Home | History | Annotate | Line # | Download | only in net80211
ieee80211_ioctl.c revision 1.17.2.1
      1  1.17.2.1     kent /*	$NetBSD: ieee80211_ioctl.c,v 1.17.2.1 2005/04/29 11:29:32 kent Exp $	*/
      2       1.1   dyoung /*-
      3       1.1   dyoung  * Copyright (c) 2001 Atsushi Onoe
      4       1.1   dyoung  * Copyright (c) 2002, 2003 Sam Leffler, Errno Consulting
      5       1.1   dyoung  * All rights reserved.
      6       1.1   dyoung  *
      7       1.1   dyoung  * Redistribution and use in source and binary forms, with or without
      8       1.1   dyoung  * modification, are permitted provided that the following conditions
      9       1.1   dyoung  * are met:
     10       1.1   dyoung  * 1. Redistributions of source code must retain the above copyright
     11       1.1   dyoung  *    notice, this list of conditions and the following disclaimer.
     12       1.1   dyoung  * 2. Redistributions in binary form must reproduce the above copyright
     13       1.1   dyoung  *    notice, this list of conditions and the following disclaimer in the
     14       1.1   dyoung  *    documentation and/or other materials provided with the distribution.
     15       1.1   dyoung  * 3. The name of the author may not be used to endorse or promote products
     16       1.1   dyoung  *    derived from this software without specific prior written permission.
     17       1.1   dyoung  *
     18       1.1   dyoung  * Alternatively, this software may be distributed under the terms of the
     19       1.1   dyoung  * GNU General Public License ("GPL") version 2 as published by the Free
     20       1.1   dyoung  * Software Foundation.
     21       1.1   dyoung  *
     22       1.1   dyoung  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
     23       1.1   dyoung  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
     24       1.1   dyoung  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
     25       1.1   dyoung  * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
     26       1.1   dyoung  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     27       1.1   dyoung  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
     28       1.1   dyoung  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
     29       1.1   dyoung  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
     30       1.1   dyoung  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
     31       1.1   dyoung  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
     32       1.1   dyoung  */
     33       1.1   dyoung 
     34       1.1   dyoung #include <sys/cdefs.h>
     35       1.3   dyoung #ifdef __FreeBSD__
     36      1.10   dyoung __FBSDID("$FreeBSD: src/sys/net80211/ieee80211_ioctl.c,v 1.13 2004/03/30 22:57:57 sam Exp $");
     37       1.3   dyoung #else
     38  1.17.2.1     kent __KERNEL_RCSID(0, "$NetBSD: ieee80211_ioctl.c,v 1.17.2.1 2005/04/29 11:29:32 kent Exp $");
     39       1.3   dyoung #endif
     40       1.1   dyoung 
     41       1.1   dyoung /*
     42       1.1   dyoung  * IEEE 802.11 ioctl support (FreeBSD-specific)
     43       1.1   dyoung  */
     44       1.1   dyoung 
     45      1.10   dyoung #include "opt_inet.h"
     46      1.10   dyoung 
     47       1.1   dyoung #include <sys/endian.h>
     48       1.1   dyoung #include <sys/param.h>
     49       1.1   dyoung #include <sys/kernel.h>
     50       1.1   dyoung #include <sys/socket.h>
     51       1.1   dyoung #include <sys/sockio.h>
     52       1.1   dyoung #include <sys/systm.h>
     53       1.4   dyoung #include <sys/proc.h>
     54  1.17.2.1     kent 
     55       1.1   dyoung #include <net/if.h>
     56       1.1   dyoung #include <net/if_arp.h>
     57       1.1   dyoung #include <net/if_media.h>
     58       1.2   dyoung #ifdef __FreeBSD__
     59       1.1   dyoung #include <net/ethernet.h>
     60       1.4   dyoung #else
     61       1.4   dyoung #include <net/if_ether.h>
     62       1.2   dyoung #endif
     63       1.1   dyoung 
     64      1.10   dyoung #ifdef INET
     65      1.10   dyoung #include <netinet/in.h>
     66      1.10   dyoung #ifdef __FreeBSD__
     67      1.10   dyoung #include <netinet/if_ether.h>
     68      1.10   dyoung #endif /* __FreeBSD__ */
     69      1.10   dyoung #include <netinet/if_inarp.h>
     70      1.10   dyoung #endif
     71      1.10   dyoung 
     72       1.1   dyoung #include <net80211/ieee80211_var.h>
     73       1.1   dyoung #include <net80211/ieee80211_ioctl.h>
     74       1.1   dyoung 
     75       1.4   dyoung #ifdef __FreeBSD__
     76       1.1   dyoung #include <dev/wi/if_wavelan_ieee.h>
     77       1.4   dyoung #else
     78       1.4   dyoung #include <dev/ic/wi_ieee.h>
     79       1.4   dyoung #endif
     80       1.1   dyoung 
     81       1.1   dyoung /*
     82       1.1   dyoung  * XXX
     83       1.1   dyoung  * Wireless LAN specific configuration interface, which is compatible
     84       1.1   dyoung  * with wicontrol(8).
     85       1.1   dyoung  */
     86       1.1   dyoung 
     87       1.1   dyoung int
     88       1.1   dyoung ieee80211_cfgget(struct ifnet *ifp, u_long cmd, caddr_t data)
     89       1.1   dyoung {
     90       1.1   dyoung 	struct ieee80211com *ic = (void *)ifp;
     91       1.1   dyoung 	int i, j, error;
     92       1.1   dyoung 	struct ifreq *ifr = (struct ifreq *)data;
     93       1.1   dyoung 	struct wi_req wreq;
     94       1.1   dyoung 	struct wi_ltv_keys *keys;
     95       1.1   dyoung 	struct wi_apinfo *ap;
     96       1.1   dyoung 	struct ieee80211_node *ni;
     97       1.1   dyoung 	struct ieee80211_rateset *rs;
     98       1.4   dyoung #ifdef WICACHE
     99       1.1   dyoung 	struct wi_sigcache wsc;
    100       1.4   dyoung #endif /* WICACHE */
    101       1.4   dyoung #if 0 /* TBD */
    102       1.1   dyoung 	struct wi_scan_p2_hdr *p2;
    103       1.1   dyoung 	struct wi_scan_res *res;
    104       1.4   dyoung #endif
    105       1.1   dyoung 
    106       1.1   dyoung 	error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
    107       1.1   dyoung 	if (error)
    108       1.1   dyoung 		return error;
    109       1.1   dyoung 	wreq.wi_len = 0;
    110       1.1   dyoung 	switch (wreq.wi_type) {
    111       1.1   dyoung 	case WI_RID_SERIALNO:
    112       1.8     onoe 	case WI_RID_STA_IDENTITY:
    113       1.1   dyoung 		/* nothing appropriate */
    114       1.1   dyoung 		break;
    115       1.1   dyoung 	case WI_RID_NODENAME:
    116       1.9   itojun 		strlcpy((char *)&wreq.wi_val[1], hostname,
    117       1.9   itojun 		    sizeof(wreq.wi_val) - sizeof(wreq.wi_val[0]));
    118       1.1   dyoung 		wreq.wi_val[0] = htole16(strlen(hostname));
    119       1.1   dyoung 		wreq.wi_len = (1 + strlen(hostname) + 1) / 2;
    120       1.1   dyoung 		break;
    121       1.1   dyoung 	case WI_RID_CURRENT_SSID:
    122       1.1   dyoung 		if (ic->ic_state != IEEE80211_S_RUN) {
    123       1.1   dyoung 			wreq.wi_val[0] = 0;
    124       1.1   dyoung 			wreq.wi_len = 1;
    125       1.1   dyoung 			break;
    126       1.1   dyoung 		}
    127       1.1   dyoung 		wreq.wi_val[0] = htole16(ic->ic_bss->ni_esslen);
    128       1.1   dyoung 		memcpy(&wreq.wi_val[1], ic->ic_bss->ni_essid,
    129       1.1   dyoung 		    ic->ic_bss->ni_esslen);
    130       1.1   dyoung 		wreq.wi_len = (1 + ic->ic_bss->ni_esslen + 1) / 2;
    131       1.1   dyoung 		break;
    132       1.1   dyoung 	case WI_RID_OWN_SSID:
    133       1.1   dyoung 	case WI_RID_DESIRED_SSID:
    134       1.1   dyoung 		wreq.wi_val[0] = htole16(ic->ic_des_esslen);
    135       1.1   dyoung 		memcpy(&wreq.wi_val[1], ic->ic_des_essid, ic->ic_des_esslen);
    136       1.1   dyoung 		wreq.wi_len = (1 + ic->ic_des_esslen + 1) / 2;
    137       1.1   dyoung 		break;
    138       1.1   dyoung 	case WI_RID_CURRENT_BSSID:
    139       1.1   dyoung 		if (ic->ic_state == IEEE80211_S_RUN)
    140       1.1   dyoung 			IEEE80211_ADDR_COPY(wreq.wi_val, ic->ic_bss->ni_bssid);
    141       1.1   dyoung 		else
    142       1.1   dyoung 			memset(wreq.wi_val, 0, IEEE80211_ADDR_LEN);
    143       1.1   dyoung 		wreq.wi_len = IEEE80211_ADDR_LEN / 2;
    144       1.1   dyoung 		break;
    145       1.1   dyoung 	case WI_RID_CHANNEL_LIST:
    146       1.1   dyoung 		memset(wreq.wi_val, 0, sizeof(wreq.wi_val));
    147       1.1   dyoung 		/*
    148       1.1   dyoung 		 * Since channel 0 is not available for DS, channel 1
    149       1.1   dyoung 		 * is assigned to LSB on WaveLAN.
