Linux Kernel  3.7.1
 All Data Structures Namespaces Files Functions Variables Typedefs Enumerations Enumerator Macros Groups Pages
3945-mac.c
Go to the documentation of this file.
1 /******************************************************************************
2  *
3  * Copyright(c) 2003 - 2011 Intel Corporation. All rights reserved.
4  *
5  * Portions of this file are derived from the ipw3945 project, as well
6  * as portions of the ieee80211 subsystem header files.
7  *
8  * This program is free software; you can redistribute it and/or modify it
9  * under the terms of version 2 of the GNU General Public License as
10  * published by the Free Software Foundation.
11  *
12  * This program is distributed in the hope that it will be useful, but WITHOUT
13  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
14  * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
15  * more details.
16  *
17  * You should have received a copy of the GNU General Public License along with
18  * this program; if not, write to the Free Software Foundation, Inc.,
19  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
20  *
21  * The full GNU General Public License is included in this distribution in the
22  * file called LICENSE.
23  *
24  * Contact Information:
25  * Intel Linux Wireless <[email protected]>
26  * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
27  *
28  *****************************************************************************/
29 
30 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
31 
32 #include <linux/kernel.h>
33 #include <linux/module.h>
34 #include <linux/init.h>
35 #include <linux/pci.h>
36 #include <linux/pci-aspm.h>
37 #include <linux/slab.h>
38 #include <linux/dma-mapping.h>
39 #include <linux/delay.h>
40 #include <linux/sched.h>
41 #include <linux/skbuff.h>
42 #include <linux/netdevice.h>
43 #include <linux/firmware.h>
44 #include <linux/etherdevice.h>
45 #include <linux/if_arp.h>
46 
47 #include <net/ieee80211_radiotap.h>
48 #include <net/mac80211.h>
49 
50 #include <asm/div64.h>
51 
52 #define DRV_NAME "iwl3945"
53 
54 #include "commands.h"
55 #include "common.h"
56 #include "3945.h"
57 #include "iwl-spectrum.h"
58 
59 /*
60  * module name, copyright, version, etc.
61  */
62 
63 #define DRV_DESCRIPTION \
64 "Intel(R) PRO/Wireless 3945ABG/BG Network Connection driver for Linux"
65 
66 #ifdef CONFIG_IWLEGACY_DEBUG
67 #define VD "d"
68 #else
69 #define VD
70 #endif
71 
72 /*
73  * add "s" to indicate spectrum measurement included.
74  * we add it here to be consistent with previous releases in which
75  * this was configurable.
76  */
77 #define DRV_VERSION IWLWIFI_VERSION VD "s"
78 #define DRV_COPYRIGHT "Copyright(c) 2003-2011 Intel Corporation"
79 #define DRV_AUTHOR "<[email protected]>"
80 
84 MODULE_LICENSE("GPL");
85 
86  /* module parameters */
88  .sw_crypto = 1,
89  .restart_fw = 1,
90  .disable_hw_scan = 1,
91  /* the rest are 0 by default */
92 };
93 
105 __le32
107 {
108  struct il3945_eeprom *eeprom = (struct il3945_eeprom *)il->eeprom;
109 
110  switch (il3945_mod_params.antenna) {
112  return 0;
113 
114  case IL_ANTENNA_MAIN:
115  if (eeprom->antenna_switch_type)
118 
119  case IL_ANTENNA_AUX:
120  if (eeprom->antenna_switch_type)
123  }
124 
125  /* bad antenna selector value */
126  IL_ERR("Bad antenna selector value (0x%x)\n",
127  il3945_mod_params.antenna);
128 
129  return 0; /* "diversity" is default if error */
130 }
131 
132 static int
133 il3945_set_ccmp_dynamic_key_info(struct il_priv *il,
134  struct ieee80211_key_conf *keyconf, u8 sta_id)
135 {
136  unsigned long flags;
137  __le16 key_flags = 0;
138  int ret;
139 
140  key_flags |= (STA_KEY_FLG_CCMP | STA_KEY_FLG_MAP_KEY_MSK);
141  key_flags |= cpu_to_le16(keyconf->keyidx << STA_KEY_FLG_KEYID_POS);
142 
143  if (sta_id == il->hw_params.bcast_id)
144  key_flags |= STA_KEY_MULTICAST_MSK;
145 
147  keyconf->hw_key_idx = keyconf->keyidx;
148  key_flags &= ~STA_KEY_FLG_INVALID;
149 
150  spin_lock_irqsave(&il->sta_lock, flags);
151  il->stations[sta_id].keyinfo.cipher = keyconf->cipher;
152  il->stations[sta_id].keyinfo.keylen = keyconf->keylen;
153  memcpy(il->stations[sta_id].keyinfo.key, keyconf->key, keyconf->keylen);
154 
155  memcpy(il->stations[sta_id].sta.key.key, keyconf->key, keyconf->keylen);
156 
157  if ((il->stations[sta_id].sta.key.
159  il->stations[sta_id].sta.key.key_offset =
161  /* else, we are overriding an existing key => no need to allocated room
162  * in uCode. */
163 
164  WARN(il->stations[sta_id].sta.key.key_offset == WEP_INVALID_OFFSET,
165  "no space for a new key");
166 
167  il->stations[sta_id].sta.key.key_flags = key_flags;
168  il->stations[sta_id].sta.sta.modify_mask = STA_MODIFY_KEY_MASK;
169  il->stations[sta_id].sta.mode = STA_CONTROL_MODIFY_MSK;
170 
171  D_INFO("hwcrypto: modify ucode station key info\n");
172 
173  ret = il_send_add_sta(il, &il->stations[sta_id].sta, CMD_ASYNC);
174 
175  spin_unlock_irqrestore(&il->sta_lock, flags);
176 
177  return ret;
178 }
179 
180 static int
181 il3945_set_tkip_dynamic_key_info(struct il_priv *il,
182  struct ieee80211_key_conf *keyconf, u8 sta_id)
183 {
184  return -EOPNOTSUPP;
185 }
186 
187 static int
188 il3945_set_wep_dynamic_key_info(struct il_priv *il,
189  struct ieee80211_key_conf *keyconf, u8 sta_id)
190 {
191  return -EOPNOTSUPP;
192 }
193 
194 static int
195 il3945_clear_sta_key_info(struct il_priv *il, u8 sta_id)
196 {
197  unsigned long flags;
198  struct il_addsta_cmd sta_cmd;
199 
200  spin_lock_irqsave(&il->sta_lock, flags);
201  memset(&il->stations[sta_id].keyinfo, 0, sizeof(struct il_hw_key));
202  memset(&il->stations[sta_id].sta.key, 0, sizeof(struct il4965_keyinfo));
203  il->stations[sta_id].sta.key.key_flags = STA_KEY_FLG_NO_ENC;
204  il->stations[sta_id].sta.sta.modify_mask = STA_MODIFY_KEY_MASK;
205  il->stations[sta_id].sta.mode = STA_CONTROL_MODIFY_MSK;
206  memcpy(&sta_cmd, &il->stations[sta_id].sta,
207  sizeof(struct il_addsta_cmd));
208  spin_unlock_irqrestore(&il->sta_lock, flags);
209 
210  D_INFO("hwcrypto: clear ucode station key info\n");
211  return il_send_add_sta(il, &sta_cmd, CMD_SYNC);
212 }
213 
214 static int
215 il3945_set_dynamic_key(struct il_priv *il, struct ieee80211_key_conf *keyconf,
216  u8 sta_id)
217 {
218  int ret = 0;
219 
220  keyconf->hw_key_idx = HW_KEY_DYNAMIC;
221 
222  switch (keyconf->cipher) {
224  ret = il3945_set_ccmp_dynamic_key_info(il, keyconf, sta_id);
225  break;
227  ret = il3945_set_tkip_dynamic_key_info(il, keyconf, sta_id);
228  break;
231  ret = il3945_set_wep_dynamic_key_info(il, keyconf, sta_id);
232  break;
233  default:
234  IL_ERR("Unknown alg: %s alg=%x\n", __func__, keyconf->cipher);
235  ret = -EINVAL;
236  }
237 
238  D_WEP("Set dynamic key: alg=%x len=%d idx=%d sta=%d ret=%d\n",
239  keyconf->cipher, keyconf->keylen, keyconf->keyidx, sta_id, ret);
240 
241  return ret;
242 }
243 
244 static int
245 il3945_remove_static_key(struct il_priv *il)
246 {
247  int ret = -EOPNOTSUPP;
248 
249  return ret;
250 }
251 
252 static int
253 il3945_set_static_key(struct il_priv *il, struct ieee80211_key_conf *key)
254 {
255  if (key->cipher == WLAN_CIPHER_SUITE_WEP40 ||
257  return -EOPNOTSUPP;
258 
259  IL_ERR("Static key invalid: cipher %x\n", key->cipher);
260  return -EINVAL;
261 }
262 
263 static void
264 il3945_clear_free_frames(struct il_priv *il)
265 {
266  struct list_head *element;
267 
268  D_INFO("%d frames on pre-allocated heap on clear.\n", il->frames_count);
269 
270  while (!list_empty(&il->free_frames)) {
271  element = il->free_frames.next;
272  list_del(element);
273  kfree(list_entry(element, struct il3945_frame, list));
274  il->frames_count--;
275  }
276 
277  if (il->frames_count) {
278  IL_WARN("%d frames still in use. Did we lose one?\n",
279  il->frames_count);
280  il->frames_count = 0;
281  }
282 }
283 
284 static struct il3945_frame *
285 il3945_get_free_frame(struct il_priv *il)
286 {
287  struct il3945_frame *frame;
288  struct list_head *element;
289  if (list_empty(&il->free_frames)) {
290  frame = kzalloc(sizeof(*frame), GFP_KERNEL);
291  if (!frame) {
292  IL_ERR("Could not allocate frame!\n");
293  return NULL;
294  }
295 
296  il->frames_count++;
297  return frame;
298  }
299 
300  element = il->free_frames.next;
301  list_del(element);
302  return list_entry(element, struct il3945_frame, list);
303 }
304 
305 static void
306 il3945_free_frame(struct il_priv *il, struct il3945_frame *frame)
307 {
308  memset(frame, 0, sizeof(*frame));
309  list_add(&frame->list, &il->free_frames);
310 }
311 
312 unsigned int
314  int left)
315 {
316 
317  if (!il_is_associated(il) || !il->beacon_skb)
318  return 0;
319 
320  if (il->beacon_skb->len > left)
321  return 0;
322 
323  memcpy(hdr, il->beacon_skb->data, il->beacon_skb->len);
324 
325  return il->beacon_skb->len;
326 }
327 
328 static int
329 il3945_send_beacon_cmd(struct il_priv *il)
330 {
331  struct il3945_frame *frame;
332  unsigned int frame_size;
333  int rc;
334  u8 rate;
335 
336  frame = il3945_get_free_frame(il);
337 
338  if (!frame) {
339  IL_ERR("Could not obtain free frame buffer for beacon "
340  "command.\n");
341  return -ENOMEM;
342  }
343 
344  rate = il_get_lowest_plcp(il);
345 
346  frame_size = il3945_hw_get_beacon_cmd(il, frame, rate);
347 
348  rc = il_send_cmd_pdu(il, C_TX_BEACON, frame_size, &frame->u.cmd[0]);
349 
350  il3945_free_frame(il, frame);
351 
352  return rc;
353 }
354 
355 static void
356 il3945_unset_hw_params(struct il_priv *il)
357 {
358  if (il->_3945.shared_virt)
359  dma_free_coherent(&il->pci_dev->dev,
360  sizeof(struct il3945_shared),
361  il->_3945.shared_virt, il->_3945.shared_phys);
362 }
363 
364 static void
365 il3945_build_tx_cmd_hwcrypto(struct il_priv *il, struct ieee80211_tx_info *info,
366  struct il_device_cmd *cmd,
367  struct sk_buff *skb_frag, int sta_id)
368 {
369  struct il3945_tx_cmd *tx_cmd = (struct il3945_tx_cmd *)cmd->cmd.payload;
370  struct il_hw_key *keyinfo = &il->stations[sta_id].keyinfo;
371 
372  tx_cmd->sec_ctl = 0;
373 
374  switch (keyinfo->cipher) {
376  tx_cmd->sec_ctl = TX_CMD_SEC_CCM;
377  memcpy(tx_cmd->key, keyinfo->key, keyinfo->keylen);
378  D_TX("tx_cmd with AES hwcrypto\n");
379  break;
380 
382  break;
383 
385  tx_cmd->sec_ctl |= TX_CMD_SEC_KEY128;
386  /* fall through */
388  tx_cmd->sec_ctl |=
389  TX_CMD_SEC_WEP | (info->control.hw_key->
390  hw_key_idx & TX_CMD_SEC_MSK) <<
392 
393  memcpy(&tx_cmd->key[3], keyinfo->key, keyinfo->keylen);
394 
395  D_TX("Configuring packet for WEP encryption " "with key %d\n",
396  info->control.hw_key->hw_key_idx);
397  break;
398 
399  default:
400  IL_ERR("Unknown encode cipher %x\n", keyinfo->cipher);
401  break;
402  }
403 }
404 
405 /*
406  * handle build C_TX command notification.
407  */
408 static void
409 il3945_build_tx_cmd_basic(struct il_priv *il, struct il_device_cmd *cmd,
410  struct ieee80211_tx_info *info,
411  struct ieee80211_hdr *hdr, u8 std_id)
412 {
413  struct il3945_tx_cmd *tx_cmd = (struct il3945_tx_cmd *)cmd->cmd.payload;
414  __le32 tx_flags = tx_cmd->tx_flags;
415  __le16 fc = hdr->frame_control;
416 
418  if (!(info->flags & IEEE80211_TX_CTL_NO_ACK)) {
420  if (ieee80211_is_mgmt(fc))
422  if (ieee80211_is_probe_resp(fc) &&
423  !(le16_to_cpu(hdr->seq_ctrl) & 0xf))
425  } else {
428  }
429 
430  tx_cmd->sta_id = std_id;
431  if (ieee80211_has_morefrags(fc))
433 
434  if (ieee80211_is_data_qos(fc)) {
435  u8 *qc = ieee80211_get_qos_ctl(hdr);
436  tx_cmd->tid_tspec = qc[0] & 0xf;
438  } else {
440  }
441 
442  il_tx_cmd_protection(il, info, fc, &tx_flags);
443 
445  if (ieee80211_is_mgmt(fc)) {
446  if (ieee80211_is_assoc_req(fc) || ieee80211_is_reassoc_req(fc))
447  tx_cmd->timeout.pm_frame_timeout = cpu_to_le16(3);
448  else
449  tx_cmd->timeout.pm_frame_timeout = cpu_to_le16(2);
450  } else {
451  tx_cmd->timeout.pm_frame_timeout = 0;
452  }
453 
454  tx_cmd->driver_txop = 0;
455  tx_cmd->tx_flags = tx_flags;
456  tx_cmd->next_frame_len = 0;
457 }
458 
459 /*
460  * start C_TX command process
461  */
462 static int
463 il3945_tx_skb(struct il_priv *il,
464  struct ieee80211_sta *sta,
465  struct sk_buff *skb)
466 {
467  struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
468  struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
469  struct il3945_tx_cmd *tx_cmd;
470  struct il_tx_queue *txq = NULL;
471  struct il_queue *q = NULL;
472  struct il_device_cmd *out_cmd;
473  struct il_cmd_meta *out_meta;
475  dma_addr_t txcmd_phys;
476  int txq_id = skb_get_queue_mapping(skb);
477  u16 len, idx, hdr_len;
478  u8 id;
479  u8 unicast;
480  u8 sta_id;
481  u8 tid = 0;
482  __le16 fc;
483  u8 wait_write_ptr = 0;
484  unsigned long flags;
485 
486  spin_lock_irqsave(&il->lock, flags);
487  if (il_is_rfkill(il)) {
488  D_DROP("Dropping - RF KILL\n");
489  goto drop_unlock;
490  }
491 
492  if ((ieee80211_get_tx_rate(il->hw, info)->hw_value & 0xFF) ==
493  IL_INVALID_RATE) {
494  IL_ERR("ERROR: No TX rate available.\n");
495  goto drop_unlock;
496  }
497 
498  unicast = !is_multicast_ether_addr(hdr->addr1);
499  id = 0;
500 
501  fc = hdr->frame_control;
502 
503 #ifdef CONFIG_IWLEGACY_DEBUG
504  if (ieee80211_is_auth(fc))
505  D_TX("Sending AUTH frame\n");
506  else if (ieee80211_is_assoc_req(fc))
507  D_TX("Sending ASSOC frame\n");
508  else if (ieee80211_is_reassoc_req(fc))
509  D_TX("Sending REASSOC frame\n");
510 #endif
511 
512  spin_unlock_irqrestore(&il->lock, flags);
513 
514  hdr_len = ieee80211_hdrlen(fc);
515 
516  /* Find idx into station table for destination station */
517  sta_id = il_sta_id_or_broadcast(il, sta);
518  if (sta_id == IL_INVALID_STATION) {
519  D_DROP("Dropping - INVALID STATION: %pM\n", hdr->addr1);
520  goto drop;
521  }
522 
523  D_RATE("station Id %d\n", sta_id);
524 
525  if (ieee80211_is_data_qos(fc)) {
526  u8 *qc = ieee80211_get_qos_ctl(hdr);
527  tid = qc[0] & IEEE80211_QOS_CTL_TID_MASK;
528  if (unlikely(tid >= MAX_TID_COUNT))
529  goto drop;
530  }
531 
532  /* Descriptor for chosen Tx queue */
533  txq = &il->txq[txq_id];
534  q = &txq->q;
535 
536  if ((il_queue_space(q) < q->high_mark))
537  goto drop;
538 
539  spin_lock_irqsave(&il->lock, flags);
540 
541  idx = il_get_cmd_idx(q, q->write_ptr, 0);
542 
543  txq->skbs[q->write_ptr] = skb;
544 
545  /* Init first empty entry in queue's array of Tx/cmd buffers */
546  out_cmd = txq->cmd[idx];
547  out_meta = &txq->meta[idx];
548  tx_cmd = (struct il3945_tx_cmd *)out_cmd->cmd.payload;
549  memset(&out_cmd->hdr, 0, sizeof(out_cmd->hdr));
550  memset(tx_cmd, 0, sizeof(*tx_cmd));
551 
552  /*
553  * Set up the Tx-command (not MAC!) header.
