tdls.c 55 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990
  1. /*
  2. * mac80211 TDLS handling code
  3. *
  4. * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
  5. * Copyright 2014, Intel Corporation
  6. * Copyright 2014 Intel Mobile Communications GmbH
  7. * Copyright 2015 - 2016 Intel Deutschland GmbH
  8. *
  9. * This file is GPLv2 as found in COPYING.
  10. */
  11. #include <linux/ieee80211.h>
  12. #include <linux/log2.h>
  13. #include <net/cfg80211.h>
  14. #include <linux/rtnetlink.h>
  15. #include "ieee80211_i.h"
  16. #include "driver-ops.h"
  17. #include "rate.h"
  18. /* give usermode some time for retries in setting up the TDLS session */
  19. #define TDLS_PEER_SETUP_TIMEOUT (15 * HZ)
  20. void ieee80211_tdls_peer_del_work(struct work_struct *wk)
  21. {
  22. struct ieee80211_sub_if_data *sdata;
  23. struct ieee80211_local *local;
  24. sdata = container_of(wk, struct ieee80211_sub_if_data,
  25. u.mgd.tdls_peer_del_work.work);
  26. local = sdata->local;
  27. mutex_lock(&local->mtx);
  28. if (!is_zero_ether_addr(sdata->u.mgd.tdls_peer)) {
  29. tdls_dbg(sdata, "TDLS del peer %pM\n", sdata->u.mgd.tdls_peer);
  30. sta_info_destroy_addr(sdata, sdata->u.mgd.tdls_peer);
  31. eth_zero_addr(sdata->u.mgd.tdls_peer);
  32. }
  33. mutex_unlock(&local->mtx);
  34. }
  35. static void ieee80211_tdls_add_ext_capab(struct ieee80211_sub_if_data *sdata,
  36. struct sk_buff *skb)
  37. {
  38. struct ieee80211_local *local = sdata->local;
  39. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  40. bool chan_switch = local->hw.wiphy->features &
  41. NL80211_FEATURE_TDLS_CHANNEL_SWITCH;
  42. bool wider_band = ieee80211_hw_check(&local->hw, TDLS_WIDER_BW) &&
  43. !ifmgd->tdls_wider_bw_prohibited;
  44. struct ieee80211_supported_band *sband = ieee80211_get_sband(sdata);
  45. bool vht = sband && sband->vht_cap.vht_supported;
  46. u8 *pos = skb_put(skb, 10);
  47. *pos++ = WLAN_EID_EXT_CAPABILITY;
  48. *pos++ = 8; /* len */
  49. *pos++ = 0x0;
  50. *pos++ = 0x0;
  51. *pos++ = 0x0;
  52. *pos++ = chan_switch ? WLAN_EXT_CAPA4_TDLS_CHAN_SWITCH : 0;
  53. *pos++ = WLAN_EXT_CAPA5_TDLS_ENABLED;
  54. *pos++ = 0;
  55. *pos++ = 0;
  56. *pos++ = (vht && wider_band) ? WLAN_EXT_CAPA8_TDLS_WIDE_BW_ENABLED : 0;
  57. }
  58. static u8
  59. ieee80211_tdls_add_subband(struct ieee80211_sub_if_data *sdata,
  60. struct sk_buff *skb, u16 start, u16 end,
  61. u16 spacing)
  62. {
  63. u8 subband_cnt = 0, ch_cnt = 0;
  64. struct ieee80211_channel *ch;
  65. struct cfg80211_chan_def chandef;
  66. int i, subband_start;
  67. struct wiphy *wiphy = sdata->local->hw.wiphy;
  68. for (i = start; i <= end; i += spacing) {
  69. if (!ch_cnt)
  70. subband_start = i;
  71. ch = ieee80211_get_channel(sdata->local->hw.wiphy, i);
  72. if (ch) {
  73. /* we will be active on the channel */
  74. cfg80211_chandef_create(&chandef, ch,
  75. NL80211_CHAN_NO_HT);
  76. if (cfg80211_reg_can_beacon_relax(wiphy, &chandef,
  77. sdata->wdev.iftype)) {
  78. ch_cnt++;
  79. /*
  80. * check if the next channel is also part of
  81. * this allowed range
  82. */
  83. continue;
  84. }
  85. }
  86. /*
  87. * we've reached the end of a range, with allowed channels
  88. * found
  89. */
  90. if (ch_cnt) {
  91. u8 *pos = skb_put(skb, 2);
  92. *pos++ = ieee80211_frequency_to_channel(subband_start);
  93. *pos++ = ch_cnt;
  94. subband_cnt++;
  95. ch_cnt = 0;
  96. }
  97. }
  98. /* all channels in the requested range are allowed - add them here */
  99. if (ch_cnt) {
  100. u8 *pos = skb_put(skb, 2);
  101. *pos++ = ieee80211_frequency_to_channel(subband_start);
  102. *pos++ = ch_cnt;
  103. subband_cnt++;
  104. }
  105. return subband_cnt;
  106. }
  107. static void
  108. ieee80211_tdls_add_supp_channels(struct ieee80211_sub_if_data *sdata,
  109. struct sk_buff *skb)
  110. {
  111. /*
  112. * Add possible channels for TDLS. These are channels that are allowed
  113. * to be active.
  114. */
  115. u8 subband_cnt;
  116. u8 *pos = skb_put(skb, 2);
  117. *pos++ = WLAN_EID_SUPPORTED_CHANNELS;
  118. /*
  119. * 5GHz and 2GHz channels numbers can overlap. Ignore this for now, as
  120. * this doesn't happen in real world scenarios.
  121. */
  122. /* 2GHz, with 5MHz spacing */
  123. subband_cnt = ieee80211_tdls_add_subband(sdata, skb, 2412, 2472, 5);
  124. /* 5GHz, with 20MHz spacing */
  125. subband_cnt += ieee80211_tdls_add_subband(sdata, skb, 5000, 5825, 20);
  126. /* length */
  127. *pos = 2 * subband_cnt;
  128. }
  129. static void ieee80211_tdls_add_oper_classes(struct ieee80211_sub_if_data *sdata,
  130. struct sk_buff *skb)
  131. {
  132. u8 *pos;
  133. u8 op_class;
  134. if (!ieee80211_chandef_to_operating_class(&sdata->vif.bss_conf.chandef,
  135. &op_class))
  136. return;
  137. pos = skb_put(skb, 4);
  138. *pos++ = WLAN_EID_SUPPORTED_REGULATORY_CLASSES;
  139. *pos++ = 2; /* len */
  140. *pos++ = op_class;
  141. *pos++ = op_class; /* give current operating class as alternate too */
  142. }
  143. static void ieee80211_tdls_add_bss_coex_ie(struct sk_buff *skb)
  144. {
  145. u8 *pos = skb_put(skb, 3);
  146. *pos++ = WLAN_EID_BSS_COEX_2040;
  147. *pos++ = 1; /* len */
  148. *pos++ = WLAN_BSS_COEX_INFORMATION_REQUEST;
  149. }
  150. static u16 ieee80211_get_tdls_sta_capab(struct ieee80211_sub_if_data *sdata,
  151. u16 status_code)
  152. {
  153. struct ieee80211_supported_band *sband;
  154. /* The capability will be 0 when sending a failure code */
  155. if (status_code != 0)
  156. return 0;
  157. sband = ieee80211_get_sband(sdata);
  158. if (sband && sband->band == NL80211_BAND_2GHZ) {
  159. return WLAN_CAPABILITY_SHORT_SLOT_TIME |
  160. WLAN_CAPABILITY_SHORT_PREAMBLE;
  161. }
  162. return 0;
  163. }
  164. static void ieee80211_tdls_add_link_ie(struct ieee80211_sub_if_data *sdata,
  165. struct sk_buff *skb, const u8 *peer,
  166. bool initiator)
  167. {
  168. struct ieee80211_tdls_lnkie *lnkid;
  169. const u8 *init_addr, *rsp_addr;
  170. if (initiator) {
  171. init_addr = sdata->vif.addr;
  172. rsp_addr = peer;
  173. } else {
  174. init_addr = peer;
  175. rsp_addr = sdata->vif.addr;
  176. }
  177. lnkid = skb_put(skb, sizeof(struct ieee80211_tdls_lnkie));
  178. lnkid->ie_type = WLAN_EID_LINK_ID;
  179. lnkid->ie_len = sizeof(struct ieee80211_tdls_lnkie) - 2;
  180. memcpy(lnkid->bssid, sdata->u.mgd.bssid, ETH_ALEN);
  181. memcpy(lnkid->init_sta, init_addr, ETH_ALEN);
  182. memcpy(lnkid->resp_sta, rsp_addr, ETH_ALEN);
  183. }
  184. static void
  185. ieee80211_tdls_add_aid(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
  186. {
  187. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  188. u8 *pos = skb_put(skb, 4);
  189. *pos++ = WLAN_EID_AID;
  190. *pos++ = 2; /* len */
  191. put_unaligned_le16(ifmgd->aid, pos);
