iwl-agn.c 105.3 KB
Newer Older
Z
Zhu Yi 已提交
1 2
/******************************************************************************
 *
W
Wey-Yi Guy 已提交
3
 * Copyright(c) 2003 - 2011 Intel Corporation. All rights reserved.
Z
Zhu Yi 已提交
4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
 *
 * Portions of this file are derived from the ipw3945 project, as well
 * as portions of the ieee80211 subsystem header files.
 *
 * This program is free software; you can redistribute it and/or modify it
 * under the terms of version 2 of the GNU General Public License as
 * published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful, but WITHOUT
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
 * more details.
 *
 * You should have received a copy of the GNU General Public License along with
 * this program; if not, write to the Free Software Foundation, Inc.,
 * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
 *
 * The full GNU General Public License is included in this distribution in the
 * file called LICENSE.
 *
 * Contact Information:
25
 *  Intel Linux Wireless <ilw@linux.intel.com>
Z
Zhu Yi 已提交
26 27 28 29
 * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
 *
 *****************************************************************************/

30 31
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

Z
Zhu Yi 已提交
32 33 34
#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/init.h>
35
#include <linux/slab.h>
Z
Zhu Yi 已提交
36 37
#include <linux/dma-mapping.h>
#include <linux/delay.h>
38
#include <linux/sched.h>
Z
Zhu Yi 已提交
39 40 41 42 43 44 45 46 47 48 49
#include <linux/skbuff.h>
#include <linux/netdevice.h>
#include <linux/wireless.h>
#include <linux/firmware.h>
#include <linux/etherdevice.h>
#include <linux/if_arp.h>

#include <net/mac80211.h>

#include <asm/div64.h>

A
Assaf Krauss 已提交
50
#include "iwl-eeprom.h"
51
#include "iwl-dev.h"
52
#include "iwl-core.h"
53
#include "iwl-io.h"
Z
Zhu Yi 已提交
54
#include "iwl-helpers.h"
55
#include "iwl-sta.h"
J
Johannes Berg 已提交
56
#include "iwl-agn-calib.h"
57
#include "iwl-agn.h"
58
#include "iwl-pci.h"
Z
Zhu Yi 已提交
59

60

Z
Zhu Yi 已提交
61 62 63 64 65 66 67 68 69
/******************************************************************************
 *
 * module boiler plate
 *
 ******************************************************************************/

/*
 * module name, copyright, version, etc.
 */
70
#define DRV_DESCRIPTION	"Intel(R) Wireless WiFi Link AGN driver for Linux"
Z
Zhu Yi 已提交
71

72
#ifdef CONFIG_IWLWIFI_DEBUG
Z
Zhu Yi 已提交
73 74 75 76 77
#define VD "d"
#else
#define VD
#endif

78
#define DRV_VERSION     IWLWIFI_VERSION VD
Z
Zhu Yi 已提交
79 80 81 82


MODULE_DESCRIPTION(DRV_DESCRIPTION);
MODULE_VERSION(DRV_VERSION);
83
MODULE_AUTHOR(DRV_COPYRIGHT " " DRV_AUTHOR);
Z
Zhu Yi 已提交
84 85
MODULE_LICENSE("GPL");

86
static int iwlagn_ant_coupling;
87
static bool iwlagn_bt_ch_announce = 1;
88

89
void iwl_update_chain_flags(struct iwl_priv *priv)
M
Mohamed Abbas 已提交
90
{
91
	struct iwl_rxon_context *ctx;
M
Mohamed Abbas 已提交
92

93 94 95
	if (priv->cfg->ops->hcmd->set_rxon_chain) {
		for_each_context(priv, ctx) {
			priv->cfg->ops->hcmd->set_rxon_chain(priv, ctx);
96
			if (ctx->active.rx_chain != ctx->staging.rx_chain)
97
				iwlagn_commit_rxon(priv, ctx);
98 99
		}
	}
M
Mohamed Abbas 已提交
100 101
}

102 103
/* Parse the beacon frame to find the TIM element and set tim_idx & tim_size */
static void iwl_set_beacon_tim(struct iwl_priv *priv,
104 105
			       struct iwl_tx_beacon_cmd *tx_beacon_cmd,
			       u8 *beacon, u32 frame_size)
106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128
{
	u16 tim_idx;
	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)beacon;

	/*
	 * The index is relative to frame start but we start looking at the
	 * variable-length part of the beacon.
	 */
	tim_idx = mgmt->u.beacon.variable - beacon;

	/* Parse variable-length elements of beacon to find WLAN_EID_TIM */
	while ((tim_idx < (frame_size - 2)) &&
			(beacon[tim_idx] != WLAN_EID_TIM))
		tim_idx += beacon[tim_idx+1] + 2;

	/* If TIM field was found, set variables */
	if ((tim_idx < (frame_size - 1)) && (beacon[tim_idx] == WLAN_EID_TIM)) {
		tx_beacon_cmd->tim_idx = cpu_to_le16(tim_idx);
		tx_beacon_cmd->tim_size = beacon[tim_idx+1];
	} else
		IWL_WARN(priv, "Unable to find TIM Element in beacon\n");
}

129
int iwlagn_send_beacon_cmd(struct iwl_priv *priv)
130 131
{
	struct iwl_tx_beacon_cmd *tx_beacon_cmd;
132 133 134
	struct iwl_host_cmd cmd = {
		.id = REPLY_TX_BEACON,
	};
135 136 137
	u32 frame_size;
	u32 rate_flags;
	u32 rate;
138

139 140 141 142
	/*
	 * We have to set up the TX command, the TX Beacon command, and the
	 * beacon contents.
	 */
143

144 145 146 147
	lockdep_assert_held(&priv->mutex);

	if (!priv->beacon_ctx) {
		IWL_ERR(priv, "trying to build beacon w/o beacon context!\n");
148
		return 0;
149 150
	}

151 152 153
	if (WARN_ON(!priv->beacon_skb))
		return -EINVAL;

154 155 156 157
	/* Allocate beacon command */
	if (!priv->beacon_cmd)
		priv->beacon_cmd = kzalloc(sizeof(*tx_beacon_cmd), GFP_KERNEL);
	tx_beacon_cmd = priv->beacon_cmd;
158 159 160 161
	if (!tx_beacon_cmd)
		return -ENOMEM;

	frame_size = priv->beacon_skb->len;
162

163
	/* Set up TX command fields */
164
	tx_beacon_cmd->tx.len = cpu_to_le16((u16)frame_size);
165
	tx_beacon_cmd->tx.sta_id = priv->beacon_ctx->bcast_sta_id;
166 167 168
	tx_beacon_cmd->tx.stop_time.life_time = TX_CMD_LIFE_TIME_INFINITE;
	tx_beacon_cmd->tx.tx_flags = TX_CMD_FLG_SEQ_CTL_MSK |
		TX_CMD_FLG_TSF_MSK | TX_CMD_FLG_STA_RATE_MSK;
169

170
	/* Set up TX beacon command fields */
171
	iwl_set_beacon_tim(priv, tx_beacon_cmd, priv->beacon_skb->data,
172
			   frame_size);
173

174
	/* Set up packet rate and flags */
175
	rate = iwl_rate_get_lowest_plcp(priv, priv->beacon_ctx);
176 177
	priv->mgmt_tx_ant = iwl_toggle_tx_ant(priv, priv->mgmt_tx_ant,
					      priv->hw_params.valid_tx_ant);
178 179 180 181 182
	rate_flags = iwl_ant_idx_to_flags(priv->mgmt_tx_ant);
	if ((rate >= IWL_FIRST_CCK_RATE) && (rate <= IWL_LAST_CCK_RATE))
		rate_flags |= RATE_MCS_CCK_MSK;
	tx_beacon_cmd->tx.rate_n_flags = iwl_hw_set_rate_n_flags(rate,
			rate_flags);
183

184
	/* Submit command */
185
	cmd.len[0] = sizeof(*tx_beacon_cmd);
186
	cmd.data[0] = tx_beacon_cmd;
187 188 189 190
	cmd.dataflags[0] = IWL_HCMD_DFL_NOCOPY;
	cmd.len[1] = frame_size;
	cmd.data[1] = priv->beacon_skb->data;
	cmd.dataflags[1] = IWL_HCMD_DFL_NOCOPY;
191

192
	return iwl_send_cmd_sync(priv, &cmd);
193 194
}

195
static void iwl_bg_beacon_update(struct work_struct *work)
Z
Zhu Yi 已提交
196
{
197 198
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, beacon_update);
Z
Zhu Yi 已提交
199 200
	struct sk_buff *beacon;

201 202 203 204 205
	mutex_lock(&priv->mutex);
	if (!priv->beacon_ctx) {
		IWL_ERR(priv, "updating beacon w/o beacon context!\n");
		goto out;
	}
Z
Zhu Yi 已提交
206

207 208 209 210 211 212 213 214 215 216
	if (priv->beacon_ctx->vif->type != NL80211_IFTYPE_AP) {
		/*
		 * The ucode will send beacon notifications even in
		 * IBSS mode, but we don't want to process them. But
		 * we need to defer the type check to here due to
		 * requiring locking around the beacon_ctx access.
		 */
		goto out;
	}

217 218
	/* Pull updated AP beacon from mac80211. will fail if not in AP mode */
	beacon = ieee80211_beacon_get(priv->hw, priv->beacon_ctx->vif);
Z
Zhu Yi 已提交
219
	if (!beacon) {
220
		IWL_ERR(priv, "update beacon failed -- keeping old\n");
221
		goto out;
Z
Zhu Yi 已提交
222 223 224
	}

	/* new beacon skb is allocated every time; dispose previous.*/
225
	dev_kfree_skb(priv->beacon_skb);
Z
Zhu Yi 已提交
226

227
	priv->beacon_skb = beacon;
Z
Zhu Yi 已提交
228

229
	iwlagn_send_beacon_cmd(priv);
230 231
 out:
	mutex_unlock(&priv->mutex);
Z
Zhu Yi 已提交
232 233
}

234 235 236 237 238 239 240 241 242 243 244 245 246 247
static void iwl_bg_bt_runtime_config(struct work_struct *work)
{
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, bt_runtime_config);

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	/* dont send host command if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
		return;
	priv->cfg->ops->hcmd->send_bt_config(priv);
}

248 249 250 251
static void iwl_bg_bt_full_concurrency(struct work_struct *work)
{
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, bt_full_concurrency);
252
	struct iwl_rxon_context *ctx;
253

254 255
	mutex_lock(&priv->mutex);

256
	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
257
		goto out;
258 259 260

	/* dont send host command if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
261
		goto out;
262 263 264 265 266 267 268 269 270

	IWL_DEBUG_INFO(priv, "BT coex in %s mode\n",
		       priv->bt_full_concurrent ?
		       "full concurrency" : "3-wire");

	/*
	 * LQ & RXON updated cmds must be sent before BT Config cmd
	 * to avoid 3-wire collisions
	 */
271 272 273
	for_each_context(priv, ctx) {
		if (priv->cfg->ops->hcmd->set_rxon_chain)
			priv->cfg->ops->hcmd->set_rxon_chain(priv, ctx);
274
		iwlagn_commit_rxon(priv, ctx);
275
	}
276 277

	priv->cfg->ops->hcmd->send_bt_config(priv);
278 279
out:
	mutex_unlock(&priv->mutex);
280 281
}

282
/**
283
 * iwl_bg_statistics_periodic - Timer callback to queue statistics
284 285 286 287 288 289 290 291
 *
 * This callback is provided in order to send a statistics request.
 *
 * This timer function is continually reset to execute within
 * REG_RECALIB_PERIOD seconds since the last STATISTICS_NOTIFICATION
 * was received.  We need to ensure we receive the statistics in order
 * to update the temperature used for calibrating the TXPOWER.
 */
292
static void iwl_bg_statistics_periodic(unsigned long data)
293 294 295 296 297 298
{
	struct iwl_priv *priv = (struct iwl_priv *)data;

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

299 300 301 302
	/* dont send host command if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
		return;

303
	iwl_send_statistics_request(priv, CMD_ASYNC, false);
304 305
}

306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328

static void iwl_print_cont_event_trace(struct iwl_priv *priv, u32 base,
					u32 start_idx, u32 num_events,
					u32 mode)
{
	u32 i;
	u32 ptr;        /* SRAM byte address of log data */
	u32 ev, time, data; /* event log data */
	unsigned long reg_flags;

	if (mode == 0)
		ptr = base + (4 * sizeof(u32)) + (start_idx * 2 * sizeof(u32));
	else
		ptr = base + (4 * sizeof(u32)) + (start_idx * 3 * sizeof(u32));

	/* Make sure device is powered up for SRAM reads */
	spin_lock_irqsave(&priv->reg_lock, reg_flags);
	if (iwl_grab_nic_access(priv)) {
		spin_unlock_irqrestore(&priv->reg_lock, reg_flags);
		return;
	}

	/* Set starting address; reads will auto-increment */
329
	iwl_write32(priv, HBUS_TARG_MEM_RADDR, ptr);
330 331 332 333 334 335 336
	rmb();

	/*
	 * "time" is actually "data" for mode 0 (no timestamp).
	 * place event id # at far right for easier visual parsing.
	 */
	for (i = 0; i < num_events; i++) {
337 338
		ev = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
		time = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
339 340 341 342
		if (mode == 0) {
			trace_iwlwifi_dev_ucode_cont_event(priv,
							0, time, ev);
		} else {
343
			data = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
344 345 346 347 348 349 350 351 352
			trace_iwlwifi_dev_ucode_cont_event(priv,
						time, data, ev);
		}
	}
	/* Allow device to power down */
	iwl_release_nic_access(priv);
	spin_unlock_irqrestore(&priv->reg_lock, reg_flags);
}

J
Johannes Berg 已提交
353
static void iwl_continuous_event_trace(struct iwl_priv *priv)
354 355 356 357 358 359 360
{
	u32 capacity;   /* event log capacity in # entries */
	u32 base;       /* SRAM byte address of event log header */
	u32 mode;       /* 0 - no timestamp, 1 - timestamp recorded */
	u32 num_wraps;  /* # times uCode wrapped to top of log */
	u32 next_entry; /* index of next entry to be written by uCode */

J
Johannes Berg 已提交
361
	base = priv->device_pointers.error_event_table;
362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427
	if (priv->cfg->ops->lib->is_valid_rtc_data_addr(base)) {
		capacity = iwl_read_targ_mem(priv, base);
		num_wraps = iwl_read_targ_mem(priv, base + (2 * sizeof(u32)));
		mode = iwl_read_targ_mem(priv, base + (1 * sizeof(u32)));
		next_entry = iwl_read_targ_mem(priv, base + (3 * sizeof(u32)));
	} else
		return;

	if (num_wraps == priv->event_log.num_wraps) {
		iwl_print_cont_event_trace(priv,
				       base, priv->event_log.next_entry,
				       next_entry - priv->event_log.next_entry,
				       mode);
		priv->event_log.non_wraps_count++;
	} else {
		if ((num_wraps - priv->event_log.num_wraps) > 1)
			priv->event_log.wraps_more_count++;
		else
			priv->event_log.wraps_once_count++;
		trace_iwlwifi_dev_ucode_wrap_event(priv,
				num_wraps - priv->event_log.num_wraps,
				next_entry, priv->event_log.next_entry);
		if (next_entry < priv->event_log.next_entry) {
			iwl_print_cont_event_trace(priv, base,
			       priv->event_log.next_entry,
			       capacity - priv->event_log.next_entry,
			       mode);

			iwl_print_cont_event_trace(priv, base, 0,
				next_entry, mode);
		} else {
			iwl_print_cont_event_trace(priv, base,
			       next_entry, capacity - next_entry,
			       mode);

			iwl_print_cont_event_trace(priv, base, 0,
				next_entry, mode);
		}
	}
	priv->event_log.num_wraps = num_wraps;
	priv->event_log.next_entry = next_entry;
}

/**
 * iwl_bg_ucode_trace - Timer callback to log ucode event
 *
 * The timer is continually set to execute every
 * UCODE_TRACE_PERIOD milliseconds after the last timer expired
 * this function is to perform continuous uCode event logging operation
 * if enabled
 */
static void iwl_bg_ucode_trace(unsigned long data)
{
	struct iwl_priv *priv = (struct iwl_priv *)data;

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	if (priv->event_log.ucode_trace) {
		iwl_continuous_event_trace(priv);
		/* Reschedule the timer to occur in UCODE_TRACE_PERIOD */
		mod_timer(&priv->ucode_trace,
			 jiffies + msecs_to_jiffies(UCODE_TRACE_PERIOD));
	}
}

428 429 430 431 432 433 434 435 436 437 438 439
static void iwl_bg_tx_flush(struct work_struct *work)
{
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, tx_flush);

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	/* do nothing if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
		return;

440 441
	IWL_DEBUG_INFO(priv, "device request: flush all tx frames\n");
	iwlagn_dev_txfifo_flush(priv, IWL_DROP_ALL);
442 443
}

Z
Zhu Yi 已提交
444
/**
445
 * iwl_rx_handle - Main entry function for receiving responses from uCode
Z
Zhu Yi 已提交
446 447 448 449 450
 *
 * Uses the priv->rx_handlers callback function array to invoke
 * the appropriate handlers, including command responses,
 * frame-received notifications, and other notifications.
 */
451
static void iwl_rx_handle(struct iwl_priv *priv)
Z
Zhu Yi 已提交
452
{
453
	struct iwl_rx_mem_buffer *rxb;
454
	struct iwl_rx_packet *pkt;
455
	struct iwl_rx_queue *rxq = &priv->rxq;
Z
Zhu Yi 已提交
456 457 458
	u32 r, i;
	int reclaim;
	unsigned long flags;
459
	u8 fill_rx = 0;
M
Mohamed Abbas 已提交
460
	u32 count = 8;
461
	int total_empty;
Z
Zhu Yi 已提交
462

463 464
	/* uCode's read index (stored in shared DRAM) indicates the last Rx
	 * buffer that the driver may process (last buffer filled by ucode). */
465
	r = le16_to_cpu(rxq->rb_stts->closed_rb_num) &  0x0FFF;
Z
Zhu Yi 已提交
466 467 468 469
	i = rxq->read;

	/* Rx interrupt, but nothing sent from uCode */
	if (i == r)
470
		IWL_DEBUG_RX(priv, "r = %d, i = %d\n", r, i);
Z
Zhu Yi 已提交
471

472
	/* calculate total frames need to be restock after handling RX */
473
	total_empty = r - rxq->write_actual;
474 475 476 477
	if (total_empty < 0)
		total_empty += RX_QUEUE_SIZE;

	if (total_empty > (RX_QUEUE_SIZE / 2))
478 479
		fill_rx = 1;

Z
Zhu Yi 已提交
480
	while (i != r) {
J
Johannes Berg 已提交
481 482
		int len;

Z
Zhu Yi 已提交
483 484
		rxb = rxq->queue[i];

485
		/* If an RXB doesn't have a Rx queue slot associated with it,
Z
Zhu Yi 已提交
486 487
		 * then a bug has been introduced in the queue refilling
		 * routines -- catch it here */
488 489 490 491
		if (WARN_ON(rxb == NULL)) {
			i = (i + 1) & RX_QUEUE_MASK;
			continue;
		}
Z
Zhu Yi 已提交
492 493 494

		rxq->queue[i] = NULL;

495
		dma_unmap_page(priv->bus.dev, rxb->page_dma,
Z
Zhu Yi 已提交
496
			       PAGE_SIZE << priv->hw_params.rx_page_order,
497
			       DMA_FROM_DEVICE);
Z
Zhu Yi 已提交
498
		pkt = rxb_addr(rxb);
Z
Zhu Yi 已提交
499

J
Johannes Berg 已提交
500 501 502
		len = le32_to_cpu(pkt->len_n_flags) & FH_RSCSR_FRAME_SIZE_MSK;
		len += sizeof(u32); /* account for status word */
		trace_iwlwifi_dev_rx(priv, pkt, len);
J
Johannes Berg 已提交
503

Z
Zhu Yi 已提交
504 505 506 507 508 509 510 511
		/* Reclaim a command buffer only if this packet is a response
		 *   to a (driver-originated) command.
		 * If the packet (e.g. Rx frame) originated from uCode,
		 *   there is no command buffer to reclaim.
		 * Ucode should set SEQ_RX_FRAME bit if ucode-originated,
		 *   but apparently a few don't get set; catch them here. */
		reclaim = !(pkt->hdr.sequence & SEQ_RX_FRAME) &&
			(pkt->hdr.cmd != REPLY_RX_PHY_CMD) &&
512
			(pkt->hdr.cmd != REPLY_RX) &&
D
Daniel Halperin 已提交
513
			(pkt->hdr.cmd != REPLY_RX_MPDU_CMD) &&
514
			(pkt->hdr.cmd != REPLY_COMPRESSED_BA) &&
Z
Zhu Yi 已提交
515 516 517
			(pkt->hdr.cmd != STATISTICS_NOTIFICATION) &&
			(pkt->hdr.cmd != REPLY_TX);

518 519 520 521 522 523 524 525 526 527 528 529 530
		/*
		 * Do the notification wait before RX handlers so
		 * even if the RX handler consumes the RXB we have
		 * access to it in the notification wait entry.
		 */
		if (!list_empty(&priv->_agn.notif_waits)) {
			struct iwl_notification_wait *w;

			spin_lock(&priv->_agn.notif_wait_lock);
			list_for_each_entry(w, &priv->_agn.notif_waits, list) {
				if (w->cmd == pkt->hdr.cmd) {
					w->triggered = true;
					if (w->fn)
531
						w->fn(priv, pkt, w->fn_data);
532 533 534 535 536 537
				}
			}
			spin_unlock(&priv->_agn.notif_wait_lock);

			wake_up_all(&priv->_agn.notif_waitq);
		}
538 539
		if (priv->pre_rx_handler)
			priv->pre_rx_handler(priv, rxb);
540

