Home | History | Annotate | Line # | Download | only in net80211
ieee80211_ioctl.c revision 1.10
      1  1.10  dyoung /*	$NetBSD: ieee80211_ioctl.c,v 1.10 2004/04/30 23:58:11 dyoung Exp $	*/
      2   1.1  dyoung /*-
      3   1.1  dyoung  * Copyright (c) 2001 Atsushi Onoe
      4   1.1  dyoung  * Copyright (c) 2002, 2003 Sam Leffler, Errno Consulting
      5   1.1  dyoung  * All rights reserved.
      6   1.1  dyoung  *
      7   1.1  dyoung  * Redistribution and use in source and binary forms, with or without
      8   1.1  dyoung  * modification, are permitted provided that the following conditions
      9   1.1  dyoung  * are met:
     10   1.1  dyoung  * 1. Redistributions of source code must retain the above copyright
     11   1.1  dyoung  *    notice, this list of conditions and the following disclaimer.
     12   1.1  dyoung  * 2. Redistributions in binary form must reproduce the above copyright
     13   1.1  dyoung  *    notice, this list of conditions and the following disclaimer in the
     14   1.1  dyoung  *    documentation and/or other materials provided with the distribution.
     15   1.1  dyoung  * 3. The name of the author may not be used to endorse or promote products
     16   1.1  dyoung  *    derived from this software without specific prior written permission.
     17   1.1  dyoung  *
     18   1.1  dyoung  * Alternatively, this software may be distributed under the terms of the
     19   1.1  dyoung  * GNU General Public License ("GPL") version 2 as published by the Free
     20   1.1  dyoung  * Software Foundation.
     21   1.1  dyoung  *
     22   1.1  dyoung  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     23   1.1  dyoung  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     24   1.1  dyoung  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     25   1.1  dyoung  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     26   1.1  dyoung  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     27   1.1  dyoung  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     28   1.1  dyoung  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     29   1.1  dyoung  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     30   1.1  dyoung  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     31   1.1  dyoung  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     32   1.1  dyoung  */
     33   1.1  dyoung 
     34   1.1  dyoung #include <sys/cdefs.h>
     35   1.3  dyoung #ifdef __FreeBSD__
     36  1.10  dyoung __FBSDID("$FreeBSD: src/sys/net80211/ieee80211_ioctl.c,v 1.13 2004/03/30 22:57:57 sam Exp $");
     37   1.3  dyoung #else
     38  1.10  dyoung __KERNEL_RCSID(0, "$NetBSD: ieee80211_ioctl.c,v 1.10 2004/04/30 23:58:11 dyoung Exp $");
     39   1.3  dyoung #endif
     40   1.1  dyoung 
     41   1.1  dyoung /*
     42   1.1  dyoung  * IEEE 802.11 ioctl support (FreeBSD-specific)
     43   1.1  dyoung  */
     44   1.1  dyoung 
     45  1.10  dyoung #include "opt_inet.h"
     46  1.10  dyoung #include "opt_ipx.h"
     47  1.10  dyoung 
     48   1.1  dyoung #include <sys/endian.h>
     49   1.1  dyoung #include <sys/param.h>
     50   1.1  dyoung #include <sys/kernel.h>
     51   1.1  dyoung #include <sys/socket.h>
     52   1.1  dyoung #include <sys/sockio.h>
     53   1.1  dyoung #include <sys/systm.h>
     54   1.4  dyoung #include <sys/proc.h>
     55   1.1  dyoung 
     56   1.1  dyoung #include <net/if.h>
     57   1.1  dyoung #include <net/if_arp.h>
     58   1.1  dyoung #include <net/if_media.h>
     59   1.2  dyoung #ifdef __FreeBSD__
     60   1.1  dyoung #include <net/ethernet.h>
     61   1.4  dyoung #else
     62   1.4  dyoung #include <net/if_ether.h>
     63   1.2  dyoung #endif
     64   1.1  dyoung 
     65  1.10  dyoung #ifdef INET
     66  1.10  dyoung #include <netinet/in.h>
     67  1.10  dyoung #ifdef __FreeBSD__
     68  1.10  dyoung #include <netinet/if_ether.h>
     69  1.10  dyoung #endif /* __FreeBSD__ */
     70  1.10  dyoung #include <netinet/if_inarp.h>
     71  1.10  dyoung #endif
     72  1.10  dyoung 
     73  1.10  dyoung #ifdef IPX
     74  1.10  dyoung #include <netipx/ipx.h>
     75  1.10  dyoung #include <netipx/ipx_if.h>
     76  1.10  dyoung #endif
     77  1.10  dyoung 
     78   1.1  dyoung #include <net80211/ieee80211_var.h>
     79   1.1  dyoung #include <net80211/ieee80211_ioctl.h>
     80   1.1  dyoung 
     81   1.4  dyoung #ifdef __FreeBSD__
     82   1.1  dyoung #include <dev/wi/if_wavelan_ieee.h>
     83   1.4  dyoung #else
     84   1.4  dyoung #include <dev/ic/wi_ieee.h>
     85   1.4  dyoung #endif
     86   1.1  dyoung 
     87   1.1  dyoung /*
     88   1.1  dyoung  * XXX
     89   1.1  dyoung  * Wireless LAN specific configuration interface, which is compatible
     90   1.1  dyoung  * with wicontrol(8).
     91   1.1  dyoung  */
     92   1.1  dyoung 
     93   1.1  dyoung int
     94   1.1  dyoung ieee80211_cfgget(struct ifnet *ifp, u_long cmd, caddr_t data)
     95   1.1  dyoung {
     96   1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
     97   1.1  dyoung 	int i, j, error;
     98   1.1  dyoung 	struct ifreq *ifr = (struct ifreq *)data;
     99   1.1  dyoung 	struct wi_req wreq;
    100   1.1  dyoung 	struct wi_ltv_keys *keys;
    101   1.1  dyoung 	struct wi_apinfo *ap;
    102   1.1  dyoung 	struct ieee80211_node *ni;
    103   1.1  dyoung 	struct ieee80211_rateset *rs;
    104   1.4  dyoung #ifdef WICACHE
    105   1.1  dyoung 	struct wi_sigcache wsc;
    106   1.4  dyoung #endif /* WICACHE */
    107   1.4  dyoung #if 0 /* TBD */
    108   1.1  dyoung 	struct wi_scan_p2_hdr *p2;
    109   1.1  dyoung 	struct wi_scan_res *res;
    110   1.4  dyoung #endif
    111   1.1  dyoung 
    112   1.1  dyoung 	error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
    113   1.1  dyoung 	if (error)
    114   1.1  dyoung 		return error;
    115   1.1  dyoung 	wreq.wi_len = 0;
    116   1.1  dyoung 	switch (wreq.wi_type) {
    117   1.1  dyoung 	case WI_RID_SERIALNO:
    118   1.8    onoe 	case WI_RID_STA_IDENTITY:
    119   1.1  dyoung 		/* nothing appropriate */
    120   1.1  dyoung 		break;
    121   1.1  dyoung 	case WI_RID_NODENAME:
    122   1.9  itojun 		strlcpy((char *)&wreq.wi_val[1], hostname,
    123   1.9  itojun 		    sizeof(wreq.wi_val) - sizeof(wreq.wi_val[0]));
    124   1.1  dyoung 		wreq.wi_val[0] = htole16(strlen(hostname));
    125   1.1  dyoung 		wreq.wi_len = (1 + strlen(hostname) + 1) / 2;
    126   1.1  dyoung 		break;
    127   1.1  dyoung 	case WI_RID_CURRENT_SSID:
    128   1.1  dyoung 		if (ic->ic_state != IEEE80211_S_RUN) {
    129   1.1  dyoung 			wreq.wi_val[0] = 0;
    130   1.1  dyoung 			wreq.wi_len = 1;
    131   1.1  dyoung 			break;
    132   1.1  dyoung 		}
    133   1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_bss->ni_esslen);
    134   1.1  dyoung 		memcpy(&wreq.wi_val[1], ic->ic_bss->ni_essid,
    135   1.1  dyoung 		    ic->ic_bss->ni_esslen);
    136   1.1  dyoung 		wreq.wi_len = (1 + ic->ic_bss->ni_esslen + 1) / 2;
    137   1.1  dyoung 		break;
    138   1.1  dyoung 	case WI_RID_OWN_SSID:
    139   1.1  dyoung 	case WI_RID_DESIRED_SSID:
    140   1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_des_esslen);
    141   1.1  dyoung 		memcpy(&wreq.wi_val[1], ic->ic_des_essid, ic->ic_des_esslen);
    142   1.1  dyoung 		wreq.wi_len = (1 + ic->ic_des_esslen + 1) / 2;
    143   1.1  dyoung 		break;
    144   1.1  dyoung 	case WI_RID_CURRENT_BSSID:
    145   1.1  dyoung 		if (ic->ic_state == IEEE80211_S_RUN)
    146   1.1  dyoung 			IEEE80211_ADDR_COPY(wreq.wi_val, ic->ic_bss->ni_bssid);
    147   1.1  dyoung 		else
    148   1.1  dyoung 			memset(wreq.wi_val, 0, IEEE80211_ADDR_LEN);
    149   1.1  dyoung 		wreq.wi_len = IEEE80211_ADDR_LEN / 2;
    150   1.1  dyoung 		break;
    151   1.1  dyoung 	case WI_RID_CHANNEL_LIST:
    152   1.1  dyoung 		memset(wreq.wi_val, 0, sizeof(wreq.wi_val));
    153   1.1  dyoung 		/*
    154   1.1  dyoung 		 * Since channel 0 is not available for DS, channel 1
    155   1.1  dyoung 		 * is assigned to LSB on WaveLAN.