  192. }
  193. /* translate numbering in the WMM parameter IE to the mac80211 notation */
  194. static enum ieee80211_ac_numbers ieee80211_ac_from_wmm(int ac)
  195. {
  196. switch (ac) {
  197. default:
  198. WARN_ON_ONCE(1);
  199. case 0:
  200. return IEEE80211_AC_BE;
  201. case 1:
  202. return IEEE80211_AC_BK;
  203. case 2:
  204. return IEEE80211_AC_VI;
  205. case 3:
  206. return IEEE80211_AC_VO;
  207. }
  208. }
  209. static u8 ieee80211_wmm_aci_aifsn(int aifsn, bool acm, int aci)
  210. {
  211. u8 ret;
  212. ret = aifsn & 0x0f;
  213. if (acm)
  214. ret |= 0x10;
  215. ret |= (aci << 5) & 0x60;
  216. return ret;
  217. }
  218. static u8 ieee80211_wmm_ecw(u16 cw_min, u16 cw_max)
  219. {
  220. return ((ilog2(cw_min + 1) << 0x0) & 0x0f) |
  221. ((ilog2(cw_max + 1) << 0x4) & 0xf0);
  222. }
  223. static void ieee80211_tdls_add_wmm_param_ie(struct ieee80211_sub_if_data *sdata,
  224. struct sk_buff *skb)
  225. {
  226. struct ieee80211_wmm_param_ie *wmm;
  227. struct ieee80211_tx_queue_params *txq;
  228. int i;
  229. wmm = skb_put_zero(skb, sizeof(*wmm));
  230. wmm->element_id = WLAN_EID_VENDOR_SPECIFIC;
  231. wmm->len = sizeof(*wmm) - 2;
  232. wmm->oui[0] = 0x00; /* Microsoft OUI 00:50:F2 */
  233. wmm->oui[1] = 0x50;
  234. wmm->oui[2] = 0xf2;
  235. wmm->oui_type = 2; /* WME */
  236. wmm->oui_subtype = 1; /* WME param */
  237. wmm->version = 1; /* WME ver */
  238. wmm->qos_info = 0; /* U-APSD not in use */
  239. /*
  240. * Use the EDCA parameters defined for the BSS, or default if the AP
  241. * doesn't support it, as mandated by 802.11-2012 section 10.22.4
  242. */
  243. for (i = 0; i < IEEE80211_NUM_ACS; i++) {
  244. txq = &sdata->tx_conf[ieee80211_ac_from_wmm(i)];
  245. wmm->ac[i].aci_aifsn = ieee80211_wmm_aci_aifsn(txq->aifs,
  246. txq->acm, i);
  247. wmm->ac[i].cw = ieee80211_wmm_ecw(txq->cw_min, txq->cw_max);
  248. wmm->ac[i].txop_limit = cpu_to_le16(txq->txop);
  249. }
  250. }
  251. static void
  252. ieee80211_tdls_chandef_vht_upgrade(struct ieee80211_sub_if_data *sdata,
  253. struct sta_info *sta)
  254. {
  255. /* IEEE802.11ac-2013 Table E-4 */
  256. u16 centers_80mhz[] = { 5210, 5290, 5530, 5610, 5690, 5775 };
  257. struct cfg80211_chan_def uc = sta->tdls_chandef;
  258. enum nl80211_chan_width max_width = ieee80211_sta_cap_chan_bw(sta);
  259. int i;
  260. /* only support upgrading non-narrow channels up to 80Mhz */
  261. if (max_width == NL80211_CHAN_WIDTH_5 ||
  262. max_width == NL80211_CHAN_WIDTH_10)
  263. return;
  264. if (max_width > NL80211_CHAN_WIDTH_80)
  265. max_width = NL80211_CHAN_WIDTH_80;
  266. if (uc.width >= max_width)
  267. return;
  268. /*
  269. * Channel usage constrains in the IEEE802.11ac-2013 specification only
  270. * allow expanding a 20MHz channel to 80MHz in a single way. In
  271. * addition, there are no 40MHz allowed channels that are not part of
  272. * the allowed 80MHz range in the 5GHz spectrum (the relevant one here).
  273. */
  274. for (i = 0; i < ARRAY_SIZE(centers_80mhz); i++)
  275. if (abs(uc.chan->center_freq - centers_80mhz[i]) <= 30) {
  276. uc.center_freq1 = centers_80mhz[i];
  277. uc.center_freq2 = 0;
  278. uc.width = NL80211_CHAN_WIDTH_80;
  279. break;
  280. }
  281. if (!uc.center_freq1)
  282. return;
  283. /* proceed to downgrade the chandef until usable or the same as AP BW */
  284. while (uc.width > max_width ||
  285. (uc.width > sta->tdls_chandef.width &&
  286. !cfg80211_reg_can_beacon_relax(sdata->local->hw.wiphy, &uc,
  287. sdata->wdev.iftype)))
  288. ieee80211_chandef_downgrade(&uc);
  289. if (!cfg80211_chandef_identical(&uc, &sta->tdls_chandef)) {
  290. tdls_dbg(sdata, "TDLS ch width upgraded %d -> %d\n",
  291. sta->tdls_chandef.width, uc.width);
  292. /*
  293. * the station is not yet authorized when BW upgrade is done,
  294. * locking is not required
  295. */
  296. sta->tdls_chandef = uc;
  297. }
  298. }
  299. static void
  300. ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
  301. struct sk_buff *skb, const u8 *peer,
  302. u8 action_code, bool initiator,
  303. const u8 *extra_ies, size_t extra_ies_len)
  304. {
  305. struct ieee80211_supported_band *sband;
  306. struct ieee80211_local *local = sdata->local;
  307. struct ieee80211_sta_ht_cap ht_cap;
  308. struct ieee80211_sta_vht_cap vht_cap;
  309. struct sta_info *sta = NULL;
  310. size_t offset = 0, noffset;
  311. u8 *pos;
  312. sband = ieee80211_get_sband(sdata);
  313. if (!sband)
  314. return;
  315. ieee80211_add_srates_ie(sdata, skb, false, sband->band);
  316. ieee80211_add_ext_srates_ie(sdata, skb, false, sband->band);
  317. ieee80211_tdls_add_supp_channels(sdata, skb);
  318. /* add any custom IEs that go before Extended Capabilities */
  319. if (extra_ies_len) {
  320. static const u8 before_ext_cap[] = {
  321. WLAN_EID_SUPP_RATES,
  322. WLAN_EID_COUNTRY,
  323. WLAN_EID_EXT_SUPP_RATES,
  324. WLAN_EID_SUPPORTED_CHANNELS,
  325. WLAN_EID_RSN,
  326. };
  327. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  328. before_ext_cap,
  329. ARRAY_SIZE(before_ext_cap),
  330. offset);
  331. skb_put_data(skb, extra_ies + offset, noffset - offset);
  332. offset = noffset;
  333. }
  334. ieee80211_tdls_add_ext_capab(sdata, skb);
  335. /* add the QoS element if we support it */
  336. if (local->hw.queues >= IEEE80211_NUM_ACS &&
  337. action_code != WLAN_PUB_ACTION_TDLS_DISCOVER_RES)
  338. ieee80211_add_wmm_info_ie(skb_put(skb, 9), 0); /* no U-APSD */
  339. /* add any custom IEs that go before HT capabilities */
  340. if (extra_ies_len) {
  341. static const u8 before_ht_cap[] = {
  342. WLAN_EID_SUPP_RATES,
  343. WLAN_EID_COUNTRY,
  344. WLAN_EID_EXT_SUPP_RATES,
  345. WLAN_EID_SUPPORTED_CHANNELS,
  346. WLAN_EID_RSN,
  347. WLAN_EID_EXT_CAPABILITY,
  348. WLAN_EID_QOS_CAPA,
  349. WLAN_EID_FAST_BSS_TRANSITION,
  350. WLAN_EID_TIMEOUT_INTERVAL,
  351. WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
  352. };
  353. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  354. before_ht_cap,
  355. ARRAY_SIZE(before_ht_cap),
  356. offset);
  357. skb_put_data(skb, extra_ies + offset, noffset - offset);
  358. offset = noffset;
  359. }
  360. mutex_lock(&local->sta_mtx);
  361. /* we should have the peer STA if we're already responding */
  362. if (action_code == WLAN_TDLS_SETUP_RESPONSE) {
  363. sta = sta_info_get(sdata, peer);
  364. if (WARN_ON_ONCE(!sta)) {
  365. mutex_unlock(&local->sta_mtx);
  366. return;
  367. }
  368. sta->tdls_chandef = sdata->vif.bss_conf.chandef;
  369. }
  370. ieee80211_tdls_add_oper_classes(sdata, skb);
  371. /*
  372. * with TDLS we can switch channels, and HT-caps are not necessarily
  373. * the same on all bands. The specification limits the setup to a
  374. * single HT-cap, so use the current band for now.
