mlme.c 120 KB
Newer Older
1 2
/*
 * BSS client mode implementation
3
 * Copyright 2003-2008, Jouni Malinen <j@w1.fi>
4 5 6 7 8 9 10 11 12 13
 * Copyright 2004, Instant802 Networks, Inc.
 * Copyright 2005, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
 * Copyright 2007, Michael Wu <flamingice@sourmilk.net>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

14
#include <linux/delay.h>
15 16 17 18
#include <linux/if_ether.h>
#include <linux/skbuff.h>
#include <linux/if_arp.h>
#include <linux/etherdevice.h>
19
#include <linux/moduleparam.h>
20
#include <linux/rtnetlink.h>
21
#include <linux/pm_qos.h>
22
#include <linux/crc32.h>
23
#include <linux/slab.h>
24
#include <linux/export.h>
25
#include <net/mac80211.h>
26
#include <asm/unaligned.h>
Johannes Berg's avatar
Johannes Berg committed
27

28
#include "ieee80211_i.h"
29
#include "driver-ops.h"
Johannes Berg's avatar
Johannes Berg committed
30 31
#include "rate.h"
#include "led.h"
32

33
#define IEEE80211_AUTH_TIMEOUT		(HZ / 5)
34
#define IEEE80211_AUTH_TIMEOUT_LONG	(HZ / 2)
35 36 37 38
#define IEEE80211_AUTH_TIMEOUT_SHORT	(HZ / 10)
#define IEEE80211_AUTH_MAX_TRIES	3
#define IEEE80211_AUTH_WAIT_ASSOC	(HZ * 5)
#define IEEE80211_ASSOC_TIMEOUT		(HZ / 5)
39
#define IEEE80211_ASSOC_TIMEOUT_LONG	(HZ / 2)
40 41
#define IEEE80211_ASSOC_TIMEOUT_SHORT	(HZ / 10)
#define IEEE80211_ASSOC_MAX_TRIES	3
Johannes Berg's avatar
Johannes Berg committed
42

43 44 45 46 47 48 49 50 51
static int max_nullfunc_tries = 2;
module_param(max_nullfunc_tries, int, 0644);
MODULE_PARM_DESC(max_nullfunc_tries,
		 "Maximum nullfunc tx tries before disconnecting (reason 4).");

static int max_probe_tries = 5;
module_param(max_probe_tries, int, 0644);
MODULE_PARM_DESC(max_probe_tries,
		 "Maximum probe tries before disconnecting (reason 4).");
52 53

/*
54 55 56 57 58 59
 * Beacon loss timeout is calculated as N frames times the
 * advertised beacon interval.  This may need to be somewhat
 * higher than what hardware might detect to account for
 * delays in the host processing frames. But since we also
 * probe on beacon miss before declaring the connection lost
 * default to what we want.
60
 */
61 62 63 64
static int beacon_loss_count = 7;
module_param(beacon_loss_count, int, 0644);
MODULE_PARM_DESC(beacon_loss_count,
		 "Number of beacon intervals before we decide beacon was lost.");
65

66 67 68 69
/*
 * Time the connection can be idle before we probe
 * it to see if we can still talk to the AP.
 */
70
#define IEEE80211_CONNECTION_IDLE_TIME	(30 * HZ)
71 72 73 74 75
/*
 * Time we wait for a probe response after sending
 * a probe request because of beacon loss or for
 * checking the connection still works.
 */
76 77 78 79 80
static int probe_wait_ms = 500;
module_param(probe_wait_ms, int, 0644);
MODULE_PARM_DESC(probe_wait_ms,
		 "Maximum time(ms) to wait for probe response"
		 " before disconnecting (reason 4).");
81

82 83 84 85 86 87 88
/*
 * Weight given to the latest Beacon frame when calculating average signal
 * strength for Beacon frames received in the current BSS. This must be
 * between 1 and 15.
 */
#define IEEE80211_SIGNAL_AVE_WEIGHT	3

89 90 91 92 93 94
/*
 * How many Beacon frames need to have been used in average signal strength
 * before starting to indicate signal change events.
 */
#define IEEE80211_SIGNAL_AVE_MIN_COUNT	4

Johannes Berg's avatar
Johannes Berg committed
95 96 97 98 99 100 101 102 103 104
/*
 * We can have multiple work items (and connection probing)
 * scheduling this timer, but we need to take care to only
 * reschedule it when it should fire _earlier_ than it was
 * asked for before, or if it's not pending right now. This
 * function ensures that. Note that it then is required to
 * run this function for all timeouts after the first one
 * has happened -- the work that runs from this timer will
 * do that.
 */
105 106
static void run_again(struct ieee80211_sub_if_data *sdata,
		      unsigned long timeout)
Johannes Berg's avatar
Johannes Berg committed
107
{
108
	sdata_assert_lock(sdata);
Johannes Berg's avatar
Johannes Berg committed
109

110 111 112
	if (!timer_pending(&sdata->u.mgd.timer) ||
	    time_before(timeout, sdata->u.mgd.timer.expires))
		mod_timer(&sdata->u.mgd.timer, timeout);
Johannes Berg's avatar
Johannes Berg committed
113 114
}

115
void ieee80211_sta_reset_beacon_monitor(struct ieee80211_sub_if_data *sdata)
116
{
117
	if (sdata->vif.driver_flags & IEEE80211_VIF_BEACON_FILTER)
118 119
		return;

120 121 122
	if (sdata->local->hw.flags & IEEE80211_HW_CONNECTION_MONITOR)
		return;

123
	mod_timer(&sdata->u.mgd.bcn_mon_timer,
124
		  round_jiffies_up(jiffies + sdata->u.mgd.beacon_timeout));
125 126
}

127 128
void ieee80211_sta_reset_conn_monitor(struct ieee80211_sub_if_data *sdata)
{
129 130
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;

131 132 133
	if (unlikely(!sdata->u.mgd.associated))
		return;

134 135 136 137 138
	if (sdata->local->hw.flags & IEEE80211_HW_CONNECTION_MONITOR)
		return;

	mod_timer(&sdata->u.mgd.conn_mon_timer,
		  round_jiffies_up(jiffies + IEEE80211_CONNECTION_IDLE_TIME));
139 140

	ifmgd->probe_send_count = 0;
141 142
}

143
static int ecw2cw(int ecw)
Johannes Berg's avatar
Johannes Berg committed
144
{
145
	return (1 << ecw) - 1;
Johannes Berg's avatar
Johannes Berg committed
146 147
}

