cmdresp.c 24.9 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22
/**
  * This file contains the handling of command
  * responses as well as events generated by firmware.
  */
#include <linux/delay.h>
#include <linux/if_arp.h>
#include <linux/netdevice.h>

#include <net/iw_handler.h>

#include "host.h"
#include "decl.h"
#include "defs.h"
#include "dev.h"
#include "join.h"
#include "wext.h"

/**
 *  @brief This function handles disconnect event. it
 *  reports disconnect to upper layer, clean tx/rx packets,
 *  reset link state etc.
 *
23
 *  @param priv    A pointer to struct lbs_private structure
24 25
 *  @return 	   n/a
 */
26
void lbs_mac_event_disconnected(struct lbs_private *priv)
27 28 29
{
	union iwreq_data wrqu;

30
	if (priv->connect_status != LBS_CONNECTED)
31 32
		return;

33
	lbs_deb_enter(LBS_DEB_ASSOC);
34 35 36 37 38 39 40 41 42 43

	memset(wrqu.ap_addr.sa_data, 0x00, ETH_ALEN);
	wrqu.ap_addr.sa_family = ARPHRD_ETHER;

	/*
	 * Cisco AP sends EAP failure and de-auth in less than 0.5 ms.
	 * It causes problem in the Supplicant
	 */

	msleep_interruptible(1000);
44
	wireless_send_event(priv->dev, SIOCGIWAP, &wrqu, NULL);
45 46

	/* report disconnect to upper layer */
47 48
	netif_stop_queue(priv->dev);
	netif_carrier_off(priv->dev);
49

50 51 52 53 54
	/* Free Tx and Rx packets */
	kfree_skb(priv->currenttxskb);
	priv->currenttxskb = NULL;
	priv->tx_pending_len = 0;

55
	/* reset SNR/NF/RSSI values */
56 57 58 59 60 61 62 63
	memset(priv->SNR, 0x00, sizeof(priv->SNR));
	memset(priv->NF, 0x00, sizeof(priv->NF));
	memset(priv->RSSI, 0x00, sizeof(priv->RSSI));
	memset(priv->rawSNR, 0x00, sizeof(priv->rawSNR));
	memset(priv->rawNF, 0x00, sizeof(priv->rawNF));
	priv->nextSNRNF = 0;
	priv->numSNRNF = 0;
	priv->connect_status = LBS_DISCONNECTED;
64

65 66 67
	/* Clear out associated SSID and BSSID since connection is
	 * no longer valid.
	 */
68 69 70
	memset(&priv->curbssparams.bssid, 0, ETH_ALEN);
	memset(&priv->curbssparams.ssid, 0, IW_ESSID_MAX_SIZE);
	priv->curbssparams.ssid_len = 0;
71

72
	if (priv->psstate != PS_STATE_FULL_POWER) {
73
		/* make firmware to exit PS mode */
74
		lbs_deb_cmd("disconnected, so exit PS mode\n");
75
		lbs_ps_wakeup(priv, 0);
76
	}
77
	lbs_deb_leave(LBS_DEB_CMD);
78 79 80 81 82
}

/**
 *  @brief This function handles MIC failure event.
 *
83
 *  @param priv    A pointer to struct lbs_private structure
84 85 86
 *  @para  event   the event id
 *  @return 	   n/a
 */
87
static void handle_mic_failureevent(struct lbs_private *priv, u32 event)
88 89 90
{
	char buf[50];

91
	lbs_deb_enter(LBS_DEB_CMD);
92 93 94 95 96 97 98 99 100 101
	memset(buf, 0, sizeof(buf));

	sprintf(buf, "%s", "MLME-MICHAELMICFAILURE.indication ");

	if (event == MACREG_INT_CODE_MIC_ERR_UNICAST) {
		strcat(buf, "unicast ");
	} else {
		strcat(buf, "multicast ");
	}

102
	lbs_send_iwevcustom_event(priv, buf);
103
	lbs_deb_leave(LBS_DEB_CMD);
104 105
}

106
static int lbs_ret_reg_access(struct lbs_private *priv,
107 108
			       u16 type, struct cmd_ds_command *resp)
{
109
	int ret = 0;
110

111
	lbs_deb_enter(LBS_DEB_CMD);
112 113

	switch (type) {
114
	case CMD_RET(CMD_MAC_REG_ACCESS):
115
		{
116
			struct cmd_ds_mac_reg_access *reg = &resp->params.macreg;
117

118 119
			priv->offsetvalue.offset = (u32)le16_to_cpu(reg->offset);
			priv->offsetvalue.value = le32_to_cpu(reg->value);
120 121 122
			break;
		}

123
	case CMD_RET(CMD_BBP_REG_ACCESS):
124
		{
125
			struct cmd_ds_bbp_reg_access *reg = &resp->params.bbpreg;
126

127 128
			priv->offsetvalue.offset = (u32)le16_to_cpu(reg->offset);
			priv->offsetvalue.value = reg->value;
129 130 131
			break;
		}

132
	case CMD_RET(CMD_RF_REG_ACCESS):
133
		{
134
			struct cmd_ds_rf_reg_access *reg = &resp->params.rfreg;
135

