sta_info.c 20.6 KB
Newer Older
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16
/*
 * Copyright 2002-2005, Instant802 Networks, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

#include <linux/module.h>
#include <linux/init.h>
#include <linux/netdevice.h>
#include <linux/types.h>
#include <linux/slab.h>
#include <linux/skbuff.h>
#include <linux/if_arp.h>
17
#include <linux/timer.h>
18
#include <linux/rtnetlink.h>
19 20 21 22 23

#include <net/mac80211.h>
#include "ieee80211_i.h"
#include "ieee80211_rate.h"
#include "sta_info.h"
J
Jiri Benc 已提交
24
#include "debugfs_sta.h"
25
#include "mesh.h"
26

27 28 29 30 31 32 33
/**
 * DOC: STA information lifetime rules
 *
 * STA info structures (&struct sta_info) are managed in a hash table
 * for faster lookup and a list for iteration. They are managed using
 * RCU, i.e. access to the list and hash table is protected by RCU.
 *
34 35 36 37 38
 * Upon allocating a STA info structure with sta_info_alloc(), the caller owns
 * that structure. It must then either destroy it using sta_info_destroy()
 * (which is pretty useless) or insert it into the hash table using
 * sta_info_insert() which demotes the reference from ownership to a regular
 * RCU-protected reference; if the function is called without protection by an
39 40 41 42 43 44
 * RCU critical section the reference is instantly invalidated. Note that the
 * caller may not do much with the STA info before inserting it, in particular,
 * it may not start any mesh peer link management or add encryption keys.
 *
 * When the insertion fails (sta_info_insert()) returns non-zero), the
 * structure will have been freed by sta_info_insert()!
45 46 47 48
 *
 * Because there are debugfs entries for each station, and adding those
 * must be able to sleep, it is also possible to "pin" a station entry,
 * that means it can be removed from the hash table but not be freed.
49 50
 * See the comment in __sta_info_unlink() for more information, this is
 * an internal capability only.
51 52
 *
 * In order to remove a STA info structure, the caller needs to first
J
Johannes Berg 已提交
53
 * unlink it (sta_info_unlink()) from the list and hash tables and
54 55
 * then destroy it while holding the RTNL; sta_info_destroy() will wait
 * for an RCU grace period to elapse before actually freeing it. Due to
56
 * the pinning and the possibility of multiple callers trying to remove
J
Johannes Berg 已提交
57
 * the same STA info at the same time, sta_info_unlink() can clear the
58 59 60
 * STA info pointer it is passed to indicate that the STA info is owned
 * by somebody else now.
 *
J
Johannes Berg 已提交
61
 * If sta_info_unlink() did not clear the pointer then the caller owns
62
 * the STA info structure now and is responsible of destroying it with
J
Johannes Berg 已提交
63
 * a call to sta_info_destroy(), not before RCU synchronisation, of
64 65 66 67 68 69 70
 * course. Note that sta_info_destroy() must be protected by the RTNL.
 *
 * In all other cases, there is no concept of ownership on a STA entry,
 * each structure is owned by the global hash table/list until it is
 * removed. All users of the structure need to be RCU protected so that
 * the structure won't be freed before they are done using it.
 */
71 72

/* Caller must hold local->sta_lock */
73 74
static int sta_info_hash_del(struct ieee80211_local *local,
			     struct sta_info *sta)
75 76 77 78 79
{
	struct sta_info *s;

	s = local->sta_hash[STA_HASH(sta->addr)];
	if (!s)
80 81
		return -ENOENT;
	if (s == sta) {
82 83
		rcu_assign_pointer(local->sta_hash[STA_HASH(sta->addr)],
				   s->hnext);
84
		return 0;
85 86
	}

87
	while (s->hnext && s->hnext != sta)
88
		s = s->hnext;
89
	if (s->hnext) {
90
		rcu_assign_pointer(s->hnext, sta->hnext);
91 92
		return 0;
	}
93

