dhd_sdio.c 109.2 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29
/*
 * Copyright (c) 2010 Broadcom Corporation
 *
 * Permission to use, copy, modify, and/or distribute this software for any
 * purpose with or without fee is hereby granted, provided that the above
 * copyright notice and this permission notice appear in all copies.
 *
 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
 * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
 * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
 * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
 */

#include <linux/types.h>
#include <linux/kernel.h>
#include <linux/kthread.h>
#include <linux/printk.h>
#include <linux/pci_ids.h>
#include <linux/netdevice.h>
#include <linux/interrupt.h>
#include <linux/sched.h>
#include <linux/mmc/sdio.h>
#include <linux/mmc/sdio_func.h>
#include <linux/mmc/card.h>
#include <linux/semaphore.h>
#include <linux/firmware.h>
30
#include <linux/module.h>
31
#include <linux/bcma/bcma.h>
32
#include <linux/debugfs.h>
33
#include <linux/vmalloc.h>
34
#include <linux/platform_data/brcmfmac-sdio.h>
35
#include <linux/moduleparam.h>
36 37 38 39 40 41 42
#include <asm/unaligned.h>
#include <defs.h>
#include <brcmu_wifi.h>
#include <brcmu_utils.h>
#include <brcm_hw_ids.h>
#include <soc.h>
#include "sdio_host.h"
43
#include "sdio_chip.h"
44
#include "nvram.h"
45 46 47

#define DCMD_RESP_TIMEOUT  2000	/* In milli second */

J
Joe Perches 已提交
48
#ifdef DEBUG
49 50 51 52 53

#define BRCMF_TRAP_INFO_SIZE	80

#define CBUF_LEN	(128)

54 55 56
/* Device console log buffer state */
#define CONSOLE_BUFFER_MAX	2024

57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94
struct rte_log_le {
	__le32 buf;		/* Can't be pointer on (64-bit) hosts */
	__le32 buf_size;
	__le32 idx;
	char *_buf_compat;	/* Redundant pointer for backward compat. */
};

struct rte_console {
	/* Virtual UART
	 * When there is no UART (e.g. Quickturn),
	 * the host should write a complete
	 * input line directly into cbuf and then write
	 * the length into vcons_in.
	 * This may also be used when there is a real UART
	 * (at risk of conflicting with
	 * the real UART).  vcons_out is currently unused.
	 */
	uint vcons_in;
	uint vcons_out;

	/* Output (logging) buffer
	 * Console output is written to a ring buffer log_buf at index log_idx.
	 * The host may read the output when it sees log_idx advance.
	 * Output will be lost if the output wraps around faster than the host
	 * polls.
	 */
	struct rte_log_le log_le;

	/* Console input line buffer
	 * Characters are read one at a time into cbuf
	 * until <CR> is received, then
	 * the buffer is processed as a command line.
	 * Also used for virtual UART.
	 */
	uint cbuf_idx;
	char cbuf[CBUF_LEN];
};

J
Joe Perches 已提交
95
#endif				/* DEBUG */
96 97 98 99
#include <chipcommon.h>

#include "dhd_bus.h"
#include "dhd_dbg.h"
100
#include "tracepoint.h"
101 102 103 104 105 106 107 108 109 110 111 112 113 114

#define TXQLEN		2048	/* bulk tx queue length */
#define TXHI		(TXQLEN - 256)	/* turn on flow control above TXHI */
#define TXLOW		(TXHI - 256)	/* turn off flow control below TXLOW */
#define PRIOMASK	7

#define TXRETRIES	2	/* # of retries for tx frames */

#define BRCMF_RXBOUND	50	/* Default for max rx frames in
				 one scheduling */

#define BRCMF_TXBOUND	20	/* Default for max tx frames in
				 one scheduling */

115 116
#define BRCMF_DEFAULT_TXGLOM_SIZE	32  /* max tx frames in glom chain */

117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253
#define BRCMF_TXMINMAX	1	/* Max tx frames if rx still pending */

#define MEMBLOCK	2048	/* Block size used for downloading
				 of dongle image */
#define MAX_DATA_BUF	(32 * 1024)	/* Must be large enough to hold
				 biggest possible glom */

#define BRCMF_FIRSTREAD	(1 << 6)


/* SBSDIO_DEVICE_CTL */

/* 1: device will assert busy signal when receiving CMD53 */
#define SBSDIO_DEVCTL_SETBUSY		0x01
/* 1: assertion of sdio interrupt is synchronous to the sdio clock */
#define SBSDIO_DEVCTL_SPI_INTR_SYNC	0x02
/* 1: mask all interrupts to host except the chipActive (rev 8) */
#define SBSDIO_DEVCTL_CA_INT_ONLY	0x04
/* 1: isolate internal sdio signals, put external pads in tri-state; requires
 * sdio bus power cycle to clear (rev 9) */
#define SBSDIO_DEVCTL_PADS_ISO		0x08
/* Force SD->SB reset mapping (rev 11) */
#define SBSDIO_DEVCTL_SB_RST_CTL	0x30
/*   Determined by CoreControl bit */
#define SBSDIO_DEVCTL_RST_CORECTL	0x00
/*   Force backplane reset */
#define SBSDIO_DEVCTL_RST_BPRESET	0x10
/*   Force no backplane reset */
#define SBSDIO_DEVCTL_RST_NOBPRESET	0x20

/* direct(mapped) cis space */

/* MAPPED common CIS address */
#define SBSDIO_CIS_BASE_COMMON		0x1000
/* maximum bytes in one CIS */
#define SBSDIO_CIS_SIZE_LIMIT		0x200
/* cis offset addr is < 17 bits */
#define SBSDIO_CIS_OFT_ADDR_MASK	0x1FFFF

/* manfid tuple length, include tuple, link bytes */
#define SBSDIO_CIS_MANFID_TUPLE_LEN	6

/* intstatus */
#define I_SMB_SW0	(1 << 0)	/* To SB Mail S/W interrupt 0 */
#define I_SMB_SW1	(1 << 1)	/* To SB Mail S/W interrupt 1 */
#define I_SMB_SW2	(1 << 2)	/* To SB Mail S/W interrupt 2 */
#define I_SMB_SW3	(1 << 3)	/* To SB Mail S/W interrupt 3 */
#define I_SMB_SW_MASK	0x0000000f	/* To SB Mail S/W interrupts mask */
#define I_SMB_SW_SHIFT	0	/* To SB Mail S/W interrupts shift */
#define I_HMB_SW0	(1 << 4)	/* To Host Mail S/W interrupt 0 */
#define I_HMB_SW1	(1 << 5)	/* To Host Mail S/W interrupt 1 */
#define I_HMB_SW2	(1 << 6)	/* To Host Mail S/W interrupt 2 */
#define I_HMB_SW3	(1 << 7)	/* To Host Mail S/W interrupt 3 */
#define I_HMB_SW_MASK	0x000000f0	/* To Host Mail S/W interrupts mask */
#define I_HMB_SW_SHIFT	4	/* To Host Mail S/W interrupts shift */
#define I_WR_OOSYNC	(1 << 8)	/* Write Frame Out Of Sync */
#define I_RD_OOSYNC	(1 << 9)	/* Read Frame Out Of Sync */
#define	I_PC		(1 << 10)	/* descriptor error */
#define	I_PD		(1 << 11)	/* data error */
#define	I_DE		(1 << 12)	/* Descriptor protocol Error */
#define	I_RU		(1 << 13)	/* Receive descriptor Underflow */
#define	I_RO		(1 << 14)	/* Receive fifo Overflow */
#define	I_XU		(1 << 15)	/* Transmit fifo Underflow */
#define	I_RI		(1 << 16)	/* Receive Interrupt */
#define I_BUSPWR	(1 << 17)	/* SDIO Bus Power Change (rev 9) */
#define I_XMTDATA_AVAIL (1 << 23)	/* bits in fifo */
#define	I_XI		(1 << 24)	/* Transmit Interrupt */
#define I_RF_TERM	(1 << 25)	/* Read Frame Terminate */
#define I_WF_TERM	(1 << 26)	/* Write Frame Terminate */
#define I_PCMCIA_XU	(1 << 27)	/* PCMCIA Transmit FIFO Underflow */
#define I_SBINT		(1 << 28)	/* sbintstatus Interrupt */
#define I_CHIPACTIVE	(1 << 29)	/* chip from doze to active state */
#define I_SRESET	(1 << 30)	/* CCCR RES interrupt */
#define I_IOE2		(1U << 31)	/* CCCR IOE2 Bit Changed */
#define	I_ERRORS	(I_PC | I_PD | I_DE | I_RU | I_RO | I_XU)
#define I_DMA		(I_RI | I_XI | I_ERRORS)

/* corecontrol */
#define CC_CISRDY		(1 << 0)	/* CIS Ready */
#define CC_BPRESEN		(1 << 1)	/* CCCR RES signal */
#define CC_F2RDY		(1 << 2)	/* set CCCR IOR2 bit */
#define CC_CLRPADSISO		(1 << 3)	/* clear SDIO pads isolation */
#define CC_XMTDATAAVAIL_MODE	(1 << 4)
#define CC_XMTDATAAVAIL_CTRL	(1 << 5)

/* SDA_FRAMECTRL */
#define SFC_RF_TERM	(1 << 0)	/* Read Frame Terminate */
#define SFC_WF_TERM	(1 << 1)	/* Write Frame Terminate */
#define SFC_CRC4WOOS	(1 << 2)	/* CRC error for write out of sync */
#define SFC_ABORTALL	(1 << 3)	/* Abort all in-progress frames */

/*
 * Software allocation of To SB Mailbox resources
 */

/* tosbmailbox bits corresponding to intstatus bits */
#define SMB_NAK		(1 << 0)	/* Frame NAK */
#define SMB_INT_ACK	(1 << 1)	/* Host Interrupt ACK */
#define SMB_USE_OOB	(1 << 2)	/* Use OOB Wakeup */
#define SMB_DEV_INT	(1 << 3)	/* Miscellaneous Interrupt */

/* tosbmailboxdata */
#define SMB_DATA_VERSION_SHIFT	16	/* host protocol version */

/*
 * Software allocation of To Host Mailbox resources
 */

/* intstatus bits */
#define I_HMB_FC_STATE	I_HMB_SW0	/* Flow Control State */
#define I_HMB_FC_CHANGE	I_HMB_SW1	/* Flow Control State Changed */
#define I_HMB_FRAME_IND	I_HMB_SW2	/* Frame Indication */
#define I_HMB_HOST_INT	I_HMB_SW3	/* Miscellaneous Interrupt */

/* tohostmailboxdata */
#define HMB_DATA_NAKHANDLED	1	/* retransmit NAK'd frame */
#define HMB_DATA_DEVREADY	2	/* talk to host after enable */
#define HMB_DATA_FC		4	/* per prio flowcontrol update flag */
#define HMB_DATA_FWREADY	8	/* fw ready for protocol activity */

#define HMB_DATA_FCDATA_MASK	0xff000000
#define HMB_DATA_FCDATA_SHIFT	24

#define HMB_DATA_VERSION_MASK	0x00ff0000
#define HMB_DATA_VERSION_SHIFT	16

/*
 * Software-defined protocol header
 */

/* Current protocol version */
#define SDPCM_PROT_VERSION	4

/*
 * Shared structure between dongle and the host.
 * The structure contains pointers to trap or assert information.
 */
254
#define SDPCM_SHARED_VERSION       0x0003
255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278
#define SDPCM_SHARED_VERSION_MASK  0x00FF
#define SDPCM_SHARED_ASSERT_BUILT  0x0100
#define SDPCM_SHARED_ASSERT        0x0200
#define SDPCM_SHARED_TRAP          0x0400

/* Space for header read, limit for data packets */
#define MAX_HDR_READ	(1 << 6)
#define MAX_RX_DATASZ	2048

/* Bump up limit on waiting for HT to account for first startup;
 * if the image is doing a CRC calculation before programming the PMU
 * for HT availability, it could take a couple hundred ms more, so
 * max out at a 1 second (1000000us).
 */
#undef PMU_MAX_TRANSITION_DLY
#define PMU_MAX_TRANSITION_DLY 1000000

/* Value for ChipClockCSR during initial setup */
#define BRCMF_INIT_CLKCTL1	(SBSDIO_FORCE_HW_CLKREQ_OFF |	\
					SBSDIO_ALP_AVAIL_REQ)

/* Flags for SDH calls */
#define F2SYNC	(SDIO_REQ_4BYTE | SDIO_REQ_FIXED)

279 280 281 282 283 284
#define BRCMF_IDLE_IMMEDIATE	(-1)	/* Enter idle immediately */
#define BRCMF_IDLE_ACTIVE	0	/* Do not request any SD clock change
					 * when idle
					 */
#define BRCMF_IDLE_INTERVAL	1

285 286 287
#define KSO_WAIT_US 50
#define MAX_KSO_ATTEMPTS (PMU_MAX_TRANSITION_DLY/KSO_WAIT_US)

288 289 290 291 292 293 294 295 296
/*
 * Conversion of 802.1D priority to precedence level
 */
static uint prio2prec(u32 prio)
{
	return (prio == PRIO_8021D_NONE || prio == PRIO_8021D_BE) ?
	       (prio^2) : prio;
}

J
Joe Perches 已提交
297
#ifdef DEBUG
298 299 300 301 302 303 304 305 306
/* Device console log buffer state */
struct brcmf_console {
	uint count;		/* Poll interval msec counter */
	uint log_addr;		/* Log struct address (fixed) */
	struct rte_log_le log_le;	/* Log struct (host copy) */
	uint bufsize;		/* Size of log buffer */
	u8 *buf;		/* Log buffer (host copy) */
	uint last;		/* Last buffer read index */
};
307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329

struct brcmf_trap_info {
	__le32		type;
	__le32		epc;
	__le32		cpsr;
	__le32		spsr;
	__le32		r0;	/* a1 */
	__le32		r1;	/* a2 */
	__le32		r2;	/* a3 */
	__le32		r3;	/* a4 */
	__le32		r4;	/* v1 */
	__le32		r5;	/* v2 */
	__le32		r6;	/* v3 */
	__le32		r7;	/* v4 */
	__le32		r8;	/* v5 */
	__le32		r9;	/* sb/v6 */
	__le32		r10;	/* sl/v7 */
	__le32		r11;	/* fp/v8 */
	__le32		r12;	/* ip */
	__le32		r13;	/* sp */
	__le32		r14;	/* lr */
	__le32		pc;	/* r15 */
};
J
Joe Perches 已提交
330
#endif				/* DEBUG */
331 332 333 334 335 336 337 338 339 340

struct sdpcm_shared {
	u32 flags;
	u32 trap_addr;
	u32 assert_exp_addr;
	u32 assert_file_addr;
	u32 assert_line;
	u32 console_addr;	/* Address of struct rte_console */
	u32 msgtrace_addr;
	u8 tag[32];
341
	u32 brpt_addr;
342 343 344 345 346 347 348 349 350 351 352
};

struct sdpcm_shared_le {
	__le32 flags;
	__le32 trap_addr;
	__le32 assert_exp_addr;
	__le32 assert_file_addr;
	__le32 assert_line;
	__le32 console_addr;	/* Address of struct rte_console */
	__le32 msgtrace_addr;
	u8 tag[32];
353
	__le32 brpt_addr;
354 355
};

356 357
/* dongle SDIO bus specific header info */
struct brcmf_sdio_hdrinfo {
358 359 360 361 362 363
	u8 seq_num;
	u8 channel;
	u16 len;
	u16 len_left;
	u16 len_nxtfrm;
	u8 dat_offset;
364 365
	bool lastfrm;
	u16 tail_pad;
366
};
367 368 369

/* misc chip info needed by some of the routines */
/* Private data for SDIO bus interaction */
370
struct brcmf_sdio {
371
	struct brcmf_sdio_dev *sdiodev;	/* sdio device handler */
372
	struct brcmf_chip *ci;	/* Chip info struct */
373 374 375 376

	u32 ramsize;		/* Size of RAM in SOCRAM (bytes) */

	u32 hostintmask;	/* Copy of Host Interrupt Mask */
377 378
	atomic_t intstatus;	/* Intstatus bits (events) pending */
	atomic_t fcstate;	/* State of dongle flow-control */
379 380 381 382 383 384 385 386 387

	uint blocksize;		/* Block size of SDIO transfers */
	uint roundup;		/* Max roundup limit */

	struct pktq txq;	/* Queue length used for flow-control */
	u8 flowcontrol;	/* per prio flow control bitmask */
	u8 tx_seq;		/* Transmit sequence number (next) */
	u8 tx_max;		/* Maximum transmit sequence allowed */

388
	u8 *hdrbuf;		/* buffer for handling rx frame */
389 390
	u8 *rxhdr;		/* Header of current rx frame (in hdrbuf) */
	u8 rx_seq;		/* Receive sequence number (expected) */
391
	struct brcmf_sdio_hdrinfo cur_read;
392
				/* info of current read frame */
393
	bool rxskip;		/* Skip receive (awaiting NAK ACK) */
394
	bool rxpending;		/* Data frame pending in dongle */
395 396 397 398 399 400

	uint rxbound;		/* Rx frames to read before resched */
	uint txbound;		/* Tx frames to send before resched */
	uint txminmax;

	struct sk_buff *glomd;	/* Packet containing glomming descriptor */
401
	struct sk_buff_head glom; /* Packet list for glommed superframe */
402 403 404 405 406
	uint glomerr;		/* Glom packet read errors */

	u8 *rxbuf;		/* Buffer for receiving control packets */
	uint rxblen;		/* Allocated length of rxbuf */
	u8 *rxctl;		/* Aligned pointer into rxbuf */
407
	u8 *rxctl_orig;		/* pointer for freeing rxctl */
408
	uint rxlen;		/* Length of valid data in buffer */
409
	spinlock_t rxctl_lock;	/* protection lock for ctrl frame resources */
410 411 412 413 414

	u8 sdpcm_ver;	/* Bus protocol reported by dongle */

	bool intr;		/* Use interrupts */
	bool poll;		/* Use polling */
415
	atomic_t ipend;		/* Device interrupt is pending */
416 417 418 419
	uint spurious;		/* Count of spurious interrupts */
	uint pollrate;		/* Ticks between device polls */
	uint polltick;		/* Tick counter */

J
Joe Perches 已提交
420
#ifdef DEBUG
421 422 423
	uint console_interval;
	struct brcmf_console console;	/* Console output polling support */
	uint console_addr;	/* Console address from shared struct */
J
Joe Perches 已提交
424
#endif				/* DEBUG */
425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448

	uint clkstate;		/* State of sd and backplane clock(s) */
	bool activity;		/* Activity flag for clock down */
	s32 idletime;		/* Control for activity timeout */
	s32 idlecount;	/* Activity timeout counter */
	s32 idleclock;	/* How to set bus driver when idle */
	bool rxflow_mode;	/* Rx flow control mode */
	bool rxflow;		/* Is rx flow control on */
	bool alp_only;		/* Don't use HT clock (ALP only) */

	u8 *ctrl_frame_buf;
	u32 ctrl_frame_len;
	bool ctrl_frame_stat;

	spinlock_t txqlock;
	wait_queue_head_t ctrl_wait;
	wait_queue_head_t dcmd_resp_wait;

	struct timer_list timer;
	struct completion watchdog_wait;
	struct task_struct *watchdog_tsk;
	bool wd_timer_valid;
	uint save_ms;

449 450
	struct workqueue_struct *brcmf_wq;
	struct work_struct datawork;
451
	atomic_t dpc_tskcnt;
452

453
	bool txoff;		/* Transmit flow-controlled */
454
	struct brcmf_sdio_count sdcnt;
455 456
	bool sr_enabled; /* SaveRestore enabled */
	bool sleeping; /* SDIO bus sleeping */
457 458

	u8 tx_hdrlen;		/* sdio bus header length for tx packet */
459 460
	bool txglom;		/* host tx glomming enable flag */
	struct sk_buff *txglom_sgpad;	/* scatter-gather padding buffer */
461 462
	u16 head_align;		/* buffer pointer alignment */
	u16 sgentry_align;	/* scatter-gather buffer alignment */
463 464 465 466 467
};

/* clkstate */
#define CLK_NONE	0
#define CLK_SDONLY	1
468
#define CLK_PENDING	2
469 470
#define CLK_AVAIL	3

J
Joe Perches 已提交
471
#ifdef DEBUG
472
static int qcount[NUMPRIO];
J
Joe Perches 已提交
473
#endif				/* DEBUG */
474

475
#define DEFAULT_SDIO_DRIVE_STRENGTH	6	/* in milliamps */
476 477 478 479 480 481 482 483 484 485 486

#define RETRYCHAN(chan) ((chan) == SDPCM_EVENT_CHANNEL)

/* Retry count for register access failures */
static const uint retry_limit = 2;

/* Limit on rounding up frames */
static const uint max_roundup = 512;

#define ALIGNMENT  4

487 488 489 490
static int brcmf_sdio_txglomsz = BRCMF_DEFAULT_TXGLOM_SIZE;
module_param_named(txglomsz, brcmf_sdio_txglomsz, int, 0);
MODULE_PARM_DESC(txglomsz, "maximum tx packet chain size [SDIO]");

491 492 493 494 495 496
enum brcmf_sdio_frmtype {
	BRCMF_SDIO_FT_NORMAL,
	BRCMF_SDIO_FT_SUPER,
	BRCMF_SDIO_FT_SUB,
};

