main.c 42.5 KB
Newer Older
1 2 3 4 5 6
/**
  * This file contains the major functions in WLAN
  * driver. It includes init, exit, open, close and main
  * thread etc..
  */

7
#include <linux/moduleparam.h>
8 9 10 11
#include <linux/delay.h>
#include <linux/etherdevice.h>
#include <linux/netdevice.h>
#include <linux/if_arp.h>
12
#include <linux/kthread.h>
13
#include <linux/kfifo.h>
14
#include <linux/stddef.h>
J
Johannes Berg 已提交
15
#include <linux/ieee80211.h>
16 17 18 19 20 21 22
#include <net/iw_handler.h>

#include "host.h"
#include "decl.h"
#include "dev.h"
#include "wext.h"
#include "debugfs.h"
23
#include "scan.h"
24
#include "assoc.h"
25
#include "cmd.h"
26

27
#define DRIVER_RELEASE_VERSION "323.p0"
28
const char lbs_driver_version[] = "COMM-USB8388-" DRIVER_RELEASE_VERSION
29 30 31 32 33
#ifdef  DEBUG
    "-dbg"
#endif
    "";

34 35

/* Module parameters */
36 37 38
unsigned int lbs_debug;
EXPORT_SYMBOL_GPL(lbs_debug);
module_param_named(libertas_debug, lbs_debug, int, 0644);
39 40


41 42 43 44 45
/* This global structure is used to send the confirm_sleep command as
 * fast as possible down to the firmware. */
struct cmd_confirm_sleep confirm_sleep;


46 47 48 49 50
#define LBS_TX_PWR_DEFAULT		20	/*100mW */
#define LBS_TX_PWR_US_DEFAULT		20	/*100mW */
#define LBS_TX_PWR_JP_DEFAULT		16	/*50mW */
#define LBS_TX_PWR_FR_DEFAULT		20	/*100mW */
#define LBS_TX_PWR_EMEA_DEFAULT	20	/*100mW */
51 52 53 54

/* Format { channel, frequency (MHz), maxtxpower } */
/* band: 'B/G', region: USA FCC/Canada IC */
static struct chan_freq_power channel_freq_power_US_BG[] = {
55 56 57 58 59 60 61 62 63 64 65
	{1, 2412, LBS_TX_PWR_US_DEFAULT},
	{2, 2417, LBS_TX_PWR_US_DEFAULT},
	{3, 2422, LBS_TX_PWR_US_DEFAULT},
	{4, 2427, LBS_TX_PWR_US_DEFAULT},
	{5, 2432, LBS_TX_PWR_US_DEFAULT},
	{6, 2437, LBS_TX_PWR_US_DEFAULT},
	{7, 2442, LBS_TX_PWR_US_DEFAULT},
	{8, 2447, LBS_TX_PWR_US_DEFAULT},
	{9, 2452, LBS_TX_PWR_US_DEFAULT},
	{10, 2457, LBS_TX_PWR_US_DEFAULT},
	{11, 2462, LBS_TX_PWR_US_DEFAULT}
66 67 68 69
};

/* band: 'B/G', region: Europe ETSI */
static struct chan_freq_power channel_freq_power_EU_BG[] = {
70 71 72 73 74 75 76 77 78 79 80 81 82
	{1, 2412, LBS_TX_PWR_EMEA_DEFAULT},
	{2, 2417, LBS_TX_PWR_EMEA_DEFAULT},
	{3, 2422, LBS_TX_PWR_EMEA_DEFAULT},
	{4, 2427, LBS_TX_PWR_EMEA_DEFAULT},
	{5, 2432, LBS_TX_PWR_EMEA_DEFAULT},
	{6, 2437, LBS_TX_PWR_EMEA_DEFAULT},
	{7, 2442, LBS_TX_PWR_EMEA_DEFAULT},
	{8, 2447, LBS_TX_PWR_EMEA_DEFAULT},
	{9, 2452, LBS_TX_PWR_EMEA_DEFAULT},
	{10, 2457, LBS_TX_PWR_EMEA_DEFAULT},
	{11, 2462, LBS_TX_PWR_EMEA_DEFAULT},
	{12, 2467, LBS_TX_PWR_EMEA_DEFAULT},
	{13, 2472, LBS_TX_PWR_EMEA_DEFAULT}
83 84 85 86
};

/* band: 'B/G', region: Spain */
static struct chan_freq_power channel_freq_power_SPN_BG[] = {
87 88
	{10, 2457, LBS_TX_PWR_DEFAULT},
	{11, 2462, LBS_TX_PWR_DEFAULT}
89 90 91 92
};

/* band: 'B/G', region: France */
static struct chan_freq_power channel_freq_power_FR_BG[] = {
93 94 95 96
	{10, 2457, LBS_TX_PWR_FR_DEFAULT},
	{11, 2462, LBS_TX_PWR_FR_DEFAULT},
	{12, 2467, LBS_TX_PWR_FR_DEFAULT},
	{13, 2472, LBS_TX_PWR_FR_DEFAULT}
97 98 99 100
};

/* band: 'B/G', region: Japan */
static struct chan_freq_power channel_freq_power_JPN_BG[] = {
101 102 103 104 105 106 107 108 109 110 111 112 113 114
	{1, 2412, LBS_TX_PWR_JP_DEFAULT},
	{2, 2417, LBS_TX_PWR_JP_DEFAULT},
	{3, 2422, LBS_TX_PWR_JP_DEFAULT},
	{4, 2427, LBS_TX_PWR_JP_DEFAULT},
	{5, 2432, LBS_TX_PWR_JP_DEFAULT},
	{6, 2437, LBS_TX_PWR_JP_DEFAULT},
	{7, 2442, LBS_TX_PWR_JP_DEFAULT},
	{8, 2447, LBS_TX_PWR_JP_DEFAULT},
	{9, 2452, LBS_TX_PWR_JP_DEFAULT},
	{10, 2457, LBS_TX_PWR_JP_DEFAULT},
	{11, 2462, LBS_TX_PWR_JP_DEFAULT},
	{12, 2467, LBS_TX_PWR_JP_DEFAULT},
	{13, 2472, LBS_TX_PWR_JP_DEFAULT},
	{14, 2484, LBS_TX_PWR_JP_DEFAULT}
115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131
};

/**
 * the structure for channel, frequency and power
 */
struct region_cfp_table {
	u8 region;
	struct chan_freq_power *cfp_BG;
	int cfp_no_BG;
};

/**
 * the structure for the mapping between region and CFP
 */
static struct region_cfp_table region_cfp_table[] = {
	{0x10,			/*US FCC */
	 channel_freq_power_US_BG,
132
	 ARRAY_SIZE(channel_freq_power_US_BG),
133 134 135 136
	 }
	,
	{0x20,			/*CANADA IC */
	 channel_freq_power_US_BG,
137
	 ARRAY_SIZE(channel_freq_power_US_BG),
138 139 140
	 }
	,
	{0x30, /*EU*/ channel_freq_power_EU_BG,
141
	 ARRAY_SIZE(channel_freq_power_EU_BG),
142 143 144
	 }
	,
	{0x31, /*SPAIN*/ channel_freq_power_SPN_BG,
145
	 ARRAY_SIZE(channel_freq_power_SPN_BG),
146 147 148
	 }
	,
	{0x32, /*FRANCE*/ channel_freq_power_FR_BG,
149
	 ARRAY_SIZE(channel_freq_power_FR_BG),
150 151 152
	 }
	,
	{0x40, /*JAPAN*/ channel_freq_power_JPN_BG,
153
	 ARRAY_SIZE(channel_freq_power_JPN_BG),
154 155 156 157 158 159
	 }
	,
/*Add new region here */
};

/**
160
 * the table to keep region code
161
 */
162
u16 lbs_region_code_to_index[MRVDRV_MAX_REGION_CODE] =
163
    { 0x10, 0x20, 0x30, 0x31, 0x32, 0x40 };
164 165

/**
166
 * 802.11b/g supported bitrates (in 500Kb/s units)
167
 */
168
u8 lbs_bg_rates[MAX_RATES] =
169 170
    { 0x02, 0x04, 0x0b, 0x16, 0x0c, 0x12, 0x18, 0x24, 0x30, 0x48, 0x60, 0x6c,
0x00, 0x00 };
171 172

/**
173 174 175
 * FW rate table.  FW refers to rates by their index in this table, not by the
 * rate value itself.  Values of 0x00 are
 * reserved positions.
176
 */
177 178 179 180
static u8 fw_data_rates[MAX_RATES] =
    { 0x02, 0x04, 0x0B, 0x16, 0x00, 0x0C, 0x12,
      0x18, 0x24, 0x30, 0x48, 0x60, 0x6C, 0x00
};
181 182