94
	return -ENOENT;
95 96
}

97
/* protected by RCU */
98 99
static struct sta_info *__sta_info_find(struct ieee80211_local *local,
					u8 *addr)
100 101 102
{
	struct sta_info *sta;

103
	sta = rcu_dereference(local->sta_hash[STA_HASH(addr)]);
104
	while (sta) {
105
		if (compare_ether_addr(sta->addr, addr) == 0)
106
			break;
107
		sta = rcu_dereference(sta->hnext);
108
	}
109 110 111 112 113
	return sta;
}

struct sta_info *sta_info_get(struct ieee80211_local *local, u8 *addr)
{
114
	return __sta_info_find(local, addr);
115 116 117
}
EXPORT_SYMBOL(sta_info_get);

118 119 120 121 122 123
struct sta_info *sta_info_get_by_idx(struct ieee80211_local *local, int idx,
				     struct net_device *dev)
{
	struct sta_info *sta;
	int i = 0;

124
	list_for_each_entry_rcu(sta, &local->sta_list, list) {
125 126
		if (dev && dev != sta->sdata->dev)
			continue;
127 128 129 130
		if (i < idx) {
			++i;
			continue;
		}
131
		return sta;
132 133 134 135
	}

	return NULL;
}
136

137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160
/**
 * __sta_info_free - internal STA free helper
 *
 * @sta: STA info to free
 *
 * This function must undo everything done by sta_info_alloc()
 * that may happen before sta_info_insert().
 */
static void __sta_info_free(struct ieee80211_local *local,
			    struct sta_info *sta)
{
	DECLARE_MAC_BUF(mbuf);

	rate_control_free_sta(sta->rate_ctrl, sta->rate_ctrl_priv);
	rate_control_put(sta->rate_ctrl);

#ifdef CONFIG_MAC80211_VERBOSE_DEBUG
	printk(KERN_DEBUG "%s: Destroyed STA %s\n",
	       wiphy_name(local->hw.wiphy), print_mac(mbuf, sta->addr));
#endif /* CONFIG_MAC80211_VERBOSE_DEBUG */

	kfree(sta);
}

161
void sta_info_destroy(struct sta_info *sta)
162
{
163
	struct ieee80211_local *local;
164
	struct sk_buff *skb;
165
	int i;
J
Johannes Berg 已提交
166

167 168 169
	ASSERT_RTNL();
	might_sleep();

J
Johannes Berg 已提交
170 171
	if (!sta)
		return;
172

173
	local = sta->local;
174 175 176 177 178 179 180 181 182

	rate_control_remove_sta_debugfs(sta);
	ieee80211_sta_debugfs_remove(sta);

#ifdef CONFIG_MAC80211_MESH
	if (ieee80211_vif_is_mesh(&sta->sdata->vif))
		mesh_plink_deactivate(sta);
#endif

183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198
	if (sta->key) {
		/*
		 * NOTE: This will call synchronize_rcu() internally to
		 * make sure no key references can be in use. We rely on
		 * that when we take this branch to make sure nobody can
		 * reference this STA struct any longer!
		 */
		ieee80211_key_free(sta->key);
		WARN_ON(sta->key);
	} else {
		/*
		 * Make sure that nobody can reference this STA struct
		 * any longer.
		 */
		synchronize_rcu();
	}
199 200 201 202 203 204

#ifdef CONFIG_MAC80211_MESH
	if (ieee80211_vif_is_mesh(&sta->sdata->vif))
		del_timer_sync(&sta->plink_timer);
#endif

205 206 207 208
	while ((skb = skb_dequeue(&sta->ps_tx_buf)) != NULL) {
		local->total_ps_buffered--;
		dev_kfree_skb_any(skb);
	}
209 210

	while ((skb = skb_dequeue(&sta->tx_filtered)) != NULL)
211
		dev_kfree_skb_any(skb);
212