    156   1.1  dyoung 		 */
    157   1.1  dyoung 		if (ic->ic_phytype == IEEE80211_T_DS)
    158   1.1  dyoung 			i = 1;
    159   1.1  dyoung 		else
    160   1.1  dyoung 			i = 0;
    161   1.1  dyoung 		for (j = 0; i <= IEEE80211_CHAN_MAX; i++, j++)
    162   1.1  dyoung 			if (isset(ic->ic_chan_active, i)) {
    163   1.1  dyoung 				setbit((u_int8_t *)wreq.wi_val, j);
    164   1.1  dyoung 				wreq.wi_len = j / 16 + 1;
    165   1.1  dyoung 			}
    166   1.1  dyoung 		break;
    167   1.1  dyoung 	case WI_RID_OWN_CHNL:
    168   1.1  dyoung 		wreq.wi_val[0] = htole16(
    169   1.1  dyoung 			ieee80211_chan2ieee(ic, ic->ic_ibss_chan));
    170   1.1  dyoung 		wreq.wi_len = 1;
    171   1.1  dyoung 		break;
    172   1.1  dyoung 	case WI_RID_CURRENT_CHAN:
    173   1.1  dyoung 		wreq.wi_val[0] = htole16(
    174   1.1  dyoung 			ieee80211_chan2ieee(ic, ic->ic_bss->ni_chan));
    175   1.1  dyoung 		wreq.wi_len = 1;
    176   1.1  dyoung 		break;
    177   1.1  dyoung 	case WI_RID_COMMS_QUALITY:
    178   1.1  dyoung 		wreq.wi_val[0] = 0;				/* quality */
    179   1.7  dyoung 		wreq.wi_val[1] =
    180   1.7  dyoung 			htole16((*ic->ic_node_getrssi)(ic, ic->ic_bss));
    181   1.1  dyoung 		wreq.wi_val[2] = 0;				/* noise */
    182   1.1  dyoung 		wreq.wi_len = 3;
    183   1.1  dyoung 		break;
    184   1.1  dyoung 	case WI_RID_PROMISC:
    185   1.1  dyoung 		wreq.wi_val[0] = htole16((ifp->if_flags & IFF_PROMISC) ? 1 : 0);
    186   1.1  dyoung 		wreq.wi_len = 1;
    187   1.1  dyoung 		break;
    188   1.1  dyoung 	case WI_RID_PORTTYPE:
    189   1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_opmode);
    190   1.1  dyoung 		wreq.wi_len = 1;
    191   1.1  dyoung 		break;
    192   1.1  dyoung 	case WI_RID_MAC_NODE:
    193   1.1  dyoung 		IEEE80211_ADDR_COPY(wreq.wi_val, ic->ic_myaddr);
    194   1.1  dyoung 		wreq.wi_len = IEEE80211_ADDR_LEN / 2;
    195   1.1  dyoung 		break;
    196   1.1  dyoung 	case WI_RID_TX_RATE:
    197   1.1  dyoung 		if (ic->ic_fixed_rate == -1)
    198   1.1  dyoung 			wreq.wi_val[0] = 0;	/* auto */
    199   1.1  dyoung 		else
    200   1.1  dyoung 			wreq.wi_val[0] = htole16(
    201   1.1  dyoung 			    (ic->ic_sup_rates[ic->ic_curmode].rs_rates[ic->ic_fixed_rate] &
    202   1.1  dyoung 			    IEEE80211_RATE_VAL) / 2);
    203   1.1  dyoung 		wreq.wi_len = 1;
    204   1.1  dyoung 		break;
    205   1.1  dyoung 	case WI_RID_CUR_TX_RATE:
    206   1.1  dyoung 		wreq.wi_val[0] = htole16(
    207   1.1  dyoung 		    (ic->ic_bss->ni_rates.rs_rates[ic->ic_bss->ni_txrate] &
    208   1.1  dyoung 		    IEEE80211_RATE_VAL) / 2);
    209   1.1  dyoung 		wreq.wi_len = 1;
    210   1.1  dyoung 		break;
    211   1.6  dyoung 	case WI_RID_FRAG_THRESH:
    212   1.6  dyoung 		wreq.wi_val[0] = htole16(ic->ic_fragthreshold);
    213   1.6  dyoung 		wreq.wi_len = 1;
    214   1.6  dyoung 		break;
    215   1.1  dyoung 	case WI_RID_RTS_THRESH:
    216   1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_rtsthreshold);
    217   1.1  dyoung 		wreq.wi_len = 1;
    218   1.1  dyoung 		break;
    219   1.1  dyoung 	case WI_RID_CREATE_IBSS:
    220   1.1  dyoung 		wreq.wi_val[0] =
    221   1.1  dyoung 		    htole16((ic->ic_flags & IEEE80211_F_IBSSON) ? 1 : 0);
    222   1.1  dyoung 		wreq.wi_len = 1;
    223   1.1  dyoung 		break;
    224   1.1  dyoung 	case WI_RID_MICROWAVE_OVEN:
    225   1.1  dyoung 		wreq.wi_val[0] = 0;	/* no ... not supported */
    226   1.1  dyoung 		wreq.wi_len = 1;
    227   1.1  dyoung 		break;
    228   1.1  dyoung 	case WI_RID_ROAMING_MODE:
    229   1.1  dyoung 		wreq.wi_val[0] = htole16(1);	/* enabled ... not supported */
    230   1.1  dyoung 		wreq.wi_len = 1;
    231   1.1  dyoung 		break;
    232   1.1  dyoung 	case WI_RID_SYSTEM_SCALE:
    233   1.1  dyoung 		wreq.wi_val[0] = htole16(1);	/* low density ... not supp */
    234   1.1  dyoung 		wreq.wi_len = 1;
    235   1.1  dyoung 		break;
    236   1.1  dyoung 	case WI_RID_PM_ENABLED:
    237   1.1  dyoung 		wreq.wi_val[0] =
    238   1.1  dyoung 		    htole16((ic->ic_flags & IEEE80211_F_PMGTON) ? 1 : 0);
    239   1.1  dyoung 		wreq.wi_len = 1;
    240   1.1  dyoung 		break;
    241   1.1  dyoung 	case WI_RID_MAX_SLEEP:
    242   1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_lintval);
    243   1.1  dyoung 		wreq.wi_len = 1;
    244   1.1  dyoung 		break;
    245   1.1  dyoung 	case WI_RID_CUR_BEACON_INT:
    246   1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_bss->ni_intval);
    247   1.1  dyoung 		wreq.wi_len = 1;
    248   1.1  dyoung 		break;
    249   1.1  dyoung 	case WI_RID_WEP_AVAIL:
    250   1.1  dyoung 		wreq.wi_val[0] =
    251   1.1  dyoung 		    htole16((ic->ic_caps & IEEE80211_C_WEP) ? 1 : 0);
    252   1.1  dyoung 		wreq.wi_len = 1;
    253   1.1  dyoung 		break;
    254   1.1  dyoung 	case WI_RID_CNFAUTHMODE:
    255   1.1  dyoung 		wreq.wi_val[0] = htole16(1);	/* TODO: open system only */
    256   1.1  dyoung 		wreq.wi_len = 1;
    257   1.1  dyoung 		break;
    258   1.1  dyoung 	case WI_RID_ENCRYPTION:
    259   1.1  dyoung 		wreq.wi_val[0] =
    260   1.1  dyoung 		    htole16((ic->ic_flags & IEEE80211_F_WEPON) ? 1 : 0);
    261   1.1  dyoung 		wreq.wi_len = 1;
    262   1.1  dyoung 		break;
    263   1.1  dyoung 	case WI_RID_TX_CRYPT_KEY:
    264   1.1  dyoung 		wreq.wi_val[0] = htole16(ic->ic_wep_txkey);
    265   1.1  dyoung 		wreq.wi_len = 1;
    266   1.1  dyoung 		break;
    267   1.1  dyoung 	case WI_RID_DEFLT_CRYPT_KEYS:
    268   1.1  dyoung 		keys = (struct wi_ltv_keys *)&wreq;
    269   1.1  dyoung 		/* do not show keys to non-root user */
    270   1.4  dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
    271   1.1  dyoung 		if (error) {
    272   1.1  dyoung 			memset(keys, 0, sizeof(*keys));
    273   1.1  dyoung 			error = 0;
    274   1.1  dyoung 			break;
    275   1.1  dyoung 		}
    276   1.1  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    277   1.1  dyoung 			keys->wi_keys[i].wi_keylen =
    278   1.1  dyoung 			    htole16(ic->ic_nw_keys[i].wk_len);
    279   1.1  dyoung 			memcpy(keys->wi_keys[i].wi_keydat,
    280   1.1  dyoung 			    ic->ic_nw_keys[i].wk_key, ic->ic_nw_keys[i].wk_len);
    281   1.1  dyoung 		}
    282   1.1  dyoung 		wreq.wi_len = sizeof(*keys) / 2;
    283   1.1  dyoung 		break;
    284   1.1  dyoung 	case WI_RID_MAX_DATALEN:
    285   1.1  dyoung 		wreq.wi_val[0] = htole16(IEEE80211_MAX_LEN);	/* TODO: frag */
    286   1.1  dyoung 		wreq.wi_len = 1;
    287   1.1  dyoung 		break;
    288   1.8    onoe 	case WI_RID_DBM_ADJUST:
    289   1.8    onoe 		/* not supported, we just pass rssi value from driver. */
    290   1.8    onoe 		break;
    291   1.1  dyoung 	case WI_RID_IFACE_STATS:
    292   1.1  dyoung 		/* XXX: should be implemented in lower drivers */
    293   1.1  dyoung 		break;
    294   1.1  dyoung 	case WI_RID_READ_APS:
    295   1.1  dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP) {
    296   1.1  dyoung 			/*
    297   1.1  dyoung 			 * Don't return results until active scan completes.
    298   1.1  dyoung 			 */
    299   1.1  dyoung 			if (ic->ic_state == IEEE80211_S_SCAN &&
    300   1.1  dyoung 			    (ic->ic_flags & IEEE80211_F_ASCAN)) {
    301   1.1  dyoung 				error = EINPROGRESS;
    302   1.1  dyoung 				break;
    303   1.1  dyoung 			}
    304   1.1  dyoung 		}
    305   1.1  dyoung 		i = 0;
    306   1.1  dyoung 		ap = (void *)((char *)wreq.wi_val + sizeof(i));
    307   1.1  dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    308   1.1  dyoung 			if ((caddr_t)(ap + 1) > (caddr_t)(&wreq + 1))
    309   1.1  dyoung 				break;
    310   1.1  dyoung 			memset(ap, 0, sizeof(*ap));
    311   1.1  dyoung 			if (ic->ic_opmode == IEEE80211_M_HOSTAP) {
    312   1.1  dyoung 				IEEE80211_ADDR_COPY(ap->bssid, ni->ni_macaddr);
    313   1.1  dyoung 				ap->namelen = ic->ic_des_esslen;
    314   1.1  dyoung 				if (ic->ic_des_esslen)
    315   1.1  dyoung 					memcpy(ap->name, ic->ic_des_essid,
    316   1.1  dyoung 					    ic->ic_des_esslen);
    317   1.1  dyoung 			} else {
    318   1.1  dyoung 				IEEE80211_ADDR_COPY(ap->bssid, ni->ni_bssid);
    319   1.1  dyoung 				ap->namelen = ni->ni_esslen;
    320   1.1  dyoung 				if (ni->ni_esslen)
    321   1.1  dyoung 					memcpy(ap->name, ni->ni_essid,
    322   1.1  dyoung 					    ni->ni_esslen);
    323   1.1  dyoung 			}
    324   1.1  dyoung 			ap->channel = ieee80211_chan2ieee(ic, ni->ni_chan);
    325   1.7  dyoung 			ap->signal = (*ic->ic_node_getrssi)(ic, ni);
    326   1.1  dyoung 			ap->capinfo = ni->ni_capinfo;
    327   1.1  dyoung 			ap->interval = ni->ni_intval;
    328   1.1  dyoung 			rs = &ni->ni_rates;
    329   1.1  dyoung 			for (j = 0; j < rs->rs_nrates; j++) {