148 149 150 151 152 153
static u32
ieee80211_determine_chantype(struct ieee80211_sub_if_data *sdata,
			     struct ieee80211_supported_band *sband,
			     struct ieee80211_channel *channel,
			     const struct ieee80211_ht_operation *ht_oper,
			     const struct ieee80211_vht_operation *vht_oper,
154
			     struct cfg80211_chan_def *chandef, bool tracking)
155
{
156
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174
	struct cfg80211_chan_def vht_chandef;
	u32 ht_cfreq, ret;

	chandef->chan = channel;
	chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
	chandef->center_freq1 = channel->center_freq;
	chandef->center_freq2 = 0;

	if (!ht_oper || !sband->ht_cap.ht_supported) {
		ret = IEEE80211_STA_DISABLE_HT | IEEE80211_STA_DISABLE_VHT;
		goto out;
	}

	chandef->width = NL80211_CHAN_WIDTH_20;

	ht_cfreq = ieee80211_channel_to_frequency(ht_oper->primary_chan,
						  channel->band);
	/* check that channel matches the right operating channel */
175
	if (!tracking && channel->center_freq != ht_cfreq) {
176 177 178 179 180 181 182
		/*
		 * It's possible that some APs are confused here;
		 * Netgear WNDR3700 sometimes reports 4 higher than
		 * the actual channel in association responses, but
		 * since we look at probe response/beacon data here
		 * it should be OK.
		 */
183 184 185 186
		sdata_info(sdata,
			   "Wrong control channel: center-freq: %d ht-cfreq: %d ht->primary_chan: %d band: %d - Disabling HT\n",
			   channel->center_freq, ht_cfreq,
			   ht_oper->primary_chan, channel->band);
187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205
		ret = IEEE80211_STA_DISABLE_HT | IEEE80211_STA_DISABLE_VHT;
		goto out;
	}

	/* check 40 MHz support, if we have it */
	if (sband->ht_cap.cap & IEEE80211_HT_CAP_SUP_WIDTH_20_40) {
		switch (ht_oper->ht_param & IEEE80211_HT_PARAM_CHA_SEC_OFFSET) {
		case IEEE80211_HT_PARAM_CHA_SEC_ABOVE:
			chandef->width = NL80211_CHAN_WIDTH_40;
			chandef->center_freq1 += 10;
			break;
		case IEEE80211_HT_PARAM_CHA_SEC_BELOW:
			chandef->width = NL80211_CHAN_WIDTH_40;
			chandef->center_freq1 -= 10;
			break;
		}
	} else {
		/* 40 MHz (and 80 MHz) must be supported for VHT */
		ret = IEEE80211_STA_DISABLE_VHT;
206 207
		/* also mark 40 MHz disabled */
		ret |= IEEE80211_STA_DISABLE_40MHZ;
208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233
		goto out;
	}

	if (!vht_oper || !sband->vht_cap.vht_supported) {
		ret = IEEE80211_STA_DISABLE_VHT;
		goto out;
	}

	vht_chandef.chan = channel;
	vht_chandef.center_freq1 =
		ieee80211_channel_to_frequency(vht_oper->center_freq_seg1_idx,
					       channel->band);
	vht_chandef.center_freq2 = 0;

	switch (vht_oper->chan_width) {
	case IEEE80211_VHT_CHANWIDTH_USE_HT:
		vht_chandef.width = chandef->width;
		break;
	case IEEE80211_VHT_CHANWIDTH_80MHZ:
		vht_chandef.width = NL80211_CHAN_WIDTH_80;
		break;
	case IEEE80211_VHT_CHANWIDTH_160MHZ:
		vht_chandef.width = NL80211_CHAN_WIDTH_160;
		break;
	case IEEE80211_VHT_CHANWIDTH_80P80MHZ:
		vht_chandef.width = NL80211_CHAN_WIDTH_80P80;
234 235 236 237
		vht_chandef.center_freq2 =
			ieee80211_channel_to_frequency(
				vht_oper->center_freq_seg2_idx,
				channel->band);
238 239
		break;
	default:
240
		if (!(ifmgd->flags & IEEE80211_STA_DISABLE_VHT))
241 242 243
			sdata_info(sdata,
				   "AP VHT operation IE has invalid channel width (%d), disable VHT\n",
				   vht_oper->chan_width);
244 245 246 247 248
		ret = IEEE80211_STA_DISABLE_VHT;
		goto out;
	}

	if (!cfg80211_chandef_valid(&vht_chandef)) {
249
		if (!(ifmgd->flags & IEEE80211_STA_DISABLE_VHT))
250 251
			sdata_info(sdata,
				   "AP VHT information is invalid, disable VHT\n");
252 253 254 255 256 257 258 259 260 261
		ret = IEEE80211_STA_DISABLE_VHT;
		goto out;
	}

	if (cfg80211_chandef_identical(chandef, &vht_chandef)) {
		ret = 0;
		goto out;
	}

	if (!cfg80211_chandef_compatible(chandef, &vht_chandef)) {
262
		if (!(ifmgd->flags & IEEE80211_STA_DISABLE_VHT))
263 264
			sdata_info(sdata,
				   "AP VHT information doesn't match HT, disable VHT\n");
265 266 267 268 269 270 271 272 273
		ret = IEEE80211_STA_DISABLE_VHT;
		goto out;
	}

	*chandef = vht_chandef;

	ret = 0;

out:
274 275 276 277
	/* don't print the message below for VHT mismatch if VHT is disabled */
	if (ret & IEEE80211_STA_DISABLE_VHT)
		vht_chandef = *chandef;

278 279 280 281 282 283 284 285
	/*
	 * Ignore the DISABLED flag when we're already connected and only
	 * tracking the APs beacon for bandwidth changes - otherwise we
	 * might get disconnected here if we connect to an AP, update our
	 * regulatory information based on the AP's country IE and the
	 * information we have is wrong/outdated and disables the channel
	 * that we're actually using for the connection to the AP.
	 */
286
	while (!cfg80211_chandef_usable(sdata->local->hw.wiphy, chandef,
287 288
					tracking ? 0 :
						   IEEE80211_CHAN_DISABLED)) {
289 290 291
		if (WARN_ON(chandef->width == NL80211_CHAN_WIDTH_20_NOHT)) {
			ret = IEEE80211_STA_DISABLE_HT |
			      IEEE80211_STA_DISABLE_VHT;
292
			break;
293 294
		}

295
		ret |= ieee80211_chandef_downgrade(chandef);
296 297
	}

298
	if (chandef->width != vht_chandef.width && !tracking)
299 300 301 302 303 304 305
		sdata_info(sdata,
			   "capabilities/regulatory prevented using AP HT/VHT configuration, downgraded\n");

	WARN_ON_ONCE(!cfg80211_chandef_valid(chandef));
	return ret;
}

306 307 308 309 310
static int ieee80211_config_bw(struct ieee80211_sub_if_data *sdata,
			       struct sta_info *sta,
			       const struct ieee80211_ht_operation *ht_oper,
			       const struct ieee80211_vht_operation *vht_oper,
			       const u8 *bssid, u32 *changed)
311 312
{
	struct ieee80211_local *local = sdata->local;
313
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
314
	struct ieee80211_supported_band *sband;
Johannes Berg's avatar
Johannes Berg committed
315
	struct ieee80211_channel *chan;
316
	struct cfg80211_chan_def chandef;
317
	u16 ht_opmode;
318 319 320
	u32 flags;
	enum ieee80211_sta_rx_bandwidth new_sta_bw;
	int ret;
321

322 323
	/* if HT was/is disabled, don't track any bandwidth changes */
	if (ifmgd->flags & IEEE80211_STA_DISABLE_HT || !ht_oper)
324 325
		return 0;