213
	for (i = 0; i <  STA_TID_NUM; i++) {
214 215 216 217 218 219 220 221
		spin_lock_bh(&sta->ampdu_mlme.ampdu_rx);
		if (sta->ampdu_mlme.tid_rx[i])
		  del_timer_sync(&sta->ampdu_mlme.tid_rx[i]->session_timer);
		spin_unlock_bh(&sta->ampdu_mlme.ampdu_rx);
		spin_lock_bh(&sta->ampdu_mlme.ampdu_tx);
		if (sta->ampdu_mlme.tid_tx[i])
		  del_timer_sync(&sta->ampdu_mlme.tid_tx[i]->addba_resp_timer);
		spin_unlock_bh(&sta->ampdu_mlme.ampdu_tx);
222
	}
223

224
	__sta_info_free(local, sta);
225 226 227
}


228 229 230
/* Caller must hold local->sta_lock */
static void sta_info_hash_add(struct ieee80211_local *local,
			      struct sta_info *sta)
231
{
232 233
	sta->hnext = local->sta_hash[STA_HASH(sta->addr)];
	rcu_assign_pointer(local->sta_hash[STA_HASH(sta->addr)], sta);
234 235
}

J
Johannes Berg 已提交
236 237
struct sta_info *sta_info_alloc(struct ieee80211_sub_if_data *sdata,
				u8 *addr, gfp_t gfp)
238
{
239
	struct ieee80211_local *local = sdata->local;
240
	struct sta_info *sta;
241
	int i;
J
Johannes Berg 已提交
242
	DECLARE_MAC_BUF(mbuf);
243

J
Johannes Berg 已提交
244
	sta = kzalloc(sizeof(*sta), gfp);
245
	if (!sta)
J
Johannes Berg 已提交
246
		return NULL;
247

248 249 250
	memcpy(sta->addr, addr, ETH_ALEN);
	sta->local = local;
	sta->sdata = sdata;
251 252

	sta->rate_ctrl = rate_control_get(local->rate_ctrl);
253
	sta->rate_ctrl_priv = rate_control_alloc_sta(sta->rate_ctrl,
J
Johannes Berg 已提交
254
						     gfp);
255 256 257
	if (!sta->rate_ctrl_priv) {
		rate_control_put(sta->rate_ctrl);
		kfree(sta);
J
Johannes Berg 已提交
258
		return NULL;
259 260
	}

261
	spin_lock_init(&sta->ampdu_mlme.ampdu_rx);
262
	spin_lock_init(&sta->ampdu_mlme.ampdu_tx);
263 264 265 266 267
	for (i = 0; i < STA_TID_NUM; i++) {
		/* timer_to_tid must be initialized with identity mapping to
		 * enable session_timer's data differentiation. refer to
		 * sta_rx_agg_session_timer_expired for useage */
		sta->timer_to_tid[i] = i;
268 269
		/* tid to tx queue: initialize according to HW (0 is valid) */
		sta->tid_to_tx_q[i] = local->hw.queues;
270 271 272 273 274 275 276
		/* rx */
		sta->ampdu_mlme.tid_state_rx[i] = HT_AGG_STATE_IDLE;
		sta->ampdu_mlme.tid_rx[i] = NULL;
		/* tx */
		sta->ampdu_mlme.tid_state_tx[i] = HT_AGG_STATE_IDLE;
		sta->ampdu_mlme.tid_tx[i] = NULL;
		sta->ampdu_mlme.addba_req_num[i] = 0;
277
	}
278 279
	skb_queue_head_init(&sta->ps_tx_buf);
	skb_queue_head_init(&sta->tx_filtered);
J
Johannes Berg 已提交
280 281 282 283 284 285

#ifdef CONFIG_MAC80211_VERBOSE_DEBUG
	printk(KERN_DEBUG "%s: Allocated STA %s\n",
	       wiphy_name(local->hw.wiphy), print_mac(mbuf, sta->addr));
#endif /* CONFIG_MAC80211_VERBOSE_DEBUG */

