scan.c 26.9 KB
Newer Older
1
/*
2 3
 * Scanning implementation
 *
4 5 6 7 8 9 10 11 12 13 14 15
 * Copyright 2003, Jouni Malinen <jkmaline@cc.hut.fi>
 * Copyright 2004, Instant802 Networks, Inc.
 * Copyright 2005, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
 * Copyright 2007, Michael Wu <flamingice@sourmilk.net>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#include <linux/if_arp.h>
16
#include <linux/etherdevice.h>
17
#include <linux/rtnetlink.h>
18
#include <linux/pm_qos.h>
19
#include <net/sch_generic.h>
20
#include <linux/slab.h>
21
#include <linux/export.h>
22 23 24
#include <net/mac80211.h>

#include "ieee80211_i.h"
25
#include "driver-ops.h"
26
#include "mesh.h"
27 28 29

#define IEEE80211_PROBE_DELAY (HZ / 33)
#define IEEE80211_CHANNEL_TIME (HZ / 33)
30
#define IEEE80211_PASSIVE_CHANNEL_TIME (HZ / 8)
31

32
static void ieee80211_rx_bss_free(struct cfg80211_bss *cbss)
33
{
34
	struct ieee80211_bss *bss = (void *)cbss->priv;
35 36 37 38 39 40

	kfree(bss_mesh_id(bss));
	kfree(bss_mesh_cfg(bss));
}

void ieee80211_rx_bss_put(struct ieee80211_local *local,
41
			  struct ieee80211_bss *bss)
42
{
43 44 45
	if (!bss)
		return;
	cfg80211_put_bss(container_of((void *)bss, struct cfg80211_bss, priv));
46 47
}

K
Kalle Valo 已提交
48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64
static bool is_uapsd_supported(struct ieee802_11_elems *elems)
{
	u8 qos_info;

	if (elems->wmm_info && elems->wmm_info_len == 7
	    && elems->wmm_info[5] == 1)
		qos_info = elems->wmm_info[6];
	else if (elems->wmm_param && elems->wmm_param_len == 24
		 && elems->wmm_param[5] == 1)
		qos_info = elems->wmm_param[6];
	else
		/* no valid wmm information or parameter element found */
		return false;

	return qos_info & IEEE80211_WMM_IE_AP_QOSINFO_UAPSD;
}

65
struct ieee80211_bss *
66 67 68 69 70
ieee80211_bss_info_update(struct ieee80211_local *local,
			  struct ieee80211_rx_status *rx_status,
			  struct ieee80211_mgmt *mgmt,
			  size_t len,
			  struct ieee802_11_elems *elems,
71 72
			  struct ieee80211_channel *channel,
			  bool beacon)
73
{
74
	struct cfg80211_bss *cbss;
75
	struct ieee80211_bss *bss;
76
	int clen, srlen;
77 78
	s32 signal = 0;

J
Johannes Berg 已提交
79
	if (local->hw.flags & IEEE80211_HW_SIGNAL_DBM)
80
		signal = rx_status->signal * 100;
J
Johannes Berg 已提交
81
	else if (local->hw.flags & IEEE80211_HW_SIGNAL_UNSPEC)
82 83
		signal = (rx_status->signal * 100) / local->hw.max_signal;

84 85 86
	cbss = cfg80211_inform_bss_frame(local->hw.wiphy, channel,
					 mgmt, len, signal, GFP_ATOMIC);
	if (!cbss)
87 88
		return NULL;

89 90
	cbss->free_priv = ieee80211_rx_bss_free;
	bss = (void *)cbss->priv;
91

92 93
	bss->device_ts = rx_status->device_timestamp;

P
Paul Stewart 已提交
94 95 96 97 98 99 100 101 102 103 104 105
	if (elems->parse_error) {
		if (beacon)
			bss->corrupt_data |= IEEE80211_BSS_CORRUPT_BEACON;
		else
			bss->corrupt_data |= IEEE80211_BSS_CORRUPT_PROBE_RESP;
	} else {
		if (beacon)
			bss->corrupt_data &= ~IEEE80211_BSS_CORRUPT_BEACON;
		else
			bss->corrupt_data &= ~IEEE80211_BSS_CORRUPT_PROBE_RESP;
	}

106
	/* save the ERP value so that it is available at association time */
P
Paul Stewart 已提交
107 108 109
	if (elems->erp_info && elems->erp_info_len >= 1 &&
			(!elems->parse_error ||
			 !(bss->valid_data & IEEE80211_BSS_VALID_ERP))) {
110
		bss->erp_value = elems->erp_info[0];
111
		bss->has_erp_value = true;
P
Paul Stewart 已提交
112 113
		if (!elems->parse_error)
			bss->valid_data |= IEEE80211_BSS_VALID_ERP;
114 115
	}