326 327 328 329 330 331 332
	/* don't check VHT if we associated as non-VHT station */
	if (ifmgd->flags & IEEE80211_STA_DISABLE_VHT)
		vht_oper = NULL;

	if (WARN_ON_ONCE(!sta))
		return -EINVAL;

333
	chan = sdata->vif.bss_conf.chandef.chan;
Johannes Berg's avatar
Johannes Berg committed
334
	sband = local->hw.wiphy->bands[chan->band];
335

336 337
	/* calculate new channel (type) based on HT/VHT operation IEs */
	flags = ieee80211_determine_chantype(sdata, sband, chan, ht_oper,
338
					     vht_oper, &chandef, true);
339 340 341 342 343 344 345 346 347 348

	/*
	 * Downgrade the new channel if we associated with restricted
	 * capabilities. For example, if we associated as a 20 MHz STA
	 * to a 40 MHz AP (due to regulatory, capabilities or config
	 * reasons) then switching to a 40 MHz channel now won't do us
	 * any good -- we couldn't use it with the AP.
	 */
	if (ifmgd->flags & IEEE80211_STA_DISABLE_80P80MHZ &&
	    chandef.width == NL80211_CHAN_WIDTH_80P80)
349
		flags |= ieee80211_chandef_downgrade(&chandef);
350 351
	if (ifmgd->flags & IEEE80211_STA_DISABLE_160MHZ &&
	    chandef.width == NL80211_CHAN_WIDTH_160)
352
		flags |= ieee80211_chandef_downgrade(&chandef);
353 354
	if (ifmgd->flags & IEEE80211_STA_DISABLE_40MHZ &&
	    chandef.width > NL80211_CHAN_WIDTH_20)
355
		flags |= ieee80211_chandef_downgrade(&chandef);
356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381

	if (cfg80211_chandef_identical(&chandef, &sdata->vif.bss_conf.chandef))
		return 0;

	sdata_info(sdata,
		   "AP %pM changed bandwidth, new config is %d MHz, width %d (%d/%d MHz)\n",
		   ifmgd->bssid, chandef.chan->center_freq, chandef.width,
		   chandef.center_freq1, chandef.center_freq2);

	if (flags != (ifmgd->flags & (IEEE80211_STA_DISABLE_HT |
				      IEEE80211_STA_DISABLE_VHT |
				      IEEE80211_STA_DISABLE_40MHZ |
				      IEEE80211_STA_DISABLE_80P80MHZ |
				      IEEE80211_STA_DISABLE_160MHZ)) ||
	    !cfg80211_chandef_valid(&chandef)) {
		sdata_info(sdata,
			   "AP %pM changed bandwidth in a way we can't support - disconnect\n",
			   ifmgd->bssid);
		return -EINVAL;
	}

	switch (chandef.width) {
	case NL80211_CHAN_WIDTH_20_NOHT:
	case NL80211_CHAN_WIDTH_20:
		new_sta_bw = IEEE80211_STA_RX_BW_20;
		break;
382
	case NL80211_CHAN_WIDTH_40:
383
		new_sta_bw = IEEE80211_STA_RX_BW_40;
384
		break;
385 386 387 388 389 390
	case NL80211_CHAN_WIDTH_80:
		new_sta_bw = IEEE80211_STA_RX_BW_80;
		break;
	case NL80211_CHAN_WIDTH_80P80:
	case NL80211_CHAN_WIDTH_160:
		new_sta_bw = IEEE80211_STA_RX_BW_160;
391
		break;
392 393
	default:
		return -EINVAL;
394
	}
395

396 397
	if (new_sta_bw > sta->cur_max_bandwidth)
		new_sta_bw = sta->cur_max_bandwidth;
398

399 400 401 402 403
	if (new_sta_bw < sta->sta.bandwidth) {
		sta->sta.bandwidth = new_sta_bw;
		rate_control_rate_update(local, sband, sta,
					 IEEE80211_RC_BW_CHANGED);
	}
404

405 406 407 408 409 410 411
	ret = ieee80211_vif_change_bandwidth(sdata, &chandef, changed);
	if (ret) {
		sdata_info(sdata,
			   "AP %pM changed bandwidth to incompatible one - disconnect\n",
			   ifmgd->bssid);
		return ret;
	}
412

413 414 415 416
	if (new_sta_bw > sta->sta.bandwidth) {
		sta->sta.bandwidth = new_sta_bw;
		rate_control_rate_update(local, sband, sta,
					 IEEE80211_RC_BW_CHANGED);
417
	}
418

419
	ht_opmode = le16_to_cpu(ht_oper->operation_mode);
420 421

	/* if bss configuration changed store the new one */
422 423
	if (sdata->vif.bss_conf.ht_operation_mode != ht_opmode) {
		*changed |= BSS_CHANGED_HT;
424
		sdata->vif.bss_conf.ht_operation_mode = ht_opmode;
425 426
	}

427
	return 0;
428 429
}

430 431
/* frame sending functions */

Johannes Berg's avatar
Johannes Berg committed
432
static void ieee80211_add_ht_ie(struct ieee80211_sub_if_data *sdata,
433
				struct sk_buff *skb, u8 ap_ht_param,
Johannes Berg's avatar
Johannes Berg committed
434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450
				struct ieee80211_supported_band *sband,
				struct ieee80211_channel *channel,
				enum ieee80211_smps_mode smps)
{
	u8 *pos;
	u32 flags = channel->flags;
	u16 cap;
	struct ieee80211_sta_ht_cap ht_cap;

	BUILD_BUG_ON(sizeof(ht_cap) != sizeof(sband->ht_cap));

	memcpy(&ht_cap, &sband->ht_cap, sizeof(ht_cap));
	ieee80211_apply_htcap_overrides(sdata, &ht_cap);

	/* determine capability flags */
	cap = ht_cap.cap;

451
	switch (ap_ht_param & IEEE80211_HT_PARAM_CHA_SEC_OFFSET) {
Johannes Berg's avatar
Johannes Berg committed
452 453 454 455 456 457 458 459 460 461 462 463 464 465
	case IEEE80211_HT_PARAM_CHA_SEC_ABOVE:
		if (flags & IEEE80211_CHAN_NO_HT40PLUS) {
			cap &= ~IEEE80211_HT_CAP_SUP_WIDTH_20_40;
			cap &= ~IEEE80211_HT_CAP_SGI_40;
		}
		break;
	case IEEE80211_HT_PARAM_CHA_SEC_BELOW:
		if (flags & IEEE80211_CHAN_NO_HT40MINUS) {
			cap &= ~IEEE80211_HT_CAP_SUP_WIDTH_20_40;
			cap &= ~IEEE80211_HT_CAP_SGI_40;
		}
		break;
	}

466 467 468 469 470 471 472 473 474 475
	/*
	 * If 40 MHz was disabled associate as though we weren't
	 * capable of 40 MHz -- some broken APs will never fall
	 * back to trying to transmit in 20 MHz.
	 */
	if (sdata->u.mgd.flags & IEEE80211_STA_DISABLE_40MHZ) {
		cap &= ~IEEE80211_HT_CAP_SUP_WIDTH_20_40;
		cap &= ~IEEE80211_HT_CAP_SGI_40;
	}

