tdls.c 55 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993
  1. /*
  2. * mac80211 TDLS handling code
  3. *
  4. * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
  5. * Copyright 2014, Intel Corporation
  6. * Copyright 2014 Intel Mobile Communications GmbH
  7. * Copyright 2015 - 2016 Intel Deutschland GmbH
  8. *
  9. * This file is GPLv2 as found in COPYING.
  10. */
  11. #include <linux/ieee80211.h>
  12. #include <linux/log2.h>
  13. #include <net/cfg80211.h>
  14. #include <linux/rtnetlink.h>
  15. #include "ieee80211_i.h"
  16. #include "driver-ops.h"
  17. #include "rate.h"
  18. /* give usermode some time for retries in setting up the TDLS session */
  19. #define TDLS_PEER_SETUP_TIMEOUT (15 * HZ)
  20. void ieee80211_tdls_peer_del_work(struct work_struct *wk)
  21. {
  22. struct ieee80211_sub_if_data *sdata;
  23. struct ieee80211_local *local;
  24. sdata = container_of(wk, struct ieee80211_sub_if_data,
  25. u.mgd.tdls_peer_del_work.work);
  26. local = sdata->local;
  27. mutex_lock(&local->mtx);
  28. if (!is_zero_ether_addr(sdata->u.mgd.tdls_peer)) {
  29. tdls_dbg(sdata, "TDLS del peer %pM\n", sdata->u.mgd.tdls_peer);
  30. sta_info_destroy_addr(sdata, sdata->u.mgd.tdls_peer);
  31. eth_zero_addr(sdata->u.mgd.tdls_peer);
  32. }
  33. mutex_unlock(&local->mtx);
  34. }
  35. static void ieee80211_tdls_add_ext_capab(struct ieee80211_sub_if_data *sdata,
  36. struct sk_buff *skb)
  37. {
  38. struct ieee80211_local *local = sdata->local;
  39. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  40. bool chan_switch = local->hw.wiphy->features &
  41. NL80211_FEATURE_TDLS_CHANNEL_SWITCH;
  42. bool wider_band = ieee80211_hw_check(&local->hw, TDLS_WIDER_BW) &&
  43. !ifmgd->tdls_wider_bw_prohibited;
  44. enum nl80211_band band = ieee80211_get_sdata_band(sdata);
  45. struct ieee80211_supported_band *sband = local->hw.wiphy->bands[band];
  46. bool vht = sband && sband->vht_cap.vht_supported;
  47. u8 *pos = (void *)skb_put(skb, 10);
  48. *pos++ = WLAN_EID_EXT_CAPABILITY;
  49. *pos++ = 8; /* len */
  50. *pos++ = 0x0;
  51. *pos++ = 0x0;
  52. *pos++ = 0x0;
  53. *pos++ = chan_switch ? WLAN_EXT_CAPA4_TDLS_CHAN_SWITCH : 0;
  54. *pos++ = WLAN_EXT_CAPA5_TDLS_ENABLED;
  55. *pos++ = 0;
  56. *pos++ = 0;
  57. *pos++ = (vht && wider_band) ? WLAN_EXT_CAPA8_TDLS_WIDE_BW_ENABLED : 0;
  58. }
  59. static u8
  60. ieee80211_tdls_add_subband(struct ieee80211_sub_if_data *sdata,
  61. struct sk_buff *skb, u16 start, u16 end,
  62. u16 spacing)
  63. {
  64. u8 subband_cnt = 0, ch_cnt = 0;
  65. struct ieee80211_channel *ch;
  66. struct cfg80211_chan_def chandef;
  67. int i, subband_start;
  68. struct wiphy *wiphy = sdata->local->hw.wiphy;
  69. for (i = start; i <= end; i += spacing) {
  70. if (!ch_cnt)
  71. subband_start = i;
  72. ch = ieee80211_get_channel(sdata->local->hw.wiphy, i);
  73. if (ch) {
  74. /* we will be active on the channel */
  75. cfg80211_chandef_create(&chandef, ch,
  76. NL80211_CHAN_NO_HT);
  77. if (cfg80211_reg_can_beacon_relax(wiphy, &chandef,
  78. sdata->wdev.iftype)) {
  79. ch_cnt++;
  80. /*
  81. * check if the next channel is also part of
  82. * this allowed range
  83. */
  84. continue;
  85. }
  86. }
  87. /*
  88. * we've reached the end of a range, with allowed channels
  89. * found
  90. */
  91. if (ch_cnt) {
  92. u8 *pos = skb_put(skb, 2);
  93. *pos++ = ieee80211_frequency_to_channel(subband_start);
  94. *pos++ = ch_cnt;
  95. subband_cnt++;
  96. ch_cnt = 0;
  97. }
  98. }
  99. /* all channels in the requested range are allowed - add them here */
  100. if (ch_cnt) {
  101. u8 *pos = skb_put(skb, 2);
  102. *pos++ = ieee80211_frequency_to_channel(subband_start);
  103. *pos++ = ch_cnt;
  104. subband_cnt++;
  105. }
  106. return subband_cnt;
  107. }
  108. static void
  109. ieee80211_tdls_add_supp_channels(struct ieee80211_sub_if_data *sdata,
  110. struct sk_buff *skb)
  111. {
  112. /*
  113. * Add possible channels for TDLS. These are channels that are allowed
  114. * to be active.
  115. */
  116. u8 subband_cnt;
  117. u8 *pos = skb_put(skb, 2);
  118. *pos++ = WLAN_EID_SUPPORTED_CHANNELS;
  119. /*
  120. * 5GHz and 2GHz channels numbers can overlap. Ignore this for now, as
  121. * this doesn't happen in real world scenarios.
  122. */
  123. /* 2GHz, with 5MHz spacing */
  124. subband_cnt = ieee80211_tdls_add_subband(sdata, skb, 2412, 2472, 5);
  125. /* 5GHz, with 20MHz spacing */
  126. subband_cnt += ieee80211_tdls_add_subband(sdata, skb, 5000, 5825, 20);
  127. /* length */
  128. *pos = 2 * subband_cnt;
  129. }
  130. static void ieee80211_tdls_add_oper_classes(struct ieee80211_sub_if_data *sdata,
  131. struct sk_buff *skb)
  132. {
  133. u8 *pos;
  134. u8 op_class;
  135. if (!ieee80211_chandef_to_operating_class(&sdata->vif.bss_conf.chandef,
  136. &op_class))
  137. return;
  138. pos = skb_put(skb, 4);
  139. *pos++ = WLAN_EID_SUPPORTED_REGULATORY_CLASSES;
  140. *pos++ = 2; /* len */
  141. *pos++ = op_class;
  142. *pos++ = op_class; /* give current operating class as alternate too */
  143. }
  144. static void ieee80211_tdls_add_bss_coex_ie(struct sk_buff *skb)
  145. {
  146. u8 *pos = (void *)skb_put(skb, 3);
  147. *pos++ = WLAN_EID_BSS_COEX_2040;
  148. *pos++ = 1; /* len */
  149. *pos++ = WLAN_BSS_COEX_INFORMATION_REQUEST;
  150. }
  151. static u16 ieee80211_get_tdls_sta_capab(struct ieee80211_sub_if_data *sdata,
  152. u16 status_code)
  153. {
  154. /* The capability will be 0 when sending a failure code */
  155. if (status_code != 0)
  156. return 0;
  157. if (ieee80211_get_sdata_band(sdata) == NL80211_BAND_2GHZ) {
  158. return WLAN_CAPABILITY_SHORT_SLOT_TIME |
  159. WLAN_CAPABILITY_SHORT_PREAMBLE;
  160. }
  161. return 0;
  162. }
  163. static void ieee80211_tdls_add_link_ie(struct ieee80211_sub_if_data *sdata,
  164. struct sk_buff *skb, const u8 *peer,
  165. bool initiator)
  166. {
  167. struct ieee80211_tdls_lnkie *lnkid;
  168. const u8 *init_addr, *rsp_addr;
  169. if (initiator) {
  170. init_addr = sdata->vif.addr;
  171. rsp_addr = peer;
  172. } else {
  173. init_addr = peer;
  174. rsp_addr = sdata->vif.addr;
  175. }
  176. lnkid = (void *)skb_put(skb, sizeof(struct ieee80211_tdls_lnkie));
  177. lnkid->ie_type = WLAN_EID_LINK_ID;
  178. lnkid->ie_len = sizeof(struct ieee80211_tdls_lnkie) - 2;
  179. memcpy(lnkid->bssid, sdata->u.mgd.bssid, ETH_ALEN);
  180. memcpy(lnkid->init_sta, init_addr, ETH_ALEN);
  181. memcpy(lnkid->resp_sta, rsp_addr, ETH_ALEN);
  182. }
  183. static void
  184. ieee80211_tdls_add_aid(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
  185. {
  186. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  187. u8 *pos = (void *)skb_put(skb, 4);
  188. *pos++ = WLAN_EID_AID;
  189. *pos++ = 2; /* len */
  190. put_unaligned_le16(ifmgd->aid, pos);
  191. }