Z
Zhu Yi 已提交
541 542
		/* Based on type of command response or notification,
		 *   handle those that need handling via function in
543
		 *   rx_handlers table.  See iwl_setup_rx_handlers() */
Z
Zhu Yi 已提交
544
		if (priv->rx_handlers[pkt->hdr.cmd]) {
545
			IWL_DEBUG_RX(priv, "r = %d, i = %d, %s, 0x%02x\n", r,
546
				i, get_cmd_string(pkt->hdr.cmd), pkt->hdr.cmd);
547
			priv->isr_stats.rx_handlers[pkt->hdr.cmd]++;
548
			priv->rx_handlers[pkt->hdr.cmd] (priv, rxb);
Z
Zhu Yi 已提交
549 550
		} else {
			/* No handling needed */
551
			IWL_DEBUG_RX(priv,
Z
Zhu Yi 已提交
552 553 554 555 556
				"r %d i %d No handler needed for %s, 0x%02x\n",
				r, i, get_cmd_string(pkt->hdr.cmd),
				pkt->hdr.cmd);
		}

557 558 559 560 561 562 563
		/*
		 * XXX: After here, we should always check rxb->page
		 * against NULL before touching it or its virtual
		 * memory (pkt). Because some rx_handler might have
		 * already taken or freed the pages.
		 */

Z
Zhu Yi 已提交
564
		if (reclaim) {
Z
Zhu Yi 已提交
565 566
			/* Invoke any callbacks, transfer the buffer to caller,
			 * and fire off the (possibly) blocking iwl_send_cmd()
Z
Zhu Yi 已提交
567
			 * as we reclaim the driver command queue */
568
			if (rxb->page)
569
				iwl_tx_cmd_complete(priv, rxb);
Z
Zhu Yi 已提交
570
			else
571
				IWL_WARN(priv, "Claim null rxb?\n");
Z
Zhu Yi 已提交
572 573
		}

574 575 576 577
		/* Reuse the page if possible. For notification packets and
		 * SKBs that fail to Rx correctly, add them back into the
		 * rx_free list for reuse later. */
		spin_lock_irqsave(&rxq->lock, flags);
Z
Zhu Yi 已提交
578
		if (rxb->page != NULL) {
579
			rxb->page_dma = dma_map_page(priv->bus.dev, rxb->page,
580
				0, PAGE_SIZE << priv->hw_params.rx_page_order,
581
				DMA_FROM_DEVICE);
582 583 584 585
			list_add_tail(&rxb->list, &rxq->rx_free);
			rxq->free_count++;
		} else
			list_add_tail(&rxb->list, &rxq->rx_used);
Z
Zhu Yi 已提交
586 587

		spin_unlock_irqrestore(&rxq->lock, flags);
588

Z
Zhu Yi 已提交
589
		i = (i + 1) & RX_QUEUE_MASK;
590 591 592 593 594
		/* If there are a lot of unused frames,
		 * restock the Rx queue so ucode wont assert. */
		if (fill_rx) {
			count++;
			if (count >= 8) {
595
				rxq->read = i;
596
				iwlagn_rx_replenish_now(priv);
597 598 599
				count = 0;
			}
		}
Z
Zhu Yi 已提交
600 601 602
	}

	/* Backtrack one entry */
603
	rxq->read = i;
604
	if (fill_rx)
605
		iwlagn_rx_replenish_now(priv);
606
	else
607
		iwlagn_rx_queue_restock(priv);
608 609
}

M
Mohamed Abbas 已提交
610 611 612 613 614 615
/* tasklet for iwlagn interrupt */
static void iwl_irq_tasklet(struct iwl_priv *priv)
{
	u32 inta = 0;
	u32 handled = 0;
	unsigned long flags;
616
	u32 i;
M
Mohamed Abbas 已提交
617 618 619 620 621 622 623 624 625
#ifdef CONFIG_IWLWIFI_DEBUG
	u32 inta_mask;
#endif

	spin_lock_irqsave(&priv->lock, flags);

	/* Ack/clear/reset pending uCode interrupts.
	 * Note:  Some bits in CSR_INT are "OR" of bits in CSR_FH_INT_STATUS,
	 */
626 627 628 629 630 631 632 633
	/* There is a hardware bug in the interrupt mask function that some
	 * interrupts (i.e. CSR_INT_BIT_SCD) can still be generated even if
	 * they are disabled in the CSR_INT_MASK register. Furthermore the
	 * ICT interrupt handling mechanism has another bug that might cause
	 * these unmasked interrupts fail to be detected. We workaround the
	 * hardware bugs here by ACKing all the possible interrupts so that
	 * interrupt coalescing can still be achieved.
	 */
634
	iwl_write32(priv, CSR_INT, priv->_agn.inta | ~priv->inta_mask);
M
Mohamed Abbas 已提交
635

636
	inta = priv->_agn.inta;
M
Mohamed Abbas 已提交
637 638

#ifdef CONFIG_IWLWIFI_DEBUG
639
	if (iwl_get_debug_level(priv) & IWL_DL_ISR) {
M
Mohamed Abbas 已提交
640 641 642 643 644 645
		/* just for debug */
		inta_mask = iwl_read32(priv, CSR_INT_MASK);
		IWL_DEBUG_ISR(priv, "inta 0x%08x, enabled 0x%08x\n ",
				inta, inta_mask);
	}
#endif
Z
Zhu Yi 已提交
646 647 648

	spin_unlock_irqrestore(&priv->lock, flags);

649 650
	/* saved interrupt in inta variable now we can reset priv->_agn.inta */
	priv->_agn.inta = 0;
M
Mohamed Abbas 已提交
651 652 653

	/* Now service all interrupt bits discovered above. */
	if (inta & CSR_INT_BIT_HW_ERR) {
654
		IWL_ERR(priv, "Hardware error detected.  Restarting.\n");
M
Mohamed Abbas 已提交
655 656 657 658 659 660 661 662 663 664 665 666 667

		/* Tell the device to stop sending interrupts */
		iwl_disable_interrupts(priv);

		priv->isr_stats.hw++;
		iwl_irq_handle_error(priv);

		handled |= CSR_INT_BIT_HW_ERR;

		return;
	}

#ifdef CONFIG_IWLWIFI_DEBUG
668
	if (iwl_get_debug_level(priv) & (IWL_DL_ISR)) {
M
Mohamed Abbas 已提交
669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692
		/* NIC fires this, but we don't use it, redundant with WAKEUP */
		if (inta & CSR_INT_BIT_SCD) {
			IWL_DEBUG_ISR(priv, "Scheduler finished to transmit "
				      "the frame/frames.\n");
			priv->isr_stats.sch++;
		}

		/* Alive notification via Rx interrupt will do the real work */
		if (inta & CSR_INT_BIT_ALIVE) {
			IWL_DEBUG_ISR(priv, "Alive interrupt\n");
			priv->isr_stats.alive++;
		}
	}
#endif
	/* Safely ignore these bits for debug checks below */
	inta &= ~(CSR_INT_BIT_SCD | CSR_INT_BIT_ALIVE);

	/* HW RF KILL switch toggled */
	if (inta & CSR_INT_BIT_RF_KILL) {
		int hw_rf_kill = 0;
		if (!(iwl_read32(priv, CSR_GP_CNTRL) &
				CSR_GP_CNTRL_REG_FLAG_HW_RF_KILL_SW))
			hw_rf_kill = 1;

693
		IWL_WARN(priv, "RF_KILL bit toggled to %s.\n",
M
Mohamed Abbas 已提交
694 695 696 697 698 699 700 701 702 703 704 705 706 707
				hw_rf_kill ? "disable radio" : "enable radio");

		priv->isr_stats.rfkill++;

		/* driver only loads ucode once setting the interface up.
		 * the driver allows loading the ucode even if the radio
		 * is killed. Hence update the killswitch state here. The
		 * rfkill handler will care about restarting if needed.
		 */
		if (!test_bit(STATUS_ALIVE, &priv->status)) {
			if (hw_rf_kill)
				set_bit(STATUS_RF_KILL_HW, &priv->status);
			else
				clear_bit(STATUS_RF_KILL_HW, &priv->status);
J
Johannes Berg 已提交
708
			wiphy_rfkill_set_hw_state(priv->hw->wiphy, hw_rf_kill);
M
Mohamed Abbas 已提交
709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733
		}

		handled |= CSR_INT_BIT_RF_KILL;
	}

	/* Chip got too hot and stopped itself */
	if (inta & CSR_INT_BIT_CT_KILL) {
		IWL_ERR(priv, "Microcode CT kill error detected.\n");
		priv->isr_stats.ctkill++;
		handled |= CSR_INT_BIT_CT_KILL;
	}

	/* Error detected by uCode */
	if (inta & CSR_INT_BIT_SW_ERR) {
		IWL_ERR(priv, "Microcode SW error detected. "
			" Restarting 0x%X.\n", inta);
		priv->isr_stats.sw++;
		iwl_irq_handle_error(priv);
		handled |= CSR_INT_BIT_SW_ERR;
	}

	/* uCode wakes up after power-down sleep */
	if (inta & CSR_INT_BIT_WAKEUP) {
		IWL_DEBUG_ISR(priv, "Wakeup interrupt\n");
		iwl_rx_queue_update_write_ptr(priv, &priv->rxq);
734 735
		for (i = 0; i < priv->hw_params.max_txq_num; i++)
			iwl_txq_update_write_ptr(priv, &priv->txq[i]);
M
Mohamed Abbas 已提交
736 737 738 739 740 741 742 743 744

		priv->isr_stats.wakeup++;

		handled |= CSR_INT_BIT_WAKEUP;
	}

	/* All uCode command responses, including Tx command responses,
	 * Rx "responses" (frame-received notification), and other
	 * notifications from uCode come through here*/
745 746
	if (inta & (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX |
			CSR_INT_BIT_RX_PERIODIC)) {
M
Mohamed Abbas 已提交
747
		IWL_DEBUG_ISR(priv, "Rx interrupt\n");
748 749 750
		if (inta & (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX)) {
			handled |= (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX);
			iwl_write32(priv, CSR_FH_INT_STATUS,
751
					CSR_FH_INT_RX_MASK);
752 753 754 755 756 757 758 759 760 761 762 763
		}
		if (inta & CSR_INT_BIT_RX_PERIODIC) {
			handled |= CSR_INT_BIT_RX_PERIODIC;
			iwl_write32(priv, CSR_INT, CSR_INT_BIT_RX_PERIODIC);
		}
		/* Sending RX interrupt require many steps to be done in the
		 * the device:
		 * 1- write interrupt to current index in ICT table.
		 * 2- dma RX frame.
		 * 3- update RX shared data to indicate last write index.
		 * 4- send interrupt.
		 * This could lead to RX race, driver could receive RX interrupt
764 765
		 * but the shared data changes does not reflect this;
		 * periodic interrupt will detect any dangling Rx activity.
766
		 */
767 768 769

		/* Disable periodic interrupt; we use it as just a one-shot. */
		iwl_write8(priv, CSR_INT_PERIODIC_REG,
770
			    CSR_INT_PERIODIC_DIS);
M
Mohamed Abbas 已提交
771
		iwl_rx_handle(priv);
772 773 774 775 776 777 778 779

		/*
		 * Enable periodic interrupt in 8 msec only if we received
		 * real RX interrupt (instead of just periodic int), to catch
		 * any dangling Rx interrupt.  If it was just the periodic
		 * interrupt, there was no dangling Rx activity, and no need
		 * to extend the periodic interrupt; one-shot is enough.
		 */
780
		if (inta & (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX))
781
			iwl_write8(priv, CSR_INT_PERIODIC_REG,
782 783
				    CSR_INT_PERIODIC_ENA);

M
Mohamed Abbas 已提交
784 785 786
		priv->isr_stats.rx++;
	}

B
Ben Cahill 已提交
787
	/* This "Tx" DMA channel is used only for loading uCode */
M
Mohamed Abbas 已提交
788
	if (inta & CSR_INT_BIT_FH_TX) {
789
		iwl_write32(priv, CSR_FH_INT_STATUS, CSR_FH_INT_TX_MASK);
B
Ben Cahill 已提交
790
		IWL_DEBUG_ISR(priv, "uCode load interrupt\n");
M
Mohamed Abbas 已提交
791 792
		priv->isr_stats.tx++;
		handled |= CSR_INT_BIT_FH_TX;
B
Ben Cahill 已提交
793
		/* Wake up uCode load routine, now that load is complete */
M
Mohamed Abbas 已提交
794 795 796 797 798 799 800 801 802
		priv->ucode_write_complete = 1;
		wake_up_interruptible(&priv->wait_command_queue);
	}

	if (inta & ~handled) {
		IWL_ERR(priv, "Unhandled INTA bits 0x%08x\n", inta & ~handled);
		priv->isr_stats.unhandled++;
	}

803
	if (inta & ~(priv->inta_mask)) {
M
Mohamed Abbas 已提交
804
		IWL_WARN(priv, "Disabled INTA bits 0x%08x were pending\n",
805
			 inta & ~priv->inta_mask);
M
Mohamed Abbas 已提交
806 807 808
	}

	/* Re-enable all interrupts */
809
	/* only Re-enable if disabled by irq */
M
Mohamed Abbas 已提交
810 811
	if (test_bit(STATUS_INT_ENABLED, &priv->status))
		iwl_enable_interrupts(priv);
812 813 814
	/* Re-enable RF_KILL if it occurred */
	else if (handled & CSR_INT_BIT_RF_KILL)
		iwl_enable_rfkill_int(priv);
M
Mohamed Abbas 已提交
815 816
}

817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930
/*****************************************************************************
 *
 * sysfs attributes
 *
 *****************************************************************************/

#ifdef CONFIG_IWLWIFI_DEBUG

/*
 * The following adds a new attribute to the sysfs representation
 * of this device driver (i.e. a new file in /sys/class/net/wlan0/device/)
 * used for controlling the debug level.
 *
 * See the level definitions in iwl for details.
 *
 * The debug_level being managed using sysfs below is a per device debug
 * level that is used instead of the global debug level if it (the per
 * device debug level) is set.
 */
static ssize_t show_debug_level(struct device *d,
				struct device_attribute *attr, char *buf)
{
	struct iwl_priv *priv = dev_get_drvdata(d);
	return sprintf(buf, "0x%08X\n", iwl_get_debug_level(priv));
}
static ssize_t store_debug_level(struct device *d,
				struct device_attribute *attr,
				 const char *buf, size_t count)
{
	struct iwl_priv *priv = dev_get_drvdata(d);
	unsigned long val;
	int ret;

	ret = strict_strtoul(buf, 0, &val);
	if (ret)
		IWL_ERR(priv, "%s is not in hex or decimal form.\n", buf);
	else {
		priv->debug_level = val;
		if (iwl_alloc_traffic_mem(priv))
			IWL_ERR(priv,
				"Not enough memory to generate traffic log\n");
	}
	return strnlen(buf, count);
}

static DEVICE_ATTR(debug_level, S_IWUSR | S_IRUGO,
			show_debug_level, store_debug_level);


#endif /* CONFIG_IWLWIFI_DEBUG */


static ssize_t show_temperature(struct device *d,
				struct device_attribute *attr, char *buf)
{
	struct iwl_priv *priv = dev_get_drvdata(d);

	if (!iwl_is_alive(priv))
		return -EAGAIN;

	return sprintf(buf, "%d\n", priv->temperature);
}

static DEVICE_ATTR(temperature, S_IRUGO, show_temperature, NULL);

static ssize_t show_tx_power(struct device *d,
			     struct device_attribute *attr, char *buf)
{
	struct iwl_priv *priv = dev_get_drvdata(d);

	if (!iwl_is_ready_rf(priv))
		return sprintf(buf, "off\n");
	else
		return sprintf(buf, "%d\n", priv->tx_power_user_lmt);
}

static ssize_t store_tx_power(struct device *d,
			      struct device_attribute *attr,
			      const char *buf, size_t count)
{
	struct iwl_priv *priv = dev_get_drvdata(d);
	unsigned long val;
	int ret;

	ret = strict_strtoul(buf, 10, &val);
	if (ret)
		IWL_INFO(priv, "%s is not in decimal form.\n", buf);
	else {
		ret = iwl_set_tx_power(priv, val, false);
		if (ret)
			IWL_ERR(priv, "failed setting tx power (0x%d).\n",
				ret);
		else
			ret = count;
	}
	return ret;
}

static DEVICE_ATTR(tx_power, S_IWUSR | S_IRUGO, show_tx_power, store_tx_power);

static struct attribute *iwl_sysfs_entries[] = {
	&dev_attr_temperature.attr,
	&dev_attr_tx_power.attr,
#ifdef CONFIG_IWLWIFI_DEBUG
	&dev_attr_debug_level.attr,
#endif
	NULL
};

static struct attribute_group iwl_attribute_group = {
	.name = NULL,		/* put in device directory */
	.attrs = iwl_sysfs_entries,
};

Z
Zhu Yi 已提交
931 932 933 934 935 936
/******************************************************************************
 *
 * uCode download functions
 *
 ******************************************************************************/

937
static void iwl_free_fw_desc(struct iwl_priv *priv, struct fw_desc *desc)
938 939
{
	if (desc->v_addr)
940
		dma_free_coherent(priv->bus.dev, desc->len,
941 942 943 944 945
				  desc->v_addr, desc->p_addr);
	desc->v_addr = NULL;
	desc->len = 0;
}

946
static void iwl_free_fw_img(struct iwl_priv *priv, struct fw_img *img)
947
{
948 949
	iwl_free_fw_desc(priv, &img->code);
	iwl_free_fw_desc(priv, &img->data);
950 951
}

952 953 954 955 956 957 958
static void iwl_dealloc_ucode(struct iwl_priv *priv)
{
	iwl_free_fw_img(priv, &priv->ucode_rt);
	iwl_free_fw_img(priv, &priv->ucode_init);
}

static int iwl_alloc_fw_desc(struct iwl_priv *priv, struct fw_desc *desc,
959 960 961 962 963 964 965
			     const void *data, size_t len)
{
	if (!len) {
		desc->v_addr = NULL;
		return -EINVAL;
	}

966
	desc->v_addr = dma_alloc_coherent(priv->bus.dev, len,
967 968 969
					  &desc->p_addr, GFP_KERNEL);
	if (!desc->v_addr)
		return -ENOMEM;
970

971 972 973 974 975
	desc->len = len;
	memcpy(desc->v_addr, data, len);
	return 0;
}

976 977
struct iwlagn_ucode_capabilities {
	u32 max_probe_length;
978
	u32 standard_phy_calibration_size;
J
Johannes Berg 已提交
979
	u32 flags;
980
};
981

982
static void iwl_ucode_callback(const struct firmware *ucode_raw, void *context);
983 984
static int iwl_mac_setup_register(struct iwl_priv *priv,
				  struct iwlagn_ucode_capabilities *capa);
985

986 987 988
#define UCODE_EXPERIMENTAL_INDEX	100
#define UCODE_EXPERIMENTAL_TAG		"exp"

989 990 991
static int __must_check iwl_request_firmware(struct iwl_priv *priv, bool first)
{
	const char *name_pre = priv->cfg->fw_name_pre;
992
	char tag[8];
993

994 995 996 997 998 999
	if (first) {
#ifdef CONFIG_IWLWIFI_DEBUG_EXPERIMENTAL_UCODE
		priv->fw_index = UCODE_EXPERIMENTAL_INDEX;
		strcpy(tag, UCODE_EXPERIMENTAL_TAG);
	} else if (priv->fw_index == UCODE_EXPERIMENTAL_INDEX) {
#endif
1000
		priv->fw_index = priv->cfg->ucode_api_max;
1001 1002
		sprintf(tag, "%d", priv->fw_index);
	} else {
1003
		priv->fw_index--;
1004 1005
		sprintf(tag, "%d", priv->fw_index);
	}
1006 1007 1008 1009 1010 1011

	if (priv->fw_index < priv->cfg->ucode_api_min) {
		IWL_ERR(priv, "no suitable firmware found!\n");
		return -ENOENT;
	}

1012
	sprintf(priv->firmware_name, "%s%s%s", name_pre, tag, ".ucode");
1013

1014 1015 1016
	IWL_DEBUG_INFO(priv, "attempting to load firmware %s'%s'\n",
		       (priv->fw_index == UCODE_EXPERIMENTAL_INDEX)
				? "EXPERIMENTAL " : "",
1017 1018 1019
		       priv->firmware_name);

	return request_firmware_nowait(THIS_MODULE, 1, priv->firmware_name,
1020 1021
				       priv->bus.dev,
				       GFP_KERNEL, priv, iwl_ucode_callback);
1022 1023
}

1024
struct iwlagn_firmware_pieces {
J
Johannes Berg 已提交
1025 1026
	const void *inst, *data, *init, *init_data;
	size_t inst_size, data_size, init_size, init_data_size;
1027 1028

	u32 build;
1029 1030 1031

	u32 init_evtlog_ptr, init_evtlog_size, init_errlog_ptr;
	u32 inst_evtlog_ptr, inst_evtlog_size, inst_errlog_ptr;
1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046
};

static int iwlagn_load_legacy_firmware(struct iwl_priv *priv,
				       const struct firmware *ucode_raw,
				       struct iwlagn_firmware_pieces *pieces)
{
	struct iwl_ucode_header *ucode = (void *)ucode_raw->data;
	u32 api_ver, hdr_size;
	const u8 *src;

	priv->ucode_ver = le32_to_cpu(ucode->ver);
	api_ver = IWL_UCODE_API(priv->ucode_ver);

	switch (api_ver) {
	default:
1047 1048 1049 1050
		hdr_size = 28;
		if (ucode_raw->size < hdr_size) {
			IWL_ERR(priv, "File size too small!\n");
			return -EINVAL;
1051
		}
1052 1053 1054 1055 1056 1057 1058
		pieces->build = le32_to_cpu(ucode->u.v2.build);
		pieces->inst_size = le32_to_cpu(ucode->u.v2.inst_size);
		pieces->data_size = le32_to_cpu(ucode->u.v2.data_size);
		pieces->init_size = le32_to_cpu(ucode->u.v2.init_size);
		pieces->init_data_size = le32_to_cpu(ucode->u.v2.init_data_size);
		src = ucode->u.v2.data;
		break;
1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078
	case 0:
	case 1:
	case 2:
		hdr_size = 24;
		if (ucode_raw->size < hdr_size) {
			IWL_ERR(priv, "File size too small!\n");
			return -EINVAL;
		}
		pieces->build = 0;
		pieces->inst_size = le32_to_cpu(ucode->u.v1.inst_size);
		pieces->data_size = le32_to_cpu(ucode->u.v1.data_size);
		pieces->init_size = le32_to_cpu(ucode->u.v1.init_size);
		pieces->init_data_size = le32_to_cpu(ucode->u.v1.init_data_size);
		src = ucode->u.v1.data;
		break;
	}

