	txq = nla_nest_start(msg, NL80211_ATTR_WIPHY_TXQ_PARAMS);
5657 	if (!txq)
5658 		goto fail;
5659 
5660 	/* We are only sending parameters for a single TXQ at a time */
5661 	params = nla_nest_start(msg, 1);
5662 	if (!params)
5663 		goto fail;
5664 
5665 	switch (queue) {
5666 	case 0:
5667 		if (nla_put_u8(msg, NL80211_TXQ_ATTR_QUEUE, NL80211_TXQ_Q_VO))
5668 			goto fail;
5669 		break;
5670 	case 1:
5671 		if (nla_put_u8(msg, NL80211_TXQ_ATTR_QUEUE, NL80211_TXQ_Q_VI))
5672 			goto fail;
5673 		break;
5674 	case 2:
5675 		if (nla_put_u8(msg, NL80211_TXQ_ATTR_QUEUE, NL80211_TXQ_Q_BE))
5676 			goto fail;
5677 		break;
5678 	case 3:
5679 		if (nla_put_u8(msg, NL80211_TXQ_ATTR_QUEUE, NL80211_TXQ_Q_BK))
5680 			goto fail;
5681 		break;
5682 	}
5683 	/* Burst time is configured in units of 0.1 msec and TXOP parameter in
5684 	 * 32 usec, so need to convert the value here. */
5685 	if (nla_put_u16(msg, NL80211_TXQ_ATTR_TXOP,
5686 			(burst_time * 100 + 16) / 32) ||
5687 	    nla_put_u16(msg, NL80211_TXQ_ATTR_CWMIN, cw_min) ||
5688 	    nla_put_u16(msg, NL80211_TXQ_ATTR_CWMAX, cw_max) ||
5689 	    nla_put_u8(msg, NL80211_TXQ_ATTR_AIFS, aifs))
5690 		goto fail;
5691 
5692 	nla_nest_end(msg, params);
5693 
5694 	nla_nest_end(msg, txq);
5695 
5696 	if (send_and_recv_msgs(drv, msg, NULL, NULL) == 0)
5697 		return 0;
5698 	msg = NULL;
5699 fail:
5700 	nlmsg_free(msg);
5701 	return -1;
5702 }
5703 
5704 
5705 static int i802_set_sta_vlan(struct i802_bss *bss, const u8 *addr,
5706 			     const char *ifname, int vlan_id)
5707 {
5708 	struct wpa_driver_nl80211_data *drv = bss->drv;
5709 	struct nl_msg *msg;
5710 	int ret;
5711 
5712 	wpa_printf(MSG_DEBUG, "nl80211: %s[%d]: set_sta_vlan(" MACSTR
5713 		   ", ifname=%s[%d], vlan_id=%d)",
5714 		   bss->ifname, if_nametoindex(bss->ifname),
5715 		   MAC2STR(addr), ifname, if_nametoindex(ifname), vlan_id);
5716 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_STATION)) ||
5717 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
5718 	    nla_put_u32(msg, NL80211_ATTR_STA_VLAN, if_nametoindex(ifname))) {
5719 		nlmsg_free(msg);
5720 		return -ENOBUFS;
5721 	}
5722 
5723 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
5724 	if (ret < 0) {
5725 		wpa_printf(MSG_ERROR, "nl80211: NL80211_ATTR_STA_VLAN (addr="
5726 			   MACSTR " ifname=%s vlan_id=%d) failed: %d (%s)",
5727 			   MAC2STR(addr), ifname, vlan_id, ret,
5728 			   strerror(-ret));
5729 	}
5730 	return ret;
5731 }
5732 
5733 
5734 static int i802_get_inact_sec(void *priv, const u8 *addr)
5735 {
5736 	struct hostap_sta_driver_data data;
5737 	int ret;
5738 
5739 	data.inactive_msec = (unsigned long) -1;
5740 	ret = i802_read_sta_data(priv, &data, addr);
5741 	if (ret == -ENOENT)
5742 		return -ENOENT;
5743 	if (ret || data.inactive_msec == (unsigned long) -1)
5744 		return -1;
5745 	return data.inactive_msec / 1000;
5746 }
5747 
5748 
5749 static int i802_sta_clear_stats(void *priv, const u8 *addr)
5750 {
5751 #if 0
5752 	/* TODO */
5753 #endif
5754 	return 0;
5755 }
5756 
5757 
5758 static int i802_sta_deauth(void *priv, const u8 *own_addr, const u8 *addr,
5759 			   int reason)
5760 {
5761 	struct i802_bss *bss = priv;
5762 	struct wpa_driver_nl80211_data *drv = bss->drv;
5763 	struct ieee80211_mgmt mgmt;
5764 
5765 	if (is_mesh_interface(drv->nlmode))
5766 		return -1;
5767 
5768 	if (drv->device_ap_sme)
5769 		return wpa_driver_nl80211_sta_remove(bss, addr, 1, reason);
5770 
5771 	memset(&mgmt, 0, sizeof(mgmt));
5772 	mgmt.frame_control = IEEE80211_FC(WLAN_FC_TYPE_MGMT,
5773 					  WLAN_FC_STYPE_DEAUTH);
5774 	memcpy(mgmt.da, addr, ETH_ALEN);
5775 	memcpy(mgmt.sa, own_addr, ETH_ALEN);
5776 	memcpy(mgmt.bssid, own_addr, ETH_ALEN);
5777 	mgmt.u.deauth.reason_code = host_to_le16(reason);
5778 	return wpa_driver_nl80211_send_mlme(bss, (u8 *) &mgmt,
5779 					    IEEE80211_HDRLEN +
5780 					    sizeof(mgmt.u.deauth), 0, 0, 0, 0,
5781 					    0, NULL, 0);
5782 }
5783 
5784 
5785 static int i802_sta_disassoc(void *priv, const u8 *own_addr, const u8 *addr,
5786 			     int reason)
5787 {
5788 	struct i802_bss *bss = priv;
5789 	struct wpa_driver_nl80211_data *drv = bss->drv;
5790 	struct ieee80211_mgmt mgmt;
5791 
5792 	if (is_mesh_interface(drv->nlmode))
5793 		return -1;
5794 
5795 	if (drv->device_ap_sme)
5796 		return wpa_driver_nl80211_sta_remove(bss, addr, 0, reason);
5797 
5798 	memset(&mgmt, 0, sizeof(mgmt));
5799 	mgmt.frame_control = IEEE80211_FC(WLAN_FC_TYPE_MGMT,
5800 					  WLAN_FC_STYPE_DISASSOC);
5801 	memcpy(mgmt.da, addr, ETH_ALEN);
5802 	memcpy(mgmt.sa, own_addr, ETH_ALEN);
5803 	memcpy(mgmt.bssid, own_addr, ETH_ALEN);
5804 	mgmt.u.disassoc.reason_code = host_to_le16(reason);
5805 	return wpa_driver_nl80211_send_mlme(bss, (u8 *) &mgmt,
5806 					    IEEE80211_HDRLEN +
5807 					    sizeof(mgmt.u.disassoc), 0, 0, 0, 0,
5808 					    0, NULL, 0);
5809 }
5810 
5811 
5812 static void dump_ifidx(struct wpa_driver_nl80211_data *drv)
5813 {
5814 	char buf[200], *pos, *end;
5815 	int i, res;
5816 
5817 	pos = buf;
5818 	end = pos + sizeof(buf);
5819 
5820 	for (i = 0; i < drv->num_if_indices; i++) {
5821 		if (!drv->if_indices[i])
5822 			continue;
5823 		res = os_snprintf(pos, end - pos, " %d(%d)",
5824 				  drv->if_indices[i],
5825 				  drv->if_indices_reason[i]);
5826 		if (os_snprintf_error(end - pos, res))
5827 			break;
5828 		pos += res;
5829 	}
5830 	*pos = '\0';
5831 
5832 	wpa_printf(MSG_DEBUG, "nl80211: if_indices[%d]:%s",
5833 		   drv->num_if_indices, buf);
5834 }
5835 
5836 
5837 static void add_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx,
5838 		      int ifidx_reason)
5839 {
5840 	int i;
5841 	int *old, *old_reason;
5842 
5843 	wpa_printf(MSG_DEBUG,
5844 		   "nl80211: Add own interface ifindex %d (ifidx_reason %d)",
5845 		   ifidx, ifidx_reason);
5846 	if (have_ifidx(drv, ifidx, ifidx_reason)) {
5847 		wpa_printf(MSG_DEBUG, "nl80211: ifindex %d already in the list",
5848 			   ifidx);
5849 		return;
5850 	}
5851 	for (i = 0; i < drv->num_if_indices; i++) {
5852 		if (drv->if_indices[i] == 0) {
5853 			drv->if_indices[i] = ifidx;
5854 			drv->if_indices_reason[i] = ifidx_reason;
5855 			dump_ifidx(drv);
5856 			return;
5857 		}
5858 	}
5859 
5860 	if (drv->if_indices != drv->default_if_indices)
5861 		old = drv->if_indices;
5862 	else
5863 		old = NULL;
5864 
5865 	if (drv->if_indices_reason != drv->default_if_indices_reason)
5866 		old_reason = drv->if_indices_reason;
5867 	else
5868 		old_reason = NULL;
5869 
5870 	drv->if_indices = os_realloc_array(old, drv->num_if_indices + 1,
5871 					   sizeof(int));
5872 	drv->if_indices_reason = os_realloc_array(old_reason,
5873 						  drv->num_if_indices + 1,
5874 						  sizeof(int));
5875 	if (!drv->if_indices) {
5876 		if (!old)
5877 			drv->if_indices = drv->default_if_indices;
5878 		else
5879 			drv->if_indices = old;
5880 	}
5881 	if (!drv->if_indices_reason) {
5882 		if (!old_reason)
5883 			drv->if_indices_reason = drv->default_if_indices_reason;
5884 		else
5885 			drv->if_indices_reason = old_reason;
5886 	}
5887 	if (!drv->if_indices || !drv->if_indices_reason) {
5888 		wpa_printf(MSG_ERROR, "Failed to reallocate memory for "
5889 			   "interfaces");
5890 		wpa_printf(MSG_ERROR, "Ignoring EAPOL on interface %d", ifidx);
5891 		return;
5892 	}
5893 	if (!old)
5894 		os_memcpy(drv->if_indices, drv->default_if_indices,
5895 			  sizeof(drv->default_if_indices));
5896 	if (!old_reason)
5897 		os_memcpy(drv->if_indices_reason,
5898 			  drv->default_if_indices_reason,
5899 			  sizeof(drv->default_if_indices_reason));
5900 	drv->if_indices[drv->num_if_indices] = ifidx;
5901 	drv->if_indices_reason[drv->num_if_indices] = ifidx_reason;
5902 	drv->num_if_indices++;
5903 	dump_ifidx(drv);
5904 }
5905 
5906 
5907 static void del_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx,
5908 		      int ifidx_reason)
5909 {
5910 	int i;
5911 
5912 	for (i = 0; i < drv->num_if_indices; i++) {
5913 		if ((drv->if_indices[i] == ifidx || ifidx == IFIDX_ANY) &&
5914 		    (drv->if_indices_reason[i] == ifidx_reason ||
5915 		     ifidx_reason == IFIDX_ANY)) {
5916 			drv->if_indices[i] = 0;
5917 			break;
5918 		}
5919 	}
5920 	dump_ifidx(drv);
5921 }
5922 
5923 
5924 static int have_ifidx(struct wpa_driver_nl80211_data *drv, int ifidx,
5925 		      int ifidx_reason)
5926 {
5927 	int i;
5928 
5929 	for (i = 0; i < drv->num_if_indices; i++)
5930 		if (drv->if_indices[i] == ifidx &&
5931 		    (drv->if_indices_reason[i] == ifidx_reason ||
5932 		     ifidx_reason == IFIDX_ANY))
5933 			return 1;
5934 
5935 	return 0;
5936 }
5937 
5938 
5939 static int i802_set_wds_sta(void *priv, const u8 *addr, int aid, int val,
5940 			    const char *bridge_ifname, char *ifname_wds)
5941 {
5942 	struct i802_bss *bss = priv;
5943 	struct wpa_driver_nl80211_data *drv = bss->drv;
5944 	char name[IFNAMSIZ + 1];
5945 
5946 	os_snprintf(name, sizeof(name), "%s.sta%d", bss->ifname, aid);
5947 	if (ifname_wds)
5948 		os_strlcpy(ifname_wds, name, IFNAMSIZ + 1);
5949 
5950 	wpa_printf(MSG_DEBUG, "nl80211: Set WDS STA addr=" MACSTR
5951 		   " aid=%d val=%d name=%s", MAC2STR(addr), aid, val, name);
5952 	if (val) {
5953 		if (!if_nametoindex(name)) {
5954 			if (nl80211_create_iface(drv, name,
5955 						 NL80211_IFTYPE_AP_VLAN,
5956 						 bss->addr, 1, NULL, NULL, 0) <
5957 			    0)
5958 				return -1;
5959 			if (bridge_ifname &&
5960 			    linux_br_add_if(drv->global->ioctl_sock,
5961 					    bridge_ifname, name) < 0)
5962 				return -1;
5963 		}
5964 		if (linux_set_iface_flags(drv->global->ioctl_sock, name, 1)) {
5965 			wpa_printf(MSG_ERROR, "nl80211: Failed to set WDS STA "
5966 				   "interface %s up", name);
5967 		}
5968 		return i802_set_sta_vlan(priv, addr, name, 0);
5969 	} else {
5970 		if (bridge_ifname)
5971 			linux_br_del_if(drv->global->ioctl_sock, bridge_ifname,
5972 					name);
5973 
5974 		i802_set_sta_vlan(priv, addr, bss->ifname, 0);
5975 		nl80211_remove_iface(drv, if_nametoindex(name));
5976 		return 0;
5977 	}
5978 }
5979 
5980 
5981 static void handle_eapol(int sock, void *eloop_ctx, void *sock_ctx)
5982 {
5983 	struct wpa_driver_nl80211_data *drv = eloop_ctx;
5984 	struct sockaddr_ll lladdr;
5985 	unsigned char buf[3000];
5986 	int len;
5987 	socklen_t fromlen = sizeof(lladdr);
5988 
5989 	len = recvfrom(sock, buf, sizeof(buf), 0,
5990 		       (struct sockaddr *)&lladdr, &fromlen);
5991 	if (len < 0) {
5992 		wpa_printf(MSG_ERROR, "nl80211: EAPOL recv failed: %s",
5993 			   strerror(errno));
5994 		return;
5995 	}
5996 
5997 	if (have_ifidx(drv, lladdr.sll_ifindex, IFIDX_ANY))
5998 		drv_event_eapol_rx(drv->ctx, lladdr.sll_addr, buf, len);
5999 }
6000 
6001 
6002 static int i802_check_bridge(struct wpa_driver_nl80211_data *drv,
6003 			     struct i802_bss *bss,
6004 			     const char *brname, const char *ifname)
6005 {
6006 	int br_ifindex;
6007 	char in_br[IFNAMSIZ];
6008 
6009 	os_strlcpy(bss->brname, brname, IFNAMSIZ);
6010 	br_ifindex = if_nametoindex(brname);
6011 	if (br_ifindex == 0) {
6012 		/*
6013 		 * Bridge was configured, but the bridge device does
6014 		 * not exist. Try to add it now.
