tdls.c 55 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014
  1. /*
  2. * mac80211 TDLS handling code
  3. *
  4. * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
  5. * Copyright 2014, Intel Corporation
  6. * Copyright 2014 Intel Mobile Communications GmbH
  7. * Copyright 2015 - 2016 Intel Deutschland GmbH
  8. *
  9. * This file is GPLv2 as found in COPYING.
  10. */
  11. #include <linux/ieee80211.h>
  12. #include <linux/log2.h>
  13. #include <net/cfg80211.h>
  14. #include <linux/rtnetlink.h>
  15. #include "ieee80211_i.h"
  16. #include "driver-ops.h"
  17. #include "rate.h"
  18. #include "wme.h"
  19. /* give usermode some time for retries in setting up the TDLS session */
  20. #define TDLS_PEER_SETUP_TIMEOUT (15 * HZ)
  21. void ieee80211_tdls_peer_del_work(struct work_struct *wk)
  22. {
  23. struct ieee80211_sub_if_data *sdata;
  24. struct ieee80211_local *local;
  25. sdata = container_of(wk, struct ieee80211_sub_if_data,
  26. u.mgd.tdls_peer_del_work.work);
  27. local = sdata->local;
  28. mutex_lock(&local->mtx);
  29. if (!is_zero_ether_addr(sdata->u.mgd.tdls_peer)) {
  30. tdls_dbg(sdata, "TDLS del peer %pM\n", sdata->u.mgd.tdls_peer);
  31. sta_info_destroy_addr(sdata, sdata->u.mgd.tdls_peer);
  32. eth_zero_addr(sdata->u.mgd.tdls_peer);
  33. }
  34. mutex_unlock(&local->mtx);
  35. }
  36. static void ieee80211_tdls_add_ext_capab(struct ieee80211_sub_if_data *sdata,
  37. struct sk_buff *skb)
  38. {
  39. struct ieee80211_local *local = sdata->local;
  40. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  41. bool chan_switch = local->hw.wiphy->features &
  42. NL80211_FEATURE_TDLS_CHANNEL_SWITCH;
  43. bool wider_band = ieee80211_hw_check(&local->hw, TDLS_WIDER_BW) &&
  44. !ifmgd->tdls_wider_bw_prohibited;
  45. struct ieee80211_supported_band *sband = ieee80211_get_sband(sdata);
  46. bool vht = sband && sband->vht_cap.vht_supported;
  47. u8 *pos = skb_put(skb, 10);
  48. *pos++ = WLAN_EID_EXT_CAPABILITY;
  49. *pos++ = 8; /* len */
  50. *pos++ = 0x0;
  51. *pos++ = 0x0;
  52. *pos++ = 0x0;
  53. *pos++ = chan_switch ? WLAN_EXT_CAPA4_TDLS_CHAN_SWITCH : 0;
  54. *pos++ = WLAN_EXT_CAPA5_TDLS_ENABLED;
  55. *pos++ = 0;
  56. *pos++ = 0;
  57. *pos++ = (vht && wider_band) ? WLAN_EXT_CAPA8_TDLS_WIDE_BW_ENABLED : 0;
  58. }
  59. static u8
  60. ieee80211_tdls_add_subband(struct ieee80211_sub_if_data *sdata,
  61. struct sk_buff *skb, u16 start, u16 end,
  62. u16 spacing)
  63. {
  64. u8 subband_cnt = 0, ch_cnt = 0;
  65. struct ieee80211_channel *ch;
  66. struct cfg80211_chan_def chandef;
  67. int i, subband_start;
  68. struct wiphy *wiphy = sdata->local->hw.wiphy;
  69. for (i = start; i <= end; i += spacing) {
  70. if (!ch_cnt)
  71. subband_start = i;
  72. ch = ieee80211_get_channel(sdata->local->hw.wiphy, i);
  73. if (ch) {
  74. /* we will be active on the channel */
  75. cfg80211_chandef_create(&chandef, ch,
  76. NL80211_CHAN_NO_HT);
  77. if (cfg80211_reg_can_beacon_relax(wiphy, &chandef,
  78. sdata->wdev.iftype)) {
  79. ch_cnt++;
  80. /*
  81. * check if the next channel is also part of
  82. * this allowed range
  83. */
  84. continue;
  85. }
  86. }
  87. /*
  88. * we've reached the end of a range, with allowed channels
  89. * found
  90. */
  91. if (ch_cnt) {
  92. u8 *pos = skb_put(skb, 2);
  93. *pos++ = ieee80211_frequency_to_channel(subband_start);
  94. *pos++ = ch_cnt;
  95. subband_cnt++;
  96. ch_cnt = 0;
  97. }
  98. }
  99. /* all channels in the requested range are allowed - add them here */
  100. if (ch_cnt) {
  101. u8 *pos = skb_put(skb, 2);
  102. *pos++ = ieee80211_frequency_to_channel(subband_start);
  103. *pos++ = ch_cnt;
  104. subband_cnt++;
  105. }
  106. return subband_cnt;
  107. }
  108. static void
  109. ieee80211_tdls_add_supp_channels(struct ieee80211_sub_if_data *sdata,
  110. struct sk_buff *skb)
  111. {
  112. /*
  113. * Add possible channels for TDLS. These are channels that are allowed
  114. * to be active.
  115. */
  116. u8 subband_cnt;
  117. u8 *pos = skb_put(skb, 2);
  118. *pos++ = WLAN_EID_SUPPORTED_CHANNELS;
  119. /*
  120. * 5GHz and 2GHz channels numbers can overlap. Ignore this for now, as
  121. * this doesn't happen in real world scenarios.
  122. */
  123. /* 2GHz, with 5MHz spacing */
  124. subband_cnt = ieee80211_tdls_add_subband(sdata, skb, 2412, 2472, 5);
  125. /* 5GHz, with 20MHz spacing */
  126. subband_cnt += ieee80211_tdls_add_subband(sdata, skb, 5000, 5825, 20);
  127. /* length */
  128. *pos = 2 * subband_cnt;
  129. }
  130. static void ieee80211_tdls_add_oper_classes(struct ieee80211_sub_if_data *sdata,
  131. struct sk_buff *skb)
  132. {
  133. u8 *pos;
  134. u8 op_class;
  135. if (!ieee80211_chandef_to_operating_class(&sdata->vif.bss_conf.chandef,
  136. &op_class))
  137. return;
  138. pos = skb_put(skb, 4);
  139. *pos++ = WLAN_EID_SUPPORTED_REGULATORY_CLASSES;
  140. *pos++ = 2; /* len */
  141. *pos++ = op_class;
  142. *pos++ = op_class; /* give current operating class as alternate too */
  143. }
  144. static void ieee80211_tdls_add_bss_coex_ie(struct sk_buff *skb)
  145. {
  146. u8 *pos = skb_put(skb, 3);
  147. *pos++ = WLAN_EID_BSS_COEX_2040;
  148. *pos++ = 1; /* len */
  149. *pos++ = WLAN_BSS_COEX_INFORMATION_REQUEST;
  150. }
  151. static u16 ieee80211_get_tdls_sta_capab(struct ieee80211_sub_if_data *sdata,
  152. u16 status_code)
  153. {
  154. struct ieee80211_supported_band *sband;
  155. /* The capability will be 0 when sending a failure code */
  156. if (status_code != 0)
  157. return 0;
  158. sband = ieee80211_get_sband(sdata);
  159. if (sband && sband->band == NL80211_BAND_2GHZ) {
  160. return WLAN_CAPABILITY_SHORT_SLOT_TIME |
  161. WLAN_CAPABILITY_SHORT_PREAMBLE;
  162. }
  163. return 0;
  164. }
  165. static void ieee80211_tdls_add_link_ie(struct ieee80211_sub_if_data *sdata,
  166. struct sk_buff *skb, const u8 *peer,
  167. bool initiator)
  168. {
  169. struct ieee80211_tdls_lnkie *lnkid;
  170. const u8 *init_addr, *rsp_addr;
  171. if (initiator) {
  172. init_addr = sdata->vif.addr;
  173. rsp_addr = peer;
  174. } else {
  175. init_addr = peer;
  176. rsp_addr = sdata->vif.addr;
  177. }
  178. lnkid = skb_put(skb, sizeof(struct ieee80211_tdls_lnkie));
  179. lnkid->ie_type = WLAN_EID_LINK_ID;
  180. lnkid->ie_len = sizeof(struct ieee80211_tdls_lnkie) - 2;
  181. memcpy(lnkid->bssid, sdata->u.mgd.bssid, ETH_ALEN);
  182. memcpy(lnkid->init_sta, init_addr, ETH_ALEN);
  183. memcpy(lnkid->resp_sta, rsp_addr, ETH_ALEN);
  184. }
  185. static void
  186. ieee80211_tdls_add_aid(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
  187. {
  188. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  189. u8 *pos = skb_put(skb, 4);
  190. *pos++ = WLAN_EID_AID;
  191. *pos++ = 2; /* len */
  192. put_unaligned_le16(ifmgd->aid, pos);
  193. }
  194. /* translate numbering in the WMM parameter IE to the mac80211 notation */
  195. static enum ieee80211_ac_numbers ieee80211_ac_from_wmm(int ac)
  196. {
  197. switch (ac) {
  198. default:
  199. WARN_ON_ONCE(1);
  200. case 0:
  201. return IEEE80211_AC_BE;
  202. case 1:
  203. return IEEE80211_AC_BK;
  204. case 2:
  205. return IEEE80211_AC_VI;
  206. case 3:
  207. return IEEE80211_AC_VO;
  208. }
  209. }
  210. static u8 ieee80211_wmm_aci_aifsn(int aifsn, bool acm, int aci)
  211. {
  212. u8 ret;
  213. ret = aifsn & 0x0f;
  214. if (acm)
  215. ret |= 0x10;
  216. ret |= (aci << 5) & 0x60;
  217. return ret;
  218. }
  219. static u8 ieee80211_wmm_ecw(u16 cw_min, u16 cw_max)
  220. {
  221. return ((ilog2(cw_min + 1) << 0x0) & 0x0f) |
  222. ((ilog2(cw_max + 1) << 0x4) & 0xf0);
  223. }
  224. static void ieee80211_tdls_add_wmm_param_ie(struct ieee80211_sub_if_data *sdata,
  225. struct sk_buff *skb)
  226. {
  227. struct ieee80211_wmm_param_ie *wmm;
  228. struct ieee80211_tx_queue_params *txq;
  229. int i;
  230. wmm = skb_put_zero(skb, sizeof(*wmm));
  231. wmm->element_id = WLAN_EID_VENDOR_SPECIFIC;
  232. wmm->len = sizeof(*wmm) - 2;
  233. wmm->oui[0] = 0x00; /* Microsoft OUI 00:50:F2 */
  234. wmm->oui[1] = 0x50;
  235. wmm->oui[2] = 0xf2;
  236. wmm->oui_type = 2; /* WME */
  237. wmm->oui_subtype = 1; /* WME param */
  238. wmm->version = 1; /* WME ver */
  239. wmm->qos_info = 0; /* U-APSD not in use */
  240. /*
  241. * Use the EDCA parameters defined for the BSS, or default if the AP
  242. * doesn't support it, as mandated by 802.11-2012 section 10.22.4
  243. */
  244. for (i = 0; i < IEEE80211_NUM_ACS; i++) {
  245. txq = &sdata->tx_conf[ieee80211_ac_from_wmm(i)];
  246. wmm->ac[i].aci_aifsn = ieee80211_wmm_aci_aifsn(txq->aifs,
  247. txq->acm, i);
  248. wmm->ac[i].cw = ieee80211_wmm_ecw(txq->cw_min, txq->cw_max);
  249. wmm->ac[i].txop_limit = cpu_to_le16(txq->txop);
  250. }
  251. }
  252. static void
  253. ieee80211_tdls_chandef_vht_upgrade(struct ieee80211_sub_if_data *sdata,
  254. struct sta_info *sta)
  255. {
  256. /* IEEE802.11ac-2013 Table E-4 */
  257. u16 centers_80mhz[] = { 5210, 5290, 5530, 5610, 5690, 5775 };
  258. struct cfg80211_chan_def uc = sta->tdls_chandef;
  259. enum nl80211_chan_width max_width = ieee80211_sta_cap_chan_bw(sta);
  260. int i;
  261. /* only support upgrading non-narrow channels up to 80Mhz */
  262. if (max_width == NL80211_CHAN_WIDTH_5 ||
  263. max_width == NL80211_CHAN_WIDTH_10)
  264. return;
  265. if (max_width > NL80211_CHAN_WIDTH_80)
  266. max_width = NL80211_CHAN_WIDTH_80;
  267. if (uc.width >= max_width)
  268. return;
  269. /*
  270. * Channel usage constrains in the IEEE802.11ac-2013 specification only
  271. * allow expanding a 20MHz channel to 80MHz in a single way. In
  272. * addition, there are no 40MHz allowed channels that are not part of
  273. * the allowed 80MHz range in the 5GHz spectrum (the relevant one here).