Johannes Berg's avatar
Johannes Berg committed
476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500
	/* set SM PS mode properly */
	cap &= ~IEEE80211_HT_CAP_SM_PS;
	switch (smps) {
	case IEEE80211_SMPS_AUTOMATIC:
	case IEEE80211_SMPS_NUM_MODES:
		WARN_ON(1);
	case IEEE80211_SMPS_OFF:
		cap |= WLAN_HT_CAP_SM_PS_DISABLED <<
			IEEE80211_HT_CAP_SM_PS_SHIFT;
		break;
	case IEEE80211_SMPS_STATIC:
		cap |= WLAN_HT_CAP_SM_PS_STATIC <<
			IEEE80211_HT_CAP_SM_PS_SHIFT;
		break;
	case IEEE80211_SMPS_DYNAMIC:
		cap |= WLAN_HT_CAP_SM_PS_DYNAMIC <<
			IEEE80211_HT_CAP_SM_PS_SHIFT;
		break;
	}

	/* reserve and fill IE */
	pos = skb_put(skb, sizeof(struct ieee80211_ht_cap) + 2);
	ieee80211_ie_build_ht_cap(pos, &ht_cap, cap);
}

501 502
static void ieee80211_add_vht_ie(struct ieee80211_sub_if_data *sdata,
				 struct sk_buff *skb,
503 504
				 struct ieee80211_supported_band *sband,
				 struct ieee80211_vht_cap *ap_vht_cap)
505 506 507 508 509 510 511 512
{
	u8 *pos;
	u32 cap;
	struct ieee80211_sta_vht_cap vht_cap;

	BUILD_BUG_ON(sizeof(vht_cap) != sizeof(sband->vht_cap));

	memcpy(&vht_cap, &sband->vht_cap, sizeof(vht_cap));
513
	ieee80211_apply_vhtcap_overrides(sdata, &vht_cap);
514 515 516 517

	/* determine capability flags */
	cap = vht_cap.cap;

518 519 520 521 522 523 524 525 526 527
	if (sdata->u.mgd.flags & IEEE80211_STA_DISABLE_80P80MHZ) {
		cap &= ~IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_160_80PLUS80MHZ;
		cap |= IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_160MHZ;
	}

	if (sdata->u.mgd.flags & IEEE80211_STA_DISABLE_160MHZ) {
		cap &= ~IEEE80211_VHT_CAP_SHORT_GI_160;
		cap &= ~IEEE80211_VHT_CAP_SUPP_CHAN_WIDTH_160MHZ;
	}

528 529 530 531 532 533 534 535
	/*
	 * Some APs apparently get confused if our capabilities are better
	 * than theirs, so restrict what we advertise in the assoc request.
	 */
	if (!(ap_vht_cap->vht_cap_info &
			cpu_to_le32(IEEE80211_VHT_CAP_SU_BEAMFORMER_CAPABLE)))
		cap &= ~IEEE80211_VHT_CAP_SU_BEAMFORMEE_CAPABLE;

536
	/* reserve and fill IE */
537
	pos = skb_put(skb, sizeof(struct ieee80211_vht_cap) + 2);
538 539 540
	ieee80211_ie_build_vht_cap(pos, &vht_cap, cap);
}

Johannes Berg's avatar
Johannes Berg committed
541 542 543 544 545 546 547 548 549
static void ieee80211_send_assoc(struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
	struct ieee80211_mgd_assoc_data *assoc_data = ifmgd->assoc_data;
	struct sk_buff *skb;
	struct ieee80211_mgmt *mgmt;
	u8 *pos, qos_info;
	size_t offset = 0, noffset;
550
	int i, count, rates_len, supp_rates_len, shift;
Johannes Berg's avatar
Johannes Berg committed
551 552
	u16 capab;
	struct ieee80211_supported_band *sband;
Johannes Berg's avatar
Johannes Berg committed
553 554
	struct ieee80211_chanctx_conf *chanctx_conf;
	struct ieee80211_channel *chan;
555
	u32 rate_flags, rates = 0;
Johannes Berg's avatar
Johannes Berg committed
556

557
	sdata_assert_lock(sdata);
Johannes Berg's avatar
Johannes Berg committed
558

Johannes Berg's avatar
Johannes Berg committed
559 560 561 562 563 564
	rcu_read_lock();
	chanctx_conf = rcu_dereference(sdata->vif.chanctx_conf);
	if (WARN_ON(!chanctx_conf)) {
		rcu_read_unlock();
		return;
	}
565
	chan = chanctx_conf->def.chan;
566
	rate_flags = ieee80211_chandef_rate_flags(&chanctx_conf->def);
Johannes Berg's avatar
Johannes Berg committed
567 568
	rcu_read_unlock();
	sband = local->hw.wiphy->bands[chan->band];
569
	shift = ieee80211_vif_get_shift(&sdata->vif);
Johannes Berg's avatar
Johannes Berg committed
570 571 572 573 574 575 576 577

	if (assoc_data->supp_rates_len) {
		/*
		 * Get all rates supported by the device and the AP as
		 * some APs don't like getting a superset of their rates
		 * in the association request (e.g. D-Link DAP 1353 in
		 * b-only mode)...
		 */
578 579 580 581
		rates_len = ieee80211_parse_bitrates(&chanctx_conf->def, sband,
						     assoc_data->supp_rates,
						     assoc_data->supp_rates_len,
						     &rates);
Johannes Berg's avatar
Johannes Berg committed
582 583 584 585 586 587
	} else {
		/*
		 * In case AP not provide any supported rates information
		 * before association, we send information element(s) with
		 * all rates that we support.
		 */
588 589 590 591 592 593 594 595
		rates_len = 0;
		for (i = 0; i < sband->n_bitrates; i++) {
			if ((rate_flags & sband->bitrates[i].flags)
			    != rate_flags)
				continue;
			rates |= BIT(i);
			rates_len++;
		}
Johannes Berg's avatar
Johannes Berg committed
596 597 598 599 600 601 602 603 604
	}

	skb = alloc_skb(local->hw.extra_tx_headroom +
			sizeof(*mgmt) + /* bit too much but doesn't matter */
			2 + assoc_data->ssid_len + /* SSID */
			4 + rates_len + /* (extended) rates */
			4 + /* power capability */
			2 + 2 * sband->n_channels + /* supported channels */
			2 + sizeof(struct ieee80211_ht_cap) + /* HT */
605
			2 + sizeof(struct ieee80211_vht_cap) + /* VHT */
Johannes Berg's avatar
Johannes Berg committed
606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671
			assoc_data->ie_len + /* extra IEs */
			9, /* WMM */
			GFP_KERNEL);
	if (!skb)
		return;

	skb_reserve(skb, local->hw.extra_tx_headroom);

	capab = WLAN_CAPABILITY_ESS;