116
	/* replace old supported rates if we get new values */
P
Paul Stewart 已提交
117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139
	if (!elems->parse_error ||
	    !(bss->valid_data & IEEE80211_BSS_VALID_RATES)) {
		srlen = 0;
		if (elems->supp_rates) {
			clen = IEEE80211_MAX_SUPP_RATES;
			if (clen > elems->supp_rates_len)
				clen = elems->supp_rates_len;
			memcpy(bss->supp_rates, elems->supp_rates, clen);
			srlen += clen;
		}
		if (elems->ext_supp_rates) {
			clen = IEEE80211_MAX_SUPP_RATES - srlen;
			if (clen > elems->ext_supp_rates_len)
				clen = elems->ext_supp_rates_len;
			memcpy(bss->supp_rates + srlen, elems->ext_supp_rates,
			       clen);
			srlen += clen;
		}
		if (srlen) {
			bss->supp_rates_len = srlen;
			if (!elems->parse_error)
				bss->valid_data |= IEEE80211_BSS_VALID_RATES;
		}
140 141
	}

P
Paul Stewart 已提交
142 143 144 145 146 147 148
	if (!elems->parse_error ||
	    !(bss->valid_data & IEEE80211_BSS_VALID_WMM)) {
		bss->wmm_used = elems->wmm_param || elems->wmm_info;
		bss->uapsd_supported = is_uapsd_supported(elems);
		if (!elems->parse_error)
			bss->valid_data |= IEEE80211_BSS_VALID_WMM;
	}
149 150 151 152 153 154

	if (!beacon)
		bss->last_probe_resp = jiffies;

	return bss;
}
155

J
Johannes Berg 已提交
156
void ieee80211_scan_rx(struct ieee80211_local *local, struct sk_buff *skb)
157
{
158
	struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
J
Johannes Berg 已提交
159 160
	struct ieee80211_sub_if_data *sdata1, *sdata2;
	struct ieee80211_mgmt *mgmt = (void *)skb->data;
161
	struct ieee80211_bss *bss;
162 163 164
	u8 *elements;
	struct ieee80211_channel *channel;
	size_t baselen;
J
Johannes Berg 已提交
165
	bool beacon;
166 167
	struct ieee802_11_elems elems;

J
Johannes Berg 已提交
168 169 170 171
	if (skb->len < 24 ||
	    (!ieee80211_is_probe_resp(mgmt->frame_control) &&
	     !ieee80211_is_beacon(mgmt->frame_control)))
		return;
172

J
Johannes Berg 已提交
173 174
	sdata1 = rcu_dereference(local->scan_sdata);
	sdata2 = rcu_dereference(local->sched_scan_sdata);
175

J
Johannes Berg 已提交
176 177
	if (likely(!sdata1 && !sdata2))
		return;
178

J
Johannes Berg 已提交
179
	if (ieee80211_is_probe_resp(mgmt->frame_control)) {
180
		/* ignore ProbeResp to foreign address */
J
Johannes Berg 已提交
181 182 183
		if ((!sdata1 || !ether_addr_equal(mgmt->da, sdata1->vif.addr)) &&
		    (!sdata2 || !ether_addr_equal(mgmt->da, sdata2->vif.addr)))
			return;
184 185 186

		elements = mgmt->u.probe_resp.variable;
		baselen = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
J
Johannes Berg 已提交
187
		beacon = false;
188 189 190
	} else {
		baselen = offsetof(struct ieee80211_mgmt, u.beacon.variable);
		elements = mgmt->u.beacon.variable;
J
Johannes Berg 已提交
191
		beacon = true;
192 193 194
	}

	if (baselen > skb->len)
J
Johannes Berg 已提交
195
		return;
196 197 198

	ieee802_11_parse_elems(elements, skb->len - baselen, &elems);

199
	channel = ieee80211_get_channel(local->hw.wiphy, rx_status->freq);
200 201

	if (!channel || channel->flags & IEEE80211_CHAN_DISABLED)
J
Johannes Berg 已提交
202
		return;
203

J
Johannes Berg 已提交
204
	bss = ieee80211_bss_info_update(local, rx_status,
205
					mgmt, skb->len, &elems,
206
					channel, beacon);
207
	if (bss)
J
Johannes Berg 已提交
208
		ieee80211_rx_bss_put(local, bss);
209 210
}

211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237
/* return false if no more work */
static bool ieee80211_prep_hw_scan(struct ieee80211_local *local)
{
	struct cfg80211_scan_request *req = local->scan_req;
	enum ieee80211_band band;
	int i, ielen, n_chans;

	do {
		if (local->hw_scan_band == IEEE80211_NUM_BANDS)
			return false;

		band = local->hw_scan_band;
		n_chans = 0;
		for (i = 0; i < req->n_channels; i++) {
			if (req->channels[i]->band == band) {
				local->hw_scan_req->channels[n_chans] =
							req->channels[i];
				n_chans++;
			}
		}

		local->hw_scan_band++;
	} while (!n_chans);

	local->hw_scan_req->n_channels = n_chans;

	ielen = ieee80211_build_preq_ies(local, (u8 *)local->hw_scan_req->ie,
238
					 local->hw_scan_ies_bufsize,
239
					 req->ie, req->ie_len, band,
240
					 req->rates[band], 0);
241
	local->hw_scan_req->ie_len = ielen;
242
	local->hw_scan_req->no_cck = req->no_cck;
243 244 245 246

	return true;
}

247
static void __ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted,
248
				       bool was_hw_scan)
249 250 251
{
	struct ieee80211_local *local = hw_to_local(hw);