/**
183 184 185 186
 *  @brief use index to get the data rate
 *
 *  @param idx                The index of data rate
 *  @return 	   		data rate or 0
187
 */
188
u32 lbs_fw_index_to_data_rate(u8 idx)
189 190 191 192 193 194 195 196 197 198 199 200
{
	if (idx >= sizeof(fw_data_rates))
		idx = 0;
	return fw_data_rates[idx];
}

/**
 *  @brief use rate to get the index
 *
 *  @param rate                 data rate
 *  @return 	   		index or 0
 */
201
u8 lbs_data_rate_to_fw_index(u32 rate)
202 203 204 205 206 207 208 209 210 211 212 213
{
	u8 i;

	if (!rate)
		return 0;

	for (i = 0; i < sizeof(fw_data_rates); i++) {
		if (rate == fw_data_rates[i])
			return i;
	}
	return 0;
}
214 215 216 217 218 219

/**
 * Attributes exported through sysfs
 */

/**
220
 * @brief Get function for sysfs attribute anycast_mask
221
 */
222
static ssize_t lbs_anycast_get(struct device *dev,
D
Dan Williams 已提交
223 224
		struct device_attribute *attr, char * buf)
{
225
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
226
	struct cmd_ds_mesh_access mesh_access;
227
	int ret;
228 229

	memset(&mesh_access, 0, sizeof(mesh_access));
230 231 232 233

	ret = lbs_mesh_access(priv, CMD_ACT_MESH_GET_ANYCAST, &mesh_access);
	if (ret)
		return ret;
234

235
	return snprintf(buf, 12, "0x%X\n", le32_to_cpu(mesh_access.data[0]));
236 237 238
}

/**
239
 * @brief Set function for sysfs attribute anycast_mask
240
 */
241
static ssize_t lbs_anycast_set(struct device *dev,
D
Dan Williams 已提交
242 243
		struct device_attribute *attr, const char * buf, size_t count)
{
244
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
245
	struct cmd_ds_mesh_access mesh_access;
246
	uint32_t datum;
247
	int ret;
248 249

	memset(&mesh_access, 0, sizeof(mesh_access));
250
	sscanf(buf, "%x", &datum);
251 252
	mesh_access.data[0] = cpu_to_le32(datum);

253 254 255 256
	ret = lbs_mesh_access(priv, CMD_ACT_MESH_SET_ANYCAST, &mesh_access);
	if (ret)
		return ret;

257 258 259
	return strlen(buf);
}

260 261 262 263 264 265
/**
 * @brief Get function for sysfs attribute prb_rsp_limit
 */
static ssize_t lbs_prb_rsp_limit_get(struct device *dev,
		struct device_attribute *attr, char *buf)
{
266
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288
	struct cmd_ds_mesh_access mesh_access;
	int ret;
	u32 retry_limit;

	memset(&mesh_access, 0, sizeof(mesh_access));
	mesh_access.data[0] = cpu_to_le32(CMD_ACT_GET);

	ret = lbs_mesh_access(priv, CMD_ACT_MESH_SET_GET_PRB_RSP_LIMIT,
			&mesh_access);
	if (ret)
		return ret;

	retry_limit = le32_to_cpu(mesh_access.data[1]);
	return snprintf(buf, 10, "%d\n", retry_limit);
}

/**
 * @brief Set function for sysfs attribute prb_rsp_limit
 */
static ssize_t lbs_prb_rsp_limit_set(struct device *dev,
		struct device_attribute *attr, const char *buf, size_t count)
{
289
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311
	struct cmd_ds_mesh_access mesh_access;
	int ret;
	unsigned long retry_limit;

	memset(&mesh_access, 0, sizeof(mesh_access));
	mesh_access.data[0] = cpu_to_le32(CMD_ACT_SET);

	if (!strict_strtoul(buf, 10, &retry_limit))
		return -ENOTSUPP;
	if (retry_limit > 15)
		return -ENOTSUPP;

	mesh_access.data[1] = cpu_to_le32(retry_limit);

	ret = lbs_mesh_access(priv, CMD_ACT_MESH_SET_GET_PRB_RSP_LIMIT,
			&mesh_access);
	if (ret)
		return ret;

	return strlen(buf);
}

312 313
static int lbs_add_rtap(struct lbs_private *priv);
static void lbs_remove_rtap(struct lbs_private *priv);
314 315
static int lbs_add_mesh(struct lbs_private *priv);
static void lbs_remove_mesh(struct lbs_private *priv);
316

317 318 319 320

/**
 * Get function for sysfs attribute rtap
 */
321
static ssize_t lbs_rtap_get(struct device *dev,
322 323
		struct device_attribute *attr, char * buf)
{
324
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
325
	return snprintf(buf, 5, "0x%X\n", priv->monitormode);
326 327 328 329 330
}

/**
 *  Set function for sysfs attribute rtap
 */
331
static ssize_t lbs_rtap_set(struct device *dev,
332 333 334
		struct device_attribute *attr, const char * buf, size_t count)
{
	int monitor_mode;
335
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
336 337

	sscanf(buf, "%x", &monitor_mode);
338 339
	if (monitor_mode) {
		if (priv->monitormode == monitor_mode)
340
			return strlen(buf);
341
		if (!priv->monitormode) {
342 343
			if (priv->infra_open || priv->mesh_open)
				return -EBUSY;
344
			if (priv->mode == IW_MODE_INFRA)
345 346 347
				lbs_cmd_80211_deauthenticate(priv,
							     priv->curbssparams.bssid,
							     WLAN_REASON_DEAUTH_LEAVING);
348
			else if (priv->mode == IW_MODE_ADHOC)
349
				lbs_adhoc_stop(priv);
350
			lbs_add_rtap(priv);
351
		}
352
		priv->monitormode = monitor_mode;
353
	} else {
354
		if (!priv->monitormode)
355
			return strlen(buf);
356
		priv->monitormode = 0;
357
		lbs_remove_rtap(priv);
D
David Woodhouse 已提交
358

359 360 361
		if (priv->currenttxskb) {
			dev_kfree_skb_any(priv->currenttxskb);
			priv->currenttxskb = NULL;
D
David Woodhouse 已提交
362 363 364 365
		}

		/* Wake queues, command thread, etc. */
		lbs_host_to_card_done(priv);
366 367
	}

368
	lbs_prepare_and_send_command(priv,
369
			CMD_802_11_MONITOR_MODE, CMD_ACT_SET,
370
			CMD_OPTION_WAITFORRSP, 0, &priv->monitormode);
371 372 373 374
	return strlen(buf);
}

/**
375 376
 * lbs_rtap attribute to be exported per ethX interface
 * through sysfs (/sys/class/net/ethX/lbs_rtap)
377
 */
378 379 380 381 382 383 384 385
static DEVICE_ATTR(lbs_rtap, 0644, lbs_rtap_get, lbs_rtap_set );

/**
 * Get function for sysfs attribute mesh
 */
static ssize_t lbs_mesh_get(struct device *dev,
		struct device_attribute *attr, char * buf)
{
386
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
387 388 389 390 391 392 393 394 395
	return snprintf(buf, 5, "0x%X\n", !!priv->mesh_dev);
}

/**
 *  Set function for sysfs attribute mesh
 */
static ssize_t lbs_mesh_set(struct device *dev,
		struct device_attribute *attr, const char * buf, size_t count)
{
396
	struct lbs_private *priv = to_net_dev(dev)->ml_priv;
397
	int enable;
398
	int ret, action = CMD_ACT_MESH_CONFIG_STOP;
399 400 401 402 403

	sscanf(buf, "%x", &enable);
	enable = !!enable;
	if (enable == !!priv->mesh_dev)
		return count;
404 405 406
	if (enable)
		action = CMD_ACT_MESH_CONFIG_START;
	ret = lbs_mesh_config(priv, action, priv->curbssparams.channel);
407 408
	if (ret)
		return ret;
409

410 411 412 413 414 415 416 417 418 419 420 421 422
	if (enable)
		lbs_add_mesh(priv);
	else
		lbs_remove_mesh(priv);

	return count;
}

/**
 * lbs_mesh attribute to be exported per ethX interface
 * through sysfs (/sys/class/net/ethX/lbs_mesh)
 */
static DEVICE_ATTR(lbs_mesh, 0644, lbs_mesh_get, lbs_mesh_set);
423

424
/**
425 426
 * anycast_mask attribute to be exported per mshX interface
 * through sysfs (/sys/class/net/mshX/anycast_mask)
427
 */
428
static DEVICE_ATTR(anycast_mask, 0644, lbs_anycast_get, lbs_anycast_set);
429