    330   1.1  dyoung 				if (rs->rs_rates[j] & IEEE80211_RATE_BASIC) {
    331   1.1  dyoung 					ap->rate = (rs->rs_rates[j] &
    332   1.1  dyoung 					    IEEE80211_RATE_VAL) * 5; /* XXX */
    333   1.1  dyoung 				}
    334   1.1  dyoung 			}
    335   1.1  dyoung 			i++;
    336   1.1  dyoung 			ap++;
    337   1.1  dyoung 		}
    338   1.1  dyoung 		memcpy(wreq.wi_val, &i, sizeof(i));
    339   1.1  dyoung 		wreq.wi_len = (sizeof(int) + sizeof(*ap) * i) / 2;
    340   1.1  dyoung 		break;
    341   1.4  dyoung #if 0
    342   1.1  dyoung 	case WI_RID_PRISM2:
    343   1.1  dyoung 		wreq.wi_val[0] = 1;	/* XXX lie so SCAN_RES can give rates */
    344   1.1  dyoung 		wreq.wi_len = sizeof(u_int16_t) / 2;
    345   1.1  dyoung 		break;
    346   1.1  dyoung 	case WI_RID_SCAN_RES:			/* compatibility interface */
    347   1.1  dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP &&
    348  1.10  dyoung 		    ic->ic_state == IEEE80211_S_SCAN &&
    349  1.10  dyoung 		    (ic->ic_flags & IEEE80211_F_ASCAN)) {
    350   1.1  dyoung 			error = EINPROGRESS;
    351   1.1  dyoung 			break;
    352   1.1  dyoung 		}
    353   1.1  dyoung 		/* NB: we use the Prism2 format so we can return rate info */
    354   1.1  dyoung 		p2 = (struct wi_scan_p2_hdr *)wreq.wi_val;
    355   1.1  dyoung 		res = (void *)&p2[1];
    356   1.1  dyoung 		i = 0;
    357   1.1  dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    358   1.1  dyoung 			if ((caddr_t)(res + 1) > (caddr_t)(&wreq + 1))
    359   1.1  dyoung 				break;
    360   1.1  dyoung 			res->wi_chan = ieee80211_chan2ieee(ic, ni->ni_chan);
    361   1.1  dyoung 			res->wi_noise = 0;
    362   1.7  dyoung 			res->wi_signal = (*ic->ic_node_getrssi)(ic, ni);
    363   1.1  dyoung 			IEEE80211_ADDR_COPY(res->wi_bssid, ni->ni_bssid);
    364   1.1  dyoung 			res->wi_interval = ni->ni_intval;
    365   1.1  dyoung 			res->wi_capinfo = ni->ni_capinfo;
    366   1.1  dyoung 			res->wi_ssid_len = ni->ni_esslen;
    367   1.1  dyoung 			memcpy(res->wi_ssid, ni->ni_essid, IEEE80211_NWID_LEN);
    368   1.1  dyoung 			/* NB: assumes wi_srates holds <= ni->ni_rates */
    369   1.1  dyoung 			memcpy(res->wi_srates, ni->ni_rates.rs_rates,
    370   1.1  dyoung 				sizeof(res->wi_srates));
    371   1.1  dyoung 			if (ni->ni_rates.rs_nrates < 10)
    372   1.1  dyoung 				res->wi_srates[ni->ni_rates.rs_nrates] = 0;
    373   1.1  dyoung 			res->wi_rate = ni->ni_rates.rs_rates[ni->ni_txrate];
    374   1.1  dyoung 			res->wi_rsvd = 0;
    375   1.1  dyoung 			res++, i++;
    376   1.1  dyoung 		}
    377   1.1  dyoung 		p2->wi_rsvd = 0;
    378   1.1  dyoung 		p2->wi_reason = i;
    379   1.1  dyoung 		wreq.wi_len = (sizeof(*p2) + sizeof(*res) * i) / 2;
    380   1.1  dyoung 		break;
    381   1.4  dyoung #endif /* 0 */
    382   1.4  dyoung #ifdef WICACHE
    383   1.1  dyoung 	case WI_RID_READ_CACHE:
    384   1.1  dyoung 		i = 0;
    385   1.1  dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    386   1.1  dyoung 			if (i == (WI_MAX_DATALEN/sizeof(struct wi_sigcache))-1)
    387   1.1  dyoung 				break;
    388   1.1  dyoung 			IEEE80211_ADDR_COPY(wsc.macsrc, ni->ni_macaddr);
    389   1.1  dyoung 			memset(&wsc.ipsrc, 0, sizeof(wsc.ipsrc));
    390   1.7  dyoung 			wsc.signal = (*ic->ic_node_getrssi)(ic, ni);
    391   1.1  dyoung 			wsc.noise = 0;
    392   1.1  dyoung 			wsc.quality = 0;
    393   1.1  dyoung 			memcpy((caddr_t)wreq.wi_val + sizeof(wsc) * i,
    394   1.1  dyoung 			    &wsc, sizeof(wsc));
    395   1.1  dyoung 			i++;
    396   1.1  dyoung 		}
    397   1.1  dyoung 		wreq.wi_len = sizeof(wsc) * i / 2;
    398   1.1  dyoung 		break;
    399   1.4  dyoung #endif /* WICACHE */
    400   1.1  dyoung 	case WI_RID_SCAN_APS:
    401   1.1  dyoung 		error = EINVAL;
    402   1.1  dyoung 		break;
    403   1.1  dyoung 	default:
    404   1.1  dyoung 		error = EINVAL;
    405   1.1  dyoung 		break;
    406   1.1  dyoung 	}
    407   1.1  dyoung 	if (error == 0) {
    408   1.1  dyoung 		wreq.wi_len++;
    409   1.1  dyoung 		error = copyout(&wreq, ifr->ifr_data, sizeof(wreq));
    410   1.1  dyoung 	}
    411   1.1  dyoung 	return error;
    412   1.1  dyoung }
    413   1.1  dyoung 
    414   1.1  dyoung static int
    415   1.1  dyoung findrate(struct ieee80211com *ic, enum ieee80211_phymode mode, int rate)
    416   1.1  dyoung {
    417   1.1  dyoung #define	IEEERATE(_ic,_m,_i) \
    418   1.1  dyoung 	((_ic)->ic_sup_rates[_m].rs_rates[_i] & IEEE80211_RATE_VAL)
    419   1.1  dyoung 	int i, nrates = ic->ic_sup_rates[mode].rs_nrates;
    420   1.1  dyoung 	for (i = 0; i < nrates; i++)
    421   1.1  dyoung 		if (IEEERATE(ic, mode, i) == rate)
    422   1.1  dyoung 			return i;
    423   1.1  dyoung 	return -1;
    424   1.1  dyoung #undef IEEERATE
    425   1.1  dyoung }
    426   1.1  dyoung 
    427   1.7  dyoung /*
    428   1.7  dyoung  * Prepare to do a user-initiated scan for AP's.  If no
    429   1.7  dyoung  * current/default channel is setup or the current channel
    430   1.7  dyoung  * is invalid then pick the first available channel from
    431   1.7  dyoung  * the active list as the place to start the scan.
    432   1.7  dyoung  */
    433   1.7  dyoung static int
    434   1.7  dyoung ieee80211_setupscan(struct ieee80211com *ic)
    435   1.7  dyoung {
    436   1.7  dyoung 	u_char *chanlist = ic->ic_chan_active;
    437   1.7  dyoung 	int i;
    438   1.7  dyoung 
    439   1.7  dyoung 	if (ic->ic_ibss_chan == NULL ||
    440   1.7  dyoung 	    isclr(chanlist, ieee80211_chan2ieee(ic, ic->ic_ibss_chan))) {
    441   1.7  dyoung 		for (i = 0; i <= IEEE80211_CHAN_MAX; i++)
    442   1.7  dyoung 			if (isset(chanlist, i)) {
    443   1.7  dyoung 				ic->ic_ibss_chan = &ic->ic_channels[i];
    444   1.7  dyoung 				goto found;
    445   1.7  dyoung 			}
    446   1.7  dyoung 		return EINVAL;			/* no active channels */
    447   1.7  dyoung found:
    448   1.7  dyoung 		;
    449   1.7  dyoung 	}
    450   1.7  dyoung 	if (ic->ic_bss->ni_chan == IEEE80211_CHAN_ANYC ||
    451   1.7  dyoung 	    isclr(chanlist, ieee80211_chan2ieee(ic, ic->ic_bss->ni_chan)))
    452   1.7  dyoung 		ic->ic_bss->ni_chan = ic->ic_ibss_chan;
    453   1.7  dyoung 	/*
    454   1.7  dyoung 	 * XXX don't permit a scan to be started unless we
    455   1.7  dyoung 	 * know the device is ready.  For the moment this means
    456   1.7  dyoung 	 * the device is marked up as this is the required to
    457   1.7  dyoung 	 * initialize the hardware.  It would be better to permit
    458   1.7  dyoung 	 * scanning prior to being up but that'll require some
    459   1.7  dyoung 	 * changes to the infrastructure.
    460   1.7  dyoung 	 */
    461   1.7  dyoung 	return (ic->ic_if.if_flags & IFF_UP) ? 0 : ENETRESET;
    462   1.7  dyoung }
    463   1.7  dyoung 
    464   1.1  dyoung int
    465   1.1  dyoung ieee80211_cfgset(struct ifnet *ifp, u_long cmd, caddr_t data)
    466   1.1  dyoung {
    467   1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    468   1.1  dyoung 	int i, j, len, error, rate;
    469   1.1  dyoung 	struct ifreq *ifr = (struct ifreq *)data;
    470   1.1  dyoung 	struct wi_ltv_keys *keys;
    471   1.1  dyoung 	struct wi_req wreq;
    472   1.1  dyoung 	u_char chanlist[roundup(IEEE80211_CHAN_MAX, NBBY)];
    473   1.1  dyoung 
    474   1.1  dyoung 	error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
    475   1.1  dyoung 	if (error)
    476   1.1  dyoung 		return error;
    477   1.1  dyoung 	len = wreq.wi_len ? (wreq.wi_len - 1) * 2 : 0;
    478   1.1  dyoung 	switch (wreq.wi_type) {
    479   1.1  dyoung 	case WI_RID_SERIALNO:
    480   1.1  dyoung 	case WI_RID_NODENAME:
    481   1.1  dyoung 		return EPERM;
    482   1.1  dyoung 	case WI_RID_CURRENT_SSID:
    483   1.1  dyoung 		return EPERM;
    484   1.1  dyoung 	case WI_RID_OWN_SSID:
    485   1.1  dyoung 	case WI_RID_DESIRED_SSID:
    486   1.1  dyoung 		if (le16toh(wreq.wi_val[0]) * 2 > len ||
    487   1.1  dyoung 		    le16toh(wreq.wi_val[0]) > IEEE80211_NWID_LEN) {
    488   1.1  dyoung 			error = ENOSPC;
    489   1.1  dyoung 			break;
    490   1.1  dyoung 		}
    491   1.1  dyoung 		memset(ic->ic_des_essid, 0, sizeof(ic->ic_des_essid));
    492   1.1  dyoung 		ic->ic_des_esslen = le16toh(wreq.wi_val[0]) * 2;
    493   1.1  dyoung 		memcpy(ic->ic_des_essid, &wreq.wi_val[1], ic->ic_des_esslen);
    494   1.1  dyoung 		error = ENETRESET;
    495   1.1  dyoung 		break;
    496   1.1  dyoung 	case WI_RID_CURRENT_BSSID:
    497   1.1  dyoung 		return EPERM;
    498   1.1  dyoung 	case WI_RID_OWN_CHNL:
    499   1.1  dyoung 		if (len != 2)
    500   1.1  dyoung 			return EINVAL;
