iwl-agn.c 106.2 KB
Newer Older
Z
Zhu Yi 已提交
1 2
/******************************************************************************
 *
W
Wey-Yi Guy 已提交
3
 * Copyright(c) 2003 - 2011 Intel Corporation. All rights reserved.
Z
Zhu Yi 已提交
4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24
 *
 * Portions of this file are derived from the ipw3945 project, as well
 * as portions of the ieee80211 subsystem header files.
 *
 * This program is free software; you can redistribute it and/or modify it
 * under the terms of version 2 of the GNU General Public License as
 * published by the Free Software Foundation.
 *
 * This program is distributed in the hope that it will be useful, but WITHOUT
 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
 * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
 * more details.
 *
 * You should have received a copy of the GNU General Public License along with
 * this program; if not, write to the Free Software Foundation, Inc.,
 * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
 *
 * The full GNU General Public License is included in this distribution in the
 * file called LICENSE.
 *
 * Contact Information:
25
 *  Intel Linux Wireless <ilw@linux.intel.com>
Z
Zhu Yi 已提交
26 27 28 29
 * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
 *
 *****************************************************************************/

30 31
#define pr_fmt(fmt) KBUILD_MODNAME ": " fmt

Z
Zhu Yi 已提交
32 33 34
#include <linux/kernel.h>
#include <linux/module.h>
#include <linux/init.h>
35
#include <linux/slab.h>
Z
Zhu Yi 已提交
36 37
#include <linux/dma-mapping.h>
#include <linux/delay.h>
38
#include <linux/sched.h>
Z
Zhu Yi 已提交
39 40 41 42 43 44 45 46 47 48 49
#include <linux/skbuff.h>
#include <linux/netdevice.h>
#include <linux/wireless.h>
#include <linux/firmware.h>
#include <linux/etherdevice.h>
#include <linux/if_arp.h>

#include <net/mac80211.h>

#include <asm/div64.h>

A
Assaf Krauss 已提交
50
#include "iwl-eeprom.h"
51
#include "iwl-dev.h"
52
#include "iwl-core.h"
53
#include "iwl-io.h"
Z
Zhu Yi 已提交
54
#include "iwl-helpers.h"
55
#include "iwl-sta.h"
J
Johannes Berg 已提交
56
#include "iwl-agn-calib.h"
57
#include "iwl-agn.h"
58
#include "iwl-pci.h"
59
#include "iwl-trans.h"
60

Z
Zhu Yi 已提交
61 62 63 64 65 66 67 68 69
/******************************************************************************
 *
 * module boiler plate
 *
 ******************************************************************************/

/*
 * module name, copyright, version, etc.
 */
70
#define DRV_DESCRIPTION	"Intel(R) Wireless WiFi Link AGN driver for Linux"
Z
Zhu Yi 已提交
71

72
#ifdef CONFIG_IWLWIFI_DEBUG
Z
Zhu Yi 已提交
73 74 75 76 77
#define VD "d"
#else
#define VD
#endif

78
#define DRV_VERSION     IWLWIFI_VERSION VD
Z
Zhu Yi 已提交
79 80 81 82


MODULE_DESCRIPTION(DRV_DESCRIPTION);
MODULE_VERSION(DRV_VERSION);
83
MODULE_AUTHOR(DRV_COPYRIGHT " " DRV_AUTHOR);
Z
Zhu Yi 已提交
84 85
MODULE_LICENSE("GPL");

86
static int iwlagn_ant_coupling;
87
static bool iwlagn_bt_ch_announce = 1;
88

89
void iwl_update_chain_flags(struct iwl_priv *priv)
M
Mohamed Abbas 已提交
90
{
91
	struct iwl_rxon_context *ctx;
M
Mohamed Abbas 已提交
92

93 94 95
	if (priv->cfg->ops->hcmd->set_rxon_chain) {
		for_each_context(priv, ctx) {
			priv->cfg->ops->hcmd->set_rxon_chain(priv, ctx);
96
			if (ctx->active.rx_chain != ctx->staging.rx_chain)
97
				iwlagn_commit_rxon(priv, ctx);
98 99
		}
	}
M
Mohamed Abbas 已提交
100 101
}

102 103
/* Parse the beacon frame to find the TIM element and set tim_idx & tim_size */
static void iwl_set_beacon_tim(struct iwl_priv *priv,
104 105
			       struct iwl_tx_beacon_cmd *tx_beacon_cmd,
			       u8 *beacon, u32 frame_size)
106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128
{
	u16 tim_idx;
	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)beacon;

	/*
	 * The index is relative to frame start but we start looking at the
	 * variable-length part of the beacon.
	 */
	tim_idx = mgmt->u.beacon.variable - beacon;

	/* Parse variable-length elements of beacon to find WLAN_EID_TIM */
	while ((tim_idx < (frame_size - 2)) &&
			(beacon[tim_idx] != WLAN_EID_TIM))
		tim_idx += beacon[tim_idx+1] + 2;

	/* If TIM field was found, set variables */
	if ((tim_idx < (frame_size - 1)) && (beacon[tim_idx] == WLAN_EID_TIM)) {
		tx_beacon_cmd->tim_idx = cpu_to_le16(tim_idx);
		tx_beacon_cmd->tim_size = beacon[tim_idx+1];
	} else
		IWL_WARN(priv, "Unable to find TIM Element in beacon\n");
}

129
int iwlagn_send_beacon_cmd(struct iwl_priv *priv)
130 131
{
	struct iwl_tx_beacon_cmd *tx_beacon_cmd;
132 133 134
	struct iwl_host_cmd cmd = {
		.id = REPLY_TX_BEACON,
	};
135
	struct ieee80211_tx_info *info;
136 137 138
	u32 frame_size;
	u32 rate_flags;
	u32 rate;
139

140 141 142 143
	/*
	 * We have to set up the TX command, the TX Beacon command, and the
	 * beacon contents.
	 */
144

145 146 147 148
	lockdep_assert_held(&priv->mutex);

	if (!priv->beacon_ctx) {
		IWL_ERR(priv, "trying to build beacon w/o beacon context!\n");
149
		return 0;
150 151
	}

152 153 154
	if (WARN_ON(!priv->beacon_skb))
		return -EINVAL;

155 156 157 158
	/* Allocate beacon command */
	if (!priv->beacon_cmd)
		priv->beacon_cmd = kzalloc(sizeof(*tx_beacon_cmd), GFP_KERNEL);
	tx_beacon_cmd = priv->beacon_cmd;
159 160 161 162
	if (!tx_beacon_cmd)
		return -ENOMEM;

	frame_size = priv->beacon_skb->len;
163

164
	/* Set up TX command fields */
165
	tx_beacon_cmd->tx.len = cpu_to_le16((u16)frame_size);
166
	tx_beacon_cmd->tx.sta_id = priv->beacon_ctx->bcast_sta_id;
167 168 169
	tx_beacon_cmd->tx.stop_time.life_time = TX_CMD_LIFE_TIME_INFINITE;
	tx_beacon_cmd->tx.tx_flags = TX_CMD_FLG_SEQ_CTL_MSK |
		TX_CMD_FLG_TSF_MSK | TX_CMD_FLG_STA_RATE_MSK;
170

171
	/* Set up TX beacon command fields */
172
	iwl_set_beacon_tim(priv, tx_beacon_cmd, priv->beacon_skb->data,
173
			   frame_size);
174

175
	/* Set up packet rate and flags */
176 177 178 179 180 181 182 183 184 185 186 187 188
	info = IEEE80211_SKB_CB(priv->beacon_skb);

	/*
	 * Let's set up the rate at least somewhat correctly;
	 * it will currently not actually be used by the uCode,
	 * it uses the broadcast station's rate instead.
	 */
	if (info->control.rates[0].idx < 0 ||
	    info->control.rates[0].flags & IEEE80211_TX_RC_MCS)
		rate = 0;
	else
		rate = info->control.rates[0].idx;

189 190
	priv->mgmt_tx_ant = iwl_toggle_tx_ant(priv, priv->mgmt_tx_ant,
					      priv->hw_params.valid_tx_ant);
191
	rate_flags = iwl_ant_idx_to_flags(priv->mgmt_tx_ant);
192 193 194 195 196

	/* In mac80211, rates for 5 GHz start at 0 */
	if (info->band == IEEE80211_BAND_5GHZ)
		rate += IWL_FIRST_OFDM_RATE;
	else if (rate >= IWL_FIRST_CCK_RATE && rate <= IWL_LAST_CCK_RATE)
197
		rate_flags |= RATE_MCS_CCK_MSK;
198 199 200

	tx_beacon_cmd->tx.rate_n_flags =
			iwl_hw_set_rate_n_flags(rate, rate_flags);
201

202
	/* Submit command */
203
	cmd.len[0] = sizeof(*tx_beacon_cmd);
204
	cmd.data[0] = tx_beacon_cmd;
205 206 207 208
	cmd.dataflags[0] = IWL_HCMD_DFL_NOCOPY;
	cmd.len[1] = frame_size;
	cmd.data[1] = priv->beacon_skb->data;
	cmd.dataflags[1] = IWL_HCMD_DFL_NOCOPY;
209

210
	return iwl_send_cmd_sync(priv, &cmd);
211 212
}

213
static void iwl_bg_beacon_update(struct work_struct *work)
Z
Zhu Yi 已提交
214
{
215 216
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, beacon_update);
Z
Zhu Yi 已提交
217 218
	struct sk_buff *beacon;

219 220 221 222 223
	mutex_lock(&priv->mutex);
	if (!priv->beacon_ctx) {
		IWL_ERR(priv, "updating beacon w/o beacon context!\n");
		goto out;
	}
Z
Zhu Yi 已提交
224

225 226 227 228 229 230 231 232 233 234
	if (priv->beacon_ctx->vif->type != NL80211_IFTYPE_AP) {
		/*
		 * The ucode will send beacon notifications even in
		 * IBSS mode, but we don't want to process them. But
		 * we need to defer the type check to here due to
		 * requiring locking around the beacon_ctx access.
		 */
		goto out;
	}

235 236
	/* Pull updated AP beacon from mac80211. will fail if not in AP mode */
	beacon = ieee80211_beacon_get(priv->hw, priv->beacon_ctx->vif);
Z
Zhu Yi 已提交
237
	if (!beacon) {
238
		IWL_ERR(priv, "update beacon failed -- keeping old\n");
239
		goto out;
Z
Zhu Yi 已提交
240 241 242
	}

	/* new beacon skb is allocated every time; dispose previous.*/
243
	dev_kfree_skb(priv->beacon_skb);
Z
Zhu Yi 已提交
244

245
	priv->beacon_skb = beacon;
Z
Zhu Yi 已提交
246

247
	iwlagn_send_beacon_cmd(priv);
248 249
 out:
	mutex_unlock(&priv->mutex);
Z
Zhu Yi 已提交
250 251
}

252 253 254 255 256 257 258 259 260 261 262 263 264 265
static void iwl_bg_bt_runtime_config(struct work_struct *work)
{
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, bt_runtime_config);

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	/* dont send host command if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
		return;
	priv->cfg->ops->hcmd->send_bt_config(priv);
}

266 267 268 269
static void iwl_bg_bt_full_concurrency(struct work_struct *work)
{
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, bt_full_concurrency);
270
	struct iwl_rxon_context *ctx;
271

272 273
	mutex_lock(&priv->mutex);

274
	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
275
		goto out;
276 277 278

	/* dont send host command if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
279
		goto out;
280 281 282 283 284 285 286 287 288

	IWL_DEBUG_INFO(priv, "BT coex in %s mode\n",
		       priv->bt_full_concurrent ?
		       "full concurrency" : "3-wire");

	/*
	 * LQ & RXON updated cmds must be sent before BT Config cmd
	 * to avoid 3-wire collisions
	 */
289 290 291
	for_each_context(priv, ctx) {
		if (priv->cfg->ops->hcmd->set_rxon_chain)
			priv->cfg->ops->hcmd->set_rxon_chain(priv, ctx);
292
		iwlagn_commit_rxon(priv, ctx);
293
	}
294 295

	priv->cfg->ops->hcmd->send_bt_config(priv);
296 297
out:
	mutex_unlock(&priv->mutex);
298 299
}

300
/**
301
 * iwl_bg_statistics_periodic - Timer callback to queue statistics
302 303 304 305 306 307 308 309
 *
 * This callback is provided in order to send a statistics request.
 *
 * This timer function is continually reset to execute within
 * REG_RECALIB_PERIOD seconds since the last STATISTICS_NOTIFICATION
 * was received.  We need to ensure we receive the statistics in order
 * to update the temperature used for calibrating the TXPOWER.
 */
310
static void iwl_bg_statistics_periodic(unsigned long data)
311 312 313 314 315 316
{
	struct iwl_priv *priv = (struct iwl_priv *)data;

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

317 318 319 320
	/* dont send host command if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
		return;

321
	iwl_send_statistics_request(priv, CMD_ASYNC, false);
322 323
}

324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346

static void iwl_print_cont_event_trace(struct iwl_priv *priv, u32 base,
					u32 start_idx, u32 num_events,
					u32 mode)
{
	u32 i;
	u32 ptr;        /* SRAM byte address of log data */
	u32 ev, time, data; /* event log data */
	unsigned long reg_flags;

	if (mode == 0)
		ptr = base + (4 * sizeof(u32)) + (start_idx * 2 * sizeof(u32));
	else
		ptr = base + (4 * sizeof(u32)) + (start_idx * 3 * sizeof(u32));

	/* Make sure device is powered up for SRAM reads */
	spin_lock_irqsave(&priv->reg_lock, reg_flags);
	if (iwl_grab_nic_access(priv)) {
		spin_unlock_irqrestore(&priv->reg_lock, reg_flags);
		return;
	}

	/* Set starting address; reads will auto-increment */
347
	iwl_write32(priv, HBUS_TARG_MEM_RADDR, ptr);
348 349 350 351 352 353 354
	rmb();

	/*
	 * "time" is actually "data" for mode 0 (no timestamp).
	 * place event id # at far right for easier visual parsing.
	 */
	for (i = 0; i < num_events; i++) {
355 356
		ev = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
		time = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
357 358 359 360
		if (mode == 0) {
			trace_iwlwifi_dev_ucode_cont_event(priv,
							0, time, ev);
		} else {
361
			data = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
362 363 364 365 366 367 368 369 370
			trace_iwlwifi_dev_ucode_cont_event(priv,
						time, data, ev);
		}
	}
	/* Allow device to power down */
	iwl_release_nic_access(priv);
	spin_unlock_irqrestore(&priv->reg_lock, reg_flags);
}

J
Johannes Berg 已提交
371
static void iwl_continuous_event_trace(struct iwl_priv *priv)
372 373 374 375 376 377 378
{
	u32 capacity;   /* event log capacity in # entries */
	u32 base;       /* SRAM byte address of event log header */
	u32 mode;       /* 0 - no timestamp, 1 - timestamp recorded */
	u32 num_wraps;  /* # times uCode wrapped to top of log */
	u32 next_entry; /* index of next entry to be written by uCode */

J
Johannes Berg 已提交
379
	base = priv->device_pointers.error_event_table;
380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445
	if (priv->cfg->ops->lib->is_valid_rtc_data_addr(base)) {
		capacity = iwl_read_targ_mem(priv, base);
		num_wraps = iwl_read_targ_mem(priv, base + (2 * sizeof(u32)));
		mode = iwl_read_targ_mem(priv, base + (1 * sizeof(u32)));
		next_entry = iwl_read_targ_mem(priv, base + (3 * sizeof(u32)));
	} else
		return;

	if (num_wraps == priv->event_log.num_wraps) {
		iwl_print_cont_event_trace(priv,
				       base, priv->event_log.next_entry,
				       next_entry - priv->event_log.next_entry,
				       mode);
		priv->event_log.non_wraps_count++;
	} else {
		if ((num_wraps - priv->event_log.num_wraps) > 1)
			priv->event_log.wraps_more_count++;
		else
			priv->event_log.wraps_once_count++;
		trace_iwlwifi_dev_ucode_wrap_event(priv,
				num_wraps - priv->event_log.num_wraps,
				next_entry, priv->event_log.next_entry);
		if (next_entry < priv->event_log.next_entry) {
			iwl_print_cont_event_trace(priv, base,
			       priv->event_log.next_entry,
			       capacity - priv->event_log.next_entry,
			       mode);

			iwl_print_cont_event_trace(priv, base, 0,
				next_entry, mode);
		} else {
			iwl_print_cont_event_trace(priv, base,
			       next_entry, capacity - next_entry,
			       mode);

			iwl_print_cont_event_trace(priv, base, 0,
				next_entry, mode);
		}
	}
	priv->event_log.num_wraps = num_wraps;
	priv->event_log.next_entry = next_entry;
}

/**
 * iwl_bg_ucode_trace - Timer callback to log ucode event
 *
 * The timer is continually set to execute every
 * UCODE_TRACE_PERIOD milliseconds after the last timer expired
 * this function is to perform continuous uCode event logging operation
 * if enabled
 */
static void iwl_bg_ucode_trace(unsigned long data)
{
	struct iwl_priv *priv = (struct iwl_priv *)data;

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	if (priv->event_log.ucode_trace) {
		iwl_continuous_event_trace(priv);
		/* Reschedule the timer to occur in UCODE_TRACE_PERIOD */
		mod_timer(&priv->ucode_trace,
			 jiffies + msecs_to_jiffies(UCODE_TRACE_PERIOD));
	}
}

446 447 448 449 450 451 452 453 454 455 456 457
static void iwl_bg_tx_flush(struct work_struct *work)
{
	struct iwl_priv *priv =
		container_of(work, struct iwl_priv, tx_flush);

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	/* do nothing if rf-kill is on */
	if (!iwl_is_ready_rf(priv))
		return;

458 459
	IWL_DEBUG_INFO(priv, "device request: flush all tx frames\n");
	iwlagn_dev_txfifo_flush(priv, IWL_DROP_ALL);
460 461
}

Z
Zhu Yi 已提交
462
/**
463
 * iwl_rx_handle - Main entry function for receiving responses from uCode
Z
Zhu Yi 已提交
464 465 466 467 468
 *
 * Uses the priv->rx_handlers callback function array to invoke
 * the appropriate handlers, including command responses,
 * frame-received notifications, and other notifications.
 */
469
static void iwl_rx_handle(struct iwl_priv *priv)
Z
Zhu Yi 已提交
470
{
471
	struct iwl_rx_mem_buffer *rxb;
472
	struct iwl_rx_packet *pkt;
473
	struct iwl_rx_queue *rxq = &priv->rxq;
Z
Zhu Yi 已提交
474 475 476
	u32 r, i;
	int reclaim;
	unsigned long flags;
477
	u8 fill_rx = 0;
M
Mohamed Abbas 已提交
478
	u32 count = 8;
479
	int total_empty;
Z
Zhu Yi 已提交
480

481 482
	/* uCode's read index (stored in shared DRAM) indicates the last Rx
	 * buffer that the driver may process (last buffer filled by ucode). */
483
	r = le16_to_cpu(rxq->rb_stts->closed_rb_num) &  0x0FFF;
Z
Zhu Yi 已提交
484 485 486 487
	i = rxq->read;

	/* Rx interrupt, but nothing sent from uCode */
	if (i == r)
488
		IWL_DEBUG_RX(priv, "r = %d, i = %d\n", r, i);
Z
Zhu Yi 已提交
489

490
	/* calculate total frames need to be restock after handling RX */
491
	total_empty = r - rxq->write_actual;
492 493 494 495
	if (total_empty < 0)
		total_empty += RX_QUEUE_SIZE;

	if (total_empty > (RX_QUEUE_SIZE / 2))
496 497
		fill_rx = 1;

Z
Zhu Yi 已提交
498
	while (i != r) {
J
Johannes Berg 已提交
499 500
		int len;

Z
Zhu Yi 已提交
501 502
		rxb = rxq->queue[i];

503
		/* If an RXB doesn't have a Rx queue slot associated with it,
Z
Zhu Yi 已提交
504 505
		 * then a bug has been introduced in the queue refilling
		 * routines -- catch it here */
506 507 508 509
		if (WARN_ON(rxb == NULL)) {
			i = (i + 1) & RX_QUEUE_MASK;
			continue;
		}
Z
Zhu Yi 已提交
510 511 512

		rxq->queue[i] = NULL;

513
		dma_unmap_page(priv->bus.dev, rxb->page_dma,
Z
Zhu Yi 已提交
514
			       PAGE_SIZE << priv->hw_params.rx_page_order,
515
			       DMA_FROM_DEVICE);
Z
Zhu Yi 已提交
516
		pkt = rxb_addr(rxb);
Z
Zhu Yi 已提交
517

J
Johannes Berg 已提交
518 519 520
		len = le32_to_cpu(pkt->len_n_flags) & FH_RSCSR_FRAME_SIZE_MSK;
		len += sizeof(u32); /* account for status word */
		trace_iwlwifi_dev_rx(priv, pkt, len);
J
Johannes Berg 已提交
521

Z
Zhu Yi 已提交
522 523 524 525 526 527 528 529
		/* Reclaim a command buffer only if this packet is a response
		 *   to a (driver-originated) command.
		 * If the packet (e.g. Rx frame) originated from uCode,
		 *   there is no command buffer to reclaim.
		 * Ucode should set SEQ_RX_FRAME bit if ucode-originated,
		 *   but apparently a few don't get set; catch them here. */
		reclaim = !(pkt->hdr.sequence & SEQ_RX_FRAME) &&
			(pkt->hdr.cmd != REPLY_RX_PHY_CMD) &&
530
			(pkt->hdr.cmd != REPLY_RX) &&
D
Daniel Halperin 已提交
531
			(pkt->hdr.cmd != REPLY_RX_MPDU_CMD) &&
532
			(pkt->hdr.cmd != REPLY_COMPRESSED_BA) &&
Z
Zhu Yi 已提交
533 534 535
			(pkt->hdr.cmd != STATISTICS_NOTIFICATION) &&
			(pkt->hdr.cmd != REPLY_TX);

