Home | History | Annotate | Line # | Download | only in usb
      1 /*	$NetBSD: if_run.c,v 1.43 2026/08/29 01:15:46 maya Exp $	*/
      2 /*	$OpenBSD: if_run.c,v 1.90 2012/03/24 15:11:04 jsg Exp $	*/
      3 
      4 /*-
      5  * Copyright (c) 2008-2010 Damien Bergamini <damien.bergamini (at) free.fr>
      6  *
      7  * Permission to use, copy, modify, and distribute this software for any
      8  * purpose with or without fee is hereby granted, provided that the above
      9  * copyright notice and this permission notice appear in all copies.
     10  *
     11  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
     12  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
     13  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
     14  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
     15  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
     16  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
     17  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
     18  */
     19 
     20 /*-
     21  * Ralink Technology RT2700U/RT2800U/RT3000U/RT3900E chipset driver.
     22  * http://www.ralinktech.com/
     23  */
     24 
     25 #include <sys/cdefs.h>
     26 __KERNEL_RCSID(0, "$NetBSD: if_run.c,v 1.43 2026/08/29 01:15:46 maya Exp $");
     27 
     28 #ifdef _KERNEL_OPT
     29 #include "opt_usb.h"
     30 #endif
     31 
     32 #include <sys/param.h>
     33 #include <sys/sockio.h>
     34 #include <sys/sysctl.h>
     35 #include <sys/mbuf.h>
     36 #include <sys/kernel.h>
     37 #include <sys/socket.h>
     38 #include <sys/systm.h>
     39 #include <sys/malloc.h>
     40 #include <sys/callout.h>
     41 #include <sys/module.h>
     42 #include <sys/conf.h>
     43 #include <sys/device.h>
     44 #include <sys/atomic.h>
     45 
     46 #include <sys/bus.h>
     47 #include <machine/endian.h>
     48 #include <sys/intr.h>
     49 
     50 #include <net/bpf.h>
     51 #include <net/if.h>
     52 #include <net/if_arp.h>
     53 #include <net/if_dl.h>
     54 #include <net/if_ether.h>
     55 #include <net/if_media.h>
     56 #include <net/if_types.h>
     57 
     58 #include <net80211/ieee80211_var.h>
     59 #include <net80211/ieee80211_amrr.h>
     60 #include <net80211/ieee80211_radiotap.h>
     61 
     62 #include <dev/firmload.h>
     63 
     64 #include <dev/usb/usb.h>
     65 #include <dev/usb/usbdi.h>
     66 #include <dev/usb/usbdivar.h>
     67 #include <dev/usb/usbdi_util.h>
     68 #include <dev/usb/usbdevs.h>
     69 
     70 #include <dev/ic/rt2860reg.h>		/* shared with ral(4) */
     71 #include <dev/usb/if_runvar.h>
     72 
     73 #ifdef RUN_DEBUG
     74 #define DPRINTF(x)	do { if (run_debug) printf x; } while (0)
     75 #define DPRINTFN(n, x)	do { if (run_debug >= (n)) printf x; } while (0)
     76 int run_debug = 0;
     77 #else
     78 #define DPRINTF(x)
     79 #define DPRINTFN(n, x)
     80 #endif
     81 
     82 #define IEEE80211_HAS_ADDR4(wh) IEEE80211_IS_DSTODS(wh)
     83 
     84 #define USB_ID(v, p)	{ USB_VENDOR_##v, USB_PRODUCT_##v##_##p }
     85 static const struct usb_devno run_devs[] = {
     86 	USB_ID(ABOCOM,		RT2770),
     87 	USB_ID(ABOCOM,		RT2870),
     88 	USB_ID(ABOCOM,		RT3070),
     89 	USB_ID(ABOCOM,		RT3071),
     90 	USB_ID(ABOCOM,		RT3072),
     91 	USB_ID(ABOCOM2,		RT2870_1),
     92 	USB_ID(ACCTON,		RT2770),
     93 	USB_ID(ACCTON,		RT2870_1),
     94 	USB_ID(ACCTON,		RT2870_2),
     95 	USB_ID(ACCTON,		RT2870_3),
     96 	USB_ID(ACCTON,		RT2870_4),
     97 	USB_ID(ACCTON,		RT2870_5),
     98 	USB_ID(ACCTON,		RT3070),
     99 	USB_ID(ACCTON,		RT3070_1),
    100 	USB_ID(ACCTON,		RT3070_2),
    101 	USB_ID(ACCTON,		RT3070_3),
    102 	USB_ID(ACCTON,		RT3070_4),
    103 	USB_ID(ACCTON,		RT3070_5),
    104 	USB_ID(ACCTON,		RT3070_6),
    105 	USB_ID(AIRTIES,		RT3070),
    106 	USB_ID(AIRTIES,		RT3070_2),
    107 	USB_ID(ALLWIN,		RT2070),
    108 	USB_ID(ALLWIN,		RT2770),
    109 	USB_ID(ALLWIN,		RT2870),
    110 	USB_ID(ALLWIN,		RT3070),
    111 	USB_ID(ALLWIN,		RT3071),
    112 	USB_ID(ALLWIN,		RT3072),
    113 	USB_ID(ALLWIN,		RT3572),
    114 	USB_ID(AMIGO,		RT2870_1),
    115 	USB_ID(AMIGO,		RT2870_2),
    116 	USB_ID(AMIT,		CGWLUSB2GNR),
    117 	USB_ID(AMIT,		RT2870_1),
    118 	USB_ID(AMIT2,		RT2870),
    119 	USB_ID(ASUSTEK,		RT2870_1),
    120 	USB_ID(ASUSTEK,		RT2870_2),
    121 	USB_ID(ASUSTEK,		RT2870_3),
    122 	USB_ID(ASUSTEK,		RT2870_4),
    123 	USB_ID(ASUSTEK,		RT2870_5),
    124 	USB_ID(ASUSTEK,		RT3070),
    125 	USB_ID(ASUSTEK,		RT3070_1),
    126 	USB_ID(ASUSTEK,		USBN53),
    127 	USB_ID(ASUSTEK,		USBN66),
    128 	USB_ID(ASUSTEK2,	USBN11),
    129 	USB_ID(AZUREWAVE,	RT2870_1),
    130 	USB_ID(AZUREWAVE,	RT2870_2),
    131 	USB_ID(AZUREWAVE,	RT3070),
    132 	USB_ID(AZUREWAVE,	RT3070_2),
    133 	USB_ID(AZUREWAVE,	RT3070_3),
    134 	USB_ID(AZUREWAVE,	RT3070_4),
    135 	USB_ID(AZUREWAVE,	RT3070_5),
    136 	USB_ID(BELKIN,		F5D8053V3),
    137 	USB_ID(BELKIN,		F5D8055),
    138 	USB_ID(BELKIN,		F5D8055V2),
    139 	USB_ID(BELKIN,		F6D4050V1),
    140 	USB_ID(BELKIN,		F6D4050V2),
    141 	USB_ID(BELKIN,		F7D1101V2),
    142 	USB_ID(BELKIN,		RT2870_1),
    143 	USB_ID(BELKIN,		RT2870_2),
    144 	USB_ID(BELKIN,		RTL8192CU_2),
    145 	USB_ID(BEWAN,		RT3070),
    146 	USB_ID(CISCOLINKSYS,	AE1000),
    147 	USB_ID(CISCOLINKSYS,	AM10),
    148 	USB_ID(CISCOLINKSYS2,	RT3070),
    149 	USB_ID(CISCOLINKSYS3,	RT3070),
    150 	USB_ID(CONCEPTRONIC,	RT2870_1),
    151 	USB_ID(CONCEPTRONIC,	RT2870_2),
    152 	USB_ID(CONCEPTRONIC,	RT2870_3),
    153 	USB_ID(CONCEPTRONIC,	RT2870_4),
    154 	USB_ID(CONCEPTRONIC,	RT2870_5),
    155 	USB_ID(CONCEPTRONIC,	RT2870_6),
    156 	USB_ID(CONCEPTRONIC,	RT2870_7),
    157 	USB_ID(CONCEPTRONIC,	RT2870_8),
    158 	USB_ID(CONCEPTRONIC,	RT3070_1),
    159 	USB_ID(CONCEPTRONIC,	RT3070_2),
    160 	USB_ID(CONCEPTRONIC,	RT3070_3),
    161 	USB_ID(COREGA,		CGWLUSB300GNM),
    162 	USB_ID(COREGA,		RT2870_1),
    163 	USB_ID(COREGA,		RT2870_2),
    164 	USB_ID(COREGA,		RT2870_3),
    165 	USB_ID(COREGA,		RT3070),
    166 	USB_ID(CYBERTAN,	RT2870),
    167 	USB_ID(DLINK,		RT2870),
    168 	USB_ID(DLINK,		RT3072),
    169 	USB_ID(DLINK,		DWA127),
    170 	USB_ID(DLINK,		DWA140B3),
    171 	USB_ID(DLINK,		DWA160B2),
    172 	USB_ID(DLINK,		DWA162),
    173 	USB_ID(DLINK2,		DWA130),
    174 	USB_ID(DLINK2,		RT2870_1),
    175 	USB_ID(DLINK2,		RT2870_2),
    176 	USB_ID(DLINK2,		RT3070_1),
    177 	USB_ID(DLINK2,		RT3070_2),
    178 	USB_ID(DLINK2,		RT3070_3),
    179 	USB_ID(DLINK2,		RT3070_4),
    180 	USB_ID(DLINK2,		RT3070_5),
    181 	USB_ID(DLINK2,		RT3072),
    182 	USB_ID(DLINK2,		RT3072_1),
    183 	USB_ID(DVICO,		RT3070),
    184 	USB_ID(EDIMAX,		EW7717),
    185 	USB_ID(EDIMAX,		EW7718),
    186 	USB_ID(EDIMAX,		EW7722UTN),
    187 	USB_ID(EDIMAX,		RT2870_1),
    188 	USB_ID(ENCORE,		RT3070),
    189 	USB_ID(ENCORE,		RT3070_2),
    190 	USB_ID(ENCORE,		RT3070_3),
    191 	USB_ID(GIGABYTE,	GNWB31N),
    192 	USB_ID(GIGABYTE,	GNWB32L),
    193 	USB_ID(GIGABYTE,	RT2870_1),
    194 	USB_ID(GIGASET,		RT3070_1),
    195 	USB_ID(GIGASET,		RT3070_2),
    196 	USB_ID(GUILLEMOT,	HWNU300),
    197 	USB_ID(HAWKING,		HWUN2),
    198 	USB_ID(HAWKING,		RT2870_1),
    199 	USB_ID(HAWKING,		RT2870_2),
    200 	USB_ID(HAWKING,		RT2870_3),
    201 	USB_ID(HAWKING,		RT2870_4),
    202 	USB_ID(HAWKING,		RT2870_5),
    203 	USB_ID(HAWKING,		RT3070),
    204 	USB_ID(IODATA,		RT3072_1),
    205 	USB_ID(IODATA,		RT3072_2),
    206 	USB_ID(IODATA,		RT3072_3),
    207 	USB_ID(IODATA,		RT3072_4),
    208 	USB_ID(LINKSYS4,	RT3070),
    209 	USB_ID(LINKSYS4,	WUSB100),
    210 	USB_ID(LINKSYS4,	WUSB54GC_3),
    211 	USB_ID(LINKSYS4,	WUSB600N),
    212 	USB_ID(LINKSYS4,	WUSB600NV2),
    213 	USB_ID(LOGITEC,		LANW300NU2),
    214 	USB_ID(LOGITEC,		LANW300NU2S),
    215 	USB_ID(LOGITEC,		LAN_W300ANU2),
    216 	USB_ID(LOGITEC,		LAN_W450ANU2E),
    217 	USB_ID(LOGITEC,		RT2870_1),
    218 	USB_ID(LOGITEC,		RT2870_2),
    219 	USB_ID(LOGITEC,		RT2870_3),
    220 	USB_ID(LOGITEC,		RT3020),
    221 	USB_ID(MELCO,		RT2870_1),
    222 	USB_ID(MELCO,		RT2870_2),
    223 	USB_ID(MELCO,		WLIUCAG300N),
    224 	USB_ID(MELCO,		WLIUCG300N),
    225 	USB_ID(MELCO,		WLIUCG301N),
    226 	USB_ID(MELCO,		WLIUCGN),
    227 	USB_ID(MELCO,		WLIUCGNHP),
    228 	USB_ID(MELCO,		WLIUCGNM),
    229 	USB_ID(MELCO,		WLIUCGNM2T),
    230 	USB_ID(MOTOROLA4,	RT2770),
    231 	USB_ID(MOTOROLA4,	RT3070),
    232 	USB_ID(MSI,		RT3070),
    233 	USB_ID(MSI,		RT3070_2),
    234 	USB_ID(MSI,		RT3070_3),
    235 	USB_ID(MSI,		RT3070_4),
    236 	USB_ID(MSI,		RT3070_5),
    237 	USB_ID(MSI,		RT3070_6),
    238 	USB_ID(MSI,		RT3070_7),
    239 	USB_ID(MSI,		RT3070_8),
    240 	USB_ID(MSI,		RT3070_9),
    241 	USB_ID(MSI,		RT3070_10),
    242 	USB_ID(MSI,		RT3070_11),
    243 	USB_ID(MSI,		RT3070_12),
    244 	USB_ID(MSI,		RT3070_13),
    245 	USB_ID(MSI,		RT3070_14),
    246 	USB_ID(MSI,		RT3070_15),
    247 	USB_ID(OVISLINK,	RT3071),
    248 	USB_ID(OVISLINK,	RT3072),
    249 	USB_ID(PARA,		RT3070),
    250 	USB_ID(PEGATRON,	RT2870),
    251 	USB_ID(PEGATRON,	RT3070),
    252 	USB_ID(PEGATRON,	RT3070_2),
    253 	USB_ID(PEGATRON,	RT3070_3),
    254 	USB_ID(PEGATRON,	RT3072),
    255 	USB_ID(PHILIPS,		RT2870),
    256 	USB_ID(PLANEX2,		GWUS300MINIS),
    257 	USB_ID(PLANEX2,		GWUSMICRO300),
    258 	USB_ID(PLANEX2,		GWUSMICRON),
