agg-tx.c 21.5 KB
Newer Older
J
Johannes Berg 已提交
1 2 3 4 5 6 7 8
/*
 * HT handling
 *
 * Copyright 2003, Jouni Malinen <jkmaline@cc.hut.fi>
 * Copyright 2002-2005, Instant802 Networks, Inc.
 * Copyright 2005-2006, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
 * Copyright 2007, Michael Wu <flamingice@sourmilk.net>
9
 * Copyright 2007-2010, Intel Corporation
J
Johannes Berg 已提交
10 11 12 13 14 15 16
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#include <linux/ieee80211.h>
17
#include <linux/slab.h>
J
Johannes Berg 已提交
18 19
#include <net/mac80211.h>
#include "ieee80211_i.h"
20
#include "driver-ops.h"
J
Johannes Berg 已提交
21 22
#include "wme.h"

23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47
/**
 * DOC: TX aggregation
 *
 * Aggregation on the TX side requires setting the hardware flag
 * %IEEE80211_HW_AMPDU_AGGREGATION as well as, if present, the @ampdu_queues
 * hardware parameter to the number of hardware AMPDU queues. If there are no
 * hardware queues then the driver will (currently) have to do all frame
 * buffering.
 *
 * When TX aggregation is started by some subsystem (usually the rate control
 * algorithm would be appropriate) by calling the
 * ieee80211_start_tx_ba_session() function, the driver will be notified via
 * its @ampdu_action function, with the %IEEE80211_AMPDU_TX_START action.
 *
 * In response to that, the driver is later required to call the
 * ieee80211_start_tx_ba_cb() (or ieee80211_start_tx_ba_cb_irqsafe())
 * function, which will start the aggregation session.
 *
 * Similarly, when the aggregation session is stopped by
 * ieee80211_stop_tx_ba_session(), the driver's @ampdu_action function will
 * be called with the action %IEEE80211_AMPDU_TX_STOP. In this case, the
 * call must not fail, and the driver must later call ieee80211_stop_tx_ba_cb()
 * (or ieee80211_stop_tx_ba_cb_irqsafe()).
 */

J
Johannes Berg 已提交
48 49 50 51 52 53 54 55 56 57 58 59 60 61
static void ieee80211_send_addba_request(struct ieee80211_sub_if_data *sdata,
					 const u8 *da, u16 tid,
					 u8 dialog_token, u16 start_seq_num,
					 u16 agg_size, u16 timeout)
{
	struct ieee80211_local *local = sdata->local;
	struct sk_buff *skb;
	struct ieee80211_mgmt *mgmt;
	u16 capab;

	skb = dev_alloc_skb(sizeof(*mgmt) + local->hw.extra_tx_headroom);

	if (!skb) {
		printk(KERN_ERR "%s: failed to allocate buffer "
62
				"for addba request frame\n", sdata->name);
J
Johannes Berg 已提交
63 64 65 66 67 68
		return;
	}
	skb_reserve(skb, local->hw.extra_tx_headroom);
	mgmt = (struct ieee80211_mgmt *) skb_put(skb, 24);
	memset(mgmt, 0, 24);
	memcpy(mgmt->da, da, ETH_ALEN);
69
	memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
70 71
	if (sdata->vif.type == NL80211_IFTYPE_AP ||
	    sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
72
		memcpy(mgmt->bssid, sdata->vif.addr, ETH_ALEN);
73 74
	else if (sdata->vif.type == NL80211_IFTYPE_STATION)
		memcpy(mgmt->bssid, sdata->u.mgd.bssid, ETH_ALEN);
J
Johannes Berg 已提交
75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94

	mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
					  IEEE80211_STYPE_ACTION);

	skb_put(skb, 1 + sizeof(mgmt->u.action.u.addba_req));

	mgmt->u.action.category = WLAN_CATEGORY_BACK;
	mgmt->u.action.u.addba_req.action_code = WLAN_ACTION_ADDBA_REQ;

	mgmt->u.action.u.addba_req.dialog_token = dialog_token;
	capab = (u16)(1 << 1);		/* bit 1 aggregation policy */
	capab |= (u16)(tid << 2); 	/* bit 5:2 TID number */
	capab |= (u16)(agg_size << 6);	/* bit 15:6 max size of aggergation */

	mgmt->u.action.u.addba_req.capab = cpu_to_le16(capab);

	mgmt->u.action.u.addba_req.timeout = cpu_to_le16(timeout);
	mgmt->u.action.u.addba_req.start_seq_num =
					cpu_to_le16(start_seq_num << 4);