136 137
			priv->offsetvalue.offset = (u32)le16_to_cpu(reg->offset);
			priv->offsetvalue.value = reg->value;
138 139 140 141
			break;
		}

	default:
142
		ret = -1;
143 144
	}

145
	lbs_deb_leave_args(LBS_DEB_CMD, "ret %d", ret);
146
	return ret;
147 148
}

149
static int lbs_ret_802_11_sleep_params(struct lbs_private *priv,
150 151 152 153
					struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_sleep_params *sp = &resp->params.sleep_params;

154
	lbs_deb_enter(LBS_DEB_CMD);
155

156 157
	lbs_deb_cmd("error 0x%x, offset 0x%x, stabletime 0x%x, calcontrol 0x%x "
		    "extsleepclk 0x%x\n", le16_to_cpu(sp->error),
158 159 160
		    le16_to_cpu(sp->offset), le16_to_cpu(sp->stabletime),
		    sp->calcontrol, sp->externalsleepclk);

161 162 163 164 165 166
	priv->sp.sp_error = le16_to_cpu(sp->error);
	priv->sp.sp_offset = le16_to_cpu(sp->offset);
	priv->sp.sp_stabletime = le16_to_cpu(sp->stabletime);
	priv->sp.sp_calcontrol = sp->calcontrol;
	priv->sp.sp_extsleepclk = sp->externalsleepclk;
	priv->sp.sp_reserved = le16_to_cpu(sp->reserved);
167

168
	lbs_deb_enter(LBS_DEB_CMD);
169 170 171
	return 0;
}

172
static int lbs_ret_802_11_stat(struct lbs_private *priv,
173 174
				struct cmd_ds_command *resp)
{
175
	lbs_deb_enter(LBS_DEB_CMD);
176
/*	currently priv->wlan802_11Stat is unused
177 178 179 180

	struct cmd_ds_802_11_get_stat *p11Stat = &resp->params.gstat;

	// TODO Convert it to Big endian befor copy
181
	memcpy(&priv->wlan802_11Stat,
182 183
	       p11Stat, sizeof(struct cmd_ds_802_11_get_stat));
*/
184
	lbs_deb_leave(LBS_DEB_CMD);
185 186 187
	return 0;
}

188
static int lbs_ret_802_11_snmp_mib(struct lbs_private *priv,
189 190 191 192 193 194
				    struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_snmp_mib *smib = &resp->params.smib;
	u16 oid = le16_to_cpu(smib->oid);
	u16 querytype = le16_to_cpu(smib->querytype);

195
	lbs_deb_enter(LBS_DEB_CMD);
196

197
	lbs_deb_cmd("SNMP_RESP: oid 0x%x, querytype 0x%x\n", oid,
198
	       querytype);
199
	lbs_deb_cmd("SNMP_RESP: Buf size %d\n", le16_to_cpu(smib->bufsize));
200

201
	if (querytype == CMD_ACT_GET) {
202
		switch (oid) {
203
		case FRAGTHRESH_I:
204
			priv->fragthsd =
205
				le16_to_cpu(*((__le16 *)(smib->value)));
206
			lbs_deb_cmd("SNMP_RESP: frag threshold %u\n",
207
				    priv->fragthsd);
208
			break;
209
		case RTSTHRESH_I:
210
			priv->rtsthsd =
211
				le16_to_cpu(*((__le16 *)(smib->value)));
212
			lbs_deb_cmd("SNMP_RESP: rts threshold %u\n",
213
				    priv->rtsthsd);
214
			break;
215
		case SHORT_RETRYLIM_I:
216
			priv->txretrycount =
217
				le16_to_cpu(*((__le16 *)(smib->value)));
218
			lbs_deb_cmd("SNMP_RESP: tx retry count %u\n",
219
				    priv->rtsthsd);
220 221 222 223 224 225
			break;
		default:
			break;
		}
	}

226
	lbs_deb_enter(LBS_DEB_CMD);
227 228 229
	return 0;
}

230
static int lbs_ret_802_11_key_material(struct lbs_private *priv,
231 232 233 234 235 236
					struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_key_material *pkeymaterial =
	    &resp->params.keymaterial;
	u16 action = le16_to_cpu(pkeymaterial->action);

237
	lbs_deb_enter(LBS_DEB_CMD);
238 239

	/* Copy the returned key to driver private data */
240
	if (action == CMD_ACT_GET) {
241 242 243 244 245 246
		u8 * buf_ptr = (u8 *) &pkeymaterial->keyParamSet;
		u8 * resp_end = (u8 *) (resp + le16_to_cpu(resp->size));

		while (buf_ptr < resp_end) {
			struct MrvlIEtype_keyParamSet * pkeyparamset =
			    (struct MrvlIEtype_keyParamSet *) buf_ptr;
247
			struct enc_key * pkey;
248 249
			u16 param_set_len = le16_to_cpu(pkeyparamset->length);
			u16 key_len = le16_to_cpu(pkeyparamset->keylen);
250 251 252
			u16 key_flags = le16_to_cpu(pkeyparamset->keyinfo);
			u16 key_type = le16_to_cpu(pkeyparamset->keytypeid);
			u8 * end;
253 254 255 256 257 258 259 260

			end = (u8 *) pkeyparamset + sizeof (pkeyparamset->type)
			                          + sizeof (pkeyparamset->length)
			                          + param_set_len;
			/* Make sure we don't access past the end of the IEs */
			if (end > resp_end)
				break;

