• source navigation  • diff markup  • identifier search  • freetext search  • 

Sources/iwinfo/iwinfo_nl80211.c

  1 /*
  2  * iwinfo - Wireless Information Library - NL80211 Backend
  3  *
  4  *   Copyright (C) 2010-2013 Jo-Philipp Wich <xm@subsignal.org>
  5  *
  6  * The iwinfo library is free software: you can redistribute it and/or
  7  * modify it under the terms of the GNU General Public License version 2
  8  * as published by the Free Software Foundation.
  9  *
 10  * The iwinfo library is distributed in the hope that it will be useful,
 11  * but WITHOUT ANY WARRANTY; without even the implied warranty of
 12  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
 13  * See the GNU General Public License for more details.
 14  *
 15  * You should have received a copy of the GNU General Public License along
 16  * with the iwinfo library. If not, see http://www.gnu.org/licenses/.
 17  *
 18  * The signal handling code is derived from the official madwifi tools,
 19  * wlanconfig.c in particular. The encryption property handling was
 20  * inspired by the hostapd madwifi driver.
 21  *
 22  * Parts of this code are derived from the Linux iw utility.
 23  */
 24 
 25 #include <sys/stat.h>
 26 #include <limits.h>
 27 #include <glob.h>
 28 #include <fnmatch.h>
 29 #include <stdarg.h>
 30 #include <stdlib.h>
 31 
 32 #include "iwinfo_nl80211.h"
 33 
 34 #define min(x, y) ((x) < (y)) ? (x) : (y)
 35 
 36 #define BIT(x) (1ULL<<(x))
 37 
 38 static struct nl80211_state *nls = NULL;
 39 
 40 static void nl80211_close(void)
 41 {
 42         if (nls)
 43         {
 44                 if (nls->nlctrl)
 45                         genl_family_put(nls->nlctrl);
 46 
 47                 if (nls->nl80211)
 48                         genl_family_put(nls->nl80211);
 49 
 50                 if (nls->nl_sock)
 51                         nl_socket_free(nls->nl_sock);
 52 
 53                 if (nls->nl_cache)
 54                         nl_cache_free(nls->nl_cache);
 55 
 56                 free(nls);
 57                 nls = NULL;
 58         }
 59 }
 60 
 61 static int nl80211_init(void)
 62 {
 63         int err, fd;
 64 
 65         if (!nls)
 66         {
 67                 nls = malloc(sizeof(struct nl80211_state));
 68                 if (!nls) {
 69                         err = -ENOMEM;
 70                         goto err;
 71                 }
 72 
 73                 memset(nls, 0, sizeof(*nls));
 74 
 75                 nls->nl_sock = nl_socket_alloc();
 76                 if (!nls->nl_sock) {
 77                         err = -ENOMEM;
 78                         goto err;
 79                 }
 80 
 81                 if (genl_connect(nls->nl_sock)) {
 82                         err = -ENOLINK;
 83                         goto err;
 84                 }
 85 
 86                 fd = nl_socket_get_fd(nls->nl_sock);
 87                 if (fcntl(fd, F_SETFD, fcntl(fd, F_GETFD) | FD_CLOEXEC) < 0) {
 88                         err = -EINVAL;
 89                         goto err;
 90                 }
 91 
 92                 if (genl_ctrl_alloc_cache(nls->nl_sock, &nls->nl_cache)) {
 93                         err = -ENOMEM;
 94                         goto err;
 95                 }
 96 
 97                 nls->nl80211 = genl_ctrl_search_by_name(nls->nl_cache, "nl80211");
 98                 if (!nls->nl80211) {
 99                         err = -ENOENT;
100                         goto err;
101                 }
102 
103                 nls->nlctrl = genl_ctrl_search_by_name(nls->nl_cache, "nlctrl");
104                 if (!nls->nlctrl) {
105                         err = -ENOENT;
106                         goto err;
107                 }
108         }
109 
110         return 0;
111 
112 
113 err:
114         nl80211_close();
115         return err;
116 }
117 
118 static int nl80211_readint(const char *path)
119 {
120         int fd;
121         int rv = -1;
122         char buffer[16];
123 
124         if ((fd = open(path, O_RDONLY)) > -1)
125         {
126                 if (read(fd, buffer, sizeof(buffer)) > 0)
127                         rv = atoi(buffer);
128 
129                 close(fd);
130         }
131 
132         return rv;
133 }
134 
135 static int nl80211_readstr(const char *path, char *buffer, int length)
136 {
137         int fd;
138         int rv = -1;
139 
140         if ((fd = open(path, O_RDONLY)) > -1)
141         {
142                 if ((rv = read(fd, buffer, length - 1)) > 0)
143                 {
144                         if (buffer[rv - 1] == '\n')
145                                 rv--;
146 
147                         buffer[rv] = 0;
148                 }
149 
150                 close(fd);
151         }
152 
153         return rv;
154 }
155 
156 static int nl80211_get_band(int nla_type)
157 {
158         switch (nla_type)
159         {
160         case NL80211_BAND_2GHZ:
161                 return IWINFO_BAND_24;
162         case NL80211_BAND_5GHZ:
163                 return IWINFO_BAND_5;
164         case NL80211_BAND_6GHZ:
165                 return IWINFO_BAND_6;
166         case NL80211_BAND_60GHZ:
167                 return IWINFO_BAND_60;
168         }
169 
170         return 0;
171 }
172 
173 
174 static int nl80211_msg_error(struct sockaddr_nl *nla,
175         struct nlmsgerr *err, void *arg)
176 {
177         int *ret = arg;
178         *ret = err->error;
179         return NL_STOP;
180 }
181 
182 static int nl80211_msg_finish(struct nl_msg *msg, void *arg)
183 {
184         int *ret = arg;
185         *ret = 0;
186         return NL_SKIP;
187 }
188 
189 static int nl80211_msg_ack(struct nl_msg *msg, void *arg)
190 {
191         int *ret = arg;
192         *ret = 0;
193         return NL_STOP;
194 }
195 
196 static int nl80211_msg_response(struct nl_msg *msg, void *arg)
197 {
198         return NL_SKIP;
199 }
200 
201 static void nl80211_free(struct nl80211_msg_conveyor *cv)
202 {
203         if (cv)
204         {
205                 if (cv->cb)
206                         nl_cb_put(cv->cb);
207 
208                 if (cv->msg)
209                         nlmsg_free(cv->msg);
210 
211                 cv->cb  = NULL;
212                 cv->msg = NULL;
213         }
214 }
215 
216 static struct nl80211_msg_conveyor * nl80211_new(struct genl_family *family,
217                                                  int cmd, int flags)
218 {
219         static struct nl80211_msg_conveyor cv;
220 
221         struct nl_msg *req = NULL;
222         struct nl_cb *cb = NULL;
223 
224         req = nlmsg_alloc();
225         if (!req)
226                 goto err;
227 
228         cb = nl_cb_alloc(NL_CB_DEFAULT);
229         if (!cb)
230                 goto err;
231 
232         genlmsg_put(req, 0, 0, genl_family_get_id(family), 0, flags, cmd, 0);
233 
234         cv.msg = req;
235         cv.cb  = cb;
236 
237         return &cv;
238 
239 err:
240         if (req)
241                 nlmsg_free(req);
242 
243         return NULL;
244 }
245 
246 static struct nl80211_msg_conveyor * nl80211_ctl(int cmd, int flags)
247 {
248         if (nl80211_init() < 0)
249                 return NULL;
250 
251         return nl80211_new(nls->nlctrl, cmd, flags);
252 }
253 
254 static const char *nl80211_phy_path_str(const char *phyname)
255 {
256         static char path[PATH_MAX];
257         const char *prefix = "/sys/devices/";
258         int prefix_len = strlen(prefix);
259         int buf_len, offset;
260         struct dirent *e;
261         char buf[512], *link;
262         int phy_idx;
263         int seq = 0;
264         DIR *d;
265 
266         snprintf(buf, sizeof(buf), "/sys/class/ieee80211/%s/index", phyname);
267         phy_idx = nl80211_readint(buf);
268         if (phy_idx < 0)
269                 return NULL;
270 
271         buf_len = snprintf(buf, sizeof(buf), "/sys/class/ieee80211/%s/device", phyname);
272         link = realpath(buf, path);
273         if (!link)
274                 return NULL;
275 
276         if (strncmp(link, prefix, prefix_len) != 0)
277                 return NULL;
278 
279         link += prefix_len;
280 
281         prefix = "platform/";
282         prefix_len = strlen(prefix);
283         if (!strncmp(link, prefix, prefix_len) && strstr(link, "/pci"))
284                 link += prefix_len;
285 
286         snprintf(buf + buf_len, sizeof(buf) - buf_len, "/ieee80211");
287         d = opendir(buf);
288         if (!d)
289                 return link;
290 
291         while ((e = readdir(d)) != NULL) {
292                 int cur_idx;
293 
294                 snprintf(buf, sizeof(buf), "/sys/class/ieee80211/%s/index", e->d_name);
295                 cur_idx = nl80211_readint(buf);
296                 if (cur_idx < 0)
297                         continue;
298 
299                 if (cur_idx >= phy_idx)
300                         continue;
301 
302                 seq++;
303         }
304 
305         closedir(d);
306 
307         if (!seq)
308                 return link;
309 
310         offset = link - path + strlen(link);
311         snprintf(path + offset, sizeof(path) - offset, "+%d", seq);
312 
313         return link;
314 }
315 
316 static int nl80211_phy_idx_from_path(const char *path)
317 {
318         char buf[512];
319         struct dirent *e;
320         const char *cur_path;
321         int cur_path_len;
322         int path_len;
323         int idx = -1;
324         DIR *d;
325 
326         if (!path)
327                 return -1;
328 
329         path_len = strlen(path);
330         if (!path_len)
331                 return -1;
332 
333         d = opendir("/sys/class/ieee80211");
334         if (!d)
335                 return -1;
336 
337         while ((e = readdir(d)) != NULL) {
338                 cur_path = nl80211_phy_path_str(e->d_name);
339                 if (!cur_path)
340                         continue;
341 
342                 cur_path_len = strlen(cur_path);
343                 if (cur_path_len < path_len)
344                         continue;
345 
346                 if (strcmp(cur_path + cur_path_len - path_len, path) != 0)
347                         continue;
348 
349                 snprintf(buf, sizeof(buf), "/sys/class/ieee80211/%s/index", e->d_name);
350                 idx = nl80211_readint(buf);
351 
352                 if (idx >= 0)
353                         break;
354         }
355 
356         closedir(d);
357 
358         return idx;
359 }
360 
361 static int nl80211_phy_idx_from_macaddr(const char *opt)
362 {
363         char buf[128];
364         int i, idx = -1;
365         glob_t gl;
366 
367         if (!opt)
368                 return -1;
369 
370         snprintf(buf, sizeof(buf), "/sys/class/ieee80211/*");
371         if (glob(buf, 0, NULL, &gl))
372                 return -1;
373 
374         for (i = 0; i < gl.gl_pathc; i++)
375         {
376                 snprintf(buf, sizeof(buf), "%s/macaddress", gl.gl_pathv[i]);
377                 if (nl80211_readstr(buf, buf, sizeof(buf)) <= 0)
378                         continue;
379 
380                 if (fnmatch(opt, buf, FNM_CASEFOLD))
381                         continue;
382 
383                 snprintf(buf, sizeof(buf), "%s/index", gl.gl_pathv[i]);
384                 if ((idx = nl80211_readint(buf)) > -1)
385                         break;
386         }
387 
388         globfree(&gl);
389 
390         return idx;
391 }
392 
393 static int nl80211_phy_idx_from_phy(const char *opt)
394 {
395         char buf[128];
396 
397         if (!opt)
398                 return -1;
399 
400         snprintf(buf, sizeof(buf), "/sys/class/ieee80211/%s/index", opt);
401         return nl80211_readint(buf);
402 }
403 
404 static int nl80211_phy_idx_from_uci(const char *name)
405 {
406         struct uci_section *s;
407         const char *opt;
408         int idx = -1;
409 
410         s = iwinfo_uci_get_radio(name, "mac80211");
411         if (!s)
412                 goto out;
413 
414         opt = uci_lookup_option_string(uci_ctx, s, "path");
415         idx = nl80211_phy_idx_from_path(opt);
416         if (idx >= 0)
417                 goto out;
418 
419         opt = uci_lookup_option_string(uci_ctx, s, "macaddr");
420         idx = nl80211_phy_idx_from_macaddr(opt);
421         if (idx >= 0)
422                 goto out;
423 
424         opt = uci_lookup_option_string(uci_ctx, s, "phy");
425         idx = nl80211_phy_idx_from_phy(opt);
426 
427 out:
428         iwinfo_uci_free();
429         return idx;
430 }
431 
432 static bool nl80211_is_ifname(const char *name)
433 {
434         struct stat st;
435         char buffer[PATH_MAX];
436 
437         snprintf(buffer, sizeof(buffer), "/sys/class/net/%s", name);
438         return !lstat(buffer, &st);
439 }
440 
441 static struct nl80211_msg_conveyor * nl80211_msg(const char *ifname,
442                                                  int cmd, int flags)
443 {
444         unsigned int ifidx = 0;
445         int phyidx = -1;
446         struct nl80211_msg_conveyor *cv;
447 
448         if (ifname == NULL)
449                 return NULL;
450 
451         if (nl80211_init() < 0)
452                 return NULL;
453 
454         if (!strncmp(ifname, "mon.", 4))
455                 ifidx = if_nametoindex(&ifname[4]);
456         else if (nl80211_is_ifname(ifname))
457                 ifidx = if_nametoindex(ifname);
458         else
459         {
460                 phyidx = nl80211_phy_idx_from_phy(ifname);
461                 if (phyidx < 0)
462                         phyidx = nl80211_phy_idx_from_uci(ifname);
463         }
464 
465         /* Valid ifidx must be greater than 0 */
466         if ((ifidx <= 0) && (phyidx < 0))
467                 return NULL;
468 
469         cv = nl80211_new(nls->nl80211, cmd, flags);
470         if (!cv)
471                 return NULL;
472 
473         if (ifidx > 0)
474                 NLA_PUT_U32(cv->msg, NL80211_ATTR_IFINDEX, ifidx);
475         else if (phyidx > -1)
476                 NLA_PUT_U32(cv->msg, NL80211_ATTR_WIPHY, phyidx);
477 
478         return cv;
479 
480 nla_put_failure:
481         nl80211_free(cv);
482         return NULL;
483 }
484 
485 static int nl80211_send(struct nl80211_msg_conveyor *cv,
486                         int (*cb_func)(struct nl_msg *, void *),
487                         void *cb_arg)
488 {
489         static struct nl80211_msg_conveyor rcv;
490         int err;
491 
492         if (cb_func)
493                 nl_cb_set(cv->cb, NL_CB_VALID, NL_CB_CUSTOM, cb_func, cb_arg);
494         else
495                 nl_cb_set(cv->cb, NL_CB_VALID, NL_CB_CUSTOM, nl80211_msg_response, &rcv);
496 
497         err = nl_send_auto_complete(nls->nl_sock, cv->msg);
498 
499         if (err < 0)
500                 goto out;
501 
502         err = 1;
503 
504         nl_cb_err(cv->cb,               NL_CB_CUSTOM, nl80211_msg_error,  &err);
505         nl_cb_set(cv->cb, NL_CB_FINISH, NL_CB_CUSTOM, nl80211_msg_finish, &err);
506         nl_cb_set(cv->cb, NL_CB_ACK,    NL_CB_CUSTOM, nl80211_msg_ack,    &err);
507 
508         while (err > 0)
509                 nl_recvmsgs(nls->nl_sock, cv->cb);
510 
511 out:
512         nl80211_free(cv);
513         return err;
514 }
515 
516 static int nl80211_request(const char *ifname, int cmd, int flags,
517                            int (*cb_func)(struct nl_msg *, void *),
518                            void *cb_arg)
519 {
520         struct nl80211_msg_conveyor *cv;
521 
522         cv = nl80211_msg(ifname, cmd, flags);
523 
524         if (!cv)
525                 return -ENOMEM;
526 
527         return nl80211_send(cv, cb_func, cb_arg);
528 }
529 
530 static struct nlattr ** nl80211_parse(struct nl_msg *msg)
531 {
532         struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
533         static struct nlattr *attr[NL80211_ATTR_MAX + 1];
534 
535         nla_parse(attr, NL80211_ATTR_MAX, genlmsg_attrdata(gnlh, 0),
536                   genlmsg_attrlen(gnlh, 0), NULL);
537 
538         return attr;
539 }
540 
541 static int nl80211_get_protocol_features_cb(struct nl_msg *msg, void *arg)
542 {
543         uint32_t *features = arg;
544         struct nlattr **attr = nl80211_parse(msg);
545 
546         if (attr[NL80211_ATTR_PROTOCOL_FEATURES])
547                 *features = nla_get_u32(attr[NL80211_ATTR_PROTOCOL_FEATURES]);
548 
549         return NL_SKIP;
550 }
551 
552 static int nl80211_get_protocol_features(const char *ifname)
553 {
554         struct nl80211_msg_conveyor *req;
555         uint32_t features = 0;
556 
557         req = nl80211_msg(ifname, NL80211_CMD_GET_PROTOCOL_FEATURES, 0);
558         if (req) {
559                 nl80211_send(req, nl80211_get_protocol_features_cb, &features);
560                 nl80211_free(req);
561         }
562 
563         return features;
564 }
565 
566 static int nl80211_subscribe_cb(struct nl_msg *msg, void *arg)
567 {
568         struct nl80211_group_conveyor *cv = arg;
569 
570         struct nlattr **attr = nl80211_parse(msg);
571         struct nlattr *mgrpinfo[CTRL_ATTR_MCAST_GRP_MAX + 1];
572         struct nlattr *mgrp;
573         int mgrpidx;
574 
575         if (!attr[CTRL_ATTR_MCAST_GROUPS])
576                 return NL_SKIP;
577 
578         nla_for_each_nested(mgrp, attr[CTRL_ATTR_MCAST_GROUPS], mgrpidx)
579         {
580                 nla_parse(mgrpinfo, CTRL_ATTR_MCAST_GRP_MAX,
581                           nla_data(mgrp), nla_len(mgrp), NULL);
582 
583                 if (mgrpinfo[CTRL_ATTR_MCAST_GRP_ID] &&
584                     mgrpinfo[CTRL_ATTR_MCAST_GRP_NAME] &&
585                     !strncmp(nla_data(mgrpinfo[CTRL_ATTR_MCAST_GRP_NAME]),
586                              cv->name, nla_len(mgrpinfo[CTRL_ATTR_MCAST_GRP_NAME])))
587                 {
588                         cv->id = nla_get_u32(mgrpinfo[CTRL_ATTR_MCAST_GRP_ID]);
589                         break;
590                 }
591         }
592 
593         return NL_SKIP;
594 }
595 
596 static int nl80211_subscribe(const char *family, const char *group)
597 {
598         struct nl80211_group_conveyor cv = { .name = group, .id = -ENOENT };
599         struct nl80211_msg_conveyor *req;
600         int err;
601 
602         req = nl80211_ctl(CTRL_CMD_GETFAMILY, 0);
603         if (req)
604         {
605                 NLA_PUT_STRING(req->msg, CTRL_ATTR_FAMILY_NAME, family);
606                 err = nl80211_send(req, nl80211_subscribe_cb, &cv);
607 
608                 if (err)
609                         return err;
610 
611                 return nl_socket_add_membership(nls->nl_sock, cv.id);
612 
613 nla_put_failure:
614                 nl80211_free(req);
615         }
616 
617         return -ENOMEM;
618 }
619 
620 
621 static int nl80211_wait_cb(struct nl_msg *msg, void *arg)
622 {
623         struct nl80211_event_conveyor *cv = arg;
624         struct genlmsghdr *gnlh = nlmsg_data(nlmsg_hdr(msg));
625 
626         if (cv->wait[gnlh->cmd / 32] & (1 << (gnlh->cmd % 32)))
627                 cv->recv = gnlh->cmd;
628 
629         return NL_SKIP;
630 }
631 
632 static int nl80211_wait_seq_check(struct nl_msg *msg, void *arg)
633 {
634         return NL_OK;
635 }
636 
637 static int __nl80211_wait(const char *family, const char *group, ...)