286
#ifdef CONFIG_MAC80211_MESH
287
	sta->plink_state = PLINK_LISTEN;
288 289 290 291
	spin_lock_init(&sta->plink_lock);
	init_timer(&sta->plink_timer);
#endif

J
Johannes Berg 已提交
292 293 294 295 296 297 298 299
	return sta;
}

int sta_info_insert(struct sta_info *sta)
{
	struct ieee80211_local *local = sta->local;
	struct ieee80211_sub_if_data *sdata = sta->sdata;
	unsigned long flags;
300
	int err = 0;
J
Johannes Berg 已提交
301 302
	DECLARE_MAC_BUF(mac);

303 304 305 306 307
	/*
	 * Can't be a WARN_ON because it can be triggered through a race:
	 * something inserts a STA (on one CPU) without holding the RTNL
	 * and another CPU turns off the net device.
	 */
308 309 310 311
	if (unlikely(!netif_running(sdata->dev))) {
		err = -ENETDOWN;
		goto out_free;
	}
312

313 314 315 316 317
	if (WARN_ON(compare_ether_addr(sta->addr, sdata->dev->dev_addr) == 0 ||
	            is_multicast_ether_addr(sta->addr))) {
		err = -EINVAL;
		goto out_free;
	}
318

319
	spin_lock_irqsave(&local->sta_lock, flags);
320
	/* check if STA exists already */
J
Johannes Berg 已提交
321
	if (__sta_info_find(local, sta->addr)) {
322
		spin_unlock_irqrestore(&local->sta_lock, flags);
323 324
		err = -EEXIST;
		goto out_free;
325
	}
326 327 328
	list_add(&sta->list, &local->sta_list);
	local->num_sta++;
	sta_info_hash_add(local, sta);
329

330 331
	/* notify driver */
	if (local->ops->sta_notify) {
332
		if (sdata->vif.type == IEEE80211_IF_TYPE_VLAN)
333 334 335
			sdata = sdata->u.vlan.ap;

		local->ops->sta_notify(local_to_hw(local), &sdata->vif,
J
Johannes Berg 已提交
336
				       STA_NOTIFY_ADD, sta->addr);
337
	}
338

339
#ifdef CONFIG_MAC80211_VERBOSE_DEBUG
J
Johannes Berg 已提交
340 341
	printk(KERN_DEBUG "%s: Inserted STA %s\n",
	       wiphy_name(local->hw.wiphy), print_mac(mac, sta->addr));
342 343
#endif /* CONFIG_MAC80211_VERBOSE_DEBUG */

J
Johannes Berg 已提交
344 345
	spin_unlock_irqrestore(&local->sta_lock, flags);

J
Jiri Benc 已提交
346
#ifdef CONFIG_MAC80211_DEBUGFS
347 348
	/*
	 * Debugfs entry adding might sleep, so schedule process
349
	 * context task for adding entry for STAs that do not yet
350 351 352 353
	 * have one.
	 * NOTE: due to auto-freeing semantics this may only be done
	 *       if the insertion is successful!
	 */
354
	queue_work(local->hw.workqueue, &local->sta_debugfs_add);
J
Jiri Benc 已提交
355 356
#endif

J
Johannes Berg 已提交
357 358 359 360
	if (ieee80211_vif_is_mesh(&sdata->vif))
		mesh_accept_plinks_update(sdata);

	return 0;
361 362 363 364
 out_free:
	BUG_ON(!err);
	__sta_info_free(local, sta);
	return err;
365 366
}

