main.c 42.5 KB
Newer Older
1 2 3 4 5 6
/**
  * This file contains the major functions in WLAN
  * driver. It includes init, exit, open, close and main
  * thread etc..
  */

7
#include <linux/moduleparam.h>
8 9 10 11
#include <linux/delay.h>
#include <linux/etherdevice.h>
#include <linux/netdevice.h>
#include <linux/if_arp.h>
12
#include <linux/kthread.h>
13
#include <linux/kfifo.h>
14
#include <linux/stddef.h>
J
Johannes Berg 已提交
15
#include <linux/ieee80211.h>
16 17 18 19 20 21 22
#include <net/iw_handler.h>

#include "host.h"
#include "decl.h"
#include "dev.h"
#include "wext.h"
#include "debugfs.h"
23
#include "scan.h"
24
#include "assoc.h"
25
#include "cmd.h"
26

27
#define DRIVER_RELEASE_VERSION "323.p0"
28
const char lbs_driver_version[] = "COMM-USB8388-" DRIVER_RELEASE_VERSION
29 30 31 32 33
#ifdef  DEBUG
    "-dbg"
#endif
    "";

34 35

/* Module parameters */
36 37 38
unsigned int lbs_debug;
EXPORT_SYMBOL_GPL(lbs_debug);
module_param_named(libertas_debug, lbs_debug, int, 0644);
39 40


41 42 43 44 45
/* This global structure is used to send the confirm_sleep command as
 * fast as possible down to the firmware. */
struct cmd_confirm_sleep confirm_sleep;


46 47 48 49 50
#define LBS_TX_PWR_DEFAULT		20	/*100mW */
#define LBS_TX_PWR_US_DEFAULT		20	/*100mW */
#define LBS_TX_PWR_JP_DEFAULT		16	/*50mW */
#define LBS_TX_PWR_FR_DEFAULT		20	/*100mW */
#define LBS_TX_PWR_EMEA_DEFAULT	20	/*100mW */
51 52 53 54

/* Format { channel, frequency (MHz), maxtxpower } */
/* band: 'B/G', region: USA FCC/Canada IC */
static struct chan_freq_power channel_freq_power_US_BG[] = {
55 56 57 58 59 60 61 62 63 64 65
	{1, 2412, LBS_TX_PWR_US_DEFAULT},
	{2, 2417, LBS_TX_PWR_US_DEFAULT},
	{3, 2422, LBS_TX_PWR_US_DEFAULT},
	{4, 2427, LBS_TX_PWR_US_DEFAULT},
	{5, 2432, LBS_TX_PWR_US_DEFAULT},
	{6, 2437, LBS_TX_PWR_US_DEFAULT},
	{7, 2442, LBS_TX_PWR_US_DEFAULT},
	{8, 2447, LBS_TX_PWR_US_DEFAULT},
	{9, 2452, LBS_TX_PWR_US_DEFAULT},
	{10, 2457, LBS_TX_PWR_US_DEFAULT},
	{11, 2462, LBS_TX_PWR_US_DEFAULT}
66 67 68 69
};

/* band: 'B/G', region: Europe ETSI */
static struct chan_freq_power channel_freq_power_EU_BG[] = {
70 71 72 73 74 75 76 77 78 79 80 81 82
	{1, 2412, LBS_TX_PWR_EMEA_DEFAULT},
	{2, 2417, LBS_TX_PWR_EMEA_DEFAULT},
	{3, 2422, LBS_TX_PWR_EMEA_DEFAULT},
	{4, 2427, LBS_TX_PWR_EMEA_DEFAULT},
	{5, 2432, LBS_TX_PWR_EMEA_DEFAULT},
	{6, 2437, LBS_TX_PWR_EMEA_DEFAULT},
	{7, 2442, LBS_TX_PWR_EMEA_DEFAULT},
	{8, 2447, LBS_TX_PWR_EMEA_DEFAULT},
	{9, 2452, LBS_TX_PWR_EMEA_DEFAULT},
	{10, 2457, LBS_TX_PWR_EMEA_DEFAULT},
	{11, 2462, LBS_TX_PWR_EMEA_DEFAULT},
	{12, 2467, LBS_TX_PWR_EMEA_DEFAULT},
	{13, 2472, LBS_TX_PWR_EMEA_DEFAULT}
83 84 85 86
};

/* band: 'B/G', region: Spain */
static struct chan_freq_power channel_freq_power_SPN_BG[] = {
87 88
	{10, 2457, LBS_TX_PWR_DEFAULT},
	{11, 2462, LBS_TX_PWR_DEFAULT}
89 90 91 92
};

/* band: 'B/G', region: France */
static struct chan_freq_power channel_freq_power_FR_BG[] = {
93 94 95 96
	{10, 2457, LBS_TX_PWR_FR_DEFAULT},
	{11, 2462, LBS_TX_PWR_FR_DEFAULT},
	{12, 2467, LBS_TX_PWR_FR_DEFAULT},
	{13, 2472, LBS_TX_PWR_FR_DEFAULT}
97 98 99 100
};

/* band: 'B/G', region: Japan */
static struct chan_freq_power channel_freq_power_JPN_BG[] = {
101 102 103 104 105 106 107 108 109 110 111 112 113 114
	{1, 2412, LBS_TX_PWR_JP_DEFAULT},
	{2, 2417, LBS_TX_PWR_JP_DEFAULT},
	{3, 2422, LBS_TX_PWR_JP_DEFAULT},
	{4, 2427, LBS_TX_PWR_JP_DEFAULT},
	{5, 2432, LBS_TX_PWR_JP_DEFAULT},
	{6, 2437, LBS_TX_PWR_JP_DEFAULT},
	{7, 2442, LBS_TX_PWR_JP_DEFAULT},
	{8, 2447, LBS_TX_PWR_JP_DEFAULT},
	{9, 2452, LBS_TX_PWR_JP_DEFAULT},
	{10, 2457, LBS_TX_PWR_JP_DEFAULT},
	{11, 2462, LBS_TX_PWR_JP_DEFAULT},
	{12, 2467, LBS_TX_PWR_JP_DEFAULT},
	{13, 2472, LBS_TX_PWR_JP_DEFAULT},
	{14, 2484, LBS_TX_PWR_JP_DEFAULT}
115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131
};

/**
 * the structure for channel, frequency and power
 */
struct region_cfp_table {
	u8 region;
	struct chan_freq_power *cfp_BG;
	int cfp_no_BG;
};

/**
 * the structure for the mapping between region and CFP
 */
static struct region_cfp_table region_cfp_table[] = {
	{0x10,			/*US FCC */
	 channel_freq_power_US_BG,
132
	 ARRAY_SIZE(channel_freq_power_US_BG),
133 134 135 136
	 }
	,
	{0x20,			/*CANADA IC */
	 channel_freq_power_US_BG,
137
	 ARRAY_SIZE(channel_freq_power_US_BG),
138 139 140
	 }
	,
	{0x30, /*EU*/ channel_freq_power_EU_BG,
141
	 ARRAY_SIZE(channel_freq_power_EU_BG),
142 143 144
	 }
	,
	{0x31, /*SPAIN*/ channel_freq_power_SPN_BG,
145
	 ARRAY_SIZE(channel_freq_power_SPN_BG),
146 147 148
	 }
	,
	{0x32, /*FRANCE*/ channel_freq_power_FR_BG,
149
	 ARRAY_SIZE(channel_freq_power_FR_BG),
150 151 152
	 }
	,
	{0x40, /*JAPAN*/ channel_freq_power_JPN_BG,
153
	 ARRAY_SIZE(channel_freq_power_JPN_BG),
154 155 156 157 158 159
	 }
	,
/*Add new region here */
};

/**
160
 * the table to keep region code
161
 */
162
u16 lbs_region_code_to_index[MRVDRV_MAX_REGION_CODE] =
163
    { 0x10, 0x20, 0x30, 0x31, 0x32, 0x40 };
164 165

/**
166
 * 802.11b/g supported bitrates (in 500Kb/s units)
167
 */
168
u8 lbs_bg_rates[MAX_RATES] =
169 170
    { 0x02, 0x04, 0x0b, 0x16, 0x0c, 0x12, 0x18, 0x24, 0x30, 0x48, 0x60, 0x6c,
0x00, 0x00 };
171 172

/**
173 174 175
 * FW rate table.  FW refers to rates by their index in this table, not by the
 * rate value itself.  Values of 0x00 are
 * reserved positions.
176
 */
177 178 179 180
static u8 fw_data_rates[MAX_RATES] =
    { 0x02, 0x04, 0x0B, 0x16, 0x00, 0x0C, 0x12,
      0x18, 0x24, 0x30, 0x48, 0x60, 0x6C, 0x00
};
181 182