536 537 538 539 540 541 542 543 544 545 546 547 548
		/*
		 * Do the notification wait before RX handlers so
		 * even if the RX handler consumes the RXB we have
		 * access to it in the notification wait entry.
		 */
		if (!list_empty(&priv->_agn.notif_waits)) {
			struct iwl_notification_wait *w;

			spin_lock(&priv->_agn.notif_wait_lock);
			list_for_each_entry(w, &priv->_agn.notif_waits, list) {
				if (w->cmd == pkt->hdr.cmd) {
					w->triggered = true;
					if (w->fn)
549
						w->fn(priv, pkt, w->fn_data);
550 551 552 553 554 555
				}
			}
			spin_unlock(&priv->_agn.notif_wait_lock);

			wake_up_all(&priv->_agn.notif_waitq);
		}
556 557
		if (priv->pre_rx_handler)
			priv->pre_rx_handler(priv, rxb);
558

Z
Zhu Yi 已提交
559 560
		/* Based on type of command response or notification,
		 *   handle those that need handling via function in
561
		 *   rx_handlers table.  See iwl_setup_rx_handlers() */
Z
Zhu Yi 已提交
562
		if (priv->rx_handlers[pkt->hdr.cmd]) {
563
			IWL_DEBUG_RX(priv, "r = %d, i = %d, %s, 0x%02x\n", r,
564
				i, get_cmd_string(pkt->hdr.cmd), pkt->hdr.cmd);
565
			priv->isr_stats.rx_handlers[pkt->hdr.cmd]++;
566
			priv->rx_handlers[pkt->hdr.cmd] (priv, rxb);
Z
Zhu Yi 已提交
567 568
		} else {
			/* No handling needed */
569
			IWL_DEBUG_RX(priv,
Z
Zhu Yi 已提交
570 571 572 573 574
				"r %d i %d No handler needed for %s, 0x%02x\n",
				r, i, get_cmd_string(pkt->hdr.cmd),
				pkt->hdr.cmd);
		}

575 576 577 578 579 580 581
		/*
		 * XXX: After here, we should always check rxb->page
		 * against NULL before touching it or its virtual
		 * memory (pkt). Because some rx_handler might have
		 * already taken or freed the pages.
		 */

Z
Zhu Yi 已提交
582
		if (reclaim) {
Z
Zhu Yi 已提交
583 584
			/* Invoke any callbacks, transfer the buffer to caller,
			 * and fire off the (possibly) blocking iwl_send_cmd()
Z
Zhu Yi 已提交
585
			 * as we reclaim the driver command queue */
586
			if (rxb->page)
587
				iwl_tx_cmd_complete(priv, rxb);
Z
Zhu Yi 已提交
588
			else
589
				IWL_WARN(priv, "Claim null rxb?\n");
Z
Zhu Yi 已提交
590 591
		}

592 593 594 595
		/* Reuse the page if possible. For notification packets and
		 * SKBs that fail to Rx correctly, add them back into the
		 * rx_free list for reuse later. */
		spin_lock_irqsave(&rxq->lock, flags);
Z
Zhu Yi 已提交
596
		if (rxb->page != NULL) {
597
			rxb->page_dma = dma_map_page(priv->bus.dev, rxb->page,
598
				0, PAGE_SIZE << priv->hw_params.rx_page_order,
599
				DMA_FROM_DEVICE);
600 601 602 603
			list_add_tail(&rxb->list, &rxq->rx_free);
			rxq->free_count++;
		} else
			list_add_tail(&rxb->list, &rxq->rx_used);
Z
Zhu Yi 已提交
604 605

		spin_unlock_irqrestore(&rxq->lock, flags);
606

Z
Zhu Yi 已提交
607
		i = (i + 1) & RX_QUEUE_MASK;
608 609 610 611 612
		/* If there are a lot of unused frames,
		 * restock the Rx queue so ucode wont assert. */
		if (fill_rx) {
			count++;
			if (count >= 8) {
613
				rxq->read = i;
614
				iwlagn_rx_replenish_now(priv);
615 616 617
				count = 0;
			}
		}
Z
Zhu Yi 已提交
618 619 620
	}

	/* Backtrack one entry */
621
	rxq->read = i;
622
	if (fill_rx)
623
		iwlagn_rx_replenish_now(priv);
624
	else
625
		iwlagn_rx_queue_restock(priv);
626 627
}

M
Mohamed Abbas 已提交
628 629 630 631 632 633
/* tasklet for iwlagn interrupt */
static void iwl_irq_tasklet(struct iwl_priv *priv)
{
	u32 inta = 0;
	u32 handled = 0;
	unsigned long flags;
634
	u32 i;
M
Mohamed Abbas 已提交
635 636 637 638 639 640 641 642 643
#ifdef CONFIG_IWLWIFI_DEBUG
	u32 inta_mask;
#endif

	spin_lock_irqsave(&priv->lock, flags);

	/* Ack/clear/reset pending uCode interrupts.
	 * Note:  Some bits in CSR_INT are "OR" of bits in CSR_FH_INT_STATUS,
	 */
644 645 646 647 648 649 650 651
	/* There is a hardware bug in the interrupt mask function that some
	 * interrupts (i.e. CSR_INT_BIT_SCD) can still be generated even if
	 * they are disabled in the CSR_INT_MASK register. Furthermore the
	 * ICT interrupt handling mechanism has another bug that might cause
	 * these unmasked interrupts fail to be detected. We workaround the
	 * hardware bugs here by ACKing all the possible interrupts so that
	 * interrupt coalescing can still be achieved.
	 */
652
	iwl_write32(priv, CSR_INT, priv->_agn.inta | ~priv->inta_mask);
M
Mohamed Abbas 已提交
653

654
	inta = priv->_agn.inta;
M
Mohamed Abbas 已提交
655 656

#ifdef CONFIG_IWLWIFI_DEBUG
657
	if (iwl_get_debug_level(priv) & IWL_DL_ISR) {
M
Mohamed Abbas 已提交
658 659 660 661 662 663
		/* just for debug */
		inta_mask = iwl_read32(priv, CSR_INT_MASK);
		IWL_DEBUG_ISR(priv, "inta 0x%08x, enabled 0x%08x\n ",
				inta, inta_mask);
	}
#endif
Z
Zhu Yi 已提交
664 665 666

	spin_unlock_irqrestore(&priv->lock, flags);

667 668
	/* saved interrupt in inta variable now we can reset priv->_agn.inta */
	priv->_agn.inta = 0;
M
Mohamed Abbas 已提交
669 670 671

	/* Now service all interrupt bits discovered above. */
	if (inta & CSR_INT_BIT_HW_ERR) {
672
		IWL_ERR(priv, "Hardware error detected.  Restarting.\n");
M
Mohamed Abbas 已提交
673 674 675 676 677 678 679 680 681 682 683 684 685

		/* Tell the device to stop sending interrupts */
		iwl_disable_interrupts(priv);

		priv->isr_stats.hw++;
		iwl_irq_handle_error(priv);

		handled |= CSR_INT_BIT_HW_ERR;

		return;
	}

#ifdef CONFIG_IWLWIFI_DEBUG
686
	if (iwl_get_debug_level(priv) & (IWL_DL_ISR)) {
M
Mohamed Abbas 已提交
687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710
		/* NIC fires this, but we don't use it, redundant with WAKEUP */
		if (inta & CSR_INT_BIT_SCD) {
			IWL_DEBUG_ISR(priv, "Scheduler finished to transmit "
				      "the frame/frames.\n");
			priv->isr_stats.sch++;
		}

		/* Alive notification via Rx interrupt will do the real work */
		if (inta & CSR_INT_BIT_ALIVE) {
			IWL_DEBUG_ISR(priv, "Alive interrupt\n");
			priv->isr_stats.alive++;
		}
	}
#endif
	/* Safely ignore these bits for debug checks below */
	inta &= ~(CSR_INT_BIT_SCD | CSR_INT_BIT_ALIVE);

	/* HW RF KILL switch toggled */
	if (inta & CSR_INT_BIT_RF_KILL) {
		int hw_rf_kill = 0;
		if (!(iwl_read32(priv, CSR_GP_CNTRL) &
				CSR_GP_CNTRL_REG_FLAG_HW_RF_KILL_SW))
			hw_rf_kill = 1;

711
		IWL_WARN(priv, "RF_KILL bit toggled to %s.\n",
M
Mohamed Abbas 已提交
712 713 714 715 716 717 718 719 720 721 722 723 724 725
				hw_rf_kill ? "disable radio" : "enable radio");

		priv->isr_stats.rfkill++;

		/* driver only loads ucode once setting the interface up.
		 * the driver allows loading the ucode even if the radio
		 * is killed. Hence update the killswitch state here. The
		 * rfkill handler will care about restarting if needed.
		 */
		if (!test_bit(STATUS_ALIVE, &priv->status)) {
			if (hw_rf_kill)
				set_bit(STATUS_RF_KILL_HW, &priv->status);
			else
				clear_bit(STATUS_RF_KILL_HW, &priv->status);
J
Johannes Berg 已提交
726
			wiphy_rfkill_set_hw_state(priv->hw->wiphy, hw_rf_kill);
M
Mohamed Abbas 已提交
727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751
		}

		handled |= CSR_INT_BIT_RF_KILL;
	}

	/* Chip got too hot and stopped itself */
	if (inta & CSR_INT_BIT_CT_KILL) {
		IWL_ERR(priv, "Microcode CT kill error detected.\n");
		priv->isr_stats.ctkill++;
		handled |= CSR_INT_BIT_CT_KILL;
	}

	/* Error detected by uCode */
	if (inta & CSR_INT_BIT_SW_ERR) {
		IWL_ERR(priv, "Microcode SW error detected. "
			" Restarting 0x%X.\n", inta);
		priv->isr_stats.sw++;
		iwl_irq_handle_error(priv);
		handled |= CSR_INT_BIT_SW_ERR;
	}

	/* uCode wakes up after power-down sleep */
	if (inta & CSR_INT_BIT_WAKEUP) {
		IWL_DEBUG_ISR(priv, "Wakeup interrupt\n");
		iwl_rx_queue_update_write_ptr(priv, &priv->rxq);
752 753
		for (i = 0; i < priv->hw_params.max_txq_num; i++)
			iwl_txq_update_write_ptr(priv, &priv->txq[i]);
M
Mohamed Abbas 已提交
754 755 756 757 758 759 760 761 762

		priv->isr_stats.wakeup++;

		handled |= CSR_INT_BIT_WAKEUP;
	}

	/* All uCode command responses, including Tx command responses,
	 * Rx "responses" (frame-received notification), and other
	 * notifications from uCode come through here*/
763 764
	if (inta & (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX |
			CSR_INT_BIT_RX_PERIODIC)) {
M
Mohamed Abbas 已提交
765
		IWL_DEBUG_ISR(priv, "Rx interrupt\n");
766 767 768
		if (inta & (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX)) {
			handled |= (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX);
			iwl_write32(priv, CSR_FH_INT_STATUS,
769
					CSR_FH_INT_RX_MASK);
770 771 772 773 774 775 776 777 778 779 780 781
		}
		if (inta & CSR_INT_BIT_RX_PERIODIC) {
			handled |= CSR_INT_BIT_RX_PERIODIC;
			iwl_write32(priv, CSR_INT, CSR_INT_BIT_RX_PERIODIC);
		}
		/* Sending RX interrupt require many steps to be done in the
		 * the device:
		 * 1- write interrupt to current index in ICT table.
		 * 2- dma RX frame.
		 * 3- update RX shared data to indicate last write index.
		 * 4- send interrupt.
		 * This could lead to RX race, driver could receive RX interrupt
782 783
		 * but the shared data changes does not reflect this;
		 * periodic interrupt will detect any dangling Rx activity.
784
		 */
785 786 787

		/* Disable periodic interrupt; we use it as just a one-shot. */
		iwl_write8(priv, CSR_INT_PERIODIC_REG,
788
			    CSR_INT_PERIODIC_DIS);
M
Mohamed Abbas 已提交
789
		iwl_rx_handle(priv);
790 791 792 793 794 795 796 797

		/*
		 * Enable periodic interrupt in 8 msec only if we received
		 * real RX interrupt (instead of just periodic int), to catch
		 * any dangling Rx interrupt.  If it was just the periodic
		 * interrupt, there was no dangling Rx activity, and no need
		 * to extend the periodic interrupt; one-shot is enough.
		 */
798
		if (inta & (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX))
799
			iwl_write8(priv, CSR_INT_PERIODIC_REG,
800 801
				    CSR_INT_PERIODIC_ENA);

M
Mohamed Abbas 已提交
802 803 804
		priv->isr_stats.rx++;
	}

B
Ben Cahill 已提交
805
	/* This "Tx" DMA channel is used only for loading uCode */
M
Mohamed Abbas 已提交
806
	if (inta & CSR_INT_BIT_FH_TX) {
807
		iwl_write32(priv, CSR_FH_INT_STATUS, CSR_FH_INT_TX_MASK);
B
Ben Cahill 已提交
808
		IWL_DEBUG_ISR(priv, "uCode load interrupt\n");
M
Mohamed Abbas 已提交
809 810
		priv->isr_stats.tx++;
		handled |= CSR_INT_BIT_FH_TX;
B
Ben Cahill 已提交
811
		/* Wake up uCode load routine, now that load is complete */
M
Mohamed Abbas 已提交
812 813 814 815 816 817 818 819 820
		priv->ucode_write_complete = 1;
		wake_up_interruptible(&priv->wait_command_queue);
	}

	if (inta & ~handled) {
		IWL_ERR(priv, "Unhandled INTA bits 0x%08x\n", inta & ~handled);
		priv->isr_stats.unhandled++;
	}

821
	if (inta & ~(priv->inta_mask)) {
M
Mohamed Abbas 已提交
822
		IWL_WARN(priv, "Disabled INTA bits 0x%08x were pending\n",
823
			 inta & ~priv->inta_mask);
M
Mohamed Abbas 已提交
824 825 826
	}

	/* Re-enable all interrupts */
827
	/* only Re-enable if disabled by irq */
M
Mohamed Abbas 已提交
828 829
	if (test_bit(STATUS_INT_ENABLED, &priv->status))
		iwl_enable_interrupts(priv);
830 831 832
	/* Re-enable RF_KILL if it occurred */
	else if (handled & CSR_INT_BIT_RF_KILL)
		iwl_enable_rfkill_int(priv);
M
Mohamed Abbas 已提交
833 834
}

835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948
/*****************************************************************************
 *
 * sysfs attributes
 *
 *****************************************************************************/

#ifdef CONFIG_IWLWIFI_DEBUG

/*
 * The following adds a new attribute to the sysfs representation
 * of this device driver (i.e. a new file in /sys/class/net/wlan0/device/)
 * used for controlling the debug level.
 *
 * See the level definitions in iwl for details.
 *
 * The debug_level being managed using sysfs below is a per device debug
 * level that is used instead of the global debug level if it (the per
 * device debug level) is set.
 */
static ssize_t show_debug_level(struct device *d,
				struct device_attribute *attr, char *buf)
{
	struct iwl_priv *priv = dev_get_drvdata(d);
	return sprintf(buf, "0x%08X\n", iwl_get_debug_level(priv));
}
static ssize_t store_debug_level(struct device *d,
				struct device_attribute *attr,
				 const char *buf, size_t count)
{
	struct iwl_priv *priv = dev_get_drvdata(d);
	unsigned long val;
	int ret;

	ret = strict_strtoul(buf, 0, &val);
	if (ret)
		IWL_ERR(priv, "%s is not in hex or decimal form.\n", buf);
	else {
		priv->debug_level = val;
		if (iwl_alloc_traffic_mem(priv))
			IWL_ERR(priv,
				"Not enough memory to generate traffic log\n");
	}
	return strnlen(buf, count);
}

static DEVICE_ATTR(debug_level, S_IWUSR | S_IRUGO,
			show_debug_level, store_debug_level);


#endif /* CONFIG_IWLWIFI_DEBUG */


static ssize_t show_temperature(struct device *d,
				struct device_attribute *attr, char *buf)
{
	struct iwl_priv *priv = dev_get_drvdata(d);

	if (!iwl_is_alive(priv))
		return -EAGAIN;

	return sprintf(buf, "%d\n", priv->temperature);
}

static DEVICE_ATTR(temperature, S_IRUGO, show_temperature, NULL);

static ssize_t show_tx_power(struct device *d,
			     struct device_attribute *attr, char *buf)
{
	struct iwl_priv *priv = dev_get_drvdata(d);

	if (!iwl_is_ready_rf(priv))
		return sprintf(buf, "off\n");
	else
		return sprintf(buf, "%d\n", priv->tx_power_user_lmt);
}

static ssize_t store_tx_power(struct device *d,
			      struct device_attribute *attr,
			      const char *buf, size_t count)
{
	struct iwl_priv *priv = dev_get_drvdata(d);
	unsigned long val;
	int ret;

	ret = strict_strtoul(buf, 10, &val);
	if (ret)
		IWL_INFO(priv, "%s is not in decimal form.\n", buf);
	else {
		ret = iwl_set_tx_power(priv, val, false);
		if (ret)
			IWL_ERR(priv, "failed setting tx power (0x%d).\n",
				ret);
		else
			ret = count;
	}
	return ret;
}

static DEVICE_ATTR(tx_power, S_IWUSR | S_IRUGO, show_tx_power, store_tx_power);

static struct attribute *iwl_sysfs_entries[] = {
	&dev_attr_temperature.attr,
	&dev_attr_tx_power.attr,
#ifdef CONFIG_IWLWIFI_DEBUG
	&dev_attr_debug_level.attr,
#endif
	NULL
};

static struct attribute_group iwl_attribute_group = {
	.name = NULL,		/* put in device directory */
	.attrs = iwl_sysfs_entries,
};

Z
Zhu Yi 已提交
949 950 951 952 953 954
/******************************************************************************
 *
 * uCode download functions
 *
 ******************************************************************************/

955
static void iwl_free_fw_desc(struct iwl_priv *priv, struct fw_desc *desc)
956 957
{
	if (desc->v_addr)
958
		dma_free_coherent(priv->bus.dev, desc->len,
959 960 961 962 963
				  desc->v_addr, desc->p_addr);
	desc->v_addr = NULL;
	desc->len = 0;
}

964
static void iwl_free_fw_img(struct iwl_priv *priv, struct fw_img *img)
965
{
966 967
	iwl_free_fw_desc(priv, &img->code);
	iwl_free_fw_desc(priv, &img->data);
968 969
}

970 971 972 973 974 975 976
static void iwl_dealloc_ucode(struct iwl_priv *priv)
{
	iwl_free_fw_img(priv, &priv->ucode_rt);
	iwl_free_fw_img(priv, &priv->ucode_init);
}

static int iwl_alloc_fw_desc(struct iwl_priv *priv, struct fw_desc *desc,
977 978 979 980 981 982 983
			     const void *data, size_t len)
{
	if (!len) {
		desc->v_addr = NULL;
		return -EINVAL;
	}

984
	desc->v_addr = dma_alloc_coherent(priv->bus.dev, len,
985 986 987
					  &desc->p_addr, GFP_KERNEL);
	if (!desc->v_addr)
		return -ENOMEM;
988

989 990 991 992 993
	desc->len = len;
	memcpy(desc->v_addr, data, len);
	return 0;
}

994 995
struct iwlagn_ucode_capabilities {
	u32 max_probe_length;
996
	u32 standard_phy_calibration_size;
J
Johannes Berg 已提交
997
	u32 flags;
998
};
999

1000
static void iwl_ucode_callback(const struct firmware *ucode_raw, void *context);
1001 1002
static int iwl_mac_setup_register(struct iwl_priv *priv,
				  struct iwlagn_ucode_capabilities *capa);
1003

1004 1005 1006
#define UCODE_EXPERIMENTAL_INDEX	100
#define UCODE_EXPERIMENTAL_TAG		"exp"

1007 1008 1009
static int __must_check iwl_request_firmware(struct iwl_priv *priv, bool first)
{
	const char *name_pre = priv->cfg->fw_name_pre;
1010
	char tag[8];
1011

1012 1013 1014 1015 1016 1017
	if (first) {
#ifdef CONFIG_IWLWIFI_DEBUG_EXPERIMENTAL_UCODE
		priv->fw_index = UCODE_EXPERIMENTAL_INDEX;
		strcpy(tag, UCODE_EXPERIMENTAL_TAG);
	} else if (priv->fw_index == UCODE_EXPERIMENTAL_INDEX) {
#endif
1018
		priv->fw_index = priv->cfg->ucode_api_max;
1019 1020
		sprintf(tag, "%d", priv->fw_index);
	} else {
1021
		priv->fw_index--;
1022 1023
		sprintf(tag, "%d", priv->fw_index);
	}
1024 1025 1026 1027 1028 1029

	if (priv->fw_index < priv->cfg->ucode_api_min) {
		IWL_ERR(priv, "no suitable firmware found!\n");
		return -ENOENT;
	}

1030
	sprintf(priv->firmware_name, "%s%s%s", name_pre, tag, ".ucode");
1031

1032 1033 1034
	IWL_DEBUG_INFO(priv, "attempting to load firmware %s'%s'\n",
		       (priv->fw_index == UCODE_EXPERIMENTAL_INDEX)
				? "EXPERIMENTAL " : "",
1035 1036 1037
		       priv->firmware_name);

	return request_firmware_nowait(THIS_MODULE, 1, priv->firmware_name,
1038 1039
				       priv->bus.dev,
				       GFP_KERNEL, priv, iwl_ucode_callback);
1040 1041
}