497 498 499 500 501 502 503 504 505 506 507 508 509 510
#define BCM43143_FIRMWARE_NAME		"brcm/brcmfmac43143-sdio.bin"
#define BCM43143_NVRAM_NAME		"brcm/brcmfmac43143-sdio.txt"
#define BCM43241B0_FIRMWARE_NAME	"brcm/brcmfmac43241b0-sdio.bin"
#define BCM43241B0_NVRAM_NAME		"brcm/brcmfmac43241b0-sdio.txt"
#define BCM43241B4_FIRMWARE_NAME	"brcm/brcmfmac43241b4-sdio.bin"
#define BCM43241B4_NVRAM_NAME		"brcm/brcmfmac43241b4-sdio.txt"
#define BCM4329_FIRMWARE_NAME		"brcm/brcmfmac4329-sdio.bin"
#define BCM4329_NVRAM_NAME		"brcm/brcmfmac4329-sdio.txt"
#define BCM4330_FIRMWARE_NAME		"brcm/brcmfmac4330-sdio.bin"
#define BCM4330_NVRAM_NAME		"brcm/brcmfmac4330-sdio.txt"
#define BCM4334_FIRMWARE_NAME		"brcm/brcmfmac4334-sdio.bin"
#define BCM4334_NVRAM_NAME		"brcm/brcmfmac4334-sdio.txt"
#define BCM4335_FIRMWARE_NAME		"brcm/brcmfmac4335-sdio.bin"
#define BCM4335_NVRAM_NAME		"brcm/brcmfmac4335-sdio.txt"
511 512
#define BCM43362_FIRMWARE_NAME		"brcm/brcmfmac43362-sdio.bin"
#define BCM43362_NVRAM_NAME		"brcm/brcmfmac43362-sdio.txt"
513 514
#define BCM4339_FIRMWARE_NAME		"brcm/brcmfmac4339-sdio.bin"
#define BCM4339_NVRAM_NAME		"brcm/brcmfmac4339-sdio.txt"
515 516 517 518 519 520 521 522 523 524 525 526 527 528 529

MODULE_FIRMWARE(BCM43143_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM43143_NVRAM_NAME);
MODULE_FIRMWARE(BCM43241B0_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM43241B0_NVRAM_NAME);
MODULE_FIRMWARE(BCM43241B4_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM43241B4_NVRAM_NAME);
MODULE_FIRMWARE(BCM4329_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM4329_NVRAM_NAME);
MODULE_FIRMWARE(BCM4330_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM4330_NVRAM_NAME);
MODULE_FIRMWARE(BCM4334_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM4334_NVRAM_NAME);
MODULE_FIRMWARE(BCM4335_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM4335_NVRAM_NAME);
530 531
MODULE_FIRMWARE(BCM43362_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM43362_NVRAM_NAME);
532 533
MODULE_FIRMWARE(BCM4339_FIRMWARE_NAME);
MODULE_FIRMWARE(BCM4339_NVRAM_NAME);
534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556

struct brcmf_firmware_names {
	u32 chipid;
	u32 revmsk;
	const char *bin;
	const char *nv;
};

enum brcmf_firmware_type {
	BRCMF_FIRMWARE_BIN,
	BRCMF_FIRMWARE_NVRAM
};

#define BRCMF_FIRMWARE_NVRAM(name) \
	name ## _FIRMWARE_NAME, name ## _NVRAM_NAME

static const struct brcmf_firmware_names brcmf_fwname_data[] = {
	{ BCM43143_CHIP_ID, 0xFFFFFFFF, BRCMF_FIRMWARE_NVRAM(BCM43143) },
	{ BCM43241_CHIP_ID, 0x0000001F, BRCMF_FIRMWARE_NVRAM(BCM43241B0) },
	{ BCM43241_CHIP_ID, 0xFFFFFFE0, BRCMF_FIRMWARE_NVRAM(BCM43241B4) },
	{ BCM4329_CHIP_ID, 0xFFFFFFFF, BRCMF_FIRMWARE_NVRAM(BCM4329) },
	{ BCM4330_CHIP_ID, 0xFFFFFFFF, BRCMF_FIRMWARE_NVRAM(BCM4330) },
	{ BCM4334_CHIP_ID, 0xFFFFFFFF, BRCMF_FIRMWARE_NVRAM(BCM4334) },
557
	{ BCM4335_CHIP_ID, 0xFFFFFFFF, BRCMF_FIRMWARE_NVRAM(BCM4335) },
558
	{ BCM43362_CHIP_ID, 0xFFFFFFFE, BRCMF_FIRMWARE_NVRAM(BCM43362) },
559
	{ BCM4339_CHIP_ID, 0xFFFFFFFF, BRCMF_FIRMWARE_NVRAM(BCM4339) }
560 561 562
};


563
static const struct firmware *brcmf_sdio_get_fw(struct brcmf_sdio *bus,
564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600
						  enum brcmf_firmware_type type)
{
	const struct firmware *fw;
	const char *name;
	int err, i;

	for (i = 0; i < ARRAY_SIZE(brcmf_fwname_data); i++) {
		if (brcmf_fwname_data[i].chipid == bus->ci->chip &&
		    brcmf_fwname_data[i].revmsk & BIT(bus->ci->chiprev)) {
			switch (type) {
			case BRCMF_FIRMWARE_BIN:
				name = brcmf_fwname_data[i].bin;
				break;
			case BRCMF_FIRMWARE_NVRAM:
				name = brcmf_fwname_data[i].nv;
				break;
			default:
				brcmf_err("invalid firmware type (%d)\n", type);
				return NULL;
			}
			goto found;
		}
	}
	brcmf_err("Unknown chipid %d [%d]\n",
		  bus->ci->chip, bus->ci->chiprev);
	return NULL;

found:
	err = request_firmware(&fw, name, &bus->sdiodev->func[2]->dev);
	if ((err) || (!fw)) {
		brcmf_err("fail to request firmware %s (%d)\n", name, err);
		return NULL;
	}

	return fw;
}

601 602 603 604 605 606 607 608 609 610 611
static void pkt_align(struct sk_buff *p, int len, int align)
{
	uint datalign;
	datalign = (unsigned long)(p->data);
	datalign = roundup(datalign, (align)) - datalign;
	if (datalign)
		skb_pull(p, datalign);
	__skb_trim(p, len);
}

/* To check if there's window offered */
612
static bool data_ok(struct brcmf_sdio *bus)
613 614 615 616 617 618 619 620 621
{
	return (u8)(bus->tx_max - bus->tx_seq) != 0 &&
	       ((u8)(bus->tx_max - bus->tx_seq) & 0x80) == 0;
}

/*
 * Reads a register in the SDIO hardware block. This block occupies a series of
 * adresses on the 32 bit backplane bus.
 */
622 623
static int
r_sdreg32(struct brcmf_sdio *bus, u32 *regvar, u32 offset)
624
{
625
	u8 idx = brcmf_sdio_chip_getinfidx(bus->ci, BCMA_CORE_SDIO_DEV);
626
	int ret;
627

628 629
	*regvar = brcmf_sdiod_regrl(bus->sdiodev,
				    bus->ci->c_inf[idx].base + offset, &ret);
630 631

	return ret;
632 633
}

634 635
static int
w_sdreg32(struct brcmf_sdio *bus, u32 regval, u32 reg_offset)
636
{
637
	u8 idx = brcmf_sdio_chip_getinfidx(bus->ci, BCMA_CORE_SDIO_DEV);
638
	int ret;
639

640 641 642
	brcmf_sdiod_regwl(bus->sdiodev,
			  bus->ci->c_inf[idx].base + reg_offset,
			  regval, &ret);
643 644

	return ret;
645 646
}

647
static int
648
brcmf_sdio_kso_control(struct brcmf_sdio *bus, bool on)
649 650 651 652 653 654 655 656 657
{
	u8 wr_val = 0, rd_val, cmp_val, bmask;
	int err = 0;
	int try_cnt = 0;

	brcmf_dbg(TRACE, "Enter\n");

	wr_val = (on << SBSDIO_FUNC1_SLEEPCSR_KSO_SHIFT);
	/* 1st KSO write goes to AOS wake up core if device is asleep  */
658 659
	brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_SLEEPCSR,
			  wr_val, &err);
660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688
	if (err) {
		brcmf_err("SDIO_AOS KSO write error: %d\n", err);
		return err;
	}

	if (on) {
		/* device WAKEUP through KSO:
		 * write bit 0 & read back until
		 * both bits 0 (kso bit) & 1 (dev on status) are set
		 */
		cmp_val = SBSDIO_FUNC1_SLEEPCSR_KSO_MASK |
			  SBSDIO_FUNC1_SLEEPCSR_DEVON_MASK;
		bmask = cmp_val;
		usleep_range(2000, 3000);
	} else {
		/* Put device to sleep, turn off KSO */
		cmp_val = 0;
		/* only check for bit0, bit1(dev on status) may not
		 * get cleared right away
		 */
		bmask = SBSDIO_FUNC1_SLEEPCSR_KSO_MASK;
	}

	do {
		/* reliable KSO bit set/clr:
		 * the sdiod sleep write access is synced to PMU 32khz clk
		 * just one write attempt may fail,
		 * read it back until it matches written value
		 */
689 690
		rd_val = brcmf_sdiod_regrb(bus->sdiodev, SBSDIO_FUNC1_SLEEPCSR,
					   &err);
691 692 693 694 695
		if (((rd_val & bmask) == cmp_val) && !err)
			break;
		brcmf_dbg(SDIO, "KSO wr/rd retry:%d (max: %d) ERR:%x\n",
			  try_cnt, MAX_KSO_ATTEMPTS, err);
		udelay(KSO_WAIT_US);
696 697
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_SLEEPCSR,
				  wr_val, &err);
698 699 700 701 702
	} while (try_cnt++ < MAX_KSO_ATTEMPTS);

	return err;
}

703 704 705 706 707
#define PKT_AVAILABLE()		(intstatus & I_HMB_FRAME_IND)

#define HOSTINTMASK		(I_HMB_SW_MASK | I_CHIPACTIVE)

/* Turn backplane clock on or off */
708
static int brcmf_sdio_htclk(struct brcmf_sdio *bus, bool on, bool pendok)
709 710 711 712 713
{
	int err;
	u8 clkctl, clkreq, devctl;
	unsigned long timeout;

714
	brcmf_dbg(SDIO, "Enter\n");
715 716 717

	clkctl = 0;

718 719 720 721 722
	if (bus->sr_enabled) {
		bus->clkstate = (on ? CLK_AVAIL : CLK_SDONLY);
		return 0;
	}

723 724 725 726 727
	if (on) {
		/* Request HT Avail */
		clkreq =
		    bus->alp_only ? SBSDIO_ALP_AVAIL_REQ : SBSDIO_HT_AVAIL_REQ;

728 729
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR,
				  clkreq, &err);
730
		if (err) {
731
			brcmf_err("HT Avail request error: %d\n", err);
732 733 734 735
			return -EBADE;
		}

		/* Check current status */
736 737
		clkctl = brcmf_sdiod_regrb(bus->sdiodev,
					   SBSDIO_FUNC1_CHIPCLKCSR, &err);
738
		if (err) {
739
			brcmf_err("HT Avail read error: %d\n", err);
740 741 742 743 744 745
			return -EBADE;
		}

		/* Go to pending and await interrupt if appropriate */
		if (!SBSDIO_CLKAV(clkctl, bus->alp_only) && pendok) {
			/* Allow only clock-available interrupt */
746 747
			devctl = brcmf_sdiod_regrb(bus->sdiodev,
						   SBSDIO_DEVICE_CTL, &err);
748
			if (err) {
749
				brcmf_err("Devctl error setting CA: %d\n",
750 751 752 753 754
					  err);
				return -EBADE;
			}

			devctl |= SBSDIO_DEVCTL_CA_INT_ONLY;
755 756
			brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_DEVICE_CTL,
					  devctl, &err);
757
			brcmf_dbg(SDIO, "CLKCTL: set PENDING\n");
758 759 760 761 762
			bus->clkstate = CLK_PENDING;

			return 0;
		} else if (bus->clkstate == CLK_PENDING) {
			/* Cancel CA-only interrupt filter */
763 764
			devctl = brcmf_sdiod_regrb(bus->sdiodev,
						   SBSDIO_DEVICE_CTL, &err);
765
			devctl &= ~SBSDIO_DEVCTL_CA_INT_ONLY;
766 767
			brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_DEVICE_CTL,
					  devctl, &err);
768 769 770 771 772 773
		}

		/* Otherwise, wait here (polling) for HT Avail */
		timeout = jiffies +
			  msecs_to_jiffies(PMU_MAX_TRANSITION_DLY/1000);
		while (!SBSDIO_CLKAV(clkctl, bus->alp_only)) {
774 775 776
			clkctl = brcmf_sdiod_regrb(bus->sdiodev,
						   SBSDIO_FUNC1_CHIPCLKCSR,
						   &err);
777 778 779 780 781 782
			if (time_after(jiffies, timeout))
				break;
			else
				usleep_range(5000, 10000);
		}
		if (err) {
783
			brcmf_err("HT Avail request error: %d\n", err);
784 785 786
			return -EBADE;
		}
		if (!SBSDIO_CLKAV(clkctl, bus->alp_only)) {
787
			brcmf_err("HT Avail timeout (%d): clkctl 0x%02x\n",
788 789 790 791 792 793
				  PMU_MAX_TRANSITION_DLY, clkctl);
			return -EBADE;
		}

		/* Mark clock available */
		bus->clkstate = CLK_AVAIL;
794
		brcmf_dbg(SDIO, "CLKCTL: turned ON\n");
795

J
Joe Perches 已提交
796
#if defined(DEBUG)
797
		if (!bus->alp_only) {
798
			if (SBSDIO_ALPONLY(clkctl))
799
				brcmf_err("HT Clock should be on\n");
800
		}
J
Joe Perches 已提交
801
#endif				/* defined (DEBUG) */
802 803 804 805 806 807 808

		bus->activity = true;
	} else {
		clkreq = 0;

		if (bus->clkstate == CLK_PENDING) {
			/* Cancel CA-only interrupt filter */
809 810
			devctl = brcmf_sdiod_regrb(bus->sdiodev,
						   SBSDIO_DEVICE_CTL, &err);
811
			devctl &= ~SBSDIO_DEVCTL_CA_INT_ONLY;
812 813
			brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_DEVICE_CTL,
					  devctl, &err);
814 815 816
		}

		bus->clkstate = CLK_SDONLY;
817 818
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR,
				  clkreq, &err);
819
		brcmf_dbg(SDIO, "CLKCTL: turned OFF\n");
820
		if (err) {
821
			brcmf_err("Failed access turning clock off: %d\n",
822 823 824 825 826 827 828 829
				  err);
			return -EBADE;
		}
	}
	return 0;
}

/* Change idle/active SD state */
830
static int brcmf_sdio_sdclk(struct brcmf_sdio *bus, bool on)
831
{
832
	brcmf_dbg(SDIO, "Enter\n");
833 834 835 836 837 838 839 840 841 842

	if (on)
		bus->clkstate = CLK_SDONLY;
	else
		bus->clkstate = CLK_NONE;

	return 0;
}

/* Transition SD and backplane clock readiness */
843
static int brcmf_sdio_clkctl(struct brcmf_sdio *bus, uint target, bool pendok)
844
{
J
Joe Perches 已提交
845
#ifdef DEBUG
846
	uint oldstate = bus->clkstate;
J
Joe Perches 已提交
847
#endif				/* DEBUG */
848

849
	brcmf_dbg(SDIO, "Enter\n");
850 851 852 853

	/* Early exit if we're already there */
	if (bus->clkstate == target) {
		if (target == CLK_AVAIL) {
854
			brcmf_sdio_wd_timer(bus, BRCMF_WD_POLL_MS);
855 856 857 858 859 860 861 862 863
			bus->activity = true;
		}
		return 0;
	}

	switch (target) {
	case CLK_AVAIL:
		/* Make sure SD clock is available */
		if (bus->clkstate == CLK_NONE)
864
			brcmf_sdio_sdclk(bus, true);
865
		/* Now request HT Avail on the backplane */
866 867
		brcmf_sdio_htclk(bus, true, pendok);
		brcmf_sdio_wd_timer(bus, BRCMF_WD_POLL_MS);
868 869 870 871 872 873
		bus->activity = true;
		break;

	case CLK_SDONLY:
		/* Remove HT request, or bring up SD clock */
		if (bus->clkstate == CLK_NONE)
874
			brcmf_sdio_sdclk(bus, true);
875
		else if (bus->clkstate == CLK_AVAIL)
876
			brcmf_sdio_htclk(bus, false, false);
877
		else
878
			brcmf_err("request for %d -> %d\n",
879
				  bus->clkstate, target);
880
		brcmf_sdio_wd_timer(bus, BRCMF_WD_POLL_MS);
881 882 883 884 885
		break;

	case CLK_NONE:
		/* Make sure to remove HT request */
		if (bus->clkstate == CLK_AVAIL)
886
			brcmf_sdio_htclk(bus, false, false);
887
		/* Now remove the SD clock */
888 889
		brcmf_sdio_sdclk(bus, false);
		brcmf_sdio_wd_timer(bus, 0);
890 891
		break;
	}
J
Joe Perches 已提交
892
#ifdef DEBUG
893
	brcmf_dbg(SDIO, "%d -> %d\n", oldstate, bus->clkstate);
J
Joe Perches 已提交
894
#endif				/* DEBUG */
895 896 897 898

	return 0;
}

899
static int
900
brcmf_sdio_bus_sleep(struct brcmf_sdio *bus, bool sleep, bool pendok)
901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922
{
	int err = 0;
	brcmf_dbg(TRACE, "Enter\n");
	brcmf_dbg(SDIO, "request %s currently %s\n",
		  (sleep ? "SLEEP" : "WAKE"),
		  (bus->sleeping ? "SLEEP" : "WAKE"));

	/* If SR is enabled control bus state with KSO */
	if (bus->sr_enabled) {
		/* Done if we're already in the requested state */
		if (sleep == bus->sleeping)
			goto end;

		/* Going to sleep */
		if (sleep) {
			/* Don't sleep if something is pending */
			if (atomic_read(&bus->intstatus) ||
			    atomic_read(&bus->ipend) > 0 ||
			    (!atomic_read(&bus->fcstate) &&
			    brcmu_pktq_mlen(&bus->txq, ~bus->flowcontrol) &&
			    data_ok(bus)))
				 return -EBUSY;
923
			err = brcmf_sdio_kso_control(bus, false);
924 925
			/* disable watchdog */
			if (!err)
926
				brcmf_sdio_wd_timer(bus, 0);
927 928
		} else {
			bus->idlecount = 0;
929
			err = brcmf_sdio_kso_control(bus, true);
930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946
		}
		if (!err) {
			/* Change state */
			bus->sleeping = sleep;
			brcmf_dbg(SDIO, "new state %s\n",
				  (sleep ? "SLEEP" : "WAKE"));
		} else {
			brcmf_err("error while changing bus sleep state %d\n",
				  err);
			return err;
		}
	}

end:
	/* control clocks */
	if (sleep) {
		if (!bus->sr_enabled)
947
			brcmf_sdio_clkctl(bus, CLK_NONE, pendok);
948
	} else {
949
		brcmf_sdio_clkctl(bus, CLK_AVAIL, pendok);
950 951 952 953 954 955
	}

	return err;

}

956
static u32 brcmf_sdio_hostmail(struct brcmf_sdio *bus)
957 958 959 960
{
	u32 intstatus = 0;
	u32 hmb_data;
	u8 fcbits;
961
	int ret;
962

963
	brcmf_dbg(SDIO, "Enter\n");
964 965

	/* Read mailbox data and ack that we did so */
966 967
	ret = r_sdreg32(bus, &hmb_data,
			offsetof(struct sdpcmd_regs, tohostmailboxdata));
968

969
	if (ret == 0)
970
		w_sdreg32(bus, SMB_INT_ACK,
971
			  offsetof(struct sdpcmd_regs, tosbmailbox));
972
	bus->sdcnt.f1regdata += 2;
973 974 975

	/* Dongle recomposed rx frames, accept them again */
	if (hmb_data & HMB_DATA_NAKHANDLED) {
976
		brcmf_dbg(SDIO, "Dongle reports NAK handled, expect rtx of %d\n",
977 978
			  bus->rx_seq);
		if (!bus->rxskip)
979
			brcmf_err("unexpected NAKHANDLED!\n");
980 981 982 983 984 985 986 987 988 989 990 991 992

		bus->rxskip = false;
		intstatus |= I_HMB_FRAME_IND;
	}

	/*
	 * DEVREADY does not occur with gSPI.
	 */
	if (hmb_data & (HMB_DATA_DEVREADY | HMB_DATA_FWREADY)) {
		bus->sdpcm_ver =
		    (hmb_data & HMB_DATA_VERSION_MASK) >>
		    HMB_DATA_VERSION_SHIFT;
		if (bus->sdpcm_ver != SDPCM_PROT_VERSION)
993
			brcmf_err("Version mismatch, dongle reports %d, "
994 995 996
				  "expecting %d\n",
				  bus->sdpcm_ver, SDPCM_PROT_VERSION);
		else
997
			brcmf_dbg(SDIO, "Dongle ready, protocol version %d\n",
998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010
				  bus->sdpcm_ver);
	}

	/*
	 * Flow Control has been moved into the RX headers and this out of band
	 * method isn't used any more.
	 * remaining backward compatible with older dongles.
	 */
	if (hmb_data & HMB_DATA_FC) {
		fcbits = (hmb_data & HMB_DATA_FCDATA_MASK) >>
							HMB_DATA_FCDATA_SHIFT;

		if (fcbits & ~bus->flowcontrol)
1011
			bus->sdcnt.fc_xoff++;
1012 1013

		if (bus->flowcontrol & ~fcbits)
1014
			bus->sdcnt.fc_xon++;
1015

1016
		bus->sdcnt.fc_rcvd++;
1017 1018 1019 1020 1021 1022 1023 1024 1025
		bus->flowcontrol = fcbits;
	}

	/* Shouldn't be any others */
	if (hmb_data & ~(HMB_DATA_DEVREADY |
			 HMB_DATA_NAKHANDLED |
			 HMB_DATA_FC |
			 HMB_DATA_FWREADY |
			 HMB_DATA_FCDATA_MASK | HMB_DATA_VERSION_MASK))
1026
		brcmf_err("Unknown mailbox data content: 0x%02x\n",
1027 1028 1029 1030 1031
			  hmb_data);

	return intstatus;
}

1032
static void brcmf_sdio_rxfail(struct brcmf_sdio *bus, bool abort, bool rtx)
1033 1034 1035 1036 1037 1038
{
	uint retries = 0;
	u16 lastrbc;
	u8 hi, lo;
	int err;

1039
	brcmf_err("%sterminate frame%s\n",
1040 1041 1042 1043
		  abort ? "abort command, " : "",
		  rtx ? ", send NAK" : "");

	if (abort)
1044
		brcmf_sdiod_abort(bus->sdiodev, SDIO_FUNC_2);
1045

1046 1047
	brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_FRAMECTRL,
			  SFC_RF_TERM, &err);
1048
	bus->sdcnt.f1regdata++;
1049 1050 1051