/**
183 184 185 186
 *  @brief use index to get the data rate
 *
 *  @param idx                The index of data rate
 *  @return 	   		data rate or 0
187
 */
188
u32 lbs_fw_index_to_data_rate(u8 idx)
189 190 191 192 193 194 195 196 197 198 199 200
{
	if (idx >= sizeof(fw_data_rates))
		idx = 0;
	return fw_data_rates[idx];
}

/**
 *  @brief use rate to get the index
 *
 *  @param rate                 data rate
 *  @return 	   		index or 0
 */
201
u8 lbs_data_rate_to_fw_index(u32 rate)
202 203 204 205 206 207 208 209 210 211 212 213
{
	u8 i;

	if (!rate)
		return 0;

	for (i = 0; i < sizeof(fw_data_rates); i++) {
		if (rate == fw_data_rates[i])
			return i;
	}
	return 0;
}
214 215 216 217 218 219

/**
 * Attributes exported through sysfs
 */

/**
220
 * @brief Get function for sysfs attribute anycast_mask
221
 */
222
static ssize_t lbs_anycast_get(struct device *dev,
D
Dan Williams 已提交
223 224
		struct device_attribute *attr, char * buf)
{
225
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
226
	struct cmd_ds_mesh_access mesh_access;
227
	int ret;
228 229

	memset(&mesh_access, 0, sizeof(mesh_access));
230 231 232 233

	ret = lbs_mesh_access(priv, CMD_ACT_MESH_GET_ANYCAST, &mesh_access);
	if (ret)
		return ret;
234

235
	return snprintf(buf, 12, "0x%X\n", le32_to_cpu(mesh_access.data[0]));
236 237 238
}

/**
239
 * @brief Set function for sysfs attribute anycast_mask
240
 */
241
static ssize_t lbs_anycast_set(struct device *dev,
D
Dan Williams 已提交
242 243
		struct device_attribute *attr, const char * buf, size_t count)
{
244
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
245
	struct cmd_ds_mesh_access mesh_access;
246
	uint32_t datum;
247
	int ret;
248 249

	memset(&mesh_access, 0, sizeof(mesh_access));
250
	sscanf(buf, "%x", &datum);
251 252
	mesh_access.data[0] = cpu_to_le32(datum);

253 254 255 256
	ret = lbs_mesh_access(priv, CMD_ACT_MESH_SET_ANYCAST, &mesh_access);
	if (ret)
		return ret;

257 258 259
	return strlen(buf);
}

260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311
/**
 * @brief Get function for sysfs attribute prb_rsp_limit
 */
static ssize_t lbs_prb_rsp_limit_get(struct device *dev,
		struct device_attribute *attr, char *buf)
{
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
	struct cmd_ds_mesh_access mesh_access;
	int ret;
	u32 retry_limit;

	memset(&mesh_access, 0, sizeof(mesh_access));
	mesh_access.data[0] = cpu_to_le32(CMD_ACT_GET);

	ret = lbs_mesh_access(priv, CMD_ACT_MESH_SET_GET_PRB_RSP_LIMIT,
			&mesh_access);
	if (ret)
		return ret;

	retry_limit = le32_to_cpu(mesh_access.data[1]);
	return snprintf(buf, 10, "%d\n", retry_limit);
}

/**
 * @brief Set function for sysfs attribute prb_rsp_limit
 */
static ssize_t lbs_prb_rsp_limit_set(struct device *dev,
		struct device_attribute *attr, const char *buf, size_t count)
{
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
	struct cmd_ds_mesh_access mesh_access;
	int ret;
	unsigned long retry_limit;

	memset(&mesh_access, 0, sizeof(mesh_access));
	mesh_access.data[0] = cpu_to_le32(CMD_ACT_SET);

	if (!strict_strtoul(buf, 10, &retry_limit))
		return -ENOTSUPP;
	if (retry_limit > 15)
		return -ENOTSUPP;

	mesh_access.data[1] = cpu_to_le32(retry_limit);

	ret = lbs_mesh_access(priv, CMD_ACT_MESH_SET_GET_PRB_RSP_LIMIT,
			&mesh_access);
	if (ret)
		return ret;

	return strlen(buf);
}

312 313
static int lbs_add_rtap(struct lbs_private *priv);
static void lbs_remove_rtap(struct lbs_private *priv);
314 315
static int lbs_add_mesh(struct lbs_private *priv);
static void lbs_remove_mesh(struct lbs_private *priv);
316

317 318 319 320

/**
 * Get function for sysfs attribute rtap
 */
321
static ssize_t lbs_rtap_get(struct device *dev,
322 323
		struct device_attribute *attr, char * buf)
{
324
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
325
	return snprintf(buf, 5, "0x%X\n", priv->monitormode);
326 327 328 329 330
}

/**
 *  Set function for sysfs attribute rtap
 */
331
static ssize_t lbs_rtap_set(struct device *dev,
332 333 334
		struct device_attribute *attr, const char * buf, size_t count)
{
	int monitor_mode;
335
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
336 337

	sscanf(buf, "%x", &monitor_mode);
338 339
	if (monitor_mode) {
		if (priv->monitormode == monitor_mode)
340
			return strlen(buf);
341
		if (!priv->monitormode) {
342 343
			if (priv->infra_open || priv->mesh_open)
				return -EBUSY;
344
			if (priv->mode == IW_MODE_INFRA)
345 346 347
				lbs_cmd_80211_deauthenticate(priv,
							     priv->curbssparams.bssid,
							     WLAN_REASON_DEAUTH_LEAVING);
348
			else if (priv->mode == IW_MODE_ADHOC)
349
				lbs_adhoc_stop(priv);
350
			lbs_add_rtap(priv);
351
		}
352
		priv->monitormode = monitor_mode;
353
	} else {
354
		if (!priv->monitormode)
355
			return strlen(buf);
356
		priv->monitormode = 0;
357
		lbs_remove_rtap(priv);
D
David Woodhouse 已提交
358

359 360 361
		if (priv->currenttxskb) {
			dev_kfree_skb_any(priv->currenttxskb);
			priv->currenttxskb = NULL;
D
David Woodhouse 已提交
362 363 364 365
		}

		/* Wake queues, command thread, etc. */
		lbs_host_to_card_done(priv);
366 367
	}

368
	lbs_prepare_and_send_command(priv,
369
			CMD_802_11_MONITOR_MODE, CMD_ACT_SET,
370
			CMD_OPTION_WAITFORRSP, 0, &priv->monitormode);
371 372 373 374
	return strlen(buf);
}

/**
375 376
 * lbs_rtap attribute to be exported per ethX interface
 * through sysfs (/sys/class/net/ethX/lbs_rtap)
377
 */
378 379 380 381 382 383 384 385
static DEVICE_ATTR(lbs_rtap, 0644, lbs_rtap_get, lbs_rtap_set );

/**
 * Get function for sysfs attribute mesh
 */
static ssize_t lbs_mesh_get(struct device *dev,
		struct device_attribute *attr, char * buf)
{
386
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
387 388 389 390 391 392 393 394 395
	return snprintf(buf, 5, "0x%X\n", !!priv->mesh_dev);
}

/**
 *  Set function for sysfs attribute mesh
 */
static ssize_t lbs_mesh_set(struct device *dev,
		struct device_attribute *attr, const char * buf, size_t count)
{
396
	struct lbs_private *priv = netdev_priv(to_net_dev(dev));
397
	int enable;
398
	int ret, action = CMD_ACT_MESH_CONFIG_STOP;
399 400 401 402 403

	sscanf(buf, "%x", &enable);
	enable = !!enable;
	if (enable == !!priv->mesh_dev)
		return count;
404 405 406
	if (enable)
		action = CMD_ACT_MESH_CONFIG_START;
	ret = lbs_mesh_config(priv, action, priv->curbssparams.channel);
407 408
	if (ret)
		return ret;
409

410 411 412 413 414 415 416 417 418 419 420 421 422
	if (enable)
		lbs_add_mesh(priv);
	else
		lbs_remove_mesh(priv);

	return count;
}

/**
 * lbs_mesh attribute to be exported per ethX interface
 * through sysfs (/sys/class/net/ethX/lbs_mesh)
 */
static DEVICE_ATTR(lbs_mesh, 0644, lbs_mesh_get, lbs_mesh_set);
423

424
/**
425 426
 * anycast_mask attribute to be exported per mshX interface
 * through sysfs (/sys/class/net/mshX/anycast_mask)
427
 */
428
static DEVICE_ATTR(anycast_mask, 0644, lbs_anycast_get, lbs_anycast_set);
429