6015 		 */
6016 		if (linux_br_add(drv->global->ioctl_sock, brname) < 0) {
6017 			wpa_printf(MSG_ERROR, "nl80211: Failed to add the "
6018 				   "bridge interface %s: %s",
6019 				   brname, strerror(errno));
6020 			return -1;
6021 		}
6022 		bss->added_bridge = 1;
6023 		br_ifindex = if_nametoindex(brname);
6024 		add_ifidx(drv, br_ifindex, drv->ifindex);
6025 	}
6026 	bss->br_ifindex = br_ifindex;
6027 
6028 	if (linux_br_get(in_br, ifname) == 0) {
6029 		if (os_strcmp(in_br, brname) == 0)
6030 			return 0; /* already in the bridge */
6031 
6032 		wpa_printf(MSG_DEBUG, "nl80211: Removing interface %s from "
6033 			   "bridge %s", ifname, in_br);
6034 		if (linux_br_del_if(drv->global->ioctl_sock, in_br, ifname) <
6035 		    0) {
6036 			wpa_printf(MSG_ERROR, "nl80211: Failed to "
6037 				   "remove interface %s from bridge "
6038 				   "%s: %s",
6039 				   ifname, brname, strerror(errno));
6040 			return -1;
6041 		}
6042 	}
6043 
6044 	wpa_printf(MSG_DEBUG, "nl80211: Adding interface %s into bridge %s",
6045 		   ifname, brname);
6046 	if (linux_br_add_if(drv->global->ioctl_sock, brname, ifname) < 0) {
6047 		wpa_printf(MSG_ERROR, "nl80211: Failed to add interface %s "
6048 			   "into bridge %s: %s",
6049 			   ifname, brname, strerror(errno));
6050 		return -1;
6051 	}
6052 	bss->added_if_into_bridge = 1;
6053 
6054 	return 0;
6055 }
6056 
6057 
6058 static void *i802_init(struct hostapd_data *hapd,
6059 		       struct wpa_init_params *params)
6060 {
6061 	struct wpa_driver_nl80211_data *drv;
6062 	struct i802_bss *bss;
6063 	size_t i;
6064 	char master_ifname[IFNAMSIZ];
6065 	int ifindex, br_ifindex = 0;
6066 	int br_added = 0;
6067 
6068 	bss = wpa_driver_nl80211_drv_init(hapd, params->ifname,
6069 					  params->global_priv, 1,
6070 					  params->bssid, params->driver_params);
6071 	if (bss == NULL)
6072 		return NULL;
6073 
6074 	drv = bss->drv;
6075 
6076 	if (linux_br_get(master_ifname, params->ifname) == 0) {
6077 		wpa_printf(MSG_DEBUG, "nl80211: Interface %s is in bridge %s",
6078 			   params->ifname, master_ifname);
6079 		br_ifindex = if_nametoindex(master_ifname);
6080 		os_strlcpy(bss->brname, master_ifname, IFNAMSIZ);
6081 	} else if ((params->num_bridge == 0 || !params->bridge[0]) &&
6082 		   linux_master_get(master_ifname, params->ifname) == 0) {
6083 		wpa_printf(MSG_DEBUG, "nl80211: Interface %s is in master %s",
6084 			params->ifname, master_ifname);
6085 		/* start listening for EAPOL on the master interface */
6086 		add_ifidx(drv, if_nametoindex(master_ifname), drv->ifindex);
6087 
6088 		/* check if master itself is under bridge */
6089 		if (linux_br_get(master_ifname, master_ifname) == 0) {
6090 			wpa_printf(MSG_DEBUG, "nl80211: which is in bridge %s",
6091 				   master_ifname);
6092 			br_ifindex = if_nametoindex(master_ifname);
6093 			os_strlcpy(bss->brname, master_ifname, IFNAMSIZ);
6094 		}
6095 	} else {
6096 		master_ifname[0] = '\0';
6097 	}
6098 
6099 	bss->br_ifindex = br_ifindex;
6100 
6101 	for (i = 0; i < params->num_bridge; i++) {
6102 		if (params->bridge[i]) {
6103 			ifindex = if_nametoindex(params->bridge[i]);
6104 			if (ifindex)
6105 				add_ifidx(drv, ifindex, drv->ifindex);
6106 			if (ifindex == br_ifindex)
6107 				br_added = 1;
6108 		}
6109 	}
6110 
6111 	/* start listening for EAPOL on the default AP interface */
6112 	add_ifidx(drv, drv->ifindex, IFIDX_ANY);
6113 
6114 	if (params->num_bridge && params->bridge[0]) {
6115 		if (i802_check_bridge(drv, bss, params->bridge[0],
6116 				      params->ifname) < 0)
6117 			goto failed;
6118 		if (os_strcmp(params->bridge[0], master_ifname) != 0)
6119 			br_added = 1;
6120 	}
6121 
6122 	if (!br_added && br_ifindex &&
6123 	    (params->num_bridge == 0 || !params->bridge[0]))
6124 		add_ifidx(drv, br_ifindex, drv->ifindex);
6125 
6126 #ifdef CONFIG_LIBNL3_ROUTE
6127 	if (bss->added_if_into_bridge) {
6128 		drv->rtnl_sk = nl_socket_alloc();
6129 		if (drv->rtnl_sk == NULL) {
6130 			wpa_printf(MSG_ERROR, "nl80211: Failed to allocate nl_sock");
6131 			goto failed;
6132 		}
6133 
6134 		if (nl_connect(drv->rtnl_sk, NETLINK_ROUTE)) {
6135 			wpa_printf(MSG_ERROR, "nl80211: Failed to connect nl_sock to NETLINK_ROUTE: %s",
6136 				   strerror(errno));
6137 			goto failed;
6138 		}
6139 	}
6140 #endif /* CONFIG_LIBNL3_ROUTE */
6141 
6142 	drv->eapol_sock = socket(PF_PACKET, SOCK_DGRAM, htons(ETH_P_PAE));
6143 	if (drv->eapol_sock < 0) {
6144 		wpa_printf(MSG_ERROR, "nl80211: socket(PF_PACKET, SOCK_DGRAM, ETH_P_PAE) failed: %s",
6145 			   strerror(errno));
6146 		goto failed;
6147 	}
6148 
6149 	if (eloop_register_read_sock(drv->eapol_sock, handle_eapol, drv, NULL))
6150 	{
6151 		wpa_printf(MSG_INFO, "nl80211: Could not register read socket for eapol");
6152 		goto failed;
6153 	}
6154 
6155 	if (linux_get_ifhwaddr(drv->global->ioctl_sock, bss->ifname,
6156 			       params->own_addr))
6157 		goto failed;
6158 	os_memcpy(drv->perm_addr, params->own_addr, ETH_ALEN);
6159 
6160 	memcpy(bss->addr, params->own_addr, ETH_ALEN);
6161 
6162 	return bss;
6163 
6164 failed:
6165 	wpa_driver_nl80211_deinit(bss);
6166 	return NULL;
6167 }
6168 
6169 
6170 static void i802_deinit(void *priv)
6171 {
6172 	struct i802_bss *bss = priv;
6173 	wpa_driver_nl80211_deinit(bss);
6174 }
6175 
6176 
6177 static enum nl80211_iftype wpa_driver_nl80211_if_type(
6178 	enum wpa_driver_if_type type)
6179 {
6180 	switch (type) {
6181 	case WPA_IF_STATION:
6182 		return NL80211_IFTYPE_STATION;
6183 	case WPA_IF_P2P_CLIENT:
6184 	case WPA_IF_P2P_GROUP:
6185 		return NL80211_IFTYPE_P2P_CLIENT;
6186 	case WPA_IF_AP_VLAN:
6187 		return NL80211_IFTYPE_AP_VLAN;
6188 	case WPA_IF_AP_BSS:
6189 		return NL80211_IFTYPE_AP;
6190 	case WPA_IF_P2P_GO:
6191 		return NL80211_IFTYPE_P2P_GO;
6192 	case WPA_IF_P2P_DEVICE:
6193 		return NL80211_IFTYPE_P2P_DEVICE;
6194 	case WPA_IF_MESH:
6195 		return NL80211_IFTYPE_MESH_POINT;
6196 	default:
6197 		return -1;
6198 	}
6199 }
6200 
6201 
6202 static int nl80211_addr_in_use(struct nl80211_global *global, const u8 *addr)
6203 {
6204 	struct wpa_driver_nl80211_data *drv;
6205 	dl_list_for_each(drv, &global->interfaces,
6206 			 struct wpa_driver_nl80211_data, list) {
6207 		if (os_memcmp(addr, drv->first_bss->addr, ETH_ALEN) == 0)
6208 			return 1;
6209 	}
6210 	return 0;
6211 }
6212 
6213 
6214 static int nl80211_vif_addr(struct wpa_driver_nl80211_data *drv, u8 *new_addr)
6215 {
6216 	unsigned int idx;
6217 
6218 	if (!drv->global)
6219 		return -1;
6220 
6221 	os_memcpy(new_addr, drv->first_bss->addr, ETH_ALEN);
6222 	for (idx = 0; idx < 64; idx++) {
6223 		new_addr[0] = drv->first_bss->addr[0] | 0x02;
6224 		new_addr[0] ^= idx << 2;
6225 		if (!nl80211_addr_in_use(drv->global, new_addr))
6226 			break;
6227 	}
6228 	if (idx == 64)
6229 		return -1;
6230 
6231 	wpa_printf(MSG_DEBUG, "nl80211: Assigned new virtual interface address "
6232 		   MACSTR, MAC2STR(new_addr));
6233 
6234 	return 0;
6235 }
6236 
6237 
6238 struct wdev_info {
6239 	u64 wdev_id;
6240 	int wdev_id_set;
6241 	u8 macaddr[ETH_ALEN];
6242 };
6243 
6244 static int nl80211_wdev_handler(struct nl_msg *msg, void *arg)
6245 {
6246 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
6247 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
6248 	struct wdev_info *wi = arg;
6249 
6250 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
6251 		  genlmsg_attrlen(gnlh, 0), NULL);
6252 	if (tb[NL80211_ATTR_WDEV]) {
6253 		wi->wdev_id = nla_get_u64(tb[NL80211_ATTR_WDEV]);
6254 		wi->wdev_id_set = 1;
6255 	}
6256 
6257 	if (tb[NL80211_ATTR_MAC])
6258 		os_memcpy(wi->macaddr, nla_data(tb[NL80211_ATTR_MAC]),
6259 			  ETH_ALEN);
6260 
6261 	return NL_SKIP;
6262 }
6263 
6264 
6265 static int wpa_driver_nl80211_if_add(void *priv, enum wpa_driver_if_type type,
6266 				     const char *ifname, const u8 *addr,
6267 				     void *bss_ctx, void **drv_priv,
6268 				     char *force_ifname, u8 *if_addr,
6269 				     const char *bridge, int use_existing,
6270 				     int setup_ap)
6271 {
6272 	enum nl80211_iftype nlmode;
6273 	struct i802_bss *bss = priv;
6274 	struct wpa_driver_nl80211_data *drv = bss->drv;
6275 	int ifidx;
6276 	int added = 1;
6277 
6278 	if (addr)
6279 		os_memcpy(if_addr, addr, ETH_ALEN);
6280 	nlmode = wpa_driver_nl80211_if_type(type);
6281 	if (nlmode == NL80211_IFTYPE_P2P_DEVICE) {
6282 		struct wdev_info p2pdev_info;
6283 
6284 		os_memset(&p2pdev_info, 0, sizeof(p2pdev_info));
6285 		ifidx = nl80211_create_iface(drv, ifname, nlmode, addr,
6286 					     0, nl80211_wdev_handler,
6287 					     &p2pdev_info, use_existing);
6288 		if (!p2pdev_info.wdev_id_set || ifidx != 0) {
6289 			wpa_printf(MSG_ERROR, "nl80211: Failed to create a P2P Device interface %s",
6290 				   ifname);
6291 			return -1;
6292 		}
6293 
6294 		drv->global->if_add_wdevid = p2pdev_info.wdev_id;
6295 		drv->global->if_add_wdevid_set = p2pdev_info.wdev_id_set;
6296 		if (!is_zero_ether_addr(p2pdev_info.macaddr))
6297 			os_memcpy(if_addr, p2pdev_info.macaddr, ETH_ALEN);
6298 		wpa_printf(MSG_DEBUG, "nl80211: New P2P Device interface %s (0x%llx) created",
6299 			   ifname,
6300 			   (long long unsigned int) p2pdev_info.wdev_id);
6301 	} else {
6302 		ifidx = nl80211_create_iface(drv, ifname, nlmode, addr,
6303 					     0, NULL, NULL, use_existing);
6304 		if (use_existing && ifidx == -ENFILE) {
6305 			added = 0;
6306 			ifidx = if_nametoindex(ifname);
6307 		} else if (ifidx < 0) {
6308 			return -1;
6309 		}
6310 	}
6311 
6312 	if (!addr) {
6313 		if (nlmode == NL80211_IFTYPE_P2P_DEVICE)
6314 			os_memcpy(if_addr, bss->addr, ETH_ALEN);
6315 		else if (linux_get_ifhwaddr(drv->global->ioctl_sock,
6316 					    ifname, if_addr) < 0) {
6317 			if (added)
6318 				nl80211_remove_iface(drv, ifidx);
6319 			return -1;
6320 		}
6321 	}
6322 
6323 	if (!addr &&
6324 	    (type == WPA_IF_P2P_CLIENT || type == WPA_IF_P2P_GROUP ||
6325 	     type == WPA_IF_P2P_GO || type == WPA_IF_MESH ||
6326 	     type == WPA_IF_STATION)) {
6327 		/* Enforce unique address */
6328 		u8 new_addr[ETH_ALEN];
6329 
6330 		if (linux_get_ifhwaddr(drv->global->ioctl_sock, ifname,
6331 				       new_addr) < 0) {
6332 			if (added)
6333 				nl80211_remove_iface(drv, ifidx);
6334 			return -1;
6335 		}
6336 		if (nl80211_addr_in_use(drv->global, new_addr)) {
6337 			wpa_printf(MSG_DEBUG, "nl80211: Allocate new address "
6338 				   "for interface %s type %d", ifname, type);
6339 			if (nl80211_vif_addr(drv, new_addr) < 0) {
6340 				if (added)
6341 					nl80211_remove_iface(drv, ifidx);
6342 				return -1;
6343 			}
6344 			if (linux_set_ifhwaddr(drv->global->ioctl_sock, ifname,
6345 					       new_addr) < 0) {
6346 				if (added)
6347 					nl80211_remove_iface(drv, ifidx);
6348 				return -1;
6349 			}
6350 		}
6351 		os_memcpy(if_addr, new_addr, ETH_ALEN);
6352 	}
6353 
6354 	if (type == WPA_IF_AP_BSS && setup_ap) {
6355 		struct i802_bss *new_bss = os_zalloc(sizeof(*new_bss));
6356 		if (new_bss == NULL) {
6357 			if (added)
6358 				nl80211_remove_iface(drv, ifidx);
6359 			return -1;
6360 		}
6361 
6362 		if (bridge &&
6363 		    i802_check_bridge(drv, new_bss, bridge, ifname) < 0) {
6364 			wpa_printf(MSG_ERROR, "nl80211: Failed to add the new "
6365 				   "interface %s to a bridge %s",
6366 				   ifname, bridge);
6367 			if (added)
6368 				nl80211_remove_iface(drv, ifidx);
6369 			os_free(new_bss);
6370 			return -1;
6371 		}
6372 
6373 		if (linux_set_iface_flags(drv->global->ioctl_sock, ifname, 1))
6374 		{
6375 			if (added)
6376 				nl80211_remove_iface(drv, ifidx);
6377 			os_free(new_bss);
6378 			return -1;
6379 		}
6380 		os_strlcpy(new_bss->ifname, ifname, IFNAMSIZ);
6381 		os_memcpy(new_bss->addr, if_addr, ETH_ALEN);
6382 		new_bss->ifindex = ifidx;
6383 		new_bss->drv = drv;
6384 		new_bss->next = drv->first_bss->next;
6385 		new_bss->freq = drv->first_bss->freq;
6386 		new_bss->ctx = bss_ctx;
6387 		new_bss->added_if = added;
6388 		drv->first_bss->next = new_bss;
6389 		if (drv_priv)
6390 			*drv_priv = new_bss;
6391 		nl80211_init_bss(new_bss);
6392 
6393 		/* Subscribe management frames for this WPA_IF_AP_BSS */
6394 		if (nl80211_setup_ap(new_bss))
6395 			return -1;
6396 	}
6397 
6398 	if (drv->global)
6399 		drv->global->if_add_ifindex = ifidx;
6400 
6401 	/*
6402 	 * Some virtual interfaces need to process EAPOL packets and events on
6403 	 * the parent interface. This is used mainly with hostapd.
6404 	 */
6405 	if (ifidx > 0 &&
6406 	    (drv->hostapd ||
6407 	     nlmode == NL80211_IFTYPE_AP_VLAN ||
6408 	     nlmode == NL80211_IFTYPE_WDS ||
6409 	     nlmode == NL80211_IFTYPE_MONITOR))
6410 		add_ifidx(drv, ifidx, IFIDX_ANY);
6411 
6412 	return 0;
6413 }
6414 
6415 
6416 static int wpa_driver_nl80211_if_remove(struct i802_bss *bss,
6417 					enum wpa_driver_if_type type,
6418 					const char *ifname)
6419 {
6420 	struct wpa_driver_nl80211_data *drv = bss->drv;
6421 	int ifindex = if_nametoindex(ifname);
6422 
6423 	wpa_printf(MSG_DEBUG, "nl80211: %s(type=%d ifname=%s) ifindex=%d added_if=%d",
6424 		   __func__, type, ifname, ifindex, bss->added_if);
6425 	if (ifindex > 0 && (bss->added_if || bss->ifindex != ifindex))
6426 		nl80211_remove_iface(drv, ifindex);
6427 	else if (ifindex > 0 && !bss->added_if) {
6428 		struct wpa_driver_nl80211_data *drv2;
6429 		dl_list_for_each(drv2, &drv->global->interfaces,
6430 				 struct wpa_driver_nl80211_data, list) {
6431 			del_ifidx(drv2, ifindex, IFIDX_ANY);
6432 			del_ifidx(drv2, IFIDX_ANY, ifindex);
6433 		}
6434 	}
6435 
6436 	if (type != WPA_IF_AP_BSS)
6437 		return 0;
6438 
6439 	if (bss->added_if_into_bridge) {
6440 		if (linux_br_del_if(drv->global->ioctl_sock, bss->brname,
6441 				    bss->ifname) < 0)
6442 			wpa_printf(MSG_INFO, "nl80211: Failed to remove "
6443 				   "interface %s from bridge %s: %s",
6444 				   bss->ifname, bss->brname, strerror(errno));
6445 	}
6446 	if (bss->added_bridge) {
6447 		if (linux_br_del(drv->global->ioctl_sock, bss->brname) < 0)
6448 			wpa_printf(MSG_INFO, "nl80211: Failed to remove "
6449 				   "bridge %s: %s",
6450 				   bss->brname, strerror(errno));
6451 	}
6452 
6453 	if (bss != drv->first_bss) {
6454 		struct i802_bss *tbss;
6455 
6456 		wpa_printf(MSG_DEBUG, "nl80211: Not the first BSS - remove it");
6457 		for (tbss = drv->first_bss; tbss; tbss = tbss->next) {
6458 			if (tbss->next == bss) {
6459 				tbss->next = bss->next;
6460 				/* Unsubscribe management frames */
6461 				nl80211_teardown_ap(bss);
6462 				nl80211_destroy_bss(bss);
6463 				if (!bss->added_if)
6464 					i802_set_iface_flags(bss, 0);
6465 				os_free(bss);
6466 				bss = NULL;
6467 				break;
6468 			}
6469 		}
6470 		if (bss)
6471 			wpa_printf(MSG_INFO, "nl80211: %s - could not find "
6472 				   "BSS %p in the list", __func__, bss);
6473 	} else {
6474 		wpa_printf(MSG_DEBUG, "nl80211: First BSS - reassign context");
6475 		nl80211_teardown_ap(bss);
6476 		if (!bss->added_if && !drv->first_bss->next)
6477 			wpa_driver_nl80211_del_beacon(drv);
6478 		nl80211_destroy_bss(bss);
6479 		if (!bss->added_if)
6480 			i802_set_iface_flags(bss, 0);
6481 		if (drv->first_bss->next) {
6482 			drv->first_bss = drv->first_bss->next;
6483 			drv->ctx = drv->first_bss->ctx;
6484 			os_free(bss);
6485 		} else {
6486 			wpa_printf(MSG_DEBUG, "nl80211: No second BSS to reassign context to");
6487 		}
6488 	}
6489 
6490 	return 0;
6491 }
6492 
6493 
6494 static int cookie_handler(struct nl_msg *msg, void *arg)
6495 {
6496 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
6497 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
6498 	u64 *cookie = arg;
6499 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
6500 		  genlmsg_attrlen(gnlh, 0), NULL);
6501 	if (tb[NL80211_ATTR_COOKIE])
6502 		*cookie = nla_get_u64(tb[NL80211_ATTR_COOKIE]);
6503 	return NL_SKIP;
6504 }
6505 
6506 
6507 static int nl80211_send_frame_cmd(struct i802_bss *bss,
6508 				  unsigned int freq, unsigned int wait,
6509 				  const u8 *buf, size_t buf_len,
6510 				  u64 *cookie_out, int no_cck, int no_ack,
6511 				  int offchanok, const u16 *csa_offs,
6512 				  size_t csa_offs_len)
6513 {
6514 	struct wpa_driver_nl80211_data *drv = bss->drv;
6515 	struct nl_msg *msg;
6516 	u64 cookie;
6517 	int ret = -1;
6518 
6519 	wpa_printf(MSG_MSGDUMP, "nl80211: CMD_FRAME freq=%u wait=%u no_cck=%d "
6520 		   "no_ack=%d offchanok=%d",
6521 		   freq, wait, no_cck, no_ack, offchanok);
6522 	wpa_hexdump(MSG_MSGDUMP, "CMD_FRAME", buf, buf_len);
6523 
6524 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_FRAME)) ||
6525 	    (freq && nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
6526 	    (wait && nla_put_u32(msg, NL80211_ATTR_DURATION, wait)) ||
6527 	    (offchanok && ((drv->capa.flags & WPA_DRIVER_FLAGS_OFFCHANNEL_TX) ||
6528 			   drv->test_use_roc_tx) &&
6529 	     nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK)) ||
6530 	    (no_cck && nla_put_flag(msg, NL80211_ATTR_TX_NO_CCK_RATE)) ||
6531 	    (no_ack && nla_put_flag(msg, NL80211_ATTR_DONT_WAIT_FOR_ACK)) ||
6532 	    (csa_offs && nla_put(msg, NL80211_ATTR_CSA_C_OFFSETS_TX,
6533 				 csa_offs_len * sizeof(u16), csa_offs)) ||
6534 	    nla_put(msg, NL80211_ATTR_FRAME, buf_len, buf))
6535 		goto fail;
6536 
6537 	cookie = 0;
6538 	ret = send_and_recv_msgs(drv, msg, cookie_handler, &cookie);
6539 	msg = NULL;
6540 	if (ret) {
6541 		wpa_printf(MSG_DEBUG, "nl80211: Frame command failed: ret=%d "
6542 			   "(%s) (freq=%u wait=%u)", ret, strerror(-ret),
6543 			   freq, wait);
6544 	} else {
6545 		wpa_printf(MSG_MSGDUMP, "nl80211: Frame TX command accepted%s; "
6546 			   "cookie 0x%llx", no_ack ? " (no ACK)" : "",
6547 			   (long long unsigned int) cookie);
6548 
6549 		if (cookie_out)
6550 			*cookie_out = no_ack ? (u64) -1 : cookie;
6551 
6552 		if (drv->num_send_action_cookies == MAX_SEND_ACTION_COOKIES) {
6553 			wpa_printf(MSG_DEBUG,
6554 				   "nl80211: Drop oldest pending send action cookie 0x%llx",
6555 				   (long long unsigned int)
6556 				   drv->send_action_cookies[0]);
6557 			os_memmove(&drv->send_action_cookies[0],
6558 				   &drv->send_action_cookies[1],
6559 				   (MAX_SEND_ACTION_COOKIES - 1) *
6560 				   sizeof(u64));
6561 			drv->num_send_action_cookies--;
6562 		}
6563 		drv->send_action_cookies[drv->num_send_action_cookies] = cookie;
6564 		drv->num_send_action_cookies++;
6565 	}
6566 
6567 fail:
6568 	nlmsg_free(msg);
6569 	return ret;
6570 }
6571 
6572 
6573 static int wpa_driver_nl80211_send_action(struct i802_bss *bss,
6574 					  unsigned int freq,
6575 					  unsigned int wait_time,
6576 					  const u8 *dst, const u8 *src,
6577 					  const u8 *bssid,
6578 					  const u8 *data, size_t data_len,
6579 					  int no_cck)
6580 {
6581 	struct wpa_driver_nl80211_data *drv = bss->drv;
6582 	int ret = -1;
6583 	u8 *buf;
6584 	struct ieee80211_hdr *hdr;
6585 
6586 	wpa_printf(MSG_DEBUG, "nl80211: Send Action frame (ifindex=%d, "
6587 		   "freq=%u MHz wait=%d ms no_cck=%d)",
6588 		   drv->ifindex, freq, wait_time, no_cck);
6589 
6590 	buf = os_zalloc(24 + data_len);
6591 	if (buf == NULL)
6592 		return ret;
6593 	os_memcpy(buf + 24, data, data_len);
6594 	hdr = (struct ieee80211_hdr *) buf;
6595 	hdr->frame_control =
6596 		IEEE80211_FC(WLAN_FC_TYPE_MGMT, WLAN_FC_STYPE_ACTION);
6597 	os_memcpy(hdr->addr1, dst, ETH_ALEN);
6598 	os_memcpy(hdr->addr2, src, ETH_ALEN);
6599 	os_memcpy(hdr->addr3, bssid, ETH_ALEN);
6600 
6601 	if (is_ap_interface(drv->nlmode) &&
6602 	    (!(drv->capa.flags & WPA_DRIVER_FLAGS_OFFCHANNEL_TX) ||
6603 	     (int) freq == bss->freq || drv->device_ap_sme ||
6604 	     !drv->use_monitor))
6605 		ret = wpa_driver_nl80211_send_mlme(bss, buf, 24 + data_len,
6606 						   0, freq, no_cck, 1,
6607 						   wait_time, NULL, 0);
6608 	else
6609 		ret = nl80211_send_frame_cmd(bss, freq, wait_time, buf,
6610 					     24 + data_len,
6611 					     &drv->send_action_cookie,
6612 					     no_cck, 0, 1, NULL, 0);
6613 
6614 	os_free(buf);
6615 	return ret;
6616 }
6617 
6618 
6619 static void nl80211_frame_wait_cancel(struct i802_bss *bss, u64 cookie)
6620 {
6621 	struct wpa_driver_nl80211_data *drv = bss->drv;
6622 	struct nl_msg *msg;
6623 	int ret;
6624 
6625 	wpa_printf(MSG_DEBUG, "nl80211: Cancel TX frame wait: cookie=0x%llx",
6626 		   (long long unsigned int) cookie);
6627 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_FRAME_WAIT_CANCEL)) ||
6628 	    nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie)) {
6629 		nlmsg_free(msg);
6630 		return;
6631 	}
6632 
6633 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
6634 	if (ret)
6635 		wpa_printf(MSG_DEBUG, "nl80211: wait cancel failed: ret=%d "
6636 			   "(%s)", ret, strerror(-ret));
6637 }
6638 
6639 
6640 static void wpa_driver_nl80211_send_action_cancel_wait(void *priv)
6641 {
6642 	struct i802_bss *bss = priv;
6643 	struct wpa_driver_nl80211_data *drv = bss->drv;
6644 	unsigned int i;
6645 	u64 cookie;
6646 
6647 	/* Cancel the last pending TX cookie */
6648 	nl80211_frame_wait_cancel(bss, drv->send_action_cookie);
6649 
6650 	/*
6651 	 * Cancel the other pending TX cookies, if any. This is needed since
6652 	 * the driver may keep a list of all pending offchannel TX operations
6653 	 * and free up the radio only once they have expired or cancelled.