  192. /* translate numbering in the WMM parameter IE to the mac80211 notation */
  193. static enum ieee80211_ac_numbers ieee80211_ac_from_wmm(int ac)
  194. {
  195. switch (ac) {
  196. default:
  197. WARN_ON_ONCE(1);
  198. case 0:
  199. return IEEE80211_AC_BE;
  200. case 1:
  201. return IEEE80211_AC_BK;
  202. case 2:
  203. return IEEE80211_AC_VI;
  204. case 3:
  205. return IEEE80211_AC_VO;
  206. }
  207. }
  208. static u8 ieee80211_wmm_aci_aifsn(int aifsn, bool acm, int aci)
  209. {
  210. u8 ret;
  211. ret = aifsn & 0x0f;
  212. if (acm)
  213. ret |= 0x10;
  214. ret |= (aci << 5) & 0x60;
  215. return ret;
  216. }
  217. static u8 ieee80211_wmm_ecw(u16 cw_min, u16 cw_max)
  218. {
  219. return ((ilog2(cw_min + 1) << 0x0) & 0x0f) |
  220. ((ilog2(cw_max + 1) << 0x4) & 0xf0);
  221. }
  222. static void ieee80211_tdls_add_wmm_param_ie(struct ieee80211_sub_if_data *sdata,
  223. struct sk_buff *skb)
  224. {
  225. struct ieee80211_wmm_param_ie *wmm;
  226. struct ieee80211_tx_queue_params *txq;
  227. int i;
  228. wmm = (void *)skb_put(skb, sizeof(*wmm));
  229. memset(wmm, 0, sizeof(*wmm));
  230. wmm->element_id = WLAN_EID_VENDOR_SPECIFIC;
  231. wmm->len = sizeof(*wmm) - 2;
  232. wmm->oui[0] = 0x00; /* Microsoft OUI 00:50:F2 */
  233. wmm->oui[1] = 0x50;
  234. wmm->oui[2] = 0xf2;
  235. wmm->oui_type = 2; /* WME */
  236. wmm->oui_subtype = 1; /* WME param */
  237. wmm->version = 1; /* WME ver */
  238. wmm->qos_info = 0; /* U-APSD not in use */
  239. /*
  240. * Use the EDCA parameters defined for the BSS, or default if the AP
  241. * doesn't support it, as mandated by 802.11-2012 section 10.22.4
  242. */
  243. for (i = 0; i < IEEE80211_NUM_ACS; i++) {
  244. txq = &sdata->tx_conf[ieee80211_ac_from_wmm(i)];
  245. wmm->ac[i].aci_aifsn = ieee80211_wmm_aci_aifsn(txq->aifs,
  246. txq->acm, i);
  247. wmm->ac[i].cw = ieee80211_wmm_ecw(txq->cw_min, txq->cw_max);
  248. wmm->ac[i].txop_limit = cpu_to_le16(txq->txop);
  249. }
  250. }
  251. static void
  252. ieee80211_tdls_chandef_vht_upgrade(struct ieee80211_sub_if_data *sdata,
  253. struct sta_info *sta)
  254. {
  255. /* IEEE802.11ac-2013 Table E-4 */
  256. u16 centers_80mhz[] = { 5210, 5290, 5530, 5610, 5690, 5775 };
  257. struct cfg80211_chan_def uc = sta->tdls_chandef;
  258. enum nl80211_chan_width max_width = ieee80211_sta_cap_chan_bw(sta);
  259. int i;
  260. /* only support upgrading non-narrow channels up to 80Mhz */
  261. if (max_width == NL80211_CHAN_WIDTH_5 ||
  262. max_width == NL80211_CHAN_WIDTH_10)
  263. return;
  264. if (max_width > NL80211_CHAN_WIDTH_80)
  265. max_width = NL80211_CHAN_WIDTH_80;
  266. if (uc.width >= max_width)
  267. return;
  268. /*
  269. * Channel usage constrains in the IEEE802.11ac-2013 specification only
  270. * allow expanding a 20MHz channel to 80MHz in a single way. In
  271. * addition, there are no 40MHz allowed channels that are not part of
  272. * the allowed 80MHz range in the 5GHz spectrum (the relevant one here).
  273. */
  274. for (i = 0; i < ARRAY_SIZE(centers_80mhz); i++)
  275. if (abs(uc.chan->center_freq - centers_80mhz[i]) <= 30) {
  276. uc.center_freq1 = centers_80mhz[i];
  277. uc.center_freq2 = 0;
  278. uc.width = NL80211_CHAN_WIDTH_80;
  279. break;
  280. }
  281. if (!uc.center_freq1)
  282. return;
  283. /* proceed to downgrade the chandef until usable or the same */
  284. while (uc.width > max_width ||
  285. !cfg80211_reg_can_beacon_relax(sdata->local->hw.wiphy, &uc,
  286. sdata->wdev.iftype))
  287. ieee80211_chandef_downgrade(&uc);
  288. if (!cfg80211_chandef_identical(&uc, &sta->tdls_chandef)) {
  289. tdls_dbg(sdata, "TDLS ch width upgraded %d -> %d\n",
  290. sta->tdls_chandef.width, uc.width);
  291. /*
  292. * the station is not yet authorized when BW upgrade is done,
  293. * locking is not required
  294. */
  295. sta->tdls_chandef = uc;
  296. }
  297. }
  298. static void
  299. ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
  300. struct sk_buff *skb, const u8 *peer,
  301. u8 action_code, bool initiator,
  302. const u8 *extra_ies, size_t extra_ies_len)
  303. {
  304. enum nl80211_band band = ieee80211_get_sdata_band(sdata);
  305. struct ieee80211_local *local = sdata->local;
  306. struct ieee80211_supported_band *sband;
  307. struct ieee80211_sta_ht_cap ht_cap;
  308. struct ieee80211_sta_vht_cap vht_cap;
  309. struct sta_info *sta = NULL;
  310. size_t offset = 0, noffset;
  311. u8 *pos;
  312. ieee80211_add_srates_ie(sdata, skb, false, band);
  313. ieee80211_add_ext_srates_ie(sdata, skb, false, band);
  314. ieee80211_tdls_add_supp_channels(sdata, skb);
  315. /* add any custom IEs that go before Extended Capabilities */
  316. if (extra_ies_len) {
  317. static const u8 before_ext_cap[] = {
  318. WLAN_EID_SUPP_RATES,
  319. WLAN_EID_COUNTRY,
  320. WLAN_EID_EXT_SUPP_RATES,
  321. WLAN_EID_SUPPORTED_CHANNELS,
  322. WLAN_EID_RSN,
  323. };
  324. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  325. before_ext_cap,
  326. ARRAY_SIZE(before_ext_cap),
  327. offset);
  328. pos = skb_put(skb, noffset - offset);
  329. memcpy(pos, extra_ies + offset, noffset - offset);
  330. offset = noffset;
  331. }
  332. ieee80211_tdls_add_ext_capab(sdata, skb);
  333. /* add the QoS element if we support it */
  334. if (local->hw.queues >= IEEE80211_NUM_ACS &&
  335. action_code != WLAN_PUB_ACTION_TDLS_DISCOVER_RES)
  336. ieee80211_add_wmm_info_ie(skb_put(skb, 9), 0); /* no U-APSD */
  337. /* add any custom IEs that go before HT capabilities */
  338. if (extra_ies_len) {
  339. static const u8 before_ht_cap[] = {
  340. WLAN_EID_SUPP_RATES,
  341. WLAN_EID_COUNTRY,
  342. WLAN_EID_EXT_SUPP_RATES,
  343. WLAN_EID_SUPPORTED_CHANNELS,
  344. WLAN_EID_RSN,
  345. WLAN_EID_EXT_CAPABILITY,
  346. WLAN_EID_QOS_CAPA,
  347. WLAN_EID_FAST_BSS_TRANSITION,
  348. WLAN_EID_TIMEOUT_INTERVAL,
  349. WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
  350. };
  351. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  352. before_ht_cap,
  353. ARRAY_SIZE(before_ht_cap),
  354. offset);
  355. pos = skb_put(skb, noffset - offset);
  356. memcpy(pos, extra_ies + offset, noffset - offset);
  357. offset = noffset;
  358. }
  359. mutex_lock(&local->sta_mtx);
  360. /* we should have the peer STA if we're already responding */
  361. if (action_code == WLAN_TDLS_SETUP_RESPONSE) {
  362. sta = sta_info_get(sdata, peer);
  363. if (WARN_ON_ONCE(!sta)) {
  364. mutex_unlock(&local->sta_mtx);
  365. return;
  366. }
  367. sta->tdls_chandef = sdata->vif.bss_conf.chandef;
  368. }
  369. ieee80211_tdls_add_oper_classes(sdata, skb);
  370. /*
  371. * with TDLS we can switch channels, and HT-caps are not necessarily
  372. * the same on all bands. The specification limits the setup to a
  373. * single HT-cap, so use the current band for now.
