scan.c 25.1 KB
Newer Older
1
/*
2 3
 * Scanning implementation
 *
4 5 6 7 8 9 10 11 12 13 14 15
 * Copyright 2003, Jouni Malinen <jkmaline@cc.hut.fi>
 * Copyright 2004, Instant802 Networks, Inc.
 * Copyright 2005, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
 * Copyright 2007, Michael Wu <flamingice@sourmilk.net>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#include <linux/if_arp.h>
16
#include <linux/rtnetlink.h>
17 18
#include <linux/pm_qos_params.h>
#include <net/sch_generic.h>
19
#include <linux/slab.h>
20 21 22
#include <net/mac80211.h>

#include "ieee80211_i.h"
23
#include "driver-ops.h"
24
#include "mesh.h"
25 26 27

#define IEEE80211_PROBE_DELAY (HZ / 33)
#define IEEE80211_CHANNEL_TIME (HZ / 33)
28
#define IEEE80211_PASSIVE_CHANNEL_TIME (HZ / 8)
29

30
struct ieee80211_bss *
31 32 33
ieee80211_rx_bss_get(struct ieee80211_local *local, u8 *bssid, int freq,
		     u8 *ssid, u8 ssid_len)
{
34 35 36 37 38 39 40 41
	struct cfg80211_bss *cbss;

	cbss = cfg80211_get_bss(local->hw.wiphy,
				ieee80211_get_channel(local->hw.wiphy, freq),
				bssid, ssid, ssid_len, 0, 0);
	if (!cbss)
		return NULL;
	return (void *)cbss->priv;
42 43
}

44
static void ieee80211_rx_bss_free(struct cfg80211_bss *cbss)
45
{
46
	struct ieee80211_bss *bss = (void *)cbss->priv;
47 48 49 50 51 52

	kfree(bss_mesh_id(bss));
	kfree(bss_mesh_cfg(bss));
}

void ieee80211_rx_bss_put(struct ieee80211_local *local,
53
			  struct ieee80211_bss *bss)
54
{
55 56 57
	if (!bss)
		return;
	cfg80211_put_bss(container_of((void *)bss, struct cfg80211_bss, priv));
58 59
}

K
Kalle Valo 已提交
60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76
static bool is_uapsd_supported(struct ieee802_11_elems *elems)
{
	u8 qos_info;

	if (elems->wmm_info && elems->wmm_info_len == 7
	    && elems->wmm_info[5] == 1)
		qos_info = elems->wmm_info[6];
	else if (elems->wmm_param && elems->wmm_param_len == 24
		 && elems->wmm_param[5] == 1)
		qos_info = elems->wmm_param[6];
	else
		/* no valid wmm information or parameter element found */
		return false;

	return qos_info & IEEE80211_WMM_IE_AP_QOSINFO_UAPSD;
}

77
struct ieee80211_bss *
78 79 80 81 82
ieee80211_bss_info_update(struct ieee80211_local *local,
			  struct ieee80211_rx_status *rx_status,
			  struct ieee80211_mgmt *mgmt,
			  size_t len,
			  struct ieee802_11_elems *elems,
83 84
			  struct ieee80211_channel *channel,
			  bool beacon)
85
{
86
	struct cfg80211_bss *cbss;
87
	struct ieee80211_bss *bss;
88
	int clen, srlen;
89 90
	s32 signal = 0;

J
Johannes Berg 已提交
91
	if (local->hw.flags & IEEE80211_HW_SIGNAL_DBM)
92
		signal = rx_status->signal * 100;
J
Johannes Berg 已提交
93
	else if (local->hw.flags & IEEE80211_HW_SIGNAL_UNSPEC)
94 95
		signal = (rx_status->signal * 100) / local->hw.max_signal;

96 97
	cbss = cfg80211_inform_bss_frame(local->hw.wiphy, channel,
					 mgmt, len, signal, GFP_ATOMIC);
98

99
	if (!cbss)
100 101
		return NULL;

102 103
	cbss->free_priv = ieee80211_rx_bss_free;
	bss = (void *)cbss->priv;
104 105 106 107 108 109 110 111 112 113 114 115 116

	/* save the ERP value so that it is available at association time */
	if (elems->erp_info && elems->erp_info_len >= 1) {
		bss->erp_value = elems->erp_info[0];
		bss->has_erp_value = 1;
	}

	if (elems->tim) {
		struct ieee80211_tim_ie *tim_ie =
			(struct ieee80211_tim_ie *)elems->tim;
		bss->dtim_period = tim_ie->dtim_period;
	}