    150       1.1   dyoung 		 */
    151       1.1   dyoung 		if (ic->ic_phytype == IEEE80211_T_DS)
    152       1.1   dyoung 			i = 1;
    153       1.1   dyoung 		else
    154       1.1   dyoung 			i = 0;
    155       1.1   dyoung 		for (j = 0; i <= IEEE80211_CHAN_MAX; i++, j++)
    156       1.1   dyoung 			if (isset(ic->ic_chan_active, i)) {
    157       1.1   dyoung 				setbit((u_int8_t *)wreq.wi_val, j);
    158       1.1   dyoung 				wreq.wi_len = j / 16 + 1;
    159       1.1   dyoung 			}
    160       1.1   dyoung 		break;
    161       1.1   dyoung 	case WI_RID_OWN_CHNL:
    162       1.1   dyoung 		wreq.wi_val[0] = htole16(
    163       1.1   dyoung 			ieee80211_chan2ieee(ic, ic->ic_ibss_chan));
    164       1.1   dyoung 		wreq.wi_len = 1;
    165       1.1   dyoung 		break;
    166       1.1   dyoung 	case WI_RID_CURRENT_CHAN:
    167       1.1   dyoung 		wreq.wi_val[0] = htole16(
    168       1.1   dyoung 			ieee80211_chan2ieee(ic, ic->ic_bss->ni_chan));
    169       1.1   dyoung 		wreq.wi_len = 1;
    170       1.1   dyoung 		break;
    171       1.1   dyoung 	case WI_RID_COMMS_QUALITY:
    172       1.1   dyoung 		wreq.wi_val[0] = 0;				/* quality */
    173       1.7   dyoung 		wreq.wi_val[1] =
    174       1.7   dyoung 			htole16((*ic->ic_node_getrssi)(ic, ic->ic_bss));
    175       1.1   dyoung 		wreq.wi_val[2] = 0;				/* noise */
    176       1.1   dyoung 		wreq.wi_len = 3;
    177       1.1   dyoung 		break;
    178       1.1   dyoung 	case WI_RID_PROMISC:
    179       1.1   dyoung 		wreq.wi_val[0] = htole16((ifp->if_flags & IFF_PROMISC) ? 1 : 0);
    180       1.1   dyoung 		wreq.wi_len = 1;
    181       1.1   dyoung 		break;
    182       1.1   dyoung 	case WI_RID_PORTTYPE:
    183       1.1   dyoung 		wreq.wi_val[0] = htole16(ic->ic_opmode);
    184       1.1   dyoung 		wreq.wi_len = 1;
    185       1.1   dyoung 		break;
    186       1.1   dyoung 	case WI_RID_MAC_NODE:
    187       1.1   dyoung 		IEEE80211_ADDR_COPY(wreq.wi_val, ic->ic_myaddr);
    188       1.1   dyoung 		wreq.wi_len = IEEE80211_ADDR_LEN / 2;
    189       1.1   dyoung 		break;
    190       1.1   dyoung 	case WI_RID_TX_RATE:
    191       1.1   dyoung 		if (ic->ic_fixed_rate == -1)
    192       1.1   dyoung 			wreq.wi_val[0] = 0;	/* auto */
    193       1.1   dyoung 		else
    194       1.1   dyoung 			wreq.wi_val[0] = htole16(
    195       1.1   dyoung 			    (ic->ic_sup_rates[ic->ic_curmode].rs_rates[ic->ic_fixed_rate] &
    196       1.1   dyoung 			    IEEE80211_RATE_VAL) / 2);
    197       1.1   dyoung 		wreq.wi_len = 1;
    198       1.1   dyoung 		break;
    199       1.1   dyoung 	case WI_RID_CUR_TX_RATE:
    200       1.1   dyoung 		wreq.wi_val[0] = htole16(
    201       1.1   dyoung 		    (ic->ic_bss->ni_rates.rs_rates[ic->ic_bss->ni_txrate] &
    202       1.1   dyoung 		    IEEE80211_RATE_VAL) / 2);
    203       1.1   dyoung 		wreq.wi_len = 1;
    204       1.1   dyoung 		break;
    205       1.6   dyoung 	case WI_RID_FRAG_THRESH:
    206       1.6   dyoung 		wreq.wi_val[0] = htole16(ic->ic_fragthreshold);
    207       1.6   dyoung 		wreq.wi_len = 1;
    208       1.6   dyoung 		break;
    209       1.1   dyoung 	case WI_RID_RTS_THRESH:
    210       1.1   dyoung 		wreq.wi_val[0] = htole16(ic->ic_rtsthreshold);
    211       1.1   dyoung 		wreq.wi_len = 1;
    212       1.1   dyoung 		break;
    213       1.1   dyoung 	case WI_RID_CREATE_IBSS:
    214       1.1   dyoung 		wreq.wi_val[0] =
    215       1.1   dyoung 		    htole16((ic->ic_flags & IEEE80211_F_IBSSON) ? 1 : 0);
    216       1.1   dyoung 		wreq.wi_len = 1;
    217       1.1   dyoung 		break;
    218       1.1   dyoung 	case WI_RID_MICROWAVE_OVEN:
    219       1.1   dyoung 		wreq.wi_val[0] = 0;	/* no ... not supported */
    220       1.1   dyoung 		wreq.wi_len = 1;
    221       1.1   dyoung 		break;
    222       1.1   dyoung 	case WI_RID_ROAMING_MODE:
    223       1.1   dyoung 		wreq.wi_val[0] = htole16(1);	/* enabled ... not supported */
    224       1.1   dyoung 		wreq.wi_len = 1;
    225       1.1   dyoung 		break;
    226       1.1   dyoung 	case WI_RID_SYSTEM_SCALE:
    227       1.1   dyoung 		wreq.wi_val[0] = htole16(1);	/* low density ... not supp */
    228       1.1   dyoung 		wreq.wi_len = 1;
    229       1.1   dyoung 		break;
    230       1.1   dyoung 	case WI_RID_PM_ENABLED:
    231       1.1   dyoung 		wreq.wi_val[0] =
    232       1.1   dyoung 		    htole16((ic->ic_flags & IEEE80211_F_PMGTON) ? 1 : 0);
    233       1.1   dyoung 		wreq.wi_len = 1;
    234       1.1   dyoung 		break;
    235       1.1   dyoung 	case WI_RID_MAX_SLEEP:
    236       1.1   dyoung 		wreq.wi_val[0] = htole16(ic->ic_lintval);
    237       1.1   dyoung 		wreq.wi_len = 1;
    238       1.1   dyoung 		break;
    239       1.1   dyoung 	case WI_RID_CUR_BEACON_INT:
    240       1.1   dyoung 		wreq.wi_val[0] = htole16(ic->ic_bss->ni_intval);
    241       1.1   dyoung 		wreq.wi_len = 1;
    242       1.1   dyoung 		break;
    243       1.1   dyoung 	case WI_RID_WEP_AVAIL:
    244       1.1   dyoung 		wreq.wi_val[0] =
    245       1.1   dyoung 		    htole16((ic->ic_caps & IEEE80211_C_WEP) ? 1 : 0);
    246       1.1   dyoung 		wreq.wi_len = 1;
    247       1.1   dyoung 		break;
    248       1.1   dyoung 	case WI_RID_CNFAUTHMODE:
    249       1.1   dyoung 		wreq.wi_val[0] = htole16(1);	/* TODO: open system only */
    250       1.1   dyoung 		wreq.wi_len = 1;
    251       1.1   dyoung 		break;
    252       1.1   dyoung 	case WI_RID_ENCRYPTION:
    253       1.1   dyoung 		wreq.wi_val[0] =
    254      1.16  mycroft 		    htole16((ic->ic_flags & IEEE80211_F_PRIVACY) ? 1 : 0);
    255       1.1   dyoung 		wreq.wi_len = 1;
    256       1.1   dyoung 		break;
    257       1.1   dyoung 	case WI_RID_TX_CRYPT_KEY:
    258       1.1   dyoung 		wreq.wi_val[0] = htole16(ic->ic_wep_txkey);
    259       1.1   dyoung 		wreq.wi_len = 1;
    260       1.1   dyoung 		break;
    261       1.1   dyoung 	case WI_RID_DEFLT_CRYPT_KEYS:
    262       1.1   dyoung 		keys = (struct wi_ltv_keys *)&wreq;
    263       1.1   dyoung 		/* do not show keys to non-root user */
    264       1.4   dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
    265       1.1   dyoung 		if (error) {
    266       1.1   dyoung 			memset(keys, 0, sizeof(*keys));
    267       1.1   dyoung 			error = 0;
    268       1.1   dyoung 			break;
    269       1.1   dyoung 		}
    270       1.1   dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    271       1.1   dyoung 			keys->wi_keys[i].wi_keylen =
    272       1.1   dyoung 			    htole16(ic->ic_nw_keys[i].wk_len);
    273       1.1   dyoung 			memcpy(keys->wi_keys[i].wi_keydat,
    274       1.1   dyoung 			    ic->ic_nw_keys[i].wk_key, ic->ic_nw_keys[i].wk_len);
    275       1.1   dyoung 		}
    276       1.1   dyoung 		wreq.wi_len = sizeof(*keys) / 2;
    277       1.1   dyoung 		break;
    278       1.1   dyoung 	case WI_RID_MAX_DATALEN:
    279       1.1   dyoung 		wreq.wi_val[0] = htole16(IEEE80211_MAX_LEN);	/* TODO: frag */
    280       1.1   dyoung 		wreq.wi_len = 1;
    281       1.1   dyoung 		break;
    282       1.8     onoe 	case WI_RID_DBM_ADJUST:
    283       1.8     onoe 		/* not supported, we just pass rssi value from driver. */
    284       1.8     onoe 		break;
    285       1.1   dyoung 	case WI_RID_IFACE_STATS:
    286       1.1   dyoung 		/* XXX: should be implemented in lower drivers */
    287       1.1   dyoung 		break;
    288       1.1   dyoung 	case WI_RID_READ_APS:
    289       1.1   dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP) {
    290       1.1   dyoung 			/*
    291       1.1   dyoung 			 * Don't return results until active scan completes.