	if (sband->band == IEEE80211_BAND_2GHZ) {
		if (!(local->hw.flags & IEEE80211_HW_2GHZ_SHORT_SLOT_INCAPABLE))
			capab |= WLAN_CAPABILITY_SHORT_SLOT_TIME;
		if (!(local->hw.flags & IEEE80211_HW_2GHZ_SHORT_PREAMBLE_INCAPABLE))
			capab |= WLAN_CAPABILITY_SHORT_PREAMBLE;
	}

	if (assoc_data->capability & WLAN_CAPABILITY_PRIVACY)
		capab |= WLAN_CAPABILITY_PRIVACY;

	if ((assoc_data->capability & WLAN_CAPABILITY_SPECTRUM_MGMT) &&
	    (local->hw.flags & IEEE80211_HW_SPECTRUM_MGMT))
		capab |= WLAN_CAPABILITY_SPECTRUM_MGMT;

	mgmt = (struct ieee80211_mgmt *) skb_put(skb, 24);
	memset(mgmt, 0, 24);
	memcpy(mgmt->da, assoc_data->bss->bssid, ETH_ALEN);
	memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
	memcpy(mgmt->bssid, assoc_data->bss->bssid, ETH_ALEN);

	if (!is_zero_ether_addr(assoc_data->prev_bssid)) {
		skb_put(skb, 10);
		mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
						  IEEE80211_STYPE_REASSOC_REQ);
		mgmt->u.reassoc_req.capab_info = cpu_to_le16(capab);
		mgmt->u.reassoc_req.listen_interval =
				cpu_to_le16(local->hw.conf.listen_interval);
		memcpy(mgmt->u.reassoc_req.current_ap, assoc_data->prev_bssid,
		       ETH_ALEN);
	} else {
		skb_put(skb, 4);
		mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
						  IEEE80211_STYPE_ASSOC_REQ);
		mgmt->u.assoc_req.capab_info = cpu_to_le16(capab);
		mgmt->u.assoc_req.listen_interval =
				cpu_to_le16(local->hw.conf.listen_interval);
	}

	/* SSID */
	pos = skb_put(skb, 2 + assoc_data->ssid_len);
	*pos++ = WLAN_EID_SSID;
	*pos++ = assoc_data->ssid_len;
	memcpy(pos, assoc_data->ssid, assoc_data->ssid_len);

	/* add all rates which were marked to be used above */
	supp_rates_len = rates_len;
	if (supp_rates_len > 8)
		supp_rates_len = 8;

	pos = skb_put(skb, supp_rates_len + 2);
	*pos++ = WLAN_EID_SUPP_RATES;
	*pos++ = supp_rates_len;

	count = 0;
	for (i = 0; i < sband->n_bitrates; i++) {
		if (BIT(i) & rates) {
672 673 674
			int rate = DIV_ROUND_UP(sband->bitrates[i].bitrate,
						5 * (1 << shift));
			*pos++ = (u8) rate;
Johannes Berg's avatar
Johannes Berg committed
675 676 677 678 679 680 681 682 683 684 685 686
			if (++count == 8)
				break;
		}
	}

	if (rates_len > count) {
		pos = skb_put(skb, rates_len - count + 2);
		*pos++ = WLAN_EID_EXT_SUPP_RATES;
		*pos++ = rates_len - count;

		for (i++; i < sband->n_bitrates; i++) {
			if (BIT(i) & rates) {
687 688 689 690
				int rate;
				rate = DIV_ROUND_UP(sband->bitrates[i].bitrate,
						    5 * (1 << shift));
				*pos++ = (u8) rate;
Johannes Berg's avatar
Johannes Berg committed
691 692 693 694 695 696 697 698 699 700
			}
		}
	}

	if (capab & WLAN_CAPABILITY_SPECTRUM_MGMT) {
		/* 1. power capabilities */
		pos = skb_put(skb, 4);
		*pos++ = WLAN_EID_PWR_CAPABILITY;
		*pos++ = 2;
		*pos++ = 0; /* min tx power */
701 702
		 /* max tx power */
		*pos++ = ieee80211_chandef_max_power(&chanctx_conf->def);
Johannes Berg's avatar
Johannes Berg committed
703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737

		/* 2. supported channels */
		/* TODO: get this in reg domain format */
		pos = skb_put(skb, 2 * sband->n_channels + 2);
		*pos++ = WLAN_EID_SUPPORTED_CHANNELS;
		*pos++ = 2 * sband->n_channels;
		for (i = 0; i < sband->n_channels; i++) {
			*pos++ = ieee80211_frequency_to_channel(
					sband->channels[i].center_freq);
			*pos++ = 1; /* one channel in the subband*/
		}
	}

	/* if present, add any custom IEs that go before HT */
	if (assoc_data->ie_len && assoc_data->ie) {
		static const u8 before_ht[] = {
			WLAN_EID_SSID,
			WLAN_EID_SUPP_RATES,
			WLAN_EID_EXT_SUPP_RATES,
			WLAN_EID_PWR_CAPABILITY,
			WLAN_EID_SUPPORTED_CHANNELS,
			WLAN_EID_RSN,
			WLAN_EID_QOS_CAPA,
			WLAN_EID_RRM_ENABLED_CAPABILITIES,
			WLAN_EID_MOBILITY_DOMAIN,
			WLAN_EID_SUPPORTED_REGULATORY_CLASSES,
		};
		noffset = ieee80211_ie_split(assoc_data->ie, assoc_data->ie_len,
					     before_ht, ARRAY_SIZE(before_ht),
					     offset);
		pos = skb_put(skb, noffset - offset);
		memcpy(pos, assoc_data->ie + offset, noffset - offset);
		offset = noffset;
	}

738 739 740 741
	if (WARN_ON_ONCE((ifmgd->flags & IEEE80211_STA_DISABLE_HT) &&
			 !(ifmgd->flags & IEEE80211_STA_DISABLE_VHT)))
		ifmgd->flags |= IEEE80211_STA_DISABLE_VHT;

742
	if (!(ifmgd->flags & IEEE80211_STA_DISABLE_HT))
743
		ieee80211_add_ht_ie(sdata, skb, assoc_data->ap_ht_param,
744
				    sband, chan, sdata->smps_mode);
Johannes Berg's avatar
Johannes Berg committed
745

746
	if (!(ifmgd->flags & IEEE80211_STA_DISABLE_VHT))
747 748
		ieee80211_add_vht_ie(sdata, skb, sband,
				     &assoc_data->ap_vht_cap);
749

Johannes Berg's avatar
Johannes Berg committed
750 751 752 753 754 755 756 757 758 759
	/* if present, add any custom non-vendor IEs that go after HT */
	if (assoc_data->ie_len && assoc_data->ie) {
		noffset = ieee80211_ie_split_vendor(assoc_data->ie,
						    assoc_data->ie_len,
						    offset);
		pos = skb_put(skb, noffset - offset);
		memcpy(pos, assoc_data->ie + offset, noffset - offset);
		offset = noffset;
	}