638 {
639         struct nl80211_event_conveyor cv = { };
640         struct nl_cb *cb;
641         int err = 0;
642         int cmd;
643         va_list ap;
644 
645         if (nl80211_subscribe(family, group))
646                 return -ENOENT;
647 
648         cb = nl_cb_alloc(NL_CB_DEFAULT);
649 
650         if (!cb)
651                 return -ENOMEM;
652 
653         nl_cb_err(cb,                  NL_CB_CUSTOM, nl80211_msg_error,      &err);
654         nl_cb_set(cb, NL_CB_SEQ_CHECK, NL_CB_CUSTOM, nl80211_wait_seq_check, NULL);
655         nl_cb_set(cb, NL_CB_VALID,     NL_CB_CUSTOM, nl80211_wait_cb,        &cv );
656 
657         va_start(ap, group);
658 
659         for (cmd = va_arg(ap, int); cmd != 0; cmd = va_arg(ap, int))
660                 cv.wait[cmd / 32] |= (1 << (cmd % 32));
661 
662         va_end(ap);
663 
664         while (!cv.recv && !err)
665                 nl_recvmsgs(nls->nl_sock, cb);
666 
667         nl_cb_put(cb);
668 
669         return err;
670 }
671 
672 #define nl80211_wait(family, group, ...) \
673         __nl80211_wait(family, group, __VA_ARGS__, 0)
674 
675 /* This is linux's ieee80211_freq_khz_to_channel() which is:
676  * SPDX-License-Identifier: GPL-2.0
677  * Copyright 2007-2009 Johannes Berg <johannes@sipsolutions.net>
678  * Copyright 2013-2014 Intel Mobile Communications GmbH
679  * Copyright 2017 Intel Deutschland GmbH
680  * Copyright (C) 2018-2022 Intel Corporation
681  */
682 static int nl80211_freq2channel(int freq)
683 {
684         if (freq == 2484)
685                 return 14;
686         else if (freq < 2484)
687                 return (freq - 2407) / 5;
688         else if (freq >= 4910 && freq <= 4980)
689                 return (freq - 4000) / 5;
690         else if (freq < 5925)
691                 return (freq - 5000) / 5;
692         else if (freq == 5935)
693                 return 2;
694         else if (freq <= 45000) /* DMG band lower limit */
695                 /* see 802.11ax D6.1 27.3.22.2 */
696                 return (freq - 5950) / 5;
697         else if (freq >= 58320 && freq <= 70200)
698                 return (freq - 56160) / 2160;
699         else
700                 return 0;
701 }
702 
703 /* This is linux's ieee80211_channel_to_freq_khz() which is:
704  * SPDX-License-Identifier: GPL-2.0
705  * Copyright 2007-2009 Johannes Berg <johannes@sipsolutions.net>
706  * Copyright 2013-2014 Intel Mobile Communications GmbH
707  * Copyright 2017 Intel Deutschland GmbH
708  * Copyright (C) 2018-2022 Intel Corporation
709  */
710 static int nl80211_channel2freq(int channel, const char *band, bool ax)
711 {
712         if (channel < 1)
713                 return 0;
714 
715         if (!band || band[0] != 'a')
716         {
717                 if (channel == 14)
718                         return 2484;
719                 else if (channel < 14)
720                         return (channel * 5) + 2407;
721         }
722         else if (strcmp(band, "ad")  == 0)
723         {
724                 if (channel < 7)
725                         return 56160 + 2160 * channel;
726         }
727         else if (ax)
728         {
729                 if (channel == 2)
730                         return 5935;
731                 if (channel < 233)
732                         return (channel * 5) + 5950;
733         }
734         else
735         {
736                 if (channel >= 182 && channel <= 196)
737                         return (channel * 5) + 4000;
738                 else
739                         return (channel * 5) + 5000;
740         }
741 
742         return 0;
743 }
744 
745 static uint8_t nl80211_freq2band(int freq)
746 {
747         if (freq >= 2412 && freq <= 2484)
748                 return IWINFO_BAND_24;
749         else if (freq >= 5160 && freq <= 5885)
750                 return IWINFO_BAND_5;
751         else if (freq >= 5925 && freq <= 7125)
752                 return IWINFO_BAND_6;
753         else if (freq >= 58320 && freq <= 69120)
754                 return IWINFO_BAND_60;
755 
756         return 0;
757 }
758 
759 static int nl80211_phyname_cb(struct nl_msg *msg, void *arg)
760 {
761         char *buf = arg;
762         struct nlattr **attr = nl80211_parse(msg);
763 
764         if (attr[NL80211_ATTR_WIPHY_NAME])
765                 memcpy(buf, nla_data(attr[NL80211_ATTR_WIPHY_NAME]),
766                        nla_len(attr[NL80211_ATTR_WIPHY_NAME]));
767         else
768                 buf[0] = 0;
769 
770         return NL_SKIP;
771 }
772 
773 static char * nl80211_ifname2phy(const char *ifname)
774 {
775         static char phy[32] = { 0 };
776 
777         memset(phy, 0, sizeof(phy));
778 
779         nl80211_request(ifname, NL80211_CMD_GET_WIPHY, 0,
780                         nl80211_phyname_cb, phy);
781 
782         return phy[0] ? phy : NULL;
783 }
784 
785 static char * nl80211_phyidx2name(unsigned int idx)
786 {
787         struct nl80211_msg_conveyor *cv;
788         static char phy[32] = { 0 };
789 
790         if (nl80211_init() < 0)
791                 return NULL;
792 
793         cv = nl80211_new(nls->nl80211, NL80211_CMD_GET_WIPHY, 0);
794         if (!cv)
795                 return NULL;
796 
797         NLA_PUT_U32(cv->msg, NL80211_ATTR_WIPHY, idx);
798 
799         memset(phy, 0, sizeof(phy));
800         nl80211_send(cv, nl80211_phyname_cb, phy);
801 
802         return phy[0] ? phy : NULL;
803 
804 nla_put_failure:
805         return NULL;
806 }
807 
808 static char * nl80211_phy2ifname(const char *ifname)
809 {
810         int ifidx = -1, cifidx, lmode = 1, clmode, phyidx;
811         char buffer[512];
812         static char nif[IFNAMSIZ] = { 0 };
813         DIR *d;
814         struct dirent *e;
815 
816         /* Only accept phy name in the form of phy%d or radio%d */
817         if (!ifname)
818                 return NULL;
819 
820         phyidx = nl80211_phy_idx_from_phy(ifname);
821         if (phyidx < 0)
822                 phyidx = nl80211_phy_idx_from_uci(ifname);;
823         if (phyidx < 0)
824                 return NULL;
825 
826         memset(nif, 0, sizeof(nif));
827 
828         if ((d = opendir("/sys/class/net")) != NULL)
829         {
830                 while ((e = readdir(d)) != NULL)
831                 {
832                         snprintf(buffer, sizeof(buffer),
833                                  "/sys/class/net/%s/phy80211/index", e->d_name);
834                         if (nl80211_readint(buffer) != phyidx)
835                                 continue;
836 
837                         snprintf(buffer, sizeof(buffer),
838                                  "/sys/class/net/%s/ifindex", e->d_name);
839                         cifidx = nl80211_readint(buffer);
840 
841                         if (cifidx < 0)
842                                 continue;
843 
844                         snprintf(buffer, sizeof(buffer),
845                                  "/sys/class/net/%s/link_mode", e->d_name);
846                         clmode = nl80211_readint(buffer);
847 
848                         /* prefer non-supplicant-based devices */
849                         if ((ifidx < 0) || (cifidx < ifidx) || ((lmode == 1) && (clmode != 1)))
850                         {
851                                 ifidx = cifidx;
852                                 lmode = clmode;
853                                 strncpy(nif, e->d_name, sizeof(nif) - 1);
854                         }
855                 }
856 
857                 closedir(d);
858         }
859 
860         return nif[0] ? nif : NULL;
861 }
862 
863 static int nl80211_get_mode_cb(struct nl_msg *msg, void *arg)
864 {
865         int *mode = arg;
866         struct nlattr **tb = nl80211_parse(msg);
867         const int ifmodes[NL80211_IFTYPE_MAX + 1] = {
868                 IWINFO_OPMODE_UNKNOWN,          /* unspecified */
869                 IWINFO_OPMODE_ADHOC,            /* IBSS */
870                 IWINFO_OPMODE_CLIENT,           /* managed */
871                 IWINFO_OPMODE_MASTER,           /* AP */
872                 IWINFO_OPMODE_AP_VLAN,          /* AP/VLAN */
873                 IWINFO_OPMODE_WDS,              /* WDS */
874                 IWINFO_OPMODE_MONITOR,          /* monitor */
875                 IWINFO_OPMODE_MESHPOINT,        /* mesh point */
876                 IWINFO_OPMODE_P2P_CLIENT,       /* P2P-client */
877                 IWINFO_OPMODE_P2P_GO,           /* P2P-GO */
878         };
879 
880         if (tb[NL80211_ATTR_IFTYPE])
881                 *mode = ifmodes[nla_get_u32(tb[NL80211_ATTR_IFTYPE])];
882 
883         return NL_SKIP;
884 }
885 
886 
887 static int nl80211_get_mode(const char *ifname, int *buf)
888 {
889         char *res;
890 
891         *buf = IWINFO_OPMODE_UNKNOWN;
892 
893         res = nl80211_phy2ifname(ifname);
894 
895         nl80211_request(res ? res : ifname, NL80211_CMD_GET_INTERFACE, 0,
896                         nl80211_get_mode_cb, buf);
897 
898         return (*buf == IWINFO_OPMODE_UNKNOWN) ? -1 : 0;
899 }
900 
901 static int __nl80211_hostapd_query(const char *ifname, ...)
902 {
903         va_list ap, ap_cur;
904         char *phy, *search, *dest, *key, *val, buf[128];
905         int len, mode, found = 0, match = 1;
906         FILE *fp;
907 
908         if (nl80211_get_mode(ifname, &mode))
909                 return 0;
910 
911         if (mode != IWINFO_OPMODE_MASTER && mode != IWINFO_OPMODE_AP_VLAN)
912                 return 0;
913 
914         phy = nl80211_ifname2phy(ifname);
915 
916         if (!phy)
917                 return 0;
918 
919         snprintf(buf, sizeof(buf), "/var/run/hostapd-%s.conf", phy);
920         fp = fopen(buf, "r");
921 
922         if (!fp)
923                 return 0;
924 
925         va_start(ap, ifname);
926 
927         /* clear all destination buffers */
928         va_copy(ap_cur, ap);
929 
930         while ((search = va_arg(ap_cur, char *)) != NULL)
931         {
932                 dest = va_arg(ap_cur, char *);
933                 len  = va_arg(ap_cur, int);
934 
935                 memset(dest, 0, len);
936         }
937 
938         va_end(ap_cur);
939 
940         /* iterate applicable lines and copy found values into dest buffers */
941         while (fgets(buf, sizeof(buf), fp))
942         {
943                 key = strtok(buf, " =\t\n");
944                 val = strtok(NULL, "\n");
945 
946                 if (!key || !val || !*key || *key == '#')
947                         continue;
948 
949                 if (!strcmp(key, "interface") || !strcmp(key, "bss"))
950                         match = !strcmp(ifname, val);
951 
952                 if (!match)
953                         continue;
954 
955                 va_copy(ap_cur, ap);
956 
957                 while ((search = va_arg(ap_cur, char *)) != NULL)
958                 {
959                         dest = va_arg(ap_cur, char *);
960                         len  = va_arg(ap_cur, int);
961 
962                         if (!strcmp(search, key))
963                         {
964                                 strncpy(dest, val, len - 1);
965                                 found++;
966                                 break;
967                         }
968                 }
969 
970                 va_end(ap_cur);
971         }
972 
973         fclose(fp);
974 
975         va_end(ap);
976 
977         return found;
978 }
979 
980 #define nl80211_hostapd_query(ifname, ...) \
981         __nl80211_hostapd_query(ifname, ##__VA_ARGS__, NULL)
982 
983 
984 static inline int nl80211_wpactl_recv(int sock, char *buf, int blen)
985 {
986         fd_set rfds;
987         struct timeval tv = { 0, 256000 };
988 
989         FD_ZERO(&rfds);
990         FD_SET(sock, &rfds);
991 
992         memset(buf, 0, blen);
993 
994         if (select(sock + 1, &rfds, NULL, NULL, &tv) < 0)
995                 return -1;
996 
997         if (!FD_ISSET(sock, &rfds))
998                 return -1;
999 
1000         return recv(sock, buf, blen - 1, 0);
1001 }
1002 
1003 static int nl80211_wpactl_connect(const char *ifname, struct sockaddr_un *local)
1004 {
1005         struct sockaddr_un remote = { 0 };
1006         size_t remote_length, local_length;
1007 
1008         int sock = socket(PF_UNIX, SOCK_DGRAM, 0);
1009         if (sock < 0)
1010                 return sock;
1011 
1012         remote.sun_family = AF_UNIX;
1013         remote_length = sizeof(remote.sun_family) +
1014                 sprintf(remote.sun_path, "/var/run/wpa_supplicant/%s", ifname);
1015 
1016         /* Set client socket file permissions so that bind() creates the client
1017         * socket with these permissions and there is no need to try to change
1018         * them with chmod() after bind() which would have potential issues with
1019         * race conditions. These permissions are needed to make sure the server
1020         * side (wpa_supplicant or hostapd) can reply to the control interface
1021         * messages.
1022         *
1023         * The lchown() calls below after bind() are also part of the needed
1024         * operations to allow the response to go through. Those are using the
1025         * no-deference-symlinks version to avoid races. */
1026         fchmod(sock, S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP);
1027 
1028         if (fcntl(sock, F_SETFD, fcntl(sock, F_GETFD) | FD_CLOEXEC) < 0)
1029         {
1030                 close(sock);
1031                 return -1;
1032         }
1033 
1034         if (connect(sock, (struct sockaddr *)&remote, remote_length))
1035         {
1036                 close(sock);
1037                 return -1;
1038         }
1039 
1040         local->sun_family = AF_UNIX;
1041         local_length = sizeof(local->sun_family) +
1042                 sprintf(local->sun_path, "/var/run/iwinfo-%s-%d", ifname, getpid());
1043 
1044         if (bind(sock, (struct sockaddr *)local, local_length) < 0)
1045         {
1046                 close(sock);
1047                 return -1;
1048         }
1049 
1050         /* Set group even if we do not have privileges to change owner */
1051         lchown(local->sun_path, -1, 101);
1052         lchown(local->sun_path, 101, 101);
1053 
1054         return sock;
1055 }
1056 
1057 static int __nl80211_wpactl_query(const char *ifname, ...)