    292       1.1   dyoung 			 */
    293       1.1   dyoung 			if (ic->ic_state == IEEE80211_S_SCAN &&
    294       1.1   dyoung 			    (ic->ic_flags & IEEE80211_F_ASCAN)) {
    295       1.1   dyoung 				error = EINPROGRESS;
    296       1.1   dyoung 				break;
    297       1.1   dyoung 			}
    298       1.1   dyoung 		}
    299       1.1   dyoung 		i = 0;
    300       1.1   dyoung 		ap = (void *)((char *)wreq.wi_val + sizeof(i));
    301       1.1   dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    302       1.1   dyoung 			if ((caddr_t)(ap + 1) > (caddr_t)(&wreq + 1))
    303       1.1   dyoung 				break;
    304       1.1   dyoung 			memset(ap, 0, sizeof(*ap));
    305       1.1   dyoung 			if (ic->ic_opmode == IEEE80211_M_HOSTAP) {
    306       1.1   dyoung 				IEEE80211_ADDR_COPY(ap->bssid, ni->ni_macaddr);
    307       1.1   dyoung 				ap->namelen = ic->ic_des_esslen;
    308       1.1   dyoung 				if (ic->ic_des_esslen)
    309       1.1   dyoung 					memcpy(ap->name, ic->ic_des_essid,
    310       1.1   dyoung 					    ic->ic_des_esslen);
    311       1.1   dyoung 			} else {
    312       1.1   dyoung 				IEEE80211_ADDR_COPY(ap->bssid, ni->ni_bssid);
    313       1.1   dyoung 				ap->namelen = ni->ni_esslen;
    314       1.1   dyoung 				if (ni->ni_esslen)
    315       1.1   dyoung 					memcpy(ap->name, ni->ni_essid,
    316       1.1   dyoung 					    ni->ni_esslen);
    317       1.1   dyoung 			}
    318       1.1   dyoung 			ap->channel = ieee80211_chan2ieee(ic, ni->ni_chan);
    319       1.7   dyoung 			ap->signal = (*ic->ic_node_getrssi)(ic, ni);
    320       1.1   dyoung 			ap->capinfo = ni->ni_capinfo;
    321       1.1   dyoung 			ap->interval = ni->ni_intval;
    322       1.1   dyoung 			rs = &ni->ni_rates;
    323       1.1   dyoung 			for (j = 0; j < rs->rs_nrates; j++) {
    324       1.1   dyoung 				if (rs->rs_rates[j] & IEEE80211_RATE_BASIC) {
    325       1.1   dyoung 					ap->rate = (rs->rs_rates[j] &
    326       1.1   dyoung 					    IEEE80211_RATE_VAL) * 5; /* XXX */
    327       1.1   dyoung 				}
    328       1.1   dyoung 			}
    329       1.1   dyoung 			i++;
    330       1.1   dyoung 			ap++;
    331       1.1   dyoung 		}
    332       1.1   dyoung 		memcpy(wreq.wi_val, &i, sizeof(i));
    333       1.1   dyoung 		wreq.wi_len = (sizeof(int) + sizeof(*ap) * i) / 2;
    334       1.1   dyoung 		break;
    335       1.4   dyoung #if 0
    336       1.1   dyoung 	case WI_RID_PRISM2:
    337       1.1   dyoung 		wreq.wi_val[0] = 1;	/* XXX lie so SCAN_RES can give rates */
    338       1.1   dyoung 		wreq.wi_len = sizeof(u_int16_t) / 2;
    339       1.1   dyoung 		break;
    340       1.1   dyoung 	case WI_RID_SCAN_RES:			/* compatibility interface */
    341       1.1   dyoung 		if (ic->ic_opmode != IEEE80211_M_HOSTAP &&
    342      1.10   dyoung 		    ic->ic_state == IEEE80211_S_SCAN &&
    343      1.10   dyoung 		    (ic->ic_flags & IEEE80211_F_ASCAN)) {
    344       1.1   dyoung 			error = EINPROGRESS;
    345       1.1   dyoung 			break;
    346       1.1   dyoung 		}
    347       1.1   dyoung 		/* NB: we use the Prism2 format so we can return rate info */
    348       1.1   dyoung 		p2 = (struct wi_scan_p2_hdr *)wreq.wi_val;
    349       1.1   dyoung 		res = (void *)&p2[1];
    350       1.1   dyoung 		i = 0;
    351       1.1   dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    352       1.1   dyoung 			if ((caddr_t)(res + 1) > (caddr_t)(&wreq + 1))
    353       1.1   dyoung 				break;
    354       1.1   dyoung 			res->wi_chan = ieee80211_chan2ieee(ic, ni->ni_chan);
    355       1.1   dyoung 			res->wi_noise = 0;
    356       1.7   dyoung 			res->wi_signal = (*ic->ic_node_getrssi)(ic, ni);
    357       1.1   dyoung 			IEEE80211_ADDR_COPY(res->wi_bssid, ni->ni_bssid);
    358       1.1   dyoung 			res->wi_interval = ni->ni_intval;
    359       1.1   dyoung 			res->wi_capinfo = ni->ni_capinfo;
    360       1.1   dyoung 			res->wi_ssid_len = ni->ni_esslen;
    361       1.1   dyoung 			memcpy(res->wi_ssid, ni->ni_essid, IEEE80211_NWID_LEN);
    362       1.1   dyoung 			/* NB: assumes wi_srates holds <= ni->ni_rates */
    363       1.1   dyoung 			memcpy(res->wi_srates, ni->ni_rates.rs_rates,
    364       1.1   dyoung 				sizeof(res->wi_srates));
    365       1.1   dyoung 			if (ni->ni_rates.rs_nrates < 10)
    366       1.1   dyoung 				res->wi_srates[ni->ni_rates.rs_nrates] = 0;
    367       1.1   dyoung 			res->wi_rate = ni->ni_rates.rs_rates[ni->ni_txrate];
    368       1.1   dyoung 			res->wi_rsvd = 0;
    369       1.1   dyoung 			res++, i++;
    370       1.1   dyoung 		}
    371       1.1   dyoung 		p2->wi_rsvd = 0;
    372       1.1   dyoung 		p2->wi_reason = i;
    373       1.1   dyoung 		wreq.wi_len = (sizeof(*p2) + sizeof(*res) * i) / 2;
    374       1.1   dyoung 		break;
    375       1.4   dyoung #endif /* 0 */
    376       1.4   dyoung #ifdef WICACHE
    377       1.1   dyoung 	case WI_RID_READ_CACHE:
    378       1.1   dyoung 		i = 0;
    379       1.1   dyoung 		TAILQ_FOREACH(ni, &ic->ic_node, ni_list) {
    380       1.1   dyoung 			if (i == (WI_MAX_DATALEN/sizeof(struct wi_sigcache))-1)
    381       1.1   dyoung 				break;
    382       1.1   dyoung 			IEEE80211_ADDR_COPY(wsc.macsrc, ni->ni_macaddr);
    383       1.1   dyoung 			memset(&wsc.ipsrc, 0, sizeof(wsc.ipsrc));
    384       1.7   dyoung 			wsc.signal = (*ic->ic_node_getrssi)(ic, ni);
    385       1.1   dyoung 			wsc.noise = 0;
    386       1.1   dyoung 			wsc.quality = 0;
    387       1.1   dyoung 			memcpy((caddr_t)wreq.wi_val + sizeof(wsc) * i,
    388       1.1   dyoung 			    &wsc, sizeof(wsc));
    389       1.1   dyoung 			i++;
    390       1.1   dyoung 		}
    391       1.1   dyoung 		wreq.wi_len = sizeof(wsc) * i / 2;
    392       1.1   dyoung 		break;
    393       1.4   dyoung #endif /* WICACHE */
    394       1.1   dyoung 	case WI_RID_SCAN_APS:
    395       1.1   dyoung 		error = EINVAL;
    396       1.1   dyoung 		break;
    397       1.1   dyoung 	default:
    398       1.1   dyoung 		error = EINVAL;
    399       1.1   dyoung 		break;
    400       1.1   dyoung 	}
    401       1.1   dyoung 	if (error == 0) {
    402       1.1   dyoung 		wreq.wi_len++;
    403       1.1   dyoung 		error = copyout(&wreq, ifr->ifr_data, sizeof(wreq));
    404       1.1   dyoung 	}
    405       1.1   dyoung 	return error;
    406       1.1   dyoung }
    407       1.1   dyoung 
    408       1.1   dyoung static int
    409       1.1   dyoung findrate(struct ieee80211com *ic, enum ieee80211_phymode mode, int rate)
    410       1.1   dyoung {
    411       1.1   dyoung #define	IEEERATE(_ic,_m,_i) \
    412       1.1   dyoung 	((_ic)->ic_sup_rates[_m].rs_rates[_i] & IEEE80211_RATE_VAL)
    413       1.1   dyoung 	int i, nrates = ic->ic_sup_rates[mode].rs_nrates;
    414       1.1   dyoung 	for (i = 0; i < nrates; i++)
    415       1.1   dyoung 		if (IEEERATE(ic, mode, i) == rate)
    416       1.1   dyoung 			return i;
    417       1.1   dyoung 	return -1;
    418       1.1   dyoung #undef IEEERATE
    419       1.1   dyoung }
    420       1.1   dyoung 
    421       1.7   dyoung /*
    422       1.7   dyoung  * Prepare to do a user-initiated scan for AP's.  If no
    423       1.7   dyoung  * current/default channel is setup or the current channel
    424       1.7   dyoung  * is invalid then pick the first available channel from
    425       1.7   dyoung  * the active list as the place to start the scan.
    426       1.7   dyoung  */
    427       1.7   dyoung static int
    428       1.7   dyoung ieee80211_setupscan(struct ieee80211com *ic)
    429       1.7   dyoung {
    430       1.7   dyoung 	u_char *chanlist = ic->ic_chan_active;
    431       1.7   dyoung 	int i;
    432       1.7   dyoung 
    433       1.7   dyoung 	if (ic->ic_ibss_chan == NULL ||
    434       1.7   dyoung 	    isclr(chanlist, ieee80211_chan2ieee(ic, ic->ic_ibss_chan))) {
    435       1.7   dyoung 		for (i = 0; i <= IEEE80211_CHAN_MAX; i++)
    436       1.7   dyoung 			if (isset(chanlist, i)) {
    437       1.7   dyoung 				ic->ic_ibss_chan = &ic->ic_channels[i];
    438       1.7   dyoung 				goto found;
    439       1.7   dyoung 			}
    440       1.7   dyoung 		return EINVAL;			/* no active channels */
    441       1.7   dyoung found:
    442       1.7   dyoung 		;
    443       1.7   dyoung 	}
    444       1.7   dyoung 	if (ic->ic_bss->ni_chan == IEEE80211_CHAN_ANYC ||
    445       1.7   dyoung 	    isclr(chanlist, ieee80211_chan2ieee(ic, ic->ic_bss->ni_chan)))
    446       1.7   dyoung 		ic->ic_bss->ni_chan = ic->ic_ibss_chan;
    447       1.7   dyoung 	/*
    448       1.7   dyoung 	 * XXX don't permit a scan to be started unless we
    449       1.7   dyoung 	 * know the device is ready.  For the moment this means
    450       1.7   dyoung 	 * the device is marked up as this is the required to
    451       1.7   dyoung 	 * initialize the hardware.  It would be better to permit
    452       1.7   dyoung 	 * scanning prior to being up but that'll require some
    453       1.7   dyoung 	 * changes to the infrastructure.