1042
struct iwlagn_firmware_pieces {
J
Johannes Berg 已提交
1043 1044
	const void *inst, *data, *init, *init_data;
	size_t inst_size, data_size, init_size, init_data_size;
1045 1046

	u32 build;
1047 1048 1049

	u32 init_evtlog_ptr, init_evtlog_size, init_errlog_ptr;
	u32 inst_evtlog_ptr, inst_evtlog_size, inst_errlog_ptr;
1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064
};

static int iwlagn_load_legacy_firmware(struct iwl_priv *priv,
				       const struct firmware *ucode_raw,
				       struct iwlagn_firmware_pieces *pieces)
{
	struct iwl_ucode_header *ucode = (void *)ucode_raw->data;
	u32 api_ver, hdr_size;
	const u8 *src;

	priv->ucode_ver = le32_to_cpu(ucode->ver);
	api_ver = IWL_UCODE_API(priv->ucode_ver);

	switch (api_ver) {
	default:
1065 1066 1067 1068
		hdr_size = 28;
		if (ucode_raw->size < hdr_size) {
			IWL_ERR(priv, "File size too small!\n");
			return -EINVAL;
1069
		}
1070 1071 1072 1073 1074 1075 1076
		pieces->build = le32_to_cpu(ucode->u.v2.build);
		pieces->inst_size = le32_to_cpu(ucode->u.v2.inst_size);
		pieces->data_size = le32_to_cpu(ucode->u.v2.data_size);
		pieces->init_size = le32_to_cpu(ucode->u.v2.init_size);
		pieces->init_data_size = le32_to_cpu(ucode->u.v2.init_data_size);
		src = ucode->u.v2.data;
		break;
1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096
	case 0:
	case 1:
	case 2:
		hdr_size = 24;
		if (ucode_raw->size < hdr_size) {
			IWL_ERR(priv, "File size too small!\n");
			return -EINVAL;
		}
		pieces->build = 0;
		pieces->inst_size = le32_to_cpu(ucode->u.v1.inst_size);
		pieces->data_size = le32_to_cpu(ucode->u.v1.data_size);
		pieces->init_size = le32_to_cpu(ucode->u.v1.init_size);
		pieces->init_data_size = le32_to_cpu(ucode->u.v1.init_data_size);
		src = ucode->u.v1.data;
		break;
	}

	/* Verify size of file vs. image size info in file's header */
	if (ucode_raw->size != hdr_size + pieces->inst_size +
				pieces->data_size + pieces->init_size +
J
Johannes Berg 已提交
1097
				pieces->init_data_size) {
1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116

		IWL_ERR(priv,
			"uCode file size %d does not match expected size\n",
			(int)ucode_raw->size);
		return -EINVAL;
	}

	pieces->inst = src;
	src += pieces->inst_size;
	pieces->data = src;
	src += pieces->data_size;
	pieces->init = src;
	src += pieces->init_size;
	pieces->init_data = src;
	src += pieces->init_data_size;

	return 0;
}

1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128 1129
static int iwlagn_wanted_ucode_alternative = 1;

static int iwlagn_load_firmware(struct iwl_priv *priv,
				const struct firmware *ucode_raw,
				struct iwlagn_firmware_pieces *pieces,
				struct iwlagn_ucode_capabilities *capa)
{
	struct iwl_tlv_ucode_header *ucode = (void *)ucode_raw->data;
	struct iwl_ucode_tlv *tlv;
	size_t len = ucode_raw->size;
	const u8 *data;
	int wanted_alternative = iwlagn_wanted_ucode_alternative, tmp;
	u64 alternatives;
1130 1131 1132
	u32 tlv_len;
	enum iwl_ucode_tlv_type tlv_type;
	const u8 *tlv_data;
1133

1134 1135
	if (len < sizeof(*ucode)) {
		IWL_ERR(priv, "uCode has invalid length: %zd\n", len);
1136
		return -EINVAL;
1137
	}
1138

1139 1140 1141
	if (ucode->magic != cpu_to_le32(IWL_TLV_UCODE_MAGIC)) {
		IWL_ERR(priv, "invalid uCode magic: 0X%x\n",
			le32_to_cpu(ucode->magic));
1142
		return -EINVAL;
1143
	}
1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167

	/*
	 * Check which alternatives are present, and "downgrade"
	 * when the chosen alternative is not present, warning
	 * the user when that happens. Some files may not have
	 * any alternatives, so don't warn in that case.
	 */
	alternatives = le64_to_cpu(ucode->alternatives);
	tmp = wanted_alternative;
	if (wanted_alternative > 63)
		wanted_alternative = 63;
	while (wanted_alternative && !(alternatives & BIT(wanted_alternative)))
		wanted_alternative--;
	if (wanted_alternative && wanted_alternative != tmp)
		IWL_WARN(priv,
			 "uCode alternative %d not available, choosing %d\n",
			 tmp, wanted_alternative);

	priv->ucode_ver = le32_to_cpu(ucode->ver);
	pieces->build = le32_to_cpu(ucode->build);
	data = ucode->data;

	len -= sizeof(*ucode);

1168
	while (len >= sizeof(*tlv)) {
1169 1170 1171 1172 1173 1174 1175 1176 1177 1178
		u16 tlv_alt;

		len -= sizeof(*tlv);
		tlv = (void *)data;

		tlv_len = le32_to_cpu(tlv->length);
		tlv_type = le16_to_cpu(tlv->type);
		tlv_alt = le16_to_cpu(tlv->alternative);
		tlv_data = tlv->data;

1179 1180 1181
		if (len < tlv_len) {
			IWL_ERR(priv, "invalid TLV len: %zd/%u\n",
				len, tlv_len);
1182
			return -EINVAL;
1183
		}
1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212
		len -= ALIGN(tlv_len, 4);
		data += sizeof(*tlv) + ALIGN(tlv_len, 4);

		/*
		 * Alternative 0 is always valid.
		 *
		 * Skip alternative TLVs that are not selected.
		 */
		if (tlv_alt != 0 && tlv_alt != wanted_alternative)
			continue;

		switch (tlv_type) {
		case IWL_UCODE_TLV_INST:
			pieces->inst = tlv_data;
			pieces->inst_size = tlv_len;
			break;
		case IWL_UCODE_TLV_DATA:
			pieces->data = tlv_data;
			pieces->data_size = tlv_len;
			break;
		case IWL_UCODE_TLV_INIT:
			pieces->init = tlv_data;
			pieces->init_size = tlv_len;
			break;
		case IWL_UCODE_TLV_INIT_DATA:
			pieces->init_data = tlv_data;
			pieces->init_data_size = tlv_len;
			break;
		case IWL_UCODE_TLV_BOOT:
J
Johannes Berg 已提交
1213
			IWL_ERR(priv, "Found unexpected BOOT ucode\n");
1214 1215
			break;
		case IWL_UCODE_TLV_PROBE_MAX_LEN:
1216 1217 1218
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			capa->max_probe_length =
1219
					le32_to_cpup((__le32 *)tlv_data);
1220
			break;
J
Johannes Berg 已提交
1221 1222 1223
		case IWL_UCODE_TLV_PAN:
			if (tlv_len)
				goto invalid_tlv_len;
J
Johannes Berg 已提交
1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240
			capa->flags |= IWL_UCODE_TLV_FLAGS_PAN;
			break;
		case IWL_UCODE_TLV_FLAGS:
			/* must be at least one u32 */
			if (tlv_len < sizeof(u32))
				goto invalid_tlv_len;
			/* and a proper number of u32s */
			if (tlv_len % sizeof(u32))
				goto invalid_tlv_len;
			/*
			 * This driver only reads the first u32 as
			 * right now no more features are defined,
			 * if that changes then either the driver
			 * will not work with the new firmware, or
			 * it'll not take advantage of new features.
			 */
			capa->flags = le32_to_cpup((__le32 *)tlv_data);
J
Johannes Berg 已提交
1241
			break;
1242
		case IWL_UCODE_TLV_INIT_EVTLOG_PTR:
1243 1244 1245
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->init_evtlog_ptr =
1246
					le32_to_cpup((__le32 *)tlv_data);
1247 1248
			break;
		case IWL_UCODE_TLV_INIT_EVTLOG_SIZE:
1249 1250 1251
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->init_evtlog_size =
1252
					le32_to_cpup((__le32 *)tlv_data);
1253 1254
			break;
		case IWL_UCODE_TLV_INIT_ERRLOG_PTR:
1255 1256 1257
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->init_errlog_ptr =
1258
					le32_to_cpup((__le32 *)tlv_data);
1259 1260
			break;
		case IWL_UCODE_TLV_RUNT_EVTLOG_PTR:
1261 1262 1263
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->inst_evtlog_ptr =
1264
					le32_to_cpup((__le32 *)tlv_data);
1265 1266
			break;
		case IWL_UCODE_TLV_RUNT_EVTLOG_SIZE:
1267 1268 1269
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->inst_evtlog_size =
1270
					le32_to_cpup((__le32 *)tlv_data);
1271 1272
			break;
		case IWL_UCODE_TLV_RUNT_ERRLOG_PTR:
1273 1274 1275
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			pieces->inst_errlog_ptr =
1276
					le32_to_cpup((__le32 *)tlv_data);
1277
			break;
1278 1279
		case IWL_UCODE_TLV_ENHANCE_SENS_TBL:
			if (tlv_len)
1280 1281
				goto invalid_tlv_len;
			priv->enhance_sensitivity_table = true;
1282
			break;
1283
		case IWL_UCODE_TLV_PHY_CALIBRATION_SIZE:
1284 1285 1286
			if (tlv_len != sizeof(u32))
				goto invalid_tlv_len;
			capa->standard_phy_calibration_size =
1287 1288
					le32_to_cpup((__le32 *)tlv_data);
			break;
1289
		default:
1290
			IWL_DEBUG_INFO(priv, "unknown TLV: %d\n", tlv_type);
1291 1292 1293 1294
			break;
		}
	}

1295 1296 1297
	if (len) {
		IWL_ERR(priv, "invalid TLV after parsing: %zd\n", len);
		iwl_print_hex_dump(priv, IWL_DL_FW, (u8 *)data, len);
1298
		return -EINVAL;
1299
	}
1300

1301 1302 1303 1304 1305 1306 1307
	return 0;

 invalid_tlv_len:
	IWL_ERR(priv, "TLV %d has invalid size: %u\n", tlv_type, tlv_len);
	iwl_print_hex_dump(priv, IWL_DL_FW, tlv_data, tlv_len);

	return -EINVAL;
1308 1309
}

Z
Zhu Yi 已提交
1310
/**
1311
 * iwl_ucode_callback - callback when firmware was loaded
Z
Zhu Yi 已提交
1312
 *
1313 1314
 * If loaded successfully, copies the firmware into buffers
 * for the card to fetch (via DMA).
Z
Zhu Yi 已提交
1315
 */
1316
static void iwl_ucode_callback(const struct firmware *ucode_raw, void *context)
Z
Zhu Yi 已提交
1317
{
1318
	struct iwl_priv *priv = context;
1319
	struct iwl_ucode_header *ucode;
1320 1321
	int err;
	struct iwlagn_firmware_pieces pieces;
1322 1323
	const unsigned int api_max = priv->cfg->ucode_api_max;
	const unsigned int api_min = priv->cfg->ucode_api_min;
1324
	u32 api_ver;
1325
	char buildstr[25];
1326
	u32 build;
1327 1328
	struct iwlagn_ucode_capabilities ucode_capa = {
		.max_probe_length = 200,
1329
		.standard_phy_calibration_size =
1330
			IWL_DEFAULT_STANDARD_PHY_CALIBRATE_TBL_SIZE,
1331
	};
1332 1333

	memset(&pieces, 0, sizeof(pieces));
Z
Zhu Yi 已提交
1334

1335
	if (!ucode_raw) {
1336 1337 1338 1339
		if (priv->fw_index <= priv->cfg->ucode_api_max)
			IWL_ERR(priv,
				"request for firmware file '%s' failed.\n",
				priv->firmware_name);
1340
		goto try_again;
Z
Zhu Yi 已提交
1341 1342
	}

1343 1344
	IWL_DEBUG_INFO(priv, "Loaded firmware file '%s' (%zd bytes).\n",
		       priv->firmware_name, ucode_raw->size);
Z
Zhu Yi 已提交
1345

1346 1347
	/* Make sure that we got at least the API version number */
	if (ucode_raw->size < 4) {
1348
		IWL_ERR(priv, "File size way too small!\n");
1349
		goto try_again;
Z
Zhu Yi 已提交
1350 1351 1352
	}

	/* Data from ucode file:  header followed by uCode images */
1353
	ucode = (struct iwl_ucode_header *)ucode_raw->data;
Z
Zhu Yi 已提交
1354

1355 1356 1357
	if (ucode->ver)
		err = iwlagn_load_legacy_firmware(priv, ucode_raw, &pieces);
	else
1358 1359
		err = iwlagn_load_firmware(priv, ucode_raw, &pieces,
					   &ucode_capa);
1360

1361 1362
	if (err)
		goto try_again;
Z
Zhu Yi 已提交
1363

1364
	api_ver = IWL_UCODE_API(priv->ucode_ver);
1365
	build = pieces.build;
1366

1367 1368 1369 1370 1371
	/*
	 * api_ver should match the api version forming part of the
	 * firmware filename ... but we don't check for that and only rely
	 * on the API version read from firmware header from here on forward
	 */
1372 1373 1374 1375 1376 1377 1378 1379 1380
	/* no api version check required for experimental uCode */
	if (priv->fw_index != UCODE_EXPERIMENTAL_INDEX) {
		if (api_ver < api_min || api_ver > api_max) {
			IWL_ERR(priv,
				"Driver unable to support your firmware API. "
				"Driver supports v%u, firmware is v%u.\n",
				api_max, api_ver);
			goto try_again;
		}
1381

1382 1383 1384 1385 1386 1387 1388
		if (api_ver != api_max)
			IWL_ERR(priv,
				"Firmware has old API version. Expected v%u, "
				"got v%u. New firmware can be obtained "
				"from http://www.intellinuxwireless.org.\n",
				api_max, api_ver);
	}
1389

1390
	if (build)
1391 1392 1393
		sprintf(buildstr, " build %u%s", build,
		       (priv->fw_index == UCODE_EXPERIMENTAL_INDEX)
				? " (EXP)" : "");
1394 1395 1396 1397 1398 1399 1400 1401 1402
	else
		buildstr[0] = '\0';

	IWL_INFO(priv, "loaded firmware version %u.%u.%u.%u%s\n",
		 IWL_UCODE_MAJOR(priv->ucode_ver),
		 IWL_UCODE_MINOR(priv->ucode_ver),
		 IWL_UCODE_API(priv->ucode_ver),
		 IWL_UCODE_SERIAL(priv->ucode_ver),
		 buildstr);
1403

1404 1405
	snprintf(priv->hw->wiphy->fw_version,
		 sizeof(priv->hw->wiphy->fw_version),
1406
		 "%u.%u.%u.%u%s",
1407 1408 1409
		 IWL_UCODE_MAJOR(priv->ucode_ver),
		 IWL_UCODE_MINOR(priv->ucode_ver),
		 IWL_UCODE_API(priv->ucode_ver),
1410 1411
		 IWL_UCODE_SERIAL(priv->ucode_ver),
		 buildstr);
Z
Zhu Yi 已提交
1412

1413 1414 1415 1416 1417 1418
	/*
	 * For any of the failures below (before allocating pci memory)
	 * we will try to load a version with a smaller API -- maybe the
	 * user just got a corrupted version of the latest API.
	 */

1419 1420 1421 1422 1423 1424 1425 1426 1427 1428
	IWL_DEBUG_INFO(priv, "f/w package hdr ucode version raw = 0x%x\n",
		       priv->ucode_ver);
	IWL_DEBUG_INFO(priv, "f/w package hdr runtime inst size = %Zd\n",
		       pieces.inst_size);
	IWL_DEBUG_INFO(priv, "f/w package hdr runtime data size = %Zd\n",
		       pieces.data_size);
	IWL_DEBUG_INFO(priv, "f/w package hdr init inst size = %Zd\n",
		       pieces.init_size);
	IWL_DEBUG_INFO(priv, "f/w package hdr init data size = %Zd\n",
		       pieces.init_data_size);
Z
Zhu Yi 已提交
1429 1430

	/* Verify that uCode images will fit in card's SRAM */
1431 1432 1433
	if (pieces.inst_size > priv->hw_params.max_inst_size) {
		IWL_ERR(priv, "uCode instr len %Zd too large to fit in\n",
			pieces.inst_size);
1434
		goto try_again;
Z
Zhu Yi 已提交
1435 1436
	}

1437 1438 1439
	if (pieces.data_size > priv->hw_params.max_data_size) {
		IWL_ERR(priv, "uCode data len %Zd too large to fit in\n",
			pieces.data_size);
1440
		goto try_again;
Z
Zhu Yi 已提交
1441
	}
1442 1443 1444 1445

	if (pieces.init_size > priv->hw_params.max_inst_size) {
		IWL_ERR(priv, "uCode init instr len %Zd too large to fit in\n",
			pieces.init_size);
1446
		goto try_again;
Z
Zhu Yi 已提交
1447
	}
1448 1449 1450 1451

	if (pieces.init_data_size > priv->hw_params.max_data_size) {
		IWL_ERR(priv, "uCode init data len %Zd too large to fit in\n",
			pieces.init_data_size);
1452
		goto try_again;
Z
Zhu Yi 已提交
1453
	}
1454

Z
Zhu Yi 已提交
1455 1456 1457 1458 1459
	/* Allocate ucode buffers for card's bus-master loading ... */

	/* Runtime instructions and 2 copies of data:
	 * 1) unmodified from disk
	 * 2) backup cache for save/restore during power-downs */
1460
	if (iwl_alloc_fw_desc(priv, &priv->ucode_rt.code,
1461 1462
			      pieces.inst, pieces.inst_size))
		goto err_pci_alloc;
1463
	if (iwl_alloc_fw_desc(priv, &priv->ucode_rt.data,
1464
			      pieces.data, pieces.data_size))
1465 1466
		goto err_pci_alloc;

Z
Zhu Yi 已提交
1467
	/* Initialization instructions and data */
1468
	if (pieces.init_size && pieces.init_data_size) {
1469
		if (iwl_alloc_fw_desc(priv, &priv->ucode_init.code,
1470 1471
				      pieces.init, pieces.init_size))
			goto err_pci_alloc;
1472
		if (iwl_alloc_fw_desc(priv, &priv->ucode_init.data,
1473
				      pieces.init_data, pieces.init_data_size))
1474 1475
			goto err_pci_alloc;
	}
Z
Zhu Yi 已提交
1476

1477 1478 1479 1480 1481 1482 1483 1484 1485 1486 1487
	/* Now that we can no longer fail, copy information */

	/*
	 * The (size - 16) / 12 formula is based on the information recorded
	 * for each event, which is of mode 1 (including timestamp) for all
	 * new microcodes that include this information.
	 */
	priv->_agn.init_evtlog_ptr = pieces.init_evtlog_ptr;
	if (pieces.init_evtlog_size)
		priv->_agn.init_evtlog_size = (pieces.init_evtlog_size - 16)/12;
	else
1488 1489
		priv->_agn.init_evtlog_size =
			priv->cfg->base_params->max_event_log_size;
1490 1491 1492 1493 1494
	priv->_agn.init_errlog_ptr = pieces.init_errlog_ptr;
	priv->_agn.inst_evtlog_ptr = pieces.inst_evtlog_ptr;
	if (pieces.inst_evtlog_size)
		priv->_agn.inst_evtlog_size = (pieces.inst_evtlog_size - 16)/12;
	else
1495 1496
		priv->_agn.inst_evtlog_size =
			priv->cfg->base_params->max_event_log_size;
1497 1498
	priv->_agn.inst_errlog_ptr = pieces.inst_errlog_ptr;

1499 1500 1501
	priv->new_scan_threshold_behaviour =
		!!(ucode_capa.flags & IWL_UCODE_TLV_FLAGS_NEWSCAN);

1502 1503
	if ((priv->cfg->sku & EEPROM_SKU_CAP_IPAN_ENABLE) &&
	    (ucode_capa.flags & IWL_UCODE_TLV_FLAGS_PAN)) {
J
Johannes Berg 已提交
1504
		priv->valid_contexts |= BIT(IWL_RXON_CTX_PAN);
1505
		priv->sta_key_max_num = STA_KEY_MAX_NUM_PAN;
J
Johannes Berg 已提交
1506 1507
	} else
		priv->sta_key_max_num = STA_KEY_MAX_NUM;
1508

J
Johannes Berg 已提交
1509 1510 1511 1512 1513
	if (priv->valid_contexts != BIT(IWL_RXON_CTX_BSS))
		priv->cmd_queue = IWL_IPAN_CMD_QUEUE_NUM;
	else
		priv->cmd_queue = IWL_DEFAULT_CMD_QUEUE_NUM;

1514 1515 1516 1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527
	/*
	 * figure out the offset of chain noise reset and gain commands
	 * base on the size of standard phy calibration commands table size
	 */
	if (ucode_capa.standard_phy_calibration_size >
	    IWL_MAX_PHY_CALIBRATE_TBL_SIZE)
		ucode_capa.standard_phy_calibration_size =
			IWL_MAX_STANDARD_PHY_CALIBRATE_TBL_SIZE;

	priv->_agn.phy_calib_chain_noise_reset_cmd =
		ucode_capa.standard_phy_calibration_size;
	priv->_agn.phy_calib_chain_noise_gain_cmd =
		ucode_capa.standard_phy_calibration_size + 1;

1528 1529 1530 1531 1532
	/**************************************************
	 * This is still part of probe() in a sense...
	 *
	 * 9. Setup and register with mac80211 and debugfs
	 **************************************************/
1533
	err = iwl_mac_setup_register(priv, &ucode_capa);
1534 1535 1536 1537 1538 1539 1540
	if (err)
		goto out_unbind;

	err = iwl_dbgfs_register(priv, DRV_NAME);
	if (err)
		IWL_ERR(priv, "failed to create debugfs files. Ignoring error: %d\n", err);

1541
	err = sysfs_create_group(&(priv->bus.dev->kobj),
1542 1543 1544 1545 1546 1547
					&iwl_attribute_group);
	if (err) {
		IWL_ERR(priv, "failed to create sysfs device attributes\n");
		goto out_unbind;
	}

Z
Zhu Yi 已提交
1548 1549
	/* We have our copies now, allow OS release its copies */
	release_firmware(ucode_raw);
1550
	complete(&priv->_agn.firmware_loading_complete);
1551 1552 1553 1554 1555 1556 1557 1558
	return;

 try_again:
	/* try next, if any */
	if (iwl_request_firmware(priv, false))
		goto out_unbind;
	release_firmware(ucode_raw);
	return;
Z
Zhu Yi 已提交
1559 1560

 err_pci_alloc:
1561
	IWL_ERR(priv, "failed to allocate pci memory\n");
1562
	iwl_dealloc_ucode(priv);
1563
 out_unbind:
1564
	complete(&priv->_agn.firmware_loading_complete);
1565
	device_release_driver(priv->bus.dev);
Z
Zhu Yi 已提交
1566 1567 1568
	release_firmware(ucode_raw);
}