252
	lockdep_assert_held(&local->mtx);
253

254 255 256 257 258 259 260 261
	/*
	 * It's ok to abort a not-yet-running scan (that
	 * we have one at all will be verified by checking
	 * local->scan_req next), but not to complete it
	 * successfully.
	 */
	if (WARN_ON(!local->scanning && !aborted))
		aborted = true;
262

263
	if (WARN_ON(!local->scan_req))
264
		return;
265

266
	if (was_hw_scan && !aborted && ieee80211_prep_hw_scan(local)) {
267 268 269 270 271 272 273
		int rc;

		rc = drv_hw_scan(local,
			rcu_dereference_protected(local->scan_sdata,
						  lockdep_is_held(&local->mtx)),
			local->hw_scan_req);

274
		if (rc == 0)
275
			return;
276 277 278 279
	}

	kfree(local->hw_scan_req);
	local->hw_scan_req = NULL;
280

281
	if (local->scan_req != local->int_scan_req)
282 283
		cfg80211_scan_done(local->scan_req, aborted);
	local->scan_req = NULL;
284
	rcu_assign_pointer(local->scan_sdata, NULL);
285

286
	local->scanning = 0;
J
Johannes Berg 已提交
287
	local->scan_channel = NULL;
288

289 290
	/* Set power back to normal operating levels. */
	ieee80211_hw_config(local, 0);
291

292 293 294
	if (!was_hw_scan) {
		ieee80211_configure_filter(local);
		drv_sw_scan_complete(local);
295
		ieee80211_offchannel_return(local, true);
296
	}
297

J
Johannes Berg 已提交
298
	ieee80211_recalc_idle(local);
299

300
	ieee80211_mlme_notify_scan_completed(local);
301
	ieee80211_ibss_notify_scan_completed(local);
302
	ieee80211_mesh_notify_scan_completed(local);
303
	ieee80211_start_next_roc(local);
304
}
305 306 307 308 309 310 311 312 313 314 315 316

void ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_scan_completed(local, aborted);

	set_bit(SCAN_COMPLETED, &local->scanning);
	if (aborted)
		set_bit(SCAN_ABORTED, &local->scanning);
	ieee80211_queue_delayed_work(&local->hw, &local->scan_work, 0);
}
317 318
EXPORT_SYMBOL(ieee80211_scan_completed);

319 320
static int ieee80211_start_sw_scan(struct ieee80211_local *local)
{
321 322 323 324
	/* Software scan is not supported in multi-channel cases */
	if (local->use_chanctx)
		return -EOPNOTSUPP;

325 326 327 328 329 330 331 332 333 334 335 336 337
	/*
	 * Hardware/driver doesn't support hw_scan, so use software
	 * scanning instead. First send a nullfunc frame with power save
	 * bit on so that AP will buffer the frames for us while we are not
	 * listening, then send probe requests to each channel and wait for
	 * the responses. After all channels are scanned, tune back to the
	 * original channel and send a nullfunc frame with power save bit
	 * off to trigger the AP to send us all the buffered frames.
	 *
	 * Note that while local->sw_scanning is true everything else but
	 * nullfunc frames and probe requests will be dropped in
	 * ieee80211_tx_h_check_assoc().
	 */
338
	drv_sw_scan_start(local);
339

340
	local->leave_oper_channel_time = jiffies;
341
	local->next_scan_state = SCAN_DECISION;
342 343
	local->scan_channel_idx = 0;

344
	ieee80211_offchannel_stop_vifs(local, true);
345

346
	ieee80211_configure_filter(local);
347

348 349 350
	/* We need to set power level at maximum rate for scanning. */
	ieee80211_hw_config(local, 0);

351
	ieee80211_queue_delayed_work(&local->hw,
352
				     &local->scan_work, 0);
353 354 355 356

	return 0;
}

357 358 359
static bool ieee80211_can_scan(struct ieee80211_local *local,
			       struct ieee80211_sub_if_data *sdata)
{
360
	if (!list_empty(&local->roc_list))
361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377
		return false;

	if (sdata->vif.type == NL80211_IFTYPE_STATION &&
	    sdata->u.mgd.flags & (IEEE80211_STA_BEACON_POLL |
				  IEEE80211_STA_CONNECTION_POLL))
		return false;

	return true;
}

void ieee80211_run_deferred_scan(struct ieee80211_local *local)
{
	lockdep_assert_held(&local->mtx);

	if (!local->scan_req || local->scanning)
		return;