    259 	USB_ID(PLANEX2,		GWUS300MINIX),
    260 	USB_ID(PLANEX2,		RT3070),
    261 	USB_ID(QCOM,		RT2870),
    262 	USB_ID(QUANTA,		RT3070),
    263 	USB_ID(RALINK,		RT2070),
    264 	USB_ID(RALINK,		RT2770),
    265 	USB_ID(RALINK,		RT2870),
    266 	USB_ID(RALINK,		RT3070),
    267 	USB_ID(RALINK,		RT3071),
    268 	USB_ID(RALINK,		RT3072),
    269 	USB_ID(RALINK,		RT3370),
    270 	USB_ID(RALINK,		RT3572),
    271 	USB_ID(RALINK,		RT3573),
    272 	USB_ID(RALINK,		RT5370),
    273 	USB_ID(RALINK,		RT5572),
    274 	USB_ID(RALINK,		RT8070),
    275 	USB_ID(SAMSUNG,		RT2870_1),
    276 	USB_ID(SENAO,		RT2870_1),
    277 	USB_ID(SENAO,		RT2870_2),
    278 	USB_ID(SENAO,		RT2870_3),
    279 	USB_ID(SENAO,		RT2870_4),
    280 	USB_ID(SENAO,		RT3070),
    281 	USB_ID(SENAO,		RT3071),
    282 	USB_ID(SENAO,		RT3072),
    283 	USB_ID(SENAO,		RT3072_2),
    284 	USB_ID(SENAO,		RT3072_3),
    285 	USB_ID(SENAO,		RT3072_4),
    286 	USB_ID(SENAO,		RT3072_5),
    287 	USB_ID(SITECOMEU,	RT2870_1),
    288 	USB_ID(SITECOMEU,	RT2870_2),
    289 	USB_ID(SITECOMEU,	RT2870_3),
    290 	USB_ID(SITECOMEU,	RT3070_1),
    291 	USB_ID(SITECOMEU,	RT3070_3),
    292 	USB_ID(SITECOMEU,	RT3072_3),
    293 	USB_ID(SITECOMEU,	RT3072_4),
    294 	USB_ID(SITECOMEU,	RT3072_5),
    295 	USB_ID(SITECOMEU,	RT3072_6),
    296 	USB_ID(SITECOMEU,	WL302),
    297 	USB_ID(SITECOMEU,	WL315),
    298 	USB_ID(SITECOMEU,	WL321),
    299 	USB_ID(SITECOMEU,	WL324),
    300 	USB_ID(SITECOMEU,	WL329),
    301 	USB_ID(SITECOMEU,	WL343),
    302 	USB_ID(SITECOMEU,	WL344),
    303 	USB_ID(SITECOMEU,	WL345),
    304 	USB_ID(SITECOMEU,	WL349V4),
    305 	USB_ID(SITECOMEU,	WL608),
    306 	USB_ID(SITECOMEU,	WLA4000),
    307 	USB_ID(SITECOMEU,	WLA5000),
    308 	USB_ID(SPARKLAN,	RT2870_1),
    309 	USB_ID(SPARKLAN,	RT2870_2),
    310 	USB_ID(SPARKLAN,	RT3070),
    311 	USB_ID(SWEEX2,		LW153),
    312 	USB_ID(SWEEX2,		LW303),
    313 	USB_ID(SWEEX2,		LW313),
    314 	USB_ID(TOSHIBA,		RT3070),
    315 	USB_ID(UMEDIA,		RT2870_1),
    316 	USB_ID(UMEDIA,		TEW645UB),
    317 	USB_ID(ZCOM,		RT2870_1),
    318 	USB_ID(ZCOM,		RT2870_2),
    319 	USB_ID(ZINWELL,		RT2870_1),
    320 	USB_ID(ZINWELL,		RT2870_2),
    321 	USB_ID(ZINWELL,		RT3070),
    322 	USB_ID(ZINWELL,		RT3072),
    323 	USB_ID(ZINWELL,		RT3072_2),
    324 	USB_ID(ZYXEL,		NWD2105),
    325 	USB_ID(ZYXEL,		NWD211AN),
    326 	USB_ID(ZYXEL,		RT2870_1),
    327 	USB_ID(ZYXEL,		RT2870_2),
    328 	USB_ID(ZYXEL,		RT3070),
    329 };
    330 
    331 static int		run_match(device_t, cfdata_t, void *);
    332 static void		run_attach(device_t, device_t, void *);
    333 static int		run_detach(device_t, int);
    334 static int		run_activate(device_t, enum devact);
    335 
    336 CFATTACH_DECL_NEW(run, sizeof(struct run_softc),
    337 	run_match, run_attach, run_detach, run_activate);
    338 
    339 static int		run_alloc_rx_ring(struct run_softc *);
    340 static void		run_free_rx_ring(struct run_softc *);
    341 static int		run_alloc_tx_ring(struct run_softc *, int);
    342 static void		run_free_tx_ring(struct run_softc *, int);
    343 static int		run_load_microcode(struct run_softc *);
    344 static int		run_reset(struct run_softc *);
    345 static int		run_read(struct run_softc *, uint16_t, uint32_t *);
    346 static int		run_read_region_1(struct run_softc *, uint16_t,
    347 			    uint8_t *, int);
    348 static int		run_write_2(struct run_softc *, uint16_t, uint16_t);
    349 static int		run_write(struct run_softc *, uint16_t, uint32_t);
    350 static int		run_write_region_1(struct run_softc *, uint16_t,
    351 			    const uint8_t *, int);
    352 static int		run_set_region_4(struct run_softc *, uint16_t,
    353 			    uint32_t, int);
    354 static int		run_efuse_read(struct run_softc *, uint16_t,
    355 			    uint16_t *, int);
    356 static int		run_efuse_read_2(struct run_softc *, uint16_t,
    357 			    uint16_t *);
    358 static int		run_eeprom_read_2(struct run_softc *, uint16_t,
    359 			    uint16_t *);
    360 static int		run_rt2870_rf_write(struct run_softc *, uint8_t,
    361 			    uint32_t);
    362 static int		run_rt3070_rf_read(struct run_softc *, uint8_t,
    363 			    uint8_t *);
    364 static int		run_rt3070_rf_write(struct run_softc *, uint8_t,
    365 			    uint8_t);
    366 static int		run_bbp_read(struct run_softc *, uint8_t, uint8_t *);
    367 static int		run_bbp_write(struct run_softc *, uint8_t, uint8_t);
    368 static int		run_mcu_cmd(struct run_softc *, uint8_t, uint16_t);
    369 static const char *	run_get_rf(uint16_t);
    370 static void		run_rt3593_get_txpower(struct run_softc *);
    371 static void		run_get_txpower(struct run_softc *);
    372 static int		run_read_eeprom(struct run_softc *);
    373 static struct ieee80211_node *
    374 			run_node_alloc(struct ieee80211_node_table *);
    375 static int		run_media_change(struct ifnet *);
    376 static void		run_next_scan(void *);
    377 static void		run_task(void *);
    378 static void		run_do_async(struct run_softc *,
    379 			    void (*)(struct run_softc *, void *), void *, int);
    380 static int		run_newstate(struct ieee80211com *,
    381 			    enum ieee80211_state, int);
    382 static void		run_newstate_cb(struct run_softc *, void *);
    383 static int		run_updateedca(struct ieee80211com *);
    384 static void		run_updateedca_cb(struct run_softc *, void *);
    385 #ifdef RUN_HWCRYPTO
    386 static int		run_set_key(struct ieee80211com *,
    387 			    const struct ieee80211_key *, const uint8_t *);
    388 static void		run_set_key_cb(struct run_softc *, void *);
    389 static int		run_delete_key(struct ieee80211com *,
    390 			    const struct ieee80211_key *);
    391 static void		run_delete_key_cb(struct run_softc *, void *);
    392 #endif
    393 static void		run_calibrate_to(void *);
    394 static void		run_calibrate_cb(struct run_softc *, void *);
    395 static void		run_newassoc(struct ieee80211_node *, int);
    396 static void		run_rx_frame(struct run_softc *, uint8_t *, int);
    397 static void		run_rxeof(struct usbd_xfer *, void *,
    398 			    usbd_status);
    399 static void		run_txeof(struct usbd_xfer *, void *,
    400 			    usbd_status);
    401 static int		run_tx(struct run_softc *, struct mbuf *,
    402 			    struct ieee80211_node *);
    403 static void		run_start(struct ifnet *);
    404 static void		run_watchdog(struct ifnet *);
    405 static int		run_ioctl(struct ifnet *, u_long, void *);
    406 static void		run_select_chan_group(struct run_softc *, int);
    407 static void		run_iq_calib(struct run_softc *, u_int);
    408 static void		run_set_agc(struct run_softc *, uint8_t);
    409 static void		run_set_rx_antenna(struct run_softc *, int);
    410 static void		run_rt2870_set_chan(struct run_softc *, u_int);
    411 static void		run_rt3070_set_chan(struct run_softc *, u_int);
    412 static void		run_rt3572_set_chan(struct run_softc *, u_int);
    413 static void		run_rt3593_set_chan(struct run_softc *, u_int);
    414 static void		run_rt5390_set_chan(struct run_softc *, u_int);
    415 static void		run_rt5592_set_chan(struct run_softc *, u_int);
    416 static int		run_set_chan(struct run_softc *,
    417 			    struct ieee80211_channel *);
    418 static void		run_updateprot(struct run_softc *);
    419 static void		run_enable_tsf_sync(struct run_softc *);
    420 static void		run_enable_mrr(struct run_softc *);
    421 static void		run_set_txpreamble(struct run_softc *);
    422 static void		run_set_basicrates(struct run_softc *);
    423 static void		run_set_leds(struct run_softc *, uint16_t);
    424 static void		run_set_bssid(struct run_softc *, const uint8_t *);
    425 static void		run_set_macaddr(struct run_softc *, const uint8_t *);
    426 static void		run_updateslot(struct ifnet *);
    427 static void		run_updateslot_cb(struct run_softc *, void *);
    428 static int8_t		run_rssi2dbm(struct run_softc *, uint8_t, uint8_t);
    429 static void		run_rt5390_bbp_init(struct run_softc *);
    430 static int		run_bbp_init(struct run_softc *);
    431 static int		run_rt3070_rf_init(struct run_softc *);
    432 static int		run_rt3593_rf_init(struct run_softc *);
    433 static int		run_rt5390_rf_init(struct run_softc *);
    434 static int		run_rt3070_filter_calib(struct run_softc *, uint8_t,
    435 			    uint8_t, uint8_t *);
    436 static void		run_rt3070_rf_setup(struct run_softc *);
    437 static void		run_rt3593_rf_setup(struct run_softc *);
    438 static void		run_rt5390_rf_setup(struct run_softc *);
    439 static int		run_txrx_enable(struct run_softc *);
    440 static int     		run_adjust_freq_offset(struct run_softc *);
    441 static int		run_init(struct ifnet *);
    442 static void		run_stop(struct ifnet *, int);
    443 #ifndef IEEE80211_STA_ONLY
    444 static int		run_setup_beacon(struct run_softc *);
    445 #endif
    446 
    447 static const struct {
    448 	uint32_t reg;
    449 	uint32_t val;
    450 } rt2870_def_mac[] = {
    451 	RT2870_DEF_MAC
    452 };
    453 
    454 static const struct {
    455 	uint8_t reg;
    456 	uint8_t val;
    457 } rt2860_def_bbp[] = {
    458 	RT2860_DEF_BBP
    459 }, rt5390_def_bbp[] = {
    460 	RT5390_DEF_BBP
    461 }, rt5592_def_bbp[] = {
    462 	RT5592_DEF_BBP
    463 };
    464 
    465 /*
    466  * Default values for BBP register R196 for RT5592.