  274. */
  275. for (i = 0; i < ARRAY_SIZE(centers_80mhz); i++)
  276. if (abs(uc.chan->center_freq - centers_80mhz[i]) <= 30) {
  277. uc.center_freq1 = centers_80mhz[i];
  278. uc.center_freq2 = 0;
  279. uc.width = NL80211_CHAN_WIDTH_80;
  280. break;
  281. }
  282. if (!uc.center_freq1)
  283. return;
  284. /* proceed to downgrade the chandef until usable or the same as AP BW */
  285. while (uc.width > max_width ||
  286. (uc.width > sta->tdls_chandef.width &&
  287. !cfg80211_reg_can_beacon_relax(sdata->local->hw.wiphy, &uc,
  288. sdata->wdev.iftype)))
  289. ieee80211_chandef_downgrade(&uc);
  290. if (!cfg80211_chandef_identical(&uc, &sta->tdls_chandef)) {
  291. tdls_dbg(sdata, "TDLS ch width upgraded %d -> %d\n",
  292. sta->tdls_chandef.width, uc.width);
  293. /*
  294. * the station is not yet authorized when BW upgrade is done,
  295. * locking is not required
  296. */
  297. sta->tdls_chandef = uc;
  298. }
  299. }
  300. static void
  301. ieee80211_tdls_add_setup_start_ies(struct ieee80211_sub_if_data *sdata,
  302. struct sk_buff *skb, const u8 *peer,
  303. u8 action_code, bool initiator,
  304. const u8 *extra_ies, size_t extra_ies_len)
  305. {
  306. struct ieee80211_supported_band *sband;
  307. struct ieee80211_local *local = sdata->local;
  308. struct ieee80211_sta_ht_cap ht_cap;
  309. struct ieee80211_sta_vht_cap vht_cap;
  310. struct sta_info *sta = NULL;
  311. size_t offset = 0, noffset;
  312. u8 *pos;
  313. sband = ieee80211_get_sband(sdata);
  314. if (!sband)
  315. return;
  316. ieee80211_add_srates_ie(sdata, skb, false, sband->band);
  317. ieee80211_add_ext_srates_ie(sdata, skb, false, sband->band);
  318. ieee80211_tdls_add_supp_channels(sdata, skb);
  319. /* add any custom IEs that go before Extended Capabilities */
  320. if (extra_ies_len) {
  321. static const u8 before_ext_cap[] = {
  322. WLAN_EID_SUPP_RATES,
  323. WLAN_EID_COUNTRY,
  324. WLAN_EID_EXT_SUPP_RATES,
  325. WLAN_EID_SUPPORTED_CHANNELS,
  326. WLAN_EID_RSN,
  327. };
  328. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  329. before_ext_cap,
  330. ARRAY_SIZE(before_ext_cap),
  331. offset);
  332. skb_put_data(skb, extra_ies + offset, noffset - offset);
  333. offset = noffset;
  334. }
  335. ieee80211_tdls_add_ext_capab(sdata, skb);
  336. /* add the QoS element if we support it */
  337. if (local->hw.queues >= IEEE80211_NUM_ACS &&
  338. action_code != WLAN_PUB_ACTION_TDLS_DISCOVER_RES)
  339. ieee80211_add_wmm_info_ie(skb_put(skb, 9), 0); /* no U-APSD */
  340. /* add any custom IEs that go before HT capabilities */
  341. if (extra_ies_len) {
  342. static const u8 before_ht_cap[] = {
  343. WLAN_EID_SUPP_RATES,
  344. WLAN_EID_COUNTRY,
  345. WLAN_EID_EXT_SUPP_RATES,
  346. WLAN_EID_SUPPORTED_CHANNELS,
  347. WLAN_EID_RSN,
  348. WLAN_EID_EXT_CAPABILITY,
  349. WLAN_EID_QOS_CAPA,
  350. WLAN_EID_FAST_BSS_TRANSITION,
  351. WLAN_EID_TIMEOUT_INTERVAL,
  352. WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
  353. };
  354. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  355. before_ht_cap,
  356. ARRAY_SIZE(before_ht_cap),
  357. offset);
  358. skb_put_data(skb, extra_ies + offset, noffset - offset);
  359. offset = noffset;
  360. }
  361. mutex_lock(&local->sta_mtx);
  362. /* we should have the peer STA if we're already responding */
  363. if (action_code == WLAN_TDLS_SETUP_RESPONSE) {
  364. sta = sta_info_get(sdata, peer);
  365. if (WARN_ON_ONCE(!sta)) {
  366. mutex_unlock(&local->sta_mtx);
  367. return;
  368. }
  369. sta->tdls_chandef = sdata->vif.bss_conf.chandef;
  370. }
  371. ieee80211_tdls_add_oper_classes(sdata, skb);
  372. /*
  373. * with TDLS we can switch channels, and HT-caps are not necessarily
  374. * the same on all bands. The specification limits the setup to a
  375. * single HT-cap, so use the current band for now.