554  * Store the chosen Tx queue and TFD idx within the sequence field;
555  * after Tx, uCode's Tx response will return this value so driver can
556  * locate the frame within the tx queue and do post-tx processing.
557  */
558  out_cmd->hdr.cmd = C_TX;
559  out_cmd->hdr.sequence =
560  cpu_to_le16((u16)
561  (QUEUE_TO_SEQ(txq_id) | IDX_TO_SEQ(q->write_ptr)));
562 
563  /* Copy MAC header from skb into command buffer */
564  memcpy(tx_cmd->hdr, hdr, hdr_len);
565 
566  if (info->control.hw_key)
567  il3945_build_tx_cmd_hwcrypto(il, info, out_cmd, skb, sta_id);
568 
569  /* TODO need this for burst mode later on */
570  il3945_build_tx_cmd_basic(il, out_cmd, info, hdr, sta_id);
571 
572  il3945_hw_build_tx_cmd_rate(il, out_cmd, info, hdr, sta_id);
573 
574  /* Total # bytes to be transmitted */
575  len = (u16) skb->len;
576  tx_cmd->len = cpu_to_le16(len);
577 
578  il_update_stats(il, true, fc, len);
579  tx_cmd->tx_flags &= ~TX_CMD_FLG_ANT_A_MSK;
580  tx_cmd->tx_flags &= ~TX_CMD_FLG_ANT_B_MSK;
581 
582  if (!ieee80211_has_morefrags(hdr->frame_control)) {
583  txq->need_update = 1;
584  } else {
585  wait_write_ptr = 1;
586  txq->need_update = 0;
587  }
588 
589  D_TX("sequence nr = 0X%x\n", le16_to_cpu(out_cmd->hdr.sequence));
590  D_TX("tx_flags = 0X%x\n", le32_to_cpu(tx_cmd->tx_flags));
591  il_print_hex_dump(il, IL_DL_TX, tx_cmd, sizeof(*tx_cmd));
592  il_print_hex_dump(il, IL_DL_TX, (u8 *) tx_cmd->hdr,
593  ieee80211_hdrlen(fc));
594 
595  /*
596  * Use the first empty entry in this queue's command buffer array
597  * to contain the Tx command and MAC header concatenated together
598  * (payload data will be in another buffer).
599  * Size of this varies, due to varying MAC header length.
600  * If end is not dword aligned, we'll have 2 extra bytes at the end
601  * of the MAC header (device reads on dword boundaries).
602  * We'll tell device about this padding later.
603  */
604  len =
605  sizeof(struct il3945_tx_cmd) + sizeof(struct il_cmd_header) +
606  hdr_len;
607  len = (len + 3) & ~3;
608 
609  /* Physical address of this Tx command's header (not MAC header!),
610  * within command buffer array. */
611  txcmd_phys =
612  pci_map_single(il->pci_dev, &out_cmd->hdr, len, PCI_DMA_TODEVICE);
613  /* we do not map meta data ... so we can safely access address to
614  * provide to unmap command*/
615  dma_unmap_addr_set(out_meta, mapping, txcmd_phys);
616  dma_unmap_len_set(out_meta, len, len);
617 
618  /* Add buffer containing Tx command and MAC(!) header to TFD's
619  * first entry */
620  il->ops->txq_attach_buf_to_tfd(il, txq, txcmd_phys, len, 1, 0);
621 
622  /* Set up TFD's 2nd entry to point directly to remainder of skb,
623  * if any (802.11 null frames have no payload). */
624  len = skb->len - hdr_len;
625  if (len) {
626  phys_addr =
627  pci_map_single(il->pci_dev, skb->data + hdr_len, len,
629  il->ops->txq_attach_buf_to_tfd(il, txq, phys_addr, len, 0,
630  U32_PAD(len));
631  }
632 
633  /* Tell device the write idx *just past* this latest filled TFD */
634  q->write_ptr = il_queue_inc_wrap(q->write_ptr, q->n_bd);
635  il_txq_update_write_ptr(il, txq);
636  spin_unlock_irqrestore(&il->lock, flags);
637 
638  if (il_queue_space(q) < q->high_mark && il->mac80211_registered) {
639  if (wait_write_ptr) {
640  spin_lock_irqsave(&il->lock, flags);
641  txq->need_update = 1;
642  il_txq_update_write_ptr(il, txq);
643  spin_unlock_irqrestore(&il->lock, flags);
644  }
645 
646  il_stop_queue(il, txq);
647  }
648 
649  return 0;
650 
651 drop_unlock:
652  spin_unlock_irqrestore(&il->lock, flags);
653 drop:
654  return -1;
655 }
656 
657 static int
658 il3945_get_measurement(struct il_priv *il,
660 {
661  struct il_spectrum_cmd spectrum;
662  struct il_rx_pkt *pkt;
663  struct il_host_cmd cmd = {
665  .data = (void *)&spectrum,
666  .flags = CMD_WANT_SKB,
667  };
668  u32 add_time = le64_to_cpu(params->start_time);
669  int rc;
670  int spectrum_resp_status;
671  int duration = le16_to_cpu(params->duration);
672 
673  if (il_is_associated(il))
674  add_time =
676  le64_to_cpu(params->start_time) -
677  il->_3945.last_tsf,
678  le16_to_cpu(il->timing.beacon_interval));
679 
680  memset(&spectrum, 0, sizeof(spectrum));
681 
682  spectrum.channel_count = cpu_to_le16(1);
683  spectrum.flags =
685  spectrum.filter_flags = MEASUREMENT_FILTER_FLAG;
686  cmd.len = sizeof(spectrum);
687  spectrum.len = cpu_to_le16(cmd.len - sizeof(spectrum.len));
688 
689  if (il_is_associated(il))
690  spectrum.start_time =
691  il_add_beacon_time(il, il->_3945.last_beacon_time, add_time,
692  le16_to_cpu(il->timing.beacon_interval));
693  else
694  spectrum.start_time = 0;
695 
696  spectrum.channels[0].duration = cpu_to_le32(duration * TIME_UNIT);
697  spectrum.channels[0].channel = params->channel;
698  spectrum.channels[0].type = type;
699  if (il->active.flags & RXON_FLG_BAND_24G_MSK)
700  spectrum.flags |=
703 
704  rc = il_send_cmd_sync(il, &cmd);
705  if (rc)
706  return rc;
707 
708  pkt = (struct il_rx_pkt *)cmd.reply_page;
709  if (pkt->hdr.flags & IL_CMD_FAILED_MSK) {
710  IL_ERR("Bad return from N_RX_ON_ASSOC command\n");
711  rc = -EIO;
712  }
713 
714  spectrum_resp_status = le16_to_cpu(pkt->u.spectrum.status);
715  switch (spectrum_resp_status) {
716  case 0: /* Command will be handled */
717  if (pkt->u.spectrum.id != 0xff) {
718  D_INFO("Replaced existing measurement: %d\n",
719  pkt->u.spectrum.id);
721  }
723  rc = 0;
724  break;
725 
726  case 1: /* Command will not be handled */
727  rc = -EAGAIN;
728  break;
729  }
730 
731  il_free_pages(il, cmd.reply_page);
732 
733  return rc;
734 }
735 
736 static void
737 il3945_hdl_alive(struct il_priv *il, struct il_rx_buf *rxb)
738 {
739  struct il_rx_pkt *pkt = rxb_addr(rxb);
740  struct il_alive_resp *palive;
741  struct delayed_work *pwork;
742 
743  palive = &pkt->u.alive_frame;
744 
745  D_INFO("Alive ucode status 0x%08X revision " "0x%01X 0x%01X\n",
746  palive->is_valid, palive->ver_type, palive->ver_subtype);
747 
748  if (palive->ver_subtype == INITIALIZE_SUBTYPE) {
749  D_INFO("Initialization Alive received.\n");
750  memcpy(&il->card_alive_init, &pkt->u.alive_frame,
751  sizeof(struct il_alive_resp));
752  pwork = &il->init_alive_start;
753  } else {
754  D_INFO("Runtime Alive received.\n");
755  memcpy(&il->card_alive, &pkt->u.alive_frame,
756  sizeof(struct il_alive_resp));
757  pwork = &il->alive_start;
759  }
760 
761  /* We delay the ALIVE response by 5ms to
762  * give the HW RF Kill time to activate... */
763  if (palive->is_valid == UCODE_VALID_OK)
765  else
766  IL_WARN("uCode did not respond OK.\n");
767 }
768 
769 static void
770 il3945_hdl_add_sta(struct il_priv *il, struct il_rx_buf *rxb)
771 {
772 #ifdef CONFIG_IWLEGACY_DEBUG
773  struct il_rx_pkt *pkt = rxb_addr(rxb);
774 #endif
775 
776  D_RX("Received C_ADD_STA: 0x%02X\n", pkt->u.status);
777 }
778 
779 static void
780 il3945_hdl_beacon(struct il_priv *il, struct il_rx_buf *rxb)
781 {
782  struct il_rx_pkt *pkt = rxb_addr(rxb);
783  struct il3945_beacon_notif *beacon = &(pkt->u.beacon_status);
784 #ifdef CONFIG_IWLEGACY_DEBUG
785  u8 rate = beacon->beacon_notify_hdr.rate;
786 
787  D_RX("beacon status %x retries %d iss %d " "tsf %d %d rate %d\n",
788  le32_to_cpu(beacon->beacon_notify_hdr.status) & TX_STATUS_MSK,
789  beacon->beacon_notify_hdr.failure_frame,
790  le32_to_cpu(beacon->ibss_mgr_status),
791  le32_to_cpu(beacon->high_tsf), le32_to_cpu(beacon->low_tsf), rate);
792 #endif
793 
795 
796 }
797 
798 /* Handle notification from uCode that card's power state is changing
799  * due to software, hardware, or critical temperature RFKILL */
800 static void
801 il3945_hdl_card_state(struct il_priv *il, struct il_rx_buf *rxb)
802 {
803  struct il_rx_pkt *pkt = rxb_addr(rxb);
804  u32 flags = le32_to_cpu(pkt->u.card_state_notif.flags);
805  unsigned long status = il->status;
806 
807  IL_WARN("Card state received: HW:%s SW:%s\n",
808  (flags & HW_CARD_DISABLED) ? "Kill" : "On",
809  (flags & SW_CARD_DISABLED) ? "Kill" : "On");
810 
812 
813  if (flags & HW_CARD_DISABLED)
814  set_bit(S_RFKILL, &il->status);
815  else
816  clear_bit(S_RFKILL, &il->status);
817 
818  il_scan_cancel(il);
819 
820  if ((test_bit(S_RFKILL, &status) !=
821  test_bit(S_RFKILL, &il->status)))
822  wiphy_rfkill_set_hw_state(il->hw->wiphy,
823  test_bit(S_RFKILL, &il->status));
824  else
826 }
827 
837 static void
838 il3945_setup_handlers(struct il_priv *il)
839 {
840  il->handlers[N_ALIVE] = il3945_hdl_alive;
841  il->handlers[C_ADD_STA] = il3945_hdl_add_sta;
847  il->handlers[N_BEACON] = il3945_hdl_beacon;
848 
849  /*
850  * The same handler is used for both the REPLY to a discrete
851  * stats request from the host as well as for the periodic
852  * stats notifications (after received beacons) from the uCode.
853  */
856 
858  il->handlers[N_CARD_STATE] = il3945_hdl_card_state;
859 
860  /* Set up hardware specific Rx handlers */
862 }
863 
864 /************************** RX-FUNCTIONS ****************************/
865 /*
866  * Rx theory of operation
867  *
868  * The host allocates 32 DMA target addresses and passes the host address
869  * to the firmware at register IL_RFDS_TBL_LOWER + N * RFD_SIZE where N is
870  * 0 to 31
871  *
872  * Rx Queue Indexes
873  * The host/firmware share two idx registers for managing the Rx buffers.
874  *
875  * The READ idx maps to the first position that the firmware may be writing
876  * to -- the driver can read up to (but not including) this position and get
877  * good data.
878  * The READ idx is managed by the firmware once the card is enabled.
879  *
880  * The WRITE idx maps to the last position the driver has read from -- the
881  * position preceding WRITE is the last slot the firmware can place a packet.
882  *
883  * The queue is empty (no good data) if WRITE = READ - 1, and is full if
884  * WRITE = READ.
885  *
886  * During initialization, the host sets up the READ queue position to the first
887  * IDX position, and WRITE to the last (READ - 1 wrapped)
888  *
889  * When the firmware places a packet in a buffer, it will advance the READ idx
890  * and fire the RX interrupt. The driver can then query the READ idx and
891  * process as many packets as possible, moving the WRITE idx forward as it
892  * resets the Rx queue buffers with new memory.
893  *
894  * The management in the driver is as follows:
895  * + A list of pre-allocated SKBs is stored in iwl->rxq->rx_free. When
896  * iwl->rxq->free_count drops to or below RX_LOW_WATERMARK, work is scheduled
897  * to replenish the iwl->rxq->rx_free.
898  * + In il3945_rx_replenish (scheduled) if 'processed' != 'read' then the
899  * iwl->rxq is replenished and the READ IDX is updated (updating the
900  * 'processed' and 'read' driver idxes as well)
901  * + A received packet is processed and handed to the kernel network stack,
902  * detached from the iwl->rxq. The driver 'processed' idx is updated.
903  * + The Host/Firmware iwl->rxq is replenished at tasklet time from the rx_free
904  * list. If there are no allocated buffers in iwl->rxq->rx_free, the READ
905  * IDX is not incremented and iwl->status(RX_STALLED) is set. If there
906  * were enough free buffers and RX_STALLED is set it is cleared.
907  *
908  *
909  * Driver sequence:
910  *
911  * il3945_rx_replenish() Replenishes rx_free list from rx_used, and calls
912  * il3945_rx_queue_restock
913  * il3945_rx_queue_restock() Moves available buffers from rx_free into Rx
914  * queue, updates firmware pointers, and updates
915  * the WRITE idx. If insufficient rx_free buffers
916  * are available, schedules il3945_rx_replenish
917  *
918  * -- enable interrupts --
919  * ISR - il3945_rx() Detach il_rx_bufs from pool up to the
920  * READ IDX, detaching the SKB from the pool.
921  * Moves the packet buffer from queue to rx_used.
922  * Calls il3945_rx_queue_restock to refill any empty
923  * slots.
924  * ...
925  *
926  */
927 
931 static inline __le32
932 il3945_dma_addr2rbd_ptr(struct il_priv *il, dma_addr_t dma_addr)
933 {
934  return cpu_to_le32((u32) dma_addr);
935 }
936 
948 static void
949 il3945_rx_queue_restock(struct il_priv *il)
950 {
951  struct il_rx_queue *rxq = &il->rxq;
952  struct list_head *element;
953  struct il_rx_buf *rxb;
954  unsigned long flags;
955  int write;
956 
957  spin_lock_irqsave(&rxq->lock, flags);
958  write = rxq->write & ~0x7;
959  while (il_rx_queue_space(rxq) > 0 && rxq->free_count) {
960  /* Get next free Rx buffer, remove from free list */
961  element = rxq->rx_free.next;
962  rxb = list_entry(element, struct il_rx_buf, list);
963  list_del(element);
964 
965  /* Point to Rx buffer via next RBD in circular buffer */
966  rxq->bd[rxq->write] =
967  il3945_dma_addr2rbd_ptr(il, rxb->page_dma);
968  rxq->queue[rxq->write] = rxb;
969  rxq->write = (rxq->write + 1) & RX_QUEUE_MASK;
970  rxq->free_count--;
971  }
972  spin_unlock_irqrestore(&rxq->lock, flags);
973  /* If the pre-allocated buffer pool is dropping low, schedule to
974  * refill it */
975  if (rxq->free_count <= RX_LOW_WATERMARK)
976  queue_work(il->workqueue, &il->rx_replenish);
977 
978  /* If we've added more space for the firmware to place data, tell it.