430 431 432 433 434 435 436
/**
 * prb_rsp_limit attribute to be exported per mshX interface
 * through sysfs (/sys/class/net/mshX/prb_rsp_limit)
 */
static DEVICE_ATTR(prb_rsp_limit, 0644, lbs_prb_rsp_limit_get,
		lbs_prb_rsp_limit_set);

437
static struct attribute *lbs_mesh_sysfs_entries[] = {
438
	&dev_attr_anycast_mask.attr,
439
	&dev_attr_prb_rsp_limit.attr,
440 441 442
	NULL,
};

443 444
static struct attribute_group lbs_mesh_attr_group = {
	.attrs = lbs_mesh_sysfs_entries,
445 446
};

447
/**
448
 *  @brief This function opens the ethX or mshX interface
449 450
 *
 *  @param dev     A pointer to net_device structure
451
 *  @return 	   0 or -EBUSY if monitor mode active
452
 */
453
static int lbs_dev_open(struct net_device *dev)
454
{
455
	struct lbs_private *priv = dev->ml_priv;
456
	int ret = 0;
457

458 459
	lbs_deb_enter(LBS_DEB_NET);

460
	spin_lock_irq(&priv->driver_lock);
461

462
	if (priv->monitormode) {
463 464 465
		ret = -EBUSY;
		goto out;
	}
466

467 468 469 470 471 472
	if (dev == priv->mesh_dev) {
		priv->mesh_open = 1;
		priv->mesh_connect_status = LBS_CONNECTED;
		netif_carrier_on(dev);
	} else {
		priv->infra_open = 1;
473

474 475
		if (priv->connect_status == LBS_CONNECTED)
			netif_carrier_on(dev);
476
		else
477
			netif_carrier_off(dev);
478
	}
479

480 481 482
	if (!priv->tx_pending_len)
		netif_wake_queue(dev);
 out:
483

484
	spin_unlock_irq(&priv->driver_lock);
485
	lbs_deb_leave_args(LBS_DEB_NET, "ret %d", ret);
486
	return ret;
487 488 489 490 491 492 493 494
}

/**
 *  @brief This function closes the mshX interface
 *
 *  @param dev     A pointer to net_device structure
 *  @return 	   0
 */
495
static int lbs_mesh_stop(struct net_device *dev)
496
{
497
	struct lbs_private *priv = dev->ml_priv;
498

499
	lbs_deb_enter(LBS_DEB_MESH);
500 501
	spin_lock_irq(&priv->driver_lock);

502
	priv->mesh_open = 0;
503 504 505 506
	priv->mesh_connect_status = LBS_DISCONNECTED;

	netif_stop_queue(dev);
	netif_carrier_off(dev);
507

508
	spin_unlock_irq(&priv->driver_lock);
509

510 511
	schedule_work(&priv->mcast_work);

512
	lbs_deb_leave(LBS_DEB_MESH);
513
	return 0;
514 515 516 517 518 519 520 521
}

/**
 *  @brief This function closes the ethX interface
 *
 *  @param dev     A pointer to net_device structure
 *  @return 	   0
 */
522
static int lbs_eth_stop(struct net_device *dev)
523
{
524
	struct lbs_private *priv = dev->ml_priv;
525

526
	lbs_deb_enter(LBS_DEB_NET);
527

528
	spin_lock_irq(&priv->driver_lock);
529
	priv->infra_open = 0;
530 531
	netif_stop_queue(dev);
	spin_unlock_irq(&priv->driver_lock);
532

533 534
	schedule_work(&priv->mcast_work);

535
	lbs_deb_leave(LBS_DEB_NET);
536
	return 0;
537 538
}

539
static void lbs_tx_timeout(struct net_device *dev)
540
{
541
	struct lbs_private *priv = dev->ml_priv;
542

543
	lbs_deb_enter(LBS_DEB_TX);
544

545
	lbs_pr_err("tx watch dog timeout\n");
546 547 548

	dev->trans_start = jiffies;

549 550 551
	if (priv->currenttxskb)
		lbs_send_tx_feedback(priv, 0);

552 553 554
	/* XX: Shouldn't we also call into the hw-specific driver
	   to kick it somehow? */
	lbs_host_to_card_done(priv);
555

556 557 558 559 560 561 562
	/* More often than not, this actually happens because the
	   firmware has crapped itself -- rather than just a very
	   busy medium. So send a harmless command, and if/when
	   _that_ times out, we'll kick it in the head. */
	lbs_prepare_and_send_command(priv, CMD_802_11_RSSI, 0,
				     0, 0, NULL);

563
	lbs_deb_leave(LBS_DEB_TX);
564 565
}

566 567
void lbs_host_to_card_done(struct lbs_private *priv)
{
568 569
	unsigned long flags;

570 571
	lbs_deb_enter(LBS_DEB_THREAD);

572
	spin_lock_irqsave(&priv->driver_lock, flags);
573 574 575 576

	priv->dnld_sent = DNLD_RES_RECEIVED;

	/* Wake main thread if commands are pending */
577
	if (!priv->cur_cmd || priv->tx_pending_len > 0)
578 579
		wake_up_interruptible(&priv->waitq);

580
	spin_unlock_irqrestore(&priv->driver_lock, flags);
581
	lbs_deb_leave(LBS_DEB_THREAD);
582 583 584
}
EXPORT_SYMBOL_GPL(lbs_host_to_card_done);

585
static int lbs_set_mac_address(struct net_device *dev, void *addr)
586 587
{
	int ret = 0;
588
	struct lbs_private *priv = dev->ml_priv;
589
	struct sockaddr *phwaddr = addr;
590
	struct cmd_ds_802_11_mac_address cmd;
591

592
	lbs_deb_enter(LBS_DEB_NET);
593

594
	/* In case it was called from the mesh device */
595
	dev = priv->dev;
596

597 598 599
	cmd.hdr.size = cpu_to_le16(sizeof(cmd));
	cmd.action = cpu_to_le16(CMD_ACT_SET);
	memcpy(cmd.macadd, phwaddr->sa_data, ETH_ALEN);
600

601
	ret = lbs_cmd_with_response(priv, CMD_802_11_MAC_ADDRESS, &cmd);
602
	if (ret) {
603
		lbs_deb_net("set MAC address failed\n");
604 605 606
		goto done;
	}

607 608
	memcpy(priv->current_addr, phwaddr->sa_data, ETH_ALEN);
	memcpy(dev->dev_addr, phwaddr->sa_data, ETH_ALEN);
609
	if (priv->mesh_dev)
610
		memcpy(priv->mesh_dev->dev_addr, phwaddr->sa_data, ETH_ALEN);
611 612

done:
613
	lbs_deb_leave_args(LBS_DEB_NET, "ret %d", ret);
614 615 616
	return ret;
}

617 618 619

static inline int mac_in_list(unsigned char *list, int list_len,
			      unsigned char *mac)
620
{
621 622 623 624 625 626 627 628 629
	while (list_len) {
		if (!memcmp(list, mac, ETH_ALEN))
			return 1;
		list += ETH_ALEN;
		list_len--;
	}
	return 0;
}

630

631 632 633 634 635 636 637 638 639
static int lbs_add_mcast_addrs(struct cmd_ds_mac_multicast_adr *cmd,
			       struct net_device *dev, int nr_addrs)
{
	int i = nr_addrs;
	struct dev_mc_list *mc_list;

	if ((dev->flags & (IFF_UP|IFF_MULTICAST)) != (IFF_UP|IFF_MULTICAST))
		return nr_addrs;

640
	netif_addr_lock_bh(dev);
641 642
	for (mc_list = dev->mc_list; mc_list; mc_list = mc_list->next) {
		if (mac_in_list(cmd->maclist, nr_addrs, mc_list->dmi_addr)) {
J
Johannes Berg 已提交
643 644
			lbs_deb_net("mcast address %s:%pM skipped\n", dev->name,
				    mc_list->dmi_addr);
645 646
			continue;
		}
647

648 649 650
		if (i == MRVDRV_MAX_MULTICAST_LIST_SIZE)
			break;
		memcpy(&cmd->maclist[6*i], mc_list->dmi_addr, ETH_ALEN);
J
Johannes Berg 已提交
651 652
		lbs_deb_net("mcast address %s:%pM added to filter\n", dev->name,
			    mc_list->dmi_addr);
653
		i++;
654
	}
655
	netif_addr_unlock_bh(dev);
656 657 658
	if (mc_list)
		return -EOVERFLOW;

659 660 661
	return i;
}

662
static void lbs_set_mcast_worker(struct work_struct *work)
663
{
664 665 666 667 668
	struct lbs_private *priv = container_of(work, struct lbs_private, mcast_work);
	struct cmd_ds_mac_multicast_adr mcast_cmd;
	int dev_flags;
	int nr_addrs;
	int old_mac_control = priv->mac_control;
669