  374. */
  375. sband = local->hw.wiphy->bands[band];
  376. memcpy(&ht_cap, &sband->ht_cap, sizeof(ht_cap));
  377. if ((action_code == WLAN_TDLS_SETUP_REQUEST ||
  378. action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) &&
  379. ht_cap.ht_supported) {
  380. ieee80211_apply_htcap_overrides(sdata, &ht_cap);
  381. /* disable SMPS in TDLS initiator */
  382. ht_cap.cap |= WLAN_HT_CAP_SM_PS_DISABLED
  383. << IEEE80211_HT_CAP_SM_PS_SHIFT;
  384. pos = skb_put(skb, sizeof(struct ieee80211_ht_cap) + 2);
  385. ieee80211_ie_build_ht_cap(pos, &ht_cap, ht_cap.cap);
  386. } else if (action_code == WLAN_TDLS_SETUP_RESPONSE &&
  387. ht_cap.ht_supported && sta->sta.ht_cap.ht_supported) {
  388. /* the peer caps are already intersected with our own */
  389. memcpy(&ht_cap, &sta->sta.ht_cap, sizeof(ht_cap));
  390. pos = skb_put(skb, sizeof(struct ieee80211_ht_cap) + 2);
  391. ieee80211_ie_build_ht_cap(pos, &ht_cap, ht_cap.cap);
  392. }
  393. if (ht_cap.ht_supported &&
  394. (ht_cap.cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40))
  395. ieee80211_tdls_add_bss_coex_ie(skb);
  396. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  397. /* add any custom IEs that go before VHT capabilities */
  398. if (extra_ies_len) {
  399. static const u8 before_vht_cap[] = {
  400. WLAN_EID_SUPP_RATES,
  401. WLAN_EID_COUNTRY,
  402. WLAN_EID_EXT_SUPP_RATES,
  403. WLAN_EID_SUPPORTED_CHANNELS,
  404. WLAN_EID_RSN,
  405. WLAN_EID_EXT_CAPABILITY,
  406. WLAN_EID_QOS_CAPA,
  407. WLAN_EID_FAST_BSS_TRANSITION,
  408. WLAN_EID_TIMEOUT_INTERVAL,
  409. WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
  410. WLAN_EID_MULTI_BAND,
  411. };
  412. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  413. before_vht_cap,
  414. ARRAY_SIZE(before_vht_cap),
  415. offset);
  416. pos = skb_put(skb, noffset - offset);
  417. memcpy(pos, extra_ies + offset, noffset - offset);
  418. offset = noffset;
  419. }
  420. /* build the VHT-cap similarly to the HT-cap */
  421. memcpy(&vht_cap, &sband->vht_cap, sizeof(vht_cap));
  422. if ((action_code == WLAN_TDLS_SETUP_REQUEST ||
  423. action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) &&
  424. vht_cap.vht_supported) {
  425. ieee80211_apply_vhtcap_overrides(sdata, &vht_cap);
  426. /* the AID is present only when VHT is implemented */
  427. if (action_code == WLAN_TDLS_SETUP_REQUEST)
  428. ieee80211_tdls_add_aid(sdata, skb);
  429. pos = skb_put(skb, sizeof(struct ieee80211_vht_cap) + 2);
  430. ieee80211_ie_build_vht_cap(pos, &vht_cap, vht_cap.cap);
  431. } else if (action_code == WLAN_TDLS_SETUP_RESPONSE &&
  432. vht_cap.vht_supported && sta->sta.vht_cap.vht_supported) {
  433. /* the peer caps are already intersected with our own */
  434. memcpy(&vht_cap, &sta->sta.vht_cap, sizeof(vht_cap));
  435. /* the AID is present only when VHT is implemented */
  436. ieee80211_tdls_add_aid(sdata, skb);
  437. pos = skb_put(skb, sizeof(struct ieee80211_vht_cap) + 2);
  438. ieee80211_ie_build_vht_cap(pos, &vht_cap, vht_cap.cap);
  439. /*
  440. * if both peers support WIDER_BW, we can expand the chandef to
  441. * a wider compatible one, up to 80MHz
  442. */
  443. if (test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW))
  444. ieee80211_tdls_chandef_vht_upgrade(sdata, sta);
  445. }
  446. mutex_unlock(&local->sta_mtx);
  447. /* add any remaining IEs */
  448. if (extra_ies_len) {
  449. noffset = extra_ies_len;
  450. pos = skb_put(skb, noffset - offset);
  451. memcpy(pos, extra_ies + offset, noffset - offset);
  452. }
  453. }
  454. static void
  455. ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_sub_if_data *sdata,
  456. struct sk_buff *skb, const u8 *peer,
  457. bool initiator, const u8 *extra_ies,
  458. size_t extra_ies_len)
  459. {
  460. struct ieee80211_local *local = sdata->local;
  461. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  462. size_t offset = 0, noffset;
  463. struct sta_info *sta, *ap_sta;
  464. enum nl80211_band band = ieee80211_get_sdata_band(sdata);
  465. u8 *pos;
  466. mutex_lock(&local->sta_mtx);
  467. sta = sta_info_get(sdata, peer);
  468. ap_sta = sta_info_get(sdata, ifmgd->bssid);
  469. if (WARN_ON_ONCE(!sta || !ap_sta)) {
  470. mutex_unlock(&local->sta_mtx);
  471. return;
  472. }
  473. sta->tdls_chandef = sdata->vif.bss_conf.chandef;
  474. /* add any custom IEs that go before the QoS IE */
  475. if (extra_ies_len) {
  476. static const u8 before_qos[] = {
  477. WLAN_EID_RSN,
  478. };
  479. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  480. before_qos,
  481. ARRAY_SIZE(before_qos),
  482. offset);
  483. pos = skb_put(skb, noffset - offset);
  484. memcpy(pos, extra_ies + offset, noffset - offset);
  485. offset = noffset;
  486. }
  487. /* add the QoS param IE if both the peer and we support it */
  488. if (local->hw.queues >= IEEE80211_NUM_ACS && sta->sta.wme)
  489. ieee80211_tdls_add_wmm_param_ie(sdata, skb);
  490. /* add any custom IEs that go before HT operation */
  491. if (extra_ies_len) {
  492. static const u8 before_ht_op[] = {
  493. WLAN_EID_RSN,
  494. WLAN_EID_QOS_CAPA,
  495. WLAN_EID_FAST_BSS_TRANSITION,
  496. WLAN_EID_TIMEOUT_INTERVAL,
  497. };
  498. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  499. before_ht_op,
  500. ARRAY_SIZE(before_ht_op),
  501. offset);
  502. pos = skb_put(skb, noffset - offset);
  503. memcpy(pos, extra_ies + offset, noffset - offset);
  504. offset = noffset;
  505. }
  506. /*
  507. * if HT support is only added in TDLS, we need an HT-operation IE.
  508. * add the IE as required by IEEE802.11-2012 9.23.3.2.
  509. */
  510. if (!ap_sta->sta.ht_cap.ht_supported && sta->sta.ht_cap.ht_supported) {
  511. u16 prot = IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED |
  512. IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
  513. IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
  514. pos = skb_put(skb, 2 + sizeof(struct ieee80211_ht_operation));
  515. ieee80211_ie_build_ht_oper(pos, &sta->sta.ht_cap,
  516. &sdata->vif.bss_conf.chandef, prot,
  517. true);
  518. }
  519. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  520. /* only include VHT-operation if not on the 2.4GHz band */
  521. if (band != NL80211_BAND_2GHZ && sta->sta.vht_cap.vht_supported) {
  522. /*
  523. * if both peers support WIDER_BW, we can expand the chandef to
  524. * a wider compatible one, up to 80MHz
  525. */
  526. if (test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW))
  527. ieee80211_tdls_chandef_vht_upgrade(sdata, sta);
  528. pos = skb_put(skb, 2 + sizeof(struct ieee80211_vht_operation));
  529. ieee80211_ie_build_vht_oper(pos, &sta->sta.vht_cap,
  530. &sta->tdls_chandef);
  531. }
  532. mutex_unlock(&local->sta_mtx);
  533. /* add any remaining IEs */
  534. if (extra_ies_len) {
  535. noffset = extra_ies_len;
  536. pos = skb_put(skb, noffset - offset);
  537. memcpy(pos, extra_ies + offset, noffset - offset);
  538. }
  539. }
  540. static void
  541. ieee80211_tdls_add_chan_switch_req_ies(struct ieee80211_sub_if_data *sdata,
  542. struct sk_buff *skb, const u8 *peer,
  543. bool initiator, const u8 *extra_ies,
  544. size_t extra_ies_len, u8 oper_class,
  545. struct cfg80211_chan_def *chandef)
  546. {
  547. struct ieee80211_tdls_data *tf;
  548. size_t offset = 0, noffset;
  549. u8 *pos;
  550. if (WARN_ON_ONCE(!chandef))
  551. return;
  552. tf = (void *)skb->data;
  553. tf->u.chan_switch_req.target_channel =
  554. ieee80211_frequency_to_channel(chandef->chan->center_freq);
  555. tf->u.chan_switch_req.oper_class = oper_class;
  556. if (extra_ies_len) {
  557. static const u8 before_lnkie[] = {
  558. WLAN_EID_SECONDARY_CHANNEL_OFFSET,
  559. };
  560. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  561. before_lnkie,
  562. ARRAY_SIZE(before_lnkie),
  563. offset);
  564. pos = skb_put(skb, noffset - offset);
  565. memcpy(pos, extra_ies + offset, noffset - offset);
  566. offset = noffset;
  567. }
  568. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  569. /* add any remaining IEs */
  570. if (extra_ies_len) {
  571. noffset = extra_ies_len;
  572. pos = skb_put(skb, noffset - offset);
  573. memcpy(pos, extra_ies + offset, noffset - offset);
  574. }
  575. }
  576. static void
  577. ieee80211_tdls_add_chan_switch_resp_ies(struct ieee80211_sub_if_data *sdata,
  578. struct sk_buff *skb, const u8 *peer,
  579. u16 status_code, bool initiator,
  580. const u8 *extra_ies,
  581. size_t extra_ies_len)
  582. {
  583. if (status_code == 0)
  584. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  585. if (extra_ies_len)
  586. memcpy(skb_put(skb, extra_ies_len), extra_ies, extra_ies_len);
  587. }
  588. static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
  589. struct sk_buff *skb, const u8 *peer,
  590. u8 action_code, u16 status_code,
  591. bool initiator, const u8 *extra_ies,
  592. size_t extra_ies_len, u8 oper_class,
  593. struct cfg80211_chan_def *chandef)
  594. {
  595. switch (action_code) {
  596. case WLAN_TDLS_SETUP_REQUEST:
  597. case WLAN_TDLS_SETUP_RESPONSE:
  598. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  599. if (status_code == 0)
  600. ieee80211_tdls_add_setup_start_ies(sdata, skb, peer,
  601. action_code,
  602. initiator,
  603. extra_ies,
  604. extra_ies_len);
  605. break;
  606. case WLAN_TDLS_SETUP_CONFIRM:
  607. if (status_code == 0)
  608. ieee80211_tdls_add_setup_cfm_ies(sdata, skb, peer,
  609. initiator, extra_ies,