261
			if (key_flags & KEY_INFO_WPA_UNICAST)
262
				pkey = &priv->wpa_unicast_key;
263
			else if (key_flags & KEY_INFO_WPA_MCAST)
264
				pkey = &priv->wpa_mcast_key;
265 266 267 268
			else
				break;

			/* Copy returned key into driver */
269
			memset(pkey, 0, sizeof(struct enc_key));
270 271
			if (key_len > sizeof(pkey->key))
				break;
272 273 274
			pkey->type = key_type;
			pkey->flags = key_flags;
			pkey->len = key_len;
275 276 277 278 279 280
			memcpy(pkey->key, pkeyparamset->key, pkey->len);

			buf_ptr = end + 1;
		}
	}

281
	lbs_deb_enter(LBS_DEB_CMD);
282 283 284
	return 0;
}

285
static int lbs_ret_802_11_mac_address(struct lbs_private *priv,
286 287 288 289
				       struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_mac_address *macadd = &resp->params.macadd;

290
	lbs_deb_enter(LBS_DEB_CMD);
291

292
	memcpy(priv->current_addr, macadd->macadd, ETH_ALEN);
293

294
	lbs_deb_enter(LBS_DEB_CMD);
295 296 297
	return 0;
}

298
static int lbs_ret_802_11_rf_tx_power(struct lbs_private *priv,
299 300 301 302
				       struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_rf_tx_power *rtp = &resp->params.txp;

303
	lbs_deb_enter(LBS_DEB_CMD);
304

305
	priv->txpowerlevel = le16_to_cpu(rtp->currentlevel);
306

307
	lbs_deb_cmd("TX power currently %d\n", priv->txpowerlevel);
308

309
	lbs_deb_leave(LBS_DEB_CMD);
310 311 312
	return 0;
}

313
static int lbs_ret_802_11_rate_adapt_rateset(struct lbs_private *priv,
314 315
					      struct cmd_ds_command *resp)
{
316
	struct cmd_ds_802_11_rate_adapt_rateset *rates = &resp->params.rateset;
317

318
	lbs_deb_enter(LBS_DEB_CMD);
319

320
	if (rates->action == CMD_ACT_GET) {
321 322
		priv->enablehwauto = le16_to_cpu(rates->enablehwauto);
		priv->ratebitmap = le16_to_cpu(rates->bitmap);
323 324
	}

325
	lbs_deb_leave(LBS_DEB_CMD);
326 327 328
	return 0;
}

329
static int lbs_ret_802_11_rssi(struct lbs_private *priv,
330 331 332 333
				struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_rssi_rsp *rssirsp = &resp->params.rssirsp;

334 335
	lbs_deb_enter(LBS_DEB_CMD);

336
	/* store the non average value */
337 338
	priv->SNR[TYPE_BEACON][TYPE_NOAVG] = le16_to_cpu(rssirsp->SNR);
	priv->NF[TYPE_BEACON][TYPE_NOAVG] = le16_to_cpu(rssirsp->noisefloor);
339

340 341
	priv->SNR[TYPE_BEACON][TYPE_AVG] = le16_to_cpu(rssirsp->avgSNR);
	priv->NF[TYPE_BEACON][TYPE_AVG] = le16_to_cpu(rssirsp->avgnoisefloor);
342

343 344 345
	priv->RSSI[TYPE_BEACON][TYPE_NOAVG] =
	    CAL_RSSI(priv->SNR[TYPE_BEACON][TYPE_NOAVG],
		     priv->NF[TYPE_BEACON][TYPE_NOAVG]);
346

347 348 349
	priv->RSSI[TYPE_BEACON][TYPE_AVG] =
	    CAL_RSSI(priv->SNR[TYPE_BEACON][TYPE_AVG] / AVG_SCALE,
		     priv->NF[TYPE_BEACON][TYPE_AVG] / AVG_SCALE);
350

351
	lbs_deb_cmd("RSSI: beacon %d, avg %d\n",
352 353
	       priv->RSSI[TYPE_BEACON][TYPE_NOAVG],
	       priv->RSSI[TYPE_BEACON][TYPE_AVG]);
354

355
	lbs_deb_leave(LBS_DEB_CMD);
356 357 358
	return 0;
}

359
static int lbs_ret_802_11_eeprom_access(struct lbs_private *priv,
360 361
				  struct cmd_ds_command *resp)
{
362
	struct lbs_ioctl_regrdwr *pbuf;
363
	pbuf = (struct lbs_ioctl_regrdwr *) priv->prdeeprom;
364