670
	lbs_deb_enter(LBS_DEB_NET);
671

672 673 674 675 676 677 678 679 680 681 682 683 684 685 686
	dev_flags = priv->dev->flags;
	if (priv->mesh_dev)
		dev_flags |= priv->mesh_dev->flags;

	if (dev_flags & IFF_PROMISC) {
		priv->mac_control |= CMD_ACT_MAC_PROMISCUOUS_ENABLE;
		priv->mac_control &= ~(CMD_ACT_MAC_ALL_MULTICAST_ENABLE |
				       CMD_ACT_MAC_MULTICAST_ENABLE);
		goto out_set_mac_control;
	} else if (dev_flags & IFF_ALLMULTI) {
	do_allmulti:
		priv->mac_control |= CMD_ACT_MAC_ALL_MULTICAST_ENABLE;
		priv->mac_control &= ~(CMD_ACT_MAC_PROMISCUOUS_ENABLE |
				       CMD_ACT_MAC_MULTICAST_ENABLE);
		goto out_set_mac_control;
687 688
	}

689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712
	/* Once for priv->dev, again for priv->mesh_dev if it exists */
	nr_addrs = lbs_add_mcast_addrs(&mcast_cmd, priv->dev, 0);
	if (nr_addrs >= 0 && priv->mesh_dev)
		nr_addrs = lbs_add_mcast_addrs(&mcast_cmd, priv->mesh_dev, nr_addrs);
	if (nr_addrs < 0)
		goto do_allmulti;

	if (nr_addrs) {
		int size = offsetof(struct cmd_ds_mac_multicast_adr,
				    maclist[6*nr_addrs]);

		mcast_cmd.action = cpu_to_le16(CMD_ACT_SET);
		mcast_cmd.hdr.size = cpu_to_le16(size);
		mcast_cmd.nr_of_adrs = cpu_to_le16(nr_addrs);

		lbs_cmd_async(priv, CMD_MAC_MULTICAST_ADR, &mcast_cmd.hdr, size);

		priv->mac_control |= CMD_ACT_MAC_MULTICAST_ENABLE;
	} else
		priv->mac_control &= ~CMD_ACT_MAC_MULTICAST_ENABLE;

	priv->mac_control &= ~(CMD_ACT_MAC_PROMISCUOUS_ENABLE |
			       CMD_ACT_MAC_ALL_MULTICAST_ENABLE);
 out_set_mac_control:
713 714
	if (priv->mac_control != old_mac_control)
		lbs_set_mac_control(priv);
715

716
	lbs_deb_leave(LBS_DEB_NET);
717 718
}

719 720
static void lbs_set_multicast_list(struct net_device *dev)
{
721
	struct lbs_private *priv = dev->ml_priv;
722 723 724 725

	schedule_work(&priv->mcast_work);
}

726
/**
727
 *  @brief This function handles the major jobs in the LBS driver.
728 729
 *  It handles all events generated by firmware, RX data received
 *  from firmware and TX data sent from kernel.
730
 *
731
 *  @param data    A pointer to lbs_thread structure
732 733
 *  @return 	   0
 */
734
static int lbs_thread(void *data)
735
{
736
	struct net_device *dev = data;
737
	struct lbs_private *priv = dev->ml_priv;
738 739
	wait_queue_t wait;

740
	lbs_deb_enter(LBS_DEB_THREAD);
741 742 743 744

	init_waitqueue_entry(&wait, current);

	for (;;) {
745
		int shouldsleep;
746
		u8 resp_idx;
747

748 749
		lbs_deb_thread("1: currenttxskb %p, dnld_sent %d\n",
				priv->currenttxskb, priv->dnld_sent);
750

751
		add_wait_queue(&priv->waitq, &wait);
752
		set_current_state(TASK_INTERRUPTIBLE);
753
		spin_lock_irq(&priv->driver_lock);
754

755
		if (kthread_should_stop())
756
			shouldsleep = 0;	/* Bye */
757 758
		else if (priv->surpriseremoved)
			shouldsleep = 1;	/* We need to wait until we're _told_ to die */
759 760
		else if (priv->psstate == PS_STATE_SLEEP)
			shouldsleep = 1;	/* Sleep mode. Nothing we can do till it wakes */
761 762
		else if (priv->cmd_timed_out)
			shouldsleep = 0;	/* Command timed out. Recover */
763 764
		else if (!priv->fw_ready)
			shouldsleep = 1;	/* Firmware not ready. We're waiting for it */
765 766
		else if (priv->dnld_sent)
			shouldsleep = 1;	/* Something is en route to the device already */
767 768
		else if (priv->tx_pending_len > 0)
			shouldsleep = 0;	/* We've a packet to send */
769 770
		else if (priv->resp_len[priv->resp_idx])
			shouldsleep = 0;	/* We have a command response */
771 772 773 774
		else if (priv->cur_cmd)
			shouldsleep = 1;	/* Can't send a command; one already running */
		else if (!list_empty(&priv->cmdpendingq))
			shouldsleep = 0;	/* We have a command to send */
775 776
		else if (__kfifo_len(priv->event_fifo))
			shouldsleep = 0;	/* We have an event to process */
777 778 779 780
		else
			shouldsleep = 1;	/* No command */

		if (shouldsleep) {
781
			lbs_deb_thread("sleeping, connect_status %d, "
782
				"psmode %d, psstate %d\n",
783 784
				priv->connect_status,
				priv->psmode, priv->psstate);
785
			spin_unlock_irq(&priv->driver_lock);
786 787
			schedule();
		} else
788
			spin_unlock_irq(&priv->driver_lock);
789

790 791
		lbs_deb_thread("2: currenttxskb %p, dnld_send %d\n",
			       priv->currenttxskb, priv->dnld_sent);
792 793

		set_current_state(TASK_RUNNING);
794
		remove_wait_queue(&priv->waitq, &wait);
795

796 797
		lbs_deb_thread("3: currenttxskb %p, dnld_sent %d\n",
			       priv->currenttxskb, priv->dnld_sent);
798

799
		if (kthread_should_stop()) {
800
			lbs_deb_thread("break from main thread\n");
801 802 803
			break;
		}

804 805 806 807
		if (priv->surpriseremoved) {
			lbs_deb_thread("adapter removed; waiting to die...\n");
			continue;
		}
808

809 810
		lbs_deb_thread("4: currenttxskb %p, dnld_sent %d\n",
		       priv->currenttxskb, priv->dnld_sent);
811

812
		/* Process any pending command response */
813
		spin_lock_irq(&priv->driver_lock);
814 815
		resp_idx = priv->resp_idx;
		if (priv->resp_len[resp_idx]) {
816
			spin_unlock_irq(&priv->driver_lock);
817 818 819
			lbs_process_command_response(priv,
				priv->resp_buf[resp_idx],
				priv->resp_len[resp_idx]);
820
			spin_lock_irq(&priv->driver_lock);
821
			priv->resp_len[resp_idx] = 0;
822
		}
823
		spin_unlock_irq(&priv->driver_lock);
824

825
		/* command timeout stuff */
826 827 828
		if (priv->cmd_timed_out && priv->cur_cmd) {
			struct cmd_ctrl_node *cmdnode = priv->cur_cmd;

829 830 831 832
			if (++priv->nr_retries > 3) {
				lbs_pr_info("Excessive timeouts submitting "
					"command 0x%04x\n",
					le16_to_cpu(cmdnode->cmdbuf->command));
833 834
				lbs_complete_command(priv, cmdnode, -ETIMEDOUT);
				priv->nr_retries = 0;
835
				if (priv->reset_card)
836
					priv->reset_card(priv);
837 838
			} else {
				priv->cur_cmd = NULL;
839
				priv->dnld_sent = DNLD_RES_RECEIVED;
840 841 842 843
				lbs_pr_info("requeueing command 0x%04x due "
					"to timeout (#%d)\n",
					le16_to_cpu(cmdnode->cmdbuf->command),
					priv->nr_retries);
844 845 846 847 848 849 850 851

				/* Stick it back at the _top_ of the pending queue
				   for immediate resubmission */
				list_add(&cmdnode->list, &priv->cmdpendingq);
			}
		}
		priv->cmd_timed_out = 0;

852 853 854 855
		/* Process hardware events, e.g. card removed, link lost */
		spin_lock_irq(&priv->driver_lock);
		while (__kfifo_len(priv->event_fifo)) {
			u32 event;
856

857 858
			__kfifo_get(priv->event_fifo, (unsigned char *) &event,
				sizeof(event));
859
			spin_unlock_irq(&priv->driver_lock);
860 861 862 863
			lbs_process_event(priv, event);
			spin_lock_irq(&priv->driver_lock);
		}
		spin_unlock_irq(&priv->driver_lock);
864

865 866 867
		if (!priv->fw_ready)
			continue;