	/* Verify size of file vs. image size info in file's header */
	if (ucode_raw->size != hdr_size + pieces->inst_size +
				pieces->data_size + pieces->init_size +
J
Johannes Berg 已提交
1079
				pieces->init_data_size) {
1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098

		IWL_ERR(priv,
			"uCode file size %d does not match expected size\n",
			(int)ucode_raw->size);
		return -EINVAL;
	}

	pieces->inst = src;
	src += pieces->inst_size;
	pieces->data = src;
	src += pieces->data_size;
	pieces->init = src;
	src += pieces->init_size;
	pieces->init_data = src;
	src += pieces->init_data_size;

	return 0;
}

1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111
static int iwlagn_wanted_ucode_alternative = 1;

static int iwlagn_load_firmware(struct iwl_priv *priv,
				const struct firmware *ucode_raw,
				struct iwlagn_firmware_pieces *pieces,
				struct iwlagn_ucode_capabilities *capa)
{
	struct iwl_tlv_ucode_header *ucode = (void *)ucode_raw->data;
	struct iwl_ucode_tlv *tlv;
	size_t len = ucode_raw->size;
	const u8 *data;
	int wanted_alternative = iwlagn_wanted_ucode_alternative, tmp;
	u64 alternatives;
1112 1113 1114
	u32 tlv_len;
	enum iwl_ucode_tlv_type tlv_type;
	const u8 *tlv_data;
1115

1116 1117
	if (len < sizeof(*ucode)) {
		IWL_ERR(priv, "uCode has invalid length: %zd\n", len);
1118
		return -EINVAL;
1119
	}
1120

1121 1122 1123
	if (ucode->magic != cpu_to_le32(IWL_TLV_UCODE_MAGIC)) {
		IWL_ERR(priv, "invalid uCode magic: 0X%x\n",
			le32_to_cpu(ucode->magic));
1124
		return -EINVAL;
1125
	}
1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149

	/*
	 * Check which alternatives are present, and "downgrade"
	 * when the chosen alternative is not present, warning
	 * the user when that happens. Some files may not have
	 * any alternatives, so don't warn in that case.
	 */
	alternatives = le64_to_cpu(ucode->alternatives);
	tmp = wanted_alternative;
	if (wanted_alternative > 63)
		wanted_alternative = 63;
	while (wanted_alternative && !(alternatives & BIT(wanted_alternative)))
		wanted_alternative--;
	if (wanted_alternative && wanted_alternative != tmp)
		IWL_WARN(priv,
			 "uCode alternative %d not available, choosing %d\n",
			 tmp, wanted_alternative);

	priv->ucode_ver = le32_to_cpu(ucode->ver);
	pieces->build = le32_to_cpu(ucode->build);
	data = ucode->data;

	len -= sizeof(*ucode);

1150
	while (len >= sizeof(*tlv)) {
1151 1152 1153 1154 1155 1156 1157 1158 1159 1160
		u16 tlv_alt;

		len -= sizeof(*tlv);
		tlv = (void *)data;

		tlv_len = le32_to_cpu(tlv->length);
		tlv_type = le16_to_cpu(tlv->type);
		tlv_alt = le16_to_cpu(tlv->alternative);
		tlv_data = tlv->data;

1161 1162 1163
		if (len < tlv_len) {
			IWL_ERR(priv, "invalid TLV len: %zd/%u\n",
				len, tlv_len);
1164
			return -EINVAL;
1165
		}
1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194
		len -= ALIGN(tlv_len, 4);
		data += sizeof(*tlv) + ALIGN(tlv_len, 4);

		/*
		 * Alternative 0 is always valid.
		 *
		 * Skip alternative TLVs that are not selected.
		 */
		if (tlv_alt != 0 && tlv_alt != wanted_alternative)
			continue;

		switch (tlv_type) {
		case IWL_UCODE_TLV_INST:
			pieces->inst = tlv_data;
			pieces->inst_size = tlv_len;
			break;
		case IWL_UCODE_TLV_DATA:
			pieces->data = tlv_data;
			pieces->data_size = tlv_len;
			break;
		case IWL_UCODE_TLV_INIT:
			pieces->init = tlv_data;
			pieces->init_size = tlv_len;
			break;
		case IWL_UCODE_TLV_INIT_DATA:
			pieces->init_data = tlv_data;
			pieces->init_data_size = tlv_len;
			break;
		case IWL_UCODE_TLV_BOOT:
J
Johannes Berg 已提交
1195
			IWL_ERR(priv, "Found unexpected BOOT ucode\n");
1196 1197
			break;
		case IWL_UCODE_TLV_PROBE_MAX_LEN:
1198 1199 1200
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			capa->max_probe_length =
1201
					le32_to_cpup((__le32 *)tlv_data);
1202
			break;
J
Johannes Berg 已提交
1203 1204 1205
		case IWL_UCODE_TLV_PAN:
			if (tlv_len)
				goto invalid_tlv_len;
J
Johannes Berg 已提交
1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222
			capa->flags |= IWL_UCODE_TLV_FLAGS_PAN;
			break;
		case IWL_UCODE_TLV_FLAGS:
			/* must be at least one u32 */
			if (tlv_len < sizeof(u32))
				goto invalid_tlv_len;
			/* and a proper number of u32s */
			if (tlv_len % sizeof(u32))
				goto invalid_tlv_len;
			/*
			 * This driver only reads the first u32 as
			 * right now no more features are defined,
			 * if that changes then either the driver
			 * will not work with the new firmware, or
			 * it'll not take advantage of new features.
			 */
			capa->flags = le32_to_cpup((__le32 *)tlv_data);
J
Johannes Berg 已提交
1223
			break;
1224
		case IWL_UCODE_TLV_INIT_EVTLOG_PTR:
1225 1226 1227
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->init_evtlog_ptr =
1228
					le32_to_cpup((__le32 *)tlv_data);
1229 1230
			break;
		case IWL_UCODE_TLV_INIT_EVTLOG_SIZE:
1231 1232 1233
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->init_evtlog_size =
1234
					le32_to_cpup((__le32 *)tlv_data);
1235 1236
			break;
		case IWL_UCODE_TLV_INIT_ERRLOG_PTR:
1237 1238 1239
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->init_errlog_ptr =
1240
					le32_to_cpup((__le32 *)tlv_data);
1241 1242
			break;
		case IWL_UCODE_TLV_RUNT_EVTLOG_PTR:
1243 1244 1245
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->inst_evtlog_ptr =
1246
					le32_to_cpup((__le32 *)tlv_data);
1247 1248
			break;
		case IWL_UCODE_TLV_RUNT_EVTLOG_SIZE:
1249 1250 1251
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->inst_evtlog_size =
1252
					le32_to_cpup((__le32 *)tlv_data);
1253 1254
			break;
		case IWL_UCODE_TLV_RUNT_ERRLOG_PTR:
1255 1256 1257
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->inst_errlog_ptr =
1258
					le32_to_cpup((__le32 *)tlv_data);
1259
			break;
1260 1261
		case IWL_UCODE_TLV_ENHANCE_SENS_TBL:
			if (tlv_len)
1262 1263
				goto invalid_tlv_len;
			priv->enhance_sensitivity_table = true;
1264
			break;
1265
		case IWL_UCODE_TLV_PHY_CALIBRATION_SIZE:
1266 1267 1268
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			capa->standard_phy_calibration_size =
1269 1270
					le32_to_cpup((__le32 *)tlv_data);
			break;
1271
		default:
1272
			IWL_DEBUG_INFO(priv, "unknown TLV: %d\n", tlv_type);
1273 1274 1275 1276
			break;
		}
	}

1277 1278 1279
	if (len) {
		IWL_ERR(priv, "invalid TLV after parsing: %zd\n", len);
		iwl_print_hex_dump(priv, IWL_DL_FW, (u8 *)data, len);
1280
		return -EINVAL;
1281
	}
1282

1283 1284 1285 1286 1287 1288 1289
	return 0;

 invalid_tlv_len:
	IWL_ERR(priv, "TLV %d has invalid size: %u\n", tlv_type, tlv_len);
	iwl_print_hex_dump(priv, IWL_DL_FW, tlv_data, tlv_len);

	return -EINVAL;
1290 1291
}

Z
Zhu Yi 已提交
1292
/**
1293
 * iwl_ucode_callback - callback when firmware was loaded
Z
Zhu Yi 已提交
1294
 *
1295 1296
 * If loaded successfully, copies the firmware into buffers
 * for the card to fetch (via DMA).
Z
Zhu Yi 已提交
1297
 */
1298
static void iwl_ucode_callback(const struct firmware *ucode_raw, void *context)
Z
Zhu Yi 已提交
1299
{
1300
	struct iwl_priv *priv = context;
1301
	struct iwl_ucode_header *ucode;
1302 1303
	int err;
	struct iwlagn_firmware_pieces pieces;
1304 1305
	const unsigned int api_max = priv->cfg->ucode_api_max;
	const unsigned int api_min = priv->cfg->ucode_api_min;
1306
	u32 api_ver;
1307
	char buildstr[25];
1308
	u32 build;
1309 1310
	struct iwlagn_ucode_capabilities ucode_capa = {
		.max_probe_length = 200,
1311
		.standard_phy_calibration_size =
1312
			IWL_DEFAULT_STANDARD_PHY_CALIBRATE_TBL_SIZE,
1313
	};
1314 1315

	memset(&pieces, 0, sizeof(pieces));
Z
Zhu Yi 已提交
1316

1317
	if (!ucode_raw) {
1318 1319 1320 1321
		if (priv->fw_index <= priv->cfg->ucode_api_max)
			IWL_ERR(priv,
				"request for firmware file '%s' failed.\n",
				priv->firmware_name);
1322
		goto try_again;
Z
Zhu Yi 已提交
1323 1324
	}

1325 1326
	IWL_DEBUG_INFO(priv, "Loaded firmware file '%s' (%zd bytes).\n",
		       priv->firmware_name, ucode_raw->size);
Z
Zhu Yi 已提交
1327

1328 1329
	/* Make sure that we got at least the API version number */
	if (ucode_raw->size < 4) {
1330
		IWL_ERR(priv, "File size way too small!\n");
1331
		goto try_again;
Z
Zhu Yi 已提交
1332 1333 1334
	}

	/* Data from ucode file:  header followed by uCode images */
1335
	ucode = (struct iwl_ucode_header *)ucode_raw->data;
Z
Zhu Yi 已提交
1336

1337 1338 1339
	if (ucode->ver)
		err = iwlagn_load_legacy_firmware(priv, ucode_raw, &pieces);
	else
1340 1341
		err = iwlagn_load_firmware(priv, ucode_raw, &pieces,
					   &ucode_capa);
1342

1343 1344
	if (err)
		goto try_again;
Z
Zhu Yi 已提交
1345

1346
	api_ver = IWL_UCODE_API(priv->ucode_ver);
1347
	build = pieces.build;
1348

1349 1350 1351 1352 1353
	/*
	 * api_ver should match the api version forming part of the
	 * firmware filename ... but we don't check for that and only rely
	 * on the API version read from firmware header from here on forward
	 */
1354 1355 1356 1357 1358 1359 1360 1361 1362
	/* no api version check required for experimental uCode */
	if (priv->fw_index != UCODE_EXPERIMENTAL_INDEX) {
		if (api_ver < api_min || api_ver > api_max) {
			IWL_ERR(priv,
				"Driver unable to support your firmware API. "
				"Driver supports v%u, firmware is v%u.\n",
				api_max, api_ver);
			goto try_again;
		}
1363

1364 1365 1366 1367 1368 1369 1370
		if (api_ver != api_max)
			IWL_ERR(priv,
				"Firmware has old API version. Expected v%u, "
				"got v%u. New firmware can be obtained "
				"from http://www.intellinuxwireless.org.\n",
				api_max, api_ver);
	}
1371

1372
	if (build)
1373 1374 1375
		sprintf(buildstr, " build %u%s", build,
		       (priv->fw_index == UCODE_EXPERIMENTAL_INDEX)
				? " (EXP)" : "");
1376 1377 1378 1379 1380 1381 1382 1383 1384
	else
		buildstr[0] = '\0';

	IWL_INFO(priv, "loaded firmware version %u.%u.%u.%u%s\n",
		 IWL_UCODE_MAJOR(priv->ucode_ver),
		 IWL_UCODE_MINOR(priv->ucode_ver),
		 IWL_UCODE_API(priv->ucode_ver),
		 IWL_UCODE_SERIAL(priv->ucode_ver),
		 buildstr);
1385

1386 1387
	snprintf(priv->hw->wiphy->fw_version,
		 sizeof(priv->hw->wiphy->fw_version),
1388
		 "%u.%u.%u.%u%s",
1389 1390 1391
		 IWL_UCODE_MAJOR(priv->ucode_ver),
		 IWL_UCODE_MINOR(priv->ucode_ver),
		 IWL_UCODE_API(priv->ucode_ver),
1392 1393
		 IWL_UCODE_SERIAL(priv->ucode_ver),
		 buildstr);
Z
Zhu Yi 已提交
1394

1395 1396 1397 1398 1399 1400
	/*
	 * For any of the failures below (before allocating pci memory)
	 * we will try to load a version with a smaller API -- maybe the
	 * user just got a corrupted version of the latest API.
	 */

1401 1402 1403 1404 1405 1406 1407 1408 1409 1410
	IWL_DEBUG_INFO(priv, "f/w package hdr ucode version raw = 0x%x\n",
		       priv->ucode_ver);
	IWL_DEBUG_INFO(priv, "f/w package hdr runtime inst size = %Zd\n",
		       pieces.inst_size);
	IWL_DEBUG_INFO(priv, "f/w package hdr runtime data size = %Zd\n",
		       pieces.data_size);
	IWL_DEBUG_INFO(priv, "f/w package hdr init inst size = %Zd\n",
		       pieces.init_size);
	IWL_DEBUG_INFO(priv, "f/w package hdr init data size = %Zd\n",
		       pieces.init_data_size);
Z
Zhu Yi 已提交
1411 1412

	/* Verify that uCode images will fit in card's SRAM */
1413 1414 1415
	if (pieces.inst_size > priv->hw_params.max_inst_size) {
		IWL_ERR(priv, "uCode instr len %Zd too large to fit in\n",
			pieces.inst_size);
1416
		goto try_again;
Z
Zhu Yi 已提交
1417 1418
	}

1419 1420 1421
	if (pieces.data_size > priv->hw_params.max_data_size) {
		IWL_ERR(priv, "uCode data len %Zd too large to fit in\n",
			pieces.data_size);
1422
		goto try_again;
Z
Zhu Yi 已提交
1423
	}
1424 1425 1426 1427

	if (pieces.init_size > priv->hw_params.max_inst_size) {
		IWL_ERR(priv, "uCode init instr len %Zd too large to fit in\n",
			pieces.init_size);
1428
		goto try_again;
Z
Zhu Yi 已提交
1429
	}
1430 1431 1432 1433

	if (pieces.init_data_size > priv->hw_params.max_data_size) {
		IWL_ERR(priv, "uCode init data len %Zd too large to fit in\n",
			pieces.init_data_size);
1434
		goto try_again;
Z
Zhu Yi 已提交
1435
	}
1436

Z
Zhu Yi 已提交
1437 1438 1439 1440 1441
	/* Allocate ucode buffers for card's bus-master loading ... */

	/* Runtime instructions and 2 copies of data:
	 * 1) unmodified from disk
	 * 2) backup cache for save/restore during power-downs */
1442
	if (iwl_alloc_fw_desc(priv, &priv->ucode_rt.code,
1443 1444
			      pieces.inst, pieces.inst_size))
		goto err_pci_alloc;
1445
	if (iwl_alloc_fw_desc(priv, &priv->ucode_rt.data,
1446
			      pieces.data, pieces.data_size))
1447 1448
		goto err_pci_alloc;

Z
Zhu Yi 已提交
1449
	/* Initialization instructions and data */
1450
	if (pieces.init_size && pieces.init_data_size) {
1451
		if (iwl_alloc_fw_desc(priv, &priv->ucode_init.code,
1452 1453
				      pieces.init, pieces.init_size))
			goto err_pci_alloc;
1454
		if (iwl_alloc_fw_desc(priv, &priv->ucode_init.data,
1455
				      pieces.init_data, pieces.init_data_size))
1456 1457
			goto err_pci_alloc;
	}
Z
Zhu Yi 已提交
1458

1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469
	/* Now that we can no longer fail, copy information */

	/*
	 * The (size - 16) / 12 formula is based on the information recorded
	 * for each event, which is of mode 1 (including timestamp) for all
	 * new microcodes that include this information.
	 */
	priv->_agn.init_evtlog_ptr = pieces.init_evtlog_ptr;
	if (pieces.init_evtlog_size)
		priv->_agn.init_evtlog_size = (pieces.init_evtlog_size - 16)/12;
	else
1470 1471
		priv->_agn.init_evtlog_size =
			priv->cfg->base_params->max_event_log_size;
1472 1473 1474 1475 1476
	priv->_agn.init_errlog_ptr = pieces.init_errlog_ptr;
	priv->_agn.inst_evtlog_ptr = pieces.inst_evtlog_ptr;
	if (pieces.inst_evtlog_size)
		priv->_agn.inst_evtlog_size = (pieces.inst_evtlog_size - 16)/12;
	else
1477 1478
		priv->_agn.inst_evtlog_size =
			priv->cfg->base_params->max_event_log_size;
1479 1480
	priv->_agn.inst_errlog_ptr = pieces.inst_errlog_ptr;

1481 1482 1483
	priv->new_scan_threshold_behaviour =
		!!(ucode_capa.flags & IWL_UCODE_TLV_FLAGS_NEWSCAN);

1484 1485
	if ((priv->cfg->sku & EEPROM_SKU_CAP_IPAN_ENABLE) &&
	    (ucode_capa.flags & IWL_UCODE_TLV_FLAGS_PAN)) {
J
Johannes Berg 已提交
1486
		priv->valid_contexts |= BIT(IWL_RXON_CTX_PAN);
1487
		priv->sta_key_max_num = STA_KEY_MAX_NUM_PAN;
J
Johannes Berg 已提交
1488 1489
	} else
		priv->sta_key_max_num = STA_KEY_MAX_NUM;
1490

J
Johannes Berg 已提交
1491 1492 1493 1494 1495
	if (priv->valid_contexts != BIT(IWL_RXON_CTX_BSS))
		priv->cmd_queue = IWL_IPAN_CMD_QUEUE_NUM;
	else
		priv->cmd_queue = IWL_DEFAULT_CMD_QUEUE_NUM;

1496 1497 1498 1499 1500 1501 1502 1503 1504 1505 1506 1507 1508 1509
	/*
	 * figure out the offset of chain noise reset and gain commands
	 * base on the size of standard phy calibration commands table size
	 */
	if (ucode_capa.standard_phy_calibration_size >
	    IWL_MAX_PHY_CALIBRATE_TBL_SIZE)
		ucode_capa.standard_phy_calibration_size =
			IWL_MAX_STANDARD_PHY_CALIBRATE_TBL_SIZE;

	priv->_agn.phy_calib_chain_noise_reset_cmd =
		ucode_capa.standard_phy_calibration_size;
	priv->_agn.phy_calib_chain_noise_gain_cmd =
		ucode_capa.standard_phy_calibration_size + 1;

1510 1511 1512 1513 1514
	/**************************************************
	 * This is still part of probe() in a sense...
	 *
	 * 9. Setup and register with mac80211 and debugfs
	 **************************************************/
1515
	err = iwl_mac_setup_register(priv, &ucode_capa);
1516 1517 1518 1519 1520 1521 1522
	if (err)
		goto out_unbind;

	err = iwl_dbgfs_register(priv, DRV_NAME);
	if (err)
		IWL_ERR(priv, "failed to create debugfs files. Ignoring error: %d\n", err);

1523
	err = sysfs_create_group(&(priv->bus.dev->kobj),
1524 1525 1526 1527 1528 1529
					&iwl_attribute_group);
	if (err) {
		IWL_ERR(priv, "failed to create sysfs device attributes\n");
		goto out_unbind;
	}

Z
Zhu Yi 已提交
1530 1531
	/* We have our copies now, allow OS release its copies */
	release_firmware(ucode_raw);
1532
	complete(&priv->_agn.firmware_loading_complete);
1533 1534 1535 1536 1537 1538 1539 1540
	return;

 try_again:
	/* try next, if any */
	if (iwl_request_firmware(priv, false))
		goto out_unbind;
	release_firmware(ucode_raw);
	return;
Z
Zhu Yi 已提交
1541 1542

 err_pci_alloc:
1543
	IWL_ERR(priv, "failed to allocate pci memory\n");
1544
	iwl_dealloc_ucode(priv);
1545
 out_unbind:
1546
	complete(&priv->_agn.firmware_loading_complete);
1547
	device_release_driver(priv->bus.dev);
Z
Zhu Yi 已提交
1548 1549 1550
	release_firmware(ucode_raw);
}