    501   1.1  dyoung 		i = le16toh(wreq.wi_val[0]);
    502   1.1  dyoung 		if (i < 0 ||
    503   1.1  dyoung 		    i > IEEE80211_CHAN_MAX ||
    504   1.1  dyoung 		    isclr(ic->ic_chan_active, i))
    505   1.1  dyoung 			return EINVAL;
    506   1.1  dyoung 		ic->ic_ibss_chan = &ic->ic_channels[i];
    507   1.1  dyoung 		if (ic->ic_flags & IEEE80211_F_SIBSS)
    508   1.1  dyoung 			error = ENETRESET;
    509   1.1  dyoung 		break;
    510   1.1  dyoung 	case WI_RID_CURRENT_CHAN:
    511   1.1  dyoung 		return EPERM;
    512   1.1  dyoung 	case WI_RID_COMMS_QUALITY:
    513   1.1  dyoung 		return EPERM;
    514   1.1  dyoung 	case WI_RID_PROMISC:
    515   1.1  dyoung 		if (len != 2)
    516   1.1  dyoung 			return EINVAL;
    517   1.1  dyoung 		if (ifp->if_flags & IFF_PROMISC) {
    518   1.1  dyoung 			if (wreq.wi_val[0] == 0) {
    519   1.1  dyoung 				ifp->if_flags &= ~IFF_PROMISC;
    520   1.1  dyoung 				error = ENETRESET;
    521   1.1  dyoung 			}
    522   1.1  dyoung 		} else {
    523   1.1  dyoung 			if (wreq.wi_val[0] != 0) {
    524   1.1  dyoung 				ifp->if_flags |= IFF_PROMISC;
    525   1.1  dyoung 				error = ENETRESET;
    526   1.1  dyoung 			}
    527   1.1  dyoung 		}
    528   1.1  dyoung 		break;
    529   1.1  dyoung 	case WI_RID_PORTTYPE:
    530   1.1  dyoung 		if (len != 2)
    531   1.1  dyoung 			return EINVAL;
    532   1.1  dyoung 		switch (le16toh(wreq.wi_val[0])) {
    533   1.1  dyoung 		case IEEE80211_M_STA:
    534   1.1  dyoung 			break;
    535   1.1  dyoung 		case IEEE80211_M_IBSS:
    536   1.1  dyoung 			if (!(ic->ic_caps & IEEE80211_C_IBSS))
    537   1.1  dyoung 				return EINVAL;
    538   1.1  dyoung 			break;
    539   1.1  dyoung 		case IEEE80211_M_AHDEMO:
    540   1.1  dyoung 			if (ic->ic_phytype != IEEE80211_T_DS ||
    541   1.1  dyoung 			    !(ic->ic_caps & IEEE80211_C_AHDEMO))
    542   1.1  dyoung 				return EINVAL;
    543   1.1  dyoung 			break;
    544   1.1  dyoung 		case IEEE80211_M_HOSTAP:
    545   1.1  dyoung 			if (!(ic->ic_caps & IEEE80211_C_HOSTAP))
    546   1.1  dyoung 				return EINVAL;
    547   1.1  dyoung 			break;
    548   1.1  dyoung 		default:
    549   1.1  dyoung 			return EINVAL;
    550   1.1  dyoung 		}
    551   1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != ic->ic_opmode) {
    552   1.1  dyoung 			ic->ic_opmode = le16toh(wreq.wi_val[0]);
    553   1.1  dyoung 			error = ENETRESET;
    554   1.1  dyoung 		}
    555   1.1  dyoung 		break;
    556   1.1  dyoung #if 0
    557   1.1  dyoung 	case WI_RID_MAC_NODE:
    558   1.1  dyoung 		if (len != IEEE80211_ADDR_LEN)
    559   1.1  dyoung 			return EINVAL;
    560   1.1  dyoung 		IEEE80211_ADDR_COPY(LLADDR(ifp->if_sadl), wreq.wi_val);
    561   1.1  dyoung 		/* if_init will copy lladdr into ic_myaddr */
    562   1.1  dyoung 		error = ENETRESET;
    563   1.1  dyoung 		break;
    564   1.1  dyoung #endif
    565   1.1  dyoung 	case WI_RID_TX_RATE:
    566   1.1  dyoung 		if (len != 2)
    567   1.1  dyoung 			return EINVAL;
    568   1.1  dyoung 		if (wreq.wi_val[0] == 0) {
    569   1.1  dyoung 			/* auto */
    570   1.1  dyoung 			ic->ic_fixed_rate = -1;
    571   1.1  dyoung 			break;
    572   1.1  dyoung 		}
    573   1.1  dyoung 		rate = 2 * le16toh(wreq.wi_val[0]);
    574   1.1  dyoung 		if (ic->ic_curmode == IEEE80211_MODE_AUTO) {
    575   1.1  dyoung 			/*
    576   1.1  dyoung 			 * In autoselect mode search for the rate.  We take
    577   1.1  dyoung 			 * the first instance which may not be right, but we
    578   1.1  dyoung 			 * are limited by the interface.  Note that we also
    579   1.1  dyoung 			 * lock the mode to insure the rate is meaningful
    580   1.1  dyoung 			 * when it is used.
    581   1.1  dyoung 			 */
    582   1.1  dyoung 			for (j = IEEE80211_MODE_11A;
    583   1.1  dyoung 			     j < IEEE80211_MODE_MAX; j++) {
    584   1.1  dyoung 				if ((ic->ic_modecaps & (1<<j)) == 0)
    585   1.1  dyoung 					continue;
    586   1.1  dyoung 				i = findrate(ic, j, rate);
    587   1.1  dyoung 				if (i != -1) {
    588   1.1  dyoung 					/* lock mode too */
    589   1.1  dyoung 					ic->ic_curmode = j;
    590   1.1  dyoung 					goto setrate;
    591   1.1  dyoung 				}
    592   1.1  dyoung 			}
    593   1.1  dyoung 		} else {
    594   1.1  dyoung 			i = findrate(ic, ic->ic_curmode, rate);
    595   1.1  dyoung 			if (i != -1)
    596   1.1  dyoung 				goto setrate;
    597   1.1  dyoung 		}
    598   1.1  dyoung 		return EINVAL;
    599   1.1  dyoung 	setrate:
    600   1.1  dyoung 		ic->ic_fixed_rate = i;
    601   1.1  dyoung 		error = ENETRESET;
    602   1.1  dyoung 		break;
    603   1.1  dyoung 	case WI_RID_CUR_TX_RATE:
    604   1.1  dyoung 		return EPERM;
    605   1.6  dyoung 	case WI_RID_FRAG_THRESH:
    606   1.6  dyoung 		if (len != 2)
    607   1.6  dyoung 			return EINVAL;
    608   1.6  dyoung 		ic->ic_fragthreshold = le16toh(wreq.wi_val[0]);
    609   1.6  dyoung 		error = ENETRESET;
    610   1.6  dyoung 		break;
    611   1.1  dyoung 	case WI_RID_RTS_THRESH:
    612   1.1  dyoung 		if (len != 2)
    613   1.1  dyoung 			return EINVAL;
    614   1.6  dyoung 		ic->ic_rtsthreshold = le16toh(wreq.wi_val[0]);
    615   1.6  dyoung 		error = ENETRESET;
    616   1.1  dyoung 		break;
    617   1.1  dyoung 	case WI_RID_CREATE_IBSS:
    618   1.1  dyoung 		if (len != 2)
    619   1.1  dyoung 			return EINVAL;
    620   1.1  dyoung 		if (wreq.wi_val[0] != 0) {
    621   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_IBSS) == 0)
    622   1.1  dyoung 				return EINVAL;
    623   1.1  dyoung 			if ((ic->ic_flags & IEEE80211_F_IBSSON) == 0) {
    624   1.1  dyoung 				ic->ic_flags |= IEEE80211_F_IBSSON;
    625   1.1  dyoung 				if (ic->ic_opmode == IEEE80211_M_IBSS &&
    626   1.1  dyoung 				    ic->ic_state == IEEE80211_S_SCAN)
    627   1.1  dyoung 					error = ENETRESET;
    628   1.1  dyoung 			}
    629   1.1  dyoung 		} else {
    630   1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_IBSSON) {
    631   1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_IBSSON;
    632   1.1  dyoung 				if (ic->ic_flags & IEEE80211_F_SIBSS) {
    633   1.1  dyoung 					ic->ic_flags &= ~IEEE80211_F_SIBSS;
    634   1.1  dyoung 					error = ENETRESET;
    635   1.1  dyoung 				}
    636   1.1  dyoung 			}
    637   1.1  dyoung 		}
    638   1.1  dyoung 		break;
    639   1.1  dyoung 	case WI_RID_MICROWAVE_OVEN:
    640   1.1  dyoung 		if (len != 2)
    641   1.1  dyoung 			return EINVAL;
    642   1.1  dyoung 		if (wreq.wi_val[0] != 0)
    643   1.1  dyoung 			return EINVAL;		/* not supported */
    644   1.1  dyoung 		break;
    645   1.1  dyoung 	case WI_RID_ROAMING_MODE:
    646   1.1  dyoung 		if (len != 2)
    647   1.1  dyoung 			return EINVAL;
    648   1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    649   1.1  dyoung 			return EINVAL;		/* not supported */
    650   1.1  dyoung 		break;
    651   1.1  dyoung 	case WI_RID_SYSTEM_SCALE:
    652   1.1  dyoung 		if (len != 2)
    653   1.1  dyoung 			return EINVAL;
    654   1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    655   1.1  dyoung 			return EINVAL;		/* not supported */
    656   1.1  dyoung 		break;
    657   1.1  dyoung 	case WI_RID_PM_ENABLED:
    658   1.1  dyoung 		if (len != 2)
    659   1.1  dyoung 			return EINVAL;
    660   1.1  dyoung 		if (wreq.wi_val[0] != 0) {
    661   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
    662   1.1  dyoung 				return EINVAL;
    663   1.1  dyoung 			if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
    664   1.1  dyoung 				ic->ic_flags |= IEEE80211_F_PMGTON;
    665   1.1  dyoung 				error = ENETRESET;
    666   1.1  dyoung 			}
    667   1.1  dyoung 		} else {
    668   1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON) {
    669   1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_PMGTON;
    670   1.1  dyoung 				error = ENETRESET;
    671   1.1  dyoung 			}
    672   1.1  dyoung 		}
    673   1.1  dyoung 		break;
    674   1.1  dyoung 	case WI_RID_MAX_SLEEP:
    675   1.1  dyoung 		if (len != 2)
    676   1.1  dyoung 			return EINVAL;
    677   1.1  dyoung 		ic->ic_lintval = le16toh(wreq.wi_val[0]);
    678   1.1  dyoung 		if (ic->ic_flags & IEEE80211_F_PMGTON)
    679   1.1  dyoung 			error = ENETRESET;
    680   1.1  dyoung 		break;
    681   1.1  dyoung 	case WI_RID_CUR_BEACON_INT:
    682   1.1  dyoung 		return EPERM;
    683   1.1  dyoung 	case WI_RID_WEP_AVAIL:
    684   1.1  dyoung 		return EPERM;
    685   1.1  dyoung 	case WI_RID_CNFAUTHMODE:
    686   1.1  dyoung 		if (len != 2)
    687   1.1  dyoung 			return EINVAL;
    688   1.1  dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    689   1.1  dyoung 			return EINVAL;		/* TODO: shared key auth */