  375. */
  376. memcpy(&ht_cap, &sband->ht_cap, sizeof(ht_cap));
  377. if ((action_code == WLAN_TDLS_SETUP_REQUEST ||
  378. action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) &&
  379. ht_cap.ht_supported) {
  380. ieee80211_apply_htcap_overrides(sdata, &ht_cap);
  381. /* disable SMPS in TDLS initiator */
  382. ht_cap.cap |= WLAN_HT_CAP_SM_PS_DISABLED
  383. << IEEE80211_HT_CAP_SM_PS_SHIFT;
  384. pos = skb_put(skb, sizeof(struct ieee80211_ht_cap) + 2);
  385. ieee80211_ie_build_ht_cap(pos, &ht_cap, ht_cap.cap);
  386. } else if (action_code == WLAN_TDLS_SETUP_RESPONSE &&
  387. ht_cap.ht_supported && sta->sta.ht_cap.ht_supported) {
  388. /* the peer caps are already intersected with our own */
  389. memcpy(&ht_cap, &sta->sta.ht_cap, sizeof(ht_cap));
  390. pos = skb_put(skb, sizeof(struct ieee80211_ht_cap) + 2);
  391. ieee80211_ie_build_ht_cap(pos, &ht_cap, ht_cap.cap);
  392. }
  393. if (ht_cap.ht_supported &&
  394. (ht_cap.cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40))
  395. ieee80211_tdls_add_bss_coex_ie(skb);
  396. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  397. /* add any custom IEs that go before VHT capabilities */
  398. if (extra_ies_len) {
  399. static const u8 before_vht_cap[] = {
  400. WLAN_EID_SUPP_RATES,
  401. WLAN_EID_COUNTRY,
  402. WLAN_EID_EXT_SUPP_RATES,
  403. WLAN_EID_SUPPORTED_CHANNELS,
  404. WLAN_EID_RSN,
  405. WLAN_EID_EXT_CAPABILITY,
  406. WLAN_EID_QOS_CAPA,
  407. WLAN_EID_FAST_BSS_TRANSITION,
  408. WLAN_EID_TIMEOUT_INTERVAL,
  409. WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
  410. WLAN_EID_MULTI_BAND,
  411. };
  412. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  413. before_vht_cap,
  414. ARRAY_SIZE(before_vht_cap),
  415. offset);
  416. skb_put_data(skb, extra_ies + offset, noffset - offset);
  417. offset = noffset;
  418. }
  419. /* build the VHT-cap similarly to the HT-cap */
  420. memcpy(&vht_cap, &sband->vht_cap, sizeof(vht_cap));
  421. if ((action_code == WLAN_TDLS_SETUP_REQUEST ||
  422. action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) &&
  423. vht_cap.vht_supported) {
  424. ieee80211_apply_vhtcap_overrides(sdata, &vht_cap);
  425. /* the AID is present only when VHT is implemented */
  426. if (action_code == WLAN_TDLS_SETUP_REQUEST)
  427. ieee80211_tdls_add_aid(sdata, skb);
  428. pos = skb_put(skb, sizeof(struct ieee80211_vht_cap) + 2);
  429. ieee80211_ie_build_vht_cap(pos, &vht_cap, vht_cap.cap);
  430. } else if (action_code == WLAN_TDLS_SETUP_RESPONSE &&
  431. vht_cap.vht_supported && sta->sta.vht_cap.vht_supported) {
  432. /* the peer caps are already intersected with our own */
  433. memcpy(&vht_cap, &sta->sta.vht_cap, sizeof(vht_cap));
  434. /* the AID is present only when VHT is implemented */
  435. ieee80211_tdls_add_aid(sdata, skb);
  436. pos = skb_put(skb, sizeof(struct ieee80211_vht_cap) + 2);
  437. ieee80211_ie_build_vht_cap(pos, &vht_cap, vht_cap.cap);
  438. /*
  439. * if both peers support WIDER_BW, we can expand the chandef to
  440. * a wider compatible one, up to 80MHz
  441. */
  442. if (test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW))
  443. ieee80211_tdls_chandef_vht_upgrade(sdata, sta);
  444. }
  445. mutex_unlock(&local->sta_mtx);
  446. /* add any remaining IEs */
  447. if (extra_ies_len) {
  448. noffset = extra_ies_len;
  449. skb_put_data(skb, extra_ies + offset, noffset - offset);
  450. }
  451. }
  452. static void
  453. ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_sub_if_data *sdata,
  454. struct sk_buff *skb, const u8 *peer,
  455. bool initiator, const u8 *extra_ies,
  456. size_t extra_ies_len)
  457. {
  458. struct ieee80211_local *local = sdata->local;
  459. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  460. size_t offset = 0, noffset;
  461. struct sta_info *sta, *ap_sta;
  462. struct ieee80211_supported_band *sband;
  463. u8 *pos;
  464. sband = ieee80211_get_sband(sdata);
  465. if (!sband)
  466. return;
  467. mutex_lock(&local->sta_mtx);
  468. sta = sta_info_get(sdata, peer);
  469. ap_sta = sta_info_get(sdata, ifmgd->bssid);
  470. if (WARN_ON_ONCE(!sta || !ap_sta)) {
  471. mutex_unlock(&local->sta_mtx);
  472. return;
  473. }
  474. sta->tdls_chandef = sdata->vif.bss_conf.chandef;
  475. /* add any custom IEs that go before the QoS IE */
  476. if (extra_ies_len) {
  477. static const u8 before_qos[] = {
  478. WLAN_EID_RSN,
  479. };
  480. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  481. before_qos,
  482. ARRAY_SIZE(before_qos),
  483. offset);
  484. skb_put_data(skb, extra_ies + offset, noffset - offset);
  485. offset = noffset;
  486. }
  487. /* add the QoS param IE if both the peer and we support it */
  488. if (local->hw.queues >= IEEE80211_NUM_ACS && sta->sta.wme)
  489. ieee80211_tdls_add_wmm_param_ie(sdata, skb);
  490. /* add any custom IEs that go before HT operation */
  491. if (extra_ies_len) {
  492. static const u8 before_ht_op[] = {
  493. WLAN_EID_RSN,
  494. WLAN_EID_QOS_CAPA,
  495. WLAN_EID_FAST_BSS_TRANSITION,
  496. WLAN_EID_TIMEOUT_INTERVAL,
  497. };
  498. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  499. before_ht_op,
  500. ARRAY_SIZE(before_ht_op),
  501. offset);
  502. skb_put_data(skb, extra_ies + offset, noffset - offset);
  503. offset = noffset;
  504. }
  505. /*
  506. * if HT support is only added in TDLS, we need an HT-operation IE.
  507. * add the IE as required by IEEE802.11-2012 9.23.3.2.
  508. */
  509. if (!ap_sta->sta.ht_cap.ht_supported && sta->sta.ht_cap.ht_supported) {
  510. u16 prot = IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED |
  511. IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
  512. IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
  513. pos = skb_put(skb, 2 + sizeof(struct ieee80211_ht_operation));
  514. ieee80211_ie_build_ht_oper(pos, &sta->sta.ht_cap,
  515. &sdata->vif.bss_conf.chandef, prot,
  516. true);
  517. }
  518. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  519. /* only include VHT-operation if not on the 2.4GHz band */
  520. if (sband->band != NL80211_BAND_2GHZ &&
  521. sta->sta.vht_cap.vht_supported) {
  522. /*
  523. * if both peers support WIDER_BW, we can expand the chandef to
  524. * a wider compatible one, up to 80MHz
  525. */
  526. if (test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW))
  527. ieee80211_tdls_chandef_vht_upgrade(sdata, sta);
  528. pos = skb_put(skb, 2 + sizeof(struct ieee80211_vht_operation));
  529. ieee80211_ie_build_vht_oper(pos, &sta->sta.vht_cap,
  530. &sta->tdls_chandef);
  531. }
  532. mutex_unlock(&local->sta_mtx);
  533. /* add any remaining IEs */
  534. if (extra_ies_len) {
  535. noffset = extra_ies_len;
  536. skb_put_data(skb, extra_ies + offset, noffset - offset);
  537. }
  538. }
  539. static void
  540. ieee80211_tdls_add_chan_switch_req_ies(struct ieee80211_sub_if_data *sdata,
  541. struct sk_buff *skb, const u8 *peer,
  542. bool initiator, const u8 *extra_ies,
  543. size_t extra_ies_len, u8 oper_class,
  544. struct cfg80211_chan_def *chandef)
  545. {
  546. struct ieee80211_tdls_data *tf;
  547. size_t offset = 0, noffset;
  548. if (WARN_ON_ONCE(!chandef))
  549. return;
  550. tf = (void *)skb->data;
  551. tf->u.chan_switch_req.target_channel =
  552. ieee80211_frequency_to_channel(chandef->chan->center_freq);
  553. tf->u.chan_switch_req.oper_class = oper_class;
  554. if (extra_ies_len) {
  555. static const u8 before_lnkie[] = {
  556. WLAN_EID_SECONDARY_CHANNEL_OFFSET,
  557. };
  558. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  559. before_lnkie,
  560. ARRAY_SIZE(before_lnkie),
  561. offset);
  562. skb_put_data(skb, extra_ies + offset, noffset - offset);
  563. offset = noffset;
  564. }
  565. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  566. /* add any remaining IEs */
  567. if (extra_ies_len) {
  568. noffset = extra_ies_len;
  569. skb_put_data(skb, extra_ies + offset, noffset - offset);
  570. }
  571. }
  572. static void
  573. ieee80211_tdls_add_chan_switch_resp_ies(struct ieee80211_sub_if_data *sdata,
  574. struct sk_buff *skb, const u8 *peer,
  575. u16 status_code, bool initiator,
  576. const u8 *extra_ies,
  577. size_t extra_ies_len)
  578. {
  579. if (status_code == 0)
  580. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  581. if (extra_ies_len)
  582. skb_put_data(skb, extra_ies, extra_ies_len);
  583. }
  584. static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
  585. struct sk_buff *skb, const u8 *peer,
  586. u8 action_code, u16 status_code,
  587. bool initiator, const u8 *extra_ies,
  588. size_t extra_ies_len, u8 oper_class,
  589. struct cfg80211_chan_def *chandef)
  590. {
  591. switch (action_code) {
  592. case WLAN_TDLS_SETUP_REQUEST:
  593. case WLAN_TDLS_SETUP_RESPONSE:
  594. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  595. if (status_code == 0)
  596. ieee80211_tdls_add_setup_start_ies(sdata, skb, peer,
  597. action_code,
  598. initiator,
  599. extra_ies,
  600. extra_ies_len);
  601. break;
  602. case WLAN_TDLS_SETUP_CONFIRM:
  603. if (status_code == 0)
  604. ieee80211_tdls_add_setup_cfm_ies(sdata, skb, peer,
  605. initiator, extra_ies,
  606. extra_ies_len);
  607. break;
  608. case WLAN_TDLS_TEARDOWN:
  609. case WLAN_TDLS_DISCOVERY_REQUEST:
  610. if (extra_ies_len)
  611. skb_put_data(skb, extra_ies, extra_ies_len);
  612. if (status_code == 0 || action_code == WLAN_TDLS_TEARDOWN)
  613. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  614. break;
  615. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  616. ieee80211_tdls_add_chan_switch_req_ies(sdata, skb, peer,
  617. initiator, extra_ies,
  618. extra_ies_len,
  619. oper_class, chandef);
  620. break;
  621. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  622. ieee80211_tdls_add_chan_switch_resp_ies(sdata, skb, peer,
  623. status_code,
  624. initiator, extra_ies,
  625. extra_ies_len);
  626. break;
  627. }
  628. }
  629. static int
  630. ieee80211_prep_tdls_encap_data(struct wiphy *wiphy, struct net_device *dev,
  631. const u8 *peer, u8 action_code, u8 dialog_token,
  632. u16 status_code, struct sk_buff *skb)
  633. {
  634. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  635. struct ieee80211_tdls_data *tf;
  636. tf = skb_put(skb, offsetof(struct ieee80211_tdls_data, u));
  637. memcpy(tf->da, peer, ETH_ALEN);
  638. memcpy(tf->sa, sdata->vif.addr, ETH_ALEN);
  639. tf->ether_type = cpu_to_be16(ETH_P_TDLS);
  640. tf->payload_type = WLAN_TDLS_SNAP_RFTYPE;
  641. /* network header is after the ethernet header */
  642. skb_set_network_header(skb, ETH_HLEN);
  643. switch (action_code) {
  644. case WLAN_TDLS_SETUP_REQUEST:
  645. tf->category = WLAN_CATEGORY_TDLS;
  646. tf->action_code = WLAN_TDLS_SETUP_REQUEST;
  647. skb_put(skb, sizeof(tf->u.setup_req));
  648. tf->u.setup_req.dialog_token = dialog_token;
  649. tf->u.setup_req.capability =
  650. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  651. status_code));
  652. break;
  653. case WLAN_TDLS_SETUP_RESPONSE:
  654. tf->category = WLAN_CATEGORY_TDLS;
  655. tf->action_code = WLAN_TDLS_SETUP_RESPONSE;
  656. skb_put(skb, sizeof(tf->u.setup_resp));
  657. tf->u.setup_resp.status_code = cpu_to_le16(status_code);
  658. tf->u.setup_resp.dialog_token = dialog_token;
  659. tf->u.setup_resp.capability =
  660. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  661. status_code));
  662. break;
  663. case WLAN_TDLS_SETUP_CONFIRM:
  664. tf->category = WLAN_CATEGORY_TDLS;
  665. tf->action_code = WLAN_TDLS_SETUP_CONFIRM;
  666. skb_put(skb, sizeof(tf->u.setup_cfm));
  667. tf->u.setup_cfm.status_code = cpu_to_le16(status_code);
  668. tf->u.setup_cfm.dialog_token = dialog_token;
  669. break;
  670. case WLAN_TDLS_TEARDOWN:
  671. tf->category = WLAN_CATEGORY_TDLS;
  672. tf->action_code = WLAN_TDLS_TEARDOWN;
  673. skb_put(skb, sizeof(tf->u.teardown));
  674. tf->u.teardown.reason_code = cpu_to_le16(status_code);
  675. break;
  676. case WLAN_TDLS_DISCOVERY_REQUEST:
  677. tf->category = WLAN_CATEGORY_TDLS;
  678. tf->action_code = WLAN_TDLS_DISCOVERY_REQUEST;
  679. skb_put(skb, sizeof(tf->u.discover_req));
  680. tf->u.discover_req.dialog_token = dialog_token;
  681. break;
  682. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  683. tf->category = WLAN_CATEGORY_TDLS;
  684. tf->action_code = WLAN_TDLS_CHANNEL_SWITCH_REQUEST;
  685. skb_put(skb, sizeof(tf->u.chan_switch_req));
  686. break;
  687. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  688. tf->category = WLAN_CATEGORY_TDLS;
  689. tf->action_code = WLAN_TDLS_CHANNEL_SWITCH_RESPONSE;
  690. skb_put(skb, sizeof(tf->u.chan_switch_resp));
  691. tf->u.chan_switch_resp.status_code = cpu_to_le16(status_code);
  692. break;
  693. default:
  694. return -EINVAL;
  695. }
  696. return 0;
  697. }
  698. static int
  699. ieee80211_prep_tdls_direct(struct wiphy *wiphy, struct net_device *dev,
  700. const u8 *peer, u8 action_code, u8 dialog_token,
  701. u16 status_code, struct sk_buff *skb)
  702. {
  703. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  704. struct ieee80211_mgmt *mgmt;
  705. mgmt = skb_put_zero(skb, 24);
  706. memcpy(mgmt->da, peer, ETH_ALEN);
  707. memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
  708. memcpy(mgmt->bssid, sdata->u.mgd.bssid, ETH_ALEN);
  709. mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
  710. IEEE80211_STYPE_ACTION);
  711. switch (action_code) {
  712. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  713. skb_put(skb, 1 + sizeof(mgmt->u.action.u.tdls_discover_resp));
  714. mgmt->u.action.category = WLAN_CATEGORY_PUBLIC;
  715. mgmt->u.action.u.tdls_discover_resp.action_code =
  716. WLAN_PUB_ACTION_TDLS_DISCOVER_RES;
  717. mgmt->u.action.u.tdls_discover_resp.dialog_token =
  718. dialog_token;
  719. mgmt->u.action.u.tdls_discover_resp.capability =
  720. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  721. status_code));
  722. break;
  723. default:
  724. return -EINVAL;
  725. }
  726. return 0;
  727. }
  728. static struct sk_buff *
  729. ieee80211_tdls_build_mgmt_packet_data(struct ieee80211_sub_if_data *sdata,
  730. const u8 *peer, u8 action_code,
  731. u8 dialog_token, u16 status_code,
  732. bool initiator, const u8 *extra_ies,
  733. size_t extra_ies_len, u8 oper_class,
  734. struct cfg80211_chan_def *chandef)
  735. {
  736. struct ieee80211_local *local = sdata->local;
  737. struct sk_buff *skb;
  738. int ret;
  739. skb = netdev_alloc_skb(sdata->dev,
  740. local->hw.extra_tx_headroom +
  741. max(sizeof(struct ieee80211_mgmt),
  742. sizeof(struct ieee80211_tdls_data)) +
  743. 50 + /* supported rates */
  744. 10 + /* ext capab */
  745. 26 + /* max(WMM-info, WMM-param) */
  746. 2 + max(sizeof(struct ieee80211_ht_cap),
  747. sizeof(struct ieee80211_ht_operation)) +
  748. 2 + max(sizeof(struct ieee80211_vht_cap),
  749. sizeof(struct ieee80211_vht_operation)) +
  750. 50 + /* supported channels */
  751. 3 + /* 40/20 BSS coex */
  752. 4 + /* AID */
  753. 4 + /* oper classes */
  754. extra_ies_len +
  755. sizeof(struct ieee80211_tdls_lnkie));
  756. if (!skb)
  757. return NULL;
  758. skb_reserve(skb, local->hw.extra_tx_headroom);
  759. switch (action_code) {
  760. case WLAN_TDLS_SETUP_REQUEST:
  761. case WLAN_TDLS_SETUP_RESPONSE:
  762. case WLAN_TDLS_SETUP_CONFIRM:
  763. case WLAN_TDLS_TEARDOWN:
  764. case WLAN_TDLS_DISCOVERY_REQUEST:
  765. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  766. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  767. ret = ieee80211_prep_tdls_encap_data(local->hw.wiphy,
  768. sdata->dev, peer,
  769. action_code, dialog_token,
  770. status_code, skb);
  771. break;
  772. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  773. ret = ieee80211_prep_tdls_direct(local->hw.wiphy, sdata->dev,
  774. peer, action_code,
  775. dialog_token, status_code,
  776. skb);
  777. break;
  778. default:
  779. ret = -ENOTSUPP;
  780. break;
  781. }
  782. if (ret < 0)
  783. goto fail;
  784. ieee80211_tdls_add_ies(sdata, skb, peer, action_code, status_code,
  785. initiator, extra_ies, extra_ies_len, oper_class,
  786. chandef);
  787. return skb;
  788. fail:
  789. dev_kfree_skb(skb);
  790. return NULL;
  791. }
  792. static int
  793. ieee80211_tdls_prep_mgmt_packet(struct wiphy *wiphy, struct net_device *dev,
  794. const u8 *peer, u8 action_code, u8 dialog_token,
  795. u16 status_code, u32 peer_capability,
  796. bool initiator, const u8 *extra_ies,
  797. size_t extra_ies_len, u8 oper_class,
  798. struct cfg80211_chan_def *chandef)
  799. {
  800. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  801. struct sk_buff *skb = NULL;
  802. struct sta_info *sta;
  803. u32 flags = 0;
  804. int ret = 0;
  805. rcu_read_lock();
  806. sta = sta_info_get(sdata, peer);
  807. /* infer the initiator if we can, to support old userspace */
  808. switch (action_code) {
  809. case WLAN_TDLS_SETUP_REQUEST:
  810. if (sta) {
  811. set_sta_flag(sta, WLAN_STA_TDLS_INITIATOR);
  812. sta->sta.tdls_initiator = false;
  813. }
  814. /* fall-through */
  815. case WLAN_TDLS_SETUP_CONFIRM:
  816. case WLAN_TDLS_DISCOVERY_REQUEST:
  817. initiator = true;
  818. break;
  819. case WLAN_TDLS_SETUP_RESPONSE:
  820. /*
  821. * In some testing scenarios, we send a request and response.
  822. * Make the last packet sent take effect for the initiator
  823. * value.
  824. */
  825. if (sta) {
  826. clear_sta_flag(sta, WLAN_STA_TDLS_INITIATOR);
  827. sta->sta.tdls_initiator = true;
  828. }
  829. /* fall-through */
  830. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  831. initiator = false;
  832. break;
  833. case WLAN_TDLS_TEARDOWN:
  834. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  835. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  836. /* any value is ok */
  837. break;
  838. default:
  839. ret = -ENOTSUPP;
  840. break;
  841. }
  842. if (sta && test_sta_flag(sta, WLAN_STA_TDLS_INITIATOR))
  843. initiator = true;
  844. rcu_read_unlock();
  845. if (ret < 0)
  846. goto fail;
  847. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, peer, action_code,
  848. dialog_token, status_code,
  849. initiator, extra_ies,
  850. extra_ies_len, oper_class,
  851. chandef);
  852. if (!skb) {
  853. ret = -EINVAL;
  854. goto fail;
  855. }
  856. if (action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) {
  857. ieee80211_tx_skb(sdata, skb);
  858. return 0;
  859. }
  860. /*
  861. * According to 802.11z: Setup req/resp are sent in AC_BK, otherwise
  862. * we should default to AC_VI.