1058 {
1059         va_list ap, ap_cur;
1060         struct sockaddr_un local = { 0 };
1061         int len, mode, found = 0, sock = -1;
1062         char *search, *dest, *key, *val, *line, *pos, buf[512];
1063 
1064         if (nl80211_get_mode(ifname, &mode))
1065                 return 0;
1066 
1067         if (mode != IWINFO_OPMODE_CLIENT &&
1068             mode != IWINFO_OPMODE_ADHOC &&
1069             mode != IWINFO_OPMODE_MESHPOINT)
1070                 return 0;
1071 
1072         sock = nl80211_wpactl_connect(ifname, &local);
1073 
1074         if (sock < 0)
1075                 return 0;
1076 
1077         va_start(ap, ifname);
1078 
1079         /* clear all destination buffers */
1080         va_copy(ap_cur, ap);
1081 
1082         while ((search = va_arg(ap_cur, char *)) != NULL)
1083         {
1084                 dest = va_arg(ap_cur, char *);
1085                 len  = va_arg(ap_cur, int);
1086 
1087                 memset(dest, 0, len);
1088         }
1089 
1090         va_end(ap_cur);
1091 
1092         send(sock, "STATUS", 6, 0);
1093 
1094         while (true)
1095         {
1096                 if (nl80211_wpactl_recv(sock, buf, sizeof(buf)) <= 0)
1097                         break;
1098 
1099                 if (buf[0] == '<')
1100                         continue;
1101 
1102                 for (line = strtok_r(buf, "\n", &pos);
1103                          line != NULL;
1104                          line = strtok_r(NULL, "\n", &pos))
1105                 {
1106                         key = strtok(line, "=");
1107                         val = strtok(NULL, "\n");
1108 
1109                         if (!key || !val)
1110                                 continue;
1111 
1112                         va_copy(ap_cur, ap);
1113 
1114                         while ((search = va_arg(ap_cur, char *)) != NULL)
1115                         {
1116                                 dest = va_arg(ap_cur, char *);
1117                                 len  = va_arg(ap_cur, int);
1118 
1119                                 if (!strcmp(search, key))
1120                                 {
1121                                         strncpy(dest, val, len - 1);
1122                                         found++;
1123                                         break;
1124                                 }
1125                         }
1126 
1127                         va_end(ap_cur);
1128                 }
1129 
1130                 break;
1131         }
1132 
1133         va_end(ap);
1134 
1135         close(sock);
1136         unlink(local.sun_path);
1137 
1138         return found;
1139 }
1140 
1141 #define nl80211_wpactl_query(ifname, ...) \
1142         __nl80211_wpactl_query(ifname, ##__VA_ARGS__, NULL)
1143 
1144 
1145 static char * nl80211_ifadd(const char *ifname)
1146 {
1147         char path[PATH_MAX];
1148         static char nif[IFNAMSIZ] = { 0 };
1149         struct nl80211_msg_conveyor *req;
1150         FILE *sysfs;
1151 
1152         req = nl80211_msg(ifname, NL80211_CMD_NEW_INTERFACE, 0);
1153         if (req)
1154         {
1155                 snprintf(nif, sizeof(nif), "tmp.%s", ifname);
1156 
1157                 NLA_PUT_STRING(req->msg, NL80211_ATTR_IFNAME, nif);
1158                 NLA_PUT_U32(req->msg, NL80211_ATTR_IFTYPE, NL80211_IFTYPE_STATION);
1159 
1160                 nl80211_send(req, NULL, NULL);
1161 
1162                 snprintf(path, sizeof(path) - 1,
1163                          "/proc/sys/net/ipv6/conf/%s/disable_ipv6", nif);
1164 
1165                 if ((sysfs = fopen(path, "w")) != NULL)
1166                 {
1167                         fwrite("\n", 1, 2, sysfs);
1168                         fclose(sysfs);
1169                 }
1170 
1171                 return nif;
1172 
1173         nla_put_failure:
1174                 nl80211_free(req);
1175         }
1176 
1177         return NULL;
1178 }
1179 
1180 static void nl80211_ifdel(const char *ifname)
1181 {
1182         struct nl80211_msg_conveyor *req;
1183 
1184         req = nl80211_msg(ifname, NL80211_CMD_DEL_INTERFACE, 0);
1185         if (req)
1186         {
1187                 NLA_PUT_STRING(req->msg, NL80211_ATTR_IFNAME, ifname);
1188 
1189                 nl80211_send(req, NULL, NULL);
1190                 return;
1191 
1192         nla_put_failure:
1193                 nl80211_free(req);
1194         }
1195 }
1196 
1197 static void nl80211_hostapd_hup(const char *ifname)
1198 {
1199         int fd, pid = 0;
1200         char buf[32];
1201         char *phy = nl80211_ifname2phy(ifname);
1202 
1203         if (phy)
1204         {
1205                 snprintf(buf, sizeof(buf), "/var/run/wifi-%s.pid", phy);
1206                 if ((fd = open(buf, O_RDONLY)) >= 0)
1207                 {
1208                         if (read(fd, buf, sizeof(buf)) > 0)
1209                                 pid = atoi(buf);
1210 
1211                         close(fd);
1212                 }
1213 
1214                 if (pid > 0)
1215                         kill(pid, 1);
1216         }
1217 }
1218 
1219 
1220 static int nl80211_probe(const char *ifname)
1221 {
1222         return !!nl80211_ifname2phy(ifname);
1223 }
1224 
1225 struct nl80211_ssid_bssid {
1226         unsigned char *ssid;
1227         unsigned char bssid[7];
1228 };
1229 
1230 static int nl80211_get_macaddr_cb(struct nl_msg *msg, void *arg)
1231 {
1232         struct nl80211_ssid_bssid *sb = arg;
1233         struct nlattr **tb = nl80211_parse(msg);
1234 
1235         if (tb[NL80211_ATTR_MAC]) {
1236                 sb->bssid[0] = 1;
1237                 memcpy(sb->bssid + 1, nla_data(tb[NL80211_ATTR_MAC]),
1238                        sizeof(sb->bssid) - 1);
1239         }
1240 
1241         return NL_SKIP;
1242 }
1243 
1244 static int nl80211_get_ssid_bssid_cb(struct nl_msg *msg, void *arg)
1245 {
1246         int ielen;
1247         unsigned char *ie;
1248         struct nl80211_ssid_bssid *sb = arg;
1249         struct nlattr **tb = nl80211_parse(msg);
1250         struct nlattr *bss[NL80211_BSS_MAX + 1];
1251 
1252         static const struct nla_policy bss_policy[NL80211_BSS_MAX + 1] = {
1253                 [NL80211_BSS_INFORMATION_ELEMENTS] = { 0 },
1254                 [NL80211_BSS_STATUS]               = { .type = NLA_U32 },
1255         };
1256 
1257         if (!tb[NL80211_ATTR_BSS] ||
1258             nla_parse_nested(bss, NL80211_BSS_MAX, tb[NL80211_ATTR_BSS],
1259                              bss_policy) ||
1260             !bss[NL80211_BSS_BSSID] ||
1261             !bss[NL80211_BSS_STATUS] ||
1262             !bss[NL80211_BSS_INFORMATION_ELEMENTS])
1263         {
1264                 return NL_SKIP;
1265         }
1266 
1267         switch (nla_get_u32(bss[NL80211_BSS_STATUS]))
1268         {
1269         case NL80211_BSS_STATUS_ASSOCIATED:
1270         case NL80211_BSS_STATUS_AUTHENTICATED:
1271         case NL80211_BSS_STATUS_IBSS_JOINED:
1272 
1273                 if (sb->ssid)
1274                 {
1275                         ie = nla_data(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
1276                         ielen = nla_len(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
1277 
1278                         while (ielen >= 2 && ielen >= ie[1])
1279                         {
1280                                 if (ie[0] == 0)
1281                                 {
1282                                         memcpy(sb->ssid, ie + 2, min(ie[1], IWINFO_ESSID_MAX_SIZE));
1283                                         return NL_SKIP;
1284                                 }
1285 
1286                                 ielen -= ie[1] + 2;
1287                                 ie += ie[1] + 2;
1288                         }
1289                 }
1290                 else
1291                 {
1292                         sb->bssid[0] = 1;
1293                         memcpy(sb->bssid + 1, nla_data(bss[NL80211_BSS_BSSID]), 6);
1294                         return NL_SKIP;
1295                 }
1296 
1297         default:
1298                 return NL_SKIP;
1299         }
1300 }
1301 
1302 static int nl80211_get_ssid(const char *ifname, char *buf)
1303 {
1304         char *res;
1305         struct nl80211_ssid_bssid sb = { .ssid = (unsigned char *)buf };
1306 
1307         /* try to find ssid from scan dump results */
1308         res = nl80211_phy2ifname(ifname);
1309         sb.ssid[0] = 0;
1310 
1311         nl80211_request(res ? res : ifname, NL80211_CMD_GET_SCAN, NLM_F_DUMP,
1312                         nl80211_get_ssid_bssid_cb, &sb);
1313 
1314         /* failed, try to find from hostapd info */
1315         if (sb.ssid[0] == 0)
1316                 nl80211_hostapd_query(ifname, "ssid", sb.ssid,
1317                                       IWINFO_ESSID_MAX_SIZE + 1);
1318 
1319         /* failed, try to obtain Mesh ID */
1320         if (sb.ssid[0] == 0)
1321                 iwinfo_ubus_query(res ? res : ifname, "mesh_id",
1322                                   buf, IWINFO_ESSID_MAX_SIZE + 1);
1323 
1324         return (sb.ssid[0] == 0) ? -1 : 0;
1325 }
1326 
1327 static int nl80211_get_bssid(const char *ifname, char *buf)
1328 {
1329         char *res, bssid[sizeof("FF:FF:FF:FF:FF:FF\0")];
1330         struct nl80211_ssid_bssid sb = { };
1331 
1332         res = nl80211_phy2ifname(ifname);
1333 
1334         /* try to obtain mac address via NL80211_CMD_GET_INTERFACE */
1335         nl80211_request(res ? res : ifname, NL80211_CMD_GET_INTERFACE, 0,
1336                         nl80211_get_macaddr_cb, &sb);
1337 
1338         /* failed, try to find bssid from scan dump results */
1339         if (sb.bssid[0] == 0)
1340                 nl80211_request(res ? res : ifname,
1341                                 NL80211_CMD_GET_SCAN, NLM_F_DUMP,
1342                                 nl80211_get_ssid_bssid_cb, &sb);
1343 
1344         /* failed, try to find mac from hostapd info */
1345         if ((sb.bssid[0] == 0) &&
1346             nl80211_hostapd_query(ifname, "bssid", bssid, sizeof(bssid)))
1347         {
1348                 sb.bssid[0] = 1;
1349                 sb.bssid[1] = strtol(&bssid[0],  NULL, 16);
1350                 sb.bssid[2] = strtol(&bssid[3],  NULL, 16);
1351                 sb.bssid[3] = strtol(&bssid[6],  NULL, 16);
1352                 sb.bssid[4] = strtol(&bssid[9],  NULL, 16);
1353                 sb.bssid[5] = strtol(&bssid[12], NULL, 16);
1354                 sb.bssid[6] = strtol(&bssid[15], NULL, 16);
1355         }
1356 
1357         if (sb.bssid[0])
1358         {
1359                 sprintf(buf, "%02X:%02X:%02X:%02X:%02X:%02X",
1360                         sb.bssid[1], sb.bssid[2], sb.bssid[3],
1361                         sb.bssid[4], sb.bssid[5], sb.bssid[6]);
1362 
1363                 return 0;
1364         }
1365 
1366         return -1;
1367 }
1368 
1369 
1370 static int nl80211_get_frequency_scan_cb(struct nl_msg *msg, void *arg)
1371 {
1372         int *freq = arg;
1373         struct nlattr **attr = nl80211_parse(msg);
1374         struct nlattr *binfo[NL80211_BSS_MAX + 1];
1375 
1376         static const struct nla_policy bss_policy[NL80211_BSS_MAX + 1] = {
1377                 [NL80211_BSS_FREQUENCY] = { .type = NLA_U32 },
1378                 [NL80211_BSS_STATUS]    = { .type = NLA_U32 },
1379         };
1380 
1381         if (attr[NL80211_ATTR_BSS] &&
1382             !nla_parse_nested(binfo, NL80211_BSS_MAX,
1383                               attr[NL80211_ATTR_BSS], bss_policy))
1384         {
1385                 if (binfo[NL80211_BSS_STATUS] && binfo[NL80211_BSS_FREQUENCY])
1386                         *freq = nla_get_u32(binfo[NL80211_BSS_FREQUENCY]);
1387         }
1388 
1389         return NL_SKIP;
1390 }
1391 
1392 static int nl80211_get_frequency_info_cb(struct nl_msg *msg, void *arg)
1393 {
1394         int *freq = arg;
1395         struct nlattr **tb = nl80211_parse(msg);
1396 
1397         if (tb[NL80211_ATTR_WIPHY_FREQ])
1398                 *freq = nla_get_u32(tb[NL80211_ATTR_WIPHY_FREQ]);
1399 
1400         return NL_SKIP;
1401 }
1402 
1403 static int nl80211_get_frequency(const char *ifname, int *buf)
1404 {
1405         char *res, channel[4] = { 0 }, hwmode[3] = { 0 }, ax[2] = { 0 };
1406 
1407         /* try to find frequency from interface info */
1408         res = nl80211_phy2ifname(ifname);
1409         *buf = 0;
1410 
1411         nl80211_request(res ? res : ifname, NL80211_CMD_GET_INTERFACE, 0,
1412                         nl80211_get_frequency_info_cb, buf);
1413 
1414         /* failed, try to find frequency from hostapd info */
1415         if ((*buf == 0) &&
1416             nl80211_hostapd_query(ifname, "hw_mode", hwmode, sizeof(hwmode),
1417                                           "channel", channel, sizeof(channel),
1418                                           "ieee80211ax", ax, sizeof(ax)) >= 2)
1419         {
1420                 *buf = nl80211_channel2freq(atoi(channel), hwmode, ax[0] == '1');
1421         }
1422 
1423         /* failed, try to find frequency from scan results */
1424         if (*buf == 0)
1425         {
1426                 res = nl80211_phy2ifname(ifname);
1427 
1428                 nl80211_request(res ? res : ifname, NL80211_CMD_GET_SCAN, NLM_F_DUMP,
1429                                 nl80211_get_frequency_scan_cb, buf);
1430         }
1431 
1432         return (*buf == 0) ? -1 : 0;
1433 }
1434 
1435 static int nl80211_get_center_freq1_cb(struct nl_msg *msg, void *arg)
1436 {
1437         int *freq = arg;
1438         struct nlattr **tb = nl80211_parse(msg);
1439 
1440         if (tb[NL80211_ATTR_CENTER_FREQ1])
1441                 *freq = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ1]);
1442 
1443         return NL_SKIP;
1444 }
1445 
1446 static int nl80211_get_center_freq1(const char *ifname, int *buf)
1447 {
1448         char *res;
1449 
1450         /* try to find frequency from interface info */
1451         res = nl80211_phy2ifname(ifname);
1452         *buf = 0;
1453 
1454         nl80211_request(res ? res : ifname, NL80211_CMD_GET_INTERFACE, 0,
1455                         nl80211_get_center_freq1_cb, buf);
1456 
1457         return (*buf == 0) ? -1 : 0;
1458 }
1459 
1460 static int nl80211_get_center_freq2_cb(struct nl_msg *msg, void *arg)
1461 {
1462         int *freq = arg;
1463         struct nlattr **tb = nl80211_parse(msg);
1464 
1465         if (tb[NL80211_ATTR_CENTER_FREQ2])
1466                 *freq = nla_get_u32(tb[NL80211_ATTR_CENTER_FREQ2]);
1467 
1468         return NL_SKIP;
1469 }
1470 
1471 static int nl80211_get_center_freq2(const char *ifname, int *buf)
1472 {
1473         char *res;
1474 
1475         /* try to find frequency from interface info */
1476         res = nl80211_phy2ifname(ifname);
1477         *buf = 0;
1478 
1479         nl80211_request(res ? res : ifname, NL80211_CMD_GET_INTERFACE, 0,
1480                         nl80211_get_center_freq2_cb, buf);
1481 
1482         return (*buf == 0) ? -1 : 0;
1483 }
1484 
1485 static int nl80211_get_channel(const char *ifname, int *buf)
1486 {
1487         if (!nl80211_get_frequency(ifname, buf))
1488         {
1489                 *buf = nl80211_freq2channel(*buf);
1490                 return 0;
1491         }
1492 
1493         return -1;
1494 }
1495 
1496 static int nl80211_get_center_chan1(const char *ifname, int *buf)
1497 {
1498         if (!nl80211_get_center_freq1(ifname, buf))
1499         {
1500                 *buf = nl80211_freq2channel(*buf);
1501                 return 0;
1502         }
1503 
1504         return -1;
1505 }
1506 
1507 static int nl80211_get_center_chan2(const char *ifname, int *buf)
1508 {
1509         if (!nl80211_get_center_freq2(ifname, buf))
1510         {
1511                 *buf = nl80211_freq2channel(*buf);
1512                 return 0;
1513         }
1514 
1515         return -1;
1516 }
1517 
1518 static int nl80211_get_txpower_cb(struct nl_msg *msg, void *arg)
1519 {
1520         int *buf = arg;
1521         struct nlattr **tb = nl80211_parse(msg);
1522 
1523         if (tb[NL80211_ATTR_WIPHY_TX_POWER_LEVEL])
1524                 *buf = iwinfo_mbm2dbm(nla_get_u32(tb[NL80211_ATTR_WIPHY_TX_POWER_LEVEL]));
1525 
1526         return NL_SKIP;
1527 }
1528 
1529 static int nl80211_get_txpower(const char *ifname, int *buf)
1530 {
1531         char *res;
1532 
1533         res = nl80211_phy2ifname(ifname);
1534         *buf = 0;
1535 
1536         if (nl80211_request(res ? res : ifname, NL80211_CMD_GET_INTERFACE, 0,
1537                             nl80211_get_txpower_cb, buf))
1538                 return -1;
1539 
1540         return 0;
1541 }
1542 
1543 
1544 static int nl80211_fill_signal_cb(struct nl_msg *msg, void *arg)
1545 {
1546         int8_t dbm;
1547         int16_t mbit;
1548         struct nl80211_rssi_rate *rr = arg;
1549         struct nlattr **attr = nl80211_parse(msg);
1550         struct nlattr *sinfo[NL80211_STA_INFO_MAX + 1];
1551         struct nlattr *rinfo[NL80211_RATE_INFO_MAX + 1];
1552 
1553         static const struct nla_policy stats_policy[NL80211_STA_INFO_MAX + 1] = {
1554                 [NL80211_STA_INFO_INACTIVE_TIME] = { .type = NLA_U32    },
1555                 [NL80211_STA_INFO_RX_BYTES]      = { .type = NLA_U32    },
1556                 [NL80211_STA_INFO_TX_BYTES]      = { .type = NLA_U32    },
1557                 [NL80211_STA_INFO_RX_BYTES64]    = { .type = NLA_U64    },