367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389
static inline void __bss_tim_set(struct ieee80211_if_ap *bss, u16 aid)
{
	/*
	 * This format has been mandated by the IEEE specifications,
	 * so this line may not be changed to use the __set_bit() format.
	 */
	bss->tim[aid / 8] |= (1 << (aid % 8));
}

static inline void __bss_tim_clear(struct ieee80211_if_ap *bss, u16 aid)
{
	/*
	 * This format has been mandated by the IEEE specifications,
	 * so this line may not be changed to use the __clear_bit() format.
	 */
	bss->tim[aid / 8] &= ~(1 << (aid % 8));
}

static void __sta_info_set_tim_bit(struct ieee80211_if_ap *bss,
				   struct sta_info *sta)
{
	if (bss)
		__bss_tim_set(bss, sta->aid);
390 391
	if (sta->local->ops->set_tim) {
		sta->local->tim_in_locked_section = true;
392
		sta->local->ops->set_tim(local_to_hw(sta->local), sta->aid, 1);
393 394
		sta->local->tim_in_locked_section = false;
	}
395 396 397 398
}

void sta_info_set_tim_bit(struct sta_info *sta)
{
399
	unsigned long flags;
400

401 402 403
	spin_lock_irqsave(&sta->local->sta_lock, flags);
	__sta_info_set_tim_bit(sta->sdata->bss, sta);
	spin_unlock_irqrestore(&sta->local->sta_lock, flags);
404 405 406 407 408 409 410
}

static void __sta_info_clear_tim_bit(struct ieee80211_if_ap *bss,
				     struct sta_info *sta)
{
	if (bss)
		__bss_tim_clear(bss, sta->aid);
411 412
	if (sta->local->ops->set_tim) {
		sta->local->tim_in_locked_section = true;
413
		sta->local->ops->set_tim(local_to_hw(sta->local), sta->aid, 0);
414 415
		sta->local->tim_in_locked_section = false;
	}
416 417 418 419
}

void sta_info_clear_tim_bit(struct sta_info *sta)
{
420
	unsigned long flags;
421

422 423 424
	spin_lock_irqsave(&sta->local->sta_lock, flags);
	__sta_info_clear_tim_bit(sta->sdata->bss, sta);
	spin_unlock_irqrestore(&sta->local->sta_lock, flags);
425 426
}

427 428 429 430 431
/*
 * See comment in __sta_info_unlink,
 * caller must hold local->sta_lock.
 */
static void __sta_info_pin(struct sta_info *sta)
432
{
433 434 435
	WARN_ON(sta->pin_status != STA_INFO_PIN_STAT_NORMAL);
	sta->pin_status = STA_INFO_PIN_STAT_PINNED;
}
436

437 438 439 440 441 442 443 444
/*
 * See comment in __sta_info_unlink, returns sta if it
 * needs to be destroyed.
 */
static struct sta_info *__sta_info_unpin(struct sta_info *sta)
{
	struct sta_info *ret = NULL;
	unsigned long flags;
445

446 447 448 449 450 451 452
	spin_lock_irqsave(&sta->local->sta_lock, flags);
	WARN_ON(sta->pin_status != STA_INFO_PIN_STAT_DESTROY &&
		sta->pin_status != STA_INFO_PIN_STAT_PINNED);
	if (sta->pin_status == STA_INFO_PIN_STAT_DESTROY)
		ret = sta;
	sta->pin_status = STA_INFO_PIN_STAT_NORMAL;
	spin_unlock_irqrestore(&sta->local->sta_lock, flags);
453

454
	return ret;
455 456
}

457
void __sta_info_unlink(struct sta_info **sta)
458
{
459 460 461 462 463 464 465 466 467 468 469 470
	struct ieee80211_local *local = (*sta)->local;
	struct ieee80211_sub_if_data *sdata = (*sta)->sdata;
#ifdef CONFIG_MAC80211_VERBOSE_DEBUG
	DECLARE_MAC_BUF(mbuf);
#endif
	/*
	 * pull caller's reference if we're already gone.
	 */
	if (sta_info_hash_del(local, *sta)) {
		*sta = NULL;
		return;
	}
471