  863. */
  864. switch (action_code) {
  865. case WLAN_TDLS_SETUP_REQUEST:
  866. case WLAN_TDLS_SETUP_RESPONSE:
  867. skb_set_queue_mapping(skb, IEEE80211_AC_BK);
  868. skb->priority = 2;
  869. break;
  870. default:
  871. skb_set_queue_mapping(skb, IEEE80211_AC_VI);
  872. skb->priority = 5;
  873. break;
  874. }
  875. /*
  876. * Set the WLAN_TDLS_TEARDOWN flag to indicate a teardown in progress.
  877. * Later, if no ACK is returned from peer, we will re-send the teardown
  878. * packet through the AP.
  879. */
  880. if ((action_code == WLAN_TDLS_TEARDOWN) &&
  881. ieee80211_hw_check(&sdata->local->hw, REPORTS_TX_ACK_STATUS)) {
  882. bool try_resend; /* Should we keep skb for possible resend */
  883. /* If not sending directly to peer - no point in keeping skb */
  884. rcu_read_lock();
  885. sta = sta_info_get(sdata, peer);
  886. try_resend = sta && test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  887. rcu_read_unlock();
  888. spin_lock_bh(&sdata->u.mgd.teardown_lock);
  889. if (try_resend && !sdata->u.mgd.teardown_skb) {
  890. /* Mark it as requiring TX status callback */
  891. flags |= IEEE80211_TX_CTL_REQ_TX_STATUS |
  892. IEEE80211_TX_INTFL_MLME_CONN_TX;
  893. /*
  894. * skb is copied since mac80211 will later set
  895. * properties that might not be the same as the AP,
  896. * such as encryption, QoS, addresses, etc.
  897. *
  898. * No problem if skb_copy() fails, so no need to check.
  899. */
  900. sdata->u.mgd.teardown_skb = skb_copy(skb, GFP_ATOMIC);
  901. sdata->u.mgd.orig_teardown_skb = skb;
  902. }
  903. spin_unlock_bh(&sdata->u.mgd.teardown_lock);
  904. }
  905. /* disable bottom halves when entering the Tx path */
  906. local_bh_disable();
  907. __ieee80211_subif_start_xmit(skb, dev, flags);
  908. local_bh_enable();
  909. return ret;
  910. fail:
  911. dev_kfree_skb(skb);
  912. return ret;
  913. }
  914. static int
  915. ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
  916. const u8 *peer, u8 action_code, u8 dialog_token,
  917. u16 status_code, u32 peer_capability, bool initiator,
  918. const u8 *extra_ies, size_t extra_ies_len)
  919. {
  920. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  921. struct ieee80211_local *local = sdata->local;
  922. enum ieee80211_smps_mode smps_mode = sdata->u.mgd.driver_smps_mode;
  923. int ret;
  924. /* don't support setup with forced SMPS mode that's not off */
  925. if (smps_mode != IEEE80211_SMPS_AUTOMATIC &&
  926. smps_mode != IEEE80211_SMPS_OFF) {
  927. tdls_dbg(sdata, "Aborting TDLS setup due to SMPS mode %d\n",
  928. smps_mode);
  929. return -ENOTSUPP;
  930. }
  931. mutex_lock(&local->mtx);
  932. /* we don't support concurrent TDLS peer setups */
  933. if (!is_zero_ether_addr(sdata->u.mgd.tdls_peer) &&
  934. !ether_addr_equal(sdata->u.mgd.tdls_peer, peer)) {
  935. ret = -EBUSY;
  936. goto out_unlock;
  937. }
  938. /*
  939. * make sure we have a STA representing the peer so we drop or buffer
  940. * non-TDLS-setup frames to the peer. We can't send other packets
  941. * during setup through the AP path.
  942. * Allow error packets to be sent - sometimes we don't even add a STA
  943. * before failing the setup.
  944. */
  945. if (status_code == 0) {
  946. rcu_read_lock();
  947. if (!sta_info_get(sdata, peer)) {
  948. rcu_read_unlock();
  949. ret = -ENOLINK;
  950. goto out_unlock;
  951. }
  952. rcu_read_unlock();
  953. }
  954. ieee80211_flush_queues(local, sdata, false);
  955. memcpy(sdata->u.mgd.tdls_peer, peer, ETH_ALEN);
  956. mutex_unlock(&local->mtx);
  957. /* we cannot take the mutex while preparing the setup packet */
  958. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
  959. dialog_token, status_code,
  960. peer_capability, initiator,
  961. extra_ies, extra_ies_len, 0,
  962. NULL);
  963. if (ret < 0) {
  964. mutex_lock(&local->mtx);
  965. eth_zero_addr(sdata->u.mgd.tdls_peer);
  966. mutex_unlock(&local->mtx);
  967. return ret;
  968. }
  969. ieee80211_queue_delayed_work(&sdata->local->hw,
  970. &sdata->u.mgd.tdls_peer_del_work,
  971. TDLS_PEER_SETUP_TIMEOUT);
  972. return 0;
  973. out_unlock:
  974. mutex_unlock(&local->mtx);
  975. return ret;
  976. }
  977. static int
  978. ieee80211_tdls_mgmt_teardown(struct wiphy *wiphy, struct net_device *dev,
  979. const u8 *peer, u8 action_code, u8 dialog_token,
  980. u16 status_code, u32 peer_capability,
  981. bool initiator, const u8 *extra_ies,
  982. size_t extra_ies_len)
  983. {
  984. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  985. struct ieee80211_local *local = sdata->local;
  986. struct sta_info *sta;
  987. int ret;
  988. /*
  989. * No packets can be transmitted to the peer via the AP during setup -
  990. * the STA is set as a TDLS peer, but is not authorized.
  991. * During teardown, we prevent direct transmissions by stopping the
  992. * queues and flushing all direct packets.
  993. */
  994. ieee80211_stop_vif_queues(local, sdata,
  995. IEEE80211_QUEUE_STOP_REASON_TDLS_TEARDOWN);
  996. ieee80211_flush_queues(local, sdata, false);
  997. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
  998. dialog_token, status_code,
  999. peer_capability, initiator,
  1000. extra_ies, extra_ies_len, 0,
  1001. NULL);
  1002. if (ret < 0)
  1003. sdata_err(sdata, "Failed sending TDLS teardown packet %d\n",
  1004. ret);
  1005. /*
  1006. * Remove the STA AUTH flag to force further traffic through the AP. If
  1007. * the STA was unreachable, it was already removed.
  1008. */
  1009. rcu_read_lock();
  1010. sta = sta_info_get(sdata, peer);
  1011. if (sta)
  1012. clear_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  1013. rcu_read_unlock();
  1014. ieee80211_wake_vif_queues(local, sdata,
  1015. IEEE80211_QUEUE_STOP_REASON_TDLS_TEARDOWN);
  1016. return 0;
  1017. }
  1018. int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
  1019. const u8 *peer, u8 action_code, u8 dialog_token,
  1020. u16 status_code, u32 peer_capability,
  1021. bool initiator, const u8 *extra_ies,
  1022. size_t extra_ies_len)
  1023. {
  1024. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1025. int ret;
  1026. if (!(wiphy->flags & WIPHY_FLAG_SUPPORTS_TDLS))
  1027. return -ENOTSUPP;
  1028. /* make sure we are in managed mode, and associated */
  1029. if (sdata->vif.type != NL80211_IFTYPE_STATION ||
  1030. !sdata->u.mgd.associated)
  1031. return -EINVAL;
  1032. switch (action_code) {
  1033. case WLAN_TDLS_SETUP_REQUEST:
  1034. case WLAN_TDLS_SETUP_RESPONSE:
  1035. ret = ieee80211_tdls_mgmt_setup(wiphy, dev, peer, action_code,
  1036. dialog_token, status_code,
  1037. peer_capability, initiator,
  1038. extra_ies, extra_ies_len);
  1039. break;
  1040. case WLAN_TDLS_TEARDOWN:
  1041. ret = ieee80211_tdls_mgmt_teardown(wiphy, dev, peer,
  1042. action_code, dialog_token,
  1043. status_code,
  1044. peer_capability, initiator,
  1045. extra_ies, extra_ies_len);
  1046. break;
  1047. case WLAN_TDLS_DISCOVERY_REQUEST:
  1048. /*
  1049. * Protect the discovery so we can hear the TDLS discovery
  1050. * response frame. It is transmitted directly and not buffered
  1051. * by the AP.