979  * Increment device's write pointer in multiples of 8. */
980  if (rxq->write_actual != (rxq->write & ~0x7) ||
981  abs(rxq->write - rxq->read) > 7) {
982  spin_lock_irqsave(&rxq->lock, flags);
983  rxq->need_update = 1;
984  spin_unlock_irqrestore(&rxq->lock, flags);
986  }
987 }
988 
997 static void
998 il3945_rx_allocate(struct il_priv *il, gfp_t priority)
999 {
1000  struct il_rx_queue *rxq = &il->rxq;
1001  struct list_head *element;
1002  struct il_rx_buf *rxb;
1003  struct page *page;
1004  unsigned long flags;
1006 
1007  while (1) {
1008  spin_lock_irqsave(&rxq->lock, flags);
1009 
1010  if (list_empty(&rxq->rx_used)) {
1011  spin_unlock_irqrestore(&rxq->lock, flags);
1012  return;
1013  }
1014  spin_unlock_irqrestore(&rxq->lock, flags);
1015 
1016  if (rxq->free_count > RX_LOW_WATERMARK)
1017  gfp_mask |= __GFP_NOWARN;
1018 
1019  if (il->hw_params.rx_page_order > 0)
1020  gfp_mask |= __GFP_COMP;
1021 
1022  /* Alloc a new receive buffer */
1023  page = alloc_pages(gfp_mask, il->hw_params.rx_page_order);
1024  if (!page) {
1025  if (net_ratelimit())
1026  D_INFO("Failed to allocate SKB buffer.\n");
1027  if (rxq->free_count <= RX_LOW_WATERMARK &&
1028  net_ratelimit())
1029  IL_ERR("Failed to allocate SKB buffer with %0x."
1030  "Only %u free buffers remaining.\n",
1031  priority, rxq->free_count);
1032  /* We don't reschedule replenish work here -- we will
1033  * call the restock method and if it still needs
1034  * more buffers it will schedule replenish */
1035  break;
1036  }
1037 
1038  spin_lock_irqsave(&rxq->lock, flags);
1039  if (list_empty(&rxq->rx_used)) {
1040  spin_unlock_irqrestore(&rxq->lock, flags);
1041  __free_pages(page, il->hw_params.rx_page_order);
1042  return;
1043  }
1044  element = rxq->rx_used.next;
1045  rxb = list_entry(element, struct il_rx_buf, list);
1046  list_del(element);
1047  spin_unlock_irqrestore(&rxq->lock, flags);
1048 
1049  rxb->page = page;
1050  /* Get physical address of RB/SKB */
1051  rxb->page_dma =
1052  pci_map_page(il->pci_dev, page, 0,
1053  PAGE_SIZE << il->hw_params.rx_page_order,
1055 
1056  spin_lock_irqsave(&rxq->lock, flags);
1057 
1058  list_add_tail(&rxb->list, &rxq->rx_free);
1059  rxq->free_count++;
1060  il->alloc_rxb_page++;
1061 
1062  spin_unlock_irqrestore(&rxq->lock, flags);
1063  }
1064 }
1065 
1066 void
1068 {
1069  unsigned long flags;
1070  int i;
1071  spin_lock_irqsave(&rxq->lock, flags);
1072  INIT_LIST_HEAD(&rxq->rx_free);
1073  INIT_LIST_HEAD(&rxq->rx_used);
1074  /* Fill the rx_used queue with _all_ of the Rx buffers */
1075  for (i = 0; i < RX_FREE_BUFFERS + RX_QUEUE_SIZE; i++) {
1076  /* In the reset function, these buffers may have been allocated
1077  * to an SKB, so we need to unmap and free potential storage */
1078  if (rxq->pool[i].page != NULL) {
1079  pci_unmap_page(il->pci_dev, rxq->pool[i].page_dma,
1080  PAGE_SIZE << il->hw_params.rx_page_order,
1082  __il_free_pages(il, rxq->pool[i].page);
1083  rxq->pool[i].page = NULL;
1084  }
1085  list_add_tail(&rxq->pool[i].list, &rxq->rx_used);
1086  }
1087 
1088  /* Set us so that we have processed and used all buffers, but have
1089  * not restocked the Rx queue with fresh buffers */
1090  rxq->read = rxq->write = 0;
1091  rxq->write_actual = 0;
1092  rxq->free_count = 0;
1093  spin_unlock_irqrestore(&rxq->lock, flags);
1094 }
1095 
1096 void
1098 {
1099  struct il_priv *il = data;
1100  unsigned long flags;
1101 
1102  il3945_rx_allocate(il, GFP_KERNEL);
1103 
1104  spin_lock_irqsave(&il->lock, flags);
1105  il3945_rx_queue_restock(il);
1106  spin_unlock_irqrestore(&il->lock, flags);
1107 }
1108 
1109 static void
1110 il3945_rx_replenish_now(struct il_priv *il)
1111 {
1112  il3945_rx_allocate(il, GFP_ATOMIC);
1113 
1114  il3945_rx_queue_restock(il);
1115 }
1116 
1117 /* Assumes that the skb field of the buffers in 'pool' is kept accurate.
1118  * If an SKB has been detached, the POOL needs to have its SKB set to NULL
1119  * This free routine walks the list of POOL entries and if SKB is set to
1120  * non NULL it is unmapped and freed
1121  */
1122 static void
1123 il3945_rx_queue_free(struct il_priv *il, struct il_rx_queue *rxq)
1124 {
1125  int i;
1126  for (i = 0; i < RX_QUEUE_SIZE + RX_FREE_BUFFERS; i++) {
1127  if (rxq->pool[i].page != NULL) {
1128  pci_unmap_page(il->pci_dev, rxq->pool[i].page_dma,
1129  PAGE_SIZE << il->hw_params.rx_page_order,
1131  __il_free_pages(il, rxq->pool[i].page);
1132  rxq->pool[i].page = NULL;
1133  }
1134  }
1135 
1136  dma_free_coherent(&il->pci_dev->dev, 4 * RX_QUEUE_SIZE, rxq->bd,
1137  rxq->bd_dma);
1138  dma_free_coherent(&il->pci_dev->dev, sizeof(struct il_rb_status),
1139  rxq->rb_stts, rxq->rb_stts_dma);
1140  rxq->bd = NULL;
1141  rxq->rb_stts = NULL;
1142 }
1143 
1144 /* Convert linear signal-to-noise ratio into dB */
1145 static u8 ratio2dB[100] = {
1146 /* 0 1 2 3 4 5 6 7 8 9 */
1147  0, 0, 6, 10, 12, 14, 16, 17, 18, 19, /* 00 - 09 */
1148  20, 21, 22, 22, 23, 23, 24, 25, 26, 26, /* 10 - 19 */
1149  26, 26, 26, 27, 27, 28, 28, 28, 29, 29, /* 20 - 29 */
1150  29, 30, 30, 30, 31, 31, 31, 31, 32, 32, /* 30 - 39 */
1151  32, 32, 32, 33, 33, 33, 33, 33, 34, 34, /* 40 - 49 */
1152  34, 34, 34, 34, 35, 35, 35, 35, 35, 35, /* 50 - 59 */
1153  36, 36, 36, 36, 36, 36, 36, 37, 37, 37, /* 60 - 69 */
1154  37, 37, 37, 37, 37, 38, 38, 38, 38, 38, /* 70 - 79 */
1155  38, 38, 38, 38, 38, 39, 39, 39, 39, 39, /* 80 - 89 */
1156  39, 39, 39, 39, 39, 40, 40, 40, 40, 40 /* 90 - 99 */
1157 };
1158 
1159 /* Calculates a relative dB value from a ratio of linear
1160  * (i.e. not dB) signal levels.
1161  * Conversion assumes that levels are voltages (20*log), not powers (10*log). */
1162 int
1164 {
1165  /* 1000:1 or higher just report as 60 dB */
1166  if (sig_ratio >= 1000)
1167  return 60;
1168 
1169  /* 100:1 or higher, divide by 10 and use table,
1170  * add 20 dB to make up for divide by 10 */
1171  if (sig_ratio >= 100)
1172  return 20 + (int)ratio2dB[sig_ratio / 10];
1173 
1174  /* We shouldn't see this */
1175  if (sig_ratio < 1)
1176  return 0;
1177 
1178  /* Use table for ratios 1:1 - 99:1 */
1179  return (int)ratio2dB[sig_ratio];
1180 }
1181 
1189 static void
1190 il3945_rx_handle(struct il_priv *il)
1191 {
1192  struct il_rx_buf *rxb;
1193  struct il_rx_pkt *pkt;
1194  struct il_rx_queue *rxq = &il->rxq;
1195  u32 r, i;
1196  int reclaim;
1197  unsigned long flags;
1198  u8 fill_rx = 0;
1199  u32 count = 8;
1200  int total_empty = 0;
1201 
1202  /* uCode's read idx (stored in shared DRAM) indicates the last Rx
1203  * buffer that the driver may process (last buffer filled by ucode). */
1204  r = le16_to_cpu(rxq->rb_stts->closed_rb_num) & 0x0FFF;
1205  i = rxq->read;
1206 
1207  /* calculate total frames need to be restock after handling RX */
1208  total_empty = r - rxq->write_actual;
1209  if (total_empty < 0)
1210  total_empty += RX_QUEUE_SIZE;
1211 
1212  if (total_empty > (RX_QUEUE_SIZE / 2))
1213  fill_rx = 1;
1214  /* Rx interrupt, but nothing sent from uCode */
1215  if (i == r)
1216  D_RX("r = %d, i = %d\n", r, i);
1217 
1218  while (i != r) {
1219  int len;
1220 
1221  rxb = rxq->queue[i];
1222 
1223  /* If an RXB doesn't have a Rx queue slot associated with it,
1224  * then a bug has been introduced in the queue refilling
1225  * routines -- catch it here */
1226  BUG_ON(rxb == NULL);
1227 
1228  rxq->queue[i] = NULL;
1229 
1230  pci_unmap_page(il->pci_dev, rxb->page_dma,
1231  PAGE_SIZE << il->hw_params.rx_page_order,
1233  pkt = rxb_addr(rxb);
1234 
1236  len += sizeof(u32); /* account for status word */
1237 
1238  /* Reclaim a command buffer only if this packet is a response
1239  * to a (driver-originated) command.
1240  * If the packet (e.g. Rx frame) originated from uCode,
1241  * there is no command buffer to reclaim.
1242  * Ucode should set SEQ_RX_FRAME bit if ucode-originated,
1243  * but apparently a few don't get set; catch them here. */
1244  reclaim = !(pkt->hdr.sequence & SEQ_RX_FRAME) &&
1245  pkt->hdr.cmd != N_STATS && pkt->hdr.cmd != C_TX;
1246 
1247  /* Based on type of command response or notification,
1248  * handle those that need handling via function in
1249  * handlers table. See il3945_setup_handlers() */
1250  if (il->handlers[pkt->hdr.cmd]) {
1251  D_RX("r = %d, i = %d, %s, 0x%02x\n", r, i,
1252  il_get_cmd_string(pkt->hdr.cmd), pkt->hdr.cmd);
1253  il->isr_stats.handlers[pkt->hdr.cmd]++;
1254  il->handlers[pkt->hdr.cmd] (il, rxb);
1255  } else {
1256  /* No handling needed */
1257  D_RX("r %d i %d No handler needed for %s, 0x%02x\n", r,
1258  i, il_get_cmd_string(pkt->hdr.cmd), pkt->hdr.cmd);
1259  }
1260 
1261  /*
1262  * XXX: After here, we should always check rxb->page
1263  * against NULL before touching it or its virtual
1264  * memory (pkt). Because some handler might have
1265  * already taken or freed the pages.
1266  */
1267 
1268  if (reclaim) {
1269  /* Invoke any callbacks, transfer the buffer to caller,
1270  * and fire off the (possibly) blocking il_send_cmd()
1271  * as we reclaim the driver command queue */
1272  if (rxb->page)
1273  il_tx_cmd_complete(il, rxb);
1274  else
1275  IL_WARN("Claim null rxb?\n");
1276  }
1277 
1278  /* Reuse the page if possible. For notification packets and
1279  * SKBs that fail to Rx correctly, add them back into the
1280  * rx_free list for reuse later. */
1281  spin_lock_irqsave(&rxq->lock, flags);
1282  if (rxb->page != NULL) {
1283  rxb->page_dma =
1284  pci_map_page(il->pci_dev, rxb->page, 0,
1285  PAGE_SIZE << il->hw_params.
1286  rx_page_order, PCI_DMA_FROMDEVICE);
1287  list_add_tail(&rxb->list, &rxq->rx_free);
1288  rxq->free_count++;
1289  } else
1290  list_add_tail(&rxb->list, &rxq->rx_used);
1291 
1292  spin_unlock_irqrestore(&rxq->lock, flags);
1293 
1294  i = (i + 1) & RX_QUEUE_MASK;
1295  /* If there are a lot of unused frames,
1296  * restock the Rx queue so ucode won't assert. */
1297  if (fill_rx) {
1298  count++;
1299  if (count >= 8) {
1300  rxq->read = i;
1301  il3945_rx_replenish_now(il);
1302  count = 0;
1303  }
1304  }
1305  }
1306 
1307  /* Backtrack one entry */
1308  rxq->read = i;
1309  if (fill_rx)
1310  il3945_rx_replenish_now(il);
1311  else
1312  il3945_rx_queue_restock(il);
1313 }
1314 
1315 /* call this function to flush any scheduled tasklet */
1316 static inline void
1317 il3945_synchronize_irq(struct il_priv *il)
1318 {
1319  /* wait to make sure we flush pending tasklet */
1320  synchronize_irq(il->pci_dev->irq);
1321  tasklet_kill(&il->irq_tasklet);
1322 }
1323 
1324 static const char *
1325 il3945_desc_lookup(int i)
1326 {
1327  switch (i) {
1328  case 1:
1329  return "FAIL";
1330  case 2:
1331  return "BAD_PARAM";
1332  case 3:
1333  return "BAD_CHECKSUM";
1334  case 4:
1335  return "NMI_INTERRUPT";
1336  case 5:
1337  return "SYSASSERT";
1338  case 6:
1339  return "FATAL_ERROR";
1340  }
1341 
1342  return "UNKNOWN";
1343 }
1344 
1345 #define ERROR_START_OFFSET (1 * sizeof(u32))
1346 #define ERROR_ELEM_SIZE (7 * sizeof(u32))
1347 
1348 void
1350 {
1351  u32 i;
1352  u32 desc, time, count, base, data1;
1353  u32 blink1, blink2, ilink1, ilink2;
1354 
1355  base = le32_to_cpu(il->card_alive.error_event_table_ptr);
1356 
1357  if (!il3945_hw_valid_rtc_data_addr(base)) {
1358  IL_ERR("Not valid error log pointer 0x%08X\n", base);
1359  return;
1360  }
1361 
1362  count = il_read_targ_mem(il, base);
1363 
1364  if (ERROR_START_OFFSET <= count * ERROR_ELEM_SIZE) {
1365  IL_ERR("Start IWL Error Log Dump:\n");
1366  IL_ERR("Status: 0x%08lX, count: %d\n", il->status, count);
1367  }
1368 
1369  IL_ERR("Desc Time asrtPC blink2 "
1370  "ilink1 nmiPC Line\n");
1371  for (i = ERROR_START_OFFSET;
1372  i < (count * ERROR_ELEM_SIZE) + ERROR_START_OFFSET;
1373  i += ERROR_ELEM_SIZE) {
1374  desc = il_read_targ_mem(il, base + i);
1375  time = il_read_targ_mem(il, base + i + 1 * sizeof(u32));
1376  blink1 = il_read_targ_mem(il, base + i + 2 * sizeof(u32));
1377  blink2 = il_read_targ_mem(il, base + i + 3 * sizeof(u32));
1378  ilink1 = il_read_targ_mem(il, base + i + 4 * sizeof(u32));
1379  ilink2 = il_read_targ_mem(il, base + i + 5 * sizeof(u32));
1380  data1 = il_read_targ_mem(il, base + i + 6 * sizeof(u32));
1381 
1382  IL_ERR("%-13s (0x%X) %010u 0x%05X 0x%05X 0x%05X 0x%05X %u\n\n",
1383  il3945_desc_lookup(desc), desc, time, blink1, blink2,
1384  ilink1, ilink2, data1);
1385  }
1386 }
1387 
1388 static void
1389 il3945_irq_tasklet(struct il_priv *il)
1390 {
1391  u32 inta, handled = 0;
1392  u32 inta_fh;
1393  unsigned long flags;
1394 #ifdef CONFIG_IWLEGACY_DEBUG
1395  u32 inta_mask;
1396 #endif
1397 
1398  spin_lock_irqsave(&il->lock, flags);
1399 
1400  /* Ack/clear/reset pending uCode interrupts.
1401  * Note: Some bits in CSR_INT are "OR" of bits in CSR_FH_INT_STATUS,
1402  * and will clear only when CSR_FH_INT_STATUS gets cleared. */
1403  inta = _il_rd(il, CSR_INT);
1404  _il_wr(il, CSR_INT, inta);
1405 
1406  /* Ack/clear/reset pending flow-handler (DMA) interrupts.