	/* Wait until the packet has been flushed (device/FIFO stable) */
	for (lastrbc = retries = 0xffff; retries > 0; retries--) {
1052 1053 1054 1055
		hi = brcmf_sdiod_regrb(bus->sdiodev,
				       SBSDIO_FUNC1_RFRAMEBCHI, &err);
		lo = brcmf_sdiod_regrb(bus->sdiodev,
				       SBSDIO_FUNC1_RFRAMEBCLO, &err);
1056
		bus->sdcnt.f1regdata += 2;
1057 1058 1059 1060 1061

		if ((hi == 0) && (lo == 0))
			break;

		if ((hi > (lastrbc >> 8)) && (lo > (lastrbc & 0x00ff))) {
1062
			brcmf_err("count growing: last 0x%04x now 0x%04x\n",
1063 1064 1065 1066 1067 1068
				  lastrbc, (hi << 8) + lo);
		}
		lastrbc = (hi << 8) + lo;
	}

	if (!retries)
1069
		brcmf_err("count never zeroed: last 0x%04x\n", lastrbc);
1070
	else
1071
		brcmf_dbg(SDIO, "flush took %d iterations\n", 0xffff - retries);
1072 1073

	if (rtx) {
1074
		bus->sdcnt.rxrtx++;
1075 1076
		err = w_sdreg32(bus, SMB_NAK,
				offsetof(struct sdpcmd_regs, tosbmailbox));
1077

1078
		bus->sdcnt.f1regdata++;
1079
		if (err == 0)
1080 1081 1082 1083
			bus->rxskip = true;
	}

	/* Clear partial in any case */
1084
	bus->cur_read.len = 0;
1085 1086

	/* If we can't reach the device, signal failure */
1087
	if (err)
1088
		bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
1089 1090
}

1091
/* return total length of buffer chain */
1092
static uint brcmf_sdio_glom_len(struct brcmf_sdio *bus)
1093 1094 1095 1096 1097 1098 1099 1100 1101 1102
{
	struct sk_buff *p;
	uint total;

	total = 0;
	skb_queue_walk(&bus->glom, p)
		total += p->len;
	return total;
}

1103
static void brcmf_sdio_free_glom(struct brcmf_sdio *bus)
1104 1105 1106 1107 1108 1109 1110 1111 1112
{
	struct sk_buff *cur, *next;

	skb_queue_walk_safe(&bus->glom, cur, next) {
		skb_unlink(cur, &bus->glom);
		brcmu_pkt_buf_free_skb(cur);
	}
}

1113 1114 1115 1116 1117 1118
/**
 * brcmfmac sdio bus specific header
 * This is the lowest layer header wrapped on the packets transmitted between
 * host and WiFi dongle which contains information needed for SDIO core and
 * firmware
 *
1119 1120
 * It consists of 3 parts: hardware header, hardware extension header and
 * software header
1121 1122 1123
 * hardware header (frame tag) - 4 bytes
 * Byte 0~1: Frame length
 * Byte 2~3: Checksum, bit-wise inverse of frame length
1124 1125 1126 1127 1128 1129 1130
 * hardware extension header - 8 bytes
 * Tx glom mode only, N/A for Rx or normal Tx
 * Byte 0~1: Packet length excluding hw frame tag
 * Byte 2: Reserved
 * Byte 3: Frame flags, bit 0: last frame indication
 * Byte 4~5: Reserved
 * Byte 6~7: Tail padding length
1131 1132 1133 1134 1135 1136 1137 1138 1139 1140
 * software header - 8 bytes
 * Byte 0: Rx/Tx sequence number
 * Byte 1: 4 MSB Channel number, 4 LSB arbitrary flag
 * Byte 2: Length of next data frame, reserved for Tx
 * Byte 3: Data offset
 * Byte 4: Flow control bits, reserved for Tx
 * Byte 5: Maximum Sequence number allowed by firmware for Tx, N/A for Tx packet
 * Byte 6~7: Reserved
 */
#define SDPCM_HWHDR_LEN			4
1141
#define SDPCM_HWEXT_LEN			8
1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172
#define SDPCM_SWHDR_LEN			8
#define SDPCM_HDRLEN			(SDPCM_HWHDR_LEN + SDPCM_SWHDR_LEN)
/* software header */
#define SDPCM_SEQ_MASK			0x000000ff
#define SDPCM_SEQ_WRAP			256
#define SDPCM_CHANNEL_MASK		0x00000f00
#define SDPCM_CHANNEL_SHIFT		8
#define SDPCM_CONTROL_CHANNEL		0	/* Control */
#define SDPCM_EVENT_CHANNEL		1	/* Asyc Event Indication */
#define SDPCM_DATA_CHANNEL		2	/* Data Xmit/Recv */
#define SDPCM_GLOM_CHANNEL		3	/* Coalesced packets */
#define SDPCM_TEST_CHANNEL		15	/* Test/debug packets */
#define SDPCM_GLOMDESC(p)		(((u8 *)p)[1] & 0x80)
#define SDPCM_NEXTLEN_MASK		0x00ff0000
#define SDPCM_NEXTLEN_SHIFT		16
#define SDPCM_DOFFSET_MASK		0xff000000
#define SDPCM_DOFFSET_SHIFT		24
#define SDPCM_FCMASK_MASK		0x000000ff
#define SDPCM_WINDOW_MASK		0x0000ff00
#define SDPCM_WINDOW_SHIFT		8

static inline u8 brcmf_sdio_getdatoffset(u8 *swheader)
{
	u32 hdrvalue;
	hdrvalue = *(u32 *)swheader;
	return (u8)((hdrvalue & SDPCM_DOFFSET_MASK) >> SDPCM_DOFFSET_SHIFT);
}

static int brcmf_sdio_hdparse(struct brcmf_sdio *bus, u8 *header,
			      struct brcmf_sdio_hdrinfo *rd,
			      enum brcmf_sdio_frmtype type)
1173 1174 1175
{
	u16 len, checksum;
	u8 rx_seq, fc, tx_seq_max;
1176
	u32 swheader;
1177

1178
	trace_brcmf_sdpcm_hdr(SDPCM_RX, header);
1179

1180
	/* hw header */
1181 1182 1183 1184 1185
	len = get_unaligned_le16(header);
	checksum = get_unaligned_le16(header + sizeof(u16));
	/* All zero means no more to read */
	if (!(len | checksum)) {
		bus->rxpending = false;
1186
		return -ENODATA;
1187 1188
	}
	if ((u16)(~(len ^ checksum))) {
1189
		brcmf_err("HW header checksum error\n");
1190
		bus->sdcnt.rx_badhdr++;
1191
		brcmf_sdio_rxfail(bus, false, false);
1192
		return -EIO;
1193 1194
	}
	if (len < SDPCM_HDRLEN) {
1195
		brcmf_err("HW header length error\n");
1196
		return -EPROTO;
1197
	}
1198 1199
	if (type == BRCMF_SDIO_FT_SUPER &&
	    (roundup(len, bus->blocksize) != rd->len)) {
1200
		brcmf_err("HW superframe header length error\n");
1201
		return -EPROTO;
1202 1203
	}
	if (type == BRCMF_SDIO_FT_SUB && len > rd->len) {
1204
		brcmf_err("HW subframe header length error\n");
1205
		return -EPROTO;
1206
	}
1207 1208
	rd->len = len;

1209 1210 1211 1212
	/* software header */
	header += SDPCM_HWHDR_LEN;
	swheader = le32_to_cpu(*(__le32 *)header);
	if (type == BRCMF_SDIO_FT_SUPER && SDPCM_GLOMDESC(header)) {
1213
		brcmf_err("Glom descriptor found in superframe head\n");
1214
		rd->len = 0;
1215
		return -EINVAL;
1216
	}
1217 1218
	rx_seq = (u8)(swheader & SDPCM_SEQ_MASK);
	rd->channel = (swheader & SDPCM_CHANNEL_MASK) >> SDPCM_CHANNEL_SHIFT;
1219 1220
	if (len > MAX_RX_DATASZ && rd->channel != SDPCM_CONTROL_CHANNEL &&
	    type != BRCMF_SDIO_FT_SUPER) {
1221
		brcmf_err("HW header length too long\n");
1222
		bus->sdcnt.rx_toolong++;
1223
		brcmf_sdio_rxfail(bus, false, false);
1224
		rd->len = 0;
1225
		return -EPROTO;
1226
	}
1227
	if (type == BRCMF_SDIO_FT_SUPER && rd->channel != SDPCM_GLOM_CHANNEL) {
1228
		brcmf_err("Wrong channel for superframe\n");
1229
		rd->len = 0;
1230
		return -EINVAL;
1231 1232 1233
	}
	if (type == BRCMF_SDIO_FT_SUB && rd->channel != SDPCM_DATA_CHANNEL &&
	    rd->channel != SDPCM_EVENT_CHANNEL) {
1234
		brcmf_err("Wrong channel for subframe\n");
1235
		rd->len = 0;
1236
		return -EINVAL;
1237
	}
1238
	rd->dat_offset = brcmf_sdio_getdatoffset(header);
1239
	if (rd->dat_offset < SDPCM_HDRLEN || rd->dat_offset > rd->len) {
1240
		brcmf_err("seq %d: bad data offset\n", rx_seq);
1241
		bus->sdcnt.rx_badhdr++;
1242
		brcmf_sdio_rxfail(bus, false, false);
1243
		rd->len = 0;
1244
		return -ENXIO;
1245 1246
	}
	if (rd->seq_num != rx_seq) {
1247
		brcmf_err("seq %d: sequence number error, expect %d\n",
1248 1249 1250 1251
			  rx_seq, rd->seq_num);
		bus->sdcnt.rx_badseq++;
		rd->seq_num = rx_seq;
	}
1252 1253
	/* no need to check the reset for subframe */
	if (type == BRCMF_SDIO_FT_SUB)
1254
		return 0;
1255
	rd->len_nxtfrm = (swheader & SDPCM_NEXTLEN_MASK) >> SDPCM_NEXTLEN_SHIFT;
1256 1257 1258
	if (rd->len_nxtfrm << 4 > MAX_RX_DATASZ) {
		/* only warm for NON glom packet */
		if (rd->channel != SDPCM_GLOM_CHANNEL)
1259
			brcmf_err("seq %d: next length error\n", rx_seq);
1260 1261
		rd->len_nxtfrm = 0;
	}
1262 1263
	swheader = le32_to_cpu(*(__le32 *)(header + 4));
	fc = swheader & SDPCM_FCMASK_MASK;
1264 1265 1266 1267 1268 1269 1270 1271
	if (bus->flowcontrol != fc) {
		if (~bus->flowcontrol & fc)
			bus->sdcnt.fc_xoff++;
		if (bus->flowcontrol & ~fc)
			bus->sdcnt.fc_xon++;
		bus->sdcnt.fc_rcvd++;
		bus->flowcontrol = fc;
	}
1272
	tx_seq_max = (swheader & SDPCM_WINDOW_MASK) >> SDPCM_WINDOW_SHIFT;
1273
	if ((u8)(tx_seq_max - bus->tx_seq) > 0x40) {
1274
		brcmf_err("seq %d: max tx seq number error\n", rx_seq);
1275 1276 1277 1278
		tx_seq_max = bus->tx_seq + 2;
	}
	bus->tx_max = tx_seq_max;

1279
	return 0;
1280 1281
}

1282 1283 1284 1285 1286 1287 1288 1289 1290
static inline void brcmf_sdio_update_hwhdr(u8 *header, u16 frm_length)
{
	*(__le16 *)header = cpu_to_le16(frm_length);
	*(((__le16 *)header) + 1) = cpu_to_le16(~frm_length);
}

static void brcmf_sdio_hdpack(struct brcmf_sdio *bus, u8 *header,
			      struct brcmf_sdio_hdrinfo *hd_info)
{
1291 1292
	u32 hdrval;
	u8 hdr_offset;
1293 1294

	brcmf_sdio_update_hwhdr(header, hd_info->len);
1295 1296 1297 1298 1299 1300 1301 1302 1303
	hdr_offset = SDPCM_HWHDR_LEN;

	if (bus->txglom) {
		hdrval = (hd_info->len - hdr_offset) | (hd_info->lastfrm << 24);
		*((__le32 *)(header + hdr_offset)) = cpu_to_le32(hdrval);
		hdrval = (u16)hd_info->tail_pad << 16;
		*(((__le32 *)(header + hdr_offset)) + 1) = cpu_to_le32(hdrval);
		hdr_offset += SDPCM_HWEXT_LEN;
	}
1304

1305 1306 1307 1308 1309 1310 1311 1312
	hdrval = hd_info->seq_num;
	hdrval |= (hd_info->channel << SDPCM_CHANNEL_SHIFT) &
		  SDPCM_CHANNEL_MASK;
	hdrval |= (hd_info->dat_offset << SDPCM_DOFFSET_SHIFT) &
		  SDPCM_DOFFSET_MASK;
	*((__le32 *)(header + hdr_offset)) = cpu_to_le32(hdrval);
	*(((__le32 *)(header + hdr_offset)) + 1) = 0;
	trace_brcmf_sdpcm_hdr(SDPCM_TX + !!(bus->txglom), header);
1313 1314
}

1315
static u8 brcmf_sdio_rxglom(struct brcmf_sdio *bus, u8 rxseq)
1316 1317 1318
{
	u16 dlen, totlen;
	u8 *dptr, num = 0;
1319
	u16 sublen;
1320
	struct sk_buff *pfirst, *pnext;
1321 1322

	int errcode;
1323
	u8 doff, sfdoff;
1324

1325
	struct brcmf_sdio_hdrinfo rd_new;
1326 1327 1328 1329

	/* If packets, issue read(s) and send up packet chain */
	/* Return sequence numbers consumed? */

1330
	brcmf_dbg(SDIO, "start: glomd %p glom %p\n",
1331
		  bus->glomd, skb_peek(&bus->glom));
1332 1333 1334

	/* If there's a descriptor, generate the packet chain */
	if (bus->glomd) {
1335
		pfirst = pnext = NULL;
1336 1337 1338
		dlen = (u16) (bus->glomd->len);
		dptr = bus->glomd->data;
		if (!dlen || (dlen & 1)) {
1339
			brcmf_err("bad glomd len(%d), ignore descriptor\n",
1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350
				  dlen);
			dlen = 0;
		}

		for (totlen = num = 0; dlen; num++) {
			/* Get (and move past) next length */
			sublen = get_unaligned_le16(dptr);
			dlen -= sizeof(u16);
			dptr += sizeof(u16);
			if ((sublen < SDPCM_HDRLEN) ||
			    ((num == 0) && (sublen < (2 * SDPCM_HDRLEN)))) {
1351
				brcmf_err("descriptor len %d bad: %d\n",
1352 1353 1354 1355
					  num, sublen);
				pnext = NULL;
				break;
			}
1356
			if (sublen % bus->sgentry_align) {
1357
				brcmf_err("sublen %d not multiple of %d\n",
1358
					  sublen, bus->sgentry_align);
1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370
			}
			totlen += sublen;

			/* For last frame, adjust read len so total
				 is a block multiple */
			if (!dlen) {
				sublen +=
				    (roundup(totlen, bus->blocksize) - totlen);
				totlen = roundup(totlen, bus->blocksize);
			}

			/* Allocate/chain packet for next subframe */
1371
			pnext = brcmu_pkt_buf_get_skb(sublen + bus->sgentry_align);
1372
			if (pnext == NULL) {
1373
				brcmf_err("bcm_pkt_buf_get_skb failed, num %d len %d\n",
1374 1375 1376
					  num, sublen);
				break;
			}
1377
			skb_queue_tail(&bus->glom, pnext);
1378 1379

			/* Adhere to start alignment requirements */
1380
			pkt_align(pnext, sublen, bus->sgentry_align);
1381 1382 1383 1384 1385 1386 1387
		}

		/* If all allocations succeeded, save packet chain
			 in bus structure */
		if (pnext) {
			brcmf_dbg(GLOM, "allocated %d-byte packet chain for %d subframes\n",
				  totlen, num);
1388 1389
			if (BRCMF_GLOM_ON() && bus->cur_read.len &&
			    totlen != bus->cur_read.len) {
1390
				brcmf_dbg(GLOM, "glomdesc mismatch: nextlen %d glomdesc %d rxseq %d\n",
1391
					  bus->cur_read.len, totlen, rxseq);
1392 1393 1394
			}
			pfirst = pnext = NULL;
		} else {
1395
			brcmf_sdio_free_glom(bus);
1396 1397 1398 1399 1400 1401
			num = 0;
		}

		/* Done with descriptor packet */
		brcmu_pkt_buf_free_skb(bus->glomd);
		bus->glomd = NULL;
1402
		bus->cur_read.len = 0;
1403 1404 1405 1406
	}

	/* Ok -- either we just generated a packet chain,
		 or had one from before */
1407
	if (!skb_queue_empty(&bus->glom)) {
1408 1409
		if (BRCMF_GLOM_ON()) {
			brcmf_dbg(GLOM, "try superframe read, packet chain:\n");
1410
			skb_queue_walk(&bus->glom, pnext) {
1411 1412 1413 1414 1415 1416
				brcmf_dbg(GLOM, "    %p: %p len 0x%04x (%d)\n",
					  pnext, (u8 *) (pnext->data),
					  pnext->len, pnext->len);
			}
		}

1417
		pfirst = skb_peek(&bus->glom);
1418
		dlen = (u16) brcmf_sdio_glom_len(bus);
1419 1420 1421 1422 1423

		/* Do an SDIO read for the superframe.  Configurable iovar to
		 * read directly into the chained packet, or allocate a large
		 * packet and and copy into the chain.
		 */
1424
		sdio_claim_host(bus->sdiodev->func[1]);
1425 1426
		errcode = brcmf_sdiod_recv_chain(bus->sdiodev,
						 &bus->glom, dlen);
1427
		sdio_release_host(bus->sdiodev->func[1]);
1428
		bus->sdcnt.f2rxdata++;
1429 1430 1431

		/* On failure, kill the superframe, allow a couple retries */
		if (errcode < 0) {
1432
			brcmf_err("glom read of %d bytes failed: %d\n",
1433 1434
				  dlen, errcode);

1435
			sdio_claim_host(bus->sdiodev->func[1]);
1436
			if (bus->glomerr++ < 3) {
1437
				brcmf_sdio_rxfail(bus, true, true);
1438 1439
			} else {
				bus->glomerr = 0;
1440
				brcmf_sdio_rxfail(bus, true, false);
1441
				bus->sdcnt.rxglomfail++;
1442
				brcmf_sdio_free_glom(bus);
1443
			}
1444
			sdio_release_host(bus->sdiodev->func[1]);
1445 1446
			return 0;
		}
1447 1448 1449 1450

		brcmf_dbg_hex_dump(BRCMF_GLOM_ON(),
				   pfirst->data, min_t(int, pfirst->len, 48),
				   "SUPERFRAME:\n");
1451

1452 1453
		rd_new.seq_num = rxseq;
		rd_new.len = dlen;
1454
		sdio_claim_host(bus->sdiodev->func[1]);
1455 1456
		errcode = brcmf_sdio_hdparse(bus, pfirst->data, &rd_new,
					     BRCMF_SDIO_FT_SUPER);
1457
		sdio_release_host(bus->sdiodev->func[1]);
1458
		bus->cur_read.len = rd_new.len_nxtfrm << 4;
1459 1460

		/* Remove superframe header, remember offset */
1461 1462
		skb_pull(pfirst, rd_new.dat_offset);
		sfdoff = rd_new.dat_offset;
1463
		num = 0;
1464 1465

		/* Validate all the subframe headers */
1466 1467 1468 1469 1470
		skb_queue_walk(&bus->glom, pnext) {
			/* leave when invalid subframe is found */
			if (errcode)
				break;

1471 1472
			rd_new.len = pnext->len;
			rd_new.seq_num = rxseq++;
1473
			sdio_claim_host(bus->sdiodev->func[1]);
1474 1475
			errcode = brcmf_sdio_hdparse(bus, pnext->data, &rd_new,
						     BRCMF_SDIO_FT_SUB);
1476
			sdio_release_host(bus->sdiodev->func[1]);
1477
			brcmf_dbg_hex_dump(BRCMF_GLOM_ON(),
1478
					   pnext->data, 32, "subframe:\n");
1479

1480
			num++;
1481 1482 1483 1484 1485
		}

		if (errcode) {
			/* Terminate frame on error, request
				 a couple retries */
1486
			sdio_claim_host(bus->sdiodev->func[1]);
1487 1488 1489
			if (bus->glomerr++ < 3) {
				/* Restore superframe header space */
				skb_push(pfirst, sfdoff);
1490
				brcmf_sdio_rxfail(bus, true, true);
1491 1492
			} else {
				bus->glomerr = 0;
1493
				brcmf_sdio_rxfail(bus, true, false);
1494
				bus->sdcnt.rxglomfail++;
1495
				brcmf_sdio_free_glom(bus);
1496
			}
1497
			sdio_release_host(bus->sdiodev->func[1]);
1498
			bus->cur_read.len = 0;
1499 1500 1501 1502 1503
			return 0;
		}

		/* Basic SD framing looks ok - process each packet (header) */

1504
		skb_queue_walk_safe(&bus->glom, pfirst, pnext) {
1505 1506
			dptr = (u8 *) (pfirst->data);
			sublen = get_unaligned_le16(dptr);
1507
			doff = brcmf_sdio_getdatoffset(&dptr[SDPCM_HWHDR_LEN]);
1508

1509
			brcmf_dbg_hex_dump(BRCMF_BYTES_ON() && BRCMF_DATA_ON(),
1510 1511
					   dptr, pfirst->len,
					   "Rx Subframe Data:\n");
1512 1513 1514 1515 1516

			__skb_trim(pfirst, sublen);
			skb_pull(pfirst, doff);

			if (pfirst->len == 0) {
1517
				skb_unlink(pfirst, &bus->glom);
1518 1519 1520 1521
				brcmu_pkt_buf_free_skb(pfirst);
				continue;
			}

1522 1523 1524 1525 1526 1527 1528
			brcmf_dbg_hex_dump(BRCMF_GLOM_ON(),
					   pfirst->data,
					   min_t(int, pfirst->len, 32),
					   "subframe %d to stack, %p (%p/%d) nxt/lnk %p/%p\n",
					   bus->glom.qlen, pfirst, pfirst->data,
					   pfirst->len, pfirst->next,
					   pfirst->prev);
1529 1530 1531
			skb_unlink(pfirst, &bus->glom);
			brcmf_rx_frame(bus->sdiodev->dev, pfirst);
			bus->sdcnt.rxglompkts++;
1532 1533
		}