472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497
	/*
	 * Also pull caller's reference if the STA is pinned by the
	 * task that is adding the debugfs entries. In that case, we
	 * leave the STA "to be freed".
	 *
	 * The rules are not trivial, but not too complex either:
	 *  (1) pin_status is only modified under the sta_lock
	 *  (2) sta_info_debugfs_add_work() will set the status
	 *	to PINNED when it found an item that needs a new
	 *	debugfs directory created. In that case, that item
	 *	must not be freed although all *RCU* users are done
	 *	with it. Hence, we tell the caller of _unlink()
	 *	that the item is already gone (as can happen when
	 *	two tasks try to unlink/destroy at the same time)
	 *  (3) We set the pin_status to DESTROY here when we
	 *	find such an item.
	 *  (4) sta_info_debugfs_add_work() will reset the pin_status
	 *	from PINNED to NORMAL when it is done with the item,
	 *	but will check for DESTROY before resetting it in
	 *	which case it will free the item.
	 */
	if ((*sta)->pin_status == STA_INFO_PIN_STAT_PINNED) {
		(*sta)->pin_status = STA_INFO_PIN_STAT_DESTROY;
		*sta = NULL;
		return;
	}
498

499
	list_del(&(*sta)->list);
500

501 502 503 504 505
	if ((*sta)->flags & WLAN_STA_PS) {
		(*sta)->flags &= ~WLAN_STA_PS;
		if (sdata->bss)
			atomic_dec(&sdata->bss->num_sta_ps);
		__sta_info_clear_tim_bit(sdata->bss, *sta);
506 507
	}

508
	local->num_sta--;
509

510
	if (local->ops->sta_notify) {
511
		if (sdata->vif.type == IEEE80211_IF_TYPE_VLAN)
512 513 514
			sdata = sdata->u.vlan.ap;

		local->ops->sta_notify(local_to_hw(local), &sdata->vif,
515
				       STA_NOTIFY_REMOVE, (*sta)->addr);
516
	}
517

518 519 520 521 522 523
	if (ieee80211_vif_is_mesh(&sdata->vif)) {
		mesh_accept_plinks_update(sdata);
#ifdef CONFIG_MAC80211_MESH
		del_timer(&(*sta)->plink_timer);
#endif
	}
524

525 526 527 528
#ifdef CONFIG_MAC80211_VERBOSE_DEBUG
	printk(KERN_DEBUG "%s: Removed STA %s\n",
	       wiphy_name(local->hw.wiphy), print_mac(mbuf, (*sta)->addr));
#endif /* CONFIG_MAC80211_VERBOSE_DEBUG */
529 530
}

531 532 533 534 535 536 537 538 539
void sta_info_unlink(struct sta_info **sta)
{
	struct ieee80211_local *local = (*sta)->local;
	unsigned long flags;

	spin_lock_irqsave(&local->sta_lock, flags);
	__sta_info_unlink(sta);
	spin_unlock_irqrestore(&local->sta_lock, flags);
}
540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566

static inline int sta_info_buffer_expired(struct ieee80211_local *local,
					  struct sta_info *sta,
					  struct sk_buff *skb)
{
	struct ieee80211_tx_packet_data *pkt_data;
	int timeout;

	if (!skb)
		return 0;

	pkt_data = (struct ieee80211_tx_packet_data *) skb->cb;

	/* Timeout: (2 * listen_interval * beacon_int * 1024 / 1000000) sec */
	timeout = (sta->listen_interval * local->hw.conf.beacon_int * 32 /
		   15625) * HZ;
	if (timeout < STA_TX_BUFFER_EXPIRE)
		timeout = STA_TX_BUFFER_EXPIRE;
	return time_after(jiffies, pkt_data->jiffies + timeout);
}


static void sta_info_cleanup_expire_buffered(struct ieee80211_local *local,
					     struct sta_info *sta)
{
	unsigned long flags;
	struct sk_buff *skb;
567
	struct ieee80211_sub_if_data *sdata;
568
	DECLARE_MAC_BUF(mac);
569 570 571 572 573 574 575