1407  * Any new interrupts that happen after this, either while we're
1408  * in this tasklet, or later, will show up in next ISR/tasklet. */
1409  inta_fh = _il_rd(il, CSR_FH_INT_STATUS);
1410  _il_wr(il, CSR_FH_INT_STATUS, inta_fh);
1411 
1412 #ifdef CONFIG_IWLEGACY_DEBUG
1413  if (il_get_debug_level(il) & IL_DL_ISR) {
1414  /* just for debug */
1415  inta_mask = _il_rd(il, CSR_INT_MASK);
1416  D_ISR("inta 0x%08x, enabled 0x%08x, fh 0x%08x\n", inta,
1417  inta_mask, inta_fh);
1418  }
1419 #endif
1420 
1421  spin_unlock_irqrestore(&il->lock, flags);
1422 
1423  /* Since CSR_INT and CSR_FH_INT_STATUS reads and clears are not
1424  * atomic, make sure that inta covers all the interrupts that
1425  * we've discovered, even if FH interrupt came in just after
1426  * reading CSR_INT. */
1427  if (inta_fh & CSR39_FH_INT_RX_MASK)
1428  inta |= CSR_INT_BIT_FH_RX;
1429  if (inta_fh & CSR39_FH_INT_TX_MASK)
1430  inta |= CSR_INT_BIT_FH_TX;
1431 
1432  /* Now service all interrupt bits discovered above. */
1433  if (inta & CSR_INT_BIT_HW_ERR) {
1434  IL_ERR("Hardware error detected. Restarting.\n");
1435 
1436  /* Tell the device to stop sending interrupts */
1437  il_disable_interrupts(il);
1438 
1439  il->isr_stats.hw++;
1440  il_irq_handle_error(il);
1441 
1442  handled |= CSR_INT_BIT_HW_ERR;
1443 
1444  return;
1445  }
1446 #ifdef CONFIG_IWLEGACY_DEBUG
1447  if (il_get_debug_level(il) & (IL_DL_ISR)) {
1448  /* NIC fires this, but we don't use it, redundant with WAKEUP */
1449  if (inta & CSR_INT_BIT_SCD) {
1450  D_ISR("Scheduler finished to transmit "
1451  "the frame/frames.\n");
1452  il->isr_stats.sch++;
1453  }
1454 
1455  /* Alive notification via Rx interrupt will do the real work */
1456  if (inta & CSR_INT_BIT_ALIVE) {
1457  D_ISR("Alive interrupt\n");
1458  il->isr_stats.alive++;
1459  }
1460  }
1461 #endif
1462  /* Safely ignore these bits for debug checks below */
1463  inta &= ~(CSR_INT_BIT_SCD | CSR_INT_BIT_ALIVE);
1464 
1465  /* Error detected by uCode */
1466  if (inta & CSR_INT_BIT_SW_ERR) {
1467  IL_ERR("Microcode SW error detected. " "Restarting 0x%X.\n",
1468  inta);
1469  il->isr_stats.sw++;
1470  il_irq_handle_error(il);
1471  handled |= CSR_INT_BIT_SW_ERR;
1472  }
1473 
1474  /* uCode wakes up after power-down sleep */
1475  if (inta & CSR_INT_BIT_WAKEUP) {
1476  D_ISR("Wakeup interrupt\n");
1478  il_txq_update_write_ptr(il, &il->txq[0]);
1479  il_txq_update_write_ptr(il, &il->txq[1]);
1480  il_txq_update_write_ptr(il, &il->txq[2]);
1481  il_txq_update_write_ptr(il, &il->txq[3]);
1482  il_txq_update_write_ptr(il, &il->txq[4]);
1483  il_txq_update_write_ptr(il, &il->txq[5]);
1484 
1485  il->isr_stats.wakeup++;
1486  handled |= CSR_INT_BIT_WAKEUP;
1487  }
1488 
1489  /* All uCode command responses, including Tx command responses,
1490  * Rx "responses" (frame-received notification), and other
1491  * notifications from uCode come through here*/
1492  if (inta & (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX)) {
1493  il3945_rx_handle(il);
1494  il->isr_stats.rx++;
1495  handled |= (CSR_INT_BIT_FH_RX | CSR_INT_BIT_SW_RX);
1496  }
1497 
1498  if (inta & CSR_INT_BIT_FH_TX) {
1499  D_ISR("Tx interrupt\n");
1500  il->isr_stats.tx++;
1501 
1502  _il_wr(il, CSR_FH_INT_STATUS, (1 << 6));
1503  il_wr(il, FH39_TCSR_CREDIT(FH39_SRVC_CHNL), 0x0);
1504  handled |= CSR_INT_BIT_FH_TX;
1505  }
1506 
1507  if (inta & ~handled) {
1508  IL_ERR("Unhandled INTA bits 0x%08x\n", inta & ~handled);
1509  il->isr_stats.unhandled++;
1510  }
1511 
1512  if (inta & ~il->inta_mask) {
1513  IL_WARN("Disabled INTA bits 0x%08x were pending\n",
1514  inta & ~il->inta_mask);
1515  IL_WARN(" with inta_fh = 0x%08x\n", inta_fh);
1516  }
1517 
1518  /* Re-enable all interrupts */
1519  /* only Re-enable if disabled by irq */
1520  if (test_bit(S_INT_ENABLED, &il->status))
1521  il_enable_interrupts(il);
1522 
1523 #ifdef CONFIG_IWLEGACY_DEBUG
1524  if (il_get_debug_level(il) & (IL_DL_ISR)) {
1525  inta = _il_rd(il, CSR_INT);
1526  inta_mask = _il_rd(il, CSR_INT_MASK);
1527  inta_fh = _il_rd(il, CSR_FH_INT_STATUS);
1528  D_ISR("End inta 0x%08x, enabled 0x%08x, fh 0x%08x, "
1529  "flags 0x%08lx\n", inta, inta_mask, inta_fh, flags);
1530  }
1531 #endif
1532 }
1533 
1534 static int
1535 il3945_get_channels_for_scan(struct il_priv *il, enum ieee80211_band band,
1536  u8 is_active, u8 n_probes,
1537  struct il3945_scan_channel *scan_ch,
1538  struct ieee80211_vif *vif)
1539 {
1540  struct ieee80211_channel *chan;
1541  const struct ieee80211_supported_band *sband;
1542  const struct il_channel_info *ch_info;
1543  u16 passive_dwell = 0;
1544  u16 active_dwell = 0;
1545  int added, i;
1546 
1547  sband = il_get_hw_mode(il, band);
1548  if (!sband)
1549  return 0;
1550 
1551  active_dwell = il_get_active_dwell_time(il, band, n_probes);
1552  passive_dwell = il_get_passive_dwell_time(il, band, vif);
1553 
1554  if (passive_dwell <= active_dwell)
1555  passive_dwell = active_dwell + 1;
1556 
1557  for (i = 0, added = 0; i < il->scan_request->n_channels; i++) {
1558  chan = il->scan_request->channels[i];
1559 
1560  if (chan->band != band)
1561  continue;
1562 
1563  scan_ch->channel = chan->hw_value;
1564 
1565  ch_info = il_get_channel_info(il, band, scan_ch->channel);
1566  if (!il_is_channel_valid(ch_info)) {
1567  D_SCAN("Channel %d is INVALID for this band.\n",
1568  scan_ch->channel);
1569  continue;
1570  }
1571 
1572  scan_ch->active_dwell = cpu_to_le16(active_dwell);
1573  scan_ch->passive_dwell = cpu_to_le16(passive_dwell);
1574  /* If passive , set up for auto-switch
1575  * and use long active_dwell time.
1576  */
1577  if (!is_active || il_is_channel_passive(ch_info) ||
1578  (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)) {
1579  scan_ch->type = 0; /* passive */
1580  if (IL_UCODE_API(il->ucode_ver) == 1)
1581  scan_ch->active_dwell =
1582  cpu_to_le16(passive_dwell - 1);
1583  } else {
1584  scan_ch->type = 1; /* active */
1585  }
1586 
1587  /* Set direct probe bits. These may be used both for active
1588  * scan channels (probes gets sent right away),
1589  * or for passive channels (probes get se sent only after
1590  * hearing clear Rx packet).*/
1591  if (IL_UCODE_API(il->ucode_ver) >= 2) {
1592  if (n_probes)
1593  scan_ch->type |= IL39_SCAN_PROBE_MASK(n_probes);
1594  } else {
1595  /* uCode v1 does not allow setting direct probe bits on
1596  * passive channel. */
1597  if ((scan_ch->type & 1) && n_probes)
1598  scan_ch->type |= IL39_SCAN_PROBE_MASK(n_probes);
1599  }
1600 
1601  /* Set txpower levels to defaults */
1602  scan_ch->tpc.dsp_atten = 110;
1603  /* scan_pwr_info->tpc.dsp_atten; */
1604 
1605  /*scan_pwr_info->tpc.tx_gain; */
1606  if (band == IEEE80211_BAND_5GHZ)
1607  scan_ch->tpc.tx_gain = ((1 << 5) | (3 << 3)) | 3;
1608  else {
1609  scan_ch->tpc.tx_gain = ((1 << 5) | (5 << 3));
1610  /* NOTE: if we were doing 6Mb OFDM for scans we'd use
1611  * power level:
1612  * scan_ch->tpc.tx_gain = ((1 << 5) | (2 << 3)) | 3;
1613  */
1614  }
1615 
1616  D_SCAN("Scanning %d [%s %d]\n", scan_ch->channel,
1617  (scan_ch->type & 1) ? "ACTIVE" : "PASSIVE",
1618  (scan_ch->type & 1) ? active_dwell : passive_dwell);
1619 
1620  scan_ch++;
1621  added++;
1622  }
1623 
1624  D_SCAN("total channels to scan %d\n", added);
1625  return added;
1626 }
1627 
1628 static void
1629 il3945_init_hw_rates(struct il_priv *il, struct ieee80211_rate *rates)
1630 {
1631  int i;
1632 
1633  for (i = 0; i < RATE_COUNT_LEGACY; i++) {
1634  rates[i].bitrate = il3945_rates[i].ieee * 5;
1635  rates[i].hw_value = i; /* Rate scaling will work on idxes */
1636  rates[i].hw_value_short = i;
1637  rates[i].flags = 0;
1638  if (i > IL39_LAST_OFDM_RATE || i < IL_FIRST_OFDM_RATE) {
1639  /*
1640  * If CCK != 1M then set short preamble rate flag.
1641  */
1642  rates[i].flags |=
1643  (il3945_rates[i].plcp ==
1645  }
1646  }
1647 }
1648 
1649 /******************************************************************************
1650  *
1651  * uCode download functions
1652  *
1653  ******************************************************************************/
1654 
1655 static void
1656 il3945_dealloc_ucode_pci(struct il_priv *il)
1657 {
1658  il_free_fw_desc(il->pci_dev, &il->ucode_code);
1659  il_free_fw_desc(il->pci_dev, &il->ucode_data);
1660  il_free_fw_desc(il->pci_dev, &il->ucode_data_backup);
1661  il_free_fw_desc(il->pci_dev, &il->ucode_init);
1662  il_free_fw_desc(il->pci_dev, &il->ucode_init_data);
1663  il_free_fw_desc(il->pci_dev, &il->ucode_boot);
1664 }
1665 
1670 static int
1671 il3945_verify_inst_full(struct il_priv *il, __le32 * image, u32 len)
1672 {
1673  u32 val;
1674  u32 save_len = len;
1675  int rc = 0;
1676  u32 errcnt;
1677 
1678  D_INFO("ucode inst image size is %u\n", len);
1679 
1681 
1682  errcnt = 0;
1683  for (; len > 0; len -= sizeof(u32), image++) {
1684  /* read data comes through single port, auto-incr addr */
1685  /* NOTE: Use the debugless read so we don't flood kernel log
1686  * if IL_DL_IO is set */
1687  val = _il_rd(il, HBUS_TARG_MEM_RDAT);
1688  if (val != le32_to_cpu(*image)) {
1689  IL_ERR("uCode INST section is invalid at "
1690  "offset 0x%x, is 0x%x, s/b 0x%x\n",
1691  save_len - len, val, le32_to_cpu(*image));
1692  rc = -EIO;
1693  errcnt++;
1694  if (errcnt >= 20)
1695  break;
1696  }
1697  }
1698 
1699  if (!errcnt)
1700  D_INFO("ucode image in INSTRUCTION memory is good\n");
1701 
1702  return rc;
1703 }
1704 
1710 static int
1711 il3945_verify_inst_sparse(struct il_priv *il, __le32 * image, u32 len)
1712 {
1713  u32 val;
1714  int rc = 0;
1715  u32 errcnt = 0;
1716  u32 i;
1717 
1718  D_INFO("ucode inst image size is %u\n", len);
1719 
1720  for (i = 0; i < len; i += 100, image += 100 / sizeof(u32)) {
1721  /* read data comes through single port, auto-incr addr */
1722  /* NOTE: Use the debugless read so we don't flood kernel log
1723  * if IL_DL_IO is set */
1725  val = _il_rd(il, HBUS_TARG_MEM_RDAT);
1726  if (val != le32_to_cpu(*image)) {
1727 #if 0 /* Enable this if you want to see details */
1728  IL_ERR("uCode INST section is invalid at "
1729  "offset 0x%x, is 0x%x, s/b 0x%x\n", i, val,
1730  *image);
1731 #endif
1732  rc = -EIO;
1733  errcnt++;
1734  if (errcnt >= 3)
1735  break;
1736  }
1737  }
1738 
1739  return rc;
1740 }
1741 
1746 static int
1747 il3945_verify_ucode(struct il_priv *il)
1748 {
1749  __le32 *image;
1750  u32 len;
1751  int rc = 0;
1752 
1753  /* Try bootstrap */
1754  image = (__le32 *) il->ucode_boot.v_addr;
1755  len = il->ucode_boot.len;
1756  rc = il3945_verify_inst_sparse(il, image, len);
1757  if (rc == 0) {
1758  D_INFO("Bootstrap uCode is good in inst SRAM\n");
1759  return 0;
1760  }
1761 
1762  /* Try initialize */
1763  image = (__le32 *) il->ucode_init.v_addr;
1764  len = il->ucode_init.len;
1765  rc = il3945_verify_inst_sparse(il, image, len);
1766  if (rc == 0) {
1767  D_INFO("Initialize uCode is good in inst SRAM\n");
1768  return 0;
1769  }
1770 
1771  /* Try runtime/protocol */
1772  image = (__le32 *) il->ucode_code.v_addr;
1773  len = il->ucode_code.len;
1774  rc = il3945_verify_inst_sparse(il, image, len);
1775  if (rc == 0) {
1776  D_INFO("Runtime uCode is good in inst SRAM\n");
1777  return 0;
1778  }
1779 
1780  IL_ERR("NO VALID UCODE IMAGE IN INSTRUCTION SRAM!!\n");
1781 
1782  /* Since nothing seems to match, show first several data entries in
1783  * instruction SRAM, so maybe visual inspection will give a clue.
1784  * Selection of bootstrap image (vs. other images) is arbitrary. */
1785  image = (__le32 *) il->ucode_boot.v_addr;
1786  len = il->ucode_boot.len;
1787  rc = il3945_verify_inst_full(il, image, len);
1788 
1789  return rc;
1790 }
1791 
1792 static void
1793 il3945_nic_start(struct il_priv *il)
1794 {
1795  /* Remove all resets to allow NIC to operate */
1796  _il_wr(il, CSR_RESET, 0);
1797 }
1798 
1799 #define IL3945_UCODE_GET(item) \
1800 static u32 il3945_ucode_get_##item(const struct il_ucode_header *ucode)\
1801 { \
1802  return le32_to_cpu(ucode->v1.item); \
1803 }
1804 
1805 static u32
1806 il3945_ucode_get_header_size(u32 api_ver)
1807 {
1808  return 24;
1809 }
1810 
1811 static u8 *
1812 il3945_ucode_get_data(const struct il_ucode_header *ucode)
1813 {
1814  return (u8 *) ucode->v1.data;
1815 }
1816 
1817 IL3945_UCODE_GET(inst_size);
1820 IL3945_UCODE_GET(init_data_size);
1821 IL3945_UCODE_GET(boot_size);
1822 
1828 static int
1829 il3945_read_ucode(struct il_priv *il)
1830 {
1831  const struct il_ucode_header *ucode;
1832  int ret = -EINVAL, idx;
1833  const struct firmware *ucode_raw;
1834  /* firmware file name contains uCode/driver compatibility version */
1835  const char *name_pre = il->cfg->fw_name_pre;
1836  const unsigned int api_max = il->cfg->ucode_api_max;
1837  const unsigned int api_min = il->cfg->ucode_api_min;
1838  char buf[25];
1839  u8 *src;
1840  size_t len;
1841  u32 api_ver, inst_size, data_size, init_size, init_data_size, boot_size;
1842 
1843  /* Ask kernel firmware_class module to get the boot firmware off disk.