    467  */
    468 static const uint8_t rt5592_bbp_r196[] = {
    469 	0xe0, 0x1f, 0x38, 0x32, 0x08, 0x28, 0x19, 0x0a, 0xff, 0x00,
    470 	0x16, 0x10, 0x10, 0x0b, 0x36, 0x2c, 0x26, 0x24, 0x42, 0x36,
    471 	0x30, 0x2d, 0x4c, 0x46, 0x3d, 0x40, 0x3e, 0x42, 0x3d, 0x40,
    472 	0x3c, 0x34, 0x2c, 0x2f, 0x3c, 0x35, 0x2e, 0x2a, 0x49, 0x41,
    473 	0x36, 0x31, 0x30, 0x30, 0x0e, 0x0d, 0x28, 0x21, 0x1c, 0x16,
    474 	0x50, 0x4a, 0x43, 0x40, 0x10, 0x10, 0x10, 0x10, 0x00, 0x00,
    475 	0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
    476 	0x00, 0x00, 0x7d, 0x14, 0x32, 0x2c, 0x36, 0x4c, 0x43, 0x2c,
    477 	0x2e, 0x36, 0x30, 0x6e
    478 };
    479 
    480 static const struct rfprog {
    481 	uint8_t chan;
    482 	uint32_t r1, r2, r3, r4;
    483 } rt2860_rf2850[] = {
    484 	RT2860_RF2850
    485 };
    486 
    487 static const struct {
    488 	uint8_t n, r, k;
    489 } rt3070_freqs[] = {
    490 	RT3070_RF3052
    491 };
    492 
    493 static const struct rt5592_freqs {
    494 	uint16_t n;
    495 	uint8_t k, m, r;
    496 } rt5592_freqs_20mhz[] = {
    497 	RT5592_RF5592_20MHZ
    498 },rt5592_freqs_40mhz[] = {
    499 	RT5592_RF5592_40MHZ
    500 };
    501 
    502 static const struct {
    503 	uint8_t reg;
    504 	uint8_t val;
    505 } rt3070_def_rf[] = {
    506 	RT3070_DEF_RF
    507 }, rt3572_def_rf[] = {
    508 	RT3572_DEF_RF
    509 },rt3593_def_rf[] = {
    510 	RT3593_DEF_RF
    511 },rt5390_def_rf[] = {
    512 	RT5390_DEF_RF
    513 },rt5392_def_rf[] = {
    514 	RT5392_DEF_RF
    515 },rt5592_def_rf[] = {
    516 	RT5592_DEF_RF
    517 },rt5592_2ghz_def_rf[] = {
    518 	RT5592_2GHZ_DEF_RF
    519 },rt5592_5ghz_def_rf[] = {
    520 	RT5592_5GHZ_DEF_RF
    521 };
    522 
    523 static const struct {
    524 	u_int firstchan;
    525 	u_int lastchan;
    526 	uint8_t reg;
    527 	uint8_t val;
    528 } rt5592_chan_5ghz[] = {
    529 	RT5592_CHAN_5GHZ
    530 };
    531 
    532 static int
    533 firmware_load(const char *dname, const char *iname, uint8_t **ucodep,
    534     size_t *sizep)
    535 {
    536 	firmware_handle_t fh;
    537 	int error;
    538 
    539 	if ((error = firmware_open(dname, iname, &fh)) != 0)
    540 		return error;
    541 	*sizep = firmware_get_size(fh);
    542 	if ((*ucodep = firmware_malloc(*sizep)) == NULL) {
    543 		firmware_close(fh);
    544 		return ENOMEM;
    545 	}
    546 	if ((error = firmware_read(fh, 0, *ucodep, *sizep)) != 0)
    547 		firmware_free(*ucodep, *sizep);
    548 	firmware_close(fh);
    549 
    550 	return error;
    551 }
    552 
    553 static int
    554 run_match(device_t parent, cfdata_t match, void *aux)
    555 {
    556 	struct usb_attach_arg *uaa = aux;
    557 
    558 	return (usb_lookup(run_devs, uaa->uaa_vendor, uaa->uaa_product) != NULL) ?
    559 	    UMATCH_VENDOR_PRODUCT : UMATCH_NONE;
    560 }
    561 
    562 static void
    563 run_attach(device_t parent, device_t self, void *aux)
    564 {
    565 	struct run_softc *sc = device_private(self);
    566 	struct usb_attach_arg *uaa = aux;
    567 	struct ieee80211com *ic = &sc->sc_ic;
    568 	struct ifnet *ifp = &sc->sc_if;
    569 	usb_interface_descriptor_t *id;
    570 	usb_endpoint_descriptor_t *ed;
    571 	char *devinfop;
    572 	int i, nrx, ntx, ntries, error;
    573 	uint32_t ver;
    574 
    575 	aprint_naive("\n");
    576 	aprint_normal("\n");
    577 
    578 	sc->sc_dev = self;
    579 	sc->sc_udev = uaa->uaa_device;
    580 
    581 	devinfop = usbd_devinfo_alloc(sc->sc_udev, 0);
    582 	aprint_normal_dev(sc->sc_dev, "%s\n", devinfop);
    583 	usbd_devinfo_free(devinfop);
    584 
    585 	error = usbd_set_config_no(sc->sc_udev, 1, 0);
    586 	if (error != 0) {
    587 		aprint_error_dev(sc->sc_dev, "failed to set configuration"
    588 		    ", err=%s\n", usbd_errstr(error));
    589 		return;
    590 	}
    591 
    592 	/* get the first interface handle */
    593 	error = usbd_device2interface_handle(sc->sc_udev, 0, &sc->sc_iface);
    594 	if (error != 0) {
    595 		aprint_error_dev(sc->sc_dev,
    596 		    "could not get interface handle\n");
    597 		return;
    598 	}
    599 
    600 	/*
    601 	 * Find all bulk endpoints.  There are 7 bulk endpoints: 1 for RX
    602 	 * and 6 for TX (4 EDCAs + HCCA + Prio).
    603 	 * Update 03-14-2009:  some devices like the Planex GW-US300MiniS
    604 	 * seem to have only 4 TX bulk endpoints (Fukaumi Naoki).
    605 	 */
    606 	nrx = ntx = 0;
    607 	id = usbd_get_interface_descriptor(sc->sc_iface);
    608 	for (i = 0; i < id->bNumEndpoints; i++) {
    609 		ed = usbd_interface2endpoint_descriptor(sc->sc_iface, i);
    610 		if (ed == NULL || UE_GET_XFERTYPE(ed->bmAttributes) != UE_BULK)
    611 			continue;
    612 
    613 		if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN) {
    614 			sc->rxq.pipe_no = ed->bEndpointAddress;
    615 			nrx++;
    616 		} else if (ntx < RUN_MAXEPOUT) {
    617 			sc->txq[ntx].pipe_no = ed->bEndpointAddress;
    618 			ntx++;
    619 		}
    620 	}
    621 	/* make sure we've got them all */
    622 	if (nrx < 1 || ntx < RUN_MAXEPOUT) {
    623 		aprint_error_dev(sc->sc_dev, "missing endpoint\n");
    624 		return;
    625 	}
    626 
    627 	usb_init_task(&sc->sc_task, run_task, sc, 0);
    628 	callout_init(&sc->scan_to, 0);
    629 	callout_setfunc(&sc->scan_to, run_next_scan, sc);
    630 	callout_init(&sc->calib_to, 0);
    631 	callout_setfunc(&sc->calib_to, run_calibrate_to, sc);
    632 
    633 	sc->amrr.amrr_min_success_threshold =  1;
    634 	sc->amrr.amrr_max_success_threshold = 10;
    635 
    636 	/* wait for the chip to settle */
    637 	for (ntries = 0; ntries < 100; ntries++) {
    638 		if (run_read(sc, RT2860_ASIC_VER_ID, &ver) != 0)
    639 			return;
    640 		if (ver != 0 && ver != 0xffffffff)
    641 			break;
    642 		DELAY(10);
    643 	}
    644 	if (ntries == 100) {
    645 		aprint_error_dev(sc->sc_dev,
    646 		    "timeout waiting for NIC to initialize\n");
    647 		return;
    648 	}
    649 	sc->mac_ver = ver >> 16;
    650 	sc->mac_rev = ver & 0xffff;
    651 
    652        /*
    653 	* Per the comment in run_write_region_1(), "the WRITE_REGION_1
    654 	* command is not stable on RT2860", but WRITE_REGION_1 calls
    655 	* of up to 64 bytes have been tested and found to work with
    656 	* mac_ver 0x5390, and they reduce the run time of "ifconfig
    657 	* run0 up" from 30 seconds to a couple of seconds on OHCI.
    658 	* Enable WRITE_REGION_1 for the tested version only.  As other
    659 	* versions are tested and found to work, they can be added
    660 	* here.
    661 	*/
    662 	if (sc->mac_ver == 0x5390)
    663 		sc->sc_flags |= RUN_USE_BLOCK_WRITE;
    664 
    665 	/* retrieve RF rev. no and various other things from EEPROM */
    666 	run_read_eeprom(sc);
    667 
    668 	aprint_verbose_dev(sc->sc_dev,
    669 	    "MAC/BBP RT%04X (rev 0x%04X), RF %s (MIMO %dT%dR), address %s\n",
    670 	    sc->mac_ver, sc->mac_rev, run_get_rf(sc->rf_rev), sc->ntxchains,
    671 	    sc->nrxchains, ether_sprintf(ic->ic_myaddr));
    672 
    673 	ic->ic_ifp = ifp;
    674 	ic->ic_phytype = IEEE80211_T_OFDM;	/* not only, but not used */
    675 	ic->ic_opmode = IEEE80211_M_STA;	/* default to BSS mode */
    676 	ic->ic_state = IEEE80211_S_INIT;
    677 
    678 	/* set device capabilities */
    679 	ic->ic_caps =
    680 	    IEEE80211_C_MONITOR |	/* monitor mode supported */
    681 #ifndef IEEE80211_STA_ONLY
    682 	    IEEE80211_C_IBSS |		/* IBSS mode supported */
    683 	    IEEE80211_C_HOSTAP |	/* HostAP mode supported */
    684 #endif
    685 	    IEEE80211_C_SHPREAMBLE |	/* short preamble supported */
    686 	    IEEE80211_C_SHSLOT |	/* short slot time supported */
    687 #ifdef RUN_HWCRYPTO
    688 	    IEEE80211_C_WEP |		/* WEP */
    689 	    IEEE80211_C_TKIP |		/* TKIP */
    690 	    IEEE80211_C_AES_CCM |	/* AES CCMP */
    691 	    IEEE80211_C_TKIPMIC |	/* TKIPMIC */
    692 #endif
    693 	    IEEE80211_C_WME |		/* WME */
    694 	    IEEE80211_C_WPA;		/* WPA/RSN */
    695 
    696 	if (sc->rf_rev == RT2860_RF_2750 ||
    697 	    sc->rf_rev == RT2860_RF_2850 ||
    698 	    sc->rf_rev == RT3070_RF_3052 ||
    699 	    sc->rf_rev == RT3070_RF_3053 ||
    700 	    sc->rf_rev == RT5592_RF_5592) {
    701 		/* set supported .11a rates */
    702 		ic->ic_sup_rates[IEEE80211_MODE_11A] =
    703 		    ieee80211_std_rateset_11a;
    704 
    705 		/* set supported .11a channels */
    706 		for (i = 14; i < (int)__arraycount(rt2860_rf2850); i++) {
    707 			uint8_t chan = rt2860_rf2850[i].chan;
    708 			ic->ic_channels[chan].ic_freq =
    709 			    ieee80211_ieee2mhz(chan, IEEE80211_CHAN_5GHZ);
    710 			ic->ic_channels[chan].ic_flags = IEEE80211_CHAN_A;
    711 		}
    712 	}
    713 
    714 	/* set supported .11b and .11g rates */
    715 	ic->ic_sup_rates[IEEE80211_MODE_11B] = ieee80211_std_rateset_11b;
    716 	ic->ic_sup_rates[IEEE80211_MODE_11G] = ieee80211_std_rateset_11g;
    717 
    718 	/* set supported .11b and .11g channels (1 through 14) */
    719 	for (i = 1; i <= 14; i++) {
    720 		ic->ic_channels[i].ic_freq =
    721 		    ieee80211_ieee2mhz(i, IEEE80211_CHAN_2GHZ);
    722 		ic->ic_channels[i].ic_flags =
    723 		    IEEE80211_CHAN_CCK | IEEE80211_CHAN_OFDM |
    724 		    IEEE80211_CHAN_DYN | IEEE80211_CHAN_2GHZ;
    725 	}
    726 
    727 	ifp->if_softc = sc;
    728 	ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
    729 	ifp->if_init = run_init;
    730 	ifp->if_ioctl = run_ioctl;
    731 	ifp->if_start = run_start;
    732 	ifp->if_watchdog = run_watchdog;
    733 	IFQ_SET_READY(&ifp->if_snd);
    734 	memcpy(ifp->if_xname, device_xname(sc->sc_dev), IFNAMSIZ);
    735 
    736 	if_initialize(ifp);
    737 	ieee80211_ifattach(ic);
    738 	ic->ic_node_alloc = run_node_alloc;
    739 	ic->ic_newassoc = run_newassoc;
    740 	ic->ic_updateslot = run_updateslot;
    741 	ic->ic_wme.wme_update = run_updateedca;
    742 #ifdef RUN_HWCRYPTO
    743 	ic->ic_crypto.cs_key_set = run_set_key;
    744 	ic->ic_crypto.cs_key_delete = run_delete_key;
    745 #endif
    746 	/* override state transition machine */
    747 	sc->sc_newstate = ic->ic_newstate;
    748 	ic->ic_newstate = run_newstate;
    749 
    750 	/* XXX media locking needs revisiting */
    751 	mutex_init(&sc->sc_media_mtx, MUTEX_DEFAULT, IPL_SOFTUSB);
    752 	ieee80211_media_init_with_lock(ic,
    753 	    run_media_change, ieee80211_media_status, &sc->sc_media_mtx);
    754 
    755 	bpf_attach2(ifp, DLT_IEEE802_11_RADIO,
    756 	    sizeof(struct ieee80211_frame) + IEEE80211_RADIOTAP_HDRLEN,
    757 	    &sc->sc_drvbpf);
    758 
    759 	sc->sc_rxtap_len = sizeof(sc->sc_rxtapu);
    760 	sc->sc_rxtap.wr_ihdr.it_len = htole16(sc->sc_rxtap_len);