1558                 [NL80211_STA_INFO_TX_BYTES64]    = { .type = NLA_U64    },
1559                 [NL80211_STA_INFO_RX_PACKETS]    = { .type = NLA_U32    },
1560                 [NL80211_STA_INFO_TX_PACKETS]    = { .type = NLA_U32    },
1561                 [NL80211_STA_INFO_SIGNAL]        = { .type = NLA_U8     },
1562                 [NL80211_STA_INFO_TX_BITRATE]    = { .type = NLA_NESTED },
1563                 [NL80211_STA_INFO_LLID]          = { .type = NLA_U16    },
1564                 [NL80211_STA_INFO_PLID]          = { .type = NLA_U16    },
1565                 [NL80211_STA_INFO_PLINK_STATE]   = { .type = NLA_U8     },
1566         };
1567 
1568         static const struct nla_policy rate_policy[NL80211_RATE_INFO_MAX + 1] = {
1569                 [NL80211_RATE_INFO_BITRATE]      = { .type = NLA_U16  },
1570                 [NL80211_RATE_INFO_MCS]          = { .type = NLA_U8   },
1571                 [NL80211_RATE_INFO_40_MHZ_WIDTH] = { .type = NLA_FLAG },
1572                 [NL80211_RATE_INFO_SHORT_GI]     = { .type = NLA_FLAG },
1573         };
1574 
1575         if (attr[NL80211_ATTR_STA_INFO])
1576         {
1577                 if (!nla_parse_nested(sinfo, NL80211_STA_INFO_MAX,
1578                                       attr[NL80211_ATTR_STA_INFO], stats_policy))
1579                 {
1580                         if (sinfo[NL80211_STA_INFO_SIGNAL])
1581                         {
1582                                 dbm = nla_get_u8(sinfo[NL80211_STA_INFO_SIGNAL]);
1583                                 rr->rssi = (rr->rssi * rr->rssi_samples + dbm) / (rr->rssi_samples + 1);
1584                                 rr->rssi_samples++;
1585                         }
1586 
1587                         if (sinfo[NL80211_STA_INFO_TX_BITRATE])
1588                         {
1589                                 if (!nla_parse_nested(rinfo, NL80211_RATE_INFO_MAX,
1590                                                       sinfo[NL80211_STA_INFO_TX_BITRATE],
1591                                                       rate_policy))
1592                                 {
1593                                         if (rinfo[NL80211_RATE_INFO_BITRATE])
1594                                         {
1595                                                 mbit = nla_get_u16(rinfo[NL80211_RATE_INFO_BITRATE]);
1596                                                 rr->rate = (rr->rate * rr->rate_samples + mbit) / (rr->rate_samples + 1);
1597                                                 rr->rate_samples++;
1598                                         }
1599                                 }
1600                         }
1601                 }
1602         }
1603 
1604         return NL_SKIP;
1605 }
1606 
1607 static void nl80211_fill_signal(const char *ifname, struct nl80211_rssi_rate *r)
1608 {
1609         DIR *d;
1610         struct dirent *de;
1611 
1612         memset(r, 0, sizeof(*r));
1613 
1614         if ((d = opendir("/sys/class/net")) != NULL)
1615         {
1616                 while ((de = readdir(d)) != NULL)
1617                 {
1618                         if (!strncmp(de->d_name, ifname, strlen(ifname)) &&
1619                             (!de->d_name[strlen(ifname)] ||
1620                              !strncmp(&de->d_name[strlen(ifname)], ".sta", 4)))
1621                         {
1622                                 nl80211_request(de->d_name, NL80211_CMD_GET_STATION,
1623                                                 NLM_F_DUMP, nl80211_fill_signal_cb, r);
1624                         }
1625                 }
1626 
1627                 closedir(d);
1628         }
1629 }
1630 
1631 static int nl80211_get_bitrate(const char *ifname, int *buf)
1632 {
1633         struct nl80211_rssi_rate rr;
1634 
1635         nl80211_fill_signal(ifname, &rr);
1636 
1637         if (rr.rate_samples)
1638         {
1639                 *buf = (rr.rate * 100);
1640                 return 0;
1641         }
1642 
1643         return -1;
1644 }
1645 
1646 static int nl80211_get_signal(const char *ifname, int *buf)
1647 {
1648         struct nl80211_rssi_rate rr;
1649 
1650         nl80211_fill_signal(ifname, &rr);
1651 
1652         if (rr.rssi_samples)
1653         {
1654                 *buf = rr.rssi;
1655                 return 0;
1656         }
1657 
1658         return -1;
1659 }
1660 
1661 struct nl80211_frequency_noise {
1662         uint32_t frequency;
1663         uint8_t noise;
1664 };
1665 
1666 static int nl80211_get_noise_cb(struct nl_msg *msg, void *arg)
1667 {
1668         struct nl80211_frequency_noise *fn = arg;
1669         struct nlattr **tb = nl80211_parse(msg);
1670         struct nlattr *si[NL80211_SURVEY_INFO_MAX + 1];
1671 
1672         static const struct nla_policy sp[NL80211_SURVEY_INFO_MAX + 1] = {
1673                 [NL80211_SURVEY_INFO_FREQUENCY] = { .type = NLA_U32 },
1674                 [NL80211_SURVEY_INFO_NOISE]     = { .type = NLA_U8  },
1675         };
1676 
1677         if (!tb[NL80211_ATTR_SURVEY_INFO])
1678                 return NL_SKIP;
1679 
1680         if (nla_parse_nested(si, NL80211_SURVEY_INFO_MAX,
1681                              tb[NL80211_ATTR_SURVEY_INFO], sp))
1682                 return NL_SKIP;
1683 
1684         if (!si[NL80211_SURVEY_INFO_NOISE] ||
1685             !si[NL80211_SURVEY_INFO_FREQUENCY])
1686                 return NL_SKIP;
1687 
1688         if (nla_get_u32(si[NL80211_SURVEY_INFO_FREQUENCY]) != fn->frequency)
1689                 return NL_SKIP;
1690 
1691         if (!fn->noise || si[NL80211_SURVEY_INFO_IN_USE])
1692                 fn->noise = nla_get_u8(si[NL80211_SURVEY_INFO_NOISE]);
1693 
1694         return NL_SKIP;
1695 }
1696 
1697 
1698 static int nl80211_get_noise(const char *ifname, int *buf)
1699 {
1700         struct nl80211_frequency_noise fn = { };
1701 
1702         if (nl80211_get_frequency(ifname, (int *)&fn.frequency) < 0)
1703                 goto out;
1704 
1705         if (nl80211_request(ifname, NL80211_CMD_GET_SURVEY, NLM_F_DUMP,
1706                             nl80211_get_noise_cb, &fn))
1707                 goto out;
1708 
1709         *buf = (int8_t)fn.noise;
1710         return 0;
1711 
1712 out:
1713         *buf = 0;
1714         return -1;
1715 }
1716 
1717 static int nl80211_get_quality(const char *ifname, int *buf)
1718 {
1719         int signal;
1720 
1721         if (!nl80211_get_signal(ifname, &signal))
1722         {
1723                 /* A positive signal level is usually just a quality
1724                  * value, pass through as-is */
1725                 if (signal >= 0)
1726                 {
1727                         *buf = signal;
1728                 }
1729 
1730                 /* The cfg80211 wext compat layer assumes a signal range
1731                  * of -110 dBm to -40 dBm, the quality value is derived
1732                  * by adding 110 to the signal level */
1733                 else
1734                 {
1735                         if (signal < -110)
1736                                 signal = -110;
1737                         else if (signal > -40)
1738                                 signal = -40;
1739 
1740                         *buf = (signal + 110);
1741                 }
1742 
1743                 return 0;
1744         }
1745 
1746         return -1;
1747 }
1748 
1749 static int nl80211_get_quality_max(const char *ifname, int *buf)
1750 {
1751         /* The cfg80211 wext compat layer assumes a maximum
1752          * quality of 70 */
1753         *buf = 70;
1754 
1755         return 0;
1756 }
1757 
1758 static int nl80211_check_wepkey(const char *key)
1759 {
1760         if (key && *key)
1761         {
1762                 switch (strlen(key))
1763                 {
1764                 case 5:
1765                 case 10:
1766                         return IWINFO_CIPHER_WEP40;
1767 
1768                 case 13:
1769                 case 26:
1770                         return IWINFO_CIPHER_WEP104;
1771                 }
1772         }
1773 
1774         return 0;
1775 }
1776 
1777 static const struct {
1778         const char *match;
1779         int version;
1780         int suite;
1781 } wpa_key_mgmt_strings[] = {
1782         { "IEEE 802.1X/EAP", 0, IWINFO_KMGMT_8021x },
1783         { "EAP-SUITE-B-192", 4, IWINFO_KMGMT_8021x },
1784         { "EAP-SUITE-B",     4, IWINFO_KMGMT_8021x },
1785         { "EAP-SHA384",      4, IWINFO_KMGMT_8021x },
1786         { "EAP-SHA256",      0, IWINFO_KMGMT_8021x },
1787         { "PSK-SHA256",      0, IWINFO_KMGMT_PSK },
1788         { "NONE",            0, IWINFO_KMGMT_NONE },
1789         { "None",            0, IWINFO_KMGMT_NONE },
1790         { "PSK",             0, IWINFO_KMGMT_PSK },
1791         { "EAP",             0, IWINFO_KMGMT_8021x },
1792         { "SAE",             4, IWINFO_KMGMT_SAE },
1793         { "OWE",             4, IWINFO_KMGMT_OWE }
1794 };
1795 
1796 static void parse_wpa_suites(const char *str, int defversion,
1797                              uint8_t *versions, uint8_t *suites)
1798 {
1799         size_t l;
1800         int i, version;
1801         const char *p, *q, *m, *sep = " \t\n,-+/";
1802 
1803         for (p = str; *p; )
1804         {
1805                 q = p;
1806 
1807                 for (i = 0; i < ARRAY_SIZE(wpa_key_mgmt_strings); i++)
1808                 {
1809                         m = wpa_key_mgmt_strings[i].match;
1810                         l = strlen(m);
1811 
1812                         if (!strncmp(q, m, l) && (!q[l] || strchr(sep, q[l])))
1813                         {
1814                                 if (wpa_key_mgmt_strings[i].version != 0)
1815                                         version = wpa_key_mgmt_strings[i].version;
1816                                 else
1817                                         version = defversion;
1818 
1819                                 *versions |= version;
1820                                 *suites |= wpa_key_mgmt_strings[i].suite;
1821 
1822                                 q += l;
1823                                 break;
1824                         }
1825                 }
1826 
1827                 if (q == p)
1828                         q += strcspn(q, sep);
1829 
1830                 p = q + strspn(q, sep);
1831         }
1832 }
1833 
1834 static const struct {
1835         const char *match;
1836         int cipher;
1837 } wpa_cipher_strings[] = {
1838         { "WEP-104", IWINFO_CIPHER_WEP104  },
1839         { "WEP-40",  IWINFO_CIPHER_WEP40   },
1840         { "NONE",    IWINFO_CIPHER_NONE    },
1841         { "TKIP",    IWINFO_CIPHER_TKIP    },
1842         { "CCMP-256",IWINFO_CIPHER_CCMP256 },
1843         { "CCMP",    IWINFO_CIPHER_CCMP    },
1844         { "GCMP-256",IWINFO_CIPHER_GCMP256 },
1845         { "GCMP",    IWINFO_CIPHER_GCMP    }
1846 };
1847 
1848 static void parse_wpa_ciphers(const char *str, uint16_t *ciphers)
1849 {
1850         int i;
1851         size_t l;
1852         const char *m, *p, *q, *sep = " \t\n,-+/";
1853 
1854         for (p = str; *p; )
1855         {
1856                 q = p;
1857 
1858                 for (i = 0; i < ARRAY_SIZE(wpa_cipher_strings); i++)
1859                 {
1860                         m = wpa_cipher_strings[i].match;
1861                         l = strlen(m);
1862 
1863                         if (!strncmp(q, m, l) && (!q[l] || strchr(sep, q[l])))
1864                         {
1865                                 *ciphers |= wpa_cipher_strings[i].cipher;
1866 
1867                                 q += l;
1868                                 break;
1869                         }
1870                 }
1871 
1872                 if (q == p)
1873                         q += strcspn(q, sep);
1874 
1875                 p = q + strspn(q, sep);
1876         }
1877 }
1878 
1879 static int nl80211_get_encryption(const char *ifname, char *buf)
1880 {
1881         char *p;
1882         int opmode;
1883         uint8_t wpa_version = 0;
1884         char wpa[2], wpa_key_mgmt[64], wpa_pairwise[16], wpa_groupwise[16];
1885         char auth_algs[2], wep_key0[27], wep_key1[27], wep_key2[27], wep_key3[27];
1886         char mode[16];
1887 
1888         struct iwinfo_crypto_entry *c = (struct iwinfo_crypto_entry *)buf;
1889 
1890         /* WPA supplicant */
1891         if (nl80211_wpactl_query(ifname,
1892                         "pairwise_cipher", wpa_pairwise,  sizeof(wpa_pairwise),
1893                         "group_cipher",    wpa_groupwise, sizeof(wpa_groupwise),
1894                         "key_mgmt",        wpa_key_mgmt,  sizeof(wpa_key_mgmt),
1895                         "mode",            mode,          sizeof(mode)))
1896         {
1897                 /* WEP or Open */
1898                 if (!strcmp(wpa_key_mgmt, "NONE"))
1899                 {
1900                         parse_wpa_ciphers(wpa_pairwise, &c->pair_ciphers);
1901                         parse_wpa_ciphers(wpa_groupwise, &c->group_ciphers);
1902 
1903                         if (c->pair_ciphers != 0 && c->pair_ciphers != IWINFO_CIPHER_NONE) {
1904                                 c->enabled     = 1;
1905                                 c->auth_suites = IWINFO_KMGMT_NONE;
1906                                 c->auth_algs   = IWINFO_AUTH_OPEN | IWINFO_AUTH_SHARED;
1907                         }
1908                         else {
1909                                 c->pair_ciphers = 0;
1910                                 c->group_ciphers = 0;
1911                         }
1912                 }
1913 
1914                 /* MESH with SAE */
1915                 else if (!strcmp(mode, "mesh") && !strcmp(wpa_key_mgmt, "UNKNOWN"))
1916                 {
1917                         c->enabled = 1;
1918                         c->wpa_version = 4;
1919                         c->auth_suites = IWINFO_KMGMT_SAE;
1920                         c->pair_ciphers = IWINFO_CIPHER_CCMP;
1921                         c->group_ciphers = IWINFO_CIPHER_CCMP;
1922                 }
1923 
1924                 /* WPA */
1925                 else
1926                 {
1927                         parse_wpa_ciphers(wpa_pairwise, &c->pair_ciphers);
1928                         parse_wpa_ciphers(wpa_groupwise, &c->group_ciphers);
1929 
1930                         p = wpa_key_mgmt;
1931 
1932                         if (!strncmp(p, "WPA2-", 5) || !strncmp(p, "WPA2/", 5))
1933                         {
1934                                 p += 5;
1935                                 wpa_version = 2;
1936                         }
1937                         else if (!strncmp(p, "WPA-", 4))
1938                         {
1939                                 p += 4;
1940                                 wpa_version = 1;
1941                         }
1942 
1943                         parse_wpa_suites(p, wpa_version, &c->wpa_version, &c->auth_suites);
1944 
1945                         c->enabled = !!(c->wpa_version && c->auth_suites);
1946                 }
1947 
1948                 return 0;
1949         }
1950 
1951         /* Hostapd */
1952         else if (nl80211_hostapd_query(ifname,
1953                                 "wpa",          wpa,          sizeof(wpa),
1954                                 "wpa_key_mgmt", wpa_key_mgmt, sizeof(wpa_key_mgmt),
1955                                 "wpa_pairwise", wpa_pairwise, sizeof(wpa_pairwise),
1956                                 "auth_algs",    auth_algs,    sizeof(auth_algs),
1957                                 "wep_key0",     wep_key0,     sizeof(wep_key0),
1958                                 "wep_key1",     wep_key1,     sizeof(wep_key1),
1959                                 "wep_key2",     wep_key2,     sizeof(wep_key2),
1960                                 "wep_key3",     wep_key3,     sizeof(wep_key3)))
1961         {
1962                 c->wpa_version = 0;
1963 
1964                 if (wpa_key_mgmt[0])
1965                 {
1966                         for (p = strtok(wpa_key_mgmt, " \t"); p != NULL; p = strtok(NULL, " \t"))
1967                         {
1968                                 if (!strncmp(p, "WPA-", 4))
1969                                         p += 4;
1970 
1971                                 if (!strncmp(p, "FT-", 3))
1972                                         p += 3;
1973 
1974                                 parse_wpa_suites(p, atoi(wpa), &c->wpa_version, &c->auth_suites);
1975                         }
1976 
1977                         c->enabled = c->wpa_version ? 1 : 0;
1978                 }
1979 
1980                 if (wpa_pairwise[0])
1981                         parse_wpa_ciphers(wpa_pairwise, &c->pair_ciphers);
1982 
1983                 if (auth_algs[0])
1984                 {
1985                         switch (atoi(auth_algs))
1986                         {
1987                         case 1:
1988                                 c->auth_algs |= IWINFO_AUTH_OPEN;
1989                                 break;
1990 
1991                         case 2:
1992                                 c->auth_algs |= IWINFO_AUTH_SHARED;
1993                                 break;
1994 
1995                         case 3:
1996                                 c->auth_algs |= IWINFO_AUTH_OPEN;
1997                                 c->auth_algs |= IWINFO_AUTH_SHARED;
1998                                 break;