1844  * request_firmware() is synchronous, file is in memory on return. */
1845  for (idx = api_max; idx >= api_min; idx--) {
1846  sprintf(buf, "%s%u%s", name_pre, idx, ".ucode");
1847  ret = request_firmware(&ucode_raw, buf, &il->pci_dev->dev);
1848  if (ret < 0) {
1849  IL_ERR("%s firmware file req failed: %d\n", buf, ret);
1850  if (ret == -ENOENT)
1851  continue;
1852  else
1853  goto error;
1854  } else {
1855  if (idx < api_max)
1856  IL_ERR("Loaded firmware %s, "
1857  "which is deprecated. "
1858  " Please use API v%u instead.\n", buf,
1859  api_max);
1860  D_INFO("Got firmware '%s' file "
1861  "(%zd bytes) from disk\n", buf, ucode_raw->size);
1862  break;
1863  }
1864  }
1865 
1866  if (ret < 0)
1867  goto error;
1868 
1869  /* Make sure that we got at least our header! */
1870  if (ucode_raw->size < il3945_ucode_get_header_size(1)) {
1871  IL_ERR("File size way too small!\n");
1872  ret = -EINVAL;
1873  goto err_release;
1874  }
1875 
1876  /* Data from ucode file: header followed by uCode images */
1877  ucode = (struct il_ucode_header *)ucode_raw->data;
1878 
1879  il->ucode_ver = le32_to_cpu(ucode->ver);
1880  api_ver = IL_UCODE_API(il->ucode_ver);
1881  inst_size = il3945_ucode_get_inst_size(ucode);
1882  data_size = il3945_ucode_get_data_size(ucode);
1883  init_size = il3945_ucode_get_init_size(ucode);
1884  init_data_size = il3945_ucode_get_init_data_size(ucode);
1885  boot_size = il3945_ucode_get_boot_size(ucode);
1886  src = il3945_ucode_get_data(ucode);
1887 
1888  /* api_ver should match the api version forming part of the
1889  * firmware filename ... but we don't check for that and only rely
1890  * on the API version read from firmware header from here on forward */
1891 
1892  if (api_ver < api_min || api_ver > api_max) {
1893  IL_ERR("Driver unable to support your firmware API. "
1894  "Driver supports v%u, firmware is v%u.\n", api_max,
1895  api_ver);
1896  il->ucode_ver = 0;
1897  ret = -EINVAL;
1898  goto err_release;
1899  }
1900  if (api_ver != api_max)
1901  IL_ERR("Firmware has old API version. Expected %u, "
1902  "got %u. New firmware can be obtained "
1903  "from http://www.intellinuxwireless.org.\n", api_max,
1904  api_ver);
1905 
1906  IL_INFO("loaded firmware version %u.%u.%u.%u\n",
1909 
1910  snprintf(il->hw->wiphy->fw_version, sizeof(il->hw->wiphy->fw_version),
1911  "%u.%u.%u.%u", IL_UCODE_MAJOR(il->ucode_ver),
1913  IL_UCODE_SERIAL(il->ucode_ver));
1914 
1915  D_INFO("f/w package hdr ucode version raw = 0x%x\n", il->ucode_ver);
1916  D_INFO("f/w package hdr runtime inst size = %u\n", inst_size);
1917  D_INFO("f/w package hdr runtime data size = %u\n", data_size);
1918  D_INFO("f/w package hdr init inst size = %u\n", init_size);
1919  D_INFO("f/w package hdr init data size = %u\n", init_data_size);
1920  D_INFO("f/w package hdr boot inst size = %u\n", boot_size);
1921 
1922  /* Verify size of file vs. image size info in file's header */
1923  if (ucode_raw->size !=
1924  il3945_ucode_get_header_size(api_ver) + inst_size + data_size +
1925  init_size + init_data_size + boot_size) {
1926 
1927  D_INFO("uCode file size %zd does not match expected size\n",
1928  ucode_raw->size);
1929  ret = -EINVAL;
1930  goto err_release;
1931  }
1932 
1933  /* Verify that uCode images will fit in card's SRAM */
1934  if (inst_size > IL39_MAX_INST_SIZE) {
1935  D_INFO("uCode instr len %d too large to fit in\n", inst_size);
1936  ret = -EINVAL;
1937  goto err_release;
1938  }
1939 
1940  if (data_size > IL39_MAX_DATA_SIZE) {
1941  D_INFO("uCode data len %d too large to fit in\n", data_size);
1942  ret = -EINVAL;
1943  goto err_release;
1944  }
1945  if (init_size > IL39_MAX_INST_SIZE) {
1946  D_INFO("uCode init instr len %d too large to fit in\n",
1947  init_size);
1948  ret = -EINVAL;
1949  goto err_release;
1950  }
1951  if (init_data_size > IL39_MAX_DATA_SIZE) {
1952  D_INFO("uCode init data len %d too large to fit in\n",
1953  init_data_size);
1954  ret = -EINVAL;
1955  goto err_release;
1956  }
1957  if (boot_size > IL39_MAX_BSM_SIZE) {
1958  D_INFO("uCode boot instr len %d too large to fit in\n",
1959  boot_size);
1960  ret = -EINVAL;
1961  goto err_release;
1962  }
1963 
1964  /* Allocate ucode buffers for card's bus-master loading ... */
1965 
1966  /* Runtime instructions and 2 copies of data:
1967  * 1) unmodified from disk
1968  * 2) backup cache for save/restore during power-downs */
1969  il->ucode_code.len = inst_size;
1970  il_alloc_fw_desc(il->pci_dev, &il->ucode_code);
1971 
1972  il->ucode_data.len = data_size;
1973  il_alloc_fw_desc(il->pci_dev, &il->ucode_data);
1974 
1975  il->ucode_data_backup.len = data_size;
1976  il_alloc_fw_desc(il->pci_dev, &il->ucode_data_backup);
1977 
1978  if (!il->ucode_code.v_addr || !il->ucode_data.v_addr ||
1979  !il->ucode_data_backup.v_addr)
1980  goto err_pci_alloc;
1981 
1982  /* Initialization instructions and data */
1983  if (init_size && init_data_size) {
1984  il->ucode_init.len = init_size;
1985  il_alloc_fw_desc(il->pci_dev, &il->ucode_init);
1986 
1987  il->ucode_init_data.len = init_data_size;
1988  il_alloc_fw_desc(il->pci_dev, &il->ucode_init_data);
1989 
1990  if (!il->ucode_init.v_addr || !il->ucode_init_data.v_addr)
1991  goto err_pci_alloc;
1992  }
1993 
1994  /* Bootstrap (instructions only, no data) */
1995  if (boot_size) {
1996  il->ucode_boot.len = boot_size;
1997  il_alloc_fw_desc(il->pci_dev, &il->ucode_boot);
1998 
1999  if (!il->ucode_boot.v_addr)
2000  goto err_pci_alloc;
2001  }
2002 
2003  /* Copy images into buffers for card's bus-master reads ... */
2004 
2005  /* Runtime instructions (first block of data in file) */
2006  len = inst_size;
2007  D_INFO("Copying (but not loading) uCode instr len %zd\n", len);
2008  memcpy(il->ucode_code.v_addr, src, len);
2009  src += len;
2010 
2011  D_INFO("uCode instr buf vaddr = 0x%p, paddr = 0x%08x\n",
2012  il->ucode_code.v_addr, (u32) il->ucode_code.p_addr);
2013 
2014  /* Runtime data (2nd block)
2015  * NOTE: Copy into backup buffer will be done in il3945_up() */
2016  len = data_size;
2017  D_INFO("Copying (but not loading) uCode data len %zd\n", len);
2018  memcpy(il->ucode_data.v_addr, src, len);
2019  memcpy(il->ucode_data_backup.v_addr, src, len);
2020  src += len;
2021 
2022  /* Initialization instructions (3rd block) */
2023  if (init_size) {
2024  len = init_size;
2025  D_INFO("Copying (but not loading) init instr len %zd\n", len);
2026  memcpy(il->ucode_init.v_addr, src, len);
2027  src += len;
2028  }
2029 
2030  /* Initialization data (4th block) */
2031  if (init_data_size) {
2032  len = init_data_size;
2033  D_INFO("Copying (but not loading) init data len %zd\n", len);
2034  memcpy(il->ucode_init_data.v_addr, src, len);
2035  src += len;
2036  }
2037 
2038  /* Bootstrap instructions (5th block) */
2039  len = boot_size;
2040  D_INFO("Copying (but not loading) boot instr len %zd\n", len);
2041  memcpy(il->ucode_boot.v_addr, src, len);
2042 
2043  /* We have our copies now, allow OS release its copies */
2044  release_firmware(ucode_raw);
2045  return 0;
2046 
2047 err_pci_alloc:
2048  IL_ERR("failed to allocate pci memory\n");
2049  ret = -ENOMEM;
2050  il3945_dealloc_ucode_pci(il);
2051 
2052 err_release:
2053  release_firmware(ucode_raw);
2054 
2055 error:
2056  return ret;
2057 }
2058 
2068 static int
2069 il3945_set_ucode_ptrs(struct il_priv *il)
2070 {
2071  dma_addr_t pinst;
2072  dma_addr_t pdata;
2073 
2074  /* bits 31:0 for 3945 */
2075  pinst = il->ucode_code.p_addr;
2076  pdata = il->ucode_data_backup.p_addr;
2077 
2078  /* Tell bootstrap uCode where to find image to load */
2079  il_wr_prph(il, BSM_DRAM_INST_PTR_REG, pinst);
2080  il_wr_prph(il, BSM_DRAM_DATA_PTR_REG, pdata);
2082 
2083  /* Inst byte count must be last to set up, bit 31 signals uCode
2084  * that all new ptr/size info is in place */
2086  il->ucode_code.len | BSM_DRAM_INST_LOAD);
2087 
2088  D_INFO("Runtime uCode pointers are set.\n");
2089 
2090  return 0;
2091 }
2092 
2100 static void
2101 il3945_init_alive_start(struct il_priv *il)
2102 {
2103  /* Check alive response for "valid" sign from uCode */
2104  if (il->card_alive_init.is_valid != UCODE_VALID_OK) {
2105  /* We had an error bringing up the hardware, so take it
2106  * all the way back down so we can try again */
2107  D_INFO("Initialize Alive failed.\n");
2108  goto restart;
2109  }
2110 
2111  /* Bootstrap uCode has loaded initialize uCode ... verify inst image.
2112  * This is a paranoid check, because we would not have gotten the
2113  * "initialize" alive if code weren't properly loaded. */
2114  if (il3945_verify_ucode(il)) {
2115  /* Runtime instruction load was bad;
2116  * take it all the way back down so we can try again */
2117  D_INFO("Bad \"initialize\" uCode load.\n");
2118  goto restart;
2119  }
2120 
2121  /* Send pointers to protocol/runtime uCode image ... init code will
2122  * load and launch runtime uCode, which will send us another "Alive"
2123  * notification. */
2124  D_INFO("Initialization Alive received.\n");
2125  if (il3945_set_ucode_ptrs(il)) {
2126  /* Runtime instruction load won't happen;
2127  * take it all the way back down so we can try again */
2128  D_INFO("Couldn't set up uCode pointers.\n");
2129  goto restart;
2130  }
2131  return;
2132 
2133 restart:
2134  queue_work(il->workqueue, &il->restart);
2135 }
2136 
2142 static void
2143 il3945_alive_start(struct il_priv *il)
2144 {
2145  int thermal_spin = 0;
2146  u32 rfkill;
2147 
2148  D_INFO("Runtime Alive received.\n");
2149 
2150  if (il->card_alive.is_valid != UCODE_VALID_OK) {
2151  /* We had an error bringing up the hardware, so take it
2152  * all the way back down so we can try again */
2153  D_INFO("Alive failed.\n");
2154  goto restart;
2155  }
2156 
2157  /* Initialize uCode has loaded Runtime uCode ... verify inst image.
2158  * This is a paranoid check, because we would not have gotten the
2159  * "runtime" alive if code weren't properly loaded. */
2160  if (il3945_verify_ucode(il)) {
2161  /* Runtime instruction load was bad;
2162  * take it all the way back down so we can try again */
2163  D_INFO("Bad runtime uCode load.\n");
2164  goto restart;
2165  }
2166 
2167  rfkill = il_rd_prph(il, APMG_RFKILL_REG);
2168  D_INFO("RFKILL status: 0x%x\n", rfkill);
2169 
2170  if (rfkill & 0x1) {
2171  clear_bit(S_RFKILL, &il->status);
2172  /* if RFKILL is not on, then wait for thermal
2173  * sensor in adapter to kick in */
2174  while (il3945_hw_get_temperature(il) == 0) {
2175  thermal_spin++;
2176  udelay(10);
2177  }
2178 
2179  if (thermal_spin)
2180  D_INFO("Thermal calibration took %dus\n",
2181  thermal_spin * 10);
2182  } else
2183  set_bit(S_RFKILL, &il->status);
2184 
2185  /* After the ALIVE response, we can send commands to 3945 uCode */
2186  set_bit(S_ALIVE, &il->status);
2187 
2188  /* Enable watchdog to monitor the driver tx queues */
2189  il_setup_watchdog(il);
2190 
2191  if (il_is_rfkill(il))
2192  return;
2193 
2195 
2197 
2198  il_power_update_mode(il, true);
2199 
2200  if (il_is_associated(il)) {
2201  struct il3945_rxon_cmd *active_rxon =
2202  (struct il3945_rxon_cmd *)(&il->active);
2203 
2204  il->staging.filter_flags |= RXON_FILTER_ASSOC_MSK;
2205  active_rxon->filter_flags &= ~RXON_FILTER_ASSOC_MSK;
2206  } else {
2207  /* Initialize our rx_config data */
2209  }
2210 
2211  /* Configure Bluetooth device coexistence support */
2212  il_send_bt_config(il);
2213 
2214  set_bit(S_READY, &il->status);
2215 
2216  /* Configure the adapter for unassociated operation */
2217  il3945_commit_rxon(il);
2218 
2220 
2221  D_INFO("ALIVE processing complete.\n");
2223 
2224  return;
2225 
2226 restart:
2227  queue_work(il->workqueue, &il->restart);
2228 }
2229 
2230 static void il3945_cancel_deferred_work(struct il_priv *il);
2231 
2232 static void
2233 __il3945_down(struct il_priv *il)
2234 {
2235  unsigned long flags;
2236  int exit_pending;
2237 
2238  D_INFO(DRV_NAME " is going down\n");
2239 
2240  il_scan_cancel_timeout(il, 200);
2241 
2242  exit_pending = test_and_set_bit(S_EXIT_PENDING, &il->status);
2243 
2244  /* Stop TX queues watchdog. We need to have S_EXIT_PENDING bit set
2245  * to prevent rearm timer */
2246  del_timer_sync(&il->watchdog);
2247 
2248  /* Station information will now be cleared in device */
2251  il_clear_driver_stations(il);
2252 
2253  /* Unblock any waiting calls */
2255 
2256  /* Wipe out the EXIT_PENDING status bit if we are not actually
2257  * exiting the module */
2258  if (!exit_pending)
2260 
2261  /* stop and reset the on-board processor */
2263 
2264  /* tell the device to stop sending interrupts */
2265  spin_lock_irqsave(&il->lock, flags);
2266  il_disable_interrupts(il);
2267  spin_unlock_irqrestore(&il->lock, flags);
2268  il3945_synchronize_irq(il);
2269 
2270  if (il->mac80211_registered)
2272 
2273  /* If we have not previously called il3945_init() then
2274  * clear all bits but the RF Kill bits and return */
2275  if (!il_is_init(il)) {
2276  il->status =
2277  test_bit(S_RFKILL, &il->status) << S_RFKILL |
2280  goto exit;
2281  }
2282 
2283  /* ...otherwise clear out all the status bits but the RF Kill
2284  * bit and continue taking the NIC down. */
2285  il->status &=
2286  test_bit(S_RFKILL, &il->status) << S_RFKILL |
2288  test_bit(S_FW_ERROR, &il->status) << S_FW_ERROR |
2290 
2291  /*
2292  * We disabled and synchronized interrupt, and priv->mutex is taken, so
2293  * here is the only thread which will program device registers, but
2294  * still have lockdep assertions, so we are taking reg_lock.
2295  */
2296  spin_lock_irq(&il->reg_lock);
2297  /* FIXME: il_grab_nic_access if rfkill is off ? */
2298 
2300  il3945_hw_rxq_stop(il);
2301  /* Power-down device's busmaster DMA clocks */
2302  _il_wr_prph(il, APMG_CLK_DIS_REG, APMG_CLK_VAL_DMA_CLK_RQT);
2303  udelay(5);
2304  /* Stop the device, and put it in low power state */
2305  _il_apm_stop(il);
2306 
2307  spin_unlock_irq(&il->reg_lock);
2308 
2310 exit:
2311  memset(&il->card_alive, 0, sizeof(struct il_alive_resp));
2312 
2313  if (il->beacon_skb)
2314  dev_kfree_skb(il->beacon_skb);
2315  il->beacon_skb = NULL;
2316 
2317  /* clear out any free frames */
2318  il3945_clear_free_frames(il);
2319 }
2320 
2321 static void
2322 il3945_down(struct il_priv *il)
2323 {
2324  mutex_lock(&il->mutex);
2325  __il3945_down(il);
2326  mutex_unlock(&il->mutex);
2327 
2328  il3945_cancel_deferred_work(il);
2329 }
2330 
2331 #define MAX_HW_RESTARTS 5
2332 
2333 static int
2334 il3945_alloc_bcast_station(struct il_priv *il)
2335 {
2336  unsigned long flags;
2337  u8 sta_id;
2338 
2339  spin_lock_irqsave(&il->sta_lock, flags);
2340  sta_id = il_prep_station(il, il_bcast_addr, false, NULL);
2341  if (sta_id == IL_INVALID_STATION) {
2342  IL_ERR("Unable to prepare broadcast station\n");
2343  spin_unlock_irqrestore(&il->sta_lock, flags);
2344 
2345  return -EINVAL;
2346  }
2347 
2348  il->stations[sta_id].used |= IL_STA_DRIVER_ACTIVE;
2349  il->stations[sta_id].used |= IL_STA_BCAST;
2350  spin_unlock_irqrestore(&il->sta_lock, flags);
2351 
2352  return 0;
2353 }
2354 
2355 static int
2356 __il3945_up(struct il_priv *il)
2357 {
2358  int rc, i;
2359 
2360  rc = il3945_alloc_bcast_station(il);
2361  if (rc)
2362  return rc;
2363 
2364  if (test_bit(S_EXIT_PENDING, &il->status)) {
2365  IL_WARN("Exit pending; will not bring the NIC up\n");
2366  return -EIO;
2367  }
2368 
2369  if (!il->ucode_data_backup.v_addr || !il->ucode_data.v_addr) {
2370  IL_ERR("ucode not available for device bring up\n");
2371  return -EIO;
2372  }
2373 
2374  /* If platform's RF_KILL switch is NOT set to KILL */
2376  clear_bit(S_RFKILL, &il->status);
2377  else {
2378  set_bit(S_RFKILL, &il->status);
2379  IL_WARN("Radio disabled by HW RF Kill switch\n");
2380  return -ENODEV;
2381  }
2382 
2383  _il_wr(il, CSR_INT, 0xFFFFFFFF);
2384 
2385  rc = il3945_hw_nic_init(il);
2386  if (rc) {
2387  IL_ERR("Unable to int nic\n");
2388  return rc;
2389  }
2390 
2391  /* make sure rfkill handshake bits are cleared */
2394 
2395  /* clear (again), then enable host interrupts */
2396  _il_wr(il, CSR_INT, 0xFFFFFFFF);
2397  il_enable_interrupts(il);
2398 
2399  /* really make sure rfkill handshake bits are cleared */
2402 
2403  /* Copy original ucode data image from disk into backup cache.