378 379 380 381
	if (!ieee80211_can_scan(local,
				rcu_dereference_protected(
					local->scan_sdata,
					lockdep_is_held(&local->mtx))))
382 383 384 385 386
		return;

	ieee80211_queue_delayed_work(&local->hw, &local->scan_work,
				     round_jiffies_relative(0));
}
387

388 389 390 391
static void ieee80211_scan_state_send_probe(struct ieee80211_local *local,
					    unsigned long *next_delay)
{
	int i;
392
	struct ieee80211_sub_if_data *sdata;
393 394
	enum ieee80211_band band = local->hw.conf.channel->band;

395
	sdata = rcu_dereference_protected(local->scan_sdata,
396
					  lockdep_is_held(&local->mtx));
397

398 399 400 401 402 403 404
	for (i = 0; i < local->scan_req->n_ssids; i++)
		ieee80211_send_probe_req(
			sdata, NULL,
			local->scan_req->ssids[i].ssid,
			local->scan_req->ssids[i].ssid_len,
			local->scan_req->ie, local->scan_req->ie_len,
			local->scan_req->rates[band], false,
405
			local->scan_req->no_cck,
J
Johannes Berg 已提交
406
			local->hw.conf.channel, true);
407 408 409 410 411 412 413 414 415

	/*
	 * After sending probe requests, wait for probe responses
	 * on the channel.
	 */
	*next_delay = IEEE80211_CHANNEL_TIME;
	local->next_scan_state = SCAN_DECISION;
}

416 417 418 419 420 421
static int __ieee80211_start_scan(struct ieee80211_sub_if_data *sdata,
				  struct cfg80211_scan_request *req)
{
	struct ieee80211_local *local = sdata->local;
	int rc;

422 423
	lockdep_assert_held(&local->mtx);

424 425 426
	if (local->scan_req)
		return -EBUSY;

427
	if (!ieee80211_can_scan(local, sdata)) {
428
		/* wait for the work to finish/time out */
429
		local->scan_req = req;
430
		rcu_assign_pointer(local->scan_sdata, sdata);
431 432 433
		return 0;
	}

434 435 436
	if (local->ops->hw_scan) {
		u8 *ies;

437 438 439
		local->hw_scan_ies_bufsize = 2 + IEEE80211_MAX_SSID_LEN +
					     local->scan_ies_len +
					     req->ie_len;
440 441 442
		local->hw_scan_req = kmalloc(
				sizeof(*local->hw_scan_req) +
				req->n_channels * sizeof(req->channels[0]) +
443
				local->hw_scan_ies_bufsize, GFP_KERNEL);
444
		if (!local->hw_scan_req)
445 446
			return -ENOMEM;

447 448 449 450 451 452
		local->hw_scan_req->ssids = req->ssids;
		local->hw_scan_req->n_ssids = req->n_ssids;
		ies = (u8 *)local->hw_scan_req +
			sizeof(*local->hw_scan_req) +
			req->n_channels * sizeof(req->channels[0]);
		local->hw_scan_req->ie = ies;
453
		local->hw_scan_req->flags = req->flags;
454 455

		local->hw_scan_band = 0;
456 457 458 459 460 461 462 463

		/*
		 * After allocating local->hw_scan_req, we must
		 * go through until ieee80211_prep_hw_scan(), so
		 * anything that might be changed here and leave
		 * this function early must not go after this
		 * allocation.
		 */
464 465 466
	}

	local->scan_req = req;
467
	rcu_assign_pointer(local->scan_sdata, sdata);
468

469
	if (local->ops->hw_scan) {
470
		__set_bit(SCAN_HW_SCANNING, &local->scanning);
471
	} else if ((req->n_channels == 1) &&
J
Johannes Berg 已提交
472
		   (req->channels[0] == local->_oper_channel)) {
473 474 475
		/*
		 * If we are scanning only on the operating channel
		 * then we do not need to stop normal activities
476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506
		 */
		unsigned long next_delay;

		__set_bit(SCAN_ONCHANNEL_SCANNING, &local->scanning);

		ieee80211_recalc_idle(local);

		/* Notify driver scan is starting, keep order of operations
		 * same as normal software scan, in case that matters. */
		drv_sw_scan_start(local);

		ieee80211_configure_filter(local); /* accept probe-responses */

		/* We need to ensure power level is at max for scanning. */
		ieee80211_hw_config(local, 0);

		if ((req->channels[0]->flags &
		     IEEE80211_CHAN_PASSIVE_SCAN) ||
		    !local->scan_req->n_ssids) {
			next_delay = IEEE80211_PASSIVE_CHANNEL_TIME;
		} else {
			ieee80211_scan_state_send_probe(local, &next_delay);
			next_delay = IEEE80211_CHANNEL_TIME;
		}

		/* Now, just wait a bit and we are all done! */
		ieee80211_queue_delayed_work(&local->hw, &local->scan_work,
					     next_delay);
		return 0;
	} else {
		/* Do normal software scan */
507
		__set_bit(SCAN_SW_SCANNING, &local->scanning);
508
	}
509