365
	lbs_deb_enter_args(LBS_DEB_CMD, "len %d",
366 367 368
	       le16_to_cpu(resp->params.rdeeprom.bytecount));
	if (pbuf->NOB < le16_to_cpu(resp->params.rdeeprom.bytecount)) {
		pbuf->NOB = 0;
369
		lbs_deb_cmd("EEPROM read length too big\n");
370 371 372 373 374 375 376
		return -1;
	}
	pbuf->NOB = le16_to_cpu(resp->params.rdeeprom.bytecount);
	if (pbuf->NOB > 0) {

		memcpy(&pbuf->value, (u8 *) & resp->params.rdeeprom.value,
		       le16_to_cpu(resp->params.rdeeprom.bytecount));
377
		lbs_deb_hex(LBS_DEB_CMD, "EEPROM", (char *)&pbuf->value,
378 379
			le16_to_cpu(resp->params.rdeeprom.bytecount));
	}
380
	lbs_deb_leave(LBS_DEB_CMD);
381 382 383
	return 0;
}

384
static int lbs_ret_get_log(struct lbs_private *priv,
385 386
			    struct cmd_ds_command *resp)
{
387
	struct cmd_ds_802_11_get_log *logmessage = &resp->params.glog;
388

389
	lbs_deb_enter(LBS_DEB_CMD);
390

391
	/* Stored little-endian */
392
	memcpy(&priv->logmsg, logmessage, sizeof(struct cmd_ds_802_11_get_log));
393

394
	lbs_deb_leave(LBS_DEB_CMD);
395 396 397
	return 0;
}

398
static int lbs_ret_802_11_enable_rsn(struct lbs_private *priv,
399 400 401
                                          struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_enable_rsn *enable_rsn = &resp->params.enbrsn;
402
	uint32_t * pdata_buf = (uint32_t *)priv->cur_cmd->callback_arg;
403 404 405

	lbs_deb_enter(LBS_DEB_CMD);

406
	if (enable_rsn->action == cpu_to_le16(CMD_ACT_GET)) {
407
		if (pdata_buf)
408
			*pdata_buf = (uint32_t) le16_to_cpu(enable_rsn->enable);
409 410
	}

411
	lbs_deb_leave(LBS_DEB_CMD);
412 413 414
	return 0;
}

415 416 417 418 419 420 421 422 423
static int lbs_ret_802_11_bcn_ctrl(struct lbs_private * priv,
					struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_beacon_control *bcn_ctrl =
	    &resp->params.bcn_ctrl;

	lbs_deb_enter(LBS_DEB_CMD);

	if (bcn_ctrl->action == CMD_ACT_GET) {
424 425
		priv->beacon_enable = (u8) le16_to_cpu(bcn_ctrl->beacon_enable);
		priv->beacon_period = le16_to_cpu(bcn_ctrl->beacon_period);
426 427 428 429 430 431
	}

	lbs_deb_enter(LBS_DEB_CMD);
	return 0;
}

432 433 434 435 436 437
static int lbs_ret_802_11_subscribe_event(struct lbs_private *priv,
	struct cmd_ds_command *resp)
{
	struct cmd_ds_802_11_subscribe_event *cmd_event =
		&resp->params.subscribe_event;
	struct cmd_ds_802_11_subscribe_event *dst_event =
438
		(void *)priv->cur_cmd->callback_arg;
439 440 441 442

	lbs_deb_enter(LBS_DEB_CMD);

	if (dst_event->action == cpu_to_le16(CMD_ACT_GET)) {
H
Holger Schurig 已提交
443
		dst_event->events = cmd_event->events;
444 445 446 447 448 449 450
		memcpy(dst_event->tlv, cmd_event->tlv, sizeof(dst_event->tlv));
	}

	lbs_deb_leave(LBS_DEB_CMD);
	return 0;
}

451 452
static inline int handle_cmd_response(struct lbs_private *priv,
				      unsigned long dummy,
453
				      struct cmd_header *cmd_response)
454
{
455
	struct cmd_ds_command *resp = (struct cmd_ds_command *) cmd_response;
456 457
	int ret = 0;
	unsigned long flags;
458
	uint16_t respcmd = le16_to_cpu(resp->command);
459

460 461
	lbs_deb_enter(LBS_DEB_HOST);

462
	switch (respcmd) {
463 464 465
	case CMD_RET(CMD_MAC_REG_ACCESS):
	case CMD_RET(CMD_BBP_REG_ACCESS):
	case CMD_RET(CMD_RF_REG_ACCESS):
466
		ret = lbs_ret_reg_access(priv, respcmd, resp);
467 468
		break;

469
	case CMD_RET(CMD_802_11_SCAN):
470
		ret = lbs_ret_80211_scan(priv, resp);
471 472
		break;

473
	case CMD_RET(CMD_802_11_GET_LOG):
474
		ret = lbs_ret_get_log(priv, resp);
475 476
		break;

477
	case CMD_RET_802_11_ASSOCIATE:
478 479
	case CMD_RET(CMD_802_11_ASSOCIATE):
	case CMD_RET(CMD_802_11_REASSOCIATE):
480
		ret = lbs_ret_80211_associate(priv, resp);
481 482
		break;

483 484
	case CMD_RET(CMD_802_11_DISASSOCIATE):
	case CMD_RET(CMD_802_11_DEAUTHENTICATE):
485
		ret = lbs_ret_80211_disassociate(priv, resp);
486 487
		break;