1569 1570 1571 1572 1573 1574 1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599
static const char *desc_lookup_text[] = {
	"OK",
	"FAIL",
	"BAD_PARAM",
	"BAD_CHECKSUM",
	"NMI_INTERRUPT_WDG",
	"SYSASSERT",
	"FATAL_ERROR",
	"BAD_COMMAND",
	"HW_ERROR_TUNE_LOCK",
	"HW_ERROR_TEMPERATURE",
	"ILLEGAL_CHAN_FREQ",
	"VCC_NOT_STABLE",
	"FH_ERROR",
	"NMI_INTERRUPT_HOST",
	"NMI_INTERRUPT_ACTION_PT",
	"NMI_INTERRUPT_UNKNOWN",
	"UCODE_VERSION_MISMATCH",
	"HW_ERROR_ABS_LOCK",
	"HW_ERROR_CAL_LOCK_FAIL",
	"NMI_INTERRUPT_INST_ACTION_PT",
	"NMI_INTERRUPT_DATA_ACTION_PT",
	"NMI_TRM_HW_ER",
	"NMI_INTERRUPT_TRM",
	"NMI_INTERRUPT_BREAK_POINT"
	"DEBUG_0",
	"DEBUG_1",
	"DEBUG_2",
	"DEBUG_3",
};

1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619
static struct { char *name; u8 num; } advanced_lookup[] = {
	{ "NMI_INTERRUPT_WDG", 0x34 },
	{ "SYSASSERT", 0x35 },
	{ "UCODE_VERSION_MISMATCH", 0x37 },
	{ "BAD_COMMAND", 0x38 },
	{ "NMI_INTERRUPT_DATA_ACTION_PT", 0x3C },
	{ "FATAL_ERROR", 0x3D },
	{ "NMI_TRM_HW_ERR", 0x46 },
	{ "NMI_INTERRUPT_TRM", 0x4C },
	{ "NMI_INTERRUPT_BREAK_POINT", 0x54 },
	{ "NMI_INTERRUPT_WDG_RXF_FULL", 0x5C },
	{ "NMI_INTERRUPT_WDG_NO_RBD_RXF_FULL", 0x64 },
	{ "NMI_INTERRUPT_HOST", 0x66 },
	{ "NMI_INTERRUPT_ACTION_PT", 0x7C },
	{ "NMI_INTERRUPT_UNKNOWN", 0x84 },
	{ "NMI_INTERRUPT_INST_ACTION_PT", 0x86 },
	{ "ADVANCED_SYSASSERT", 0 },
};

static const char *desc_lookup(u32 num)
1620
{
1621 1622
	int i;
	int max = ARRAY_SIZE(desc_lookup_text);
1623

1624 1625
	if (num < max)
		return desc_lookup_text[num];
1626

1627 1628 1629
	max = ARRAY_SIZE(advanced_lookup) - 1;
	for (i = 0; i < max; i++) {
		if (advanced_lookup[i].num == num)
1630
			break;
1631 1632
	}
	return advanced_lookup[i].name;
1633 1634 1635 1636 1637 1638 1639
}

#define ERROR_START_OFFSET  (1 * sizeof(u32))
#define ERROR_ELEM_SIZE     (7 * sizeof(u32))

void iwl_dump_nic_error_log(struct iwl_priv *priv)
{
W
Wey-Yi Guy 已提交
1640
	u32 base;
1641
	struct iwl_error_event_table table;
1642

J
Johannes Berg 已提交
1643
	base = priv->device_pointers.error_event_table;
1644
	if (priv->ucode_type == IWL_UCODE_INIT) {
1645 1646 1647 1648 1649 1650
		if (!base)
			base = priv->_agn.init_errlog_ptr;
	} else {
		if (!base)
			base = priv->_agn.inst_errlog_ptr;
	}
1651 1652

	if (!priv->cfg->ops->lib->is_valid_rtc_data_addr(base)) {
1653 1654
		IWL_ERR(priv,
			"Not valid error log pointer 0x%08X for %s uCode\n",
1655
			base,
1656
			(priv->ucode_type == IWL_UCODE_INIT)
1657
					? "Init" : "RT");
1658 1659 1660
		return;
	}

1661 1662
	iwl_read_targ_mem_words(priv, base, &table, sizeof(table));

W
Wey-Yi Guy 已提交
1663
	if (ERROR_START_OFFSET <= table.valid * ERROR_ELEM_SIZE) {
1664 1665
		IWL_ERR(priv, "Start IWL Error Log Dump:\n");
		IWL_ERR(priv, "Status: 0x%08lX, count: %d\n",
W
Wey-Yi Guy 已提交
1666
			priv->status, table.valid);
1667 1668
	}

W
Wey-Yi Guy 已提交
1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696
	priv->isr_stats.err_code = table.error_id;

	trace_iwlwifi_dev_ucode_error(priv, table.error_id, table.tsf_low,
				      table.data1, table.data2, table.line,
				      table.blink1, table.blink2, table.ilink1,
				      table.ilink2, table.bcon_time, table.gp1,
				      table.gp2, table.gp3, table.ucode_ver,
				      table.hw_ver, table.brd_ver);
	IWL_ERR(priv, "0x%08X | %-28s\n", table.error_id,
		desc_lookup(table.error_id));
	IWL_ERR(priv, "0x%08X | uPc\n", table.pc);
	IWL_ERR(priv, "0x%08X | branchlink1\n", table.blink1);
	IWL_ERR(priv, "0x%08X | branchlink2\n", table.blink2);
	IWL_ERR(priv, "0x%08X | interruptlink1\n", table.ilink1);
	IWL_ERR(priv, "0x%08X | interruptlink2\n", table.ilink2);
	IWL_ERR(priv, "0x%08X | data1\n", table.data1);
	IWL_ERR(priv, "0x%08X | data2\n", table.data2);
	IWL_ERR(priv, "0x%08X | line\n", table.line);
	IWL_ERR(priv, "0x%08X | beacon time\n", table.bcon_time);
	IWL_ERR(priv, "0x%08X | tsf low\n", table.tsf_low);
	IWL_ERR(priv, "0x%08X | tsf hi\n", table.tsf_hi);
	IWL_ERR(priv, "0x%08X | time gp1\n", table.gp1);
	IWL_ERR(priv, "0x%08X | time gp2\n", table.gp2);
	IWL_ERR(priv, "0x%08X | time gp3\n", table.gp3);
	IWL_ERR(priv, "0x%08X | uCode version\n", table.ucode_ver);
	IWL_ERR(priv, "0x%08X | hw version\n", table.hw_ver);
	IWL_ERR(priv, "0x%08X | board version\n", table.brd_ver);
	IWL_ERR(priv, "0x%08X | hcmd\n", table.hcmd);
1697 1698 1699 1700 1701 1702 1703 1704
}

#define EVENT_START_OFFSET  (4 * sizeof(u32))

/**
 * iwl_print_event_log - Dump error event log to syslog
 *
 */
W
Wey-Yi Guy 已提交
1705 1706 1707
static int iwl_print_event_log(struct iwl_priv *priv, u32 start_idx,
			       u32 num_events, u32 mode,
			       int pos, char **buf, size_t bufsz)
1708 1709 1710 1711 1712 1713
{
	u32 i;
	u32 base;       /* SRAM byte address of event log header */
	u32 event_size; /* 2 u32s, or 3 u32s if timestamp recorded */
	u32 ptr;        /* SRAM byte address of log data */
	u32 ev, time, data; /* event log data */
B
Ben Cahill 已提交
1714
	unsigned long reg_flags;
1715 1716

	if (num_events == 0)
W
Wey-Yi Guy 已提交
1717
		return pos;
1718

J
Johannes Berg 已提交
1719
	base = priv->device_pointers.log_event_table;
1720
	if (priv->ucode_type == IWL_UCODE_INIT) {
1721 1722 1723 1724 1725 1726
		if (!base)
			base = priv->_agn.init_evtlog_ptr;
	} else {
		if (!base)
			base = priv->_agn.inst_evtlog_ptr;
	}
1727 1728 1729 1730 1731 1732 1733 1734

	if (mode == 0)
		event_size = 2 * sizeof(u32);
	else
		event_size = 3 * sizeof(u32);

	ptr = base + EVENT_START_OFFSET + (start_idx * event_size);

B
Ben Cahill 已提交
1735 1736 1737 1738 1739
	/* Make sure device is powered up for SRAM reads */
	spin_lock_irqsave(&priv->reg_lock, reg_flags);
	iwl_grab_nic_access(priv);

	/* Set starting address; reads will auto-increment */
1740
	iwl_write32(priv, HBUS_TARG_MEM_RADDR, ptr);
B
Ben Cahill 已提交
1741 1742
	rmb();

1743 1744 1745
	/* "time" is actually "data" for mode 0 (no timestamp).
	* place event id # at far right for easier visual parsing. */
	for (i = 0; i < num_events; i++) {
1746 1747
		ev = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
		time = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
1748 1749
		if (mode == 0) {
			/* data, ev */
W
Wey-Yi Guy 已提交
1750 1751 1752 1753 1754 1755 1756 1757 1758 1759
			if (bufsz) {
				pos += scnprintf(*buf + pos, bufsz - pos,
						"EVT_LOG:0x%08x:%04u\n",
						time, ev);
			} else {
				trace_iwlwifi_dev_ucode_event(priv, 0,
					time, ev);
				IWL_ERR(priv, "EVT_LOG:0x%08x:%04u\n",
					time, ev);
			}
1760
		} else {
1761
			data = iwl_read32(priv, HBUS_TARG_MEM_RDAT);
W
Wey-Yi Guy 已提交
1762 1763 1764 1765 1766 1767
			if (bufsz) {
				pos += scnprintf(*buf + pos, bufsz - pos,
						"EVT_LOGT:%010u:0x%08x:%04u\n",
						 time, data, ev);
			} else {
				IWL_ERR(priv, "EVT_LOGT:%010u:0x%08x:%04u\n",
1768
					time, data, ev);
W
Wey-Yi Guy 已提交
1769 1770 1771
				trace_iwlwifi_dev_ucode_event(priv, time,
					data, ev);
			}
1772 1773
		}
	}
B
Ben Cahill 已提交
1774 1775 1776 1777

	/* Allow device to power down */
	iwl_release_nic_access(priv);
	spin_unlock_irqrestore(&priv->reg_lock, reg_flags);
W
Wey-Yi Guy 已提交
1778
	return pos;
1779 1780
}

1781 1782 1783
/**
 * iwl_print_last_event_logs - Dump the newest # of event log to syslog
 */
W
Wey-Yi Guy 已提交
1784 1785 1786 1787
static int iwl_print_last_event_logs(struct iwl_priv *priv, u32 capacity,
				    u32 num_wraps, u32 next_entry,
				    u32 size, u32 mode,
				    int pos, char **buf, size_t bufsz)
1788 1789 1790 1791 1792 1793 1794
{
	/*
	 * display the newest DEFAULT_LOG_ENTRIES entries
	 * i.e the entries just before the next ont that uCode would fill.
	 */
	if (num_wraps) {
		if (next_entry < size) {
W
Wey-Yi Guy 已提交
1795 1796 1797 1798 1799 1800 1801
			pos = iwl_print_event_log(priv,
						capacity - (size - next_entry),
						size - next_entry, mode,
						pos, buf, bufsz);
			pos = iwl_print_event_log(priv, 0,
						  next_entry, mode,
						  pos, buf, bufsz);
1802
		} else
W
Wey-Yi Guy 已提交
1803 1804
			pos = iwl_print_event_log(priv, next_entry - size,
						  size, mode, pos, buf, bufsz);
1805
	} else {
W
Wey-Yi Guy 已提交
1806 1807 1808 1809 1810 1811 1812
		if (next_entry < size) {
			pos = iwl_print_event_log(priv, 0, next_entry,
						  mode, pos, buf, bufsz);
		} else {
			pos = iwl_print_event_log(priv, next_entry - size,
						  size, mode, pos, buf, bufsz);
		}
1813
	}
W
Wey-Yi Guy 已提交
1814
	return pos;
1815 1816 1817 1818
}

#define DEFAULT_DUMP_EVENT_LOG_ENTRIES (20)

W
Wey-Yi Guy 已提交
1819 1820
int iwl_dump_nic_event_log(struct iwl_priv *priv, bool full_log,
			    char **buf, bool display)
1821 1822 1823 1824 1825 1826 1827
{
	u32 base;       /* SRAM byte address of event log header */
	u32 capacity;   /* event log capacity in # entries */
	u32 mode;       /* 0 - no timestamp, 1 - timestamp recorded */
	u32 num_wraps;  /* # times uCode wrapped to top of log */
	u32 next_entry; /* index of next entry to be written by uCode */
	u32 size;       /* # entries that we'll print */
1828
	u32 logsize;
W
Wey-Yi Guy 已提交
1829 1830
	int pos = 0;
	size_t bufsz = 0;
1831

J
Johannes Berg 已提交
1832
	base = priv->device_pointers.log_event_table;
1833
	if (priv->ucode_type == IWL_UCODE_INIT) {
1834 1835 1836 1837 1838 1839 1840 1841
		logsize = priv->_agn.init_evtlog_size;
		if (!base)
			base = priv->_agn.init_evtlog_ptr;
	} else {
		logsize = priv->_agn.inst_evtlog_size;
		if (!base)
			base = priv->_agn.inst_evtlog_ptr;
	}
1842 1843

	if (!priv->cfg->ops->lib->is_valid_rtc_data_addr(base)) {
1844 1845
		IWL_ERR(priv,
			"Invalid event log pointer 0x%08X for %s uCode\n",
1846
			base,
1847
			(priv->ucode_type == IWL_UCODE_INIT)
1848
					? "Init" : "RT");
1849
		return -EINVAL;
1850 1851 1852 1853 1854 1855 1856 1857
	}

	/* event log header */
	capacity = iwl_read_targ_mem(priv, base);
	mode = iwl_read_targ_mem(priv, base + (1 * sizeof(u32)));
	num_wraps = iwl_read_targ_mem(priv, base + (2 * sizeof(u32)));
	next_entry = iwl_read_targ_mem(priv, base + (3 * sizeof(u32)));

1858
	if (capacity > logsize) {
B
Ben Cahill 已提交
1859
		IWL_ERR(priv, "Log capacity %d is bogus, limit to %d entries\n",
1860 1861
			capacity, logsize);
		capacity = logsize;
B
Ben Cahill 已提交
1862 1863
	}

1864
	if (next_entry > logsize) {
B
Ben Cahill 已提交
1865
		IWL_ERR(priv, "Log write index %d is bogus, limit to %d\n",
1866 1867
			next_entry, logsize);
		next_entry = logsize;
B
Ben Cahill 已提交
1868 1869
	}

1870 1871 1872 1873 1874
	size = num_wraps ? capacity : next_entry;

	/* bail out if nothing in log */
	if (size == 0) {
		IWL_ERR(priv, "Start IWL Event Log Dump: nothing in log\n");
W
Wey-Yi Guy 已提交
1875
		return pos;
1876 1877
	}

1878
	/* enable/disable bt channel inhibition */
1879 1880
	priv->bt_ch_announce = iwlagn_bt_ch_announce;

1881
#ifdef CONFIG_IWLWIFI_DEBUG
1882
	if (!(iwl_get_debug_level(priv) & IWL_DL_FW_ERRORS) && !full_log)
1883 1884 1885 1886 1887 1888 1889 1890
		size = (size > DEFAULT_DUMP_EVENT_LOG_ENTRIES)
			? DEFAULT_DUMP_EVENT_LOG_ENTRIES : size;
#else
	size = (size > DEFAULT_DUMP_EVENT_LOG_ENTRIES)
		? DEFAULT_DUMP_EVENT_LOG_ENTRIES : size;
#endif
	IWL_ERR(priv, "Start IWL Event Log Dump: display last %u entries\n",
		size);
1891

1892
#ifdef CONFIG_IWLWIFI_DEBUG
W
Wey-Yi Guy 已提交
1893 1894 1895 1896 1897 1898 1899
	if (display) {
		if (full_log)
			bufsz = capacity * 48;
		else
			bufsz = size * 48;
		*buf = kmalloc(bufsz, GFP_KERNEL);
		if (!*buf)
1900
			return -ENOMEM;
W
Wey-Yi Guy 已提交
1901
	}
1902 1903 1904 1905 1906 1907 1908
	if ((iwl_get_debug_level(priv) & IWL_DL_FW_ERRORS) || full_log) {
		/*
		 * if uCode has wrapped back to top of log,
		 * start at the oldest entry,
		 * i.e the next one that uCode would fill.
		 */
		if (num_wraps)
W
Wey-Yi Guy 已提交
1909 1910 1911
			pos = iwl_print_event_log(priv, next_entry,
						capacity - next_entry, mode,
						pos, buf, bufsz);
1912
		/* (then/else) start at top of log */
W
Wey-Yi Guy 已提交
1913 1914
		pos = iwl_print_event_log(priv, 0,
					  next_entry, mode, pos, buf, bufsz);
1915
	} else
W
Wey-Yi Guy 已提交
1916 1917 1918
		pos = iwl_print_last_event_logs(priv, capacity, num_wraps,
						next_entry, size, mode,
						pos, buf, bufsz);
1919
#else
W
Wey-Yi Guy 已提交
1920 1921 1922
	pos = iwl_print_last_event_logs(priv, capacity, num_wraps,
					next_entry, size, mode,
					pos, buf, bufsz);
1923
#endif
W
Wey-Yi Guy 已提交
1924
	return pos;
1925
}
1926

1927 1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939
static void iwl_rf_kill_ct_config(struct iwl_priv *priv)
{
	struct iwl_ct_kill_config cmd;
	struct iwl_ct_kill_throttling_config adv_cmd;
	unsigned long flags;
	int ret = 0;

	spin_lock_irqsave(&priv->lock, flags);
	iwl_write32(priv, CSR_UCODE_DRV_GP1_CLR,
		    CSR_UCODE_DRV_GP1_REG_BIT_CT_KILL_EXIT);
	spin_unlock_irqrestore(&priv->lock, flags);
	priv->thermal_throttle.ct_kill_toggle = false;

1940
	if (priv->cfg->base_params->support_ct_kill_exit) {
1941 1942 1943 1944 1945 1946 1947 1948 1949 1950 1951 1952 1953 1954 1955 1956 1957 1958 1959 1960 1961 1962 1963 1964 1965 1966 1967 1968 1969 1970 1971 1972
		adv_cmd.critical_temperature_enter =
			cpu_to_le32(priv->hw_params.ct_kill_threshold);
		adv_cmd.critical_temperature_exit =
			cpu_to_le32(priv->hw_params.ct_kill_exit_threshold);

		ret = iwl_send_cmd_pdu(priv, REPLY_CT_KILL_CONFIG_CMD,
				       sizeof(adv_cmd), &adv_cmd);
		if (ret)
			IWL_ERR(priv, "REPLY_CT_KILL_CONFIG_CMD failed\n");
		else
			IWL_DEBUG_INFO(priv, "REPLY_CT_KILL_CONFIG_CMD "
					"succeeded, "
					"critical temperature enter is %d,"
					"exit is %d\n",
				       priv->hw_params.ct_kill_threshold,
				       priv->hw_params.ct_kill_exit_threshold);
	} else {
		cmd.critical_temperature_R =
			cpu_to_le32(priv->hw_params.ct_kill_threshold);

		ret = iwl_send_cmd_pdu(priv, REPLY_CT_KILL_CONFIG_CMD,
				       sizeof(cmd), &cmd);
		if (ret)
			IWL_ERR(priv, "REPLY_CT_KILL_CONFIG_CMD failed\n");
		else
			IWL_DEBUG_INFO(priv, "REPLY_CT_KILL_CONFIG_CMD "
					"succeeded, "
					"critical temperature is %d\n",
					priv->hw_params.ct_kill_threshold);
	}
}

1973 1974 1975 1976 1977
static int iwlagn_send_calib_cfg_rt(struct iwl_priv *priv, u32 cfg)
{
	struct iwl_calib_cfg_cmd calib_cfg_cmd;
	struct iwl_host_cmd cmd = {
		.id = CALIBRATION_CFG_CMD,
1978 1979
		.len = { sizeof(struct iwl_calib_cfg_cmd), },
		.data = { &calib_cfg_cmd, },
1980 1981 1982 1983
	};

	memset(&calib_cfg_cmd, 0, sizeof(calib_cfg_cmd));
	calib_cfg_cmd.ucd_calib_cfg.once.is_enable = IWL_CALIB_INIT_CFG_ALL;
1984
	calib_cfg_cmd.ucd_calib_cfg.once.start = cpu_to_le32(cfg);
1985 1986 1987 1988 1989

	return iwl_send_cmd(priv, &cmd);
}


Z
Zhu Yi 已提交
1990
/**
1991
 * iwl_alive_start - called after REPLY_ALIVE notification received
Z
Zhu Yi 已提交
1992
 *                   from protocol/runtime uCode (initialization uCode's
1993
 *                   Alive gets handled by iwl_init_alive_start()).
Z
Zhu Yi 已提交
1994
 */
1995
int iwl_alive_start(struct iwl_priv *priv)
Z
Zhu Yi 已提交
1996
{
1997
	int ret = 0;
1998
	struct iwl_rxon_context *ctx = &priv->contexts[IWL_RXON_CTX_BSS];
Z
Zhu Yi 已提交
1999

2000
	iwl_reset_ict(priv);
Z
Zhu Yi 已提交
2001

2002
	IWL_DEBUG_INFO(priv, "Runtime Alive received.\n");
2003

2004
	/* After the ALIVE response, we can send host commands to the uCode */
Z
Zhu Yi 已提交
2005 2006
	set_bit(STATUS_ALIVE, &priv->status);

2007 2008
	/* Enable watchdog to monitor the driver tx queues */
	iwl_setup_watchdog(priv);
2009

2010
	if (iwl_is_rfkill(priv))
2011
		return -ERFKILL;
Z
Zhu Yi 已提交
2012

2013
	/* download priority table before any calibration request */
2014 2015
	if (priv->cfg->bt_params &&
	    priv->cfg->bt_params->advanced_bt_coexist) {
2016 2017 2018 2019 2020 2021
		/* Configure Bluetooth device coexistence support */
		priv->bt_valid = IWLAGN_BT_ALL_VALID_MSK;
		priv->kill_ack_mask = IWLAGN_BT_KILL_ACK_MASK_DEFAULT;
		priv->kill_cts_mask = IWLAGN_BT_KILL_CTS_MASK_DEFAULT;
		priv->cfg->ops->hcmd->send_bt_config(priv);
		priv->bt_valid = IWLAGN_BT_VALID_ENABLE_FLAGS;
2022
		iwlagn_send_prio_tbl(priv);
2023 2024