  1052. */
  1053. drv_mgd_protect_tdls_discover(sdata->local, sdata);
  1054. /* fall-through */
  1055. case WLAN_TDLS_SETUP_CONFIRM:
  1056. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  1057. /* no special handling */
  1058. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
  1059. action_code,
  1060. dialog_token,
  1061. status_code,
  1062. peer_capability,
  1063. initiator, extra_ies,
  1064. extra_ies_len, 0, NULL);
  1065. break;
  1066. default:
  1067. ret = -EOPNOTSUPP;
  1068. break;
  1069. }
  1070. tdls_dbg(sdata, "TDLS mgmt action %d peer %pM status %d\n",
  1071. action_code, peer, ret);
  1072. return ret;
  1073. }
  1074. static void iee80211_tdls_recalc_chanctx(struct ieee80211_sub_if_data *sdata,
  1075. struct sta_info *sta)
  1076. {
  1077. struct ieee80211_local *local = sdata->local;
  1078. struct ieee80211_chanctx_conf *conf;
  1079. struct ieee80211_chanctx *ctx;
  1080. enum nl80211_chan_width width;
  1081. struct ieee80211_supported_band *sband;
  1082. mutex_lock(&local->chanctx_mtx);
  1083. conf = rcu_dereference_protected(sdata->vif.chanctx_conf,
  1084. lockdep_is_held(&local->chanctx_mtx));
  1085. if (conf) {
  1086. width = conf->def.width;
  1087. sband = local->hw.wiphy->bands[conf->def.chan->band];
  1088. ctx = container_of(conf, struct ieee80211_chanctx, conf);
  1089. ieee80211_recalc_chanctx_chantype(local, ctx);
  1090. /* if width changed and a peer is given, update its BW */
  1091. if (width != conf->def.width && sta &&
  1092. test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW)) {
  1093. enum ieee80211_sta_rx_bandwidth bw;
  1094. bw = ieee80211_chan_width_to_rx_bw(conf->def.width);
  1095. bw = min(bw, ieee80211_sta_cap_rx_bw(sta));
  1096. if (bw != sta->sta.bandwidth) {
  1097. sta->sta.bandwidth = bw;
  1098. rate_control_rate_update(local, sband, sta,
  1099. IEEE80211_RC_BW_CHANGED);
  1100. /*
  1101. * if a TDLS peer BW was updated, we need to
  1102. * recalc the chandef width again, to get the
  1103. * correct chanctx min_def
  1104. */
  1105. ieee80211_recalc_chanctx_chantype(local, ctx);
  1106. }
  1107. }
  1108. }
  1109. mutex_unlock(&local->chanctx_mtx);
  1110. }
  1111. static int iee80211_tdls_have_ht_peers(struct ieee80211_sub_if_data *sdata)
  1112. {
  1113. struct sta_info *sta;
  1114. bool result = false;
  1115. rcu_read_lock();
  1116. list_for_each_entry_rcu(sta, &sdata->local->sta_list, list) {
  1117. if (!sta->sta.tdls || sta->sdata != sdata || !sta->uploaded ||
  1118. !test_sta_flag(sta, WLAN_STA_AUTHORIZED) ||
  1119. !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH) ||
  1120. !sta->sta.ht_cap.ht_supported)
  1121. continue;
  1122. result = true;
  1123. break;
  1124. }
  1125. rcu_read_unlock();
  1126. return result;
  1127. }
  1128. static void
  1129. iee80211_tdls_recalc_ht_protection(struct ieee80211_sub_if_data *sdata,
  1130. struct sta_info *sta)
  1131. {
  1132. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  1133. bool tdls_ht;
  1134. u16 protection = IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED |
  1135. IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
  1136. IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
  1137. u16 opmode;
  1138. /* Nothing to do if the BSS connection uses HT */
  1139. if (!(ifmgd->flags & IEEE80211_STA_DISABLE_HT))
  1140. return;
  1141. tdls_ht = (sta && sta->sta.ht_cap.ht_supported) ||
  1142. iee80211_tdls_have_ht_peers(sdata);
  1143. opmode = sdata->vif.bss_conf.ht_operation_mode;
  1144. if (tdls_ht)
  1145. opmode |= protection;
  1146. else
  1147. opmode &= ~protection;
  1148. if (opmode == sdata->vif.bss_conf.ht_operation_mode)
  1149. return;
  1150. sdata->vif.bss_conf.ht_operation_mode = opmode;
  1151. ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_HT);
  1152. }
  1153. int ieee80211_tdls_oper(struct wiphy *wiphy, struct net_device *dev,
  1154. const u8 *peer, enum nl80211_tdls_operation oper)
  1155. {
  1156. struct sta_info *sta;
  1157. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1158. struct ieee80211_local *local = sdata->local;
  1159. int ret;
  1160. if (!(wiphy->flags & WIPHY_FLAG_SUPPORTS_TDLS))
  1161. return -ENOTSUPP;
  1162. if (sdata->vif.type != NL80211_IFTYPE_STATION)
  1163. return -EINVAL;
  1164. switch (oper) {
  1165. case NL80211_TDLS_ENABLE_LINK:
  1166. case NL80211_TDLS_DISABLE_LINK:
  1167. break;
  1168. case NL80211_TDLS_TEARDOWN:
  1169. case NL80211_TDLS_SETUP:
  1170. case NL80211_TDLS_DISCOVERY_REQ:
  1171. /* We don't support in-driver setup/teardown/discovery */
  1172. return -ENOTSUPP;
  1173. }
  1174. /* protect possible bss_conf changes and avoid concurrency in
  1175. * ieee80211_bss_info_change_notify()
  1176. */
  1177. sdata_lock(sdata);
  1178. mutex_lock(&local->mtx);
  1179. tdls_dbg(sdata, "TDLS oper %d peer %pM\n", oper, peer);
  1180. switch (oper) {
  1181. case NL80211_TDLS_ENABLE_LINK:
  1182. if (sdata->vif.csa_active) {
  1183. tdls_dbg(sdata, "TDLS: disallow link during CSA\n");
  1184. ret = -EBUSY;
  1185. break;
  1186. }
  1187. mutex_lock(&local->sta_mtx);
  1188. sta = sta_info_get(sdata, peer);
  1189. if (!sta) {
  1190. mutex_unlock(&local->sta_mtx);
  1191. ret = -ENOLINK;
  1192. break;
  1193. }
  1194. iee80211_tdls_recalc_chanctx(sdata, sta);
  1195. iee80211_tdls_recalc_ht_protection(sdata, sta);
  1196. set_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  1197. mutex_unlock(&local->sta_mtx);
  1198. WARN_ON_ONCE(is_zero_ether_addr(sdata->u.mgd.tdls_peer) ||
  1199. !ether_addr_equal(sdata->u.mgd.tdls_peer, peer));
  1200. ret = 0;
  1201. break;
  1202. case NL80211_TDLS_DISABLE_LINK:
  1203. /*
  1204. * The teardown message in ieee80211_tdls_mgmt_teardown() was
  1205. * created while the queues were stopped, so it might still be
  1206. * pending. Before flushing the queues we need to be sure the
  1207. * message is handled by the tasklet handling pending messages,
  1208. * otherwise we might start destroying the station before
  1209. * sending the teardown packet.
  1210. * Note that this only forces the tasklet to flush pendings -
  1211. * not to stop the tasklet from rescheduling itself.
  1212. */
  1213. tasklet_kill(&local->tx_pending_tasklet);
  1214. /* flush a potentially queued teardown packet */
  1215. ieee80211_flush_queues(local, sdata, false);
  1216. ret = sta_info_destroy_addr(sdata, peer);
  1217. mutex_lock(&local->sta_mtx);
  1218. iee80211_tdls_recalc_ht_protection(sdata, NULL);
  1219. mutex_unlock(&local->sta_mtx);
  1220. iee80211_tdls_recalc_chanctx(sdata, NULL);
  1221. break;
  1222. default:
  1223. ret = -ENOTSUPP;
  1224. break;
  1225. }
  1226. if (ret == 0 && ether_addr_equal(sdata->u.mgd.tdls_peer, peer)) {
  1227. cancel_delayed_work(&sdata->u.mgd.tdls_peer_del_work);
  1228. eth_zero_addr(sdata->u.mgd.tdls_peer);
  1229. }
  1230. if (ret == 0)
  1231. ieee80211_queue_work(&sdata->local->hw,
  1232. &sdata->u.mgd.request_smps_work);
  1233. mutex_unlock(&local->mtx);
  1234. sdata_unlock(sdata);
  1235. return ret;
  1236. }
  1237. void ieee80211_tdls_oper_request(struct ieee80211_vif *vif, const u8 *peer,
  1238. enum nl80211_tdls_operation oper,
  1239. u16 reason_code, gfp_t gfp)
  1240. {
  1241. struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
  1242. if (vif->type != NL80211_IFTYPE_STATION || !vif->bss_conf.assoc) {
  1243. sdata_err(sdata, "Discarding TDLS oper %d - not STA or disconnected\n",
  1244. oper);
  1245. return;
  1246. }
  1247. cfg80211_tdls_oper_request(sdata->dev, peer, oper, reason_code, gfp);
  1248. }
  1249. EXPORT_SYMBOL(ieee80211_tdls_oper_request);
  1250. static void
  1251. iee80211_tdls_add_ch_switch_timing(u8 *buf, u16 switch_time, u16 switch_timeout)
  1252. {
  1253. struct ieee80211_ch_switch_timing *ch_sw;
  1254. *buf++ = WLAN_EID_CHAN_SWITCH_TIMING;
  1255. *buf++ = sizeof(struct ieee80211_ch_switch_timing);
  1256. ch_sw = (void *)buf;
  1257. ch_sw->switch_time = cpu_to_le16(switch_time);
  1258. ch_sw->switch_timeout = cpu_to_le16(switch_timeout);
  1259. }
  1260. /* find switch timing IE in SKB ready for Tx */
  1261. static const u8 *ieee80211_tdls_find_sw_timing_ie(struct sk_buff *skb)
  1262. {
  1263. struct ieee80211_tdls_data *tf;
  1264. const u8 *ie_start;
  1265. /*
  1266. * Get the offset for the new location of the switch timing IE.
  1267. * The SKB network header will now point to the "payload_type"
  1268. * element of the TDLS data frame struct.
  1269. */
  1270. tf = container_of(skb->data + skb_network_offset(skb),
  1271. struct ieee80211_tdls_data, payload_type);
  1272. ie_start = tf->u.chan_switch_req.variable;
  1273. return cfg80211_find_ie(WLAN_EID_CHAN_SWITCH_TIMING, ie_start,
  1274. skb->len - (ie_start - skb->data));
  1275. }
  1276. static struct sk_buff *
  1277. ieee80211_tdls_ch_sw_tmpl_get(struct sta_info *sta, u8 oper_class,
  1278. struct cfg80211_chan_def *chandef,
  1279. u32 *ch_sw_tm_ie_offset)
  1280. {
  1281. struct ieee80211_sub_if_data *sdata = sta->sdata;
  1282. u8 extra_ies[2 + sizeof(struct ieee80211_sec_chan_offs_ie) +
  1283. 2 + sizeof(struct ieee80211_ch_switch_timing)];
  1284. int extra_ies_len = 2 + sizeof(struct ieee80211_ch_switch_timing);
  1285. u8 *pos = extra_ies;
  1286. struct sk_buff *skb;
  1287. /*
  1288. * if chandef points to a wide channel add a Secondary-Channel
  1289. * Offset information element
  1290. */
  1291. if (chandef->width == NL80211_CHAN_WIDTH_40) {
  1292. struct ieee80211_sec_chan_offs_ie *sec_chan_ie;
  1293. bool ht40plus;
  1294. *pos++ = WLAN_EID_SECONDARY_CHANNEL_OFFSET;
  1295. *pos++ = sizeof(*sec_chan_ie);
  1296. sec_chan_ie = (void *)pos;
  1297. ht40plus = cfg80211_get_chandef_type(chandef) ==
  1298. NL80211_CHAN_HT40PLUS;
  1299. sec_chan_ie->sec_chan_offs = ht40plus ?