1534
		bus->sdcnt.rxglomframes++;
1535 1536 1537 1538
	}
	return num;
}

1539 1540
static int brcmf_sdio_dcmd_resp_wait(struct brcmf_sdio *bus, uint *condition,
				     bool *pending)
1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560
{
	DECLARE_WAITQUEUE(wait, current);
	int timeout = msecs_to_jiffies(DCMD_RESP_TIMEOUT);

	/* Wait until control frame is available */
	add_wait_queue(&bus->dcmd_resp_wait, &wait);
	set_current_state(TASK_INTERRUPTIBLE);

	while (!(*condition) && (!signal_pending(current) && timeout))
		timeout = schedule_timeout(timeout);

	if (signal_pending(current))
		*pending = true;

	set_current_state(TASK_RUNNING);
	remove_wait_queue(&bus->dcmd_resp_wait, &wait);

	return timeout;
}

1561
static int brcmf_sdio_dcmd_resp_wake(struct brcmf_sdio *bus)
1562 1563 1564 1565 1566 1567 1568
{
	if (waitqueue_active(&bus->dcmd_resp_wait))
		wake_up_interruptible(&bus->dcmd_resp_wait);

	return 0;
}
static void
1569
brcmf_sdio_read_control(struct brcmf_sdio *bus, u8 *hdr, uint len, uint doff)
1570 1571
{
	uint rdlen, pad;
1572
	u8 *buf = NULL, *rbuf;
1573 1574 1575 1576
	int sdret;

	brcmf_dbg(TRACE, "Enter\n");

1577 1578
	if (bus->rxblen)
		buf = vzalloc(bus->rxblen);
1579
	if (!buf)
1580
		goto done;
1581

1582
	rbuf = bus->rxbuf;
1583
	pad = ((unsigned long)rbuf % bus->head_align);
1584
	if (pad)
1585
		rbuf += (bus->head_align - pad);
1586 1587

	/* Copy the already-read portion over */
1588
	memcpy(buf, hdr, BRCMF_FIRSTREAD);
1589 1590 1591 1592 1593 1594 1595 1596
	if (len <= BRCMF_FIRSTREAD)
		goto gotpkt;

	/* Raise rdlen to next SDIO block to avoid tail command */
	rdlen = len - BRCMF_FIRSTREAD;
	if (bus->roundup && bus->blocksize && (rdlen > bus->blocksize)) {
		pad = bus->blocksize - (rdlen % bus->blocksize);
		if ((pad <= bus->roundup) && (pad < bus->blocksize) &&
1597
		    ((len + pad) < bus->sdiodev->bus_if->maxctl))
1598
			rdlen += pad;
1599 1600
	} else if (rdlen % bus->head_align) {
		rdlen += bus->head_align - (rdlen % bus->head_align);
1601 1602 1603
	}

	/* Drop if the read is too big or it exceeds our maximum */
1604
	if ((rdlen + BRCMF_FIRSTREAD) > bus->sdiodev->bus_if->maxctl) {
1605
		brcmf_err("%d-byte control read exceeds %d-byte buffer\n",
1606
			  rdlen, bus->sdiodev->bus_if->maxctl);
1607
		brcmf_sdio_rxfail(bus, false, false);
1608 1609 1610
		goto done;
	}

1611
	if ((len - doff) > bus->sdiodev->bus_if->maxctl) {
1612
		brcmf_err("%d-byte ctl frame (%d-byte ctl data) exceeds %d-byte limit\n",
1613
			  len, len - doff, bus->sdiodev->bus_if->maxctl);
1614
		bus->sdcnt.rx_toolong++;
1615
		brcmf_sdio_rxfail(bus, false, false);
1616 1617 1618
		goto done;
	}

1619
	/* Read remain of frame body */
1620
	sdret = brcmf_sdiod_recv_buf(bus->sdiodev, rbuf, rdlen);
1621
	bus->sdcnt.f2rxdata++;
1622 1623 1624

	/* Control frame failures need retransmission */
	if (sdret < 0) {
1625
		brcmf_err("read %d control bytes failed: %d\n",
1626
			  rdlen, sdret);
1627
		bus->sdcnt.rxc_errors++;
1628
		brcmf_sdio_rxfail(bus, true, true);
1629
		goto done;
1630 1631
	} else
		memcpy(buf + BRCMF_FIRSTREAD, rbuf, rdlen);
1632 1633 1634

gotpkt:

1635
	brcmf_dbg_hex_dump(BRCMF_BYTES_ON() && BRCMF_CTL_ON(),
1636
			   buf, len, "RxCtrl:\n");
1637 1638

	/* Point to valid data and indicate its length */
1639 1640
	spin_lock_bh(&bus->rxctl_lock);
	if (bus->rxctl) {
1641
		brcmf_err("last control frame is being processed.\n");
1642 1643 1644 1645 1646 1647
		spin_unlock_bh(&bus->rxctl_lock);
		vfree(buf);
		goto done;
	}
	bus->rxctl = buf + doff;
	bus->rxctl_orig = buf;
1648
	bus->rxlen = len - doff;
1649
	spin_unlock_bh(&bus->rxctl_lock);
1650 1651 1652

done:
	/* Awake any waiters */
1653
	brcmf_sdio_dcmd_resp_wake(bus);
1654 1655 1656
}

/* Pad read to blocksize for efficiency */
1657
static void brcmf_sdio_pad(struct brcmf_sdio *bus, u16 *pad, u16 *rdlen)
1658 1659 1660 1661 1662 1663
{
	if (bus->roundup && bus->blocksize && *rdlen > bus->blocksize) {
		*pad = bus->blocksize - (*rdlen % bus->blocksize);
		if (*pad <= bus->roundup && *pad < bus->blocksize &&
		    *rdlen + *pad + BRCMF_FIRSTREAD < MAX_RX_DATASZ)
			*rdlen += *pad;
1664 1665
	} else if (*rdlen % bus->head_align) {
		*rdlen += bus->head_align - (*rdlen % bus->head_align);
1666 1667 1668
	}
}

1669
static uint brcmf_sdio_readframes(struct brcmf_sdio *bus, uint maxframes)
1670 1671 1672 1673
{
	struct sk_buff *pkt;		/* Packet for event or data frames */
	u16 pad;		/* Number of pad bytes to read */
	uint rxleft = 0;	/* Remaining number of frames allowed */
1674
	int ret;		/* Return code from calls */
1675
	uint rxcount = 0;	/* Total frames read */
1676
	struct brcmf_sdio_hdrinfo *rd = &bus->cur_read, rd_new;
1677
	u8 head_read = 0;
1678 1679 1680 1681

	brcmf_dbg(TRACE, "Enter\n");

	/* Not finished unless we encounter no more frames indication */
1682
	bus->rxpending = true;
1683

1684
	for (rd->seq_num = bus->rx_seq, rxleft = maxframes;
1685
	     !bus->rxskip && rxleft &&
1686
	     bus->sdiodev->bus_if->state != BRCMF_BUS_DOWN;
1687
	     rd->seq_num++, rxleft--) {
1688 1689

		/* Handle glomming separately */
1690
		if (bus->glomd || !skb_queue_empty(&bus->glom)) {
1691 1692
			u8 cnt;
			brcmf_dbg(GLOM, "calling rxglom: glomd %p, glom %p\n",
1693
				  bus->glomd, skb_peek(&bus->glom));
1694
			cnt = brcmf_sdio_rxglom(bus, rd->seq_num);
1695
			brcmf_dbg(GLOM, "rxglom returned %d\n", cnt);
1696
			rd->seq_num += cnt - 1;
1697 1698 1699 1700
			rxleft = (rxleft > cnt) ? (rxleft - cnt) : 1;
			continue;
		}

1701 1702
		rd->len_left = rd->len;
		/* read header first for unknow frame length */
1703
		sdio_claim_host(bus->sdiodev->func[1]);
1704
		if (!rd->len) {
1705 1706
			ret = brcmf_sdiod_recv_buf(bus->sdiodev,
						   bus->rxhdr, BRCMF_FIRSTREAD);
1707
			bus->sdcnt.f2rxhdrs++;
1708
			if (ret < 0) {
1709
				brcmf_err("RXHEADER FAILED: %d\n",
1710
					  ret);
1711
				bus->sdcnt.rx_hdrfail++;
1712
				brcmf_sdio_rxfail(bus, true, true);
1713
				sdio_release_host(bus->sdiodev->func[1]);
1714 1715 1716
				continue;
			}

1717
			brcmf_dbg_hex_dump(BRCMF_BYTES_ON() || BRCMF_HDRS_ON(),
1718 1719
					   bus->rxhdr, SDPCM_HDRLEN,
					   "RxHdr:\n");
1720

1721 1722
			if (brcmf_sdio_hdparse(bus, bus->rxhdr, rd,
					       BRCMF_SDIO_FT_NORMAL)) {
1723
				sdio_release_host(bus->sdiodev->func[1]);
1724 1725 1726 1727
				if (!bus->rxpending)
					break;
				else
					continue;
1728 1729
			}

1730
			if (rd->channel == SDPCM_CONTROL_CHANNEL) {
1731 1732 1733
				brcmf_sdio_read_control(bus, bus->rxhdr,
							rd->len,
							rd->dat_offset);
1734 1735 1736 1737 1738
				/* prepare the descriptor for the next read */
				rd->len = rd->len_nxtfrm << 4;
				rd->len_nxtfrm = 0;
				/* treat all packet as event if we don't know */
				rd->channel = SDPCM_EVENT_CHANNEL;
1739
				sdio_release_host(bus->sdiodev->func[1]);
1740 1741
				continue;
			}
1742 1743 1744
			rd->len_left = rd->len > BRCMF_FIRSTREAD ?
				       rd->len - BRCMF_FIRSTREAD : 0;
			head_read = BRCMF_FIRSTREAD;
1745 1746
		}

1747
		brcmf_sdio_pad(bus, &pad, &rd->len_left);
1748

1749
		pkt = brcmu_pkt_buf_get_skb(rd->len_left + head_read +
1750
					    bus->head_align);
1751 1752
		if (!pkt) {
			/* Give up on data, request rtx of events */
1753
			brcmf_err("brcmu_pkt_buf_get_skb failed\n");
1754
			brcmf_sdio_rxfail(bus, false,
1755
					    RETRYCHAN(rd->channel));
1756
			sdio_release_host(bus->sdiodev->func[1]);
1757 1758
			continue;
		}
1759
		skb_pull(pkt, head_read);
1760
		pkt_align(pkt, rd->len_left, bus->head_align);
1761

1762
		ret = brcmf_sdiod_recv_pkt(bus->sdiodev, pkt);
1763
		bus->sdcnt.f2rxdata++;
1764
		sdio_release_host(bus->sdiodev->func[1]);
1765

1766
		if (ret < 0) {
1767
			brcmf_err("read %d bytes from channel %d failed: %d\n",
1768
				  rd->len, rd->channel, ret);
1769
			brcmu_pkt_buf_free_skb(pkt);
1770
			sdio_claim_host(bus->sdiodev->func[1]);
1771
			brcmf_sdio_rxfail(bus, true,
1772
					    RETRYCHAN(rd->channel));
1773
			sdio_release_host(bus->sdiodev->func[1]);
1774 1775 1776
			continue;
		}

1777 1778 1779 1780 1781 1782 1783
		if (head_read) {
			skb_push(pkt, head_read);
			memcpy(pkt->data, bus->rxhdr, head_read);
			head_read = 0;
		} else {
			memcpy(bus->rxhdr, pkt->data, SDPCM_HDRLEN);
			rd_new.seq_num = rd->seq_num;
1784
			sdio_claim_host(bus->sdiodev->func[1]);
1785 1786
			if (brcmf_sdio_hdparse(bus, bus->rxhdr, &rd_new,
					       BRCMF_SDIO_FT_NORMAL)) {
1787 1788 1789 1790 1791
				rd->len = 0;
				brcmu_pkt_buf_free_skb(pkt);
			}
			bus->sdcnt.rx_readahead_cnt++;
			if (rd->len != roundup(rd_new.len, 16)) {
1792
				brcmf_err("frame length mismatch:read %d, should be %d\n",
1793 1794 1795
					  rd->len,
					  roundup(rd_new.len, 16) >> 4);
				rd->len = 0;
1796
				brcmf_sdio_rxfail(bus, true, true);
1797
				sdio_release_host(bus->sdiodev->func[1]);
1798 1799 1800
				brcmu_pkt_buf_free_skb(pkt);
				continue;
			}
1801
			sdio_release_host(bus->sdiodev->func[1]);
1802 1803 1804 1805 1806 1807 1808 1809 1810 1811 1812
			rd->len_nxtfrm = rd_new.len_nxtfrm;
			rd->channel = rd_new.channel;
			rd->dat_offset = rd_new.dat_offset;

			brcmf_dbg_hex_dump(!(BRCMF_BYTES_ON() &&
					     BRCMF_DATA_ON()) &&
					   BRCMF_HDRS_ON(),
					   bus->rxhdr, SDPCM_HDRLEN,
					   "RxHdr:\n");

			if (rd_new.channel == SDPCM_CONTROL_CHANNEL) {
1813
				brcmf_err("readahead on control packet %d?\n",
1814 1815 1816
					  rd_new.seq_num);
				/* Force retry w/normal header read */
				rd->len = 0;
1817
				sdio_claim_host(bus->sdiodev->func[1]);
1818
				brcmf_sdio_rxfail(bus, false, true);
1819
				sdio_release_host(bus->sdiodev->func[1]);
1820 1821 1822 1823
				brcmu_pkt_buf_free_skb(pkt);
				continue;
			}
		}
1824

1825
		brcmf_dbg_hex_dump(BRCMF_BYTES_ON() && BRCMF_DATA_ON(),
1826
				   pkt->data, rd->len, "Rx Data:\n");
1827 1828

		/* Save superframe descriptor and allocate packet frame */
1829
		if (rd->channel == SDPCM_GLOM_CHANNEL) {
1830
			if (SDPCM_GLOMDESC(&bus->rxhdr[SDPCM_HWHDR_LEN])) {
1831
				brcmf_dbg(GLOM, "glom descriptor, %d bytes:\n",
1832
					  rd->len);
1833
				brcmf_dbg_hex_dump(BRCMF_GLOM_ON(),
1834
						   pkt->data, rd->len,
1835
						   "Glom Data:\n");
1836
				__skb_trim(pkt, rd->len);
1837 1838 1839
				skb_pull(pkt, SDPCM_HDRLEN);
				bus->glomd = pkt;
			} else {
1840
				brcmf_err("%s: glom superframe w/o "
1841
					  "descriptor!\n", __func__);
1842
				sdio_claim_host(bus->sdiodev->func[1]);
1843
				brcmf_sdio_rxfail(bus, false, false);
1844
				sdio_release_host(bus->sdiodev->func[1]);
1845
			}
1846 1847 1848 1849 1850
			/* prepare the descriptor for the next read */
			rd->len = rd->len_nxtfrm << 4;
			rd->len_nxtfrm = 0;
			/* treat all packet as event if we don't know */
			rd->channel = SDPCM_EVENT_CHANNEL;
1851 1852 1853 1854
			continue;
		}

		/* Fill in packet len and prio, deliver upward */
1855 1856 1857 1858 1859 1860 1861 1862
		__skb_trim(pkt, rd->len);
		skb_pull(pkt, rd->dat_offset);

		/* prepare the descriptor for the next read */
		rd->len = rd->len_nxtfrm << 4;
		rd->len_nxtfrm = 0;
		/* treat all packet as event if we don't know */
		rd->channel = SDPCM_EVENT_CHANNEL;
1863 1864 1865 1866 1867 1868

		if (pkt->len == 0) {
			brcmu_pkt_buf_free_skb(pkt);
			continue;
		}

1869
		brcmf_rx_frame(bus->sdiodev->dev, pkt);
1870
	}
1871

1872 1873 1874
	rxcount = maxframes - rxleft;
	/* Message if we hit the limit */
	if (!rxleft)
1875
		brcmf_dbg(DATA, "hit rx limit of %d frames\n", maxframes);
1876 1877 1878 1879
	else
		brcmf_dbg(DATA, "processed %d frames\n", rxcount);
	/* Back off rxseq if awaiting rtx, update rx_seq */
	if (bus->rxskip)
1880 1881
		rd->seq_num--;
	bus->rx_seq = rd->seq_num;
1882 1883 1884 1885 1886

	return rxcount;
}

static void
1887
brcmf_sdio_wait_event_wakeup(struct brcmf_sdio *bus)
1888 1889 1890 1891 1892 1893
{
	if (waitqueue_active(&bus->ctrl_wait))
		wake_up_interruptible(&bus->ctrl_wait);
	return;
}

1894 1895
static int brcmf_sdio_txpkt_hdalign(struct brcmf_sdio *bus, struct sk_buff *pkt)
{
1896
	u16 head_pad;
1897 1898 1899 1900 1901
	u8 *dat_buf;

	dat_buf = (u8 *)(pkt->data);

	/* Check head padding */
1902
	head_pad = ((unsigned long)dat_buf % bus->head_align);
1903 1904 1905 1906 1907 1908 1909 1910 1911 1912 1913 1914 1915 1916
	if (head_pad) {
		if (skb_headroom(pkt) < head_pad) {
			bus->sdiodev->bus_if->tx_realloc++;
			head_pad = 0;
			if (skb_cow(pkt, head_pad))
				return -ENOMEM;
		}
		skb_push(pkt, head_pad);
		dat_buf = (u8 *)(pkt->data);
		memset(dat_buf, 0, head_pad + bus->tx_hdrlen);
	}
	return head_pad;
}

1917 1918 1919 1920
/**
 * struct brcmf_skbuff_cb reserves first two bytes in sk_buff::cb for
 * bus layer usage.
 */
1921
/* flag marking a dummy skb added for DMA alignment requirement */
1922
#define ALIGN_SKB_FLAG		0x8000
1923
/* bit mask of data length chopped from the previous packet */
1924 1925
#define ALIGN_SKB_CHOP_LEN_MASK	0x7fff

1926
static int brcmf_sdio_txpkt_prep_sg(struct brcmf_sdio *bus,
1927
				    struct sk_buff_head *pktq,
1928
				    struct sk_buff *pkt, u16 total_len)
1929
{
1930
	struct brcmf_sdio_dev *sdiodev;
1931
	struct sk_buff *pkt_pad;
1932
	u16 tail_pad, tail_chop, chain_pad;
1933
	unsigned int blksize;
1934 1935
	bool lastfrm;
	int ntail, ret;
1936

1937
	sdiodev = bus->sdiodev;
1938 1939
	blksize = sdiodev->func[SDIO_FUNC_2]->cur_blksize;
	/* sg entry alignment should be a divisor of block size */
1940
	WARN_ON(blksize % bus->sgentry_align);
1941 1942

	/* Check tail padding */
1943 1944
	lastfrm = skb_queue_is_last(pktq, pkt);
	tail_pad = 0;
1945
	tail_chop = pkt->len % bus->sgentry_align;
1946
	if (tail_chop)
1947
		tail_pad = bus->sgentry_align - tail_chop;
1948 1949 1950
	chain_pad = (total_len + tail_pad) % blksize;
	if (lastfrm && chain_pad)
		tail_pad += blksize - chain_pad;
1951
	if (skb_tailroom(pkt) < tail_pad && pkt->len > blksize) {
1952 1953 1954
		pkt_pad = bus->txglom_sgpad;
		if (pkt_pad == NULL)
			  brcmu_pkt_buf_get_skb(tail_pad + tail_chop);
1955 1956
		if (pkt_pad == NULL)
			return -ENOMEM;
1957 1958 1959
		ret = brcmf_sdio_txpkt_hdalign(bus, pkt_pad);
		if (unlikely(ret < 0))
			return ret;
1960 1961 1962 1963 1964 1965 1966 1967 1968 1969 1970 1971 1972 1973 1974 1975 1976
		memcpy(pkt_pad->data,
		       pkt->data + pkt->len - tail_chop,
		       tail_chop);
		*(u32 *)(pkt_pad->cb) = ALIGN_SKB_FLAG + tail_chop;
		skb_trim(pkt, pkt->len - tail_chop);
		__skb_queue_after(pktq, pkt, pkt_pad);
	} else {
		ntail = pkt->data_len + tail_pad -
			(pkt->end - pkt->tail);
		if (skb_cloned(pkt) || ntail > 0)
			if (pskb_expand_head(pkt, 0, ntail, GFP_ATOMIC))
				return -ENOMEM;
		if (skb_linearize(pkt))
			return -ENOMEM;
		__skb_put(pkt, tail_pad);
	}

1977
	return tail_pad;
1978 1979
}

1980 1981 1982 1983 1984 1985 1986 1987 1988 1989 1990 1991 1992 1993 1994
/**
 * brcmf_sdio_txpkt_prep - packet preparation for transmit
 * @bus: brcmf_sdio structure pointer
 * @pktq: packet list pointer
 * @chan: virtual channel to transmit the packet
 *
 * Processes to be applied to the packet
 *	- Align data buffer pointer
 *	- Align data buffer length
 *	- Prepare header
 * Return: negative value if there is error
 */
static int
brcmf_sdio_txpkt_prep(struct brcmf_sdio *bus, struct sk_buff_head *pktq,
		      uint chan)
1995
{
1996
	u16 head_pad, total_len;
1997
	struct sk_buff *pkt_next;
1998 1999
	u8 txseq;
	int ret;
2000
	struct brcmf_sdio_hdrinfo hd_info = {0};
2001

2002 2003 2004 2005 2006 2007 2008 2009 2010 2011
	txseq = bus->tx_seq;
	total_len = 0;
	skb_queue_walk(pktq, pkt_next) {
		/* alignment packet inserted in previous
		 * loop cycle can be skipped as it is
		 * already properly aligned and does not
		 * need an sdpcm header.
		 */
		if (*(u32 *)(pkt_next->cb) & ALIGN_SKB_FLAG)
			continue;
2012

2013 2014 2015 2016 2017 2018 2019
		/* align packet data pointer */
		ret = brcmf_sdio_txpkt_hdalign(bus, pkt_next);
		if (ret < 0)
			return ret;
		head_pad = (u16)ret;
		if (head_pad)
			memset(pkt_next->data, 0, head_pad + bus->tx_hdrlen);
2020