760 761
	if (assoc_data->wmm) {
		if (assoc_data->uapsd) {
762 763
			qos_info = ifmgd->uapsd_queues;
			qos_info |= (ifmgd->uapsd_max_sp_len <<
Johannes Berg's avatar
Johannes Berg committed
764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787
				     IEEE80211_WMM_IE_STA_QOSINFO_SP_SHIFT);
		} else {
			qos_info = 0;
		}

		pos = skb_put(skb, 9);
		*pos++ = WLAN_EID_VENDOR_SPECIFIC;
		*pos++ = 7; /* len */
		*pos++ = 0x00; /* Microsoft OUI 00:50:F2 */
		*pos++ = 0x50;
		*pos++ = 0xf2;
		*pos++ = 2; /* WME */
		*pos++ = 0; /* WME info */
		*pos++ = 1; /* WME ver */
		*pos++ = qos_info;
	}

	/* add any remaining custom (i.e. vendor specific here) IEs */
	if (assoc_data->ie_len && assoc_data->ie) {
		noffset = assoc_data->ie_len;
		pos = skb_put(skb, noffset - offset);
		memcpy(pos, assoc_data->ie + offset, noffset - offset);
	}

Johannes Berg's avatar
Johannes Berg committed
788 789
	drv_mgd_prepare_tx(local, sdata);

Johannes Berg's avatar
Johannes Berg committed
790
	IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT;
791 792 793
	if (local->hw.flags & IEEE80211_HW_REPORTS_TX_ACK_STATUS)
		IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_CTL_REQ_TX_STATUS |
						IEEE80211_TX_INTFL_MLME_CONN_TX;
Johannes Berg's avatar
Johannes Berg committed
794 795 796
	ieee80211_tx_skb(sdata, skb);
}

797 798 799 800 801 802
void ieee80211_send_pspoll(struct ieee80211_local *local,
			   struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_pspoll *pspoll;
	struct sk_buff *skb;

803 804
	skb = ieee80211_pspoll_get(&local->hw, &sdata->vif);
	if (!skb)
805 806
		return;

807 808
	pspoll = (struct ieee80211_pspoll *) skb->data;
	pspoll->frame_control |= cpu_to_le16(IEEE80211_FCTL_PM);
809

810 811
	IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT;
	ieee80211_tx_skb(sdata, skb);
812 813
}

814 815 816 817 818
void ieee80211_send_nullfunc(struct ieee80211_local *local,
			     struct ieee80211_sub_if_data *sdata,
			     int powersave)
{
	struct sk_buff *skb;
819
	struct ieee80211_hdr_3addr *nullfunc;
820
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
821

822 823
	skb = ieee80211_nullfunc_get(&local->hw, &sdata->vif);
	if (!skb)
824 825
		return;

826
	nullfunc = (struct ieee80211_hdr_3addr *) skb->data;
827
	if (powersave)
828
		nullfunc->frame_control |= cpu_to_le16(IEEE80211_FCTL_PM);
829

830 831
	IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT |
					IEEE80211_TX_INTFL_OFFCHAN_TX_OK;
832 833 834 835

	if (local->hw.flags & IEEE80211_HW_REPORTS_TX_ACK_STATUS)
		IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_CTL_REQ_TX_STATUS;

836
	if (ifmgd->flags & IEEE80211_STA_CONNECTION_POLL)
837 838
		IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_CTL_USE_MINRATE;

839
	ieee80211_tx_skb(sdata, skb);
840 841
}

842 843 844 845 846 847 848 849 850 851 852
static void ieee80211_send_4addr_nullfunc(struct ieee80211_local *local,
					  struct ieee80211_sub_if_data *sdata)
{
	struct sk_buff *skb;
	struct ieee80211_hdr *nullfunc;
	__le16 fc;

	if (WARN_ON(sdata->vif.type != NL80211_IFTYPE_STATION))
		return;

	skb = dev_alloc_skb(local->hw.extra_tx_headroom + 30);
853
	if (!skb)
854
		return;
855

856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871
	skb_reserve(skb, local->hw.extra_tx_headroom);

	nullfunc = (struct ieee80211_hdr *) skb_put(skb, 30);
	memset(nullfunc, 0, 30);
	fc = cpu_to_le16(IEEE80211_FTYPE_DATA | IEEE80211_STYPE_NULLFUNC |
			 IEEE80211_FCTL_FROMDS | IEEE80211_FCTL_TODS);
	nullfunc->frame_control = fc;
	memcpy(nullfunc->addr1, sdata->u.mgd.bssid, ETH_ALEN);
	memcpy(nullfunc->addr2, sdata->vif.addr, ETH_ALEN);
	memcpy(nullfunc->addr3, sdata->u.mgd.bssid, ETH_ALEN);
	memcpy(nullfunc->addr4, sdata->vif.addr, ETH_ALEN);

	IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT;
	ieee80211_tx_skb(sdata, skb);
}

872 873 874 875 876
/* spectrum management related things */
static void ieee80211_chswitch_work(struct work_struct *work)
{
	struct ieee80211_sub_if_data *sdata =
		container_of(work, struct ieee80211_sub_if_data, u.mgd.chswitch_work);
877
	struct ieee80211_local *local = sdata->local;
878
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
879 880
	u32 changed = 0;
	int ret;
881

882
	if (!ieee80211_sdata_running(sdata))
883 884
		return;

885
	sdata_lock(sdata);
886 887
	if (!ifmgd->associated)
		goto out;
888

889 890 891 892 893 894 895 896 897
	ret = ieee80211_vif_change_channel(sdata, &local->csa_chandef,
					   &changed);
	if (ret) {
		sdata_info(sdata,
			   "vif channel switch failed, disconnecting\n");
		ieee80211_queue_work(&sdata->local->hw,
				     &ifmgd->csa_connection_drop_work);
		goto out;
	}
898

899 900 901 902 903 904 905 906 907
	if (!local->use_chanctx) {
		local->_oper_chandef = local->csa_chandef;
		/* Call "hw_config" only if doing sw channel switch.
		 * Otherwise update the channel directly
		 */
		if (!local->ops->channel_switch)
			ieee80211_hw_config(local, 0);
		else
			local->hw.conf.chandef = local->_oper_chandef;
908
	}
909

910
	/* XXX: shouldn't really modify cfg80211-owned data! */
911
	ifmgd->associated->channel = local->csa_chandef.chan;
912

913
	/* XXX: wait for a beacon first? */
914
	ieee80211_wake_queues_by_reason(&local->hw,
915
					IEEE80211_MAX_QUEUE_MAP,
916
					IEEE80211_QUEUE_STOP_REASON_CSA);
917 918 919

	ieee80211_bss_info_change_notify(sdata, changed);

920
 out:
921
	sdata->vif.csa_active = false;
922
	ifmgd->flags &= ~IEEE80211_STA_CSA_RECEIVED;
923
	sdata_unlock(sdata);
924 925
}