  1300. IEEE80211_HT_PARAM_CHA_SEC_ABOVE :
  1301. IEEE80211_HT_PARAM_CHA_SEC_BELOW;
  1302. pos += sizeof(*sec_chan_ie);
  1303. extra_ies_len += 2 + sizeof(struct ieee80211_sec_chan_offs_ie);
  1304. }
  1305. /* just set the values to 0, this is a template */
  1306. iee80211_tdls_add_ch_switch_timing(pos, 0, 0);
  1307. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
  1308. WLAN_TDLS_CHANNEL_SWITCH_REQUEST,
  1309. 0, 0, !sta->sta.tdls_initiator,
  1310. extra_ies, extra_ies_len,
  1311. oper_class, chandef);
  1312. if (!skb)
  1313. return NULL;
  1314. skb = ieee80211_build_data_template(sdata, skb, 0);
  1315. if (IS_ERR(skb)) {
  1316. tdls_dbg(sdata, "Failed building TDLS channel switch frame\n");
  1317. return NULL;
  1318. }
  1319. if (ch_sw_tm_ie_offset) {
  1320. const u8 *tm_ie = ieee80211_tdls_find_sw_timing_ie(skb);
  1321. if (!tm_ie) {
  1322. tdls_dbg(sdata, "No switch timing IE in TDLS switch\n");
  1323. dev_kfree_skb_any(skb);
  1324. return NULL;
  1325. }
  1326. *ch_sw_tm_ie_offset = tm_ie - skb->data;
  1327. }
  1328. tdls_dbg(sdata,
  1329. "TDLS channel switch request template for %pM ch %d width %d\n",
  1330. sta->sta.addr, chandef->chan->center_freq, chandef->width);
  1331. return skb;
  1332. }
  1333. int
  1334. ieee80211_tdls_channel_switch(struct wiphy *wiphy, struct net_device *dev,
  1335. const u8 *addr, u8 oper_class,
  1336. struct cfg80211_chan_def *chandef)
  1337. {
  1338. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1339. struct ieee80211_local *local = sdata->local;
  1340. struct sta_info *sta;
  1341. struct sk_buff *skb = NULL;
  1342. u32 ch_sw_tm_ie;
  1343. int ret;
  1344. mutex_lock(&local->sta_mtx);
  1345. sta = sta_info_get(sdata, addr);
  1346. if (!sta) {
  1347. tdls_dbg(sdata,
  1348. "Invalid TDLS peer %pM for channel switch request\n",
  1349. addr);
  1350. ret = -ENOENT;
  1351. goto out;
  1352. }
  1353. if (!test_sta_flag(sta, WLAN_STA_TDLS_CHAN_SWITCH)) {
  1354. tdls_dbg(sdata, "TDLS channel switch unsupported by %pM\n",
  1355. addr);
  1356. ret = -ENOTSUPP;
  1357. goto out;
  1358. }
  1359. skb = ieee80211_tdls_ch_sw_tmpl_get(sta, oper_class, chandef,
  1360. &ch_sw_tm_ie);
  1361. if (!skb) {
  1362. ret = -ENOENT;
  1363. goto out;
  1364. }
  1365. ret = drv_tdls_channel_switch(local, sdata, &sta->sta, oper_class,
  1366. chandef, skb, ch_sw_tm_ie);
  1367. if (!ret)
  1368. set_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL);
  1369. out:
  1370. mutex_unlock(&local->sta_mtx);
  1371. dev_kfree_skb_any(skb);
  1372. return ret;
  1373. }
  1374. void
  1375. ieee80211_tdls_cancel_channel_switch(struct wiphy *wiphy,
  1376. struct net_device *dev,
  1377. const u8 *addr)
  1378. {
  1379. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1380. struct ieee80211_local *local = sdata->local;
  1381. struct sta_info *sta;
  1382. mutex_lock(&local->sta_mtx);
  1383. sta = sta_info_get(sdata, addr);
  1384. if (!sta) {
  1385. tdls_dbg(sdata,
  1386. "Invalid TDLS peer %pM for channel switch cancel\n",
  1387. addr);
  1388. goto out;
  1389. }
  1390. if (!test_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL)) {
  1391. tdls_dbg(sdata, "TDLS channel switch not initiated by %pM\n",
  1392. addr);
  1393. goto out;
  1394. }
  1395. drv_tdls_cancel_channel_switch(local, sdata, &sta->sta);
  1396. clear_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL);
  1397. out:
  1398. mutex_unlock(&local->sta_mtx);
  1399. }
  1400. static struct sk_buff *
  1401. ieee80211_tdls_ch_sw_resp_tmpl_get(struct sta_info *sta,
  1402. u32 *ch_sw_tm_ie_offset)
  1403. {
  1404. struct ieee80211_sub_if_data *sdata = sta->sdata;
  1405. struct sk_buff *skb;
  1406. u8 extra_ies[2 + sizeof(struct ieee80211_ch_switch_timing)];
  1407. /* initial timing are always zero in the template */
  1408. iee80211_tdls_add_ch_switch_timing(extra_ies, 0, 0);
  1409. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
  1410. WLAN_TDLS_CHANNEL_SWITCH_RESPONSE,
  1411. 0, 0, !sta->sta.tdls_initiator,
  1412. extra_ies, sizeof(extra_ies), 0, NULL);
  1413. if (!skb)
  1414. return NULL;
  1415. skb = ieee80211_build_data_template(sdata, skb, 0);
  1416. if (IS_ERR(skb)) {
  1417. tdls_dbg(sdata,
  1418. "Failed building TDLS channel switch resp frame\n");
  1419. return NULL;
  1420. }
  1421. if (ch_sw_tm_ie_offset) {
  1422. const u8 *tm_ie = ieee80211_tdls_find_sw_timing_ie(skb);
  1423. if (!tm_ie) {
  1424. tdls_dbg(sdata,
  1425. "No switch timing IE in TDLS switch resp\n");
  1426. dev_kfree_skb_any(skb);
  1427. return NULL;
  1428. }
  1429. *ch_sw_tm_ie_offset = tm_ie - skb->data;
  1430. }
  1431. tdls_dbg(sdata, "TDLS get channel switch response template for %pM\n",
  1432. sta->sta.addr);
  1433. return skb;
  1434. }
  1435. static int
  1436. ieee80211_process_tdls_channel_switch_resp(struct ieee80211_sub_if_data *sdata,
  1437. struct sk_buff *skb)
  1438. {
  1439. struct ieee80211_local *local = sdata->local;
  1440. struct ieee802_11_elems elems;
  1441. struct sta_info *sta;
  1442. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1443. bool local_initiator;
  1444. struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
  1445. int baselen = offsetof(typeof(*tf), u.chan_switch_resp.variable);
  1446. struct ieee80211_tdls_ch_sw_params params = {};
  1447. int ret;
  1448. params.action_code = WLAN_TDLS_CHANNEL_SWITCH_RESPONSE;
  1449. params.timestamp = rx_status->device_timestamp;
  1450. if (skb->len < baselen) {
  1451. tdls_dbg(sdata, "TDLS channel switch resp too short: %d\n",
  1452. skb->len);
  1453. return -EINVAL;
  1454. }
  1455. mutex_lock(&local->sta_mtx);
  1456. sta = sta_info_get(sdata, tf->sa);
  1457. if (!sta || !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH)) {
  1458. tdls_dbg(sdata, "TDLS chan switch from non-peer sta %pM\n",
  1459. tf->sa);
  1460. ret = -EINVAL;
  1461. goto out;
  1462. }
  1463. params.sta = &sta->sta;
  1464. params.status = le16_to_cpu(tf->u.chan_switch_resp.status_code);
  1465. if (params.status != 0) {
  1466. ret = 0;
  1467. goto call_drv;
  1468. }
  1469. ieee802_11_parse_elems(tf->u.chan_switch_resp.variable,
  1470. skb->len - baselen, false, &elems);
  1471. if (elems.parse_error) {
  1472. tdls_dbg(sdata, "Invalid IEs in TDLS channel switch resp\n");
  1473. ret = -EINVAL;
  1474. goto out;
  1475. }
  1476. if (!elems.ch_sw_timing || !elems.lnk_id) {
  1477. tdls_dbg(sdata, "TDLS channel switch resp - missing IEs\n");
  1478. ret = -EINVAL;
  1479. goto out;
  1480. }
  1481. /* validate the initiator is set correctly */
  1482. local_initiator =
  1483. !memcmp(elems.lnk_id->init_sta, sdata->vif.addr, ETH_ALEN);
  1484. if (local_initiator == sta->sta.tdls_initiator) {
  1485. tdls_dbg(sdata, "TDLS chan switch invalid lnk-id initiator\n");
  1486. ret = -EINVAL;
  1487. goto out;
  1488. }
  1489. params.switch_time = le16_to_cpu(elems.ch_sw_timing->switch_time);
  1490. params.switch_timeout = le16_to_cpu(elems.ch_sw_timing->switch_timeout);
  1491. params.tmpl_skb =
  1492. ieee80211_tdls_ch_sw_resp_tmpl_get(sta, &params.ch_sw_tm_ie);
  1493. if (!params.tmpl_skb) {
  1494. ret = -ENOENT;
  1495. goto out;
  1496. }
  1497. ret = 0;
  1498. call_drv:
  1499. drv_tdls_recv_channel_switch(sdata->local, sdata, &params);
  1500. tdls_dbg(sdata,
  1501. "TDLS channel switch response received from %pM status %d\n",
  1502. tf->sa, params.status);
  1503. out:
  1504. mutex_unlock(&local->sta_mtx);
  1505. dev_kfree_skb_any(params.tmpl_skb);
  1506. return ret;
  1507. }
  1508. static int
  1509. ieee80211_process_tdls_channel_switch_req(struct ieee80211_sub_if_data *sdata,
  1510. struct sk_buff *skb)
  1511. {
  1512. struct ieee80211_local *local = sdata->local;
  1513. struct ieee802_11_elems elems;
  1514. struct cfg80211_chan_def chandef;
  1515. struct ieee80211_channel *chan;
  1516. enum nl80211_channel_type chan_type;
  1517. int freq;
  1518. u8 target_channel, oper_class;
  1519. bool local_initiator;
  1520. struct sta_info *sta;
  1521. enum nl80211_band band;
  1522. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1523. struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
  1524. int baselen = offsetof(typeof(*tf), u.chan_switch_req.variable);
  1525. struct ieee80211_tdls_ch_sw_params params = {};
  1526. int ret = 0;
  1527. params.action_code = WLAN_TDLS_CHANNEL_SWITCH_REQUEST;
  1528. params.timestamp = rx_status->device_timestamp;
  1529. if (skb->len < baselen) {
  1530. tdls_dbg(sdata, "TDLS channel switch req too short: %d\n",
  1531. skb->len);
  1532. return -EINVAL;
  1533. }
  1534. target_channel = tf->u.chan_switch_req.target_channel;
  1535. oper_class = tf->u.chan_switch_req.oper_class;
  1536. /*
  1537. * We can't easily infer the channel band. The operating class is
  1538. * ambiguous - there are multiple tables (US/Europe/JP/Global). The
  1539. * solution here is to treat channels with number >14 as 5GHz ones,
  1540. * and specifically check for the (oper_class, channel) combinations
  1541. * where this doesn't hold. These are thankfully unique according to
  1542. * IEEE802.11-2012.