J
Johannes Berg 已提交
510
	ieee80211_recalc_idle(local);
511

512 513
	if (local->ops->hw_scan) {
		WARN_ON(!ieee80211_prep_hw_scan(local));
514
		rc = drv_hw_scan(local, sdata, local->hw_scan_req);
515
	} else
516 517 518
		rc = ieee80211_start_sw_scan(local);

	if (rc) {
519 520
		kfree(local->hw_scan_req);
		local->hw_scan_req = NULL;
521
		local->scanning = 0;
522

J
Johannes Berg 已提交
523 524
		ieee80211_recalc_idle(local);

525
		local->scan_req = NULL;
526
		rcu_assign_pointer(local->scan_sdata, NULL);
527 528 529 530 531
	}

	return rc;
}

532 533 534 535 536 537 538 539 540 541 542 543
static unsigned long
ieee80211_scan_get_channel_time(struct ieee80211_channel *chan)
{
	/*
	 * TODO: channel switching also consumes quite some time,
	 * add that delay as well to get a better estimation
	 */
	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
		return IEEE80211_PASSIVE_CHANNEL_TIME;
	return IEEE80211_PROBE_DELAY + IEEE80211_CHANNEL_TIME;
}

544 545
static void ieee80211_scan_state_decision(struct ieee80211_local *local,
					  unsigned long *next_delay)
H
Helmut Schaa 已提交
546
{
547
	bool associated = false;
548 549 550 551
	bool tx_empty = true;
	bool bad_latency;
	bool listen_int_exceeded;
	unsigned long min_beacon_int = 0;
552
	struct ieee80211_sub_if_data *sdata;
553
	struct ieee80211_channel *next_chan;
554
	enum mac80211_scan_state next_scan_state;
555

556 557 558 559 560
	/*
	 * check if at least one STA interface is associated,
	 * check if at least one STA interface has pending tx frames
	 * and grab the lowest used beacon interval
	 */
561 562
	mutex_lock(&local->iflist_mtx);
	list_for_each_entry(sdata, &local->interfaces, list) {
563
		if (!ieee80211_sdata_running(sdata))
564 565 566 567 568
			continue;

		if (sdata->vif.type == NL80211_IFTYPE_STATION) {
			if (sdata->u.mgd.associated) {
				associated = true;
569 570 571 572 573 574 575 576 577 578

				if (sdata->vif.bss_conf.beacon_int <
				    min_beacon_int || min_beacon_int == 0)
					min_beacon_int =
						sdata->vif.bss_conf.beacon_int;

				if (!qdisc_all_tx_empty(sdata->dev)) {
					tx_empty = false;
					break;
				}
579 580 581 582 583
			}
		}
	}
	mutex_unlock(&local->iflist_mtx);

584 585
	next_chan = local->scan_req->channels[local->scan_channel_idx];

586
	/*
587 588 589 590 591 592 593 594 595 596 597 598 599
	 * we're currently scanning a different channel, let's
	 * see if we can scan another channel without interfering
	 * with the current traffic situation.
	 *
	 * Since we don't know if the AP has pending frames for us
	 * we can only check for our tx queues and use the current
	 * pm_qos requirements for rx. Hence, if no tx traffic occurs
	 * at all we will scan as many channels in a row as the pm_qos
	 * latency allows us to. Additionally we also check for the
	 * currently negotiated listen interval to prevent losing
	 * frames unnecessarily.
	 *
	 * Otherwise switch back to the operating channel.
600 601
	 */

602 603 604 605
	bad_latency = time_after(jiffies +
			ieee80211_scan_get_channel_time(next_chan),
			local->leave_oper_channel_time +
			usecs_to_jiffies(pm_qos_request(PM_QOS_NETWORK_LATENCY)));
606

607 608 609 610 611
	listen_int_exceeded = time_after(jiffies +
			ieee80211_scan_get_channel_time(next_chan),
			local->leave_oper_channel_time +
			usecs_to_jiffies(min_beacon_int * 1024) *
			local->hw.conf.listen_interval);
612

613 614 615 616 617 618 619 620 621 622 623 624
	if (associated && !tx_empty) {
		if (local->scan_req->flags & NL80211_SCAN_FLAG_LOW_PRIORITY)
			next_scan_state = SCAN_ABORT;
		else
			next_scan_state = SCAN_SUSPEND;
	} else if (associated && (bad_latency || listen_int_exceeded)) {
		next_scan_state = SCAN_SUSPEND;
	} else {
		next_scan_state = SCAN_SET_CHANNEL;
	}

	local->next_scan_state = next_scan_state;
625

626
	*next_delay = 0;
627 628
}

629 630 631 632 633 634
static void ieee80211_scan_state_set_channel(struct ieee80211_local *local,
					     unsigned long *next_delay)
{
	int skip;
	struct ieee80211_channel *chan;

H
Helmut Schaa 已提交
635 636 637
	skip = 0;
	chan = local->scan_req->channels[local->scan_channel_idx];