95
	ieee80211_tx_skb(sdata, skb);
J
Johannes Berg 已提交
96 97 98 99 100 101 102 103 104 105 106 107
}

void ieee80211_send_bar(struct ieee80211_sub_if_data *sdata, u8 *ra, u16 tid, u16 ssn)
{
	struct ieee80211_local *local = sdata->local;
	struct sk_buff *skb;
	struct ieee80211_bar *bar;
	u16 bar_control = 0;

	skb = dev_alloc_skb(sizeof(*bar) + local->hw.extra_tx_headroom);
	if (!skb) {
		printk(KERN_ERR "%s: failed to allocate buffer for "
108
			"bar frame\n", sdata->name);
J
Johannes Berg 已提交
109 110 111 112 113 114 115 116
		return;
	}
	skb_reserve(skb, local->hw.extra_tx_headroom);
	bar = (struct ieee80211_bar *)skb_put(skb, sizeof(*bar));
	memset(bar, 0, sizeof(*bar));
	bar->frame_control = cpu_to_le16(IEEE80211_FTYPE_CTL |
					 IEEE80211_STYPE_BACK_REQ);
	memcpy(bar->ra, ra, ETH_ALEN);
117
	memcpy(bar->ta, sdata->vif.addr, ETH_ALEN);
J
Johannes Berg 已提交
118 119 120 121 122 123
	bar_control |= (u16)IEEE80211_BAR_CTRL_ACK_POLICY_NORMAL;
	bar_control |= (u16)IEEE80211_BAR_CTRL_CBMTID_COMPRESSED_BA;
	bar_control |= (u16)(tid << 12);
	bar->control = cpu_to_le16(bar_control);
	bar->start_seq_num = cpu_to_le16(ssn);

124 125
	IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT;
	ieee80211_tx_skb(sdata, skb);
J
Johannes Berg 已提交
126 127
}

128 129 130 131 132 133 134 135
static void kfree_tid_tx(struct rcu_head *rcu_head)
{
	struct tid_ampdu_tx *tid_tx =
	    container_of(rcu_head, struct tid_ampdu_tx, rcu_head);

	kfree(tid_tx);
}

J
Johannes Berg 已提交
136 137
int ___ieee80211_stop_tx_ba_session(struct sta_info *sta, u16 tid,
				    enum ieee80211_back_parties initiator)
138
{
139
	struct ieee80211_local *local = sta->local;
140
	struct tid_ampdu_tx *tid_tx = sta->ampdu_mlme.tid_tx[tid];
141
	int ret;
142

143
	lockdep_assert_held(&sta->ampdu_mlme.mtx);
144

145
	if (!tid_tx)
146
		return -ENOENT;
147

148 149
	spin_lock_bh(&sta->lock);

150 151 152
	if (test_bit(HT_AGG_STATE_WANT_START, &tid_tx->state)) {
		/* not even started yet! */
		rcu_assign_pointer(sta->ampdu_mlme.tid_tx[tid], NULL);
153
		spin_unlock_bh(&sta->lock);
154 155 156 157
		call_rcu(&tid_tx->rcu_head, kfree_tid_tx);
		return 0;
	}

158 159
	spin_unlock_bh(&sta->lock);

160 161 162 163 164
#ifdef CONFIG_MAC80211_HT_DEBUG
	printk(KERN_DEBUG "Tx BA session stop requested for %pM tid %u\n",
	       sta->sta.addr, tid);
#endif /* CONFIG_MAC80211_HT_DEBUG */

165
	set_bit(HT_AGG_STATE_STOPPING, &tid_tx->state);
166

167 168 169 170 171 172
	/*
	 * After this packets are no longer handed right through
	 * to the driver but are put onto tid_tx->pending instead,
	 * with locking to ensure proper access.
	 */
	clear_bit(HT_AGG_STATE_OPERATIONAL, &tid_tx->state);
173

174
	tid_tx->stop_initiator = initiator;
175

J
Johannes Berg 已提交
176
	ret = drv_ampdu_action(local, sta->sdata,
177
			       IEEE80211_AMPDU_TX_STOP,
178
			       &sta->sta, tid, NULL);
179 180 181