  1543. * We consider only the 2GHz and 5GHz bands and 20MHz+ channels as
  1544. * valid here.
  1545. */
  1546. if ((oper_class == 112 || oper_class == 2 || oper_class == 3 ||
  1547. oper_class == 4 || oper_class == 5 || oper_class == 6) &&
  1548. target_channel < 14)
  1549. band = NL80211_BAND_5GHZ;
  1550. else
  1551. band = target_channel < 14 ? NL80211_BAND_2GHZ :
  1552. NL80211_BAND_5GHZ;
  1553. freq = ieee80211_channel_to_frequency(target_channel, band);
  1554. if (freq == 0) {
  1555. tdls_dbg(sdata, "Invalid channel in TDLS chan switch: %d\n",
  1556. target_channel);
  1557. return -EINVAL;
  1558. }
  1559. chan = ieee80211_get_channel(sdata->local->hw.wiphy, freq);
  1560. if (!chan) {
  1561. tdls_dbg(sdata,
  1562. "Unsupported channel for TDLS chan switch: %d\n",
  1563. target_channel);
  1564. return -EINVAL;
  1565. }
  1566. ieee802_11_parse_elems(tf->u.chan_switch_req.variable,
  1567. skb->len - baselen, false, &elems);
  1568. if (elems.parse_error) {
  1569. tdls_dbg(sdata, "Invalid IEs in TDLS channel switch req\n");
  1570. return -EINVAL;
  1571. }
  1572. if (!elems.ch_sw_timing || !elems.lnk_id) {
  1573. tdls_dbg(sdata, "TDLS channel switch req - missing IEs\n");
  1574. return -EINVAL;
  1575. }
  1576. if (!elems.sec_chan_offs) {
  1577. chan_type = NL80211_CHAN_HT20;
  1578. } else {
  1579. switch (elems.sec_chan_offs->sec_chan_offs) {
  1580. case IEEE80211_HT_PARAM_CHA_SEC_ABOVE:
  1581. chan_type = NL80211_CHAN_HT40PLUS;
  1582. break;
  1583. case IEEE80211_HT_PARAM_CHA_SEC_BELOW:
  1584. chan_type = NL80211_CHAN_HT40MINUS;
  1585. break;
  1586. default:
  1587. chan_type = NL80211_CHAN_HT20;
  1588. break;
  1589. }
  1590. }
  1591. cfg80211_chandef_create(&chandef, chan, chan_type);
  1592. /* we will be active on the TDLS link */
  1593. if (!cfg80211_reg_can_beacon_relax(sdata->local->hw.wiphy, &chandef,
  1594. sdata->wdev.iftype)) {
  1595. tdls_dbg(sdata, "TDLS chan switch to forbidden channel\n");
  1596. return -EINVAL;
  1597. }
  1598. mutex_lock(&local->sta_mtx);
  1599. sta = sta_info_get(sdata, tf->sa);
  1600. if (!sta || !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH)) {
  1601. tdls_dbg(sdata, "TDLS chan switch from non-peer sta %pM\n",
  1602. tf->sa);
  1603. ret = -EINVAL;
  1604. goto out;
  1605. }
  1606. params.sta = &sta->sta;
  1607. /* validate the initiator is set correctly */
  1608. local_initiator =
  1609. !memcmp(elems.lnk_id->init_sta, sdata->vif.addr, ETH_ALEN);
  1610. if (local_initiator == sta->sta.tdls_initiator) {
  1611. tdls_dbg(sdata, "TDLS chan switch invalid lnk-id initiator\n");
  1612. ret = -EINVAL;
  1613. goto out;
  1614. }
  1615. /* peer should have known better */
  1616. if (!sta->sta.ht_cap.ht_supported && elems.sec_chan_offs &&
  1617. elems.sec_chan_offs->sec_chan_offs) {
  1618. tdls_dbg(sdata, "TDLS chan switch - wide chan unsupported\n");
  1619. ret = -ENOTSUPP;
  1620. goto out;
  1621. }
  1622. params.chandef = &chandef;
  1623. params.switch_time = le16_to_cpu(elems.ch_sw_timing->switch_time);
  1624. params.switch_timeout = le16_to_cpu(elems.ch_sw_timing->switch_timeout);
  1625. params.tmpl_skb =
  1626. ieee80211_tdls_ch_sw_resp_tmpl_get(sta,
  1627. &params.ch_sw_tm_ie);
  1628. if (!params.tmpl_skb) {
  1629. ret = -ENOENT;
  1630. goto out;
  1631. }
  1632. drv_tdls_recv_channel_switch(sdata->local, sdata, &params);
  1633. tdls_dbg(sdata,
  1634. "TDLS ch switch request received from %pM ch %d width %d\n",
  1635. tf->sa, params.chandef->chan->center_freq,
  1636. params.chandef->width);
  1637. out:
  1638. mutex_unlock(&local->sta_mtx);
  1639. dev_kfree_skb_any(params.tmpl_skb);
  1640. return ret;
  1641. }
  1642. static void
  1643. ieee80211_process_tdls_channel_switch(struct ieee80211_sub_if_data *sdata,
  1644. struct sk_buff *skb)
  1645. {
  1646. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1647. struct wiphy *wiphy = sdata->local->hw.wiphy;
  1648. ASSERT_RTNL();
  1649. /* make sure the driver supports it */
  1650. if (!(wiphy->features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
  1651. return;
  1652. /* we want to access the entire packet */
  1653. if (skb_linearize(skb))
  1654. return;
  1655. /*
  1656. * The packet/size was already validated by mac80211 Rx path, only look
  1657. * at the action type.
  1658. */
  1659. switch (tf->action_code) {
  1660. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  1661. ieee80211_process_tdls_channel_switch_req(sdata, skb);
  1662. break;
  1663. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  1664. ieee80211_process_tdls_channel_switch_resp(sdata, skb);
  1665. break;
  1666. default:
  1667. WARN_ON_ONCE(1);
  1668. return;
  1669. }
  1670. }
  1671. void ieee80211_teardown_tdls_peers(struct ieee80211_sub_if_data *sdata)
  1672. {
  1673. struct sta_info *sta;
  1674. u16 reason = WLAN_REASON_TDLS_TEARDOWN_UNSPECIFIED;
  1675. rcu_read_lock();
  1676. list_for_each_entry_rcu(sta, &sdata->local->sta_list, list) {
  1677. if (!sta->sta.tdls || sta->sdata != sdata || !sta->uploaded ||
  1678. !test_sta_flag(sta, WLAN_STA_AUTHORIZED))
  1679. continue;
  1680. ieee80211_tdls_oper_request(&sdata->vif, sta->sta.addr,
  1681. NL80211_TDLS_TEARDOWN, reason,
  1682. GFP_ATOMIC);
  1683. }
  1684. rcu_read_unlock();
  1685. }
  1686. void ieee80211_tdls_chsw_work(struct work_struct *wk)
  1687. {
  1688. struct ieee80211_local *local =
  1689. container_of(wk, struct ieee80211_local, tdls_chsw_work);
  1690. struct ieee80211_sub_if_data *sdata;
  1691. struct sk_buff *skb;
  1692. struct ieee80211_tdls_data *tf;
  1693. rtnl_lock();
  1694. while ((skb = skb_dequeue(&local->skb_queue_tdls_chsw))) {
  1695. tf = (struct ieee80211_tdls_data *)skb->data;
  1696. list_for_each_entry(sdata, &local->interfaces, list) {
  1697. if (!ieee80211_sdata_running(sdata) ||
  1698. sdata->vif.type != NL80211_IFTYPE_STATION ||
  1699. !ether_addr_equal(tf->da, sdata->vif.addr))
  1700. continue;
  1701. ieee80211_process_tdls_channel_switch(sdata, skb);
  1702. break;
  1703. }
  1704. kfree_skb(skb);
  1705. }
  1706. rtnl_unlock();
  1707. }