1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581
static const char *desc_lookup_text[] = {
	"OK",
	"FAIL",
	"BAD_PARAM",
	"BAD_CHECKSUM",
	"NMI_INTERRUPT_WDG",
	"SYSASSERT",
	"FATAL_ERROR",
	"BAD_COMMAND",
	"HW_ERROR_TUNE_LOCK",
	"HW_ERROR_TEMPERATURE",
	"ILLEGAL_CHAN_FREQ",
	"VCC_NOT_STABLE",
	"FH_ERROR",
	"NMI_INTERRUPT_HOST",
	"NMI_INTERRUPT_ACTION_PT",
	"NMI_INTERRUPT_UNKNOWN",
	"UCODE_VERSION_MISMATCH",
	"HW_ERROR_ABS_LOCK",
	"HW_ERROR_CAL_LOCK_FAIL",
	"NMI_INTERRUPT_INST_ACTION_PT",
	"NMI_INTERRUPT_DATA_ACTION_PT",
	"NMI_TRM_HW_ER",
	"NMI_INTERRUPT_TRM",
	"NMI_INTERRUPT_BREAK_POINT"
	"DEBUG_0",
	"DEBUG_1",
	"DEBUG_2",
	"DEBUG_3",
};

1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601
static struct { char *name; u8 num; } advanced_lookup[] = {
	{ "NMI_INTERRUPT_WDG", 0x34 },
	{ "SYSASSERT", 0x35 },
	{ "UCODE_VERSION_MISMATCH", 0x37 },
	{ "BAD_COMMAND", 0x38 },
	{ "NMI_INTERRUPT_DATA_ACTION_PT", 0x3C },
	{ "FATAL_ERROR", 0x3D },
	{ "NMI_TRM_HW_ERR", 0x46 },
	{ "NMI_INTERRUPT_TRM", 0x4C },
	{ "NMI_INTERRUPT_BREAK_POINT", 0x54 },
	{ "NMI_INTERRUPT_WDG_RXF_FULL", 0x5C },
	{ "NMI_INTERRUPT_WDG_NO_RBD_RXF_FULL", 0x64 },
	{ "NMI_INTERRUPT_HOST", 0x66 },
	{ "NMI_INTERRUPT_ACTION_PT", 0x7C },
	{ "NMI_INTERRUPT_UNKNOWN", 0x84 },
	{ "NMI_INTERRUPT_INST_ACTION_PT", 0x86 },
	{ "ADVANCED_SYSASSERT", 0 },
};

static const char *desc_lookup(u32 num)
1602
{
1603 1604
	int i;
	int max = ARRAY_SIZE(desc_lookup_text);
1605

1606 1607
	if (num < max)
		return desc_lookup_text[num];
1608

1609 1610 1611
	max = ARRAY_SIZE(advanced_lookup) - 1;
	for (i = 0; i < max; i++) {
		if (advanced_lookup[i].num == num)
1612
			break;
1613 1614
	}
	return advanced_lookup[i].name;
1615 1616 1617 1618 1619 1620 1621
}

#define ERROR_START_OFFSET  (1 * sizeof(u32))
#define ERROR_ELEM_SIZE     (7 * sizeof(u32))

void iwl_dump_nic_error_log(struct iwl_priv *priv)
{
W
Wey-Yi Guy 已提交
1622
	u32 base;
1623
	struct iwl_error_event_table table;
1624

J
Johannes Berg 已提交
1625
	base = priv->device_pointers.error_event_table;
1626
	if (priv->ucode_type == IWL_UCODE_INIT) {
1627 1628 1629 1630 1631 1632
		if (!base)
			base = priv->_agn.init_errlog_ptr;
	} else {
		if (!base)
			base = priv->_agn.inst_errlog_ptr;
	}
1633 1634

	if (!priv->cfg->ops->lib->is_valid_rtc_data_addr(base)) {
1635 1636
		IWL_ERR(priv,
			"Not valid error log pointer 0x%08X for %s uCode\n",
1637
			base,
1638
			(priv->ucode_type == IWL_UCODE_INIT)
1639
					? "Init" : "RT");
1640 1641 1642
		return;
	}

1643 1644
	iwl_read_targ_mem_words(priv, base, &table, sizeof(table));

W
Wey-Yi Guy 已提交
1645
	if (ERROR_START_OFFSET <= table.valid * ERROR_ELEM_SIZE) {
1646 1647
		IWL_ERR(priv, "Start IWL Error Log Dump:\n");
		IWL_ERR(priv, "Status: 0x%08lX, count: %d\n",
W
Wey-Yi Guy 已提交
1648
			priv->status, table.valid);
1649 1650
	}

W
Wey-Yi Guy 已提交
1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666 1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678
	priv->isr_stats.err_code = table.error_id;

	trace_iwlwifi_dev_ucode_error(priv, table.error_id, table.tsf_low,
				      table.data1, table.data2, table.line,
				      table.blink1, table.blink2, table.ilink1,
				      table.ilink2, table.bcon_time, table.gp1,
				      table.gp2, table.gp3, table.ucode_ver,
				      table.hw_ver, table.brd_ver);
	IWL_ERR(priv, "0x%08X | %-28s\n", table.error_id,
		desc_lookup(table.error_id));
	IWL_ERR(priv, "0x%08X | uPc\n", table.pc);
	IWL_ERR(priv, "0x%08X | branchlink1\n", table.blink1);
	IWL_ERR(priv, "0x%08X | branchlink2\n", table.blink2);
	IWL_ERR(priv, "0x%08X | interruptlink1\n", table.ilink1);
	IWL_ERR(priv, "0x%08X | interruptlink2\n", table.ilink2);
	IWL_ERR(priv, "0x%08X | data1\n", table.data1);
	IWL_ERR(priv, "0x%08X | data2\n", table.data2);
	IWL_ERR(priv, "0x%08X | line\n", table.line);
	IWL_ERR(priv, "0x%08X | beacon time\n", table.bcon_time);
	IWL_ERR(priv, "0x%08X | tsf low\n", table.tsf_low);
	IWL_ERR(priv, "0x%08X | tsf hi\n", table.tsf_hi);
	IWL_ERR(priv, "0x%08X | time gp1\n", table.gp1);
	IWL_ERR(priv, "0x%08X | time gp2\n", table.gp2);
	IWL_ERR(priv, "0x%08X | time gp3\n", table.gp3);
	IWL_ERR(priv, "0x%08X | uCode version\n", table.ucode_ver);
	IWL_ERR(priv, "0x%08X | hw version\n", table.hw_ver);
	IWL_ERR(priv, "0x%08X | board version\n", table.brd_ver);
	IWL_ERR(priv, "0x%08X | hcmd\n", table.hcmd);
1679 1680 1681 1682 1683 1684 1685 1686
}

#define EVENT_START_OFFSET  (4 * sizeof(u32))

/**
 * iwl_print_event_log - Dump error event log to syslog
 *
 */
W
Wey-Yi Guy 已提交
1687 1688 1689
static int iwl_print_event_log(struct iwl_priv *priv, u32 start_idx,
			       u32 num_events, u32 mode,
			       int pos, char **buf, size_t bufsz)
1690 1691 1692 1693 1694 1695
{
	u32 i;
	u32 base;       /* SRAM byte address of event log header */
	u32 event_size; /* 2 u32s, or 3 u32s if timestamp recorded */
	u32 ptr;        /* SRAM byte address of log data */
	u32 ev, time, data; /* event log data */
B
Ben Cahill 已提交
1696
	unsigned long reg_flags;
1697 1698

	if (num_events == 0)
W
Wey-Yi Guy 已提交
1699
		return pos;
1700

J
Johannes Berg 已提交
1701
	base = priv->device_pointers.log_event_table;
1702
	if (priv->ucode_type == IWL_UCODE_INIT) {
1703 1704 1705 1706 1707 1708
		if (!base)
			base = priv->_agn.init_evtlog_ptr;
	} else {
		if (!base)
			base = priv->_agn.inst_evtlog_ptr;
	}
1709 1710 1711 1712 1713 1714 1715 1716

	if (mode == 0)
		event_size = 2 * sizeof(u32);
	else
		event_size = 3 * sizeof(u32);

	ptr = base + EVENT_START_OFFSET + (start_idx * event_size);

B
Ben Cahill 已提交
1717 1718 1719 1720 1721
	/* Make sure device is powered up for SRAM reads */
	spin_lock_irqsave(&priv->reg_lock, reg_flags);
	iwl_grab_nic_access(priv);

	/* Set starting address; reads will auto-increment */
1722
	iwl_write32(priv, HBUS_TARG_MEM_RADDR, ptr);
B
Ben Cahill 已提交
1723 1724
	rmb();

1725 1726 1727
	/* "time" is actually "data" for mode 0 (no timestamp).
	* place event id # at far right for easier visual parsing. */
	for (i = 0; i < num_events; i++) {
1728 1729
		ev = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
		time = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
1730 1731
		if (mode == 0) {
			/* data, ev */
W
Wey-Yi Guy 已提交
1732 1733 1734 1735 1736 1737 1738 1739 1740 1741
			if (bufsz) {
				pos += scnprintf(*buf + pos, bufsz - pos,
						"EVT_LOG:0x%08x:%04u\n",
						time, ev);
			} else {
				trace_iwlwifi_dev_ucode_event(priv, 0,
					time, ev);
				IWL_ERR(priv, "EVT_LOG:0x%08x:%04u\n",
					time, ev);
			}
1742
		} else {
1743
			data = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
W
Wey-Yi Guy 已提交
1744 1745 1746 1747 1748 1749
			if (bufsz) {
				pos += scnprintf(*buf + pos, bufsz - pos,
						"EVT_LOGT:%010u:0x%08x:%04u\n",
						 time, data, ev);
			} else {
				IWL_ERR(priv, "EVT_LOGT:%010u:0x%08x:%04u\n",
1750
					time, data, ev);
W
Wey-Yi Guy 已提交
1751 1752 1753
				trace_iwlwifi_dev_ucode_event(priv, time,
					data, ev);
			}
1754 1755
		}
	}
B
Ben Cahill 已提交
1756 1757 1758 1759

	/* Allow device to power down */
	iwl_release_nic_access(priv);
	spin_unlock_irqrestore(&priv->reg_lock, reg_flags);
W
Wey-Yi Guy 已提交
1760
	return pos;
1761 1762
}

1763 1764 1765
/**
 * iwl_print_last_event_logs - Dump the newest # of event log to syslog
 */
W
Wey-Yi Guy 已提交
1766 1767 1768 1769
static int iwl_print_last_event_logs(struct iwl_priv *priv, u32 capacity,
				    u32 num_wraps, u32 next_entry,
				    u32 size, u32 mode,
				    int pos, char **buf, size_t bufsz)
1770 1771 1772 1773 1774 1775 1776
{
	/*
	 * display the newest DEFAULT_LOG_ENTRIES entries
	 * i.e the entries just before the next ont that uCode would fill.
	 */
	if (num_wraps) {
		if (next_entry < size) {
W
Wey-Yi Guy 已提交
1777 1778 1779 1780 1781 1782 1783
			pos = iwl_print_event_log(priv,
						capacity - (size - next_entry),
						size - next_entry, mode,
						pos, buf, bufsz);
			pos = iwl_print_event_log(priv, 0,
						  next_entry, mode,
						  pos, buf, bufsz);
1784
		} else
W
Wey-Yi Guy 已提交
1785 1786
			pos = iwl_print_event_log(priv, next_entry - size,
						  size, mode, pos, buf, bufsz);
1787
	} else {
W
Wey-Yi Guy 已提交
1788 1789 1790 1791 1792 1793 1794
		if (next_entry < size) {
			pos = iwl_print_event_log(priv, 0, next_entry,
						  mode, pos, buf, bufsz);
		} else {
			pos = iwl_print_event_log(priv, next_entry - size,
						  size, mode, pos, buf, bufsz);
		}
1795
	}
W
Wey-Yi Guy 已提交
1796
	return pos;
1797 1798 1799 1800
}

#define DEFAULT_DUMP_EVENT_LOG_ENTRIES (20)

W
Wey-Yi Guy 已提交
1801 1802
int iwl_dump_nic_event_log(struct iwl_priv *priv, bool full_log,
			    char **buf, bool display)
1803 1804 1805 1806 1807 1808 1809
{
	u32 base;       /* SRAM byte address of event log header */
	u32 capacity;   /* event log capacity in # entries */
	u32 mode;       /* 0 - no timestamp, 1 - timestamp recorded */
	u32 num_wraps;  /* # times uCode wrapped to top of log */
	u32 next_entry; /* index of next entry to be written by uCode */
	u32 size;       /* # entries that we'll print */
1810
	u32 logsize;
W
Wey-Yi Guy 已提交
1811 1812
	int pos = 0;
	size_t bufsz = 0;
1813

J
Johannes Berg 已提交
1814
	base = priv->device_pointers.log_event_table;
1815
	if (priv->ucode_type == IWL_UCODE_INIT) {
1816 1817 1818 1819 1820 1821 1822 1823
		logsize = priv->_agn.init_evtlog_size;
		if (!base)
			base = priv->_agn.init_evtlog_ptr;
	} else {
		logsize = priv->_agn.inst_evtlog_size;
		if (!base)
			base = priv->_agn.inst_evtlog_ptr;
	}
1824 1825

	if (!priv->cfg->ops->lib->is_valid_rtc_data_addr(base)) {
1826 1827
		IWL_ERR(priv,
			"Invalid event log pointer 0x%08X for %s uCode\n",
1828
			base,
1829
			(priv->ucode_type == IWL_UCODE_INIT)
1830
					? "Init" : "RT");
1831
		return -EINVAL;
1832 1833 1834 1835 1836 1837 1838 1839
	}

	/* event log header */
	capacity = iwl_read_targ_mem(priv, base);
	mode = iwl_read_targ_mem(priv, base + (1 * sizeof(u32)));
	num_wraps = iwl_read_targ_mem(priv, base + (2 * sizeof(u32)));
	next_entry = iwl_read_targ_mem(priv, base + (3 * sizeof(u32)));

1840
	if (capacity > logsize) {
B
Ben Cahill 已提交
1841
		IWL_ERR(priv, "Log capacity %d is bogus, limit to %d entries\n",
1842 1843
			capacity, logsize);
		capacity = logsize;
B
Ben Cahill 已提交
1844 1845
	}

1846
	if (next_entry > logsize) {
B
Ben Cahill 已提交
1847
		IWL_ERR(priv, "Log write index %d is bogus, limit to %d\n",
1848 1849
			next_entry, logsize);
		next_entry = logsize;
B
Ben Cahill 已提交
1850 1851
	}

1852 1853 1854 1855 1856
	size = num_wraps ? capacity : next_entry;

	/* bail out if nothing in log */
	if (size == 0) {
		IWL_ERR(priv, "Start IWL Event Log Dump: nothing in log\n");
W
Wey-Yi Guy 已提交
1857
		return pos;
1858 1859
	}

1860
	/* enable/disable bt channel inhibition */
1861 1862
	priv->bt_ch_announce = iwlagn_bt_ch_announce;

1863
#ifdef CONFIG_IWLWIFI_DEBUG
1864
	if (!(iwl_get_debug_level(priv) & IWL_DL_FW_ERRORS) && !full_log)
1865 1866 1867 1868 1869 1870 1871 1872
		size = (size > DEFAULT_DUMP_EVENT_LOG_ENTRIES)
			? DEFAULT_DUMP_EVENT_LOG_ENTRIES : size;
#else
	size = (size > DEFAULT_DUMP_EVENT_LOG_ENTRIES)
		? DEFAULT_DUMP_EVENT_LOG_ENTRIES : size;
#endif
	IWL_ERR(priv, "Start IWL Event Log Dump: display last %u entries\n",
		size);
1873

1874
#ifdef CONFIG_IWLWIFI_DEBUG
W
Wey-Yi Guy 已提交
1875 1876 1877 1878 1879 1880 1881
	if (display) {
		if (full_log)
			bufsz = capacity * 48;
		else
			bufsz = size * 48;
		*buf = kmalloc(bufsz, GFP_KERNEL);
		if (!*buf)
1882
			return -ENOMEM;
W
Wey-Yi Guy 已提交
1883
	}
1884 1885 1886 1887 1888 1889 1890
	if ((iwl_get_debug_level(priv) & IWL_DL_FW_ERRORS) || full_log) {
		/*
		 * if uCode has wrapped back to top of log,
		 * start at the oldest entry,
		 * i.e the next one that uCode would fill.
		 */
		if (num_wraps)
W
Wey-Yi Guy 已提交
1891 1892 1893
			pos = iwl_print_event_log(priv, next_entry,
						capacity - next_entry, mode,
						pos, buf, bufsz);
1894
		/* (then/else) start at top of log */
W
Wey-Yi Guy 已提交
1895 1896
		pos = iwl_print_event_log(priv, 0,
					  next_entry, mode, pos, buf, bufsz);
1897
	} else
W
Wey-Yi Guy 已提交
1898 1899 1900
		pos = iwl_print_last_event_logs(priv, capacity, num_wraps,
						next_entry, size, mode,
						pos, buf, bufsz);
1901
#else
W
Wey-Yi Guy 已提交
1902 1903 1904
	pos = iwl_print_last_event_logs(priv, capacity, num_wraps,
					next_entry, size, mode,
					pos, buf, bufsz);
1905
#endif
W
Wey-Yi Guy 已提交
1906
	return pos;
1907
}
1908

1909 1910 1911 1912 1913 1914 1915 1916 1917 1918 1919 1920 1921
static void iwl_rf_kill_ct_config(struct iwl_priv *priv)
{
	struct iwl_ct_kill_config cmd;
	struct iwl_ct_kill_throttling_config adv_cmd;
	unsigned long flags;
	int ret = 0;

	spin_lock_irqsave(&priv->lock, flags);
	iwl_write32(priv, CSR_UCODE_DRV_GP1_CLR,
		    CSR_UCODE_DRV_GP1_REG_BIT_CT_KILL_EXIT);
	spin_unlock_irqrestore(&priv->lock, flags);
	priv->thermal_throttle.ct_kill_toggle = false;

1922
	if (priv->cfg->base_params->support_ct_kill_exit) {
1923 1924 1925 1926 1927 1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939 1940 1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953 1954
		adv_cmd.critical_temperature_enter =
			cpu_to_le32(priv->hw_params.ct_kill_threshold);
		adv_cmd.critical_temperature_exit =
			cpu_to_le32(priv->hw_params.ct_kill_exit_threshold);

		ret = iwl_send_cmd_pdu(priv, REPLY_CT_KILL_CONFIG_CMD,
				       sizeof(adv_cmd), &adv_cmd);
		if (ret)
			IWL_ERR(priv, "REPLY_CT_KILL_CONFIG_CMD failed\n");
		else
			IWL_DEBUG_INFO(priv, "REPLY_CT_KILL_CONFIG_CMD "
					"succeeded, "
					"critical temperature enter is %d,"
					"exit is %d\n",
				       priv->hw_params.ct_kill_threshold,
				       priv->hw_params.ct_kill_exit_threshold);
	} else {
		cmd.critical_temperature_R =
			cpu_to_le32(priv->hw_params.ct_kill_threshold);

		ret = iwl_send_cmd_pdu(priv, REPLY_CT_KILL_CONFIG_CMD,
				       sizeof(cmd), &cmd);
		if (ret)
			IWL_ERR(priv, "REPLY_CT_KILL_CONFIG_CMD failed\n");
		else
			IWL_DEBUG_INFO(priv, "REPLY_CT_KILL_CONFIG_CMD "
					"succeeded, "
					"critical temperature is %d\n",
					priv->hw_params.ct_kill_threshold);
	}
}

1955 1956 1957 1958 1959
static int iwlagn_send_calib_cfg_rt(struct iwl_priv *priv, u32 cfg)
{
	struct iwl_calib_cfg_cmd calib_cfg_cmd;
	struct iwl_host_cmd cmd = {
		.id = CALIBRATION_CFG_CMD,
1960 1961
		.len = { sizeof(struct iwl_calib_cfg_cmd), },
		.data = { &calib_cfg_cmd, },
1962 1963 1964 1965
	};

	memset(&calib_cfg_cmd, 0, sizeof(calib_cfg_cmd));
	calib_cfg_cmd.ucd_calib_cfg.once.is_enable = IWL_CALIB_INIT_CFG_ALL;
1966
	calib_cfg_cmd.ucd_calib_cfg.once.start = cpu_to_le32(cfg);
1967 1968 1969 1970 1971

	return iwl_send_cmd(priv, &cmd);
}


Z
Zhu Yi 已提交
1972
/**
1973
 * iwl_alive_start - called after REPLY_ALIVE notification received
Z
Zhu Yi 已提交
1974
 *                   from protocol/runtime uCode (initialization uCode's
1975
 *                   Alive gets handled by iwl_init_alive_start()).
Z
Zhu Yi 已提交
1976
 */
1977
int iwl_alive_start(struct iwl_priv *priv)
Z
Zhu Yi 已提交
1978
{
1979
	int ret = 0;
1980
	struct iwl_rxon_context *ctx = &priv->contexts[IWL_RXON_CTX_BSS];
Z
Zhu Yi 已提交
1981

1982
	iwl_reset_ict(priv);
Z
Zhu Yi 已提交
1983

1984
	IWL_DEBUG_INFO(priv, "Runtime Alive received.\n");
1985

1986
	/* After the ALIVE response, we can send host commands to the uCode */
Z
Zhu Yi 已提交
1987 1988
	set_bit(STATUS_ALIVE, &priv->status);

1989 1990
	/* Enable watchdog to monitor the driver tx queues */
	iwl_setup_watchdog(priv);
1991