	/* HW shall not deny going back to legacy */
	if (WARN_ON(ret)) {
182 183 184 185
		/*
		 * We may have pending packets get stuck in this case...
		 * Not bothering with a workaround for now.
		 */
186 187 188 189 190
	}

	return ret;
}

J
Johannes Berg 已提交
191 192 193 194 195 196 197 198 199 200 201 202
/*
 * After sending add Block Ack request we activated a timer until
 * add Block Ack response will arrive from the recipient.
 * If this timer expires sta_addba_resp_timer_expired will be executed.
 */
static void sta_addba_resp_timer_expired(unsigned long data)
{
	/* not an elegant detour, but there is no choice as the timer passes
	 * only one argument, and both sta_info and TID are needed, so init
	 * flow in sta_info_create gives the TID as data, while the timer_to_id
	 * array gives the sta through container_of */
	u16 tid = *(u8 *)data;
203
	struct sta_info *sta = container_of((void *)data,
J
Johannes Berg 已提交
204
		struct sta_info, timer_to_tid[tid]);
205
	struct tid_ampdu_tx *tid_tx;
206

J
Johannes Berg 已提交
207
	/* check if the TID waits for addBA response */
208 209
	rcu_read_lock();
	tid_tx = rcu_dereference(sta->ampdu_mlme.tid_tx[tid]);
210 211
	if (!tid_tx ||
	    test_bit(HT_AGG_STATE_RESPONSE_RECEIVED, &tid_tx->state)) {
212
		rcu_read_unlock();
J
Johannes Berg 已提交
213 214
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "timer expired on tid %d but we are not "
J
Johannes Berg 已提交
215
				"(or no longer) expecting addBA response there\n",
216
			tid);
J
Johannes Berg 已提交
217
#endif
218
		return;
J
Johannes Berg 已提交
219 220 221 222 223 224
	}

#ifdef CONFIG_MAC80211_HT_DEBUG
	printk(KERN_DEBUG "addBA response timer expired on tid %d\n", tid);
#endif

225 226
	ieee80211_stop_tx_ba_session(&sta->sta, tid);
	rcu_read_unlock();
J
Johannes Berg 已提交
227 228
}

229 230 231 232 233
static inline int ieee80211_ac_from_tid(int tid)
{
	return ieee802_1d_to_ac[tid & 7];
}

234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268
/*
 * When multiple aggregation sessions on multiple stations
 * are being created/destroyed simultaneously, we need to
 * refcount the global queue stop caused by that in order
 * to not get into a situation where one of the aggregation
 * setup or teardown re-enables queues before the other is
 * ready to handle that.
 *
 * These two functions take care of this issue by keeping
 * a global "agg_queue_stop" refcount.
 */
static void __acquires(agg_queue)
ieee80211_stop_queue_agg(struct ieee80211_local *local, int tid)
{
	int queue = ieee80211_ac_from_tid(tid);

	if (atomic_inc_return(&local->agg_queue_stop[queue]) == 1)
		ieee80211_stop_queue_by_reason(
			&local->hw, queue,
			IEEE80211_QUEUE_STOP_REASON_AGGREGATION);
	__acquire(agg_queue);
}

static void __releases(agg_queue)
ieee80211_wake_queue_agg(struct ieee80211_local *local, int tid)
{
	int queue = ieee80211_ac_from_tid(tid);

	if (atomic_dec_return(&local->agg_queue_stop[queue]) == 0)
		ieee80211_wake_queue_by_reason(
			&local->hw, queue,
			IEEE80211_QUEUE_STOP_REASON_AGGREGATION);
	__release(agg_queue);
}

J
Johannes Berg 已提交
269
void ieee80211_tx_ba_session_handle_start(struct sta_info *sta, int tid)
270 271 272 273 274 275 276
{
	struct tid_ampdu_tx *tid_tx = sta->ampdu_mlme.tid_tx[tid];
	struct ieee80211_local *local = sta->local;
	struct ieee80211_sub_if_data *sdata = sta->sdata;
	u16 start_seq_num;
	int ret;

277 278
	lockdep_assert_held(&sta->ampdu_mlme.mtx);

279 280 281 282 283 284 285 286 287 288 289 290
	/*
	 * While we're asking the driver about the aggregation,
	 * stop the AC queue so that we don't have to worry
	 * about frames that came in while we were doing that,
	 * which would require us to put them to the AC pending
	 * afterwards which just makes the code more complex.
	 */
	ieee80211_stop_queue_agg(local, tid);

	clear_bit(HT_AGG_STATE_WANT_START, &tid_tx->state);