6654 	 */
6655 	for (i = drv->num_send_action_cookies; i > 0; i--) {
6656 		cookie = drv->send_action_cookies[i - 1];
6657 		if (cookie != drv->send_action_cookie)
6658 			nl80211_frame_wait_cancel(bss, cookie);
6659 	}
6660 	drv->num_send_action_cookies = 0;
6661 }
6662 
6663 
6664 static int wpa_driver_nl80211_remain_on_channel(void *priv, unsigned int freq,
6665 						unsigned int duration)
6666 {
6667 	struct i802_bss *bss = priv;
6668 	struct wpa_driver_nl80211_data *drv = bss->drv;
6669 	struct nl_msg *msg;
6670 	int ret;
6671 	u64 cookie;
6672 
6673 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_REMAIN_ON_CHANNEL)) ||
6674 	    nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
6675 	    nla_put_u32(msg, NL80211_ATTR_DURATION, duration)) {
6676 		nlmsg_free(msg);
6677 		return -1;
6678 	}
6679 
6680 	cookie = 0;
6681 	ret = send_and_recv_msgs(drv, msg, cookie_handler, &cookie);
6682 	if (ret == 0) {
6683 		wpa_printf(MSG_DEBUG, "nl80211: Remain-on-channel cookie "
6684 			   "0x%llx for freq=%u MHz duration=%u",
6685 			   (long long unsigned int) cookie, freq, duration);
6686 		drv->remain_on_chan_cookie = cookie;
6687 		drv->pending_remain_on_chan = 1;
6688 		return 0;
6689 	}
6690 	wpa_printf(MSG_DEBUG, "nl80211: Failed to request remain-on-channel "
6691 		   "(freq=%d duration=%u): %d (%s)",
6692 		   freq, duration, ret, strerror(-ret));
6693 	return -1;
6694 }
6695 
6696 
6697 static int wpa_driver_nl80211_cancel_remain_on_channel(void *priv)
6698 {
6699 	struct i802_bss *bss = priv;
6700 	struct wpa_driver_nl80211_data *drv = bss->drv;
6701 	struct nl_msg *msg;
6702 	int ret;
6703 
6704 	if (!drv->pending_remain_on_chan) {
6705 		wpa_printf(MSG_DEBUG, "nl80211: No pending remain-on-channel "
6706 			   "to cancel");
6707 		return -1;
6708 	}
6709 
6710 	wpa_printf(MSG_DEBUG, "nl80211: Cancel remain-on-channel with cookie "
6711 		   "0x%llx",
6712 		   (long long unsigned int) drv->remain_on_chan_cookie);
6713 
6714 	msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL);
6715 	if (!msg ||
6716 	    nla_put_u64(msg, NL80211_ATTR_COOKIE, drv->remain_on_chan_cookie)) {
6717 		nlmsg_free(msg);
6718 		return -1;
6719 	}
6720 
6721 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
6722 	if (ret == 0)
6723 		return 0;
6724 	wpa_printf(MSG_DEBUG, "nl80211: Failed to cancel remain-on-channel: "
6725 		   "%d (%s)", ret, strerror(-ret));
6726 	return -1;
6727 }
6728 
6729 
6730 static int wpa_driver_nl80211_probe_req_report(struct i802_bss *bss, int report)
6731 {
6732 	struct wpa_driver_nl80211_data *drv = bss->drv;
6733 
6734 	if (!report) {
6735 		if (bss->nl_preq && drv->device_ap_sme &&
6736 		    is_ap_interface(drv->nlmode) && !bss->in_deinit &&
6737 		    !bss->static_ap) {
6738 			/*
6739 			 * Do not disable Probe Request reporting that was
6740 			 * enabled in nl80211_setup_ap().
6741 			 */
6742 			wpa_printf(MSG_DEBUG, "nl80211: Skip disabling of "
6743 				   "Probe Request reporting nl_preq=%p while "
6744 				   "in AP mode", bss->nl_preq);
6745 		} else if (bss->nl_preq) {
6746 			wpa_printf(MSG_DEBUG, "nl80211: Disable Probe Request "
6747 				   "reporting nl_preq=%p", bss->nl_preq);
6748 			nl80211_destroy_eloop_handle(&bss->nl_preq);
6749 		}
6750 		return 0;
6751 	}
6752 
6753 	if (bss->nl_preq) {
6754 		wpa_printf(MSG_DEBUG, "nl80211: Probe Request reporting "
6755 			   "already on! nl_preq=%p", bss->nl_preq);
6756 		return 0;
6757 	}
6758 
6759 	bss->nl_preq = nl_create_handle(drv->global->nl_cb, "preq");
6760 	if (bss->nl_preq == NULL)
6761 		return -1;
6762 	wpa_printf(MSG_DEBUG, "nl80211: Enable Probe Request "
6763 		   "reporting nl_preq=%p", bss->nl_preq);
6764 
6765 	if (nl80211_register_frame(bss, bss->nl_preq,
6766 				   (WLAN_FC_TYPE_MGMT << 2) |
6767 				   (WLAN_FC_STYPE_PROBE_REQ << 4),
6768 				   NULL, 0) < 0)
6769 		goto out_err;
6770 
6771 	nl80211_register_eloop_read(&bss->nl_preq,
6772 				    wpa_driver_nl80211_event_receive,
6773 				    bss->nl_cb);
6774 
6775 	return 0;
6776 
6777  out_err:
6778 	nl_destroy_handles(&bss->nl_preq);
6779 	return -1;
6780 }
6781 
6782 
6783 static int nl80211_disable_11b_rates(struct wpa_driver_nl80211_data *drv,
6784 				     int ifindex, int disabled)
6785 {
6786 	struct nl_msg *msg;
6787 	struct nlattr *bands, *band;
6788 	int ret;
6789 
6790 	wpa_printf(MSG_DEBUG,
6791 		   "nl80211: NL80211_CMD_SET_TX_BITRATE_MASK (ifindex=%d %s)",
6792 		   ifindex, disabled ? "NL80211_TXRATE_LEGACY=OFDM-only" :
6793 		   "no NL80211_TXRATE_LEGACY constraint");
6794 
6795 	msg = nl80211_ifindex_msg(drv, ifindex, 0,
6796 				  NL80211_CMD_SET_TX_BITRATE_MASK);
6797 	if (!msg)
6798 		return -1;
6799 
6800 	bands = nla_nest_start(msg, NL80211_ATTR_TX_RATES);
6801 	if (!bands)
6802 		goto fail;
6803 
6804 	/*
6805 	 * Disable 2 GHz rates 1, 2, 5.5, 11 Mbps by masking out everything
6806 	 * else apart from 6, 9, 12, 18, 24, 36, 48, 54 Mbps from non-MCS
6807 	 * rates. All 5 GHz rates are left enabled.
6808 	 */
6809 	band = nla_nest_start(msg, NL80211_BAND_2GHZ);
6810 	if (!band ||
6811 	    (disabled && nla_put(msg, NL80211_TXRATE_LEGACY, 8,
6812 				 "\x0c\x12\x18\x24\x30\x48\x60\x6c")))
6813 		goto fail;
6814 	nla_nest_end(msg, band);
6815 
6816 	nla_nest_end(msg, bands);
6817 
6818 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
6819 	if (ret) {
6820 		wpa_printf(MSG_DEBUG, "nl80211: Set TX rates failed: ret=%d "
6821 			   "(%s)", ret, strerror(-ret));
6822 	} else
6823 		drv->disabled_11b_rates = disabled;
6824 
6825 	return ret;
6826 
6827 fail:
6828 	nlmsg_free(msg);
6829 	return -1;
6830 }
6831 
6832 
6833 static int wpa_driver_nl80211_deinit_ap(void *priv)
6834 {
6835 	struct i802_bss *bss = priv;
6836 	struct wpa_driver_nl80211_data *drv = bss->drv;
6837 	if (!is_ap_interface(drv->nlmode))
6838 		return -1;
6839 	wpa_driver_nl80211_del_beacon(drv);
6840 	bss->beacon_set = 0;
6841 
6842 	/*
6843 	 * If the P2P GO interface was dynamically added, then it is
6844 	 * possible that the interface change to station is not possible.
6845 	 */
6846 	if (drv->nlmode == NL80211_IFTYPE_P2P_GO && bss->if_dynamic)
6847 		return 0;
6848 
6849 	return wpa_driver_nl80211_set_mode(priv, NL80211_IFTYPE_STATION);
6850 }
6851 
6852 
6853 static int wpa_driver_nl80211_stop_ap(void *priv)
6854 {
6855 	struct i802_bss *bss = priv;
6856 	struct wpa_driver_nl80211_data *drv = bss->drv;
6857 	if (!is_ap_interface(drv->nlmode))
6858 		return -1;
6859 	wpa_driver_nl80211_del_beacon(drv);
6860 	bss->beacon_set = 0;
6861 	return 0;
6862 }
6863 
6864 
6865 static int wpa_driver_nl80211_deinit_p2p_cli(void *priv)
6866 {
6867 	struct i802_bss *bss = priv;
6868 	struct wpa_driver_nl80211_data *drv = bss->drv;
6869 	if (drv->nlmode != NL80211_IFTYPE_P2P_CLIENT)
6870 		return -1;
6871 
6872 	/*
6873 	 * If the P2P Client interface was dynamically added, then it is
6874 	 * possible that the interface change to station is not possible.
6875 	 */
6876 	if (bss->if_dynamic)
6877 		return 0;
6878 
6879 	return wpa_driver_nl80211_set_mode(priv, NL80211_IFTYPE_STATION);
6880 }
6881 
6882 
6883 static void wpa_driver_nl80211_resume(void *priv)
6884 {
6885 	struct i802_bss *bss = priv;
6886 	enum nl80211_iftype nlmode = nl80211_get_ifmode(bss);
6887 
6888 	if (i802_set_iface_flags(bss, 1))
6889 		wpa_printf(MSG_DEBUG, "nl80211: Failed to set interface up on resume event");
6890 
6891 	if (is_p2p_net_interface(nlmode))
6892 		nl80211_disable_11b_rates(bss->drv, bss->drv->ifindex, 1);
6893 }
6894 
6895 
6896 static int nl80211_signal_monitor(void *priv, int threshold, int hysteresis)
6897 {
6898 	struct i802_bss *bss = priv;
6899 	struct wpa_driver_nl80211_data *drv = bss->drv;
6900 	struct nl_msg *msg;
6901 	struct nlattr *cqm;
6902 
6903 	wpa_printf(MSG_DEBUG, "nl80211: Signal monitor threshold=%d "
6904 		   "hysteresis=%d", threshold, hysteresis);
6905 
6906 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_CQM)) ||
6907 	    !(cqm = nla_nest_start(msg, NL80211_ATTR_CQM)) ||
6908 	    nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THOLD, threshold) ||
6909 	    nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_HYST, hysteresis)) {
6910 		nlmsg_free(msg);
6911 		return -1;
6912 	}
6913 	nla_nest_end(msg, cqm);
6914 
6915 	return send_and_recv_msgs(drv, msg, NULL, NULL);
6916 }
6917 
6918 
6919 static int get_channel_width(struct nl_msg *msg, void *arg)
6920 {
6921 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
6922 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
6923 	struct wpa_signal_info *sig_change = arg;
6924 
6925 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
6926 		  genlmsg_attrlen(gnlh, 0), NULL);
6927 
6928 	sig_change->center_frq1 = -1;
6929 	sig_change->center_frq2 = -1;
6930 	sig_change->chanwidth = CHAN_WIDTH_UNKNOWN;
6931 
6932 	if (tb[NL80211_ATTR_CHANNEL_WIDTH]) {
6933 		sig_change->chanwidth = convert2width(
6934 			nla_get_u32(tb[NL80211_ATTR_CHANNEL_WIDTH]));
6935 		if (tb[NL80211_ATTR_CENTER_FREQ1])
6936 			sig_change->center_frq1 =
6937 				nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ1]);
6938 		if (tb[NL80211_ATTR_CENTER_FREQ2])
6939 			sig_change->center_frq2 =
6940 				nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ2]);
6941 	}
6942 
6943 	return NL_SKIP;
6944 }
6945 
6946 
6947 static int nl80211_get_channel_width(struct wpa_driver_nl80211_data *drv,
6948 				     struct wpa_signal_info *sig)
6949 {
6950 	struct nl_msg *msg;
6951 
6952 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_GET_INTERFACE);
6953 	return send_and_recv_msgs(drv, msg, get_channel_width, sig);
6954 }
6955 
6956 
6957 static int nl80211_signal_poll(void *priv, struct wpa_signal_info *si)
6958 {
6959 	struct i802_bss *bss = priv;
6960 	struct wpa_driver_nl80211_data *drv = bss->drv;
6961 	int res;
6962 
6963 	os_memset(si, 0, sizeof(*si));
6964 	res = nl80211_get_link_signal(drv, si);
6965 	if (res) {
6966 		if (drv->nlmode != NL80211_IFTYPE_ADHOC &&
6967 		    drv->nlmode != NL80211_IFTYPE_MESH_POINT)
6968 			return res;
6969 		si->current_signal = 0;
6970 	}
6971 
6972 	res = nl80211_get_channel_width(drv, si);
6973 	if (res != 0)
6974 		return res;
6975 
6976 	return nl80211_get_link_noise(drv, si);
6977 }
6978 
6979 
6980 static int nl80211_send_frame(void *priv, const u8 *data, size_t data_len,
6981 			      int encrypt)
6982 {
6983 	struct i802_bss *bss = priv;
6984 	return wpa_driver_nl80211_send_frame(bss, data, data_len, encrypt, 0,
6985 					     0, 0, 0, 0, NULL, 0);
6986 }
6987 
6988 
6989 static int nl80211_set_param(void *priv, const char *param)
6990 {
6991 	struct i802_bss *bss = priv;
6992 	struct wpa_driver_nl80211_data *drv = bss->drv;
6993 
6994 	if (param == NULL)
6995 		return 0;
6996 	wpa_printf(MSG_DEBUG, "nl80211: driver param='%s'", param);
6997 
6998 #ifdef CONFIG_P2P
6999 	if (os_strstr(param, "use_p2p_group_interface=1")) {
7000 		wpa_printf(MSG_DEBUG, "nl80211: Use separate P2P group "
7001 			   "interface");
7002 		drv->capa.flags |= WPA_DRIVER_FLAGS_P2P_CONCURRENT;
7003 		drv->capa.flags |= WPA_DRIVER_FLAGS_P2P_MGMT_AND_NON_P2P;
7004 	}
7005 #endif /* CONFIG_P2P */
7006 
7007 	if (os_strstr(param, "use_monitor=1"))
7008 		drv->use_monitor = 1;
7009 
7010 	if (os_strstr(param, "force_connect_cmd=1")) {
7011 		drv->capa.flags &= ~WPA_DRIVER_FLAGS_SME;
7012 		drv->force_connect_cmd = 1;
7013 	}
7014 
7015 	if (os_strstr(param, "force_bss_selection=1"))
7016 		drv->capa.flags |= WPA_DRIVER_FLAGS_BSS_SELECTION;
7017 
7018 	if (os_strstr(param, "no_offchannel_tx=1")) {
7019 		drv->capa.flags &= ~WPA_DRIVER_FLAGS_OFFCHANNEL_TX;
7020 		drv->test_use_roc_tx = 1;
7021 	}
7022 
7023 	return 0;
7024 }
7025 
7026 
7027 static void * nl80211_global_init(void *ctx)
7028 {
7029 	struct nl80211_global *global;
7030 	struct netlink_config *cfg;
7031 
7032 	global = os_zalloc(sizeof(*global));
7033 	if (global == NULL)
7034 		return NULL;
7035 	global->ctx = ctx;
7036 	global->ioctl_sock = -1;
7037 	dl_list_init(&global->interfaces);
7038 	global->if_add_ifindex = -1;
7039 
7040 	cfg = os_zalloc(sizeof(*cfg));
7041 	if (cfg == NULL)
7042 		goto err;
7043 
7044 	cfg->ctx = global;
7045 	cfg->newlink_cb = wpa_driver_nl80211_event_rtm_newlink;
7046 	cfg->dellink_cb = wpa_driver_nl80211_event_rtm_dellink;
7047 	global->netlink = netlink_init(cfg);
7048 	if (global->netlink == NULL) {
7049 		os_free(cfg);
7050 		goto err;
7051 	}
7052 
7053 	if (wpa_driver_nl80211_init_nl_global(global) < 0)
7054 		goto err;
7055 
7056 	global->ioctl_sock = socket(PF_INET, SOCK_DGRAM, 0);
7057 	if (global->ioctl_sock < 0) {
7058 		wpa_printf(MSG_ERROR, "nl80211: socket(PF_INET,SOCK_DGRAM) failed: %s",
7059 			   strerror(errno));
7060 		goto err;
7061 	}
7062 
7063 	return global;
7064 
7065 err:
7066 	nl80211_global_deinit(global);
7067 	return NULL;
7068 }
7069 
7070 
7071 static void nl80211_global_deinit(void *priv)
7072 {
7073 	struct nl80211_global *global = priv;
7074 	if (global == NULL)
7075 		return;
7076 	if (!dl_list_empty(&global->interfaces)) {
7077 		wpa_printf(MSG_ERROR, "nl80211: %u interface(s) remain at "
7078 			   "nl80211_global_deinit",
7079 			   dl_list_len(&global->interfaces));
7080 	}
7081 
7082 	if (global->netlink)
7083 		netlink_deinit(global->netlink);
7084 
7085 	nl_destroy_handles(&global->nl);
7086 
7087 	if (global->nl_event)
7088 		nl80211_destroy_eloop_handle(&global->nl_event);
7089 
7090 	nl_cb_put(global->nl_cb);
7091 
7092 	if (global->ioctl_sock >= 0)
7093 		close(global->ioctl_sock);
7094 
7095 	os_free(global);
7096 }
7097 
7098 
7099 static const char * nl80211_get_radio_name(void *priv)
7100 {
7101 	struct i802_bss *bss = priv;
7102 	struct wpa_driver_nl80211_data *drv = bss->drv;
7103 	return drv->phyname;
7104 }
7105 
7106 
7107 static int nl80211_pmkid(struct i802_bss *bss, int cmd, const u8 *bssid,
7108 			 const u8 *pmkid)
7109 {
7110 	struct nl_msg *msg;
7111 
7112 	if (!(msg = nl80211_bss_msg(bss, 0, cmd)) ||
7113 	    (pmkid && nla_put(msg, NL80211_ATTR_PMKID, 16, pmkid)) ||
7114 	    (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))) {
7115 		nlmsg_free(msg);
7116 		return -ENOBUFS;
7117 	}
7118 
7119 	return send_and_recv_msgs(bss->drv, msg, NULL, NULL);
7120 }
7121 
7122 
7123 static int nl80211_add_pmkid(void *priv, const u8 *bssid, const u8 *pmkid)
7124 {
7125 	struct i802_bss *bss = priv;
7126 	wpa_printf(MSG_DEBUG, "nl80211: Add PMKID for " MACSTR, MAC2STR(bssid));
7127 	return nl80211_pmkid(bss, NL80211_CMD_SET_PMKSA, bssid, pmkid);
7128 }
7129 
7130 
7131 static int nl80211_remove_pmkid(void *priv, const u8 *bssid, const u8 *pmkid)
7132 {
7133 	struct i802_bss *bss = priv;
7134 	wpa_printf(MSG_DEBUG, "nl80211: Delete PMKID for " MACSTR,
7135 		   MAC2STR(bssid));
7136 	return nl80211_pmkid(bss, NL80211_CMD_DEL_PMKSA, bssid, pmkid);
7137 }
7138 
7139 
7140 static int nl80211_flush_pmkid(void *priv)
7141 {
7142 	struct i802_bss *bss = priv;
7143 	wpa_printf(MSG_DEBUG, "nl80211: Flush PMKIDs");
7144 	return nl80211_pmkid(bss, NL80211_CMD_FLUSH_PMKSA, NULL, NULL);
7145 }
7146 
7147 
7148 static void clean_survey_results(struct survey_results *survey_results)
7149 {
7150 	struct freq_survey *survey, *tmp;
7151 
7152 	if (dl_list_empty(&survey_results->survey_list))
7153 		return;
7154 
7155 	dl_list_for_each_safe(survey, tmp, &survey_results->survey_list,
7156 			      struct freq_survey, list) {
7157 		dl_list_del(&survey->list);
7158 		os_free(survey);
7159 	}
7160 }
7161 
7162 
7163 static void add_survey(struct nlattr **sinfo, u32 ifidx,
7164 		       struct dl_list *survey_list)
7165 {
7166 	struct freq_survey *survey;
7167 
7168 	survey = os_zalloc(sizeof(struct freq_survey));
7169 	if  (!survey)
7170 		return;
7171 
7172 	survey->ifidx = ifidx;
7173 	survey->freq = nla_get_u32(sinfo[NL80211_SURVEY_INFO_FREQUENCY]);
7174 	survey->filled = 0;
7175 
7176 	if (sinfo[NL80211_SURVEY_INFO_NOISE]) {
7177 		survey->nf = (int8_t)
7178 			nla_get_u8(sinfo[NL80211_SURVEY_INFO_NOISE]);
7179 		survey->filled |= SURVEY_HAS_NF;
7180 	}
7181 
7182 	if (sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME]) {
7183 		survey->channel_time =