  610. extra_ies_len);
  611. break;
  612. case WLAN_TDLS_TEARDOWN:
  613. case WLAN_TDLS_DISCOVERY_REQUEST:
  614. if (extra_ies_len)
  615. memcpy(skb_put(skb, extra_ies_len), extra_ies,
  616. extra_ies_len);
  617. if (status_code == 0 || action_code == WLAN_TDLS_TEARDOWN)
  618. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  619. break;
  620. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  621. ieee80211_tdls_add_chan_switch_req_ies(sdata, skb, peer,
  622. initiator, extra_ies,
  623. extra_ies_len,
  624. oper_class, chandef);
  625. break;
  626. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  627. ieee80211_tdls_add_chan_switch_resp_ies(sdata, skb, peer,
  628. status_code,
  629. initiator, extra_ies,
  630. extra_ies_len);
  631. break;
  632. }
  633. }
  634. static int
  635. ieee80211_prep_tdls_encap_data(struct wiphy *wiphy, struct net_device *dev,
  636. const u8 *peer, u8 action_code, u8 dialog_token,
  637. u16 status_code, struct sk_buff *skb)
  638. {
  639. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  640. struct ieee80211_tdls_data *tf;
  641. tf = (void *)skb_put(skb, offsetof(struct ieee80211_tdls_data, u));
  642. memcpy(tf->da, peer, ETH_ALEN);
  643. memcpy(tf->sa, sdata->vif.addr, ETH_ALEN);
  644. tf->ether_type = cpu_to_be16(ETH_P_TDLS);
  645. tf->payload_type = WLAN_TDLS_SNAP_RFTYPE;
  646. /* network header is after the ethernet header */
  647. skb_set_network_header(skb, ETH_HLEN);
  648. switch (action_code) {
  649. case WLAN_TDLS_SETUP_REQUEST:
  650. tf->category = WLAN_CATEGORY_TDLS;
  651. tf->action_code = WLAN_TDLS_SETUP_REQUEST;
  652. skb_put(skb, sizeof(tf->u.setup_req));
  653. tf->u.setup_req.dialog_token = dialog_token;
  654. tf->u.setup_req.capability =
  655. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  656. status_code));
  657. break;
  658. case WLAN_TDLS_SETUP_RESPONSE:
  659. tf->category = WLAN_CATEGORY_TDLS;
  660. tf->action_code = WLAN_TDLS_SETUP_RESPONSE;
  661. skb_put(skb, sizeof(tf->u.setup_resp));
  662. tf->u.setup_resp.status_code = cpu_to_le16(status_code);
  663. tf->u.setup_resp.dialog_token = dialog_token;
  664. tf->u.setup_resp.capability =
  665. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  666. status_code));
  667. break;
  668. case WLAN_TDLS_SETUP_CONFIRM:
  669. tf->category = WLAN_CATEGORY_TDLS;
  670. tf->action_code = WLAN_TDLS_SETUP_CONFIRM;
  671. skb_put(skb, sizeof(tf->u.setup_cfm));
  672. tf->u.setup_cfm.status_code = cpu_to_le16(status_code);
  673. tf->u.setup_cfm.dialog_token = dialog_token;
  674. break;
  675. case WLAN_TDLS_TEARDOWN:
  676. tf->category = WLAN_CATEGORY_TDLS;
  677. tf->action_code = WLAN_TDLS_TEARDOWN;
  678. skb_put(skb, sizeof(tf->u.teardown));
  679. tf->u.teardown.reason_code = cpu_to_le16(status_code);
  680. break;
  681. case WLAN_TDLS_DISCOVERY_REQUEST:
  682. tf->category = WLAN_CATEGORY_TDLS;
  683. tf->action_code = WLAN_TDLS_DISCOVERY_REQUEST;
  684. skb_put(skb, sizeof(tf->u.discover_req));
  685. tf->u.discover_req.dialog_token = dialog_token;
  686. break;
  687. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  688. tf->category = WLAN_CATEGORY_TDLS;
  689. tf->action_code = WLAN_TDLS_CHANNEL_SWITCH_REQUEST;
  690. skb_put(skb, sizeof(tf->u.chan_switch_req));
  691. break;
  692. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  693. tf->category = WLAN_CATEGORY_TDLS;
  694. tf->action_code = WLAN_TDLS_CHANNEL_SWITCH_RESPONSE;
  695. skb_put(skb, sizeof(tf->u.chan_switch_resp));
  696. tf->u.chan_switch_resp.status_code = cpu_to_le16(status_code);
  697. break;
  698. default:
  699. return -EINVAL;
  700. }
  701. return 0;
  702. }
  703. static int
  704. ieee80211_prep_tdls_direct(struct wiphy *wiphy, struct net_device *dev,
  705. const u8 *peer, u8 action_code, u8 dialog_token,
  706. u16 status_code, struct sk_buff *skb)
  707. {
  708. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  709. struct ieee80211_mgmt *mgmt;
  710. mgmt = (void *)skb_put(skb, 24);
  711. memset(mgmt, 0, 24);
  712. memcpy(mgmt->da, peer, ETH_ALEN);
  713. memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
  714. memcpy(mgmt->bssid, sdata->u.mgd.bssid, ETH_ALEN);
  715. mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
  716. IEEE80211_STYPE_ACTION);
  717. switch (action_code) {
  718. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  719. skb_put(skb, 1 + sizeof(mgmt->u.action.u.tdls_discover_resp));
  720. mgmt->u.action.category = WLAN_CATEGORY_PUBLIC;
  721. mgmt->u.action.u.tdls_discover_resp.action_code =
  722. WLAN_PUB_ACTION_TDLS_DISCOVER_RES;
  723. mgmt->u.action.u.tdls_discover_resp.dialog_token =
  724. dialog_token;
  725. mgmt->u.action.u.tdls_discover_resp.capability =
  726. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  727. status_code));
  728. break;
  729. default:
  730. return -EINVAL;
  731. }
  732. return 0;
  733. }
  734. static struct sk_buff *
  735. ieee80211_tdls_build_mgmt_packet_data(struct ieee80211_sub_if_data *sdata,
  736. const u8 *peer, u8 action_code,
  737. u8 dialog_token, u16 status_code,
  738. bool initiator, const u8 *extra_ies,
  739. size_t extra_ies_len, u8 oper_class,
  740. struct cfg80211_chan_def *chandef)
  741. {
  742. struct ieee80211_local *local = sdata->local;
  743. struct sk_buff *skb;
  744. int ret;
  745. skb = netdev_alloc_skb(sdata->dev,
  746. local->hw.extra_tx_headroom +
  747. max(sizeof(struct ieee80211_mgmt),
  748. sizeof(struct ieee80211_tdls_data)) +
  749. 50 + /* supported rates */
  750. 10 + /* ext capab */
  751. 26 + /* max(WMM-info, WMM-param) */
  752. 2 + max(sizeof(struct ieee80211_ht_cap),
  753. sizeof(struct ieee80211_ht_operation)) +
  754. 2 + max(sizeof(struct ieee80211_vht_cap),
  755. sizeof(struct ieee80211_vht_operation)) +
  756. 50 + /* supported channels */
  757. 3 + /* 40/20 BSS coex */
  758. 4 + /* AID */
  759. 4 + /* oper classes */
  760. extra_ies_len +
  761. sizeof(struct ieee80211_tdls_lnkie));
  762. if (!skb)
  763. return NULL;
  764. skb_reserve(skb, local->hw.extra_tx_headroom);
  765. switch (action_code) {
  766. case WLAN_TDLS_SETUP_REQUEST:
  767. case WLAN_TDLS_SETUP_RESPONSE:
  768. case WLAN_TDLS_SETUP_CONFIRM:
  769. case WLAN_TDLS_TEARDOWN:
  770. case WLAN_TDLS_DISCOVERY_REQUEST:
  771. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  772. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  773. ret = ieee80211_prep_tdls_encap_data(local->hw.wiphy,
  774. sdata->dev, peer,
  775. action_code, dialog_token,
  776. status_code, skb);
  777. break;
  778. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  779. ret = ieee80211_prep_tdls_direct(local->hw.wiphy, sdata->dev,
  780. peer, action_code,
  781. dialog_token, status_code,
  782. skb);
  783. break;
  784. default:
  785. ret = -ENOTSUPP;
  786. break;
  787. }
  788. if (ret < 0)
  789. goto fail;
  790. ieee80211_tdls_add_ies(sdata, skb, peer, action_code, status_code,
  791. initiator, extra_ies, extra_ies_len, oper_class,
  792. chandef);
  793. return skb;
  794. fail:
  795. dev_kfree_skb(skb);
  796. return NULL;
  797. }
  798. static int
  799. ieee80211_tdls_prep_mgmt_packet(struct wiphy *wiphy, struct net_device *dev,
  800. const u8 *peer, u8 action_code, u8 dialog_token,
  801. u16 status_code, u32 peer_capability,
  802. bool initiator, const u8 *extra_ies,
  803. size_t extra_ies_len, u8 oper_class,
  804. struct cfg80211_chan_def *chandef)
  805. {
  806. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  807. struct sk_buff *skb = NULL;
  808. struct sta_info *sta;
  809. u32 flags = 0;
  810. int ret = 0;
  811. rcu_read_lock();
  812. sta = sta_info_get(sdata, peer);
  813. /* infer the initiator if we can, to support old userspace */
  814. switch (action_code) {
  815. case WLAN_TDLS_SETUP_REQUEST:
  816. if (sta) {
  817. set_sta_flag(sta, WLAN_STA_TDLS_INITIATOR);
  818. sta->sta.tdls_initiator = false;
  819. }
  820. /* fall-through */
  821. case WLAN_TDLS_SETUP_CONFIRM:
  822. case WLAN_TDLS_DISCOVERY_REQUEST:
  823. initiator = true;
  824. break;
  825. case WLAN_TDLS_SETUP_RESPONSE:
  826. /*
  827. * In some testing scenarios, we send a request and response.
  828. * Make the last packet sent take effect for the initiator
  829. * value.
  830. */
  831. if (sta) {
  832. clear_sta_flag(sta, WLAN_STA_TDLS_INITIATOR);
  833. sta->sta.tdls_initiator = true;
  834. }
  835. /* fall-through */
  836. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  837. initiator = false;
  838. break;
  839. case WLAN_TDLS_TEARDOWN:
  840. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  841. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  842. /* any value is ok */
  843. break;
  844. default:
  845. ret = -ENOTSUPP;
  846. break;
  847. }
  848. if (sta && test_sta_flag(sta, WLAN_STA_TDLS_INITIATOR))
  849. initiator = true;
  850. rcu_read_unlock();
  851. if (ret < 0)
  852. goto fail;
  853. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, peer, action_code,
  854. dialog_token, status_code,
  855. initiator, extra_ies,
  856. extra_ies_len, oper_class,
  857. chandef);
  858. if (!skb) {
  859. ret = -EINVAL;
  860. goto fail;
  861. }
  862. if (action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) {
  863. ieee80211_tx_skb(sdata, skb);
  864. return 0;
  865. }
  866. /*
  867. * According to 802.11z: Setup req/resp are sent in AC_BK, otherwise
  868. * we should default to AC_VI.