    690   1.1  dyoung 		break;
    691   1.1  dyoung 	case WI_RID_ENCRYPTION:
    692   1.1  dyoung 		if (len != 2)
    693   1.1  dyoung 			return EINVAL;
    694   1.1  dyoung 		if (wreq.wi_val[0] != 0) {
    695   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    696   1.1  dyoung 				return EINVAL;
    697   1.1  dyoung 			if ((ic->ic_flags & IEEE80211_F_WEPON) == 0) {
    698   1.1  dyoung 				ic->ic_flags |= IEEE80211_F_WEPON;
    699   1.1  dyoung 				error = ENETRESET;
    700   1.1  dyoung 			}
    701   1.1  dyoung 		} else {
    702   1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_WEPON) {
    703   1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_WEPON;
    704   1.1  dyoung 				error = ENETRESET;
    705   1.1  dyoung 			}
    706   1.1  dyoung 		}
    707   1.1  dyoung 		break;
    708   1.1  dyoung 	case WI_RID_TX_CRYPT_KEY:
    709   1.1  dyoung 		if (len != 2)
    710   1.1  dyoung 			return EINVAL;
    711   1.1  dyoung 		i = le16toh(wreq.wi_val[0]);
    712   1.1  dyoung 		if (i >= IEEE80211_WEP_NKID)
    713   1.1  dyoung 			return EINVAL;
    714   1.1  dyoung 		ic->ic_wep_txkey = i;
    715   1.1  dyoung 		break;
    716   1.1  dyoung 	case WI_RID_DEFLT_CRYPT_KEYS:
    717   1.1  dyoung 		if (len != sizeof(struct wi_ltv_keys))
    718   1.1  dyoung 			return EINVAL;
    719   1.1  dyoung 		keys = (struct wi_ltv_keys *)&wreq;
    720   1.1  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    721   1.1  dyoung 			len = le16toh(keys->wi_keys[i].wi_keylen);
    722   1.1  dyoung 			if (len != 0 && len < IEEE80211_WEP_KEYLEN)
    723   1.1  dyoung 				return EINVAL;
    724   1.1  dyoung 			if (len > sizeof(ic->ic_nw_keys[i].wk_key))
    725   1.1  dyoung 				return EINVAL;
    726   1.1  dyoung 		}
    727   1.1  dyoung 		memset(ic->ic_nw_keys, 0, sizeof(ic->ic_nw_keys));
    728   1.1  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    729   1.1  dyoung 			len = le16toh(keys->wi_keys[i].wi_keylen);
    730   1.1  dyoung 			ic->ic_nw_keys[i].wk_len = len;
    731   1.1  dyoung 			memcpy(ic->ic_nw_keys[i].wk_key,
    732   1.1  dyoung 			    keys->wi_keys[i].wi_keydat, len);
    733   1.1  dyoung 		}
    734   1.1  dyoung 		error = ENETRESET;
    735   1.1  dyoung 		break;
    736   1.1  dyoung 	case WI_RID_MAX_DATALEN:
    737   1.1  dyoung 		if (len != 2)
    738   1.1  dyoung 			return EINVAL;
    739   1.1  dyoung 		len = le16toh(wreq.wi_val[0]);
    740   1.1  dyoung 		if (len < 350 /* ? */ || len > IEEE80211_MAX_LEN)
    741   1.1  dyoung 			return EINVAL;
    742   1.1  dyoung 		if (len != IEEE80211_MAX_LEN)
    743   1.1  dyoung 			return EINVAL;		/* TODO: fragment */
    744   1.1  dyoung 		ic->ic_fragthreshold = len;
    745   1.1  dyoung 		error = ENETRESET;
    746   1.1  dyoung 		break;
    747   1.1  dyoung 	case WI_RID_IFACE_STATS:
    748   1.1  dyoung 		error = EPERM;
    749   1.1  dyoung 		break;
    750   1.1  dyoung 	case WI_RID_SCAN_REQ:			/* XXX wicontrol */
    751   1.1  dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
    752   1.1  dyoung 			break;
    753   1.7  dyoung 		error = ieee80211_setupscan(ic);
    754   1.7  dyoung 		if (error == 0)
    755   1.7  dyoung 			error = ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
    756   1.1  dyoung 		break;
    757   1.1  dyoung 	case WI_RID_SCAN_APS:
    758   1.1  dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
    759   1.1  dyoung 			break;
    760   1.1  dyoung 		len--;			/* XXX: tx rate? */
    761   1.1  dyoung 		/* FALLTHRU */
    762   1.1  dyoung 	case WI_RID_CHANNEL_LIST:
    763   1.1  dyoung 		memset(chanlist, 0, sizeof(chanlist));
    764   1.1  dyoung 		/*
    765   1.1  dyoung 		 * Since channel 0 is not available for DS, channel 1
    766   1.1  dyoung 		 * is assigned to LSB on WaveLAN.
    767   1.1  dyoung 		 */
    768   1.1  dyoung 		if (ic->ic_phytype == IEEE80211_T_DS)
    769   1.1  dyoung 			i = 1;
    770   1.1  dyoung 		else
    771   1.1  dyoung 			i = 0;
    772   1.1  dyoung 		for (j = 0; i <= IEEE80211_CHAN_MAX; i++, j++) {
    773   1.1  dyoung 			if ((j / 8) >= len)
    774   1.1  dyoung 				break;
    775   1.1  dyoung 			if (isclr((u_int8_t *)wreq.wi_val, j))
    776   1.1  dyoung 				continue;
    777   1.1  dyoung 			if (isclr(ic->ic_chan_active, i)) {
    778   1.1  dyoung 				if (wreq.wi_type != WI_RID_CHANNEL_LIST)
    779   1.1  dyoung 					continue;
    780   1.1  dyoung 				if (isclr(ic->ic_chan_avail, i))
    781   1.1  dyoung 					return EPERM;
    782   1.1  dyoung 			}
    783   1.1  dyoung 			setbit(chanlist, i);
    784   1.1  dyoung 		}
    785   1.1  dyoung 		memcpy(ic->ic_chan_active, chanlist,
    786   1.1  dyoung 		    sizeof(ic->ic_chan_active));
    787   1.7  dyoung 		error = ieee80211_setupscan(ic);
    788   1.7  dyoung 		if (wreq.wi_type == WI_RID_CHANNEL_LIST) {
    789   1.7  dyoung 			/* NB: ignore error from ieee80211_setupscan */
    790   1.1  dyoung 			error = ENETRESET;
    791   1.7  dyoung 		} else if (error == 0)
    792   1.1  dyoung 			error = ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
    793   1.1  dyoung 		break;
    794   1.1  dyoung 	default:
    795   1.1  dyoung 		error = EINVAL;
    796   1.1  dyoung 		break;
    797   1.1  dyoung 	}
    798   1.1  dyoung 	return error;
    799   1.1  dyoung }
    800   1.1  dyoung 
    801   1.2  dyoung #ifdef __FreeBSD__
    802   1.1  dyoung int
    803   1.1  dyoung ieee80211_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data)
    804   1.1  dyoung {
    805   1.1  dyoung 	struct ieee80211com *ic = (void *)ifp;
    806   1.1  dyoung 	int error = 0;
    807   1.1  dyoung 	u_int kid, len;
    808   1.1  dyoung 	struct ieee80211req *ireq;
    809   1.7  dyoung 	struct ifreq *ifr;
    810   1.1  dyoung 	u_int8_t tmpkey[IEEE80211_KEYBUF_SIZE];
    811   1.1  dyoung 	char tmpssid[IEEE80211_NWID_LEN];
    812   1.1  dyoung 	struct ieee80211_channel *chan;
    813  1.10  dyoung 	struct ifaddr *ifa;			/* XXX */
    814   1.1  dyoung 
    815   1.1  dyoung 	switch (cmd) {
    816   1.1  dyoung 	case SIOCSIFMEDIA:
    817   1.1  dyoung 	case SIOCGIFMEDIA:
    818   1.1  dyoung 		error = ifmedia_ioctl(ifp, (struct ifreq *) data,
    819   1.1  dyoung 				&ic->ic_media, cmd);
    820   1.1  dyoung 		break;
    821   1.1  dyoung 	case SIOCG80211:
    822   1.1  dyoung 		ireq = (struct ieee80211req *) data;
    823   1.1  dyoung 		switch (ireq->i_type) {
    824   1.1  dyoung 		case IEEE80211_IOC_SSID:
    825   1.1  dyoung 			switch (ic->ic_state) {
    826   1.1  dyoung 			case IEEE80211_S_INIT:
    827   1.1  dyoung 			case IEEE80211_S_SCAN:
    828   1.1  dyoung 				ireq->i_len = ic->ic_des_esslen;
    829   1.1  dyoung 				memcpy(tmpssid, ic->ic_des_essid, ireq->i_len);
    830   1.1  dyoung 				break;
    831   1.1  dyoung 			default:
    832   1.1  dyoung 				ireq->i_len = ic->ic_bss->ni_esslen;
    833   1.1  dyoung 				memcpy(tmpssid, ic->ic_bss->ni_essid,
    834   1.1  dyoung 					ireq->i_len);
    835   1.1  dyoung 				break;
    836   1.1  dyoung 			}
    837   1.1  dyoung 			error = copyout(tmpssid, ireq->i_data, ireq->i_len);
    838   1.1  dyoung 			break;
    839   1.1  dyoung 		case IEEE80211_IOC_NUMSSIDS:
    840   1.1  dyoung 			ireq->i_val = 1;
    841   1.1  dyoung 			break;
    842   1.1  dyoung 		case IEEE80211_IOC_WEP:
    843   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    844   1.1  dyoung 				ireq->i_val = IEEE80211_WEP_NOSUP;
    845   1.1  dyoung 			} else {
    846   1.1  dyoung 				if (ic->ic_flags & IEEE80211_F_WEPON) {
    847   1.1  dyoung 					ireq->i_val =
    848   1.1  dyoung 					    IEEE80211_WEP_MIXED;
    849   1.1  dyoung 				} else {
    850   1.1  dyoung 					ireq->i_val =
    851   1.1  dyoung 					    IEEE80211_WEP_OFF;
    852   1.1  dyoung 				}
    853   1.1  dyoung 			}
    854   1.1  dyoung 			break;
    855   1.1  dyoung 		case IEEE80211_IOC_WEPKEY:
    856   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    857   1.1  dyoung 				error = EINVAL;
    858   1.1  dyoung 				break;
    859   1.1  dyoung 			}
    860   1.1  dyoung 			kid = (u_int) ireq->i_val;
    861   1.1  dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    862   1.1  dyoung 				error = EINVAL;
    863   1.1  dyoung 				break;
    864   1.1  dyoung 			}
    865   1.1  dyoung 			len = (u_int) ic->ic_nw_keys[kid].wk_len;
    866   1.1  dyoung 			/* NB: only root can read WEP keys */
    867   1.7  dyoung 			if (suser(curthread) == 0) {
    868   1.1  dyoung 				bcopy(ic->ic_nw_keys[kid].wk_key, tmpkey, len);
    869   1.1  dyoung 			} else {
    870   1.1  dyoung 				bzero(tmpkey, len);
    871   1.1  dyoung 			}