2404  * This will be used to initialize the on-board processor's
2405  * data SRAM for a clean start when the runtime program first loads. */
2406  memcpy(il->ucode_data_backup.v_addr, il->ucode_data.v_addr,
2407  il->ucode_data.len);
2408 
2409  /* We return success when we resume from suspend and rf_kill is on. */
2410  if (test_bit(S_RFKILL, &il->status))
2411  return 0;
2412 
2413  for (i = 0; i < MAX_HW_RESTARTS; i++) {
2414 
2415  /* load bootstrap state machine,
2416  * load bootstrap program into processor's memory,
2417  * prepare to load the "initialize" uCode */
2418  rc = il->ops->load_ucode(il);
2419 
2420  if (rc) {
2421  IL_ERR("Unable to set up bootstrap uCode: %d\n", rc);
2422  continue;
2423  }
2424 
2425  /* start card; "initialize" will load runtime ucode */
2426  il3945_nic_start(il);
2427 
2428  D_INFO(DRV_NAME " is coming up\n");
2429 
2430  return 0;
2431  }
2432 
2433  set_bit(S_EXIT_PENDING, &il->status);
2434  __il3945_down(il);
2436 
2437  /* tried to restart and config the device for as long as our
2438  * patience could withstand */
2439  IL_ERR("Unable to initialize device after %d attempts.\n", i);
2440  return -EIO;
2441 }
2442 
2443 /*****************************************************************************
2444  *
2445  * Workqueue callbacks
2446  *
2447  *****************************************************************************/
2448 
2449 static void
2450 il3945_bg_init_alive_start(struct work_struct *data)
2451 {
2452  struct il_priv *il =
2453  container_of(data, struct il_priv, init_alive_start.work);
2454 
2455  mutex_lock(&il->mutex);
2456  if (test_bit(S_EXIT_PENDING, &il->status))
2457  goto out;
2458 
2459  il3945_init_alive_start(il);
2460 out:
2461  mutex_unlock(&il->mutex);
2462 }
2463 
2464 static void
2465 il3945_bg_alive_start(struct work_struct *data)
2466 {
2467  struct il_priv *il =
2468  container_of(data, struct il_priv, alive_start.work);
2469 
2470  mutex_lock(&il->mutex);
2471  if (test_bit(S_EXIT_PENDING, &il->status) || il->txq == NULL)
2472  goto out;
2473 
2474  il3945_alive_start(il);
2475 out:
2476  mutex_unlock(&il->mutex);
2477 }
2478 
2479 /*
2480  * 3945 cannot interrupt driver when hardware rf kill switch toggles;
2481  * driver must poll CSR_GP_CNTRL_REG register for change. This register
2482  * *is* readable even when device has been SW_RESET into low power mode
2483  * (e.g. during RF KILL).
2484  */
2485 static void
2486 il3945_rfkill_poll(struct work_struct *data)
2487 {
2488  struct il_priv *il =
2489  container_of(data, struct il_priv, _3945.rfkill_poll.work);
2490  bool old_rfkill = test_bit(S_RFKILL, &il->status);
2491  bool new_rfkill =
2493 
2494  if (new_rfkill != old_rfkill) {
2495  if (new_rfkill)
2496  set_bit(S_RFKILL, &il->status);
2497  else
2498  clear_bit(S_RFKILL, &il->status);
2499 
2500  wiphy_rfkill_set_hw_state(il->hw->wiphy, new_rfkill);
2501 
2502  D_RF_KILL("RF_KILL bit toggled to %s.\n",
2503  new_rfkill ? "disable radio" : "enable radio");
2504  }
2505 
2506  /* Keep this running, even if radio now enabled. This will be
2507  * cancelled in mac_start() if system decides to start again */
2508  queue_delayed_work(il->workqueue, &il->_3945.rfkill_poll,
2509  round_jiffies_relative(2 * HZ));
2510 
2511 }
2512 
2513 int
2515 {
2516  struct il_host_cmd cmd = {
2517  .id = C_SCAN,
2518  .len = sizeof(struct il3945_scan_cmd),
2519  .flags = CMD_SIZE_HUGE,
2520  };
2521  struct il3945_scan_cmd *scan;
2522  u8 n_probes = 0;
2523  enum ieee80211_band band;
2524  bool is_active = false;
2525  int ret;
2526  u16 len;
2527 
2528  lockdep_assert_held(&il->mutex);
2529 
2530  if (!il->scan_cmd) {
2531  il->scan_cmd =
2532  kmalloc(sizeof(struct il3945_scan_cmd) + IL_MAX_SCAN_SIZE,
2533  GFP_KERNEL);
2534  if (!il->scan_cmd) {
2535  D_SCAN("Fail to allocate scan memory\n");
2536  return -ENOMEM;
2537  }
2538  }
2539  scan = il->scan_cmd;
2540  memset(scan, 0, sizeof(struct il3945_scan_cmd) + IL_MAX_SCAN_SIZE);
2541 
2544 
2545  if (il_is_associated(il)) {
2546  u16 interval;
2547  u32 extra;
2548  u32 suspend_time = 100;
2549  u32 scan_suspend_time = 100;
2550 
2551  D_INFO("Scanning while associated...\n");
2552 
2553  interval = vif->bss_conf.beacon_int;
2554 
2555  scan->suspend_time = 0;
2556  scan->max_out_time = cpu_to_le32(200 * 1024);
2557  if (!interval)
2558  interval = suspend_time;
2559  /*
2560  * suspend time format:
2561  * 0-19: beacon interval in usec (time before exec.)
2562  * 20-23: 0
2563  * 24-31: number of beacons (suspend between channels)
2564  */
2565 
2566  extra = (suspend_time / interval) << 24;
2567  scan_suspend_time =
2568  0xFF0FFFFF & (extra | ((suspend_time % interval) * 1024));
2569 
2570  scan->suspend_time = cpu_to_le32(scan_suspend_time);
2571  D_SCAN("suspend_time 0x%X beacon interval %d\n",
2572  scan_suspend_time, interval);
2573  }
2574 
2575  if (il->scan_request->n_ssids) {
2576  int i, p = 0;
2577  D_SCAN("Kicking off active scan\n");
2578  for (i = 0; i < il->scan_request->n_ssids; i++) {
2579  /* always does wildcard anyway */
2580  if (!il->scan_request->ssids[i].ssid_len)
2581  continue;
2582  scan->direct_scan[p].id = WLAN_EID_SSID;
2583  scan->direct_scan[p].len =
2584  il->scan_request->ssids[i].ssid_len;
2585  memcpy(scan->direct_scan[p].ssid,
2586  il->scan_request->ssids[i].ssid,
2587  il->scan_request->ssids[i].ssid_len);
2588  n_probes++;
2589  p++;
2590  }
2591  is_active = true;
2592  } else
2593  D_SCAN("Kicking off passive scan.\n");
2594 
2595  /* We don't build a direct scan probe request; the uCode will do
2596  * that based on the direct_mask added to each channel entry */
2597  scan->tx_cmd.tx_flags = TX_CMD_FLG_SEQ_CTL_MSK;
2598  scan->tx_cmd.sta_id = il->hw_params.bcast_id;
2599  scan->tx_cmd.stop_time.life_time = TX_CMD_LIFE_TIME_INFINITE;
2600 
2601  /* flags + rate selection */
2602 
2603  switch (il->scan_band) {
2604  case IEEE80211_BAND_2GHZ:
2606  scan->tx_cmd.rate = RATE_1M_PLCP;
2607  band = IEEE80211_BAND_2GHZ;
2608  break;
2609  case IEEE80211_BAND_5GHZ:
2610  scan->tx_cmd.rate = RATE_6M_PLCP;
2611  band = IEEE80211_BAND_5GHZ;
2612  break;
2613  default:
2614  IL_WARN("Invalid scan band\n");
2615  return -EIO;
2616  }
2617 
2618  /*
2619  * If active scaning is requested but a certain channel is marked
2620  * passive, we can do active scanning if we detect transmissions. For
2621  * passive only scanning disable switching to active on any channel.
2622  */
2623  scan->good_CRC_th =
2625 
2626  len =
2627  il_fill_probe_req(il, (struct ieee80211_mgmt *)scan->data,
2628  vif->addr, il->scan_request->ie,
2629  il->scan_request->ie_len,
2630  IL_MAX_SCAN_SIZE - sizeof(*scan));
2631  scan->tx_cmd.len = cpu_to_le16(len);
2632 
2633  /* select Rx antennas */
2634  scan->flags |= il3945_get_antenna_flags(il);
2635 
2636  scan->channel_count =
2637  il3945_get_channels_for_scan(il, band, is_active, n_probes,
2638  (void *)&scan->data[len], vif);
2639  if (scan->channel_count == 0) {
2640  D_SCAN("channel count %d\n", scan->channel_count);
2641  return -EIO;
2642  }
2643 
2644  cmd.len +=
2645  le16_to_cpu(scan->tx_cmd.len) +
2646  scan->channel_count * sizeof(struct il3945_scan_channel);
2647  cmd.data = scan;
2648  scan->len = cpu_to_le16(cmd.len);
2649 
2650  set_bit(S_SCAN_HW, &il->status);
2651  ret = il_send_cmd_sync(il, &cmd);
2652  if (ret)
2653  clear_bit(S_SCAN_HW, &il->status);
2654  return ret;
2655 }
2656 
2657 void
2659 {
2660  /*
2661  * Since setting the RXON may have been deferred while
2662  * performing the scan, fire one off if needed
2663  */
2664  if (memcmp(&il->staging, &il->active, sizeof(il->staging)))
2665  il3945_commit_rxon(il);
2666 }
2667 
2668 static void
2669 il3945_bg_restart(struct work_struct *data)
2670 {
2671  struct il_priv *il = container_of(data, struct il_priv, restart);
2672 
2673  if (test_bit(S_EXIT_PENDING, &il->status))
2674  return;
2675 
2676  if (test_and_clear_bit(S_FW_ERROR, &il->status)) {
2677  mutex_lock(&il->mutex);
2678  il->is_open = 0;
2679  mutex_unlock(&il->mutex);
2680  il3945_down(il);
2681  ieee80211_restart_hw(il->hw);
2682  } else {
2683  il3945_down(il);
2684 
2685  mutex_lock(&il->mutex);
2686  if (test_bit(S_EXIT_PENDING, &il->status)) {
2687  mutex_unlock(&il->mutex);
2688  return;
2689  }
2690 
2691  __il3945_up(il);
2692  mutex_unlock(&il->mutex);
2693  }
2694 }
2695 
2696 static void
2697 il3945_bg_rx_replenish(struct work_struct *data)
2698 {
2699  struct il_priv *il = container_of(data, struct il_priv, rx_replenish);
2700 
2701  mutex_lock(&il->mutex);
2702  if (test_bit(S_EXIT_PENDING, &il->status))
2703  goto out;
2704 
2705  il3945_rx_replenish(il);
2706 out:
2707  mutex_unlock(&il->mutex);
2708 }
2709 
2710 void
2712 {
2713  int rc = 0;
2714  struct ieee80211_conf *conf = NULL;
2715 
2716  if (!il->vif || !il->is_open)
2717  return;
2718 
2719  D_ASSOC("Associated as %d to: %pM\n", il->vif->bss_conf.aid,
2720  il->active.bssid_addr);
2721 
2722  if (test_bit(S_EXIT_PENDING, &il->status))
2723  return;
2724 
2725  il_scan_cancel_timeout(il, 200);
2726 
2727  conf = &il->hw->conf;
2728 
2729  il->staging.filter_flags &= ~RXON_FILTER_ASSOC_MSK;
2730  il3945_commit_rxon(il);
2731 
2732  rc = il_send_rxon_timing(il);
2733  if (rc)
2734  IL_WARN("C_RXON_TIMING failed - " "Attempting to continue.\n");
2735 
2736  il->staging.filter_flags |= RXON_FILTER_ASSOC_MSK;
2737 
2738  il->staging.assoc_id = cpu_to_le16(il->vif->bss_conf.aid);
2739 
2740  D_ASSOC("assoc id %d beacon interval %d\n", il->vif->bss_conf.aid,
2741  il->vif->bss_conf.beacon_int);
2742 
2743  if (il->vif->bss_conf.use_short_preamble)
2744  il->staging.flags |= RXON_FLG_SHORT_PREAMBLE_MSK;
2745  else
2746  il->staging.flags &= ~RXON_FLG_SHORT_PREAMBLE_MSK;
2747 
2748  if (il->staging.flags & RXON_FLG_BAND_24G_MSK) {
2749  if (il->vif->bss_conf.use_short_slot)
2750  il->staging.flags |= RXON_FLG_SHORT_SLOT_MSK;
2751  else
2752  il->staging.flags &= ~RXON_FLG_SHORT_SLOT_MSK;
2753  }
2754 
2755  il3945_commit_rxon(il);
2756 
2757  switch (il->vif->type) {
2760  break;
2761  case NL80211_IFTYPE_ADHOC:
2762  il3945_send_beacon_cmd(il);
2763  break;
2764  default:
2765  IL_ERR("%s Should not be called in %d mode\n", __func__,
2766  il->vif->type);
2767  break;
2768  }
2769 }
2770 
2771 /*****************************************************************************
2772  *
2773  * mac80211 entry point functions
2774  *
2775  *****************************************************************************/
2776 
2777 #define UCODE_READY_TIMEOUT (2 * HZ)
2778 
2779 static int
2780 il3945_mac_start(struct ieee80211_hw *hw)
2781 {
2782  struct il_priv *il = hw->priv;
2783  int ret;
2784 
2785  /* we should be verifying the device is ready to be opened */
2786  mutex_lock(&il->mutex);
2787  D_MAC80211("enter\n");
2788 
2789  /* fetch ucode file from disk, alloc and copy to bus-master buffers ...
2790  * ucode filename and max sizes are card-specific. */
2791 
2792  if (!il->ucode_code.len) {
2793  ret = il3945_read_ucode(il);
2794  if (ret) {
2795  IL_ERR("Could not read microcode: %d\n", ret);
2796  mutex_unlock(&il->mutex);
2797  goto out_release_irq;
2798  }
2799  }
2800 
2801  ret = __il3945_up(il);
2802 
2803  mutex_unlock(&il->mutex);
2804 
2805  if (ret)
2806  goto out_release_irq;
2807 
2808  D_INFO("Start UP work.\n");
2809 
2810  /* Wait for START_ALIVE from ucode. Otherwise callbacks from
2811  * mac80211 will not be run successfully. */
2813  test_bit(S_READY, &il->status),
2815  if (!ret) {
2816  if (!test_bit(S_READY, &il->status)) {
2817  IL_ERR("Wait for START_ALIVE timeout after %dms.\n",
2819  ret = -ETIMEDOUT;
2820  goto out_release_irq;
2821  }
2822  }
2823 
2824  /* ucode is running and will send rfkill notifications,
2825  * no need to poll the killswitch state anymore */
2826  cancel_delayed_work(&il->_3945.rfkill_poll);
2827 
2828  il->is_open = 1;
2829  D_MAC80211("leave\n");
2830  return 0;
2831 
2832 out_release_irq:
2833  il->is_open = 0;
2834  D_MAC80211("leave - failed\n");
2835  return ret;
2836 }
2837 
2838 static void
2839 il3945_mac_stop(struct ieee80211_hw *hw)
2840 {
2841  struct il_priv *il = hw->priv;
2842 
2843  D_MAC80211("enter\n");
2844 
2845  if (!il->is_open) {
2846  D_MAC80211("leave - skip\n");
2847  return;
2848  }
2849 
2850  il->is_open = 0;
2851 
2852  il3945_down(il);
2853 
2855 
2856  /* start polling the killswitch state again */
2857  queue_delayed_work(il->workqueue, &il->_3945.rfkill_poll,
2858  round_jiffies_relative(2 * HZ));
2859 
2860  D_MAC80211("leave\n");
2861 }
2862 
2863 static void
2864 il3945_mac_tx(struct ieee80211_hw *hw,
2865  struct ieee80211_tx_control *control,
2866  struct sk_buff *skb)
2867 {
2868  struct il_priv *il = hw->priv;
2869 
2870  D_MAC80211("enter\n");
2871 
2872  D_TX("dev->xmit(%d bytes) at rate 0x%02x\n", skb->len,
2873  ieee80211_get_tx_rate(hw, IEEE80211_SKB_CB(skb))->bitrate);
2874 
2875  if (il3945_tx_skb(il, control->sta, skb))
2876  dev_kfree_skb_any(skb);
2877 
2878  D_MAC80211("leave\n");
2879 }
2880 
2881 void
2883 {
2884  struct ieee80211_vif *vif = il->vif;
2885  int rc = 0;
2886 
2887  if (test_bit(S_EXIT_PENDING, &il->status))
2888  return;
2889 
2890  /* The following should be done only at AP bring up */
2891  if (!(il_is_associated(il))) {
2892 
2893  /* RXON - unassoc (to set timing command) */
2894  il->staging.filter_flags &= ~RXON_FILTER_ASSOC_MSK;
2895  il3945_commit_rxon(il);
2896 
2897  /* RXON Timing */
2898  rc = il_send_rxon_timing(il);
2899  if (rc)
2900  IL_WARN("C_RXON_TIMING failed - "
2901  "Attempting to continue.\n");
2902 
2903  il->staging.assoc_id = 0;
2904 
2905  if (vif->bss_conf.use_short_preamble)
2906  il->staging.flags |= RXON_FLG_SHORT_PREAMBLE_MSK;
2907  else
2908  il->staging.flags &= ~RXON_FLG_SHORT_PREAMBLE_MSK;
2909 
2910  if (il->staging.flags & RXON_FLG_BAND_24G_MSK) {
2911  if (vif->bss_conf.use_short_slot)
2912  il->staging.flags |= RXON_FLG_SHORT_SLOT_MSK;
2913  else
2914  il->staging.flags &= ~RXON_FLG_SHORT_SLOT_MSK;
2915  }
2916  /* restore RXON assoc */
2917  il->staging.filter_flags |= RXON_FILTER_ASSOC_MSK;
2918  il3945_commit_rxon(il);
2919  }
2920  il3945_send_beacon_cmd(il);
2921 }
2922 
2923 static int
2924 il3945_mac_set_key(struct ieee80211_hw *hw, enum set_key_cmd cmd,
2925  struct ieee80211_vif *vif, struct ieee80211_sta *sta,
2926  struct ieee80211_key_conf *key)
2927 {
2928  struct il_priv *il = hw->priv;
2929  int ret = 0;
2930  u8 sta_id = IL_INVALID_STATION;
2931  u8 static_key;
2932 
2933  D_MAC80211("enter\n");
2934 
2935  if (il3945_mod_params.sw_crypto) {
2936  D_MAC80211("leave - hwcrypto disabled\n");
2937  return -EOPNOTSUPP;
2938  }
2939 
2940  /*
2941  * To support IBSS RSN, don't program group keys in IBSS, the
2942  * hardware will then not attempt to decrypt the frames.