488 489
	case CMD_RET(CMD_802_11_AD_HOC_START):
	case CMD_RET(CMD_802_11_AD_HOC_JOIN):
490
		ret = lbs_ret_80211_ad_hoc_start(priv, resp);
491 492
		break;

493
	case CMD_RET(CMD_802_11_GET_STAT):
494
		ret = lbs_ret_802_11_stat(priv, resp);
495 496
		break;

497
	case CMD_RET(CMD_802_11_SNMP_MIB):
498
		ret = lbs_ret_802_11_snmp_mib(priv, resp);
499 500
		break;

501
	case CMD_RET(CMD_802_11_RF_TX_POWER):
502
		ret = lbs_ret_802_11_rf_tx_power(priv, resp);
503 504
		break;

505 506
	case CMD_RET(CMD_802_11_SET_AFC):
	case CMD_RET(CMD_802_11_GET_AFC):
507
		spin_lock_irqsave(&priv->driver_lock, flags);
508
		memmove((void *)priv->cur_cmd->callback_arg, &resp->params.afc,
509
			sizeof(struct cmd_ds_802_11_afc));
510
		spin_unlock_irqrestore(&priv->driver_lock, flags);
511 512 513

		break;

514 515 516 517 518 519
	case CMD_RET(CMD_MAC_MULTICAST_ADR):
	case CMD_RET(CMD_MAC_CONTROL):
	case CMD_RET(CMD_802_11_SET_WEP):
	case CMD_RET(CMD_802_11_RESET):
	case CMD_RET(CMD_802_11_AUTHENTICATE):
	case CMD_RET(CMD_802_11_BEACON_STOP):
520 521
		break;

522
	case CMD_RET(CMD_802_11_ENABLE_RSN):
523
		ret = lbs_ret_802_11_enable_rsn(priv, resp);
524 525
		break;

526
	case CMD_RET(CMD_802_11_RATE_ADAPT_RATESET):
527
		ret = lbs_ret_802_11_rate_adapt_rateset(priv, resp);
528 529
		break;

530
	case CMD_RET(CMD_802_11_RSSI):
531
		ret = lbs_ret_802_11_rssi(priv, resp);
532 533
		break;

534
	case CMD_RET(CMD_802_11_MAC_ADDRESS):
535
		ret = lbs_ret_802_11_mac_address(priv, resp);
536 537
		break;

538
	case CMD_RET(CMD_802_11_AD_HOC_STOP):
539
		ret = lbs_ret_80211_ad_hoc_stop(priv, resp);
540 541
		break;

542
	case CMD_RET(CMD_802_11_KEY_MATERIAL):
543
		ret = lbs_ret_802_11_key_material(priv, resp);
544 545
		break;

546
	case CMD_RET(CMD_802_11_EEPROM_ACCESS):
547
		ret = lbs_ret_802_11_eeprom_access(priv, resp);
548 549
		break;

550
	case CMD_RET(CMD_802_11D_DOMAIN_INFO):
551
		ret = lbs_ret_802_11d_domain_info(priv, resp);
552 553
		break;

554
	case CMD_RET(CMD_802_11_SLEEP_PARAMS):
555
		ret = lbs_ret_802_11_sleep_params(priv, resp);
556
		break;
557
	case CMD_RET(CMD_802_11_TPC_CFG):
558
		spin_lock_irqsave(&priv->driver_lock, flags);
559
		memmove((void *)priv->cur_cmd->callback_arg, &resp->params.tpccfg,
560
			sizeof(struct cmd_ds_802_11_tpc_cfg));
561
		spin_unlock_irqrestore(&priv->driver_lock, flags);
562
		break;
563
	case CMD_RET(CMD_802_11_LED_GPIO_CTRL):
564
		spin_lock_irqsave(&priv->driver_lock, flags);
565
		memmove((void *)priv->cur_cmd->callback_arg, &resp->params.ledgpio,
566
			sizeof(struct cmd_ds_802_11_led_ctrl));
567
		spin_unlock_irqrestore(&priv->driver_lock, flags);
568
		break;
569 570 571 572
	case CMD_RET(CMD_802_11_SUBSCRIBE_EVENT):
		ret = lbs_ret_802_11_subscribe_event(priv, resp);
		break;

573
	case CMD_RET(CMD_802_11_PWR_CFG):
574
		spin_lock_irqsave(&priv->driver_lock, flags);
575
		memmove((void *)priv->cur_cmd->callback_arg, &resp->params.pwrcfg,
576
			sizeof(struct cmd_ds_802_11_pwr_cfg));
577
		spin_unlock_irqrestore(&priv->driver_lock, flags);
578 579 580

		break;