1992
	if (iwl_is_rfkill(priv))
1993
		return -ERFKILL;
Z
Zhu Yi 已提交
1994

1995
	/* download priority table before any calibration request */
1996 1997
	if (priv->cfg->bt_params &&
	    priv->cfg->bt_params->advanced_bt_coexist) {
1998 1999 2000 2001 2002 2003
		/* Configure Bluetooth device coexistence support */
		priv->bt_valid = IWLAGN_BT_ALL_VALID_MSK;
		priv->kill_ack_mask = IWLAGN_BT_KILL_ACK_MASK_DEFAULT;
		priv->kill_cts_mask = IWLAGN_BT_KILL_CTS_MASK_DEFAULT;
		priv->cfg->ops->hcmd->send_bt_config(priv);
		priv->bt_valid = IWLAGN_BT_VALID_ENABLE_FLAGS;
2004
		iwlagn_send_prio_tbl(priv);
2005 2006

		/* FIXME: w/a to force change uCode BT state machine */
2007 2008 2009 2010 2011 2012 2013 2014
		ret = iwlagn_send_bt_env(priv, IWL_BT_COEX_ENV_OPEN,
					 BT_COEX_PRIO_TBL_EVT_INIT_CALIB2);
		if (ret)
			return ret;
		ret = iwlagn_send_bt_env(priv, IWL_BT_COEX_ENV_CLOSE,
					 BT_COEX_PRIO_TBL_EVT_INIT_CALIB2);
		if (ret)
			return ret;
2015
	}
2016 2017 2018
	if (priv->hw_params.calib_rt_cfg)
		iwlagn_send_calib_cfg_rt(priv, priv->hw_params.calib_rt_cfg);

2019
	ieee80211_wake_queues(priv->hw);
Z
Zhu Yi 已提交
2020

2021
	priv->active_rate = IWL_RATES_MASK;
Z
Zhu Yi 已提交
2022

2023 2024 2025 2026
	/* Configure Tx antenna selection based on H/W config */
	if (priv->cfg->ops->hcmd->set_tx_ant)
		priv->cfg->ops->hcmd->set_tx_ant(priv, priv->cfg->valid_tx_ant);

2027
	if (iwl_is_associated_ctx(ctx)) {
G
Gregory Greenman 已提交
2028
		struct iwl_rxon_cmd *active_rxon =
2029
				(struct iwl_rxon_cmd *)&ctx->active;
2030
		/* apply any changes in staging */
2031
		ctx->staging.filter_flags |= RXON_FILTER_ASSOC_MSK;
Z
Zhu Yi 已提交
2032 2033
		active_rxon->filter_flags &= ~RXON_FILTER_ASSOC_MSK;
	} else {
2034
		struct iwl_rxon_context *tmp;
Z
Zhu Yi 已提交
2035
		/* Initialize our rx_config data */
2036 2037
		for_each_context(priv, tmp)
			iwl_connection_init_rx_config(priv, tmp);
2038 2039

		if (priv->cfg->ops->hcmd->set_rxon_chain)
2040
			priv->cfg->ops->hcmd->set_rxon_chain(priv, ctx);
Z
Zhu Yi 已提交
2041 2042
	}

2043 2044 2045 2046 2047
	if (!priv->cfg->bt_params || (priv->cfg->bt_params &&
	    !priv->cfg->bt_params->advanced_bt_coexist)) {
		/*
		 * default is 2-wire BT coexexistence support
		 */
2048 2049
		priv->cfg->ops->hcmd->send_bt_config(priv);
	}
Z
Zhu Yi 已提交
2050

2051 2052
	iwl_reset_run_time_calib(priv);

2053 2054
	set_bit(STATUS_READY, &priv->status);

Z
Zhu Yi 已提交
2055
	/* Configure the adapter for unassociated operation */
2056
	ret = iwlagn_commit_rxon(priv, ctx);
2057 2058
	if (ret)
		return ret;
Z
Zhu Yi 已提交
2059 2060

	/* At this point, the NIC is initialized and operational */
2061
	iwl_rf_kill_ct_config(priv);
2062

2063
	IWL_DEBUG_INFO(priv, "ALIVE processing complete.\n");
2064

2065
	return iwl_power_update_mode(priv, true);
Z
Zhu Yi 已提交
2066 2067
}

2068
static void iwl_cancel_deferred_work(struct iwl_priv *priv);
Z
Zhu Yi 已提交
2069

2070
static void __iwl_down(struct iwl_priv *priv)
Z
Zhu Yi 已提交
2071
{
2072
	int exit_pending;
Z
Zhu Yi 已提交
2073

2074
	IWL_DEBUG_INFO(priv, DRV_NAME " is going down\n");
Z
Zhu Yi 已提交
2075

2076 2077 2078
	iwl_scan_cancel_timeout(priv, 200);

	exit_pending = test_and_set_bit(STATUS_EXIT_PENDING, &priv->status);
Z
Zhu Yi 已提交
2079

2080 2081
	/* Stop TX queues watchdog. We need to have STATUS_EXIT_PENDING bit set
	 * to prevent rearm timer */
2082
	del_timer_sync(&priv->watchdog);
2083

2084
	iwl_clear_ucode_stations(priv, NULL);
2085
	iwl_dealloc_bcast_stations(priv);
2086
	iwl_clear_driver_stations(priv);
Z
Zhu Yi 已提交
2087

2088
	/* reset BT coex data */
2089
	priv->bt_status = 0;
2090 2091 2092 2093 2094
	if (priv->cfg->bt_params)
		priv->bt_traffic_load =
			 priv->cfg->bt_params->bt_init_traffic_load;
	else
		priv->bt_traffic_load = 0;
2095 2096
	priv->bt_full_concurrent = false;
	priv->bt_ci_compliance = 0;
2097

Z
Zhu Yi 已提交
2098 2099 2100 2101 2102 2103 2104 2105
	/* Wipe out the EXIT_PENDING status bit if we are not actually
	 * exiting the module */
	if (!exit_pending)
		clear_bit(STATUS_EXIT_PENDING, &priv->status);

	if (priv->mac80211_registered)
		ieee80211_stop_queues(priv->hw);

J
Johannes Berg 已提交
2106
	/* Clear out all status bits but a few that are stable across reset */
Z
Zhu Yi 已提交
2107 2108
	priv->status &= test_bit(STATUS_RF_KILL_HW, &priv->status) <<
				STATUS_RF_KILL_HW |
2109 2110
			test_bit(STATUS_GEO_CONFIGURED, &priv->status) <<
				STATUS_GEO_CONFIGURED |
Z
Zhu Yi 已提交
2111
			test_bit(STATUS_FW_ERROR, &priv->status) <<
2112 2113 2114
				STATUS_FW_ERROR |
		       test_bit(STATUS_EXIT_PENDING, &priv->status) <<
				STATUS_EXIT_PENDING;
Z
Zhu Yi 已提交
2115

J
Johannes Berg 已提交
2116
	iwlagn_stop_device(priv);
2117

2118
	dev_kfree_skb(priv->beacon_skb);
2119
	priv->beacon_skb = NULL;
Z
Zhu Yi 已提交
2120 2121
}

2122
static void iwl_down(struct iwl_priv *priv)
Z
Zhu Yi 已提交
2123 2124
{
	mutex_lock(&priv->mutex);
2125
	__iwl_down(priv);
Z
Zhu Yi 已提交
2126
	mutex_unlock(&priv->mutex);
2127

2128
	iwl_cancel_deferred_work(priv);
Z
Zhu Yi 已提交
2129 2130
}

M
Mohamed Abbas 已提交
2131 2132
#define HW_READY_TIMEOUT (50)

J
Johannes Berg 已提交
2133
/* Note: returns poll_bit return value, which is >= 0 if success */
M
Mohamed Abbas 已提交
2134 2135
static int iwl_set_hw_ready(struct iwl_priv *priv)
{
J
Johannes Berg 已提交
2136
	int ret;
M
Mohamed Abbas 已提交
2137 2138 2139 2140 2141 2142 2143 2144 2145 2146

	iwl_set_bit(priv, CSR_HW_IF_CONFIG_REG,
		CSR_HW_IF_CONFIG_REG_BIT_NIC_READY);

	/* See if we got it */
	ret = iwl_poll_bit(priv, CSR_HW_IF_CONFIG_REG,
				CSR_HW_IF_CONFIG_REG_BIT_NIC_READY,
				CSR_HW_IF_CONFIG_REG_BIT_NIC_READY,
				HW_READY_TIMEOUT);

J
Johannes Berg 已提交
2147
	IWL_DEBUG_INFO(priv, "hardware%s ready\n", ret < 0 ? " not" : "");
M
Mohamed Abbas 已提交
2148 2149 2150
	return ret;
}

J
Johannes Berg 已提交
2151
/* Note: returns standard 0/-ERROR code */
J
Johannes Berg 已提交
2152
int iwl_prepare_card_hw(struct iwl_priv *priv)
M
Mohamed Abbas 已提交
2153
{
J
Johannes Berg 已提交
2154
	int ret;
M
Mohamed Abbas 已提交
2155

2156
	IWL_DEBUG_INFO(priv, "iwl_prepare_card_hw enter\n");
M
Mohamed Abbas 已提交
2157

2158
	ret = iwl_set_hw_ready(priv);
J
Johannes Berg 已提交
2159 2160
	if (ret >= 0)
		return 0;
2161 2162

	/* If HW is not ready, prepare the conditions to check again */
M
Mohamed Abbas 已提交
2163 2164 2165 2166 2167 2168 2169
	iwl_set_bit(priv, CSR_HW_IF_CONFIG_REG,
			CSR_HW_IF_CONFIG_REG_PREPARE);

	ret = iwl_poll_bit(priv, CSR_HW_IF_CONFIG_REG,
			~CSR_HW_IF_CONFIG_REG_BIT_NIC_PREPARE_DONE,
			CSR_HW_IF_CONFIG_REG_BIT_NIC_PREPARE_DONE, 150000);

J
Johannes Berg 已提交
2170 2171
	if (ret < 0)
		return ret;
M
Mohamed Abbas 已提交
2172

J
Johannes Berg 已提交
2173 2174 2175 2176
	/* HW should be ready by now, check again. */
	ret = iwl_set_hw_ready(priv);
	if (ret >= 0)
		return 0;
M
Mohamed Abbas 已提交
2177 2178 2179
	return ret;
}

Z
Zhu Yi 已提交
2180 2181
#define MAX_HW_RESTARTS 5

2182
static int __iwl_up(struct iwl_priv *priv)
Z
Zhu Yi 已提交
2183
{
2184
	struct iwl_rxon_context *ctx;
2185
	int ret;
Z
Zhu Yi 已提交
2186

2187 2188
	lockdep_assert_held(&priv->mutex);

Z
Zhu Yi 已提交
2189
	if (test_bit(STATUS_EXIT_PENDING, &priv->status)) {
2190
		IWL_WARN(priv, "Exit pending; will not bring the NIC up\n");
Z
Zhu Yi 已提交
2191 2192 2193
		return -EIO;
	}

2194
	for_each_context(priv, ctx) {
2195
		ret = iwlagn_alloc_bcast_station(priv, ctx);
2196 2197 2198 2199 2200
		if (ret) {
			iwl_dealloc_bcast_stations(priv);
			return ret;
		}
	}
2201

2202 2203 2204 2205 2206
	ret = iwlagn_run_init_ucode(priv);
	if (ret) {
		IWL_ERR(priv, "Failed to run INIT ucode: %d\n", ret);
		goto error;
	}
Z
Zhu Yi 已提交
2207

2208
	ret = iwlagn_load_ucode_wait_alive(priv,
2209
					   &priv->ucode_rt,
2210
					   IWL_UCODE_REGULAR);
2211 2212 2213
	if (ret) {
		IWL_ERR(priv, "Failed to start RT ucode: %d\n", ret);
		goto error;
Z
Zhu Yi 已提交
2214 2215
	}

2216 2217 2218 2219 2220 2221
	ret = iwl_alive_start(priv);
	if (ret)
		goto error;
	return 0;

 error:
Z
Zhu Yi 已提交
2222
	set_bit(STATUS_EXIT_PENDING, &priv->status);
2223
	__iwl_down(priv);
M
Mohamed Abbas 已提交
2224
	clear_bit(STATUS_EXIT_PENDING, &priv->status);
Z
Zhu Yi 已提交
2225

2226 2227
	IWL_ERR(priv, "Unable to initialize device.\n");
	return ret;
Z
Zhu Yi 已提交
2228 2229 2230 2231 2232 2233 2234 2235 2236
}


/*****************************************************************************
 *
 * Workqueue callbacks
 *
 *****************************************************************************/

2237 2238 2239 2240 2241 2242 2243 2244 2245 2246 2247 2248 2249 2250
static void iwl_bg_run_time_calib_work(struct work_struct *work)
{
	struct iwl_priv *priv = container_of(work, struct iwl_priv,
			run_time_calib_work);

	mutex_lock(&priv->mutex);

	if (test_bit(STATUS_EXIT_PENDING, &priv->status) ||
	    test_bit(STATUS_SCANNING, &priv->status)) {
		mutex_unlock(&priv->mutex);
		return;
	}

	if (priv->start_calib) {
2251 2252
		iwl_chain_noise_calibration(priv);
		iwl_sensitivity_calibration(priv);
2253 2254 2255 2256 2257
	}

	mutex_unlock(&priv->mutex);
}

J
Johannes Berg 已提交
2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268 2269 2270 2271 2272 2273 2274 2275 2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293
static void iwlagn_prepare_restart(struct iwl_priv *priv)
{
	struct iwl_rxon_context *ctx;
	bool bt_full_concurrent;
	u8 bt_ci_compliance;
	u8 bt_load;
	u8 bt_status;

	lockdep_assert_held(&priv->mutex);

	for_each_context(priv, ctx)
		ctx->vif = NULL;
	priv->is_open = 0;

	/*
	 * __iwl_down() will clear the BT status variables,
	 * which is correct, but when we restart we really
	 * want to keep them so restore them afterwards.
	 *
	 * The restart process will later pick them up and
	 * re-configure the hw when we reconfigure the BT
	 * command.
	 */
	bt_full_concurrent = priv->bt_full_concurrent;
	bt_ci_compliance = priv->bt_ci_compliance;
	bt_load = priv->bt_traffic_load;
	bt_status = priv->bt_status;

	__iwl_down(priv);

	priv->bt_full_concurrent = bt_full_concurrent;
	priv->bt_ci_compliance = bt_ci_compliance;
	priv->bt_traffic_load = bt_load;
	priv->bt_status = bt_status;
}

2294
static void iwl_bg_restart(struct work_struct *data)
Z
Zhu Yi 已提交
2295
{
2296
	struct iwl_priv *priv = container_of(data, struct iwl_priv, restart);
Z
Zhu Yi 已提交
2297 2298 2299 2300

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

J
Johannes Berg 已提交
2301 2302
	if (test_and_clear_bit(STATUS_FW_ERROR, &priv->status)) {
		mutex_lock(&priv->mutex);
J
Johannes Berg 已提交
2303
		iwlagn_prepare_restart(priv);
J
Johannes Berg 已提交
2304
		mutex_unlock(&priv->mutex);
2305
		iwl_cancel_deferred_work(priv);
J
Johannes Berg 已提交
2306 2307
		ieee80211_restart_hw(priv->hw);
	} else {
2308
		WARN_ON(1);
J
Johannes Berg 已提交
2309
	}
Z
Zhu Yi 已提交
2310 2311
}

2312
static void iwl_bg_rx_replenish(struct work_struct *data)
Z
Zhu Yi 已提交
2313
{
2314 2315
	struct iwl_priv *priv =
	    container_of(data, struct iwl_priv, rx_replenish);
Z
Zhu Yi 已提交
2316 2317 2318 2319 2320

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	mutex_lock(&priv->mutex);
2321
	iwlagn_rx_replenish(priv);
Z
Zhu Yi 已提交
2322 2323 2324
	mutex_unlock(&priv->mutex);
}

J
Johannes Berg 已提交
2325 2326 2327 2328 2329 2330 2331 2332 2333 2334 2335 2336 2337 2338 2339 2340 2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 2351 2352 2353 2354 2355 2356 2357 2358 2359 2360 2361 2362 2363 2364 2365 2366 2367 2368 2369 2370 2371 2372 2373 2374 2375 2376 2377 2378 2379 2380 2381 2382 2383 2384 2385 2386 2387 2388 2389 2390 2391 2392 2393 2394 2395 2396
static int iwl_mac_offchannel_tx(struct ieee80211_hw *hw, struct sk_buff *skb,
				 struct ieee80211_channel *chan,
				 enum nl80211_channel_type channel_type,
				 unsigned int wait)
{
	struct iwl_priv *priv = hw->priv;
	int ret;

	/* Not supported if we don't have PAN */
	if (!(priv->valid_contexts & BIT(IWL_RXON_CTX_PAN))) {
		ret = -EOPNOTSUPP;
		goto free;
	}

	/* Not supported on pre-P2P firmware */
	if (!(priv->contexts[IWL_RXON_CTX_PAN].interface_modes &
					BIT(NL80211_IFTYPE_P2P_CLIENT))) {
		ret = -EOPNOTSUPP;
		goto free;
	}

	mutex_lock(&priv->mutex);

	if (!priv->contexts[IWL_RXON_CTX_PAN].is_active) {
		/*
		 * If the PAN context is free, use the normal
		 * way of doing remain-on-channel offload + TX.
		 */
		ret = 1;
		goto out;
	}

	/* TODO: queue up if scanning? */
	if (test_bit(STATUS_SCANNING, &priv->status) ||
	    priv->_agn.offchan_tx_skb) {
		ret = -EBUSY;
		goto out;
	}

	/*
	 * max_scan_ie_len doesn't include the blank SSID or the header,
	 * so need to add that again here.
	 */
	if (skb->len > hw->wiphy->max_scan_ie_len + 24 + 2) {
		ret = -ENOBUFS;
		goto out;
	}

	priv->_agn.offchan_tx_skb = skb;
	priv->_agn.offchan_tx_timeout = wait;
	priv->_agn.offchan_tx_chan = chan;

	ret = iwl_scan_initiate(priv, priv->contexts[IWL_RXON_CTX_PAN].vif,
				IWL_SCAN_OFFCH_TX, chan->band);
	if (ret)
		priv->_agn.offchan_tx_skb = NULL;
 out:
	mutex_unlock(&priv->mutex);
 free:
	if (ret < 0)
		kfree_skb(skb);

	return ret;
}

static int iwl_mac_offchannel_tx_cancel_wait(struct ieee80211_hw *hw)
{
	struct iwl_priv *priv = hw->priv;
	int ret;

	mutex_lock(&priv->mutex);

2397 2398 2399 2400
	if (!priv->_agn.offchan_tx_skb) {
		ret = -EINVAL;
		goto unlock;
	}
J
Johannes Berg 已提交
2401 2402 2403 2404 2405 2406

	priv->_agn.offchan_tx_skb = NULL;

	ret = iwl_scan_cancel_timeout(priv, 200);
	if (ret)
		ret = -EIO;
2407
unlock:
J
Johannes Berg 已提交
2408 2409 2410 2411 2412
	mutex_unlock(&priv->mutex);

	return ret;
}

Z
Zhu Yi 已提交
2413 2414 2415 2416 2417 2418
/*****************************************************************************
 *
 * mac80211 entry point functions
 *
 *****************************************************************************/

2419 2420 2421 2422 2423 2424 2425 2426 2427 2428 2429 2430 2431 2432 2433 2434 2435 2436 2437 2438 2439 2440 2441 2442 2443 2444 2445 2446 2447 2448 2449 2450 2451 2452 2453 2454 2455 2456 2457 2458 2459 2460 2461 2462 2463 2464 2465 2466 2467 2468 2469 2470 2471 2472 2473 2474 2475 2476 2477 2478 2479 2480 2481 2482 2483 2484 2485 2486 2487 2488 2489
static const struct ieee80211_iface_limit iwlagn_sta_ap_limits[] = {
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_AP),
	},
};

static const struct ieee80211_iface_limit iwlagn_2sta_limits[] = {
	{
		.max = 2,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
};

static const struct ieee80211_iface_limit iwlagn_p2p_sta_go_limits[] = {
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_P2P_GO) |
			 BIT(NL80211_IFTYPE_AP),
	},
};

static const struct ieee80211_iface_limit iwlagn_p2p_2sta_limits[] = {
	{
		.max = 2,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_P2P_CLIENT),
	},
};

static const struct ieee80211_iface_combination
iwlagn_iface_combinations_dualmode[] = {
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .beacon_int_infra_match = true,
	  .limits = iwlagn_sta_ap_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_sta_ap_limits),
	},
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .limits = iwlagn_2sta_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_2sta_limits),
	},
};

static const struct ieee80211_iface_combination
iwlagn_iface_combinations_p2p[] = {
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .beacon_int_infra_match = true,
	  .limits = iwlagn_p2p_sta_go_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_p2p_sta_go_limits),
	},
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .limits = iwlagn_p2p_2sta_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_p2p_2sta_limits),
	},
};

2490 2491 2492 2493
/*
 * Not a mac80211 entry point function, but it fits in with all the
 * other mac80211 functions grouped here.
 */
2494 2495
static int iwl_mac_setup_register(struct iwl_priv *priv,
				  struct iwlagn_ucode_capabilities *capa)
2496 2497 2498
{
	int ret;
	struct ieee80211_hw *hw = priv->hw;
2499 2500
	struct iwl_rxon_context *ctx;

2501 2502 2503 2504 2505
	hw->rate_control_algorithm = "iwl-agn-rs";

	/* Tell mac80211 our characteristics */
	hw->flags = IEEE80211_HW_SIGNAL_DBM |
		    IEEE80211_HW_AMPDU_AGGREGATION |
2506
		    IEEE80211_HW_NEED_DTIM_PERIOD |
2507 2508
		    IEEE80211_HW_SPECTRUM_MGMT |
		    IEEE80211_HW_REPORTS_TX_ACK_STATUS;
2509

2510 2511
	hw->max_tx_aggregation_subframes = LINK_QUAL_AGG_FRAME_LIMIT_DEF;