117 118 119 120
	/* If the beacon had no TIM IE, or it was invalid, use 1 */
	if (beacon && !bss->dtim_period)
		bss->dtim_period = 1;

121 122
	/* replace old supported rates if we get new values */
	srlen = 0;
123
	if (elems->supp_rates) {
124
		clen = IEEE80211_MAX_SUPP_RATES;
125 126
		if (clen > elems->supp_rates_len)
			clen = elems->supp_rates_len;
127 128
		memcpy(bss->supp_rates, elems->supp_rates, clen);
		srlen += clen;
129 130
	}
	if (elems->ext_supp_rates) {
131
		clen = IEEE80211_MAX_SUPP_RATES - srlen;
132 133
		if (clen > elems->ext_supp_rates_len)
			clen = elems->ext_supp_rates_len;
134 135
		memcpy(bss->supp_rates + srlen, elems->ext_supp_rates, clen);
		srlen += clen;
136
	}
137 138
	if (srlen)
		bss->supp_rates_len = srlen;
139 140

	bss->wmm_used = elems->wmm_param || elems->wmm_info;
K
Kalle Valo 已提交
141
	bss->uapsd_supported = is_uapsd_supported(elems);
142 143 144 145 146 147

	if (!beacon)
		bss->last_probe_resp = jiffies;

	return bss;
}
148

149
ieee80211_rx_result
150
ieee80211_scan_rx(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
151
{
152
	struct ieee80211_rx_status *rx_status = IEEE80211_SKB_RXCB(skb);
153
	struct ieee80211_mgmt *mgmt;
154
	struct ieee80211_bss *bss;
155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172
	u8 *elements;
	struct ieee80211_channel *channel;
	size_t baselen;
	int freq;
	__le16 fc;
	bool presp, beacon = false;
	struct ieee802_11_elems elems;

	if (skb->len < 2)
		return RX_DROP_UNUSABLE;

	mgmt = (struct ieee80211_mgmt *) skb->data;
	fc = mgmt->frame_control;

	if (ieee80211_is_ctl(fc))
		return RX_CONTINUE;

	if (skb->len < 24)
173
		return RX_CONTINUE;
174 175 176 177

	presp = ieee80211_is_probe_resp(fc);
	if (presp) {
		/* ignore ProbeResp to foreign address */
178
		if (memcmp(mgmt->da, sdata->vif.addr, ETH_ALEN))
179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198
			return RX_DROP_MONITOR;

		presp = true;
		elements = mgmt->u.probe_resp.variable;
		baselen = offsetof(struct ieee80211_mgmt, u.probe_resp.variable);
	} else {
		beacon = ieee80211_is_beacon(fc);
		baselen = offsetof(struct ieee80211_mgmt, u.beacon.variable);
		elements = mgmt->u.beacon.variable;
	}

	if (!presp && !beacon)
		return RX_CONTINUE;

	if (baselen > skb->len)
		return RX_DROP_MONITOR;

	ieee802_11_parse_elems(elements, skb->len - baselen, &elems);

	if (elems.ds_params && elems.ds_params_len == 1)
199 200
		freq = ieee80211_channel_to_frequency(elems.ds_params[0],
						      rx_status->band);
201 202 203 204 205 206 207 208 209 210
	else
		freq = rx_status->freq;

	channel = ieee80211_get_channel(sdata->local->hw.wiphy, freq);

	if (!channel || channel->flags & IEEE80211_CHAN_DISABLED)
		return RX_DROP_MONITOR;

	bss = ieee80211_bss_info_update(sdata->local, rx_status,
					mgmt, skb->len, &elems,
211
					channel, beacon);
212 213
	if (bss)
		ieee80211_rx_bss_put(sdata->local, bss);
214

215 216 217 218 219 220 221 222
	/* If we are on-operating-channel, and this packet is for the
	 * current channel, pass the pkt on up the stack so that
	 * the rest of the stack can make use of it.
	 */
	if (ieee80211_cfg_on_oper_channel(sdata->local)
	    && (channel == sdata->local->oper_channel))
		return RX_CONTINUE;