    761 	sc->sc_rxtap.wr_ihdr.it_present = htole32(RUN_RX_RADIOTAP_PRESENT);
    762 
    763 	sc->sc_txtap_len = sizeof(sc->sc_txtapu);
    764 	sc->sc_txtap.wt_ihdr.it_len = htole16(sc->sc_txtap_len);
    765 	sc->sc_txtap.wt_ihdr.it_present = htole32(RUN_TX_RADIOTAP_PRESENT);
    766 
    767 	ifp->if_percpuq = if_percpuq_create(ifp);
    768 	if_register(ifp);
    769 
    770 	ieee80211_announce(ic);
    771 
    772 	usbd_add_drv_event(USB_EVENT_DRIVER_ATTACH, sc->sc_udev, sc->sc_dev);
    773 
    774 	if (!pmf_device_register(self, NULL, NULL))
    775 		aprint_error_dev(self, "couldn't establish power handler\n");
    776 }
    777 
    778 static int
    779 run_detach(device_t self, int flags)
    780 {
    781 	struct run_softc *sc = device_private(self);
    782 	struct ifnet *ifp = &sc->sc_if;
    783 	struct ieee80211com *ic = &sc->sc_ic;
    784 	int s;
    785 
    786 	if (ifp->if_softc == NULL)
    787 		return 0;
    788 
    789 	pmf_device_deregister(self);
    790 
    791 	s = splusb();
    792 
    793 	sc->sc_flags |= RUN_DETACHING;
    794 
    795 	if (ifp->if_flags & IFF_RUNNING) {
    796 		run_stop(ifp, 0);
    797 		callout_halt(&sc->scan_to, NULL);
    798 		callout_halt(&sc->calib_to, NULL);
    799 		usb_rem_task_wait(sc->sc_udev, &sc->sc_task, USB_TASKQ_DRIVER,
    800 		    NULL);
    801 	}
    802 
    803 	ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
    804 	bpf_detach(ifp);
    805 	ieee80211_ifdetach(ic);
    806 	if_detach(ifp);
    807 
    808 	splx(s);
    809 
    810 	usbd_add_drv_event(USB_EVENT_DRIVER_DETACH, sc->sc_udev, sc->sc_dev);
    811 
    812 	callout_stop(&sc->scan_to);
    813 	callout_stop(&sc->calib_to);
    814 
    815 	callout_destroy(&sc->scan_to);
    816 	callout_destroy(&sc->calib_to);
    817 
    818 	return 0;
    819 }
    820 
    821 static int
    822 run_activate(device_t self, enum devact act)
    823 {
    824 	struct run_softc *sc = device_private(self);
    825 
    826 	switch (act) {
    827 	case DVACT_DEACTIVATE:
    828 		if_deactivate(sc->sc_ic.ic_ifp);
    829 		return 0;
    830 	default:
    831 		return EOPNOTSUPP;
    832 	}
    833 }
    834 
    835 static int
    836 run_alloc_rx_ring(struct run_softc *sc)
    837 {
    838 	struct run_rx_ring *rxq = &sc->rxq;
    839 	int i, error;
    840 
    841 	error = usbd_open_pipe(sc->sc_iface, rxq->pipe_no, 0, &rxq->pipeh);
    842 	if (error != 0)
    843 		goto fail;
    844 
    845 	for (i = 0; i < RUN_RX_RING_COUNT; i++) {
    846 		struct run_rx_data *data = &rxq->data[i];
    847 
    848 		data->sc = sc;	/* backpointer for callbacks */
    849 
    850 		error = usbd_create_xfer(sc->rxq.pipeh, RUN_MAX_RXSZ,
    851 		    0, 0, &data->xfer);
    852 		if (error)
    853 			goto fail;
    854 
    855 		data->buf = usbd_get_buffer(data->xfer);
    856 	}
    857 	if (error != 0)
    858 fail:		run_free_rx_ring(sc);
    859 	return error;
    860 }
    861 
    862 static void
    863 run_free_rx_ring(struct run_softc *sc)
    864 {
    865 	struct run_rx_ring *rxq = &sc->rxq;
    866 	int i;
    867 
    868 	if (rxq->pipeh != NULL) {
    869 		usbd_abort_pipe(rxq->pipeh);
    870 	}
    871 	for (i = 0; i < RUN_RX_RING_COUNT; i++) {
    872 		if (rxq->data[i].xfer != NULL)
    873 			usbd_destroy_xfer(rxq->data[i].xfer);
    874 		rxq->data[i].xfer = NULL;
    875 	}
    876 	if (rxq->pipeh != NULL) {
    877 		usbd_close_pipe(rxq->pipeh);
    878 		rxq->pipeh = NULL;
    879 	}
    880 }
    881 
    882 static int
    883 run_alloc_tx_ring(struct run_softc *sc, int qid)
    884 {
    885 	struct run_tx_ring *txq = &sc->txq[qid];
    886 	int i, error;
    887 	uint16_t txwisize;
    888 
    889 	txwisize = sizeof(struct rt2860_txwi);
    890 	if (sc->mac_ver == 0x5592)
    891 		txwisize += sizeof(uint32_t);
    892 
    893 	txq->cur = txq->queued = 0;
    894 
    895 	error = usbd_open_pipe(sc->sc_iface, txq->pipe_no, 0, &txq->pipeh);
    896 	if (error != 0)
    897 		goto fail;
    898 
    899 	for (i = 0; i < RUN_TX_RING_COUNT; i++) {
    900 		struct run_tx_data *data = &txq->data[i];
    901 
    902 		data->sc = sc;	/* backpointer for callbacks */
    903 		data->qid = qid;
    904 
    905 		error = usbd_create_xfer(txq->pipeh, RUN_MAX_TXSZ,
    906 		    USBD_FORCE_SHORT_XFER, 0, &data->xfer);
    907 		if (error)
    908 			goto fail;
    909 
    910 		data->buf = usbd_get_buffer(data->xfer);
    911 		/* zeroize the TXD + TXWI part */
    912 		memset(data->buf, 0, sizeof(struct rt2870_txd) + txwisize);
    913 	}
    914 	if (error != 0)
    915 fail:		run_free_tx_ring(sc, qid);
    916 	return error;
    917 }
    918 
    919 static void
    920 run_free_tx_ring(struct run_softc *sc, int qid)
    921 {
    922 	struct run_tx_ring *txq = &sc->txq[qid];
    923 	int i;
    924 
    925 	if (txq->pipeh != NULL) {
    926 		usbd_abort_pipe(txq->pipeh);
    927 		usbd_close_pipe(txq->pipeh);
    928 		txq->pipeh = NULL;
    929 	}
    930 	for (i = 0; i < RUN_TX_RING_COUNT; i++) {
    931 		if (txq->data[i].xfer != NULL)
    932 			usbd_destroy_xfer(txq->data[i].xfer);
    933 		txq->data[i].xfer = NULL;
    934 	}
    935 }
    936 
    937 static int __noinline
    938 run_load_microcode(struct run_softc *sc)
    939 {
    940 	usb_device_request_t req;
    941 	const char *fwname;
    942 	u_char *ucode = NULL;	/* XXX gcc 4.8.3: maybe-uninitialized */
    943 	size_t size = 0;	/* XXX gcc 4.8.3: maybe-uninitialized */
    944 	uint32_t tmp;
    945 	int ntries, error;
    946 
    947 	/* RT3071/RT3072 use a different firmware */
    948 	if (sc->mac_ver != 0x2860 &&
    949 	    sc->mac_ver != 0x2872 &&
    950 	    sc->mac_ver != 0x3070)
    951 		fwname = "run-rt3071";
    952 	else
    953 		fwname = "run-rt2870";
    954 
    955 	if ((error = firmware_load("run", fwname, &ucode, &size)) != 0) {
    956 		device_printf(sc->sc_dev,
    957 		    "error %d, could not read firmware %s\n", error, fwname);
    958 		return error;
    959 	}
    960 	if (size != 4096) {
    961 		device_printf(sc->sc_dev,
    962 		    "invalid firmware size (should be 4KB)\n");
    963 		firmware_free(ucode, size);
    964 		return EINVAL;
    965 	}
    966 
    967 	run_read(sc, RT2860_ASIC_VER_ID, &tmp);
    968 	/* write microcode image */
    969 	run_write_region_1(sc, RT2870_FW_BASE, ucode, size);
    970 	firmware_free(ucode, size);
    971 	run_write(sc, RT2860_H2M_MAILBOX_CID, 0xffffffff);
    972 	run_write(sc, RT2860_H2M_MAILBOX_STATUS, 0xffffffff);
    973 
    974 	req.bmRequestType = UT_WRITE_VENDOR_DEVICE;
    975 	req.bRequest = RT2870_RESET;
    976 	USETW(req.wValue, 8);
    977 	USETW(req.wIndex, 0);
    978 	USETW(req.wLength, 0);
    979 	if ((error = usbd_do_request(sc->sc_udev, &req, NULL)) != 0)
    980 		return error;
    981 
    982 	usbd_delay_ms(sc->sc_udev, 10);
    983 	run_write(sc, RT2860_H2M_BBPAGENT, 0);
    984 	run_write(sc, RT2860_H2M_MAILBOX, 0);
    985 	run_write(sc, RT2860_H2M_INTSRC, 0);
    986 	if ((error = run_mcu_cmd(sc, RT2860_MCU_CMD_RFRESET, 0)) != 0)
    987 		return error;
    988 
    989 	/* wait until microcontroller is ready */
    990 	for (ntries = 0; ntries < 1000; ntries++) {
    991 		if ((error = run_read(sc, RT2860_SYS_CTRL, &tmp)) != 0)
    992 			return error;
    993 		if (tmp & RT2860_MCU_READY)
    994 			break;
    995 		usbd_delay_ms(sc->sc_udev, 10);
    996 	}
    997 	if (ntries == 1000) {
    998 		device_printf(sc->sc_dev,
    999 		    "timeout waiting for MCU to initialize\n");
   1000 		return ETIMEDOUT;
   1001 	}
   1002 
   1003 	sc->sc_flags |= RUN_FWLOADED;
   1004 
   1005 	DPRINTF(("microcode successfully loaded after %d tries\n", ntries));
   1006 	return 0;
   1007 }
   1008 
   1009 static int __noinline
   1010 run_reset(struct run_softc *sc)
   1011 {
   1012 	usb_device_request_t req;
   1013 
   1014 	req.bmRequestType = UT_WRITE_VENDOR_DEVICE;
   1015 	req.bRequest = RT2870_RESET;
   1016 	USETW(req.wValue, 1);
   1017 	USETW(req.wIndex, 0);
   1018 	USETW(req.wLength, 0);
   1019 	return usbd_do_request(sc->sc_udev, &req, NULL);
   1020 }
   1021 
   1022 static int __noinline
   1023 run_read(struct run_softc *sc, uint16_t reg, uint32_t *val)
   1024 {
   1025 	uint32_t tmp;
   1026 	int error;
   1027 
   1028 	error = run_read_region_1(sc, reg, (uint8_t *)&tmp, sizeof(tmp));
   1029 	if (error == 0)
   1030 		*val = le32toh(tmp);
   1031 	else
   1032 		*val = 0xffffffff;
   1033 	return error;
   1034 }
   1035 
   1036 static int
   1037 run_read_region_1(struct run_softc *sc, uint16_t reg, uint8_t *buf, int len)
   1038 {
   1039 	usb_device_request_t req;
   1040 
   1041 	req.bmRequestType = UT_READ_VENDOR_DEVICE;
   1042 	req.bRequest = RT2870_READ_REGION_1;
   1043 	USETW(req.wValue, 0);
   1044 	USETW(req.wIndex, reg);
   1045 	USETW(req.wLength, len);
   1046 	return usbd_do_request(sc->sc_udev, &req, buf);
   1047 }
   1048 
   1049 static int
   1050 run_write_2(struct run_softc *sc, uint16_t reg, uint16_t val)
   1051 {
   1052 	usb_device_request_t req;
   1053 
   1054 	req.bmRequestType = UT_WRITE_VENDOR_DEVICE;
   1055 	req.bRequest = RT2870_WRITE_2;
   1056 	USETW(req.wValue, val);
   1057 	USETW(req.wIndex, reg);
   1058 	USETW(req.wLength, 0);
   1059 	return usbd_do_request(sc->sc_udev, &req, NULL);
   1060 }
   1061 
   1062 static int __noinline
   1063 run_write(struct run_softc *sc, uint16_t reg, uint32_t val)
   1064 {
   1065 	uint32_t tmp = htole32(val);
   1066 	return run_write_region_1(sc, reg, (uint8_t *)&tmp, sizeof(tmp));
   1067 }
   1068 
   1069 static int
   1070 run_write_region_1(struct run_softc *sc, uint16_t reg, const uint8_t *buf,
   1071     int len)
   1072 {
   1073 	int error = 0;
   1074 	if (sc->sc_flags & RUN_USE_BLOCK_WRITE) {
   1075 		usb_device_request_t req;
   1076 		/*
   1077 		 * NOTE: It appears the WRITE_REGION_1 command cannot be
   1078 		 * passed a huge amount of data, which will crash the
   1079 		 * firmware. Limit amount of data passed to 64 bytes at a
   1080 		 * time.
   1081 		 */
   1082 		while (len > 0) {
   1083 			int delta = MIN(len, 64);
   1084 			req.bmRequestType = UT_WRITE_VENDOR_DEVICE;
   1085 			req.bRequest = RT2870_WRITE_REGION_1;
   1086 			USETW(req.wValue, 0);
   1087 			USETW(req.wIndex, reg);
   1088 			USETW(req.wLength, delta);
   1089 			error = usbd_do_request(sc->sc_udev, &req,
   1090 			    __UNCONST(buf));
   1091 			if (error != 0)
   1092 				break;
   1093 			reg += delta;
   1094 			buf += delta;
   1095 			len -= delta;
   1096 		}
   1097 	} else {
   1098 		/*
   1099 		 * NB: the WRITE_REGION_1 command is not stable on RT2860.
   1100 		 * We thus issue multiple WRITE_2 commands instead.