	/*
291 292
	 * make sure no packets are being processed to get
	 * valid starting sequence number
293
	 */
294 295
	synchronize_net();

296 297 298 299 300 301 302 303 304
	start_seq_num = sta->tid_seq[tid] >> 4;

	ret = drv_ampdu_action(local, sdata, IEEE80211_AMPDU_TX_START,
			       &sta->sta, tid, &start_seq_num);
	if (ret) {
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "BA request denied - HW unavailable for"
					" tid %d\n", tid);
#endif
305
		spin_lock_bh(&sta->lock);
306
		rcu_assign_pointer(sta->ampdu_mlme.tid_tx[tid], NULL);
307 308
		spin_unlock_bh(&sta->lock);

309 310 311 312 313 314 315 316 317 318 319 320 321 322
		ieee80211_wake_queue_agg(local, tid);
		call_rcu(&tid_tx->rcu_head, kfree_tid_tx);
		return;
	}

	/* we can take packets again now */
	ieee80211_wake_queue_agg(local, tid);

	/* activate the timer for the recipient's addBA response */
	mod_timer(&tid_tx->addba_resp_timer, jiffies + ADDBA_RESP_INTERVAL);
#ifdef CONFIG_MAC80211_HT_DEBUG
	printk(KERN_DEBUG "activated addBA response timer on tid %d\n", tid);
#endif

323
	spin_lock_bh(&sta->lock);
324
	sta->ampdu_mlme.addba_req_num[tid]++;
325
	spin_unlock_bh(&sta->lock);
326 327 328 329 330 331 332

	/* send AddBA request */
	ieee80211_send_addba_request(sdata, sta->sta.addr, tid,
				     tid_tx->dialog_token, start_seq_num,
				     0x40, 5000);
}

333
int ieee80211_start_tx_ba_session(struct ieee80211_sta *pubsta, u16 tid)
J
Johannes Berg 已提交
334
{
335 336 337
	struct sta_info *sta = container_of(pubsta, struct sta_info, sta);
	struct ieee80211_sub_if_data *sdata = sta->sdata;
	struct ieee80211_local *local = sdata->local;
338
	struct tid_ampdu_tx *tid_tx;
339
	int ret = 0;
J
Johannes Berg 已提交
340

J
Johannes Berg 已提交
341 342
	trace_api_start_tx_ba_session(pubsta, tid);

343 344 345
	if (WARN_ON(!local->ops->ampdu_action))
		return -EINVAL;

346 347
	if ((tid >= STA_TID_NUM) ||
	    !(local->hw.flags & IEEE80211_HW_AMPDU_AGGREGATION))
J
Johannes Berg 已提交
348 349 350 351
		return -EINVAL;

#ifdef CONFIG_MAC80211_HT_DEBUG
	printk(KERN_DEBUG "Open BA session requested for %pM tid %u\n",
352
	       pubsta->addr, tid);
J
Johannes Berg 已提交
353 354
#endif /* CONFIG_MAC80211_HT_DEBUG */

355 356 357 358 359 360
	/*
	 * The aggregation code is not prepared to handle
	 * anything but STA/AP due to the BSSID handling.
	 * IBSS could work in the code but isn't supported
	 * by drivers or the standard.
	 */
361 362 363 364
	if (sdata->vif.type != NL80211_IFTYPE_STATION &&
	    sdata->vif.type != NL80211_IFTYPE_AP_VLAN &&
	    sdata->vif.type != NL80211_IFTYPE_AP)
		return -EINVAL;
365

366
	if (test_sta_flags(sta, WLAN_STA_BLOCK_BA)) {
367
#ifdef CONFIG_MAC80211_HT_DEBUG
368
		printk(KERN_DEBUG "BA sessions blocked. "
369 370
		       "Denying BA session request\n");
#endif
371
		return -EINVAL;
372 373
	}

J
Johannes Berg 已提交
374 375 376 377 378 379 380 381
	spin_lock_bh(&sta->lock);

	/* we have tried too many times, receiver does not want A-MPDU */
	if (sta->ampdu_mlme.addba_req_num[tid] > HT_AGG_MAX_RETRIES) {
		ret = -EBUSY;
		goto err_unlock_sta;
	}

382
	tid_tx = sta->ampdu_mlme.tid_tx[tid];
J
Johannes Berg 已提交
383
	/* check if the TID is not in aggregation flow already */
384
	if (tid_tx) {
J
Johannes Berg 已提交
385 386 387 388 389 390 391 392 393
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "BA request denied - session is not "
				 "idle on tid %u\n", tid);
#endif /* CONFIG_MAC80211_HT_DEBUG */
		ret = -EAGAIN;
		goto err_unlock_sta;
	}