223 224 225 226
	dev_kfree_skb(skb);
	return RX_QUEUED;
}

227 228 229 230
/* return false if no more work */
static bool ieee80211_prep_hw_scan(struct ieee80211_local *local)
{
	struct cfg80211_scan_request *req = local->scan_req;
231
	struct ieee80211_sub_if_data *sdata = local->scan_sdata;
232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254
	enum ieee80211_band band;
	int i, ielen, n_chans;

	do {
		if (local->hw_scan_band == IEEE80211_NUM_BANDS)
			return false;

		band = local->hw_scan_band;
		n_chans = 0;
		for (i = 0; i < req->n_channels; i++) {
			if (req->channels[i]->band == band) {
				local->hw_scan_req->channels[n_chans] =
							req->channels[i];
				n_chans++;
			}
		}

		local->hw_scan_band++;
	} while (!n_chans);

	local->hw_scan_req->n_channels = n_chans;

	ielen = ieee80211_build_preq_ies(local, (u8 *)local->hw_scan_req->ie,
255 256
					 req->ie, req->ie_len, band,
					 sdata->rc_rateidx_mask[band], 0);
257 258 259 260 261
	local->hw_scan_req->ie_len = ielen;

	return true;
}

262
static void __ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted,
263
				       bool was_hw_scan)
264 265
{
	struct ieee80211_local *local = hw_to_local(hw);
266 267
	bool on_oper_chan;
	bool enable_beacons = false;
268

269
	lockdep_assert_held(&local->mtx);
270

271 272 273 274 275 276 277 278
	/*
	 * It's ok to abort a not-yet-running scan (that
	 * we have one at all will be verified by checking
	 * local->scan_req next), but not to complete it
	 * successfully.
	 */
	if (WARN_ON(!local->scanning && !aborted))
		aborted = true;
279

280
	if (WARN_ON(!local->scan_req))
281
		return;
282

283
	if (was_hw_scan && !aborted && ieee80211_prep_hw_scan(local)) {
284 285
		int rc = drv_hw_scan(local, local->scan_sdata, local->hw_scan_req);
		if (rc == 0)
286
			return;
287 288 289 290
	}

	kfree(local->hw_scan_req);
	local->hw_scan_req = NULL;
291

292
	if (local->scan_req != local->int_scan_req)
293 294
		cfg80211_scan_done(local->scan_req, aborted);
	local->scan_req = NULL;
295
	local->scan_sdata = NULL;
296

297
	local->scanning = 0;
J
Johannes Berg 已提交
298
	local->scan_channel = NULL;
299

300 301
	on_oper_chan = ieee80211_cfg_on_oper_channel(local);

302
	if (was_hw_scan || !on_oper_chan)
303
		ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
304
	else
305 306
		/* Set power back to normal operating levels. */
		ieee80211_hw_config(local, 0);
307

308
	if (!was_hw_scan) {
309
		bool on_oper_chan2;
310 311
		ieee80211_configure_filter(local);
		drv_sw_scan_complete(local);
312 313 314 315 316 317 318
		on_oper_chan2 = ieee80211_cfg_on_oper_channel(local);
		/* We should always be on-channel at this point. */
		WARN_ON(!on_oper_chan2);
		if (on_oper_chan2 && (on_oper_chan != on_oper_chan2))
			enable_beacons = true;

		ieee80211_offchannel_return(local, enable_beacons, true);
319
	}
320

J
Johannes Berg 已提交
321
	ieee80211_recalc_idle(local);
322

323
	ieee80211_mlme_notify_scan_completed(local);
324
	ieee80211_ibss_notify_scan_completed(local);
325
	ieee80211_mesh_notify_scan_completed(local);
J
Johannes Berg 已提交
326
	ieee80211_queue_work(&local->hw, &local->work_work);
327
}
328 329 330 331 332 333 334 335 336 337 338 339

void ieee80211_scan_completed(struct ieee80211_hw *hw, bool aborted)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_scan_completed(local, aborted);

	set_bit(SCAN_COMPLETED, &local->scanning);
	if (aborted)
		set_bit(SCAN_ABORTED, &local->scanning);
	ieee80211_queue_delayed_work(&local->hw, &local->scan_work, 0);
}
340 341
EXPORT_SYMBOL(ieee80211_scan_completed);

342 343 344 345 346 347 348 349 350 351 352 353 354 355 356
static int ieee80211_start_sw_scan(struct ieee80211_local *local)
{
	/*
	 * Hardware/driver doesn't support hw_scan, so use software
	 * scanning instead. First send a nullfunc frame with power save
	 * bit on so that AP will buffer the frames for us while we are not
	 * listening, then send probe requests to each channel and wait for
	 * the responses. After all channels are scanned, tune back to the
	 * original channel and send a nullfunc frame with power save bit
	 * off to trigger the AP to send us all the buffered frames.
	 *
	 * Note that while local->sw_scanning is true everything else but
	 * nullfunc frames and probe requests will be dropped in
	 * ieee80211_tx_h_check_assoc().
	 */
357
	drv_sw_scan_start(local);
358