   1101 		 */
   1102 		int i;
   1103 		KASSERT((len & 1) == 0);
   1104 		for (i = 0; i < len && error == 0; i += 2)
   1105 			error = run_write_2(sc, reg + i, buf[i] | buf[i + 1] << 8);
   1106 	}
   1107 	return error;
   1108 }
   1109 
   1110 static int
   1111 run_set_region_4(struct run_softc *sc, uint16_t reg, uint32_t val, int count)
   1112 {
   1113 	int error = 0;
   1114 
   1115 	if (sc->sc_flags & RUN_USE_BLOCK_WRITE) {
   1116 		while (count > 0) {
   1117 			int i, delta;
   1118 			uint32_t tmp[16];
   1119 
   1120 			delta = MIN(count, __arraycount(tmp));
   1121 			for (i = 0; i < delta; i++)
   1122 				tmp[i] = htole32(val);
   1123 			error = run_write_region_1(sc, reg, (uint8_t *)tmp,
   1124 			    delta * sizeof(uint32_t));
   1125 			if (error != 0)
   1126 				break;
   1127 			reg += delta * sizeof(uint32_t);
   1128 			count -= delta;
   1129 		}
   1130 	} else {
   1131 		for (; count > 0 && error == 0; count--, reg += 4)
   1132 			error = run_write(sc, reg, val);
   1133 	}
   1134 	return error;
   1135 }
   1136 
   1137 static int
   1138 run_efuse_read(struct run_softc *sc, uint16_t addr, uint16_t *val, int count)
   1139 {
   1140 	uint32_t tmp;
   1141 	uint16_t reg;
   1142 	int error, ntries;
   1143 
   1144 	if ((error = run_read(sc, RT3070_EFUSE_CTRL, &tmp)) != 0)
   1145 		return error;
   1146 
   1147 	if (count == 2)
   1148 		addr *= 2;
   1149 	/*-
   1150 	 * Read one 16-byte block into registers EFUSE_DATA[0-3]:
   1151 	 * DATA0: F E D C
   1152 	 * DATA1: B A 9 8
   1153 	 * DATA2: 7 6 5 4
   1154 	 * DATA3: 3 2 1 0
   1155 	 */
   1156 	tmp &= ~(RT3070_EFSROM_MODE_MASK | RT3070_EFSROM_AIN_MASK);
   1157 	tmp |= (addr & ~0xf) << RT3070_EFSROM_AIN_SHIFT | RT3070_EFSROM_KICK;
   1158 	run_write(sc, RT3070_EFUSE_CTRL, tmp);
   1159 	for (ntries = 0; ntries < 100; ntries++) {
   1160 		if ((error = run_read(sc, RT3070_EFUSE_CTRL, &tmp)) != 0)
   1161 			return error;
   1162 		if (!(tmp & RT3070_EFSROM_KICK))
   1163 			break;
   1164 		usbd_delay_ms(sc->sc_udev, 2);
   1165 	}
   1166 	if (ntries == 100)
   1167 		return ETIMEDOUT;
   1168 
   1169 	if ((tmp & RT3070_EFUSE_AOUT_MASK) == RT3070_EFUSE_AOUT_MASK) {
   1170 		*val = 0xffff;	/* address not found */
   1171 		return 0;
   1172 	}
   1173 	/* determine to which 32-bit register our 16-bit word belongs */
   1174 	reg = RT3070_EFUSE_DATA3 - (addr & 0xc);
   1175 	if ((error = run_read(sc, reg, &tmp)) != 0)
   1176 		return error;
   1177 
   1178 	tmp >>= (8 * (addr & 0x3));
   1179 	*val = (addr & 1) ? tmp >> 16 : tmp & 0xffff;
   1180 	return 0;
   1181 }
   1182 
   1183 /* Read 16-bit from eFUSE ROM for RT3xxxx. */
   1184 static int
   1185 run_efuse_read_2(struct run_softc *sc, uint16_t addr, uint16_t *val)
   1186 {
   1187 	return run_efuse_read(sc, addr, val, 2);
   1188 }
   1189 
   1190 static int
   1191 run_eeprom_read_2(struct run_softc *sc, uint16_t addr, uint16_t *val)
   1192 {
   1193 	usb_device_request_t req;
   1194 	uint16_t tmp;
   1195 	int error;
   1196 
   1197 	addr *= 2;
   1198 	req.bmRequestType = UT_READ_VENDOR_DEVICE;
   1199 	req.bRequest = RT2870_EEPROM_READ;
   1200 	USETW(req.wValue, 0);
   1201 	USETW(req.wIndex, addr);
   1202 	USETW(req.wLength, sizeof(tmp));
   1203 	error = usbd_do_request(sc->sc_udev, &req, &tmp);
   1204 	if (error == 0)
   1205 		*val = le16toh(tmp);
   1206 	else
   1207 		*val = 0xffff;
   1208 	return error;
   1209 }
   1210 
   1211 static __inline int
   1212 run_srom_read(struct run_softc *sc, uint16_t addr, uint16_t *val)
   1213 {
   1214 
   1215 	/* either eFUSE ROM or EEPROM */
   1216 	return sc->sc_srom_read(sc, addr, val);
   1217 }
   1218 
   1219 static int
   1220 run_rt2870_rf_write(struct run_softc *sc, uint8_t reg, uint32_t val)
   1221 {
   1222 	uint32_t tmp;
   1223 	int error, ntries;
   1224 
   1225 	for (ntries = 0; ntries < 10; ntries++) {
   1226 		if ((error = run_read(sc, RT2860_RF_CSR_CFG0, &tmp)) != 0)
   1227 			return error;
   1228 		if (!(tmp & RT2860_RF_REG_CTRL))
   1229 			break;
   1230 	}
   1231 	if (ntries == 10)
   1232 		return ETIMEDOUT;
   1233 
   1234 	/* RF registers are 24-bit on the RT2860 */
   1235 	tmp = RT2860_RF_REG_CTRL | 24 << RT2860_RF_REG_WIDTH_SHIFT |
   1236 	    (val & 0x3fffff) << 2 | (reg & 3);
   1237 	return run_write(sc, RT2860_RF_CSR_CFG0, tmp);
   1238 }
   1239 
   1240 static int
   1241 run_rt3070_rf_read(struct run_softc *sc, uint8_t reg, uint8_t *val)
   1242 {
   1243 	uint32_t tmp;
   1244 	int error, ntries;
   1245 
   1246 	for (ntries = 0; ntries < 100; ntries++) {
   1247 		if ((error = run_read(sc, RT3070_RF_CSR_CFG, &tmp)) != 0)
   1248 			return error;
   1249 		if (!(tmp & RT3070_RF_KICK))
   1250 			break;
   1251 	}
   1252 	if (ntries == 100)
   1253 		return ETIMEDOUT;
   1254 
   1255 	tmp = RT3070_RF_KICK | reg << 8;
   1256 	if ((error = run_write(sc, RT3070_RF_CSR_CFG, tmp)) != 0)
   1257 		return error;
   1258 
   1259 	for (ntries = 0; ntries < 100; ntries++) {
   1260 		if ((error = run_read(sc, RT3070_RF_CSR_CFG, &tmp)) != 0)
   1261 			return error;
   1262 		if (!(tmp & RT3070_RF_KICK))
   1263 			break;
   1264 	}
   1265 	if (ntries == 100)
   1266 		return ETIMEDOUT;
   1267 
   1268 	*val = tmp & 0xff;
   1269 	return 0;
   1270 }
   1271 
   1272 static int
   1273 run_rt3070_rf_write(struct run_softc *sc, uint8_t reg, uint8_t val)
   1274 {
   1275 	uint32_t tmp;
   1276 	int error, ntries;
   1277 
   1278 	for (ntries = 0; ntries < 10; ntries++) {
   1279 		if ((error = run_read(sc, RT3070_RF_CSR_CFG, &tmp)) != 0)
   1280 			return error;
   1281 		if (!(tmp & RT3070_RF_KICK))
   1282 			break;
   1283 	}
   1284 	if (ntries == 10)
   1285 		return ETIMEDOUT;
   1286 
   1287 	tmp = RT3070_RF_WRITE | RT3070_RF_KICK | reg << 8 | val;
   1288 	return run_write(sc, RT3070_RF_CSR_CFG, tmp);
   1289 }
   1290 
   1291 static int
   1292 run_bbp_read(struct run_softc *sc, uint8_t reg, uint8_t *val)
   1293 {
   1294 	uint32_t tmp;
   1295 	int ntries, error;
   1296 
   1297 	for (ntries = 0; ntries < 10; ntries++) {
   1298 		if ((error = run_read(sc, RT2860_BBP_CSR_CFG, &tmp)) != 0)
   1299 			return error;
   1300 		if (!(tmp & RT2860_BBP_CSR_KICK))
   1301 			break;
   1302 	}
   1303 	if (ntries == 10)
   1304 		return ETIMEDOUT;
   1305 
   1306 	tmp = RT2860_BBP_CSR_READ | RT2860_BBP_CSR_KICK | reg << 8;
   1307 	if ((error = run_write(sc, RT2860_BBP_CSR_CFG, tmp)) != 0)
   1308 		return error;
   1309 
   1310 	for (ntries = 0; ntries < 10; ntries++) {
   1311 		if ((error = run_read(sc, RT2860_BBP_CSR_CFG, &tmp)) != 0)
   1312 			return error;
   1313 		if (!(tmp & RT2860_BBP_CSR_KICK))
   1314 			break;
   1315 	}
   1316 	if (ntries == 10)
   1317 		return ETIMEDOUT;
   1318 
   1319 	*val = tmp & 0xff;
   1320 	return 0;
   1321 }
   1322 
   1323 static int
   1324 run_bbp_write(struct run_softc *sc, uint8_t reg, uint8_t val)
   1325 {
   1326 	uint32_t tmp;
   1327 	int ntries, error;
   1328 
   1329 	for (ntries = 0; ntries < 10; ntries++) {
   1330 		if ((error = run_read(sc, RT2860_BBP_CSR_CFG, &tmp)) != 0)
   1331 			return error;
   1332 		if (!(tmp & RT2860_BBP_CSR_KICK))
   1333 			break;
   1334 	}
   1335 	if (ntries == 10)
   1336 		return ETIMEDOUT;
   1337 
   1338 	tmp = RT2860_BBP_CSR_KICK | reg << 8 | val;
   1339 	return run_write(sc, RT2860_BBP_CSR_CFG, tmp);
   1340 }
   1341 
   1342 /*
   1343  * Send a command to the 8051 microcontroller unit.
   1344  */
   1345 static int
   1346 run_mcu_cmd(struct run_softc *sc, uint8_t cmd, uint16_t arg)
   1347 {
   1348 	uint32_t tmp;
   1349 	int error, ntries;
   1350 
   1351 	for (ntries = 0; ntries < 100; ntries++) {
   1352 		if ((error = run_read(sc, RT2860_H2M_MAILBOX, &tmp)) != 0)
   1353 			return error;
   1354 		if (!(tmp & RT2860_H2M_BUSY))
   1355 			break;
   1356 	}
   1357 	if (ntries == 100)
   1358 		return ETIMEDOUT;
   1359 
   1360 	tmp = RT2860_H2M_BUSY | RT2860_TOKEN_NO_INTR << 16 | arg;
   1361 	if ((error = run_write(sc, RT2860_H2M_MAILBOX, tmp)) == 0)
   1362 		error = run_write(sc, RT2860_HOST_CMD, cmd);
   1363 	return error;
   1364 }
   1365 
   1366 /*
   1367  * Add `delta' (signed) to each 4-bit sub-word of a 32-bit word.
   1368  * Used to adjust per-rate Tx power registers.