430 431 432 433 434 435 436
/**
 * prb_rsp_limit attribute to be exported per mshX interface
 * through sysfs (/sys/class/net/mshX/prb_rsp_limit)
 */
static DEVICE_ATTR(prb_rsp_limit, 0644, lbs_prb_rsp_limit_get,
		lbs_prb_rsp_limit_set);

437
static struct attribute *lbs_mesh_sysfs_entries[] = {
438
	&dev_attr_anycast_mask.attr,
439
	&dev_attr_prb_rsp_limit.attr,
440 441 442
	NULL,
};

443 444
static struct attribute_group lbs_mesh_attr_group = {
	.attrs = lbs_mesh_sysfs_entries,
445 446
};

447
/**
448
 *  @brief This function opens the ethX or mshX interface
449 450
 *
 *  @param dev     A pointer to net_device structure
451
 *  @return 	   0 or -EBUSY if monitor mode active
452
 */
453
static int lbs_dev_open(struct net_device *dev)
454
{
455
	struct lbs_private *priv = netdev_priv(dev) ;
456
	int ret = 0;
457

458 459
	lbs_deb_enter(LBS_DEB_NET);

460
	spin_lock_irq(&priv->driver_lock);
461

462
	if (priv->monitormode) {
463 464 465
		ret = -EBUSY;
		goto out;
	}
466

467 468 469 470 471 472
	if (dev == priv->mesh_dev) {
		priv->mesh_open = 1;
		priv->mesh_connect_status = LBS_CONNECTED;
		netif_carrier_on(dev);
	} else {
		priv->infra_open = 1;
473

474 475
		if (priv->connect_status == LBS_CONNECTED)
			netif_carrier_on(dev);
476
		else
477
			netif_carrier_off(dev);
478
	}
479

480 481 482
	if (!priv->tx_pending_len)
		netif_wake_queue(dev);
 out:
483

484
	spin_unlock_irq(&priv->driver_lock);
485
	lbs_deb_leave_args(LBS_DEB_NET, "ret %d", ret);
486
	return ret;
487 488 489 490 491 492 493 494
}

/**
 *  @brief This function closes the mshX interface
 *
 *  @param dev     A pointer to net_device structure
 *  @return 	   0
 */
495
static int lbs_mesh_stop(struct net_device *dev)
496
{
497
	struct lbs_private *priv = dev->ml_priv;
498

499
	lbs_deb_enter(LBS_DEB_MESH);
500 501
	spin_lock_irq(&priv->driver_lock);

502
	priv->mesh_open = 0;
503 504 505 506
	priv->mesh_connect_status = LBS_DISCONNECTED;

	netif_stop_queue(dev);
	netif_carrier_off(dev);
507

508
	spin_unlock_irq(&priv->driver_lock);
509

510 511
	schedule_work(&priv->mcast_work);

512
	lbs_deb_leave(LBS_DEB_MESH);
513
	return 0;
514 515 516 517 518 519 520 521
}

/**
 *  @brief This function closes the ethX interface
 *
 *  @param dev     A pointer to net_device structure
 *  @return 	   0
 */
522
static int lbs_eth_stop(struct net_device *dev)
523
{
524
	struct lbs_private *priv = netdev_priv(dev);
525

526
	lbs_deb_enter(LBS_DEB_NET);
527

528
	spin_lock_irq(&priv->driver_lock);
529
	priv->infra_open = 0;
530 531
	netif_stop_queue(dev);
	spin_unlock_irq(&priv->driver_lock);
532

533 534
	schedule_work(&priv->mcast_work);

535
	lbs_deb_leave(LBS_DEB_NET);
536
	return 0;
537 538
}

539
static void lbs_tx_timeout(struct net_device *dev)
540
{
541
	struct lbs_private *priv = netdev_priv(dev);
542

543
	lbs_deb_enter(LBS_DEB_TX);
544

545
	lbs_pr_err("tx watch dog timeout\n");
546 547 548

	dev->trans_start = jiffies;

549 550 551
	if (priv->currenttxskb)
		lbs_send_tx_feedback(priv, 0);

552 553 554
	/* XX: Shouldn't we also call into the hw-specific driver
	   to kick it somehow? */
	lbs_host_to_card_done(priv);
555

556 557 558 559 560 561 562
	/* More often than not, this actually happens because the
	   firmware has crapped itself -- rather than just a very
	   busy medium. So send a harmless command, and if/when
	   _that_ times out, we'll kick it in the head. */
	lbs_prepare_and_send_command(priv, CMD_802_11_RSSI, 0,
				     0, 0, NULL);

563
	lbs_deb_leave(LBS_DEB_TX);
564 565
}

566 567
void lbs_host_to_card_done(struct lbs_private *priv)
{
568 569
	unsigned long flags;

570 571
	lbs_deb_enter(LBS_DEB_THREAD);

572
	spin_lock_irqsave(&priv->driver_lock, flags);
573 574 575 576

	priv->dnld_sent = DNLD_RES_RECEIVED;

	/* Wake main thread if commands are pending */
577
	if (!priv->cur_cmd || priv->tx_pending_len > 0)
578 579
		wake_up_interruptible(&priv->waitq);

580
	spin_unlock_irqrestore(&priv->driver_lock, flags);
581
	lbs_deb_leave(LBS_DEB_THREAD);
582 583 584
}
EXPORT_SYMBOL_GPL(lbs_host_to_card_done);

585 586 587
/**
 *  @brief This function returns the network statistics
 *
588
 *  @param dev     A pointer to struct lbs_private structure
589 590
 *  @return 	   A pointer to net_device_stats structure
 */
591
static struct net_device_stats *lbs_get_stats(struct net_device *dev)
592
{
593
	struct lbs_private *priv = netdev_priv(dev);
594

595
	lbs_deb_enter(LBS_DEB_NET);
596 597 598
	return &priv->stats;
}

599
static int lbs_set_mac_address(struct net_device *dev, void *addr)
600 601
{
	int ret = 0;
602
	struct lbs_private *priv = netdev_priv(dev);
603
	struct sockaddr *phwaddr = addr;
604
	struct cmd_ds_802_11_mac_address cmd;
605

606
	lbs_deb_enter(LBS_DEB_NET);
607

608
	/* In case it was called from the mesh device */
609
	dev = priv->dev;
610

611 612 613
	cmd.hdr.size = cpu_to_le16(sizeof(cmd));
	cmd.action = cpu_to_le16(CMD_ACT_SET);
	memcpy(cmd.macadd, phwaddr->sa_data, ETH_ALEN);
614

615
	ret = lbs_cmd_with_response(priv, CMD_802_11_MAC_ADDRESS, &cmd);
616
	if (ret) {
617
		lbs_deb_net("set MAC address failed\n");
618 619 620
		goto done;
	}

621 622
	memcpy(priv->current_addr, phwaddr->sa_data, ETH_ALEN);
	memcpy(dev->dev_addr, phwaddr->sa_data, ETH_ALEN);
623
	if (priv->mesh_dev)
624
		memcpy(priv->mesh_dev->dev_addr, phwaddr->sa_data, ETH_ALEN);
625 626

done:
627
	lbs_deb_leave_args(LBS_DEB_NET, "ret %d", ret);
628 629 630
	return ret;
}

631 632 633

static inline int mac_in_list(unsigned char *list, int list_len,
			      unsigned char *mac)
634
{
635 636 637 638 639 640 641 642 643
	while (list_len) {
		if (!memcmp(list, mac, ETH_ALEN))
			return 1;
		list += ETH_ALEN;
		list_len--;
	}
	return 0;
}

644

645 646 647 648 649 650 651 652 653
static int lbs_add_mcast_addrs(struct cmd_ds_mac_multicast_adr *cmd,
			       struct net_device *dev, int nr_addrs)
{
	int i = nr_addrs;
	struct dev_mc_list *mc_list;

	if ((dev->flags & (IFF_UP|IFF_MULTICAST)) != (IFF_UP|IFF_MULTICAST))
		return nr_addrs;

654
	netif_addr_lock_bh(dev);
655 656
	for (mc_list = dev->mc_list; mc_list; mc_list = mc_list->next) {
		if (mac_in_list(cmd->maclist, nr_addrs, mc_list->dmi_addr)) {
J
Johannes Berg 已提交
657 658
			lbs_deb_net("mcast address %s:%pM skipped\n", dev->name,
				    mc_list->dmi_addr);
659 660
			continue;
		}
661

662 663 664
		if (i == MRVDRV_MAX_MULTICAST_LIST_SIZE)
			break;
		memcpy(&cmd->maclist[6*i], mc_list->dmi_addr, ETH_ALEN);
J
Johannes Berg 已提交
665 666
		lbs_deb_net("mcast address %s:%pM added to filter\n", dev->name,
			    mc_list->dmi_addr);
667
		i++;
668
	}
669
	netif_addr_unlock_bh(dev);
670 671 672
	if (mc_list)
		return -EOVERFLOW;