1999                         }
2000 
2001                         c->pair_ciphers |= nl80211_check_wepkey(wep_key0);
2002                         c->pair_ciphers |= nl80211_check_wepkey(wep_key1);
2003                         c->pair_ciphers |= nl80211_check_wepkey(wep_key2);
2004                         c->pair_ciphers |= nl80211_check_wepkey(wep_key3);
2005 
2006                         c->enabled = (c->auth_algs && c->pair_ciphers) ? 1 : 0;
2007                 }
2008 
2009                 c->group_ciphers = c->pair_ciphers;
2010 
2011                 return 0;
2012         }
2013 
2014         /* Ad-Hoc or Mesh interfaces without wpa_supplicant are open */
2015         else if (!nl80211_get_mode(ifname, &opmode) &&
2016                  (opmode == IWINFO_OPMODE_ADHOC ||
2017                   opmode == IWINFO_OPMODE_MESHPOINT))
2018         {
2019                 c->enabled = 0;
2020 
2021                 return 0;
2022         }
2023 
2024 
2025         return -1;
2026 }
2027 
2028 static int nl80211_get_phyname(const char *ifname, char *buf)
2029 {
2030         const char *name;
2031 
2032         name = nl80211_ifname2phy(ifname);
2033 
2034         if (name)
2035         {
2036                 strcpy(buf, name);
2037                 return 0;
2038         }
2039         else if ((name = nl80211_phy2ifname(ifname)) != NULL)
2040         {
2041                 name = nl80211_ifname2phy(name);
2042 
2043                 if (name)
2044                 {
2045                         strcpy(buf, ifname);
2046                         return 0;
2047                 }
2048         }
2049 
2050         return -1;
2051 }
2052 
2053 
2054 static void nl80211_parse_rateinfo(struct nlattr **ri,
2055                                    struct iwinfo_rate_entry *re)
2056 {
2057         if (ri[NL80211_RATE_INFO_BITRATE32])
2058                 re->rate = nla_get_u32(ri[NL80211_RATE_INFO_BITRATE32]) * 100;
2059         else if (ri[NL80211_RATE_INFO_BITRATE])
2060                 re->rate = nla_get_u16(ri[NL80211_RATE_INFO_BITRATE]) * 100;
2061 
2062         if (ri[NL80211_RATE_INFO_EHT_MCS])
2063         {
2064                 re->is_eht = 1;
2065                 re->mcs = nla_get_u8(ri[NL80211_RATE_INFO_EHT_MCS]);
2066 
2067                 if (ri[NL80211_RATE_INFO_EHT_NSS])
2068                         re->nss = nla_get_u8(ri[NL80211_RATE_INFO_EHT_NSS]);
2069                 if (ri[NL80211_RATE_INFO_EHT_GI])
2070                         re->eht_gi = nla_get_u8(ri[NL80211_RATE_INFO_EHT_GI]);
2071         }
2072         else if (ri[NL80211_RATE_INFO_HE_MCS])
2073         {
2074                 re->is_he = 1;
2075                 re->mcs = nla_get_u8(ri[NL80211_RATE_INFO_HE_MCS]);
2076 
2077                 if (ri[NL80211_RATE_INFO_HE_NSS])
2078                         re->nss = nla_get_u8(ri[NL80211_RATE_INFO_HE_NSS]);
2079                 if (ri[NL80211_RATE_INFO_HE_GI])
2080                         re->he_gi = nla_get_u8(ri[NL80211_RATE_INFO_HE_GI]);
2081                 if (ri[NL80211_RATE_INFO_HE_DCM])
2082                         re->he_dcm = nla_get_u8(ri[NL80211_RATE_INFO_HE_DCM]);
2083         }
2084         else if (ri[NL80211_RATE_INFO_VHT_MCS])
2085         {
2086                 re->is_vht = 1;
2087                 re->mcs = nla_get_u8(ri[NL80211_RATE_INFO_VHT_MCS]);
2088 
2089                 if (ri[NL80211_RATE_INFO_VHT_NSS])
2090                         re->nss = nla_get_u8(ri[NL80211_RATE_INFO_VHT_NSS]);
2091         }
2092         else if (ri[NL80211_RATE_INFO_MCS])
2093         {
2094                 re->is_ht = 1;
2095                 re->mcs = nla_get_u8(ri[NL80211_RATE_INFO_MCS]);
2096         }
2097 
2098         if (ri[NL80211_RATE_INFO_5_MHZ_WIDTH])
2099                 re->mhz = 5;
2100         else if (ri[NL80211_RATE_INFO_10_MHZ_WIDTH])
2101                 re->mhz = 10;
2102         else if (ri[NL80211_RATE_INFO_40_MHZ_WIDTH])
2103                 re->mhz = 40;
2104         else if (ri[NL80211_RATE_INFO_80_MHZ_WIDTH])
2105                 re->mhz = 80;
2106         else if (ri[NL80211_RATE_INFO_80P80_MHZ_WIDTH] ||
2107                  ri[NL80211_RATE_INFO_160_MHZ_WIDTH])
2108                 re->mhz = 160;
2109         else if (ri[NL80211_RATE_INFO_320_MHZ_WIDTH])
2110                 re->mhz_hi = 320 / 256, re->mhz = 320 % 256;
2111         else
2112                 re->mhz = 20;
2113 
2114         if (ri[NL80211_RATE_INFO_SHORT_GI])
2115                 re->is_short_gi = 1;
2116 
2117         re->is_40mhz = (re->mhz == 40);
2118 }
2119 
2120 static int nl80211_get_survey_cb(struct nl_msg *msg, void *arg)
2121 {
2122         struct nl80211_array_buf *arr = arg;
2123         struct iwinfo_survey_entry *e = arr->buf;
2124         struct nlattr **attr = nl80211_parse(msg);
2125         struct nlattr *sinfo[NL80211_SURVEY_INFO_MAX + 1];
2126         int rc;
2127 
2128         static const struct nla_policy survey_policy[NL80211_SURVEY_INFO_MAX + 1] = {
2129                 [NL80211_SURVEY_INFO_FREQUENCY] = { .type = NLA_U32 },
2130                 [NL80211_SURVEY_INFO_NOISE]  = { .type = NLA_U8     },
2131                 [NL80211_SURVEY_INFO_TIME] = { .type = NLA_U64   },
2132                 [NL80211_SURVEY_INFO_TIME_BUSY] = { .type = NLA_U64   },
2133                 [NL80211_SURVEY_INFO_TIME_EXT_BUSY] = { .type = NLA_U64   },
2134                 [NL80211_SURVEY_INFO_TIME_RX] = { .type = NLA_U64   },
2135                 [NL80211_SURVEY_INFO_TIME_TX] = { .type = NLA_U64   },
2136         };
2137 
2138         rc = nla_parse_nested(sinfo, NL80211_SURVEY_INFO_MAX,
2139                                 attr[NL80211_ATTR_SURVEY_INFO],
2140                                 survey_policy);
2141         if (rc)
2142                 return NL_SKIP;
2143 
2144         /* advance to end of array */
2145         e += arr->count;
2146         memset(e, 0, sizeof(*e));
2147 
2148         if (sinfo[NL80211_SURVEY_INFO_FREQUENCY])
2149                 e->mhz = nla_get_u32(sinfo[NL80211_SURVEY_INFO_FREQUENCY]);
2150 
2151         if (sinfo[NL80211_SURVEY_INFO_NOISE])
2152                 e->noise = nla_get_u8(sinfo[NL80211_SURVEY_INFO_NOISE]);
2153 
2154         if (sinfo[NL80211_SURVEY_INFO_TIME])
2155                 e->active_time = nla_get_u64(sinfo[NL80211_SURVEY_INFO_TIME]);
2156 
2157         if (sinfo[NL80211_SURVEY_INFO_TIME_BUSY])
2158                 e->busy_time = nla_get_u64(sinfo[NL80211_SURVEY_INFO_TIME_BUSY]);
2159 
2160         if (sinfo[NL80211_SURVEY_INFO_TIME_EXT_BUSY])
2161                 e->busy_time_ext = nla_get_u64(sinfo[NL80211_SURVEY_INFO_TIME_EXT_BUSY]);
2162 
2163         if (sinfo[NL80211_SURVEY_INFO_TIME_RX])
2164                 e->rxtime = nla_get_u64(sinfo[NL80211_SURVEY_INFO_TIME_RX]);
2165 
2166         if (sinfo[NL80211_SURVEY_INFO_TIME_TX])
2167                 e->txtime = nla_get_u64(sinfo[NL80211_SURVEY_INFO_TIME_TX]);
2168 
2169         arr->count++;
2170         return NL_SKIP;
2171 }
2172 
2173 
2174 static void plink_state_to_str(char *dst, unsigned state)
2175 {
2176         switch (state) {
2177         case NL80211_PLINK_LISTEN:
2178                 strcpy(dst, "LISTEN");
2179                 break;
2180         case NL80211_PLINK_OPN_SNT:
2181                 strcpy(dst, "OPN_SNT");
2182                 break;
2183         case NL80211_PLINK_OPN_RCVD:
2184                 strcpy(dst, "OPN_RCVD");
2185                 break;
2186         case NL80211_PLINK_CNF_RCVD:
2187                 strcpy(dst, "CNF_RCVD");
2188                 break;
2189         case NL80211_PLINK_ESTAB:
2190                 strcpy(dst, "ESTAB");
2191                 break;
2192         case NL80211_PLINK_HOLDING:
2193                 strcpy(dst, "HOLDING");
2194                 break;
2195         case NL80211_PLINK_BLOCKED:
2196                 strcpy(dst, "BLOCKED");
2197                 break;
2198         default:
2199                 strcpy(dst, "UNKNOWN");
2200                 break;
2201         }
2202 }
2203 
2204 static void power_mode_to_str(char *dst, struct nlattr *a)
2205 {
2206         enum nl80211_mesh_power_mode pm = nla_get_u32(a);
2207 
2208         switch (pm) {
2209         case NL80211_MESH_POWER_ACTIVE:
2210                 strcpy(dst, "ACTIVE");
2211                 break;
2212         case NL80211_MESH_POWER_LIGHT_SLEEP:
2213                 strcpy(dst, "LIGHT SLEEP");
2214                 break;
2215         case NL80211_MESH_POWER_DEEP_SLEEP:
2216                 strcpy(dst, "DEEP SLEEP");
2217                 break;
2218         default:
2219                 strcpy(dst, "UNKNOWN");
2220                 break;
2221         }
2222 }
2223 
2224 static int nl80211_get_assoclist_cb(struct nl_msg *msg, void *arg)
2225 {
2226         struct nl80211_array_buf *arr = arg;
2227         struct iwinfo_assoclist_entry *e = arr->buf;
2228         struct nlattr **attr = nl80211_parse(msg);
2229         struct nlattr *sinfo[NL80211_STA_INFO_MAX + 1];
2230         struct nlattr *rinfo[NL80211_RATE_INFO_MAX + 1];
2231         struct nl80211_sta_flag_update *sta_flags;
2232 
2233         static const struct nla_policy stats_policy[NL80211_STA_INFO_MAX + 1] = {
2234                 [NL80211_STA_INFO_INACTIVE_TIME] = { .type = NLA_U32    },
2235                 [NL80211_STA_INFO_RX_PACKETS]    = { .type = NLA_U32    },
2236                 [NL80211_STA_INFO_TX_PACKETS]    = { .type = NLA_U32    },
2237                 [NL80211_STA_INFO_RX_BITRATE]    = { .type = NLA_NESTED },
2238                 [NL80211_STA_INFO_TX_BITRATE]    = { .type = NLA_NESTED },
2239                 [NL80211_STA_INFO_SIGNAL]        = { .type = NLA_U8     },
2240                 [NL80211_STA_INFO_SIGNAL_AVG]    = { .type = NLA_U8     },
2241                 [NL80211_STA_INFO_RX_BYTES]      = { .type = NLA_U32    },
2242                 [NL80211_STA_INFO_TX_BYTES]      = { .type = NLA_U32    },
2243                 [NL80211_STA_INFO_RX_BYTES64]    = { .type = NLA_U64    },
2244                 [NL80211_STA_INFO_TX_BYTES64]    = { .type = NLA_U64    },
2245                 [NL80211_STA_INFO_TX_RETRIES]    = { .type = NLA_U32    },
2246                 [NL80211_STA_INFO_TX_FAILED]     = { .type = NLA_U32    },
2247                 [NL80211_STA_INFO_CONNECTED_TIME]= { .type = NLA_U32    },
2248                 [NL80211_STA_INFO_RX_DROP_MISC]  = { .type = NLA_U64    },
2249                 [NL80211_STA_INFO_T_OFFSET]      = { .type = NLA_U64    },
2250                 [NL80211_STA_INFO_STA_FLAGS] =
2251                         { .minlen = sizeof(struct nl80211_sta_flag_update) },
2252                 [NL80211_STA_INFO_EXPECTED_THROUGHPUT]   = { .type = NLA_U32    },
2253                 /* mesh */
2254                 [NL80211_STA_INFO_LLID]          = { .type = NLA_U16    },
2255                 [NL80211_STA_INFO_PLID]          = { .type = NLA_U16    },
2256                 [NL80211_STA_INFO_PLINK_STATE]   = { .type = NLA_U8     },
2257                 [NL80211_STA_INFO_LOCAL_PM]      = { .type = NLA_U32    },
2258                 [NL80211_STA_INFO_PEER_PM]       = { .type = NLA_U32    },
2259                 [NL80211_STA_INFO_NONPEER_PM]    = { .type = NLA_U32    },
2260         };
2261 
2262         static const struct nla_policy rate_policy[NL80211_RATE_INFO_MAX + 1] = {
2263                 [NL80211_RATE_INFO_BITRATE]      = { .type = NLA_U16    },
2264                 [NL80211_RATE_INFO_MCS]          = { .type = NLA_U8     },
2265                 [NL80211_RATE_INFO_40_MHZ_WIDTH] = { .type = NLA_FLAG   },
2266                 [NL80211_RATE_INFO_SHORT_GI]     = { .type = NLA_FLAG   },
2267         };
2268 
2269         /* advance to end of array */
2270         e += arr->count;
2271         memset(e, 0, sizeof(*e));
2272 
2273         if (attr[NL80211_ATTR_MAC])
2274                 memcpy(e->mac, nla_data(attr[NL80211_ATTR_MAC]), 6);
2275 
2276         if (attr[NL80211_ATTR_STA_INFO] &&
2277             !nla_parse_nested(sinfo, NL80211_STA_INFO_MAX,
2278                               attr[NL80211_ATTR_STA_INFO], stats_policy))
2279         {
2280                 if (sinfo[NL80211_STA_INFO_SIGNAL])
2281                         e->signal = nla_get_u8(sinfo[NL80211_STA_INFO_SIGNAL]);
2282 
2283                 if (sinfo[NL80211_STA_INFO_SIGNAL_AVG])
2284                         e->signal_avg = nla_get_u8(sinfo[NL80211_STA_INFO_SIGNAL_AVG]);
2285 
2286                 if (sinfo[NL80211_STA_INFO_INACTIVE_TIME])
2287                         e->inactive = nla_get_u32(sinfo[NL80211_STA_INFO_INACTIVE_TIME]);
2288 
2289                 if (sinfo[NL80211_STA_INFO_CONNECTED_TIME])
2290                         e->connected_time = nla_get_u32(sinfo[NL80211_STA_INFO_CONNECTED_TIME]);
2291 
2292                 if (sinfo[NL80211_STA_INFO_RX_PACKETS])
2293                         e->rx_packets = nla_get_u32(sinfo[NL80211_STA_INFO_RX_PACKETS]);
2294 
2295                 if (sinfo[NL80211_STA_INFO_TX_PACKETS])
2296                         e->tx_packets = nla_get_u32(sinfo[NL80211_STA_INFO_TX_PACKETS]);
2297 
2298                 if (sinfo[NL80211_STA_INFO_RX_BITRATE] &&
2299                     !nla_parse_nested(rinfo, NL80211_RATE_INFO_MAX,
2300                                       sinfo[NL80211_STA_INFO_RX_BITRATE], rate_policy))
2301                         nl80211_parse_rateinfo(rinfo, &e->rx_rate);
2302 
2303                 if (sinfo[NL80211_STA_INFO_TX_BITRATE] &&
2304                     !nla_parse_nested(rinfo, NL80211_RATE_INFO_MAX,
2305                                       sinfo[NL80211_STA_INFO_TX_BITRATE], rate_policy))
2306                         nl80211_parse_rateinfo(rinfo, &e->tx_rate);
2307 
2308                 if (sinfo[NL80211_STA_INFO_RX_BYTES64])
2309                         e->rx_bytes = nla_get_u64(sinfo[NL80211_STA_INFO_RX_BYTES64]);
2310                 else if (sinfo[NL80211_STA_INFO_RX_BYTES])
2311                         e->rx_bytes = nla_get_u32(sinfo[NL80211_STA_INFO_RX_BYTES]);
2312 
2313                 if (sinfo[NL80211_STA_INFO_TX_BYTES64])
2314                         e->tx_bytes = nla_get_u64(sinfo[NL80211_STA_INFO_TX_BYTES64]);
2315                 else if (sinfo[NL80211_STA_INFO_TX_BYTES])
2316                         e->tx_bytes = nla_get_u32(sinfo[NL80211_STA_INFO_TX_BYTES]);
2317 
2318                 if (sinfo[NL80211_STA_INFO_TX_RETRIES])
2319                         e->tx_retries = nla_get_u32(sinfo[NL80211_STA_INFO_TX_RETRIES]);
2320 
2321                 if (sinfo[NL80211_STA_INFO_TX_FAILED])
2322                         e->tx_failed = nla_get_u32(sinfo[NL80211_STA_INFO_TX_FAILED]);
2323 
2324                 if (sinfo[NL80211_STA_INFO_T_OFFSET])
2325                         e->t_offset = nla_get_u64(sinfo[NL80211_STA_INFO_T_OFFSET]);
2326 
2327                 if (sinfo[NL80211_STA_INFO_RX_DROP_MISC])
2328                         e->rx_drop_misc = nla_get_u64(sinfo[NL80211_STA_INFO_RX_DROP_MISC]);
2329 
2330                 if (sinfo[NL80211_STA_INFO_EXPECTED_THROUGHPUT])
2331                         e->thr = nla_get_u32(sinfo[NL80211_STA_INFO_EXPECTED_THROUGHPUT]);
2332 
2333                 /* mesh */
2334                 if (sinfo[NL80211_STA_INFO_LLID])
2335                         e->llid = nla_get_u16(sinfo[NL80211_STA_INFO_LLID]);
2336 
2337                 if (sinfo[NL80211_STA_INFO_PLID])
2338                         e->plid = nla_get_u16(sinfo[NL80211_STA_INFO_PLID]);
2339 
2340                 if (sinfo[NL80211_STA_INFO_PLINK_STATE])
2341                         plink_state_to_str(e->plink_state,
2342                                 nla_get_u8(sinfo[NL80211_STA_INFO_PLINK_STATE]));
2343 
2344                 if (sinfo[NL80211_STA_INFO_LOCAL_PM])
2345                         power_mode_to_str(e->local_ps, sinfo[NL80211_STA_INFO_LOCAL_PM]);
2346                 if (sinfo[NL80211_STA_INFO_PEER_PM])
2347                         power_mode_to_str(e->peer_ps, sinfo[NL80211_STA_INFO_PEER_PM]);
2348                 if (sinfo[NL80211_STA_INFO_NONPEER_PM])
2349                         power_mode_to_str(e->nonpeer_ps, sinfo[NL80211_STA_INFO_NONPEER_PM]);
2350 
2351                 /* Station flags */
2352                 if (sinfo[NL80211_STA_INFO_STA_FLAGS])
2353                 {
2354                         sta_flags = (struct nl80211_sta_flag_update *)
2355                                 nla_data(sinfo[NL80211_STA_INFO_STA_FLAGS]);
2356 
2357                         if (sta_flags->mask & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
2358                             sta_flags->set & BIT(NL80211_STA_FLAG_AUTHORIZED))
2359                                 e->is_authorized = 1;
2360 
2361                         if (sta_flags->mask & BIT(NL80211_STA_FLAG_AUTHENTICATED) &&
2362                             sta_flags->set & BIT(NL80211_STA_FLAG_AUTHENTICATED))
2363                                 e->is_authenticated = 1;
2364 
2365                         if (sta_flags->mask & BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) &&
2366                             sta_flags->set & BIT(NL80211_STA_FLAG_SHORT_PREAMBLE))
2367                                 e->is_preamble_short = 1;
2368 
2369                         if (sta_flags->mask & BIT(NL80211_STA_FLAG_WME) &&
2370                             sta_flags->set & BIT(NL80211_STA_FLAG_WME))
2371                                 e->is_wme = 1;
2372 
2373                         if (sta_flags->mask & BIT(NL80211_STA_FLAG_MFP) &&