2021
		total_len += pkt_next->len;
2022

2023
		hd_info.len = pkt_next->len;
2024 2025 2026 2027 2028 2029 2030 2031 2032
		hd_info.lastfrm = skb_queue_is_last(pktq, pkt_next);
		if (bus->txglom && pktq->qlen > 1) {
			ret = brcmf_sdio_txpkt_prep_sg(bus, pktq,
						       pkt_next, total_len);
			if (ret < 0)
				return ret;
			hd_info.tail_pad = (u16)ret;
			total_len += (u16)ret;
		}
2033

2034 2035 2036 2037 2038 2039 2040 2041 2042 2043 2044 2045 2046 2047 2048 2049 2050 2051 2052 2053 2054 2055
		hd_info.channel = chan;
		hd_info.dat_offset = head_pad + bus->tx_hdrlen;
		hd_info.seq_num = txseq++;

		/* Now fill the header */
		brcmf_sdio_hdpack(bus, pkt_next->data, &hd_info);

		if (BRCMF_BYTES_ON() &&
		    ((BRCMF_CTL_ON() && chan == SDPCM_CONTROL_CHANNEL) ||
		     (BRCMF_DATA_ON() && chan != SDPCM_CONTROL_CHANNEL)))
			brcmf_dbg_hex_dump(true, pkt_next, hd_info.len,
					   "Tx Frame:\n");
		else if (BRCMF_HDRS_ON())
			brcmf_dbg_hex_dump(true, pkt_next,
					   head_pad + bus->tx_hdrlen,
					   "Tx Header:\n");
	}
	/* Hardware length tag of the first packet should be total
	 * length of the chain (including padding)
	 */
	if (bus->txglom)
		brcmf_sdio_update_hwhdr(pktq->next->data, total_len);
2056 2057
	return 0;
}
2058

2059 2060 2061 2062 2063 2064 2065 2066 2067 2068 2069 2070 2071 2072
/**
 * brcmf_sdio_txpkt_postp - packet post processing for transmit
 * @bus: brcmf_sdio structure pointer
 * @pktq: packet list pointer
 *
 * Processes to be applied to the packet
 *	- Remove head padding
 *	- Remove tail padding
 */
static void
brcmf_sdio_txpkt_postp(struct brcmf_sdio *bus, struct sk_buff_head *pktq)
{
	u8 *hdr;
	u32 dat_offset;
2073
	u16 tail_pad;
2074 2075 2076 2077 2078
	u32 dummy_flags, chop_len;
	struct sk_buff *pkt_next, *tmp, *pkt_prev;

	skb_queue_walk_safe(pktq, pkt_next, tmp) {
		dummy_flags = *(u32 *)(pkt_next->cb);
2079 2080
		if (dummy_flags & ALIGN_SKB_FLAG) {
			chop_len = dummy_flags & ALIGN_SKB_CHOP_LEN_MASK;
2081 2082 2083 2084 2085 2086 2087
			if (chop_len) {
				pkt_prev = pkt_next->prev;
				skb_put(pkt_prev, chop_len);
			}
			__skb_unlink(pkt_next, pktq);
			brcmu_pkt_buf_free_skb(pkt_next);
		} else {
2088
			hdr = pkt_next->data + bus->tx_hdrlen - SDPCM_SWHDR_LEN;
2089 2090 2091 2092
			dat_offset = le32_to_cpu(*(__le32 *)hdr);
			dat_offset = (dat_offset & SDPCM_DOFFSET_MASK) >>
				     SDPCM_DOFFSET_SHIFT;
			skb_pull(pkt_next, dat_offset);
2093 2094 2095 2096
			if (bus->txglom) {
				tail_pad = le16_to_cpu(*(__le16 *)(hdr - 2));
				skb_trim(pkt_next, pkt_next->len - tail_pad);
			}
2097
		}
2098
	}
2099
}
2100

2101 2102
/* Writes a HW/SW header into the packet and sends it. */
/* Assumes: (a) header space already there, (b) caller holds lock */
2103 2104
static int brcmf_sdio_txpkt(struct brcmf_sdio *bus, struct sk_buff_head *pktq,
			    uint chan)
2105 2106 2107
{
	int ret;
	int i;
2108
	struct sk_buff *pkt_next, *tmp;
2109 2110 2111

	brcmf_dbg(TRACE, "Enter\n");

2112
	ret = brcmf_sdio_txpkt_prep(bus, pktq, chan);
2113 2114
	if (ret)
		goto done;
2115

2116
	sdio_claim_host(bus->sdiodev->func[1]);
2117
	ret = brcmf_sdiod_send_pkt(bus->sdiodev, pktq);
2118
	bus->sdcnt.f2txdata++;
2119 2120 2121 2122 2123

	if (ret < 0) {
		/* On failure, abort the command and terminate the frame */
		brcmf_dbg(INFO, "sdio error %d, abort command and terminate frame\n",
			  ret);
2124
		bus->sdcnt.tx_sderrs++;
2125

2126 2127 2128
		brcmf_sdiod_abort(bus->sdiodev, SDIO_FUNC_2);
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_FRAMECTRL,
				  SFC_WF_TERM, NULL);
2129
		bus->sdcnt.f1regdata++;
2130 2131 2132

		for (i = 0; i < 3; i++) {
			u8 hi, lo;
2133 2134 2135 2136
			hi = brcmf_sdiod_regrb(bus->sdiodev,
					       SBSDIO_FUNC1_WFRAMEBCHI, NULL);
			lo = brcmf_sdiod_regrb(bus->sdiodev,
					       SBSDIO_FUNC1_WFRAMEBCLO, NULL);
2137
			bus->sdcnt.f1regdata += 2;
2138 2139 2140 2141
			if ((hi == 0) && (lo == 0))
				break;
		}
	}
2142
	sdio_release_host(bus->sdiodev->func[1]);
2143 2144

done:
2145 2146 2147 2148 2149 2150 2151
	brcmf_sdio_txpkt_postp(bus, pktq);
	if (ret == 0)
		bus->tx_seq = (bus->tx_seq + pktq->qlen) % SDPCM_SEQ_WRAP;
	skb_queue_walk_safe(pktq, pkt_next, tmp) {
		__skb_unlink(pkt_next, pktq);
		brcmf_txcomplete(bus->sdiodev->dev, pkt_next, ret == 0);
	}
2152 2153 2154
	return ret;
}

2155
static uint brcmf_sdio_sendfromq(struct brcmf_sdio *bus, uint maxframes)
2156 2157
{
	struct sk_buff *pkt;
2158
	struct sk_buff_head pktq;
2159
	u32 intstatus = 0;
2160
	int ret = 0, prec_out, i;
2161
	uint cnt = 0;
2162
	u8 tx_prec_map, pkt_num;
2163 2164 2165 2166 2167 2168

	brcmf_dbg(TRACE, "Enter\n");

	tx_prec_map = ~bus->flowcontrol;

	/* Send frames until the limit or some other event */
2169 2170 2171 2172 2173 2174 2175 2176
	for (cnt = 0; (cnt < maxframes) && data_ok(bus);) {
		pkt_num = 1;
		__skb_queue_head_init(&pktq);
		if (bus->txglom)
			pkt_num = min_t(u8, bus->tx_max - bus->tx_seq,
					brcmf_sdio_txglomsz);
		pkt_num = min_t(u32, pkt_num,
				brcmu_pktq_mlen(&bus->txq, ~bus->flowcontrol));
2177
		spin_lock_bh(&bus->txqlock);
2178 2179 2180 2181 2182 2183
		for (i = 0; i < pkt_num; i++) {
			pkt = brcmu_pktq_mdeq(&bus->txq, tx_prec_map,
					      &prec_out);
			if (pkt == NULL)
				break;
			__skb_queue_tail(&pktq, pkt);
2184 2185
		}
		spin_unlock_bh(&bus->txqlock);
2186 2187
		if (i == 0)
			break;
2188

2189
		ret = brcmf_sdio_txpkt(bus, &pktq, SDPCM_DATA_CHANNEL);
2190
		cnt += i;
2191 2192 2193 2194

		/* In poll mode, need to check for other events */
		if (!bus->intr && cnt) {
			/* Check device status, signal pending interrupt */
2195
			sdio_claim_host(bus->sdiodev->func[1]);
2196 2197 2198
			ret = r_sdreg32(bus, &intstatus,
					offsetof(struct sdpcmd_regs,
						 intstatus));
2199
			sdio_release_host(bus->sdiodev->func[1]);
2200
			bus->sdcnt.f2txdata++;
2201
			if (ret != 0)
2202 2203
				break;
			if (intstatus & bus->hostintmask)
2204
				atomic_set(&bus->ipend, 1);
2205 2206 2207 2208
		}
	}

	/* Deflow-control stack if needed */
2209
	if ((bus->sdiodev->bus_if->state == BRCMF_BUS_DATA) &&
2210
	    bus->txoff && (pktq_len(&bus->txq) < TXLOW)) {
2211 2212
		bus->txoff = false;
		brcmf_txflowblock(bus->sdiodev->dev, false);
2213
	}
2214 2215 2216 2217

	return cnt;
}

2218
static void brcmf_sdio_bus_stop(struct device *dev)
2219 2220 2221 2222 2223
{
	u32 local_hostintmask;
	u8 saveclk;
	int err;
	struct brcmf_bus *bus_if = dev_get_drvdata(dev);
2224
	struct brcmf_sdio_dev *sdiodev = bus_if->bus_priv.sdio;
2225 2226 2227 2228 2229 2230 2231 2232 2233 2234
	struct brcmf_sdio *bus = sdiodev->bus;

	brcmf_dbg(TRACE, "Enter\n");

	if (bus->watchdog_tsk) {
		send_sig(SIGTERM, bus->watchdog_tsk, 1);
		kthread_stop(bus->watchdog_tsk);
		bus->watchdog_tsk = NULL;
	}

2235
	sdio_claim_host(bus->sdiodev->func[1]);
2236 2237

	/* Enable clock for device interrupts */
2238
	brcmf_sdio_bus_sleep(bus, false, false);
2239 2240

	/* Disable and clear interrupts at the chip level also */
2241
	w_sdreg32(bus, 0, offsetof(struct sdpcmd_regs, hostintmask));
2242 2243 2244 2245 2246 2247 2248
	local_hostintmask = bus->hostintmask;
	bus->hostintmask = 0;

	/* Change our idea of bus state */
	bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;

	/* Force clocks on backplane to be sure F2 interrupt propagates */
2249 2250
	saveclk = brcmf_sdiod_regrb(bus->sdiodev,
				    SBSDIO_FUNC1_CHIPCLKCSR, &err);
2251
	if (!err) {
2252 2253
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR,
				  (saveclk | SBSDIO_FORCE_HT), &err);
2254 2255
	}
	if (err)
2256
		brcmf_err("Failed to force clock for F2: err %d\n", err);
2257 2258 2259

	/* Turn off the bus (F2), free any pending packets */
	brcmf_dbg(INTR, "disable SDIO interrupts\n");
2260
	sdio_disable_func(bus->sdiodev->func[SDIO_FUNC_2]);
2261 2262 2263

	/* Clear any pending interrupts now that F2 is disabled */
	w_sdreg32(bus, local_hostintmask,
2264
		  offsetof(struct sdpcmd_regs, intstatus));
2265

2266
	sdio_release_host(bus->sdiodev->func[1]);
2267 2268 2269 2270 2271 2272 2273

	/* Clear the data packet queues */
	brcmu_pktq_flush(&bus->txq, true, NULL, NULL);

	/* Clear any held glomming stuff */
	if (bus->glomd)
		brcmu_pkt_buf_free_skb(bus->glomd);
2274
	brcmf_sdio_free_glom(bus);
2275 2276

	/* Clear rx control and wake any waiters */
2277
	spin_lock_bh(&bus->rxctl_lock);
2278
	bus->rxlen = 0;
2279
	spin_unlock_bh(&bus->rxctl_lock);
2280
	brcmf_sdio_dcmd_resp_wake(bus);
2281 2282 2283 2284 2285 2286

	/* Reset some F2 state stuff */
	bus->rxskip = false;
	bus->tx_seq = bus->rx_seq = 0;
}

2287
static inline void brcmf_sdio_clrintr(struct brcmf_sdio *bus)
2288 2289 2290
{
	unsigned long flags;

2291 2292 2293 2294 2295 2296 2297
	if (bus->sdiodev->oob_irq_requested) {
		spin_lock_irqsave(&bus->sdiodev->irq_en_lock, flags);
		if (!bus->sdiodev->irq_en && !atomic_read(&bus->ipend)) {
			enable_irq(bus->sdiodev->pdata->oob_irq_nr);
			bus->sdiodev->irq_en = true;
		}
		spin_unlock_irqrestore(&bus->sdiodev->irq_en_lock, flags);
2298 2299 2300
	}
}

2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311
static int brcmf_sdio_intr_rstatus(struct brcmf_sdio *bus)
{
	u8 idx;
	u32 addr;
	unsigned long val;
	int n, ret;

	idx = brcmf_sdio_chip_getinfidx(bus->ci, BCMA_CORE_SDIO_DEV);
	addr = bus->ci->c_inf[idx].base +
	       offsetof(struct sdpcmd_regs, intstatus);

2312
	val = brcmf_sdiod_regrl(bus->sdiodev, addr, &ret);
2313 2314 2315 2316 2317 2318 2319 2320 2321
	bus->sdcnt.f1regdata++;
	if (ret != 0)
		val = 0;

	val &= bus->hostintmask;
	atomic_set(&bus->fcstate, !!(val & I_HMB_FC_STATE));

	/* Clear interrupts */
	if (val) {
2322
		brcmf_sdiod_regwl(bus->sdiodev, addr, val, &ret);
2323 2324 2325 2326 2327 2328 2329 2330 2331 2332 2333 2334 2335
		bus->sdcnt.f1regdata++;
	}

	if (ret) {
		atomic_set(&bus->intstatus, 0);
	} else if (val) {
		for_each_set_bit(n, &val, 32)
			set_bit(n, (unsigned long *)&bus->intstatus.counter);
	}

	return ret;
}

2336
static void brcmf_sdio_dpc(struct brcmf_sdio *bus)
2337
{
2338 2339
	u32 newstatus = 0;
	unsigned long intstatus;
2340 2341 2342
	uint rxlimit = bus->rxbound;	/* Rx frames to read before resched */
	uint txlimit = bus->txbound;	/* Tx frames to send before resched */
	uint framecnt = 0;	/* Temporary counter of tx/rx frames */
2343
	int err = 0, n;
2344 2345 2346

	brcmf_dbg(TRACE, "Enter\n");

2347
	sdio_claim_host(bus->sdiodev->func[1]);
2348 2349

	/* If waiting for HTAVAIL, check status */
2350
	if (!bus->sr_enabled && bus->clkstate == CLK_PENDING) {
2351 2352
		u8 clkctl, devctl = 0;

J
Joe Perches 已提交
2353
#ifdef DEBUG
2354
		/* Check for inconsistent device control */
2355 2356
		devctl = brcmf_sdiod_regrb(bus->sdiodev,
					   SBSDIO_DEVICE_CTL, &err);
2357
		if (err) {
2358
			brcmf_err("error reading DEVCTL: %d\n", err);
2359
			bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
2360
		}
J
Joe Perches 已提交
2361
#endif				/* DEBUG */
2362 2363

		/* Read CSR, if clock on switch to AVAIL, else ignore */
2364 2365
		clkctl = brcmf_sdiod_regrb(bus->sdiodev,
					   SBSDIO_FUNC1_CHIPCLKCSR, &err);
2366
		if (err) {
2367
			brcmf_err("error reading CSR: %d\n",
2368
				  err);
2369
			bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
2370 2371
		}

2372
		brcmf_dbg(SDIO, "DPC: PENDING, devctl 0x%02x clkctl 0x%02x\n",
2373 2374 2375
			  devctl, clkctl);

		if (SBSDIO_HTAV(clkctl)) {
2376 2377
			devctl = brcmf_sdiod_regrb(bus->sdiodev,
						   SBSDIO_DEVICE_CTL, &err);
2378
			if (err) {
2379
				brcmf_err("error reading DEVCTL: %d\n",
2380
					  err);
2381
				bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
2382 2383
			}
			devctl &= ~SBSDIO_DEVCTL_CA_INT_ONLY;
2384 2385
			brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_DEVICE_CTL,
					  devctl, &err);
2386
			if (err) {
2387
				brcmf_err("error writing DEVCTL: %d\n",
2388
					  err);
2389
				bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
2390 2391 2392 2393 2394 2395
			}
			bus->clkstate = CLK_AVAIL;
		}
	}

	/* Make sure backplane clock is on */
2396
	brcmf_sdio_bus_sleep(bus, false, true);
2397 2398

	/* Pending interrupt indicates new device status */
2399 2400
	if (atomic_read(&bus->ipend) > 0) {
		atomic_set(&bus->ipend, 0);
2401
		err = brcmf_sdio_intr_rstatus(bus);
2402 2403
	}

2404 2405
	/* Start with leftover status bits */
	intstatus = atomic_xchg(&bus->intstatus, 0);
2406 2407 2408 2409 2410 2411 2412

	/* Handle flow-control change: read new state in case our ack
	 * crossed another change interrupt.  If change still set, assume
	 * FC ON for safety, let next loop through do the debounce.
	 */
	if (intstatus & I_HMB_FC_CHANGE) {
		intstatus &= ~I_HMB_FC_CHANGE;
2413 2414
		err = w_sdreg32(bus, I_HMB_FC_CHANGE,
				offsetof(struct sdpcmd_regs, intstatus));
2415

2416 2417
		err = r_sdreg32(bus, &newstatus,
				offsetof(struct sdpcmd_regs, intstatus));
2418
		bus->sdcnt.f1regdata += 2;
2419 2420
		atomic_set(&bus->fcstate,
			   !!(newstatus & (I_HMB_FC_STATE | I_HMB_FC_CHANGE)));
2421 2422 2423 2424 2425 2426
		intstatus |= (newstatus & bus->hostintmask);
	}

	/* Handle host mailbox indication */
	if (intstatus & I_HMB_HOST_INT) {
		intstatus &= ~I_HMB_HOST_INT;
2427
		intstatus |= brcmf_sdio_hostmail(bus);
2428 2429
	}

2430
	sdio_release_host(bus->sdiodev->func[1]);
2431

2432 2433
	/* Generally don't ask for these, can get CRC errors... */
	if (intstatus & I_WR_OOSYNC) {
2434
		brcmf_err("Dongle reports WR_OOSYNC\n");
2435 2436 2437 2438
		intstatus &= ~I_WR_OOSYNC;
	}

	if (intstatus & I_RD_OOSYNC) {
2439
		brcmf_err("Dongle reports RD_OOSYNC\n");
2440 2441 2442 2443
		intstatus &= ~I_RD_OOSYNC;
	}

	if (intstatus & I_SBINT) {
2444
		brcmf_err("Dongle reports SBINT\n");
2445 2446 2447 2448 2449 2450 2451 2452 2453 2454 2455 2456 2457 2458
		intstatus &= ~I_SBINT;
	}

	/* Would be active due to wake-wlan in gSPI */
	if (intstatus & I_CHIPACTIVE) {
		brcmf_dbg(INFO, "Dongle reports CHIPACTIVE\n");
		intstatus &= ~I_CHIPACTIVE;
	}

	/* Ignore frame indications if rxskip is set */
	if (bus->rxskip)
		intstatus &= ~I_HMB_FRAME_IND;

	/* On frame indication, read available frames */
F
Franky Lin 已提交
2459
	if (PKT_AVAILABLE() && bus->clkstate == CLK_AVAIL) {
2460 2461
		framecnt = brcmf_sdio_readframes(bus, rxlimit);
		if (!bus->rxpending)
2462 2463 2464 2465 2466
			intstatus &= ~I_HMB_FRAME_IND;
		rxlimit -= min(framecnt, rxlimit);
	}

	/* Keep still-pending events for next scheduling */
2467 2468 2469 2470
	if (intstatus) {
		for_each_set_bit(n, &intstatus, 32)
			set_bit(n, (unsigned long *)&bus->intstatus.counter);
	}
2471

2472
	brcmf_sdio_clrintr(bus);
2473

2474 2475
	if (data_ok(bus) && bus->ctrl_frame_stat &&
		(bus->clkstate == CLK_AVAIL)) {
F
Franky Lin 已提交
2476
		int i;
2477

2478
		sdio_claim_host(bus->sdiodev->func[1]);
2479
		err = brcmf_sdiod_send_buf(bus->sdiodev, bus->ctrl_frame_buf,
2480
					   (u32)bus->ctrl_frame_len);
2481

F
Franky Lin 已提交
2482
		if (err < 0) {
2483 2484 2485
			/* On failure, abort the command and
				terminate the frame */
			brcmf_dbg(INFO, "sdio error %d, abort command and terminate frame\n",
F
Franky Lin 已提交
2486
				  err);
2487
			bus->sdcnt.tx_sderrs++;
2488

2489
			brcmf_sdiod_abort(bus->sdiodev, SDIO_FUNC_2);
2490

2491 2492
			brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_FRAMECTRL,
					  SFC_WF_TERM, &err);
2493
			bus->sdcnt.f1regdata++;
2494 2495 2496

			for (i = 0; i < 3; i++) {
				u8 hi, lo;
2497 2498 2499 2500 2501 2502
				hi = brcmf_sdiod_regrb(bus->sdiodev,
						       SBSDIO_FUNC1_WFRAMEBCHI,
						       &err);
				lo = brcmf_sdiod_regrb(bus->sdiodev,
						       SBSDIO_FUNC1_WFRAMEBCLO,
						       &err);
2503
				bus->sdcnt.f1regdata += 2;
2504 2505 2506 2507
				if ((hi == 0) && (lo == 0))
					break;
			}

F
Franky Lin 已提交
2508
		} else {
2509
			bus->tx_seq = (bus->tx_seq + 1) % SDPCM_SEQ_WRAP;
F
Franky Lin 已提交
2510
		}
2511
		sdio_release_host(bus->sdiodev->func[1]);
2512
		bus->ctrl_frame_stat = false;
2513
		brcmf_sdio_wait_event_wakeup(bus);
2514 2515
	}
	/* Send queued frames (limit 1 if rx may still be pending) */
2516
	else if ((bus->clkstate == CLK_AVAIL) && !atomic_read(&bus->fcstate) &&
2517 2518
		 brcmu_pktq_mlen(&bus->txq, ~bus->flowcontrol) && txlimit
		 && data_ok(bus)) {
2519 2520
		framecnt = bus->rxpending ? min(txlimit, bus->txminmax) :
					    txlimit;
2521
		framecnt = brcmf_sdio_sendfromq(bus, framecnt);
2522 2523 2524
		txlimit -= framecnt;
	}