673 674 675
	return i;
}

676
static void lbs_set_mcast_worker(struct work_struct *work)
677
{
678 679 680 681 682
	struct lbs_private *priv = container_of(work, struct lbs_private, mcast_work);
	struct cmd_ds_mac_multicast_adr mcast_cmd;
	int dev_flags;
	int nr_addrs;
	int old_mac_control = priv->mac_control;
683

684
	lbs_deb_enter(LBS_DEB_NET);
685

686 687 688 689 690 691 692 693 694 695 696 697 698 699 700
	dev_flags = priv->dev->flags;
	if (priv->mesh_dev)
		dev_flags |= priv->mesh_dev->flags;

	if (dev_flags & IFF_PROMISC) {
		priv->mac_control |= CMD_ACT_MAC_PROMISCUOUS_ENABLE;
		priv->mac_control &= ~(CMD_ACT_MAC_ALL_MULTICAST_ENABLE |
				       CMD_ACT_MAC_MULTICAST_ENABLE);
		goto out_set_mac_control;
	} else if (dev_flags & IFF_ALLMULTI) {
	do_allmulti:
		priv->mac_control |= CMD_ACT_MAC_ALL_MULTICAST_ENABLE;
		priv->mac_control &= ~(CMD_ACT_MAC_PROMISCUOUS_ENABLE |
				       CMD_ACT_MAC_MULTICAST_ENABLE);
		goto out_set_mac_control;
701 702
	}

703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726
	/* Once for priv->dev, again for priv->mesh_dev if it exists */
	nr_addrs = lbs_add_mcast_addrs(&mcast_cmd, priv->dev, 0);
	if (nr_addrs >= 0 && priv->mesh_dev)
		nr_addrs = lbs_add_mcast_addrs(&mcast_cmd, priv->mesh_dev, nr_addrs);
	if (nr_addrs < 0)
		goto do_allmulti;

	if (nr_addrs) {
		int size = offsetof(struct cmd_ds_mac_multicast_adr,
				    maclist[6*nr_addrs]);

		mcast_cmd.action = cpu_to_le16(CMD_ACT_SET);
		mcast_cmd.hdr.size = cpu_to_le16(size);
		mcast_cmd.nr_of_adrs = cpu_to_le16(nr_addrs);

		lbs_cmd_async(priv, CMD_MAC_MULTICAST_ADR, &mcast_cmd.hdr, size);

		priv->mac_control |= CMD_ACT_MAC_MULTICAST_ENABLE;
	} else
		priv->mac_control &= ~CMD_ACT_MAC_MULTICAST_ENABLE;

	priv->mac_control &= ~(CMD_ACT_MAC_PROMISCUOUS_ENABLE |
			       CMD_ACT_MAC_ALL_MULTICAST_ENABLE);
 out_set_mac_control:
727 728
	if (priv->mac_control != old_mac_control)
		lbs_set_mac_control(priv);
729

730
	lbs_deb_leave(LBS_DEB_NET);
731 732
}

733 734
static void lbs_set_multicast_list(struct net_device *dev)
{
735
	struct lbs_private *priv = netdev_priv(dev);
736 737 738 739

	schedule_work(&priv->mcast_work);
}

740
/**
741
 *  @brief This function handles the major jobs in the LBS driver.
742 743
 *  It handles all events generated by firmware, RX data received
 *  from firmware and TX data sent from kernel.
744
 *
745
 *  @param data    A pointer to lbs_thread structure
746 747
 *  @return 	   0
 */
748
static int lbs_thread(void *data)
749
{
750
	struct net_device *dev = data;
751
	struct lbs_private *priv = netdev_priv(dev);
752 753
	wait_queue_t wait;

754
	lbs_deb_enter(LBS_DEB_THREAD);
755 756 757 758

	init_waitqueue_entry(&wait, current);

	for (;;) {
759
		int shouldsleep;
760
		u8 resp_idx;
761

762 763
		lbs_deb_thread("1: currenttxskb %p, dnld_sent %d\n",
				priv->currenttxskb, priv->dnld_sent);
764

765
		add_wait_queue(&priv->waitq, &wait);
766
		set_current_state(TASK_INTERRUPTIBLE);
767
		spin_lock_irq(&priv->driver_lock);
768

769
		if (kthread_should_stop())
770
			shouldsleep = 0;	/* Bye */
771 772
		else if (priv->surpriseremoved)
			shouldsleep = 1;	/* We need to wait until we're _told_ to die */
773 774
		else if (priv->psstate == PS_STATE_SLEEP)
			shouldsleep = 1;	/* Sleep mode. Nothing we can do till it wakes */
775 776
		else if (priv->cmd_timed_out)
			shouldsleep = 0;	/* Command timed out. Recover */
777 778
		else if (!priv->fw_ready)
			shouldsleep = 1;	/* Firmware not ready. We're waiting for it */
779 780
		else if (priv->dnld_sent)
			shouldsleep = 1;	/* Something is en route to the device already */
781 782
		else if (priv->tx_pending_len > 0)
			shouldsleep = 0;	/* We've a packet to send */
783 784
		else if (priv->resp_len[priv->resp_idx])
			shouldsleep = 0;	/* We have a command response */
785 786 787 788
		else if (priv->cur_cmd)
			shouldsleep = 1;	/* Can't send a command; one already running */
		else if (!list_empty(&priv->cmdpendingq))
			shouldsleep = 0;	/* We have a command to send */
789 790
		else if (__kfifo_len(priv->event_fifo))
			shouldsleep = 0;	/* We have an event to process */
791 792 793 794
		else
			shouldsleep = 1;	/* No command */

		if (shouldsleep) {
795
			lbs_deb_thread("sleeping, connect_status %d, "
796
				"psmode %d, psstate %d\n",
797 798
				priv->connect_status,
				priv->psmode, priv->psstate);
799
			spin_unlock_irq(&priv->driver_lock);
800 801
			schedule();
		} else
802
			spin_unlock_irq(&priv->driver_lock);
803

804 805
		lbs_deb_thread("2: currenttxskb %p, dnld_send %d\n",
			       priv->currenttxskb, priv->dnld_sent);
806 807

		set_current_state(TASK_RUNNING);
808
		remove_wait_queue(&priv->waitq, &wait);
809

810 811
		lbs_deb_thread("3: currenttxskb %p, dnld_sent %d\n",
			       priv->currenttxskb, priv->dnld_sent);
812

813
		if (kthread_should_stop()) {
814
			lbs_deb_thread("break from main thread\n");
815 816 817
			break;
		}

818 819 820 821
		if (priv->surpriseremoved) {
			lbs_deb_thread("adapter removed; waiting to die...\n");
			continue;
		}
822

823 824
		lbs_deb_thread("4: currenttxskb %p, dnld_sent %d\n",
		       priv->currenttxskb, priv->dnld_sent);
825

826
		/* Process any pending command response */
827
		spin_lock_irq(&priv->driver_lock);
828 829
		resp_idx = priv->resp_idx;
		if (priv->resp_len[resp_idx]) {
830
			spin_unlock_irq(&priv->driver_lock);
831 832 833
			lbs_process_command_response(priv,
				priv->resp_buf[resp_idx],
				priv->resp_len[resp_idx]);
834
			spin_lock_irq(&priv->driver_lock);
835
			priv->resp_len[resp_idx] = 0;
836
		}
837
		spin_unlock_irq(&priv->driver_lock);
838

839
		/* command timeout stuff */
840 841 842
		if (priv->cmd_timed_out && priv->cur_cmd) {
			struct cmd_ctrl_node *cmdnode = priv->cur_cmd;

843 844 845 846
			if (++priv->nr_retries > 3) {
				lbs_pr_info("Excessive timeouts submitting "
					"command 0x%04x\n",
					le16_to_cpu(cmdnode->cmdbuf->command));
847 848
				lbs_complete_command(priv, cmdnode, -ETIMEDOUT);
				priv->nr_retries = 0;
849
				if (priv->reset_card)
850
					priv->reset_card(priv);
851 852
			} else {
				priv->cur_cmd = NULL;
853
				priv->dnld_sent = DNLD_RES_RECEIVED;
854 855 856 857
				lbs_pr_info("requeueing command 0x%04x due "
					"to timeout (#%d)\n",
					le16_to_cpu(cmdnode->cmdbuf->command),
					priv->nr_retries);
858 859 860 861 862 863 864 865

				/* Stick it back at the _top_ of the pending queue
				   for immediate resubmission */
				list_add(&cmdnode->list, &priv->cmdpendingq);
			}
		}
		priv->cmd_timed_out = 0;