7184 			nla_get_u64(sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME]);
7185 		survey->filled |= SURVEY_HAS_CHAN_TIME;
7186 	}
7187 
7188 	if (sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY]) {
7189 		survey->channel_time_busy =
7190 			nla_get_u64(sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY]);
7191 		survey->filled |= SURVEY_HAS_CHAN_TIME_BUSY;
7192 	}
7193 
7194 	if (sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME_RX]) {
7195 		survey->channel_time_rx =
7196 			nla_get_u64(sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME_RX]);
7197 		survey->filled |= SURVEY_HAS_CHAN_TIME_RX;
7198 	}
7199 
7200 	if (sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME_TX]) {
7201 		survey->channel_time_tx =
7202 			nla_get_u64(sinfo[NL80211_SURVEY_INFO_CHANNEL_TIME_TX]);
7203 		survey->filled |= SURVEY_HAS_CHAN_TIME_TX;
7204 	}
7205 
7206 	wpa_printf(MSG_DEBUG, "nl80211: Freq survey dump event (freq=%d MHz noise=%d channel_time=%ld busy_time=%ld tx_time=%ld rx_time=%ld filled=%04x)",
7207 		   survey->freq,
7208 		   survey->nf,
7209 		   (unsigned long int) survey->channel_time,
7210 		   (unsigned long int) survey->channel_time_busy,
7211 		   (unsigned long int) survey->channel_time_tx,
7212 		   (unsigned long int) survey->channel_time_rx,
7213 		   survey->filled);
7214 
7215 	dl_list_add_tail(survey_list, &survey->list);
7216 }
7217 
7218 
7219 static int check_survey_ok(struct nlattr **sinfo, u32 surveyed_freq,
7220 			   unsigned int freq_filter)
7221 {
7222 	if (!freq_filter)
7223 		return 1;
7224 
7225 	return freq_filter == surveyed_freq;
7226 }
7227 
7228 
7229 static int survey_handler(struct nl_msg *msg, void *arg)
7230 {
7231 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
7232 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
7233 	struct nlattr *sinfo[NL80211_SURVEY_INFO_MAX + 1];
7234 	struct survey_results *survey_results;
7235 	u32 surveyed_freq = 0;
7236 	u32 ifidx;
7237 
7238 	static struct nla_policy survey_policy[NL80211_SURVEY_INFO_MAX + 1] = {
7239 		[NL80211_SURVEY_INFO_FREQUENCY] = { .type = NLA_U32 },
7240 		[NL80211_SURVEY_INFO_NOISE] = { .type = NLA_U8 },
7241 	};
7242 
7243 	survey_results = (struct survey_results *) arg;
7244 
7245 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
7246 		  genlmsg_attrlen(gnlh, 0), NULL);
7247 
7248 	if (!tb[NL80211_ATTR_IFINDEX])
7249 		return NL_SKIP;
7250 
7251 	ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
7252 
7253 	if (!tb[NL80211_ATTR_SURVEY_INFO])
7254 		return NL_SKIP;
7255 
7256 	if (nla_parse_nested(sinfo, NL80211_SURVEY_INFO_MAX,
7257 			     tb[NL80211_ATTR_SURVEY_INFO],
7258 			     survey_policy))
7259 		return NL_SKIP;
7260 
7261 	if (!sinfo[NL80211_SURVEY_INFO_FREQUENCY]) {
7262 		wpa_printf(MSG_ERROR, "nl80211: Invalid survey data");
7263 		return NL_SKIP;
7264 	}
7265 
7266 	surveyed_freq = nla_get_u32(sinfo[NL80211_SURVEY_INFO_FREQUENCY]);
7267 
7268 	if (!check_survey_ok(sinfo, surveyed_freq,
7269 			     survey_results->freq_filter))
7270 		return NL_SKIP;
7271 
7272 	if (survey_results->freq_filter &&
7273 	    survey_results->freq_filter != surveyed_freq) {
7274 		wpa_printf(MSG_EXCESSIVE, "nl80211: Ignoring survey data for freq %d MHz",
7275 			   surveyed_freq);
7276 		return NL_SKIP;
7277 	}
7278 
7279 	add_survey(sinfo, ifidx, &survey_results->survey_list);
7280 
7281 	return NL_SKIP;
7282 }
7283 
7284 
7285 static int wpa_driver_nl80211_get_survey(void *priv, unsigned int freq)
7286 {
7287 	struct i802_bss *bss = priv;
7288 	struct wpa_driver_nl80211_data *drv = bss->drv;
7289 	struct nl_msg *msg;
7290 	int err;
7291 	union wpa_event_data data;
7292 	struct survey_results *survey_results;
7293 
7294 	os_memset(&data, 0, sizeof(data));
7295 	survey_results = &data.survey_results;
7296 
7297 	dl_list_init(&survey_results->survey_list);
7298 
7299 	msg = nl80211_drv_msg(drv, NLM_F_DUMP, NL80211_CMD_GET_SURVEY);
7300 	if (!msg)
7301 		return -ENOBUFS;
7302 
7303 	if (freq)
7304 		data.survey_results.freq_filter = freq;
7305 
7306 	do {
7307 		wpa_printf(MSG_DEBUG, "nl80211: Fetch survey data");
7308 		err = send_and_recv_msgs(drv, msg, survey_handler,
7309 					 survey_results);
7310 	} while (err > 0);
7311 
7312 	if (err)
7313 		wpa_printf(MSG_ERROR, "nl80211: Failed to process survey data");
7314 	else
7315 		wpa_supplicant_event(drv->ctx, EVENT_SURVEY, &data);
7316 
7317 	clean_survey_results(survey_results);
7318 	return err;
7319 }
7320 
7321 
7322 static void nl80211_set_rekey_info(void *priv, const u8 *kek, size_t kek_len,
7323 				   const u8 *kck, size_t kck_len,
7324 				   const u8 *replay_ctr)
7325 {
7326 	struct i802_bss *bss = priv;
7327 	struct wpa_driver_nl80211_data *drv = bss->drv;
7328 	struct nlattr *replay_nested;
7329 	struct nl_msg *msg;
7330 	int ret;
7331 
7332 	if (!drv->set_rekey_offload)
7333 		return;
7334 
7335 	wpa_printf(MSG_DEBUG, "nl80211: Set rekey offload");
7336 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_REKEY_OFFLOAD)) ||
7337 	    !(replay_nested = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA)) ||
7338 	    nla_put(msg, NL80211_REKEY_DATA_KEK, kek_len, kek) ||
7339 	    nla_put(msg, NL80211_REKEY_DATA_KCK, kck_len, kck) ||
7340 	    nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR, NL80211_REPLAY_CTR_LEN,
7341 		    replay_ctr)) {
7342 		nl80211_nlmsg_clear(msg);
7343 		nlmsg_free(msg);
7344 		return;
7345 	}
7346 
7347 	nla_nest_end(msg, replay_nested);
7348 
7349 	ret = send_and_recv_msgs(drv, msg, NULL, (void *) -1);
7350 	if (ret == -EOPNOTSUPP) {
7351 		wpa_printf(MSG_DEBUG,
7352 			   "nl80211: Driver does not support rekey offload");
7353 		drv->set_rekey_offload = 0;
7354 	}
7355 }
7356 
7357 
7358 static void nl80211_send_null_frame(struct i802_bss *bss, const u8 *own_addr,
7359 				    const u8 *addr, int qos)
7360 {
7361 	/* send data frame to poll STA and check whether
7362 	 * this frame is ACKed */
7363 	struct {
7364 		struct ieee80211_hdr hdr;
7365 		u16 qos_ctl;
7366 	} STRUCT_PACKED nulldata;
7367 	size_t size;
7368 
7369 	/* Send data frame to poll STA and check whether this frame is ACKed */
7370 
7371 	os_memset(&nulldata, 0, sizeof(nulldata));
7372 
7373 	if (qos) {
7374 		nulldata.hdr.frame_control =
7375 			IEEE80211_FC(WLAN_FC_TYPE_DATA,
7376 				     WLAN_FC_STYPE_QOS_NULL);
7377 		size = sizeof(nulldata);
7378 	} else {
7379 		nulldata.hdr.frame_control =
7380 			IEEE80211_FC(WLAN_FC_TYPE_DATA,
7381 				     WLAN_FC_STYPE_NULLFUNC);
7382 		size = sizeof(struct ieee80211_hdr);
7383 	}
7384 
7385 	nulldata.hdr.frame_control |= host_to_le16(WLAN_FC_FROMDS);
7386 	os_memcpy(nulldata.hdr.IEEE80211_DA_FROMDS, addr, ETH_ALEN);
7387 	os_memcpy(nulldata.hdr.IEEE80211_BSSID_FROMDS, own_addr, ETH_ALEN);
7388 	os_memcpy(nulldata.hdr.IEEE80211_SA_FROMDS, own_addr, ETH_ALEN);
7389 
7390 	if (wpa_driver_nl80211_send_mlme(bss, (u8 *) &nulldata, size, 0, 0, 0,
7391 					 0, 0, NULL, 0) < 0)
7392 		wpa_printf(MSG_DEBUG, "nl80211_send_null_frame: Failed to "
7393 			   "send poll frame");
7394 }
7395 
7396 static void nl80211_poll_client(void *priv, const u8 *own_addr, const u8 *addr,
7397 				int qos)
7398 {
7399 	struct i802_bss *bss = priv;
7400 	struct wpa_driver_nl80211_data *drv = bss->drv;
7401 	struct nl_msg *msg;
7402 	int ret;
7403 
7404 	if (!drv->poll_command_supported) {
7405 		nl80211_send_null_frame(bss, own_addr, addr, qos);
7406 		return;
7407 	}
7408 
7409 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_PROBE_CLIENT)) ||
7410 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) {
7411 		nlmsg_free(msg);
7412 		return;
7413 	}
7414 
7415 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
7416 	if (ret < 0) {
7417 		wpa_printf(MSG_DEBUG, "nl80211: Client probe request for "
7418 			   MACSTR " failed: ret=%d (%s)",
7419 			   MAC2STR(addr), ret, strerror(-ret));
7420 	}
7421 }
7422 
7423 
7424 static int nl80211_set_power_save(struct i802_bss *bss, int enabled)
7425 {
7426 	struct nl_msg *msg;
7427 
7428 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_SET_POWER_SAVE)) ||
7429 	    nla_put_u32(msg, NL80211_ATTR_PS_STATE,
7430 			enabled ? NL80211_PS_ENABLED : NL80211_PS_DISABLED)) {
7431 		nlmsg_free(msg);
7432 		return -ENOBUFS;
7433 	}
7434 	return send_and_recv_msgs(bss->drv, msg, NULL, NULL);
7435 }
7436 
7437 
7438 static int nl80211_set_p2p_powersave(void *priv, int legacy_ps, int opp_ps,
7439 				     int ctwindow)
7440 {
7441 	struct i802_bss *bss = priv;
7442 
7443 	wpa_printf(MSG_DEBUG, "nl80211: set_p2p_powersave (legacy_ps=%d "
7444 		   "opp_ps=%d ctwindow=%d)", legacy_ps, opp_ps, ctwindow);
7445 
7446 	if (opp_ps != -1 || ctwindow != -1) {
7447 #ifdef ANDROID_P2P
7448 		wpa_driver_set_p2p_ps(priv, legacy_ps, opp_ps, ctwindow);
7449 #else /* ANDROID_P2P */
7450 		return -1; /* Not yet supported */
7451 #endif /* ANDROID_P2P */
7452 	}
7453 
7454 	if (legacy_ps == -1)
7455 		return 0;
7456 	if (legacy_ps != 0 && legacy_ps != 1)
7457 		return -1; /* Not yet supported */
7458 
7459 	return nl80211_set_power_save(bss, legacy_ps);
7460 }
7461 
7462 
7463 static int nl80211_start_radar_detection(void *priv,
7464 					 struct hostapd_freq_params *freq)
7465 {
7466 	struct i802_bss *bss = priv;
7467 	struct wpa_driver_nl80211_data *drv = bss->drv;
7468 	struct nl_msg *msg;
7469 	int ret;
7470 
7471 	wpa_printf(MSG_DEBUG, "nl80211: Start radar detection (CAC) %d MHz (ht_enabled=%d, vht_enabled=%d, bandwidth=%d MHz, cf1=%d MHz, cf2=%d MHz)",
7472 		   freq->freq, freq->ht_enabled, freq->vht_enabled,
7473 		   freq->bandwidth, freq->center_freq1, freq->center_freq2);
7474 
7475 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_RADAR)) {
7476 		wpa_printf(MSG_DEBUG, "nl80211: Driver does not support radar "
7477 			   "detection");
7478 		return -1;
7479 	}
7480 
7481 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_RADAR_DETECT)) ||
7482 	    nl80211_put_freq_params(msg, freq) < 0) {
7483 		nlmsg_free(msg);
7484 		return -1;
7485 	}
7486 
7487 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
7488 	if (ret == 0)
7489 		return 0;
7490 	wpa_printf(MSG_DEBUG, "nl80211: Failed to start radar detection: "
7491 		   "%d (%s)", ret, strerror(-ret));
7492 	return -1;
7493 }
7494 
7495 #ifdef CONFIG_TDLS
7496 
7497 static int nl80211_send_tdls_mgmt(void *priv, const u8 *dst, u8 action_code,
7498 				  u8 dialog_token, u16 status_code,
7499 				  u32 peer_capab, int initiator, const u8 *buf,
7500 				  size_t len)
7501 {
7502 	struct i802_bss *bss = priv;
7503 	struct wpa_driver_nl80211_data *drv = bss->drv;
7504 	struct nl_msg *msg;
7505 
7506 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_SUPPORT))
7507 		return -EOPNOTSUPP;
7508 
7509 	if (!dst)
7510 		return -EINVAL;
7511 
7512 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_TDLS_MGMT)) ||
7513 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
7514 	    nla_put_u8(msg, NL80211_ATTR_TDLS_ACTION, action_code) ||
7515 	    nla_put_u8(msg, NL80211_ATTR_TDLS_DIALOG_TOKEN, dialog_token) ||
7516 	    nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status_code))
7517 		goto fail;
7518 	if (peer_capab) {
7519 		/*
7520 		 * The internal enum tdls_peer_capability definition is
7521 		 * currently identical with the nl80211 enum
7522 		 * nl80211_tdls_peer_capability, so no conversion is needed
7523 		 * here.
7524 		 */
7525 		if (nla_put_u32(msg, NL80211_ATTR_TDLS_PEER_CAPABILITY,
7526 				peer_capab))
7527 			goto fail;
7528 	}
7529 	if ((initiator &&
7530 	     nla_put_flag(msg, NL80211_ATTR_TDLS_INITIATOR)) ||
7531 	    nla_put(msg, NL80211_ATTR_IE, len, buf))
7532 		goto fail;
7533 
7534 	return send_and_recv_msgs(drv, msg, NULL, NULL);
7535 
7536 fail:
7537 	nlmsg_free(msg);
7538 	return -ENOBUFS;
7539 }
7540 
7541 
7542 static int nl80211_tdls_oper(void *priv, enum tdls_oper oper, const u8 *peer)
7543 {
7544 	struct i802_bss *bss = priv;
7545 	struct wpa_driver_nl80211_data *drv = bss->drv;
7546 	struct nl_msg *msg;
7547 	enum nl80211_tdls_operation nl80211_oper;
7548 
7549 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_SUPPORT))
7550 		return -EOPNOTSUPP;
7551 
7552 	switch (oper) {
7553 	case TDLS_DISCOVERY_REQ:
7554 		nl80211_oper = NL80211_TDLS_DISCOVERY_REQ;
7555 		break;
7556 	case TDLS_SETUP:
7557 		nl80211_oper = NL80211_TDLS_SETUP;
7558 		break;
7559 	case TDLS_TEARDOWN:
7560 		nl80211_oper = NL80211_TDLS_TEARDOWN;
7561 		break;
7562 	case TDLS_ENABLE_LINK:
7563 		nl80211_oper = NL80211_TDLS_ENABLE_LINK;
7564 		break;
7565 	case TDLS_DISABLE_LINK:
7566 		nl80211_oper = NL80211_TDLS_DISABLE_LINK;
7567 		break;
7568 	case TDLS_ENABLE:
7569 		return 0;
7570 	case TDLS_DISABLE:
7571 		return 0;
7572 	default:
7573 		return -EINVAL;
7574 	}
7575 
7576 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_TDLS_OPER)) ||
7577 	    nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, nl80211_oper) ||
7578 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer)) {
7579 		nlmsg_free(msg);
7580 		return -ENOBUFS;
7581 	}
7582 
7583 	return send_and_recv_msgs(drv, msg, NULL, NULL);
7584 }
7585 
7586 
7587 static int
7588 nl80211_tdls_enable_channel_switch(void *priv, const u8 *addr, u8 oper_class,
7589 				   const struct hostapd_freq_params *params)
7590 {
7591 	struct i802_bss *bss = priv;
7592 	struct wpa_driver_nl80211_data *drv = bss->drv;
7593 	struct nl_msg *msg;
7594 	int ret = -ENOBUFS;
7595 
7596 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_SUPPORT) ||
7597 	    !(drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_CHANNEL_SWITCH))
7598 		return -EOPNOTSUPP;
7599 
7600 	wpa_printf(MSG_DEBUG, "nl80211: Enable TDLS channel switch " MACSTR
7601 		   " oper_class=%u freq=%u",
7602 		   MAC2STR(addr), oper_class, params->freq);
7603 	msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_TDLS_CHANNEL_SWITCH);
7604 	if (!msg ||
7605 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
7606 	    nla_put_u8(msg, NL80211_ATTR_OPER_CLASS, oper_class) ||
7607 	    (ret = nl80211_put_freq_params(msg, params))) {
7608 		nlmsg_free(msg);
7609 		wpa_printf(MSG_DEBUG, "nl80211: Could not build TDLS chan switch");
7610 		return ret;
7611 	}
7612 
7613 	return send_and_recv_msgs(drv, msg, NULL, NULL);
7614 }
7615 
7616 
7617 static int
7618 nl80211_tdls_disable_channel_switch(void *priv, const u8 *addr)
7619 {
7620 	struct i802_bss *bss = priv;
7621 	struct wpa_driver_nl80211_data *drv = bss->drv;
7622 	struct nl_msg *msg;
7623 
7624 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_SUPPORT) ||
7625 	    !(drv->capa.flags & WPA_DRIVER_FLAGS_TDLS_CHANNEL_SWITCH))
7626 		return -EOPNOTSUPP;
7627 
7628 	wpa_printf(MSG_DEBUG, "nl80211: Disable TDLS channel switch " MACSTR,
7629 		   MAC2STR(addr));
7630 	msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH);
7631 	if (!msg ||
7632 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) {
7633 		nlmsg_free(msg);
7634 		wpa_printf(MSG_DEBUG,
7635 			   "nl80211: Could not build TDLS cancel chan switch");
7636 		return -ENOBUFS;
7637 	}
7638 
7639 	return send_and_recv_msgs(drv, msg, NULL, NULL);
7640 }
7641 
7642 #endif /* CONFIG TDLS */
7643 
7644 
7645 static int driver_nl80211_set_key(const char *ifname, void *priv,
7646 				  enum wpa_alg alg, const u8 *addr,
7647 				  int key_idx, int set_tx,
7648 				  const u8 *seq, size_t seq_len,
7649 				  const u8 *key, size_t key_len)
7650 {
7651 	struct i802_bss *bss = priv;
7652 	return wpa_driver_nl80211_set_key(ifname, bss, alg, addr, key_idx,
7653 					  set_tx, seq, seq_len, key, key_len);
7654 }
7655 
7656 
7657 static int driver_nl80211_scan2(void *priv,
7658 				struct wpa_driver_scan_params *params)
7659 {
7660 	struct i802_bss *bss = priv;
7661 #ifdef CONFIG_DRIVER_NL80211_QCA
7662 	struct wpa_driver_nl80211_data *drv = bss->drv;
7663 
7664 	/*
7665 	 * Do a vendor specific scan if possible. If only_new_results is
7666 	 * set, do a normal scan since a kernel (cfg80211) BSS cache flush
7667 	 * cannot be achieved through a vendor scan. The below condition may
7668 	 * need to be modified if new scan flags are added in the future whose
7669 	 * functionality can only be achieved through a normal scan.