    454       1.7   dyoung 	 */
    455       1.7   dyoung 	return (ic->ic_if.if_flags & IFF_UP) ? 0 : ENETRESET;
    456       1.7   dyoung }
    457       1.7   dyoung 
    458       1.1   dyoung int
    459       1.1   dyoung ieee80211_cfgset(struct ifnet *ifp, u_long cmd, caddr_t data)
    460       1.1   dyoung {
    461       1.1   dyoung 	struct ieee80211com *ic = (void *)ifp;
    462       1.1   dyoung 	int i, j, len, error, rate;
    463       1.1   dyoung 	struct ifreq *ifr = (struct ifreq *)data;
    464       1.1   dyoung 	struct wi_ltv_keys *keys;
    465       1.1   dyoung 	struct wi_req wreq;
    466       1.1   dyoung 	u_char chanlist[roundup(IEEE80211_CHAN_MAX, NBBY)];
    467       1.1   dyoung 
    468       1.1   dyoung 	error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
    469       1.1   dyoung 	if (error)
    470       1.1   dyoung 		return error;
    471       1.1   dyoung 	len = wreq.wi_len ? (wreq.wi_len - 1) * 2 : 0;
    472       1.1   dyoung 	switch (wreq.wi_type) {
    473       1.1   dyoung 	case WI_RID_SERIALNO:
    474       1.1   dyoung 	case WI_RID_NODENAME:
    475       1.1   dyoung 		return EPERM;
    476       1.1   dyoung 	case WI_RID_CURRENT_SSID:
    477       1.1   dyoung 		return EPERM;
    478       1.1   dyoung 	case WI_RID_OWN_SSID:
    479       1.1   dyoung 	case WI_RID_DESIRED_SSID:
    480       1.1   dyoung 		if (le16toh(wreq.wi_val[0]) * 2 > len ||
    481       1.1   dyoung 		    le16toh(wreq.wi_val[0]) > IEEE80211_NWID_LEN) {
    482       1.1   dyoung 			error = ENOSPC;
    483       1.1   dyoung 			break;
    484       1.1   dyoung 		}
    485       1.1   dyoung 		memset(ic->ic_des_essid, 0, sizeof(ic->ic_des_essid));
    486       1.1   dyoung 		ic->ic_des_esslen = le16toh(wreq.wi_val[0]) * 2;
    487       1.1   dyoung 		memcpy(ic->ic_des_essid, &wreq.wi_val[1], ic->ic_des_esslen);
    488       1.1   dyoung 		error = ENETRESET;
    489       1.1   dyoung 		break;
    490       1.1   dyoung 	case WI_RID_CURRENT_BSSID:
    491       1.1   dyoung 		return EPERM;
    492       1.1   dyoung 	case WI_RID_OWN_CHNL:
    493       1.1   dyoung 		if (len != 2)
    494       1.1   dyoung 			return EINVAL;
    495       1.1   dyoung 		i = le16toh(wreq.wi_val[0]);
    496       1.1   dyoung 		if (i < 0 ||
    497       1.1   dyoung 		    i > IEEE80211_CHAN_MAX ||
    498       1.1   dyoung 		    isclr(ic->ic_chan_active, i))
    499       1.1   dyoung 			return EINVAL;
    500       1.1   dyoung 		ic->ic_ibss_chan = &ic->ic_channels[i];
    501       1.1   dyoung 		if (ic->ic_flags & IEEE80211_F_SIBSS)
    502       1.1   dyoung 			error = ENETRESET;
    503       1.1   dyoung 		break;
    504       1.1   dyoung 	case WI_RID_CURRENT_CHAN:
    505       1.1   dyoung 		return EPERM;
    506       1.1   dyoung 	case WI_RID_COMMS_QUALITY:
    507       1.1   dyoung 		return EPERM;
    508       1.1   dyoung 	case WI_RID_PROMISC:
    509       1.1   dyoung 		if (len != 2)
    510       1.1   dyoung 			return EINVAL;
    511       1.1   dyoung 		if (ifp->if_flags & IFF_PROMISC) {
    512       1.1   dyoung 			if (wreq.wi_val[0] == 0) {
    513       1.1   dyoung 				ifp->if_flags &= ~IFF_PROMISC;
    514       1.1   dyoung 				error = ENETRESET;
    515       1.1   dyoung 			}
    516       1.1   dyoung 		} else {
    517       1.1   dyoung 			if (wreq.wi_val[0] != 0) {
    518       1.1   dyoung 				ifp->if_flags |= IFF_PROMISC;
    519       1.1   dyoung 				error = ENETRESET;
    520       1.1   dyoung 			}
    521       1.1   dyoung 		}
    522       1.1   dyoung 		break;
    523       1.1   dyoung 	case WI_RID_PORTTYPE:
    524       1.1   dyoung 		if (len != 2)
    525       1.1   dyoung 			return EINVAL;
    526       1.1   dyoung 		switch (le16toh(wreq.wi_val[0])) {
    527       1.1   dyoung 		case IEEE80211_M_STA:
    528       1.1   dyoung 			break;
    529       1.1   dyoung 		case IEEE80211_M_IBSS:
    530       1.1   dyoung 			if (!(ic->ic_caps & IEEE80211_C_IBSS))
    531       1.1   dyoung 				return EINVAL;
    532       1.1   dyoung 			break;
    533       1.1   dyoung 		case IEEE80211_M_AHDEMO:
    534       1.1   dyoung 			if (ic->ic_phytype != IEEE80211_T_DS ||
    535       1.1   dyoung 			    !(ic->ic_caps & IEEE80211_C_AHDEMO))
    536       1.1   dyoung 				return EINVAL;
    537       1.1   dyoung 			break;
    538       1.1   dyoung 		case IEEE80211_M_HOSTAP:
    539       1.1   dyoung 			if (!(ic->ic_caps & IEEE80211_C_HOSTAP))
    540       1.1   dyoung 				return EINVAL;
    541       1.1   dyoung 			break;
    542       1.1   dyoung 		default:
    543       1.1   dyoung 			return EINVAL;
    544       1.1   dyoung 		}
    545       1.1   dyoung 		if (le16toh(wreq.wi_val[0]) != ic->ic_opmode) {
    546       1.1   dyoung 			ic->ic_opmode = le16toh(wreq.wi_val[0]);
    547       1.1   dyoung 			error = ENETRESET;
    548       1.1   dyoung 		}
    549       1.1   dyoung 		break;
    550       1.1   dyoung #if 0
    551       1.1   dyoung 	case WI_RID_MAC_NODE:
    552       1.1   dyoung 		if (len != IEEE80211_ADDR_LEN)
    553       1.1   dyoung 			return EINVAL;
    554       1.1   dyoung 		IEEE80211_ADDR_COPY(LLADDR(ifp->if_sadl), wreq.wi_val);
    555       1.1   dyoung 		/* if_init will copy lladdr into ic_myaddr */
    556       1.1   dyoung 		error = ENETRESET;
    557       1.1   dyoung 		break;
    558       1.1   dyoung #endif
    559       1.1   dyoung 	case WI_RID_TX_RATE:
    560       1.1   dyoung 		if (len != 2)
    561       1.1   dyoung 			return EINVAL;
    562       1.1   dyoung 		if (wreq.wi_val[0] == 0) {
    563       1.1   dyoung 			/* auto */
    564       1.1   dyoung 			ic->ic_fixed_rate = -1;
    565       1.1   dyoung 			break;
    566       1.1   dyoung 		}
    567       1.1   dyoung 		rate = 2 * le16toh(wreq.wi_val[0]);
    568       1.1   dyoung 		if (ic->ic_curmode == IEEE80211_MODE_AUTO) {
    569       1.1   dyoung 			/*
    570       1.1   dyoung 			 * In autoselect mode search for the rate.  We take
    571       1.1   dyoung 			 * the first instance which may not be right, but we
    572       1.1   dyoung 			 * are limited by the interface.  Note that we also
    573       1.1   dyoung 			 * lock the mode to insure the rate is meaningful
    574       1.1   dyoung 			 * when it is used.
    575       1.1   dyoung 			 */
    576       1.1   dyoung 			for (j = IEEE80211_MODE_11A;
    577       1.1   dyoung 			     j < IEEE80211_MODE_MAX; j++) {
    578       1.1   dyoung 				if ((ic->ic_modecaps & (1<<j)) == 0)
    579       1.1   dyoung 					continue;
    580       1.1   dyoung 				i = findrate(ic, j, rate);
    581       1.1   dyoung 				if (i != -1) {
    582       1.1   dyoung 					/* lock mode too */
    583       1.1   dyoung 					ic->ic_curmode = j;
    584       1.1   dyoung 					goto setrate;
    585       1.1   dyoung 				}
    586       1.1   dyoung 			}
    587       1.1   dyoung 		} else {
    588       1.1   dyoung 			i = findrate(ic, ic->ic_curmode, rate);
    589       1.1   dyoung 			if (i != -1)
    590       1.1   dyoung 				goto setrate;
    591       1.1   dyoung 		}
    592       1.1   dyoung 		return EINVAL;
    593       1.1   dyoung 	setrate:
    594       1.1   dyoung 		ic->ic_fixed_rate = i;
    595       1.1   dyoung 		error = ENETRESET;
    596       1.1   dyoung 		break;
    597       1.1   dyoung 	case WI_RID_CUR_TX_RATE:
    598       1.1   dyoung 		return EPERM;
    599       1.6   dyoung 	case WI_RID_FRAG_THRESH:
    600       1.6   dyoung 		if (len != 2)
    601       1.6   dyoung 			return EINVAL;
    602       1.6   dyoung 		ic->ic_fragthreshold = le16toh(wreq.wi_val[0]);
    603       1.6   dyoung 		error = ENETRESET;
    604       1.6   dyoung 		break;
    605       1.1   dyoung 	case WI_RID_RTS_THRESH:
    606       1.1   dyoung 		if (len != 2)
    607       1.1   dyoung 			return EINVAL;
    608       1.6   dyoung 		ic->ic_rtsthreshold = le16toh(wreq.wi_val[0]);
    609       1.6   dyoung 		error = ENETRESET;
    610       1.1   dyoung 		break;
    611       1.1   dyoung 	case WI_RID_CREATE_IBSS:
    612       1.1   dyoung 		if (len != 2)
    613       1.1   dyoung 			return EINVAL;
    614       1.1   dyoung 		if (wreq.wi_val[0] != 0) {
    615       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_IBSS) == 0)
    616       1.1   dyoung 				return EINVAL;
    617       1.1   dyoung 			if ((ic->ic_flags & IEEE80211_F_IBSSON) == 0) {
    618       1.1   dyoung 				ic->ic_flags |= IEEE80211_F_IBSSON;
    619       1.1   dyoung 				if (ic->ic_opmode == IEEE80211_M_IBSS &&
    620       1.1   dyoung 				    ic->ic_state == IEEE80211_S_SCAN)
    621       1.1   dyoung 					error = ENETRESET;
    622       1.1   dyoung 			}
    623       1.1   dyoung 		} else {
    624       1.1   dyoung 			if (ic->ic_flags & IEEE80211_F_IBSSON) {
    625       1.1   dyoung 				ic->ic_flags &= ~IEEE80211_F_IBSSON;
    626       1.1   dyoung 				if (ic->ic_flags & IEEE80211_F_SIBSS) {
    627       1.1   dyoung 					ic->ic_flags &= ~IEEE80211_F_SIBSS;
    628       1.1   dyoung 					error = ENETRESET;
    629       1.1   dyoung 				}
    630       1.1   dyoung 			}
    631       1.1   dyoung 		}
    632       1.1   dyoung 		break;
    633       1.1   dyoung 	case WI_RID_MICROWAVE_OVEN:
    634       1.1   dyoung 		if (len != 2)
    635       1.1   dyoung 			return EINVAL;
    636       1.1   dyoung 		if (wreq.wi_val[0] != 0)
    637       1.1   dyoung 			return EINVAL;		/* not supported */
    638       1.1   dyoung 		break;
    639       1.1   dyoung 	case WI_RID_ROAMING_MODE:
    640       1.1   dyoung 		if (len != 2)