  869. */
  870. switch (action_code) {
  871. case WLAN_TDLS_SETUP_REQUEST:
  872. case WLAN_TDLS_SETUP_RESPONSE:
  873. skb_set_queue_mapping(skb, IEEE80211_AC_BK);
  874. skb->priority = 2;
  875. break;
  876. default:
  877. skb_set_queue_mapping(skb, IEEE80211_AC_VI);
  878. skb->priority = 5;
  879. break;
  880. }
  881. /*
  882. * Set the WLAN_TDLS_TEARDOWN flag to indicate a teardown in progress.
  883. * Later, if no ACK is returned from peer, we will re-send the teardown
  884. * packet through the AP.
  885. */
  886. if ((action_code == WLAN_TDLS_TEARDOWN) &&
  887. ieee80211_hw_check(&sdata->local->hw, REPORTS_TX_ACK_STATUS)) {
  888. bool try_resend; /* Should we keep skb for possible resend */
  889. /* If not sending directly to peer - no point in keeping skb */
  890. rcu_read_lock();
  891. sta = sta_info_get(sdata, peer);
  892. try_resend = sta && test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  893. rcu_read_unlock();
  894. spin_lock_bh(&sdata->u.mgd.teardown_lock);
  895. if (try_resend && !sdata->u.mgd.teardown_skb) {
  896. /* Mark it as requiring TX status callback */
  897. flags |= IEEE80211_TX_CTL_REQ_TX_STATUS |
  898. IEEE80211_TX_INTFL_MLME_CONN_TX;
  899. /*
  900. * skb is copied since mac80211 will later set
  901. * properties that might not be the same as the AP,
  902. * such as encryption, QoS, addresses, etc.
  903. *
  904. * No problem if skb_copy() fails, so no need to check.
  905. */
  906. sdata->u.mgd.teardown_skb = skb_copy(skb, GFP_ATOMIC);
  907. sdata->u.mgd.orig_teardown_skb = skb;
  908. }
  909. spin_unlock_bh(&sdata->u.mgd.teardown_lock);
  910. }
  911. /* disable bottom halves when entering the Tx path */
  912. local_bh_disable();
  913. __ieee80211_subif_start_xmit(skb, dev, flags);
  914. local_bh_enable();
  915. return ret;
  916. fail:
  917. dev_kfree_skb(skb);
  918. return ret;
  919. }
  920. static int
  921. ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
  922. const u8 *peer, u8 action_code, u8 dialog_token,
  923. u16 status_code, u32 peer_capability, bool initiator,
  924. const u8 *extra_ies, size_t extra_ies_len)
  925. {
  926. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  927. struct ieee80211_local *local = sdata->local;
  928. enum ieee80211_smps_mode smps_mode = sdata->u.mgd.driver_smps_mode;
  929. int ret;
  930. /* don't support setup with forced SMPS mode that's not off */
  931. if (smps_mode != IEEE80211_SMPS_AUTOMATIC &&
  932. smps_mode != IEEE80211_SMPS_OFF) {
  933. tdls_dbg(sdata, "Aborting TDLS setup due to SMPS mode %d\n",
  934. smps_mode);
  935. return -ENOTSUPP;
  936. }
  937. mutex_lock(&local->mtx);
  938. /* we don't support concurrent TDLS peer setups */
  939. if (!is_zero_ether_addr(sdata->u.mgd.tdls_peer) &&
  940. !ether_addr_equal(sdata->u.mgd.tdls_peer, peer)) {
  941. ret = -EBUSY;
  942. goto out_unlock;
  943. }
  944. /*
  945. * make sure we have a STA representing the peer so we drop or buffer
  946. * non-TDLS-setup frames to the peer. We can't send other packets
  947. * during setup through the AP path.
  948. * Allow error packets to be sent - sometimes we don't even add a STA
  949. * before failing the setup.
  950. */
  951. if (status_code == 0) {
  952. rcu_read_lock();
  953. if (!sta_info_get(sdata, peer)) {
  954. rcu_read_unlock();
  955. ret = -ENOLINK;
  956. goto out_unlock;
  957. }
  958. rcu_read_unlock();
  959. }
  960. ieee80211_flush_queues(local, sdata, false);
  961. memcpy(sdata->u.mgd.tdls_peer, peer, ETH_ALEN);
  962. mutex_unlock(&local->mtx);
  963. /* we cannot take the mutex while preparing the setup packet */
  964. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
  965. dialog_token, status_code,
  966. peer_capability, initiator,
  967. extra_ies, extra_ies_len, 0,
  968. NULL);
  969. if (ret < 0) {
  970. mutex_lock(&local->mtx);
  971. eth_zero_addr(sdata->u.mgd.tdls_peer);
  972. mutex_unlock(&local->mtx);
  973. return ret;
  974. }
  975. ieee80211_queue_delayed_work(&sdata->local->hw,
  976. &sdata->u.mgd.tdls_peer_del_work,
  977. TDLS_PEER_SETUP_TIMEOUT);
  978. return 0;
  979. out_unlock:
  980. mutex_unlock(&local->mtx);
  981. return ret;
  982. }
  983. static int
  984. ieee80211_tdls_mgmt_teardown(struct wiphy *wiphy, struct net_device *dev,
  985. const u8 *peer, u8 action_code, u8 dialog_token,
  986. u16 status_code, u32 peer_capability,
  987. bool initiator, const u8 *extra_ies,
  988. size_t extra_ies_len)
  989. {
  990. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  991. struct ieee80211_local *local = sdata->local;
  992. struct sta_info *sta;
  993. int ret;
  994. /*
  995. * No packets can be transmitted to the peer via the AP during setup -
  996. * the STA is set as a TDLS peer, but is not authorized.
  997. * During teardown, we prevent direct transmissions by stopping the
  998. * queues and flushing all direct packets.
  999. */
  1000. ieee80211_stop_vif_queues(local, sdata,
  1001. IEEE80211_QUEUE_STOP_REASON_TDLS_TEARDOWN);
  1002. ieee80211_flush_queues(local, sdata, false);
  1003. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
  1004. dialog_token, status_code,
  1005. peer_capability, initiator,
  1006. extra_ies, extra_ies_len, 0,
  1007. NULL);
  1008. if (ret < 0)
  1009. sdata_err(sdata, "Failed sending TDLS teardown packet %d\n",
  1010. ret);
  1011. /*
  1012. * Remove the STA AUTH flag to force further traffic through the AP. If
  1013. * the STA was unreachable, it was already removed.
  1014. */
  1015. rcu_read_lock();
  1016. sta = sta_info_get(sdata, peer);
  1017. if (sta)
  1018. clear_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  1019. rcu_read_unlock();
  1020. ieee80211_wake_vif_queues(local, sdata,
  1021. IEEE80211_QUEUE_STOP_REASON_TDLS_TEARDOWN);
  1022. return 0;
  1023. }
  1024. int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
  1025. const u8 *peer, u8 action_code, u8 dialog_token,
  1026. u16 status_code, u32 peer_capability,
  1027. bool initiator, const u8 *extra_ies,
  1028. size_t extra_ies_len)
  1029. {
  1030. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1031. int ret;
  1032. if (!(wiphy->flags & WIPHY_FLAG_SUPPORTS_TDLS))
  1033. return -ENOTSUPP;
  1034. /* make sure we are in managed mode, and associated */
  1035. if (sdata->vif.type != NL80211_IFTYPE_STATION ||
  1036. !sdata->u.mgd.associated)
  1037. return -EINVAL;
  1038. switch (action_code) {
  1039. case WLAN_TDLS_SETUP_REQUEST:
  1040. case WLAN_TDLS_SETUP_RESPONSE:
  1041. ret = ieee80211_tdls_mgmt_setup(wiphy, dev, peer, action_code,
  1042. dialog_token, status_code,
  1043. peer_capability, initiator,
  1044. extra_ies, extra_ies_len);
  1045. break;
  1046. case WLAN_TDLS_TEARDOWN:
  1047. ret = ieee80211_tdls_mgmt_teardown(wiphy, dev, peer,
  1048. action_code, dialog_token,
  1049. status_code,
  1050. peer_capability, initiator,
  1051. extra_ies, extra_ies_len);
  1052. break;
  1053. case WLAN_TDLS_DISCOVERY_REQUEST:
  1054. /*
  1055. * Protect the discovery so we can hear the TDLS discovery
  1056. * response frame. It is transmitted directly and not buffered
  1057. * by the AP.