		/* FIXME: w/a to force change uCode BT state machine */
2025 2026 2027 2028 2029 2030 2031 2032
		ret = iwlagn_send_bt_env(priv, IWL_BT_COEX_ENV_OPEN,
					 BT_COEX_PRIO_TBL_EVT_INIT_CALIB2);
		if (ret)
			return ret;
		ret = iwlagn_send_bt_env(priv, IWL_BT_COEX_ENV_CLOSE,
					 BT_COEX_PRIO_TBL_EVT_INIT_CALIB2);
		if (ret)
			return ret;
2033
	}
2034 2035 2036
	if (priv->hw_params.calib_rt_cfg)
		iwlagn_send_calib_cfg_rt(priv, priv->hw_params.calib_rt_cfg);

2037
	ieee80211_wake_queues(priv->hw);
Z
Zhu Yi 已提交
2038

2039
	priv->active_rate = IWL_RATES_MASK;
Z
Zhu Yi 已提交
2040

2041 2042 2043 2044
	/* Configure Tx antenna selection based on H/W config */
	if (priv->cfg->ops->hcmd->set_tx_ant)
		priv->cfg->ops->hcmd->set_tx_ant(priv, priv->cfg->valid_tx_ant);

2045
	if (iwl_is_associated_ctx(ctx)) {
G
Gregory Greenman 已提交
2046
		struct iwl_rxon_cmd *active_rxon =
2047
				(struct iwl_rxon_cmd *)&ctx->active;
2048
		/* apply any changes in staging */
2049
		ctx->staging.filter_flags |= RXON_FILTER_ASSOC_MSK;
Z
Zhu Yi 已提交
2050 2051
		active_rxon->filter_flags &= ~RXON_FILTER_ASSOC_MSK;
	} else {
2052
		struct iwl_rxon_context *tmp;
Z
Zhu Yi 已提交
2053
		/* Initialize our rx_config data */
2054 2055
		for_each_context(priv, tmp)
			iwl_connection_init_rx_config(priv, tmp);
2056 2057

		if (priv->cfg->ops->hcmd->set_rxon_chain)
2058
			priv->cfg->ops->hcmd->set_rxon_chain(priv, ctx);
Z
Zhu Yi 已提交
2059 2060
	}

2061 2062 2063 2064 2065
	if (!priv->cfg->bt_params || (priv->cfg->bt_params &&
	    !priv->cfg->bt_params->advanced_bt_coexist)) {
		/*
		 * default is 2-wire BT coexexistence support
		 */
2066 2067
		priv->cfg->ops->hcmd->send_bt_config(priv);
	}
Z
Zhu Yi 已提交
2068

2069 2070
	iwl_reset_run_time_calib(priv);

2071 2072
	set_bit(STATUS_READY, &priv->status);

Z
Zhu Yi 已提交
2073
	/* Configure the adapter for unassociated operation */
2074
	ret = iwlagn_commit_rxon(priv, ctx);
2075 2076
	if (ret)
		return ret;
Z
Zhu Yi 已提交
2077 2078

	/* At this point, the NIC is initialized and operational */
2079
	iwl_rf_kill_ct_config(priv);
2080

2081
	IWL_DEBUG_INFO(priv, "ALIVE processing complete.\n");
2082

2083
	return iwl_power_update_mode(priv, true);
Z
Zhu Yi 已提交
2084 2085
}

2086
static void iwl_cancel_deferred_work(struct iwl_priv *priv);
Z
Zhu Yi 已提交
2087

2088
static void __iwl_down(struct iwl_priv *priv)
Z
Zhu Yi 已提交
2089
{
2090
	int exit_pending;
Z
Zhu Yi 已提交
2091

2092
	IWL_DEBUG_INFO(priv, DRV_NAME " is going down\n");
Z
Zhu Yi 已提交
2093

2094 2095 2096
	iwl_scan_cancel_timeout(priv, 200);

	exit_pending = test_and_set_bit(STATUS_EXIT_PENDING, &priv->status);
Z
Zhu Yi 已提交
2097

2098 2099
	/* Stop TX queues watchdog. We need to have STATUS_EXIT_PENDING bit set
	 * to prevent rearm timer */
2100
	del_timer_sync(&priv->watchdog);
2101

2102
	iwl_clear_ucode_stations(priv, NULL);
2103
	iwl_dealloc_bcast_stations(priv);
2104
	iwl_clear_driver_stations(priv);
Z
Zhu Yi 已提交
2105

2106
	/* reset BT coex data */
2107
	priv->bt_status = 0;
2108 2109 2110 2111 2112
	if (priv->cfg->bt_params)
		priv->bt_traffic_load =
			 priv->cfg->bt_params->bt_init_traffic_load;
	else
		priv->bt_traffic_load = 0;
2113 2114
	priv->bt_full_concurrent = false;
	priv->bt_ci_compliance = 0;
2115

Z
Zhu Yi 已提交
2116 2117 2118 2119 2120 2121 2122 2123
	/* Wipe out the EXIT_PENDING status bit if we are not actually
	 * exiting the module */
	if (!exit_pending)
		clear_bit(STATUS_EXIT_PENDING, &priv->status);

	if (priv->mac80211_registered)
		ieee80211_stop_queues(priv->hw);

J
Johannes Berg 已提交
2124
	/* Clear out all status bits but a few that are stable across reset */
Z
Zhu Yi 已提交
2125 2126
	priv->status &= test_bit(STATUS_RF_KILL_HW, &priv->status) <<
				STATUS_RF_KILL_HW |
2127 2128
			test_bit(STATUS_GEO_CONFIGURED, &priv->status) <<
				STATUS_GEO_CONFIGURED |
Z
Zhu Yi 已提交
2129
			test_bit(STATUS_FW_ERROR, &priv->status) <<
2130 2131 2132
				STATUS_FW_ERROR |
		       test_bit(STATUS_EXIT_PENDING, &priv->status) <<
				STATUS_EXIT_PENDING;
Z
Zhu Yi 已提交
2133

J
Johannes Berg 已提交
2134
	iwlagn_stop_device(priv);
2135

2136
	dev_kfree_skb(priv->beacon_skb);
2137
	priv->beacon_skb = NULL;
Z
Zhu Yi 已提交
2138 2139
}

2140
static void iwl_down(struct iwl_priv *priv)
Z
Zhu Yi 已提交
2141 2142
{
	mutex_lock(&priv->mutex);
2143
	__iwl_down(priv);
Z
Zhu Yi 已提交
2144
	mutex_unlock(&priv->mutex);
2145

2146
	iwl_cancel_deferred_work(priv);
Z
Zhu Yi 已提交
2147 2148
}

M
Mohamed Abbas 已提交
2149 2150
#define HW_READY_TIMEOUT (50)

J
Johannes Berg 已提交
2151
/* Note: returns poll_bit return value, which is >= 0 if success */
M
Mohamed Abbas 已提交
2152 2153
static int iwl_set_hw_ready(struct iwl_priv *priv)
{
J
Johannes Berg 已提交
2154
	int ret;
M
Mohamed Abbas 已提交
2155 2156 2157 2158 2159 2160 2161 2162 2163 2164

	iwl_set_bit(priv, CSR_HW_IF_CONFIG_REG,
		CSR_HW_IF_CONFIG_REG_BIT_NIC_READY);

	/* See if we got it */
	ret = iwl_poll_bit(priv, CSR_HW_IF_CONFIG_REG,
				CSR_HW_IF_CONFIG_REG_BIT_NIC_READY,
				CSR_HW_IF_CONFIG_REG_BIT_NIC_READY,
				HW_READY_TIMEOUT);

J
Johannes Berg 已提交
2165
	IWL_DEBUG_INFO(priv, "hardware%s ready\n", ret < 0 ? " not" : "");
M
Mohamed Abbas 已提交
2166 2167 2168
	return ret;
}

J
Johannes Berg 已提交
2169
/* Note: returns standard 0/-ERROR code */
J
Johannes Berg 已提交
2170
int iwl_prepare_card_hw(struct iwl_priv *priv)
M
Mohamed Abbas 已提交
2171
{
J
Johannes Berg 已提交
2172
	int ret;
M
Mohamed Abbas 已提交
2173

2174
	IWL_DEBUG_INFO(priv, "iwl_prepare_card_hw enter\n");
M
Mohamed Abbas 已提交
2175

2176
	ret = iwl_set_hw_ready(priv);
J
Johannes Berg 已提交
2177 2178
	if (ret >= 0)
		return 0;
2179 2180

	/* If HW is not ready, prepare the conditions to check again */
M
Mohamed Abbas 已提交
2181 2182 2183 2184 2185 2186 2187
	iwl_set_bit(priv, CSR_HW_IF_CONFIG_REG,
			CSR_HW_IF_CONFIG_REG_PREPARE);

	ret = iwl_poll_bit(priv, CSR_HW_IF_CONFIG_REG,
			~CSR_HW_IF_CONFIG_REG_BIT_NIC_PREPARE_DONE,
			CSR_HW_IF_CONFIG_REG_BIT_NIC_PREPARE_DONE, 150000);

J
Johannes Berg 已提交
2188 2189
	if (ret < 0)
		return ret;
M
Mohamed Abbas 已提交
2190

J
Johannes Berg 已提交
2191 2192 2193 2194
	/* HW should be ready by now, check again. */
	ret = iwl_set_hw_ready(priv);
	if (ret >= 0)
		return 0;
M
Mohamed Abbas 已提交
2195 2196 2197
	return ret;
}

Z
Zhu Yi 已提交
2198 2199
#define MAX_HW_RESTARTS 5

2200
static int __iwl_up(struct iwl_priv *priv)
Z
Zhu Yi 已提交
2201
{
2202
	struct iwl_rxon_context *ctx;
2203
	int ret;
Z
Zhu Yi 已提交
2204

2205 2206
	lockdep_assert_held(&priv->mutex);

Z
Zhu Yi 已提交
2207
	if (test_bit(STATUS_EXIT_PENDING, &priv->status)) {
2208
		IWL_WARN(priv, "Exit pending; will not bring the NIC up\n");
Z
Zhu Yi 已提交
2209 2210 2211
		return -EIO;
	}

2212
	for_each_context(priv, ctx) {
2213
		ret = iwlagn_alloc_bcast_station(priv, ctx);
2214 2215 2216 2217 2218
		if (ret) {
			iwl_dealloc_bcast_stations(priv);
			return ret;
		}
	}
2219

2220 2221 2222 2223 2224
	ret = iwlagn_run_init_ucode(priv);
	if (ret) {
		IWL_ERR(priv, "Failed to run INIT ucode: %d\n", ret);
		goto error;
	}
Z
Zhu Yi 已提交
2225

2226
	ret = iwlagn_load_ucode_wait_alive(priv,
2227
					   &priv->ucode_rt,
2228
					   IWL_UCODE_REGULAR);
2229 2230 2231
	if (ret) {
		IWL_ERR(priv, "Failed to start RT ucode: %d\n", ret);
		goto error;
Z
Zhu Yi 已提交
2232 2233
	}

2234 2235 2236 2237 2238 2239
	ret = iwl_alive_start(priv);
	if (ret)
		goto error;
	return 0;

 error:
Z
Zhu Yi 已提交
2240
	set_bit(STATUS_EXIT_PENDING, &priv->status);
2241
	__iwl_down(priv);
M
Mohamed Abbas 已提交
2242
	clear_bit(STATUS_EXIT_PENDING, &priv->status);
Z
Zhu Yi 已提交
2243

2244 2245
	IWL_ERR(priv, "Unable to initialize device.\n");
	return ret;
Z
Zhu Yi 已提交
2246 2247 2248 2249 2250 2251 2252 2253 2254
}


/*****************************************************************************
 *
 * Workqueue callbacks
 *
 *****************************************************************************/

2255 2256 2257 2258 2259 2260 2261 2262 2263 2264 2265 2266 2267 2268
static void iwl_bg_run_time_calib_work(struct work_struct *work)
{
	struct iwl_priv *priv = container_of(work, struct iwl_priv,
			run_time_calib_work);

	mutex_lock(&priv->mutex);

	if (test_bit(STATUS_EXIT_PENDING, &priv->status) ||
	    test_bit(STATUS_SCANNING, &priv->status)) {
		mutex_unlock(&priv->mutex);
		return;
	}

	if (priv->start_calib) {
2269 2270
		iwl_chain_noise_calibration(priv);
		iwl_sensitivity_calibration(priv);
2271 2272 2273 2274 2275
	}

	mutex_unlock(&priv->mutex);
}

J
Johannes Berg 已提交
2276 2277 2278 2279 2280 2281 2282 2283 2284 2285 2286 2287 2288 2289 2290 2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301 2302 2303 2304 2305 2306 2307 2308 2309 2310 2311
static void iwlagn_prepare_restart(struct iwl_priv *priv)
{
	struct iwl_rxon_context *ctx;
	bool bt_full_concurrent;
	u8 bt_ci_compliance;
	u8 bt_load;
	u8 bt_status;

	lockdep_assert_held(&priv->mutex);

	for_each_context(priv, ctx)
		ctx->vif = NULL;
	priv->is_open = 0;

	/*
	 * __iwl_down() will clear the BT status variables,
	 * which is correct, but when we restart we really
	 * want to keep them so restore them afterwards.
	 *
	 * The restart process will later pick them up and
	 * re-configure the hw when we reconfigure the BT
	 * command.
	 */
	bt_full_concurrent = priv->bt_full_concurrent;
	bt_ci_compliance = priv->bt_ci_compliance;
	bt_load = priv->bt_traffic_load;
	bt_status = priv->bt_status;

	__iwl_down(priv);

	priv->bt_full_concurrent = bt_full_concurrent;
	priv->bt_ci_compliance = bt_ci_compliance;
	priv->bt_traffic_load = bt_load;
	priv->bt_status = bt_status;
}

2312
static void iwl_bg_restart(struct work_struct *data)
Z
Zhu Yi 已提交
2313
{
2314
	struct iwl_priv *priv = container_of(data, struct iwl_priv, restart);
Z
Zhu Yi 已提交
2315 2316 2317 2318

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

J
Johannes Berg 已提交
2319 2320
	if (test_and_clear_bit(STATUS_FW_ERROR, &priv->status)) {
		mutex_lock(&priv->mutex);
J
Johannes Berg 已提交
2321
		iwlagn_prepare_restart(priv);
J
Johannes Berg 已提交
2322
		mutex_unlock(&priv->mutex);
2323
		iwl_cancel_deferred_work(priv);
J
Johannes Berg 已提交
2324 2325
		ieee80211_restart_hw(priv->hw);
	} else {
2326
		WARN_ON(1);
J
Johannes Berg 已提交
2327
	}
Z
Zhu Yi 已提交
2328 2329
}

2330
static void iwl_bg_rx_replenish(struct work_struct *data)
Z
Zhu Yi 已提交
2331
{
2332 2333
	struct iwl_priv *priv =
	    container_of(data, struct iwl_priv, rx_replenish);
Z
Zhu Yi 已提交
2334 2335 2336 2337 2338

	if (test_bit(STATUS_EXIT_PENDING, &priv->status))
		return;

	mutex_lock(&priv->mutex);
2339
	iwlagn_rx_replenish(priv);
Z
Zhu Yi 已提交
2340 2341 2342
	mutex_unlock(&priv->mutex);
}

J
Johannes Berg 已提交
2343 2344 2345 2346 2347 2348 2349 2350 2351 2352 2353 2354 2355 2356 2357 2358 2359 2360 2361 2362 2363 2364 2365 2366 2367 2368 2369 2370 2371 2372 2373 2374 2375 2376 2377 2378 2379 2380 2381 2382 2383 2384 2385 2386 2387 2388 2389 2390 2391 2392 2393 2394 2395 2396 2397 2398 2399 2400 2401 2402 2403 2404 2405 2406 2407 2408 2409 2410 2411 2412 2413 2414
static int iwl_mac_offchannel_tx(struct ieee80211_hw *hw, struct sk_buff *skb,
				 struct ieee80211_channel *chan,
				 enum nl80211_channel_type channel_type,
				 unsigned int wait)
{
	struct iwl_priv *priv = hw->priv;
	int ret;

	/* Not supported if we don't have PAN */
	if (!(priv->valid_contexts & BIT(IWL_RXON_CTX_PAN))) {
		ret = -EOPNOTSUPP;
		goto free;
	}

	/* Not supported on pre-P2P firmware */
	if (!(priv->contexts[IWL_RXON_CTX_PAN].interface_modes &
					BIT(NL80211_IFTYPE_P2P_CLIENT))) {
		ret = -EOPNOTSUPP;
		goto free;
	}

	mutex_lock(&priv->mutex);

	if (!priv->contexts[IWL_RXON_CTX_PAN].is_active) {
		/*
		 * If the PAN context is free, use the normal
		 * way of doing remain-on-channel offload + TX.
		 */
		ret = 1;
		goto out;
	}

	/* TODO: queue up if scanning? */
	if (test_bit(STATUS_SCANNING, &priv->status) ||
	    priv->_agn.offchan_tx_skb) {
		ret = -EBUSY;
		goto out;
	}

	/*
	 * max_scan_ie_len doesn't include the blank SSID or the header,
	 * so need to add that again here.
	 */
	if (skb->len > hw->wiphy->max_scan_ie_len + 24 + 2) {
		ret = -ENOBUFS;
		goto out;
	}

	priv->_agn.offchan_tx_skb = skb;
	priv->_agn.offchan_tx_timeout = wait;
	priv->_agn.offchan_tx_chan = chan;

	ret = iwl_scan_initiate(priv, priv->contexts[IWL_RXON_CTX_PAN].vif,
				IWL_SCAN_OFFCH_TX, chan->band);
	if (ret)
		priv->_agn.offchan_tx_skb = NULL;
 out:
	mutex_unlock(&priv->mutex);
 free:
	if (ret < 0)
		kfree_skb(skb);

	return ret;
}

static int iwl_mac_offchannel_tx_cancel_wait(struct ieee80211_hw *hw)
{
	struct iwl_priv *priv = hw->priv;
	int ret;

	mutex_lock(&priv->mutex);

2415 2416 2417 2418
	if (!priv->_agn.offchan_tx_skb) {
		ret = -EINVAL;
		goto unlock;
	}
J
Johannes Berg 已提交
2419 2420 2421 2422 2423 2424

	priv->_agn.offchan_tx_skb = NULL;

	ret = iwl_scan_cancel_timeout(priv, 200);
	if (ret)
		ret = -EIO;
2425
unlock:
J
Johannes Berg 已提交
2426 2427 2428 2429 2430
	mutex_unlock(&priv->mutex);

	return ret;
}

Z
Zhu Yi 已提交
2431 2432 2433 2434 2435 2436
/*****************************************************************************
 *
 * mac80211 entry point functions
 *
 *****************************************************************************/

2437 2438 2439 2440 2441 2442 2443 2444 2445 2446 2447 2448 2449 2450 2451 2452 2453 2454 2455 2456 2457 2458 2459 2460 2461 2462 2463 2464 2465 2466 2467 2468 2469 2470 2471 2472 2473 2474 2475 2476 2477 2478 2479 2480 2481 2482 2483 2484 2485 2486 2487 2488 2489 2490 2491 2492 2493 2494 2495 2496 2497 2498 2499 2500 2501 2502 2503 2504 2505 2506 2507
static const struct ieee80211_iface_limit iwlagn_sta_ap_limits[] = {
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_AP),
	},
};

static const struct ieee80211_iface_limit iwlagn_2sta_limits[] = {
	{
		.max = 2,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
};

static const struct ieee80211_iface_limit iwlagn_p2p_sta_go_limits[] = {
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_P2P_GO) |
			 BIT(NL80211_IFTYPE_AP),
	},
};

static const struct ieee80211_iface_limit iwlagn_p2p_2sta_limits[] = {
	{
		.max = 2,
		.types = BIT(NL80211_IFTYPE_STATION),
	},
	{
		.max = 1,
		.types = BIT(NL80211_IFTYPE_P2P_CLIENT),
	},
};

static const struct ieee80211_iface_combination
iwlagn_iface_combinations_dualmode[] = {
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .beacon_int_infra_match = true,
	  .limits = iwlagn_sta_ap_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_sta_ap_limits),
	},
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .limits = iwlagn_2sta_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_2sta_limits),
	},
};

static const struct ieee80211_iface_combination
iwlagn_iface_combinations_p2p[] = {
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .beacon_int_infra_match = true,
	  .limits = iwlagn_p2p_sta_go_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_p2p_sta_go_limits),
	},
	{ .num_different_channels = 1,
	  .max_interfaces = 2,
	  .limits = iwlagn_p2p_2sta_limits,
	  .n_limits = ARRAY_SIZE(iwlagn_p2p_2sta_limits),
	},
};

2508 2509 2510 2511
/*
 * Not a mac80211 entry point function, but it fits in with all the
 * other mac80211 functions grouped here.
 */
2512 2513
static int iwl_mac_setup_register(struct iwl_priv *priv,
				  struct iwlagn_ucode_capabilities *capa)
2514 2515 2516
{
	int ret;
	struct ieee80211_hw *hw = priv->hw;
2517 2518
	struct iwl_rxon_context *ctx;

2519 2520 2521 2522 2523
	hw->rate_control_algorithm = "iwl-agn-rs";

	/* Tell mac80211 our characteristics */
	hw->flags = IEEE80211_HW_SIGNAL_DBM |
		    IEEE80211_HW_AMPDU_AGGREGATION |
2524
		    IEEE80211_HW_NEED_DTIM_PERIOD |
2525 2526
		    IEEE80211_HW_SPECTRUM_MGMT |
		    IEEE80211_HW_REPORTS_TX_ACK_STATUS;
2527

2528 2529
	hw->max_tx_aggregation_subframes = LINK_QUAL_AGG_FRAME_LIMIT_DEF;

