Home | History | Annotate | Line # | Download | only in net80211
ieee80211_ioctl.c revision 1.1.1.2
      1      1.1  dyoung /*-
      2      1.1  dyoung  * Copyright (c) 2001 Atsushi Onoe
      3      1.1  dyoung  * Copyright (c) 2002, 2003 Sam Leffler, Errno Consulting
      4      1.1  dyoung  * All rights reserved.
      5      1.1  dyoung  *
      6      1.1  dyoung  * Redistribution and use in source and binary forms, with or without
      7      1.1  dyoung  * modification, are permitted provided that the following conditions
      8      1.1  dyoung  * are met:
      9      1.1  dyoung  * 1. Redistributions of source code must retain the above copyright
     10      1.1  dyoung  *    notice, this list of conditions and the following disclaimer.
     11      1.1  dyoung  * 2. Redistributions in binary form must reproduce the above copyright
     12      1.1  dyoung  *    notice, this list of conditions and the following disclaimer in the
     13      1.1  dyoung  *    documentation and/or other materials provided with the distribution.
     14      1.1  dyoung  * 3. The name of the author may not be used to endorse or promote products
     15      1.1  dyoung  *    derived from this software without specific prior written permission.
     16      1.1  dyoung  *
     17      1.1  dyoung  * Alternatively, this software may be distributed under the terms of the
     18      1.1  dyoung  * GNU General Public License ("GPL") version 2 as published by the Free
     19      1.1  dyoung  * Software Foundation.
     20      1.1  dyoung  *
     21      1.1  dyoung  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     22      1.1  dyoung  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     23      1.1  dyoung  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     24      1.1  dyoung  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     25      1.1  dyoung  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     26      1.1  dyoung  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     27      1.1  dyoung  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     28      1.1  dyoung  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     29      1.1  dyoung  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     30      1.1  dyoung  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     31      1.1  dyoung  */
     32      1.1  dyoung 
     33      1.1  dyoung #include <sys/cdefs.h>
     34  1.1.1.2  dyoung __FBSDID("$FreeBSD: src/sys/net80211/ieee80211_ioctl.c,v 1.9 2003/11/13 05:23:58 sam Exp $");
     35      1.1  dyoung 
     36      1.1  dyoung /*
     37      1.1  dyoung  * IEEE 802.11 ioctl support (FreeBSD-specific)
     38      1.1  dyoung  */
     39      1.1  dyoung 
     40      1.1  dyoung #include <sys/endian.h>
     41      1.1  dyoung #include <sys/param.h>
     42      1.1  dyoung #include <sys/kernel.h>
     43      1.1  dyoung #include <sys/socket.h>
     44      1.1  dyoung #include <sys/sockio.h>
     45      1.1  dyoung #include <sys/systm.h>
     46      1.1  dyoung 
     47      1.1  dyoung #include <net/if.h>
     48      1.1  dyoung #include <net/if_arp.h>
     49      1.1  dyoung #include <net/if_media.h>
     50      1.1  dyoung #include <net/ethernet.h>
     51      1.1  dyoung 
     52      1.1  dyoung #include <net80211/ieee80211_var.h>
     53      1.1  dyoung #include <net80211/ieee80211_ioctl.h>
     54      1.1  dyoung 
     55      1.1  dyoung #include <dev/wi/if_wavelan_ieee.h>
     56      1.1  dyoung 
     57      1.1  dyoung /*
     58      1.1  dyoung  * XXX
     59      1.1  dyoung  * Wireless LAN specific configuration interface, which is compatible
     60      1.1  dyoung  * with wicontrol(8).
     61      1.1  dyoung  */
     62      1.1  dyoung 
     63      1.1  dyoung int
     64      1.1  dyoung ieee80211_cfgget(struct ifnet *ifp, u_long cmd, caddr_t data)
     65      1.1  dyoung {
     66      1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
     67      1.1  dyoung 	int i, j, error;
     68      1.1  dyoung 	struct ifreq *ifr = (struct ifreq *)data;
     69      1.1  dyoung 	struct wi_req wreq;
     70      1.1  dyoung 	struct wi_ltv_keys *keys;
     71      1.1  dyoung 	struct wi_apinfo *ap;
     72      1.1  dyoung 	struct ieee80211_node *ni;
     73      1.1  dyoung 	struct ieee80211_rateset *rs;
     74      1.1  dyoung 	struct wi_sigcache wsc;
     75      1.1  dyoung 	struct wi_scan_p2_hdr *p2;
     76      1.1  dyoung 	struct wi_scan_res *res;
     77      1.1  dyoung 
     78      1.1  dyoung 	error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
     79      1.1  dyoung 	if (error)
     80      1.1  dyoung 		return error;
     81      1.1  dyoung 	wreq.wi_len = 0;
     82      1.1  dyoung 	switch (wreq.wi_type) {
     83      1.1  dyoung 	case WI_RID_SERIALNO:
     84      1.1  dyoung 		/* nothing appropriate */
     85      1.1  dyoung 		break;
     86      1.1  dyoung 	case WI_RID_NODENAME:
     87      1.1  dyoung 		strcpy((char *)&wreq.wi_val[1], hostname);
     88      1.1  dyoung 		wreq.wi_val[0] = htole16(strlen(hostname));
     89      1.1  dyoung 		wreq.wi_len = (1 + strlen(hostname) + 1) / 2;
     90      1.1  dyoung 		break;
     91      1.1  dyoung 	case WI_RID_CURRENT_SSID:
     92      1.1  dyoung 		if (ic->ic_state != IEEE80211_S_RUN) {
     93      1.1  dyoung 			wreq.wi_val[0] = 0;
     94      1.1  dyoung 			wreq.wi_len = 1;
     95      1.1  dyoung 			break;
     96      1.1  dyoung 		}
     97      1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_bss->ni_esslen);
     98      1.1  dyoung 		memcpy(&wreq.wi_val[1], ic->ic_bss->ni_essid,
     99      1.1  dyoung 		    ic->ic_bss->ni_esslen);
    100      1.1  dyoung 		wreq.wi_len = (1 + ic->ic_bss->ni_esslen + 1) / 2;
    101      1.1  dyoung 		break;
    102      1.1  dyoung 	case WI_RID_OWN_SSID:
    103      1.1  dyoung 	case WI_RID_DESIRED_SSID:
    104      1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_des_esslen);
    105      1.1  dyoung 		memcpy(&wreq.wi_val[1], ic->ic_des_essid, ic->ic_des_esslen);
    106      1.1  dyoung 		wreq.wi_len = (1 + ic->ic_des_esslen + 1) / 2;
    107      1.1  dyoung 		break;
    108      1.1  dyoung 	case WI_RID_CURRENT_BSSID:
    109      1.1  dyoung 		if (ic->ic_state == IEEE80211_S_RUN)
    110      1.1  dyoung 			IEEE80211_ADDR_COPY(wreq.wi_val, ic->ic_bss->ni_bssid);
    111      1.1  dyoung 		else
    112      1.1  dyoung 			memset(wreq.wi_val, 0, IEEE80211_ADDR_LEN);
    113      1.1  dyoung 		wreq.wi_len = IEEE80211_ADDR_LEN / 2;
    114      1.1  dyoung 		break;
    115      1.1  dyoung 	case WI_RID_CHANNEL_LIST:
    116      1.1  dyoung 		memset(wreq.wi_val, 0, sizeof(wreq.wi_val));
    117      1.1  dyoung 		/*
    118      1.1  dyoung 		 * Since channel 0 is not available for DS, channel 1
    119      1.1  dyoung 		 * is assigned to LSB on WaveLAN.