7670 	 */
7671 	if (drv->scan_vendor_cmd_avail && !params->only_new_results)
7672 		return wpa_driver_nl80211_vendor_scan(bss, params);
7673 #endif /* CONFIG_DRIVER_NL80211_QCA */
7674 	return wpa_driver_nl80211_scan(bss, params);
7675 }
7676 
7677 
7678 static int driver_nl80211_deauthenticate(void *priv, const u8 *addr,
7679 					 int reason_code)
7680 {
7681 	struct i802_bss *bss = priv;
7682 	return wpa_driver_nl80211_deauthenticate(bss, addr, reason_code);
7683 }
7684 
7685 
7686 static int driver_nl80211_authenticate(void *priv,
7687 				       struct wpa_driver_auth_params *params)
7688 {
7689 	struct i802_bss *bss = priv;
7690 	return wpa_driver_nl80211_authenticate(bss, params);
7691 }
7692 
7693 
7694 static void driver_nl80211_deinit(void *priv)
7695 {
7696 	struct i802_bss *bss = priv;
7697 	wpa_driver_nl80211_deinit(bss);
7698 }
7699 
7700 
7701 static int driver_nl80211_if_remove(void *priv, enum wpa_driver_if_type type,
7702 				    const char *ifname)
7703 {
7704 	struct i802_bss *bss = priv;
7705 	return wpa_driver_nl80211_if_remove(bss, type, ifname);
7706 }
7707 
7708 
7709 static int driver_nl80211_send_mlme(void *priv, const u8 *data,
7710 				    size_t data_len, int noack,
7711 				    unsigned int freq,
7712 				    const u16 *csa_offs, size_t csa_offs_len)
7713 {
7714 	struct i802_bss *bss = priv;
7715 	return wpa_driver_nl80211_send_mlme(bss, data, data_len, noack,
7716 					    freq, 0, 0, 0, csa_offs,
7717 					    csa_offs_len);
7718 }
7719 
7720 
7721 static int driver_nl80211_sta_remove(void *priv, const u8 *addr)
7722 {
7723 	struct i802_bss *bss = priv;
7724 	return wpa_driver_nl80211_sta_remove(bss, addr, -1, 0);
7725 }
7726 
7727 
7728 static int driver_nl80211_set_sta_vlan(void *priv, const u8 *addr,
7729 				       const char *ifname, int vlan_id)
7730 {
7731 	struct i802_bss *bss = priv;
7732 	return i802_set_sta_vlan(bss, addr, ifname, vlan_id);
7733 }
7734 
7735 
7736 static int driver_nl80211_read_sta_data(void *priv,
7737 					struct hostap_sta_driver_data *data,
7738 					const u8 *addr)
7739 {
7740 	struct i802_bss *bss = priv;
7741 	return i802_read_sta_data(bss, data, addr);
7742 }
7743 
7744 
7745 static int driver_nl80211_send_action(void *priv, unsigned int freq,
7746 				      unsigned int wait_time,
7747 				      const u8 *dst, const u8 *src,
7748 				      const u8 *bssid,
7749 				      const u8 *data, size_t data_len,
7750 				      int no_cck)
7751 {
7752 	struct i802_bss *bss = priv;
7753 	return wpa_driver_nl80211_send_action(bss, freq, wait_time, dst, src,
7754 					      bssid, data, data_len, no_cck);
7755 }
7756 
7757 
7758 static int driver_nl80211_probe_req_report(void *priv, int report)
7759 {
7760 	struct i802_bss *bss = priv;
7761 	return wpa_driver_nl80211_probe_req_report(bss, report);
7762 }
7763 
7764 
7765 static int wpa_driver_nl80211_update_ft_ies(void *priv, const u8 *md,
7766 					    const u8 *ies, size_t ies_len)
7767 {
7768 	int ret;
7769 	struct nl_msg *msg;
7770 	struct i802_bss *bss = priv;
7771 	struct wpa_driver_nl80211_data *drv = bss->drv;
7772 	u16 mdid = WPA_GET_LE16(md);
7773 
7774 	wpa_printf(MSG_DEBUG, "nl80211: Updating FT IEs");
7775 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_UPDATE_FT_IES)) ||
7776 	    nla_put(msg, NL80211_ATTR_IE, ies_len, ies) ||
7777 	    nla_put_u16(msg, NL80211_ATTR_MDID, mdid)) {
7778 		nlmsg_free(msg);
7779 		return -ENOBUFS;
7780 	}
7781 
7782 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
7783 	if (ret) {
7784 		wpa_printf(MSG_DEBUG, "nl80211: update_ft_ies failed "
7785 			   "err=%d (%s)", ret, strerror(-ret));
7786 	}
7787 
7788 	return ret;
7789 }
7790 
7791 
7792 static const u8 * wpa_driver_nl80211_get_macaddr(void *priv)
7793 {
7794 	struct i802_bss *bss = priv;
7795 	struct wpa_driver_nl80211_data *drv = bss->drv;
7796 
7797 	if (drv->nlmode != NL80211_IFTYPE_P2P_DEVICE)
7798 		return NULL;
7799 
7800 	return bss->addr;
7801 }
7802 
7803 
7804 static const char * scan_state_str(enum scan_states scan_state)
7805 {
7806 	switch (scan_state) {
7807 	case NO_SCAN:
7808 		return "NO_SCAN";
7809 	case SCAN_REQUESTED:
7810 		return "SCAN_REQUESTED";
7811 	case SCAN_STARTED:
7812 		return "SCAN_STARTED";
7813 	case SCAN_COMPLETED:
7814 		return "SCAN_COMPLETED";
7815 	case SCAN_ABORTED:
7816 		return "SCAN_ABORTED";
7817 	case SCHED_SCAN_STARTED:
7818 		return "SCHED_SCAN_STARTED";
7819 	case SCHED_SCAN_STOPPED:
7820 		return "SCHED_SCAN_STOPPED";
7821 	case SCHED_SCAN_RESULTS:
7822 		return "SCHED_SCAN_RESULTS";
7823 	}
7824 
7825 	return "??";
7826 }
7827 
7828 
7829 static int wpa_driver_nl80211_status(void *priv, char *buf, size_t buflen)
7830 {
7831 	struct i802_bss *bss = priv;
7832 	struct wpa_driver_nl80211_data *drv = bss->drv;
7833 	int res;
7834 	char *pos, *end;
7835 
7836 	pos = buf;
7837 	end = buf + buflen;
7838 
7839 	res = os_snprintf(pos, end - pos,
7840 			  "ifindex=%d\n"
7841 			  "ifname=%s\n"
7842 			  "brname=%s\n"
7843 			  "addr=" MACSTR "\n"
7844 			  "freq=%d\n"
7845 			  "%s%s%s%s%s",
7846 			  bss->ifindex,
7847 			  bss->ifname,
7848 			  bss->brname,
7849 			  MAC2STR(bss->addr),
7850 			  bss->freq,
7851 			  bss->beacon_set ? "beacon_set=1\n" : "",
7852 			  bss->added_if_into_bridge ?
7853 			  "added_if_into_bridge=1\n" : "",
7854 			  bss->added_bridge ? "added_bridge=1\n" : "",
7855 			  bss->in_deinit ? "in_deinit=1\n" : "",
7856 			  bss->if_dynamic ? "if_dynamic=1\n" : "");
7857 	if (os_snprintf_error(end - pos, res))
7858 		return pos - buf;
7859 	pos += res;
7860 
7861 	if (bss->wdev_id_set) {
7862 		res = os_snprintf(pos, end - pos, "wdev_id=%llu\n",
7863 				  (unsigned long long) bss->wdev_id);
7864 		if (os_snprintf_error(end - pos, res))
7865 			return pos - buf;
7866 		pos += res;
7867 	}
7868 
7869 	res = os_snprintf(pos, end - pos,
7870 			  "phyname=%s\n"
7871 			  "perm_addr=" MACSTR "\n"
7872 			  "drv_ifindex=%d\n"
7873 			  "operstate=%d\n"
7874 			  "scan_state=%s\n"
7875 			  "auth_bssid=" MACSTR "\n"
7876 			  "auth_attempt_bssid=" MACSTR "\n"
7877 			  "bssid=" MACSTR "\n"
7878 			  "prev_bssid=" MACSTR "\n"
7879 			  "associated=%d\n"
7880 			  "assoc_freq=%u\n"
7881 			  "monitor_sock=%d\n"
7882 			  "monitor_ifidx=%d\n"
7883 			  "monitor_refcount=%d\n"
7884 			  "last_mgmt_freq=%u\n"
7885 			  "eapol_tx_sock=%d\n"
7886 			  "%s%s%s%s%s%s%s%s%s%s%s%s%s",
7887 			  drv->phyname,
7888 			  MAC2STR(drv->perm_addr),
7889 			  drv->ifindex,
7890 			  drv->operstate,
7891 			  scan_state_str(drv->scan_state),
7892 			  MAC2STR(drv->auth_bssid),
7893 			  MAC2STR(drv->auth_attempt_bssid),
7894 			  MAC2STR(drv->bssid),
7895 			  MAC2STR(drv->prev_bssid),
7896 			  drv->associated,
7897 			  drv->assoc_freq,
7898 			  drv->monitor_sock,
7899 			  drv->monitor_ifidx,
7900 			  drv->monitor_refcount,
7901 			  drv->last_mgmt_freq,
7902 			  drv->eapol_tx_sock,
7903 			  drv->ignore_if_down_event ?
7904 			  "ignore_if_down_event=1\n" : "",
7905 			  drv->scan_complete_events ?
7906 			  "scan_complete_events=1\n" : "",
7907 			  drv->disabled_11b_rates ?
7908 			  "disabled_11b_rates=1\n" : "",
7909 			  drv->pending_remain_on_chan ?
7910 			  "pending_remain_on_chan=1\n" : "",
7911 			  drv->in_interface_list ? "in_interface_list=1\n" : "",
7912 			  drv->device_ap_sme ? "device_ap_sme=1\n" : "",
7913 			  drv->poll_command_supported ?
7914 			  "poll_command_supported=1\n" : "",
7915 			  drv->data_tx_status ? "data_tx_status=1\n" : "",
7916 			  drv->scan_for_auth ? "scan_for_auth=1\n" : "",
7917 			  drv->retry_auth ? "retry_auth=1\n" : "",
7918 			  drv->use_monitor ? "use_monitor=1\n" : "",
7919 			  drv->ignore_next_local_disconnect ?
7920 			  "ignore_next_local_disconnect=1\n" : "",
7921 			  drv->ignore_next_local_deauth ?
7922 			  "ignore_next_local_deauth=1\n" : "");
7923 	if (os_snprintf_error(end - pos, res))
7924 		return pos - buf;
7925 	pos += res;
7926 
7927 	if (drv->has_capability) {
7928 		res = os_snprintf(pos, end - pos,
7929 				  "capa.key_mgmt=0x%x\n"
7930 				  "capa.enc=0x%x\n"
7931 				  "capa.auth=0x%x\n"
7932 				  "capa.flags=0x%llx\n"
7933 				  "capa.rrm_flags=0x%x\n"
7934 				  "capa.max_scan_ssids=%d\n"
7935 				  "capa.max_sched_scan_ssids=%d\n"
7936 				  "capa.sched_scan_supported=%d\n"
7937 				  "capa.max_match_sets=%d\n"
7938 				  "capa.max_remain_on_chan=%u\n"
7939 				  "capa.max_stations=%u\n"
7940 				  "capa.probe_resp_offloads=0x%x\n"
7941 				  "capa.max_acl_mac_addrs=%u\n"
7942 				  "capa.num_multichan_concurrent=%u\n"
7943 				  "capa.mac_addr_rand_sched_scan_supported=%d\n"
7944 				  "capa.mac_addr_rand_scan_supported=%d\n"
7945 				  "capa.conc_capab=%u\n"
7946 				  "capa.max_conc_chan_2_4=%u\n"
7947 				  "capa.max_conc_chan_5_0=%u\n"
7948 				  "capa.max_sched_scan_plans=%u\n"
7949 				  "capa.max_sched_scan_plan_interval=%u\n"
7950 				  "capa.max_sched_scan_plan_iterations=%u\n",
7951 				  drv->capa.key_mgmt,
7952 				  drv->capa.enc,
7953 				  drv->capa.auth,
7954 				  (unsigned long long) drv->capa.flags,
7955 				  drv->capa.rrm_flags,
7956 				  drv->capa.max_scan_ssids,
7957 				  drv->capa.max_sched_scan_ssids,
7958 				  drv->capa.sched_scan_supported,
7959 				  drv->capa.max_match_sets,
7960 				  drv->capa.max_remain_on_chan,
7961 				  drv->capa.max_stations,
7962 				  drv->capa.probe_resp_offloads,
7963 				  drv->capa.max_acl_mac_addrs,
7964 				  drv->capa.num_multichan_concurrent,
7965 				  drv->capa.mac_addr_rand_sched_scan_supported,
7966 				  drv->capa.mac_addr_rand_scan_supported,
7967 				  drv->capa.conc_capab,
7968 				  drv->capa.max_conc_chan_2_4,
7969 				  drv->capa.max_conc_chan_5_0,
7970 				  drv->capa.max_sched_scan_plans,
7971 				  drv->capa.max_sched_scan_plan_interval,
7972 				  drv->capa.max_sched_scan_plan_iterations);
7973 		if (os_snprintf_error(end - pos, res))
7974 			return pos - buf;
7975 		pos += res;
7976 	}
7977 
7978 	return pos - buf;
7979 }
7980 
7981 
7982 static int set_beacon_data(struct nl_msg *msg, struct beacon_data *settings)
7983 {
7984 	if ((settings->head &&
7985 	     nla_put(msg, NL80211_ATTR_BEACON_HEAD,
7986 		     settings->head_len, settings->head)) ||
7987 	    (settings->tail &&
7988 	     nla_put(msg, NL80211_ATTR_BEACON_TAIL,
7989 		     settings->tail_len, settings->tail)) ||
7990 	    (settings->beacon_ies &&
7991 	     nla_put(msg, NL80211_ATTR_IE,
7992 		     settings->beacon_ies_len, settings->beacon_ies)) ||
7993 	    (settings->proberesp_ies &&
7994 	     nla_put(msg, NL80211_ATTR_IE_PROBE_RESP,
7995 		     settings->proberesp_ies_len, settings->proberesp_ies)) ||
7996 	    (settings->assocresp_ies &&
7997 	     nla_put(msg, NL80211_ATTR_IE_ASSOC_RESP,
7998 		     settings->assocresp_ies_len, settings->assocresp_ies)) ||
7999 	    (settings->probe_resp &&
8000 	     nla_put(msg, NL80211_ATTR_PROBE_RESP,
8001 		     settings->probe_resp_len, settings->probe_resp)))
8002 		return -ENOBUFS;
8003 
8004 	return 0;
8005 }
8006 
8007 
8008 static int nl80211_switch_channel(void *priv, struct csa_settings *settings)
8009 {
8010 	struct nl_msg *msg;
8011 	struct i802_bss *bss = priv;
8012 	struct wpa_driver_nl80211_data *drv = bss->drv;
8013 	struct nlattr *beacon_csa;
8014 	int ret = -ENOBUFS;
8015 	int csa_off_len = 0;
8016 	int i;
8017 
8018 	wpa_printf(MSG_DEBUG, "nl80211: Channel switch request (cs_count=%u block_tx=%u freq=%d width=%d cf1=%d cf2=%d)",
8019 		   settings->cs_count, settings->block_tx,
8020 		   settings->freq_params.freq, settings->freq_params.bandwidth,
8021 		   settings->freq_params.center_freq1,
8022 		   settings->freq_params.center_freq2);
8023 
8024 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_AP_CSA)) {
8025 		wpa_printf(MSG_DEBUG, "nl80211: Driver does not support channel switch command");
8026 		return -EOPNOTSUPP;
8027 	}
8028 
8029 	if ((drv->nlmode != NL80211_IFTYPE_AP) &&
8030 	    (drv->nlmode != NL80211_IFTYPE_P2P_GO))
8031 		return -EOPNOTSUPP;
8032 
8033 	/*
8034 	 * Remove empty counters, assuming Probe Response and Beacon frame
8035 	 * counters match. This implementation assumes that there are only two
8036 	 * counters.