   1369  */
   1370 static __inline uint32_t
   1371 b4inc(uint32_t b32, int8_t delta)
   1372 {
   1373 	int8_t i, b4;
   1374 
   1375 	for (i = 0; i < 8; i++) {
   1376 		b4 = b32 & 0xf;
   1377 		b4 += delta;
   1378 		if (b4 < 0)
   1379 			b4 = 0;
   1380 		else if (b4 > 0xf)
   1381 			b4 = 0xf;
   1382 		b32 = b32 >> 4 | b4 << 28;
   1383 	}
   1384 	return b32;
   1385 }
   1386 
   1387 static const char *
   1388 run_get_rf(uint16_t rev)
   1389 {
   1390 	switch (rev) {
   1391 	case RT2860_RF_2820:	return "RT2820";
   1392 	case RT2860_RF_2850:	return "RT2850";
   1393 	case RT2860_RF_2720:	return "RT2720";
   1394 	case RT2860_RF_2750:	return "RT2750";
   1395 	case RT3070_RF_3020:	return "RT3020";
   1396 	case RT3070_RF_2020:	return "RT2020";
   1397 	case RT3070_RF_3021:	return "RT3021";
   1398 	case RT3070_RF_3022:	return "RT3022";
   1399 	case RT3070_RF_3052:	return "RT3052";
   1400 	case RT3070_RF_3053:    return "RT3053";
   1401 	case RT5592_RF_5592:    return "RT5592";
   1402 	case RT5390_RF_5370:    return "RT5370";
   1403 	case RT5390_RF_5372:    return "RT5372";
   1404 	}
   1405 	return "unknown";
   1406 }
   1407 
   1408 static void
   1409 run_rt3593_get_txpower(struct run_softc *sc)
   1410 {
   1411 	uint16_t addr, val;
   1412 	int i;
   1413 
   1414 	/* Read power settings for 2GHz channels. */
   1415 	for (i = 0; i < 14; i += 2) {
   1416 		addr = (sc->ntxchains == 3) ? RT3593_EEPROM_PWR2GHZ_BASE1 :
   1417 		    RT2860_EEPROM_PWR2GHZ_BASE1;
   1418 		run_srom_read(sc, addr + i / 2, &val);
   1419 		sc->txpow1[i + 0] = (int8_t)(val & 0xff);
   1420 		sc->txpow1[i + 1] = (int8_t)(val >> 8);
   1421 
   1422 		addr = (sc->ntxchains == 3) ? RT3593_EEPROM_PWR2GHZ_BASE2 :
   1423 		    RT2860_EEPROM_PWR2GHZ_BASE2;
   1424 		run_srom_read(sc, addr + i / 2, &val);
   1425 		sc->txpow2[i + 0] = (int8_t)(val & 0xff);
   1426 		sc->txpow2[i + 1] = (int8_t)(val >> 8);
   1427 
   1428 		if (sc->ntxchains == 3) {
   1429 			run_srom_read(sc, RT3593_EEPROM_PWR2GHZ_BASE3 + i / 2,
   1430 			    &val);
   1431 			sc->txpow3[i + 0] = (int8_t)(val & 0xff);
   1432 			sc->txpow3[i + 1] = (int8_t)(val >> 8);
   1433 		}
   1434 	}
   1435 	/* Fix broken Tx power entries. */
   1436 	for (i = 0; i < 14; i++) {
   1437 		if (sc->txpow1[i] > 31)
   1438 			sc->txpow1[i] = 5;
   1439 		if (sc->txpow2[i] > 31)
   1440 			sc->txpow2[i] = 5;
   1441 		if (sc->ntxchains == 3) {
   1442 			if (sc->txpow3[i] > 31)
   1443 				sc->txpow3[i] = 5;
   1444 		}
   1445 	}
   1446 	/* Read power settings for 5GHz channels. */
   1447 	for (i = 0; i < 40; i += 2) {
   1448 		run_srom_read(sc, RT3593_EEPROM_PWR5GHZ_BASE1 + i / 2, &val);
   1449 		sc->txpow1[i + 14] = (int8_t)(val & 0xff);
   1450 		sc->txpow1[i + 15] = (int8_t)(val >> 8);
   1451 
   1452 		run_srom_read(sc, RT3593_EEPROM_PWR5GHZ_BASE2 + i / 2, &val);
   1453 		sc->txpow2[i + 14] = (int8_t)(val & 0xff);
   1454 		sc->txpow2[i + 15] = (int8_t)(val >> 8);
   1455 
   1456 		if (sc->ntxchains == 3) {
   1457 			run_srom_read(sc, RT3593_EEPROM_PWR5GHZ_BASE3 + i / 2,
   1458 			    &val);
   1459 			sc->txpow3[i + 14] = (int8_t)(val & 0xff);
   1460 			sc->txpow3[i + 15] = (int8_t)(val >> 8);
   1461 		}
   1462 	}
   1463 }
   1464 
   1465 static void
   1466 run_get_txpower(struct run_softc *sc)
   1467 {
   1468 	uint16_t val;
   1469 	int i;
   1470 
   1471 	/* Read power settings for 2GHz channels. */
   1472 	for (i = 0; i < 14; i += 2) {
   1473 		run_srom_read(sc, RT2860_EEPROM_PWR2GHZ_BASE1 + i / 2, &val);
   1474 		sc->txpow1[i + 0] = (int8_t)(val & 0xff);
   1475 		sc->txpow1[i + 1] = (int8_t)(val >> 8);
   1476 
   1477 		if (sc->mac_ver != 0x5390) {
   1478 			run_srom_read(sc,
   1479 			    RT2860_EEPROM_PWR2GHZ_BASE2 + i / 2, &val);
   1480 			sc->txpow2[i + 0] = (int8_t)(val & 0xff);
   1481 			sc->txpow2[i + 1] = (int8_t)(val >> 8);
   1482 		}
   1483 	}
   1484 	/* Fix broken Tx power entries. */
   1485 	for (i = 0; i < 14; i++) {
   1486 		if (sc->mac_ver >= 0x5390) {
   1487 			if (sc->txpow1[i] < 0 || sc->txpow1[i] > 39)
   1488 				sc->txpow1[i] = 5;
   1489 		} else {
   1490 			if (sc->txpow1[i] < 0 || sc->txpow1[i] > 31)
   1491 				sc->txpow1[i] = 5;
   1492 		}
   1493 		if (sc->mac_ver > 0x5390) {
   1494 			if (sc->txpow2[i] < 0 || sc->txpow2[i] > 39)
   1495 				sc->txpow2[i] = 5;
   1496 		} else if (sc->mac_ver < 0x5390) {
   1497 			if (sc->txpow2[i] < 0 || sc->txpow2[i] > 31)
   1498 				sc->txpow2[i] = 5;
   1499 		}
   1500 		DPRINTF(("chan %d: power1=%d, power2=%d\n",
   1501 		    rt2860_rf2850[i].chan, sc->txpow1[i], sc->txpow2[i]));
   1502 	}
   1503 	/* Read power settings for 5GHz channels. */
   1504 	for (i = 0; i < 40; i += 2) {
   1505 		run_srom_read(sc, RT2860_EEPROM_PWR5GHZ_BASE1 + i / 2, &val);
   1506 		sc->txpow1[i + 14] = (int8_t)(val & 0xff);
   1507 		sc->txpow1[i + 15] = (int8_t)(val >> 8);
   1508 
   1509 		run_srom_read(sc, RT2860_EEPROM_PWR5GHZ_BASE2 + i / 2, &val);
   1510 		sc->txpow2[i + 14] = (int8_t)(val & 0xff);
   1511 		sc->txpow2[i + 15] = (int8_t)(val >> 8);
   1512 	}
   1513 	/* Fix broken Tx power entries. */
   1514 	for (i = 0; i < 40; i++ ) {
   1515 		if (sc->mac_ver != 0x5592) {
   1516 			if (sc->txpow1[14 + i] < -7 || sc->txpow1[14 + i] > 15)
   1517 				sc->txpow1[14 + i] = 5;
   1518 			if (sc->txpow2[14 + i] < -7 || sc->txpow2[14 + i] > 15)
   1519 				sc->txpow2[14 + i] = 5;
   1520 		}
   1521 		DPRINTF(("chan %d: power1=%d, power2=%d\n",
   1522 		    rt2860_rf2850[14 + i].chan, sc->txpow1[14 + i],
   1523 		    sc->txpow2[14 + i]));
   1524 	}
   1525 }
   1526 
   1527 static int
   1528 run_read_eeprom(struct run_softc *sc)
   1529 {
   1530 	struct ieee80211com *ic = &sc->sc_ic;
   1531 	int8_t delta_2ghz, delta_5ghz;
   1532 	uint32_t tmp;
   1533 	uint16_t val;
   1534 	int ridx, ant, i;
   1535 
   1536 	/* check whether the ROM is eFUSE ROM or EEPROM */
   1537 	sc->sc_srom_read = run_eeprom_read_2;
   1538 	if (sc->mac_ver >= 0x3070) {
   1539 		run_read(sc, RT3070_EFUSE_CTRL, &tmp);
   1540 		DPRINTF(("EFUSE_CTRL=0x%08x\n", tmp));
   1541 		if (tmp & RT3070_SEL_EFUSE)
   1542 			sc->sc_srom_read = run_efuse_read_2;
   1543 	}
   1544 
   1545 	/* read ROM version */
   1546 	run_srom_read(sc, RT2860_EEPROM_VERSION, &val);
   1547 	DPRINTF(("EEPROM rev=%d, FAE=%d\n", val & 0xff, val >> 8));
   1548 
   1549 	/* read MAC address */
   1550 	run_srom_read(sc, RT2860_EEPROM_MAC01, &val);
   1551 	ic->ic_myaddr[0] = val & 0xff;
   1552 	ic->ic_myaddr[1] = val >> 8;
   1553 	run_srom_read(sc, RT2860_EEPROM_MAC23, &val);
   1554 	ic->ic_myaddr[2] = val & 0xff;
   1555 	ic->ic_myaddr[3] = val >> 8;
   1556 	run_srom_read(sc, RT2860_EEPROM_MAC45, &val);
   1557 	ic->ic_myaddr[4] = val & 0xff;
   1558 	ic->ic_myaddr[5] = val >> 8;
   1559 
   1560 	if (sc->mac_ver < 0x3593) {
   1561 		/* read vendor BBP settings */
   1562 		for (i = 0; i < 10; i++) {
   1563 			run_srom_read(sc, RT2860_EEPROM_BBP_BASE + i, &val);
   1564 			sc->bbp[i].val = val & 0xff;
   1565 			sc->bbp[i].reg = val >> 8;
   1566 			DPRINTF(("BBP%d=0x%02x\n", sc->bbp[i].reg,
   1567 			    sc->bbp[i].val));
   1568 		}
   1569 
   1570 		if (sc->mac_ver >= 0x3071) {
   1571 			/* read vendor RF settings */
   1572 			for (i = 0; i < 8; i++) {
   1573 				run_srom_read(sc, RT3071_EEPROM_RF_BASE + i,
   1574 				    &val);
   1575 				sc->rf[i].val = val & 0xff;
   1576 				sc->rf[i].reg = val >> 8;
   1577 				DPRINTF(("RF%d=0x%02x\n", sc->rf[i].reg,
   1578 				    sc->rf[i].val));
   1579 			}
   1580 		}
   1581 	}
   1582 
   1583 	/* read RF frequency offset from EEPROM */
   1584 	run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_FREQ_LEDS :
   1585 	    RT3593_EEPROM_FREQ, &val);
   1586 	sc->freq = ((val & 0xff) != 0xff) ? val & 0xff : 0;
   1587 	DPRINTF(("EEPROM freq offset %d\n", sc->freq & 0xff));
   1588 	run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_FREQ_LEDS :
   1589 	    RT3593_EEPROM_FREQ, &val);
   1590 	if ((val >> 8) != 0xff) {
   1591 		/* read LEDs operating mode */
   1592 		sc->leds = val >> 8;
   1593 		run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_LED1 :
   1594 		    RT3593_EEPROM_LED1, &sc->led[0]);
   1595 		run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_LED2 :
   1596 		    RT3593_EEPROM_LED2, &sc->led[1]);
   1597 		run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_LED3 :
   1598 		    RT3593_EEPROM_LED3, &sc->led[2]);
   1599 	} else {
   1600 		/* broken EEPROM, use default settings */
   1601 		sc->leds = 0x01;
   1602 		sc->led[0] = 0x5555;
   1603 		sc->led[1] = 0x2221;
   1604 		sc->led[2] = 0x5627;	/* differs from RT2860 */
   1605 	}
   1606 	DPRINTF(("EEPROM LED mode=0x%02x, LEDs=0x%04x/0x%04x/0x%04x\n",
   1607 	    sc->leds, sc->led[0], sc->led[1], sc->led[2]));
   1608 
   1609 	/* read RF information */
   1610 	if (sc->mac_ver == 0x5390 || sc->mac_ver == 0x5392)
   1611 		run_srom_read(sc, 0x00, &val);
   1612 	else
   1613 		run_srom_read(sc, RT2860_EEPROM_ANTENNA, &val);
   1614 	if (val == 0xffff) {
   1615 		DPRINTF(("invalid EEPROM antenna info, using default\n"));
   1616 		if (sc->mac_ver == 0x3572) {
   1617 			/* default to RF3052 2T2R */
   1618 			sc->rf_rev = RT3070_RF_3052;
   1619 			sc->ntxchains = 2;
   1620 			sc->nrxchains = 2;
   1621 		} else if (sc->mac_ver >= 0x3070) {
   1622 			/* default to RF3020 1T1R */
   1623 			sc->rf_rev = RT3070_RF_3020;
   1624 			sc->ntxchains = 1;
   1625 			sc->nrxchains = 1;
   1626 		} else {
   1627 			/* default to RF2820 1T2R */
   1628 			sc->rf_rev = RT2860_RF_2820;
   1629 			sc->ntxchains = 1;
   1630 			sc->nrxchains = 2;
   1631 		}
   1632 	} else {
   1633 		if (sc->mac_ver == 0x5390 || sc->mac_ver == 0x5392) {
   1634 			sc->rf_rev = val;
   1635 			run_srom_read(sc, RT2860_EEPROM_ANTENNA, &val);
   1636 		} else
   1637 			sc->rf_rev = (val >> 8) & 0xf;
   1638 		sc->ntxchains = (val >> 4) & 0xf;
   1639 		sc->nrxchains = val & 0xf;
   1640 	}
   1641 	DPRINTF(("EEPROM RF rev=0x%04x chains=%dT%dR\n",
   1642 	    sc->rf_rev, sc->ntxchains, sc->nrxchains));
   1643 
   1644 	run_srom_read(sc, RT2860_EEPROM_CONFIG, &val);
   1645 	DPRINTF(("EEPROM CFG 0x%04x\n", val));
   1646 	/* check if driver should patch the DAC issue */
   1647 	if ((val >> 8) != 0xff)
   1648 		sc->patch_dac = (val >> 15) & 1;
   1649 	if ((val & 0xff) != 0xff) {
   1650 		sc->ext_5ghz_lna = (val >> 3) & 1;
   1651 		sc->ext_2ghz_lna = (val >> 2) & 1;
   1652 		/* check if RF supports automatic Tx access gain control */
   1653 		sc->calib_2ghz = sc->calib_5ghz = (val >> 1) & 1;
   1654 		/* check if we have a hardware radio switch */
   1655 		sc->rfswitch = val & 1;
   1656 	}
   1657 
   1658 	/* Read Tx power settings. */
   1659 	if (sc->mac_ver == 0x3593)
   1660 		run_rt3593_get_txpower(sc);
   1661 	else
   1662 		run_get_txpower(sc);
   1663 
   1664 	/* read Tx power compensation for each Tx rate */
   1665 	run_srom_read(sc, RT2860_EEPROM_DELTAPWR, &val);
   1666 	delta_2ghz = delta_5ghz = 0;
   1667 	if ((val & 0xff) != 0xff && (val & 0x80)) {
   1668 		delta_2ghz = val & 0xf;
   1669 		if (!(val & 0x40))	/* negative number */
   1670 			delta_2ghz = -delta_2ghz;
   1671 	}
   1672 	val >>= 8;
   1673 	if ((val & 0xff) != 0xff && (val & 0x80)) {
   1674 		delta_5ghz = val & 0xf;
   1675 		if (!(val & 0x40))	/* negative number */
   1676 			delta_5ghz = -delta_5ghz;
   1677 	}
   1678 	DPRINTF(("power compensation=%d (2GHz), %d (5GHz)\n",
   1679 	    delta_2ghz, delta_5ghz));
   1680 
   1681 	for (ridx = 0; ridx < 5; ridx++) {
   1682 		uint32_t reg;
   1683 
   1684 		run_srom_read(sc, RT2860_EEPROM_RPWR + ridx * 2, &val);
   1685 		reg = val;
   1686 		run_srom_read(sc, RT2860_EEPROM_RPWR + ridx * 2 + 1, &val);
   1687 		reg |= (uint32_t)val << 16;
   1688 
   1689 		sc->txpow20mhz[ridx] = reg;
   1690 		sc->txpow40mhz_2ghz[ridx] = b4inc(reg, delta_2ghz);
   1691 		sc->txpow40mhz_5ghz[ridx] = b4inc(reg, delta_5ghz);
   1692 
   1693 		DPRINTF(("ridx %d: power 20MHz=0x%08x, 40MHz/2GHz=0x%08x, "
   1694 		    "40MHz/5GHz=0x%08x\n", ridx, sc->txpow20mhz[ridx],
   1695 		    sc->txpow40mhz_2ghz[ridx], sc->txpow40mhz_5ghz[ridx]));
   1696 	}
   1697 
   1698 	DPRINTF(("mac_ver %hx\n", sc->mac_ver));
   1699 	/* read RSSI offsets and LNA gains from EEPROM */
   1700 	run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_RSSI1_2GHZ :
   1701 	    RT3593_EEPROM_RSSI1_2GHZ, &val);
   1702 	sc->rssi_2ghz[0] = val & 0xff;	/* Ant A */
   1703 	sc->rssi_2ghz[1] = val >> 8;	/* Ant B */
   1704 	run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_RSSI2_2GHZ :
   1705 	    RT3593_EEPROM_RSSI2_2GHZ, &val);
   1706 	if (sc->mac_ver >= 0x3070) {
   1707 		if (sc->mac_ver == 0x3593) {
   1708 			sc->txmixgain_2ghz = 0;
   1709 			sc->rssi_2ghz[2] = val & 0xff; 	/* Ant C */
   1710 		} else {
   1711 			/*
   1712 			 * On RT3070 chips (limited to 2 Rx chains), this ROM
   1713 			 * field contains the Tx mixer gain for the 2GHz band.