    120      1.1  dyoung 		 */
    121      1.1  dyoung 		if (ic->ic_phytype == IEEE80211_T_DS)
    122      1.1  dyoung 			i = 1;
    123      1.1  dyoung 		else
    124      1.1  dyoung 			i = 0;
    125      1.1  dyoung 		for (j = 0; i <= IEEE80211_CHAN_MAX; i++, j++)
    126      1.1  dyoung 			if (isset(ic->ic_chan_active, i)) {
    127      1.1  dyoung 				setbit((u_int8_t *)wreq.wi_val, j);
    128      1.1  dyoung 				wreq.wi_len = j / 16 + 1;
    129      1.1  dyoung 			}
    130      1.1  dyoung 		break;
    131      1.1  dyoung 	case WI_RID_OWN_CHNL:
    132      1.1  dyoung 		wreq.wi_val[0] = htole16(
    133      1.1  dyoung 			ieee80211_chan2ieee(ic, ic->ic_ibss_chan));
    134      1.1  dyoung 		wreq.wi_len = 1;
    135      1.1  dyoung 		break;
    136      1.1  dyoung 	case WI_RID_CURRENT_CHAN:
    137      1.1  dyoung 		wreq.wi_val[0] = htole16(
    138      1.1  dyoung 			ieee80211_chan2ieee(ic, ic->ic_bss->ni_chan));
    139      1.1  dyoung 		wreq.wi_len = 1;
    140      1.1  dyoung 		break;
    141      1.1  dyoung 	case WI_RID_COMMS_QUALITY:
    142      1.1  dyoung 		wreq.wi_val[0] = 0;				/* quality */
    143  1.1.1.2  dyoung 		wreq.wi_val[1] =
    144  1.1.1.2  dyoung 			htole16((*ic->ic_node_getrssi)(ic, ic->ic_bss));
    145      1.1  dyoung 		wreq.wi_val[2] = 0;				/* noise */
    146      1.1  dyoung 		wreq.wi_len = 3;
    147      1.1  dyoung 		break;
    148      1.1  dyoung 	case WI_RID_PROMISC:
    149      1.1  dyoung 		wreq.wi_val[0] = htole16((ifp->if_flags & IFF_PROMISC) ? 1 : 0);
    150      1.1  dyoung 		wreq.wi_len = 1;
    151      1.1  dyoung 		break;
    152      1.1  dyoung 	case WI_RID_PORTTYPE:
    153      1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_opmode);
    154      1.1  dyoung 		wreq.wi_len = 1;
    155      1.1  dyoung 		break;
    156      1.1  dyoung 	case WI_RID_MAC_NODE:
    157      1.1  dyoung 		IEEE80211_ADDR_COPY(wreq.wi_val, ic->ic_myaddr);
    158      1.1  dyoung 		wreq.wi_len = IEEE80211_ADDR_LEN / 2;
    159      1.1  dyoung 		break;
    160      1.1  dyoung 	case WI_RID_TX_RATE:
    161      1.1  dyoung 		if (ic->ic_fixed_rate == -1)
    162      1.1  dyoung 			wreq.wi_val[0] = 0;	/* auto */
    163      1.1  dyoung 		else
    164      1.1  dyoung 			wreq.wi_val[0] = htole16(
    165      1.1  dyoung 			    (ic->ic_sup_rates[ic->ic_curmode].rs_rates[ic->ic_fixed_rate] &
    166      1.1  dyoung 			    IEEE80211_RATE_VAL) / 2);
    167      1.1  dyoung 		wreq.wi_len = 1;
    168      1.1  dyoung 		break;
    169      1.1  dyoung 	case WI_RID_CUR_TX_RATE:
    170      1.1  dyoung 		wreq.wi_val[0] = htole16(
    171      1.1  dyoung 		    (ic->ic_bss->ni_rates.rs_rates[ic->ic_bss->ni_txrate] &
    172      1.1  dyoung 		    IEEE80211_RATE_VAL) / 2);
    173      1.1  dyoung 		wreq.wi_len = 1;
    174      1.1  dyoung 		break;
    175      1.1  dyoung 	case WI_RID_RTS_THRESH:
    176      1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_rtsthreshold);
    177      1.1  dyoung 		wreq.wi_len = 1;
    178      1.1  dyoung 		break;
    179      1.1  dyoung 	case WI_RID_CREATE_IBSS:
    180      1.1  dyoung 		wreq.wi_val[0] =
    181      1.1  dyoung 		    htole16((ic->ic_flags & IEEE80211_F_IBSSON) ? 1 : 0);
    182      1.1  dyoung 		wreq.wi_len = 1;
    183      1.1  dyoung 		break;
    184      1.1  dyoung 	case WI_RID_MICROWAVE_OVEN:
    185      1.1  dyoung 		wreq.wi_val[0] = 0;	/* no ... not supported */
    186      1.1  dyoung 		wreq.wi_len = 1;
    187      1.1  dyoung 		break;
    188      1.1  dyoung 	case WI_RID_ROAMING_MODE:
    189      1.1  dyoung 		wreq.wi_val[0] = htole16(1);	/* enabled ... not supported */
    190      1.1  dyoung 		wreq.wi_len = 1;
    191      1.1  dyoung 		break;
    192      1.1  dyoung 	case WI_RID_SYSTEM_SCALE:
    193      1.1  dyoung 		wreq.wi_val[0] = htole16(1);	/* low density ... not supp */
    194      1.1  dyoung 		wreq.wi_len = 1;
    195      1.1  dyoung 		break;
    196      1.1  dyoung 	case WI_RID_PM_ENABLED:
    197      1.1  dyoung 		wreq.wi_val[0] =
    198      1.1  dyoung 		    htole16((ic->ic_flags & IEEE80211_F_PMGTON) ? 1 : 0);
    199      1.1  dyoung 		wreq.wi_len = 1;
    200      1.1  dyoung 		break;
    201      1.1  dyoung 	case WI_RID_MAX_SLEEP:
    202      1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_lintval);
    203      1.1  dyoung 		wreq.wi_len = 1;
    204      1.1  dyoung 		break;
    205      1.1  dyoung 	case WI_RID_CUR_BEACON_INT:
    206      1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_bss->ni_intval);
    207      1.1  dyoung 		wreq.wi_len = 1;
    208      1.1  dyoung 		break;
    209      1.1  dyoung 	case WI_RID_WEP_AVAIL:
    210      1.1  dyoung 		wreq.wi_val[0] =
    211      1.1  dyoung 		    htole16((ic->ic_caps & IEEE80211_C_WEP) ? 1 : 0);
    212      1.1  dyoung 		wreq.wi_len = 1;
    213      1.1  dyoung 		break;
    214      1.1  dyoung 	case WI_RID_CNFAUTHMODE:
    215      1.1  dyoung 		wreq.wi_val[0] = htole16(1);	/* TODO: open system only */
    216      1.1  dyoung 		wreq.wi_len = 1;
    217      1.1  dyoung 		break;
    218      1.1  dyoung 	case WI_RID_ENCRYPTION:
    219      1.1  dyoung 		wreq.wi_val[0] =
    220      1.1  dyoung 		    htole16((ic->ic_flags & IEEE80211_F_WEPON) ? 1 : 0);
    221      1.1  dyoung 		wreq.wi_len = 1;
    222      1.1  dyoung 		break;
    223      1.1  dyoung 	case WI_RID_TX_CRYPT_KEY:
    224      1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_wep_txkey);
    225      1.1  dyoung 		wreq.wi_len = 1;
    226      1.1  dyoung 		break;
    227      1.1  dyoung 	case WI_RID_DEFLT_CRYPT_KEYS:
    228      1.1  dyoung 		keys = (struct wi_ltv_keys *)&wreq;
    229      1.1  dyoung 		/* do not show keys to non-root user */
    230      1.1  dyoung 		error = suser(curthread);
    231      1.1  dyoung 		if (error) {
    232      1.1  dyoung 			memset(keys, 0, sizeof(*keys));
    233      1.1  dyoung 			error = 0;
    234      1.1  dyoung 			break;
    235      1.1  dyoung 		}
    236      1.1  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    237      1.1  dyoung 			keys->wi_keys[i].wi_keylen =
    238      1.1  dyoung 			    htole16(ic->ic_nw_keys[i].wk_len);
    239      1.1  dyoung 			memcpy(keys->wi_keys[i].wi_keydat,
    240      1.1  dyoung 			    ic->ic_nw_keys[i].wk_key, ic->ic_nw_keys[i].wk_len);
    241      1.1  dyoung 		}
    242      1.1  dyoung 		wreq.wi_len = sizeof(*keys) / 2;
    243      1.1  dyoung 		break;
    244      1.1  dyoung 	case WI_RID_MAX_DATALEN:
    245      1.1  dyoung 		wreq.wi_val[0] = htole16(IEEE80211_MAX_LEN);	/* TODO: frag */
    246      1.1  dyoung 		wreq.wi_len = 1;
    247      1.1  dyoung 		break;
    248      1.1  dyoung 	case WI_RID_IFACE_STATS:
    249      1.1  dyoung 		/* XXX: should be implemented in lower drivers */
    250      1.1  dyoung 		break;
    251      1.1  dyoung 	case WI_RID_READ_APS:
    252      1.1  dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP) {
    253      1.1  dyoung 			/*
    254      1.1  dyoung 			 * Don't return results until active scan completes.