	/* prepare A-MPDU MLME for Tx aggregation */
394 395
	tid_tx = kzalloc(sizeof(struct tid_ampdu_tx), GFP_ATOMIC);
	if (!tid_tx) {
J
Johannes Berg 已提交
396 397 398 399 400 401
#ifdef CONFIG_MAC80211_HT_DEBUG
		if (net_ratelimit())
			printk(KERN_ERR "allocate tx mlme to tid %d failed\n",
					tid);
#endif
		ret = -ENOMEM;
402
		goto err_unlock_sta;
J
Johannes Berg 已提交
403
	}
404

405
	skb_queue_head_init(&tid_tx->pending);
406
	__set_bit(HT_AGG_STATE_WANT_START, &tid_tx->state);
407

J
Johannes Berg 已提交
408
	/* Tx timer */
409 410 411
	tid_tx->addba_resp_timer.function = sta_addba_resp_timer_expired;
	tid_tx->addba_resp_timer.data = (unsigned long)&sta->timer_to_tid[tid];
	init_timer(&tid_tx->addba_resp_timer);
J
Johannes Berg 已提交
412

413
	/* assign a dialog token */
J
Johannes Berg 已提交
414
	sta->ampdu_mlme.dialog_token_allocator++;
415
	tid_tx->dialog_token = sta->ampdu_mlme.dialog_token_allocator;
J
Johannes Berg 已提交
416

417 418
	/* finally, assign it to the array */
	rcu_assign_pointer(sta->ampdu_mlme.tid_tx[tid], tid_tx);
419

420
	ieee80211_queue_work(&local->hw, &sta->ampdu_mlme.work);
J
Johannes Berg 已提交
421

422
	/* this flow continues off the work */
423
 err_unlock_sta:
J
Johannes Berg 已提交
424 425 426 427 428
	spin_unlock_bh(&sta->lock);
	return ret;
}
EXPORT_SYMBOL(ieee80211_start_tx_ba_session);

429 430
/*
 * splice packets from the STA's pending to the local pending,
431
 * requires a call to ieee80211_agg_splice_finish later
432
 */
433 434 435
static void __acquires(agg_queue)
ieee80211_agg_splice_packets(struct ieee80211_local *local,
			     struct tid_ampdu_tx *tid_tx, u16 tid)
436
{
437
	int queue = ieee80211_ac_from_tid(tid);
438 439
	unsigned long flags;

440
	ieee80211_stop_queue_agg(local, tid);
441

442 443
	if (WARN(!tid_tx, "TID %d gone but expected when splicing aggregates"
			  " from the pending queue\n", tid))
444 445
		return;

446
	if (!skb_queue_empty(&tid_tx->pending)) {
447 448
		spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
		/* copy over remaining packets */
449 450
		skb_queue_splice_tail_init(&tid_tx->pending,
					   &local->pending[queue]);
451 452 453 454
		spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
	}
}

455 456
static void __releases(agg_queue)
ieee80211_agg_splice_finish(struct ieee80211_local *local, u16 tid)
457
{
458
	ieee80211_wake_queue_agg(local, tid);
459 460
}

461 462 463
static void ieee80211_agg_tx_operational(struct ieee80211_local *local,
					 struct sta_info *sta, u16 tid)
{
464
	lockdep_assert_held(&sta->ampdu_mlme.mtx);
465

466
#ifdef CONFIG_MAC80211_HT_DEBUG
467
	printk(KERN_DEBUG "Aggregation is on for tid %d\n", tid);
468 469
#endif

470 471 472 473 474 475 476 477 478 479
	drv_ampdu_action(local, sta->sdata,
			 IEEE80211_AMPDU_TX_OPERATIONAL,
			 &sta->sta, tid, NULL);

	/*
	 * synchronize with TX path, while splicing the TX path
	 * should block so it won't put more packets onto pending.
	 */
	spin_lock_bh(&sta->lock);

480
	ieee80211_agg_splice_packets(local, sta->ampdu_mlme.tid_tx[tid], tid);
481
	/*
482 483 484
	 * Now mark as operational. This will be visible
	 * in the TX path, and lets it go lock-free in
	 * the common case.
485
	 */
486 487
	set_bit(HT_AGG_STATE_OPERATIONAL, &sta->ampdu_mlme.tid_tx[tid]->state);
	ieee80211_agg_splice_finish(local, tid);
488