359
	local->leave_oper_channel_time = 0;
360
	local->next_scan_state = SCAN_DECISION;
361 362
	local->scan_channel_idx = 0;

363 364 365 366 367
	/* We always want to use off-channel PS, even if we
	 * are not really leaving oper-channel.  Don't
	 * tell the AP though, as long as we are on-channel.
	 */
	ieee80211_offchannel_enable_all_ps(local, false);
368

369
	ieee80211_configure_filter(local);
370

371 372 373
	/* We need to set power level at maximum rate for scanning. */
	ieee80211_hw_config(local, 0);

374 375 376
	ieee80211_queue_delayed_work(&local->hw,
				     &local->scan_work,
				     IEEE80211_CHANNEL_TIME);
377 378 379 380 381 382 383 384 385 386 387

	return 0;
}


static int __ieee80211_start_scan(struct ieee80211_sub_if_data *sdata,
				  struct cfg80211_scan_request *req)
{
	struct ieee80211_local *local = sdata->local;
	int rc;

388 389
	lockdep_assert_held(&local->mtx);

390 391 392
	if (local->scan_req)
		return -EBUSY;

393 394
	if (!list_empty(&local->work_list)) {
		/* wait for the work to finish/time out */
395 396 397 398 399
		local->scan_req = req;
		local->scan_sdata = sdata;
		return 0;
	}

400 401 402
	if (local->ops->hw_scan) {
		u8 *ies;

403 404 405 406 407 408
		local->hw_scan_req = kmalloc(
				sizeof(*local->hw_scan_req) +
				req->n_channels * sizeof(req->channels[0]) +
				2 + IEEE80211_MAX_SSID_LEN + local->scan_ies_len +
				req->ie_len, GFP_KERNEL);
		if (!local->hw_scan_req)
409 410
			return -ENOMEM;

411 412 413 414 415 416 417 418
		local->hw_scan_req->ssids = req->ssids;
		local->hw_scan_req->n_ssids = req->n_ssids;
		ies = (u8 *)local->hw_scan_req +
			sizeof(*local->hw_scan_req) +
			req->n_channels * sizeof(req->channels[0]);
		local->hw_scan_req->ie = ies;

		local->hw_scan_band = 0;
419 420 421 422 423 424 425 426

		/*
		 * After allocating local->hw_scan_req, we must
		 * go through until ieee80211_prep_hw_scan(), so
		 * anything that might be changed here and leave
		 * this function early must not go after this
		 * allocation.
		 */
427 428 429 430 431 432
	}

	local->scan_req = req;
	local->scan_sdata = sdata;

	if (local->ops->hw_scan)
433
		__set_bit(SCAN_HW_SCANNING, &local->scanning);
434
	else
435
		__set_bit(SCAN_SW_SCANNING, &local->scanning);
436

J
Johannes Berg 已提交
437
	ieee80211_recalc_idle(local);
438

439 440
	if (local->ops->hw_scan) {
		WARN_ON(!ieee80211_prep_hw_scan(local));
441
		rc = drv_hw_scan(local, sdata, local->hw_scan_req);
442
	} else
443 444 445
		rc = ieee80211_start_sw_scan(local);

	if (rc) {
446 447
		kfree(local->hw_scan_req);
		local->hw_scan_req = NULL;
448
		local->scanning = 0;
449

J
Johannes Berg 已提交
450 451
		ieee80211_recalc_idle(local);

452 453 454 455 456 457 458
		local->scan_req = NULL;
		local->scan_sdata = NULL;
	}

	return rc;
}

459 460 461 462 463 464 465 466 467 468 469 470
static unsigned long
ieee80211_scan_get_channel_time(struct ieee80211_channel *chan)
{
	/*
	 * TODO: channel switching also consumes quite some time,
	 * add that delay as well to get a better estimation
	 */
	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
		return IEEE80211_PASSIVE_CHANNEL_TIME;
	return IEEE80211_PROBE_DELAY + IEEE80211_CHANNEL_TIME;
}