    255      1.1  dyoung 			 */
    256      1.1  dyoung 			if (ic->ic_state == IEEE80211_S_SCAN &&
    257      1.1  dyoung 			    (ic->ic_flags & IEEE80211_F_ASCAN)) {
    258      1.1  dyoung 				error = EINPROGRESS;
    259      1.1  dyoung 				break;
    260      1.1  dyoung 			}
    261      1.1  dyoung 		}
    262      1.1  dyoung 		i = 0;
    263      1.1  dyoung 		ap = (void *)((char *)wreq.wi_val + sizeof(i));
    264      1.1  dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    265      1.1  dyoung 			if ((caddr_t)(ap + 1) > (caddr_t)(&wreq + 1))
    266      1.1  dyoung 				break;
    267      1.1  dyoung 			memset(ap, 0, sizeof(*ap));
    268      1.1  dyoung 			if (ic->ic_opmode == IEEE80211_M_HOSTAP) {
    269      1.1  dyoung 				IEEE80211_ADDR_COPY(ap->bssid, ni->ni_macaddr);
    270      1.1  dyoung 				ap->namelen = ic->ic_des_esslen;
    271      1.1  dyoung 				if (ic->ic_des_esslen)
    272      1.1  dyoung 					memcpy(ap->name, ic->ic_des_essid,
    273      1.1  dyoung 					    ic->ic_des_esslen);
    274      1.1  dyoung 			} else {
    275      1.1  dyoung 				IEEE80211_ADDR_COPY(ap->bssid, ni->ni_bssid);
    276      1.1  dyoung 				ap->namelen = ni->ni_esslen;
    277      1.1  dyoung 				if (ni->ni_esslen)
    278      1.1  dyoung 					memcpy(ap->name, ni->ni_essid,
    279      1.1  dyoung 					    ni->ni_esslen);
    280      1.1  dyoung 			}
    281      1.1  dyoung 			ap->channel = ieee80211_chan2ieee(ic, ni->ni_chan);
    282  1.1.1.2  dyoung 			ap->signal = (*ic->ic_node_getrssi)(ic, ni);
    283      1.1  dyoung 			ap->capinfo = ni->ni_capinfo;
    284      1.1  dyoung 			ap->interval = ni->ni_intval;
    285      1.1  dyoung 			rs = &ni->ni_rates;
    286      1.1  dyoung 			for (j = 0; j < rs->rs_nrates; j++) {
    287      1.1  dyoung 				if (rs->rs_rates[j] & IEEE80211_RATE_BASIC) {
    288      1.1  dyoung 					ap->rate = (rs->rs_rates[j] &
    289      1.1  dyoung 					    IEEE80211_RATE_VAL) * 5; /* XXX */
    290      1.1  dyoung 				}
    291      1.1  dyoung 			}
    292      1.1  dyoung 			i++;
    293      1.1  dyoung 			ap++;
    294      1.1  dyoung 		}
    295      1.1  dyoung 		memcpy(wreq.wi_val, &i, sizeof(i));
    296      1.1  dyoung 		wreq.wi_len = (sizeof(int) + sizeof(*ap) * i) / 2;
    297      1.1  dyoung 		break;
    298      1.1  dyoung 	case WI_RID_PRISM2:
    299      1.1  dyoung 		wreq.wi_val[0] = 1;	/* XXX lie so SCAN_RES can give rates */
    300      1.1  dyoung 		wreq.wi_len = sizeof(u_int16_t) / 2;
    301      1.1  dyoung 		break;
    302      1.1  dyoung 	case WI_RID_SCAN_RES:			/* compatibility interface */
    303      1.1  dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP &&
    304      1.1  dyoung 		    ic->ic_state == IEEE80211_S_SCAN) {
    305      1.1  dyoung 			error = EINPROGRESS;
    306      1.1  dyoung 			break;
    307      1.1  dyoung 		}
    308      1.1  dyoung 		/* NB: we use the Prism2 format so we can return rate info */
    309      1.1  dyoung 		p2 = (struct wi_scan_p2_hdr *)wreq.wi_val;
    310      1.1  dyoung 		res = (void *)&p2[1];
    311      1.1  dyoung 		i = 0;
    312      1.1  dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    313      1.1  dyoung 			if ((caddr_t)(res + 1) > (caddr_t)(&wreq + 1))
    314      1.1  dyoung 				break;
    315      1.1  dyoung 			res->wi_chan = ieee80211_chan2ieee(ic, ni->ni_chan);
    316      1.1  dyoung 			res->wi_noise = 0;
    317  1.1.1.2  dyoung 			res->wi_signal = (*ic->ic_node_getrssi)(ic, ni);
    318      1.1  dyoung 			IEEE80211_ADDR_COPY(res->wi_bssid, ni->ni_bssid);
    319      1.1  dyoung 			res->wi_interval = ni->ni_intval;
    320      1.1  dyoung 			res->wi_capinfo = ni->ni_capinfo;
    321      1.1  dyoung 			res->wi_ssid_len = ni->ni_esslen;
    322      1.1  dyoung 			memcpy(res->wi_ssid, ni->ni_essid, IEEE80211_NWID_LEN);
    323      1.1  dyoung 			/* NB: assumes wi_srates holds <= ni->ni_rates */
    324      1.1  dyoung 			memcpy(res->wi_srates, ni->ni_rates.rs_rates,
    325      1.1  dyoung 				sizeof(res->wi_srates));
    326      1.1  dyoung 			if (ni->ni_rates.rs_nrates < 10)
    327      1.1  dyoung 				res->wi_srates[ni->ni_rates.rs_nrates] = 0;
    328      1.1  dyoung 			res->wi_rate = ni->ni_rates.rs_rates[ni->ni_txrate];
    329      1.1  dyoung 			res->wi_rsvd = 0;
    330      1.1  dyoung 			res++, i++;
    331      1.1  dyoung 		}
    332      1.1  dyoung 		p2->wi_rsvd = 0;
    333      1.1  dyoung 		p2->wi_reason = i;
    334      1.1  dyoung 		wreq.wi_len = (sizeof(*p2) + sizeof(*res) * i) / 2;
    335      1.1  dyoung 		break;
    336      1.1  dyoung 	case WI_RID_READ_CACHE:
    337      1.1  dyoung 		i = 0;
    338      1.1  dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    339      1.1  dyoung 			if (i == (WI_MAX_DATALEN/sizeof(struct wi_sigcache))-1)
    340      1.1  dyoung 				break;
    341      1.1  dyoung 			IEEE80211_ADDR_COPY(wsc.macsrc, ni->ni_macaddr);
    342      1.1  dyoung 			memset(&wsc.ipsrc, 0, sizeof(wsc.ipsrc));
    343  1.1.1.2  dyoung 			wsc.signal = (*ic->ic_node_getrssi)(ic, ni);
    344      1.1  dyoung 			wsc.noise = 0;
    345      1.1  dyoung 			wsc.quality = 0;
    346      1.1  dyoung 			memcpy((caddr_t)wreq.wi_val + sizeof(wsc) * i,
    347      1.1  dyoung 			    &wsc, sizeof(wsc));
    348      1.1  dyoung 			i++;
    349      1.1  dyoung 		}
    350      1.1  dyoung 		wreq.wi_len = sizeof(wsc) * i / 2;
    351      1.1  dyoung 		break;
    352      1.1  dyoung 	case WI_RID_SCAN_APS:
    353      1.1  dyoung 		error = EINVAL;
    354      1.1  dyoung 		break;
    355      1.1  dyoung 	default:
    356      1.1  dyoung 		error = EINVAL;
    357      1.1  dyoung 		break;
    358      1.1  dyoung 	}
    359      1.1  dyoung 	if (error == 0) {
    360      1.1  dyoung 		wreq.wi_len++;
    361      1.1  dyoung 		error = copyout(&wreq, ifr->ifr_data, sizeof(wreq));
    362      1.1  dyoung 	}
    363      1.1  dyoung 	return error;
    364      1.1  dyoung }
    365      1.1  dyoung 
    366      1.1  dyoung static int
    367      1.1  dyoung findrate(struct ieee80211com *ic, enum ieee80211_phymode mode, int rate)
    368      1.1  dyoung {
    369      1.1  dyoung #define	IEEERATE(_ic,_m,_i) \
    370      1.1  dyoung 	((_ic)->ic_sup_rates[_m].rs_rates[_i] & IEEE80211_RATE_VAL)
    371      1.1  dyoung 	int i, nrates = ic->ic_sup_rates[mode].rs_nrates;
    372      1.1  dyoung 	for (i = 0; i < nrates; i++)
    373      1.1  dyoung 		if (IEEERATE(ic, mode, i) == rate)
    374      1.1  dyoung 			return i;
    375      1.1  dyoung 	return -1;
    376      1.1  dyoung #undef IEEERATE
    377      1.1  dyoung }
    378      1.1  dyoung 
    379  1.1.1.2  dyoung /*
    380  1.1.1.2  dyoung  * Prepare to do a user-initiated scan for AP's.  If no
    381  1.1.1.2  dyoung  * current/default channel is setup or the current channel
    382  1.1.1.2  dyoung  * is invalid then pick the first available channel from
    383  1.1.1.2  dyoung  * the active list as the place to start the scan.