2512 2513
	hw->flags |= IEEE80211_HW_SUPPORTS_PS |
		     IEEE80211_HW_SUPPORTS_DYNAMIC_PS;
2514

2515
	if (priv->cfg->sku & EEPROM_SKU_CAP_11N_ENABLE)
J
Johannes Berg 已提交
2516 2517 2518
		hw->flags |= IEEE80211_HW_SUPPORTS_DYNAMIC_SMPS |
			     IEEE80211_HW_SUPPORTS_STATIC_SMPS;

J
Johannes Berg 已提交
2519 2520 2521
	if (capa->flags & IWL_UCODE_TLV_FLAGS_MFP)
		hw->flags |= IEEE80211_HW_MFP_CAPABLE;

2522
	hw->sta_data_size = sizeof(struct iwl_station_priv);
J
Johannes Berg 已提交
2523 2524
	hw->vif_data_size = sizeof(struct iwl_vif_priv);

2525 2526 2527 2528
	for_each_context(priv, ctx) {
		hw->wiphy->interface_modes |= ctx->interface_modes;
		hw->wiphy->interface_modes |= ctx->exclusive_interface_modes;
	}
2529

2530 2531
	BUILD_BUG_ON(NUM_IWL_RXON_CTX != 2);

2532
	if (hw->wiphy->interface_modes & BIT(NL80211_IFTYPE_P2P_CLIENT)) {
2533 2534 2535
		hw->wiphy->iface_combinations = iwlagn_iface_combinations_p2p;
		hw->wiphy->n_iface_combinations =
			ARRAY_SIZE(iwlagn_iface_combinations_p2p);
2536
	} else if (hw->wiphy->interface_modes & BIT(NL80211_IFTYPE_AP)) {
2537 2538 2539 2540 2541
		hw->wiphy->iface_combinations = iwlagn_iface_combinations_dualmode;
		hw->wiphy->n_iface_combinations =
			ARRAY_SIZE(iwlagn_iface_combinations_dualmode);
	}

2542 2543
	hw->wiphy->max_remain_on_channel_duration = 1000;

R
Reinette Chatre 已提交
2544
	hw->wiphy->flags |= WIPHY_FLAG_CUSTOM_REGULATORY |
J
Johannes Berg 已提交
2545 2546
			    WIPHY_FLAG_DISABLE_BEACON_HINTS |
			    WIPHY_FLAG_IBSS_RSN;
2547

2548 2549 2550 2551
	if (iwlagn_mod_params.power_save)
		hw->wiphy->flags |= WIPHY_FLAG_PS_ON_BY_DEFAULT;
	else
		hw->wiphy->flags &= ~WIPHY_FLAG_PS_ON_BY_DEFAULT;
2552

2553
	hw->wiphy->max_scan_ssids = PROBE_OPTION_MAX;
2554
	/* we create the 802.11 header and a zero-length SSID element */
2555
	hw->wiphy->max_scan_ie_len = capa->max_probe_length - 24 - 2;
2556 2557 2558 2559 2560 2561 2562 2563 2564 2565 2566 2567 2568

	/* Default value; 4 EDCA QOS priorities */
	hw->queues = 4;

	hw->max_listen_interval = IWL_CONN_MAX_LISTEN_INTERVAL;

	if (priv->bands[IEEE80211_BAND_2GHZ].n_channels)
		priv->hw->wiphy->bands[IEEE80211_BAND_2GHZ] =
			&priv->bands[IEEE80211_BAND_2GHZ];
	if (priv->bands[IEEE80211_BAND_5GHZ].n_channels)
		priv->hw->wiphy->bands[IEEE80211_BAND_5GHZ] =
			&priv->bands[IEEE80211_BAND_5GHZ];

2569 2570
	iwl_leds_init(priv);

2571 2572 2573 2574 2575 2576 2577 2578 2579 2580 2581
	ret = ieee80211_register_hw(priv->hw);
	if (ret) {
		IWL_ERR(priv, "Failed to register hw (error %d)\n", ret);
		return ret;
	}
	priv->mac80211_registered = 1;

	return 0;
}


2582
static int iwlagn_mac_start(struct ieee80211_hw *hw)
Z
Zhu Yi 已提交
2583
{
2584
	struct iwl_priv *priv = hw->priv;
2585
	int ret;
Z
Zhu Yi 已提交
2586

2587
	IWL_DEBUG_MAC80211(priv, "enter\n");
Z
Zhu Yi 已提交
2588 2589 2590

	/* we should be verifying the device is ready to be opened */
	mutex_lock(&priv->mutex);
2591
	ret = __iwl_up(priv);
Z
Zhu Yi 已提交
2592
	mutex_unlock(&priv->mutex);
2593
	if (ret)
2594
		return ret;
2595

2596
	IWL_DEBUG_INFO(priv, "Start UP work done.\n");
2597

2598 2599 2600
	/* Now we should be done, and the READY bit should be set. */
	if (WARN_ON(!test_bit(STATUS_READY, &priv->status)))
		ret = -EIO;
T
Tomas Winkler 已提交
2601

2602
	iwlagn_led_enable(priv);
J
Johannes Berg 已提交
2603

T
Tomas Winkler 已提交
2604
	priv->is_open = 1;
2605
	IWL_DEBUG_MAC80211(priv, "leave\n");
Z
Zhu Yi 已提交
2606 2607 2608
	return 0;
}

2609
static void iwlagn_mac_stop(struct ieee80211_hw *hw)
Z
Zhu Yi 已提交
2610
{
2611
	struct iwl_priv *priv = hw->priv;
Z
Zhu Yi 已提交
2612

2613
	IWL_DEBUG_MAC80211(priv, "enter\n");
M
Mohamed Abbas 已提交
2614

J
Johannes Berg 已提交
2615
	if (!priv->is_open)
2616 2617
		return;

Z
Zhu Yi 已提交
2618
	priv->is_open = 0;
2619

2620
	iwl_down(priv);
2621 2622

	flush_workqueue(priv->workqueue);
2623

2624 2625
	/* User space software may expect getting rfkill changes
	 * even if interface is down */
2626
	iwl_write32(priv, CSR_INT, 0xFFFFFFFF);
2627
	iwl_enable_rfkill_int(priv);
M
Mohamed Abbas 已提交
2628

2629
	IWL_DEBUG_MAC80211(priv, "leave\n");
Z
Zhu Yi 已提交
2630 2631
}

2632
static void iwlagn_mac_tx(struct ieee80211_hw *hw, struct sk_buff *skb)
Z
Zhu Yi 已提交
2633
{
2634
	struct iwl_priv *priv = hw->priv;
Z
Zhu Yi 已提交
2635

2636
	IWL_DEBUG_MACDUMP(priv, "enter\n");
Z
Zhu Yi 已提交
2637

2638
	IWL_DEBUG_TX(priv, "dev->xmit(%d bytes) at rate 0x%02x\n", skb->len,
2639
		     ieee80211_get_tx_rate(hw, IEEE80211_SKB_CB(skb))->bitrate);
Z
Zhu Yi 已提交
2640

2641
	if (iwlagn_tx_skb(priv, skb))
Z
Zhu Yi 已提交
2642 2643
		dev_kfree_skb_any(skb);

2644
	IWL_DEBUG_MACDUMP(priv, "leave\n");
Z
Zhu Yi 已提交
2645 2646
}

2647 2648 2649 2650 2651
static void iwlagn_mac_update_tkip_key(struct ieee80211_hw *hw,
				       struct ieee80211_vif *vif,
				       struct ieee80211_key_conf *keyconf,
				       struct ieee80211_sta *sta,
				       u32 iv32, u16 *phase1key)
2652
{
2653
	struct iwl_priv *priv = hw->priv;
2654 2655
	struct iwl_vif_priv *vif_priv = (void *)vif->drv_priv;

2656
	IWL_DEBUG_MAC80211(priv, "enter\n");
2657

2658
	iwl_update_tkip_key(priv, vif_priv->ctx, keyconf, sta,
2659
			    iv32, phase1key);
2660

2661
	IWL_DEBUG_MAC80211(priv, "leave\n");
2662 2663
}

2664 2665 2666 2667
static int iwlagn_mac_set_key(struct ieee80211_hw *hw, enum set_key_cmd cmd,
			      struct ieee80211_vif *vif,
			      struct ieee80211_sta *sta,
			      struct ieee80211_key_conf *key)
Z
Zhu Yi 已提交
2668
{
2669
	struct iwl_priv *priv = hw->priv;
2670
	struct iwl_vif_priv *vif_priv = (void *)vif->drv_priv;
2671
	struct iwl_rxon_context *ctx = vif_priv->ctx;
2672 2673 2674
	int ret;
	u8 sta_id;
	bool is_default_wep_key = false;
Z
Zhu Yi 已提交
2675

2676
	IWL_DEBUG_MAC80211(priv, "enter\n");
Z
Zhu Yi 已提交
2677

D
Don Fry 已提交
2678
	if (iwlagn_mod_params.sw_crypto) {
2679
		IWL_DEBUG_MAC80211(priv, "leave - hwcrypto disabled\n");
Z
Zhu Yi 已提交
2680 2681 2682
		return -EOPNOTSUPP;
	}

J
Johannes Berg 已提交
2683 2684 2685 2686 2687 2688 2689 2690
	/*
	 * To support IBSS RSN, don't program group keys in IBSS, the
	 * hardware will then not attempt to decrypt the frames.
	 */
	if (vif->type == NL80211_IFTYPE_ADHOC &&
	    !(key->flags & IEEE80211_KEY_FLAG_PAIRWISE))
		return -EOPNOTSUPP;

2691
	sta_id = iwl_sta_id_or_broadcast(priv, vif_priv->ctx, sta);
2692 2693
	if (sta_id == IWL_INVALID_STATION)
		return -EINVAL;
Z
Zhu Yi 已提交
2694

2695
	mutex_lock(&priv->mutex);
2696
	iwl_scan_cancel_timeout(priv, 100);
2697

J
Johannes Berg 已提交
2698 2699
	/*
	 * If we are getting WEP group key and we didn't receive any key mapping
2700 2701
	 * so far, we are in legacy wep mode (group key only), otherwise we are
	 * in 1X mode.
J
Johannes Berg 已提交
2702 2703
	 * In legacy wep mode, we use another host command to the uCode.
	 */
2704 2705
	if ((key->cipher == WLAN_CIPHER_SUITE_WEP40 ||
	     key->cipher == WLAN_CIPHER_SUITE_WEP104) &&
2706
	    !sta) {
2707
		if (cmd == SET_KEY)
2708
			is_default_wep_key = !ctx->key_mapping_keys;
2709
		else
2710 2711
			is_default_wep_key =
					(key->hw_key_idx == HW_KEY_DEFAULT);
2712
	}
2713

Z
Zhu Yi 已提交
2714
	switch (cmd) {
2715
	case SET_KEY:
2716
		if (is_default_wep_key)
2717
			ret = iwl_set_default_wep_key(priv, vif_priv->ctx, key);
2718
		else
2719 2720
			ret = iwl_set_dynamic_key(priv, vif_priv->ctx,
						  key, sta_id);
2721

2722
		IWL_DEBUG_MAC80211(priv, "enable hwcrypto key\n");
Z
Zhu Yi 已提交
2723 2724
		break;
	case DISABLE_KEY:
2725
		if (is_default_wep_key)
2726
			ret = iwl_remove_default_wep_key(priv, ctx, key);
2727
		else
2728
			ret = iwl_remove_dynamic_key(priv, ctx, key, sta_id);
2729

2730
		IWL_DEBUG_MAC80211(priv, "disable hwcrypto key\n");
Z
Zhu Yi 已提交
2731 2732
		break;
	default:
2733
		ret = -EINVAL;
Z
Zhu Yi 已提交
2734 2735
	}

2736
	mutex_unlock(&priv->mutex);
2737
	IWL_DEBUG_MAC80211(priv, "leave\n");
Z
Zhu Yi 已提交
2738

2739
	return ret;
Z
Zhu Yi 已提交
2740 2741
}

2742 2743 2744 2745 2746
static int iwlagn_mac_ampdu_action(struct ieee80211_hw *hw,
				   struct ieee80211_vif *vif,
				   enum ieee80211_ampdu_mlme_action action,
				   struct ieee80211_sta *sta, u16 tid, u16 *ssn,
				   u8 buf_size)
2747 2748
{
	struct iwl_priv *priv = hw->priv;
2749
	int ret = -EINVAL;
2750
	struct iwl_station_priv *sta_priv = (void *) sta->drv_priv;
2751

2752
	IWL_DEBUG_HT(priv, "A-MPDU action on addr %pM tid %d\n",
J
Johannes Berg 已提交
2753
		     sta->addr, tid);
2754

2755
	if (!(priv->cfg->sku & EEPROM_SKU_CAP_11N_ENABLE))
2756 2757
		return -EACCES;

2758 2759
	mutex_lock(&priv->mutex);

2760 2761
	switch (action) {
	case IEEE80211_AMPDU_RX_START:
2762
		IWL_DEBUG_HT(priv, "start Rx\n");
2763 2764
		ret = iwl_sta_rx_agg_start(priv, sta, tid, *ssn);
		break;
2765
	case IEEE80211_AMPDU_RX_STOP:
2766
		IWL_DEBUG_HT(priv, "stop Rx\n");
2767
		ret = iwl_sta_rx_agg_stop(priv, sta, tid);
2768
		if (test_bit(STATUS_EXIT_PENDING, &priv->status))
2769 2770
			ret = 0;
		break;
2771
	case IEEE80211_AMPDU_TX_START:
2772
		IWL_DEBUG_HT(priv, "start Tx\n");
2773
		ret = iwlagn_tx_agg_start(priv, vif, sta, tid, ssn);
W
Wey-Yi Guy 已提交
2774 2775 2776 2777 2778
		if (ret == 0) {
			priv->_agn.agg_tids_count++;
			IWL_DEBUG_HT(priv, "priv->_agn.agg_tids_count = %u\n",
				     priv->_agn.agg_tids_count);
		}
2779
		break;
2780
	case IEEE80211_AMPDU_TX_STOP:
2781
		IWL_DEBUG_HT(priv, "stop Tx\n");
2782
		ret = iwlagn_tx_agg_stop(priv, vif, sta, tid);
W
Wey-Yi Guy 已提交
2783 2784 2785 2786 2787
		if ((ret == 0) && (priv->_agn.agg_tids_count > 0)) {
			priv->_agn.agg_tids_count--;
			IWL_DEBUG_HT(priv, "priv->_agn.agg_tids_count = %u\n",
				     priv->_agn.agg_tids_count);
		}
2788
		if (test_bit(STATUS_EXIT_PENDING, &priv->status))
2789
			ret = 0;
2790 2791
		if (priv->cfg->ht_params &&
		    priv->cfg->ht_params->use_rts_for_aggregation) {
J
Johannes Berg 已提交
2792 2793 2794 2795 2796
			/*
			 * switch off RTS/CTS if it was previously enabled
			 */
			sta_priv->lq_sta.lq.general_params.flags &=
				~LINK_QUAL_FLAGS_SET_STA_TLC_RTS_MSK;
2797 2798
			iwl_send_lq_cmd(priv, iwl_rxon_ctx_from_vif(vif),
					&sta_priv->lq_sta.lq, CMD_ASYNC, false);
J
Johannes Berg 已提交
2799
		}
2800
		break;
2801
	case IEEE80211_AMPDU_TX_OPERATIONAL:
2802 2803 2804 2805
		buf_size = min_t(int, buf_size, LINK_QUAL_AGG_FRAME_LIMIT_DEF);

		iwlagn_txq_agg_queue_setup(priv, sta, tid, buf_size);

2806 2807 2808 2809 2810 2811 2812 2813 2814 2815 2816 2817 2818 2819 2820 2821 2822 2823 2824 2825
		/*
		 * If the limit is 0, then it wasn't initialised yet,
		 * use the default. We can do that since we take the
		 * minimum below, and we don't want to go above our
		 * default due to hardware restrictions.
		 */
		if (sta_priv->max_agg_bufsize == 0)
			sta_priv->max_agg_bufsize =
				LINK_QUAL_AGG_FRAME_LIMIT_DEF;

		/*
		 * Even though in theory the peer could have different
		 * aggregation reorder buffer sizes for different sessions,
		 * our ucode doesn't allow for that and has a global limit
		 * for each station. Therefore, use the minimum of all the
		 * aggregation sessions and our default value.
		 */
		sta_priv->max_agg_bufsize =
			min(sta_priv->max_agg_bufsize, buf_size);

2826 2827
		if (priv->cfg->ht_params &&
		    priv->cfg->ht_params->use_rts_for_aggregation) {
2828 2829 2830 2831
			/*
			 * switch to RTS/CTS if it is the prefer protection
			 * method for HT traffic
			 */
J
Johannes Berg 已提交
2832 2833 2834

			sta_priv->lq_sta.lq.general_params.flags |=
				LINK_QUAL_FLAGS_SET_STA_TLC_RTS_MSK;
2835
		}
2836 2837 2838 2839 2840 2841

		sta_priv->lq_sta.lq.agg_params.agg_frame_cnt_limit =
			sta_priv->max_agg_bufsize;

		iwl_send_lq_cmd(priv, iwl_rxon_ctx_from_vif(vif),
				&sta_priv->lq_sta.lq, CMD_ASYNC, false);
2842 2843 2844

		IWL_INFO(priv, "Tx aggregation enabled on ra = %pM tid = %d\n",
			 sta->addr, tid);
2845
		ret = 0;
2846 2847
		break;
	}
2848 2849 2850
	mutex_unlock(&priv->mutex);

	return ret;
2851
}
2852

2853 2854 2855
static int iwlagn_mac_sta_add(struct ieee80211_hw *hw,
			      struct ieee80211_vif *vif,
			      struct ieee80211_sta *sta)
2856 2857 2858
{
	struct iwl_priv *priv = hw->priv;
	struct iwl_station_priv *sta_priv = (void *)sta->drv_priv;
2859
	struct iwl_vif_priv *vif_priv = (void *)vif->drv_priv;
2860
	bool is_ap = vif->type == NL80211_IFTYPE_STATION;
2861 2862 2863 2864 2865
	int ret;
	u8 sta_id;

	IWL_DEBUG_INFO(priv, "received request to add station %pM\n",
			sta->addr);
2866 2867 2868 2869
	mutex_lock(&priv->mutex);
	IWL_DEBUG_INFO(priv, "proceeding to add station %pM\n",
			sta->addr);
	sta_priv->common.sta_id = IWL_INVALID_STATION;
2870 2871 2872 2873 2874

	atomic_set(&sta_priv->pending_frames, 0);
	if (vif->type == NL80211_IFTYPE_AP)
		sta_priv->client = true;

2875
	ret = iwl_add_station_common(priv, vif_priv->ctx, sta->addr,
2876
				     is_ap, sta, &sta_id);
2877 2878 2879 2880
	if (ret) {
		IWL_ERR(priv, "Unable to add station %pM (%d)\n",
			sta->addr, ret);
		/* Should we return success if return code is EEXIST ? */
2881
		mutex_unlock(&priv->mutex);
2882 2883 2884
		return ret;
	}

J
Johannes Berg 已提交
2885 2886
	sta_priv->common.sta_id = sta_id;

2887
	/* Initialize rate scaling */
2888
	IWL_DEBUG_INFO(priv, "Initializing rate scaling for station %pM\n",
2889 2890
		       sta->addr);
	iwl_rs_rate_init(priv, sta, sta_id);
2891
	mutex_unlock(&priv->mutex);
2892

J
Johannes Berg 已提交
2893
	return 0;
2894 2895
}

2896 2897
static void iwlagn_mac_channel_switch(struct ieee80211_hw *hw,
				struct ieee80211_channel_switch *ch_switch)
2898 2899 2900 2901
{
	struct iwl_priv *priv = hw->priv;
	const struct iwl_channel_info *ch_info;
	struct ieee80211_conf *conf = &hw->conf;
2902
	struct ieee80211_channel *channel = ch_switch->channel;
2903
	struct iwl_ht_config *ht_conf = &priv->current_ht_config;
2904 2905 2906 2907 2908 2909 2910 2911 2912
	/*
	 * MULTI-FIXME
	 * When we add support for multiple interfaces, we need to
	 * revisit this. The channel switch command in the device
	 * only affects the BSS context, but what does that really
	 * mean? And what if we get a CSA on the second interface?
	 * This needs a lot of work.
	 */
	struct iwl_rxon_context *ctx = &priv->contexts[IWL_RXON_CTX_BSS];
2913 2914 2915 2916
	u16 ch;

	IWL_DEBUG_MAC80211(priv, "enter\n");

2917 2918
	mutex_lock(&priv->mutex);

2919
	if (iwl_is_rfkill(priv))
2920
		goto out;
2921 2922

	if (test_bit(STATUS_EXIT_PENDING, &priv->status) ||
2923 2924
	    test_bit(STATUS_SCANNING, &priv->status) ||
	    test_bit(STATUS_CHANNEL_SWITCH_PENDING, &priv->status))
2925
		goto out;
2926

2927
	if (!iwl_is_associated_ctx(ctx))
2928
		goto out;
2929

2930 2931
	if (!priv->cfg->ops->lib->set_channel_switch)
		goto out;
2932

2933 2934 2935 2936 2937 2938 2939 2940 2941
	ch = channel->hw_value;
	if (le16_to_cpu(ctx->active.channel) == ch)
		goto out;

	ch_info = iwl_get_channel_info(priv, channel->band, ch);
	if (!is_channel_valid(ch_info)) {
		IWL_DEBUG_MAC80211(priv, "invalid channel\n");
		goto out;
	}
2942