866 867 868 869
		/* Process hardware events, e.g. card removed, link lost */
		spin_lock_irq(&priv->driver_lock);
		while (__kfifo_len(priv->event_fifo)) {
			u32 event;
870

871 872
			__kfifo_get(priv->event_fifo, (unsigned char *) &event,
				sizeof(event));
873
			spin_unlock_irq(&priv->driver_lock);
874 875 876 877
			lbs_process_event(priv, event);
			spin_lock_irq(&priv->driver_lock);
		}
		spin_unlock_irq(&priv->driver_lock);
878

879 880 881
		if (!priv->fw_ready)
			continue;

882
		/* Check if we need to confirm Sleep Request received previously */
883 884 885
		if (priv->psstate == PS_STATE_PRE_SLEEP &&
		    !priv->dnld_sent && !priv->cur_cmd) {
			if (priv->connect_status == LBS_CONNECTED) {
886 887 888 889
				lbs_deb_thread("pre-sleep, currenttxskb %p, "
					"dnld_sent %d, cur_cmd %p\n",
					priv->currenttxskb, priv->dnld_sent,
					priv->cur_cmd);
890

891
				lbs_ps_confirm_sleep(priv);
892 893 894 895 896 897
			} else {
				/* workaround for firmware sending
				 * deauth/linkloss event immediately
				 * after sleep request; remove this
				 * after firmware fixes it
				 */
898
				priv->psstate = PS_STATE_AWAKE;
899 900
				lbs_pr_alert("ignore PS_SleepConfirm in "
					"non-connected state\n");
901 902 903 904 905 906
			}
		}

		/* The PS state is changed during processing of Sleep Request
		 * event above
		 */
907 908
		if ((priv->psstate == PS_STATE_SLEEP) ||
		    (priv->psstate == PS_STATE_PRE_SLEEP))
909 910 911
			continue;

		/* Execute the next command */
912
		if (!priv->dnld_sent && !priv->cur_cmd)
913
			lbs_execute_next_command(priv);
914 915

		/* Wake-up command waiters which can't sleep in
916
		 * lbs_prepare_and_send_command
917
		 */
918 919
		if (!list_empty(&priv->cmdpendingq))
			wake_up_all(&priv->cmd_pending);
920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941

		spin_lock_irq(&priv->driver_lock);
		if (!priv->dnld_sent && priv->tx_pending_len > 0) {
			int ret = priv->hw_host_to_card(priv, MVMS_DAT,
							priv->tx_pending_buf,
							priv->tx_pending_len);
			if (ret) {
				lbs_deb_tx("host_to_card failed %d\n", ret);
				priv->dnld_sent = DNLD_RES_RECEIVED;
			}
			priv->tx_pending_len = 0;
			if (!priv->currenttxskb) {
				/* We can wake the queues immediately if we aren't
				   waiting for TX feedback */
				if (priv->connect_status == LBS_CONNECTED)
					netif_wake_queue(priv->dev);
				if (priv->mesh_dev &&
				    priv->mesh_connect_status == LBS_CONNECTED)
					netif_wake_queue(priv->mesh_dev);
			}
		}
		spin_unlock_irq(&priv->driver_lock);
942 943
	}

944 945
	del_timer(&priv->command_timer);
	wake_up_all(&priv->cmd_pending);
946

947
	lbs_deb_leave(LBS_DEB_THREAD);
948 949 950
	return 0;
}

951 952 953
static int lbs_suspend_callback(struct lbs_private *priv, unsigned long dummy,
				struct cmd_header *cmd)
{
954
	lbs_deb_enter(LBS_DEB_FW);
955 956 957 958 959 960

	netif_device_detach(priv->dev);
	if (priv->mesh_dev)
		netif_device_detach(priv->mesh_dev);

	priv->fw_ready = 0;
961
	lbs_deb_leave(LBS_DEB_FW);
962 963 964 965 966 967 968 969
	return 0;
}

int lbs_suspend(struct lbs_private *priv)
{
	struct cmd_header cmd;
	int ret;

970 971
	lbs_deb_enter(LBS_DEB_FW);

972 973 974 975 976
	if (priv->wol_criteria == 0xffffffff) {
		lbs_pr_info("Suspend attempt without configuring wake params!\n");
		return -EINVAL;
	}

977
	memset(&cmd, 0, sizeof(cmd));
978

979 980 981 982 983
	ret = __lbs_cmd(priv, CMD_802_11_HOST_SLEEP_ACTIVATE, &cmd,
			sizeof(cmd), lbs_suspend_callback, 0);
	if (ret)
		lbs_pr_info("HOST_SLEEP_ACTIVATE failed: %d\n", ret);

984
	lbs_deb_leave_args(LBS_DEB_FW, "ret %d", ret);
985 986 987 988
	return ret;
}
EXPORT_SYMBOL_GPL(lbs_suspend);

989
void lbs_resume(struct lbs_private *priv)
990
{
991 992
	lbs_deb_enter(LBS_DEB_FW);

993 994 995 996 997 998 999 1000 1001 1002 1003
	priv->fw_ready = 1;

	/* Firmware doesn't seem to give us RX packets any more
	   until we send it some command. Might as well update */
	lbs_prepare_and_send_command(priv, CMD_802_11_RSSI, 0,
				     0, 0, NULL);

	netif_device_attach(priv->dev);
	if (priv->mesh_dev)
		netif_device_attach(priv->mesh_dev);

1004
	lbs_deb_leave(LBS_DEB_FW);
1005 1006 1007
}
EXPORT_SYMBOL_GPL(lbs_resume);

H
Holger Schurig 已提交
1008 1009 1010 1011 1012
/**
 *  @brief This function downloads firmware image, gets
 *  HW spec from firmware and set basic parameters to
 *  firmware.
 *
1013
 *  @param priv    A pointer to struct lbs_private structure
H
Holger Schurig 已提交
1014 1015
 *  @return 	   0 or -1
 */
1016
static int lbs_setup_firmware(struct lbs_private *priv)
H
Holger Schurig 已提交
1017 1018
{
	int ret = -1;
1019
	s16 curlevel = 0, minlevel = 0, maxlevel = 0;
H
Holger Schurig 已提交
1020 1021 1022

	lbs_deb_enter(LBS_DEB_FW);

1023
	/* Read MAC address from firmware */
1024
	memset(priv->current_addr, 0xff, ETH_ALEN);
1025
	ret = lbs_update_hw_spec(priv);
1026
	if (ret)
H
Holger Schurig 已提交
1027 1028
		goto done;

1029 1030 1031 1032 1033 1034 1035 1036
	/* Read power levels if available */
	ret = lbs_get_tx_power(priv, &curlevel, &minlevel, &maxlevel);
	if (ret == 0) {
		priv->txpower_cur = curlevel;
		priv->txpower_min = minlevel;
		priv->txpower_max = maxlevel;
	}

1037
	lbs_set_mac_control(priv);
H
Holger Schurig 已提交
1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048
done:
	lbs_deb_leave_args(LBS_DEB_FW, "ret %d", ret);
	return ret;
}

/**
 *  This function handles the timeout of command sending.
 *  It will re-send the same command again.
 */
static void command_timer_fn(unsigned long data)
{
1049
	struct lbs_private *priv = (struct lbs_private *)data;
H
Holger Schurig 已提交
1050 1051
	unsigned long flags;

1052
	lbs_deb_enter(LBS_DEB_CMD);
1053
	spin_lock_irqsave(&priv->driver_lock, flags);
H
Holger Schurig 已提交
1054

1055
	if (!priv->cur_cmd)
1056
		goto out;
H
Holger Schurig 已提交
1057

1058 1059
	lbs_pr_info("command 0x%04x timed out\n",
		le16_to_cpu(priv->cur_cmd->cmdbuf->command));
H
Holger Schurig 已提交
1060

1061
	priv->cmd_timed_out = 1;
H
Holger Schurig 已提交
1062
	wake_up_interruptible(&priv->waitq);
1063
out:
1064
	spin_unlock_irqrestore(&priv->driver_lock, flags);
1065
	lbs_deb_leave(LBS_DEB_CMD);
H
Holger Schurig 已提交
1066 1067
}

1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079
static void lbs_sync_channel_worker(struct work_struct *work)
{
	struct lbs_private *priv = container_of(work, struct lbs_private,
		sync_channel);

	lbs_deb_enter(LBS_DEB_MAIN);
	if (lbs_update_channel(priv))
		lbs_pr_info("Channel synchronization failed.");
	lbs_deb_leave(LBS_DEB_MAIN);
}


1080
static int lbs_init_adapter(struct lbs_private *priv)
1081
{
H
Holger Schurig 已提交
1082
	size_t bufsize;
1083
	int i, ret = 0;
H
Holger Schurig 已提交
1084

1085 1086
	lbs_deb_enter(LBS_DEB_MAIN);