868
		/* Check if we need to confirm Sleep Request received previously */
869 870 871
		if (priv->psstate == PS_STATE_PRE_SLEEP &&
		    !priv->dnld_sent && !priv->cur_cmd) {
			if (priv->connect_status == LBS_CONNECTED) {
872 873 874 875
				lbs_deb_thread("pre-sleep, currenttxskb %p, "
					"dnld_sent %d, cur_cmd %p\n",
					priv->currenttxskb, priv->dnld_sent,
					priv->cur_cmd);
876

877
				lbs_ps_confirm_sleep(priv);
878 879 880 881 882 883
			} else {
				/* workaround for firmware sending
				 * deauth/linkloss event immediately
				 * after sleep request; remove this
				 * after firmware fixes it
				 */
884
				priv->psstate = PS_STATE_AWAKE;
885 886
				lbs_pr_alert("ignore PS_SleepConfirm in "
					"non-connected state\n");
887 888 889 890 891 892
			}
		}

		/* The PS state is changed during processing of Sleep Request
		 * event above
		 */
893 894
		if ((priv->psstate == PS_STATE_SLEEP) ||
		    (priv->psstate == PS_STATE_PRE_SLEEP))
895 896 897
			continue;

		/* Execute the next command */
898
		if (!priv->dnld_sent && !priv->cur_cmd)
899
			lbs_execute_next_command(priv);
900 901

		/* Wake-up command waiters which can't sleep in
902
		 * lbs_prepare_and_send_command
903
		 */
904 905
		if (!list_empty(&priv->cmdpendingq))
			wake_up_all(&priv->cmd_pending);
906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927

		spin_lock_irq(&priv->driver_lock);
		if (!priv->dnld_sent && priv->tx_pending_len > 0) {
			int ret = priv->hw_host_to_card(priv, MVMS_DAT,
							priv->tx_pending_buf,
							priv->tx_pending_len);
			if (ret) {
				lbs_deb_tx("host_to_card failed %d\n", ret);
				priv->dnld_sent = DNLD_RES_RECEIVED;
			}
			priv->tx_pending_len = 0;
			if (!priv->currenttxskb) {
				/* We can wake the queues immediately if we aren't
				   waiting for TX feedback */
				if (priv->connect_status == LBS_CONNECTED)
					netif_wake_queue(priv->dev);
				if (priv->mesh_dev &&
				    priv->mesh_connect_status == LBS_CONNECTED)
					netif_wake_queue(priv->mesh_dev);
			}
		}
		spin_unlock_irq(&priv->driver_lock);
928 929
	}

930 931
	del_timer(&priv->command_timer);
	wake_up_all(&priv->cmd_pending);
932

933
	lbs_deb_leave(LBS_DEB_THREAD);
934 935 936
	return 0;
}

937 938 939
static int lbs_suspend_callback(struct lbs_private *priv, unsigned long dummy,
				struct cmd_header *cmd)
{
940
	lbs_deb_enter(LBS_DEB_FW);
941 942 943 944 945 946

	netif_device_detach(priv->dev);
	if (priv->mesh_dev)
		netif_device_detach(priv->mesh_dev);

	priv->fw_ready = 0;
947
	lbs_deb_leave(LBS_DEB_FW);
948 949 950 951 952 953 954 955
	return 0;
}

int lbs_suspend(struct lbs_private *priv)
{
	struct cmd_header cmd;
	int ret;

956 957
	lbs_deb_enter(LBS_DEB_FW);

958 959 960 961 962
	if (priv->wol_criteria == 0xffffffff) {
		lbs_pr_info("Suspend attempt without configuring wake params!\n");
		return -EINVAL;
	}

963
	memset(&cmd, 0, sizeof(cmd));
964

965 966 967 968 969
	ret = __lbs_cmd(priv, CMD_802_11_HOST_SLEEP_ACTIVATE, &cmd,
			sizeof(cmd), lbs_suspend_callback, 0);
	if (ret)
		lbs_pr_info("HOST_SLEEP_ACTIVATE failed: %d\n", ret);

970
	lbs_deb_leave_args(LBS_DEB_FW, "ret %d", ret);
971 972 973 974
	return ret;
}
EXPORT_SYMBOL_GPL(lbs_suspend);

975
void lbs_resume(struct lbs_private *priv)
976
{
977 978
	lbs_deb_enter(LBS_DEB_FW);

979 980 981 982 983 984 985 986 987 988 989
	priv->fw_ready = 1;

	/* Firmware doesn't seem to give us RX packets any more
	   until we send it some command. Might as well update */
	lbs_prepare_and_send_command(priv, CMD_802_11_RSSI, 0,
				     0, 0, NULL);

	netif_device_attach(priv->dev);
	if (priv->mesh_dev)
		netif_device_attach(priv->mesh_dev);

990
	lbs_deb_leave(LBS_DEB_FW);
991 992 993
}
EXPORT_SYMBOL_GPL(lbs_resume);

H
Holger Schurig 已提交
994
/**
995 996
 * @brief This function gets the HW spec from the firmware and sets
 *        some basic parameters.
H
Holger Schurig 已提交
997
 *
998
 *  @param priv    A pointer to struct lbs_private structure
H
Holger Schurig 已提交
999 1000
 *  @return 	   0 or -1
 */
1001
static int lbs_setup_firmware(struct lbs_private *priv)
H
Holger Schurig 已提交
1002 1003
{
	int ret = -1;
1004
	s16 curlevel = 0, minlevel = 0, maxlevel = 0;
H
Holger Schurig 已提交
1005 1006 1007

	lbs_deb_enter(LBS_DEB_FW);

1008
	/* Read MAC address from firmware */
1009
	memset(priv->current_addr, 0xff, ETH_ALEN);
1010
	ret = lbs_update_hw_spec(priv);
1011
	if (ret)
H
Holger Schurig 已提交
1012 1013
		goto done;

1014 1015 1016 1017 1018 1019 1020 1021
	/* Read power levels if available */
	ret = lbs_get_tx_power(priv, &curlevel, &minlevel, &maxlevel);
	if (ret == 0) {
		priv->txpower_cur = curlevel;
		priv->txpower_min = minlevel;
		priv->txpower_max = maxlevel;
	}

1022
	lbs_set_mac_control(priv);
H
Holger Schurig 已提交
1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033
done:
	lbs_deb_leave_args(LBS_DEB_FW, "ret %d", ret);
	return ret;
}

/**
 *  This function handles the timeout of command sending.
 *  It will re-send the same command again.
 */
static void command_timer_fn(unsigned long data)
{
1034
	struct lbs_private *priv = (struct lbs_private *)data;
H
Holger Schurig 已提交
1035 1036
	unsigned long flags;

1037
	lbs_deb_enter(LBS_DEB_CMD);
1038
	spin_lock_irqsave(&priv->driver_lock, flags);
H
Holger Schurig 已提交
1039

1040
	if (!priv->cur_cmd)
1041
		goto out;
H
Holger Schurig 已提交
1042

1043 1044
	lbs_pr_info("command 0x%04x timed out\n",
		le16_to_cpu(priv->cur_cmd->cmdbuf->command));
H
Holger Schurig 已提交
1045

1046
	priv->cmd_timed_out = 1;
H
Holger Schurig 已提交
1047
	wake_up_interruptible(&priv->waitq);
1048
out:
1049
	spin_unlock_irqrestore(&priv->driver_lock, flags);
1050
	lbs_deb_leave(LBS_DEB_CMD);
H
Holger Schurig 已提交
1051 1052
}

1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064
static void lbs_sync_channel_worker(struct work_struct *work)
{
	struct lbs_private *priv = container_of(work, struct lbs_private,
		sync_channel);

	lbs_deb_enter(LBS_DEB_MAIN);
	if (lbs_update_channel(priv))
		lbs_pr_info("Channel synchronization failed.");
	lbs_deb_leave(LBS_DEB_MAIN);
}


1065
static int lbs_init_adapter(struct lbs_private *priv)
1066
{
H
Holger Schurig 已提交
1067
	size_t bufsize;
1068
	int i, ret = 0;
H
Holger Schurig 已提交
1069

1070 1071
	lbs_deb_enter(LBS_DEB_MAIN);

H
Holger Schurig 已提交
1072 1073
	/* Allocate buffer to store the BSSID list */
	bufsize = MAX_NETWORK_COUNT * sizeof(struct bss_descriptor);
1074 1075
	priv->networks = kzalloc(bufsize, GFP_KERNEL);
	if (!priv->networks) {
H
Holger Schurig 已提交
1076
		lbs_pr_err("Out of memory allocating beacons\n");
1077 1078
		ret = -1;
		goto out;
H
Holger Schurig 已提交
1079 1080
	}