  376. */
  377. memcpy(&ht_cap, &sband->ht_cap, sizeof(ht_cap));
  378. if ((action_code == WLAN_TDLS_SETUP_REQUEST ||
  379. action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) &&
  380. ht_cap.ht_supported) {
  381. ieee80211_apply_htcap_overrides(sdata, &ht_cap);
  382. /* disable SMPS in TDLS initiator */
  383. ht_cap.cap |= WLAN_HT_CAP_SM_PS_DISABLED
  384. << IEEE80211_HT_CAP_SM_PS_SHIFT;
  385. pos = skb_put(skb, sizeof(struct ieee80211_ht_cap) + 2);
  386. ieee80211_ie_build_ht_cap(pos, &ht_cap, ht_cap.cap);
  387. } else if (action_code == WLAN_TDLS_SETUP_RESPONSE &&
  388. ht_cap.ht_supported && sta->sta.ht_cap.ht_supported) {
  389. /* the peer caps are already intersected with our own */
  390. memcpy(&ht_cap, &sta->sta.ht_cap, sizeof(ht_cap));
  391. pos = skb_put(skb, sizeof(struct ieee80211_ht_cap) + 2);
  392. ieee80211_ie_build_ht_cap(pos, &ht_cap, ht_cap.cap);
  393. }
  394. if (ht_cap.ht_supported &&
  395. (ht_cap.cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40))
  396. ieee80211_tdls_add_bss_coex_ie(skb);
  397. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  398. /* add any custom IEs that go before VHT capabilities */
  399. if (extra_ies_len) {
  400. static const u8 before_vht_cap[] = {
  401. WLAN_EID_SUPP_RATES,
  402. WLAN_EID_COUNTRY,
  403. WLAN_EID_EXT_SUPP_RATES,
  404. WLAN_EID_SUPPORTED_CHANNELS,
  405. WLAN_EID_RSN,
  406. WLAN_EID_EXT_CAPABILITY,
  407. WLAN_EID_QOS_CAPA,
  408. WLAN_EID_FAST_BSS_TRANSITION,
  409. WLAN_EID_TIMEOUT_INTERVAL,
  410. WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
  411. WLAN_EID_MULTI_BAND,
  412. };
  413. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  414. before_vht_cap,
  415. ARRAY_SIZE(before_vht_cap),
  416. offset);
  417. skb_put_data(skb, extra_ies + offset, noffset - offset);
  418. offset = noffset;
  419. }
  420. /* build the VHT-cap similarly to the HT-cap */
  421. memcpy(&vht_cap, &sband->vht_cap, sizeof(vht_cap));
  422. if ((action_code == WLAN_TDLS_SETUP_REQUEST ||
  423. action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) &&
  424. vht_cap.vht_supported) {
  425. ieee80211_apply_vhtcap_overrides(sdata, &vht_cap);
  426. /* the AID is present only when VHT is implemented */
  427. if (action_code == WLAN_TDLS_SETUP_REQUEST)
  428. ieee80211_tdls_add_aid(sdata, skb);
  429. pos = skb_put(skb, sizeof(struct ieee80211_vht_cap) + 2);
  430. ieee80211_ie_build_vht_cap(pos, &vht_cap, vht_cap.cap);
  431. } else if (action_code == WLAN_TDLS_SETUP_RESPONSE &&
  432. vht_cap.vht_supported && sta->sta.vht_cap.vht_supported) {
  433. /* the peer caps are already intersected with our own */
  434. memcpy(&vht_cap, &sta->sta.vht_cap, sizeof(vht_cap));
  435. /* the AID is present only when VHT is implemented */
  436. ieee80211_tdls_add_aid(sdata, skb);
  437. pos = skb_put(skb, sizeof(struct ieee80211_vht_cap) + 2);
  438. ieee80211_ie_build_vht_cap(pos, &vht_cap, vht_cap.cap);
  439. /*
  440. * if both peers support WIDER_BW, we can expand the chandef to
  441. * a wider compatible one, up to 80MHz
  442. */
  443. if (test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW))
  444. ieee80211_tdls_chandef_vht_upgrade(sdata, sta);
  445. }
  446. mutex_unlock(&local->sta_mtx);
  447. /* add any remaining IEs */
  448. if (extra_ies_len) {
  449. noffset = extra_ies_len;
  450. skb_put_data(skb, extra_ies + offset, noffset - offset);
  451. }
  452. }
  453. static void
  454. ieee80211_tdls_add_setup_cfm_ies(struct ieee80211_sub_if_data *sdata,
  455. struct sk_buff *skb, const u8 *peer,
  456. bool initiator, const u8 *extra_ies,
  457. size_t extra_ies_len)
  458. {
  459. struct ieee80211_local *local = sdata->local;
  460. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  461. size_t offset = 0, noffset;
  462. struct sta_info *sta, *ap_sta;
  463. struct ieee80211_supported_band *sband;
  464. u8 *pos;
  465. sband = ieee80211_get_sband(sdata);
  466. if (!sband)
  467. return;
  468. mutex_lock(&local->sta_mtx);
  469. sta = sta_info_get(sdata, peer);
  470. ap_sta = sta_info_get(sdata, ifmgd->bssid);
  471. if (WARN_ON_ONCE(!sta || !ap_sta)) {
  472. mutex_unlock(&local->sta_mtx);
  473. return;
  474. }
  475. sta->tdls_chandef = sdata->vif.bss_conf.chandef;
  476. /* add any custom IEs that go before the QoS IE */
  477. if (extra_ies_len) {
  478. static const u8 before_qos[] = {
  479. WLAN_EID_RSN,
  480. };
  481. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  482. before_qos,
  483. ARRAY_SIZE(before_qos),
  484. offset);
  485. skb_put_data(skb, extra_ies + offset, noffset - offset);
  486. offset = noffset;
  487. }
  488. /* add the QoS param IE if both the peer and we support it */
  489. if (local->hw.queues >= IEEE80211_NUM_ACS && sta->sta.wme)
  490. ieee80211_tdls_add_wmm_param_ie(sdata, skb);
  491. /* add any custom IEs that go before HT operation */
  492. if (extra_ies_len) {
  493. static const u8 before_ht_op[] = {
  494. WLAN_EID_RSN,
  495. WLAN_EID_QOS_CAPA,
  496. WLAN_EID_FAST_BSS_TRANSITION,
  497. WLAN_EID_TIMEOUT_INTERVAL,
  498. };
  499. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  500. before_ht_op,
  501. ARRAY_SIZE(before_ht_op),
  502. offset);
  503. skb_put_data(skb, extra_ies + offset, noffset - offset);
  504. offset = noffset;
  505. }
  506. /*
  507. * if HT support is only added in TDLS, we need an HT-operation IE.
  508. * add the IE as required by IEEE802.11-2012 9.23.3.2.
  509. */
  510. if (!ap_sta->sta.ht_cap.ht_supported && sta->sta.ht_cap.ht_supported) {
  511. u16 prot = IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED |
  512. IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
  513. IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
  514. pos = skb_put(skb, 2 + sizeof(struct ieee80211_ht_operation));
  515. ieee80211_ie_build_ht_oper(pos, &sta->sta.ht_cap,
  516. &sdata->vif.bss_conf.chandef, prot,
  517. true);
  518. }
  519. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  520. /* only include VHT-operation if not on the 2.4GHz band */
  521. if (sband->band != NL80211_BAND_2GHZ &&
  522. sta->sta.vht_cap.vht_supported) {
  523. /*
  524. * if both peers support WIDER_BW, we can expand the chandef to
  525. * a wider compatible one, up to 80MHz
  526. */
  527. if (test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW))
  528. ieee80211_tdls_chandef_vht_upgrade(sdata, sta);
  529. pos = skb_put(skb, 2 + sizeof(struct ieee80211_vht_operation));
  530. ieee80211_ie_build_vht_oper(pos, &sta->sta.vht_cap,
  531. &sta->tdls_chandef);
  532. }
  533. mutex_unlock(&local->sta_mtx);
  534. /* add any remaining IEs */
  535. if (extra_ies_len) {
  536. noffset = extra_ies_len;
  537. skb_put_data(skb, extra_ies + offset, noffset - offset);
  538. }
  539. }
  540. static void
  541. ieee80211_tdls_add_chan_switch_req_ies(struct ieee80211_sub_if_data *sdata,
  542. struct sk_buff *skb, const u8 *peer,
  543. bool initiator, const u8 *extra_ies,
  544. size_t extra_ies_len, u8 oper_class,
  545. struct cfg80211_chan_def *chandef)
  546. {
  547. struct ieee80211_tdls_data *tf;
  548. size_t offset = 0, noffset;
  549. if (WARN_ON_ONCE(!chandef))
  550. return;
  551. tf = (void *)skb->data;
  552. tf->u.chan_switch_req.target_channel =
  553. ieee80211_frequency_to_channel(chandef->chan->center_freq);
  554. tf->u.chan_switch_req.oper_class = oper_class;
  555. if (extra_ies_len) {
  556. static const u8 before_lnkie[] = {
  557. WLAN_EID_SECONDARY_CHANNEL_OFFSET,
  558. };
  559. noffset = ieee80211_ie_split(extra_ies, extra_ies_len,
  560. before_lnkie,
  561. ARRAY_SIZE(before_lnkie),
  562. offset);
  563. skb_put_data(skb, extra_ies + offset, noffset - offset);
  564. offset = noffset;
  565. }
  566. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  567. /* add any remaining IEs */
  568. if (extra_ies_len) {
  569. noffset = extra_ies_len;
  570. skb_put_data(skb, extra_ies + offset, noffset - offset);
  571. }
  572. }
  573. static void
  574. ieee80211_tdls_add_chan_switch_resp_ies(struct ieee80211_sub_if_data *sdata,
  575. struct sk_buff *skb, const u8 *peer,
  576. u16 status_code, bool initiator,
  577. const u8 *extra_ies,
  578. size_t extra_ies_len)
  579. {
  580. if (status_code == 0)
  581. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  582. if (extra_ies_len)
  583. skb_put_data(skb, extra_ies, extra_ies_len);
  584. }
  585. static void ieee80211_tdls_add_ies(struct ieee80211_sub_if_data *sdata,
  586. struct sk_buff *skb, const u8 *peer,
  587. u8 action_code, u16 status_code,
  588. bool initiator, const u8 *extra_ies,
  589. size_t extra_ies_len, u8 oper_class,
  590. struct cfg80211_chan_def *chandef)
  591. {
  592. switch (action_code) {
  593. case WLAN_TDLS_SETUP_REQUEST:
  594. case WLAN_TDLS_SETUP_RESPONSE:
  595. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  596. if (status_code == 0)
  597. ieee80211_tdls_add_setup_start_ies(sdata, skb, peer,
  598. action_code,
  599. initiator,
  600. extra_ies,
  601. extra_ies_len);
  602. break;
  603. case WLAN_TDLS_SETUP_CONFIRM:
  604. if (status_code == 0)
  605. ieee80211_tdls_add_setup_cfm_ies(sdata, skb, peer,
  606. initiator, extra_ies,
  607. extra_ies_len);
  608. break;
  609. case WLAN_TDLS_TEARDOWN:
  610. case WLAN_TDLS_DISCOVERY_REQUEST:
  611. if (extra_ies_len)
  612. skb_put_data(skb, extra_ies, extra_ies_len);
  613. if (status_code == 0 || action_code == WLAN_TDLS_TEARDOWN)
  614. ieee80211_tdls_add_link_ie(sdata, skb, peer, initiator);
  615. break;