2525
	if ((bus->sdiodev->bus_if->state == BRCMF_BUS_DOWN) || (err != 0)) {
2526
		brcmf_err("failed backplane access over SDIO, halting operation\n");
2527
		bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
2528 2529 2530 2531 2532 2533
		atomic_set(&bus->intstatus, 0);
	} else if (atomic_read(&bus->intstatus) ||
		   atomic_read(&bus->ipend) > 0 ||
		   (!atomic_read(&bus->fcstate) &&
		    brcmu_pktq_mlen(&bus->txq, ~bus->flowcontrol) &&
		    data_ok(bus)) || PKT_AVAILABLE()) {
2534
		atomic_inc(&bus->dpc_tskcnt);
2535 2536 2537 2538 2539 2540
	}

	/* If we're done for now, turn off clock request. */
	if ((bus->clkstate != CLK_PENDING)
	    && bus->idletime == BRCMF_IDLE_IMMEDIATE) {
		bus->activity = false;
2541
		brcmf_dbg(SDIO, "idle state\n");
2542
		sdio_claim_host(bus->sdiodev->func[1]);
2543
		brcmf_sdio_bus_sleep(bus, true, false);
2544
		sdio_release_host(bus->sdiodev->func[1]);
2545 2546 2547
	}
}

2548
static struct pktq *brcmf_sdio_bus_gettxq(struct device *dev)
2549 2550 2551 2552 2553 2554 2555 2556
{
	struct brcmf_bus *bus_if = dev_get_drvdata(dev);
	struct brcmf_sdio_dev *sdiodev = bus_if->bus_priv.sdio;
	struct brcmf_sdio *bus = sdiodev->bus;

	return &bus->txq;
}

2557
static int brcmf_sdio_bus_txdata(struct device *dev, struct sk_buff *pkt)
2558 2559 2560
{
	int ret = -EBADE;
	uint datalen, prec;
2561
	struct brcmf_bus *bus_if = dev_get_drvdata(dev);
2562
	struct brcmf_sdio_dev *sdiodev = bus_if->bus_priv.sdio;
2563
	struct brcmf_sdio *bus = sdiodev->bus;
2564
	ulong flags;
2565 2566 2567 2568 2569 2570

	brcmf_dbg(TRACE, "Enter\n");

	datalen = pkt->len;

	/* Add space for the header */
2571
	skb_push(pkt, bus->tx_hdrlen);
2572 2573 2574 2575 2576 2577 2578
	/* precondition: IS_ALIGNED((unsigned long)(pkt->data), 2) */

	prec = prio2prec((pkt->priority & PRIOMASK));

	/* Check for existing queue, current flow-control,
			 pending event, or pending clock */
	brcmf_dbg(TRACE, "deferring pktq len %d\n", pktq_len(&bus->txq));
2579
	bus->sdcnt.fcqueued++;
2580 2581

	/* Priority based enq */
2582
	spin_lock_irqsave(&bus->txqlock, flags);
2583
	if (!brcmf_c_prec_enq(bus->sdiodev->dev, &bus->txq, pkt, prec)) {
2584
		skb_pull(pkt, bus->tx_hdrlen);
2585
		brcmf_err("out of bus->txq !!!\n");
2586 2587 2588 2589 2590
		ret = -ENOSR;
	} else {
		ret = 0;
	}

2591
	if (pktq_len(&bus->txq) >= TXHI) {
2592 2593
		bus->txoff = true;
		brcmf_txflowblock(bus->sdiodev->dev, true);
2594
	}
2595
	spin_unlock_irqrestore(&bus->txqlock, flags);
2596

J
Joe Perches 已提交
2597
#ifdef DEBUG
2598 2599 2600
	if (pktq_plen(&bus->txq, prec) > qcount[prec])
		qcount[prec] = pktq_plen(&bus->txq, prec);
#endif
2601

2602 2603
	if (atomic_read(&bus->dpc_tskcnt) == 0) {
		atomic_inc(&bus->dpc_tskcnt);
2604
		queue_work(bus->brcmf_wq, &bus->datawork);
2605 2606 2607 2608 2609
	}

	return ret;
}

J
Joe Perches 已提交
2610
#ifdef DEBUG
2611 2612
#define CONSOLE_LINE_MAX	192

2613
static int brcmf_sdio_readconsole(struct brcmf_sdio *bus)
2614 2615 2616 2617 2618 2619 2620 2621 2622 2623 2624 2625
{
	struct brcmf_console *c = &bus->console;
	u8 line[CONSOLE_LINE_MAX], ch;
	u32 n, idx, addr;
	int rv;

	/* Don't do anything until FWREADY updates console address */
	if (bus->console_addr == 0)
		return 0;

	/* Read console log struct */
	addr = bus->console_addr + offsetof(struct rte_console, log_le);
2626 2627
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, addr, (u8 *)&c->log_le,
			       sizeof(c->log_le));
2628 2629 2630 2631 2632 2633 2634 2635 2636 2637 2638 2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650 2651
	if (rv < 0)
		return rv;

	/* Allocate console buffer (one time only) */
	if (c->buf == NULL) {
		c->bufsize = le32_to_cpu(c->log_le.buf_size);
		c->buf = kmalloc(c->bufsize, GFP_ATOMIC);
		if (c->buf == NULL)
			return -ENOMEM;
	}

	idx = le32_to_cpu(c->log_le.idx);

	/* Protect against corrupt value */
	if (idx > c->bufsize)
		return -EBADE;

	/* Skip reading the console buffer if the index pointer
	 has not moved */
	if (idx == c->last)
		return 0;

	/* Read the console buffer */
	addr = le32_to_cpu(c->log_le.buf);
2652
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, addr, c->buf, c->bufsize);
2653 2654 2655 2656 2657 2658 2659 2660 2661 2662 2663 2664 2665 2666 2667 2668 2669 2670 2671 2672 2673 2674 2675 2676 2677 2678 2679 2680
	if (rv < 0)
		return rv;

	while (c->last != idx) {
		for (n = 0; n < CONSOLE_LINE_MAX - 2; n++) {
			if (c->last == idx) {
				/* This would output a partial line.
				 * Instead, back up
				 * the buffer pointer and output this
				 * line next time around.
				 */
				if (c->last >= n)
					c->last -= n;
				else
					c->last = c->bufsize - n;
				goto break2;
			}
			ch = c->buf[c->last];
			c->last = (c->last + 1) % c->bufsize;
			if (ch == '\n')
				break;
			line[n] = ch;
		}

		if (n > 0) {
			if (line[n - 1] == '\r')
				n--;
			line[n] = 0;
2681
			pr_debug("CONSOLE: %s\n", line);
2682 2683 2684 2685 2686 2687
		}
	}
break2:

	return 0;
}
J
Joe Perches 已提交
2688
#endif				/* DEBUG */
2689

2690
static int brcmf_sdio_tx_frame(struct brcmf_sdio *bus, u8 *frame, u16 len)
2691 2692 2693 2694 2695
{
	int i;
	int ret;

	bus->ctrl_frame_stat = false;
2696
	ret = brcmf_sdiod_send_buf(bus->sdiodev, frame, len);
2697 2698 2699 2700 2701

	if (ret < 0) {
		/* On failure, abort the command and terminate the frame */
		brcmf_dbg(INFO, "sdio error %d, abort command and terminate frame\n",
			  ret);
2702
		bus->sdcnt.tx_sderrs++;
2703

2704
		brcmf_sdiod_abort(bus->sdiodev, SDIO_FUNC_2);
2705

2706 2707
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_FRAMECTRL,
				  SFC_WF_TERM, NULL);
2708
		bus->sdcnt.f1regdata++;
2709 2710 2711

		for (i = 0; i < 3; i++) {
			u8 hi, lo;
2712 2713 2714 2715
			hi = brcmf_sdiod_regrb(bus->sdiodev,
					       SBSDIO_FUNC1_WFRAMEBCHI, NULL);
			lo = brcmf_sdiod_regrb(bus->sdiodev,
					       SBSDIO_FUNC1_WFRAMEBCLO, NULL);
2716
			bus->sdcnt.f1regdata += 2;
2717 2718 2719 2720 2721 2722
			if (hi == 0 && lo == 0)
				break;
		}
		return ret;
	}

2723
	bus->tx_seq = (bus->tx_seq + 1) % SDPCM_SEQ_WRAP;
2724 2725 2726 2727

	return ret;
}

2728
static int
2729
brcmf_sdio_bus_txctl(struct device *dev, unsigned char *msg, uint msglen)
2730 2731
{
	u8 *frame;
2732
	u16 len, pad;
2733 2734 2735
	uint retries = 0;
	u8 doff = 0;
	int ret = -1;
2736
	struct brcmf_bus *bus_if = dev_get_drvdata(dev);
2737
	struct brcmf_sdio_dev *sdiodev = bus_if->bus_priv.sdio;
2738
	struct brcmf_sdio *bus = sdiodev->bus;
2739
	struct brcmf_sdio_hdrinfo hd_info = {0};
2740 2741 2742 2743

	brcmf_dbg(TRACE, "Enter\n");

	/* Back the pointer to make a room for bus header */
2744 2745
	frame = msg - bus->tx_hdrlen;
	len = (msglen += bus->tx_hdrlen);
2746 2747

	/* Add alignment padding (optional for ctl frames) */
2748
	doff = ((unsigned long)frame % bus->head_align);
2749 2750 2751 2752
	if (doff) {
		frame -= doff;
		len += doff;
		msglen += doff;
2753
		memset(frame, 0, doff + bus->tx_hdrlen);
2754
	}
2755
	/* precondition: doff < bus->head_align */
2756
	doff += bus->tx_hdrlen;
2757 2758

	/* Round send length to next SDIO block */
2759
	pad = 0;
2760
	if (bus->roundup && bus->blocksize && (len > bus->blocksize)) {
2761 2762 2763
		pad = bus->blocksize - (len % bus->blocksize);
		if ((pad > bus->roundup) || (pad >= bus->blocksize))
			pad = 0;
2764 2765
	} else if (len % bus->head_align) {
		pad = bus->head_align - (len % bus->head_align);
2766
	}
2767
	len += pad;
2768 2769 2770 2771

	/* precondition: IS_ALIGNED((unsigned long)frame, 2) */

	/* Make sure backplane clock is on */
2772
	sdio_claim_host(bus->sdiodev->func[1]);
2773
	brcmf_sdio_bus_sleep(bus, false, false);
2774
	sdio_release_host(bus->sdiodev->func[1]);
2775

2776 2777 2778
	hd_info.len = (u16)msglen;
	hd_info.channel = SDPCM_CONTROL_CHANNEL;
	hd_info.dat_offset = doff;
2779
	hd_info.seq_num = bus->tx_seq;
2780 2781
	hd_info.lastfrm = true;
	hd_info.tail_pad = pad;
2782
	brcmf_sdio_hdpack(bus, frame, &hd_info);
2783

2784 2785 2786
	if (bus->txglom)
		brcmf_sdio_update_hwhdr(frame, len);

2787 2788 2789 2790 2791 2792 2793 2794
	if (!data_ok(bus)) {
		brcmf_dbg(INFO, "No bus credit bus->tx_max %d, bus->tx_seq %d\n",
			  bus->tx_max, bus->tx_seq);
		bus->ctrl_frame_stat = true;
		/* Send from dpc */
		bus->ctrl_frame_buf = frame;
		bus->ctrl_frame_len = len;

2795 2796 2797
		wait_event_interruptible_timeout(bus->ctrl_wait,
						 !bus->ctrl_frame_stat,
						 msecs_to_jiffies(2000));
2798

2799
		if (!bus->ctrl_frame_stat) {
2800
			brcmf_dbg(SDIO, "ctrl_frame_stat == false\n");
2801 2802
			ret = 0;
		} else {
2803
			brcmf_dbg(SDIO, "ctrl_frame_stat == true\n");
2804 2805 2806 2807 2808
			ret = -1;
		}
	}

	if (ret == -1) {
2809 2810 2811 2812 2813
		brcmf_dbg_hex_dump(BRCMF_BYTES_ON() && BRCMF_CTL_ON(),
				   frame, len, "Tx Frame:\n");
		brcmf_dbg_hex_dump(!(BRCMF_BYTES_ON() && BRCMF_CTL_ON()) &&
				   BRCMF_HDRS_ON(),
				   frame, min_t(u16, len, 16), "TxHdr:\n");
2814 2815

		do {
2816
			sdio_claim_host(bus->sdiodev->func[1]);
2817
			ret = brcmf_sdio_tx_frame(bus, frame, len);
2818
			sdio_release_host(bus->sdiodev->func[1]);
2819 2820 2821
		} while (ret < 0 && retries++ < TXRETRIES);
	}

2822
	if ((bus->idletime == BRCMF_IDLE_IMMEDIATE) &&
2823
	    atomic_read(&bus->dpc_tskcnt) == 0) {
2824
		bus->activity = false;
2825
		sdio_claim_host(bus->sdiodev->func[1]);
2826
		brcmf_dbg(INFO, "idle\n");
2827
		brcmf_sdio_clkctl(bus, CLK_NONE, true);
2828
		sdio_release_host(bus->sdiodev->func[1]);
2829 2830 2831
	}

	if (ret)
2832
		bus->sdcnt.tx_ctlerrs++;
2833
	else
2834
		bus->sdcnt.tx_ctlpkts++;
2835 2836 2837 2838

	return ret ? -EIO : 0;
}

2839
#ifdef DEBUG
2840 2841 2842 2843 2844 2845 2846 2847 2848 2849 2850 2851 2852 2853
static inline bool brcmf_sdio_valid_shared_address(u32 addr)
{
	return !(addr == 0 || ((~addr >> 16) & 0xffff) == (addr & 0xffff));
}

static int brcmf_sdio_readshared(struct brcmf_sdio *bus,
				 struct sdpcm_shared *sh)
{
	u32 addr;
	int rv;
	u32 shaddr = 0;
	struct sdpcm_shared_le sh_le;
	__le32 addr_le;

2854
	shaddr = bus->ci->rambase + bus->ramsize - 4;
2855 2856 2857 2858 2859

	/*
	 * Read last word in socram to determine
	 * address of sdpcm_shared structure
	 */
2860
	sdio_claim_host(bus->sdiodev->func[1]);
2861
	brcmf_sdio_bus_sleep(bus, false, false);
2862
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, shaddr, (u8 *)&addr_le, 4);
2863
	sdio_release_host(bus->sdiodev->func[1]);
2864 2865 2866 2867 2868
	if (rv < 0)
		return rv;

	addr = le32_to_cpu(addr_le);

2869
	brcmf_dbg(SDIO, "sdpcm_shared address 0x%08X\n", addr);
2870 2871 2872 2873 2874 2875

	/*
	 * Check if addr is valid.
	 * NVRAM length at the end of memory should have been overwritten.
	 */
	if (!brcmf_sdio_valid_shared_address(addr)) {
2876
			brcmf_err("invalid sdpcm_shared address 0x%08X\n",
2877 2878 2879 2880 2881
				  addr);
			return -EINVAL;
	}

	/* Read hndrte_shared structure */
2882 2883
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, addr, (u8 *)&sh_le,
			       sizeof(struct sdpcm_shared_le));
2884 2885 2886 2887 2888 2889 2890 2891 2892 2893 2894 2895
	if (rv < 0)
		return rv;

	/* Endianness */
	sh->flags = le32_to_cpu(sh_le.flags);
	sh->trap_addr = le32_to_cpu(sh_le.trap_addr);
	sh->assert_exp_addr = le32_to_cpu(sh_le.assert_exp_addr);
	sh->assert_file_addr = le32_to_cpu(sh_le.assert_file_addr);
	sh->assert_line = le32_to_cpu(sh_le.assert_line);
	sh->console_addr = le32_to_cpu(sh_le.console_addr);
	sh->msgtrace_addr = le32_to_cpu(sh_le.msgtrace_addr);

2896 2897
	if ((sh->flags & SDPCM_SHARED_VERSION_MASK) > SDPCM_SHARED_VERSION) {
		brcmf_err("sdpcm shared version unsupported: dhd %d dongle %d\n",
2898 2899 2900 2901 2902 2903 2904 2905 2906 2907 2908 2909 2910 2911 2912 2913 2914 2915 2916 2917 2918
			  SDPCM_SHARED_VERSION,
			  sh->flags & SDPCM_SHARED_VERSION_MASK);
		return -EPROTO;
	}

	return 0;
}

static int brcmf_sdio_dump_console(struct brcmf_sdio *bus,
				   struct sdpcm_shared *sh, char __user *data,
				   size_t count)
{
	u32 addr, console_ptr, console_size, console_index;
	char *conbuf = NULL;
	__le32 sh_val;
	int rv;
	loff_t pos = 0;
	int nbytes = 0;

	/* obtain console information from device memory */
	addr = sh->console_addr + offsetof(struct rte_console, log_le);
2919 2920
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, addr,
			       (u8 *)&sh_val, sizeof(u32));
2921 2922 2923 2924 2925
	if (rv < 0)
		return rv;
	console_ptr = le32_to_cpu(sh_val);

	addr = sh->console_addr + offsetof(struct rte_console, log_le.buf_size);
2926 2927
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, addr,
			       (u8 *)&sh_val, sizeof(u32));
2928 2929 2930 2931 2932
	if (rv < 0)
		return rv;
	console_size = le32_to_cpu(sh_val);

	addr = sh->console_addr + offsetof(struct rte_console, log_le.idx);
2933 2934
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, addr,
			       (u8 *)&sh_val, sizeof(u32));
2935 2936 2937 2938 2939 2940 2941 2942 2943 2944 2945 2946 2947
	if (rv < 0)
		return rv;
	console_index = le32_to_cpu(sh_val);

	/* allocate buffer for console data */
	if (console_size <= CONSOLE_BUFFER_MAX)
		conbuf = vzalloc(console_size+1);

	if (!conbuf)
		return -ENOMEM;

	/* obtain the console data from device */
	conbuf[console_size] = '\0';
2948 2949
	rv = brcmf_sdiod_ramrw(bus->sdiodev, false, console_ptr, (u8 *)conbuf,
			       console_size);
2950 2951 2952 2953 2954 2955 2956 2957 2958 2959 2960 2961 2962 2963 2964 2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975 2976 2977 2978 2979 2980
	if (rv < 0)
		goto done;

	rv = simple_read_from_buffer(data, count, &pos,
				     conbuf + console_index,
				     console_size - console_index);
	if (rv < 0)
		goto done;

	nbytes = rv;
	if (console_index > 0) {
		pos = 0;
		rv = simple_read_from_buffer(data+nbytes, count, &pos,
					     conbuf, console_index - 1);
		if (rv < 0)
			goto done;
		rv += nbytes;
	}
done:
	vfree(conbuf);
	return rv;
}

static int brcmf_sdio_trap_info(struct brcmf_sdio *bus, struct sdpcm_shared *sh,
				char __user *data, size_t count)
{
	int error, res;
	char buf[350];
	struct brcmf_trap_info tr;
	loff_t pos = 0;

2981 2982
	if ((sh->flags & SDPCM_SHARED_TRAP) == 0) {
		brcmf_dbg(INFO, "no trap in firmware\n");
2983
		return 0;
2984
	}
2985

2986 2987
	error = brcmf_sdiod_ramrw(bus->sdiodev, false, sh->trap_addr, (u8 *)&tr,
				  sizeof(struct brcmf_trap_info));
2988 2989 2990 2991 2992 2993 2994 2995 2996 2997 2998 2999
	if (error < 0)
		return error;

	res = scnprintf(buf, sizeof(buf),
			"dongle trap info: type 0x%x @ epc 0x%08x\n"
			"  cpsr 0x%08x spsr 0x%08x sp 0x%08x\n"
			"  lr   0x%08x pc   0x%08x offset 0x%x\n"
			"  r0   0x%08x r1   0x%08x r2 0x%08x r3 0x%08x\n"
			"  r4   0x%08x r5   0x%08x r6 0x%08x r7 0x%08x\n",
			le32_to_cpu(tr.type), le32_to_cpu(tr.epc),
			le32_to_cpu(tr.cpsr), le32_to_cpu(tr.spsr),
			le32_to_cpu(tr.r13), le32_to_cpu(tr.r14),
3000
			le32_to_cpu(tr.pc), sh->trap_addr,
3001 3002 3003 3004 3005
			le32_to_cpu(tr.r0), le32_to_cpu(tr.r1),
			le32_to_cpu(tr.r2), le32_to_cpu(tr.r3),
			le32_to_cpu(tr.r4), le32_to_cpu(tr.r5),
			le32_to_cpu(tr.r6), le32_to_cpu(tr.r7));

3006
	return simple_read_from_buffer(data, count, &pos, buf, res);
3007 3008 3009 3010 3011 3012 3013 3014 3015 3016 3017 3018 3019 3020 3021 3022 3023 3024 3025 3026 3027
}

static int brcmf_sdio_assert_info(struct brcmf_sdio *bus,
				  struct sdpcm_shared *sh, char __user *data,
				  size_t count)
{
	int error = 0;
	char buf[200];
	char file[80] = "?";
	char expr[80] = "<???>";
	int res;
	loff_t pos = 0;

	if ((sh->flags & SDPCM_SHARED_ASSERT_BUILT) == 0) {
		brcmf_dbg(INFO, "firmware not built with -assert\n");
		return 0;
	} else if ((sh->flags & SDPCM_SHARED_ASSERT) == 0) {
		brcmf_dbg(INFO, "no assert in dongle\n");
		return 0;
	}

3028
	sdio_claim_host(bus->sdiodev->func[1]);
3029
	if (sh->assert_file_addr != 0) {
3030 3031
		error = brcmf_sdiod_ramrw(bus->sdiodev, false,
					  sh->assert_file_addr, (u8 *)file, 80);
3032 3033 3034 3035
		if (error < 0)
			return error;
	}
	if (sh->assert_exp_addr != 0) {
3036 3037
		error = brcmf_sdiod_ramrw(bus->sdiodev, false,
					  sh->assert_exp_addr, (u8 *)expr, 80);
3038 3039 3040
		if (error < 0)
			return error;
	}
3041
	sdio_release_host(bus->sdiodev->func[1]);
3042 3043 3044 3045 3046 3047 3048

	res = scnprintf(buf, sizeof(buf),
			"dongle assert: %s:%d: assert(%s)\n",
			file, sh->assert_line, expr);
	return simple_read_from_buffer(data, count, &pos, buf, res);
}