    384  1.1.1.2  dyoung  */
    385  1.1.1.2  dyoung static int
    386  1.1.1.2  dyoung ieee80211_setupscan(struct ieee80211com *ic)
    387  1.1.1.2  dyoung {
    388  1.1.1.2  dyoung 	u_char *chanlist = ic->ic_chan_active;
    389  1.1.1.2  dyoung 	int i;
    390  1.1.1.2  dyoung 
    391  1.1.1.2  dyoung 	if (ic->ic_ibss_chan == NULL ||
    392  1.1.1.2  dyoung 	    isclr(chanlist, ieee80211_chan2ieee(ic, ic->ic_ibss_chan))) {
    393  1.1.1.2  dyoung 		for (i = 0; i <= IEEE80211_CHAN_MAX; i++)
    394  1.1.1.2  dyoung 			if (isset(chanlist, i)) {
    395  1.1.1.2  dyoung 				ic->ic_ibss_chan = &ic->ic_channels[i];
    396  1.1.1.2  dyoung 				goto found;
    397  1.1.1.2  dyoung 			}
    398  1.1.1.2  dyoung 		return EINVAL;			/* no active channels */
    399  1.1.1.2  dyoung found:
    400  1.1.1.2  dyoung 		;
    401  1.1.1.2  dyoung 	}
    402  1.1.1.2  dyoung 	if (ic->ic_bss->ni_chan == IEEE80211_CHAN_ANYC ||
    403  1.1.1.2  dyoung 	    isclr(chanlist, ieee80211_chan2ieee(ic, ic->ic_bss->ni_chan)))
    404  1.1.1.2  dyoung 		ic->ic_bss->ni_chan = ic->ic_ibss_chan;
    405  1.1.1.2  dyoung 	/*
    406  1.1.1.2  dyoung 	 * XXX don't permit a scan to be started unless we
    407  1.1.1.2  dyoung 	 * know the device is ready.  For the moment this means
    408  1.1.1.2  dyoung 	 * the device is marked up as this is the required to
    409  1.1.1.2  dyoung 	 * initialize the hardware.  It would be better to permit
    410  1.1.1.2  dyoung 	 * scanning prior to being up but that'll require some
    411  1.1.1.2  dyoung 	 * changes to the infrastructure.
    412  1.1.1.2  dyoung 	 */
    413  1.1.1.2  dyoung 	return (ic->ic_if.if_flags & IFF_UP) ? 0 : ENETRESET;
    414  1.1.1.2  dyoung }
    415  1.1.1.2  dyoung 
    416      1.1  dyoung int
    417      1.1  dyoung ieee80211_cfgset(struct ifnet *ifp, u_long cmd, caddr_t data)
    418      1.1  dyoung {
    419      1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    420      1.1  dyoung 	int i, j, len, error, rate;
    421      1.1  dyoung 	struct ifreq *ifr = (struct ifreq *)data;
    422      1.1  dyoung 	struct wi_ltv_keys *keys;
    423      1.1  dyoung 	struct wi_req wreq;
    424      1.1  dyoung 	u_char chanlist[roundup(IEEE80211_CHAN_MAX, NBBY)];
    425      1.1  dyoung 
    426      1.1  dyoung 	error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
    427      1.1  dyoung 	if (error)
    428      1.1  dyoung 		return error;
    429      1.1  dyoung 	len = wreq.wi_len ? (wreq.wi_len - 1) * 2 : 0;
    430      1.1  dyoung 	switch (wreq.wi_type) {
    431      1.1  dyoung 	case WI_RID_SERIALNO:
    432      1.1  dyoung 	case WI_RID_NODENAME:
    433      1.1  dyoung 		return EPERM;
    434      1.1  dyoung 	case WI_RID_CURRENT_SSID:
    435      1.1  dyoung 		return EPERM;
    436      1.1  dyoung 	case WI_RID_OWN_SSID:
    437      1.1  dyoung 	case WI_RID_DESIRED_SSID:
    438      1.1  dyoung 		if (le16toh(wreq.wi_val[0]) * 2 > len ||
    439      1.1  dyoung 		    le16toh(wreq.wi_val[0]) > IEEE80211_NWID_LEN) {
    440      1.1  dyoung 			error = ENOSPC;
    441      1.1  dyoung 			break;
    442      1.1  dyoung 		}
    443      1.1  dyoung 		memset(ic->ic_des_essid, 0, sizeof(ic->ic_des_essid));
    444      1.1  dyoung 		ic->ic_des_esslen = le16toh(wreq.wi_val[0]) * 2;
    445      1.1  dyoung 		memcpy(ic->ic_des_essid, &wreq.wi_val[1], ic->ic_des_esslen);
    446      1.1  dyoung 		error = ENETRESET;
    447      1.1  dyoung 		break;
    448      1.1  dyoung 	case WI_RID_CURRENT_BSSID:
    449      1.1  dyoung 		return EPERM;
    450      1.1  dyoung 	case WI_RID_OWN_CHNL:
    451      1.1  dyoung 		if (len != 2)
    452      1.1  dyoung 			return EINVAL;
    453      1.1  dyoung 		i = le16toh(wreq.wi_val[0]);
    454      1.1  dyoung 		if (i < 0 ||
    455      1.1  dyoung 		    i > IEEE80211_CHAN_MAX ||
    456      1.1  dyoung 		    isclr(ic->ic_chan_active, i))
    457      1.1  dyoung 			return EINVAL;
    458      1.1  dyoung 		ic->ic_ibss_chan = &ic->ic_channels[i];
    459      1.1  dyoung 		if (ic->ic_flags & IEEE80211_F_SIBSS)
    460      1.1  dyoung 			error = ENETRESET;
    461      1.1  dyoung 		break;
    462      1.1  dyoung 	case WI_RID_CURRENT_CHAN:
    463      1.1  dyoung 		return EPERM;
    464      1.1  dyoung 	case WI_RID_COMMS_QUALITY:
    465      1.1  dyoung 		return EPERM;
    466      1.1  dyoung 	case WI_RID_PROMISC:
    467      1.1  dyoung 		if (len != 2)
    468      1.1  dyoung 			return EINVAL;
    469      1.1  dyoung 		if (ifp->if_flags & IFF_PROMISC) {
    470      1.1  dyoung 			if (wreq.wi_val[0] == 0) {
    471      1.1  dyoung 				ifp->if_flags &= ~IFF_PROMISC;
    472      1.1  dyoung 				error = ENETRESET;
    473      1.1  dyoung 			}
    474      1.1  dyoung 		} else {
    475      1.1  dyoung 			if (wreq.wi_val[0] != 0) {
    476      1.1  dyoung 				ifp->if_flags |= IFF_PROMISC;
    477      1.1  dyoung 				error = ENETRESET;
    478      1.1  dyoung 			}
    479      1.1  dyoung 		}
    480      1.1  dyoung 		break;
    481      1.1  dyoung 	case WI_RID_PORTTYPE:
    482      1.1  dyoung 		if (len != 2)
    483      1.1  dyoung 			return EINVAL;
    484      1.1  dyoung 		switch (le16toh(wreq.wi_val[0])) {
    485      1.1  dyoung 		case IEEE80211_M_STA:
    486      1.1  dyoung 			break;
    487      1.1  dyoung 		case IEEE80211_M_IBSS:
    488      1.1  dyoung 			if (!(ic->ic_caps & IEEE80211_C_IBSS))
    489      1.1  dyoung 				return EINVAL;
    490      1.1  dyoung 			break;
    491      1.1  dyoung 		case IEEE80211_M_AHDEMO:
    492      1.1  dyoung 			if (ic->ic_phytype != IEEE80211_T_DS ||
    493      1.1  dyoung 			    !(ic->ic_caps & IEEE80211_C_AHDEMO))
    494      1.1  dyoung 				return EINVAL;
    495      1.1  dyoung 			break;
    496      1.1  dyoung 		case IEEE80211_M_HOSTAP:
    497      1.1  dyoung 			if (!(ic->ic_caps & IEEE80211_C_HOSTAP))
    498      1.1  dyoung 				return EINVAL;
    499      1.1  dyoung 			break;
    500      1.1  dyoung 		default:
    501      1.1  dyoung 			return EINVAL;
    502      1.1  dyoung 		}
    503      1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != ic->ic_opmode) {
    504      1.1  dyoung 			ic->ic_opmode = le16toh(wreq.wi_val[0]);
    505      1.1  dyoung 			error = ENETRESET;
    506      1.1  dyoung 		}
    507      1.1  dyoung 		break;
    508      1.1  dyoung #if 0