2943
	spin_lock_irq(&priv->lock);
2944

2945
	priv->current_ht_config.smps = conf->smps_mode;
2946

2947 2948 2949 2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961
	/* Configure HT40 channels */
	ctx->ht.enabled = conf_is_ht(conf);
	if (ctx->ht.enabled) {
		if (conf_is_ht40_minus(conf)) {
			ctx->ht.extension_chan_offset =
				IEEE80211_HT_PARAM_CHA_SEC_BELOW;
			ctx->ht.is_40mhz = true;
		} else if (conf_is_ht40_plus(conf)) {
			ctx->ht.extension_chan_offset =
				IEEE80211_HT_PARAM_CHA_SEC_ABOVE;
			ctx->ht.is_40mhz = true;
		} else {
			ctx->ht.extension_chan_offset =
				IEEE80211_HT_PARAM_CHA_SEC_NONE;
			ctx->ht.is_40mhz = false;
2962
		}
2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975 2976 2977 2978 2979 2980 2981 2982 2983 2984 2985
	} else
		ctx->ht.is_40mhz = false;

	if ((le16_to_cpu(ctx->staging.channel) != ch))
		ctx->staging.flags = 0;

	iwl_set_rxon_channel(priv, channel, ctx);
	iwl_set_rxon_ht(priv, ht_conf);
	iwl_set_flags_for_band(priv, ctx, channel->band, ctx->vif);

	spin_unlock_irq(&priv->lock);

	iwl_set_rate(priv);
	/*
	 * at this point, staging_rxon has the
	 * configuration for channel switch
	 */
	set_bit(STATUS_CHANNEL_SWITCH_PENDING, &priv->status);
	priv->switch_channel = cpu_to_le16(ch);
	if (priv->cfg->ops->lib->set_channel_switch(priv, ch_switch)) {
		clear_bit(STATUS_CHANNEL_SWITCH_PENDING, &priv->status);
		priv->switch_channel = 0;
		ieee80211_chswitch_done(ctx->vif, false);
2986
	}
2987

2988 2989 2990 2991 2992
out:
	mutex_unlock(&priv->mutex);
	IWL_DEBUG_MAC80211(priv, "leave\n");
}

2993 2994 2995 2996
static void iwlagn_configure_filter(struct ieee80211_hw *hw,
				    unsigned int changed_flags,
				    unsigned int *total_flags,
				    u64 multicast)
J
Johannes Berg 已提交
2997 2998 2999
{
	struct iwl_priv *priv = hw->priv;
	__le32 filter_or = 0, filter_nand = 0;
3000
	struct iwl_rxon_context *ctx;
J
Johannes Berg 已提交
3001 3002 3003 3004 3005 3006 3007 3008 3009 3010 3011 3012

#define CHK(test, flag)	do { \
	if (*total_flags & (test))		\
		filter_or |= (flag);		\
	else					\
		filter_nand |= (flag);		\
	} while (0)

	IWL_DEBUG_MAC80211(priv, "Enter: changed: 0x%x, total: 0x%x\n",
			changed_flags, *total_flags);

	CHK(FIF_OTHER_BSS | FIF_PROMISC_IN_BSS, RXON_FILTER_PROMISC_MSK);
J
Johannes Berg 已提交
3013 3014
	/* Setting _just_ RXON_FILTER_CTL2HOST_MSK causes FH errors */
	CHK(FIF_CONTROL, RXON_FILTER_CTL2HOST_MSK | RXON_FILTER_PROMISC_MSK);
J
Johannes Berg 已提交
3015 3016 3017 3018 3019 3020
	CHK(FIF_BCN_PRBRESP_PROMISC, RXON_FILTER_BCON_AWARE_MSK);

#undef CHK

	mutex_lock(&priv->mutex);

3021 3022 3023
	for_each_context(priv, ctx) {
		ctx->staging.filter_flags &= ~filter_nand;
		ctx->staging.filter_flags |= filter_or;
3024 3025 3026 3027 3028

		/*
		 * Not committing directly because hardware can perform a scan,
		 * but we'll eventually commit the filter flags change anyway.
		 */
3029
	}
J
Johannes Berg 已提交
3030 3031 3032 3033 3034 3035 3036 3037 3038 3039 3040 3041 3042

	mutex_unlock(&priv->mutex);

	/*
	 * Receiving all multicast frames is always enabled by the
	 * default flags setup in iwl_connection_init_rx_config()
	 * since we currently do not support programming multicast
	 * filters into the device.
	 */
	*total_flags &= FIF_OTHER_BSS | FIF_ALLMULTI | FIF_PROMISC_IN_BSS |
			FIF_BCN_PRBRESP_PROMISC | FIF_CONTROL;
}

3043
static void iwlagn_mac_flush(struct ieee80211_hw *hw, bool drop)
3044 3045 3046 3047 3048 3049 3050 3051 3052 3053 3054 3055 3056 3057 3058 3059 3060 3061 3062 3063 3064
{
	struct iwl_priv *priv = hw->priv;

	mutex_lock(&priv->mutex);
	IWL_DEBUG_MAC80211(priv, "enter\n");

	if (test_bit(STATUS_EXIT_PENDING, &priv->status)) {
		IWL_DEBUG_TX(priv, "Aborting flush due to device shutdown\n");
		goto done;
	}
	if (iwl_is_rfkill(priv)) {
		IWL_DEBUG_TX(priv, "Aborting flush due to RF Kill\n");
		goto done;
	}

	/*
	 * mac80211 will not push any more frames for transmit
	 * until the flush is completed
	 */
	if (drop) {
		IWL_DEBUG_MAC80211(priv, "send flush command\n");
3065
		if (iwlagn_txfifo_flush(priv, IWL_DROP_ALL)) {
3066 3067 3068 3069 3070 3071 3072 3073 3074 3075 3076
			IWL_ERR(priv, "flush request fail\n");
			goto done;
		}
	}
	IWL_DEBUG_MAC80211(priv, "wait transmit/flush all frames\n");
	iwlagn_wait_tx_queue_empty(priv);
done:
	mutex_unlock(&priv->mutex);
	IWL_DEBUG_MAC80211(priv, "leave\n");
}

3077 3078 3079 3080 3081 3082 3083 3084 3085 3086 3087 3088 3089 3090 3091 3092 3093
static void iwlagn_disable_roc(struct iwl_priv *priv)
{
	struct iwl_rxon_context *ctx = &priv->contexts[IWL_RXON_CTX_PAN];
	struct ieee80211_channel *chan = ACCESS_ONCE(priv->hw->conf.channel);

	lockdep_assert_held(&priv->mutex);

	if (!ctx->is_active)
		return;

	ctx->staging.dev_type = RXON_DEV_TYPE_2STA;
	ctx->staging.filter_flags &= ~RXON_FILTER_ASSOC_MSK;
	iwl_set_rxon_channel(priv, chan, ctx);
	iwl_set_flags_for_band(priv, ctx, chan->band, NULL);

	priv->_agn.hw_roc_channel = NULL;

3094
	iwlagn_commit_rxon(priv, ctx);
3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105 3106 3107 3108 3109 3110 3111 3112 3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123 3124 3125 3126 3127 3128 3129 3130 3131 3132 3133 3134 3135 3136

	ctx->is_active = false;
}

static void iwlagn_bg_roc_done(struct work_struct *work)
{
	struct iwl_priv *priv = container_of(work, struct iwl_priv,
					     _agn.hw_roc_work.work);

	mutex_lock(&priv->mutex);
	ieee80211_remain_on_channel_expired(priv->hw);
	iwlagn_disable_roc(priv);
	mutex_unlock(&priv->mutex);
}

static int iwl_mac_remain_on_channel(struct ieee80211_hw *hw,
				     struct ieee80211_channel *channel,
				     enum nl80211_channel_type channel_type,
				     int duration)
{
	struct iwl_priv *priv = hw->priv;
	int err = 0;

	if (!(priv->valid_contexts & BIT(IWL_RXON_CTX_PAN)))
		return -EOPNOTSUPP;

	if (!(priv->contexts[IWL_RXON_CTX_PAN].interface_modes &
					BIT(NL80211_IFTYPE_P2P_CLIENT)))
		return -EOPNOTSUPP;

	mutex_lock(&priv->mutex);

	if (priv->contexts[IWL_RXON_CTX_PAN].is_active ||
	    test_bit(STATUS_SCAN_HW, &priv->status)) {
		err = -EBUSY;
		goto out;
	}

	priv->contexts[IWL_RXON_CTX_PAN].is_active = true;
	priv->_agn.hw_roc_channel = channel;
	priv->_agn.hw_roc_chantype = channel_type;
	priv->_agn.hw_roc_duration = DIV_ROUND_UP(duration * 1000, 1024);
3137
	iwlagn_commit_rxon(priv, &priv->contexts[IWL_RXON_CTX_PAN]);
3138 3139 3140
	queue_delayed_work(priv->workqueue, &priv->_agn.hw_roc_work,
			   msecs_to_jiffies(duration + 20));

3141
	msleep(IWL_MIN_SLOT_TIME); /* TU is almost ms */
3142 3143 3144 3145 3146 3147 3148 3149 3150 3151 3152 3153 3154 3155 3156 3157 3158 3159 3160 3161 3162 3163 3164 3165
	ieee80211_ready_on_channel(priv->hw);

 out:
	mutex_unlock(&priv->mutex);

	return err;
}

static int iwl_mac_cancel_remain_on_channel(struct ieee80211_hw *hw)
{
	struct iwl_priv *priv = hw->priv;

	if (!(priv->valid_contexts & BIT(IWL_RXON_CTX_PAN)))
		return -EOPNOTSUPP;

	cancel_delayed_work_sync(&priv->_agn.hw_roc_work);

	mutex_lock(&priv->mutex);
	iwlagn_disable_roc(priv);
	mutex_unlock(&priv->mutex);

	return 0;
}

Z
Zhu Yi 已提交
3166 3167 3168 3169 3170 3171
/*****************************************************************************
 *
 * driver setup and teardown
 *
 *****************************************************************************/

3172
static void iwl_setup_deferred_work(struct iwl_priv *priv)
Z
Zhu Yi 已提交
3173
{
3174
	priv->workqueue = create_singlethread_workqueue(DRV_NAME);
Z
Zhu Yi 已提交
3175 3176 3177

	init_waitqueue_head(&priv->wait_command_queue);

3178 3179 3180
	INIT_WORK(&priv->restart, iwl_bg_restart);
	INIT_WORK(&priv->rx_replenish, iwl_bg_rx_replenish);
	INIT_WORK(&priv->beacon_update, iwl_bg_beacon_update);
3181
	INIT_WORK(&priv->run_time_calib_work, iwl_bg_run_time_calib_work);
3182
	INIT_WORK(&priv->tx_flush, iwl_bg_tx_flush);
3183
	INIT_WORK(&priv->bt_full_concurrency, iwl_bg_bt_full_concurrency);
3184
	INIT_WORK(&priv->bt_runtime_config, iwl_bg_bt_runtime_config);
3185
	INIT_DELAYED_WORK(&priv->_agn.hw_roc_work, iwlagn_bg_roc_done);
3186 3187

	iwl_setup_scan_deferred_work(priv);
C
Christoph Hellwig 已提交
3188

3189 3190 3191 3192 3193
	if (priv->cfg->ops->lib->setup_deferred_work)
		priv->cfg->ops->lib->setup_deferred_work(priv);

	init_timer(&priv->statistics_periodic);
	priv->statistics_periodic.data = (unsigned long)priv;
3194
	priv->statistics_periodic.function = iwl_bg_statistics_periodic;
Z
Zhu Yi 已提交
3195

3196 3197 3198 3199
	init_timer(&priv->ucode_trace);
	priv->ucode_trace.data = (unsigned long)priv;
	priv->ucode_trace.function = iwl_bg_ucode_trace;

3200 3201 3202
	init_timer(&priv->watchdog);
	priv->watchdog.data = (unsigned long)priv;
	priv->watchdog.function = iwl_bg_watchdog;
3203

W
Wey-Yi Guy 已提交
3204 3205
	tasklet_init(&priv->irq_tasklet, (void (*)(unsigned long))
		iwl_irq_tasklet, (unsigned long)priv);
Z
Zhu Yi 已提交
3206 3207
}

3208
static void iwl_cancel_deferred_work(struct iwl_priv *priv)
Z
Zhu Yi 已提交
3209
{
3210 3211
	if (priv->cfg->ops->lib->cancel_deferred_work)
		priv->cfg->ops->lib->cancel_deferred_work(priv);
Z
Zhu Yi 已提交
3212

3213
	cancel_work_sync(&priv->run_time_calib_work);
Z
Zhu Yi 已提交
3214
	cancel_work_sync(&priv->beacon_update);
3215 3216 3217

	iwl_cancel_scan_deferred_work(priv);

3218
	cancel_work_sync(&priv->bt_full_concurrency);
3219
	cancel_work_sync(&priv->bt_runtime_config);
3220

3221
	del_timer_sync(&priv->statistics_periodic);
3222
	del_timer_sync(&priv->ucode_trace);
Z
Zhu Yi 已提交
3223 3224
}

3225 3226 3227 3228 3229 3230 3231 3232 3233 3234 3235 3236 3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254 3255 3256 3257 3258 3259
static void iwl_init_hw_rates(struct iwl_priv *priv,
			      struct ieee80211_rate *rates)
{
	int i;

	for (i = 0; i < IWL_RATE_COUNT_LEGACY; i++) {
		rates[i].bitrate = iwl_rates[i].ieee * 5;
		rates[i].hw_value = i; /* Rate scaling will work on indexes */
		rates[i].hw_value_short = i;
		rates[i].flags = 0;
		if ((i >= IWL_FIRST_CCK_RATE) && (i <= IWL_LAST_CCK_RATE)) {
			/*
			 * If CCK != 1M then set short preamble rate flag.
			 */
			rates[i].flags |=
				(iwl_rates[i].plcp == IWL_RATE_1M_PLCP) ?
					0 : IEEE80211_RATE_SHORT_PREAMBLE;
		}
	}
}

static int iwl_init_drv(struct iwl_priv *priv)
{
	int ret;

	spin_lock_init(&priv->sta_lock);
	spin_lock_init(&priv->hcmd_lock);

	mutex_init(&priv->mutex);

	priv->ieee_channels = NULL;
	priv->ieee_rates = NULL;
	priv->band = IEEE80211_BAND_2GHZ;

	priv->iw_mode = NL80211_IFTYPE_STATION;
J
Johannes Berg 已提交
3260
	priv->current_ht_config.smps = IEEE80211_SMPS_STATIC;
3261
	priv->missed_beacon_threshold = IWL_MISSED_BEACON_THRESHOLD_DEF;
W
Wey-Yi Guy 已提交
3262
	priv->_agn.agg_tids_count = 0;
3263

3264 3265 3266 3267 3268
	/* initialize force reset */
	priv->force_reset[IWL_RF_RESET].reset_duration =
		IWL_DELAY_NEXT_FORCE_RF_RESET;
	priv->force_reset[IWL_FW_RESET].reset_duration =
		IWL_DELAY_NEXT_FORCE_FW_RELOAD;
3269

3270 3271
	priv->rx_statistics_jiffies = jiffies;

3272 3273
	/* Choose which receivers/antennas to use */
	if (priv->cfg->ops->hcmd->set_rxon_chain)
3274 3275
		priv->cfg->ops->hcmd->set_rxon_chain(priv,
					&priv->contexts[IWL_RXON_CTX_BSS]);
3276 3277 3278

	iwl_init_scan_params(priv);

3279
	/* init bt coex */
3280 3281
	if (priv->cfg->bt_params &&
	    priv->cfg->bt_params->advanced_bt_coexist) {
W
Wey-Yi Guy 已提交
3282 3283 3284
		priv->kill_ack_mask = IWLAGN_BT_KILL_ACK_MASK_DEFAULT;
		priv->kill_cts_mask = IWLAGN_BT_KILL_CTS_MASK_DEFAULT;
		priv->bt_valid = IWLAGN_BT_ALL_VALID_MSK;
3285 3286 3287 3288 3289
		priv->bt_on_thresh = BT_ON_THRESHOLD_DEF;
		priv->bt_duration = BT_DURATION_LIMIT_DEF;
		priv->dynamic_frag_thresh = BT_FRAG_THRESHOLD_DEF;
	}

3290 3291 3292 3293 3294 3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305 3306 3307 3308 3309 3310 3311 3312 3313 3314 3315
	ret = iwl_init_channel_map(priv);
	if (ret) {
		IWL_ERR(priv, "initializing regulatory failed: %d\n", ret);
		goto err;
	}

	ret = iwlcore_init_geos(priv);
	if (ret) {
		IWL_ERR(priv, "initializing geos failed: %d\n", ret);
		goto err_free_channel_map;
	}
	iwl_init_hw_rates(priv, priv->ieee_rates);

	return 0;

err_free_channel_map:
	iwl_free_channel_map(priv);
err:
	return ret;
}

static void iwl_uninit_drv(struct iwl_priv *priv)
{
	iwl_calib_free_results(priv);
	iwlcore_free_geos(priv);
	iwl_free_channel_map(priv);
3316
	kfree(priv->scan_cmd);
3317
	kfree(priv->beacon_cmd);
3318 3319
}

3320
struct ieee80211_ops iwlagn_hw_ops = {
3321 3322 3323
	.tx = iwlagn_mac_tx,
	.start = iwlagn_mac_start,
	.stop = iwlagn_mac_stop,
3324 3325
	.add_interface = iwl_mac_add_interface,
	.remove_interface = iwl_mac_remove_interface,
3326
	.change_interface = iwl_mac_change_interface,
3327
	.config = iwlagn_mac_config,
J
Johannes Berg 已提交
3328
	.configure_filter = iwlagn_configure_filter,
3329 3330
	.set_key = iwlagn_mac_set_key,
	.update_tkip_key = iwlagn_mac_update_tkip_key,
3331
	.conf_tx = iwl_mac_conf_tx,
3332 3333
	.bss_info_changed = iwlagn_bss_info_changed,
	.ampdu_action = iwlagn_mac_ampdu_action,
3334
	.hw_scan = iwl_mac_hw_scan,
3335
	.sta_notify = iwlagn_mac_sta_notify,
3336 3337
	.sta_add = iwlagn_mac_sta_add,
	.sta_remove = iwl_mac_sta_remove,
3338 3339
	.channel_switch = iwlagn_mac_channel_switch,
	.flush = iwlagn_mac_flush,
3340
	.tx_last_beacon = iwl_mac_tx_last_beacon,
3341 3342
	.remain_on_channel = iwl_mac_remain_on_channel,
	.cancel_remain_on_channel = iwl_mac_cancel_remain_on_channel,
J
Johannes Berg 已提交
3343 3344
	.offchannel_tx = iwl_mac_offchannel_tx,
	.offchannel_tx_cancel_wait = iwl_mac_offchannel_tx_cancel_wait,
3345
	CFG80211_TESTMODE_CMD(iwl_testmode_cmd)
3346
	CFG80211_TESTMODE_DUMP(iwl_testmode_dump)
Z
Zhu Yi 已提交
3347 3348
};

J
Johannes Berg 已提交
3349
static u32 iwl_hw_detect(struct iwl_priv *priv)
3350
{
3351
	return iwl_read32(priv, CSR_HW_REV);
3352 3353
}

3354 3355 3356 3357
static int iwl_set_hw_params(struct iwl_priv *priv)
{
	priv->hw_params.max_rxq_size = RX_QUEUE_SIZE;
	priv->hw_params.max_rxq_log = RX_QUEUE_SIZE_LOG;
D
Don Fry 已提交
3358
	if (iwlagn_mod_params.amsdu_size_8K)
3359 3360 3361 3362 3363 3364
		priv->hw_params.rx_page_order = get_order(IWL_RX_BUF_SIZE_8K);
	else
		priv->hw_params.rx_page_order = get_order(IWL_RX_BUF_SIZE_4K);

	priv->hw_params.max_beacon_itrvl = IWL_MAX_UCODE_BEACON_INTERVAL;

D
Don Fry 已提交
3365
	if (iwlagn_mod_params.disable_11n)
3366
		priv->cfg->sku &= ~EEPROM_SKU_CAP_11N_ENABLE;
3367 3368 3369 3370 3371

	/* Device-specific setup */
	return priv->cfg->ops->lib->set_hw_params(priv);
}

3372 3373 3374 3375 3376 3377 3378 3379 3380 3381 3382 3383 3384 3385 3386 3387 3388 3389 3390 3391 3392 3393
static const u8 iwlagn_bss_ac_to_fifo[] = {
	IWL_TX_FIFO_VO,
	IWL_TX_FIFO_VI,
	IWL_TX_FIFO_BE,
	IWL_TX_FIFO_BK,
};

static const u8 iwlagn_bss_ac_to_queue[] = {
	0, 1, 2, 3,
};

static const u8 iwlagn_pan_ac_to_fifo[] = {
	IWL_TX_FIFO_VO_IPAN,
	IWL_TX_FIFO_VI_IPAN,
	IWL_TX_FIFO_BE_IPAN,
	IWL_TX_FIFO_BK_IPAN,
};

static const u8 iwlagn_pan_ac_to_queue[] = {
	7, 6, 5, 4,
};

3394 3395 3396 3397 3398 3399 3400 3401 3402 3403 3404 3405 3406 3407 3408 3409 3410 3411 3412 3413 3414 3415
/* This function both allocates and initializes hw and priv. */
static struct ieee80211_hw *iwl_alloc_all(struct iwl_cfg *cfg)
{
	struct iwl_priv *priv;
	/* mac80211 allocates memory for this device instance, including
	 *   space for this driver's private structure */
	struct ieee80211_hw *hw;

	hw = ieee80211_alloc_hw(sizeof(struct iwl_priv), &iwlagn_hw_ops);
	if (hw == NULL) {
		pr_err("%s: Can not allocate network device\n",
		       cfg->name);
		goto out;
	}

	priv = hw->priv;
	priv->hw = hw;

out:
	return hw;
}

3416
static void iwl_init_context(struct iwl_priv *priv)
Z
Zhu Yi 已提交
3417
{
3418
	int i;
3419

3420 3421 3422 3423 3424 3425 3426 3427 3428 3429
	/*
	 * The default context is always valid,
	 * more may be discovered when firmware
	 * is loaded.
	 */
	priv->valid_contexts = BIT(IWL_RXON_CTX_BSS);

	for (i = 0; i < NUM_IWL_RXON_CTX; i++)
		priv->contexts[i].ctxid = i;