3049
static int brcmf_sdio_checkdied(struct brcmf_sdio *bus)
3050 3051 3052 3053 3054 3055 3056 3057 3058 3059 3060 3061
{
	int error;
	struct sdpcm_shared sh;

	error = brcmf_sdio_readshared(bus, &sh);

	if (error < 0)
		return error;

	if ((sh.flags & SDPCM_SHARED_ASSERT_BUILT) == 0)
		brcmf_dbg(INFO, "firmware not built with -assert\n");
	else if (sh.flags & SDPCM_SHARED_ASSERT)
3062
		brcmf_err("assertion in dongle\n");
3063 3064

	if (sh.flags & SDPCM_SHARED_TRAP)
3065
		brcmf_err("firmware trap in dongle\n");
3066 3067 3068 3069

	return 0;
}

3070 3071
static int brcmf_sdio_died_dump(struct brcmf_sdio *bus, char __user *data,
				size_t count, loff_t *ppos)
3072 3073 3074 3075 3076 3077 3078 3079 3080 3081 3082 3083 3084 3085 3086 3087 3088
{
	int error = 0;
	struct sdpcm_shared sh;
	int nbytes = 0;
	loff_t pos = *ppos;

	if (pos != 0)
		return 0;

	error = brcmf_sdio_readshared(bus, &sh);
	if (error < 0)
		goto done;

	error = brcmf_sdio_assert_info(bus, &sh, data, count);
	if (error < 0)
		goto done;
	nbytes = error;
3089 3090

	error = brcmf_sdio_trap_info(bus, &sh, data+nbytes, count);
3091 3092
	if (error < 0)
		goto done;
3093 3094 3095 3096 3097 3098
	nbytes += error;

	error = brcmf_sdio_dump_console(bus, &sh, data+nbytes, count);
	if (error < 0)
		goto done;
	nbytes += error;
3099

3100 3101
	error = nbytes;
	*ppos += nbytes;
3102 3103 3104 3105 3106 3107 3108 3109 3110 3111
done:
	return error;
}

static ssize_t brcmf_sdio_forensic_read(struct file *f, char __user *data,
					size_t count, loff_t *ppos)
{
	struct brcmf_sdio *bus = f->private_data;
	int res;

3112
	res = brcmf_sdio_died_dump(bus, data, count, ppos);
3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123
	if (res > 0)
		*ppos += res;
	return (ssize_t)res;
}

static const struct file_operations brcmf_sdio_forensic_ops = {
	.owner = THIS_MODULE,
	.open = simple_open,
	.read = brcmf_sdio_forensic_read
};

3124 3125 3126
static void brcmf_sdio_debugfs_create(struct brcmf_sdio *bus)
{
	struct brcmf_pub *drvr = bus->sdiodev->bus_if->drvr;
3127
	struct dentry *dentry = brcmf_debugfs_get_devdir(drvr);
3128

3129 3130 3131 3132 3133
	if (IS_ERR_OR_NULL(dentry))
		return;

	debugfs_create_file("forensics", S_IRUGO, dentry, bus,
			    &brcmf_sdio_forensic_ops);
3134 3135 3136
	brcmf_debugfs_create_sdio_count(drvr, &bus->sdcnt);
}
#else
3137
static int brcmf_sdio_checkdied(struct brcmf_sdio *bus)
3138 3139 3140 3141
{
	return 0;
}

3142 3143 3144 3145 3146
static void brcmf_sdio_debugfs_create(struct brcmf_sdio *bus)
{
}
#endif /* DEBUG */

3147
static int
3148
brcmf_sdio_bus_rxctl(struct device *dev, unsigned char *msg, uint msglen)
3149 3150 3151 3152
{
	int timeleft;
	uint rxlen = 0;
	bool pending;
3153
	u8 *buf;
3154
	struct brcmf_bus *bus_if = dev_get_drvdata(dev);
3155
	struct brcmf_sdio_dev *sdiodev = bus_if->bus_priv.sdio;
3156
	struct brcmf_sdio *bus = sdiodev->bus;
3157 3158 3159 3160

	brcmf_dbg(TRACE, "Enter\n");

	/* Wait until control frame is available */
3161
	timeleft = brcmf_sdio_dcmd_resp_wait(bus, &bus->rxlen, &pending);
3162

3163
	spin_lock_bh(&bus->rxctl_lock);
3164 3165
	rxlen = bus->rxlen;
	memcpy(msg, bus->rxctl, min(msglen, rxlen));
3166 3167 3168
	bus->rxctl = NULL;
	buf = bus->rxctl_orig;
	bus->rxctl_orig = NULL;
3169
	bus->rxlen = 0;
3170 3171
	spin_unlock_bh(&bus->rxctl_lock);
	vfree(buf);
3172 3173 3174 3175 3176

	if (rxlen) {
		brcmf_dbg(CTL, "resumed on rxctl frame, got %d expected %d\n",
			  rxlen, msglen);
	} else if (timeleft == 0) {
3177
		brcmf_err("resumed on timeout\n");
3178
		brcmf_sdio_checkdied(bus);
3179
	} else if (pending) {
3180 3181 3182 3183
		brcmf_dbg(CTL, "cancelled\n");
		return -ERESTARTSYS;
	} else {
		brcmf_dbg(CTL, "resumed for unknown reason?\n");
3184
		brcmf_sdio_checkdied(bus);
3185 3186 3187
	}

	if (rxlen)
3188
		bus->sdcnt.rx_ctlpkts++;
3189
	else
3190
		bus->sdcnt.rx_ctlerrs++;
3191 3192 3193 3194

	return rxlen ? (int)rxlen : -ETIMEDOUT;
}

3195 3196 3197 3198 3199 3200 3201 3202 3203 3204 3205 3206 3207 3208 3209 3210 3211 3212 3213 3214 3215 3216 3217 3218 3219 3220 3221 3222 3223 3224 3225 3226 3227 3228 3229 3230 3231 3232 3233 3234 3235 3236 3237 3238 3239 3240 3241 3242 3243 3244 3245 3246 3247 3248
#ifdef DEBUG
static bool
brcmf_sdio_verifymemory(struct brcmf_sdio_dev *sdiodev, u32 ram_addr,
			u8 *ram_data, uint ram_sz)
{
	char *ram_cmp;
	int err;
	bool ret = true;
	int address;
	int offset;
	int len;

	/* read back and verify */
	brcmf_dbg(INFO, "Compare RAM dl & ul at 0x%08x; size=%d\n", ram_addr,
		  ram_sz);
	ram_cmp = kmalloc(MEMBLOCK, GFP_KERNEL);
	/* do not proceed while no memory but  */
	if (!ram_cmp)
		return true;

	address = ram_addr;
	offset = 0;
	while (offset < ram_sz) {
		len = ((offset + MEMBLOCK) < ram_sz) ? MEMBLOCK :
		      ram_sz - offset;
		err = brcmf_sdiod_ramrw(sdiodev, false, address, ram_cmp, len);
		if (err) {
			brcmf_err("error %d on reading %d membytes at 0x%08x\n",
				  err, len, address);
			ret = false;
			break;
		} else if (memcmp(ram_cmp, &ram_data[offset], len)) {
			brcmf_err("Downloaded RAM image is corrupted, block offset is %d, len is %d\n",
				  offset, len);
			ret = false;
			break;
		}
		offset += len;
		address += len;
	}

	kfree(ram_cmp);

	return ret;
}
#else	/* DEBUG */
static bool
brcmf_sdio_verifymemory(struct brcmf_sdio_dev *sdiodev, u32 ram_addr,
			u8 *ram_data, uint ram_sz)
{
	return true;
}
#endif	/* DEBUG */

3249 3250
static int brcmf_sdio_download_code_file(struct brcmf_sdio *bus,
					 const struct firmware *fw)
3251
{
3252
	int err;
3253
	int offset;
3254 3255 3256
	int address;
	int len;

3257 3258
	brcmf_dbg(TRACE, "Enter\n");

3259 3260 3261 3262 3263 3264
	err = 0;
	offset = 0;
	address = bus->ci->rambase;
	while (offset < fw->size) {
		len = ((offset + MEMBLOCK) < fw->size) ? MEMBLOCK :
		      fw->size - offset;
3265 3266
		err = brcmf_sdiod_ramrw(bus->sdiodev, true, address,
					(u8 *)&fw->data[offset], len);
3267
		if (err) {
3268
			brcmf_err("error %d on writing %d membytes at 0x%08x\n",
3269
				  err, len, address);
3270
			return err;
3271
		}
3272 3273
		offset += len;
		address += len;
3274
	}
3275 3276 3277 3278
	if (!err)
		if (!brcmf_sdio_verifymemory(bus->sdiodev, bus->ci->rambase,
					     (u8 *)fw->data, fw->size))
			err = -EIO;
3279

3280
	return err;
3281 3282
}

3283 3284
static int brcmf_sdio_download_nvram(struct brcmf_sdio *bus,
				     const struct firmware *nv)
3285
{
3286 3287 3288 3289 3290 3291
	void *vars;
	u32 varsz;
	int address;
	int err;

	brcmf_dbg(TRACE, "Enter\n");
3292

3293
	vars = brcmf_nvram_strip(nv, &varsz);
3294

3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305 3306 3307 3308
	if (vars == NULL)
		return -EINVAL;

	address = bus->ci->ramsize - varsz + bus->ci->rambase;
	err = brcmf_sdiod_ramrw(bus->sdiodev, true, address, vars, varsz);
	if (err)
		brcmf_err("error %d on writing %d nvram bytes at 0x%08x\n",
			  err, varsz, address);
	else if (!brcmf_sdio_verifymemory(bus->sdiodev, address, vars, varsz))
		err = -EIO;

	brcmf_nvram_free(vars);

	return err;
3309 3310
}

3311
static int brcmf_sdio_download_firmware(struct brcmf_sdio *bus)
3312
{
3313
	int bcmerror = -EFAULT;
3314 3315
	const struct firmware *fw;
	u32 rstvec;
3316 3317 3318

	sdio_claim_host(bus->sdiodev->func[1]);
	brcmf_sdio_clkctl(bus, CLK_AVAIL, false);
3319 3320

	/* Keep arm in reset */
3321 3322 3323 3324 3325
	brcmf_sdio_chip_enter_download(bus->sdiodev, bus->ci);

	fw = brcmf_sdio_get_fw(bus, BRCMF_FIRMWARE_BIN);
	if (fw == NULL) {
		bcmerror = -ENOENT;
3326 3327 3328
		goto err;
	}

3329 3330 3331 3332 3333 3334
	rstvec = get_unaligned_le32(fw->data);
	brcmf_dbg(SDIO, "firmware rstvec: %x\n", rstvec);

	bcmerror = brcmf_sdio_download_code_file(bus, fw);
	release_firmware(fw);
	if (bcmerror) {
3335
		brcmf_err("dongle image file download failed\n");
3336 3337 3338
		goto err;
	}

3339 3340 3341 3342 3343 3344 3345 3346 3347
	fw = brcmf_sdio_get_fw(bus, BRCMF_FIRMWARE_NVRAM);
	if (fw == NULL) {
		bcmerror = -ENOENT;
		goto err;
	}

	bcmerror = brcmf_sdio_download_nvram(bus, fw);
	release_firmware(fw);
	if (bcmerror) {
3348
		brcmf_err("dongle nvram file download failed\n");
3349 3350
		goto err;
	}
3351 3352

	/* Take arm out of reset */
3353
	if (!brcmf_sdio_chip_exit_download(bus->sdiodev, bus->ci, rstvec)) {
3354
		brcmf_err("error getting out of ARM core reset\n");
3355 3356 3357
		goto err;
	}

3358 3359
	/* Allow HT Clock now that the ARM is running. */
	bus->sdiodev->bus_if->state = BRCMF_BUS_LOAD;
3360 3361 3362
	bcmerror = 0;

err:
3363 3364
	brcmf_sdio_clkctl(bus, CLK_SDONLY, false);
	sdio_release_host(bus->sdiodev->func[1]);
3365 3366 3367
	return bcmerror;
}

3368
static bool brcmf_sdio_sr_capable(struct brcmf_sdio *bus)
3369
{
3370 3371
	u32 addr, reg, pmu_cc3_mask = ~0;
	int err;
3372 3373 3374 3375 3376 3377 3378

	brcmf_dbg(TRACE, "Enter\n");

	/* old chips with PMU version less than 17 don't support save restore */
	if (bus->ci->pmurev < 17)
		return false;

3379 3380 3381 3382 3383 3384 3385 3386 3387 3388 3389 3390 3391 3392 3393
	switch (bus->ci->chip) {
	case BCM43241_CHIP_ID:
	case BCM4335_CHIP_ID:
	case BCM4339_CHIP_ID:
		/* read PMU chipcontrol register 3 */
		addr = CORE_CC_REG(bus->ci->c_inf[0].base, chipcontrol_addr);
		brcmf_sdiod_regwl(bus->sdiodev, addr, 3, NULL);
		addr = CORE_CC_REG(bus->ci->c_inf[0].base, chipcontrol_data);
		reg = brcmf_sdiod_regrl(bus->sdiodev, addr, NULL);
		return (reg & pmu_cc3_mask) != 0;
	default:
		addr = CORE_CC_REG(bus->ci->c_inf[0].base, pmucapabilities_ext);
		reg = brcmf_sdiod_regrl(bus->sdiodev, addr, &err);
		if ((reg & PCAPEXT_SR_SUPPORTED_MASK) == 0)
			return false;
3394

3395 3396 3397 3398 3399
		addr = CORE_CC_REG(bus->ci->c_inf[0].base, retention_ctl);
		reg = brcmf_sdiod_regrl(bus->sdiodev, addr, NULL);
		return (reg & (PMU_RCTL_MACPHY_DISABLE_MASK |
			       PMU_RCTL_LOGIC_DISABLE_MASK)) == 0;
	}
3400 3401
}

3402
static void brcmf_sdio_sr_init(struct brcmf_sdio *bus)
3403 3404 3405 3406 3407 3408
{
	int err = 0;
	u8 val;

	brcmf_dbg(TRACE, "Enter\n");

3409
	val = brcmf_sdiod_regrb(bus->sdiodev, SBSDIO_FUNC1_WAKEUPCTRL, &err);
3410 3411 3412 3413 3414 3415
	if (err) {
		brcmf_err("error reading SBSDIO_FUNC1_WAKEUPCTRL\n");
		return;
	}

	val |= 1 << SBSDIO_FUNC1_WCTRL_HTWAIT_SHIFT;
3416
	brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_WAKEUPCTRL, val, &err);
3417 3418 3419 3420 3421 3422
	if (err) {
		brcmf_err("error writing SBSDIO_FUNC1_WAKEUPCTRL\n");
		return;
	}

	/* Add CMD14 Support */
3423 3424 3425 3426
	brcmf_sdiod_regwb(bus->sdiodev, SDIO_CCCR_BRCM_CARDCAP,
			  (SDIO_CCCR_BRCM_CARDCAP_CMD14_SUPPORT |
			   SDIO_CCCR_BRCM_CARDCAP_CMD14_EXT),
			  &err);
3427 3428 3429 3430 3431
	if (err) {
		brcmf_err("error writing SDIO_CCCR_BRCM_CARDCAP\n");
		return;
	}

3432 3433
	brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR,
			  SBSDIO_FORCE_HT, &err);
3434 3435 3436 3437 3438 3439 3440 3441 3442 3443 3444
	if (err) {
		brcmf_err("error writing SBSDIO_FUNC1_CHIPCLKCSR\n");
		return;
	}

	/* set flag */
	bus->sr_enabled = true;
	brcmf_dbg(INFO, "SR enabled\n");
}

/* enable KSO bit */
3445
static int brcmf_sdio_kso_init(struct brcmf_sdio *bus)
3446 3447 3448 3449 3450 3451 3452 3453 3454 3455
{
	u8 val;
	int err = 0;

	brcmf_dbg(TRACE, "Enter\n");

	/* KSO bit added in SDIO core rev 12 */
	if (bus->ci->c_inf[1].rev < 12)
		return 0;

3456
	val = brcmf_sdiod_regrb(bus->sdiodev, SBSDIO_FUNC1_SLEEPCSR, &err);
3457 3458 3459 3460 3461 3462 3463 3464
	if (err) {
		brcmf_err("error reading SBSDIO_FUNC1_SLEEPCSR\n");
		return err;
	}

	if (!(val & SBSDIO_FUNC1_SLEEPCSR_KSO_MASK)) {
		val |= (SBSDIO_FUNC1_SLEEPCSR_KSO_EN <<
			SBSDIO_FUNC1_SLEEPCSR_KSO_SHIFT);
3465 3466
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_SLEEPCSR,
				  val, &err);
3467 3468 3469 3470 3471 3472 3473 3474 3475 3476
		if (err) {
			brcmf_err("error writing SBSDIO_FUNC1_SLEEPCSR\n");
			return err;
		}
	}

	return 0;
}


3477
static int brcmf_sdio_bus_preinit(struct device *dev)
3478 3479 3480 3481
{
	struct brcmf_bus *bus_if = dev_get_drvdata(dev);
	struct brcmf_sdio_dev *sdiodev = bus_if->bus_priv.sdio;
	struct brcmf_sdio *bus = sdiodev->bus;
3482
	uint pad_size;
3483 3484 3485 3486
	u32 value;
	u8 idx;
	int err;

3487 3488 3489 3490
	/* the commands below use the terms tx and rx from
	 * a device perspective, ie. bus:txglom affects the
	 * bus transfers from device to host.
	 */
3491 3492 3493 3494 3495 3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506
	idx = brcmf_sdio_chip_getinfidx(bus->ci, BCMA_CORE_SDIO_DEV);
	if (bus->ci->c_inf[idx].rev < 12) {
		/* for sdio core rev < 12, disable txgloming */
		value = 0;
		err = brcmf_iovar_data_set(dev, "bus:txglom", &value,
					   sizeof(u32));
	} else {
		/* otherwise, set txglomalign */
		value = 4;
		if (sdiodev->pdata)
			value = sdiodev->pdata->sd_sgentry_align;
		/* SDIO ADMA requires at least 32 bit alignment */
		value = max_t(u32, value, 4);
		err = brcmf_iovar_data_set(dev, "bus:txglomalign", &value,
					   sizeof(u32));
	}
3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517 3518 3519 3520 3521 3522 3523 3524 3525 3526 3527 3528 3529 3530 3531 3532

	if (err < 0)
		goto done;

	bus->tx_hdrlen = SDPCM_HWHDR_LEN + SDPCM_SWHDR_LEN;
	if (sdiodev->sg_support) {
		bus->txglom = false;
		value = 1;
		pad_size = bus->sdiodev->func[2]->cur_blksize << 1;
		bus->txglom_sgpad = brcmu_pkt_buf_get_skb(pad_size);
		if (!bus->txglom_sgpad)
			brcmf_err("allocating txglom padding skb failed, reduced performance\n");

		err = brcmf_iovar_data_set(bus->sdiodev->dev, "bus:rxglom",
					   &value, sizeof(u32));
		if (err < 0) {
			/* bus:rxglom is allowed to fail */
			err = 0;
		} else {
			bus->txglom = true;
			bus->tx_hdrlen += SDPCM_HWEXT_LEN;
		}
	}
	brcmf_bus_add_txhdrlen(bus->sdiodev->dev, bus->tx_hdrlen);

done:
3533 3534 3535
	return err;
}

3536
static int brcmf_sdio_bus_init(struct device *dev)
3537
{
3538
	struct brcmf_bus *bus_if = dev_get_drvdata(dev);
3539
	struct brcmf_sdio_dev *sdiodev = bus_if->bus_priv.sdio;
3540
	struct brcmf_sdio *bus = sdiodev->bus;
3541 3542 3543 3544 3545 3546
	int err, ret = 0;
	u8 saveclk;

	brcmf_dbg(TRACE, "Enter\n");

	/* try to download image and nvram to the dongle */
3547
	if (bus_if->state == BRCMF_BUS_DOWN) {
3548
		bus->alp_only = true;
3549 3550 3551
		err = brcmf_sdio_download_firmware(bus);
		if (err)
			return err;
3552
		bus->alp_only = false;
3553 3554
	}

3555
	if (!bus->sdiodev->bus_if->drvr)
3556 3557 3558
		return 0;

	/* Start the watchdog timer */
3559
	bus->sdcnt.tickcnt = 0;
3560
	brcmf_sdio_wd_timer(bus, BRCMF_WD_POLL_MS);
3561

3562
	sdio_claim_host(bus->sdiodev->func[1]);
3563 3564

	/* Make sure backplane clock is on, needed to generate F2 interrupt */
3565
	brcmf_sdio_clkctl(bus, CLK_AVAIL, false);
3566 3567 3568 3569
	if (bus->clkstate != CLK_AVAIL)
		goto exit;

	/* Force clocks on backplane to be sure F2 interrupt propagates */
3570 3571
	saveclk = brcmf_sdiod_regrb(bus->sdiodev,
				    SBSDIO_FUNC1_CHIPCLKCSR, &err);
3572
	if (!err) {
3573 3574
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR,
				  (saveclk | SBSDIO_FORCE_HT), &err);
3575 3576
	}
	if (err) {
3577
		brcmf_err("Failed to force clock for F2: err %d\n", err);
3578 3579 3580 3581 3582
		goto exit;
	}

	/* Enable function 2 (frame transfers) */
	w_sdreg32(bus, SDPCM_PROT_VERSION << SMB_DATA_VERSION_SHIFT,
3583
		  offsetof(struct sdpcmd_regs, tosbmailboxdata));
3584
	err = sdio_enable_func(bus->sdiodev->func[SDIO_FUNC_2]);
3585 3586


3587
	brcmf_dbg(INFO, "enable F2: err=%d\n", err);
3588 3589

	/* If F2 successfully enabled, set core and enable interrupts */
3590
	if (!err) {
3591 3592 3593
		/* Set up the interrupt mask and enable interrupts */
		bus->hostintmask = HOSTINTMASK;
		w_sdreg32(bus, bus->hostintmask,
3594
			  offsetof(struct sdpcmd_regs, hostintmask));
3595