  616. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  617. ieee80211_tdls_add_chan_switch_req_ies(sdata, skb, peer,
  618. initiator, extra_ies,
  619. extra_ies_len,
  620. oper_class, chandef);
  621. break;
  622. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  623. ieee80211_tdls_add_chan_switch_resp_ies(sdata, skb, peer,
  624. status_code,
  625. initiator, extra_ies,
  626. extra_ies_len);
  627. break;
  628. }
  629. }
  630. static int
  631. ieee80211_prep_tdls_encap_data(struct wiphy *wiphy, struct net_device *dev,
  632. const u8 *peer, u8 action_code, u8 dialog_token,
  633. u16 status_code, struct sk_buff *skb)
  634. {
  635. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  636. struct ieee80211_tdls_data *tf;
  637. tf = skb_put(skb, offsetof(struct ieee80211_tdls_data, u));
  638. memcpy(tf->da, peer, ETH_ALEN);
  639. memcpy(tf->sa, sdata->vif.addr, ETH_ALEN);
  640. tf->ether_type = cpu_to_be16(ETH_P_TDLS);
  641. tf->payload_type = WLAN_TDLS_SNAP_RFTYPE;
  642. /* network header is after the ethernet header */
  643. skb_set_network_header(skb, ETH_HLEN);
  644. switch (action_code) {
  645. case WLAN_TDLS_SETUP_REQUEST:
  646. tf->category = WLAN_CATEGORY_TDLS;
  647. tf->action_code = WLAN_TDLS_SETUP_REQUEST;
  648. skb_put(skb, sizeof(tf->u.setup_req));
  649. tf->u.setup_req.dialog_token = dialog_token;
  650. tf->u.setup_req.capability =
  651. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  652. status_code));
  653. break;
  654. case WLAN_TDLS_SETUP_RESPONSE:
  655. tf->category = WLAN_CATEGORY_TDLS;
  656. tf->action_code = WLAN_TDLS_SETUP_RESPONSE;
  657. skb_put(skb, sizeof(tf->u.setup_resp));
  658. tf->u.setup_resp.status_code = cpu_to_le16(status_code);
  659. tf->u.setup_resp.dialog_token = dialog_token;
  660. tf->u.setup_resp.capability =
  661. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  662. status_code));
  663. break;
  664. case WLAN_TDLS_SETUP_CONFIRM:
  665. tf->category = WLAN_CATEGORY_TDLS;
  666. tf->action_code = WLAN_TDLS_SETUP_CONFIRM;
  667. skb_put(skb, sizeof(tf->u.setup_cfm));
  668. tf->u.setup_cfm.status_code = cpu_to_le16(status_code);
  669. tf->u.setup_cfm.dialog_token = dialog_token;
  670. break;
  671. case WLAN_TDLS_TEARDOWN:
  672. tf->category = WLAN_CATEGORY_TDLS;
  673. tf->action_code = WLAN_TDLS_TEARDOWN;
  674. skb_put(skb, sizeof(tf->u.teardown));
  675. tf->u.teardown.reason_code = cpu_to_le16(status_code);
  676. break;
  677. case WLAN_TDLS_DISCOVERY_REQUEST:
  678. tf->category = WLAN_CATEGORY_TDLS;
  679. tf->action_code = WLAN_TDLS_DISCOVERY_REQUEST;
  680. skb_put(skb, sizeof(tf->u.discover_req));
  681. tf->u.discover_req.dialog_token = dialog_token;
  682. break;
  683. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  684. tf->category = WLAN_CATEGORY_TDLS;
  685. tf->action_code = WLAN_TDLS_CHANNEL_SWITCH_REQUEST;
  686. skb_put(skb, sizeof(tf->u.chan_switch_req));
  687. break;
  688. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  689. tf->category = WLAN_CATEGORY_TDLS;
  690. tf->action_code = WLAN_TDLS_CHANNEL_SWITCH_RESPONSE;
  691. skb_put(skb, sizeof(tf->u.chan_switch_resp));
  692. tf->u.chan_switch_resp.status_code = cpu_to_le16(status_code);
  693. break;
  694. default:
  695. return -EINVAL;
  696. }
  697. return 0;
  698. }
  699. static int
  700. ieee80211_prep_tdls_direct(struct wiphy *wiphy, struct net_device *dev,
  701. const u8 *peer, u8 action_code, u8 dialog_token,
  702. u16 status_code, struct sk_buff *skb)
  703. {
  704. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  705. struct ieee80211_mgmt *mgmt;
  706. mgmt = skb_put_zero(skb, 24);
  707. memcpy(mgmt->da, peer, ETH_ALEN);
  708. memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
  709. memcpy(mgmt->bssid, sdata->u.mgd.bssid, ETH_ALEN);
  710. mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
  711. IEEE80211_STYPE_ACTION);
  712. switch (action_code) {
  713. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  714. skb_put(skb, 1 + sizeof(mgmt->u.action.u.tdls_discover_resp));
  715. mgmt->u.action.category = WLAN_CATEGORY_PUBLIC;
  716. mgmt->u.action.u.tdls_discover_resp.action_code =
  717. WLAN_PUB_ACTION_TDLS_DISCOVER_RES;
  718. mgmt->u.action.u.tdls_discover_resp.dialog_token =
  719. dialog_token;
  720. mgmt->u.action.u.tdls_discover_resp.capability =
  721. cpu_to_le16(ieee80211_get_tdls_sta_capab(sdata,
  722. status_code));
  723. break;
  724. default:
  725. return -EINVAL;
  726. }
  727. return 0;
  728. }
  729. static struct sk_buff *
  730. ieee80211_tdls_build_mgmt_packet_data(struct ieee80211_sub_if_data *sdata,
  731. const u8 *peer, u8 action_code,
  732. u8 dialog_token, u16 status_code,
  733. bool initiator, const u8 *extra_ies,
  734. size_t extra_ies_len, u8 oper_class,
  735. struct cfg80211_chan_def *chandef)
  736. {
  737. struct ieee80211_local *local = sdata->local;
  738. struct sk_buff *skb;
  739. int ret;
  740. skb = netdev_alloc_skb(sdata->dev,
  741. local->hw.extra_tx_headroom +
  742. max(sizeof(struct ieee80211_mgmt),
  743. sizeof(struct ieee80211_tdls_data)) +
  744. 50 + /* supported rates */
  745. 10 + /* ext capab */
  746. 26 + /* max(WMM-info, WMM-param) */
  747. 2 + max(sizeof(struct ieee80211_ht_cap),
  748. sizeof(struct ieee80211_ht_operation)) +
  749. 2 + max(sizeof(struct ieee80211_vht_cap),
  750. sizeof(struct ieee80211_vht_operation)) +
  751. 50 + /* supported channels */
  752. 3 + /* 40/20 BSS coex */
  753. 4 + /* AID */
  754. 4 + /* oper classes */
  755. extra_ies_len +
  756. sizeof(struct ieee80211_tdls_lnkie));
  757. if (!skb)
  758. return NULL;
  759. skb_reserve(skb, local->hw.extra_tx_headroom);
  760. switch (action_code) {
  761. case WLAN_TDLS_SETUP_REQUEST:
  762. case WLAN_TDLS_SETUP_RESPONSE:
  763. case WLAN_TDLS_SETUP_CONFIRM:
  764. case WLAN_TDLS_TEARDOWN:
  765. case WLAN_TDLS_DISCOVERY_REQUEST:
  766. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  767. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  768. ret = ieee80211_prep_tdls_encap_data(local->hw.wiphy,
  769. sdata->dev, peer,
  770. action_code, dialog_token,
  771. status_code, skb);
  772. break;
  773. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  774. ret = ieee80211_prep_tdls_direct(local->hw.wiphy, sdata->dev,
  775. peer, action_code,
  776. dialog_token, status_code,
  777. skb);
  778. break;
  779. default:
  780. ret = -ENOTSUPP;
  781. break;
  782. }
  783. if (ret < 0)
  784. goto fail;
  785. ieee80211_tdls_add_ies(sdata, skb, peer, action_code, status_code,
  786. initiator, extra_ies, extra_ies_len, oper_class,
  787. chandef);
  788. return skb;
  789. fail:
  790. dev_kfree_skb(skb);
  791. return NULL;
  792. }
  793. static int
  794. ieee80211_tdls_prep_mgmt_packet(struct wiphy *wiphy, struct net_device *dev,
  795. const u8 *peer, u8 action_code, u8 dialog_token,
  796. u16 status_code, u32 peer_capability,
  797. bool initiator, const u8 *extra_ies,
  798. size_t extra_ies_len, u8 oper_class,
  799. struct cfg80211_chan_def *chandef)
  800. {
  801. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  802. struct sk_buff *skb = NULL;
  803. struct sta_info *sta;
  804. u32 flags = 0;
  805. int ret = 0;
  806. rcu_read_lock();
  807. sta = sta_info_get(sdata, peer);
  808. /* infer the initiator if we can, to support old userspace */
  809. switch (action_code) {
  810. case WLAN_TDLS_SETUP_REQUEST:
  811. if (sta) {
  812. set_sta_flag(sta, WLAN_STA_TDLS_INITIATOR);
  813. sta->sta.tdls_initiator = false;
  814. }
  815. /* fall-through */
  816. case WLAN_TDLS_SETUP_CONFIRM:
  817. case WLAN_TDLS_DISCOVERY_REQUEST:
  818. initiator = true;
  819. break;
  820. case WLAN_TDLS_SETUP_RESPONSE:
  821. /*
  822. * In some testing scenarios, we send a request and response.
  823. * Make the last packet sent take effect for the initiator
  824. * value.
  825. */
  826. if (sta) {
  827. clear_sta_flag(sta, WLAN_STA_TDLS_INITIATOR);
  828. sta->sta.tdls_initiator = true;
  829. }
  830. /* fall-through */
  831. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  832. initiator = false;
  833. break;
  834. case WLAN_TDLS_TEARDOWN:
  835. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  836. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  837. /* any value is ok */
  838. break;
  839. default:
  840. ret = -ENOTSUPP;
  841. break;
  842. }
  843. if (sta && test_sta_flag(sta, WLAN_STA_TDLS_INITIATOR))
  844. initiator = true;
  845. rcu_read_unlock();
  846. if (ret < 0)
  847. goto fail;
  848. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, peer, action_code,
  849. dialog_token, status_code,
  850. initiator, extra_ies,
  851. extra_ies_len, oper_class,
  852. chandef);
  853. if (!skb) {
  854. ret = -EINVAL;
  855. goto fail;
  856. }
  857. if (action_code == WLAN_PUB_ACTION_TDLS_DISCOVER_RES) {
  858. ieee80211_tx_skb(sdata, skb);
  859. return 0;
  860. }
  861. /*
  862. * According to 802.11z: Setup req/resp are sent in AC_BK, otherwise
  863. * we should default to AC_VI.
  864. */
  865. switch (action_code) {
  866. case WLAN_TDLS_SETUP_REQUEST:
  867. case WLAN_TDLS_SETUP_RESPONSE:
  868. skb->priority = 256 + 2;
  869. break;
  870. default:
  871. skb->priority = 256 + 5;
  872. break;
  873. }
  874. skb_set_queue_mapping(skb, ieee80211_select_queue(sdata, skb));
  875. /*
  876. * Set the WLAN_TDLS_TEARDOWN flag to indicate a teardown in progress.
  877. * Later, if no ACK is returned from peer, we will re-send the teardown
  878. * packet through the AP.