    641       1.1   dyoung 			return EINVAL;
    642       1.1   dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    643       1.1   dyoung 			return EINVAL;		/* not supported */
    644       1.1   dyoung 		break;
    645       1.1   dyoung 	case WI_RID_SYSTEM_SCALE:
    646       1.1   dyoung 		if (len != 2)
    647       1.1   dyoung 			return EINVAL;
    648       1.1   dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    649       1.1   dyoung 			return EINVAL;		/* not supported */
    650       1.1   dyoung 		break;
    651       1.1   dyoung 	case WI_RID_PM_ENABLED:
    652       1.1   dyoung 		if (len != 2)
    653       1.1   dyoung 			return EINVAL;
    654       1.1   dyoung 		if (wreq.wi_val[0] != 0) {
    655       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
    656       1.1   dyoung 				return EINVAL;
    657       1.1   dyoung 			if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
    658       1.1   dyoung 				ic->ic_flags |= IEEE80211_F_PMGTON;
    659       1.1   dyoung 				error = ENETRESET;
    660       1.1   dyoung 			}
    661       1.1   dyoung 		} else {
    662       1.1   dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON) {
    663       1.1   dyoung 				ic->ic_flags &= ~IEEE80211_F_PMGTON;
    664       1.1   dyoung 				error = ENETRESET;
    665       1.1   dyoung 			}
    666       1.1   dyoung 		}
    667       1.1   dyoung 		break;
    668       1.1   dyoung 	case WI_RID_MAX_SLEEP:
    669       1.1   dyoung 		if (len != 2)
    670       1.1   dyoung 			return EINVAL;
    671       1.1   dyoung 		ic->ic_lintval = le16toh(wreq.wi_val[0]);
    672       1.1   dyoung 		if (ic->ic_flags & IEEE80211_F_PMGTON)
    673       1.1   dyoung 			error = ENETRESET;
    674       1.1   dyoung 		break;
    675       1.1   dyoung 	case WI_RID_CUR_BEACON_INT:
    676       1.1   dyoung 		return EPERM;
    677       1.1   dyoung 	case WI_RID_WEP_AVAIL:
    678       1.1   dyoung 		return EPERM;
    679       1.1   dyoung 	case WI_RID_CNFAUTHMODE:
    680       1.1   dyoung 		if (len != 2)
    681       1.1   dyoung 			return EINVAL;
    682       1.1   dyoung 		if (le16toh(wreq.wi_val[0]) != 1)
    683       1.1   dyoung 			return EINVAL;		/* TODO: shared key auth */
    684       1.1   dyoung 		break;
    685       1.1   dyoung 	case WI_RID_ENCRYPTION:
    686       1.1   dyoung 		if (len != 2)
    687       1.1   dyoung 			return EINVAL;
    688       1.1   dyoung 		if (wreq.wi_val[0] != 0) {
    689       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    690       1.1   dyoung 				return EINVAL;
    691      1.16  mycroft 			if ((ic->ic_flags & IEEE80211_F_PRIVACY) == 0) {
    692      1.16  mycroft 				ic->ic_flags |= IEEE80211_F_PRIVACY;
    693       1.1   dyoung 				error = ENETRESET;
    694       1.1   dyoung 			}
    695       1.1   dyoung 		} else {
    696      1.16  mycroft 			if (ic->ic_flags & IEEE80211_F_PRIVACY) {
    697      1.16  mycroft 				ic->ic_flags &= ~IEEE80211_F_PRIVACY;
    698       1.1   dyoung 				error = ENETRESET;
    699       1.1   dyoung 			}
    700       1.1   dyoung 		}
    701       1.1   dyoung 		break;
    702       1.1   dyoung 	case WI_RID_TX_CRYPT_KEY:
    703       1.1   dyoung 		if (len != 2)
    704       1.1   dyoung 			return EINVAL;
    705       1.1   dyoung 		i = le16toh(wreq.wi_val[0]);
    706       1.1   dyoung 		if (i >= IEEE80211_WEP_NKID)
    707       1.1   dyoung 			return EINVAL;
    708       1.1   dyoung 		ic->ic_wep_txkey = i;
    709       1.1   dyoung 		break;
    710       1.1   dyoung 	case WI_RID_DEFLT_CRYPT_KEYS:
    711       1.1   dyoung 		if (len != sizeof(struct wi_ltv_keys))
    712       1.1   dyoung 			return EINVAL;
    713       1.1   dyoung 		keys = (struct wi_ltv_keys *)&wreq;
    714       1.1   dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    715       1.1   dyoung 			len = le16toh(keys->wi_keys[i].wi_keylen);
    716       1.1   dyoung 			if (len != 0 && len < IEEE80211_WEP_KEYLEN)
    717       1.1   dyoung 				return EINVAL;
    718       1.1   dyoung 			if (len > sizeof(ic->ic_nw_keys[i].wk_key))
    719       1.1   dyoung 				return EINVAL;
    720       1.1   dyoung 		}
    721       1.1   dyoung 		memset(ic->ic_nw_keys, 0, sizeof(ic->ic_nw_keys));
    722       1.1   dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
    723       1.1   dyoung 			len = le16toh(keys->wi_keys[i].wi_keylen);
    724       1.1   dyoung 			ic->ic_nw_keys[i].wk_len = len;
    725       1.1   dyoung 			memcpy(ic->ic_nw_keys[i].wk_key,
    726       1.1   dyoung 			    keys->wi_keys[i].wi_keydat, len);
    727       1.1   dyoung 		}
    728       1.1   dyoung 		error = ENETRESET;
    729       1.1   dyoung 		break;
    730       1.1   dyoung 	case WI_RID_MAX_DATALEN:
    731       1.1   dyoung 		if (len != 2)
    732       1.1   dyoung 			return EINVAL;
    733       1.1   dyoung 		len = le16toh(wreq.wi_val[0]);
    734       1.1   dyoung 		if (len < 350 /* ? */ || len > IEEE80211_MAX_LEN)
    735       1.1   dyoung 			return EINVAL;
    736       1.1   dyoung 		if (len != IEEE80211_MAX_LEN)
    737       1.1   dyoung 			return EINVAL;		/* TODO: fragment */
    738       1.1   dyoung 		ic->ic_fragthreshold = len;
    739       1.1   dyoung 		error = ENETRESET;
    740       1.1   dyoung 		break;
    741       1.1   dyoung 	case WI_RID_IFACE_STATS:
    742       1.1   dyoung 		error = EPERM;
    743       1.1   dyoung 		break;
    744       1.1   dyoung 	case WI_RID_SCAN_REQ:			/* XXX wicontrol */
    745       1.1   dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
    746       1.1   dyoung 			break;
    747       1.7   dyoung 		error = ieee80211_setupscan(ic);
    748       1.7   dyoung 		if (error == 0)
    749       1.7   dyoung 			error = ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
    750       1.1   dyoung 		break;
    751       1.1   dyoung 	case WI_RID_SCAN_APS:
    752       1.1   dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
    753       1.1   dyoung 			break;
    754       1.1   dyoung 		len--;			/* XXX: tx rate? */
    755       1.1   dyoung 		/* FALLTHRU */
    756       1.1   dyoung 	case WI_RID_CHANNEL_LIST:
    757       1.1   dyoung 		memset(chanlist, 0, sizeof(chanlist));
    758       1.1   dyoung 		/*
    759       1.1   dyoung 		 * Since channel 0 is not available for DS, channel 1
    760       1.1   dyoung 		 * is assigned to LSB on WaveLAN.
    761       1.1   dyoung 		 */
    762       1.1   dyoung 		if (ic->ic_phytype == IEEE80211_T_DS)
    763       1.1   dyoung 			i = 1;
    764       1.1   dyoung 		else
    765       1.1   dyoung 			i = 0;
    766       1.1   dyoung 		for (j = 0; i <= IEEE80211_CHAN_MAX; i++, j++) {
    767       1.1   dyoung 			if ((j / 8) >= len)
    768       1.1   dyoung 				break;
    769       1.1   dyoung 			if (isclr((u_int8_t *)wreq.wi_val, j))
    770       1.1   dyoung 				continue;
    771       1.1   dyoung 			if (isclr(ic->ic_chan_active, i)) {
    772       1.1   dyoung 				if (wreq.wi_type != WI_RID_CHANNEL_LIST)
    773       1.1   dyoung 					continue;
    774       1.1   dyoung 				if (isclr(ic->ic_chan_avail, i))
    775       1.1   dyoung 					return EPERM;
    776       1.1   dyoung 			}
    777       1.1   dyoung 			setbit(chanlist, i);
    778       1.1   dyoung 		}
    779       1.1   dyoung 		memcpy(ic->ic_chan_active, chanlist,
    780       1.1   dyoung 		    sizeof(ic->ic_chan_active));
    781       1.7   dyoung 		error = ieee80211_setupscan(ic);
    782       1.7   dyoung 		if (wreq.wi_type == WI_RID_CHANNEL_LIST) {
    783       1.7   dyoung 			/* NB: ignore error from ieee80211_setupscan */
    784       1.1   dyoung 			error = ENETRESET;
    785       1.7   dyoung 		} else if (error == 0)
    786       1.1   dyoung 			error = ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
    787       1.1   dyoung 		break;
    788       1.1   dyoung 	default:
    789       1.1   dyoung 		error = EINVAL;
    790       1.1   dyoung 		break;
    791       1.1   dyoung 	}
    792       1.1   dyoung 	return error;
    793       1.1   dyoung }
    794       1.1   dyoung 
    795       1.2   dyoung #ifdef __FreeBSD__
    796       1.1   dyoung int
    797       1.1   dyoung ieee80211_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data)
    798       1.1   dyoung {
    799       1.1   dyoung 	struct ieee80211com *ic = (void *)ifp;
    800       1.1   dyoung 	int error = 0;
    801       1.1   dyoung 	u_int kid, len;
    802       1.1   dyoung 	struct ieee80211req *ireq;
    803       1.7   dyoung 	struct ifreq *ifr;
    804       1.1   dyoung 	u_int8_t tmpkey[IEEE80211_KEYBUF_SIZE];
    805       1.1   dyoung 	char tmpssid[IEEE80211_NWID_LEN];
    806       1.1   dyoung 	struct ieee80211_channel *chan;
    807      1.10   dyoung 	struct ifaddr *ifa;			/* XXX */
    808       1.1   dyoung 
    809       1.1   dyoung 	switch (cmd) {
    810       1.1   dyoung 	case SIOCSIFMEDIA:
    811       1.1   dyoung 	case SIOCGIFMEDIA:
    812       1.1   dyoung 		error = ifmedia_ioctl(ifp, (struct ifreq *) data,
    813       1.1   dyoung 				&ic->ic_media, cmd);
    814       1.1   dyoung 		break;
    815       1.1   dyoung 	case SIOCG80211:
    816       1.1   dyoung 		ireq = (struct ieee80211req *) data;
    817       1.1   dyoung 		switch (ireq->i_type) {
    818       1.1   dyoung 		case IEEE80211_IOC_SSID:
    819       1.1   dyoung 			switch (ic->ic_state) {
    820       1.1   dyoung 			case IEEE80211_S_INIT:
    821       1.1   dyoung 			case IEEE80211_S_SCAN:
    822       1.1   dyoung 				ireq->i_len = ic->ic_des_esslen;