H
Holger Schurig 已提交
1087 1088
	/* Allocate buffer to store the BSSID list */
	bufsize = MAX_NETWORK_COUNT * sizeof(struct bss_descriptor);
1089 1090
	priv->networks = kzalloc(bufsize, GFP_KERNEL);
	if (!priv->networks) {
H
Holger Schurig 已提交
1091
		lbs_pr_err("Out of memory allocating beacons\n");
1092 1093
		ret = -1;
		goto out;
H
Holger Schurig 已提交
1094 1095
	}

1096
	/* Initialize scan result lists */
1097 1098
	INIT_LIST_HEAD(&priv->network_free_list);
	INIT_LIST_HEAD(&priv->network_list);
1099
	for (i = 0; i < MAX_NETWORK_COUNT; i++) {
1100 1101
		list_add_tail(&priv->networks[i].list,
			      &priv->network_free_list);
1102
	}
H
Holger Schurig 已提交
1103

1104
	memset(priv->current_addr, 0xff, ETH_ALEN);
H
Holger Schurig 已提交
1105

1106 1107 1108 1109 1110
	priv->connect_status = LBS_DISCONNECTED;
	priv->mesh_connect_status = LBS_DISCONNECTED;
	priv->secinfo.auth_mode = IW_AUTH_ALG_OPEN_SYSTEM;
	priv->mode = IW_MODE_INFRA;
	priv->curbssparams.channel = DEFAULT_AD_HOC_CHANNEL;
1111
	priv->mac_control = CMD_ACT_MAC_RX_ON | CMD_ACT_MAC_TX_ON;
1112
	priv->radio_on = 1;
1113
	priv->enablehwauto = 1;
1114 1115 1116
	priv->capability = WLAN_CAPABILITY_SHORT_PREAMBLE;
	priv->psmode = LBS802_11POWERMODECAM;
	priv->psstate = PS_STATE_FULL_POWER;
H
Holger Schurig 已提交
1117

1118
	mutex_init(&priv->lock);
H
Holger Schurig 已提交
1119

1120
	setup_timer(&priv->command_timer, command_timer_fn,
1121
		(unsigned long)priv);
H
Holger Schurig 已提交
1122

1123 1124
	INIT_LIST_HEAD(&priv->cmdfreeq);
	INIT_LIST_HEAD(&priv->cmdpendingq);
H
Holger Schurig 已提交
1125

1126 1127
	spin_lock_init(&priv->driver_lock);
	init_waitqueue_head(&priv->cmd_pending);
H
Holger Schurig 已提交
1128

1129
	/* Allocate the command buffers */
1130
	if (lbs_allocate_cmd_buffer(priv)) {
1131
		lbs_pr_err("Out of memory allocating command buffers\n");
1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143
		ret = -ENOMEM;
		goto out;
	}
	priv->resp_idx = 0;
	priv->resp_len[0] = priv->resp_len[1] = 0;

	/* Create the event FIFO */
	priv->event_fifo = kfifo_alloc(sizeof(u32) * 16, GFP_KERNEL, NULL);
	if (IS_ERR(priv->event_fifo)) {
		lbs_pr_err("Out of memory allocating event FIFO buffer\n");
		ret = -ENOMEM;
		goto out;
1144
	}
H
Holger Schurig 已提交
1145

1146
out:
1147 1148
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);

1149 1150
	return ret;
}
H
Holger Schurig 已提交
1151

1152
static void lbs_free_adapter(struct lbs_private *priv)
1153
{
1154
	lbs_deb_enter(LBS_DEB_MAIN);
H
Holger Schurig 已提交
1155

1156
	lbs_free_cmd_buffer(priv);
1157 1158
	if (priv->event_fifo)
		kfifo_free(priv->event_fifo);
1159 1160 1161
	del_timer(&priv->command_timer);
	kfree(priv->networks);
	priv->networks = NULL;
1162 1163

	lbs_deb_leave(LBS_DEB_MAIN);
H
Holger Schurig 已提交
1164 1165
}

1166 1167
/**
 * @brief This function adds the card. it will probe the
1168
 * card, allocate the lbs_priv and initialize the device.
1169 1170
 *
 *  @param card    A pointer to card
1171
 *  @return 	   A pointer to struct lbs_private structure
1172
 */
1173
struct lbs_private *lbs_add_card(void *card, struct device *dmdev)
1174 1175
{
	struct net_device *dev = NULL;
1176
	struct lbs_private *priv = NULL;
1177

1178
	lbs_deb_enter(LBS_DEB_MAIN);
1179 1180

	/* Allocate an Ethernet device and register it */
1181 1182
	dev = alloc_etherdev(sizeof(struct lbs_private));
	if (!dev) {
1183
		lbs_pr_err("init ethX device failed\n");
1184
		goto done;
1185
	}
1186
	priv = netdev_priv(dev);
1187

1188
	if (lbs_init_adapter(priv)) {
1189 1190 1191 1192
		lbs_pr_err("failed to initialize adapter structure.\n");
		goto err_init_adapter;
	}

1193 1194
	priv->dev = dev;
	priv->card = card;
1195 1196 1197 1198
	priv->mesh_open = 0;
	priv->infra_open = 0;

	/* Setup the OS Interface to our functions */
1199
	dev->open = lbs_dev_open;
1200
	dev->hard_start_xmit = lbs_hard_start_xmit;
1201
	dev->stop = lbs_eth_stop;
1202 1203 1204
	dev->set_mac_address = lbs_set_mac_address;
	dev->tx_timeout = lbs_tx_timeout;
	dev->get_stats = lbs_get_stats;
1205
	dev->watchdog_timeo = 5 * HZ;
1206
	dev->ethtool_ops = &lbs_ethtool_ops;
1207
#ifdef	WIRELESS_EXT
1208
	dev->wireless_handlers = (struct iw_handler_def *)&lbs_handler_def;
1209 1210
#endif
	dev->flags |= IFF_BROADCAST | IFF_MULTICAST;
1211
	dev->set_multicast_list = lbs_set_multicast_list;
1212

1213 1214
	SET_NETDEV_DEV(dev, dmdev);

1215
	priv->rtap_net_dev = NULL;
1216 1217 1218

	lbs_deb_thread("Starting main thread...\n");
	init_waitqueue_head(&priv->waitq);
1219
	priv->main_thread = kthread_run(lbs_thread, dev, "lbs_main");
1220 1221
	if (IS_ERR(priv->main_thread)) {
		lbs_deb_thread("Error creating main thread.\n");
1222
		goto err_init_adapter;
1223 1224
	}

1225 1226 1227
	priv->work_thread = create_singlethread_workqueue("lbs_worker");
	INIT_DELAYED_WORK(&priv->assoc_work, lbs_association_worker);
	INIT_DELAYED_WORK(&priv->scan_work, lbs_scan_worker);
1228
	INIT_WORK(&priv->mcast_work, lbs_set_mcast_worker);
1229
	INIT_WORK(&priv->sync_channel, lbs_sync_channel_worker);
1230

1231 1232 1233
	sprintf(priv->mesh_ssid, "mesh");
	priv->mesh_ssid_len = 4;

1234 1235 1236
	priv->wol_criteria = 0xffffffff;
	priv->wol_gpio = 0xff;

1237 1238
	goto done;

1239
err_init_adapter:
1240
	lbs_free_adapter(priv);
1241
	free_netdev(dev);
1242
	priv = NULL;
1243

1244
done:
1245
	lbs_deb_leave_args(LBS_DEB_MAIN, "priv %p", priv);
1246 1247
	return priv;
}
1248
EXPORT_SYMBOL_GPL(lbs_add_card);
1249

1250

1251
void lbs_remove_card(struct lbs_private *priv)
1252
{
1253
	struct net_device *dev = priv->dev;
1254
	union iwreq_data wrqu;
1255 1256

	lbs_deb_enter(LBS_DEB_MAIN);
1257

1258
	lbs_remove_mesh(priv);
1259
	lbs_remove_rtap(priv);
1260

1261
	dev = priv->dev;
1262

1263 1264
	cancel_delayed_work_sync(&priv->scan_work);
	cancel_delayed_work_sync(&priv->assoc_work);
1265
	cancel_work_sync(&priv->mcast_work);
1266 1267 1268 1269 1270

	/* worker thread destruction blocks on the in-flight command which
	 * should have been cleared already in lbs_stop_card().
	 */
	lbs_deb_main("destroying worker thread\n");
1271
	destroy_workqueue(priv->work_thread);
1272
	lbs_deb_main("done destroying worker thread\n");
1273

1274 1275
	if (priv->psmode == LBS802_11POWERMODEMAX_PSP) {
		priv->psmode = LBS802_11POWERMODECAM;
1276
		lbs_ps_wakeup(priv, CMD_OPTION_WAITFORRSP);
1277 1278
	}