  879. */
  880. if ((action_code == WLAN_TDLS_TEARDOWN) &&
  881. ieee80211_hw_check(&sdata->local->hw, REPORTS_TX_ACK_STATUS)) {
  882. bool try_resend; /* Should we keep skb for possible resend */
  883. /* If not sending directly to peer - no point in keeping skb */
  884. rcu_read_lock();
  885. sta = sta_info_get(sdata, peer);
  886. try_resend = sta && test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  887. rcu_read_unlock();
  888. spin_lock_bh(&sdata->u.mgd.teardown_lock);
  889. if (try_resend && !sdata->u.mgd.teardown_skb) {
  890. /* Mark it as requiring TX status callback */
  891. flags |= IEEE80211_TX_CTL_REQ_TX_STATUS |
  892. IEEE80211_TX_INTFL_MLME_CONN_TX;
  893. /*
  894. * skb is copied since mac80211 will later set
  895. * properties that might not be the same as the AP,
  896. * such as encryption, QoS, addresses, etc.
  897. *
  898. * No problem if skb_copy() fails, so no need to check.
  899. */
  900. sdata->u.mgd.teardown_skb = skb_copy(skb, GFP_ATOMIC);
  901. sdata->u.mgd.orig_teardown_skb = skb;
  902. }
  903. spin_unlock_bh(&sdata->u.mgd.teardown_lock);
  904. }
  905. /* disable bottom halves when entering the Tx path */
  906. local_bh_disable();
  907. __ieee80211_subif_start_xmit(skb, dev, flags);
  908. local_bh_enable();
  909. return ret;
  910. fail:
  911. dev_kfree_skb(skb);
  912. return ret;
  913. }
  914. static int
  915. ieee80211_tdls_mgmt_setup(struct wiphy *wiphy, struct net_device *dev,
  916. const u8 *peer, u8 action_code, u8 dialog_token,
  917. u16 status_code, u32 peer_capability, bool initiator,
  918. const u8 *extra_ies, size_t extra_ies_len)
  919. {
  920. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  921. struct ieee80211_local *local = sdata->local;
  922. enum ieee80211_smps_mode smps_mode = sdata->u.mgd.driver_smps_mode;
  923. int ret;
  924. /* don't support setup with forced SMPS mode that's not off */
  925. if (smps_mode != IEEE80211_SMPS_AUTOMATIC &&
  926. smps_mode != IEEE80211_SMPS_OFF) {
  927. tdls_dbg(sdata, "Aborting TDLS setup due to SMPS mode %d\n",
  928. smps_mode);
  929. return -ENOTSUPP;
  930. }
  931. mutex_lock(&local->mtx);
  932. /* we don't support concurrent TDLS peer setups */
  933. if (!is_zero_ether_addr(sdata->u.mgd.tdls_peer) &&
  934. !ether_addr_equal(sdata->u.mgd.tdls_peer, peer)) {
  935. ret = -EBUSY;
  936. goto out_unlock;
  937. }
  938. /*
  939. * make sure we have a STA representing the peer so we drop or buffer
  940. * non-TDLS-setup frames to the peer. We can't send other packets
  941. * during setup through the AP path.
  942. * Allow error packets to be sent - sometimes we don't even add a STA
  943. * before failing the setup.
  944. */
  945. if (status_code == 0) {
  946. rcu_read_lock();
  947. if (!sta_info_get(sdata, peer)) {
  948. rcu_read_unlock();
  949. ret = -ENOLINK;
  950. goto out_unlock;
  951. }
  952. rcu_read_unlock();
  953. }
  954. ieee80211_flush_queues(local, sdata, false);
  955. memcpy(sdata->u.mgd.tdls_peer, peer, ETH_ALEN);
  956. mutex_unlock(&local->mtx);
  957. /* we cannot take the mutex while preparing the setup packet */
  958. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
  959. dialog_token, status_code,
  960. peer_capability, initiator,
  961. extra_ies, extra_ies_len, 0,
  962. NULL);
  963. if (ret < 0) {
  964. mutex_lock(&local->mtx);
  965. eth_zero_addr(sdata->u.mgd.tdls_peer);
  966. mutex_unlock(&local->mtx);
  967. return ret;
  968. }
  969. ieee80211_queue_delayed_work(&sdata->local->hw,
  970. &sdata->u.mgd.tdls_peer_del_work,
  971. TDLS_PEER_SETUP_TIMEOUT);
  972. return 0;
  973. out_unlock:
  974. mutex_unlock(&local->mtx);
  975. return ret;
  976. }
  977. static int
  978. ieee80211_tdls_mgmt_teardown(struct wiphy *wiphy, struct net_device *dev,
  979. const u8 *peer, u8 action_code, u8 dialog_token,
  980. u16 status_code, u32 peer_capability,
  981. bool initiator, const u8 *extra_ies,
  982. size_t extra_ies_len)
  983. {
  984. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  985. struct ieee80211_local *local = sdata->local;
  986. struct sta_info *sta;
  987. int ret;
  988. /*
  989. * No packets can be transmitted to the peer via the AP during setup -
  990. * the STA is set as a TDLS peer, but is not authorized.
  991. * During teardown, we prevent direct transmissions by stopping the
  992. * queues and flushing all direct packets.
  993. */
  994. ieee80211_stop_vif_queues(local, sdata,
  995. IEEE80211_QUEUE_STOP_REASON_TDLS_TEARDOWN);
  996. ieee80211_flush_queues(local, sdata, false);
  997. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer, action_code,
  998. dialog_token, status_code,
  999. peer_capability, initiator,
  1000. extra_ies, extra_ies_len, 0,
  1001. NULL);
  1002. if (ret < 0)
  1003. sdata_err(sdata, "Failed sending TDLS teardown packet %d\n",
  1004. ret);
  1005. /*
  1006. * Remove the STA AUTH flag to force further traffic through the AP. If
  1007. * the STA was unreachable, it was already removed.
  1008. */
  1009. rcu_read_lock();
  1010. sta = sta_info_get(sdata, peer);
  1011. if (sta)
  1012. clear_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  1013. rcu_read_unlock();
  1014. ieee80211_wake_vif_queues(local, sdata,
  1015. IEEE80211_QUEUE_STOP_REASON_TDLS_TEARDOWN);
  1016. return 0;
  1017. }
  1018. int ieee80211_tdls_mgmt(struct wiphy *wiphy, struct net_device *dev,
  1019. const u8 *peer, u8 action_code, u8 dialog_token,
  1020. u16 status_code, u32 peer_capability,
  1021. bool initiator, const u8 *extra_ies,
  1022. size_t extra_ies_len)
  1023. {
  1024. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1025. int ret;
  1026. if (!(wiphy->flags & WIPHY_FLAG_SUPPORTS_TDLS))
  1027. return -ENOTSUPP;
  1028. /* make sure we are in managed mode, and associated */
  1029. if (sdata->vif.type != NL80211_IFTYPE_STATION ||
  1030. !sdata->u.mgd.associated)
  1031. return -EINVAL;
  1032. switch (action_code) {
  1033. case WLAN_TDLS_SETUP_REQUEST:
  1034. case WLAN_TDLS_SETUP_RESPONSE:
  1035. ret = ieee80211_tdls_mgmt_setup(wiphy, dev, peer, action_code,
  1036. dialog_token, status_code,
  1037. peer_capability, initiator,
  1038. extra_ies, extra_ies_len);
  1039. break;
  1040. case WLAN_TDLS_TEARDOWN:
  1041. ret = ieee80211_tdls_mgmt_teardown(wiphy, dev, peer,
  1042. action_code, dialog_token,
  1043. status_code,
  1044. peer_capability, initiator,
  1045. extra_ies, extra_ies_len);
  1046. break;
  1047. case WLAN_TDLS_DISCOVERY_REQUEST:
  1048. /*
  1049. * Protect the discovery so we can hear the TDLS discovery
  1050. * response frame. It is transmitted directly and not buffered
  1051. * by the AP.