    823       1.1   dyoung 				memcpy(tmpssid, ic->ic_des_essid, ireq->i_len);
    824       1.1   dyoung 				break;
    825       1.1   dyoung 			default:
    826       1.1   dyoung 				ireq->i_len = ic->ic_bss->ni_esslen;
    827       1.1   dyoung 				memcpy(tmpssid, ic->ic_bss->ni_essid,
    828       1.1   dyoung 					ireq->i_len);
    829       1.1   dyoung 				break;
    830       1.1   dyoung 			}
    831       1.1   dyoung 			error = copyout(tmpssid, ireq->i_data, ireq->i_len);
    832       1.1   dyoung 			break;
    833       1.1   dyoung 		case IEEE80211_IOC_NUMSSIDS:
    834       1.1   dyoung 			ireq->i_val = 1;
    835       1.1   dyoung 			break;
    836       1.1   dyoung 		case IEEE80211_IOC_WEP:
    837       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    838  1.17.2.1     kent 				ireq->i_val = IEEE80211_WEP_NOSUP;
    839       1.1   dyoung 			} else {
    840      1.16  mycroft 				if (ic->ic_flags & IEEE80211_F_PRIVACY) {
    841       1.1   dyoung 					ireq->i_val =
    842       1.1   dyoung 					    IEEE80211_WEP_MIXED;
    843       1.1   dyoung 				} else {
    844       1.1   dyoung 					ireq->i_val =
    845       1.1   dyoung 					    IEEE80211_WEP_OFF;
    846       1.1   dyoung 				}
    847       1.1   dyoung 			}
    848       1.1   dyoung 			break;
    849       1.1   dyoung 		case IEEE80211_IOC_WEPKEY:
    850       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    851       1.1   dyoung 				error = EINVAL;
    852       1.1   dyoung 				break;
    853       1.1   dyoung 			}
    854       1.1   dyoung 			kid = (u_int) ireq->i_val;
    855       1.1   dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    856       1.1   dyoung 				error = EINVAL;
    857       1.1   dyoung 				break;
    858       1.1   dyoung 			}
    859       1.1   dyoung 			len = (u_int) ic->ic_nw_keys[kid].wk_len;
    860       1.1   dyoung 			/* NB: only root can read WEP keys */
    861       1.7   dyoung 			if (suser(curthread) == 0) {
    862       1.1   dyoung 				bcopy(ic->ic_nw_keys[kid].wk_key, tmpkey, len);
    863       1.1   dyoung 			} else {
    864       1.1   dyoung 				bzero(tmpkey, len);
    865       1.1   dyoung 			}
    866       1.1   dyoung 			ireq->i_len = len;
    867       1.1   dyoung 			error = copyout(tmpkey, ireq->i_data, len);
    868       1.1   dyoung 			break;
    869       1.1   dyoung 		case IEEE80211_IOC_NUMWEPKEYS:
    870       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    871       1.1   dyoung 				error = EINVAL;
    872       1.1   dyoung 			else
    873       1.1   dyoung 				ireq->i_val = IEEE80211_WEP_NKID;
    874       1.1   dyoung 			break;
    875       1.1   dyoung 		case IEEE80211_IOC_WEPTXKEY:
    876       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0)
    877       1.1   dyoung 				error = EINVAL;
    878       1.1   dyoung 			else
    879       1.1   dyoung 				ireq->i_val = ic->ic_wep_txkey;
    880       1.1   dyoung 			break;
    881       1.1   dyoung 		case IEEE80211_IOC_AUTHMODE:
    882       1.1   dyoung 			ireq->i_val = IEEE80211_AUTH_OPEN;
    883       1.1   dyoung 			break;
    884       1.1   dyoung 		case IEEE80211_IOC_CHANNEL:
    885       1.1   dyoung 			switch (ic->ic_state) {
    886       1.1   dyoung 			case IEEE80211_S_INIT:
    887       1.1   dyoung 			case IEEE80211_S_SCAN:
    888       1.1   dyoung 				if (ic->ic_opmode == IEEE80211_M_STA)
    889       1.1   dyoung 					chan = ic->ic_des_chan;
    890       1.1   dyoung 				else
    891       1.1   dyoung 					chan = ic->ic_ibss_chan;
    892       1.1   dyoung 				break;
    893       1.1   dyoung 			default:
    894       1.1   dyoung 				chan = ic->ic_bss->ni_chan;
    895       1.1   dyoung 				break;
    896       1.1   dyoung 			}
    897       1.1   dyoung 			ireq->i_val = ieee80211_chan2ieee(ic, chan);
    898       1.1   dyoung 			break;
    899       1.1   dyoung 		case IEEE80211_IOC_POWERSAVE:
    900       1.1   dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON)
    901       1.1   dyoung 				ireq->i_val = IEEE80211_POWERSAVE_ON;
    902       1.1   dyoung 			else
    903       1.1   dyoung 				ireq->i_val = IEEE80211_POWERSAVE_OFF;
    904       1.1   dyoung 			break;
    905       1.1   dyoung 		case IEEE80211_IOC_POWERSAVESLEEP:
    906       1.1   dyoung 			ireq->i_val = ic->ic_lintval;
    907       1.1   dyoung 			break;
    908       1.7   dyoung 		case IEEE80211_IOC_RTSTHRESHOLD:
    909       1.1   dyoung 			ireq->i_val = ic->ic_rtsthreshold;
    910       1.1   dyoung 			break;
    911      1.10   dyoung 		case IEEE80211_IOC_PROTMODE:
    912      1.10   dyoung 			ireq->i_val = ic->ic_protmode;
    913      1.10   dyoung 			break;
    914      1.10   dyoung 		case IEEE80211_IOC_TXPOWER:
    915      1.10   dyoung 			if ((ic->ic_caps & IEEE80211_C_TXPMGT) == 0)
    916      1.10   dyoung 				error = EINVAL;
    917      1.10   dyoung 			else
    918      1.10   dyoung 				ireq->i_val = ic->ic_txpower;
    919      1.10   dyoung 			break;
    920       1.1   dyoung 		default:
    921       1.1   dyoung 			error = EINVAL;
    922      1.10   dyoung 			break;
    923       1.1   dyoung 		}
    924       1.1   dyoung 		break;
    925       1.1   dyoung 	case SIOCS80211:
    926       1.4   dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
    927       1.1   dyoung 		if (error)
    928       1.1   dyoung 			break;
    929       1.1   dyoung 		ireq = (struct ieee80211req *) data;
    930       1.1   dyoung 		switch (ireq->i_type) {
    931       1.1   dyoung 		case IEEE80211_IOC_SSID:
    932       1.1   dyoung 			if (ireq->i_val != 0 ||
    933       1.1   dyoung 			    ireq->i_len > IEEE80211_NWID_LEN) {
    934       1.1   dyoung 				error = EINVAL;
    935       1.1   dyoung 				break;
    936       1.1   dyoung 			}
    937       1.1   dyoung 			error = copyin(ireq->i_data, tmpssid, ireq->i_len);
    938       1.1   dyoung 			if (error)
    939       1.1   dyoung 				break;
    940       1.1   dyoung 			memset(ic->ic_des_essid, 0, IEEE80211_NWID_LEN);
    941       1.1   dyoung 			ic->ic_des_esslen = ireq->i_len;
    942       1.1   dyoung 			memcpy(ic->ic_des_essid, tmpssid, ireq->i_len);
    943       1.1   dyoung 			error = ENETRESET;
    944       1.1   dyoung 			break;
    945       1.1   dyoung 		case IEEE80211_IOC_WEP:
    946       1.1   dyoung 			/*
    947       1.1   dyoung 			 * These cards only support one mode so
    948       1.1   dyoung 			 * we just turn wep on if what ever is
    949       1.1   dyoung 			 * passed in is not OFF.
    950       1.1   dyoung 			 */
    951       1.1   dyoung 			if (ireq->i_val == IEEE80211_WEP_OFF) {
    952      1.16  mycroft 				ic->ic_flags &= ~IEEE80211_F_PRIVACY;
    953       1.1   dyoung 			} else {
    954      1.16  mycroft 				ic->ic_flags |= IEEE80211_F_PRIVACY;
    955       1.1   dyoung 			}
    956       1.1   dyoung 			error = ENETRESET;
    957       1.1   dyoung 			break;
    958       1.1   dyoung 		case IEEE80211_IOC_WEPKEY:
    959       1.1   dyoung 			if ((ic->ic_caps & IEEE80211_C_WEP) == 0) {
    960       1.1   dyoung 				error = EINVAL;
    961       1.1   dyoung 				break;
    962       1.1   dyoung 			}
    963       1.1   dyoung 			kid = (u_int) ireq->i_val;
    964       1.1   dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    965       1.1   dyoung 				error = EINVAL;
    966       1.1   dyoung 				break;
    967  1.17.2.1     kent 			}
    968       1.1   dyoung 			if (ireq->i_len > sizeof(tmpkey)) {
    969       1.1   dyoung 				error = EINVAL;
    970       1.1   dyoung 				break;
    971       1.1   dyoung 			}
    972       1.1   dyoung 			memset(tmpkey, 0, sizeof(tmpkey));
    973       1.1   dyoung 			error = copyin(ireq->i_data, tmpkey, ireq->i_len);
    974       1.1   dyoung 			if (error)
    975       1.1   dyoung 				break;
    976       1.1   dyoung 			memcpy(ic->ic_nw_keys[kid].wk_key, tmpkey,
    977       1.1   dyoung 				sizeof(tmpkey));
    978       1.1   dyoung 			ic->ic_nw_keys[kid].wk_len = ireq->i_len;
    979       1.1   dyoung 			error = ENETRESET;
    980       1.1   dyoung 			break;
    981       1.1   dyoung 		case IEEE80211_IOC_WEPTXKEY:
    982       1.1   dyoung 			kid = (u_int) ireq->i_val;
    983       1.1   dyoung 			if (kid >= IEEE80211_WEP_NKID) {
    984       1.1   dyoung 				error = EINVAL;
    985       1.1   dyoung 				break;
    986       1.1   dyoung 			}
    987       1.1   dyoung 			ic->ic_wep_txkey = kid;
    988       1.1   dyoung 			error = ENETRESET;
    989       1.1   dyoung 			break;
    990       1.1   dyoung #if 0
    991       1.1   dyoung 		case IEEE80211_IOC_AUTHMODE:
    992       1.1   dyoung 			sc->wi_authmode = ireq->i_val;
    993       1.1   dyoung 			break;
    994       1.1   dyoung #endif
    995       1.1   dyoung 		case IEEE80211_IOC_CHANNEL:
    996       1.1   dyoung 			/* XXX 0xffff overflows 16-bit signed */
    997       1.1   dyoung 			if (ireq->i_val == 0 ||
    998       1.1   dyoung 			    ireq->i_val == (int16_t) IEEE80211_CHAN_ANY)
    999       1.1   dyoung 				ic->ic_des_chan = IEEE80211_CHAN_ANYC;
   1000       1.1   dyoung 			else if ((u_int) ireq->i_val > IEEE80211_CHAN_MAX ||
   1001       1.1   dyoung 			    isclr(ic->ic_chan_active, ireq->i_val)) {
   1002       1.1   dyoung 				error = EINVAL;
   1003       1.1   dyoung 				break;
   1004       1.1   dyoung 			} else
   1005       1.1   dyoung 				ic->ic_ibss_chan = ic->ic_des_chan =
   1006       1.1   dyoung 					&ic->ic_channels[ireq->i_val];
   1007       1.1   dyoung 			switch (ic->ic_state) {