3430 3431
	priv->contexts[IWL_RXON_CTX_BSS].always_active = true;
	priv->contexts[IWL_RXON_CTX_BSS].is_active = true;
3432 3433 3434
	priv->contexts[IWL_RXON_CTX_BSS].rxon_cmd = REPLY_RXON;
	priv->contexts[IWL_RXON_CTX_BSS].rxon_timing_cmd = REPLY_RXON_TIMING;
	priv->contexts[IWL_RXON_CTX_BSS].rxon_assoc_cmd = REPLY_RXON_ASSOC;
J
Johannes Berg 已提交
3435
	priv->contexts[IWL_RXON_CTX_BSS].qos_cmd = REPLY_QOS_PARAM;
3436
	priv->contexts[IWL_RXON_CTX_BSS].ap_sta_id = IWL_AP_ID;
3437
	priv->contexts[IWL_RXON_CTX_BSS].wep_key_cmd = REPLY_WEPKEY;
3438 3439
	priv->contexts[IWL_RXON_CTX_BSS].ac_to_fifo = iwlagn_bss_ac_to_fifo;
	priv->contexts[IWL_RXON_CTX_BSS].ac_to_queue = iwlagn_bss_ac_to_queue;
3440 3441 3442 3443
	priv->contexts[IWL_RXON_CTX_BSS].exclusive_interface_modes =
		BIT(NL80211_IFTYPE_ADHOC);
	priv->contexts[IWL_RXON_CTX_BSS].interface_modes =
		BIT(NL80211_IFTYPE_STATION);
3444
	priv->contexts[IWL_RXON_CTX_BSS].ap_devtype = RXON_DEV_TYPE_AP;
3445 3446 3447
	priv->contexts[IWL_RXON_CTX_BSS].ibss_devtype = RXON_DEV_TYPE_IBSS;
	priv->contexts[IWL_RXON_CTX_BSS].station_devtype = RXON_DEV_TYPE_ESS;
	priv->contexts[IWL_RXON_CTX_BSS].unused_devtype = RXON_DEV_TYPE_ESS;
J
Johannes Berg 已提交
3448 3449

	priv->contexts[IWL_RXON_CTX_PAN].rxon_cmd = REPLY_WIPAN_RXON;
3450 3451 3452 3453
	priv->contexts[IWL_RXON_CTX_PAN].rxon_timing_cmd =
		REPLY_WIPAN_RXON_TIMING;
	priv->contexts[IWL_RXON_CTX_PAN].rxon_assoc_cmd =
		REPLY_WIPAN_RXON_ASSOC;
J
Johannes Berg 已提交
3454 3455 3456 3457 3458
	priv->contexts[IWL_RXON_CTX_PAN].qos_cmd = REPLY_WIPAN_QOS_PARAM;
	priv->contexts[IWL_RXON_CTX_PAN].ap_sta_id = IWL_AP_ID_PAN;
	priv->contexts[IWL_RXON_CTX_PAN].wep_key_cmd = REPLY_WIPAN_WEPKEY;
	priv->contexts[IWL_RXON_CTX_PAN].bcast_sta_id = IWLAGN_PAN_BCAST_ID;
	priv->contexts[IWL_RXON_CTX_PAN].station_flags = STA_FLG_PAN_STATION;
3459 3460 3461
	priv->contexts[IWL_RXON_CTX_PAN].ac_to_fifo = iwlagn_pan_ac_to_fifo;
	priv->contexts[IWL_RXON_CTX_PAN].ac_to_queue = iwlagn_pan_ac_to_queue;
	priv->contexts[IWL_RXON_CTX_PAN].mcast_queue = IWL_IPAN_MCAST_QUEUE;
3462 3463
	priv->contexts[IWL_RXON_CTX_PAN].interface_modes =
		BIT(NL80211_IFTYPE_STATION) | BIT(NL80211_IFTYPE_AP);
W
Wey-Yi Guy 已提交
3464 3465 3466 3467
#ifdef CONFIG_IWL_P2P
	priv->contexts[IWL_RXON_CTX_PAN].interface_modes |=
		BIT(NL80211_IFTYPE_P2P_CLIENT) | BIT(NL80211_IFTYPE_P2P_GO);
#endif
3468 3469 3470
	priv->contexts[IWL_RXON_CTX_PAN].ap_devtype = RXON_DEV_TYPE_CP;
	priv->contexts[IWL_RXON_CTX_PAN].station_devtype = RXON_DEV_TYPE_2STA;
	priv->contexts[IWL_RXON_CTX_PAN].unused_devtype = RXON_DEV_TYPE_P2P;
J
Johannes Berg 已提交
3471 3472

	BUILD_BUG_ON(NUM_IWL_RXON_CTX != 2);
3473 3474
}

3475 3476
int iwl_probe(void *bus_specific, struct iwl_bus_ops *bus_ops,
		struct iwl_cfg *cfg)
3477 3478 3479 3480
{
	int err = 0;
	struct iwl_priv *priv;
	struct ieee80211_hw *hw;
3481
	u16 num_mac;
3482 3483 3484 3485 3486 3487 3488 3489
	u32 hw_rev;

	/************************
	 * 1. Allocating HW data
	 ************************/
	hw = iwl_alloc_all(cfg);
	if (!hw) {
		err = -ENOMEM;
3490 3491 3492
		goto out;
	}

3493
	priv = hw->priv;
3494 3495 3496 3497

	priv->bus.priv = priv;
	priv->bus.bus_specific = bus_specific;
	priv->bus.ops = bus_ops;
3498
	priv->bus.irq = priv->bus.ops->get_irq(&priv->bus);
3499
	priv->bus.ops->set_drv_data(&priv->bus, priv);
3500
	priv->bus.dev = priv->bus.ops->get_dev(&priv->bus);
3501

3502
	/* At this point both hw and priv are allocated. */
3503

3504
	SET_IEEE80211_DEV(hw, priv->bus.dev);
Z
Zhu Yi 已提交
3505

3506
	IWL_DEBUG_INFO(priv, "*** LOAD DRIVER ***\n");
T
Tomas Winkler 已提交
3507
	priv->cfg = cfg;
3508
	priv->inta_mask = CSR_INI_SET_MASK;
3509

3510 3511 3512 3513 3514
	/* is antenna coupling more than 35dB ? */
	priv->bt_ant_couple_ok =
		(iwlagn_ant_coupling > IWL_BT_ANTENNA_COUPLING_THRESHOLD) ?
		true : false;

3515
	/* enable/disable bt channel inhibition */
3516
	priv->bt_ch_announce = iwlagn_bt_ch_announce;
3517 3518
	IWL_DEBUG_INFO(priv, "BT channel inhibition is %s\n",
		       (priv->bt_ch_announce) ? "On" : "Off");
3519

3520 3521
	if (iwl_alloc_traffic_mem(priv))
		IWL_ERR(priv, "Not enough memory to generate traffic log\n");
Z
Zhu Yi 已提交
3522

3523

3524
	/* these spin locks will be used in apm_ops.init and EEPROM access
M
Mohamed Abbas 已提交
3525 3526 3527
	 * we should init now
	 */
	spin_lock_init(&priv->reg_lock);
3528
	spin_lock_init(&priv->lock);
3529 3530 3531 3532 3533 3534 3535 3536

	/*
	 * stop and reset the on-board processor just in case it is in a
	 * strange state ... like being left stranded by a primary kernel
	 * and this is now the kdump kernel trying to start up
	 */
	iwl_write32(priv, CSR_RESET, CSR_RESET_REG_FLAG_NEVO_RESET);

3537 3538 3539
	/***********************
	 * 3. Read REV register
	 ***********************/
J
Johannes Berg 已提交
3540
	hw_rev = iwl_hw_detect(priv);
3541
	IWL_INFO(priv, "Detected %s, REV=0x%X\n",
J
Johannes Berg 已提交
3542
		priv->cfg->name, hw_rev);
3543

J
Johannes Berg 已提交
3544
	if (iwl_prepare_card_hw(priv)) {
3545
		err = -EIO;
M
Mohamed Abbas 已提交
3546
		IWL_WARN(priv, "Failed, HW not ready\n");
3547
		goto out_free_traffic_mem;
M
Mohamed Abbas 已提交
3548 3549
	}

T
Tomas Winkler 已提交
3550 3551 3552
	/*****************
	 * 4. Read EEPROM
	 *****************/
3553
	/* Read the EEPROM */
J
Johannes Berg 已提交
3554
	err = iwl_eeprom_init(priv, hw_rev);
3555
	if (err) {
3556
		IWL_ERR(priv, "Unable to init EEPROM\n");
3557
		goto out_free_traffic_mem;
3558
	}
3559 3560
	err = iwl_eeprom_check_version(priv);
	if (err)
3561
		goto out_free_eeprom;
3562

3563 3564 3565 3566
	err = iwl_eeprom_check_sku(priv);
	if (err)
		goto out_free_eeprom;

3567
	/* extract MAC Address */
3568 3569 3570 3571 3572 3573 3574 3575 3576 3577 3578
	iwl_eeprom_get_mac(priv, priv->addresses[0].addr);
	IWL_DEBUG_INFO(priv, "MAC address: %pM\n", priv->addresses[0].addr);
	priv->hw->wiphy->addresses = priv->addresses;
	priv->hw->wiphy->n_addresses = 1;
	num_mac = iwl_eeprom_query16(priv, EEPROM_NUM_MAC_ADDRESS);
	if (num_mac > 1) {
		memcpy(priv->addresses[1].addr, priv->addresses[0].addr,
		       ETH_ALEN);
		priv->addresses[1].addr[5]++;
		priv->hw->wiphy->n_addresses++;
	}
3579

3580 3581 3582
	/* initialize all valid contexts */
	iwl_init_context(priv);

3583 3584 3585
	/************************
	 * 5. Setup HW constants
	 ************************/
3586
	if (iwl_set_hw_params(priv)) {
3587
		err = -ENOENT;
3588
		IWL_ERR(priv, "failed to set hw parameters\n");
3589
		goto out_free_eeprom;
3590 3591 3592
	}

	/*******************
T
Tomas Winkler 已提交
3593
	 * 6. Setup priv
3594
	 *******************/
Z
Zhu Yi 已提交
3595

T
Tomas Winkler 已提交
3596
	err = iwl_init_drv(priv);
3597
	if (err)
R
Ron Rindjunsky 已提交
3598
		goto out_free_eeprom;
3599
	/* At this point both hw and priv are initialized. */
3600 3601

	/********************
3602
	 * 7. Setup services
3603
	 ********************/
J
Johannes Berg 已提交
3604
	iwl_alloc_isr_ict(priv);
3605

3606 3607
	err = request_irq(priv->bus.irq, iwl_isr_ict, IRQF_SHARED,
			  DRV_NAME, priv);
3608
	if (err) {
3609
		IWL_ERR(priv, "Error allocating IRQ %d\n", priv->bus.irq);
3610
		goto out_uninit_drv;
3611
	}
3612

3613
	iwl_setup_deferred_work(priv);
3614
	iwl_setup_rx_handlers(priv);
3615
	iwl_testmode_init(priv);
3616

J
Johannes Berg 已提交
3617
	/*********************************************
3618
	 * 8. Enable interrupts
J
Johannes Berg 已提交
3619
	 *********************************************/
T
Tomas Winkler 已提交
3620

3621
	iwl_enable_rfkill_int(priv);
3622 3623 3624 3625 3626 3627

	/* If platform's RF_KILL switch is NOT set to KILL */
	if (iwl_read32(priv, CSR_GP_CNTRL) & CSR_GP_CNTRL_REG_FLAG_HW_RF_KILL_SW)
		clear_bit(STATUS_RF_KILL_HW, &priv->status);
	else
		set_bit(STATUS_RF_KILL_HW, &priv->status);
T
Tomas Winkler 已提交
3628

J
Johannes Berg 已提交
3629 3630
	wiphy_rfkill_set_hw_state(priv->hw->wiphy,
		test_bit(STATUS_RF_KILL_HW, &priv->status));
3631

3632
	iwl_power_initialize(priv);
3633
	iwl_tt_initialize(priv);
J
Johannes Berg 已提交
3634

3635
	init_completion(&priv->_agn.firmware_loading_complete);
3636

3637
	err = iwl_request_firmware(priv, true);
J
Johannes Berg 已提交
3638
	if (err)
3639
		goto out_destroy_workqueue;
J
Johannes Berg 已提交
3640

Z
Zhu Yi 已提交
3641 3642
	return 0;

3643
 out_destroy_workqueue:
3644 3645
	destroy_workqueue(priv->workqueue);
	priv->workqueue = NULL;
3646
	free_irq(priv->bus.irq, priv);
3647
	iwl_free_isr_ict(priv);
3648
 out_uninit_drv:
T
Tomas Winkler 已提交
3649
	iwl_uninit_drv(priv);
3650 3651
 out_free_eeprom:
	iwl_eeprom_free(priv);
3652
 out_free_traffic_mem:
3653
	iwl_free_traffic_mem(priv);
3654
	ieee80211_free_hw(priv->hw);
Z
Zhu Yi 已提交
3655 3656 3657 3658
 out:
	return err;
}

3659
void __devexit iwl_remove(struct iwl_priv * priv)
Z
Zhu Yi 已提交
3660
{
3661
	unsigned long flags;
Z
Zhu Yi 已提交
3662

3663
	wait_for_completion(&priv->_agn.firmware_loading_complete);
3664

3665
	IWL_DEBUG_INFO(priv, "*** UNLOAD DRIVER ***\n");
Z
Zhu Yi 已提交
3666

3667
	iwl_dbgfs_unregister(priv);
3668 3669
	sysfs_remove_group(&priv->bus.dev->kobj,
			   &iwl_attribute_group);
3670

3671 3672
	/* ieee80211_unregister_hw call wil cause iwl_mac_stop to
	 * to be called and iwl_down since we are removing the device
3673 3674 3675
	 * we need to set STATUS_EXIT_PENDING bit.
	 */
	set_bit(STATUS_EXIT_PENDING, &priv->status);
3676

W
Wey-Yi Guy 已提交
3677
	iwl_testmode_cleanup(priv);
3678 3679
	iwl_leds_exit(priv);

3680 3681 3682 3683 3684
	if (priv->mac80211_registered) {
		ieee80211_unregister_hw(priv->hw);
		priv->mac80211_registered = 0;
	}

J
Johannes Berg 已提交
3685
	/* Reset to low power before unloading driver. */
J
Johannes Berg 已提交
3686
	iwl_apm_stop(priv);
3687

3688 3689
	iwl_tt_exit(priv);

3690 3691 3692 3693
	/* make sure we flush any pending irq or
	 * tasklet for the driver
	 */
	spin_lock_irqsave(&priv->lock, flags);
3694
	iwl_disable_interrupts(priv);
3695 3696 3697 3698
	spin_unlock_irqrestore(&priv->lock, flags);

	iwl_synchronize_irq(priv);

3699
	iwl_dealloc_ucode(priv);
Z
Zhu Yi 已提交
3700 3701

	if (priv->rxq.bd)
3702
		iwlagn_rx_queue_free(priv, &priv->rxq);
3703
	iwlagn_hw_txq_ctx_free(priv);
Z
Zhu Yi 已提交
3704

3705
	iwl_eeprom_free(priv);
Z
Zhu Yi 已提交
3706 3707


M
Mohamed Abbas 已提交
3708 3709 3710
	/*netif_stop_queue(dev); */
	flush_workqueue(priv->workqueue);

3711
	/* ieee80211_unregister_hw calls iwl_mac_stop, which flushes
Z
Zhu Yi 已提交
3712 3713 3714 3715
	 * priv->workqueue... so we can't take down the workqueue
	 * until now... */
	destroy_workqueue(priv->workqueue);
	priv->workqueue = NULL;
3716
	iwl_free_traffic_mem(priv);
Z
Zhu Yi 已提交
3717

3718
	free_irq(priv->bus.irq, priv);
3719
	priv->bus.ops->set_drv_data(&priv->bus, NULL);
Z
Zhu Yi 已提交
3720

T
Tomas Winkler 已提交
3721
	iwl_uninit_drv(priv);
Z
Zhu Yi 已提交
3722

J
Johannes Berg 已提交
3723
	iwl_free_isr_ict(priv);
M
Mohamed Abbas 已提交
3724

3725
	dev_kfree_skb(priv->beacon_skb);
Z
Zhu Yi 已提交
3726 3727 3728 3729 3730 3731 3732 3733 3734 3735

	ieee80211_free_hw(priv->hw);
}


/*****************************************************************************
 *
 * driver and module entry point
 *
 *****************************************************************************/
3736
static int __init iwl_init(void)
Z
Zhu Yi 已提交
3737 3738 3739
{

	int ret;
3740 3741
	pr_info(DRV_DESCRIPTION ", " DRV_VERSION "\n");
	pr_info(DRV_COPYRIGHT "\n");
3742

3743
	ret = iwlagn_rate_control_register();
3744
	if (ret) {
3745
		pr_err("Unable to register rate control algorithm: %d\n", ret);
3746 3747 3748
		return ret;
	}

3749
	ret = iwl_pci_register_driver();
Z
Zhu Yi 已提交
3750

3751 3752
	if (ret)
		goto error_register;
Z
Zhu Yi 已提交
3753
	return ret;
3754 3755

error_register:
3756
	iwlagn_rate_control_unregister();
3757
	return ret;
Z
Zhu Yi 已提交
3758 3759
}

3760
static void __exit iwl_exit(void)
Z
Zhu Yi 已提交
3761
{
3762
	iwl_pci_unregister_driver();
3763
	iwlagn_rate_control_unregister();
Z
Zhu Yi 已提交
3764 3765
}

3766 3767
module_exit(iwl_exit);
module_init(iwl_init);
3768 3769

#ifdef CONFIG_IWLWIFI_DEBUG
3770
module_param_named(debug, iwl_debug_level, uint, S_IRUGO | S_IWUSR);
3771 3772 3773
MODULE_PARM_DESC(debug, "debug output mask");
#endif

3774 3775 3776 3777 3778 3779 3780 3781 3782 3783 3784
module_param_named(swcrypto, iwlagn_mod_params.sw_crypto, int, S_IRUGO);
MODULE_PARM_DESC(swcrypto, "using crypto in software (default 0 [hardware])");
module_param_named(queues_num, iwlagn_mod_params.num_of_queues, int, S_IRUGO);
MODULE_PARM_DESC(queues_num, "number of hw queues.");
module_param_named(11n_disable, iwlagn_mod_params.disable_11n, int, S_IRUGO);
MODULE_PARM_DESC(11n_disable, "disable 11n functionality");
module_param_named(amsdu_size_8K, iwlagn_mod_params.amsdu_size_8K,
		   int, S_IRUGO);
MODULE_PARM_DESC(amsdu_size_8K, "enable 8K amsdu size");
module_param_named(fw_restart, iwlagn_mod_params.restart_fw, int, S_IRUGO);
MODULE_PARM_DESC(fw_restart, "restart firmware in case of error");
3785 3786 3787 3788 3789

module_param_named(ucode_alternative, iwlagn_wanted_ucode_alternative, int,
		   S_IRUGO);
MODULE_PARM_DESC(ucode_alternative,
		 "specify ucode alternative to use from ucode file");
3790 3791 3792 3793

module_param_named(antenna_coupling, iwlagn_ant_coupling, int, S_IRUGO);
MODULE_PARM_DESC(antenna_coupling,
		 "specify antenna coupling in dB (defualt: 0 dB)");
3794

3795 3796 3797
module_param_named(bt_ch_inhibition, iwlagn_bt_ch_announce, bool, S_IRUGO);
MODULE_PARM_DESC(bt_ch_inhibition,
		 "Disable BT channel inhibition (default: enable)");
3798 3799 3800 3801 3802 3803

module_param_named(plcp_check, iwlagn_mod_params.plcp_check, bool, S_IRUGO);
MODULE_PARM_DESC(plcp_check, "Check plcp health (default: 1 [enabled])");

module_param_named(ack_check, iwlagn_mod_params.ack_check, bool, S_IRUGO);
MODULE_PARM_DESC(ack_check, "Check ack health (default: 0 [disabled])");
3804 3805 3806 3807 3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818 3819 3820 3821 3822 3823

/*
 * set bt_coex_active to true, uCode will do kill/defer
 * every time the priority line is asserted (BT is sending signals on the
 * priority line in the PCIx).
 * set bt_coex_active to false, uCode will ignore the BT activity and
 * perform the normal operation
 *
 * User might experience transmit issue on some platform due to WiFi/BT
 * co-exist problem. The possible behaviors are:
 *   Able to scan and finding all the available AP
 *   Not able to associate with any AP
 * On those platforms, WiFi communication can be restored by set
 * "bt_coex_active" module parameter to "false"
 *
 * default: bt_coex_active = true (BT_COEX_ENABLE)
 */
module_param_named(bt_coex_active, iwlagn_mod_params.bt_coex_active,
		bool, S_IRUGO);
MODULE_PARM_DESC(bt_coex_active, "enable wifi/bt co-exist (default: enable)");
3824 3825 3826 3827

module_param_named(led_mode, iwlagn_mod_params.led_mode, int, S_IRUGO);
MODULE_PARM_DESC(led_mode, "0=system default, "
		"1=On(RF On)/Off(RF Off), 2=blinking (default: 0)");
3828

3829 3830 3831 3832 3833
module_param_named(power_save, iwlagn_mod_params.power_save,
		bool, S_IRUGO);
MODULE_PARM_DESC(power_save,
		 "enable WiFi power management (default: disable)");

3834 3835 3836 3837 3838 3839 3840 3841 3842
/*
 * For now, keep using power level 1 instead of automatically
 * adjusting ...
 */
module_param_named(no_sleep_autoadjust, iwlagn_mod_params.no_sleep_autoadjust,
		bool, S_IRUGO);
MODULE_PARM_DESC(no_sleep_autoadjust,
		 "don't automatically adjust sleep level "
		 "according to maximum network latency (default: true)");