8037 	 */
8038 	if (settings->counter_offset_beacon[0] &&
8039 	    !settings->counter_offset_beacon[1]) {
8040 		csa_off_len = 1;
8041 	} else if (settings->counter_offset_beacon[1] &&
8042 		   !settings->counter_offset_beacon[0]) {
8043 		csa_off_len = 1;
8044 		settings->counter_offset_beacon[0] =
8045 			settings->counter_offset_beacon[1];
8046 		settings->counter_offset_presp[0] =
8047 			settings->counter_offset_presp[1];
8048 	} else if (settings->counter_offset_beacon[1] &&
8049 		   settings->counter_offset_beacon[0]) {
8050 		csa_off_len = 2;
8051 	} else {
8052 		wpa_printf(MSG_ERROR, "nl80211: No CSA counters provided");
8053 		return -EINVAL;
8054 	}
8055 
8056 	/* Check CSA counters validity */
8057 	if (drv->capa.max_csa_counters &&
8058 	    csa_off_len > drv->capa.max_csa_counters) {
8059 		wpa_printf(MSG_ERROR,
8060 			   "nl80211: Too many CSA counters provided");
8061 		return -EINVAL;
8062 	}
8063 
8064 	if (!settings->beacon_csa.tail)
8065 		return -EINVAL;
8066 
8067 	for (i = 0; i < csa_off_len; i++) {
8068 		u16 csa_c_off_bcn = settings->counter_offset_beacon[i];
8069 		u16 csa_c_off_presp = settings->counter_offset_presp[i];
8070 
8071 		if ((settings->beacon_csa.tail_len <= csa_c_off_bcn) ||
8072 		    (settings->beacon_csa.tail[csa_c_off_bcn] !=
8073 		     settings->cs_count))
8074 			return -EINVAL;
8075 
8076 		if (settings->beacon_csa.probe_resp &&
8077 		    ((settings->beacon_csa.probe_resp_len <=
8078 		      csa_c_off_presp) ||
8079 		     (settings->beacon_csa.probe_resp[csa_c_off_presp] !=
8080 		      settings->cs_count)))
8081 			return -EINVAL;
8082 	}
8083 
8084 	if (!(msg = nl80211_bss_msg(bss, 0, NL80211_CMD_CHANNEL_SWITCH)) ||
8085 	    nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT,
8086 			settings->cs_count) ||
8087 	    (ret = nl80211_put_freq_params(msg, &settings->freq_params)) ||
8088 	    (settings->block_tx &&
8089 	     nla_put_flag(msg, NL80211_ATTR_CH_SWITCH_BLOCK_TX)))
8090 		goto error;
8091 
8092 	/* beacon_after params */
8093 	ret = set_beacon_data(msg, &settings->beacon_after);
8094 	if (ret)
8095 		goto error;
8096 
8097 	/* beacon_csa params */
8098 	beacon_csa = nla_nest_start(msg, NL80211_ATTR_CSA_IES);
8099 	if (!beacon_csa)
8100 		goto fail;
8101 
8102 	ret = set_beacon_data(msg, &settings->beacon_csa);
8103 	if (ret)
8104 		goto error;
8105 
8106 	if (nla_put(msg, NL80211_ATTR_CSA_C_OFF_BEACON,
8107 		    csa_off_len * sizeof(u16),
8108 		    settings->counter_offset_beacon) ||
8109 	    (settings->beacon_csa.probe_resp &&
8110 	     nla_put(msg, NL80211_ATTR_CSA_C_OFF_PRESP,
8111 		     csa_off_len * sizeof(u16),
8112 		     settings->counter_offset_presp)))
8113 		goto fail;
8114 
8115 	nla_nest_end(msg, beacon_csa);
8116 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8117 	if (ret) {
8118 		wpa_printf(MSG_DEBUG, "nl80211: switch_channel failed err=%d (%s)",
8119 			   ret, strerror(-ret));
8120 	}
8121 	return ret;
8122 
8123 fail:
8124 	ret = -ENOBUFS;
8125 error:
8126 	nlmsg_free(msg);
8127 	wpa_printf(MSG_DEBUG, "nl80211: Could not build channel switch request");
8128 	return ret;
8129 }
8130 
8131 
8132 static int nl80211_add_ts(void *priv, u8 tsid, const u8 *addr,
8133 			  u8 user_priority, u16 admitted_time)
8134 {
8135 	struct i802_bss *bss = priv;
8136 	struct wpa_driver_nl80211_data *drv = bss->drv;
8137 	struct nl_msg *msg;
8138 	int ret;
8139 
8140 	wpa_printf(MSG_DEBUG,
8141 		   "nl80211: add_ts request: tsid=%u admitted_time=%u up=%d",
8142 		   tsid, admitted_time, user_priority);
8143 
8144 	if (!is_sta_interface(drv->nlmode))
8145 		return -ENOTSUP;
8146 
8147 	msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_ADD_TX_TS);
8148 	if (!msg ||
8149 	    nla_put_u8(msg, NL80211_ATTR_TSID, tsid) ||
8150 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
8151 	    nla_put_u8(msg, NL80211_ATTR_USER_PRIO, user_priority) ||
8152 	    nla_put_u16(msg, NL80211_ATTR_ADMITTED_TIME, admitted_time)) {
8153 		nlmsg_free(msg);
8154 		return -ENOBUFS;
8155 	}
8156 
8157 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8158 	if (ret)
8159 		wpa_printf(MSG_DEBUG, "nl80211: add_ts failed err=%d (%s)",
8160 			   ret, strerror(-ret));
8161 	return ret;
8162 }
8163 
8164 
8165 static int nl80211_del_ts(void *priv, u8 tsid, const u8 *addr)
8166 {
8167 	struct i802_bss *bss = priv;
8168 	struct wpa_driver_nl80211_data *drv = bss->drv;
8169 	struct nl_msg *msg;
8170 	int ret;
8171 
8172 	wpa_printf(MSG_DEBUG, "nl80211: del_ts request: tsid=%u", tsid);
8173 
8174 	if (!is_sta_interface(drv->nlmode))
8175 		return -ENOTSUP;
8176 
8177 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_DEL_TX_TS)) ||
8178 	    nla_put_u8(msg, NL80211_ATTR_TSID, tsid) ||
8179 	    nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) {
8180 		nlmsg_free(msg);
8181 		return -ENOBUFS;
8182 	}
8183 
8184 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8185 	if (ret)
8186 		wpa_printf(MSG_DEBUG, "nl80211: del_ts failed err=%d (%s)",
8187 			   ret, strerror(-ret));
8188 	return ret;
8189 }
8190 
8191 
8192 #ifdef CONFIG_TESTING_OPTIONS
8193 static int cmd_reply_handler(struct nl_msg *msg, void *arg)
8194 {
8195 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
8196 	struct wpabuf *buf = arg;
8197 
8198 	if (!buf)
8199 		return NL_SKIP;
8200 
8201 	if ((size_t) genlmsg_attrlen(gnlh, 0) > wpabuf_tailroom(buf)) {
8202 		wpa_printf(MSG_INFO, "nl80211: insufficient buffer space for reply");
8203 		return NL_SKIP;
8204 	}
8205 
8206 	wpabuf_put_data(buf, genlmsg_attrdata(gnlh, 0),
8207 			genlmsg_attrlen(gnlh, 0));
8208 
8209 	return NL_SKIP;
8210 }
8211 #endif /* CONFIG_TESTING_OPTIONS */
8212 
8213 
8214 static int vendor_reply_handler(struct nl_msg *msg, void *arg)
8215 {
8216 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
8217 	struct nlattr *nl_vendor_reply, *nl;
8218 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
8219 	struct wpabuf *buf = arg;
8220 	int rem;
8221 
8222 	if (!buf)
8223 		return NL_SKIP;
8224 
8225 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
8226 		  genlmsg_attrlen(gnlh, 0), NULL);
8227 	nl_vendor_reply = tb[NL80211_ATTR_VENDOR_DATA];
8228 
8229 	if (!nl_vendor_reply)
8230 		return NL_SKIP;
8231 
8232 	if ((size_t) nla_len(nl_vendor_reply) > wpabuf_tailroom(buf)) {
8233 		wpa_printf(MSG_INFO, "nl80211: Vendor command: insufficient buffer space for reply");
8234 		return NL_SKIP;
8235 	}
8236 
8237 	nla_for_each_nested(nl, nl_vendor_reply, rem) {
8238 		wpabuf_put_data(buf, nla_data(nl), nla_len(nl));
8239 	}
8240 
8241 	return NL_SKIP;
8242 }
8243 
8244 
8245 static int nl80211_vendor_cmd(void *priv, unsigned int vendor_id,
8246 			      unsigned int subcmd, const u8 *data,
8247 			      size_t data_len, struct wpabuf *buf)
8248 {
8249 	struct i802_bss *bss = priv;
8250 	struct wpa_driver_nl80211_data *drv = bss->drv;
8251 	struct nl_msg *msg;
8252 	int ret;
8253 
8254 #ifdef CONFIG_TESTING_OPTIONS
8255 	if (vendor_id == 0xffffffff) {
8256 		msg = nlmsg_alloc();
8257 		if (!msg)
8258 			return -ENOMEM;
8259 
8260 		nl80211_cmd(drv, msg, 0, subcmd);
8261 		if (nlmsg_append(msg, (void *) data, data_len, NLMSG_ALIGNTO) <
8262 		    0)
8263 			goto fail;
8264 		ret = send_and_recv_msgs(drv, msg, cmd_reply_handler, buf);
8265 		if (ret)
8266 			wpa_printf(MSG_DEBUG, "nl80211: command failed err=%d",
8267 				   ret);
8268 		return ret;
8269 	}
8270 #endif /* CONFIG_TESTING_OPTIONS */
8271 
8272 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_VENDOR)) ||
8273 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, vendor_id) ||
8274 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD, subcmd) ||
8275 	    (data &&
8276 	     nla_put(msg, NL80211_ATTR_VENDOR_DATA, data_len, data)))
8277 		goto fail;
8278 
8279 	ret = send_and_recv_msgs(drv, msg, vendor_reply_handler, buf);
8280 	if (ret)
8281 		wpa_printf(MSG_DEBUG, "nl80211: vendor command failed err=%d",
8282 			   ret);
8283 	return ret;
8284 
8285 fail:
8286 	nlmsg_free(msg);
8287 	return -ENOBUFS;
8288 }
8289 
8290 
8291 static int nl80211_set_qos_map(void *priv, const u8 *qos_map_set,
8292 			       u8 qos_map_set_len)
8293 {
8294 	struct i802_bss *bss = priv;
8295 	struct wpa_driver_nl80211_data *drv = bss->drv;
8296 	struct nl_msg *msg;
8297 	int ret;
8298 
8299 	wpa_hexdump(MSG_DEBUG, "nl80211: Setting QoS Map",
8300 		    qos_map_set, qos_map_set_len);
8301 
8302 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_SET_QOS_MAP)) ||
8303 	    nla_put(msg, NL80211_ATTR_QOS_MAP, qos_map_set_len, qos_map_set)) {
8304 		nlmsg_free(msg);
8305 		return -ENOBUFS;
8306 	}
8307 
8308 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8309 	if (ret)
8310 		wpa_printf(MSG_DEBUG, "nl80211: Setting QoS Map failed");
8311 
8312 	return ret;
8313 }
8314 
8315 
8316 static int nl80211_set_wowlan(void *priv,
8317 			      const struct wowlan_triggers *triggers)
8318 {
8319 	struct i802_bss *bss = priv;
8320 	struct wpa_driver_nl80211_data *drv = bss->drv;
8321 	struct nl_msg *msg;
8322 	struct nlattr *wowlan_triggers;
8323 	int ret;
8324 
8325 	wpa_printf(MSG_DEBUG, "nl80211: Setting wowlan");
8326 
8327 	if (!(msg = nl80211_cmd_msg(bss, 0, NL80211_CMD_SET_WOWLAN)) ||
8328 	    !(wowlan_triggers = nla_nest_start(msg,
8329 					       NL80211_ATTR_WOWLAN_TRIGGERS)) ||
8330 	    (triggers->any &&
8331 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
8332 	    (triggers->disconnect &&
8333 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
8334 	    (triggers->magic_pkt &&
8335 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
8336 	    (triggers->gtk_rekey_failure &&
8337 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
8338 	    (triggers->eap_identity_req &&
8339 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
8340 	    (triggers->four_way_handshake &&
8341 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
8342 	    (triggers->rfkill_release &&
8343 	     nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))) {
8344 		nlmsg_free(msg);
8345 		return -ENOBUFS;
8346 	}
8347 
8348 	nla_nest_end(msg, wowlan_triggers);
8349 
8350 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8351 	if (ret)
8352 		wpa_printf(MSG_DEBUG, "nl80211: Setting wowlan failed");
8353 
8354 	return ret;
8355 }
8356 
8357 
8358 #ifdef CONFIG_DRIVER_NL80211_QCA
8359 static int nl80211_roaming(void *priv, int allowed, const u8 *bssid)
8360 {
8361 	struct i802_bss *bss = priv;
8362 	struct wpa_driver_nl80211_data *drv = bss->drv;
8363 	struct nl_msg *msg;
8364 	struct nlattr *params;
8365 
8366 	wpa_printf(MSG_DEBUG, "nl80211: Roaming policy: allowed=%d", allowed);
8367 
8368 	if (!drv->roaming_vendor_cmd_avail) {
8369 		wpa_printf(MSG_DEBUG,
8370 			   "nl80211: Ignore roaming policy change since driver does not provide command for setting it");
8371 		return -1;
8372 	}
8373 
8374 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
8375 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
8376 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
8377 			QCA_NL80211_VENDOR_SUBCMD_ROAMING) ||
8378 	    !(params = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA)) ||
8379 	    nla_put_u32(msg, QCA_WLAN_VENDOR_ATTR_ROAMING_POLICY,
8380 			allowed ? QCA_ROAMING_ALLOWED_WITHIN_ESS :
8381 			QCA_ROAMING_NOT_ALLOWED) ||
8382 	    (bssid &&
8383 	     nla_put(msg, QCA_WLAN_VENDOR_ATTR_MAC_ADDR, ETH_ALEN, bssid))) {
8384 		nlmsg_free(msg);
8385 		return -1;
8386 	}
8387 	nla_nest_end(msg, params);
8388 
8389 	return send_and_recv_msgs(drv, msg, NULL, NULL);
8390 }
8391 #endif /* CONFIG_DRIVER_NL80211_QCA */
8392 
8393 
8394 static int nl80211_set_mac_addr(void *priv, const u8 *addr)
8395 {
8396 	struct i802_bss *bss = priv;
8397 	struct wpa_driver_nl80211_data *drv = bss->drv;
8398 	int new_addr = addr != NULL;
8399 
8400 	if (TEST_FAIL())
8401 		return -1;
8402 
8403 	if (!addr)
8404 		addr = drv->perm_addr;
8405 
8406 	if (linux_set_iface_flags(drv->global->ioctl_sock, bss->ifname, 0) < 0)
8407 		return -1;
8408 
8409 	if (linux_set_ifhwaddr(drv->global->ioctl_sock, bss->ifname, addr) < 0)
8410 	{
8411 		wpa_printf(MSG_DEBUG,
8412 			   "nl80211: failed to set_mac_addr for %s to " MACSTR,
8413 			   bss->ifname, MAC2STR(addr));
8414 		if (linux_set_iface_flags(drv->global->ioctl_sock, bss->ifname,
8415 					  1) < 0) {
8416 			wpa_printf(MSG_DEBUG,
8417 				   "nl80211: Could not restore interface UP after failed set_mac_addr");
8418 		}
8419 		return -1;
8420 	}
8421 
8422 	wpa_printf(MSG_DEBUG, "nl80211: set_mac_addr for %s to " MACSTR,
8423 		   bss->ifname, MAC2STR(addr));
8424 	drv->addr_changed = new_addr;
8425 	os_memcpy(bss->addr, addr, ETH_ALEN);
8426 
8427 	if (linux_set_iface_flags(drv->global->ioctl_sock, bss->ifname, 1) < 0)
8428 	{
8429 		wpa_printf(MSG_DEBUG,
8430 			   "nl80211: Could not restore interface UP after set_mac_addr");
8431 	}
8432 
8433 	return 0;
8434 }
8435 
8436 
8437 #ifdef CONFIG_MESH
8438 
8439 static int wpa_driver_nl80211_init_mesh(void *priv)
8440 {
8441 	if (wpa_driver_nl80211_set_mode(priv, NL80211_IFTYPE_MESH_POINT)) {
8442 		wpa_printf(MSG_INFO,
8443 			   "nl80211: Failed to set interface into mesh mode");
8444 		return -1;
8445 	}
8446 	return 0;
8447 }
8448 
8449 
8450 static int nl80211_put_mesh_id(struct nl_msg *msg, const u8 *mesh_id,
8451 			       size_t mesh_id_len)
8452 {
8453 	if (mesh_id) {
8454 		wpa_hexdump_ascii(MSG_DEBUG, "  * Mesh ID (SSID)",
8455 				  mesh_id, mesh_id_len);
8456 		return nla_put(msg, NL80211_ATTR_MESH_ID, mesh_id_len, mesh_id);
8457 	}
8458 
8459 	return 0;
8460 }
8461 
8462 
8463 static int nl80211_put_mesh_config(struct nl_msg *msg,
8464 				   struct wpa_driver_mesh_bss_params *params)
8465 {
8466 	struct nlattr *container;
8467 
8468 	container = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
8469 	if (!container)
8470 		return -1;
8471 
8472 	if (((params->flags & WPA_DRIVER_MESH_CONF_FLAG_AUTO_PLINKS) &&
8473 	     nla_put_u32(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
8474 			 params->auto_plinks)) ||
8475 	    ((params->flags & WPA_DRIVER_MESH_CONF_FLAG_MAX_PEER_LINKS) &&
8476 	     nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
8477 			 params->max_peer_links)))
8478 		return -1;
8479 
8480 	/*
8481 	 * Set NL80211_MESHCONF_PLINK_TIMEOUT even if user mpm is used because
8482 	 * the timer could disconnect stations even in that case.
8483 	 */
8484 	if ((params->flags & WPA_DRIVER_MESH_CONF_FLAG_PEER_LINK_TIMEOUT) &&
8485 	    nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
8486 			params->peer_link_timeout)) {
8487 		wpa_printf(MSG_ERROR, "nl80211: Failed to set PLINK_TIMEOUT");
8488 		return -1;
8489 	}
8490 
8491 	if ((params->flags & WPA_DRIVER_MESH_CONF_FLAG_HT_OP_MODE) &&
8492 	    nla_put_u16(msg, NL80211_MESHCONF_HT_OPMODE, params->ht_opmode)) {
8493 		wpa_printf(MSG_ERROR, "nl80211: Failed to set HT_OP_MODE");
8494 		return -1;
8495 	}
8496 
8497 	nla_nest_end(msg, container);
8498 
8499 	return 0;
8500 }
8501 
8502 
8503 static int nl80211_join_mesh(struct i802_bss *bss,
8504 			     struct wpa_driver_mesh_join_params *params)
8505 {
8506 	struct wpa_driver_nl80211_data *drv = bss->drv;
8507 	struct nl_msg *msg;
8508 	struct nlattr *container;
8509 	int ret = -1;
8510 
8511 	wpa_printf(MSG_DEBUG, "nl80211: mesh join (ifindex=%d)", drv->ifindex);
8512 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_JOIN_MESH);
8513 	if (!msg ||
8514 	    nl80211_put_freq_params(msg, &params->freq) ||
8515 	    nl80211_put_basic_rates(msg, params->basic_rates) ||
8516 	    nl80211_put_mesh_id(msg, params->meshid, params->meshid_len) ||
8517 	    nl80211_put_beacon_int(msg, params->beacon_int) ||
8518 	    nl80211_put_dtim_period(msg, params->dtim_period))
8519 		goto fail;
8520 
8521 	wpa_printf(MSG_DEBUG, "  * flags=%08X", params->flags);
8522 
8523 	container = nla_nest_start(msg, NL80211_ATTR_MESH_SETUP);
8524 	if (!container)
8525 		goto fail;
8526 
8527 	if (params->ies) {
8528 		wpa_hexdump(MSG_DEBUG, "  * IEs", params->ies, params->ie_len);
8529 		if (nla_put(msg, NL80211_MESH_SETUP_IE, params->ie_len,
8530 			    params->ies))
8531 			goto fail;
8532 	}
8533 	/* WPA_DRIVER_MESH_FLAG_OPEN_AUTH is treated as default by nl80211 */
8534 	if (params->flags & WPA_DRIVER_MESH_FLAG_SAE_AUTH) {
8535 		if (nla_put_u8(msg, NL80211_MESH_SETUP_AUTH_PROTOCOL, 0x1) ||
8536 		    nla_put_flag(msg, NL80211_MESH_SETUP_USERSPACE_AUTH))
8537 			goto fail;
8538 	}
8539 	if ((params->flags & WPA_DRIVER_MESH_FLAG_AMPE) &&
8540 	    nla_put_flag(msg, NL80211_MESH_SETUP_USERSPACE_AMPE))
8541 		goto fail;
8542 	if ((params->flags & WPA_DRIVER_MESH_FLAG_USER_MPM) &&
8543 	    nla_put_flag(msg, NL80211_MESH_SETUP_USERSPACE_MPM))
8544 		goto fail;
8545 	nla_nest_end(msg, container);
8546 
8547 	params->conf.flags |= WPA_DRIVER_MESH_CONF_FLAG_AUTO_PLINKS;
8548 	params->conf.flags |= WPA_DRIVER_MESH_CONF_FLAG_PEER_LINK_TIMEOUT;
8549 	params->conf.flags |= WPA_DRIVER_MESH_CONF_FLAG_MAX_PEER_LINKS;
8550 	if (nl80211_put_mesh_config(msg, &params->conf) < 0)
8551 		goto fail;
8552 
8553 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8554 	msg = NULL;
8555 	if (ret) {
8556 		wpa_printf(MSG_DEBUG, "nl80211: mesh join failed: ret=%d (%s)",
8557 			   ret, strerror(-ret));
8558 		goto fail;
8559 	}
8560 	ret = 0;
8561 	drv->assoc_freq = bss->freq = params->freq.freq;
8562 	wpa_printf(MSG_DEBUG, "nl80211: mesh join request send successfully");
8563 
8564 fail:
8565 	nlmsg_free(msg);
8566 	return ret;
8567 }
8568 
8569 
8570 static int
8571 wpa_driver_nl80211_join_mesh(void *priv,
8572 			     struct wpa_driver_mesh_join_params *params)
8573 {
8574 	struct i802_bss *bss = priv;
8575 	int ret, timeout;
8576 
8577 	timeout = params->conf.peer_link_timeout;
8578 
8579 	/* Disable kernel inactivity timer */
8580 	if (params->flags & WPA_DRIVER_MESH_FLAG_USER_MPM)
8581 		params->conf.peer_link_timeout = 0;
8582 
8583 	ret = nl80211_join_mesh(bss, params);
8584 	if (ret == -EINVAL && params->conf.peer_link_timeout == 0) {
8585 		wpa_printf(MSG_DEBUG,
8586 			   "nl80211: Mesh join retry for peer_link_timeout");
8587 		/*
8588 		 * Old kernel does not support setting
8589 		 * NL80211_MESHCONF_PLINK_TIMEOUT to zero, so set 60 seconds
8590 		 * into future from peer_link_timeout.