3596
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_WATERMARK, 8, &err);
3597
	} else {
3598
		/* Disable F2 again */
3599
		sdio_disable_func(bus->sdiodev->func[SDIO_FUNC_2]);
3600
		ret = -ENODEV;
3601 3602
	}

3603 3604
	if (brcmf_sdio_sr_capable(bus)) {
		brcmf_sdio_sr_init(bus);
3605 3606
	} else {
		/* Restore previous clock setting */
3607 3608
		brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR,
				  saveclk, &err);
3609
	}
3610

3611
	if (ret == 0) {
3612
		ret = brcmf_sdiod_intr_register(bus->sdiodev);
3613
		if (ret != 0)
3614
			brcmf_err("intr register failed:%d\n", ret);
3615 3616
	}

3617
	/* If we didn't come up, turn off backplane clock */
3618
	if (ret != 0)
3619
		brcmf_sdio_clkctl(bus, CLK_NONE, false);
3620 3621

exit:
3622
	sdio_release_host(bus->sdiodev->func[1]);
3623 3624 3625 3626

	return ret;
}

3627
void brcmf_sdio_isr(struct brcmf_sdio *bus)
3628 3629 3630 3631
{
	brcmf_dbg(TRACE, "Enter\n");

	if (!bus) {
3632
		brcmf_err("bus is null pointer, exiting\n");
3633 3634 3635
		return;
	}

3636
	if (bus->sdiodev->bus_if->state == BRCMF_BUS_DOWN) {
3637
		brcmf_err("bus is down. we have nothing to do\n");
3638 3639 3640
		return;
	}
	/* Count the interrupt call */
3641
	bus->sdcnt.intrcount++;
3642 3643 3644 3645
	if (in_interrupt())
		atomic_set(&bus->ipend, 1);
	else
		if (brcmf_sdio_intr_rstatus(bus)) {
3646
			brcmf_err("failed backplane access\n");
3647 3648
			bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
		}
3649 3650 3651

	/* Disable additional interrupts (is this needed now)? */
	if (!bus->intr)
3652
		brcmf_err("isr w/o interrupt configured!\n");
3653

3654
	atomic_inc(&bus->dpc_tskcnt);
3655
	queue_work(bus->brcmf_wq, &bus->datawork);
3656 3657
}

3658
static bool brcmf_sdio_bus_watchdog(struct brcmf_sdio *bus)
3659
{
J
Joe Perches 已提交
3660
#ifdef DEBUG
3661
	struct brcmf_bus *bus_if = dev_get_drvdata(bus->sdiodev->dev);
J
Joe Perches 已提交
3662
#endif	/* DEBUG */
3663 3664 3665 3666

	brcmf_dbg(TIMER, "Enter\n");

	/* Poll period: check device if appropriate. */
3667 3668
	if (!bus->sr_enabled &&
	    bus->poll && (++bus->polltick >= bus->pollrate)) {
3669 3670 3671 3672 3673 3674
		u32 intstatus = 0;

		/* Reset poll tick */
		bus->polltick = 0;

		/* Check device if no interrupts */
3675 3676
		if (!bus->intr ||
		    (bus->sdcnt.intrcount == bus->sdcnt.lastintrs)) {
3677

3678
			if (atomic_read(&bus->dpc_tskcnt) == 0) {
3679
				u8 devpend;
3680

3681
				sdio_claim_host(bus->sdiodev->func[1]);
3682 3683 3684
				devpend = brcmf_sdiod_regrb(bus->sdiodev,
							    SDIO_CCCR_INTx,
							    NULL);
3685
				sdio_release_host(bus->sdiodev->func[1]);
3686 3687 3688 3689 3690 3691 3692 3693
				intstatus =
				    devpend & (INTR_STATUS_FUNC1 |
					       INTR_STATUS_FUNC2);
			}

			/* If there is something, make like the ISR and
				 schedule the DPC */
			if (intstatus) {
3694
				bus->sdcnt.pollcnt++;
3695
				atomic_set(&bus->ipend, 1);
3696

3697
				atomic_inc(&bus->dpc_tskcnt);
3698
				queue_work(bus->brcmf_wq, &bus->datawork);
3699 3700 3701 3702
			}
		}

		/* Update interrupt tracking */
3703
		bus->sdcnt.lastintrs = bus->sdcnt.intrcount;
3704
	}
J
Joe Perches 已提交
3705
#ifdef DEBUG
3706
	/* Poll for console output periodically */
H
Hante Meuleman 已提交
3707
	if (bus_if && bus_if->state == BRCMF_BUS_DATA &&
3708
	    bus->console_interval != 0) {
3709 3710 3711
		bus->console.count += BRCMF_WD_POLL_MS;
		if (bus->console.count >= bus->console_interval) {
			bus->console.count -= bus->console_interval;
3712
			sdio_claim_host(bus->sdiodev->func[1]);
3713
			/* Make sure backplane clock is on */
3714 3715
			brcmf_sdio_bus_sleep(bus, false, false);
			if (brcmf_sdio_readconsole(bus) < 0)
3716 3717
				/* stop on error */
				bus->console_interval = 0;
3718
			sdio_release_host(bus->sdiodev->func[1]);
3719 3720
		}
	}
J
Joe Perches 已提交
3721
#endif				/* DEBUG */
3722 3723 3724 3725 3726 3727 3728

	/* On idle timeout clear activity flag and/or turn off clock */
	if ((bus->idletime > 0) && (bus->clkstate == CLK_AVAIL)) {
		if (++bus->idlecount >= bus->idletime) {
			bus->idlecount = 0;
			if (bus->activity) {
				bus->activity = false;
3729
				brcmf_sdio_wd_timer(bus, BRCMF_WD_POLL_MS);
3730
			} else {
3731
				brcmf_dbg(SDIO, "idle\n");
3732
				sdio_claim_host(bus->sdiodev->func[1]);
3733
				brcmf_sdio_bus_sleep(bus, true, false);
3734
				sdio_release_host(bus->sdiodev->func[1]);
3735 3736 3737 3738
			}
		}
	}

3739
	return (atomic_read(&bus->ipend) > 0);
3740 3741
}

3742 3743 3744 3745 3746
static void brcmf_sdio_dataworker(struct work_struct *work)
{
	struct brcmf_sdio *bus = container_of(work, struct brcmf_sdio,
					      datawork);

3747
	while (atomic_read(&bus->dpc_tskcnt)) {
3748
		brcmf_sdio_dpc(bus);
3749
		atomic_dec(&bus->dpc_tskcnt);
3750 3751 3752
	}
}

3753
static bool
3754
brcmf_sdio_probe_attach(struct brcmf_sdio *bus)
3755 3756 3757 3758 3759
{
	u8 clkctl = 0;
	int err = 0;
	int reg_addr;
	u32 reg_val;
3760
	u32 drivestrength;
3761

3762 3763
	sdio_claim_host(bus->sdiodev->func[1]);

3764
	pr_debug("F1 signature read @0x18000000=0x%4x\n",
3765
		 brcmf_sdiod_regrl(bus->sdiodev, SI_ENUM_BASE, NULL));
3766 3767

	/*
3768
	 * Force PLL off until brcmf_sdio_chip_attach()
3769 3770 3771
	 * programs PLL control regs
	 */

3772 3773
	brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR,
			  BRCMF_INIT_CLKCTL1, &err);
3774
	if (!err)
3775 3776
		clkctl = brcmf_sdiod_regrb(bus->sdiodev,
					   SBSDIO_FUNC1_CHIPCLKCSR, &err);
3777 3778

	if (err || ((clkctl & ~SBSDIO_AVBITS) != BRCMF_INIT_CLKCTL1)) {
3779
		brcmf_err("ChipClkCSR access: err %d wrote 0x%02x read 0x%02x\n",
3780 3781 3782 3783
			  err, BRCMF_INIT_CLKCTL1, clkctl);
		goto fail;
	}

3784
	if (brcmf_sdio_chip_attach(bus->sdiodev, &bus->ci)) {
3785
		brcmf_err("brcmf_sdio_chip_attach failed!\n");
3786 3787 3788
		goto fail;
	}

3789
	if (brcmf_sdio_kso_init(bus)) {
3790 3791 3792 3793
		brcmf_err("error enabling KSO\n");
		goto fail;
	}

3794 3795 3796 3797 3798
	if ((bus->sdiodev->pdata) && (bus->sdiodev->pdata->drive_strength))
		drivestrength = bus->sdiodev->pdata->drive_strength;
	else
		drivestrength = DEFAULT_SDIO_DRIVE_STRENGTH;
	brcmf_sdio_chip_drivestrengthinit(bus->sdiodev, bus->ci, drivestrength);
3799

3800
	/* Get info on the SOCRAM cores... */
3801 3802
	bus->ramsize = bus->ci->ramsize;
	if (!(bus->ramsize)) {
3803
		brcmf_err("failed to find SOCRAM memory!\n");
3804 3805 3806
		goto fail;
	}

3807
	/* Set card control so an SDIO card reset does a WLAN backplane reset */
3808 3809
	reg_val = brcmf_sdiod_regrb(bus->sdiodev,
				    SDIO_CCCR_BRCM_CARDCTRL, &err);
3810 3811 3812 3813 3814
	if (err)
		goto fail;

	reg_val |= SDIO_CCCR_BRCM_CARDCTRL_WLANRESET;

3815 3816
	brcmf_sdiod_regwb(bus->sdiodev,
			  SDIO_CCCR_BRCM_CARDCTRL, reg_val, &err);
3817 3818 3819 3820 3821 3822
	if (err)
		goto fail;

	/* set PMUControl so a backplane reset does PMU state reload */
	reg_addr = CORE_CC_REG(bus->ci->c_inf[0].base,
			       pmucontrol);
3823 3824 3825
	reg_val = brcmf_sdiod_regrl(bus->sdiodev,
				    reg_addr,
				    &err);
3826 3827 3828 3829 3830
	if (err)
		goto fail;

	reg_val |= (BCMA_CC_PMU_CTL_RES_RELOAD << BCMA_CC_PMU_CTL_RES_SHIFT);

3831 3832 3833 3834
	brcmf_sdiod_regwl(bus->sdiodev,
			  reg_addr,
			  reg_val,
			  &err);
3835 3836 3837
	if (err)
		goto fail;

3838

3839 3840
	sdio_release_host(bus->sdiodev->func[1]);

3841 3842
	brcmu_pktq_init(&bus->txq, (PRIOMASK + 1), TXQLEN);

3843 3844 3845 3846
	/* allocate header buffer */
	bus->hdrbuf = kzalloc(MAX_HDR_READ + bus->head_align, GFP_KERNEL);
	if (!bus->hdrbuf)
		return false;
3847 3848
	/* Locate an appropriately-aligned portion of hdrbuf */
	bus->rxhdr = (u8 *) roundup((unsigned long)&bus->hdrbuf[0],
3849
				    bus->head_align);
3850 3851 3852 3853 3854 3855 3856 3857 3858 3859

	/* Set the poll and/or interrupt flags */
	bus->intr = true;
	bus->poll = false;
	if (bus->poll)
		bus->pollrate = 1;

	return true;

fail:
3860
	sdio_release_host(bus->sdiodev->func[1]);
3861 3862 3863 3864
	return false;
}

static int
3865
brcmf_sdio_watchdog_thread(void *data)
3866
{
3867
	struct brcmf_sdio *bus = (struct brcmf_sdio *)data;
3868 3869 3870 3871 3872 3873 3874

	allow_signal(SIGTERM);
	/* Run until signal received */
	while (1) {
		if (kthread_should_stop())
			break;
		if (!wait_for_completion_interruptible(&bus->watchdog_wait)) {
3875
			brcmf_sdio_bus_watchdog(bus);
3876
			/* Count the tick for reference */
3877
			bus->sdcnt.tickcnt++;
3878 3879 3880 3881 3882 3883 3884
		} else
			break;
	}
	return 0;
}

static void
3885
brcmf_sdio_watchdog(unsigned long data)
3886
{
3887
	struct brcmf_sdio *bus = (struct brcmf_sdio *)data;
3888 3889 3890 3891 3892 3893 3894 3895 3896 3897

	if (bus->watchdog_tsk) {
		complete(&bus->watchdog_wait);
		/* Reschedule the watchdog */
		if (bus->wd_timer_valid)
			mod_timer(&bus->timer,
				  jiffies + BRCMF_WD_POLL_MS * HZ / 1000);
	}
}

A
Arend van Spriel 已提交
3898
static struct brcmf_bus_ops brcmf_sdio_bus_ops = {
3899 3900 3901 3902 3903 3904 3905
	.stop = brcmf_sdio_bus_stop,
	.preinit = brcmf_sdio_bus_preinit,
	.init = brcmf_sdio_bus_init,
	.txdata = brcmf_sdio_bus_txdata,
	.txctl = brcmf_sdio_bus_txctl,
	.rxctl = brcmf_sdio_bus_rxctl,
	.gettxq = brcmf_sdio_bus_gettxq,
A
Arend van Spriel 已提交
3906 3907
};

3908
struct brcmf_sdio *brcmf_sdio_probe(struct brcmf_sdio_dev *sdiodev)
3909 3910
{
	int ret;
3911
	struct brcmf_sdio *bus;
3912 3913 3914 3915

	brcmf_dbg(TRACE, "Enter\n");

	/* Allocate private bus interface state */
3916
	bus = kzalloc(sizeof(struct brcmf_sdio), GFP_ATOMIC);
3917 3918 3919 3920 3921
	if (!bus)
		goto fail;

	bus->sdiodev = sdiodev;
	sdiodev->bus = bus;
3922
	skb_queue_head_init(&bus->glom);
3923 3924 3925
	bus->txbound = BRCMF_TXBOUND;
	bus->rxbound = BRCMF_RXBOUND;
	bus->txminmax = BRCMF_TXMINMAX;
3926
	bus->tx_seq = SDPCM_SEQ_WRAP - 1;
3927

3928 3929 3930 3931 3932 3933 3934 3935 3936 3937 3938 3939
	/* platform specific configuration:
	 *   alignments must be at least 4 bytes for ADMA
         */
	bus->head_align = ALIGNMENT;
	bus->sgentry_align = ALIGNMENT;
	if (sdiodev->pdata) {
		if (sdiodev->pdata->sd_head_align > ALIGNMENT)
			bus->head_align = sdiodev->pdata->sd_head_align;
		if (sdiodev->pdata->sd_sgentry_align > ALIGNMENT)
			bus->sgentry_align = sdiodev->pdata->sd_sgentry_align;
	}

3940 3941 3942
	INIT_WORK(&bus->datawork, brcmf_sdio_dataworker);
	bus->brcmf_wq = create_singlethread_workqueue("brcmf_wq");
	if (bus->brcmf_wq == NULL) {
3943
		brcmf_err("insufficient memory to create txworkqueue\n");
3944 3945 3946
		goto fail;
	}

3947
	/* attempt to attach to the dongle */
3948 3949
	if (!(brcmf_sdio_probe_attach(bus))) {
		brcmf_err("brcmf_sdio_probe_attach failed\n");
3950 3951 3952
		goto fail;
	}

3953
	spin_lock_init(&bus->rxctl_lock);
3954 3955 3956 3957 3958 3959 3960
	spin_lock_init(&bus->txqlock);
	init_waitqueue_head(&bus->ctrl_wait);
	init_waitqueue_head(&bus->dcmd_resp_wait);

	/* Set up the watchdog timer */
	init_timer(&bus->timer);
	bus->timer.data = (unsigned long)bus;
3961
	bus->timer.function = brcmf_sdio_watchdog;
3962 3963 3964

	/* Initialize watchdog thread */
	init_completion(&bus->watchdog_wait);
3965
	bus->watchdog_tsk = kthread_run(brcmf_sdio_watchdog_thread,
3966 3967
					bus, "brcmf_watchdog");
	if (IS_ERR(bus->watchdog_tsk)) {
3968
		pr_warn("brcmf_watchdog thread failed to start\n");
3969 3970 3971
		bus->watchdog_tsk = NULL;
	}
	/* Initialize DPC thread */
3972
	atomic_set(&bus->dpc_tskcnt, 0);
3973

3974
	/* Assign bus interface call back */
A
Arend van Spriel 已提交
3975 3976
	bus->sdiodev->bus_if->dev = bus->sdiodev->dev;
	bus->sdiodev->bus_if->ops = &brcmf_sdio_bus_ops;
3977 3978
	bus->sdiodev->bus_if->chip = bus->ci->chip;
	bus->sdiodev->bus_if->chiprev = bus->ci->chiprev;
A
Arend van Spriel 已提交
3979

3980 3981 3982 3983
	/* default sdio bus header length for tx packet */
	bus->tx_hdrlen = SDPCM_HWHDR_LEN + SDPCM_SWHDR_LEN;

	/* Attach to the common layer, reserve hdr space */
3984
	ret = brcmf_attach(bus->sdiodev->dev);
3985
	if (ret != 0) {
3986
		brcmf_err("brcmf_attach failed\n");
3987 3988 3989 3990
		goto fail;
	}

	/* Allocate buffers */
3991 3992 3993 3994 3995 3996 3997 3998 3999
	if (bus->sdiodev->bus_if->maxctl) {
		bus->rxblen =
		    roundup((bus->sdiodev->bus_if->maxctl + SDPCM_HDRLEN),
			    ALIGNMENT) + bus->head_align;
		bus->rxbuf = kmalloc(bus->rxblen, GFP_ATOMIC);
		if (!(bus->rxbuf)) {
			brcmf_err("rxbuf allocation failed\n");
			goto fail;
		}
4000 4001
	}

4002 4003 4004 4005 4006 4007 4008 4009 4010 4011 4012 4013 4014 4015 4016 4017 4018 4019 4020 4021 4022 4023 4024 4025 4026
	sdio_claim_host(bus->sdiodev->func[1]);

	/* Disable F2 to clear any intermediate frame state on the dongle */
	sdio_disable_func(bus->sdiodev->func[SDIO_FUNC_2]);

	bus->sdiodev->bus_if->state = BRCMF_BUS_DOWN;
	bus->rxflow = false;

	/* Done with backplane-dependent accesses, can drop clock... */
	brcmf_sdiod_regwb(bus->sdiodev, SBSDIO_FUNC1_CHIPCLKCSR, 0, NULL);

	sdio_release_host(bus->sdiodev->func[1]);

	/* ...and initialize clock/power states */
	bus->clkstate = CLK_SDONLY;
	bus->idletime = BRCMF_IDLE_INTERVAL;
	bus->idleclock = BRCMF_IDLE_ACTIVE;

	/* Query the F2 block size, set roundup accordingly */
	bus->blocksize = bus->sdiodev->func[2]->cur_blksize;
	bus->roundup = min(max_roundup, bus->blocksize);

	/* SR state */
	bus->sleeping = false;
	bus->sr_enabled = false;
4027

4028
	brcmf_sdio_debugfs_create(bus);
4029 4030 4031
	brcmf_dbg(INFO, "completed!!\n");

	/* if firmware path present try to download and bring up bus */
4032
	ret = brcmf_bus_start(bus->sdiodev->dev);
4033
	if (ret != 0) {
4034
		brcmf_err("dongle is not responding\n");
4035
		goto fail;
4036
	}
4037

4038 4039 4040
	return bus;

fail:
4041
	brcmf_sdio_remove(bus);
4042 4043 4044
	return NULL;
}

4045 4046
/* Detach and free everything */
void brcmf_sdio_remove(struct brcmf_sdio *bus)
4047 4048 4049
{
	brcmf_dbg(TRACE, "Enter\n");

4050 4051 4052 4053 4054 4055 4056 4057 4058 4059
	if (bus) {
		/* De-register interrupt handler */
		brcmf_sdiod_intr_unregister(bus->sdiodev);

		cancel_work_sync(&bus->datawork);
		if (bus->brcmf_wq)
			destroy_workqueue(bus->brcmf_wq);

		if (bus->sdiodev->bus_if->drvr) {
			brcmf_detach(bus->sdiodev->dev);
4060 4061 4062 4063 4064
		}

		if (bus->ci) {
			sdio_claim_host(bus->sdiodev->func[1]);
			brcmf_sdio_clkctl(bus, CLK_AVAIL, false);
4065 4066 4067 4068 4069
			/* Leave the device in state where it is 'quiet'. This
			 * is done by putting it in download_state which
			 * essentially resets all necessary cores
			 */
			msleep(20);
4070
			brcmf_sdio_chip_enter_download(bus->sdiodev, bus->ci);
4071 4072 4073
			brcmf_sdio_clkctl(bus, CLK_NONE, false);
			sdio_release_host(bus->sdiodev->func[1]);
			brcmf_sdio_chip_detach(&bus->ci);
4074 4075 4076
		}

		brcmu_pkt_buf_free_skb(bus->txglom_sgpad);
4077
		kfree(bus->rxbuf);
4078 4079 4080
		kfree(bus->hdrbuf);
		kfree(bus);
	}
4081 4082 4083 4084

	brcmf_dbg(TRACE, "Disconnected\n");
}

4085
void brcmf_sdio_wd_timer(struct brcmf_sdio *bus, uint wdtick)
4086 4087
{
	/* Totally stop the timer */
4088
	if (!wdtick && bus->wd_timer_valid) {
4089 4090 4091 4092 4093 4094
		del_timer_sync(&bus->timer);
		bus->wd_timer_valid = false;
		bus->save_ms = wdtick;
		return;
	}

4095
	/* don't start the wd until fw is loaded */
4096
	if (bus->sdiodev->bus_if->state != BRCMF_BUS_DATA)
4097 4098
		return;

4099 4100
	if (wdtick) {
		if (bus->save_ms != BRCMF_WD_POLL_MS) {
4101
			if (bus->wd_timer_valid)
4102 4103 4104 4105 4106 4107 4108 4109 4110 4111 4112 4113 4114 4115 4116 4117 4118 4119 4120 4121
				/* Stop timer and restart at new value */
				del_timer_sync(&bus->timer);

			/* Create timer again when watchdog period is
			   dynamically changed or in the first instance
			 */
			bus->timer.expires =
				jiffies + BRCMF_WD_POLL_MS * HZ / 1000;
			add_timer(&bus->timer);

		} else {
			/* Re arm the timer, at last watchdog period */
			mod_timer(&bus->timer,
				jiffies + BRCMF_WD_POLL_MS * HZ / 1000);
		}

		bus->wd_timer_valid = true;
		bus->save_ms = wdtick;
	}
}