  1052. */
  1053. drv_mgd_protect_tdls_discover(sdata->local, sdata);
  1054. /* fall-through */
  1055. case WLAN_TDLS_SETUP_CONFIRM:
  1056. case WLAN_PUB_ACTION_TDLS_DISCOVER_RES:
  1057. /* no special handling */
  1058. ret = ieee80211_tdls_prep_mgmt_packet(wiphy, dev, peer,
  1059. action_code,
  1060. dialog_token,
  1061. status_code,
  1062. peer_capability,
  1063. initiator, extra_ies,
  1064. extra_ies_len, 0, NULL);
  1065. break;
  1066. default:
  1067. ret = -EOPNOTSUPP;
  1068. break;
  1069. }
  1070. tdls_dbg(sdata, "TDLS mgmt action %d peer %pM status %d\n",
  1071. action_code, peer, ret);
  1072. return ret;
  1073. }
  1074. static void iee80211_tdls_recalc_chanctx(struct ieee80211_sub_if_data *sdata,
  1075. struct sta_info *sta)
  1076. {
  1077. struct ieee80211_local *local = sdata->local;
  1078. struct ieee80211_chanctx_conf *conf;
  1079. struct ieee80211_chanctx *ctx;
  1080. enum nl80211_chan_width width;
  1081. struct ieee80211_supported_band *sband;
  1082. mutex_lock(&local->chanctx_mtx);
  1083. conf = rcu_dereference_protected(sdata->vif.chanctx_conf,
  1084. lockdep_is_held(&local->chanctx_mtx));
  1085. if (conf) {
  1086. width = conf->def.width;
  1087. sband = local->hw.wiphy->bands[conf->def.chan->band];
  1088. ctx = container_of(conf, struct ieee80211_chanctx, conf);
  1089. ieee80211_recalc_chanctx_chantype(local, ctx);
  1090. /* if width changed and a peer is given, update its BW */
  1091. if (width != conf->def.width && sta &&
  1092. test_sta_flag(sta, WLAN_STA_TDLS_WIDER_BW)) {
  1093. enum ieee80211_sta_rx_bandwidth bw;
  1094. bw = ieee80211_chan_width_to_rx_bw(conf->def.width);
  1095. bw = min(bw, ieee80211_sta_cap_rx_bw(sta));
  1096. if (bw != sta->sta.bandwidth) {
  1097. sta->sta.bandwidth = bw;
  1098. rate_control_rate_update(local, sband, sta,
  1099. IEEE80211_RC_BW_CHANGED);
  1100. /*
  1101. * if a TDLS peer BW was updated, we need to
  1102. * recalc the chandef width again, to get the
  1103. * correct chanctx min_def
  1104. */
  1105. ieee80211_recalc_chanctx_chantype(local, ctx);
  1106. }
  1107. }
  1108. }
  1109. mutex_unlock(&local->chanctx_mtx);
  1110. }
  1111. static int iee80211_tdls_have_ht_peers(struct ieee80211_sub_if_data *sdata)
  1112. {
  1113. struct sta_info *sta;
  1114. bool result = false;
  1115. rcu_read_lock();
  1116. list_for_each_entry_rcu(sta, &sdata->local->sta_list, list) {
  1117. if (!sta->sta.tdls || sta->sdata != sdata || !sta->uploaded ||
  1118. !test_sta_flag(sta, WLAN_STA_AUTHORIZED) ||
  1119. !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH) ||
  1120. !sta->sta.ht_cap.ht_supported)
  1121. continue;
  1122. result = true;
  1123. break;
  1124. }
  1125. rcu_read_unlock();
  1126. return result;
  1127. }
  1128. static void
  1129. iee80211_tdls_recalc_ht_protection(struct ieee80211_sub_if_data *sdata,
  1130. struct sta_info *sta)
  1131. {
  1132. struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
  1133. bool tdls_ht;
  1134. u16 protection = IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED |
  1135. IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
  1136. IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
  1137. u16 opmode;
  1138. /* Nothing to do if the BSS connection uses HT */
  1139. if (!(ifmgd->flags & IEEE80211_STA_DISABLE_HT))
  1140. return;
  1141. tdls_ht = (sta && sta->sta.ht_cap.ht_supported) ||
  1142. iee80211_tdls_have_ht_peers(sdata);
  1143. opmode = sdata->vif.bss_conf.ht_operation_mode;
  1144. if (tdls_ht)
  1145. opmode |= protection;
  1146. else
  1147. opmode &= ~protection;
  1148. if (opmode == sdata->vif.bss_conf.ht_operation_mode)
  1149. return;
  1150. sdata->vif.bss_conf.ht_operation_mode = opmode;
  1151. ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_HT);
  1152. }
  1153. int ieee80211_tdls_oper(struct wiphy *wiphy, struct net_device *dev,
  1154. const u8 *peer, enum nl80211_tdls_operation oper)
  1155. {
  1156. struct sta_info *sta;
  1157. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1158. struct ieee80211_local *local = sdata->local;
  1159. int ret;
  1160. if (!(wiphy->flags & WIPHY_FLAG_SUPPORTS_TDLS))
  1161. return -ENOTSUPP;
  1162. if (sdata->vif.type != NL80211_IFTYPE_STATION)
  1163. return -EINVAL;
  1164. switch (oper) {
  1165. case NL80211_TDLS_ENABLE_LINK:
  1166. case NL80211_TDLS_DISABLE_LINK:
  1167. break;
  1168. case NL80211_TDLS_TEARDOWN:
  1169. case NL80211_TDLS_SETUP:
  1170. case NL80211_TDLS_DISCOVERY_REQ:
  1171. /* We don't support in-driver setup/teardown/discovery */
  1172. return -ENOTSUPP;
  1173. }
  1174. /* protect possible bss_conf changes and avoid concurrency in
  1175. * ieee80211_bss_info_change_notify()
  1176. */
  1177. sdata_lock(sdata);
  1178. mutex_lock(&local->mtx);
  1179. tdls_dbg(sdata, "TDLS oper %d peer %pM\n", oper, peer);
  1180. switch (oper) {
  1181. case NL80211_TDLS_ENABLE_LINK:
  1182. if (sdata->vif.csa_active) {
  1183. tdls_dbg(sdata, "TDLS: disallow link during CSA\n");
  1184. ret = -EBUSY;
  1185. break;
  1186. }
  1187. mutex_lock(&local->sta_mtx);
  1188. sta = sta_info_get(sdata, peer);
  1189. if (!sta) {
  1190. mutex_unlock(&local->sta_mtx);
  1191. ret = -ENOLINK;
  1192. break;
  1193. }
  1194. iee80211_tdls_recalc_chanctx(sdata, sta);
  1195. iee80211_tdls_recalc_ht_protection(sdata, sta);
  1196. set_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH);
  1197. mutex_unlock(&local->sta_mtx);
  1198. WARN_ON_ONCE(is_zero_ether_addr(sdata->u.mgd.tdls_peer) ||
  1199. !ether_addr_equal(sdata->u.mgd.tdls_peer, peer));
  1200. ret = 0;
  1201. break;
  1202. case NL80211_TDLS_DISABLE_LINK:
  1203. /*
  1204. * The teardown message in ieee80211_tdls_mgmt_teardown() was
  1205. * created while the queues were stopped, so it might still be
  1206. * pending. Before flushing the queues we need to be sure the
  1207. * message is handled by the tasklet handling pending messages,
  1208. * otherwise we might start destroying the station before
  1209. * sending the teardown packet.
  1210. * Note that this only forces the tasklet to flush pendings -
  1211. * not to stop the tasklet from rescheduling itself.
  1212. */
  1213. tasklet_kill(&local->tx_pending_tasklet);
  1214. /* flush a potentially queued teardown packet */
  1215. ieee80211_flush_queues(local, sdata, false);
  1216. ret = sta_info_destroy_addr(sdata, peer);
  1217. mutex_lock(&local->sta_mtx);
  1218. iee80211_tdls_recalc_ht_protection(sdata, NULL);
  1219. mutex_unlock(&local->sta_mtx);
  1220. iee80211_tdls_recalc_chanctx(sdata, NULL);
  1221. break;
  1222. default:
  1223. ret = -ENOTSUPP;
  1224. break;
  1225. }
  1226. if (ret == 0 && ether_addr_equal(sdata->u.mgd.tdls_peer, peer)) {
  1227. cancel_delayed_work(&sdata->u.mgd.tdls_peer_del_work);
  1228. eth_zero_addr(sdata->u.mgd.tdls_peer);
  1229. }
  1230. if (ret == 0)
  1231. ieee80211_queue_work(&sdata->local->hw,
  1232. &sdata->u.mgd.request_smps_work);
  1233. mutex_unlock(&local->mtx);
  1234. sdata_unlock(sdata);
  1235. return ret;
  1236. }
  1237. void ieee80211_tdls_oper_request(struct ieee80211_vif *vif, const u8 *peer,
  1238. enum nl80211_tdls_operation oper,
  1239. u16 reason_code, gfp_t gfp)
  1240. {
  1241. struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
  1242. if (vif->type != NL80211_IFTYPE_STATION || !vif->bss_conf.assoc) {
  1243. sdata_err(sdata, "Discarding TDLS oper %d - not STA or disconnected\n",
  1244. oper);
  1245. return;
  1246. }
  1247. cfg80211_tdls_oper_request(sdata->dev, peer, oper, reason_code, gfp);
  1248. }
  1249. EXPORT_SYMBOL(ieee80211_tdls_oper_request);
  1250. static void
  1251. iee80211_tdls_add_ch_switch_timing(u8 *buf, u16 switch_time, u16 switch_timeout)
  1252. {
  1253. struct ieee80211_ch_switch_timing *ch_sw;
  1254. *buf++ = WLAN_EID_CHAN_SWITCH_TIMING;
  1255. *buf++ = sizeof(struct ieee80211_ch_switch_timing);
  1256. ch_sw = (void *)buf;
  1257. ch_sw->switch_time = cpu_to_le16(switch_time);
  1258. ch_sw->switch_timeout = cpu_to_le16(switch_timeout);
  1259. }
  1260. /* find switch timing IE in SKB ready for Tx */
  1261. static const u8 *ieee80211_tdls_find_sw_timing_ie(struct sk_buff *skb)
  1262. {
  1263. struct ieee80211_tdls_data *tf;
  1264. const u8 *ie_start;
  1265. /*
  1266. * Get the offset for the new location of the switch timing IE.
  1267. * The SKB network header will now point to the "payload_type"
  1268. * element of the TDLS data frame struct.
  1269. */
  1270. tf = container_of(skb->data + skb_network_offset(skb),
  1271. struct ieee80211_tdls_data, payload_type);
  1272. ie_start = tf->u.chan_switch_req.variable;
  1273. return cfg80211_find_ie(WLAN_EID_CHAN_SWITCH_TIMING, ie_start,
  1274. skb->len - (ie_start - skb->data));
  1275. }
  1276. static struct sk_buff *
  1277. ieee80211_tdls_ch_sw_tmpl_get(struct sta_info *sta, u8 oper_class,
  1278. struct cfg80211_chan_def *chandef,
  1279. u32 *ch_sw_tm_ie_offset)
  1280. {
  1281. struct ieee80211_sub_if_data *sdata = sta->sdata;
  1282. u8 extra_ies[2 + sizeof(struct ieee80211_sec_chan_offs_ie) +
  1283. 2 + sizeof(struct ieee80211_ch_switch_timing)];
  1284. int extra_ies_len = 2 + sizeof(struct ieee80211_ch_switch_timing);
  1285. u8 *pos = extra_ies;
  1286. struct sk_buff *skb;
  1287. /*
  1288. * if chandef points to a wide channel add a Secondary-Channel
  1289. * Offset information element
  1290. */
  1291. if (chandef->width == NL80211_CHAN_WIDTH_40) {
  1292. struct ieee80211_sec_chan_offs_ie *sec_chan_ie;
  1293. bool ht40plus;
  1294. *pos++ = WLAN_EID_SECONDARY_CHANNEL_OFFSET;
  1295. *pos++ = sizeof(*sec_chan_ie);
  1296. sec_chan_ie = (void *)pos;
  1297. ht40plus = cfg80211_get_chandef_type(chandef) ==
  1298. NL80211_CHAN_HT40PLUS;
  1299. sec_chan_ie->sec_chan_offs = ht40plus ?