  1058. */
  1059. drv_mgd_protect_tdls_discover(sdata->local, sdata);
  1060. /* fall-through */
  1061. case WLAN_TDLS_SETUP_CONFIRM:
  1062. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  1063. /* no special handling */
  1064. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
  1065. action_code,
  1066. dialog_token,
  1067. status_code,
  1068. peer_capability,
  1069. initiator, extra_ies,
  1070. extra_ies_len, 0, NULL);
  1071. break;
  1072. default:
  1073. ret = -EOPNOTSUPP;
  1074. break;
  1075. }
  1076. tdls_dbg(sdata, "TDLS mgmt action %d peer %pM status %d\n",
  1077. action_code, peer, ret);
  1078. return ret;
  1079. }
  1080. static void iee80211_tdls_recalc_chanctx(struct ieee80211_sub_if_data *sdata,
  1081. struct sta_info *sta)
  1082. {
  1083. struct ieee80211_local *local = sdata->local;
  1084. struct ieee80211_chanctx_conf *conf;
  1085. struct ieee80211_chanctx *ctx;
  1086. enum nl80211_chan_width width;
  1087. struct ieee80211_supported_band *sband;
  1088. mutex_lock(&local->chanctx_mtx);
  1089. conf = rcu_dereference_protected(sdata->vif.chanctx_conf,
  1090. lockdep_is_held(&local->chanctx_mtx));
  1091. if (conf) {
  1092. width = conf->def.width;
  1093. sband = local->hw.wiphy->bands[conf->def.chan->band];
  1094. ctx = container_of(conf, struct ieee80211_chanctx, conf);
  1095. ieee80211_recalc_chanctx_chantype(local, ctx);
  1096. /* if width changed and a peer is given, update its BW */
  1097. if (width != conf->def.width && sta &&
  1098. test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW)) {
  1099. enum ieee80211_sta_rx_bandwidth bw;
  1100. bw = ieee80211_chan_width_to_rx_bw(conf->def.width);
  1101. bw = min(bw, ieee80211_sta_cap_rx_bw(sta));
  1102. if (bw != sta->sta.bandwidth) {
  1103. sta->sta.bandwidth = bw;
  1104. rate_control_rate_update(local, sband, sta,
  1105. IEEE80211_RC_BW_CHANGED);
  1106. /*
  1107. * if a TDLS peer BW was updated, we need to
  1108. * recalc the chandef width again, to get the
  1109. * correct chanctx min_def
  1110. */
  1111. ieee80211_recalc_chanctx_chantype(local, ctx);
  1112. }
  1113. }
  1114. }
  1115. mutex_unlock(&local->chanctx_mtx);
  1116. }
  1117. static int iee80211_tdls_have_ht_peers(struct ieee80211_sub_if_data *sdata)
  1118. {
  1119. struct sta_info *sta;
  1120. bool result = false;
  1121. rcu_read_lock();
  1122. list_for_each_entry_rcu(sta, &sdata->local->sta_list, list) {
  1123. if (!sta->sta.tdls || sta->sdata != sdata || !sta->uploaded ||
  1124. !test_sta_flag(sta, WLAN_STA_AUTHORIZED) ||
  1125. !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH) ||
  1126. !sta->sta.ht_cap.ht_supported)
  1127. continue;
  1128. result = true;
  1129. break;
  1130. }
  1131. rcu_read_unlock();
  1132. return result;
  1133. }
  1134. static void
  1135. iee80211_tdls_recalc_ht_protection(struct ieee80211_sub_if_data *sdata,
  1136. struct sta_info *sta)
  1137. {
  1138. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  1139. bool tdls_ht;
  1140. u16 protection = IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED |
  1141. IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
  1142. IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
  1143. u16 opmode;
  1144. /* Nothing to do if the BSS connection uses HT */
  1145. if (!(ifmgd->flags & IEEE80211_STA_DISABLE_HT))
  1146. return;
  1147. tdls_ht = (sta && sta->sta.ht_cap.ht_supported) ||
  1148. iee80211_tdls_have_ht_peers(sdata);
  1149. opmode = sdata->vif.bss_conf.ht_operation_mode;
  1150. if (tdls_ht)
  1151. opmode |= protection;
  1152. else
  1153. opmode &= ~protection;
  1154. if (opmode == sdata->vif.bss_conf.ht_operation_mode)
  1155. return;
  1156. sdata->vif.bss_conf.ht_operation_mode = opmode;
  1157. ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_HT);
  1158. }
  1159. int ieee80211_tdls_oper(struct wiphy *wiphy, struct net_device *dev,
  1160. const u8 *peer, enum nl80211_tdls_operation oper)
  1161. {
  1162. struct sta_info *sta;
  1163. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1164. struct ieee80211_local *local = sdata->local;
  1165. int ret;
  1166. if (!(wiphy->flags & WIPHY_FLAG_SUPPORTS_TDLS))
  1167. return -ENOTSUPP;
  1168. if (sdata->vif.type != NL80211_IFTYPE_STATION)
  1169. return -EINVAL;
  1170. switch (oper) {
  1171. case NL80211_TDLS_ENABLE_LINK:
  1172. case NL80211_TDLS_DISABLE_LINK:
  1173. break;
  1174. case NL80211_TDLS_TEARDOWN:
  1175. case NL80211_TDLS_SETUP:
  1176. case NL80211_TDLS_DISCOVERY_REQ:
  1177. /* We don't support in-driver setup/teardown/discovery */
  1178. return -ENOTSUPP;
  1179. }
  1180. /* protect possible bss_conf changes and avoid concurrency in
  1181. * ieee80211_bss_info_change_notify()
  1182. */
  1183. sdata_lock(sdata);
  1184. mutex_lock(&local->mtx);
  1185. tdls_dbg(sdata, "TDLS oper %d peer %pM\n", oper, peer);
  1186. switch (oper) {
  1187. case NL80211_TDLS_ENABLE_LINK:
  1188. if (sdata->vif.csa_active) {
  1189. tdls_dbg(sdata, "TDLS: disallow link during CSA\n");
  1190. ret = -EBUSY;
  1191. break;
  1192. }
  1193. mutex_lock(&local->sta_mtx);
  1194. sta = sta_info_get(sdata, peer);
  1195. if (!sta) {
  1196. mutex_unlock(&local->sta_mtx);
  1197. ret = -ENOLINK;
  1198. break;
  1199. }
  1200. iee80211_tdls_recalc_chanctx(sdata, sta);
  1201. iee80211_tdls_recalc_ht_protection(sdata, sta);
  1202. set_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  1203. mutex_unlock(&local->sta_mtx);
  1204. WARN_ON_ONCE(is_zero_ether_addr(sdata->u.mgd.tdls_peer) ||
  1205. !ether_addr_equal(sdata->u.mgd.tdls_peer, peer));
  1206. ret = 0;
  1207. break;
  1208. case NL80211_TDLS_DISABLE_LINK:
  1209. /*
  1210. * The teardown message in ieee80211_tdls_mgmt_teardown() was
  1211. * created while the queues were stopped, so it might still be
  1212. * pending. Before flushing the queues we need to be sure the
  1213. * message is handled by the tasklet handling pending messages,
  1214. * otherwise we might start destroying the station before
  1215. * sending the teardown packet.
  1216. * Note that this only forces the tasklet to flush pendings -
  1217. * not to stop the tasklet from rescheduling itself.
  1218. */
  1219. tasklet_kill(&local->tx_pending_tasklet);
  1220. /* flush a potentially queued teardown packet */
  1221. ieee80211_flush_queues(local, sdata, false);
  1222. ret = sta_info_destroy_addr(sdata, peer);
  1223. mutex_lock(&local->sta_mtx);
  1224. iee80211_tdls_recalc_ht_protection(sdata, NULL);
  1225. mutex_unlock(&local->sta_mtx);
  1226. iee80211_tdls_recalc_chanctx(sdata, NULL);
  1227. break;
  1228. default:
  1229. ret = -ENOTSUPP;
  1230. break;
  1231. }
  1232. if (ret == 0 && ether_addr_equal(sdata->u.mgd.tdls_peer, peer)) {
  1233. cancel_delayed_work(&sdata->u.mgd.tdls_peer_del_work);
  1234. eth_zero_addr(sdata->u.mgd.tdls_peer);
  1235. }
  1236. if (ret == 0)
  1237. ieee80211_queue_work(&sdata->local->hw,
  1238. &sdata->u.mgd.request_smps_work);
  1239. mutex_unlock(&local->mtx);
  1240. sdata_unlock(sdata);
  1241. return ret;
  1242. }
  1243. void ieee80211_tdls_oper_request(struct ieee80211_vif *vif, const u8 *peer,
  1244. enum nl80211_tdls_operation oper,
  1245. u16 reason_code, gfp_t gfp)
  1246. {
  1247. struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
  1248. if (vif->type != NL80211_IFTYPE_STATION || !vif->bss_conf.assoc) {
  1249. sdata_err(sdata, "Discarding TDLS oper %d - not STA or disconnected\n",
  1250. oper);
  1251. return;
  1252. }
  1253. cfg80211_tdls_oper_request(sdata->dev, peer, oper, reason_code, gfp);
  1254. }
  1255. EXPORT_SYMBOL(ieee80211_tdls_oper_request);
  1256. static void
  1257. iee80211_tdls_add_ch_switch_timing(u8 *buf, u16 switch_time, u16 switch_timeout)
  1258. {
  1259. struct ieee80211_ch_switch_timing *ch_sw;
  1260. *buf++ = WLAN_EID_CHAN_SWITCH_TIMING;
  1261. *buf++ = sizeof(struct ieee80211_ch_switch_timing);
  1262. ch_sw = (void *)buf;
  1263. ch_sw->switch_time = cpu_to_le16(switch_time);
  1264. ch_sw->switch_timeout = cpu_to_le16(switch_timeout);
  1265. }
  1266. /* find switch timing IE in SKB ready for Tx */
  1267. static const u8 *ieee80211_tdls_find_sw_timing_ie(struct sk_buff *skb)
  1268. {
  1269. struct ieee80211_tdls_data *tf;
  1270. const u8 *ie_start;
  1271. /*
  1272. * Get the offset for the new location of the switch timing IE.
  1273. * The SKB network header will now point to the "payload_type"
  1274. * element of the TDLS data frame struct.
  1275. */
  1276. tf = container_of(skb->data + skb_network_offset(skb),
  1277. struct ieee80211_tdls_data, payload_type);
  1278. ie_start = tf->u.chan_switch_req.variable;
  1279. return cfg80211_find_ie(WLAN_EID_CHAN_SWITCH_TIMING, ie_start,
  1280. skb->len - (ie_start - skb->data));
  1281. }
  1282. static struct sk_buff *
  1283. ieee80211_tdls_ch_sw_tmpl_get(struct sta_info *sta, u8 oper_class,
  1284. struct cfg80211_chan_def *chandef,
  1285. u32 *ch_sw_tm_ie_offset)
  1286. {
  1287. struct ieee80211_sub_if_data *sdata = sta->sdata;
  1288. u8 extra_ies[2 + sizeof(struct ieee80211_sec_chan_offs_ie) +
  1289. 2 + sizeof(struct ieee80211_ch_switch_timing)];
  1290. int extra_ies_len = 2 + sizeof(struct ieee80211_ch_switch_timing);
  1291. u8 *pos = extra_ies;
  1292. struct sk_buff *skb;
  1293. /*
  1294. * if chandef points to a wide channel add a Secondary-Channel
  1295. * Offset information element
  1296. */
  1297. if (chandef->width == NL80211_CHAN_WIDTH_40) {
  1298. struct ieee80211_sec_chan_offs_ie *sec_chan_ie;
  1299. bool ht40plus;
  1300. *pos++ = WLAN_EID_SECONDARY_CHANNEL_OFFSET;
  1301. *pos++ = sizeof(*sec_chan_ie);
  1302. sec_chan_ie = (void *)pos;
  1303. ht40plus = cfg80211_get_chandef_type(chandef) ==
  1304. NL80211_CHAN_HT40PLUS;
  1305. sec_chan_ie->sec_chan_offs = ht40plus ?