2374                             sta_flags->set & BIT(NL80211_STA_FLAG_MFP))
2375                                 e->is_mfp = 1;
2376 
2377                         if (sta_flags->mask & BIT(NL80211_STA_FLAG_TDLS_PEER) &&
2378                             sta_flags->set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2379                                 e->is_tdls = 1;
2380                 }
2381         }
2382 
2383         e->noise = 0; /* filled in by caller */
2384         arr->count++;
2385 
2386         return NL_SKIP;
2387 }
2388 
2389 static int nl80211_get_survey(const char *ifname, char *buf, int *len)
2390 {
2391         struct nl80211_array_buf arr = { .buf = buf, .count = 0 };
2392         int rc;
2393 
2394         rc = nl80211_request(ifname, NL80211_CMD_GET_SURVEY,
2395                         NLM_F_DUMP, nl80211_get_survey_cb, &arr);
2396         if (!rc)
2397                 *len = (arr.count * sizeof(struct iwinfo_survey_entry));
2398         else
2399                 *len = 0;
2400 
2401         return 0;
2402 }
2403 
2404 static int nl80211_get_assoclist(const char *ifname, char *buf, int *len)
2405 {
2406         DIR *d;
2407         int i, noise = 0;
2408         struct dirent *de;
2409         struct nl80211_array_buf arr = { .buf = buf, .count = 0 };
2410         struct iwinfo_assoclist_entry *e;
2411 
2412         if ((d = opendir("/sys/class/net")) != NULL)
2413         {
2414                 while ((de = readdir(d)) != NULL)
2415                 {
2416                         if (!strncmp(de->d_name, ifname, strlen(ifname)) &&
2417                             (!de->d_name[strlen(ifname)] ||
2418                              !strncmp(&de->d_name[strlen(ifname)], ".sta", 4)))
2419                         {
2420                                 nl80211_request(de->d_name, NL80211_CMD_GET_STATION,
2421                                                 NLM_F_DUMP, nl80211_get_assoclist_cb, &arr);
2422                         }
2423                 }
2424 
2425                 closedir(d);
2426 
2427                 if (!nl80211_get_noise(ifname, &noise))
2428                         for (i = 0, e = arr.buf; i < arr.count; i++, e++)
2429                                 e->noise = noise;
2430 
2431                 *len = (arr.count * sizeof(struct iwinfo_assoclist_entry));
2432                 return 0;
2433         }
2434 
2435         return -1;
2436 }
2437 
2438 static int nl80211_get_txpwrlist_cb(struct nl_msg *msg, void *arg)
2439 {
2440         int *dbm_max = arg;
2441         int ch_cur, ch_cmp, bands_remain, freqs_remain;
2442 
2443         struct nlattr **attr = nl80211_parse(msg);
2444         struct nlattr *bands[NL80211_BAND_ATTR_MAX + 1];
2445         struct nlattr *freqs[NL80211_FREQUENCY_ATTR_MAX + 1];
2446         struct nlattr *band, *freq;
2447 
2448         static const struct nla_policy freq_policy[NL80211_FREQUENCY_ATTR_MAX + 1] = {
2449                 [NL80211_FREQUENCY_ATTR_FREQ]         = { .type = NLA_U32  },
2450                 [NL80211_FREQUENCY_ATTR_DISABLED]     = { .type = NLA_FLAG },
2451                 [NL80211_FREQUENCY_ATTR_PASSIVE_SCAN] = { .type = NLA_FLAG },
2452                 [NL80211_FREQUENCY_ATTR_NO_IBSS]      = { .type = NLA_FLAG },
2453                 [NL80211_FREQUENCY_ATTR_RADAR]        = { .type = NLA_FLAG },
2454                 [NL80211_FREQUENCY_ATTR_MAX_TX_POWER] = { .type = NLA_U32  },
2455         };
2456 
2457         ch_cur = *dbm_max; /* value int* is initialized with channel by caller */
2458         *dbm_max = -1;
2459 
2460         nla_for_each_nested(band, attr[NL80211_ATTR_WIPHY_BANDS], bands_remain)
2461         {
2462                 nla_parse(bands, NL80211_BAND_ATTR_MAX, nla_data(band),
2463                           nla_len(band), NULL);
2464 
2465                 nla_for_each_nested(freq, bands[NL80211_BAND_ATTR_FREQS], freqs_remain)
2466                 {
2467                         nla_parse(freqs, NL80211_FREQUENCY_ATTR_MAX,
2468                                   nla_data(freq), nla_len(freq), freq_policy);
2469 
2470                         ch_cmp = nl80211_freq2channel(nla_get_u32(
2471                                 freqs[NL80211_FREQUENCY_ATTR_FREQ]));
2472 
2473                         if ((!ch_cur || (ch_cmp == ch_cur)) &&
2474                             freqs[NL80211_FREQUENCY_ATTR_MAX_TX_POWER])
2475                         {
2476                                 *dbm_max = (int)(0.01 * nla_get_u32(
2477                                         freqs[NL80211_FREQUENCY_ATTR_MAX_TX_POWER]));
2478 
2479                                 break;
2480                         }
2481                 }
2482         }
2483 
2484         return NL_SKIP;
2485 }
2486 
2487 static int nl80211_get_txpwrlist(const char *ifname, char *buf, int *len)
2488 {
2489         int err, ch_cur;
2490         int dbm_max = -1, dbm_cur, dbm_cnt;
2491         struct iwinfo_txpwrlist_entry entry;
2492 
2493         if (nl80211_get_channel(ifname, &ch_cur))
2494                 ch_cur = 0;
2495 
2496         /* initialize the value pointer with channel for callback */
2497         dbm_max = ch_cur;
2498 
2499         err = nl80211_request(ifname, NL80211_CMD_GET_WIPHY, 0,
2500                               nl80211_get_txpwrlist_cb, &dbm_max);
2501 
2502         if (!err)
2503         {
2504                 for (dbm_cur = 0, dbm_cnt = 0;
2505                      dbm_cur < dbm_max;
2506                      dbm_cur++, dbm_cnt++)
2507                 {
2508                         entry.dbm = dbm_cur;
2509                         entry.mw  = iwinfo_dbm2mw(dbm_cur);
2510 
2511                         memcpy(&buf[dbm_cnt * sizeof(entry)], &entry, sizeof(entry));
2512                 }
2513 
2514                 entry.dbm = dbm_max;
2515                 entry.mw  = iwinfo_dbm2mw(dbm_max);
2516 
2517                 memcpy(&buf[dbm_cnt * sizeof(entry)], &entry, sizeof(entry));
2518                 dbm_cnt++;
2519 
2520                 *len = dbm_cnt * sizeof(entry);
2521                 return 0;
2522         }
2523 
2524         return -1;
2525 }
2526 
2527 static void nl80211_get_scancrypto(char *spec, struct iwinfo_crypto_entry *c)
2528 {
2529         int wpa_version = 0;
2530         char *p, *q, *proto, *suites;
2531 
2532         c->enabled = 0;
2533 
2534         for (p = strtok_r(spec, "[]", &q); p; p = strtok_r(NULL, "[]", &q)) {
2535                 if (!strcmp(p, "WEP")) {
2536                         c->enabled      = 1;
2537                         c->auth_suites  = IWINFO_KMGMT_NONE;
2538                         c->auth_algs    = IWINFO_AUTH_OPEN | IWINFO_AUTH_SHARED;
2539                         c->pair_ciphers = IWINFO_CIPHER_WEP40 | IWINFO_CIPHER_WEP104;
2540                         break;
2541                 }
2542 
2543                 proto = strtok(p, "-");
2544                 suites = strtok(NULL, "]");
2545 
2546                 if (!proto || !suites)
2547                         continue;
2548 
2549                 if (!strcmp(proto, "WPA2") || !strcmp(proto, "RSN"))
2550                         wpa_version = 2;
2551                 else if (!strcmp(proto, "WPA"))
2552                         wpa_version = 1;
2553                 else
2554                         continue;
2555 
2556                 c->enabled = 1;
2557 
2558                 parse_wpa_suites(suites, wpa_version, &c->wpa_version, &c->auth_suites);
2559                 parse_wpa_ciphers(suites, &c->pair_ciphers);
2560         }
2561 }
2562 
2563 
2564 struct nl80211_scanlist {
2565         struct iwinfo_scanlist_entry *e;
2566         int len;
2567 };
2568 
2569 
2570 static void nl80211_get_scanlist_ie(struct nlattr **bss,
2571                                     struct iwinfo_scanlist_entry *e)
2572 {
2573         int ielen = nla_len(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
2574         unsigned char *ie = nla_data(bss[NL80211_BSS_INFORMATION_ELEMENTS]);
2575         static unsigned char ms_oui[3] = { 0x00, 0x50, 0xf2 };
2576         int len;
2577 
2578         while (ielen >= 2 && ielen >= ie[1])
2579         {
2580                 switch (ie[0])
2581                 {
2582                 case 0: /* SSID */
2583                 case 114: /* Mesh ID */
2584                         if (e->ssid[0] == 0) {
2585                                 len = min(ie[1], IWINFO_ESSID_MAX_SIZE);
2586                                 memcpy(e->ssid, ie + 2, len);
2587                                 e->ssid[len] = 0;
2588                         }
2589                         break;
2590 
2591                 case 48: /* RSN */
2592                         iwinfo_parse_rsn(&e->crypto, ie + 2, ie[1],
2593                                          IWINFO_CIPHER_CCMP, IWINFO_KMGMT_8021x);
2594                         break;
2595 
2596                 case 221: /* Vendor */
2597                         if (ie[1] >= 4 && !memcmp(ie + 2, ms_oui, 3) && ie[5] == 1)
2598                                 iwinfo_parse_rsn(&e->crypto, ie + 6, ie[1] - 4,
2599                                                  IWINFO_CIPHER_TKIP, IWINFO_KMGMT_PSK);
2600                         break;
2601                 case 61: /* HT operation */
2602                         if (ie[1] >= 3) {
2603                                 e->ht_chan_info.primary_chan = ie[2];
2604                                 e->ht_chan_info.secondary_chan_off = ie[3] & 0x3;
2605                                 e->ht_chan_info.chan_width = (ie[4] & 0x4)>>2;
2606                         }
2607                         break;
2608                 case 192: /* VHT operation */
2609                         if (ie[1] >= 3) {
2610                                 e->vht_chan_info.chan_width = ie[2];
2611                                 e->vht_chan_info.center_chan_1 = ie[3];
2612                                 e->vht_chan_info.center_chan_2 = ie[4];
2613                         }
2614                         break;
2615                 }
2616 
2617                 ielen -= ie[1] + 2;
2618                 ie += ie[1] + 2;
2619         }
2620 }
2621 
2622 static int nl80211_get_scanlist_cb(struct nl_msg *msg, void *arg)
2623 {
2624         int8_t rssi;
2625         uint16_t caps;
2626 
2627         struct nl80211_scanlist *sl = arg;
2628         struct nlattr **tb = nl80211_parse(msg);
2629         struct nlattr *bss[NL80211_BSS_MAX + 1];
2630 
2631         static const struct nla_policy bss_policy[NL80211_BSS_MAX + 1] = {
2632                 [NL80211_BSS_TSF]                  = { .type = NLA_U64 },
2633                 [NL80211_BSS_FREQUENCY]            = { .type = NLA_U32 },
2634                 [NL80211_BSS_BSSID]                = { 0 },
2635                 [NL80211_BSS_BEACON_INTERVAL]      = { .type = NLA_U16 },
2636                 [NL80211_BSS_CAPABILITY]           = { .type = NLA_U16 },
2637                 [NL80211_BSS_INFORMATION_ELEMENTS] = { 0 },
2638                 [NL80211_BSS_SIGNAL_MBM]           = { .type = NLA_U32 },
2639                 [NL80211_BSS_SIGNAL_UNSPEC]        = { .type = NLA_U8  },
2640                 [NL80211_BSS_STATUS]               = { .type = NLA_U32 },
2641                 [NL80211_BSS_SEEN_MS_AGO]          = { .type = NLA_U32 },
2642                 [NL80211_BSS_BEACON_IES]           = { 0 },
2643         };
2644 
2645         if (!tb[NL80211_ATTR_BSS] ||
2646                 nla_parse_nested(bss, NL80211_BSS_MAX, tb[NL80211_ATTR_BSS],
2647                                  bss_policy) ||
2648                 !bss[NL80211_BSS_BSSID])
2649         {
2650                 return NL_SKIP;
2651         }
2652 
2653         if (bss[NL80211_BSS_CAPABILITY])
2654                 caps = nla_get_u16(bss[NL80211_BSS_CAPABILITY]);
2655         else
2656                 caps = 0;
2657 
2658         memset(sl->e, 0, sizeof(*sl->e));
2659         memcpy(sl->e->mac, nla_data(bss[NL80211_BSS_BSSID]), 6);
2660 
2661         if (caps & (1<<1))
2662                 sl->e->mode = IWINFO_OPMODE_ADHOC;
2663         else if (caps & (1<<0))
2664                 sl->e->mode = IWINFO_OPMODE_MASTER;
2665         else
2666                 sl->e->mode = IWINFO_OPMODE_MESHPOINT;
2667 
2668         if (caps & (1<<4))
2669                 sl->e->crypto.enabled = 1;
2670 
2671         if (bss[NL80211_BSS_FREQUENCY])
2672         {
2673                 sl->e->mhz = nla_get_u32(bss[NL80211_BSS_FREQUENCY]);
2674                 sl->e->band = nl80211_freq2band(sl->e->mhz);
2675                 sl->e->channel = nl80211_freq2channel(sl->e->mhz);
2676         }
2677 
2678         if (bss[NL80211_BSS_INFORMATION_ELEMENTS])
2679                 nl80211_get_scanlist_ie(bss, sl->e);
2680 
2681         if (bss[NL80211_BSS_SIGNAL_MBM])
2682         {
2683                 sl->e->signal =
2684                         (uint8_t)((int32_t)nla_get_u32(bss[NL80211_BSS_SIGNAL_MBM]) / 100);
2685 
2686                 rssi = sl->e->signal - 0x100;
2687 
2688                 if (rssi < -110)
2689                         rssi = -110;
2690                 else if (rssi > -40)
2691                         rssi = -40;
2692 
2693                 sl->e->quality = (rssi + 110);
2694                 sl->e->quality_max = 70;
2695         }
2696 
2697         if (sl->e->crypto.enabled && !sl->e->crypto.wpa_version)
2698         {
2699                 sl->e->crypto.auth_algs    = IWINFO_AUTH_OPEN | IWINFO_AUTH_SHARED;
2700                 sl->e->crypto.pair_ciphers = IWINFO_CIPHER_WEP40 | IWINFO_CIPHER_WEP104;
2701         }
2702 
2703         sl->e++;
2704         sl->len++;
2705 
2706         return NL_SKIP;
2707 }
2708 
2709 static int nl80211_get_scanlist_nl(const char *ifname, char *buf, int *len)
2710 {
2711         struct nl80211_scanlist sl = { .e = (struct iwinfo_scanlist_entry *)buf };
2712 
2713         if (nl80211_request(ifname, NL80211_CMD_TRIGGER_SCAN, 0, NULL, NULL))
2714                 goto out;
2715 
2716         if (nl80211_wait("nl80211", "scan",
2717                          NL80211_CMD_NEW_SCAN_RESULTS, NL80211_CMD_SCAN_ABORTED))
2718                 goto out;
2719 
2720         if (nl80211_request(ifname, NL80211_CMD_GET_SCAN, NLM_F_DUMP,
2721                             nl80211_get_scanlist_cb, &sl))
2722                 goto out;
2723 
2724         *len = sl.len * sizeof(struct iwinfo_scanlist_entry);
2725         return 0;
2726 
2727 out:
2728         *len = 0;
2729         return -1;
2730 }
2731 
2732 static int wpasupp_ssid_decode(const char *in, char *out, int outlen)
2733 {
2734 #define hex(x) \
2735         (((x) >= 'a') ? ((x) - 'a' + 10) : \
2736                 (((x) >= 'A') ? ((x) - 'A' + 10) : ((x) - '')))
2737 
2738         int len = 0;
2739 
2740         while (*in)
2741         {
2742                 if (len + 1 >= outlen)
2743                         break;
2744 
2745                 switch (*in)
2746                 {
2747                 case '\\':
2748                         in++;
2749                         switch (*in)
2750                         {
2751                         case 'n':
2752                                 out[len++] = '\n'; in++;
2753                                 break;
2754 
2755                         case 'r':
2756                                 out[len++] = '\r'; in++;
2757                                 break;
2758 
2759                         case 't':
2760                                 out[len++] = '\t'; in++;
2761                                 break;
2762 
2763                         case 'e':
2764                                 out[len++] = '\033'; in++;
2765                                 break;
2766 
2767                         case 'x':
2768                                 if (isxdigit(*(in+1)) && isxdigit(*(in+2)))
2769                                         out[len++] = hex(*(in+1)) * 16 + hex(*(in+2));
2770                                 in += 3;
2771                                 break;
2772 
2773                         default:
2774                                 out[len++] = *in++;
2775                                 break;
2776                         }
2777                         break;
2778 
2779                 default:
2780                         out[len++] = *in++;
2781                         break;
2782                 }
2783         }
2784 
2785         if (outlen > len)
2786                 out[len] = '\0';
2787 
2788         return len;
2789 }
2790 
2791 static int nl80211_get_scanlist_wpactl(const char *ifname, char *buf, int *len)
2792 {
2793         int sock, qmax, rssi, tries, count = -1, ready = 0;
2794         char *pos, *line, *bssid, *freq, *signal, *flags, *ssid, reply[4096];
2795         struct sockaddr_un local = { 0 };
2796         struct iwinfo_scanlist_entry *e = (struct iwinfo_scanlist_entry *)buf;
2797 
2798         sock = nl80211_wpactl_connect(ifname, &local);
2799 
2800         if (sock < 0)
2801                 return sock;
2802 
2803         send(sock, "ATTACH", 6, 0);
2804         send(sock, "SCAN", 4, 0);
2805 
2806         /*
2807          * wait for scan results:
2808          *   nl80211_wpactl_recv() will use a timeout of 256ms and we need to scan
2809          *   72 channels at most. We'll also receive two "OK" messages acknowledging
2810          *   the "ATTACH" and "SCAN" commands and the driver might need a bit extra
2811          *   time to process the results, so try 72 + 2 + 1 times.