    509      1.1  dyoung 	case WI_RID_MAC_NODE:
    510      1.1  dyoung 		if (len != IEEE80211_ADDR_LEN)
    511      1.1  dyoung 			return EINVAL;
    512      1.1  dyoung 		IEEE80211_ADDR_COPY(LLADDR(ifp->if_sadl), wreq.wi_val);
    513      1.1  dyoung 		/* if_init will copy lladdr into ic_myaddr */
    514      1.1  dyoung 		error = ENETRESET;
    515      1.1  dyoung 		break;
    516      1.1  dyoung #endif
    517      1.1  dyoung 	case WI_RID_TX_RATE:
    518      1.1  dyoung 		if (len != 2)
    519      1.1  dyoung 			return EINVAL;
    520      1.1  dyoung 		if (wreq.wi_val[0] == 0) {
    521      1.1  dyoung 			/* auto */
    522      1.1  dyoung 			ic->ic_fixed_rate = -1;
    523      1.1  dyoung 			break;
    524      1.1  dyoung 		}
    525      1.1  dyoung 		rate = 2 * le16toh(wreq.wi_val[0]);
    526      1.1  dyoung 		if (ic->ic_curmode == IEEE80211_MODE_AUTO) {
    527      1.1  dyoung 			/*
    528      1.1  dyoung 			 * In autoselect mode search for the rate.  We take
    529      1.1  dyoung 			 * the first instance which may not be right, but we
    530      1.1  dyoung 			 * are limited by the interface.  Note that we also
    531      1.1  dyoung 			 * lock the mode to insure the rate is meaningful
    532      1.1  dyoung 			 * when it is used.
    533      1.1  dyoung 			 */
    534      1.1  dyoung 			for (j = IEEE80211_MODE_11A;
    535      1.1  dyoung 			     j < IEEE80211_MODE_MAX; j++) {
    536      1.1  dyoung 				if ((ic->ic_modecaps & (1<<j)) == 0)
    537      1.1  dyoung 					continue;
    538      1.1  dyoung 				i = findrate(ic, j, rate);
    539      1.1  dyoung 				if (i != -1) {
    540      1.1  dyoung 					/* lock mode too */
    541      1.1  dyoung 					ic->ic_curmode = j;
    542      1.1  dyoung 					goto setrate;
    543      1.1  dyoung 				}
    544      1.1  dyoung 			}
    545      1.1  dyoung 		} else {
    546      1.1  dyoung 			i = findrate(ic, ic->ic_curmode, rate);
    547      1.1  dyoung 			if (i != -1)
    548      1.1  dyoung 				goto setrate;
    549      1.1  dyoung 		}
    550      1.1  dyoung 		return EINVAL;
    551      1.1  dyoung 	setrate:
    552      1.1  dyoung 		ic->ic_fixed_rate = i;
    553      1.1  dyoung 		error = ENETRESET;
    554      1.1  dyoung 		break;
    555      1.1  dyoung 	case WI_RID_CUR_TX_RATE:
    556      1.1  dyoung 		return EPERM;
    557      1.1  dyoung 	case WI_RID_RTS_THRESH:
    558      1.1  dyoung 		if (len != 2)
    559      1.1  dyoung 			return EINVAL;
    560      1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != IEEE80211_MAX_LEN)
    561      1.1  dyoung 			return EINVAL;		/* TODO: RTS */
    562      1.1  dyoung 		break;
    563      1.1  dyoung 	case WI_RID_CREATE_IBSS:
    564      1.1  dyoung 		if (len != 2)
    565      1.1  dyoung 			return EINVAL;
    566      1.1  dyoung 		if (wreq.wi_val[0] != 0) {
    567      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_IBSS) == 0)
    568      1.1  dyoung 				return EINVAL;
    569      1.1  dyoung 			if ((ic->ic_flags & IEEE80211_F_IBSSON) == 0) {
    570      1.1  dyoung 				ic->ic_flags |= IEEE80211_F_IBSSON;
    571      1.1  dyoung 				if (ic->ic_opmode == IEEE80211_M_IBSS &&
    572      1.1  dyoung 				    ic->ic_state == IEEE80211_S_SCAN)
    573      1.1  dyoung 					error = ENETRESET;
    574      1.1  dyoung 			}
    575      1.1  dyoung 		} else {
    576      1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_IBSSON) {
    577      1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_IBSSON;
    578      1.1  dyoung 				if (ic->ic_flags & IEEE80211_F_SIBSS) {
    579      1.1  dyoung 					ic->ic_flags &= ~IEEE80211_F_SIBSS;
    580      1.1  dyoung 					error = ENETRESET;
    581      1.1  dyoung 				}
    582      1.1  dyoung 			}
    583      1.1  dyoung 		}
    584      1.1  dyoung 		break;
    585      1.1  dyoung 	case WI_RID_MICROWAVE_OVEN:
    586      1.1  dyoung 		if (len != 2)
    587      1.1  dyoung 			return EINVAL;
    588      1.1  dyoung 		if (wreq.wi_val[0] != 0)
    589      1.1  dyoung 			return EINVAL;		/* not supported */
    590      1.1  dyoung 		break;
    591      1.1  dyoung 	case WI_RID_ROAMING_MODE:
    592      1.1  dyoung 		if (len != 2)
    593      1.1  dyoung 			return EINVAL;
    594      1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    595      1.1  dyoung 			return EINVAL;		/* not supported */
    596      1.1  dyoung 		break;
    597      1.1  dyoung 	case WI_RID_SYSTEM_SCALE:
    598      1.1  dyoung 		if (len != 2)
    599      1.1  dyoung 			return EINVAL;
    600      1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    601      1.1  dyoung 			return EINVAL;		/* not supported */
    602      1.1  dyoung 		break;
    603      1.1  dyoung 	case WI_RID_PM_ENABLED:
    604      1.1  dyoung 		if (len != 2)
    605      1.1  dyoung 			return EINVAL;
    606      1.1  dyoung 		if (wreq.wi_val[0] != 0) {
    607      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
    608      1.1  dyoung 				return EINVAL;
    609      1.1  dyoung 			if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
    610      1.1  dyoung 				ic->ic_flags |= IEEE80211_F_PMGTON;
    611      1.1  dyoung 				error = ENETRESET;
    612      1.1  dyoung 			}
    613      1.1  dyoung 		} else {
    614      1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON) {
    615      1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_PMGTON;
    616      1.1  dyoung 				error = ENETRESET;
    617      1.1  dyoung 			}
    618      1.1  dyoung 		}
    619      1.1  dyoung 		break;
    620      1.1  dyoung 	case WI_RID_MAX_SLEEP:
    621      1.1  dyoung 		if (len != 2)
    622      1.1  dyoung 			return EINVAL;
    623      1.1  dyoung 		ic->ic_lintval = le16toh(wreq.wi_val[0]);
    624      1.1  dyoung 		if (ic->ic_flags & IEEE80211_F_PMGTON)
    625      1.1  dyoung 			error = ENETRESET;
    626      1.1  dyoung 		break;
    627      1.1  dyoung 	case WI_RID_CUR_BEACON_INT:
    628      1.1  dyoung 		return EPERM;
    629      1.1  dyoung 	case WI_RID_WEP_AVAIL:
    630      1.1  dyoung 		return EPERM;
    631      1.1  dyoung 	case WI_RID_CNFAUTHMODE:
    632      1.1  dyoung 		if (len != 2)
    633      1.1  dyoung 			return EINVAL;
    634      1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    635      1.1  dyoung 			return EINVAL;		/* TODO: shared key auth */