2530 2531
	hw->flags |= IEEE80211_HW_SUPPORTS_PS |
		     IEEE80211_HW_SUPPORTS_DYNAMIC_PS;
2532

2533
	if (priv->cfg->sku & EEPROM_SKU_CAP_11N_ENABLE)
J
Johannes Berg 已提交
2534 2535 2536
		hw->flags |= IEEE80211_HW_SUPPORTS_DYNAMIC_SMPS |
			     IEEE80211_HW_SUPPORTS_STATIC_SMPS;

J
Johannes Berg 已提交
2537 2538 2539
	if (capa->flags & IWL_UCODE_TLV_FLAGS_MFP)
		hw->flags |= IEEE80211_HW_MFP_CAPABLE;

2540
	hw->sta_data_size = sizeof(struct iwl_station_priv);
J
Johannes Berg 已提交
2541 2542
	hw->vif_data_size = sizeof(struct iwl_vif_priv);

2543 2544 2545 2546
	for_each_context(priv, ctx) {
		hw->wiphy->interface_modes |= ctx->interface_modes;
		hw->wiphy->interface_modes |= ctx->exclusive_interface_modes;
	}
2547

2548 2549
	BUILD_BUG_ON(NUM_IWL_RXON_CTX != 2);

2550
	if (hw->wiphy->interface_modes & BIT(NL80211_IFTYPE_P2P_CLIENT)) {
2551 2552 2553
		hw->wiphy->iface_combinations = iwlagn_iface_combinations_p2p;
		hw->wiphy->n_iface_combinations =
			ARRAY_SIZE(iwlagn_iface_combinations_p2p);
2554
	} else if (hw->wiphy->interface_modes & BIT(NL80211_IFTYPE_AP)) {
2555 2556 2557 2558 2559
		hw->wiphy->iface_combinations = iwlagn_iface_combinations_dualmode;
		hw->wiphy->n_iface_combinations =
			ARRAY_SIZE(iwlagn_iface_combinations_dualmode);
	}

2560 2561
	hw->wiphy->max_remain_on_channel_duration = 1000;

R
Reinette Chatre 已提交
2562
	hw->wiphy->flags |= WIPHY_FLAG_CUSTOM_REGULATORY |
J
Johannes Berg 已提交
2563 2564
			    WIPHY_FLAG_DISABLE_BEACON_HINTS |
			    WIPHY_FLAG_IBSS_RSN;
2565

2566 2567 2568 2569
	if (iwlagn_mod_params.power_save)
		hw->wiphy->flags |= WIPHY_FLAG_PS_ON_BY_DEFAULT;
	else
		hw->wiphy->flags &= ~WIPHY_FLAG_PS_ON_BY_DEFAULT;
2570

2571
	hw->wiphy->max_scan_ssids = PROBE_OPTION_MAX;
2572
	/* we create the 802.11 header and a zero-length SSID element */
2573
	hw->wiphy->max_scan_ie_len = capa->max_probe_length - 24 - 2;
2574 2575 2576 2577 2578 2579 2580 2581 2582 2583 2584 2585 2586

	/* Default value; 4 EDCA QOS priorities */
	hw->queues = 4;

	hw->max_listen_interval = IWL_CONN_MAX_LISTEN_INTERVAL;

	if (priv->bands[IEEE80211_BAND_2GHZ].n_channels)
		priv->hw->wiphy->bands[IEEE80211_BAND_2GHZ] =
			&priv->bands[IEEE80211_BAND_2GHZ];
	if (priv->bands[IEEE80211_BAND_5GHZ].n_channels)
		priv->hw->wiphy->bands[IEEE80211_BAND_5GHZ] =
			&priv->bands[IEEE80211_BAND_5GHZ];

2587 2588
	iwl_leds_init(priv);

2589 2590 2591 2592 2593 2594 2595 2596 2597 2598 2599
	ret = ieee80211_register_hw(priv->hw);
	if (ret) {
		IWL_ERR(priv, "Failed to register hw (error %d)\n", ret);
		return ret;
	}
	priv->mac80211_registered = 1;

	return 0;
}


2600
static int iwlagn_mac_start(struct ieee80211_hw *hw)
Z
Zhu Yi 已提交
2601
{
2602
	struct iwl_priv *priv = hw->priv;
2603
	int ret;
Z
Zhu Yi 已提交
2604

2605
	IWL_DEBUG_MAC80211(priv, "enter\n");
Z
Zhu Yi 已提交
2606 2607 2608

	/* we should be verifying the device is ready to be opened */
	mutex_lock(&priv->mutex);
2609
	ret = __iwl_up(priv);
Z
Zhu Yi 已提交
2610
	mutex_unlock(&priv->mutex);
2611
	if (ret)
2612
		return ret;
2613

2614
	IWL_DEBUG_INFO(priv, "Start UP work done.\n");
2615

2616 2617 2618
	/* Now we should be done, and the READY bit should be set. */
	if (WARN_ON(!test_bit(STATUS_READY, &priv->status)))
		ret = -EIO;
T
Tomas Winkler 已提交
2619

2620
	iwlagn_led_enable(priv);
J
Johannes Berg 已提交
2621

T
Tomas Winkler 已提交
2622
	priv->is_open = 1;
2623
	IWL_DEBUG_MAC80211(priv, "leave\n");
Z
Zhu Yi 已提交
2624 2625 2626
	return 0;
}

2627
static void iwlagn_mac_stop(struct ieee80211_hw *hw)
Z
Zhu Yi 已提交
2628
{
2629
	struct iwl_priv *priv = hw->priv;
Z
Zhu Yi 已提交
2630

2631
	IWL_DEBUG_MAC80211(priv, "enter\n");
M
Mohamed Abbas 已提交
2632

J
Johannes Berg 已提交
2633
	if (!priv->is_open)
2634 2635
		return;

Z
Zhu Yi 已提交
2636
	priv->is_open = 0;
2637

2638
	iwl_down(priv);
2639 2640

	flush_workqueue(priv->workqueue);
2641

2642 2643
	/* User space software may expect getting rfkill changes
	 * even if interface is down */
2644
	iwl_write32(priv, CSR_INT, 0xFFFFFFFF);
2645
	iwl_enable_rfkill_int(priv);
M
Mohamed Abbas 已提交
2646

2647
	IWL_DEBUG_MAC80211(priv, "leave\n");
Z
Zhu Yi 已提交
2648 2649
}

2650
static void iwlagn_mac_tx(struct ieee80211_hw *hw, struct sk_buff *skb)
Z
Zhu Yi 已提交
2651
{
2652
	struct iwl_priv *priv = hw->priv;
Z
Zhu Yi 已提交
2653

2654
	IWL_DEBUG_MACDUMP(priv, "enter\n");
Z
Zhu Yi 已提交
2655

2656
	IWL_DEBUG_TX(priv, "dev->xmit(%d bytes) at rate 0x%02x\n", skb->len,
2657
		     ieee80211_get_tx_rate(hw, IEEE80211_SKB_CB(skb))->bitrate);
Z
Zhu Yi 已提交
2658

2659
	if (iwlagn_tx_skb(priv, skb))
Z
Zhu Yi 已提交
2660 2661
		dev_kfree_skb_any(skb);

2662
	IWL_DEBUG_MACDUMP(priv, "leave\n");
Z
Zhu Yi 已提交
2663 2664
}

2665 2666 2667 2668 2669
static void iwlagn_mac_update_tkip_key(struct ieee80211_hw *hw,
				       struct ieee80211_vif *vif,
				       struct ieee80211_key_conf *keyconf,
				       struct ieee80211_sta *sta,
				       u32 iv32, u16 *phase1key)
2670
{
2671
	struct iwl_priv *priv = hw->priv;
2672 2673
	struct iwl_vif_priv *vif_priv = (void *)vif->drv_priv;

2674
	IWL_DEBUG_MAC80211(priv, "enter\n");
2675

2676
	iwl_update_tkip_key(priv, vif_priv->ctx, keyconf, sta,
2677
			    iv32, phase1key);
2678

2679
	IWL_DEBUG_MAC80211(priv, "leave\n");
2680 2681
}

2682 2683 2684 2685
static int iwlagn_mac_set_key(struct ieee80211_hw *hw, enum set_key_cmd cmd,
			      struct ieee80211_vif *vif,
			      struct ieee80211_sta *sta,
			      struct ieee80211_key_conf *key)
Z
Zhu Yi 已提交
2686
{
2687
	struct iwl_priv *priv = hw->priv;
2688
	struct iwl_vif_priv *vif_priv = (void *)vif->drv_priv;
2689
	struct iwl_rxon_context *ctx = vif_priv->ctx;
2690 2691 2692
	int ret;
	u8 sta_id;
	bool is_default_wep_key = false;
Z
Zhu Yi 已提交
2693

2694
	IWL_DEBUG_MAC80211(priv, "enter\n");
Z
Zhu Yi 已提交
2695

D
Don Fry 已提交
2696
	if (iwlagn_mod_params.sw_crypto) {
2697
		IWL_DEBUG_MAC80211(priv, "leave - hwcrypto disabled\n");
Z
Zhu Yi 已提交
2698 2699 2700
		return -EOPNOTSUPP;
	}

J
Johannes Berg 已提交
2701 2702 2703 2704 2705 2706 2707 2708
	/*
	 * To support IBSS RSN, don't program group keys in IBSS, the
	 * hardware will then not attempt to decrypt the frames.
	 */
	if (vif->type == NL80211_IFTYPE_ADHOC &&
	    !(key->flags & IEEE80211_KEY_FLAG_PAIRWISE))
		return -EOPNOTSUPP;

2709
	sta_id = iwl_sta_id_or_broadcast(priv, vif_priv->ctx, sta);
2710 2711
	if (sta_id == IWL_INVALID_STATION)
		return -EINVAL;
Z
Zhu Yi 已提交
2712

2713
	mutex_lock(&priv->mutex);
2714
	iwl_scan_cancel_timeout(priv, 100);
2715

J
Johannes Berg 已提交
2716 2717
	/*
	 * If we are getting WEP group key and we didn't receive any key mapping
2718 2719
	 * so far, we are in legacy wep mode (group key only), otherwise we are
	 * in 1X mode.
J
Johannes Berg 已提交
2720 2721
	 * In legacy wep mode, we use another host command to the uCode.
	 */
2722 2723
	if ((key->cipher == WLAN_CIPHER_SUITE_WEP40 ||
	     key->cipher == WLAN_CIPHER_SUITE_WEP104) &&
2724
	    !sta) {
2725
		if (cmd == SET_KEY)
2726
			is_default_wep_key = !ctx->key_mapping_keys;
2727
		else
2728 2729
			is_default_wep_key =
					(key->hw_key_idx == HW_KEY_DEFAULT);
2730
	}
2731

Z
Zhu Yi 已提交
2732
	switch (cmd) {
2733
	case SET_KEY:
2734
		if (is_default_wep_key)
2735
			ret = iwl_set_default_wep_key(priv, vif_priv->ctx, key);
2736
		else
2737 2738
			ret = iwl_set_dynamic_key(priv, vif_priv->ctx,
						  key, sta_id);
2739

2740
		IWL_DEBUG_MAC80211(priv, "enable hwcrypto key\n");
Z
Zhu Yi 已提交
2741 2742
		break;
	case DISABLE_KEY:
2743
		if (is_default_wep_key)
2744
			ret = iwl_remove_default_wep_key(priv, ctx, key);
2745
		else
2746
			ret = iwl_remove_dynamic_key(priv, ctx, key, sta_id);
2747

2748
		IWL_DEBUG_MAC80211(priv, "disable hwcrypto key\n");
Z
Zhu Yi 已提交
2749 2750
		break;
	default:
2751
		ret = -EINVAL;
Z
Zhu Yi 已提交
2752 2753
	}

2754
	mutex_unlock(&priv->mutex);
2755
	IWL_DEBUG_MAC80211(priv, "leave\n");
Z
Zhu Yi 已提交
2756

2757
	return ret;
Z
Zhu Yi 已提交
2758 2759
}

2760 2761 2762 2763 2764
static int iwlagn_mac_ampdu_action(struct ieee80211_hw *hw,
				   struct ieee80211_vif *vif,
				   enum ieee80211_ampdu_mlme_action action,
				   struct ieee80211_sta *sta, u16 tid, u16 *ssn,
				   u8 buf_size)
2765 2766
{
	struct iwl_priv *priv = hw->priv;
2767
	int ret = -EINVAL;
2768
	struct iwl_station_priv *sta_priv = (void *) sta->drv_priv;
2769

2770
	IWL_DEBUG_HT(priv, "A-MPDU action on addr %pM tid %d\n",
J
Johannes Berg 已提交
2771
		     sta->addr, tid);
2772

2773
	if (!(priv->cfg->sku & EEPROM_SKU_CAP_11N_ENABLE))
2774 2775
		return -EACCES;

2776 2777
	mutex_lock(&priv->mutex);

2778 2779
	switch (action) {
	case IEEE80211_AMPDU_RX_START:
2780
		IWL_DEBUG_HT(priv, "start Rx\n");
2781 2782
		ret = iwl_sta_rx_agg_start(priv, sta, tid, *ssn);
		break;
2783
	case IEEE80211_AMPDU_RX_STOP:
2784
		IWL_DEBUG_HT(priv, "stop Rx\n");
2785
		ret = iwl_sta_rx_agg_stop(priv, sta, tid);
2786
		if (test_bit(STATUS_EXIT_PENDING, &priv->status))
2787 2788
			ret = 0;
		break;
2789
	case IEEE80211_AMPDU_TX_START:
2790
		IWL_DEBUG_HT(priv, "start Tx\n");
2791
		ret = iwlagn_tx_agg_start(priv, vif, sta, tid, ssn);
W
Wey-Yi Guy 已提交
2792 2793 2794 2795 2796
		if (ret == 0) {
			priv->_agn.agg_tids_count++;
			IWL_DEBUG_HT(priv, "priv->_agn.agg_tids_count = %u\n",
				     priv->_agn.agg_tids_count);
		}
2797
		break;
2798
	case IEEE80211_AMPDU_TX_STOP:
2799
		IWL_DEBUG_HT(priv, "stop Tx\n");
2800
		ret = iwlagn_tx_agg_stop(priv, vif, sta, tid);
W
Wey-Yi Guy 已提交
2801 2802 2803 2804 2805
		if ((ret == 0) && (priv->_agn.agg_tids_count > 0)) {
			priv->_agn.agg_tids_count--;
			IWL_DEBUG_HT(priv, "priv->_agn.agg_tids_count = %u\n",
				     priv->_agn.agg_tids_count);
		}
2806
		if (test_bit(STATUS_EXIT_PENDING, &priv->status))
2807
			ret = 0;
2808 2809
		if (priv->cfg->ht_params &&
		    priv->cfg->ht_params->use_rts_for_aggregation) {
J
Johannes Berg 已提交
2810 2811 2812 2813 2814
			/*
			 * switch off RTS/CTS if it was previously enabled
			 */
			sta_priv->lq_sta.lq.general_params.flags &=
				~LINK_QUAL_FLAGS_SET_STA_TLC_RTS_MSK;
2815 2816
			iwl_send_lq_cmd(priv, iwl_rxon_ctx_from_vif(vif),
					&sta_priv->lq_sta.lq, CMD_ASYNC, false);
J
Johannes Berg 已提交
2817
		}
2818
		break;
2819
	case IEEE80211_AMPDU_TX_OPERATIONAL:
2820 2821 2822 2823
		buf_size = min_t(int, buf_size, LINK_QUAL_AGG_FRAME_LIMIT_DEF);

		iwlagn_txq_agg_queue_setup(priv, sta, tid, buf_size);

2824 2825 2826 2827 2828 2829 2830 2831 2832 2833 2834 2835 2836 2837 2838 2839 2840 2841 2842 2843
		/*
		 * If the limit is 0, then it wasn't initialised yet,
		 * use the default. We can do that since we take the
		 * minimum below, and we don't want to go above our
		 * default due to hardware restrictions.
		 */
		if (sta_priv->max_agg_bufsize == 0)
			sta_priv->max_agg_bufsize =
				LINK_QUAL_AGG_FRAME_LIMIT_DEF;

		/*
		 * Even though in theory the peer could have different
		 * aggregation reorder buffer sizes for different sessions,
		 * our ucode doesn't allow for that and has a global limit
		 * for each station. Therefore, use the minimum of all the
		 * aggregation sessions and our default value.
		 */
		sta_priv->max_agg_bufsize =
			min(sta_priv->max_agg_bufsize, buf_size);

2844 2845
		if (priv->cfg->ht_params &&
		    priv->cfg->ht_params->use_rts_for_aggregation) {
2846 2847 2848 2849
			/*
			 * switch to RTS/CTS if it is the prefer protection
			 * method for HT traffic
			 */
J
Johannes Berg 已提交
2850 2851 2852

			sta_priv->lq_sta.lq.general_params.flags |=
				LINK_QUAL_FLAGS_SET_STA_TLC_RTS_MSK;
2853
		}
2854 2855 2856 2857 2858 2859

		sta_priv->lq_sta.lq.agg_params.agg_frame_cnt_limit =
			sta_priv->max_agg_bufsize;

		iwl_send_lq_cmd(priv, iwl_rxon_ctx_from_vif(vif),
				&sta_priv->lq_sta.lq, CMD_ASYNC, false);
2860 2861 2862

		IWL_INFO(priv, "Tx aggregation enabled on ra = %pM tid = %d\n",
			 sta->addr, tid);
2863
		ret = 0;
2864 2865
		break;
	}
2866 2867 2868
	mutex_unlock(&priv->mutex);

	return ret;
2869
}
2870

2871 2872 2873
static int iwlagn_mac_sta_add(struct ieee80211_hw *hw,
			      struct ieee80211_vif *vif,
			      struct ieee80211_sta *sta)
2874 2875 2876
{
	struct iwl_priv *priv = hw->priv;
	struct iwl_station_priv *sta_priv = (void *)sta->drv_priv;
2877
	struct iwl_vif_priv *vif_priv = (void *)vif->drv_priv;
2878
	bool is_ap = vif->type == NL80211_IFTYPE_STATION;
2879 2880 2881 2882 2883
	int ret;
	u8 sta_id;

	IWL_DEBUG_INFO(priv, "received request to add station %pM\n",
			sta->addr);
2884 2885 2886 2887
	mutex_lock(&priv->mutex);
	IWL_DEBUG_INFO(priv, "proceeding to add station %pM\n",
			sta->addr);
	sta_priv->common.sta_id = IWL_INVALID_STATION;
2888 2889 2890 2891 2892

	atomic_set(&sta_priv->pending_frames, 0);
	if (vif->type == NL80211_IFTYPE_AP)
		sta_priv->client = true;

2893
	ret = iwl_add_station_common(priv, vif_priv->ctx, sta->addr,
2894
				     is_ap, sta, &sta_id);
2895 2896 2897 2898
	if (ret) {
		IWL_ERR(priv, "Unable to add station %pM (%d)\n",
			sta->addr, ret);
		/* Should we return success if return code is EEXIST ? */
2899
		mutex_unlock(&priv->mutex);
2900 2901 2902
		return ret;
	}

J
Johannes Berg 已提交
2903 2904
	sta_priv->common.sta_id = sta_id;

2905
	/* Initialize rate scaling */
2906
	IWL_DEBUG_INFO(priv, "Initializing rate scaling for station %pM\n",
2907 2908
		       sta->addr);
	iwl_rs_rate_init(priv, sta, sta_id);
2909
	mutex_unlock(&priv->mutex);
2910

J
Johannes Berg 已提交
2911
	return 0;
2912 2913
}

2914 2915
static void iwlagn_mac_channel_switch(struct ieee80211_hw *hw,
				struct ieee80211_channel_switch *ch_switch)
2916 2917 2918 2919
{
	struct iwl_priv *priv = hw->priv;
	const struct iwl_channel_info *ch_info;
	struct ieee80211_conf *conf = &hw->conf;
2920
	struct ieee80211_channel *channel = ch_switch->channel;
2921
	struct iwl_ht_config *ht_conf = &priv->current_ht_config;
2922 2923 2924 2925 2926 2927 2928 2929 2930
	/*
	 * MULTI-FIXME
	 * When we add support for multiple interfaces, we need to
	 * revisit this. The channel switch command in the device
	 * only affects the BSS context, but what does that really
	 * mean? And what if we get a CSA on the second interface?
	 * This needs a lot of work.
	 */
	struct iwl_rxon_context *ctx = &priv->contexts[IWL_RXON_CTX_BSS];
2931 2932 2933 2934
	u16 ch;

	IWL_DEBUG_MAC80211(priv, "enter\n");

2935 2936
	mutex_lock(&priv->mutex);

2937
	if (iwl_is_rfkill(priv))
2938
		goto out;
2939 2940

	if (test_bit(STATUS_EXIT_PENDING, &priv->status) ||
2941 2942
	    test_bit(STATUS_SCANNING, &priv->status) ||
	    test_bit(STATUS_CHANNEL_SWITCH_PENDING, &priv->status))
2943
		goto out;
2944

2945
	if (!iwl_is_associated_ctx(ctx))
2946
		goto out;
2947

2948 2949
	if (!priv->cfg->ops->lib->set_channel_switch)
		goto out;
2950

2951 2952 2953 2954 2955 2956 2957 2958 2959
	ch = channel->hw_value;
	if (le16_to_cpu(ctx->active.channel) == ch)
		goto out;

	ch_info = iwl_get_channel_info(priv, channel->band, ch);
	if (!is_channel_valid(ch_info)) {
		IWL_DEBUG_MAC80211(priv, "invalid channel\n");
		goto out;
	}
2960