  1306. IEEE80211_HT_PARAM_CHA_SEC_ABOVE :
  1307. IEEE80211_HT_PARAM_CHA_SEC_BELOW;
  1308. pos += sizeof(*sec_chan_ie);
  1309. extra_ies_len += 2 + sizeof(struct ieee80211_sec_chan_offs_ie);
  1310. }
  1311. /* just set the values to 0, this is a template */
  1312. iee80211_tdls_add_ch_switch_timing(pos, 0, 0);
  1313. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
  1314. WLAN_TDLS_CHANNEL_SWITCH_REQUEST,
  1315. 0, 0, !sta->sta.tdls_initiator,
  1316. extra_ies, extra_ies_len,
  1317. oper_class, chandef);
  1318. if (!skb)
  1319. return NULL;
  1320. skb = ieee80211_build_data_template(sdata, skb, 0);
  1321. if (IS_ERR(skb)) {
  1322. tdls_dbg(sdata, "Failed building TDLS channel switch frame\n");
  1323. return NULL;
  1324. }
  1325. if (ch_sw_tm_ie_offset) {
  1326. const u8 *tm_ie = ieee80211_tdls_find_sw_timing_ie(skb);
  1327. if (!tm_ie) {
  1328. tdls_dbg(sdata, "No switch timing IE in TDLS switch\n");
  1329. dev_kfree_skb_any(skb);
  1330. return NULL;
  1331. }
  1332. *ch_sw_tm_ie_offset = tm_ie - skb->data;
  1333. }
  1334. tdls_dbg(sdata,
  1335. "TDLS channel switch request template for %pM ch %d width %d\n",
  1336. sta->sta.addr, chandef->chan->center_freq, chandef->width);
  1337. return skb;
  1338. }
  1339. int
  1340. ieee80211_tdls_channel_switch(struct wiphy *wiphy, struct net_device *dev,
  1341. const u8 *addr, u8 oper_class,
  1342. struct cfg80211_chan_def *chandef)
  1343. {
  1344. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1345. struct ieee80211_local *local = sdata->local;
  1346. struct sta_info *sta;
  1347. struct sk_buff *skb = NULL;
  1348. u32 ch_sw_tm_ie;
  1349. int ret;
  1350. mutex_lock(&local->sta_mtx);
  1351. sta = sta_info_get(sdata, addr);
  1352. if (!sta) {
  1353. tdls_dbg(sdata,
  1354. "Invalid TDLS peer %pM for channel switch request\n",
  1355. addr);
  1356. ret = -ENOENT;
  1357. goto out;
  1358. }
  1359. if (!test_sta_flag(sta, WLAN_STA_TDLS_CHAN_SWITCH)) {
  1360. tdls_dbg(sdata, "TDLS channel switch unsupported by %pM\n",
  1361. addr);
  1362. ret = -ENOTSUPP;
  1363. goto out;
  1364. }
  1365. skb = ieee80211_tdls_ch_sw_tmpl_get(sta, oper_class, chandef,
  1366. &ch_sw_tm_ie);
  1367. if (!skb) {
  1368. ret = -ENOENT;
  1369. goto out;
  1370. }
  1371. ret = drv_tdls_channel_switch(local, sdata, &sta->sta, oper_class,
  1372. chandef, skb, ch_sw_tm_ie);
  1373. if (!ret)
  1374. set_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL);
  1375. out:
  1376. mutex_unlock(&local->sta_mtx);
  1377. dev_kfree_skb_any(skb);
  1378. return ret;
  1379. }
  1380. void
  1381. ieee80211_tdls_cancel_channel_switch(struct wiphy *wiphy,
  1382. struct net_device *dev,
  1383. const u8 *addr)
  1384. {
  1385. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1386. struct ieee80211_local *local = sdata->local;
  1387. struct sta_info *sta;
  1388. mutex_lock(&local->sta_mtx);
  1389. sta = sta_info_get(sdata, addr);
  1390. if (!sta) {
  1391. tdls_dbg(sdata,
  1392. "Invalid TDLS peer %pM for channel switch cancel\n",
  1393. addr);
  1394. goto out;
  1395. }
  1396. if (!test_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL)) {
  1397. tdls_dbg(sdata, "TDLS channel switch not initiated by %pM\n",
  1398. addr);
  1399. goto out;
  1400. }
  1401. drv_tdls_cancel_channel_switch(local, sdata, &sta->sta);
  1402. clear_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL);
  1403. out:
  1404. mutex_unlock(&local->sta_mtx);
  1405. }
  1406. static struct sk_buff *
  1407. ieee80211_tdls_ch_sw_resp_tmpl_get(struct sta_info *sta,
  1408. u32 *ch_sw_tm_ie_offset)
  1409. {
  1410. struct ieee80211_sub_if_data *sdata = sta->sdata;
  1411. struct sk_buff *skb;
  1412. u8 extra_ies[2 + sizeof(struct ieee80211_ch_switch_timing)];
  1413. /* initial timing are always zero in the template */
  1414. iee80211_tdls_add_ch_switch_timing(extra_ies, 0, 0);
  1415. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
  1416. WLAN_TDLS_CHANNEL_SWITCH_RESPONSE,
  1417. 0, 0, !sta->sta.tdls_initiator,
  1418. extra_ies, sizeof(extra_ies), 0, NULL);
  1419. if (!skb)
  1420. return NULL;
  1421. skb = ieee80211_build_data_template(sdata, skb, 0);
  1422. if (IS_ERR(skb)) {
  1423. tdls_dbg(sdata,
  1424. "Failed building TDLS channel switch resp frame\n");
  1425. return NULL;
  1426. }
  1427. if (ch_sw_tm_ie_offset) {
  1428. const u8 *tm_ie = ieee80211_tdls_find_sw_timing_ie(skb);
  1429. if (!tm_ie) {
  1430. tdls_dbg(sdata,
  1431. "No switch timing IE in TDLS switch resp\n");
  1432. dev_kfree_skb_any(skb);
  1433. return NULL;
  1434. }
  1435. *ch_sw_tm_ie_offset = tm_ie - skb->data;
  1436. }
  1437. tdls_dbg(sdata, "TDLS get channel switch response template for %pM\n",
  1438. sta->sta.addr);
  1439. return skb;
  1440. }
  1441. static int
  1442. ieee80211_process_tdls_channel_switch_resp(struct ieee80211_sub_if_data *sdata,
  1443. struct sk_buff *skb)
  1444. {
  1445. struct ieee80211_local *local = sdata->local;
  1446. struct ieee802_11_elems elems;
  1447. struct sta_info *sta;
  1448. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1449. bool local_initiator;
  1450. struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
  1451. int baselen = offsetof(typeof(*tf), u.chan_switch_resp.variable);
  1452. struct ieee80211_tdls_ch_sw_params params = {};
  1453. int ret;
  1454. params.action_code = WLAN_TDLS_CHANNEL_SWITCH_RESPONSE;
  1455. params.timestamp = rx_status->device_timestamp;
  1456. if (skb->len < baselen) {
  1457. tdls_dbg(sdata, "TDLS channel switch resp too short: %d\n",
  1458. skb->len);
  1459. return -EINVAL;
  1460. }
  1461. mutex_lock(&local->sta_mtx);
  1462. sta = sta_info_get(sdata, tf->sa);
  1463. if (!sta || !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH)) {
  1464. tdls_dbg(sdata, "TDLS chan switch from non-peer sta %pM\n",
  1465. tf->sa);
  1466. ret = -EINVAL;
  1467. goto out;
  1468. }
  1469. params.sta = &sta->sta;
  1470. params.status = le16_to_cpu(tf->u.chan_switch_resp.status_code);
  1471. if (params.status != 0) {
  1472. ret = 0;
  1473. goto call_drv;
  1474. }
  1475. ieee802_11_parse_elems(tf->u.chan_switch_resp.variable,
  1476. skb->len - baselen, false, &elems);
  1477. if (elems.parse_error) {
  1478. tdls_dbg(sdata, "Invalid IEs in TDLS channel switch resp\n");
  1479. ret = -EINVAL;
  1480. goto out;
  1481. }
  1482. if (!elems.ch_sw_timing || !elems.lnk_id) {
  1483. tdls_dbg(sdata, "TDLS channel switch resp - missing IEs\n");
  1484. ret = -EINVAL;
  1485. goto out;
  1486. }
  1487. /* validate the initiator is set correctly */
  1488. local_initiator =
  1489. !memcmp(elems.lnk_id->init_sta, sdata->vif.addr, ETH_ALEN);
  1490. if (local_initiator == sta->sta.tdls_initiator) {
  1491. tdls_dbg(sdata, "TDLS chan switch invalid lnk-id initiator\n");
  1492. ret = -EINVAL;
  1493. goto out;
  1494. }
  1495. params.switch_time = le16_to_cpu(elems.ch_sw_timing->switch_time);
  1496. params.switch_timeout = le16_to_cpu(elems.ch_sw_timing->switch_timeout);
  1497. params.tmpl_skb =
  1498. ieee80211_tdls_ch_sw_resp_tmpl_get(sta, &params.ch_sw_tm_ie);
  1499. if (!params.tmpl_skb) {
  1500. ret = -ENOENT;
  1501. goto out;
  1502. }
  1503. ret = 0;
  1504. call_drv:
  1505. drv_tdls_recv_channel_switch(sdata->local, sdata, &params);
  1506. tdls_dbg(sdata,
  1507. "TDLS channel switch response received from %pM status %d\n",
  1508. tf->sa, params.status);
  1509. out:
  1510. mutex_unlock(&local->sta_mtx);
  1511. dev_kfree_skb_any(params.tmpl_skb);
  1512. return ret;
  1513. }
  1514. static int
  1515. ieee80211_process_tdls_channel_switch_req(struct ieee80211_sub_if_data *sdata,
  1516. struct sk_buff *skb)
  1517. {
  1518. struct ieee80211_local *local = sdata->local;
  1519. struct ieee802_11_elems elems;
  1520. struct cfg80211_chan_def chandef;
  1521. struct ieee80211_channel *chan;
  1522. enum nl80211_channel_type chan_type;
  1523. int freq;
  1524. u8 target_channel, oper_class;
  1525. bool local_initiator;
  1526. struct sta_info *sta;
  1527. enum nl80211_band band;
  1528. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1529. struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
  1530. int baselen = offsetof(typeof(*tf), u.chan_switch_req.variable);
  1531. struct ieee80211_tdls_ch_sw_params params = {};
  1532. int ret = 0;
  1533. params.action_code = WLAN_TDLS_CHANNEL_SWITCH_REQUEST;
  1534. params.timestamp = rx_status->device_timestamp;
  1535. if (skb->len < baselen) {
  1536. tdls_dbg(sdata, "TDLS channel switch req too short: %d\n",
  1537. skb->len);
  1538. return -EINVAL;
  1539. }
  1540. target_channel = tf->u.chan_switch_req.target_channel;
  1541. oper_class = tf->u.chan_switch_req.oper_class;
  1542. /*
  1543. * We can't easily infer the channel band. The operating class is
  1544. * ambiguous - there are multiple tables (US/Europe/JP/Global). The
  1545. * solution here is to treat channels with number >14 as 5GHz ones,
  1546. * and specifically check for the (oper_class, channel) combinations
  1547. * where this doesn't hold. These are thankfully unique according to
  1548. * IEEE802.11-2012.