471 472
static void ieee80211_scan_state_decision(struct ieee80211_local *local,
					  unsigned long *next_delay)
H
Helmut Schaa 已提交
473
{
474
	bool associated = false;
475 476 477 478
	bool tx_empty = true;
	bool bad_latency;
	bool listen_int_exceeded;
	unsigned long min_beacon_int = 0;
479
	struct ieee80211_sub_if_data *sdata;
480
	struct ieee80211_channel *next_chan;
481

482 483 484 485 486
	/*
	 * check if at least one STA interface is associated,
	 * check if at least one STA interface has pending tx frames
	 * and grab the lowest used beacon interval
	 */
487 488
	mutex_lock(&local->iflist_mtx);
	list_for_each_entry(sdata, &local->interfaces, list) {
489
		if (!ieee80211_sdata_running(sdata))
490 491 492 493 494
			continue;

		if (sdata->vif.type == NL80211_IFTYPE_STATION) {
			if (sdata->u.mgd.associated) {
				associated = true;
495 496 497 498 499 500 501 502 503 504

				if (sdata->vif.bss_conf.beacon_int <
				    min_beacon_int || min_beacon_int == 0)
					min_beacon_int =
						sdata->vif.bss_conf.beacon_int;

				if (!qdisc_all_tx_empty(sdata->dev)) {
					tx_empty = false;
					break;
				}
505 506 507 508 509
			}
		}
	}
	mutex_unlock(&local->iflist_mtx);

510 511 512 513
	next_chan = local->scan_req->channels[local->scan_channel_idx];

	if (ieee80211_cfg_on_oper_channel(local)) {
		/* We're currently on operating channel. */
514
		if (next_chan == local->oper_channel)
515 516 517 518 519 520 521 522 523
			/* We don't need to move off of operating channel. */
			local->next_scan_state = SCAN_SET_CHANNEL;
		else
			/*
			 * We do need to leave operating channel, as next
			 * scan is somewhere else.
			 */
			local->next_scan_state = SCAN_LEAVE_OPER_CHANNEL;
	} else {
524 525
		/*
		 * we're currently scanning a different channel, let's
526 527 528 529 530 531 532 533 534 535 536 537
		 * see if we can scan another channel without interfering
		 * with the current traffic situation.
		 *
		 * Since we don't know if the AP has pending frames for us
		 * we can only check for our tx queues and use the current
		 * pm_qos requirements for rx. Hence, if no tx traffic occurs
		 * at all we will scan as many channels in a row as the pm_qos
		 * latency allows us to. Additionally we also check for the
		 * currently negotiated listen interval to prevent losing
		 * frames unnecessarily.
		 *
		 * Otherwise switch back to the operating channel.
538
		 */
539 540 541 542

		bad_latency = time_after(jiffies +
				ieee80211_scan_get_channel_time(next_chan),
				local->leave_oper_channel_time +
543
				usecs_to_jiffies(pm_qos_request(PM_QOS_NETWORK_LATENCY)));
544 545 546 547 548 549 550 551 552

		listen_int_exceeded = time_after(jiffies +
				ieee80211_scan_get_channel_time(next_chan),
				local->leave_oper_channel_time +
				usecs_to_jiffies(min_beacon_int * 1024) *
				local->hw.conf.listen_interval);

		if (associated && ( !tx_empty || bad_latency ||
		    listen_int_exceeded))
553
			local->next_scan_state = SCAN_ENTER_OPER_CHANNEL;
554
		else
555
			local->next_scan_state = SCAN_SET_CHANNEL;
556 557
	}

558 559 560
	*next_delay = 0;
}

561 562 563
static void ieee80211_scan_state_leave_oper_channel(struct ieee80211_local *local,
						    unsigned long *next_delay)
{
564 565 566 567
	/* PS will already be in off-channel mode,
	 * we do that once at the beginning of scanning.
	 */
	ieee80211_offchannel_stop_vifs(local, false);
568

569 570 571 572 573 574 575 576 577
	/*
	 * What if the nullfunc frames didn't arrive?
	 */
	drv_flush(local, false);
	if (local->ops->flush)
		*next_delay = 0;
	else
		*next_delay = HZ / 10;

578 579 580
	/* remember when we left the operating channel */
	local->leave_oper_channel_time = jiffies;

581
	/* advance to the next channel to be scanned */
582
	local->next_scan_state = SCAN_SET_CHANNEL;
583 584 585 586 587 588 589
}

static void ieee80211_scan_state_enter_oper_channel(struct ieee80211_local *local,
						    unsigned long *next_delay)
{
	/* switch back to the operating channel */
	local->scan_channel = NULL;
590 591
	if (!ieee80211_cfg_on_oper_channel(local))
		ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL);
592 593