1081
	/* Initialize scan result lists */
1082 1083
	INIT_LIST_HEAD(&priv->network_free_list);
	INIT_LIST_HEAD(&priv->network_list);
1084
	for (i = 0; i < MAX_NETWORK_COUNT; i++) {
1085 1086
		list_add_tail(&priv->networks[i].list,
			      &priv->network_free_list);
1087
	}
H
Holger Schurig 已提交
1088

1089
	memset(priv->current_addr, 0xff, ETH_ALEN);
H
Holger Schurig 已提交
1090

1091 1092 1093 1094 1095
	priv->connect_status = LBS_DISCONNECTED;
	priv->mesh_connect_status = LBS_DISCONNECTED;
	priv->secinfo.auth_mode = IW_AUTH_ALG_OPEN_SYSTEM;
	priv->mode = IW_MODE_INFRA;
	priv->curbssparams.channel = DEFAULT_AD_HOC_CHANNEL;
1096
	priv->mac_control = CMD_ACT_MAC_RX_ON | CMD_ACT_MAC_TX_ON;
1097
	priv->radio_on = 1;
1098
	priv->enablehwauto = 1;
1099 1100 1101
	priv->capability = WLAN_CAPABILITY_SHORT_PREAMBLE;
	priv->psmode = LBS802_11POWERMODECAM;
	priv->psstate = PS_STATE_FULL_POWER;
H
Holger Schurig 已提交
1102

1103
	mutex_init(&priv->lock);
H
Holger Schurig 已提交
1104

1105
	setup_timer(&priv->command_timer, command_timer_fn,
1106
		(unsigned long)priv);
H
Holger Schurig 已提交
1107

1108 1109
	INIT_LIST_HEAD(&priv->cmdfreeq);
	INIT_LIST_HEAD(&priv->cmdpendingq);
H
Holger Schurig 已提交
1110

1111 1112
	spin_lock_init(&priv->driver_lock);
	init_waitqueue_head(&priv->cmd_pending);
H
Holger Schurig 已提交
1113

1114
	/* Allocate the command buffers */
1115
	if (lbs_allocate_cmd_buffer(priv)) {
1116
		lbs_pr_err("Out of memory allocating command buffers\n");
1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128
		ret = -ENOMEM;
		goto out;
	}
	priv->resp_idx = 0;
	priv->resp_len[0] = priv->resp_len[1] = 0;

	/* Create the event FIFO */
	priv->event_fifo = kfifo_alloc(sizeof(u32) * 16, GFP_KERNEL, NULL);
	if (IS_ERR(priv->event_fifo)) {
		lbs_pr_err("Out of memory allocating event FIFO buffer\n");
		ret = -ENOMEM;
		goto out;
1129
	}
H
Holger Schurig 已提交
1130

1131
out:
1132 1133
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);

1134 1135
	return ret;
}
H
Holger Schurig 已提交
1136

1137
static void lbs_free_adapter(struct lbs_private *priv)
1138
{
1139
	lbs_deb_enter(LBS_DEB_MAIN);
H
Holger Schurig 已提交
1140

1141
	lbs_free_cmd_buffer(priv);
1142 1143
	if (priv->event_fifo)
		kfifo_free(priv->event_fifo);
1144 1145 1146
	del_timer(&priv->command_timer);
	kfree(priv->networks);
	priv->networks = NULL;
1147 1148

	lbs_deb_leave(LBS_DEB_MAIN);
H
Holger Schurig 已提交
1149 1150
}

1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161
static const struct net_device_ops lbs_netdev_ops = {
	.ndo_open 		= lbs_dev_open,
	.ndo_stop		= lbs_eth_stop,
	.ndo_start_xmit		= lbs_hard_start_xmit,
	.ndo_set_mac_address	= lbs_set_mac_address,
	.ndo_tx_timeout 	= lbs_tx_timeout,
	.ndo_set_multicast_list = lbs_set_multicast_list,
	.ndo_change_mtu		= eth_change_mtu,
	.ndo_validate_addr	= eth_validate_addr,
};

1162 1163
/**
 * @brief This function adds the card. it will probe the
1164
 * card, allocate the lbs_priv and initialize the device.
1165 1166
 *
 *  @param card    A pointer to card
1167
 *  @return 	   A pointer to struct lbs_private structure
1168
 */
1169
struct lbs_private *lbs_add_card(void *card, struct device *dmdev)
1170 1171
{
	struct net_device *dev = NULL;
1172
	struct lbs_private *priv = NULL;
1173

1174
	lbs_deb_enter(LBS_DEB_MAIN);
1175 1176

	/* Allocate an Ethernet device and register it */
1177 1178
	dev = alloc_etherdev(sizeof(struct lbs_private));
	if (!dev) {
1179
		lbs_pr_err("init wlanX device failed\n");
1180
		goto done;
1181
	}
1182
	priv = netdev_priv(dev);
1183
	dev->ml_priv = priv;
1184

1185
	if (lbs_init_adapter(priv)) {
1186 1187 1188 1189
		lbs_pr_err("failed to initialize adapter structure.\n");
		goto err_init_adapter;
	}

1190 1191
	priv->dev = dev;
	priv->card = card;
1192 1193 1194 1195
	priv->mesh_open = 0;
	priv->infra_open = 0;

	/* Setup the OS Interface to our functions */
1196
 	dev->netdev_ops = &lbs_netdev_ops;
1197
	dev->watchdog_timeo = 5 * HZ;
1198
	dev->ethtool_ops = &lbs_ethtool_ops;
1199
#ifdef	WIRELESS_EXT
1200
	dev->wireless_handlers = &lbs_handler_def;
1201 1202 1203
#endif
	dev->flags |= IFF_BROADCAST | IFF_MULTICAST;

1204 1205
	SET_NETDEV_DEV(dev, dmdev);

1206
	priv->rtap_net_dev = NULL;
1207
	strcpy(dev->name, "wlan%d");
1208 1209 1210

	lbs_deb_thread("Starting main thread...\n");
	init_waitqueue_head(&priv->waitq);
1211
	priv->main_thread = kthread_run(lbs_thread, dev, "lbs_main");
1212 1213
	if (IS_ERR(priv->main_thread)) {
		lbs_deb_thread("Error creating main thread.\n");
1214
		goto err_init_adapter;
1215 1216
	}

1217 1218 1219
	priv->work_thread = create_singlethread_workqueue("lbs_worker");
	INIT_DELAYED_WORK(&priv->assoc_work, lbs_association_worker);
	INIT_DELAYED_WORK(&priv->scan_work, lbs_scan_worker);
1220
	INIT_WORK(&priv->mcast_work, lbs_set_mcast_worker);
1221
	INIT_WORK(&priv->sync_channel, lbs_sync_channel_worker);
1222

1223 1224 1225
	sprintf(priv->mesh_ssid, "mesh");
	priv->mesh_ssid_len = 4;

1226 1227 1228
	priv->wol_criteria = 0xffffffff;
	priv->wol_gpio = 0xff;

1229 1230
	goto done;

1231
err_init_adapter:
1232
	lbs_free_adapter(priv);
1233
	free_netdev(dev);
1234
	priv = NULL;
1235

1236
done:
1237
	lbs_deb_leave_args(LBS_DEB_MAIN, "priv %p", priv);
1238 1239
	return priv;
}
1240
EXPORT_SYMBOL_GPL(lbs_add_card);
1241

1242

1243
void lbs_remove_card(struct lbs_private *priv)
1244
{
1245
	struct net_device *dev = priv->dev;
1246
	union iwreq_data wrqu;
1247 1248

	lbs_deb_enter(LBS_DEB_MAIN);
1249

1250
	lbs_remove_mesh(priv);
1251
	lbs_remove_rtap(priv);
1252

1253
	dev = priv->dev;
1254

1255 1256
	cancel_delayed_work_sync(&priv->scan_work);
	cancel_delayed_work_sync(&priv->assoc_work);
1257
	cancel_work_sync(&priv->mcast_work);
1258 1259 1260 1261 1262

	/* worker thread destruction blocks on the in-flight command which
	 * should have been cleared already in lbs_stop_card().
	 */
	lbs_deb_main("destroying worker thread\n");
1263
	destroy_workqueue(priv->work_thread);
1264
	lbs_deb_main("done destroying worker thread\n");
1265

1266 1267
	if (priv->psmode == LBS802_11POWERMODEMAX_PSP) {
		priv->psmode = LBS802_11POWERMODECAM;
1268
		lbs_ps_wakeup(priv, CMD_OPTION_WAITFORRSP);
1269 1270
	}

1271 1272 1273 1274 1275
	memset(wrqu.ap_addr.sa_data, 0xaa, ETH_ALEN);
	wrqu.ap_addr.sa_family = ARPHRD_ETHER;
	wireless_send_event(priv->dev, SIOCGIWAP, &wrqu, NULL);