    872   1.1  dyoung 			ireq->i_len = len;
    873   1.1  dyoung 			error = copyout(tmpkey, ireq->i_data, len);
    874   1.1  dyoung 			break;
    875   1.1  dyoung 		case IEEE80211_IOC_NUMWEPKEYS:
    876   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    877   1.1  dyoung 				error = EINVAL;
    878   1.1  dyoung 			else
    879   1.1  dyoung 				ireq->i_val = IEEE80211_WEP_NKID;
    880   1.1  dyoung 			break;
    881   1.1  dyoung 		case IEEE80211_IOC_WEPTXKEY:
    882   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    883   1.1  dyoung 				error = EINVAL;
    884   1.1  dyoung 			else
    885   1.1  dyoung 				ireq->i_val = ic->ic_wep_txkey;
    886   1.1  dyoung 			break;
    887   1.1  dyoung 		case IEEE80211_IOC_AUTHMODE:
    888   1.1  dyoung 			ireq->i_val = IEEE80211_AUTH_OPEN;
    889   1.1  dyoung 			break;
    890   1.1  dyoung 		case IEEE80211_IOC_CHANNEL:
    891   1.1  dyoung 			switch (ic->ic_state) {
    892   1.1  dyoung 			case IEEE80211_S_INIT:
    893   1.1  dyoung 			case IEEE80211_S_SCAN:
    894   1.1  dyoung 				if (ic->ic_opmode == IEEE80211_M_STA)
    895   1.1  dyoung 					chan = ic->ic_des_chan;
    896   1.1  dyoung 				else
    897   1.1  dyoung 					chan = ic->ic_ibss_chan;
    898   1.1  dyoung 				break;
    899   1.1  dyoung 			default:
    900   1.1  dyoung 				chan = ic->ic_bss->ni_chan;
    901   1.1  dyoung 				break;
    902   1.1  dyoung 			}
    903   1.1  dyoung 			ireq->i_val = ieee80211_chan2ieee(ic, chan);
    904   1.1  dyoung 			break;
    905   1.1  dyoung 		case IEEE80211_IOC_POWERSAVE:
    906   1.1  dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON)
    907   1.1  dyoung 				ireq->i_val = IEEE80211_POWERSAVE_ON;
    908   1.1  dyoung 			else
    909   1.1  dyoung 				ireq->i_val = IEEE80211_POWERSAVE_OFF;
    910   1.1  dyoung 			break;
    911   1.1  dyoung 		case IEEE80211_IOC_POWERSAVESLEEP:
    912   1.1  dyoung 			ireq->i_val = ic->ic_lintval;
    913   1.1  dyoung 			break;
    914   1.7  dyoung 		case IEEE80211_IOC_RTSTHRESHOLD:
    915   1.1  dyoung 			ireq->i_val = ic->ic_rtsthreshold;
    916   1.1  dyoung 			break;
    917  1.10  dyoung 		case IEEE80211_IOC_PROTMODE:
    918  1.10  dyoung 			ireq->i_val = ic->ic_protmode;
    919  1.10  dyoung 			break;
    920  1.10  dyoung 		case IEEE80211_IOC_TXPOWER:
    921  1.10  dyoung 			if ((ic->ic_caps & IEEE80211_C_TXPMGT) == 0)
    922  1.10  dyoung 				error = EINVAL;
    923  1.10  dyoung 			else
    924  1.10  dyoung 				ireq->i_val = ic->ic_txpower;
    925  1.10  dyoung 			break;
    926   1.1  dyoung 		default:
    927   1.1  dyoung 			error = EINVAL;
    928  1.10  dyoung 			break;
    929   1.1  dyoung 		}
    930   1.1  dyoung 		break;
    931   1.1  dyoung 	case SIOCS80211:
    932   1.4  dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
    933   1.1  dyoung 		if (error)
    934   1.1  dyoung 			break;
    935   1.1  dyoung 		ireq = (struct ieee80211req *) data;
    936   1.1  dyoung 		switch (ireq->i_type) {
    937   1.1  dyoung 		case IEEE80211_IOC_SSID:
    938   1.1  dyoung 			if (ireq->i_val != 0 ||
    939   1.1  dyoung 			    ireq->i_len > IEEE80211_NWID_LEN) {
    940   1.1  dyoung 				error = EINVAL;
    941   1.1  dyoung 				break;
    942   1.1  dyoung 			}
    943   1.1  dyoung 			error = copyin(ireq->i_data, tmpssid, ireq->i_len);
    944   1.1  dyoung 			if (error)
    945   1.1  dyoung 				break;
    946   1.1  dyoung 			memset(ic->ic_des_essid, 0, IEEE80211_NWID_LEN);
    947   1.1  dyoung 			ic->ic_des_esslen = ireq->i_len;
    948   1.1  dyoung 			memcpy(ic->ic_des_essid, tmpssid, ireq->i_len);
    949   1.1  dyoung 			error = ENETRESET;
    950   1.1  dyoung 			break;
    951   1.1  dyoung 		case IEEE80211_IOC_WEP:
    952   1.1  dyoung 			/*
    953   1.1  dyoung 			 * These cards only support one mode so
    954   1.1  dyoung 			 * we just turn wep on if what ever is
    955   1.1  dyoung 			 * passed in is not OFF.
    956   1.1  dyoung 			 */
    957   1.1  dyoung 			if (ireq->i_val == IEEE80211_WEP_OFF) {
    958   1.1  dyoung 				ic->ic_flags &= ~IEEE80211_F_WEPON;
    959   1.1  dyoung 			} else {
    960   1.1  dyoung 				ic->ic_flags |= IEEE80211_F_WEPON;
    961   1.1  dyoung 			}
    962   1.1  dyoung 			error = ENETRESET;
    963   1.1  dyoung 			break;
    964   1.1  dyoung 		case IEEE80211_IOC_WEPKEY:
    965   1.1  dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    966   1.1  dyoung 				error = EINVAL;
    967   1.1  dyoung 				break;
    968   1.1  dyoung 			}
    969   1.1  dyoung 			kid = (u_int) ireq->i_val;
    970   1.1  dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    971   1.1  dyoung 				error = EINVAL;
    972   1.1  dyoung 				break;
    973   1.1  dyoung 			}
    974   1.1  dyoung 			if (ireq->i_len > sizeof(tmpkey)) {
    975   1.1  dyoung 				error = EINVAL;
    976   1.1  dyoung 				break;
    977   1.1  dyoung 			}
    978   1.1  dyoung 			memset(tmpkey, 0, sizeof(tmpkey));
    979   1.1  dyoung 			error = copyin(ireq->i_data, tmpkey, ireq->i_len);
    980   1.1  dyoung 			if (error)
    981   1.1  dyoung 				break;
    982   1.1  dyoung 			memcpy(ic->ic_nw_keys[kid].wk_key, tmpkey,
    983   1.1  dyoung 				sizeof(tmpkey));
    984   1.1  dyoung 			ic->ic_nw_keys[kid].wk_len = ireq->i_len;
    985   1.1  dyoung 			error = ENETRESET;
    986   1.1  dyoung 			break;
    987   1.1  dyoung 		case IEEE80211_IOC_WEPTXKEY:
    988   1.1  dyoung 			kid = (u_int) ireq->i_val;
    989   1.1  dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    990   1.1  dyoung 				error = EINVAL;
    991   1.1  dyoung 				break;
    992   1.1  dyoung 			}
    993   1.1  dyoung 			ic->ic_wep_txkey = kid;
    994   1.1  dyoung 			error = ENETRESET;
    995   1.1  dyoung 			break;
    996   1.1  dyoung #if 0
    997   1.1  dyoung 		case IEEE80211_IOC_AUTHMODE:
    998   1.1  dyoung 			sc->wi_authmode = ireq->i_val;
    999   1.1  dyoung 			break;
   1000   1.1  dyoung #endif
   1001   1.1  dyoung 		case IEEE80211_IOC_CHANNEL:
   1002   1.1  dyoung 			/* XXX 0xffff overflows 16-bit signed */
   1003   1.1  dyoung 			if (ireq->i_val == 0 ||
   1004   1.1  dyoung 			    ireq->i_val == (int16_t) IEEE80211_CHAN_ANY)
   1005   1.1  dyoung 				ic->ic_des_chan = IEEE80211_CHAN_ANYC;
   1006   1.1  dyoung 			else if ((u_int) ireq->i_val > IEEE80211_CHAN_MAX ||
   1007   1.1  dyoung 			    isclr(ic->ic_chan_active, ireq->i_val)) {
   1008   1.1  dyoung 				error = EINVAL;
   1009   1.1  dyoung 				break;
   1010   1.1  dyoung 			} else
   1011   1.1  dyoung 				ic->ic_ibss_chan = ic->ic_des_chan =
   1012   1.1  dyoung 					&ic->ic_channels[ireq->i_val];
   1013   1.1  dyoung 			switch (ic->ic_state) {
   1014   1.1  dyoung 			case IEEE80211_S_INIT:
   1015   1.1  dyoung 			case IEEE80211_S_SCAN:
   1016   1.1  dyoung 				error = ENETRESET;
   1017   1.1  dyoung 				break;
   1018   1.1  dyoung 			default:
   1019   1.1  dyoung 				if (ic->ic_opmode == IEEE80211_M_STA) {
   1020   1.1  dyoung 					if (ic->ic_des_chan != IEEE80211_CHAN_ANYC &&
   1021   1.1  dyoung 					    ic->ic_bss->ni_chan != ic->ic_des_chan)
   1022   1.1  dyoung 						error = ENETRESET;
   1023   1.1  dyoung 				} else {
   1024   1.1  dyoung 					if (ic->ic_bss->ni_chan != ic->ic_ibss_chan)
   1025   1.1  dyoung 						error = ENETRESET;
   1026   1.1  dyoung 				}
   1027   1.1  dyoung 				break;
   1028   1.1  dyoung 			}
   1029   1.1  dyoung 			break;
   1030   1.1  dyoung 		case IEEE80211_IOC_POWERSAVE:
   1031   1.1  dyoung 			switch (ireq->i_val) {
   1032   1.1  dyoung 			case IEEE80211_POWERSAVE_OFF:
   1033   1.1  dyoung 				if (ic->ic_flags & IEEE80211_F_PMGTON) {
   1034   1.1  dyoung 					ic->ic_flags &= ~IEEE80211_F_PMGTON;
   1035   1.1  dyoung 					error = ENETRESET;
   1036   1.1  dyoung 				}
   1037   1.1  dyoung 				break;
   1038   1.1  dyoung 			case IEEE80211_POWERSAVE_ON:
   1039   1.1  dyoung 				if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
   1040   1.1  dyoung 					error = EINVAL;
   1041   1.1  dyoung 				else if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
   1042   1.1  dyoung 					ic->ic_flags |= IEEE80211_F_PMGTON;
   1043   1.1  dyoung 					error = ENETRESET;
   1044   1.1  dyoung 				}
   1045   1.1  dyoung 				break;
   1046   1.1  dyoung 			default:
   1047   1.1  dyoung 				error = EINVAL;
   1048   1.1  dyoung 				break;
   1049   1.1  dyoung 			}
   1050   1.1  dyoung 			break;
   1051   1.1  dyoung 		case IEEE80211_IOC_POWERSAVESLEEP:
   1052   1.1  dyoung 			if (ireq->i_val < 0) {
   1053   1.1  dyoung 				error = EINVAL;
   1054   1.1  dyoung 				break;
   1055   1.1  dyoung 			}
   1056   1.1  dyoung 			ic->ic_lintval = ireq->i_val;