1279 1280 1281 1282 1283
	memset(wrqu.ap_addr.sa_data, 0xaa, ETH_ALEN);
	wrqu.ap_addr.sa_family = ARPHRD_ETHER;
	wireless_send_event(priv->dev, SIOCGIWAP, &wrqu, NULL);

	/* Stop the thread servicing the interrupts */
1284
	priv->surpriseremoved = 1;
1285 1286
	kthread_stop(priv->main_thread);

1287
	lbs_free_adapter(priv);
1288 1289 1290 1291 1292 1293

	priv->dev = NULL;
	free_netdev(dev);

	lbs_deb_leave(LBS_DEB_MAIN);
}
1294
EXPORT_SYMBOL_GPL(lbs_remove_card);
1295 1296


1297
int lbs_start_card(struct lbs_private *priv)
1298 1299 1300 1301 1302 1303 1304
{
	struct net_device *dev = priv->dev;
	int ret = -1;

	lbs_deb_enter(LBS_DEB_MAIN);

	/* poke the firmware */
1305
	ret = lbs_setup_firmware(priv);
1306 1307 1308 1309
	if (ret)
		goto done;

	/* init 802.11d */
1310
	lbs_init_11d(priv);
1311 1312

	if (register_netdev(dev)) {
1313
		lbs_pr_err("cannot register ethX device\n");
1314
		goto done;
1315
	}
1316 1317 1318

	lbs_update_channel(priv);

1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334
	/* 5.0.16p0 is known to NOT support any mesh */
	if (priv->fwrelease > 0x05001000) {
		/* Enable mesh, if supported, and work out which TLV it uses.
		   0x100 + 291 is an unofficial value used in 5.110.20.pXX
		   0x100 + 37 is the official value used in 5.110.21.pXX
		   but we check them in that order because 20.pXX doesn't
		   give an error -- it just silently fails. */

		/* 5.110.20.pXX firmware will fail the command if the channel
		   doesn't match the existing channel. But only if the TLV
		   is correct. If the channel is wrong, _BOTH_ versions will
		   give an error to 0x100+291, and allow 0x100+37 to succeed.
		   It's just that 5.110.20.pXX will not have done anything
		   useful */

		priv->mesh_tlv = 0x100 + 291;
1335 1336
		if (lbs_mesh_config(priv, CMD_ACT_MESH_CONFIG_START,
				    priv->curbssparams.channel)) {
1337
			priv->mesh_tlv = 0x100 + 37;
1338 1339
			if (lbs_mesh_config(priv, CMD_ACT_MESH_CONFIG_START,
					    priv->curbssparams.channel))
1340 1341 1342 1343 1344 1345 1346
				priv->mesh_tlv = 0;
		}
		if (priv->mesh_tlv) {
			lbs_add_mesh(priv);

			if (device_create_file(&dev->dev, &dev_attr_lbs_mesh))
				lbs_pr_err("cannot register lbs_mesh attribute\n");
1347 1348 1349 1350 1351 1352 1353

			/* While rtap isn't related to mesh, only mesh-enabled
			 * firmware implements the rtap functionality via
			 * CMD_802_11_MONITOR_MODE.
			 */
			if (device_create_file(&dev->dev, &dev_attr_lbs_rtap))
				lbs_pr_err("cannot register lbs_rtap attribute\n");
1354
		}
1355
	}
1356

1357
	lbs_debugfs_init_one(priv, dev);
1358

1359 1360
	lbs_pr_info("%s: Marvell WLAN 802.11 adapter\n", dev->name);

1361
	ret = 0;
1362

1363
done:
1364 1365 1366
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
	return ret;
}
1367
EXPORT_SYMBOL_GPL(lbs_start_card);
1368 1369


1370
void lbs_stop_card(struct lbs_private *priv)
1371
{
1372
	struct net_device *dev;
1373 1374 1375 1376 1377
	struct cmd_ctrl_node *cmdnode;
	unsigned long flags;

	lbs_deb_enter(LBS_DEB_MAIN);

1378 1379
	if (!priv)
		goto out;
1380
	dev = priv->dev;
1381

1382 1383
	netif_stop_queue(dev);
	netif_carrier_off(dev);
1384

1385
	lbs_debugfs_remove_one(priv);
1386
	if (priv->mesh_tlv) {
1387
		device_remove_file(&dev->dev, &dev_attr_lbs_mesh);
1388
		device_remove_file(&dev->dev, &dev_attr_lbs_rtap);
1389
	}
1390

1391
	/* Delete the timeout of the currently processing command */
1392
	del_timer_sync(&priv->command_timer);
1393 1394

	/* Flush pending command nodes */
1395
	spin_lock_irqsave(&priv->driver_lock, flags);
1396
	lbs_deb_main("clearing pending commands\n");
1397
	list_for_each_entry(cmdnode, &priv->cmdpendingq, list) {
1398
		cmdnode->result = -ENOENT;
1399 1400 1401
		cmdnode->cmdwaitqwoken = 1;
		wake_up_interruptible(&cmdnode->cmdwait_q);
	}
1402 1403 1404 1405 1406 1407 1408 1409 1410

	/* Flush the command the card is currently processing */
	if (priv->cur_cmd) {
		lbs_deb_main("clearing current command\n");
		priv->cur_cmd->result = -ENOENT;
		priv->cur_cmd->cmdwaitqwoken = 1;
		wake_up_interruptible(&priv->cur_cmd->cmdwait_q);
	}
	lbs_deb_main("done clearing commands\n");
1411
	spin_unlock_irqrestore(&priv->driver_lock, flags);
1412 1413 1414

	unregister_netdev(dev);

1415
out:
1416
	lbs_deb_leave(LBS_DEB_MAIN);
1417
}
1418
EXPORT_SYMBOL_GPL(lbs_stop_card);
1419

1420

1421 1422 1423
/**
 * @brief This function adds mshX interface
 *
1424
 *  @param priv    A pointer to the struct lbs_private structure
1425 1426
 *  @return 	   0 if successful, -X otherwise
 */
1427
static int lbs_add_mesh(struct lbs_private *priv)
1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439
{
	struct net_device *mesh_dev = NULL;
	int ret = 0;

	lbs_deb_enter(LBS_DEB_MESH);

	/* Allocate a virtual mesh device */
	if (!(mesh_dev = alloc_netdev(0, "msh%d", ether_setup))) {
		lbs_deb_mesh("init mshX device failed\n");
		ret = -ENOMEM;
		goto done;
	}
1440
	mesh_dev->ml_priv = priv;
1441 1442
	priv->mesh_dev = mesh_dev;

1443
	mesh_dev->open = lbs_dev_open;
1444
	mesh_dev->hard_start_xmit = lbs_hard_start_xmit;
1445
	mesh_dev->stop = lbs_mesh_stop;
1446 1447 1448
	mesh_dev->get_stats = lbs_get_stats;
	mesh_dev->set_mac_address = lbs_set_mac_address;
	mesh_dev->ethtool_ops = &lbs_ethtool_ops;
1449 1450
	memcpy(mesh_dev->dev_addr, priv->dev->dev_addr,
			sizeof(priv->dev->dev_addr));
1451

1452
	SET_NETDEV_DEV(priv->mesh_dev, priv->dev->dev.parent);
1453

1454
#ifdef	WIRELESS_EXT
1455
	mesh_dev->wireless_handlers = (struct iw_handler_def *)&mesh_handler_def;
1456
#endif
1457 1458
	mesh_dev->flags |= IFF_BROADCAST | IFF_MULTICAST;
	mesh_dev->set_multicast_list = lbs_set_multicast_list;
1459 1460 1461 1462 1463 1464 1465
	/* Register virtual mesh interface */
	ret = register_netdev(mesh_dev);
	if (ret) {
		lbs_pr_err("cannot register mshX virtual interface\n");
		goto err_free;
	}

1466
	ret = sysfs_create_group(&(mesh_dev->dev.kobj), &lbs_mesh_attr_group);
1467 1468 1469
	if (ret)
		goto err_unregister;

1470 1471
	lbs_persist_config_init(mesh_dev);