  1300. IEEE80211_HT_PARAM_CHA_SEC_ABOVE :
  1301. IEEE80211_HT_PARAM_CHA_SEC_BELOW;
  1302. pos += sizeof(*sec_chan_ie);
  1303. extra_ies_len += 2 + sizeof(struct ieee80211_sec_chan_offs_ie);
  1304. }
  1305. /* just set the values to 0, this is a template */
  1306. iee80211_tdls_add_ch_switch_timing(pos, 0, 0);
  1307. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
  1308. WLAN_TDLS_CHANNEL_SWITCH_REQUEST,
  1309. 0, 0, !sta->sta.tdls_initiator,
  1310. extra_ies, extra_ies_len,
  1311. oper_class, chandef);
  1312. if (!skb)
  1313. return NULL;
  1314. skb = ieee80211_build_data_template(sdata, skb, 0);
  1315. if (IS_ERR(skb)) {
  1316. tdls_dbg(sdata, "Failed building TDLS channel switch frame\n");
  1317. return NULL;
  1318. }
  1319. if (ch_sw_tm_ie_offset) {
  1320. const u8 *tm_ie = ieee80211_tdls_find_sw_timing_ie(skb);
  1321. if (!tm_ie) {
  1322. tdls_dbg(sdata, "No switch timing IE in TDLS switch\n");
  1323. dev_kfree_skb_any(skb);
  1324. return NULL;
  1325. }
  1326. *ch_sw_tm_ie_offset = tm_ie - skb->data;
  1327. }
  1328. tdls_dbg(sdata,
  1329. "TDLS channel switch request template for %pM ch %d width %d\n",
  1330. sta->sta.addr, chandef->chan->center_freq, chandef->width);
  1331. return skb;
  1332. }
  1333. int
  1334. ieee80211_tdls_channel_switch(struct wiphy *wiphy, struct net_device *dev,
  1335. const u8 *addr, u8 oper_class,
  1336. struct cfg80211_chan_def *chandef)
  1337. {
  1338. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1339. struct ieee80211_local *local = sdata->local;
  1340. struct sta_info *sta;
  1341. struct sk_buff *skb = NULL;
  1342. u32 ch_sw_tm_ie;
  1343. int ret;
  1344. mutex_lock(&local->sta_mtx);
  1345. sta = sta_info_get(sdata, addr);
  1346. if (!sta) {
  1347. tdls_dbg(sdata,
  1348. "Invalid TDLS peer %pM for channel switch request\n",
  1349. addr);
  1350. ret = -ENOENT;
  1351. goto out;
  1352. }
  1353. if (!test_sta_flag(sta, WLAN_STA_TDLS_CHAN_SWITCH)) {
  1354. tdls_dbg(sdata, "TDLS channel switch unsupported by %pM\n",
  1355. addr);
  1356. ret = -ENOTSUPP;
  1357. goto out;
  1358. }
  1359. skb = ieee80211_tdls_ch_sw_tmpl_get(sta, oper_class, chandef,
  1360. &ch_sw_tm_ie);
  1361. if (!skb) {
  1362. ret = -ENOENT;
  1363. goto out;
  1364. }
  1365. ret = drv_tdls_channel_switch(local, sdata, &sta->sta, oper_class,
  1366. chandef, skb, ch_sw_tm_ie);
  1367. if (!ret)
  1368. set_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL);
  1369. out:
  1370. mutex_unlock(&local->sta_mtx);
  1371. dev_kfree_skb_any(skb);
  1372. return ret;
  1373. }
  1374. void
  1375. ieee80211_tdls_cancel_channel_switch(struct wiphy *wiphy,
  1376. struct net_device *dev,
  1377. const u8 *addr)
  1378. {
  1379. struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
  1380. struct ieee80211_local *local = sdata->local;
  1381. struct sta_info *sta;
  1382. mutex_lock(&local->sta_mtx);
  1383. sta = sta_info_get(sdata, addr);
  1384. if (!sta) {
  1385. tdls_dbg(sdata,
  1386. "Invalid TDLS peer %pM for channel switch cancel\n",
  1387. addr);
  1388. goto out;
  1389. }
  1390. if (!test_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL)) {
  1391. tdls_dbg(sdata, "TDLS channel switch not initiated by %pM\n",
  1392. addr);
  1393. goto out;
  1394. }
  1395. drv_tdls_cancel_channel_switch(local, sdata, &sta->sta);
  1396. clear_sta_flag(sta, WLAN_STA_TDLS_OFF_CHANNEL);
  1397. out:
  1398. mutex_unlock(&local->sta_mtx);
  1399. }
  1400. static struct sk_buff *
  1401. ieee80211_tdls_ch_sw_resp_tmpl_get(struct sta_info *sta,
  1402. u32 *ch_sw_tm_ie_offset)
  1403. {
  1404. struct ieee80211_sub_if_data *sdata = sta->sdata;
  1405. struct sk_buff *skb;
  1406. u8 extra_ies[2 + sizeof(struct ieee80211_ch_switch_timing)];
  1407. /* initial timing are always zero in the template */
  1408. iee80211_tdls_add_ch_switch_timing(extra_ies, 0, 0);
  1409. skb = ieee80211_tdls_build_mgmt_packet_data(sdata, sta->sta.addr,
  1410. WLAN_TDLS_CHANNEL_SWITCH_RESPONSE,
  1411. 0, 0, !sta->sta.tdls_initiator,
  1412. extra_ies, sizeof(extra_ies), 0, NULL);
  1413. if (!skb)
  1414. return NULL;
  1415. skb = ieee80211_build_data_template(sdata, skb, 0);
  1416. if (IS_ERR(skb)) {
  1417. tdls_dbg(sdata,
  1418. "Failed building TDLS channel switch resp frame\n");
  1419. return NULL;
  1420. }
  1421. if (ch_sw_tm_ie_offset) {
  1422. const u8 *tm_ie = ieee80211_tdls_find_sw_timing_ie(skb);
  1423. if (!tm_ie) {
  1424. tdls_dbg(sdata,
  1425. "No switch timing IE in TDLS switch resp\n");
  1426. dev_kfree_skb_any(skb);
  1427. return NULL;
  1428. }
  1429. *ch_sw_tm_ie_offset = tm_ie - skb->data;
  1430. }
  1431. tdls_dbg(sdata, "TDLS get channel switch response template for %pM\n",
  1432. sta->sta.addr);
  1433. return skb;
  1434. }
  1435. static int
  1436. ieee80211_process_tdls_channel_switch_resp(struct ieee80211_sub_if_data *sdata,
  1437. struct sk_buff *skb)
  1438. {
  1439. struct ieee80211_local *local = sdata->local;
  1440. struct ieee802_11_elems elems;
  1441. struct sta_info *sta;
  1442. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1443. bool local_initiator;
  1444. struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
  1445. int baselen = offsetof(typeof(*tf), u.chan_switch_resp.variable);
  1446. struct ieee80211_tdls_ch_sw_params params = {};
  1447. int ret;
  1448. params.action_code = WLAN_TDLS_CHANNEL_SWITCH_RESPONSE;
  1449. params.timestamp = rx_status->device_timestamp;
  1450. if (skb->len < baselen) {
  1451. tdls_dbg(sdata, "TDLS channel switch resp too short: %d\n",
  1452. skb->len);
  1453. return -EINVAL;
  1454. }
  1455. mutex_lock(&local->sta_mtx);
  1456. sta = sta_info_get(sdata, tf->sa);
  1457. if (!sta || !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH)) {
  1458. tdls_dbg(sdata, "TDLS chan switch from non-peer sta %pM\n",
  1459. tf->sa);
  1460. ret = -EINVAL;
  1461. goto out;
  1462. }
  1463. params.sta = &sta->sta;
  1464. params.status = le16_to_cpu(tf->u.chan_switch_resp.status_code);
  1465. if (params.status != 0) {
  1466. ret = 0;
  1467. goto call_drv;
  1468. }
  1469. ieee802_11_parse_elems(tf->u.chan_switch_resp.variable,
  1470. skb->len - baselen, false, &elems);
  1471. if (elems.parse_error) {
  1472. tdls_dbg(sdata, "Invalid IEs in TDLS channel switch resp\n");
  1473. ret = -EINVAL;
  1474. goto out;
  1475. }
  1476. if (!elems.ch_sw_timing || !elems.lnk_id) {
  1477. tdls_dbg(sdata, "TDLS channel switch resp - missing IEs\n");
  1478. ret = -EINVAL;
  1479. goto out;
  1480. }
  1481. /* validate the initiator is set correctly */
  1482. local_initiator =
  1483. !memcmp(elems.lnk_id->init_sta, sdata->vif.addr, ETH_ALEN);
  1484. if (local_initiator == sta->sta.tdls_initiator) {
  1485. tdls_dbg(sdata, "TDLS chan switch invalid lnk-id initiator\n");
  1486. ret = -EINVAL;
  1487. goto out;
  1488. }
  1489. params.switch_time = le16_to_cpu(elems.ch_sw_timing->switch_time);
  1490. params.switch_timeout = le16_to_cpu(elems.ch_sw_timing->switch_timeout);
  1491. params.tmpl_skb =
  1492. ieee80211_tdls_ch_sw_resp_tmpl_get(sta, &params.ch_sw_tm_ie);
  1493. if (!params.tmpl_skb) {
  1494. ret = -ENOENT;
  1495. goto out;
  1496. }
  1497. ret = 0;
  1498. call_drv:
  1499. drv_tdls_recv_channel_switch(sdata->local, sdata, &params);
  1500. tdls_dbg(sdata,
  1501. "TDLS channel switch response received from %pM status %d\n",
  1502. tf->sa, params.status);
  1503. out:
  1504. mutex_unlock(&local->sta_mtx);
  1505. dev_kfree_skb_any(params.tmpl_skb);
  1506. return ret;
  1507. }
  1508. static int
  1509. ieee80211_process_tdls_channel_switch_req(struct ieee80211_sub_if_data *sdata,
  1510. struct sk_buff *skb)
  1511. {
  1512. struct ieee80211_local *local = sdata->local;
  1513. struct ieee802_11_elems elems;
  1514. struct cfg80211_chan_def chandef;
  1515. struct ieee80211_channel *chan;
  1516. enum nl80211_channel_type chan_type;
  1517. int freq;
  1518. u8 target_channel, oper_class;
  1519. bool local_initiator;
  1520. struct sta_info *sta;
  1521. enum nl80211_band band;
  1522. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1523. struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
  1524. int baselen = offsetof(typeof(*tf), u.chan_switch_req.variable);
  1525. struct ieee80211_tdls_ch_sw_params params = {};
  1526. int ret = 0;
  1527. params.action_code = WLAN_TDLS_CHANNEL_SWITCH_REQUEST;
  1528. params.timestamp = rx_status->device_timestamp;
  1529. if (skb->len < baselen) {
  1530. tdls_dbg(sdata, "TDLS channel switch req too short: %d\n",
  1531. skb->len);
  1532. return -EINVAL;
  1533. }
  1534. target_channel = tf->u.chan_switch_req.target_channel;
  1535. oper_class = tf->u.chan_switch_req.oper_class;
  1536. /*
  1537. * We can't easily infer the channel band. The operating class is
  1538. * ambiguous - there are multiple tables (US/Europe/JP/Global). The
  1539. * solution here is to treat channels with number >14 as 5GHz ones,
  1540. * and specifically check for the (oper_class, channel) combinations
  1541. * where this doesn't hold. These are thankfully unique according to
  1542. * IEEE802.11-2012.