	/*
594 595 596
	 * Re-enable vifs and beaconing.  Leave PS
	 * in off-channel state..will put that back
	 * on-channel at the end of scanning.
597
	 */
598
	ieee80211_offchannel_return(local, true, false);
599 600

	*next_delay = HZ / 5;
601
	local->next_scan_state = SCAN_DECISION;
602 603
}

604 605 606 607 608 609
static void ieee80211_scan_state_set_channel(struct ieee80211_local *local,
					     unsigned long *next_delay)
{
	int skip;
	struct ieee80211_channel *chan;

H
Helmut Schaa 已提交
610 611 612
	skip = 0;
	chan = local->scan_req->channels[local->scan_channel_idx];

J
Johannes Berg 已提交
613
	local->scan_channel = chan;
614 615

	/* Only call hw-config if we really need to change channels. */
616
	if (chan != local->hw.conf.channel)
617 618
		if (ieee80211_hw_config(local, IEEE80211_CONF_CHANGE_CHANNEL))
			skip = 1;
H
Helmut Schaa 已提交
619 620 621 622

	/* advance state machine to next channel/band */
	local->scan_channel_idx++;

623 624 625
	if (skip) {
		/* if we skip this channel return to the decision state */
		local->next_scan_state = SCAN_DECISION;
626
		return;
627
	}
H
Helmut Schaa 已提交
628 629 630 631 632 633 634 635 636 637 638 639 640 641

	/*
	 * Probe delay is used to update the NAV, cf. 11.1.3.2.2
	 * (which unfortunately doesn't say _why_ step a) is done,
	 * but it waits for the probe delay or until a frame is
	 * received - and the received frame would update the NAV).
	 * For now, we do not support waiting until a frame is
	 * received.
	 *
	 * In any case, it is not necessary for a passive scan.
	 */
	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN ||
	    !local->scan_req->n_ssids) {
		*next_delay = IEEE80211_PASSIVE_CHANNEL_TIME;
642
		local->next_scan_state = SCAN_DECISION;
643
		return;
H
Helmut Schaa 已提交
644 645
	}

646
	/* active scan, send probes */
H
Helmut Schaa 已提交
647
	*next_delay = IEEE80211_PROBE_DELAY;
648
	local->next_scan_state = SCAN_SEND_PROBE;
H
Helmut Schaa 已提交
649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668
}

static void ieee80211_scan_state_send_probe(struct ieee80211_local *local,
					    unsigned long *next_delay)
{
	int i;
	struct ieee80211_sub_if_data *sdata = local->scan_sdata;

	for (i = 0; i < local->scan_req->n_ssids; i++)
		ieee80211_send_probe_req(
			sdata, NULL,
			local->scan_req->ssids[i].ssid,
			local->scan_req->ssids[i].ssid_len,
			local->scan_req->ie, local->scan_req->ie_len);

	/*
	 * After sending probe requests, wait for probe responses
	 * on the channel.
	 */
	*next_delay = IEEE80211_CHANNEL_TIME;
669
	local->next_scan_state = SCAN_DECISION;
H
Helmut Schaa 已提交
670 671
}

672
void ieee80211_scan_work(struct work_struct *work)
673 674 675
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local, scan_work.work);
676
	struct ieee80211_sub_if_data *sdata;
677
	unsigned long next_delay = 0;
678
	bool aborted, hw_scan;
679

680
	mutex_lock(&local->mtx);
681

682 683
	sdata = local->scan_sdata;

684
	if (test_and_clear_bit(SCAN_COMPLETED, &local->scanning)) {
685
		aborted = test_and_clear_bit(SCAN_ABORTED, &local->scanning);
686
		goto out_complete;
687 688
	}

689 690
	if (!sdata || !local->scan_req)
		goto out;
691

692
	if (local->scan_req && !local->scanning) {
693 694 695 696
		struct cfg80211_scan_request *req = local->scan_req;
		int rc;

		local->scan_req = NULL;
697
		local->scan_sdata = NULL;
698 699

		rc = __ieee80211_start_scan(sdata, req);
700
		if (rc) {
701 702
			/* need to complete scan in cfg80211 */
			local->scan_req = req;
703 704 705 706
			aborted = true;
			goto out_complete;
		} else
			goto out;
707 708
	}

709 710 711
	/*
	 * Avoid re-scheduling when the sdata is going away.
	 */
712
	if (!ieee80211_sdata_running(sdata)) {
713 714
		aborted = true;
		goto out_complete;
715
	}
716