J
Johannes Berg 已提交
638
	local->scan_channel = chan;
639

640 641
	if (ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL))
		skip = 1;
H
Helmut Schaa 已提交
642 643 644 645

	/* advance state machine to next channel/band */
	local->scan_channel_idx++;

646 647 648
	if (skip) {
		/* if we skip this channel return to the decision state */
		local->next_scan_state = SCAN_DECISION;
649
		return;
650
	}
H
Helmut Schaa 已提交
651 652 653 654 655 656 657 658 659 660 661 662 663 664

	/*
	 * Probe delay is used to update the NAV, cf. 11.1.3.2.2
	 * (which unfortunately doesn't say _why_ step a) is done,
	 * but it waits for the probe delay or until a frame is
	 * received - and the received frame would update the NAV).
	 * For now, we do not support waiting until a frame is
	 * received.
	 *
	 * In any case, it is not necessary for a passive scan.
	 */
	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN ||
	    !local->scan_req->n_ssids) {
		*next_delay = IEEE80211_PASSIVE_CHANNEL_TIME;
665
		local->next_scan_state = SCAN_DECISION;
666
		return;
H
Helmut Schaa 已提交
667 668
	}

669
	/* active scan, send probes */
H
Helmut Schaa 已提交
670
	*next_delay = IEEE80211_PROBE_DELAY;
671
	local->next_scan_state = SCAN_SEND_PROBE;
H
Helmut Schaa 已提交
672 673
}

674 675 676 677 678 679 680 681 682 683 684 685
static void ieee80211_scan_state_suspend(struct ieee80211_local *local,
					 unsigned long *next_delay)
{
	/* switch back to the operating channel */
	local->scan_channel = NULL;
	ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);

	/*
	 * Re-enable vifs and beaconing.  Leave PS
	 * in off-channel state..will put that back
	 * on-channel at the end of scanning.
	 */
686
	ieee80211_offchannel_return(local, false);
687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708

	*next_delay = HZ / 5;
	/* afterwards, resume scan & go to next channel */
	local->next_scan_state = SCAN_RESUME;
}

static void ieee80211_scan_state_resume(struct ieee80211_local *local,
					unsigned long *next_delay)
{
	/* PS already is in off-channel mode */
	ieee80211_offchannel_stop_vifs(local, false);

	if (local->ops->flush) {
		drv_flush(local, false);
		*next_delay = 0;
	} else
		*next_delay = HZ / 10;

	/* remember when we left the operating channel */
	local->leave_oper_channel_time = jiffies;

	/* advance to the next channel to be scanned */
709
	local->next_scan_state = SCAN_SET_CHANNEL;
710 711
}

712
void ieee80211_scan_work(struct work_struct *work)
713 714 715
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local, scan_work.work);
716
	struct ieee80211_sub_if_data *sdata;
717
	unsigned long next_delay = 0;
718
	bool aborted, hw_scan;
719

720
	mutex_lock(&local->mtx);
721

722 723
	sdata = rcu_dereference_protected(local->scan_sdata,
					  lockdep_is_held(&local->mtx));
724

725 726 727 728 729 730
	/* When scanning on-channel, the first-callback means completed. */
	if (test_bit(SCAN_ONCHANNEL_SCANNING, &local->scanning)) {
		aborted = test_and_clear_bit(SCAN_ABORTED, &local->scanning);
		goto out_complete;
	}

731
	if (test_and_clear_bit(SCAN_COMPLETED, &local->scanning)) {
732
		aborted = test_and_clear_bit(SCAN_ABORTED, &local->scanning);
733
		goto out_complete;
734 735
	}

736 737
	if (!sdata || !local->scan_req)
		goto out;
738

739
	if (local->scan_req && !local->scanning) {
740 741 742 743
		struct cfg80211_scan_request *req = local->scan_req;
		int rc;

		local->scan_req = NULL;
744
		rcu_assign_pointer(local->scan_sdata, NULL);
745 746

		rc = __ieee80211_start_scan(sdata, req);
747
		if (rc) {
748 749
			/* need to complete scan in cfg80211 */
			local->scan_req = req;
750 751 752 753
			aborted = true;
			goto out_complete;
		} else
			goto out;
754 755
	}

756 757 758
	/*
	 * Avoid re-scheduling when the sdata is going away.
	 */
759
	if (!ieee80211_sdata_running(sdata)) {
760 761
		aborted = true;
		goto out_complete;
762
	}
763

764 765 766 767 768
	/*
	 * as long as no delay is required advance immediately
	 * without scheduling a new work
	 */
	do {
769 770 771 772 773
		if (!ieee80211_sdata_running(sdata)) {
			aborted = true;
			goto out_complete;
		}