581
	case CMD_RET(CMD_GET_TSF):
582
		spin_lock_irqsave(&priv->driver_lock, flags);
583
		memcpy((void *)priv->cur_cmd->callback_arg,
584
		       &resp->params.gettsf.tsfvalue, sizeof(u64));
585
		spin_unlock_irqrestore(&priv->driver_lock, flags);
586
		break;
587
	case CMD_RET(CMD_BT_ACCESS):
588
		spin_lock_irqsave(&priv->driver_lock, flags);
589 590
		if (priv->cur_cmd->callback_arg)
			memcpy((void *)priv->cur_cmd->callback_arg,
591
			       &resp->params.bt.addr1, 2 * ETH_ALEN);
592
		spin_unlock_irqrestore(&priv->driver_lock, flags);
593
		break;
594
	case CMD_RET(CMD_FWT_ACCESS):
595
		spin_lock_irqsave(&priv->driver_lock, flags);
596 597
		if (priv->cur_cmd->callback_arg)
			memcpy((void *)priv->cur_cmd->callback_arg, &resp->params.fwt,
598
			       sizeof(resp->params.fwt));
599
		spin_unlock_irqrestore(&priv->driver_lock, flags);
600
		break;
601 602 603 604
	case CMD_RET(CMD_802_11_BEACON_CTRL):
		ret = lbs_ret_802_11_bcn_ctrl(priv, resp);
		break;

605
	default:
606
		lbs_deb_host("CMD_RESP: unknown cmd response 0x%04x\n",
607
			     le16_to_cpu(resp->command));
608 609
		break;
	}
610
	lbs_deb_leave(LBS_DEB_HOST);
611 612 613
	return ret;
}

614
int lbs_process_rx_command(struct lbs_private *priv)
615
{
616
	uint16_t respcmd, curcmd;
617
	struct cmd_header *resp;
618
	int ret = 0;
619 620
	unsigned long flags;
	uint16_t result;
621

622
	lbs_deb_enter(LBS_DEB_HOST);
623

624 625
	mutex_lock(&priv->lock);
	spin_lock_irqsave(&priv->driver_lock, flags);
626

627
	if (!priv->cur_cmd) {
628
		lbs_deb_host("CMD_RESP: cur_cmd is NULL\n");
629
		ret = -1;
630
		spin_unlock_irqrestore(&priv->driver_lock, flags);
631 632
		goto done;
	}
633

634
	resp = (void *)priv->upld_buf;
635

636 637
	curcmd = le16_to_cpu(resp->command);

638 639 640
	respcmd = le16_to_cpu(resp->command);
	result = le16_to_cpu(resp->result);

641 642
	lbs_deb_host("CMD_RESP: response 0x%04x, seq %d, size %d, jiffies %lu\n",
		     respcmd, le16_to_cpu(resp->seqnum), priv->upld_len, jiffies);
643
	lbs_deb_hex(LBS_DEB_HOST, "CMD_RESP", (void *) resp, priv->upld_len);
644

645
	if (resp->seqnum != resp->seqnum) {
646
		lbs_pr_info("Received CMD_RESP with invalid sequence %d (expected %d)\n",
647
			    le16_to_cpu(resp->seqnum), le16_to_cpu(resp->seqnum));
648
		spin_unlock_irqrestore(&priv->driver_lock, flags);
649 650 651
		ret = -1;
		goto done;
	}
652 653 654 655 656 657 658 659
	if (respcmd != CMD_RET(curcmd) &&
	    respcmd != CMD_802_11_ASSOCIATE && curcmd != CMD_RET_802_11_ASSOCIATE) {
		lbs_pr_info("Invalid CMD_RESP %x to command %x!\n", respcmd, curcmd);
		spin_unlock_irqrestore(&priv->driver_lock, flags);
		ret = -1;
		goto done;
	}

660 661 662 663 664 665 666 667 668 669
	if (resp->result == cpu_to_le16(0x0004)) {
		/* 0x0004 means -EAGAIN. Drop the response, let it time out
		   and be resubmitted */
		lbs_pr_info("Firmware returns DEFER to command %x. Will let it time out...\n",
			    le16_to_cpu(resp->command));
		spin_unlock_irqrestore(&priv->driver_lock, flags);
		ret = -1;
		goto done;
	}

670 671
	/* Now we got response from FW, cancel the command timer */
	del_timer(&priv->command_timer);
672 673 674 675 676 677
	priv->cmd_timed_out = 0;
	if (priv->nr_retries) {
		lbs_pr_info("Received result %x to command %x after %d retries\n",
			    result, curcmd, priv->nr_retries);
		priv->nr_retries = 0;
	}
678 679

	/* Store the response code to cur_cmd_retcode. */
680
	priv->cur_cmd_retcode = result;
681

682
	if (respcmd == CMD_RET(CMD_802_11_PS_MODE)) {
683
		struct cmd_ds_802_11_ps_mode *psmode = (void *) &resp[1];
684
		u16 action = le16_to_cpu(psmode->action);
685

686 687
		lbs_deb_host(
		       "CMD_RESP: PS_MODE cmd reply result 0x%x, action 0x%x\n",
688
		       result, action);
689 690

		if (result) {
691
			lbs_deb_host("CMD_RESP: PS command failed with 0x%x\n",
692 693 694 695
				    result);
			/*
			 * We should not re-try enter-ps command in
			 * ad-hoc mode. It takes place in
696
			 * lbs_execute_next_command().
697
			 */
698
			if (priv->mode == IW_MODE_ADHOC &&
699
			    action == CMD_SUBCMD_ENTER_PS)
700
				priv->psmode = LBS802_11POWERMODECAM;
701
		} else if (action == CMD_SUBCMD_ENTER_PS) {
702 703
			priv->needtowakeup = 0;
			priv->psstate = PS_STATE_AWAKE;
704