  1543. * We consider only the 2GHz and 5GHz bands and 20MHz+ channels as
  1544. * valid here.
  1545. */
  1546. if ((oper_class == 112 || oper_class == 2 || oper_class == 3 ||
  1547. oper_class == 4 || oper_class == 5 || oper_class == 6) &&
  1548. target_channel < 14)
  1549. band = NL80211_BAND_5GHZ;
  1550. else
  1551. band = target_channel < 14 ? NL80211_BAND_2GHZ :
  1552. NL80211_BAND_5GHZ;
  1553. freq = ieee80211_channel_to_frequency(target_channel, band);
  1554. if (freq == 0) {
  1555. tdls_dbg(sdata, "Invalid channel in TDLS chan switch: %d\n",
  1556. target_channel);
  1557. return -EINVAL;
  1558. }
  1559. chan = ieee80211_get_channel(sdata->local->hw.wiphy, freq);
  1560. if (!chan) {
  1561. tdls_dbg(sdata,
  1562. "Unsupported channel for TDLS chan switch: %d\n",
  1563. target_channel);
  1564. return -EINVAL;
  1565. }
  1566. ieee802_11_parse_elems(tf->u.chan_switch_req.variable,
  1567. skb->len - baselen, false, &elems);
  1568. if (elems.parse_error) {
  1569. tdls_dbg(sdata, "Invalid IEs in TDLS channel switch req\n");
  1570. return -EINVAL;
  1571. }
  1572. if (!elems.ch_sw_timing || !elems.lnk_id) {
  1573. tdls_dbg(sdata, "TDLS channel switch req - missing IEs\n");
  1574. return -EINVAL;
  1575. }
  1576. if (!elems.sec_chan_offs) {
  1577. chan_type = NL80211_CHAN_HT20;
  1578. } else {
  1579. switch (elems.sec_chan_offs->sec_chan_offs) {
  1580. case IEEE80211_HT_PARAM_CHA_SEC_ABOVE:
  1581. chan_type = NL80211_CHAN_HT40PLUS;
  1582. break;
  1583. case IEEE80211_HT_PARAM_CHA_SEC_BELOW:
  1584. chan_type = NL80211_CHAN_HT40MINUS;
  1585. break;
  1586. default:
  1587. chan_type = NL80211_CHAN_HT20;
  1588. break;
  1589. }
  1590. }
  1591. cfg80211_chandef_create(&chandef, chan, chan_type);
  1592. /* we will be active on the TDLS link */
  1593. if (!cfg80211_reg_can_beacon_relax(sdata->local->hw.wiphy, &chandef,
  1594. sdata->wdev.iftype)) {
  1595. tdls_dbg(sdata, "TDLS chan switch to forbidden channel\n");
  1596. return -EINVAL;
  1597. }
  1598. mutex_lock(&local->sta_mtx);
  1599. sta = sta_info_get(sdata, tf->sa);
  1600. if (!sta || !test_sta_flag(sta, WLAN_STA_TDLS_PEER_AUTH)) {
  1601. tdls_dbg(sdata, "TDLS chan switch from non-peer sta %pM\n",
  1602. tf->sa);
  1603. ret = -EINVAL;
  1604. goto out;
  1605. }
  1606. params.sta = &sta->sta;
  1607. /* validate the initiator is set correctly */
  1608. local_initiator =
  1609. !memcmp(elems.lnk_id->init_sta, sdata->vif.addr, ETH_ALEN);
  1610. if (local_initiator == sta->sta.tdls_initiator) {
  1611. tdls_dbg(sdata, "TDLS chan switch invalid lnk-id initiator\n");
  1612. ret = -EINVAL;
  1613. goto out;
  1614. }
  1615. /* peer should have known better */
  1616. if (!sta->sta.ht_cap.ht_supported && elems.sec_chan_offs &&
  1617. elems.sec_chan_offs->sec_chan_offs) {
  1618. tdls_dbg(sdata, "TDLS chan switch - wide chan unsupported\n");
  1619. ret = -ENOTSUPP;
  1620. goto out;
  1621. }
  1622. params.chandef = &chandef;
  1623. params.switch_time = le16_to_cpu(elems.ch_sw_timing->switch_time);
  1624. params.switch_timeout = le16_to_cpu(elems.ch_sw_timing->switch_timeout);
  1625. params.tmpl_skb =
  1626. ieee80211_tdls_ch_sw_resp_tmpl_get(sta,
  1627. &params.ch_sw_tm_ie);
  1628. if (!params.tmpl_skb) {
  1629. ret = -ENOENT;
  1630. goto out;
  1631. }
  1632. drv_tdls_recv_channel_switch(sdata->local, sdata, &params);
  1633. tdls_dbg(sdata,
  1634. "TDLS ch switch request received from %pM ch %d width %d\n",
  1635. tf->sa, params.chandef->chan->center_freq,
  1636. params.chandef->width);
  1637. out:
  1638. mutex_unlock(&local->sta_mtx);
  1639. dev_kfree_skb_any(params.tmpl_skb);
  1640. return ret;
  1641. }
  1642. static void
  1643. ieee80211_process_tdls_channel_switch(struct ieee80211_sub_if_data *sdata,
  1644. struct sk_buff *skb)
  1645. {
  1646. struct ieee80211_tdls_data *tf = (void *)skb->data;
  1647. struct wiphy *wiphy = sdata->local->hw.wiphy;
  1648. ASSERT_RTNL();
  1649. /* make sure the driver supports it */
  1650. if (!(wiphy->features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
  1651. return;
  1652. /* we want to access the entire packet */
  1653. if (skb_linearize(skb))
  1654. return;
  1655. /*
  1656. * The packet/size was already validated by mac80211 Rx path, only look
  1657. * at the action type.
  1658. */
  1659. switch (tf->action_code) {
  1660. case WLAN_TDLS_CHANNEL_SWITCH_REQUEST:
  1661. ieee80211_process_tdls_channel_switch_req(sdata, skb);
  1662. break;
  1663. case WLAN_TDLS_CHANNEL_SWITCH_RESPONSE:
  1664. ieee80211_process_tdls_channel_switch_resp(sdata, skb);
  1665. break;
  1666. default:
  1667. WARN_ON_ONCE(1);
  1668. return;
  1669. }
  1670. }
  1671. void ieee80211_teardown_tdls_peers(struct ieee80211_sub_if_data *sdata)
  1672. {
  1673. struct sta_info *sta;
  1674. u16 reason = WLAN_REASON_TDLS_TEARDOWN_UNSPECIFIED;
  1675. rcu_read_lock();
  1676. list_for_each_entry_rcu(sta, &sdata->local->sta_list, list) {
  1677. if (!sta->sta.tdls || sta->sdata != sdata || !sta->uploaded ||
  1678. !test_sta_flag(sta, WLAN_STA_AUTHORIZED))
  1679. continue;
  1680. ieee80211_tdls_oper_request(&sdata->vif, sta->sta.addr,
  1681. NL80211_TDLS_TEARDOWN, reason,
  1682. GFP_ATOMIC);
  1683. }
  1684. rcu_read_unlock();
  1685. }
  1686. void ieee80211_tdls_chsw_work(struct work_struct *wk)
  1687. {
  1688. struct ieee80211_local *local =
  1689. container_of(wk, struct ieee80211_local, tdls_chsw_work);
  1690. struct ieee80211_sub_if_data *sdata;
  1691. struct sk_buff *skb;
  1692. struct ieee80211_tdls_data *tf;
  1693. rtnl_lock();
  1694. while ((skb = skb_dequeue(&local->skb_queue_tdls_chsw))) {
  1695. tf = (struct ieee80211_tdls_data *)skb->data;
  1696. list_for_each_entry(sdata, &local->interfaces, list) {
  1697. if (!ieee80211_sdata_running(sdata) ||
  1698. sdata->vif.type != NL80211_IFTYPE_STATION ||
  1699. !ether_addr_equal(tf->da, sdata->vif.addr))
  1700. continue;
  1701. ieee80211_process_tdls_channel_switch(sdata, skb);
  1702. break;
  1703. }
  1704. kfree_skb(skb);
  1705. }
  1706. rtnl_unlock();
  1707. }
  1708. void ieee80211_tdls_handle_disconnect(struct ieee80211_sub_if_data *sdata,
  1709. const u8 *peer, u16 reason)
  1710. {
  1711. struct ieee80211_sta *sta;
  1712. rcu_read_lock();
  1713. sta = ieee80211_find_sta(&sdata->vif, peer);
  1714. if (!sta || !sta->tdls) {
  1715. rcu_read_unlock();
  1716. return;
  1717. }
  1718. rcu_read_unlock();
  1719. tdls_dbg(sdata, "disconnected from TDLS peer %pM (Reason: %u=%s)\n",
  1720. peer, reason,
  1721. ieee80211_get_reason_code_string(reason));
  1722. ieee80211_tdls_oper_request(&sdata->vif, peer,
  1723. NL80211_TDLS_TEARDOWN,
  1724. WLAN_REASON_TDLS_TEARDOWN_UNREACHABLE,
  1725. GFP_ATOMIC);
  1726. }