   1008       1.1   dyoung 			case IEEE80211_S_INIT:
   1009       1.1   dyoung 			case IEEE80211_S_SCAN:
   1010       1.1   dyoung 				error = ENETRESET;
   1011       1.1   dyoung 				break;
   1012       1.1   dyoung 			default:
   1013       1.1   dyoung 				if (ic->ic_opmode == IEEE80211_M_STA) {
   1014       1.1   dyoung 					if (ic->ic_des_chan != IEEE80211_CHAN_ANYC &&
   1015       1.1   dyoung 					    ic->ic_bss->ni_chan != ic->ic_des_chan)
   1016       1.1   dyoung 						error = ENETRESET;
   1017       1.1   dyoung 				} else {
   1018       1.1   dyoung 					if (ic->ic_bss->ni_chan != ic->ic_ibss_chan)
   1019       1.1   dyoung 						error = ENETRESET;
   1020       1.1   dyoung 				}
   1021       1.1   dyoung 				break;
   1022       1.1   dyoung 			}
   1023       1.1   dyoung 			break;
   1024       1.1   dyoung 		case IEEE80211_IOC_POWERSAVE:
   1025       1.1   dyoung 			switch (ireq->i_val) {
   1026       1.1   dyoung 			case IEEE80211_POWERSAVE_OFF:
   1027       1.1   dyoung 				if (ic->ic_flags & IEEE80211_F_PMGTON) {
   1028       1.1   dyoung 					ic->ic_flags &= ~IEEE80211_F_PMGTON;
   1029       1.1   dyoung 					error = ENETRESET;
   1030       1.1   dyoung 				}
   1031       1.1   dyoung 				break;
   1032       1.1   dyoung 			case IEEE80211_POWERSAVE_ON:
   1033       1.1   dyoung 				if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
   1034       1.1   dyoung 					error = EINVAL;
   1035       1.1   dyoung 				else if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
   1036       1.1   dyoung 					ic->ic_flags |= IEEE80211_F_PMGTON;
   1037       1.1   dyoung 					error = ENETRESET;
   1038       1.1   dyoung 				}
   1039       1.1   dyoung 				break;
   1040       1.1   dyoung 			default:
   1041       1.1   dyoung 				error = EINVAL;
   1042       1.1   dyoung 				break;
   1043       1.1   dyoung 			}
   1044       1.1   dyoung 			break;
   1045       1.1   dyoung 		case IEEE80211_IOC_POWERSAVESLEEP:
   1046       1.1   dyoung 			if (ireq->i_val < 0) {
   1047       1.1   dyoung 				error = EINVAL;
   1048       1.1   dyoung 				break;
   1049       1.1   dyoung 			}
   1050       1.1   dyoung 			ic->ic_lintval = ireq->i_val;
   1051       1.1   dyoung 			error = ENETRESET;
   1052       1.1   dyoung 			break;
   1053       1.7   dyoung 		case IEEE80211_IOC_RTSTHRESHOLD:
   1054       1.1   dyoung 			if (!(IEEE80211_RTS_MIN < ireq->i_val &&
   1055       1.2   dyoung 			      ireq->i_val <= IEEE80211_RTS_MAX + 1)) {
   1056       1.1   dyoung 				error = EINVAL;
   1057       1.1   dyoung 				break;
   1058       1.1   dyoung 			}
   1059       1.1   dyoung 			ic->ic_rtsthreshold = ireq->i_val;
   1060       1.1   dyoung 			error = ENETRESET;
   1061       1.1   dyoung 			break;
   1062      1.10   dyoung 		case IEEE80211_IOC_PROTMODE:
   1063      1.10   dyoung 			if (ireq->i_val > IEEE80211_PROT_RTSCTS) {
   1064      1.10   dyoung 				error = EINVAL;
   1065      1.10   dyoung 				break;
   1066      1.10   dyoung 			}
   1067      1.10   dyoung 			ic->ic_protmode = ireq->i_val;
   1068      1.10   dyoung 			/* NB: if not operating in 11g this can wait */
   1069      1.10   dyoung 			if (ic->ic_curmode == IEEE80211_MODE_11G)
   1070      1.10   dyoung 				error = ENETRESET;
   1071      1.10   dyoung 			break;
   1072      1.10   dyoung 		case IEEE80211_IOC_TXPOWER:
   1073      1.10   dyoung 			if ((ic->ic_caps & IEEE80211_C_TXPMGT) == 0) {
   1074      1.10   dyoung 				error = EINVAL;
   1075      1.10   dyoung 				break;
   1076      1.10   dyoung 			}
   1077      1.10   dyoung 			if (!(IEEE80211_TXPOWER_MIN < ireq->i_val &&
   1078      1.10   dyoung 			      ireq->i_val < IEEE80211_TXPOWER_MAX)) {
   1079      1.10   dyoung 				error = EINVAL;
   1080      1.10   dyoung 				break;
   1081      1.10   dyoung 			}
   1082      1.10   dyoung 			ic->ic_txpower = ireq->i_val;
   1083      1.10   dyoung 			error = ENETRESET;
   1084      1.10   dyoung 			break;
   1085       1.1   dyoung 		default:
   1086       1.1   dyoung 			error = EINVAL;
   1087       1.1   dyoung 			break;
   1088       1.1   dyoung 		}
   1089       1.1   dyoung 		break;
   1090       1.1   dyoung 	case SIOCGIFGENERIC:
   1091       1.1   dyoung 		error = ieee80211_cfgget(ifp, cmd, data);
   1092       1.1   dyoung 		break;
   1093       1.1   dyoung 	case SIOCSIFGENERIC:
   1094       1.4   dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
   1095       1.1   dyoung 		if (error)
   1096       1.1   dyoung 			break;
   1097       1.1   dyoung 		error = ieee80211_cfgset(ifp, cmd, data);
   1098       1.1   dyoung 		break;
   1099       1.1   dyoung 	default:
   1100       1.1   dyoung 		error = ether_ioctl(ifp, cmd, data);
   1101       1.1   dyoung 		break;
   1102       1.1   dyoung 	}
   1103       1.1   dyoung 	return error;
   1104       1.1   dyoung }
   1105       1.2   dyoung #endif /* __FreeBSD__ */
   1106       1.2   dyoung 
   1107       1.2   dyoung #ifdef __NetBSD__
   1108       1.2   dyoung int
   1109       1.2   dyoung ieee80211_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data)
   1110       1.2   dyoung {
   1111       1.2   dyoung 	struct ieee80211com *ic = (void *)ifp;
   1112       1.2   dyoung 	struct ifreq *ifr = (struct ifreq *)data;
   1113      1.17   dyoung 	int i, error = 0, s;
   1114       1.2   dyoung 	struct ieee80211_nwid nwid;
   1115       1.2   dyoung 	struct ieee80211_nwkey *nwkey;
   1116       1.2   dyoung 	struct ieee80211_power *power;
   1117       1.2   dyoung 	struct ieee80211_bssid *bssid;
   1118       1.2   dyoung 	struct ieee80211chanreq *chanreq;
   1119       1.2   dyoung 	struct ieee80211_channel *chan;
   1120       1.2   dyoung 	struct ieee80211_wepkey keys[IEEE80211_WEP_NKID];
   1121       1.2   dyoung 	static const u_int8_t empty_macaddr[IEEE80211_ADDR_LEN] = {
   1122       1.2   dyoung 		0x00, 0x00, 0x00, 0x00, 0x00, 0x00
   1123       1.2   dyoung 	};
   1124       1.2   dyoung 
   1125       1.2   dyoung 	switch (cmd) {
   1126       1.2   dyoung 	case SIOCSIFMEDIA:
   1127       1.2   dyoung 	case SIOCGIFMEDIA:
   1128       1.2   dyoung 		error = ifmedia_ioctl(ifp, ifr, &ic->ic_media, cmd);
   1129       1.2   dyoung 		break;
   1130       1.2   dyoung 	case SIOCS80211NWID:
   1131       1.2   dyoung 		if ((error = copyin(ifr->ifr_data, &nwid, sizeof(nwid))) != 0)
   1132       1.2   dyoung 			break;
   1133       1.2   dyoung 		if (nwid.i_len > IEEE80211_NWID_LEN) {
   1134       1.2   dyoung 			error = EINVAL;
   1135       1.2   dyoung 			break;
   1136       1.2   dyoung 		}
   1137       1.2   dyoung 		memset(ic->ic_des_essid, 0, IEEE80211_NWID_LEN);
   1138       1.2   dyoung 		ic->ic_des_esslen = nwid.i_len;
   1139       1.2   dyoung 		memcpy(ic->ic_des_essid, nwid.i_nwid, nwid.i_len);
   1140       1.2   dyoung 		error = ENETRESET;
   1141       1.2   dyoung 		break;
   1142       1.2   dyoung 	case SIOCG80211NWID:
   1143       1.2   dyoung 		memset(&nwid, 0, sizeof(nwid));
   1144       1.2   dyoung 		switch (ic->ic_state) {
   1145       1.2   dyoung 		case IEEE80211_S_INIT:
   1146       1.2   dyoung 		case IEEE80211_S_SCAN:
   1147       1.2   dyoung 			nwid.i_len = ic->ic_des_esslen;
   1148       1.2   dyoung 			memcpy(nwid.i_nwid, ic->ic_des_essid, nwid.i_len);
   1149       1.2   dyoung 			break;
   1150       1.2   dyoung 		default:
   1151       1.2   dyoung 			nwid.i_len = ic->ic_bss->ni_esslen;
   1152       1.2   dyoung 			memcpy(nwid.i_nwid, ic->ic_bss->ni_essid, nwid.i_len);
   1153       1.2   dyoung 			break;
   1154       1.2   dyoung 		}
   1155       1.2   dyoung 		error = copyout(&nwid, ifr->ifr_data, sizeof(nwid));
   1156       1.2   dyoung 		break;
   1157       1.2   dyoung 	case SIOCS80211NWKEY:
   1158       1.2   dyoung 		nwkey = (struct ieee80211_nwkey *)data;
   1159       1.5   dyoung 		if ((ic->ic_caps & IEEE80211_C_WEP) == 0 &&
   1160       1.2   dyoung 		    nwkey->i_wepon != IEEE80211_NWKEY_OPEN) {
   1161       1.2   dyoung 			error = EINVAL;
   1162       1.2   dyoung 			break;
   1163       1.2   dyoung 		}
   1164       1.2   dyoung 		/* check and copy keys */
   1165       1.2   dyoung 		memset(keys, 0, sizeof(keys));
   1166       1.2   dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
   1167       1.2   dyoung 			keys[i].wk_len = nwkey->i_key[i].i_keylen;
   1168       1.2   dyoung 			if ((keys[i].wk_len > 0 &&
   1169       1.2   dyoung 			    keys[i].wk_len < IEEE80211_WEP_KEYLEN) ||
   1170       1.2   dyoung 			    keys[i].wk_len > sizeof(keys[i].wk_key)) {
   1171       1.2   dyoung 				error = EINVAL;
   1172       1.2   dyoung 				break;
   1173       1.2   dyoung 			}
   1174       1.2   dyoung 			if (keys[i].wk_len <= 0)
   1175       1.2   dyoung 				continue;
   1176       1.2   dyoung 			if ((error = copyin(nwkey->i_key[i].i_keydat,
   1177       1.2   dyoung 			    keys[i].wk_key, keys[i].wk_len)) != 0)
   1178       1.2   dyoung 				break;
   1179       1.2   dyoung 		}
   1180       1.2   dyoung 		if (error)
   1181       1.2   dyoung 			break;
   1182       1.2   dyoung 		i = nwkey->i_defkid - 1;
   1183       1.2   dyoung 		if (i < 0 || i >= IEEE80211_WEP_NKID ||
   1184       1.2   dyoung 		    keys[i].wk_len == 0 ||
   1185       1.2   dyoung 		    (keys[i].wk_len == -1 && ic->ic_nw_keys[i].wk_len == 0)) {
   1186       1.2   dyoung 			if (nwkey->i_wepon != IEEE80211_NWKEY_OPEN) {
   1187       1.2   dyoung 				error = EINVAL;
   1188       1.2   dyoung 				break;
   1189       1.2   dyoung 			}
   1190       1.2   dyoung 		} else
   1191       1.2   dyoung 			ic->ic_wep_txkey = i;