	if (skb_queue_empty(&sta->ps_tx_buf))
		return;

	for (;;) {
		spin_lock_irqsave(&sta->ps_tx_buf.lock, flags);
		skb = skb_peek(&sta->ps_tx_buf);
576
		if (sta_info_buffer_expired(local, sta, skb))
577
			skb = __skb_dequeue(&sta->ps_tx_buf);
578
		else
579 580 581
			skb = NULL;
		spin_unlock_irqrestore(&sta->ps_tx_buf.lock, flags);

582
		if (!skb)
583
			break;
584

585
		sdata = sta->sdata;
586 587 588 589 590
		local->total_ps_buffered--;
		printk(KERN_DEBUG "Buffered frame expired (STA "
		       "%s)\n", print_mac(mac, sta->addr));
		dev_kfree_skb(skb);

591 592
		if (skb_queue_empty(&sta->ps_tx_buf))
			sta_info_clear_tim_bit(sta);
593 594 595 596 597 598 599 600 601
	}
}


static void sta_info_cleanup(unsigned long data)
{
	struct ieee80211_local *local = (struct ieee80211_local *) data;
	struct sta_info *sta;

602 603
	rcu_read_lock();
	list_for_each_entry_rcu(sta, &local->sta_list, list)
604
		sta_info_cleanup_expire_buffered(local, sta);
605
	rcu_read_unlock();
606

607 608
	local->sta_cleanup.expires =
		round_jiffies(jiffies + STA_INFO_CLEANUP_INTERVAL);
609 610 611
	add_timer(&local->sta_cleanup);
}

J
Jiri Benc 已提交
612
#ifdef CONFIG_MAC80211_DEBUGFS
613
static void sta_info_debugfs_add_work(struct work_struct *work)
J
Jiri Benc 已提交
614 615 616 617
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local, sta_debugfs_add);
	struct sta_info *sta, *tmp;
618
	unsigned long flags;
J
Jiri Benc 已提交
619 620 621

	while (1) {
		sta = NULL;
622 623

		spin_lock_irqsave(&local->sta_lock, flags);
J
Jiri Benc 已提交
624
		list_for_each_entry(tmp, &local->sta_list, list) {
625
			if (!tmp->debugfs.dir) {
J
Jiri Benc 已提交
626
				sta = tmp;
627
				__sta_info_pin(sta);
J
Jiri Benc 已提交
628 629 630
				break;
			}
		}
631
		spin_unlock_irqrestore(&local->sta_lock, flags);
J
Jiri Benc 已提交
632 633 634 635 636 637

		if (!sta)
			break;

		ieee80211_sta_debugfs_add(sta);
		rate_control_add_sta_debugfs(sta);
638 639

		sta = __sta_info_unpin(sta);
640 641 642
		rtnl_lock();
		sta_info_destroy(sta);
		rtnl_unlock();
J
Jiri Benc 已提交
643 644 645 646
	}
}
#endif

J
Johannes Berg 已提交
647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675
void __ieee80211_run_pending_flush(struct ieee80211_local *local)
{
	struct sta_info *sta;
	unsigned long flags;

	ASSERT_RTNL();

	spin_lock_irqsave(&local->sta_lock, flags);
	while (!list_empty(&local->sta_flush_list)) {
		sta = list_first_entry(&local->sta_flush_list,
				       struct sta_info, list);
		list_del(&sta->list);
		spin_unlock_irqrestore(&local->sta_lock, flags);
		sta_info_destroy(sta);
		spin_lock_irqsave(&local->sta_lock, flags);
	}
	spin_unlock_irqrestore(&local->sta_lock, flags);
}

static void ieee80211_sta_flush_work(struct work_struct *work)
{
	struct ieee80211_local *local =
		container_of(work, struct ieee80211_local, sta_flush_work);

	rtnl_lock();
	__ieee80211_run_pending_flush(local);
	rtnl_unlock();
}

676 677
void sta_info_init(struct ieee80211_local *local)
{
678
	spin_lock_init(&local->sta_lock);
679
	INIT_LIST_HEAD(&local->sta_list);
J
Johannes Berg 已提交
680 681
	INIT_LIST_HEAD(&local->sta_flush_list);
	INIT_WORK(&local->sta_flush_work, ieee80211_sta_flush_work);
682