	/* Stop the thread servicing the interrupts */
1276
	priv->surpriseremoved = 1;
1277 1278
	kthread_stop(priv->main_thread);

1279
	lbs_free_adapter(priv);
1280 1281 1282 1283 1284 1285

	priv->dev = NULL;
	free_netdev(dev);

	lbs_deb_leave(LBS_DEB_MAIN);
}
1286
EXPORT_SYMBOL_GPL(lbs_remove_card);
1287 1288


1289
int lbs_start_card(struct lbs_private *priv)
1290 1291 1292 1293 1294 1295 1296
{
	struct net_device *dev = priv->dev;
	int ret = -1;

	lbs_deb_enter(LBS_DEB_MAIN);

	/* poke the firmware */
1297
	ret = lbs_setup_firmware(priv);
1298 1299 1300 1301
	if (ret)
		goto done;

	/* init 802.11d */
1302
	lbs_init_11d(priv);
1303 1304

	if (register_netdev(dev)) {
1305
		lbs_pr_err("cannot register ethX device\n");
1306
		goto done;
1307
	}
1308 1309 1310

	lbs_update_channel(priv);

1311 1312 1313 1314
	/* Check mesh FW version and appropriately send the mesh start
	 * command
	 */
	if (priv->mesh_fw_ver == MESH_FW_OLD) {
1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327
		/* Enable mesh, if supported, and work out which TLV it uses.
		   0x100 + 291 is an unofficial value used in 5.110.20.pXX
		   0x100 + 37 is the official value used in 5.110.21.pXX
		   but we check them in that order because 20.pXX doesn't
		   give an error -- it just silently fails. */

		/* 5.110.20.pXX firmware will fail the command if the channel
		   doesn't match the existing channel. But only if the TLV
		   is correct. If the channel is wrong, _BOTH_ versions will
		   give an error to 0x100+291, and allow 0x100+37 to succeed.
		   It's just that 5.110.20.pXX will not have done anything
		   useful */

1328
		priv->mesh_tlv = TLV_TYPE_OLD_MESH_ID;
1329 1330
		if (lbs_mesh_config(priv, CMD_ACT_MESH_CONFIG_START,
				    priv->curbssparams.channel)) {
1331
			priv->mesh_tlv = TLV_TYPE_MESH_ID;
1332 1333
			if (lbs_mesh_config(priv, CMD_ACT_MESH_CONFIG_START,
					    priv->curbssparams.channel))
1334 1335
				priv->mesh_tlv = 0;
		}
1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356
	} else if (priv->mesh_fw_ver == MESH_FW_NEW) {
		/* 10.0.0.pXX new firmwares should succeed with TLV
		 * 0x100+37; Do not invoke command with old TLV.
		 */
		priv->mesh_tlv = TLV_TYPE_MESH_ID;
		if (lbs_mesh_config(priv, CMD_ACT_MESH_CONFIG_START,
				    priv->curbssparams.channel))
			priv->mesh_tlv = 0;
	}
	if (priv->mesh_tlv) {
		lbs_add_mesh(priv);

		if (device_create_file(&dev->dev, &dev_attr_lbs_mesh))
			lbs_pr_err("cannot register lbs_mesh attribute\n");

		/* While rtap isn't related to mesh, only mesh-enabled
		 * firmware implements the rtap functionality via
		 * CMD_802_11_MONITOR_MODE.
		 */
		if (device_create_file(&dev->dev, &dev_attr_lbs_rtap))
			lbs_pr_err("cannot register lbs_rtap attribute\n");
1357
	}
1358

1359
	lbs_debugfs_init_one(priv, dev);
1360

1361 1362
	lbs_pr_info("%s: Marvell WLAN 802.11 adapter\n", dev->name);

1363
	ret = 0;
1364

1365
done:
1366 1367 1368
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
	return ret;
}
1369
EXPORT_SYMBOL_GPL(lbs_start_card);
1370 1371


1372
void lbs_stop_card(struct lbs_private *priv)
1373
{
1374
	struct net_device *dev;
1375 1376 1377 1378 1379
	struct cmd_ctrl_node *cmdnode;
	unsigned long flags;

	lbs_deb_enter(LBS_DEB_MAIN);

1380 1381
	if (!priv)
		goto out;
1382
	dev = priv->dev;
1383

1384 1385
	netif_stop_queue(dev);
	netif_carrier_off(dev);
1386

1387
	lbs_debugfs_remove_one(priv);
1388
	if (priv->mesh_tlv) {
1389
		device_remove_file(&dev->dev, &dev_attr_lbs_mesh);
1390
		device_remove_file(&dev->dev, &dev_attr_lbs_rtap);
1391
	}
1392

1393
	/* Delete the timeout of the currently processing command */
1394
	del_timer_sync(&priv->command_timer);
1395 1396

	/* Flush pending command nodes */
1397
	spin_lock_irqsave(&priv->driver_lock, flags);
1398
	lbs_deb_main("clearing pending commands\n");
1399
	list_for_each_entry(cmdnode, &priv->cmdpendingq, list) {
1400
		cmdnode->result = -ENOENT;
1401 1402 1403
		cmdnode->cmdwaitqwoken = 1;
		wake_up_interruptible(&cmdnode->cmdwait_q);
	}
1404 1405 1406 1407 1408 1409 1410 1411 1412

	/* Flush the command the card is currently processing */
	if (priv->cur_cmd) {
		lbs_deb_main("clearing current command\n");
		priv->cur_cmd->result = -ENOENT;
		priv->cur_cmd->cmdwaitqwoken = 1;
		wake_up_interruptible(&priv->cur_cmd->cmdwait_q);
	}
	lbs_deb_main("done clearing commands\n");
1413
	spin_unlock_irqrestore(&priv->driver_lock, flags);
1414 1415 1416

	unregister_netdev(dev);

1417
out:
1418
	lbs_deb_leave(LBS_DEB_MAIN);
1419
}
1420
EXPORT_SYMBOL_GPL(lbs_stop_card);
1421

1422

1423 1424 1425 1426 1427 1428 1429 1430
static const struct net_device_ops mesh_netdev_ops = {
	.ndo_open		= lbs_dev_open,
	.ndo_stop 		= lbs_mesh_stop,
	.ndo_start_xmit		= lbs_hard_start_xmit,
	.ndo_set_mac_address	= lbs_set_mac_address,
	.ndo_set_multicast_list = lbs_set_multicast_list,
};

1431 1432 1433
/**
 * @brief This function adds mshX interface
 *
1434
 *  @param priv    A pointer to the struct lbs_private structure
1435 1436
 *  @return 	   0 if successful, -X otherwise
 */
1437
static int lbs_add_mesh(struct lbs_private *priv)
1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449
{
	struct net_device *mesh_dev = NULL;
	int ret = 0;

	lbs_deb_enter(LBS_DEB_MESH);

	/* Allocate a virtual mesh device */
	if (!(mesh_dev = alloc_netdev(0, "msh%d", ether_setup))) {
		lbs_deb_mesh("init mshX device failed\n");
		ret = -ENOMEM;
		goto done;
	}
1450
	mesh_dev->ml_priv = priv;
1451 1452
	priv->mesh_dev = mesh_dev;

1453
	mesh_dev->netdev_ops = &mesh_netdev_ops;
1454
	mesh_dev->ethtool_ops = &lbs_ethtool_ops;
1455 1456
	memcpy(mesh_dev->dev_addr, priv->dev->dev_addr,
			sizeof(priv->dev->dev_addr));
1457

1458
	SET_NETDEV_DEV(priv->mesh_dev, priv->dev->dev.parent);
1459

1460
#ifdef	WIRELESS_EXT
1461
	mesh_dev->wireless_handlers = (struct iw_handler_def *)&mesh_handler_def;
1462
#endif
1463
	mesh_dev->flags |= IFF_BROADCAST | IFF_MULTICAST;
1464 1465 1466 1467 1468 1469 1470
	/* Register virtual mesh interface */
	ret = register_netdev(mesh_dev);
	if (ret) {
		lbs_pr_err("cannot register mshX virtual interface\n");
		goto err_free;
	}

1471
	ret = sysfs_create_group(&(mesh_dev->dev.kobj), &lbs_mesh_attr_group);
1472 1473 1474
	if (ret)
		goto err_unregister;

1475 1476
	lbs_persist_config_init(mesh_dev);