489
	spin_unlock_bh(&sta->lock);
490 491
}

492
void ieee80211_start_tx_ba_cb(struct ieee80211_vif *vif, u8 *ra, u16 tid)
J
Johannes Berg 已提交
493
{
494 495
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
	struct ieee80211_local *local = sdata->local;
J
Johannes Berg 已提交
496
	struct sta_info *sta;
497
	struct tid_ampdu_tx *tid_tx;
J
Johannes Berg 已提交
498

J
Johannes Berg 已提交
499 500
	trace_api_start_tx_ba_cb(sdata, ra, tid);

J
Johannes Berg 已提交
501 502 503 504 505 506 507 508
	if (tid >= STA_TID_NUM) {
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "Bad TID value: tid = %d (>= %d)\n",
				tid, STA_TID_NUM);
#endif
		return;
	}

509
	mutex_lock(&local->sta_mtx);
510
	sta = sta_info_get(sdata, ra);
J
Johannes Berg 已提交
511
	if (!sta) {
512
		mutex_unlock(&local->sta_mtx);
J
Johannes Berg 已提交
513 514 515 516 517 518
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "Could not find station: %pM\n", ra);
#endif
		return;
	}

519
	mutex_lock(&sta->ampdu_mlme.mtx);
520
	tid_tx = sta->ampdu_mlme.tid_tx[tid];
J
Johannes Berg 已提交
521

522
	if (WARN_ON(!tid_tx)) {
J
Johannes Berg 已提交
523
#ifdef CONFIG_MAC80211_HT_DEBUG
524
		printk(KERN_DEBUG "addBA was not requested!\n");
J
Johannes Berg 已提交
525
#endif
526
		goto unlock;
J
Johannes Berg 已提交
527 528
	}

529
	if (WARN_ON(test_and_set_bit(HT_AGG_STATE_DRV_READY, &tid_tx->state)))
530
		goto unlock;
J
Johannes Berg 已提交
531

532
	if (test_bit(HT_AGG_STATE_RESPONSE_RECEIVED, &tid_tx->state))
533
		ieee80211_agg_tx_operational(local, sta, tid);
534

535 536 537
 unlock:
	mutex_unlock(&sta->ampdu_mlme.mtx);
	mutex_unlock(&local->sta_mtx);
J
Johannes Berg 已提交
538 539
}

540
void ieee80211_start_tx_ba_cb_irqsafe(struct ieee80211_vif *vif,
541 542
				      const u8 *ra, u16 tid)
{
543 544
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
	struct ieee80211_local *local = sdata->local;
545 546 547 548 549 550 551
	struct ieee80211_ra_tid *ra_tid;
	struct sk_buff *skb = dev_alloc_skb(0);

	if (unlikely(!skb)) {
#ifdef CONFIG_MAC80211_HT_DEBUG
		if (net_ratelimit())
			printk(KERN_WARNING "%s: Not enough memory, "
552
			       "dropping start BA session", sdata->name);
553 554 555 556 557 558 559
#endif
		return;
	}
	ra_tid = (struct ieee80211_ra_tid *) &skb->cb;
	memcpy(&ra_tid->ra, ra, ETH_ALEN);
	ra_tid->tid = tid;

560 561 562
	skb->pkt_type = IEEE80211_SDATA_QUEUE_AGG_START;
	skb_queue_tail(&sdata->skb_queue, skb);
	ieee80211_queue_work(&local->hw, &sdata->work);
563 564 565
}
EXPORT_SYMBOL(ieee80211_start_tx_ba_cb_irqsafe);

566 567 568 569 570
int __ieee80211_stop_tx_ba_session(struct sta_info *sta, u16 tid,
				   enum ieee80211_back_parties initiator)
{
	int ret;

571
	mutex_lock(&sta->ampdu_mlme.mtx);
572 573 574

	ret = ___ieee80211_stop_tx_ba_session(sta, tid, initiator);

575 576
	mutex_unlock(&sta->ampdu_mlme.mtx);

577 578
	return ret;
}
J
Johannes Berg 已提交
579

580
int ieee80211_stop_tx_ba_session(struct ieee80211_sta *pubsta, u16 tid)
J
Johannes Berg 已提交
581
{
582 583 584
	struct sta_info *sta = container_of(pubsta, struct sta_info, sta);
	struct ieee80211_sub_if_data *sdata = sta->sdata;
	struct ieee80211_local *local = sdata->local;
585 586
	struct tid_ampdu_tx *tid_tx;
	int ret = 0;
J
Johannes Berg 已提交
587