1472 1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485
	/* Everything successful */
	ret = 0;
	goto done;

err_unregister:
	unregister_netdev(mesh_dev);

err_free:
	free_netdev(mesh_dev);

done:
	lbs_deb_leave_args(LBS_DEB_MESH, "ret %d", ret);
	return ret;
}
1486

1487
static void lbs_remove_mesh(struct lbs_private *priv)
1488 1489 1490 1491 1492
{
	struct net_device *mesh_dev;


	mesh_dev = priv->mesh_dev;
1493
	if (!mesh_dev)
1494
		return;
1495

1496
	lbs_deb_enter(LBS_DEB_MESH);
1497
	netif_stop_queue(mesh_dev);
1498
	netif_carrier_off(mesh_dev);
1499
	sysfs_remove_group(&(mesh_dev->dev.kobj), &lbs_mesh_attr_group);
1500
	lbs_persist_config_remove(mesh_dev);
1501
	unregister_netdev(mesh_dev);
1502
	priv->mesh_dev = NULL;
1503
	free_netdev(mesh_dev);
1504
	lbs_deb_leave(LBS_DEB_MESH);
1505 1506
}

1507 1508 1509 1510 1511 1512 1513 1514 1515
/**
 *  @brief This function finds the CFP in
 *  region_cfp_table based on region and band parameter.
 *
 *  @param region  The region code
 *  @param band	   The band
 *  @param cfp_no  A pointer to CFP number
 *  @return 	   A pointer to CFP
 */
1516
struct chan_freq_power *lbs_get_region_cfp_table(u8 region, int *cfp_no)
1517 1518 1519
{
	int i, end;

1520
	lbs_deb_enter(LBS_DEB_MAIN);
1521

1522
	end = ARRAY_SIZE(region_cfp_table);
1523 1524

	for (i = 0; i < end ; i++) {
1525
		lbs_deb_main("region_cfp_table[i].region=%d\n",
1526 1527 1528
			region_cfp_table[i].region);
		if (region_cfp_table[i].region == region) {
			*cfp_no = region_cfp_table[i].cfp_no_BG;
1529
			lbs_deb_leave(LBS_DEB_MAIN);
1530 1531 1532 1533
			return region_cfp_table[i].cfp_BG;
		}
	}

1534
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret NULL");
1535 1536 1537
	return NULL;
}

1538
int lbs_set_regiontable(struct lbs_private *priv, u8 region, u8 band)
1539
{
1540
	int ret = 0;
1541 1542 1543 1544 1545
	int i = 0;

	struct chan_freq_power *cfp;
	int cfp_no;

1546
	lbs_deb_enter(LBS_DEB_MAIN);
1547

1548
	memset(priv->region_channel, 0, sizeof(priv->region_channel));
1549

1550
	cfp = lbs_get_region_cfp_table(region, &cfp_no);
1551 1552 1553 1554 1555 1556 1557 1558
	if (cfp != NULL) {
		priv->region_channel[i].nrcfp = cfp_no;
		priv->region_channel[i].CFP = cfp;
	} else {
		lbs_deb_main("wrong region code %#x in band B/G\n",
		       region);
		ret = -1;
		goto out;
1559
	}
1560 1561 1562 1563
	priv->region_channel[i].valid = 1;
	priv->region_channel[i].region = region;
	priv->region_channel[i].band = band;
	i++;
1564 1565 1566
out:
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
	return ret;
1567 1568
}

1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588
void lbs_queue_event(struct lbs_private *priv, u32 event)
{
	unsigned long flags;

	lbs_deb_enter(LBS_DEB_THREAD);
	spin_lock_irqsave(&priv->driver_lock, flags);

	if (priv->psstate == PS_STATE_SLEEP)
		priv->psstate = PS_STATE_AWAKE;

	__kfifo_put(priv->event_fifo, (unsigned char *) &event, sizeof(u32));

	wake_up_interruptible(&priv->waitq);

	spin_unlock_irqrestore(&priv->driver_lock, flags);
	lbs_deb_leave(LBS_DEB_THREAD);
}
EXPORT_SYMBOL_GPL(lbs_queue_event);

void lbs_notify_command_response(struct lbs_private *priv, u8 resp_idx)
1589
{
1590
	lbs_deb_enter(LBS_DEB_THREAD);
1591

1592
	if (priv->psstate == PS_STATE_SLEEP)
1593
		priv->psstate = PS_STATE_AWAKE;
1594 1595 1596 1597 1598

	/* Swap buffers by flipping the response index */
	BUG_ON(resp_idx > 1);
	priv->resp_idx = resp_idx;

1599
	wake_up_interruptible(&priv->waitq);
1600

1601
	lbs_deb_leave(LBS_DEB_THREAD);
1602
}
1603
EXPORT_SYMBOL_GPL(lbs_notify_command_response);
1604

1605
static int __init lbs_init_module(void)
1606
{
1607
	lbs_deb_enter(LBS_DEB_MAIN);
1608 1609 1610 1611
	memset(&confirm_sleep, 0, sizeof(confirm_sleep));
	confirm_sleep.hdr.command = cpu_to_le16(CMD_802_11_PS_MODE);
	confirm_sleep.hdr.size = cpu_to_le16(sizeof(confirm_sleep));
	confirm_sleep.action = cpu_to_le16(CMD_SUBCMD_SLEEP_CONFIRMED);
1612
	lbs_debugfs_init();
1613 1614
	lbs_deb_leave(LBS_DEB_MAIN);
	return 0;
1615 1616
}

1617
static void __exit lbs_exit_module(void)
1618
{
1619
	lbs_deb_enter(LBS_DEB_MAIN);
1620
	lbs_debugfs_remove();
1621
	lbs_deb_leave(LBS_DEB_MAIN);
1622 1623
}

1624 1625 1626 1627
/*
 * rtap interface support fuctions
 */

1628
static int lbs_rtap_open(struct net_device *dev)
1629
{
1630
	/* Yes, _stop_ the queue. Because we don't support injection */
1631 1632 1633 1634 1635
	lbs_deb_enter(LBS_DEB_MAIN);
	netif_carrier_off(dev);
	netif_stop_queue(dev);
	lbs_deb_leave(LBS_DEB_LEAVE);
	return 0;
1636 1637
}

1638
static int lbs_rtap_stop(struct net_device *dev)
1639
{
1640 1641 1642
	lbs_deb_enter(LBS_DEB_MAIN);
	lbs_deb_leave(LBS_DEB_MAIN);
	return 0;
1643 1644
}

1645
static int lbs_rtap_hard_start_xmit(struct sk_buff *skb, struct net_device *dev)
1646
{
1647 1648
	netif_stop_queue(dev);
	return NETDEV_TX_BUSY;
1649 1650
}

1651
static struct net_device_stats *lbs_rtap_get_stats(struct net_device *dev)
1652
{
1653
	struct lbs_private *priv = dev->ml_priv;
1654
	lbs_deb_enter(LBS_DEB_NET);
1655
	return &priv->stats;
1656 1657 1658
}


1659
static void lbs_remove_rtap(struct lbs_private *priv)
1660
{
1661
	lbs_deb_enter(LBS_DEB_MAIN);
1662
	if (priv->rtap_net_dev == NULL)
1663
		goto out;
1664
	unregister_netdev(priv->rtap_net_dev);
1665
	free_netdev(priv->rtap_net_dev);
1666
	priv->rtap_net_dev = NULL;
1667
out:
1668
	lbs_deb_leave(LBS_DEB_MAIN);
1669 1670
}

1671
static int lbs_add_rtap(struct lbs_private *priv)
1672
{
1673
	int ret = 0;
1674
	struct net_device *rtap_dev;
1675

1676 1677 1678 1679 1680
	lbs_deb_enter(LBS_DEB_MAIN);
	if (priv->rtap_net_dev) {
		ret = -EPERM;
		goto out;
	}
1681

1682
	rtap_dev = alloc_netdev(0, "rtap%d", ether_setup);
1683 1684 1685 1686
	if (rtap_dev == NULL) {
		ret = -ENOMEM;
		goto out;
	}
1687

1688
	memcpy(rtap_dev->dev_addr, priv->current_addr, ETH_ALEN);
1689 1690 1691 1692 1693
	rtap_dev->type = ARPHRD_IEEE80211_RADIOTAP;
	rtap_dev->open = lbs_rtap_open;
	rtap_dev->stop = lbs_rtap_stop;
	rtap_dev->get_stats = lbs_rtap_get_stats;
	rtap_dev->hard_start_xmit = lbs_rtap_hard_start_xmit;
1694
	rtap_dev->ml_priv = priv;
1695
	SET_NETDEV_DEV(rtap_dev, priv->dev->dev.parent);
1696

1697 1698
	ret = register_netdev(rtap_dev);
	if (ret) {
1699
		free_netdev(rtap_dev);
1700
		goto out;
1701
	}
1702
	priv->rtap_net_dev = rtap_dev;
1703

1704 1705 1706
out:
	lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
	return ret;
1707 1708
}

1709 1710
module_init(lbs_init_module);
module_exit(lbs_exit_module);
1711

1712
MODULE_DESCRIPTION("Libertas WLAN Driver Library");
1713 1714
MODULE_AUTHOR("Marvell International Ltd.");
MODULE_LICENSE("GPL");