1477 1478 1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489 1490
	/* Everything successful */
	ret = 0;
	goto done;

err_unregister:
	unregister_netdev(mesh_dev);

err_free:
	free_netdev(mesh_dev);

done:
	lbs_deb_leave_args(LBS_DEB_MESH, "ret %d", ret);
	return ret;
}
1491

1492
static void lbs_remove_mesh(struct lbs_private *priv)
1493 1494 1495 1496 1497
{
	struct net_device *mesh_dev;


	mesh_dev = priv->mesh_dev;
1498
	if (!mesh_dev)
1499
		return;
1500

1501
	lbs_deb_enter(LBS_DEB_MESH);
1502
	netif_stop_queue(mesh_dev);
1503
	netif_carrier_off(mesh_dev);
1504
	sysfs_remove_group(&(mesh_dev->dev.kobj), &lbs_mesh_attr_group);
1505
	lbs_persist_config_remove(mesh_dev);
1506
	unregister_netdev(mesh_dev);
1507
	priv->mesh_dev = NULL;
1508
	free_netdev(mesh_dev);
1509
	lbs_deb_leave(LBS_DEB_MESH);
1510 1511
}

1512 1513 1514 1515 1516 1517 1518 1519 1520
/**
 *  @brief This function finds the CFP in
 *  region_cfp_table based on region and band parameter.
 *
 *  @param region  The region code
 *  @param band	   The band
 *  @param cfp_no  A pointer to CFP number
 *  @return 	   A pointer to CFP
 */
1521
struct chan_freq_power *lbs_get_region_cfp_table(u8 region, int *cfp_no)
1522 1523 1524
{
	int i, end;

1525
	lbs_deb_enter(LBS_DEB_MAIN);
1526

1527
	end = ARRAY_SIZE(region_cfp_table);
1528 1529

	for (i = 0; i < end ; i++) {
1530
		lbs_deb_main("region_cfp_table[i].region=%d\n",
1531 1532 1533
			region_cfp_table[i].region);
		if (region_cfp_table[i].region == region) {
			*cfp_no = region_cfp_table[i].cfp_no_BG;
1534
			lbs_deb_leave(LBS_DEB_MAIN);
1535 1536 1537 1538
			return region_cfp_table[i].cfp_BG;
		}
	}

1539
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret NULL");
1540 1541 1542
	return NULL;
}

1543
int lbs_set_regiontable(struct lbs_private *priv, u8 region, u8 band)
1544
{
1545
	int ret = 0;
1546 1547 1548 1549 1550
	int i = 0;

	struct chan_freq_power *cfp;
	int cfp_no;

1551
	lbs_deb_enter(LBS_DEB_MAIN);
1552

1553
	memset(priv->region_channel, 0, sizeof(priv->region_channel));
1554

1555
	cfp = lbs_get_region_cfp_table(region, &cfp_no);
1556 1557 1558 1559 1560 1561 1562 1563
	if (cfp != NULL) {
		priv->region_channel[i].nrcfp = cfp_no;
		priv->region_channel[i].CFP = cfp;
	} else {
		lbs_deb_main("wrong region code %#x in band B/G\n",
		       region);
		ret = -1;
		goto out;
1564
	}
1565 1566 1567 1568
	priv->region_channel[i].valid = 1;
	priv->region_channel[i].region = region;
	priv->region_channel[i].band = band;
	i++;
1569 1570 1571
out:
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
	return ret;
1572 1573
}

1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593
void lbs_queue_event(struct lbs_private *priv, u32 event)
{
	unsigned long flags;

	lbs_deb_enter(LBS_DEB_THREAD);
	spin_lock_irqsave(&priv->driver_lock, flags);

	if (priv->psstate == PS_STATE_SLEEP)
		priv->psstate = PS_STATE_AWAKE;

	__kfifo_put(priv->event_fifo, (unsigned char *) &event, sizeof(u32));

	wake_up_interruptible(&priv->waitq);

	spin_unlock_irqrestore(&priv->driver_lock, flags);
	lbs_deb_leave(LBS_DEB_THREAD);
}
EXPORT_SYMBOL_GPL(lbs_queue_event);

void lbs_notify_command_response(struct lbs_private *priv, u8 resp_idx)
1594
{
1595
	lbs_deb_enter(LBS_DEB_THREAD);
1596

1597
	if (priv->psstate == PS_STATE_SLEEP)
1598
		priv->psstate = PS_STATE_AWAKE;
1599 1600 1601 1602 1603

	/* Swap buffers by flipping the response index */
	BUG_ON(resp_idx > 1);
	priv->resp_idx = resp_idx;

1604
	wake_up_interruptible(&priv->waitq);
1605

1606
	lbs_deb_leave(LBS_DEB_THREAD);
1607
}
1608
EXPORT_SYMBOL_GPL(lbs_notify_command_response);
1609

1610
static int __init lbs_init_module(void)
1611
{
1612
	lbs_deb_enter(LBS_DEB_MAIN);
1613 1614 1615 1616
	memset(&confirm_sleep, 0, sizeof(confirm_sleep));
	confirm_sleep.hdr.command = cpu_to_le16(CMD_802_11_PS_MODE);
	confirm_sleep.hdr.size = cpu_to_le16(sizeof(confirm_sleep));
	confirm_sleep.action = cpu_to_le16(CMD_SUBCMD_SLEEP_CONFIRMED);
1617
	lbs_debugfs_init();
1618 1619
	lbs_deb_leave(LBS_DEB_MAIN);
	return 0;
1620 1621
}

1622
static void __exit lbs_exit_module(void)
1623
{
1624
	lbs_deb_enter(LBS_DEB_MAIN);
1625
	lbs_debugfs_remove();
1626
	lbs_deb_leave(LBS_DEB_MAIN);
1627 1628
}

1629 1630 1631 1632
/*
 * rtap interface support fuctions
 */

1633
static int lbs_rtap_open(struct net_device *dev)
1634
{
1635
	/* Yes, _stop_ the queue. Because we don't support injection */
1636 1637 1638 1639 1640
	lbs_deb_enter(LBS_DEB_MAIN);
	netif_carrier_off(dev);
	netif_stop_queue(dev);
	lbs_deb_leave(LBS_DEB_LEAVE);
	return 0;
1641 1642
}

1643
static int lbs_rtap_stop(struct net_device *dev)
1644
{
1645 1646 1647
	lbs_deb_enter(LBS_DEB_MAIN);
	lbs_deb_leave(LBS_DEB_MAIN);
	return 0;
1648 1649
}

1650 1651
static netdev_tx_t lbs_rtap_hard_start_xmit(struct sk_buff *skb,
					    struct net_device *dev)
1652
{
1653 1654
	netif_stop_queue(dev);
	return NETDEV_TX_BUSY;
1655 1656
}

1657
static void lbs_remove_rtap(struct lbs_private *priv)
1658
{
1659
	lbs_deb_enter(LBS_DEB_MAIN);
1660
	if (priv->rtap_net_dev == NULL)
1661
		goto out;
1662
	unregister_netdev(priv->rtap_net_dev);
1663
	free_netdev(priv->rtap_net_dev);
1664
	priv->rtap_net_dev = NULL;
1665
out:
1666
	lbs_deb_leave(LBS_DEB_MAIN);
1667 1668
}

1669 1670 1671 1672 1673 1674
static const struct net_device_ops rtap_netdev_ops = {
	.ndo_open = lbs_rtap_open,
	.ndo_stop = lbs_rtap_stop,
	.ndo_start_xmit = lbs_rtap_hard_start_xmit,
};

1675
static int lbs_add_rtap(struct lbs_private *priv)
1676
{
1677
	int ret = 0;
1678
	struct net_device *rtap_dev;
1679

1680 1681 1682 1683 1684
	lbs_deb_enter(LBS_DEB_MAIN);
	if (priv->rtap_net_dev) {
		ret = -EPERM;
		goto out;
	}
1685

1686
	rtap_dev = alloc_netdev(0, "rtap%d", ether_setup);
1687 1688 1689 1690
	if (rtap_dev == NULL) {
		ret = -ENOMEM;
		goto out;
	}
1691

1692
	memcpy(rtap_dev->dev_addr, priv->current_addr, ETH_ALEN);
1693
	rtap_dev->type = ARPHRD_IEEE80211_RADIOTAP;
1694
	rtap_dev->netdev_ops = &rtap_netdev_ops;
1695
	rtap_dev->ml_priv = priv;
1696
	SET_NETDEV_DEV(rtap_dev, priv->dev->dev.parent);
1697

1698 1699
	ret = register_netdev(rtap_dev);
	if (ret) {
1700
		free_netdev(rtap_dev);
1701
		goto out;
1702
	}
1703
	priv->rtap_net_dev = rtap_dev;
1704

1705 1706 1707
out:
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
	return ret;
1708 1709
}

1710 1711
module_init(lbs_init_module);
module_exit(lbs_exit_module);
1712

1713
MODULE_DESCRIPTION("Libertas WLAN Driver Library");
1714 1715
MODULE_AUTHOR("Marvell International Ltd.");
MODULE_LICENSE("GPL");