2961
	spin_lock_irq(&priv->lock);
2962

2963
	priv->current_ht_config.smps = conf->smps_mode;
2964

2965 2966 2967 2968 2969 2970 2971 2972 2973 2974 2975 2976 2977 2978 2979
	/* Configure HT40 channels */
	ctx->ht.enabled = conf_is_ht(conf);
	if (ctx->ht.enabled) {
		if (conf_is_ht40_minus(conf)) {
			ctx->ht.extension_chan_offset =
				IEEE80211_HT_PARAM_CHA_SEC_BELOW;
			ctx->ht.is_40mhz = true;
		} else if (conf_is_ht40_plus(conf)) {
			ctx->ht.extension_chan_offset =
				IEEE80211_HT_PARAM_CHA_SEC_ABOVE;
			ctx->ht.is_40mhz = true;
		} else {
			ctx->ht.extension_chan_offset =
				IEEE80211_HT_PARAM_CHA_SEC_NONE;
			ctx->ht.is_40mhz = false;
2980
		}
2981 2982 2983 2984 2985 2986 2987 2988 2989 2990 2991 2992 2993 2994 2995 2996 2997 2998 2999 3000 3001 3002 3003
	} else
		ctx->ht.is_40mhz = false;

	if ((le16_to_cpu(ctx->staging.channel) != ch))
		ctx->staging.flags = 0;

	iwl_set_rxon_channel(priv, channel, ctx);
	iwl_set_rxon_ht(priv, ht_conf);
	iwl_set_flags_for_band(priv, ctx, channel->band, ctx->vif);

	spin_unlock_irq(&priv->lock);

	iwl_set_rate(priv);
	/*
	 * at this point, staging_rxon has the
	 * configuration for channel switch
	 */
	set_bit(STATUS_CHANNEL_SWITCH_PENDING, &priv->status);
	priv->switch_channel = cpu_to_le16(ch);
	if (priv->cfg->ops->lib->set_channel_switch(priv, ch_switch)) {
		clear_bit(STATUS_CHANNEL_SWITCH_PENDING, &priv->status);
		priv->switch_channel = 0;
		ieee80211_chswitch_done(ctx->vif, false);
3004
	}
3005

3006 3007 3008 3009 3010
out:
	mutex_unlock(&priv->mutex);
	IWL_DEBUG_MAC80211(priv, "leave\n");
}

3011 3012 3013 3014
static void iwlagn_configure_filter(struct ieee80211_hw *hw,
				    unsigned int changed_flags,
				    unsigned int *total_flags,
				    u64 multicast)
J
Johannes Berg 已提交
3015 3016 3017
{
	struct iwl_priv *priv = hw->priv;
	__le32 filter_or = 0, filter_nand = 0;
3018
	struct iwl_rxon_context *ctx;
J
Johannes Berg 已提交
3019 3020 3021 3022 3023 3024 3025 3026 3027 3028 3029 3030

#define CHK(test, flag)	do { \
	if (*total_flags & (test))		\
		filter_or |= (flag);		\
	else					\
		filter_nand |= (flag);		\
	} while (0)

	IWL_DEBUG_MAC80211(priv, "Enter: changed: 0x%x, total: 0x%x\n",
			changed_flags, *total_flags);

	CHK(FIF_OTHER_BSS | FIF_PROMISC_IN_BSS, RXON_FILTER_PROMISC_MSK);
J
Johannes Berg 已提交
3031 3032
	/* Setting _just_ RXON_FILTER_CTL2HOST_MSK causes FH errors */
	CHK(FIF_CONTROL, RXON_FILTER_CTL2HOST_MSK | RXON_FILTER_PROMISC_MSK);
J
Johannes Berg 已提交
3033 3034 3035 3036 3037 3038
	CHK(FIF_BCN_PRBRESP_PROMISC, RXON_FILTER_BCON_AWARE_MSK);

#undef CHK

	mutex_lock(&priv->mutex);

3039 3040 3041
	for_each_context(priv, ctx) {
		ctx->staging.filter_flags &= ~filter_nand;
		ctx->staging.filter_flags |= filter_or;
3042 3043 3044 3045 3046

		/*
		 * Not committing directly because hardware can perform a scan,
		 * but we'll eventually commit the filter flags change anyway.
		 */
3047
	}
J
Johannes Berg 已提交
3048 3049 3050 3051 3052 3053 3054 3055 3056 3057 3058 3059 3060

	mutex_unlock(&priv->mutex);

	/*
	 * Receiving all multicast frames is always enabled by the
	 * default flags setup in iwl_connection_init_rx_config()
	 * since we currently do not support programming multicast
	 * filters into the device.
	 */
	*total_flags &= FIF_OTHER_BSS | FIF_ALLMULTI | FIF_PROMISC_IN_BSS |
			FIF_BCN_PRBRESP_PROMISC | FIF_CONTROL;
}

3061
static void iwlagn_mac_flush(struct ieee80211_hw *hw, bool drop)
3062 3063 3064 3065 3066 3067 3068 3069 3070 3071 3072 3073 3074 3075 3076 3077 3078 3079 3080 3081 3082
{
	struct iwl_priv *priv = hw->priv;

	mutex_lock(&priv->mutex);
	IWL_DEBUG_MAC80211(priv, "enter\n");

	if (test_bit(STATUS_EXIT_PENDING, &priv->status)) {
		IWL_DEBUG_TX(priv, "Aborting flush due to device shutdown\n");
		goto done;
	}
	if (iwl_is_rfkill(priv)) {
		IWL_DEBUG_TX(priv, "Aborting flush due to RF Kill\n");
		goto done;
	}

	/*
	 * mac80211 will not push any more frames for transmit
	 * until the flush is completed
	 */
	if (drop) {
		IWL_DEBUG_MAC80211(priv, "send flush command\n");
3083
		if (iwlagn_txfifo_flush(priv, IWL_DROP_ALL)) {
3084 3085 3086 3087 3088 3089 3090 3091 3092 3093 3094
			IWL_ERR(priv, "flush request fail\n");
			goto done;
		}
	}
	IWL_DEBUG_MAC80211(priv, "wait transmit/flush all frames\n");
	iwlagn_wait_tx_queue_empty(priv);
done:
	mutex_unlock(&priv->mutex);
	IWL_DEBUG_MAC80211(priv, "leave\n");
}

3095 3096 3097 3098 3099 3100 3101 3102 3103 3104 3105 3106 3107 3108 3109 3110 3111
static void iwlagn_disable_roc(struct iwl_priv *priv)
{
	struct iwl_rxon_context *ctx = &priv->contexts[IWL_RXON_CTX_PAN];
	struct ieee80211_channel *chan = ACCESS_ONCE(priv->hw->conf.channel);

	lockdep_assert_held(&priv->mutex);

	if (!ctx->is_active)
		return;

	ctx->staging.dev_type = RXON_DEV_TYPE_2STA;
	ctx->staging.filter_flags &= ~RXON_FILTER_ASSOC_MSK;
	iwl_set_rxon_channel(priv, chan, ctx);
	iwl_set_flags_for_band(priv, ctx, chan->band, NULL);

	priv->_agn.hw_roc_channel = NULL;

3112
	iwlagn_commit_rxon(priv, ctx);
3113 3114 3115 3116 3117 3118 3119 3120 3121 3122 3123 3124 3125 3126 3127 3128 3129 3130 3131 3132 3133 3134 3135 3136 3137 3138 3139 3140 3141 3142 3143 3144 3145 3146 3147 3148 3149 3150 3151 3152 3153 3154

	ctx->is_active = false;
}

static void iwlagn_bg_roc_done(struct work_struct *work)
{
	struct iwl_priv *priv = container_of(work, struct iwl_priv,
					     _agn.hw_roc_work.work);

	mutex_lock(&priv->mutex);
	ieee80211_remain_on_channel_expired(priv->hw);
	iwlagn_disable_roc(priv);
	mutex_unlock(&priv->mutex);
}

static int iwl_mac_remain_on_channel(struct ieee80211_hw *hw,
				     struct ieee80211_channel *channel,
				     enum nl80211_channel_type channel_type,
				     int duration)
{
	struct iwl_priv *priv = hw->priv;
	int err = 0;

	if (!(priv->valid_contexts & BIT(IWL_RXON_CTX_PAN)))
		return -EOPNOTSUPP;

	if (!(priv->contexts[IWL_RXON_CTX_PAN].interface_modes &
					BIT(NL80211_IFTYPE_P2P_CLIENT)))
		return -EOPNOTSUPP;

	mutex_lock(&priv->mutex);

	if (priv->contexts[IWL_RXON_CTX_PAN].is_active ||
	    test_bit(STATUS_SCAN_HW, &priv->status)) {
		err = -EBUSY;
		goto out;
	}

	priv->contexts[IWL_RXON_CTX_PAN].is_active = true;
	priv->_agn.hw_roc_channel = channel;
	priv->_agn.hw_roc_chantype = channel_type;
	priv->_agn.hw_roc_duration = DIV_ROUND_UP(duration * 1000, 1024);
3155
	iwlagn_commit_rxon(priv, &priv->contexts[IWL_RXON_CTX_PAN]);
3156 3157 3158
	queue_delayed_work(priv->workqueue, &priv->_agn.hw_roc_work,
			   msecs_to_jiffies(duration + 20));

3159
	msleep(IWL_MIN_SLOT_TIME); /* TU is almost ms */
3160 3161 3162 3163 3164 3165 3166 3167 3168 3169 3170 3171 3172 3173 3174 3175 3176 3177 3178 3179 3180 3181 3182 3183
	ieee80211_ready_on_channel(priv->hw);

 out:
	mutex_unlock(&priv->mutex);

	return err;
}

static int iwl_mac_cancel_remain_on_channel(struct ieee80211_hw *hw)
{
	struct iwl_priv *priv = hw->priv;

	if (!(priv->valid_contexts & BIT(IWL_RXON_CTX_PAN)))
		return -EOPNOTSUPP;

	cancel_delayed_work_sync(&priv->_agn.hw_roc_work);

	mutex_lock(&priv->mutex);
	iwlagn_disable_roc(priv);
	mutex_unlock(&priv->mutex);

	return 0;
}

Z
Zhu Yi 已提交
3184 3185 3186 3187 3188 3189
/*****************************************************************************
 *
 * driver setup and teardown
 *
 *****************************************************************************/

3190
static void iwl_setup_deferred_work(struct iwl_priv *priv)
Z
Zhu Yi 已提交
3191
{
3192
	priv->workqueue = create_singlethread_workqueue(DRV_NAME);
Z
Zhu Yi 已提交
3193 3194 3195

	init_waitqueue_head(&priv->wait_command_queue);

3196 3197 3198
	INIT_WORK(&priv->restart, iwl_bg_restart);
	INIT_WORK(&priv->rx_replenish, iwl_bg_rx_replenish);
	INIT_WORK(&priv->beacon_update, iwl_bg_beacon_update);
3199
	INIT_WORK(&priv->run_time_calib_work, iwl_bg_run_time_calib_work);
3200
	INIT_WORK(&priv->tx_flush, iwl_bg_tx_flush);
3201
	INIT_WORK(&priv->bt_full_concurrency, iwl_bg_bt_full_concurrency);
3202
	INIT_WORK(&priv->bt_runtime_config, iwl_bg_bt_runtime_config);
3203
	INIT_DELAYED_WORK(&priv->_agn.hw_roc_work, iwlagn_bg_roc_done);
3204 3205

	iwl_setup_scan_deferred_work(priv);
C
Christoph Hellwig 已提交
3206

3207 3208 3209 3210 3211
	if (priv->cfg->ops->lib->setup_deferred_work)
		priv->cfg->ops->lib->setup_deferred_work(priv);

	init_timer(&priv->statistics_periodic);
	priv->statistics_periodic.data = (unsigned long)priv;
3212
	priv->statistics_periodic.function = iwl_bg_statistics_periodic;
Z
Zhu Yi 已提交
3213

3214 3215 3216 3217
	init_timer(&priv->ucode_trace);
	priv->ucode_trace.data = (unsigned long)priv;
	priv->ucode_trace.function = iwl_bg_ucode_trace;

3218 3219 3220
	init_timer(&priv->watchdog);
	priv->watchdog.data = (unsigned long)priv;
	priv->watchdog.function = iwl_bg_watchdog;
3221

W
Wey-Yi Guy 已提交
3222 3223
	tasklet_init(&priv->irq_tasklet, (void (*)(unsigned long))
		iwl_irq_tasklet, (unsigned long)priv);
Z
Zhu Yi 已提交
3224 3225
}

3226
static void iwl_cancel_deferred_work(struct iwl_priv *priv)
Z
Zhu Yi 已提交
3227
{
3228 3229
	if (priv->cfg->ops->lib->cancel_deferred_work)
		priv->cfg->ops->lib->cancel_deferred_work(priv);
Z
Zhu Yi 已提交
3230

3231
	cancel_work_sync(&priv->run_time_calib_work);
Z
Zhu Yi 已提交
3232
	cancel_work_sync(&priv->beacon_update);
3233 3234 3235

	iwl_cancel_scan_deferred_work(priv);

3236
	cancel_work_sync(&priv->bt_full_concurrency);
3237
	cancel_work_sync(&priv->bt_runtime_config);
3238

3239
	del_timer_sync(&priv->statistics_periodic);
3240
	del_timer_sync(&priv->ucode_trace);
Z
Zhu Yi 已提交
3241 3242
}

3243 3244 3245 3246 3247 3248 3249 3250 3251 3252 3253 3254 3255 3256 3257 3258 3259 3260 3261 3262 3263 3264 3265 3266 3267 3268 3269 3270 3271 3272 3273 3274 3275 3276 3277
static void iwl_init_hw_rates(struct iwl_priv *priv,
			      struct ieee80211_rate *rates)
{
	int i;

	for (i = 0; i < IWL_RATE_COUNT_LEGACY; i++) {
		rates[i].bitrate = iwl_rates[i].ieee * 5;
		rates[i].hw_value = i; /* Rate scaling will work on indexes */
		rates[i].hw_value_short = i;
		rates[i].flags = 0;
		if ((i >= IWL_FIRST_CCK_RATE) && (i <= IWL_LAST_CCK_RATE)) {
			/*
			 * If CCK != 1M then set short preamble rate flag.
			 */
			rates[i].flags |=
				(iwl_rates[i].plcp == IWL_RATE_1M_PLCP) ?
					0 : IEEE80211_RATE_SHORT_PREAMBLE;
		}
	}
}

static int iwl_init_drv(struct iwl_priv *priv)
{
	int ret;

	spin_lock_init(&priv->sta_lock);
	spin_lock_init(&priv->hcmd_lock);

	mutex_init(&priv->mutex);

	priv->ieee_channels = NULL;
	priv->ieee_rates = NULL;
	priv->band = IEEE80211_BAND_2GHZ;

	priv->iw_mode = NL80211_IFTYPE_STATION;
J
Johannes Berg 已提交
3278
	priv->current_ht_config.smps = IEEE80211_SMPS_STATIC;
3279
	priv->missed_beacon_threshold = IWL_MISSED_BEACON_THRESHOLD_DEF;
W
Wey-Yi Guy 已提交
3280
	priv->_agn.agg_tids_count = 0;
3281

3282 3283 3284 3285 3286
	/* initialize force reset */
	priv->force_reset[IWL_RF_RESET].reset_duration =
		IWL_DELAY_NEXT_FORCE_RF_RESET;
	priv->force_reset[IWL_FW_RESET].reset_duration =
		IWL_DELAY_NEXT_FORCE_FW_RELOAD;
3287

3288 3289
	priv->rx_statistics_jiffies = jiffies;

3290 3291
	/* Choose which receivers/antennas to use */
	if (priv->cfg->ops->hcmd->set_rxon_chain)
3292 3293
		priv->cfg->ops->hcmd->set_rxon_chain(priv,
					&priv->contexts[IWL_RXON_CTX_BSS]);
3294 3295 3296

	iwl_init_scan_params(priv);

3297
	/* init bt coex */
3298 3299
	if (priv->cfg->bt_params &&
	    priv->cfg->bt_params->advanced_bt_coexist) {
W
Wey-Yi Guy 已提交
3300 3301 3302
		priv->kill_ack_mask = IWLAGN_BT_KILL_ACK_MASK_DEFAULT;
		priv->kill_cts_mask = IWLAGN_BT_KILL_CTS_MASK_DEFAULT;
		priv->bt_valid = IWLAGN_BT_ALL_VALID_MSK;
3303 3304 3305 3306 3307
		priv->bt_on_thresh = BT_ON_THRESHOLD_DEF;
		priv->bt_duration = BT_DURATION_LIMIT_DEF;
		priv->dynamic_frag_thresh = BT_FRAG_THRESHOLD_DEF;
	}

3308 3309 3310 3311 3312 3313 3314 3315 3316 3317 3318 3319 3320 3321 3322 3323 3324 3325 3326 3327 3328 3329 3330 3331 3332 3333
	ret = iwl_init_channel_map(priv);
	if (ret) {
		IWL_ERR(priv, "initializing regulatory failed: %d\n", ret);
		goto err;
	}

	ret = iwlcore_init_geos(priv);
	if (ret) {
		IWL_ERR(priv, "initializing geos failed: %d\n", ret);
		goto err_free_channel_map;
	}
	iwl_init_hw_rates(priv, priv->ieee_rates);

	return 0;

err_free_channel_map:
	iwl_free_channel_map(priv);
err:
	return ret;
}

static void iwl_uninit_drv(struct iwl_priv *priv)
{
	iwl_calib_free_results(priv);
	iwlcore_free_geos(priv);
	iwl_free_channel_map(priv);
3334
	kfree(priv->scan_cmd);
3335
	kfree(priv->beacon_cmd);
3336 3337
}

3338
struct ieee80211_ops iwlagn_hw_ops = {
3339 3340 3341
	.tx = iwlagn_mac_tx,
	.start = iwlagn_mac_start,
	.stop = iwlagn_mac_stop,
3342 3343
	.add_interface = iwl_mac_add_interface,
	.remove_interface = iwl_mac_remove_interface,
3344
	.change_interface = iwl_mac_change_interface,
3345
	.config = iwlagn_mac_config,
J
Johannes Berg 已提交
3346
	.configure_filter = iwlagn_configure_filter,
3347 3348
	.set_key = iwlagn_mac_set_key,
	.update_tkip_key = iwlagn_mac_update_tkip_key,
3349
	.conf_tx = iwl_mac_conf_tx,
3350 3351
	.bss_info_changed = iwlagn_bss_info_changed,
	.ampdu_action = iwlagn_mac_ampdu_action,
3352
	.hw_scan = iwl_mac_hw_scan,
3353
	.sta_notify = iwlagn_mac_sta_notify,
3354 3355
	.sta_add = iwlagn_mac_sta_add,
	.sta_remove = iwl_mac_sta_remove,
3356 3357
	.channel_switch = iwlagn_mac_channel_switch,
	.flush = iwlagn_mac_flush,
3358
	.tx_last_beacon = iwl_mac_tx_last_beacon,
3359 3360
	.remain_on_channel = iwl_mac_remain_on_channel,
	.cancel_remain_on_channel = iwl_mac_cancel_remain_on_channel,
J
Johannes Berg 已提交
3361 3362
	.offchannel_tx = iwl_mac_offchannel_tx,
	.offchannel_tx_cancel_wait = iwl_mac_offchannel_tx_cancel_wait,
3363
	CFG80211_TESTMODE_CMD(iwl_testmode_cmd)
3364
	CFG80211_TESTMODE_DUMP(iwl_testmode_dump)
Z
Zhu Yi 已提交
3365 3366
};

J
Johannes Berg 已提交
3367
static u32 iwl_hw_detect(struct iwl_priv *priv)
3368
{
3369
	return iwl_read32(priv, CSR_HW_REV);
3370 3371
}

3372 3373 3374 3375
static int iwl_set_hw_params(struct iwl_priv *priv)
{
	priv->hw_params.max_rxq_size = RX_QUEUE_SIZE;
	priv->hw_params.max_rxq_log = RX_QUEUE_SIZE_LOG;
D
Don Fry 已提交
3376
	if (iwlagn_mod_params.amsdu_size_8K)
3377 3378 3379 3380 3381 3382
		priv->hw_params.rx_page_order = get_order(IWL_RX_BUF_SIZE_8K);
	else
		priv->hw_params.rx_page_order = get_order(IWL_RX_BUF_SIZE_4K);

	priv->hw_params.max_beacon_itrvl = IWL_MAX_UCODE_BEACON_INTERVAL;

D
Don Fry 已提交
3383
	if (iwlagn_mod_params.disable_11n)
3384
		priv->cfg->sku &= ~EEPROM_SKU_CAP_11N_ENABLE;
3385 3386 3387 3388 3389

	/* Device-specific setup */
	return priv->cfg->ops->lib->set_hw_params(priv);
}

3390 3391 3392 3393 3394 3395 3396 3397 3398 3399 3400 3401 3402 3403 3404 3405 3406 3407 3408 3409 3410 3411
static const u8 iwlagn_bss_ac_to_fifo[] = {
	IWL_TX_FIFO_VO,
	IWL_TX_FIFO_VI,
	IWL_TX_FIFO_BE,
	IWL_TX_FIFO_BK,
};

static const u8 iwlagn_bss_ac_to_queue[] = {
	0, 1, 2, 3,
};

static const u8 iwlagn_pan_ac_to_fifo[] = {
	IWL_TX_FIFO_VO_IPAN,
	IWL_TX_FIFO_VI_IPAN,
	IWL_TX_FIFO_BE_IPAN,
	IWL_TX_FIFO_BK_IPAN,
};

static const u8 iwlagn_pan_ac_to_queue[] = {
	7, 6, 5, 4,
};

3412 3413 3414 3415 3416 3417 3418 3419 3420 3421 3422 3423 3424 3425 3426 3427 3428 3429 3430 3431 3432 3433
/* This function both allocates and initializes hw and priv. */
static struct ieee80211_hw *iwl_alloc_all(struct iwl_cfg *cfg)
{
	struct iwl_priv *priv;
	/* mac80211 allocates memory for this device instance, including
	 *   space for this driver's private structure */
	struct ieee80211_hw *hw;

	hw = ieee80211_alloc_hw(sizeof(struct iwl_priv), &iwlagn_hw_ops);
	if (hw == NULL) {
		pr_err("%s: Can not allocate network device\n",
		       cfg->name);
		goto out;
	}

	priv = hw->priv;
	priv->hw = hw;

out:
	return hw;
}

3434
static void iwl_init_context(struct iwl_priv *priv)
Z
Zhu Yi 已提交
3435
{
3436
	int i;
3437

3438 3439 3440 3441 3442 3443 3444 3445 3446 3447
	/*
	 * The default context is always valid,
	 * more may be discovered when firmware
	 * is loaded.
	 */
	priv->valid_contexts = BIT(IWL_RXON_CTX_BSS);

	for (i = 0; i < NUM_IWL_RXON_CTX; i++)
		priv->contexts[i].ctxid = i;