   1714 			 */
   1715 			if ((val & 0xff) != 0xff)
   1716 				sc->txmixgain_2ghz = val & 0x7;
   1717 		}
   1718 		DPRINTF(("tx mixer gain=%u (2GHz)\n", sc->txmixgain_2ghz));
   1719 	} else {
   1720 		sc->rssi_2ghz[2] = val & 0xff;	/* Ant C */
   1721 	}
   1722 	if (sc->mac_ver == 0x3593)
   1723 		run_srom_read(sc, RT3593_EEPROM_LNA_5GHZ, &val);
   1724 	sc->lna[2] = val >> 8;		/* channel group 2 */
   1725 
   1726 	run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_RSSI1_5GHZ :
   1727 	    RT3593_EEPROM_RSSI1_5GHZ, &val);
   1728 	sc->rssi_5ghz[0] = val & 0xff;	/* Ant A */
   1729 	sc->rssi_5ghz[1] = val >> 8;	/* Ant B */
   1730 	run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_RSSI2_5GHZ :
   1731 	    RT3593_EEPROM_RSSI2_5GHZ, &val);
   1732 	if (sc->mac_ver == 0x3572) {
   1733 		/*
   1734 		 * On RT3572 chips (limited to 2 Rx chains), this ROM
   1735 		 * field contains the Tx mixer gain for the 5GHz band.
   1736 		 */
   1737 		if ((val & 0xff) != 0xff)
   1738 			sc->txmixgain_5ghz = val & 0x7;
   1739 		DPRINTF(("tx mixer gain=%u (5GHz)\n", sc->txmixgain_5ghz));
   1740 	} else {
   1741 		sc->rssi_5ghz[2] = val & 0xff;	/* Ant C */
   1742 	}
   1743 	if (sc->mac_ver == 0x3593) {
   1744 		sc->txmixgain_5ghz = 0;
   1745 		run_srom_read(sc, RT3593_EEPROM_LNA_5GHZ, &val);
   1746 	}
   1747 	sc->lna[3] = val >> 8;		/* channel group 3 */
   1748 
   1749 	run_srom_read(sc, (sc->mac_ver != 0x3593) ? RT2860_EEPROM_LNA :
   1750 	    RT3593_EEPROM_LNA, &val);
   1751 	sc->lna[0] = val & 0xff;	/* channel group 0 */
   1752 	sc->lna[1] = val >> 8;		/* channel group 1 */
   1753 
   1754 	/* fix broken 5GHz LNA entries */
   1755 	if (sc->lna[2] == 0 || sc->lna[2] == 0xff) {
   1756 		DPRINTF(("invalid LNA for channel group %d\n", 2));
   1757 		sc->lna[2] = sc->lna[1];
   1758 	}
   1759 	if (sc->lna[3] == 0 || sc->lna[3] == 0xff) {
   1760 		DPRINTF(("invalid LNA for channel group %d\n", 3));
   1761 		sc->lna[3] = sc->lna[1];
   1762 	}
   1763 
   1764 	/* fix broken RSSI offset entries */
   1765 	for (ant = 0; ant < 3; ant++) {
   1766 		if (sc->rssi_2ghz[ant] < -10 || sc->rssi_2ghz[ant] > 10) {
   1767 			DPRINTF(("invalid RSSI%d offset: %d (2GHz)\n",
   1768 			    ant + 1, sc->rssi_2ghz[ant]));
   1769 			sc->rssi_2ghz[ant] = 0;
   1770 		}
   1771 		if (sc->rssi_5ghz[ant] < -10 || sc->rssi_5ghz[ant] > 10) {
   1772 			DPRINTF(("invalid RSSI%d offset: %d (5GHz)\n",
   1773 			    ant + 1, sc->rssi_5ghz[ant]));
   1774 			sc->rssi_5ghz[ant] = 0;
   1775 		}
   1776 	}
   1777 	return 0;
   1778 }
   1779 
   1780 static struct ieee80211_node *
   1781 run_node_alloc(struct ieee80211_node_table *nt)
   1782 {
   1783 	struct run_node *rn =
   1784 	    malloc(sizeof(struct run_node), M_DEVBUF, M_NOWAIT | M_ZERO);
   1785 	return rn ? &rn->ni : NULL;
   1786 }
   1787 
   1788 static int
   1789 run_media_change(struct ifnet *ifp)
   1790 {
   1791 	struct run_softc *sc = ifp->if_softc;
   1792 	struct ieee80211com *ic = &sc->sc_ic;
   1793 	uint8_t rate, ridx;
   1794 	int error;
   1795 
   1796 	error = ieee80211_media_change(ifp);
   1797 	if (error != ENETRESET)
   1798 		return error;
   1799 
   1800 	if (ic->ic_fixed_rate != IEEE80211_FIXED_RATE_NONE) {
   1801 		rate = ic->ic_sup_rates[ic->ic_curmode].
   1802 		    rs_rates[ic->ic_fixed_rate] & IEEE80211_RATE_VAL;
   1803 		for (ridx = 0; ridx <= RT2860_RIDX_MAX; ridx++)
   1804 			if (rt2860_rates[ridx].rate == rate)
   1805 				break;
   1806 		sc->fixed_ridx = ridx;
   1807 	}
   1808 
   1809 	if ((ifp->if_flags & (IFF_UP | IFF_RUNNING)) == (IFF_UP | IFF_RUNNING))
   1810 		run_init(ifp);
   1811 
   1812 	return 0;
   1813 }
   1814 
   1815 static void
   1816 run_next_scan(void *arg)
   1817 {
   1818 	struct run_softc *sc = arg;
   1819 
   1820 	if (sc->sc_ic.ic_state == IEEE80211_S_SCAN)
   1821 		ieee80211_next_scan(&sc->sc_ic);
   1822 }
   1823 
   1824 static void
   1825 run_task(void *arg)
   1826 {
   1827 	struct run_softc *sc = arg;
   1828 	struct run_host_cmd_ring *ring = &sc->cmdq;
   1829 	struct run_host_cmd *cmd;
   1830 	int s;
   1831 
   1832 	/* process host commands */
   1833 	s = splusb();
   1834 	while (ring->next != ring->cur) {
   1835 		cmd = &ring->cmd[ring->next];
   1836 		splx(s);
   1837 		membar_consumer();
   1838 		/* callback */
   1839 		cmd->cb(sc, cmd->data);
   1840 		s = splusb();
   1841 		atomic_dec_uint(&ring->queued);
   1842 		ring->next = (ring->next + 1) % RUN_HOST_CMD_RING_COUNT;
   1843 	}
   1844 	wakeup(ring);
   1845 	splx(s);
   1846 }
   1847 
   1848 static void
   1849 run_do_async(struct run_softc *sc, void (*cb)(struct run_softc *, void *),
   1850     void *arg, int len)
   1851 {
   1852 	struct run_host_cmd_ring *ring = &sc->cmdq;
   1853 	struct run_host_cmd *cmd;
   1854 	int s;
   1855 
   1856 	if (sc->sc_flags & RUN_DETACHING)
   1857 		return;
   1858 
   1859 	s = splusb();
   1860 	cmd = &ring->cmd[ring->cur];
   1861 	cmd->cb = cb;
   1862 	KASSERT(len <= sizeof(cmd->data));
   1863 	memcpy(cmd->data, arg, len);
   1864 	membar_producer();
   1865 	ring->cur = (ring->cur + 1) % RUN_HOST_CMD_RING_COUNT;
   1866 
   1867 	/* if there is no pending command already, schedule a task */
   1868 	if (atomic_inc_uint_nv(&ring->queued) == 1)
   1869 		usb_add_task(sc->sc_udev, &sc->sc_task, USB_TASKQ_DRIVER);
   1870 	splx(s);
   1871 }
   1872 
   1873 static int
   1874 run_newstate(struct ieee80211com *ic, enum ieee80211_state nstate, int arg)
   1875 {
   1876 	struct run_softc *sc = ic->ic_ifp->if_softc;
   1877 	struct run_cmd_newstate cmd;
   1878 
   1879 	callout_stop(&sc->scan_to);
   1880 	callout_stop(&sc->calib_to);
   1881 
   1882 	/* do it in a process context */
   1883 	cmd.state = nstate;
   1884 	cmd.arg = arg;
   1885 	run_do_async(sc, run_newstate_cb, &cmd, sizeof(cmd));
   1886 	return 0;
   1887 }
   1888 
   1889 static void
   1890 run_newstate_cb(struct run_softc *sc, void *arg)
   1891 {
   1892 	struct run_cmd_newstate *cmd = arg;
   1893 	struct ifnet *ifp = &sc->sc_if;
   1894 	struct ieee80211com *ic = &sc->sc_ic;
   1895 	enum ieee80211_state ostate;
   1896 	struct ieee80211_node *ni;
   1897 	uint32_t tmp, sta[3];
   1898 	uint8_t wcid;
   1899 	int s;
   1900 
   1901 	s = splnet();
   1902 	ostate = ic->ic_state;
   1903 
   1904 	if (ostate == IEEE80211_S_RUN) {
   1905 		/* turn link LED off */
   1906 		run_set_leds(sc, RT2860_LED_RADIO);
   1907 	}
   1908 
   1909 	switch (cmd->state) {
   1910 	case IEEE80211_S_INIT:
   1911 		if (ostate == IEEE80211_S_RUN) {
   1912 			/* abort TSF synchronization */
   1913 			run_read(sc, RT2860_BCN_TIME_CFG, &tmp);
   1914 			run_write(sc, RT2860_BCN_TIME_CFG,
   1915 			    tmp & ~(RT2860_BCN_TX_EN | RT2860_TSF_TIMER_EN |
   1916 			    RT2860_TBTT_TIMER_EN));
   1917 		}
   1918 		break;
   1919 
   1920 	case IEEE80211_S_SCAN:
   1921 		run_set_chan(sc, ic->ic_curchan);
   1922 		callout_schedule(&sc->scan_to, hz / 5);
   1923 		break;
   1924 
   1925 	case IEEE80211_S_AUTH:
   1926 	case IEEE80211_S_ASSOC:
   1927 		run_set_chan(sc, ic->ic_curchan);
   1928 		break;
   1929 
   1930 	case IEEE80211_S_RUN:
   1931 		run_set_chan(sc, ic->ic_curchan);
   1932 
   1933 		ni = ic->ic_bss;
   1934 
   1935 		if (ic->ic_opmode != IEEE80211_M_MONITOR) {
   1936 			run_updateslot(ifp);
   1937 			run_enable_mrr(sc);
   1938 			run_set_txpreamble(sc);
   1939 			run_set_basicrates(sc);
   1940 			run_set_bssid(sc, ni->ni_bssid);
   1941 		}
   1942 #ifndef IEEE80211_STA_ONLY
   1943 		if (ic->ic_opmode == IEEE80211_M_HOSTAP ||
   1944 		    ic->ic_opmode == IEEE80211_M_IBSS)
   1945 			(void)run_setup_beacon(sc);
   1946 #endif
   1947 		if (ic->ic_opmode == IEEE80211_M_STA) {
   1948 			/* add BSS entry to the WCID table */
   1949 			wcid = RUN_AID2WCID(ni->ni_associd);
   1950 			run_write_region_1(sc, RT2860_WCID_ENTRY(wcid),
   1951 			    ni->ni_macaddr, IEEE80211_ADDR_LEN);
   1952 
   1953 			/* fake a join to init the tx rate */
   1954 			run_newassoc(ni, 1);
   1955 		}
   1956 		if (ic->ic_opmode != IEEE80211_M_MONITOR) {
   1957 			run_enable_tsf_sync(sc);
   1958 
   1959 			/* clear statistic registers used by AMRR */
   1960 			run_read_region_1(sc, RT2860_TX_STA_CNT0,
   1961 			    (uint8_t *)sta, sizeof(sta));
   1962 			/* start calibration timer */
   1963 			callout_schedule(&sc->calib_to, hz);
   1964 		}
   1965 
   1966 		/* turn link LED on */
   1967 		run_set_leds(sc, RT2860_LED_RADIO |
   1968 		    (IEEE80211_IS_CHAN_2GHZ(ic->ic_curchan) ?