2943  */
2944  if (vif->type == NL80211_IFTYPE_ADHOC &&
2945  !(key->flags & IEEE80211_KEY_FLAG_PAIRWISE)) {
2946  D_MAC80211("leave - IBSS RSN\n");
2947  return -EOPNOTSUPP;
2948  }
2949 
2950  static_key = !il_is_associated(il);
2951 
2952  if (!static_key) {
2953  sta_id = il_sta_id_or_broadcast(il, sta);
2954  if (sta_id == IL_INVALID_STATION) {
2955  D_MAC80211("leave - station not found\n");
2956  return -EINVAL;
2957  }
2958  }
2959 
2960  mutex_lock(&il->mutex);
2961  il_scan_cancel_timeout(il, 100);
2962 
2963  switch (cmd) {
2964  case SET_KEY:
2965  if (static_key)
2966  ret = il3945_set_static_key(il, key);
2967  else
2968  ret = il3945_set_dynamic_key(il, key, sta_id);
2969  D_MAC80211("enable hwcrypto key\n");
2970  break;
2971  case DISABLE_KEY:
2972  if (static_key)
2973  ret = il3945_remove_static_key(il);
2974  else
2975  ret = il3945_clear_sta_key_info(il, sta_id);
2976  D_MAC80211("disable hwcrypto key\n");
2977  break;
2978  default:
2979  ret = -EINVAL;
2980  }
2981 
2982  D_MAC80211("leave ret %d\n", ret);
2983  mutex_unlock(&il->mutex);
2984 
2985  return ret;
2986 }
2987 
2988 static int
2989 il3945_mac_sta_add(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
2990  struct ieee80211_sta *sta)
2991 {
2992  struct il_priv *il = hw->priv;
2993  struct il3945_sta_priv *sta_priv = (void *)sta->drv_priv;
2994  int ret;
2995  bool is_ap = vif->type == NL80211_IFTYPE_STATION;
2996  u8 sta_id;
2997 
2998  mutex_lock(&il->mutex);
2999  D_INFO("station %pM\n", sta->addr);
3000  sta_priv->common.sta_id = IL_INVALID_STATION;
3001 
3002  ret = il_add_station_common(il, sta->addr, is_ap, sta, &sta_id);
3003  if (ret) {
3004  IL_ERR("Unable to add station %pM (%d)\n", sta->addr, ret);
3005  /* Should we return success if return code is EEXIST ? */
3006  mutex_unlock(&il->mutex);
3007  return ret;
3008  }
3009 
3010  sta_priv->common.sta_id = sta_id;
3011 
3012  /* Initialize rate scaling */
3013  D_INFO("Initializing rate scaling for station %pM\n", sta->addr);
3014  il3945_rs_rate_init(il, sta, sta_id);
3015  mutex_unlock(&il->mutex);
3016 
3017  return 0;
3018 }
3019 
3020 static void
3021 il3945_configure_filter(struct ieee80211_hw *hw, unsigned int changed_flags,
3022  unsigned int *total_flags, u64 multicast)
3023 {
3024  struct il_priv *il = hw->priv;
3025  __le32 filter_or = 0, filter_nand = 0;
3026 
3027 #define CHK(test, flag) do { \
3028  if (*total_flags & (test)) \
3029  filter_or |= (flag); \
3030  else \
3031  filter_nand |= (flag); \
3032  } while (0)
3033 
3034  D_MAC80211("Enter: changed: 0x%x, total: 0x%x\n", changed_flags,
3035  *total_flags);
3036 
3040 
3041 #undef CHK
3042 
3043  mutex_lock(&il->mutex);
3044 
3045  il->staging.filter_flags &= ~filter_nand;
3046  il->staging.filter_flags |= filter_or;
3047 
3048  /*
3049  * Not committing directly because hardware can perform a scan,
3050  * but even if hw is ready, committing here breaks for some reason,
3051  * we'll eventually commit the filter flags change anyway.
3052  */
3053 
3054  mutex_unlock(&il->mutex);
3055 
3056  /*
3057  * Receiving all multicast frames is always enabled by the
3058  * default flags setup in il_connection_init_rx_config()
3059  * since we currently do not support programming multicast
3060  * filters into the device.
3061  */
3062  *total_flags &=
3065 }
3066 
3067 /*****************************************************************************
3068  *
3069  * sysfs attributes
3070  *
3071  *****************************************************************************/
3072 
3073 #ifdef CONFIG_IWLEGACY_DEBUG
3074 
3075 /*
3076  * The following adds a new attribute to the sysfs representation
3077  * of this device driver (i.e. a new file in /sys/bus/pci/drivers/iwl/)
3078  * used for controlling the debug level.
3079  *
3080  * See the level definitions in iwl for details.
3081  *
3082  * The debug_level being managed using sysfs below is a per device debug
3083  * level that is used instead of the global debug level if it (the per
3084  * device debug level) is set.
3085  */
3086 static ssize_t
3087 il3945_show_debug_level(struct device *d, struct device_attribute *attr,
3088  char *buf)
3089 {
3090  struct il_priv *il = dev_get_drvdata(d);
3091  return sprintf(buf, "0x%08X\n", il_get_debug_level(il));
3092 }
3093 
3094 static ssize_t
3095 il3945_store_debug_level(struct device *d, struct device_attribute *attr,
3096  const char *buf, size_t count)
3097 {
3098  struct il_priv *il = dev_get_drvdata(d);
3099  unsigned long val;
3100  int ret;
3101 
3102  ret = strict_strtoul(buf, 0, &val);
3103  if (ret)
3104  IL_INFO("%s is not in hex or decimal form.\n", buf);
3105  else
3106  il->debug_level = val;
3107 
3108  return strnlen(buf, count);
3109 }
3110 
3111 static DEVICE_ATTR(debug_level, S_IWUSR | S_IRUGO, il3945_show_debug_level,
3112  il3945_store_debug_level);
3113 
3114 #endif /* CONFIG_IWLEGACY_DEBUG */
3115 
3116 static ssize_t
3117 il3945_show_temperature(struct device *d, struct device_attribute *attr,
3118  char *buf)
3119 {
3120  struct il_priv *il = dev_get_drvdata(d);
3121 
3122  if (!il_is_alive(il))
3123  return -EAGAIN;
3124 
3125  return sprintf(buf, "%d\n", il3945_hw_get_temperature(il));
3126 }
3127 
3128 static DEVICE_ATTR(temperature, S_IRUGO, il3945_show_temperature, NULL);
3129 
3130 static ssize_t
3131 il3945_show_tx_power(struct device *d, struct device_attribute *attr, char *buf)
3132 {
3133  struct il_priv *il = dev_get_drvdata(d);
3134  return sprintf(buf, "%d\n", il->tx_power_user_lmt);
3135 }
3136 
3137 static ssize_t
3138 il3945_store_tx_power(struct device *d, struct device_attribute *attr,
3139  const char *buf, size_t count)
3140 {
3141  struct il_priv *il = dev_get_drvdata(d);
3142  char *p = (char *)buf;
3143  u32 val;
3144 
3145  val = simple_strtoul(p, &p, 10);
3146  if (p == buf)
3147  IL_INFO(": %s is not in decimal form.\n", buf);
3148  else
3149  il3945_hw_reg_set_txpower(il, val);
3150 
3151  return count;
3152 }
3153 
3154 static DEVICE_ATTR(tx_power, S_IWUSR | S_IRUGO, il3945_show_tx_power,
3155  il3945_store_tx_power);
3156 
3157 static ssize_t
3158 il3945_show_flags(struct device *d, struct device_attribute *attr, char *buf)
3159 {
3160  struct il_priv *il = dev_get_drvdata(d);
3161 
3162  return sprintf(buf, "0x%04X\n", il->active.flags);
3163 }
3164 
3165 static ssize_t
3166 il3945_store_flags(struct device *d, struct device_attribute *attr,
3167  const char *buf, size_t count)
3168 {
3169  struct il_priv *il = dev_get_drvdata(d);
3170  u32 flags = simple_strtoul(buf, NULL, 0);
3171 
3172  mutex_lock(&il->mutex);
3173  if (le32_to_cpu(il->staging.flags) != flags) {
3174  /* Cancel any currently running scans... */
3175  if (il_scan_cancel_timeout(il, 100))
3176  IL_WARN("Could not cancel scan.\n");
3177  else {
3178  D_INFO("Committing rxon.flags = 0x%04X\n", flags);
3179  il->staging.flags = cpu_to_le32(flags);
3180  il3945_commit_rxon(il);
3181  }
3182  }
3183  mutex_unlock(&il->mutex);
3184 
3185  return count;
3186 }
3187 
3188 static DEVICE_ATTR(flags, S_IWUSR | S_IRUGO, il3945_show_flags,
3189  il3945_store_flags);
3190 
3191 static ssize_t
3192 il3945_show_filter_flags(struct device *d, struct device_attribute *attr,
3193  char *buf)
3194 {
3195  struct il_priv *il = dev_get_drvdata(d);
3196 
3197  return sprintf(buf, "0x%04X\n", le32_to_cpu(il->active.filter_flags));
3198 }
3199 
3200 static ssize_t
3201 il3945_store_filter_flags(struct device *d, struct device_attribute *attr,
3202  const char *buf, size_t count)
3203 {
3204  struct il_priv *il = dev_get_drvdata(d);
3205  u32 filter_flags = simple_strtoul(buf, NULL, 0);
3206 
3207  mutex_lock(&il->mutex);
3208  if (le32_to_cpu(il->staging.filter_flags) != filter_flags) {
3209  /* Cancel any currently running scans... */
3210  if (il_scan_cancel_timeout(il, 100))
3211  IL_WARN("Could not cancel scan.\n");
3212  else {
3213  D_INFO("Committing rxon.filter_flags = " "0x%04X\n",
3214  filter_flags);
3215  il->staging.filter_flags = cpu_to_le32(filter_flags);
3216  il3945_commit_rxon(il);
3217  }
3218  }
3219  mutex_unlock(&il->mutex);
3220 
3221  return count;
3222 }
3223 
3224 static DEVICE_ATTR(filter_flags, S_IWUSR | S_IRUGO, il3945_show_filter_flags,
3225  il3945_store_filter_flags);
3226 
3227 static ssize_t
3228 il3945_show_measurement(struct device *d, struct device_attribute *attr,
3229  char *buf)
3230 {
3231  struct il_priv *il = dev_get_drvdata(d);
3232  struct il_spectrum_notification measure_report;
3233  u32 size = sizeof(measure_report), len = 0, ofs = 0;
3234  u8 *data = (u8 *) &measure_report;
3235  unsigned long flags;
3236 
3237  spin_lock_irqsave(&il->lock, flags);
3238  if (!(il->measurement_status & MEASUREMENT_READY)) {
3239  spin_unlock_irqrestore(&il->lock, flags);
3240  return 0;
3241  }
3242  memcpy(&measure_report, &il->measure_report, size);
3243  il->measurement_status = 0;
3244  spin_unlock_irqrestore(&il->lock, flags);
3245 
3246  while (size && PAGE_SIZE - len) {
3247  hex_dump_to_buffer(data + ofs, size, 16, 1, buf + len,
3248  PAGE_SIZE - len, 1);
3249  len = strlen(buf);
3250  if (PAGE_SIZE - len)
3251  buf[len++] = '\n';
3252 
3253  ofs += 16;
3254  size -= min(size, 16U);
3255  }
3256 
3257  return len;
3258 }
3259 
3260 static ssize_t
3261 il3945_store_measurement(struct device *d, struct device_attribute *attr,
3262  const char *buf, size_t count)
3263 {
3264  struct il_priv *il = dev_get_drvdata(d);
3265  struct ieee80211_measurement_params params = {
3266  .channel = le16_to_cpu(il->active.channel),
3267  .start_time = cpu_to_le64(il->_3945.last_tsf),
3268  .duration = cpu_to_le16(1),
3269  };
3270  u8 type = IL_MEASURE_BASIC;
3271  u8 buffer[32];
3272  u8 channel;
3273 
3274  if (count) {
3275  char *p = buffer;
3276  strncpy(buffer, buf, min(sizeof(buffer), count));
3277  channel = simple_strtoul(p, NULL, 0);
3278  if (channel)
3279  params.channel = channel;
3280 
3281  p = buffer;
3282  while (*p && *p != ' ')
3283  p++;
3284  if (*p)
3285  type = simple_strtoul(p + 1, NULL, 0);
3286  }
3287 
3288  D_INFO("Invoking measurement of type %d on " "channel %d (for '%s')\n",
3289  type, params.channel, buf);
3290  il3945_get_measurement(il, &params, type);
3291 
3292  return count;
3293 }
3294 
3295 static DEVICE_ATTR(measurement, S_IRUSR | S_IWUSR, il3945_show_measurement,
3296  il3945_store_measurement);
3297 
3298 static ssize_t
3299 il3945_store_retry_rate(struct device *d, struct device_attribute *attr,
3300  const char *buf, size_t count)
3301 {
3302  struct il_priv *il = dev_get_drvdata(d);
3303 
3304  il->retry_rate = simple_strtoul(buf, NULL, 0);
3305  if (il->retry_rate <= 0)
3306  il->retry_rate = 1;
3307 
3308  return count;
3309 }
3310 
3311 static ssize_t
3312 il3945_show_retry_rate(struct device *d, struct device_attribute *attr,
3313  char *buf)
3314 {
3315  struct il_priv *il = dev_get_drvdata(d);
3316  return sprintf(buf, "%d", il->retry_rate);
3317 }
3318 
3319 static DEVICE_ATTR(retry_rate, S_IWUSR | S_IRUSR, il3945_show_retry_rate,
3320  il3945_store_retry_rate);
3321 
3322 static ssize_t
3323 il3945_show_channels(struct device *d, struct device_attribute *attr, char *buf)
3324 {
3325  /* all this shit doesn't belong into sysfs anyway */
3326  return 0;
3327 }
3328 
3329 static DEVICE_ATTR(channels, S_IRUSR, il3945_show_channels, NULL);
3330 
3331 static ssize_t
3332 il3945_show_antenna(struct device *d, struct device_attribute *attr, char *buf)
3333 {
3334  struct il_priv *il = dev_get_drvdata(d);
3335 
3336  if (!il_is_alive(il))
3337  return -EAGAIN;
3338 
3339  return sprintf(buf, "%d\n", il3945_mod_params.antenna);
3340 }
3341 
3342 static ssize_t
3343 il3945_store_antenna(struct device *d, struct device_attribute *attr,
3344  const char *buf, size_t count)
3345 {
3346  struct il_priv *il __maybe_unused = dev_get_drvdata(d);
3347  int ant;
3348 
3349  if (count == 0)
3350  return 0;
3351 
3352  if (sscanf(buf, "%1i", &ant) != 1) {
3353  D_INFO("not in hex or decimal form.\n");
3354  return count;
3355  }
3356 
3357  if (ant >= 0 && ant <= 2) {
3358  D_INFO("Setting antenna select to %d.\n", ant);
3359  il3945_mod_params.antenna = (enum il3945_antenna)ant;
3360  } else
3361  D_INFO("Bad antenna select value %d.\n", ant);
3362 
3363  return count;
3364 }
3365 
3366 static DEVICE_ATTR(antenna, S_IWUSR | S_IRUGO, il3945_show_antenna,
3367  il3945_store_antenna);
3368 
3369 static ssize_t
3370 il3945_show_status(struct device *d, struct device_attribute *attr, char *buf)
3371 {
3372  struct il_priv *il = dev_get_drvdata(d);
3373  if (!il_is_alive(il))
3374  return -EAGAIN;
3375  return sprintf(buf, "0x%08x\n", (int)il->status);
3376 }
3377 
3378 static DEVICE_ATTR(status, S_IRUGO, il3945_show_status, NULL);
3379 
3380 static ssize_t
3381 il3945_dump_error_log(struct device *d, struct device_attribute *attr,
3382  const char *buf, size_t count)
3383 {
3384  struct il_priv *il = dev_get_drvdata(d);
3385  char *p = (char *)buf;
3386 
3387  if (p[0] == '1')
3389 
3390  return strnlen(buf, count);
3391 }
3392 
3393 static DEVICE_ATTR(dump_errors, S_IWUSR, NULL, il3945_dump_error_log);
3394 
3395 /*****************************************************************************
3396  *
3397  * driver setup and tear down
3398  *
3399  *****************************************************************************/
3400 
3401 static void
3402 il3945_setup_deferred_work(struct il_priv *il)
3403 {
3405 
3407 
3408  INIT_WORK(&il->restart, il3945_bg_restart);
3409  INIT_WORK(&il->rx_replenish, il3945_bg_rx_replenish);
3410  INIT_DELAYED_WORK(&il->init_alive_start, il3945_bg_init_alive_start);
3411  INIT_DELAYED_WORK(&il->alive_start, il3945_bg_alive_start);
3412  INIT_DELAYED_WORK(&il->_3945.rfkill_poll, il3945_rfkill_poll);
3413 
3415 
3417 
3418  init_timer(&il->watchdog);
3419  il->watchdog.data = (unsigned long)il;
3420  il->watchdog.function = il_bg_watchdog;
3421 
3423  (void (*)(unsigned long))il3945_irq_tasklet,