   1192       1.2   dyoung 		/* save the key */
   1193       1.2   dyoung 		if (nwkey->i_wepon == IEEE80211_NWKEY_OPEN)
   1194      1.16  mycroft 			ic->ic_flags &= ~IEEE80211_F_PRIVACY;
   1195       1.2   dyoung 		else
   1196      1.16  mycroft 			ic->ic_flags |= IEEE80211_F_PRIVACY;
   1197       1.2   dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
   1198       1.2   dyoung 			if (keys[i].wk_len < 0)
   1199       1.2   dyoung 				continue;
   1200       1.2   dyoung 			ic->ic_nw_keys[i].wk_len = keys[i].wk_len;
   1201       1.2   dyoung 			memcpy(ic->ic_nw_keys[i].wk_key, keys[i].wk_key,
   1202       1.2   dyoung 			    sizeof(keys[i].wk_key));
   1203       1.2   dyoung 		}
   1204       1.2   dyoung 		error = ENETRESET;
   1205       1.2   dyoung 		break;
   1206       1.2   dyoung 	case SIOCG80211NWKEY:
   1207       1.2   dyoung 		nwkey = (struct ieee80211_nwkey *)data;
   1208      1.16  mycroft 		if (ic->ic_flags & IEEE80211_F_PRIVACY)
   1209       1.2   dyoung 			nwkey->i_wepon = IEEE80211_NWKEY_WEP;
   1210       1.2   dyoung 		else
   1211       1.2   dyoung 			nwkey->i_wepon = IEEE80211_NWKEY_OPEN;
   1212       1.2   dyoung 		nwkey->i_defkid = ic->ic_wep_txkey + 1;
   1213       1.2   dyoung 		for (i = 0; i < IEEE80211_WEP_NKID; i++) {
   1214       1.2   dyoung 			if (nwkey->i_key[i].i_keydat == NULL)
   1215       1.2   dyoung 				continue;
   1216       1.2   dyoung 			/* do not show any keys to non-root user */
   1217       1.2   dyoung 			if ((error = suser(curproc->p_ucred,
   1218       1.2   dyoung 			    &curproc->p_acflag)) != 0)
   1219       1.2   dyoung 				break;
   1220       1.2   dyoung 			nwkey->i_key[i].i_keylen = ic->ic_nw_keys[i].wk_len;
   1221       1.2   dyoung 			if ((error = copyout(ic->ic_nw_keys[i].wk_key,
   1222       1.2   dyoung 			    nwkey->i_key[i].i_keydat,
   1223       1.2   dyoung 			    ic->ic_nw_keys[i].wk_len)) != 0)
   1224       1.2   dyoung 				break;
   1225       1.2   dyoung 		}
   1226       1.2   dyoung 		break;
   1227       1.2   dyoung 	case SIOCS80211POWER:
   1228       1.2   dyoung 		power = (struct ieee80211_power *)data;
   1229       1.2   dyoung 		ic->ic_lintval = power->i_maxsleep;
   1230       1.2   dyoung 		if (power->i_enabled != 0) {
   1231       1.5   dyoung 			if ((ic->ic_caps & IEEE80211_C_PMGT) == 0)
   1232       1.2   dyoung 				error = EINVAL;
   1233       1.2   dyoung 			else if ((ic->ic_flags & IEEE80211_F_PMGTON) == 0) {
   1234       1.2   dyoung 				ic->ic_flags |= IEEE80211_F_PMGTON;
   1235       1.2   dyoung 				error = ENETRESET;
   1236       1.2   dyoung 			}
   1237       1.2   dyoung 		} else {
   1238       1.2   dyoung 			if (ic->ic_flags & IEEE80211_F_PMGTON) {
   1239       1.2   dyoung 				ic->ic_flags &= ~IEEE80211_F_PMGTON;
   1240       1.2   dyoung 				error = ENETRESET;
   1241       1.2   dyoung 			}
   1242       1.2   dyoung 		}
   1243       1.2   dyoung 		break;
   1244       1.2   dyoung 	case SIOCG80211POWER:
   1245       1.2   dyoung 		power = (struct ieee80211_power *)data;
   1246       1.2   dyoung 		power->i_enabled = (ic->ic_flags & IEEE80211_F_PMGTON) ? 1 : 0;
   1247       1.2   dyoung 		power->i_maxsleep = ic->ic_lintval;
   1248       1.2   dyoung 		break;
   1249       1.2   dyoung 	case SIOCS80211BSSID:
   1250       1.2   dyoung 		bssid = (struct ieee80211_bssid *)data;
   1251       1.2   dyoung 		if (IEEE80211_ADDR_EQ(bssid->i_bssid, empty_macaddr))
   1252       1.2   dyoung 			ic->ic_flags &= ~IEEE80211_F_DESBSSID;
   1253       1.2   dyoung 		else {
   1254       1.2   dyoung 			ic->ic_flags |= IEEE80211_F_DESBSSID;
   1255       1.2   dyoung 			IEEE80211_ADDR_COPY(ic->ic_des_bssid, bssid->i_bssid);
   1256       1.2   dyoung 		}
   1257       1.2   dyoung 		if (ic->ic_opmode == IEEE80211_M_HOSTAP)
   1258       1.2   dyoung 			break;
   1259       1.2   dyoung 		switch (ic->ic_state) {
   1260       1.2   dyoung 		case IEEE80211_S_INIT:
   1261       1.2   dyoung 		case IEEE80211_S_SCAN:
   1262       1.2   dyoung 			error = ENETRESET;
   1263       1.2   dyoung 			break;
   1264       1.2   dyoung 		default:
   1265       1.2   dyoung 			if ((ic->ic_flags & IEEE80211_F_DESBSSID) &&
   1266       1.2   dyoung 			    !IEEE80211_ADDR_EQ(ic->ic_des_bssid,
   1267       1.2   dyoung 			    ic->ic_bss->ni_bssid))
   1268       1.2   dyoung 				error = ENETRESET;
   1269       1.2   dyoung 			break;
   1270       1.2   dyoung 		}
   1271       1.2   dyoung 		break;
   1272       1.2   dyoung 	case SIOCG80211BSSID:
   1273       1.2   dyoung 		bssid = (struct ieee80211_bssid *)data;
   1274       1.2   dyoung 		switch (ic->ic_state) {
   1275       1.2   dyoung 		case IEEE80211_S_INIT:
   1276       1.2   dyoung 		case IEEE80211_S_SCAN:
   1277       1.2   dyoung 			if (ic->ic_opmode == IEEE80211_M_HOSTAP)
   1278       1.2   dyoung 				IEEE80211_ADDR_COPY(bssid->i_bssid,
   1279       1.2   dyoung 				    ic->ic_myaddr);
   1280       1.2   dyoung 			else if (ic->ic_flags & IEEE80211_F_DESBSSID)
   1281       1.2   dyoung 				IEEE80211_ADDR_COPY(bssid->i_bssid,
   1282       1.2   dyoung 				    ic->ic_des_bssid);
   1283       1.2   dyoung 			else
   1284       1.2   dyoung 				memset(bssid->i_bssid, 0, IEEE80211_ADDR_LEN);
   1285       1.2   dyoung 			break;
   1286       1.2   dyoung 		default:
   1287       1.2   dyoung 			IEEE80211_ADDR_COPY(bssid->i_bssid,
   1288       1.2   dyoung 			    ic->ic_bss->ni_bssid);
   1289       1.2   dyoung 			break;
   1290       1.2   dyoung 		}
   1291       1.2   dyoung 		break;
   1292       1.2   dyoung 	case SIOCS80211CHANNEL:
   1293       1.2   dyoung 		chanreq = (struct ieee80211chanreq *)data;
   1294       1.2   dyoung 		if (chanreq->i_channel == IEEE80211_CHAN_ANY)
   1295       1.2   dyoung 			ic->ic_des_chan = IEEE80211_CHAN_ANYC;
   1296       1.2   dyoung 		else if (chanreq->i_channel > IEEE80211_CHAN_MAX ||
   1297       1.2   dyoung 		    isclr(ic->ic_chan_active, chanreq->i_channel)) {
   1298       1.2   dyoung 			error = EINVAL;
   1299       1.2   dyoung 			break;
   1300       1.2   dyoung 		} else
   1301       1.4   dyoung 			ic->ic_ibss_chan = ic->ic_des_chan =
   1302       1.4   dyoung 			    &ic->ic_channels[chanreq->i_channel];
   1303       1.2   dyoung 		switch (ic->ic_state) {
   1304       1.2   dyoung 		case IEEE80211_S_INIT:
   1305       1.2   dyoung 		case IEEE80211_S_SCAN:
   1306       1.2   dyoung 			error = ENETRESET;
   1307       1.2   dyoung 			break;
   1308       1.2   dyoung 		default:
   1309       1.2   dyoung 			if (ic->ic_opmode == IEEE80211_M_STA) {
   1310       1.2   dyoung 				if (ic->ic_des_chan != IEEE80211_CHAN_ANYC &&
   1311       1.2   dyoung 				    ic->ic_bss->ni_chan != ic->ic_des_chan)
   1312       1.2   dyoung 					error = ENETRESET;
   1313       1.2   dyoung 			} else {
   1314       1.2   dyoung 				if (ic->ic_bss->ni_chan != ic->ic_ibss_chan)
   1315       1.2   dyoung 					error = ENETRESET;
   1316       1.2   dyoung 			}
   1317       1.2   dyoung 			break;
   1318       1.2   dyoung 		}
   1319       1.2   dyoung 		break;
   1320       1.2   dyoung 	case SIOCG80211CHANNEL:
   1321       1.2   dyoung 		chanreq = (struct ieee80211chanreq *)data;
   1322       1.2   dyoung 		switch (ic->ic_state) {
   1323       1.2   dyoung 		case IEEE80211_S_INIT:
   1324       1.2   dyoung 		case IEEE80211_S_SCAN:
   1325       1.2   dyoung 			if (ic->ic_opmode == IEEE80211_M_STA)
   1326       1.2   dyoung 				chan = ic->ic_des_chan;
   1327       1.2   dyoung 			else
   1328       1.2   dyoung 				chan = ic->ic_ibss_chan;
   1329       1.2   dyoung 			break;
   1330       1.2   dyoung 		default:
   1331       1.2   dyoung 			chan = ic->ic_bss->ni_chan;
   1332       1.2   dyoung 			break;
   1333       1.2   dyoung 		}
   1334       1.2   dyoung 		chanreq->i_channel = ieee80211_chan2ieee(ic, chan);
   1335       1.2   dyoung 		break;
   1336       1.2   dyoung 	case SIOCGIFGENERIC:
   1337       1.2   dyoung 		error = ieee80211_cfgget(ifp, cmd, data);
   1338       1.2   dyoung 		break;
   1339       1.2   dyoung 	case SIOCSIFGENERIC:
   1340       1.2   dyoung 		error = suser(curproc->p_ucred, &curproc->p_acflag);
   1341       1.2   dyoung 		if (error)
   1342       1.2   dyoung 			break;
   1343       1.2   dyoung 		error = ieee80211_cfgset(ifp, cmd, data);
   1344       1.7   dyoung 		break;
   1345      1.17   dyoung 	case SIOCG80211ZSTATS:
   1346       1.7   dyoung 	case SIOCG80211STATS:
   1347       1.7   dyoung 		ifr = (struct ifreq *)data;
   1348      1.17   dyoung 		s = splnet();
   1349       1.7   dyoung 		copyout(&ic->ic_stats, ifr->ifr_data, sizeof (ic->ic_stats));
   1350      1.17   dyoung 		if (cmd == SIOCG80211ZSTATS)
   1351      1.17   dyoung 			(void)memset(&ic->ic_stats, 0, sizeof(ic->ic_stats));
   1352      1.17   dyoung 		splx(s);
   1353       1.2   dyoung 		break;
   1354      1.10   dyoung 	case SIOCSIFMTU:
   1355      1.10   dyoung 		ifr = (struct ifreq *)data;
   1356      1.10   dyoung 		if (!(IEEE80211_MTU_MIN <= ifr->ifr_mtu &&
   1357      1.10   dyoung 		    ifr->ifr_mtu <= IEEE80211_MTU_MAX))
   1358      1.10   dyoung 			error = EINVAL;
   1359      1.10   dyoung 		else
   1360      1.10   dyoung 			ifp->if_mtu = ifr->ifr_mtu;
   1361      1.10   dyoung 		break;
   1362       1.2   dyoung 	default:
   1363       1.2   dyoung 		error = ether_ioctl(ifp, cmd, data);
   1364       1.2   dyoung 		break;
   1365       1.2   dyoung 	}
   1366       1.2   dyoung 	return error;
   1367       1.2   dyoung }
   1368       1.2   dyoung #endif /* __NetBSD__ */
   1369