8591 		 */
8592 		params->conf.peer_link_timeout = timeout + 60;
8593 		ret = nl80211_join_mesh(priv, params);
8594 	}
8595 
8596 	params->conf.peer_link_timeout = timeout;
8597 	return ret;
8598 }
8599 
8600 
8601 static int wpa_driver_nl80211_leave_mesh(void *priv)
8602 {
8603 	struct i802_bss *bss = priv;
8604 	struct wpa_driver_nl80211_data *drv = bss->drv;
8605 	struct nl_msg *msg;
8606 	int ret;
8607 
8608 	wpa_printf(MSG_DEBUG, "nl80211: mesh leave (ifindex=%d)", drv->ifindex);
8609 	msg = nl80211_drv_msg(drv, 0, NL80211_CMD_LEAVE_MESH);
8610 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8611 	if (ret) {
8612 		wpa_printf(MSG_DEBUG, "nl80211: mesh leave failed: ret=%d (%s)",
8613 			   ret, strerror(-ret));
8614 	} else {
8615 		wpa_printf(MSG_DEBUG,
8616 			   "nl80211: mesh leave request send successfully");
8617 	}
8618 
8619 	if (wpa_driver_nl80211_set_mode(drv->first_bss,
8620 					NL80211_IFTYPE_STATION)) {
8621 		wpa_printf(MSG_INFO,
8622 			   "nl80211: Failed to set interface into station mode");
8623 	}
8624 	return ret;
8625 }
8626 
8627 #endif /* CONFIG_MESH */
8628 
8629 
8630 static int wpa_driver_br_add_ip_neigh(void *priv, u8 version,
8631 				      const u8 *ipaddr, int prefixlen,
8632 				      const u8 *addr)
8633 {
8634 #ifdef CONFIG_LIBNL3_ROUTE
8635 	struct i802_bss *bss = priv;
8636 	struct wpa_driver_nl80211_data *drv = bss->drv;
8637 	struct rtnl_neigh *rn;
8638 	struct nl_addr *nl_ipaddr = NULL;
8639 	struct nl_addr *nl_lladdr = NULL;
8640 	int family, addrsize;
8641 	int res;
8642 
8643 	if (!ipaddr || prefixlen == 0 || !addr)
8644 		return -EINVAL;
8645 
8646 	if (bss->br_ifindex == 0) {
8647 		wpa_printf(MSG_DEBUG,
8648 			   "nl80211: bridge must be set before adding an ip neigh to it");
8649 		return -1;
8650 	}
8651 
8652 	if (!drv->rtnl_sk) {
8653 		wpa_printf(MSG_DEBUG,
8654 			   "nl80211: nl_sock for NETLINK_ROUTE is not initialized");
8655 		return -1;
8656 	}
8657 
8658 	if (version == 4) {
8659 		family = AF_INET;
8660 		addrsize = 4;
8661 	} else if (version == 6) {
8662 		family = AF_INET6;
8663 		addrsize = 16;
8664 	} else {
8665 		return -EINVAL;
8666 	}
8667 
8668 	rn = rtnl_neigh_alloc();
8669 	if (rn == NULL)
8670 		return -ENOMEM;
8671 
8672 	/* set the destination ip address for neigh */
8673 	nl_ipaddr = nl_addr_build(family, (void *) ipaddr, addrsize);
8674 	if (nl_ipaddr == NULL) {
8675 		wpa_printf(MSG_DEBUG, "nl80211: nl_ipaddr build failed");
8676 		res = -ENOMEM;
8677 		goto errout;
8678 	}
8679 	nl_addr_set_prefixlen(nl_ipaddr, prefixlen);
8680 	res = rtnl_neigh_set_dst(rn, nl_ipaddr);
8681 	if (res) {
8682 		wpa_printf(MSG_DEBUG,
8683 			   "nl80211: neigh set destination addr failed");
8684 		goto errout;
8685 	}
8686 
8687 	/* set the corresponding lladdr for neigh */
8688 	nl_lladdr = nl_addr_build(AF_BRIDGE, (u8 *) addr, ETH_ALEN);
8689 	if (nl_lladdr == NULL) {
8690 		wpa_printf(MSG_DEBUG, "nl80211: neigh set lladdr failed");
8691 		res = -ENOMEM;
8692 		goto errout;
8693 	}
8694 	rtnl_neigh_set_lladdr(rn, nl_lladdr);
8695 
8696 	rtnl_neigh_set_ifindex(rn, bss->br_ifindex);
8697 	rtnl_neigh_set_state(rn, NUD_PERMANENT);
8698 
8699 	res = rtnl_neigh_add(drv->rtnl_sk, rn, NLM_F_CREATE);
8700 	if (res) {
8701 		wpa_printf(MSG_DEBUG,
8702 			   "nl80211: Adding bridge ip neigh failed: %s",
8703 			   strerror(errno));
8704 	}
8705 errout:
8706 	if (nl_lladdr)
8707 		nl_addr_put(nl_lladdr);
8708 	if (nl_ipaddr)
8709 		nl_addr_put(nl_ipaddr);
8710 	if (rn)
8711 		rtnl_neigh_put(rn);
8712 	return res;
8713 #else /* CONFIG_LIBNL3_ROUTE */
8714 	return -1;
8715 #endif /* CONFIG_LIBNL3_ROUTE */
8716 }
8717 
8718 
8719 static int wpa_driver_br_delete_ip_neigh(void *priv, u8 version,
8720 					 const u8 *ipaddr)
8721 {
8722 #ifdef CONFIG_LIBNL3_ROUTE
8723 	struct i802_bss *bss = priv;
8724 	struct wpa_driver_nl80211_data *drv = bss->drv;
8725 	struct rtnl_neigh *rn;
8726 	struct nl_addr *nl_ipaddr;
8727 	int family, addrsize;
8728 	int res;
8729 
8730 	if (!ipaddr)
8731 		return -EINVAL;
8732 
8733 	if (version == 4) {
8734 		family = AF_INET;
8735 		addrsize = 4;
8736 	} else if (version == 6) {
8737 		family = AF_INET6;
8738 		addrsize = 16;
8739 	} else {
8740 		return -EINVAL;
8741 	}
8742 
8743 	if (bss->br_ifindex == 0) {
8744 		wpa_printf(MSG_DEBUG,
8745 			   "nl80211: bridge must be set to delete an ip neigh");
8746 		return -1;
8747 	}
8748 
8749 	if (!drv->rtnl_sk) {
8750 		wpa_printf(MSG_DEBUG,
8751 			   "nl80211: nl_sock for NETLINK_ROUTE is not initialized");
8752 		return -1;
8753 	}
8754 
8755 	rn = rtnl_neigh_alloc();
8756 	if (rn == NULL)
8757 		return -ENOMEM;
8758 
8759 	/* set the destination ip address for neigh */
8760 	nl_ipaddr = nl_addr_build(family, (void *) ipaddr, addrsize);
8761 	if (nl_ipaddr == NULL) {
8762 		wpa_printf(MSG_DEBUG, "nl80211: nl_ipaddr build failed");
8763 		res = -ENOMEM;
8764 		goto errout;
8765 	}
8766 	res = rtnl_neigh_set_dst(rn, nl_ipaddr);
8767 	if (res) {
8768 		wpa_printf(MSG_DEBUG,
8769 			   "nl80211: neigh set destination addr failed");
8770 		goto errout;
8771 	}
8772 
8773 	rtnl_neigh_set_ifindex(rn, bss->br_ifindex);
8774 
8775 	res = rtnl_neigh_delete(drv->rtnl_sk, rn, 0);
8776 	if (res) {
8777 		wpa_printf(MSG_DEBUG,
8778 			   "nl80211: Deleting bridge ip neigh failed: %s",
8779 			   strerror(errno));
8780 	}
8781 errout:
8782 	if (nl_ipaddr)
8783 		nl_addr_put(nl_ipaddr);
8784 	if (rn)
8785 		rtnl_neigh_put(rn);
8786 	return res;
8787 #else /* CONFIG_LIBNL3_ROUTE */
8788 	return -1;
8789 #endif /* CONFIG_LIBNL3_ROUTE */
8790 }
8791 
8792 
8793 static int linux_write_system_file(const char *path, unsigned int val)
8794 {
8795 	char buf[50];
8796 	int fd, len;
8797 
8798 	len = os_snprintf(buf, sizeof(buf), "%u\n", val);
8799 	if (os_snprintf_error(sizeof(buf), len))
8800 		return -1;
8801 
8802 	fd = open(path, O_WRONLY);
8803 	if (fd < 0)
8804 		return -1;
8805 
8806 	if (write(fd, buf, len) < 0) {
8807 		wpa_printf(MSG_DEBUG,
8808 			   "nl80211: Failed to write Linux system file: %s with the value of %d",
8809 			   path, val);
8810 		close(fd);
8811 		return -1;
8812 	}
8813 	close(fd);
8814 
8815 	return 0;
8816 }
8817 
8818 
8819 static const char * drv_br_port_attr_str(enum drv_br_port_attr attr)
8820 {
8821 	switch (attr) {
8822 	case DRV_BR_PORT_ATTR_PROXYARP:
8823 		return "proxyarp_wifi";
8824 	case DRV_BR_PORT_ATTR_HAIRPIN_MODE:
8825 		return "hairpin_mode";
8826 	}
8827 
8828 	return NULL;
8829 }
8830 
8831 
8832 static int wpa_driver_br_port_set_attr(void *priv, enum drv_br_port_attr attr,
8833 				       unsigned int val)
8834 {
8835 	struct i802_bss *bss = priv;
8836 	char path[128];
8837 	const char *attr_txt;
8838 
8839 	attr_txt = drv_br_port_attr_str(attr);
8840 	if (attr_txt == NULL)
8841 		return -EINVAL;
8842 
8843 	os_snprintf(path, sizeof(path), "/sys/class/net/%s/brport/%s",
8844 		    bss->ifname, attr_txt);
8845 
8846 	if (linux_write_system_file(path, val))
8847 		return -1;
8848 
8849 	return 0;
8850 }
8851 
8852 
8853 static const char * drv_br_net_param_str(enum drv_br_net_param param)
8854 {
8855 	switch (param) {
8856 	case DRV_BR_NET_PARAM_GARP_ACCEPT:
8857 		return "arp_accept";
8858 	default:
8859 		return NULL;
8860 	}
8861 }
8862 
8863 
8864 static int wpa_driver_br_set_net_param(void *priv, enum drv_br_net_param param,
8865 				       unsigned int val)
8866 {
8867 	struct i802_bss *bss = priv;
8868 	char path[128];
8869 	const char *param_txt;
8870 	int ip_version = 4;
8871 
8872 	if (param == DRV_BR_MULTICAST_SNOOPING) {
8873 		os_snprintf(path, sizeof(path),
8874 			    "/sys/devices/virtual/net/%s/bridge/multicast_snooping",
8875 			    bss->brname);
8876 		goto set_val;
8877 	}
8878 
8879 	param_txt = drv_br_net_param_str(param);
8880 	if (param_txt == NULL)
8881 		return -EINVAL;
8882 
8883 	switch (param) {
8884 		case DRV_BR_NET_PARAM_GARP_ACCEPT:
8885 			ip_version = 4;
8886 			break;
8887 		default:
8888 			return -EINVAL;
8889 	}
8890 
8891 	os_snprintf(path, sizeof(path), "/proc/sys/net/ipv%d/conf/%s/%s",
8892 		    ip_version, bss->brname, param_txt);
8893 
8894 set_val:
8895 	if (linux_write_system_file(path, val))
8896 		return -1;
8897 
8898 	return 0;
8899 }
8900 
8901 
8902 #ifdef CONFIG_DRIVER_NL80211_QCA
8903 
8904 static int hw_mode_to_qca_acs(enum hostapd_hw_mode hw_mode)
8905 {
8906 	switch (hw_mode) {
8907 	case HOSTAPD_MODE_IEEE80211B:
8908 		return QCA_ACS_MODE_IEEE80211B;
8909 	case HOSTAPD_MODE_IEEE80211G:
8910 		return QCA_ACS_MODE_IEEE80211G;
8911 	case HOSTAPD_MODE_IEEE80211A:
8912 		return QCA_ACS_MODE_IEEE80211A;
8913 	case HOSTAPD_MODE_IEEE80211AD:
8914 		return QCA_ACS_MODE_IEEE80211AD;
8915 	case HOSTAPD_MODE_IEEE80211ANY:
8916 		return QCA_ACS_MODE_IEEE80211ANY;
8917 	default:
8918 		return -1;
8919 	}
8920 }
8921 
8922 
8923 static int add_acs_freq_list(struct nl_msg *msg, const int *freq_list)
8924 {
8925 	int i, len, ret;
8926 	u32 *freqs;
8927 
8928 	if (!freq_list)
8929 		return 0;
8930 	len = int_array_len(freq_list);
8931 	freqs = os_malloc(sizeof(u32) * len);
8932 	if (!freqs)
8933 		return -1;
8934 	for (i = 0; i < len; i++)
8935 		freqs[i] = freq_list[i];
8936 	ret = nla_put(msg, QCA_WLAN_VENDOR_ATTR_ACS_FREQ_LIST,
8937 		      sizeof(u32) * len, freqs);
8938 	os_free(freqs);
8939 	return ret;
8940 }
8941 
8942 
8943 static int wpa_driver_do_acs(void *priv, struct drv_acs_params *params)
8944 {
8945 	struct i802_bss *bss = priv;
8946 	struct wpa_driver_nl80211_data *drv = bss->drv;
8947 	struct nl_msg *msg;
8948 	struct nlattr *data;
8949 	int ret;
8950 	int mode;
8951 
8952 	mode = hw_mode_to_qca_acs(params->hw_mode);
8953 	if (mode < 0)
8954 		return -1;
8955 
8956 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
8957 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
8958 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
8959 			QCA_NL80211_VENDOR_SUBCMD_DO_ACS) ||
8960 	    !(data = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA)) ||
8961 	    nla_put_u8(msg, QCA_WLAN_VENDOR_ATTR_ACS_HW_MODE, mode) ||
8962 	    (params->ht_enabled &&
8963 	     nla_put_flag(msg, QCA_WLAN_VENDOR_ATTR_ACS_HT_ENABLED)) ||
8964 	    (params->ht40_enabled &&
8965 	     nla_put_flag(msg, QCA_WLAN_VENDOR_ATTR_ACS_HT40_ENABLED)) ||
8966 	    (params->vht_enabled &&
8967 	     nla_put_flag(msg, QCA_WLAN_VENDOR_ATTR_ACS_VHT_ENABLED)) ||
8968 	    nla_put_u16(msg, QCA_WLAN_VENDOR_ATTR_ACS_CHWIDTH,
8969 			params->ch_width) ||
8970 	    (params->ch_list_len &&
8971 	     nla_put(msg, QCA_WLAN_VENDOR_ATTR_ACS_CH_LIST, params->ch_list_len,
8972 		     params->ch_list)) ||
8973 	    add_acs_freq_list(msg, params->freq_list)) {
8974 		nlmsg_free(msg);
8975 		return -ENOBUFS;
8976 	}
8977 	nla_nest_end(msg, data);
8978 
8979 	wpa_printf(MSG_DEBUG,
8980 		   "nl80211: ACS Params: HW_MODE: %d HT: %d HT40: %d VHT: %d BW: %d CH_LIST_LEN: %u",
8981 		   params->hw_mode, params->ht_enabled, params->ht40_enabled,
8982 		   params->vht_enabled, params->ch_width, params->ch_list_len);
8983 
8984 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
8985 	if (ret) {
8986 		wpa_printf(MSG_DEBUG,
8987 			   "nl80211: Failed to invoke driver ACS function: %s",
8988 			   strerror(errno));
8989 	}
8990 	return ret;
8991 }
8992 
8993 
8994 static int nl80211_set_band(void *priv, enum set_band band)
8995 {
8996 	struct i802_bss *bss = priv;
8997 	struct wpa_driver_nl80211_data *drv = bss->drv;
8998 	struct nl_msg *msg;
8999 	struct nlattr *data;
9000 	int ret;
9001 	enum qca_set_band qca_band;
9002 
9003 	if (!drv->setband_vendor_cmd_avail)
9004 		return -1;
9005 
9006 	switch (band) {
9007 	case WPA_SETBAND_AUTO:
9008 		qca_band = QCA_SETBAND_AUTO;
9009 		break;
9010 	case WPA_SETBAND_5G:
9011 		qca_band = QCA_SETBAND_5G;
9012 		break;
9013 	case WPA_SETBAND_2G:
9014 		qca_band = QCA_SETBAND_2G;
9015 		break;
9016 	default:
9017 		return -1;
9018 	}
9019 
9020 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
9021 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
9022 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
9023 			QCA_NL80211_VENDOR_SUBCMD_SETBAND) ||
9024 	    !(data = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA)) ||
9025 	    nla_put_u32(msg, QCA_WLAN_VENDOR_ATTR_SETBAND_VALUE, qca_band)) {
9026 		nlmsg_free(msg);
9027 		return -ENOBUFS;
9028 	}
9029 	nla_nest_end(msg, data);
9030 
9031 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
9032 	if (ret) {
9033 		wpa_printf(MSG_DEBUG,
9034 			   "nl80211: Driver setband function failed: %s",
9035 			   strerror(errno));
9036 	}
9037 	return ret;
9038 }
9039 
9040 
9041 struct nl80211_pcl {
9042 	unsigned int num;
9043 	unsigned int *freq_list;
9044 };
9045 
9046 static int preferred_freq_info_handler(struct nl_msg *msg, void *arg)
9047 {
9048 	struct nlattr *tb[NL80211_ATTR_MAX + 1];
9049 	struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
9050 	struct nl80211_pcl *param = arg;
9051 	struct nlattr *nl_vend, *attr;
9052 	enum qca_iface_type iface_type;
9053 	struct nlattr *tb_vendor[QCA_WLAN_VENDOR_ATTR_MAX + 1];
9054 	unsigned int num, max_num;
9055 	u32 *freqs;
9056 
9057 	nla_parse(tb, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
9058 		  genlmsg_attrlen(gnlh, 0), NULL);
9059 
9060 	nl_vend = tb[NL80211_ATTR_VENDOR_DATA];
9061 	if (!nl_vend)
9062 		return NL_SKIP;
9063 
9064 	nla_parse(tb_vendor, QCA_WLAN_VENDOR_ATTR_MAX,
9065 		  nla_data(nl_vend), nla_len(nl_vend), NULL);
9066 
9067 	attr = tb_vendor[
9068 		QCA_WLAN_VENDOR_ATTR_GET_PREFERRED_FREQ_LIST_IFACE_TYPE];
9069 	if (!attr) {
9070 		wpa_printf(MSG_ERROR, "nl80211: iface_type couldn't be found");
9071 		param->num = 0;
9072 		return NL_SKIP;
9073 	}
9074 
9075 	iface_type = (enum qca_iface_type) nla_get_u32(attr);
9076 	wpa_printf(MSG_DEBUG, "nl80211: Driver returned iface_type=%d",
9077 		   iface_type);
9078 
9079 	attr = tb_vendor[QCA_WLAN_VENDOR_ATTR_GET_PREFERRED_FREQ_LIST];
9080 	if (!attr) {
9081 		wpa_printf(MSG_ERROR,
9082 			   "nl80211: preferred_freq_list couldn't be found");
9083 		param->num = 0;
9084 		return NL_SKIP;
9085 	}
9086 
9087 	/*
9088 	 * param->num has the maximum number of entries for which there
9089 	 * is room in the freq_list provided by the caller.