3424  (unsigned long)il);
3425 }
3426 
3427 static void
3428 il3945_cancel_deferred_work(struct il_priv *il)
3429 {
3431 
3434 
3436 }
3437 
3438 static struct attribute *il3945_sysfs_entries[] = {
3439  &dev_attr_antenna.attr,
3440  &dev_attr_channels.attr,
3441  &dev_attr_dump_errors.attr,
3442  &dev_attr_flags.attr,
3443  &dev_attr_filter_flags.attr,
3444  &dev_attr_measurement.attr,
3445  &dev_attr_retry_rate.attr,
3446  &dev_attr_status.attr,
3447  &dev_attr_temperature.attr,
3448  &dev_attr_tx_power.attr,
3449 #ifdef CONFIG_IWLEGACY_DEBUG
3450  &dev_attr_debug_level.attr,
3451 #endif
3452  NULL
3453 };
3454 
3455 static struct attribute_group il3945_attribute_group = {
3456  .name = NULL, /* put in device directory */
3457  .attrs = il3945_sysfs_entries,
3458 };
3459 
3461  .tx = il3945_mac_tx,
3462  .start = il3945_mac_start,
3463  .stop = il3945_mac_stop,
3464  .add_interface = il_mac_add_interface,
3465  .remove_interface = il_mac_remove_interface,
3466  .change_interface = il_mac_change_interface,
3467  .config = il_mac_config,
3468  .configure_filter = il3945_configure_filter,
3469  .set_key = il3945_mac_set_key,
3470  .conf_tx = il_mac_conf_tx,
3471  .reset_tsf = il_mac_reset_tsf,
3472  .bss_info_changed = il_mac_bss_info_changed,
3473  .hw_scan = il_mac_hw_scan,
3474  .sta_add = il3945_mac_sta_add,
3475  .sta_remove = il_mac_sta_remove,
3476  .tx_last_beacon = il_mac_tx_last_beacon,
3477 };
3478 
3479 static int
3480 il3945_init_drv(struct il_priv *il)
3481 {
3482  int ret;
3483  struct il3945_eeprom *eeprom = (struct il3945_eeprom *)il->eeprom;
3484 
3485  il->retry_rate = 1;
3486  il->beacon_skb = NULL;
3487 
3488  spin_lock_init(&il->sta_lock);
3489  spin_lock_init(&il->hcmd_lock);
3490 
3491  INIT_LIST_HEAD(&il->free_frames);
3492 
3493  mutex_init(&il->mutex);
3494 
3495  il->ieee_channels = NULL;
3496  il->ieee_rates = NULL;
3497  il->band = IEEE80211_BAND_2GHZ;
3498 
3501 
3502  /* initialize force reset */
3503  il->force_reset.reset_duration = IL_DELAY_NEXT_FORCE_FW_RELOAD;
3504 
3505  if (eeprom->version < EEPROM_3945_EEPROM_VERSION) {
3506  IL_WARN("Unsupported EEPROM version: 0x%04X\n",
3507  eeprom->version);
3508  ret = -EINVAL;
3509  goto err;
3510  }
3511  ret = il_init_channel_map(il);
3512  if (ret) {
3513  IL_ERR("initializing regulatory failed: %d\n", ret);
3514  goto err;
3515  }
3516 
3517  /* Set up txpower settings in driver for all channels */
3519  ret = -EIO;
3520  goto err_free_channel_map;
3521  }
3522 
3523  ret = il_init_geos(il);
3524  if (ret) {
3525  IL_ERR("initializing geos failed: %d\n", ret);
3526  goto err_free_channel_map;
3527  }
3528  il3945_init_hw_rates(il, il->ieee_rates);
3529 
3530  return 0;
3531 
3532 err_free_channel_map:
3533  il_free_channel_map(il);
3534 err:
3535  return ret;
3536 }
3537 
3538 #define IL3945_MAX_PROBE_REQUEST 200
3539 
3540 static int
3541 il3945_setup_mac(struct il_priv *il)
3542 {
3543  int ret;
3544  struct ieee80211_hw *hw = il->hw;
3545 
3546  hw->rate_control_algorithm = "iwl-3945-rs";
3547  hw->sta_data_size = sizeof(struct il3945_sta_priv);
3548  hw->vif_data_size = sizeof(struct il_vif_priv);
3549 
3550  /* Tell mac80211 our characteristics */
3552 
3553  hw->wiphy->interface_modes =
3555 
3556  hw->wiphy->flags |=
3559 
3560  hw->wiphy->max_scan_ssids = PROBE_OPTION_MAX_3945;
3561  /* we create the 802.11 header and a zero-length SSID element */
3562  hw->wiphy->max_scan_ie_len = IL3945_MAX_PROBE_REQUEST - 24 - 2;
3563 
3564  /* Default value; 4 EDCA QOS priorities */
3565  hw->queues = 4;
3566 
3567  if (il->bands[IEEE80211_BAND_2GHZ].n_channels)
3568  il->hw->wiphy->bands[IEEE80211_BAND_2GHZ] =
3569  &il->bands[IEEE80211_BAND_2GHZ];
3570 
3571  if (il->bands[IEEE80211_BAND_5GHZ].n_channels)
3572  il->hw->wiphy->bands[IEEE80211_BAND_5GHZ] =
3573  &il->bands[IEEE80211_BAND_5GHZ];
3574 
3575  il_leds_init(il);
3576 
3577  ret = ieee80211_register_hw(il->hw);
3578  if (ret) {
3579  IL_ERR("Failed to register hw (error %d)\n", ret);
3580  return ret;
3581  }
3582  il->mac80211_registered = 1;
3583 
3584  return 0;
3585 }
3586 
3587 static int
3588 il3945_pci_probe(struct pci_dev *pdev, const struct pci_device_id *ent)
3589 {
3590  int err = 0;
3591  struct il_priv *il;
3592  struct ieee80211_hw *hw;
3593  struct il_cfg *cfg = (struct il_cfg *)(ent->driver_data);
3594  struct il3945_eeprom *eeprom;
3595  unsigned long flags;
3596 
3597  /***********************
3598  * 1. Allocating HW data
3599  * ********************/
3600 
3601  hw = ieee80211_alloc_hw(sizeof(struct il_priv), &il3945_mac_ops);
3602  if (!hw) {
3603  err = -ENOMEM;
3604  goto out;
3605  }
3606  il = hw->priv;
3607  il->hw = hw;
3608  SET_IEEE80211_DEV(hw, &pdev->dev);
3609 
3611 
3612  /*
3613  * Disabling hardware scan means that mac80211 will perform scans
3614  * "the hard way", rather than using device's scan.
3615  */
3616  if (il3945_mod_params.disable_hw_scan) {
3617  D_INFO("Disabling hw_scan\n");
3618  il3945_mac_ops.hw_scan = NULL;
3619  }
3620 
3621  D_INFO("*** LOAD DRIVER ***\n");
3622  il->cfg = cfg;
3623  il->ops = &il3945_ops;
3624 #ifdef CONFIG_IWLEGACY_DEBUGFS
3625  il->debugfs_ops = &il3945_debugfs_ops;
3626 #endif
3627  il->pci_dev = pdev;
3629 
3630  /***************************
3631  * 2. Initializing PCI bus
3632  * *************************/
3636 
3637  if (pci_enable_device(pdev)) {
3638  err = -ENODEV;
3639  goto out_ieee80211_free_hw;
3640  }
3641 
3642  pci_set_master(pdev);
3643 
3644  err = pci_set_dma_mask(pdev, DMA_BIT_MASK(32));
3645  if (!err)
3646  err = pci_set_consistent_dma_mask(pdev, DMA_BIT_MASK(32));
3647  if (err) {
3648  IL_WARN("No suitable DMA available.\n");
3649  goto out_pci_disable_device;
3650  }
3651 
3652  pci_set_drvdata(pdev, il);
3653  err = pci_request_regions(pdev, DRV_NAME);
3654  if (err)
3655  goto out_pci_disable_device;
3656 
3657  /***********************
3658  * 3. Read REV Register
3659  * ********************/
3660  il->hw_base = pci_ioremap_bar(pdev, 0);
3661  if (!il->hw_base) {
3662  err = -ENODEV;
3663  goto out_pci_release_regions;
3664  }
3665 
3666  D_INFO("pci_resource_len = 0x%08llx\n",
3667  (unsigned long long)pci_resource_len(pdev, 0));
3668  D_INFO("pci_resource_base = %p\n", il->hw_base);
3669 
3670  /* We disable the RETRY_TIMEOUT register (0x41) to keep
3671  * PCI Tx retries from interfering with C3 CPU state */
3672  pci_write_config_byte(pdev, 0x41, 0x00);
3673 
3674  /* these spin locks will be used in apm_init and EEPROM access
3675  * we should init now
3676  */
3677  spin_lock_init(&il->reg_lock);
3678  spin_lock_init(&il->lock);
3679 
3680  /*
3681  * stop and reset the on-board processor just in case it is in a
3682  * strange state ... like being left stranded by a primary kernel
3683  * and this is now the kdump kernel trying to start up
3684  */
3686 
3687  /***********************
3688  * 4. Read EEPROM
3689  * ********************/
3690 
3691  /* Read the EEPROM */
3692  err = il_eeprom_init(il);
3693  if (err) {
3694  IL_ERR("Unable to init EEPROM\n");
3695  goto out_iounmap;
3696  }
3697  /* MAC Address location in EEPROM same for 3945/4965 */
3698  eeprom = (struct il3945_eeprom *)il->eeprom;
3699  D_INFO("MAC address: %pM\n", eeprom->mac_address);
3700  SET_IEEE80211_PERM_ADDR(il->hw, eeprom->mac_address);
3701 
3702  /***********************
3703  * 5. Setup HW Constants
3704  * ********************/
3705  /* Device-specific setup */
3706  if (il3945_hw_set_hw_params(il)) {
3707  IL_ERR("failed to set hw settings\n");
3708  goto out_eeprom_free;
3709  }
3710 
3711  /***********************
3712  * 6. Setup il
3713  * ********************/
3714 
3715  err = il3945_init_drv(il);
3716  if (err) {
3717  IL_ERR("initializing driver failed\n");
3718  goto out_unset_hw_params;
3719  }
3720 
3721  IL_INFO("Detected Intel Wireless WiFi Link %s\n", il->cfg->name);
3722 
3723  /***********************
3724  * 7. Setup Services
3725  * ********************/
3726 
3727  spin_lock_irqsave(&il->lock, flags);
3728  il_disable_interrupts(il);
3729  spin_unlock_irqrestore(&il->lock, flags);
3730 
3731  pci_enable_msi(il->pci_dev);
3732 
3733  err = request_irq(il->pci_dev->irq, il_isr, IRQF_SHARED, DRV_NAME, il);
3734  if (err) {
3735  IL_ERR("Error allocating IRQ %d\n", il->pci_dev->irq);
3736  goto out_disable_msi;
3737  }
3738 
3739  err = sysfs_create_group(&pdev->dev.kobj, &il3945_attribute_group);
3740  if (err) {
3741  IL_ERR("failed to create sysfs device attributes\n");
3742  goto out_release_irq;
3743  }
3744 
3745  il_set_rxon_channel(il, &il->bands[IEEE80211_BAND_2GHZ].channels[5]);
3746  il3945_setup_deferred_work(il);
3747  il3945_setup_handlers(il);
3748  il_power_initialize(il);
3749 
3750  /*********************************
3751  * 8. Setup and Register mac80211
3752  * *******************************/
3753 
3754  il_enable_interrupts(il);
3755 
3756  err = il3945_setup_mac(il);
3757  if (err)
3758  goto out_remove_sysfs;
3759 
3760  err = il_dbgfs_register(il, DRV_NAME);
3761  if (err)
3762  IL_ERR("failed to create debugfs files. Ignoring error: %d\n",
3763  err);
3764 
3765  /* Start monitoring the killswitch */
3766  queue_delayed_work(il->workqueue, &il->_3945.rfkill_poll, 2 * HZ);
3767 
3768  return 0;
3769 
3770 out_remove_sysfs:
3772  il->workqueue = NULL;
3773  sysfs_remove_group(&pdev->dev.kobj, &il3945_attribute_group);
3774 out_release_irq:
3775  free_irq(il->pci_dev->irq, il);
3776 out_disable_msi:
3777  pci_disable_msi(il->pci_dev);
3778  il_free_geos(il);
3779  il_free_channel_map(il);
3780 out_unset_hw_params:
3781  il3945_unset_hw_params(il);
3782 out_eeprom_free:
3783  il_eeprom_free(il);
3784 out_iounmap:
3785  iounmap(il->hw_base);
3786 out_pci_release_regions:
3787  pci_release_regions(pdev);
3788 out_pci_disable_device:
3789  pci_set_drvdata(pdev, NULL);
3790  pci_disable_device(pdev);
3791 out_ieee80211_free_hw:
3792  ieee80211_free_hw(il->hw);
3793 out:
3794  return err;
3795 }
3796 
3797 static void __devexit
3798 il3945_pci_remove(struct pci_dev *pdev)
3799 {
3800  struct il_priv *il = pci_get_drvdata(pdev);
3801  unsigned long flags;
3802 
3803  if (!il)
3804  return;
3805 
3806  D_INFO("*** UNLOAD DRIVER ***\n");
3807 
3808  il_dbgfs_unregister(il);
3809 
3810  set_bit(S_EXIT_PENDING, &il->status);
3811 
3812  il_leds_exit(il);
3813 
3814  if (il->mac80211_registered) {
3816  il->mac80211_registered = 0;
3817  } else {
3818  il3945_down(il);
3819  }
3820 
3821  /*
3822  * Make sure device is reset to low power before unloading driver.
3823  * This may be redundant with il_down(), but there are paths to
3824  * run il_down() without calling apm_ops.stop(), and there are
3825  * paths to avoid running il_down() at all before leaving driver.
3826  * This (inexpensive) call *makes sure* device is reset.
3827  */
3828  il_apm_stop(il);
3829 
3830  /* make sure we flush any pending irq or
3831  * tasklet for the driver
3832  */
3833  spin_lock_irqsave(&il->lock, flags);
3834  il_disable_interrupts(il);
3835  spin_unlock_irqrestore(&il->lock, flags);
3836 
3837  il3945_synchronize_irq(il);
3838 
3839  sysfs_remove_group(&pdev->dev.kobj, &il3945_attribute_group);
3840 
3841  cancel_delayed_work_sync(&il->_3945.rfkill_poll);
3842 
3843  il3945_dealloc_ucode_pci(il);
3844 
3845  if (il->rxq.bd)
3846  il3945_rx_queue_free(il, &il->rxq);
3848 
3849  il3945_unset_hw_params(il);
3850 
3851  /*netif_stop_queue(dev); */
3853 
3854  /* ieee80211_unregister_hw calls il3945_mac_stop, which flushes
3855  * il->workqueue... so we can't take down the workqueue
3856  * until now... */
3858  il->workqueue = NULL;
3859 
3860  free_irq(pdev->irq, il);
3861  pci_disable_msi(pdev);
3862 
3863  iounmap(il->hw_base);
3864  pci_release_regions(pdev);
3865  pci_disable_device(pdev);
3866  pci_set_drvdata(pdev, NULL);
3867 
3868  il_free_channel_map(il);
3869  il_free_geos(il);
3870  kfree(il->scan_cmd);
3871  if (il->beacon_skb)
3872  dev_kfree_skb(il->beacon_skb);
3873 
3874  ieee80211_free_hw(il->hw);
3875 }
3876 
3877 /*****************************************************************************
3878  *
3879  * driver and module entry point
3880  *
3881  *****************************************************************************/
3882 
3883 static struct pci_driver il3945_driver = {
3884  .name = DRV_NAME,
3885  .id_table = il3945_hw_card_ids,
3886  .probe = il3945_pci_probe,
3887  .remove = __devexit_p(il3945_pci_remove),
3888  .driver.pm = IL_LEGACY_PM_OPS,
3889 };
3890 
3891 static int __init
3892 il3945_init(void)
3893 {
3894 
3895  int ret;
3896  pr_info(DRV_DESCRIPTION ", " DRV_VERSION "\n");
3897  pr_info(DRV_COPYRIGHT "\n");
3898 
3900  if (ret) {
3901  pr_err("Unable to register rate control algorithm: %d\n", ret);
3902  return ret;
3903  }
3904 
3905  ret = pci_register_driver(&il3945_driver);
3906  if (ret) {
3907  pr_err("Unable to initialize PCI module\n");
3908  goto error_register;
3909  }
3910 
3911  return ret;
3912 
3913 error_register:
3915  return ret;
3916 }
3917 
3918 static void __exit
3919 il3945_exit(void)
3920 {
3921  pci_unregister_driver(&il3945_driver);
3923 }
3924 
3926 
3927 module_param_named(antenna, il3945_mod_params.antenna, int, S_IRUGO);
3928 MODULE_PARM_DESC(antenna, "select antenna (1=Main, 2=Aux, default 0 [both])");
3929 module_param_named(swcrypto, il3945_mod_params.sw_crypto, int, S_IRUGO);
3930 MODULE_PARM_DESC(swcrypto, "using software crypto (default 1 [software])");
3931 module_param_named(disable_hw_scan, il3945_mod_params.disable_hw_scan, int,
3932  S_IRUGO);
3933 MODULE_PARM_DESC(disable_hw_scan, "disable hardware scanning (default 1)");
3934 #ifdef CONFIG_IWLEGACY_DEBUG
3936 MODULE_PARM_DESC(debug, "debug output mask");
3937 #endif
3938 module_param_named(fw_restart, il3945_mod_params.restart_fw, int, S_IRUGO);
3939 MODULE_PARM_DESC(fw_restart, "restart firmware in case of error");
3940 
3941 module_exit(il3945_exit);
3942 module_init(il3945_init);