717 718 719 720 721
	/*
	 * as long as no delay is required advance immediately
	 * without scheduling a new work
	 */
	do {
722 723 724 725 726
		if (!ieee80211_sdata_running(sdata)) {
			aborted = true;
			goto out_complete;
		}

727
		switch (local->next_scan_state) {
728
		case SCAN_DECISION:
729 730 731 732 733 734
			/* if no more bands/channels left, complete scan */
			if (local->scan_channel_idx >= local->scan_req->n_channels) {
				aborted = false;
				goto out_complete;
			}
			ieee80211_scan_state_decision(local, &next_delay);
735
			break;
736 737 738
		case SCAN_SET_CHANNEL:
			ieee80211_scan_state_set_channel(local, &next_delay);
			break;
739 740 741
		case SCAN_SEND_PROBE:
			ieee80211_scan_state_send_probe(local, &next_delay);
			break;
742 743 744 745 746 747
		case SCAN_LEAVE_OPER_CHANNEL:
			ieee80211_scan_state_leave_oper_channel(local, &next_delay);
			break;
		case SCAN_ENTER_OPER_CHANNEL:
			ieee80211_scan_state_enter_oper_channel(local, &next_delay);
			break;
748 749
		}
	} while (next_delay == 0);
750

751
	ieee80211_queue_delayed_work(&local->hw, &local->scan_work, next_delay);
752
	goto out;
753 754

out_complete:
755
	hw_scan = test_bit(SCAN_HW_SCANNING, &local->scanning);
756
	__ieee80211_scan_completed(&local->hw, aborted, hw_scan);
757 758
out:
	mutex_unlock(&local->mtx);
759 760
}

761 762
int ieee80211_request_scan(struct ieee80211_sub_if_data *sdata,
			   struct cfg80211_scan_request *req)
763
{
764
	int res;
765

766
	mutex_lock(&sdata->local->mtx);
767
	res = __ieee80211_start_scan(sdata, req);
768
	mutex_unlock(&sdata->local->mtx);
769

770
	return res;
771 772
}

773
int ieee80211_request_internal_scan(struct ieee80211_sub_if_data *sdata,
J
Johannes Berg 已提交
774 775
				    const u8 *ssid, u8 ssid_len,
				    struct ieee80211_channel *chan)
776 777
{
	struct ieee80211_local *local = sdata->local;
778
	int ret = -EBUSY;
779
	enum ieee80211_band band;
780

781
	mutex_lock(&local->mtx);
782

783 784 785
	/* busy scanning */
	if (local->scan_req)
		goto unlock;
J
Johannes Berg 已提交
786

J
Johannes Berg 已提交
787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810
	/* fill internal scan request */
	if (!chan) {
		int i, nchan = 0;

		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
			if (!local->hw.wiphy->bands[band])
				continue;
			for (i = 0;
			     i < local->hw.wiphy->bands[band]->n_channels;
			     i++) {
				local->int_scan_req->channels[nchan] =
				    &local->hw.wiphy->bands[band]->channels[i];
				nchan++;
			}
		}

		local->int_scan_req->n_channels = nchan;
	} else {
		local->int_scan_req->channels[0] = chan;
		local->int_scan_req->n_channels = 1;
	}

	local->int_scan_req->ssids = &local->scan_ssid;
	local->int_scan_req->n_ssids = 1;
811 812
	memcpy(local->int_scan_req->ssids[0].ssid, ssid, IEEE80211_MAX_SSID_LEN);
	local->int_scan_req->ssids[0].ssid_len = ssid_len;
J
Johannes Berg 已提交
813

814
	ret = __ieee80211_start_scan(sdata, sdata->local->int_scan_req);
815
 unlock:
816
	mutex_unlock(&local->mtx);
817
	return ret;
818
}
819

820 821 822
/*
 * Only call this function when a scan can't be queued -- under RTNL.
 */
823 824 825
void ieee80211_scan_cancel(struct ieee80211_local *local)
{
	/*
826
	 * We are canceling software scan, or deferred scan that was not
827 828 829 830 831 832 833 834 835 836 837
	 * yet really started (see __ieee80211_start_scan ).
	 *
	 * Regarding hardware scan:
	 * - we can not call  __ieee80211_scan_completed() as when
	 *   SCAN_HW_SCANNING bit is set this function change
	 *   local->hw_scan_req to operate on 5G band, what race with
	 *   driver which can use local->hw_scan_req
	 *
	 * - we can not cancel scan_work since driver can schedule it
	 *   by ieee80211_scan_completed(..., true) to finish scan
	 *
838 839 840
	 * Hence we only call the cancel_hw_scan() callback, but the low-level
	 * driver is still responsible for calling ieee80211_scan_completed()
	 * after the scan was completed/aborted.
841
	 */
842