   1057   1.1  dyoung 			error = ENETRESET;
   1058   1.1  dyoung 			break;
   1059   1.7  dyoung 		case IEEE80211_IOC_RTSTHRESHOLD:
   1060   1.1  dyoung 			if (!(IEEE80211_RTS_MIN < ireq->i_val &&
   1061   1.2  dyoung 			      ireq->i_val <= IEEE80211_RTS_MAX + 1)) {
   1062   1.1  dyoung 				error = EINVAL;
   1063   1.1  dyoung 				break;
   1064   1.1  dyoung 			}
   1065   1.1  dyoung 			ic->ic_rtsthreshold = ireq->i_val;
   1066   1.1  dyoung 			error = ENETRESET;
   1067   1.1  dyoung 			break;
   1068  1.10  dyoung 		case IEEE80211_IOC_PROTMODE:
   1069  1.10  dyoung 			if (ireq->i_val > IEEE80211_PROT_RTSCTS) {
   1070  1.10  dyoung 				error = EINVAL;
   1071  1.10  dyoung 				break;
   1072  1.10  dyoung 			}
   1073  1.10  dyoung 			ic->ic_protmode = ireq->i_val;
   1074  1.10  dyoung 			/* NB: if not operating in 11g this can wait */
   1075  1.10  dyoung 			if (ic->ic_curmode == IEEE80211_MODE_11G)
   1076  1.10  dyoung 				error = ENETRESET;
   1077  1.10  dyoung 			break;
   1078  1.10  dyoung 		case IEEE80211_IOC_TXPOWER:
   1079  1.10  dyoung 			if ((ic->ic_caps & IEEE80211_C_TXPMGT) == 0) {
   1080  1.10  dyoung 				error = EINVAL;
   1081  1.10  dyoung 				break;
   1082  1.10  dyoung 			}
   1083  1.10  dyoung 			if (!(IEEE80211_TXPOWER_MIN < ireq->i_val &&
   1084  1.10  dyoung 			      ireq->i_val < IEEE80211_TXPOWER_MAX)) {
   1085  1.10  dyoung 				error = EINVAL;
   1086  1.10  dyoung 				break;
   1087  1.10  dyoung 			}
   1088  1.10  dyoung 			ic->ic_txpower = ireq->i_val;
   1089  1.10  dyoung 			error = ENETRESET;
   1090  1.10  dyoung 			break;
   1091   1.1  dyoung 		default:
   1092   1.1  dyoung 			error = EINVAL;
   1093   1.1  dyoung 			break;
   1094   1.1  dyoung 		}
   1095   1.1  dyoung 		break;
   1096   1.1  dyoung 	case SIOCGIFGENERIC:
   1097   1.1  dyoung 		error = ieee80211_cfgget(ifp, cmd, data);
   1098   1.1  dyoung 		break;
   1099   1.1  dyoung 	case SIOCSIFGENERIC:
   1100   1.4  dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
   1101   1.1  dyoung 		if (error)
   1102   1.1  dyoung 			break;
   1103   1.1  dyoung 		error = ieee80211_cfgset(ifp, cmd, data);
   1104   1.1  dyoung 		break;
   1105   1.1  dyoung 	default:
   1106   1.1  dyoung 		error = ether_ioctl(ifp, cmd, data);
   1107   1.1  dyoung 		break;
   1108   1.1  dyoung 	}
   1109   1.1  dyoung 	return error;
   1110   1.1  dyoung }
   1111   1.2  dyoung #endif /* __FreeBSD__ */
   1112   1.2  dyoung 
   1113   1.2  dyoung #ifdef __NetBSD__
   1114   1.2  dyoung int
   1115   1.2  dyoung ieee80211_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data)
   1116   1.2  dyoung {
   1117   1.2  dyoung 	struct ieee80211com *ic = (void *)ifp;
   1118   1.2  dyoung 	struct ifreq *ifr = (struct ifreq *)data;
   1119   1.2  dyoung 	int i, error = 0;
   1120   1.2  dyoung 	struct ieee80211_nwid nwid;
   1121   1.2  dyoung 	struct ieee80211_nwkey *nwkey;
   1122   1.2  dyoung 	struct ieee80211_power *power;
   1123   1.2  dyoung 	struct ieee80211_bssid *bssid;
   1124   1.2  dyoung 	struct ieee80211chanreq *chanreq;
   1125   1.2  dyoung 	struct ieee80211_channel *chan;
   1126   1.2  dyoung 	struct ieee80211_wepkey keys[IEEE80211_WEP_NKID];
   1127   1.2  dyoung 	static const u_int8_t empty_macaddr[IEEE80211_ADDR_LEN] = {
   1128   1.2  dyoung 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00
   1129   1.2  dyoung 	};
   1130  1.10  dyoung 	struct ifaddr *ifa;			/* XXX */
   1131   1.2  dyoung 
   1132   1.2  dyoung 	switch (cmd) {
   1133   1.2  dyoung 	case SIOCSIFMEDIA:
   1134   1.2  dyoung 	case SIOCGIFMEDIA:
   1135   1.2  dyoung 		error = ifmedia_ioctl(ifp, ifr, &ic->ic_media, cmd);
   1136   1.2  dyoung 		break;
   1137   1.2  dyoung 	case SIOCS80211NWID:
   1138   1.2  dyoung 		if ((error = copyin(ifr->ifr_data, &nwid, sizeof(nwid))) != 0)
   1139   1.2  dyoung 			break;
   1140   1.2  dyoung 		if (nwid.i_len > IEEE80211_NWID_LEN) {
   1141   1.2  dyoung 			error = EINVAL;
   1142   1.2  dyoung 			break;
   1143   1.2  dyoung 		}
   1144   1.2  dyoung 		memset(ic->ic_des_essid, 0, IEEE80211_NWID_LEN);
   1145   1.2  dyoung 		ic->ic_des_esslen = nwid.i_len;
   1146   1.2  dyoung 		memcpy(ic->ic_des_essid, nwid.i_nwid, nwid.i_len);
   1147   1.2  dyoung 		error = ENETRESET;
   1148   1.2  dyoung 		break;
   1149   1.2  dyoung 	case SIOCG80211NWID:
   1150   1.2  dyoung 		memset(&nwid, 0, sizeof(nwid));
   1151   1.2  dyoung 		switch (ic->ic_state) {
   1152   1.2  dyoung 		case IEEE80211_S_INIT:
   1153   1.2  dyoung 		case IEEE80211_S_SCAN:
   1154   1.2  dyoung 			nwid.i_len = ic->ic_des_esslen;
   1155   1.2  dyoung 			memcpy(nwid.i_nwid, ic->ic_des_essid, nwid.i_len);
   1156   1.2  dyoung 			break;
   1157   1.2  dyoung 		default:
   1158   1.2  dyoung 			nwid.i_len = ic->ic_bss->ni_esslen;
   1159   1.2  dyoung 			memcpy(nwid.i_nwid, ic->ic_bss->ni_essid, nwid.i_len);
   1160   1.2  dyoung 			break;
   1161   1.2  dyoung 		}
   1162   1.2  dyoung 		error = copyout(&nwid, ifr->ifr_data, sizeof(nwid));
   1163   1.2  dyoung 		break;
   1164   1.2  dyoung 	case SIOCS80211NWKEY:
   1165   1.2  dyoung 		nwkey = (struct ieee80211_nwkey *)data;
   1166   1.5  dyoung 		if ((ic->ic_caps & IEEE80211_C_WEP) == 0 &&
   1167   1.2  dyoung 		    nwkey->i_wepon != IEEE80211_NWKEY_OPEN) {
   1168   1.2  dyoung 			error = EINVAL;
   1169   1.2  dyoung 			break;
   1170   1.2  dyoung 		}
   1171   1.2  dyoung 		/* check and copy keys */
   1172   1.2  dyoung 		memset(keys, 0, sizeof(keys));
   1173   1.2  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
   1174   1.2  dyoung 			keys[i].wk_len = nwkey->i_key[i].i_keylen;
   1175   1.2  dyoung 			if ((keys[i].wk_len > 0 &&
   1176   1.2  dyoung 			    keys[i].wk_len < IEEE80211_WEP_KEYLEN) ||
   1177   1.2  dyoung 			    keys[i].wk_len > sizeof(keys[i].wk_key)) {
   1178   1.2  dyoung 				error = EINVAL;
   1179   1.2  dyoung 				break;
   1180   1.2  dyoung 			}
   1181   1.2  dyoung 			if (keys[i].wk_len <= 0)
   1182   1.2  dyoung 				continue;
   1183   1.2  dyoung 			if ((error = copyin(nwkey->i_key[i].i_keydat,
   1184   1.2  dyoung 			    keys[i].wk_key, keys[i].wk_len)) != 0)
   1185   1.2  dyoung 				break;
   1186   1.2  dyoung 		}
   1187   1.2  dyoung 		if (error)
   1188   1.2  dyoung 			break;
   1189   1.2  dyoung 		i = nwkey->i_defkid - 1;
   1190   1.2  dyoung 		if (i < 0 || i >= IEEE80211_WEP_NKID ||
   1191   1.2  dyoung 		    keys[i].wk_len == 0 ||
   1192   1.2  dyoung 		    (keys[i].wk_len == -1 && ic->ic_nw_keys[i].wk_len == 0)) {
   1193   1.2  dyoung 			if (nwkey->i_wepon != IEEE80211_NWKEY_OPEN) {
   1194   1.2  dyoung 				error = EINVAL;
   1195   1.2  dyoung 				break;
   1196   1.2  dyoung 			}
   1197   1.2  dyoung 		} else
   1198   1.2  dyoung 			ic->ic_wep_txkey = i;
   1199   1.2  dyoung 		/* save the key */
   1200   1.2  dyoung 		if (nwkey->i_wepon == IEEE80211_NWKEY_OPEN)
   1201   1.2  dyoung 			ic->ic_flags &= ~IEEE80211_F_WEPON;
   1202   1.2  dyoung 		else
   1203   1.2  dyoung 			ic->ic_flags |= IEEE80211_F_WEPON;
   1204   1.2  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
   1205   1.2  dyoung 			if (keys[i].wk_len < 0)
   1206   1.2  dyoung 				continue;
   1207   1.2  dyoung 			ic->ic_nw_keys[i].wk_len = keys[i].wk_len;
   1208   1.2  dyoung 			memcpy(ic->ic_nw_keys[i].wk_key, keys[i].wk_key,
   1209   1.2  dyoung 			    sizeof(keys[i].wk_key));
   1210   1.2  dyoung 		}
   1211   1.2  dyoung 		error = ENETRESET;
   1212   1.2  dyoung 		break;
   1213   1.2  dyoung 	case SIOCG80211NWKEY:
   1214   1.2  dyoung 		nwkey = (struct ieee80211_nwkey *)data;
   1215   1.2  dyoung 		if (ic->ic_flags & IEEE80211_F_WEPON)
   1216   1.2  dyoung 			nwkey->i_wepon = IEEE80211_NWKEY_WEP;
   1217   1.2  dyoung 		else
   1218   1.2  dyoung 			nwkey->i_wepon = IEEE80211_NWKEY_OPEN;
   1219   1.2  dyoung 		nwkey->i_defkid = ic->ic_wep_txkey + 1;
   1220   1.2  dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
   1221   1.2  dyoung 			if (nwkey->i_key[i].i_keydat == NULL)
   1222   1.2  dyoung 				continue;
   1223   1.2  dyoung 			/* do not show any keys to non-root user */
   1224   1.2  dyoung 			if ((error = suser(curproc->p_ucred,
   1225   1.2  dyoung 			    &curproc->p_acflag)) != 0)
   1226   1.2  dyoung 				break;
   1227   1.2  dyoung 			nwkey->i_key[i].i_keylen = ic->ic_nw_keys[i].wk_len;
   1228   1.2  dyoung 			if ((error = copyout(ic->ic_nw_keys[i].wk_key,
   1229   1.2  dyoung 			    nwkey->i_key[i].i_keydat,
   1230   1.2  dyoung 			    ic->ic_nw_keys[i].wk_len)) != 0)
   1231   1.2  dyoung 				break;
   1232   1.2  dyoung 		}
   1233   1.2  dyoung 		break;
   1234   1.2  dyoung 	case SIOCS80211POWER:
   1235   1.2  dyoung 		power = (struct ieee80211_power *)data;
   1236   1.2  dyoung 		ic->ic_lintval = power->i_maxsleep;
   1237   1.2  dyoung 		if (power->i_enabled != 0) {
   1238   1.5  dyoung 			if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
   1239   1.2  dyoung 				error = EINVAL;
   1240   1.2  dyoung 			else if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
   1241   1.2  dyoung 				ic->ic_flags |= IEEE80211_F_PMGTON;
   1242   1.2  dyoung 				error = ENETRESET;
   1243   1.2  dyoung 			}
   1244   1.2  dyoung 		} else {
   1245   1.2  dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON) {
   1246   1.2  dyoung 				ic->ic_flags &= ~IEEE80211_F_PMGTON;
   1247   1.2  dyoung 				error = ENETRESET;
   1248   1.2  dyoung 			}
   1249   1.2  dyoung 		}
   1250   1.2  dyoung 		break;
   1251   1.2  dyoung 	case SIOCG80211POWER:
   1252   1.2  dyoung 		power = (struct ieee80211_power *)data;
   1253   1.2  dyoung 		power->i_enabled = (ic->ic_flags & IEEE80211_F_PMGTON) ? 1 : 0;
   1254   1.2  dyoung 		power->i_maxsleep = ic->ic_lintval;
   1255   1.2  dyoung 		break;
   1256   1.2  dyoung 	case SIOCS80211BSSID:
   1257   1.2  dyoung 		bssid = (struct ieee80211_bssid *)data;
   1258   1.2  dyoung 		if (IEEE80211_ADDR_EQ(bssid->i_bssid, empty_macaddr))
   1259   1.2  dyoung 			ic->ic_flags &= ~IEEE80211_F_DESBSSID;
   1260   1.2  dyoung 		else {
   1261   1.2  dyoung 			ic->ic_flags |= IEEE80211_F_DESBSSID;
   1262   1.2  dyoung 			IEEE80211_ADDR_COPY(ic->ic_des_bssid, bssid->i_bssid);
   1263   1.2  dyoung 		}
   1264   1.2  dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
   1265   1.2  dyoung 			break;
   1266   1.2  dyoung 		switch (ic->ic_state) {
   1267   1.2  dyoung 		case IEEE80211_S_INIT:
   1268   1.2  dyoung 		case IEEE80211_S_SCAN:
   1269   1.2  dyoung 			error = ENETRESET;
   1270   1.2  dyoung 			break;
   1271   1.2  dyoung 		default:
   1272   1.2  dyoung 			if ((ic->ic_flags & IEEE80211_F_DESBSSID) &&
   1273   1.2  dyoung 			    !IEEE80211_ADDR_EQ(ic->ic_des_bssid,
   1274   1.2  dyoung 			    ic->ic_bss->ni_bssid))
   1275   1.2  dyoung 				error = ENETRESET;
   1276   1.2  dyoung 			break;
   1277   1.2  dyoung 		}
   1278   1.2  dyoung 		break;
   1279   1.2  dyoung 	case SIOCG80211BSSID:
   1280   1.2  dyoung 		bssid = (struct ieee80211_bssid *)data;
   1281   1.2  dyoung 		switch (ic->ic_state) {
   1282   1.2  dyoung 		case IEEE80211_S_INIT:
   1283   1.2  dyoung 		case IEEE80211_S_SCAN:
   1284   1.2  dyoung 			if (ic->ic_opmode == IEEE80211_M_HOSTAP)
   1285   1.2  dyoung 				IEEE80211_ADDR_COPY(bssid->i_bssid,
   1286   1.2  dyoung 				    ic->ic_myaddr);
   1287   1.2  dyoung 			else if (ic->ic_flags & IEEE80211_F_DESBSSID)
   1288   1.2  dyoung 				IEEE80211_ADDR_COPY(bssid->i_bssid,
   1289   1.2  dyoung 				    ic->ic_des_bssid);
   1290   1.2  dyoung 			else
   1291   1.2  dyoung 				memset(bssid->i_bssid, 0, IEEE80211_ADDR_LEN);
   1292   1.2  dyoung 			break;
   1293   1.2  dyoung 		default:
   1294   1.2  dyoung 			IEEE80211_ADDR_COPY(bssid->i_bssid,
   1295   1.2  dyoung 			    ic->ic_bss->ni_bssid);
   1296   1.2  dyoung 			break;
   1297   1.2  dyoung 		}
   1298   1.2  dyoung 		break;
   1299   1.2  dyoung 	case SIOCS80211CHANNEL:
   1300   1.2  dyoung 		chanreq = (struct ieee80211chanreq *)data;
   1301   1.2  dyoung 		if (chanreq->i_channel == IEEE80211_CHAN_ANY)
   1302   1.2  dyoung 			ic->ic_des_chan = IEEE80211_CHAN_ANYC;
   1303   1.2  dyoung 		else if (chanreq->i_channel > IEEE80211_CHAN_MAX ||
   1304   1.2  dyoung 		    isclr(ic->ic_chan_active, chanreq->i_channel)) {
   1305   1.2  dyoung 			error = EINVAL;
   1306   1.2  dyoung 			break;
   1307   1.2  dyoung 		} else
   1308   1.4  dyoung 			ic->ic_ibss_chan = ic->ic_des_chan =
   1309   1.4  dyoung 			    &ic->ic_channels[chanreq->i_channel];
   1310   1.2  dyoung 		switch (ic->ic_state) {
   1311   1.2  dyoung 		case IEEE80211_S_INIT:
   1312   1.2  dyoung 		case IEEE80211_S_SCAN:
   1313   1.2  dyoung 			error = ENETRESET;
   1314   1.2  dyoung 			break;
   1315   1.2  dyoung 		default:
   1316   1.2  dyoung 			if (ic->ic_opmode == IEEE80211_M_STA) {
   1317   1.2  dyoung 				if (ic->ic_des_chan != IEEE80211_CHAN_ANYC &&
   1318   1.2  dyoung 				    ic->ic_bss->ni_chan != ic->ic_des_chan)
   1319   1.2  dyoung 					error = ENETRESET;
   1320   1.2  dyoung 			} else {
   1321   1.2  dyoung 				if (ic->ic_bss->ni_chan != ic->ic_ibss_chan)
   1322   1.2  dyoung 					error = ENETRESET;
   1323   1.2  dyoung 			}
   1324   1.2  dyoung 			break;
   1325   1.2  dyoung 		}
   1326   1.2  dyoung 		break;
   1327   1.2  dyoung 	case SIOCG80211CHANNEL:
   1328   1.2  dyoung 		chanreq = (struct ieee80211chanreq *)data;
   1329   1.2  dyoung 		switch (ic->ic_state) {
   1330   1.2  dyoung 		case IEEE80211_S_INIT:
   1331   1.2  dyoung 		case IEEE80211_S_SCAN:
   1332   1.2  dyoung 			if (ic->ic_opmode == IEEE80211_M_STA)
   1333   1.2  dyoung 				chan = ic->ic_des_chan;
   1334   1.2  dyoung 			else
   1335   1.2  dyoung 				chan = ic->ic_ibss_chan;
   1336   1.2  dyoung 			break;
   1337   1.2  dyoung 		default:
   1338   1.2  dyoung 			chan = ic->ic_bss->ni_chan;
   1339   1.2  dyoung 			break;
   1340   1.2  dyoung 		}
   1341   1.2  dyoung 		chanreq->i_channel = ieee80211_chan2ieee(ic, chan);
   1342   1.2  dyoung 		break;
   1343   1.2  dyoung 	case SIOCGIFGENERIC:
   1344   1.2  dyoung 		error = ieee80211_cfgget(ifp, cmd, data);
   1345   1.2  dyoung 		break;
   1346   1.2  dyoung 	case SIOCSIFGENERIC:
   1347   1.2  dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
   1348   1.2  dyoung 		if (error)
   1349   1.2  dyoung 			break;
   1350   1.2  dyoung 		error = ieee80211_cfgset(ifp, cmd, data);
   1351   1.7  dyoung 		break;
   1352   1.7  dyoung 	case SIOCG80211STATS:
   1353   1.7  dyoung 		ifr = (struct ifreq *)data;
   1354   1.7  dyoung 		copyout(&ic->ic_stats, ifr->ifr_data, sizeof (ic->ic_stats));
   1355   1.2  dyoung 		break;
   1356  1.10  dyoung 	case SIOCSIFMTU:
   1357  1.10  dyoung 		ifr = (struct ifreq *)data;
   1358  1.10  dyoung 		if (!(IEEE80211_MTU_MIN <= ifr->ifr_mtu &&
   1359  1.10  dyoung 		    ifr->ifr_mtu <= IEEE80211_MTU_MAX))
   1360  1.10  dyoung 			error = EINVAL;
   1361  1.10  dyoung 		else
   1362  1.10  dyoung 			ifp->if_mtu = ifr->ifr_mtu;
   1363  1.10  dyoung 		break;
   1364  1.10  dyoung 	case SIOCSIFADDR:
   1365  1.10  dyoung 		/*
   1366  1.10  dyoung 		 * XXX Handle this directly so we can supress if_init calls.
   1367  1.10  dyoung 		 * XXX This should be done in ether_ioctl but for the moment
   1368  1.10  dyoung 		 * XXX there are too many other parts of the system that
   1369  1.10  dyoung 		 * XXX set IFF_UP and so supress if_init being called when
   1370  1.10  dyoung 		 * XXX it should be.
   1371  1.10  dyoung 		 */
   1372  1.10  dyoung 		ifa = (struct ifaddr *) data;
   1373  1.10  dyoung 		switch (ifa->ifa_addr->sa_family) {
   1374  1.10  dyoung #ifdef INET
   1375  1.10  dyoung 		case AF_INET:
   1376  1.10  dyoung 			if ((ifp->if_flags & IFF_UP) == 0) {
   1377  1.10  dyoung 				ifp->if_flags |= IFF_UP;
   1378  1.10  dyoung 				ifp->if_init(ifp->if_softc);
   1379  1.10  dyoung 			}
   1380  1.10  dyoung 			arp_ifinit(ifp, ifa);
   1381  1.10  dyoung 			break;
   1382  1.10  dyoung #endif
   1383  1.10  dyoung #ifdef IPX
   1384  1.10  dyoung 		/*
   1385  1.10  dyoung 		 * XXX - This code is probably wrong,
   1386  1.10  dyoung 		 *	 but has been copied many times.
   1387  1.10  dyoung 		 */
   1388  1.10  dyoung 		case AF_IPX: {
   1389  1.10  dyoung 			struct ipx_addr *ina = &(IA_SIPX(ifa)->sipx_addr);
   1390  1.10  dyoung 			struct arpcom *ac = (struct arpcom *)ifp;
   1391  1.10  dyoung 
   1392  1.10  dyoung 			if (ipx_nullhost(*ina))
   1393  1.10  dyoung 				ina->x_host = *(union ipx_host *) ac->ac_enaddr;
   1394  1.10  dyoung 			else
   1395  1.10  dyoung 				bcopy((caddr_t) ina->x_host.c_host,
   1396  1.10  dyoung 				      (caddr_t) ac->ac_enaddr,
   1397  1.10  dyoung 				      sizeof(ac->ac_enaddr));
   1398  1.10  dyoung 			/* fall thru... */
   1399  1.10  dyoung 		}
   1400  1.10  dyoung #endif
   1401  1.10  dyoung 		default:
   1402  1.10  dyoung 			if ((ifp->if_flags & IFF_UP) == 0) {
   1403  1.10  dyoung 				ifp->if_flags |= IFF_UP;
   1404  1.10  dyoung 				ifp->if_init(ifp->if_softc);
   1405  1.10  dyoung 			}
   1406  1.10  dyoung 			break;
   1407  1.10  dyoung 		}
   1408  1.10  dyoung 		break;
   1409   1.2  dyoung 	default:
   1410   1.2  dyoung 		error = ether_ioctl(ifp, cmd, data);
   1411   1.2  dyoung 		break;
   1412   1.2  dyoung 	}
   1413   1.2  dyoung 	return error;
   1414   1.2  dyoung }
   1415   1.2  dyoung #endif /* __NetBSD__ */
   1416