    636      1.1  dyoung 		break;
    637      1.1  dyoung 	case WI_RID_ENCRYPTION:
    638      1.1  dyoung 		if (len != 2)
    639      1.1  dyoung 			return EINVAL;
    640      1.1  dyoung 		if (wreq.wi_val[0] != 0) {
    641      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    642      1.1  dyoung 				return EINVAL;
    643      1.1  dyoung 			if ((ic->ic_flags & IEEE80211_F_WEPON) == 0) {
    644      1.1  dyoung 				ic->ic_flags |= IEEE80211_F_WEPON;
    645      1.1  dyoung 				error = ENETRESET;
    646      1.1  dyoung 			}
    647      1.1  dyoung 		} else {
    648      1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_WEPON) {
    649      1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_WEPON;
    650      1.1  dyoung 				error = ENETRESET;
    651      1.1  dyoung 			}
    652      1.1  dyoung 		}
    653      1.1  dyoung 		break;
    654      1.1  dyoung 	case WI_RID_TX_CRYPT_KEY:
    655      1.1  dyoung 		if (len != 2)
    656      1.1  dyoung 			return EINVAL;
    657      1.1  dyoung 		i = le16toh(wreq.wi_val[0]);
    658      1.1  dyoung 		if (i >= IEEE80211_WEP_NKID)
    659      1.1  dyoung 			return EINVAL;
    660      1.1  dyoung 		ic->ic_wep_txkey = i;
    661      1.1  dyoung 		break;
    662      1.1  dyoung 	case WI_RID_DEFLT_CRYPT_KEYS:
    663      1.1  dyoung 		if (len != sizeof(struct wi_ltv_keys))
    664      1.1  dyoung 			return EINVAL;
    665      1.1  dyoung 		keys = (struct wi_ltv_keys *)&wreq;
    666      1.1  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    667      1.1  dyoung 			len = le16toh(keys->wi_keys[i].wi_keylen);
    668      1.1  dyoung 			if (len != 0 && len < IEEE80211_WEP_KEYLEN)
    669      1.1  dyoung 				return EINVAL;
    670      1.1  dyoung 			if (len > sizeof(ic->ic_nw_keys[i].wk_key))
    671      1.1  dyoung 				return EINVAL;
    672      1.1  dyoung 		}
    673      1.1  dyoung 		memset(ic->ic_nw_keys, 0, sizeof(ic->ic_nw_keys));
    674      1.1  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    675      1.1  dyoung 			len = le16toh(keys->wi_keys[i].wi_keylen);
    676      1.1  dyoung 			ic->ic_nw_keys[i].wk_len = len;
    677      1.1  dyoung 			memcpy(ic->ic_nw_keys[i].wk_key,
    678      1.1  dyoung 			    keys->wi_keys[i].wi_keydat, len);
    679      1.1  dyoung 		}
    680      1.1  dyoung 		error = ENETRESET;
    681      1.1  dyoung 		break;
    682      1.1  dyoung 	case WI_RID_MAX_DATALEN:
    683      1.1  dyoung 		if (len != 2)
    684      1.1  dyoung 			return EINVAL;
    685      1.1  dyoung 		len = le16toh(wreq.wi_val[0]);
    686      1.1  dyoung 		if (len < 350 /* ? */ || len > IEEE80211_MAX_LEN)
    687      1.1  dyoung 			return EINVAL;
    688      1.1  dyoung 		if (len != IEEE80211_MAX_LEN)
    689      1.1  dyoung 			return EINVAL;		/* TODO: fragment */
    690      1.1  dyoung 		ic->ic_fragthreshold = len;
    691      1.1  dyoung 		error = ENETRESET;
    692      1.1  dyoung 		break;
    693      1.1  dyoung 	case WI_RID_IFACE_STATS:
    694      1.1  dyoung 		error = EPERM;
    695      1.1  dyoung 		break;
    696      1.1  dyoung 	case WI_RID_SCAN_REQ:			/* XXX wicontrol */
    697      1.1  dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
    698      1.1  dyoung 			break;
    699  1.1.1.2  dyoung 		error = ieee80211_setupscan(ic);
    700  1.1.1.2  dyoung 		if (error == 0)
    701  1.1.1.2  dyoung 			error = ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
    702      1.1  dyoung 		break;
    703      1.1  dyoung 	case WI_RID_SCAN_APS:
    704      1.1  dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
    705      1.1  dyoung 			break;
    706      1.1  dyoung 		len--;			/* XXX: tx rate? */
    707      1.1  dyoung 		/* FALLTHRU */
    708      1.1  dyoung 	case WI_RID_CHANNEL_LIST:
    709      1.1  dyoung 		memset(chanlist, 0, sizeof(chanlist));
    710      1.1  dyoung 		/*
    711      1.1  dyoung 		 * Since channel 0 is not available for DS, channel 1
    712      1.1  dyoung 		 * is assigned to LSB on WaveLAN.
    713      1.1  dyoung 		 */
    714      1.1  dyoung 		if (ic->ic_phytype == IEEE80211_T_DS)
    715      1.1  dyoung 			i = 1;
    716      1.1  dyoung 		else
    717      1.1  dyoung 			i = 0;
    718      1.1  dyoung 		for (j = 0; i <= IEEE80211_CHAN_MAX; i++, j++) {
    719      1.1  dyoung 			if ((j / 8) >= len)
    720      1.1  dyoung 				break;
    721      1.1  dyoung 			if (isclr((u_int8_t *)wreq.wi_val, j))
    722      1.1  dyoung 				continue;
    723      1.1  dyoung 			if (isclr(ic->ic_chan_active, i)) {
    724      1.1  dyoung 				if (wreq.wi_type != WI_RID_CHANNEL_LIST)
    725      1.1  dyoung 					continue;
    726      1.1  dyoung 				if (isclr(ic->ic_chan_avail, i))
    727      1.1  dyoung 					return EPERM;
    728      1.1  dyoung 			}
    729      1.1  dyoung 			setbit(chanlist, i);
    730      1.1  dyoung 		}
    731      1.1  dyoung 		memcpy(ic->ic_chan_active, chanlist,
    732      1.1  dyoung 		    sizeof(ic->ic_chan_active));
    733  1.1.1.2  dyoung 		error = ieee80211_setupscan(ic);
    734  1.1.1.2  dyoung 		if (wreq.wi_type == WI_RID_CHANNEL_LIST) {
    735  1.1.1.2  dyoung 			/* NB: ignore error from ieee80211_setupscan */
    736      1.1  dyoung 			error = ENETRESET;
    737  1.1.1.2  dyoung 		} else if (error == 0)
    738      1.1  dyoung 			error = ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
    739      1.1  dyoung 		break;
    740      1.1  dyoung 	default:
    741      1.1  dyoung 		error = EINVAL;
    742      1.1  dyoung 		break;
    743      1.1  dyoung 	}
    744      1.1  dyoung 	return error;
    745      1.1  dyoung }
    746      1.1  dyoung 
    747      1.1  dyoung int
    748      1.1  dyoung ieee80211_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data)
    749      1.1  dyoung {
    750      1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    751      1.1  dyoung 	int error = 0;
    752      1.1  dyoung 	u_int kid, len;
    753      1.1  dyoung 	struct ieee80211req *ireq;
    754  1.1.1.2  dyoung 	struct ifreq *ifr;
    755      1.1  dyoung 	u_int8_t tmpkey[IEEE80211_KEYBUF_SIZE];
    756      1.1  dyoung 	char tmpssid[IEEE80211_NWID_LEN];
    757      1.1  dyoung 	struct ieee80211_channel *chan;
    758      1.1  dyoung 
    759      1.1  dyoung 	switch (cmd) {
    760      1.1  dyoung 	case SIOCSIFMEDIA:
    761      1.1  dyoung 	case SIOCGIFMEDIA:
    762      1.1  dyoung 		error = ifmedia_ioctl(ifp, (struct ifreq *) data,
    763      1.1  dyoung 				&ic->ic_media, cmd);
    764      1.1  dyoung 		break;
    765      1.1  dyoung 	case SIOCG80211:
    766      1.1  dyoung 		ireq = (struct ieee80211req *) data;
    767      1.1  dyoung 		switch (ireq->i_type) {
    768      1.1  dyoung 		case IEEE80211_IOC_SSID:
    769      1.1  dyoung 			switch (ic->ic_state) {
    770      1.1  dyoung 			case IEEE80211_S_INIT:
    771      1.1  dyoung 			case IEEE80211_S_SCAN:
    772      1.1  dyoung 				ireq->i_len = ic->ic_des_esslen;
    773      1.1  dyoung 				memcpy(tmpssid, ic->ic_des_essid, ireq->i_len);
    774      1.1  dyoung 				break;
    775      1.1  dyoung 			default:
    776      1.1  dyoung 				ireq->i_len = ic->ic_bss->ni_esslen;
    777      1.1  dyoung 				memcpy(tmpssid, ic->ic_bss->ni_essid,
    778      1.1  dyoung 					ireq->i_len);
    779      1.1  dyoung 				break;
    780      1.1  dyoung 			}
    781      1.1  dyoung 			error = copyout(tmpssid, ireq->i_data, ireq->i_len);
    782      1.1  dyoung 			break;
    783      1.1  dyoung 		case IEEE80211_IOC_NUMSSIDS:
    784      1.1  dyoung 			ireq->i_val = 1;
    785      1.1  dyoung 			break;
    786      1.1  dyoung 		case IEEE80211_IOC_WEP:
    787      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    788      1.1  dyoung 				ireq->i_val = IEEE80211_WEP_NOSUP;
    789      1.1  dyoung 			} else {
    790      1.1  dyoung 				if (ic->ic_flags & IEEE80211_F_WEPON) {
    791      1.1  dyoung 					ireq->i_val =
    792      1.1  dyoung 					    IEEE80211_WEP_MIXED;
    793      1.1  dyoung 				} else {
    794      1.1  dyoung 					ireq->i_val =
    795      1.1  dyoung 					    IEEE80211_WEP_OFF;
    796      1.1  dyoung 				}
    797      1.1  dyoung 			}
    798      1.1  dyoung 			break;
    799      1.1  dyoung 		case IEEE80211_IOC_WEPKEY:
    800      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    801      1.1  dyoung 				error = EINVAL;
    802      1.1  dyoung 				break;
    803      1.1  dyoung 			}
    804      1.1  dyoung 			kid = (u_int) ireq->i_val;
    805      1.1  dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    806      1.1  dyoung 				error = EINVAL;
    807      1.1  dyoung 				break;
    808      1.1  dyoung 			}
    809      1.1  dyoung 			len = (u_int) ic->ic_nw_keys[kid].wk_len;
    810      1.1  dyoung 			/* NB: only root can read WEP keys */
    811  1.1.1.2  dyoung 			if (suser(curthread) == 0) {
    812      1.1  dyoung 				bcopy(ic->ic_nw_keys[kid].wk_key, tmpkey, len);
    813      1.1  dyoung 			} else {
    814      1.1  dyoung 				bzero(tmpkey, len);
    815      1.1  dyoung 			}
    816      1.1  dyoung 			ireq->i_len = len;
    817      1.1  dyoung 			error = copyout(tmpkey, ireq->i_data, len);
    818      1.1  dyoung 			break;
    819      1.1  dyoung 		case IEEE80211_IOC_NUMWEPKEYS:
    820      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    821      1.1  dyoung 				error = EINVAL;
    822      1.1  dyoung 			else
    823      1.1  dyoung 				ireq->i_val = IEEE80211_WEP_NKID;
    824      1.1  dyoung 			break;
    825      1.1  dyoung 		case IEEE80211_IOC_WEPTXKEY:
    826      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    827      1.1  dyoung 				error = EINVAL;
    828      1.1  dyoung 			else
    829      1.1  dyoung 				ireq->i_val = ic->ic_wep_txkey;
    830      1.1  dyoung 			break;
    831      1.1  dyoung 		case IEEE80211_IOC_AUTHMODE:
    832      1.1  dyoung 			ireq->i_val = IEEE80211_AUTH_OPEN;
    833      1.1  dyoung 			break;
    834      1.1  dyoung 		case IEEE80211_IOC_CHANNEL:
    835      1.1  dyoung 			switch (ic->ic_state) {
    836      1.1  dyoung 			case IEEE80211_S_INIT:
    837      1.1  dyoung 			case IEEE80211_S_SCAN:
    838      1.1  dyoung 				if (ic->ic_opmode == IEEE80211_M_STA)
    839      1.1  dyoung 					chan = ic->ic_des_chan;
    840      1.1  dyoung 				else
    841      1.1  dyoung 					chan = ic->ic_ibss_chan;
    842      1.1  dyoung 				break;
    843      1.1  dyoung 			default:
    844      1.1  dyoung 				chan = ic->ic_bss->ni_chan;
    845      1.1  dyoung 				break;
    846      1.1  dyoung 			}
    847      1.1  dyoung 			ireq->i_val = ieee80211_chan2ieee(ic, chan);
    848      1.1  dyoung 			break;
    849      1.1  dyoung 		case IEEE80211_IOC_POWERSAVE:
    850      1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON)
    851      1.1  dyoung 				ireq->i_val = IEEE80211_POWERSAVE_ON;
    852      1.1  dyoung 			else
    853      1.1  dyoung 				ireq->i_val = IEEE80211_POWERSAVE_OFF;
    854      1.1  dyoung 			break;
    855      1.1  dyoung 		case IEEE80211_IOC_POWERSAVESLEEP:
    856      1.1  dyoung 			ireq->i_val = ic->ic_lintval;
    857      1.1  dyoung 			break;
    858  1.1.1.2  dyoung 		case IEEE80211_IOC_RTSTHRESHOLD:
    859      1.1  dyoung 			ireq->i_val = ic->ic_rtsthreshold;
    860      1.1  dyoung 			break;
    861      1.1  dyoung 		default:
    862      1.1  dyoung 			error = EINVAL;
    863      1.1  dyoung 		}
    864      1.1  dyoung 		break;
    865      1.1  dyoung 	case SIOCS80211:
    866      1.1  dyoung 		error = suser(curthread);
    867      1.1  dyoung 		if (error)
    868      1.1  dyoung 			break;
    869      1.1  dyoung 		ireq = (struct ieee80211req *) data;
    870      1.1  dyoung 		switch (ireq->i_type) {
    871      1.1  dyoung 		case IEEE80211_IOC_SSID:
    872      1.1  dyoung 			if (ireq->i_val != 0 ||
    873      1.1  dyoung 			    ireq->i_len > IEEE80211_NWID_LEN) {
    874      1.1  dyoung 				error = EINVAL;
    875      1.1  dyoung 				break;
    876      1.1  dyoung 			}
    877      1.1  dyoung 			error = copyin(ireq->i_data, tmpssid, ireq->i_len);
    878      1.1  dyoung 			if (error)
    879      1.1  dyoung 				break;
    880      1.1  dyoung 			memset(ic->ic_des_essid, 0, IEEE80211_NWID_LEN);
    881      1.1  dyoung 			ic->ic_des_esslen = ireq->i_len;
    882      1.1  dyoung 			memcpy(ic->ic_des_essid, tmpssid, ireq->i_len);
    883      1.1  dyoung 			error = ENETRESET;
    884      1.1  dyoung 			break;
    885      1.1  dyoung 		case IEEE80211_IOC_WEP:
    886      1.1  dyoung 			/*
    887      1.1  dyoung 			 * These cards only support one mode so
    888      1.1  dyoung 			 * we just turn wep on if what ever is
    889      1.1  dyoung 			 * passed in is not OFF.