2812          */
2813         for (tries = 0; tries < 75; tries++)
2814         {
2815                 if (nl80211_wpactl_recv(sock, reply, sizeof(reply)) <= 0)
2816                         continue;
2817 
2818                 /* got an event notification */
2819                 if (reply[0] == '<')
2820                 {
2821                         /* scan results are ready */
2822                         if (strstr(reply, "CTRL-EVENT-SCAN-RESULTS"))
2823                         {
2824                                 /* send "SCAN_RESULTS" command */
2825                                 ready = (send(sock, "SCAN_RESULTS", 12, 0) == 12);
2826                                 break;
2827                         }
2828 
2829                         /* is another unrelated event, retry */
2830                         tries--;
2831                 }
2832 
2833                 /* scanning already in progress, keep awaiting results */
2834                 else if (!strcmp(reply, "FAIL-BUSY\n"))
2835                 {
2836                         tries--;
2837                 }
2838 
2839                 /* another failure, abort */
2840                 else if (!strncmp(reply, "FAIL-", 5))
2841                 {
2842                         break;
2843                 }
2844         }
2845 
2846         /* receive and parse scan results if the wait above didn't time out */
2847         while (ready && nl80211_wpactl_recv(sock, reply, sizeof(reply)) > 0)
2848         {
2849                 /* received an event notification, receive again */
2850                 if (reply[0] == '<')
2851                         continue;
2852 
2853                 nl80211_get_quality_max(ifname, &qmax);
2854 
2855                 for (line = strtok_r(reply, "\n", &pos);
2856                      line != NULL;
2857                      line = strtok_r(NULL, "\n", &pos))
2858                 {
2859                         /* skip header line */
2860                         if (count < 0)
2861                         {
2862                                 count++;
2863                                 continue;
2864                         }
2865 
2866                         bssid  = strtok(line, "\t");
2867                         freq   = strtok(NULL, "\t");
2868                         signal = strtok(NULL, "\t");
2869                         flags  = strtok(NULL, "\t");
2870                         ssid   = strtok(NULL, "\n");
2871 
2872                         if (!bssid || !freq || !signal || !flags)
2873                                 continue;
2874 
2875                         /* BSSID */
2876                         e->mac[0] = strtol(&bssid[0],  NULL, 16);
2877                         e->mac[1] = strtol(&bssid[3],  NULL, 16);
2878                         e->mac[2] = strtol(&bssid[6],  NULL, 16);
2879                         e->mac[3] = strtol(&bssid[9],  NULL, 16);
2880                         e->mac[4] = strtol(&bssid[12], NULL, 16);
2881                         e->mac[5] = strtol(&bssid[15], NULL, 16);
2882 
2883                         /* SSID */
2884                         if (ssid)
2885                                 wpasupp_ssid_decode(ssid, e->ssid, sizeof(e->ssid));
2886                         else
2887                                 e->ssid[0] = 0;
2888 
2889                         /* Mode */
2890                         if (strstr(flags, "[MESH]"))
2891                                 e->mode = IWINFO_OPMODE_MESHPOINT;
2892                         else if (strstr(flags, "[IBSS]"))
2893                                 e->mode = IWINFO_OPMODE_ADHOC;
2894                         else
2895                                 e->mode = IWINFO_OPMODE_MASTER;
2896 
2897                         /* Channel */
2898                         e->mhz = atoi(freq);
2899                         e->band = nl80211_freq2band(e->mhz);
2900                         e->channel = nl80211_freq2channel(e->mhz);
2901 
2902                         /* Signal */
2903                         rssi = atoi(signal);
2904                         e->signal = rssi;
2905 
2906                         /* Quality */
2907                         if (rssi < 0)
2908                         {
2909                                 /* The cfg80211 wext compat layer assumes a signal range
2910                                  * of -110 dBm to -40 dBm, the quality value is derived
2911                                  * by adding 110 to the signal level */
2912                                 if (rssi < -110)
2913                                         rssi = -110;
2914                                 else if (rssi > -40)
2915                                         rssi = -40;
2916 
2917                                 e->quality = (rssi + 110);
2918                         }
2919                         else
2920                         {
2921                                 e->quality = rssi;
2922                         }
2923 
2924                         /* Max. Quality */
2925                         e->quality_max = qmax;
2926 
2927                         /* Crypto */
2928                         nl80211_get_scancrypto(flags, &e->crypto);
2929 
2930                         count++;
2931                         e++;
2932                 }
2933 
2934                 *len = count * sizeof(struct iwinfo_scanlist_entry);
2935                 break;
2936         }
2937 
2938         close(sock);
2939         unlink(local.sun_path);
2940 
2941         return (count >= 0) ? 0 : -1;
2942 }
2943 
2944 static int nl80211_get_scanlist(const char *ifname, char *buf, int *len)
2945 {
2946         char *res;
2947         int rv, mode;
2948 
2949         *len = 0;
2950 
2951         /* Got a radioX pseudo interface, find some interface on it or create one */
2952         if (!strncmp(ifname, "radio", 5))
2953         {
2954                 /* Reuse existing interface */
2955                 if ((res = nl80211_phy2ifname(ifname)) != NULL)
2956                 {
2957                         return nl80211_get_scanlist(res, buf, len);
2958                 }
2959 
2960                 /* Need to spawn a temporary iface for scanning */
2961                 else if ((res = nl80211_ifadd(ifname)) != NULL)
2962                 {
2963                         rv = nl80211_get_scanlist(res, buf, len);
2964                         nl80211_ifdel(res);
2965                         return rv;
2966                 }
2967         }
2968 
2969         /* WPA supplicant */
2970         if (!nl80211_get_scanlist_wpactl(ifname, buf, len))
2971         {
2972                 return 0;
2973         }
2974 
2975         /* station / ad-hoc / monitor scan */
2976         else if (!nl80211_get_mode(ifname, &mode) &&
2977                  (mode == IWINFO_OPMODE_ADHOC ||
2978                   mode == IWINFO_OPMODE_MASTER ||
2979                   mode == IWINFO_OPMODE_CLIENT ||
2980                   mode == IWINFO_OPMODE_MONITOR) &&
2981                  iwinfo_ifup(ifname))
2982         {
2983                 return nl80211_get_scanlist_nl(ifname, buf, len);
2984         }
2985 
2986         /* AP scan */
2987         else
2988         {
2989                 /* Got a temp interface, don't create yet another one */
2990                 if (!strncmp(ifname, "tmp.", 4))
2991                 {
2992                         if (!iwinfo_ifup(ifname))
2993                                 return -1;
2994 
2995                         rv = nl80211_get_scanlist_nl(ifname, buf, len);
2996                         iwinfo_ifdown(ifname);
2997                         return rv;
2998                 }
2999 
3000                 /* Spawn a new scan interface */
3001                 else
3002                 {
3003                         if (!(res = nl80211_ifadd(ifname)))
3004                                 return -1;
3005 
3006                         iwinfo_ifmac(res);
3007 
3008                         /* if we can take the new interface up, the driver supports an
3009                          * additional interface and there's no need to tear down the ap */
3010                         if (iwinfo_ifup(res))
3011                         {
3012                                 rv = nl80211_get_scanlist_nl(res, buf, len);
3013                                 iwinfo_ifdown(res);
3014                         }
3015 
3016                         /* driver cannot create secondary interface, take down ap
3017                          * during scan */
3018                         else if (iwinfo_ifdown(ifname) && iwinfo_ifup(res))
3019                         {
3020                                 rv = nl80211_get_scanlist_nl(res, buf, len);
3021                                 iwinfo_ifdown(res);
3022                                 iwinfo_ifup(ifname);
3023                                 nl80211_hostapd_hup(ifname);
3024                         }
3025                         else
3026                                 rv = -1;
3027 
3028                         nl80211_ifdel(res);
3029                         return rv;
3030                 }
3031         }
3032 
3033         return -1;
3034 }
3035 
3036 static int nl80211_get_freqlist_cb(struct nl_msg *msg, void *arg)
3037 {
3038         int bands_remain, freqs_remain;
3039 
3040         struct nl80211_array_buf *arr = arg;
3041         struct iwinfo_freqlist_entry *e;
3042 
3043         struct nlattr **attr = nl80211_parse(msg);
3044         struct nlattr *bands[NL80211_BAND_ATTR_MAX + 1];
3045         struct nlattr *freqs[NL80211_FREQUENCY_ATTR_MAX + 1];
3046         struct nlattr *band, *freq;
3047 
3048         e = arr->buf;
3049         e += arr->count;
3050 
3051         if (attr[NL80211_ATTR_WIPHY_BANDS]) {
3052                 nla_for_each_nested(band, attr[NL80211_ATTR_WIPHY_BANDS], bands_remain)
3053                 {
3054                         nla_parse(bands, NL80211_BAND_ATTR_MAX,
3055                                   nla_data(band), nla_len(band), NULL);
3056 
3057                         if (bands[NL80211_BAND_ATTR_FREQS]) {
3058                                 nla_for_each_nested(freq, bands[NL80211_BAND_ATTR_FREQS], freqs_remain)
3059                                 {
3060                                         nla_parse(freqs, NL80211_FREQUENCY_ATTR_MAX,
3061                                                   nla_data(freq), nla_len(freq), NULL);
3062 
3063                                         if (!freqs[NL80211_FREQUENCY_ATTR_FREQ] ||
3064                                             freqs[NL80211_FREQUENCY_ATTR_DISABLED])
3065                                                 continue;
3066 
3067                                         e->band = nl80211_get_band(band->nla_type);
3068                                         e->mhz = nla_get_u32(freqs[NL80211_FREQUENCY_ATTR_FREQ]);
3069                                         e->channel = nl80211_freq2channel(e->mhz);
3070 
3071                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_HT40_MINUS])
3072                                                 e->flags |= IWINFO_FREQ_NO_HT40MINUS;
3073                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_HT40_PLUS])
3074                                                 e->flags |= IWINFO_FREQ_NO_HT40PLUS;
3075                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_80MHZ])
3076                                                 e->flags |= IWINFO_FREQ_NO_80MHZ;
3077                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_160MHZ])
3078                                                 e->flags |= IWINFO_FREQ_NO_160MHZ;
3079                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_20MHZ])
3080                                                 e->flags |= IWINFO_FREQ_NO_20MHZ;
3081                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_10MHZ])
3082                                                 e->flags |= IWINFO_FREQ_NO_10MHZ;
3083                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_HE])
3084                                                 e->flags |= IWINFO_FREQ_NO_HE;
3085                                         if (freqs[NL80211_FREQUENCY_ATTR_NO_IR] &&
3086                                             !freqs[NL80211_FREQUENCY_ATTR_RADAR])
3087                                                 e->flags |= IWINFO_FREQ_NO_IR;
3088                                         if (freqs[NL80211_FREQUENCY_ATTR_INDOOR_ONLY])
3089                                                 e->flags |= IWINFO_FREQ_INDOOR_ONLY;
3090 
3091                                         /* keep backwards compatibility */
3092                                         e->restricted = (e->flags & IWINFO_FREQ_NO_IR) ? 1 : 0;
3093 
3094                                         e++;
3095                                         arr->count++;
3096                                 }
3097                         }
3098                 }
3099         }
3100 
3101         return NL_SKIP;
3102 }
3103 
3104 static int nl80211_get_freqlist(const char *ifname, char *buf, int *len)
3105 {
3106         struct nl80211_msg_conveyor *cv;
3107         struct nl80211_array_buf arr = { .buf = buf, .count = 0 };
3108         uint32_t features = nl80211_get_protocol_features(ifname);
3109         int flags;
3110 
3111         flags = features & NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP ? NLM_F_DUMP : 0;
3112         cv = nl80211_msg(ifname, NL80211_CMD_GET_WIPHY, flags);
3113         if (!cv)
3114                 goto out;
3115 
3116         NLA_PUT_FLAG(cv->msg, NL80211_ATTR_SPLIT_WIPHY_DUMP);
3117         if (nl80211_send(cv, nl80211_get_freqlist_cb, &arr))
3118                 goto out;
3119 
3120         *len = arr.count * sizeof(struct iwinfo_freqlist_entry);
3121         return 0;
3122 
3123 nla_put_failure:
3124         nl80211_free(cv);
3125 out:
3126         *len = 0;
3127         return -1;
3128 }
3129 
3130 static int nl80211_get_country_cb(struct nl_msg *msg, void *arg)
3131 {
3132         char *buf = arg;
3133         struct nlattr **attr = nl80211_parse(msg);
3134 
3135         if (attr[NL80211_ATTR_REG_ALPHA2])
3136                 memcpy(buf, nla_data(attr[NL80211_ATTR_REG_ALPHA2]), 2);
3137         else
3138                 buf[0] = 0;
3139 
3140         return NL_SKIP;
3141 }
3142 
3143 static int nl80211_get_country(const char *ifname, char *buf)
3144 {
3145         if (nl80211_request(ifname, NL80211_CMD_GET_REG, 0,
3146                             nl80211_get_country_cb, buf))
3147                 return -1;
3148 
3149         return 0;
3150 }
3151 
3152 static int nl80211_get_countrylist(const char *ifname, char *buf, int *len)
3153 {
3154         int count;
3155         struct iwinfo_country_entry *e = (struct iwinfo_country_entry *)buf;
3156         const struct iwinfo_iso3166_label *l;
3157 
3158         for (l = IWINFO_ISO3166_NAMES, count = 0; l->iso3166; l++, e++, count++)
3159         {
3160                 e->iso3166 = l->iso3166;
3161                 e->ccode[0] = (l->iso3166 / 256);
3162                 e->ccode[1] = (l->iso3166 % 256);
3163                 e->ccode[2] = 0;
3164         }
3165 
3166         *len = (count * sizeof(struct iwinfo_country_entry));
3167         return 0;
3168 }
3169 
3170 
3171 struct nl80211_modes
3172 {
3173         bool ok;
3174         uint32_t hw;
3175         uint32_t ht;
3176 
3177         uint8_t bands;
3178 
3179         uint16_t nl_ht;
3180         uint32_t nl_vht;
3181         uint16_t he_phy_cap[6];
3182         uint16_t eht_phy_cap[9];
3183 };
3184 
3185 static void nl80211_eval_modelist(struct nl80211_modes *m)
3186 {
3187         /* Treat any nonzero capability as 11n */
3188         if (m->nl_ht > 0)
3189         {
3190                 m->hw |= IWINFO_80211_N;
3191                 m->ht |= IWINFO_HTMODE_HT20;
3192 
3193                 if (m->nl_ht & (1 << 1))
3194                         m->ht |= IWINFO_HTMODE_HT40;
3195         }
3196 
3197         if (m->he_phy_cap[0] != 0) {
3198                 m->hw |= IWINFO_80211_AX;
3199                 m->ht |= IWINFO_HTMODE_HE20;
3200 
3201                 if (m->he_phy_cap[0] & BIT(9))
3202                         m->ht |= IWINFO_HTMODE_HE40;
3203                 if (m->he_phy_cap[0] & BIT(10))
3204                         m->ht |= IWINFO_HTMODE_HE40 | IWINFO_HTMODE_HE80;
3205                 if (m->he_phy_cap[0] & BIT(11))
3206                         m->ht |= IWINFO_HTMODE_HE160;
3207                 if (m->he_phy_cap[0] & BIT(12))
3208                         m->ht |= IWINFO_HTMODE_HE160 | IWINFO_HTMODE_HE80_80;
3209         }
3210 
3211         if (m->eht_phy_cap[0] != 0) {
3212                 m->hw |= IWINFO_80211_BE;
3213                 m->ht |= IWINFO_HTMODE_EHT20;
3214 
3215                 if (m->he_phy_cap[0] & BIT(9))
3216                         m->ht |= IWINFO_HTMODE_EHT40;
3217                 if (m->he_phy_cap[0] & BIT(10))
3218                         m->ht |= IWINFO_HTMODE_EHT40 | IWINFO_HTMODE_EHT80;
3219                 if (m->he_phy_cap[0] & BIT(11))
3220                         m->ht |= IWINFO_HTMODE_EHT160;
3221                 if (m->he_phy_cap[0] & BIT(12))
3222                         m->ht |= IWINFO_HTMODE_EHT160 | IWINFO_HTMODE_EHT80_80;
3223                 if ((m->eht_phy_cap[0] & BIT(9)) && (m->bands & IWINFO_BAND_6))
3224                         m->ht |= IWINFO_HTMODE_EHT320;
3225         }
3226 
3227         if (m->bands & IWINFO_BAND_24)
3228         {
3229                 m->hw |= IWINFO_80211_B;
3230                 m->hw |= IWINFO_80211_G;
3231         }
3232 
3233         if (m->bands & IWINFO_BAND_5)
3234         {
3235                 /* Treat any nonzero capability as 11ac */
3236                 if (m->nl_vht > 0)
3237                 {
3238                         m->hw |= IWINFO_80211_AC;
3239                         m->ht |= IWINFO_HTMODE_VHT20 | IWINFO_HTMODE_VHT40 | IWINFO_HTMODE_VHT80;
3240 
3241                         switch ((m->nl_vht >> 2) & 3)
3242                         {
3243                         case 2:
3244                                 m->ht |= IWINFO_HTMODE_VHT80_80;
3245                                 /* fall through */
3246 
3247                         case 1:
3248                                 m->ht |= IWINFO_HTMODE_VHT160;
3249                         }
3250                 }
3251                 else
3252                 {
3253                         m->hw |= IWINFO_80211_A;
3254                 }
3255         }
3256 
3257         if (m->bands & IWINFO_BAND_60)
3258         {
3259                 m->hw |= IWINFO_80211_AD;
3260         }
3261 
3262 }
3263 