843
	mutex_lock(&local->mtx);
844 845 846 847 848 849 850
	if (!local->scan_req)
		goto out;

	if (test_bit(SCAN_HW_SCANNING, &local->scanning)) {
		if (local->ops->cancel_hw_scan)
			drv_cancel_hw_scan(local, local->scan_sdata);
		goto out;
851
	}
852 853 854 855 856 857 858 859 860 861

	/*
	 * If the work is currently running, it must be blocked on
	 * the mutex, but we'll set scan_sdata = NULL and it'll
	 * simply exit once it acquires the mutex.
	 */
	cancel_delayed_work(&local->scan_work);
	/* and clean up */
	__ieee80211_scan_completed(&local->hw, true, false);
out:
862
	mutex_unlock(&local->mtx);
863
}
864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914

int ieee80211_request_sched_scan_start(struct ieee80211_sub_if_data *sdata,
				       struct cfg80211_sched_scan_request *req)
{
	struct ieee80211_local *local = sdata->local;
	int ret, i;

	mutex_lock(&sdata->local->mtx);

	if (local->sched_scanning) {
		ret = -EBUSY;
		goto out;
	}

	if (!local->ops->sched_scan_start) {
		ret = -ENOTSUPP;
		goto out;
	}

	for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
		local->sched_scan_ies.ie[i] = kzalloc(2 +
						      IEEE80211_MAX_SSID_LEN +
						      local->scan_ies_len,
						      GFP_KERNEL);
		if (!local->sched_scan_ies.ie[i]) {
			ret = -ENOMEM;
			goto out_free;
		}

		local->sched_scan_ies.len[i] =
			ieee80211_build_preq_ies(local,
						 local->sched_scan_ies.ie[i],
						 req->ie, req->ie_len, i,
						 (u32) -1, 0);
	}

	ret = drv_sched_scan_start(local, sdata, req,
				   &local->sched_scan_ies);
	if (ret == 0) {
		local->sched_scanning = true;
		goto out;
	}

out_free:
	while (i > 0)
		kfree(local->sched_scan_ies.ie[--i]);
out:
	mutex_unlock(&sdata->local->mtx);
	return ret;
}

915
int ieee80211_request_sched_scan_stop(struct ieee80211_sub_if_data *sdata)
916 917 918 919 920 921 922 923 924 925 926 927 928 929 930
{
	struct ieee80211_local *local = sdata->local;
	int ret = 0, i;

	mutex_lock(&sdata->local->mtx);

	if (!local->ops->sched_scan_stop) {
		ret = -ENOTSUPP;
		goto out;
	}

	if (local->sched_scanning) {
		for (i = 0; i < IEEE80211_NUM_BANDS; i++)
			kfree(local->sched_scan_ies.ie[i]);

931
		drv_sched_scan_stop(local, sdata);
932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949
		local->sched_scanning = false;
	}
out:
	mutex_unlock(&sdata->local->mtx);

	return ret;
}

void ieee80211_sched_scan_results(struct ieee80211_hw *hw)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_sched_scan_results(local);

	cfg80211_sched_scan_results(hw->wiphy);
}
EXPORT_SYMBOL(ieee80211_sched_scan_results);

950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973
void ieee80211_sched_scan_stopped_work(struct work_struct *work)
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local,
			     sched_scan_stopped_work);
	int i;

	mutex_lock(&local->mtx);

	if (!local->sched_scanning) {
		mutex_unlock(&local->mtx);
		return;
	}

	for (i = 0; i < IEEE80211_NUM_BANDS; i++)
		kfree(local->sched_scan_ies.ie[i]);

	local->sched_scanning = false;

	mutex_unlock(&local->mtx);

	cfg80211_sched_scan_stopped(local->hw.wiphy);
}

974 975 976 977 978 979
void ieee80211_sched_scan_stopped(struct ieee80211_hw *hw)
{
	struct ieee80211_local *local = hw_to_local(hw);

	trace_api_sched_scan_stopped(local);

980
	ieee80211_queue_work(&local->hw, &local->sched_scan_stopped_work);
981 982
}
EXPORT_SYMBOL(ieee80211_sched_scan_stopped);