683 684
	setup_timer(&local->sta_cleanup, sta_info_cleanup,
		    (unsigned long)local);
685 686
	local->sta_cleanup.expires =
		round_jiffies(jiffies + STA_INFO_CLEANUP_INTERVAL);
J
Jiri Benc 已提交
687 688

#ifdef CONFIG_MAC80211_DEBUGFS
689
	INIT_WORK(&local->sta_debugfs_add, sta_info_debugfs_add_work);
J
Jiri Benc 已提交
690
#endif
691 692 693 694 695 696 697 698 699 700 701
}

int sta_info_start(struct ieee80211_local *local)
{
	add_timer(&local->sta_cleanup);
	return 0;
}

void sta_info_stop(struct ieee80211_local *local)
{
	del_timer(&local->sta_cleanup);
J
Johannes Berg 已提交
702 703 704
	cancel_work_sync(&local->sta_flush_work);

	rtnl_lock();
705
	sta_info_flush(local, NULL);
J
Johannes Berg 已提交
706 707
	__ieee80211_run_pending_flush(local);
	rtnl_unlock();
708 709 710 711
}

/**
 * sta_info_flush - flush matching STA entries from the STA table
712 713 714
 *
 * Returns the number of removed STA entries.
 *
715
 * @local: local interface data
716
 * @sdata: matching rule for the net device (sta->dev) or %NULL to match all STAs
717
 */
718
int sta_info_flush(struct ieee80211_local *local,
719
		    struct ieee80211_sub_if_data *sdata)
720 721
{
	struct sta_info *sta, *tmp;
722
	LIST_HEAD(tmp_list);
723
	int ret = 0;
724
	unsigned long flags;
725

726
	might_sleep();
J
Johannes Berg 已提交
727
	ASSERT_RTNL();
728

729 730 731 732
	spin_lock_irqsave(&local->sta_lock, flags);
	list_for_each_entry_safe(sta, tmp, &local->sta_list, list) {
		if (!sdata || sdata == sta->sdata) {
			__sta_info_unlink(&sta);
733
			if (sta) {
734
				list_add_tail(&sta->list, &tmp_list);
735 736
				ret++;
			}
737
		}
738
	}
739 740 741 742
	spin_unlock_irqrestore(&local->sta_lock, flags);

	list_for_each_entry_safe(sta, tmp, &tmp_list, list)
		sta_info_destroy(sta);
743 744

	return ret;
745
}
J
Johannes Berg 已提交
746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778

/**
 * sta_info_flush_delayed - flush matching STA entries from the STA table
 *
 * This function unlinks all stations for a given interface and queues
 * them for freeing. Note that the workqueue function scheduled here has
 * to run before any new keys can be added to the system to avoid set_key()
 * callback ordering issues.
 *
 * @sdata: the interface
 */
void sta_info_flush_delayed(struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_local *local = sdata->local;
	struct sta_info *sta, *tmp;
	unsigned long flags;
	bool work = false;

	spin_lock_irqsave(&local->sta_lock, flags);
	list_for_each_entry_safe(sta, tmp, &local->sta_list, list) {
		if (sdata == sta->sdata) {
			__sta_info_unlink(&sta);
			if (sta) {
				list_add_tail(&sta->list,
					      &local->sta_flush_list);
				work = true;
			}
		}
	}
	if (work)
		schedule_work(&local->sta_flush_work);
	spin_unlock_irqrestore(&local->sta_lock, flags);
}