3264 static int nl80211_get_modelist_cb(struct nl_msg *msg, void *arg)
3265 {
3266         struct nl80211_modes *m = arg;
3267         int bands_remain;
3268         struct nlattr **attr = nl80211_parse(msg);
3269         struct nlattr *bands[NL80211_BAND_ATTR_MAX + 1];
3270         struct nlattr *band;
3271 
3272         if (attr[NL80211_ATTR_WIPHY_BANDS])
3273         {
3274                 nla_for_each_nested(band, attr[NL80211_ATTR_WIPHY_BANDS], bands_remain)
3275                 {
3276                         m->bands |= nl80211_get_band(band->nla_type);
3277 
3278                         nla_parse(bands, NL80211_BAND_ATTR_MAX,
3279                                   nla_data(band), nla_len(band), NULL);
3280 
3281                         if (bands[NL80211_BAND_ATTR_HT_CAPA])
3282                                 m->nl_ht = nla_get_u16(bands[NL80211_BAND_ATTR_HT_CAPA]);
3283 
3284                         if (bands[NL80211_BAND_ATTR_VHT_CAPA])
3285                                 m->nl_vht = nla_get_u32(bands[NL80211_BAND_ATTR_VHT_CAPA]);
3286 
3287                         if (bands[NL80211_BAND_ATTR_IFTYPE_DATA]) {
3288                                 struct nlattr *tb[NL80211_BAND_IFTYPE_ATTR_MAX + 1];
3289                                 struct nlattr *nl_iftype;
3290                                 int rem_band;
3291                                 int len;
3292 
3293                                 nla_for_each_nested(nl_iftype, bands[NL80211_BAND_ATTR_IFTYPE_DATA], rem_band) {
3294                                         nla_parse(tb, NL80211_BAND_IFTYPE_ATTR_MAX,
3295                                                   nla_data(nl_iftype), nla_len(nl_iftype), NULL);
3296 
3297                                         // HE
3298                                         if (tb[NL80211_BAND_IFTYPE_ATTR_HE_CAP_PHY]) {
3299                                                 len = nla_len(tb[NL80211_BAND_IFTYPE_ATTR_HE_CAP_PHY]);
3300 
3301                                                 if (len > sizeof(m->he_phy_cap) - 1)
3302                                                         len = sizeof(m->he_phy_cap) - 1;
3303                                                 memcpy(&((__u8 *)m->he_phy_cap)[1],
3304                                                         nla_data(tb[NL80211_BAND_IFTYPE_ATTR_HE_CAP_PHY]),
3305                                                         len);
3306                                         }
3307 
3308                                         // EHT
3309                                         if (tb[NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PHY]) {
3310                                                 len = nla_len(tb[NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PHY]);
3311 
3312                                                 if (len > sizeof(m->eht_phy_cap) - 1)
3313                                                         len = sizeof(m->eht_phy_cap) - 1;
3314                                                 memcpy(&((uint8_t *)m->eht_phy_cap)[1],
3315                                                         nla_data(tb[NL80211_BAND_IFTYPE_ATTR_EHT_CAP_PHY]),
3316                                                         len);
3317                                         }
3318                                 }
3319                         }
3320                 }
3321 
3322                 m->ok = 1;
3323         }
3324 
3325         return NL_SKIP;
3326 }
3327 
3328 static int nl80211_get_hwmodelist(const char *ifname, int *buf)
3329 {
3330         struct nl80211_msg_conveyor *cv;
3331         struct nl80211_modes m = {};
3332         uint32_t features = nl80211_get_protocol_features(ifname);
3333         int flags;
3334 
3335         flags = features & NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP ? NLM_F_DUMP : 0;
3336         cv = nl80211_msg(ifname, NL80211_CMD_GET_WIPHY, flags);
3337         if (!cv)
3338                 goto out;
3339 
3340         NLA_PUT_FLAG(cv->msg, NL80211_ATTR_SPLIT_WIPHY_DUMP);
3341         if (nl80211_send(cv, nl80211_get_modelist_cb, &m))
3342                 goto nla_put_failure;
3343 
3344         nl80211_eval_modelist(&m);
3345 
3346         *buf = m.hw;
3347 
3348         return 0;
3349 
3350 nla_put_failure:
3351         nl80211_free(cv);
3352 out:
3353         return -1;
3354 }
3355 
3356 struct chan_info {
3357         int width;
3358         int mode;
3359 };
3360 
3361 static int nl80211_get_htmode_cb(struct nl_msg *msg, void *arg)
3362 {
3363         struct nlattr **tb = nl80211_parse(msg);
3364         struct nlattr *cur;
3365         struct chan_info *chn = arg;
3366 
3367         if ((cur = tb[NL80211_ATTR_CHANNEL_WIDTH]))
3368                 chn->width = nla_get_u32(cur);
3369 
3370         if ((cur = tb[NL80211_ATTR_BSS_HT_OPMODE]))
3371                 chn->mode = nla_get_u32(cur);
3372 
3373         return NL_SKIP;
3374 }
3375 
3376 static int nl80211_get_htmode(const char *ifname, int *buf)
3377 {
3378         struct chan_info chn = { 0 };
3379         char *res, b[2] = { 0 };
3380         int err;
3381         bool he = false;
3382         bool eht = false;
3383 
3384         res = nl80211_phy2ifname(ifname);
3385         *buf = 0;
3386 
3387         err =  nl80211_request(res ? res : ifname,
3388                                 NL80211_CMD_GET_INTERFACE, 0,
3389                                 nl80211_get_htmode_cb, &chn);
3390         if (err)
3391                 return -1;
3392 
3393         if (nl80211_hostapd_query(res ? res : ifname, "ieee80211be", b, sizeof(b)))
3394                 eht = b[0] == '1';
3395 
3396         if (nl80211_hostapd_query(res ? res : ifname, "ieee80211ax", b, sizeof(b)))
3397                 he = b[0] == '1';
3398         else if (nl80211_wpactl_query(res ? res : ifname, "wifi_generation", b, sizeof(b))) {
3399                 he = b[0] == '6';
3400                 eht = b[0] == '7';
3401         }
3402 
3403         switch (chn.width) {
3404         case NL80211_CHAN_WIDTH_20:
3405                 if (eht)
3406                         *buf = IWINFO_HTMODE_EHT20;
3407                 else if (he)
3408                         *buf = IWINFO_HTMODE_HE20;
3409                 else if (chn.mode == -1)
3410                         *buf = IWINFO_HTMODE_VHT20;
3411                 else
3412                         *buf = IWINFO_HTMODE_HT20;
3413                 break;
3414         case NL80211_CHAN_WIDTH_40:
3415                 if (eht)
3416                         *buf = IWINFO_HTMODE_EHT40;
3417                 else if (he)
3418                         *buf = IWINFO_HTMODE_HE40;
3419                 else if (chn.mode == -1)
3420                         *buf = IWINFO_HTMODE_VHT40;
3421                 else
3422                         *buf = IWINFO_HTMODE_HT40;
3423                 break;
3424         case NL80211_CHAN_WIDTH_80:
3425                 if (eht)
3426                         *buf = IWINFO_HTMODE_EHT80;
3427                 else if (he)
3428                         *buf = IWINFO_HTMODE_HE80;
3429                 else
3430                         *buf = IWINFO_HTMODE_VHT80;
3431                 break;
3432         case NL80211_CHAN_WIDTH_80P80:
3433                 if (eht)
3434                         *buf = IWINFO_HTMODE_EHT80_80;
3435                 else if (he)
3436                         *buf = IWINFO_HTMODE_HE80_80;
3437                 else
3438                         *buf = IWINFO_HTMODE_VHT80_80;
3439                 break;
3440         case NL80211_CHAN_WIDTH_160:
3441                 if (eht)
3442                         *buf = IWINFO_HTMODE_EHT160;
3443                 else if (he)
3444                         *buf = IWINFO_HTMODE_HE160;
3445                 else
3446                         *buf = IWINFO_HTMODE_VHT160;
3447                 break;
3448         case NL80211_CHAN_WIDTH_320:
3449                 *buf = IWINFO_HTMODE_EHT320;
3450                 break;
3451         case NL80211_CHAN_WIDTH_5:
3452         case NL80211_CHAN_WIDTH_10:
3453         case NL80211_CHAN_WIDTH_20_NOHT:
3454                 *buf = IWINFO_HTMODE_NOHT;
3455                 break;
3456         default:
3457                 return -1;
3458         }
3459 
3460         return 0;
3461 }
3462 
3463 static int nl80211_get_htmodelist(const char *ifname, int *buf)
3464 {
3465         struct nl80211_msg_conveyor *cv;
3466         struct nl80211_modes m = {};
3467         uint32_t features = nl80211_get_protocol_features(ifname);
3468         int flags;
3469 
3470         flags = features & NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP ? NLM_F_DUMP : 0;
3471         cv = nl80211_msg(ifname, NL80211_CMD_GET_WIPHY, flags);
3472         if (!cv)
3473                 goto out;
3474 
3475         NLA_PUT_FLAG(cv->msg, NL80211_ATTR_SPLIT_WIPHY_DUMP);
3476         if (nl80211_send(cv, nl80211_get_modelist_cb, &m))
3477                 goto nla_put_failure;
3478 
3479         nl80211_eval_modelist(&m);
3480 
3481         *buf = m.ht;
3482 
3483         return 0;
3484 
3485 nla_put_failure:
3486         nl80211_free(cv);
3487 out:
3488         return -1;
3489 }
3490 
3491 
3492 static int nl80211_get_ifcomb_cb(struct nl_msg *msg, void *arg)
3493 {
3494         struct nlattr **attr = nl80211_parse(msg);
3495         struct nlattr *comb;
3496         int *ret = arg;
3497         int comb_rem, limit_rem, mode_rem;
3498 
3499         *ret = 0;
3500         if (!attr[NL80211_ATTR_INTERFACE_COMBINATIONS])
3501                 return NL_SKIP;
3502 
3503         nla_for_each_nested(comb, attr[NL80211_ATTR_INTERFACE_COMBINATIONS], comb_rem)
3504         {
3505                 static const struct nla_policy iface_combination_policy[NUM_NL80211_IFACE_COMB] = {
3506                         [NL80211_IFACE_COMB_LIMITS] = { .type = NLA_NESTED },
3507                         [NL80211_IFACE_COMB_MAXNUM] = { .type = NLA_U32 },
3508                 };
3509                 struct nlattr *tb_comb[NUM_NL80211_IFACE_COMB+1];
3510                 static const struct nla_policy iface_limit_policy[NUM_NL80211_IFACE_LIMIT] = {
3511                         [NL80211_IFACE_LIMIT_TYPES] = { .type = NLA_NESTED },
3512                         [NL80211_IFACE_LIMIT_MAX] = { .type = NLA_U32 },
3513                 };
3514                 struct nlattr *tb_limit[NUM_NL80211_IFACE_LIMIT+1];
3515                 struct nlattr *limit;
3516 
3517                 nla_parse_nested(tb_comb, NUM_NL80211_IFACE_COMB, comb, iface_combination_policy);
3518 
3519                 if (!tb_comb[NL80211_IFACE_COMB_LIMITS])
3520                         continue;
3521 
3522                 nla_for_each_nested(limit, tb_comb[NL80211_IFACE_COMB_LIMITS], limit_rem)
3523                 {
3524                         struct nlattr *mode;
3525 
3526                         nla_parse_nested(tb_limit, NUM_NL80211_IFACE_LIMIT, limit, iface_limit_policy);
3527 
3528                         if (!tb_limit[NL80211_IFACE_LIMIT_TYPES] ||
3529                             !tb_limit[NL80211_IFACE_LIMIT_MAX])
3530                                 continue;
3531 
3532                         if (nla_get_u32(tb_limit[NL80211_IFACE_LIMIT_MAX]) < 2)
3533                                 continue;
3534 
3535                         nla_for_each_nested(mode, tb_limit[NL80211_IFACE_LIMIT_TYPES], mode_rem) {
3536                                 if (nla_type(mode) == NL80211_IFTYPE_AP)
3537                                         *ret = 1;
3538                         }
3539                 }
3540         }
3541 
3542         return NL_SKIP;
3543 }
3544 
3545 static int nl80211_get_mbssid_support(const char *ifname, int *buf)
3546 {
3547         if (nl80211_request(ifname, NL80211_CMD_GET_WIPHY, 0,
3548                             nl80211_get_ifcomb_cb, buf))
3549                 return -1;
3550 
3551         return 0;
3552 }
3553 
3554 static int nl80211_hardware_id_from_fdt(struct iwinfo_hardware_id *id, const char *ifname)
3555 {
3556         char *phy, path[PATH_MAX];
3557 
3558         /* Try to determine the phy name from the given interface */
3559         phy = nl80211_ifname2phy(ifname);
3560 
3561         snprintf(path, sizeof(path), "/sys/class/%s/%s/device/of_node/compatible",
3562                  phy ? "ieee80211" : "net", phy ? phy : ifname);
3563 
3564         if (nl80211_readstr(path, id->compatible, sizeof(id->compatible)) <= 0)
3565                 return -1;
3566 
3567         return 0;
3568 }
3569 
3570 
3571 static int nl80211_get_hardware_id(const char *ifname, char *buf)
3572 {
3573         struct iwinfo_hardware_id *id = (struct iwinfo_hardware_id *)buf;
3574         char *phy, num[8], path[PATH_MAX];
3575         int i;
3576 
3577         struct { const char *path; uint16_t *dest; } lookup[] = {
3578                 { "vendor", &id->vendor_id },
3579                 { "device", &id->device_id },
3580                 { "subsystem_vendor", &id->subsystem_vendor_id },
3581                 { "subsystem_device", &id->subsystem_device_id },
3582                 { "../idVendor", &id->subsystem_vendor_id },
3583                 { "../idProduct", &id->subsystem_device_id }
3584         };
3585 
3586         memset(id, 0, sizeof(*id));
3587 
3588         /* Try to determine the phy name from the given interface */
3589         phy = nl80211_ifname2phy(ifname);
3590 
3591         for (i = 0; i < ARRAY_SIZE(lookup); i++)
3592         {
3593                 snprintf(path, sizeof(path), "/sys/class/%s/%s/device/%s",
3594                          phy ? "ieee80211" : "net",
3595                          phy ? phy : ifname, lookup[i].path);
3596 
3597                 if (nl80211_readstr(path, num, sizeof(num)) > 0)
3598                         *lookup[i].dest = strtoul(num, NULL, 16);
3599         }
3600 
3601         /* Failed to obtain hardware PCI/USB IDs... */
3602         if (id->vendor_id == 0 && id->device_id == 0 &&
3603             id->subsystem_vendor_id == 0 && id->subsystem_device_id == 0)
3604                 /* ... first fallback to FDT ... */
3605                 if (nl80211_hardware_id_from_fdt(id, ifname) == -1)
3606                         /* ... then board config */
3607                         return iwinfo_hardware_id_from_mtd(id);
3608 
3609         return 0;
3610 }
3611 
3612 static const struct iwinfo_hardware_entry *
3613 nl80211_get_hardware_entry(const char *ifname)
3614 {
3615         struct iwinfo_hardware_id id;
3616 
3617         if (nl80211_get_hardware_id(ifname, (char *)&id))
3618                 return NULL;
3619 
3620         return iwinfo_hardware(&id);
3621 }
3622 
3623 static int nl80211_get_hardware_name(const char *ifname, char *buf)
3624 {
3625         const struct iwinfo_hardware_entry *hw;
3626 
3627         if (!(hw = nl80211_get_hardware_entry(ifname)))
3628                 sprintf(buf, "Generic MAC80211");
3629         else
3630                 sprintf(buf, "%s %s", hw->vendor_name, hw->device_name);
3631 
3632         return 0;
3633 }
3634 
3635 static int nl80211_get_txpower_offset(const char *ifname, int *buf)
3636 {
3637         const struct iwinfo_hardware_entry *hw;
3638 
3639         if (!(hw = nl80211_get_hardware_entry(ifname)))
3640                 return -1;
3641 
3642         *buf = hw->txpower_offset;
3643         return 0;
3644 }
3645 
3646 static int nl80211_get_frequency_offset(const char *ifname, int *buf)
3647 {
3648         const struct iwinfo_hardware_entry *hw;
3649 
3650         if (!(hw = nl80211_get_hardware_entry(ifname)))
3651                 return -1;
3652 
3653         *buf = hw->frequency_offset;
3654         return 0;
3655 }
3656 
3657 static int nl80211_lookup_phyname(const char *section, char *buf)
3658 {
3659         const char *name;
3660         int idx;
3661 
3662         if (!strncmp(section, "path=", 5))
3663                 idx = nl80211_phy_idx_from_path(section + 5);
3664         else if (!strncmp(section, "macaddr=", 8))
3665                 idx = nl80211_phy_idx_from_macaddr(section + 8);
3666         else
3667                 idx = nl80211_phy_idx_from_uci(section);
3668 
3669         if (idx < 0)
3670                 return -1;
3671 
3672         name = nl80211_phyidx2name(idx);
3673         if (!name)
3674                 return -1;
3675 
3676         strcpy(buf, name);
3677         return 0;
3678 }
3679 
3680 static int nl80211_phy_path(const char *phyname, const char **path)
3681 {
3682         if (strchr(phyname, '/'))
3683                 return -1;
3684 
3685         *path = nl80211_phy_path_str(phyname);
3686         if (!*path)
3687                 return -1;
3688 
3689         return 0;
3690 }
3691 
3692 const struct iwinfo_ops nl80211_ops = {
3693         .name             = "nl80211",
3694         .probe            = nl80211_probe,
3695         .channel          = nl80211_get_channel,
3696         .center_chan1     = nl80211_get_center_chan1,
3697         .center_chan2     = nl80211_get_center_chan2,
3698         .frequency        = nl80211_get_frequency,
3699         .frequency_offset = nl80211_get_frequency_offset,
3700         .txpower          = nl80211_get_txpower,
3701         .txpower_offset   = nl80211_get_txpower_offset,
3702         .bitrate          = nl80211_get_bitrate,
3703         .signal           = nl80211_get_signal,
3704         .noise            = nl80211_get_noise,
3705         .quality          = nl80211_get_quality,
3706         .quality_max      = nl80211_get_quality_max,
3707         .mbssid_support   = nl80211_get_mbssid_support,
3708         .hwmodelist       = nl80211_get_hwmodelist,
3709         .htmodelist       = nl80211_get_htmodelist,
3710         .htmode           = nl80211_get_htmode,
3711         .mode             = nl80211_get_mode,
3712         .ssid             = nl80211_get_ssid,
3713         .bssid            = nl80211_get_bssid,
3714         .country          = nl80211_get_country,
3715         .hardware_id      = nl80211_get_hardware_id,
3716         .hardware_name    = nl80211_get_hardware_name,
3717         .encryption       = nl80211_get_encryption,
3718         .phyname          = nl80211_get_phyname,
3719         .assoclist        = nl80211_get_assoclist,
3720         .txpwrlist        = nl80211_get_txpwrlist,
3721         .scanlist         = nl80211_get_scanlist,
3722         .freqlist         = nl80211_get_freqlist,
3723         .countrylist      = nl80211_get_countrylist,
3724         .survey           = nl80211_get_survey,
3725         .lookup_phy       = nl80211_lookup_phyname,
3726         .phy_path         = nl80211_phy_path,
3727         .close            = nl80211_close
3728 };
3729 

This page was automatically generated by LXR 0.3.1.  •  OpenWrt