  1549. * We consider only the 2GHz and 5GHz bands and 20MHz+ channels as
  1550. * valid here.
  1551. */
  1552. if ((oper_class == 112 || oper_class == 2 || oper_class == 3 ||
  1553. oper_class == 4 || oper_class == 5 || oper_class == 6) &&
  1554. target_channel < 14)
  1555. band = NL80211_BAND_5GHZ;
  1556. else
  1557. band = target_channel < 14 ? NL80211_BAND_2GHZ :
  1558. NL80211_BAND_5GHZ;
  1559. freq = ieee80211_channel_to_frequency(target_channel, band);
  1560. if (freq == 0) {
  1561. tdls_dbg(sdata, "Invalid channel in TDLS chan switch: %d\n",
  1562. target_channel);
  1563. return -EINVAL;
  1564. }
  1565. chan = ieee80211_get_channel(sdata->local->hw.wiphy, freq);
  1566. if (!chan) {
  1567. tdls_dbg(sdata,
  1568. "Unsupported channel for TDLS chan switch: %d\n",
  1569. target_channel);
  1570. return -EINVAL;
  1571. }
  1572. ieee802_11_parse_elems(tf->u.chan_switch_req.variable,
  1573. skb->len - baselen, false, &elems);
  1574. if (elems.parse_error) {
  1575. tdls_dbg(sdata, "Invalid IEs in TDLS channel switch req\n");
  1576. return -EINVAL;
  1577. }
  1578. if (!elems.ch_sw_timing || !elems.lnk_id) {
  1579. tdls_dbg(sdata, "TDLS channel switch req - missing IEs\n");
  1580. return -EINVAL;
  1581. }
  1582. if (!elems.sec_chan_offs) {
  1583. chan_type = NL80211_CHAN_HT20;
  1584. } else {
  1585. switch (elems.sec_chan_offs->sec_chan_offs) {
  1586. case IEEE80211_HT_PARAM_CHA_SEC_ABOVE:
  1587. chan_type = NL80211_CHAN_HT40PLUS;
  1588. break;
  1589. case IEEE80211_HT_PARAM_CHA_SEC_BELOW:
  1590. chan_type = NL80211_CHAN_HT40MINUS;
  1591. break;
  1592. default:
  1593. chan_type = NL80211_CHAN_HT20;
  1594. break;
  1595. }
  1596. }
  1597. cfg80211_chandef_create(&chandef, chan, chan_type);
  1598. /* we will be active on the TDLS link */
  1599. if (!cfg80211_reg_can_beacon_relax(sdata->local->hw.wiphy, &chandef,
  1600. sdata->wdev.iftype)) {
  1601. tdls_dbg(sdata, "TDLS chan switch to forbidden channel\n");
  1602. return -EINVAL;
  1603. }
  1604. mutex_lock(&local->sta_mtx);
  1605. sta = sta_info_get(sdata, tf->sa);
  1606. if (!sta || !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH)) {
  1607. tdls_dbg(sdata, "TDLS chan switch from non-peer sta %pM\n",
  1608. tf->sa);
  1609. ret = -EINVAL;
  1610. goto out;
  1611. }
  1612. params.sta = &sta->sta;
  1613. /* validate the initiator is set correctly */
  1614. local_initiator =
  1615. !memcmp(elems.lnk_id->init_sta, sdata->vif.addr, ETH_ALEN);
  1616. if (local_initiator == sta->sta.tdls_initiator) {
  1617. tdls_dbg(sdata, "TDLS chan switch invalid lnk-id initiator\n");
  1618. ret = -EINVAL;
  1619. goto out;
  1620. }
  1621. /* peer should have known better */
  1622. if (!sta->sta.ht_cap.ht_supported && elems.sec_chan_offs &&
  1623. elems.sec_chan_offs->sec_chan_offs) {
  1624. tdls_dbg(sdata, "TDLS chan switch - wide chan unsupported\n");
  1625. ret = -ENOTSUPP;
  1626. goto out;
  1627. }
  1628. params.chandef = &chandef;
  1629. params.switch_time = le16_to_cpu(elems.ch_sw_timing->switch_time);
  1630. params.switch_timeout = le16_to_cpu(elems.ch_sw_timing->switch_timeout);
  1631. params.tmpl_skb =
  1632. ieee80211_tdls_ch_sw_resp_tmpl_get(sta,
  1633. &params.ch_sw_tm_ie);
  1634. if (!params.tmpl_skb) {
  1635. ret = -ENOENT;
  1636. goto out;
  1637. }
  1638. drv_tdls_recv_channel_switch(sdata->local, sdata, &params);
  1639. tdls_dbg(sdata,
  1640. "TDLS ch switch request received from %pM ch %d width %d\n",
  1641. tf->sa, params.chandef->chan->center_freq,
  1642. params.chandef->width);
  1643. out:
  1644. mutex_unlock(&local->sta_mtx);
  1645. dev_kfree_skb_any(params.tmpl_skb);
  1646. return ret;
  1647. }
  1648. static void
  1649. ieee80211_process_tdls_channel_switch(struct ieee80211_sub_if_data *sdata,
  1650. struct sk_buff *skb)
  1651. {
  1652. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1653. struct wiphy *wiphy = sdata->local->hw.wiphy;
  1654. ASSERT_RTNL();
  1655. /* make sure the driver supports it */
  1656. if (!(wiphy->features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
  1657. return;
  1658. /* we want to access the entire packet */
  1659. if (skb_linearize(skb))
  1660. return;
  1661. /*
  1662. * The packet/size was already validated by mac80211 Rx path, only look
  1663. * at the action type.
  1664. */
  1665. switch (tf->action_code) {
  1666. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  1667. ieee80211_process_tdls_channel_switch_req(sdata, skb);
  1668. break;
  1669. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  1670. ieee80211_process_tdls_channel_switch_resp(sdata, skb);
  1671. break;
  1672. default:
  1673. WARN_ON_ONCE(1);
  1674. return;
  1675. }
  1676. }
  1677. void ieee80211_teardown_tdls_peers(struct ieee80211_sub_if_data *sdata)
  1678. {
  1679. struct sta_info *sta;
  1680. u16 reason = WLAN_REASON_TDLS_TEARDOWN_UNSPECIFIED;
  1681. rcu_read_lock();
  1682. list_for_each_entry_rcu(sta, &sdata->local->sta_list, list) {
  1683. if (!sta->sta.tdls || sta->sdata != sdata || !sta->uploaded ||
  1684. !test_sta_flag(sta, WLAN_STA_AUTHORIZED))
  1685. continue;
  1686. ieee80211_tdls_oper_request(&sdata->vif, sta->sta.addr,
  1687. NL80211_TDLS_TEARDOWN, reason,
  1688. GFP_ATOMIC);
  1689. }
  1690. rcu_read_unlock();
  1691. }
  1692. void ieee80211_tdls_chsw_work(struct work_struct *wk)
  1693. {
  1694. struct ieee80211_local *local =
  1695. container_of(wk, struct ieee80211_local, tdls_chsw_work);
  1696. struct ieee80211_sub_if_data *sdata;
  1697. struct sk_buff *skb;
  1698. struct ieee80211_tdls_data *tf;
  1699. rtnl_lock();
  1700. while ((skb = skb_dequeue(&local->skb_queue_tdls_chsw))) {
  1701. tf = (struct ieee80211_tdls_data *)skb->data;
  1702. list_for_each_entry(sdata, &local->interfaces, list) {
  1703. if (!ieee80211_sdata_running(sdata) ||
  1704. sdata->vif.type != NL80211_IFTYPE_STATION ||
  1705. !ether_addr_equal(tf->da, sdata->vif.addr))
  1706. continue;
  1707. ieee80211_process_tdls_channel_switch(sdata, skb);
  1708. break;
  1709. }
  1710. kfree_skb(skb);
  1711. }
  1712. rtnl_unlock();
  1713. }