705
			lbs_deb_host("CMD_RESP: ENTER_PS command response\n");
706
			if (priv->connect_status != LBS_CONNECTED) {
707 708 709 710
				/*
				 * When Deauth Event received before Enter_PS command
				 * response, We need to wake up the firmware.
				 */
711
				lbs_deb_host(
712
				       "disconnected, invoking lbs_ps_wakeup\n");
713

714 715
				spin_unlock_irqrestore(&priv->driver_lock, flags);
				mutex_unlock(&priv->lock);
716
				lbs_ps_wakeup(priv, 0);
717 718
				mutex_lock(&priv->lock);
				spin_lock_irqsave(&priv->driver_lock, flags);
719
			}
720
		} else if (action == CMD_SUBCMD_EXIT_PS) {
721 722
			priv->needtowakeup = 0;
			priv->psstate = PS_STATE_FULL_POWER;
723
			lbs_deb_host("CMD_RESP: EXIT_PS command response\n");
724
		} else {
725
			lbs_deb_host("CMD_RESP: PS action 0x%X\n", action);
726 727
		}

728
		lbs_complete_command(priv, priv->cur_cmd, result);
729
		spin_unlock_irqrestore(&priv->driver_lock, flags);
730 731 732 733 734 735 736

		ret = 0;
		goto done;
	}

	/* If the command is not successful, cleanup and return failure */
	if ((result != 0 || !(respcmd & 0x8000))) {
737 738
		lbs_deb_host("CMD_RESP: error 0x%04x in command reply 0x%04x\n",
		       result, respcmd);
739 740 741 742
		/*
		 * Handling errors here
		 */
		switch (respcmd) {
743 744
		case CMD_RET(CMD_GET_HW_SPEC):
		case CMD_RET(CMD_802_11_RESET):
745
			lbs_deb_host("CMD_RESP: reset failed\n");
746 747 748
			break;

		}
749
		lbs_complete_command(priv, priv->cur_cmd, result);
750
		spin_unlock_irqrestore(&priv->driver_lock, flags);
751 752 753 754 755

		ret = -1;
		goto done;
	}

756
	spin_unlock_irqrestore(&priv->driver_lock, flags);
757

758 759
	if (priv->cur_cmd && priv->cur_cmd->callback) {
		ret = priv->cur_cmd->callback(priv, priv->cur_cmd->callback_arg,
760
				resp);
761
	} else
762
		ret = handle_cmd_response(priv, 0, resp);
763

764
	spin_lock_irqsave(&priv->driver_lock, flags);
765

766
	if (priv->cur_cmd) {
767
		/* Clean up and Put current command back to cmdfreeq */
768
		lbs_complete_command(priv, priv->cur_cmd, result);
769
	}
770
	spin_unlock_irqrestore(&priv->driver_lock, flags);
771 772

done:
773
	mutex_unlock(&priv->lock);
774
	lbs_deb_leave_args(LBS_DEB_HOST, "ret %d", ret);
775 776 777
	return ret;
}

778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801
static int lbs_send_confirmwake(struct lbs_private *priv)
{
	struct cmd_header *cmd = &priv->lbs_ps_confirm_wake;
	int ret = 0;

	lbs_deb_enter(LBS_DEB_HOST);

	cmd->command = cpu_to_le16(CMD_802_11_WAKEUP_CONFIRM);
	cmd->size = cpu_to_le16(sizeof(*cmd));
	cmd->seqnum = cpu_to_le16(++priv->seqnum);
	cmd->result = 0;

	lbs_deb_host("SEND_WAKEC_CMD: before download\n");

	lbs_deb_hex(LBS_DEB_HOST, "wake confirm command", (void *)cmd, sizeof(*cmd));

	ret = priv->hw_host_to_card(priv, MVMS_CMD, (void *)cmd, sizeof(*cmd));
	if (ret)
		lbs_pr_alert("SEND_WAKEC_CMD: Host to Card failed for Confirm Wake\n");

	lbs_deb_leave_args(LBS_DEB_HOST, "ret %d", ret);
	return ret;
}

802
int lbs_process_event(struct lbs_private *priv)
803 804 805 806
{
	int ret = 0;
	u32 eventcause;

807 808
	lbs_deb_enter(LBS_DEB_CMD);

809 810 811
	spin_lock_irq(&priv->driver_lock);
	eventcause = priv->eventcause >> SBI_EVENT_CAUSE_SHIFT;
	spin_unlock_irq(&priv->driver_lock);
812

813
	lbs_deb_cmd("event cause %d\n", eventcause);
814

815
	switch (eventcause) {
816
	case MACREG_INT_CODE_LINK_SENSED:
817
		lbs_deb_cmd("EVENT: MACREG_INT_CODE_LINK_SENSED\n");
818 819 820
		break;

	case MACREG_INT_CODE_DEAUTHENTICATED:
821
		lbs_deb_cmd("EVENT: deauthenticated\n");
822
		lbs_mac_event_disconnected(priv);
823 824 825
		break;

	case MACREG_INT_CODE_DISASSOCIATED:
826
		lbs_deb_cmd("EVENT: disassociated\n");
827
		lbs_mac_event_disconnected(priv);
828 829
		break;