926 927
void ieee80211_chswitch_done(struct ieee80211_vif *vif, bool success)
{
Johannes Berg's avatar
Johannes Berg committed
928 929
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
930 931 932

	trace_api_chswitch_done(sdata, success);
	if (!success) {
933 934 935 936 937 938
		sdata_info(sdata,
			   "driver channel switch failed, disconnecting\n");
		ieee80211_queue_work(&sdata->local->hw,
				     &ifmgd->csa_connection_drop_work);
	} else {
		ieee80211_queue_work(&sdata->local->hw, &ifmgd->chswitch_work);
939 940 941 942
	}
}
EXPORT_SYMBOL(ieee80211_chswitch_done);

943 944 945 946
static void ieee80211_chswitch_timer(unsigned long data)
{
	struct ieee80211_sub_if_data *sdata =
		(struct ieee80211_sub_if_data *) data;
947

948
	ieee80211_queue_work(&sdata->local->hw, &sdata->u.mgd.chswitch_work);
949 950
}

951
static void
Johannes Berg's avatar
Johannes Berg committed
952
ieee80211_sta_process_chanswitch(struct ieee80211_sub_if_data *sdata,
953 954
				 u64 timestamp, struct ieee802_11_elems *elems,
				 bool beacon)
955
{
956
	struct ieee80211_local *local = sdata->local;
957
	struct ieee80211_if_managed *ifmgd = &sdata->u.mgd;
958
	struct cfg80211_bss *cbss = ifmgd->associated;
Johannes Berg's avatar
Johannes Berg committed
959
	struct ieee80211_chanctx *chanctx;
960
	enum ieee80211_band current_band;
961 962
	u8 count;
	u8 mode;
963
	struct cfg80211_chan_def new_chandef = {};
964
	int res;
965

966
	sdata_assert_lock(sdata);
967

968
	if (!cbss)
969 970
		return;

971
	if (local->scanning)
972 973
		return;

974
	/* disregard subsequent announcements if we are already processing */
975 976 977
	if (ifmgd->flags & IEEE80211_STA_CSA_RECEIVED)
		return;

978 979 980 981 982 983
	current_band = cbss->channel->band;
	res = ieee80211_parse_ch_switch_ie(sdata, elems, beacon, current_band,
					   ifmgd->flags,
					   ifmgd->associated->bssid, &count,
					   &mode, &new_chandef);
	if (res	< 0)
984
		ieee80211_queue_work(&local->hw,
985
				     &ifmgd->csa_connection_drop_work);
986
	if (res)
987
		return;
988

989 990 991 992
	if (!cfg80211_chandef_usable(local->hw.wiphy, &new_chandef,
				     IEEE80211_CHAN_DISABLED)) {
		sdata_info(sdata,
			   "AP %pM switches to unsupported channel (%d MHz, width:%d, CF1/2: %d/%d MHz), disconnecting\n",
993 994
			   ifmgd->associated->bssid,
			   new_chandef.chan->center_freq,
995 996 997 998 999 1000 1001
			   new_chandef.width, new_chandef.center_freq1,
			   new_chandef.center_freq2);
		ieee80211_queue_work(&local->hw,
				     &ifmgd->csa_connection_drop_work);
		return;
	}

1002
	ifmgd->flags |= IEEE80211_STA_CSA_RECEIVED;
1003
	sdata->vif.csa_active = true;
1004

1005
	mutex_lock(&local->chanctx_mtx);
1006
	if (local->use_chanctx) {
1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019
		u32 num_chanctx = 0;
		list_for_each_entry(chanctx, &local->chanctx_list, list)
		       num_chanctx++;

		if (num_chanctx > 1 ||
		    !(local->hw.flags & IEEE80211_HW_CHANCTX_STA_CSA)) {
			sdata_info(sdata,
				   "not handling chan-switch with channel contexts\n");
			ieee80211_queue_work(&local->hw,
					     &ifmgd->csa_connection_drop_work);
			mutex_unlock(&local->chanctx_mtx);
			return;
		}
Johannes Berg's avatar
Johannes Berg committed
1020 1021 1022
	}

	if (WARN_ON(!rcu_access_pointer(sdata->vif.chanctx_conf))) {
1023 1024
		ieee80211_queue_work(&local->hw,
				     &ifmgd->csa_connection_drop_work);
1025
		mutex_unlock(&local->chanctx_mtx);
Johannes Berg's avatar
Johannes Berg committed
1026 1027 1028 1029 1030 1031 1032
		return;
	}
	chanctx = container_of(rcu_access_pointer(sdata->vif.chanctx_conf),
			       struct ieee80211_chanctx, conf);
	if (chanctx->refcount > 1) {
		sdata_info(sdata,
			   "channel switch with multiple interfaces on the same channel, disconnecting\n");
1033
		ieee80211_queue_work(&local->hw,
Johannes Berg's avatar
Johannes Berg committed
1034
				     &ifmgd->csa_connection_drop_work);
1035
		mutex_unlock(&local->chanctx_mtx);
Johannes Berg's avatar
Johannes Berg committed
1036 1037
		return;
	}
1038
	mutex_unlock(&local->chanctx_mtx);
Johannes Berg's avatar
Johannes Berg committed
1039

1040
	local->csa_chandef = new_chandef;
Johannes Berg's avatar
Johannes Berg committed
1041

1042 1043
	if (mode)
		ieee80211_stop_queues_by_reason(&local->hw,
1044
				IEEE80211_MAX_QUEUE_MAP,
1045 1046
				IEEE80211_QUEUE_STOP_REASON_CSA);

1047
	if (local->ops->channel_switch) {
1048
		/* use driver's channel switch callback */
1049 1050
		struct ieee80211_channel_switch ch_switch = {
			.timestamp = timestamp,
1051
			.block_tx = mode,
1052
			.chandef = new_chandef,
1053
			.count = count,
1054 1055
		};

1056
		drv_channel_switch(local, &ch_switch);
1057 1058 1059 1060
		return;
	}

	/* channel switch handled in software */
1061 1062
	if (count <= 1)
		ieee80211_queue_work(&local->hw, &ifmgd->chswitch_work);
1063
	else
1064
		mod_timer(&ifmgd->chswitch_timer,
1065
			  TU_TO_EXP_TIME(count * cbss->beacon_interval));
1066 1067
}

1068 1069 1070 1071
static u32 ieee80211_handle_pwr_constr(struct ieee80211_sub_if_data *sdata,
				       struct ieee80211_channel *channel,
				       const u8 *country_ie, u8 country_ie_len,
				       const u8 *pwr_constr_elem)
1072
{
1073 1074 1075 1076
	struct ieee80211_country_ie_triplet *triplet;
	int chan = ieee80211_frequency_to_channel(channel->center_freq);
	int i, chan_pwr, chan_increment, new_ap_level;
	bool have_chan_pwr = false;
1077

1078 1079
	/* Invalid IE */
	if (country_ie_len % 2 || country_ie_len < IEEE80211_COUNTRY_IE_MIN_LEN)
1080
		return 0;
1081

1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095
	triplet = (void *)(country_ie + 3);
	country_ie_len -= 3;

	switch (channel->band) {
	default:
		WARN_ON_ONCE(1);
		/* fall through */
	case IEEE80211_BAND_2GHZ:
	case IEEE80211_BAND_60GHZ:
		chan_increment = 1;
		break;
	case IEEE80211_BAND_5GHZ:
		chan_increment = 4;
		break;
1096
	}
1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120