    890      1.1  dyoung 			 */
    891      1.1  dyoung 			if (ireq->i_val == IEEE80211_WEP_OFF) {
    892      1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_WEPON;
    893      1.1  dyoung 			} else {
    894      1.1  dyoung 				ic->ic_flags |= IEEE80211_F_WEPON;
    895      1.1  dyoung 			}
    896      1.1  dyoung 			error = ENETRESET;
    897      1.1  dyoung 			break;
    898      1.1  dyoung 		case IEEE80211_IOC_WEPKEY:
    899      1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    900      1.1  dyoung 				error = EINVAL;
    901      1.1  dyoung 				break;
    902      1.1  dyoung 			}
    903      1.1  dyoung 			kid = (u_int) ireq->i_val;
    904      1.1  dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    905      1.1  dyoung 				error = EINVAL;
    906      1.1  dyoung 				break;
    907      1.1  dyoung 			}
    908      1.1  dyoung 			if (ireq->i_len > sizeof(tmpkey)) {
    909      1.1  dyoung 				error = EINVAL;
    910      1.1  dyoung 				break;
    911      1.1  dyoung 			}
    912      1.1  dyoung 			memset(tmpkey, 0, sizeof(tmpkey));
    913      1.1  dyoung 			error = copyin(ireq->i_data, tmpkey, ireq->i_len);
    914      1.1  dyoung 			if (error)
    915      1.1  dyoung 				break;
    916      1.1  dyoung 			memcpy(ic->ic_nw_keys[kid].wk_key, tmpkey,
    917      1.1  dyoung 				sizeof(tmpkey));
    918      1.1  dyoung 			ic->ic_nw_keys[kid].wk_len = ireq->i_len;
    919      1.1  dyoung 			error = ENETRESET;
    920      1.1  dyoung 			break;
    921      1.1  dyoung 		case IEEE80211_IOC_WEPTXKEY:
    922      1.1  dyoung 			kid = (u_int) ireq->i_val;
    923      1.1  dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    924      1.1  dyoung 				error = EINVAL;
    925      1.1  dyoung 				break;
    926      1.1  dyoung 			}
    927      1.1  dyoung 			ic->ic_wep_txkey = kid;
    928      1.1  dyoung 			error = ENETRESET;
    929      1.1  dyoung 			break;
    930      1.1  dyoung #if 0
    931      1.1  dyoung 		case IEEE80211_IOC_AUTHMODE:
    932      1.1  dyoung 			sc->wi_authmode = ireq->i_val;
    933      1.1  dyoung 			break;
    934      1.1  dyoung #endif
    935      1.1  dyoung 		case IEEE80211_IOC_CHANNEL:
    936      1.1  dyoung 			/* XXX 0xffff overflows 16-bit signed */
    937      1.1  dyoung 			if (ireq->i_val == 0 ||
    938      1.1  dyoung 			    ireq->i_val == (int16_t) IEEE80211_CHAN_ANY)
    939      1.1  dyoung 				ic->ic_des_chan = IEEE80211_CHAN_ANYC;
    940      1.1  dyoung 			else if ((u_int) ireq->i_val > IEEE80211_CHAN_MAX ||
    941      1.1  dyoung 			    isclr(ic->ic_chan_active, ireq->i_val)) {
    942      1.1  dyoung 				error = EINVAL;
    943      1.1  dyoung 				break;
    944      1.1  dyoung 			} else
    945      1.1  dyoung 				ic->ic_ibss_chan = ic->ic_des_chan =
    946      1.1  dyoung 					&ic->ic_channels[ireq->i_val];
    947      1.1  dyoung 			switch (ic->ic_state) {
    948      1.1  dyoung 			case IEEE80211_S_INIT:
    949      1.1  dyoung 			case IEEE80211_S_SCAN:
    950      1.1  dyoung 				error = ENETRESET;
    951      1.1  dyoung 				break;
    952      1.1  dyoung 			default:
    953      1.1  dyoung 				if (ic->ic_opmode == IEEE80211_M_STA) {
    954      1.1  dyoung 					if (ic->ic_des_chan != IEEE80211_CHAN_ANYC &&
    955      1.1  dyoung 					    ic->ic_bss->ni_chan != ic->ic_des_chan)
    956      1.1  dyoung 						error = ENETRESET;
    957      1.1  dyoung 				} else {
    958      1.1  dyoung 					if (ic->ic_bss->ni_chan != ic->ic_ibss_chan)
    959      1.1  dyoung 						error = ENETRESET;
    960      1.1  dyoung 				}
    961      1.1  dyoung 				break;
    962      1.1  dyoung 			}
    963      1.1  dyoung 			break;
    964      1.1  dyoung 		case IEEE80211_IOC_POWERSAVE:
    965      1.1  dyoung 			switch (ireq->i_val) {
    966      1.1  dyoung 			case IEEE80211_POWERSAVE_OFF:
    967      1.1  dyoung 				if (ic->ic_flags & IEEE80211_F_PMGTON) {
    968      1.1  dyoung 					ic->ic_flags &= ~IEEE80211_F_PMGTON;
    969      1.1  dyoung 					error = ENETRESET;
    970      1.1  dyoung 				}
    971      1.1  dyoung 				break;
    972      1.1  dyoung 			case IEEE80211_POWERSAVE_ON:
    973      1.1  dyoung 				if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
    974      1.1  dyoung 					error = EINVAL;
    975      1.1  dyoung 				else if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
    976      1.1  dyoung 					ic->ic_flags |= IEEE80211_F_PMGTON;
    977      1.1  dyoung 					error = ENETRESET;
    978      1.1  dyoung 				}
    979      1.1  dyoung 				break;
    980      1.1  dyoung 			default:
    981      1.1  dyoung 				error = EINVAL;
    982      1.1  dyoung 				break;
    983      1.1  dyoung 			}
    984      1.1  dyoung 			break;
    985      1.1  dyoung 		case IEEE80211_IOC_POWERSAVESLEEP:
    986      1.1  dyoung 			if (ireq->i_val < 0) {
    987      1.1  dyoung 				error = EINVAL;
    988      1.1  dyoung 				break;
    989      1.1  dyoung 			}
    990      1.1  dyoung 			ic->ic_lintval = ireq->i_val;
    991      1.1  dyoung 			error = ENETRESET;
    992      1.1  dyoung 			break;
    993  1.1.1.2  dyoung 		case IEEE80211_IOC_RTSTHRESHOLD:
    994      1.1  dyoung 			if (!(IEEE80211_RTS_MIN < ireq->i_val &&
    995      1.1  dyoung 			      ireq->i_val < IEEE80211_RTS_MAX)) {
    996      1.1  dyoung 				error = EINVAL;
    997      1.1  dyoung 				break;
    998      1.1  dyoung 			}
    999      1.1  dyoung 			ic->ic_rtsthreshold = ireq->i_val;
   1000      1.1  dyoung 			error = ENETRESET;
   1001      1.1  dyoung 			break;
   1002      1.1  dyoung 		default:
   1003      1.1  dyoung 			error = EINVAL;
   1004      1.1  dyoung 			break;
   1005      1.1  dyoung 		}
   1006      1.1  dyoung 		break;
   1007      1.1  dyoung 	case SIOCGIFGENERIC:
   1008      1.1  dyoung 		error = ieee80211_cfgget(ifp, cmd, data);
   1009      1.1  dyoung 		break;
   1010      1.1  dyoung 	case SIOCSIFGENERIC:
   1011      1.1  dyoung 		error = suser(curthread);
   1012      1.1  dyoung 		if (error)
   1013      1.1  dyoung 			break;
   1014      1.1  dyoung 		error = ieee80211_cfgset(ifp, cmd, data);
   1015  1.1.1.2  dyoung 		break;
   1016  1.1.1.2  dyoung 	case SIOCG80211STATS:
   1017  1.1.1.2  dyoung 		ifr = (struct ifreq *)data;
   1018  1.1.1.2  dyoung 		copyout(&ic->ic_stats, ifr->ifr_data, sizeof (ic->ic_stats));
   1019      1.1  dyoung 		break;
   1020      1.1  dyoung 	default:
   1021      1.1  dyoung 		error = ether_ioctl(ifp, cmd, data);
   1022      1.1  dyoung 		break;
   1023      1.1  dyoung 	}
   1024      1.1  dyoung 	return error;
   1025      1.1  dyoung }
   1026