774
		switch (local->next_scan_state) {
775
		case SCAN_DECISION:
776 777 778 779 780 781
			/* if no more bands/channels left, complete scan */
			if (local->scan_channel_idx >= local->scan_req->n_channels) {
				aborted = false;
				goto out_complete;
			}
			ieee80211_scan_state_decision(local, &next_delay);
782
			break;
783 784 785
		case SCAN_SET_CHANNEL:
			ieee80211_scan_state_set_channel(local, &next_delay);
			break;
786 787 788
		case SCAN_SEND_PROBE:
			ieee80211_scan_state_send_probe(local, &next_delay);
			break;
789 790
		case SCAN_SUSPEND:
			ieee80211_scan_state_suspend(local, &next_delay);
791
			break;
792 793
		case SCAN_RESUME:
			ieee80211_scan_state_resume(local, &next_delay);
794
			break;
795 796 797
		case SCAN_ABORT:
			aborted = true;
			goto out_complete;
798 799
		}
	} while (next_delay == 0);
800

801
	ieee80211_queue_delayed_work(&local->hw, &local->scan_work, next_delay);
802
	goto out;
803 804

out_complete:
805
	hw_scan = test_bit(SCAN_HW_SCANNING, &local->scanning);
806
	__ieee80211_scan_completed(&local->hw, aborted, hw_scan);
807 808
out:
	mutex_unlock(&local->mtx);
809 810
}

811 812
int ieee80211_request_scan(struct ieee80211_sub_if_data *sdata,
			   struct cfg80211_scan_request *req)
813
{
814
	int res;
815

816
	mutex_lock(&sdata->local->mtx);
817
	res = __ieee80211_start_scan(sdata, req);
818
	mutex_unlock(&sdata->local->mtx);
819

820
	return res;
821 822
}

S
Stanislaw Gruszka 已提交
823 824 825
int ieee80211_request_ibss_scan(struct ieee80211_sub_if_data *sdata,
				const u8 *ssid, u8 ssid_len,
				struct ieee80211_channel *chan)
826 827
{
	struct ieee80211_local *local = sdata->local;
828
	int ret = -EBUSY;
829
	enum ieee80211_band band;
830

831
	mutex_lock(&local->mtx);
832

833 834 835
	/* busy scanning */
	if (local->scan_req)
		goto unlock;
J
Johannes Berg 已提交
836

J
Johannes Berg 已提交
837 838
	/* fill internal scan request */
	if (!chan) {
S
Stanislaw Gruszka 已提交
839 840
		int i, max_n;
		int n_ch = 0;
J
Johannes Berg 已提交
841 842 843 844

		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
			if (!local->hw.wiphy->bands[band])
				continue;
S
Stanislaw Gruszka 已提交
845 846 847 848

			max_n = local->hw.wiphy->bands[band]->n_channels;
			for (i = 0; i < max_n; i++) {
				struct ieee80211_channel *tmp_ch =
J
Johannes Berg 已提交
849
				    &local->hw.wiphy->bands[band]->channels[i];
S
Stanislaw Gruszka 已提交
850 851 852 853 854 855 856

				if (tmp_ch->flags & (IEEE80211_CHAN_NO_IBSS |
						     IEEE80211_CHAN_DISABLED))
					continue;

				local->int_scan_req->channels[n_ch] = tmp_ch;
				n_ch++;
J
Johannes Berg 已提交
857 858 859
			}
		}

S
Stanislaw Gruszka 已提交
860 861 862 863
		if (WARN_ON_ONCE(n_ch == 0))
			goto unlock;

		local->int_scan_req->n_channels = n_ch;
J
Johannes Berg 已提交
864
	} else {
S
Stanislaw Gruszka 已提交
865 866 867 868
		if (WARN_ON_ONCE(chan->flags & (IEEE80211_CHAN_NO_IBSS |
						IEEE80211_CHAN_DISABLED)))
			goto unlock;

J
Johannes Berg 已提交
869 870 871 872 873 874
		local->int_scan_req->channels[0] = chan;
		local->int_scan_req->n_channels = 1;
	}

	local->int_scan_req->ssids = &local->scan_ssid;
	local->int_scan_req->n_ssids = 1;
875 876
	memcpy(local->int_scan_req->ssids[0].ssid, ssid, IEEE80211_MAX_SSID_LEN);
	local->int_scan_req->ssids[0].ssid_len = ssid_len;
J
Johannes Berg 已提交
877

878
	ret = __ieee80211_start_scan(sdata, sdata->local->int_scan_req);
879
 unlock:
880
	mutex_unlock(&local->mtx);
881
	return ret;
882
}
883

884 885 886
/*
 * Only call this function when a scan can't be queued -- under RTNL.
 */
887 888 889
void ieee80211_scan_cancel(struct ieee80211_local *local)
{
	/*
890
	 * We are canceling software scan, or deferred scan that was not
891 892 893 894 895 896 897 898 899 900 901
	 * yet really started (see __ieee80211_start_scan ).
	 *
	 * Regarding hardware scan:
	 * - we can not call  __ieee80211_scan_completed() as when
	 *   SCAN_HW_SCANNING bit is set this function change
	 *   local->hw_scan_req to operate on 5G band, what race with
	 *   driver which can use local->hw_scan_req
	 *
	 * - we can not cancel scan_work since driver can schedule it
	 *   by ieee80211_scan_completed(..., true) to finish scan
	 *
902 903 904
	 * Hence we only call the cancel_hw_scan() callback, but the low-level
	 * driver is still responsible for calling ieee80211_scan_completed()
	 * after the scan was completed/aborted.
905
	 */
906