	/* find channel */
	while (country_ie_len >= 3) {
		u8 first_channel = triplet->chans.first_channel;

		if (first_channel >= IEEE80211_COUNTRY_EXTENSION_ID)
			goto next;

		for (i = 0; i < triplet->chans.num_channels; i++) {
			if (first_channel + i * chan_increment == chan) {
				have_chan_pwr = true;
				chan_pwr = triplet->chans.max_power;
				break;
			}
		}
		if (have_chan_pwr)
			break;

 next:
		triplet++;
		country_ie_len -= 3;
	}

	if (!have_chan_pwr)
1121
		return 0;
1122 1123 1124

	new_ap_level = max_t(int, 0, chan_pwr - *pwr_constr_elem);

1125 1126
	if (sdata->ap_power_level == new_ap_level)
		return 0;
1127 1128 1129 1130 1131

	sdata_info(sdata,
		   "Limiting TX power to %d (%d - %d) dBm as advertised by %pM\n",
		   new_ap_level, chan_pwr, *pwr_constr_elem,
		   sdata->u.mgd.bssid);
1132 1133 1134 1135
	sdata->ap_power_level = new_ap_level;
	if (__ieee80211_recalc_txpower(sdata))
		return BSS_CHANGED_TXPOWER;
	return 0;
1136 1137
}

1138 1139 1140 1141 1142 1143
/* powersave */
static void ieee80211_enable_ps(struct ieee80211_local *local,
				struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_conf *conf = &local->hw.conf;

Johannes Berg's avatar
Johannes Berg committed
1144 1145 1146 1147
	/*
	 * If we are scanning right now then the parameters will
	 * take effect when scan finishes.
	 */
1148
	if (local->scanning)
Johannes Berg's avatar
Johannes Berg committed
1149 1150
		return;

1151 1152 1153 1154 1155 1156 1157
	if (conf->dynamic_ps_timeout > 0 &&
	    !(local->hw.flags & IEEE80211_HW_SUPPORTS_DYNAMIC_PS)) {
		mod_timer(&local->dynamic_ps_timer, jiffies +
			  msecs_to_jiffies(conf->dynamic_ps_timeout));
	} else {
		if (local->hw.flags & IEEE80211_HW_PS_NULLFUNC_STACK)
			ieee80211_send_nullfunc(local, sdata, 1);
1158

1159 1160 1161 1162 1163 1164
		if ((local->hw.flags & IEEE80211_HW_PS_NULLFUNC_STACK) &&
		    (local->hw.flags & IEEE80211_HW_REPORTS_TX_ACK_STATUS))
			return;

		conf->flags |= IEEE80211_CONF_PS;
		ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_PS);
1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181
	}
}

static void ieee80211_change_ps(struct ieee80211_local *local)
{
	struct ieee80211_conf *conf = &local->hw.conf;

	if (local->ps_sdata) {
		ieee80211_enable_ps(local, local->ps_sdata);
	} else if (conf->flags & IEEE80211_CONF_PS) {
		conf->flags &= ~IEEE80211_CONF_PS;
		ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_PS);
		del_timer_sync(&local->dynamic_ps_timer);
		cancel_work_sync(&local->dynamic_ps_enable_work);
	}
}

1182 1183 1184 1185
static bool ieee80211_powersave_allowed(struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_if_managed *mgd = &sdata->u.mgd;
	struct sta_info *sta = NULL;
1186
	bool authorized = false;
1187 1188 1189 1190

	if (!mgd->powersave)
		return false;

1191 1192 1193
	if (mgd->broken_ap)
		return false;

1194 1195 1196
	if (!mgd->associated)
		return false;

1197
	if (mgd->flags & IEEE80211_STA_CONNECTION_POLL)
1198 1199
		return false;

1200
	if (!mgd->have_beacon)
1201 1202
		return false;

1203 1204 1205
	rcu_read_lock();
	sta = sta_info_get(sdata, mgd->bssid);
	if (sta)
1206
		authorized = test_sta_flag(sta, WLAN_STA_AUTHORIZED);
1207 1208
	rcu_read_unlock();

1209
	return authorized;
1210 1211
}

1212
/* need to hold RTNL or interface lock */
1213
void ieee80211_recalc_ps(struct ieee80211_local *local, s32 latency)
1214 1215 1216
{
	struct ieee80211_sub_if_data *sdata, *found = NULL;
	int count = 0;
1217
	int timeout;
1218 1219 1220 1221 1222 1223 1224

	if (!(local->hw.flags & IEEE80211_HW_SUPPORTS_PS)) {
		local->ps_sdata = NULL;
		return;
	}

	list_for_each_entry(sdata, &local->interfaces, list) {
1225
		if (!ieee80211_sdata_running(sdata))
1226
			continue;
1227 1228 1229 1230 1231 1232 1233 1234
		if (sdata->vif.type == NL80211_IFTYPE_AP) {
			/* If an AP vif is found, then disable PS
			 * by setting the count to zero thereby setting
			 * ps_sdata to NULL.
			 */
			count = 0;
			break;
		}
1235 1236 1237 1238 1239 1240
		if (sdata->vif.type != NL80211_IFTYPE_STATION)
			continue;
		found = sdata;
		count++;
	}

1241
	if (count == 1 && ieee80211_powersave_allowed(found)) {
1242 1243 1244
		s32 beaconint_us;

		if (latency < 0)
Mark Gross's avatar
Mark Gross committed
1245
			latency = pm_qos_request(PM_QOS_NETWORK_LATENCY);
1246 1247 1248 1249

		beaconint_us = ieee80211_tu_to_usec(
					found->vif.bss_conf.beacon_int);

1250
		timeout = local->dynamic_ps_forced_timeout;
1251 1252
		if (timeout < 0) {
			/*
1253 1254
			 * Go to full PSM if the user configures a very low
			 * latency requirement.
1255 1256 1257
			 * The 2000 second value is there for compatibility
			 * until the PM_QOS_NETWORK_LATENCY is configured
			 * with real values.
1258
			 */
1259 1260
			if (latency > (1900 * USEC_PER_MSEC) &&
			    latency != (2000 * USEC_PER_SEC))
1261
				timeout = 0;
1262 1263
			else
				timeout = 100;
1264
		}
1265
		local->hw.conf.dynamic_ps_timeout = timeout;
1266

1267
		if (beaconint_us > latency) {
1268
			local->ps_sdata = NULL;
1269 1270
		} else {
			int maxslp = 1;
1271
			u8 dtimper = found->u.mgd.dtim_period;
1272 1273 1274 1275 1276

			/* If the TIM IE is invalid, pretend the value is 1 */
			if (!dtimper)
				dtimper = 1;
			else if (dtimper > 1)
1277 1278 1279
				maxslp = min_t(int, dtimper,
						    latency / beaconint_us);

1280
			local->hw.conf.max_sleep_period = maxslp;
1281
			local->hw.conf.ps_dtim_period = dtimper;
1282
			local->ps_sdata = found;
Johannes Berg's avatar