3448 3449
	priv->contexts[IWL_RXON_CTX_BSS].always_active = true;
	priv->contexts[IWL_RXON_CTX_BSS].is_active = true;
3450 3451 3452
	priv->contexts[IWL_RXON_CTX_BSS].rxon_cmd = REPLY_RXON;
	priv->contexts[IWL_RXON_CTX_BSS].rxon_timing_cmd = REPLY_RXON_TIMING;
	priv->contexts[IWL_RXON_CTX_BSS].rxon_assoc_cmd = REPLY_RXON_ASSOC;
J
Johannes Berg 已提交
3453
	priv->contexts[IWL_RXON_CTX_BSS].qos_cmd = REPLY_QOS_PARAM;
3454
	priv->contexts[IWL_RXON_CTX_BSS].ap_sta_id = IWL_AP_ID;
3455
	priv->contexts[IWL_RXON_CTX_BSS].wep_key_cmd = REPLY_WEPKEY;
3456 3457
	priv->contexts[IWL_RXON_CTX_BSS].ac_to_fifo = iwlagn_bss_ac_to_fifo;
	priv->contexts[IWL_RXON_CTX_BSS].ac_to_queue = iwlagn_bss_ac_to_queue;
3458 3459 3460 3461
	priv->contexts[IWL_RXON_CTX_BSS].exclusive_interface_modes =
		BIT(NL80211_IFTYPE_ADHOC);
	priv->contexts[IWL_RXON_CTX_BSS].interface_modes =
		BIT(NL80211_IFTYPE_STATION);
3462
	priv->contexts[IWL_RXON_CTX_BSS].ap_devtype = RXON_DEV_TYPE_AP;
3463 3464 3465
	priv->contexts[IWL_RXON_CTX_BSS].ibss_devtype = RXON_DEV_TYPE_IBSS;
	priv->contexts[IWL_RXON_CTX_BSS].station_devtype = RXON_DEV_TYPE_ESS;
	priv->contexts[IWL_RXON_CTX_BSS].unused_devtype = RXON_DEV_TYPE_ESS;
J
Johannes Berg 已提交
3466 3467

	priv->contexts[IWL_RXON_CTX_PAN].rxon_cmd = REPLY_WIPAN_RXON;
3468 3469 3470 3471
	priv->contexts[IWL_RXON_CTX_PAN].rxon_timing_cmd =
		REPLY_WIPAN_RXON_TIMING;
	priv->contexts[IWL_RXON_CTX_PAN].rxon_assoc_cmd =
		REPLY_WIPAN_RXON_ASSOC;
J
Johannes Berg 已提交
3472 3473 3474 3475 3476
	priv->contexts[IWL_RXON_CTX_PAN].qos_cmd = REPLY_WIPAN_QOS_PARAM;
	priv->contexts[IWL_RXON_CTX_PAN].ap_sta_id = IWL_AP_ID_PAN;
	priv->contexts[IWL_RXON_CTX_PAN].wep_key_cmd = REPLY_WIPAN_WEPKEY;
	priv->contexts[IWL_RXON_CTX_PAN].bcast_sta_id = IWLAGN_PAN_BCAST_ID;
	priv->contexts[IWL_RXON_CTX_PAN].station_flags = STA_FLG_PAN_STATION;
3477 3478 3479
	priv->contexts[IWL_RXON_CTX_PAN].ac_to_fifo = iwlagn_pan_ac_to_fifo;
	priv->contexts[IWL_RXON_CTX_PAN].ac_to_queue = iwlagn_pan_ac_to_queue;
	priv->contexts[IWL_RXON_CTX_PAN].mcast_queue = IWL_IPAN_MCAST_QUEUE;
3480 3481
	priv->contexts[IWL_RXON_CTX_PAN].interface_modes =
		BIT(NL80211_IFTYPE_STATION) | BIT(NL80211_IFTYPE_AP);
W
Wey-Yi Guy 已提交
3482 3483 3484 3485
#ifdef CONFIG_IWL_P2P
	priv->contexts[IWL_RXON_CTX_PAN].interface_modes |=
		BIT(NL80211_IFTYPE_P2P_CLIENT) | BIT(NL80211_IFTYPE_P2P_GO);
#endif
3486 3487 3488
	priv->contexts[IWL_RXON_CTX_PAN].ap_devtype = RXON_DEV_TYPE_CP;
	priv->contexts[IWL_RXON_CTX_PAN].station_devtype = RXON_DEV_TYPE_2STA;
	priv->contexts[IWL_RXON_CTX_PAN].unused_devtype = RXON_DEV_TYPE_P2P;
J
Johannes Berg 已提交
3489 3490

	BUILD_BUG_ON(NUM_IWL_RXON_CTX != 2);
3491 3492
}

3493 3494
int iwl_probe(void *bus_specific, struct iwl_bus_ops *bus_ops,
		struct iwl_cfg *cfg)
3495 3496 3497 3498
{
	int err = 0;
	struct iwl_priv *priv;
	struct ieee80211_hw *hw;
3499
	u16 num_mac;
3500 3501 3502 3503 3504 3505 3506 3507
	u32 hw_rev;

	/************************
	 * 1. Allocating HW data
	 ************************/
	hw = iwl_alloc_all(cfg);
	if (!hw) {
		err = -ENOMEM;
3508 3509 3510
		goto out;
	}

3511
	priv = hw->priv;
3512 3513 3514 3515

	priv->bus.priv = priv;
	priv->bus.bus_specific = bus_specific;
	priv->bus.ops = bus_ops;
3516
	priv->bus.irq = priv->bus.ops->get_irq(&priv->bus);
3517
	priv->bus.ops->set_drv_data(&priv->bus, priv);
3518
	priv->bus.dev = priv->bus.ops->get_dev(&priv->bus);
3519

3520 3521
	iwl_trans_register(&priv->trans);

3522
	/* At this point both hw and priv are allocated. */
3523

3524
	SET_IEEE80211_DEV(hw, priv->bus.dev);
Z
Zhu Yi 已提交
3525

3526
	IWL_DEBUG_INFO(priv, "*** LOAD DRIVER ***\n");
T
Tomas Winkler 已提交
3527
	priv->cfg = cfg;
3528
	priv->inta_mask = CSR_INI_SET_MASK;
3529

3530 3531 3532 3533 3534
	/* is antenna coupling more than 35dB ? */
	priv->bt_ant_couple_ok =
		(iwlagn_ant_coupling > IWL_BT_ANTENNA_COUPLING_THRESHOLD) ?
		true : false;

3535
	/* enable/disable bt channel inhibition */
3536
	priv->bt_ch_announce = iwlagn_bt_ch_announce;
3537 3538
	IWL_DEBUG_INFO(priv, "BT channel inhibition is %s\n",
		       (priv->bt_ch_announce) ? "On" : "Off");
3539

3540 3541
	if (iwl_alloc_traffic_mem(priv))
		IWL_ERR(priv, "Not enough memory to generate traffic log\n");
Z
Zhu Yi 已提交
3542

3543

3544
	/* these spin locks will be used in apm_ops.init and EEPROM access
M
Mohamed Abbas 已提交
3545 3546 3547
	 * we should init now
	 */
	spin_lock_init(&priv->reg_lock);
3548
	spin_lock_init(&priv->lock);
3549 3550 3551 3552 3553 3554 3555 3556

	/*
	 * stop and reset the on-board processor just in case it is in a
	 * strange state ... like being left stranded by a primary kernel
	 * and this is now the kdump kernel trying to start up
	 */
	iwl_write32(priv, CSR_RESET, CSR_RESET_REG_FLAG_NEVO_RESET);

3557 3558 3559
	/***********************
	 * 3. Read REV register
	 ***********************/
J
Johannes Berg 已提交
3560
	hw_rev = iwl_hw_detect(priv);
3561
	IWL_INFO(priv, "Detected %s, REV=0x%X\n",
J
Johannes Berg 已提交
3562
		priv->cfg->name, hw_rev);
3563

J
Johannes Berg 已提交
3564
	if (iwl_prepare_card_hw(priv)) {
3565
		err = -EIO;
M
Mohamed Abbas 已提交
3566
		IWL_WARN(priv, "Failed, HW not ready\n");
3567
		goto out_free_traffic_mem;
M
Mohamed Abbas 已提交
3568 3569
	}

T
Tomas Winkler 已提交
3570 3571 3572
	/*****************
	 * 4. Read EEPROM
	 *****************/
3573
	/* Read the EEPROM */
J
Johannes Berg 已提交
3574
	err = iwl_eeprom_init(priv, hw_rev);
3575
	if (err) {
3576
		IWL_ERR(priv, "Unable to init EEPROM\n");
3577
		goto out_free_traffic_mem;
3578
	}
3579 3580
	err = iwl_eeprom_check_version(priv);
	if (err)
3581
		goto out_free_eeprom;
3582

3583 3584 3585 3586
	err = iwl_eeprom_check_sku(priv);
	if (err)
		goto out_free_eeprom;

3587
	/* extract MAC Address */
3588 3589 3590 3591 3592 3593 3594 3595 3596 3597 3598
	iwl_eeprom_get_mac(priv, priv->addresses[0].addr);
	IWL_DEBUG_INFO(priv, "MAC address: %pM\n", priv->addresses[0].addr);
	priv->hw->wiphy->addresses = priv->addresses;
	priv->hw->wiphy->n_addresses = 1;
	num_mac = iwl_eeprom_query16(priv, EEPROM_NUM_MAC_ADDRESS);
	if (num_mac > 1) {
		memcpy(priv->addresses[1].addr, priv->addresses[0].addr,
		       ETH_ALEN);
		priv->addresses[1].addr[5]++;
		priv->hw->wiphy->n_addresses++;
	}
3599

3600 3601 3602
	/* initialize all valid contexts */
	iwl_init_context(priv);

3603 3604 3605
	/************************
	 * 5. Setup HW constants
	 ************************/
3606
	if (iwl_set_hw_params(priv)) {
3607
		err = -ENOENT;
3608
		IWL_ERR(priv, "failed to set hw parameters\n");
3609
		goto out_free_eeprom;
3610 3611 3612
	}

	/*******************
T
Tomas Winkler 已提交
3613
	 * 6. Setup priv
3614
	 *******************/
Z
Zhu Yi 已提交
3615

T
Tomas Winkler 已提交
3616
	err = iwl_init_drv(priv);
3617
	if (err)
R
Ron Rindjunsky 已提交
3618
		goto out_free_eeprom;
3619
	/* At this point both hw and priv are initialized. */
3620 3621

	/********************
3622
	 * 7. Setup services
3623
	 ********************/
J
Johannes Berg 已提交
3624
	iwl_alloc_isr_ict(priv);
3625

3626 3627
	err = request_irq(priv->bus.irq, iwl_isr_ict, IRQF_SHARED,
			  DRV_NAME, priv);
3628
	if (err) {
3629
		IWL_ERR(priv, "Error allocating IRQ %d\n", priv->bus.irq);
3630
		goto out_uninit_drv;
3631
	}
3632

3633
	iwl_setup_deferred_work(priv);
3634
	iwl_setup_rx_handlers(priv);
3635
	iwl_testmode_init(priv);
3636

J
Johannes Berg 已提交
3637
	/*********************************************
3638
	 * 8. Enable interrupts
J
Johannes Berg 已提交
3639
	 *********************************************/
T
Tomas Winkler 已提交
3640

3641
	iwl_enable_rfkill_int(priv);
3642 3643 3644 3645 3646 3647

	/* If platform's RF_KILL switch is NOT set to KILL */
	if (iwl_read32(priv, CSR_GP_CNTRL) & CSR_GP_CNTRL_REG_FLAG_HW_RF_KILL_SW)
		clear_bit(STATUS_RF_KILL_HW, &priv->status);
	else
		set_bit(STATUS_RF_KILL_HW, &priv->status);
T
Tomas Winkler 已提交
3648

J
Johannes Berg 已提交
3649 3650
	wiphy_rfkill_set_hw_state(priv->hw->wiphy,
		test_bit(STATUS_RF_KILL_HW, &priv->status));
3651

3652
	iwl_power_initialize(priv);
3653
	iwl_tt_initialize(priv);
J
Johannes Berg 已提交
3654

3655
	init_completion(&priv->_agn.firmware_loading_complete);
3656

3657
	err = iwl_request_firmware(priv, true);
J
Johannes Berg 已提交
3658
	if (err)
3659
		goto out_destroy_workqueue;
J
Johannes Berg 已提交
3660

Z
Zhu Yi 已提交
3661 3662
	return 0;

3663
 out_destroy_workqueue:
3664 3665
	destroy_workqueue(priv->workqueue);
	priv->workqueue = NULL;
3666
	free_irq(priv->bus.irq, priv);
3667
	iwl_free_isr_ict(priv);
3668
 out_uninit_drv:
T
Tomas Winkler 已提交
3669
	iwl_uninit_drv(priv);
3670 3671
 out_free_eeprom:
	iwl_eeprom_free(priv);
3672
 out_free_traffic_mem:
3673
	iwl_free_traffic_mem(priv);
3674
	ieee80211_free_hw(priv->hw);
Z
Zhu Yi 已提交
3675 3676 3677 3678
 out:
	return err;
}

3679
void __devexit iwl_remove(struct iwl_priv * priv)
Z
Zhu Yi 已提交
3680
{
3681
	unsigned long flags;
Z
Zhu Yi 已提交
3682

3683
	wait_for_completion(&priv->_agn.firmware_loading_complete);
3684

3685
	IWL_DEBUG_INFO(priv, "*** UNLOAD DRIVER ***\n");
Z
Zhu Yi 已提交
3686

3687
	iwl_dbgfs_unregister(priv);
3688 3689
	sysfs_remove_group(&priv->bus.dev->kobj,
			   &iwl_attribute_group);
3690

3691 3692
	/* ieee80211_unregister_hw call wil cause iwl_mac_stop to
	 * to be called and iwl_down since we are removing the device
3693 3694 3695
	 * we need to set STATUS_EXIT_PENDING bit.
	 */
	set_bit(STATUS_EXIT_PENDING, &priv->status);
3696

W
Wey-Yi Guy 已提交
3697
	iwl_testmode_cleanup(priv);
3698 3699
	iwl_leds_exit(priv);

3700 3701 3702 3703 3704
	if (priv->mac80211_registered) {
		ieee80211_unregister_hw(priv->hw);
		priv->mac80211_registered = 0;
	}

J
Johannes Berg 已提交
3705
	/* Reset to low power before unloading driver. */
J
Johannes Berg 已提交
3706
	iwl_apm_stop(priv);
3707

3708 3709
	iwl_tt_exit(priv);

3710 3711 3712 3713
	/* make sure we flush any pending irq or
	 * tasklet for the driver
	 */
	spin_lock_irqsave(&priv->lock, flags);
3714
	iwl_disable_interrupts(priv);
3715 3716 3717 3718
	spin_unlock_irqrestore(&priv->lock, flags);

	iwl_synchronize_irq(priv);

3719
	iwl_dealloc_ucode(priv);
Z
Zhu Yi 已提交
3720 3721

	if (priv->rxq.bd)
3722
		iwlagn_rx_queue_free(priv, &priv->rxq);
3723
	iwlagn_hw_txq_ctx_free(priv);
Z
Zhu Yi 已提交
3724

3725
	iwl_eeprom_free(priv);
Z
Zhu Yi 已提交
3726 3727


M
Mohamed Abbas 已提交
3728 3729 3730
	/*netif_stop_queue(dev); */
	flush_workqueue(priv->workqueue);

3731
	/* ieee80211_unregister_hw calls iwl_mac_stop, which flushes
Z
Zhu Yi 已提交
3732 3733 3734 3735
	 * priv->workqueue... so we can't take down the workqueue
	 * until now... */
	destroy_workqueue(priv->workqueue);
	priv->workqueue = NULL;
3736
	iwl_free_traffic_mem(priv);
Z
Zhu Yi 已提交
3737

3738
	free_irq(priv->bus.irq, priv);
3739
	priv->bus.ops->set_drv_data(&priv->bus, NULL);
Z
Zhu Yi 已提交
3740

T
Tomas Winkler 已提交
3741
	iwl_uninit_drv(priv);
Z
Zhu Yi 已提交
3742

J
Johannes Berg 已提交
3743
	iwl_free_isr_ict(priv);
M
Mohamed Abbas 已提交
3744

3745
	dev_kfree_skb(priv->beacon_skb);
Z
Zhu Yi 已提交
3746 3747 3748 3749 3750 3751 3752 3753 3754 3755

	ieee80211_free_hw(priv->hw);
}


/*****************************************************************************
 *
 * driver and module entry point
 *
 *****************************************************************************/
3756
static int __init iwl_init(void)
Z
Zhu Yi 已提交
3757 3758 3759
{

	int ret;
3760 3761
	pr_info(DRV_DESCRIPTION ", " DRV_VERSION "\n");
	pr_info(DRV_COPYRIGHT "\n");
3762

3763
	ret = iwlagn_rate_control_register();
3764
	if (ret) {
3765
		pr_err("Unable to register rate control algorithm: %d\n", ret);
3766 3767 3768
		return ret;
	}

3769
	ret = iwl_pci_register_driver();
Z
Zhu Yi 已提交
3770

3771 3772
	if (ret)
		goto error_register;
Z
Zhu Yi 已提交
3773
	return ret;
3774 3775

error_register:
3776
	iwlagn_rate_control_unregister();
3777
	return ret;
Z
Zhu Yi 已提交
3778 3779
}

3780
static void __exit iwl_exit(void)
Z
Zhu Yi 已提交
3781
{
3782
	iwl_pci_unregister_driver();
3783
	iwlagn_rate_control_unregister();
Z
Zhu Yi 已提交
3784 3785
}

3786 3787
module_exit(iwl_exit);
module_init(iwl_init);
3788 3789

#ifdef CONFIG_IWLWIFI_DEBUG
3790
module_param_named(debug, iwl_debug_level, uint, S_IRUGO | S_IWUSR);
3791 3792 3793
MODULE_PARM_DESC(debug, "debug output mask");
#endif

3794 3795 3796 3797 3798 3799 3800 3801 3802 3803 3804
module_param_named(swcrypto, iwlagn_mod_params.sw_crypto, int, S_IRUGO);
MODULE_PARM_DESC(swcrypto, "using crypto in software (default 0 [hardware])");
module_param_named(queues_num, iwlagn_mod_params.num_of_queues, int, S_IRUGO);
MODULE_PARM_DESC(queues_num, "number of hw queues.");
module_param_named(11n_disable, iwlagn_mod_params.disable_11n, int, S_IRUGO);
MODULE_PARM_DESC(11n_disable, "disable 11n functionality");
module_param_named(amsdu_size_8K, iwlagn_mod_params.amsdu_size_8K,
		   int, S_IRUGO);
MODULE_PARM_DESC(amsdu_size_8K, "enable 8K amsdu size");
module_param_named(fw_restart, iwlagn_mod_params.restart_fw, int, S_IRUGO);
MODULE_PARM_DESC(fw_restart, "restart firmware in case of error");
3805 3806 3807 3808 3809

module_param_named(ucode_alternative, iwlagn_wanted_ucode_alternative, int,
		   S_IRUGO);
MODULE_PARM_DESC(ucode_alternative,
		 "specify ucode alternative to use from ucode file");
3810 3811 3812 3813

module_param_named(antenna_coupling, iwlagn_ant_coupling, int, S_IRUGO);
MODULE_PARM_DESC(antenna_coupling,
		 "specify antenna coupling in dB (defualt: 0 dB)");
3814

3815 3816 3817
module_param_named(bt_ch_inhibition, iwlagn_bt_ch_announce, bool, S_IRUGO);
MODULE_PARM_DESC(bt_ch_inhibition,
		 "Disable BT channel inhibition (default: enable)");
3818 3819 3820 3821 3822 3823

module_param_named(plcp_check, iwlagn_mod_params.plcp_check, bool, S_IRUGO);
MODULE_PARM_DESC(plcp_check, "Check plcp health (default: 1 [enabled])");

module_param_named(ack_check, iwlagn_mod_params.ack_check, bool, S_IRUGO);
MODULE_PARM_DESC(ack_check, "Check ack health (default: 0 [disabled])");
3824

3825 3826 3827 3828
module_param_named(wd_disable, iwlagn_mod_params.wd_disable, bool, S_IRUGO);
MODULE_PARM_DESC(wd_disable,
		"Disable stuck queue watchdog timer (default: 0 [enabled])");

3829 3830 3831 3832 3833 3834 3835 3836 3837 3838 3839 3840 3841 3842 3843 3844 3845 3846 3847
/*
 * set bt_coex_active to true, uCode will do kill/defer
 * every time the priority line is asserted (BT is sending signals on the
 * priority line in the PCIx).
 * set bt_coex_active to false, uCode will ignore the BT activity and
 * perform the normal operation
 *
 * User might experience transmit issue on some platform due to WiFi/BT
 * co-exist problem. The possible behaviors are:
 *   Able to scan and finding all the available AP
 *   Not able to associate with any AP
 * On those platforms, WiFi communication can be restored by set
 * "bt_coex_active" module parameter to "false"
 *
 * default: bt_coex_active = true (BT_COEX_ENABLE)
 */
module_param_named(bt_coex_active, iwlagn_mod_params.bt_coex_active,
		bool, S_IRUGO);
MODULE_PARM_DESC(bt_coex_active, "enable wifi/bt co-exist (default: enable)");
3848 3849 3850 3851

module_param_named(led_mode, iwlagn_mod_params.led_mode, int, S_IRUGO);
MODULE_PARM_DESC(led_mode, "0=system default, "
		"1=On(RF On)/Off(RF Off), 2=blinking (default: 0)");
3852

3853 3854 3855 3856 3857
module_param_named(power_save, iwlagn_mod_params.power_save,
		bool, S_IRUGO);
MODULE_PARM_DESC(power_save,
		 "enable WiFi power management (default: disable)");

3858 3859 3860 3861 3862
module_param_named(power_level, iwlagn_mod_params.power_level,
		int, S_IRUGO);
MODULE_PARM_DESC(power_level,
		 "default power save level (range from 1 - 5, default: 1)");

3863 3864 3865 3866 3867 3868 3869 3870 3871
/*
 * For now, keep using power level 1 instead of automatically
 * adjusting ...
 */
module_param_named(no_sleep_autoadjust, iwlagn_mod_params.no_sleep_autoadjust,
		bool, S_IRUGO);
MODULE_PARM_DESC(no_sleep_autoadjust,
		 "don't automatically adjust sleep level "
		 "according to maximum network latency (default: true)");