588
	trace_api_stop_tx_ba_session(pubsta, tid);
J
Johannes Berg 已提交
589

J
Johannes Berg 已提交
590
	if (!local->ops->ampdu_action)
591 592
		return -EINVAL;

J
Johannes Berg 已提交
593 594 595
	if (tid >= STA_TID_NUM)
		return -EINVAL;

596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615
	spin_lock_bh(&sta->lock);
	tid_tx = sta->ampdu_mlme.tid_tx[tid];

	if (!tid_tx) {
		ret = -ENOENT;
		goto unlock;
	}

	if (test_bit(HT_AGG_STATE_STOPPING, &tid_tx->state)) {
		/* already in progress stopping it */
		ret = 0;
		goto unlock;
	}

	set_bit(HT_AGG_STATE_WANT_STOP, &tid_tx->state);
	ieee80211_queue_work(&local->hw, &sta->ampdu_mlme.work);

 unlock:
	spin_unlock_bh(&sta->lock);
	return ret;
J
Johannes Berg 已提交
616 617 618
}
EXPORT_SYMBOL(ieee80211_stop_tx_ba_session);

619
void ieee80211_stop_tx_ba_cb(struct ieee80211_vif *vif, u8 *ra, u8 tid)
J
Johannes Berg 已提交
620
{
621 622
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
	struct ieee80211_local *local = sdata->local;
J
Johannes Berg 已提交
623
	struct sta_info *sta;
624
	struct tid_ampdu_tx *tid_tx;
J
Johannes Berg 已提交
625

J
Johannes Berg 已提交
626 627
	trace_api_stop_tx_ba_cb(sdata, ra, tid);

J
Johannes Berg 已提交
628 629 630 631 632 633 634 635 636 637 638 639 640
	if (tid >= STA_TID_NUM) {
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "Bad TID value: tid = %d (>= %d)\n",
				tid, STA_TID_NUM);
#endif
		return;
	}

#ifdef CONFIG_MAC80211_HT_DEBUG
	printk(KERN_DEBUG "Stopping Tx BA session for %pM tid %d\n",
	       ra, tid);
#endif /* CONFIG_MAC80211_HT_DEBUG */

641 642
	mutex_lock(&local->sta_mtx);

643
	sta = sta_info_get(sdata, ra);
J
Johannes Berg 已提交
644 645 646 647
	if (!sta) {
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "Could not find station: %pM\n", ra);
#endif
648
		goto unlock;
J
Johannes Berg 已提交
649 650
	}

651
	mutex_lock(&sta->ampdu_mlme.mtx);
652 653 654 655
	spin_lock_bh(&sta->lock);
	tid_tx = sta->ampdu_mlme.tid_tx[tid];

	if (!tid_tx || !test_bit(HT_AGG_STATE_STOPPING, &tid_tx->state)) {
J
Johannes Berg 已提交
656 657 658
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "unexpected callback to A-MPDU stop\n");
#endif
659
		goto unlock_sta;
J
Johannes Berg 已提交
660 661
	}

662
	if (tid_tx->stop_initiator == WLAN_BACK_INITIATOR)
J
Johannes Berg 已提交
663 664 665
		ieee80211_send_delba(sta->sdata, ra, tid,
			WLAN_BACK_INITIATOR, WLAN_REASON_QSTA_NOT_USE);

666 667 668 669 670 671 672 673 674
	/*
	 * When we get here, the TX path will not be lockless any more wrt.
	 * aggregation, since the OPERATIONAL bit has long been cleared.
	 * Thus it will block on getting the lock, if it occurs. So if we
	 * stop the queue now, we will not get any more packets, and any
	 * that might be being processed will wait for us here, thereby
	 * guaranteeing that no packets go to the tid_tx pending queue any
	 * more.
	 */
J
Johannes Berg 已提交
675

676
	ieee80211_agg_splice_packets(local, tid_tx, tid);
677

678 679
	/* future packets must not find the tid_tx struct any more */
	rcu_assign_pointer(sta->ampdu_mlme.tid_tx[tid], NULL);
680