907
	mutex_lock(&local->mtx);
908 909 910 911 912
	if (!local->scan_req)
		goto out;

	if (test_bit(SCAN_HW_SCANNING, &local->scanning)) {
		if (local->ops->cancel_hw_scan)
913 914 915
			drv_cancel_hw_scan(local,
				rcu_dereference_protected(local->scan_sdata,
						lockdep_is_held(&local->mtx)));
916
		goto out;
917
	}
918 919 920 921 922 923 924 925 926 927

	/*
	 * If the work is currently running, it must be blocked on
	 * the mutex, but we'll set scan_sdata = NULL and it'll
	 * simply exit once it acquires the mutex.
	 */
	cancel_delayed_work(&local->scan_work);
	/* and clean up */
	__ieee80211_scan_completed(&local->hw, true, false);
out:
928
	mutex_unlock(&local->mtx);
929
}
930 931 932 933 934

int ieee80211_request_sched_scan_start(struct ieee80211_sub_if_data *sdata,
				       struct cfg80211_sched_scan_request *req)
{
	struct ieee80211_local *local = sdata->local;
D
David Spinadel 已提交
935
	struct ieee80211_sched_scan_ies sched_scan_ies = {};
936 937 938 939
	int ret, i, iebufsz;

	iebufsz = 2 + IEEE80211_MAX_SSID_LEN +
		  local->scan_ies_len + req->ie_len;
940

941
	mutex_lock(&local->mtx);
942

943
	if (rcu_access_pointer(local->sched_scan_sdata)) {
944 945 946 947 948 949 950 951 952 953
		ret = -EBUSY;
		goto out;
	}

	if (!local->ops->sched_scan_start) {
		ret = -ENOTSUPP;
		goto out;
	}

	for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
954 955 956
		if (!local->hw.wiphy->bands[i])
			continue;

957
		sched_scan_ies.ie[i] = kzalloc(iebufsz, GFP_KERNEL);
958
		if (!sched_scan_ies.ie[i]) {
959 960 961 962
			ret = -ENOMEM;
			goto out_free;
		}

963 964
		sched_scan_ies.len[i] =
			ieee80211_build_preq_ies(local, sched_scan_ies.ie[i],
965 966
						 iebufsz, req->ie, req->ie_len,
						 i, (u32) -1, 0);
967 968
	}

969 970
	ret = drv_sched_scan_start(local, sdata, req, &sched_scan_ies);
	if (ret == 0)
971
		rcu_assign_pointer(local->sched_scan_sdata, sdata);
972 973 974

out_free:
	while (i > 0)
975
		kfree(sched_scan_ies.ie[--i]);
976
out:
977
	mutex_unlock(&local->mtx);
978 979 980
	return ret;
}

981
int ieee80211_request_sched_scan_stop(struct ieee80211_sub_if_data *sdata)
982 983
{
	struct ieee80211_local *local = sdata->local;
984
	int ret = 0;
985

986
	mutex_lock(&local->mtx);
987 988 989 990 991 992

	if (!local->ops->sched_scan_stop) {
		ret = -ENOTSUPP;
		goto out;
	}

993
	if (rcu_access_pointer(local->sched_scan_sdata))
994
		drv_sched_scan_stop(local, sdata);
995

996
out:
997
	mutex_unlock(&local->mtx);
998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011

	return ret;
}

void ieee80211_sched_scan_results(struct ieee80211_hw *hw)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_sched_scan_results(local);

	cfg80211_sched_scan_results(hw->wiphy);
}
EXPORT_SYMBOL(ieee80211_sched_scan_results);

1012 1013 1014 1015 1016 1017 1018 1019
void ieee80211_sched_scan_stopped_work(struct work_struct *work)
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local,
			     sched_scan_stopped_work);

	mutex_lock(&local->mtx);

1020
	if (!rcu_access_pointer(local->sched_scan_sdata)) {
1021 1022 1023 1024
		mutex_unlock(&local->mtx);
		return;
	}

1025
	rcu_assign_pointer(local->sched_scan_sdata, NULL);
1026 1027 1028 1029 1030 1031

	mutex_unlock(&local->mtx);

	cfg80211_sched_scan_stopped(local->hw.wiphy);
}

1032 1033 1034 1035 1036 1037
void ieee80211_sched_scan_stopped(struct ieee80211_hw *hw)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_sched_scan_stopped(local);

1038
	ieee80211_queue_work(&local->hw, &local->sched_scan_stopped_work);
1039 1040
}
EXPORT_SYMBOL(ieee80211_sched_scan_stopped);