830
	case MACREG_INT_CODE_LINK_LOST_NO_SCAN:
831
		lbs_deb_cmd("EVENT: link lost\n");
832
		lbs_mac_event_disconnected(priv);
833 834 835
		break;

	case MACREG_INT_CODE_PS_SLEEP:
836
		lbs_deb_cmd("EVENT: sleep\n");
837 838

		/* handle unexpected PS SLEEP event */
839
		if (priv->psstate == PS_STATE_FULL_POWER) {
840
			lbs_deb_cmd(
841
			       "EVENT: in FULL POWER mode, ignoreing PS_SLEEP\n");
842 843
			break;
		}
844
		priv->psstate = PS_STATE_PRE_SLEEP;
845

846
		lbs_ps_confirm_sleep(priv, (u16) priv->psmode);
847 848 849

		break;

850 851 852 853 854
	case MACREG_INT_CODE_HOST_AWAKE:
		lbs_deb_cmd("EVENT: HOST_AWAKE\n");
		lbs_send_confirmwake(priv);
		break;

855
	case MACREG_INT_CODE_PS_AWAKE:
856
		lbs_deb_cmd("EVENT: awake\n");
857
		/* handle unexpected PS AWAKE event */
858
		if (priv->psstate == PS_STATE_FULL_POWER) {
859
			lbs_deb_cmd(
860 861 862 863
			       "EVENT: In FULL POWER mode - ignore PS AWAKE\n");
			break;
		}

864
		priv->psstate = PS_STATE_AWAKE;
865

866
		if (priv->needtowakeup) {
867 868 869
			/*
			 * wait for the command processing to finish
			 * before resuming sending
870
			 * priv->needtowakeup will be set to FALSE
871
			 * in lbs_ps_wakeup()
872
			 */
873
			lbs_deb_cmd("waking up ...\n");
874
			lbs_ps_wakeup(priv, 0);
875 876 877 878
		}
		break;

	case MACREG_INT_CODE_MIC_ERR_UNICAST:
879
		lbs_deb_cmd("EVENT: UNICAST MIC ERROR\n");
880 881 882 883
		handle_mic_failureevent(priv, MACREG_INT_CODE_MIC_ERR_UNICAST);
		break;

	case MACREG_INT_CODE_MIC_ERR_MULTICAST:
884
		lbs_deb_cmd("EVENT: MULTICAST MIC ERROR\n");
885 886 887 888 889 890 891
		handle_mic_failureevent(priv, MACREG_INT_CODE_MIC_ERR_MULTICAST);
		break;
	case MACREG_INT_CODE_MIB_CHANGED:
	case MACREG_INT_CODE_INIT_DONE:
		break;

	case MACREG_INT_CODE_ADHOC_BCN_LOST:
892
		lbs_deb_cmd("EVENT: ADHOC beacon lost\n");
893 894 895
		break;

	case MACREG_INT_CODE_RSSI_LOW:
896
		lbs_pr_alert("EVENT: rssi low\n");
897 898
		break;
	case MACREG_INT_CODE_SNR_LOW:
899
		lbs_pr_alert("EVENT: snr low\n");
900 901
		break;
	case MACREG_INT_CODE_MAX_FAIL:
902
		lbs_pr_alert("EVENT: max fail\n");
903 904
		break;
	case MACREG_INT_CODE_RSSI_HIGH:
905
		lbs_pr_alert("EVENT: rssi high\n");
906 907
		break;
	case MACREG_INT_CODE_SNR_HIGH:
908
		lbs_pr_alert("EVENT: snr high\n");
909 910
		break;

911
	case MACREG_INT_CODE_MESH_AUTO_STARTED:
912 913 914 915 916
		/* Ignore spurious autostart events if autostart is disabled */
		if (!priv->mesh_autostart_enabled) {
			lbs_pr_info("EVENT: MESH_AUTO_STARTED (ignoring)\n");
			break;
		}
917
		lbs_pr_info("EVENT: MESH_AUTO_STARTED\n");
918
		priv->mesh_connect_status = LBS_CONNECTED;
919
		if (priv->mesh_open) {
920
			netif_carrier_on(priv->mesh_dev);
921 922
			if (!priv->tx_pending_len)
				netif_wake_queue(priv->mesh_dev);
923
		}
924
		priv->mode = IW_MODE_ADHOC;
925
		schedule_work(&priv->sync_channel);
926 927
		break;

928
	default:
929
		lbs_pr_alert("EVENT: unknown event id %d\n", eventcause);
930 931 932
		break;
	}

933 934 935
	spin_lock_irq(&priv->driver_lock);
	priv->eventcause = 0;
	spin_unlock_irq(&priv->driver_lock);
936

937
	lbs_deb_leave_args(LBS_DEB_CMD, "ret %d", ret);
938 939
	return ret;
}