9090 	 */
9091 	freqs = nla_data(attr);
9092 	max_num = nla_len(attr) / sizeof(u32);
9093 	if (max_num > param->num)
9094 		max_num = param->num;
9095 	for (num = 0; num < max_num; num++)
9096 		param->freq_list[num] = freqs[num];
9097 	param->num = num;
9098 
9099 	return NL_SKIP;
9100 }
9101 
9102 
9103 static int nl80211_get_pref_freq_list(void *priv,
9104 				      enum wpa_driver_if_type if_type,
9105 				      unsigned int *num,
9106 				      unsigned int *freq_list)
9107 {
9108 	struct i802_bss *bss = priv;
9109 	struct wpa_driver_nl80211_data *drv = bss->drv;
9110 	struct nl_msg *msg;
9111 	int ret;
9112 	unsigned int i;
9113 	struct nlattr *params;
9114 	struct nl80211_pcl param;
9115 	enum qca_iface_type iface_type;
9116 
9117 	if (!drv->get_pref_freq_list)
9118 		return -1;
9119 
9120 	switch (if_type) {
9121 	case WPA_IF_STATION:
9122 		iface_type = QCA_IFACE_TYPE_STA;
9123 		break;
9124 	case WPA_IF_AP_BSS:
9125 		iface_type = QCA_IFACE_TYPE_AP;
9126 		break;
9127 	case WPA_IF_P2P_GO:
9128 		iface_type = QCA_IFACE_TYPE_P2P_GO;
9129 		break;
9130 	case WPA_IF_P2P_CLIENT:
9131 		iface_type = QCA_IFACE_TYPE_P2P_CLIENT;
9132 		break;
9133 	case WPA_IF_IBSS:
9134 		iface_type = QCA_IFACE_TYPE_IBSS;
9135 		break;
9136 	case WPA_IF_TDLS:
9137 		iface_type = QCA_IFACE_TYPE_TDLS;
9138 		break;
9139 	default:
9140 		return -1;
9141 	}
9142 
9143 	param.num = *num;
9144 	param.freq_list = freq_list;
9145 
9146 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
9147 	    nla_put_u32(msg, NL80211_ATTR_IFINDEX, drv->ifindex) ||
9148 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
9149 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
9150 			QCA_NL80211_VENDOR_SUBCMD_GET_PREFERRED_FREQ_LIST) ||
9151 	    !(params = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA)) ||
9152 	    nla_put_u32(msg,
9153 			QCA_WLAN_VENDOR_ATTR_GET_PREFERRED_FREQ_LIST_IFACE_TYPE,
9154 			iface_type)) {
9155 		wpa_printf(MSG_ERROR,
9156 			   "%s: err in adding vendor_cmd and vendor_data",
9157 			   __func__);
9158 		nlmsg_free(msg);
9159 		return -1;
9160 	}
9161 	nla_nest_end(msg, params);
9162 
9163 	os_memset(freq_list, 0, *num * sizeof(freq_list[0]));
9164 	ret = send_and_recv_msgs(drv, msg, preferred_freq_info_handler, &param);
9165 	if (ret) {
9166 		wpa_printf(MSG_ERROR,
9167 			   "%s: err in send_and_recv_msgs", __func__);
9168 		return ret;
9169 	}
9170 
9171 	*num = param.num;
9172 
9173 	for (i = 0; i < *num; i++) {
9174 		wpa_printf(MSG_DEBUG, "nl80211: preferred_channel_list[%d]=%d",
9175 			   i, freq_list[i]);
9176 	}
9177 
9178 	return 0;
9179 }
9180 
9181 
9182 static int nl80211_set_prob_oper_freq(void *priv, unsigned int freq)
9183 {
9184 	struct i802_bss *bss = priv;
9185 	struct wpa_driver_nl80211_data *drv = bss->drv;
9186 	struct nl_msg *msg;
9187 	int ret;
9188 	struct nlattr *params;
9189 
9190 	if (!drv->set_prob_oper_freq)
9191 		return -1;
9192 
9193 	wpa_printf(MSG_DEBUG,
9194 		   "nl80211: Set P2P probable operating freq %u for ifindex %d",
9195 		   freq, bss->ifindex);
9196 
9197 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
9198 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
9199 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
9200 			QCA_NL80211_VENDOR_SUBCMD_SET_PROBABLE_OPER_CHANNEL) ||
9201 	    !(params = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA)) ||
9202 	    nla_put_u32(msg,
9203 			QCA_WLAN_VENDOR_ATTR_PROBABLE_OPER_CHANNEL_IFACE_TYPE,
9204 			QCA_IFACE_TYPE_P2P_CLIENT) ||
9205 	    nla_put_u32(msg,
9206 			QCA_WLAN_VENDOR_ATTR_PROBABLE_OPER_CHANNEL_FREQ,
9207 			freq)) {
9208 		wpa_printf(MSG_ERROR,
9209 			   "%s: err in adding vendor_cmd and vendor_data",
9210 			   __func__);
9211 		nlmsg_free(msg);
9212 		return -1;
9213 	}
9214 	nla_nest_end(msg, params);
9215 
9216 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
9217 	msg = NULL;
9218 	if (ret) {
9219 		wpa_printf(MSG_ERROR, "%s: err in send_and_recv_msgs",
9220 			   __func__);
9221 		return ret;
9222 	}
9223 	nlmsg_free(msg);
9224 	return 0;
9225 }
9226 
9227 
9228 static int nl80211_p2p_lo_start(void *priv, unsigned int freq,
9229 				unsigned int period, unsigned int interval,
9230 				unsigned int count, const u8 *device_types,
9231 				size_t dev_types_len,
9232 				const u8 *ies, size_t ies_len)
9233 {
9234 	struct i802_bss *bss = priv;
9235 	struct wpa_driver_nl80211_data *drv = bss->drv;
9236 	struct nl_msg *msg;
9237 	struct nlattr *container;
9238 	int ret;
9239 
9240 	wpa_printf(MSG_DEBUG,
9241 		   "nl80211: Start P2P Listen offload: freq=%u, period=%u, interval=%u, count=%u",
9242 		   freq, period, interval, count);
9243 
9244 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_P2P_LISTEN_OFFLOAD))
9245 		return -1;
9246 
9247 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
9248 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
9249 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
9250 			QCA_NL80211_VENDOR_SUBCMD_P2P_LISTEN_OFFLOAD_START))
9251 		goto fail;
9252 
9253 	container = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA);
9254 	if (!container)
9255 		goto fail;
9256 
9257 	if (nla_put_u32(msg, QCA_WLAN_VENDOR_ATTR_P2P_LISTEN_OFFLOAD_CHANNEL,
9258 			freq) ||
9259 	    nla_put_u32(msg, QCA_WLAN_VENDOR_ATTR_P2P_LISTEN_OFFLOAD_PERIOD,
9260 			period) ||
9261 	    nla_put_u32(msg, QCA_WLAN_VENDOR_ATTR_P2P_LISTEN_OFFLOAD_INTERVAL,
9262 			interval) ||
9263 	    nla_put_u32(msg, QCA_WLAN_VENDOR_ATTR_P2P_LISTEN_OFFLOAD_COUNT,
9264 			count) ||
9265 	    nla_put(msg, QCA_WLAN_VENDOR_ATTR_P2P_LISTEN_OFFLOAD_DEVICE_TYPES,
9266 		    dev_types_len, device_types) ||
9267 	    nla_put(msg, QCA_WLAN_VENDOR_ATTR_P2P_LISTEN_OFFLOAD_VENDOR_IE,
9268 		    ies_len, ies))
9269 		goto fail;
9270 
9271 	nla_nest_end(msg, container);
9272 	ret = send_and_recv_msgs(drv, msg, NULL, NULL);
9273 	msg = NULL;
9274 	if (ret) {
9275 		wpa_printf(MSG_DEBUG,
9276 			   "nl80211: Failed to send P2P Listen offload vendor command");
9277 		goto fail;
9278 	}
9279 
9280 	return 0;
9281 
9282 fail:
9283 	nlmsg_free(msg);
9284 	return -1;
9285 }
9286 
9287 
9288 static int nl80211_p2p_lo_stop(void *priv)
9289 {
9290 	struct i802_bss *bss = priv;
9291 	struct wpa_driver_nl80211_data *drv = bss->drv;
9292 	struct nl_msg *msg;
9293 
9294 	wpa_printf(MSG_DEBUG, "nl80211: Stop P2P Listen offload");
9295 
9296 	if (!(drv->capa.flags & WPA_DRIVER_FLAGS_P2P_LISTEN_OFFLOAD))
9297 		return -1;
9298 
9299 	if (!(msg = nl80211_drv_msg(drv, 0, NL80211_CMD_VENDOR)) ||
9300 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_ID, OUI_QCA) ||
9301 	    nla_put_u32(msg, NL80211_ATTR_VENDOR_SUBCMD,
9302 			QCA_NL80211_VENDOR_SUBCMD_P2P_LISTEN_OFFLOAD_STOP)) {
9303 		nlmsg_free(msg);
9304 		return -1;
9305 	}
9306 
9307 	return send_and_recv_msgs(drv, msg, NULL, NULL);
9308 }
9309 
9310 #endif /* CONFIG_DRIVER_NL80211_QCA */
9311 
9312 
9313 static int nl80211_write_to_file(const char *name, unsigned int val)
9314 {
9315 	int fd, len;
9316 	char tmp[128];
9317 
9318 	fd = open(name, O_RDWR);
9319 	if (fd < 0) {
9320 		wpa_printf(MSG_ERROR, "nl80211: Failed to open %s: %s",
9321 			   name, strerror(errno));
9322 		return fd;
9323 	}
9324 
9325 	len = os_snprintf(tmp, sizeof(tmp), "%u\n", val);
9326 	len = write(fd, tmp, len);
9327 	if (len < 0)
9328 		wpa_printf(MSG_ERROR, "nl80211: Failed to write to %s: %s",
9329 			   name, strerror(errno));
9330 	close(fd);
9331 
9332 	return 0;
9333 }
9334 
9335 
9336 static int nl80211_configure_data_frame_filters(void *priv, u32 filter_flags)
9337 {
9338 	struct i802_bss *bss = priv;
9339 	char path[128];
9340 	int ret;
9341 
9342 	wpa_printf(MSG_DEBUG, "nl80211: Data frame filter flags=0x%x",
9343 		   filter_flags);
9344 
9345 	/* Configure filtering of unicast frame encrypted using GTK */
9346 	ret = os_snprintf(path, sizeof(path),
9347 			  "/proc/sys/net/ipv4/conf/%s/drop_unicast_in_l2_multicast",
9348 			  bss->ifname);
9349 	if (os_snprintf_error(sizeof(path), ret))
9350 		return -1;
9351 
9352 	ret = nl80211_write_to_file(path,
9353 				    !!(filter_flags &
9354 				       WPA_DATA_FRAME_FILTER_FLAG_GTK));
9355 	if (ret) {
9356 		wpa_printf(MSG_ERROR,
9357 			   "nl80211: Failed to set IPv4 unicast in multicast filter");
9358 		return ret;
9359 	}
9360 
9361 	os_snprintf(path, sizeof(path),
9362 		    "/proc/sys/net/ipv6/conf/%s/drop_unicast_in_l2_multicast",
9363 		    bss->ifname);
9364 	ret = nl80211_write_to_file(path,
9365 				    !!(filter_flags &
9366 				       WPA_DATA_FRAME_FILTER_FLAG_GTK));
9367 
9368 	if (ret) {
9369 		wpa_printf(MSG_ERROR,
9370 			   "nl80211: Failed to set IPv6 unicast in multicast filter");
9371 		return ret;
9372 	}
9373 
9374 	/* Configure filtering of unicast frame encrypted using GTK */
9375 	os_snprintf(path, sizeof(path),
9376 		    "/proc/sys/net/ipv4/conf/%s/drop_gratuitous_arp",
9377 		    bss->ifname);
9378 	ret = nl80211_write_to_file(path,
9379 				    !!(filter_flags &
9380 				       WPA_DATA_FRAME_FILTER_FLAG_ARP));
9381 	if (ret) {
9382 		wpa_printf(MSG_ERROR,
9383 			   "nl80211: Failed set gratuitous ARP filter");
9384 		return ret;
9385 	}
9386 
9387 	/* Configure filtering of IPv6 NA frames */
9388 	os_snprintf(path, sizeof(path),
9389 		    "/proc/sys/net/ipv6/conf/%s/drop_unsolicited_na",
9390 		    bss->ifname);
9391 	ret = nl80211_write_to_file(path,
9392 				    !!(filter_flags &
9393 				       WPA_DATA_FRAME_FILTER_FLAG_NA));
9394 	if (ret) {
9395 		wpa_printf(MSG_ERROR,
9396 			   "nl80211: Failed to set unsolicited NA filter");
9397 		return ret;
9398 	}
9399 
9400 	return 0;
9401 }
9402 
9403 
9404 static int nl80211_get_ext_capab(void *priv, enum wpa_driver_if_type type,
9405 				 const u8 **ext_capa, const u8 **ext_capa_mask,
9406 				 unsigned int *ext_capa_len)
9407 {
9408 	struct i802_bss *bss = priv;
9409 	struct wpa_driver_nl80211_data *drv = bss->drv;
9410 	enum nl80211_iftype nlmode;
9411 	unsigned int i;
9412 
9413 	if (!ext_capa || !ext_capa_mask || !ext_capa_len)
9414 		return -1;
9415 
9416 	nlmode = wpa_driver_nl80211_if_type(type);
9417 
9418 	/* By default, use the per-radio values */
9419 	*ext_capa = drv->extended_capa;
9420 	*ext_capa_mask = drv->extended_capa_mask;
9421 	*ext_capa_len = drv->extended_capa_len;
9422 
9423 	/* Replace the default value if a per-interface type value exists */
9424 	for (i = 0; i < drv->num_iface_ext_capa; i++) {
9425 		if (nlmode == drv->iface_ext_capa[i].iftype) {
9426 			*ext_capa = drv->iface_ext_capa[i].ext_capa;
9427 			*ext_capa_mask = drv->iface_ext_capa[i].ext_capa_mask;
9428 			*ext_capa_len = drv->iface_ext_capa[i].ext_capa_len;
9429 			break;
9430 		}
9431 	}
9432 
9433 	return 0;
9434 }
9435 
9436 
9437 const struct wpa_driver_ops wpa_driver_nl80211_ops = {
9438 	.name = "nl80211",
9439 	.desc = "Linux nl80211/cfg80211",
9440 	.get_bssid = wpa_driver_nl80211_get_bssid,
9441 	.get_ssid = wpa_driver_nl80211_get_ssid,
9442 	.set_key = driver_nl80211_set_key,
9443 	.scan2 = driver_nl80211_scan2,
9444 	.sched_scan = wpa_driver_nl80211_sched_scan,
9445 	.stop_sched_scan = wpa_driver_nl80211_stop_sched_scan,
9446 	.get_scan_results2 = wpa_driver_nl80211_get_scan_results,
9447 	.abort_scan = wpa_driver_nl80211_abort_scan,
9448 	.deauthenticate = driver_nl80211_deauthenticate,
9449 	.authenticate = driver_nl80211_authenticate,
9450 	.associate = wpa_driver_nl80211_associate,
9451 	.global_init = nl80211_global_init,
9452 	.global_deinit = nl80211_global_deinit,
9453 	.init2 = wpa_driver_nl80211_init,
9454 	.deinit = driver_nl80211_deinit,
9455 	.get_capa = wpa_driver_nl80211_get_capa,
9456 	.set_operstate = wpa_driver_nl80211_set_operstate,
9457 	.set_supp_port = wpa_driver_nl80211_set_supp_port,
9458 	.set_country = wpa_driver_nl80211_set_country,
9459 	.get_country = wpa_driver_nl80211_get_country,
9460 	.set_ap = wpa_driver_nl80211_set_ap,
9461 	.set_acl = wpa_driver_nl80211_set_acl,
9462 	.if_add = wpa_driver_nl80211_if_add,
9463 	.if_remove = driver_nl80211_if_remove,
9464 	.send_mlme = driver_nl80211_send_mlme,
9465 	.get_hw_feature_data = nl80211_get_hw_feature_data,
9466 	.sta_add = wpa_driver_nl80211_sta_add,
9467 	.sta_remove = driver_nl80211_sta_remove,
9468 	.hapd_send_eapol = wpa_driver_nl80211_hapd_send_eapol,
9469 	.sta_set_flags = wpa_driver_nl80211_sta_set_flags,
9470 	.hapd_init = i802_init,
9471 	.hapd_deinit = i802_deinit,
9472 	.set_wds_sta = i802_set_wds_sta,
9473 	.get_seqnum = i802_get_seqnum,
9474 	.flush = i802_flush,
9475 	.get_inact_sec = i802_get_inact_sec,
9476 	.sta_clear_stats = i802_sta_clear_stats,
9477 	.set_rts = i802_set_rts,
9478 	.set_frag = i802_set_frag,
9479 	.set_tx_queue_params = i802_set_tx_queue_params,
9480 	.set_sta_vlan = driver_nl80211_set_sta_vlan,
9481 	.sta_deauth = i802_sta_deauth,
9482 	.sta_disassoc = i802_sta_disassoc,
9483 	.read_sta_data = driver_nl80211_read_sta_data,
9484 	.set_freq = i802_set_freq,
9485 	.send_action = driver_nl80211_send_action,
9486 	.send_action_cancel_wait = wpa_driver_nl80211_send_action_cancel_wait,
9487 	.remain_on_channel = wpa_driver_nl80211_remain_on_channel,
9488 	.cancel_remain_on_channel =
9489 	wpa_driver_nl80211_cancel_remain_on_channel,
9490 	.probe_req_report = driver_nl80211_probe_req_report,
9491 	.deinit_ap = wpa_driver_nl80211_deinit_ap,
9492 	.deinit_p2p_cli = wpa_driver_nl80211_deinit_p2p_cli,
9493 	.resume = wpa_driver_nl80211_resume,
9494 	.signal_monitor = nl80211_signal_monitor,
9495 	.signal_poll = nl80211_signal_poll,
9496 	.send_frame = nl80211_send_frame,
9497 	.set_param = nl80211_set_param,
9498 	.get_radio_name = nl80211_get_radio_name,
9499 	.add_pmkid = nl80211_add_pmkid,
9500 	.remove_pmkid = nl80211_remove_pmkid,
9501 	.flush_pmkid = nl80211_flush_pmkid,
9502 	.set_rekey_info = nl80211_set_rekey_info,
9503 	.poll_client = nl80211_poll_client,
9504 	.set_p2p_powersave = nl80211_set_p2p_powersave,
9505 	.start_dfs_cac = nl80211_start_radar_detection,
9506 	.stop_ap = wpa_driver_nl80211_stop_ap,
9507 #ifdef CONFIG_TDLS
9508 	.send_tdls_mgmt = nl80211_send_tdls_mgmt,
9509 	.tdls_oper = nl80211_tdls_oper,
9510 	.tdls_enable_channel_switch = nl80211_tdls_enable_channel_switch,
9511 	.tdls_disable_channel_switch = nl80211_tdls_disable_channel_switch,
9512 #endif /* CONFIG_TDLS */
9513 	.update_ft_ies = wpa_driver_nl80211_update_ft_ies,
9514 	.get_mac_addr = wpa_driver_nl80211_get_macaddr,
9515 	.get_survey = wpa_driver_nl80211_get_survey,
9516 	.status = wpa_driver_nl80211_status,
9517 	.switch_channel = nl80211_switch_channel,
9518 #ifdef ANDROID_P2P
9519 	.set_noa = wpa_driver_set_p2p_noa,
9520 	.get_noa = wpa_driver_get_p2p_noa,
9521 	.set_ap_wps_ie = wpa_driver_set_ap_wps_p2p_ie,
9522 #endif /* ANDROID_P2P */
9523 #ifdef ANDROID
9524 #ifndef ANDROID_LIB_STUB
9525 	.driver_cmd = wpa_driver_nl80211_driver_cmd,
9526 #endif /* !ANDROID_LIB_STUB */
9527 #endif /* ANDROID */
9528 	.vendor_cmd = nl80211_vendor_cmd,
9529 	.set_qos_map = nl80211_set_qos_map,
9530 	.set_wowlan = nl80211_set_wowlan,
9531 	.set_mac_addr = nl80211_set_mac_addr,
9532 #ifdef CONFIG_MESH
9533 	.init_mesh = wpa_driver_nl80211_init_mesh,
9534 	.join_mesh = wpa_driver_nl80211_join_mesh,
9535 	.leave_mesh = wpa_driver_nl80211_leave_mesh,
9536 #endif /* CONFIG_MESH */
9537 	.br_add_ip_neigh = wpa_driver_br_add_ip_neigh,
9538 	.br_delete_ip_neigh = wpa_driver_br_delete_ip_neigh,
9539 	.br_port_set_attr = wpa_driver_br_port_set_attr,
9540 	.br_set_net_param = wpa_driver_br_set_net_param,
9541 	.add_tx_ts = nl80211_add_ts,
9542 	.del_tx_ts = nl80211_del_ts,
9543 	.get_ifindex = nl80211_get_ifindex,
9544 #ifdef CONFIG_DRIVER_NL80211_QCA
9545 	.roaming = nl80211_roaming,
9546 	.do_acs = wpa_driver_do_acs,
9547 	.set_band = nl80211_set_band,
9548 	.get_pref_freq_list = nl80211_get_pref_freq_list,
9549 	.set_prob_oper_freq = nl80211_set_prob_oper_freq,
9550 	.p2p_lo_start = nl80211_p2p_lo_start,
9551 	.p2p_lo_stop = nl80211_p2p_lo_stop,
9552 	.set_default_scan_ies = nl80211_set_default_scan_ies,
9553 #endif /* CONFIG_DRIVER_NL80211_QCA */
9554 	.configure_data_frame_filters = nl80211_configure_data_frame_filters,
9555 	.get_ext_capab = nl80211_get_ext_capab,
9556 };
9557