681
	ieee80211_agg_splice_finish(local, tid);
682

683
	call_rcu(&tid_tx->rcu_head, kfree_tid_tx);
J
Johannes Berg 已提交
684

685
 unlock_sta:
686
	spin_unlock_bh(&sta->lock);
687 688 689
	mutex_unlock(&sta->ampdu_mlme.mtx);
 unlock:
	mutex_unlock(&local->sta_mtx);
J
Johannes Berg 已提交
690 691
}

692
void ieee80211_stop_tx_ba_cb_irqsafe(struct ieee80211_vif *vif,
J
Johannes Berg 已提交
693 694
				     const u8 *ra, u16 tid)
{
695 696
	struct ieee80211_sub_if_data *sdata = vif_to_sdata(vif);
	struct ieee80211_local *local = sdata->local;
J
Johannes Berg 已提交
697 698 699 700 701 702 703
	struct ieee80211_ra_tid *ra_tid;
	struct sk_buff *skb = dev_alloc_skb(0);

	if (unlikely(!skb)) {
#ifdef CONFIG_MAC80211_HT_DEBUG
		if (net_ratelimit())
			printk(KERN_WARNING "%s: Not enough memory, "
704
			       "dropping stop BA session", sdata->name);
J
Johannes Berg 已提交
705 706 707 708 709 710 711
#endif
		return;
	}
	ra_tid = (struct ieee80211_ra_tid *) &skb->cb;
	memcpy(&ra_tid->ra, ra, ETH_ALEN);
	ra_tid->tid = tid;

712 713 714
	skb->pkt_type = IEEE80211_SDATA_QUEUE_AGG_STOP;
	skb_queue_tail(&sdata->skb_queue, skb);
	ieee80211_queue_work(&local->hw, &sdata->work);
J
Johannes Berg 已提交
715 716 717
}
EXPORT_SYMBOL(ieee80211_stop_tx_ba_cb_irqsafe);

718

J
Johannes Berg 已提交
719 720 721 722 723
void ieee80211_process_addba_resp(struct ieee80211_local *local,
				  struct sta_info *sta,
				  struct ieee80211_mgmt *mgmt,
				  size_t len)
{
724
	struct tid_ampdu_tx *tid_tx;
725
	u16 capab, tid;
J
Johannes Berg 已提交
726 727 728 729

	capab = le16_to_cpu(mgmt->u.action.u.addba_resp.capab);
	tid = (capab & IEEE80211_ADDBA_PARAM_TID_MASK) >> 2;

730
	mutex_lock(&sta->ampdu_mlme.mtx);
J
Johannes Berg 已提交
731

732 733
	tid_tx = sta->ampdu_mlme.tid_tx[tid];
	if (!tid_tx)
734
		goto out;
J
Johannes Berg 已提交
735

736
	if (mgmt->u.action.u.addba_resp.dialog_token != tid_tx->dialog_token) {
J
Johannes Berg 已提交
737 738
#ifdef CONFIG_MAC80211_HT_DEBUG
		printk(KERN_DEBUG "wrong addBA response token, tid %d\n", tid);
739
#endif
740
		goto out;
J
Johannes Berg 已提交
741 742
	}

743
	del_timer(&tid_tx->addba_resp_timer);
744

J
Johannes Berg 已提交
745
#ifdef CONFIG_MAC80211_HT_DEBUG
746
	printk(KERN_DEBUG "switched off addBA timer for tid %d\n", tid);
747
#endif
J
Johannes Berg 已提交
748

J
Johannes Berg 已提交
749 750
	if (le16_to_cpu(mgmt->u.action.u.addba_resp.status)
			== WLAN_STATUS_SUCCESS) {
751 752 753 754 755
		if (test_and_set_bit(HT_AGG_STATE_RESPONSE_RECEIVED,
				     &tid_tx->state)) {
			/* ignore duplicate response */
			goto out;
		}
J
Johannes Berg 已提交
756

757
		if (test_bit(HT_AGG_STATE_DRV_READY, &tid_tx->state))
758
			ieee80211_agg_tx_operational(local, sta, tid);
J
Johannes Berg 已提交
759

760
		sta->ampdu_mlme.addba_req_num[tid] = 0;
J
Johannes Berg 已提交
761
	} else {
762
		___ieee80211_stop_tx_ba_session(sta, tid, WLAN_BACK_INITIATOR);
J
Johannes Berg 已提交
763
	}
J
Johannes Berg 已提交
764 765

 out:
766
	mutex_unlock(&sta->ampdu_mlme.mtx);
J
Johannes Berg 已提交
767
}