   1969 		     RT2860_LED_LINK_2GHZ : RT2860_LED_LINK_5GHZ));
   1970 		break;
   1971 	}
   1972 	(void)sc->sc_newstate(ic, cmd->state, cmd->arg);
   1973 	splx(s);
   1974 }
   1975 
   1976 static int
   1977 run_updateedca(struct ieee80211com *ic)
   1978 {
   1979 
   1980 	/* do it in a process context */
   1981 	run_do_async(ic->ic_ifp->if_softc, run_updateedca_cb, NULL, 0);
   1982 	return 0;
   1983 }
   1984 
   1985 /* ARGSUSED */
   1986 static void
   1987 run_updateedca_cb(struct run_softc *sc, void *arg)
   1988 {
   1989 	struct ieee80211com *ic = &sc->sc_ic;
   1990 	int s, aci;
   1991 
   1992 	s = splnet();
   1993 	/* update MAC TX configuration registers */
   1994 	for (aci = 0; aci < WME_NUM_AC; aci++) {
   1995 		run_write(sc, RT2860_EDCA_AC_CFG(aci),
   1996 		    ic->ic_wme.wme_params[aci].wmep_logcwmax << 16 |
   1997 		    ic->ic_wme.wme_params[aci].wmep_logcwmin << 12 |
   1998 		    ic->ic_wme.wme_params[aci].wmep_aifsn  <<  8 |
   1999 		    ic->ic_wme.wme_params[aci].wmep_txopLimit);
   2000 	}
   2001 
   2002 	/* update SCH/DMA registers too */
   2003 	run_write(sc, RT2860_WMM_AIFSN_CFG,
   2004 	    ic->ic_wme.wme_params[WME_AC_VO].wmep_aifsn  << 12 |
   2005 	    ic->ic_wme.wme_params[WME_AC_VI].wmep_aifsn  <<  8 |
   2006 	    ic->ic_wme.wme_params[WME_AC_BK].wmep_aifsn  <<  4 |
   2007 	    ic->ic_wme.wme_params[WME_AC_BE].wmep_aifsn);
   2008 	run_write(sc, RT2860_WMM_CWMIN_CFG,
   2009 	    ic->ic_wme.wme_params[WME_AC_VO].wmep_logcwmin << 12 |
   2010 	    ic->ic_wme.wme_params[WME_AC_VI].wmep_logcwmin <<  8 |
   2011 	    ic->ic_wme.wme_params[WME_AC_BK].wmep_logcwmin <<  4 |
   2012 	    ic->ic_wme.wme_params[WME_AC_BE].wmep_logcwmin);
   2013 	run_write(sc, RT2860_WMM_CWMAX_CFG,
   2014 	    ic->ic_wme.wme_params[WME_AC_VO].wmep_logcwmax << 12 |
   2015 	    ic->ic_wme.wme_params[WME_AC_VI].wmep_logcwmax <<  8 |
   2016 	    ic->ic_wme.wme_params[WME_AC_BK].wmep_logcwmax <<  4 |
   2017 	    ic->ic_wme.wme_params[WME_AC_BE].wmep_logcwmax);
   2018 	run_write(sc, RT2860_WMM_TXOP0_CFG,
   2019 	    ic->ic_wme.wme_params[WME_AC_BK].wmep_txopLimit << 16 |
   2020 	    ic->ic_wme.wme_params[WME_AC_BE].wmep_txopLimit);
   2021 	run_write(sc, RT2860_WMM_TXOP1_CFG,
   2022 	    ic->ic_wme.wme_params[WME_AC_VO].wmep_txopLimit << 16 |
   2023 	    ic->ic_wme.wme_params[WME_AC_VI].wmep_txopLimit);
   2024 	splx(s);
   2025 }
   2026 
   2027 #ifdef RUN_HWCRYPTO
   2028 static int
   2029 run_set_key(struct ieee80211com *ic, const struct ieee80211_key *k,
   2030     const uint8_t *mac)
   2031 {
   2032 	struct run_softc *sc = ic->ic_ifp->if_softc;
   2033 	struct ieee80211_node *ni = ic->ic_bss;
   2034 	struct run_cmd_key cmd;
   2035 
   2036 	/* do it in a process context */
   2037 	cmd.key = *k;
   2038 	cmd.associd = (ni != NULL) ? ni->ni_associd : 0;
   2039 	run_do_async(sc, run_set_key_cb, &cmd, sizeof(cmd));
   2040 	return 1;
   2041 }
   2042 
   2043 static void
   2044 run_set_key_cb(struct run_softc *sc, void *arg)
   2045 {
   2046 #ifndef IEEE80211_STA_ONLY
   2047 	struct ieee80211com *ic = &sc->sc_ic;
   2048 #endif
   2049 	struct run_cmd_key *cmd = arg;
   2050 	struct ieee80211_key *k = &cmd->key;
   2051 	uint32_t attr;
   2052 	uint16_t base;
   2053 	uint8_t mode, wcid, iv[8];
   2054 
   2055 	/* map net80211 cipher to RT2860 security mode */
   2056 	switch (k->wk_cipher->ic_cipher) {
   2057 	case IEEE80211_CIPHER_WEP:
   2058 		k->wk_flags |= IEEE80211_KEY_GROUP; /* XXX */
   2059 		if (k->wk_keylen == 5)
   2060 			mode = RT2860_MODE_WEP40;
   2061 		else
   2062 			mode = RT2860_MODE_WEP104;
   2063 		break;
   2064 	case IEEE80211_CIPHER_TKIP:
   2065 		mode = RT2860_MODE_TKIP;
   2066 		break;
   2067 	case IEEE80211_CIPHER_AES_CCM:
   2068 		mode = RT2860_MODE_AES_CCMP;
   2069 		break;
   2070 	default:
   2071 		return;
   2072 	}
   2073 
   2074 	if (k->wk_flags & IEEE80211_KEY_GROUP) {
   2075 		wcid = 0;	/* NB: update WCID0 for group keys */
   2076 		base = RT2860_SKEY(0, k->wk_keyix);
   2077 	} else {
   2078 		wcid = RUN_AID2WCID(cmd->associd);
   2079 		base = RT2860_PKEY(wcid);
   2080 	}
   2081 
   2082 	if (k->wk_cipher->ic_cipher == IEEE80211_CIPHER_TKIP) {
   2083 		run_write_region_1(sc, base, k->wk_key, 16);
   2084 #ifndef IEEE80211_STA_ONLY
   2085 		if (ic->ic_opmode == IEEE80211_M_HOSTAP) {
   2086 			run_write_region_1(sc, base + 16, &k->wk_key[16], 8);
   2087 			run_write_region_1(sc, base + 24, &k->wk_key[24], 8);
   2088 		} else
   2089 #endif
   2090 		{
   2091 			run_write_region_1(sc, base + 16, &k->wk_key[24], 8);
   2092 			run_write_region_1(sc, base + 24, &k->wk_key[16], 8);
   2093 		}
   2094 	} else {
   2095 		/* roundup len to 16-bit: XXX fix write_region_1() instead */
   2096 		run_write_region_1(sc, base, k->wk_key,
   2097 		    (k->wk_keylen + 1) & ~1);
   2098 	}
   2099 
   2100 	if (!(k->wk_flags & IEEE80211_KEY_GROUP) ||
   2101 	    (k->wk_flags & IEEE80211_KEY_XMIT)) {
   2102 		/* set initial packet number in IV+EIV */
   2103 		if (k->wk_cipher->ic_cipher == IEEE80211_CIPHER_WEP) {
   2104 			memset(iv, 0, sizeof(iv));
   2105 			iv[3] = sc->sc_ic.ic_crypto.cs_def_txkey << 6;
   2106 		} else {
   2107 			if (k->wk_cipher->ic_cipher == IEEE80211_CIPHER_TKIP) {
   2108 				iv[0] = k->wk_keytsc >> 8;
   2109 				iv[1] = (iv[0] | 0x20) & 0x7f;
   2110 				iv[2] = k->wk_keytsc;
   2111 			} else /* CCMP */ {
   2112 				iv[0] = k->wk_keytsc;
   2113 				iv[1] = k->wk_keytsc >> 8;
   2114 				iv[2] = 0;
   2115 			}
   2116 			iv[3] = k->wk_keyix << 6 | IEEE80211_WEP_EXTIV;
   2117 			iv[4] = k->wk_keytsc >> 16;
   2118 			iv[5] = k->wk_keytsc >> 24;
   2119 			iv[6] = k->wk_keytsc >> 32;
   2120 			iv[7] = k->wk_keytsc >> 40;
   2121 		}
   2122 		run_write_region_1(sc, RT2860_IVEIV(wcid), iv, 8);
   2123 	}
   2124 
   2125 	if (k->wk_flags & IEEE80211_KEY_GROUP) {
   2126 		/* install group key */
   2127 		run_read(sc, RT2860_SKEY_MODE_0_7, &attr);
   2128 		attr &= ~(0xf << (k->wk_keyix * 4));
   2129 		attr |= mode << (k->wk_keyix * 4);
   2130 		run_write(sc, RT2860_SKEY_MODE_0_7, attr);
   2131 	} else {
   2132 		/* install pairwise key */
   2133 		run_read(sc, RT2860_WCID_ATTR(wcid), &attr);
   2134 		attr = (attr & ~0xf) | (mode << 1) | RT2860_RX_PKEY_EN;
   2135 		run_write(sc, RT2860_WCID_ATTR(wcid), attr);
   2136 	}
   2137 }
   2138 
   2139 static int
   2140 run_delete_key(struct ieee80211com *ic, const struct ieee80211_key *k)
   2141 {
   2142 	struct run_softc *sc = ic->ic_ifp->if_softc;
   2143 	struct ieee80211_node *ni = ic->ic_bss;
   2144 	struct run_cmd_key cmd;
   2145 
   2146 	/* do it in a process context */
   2147 	cmd.key = *k;
   2148 	cmd.associd = (ni != NULL) ? ni->ni_associd : 0;
   2149 	run_do_async(sc, run_delete_key_cb, &cmd, sizeof(cmd));
   2150 	return 1;
   2151 }
   2152 
   2153 static void
   2154 run_delete_key_cb(struct run_softc *sc, void *arg)
   2155 {
   2156 	struct run_cmd_key *cmd = arg;
   2157 	struct ieee80211_key *k = &cmd->key;
   2158 	uint32_t attr;
   2159 	uint8_t wcid;
   2160 
   2161 	if (k->wk_cipher->ic_cipher == IEEE80211_CIPHER_WEP)
   2162 		k->wk_flags |= IEEE80211_KEY_GROUP; /* XXX */
   2163 
   2164 	if (k->wk_flags & IEEE80211_KEY_GROUP) {
   2165 		/* remove group key */
   2166 		run_read(sc, RT2860_SKEY_MODE_0_7, &attr);
   2167 		attr &= ~(0xf << (k->wk_keyix * 4));
   2168 		run_write(sc, RT2860_SKEY_MODE_0_7, attr);
   2169 
   2170 	} else {
   2171 		/* remove pairwise key */
   2172 		wcid = RUN_AID2WCID(cmd->associd);
   2173 		run_read(sc, RT2860_WCID_ATTR(wcid), &attr);
   2174 		attr &= ~0xf;
   2175 		run_write(sc, RT2860_WCID_ATTR(wcid), attr);
   2176 	}
   2177 }
   2178 #endif
   2179 
   2180 static void
   2181 run_calibrate_to(void *arg)
   2182 {
   2183 
   2184 	/* do it in a process context */
   2185 	run_do_async(arg, run_calibrate_cb, NULL, 0);
   2186 	/* next timeout will be rescheduled in the calibration task */
   2187 }
   2188 
   2189 /* ARGSUSED */
   2190 static void
   2191 run_calibrate_cb(struct run_softc *sc, void *arg)
   2192 {
   2193 	struct ifnet *ifp = &sc->sc_if;
   2194 	uint32_t sta[3];
   2195 	int s, error;
   2196 
   2197 	/* read statistic counters (clear on read) and update AMRR state */
   2198 	error = run_read_region_1(sc, RT2860_TX_STA_CNT0, (uint8_t *)sta,
   2199 	    sizeof(sta));
   2200 	if (error != 0)
   2201 		goto skip;
   2202 
   2203 	DPRINTF(("retrycnt=%d txcnt=%d failcnt=%d\n",
   2204 	    le32toh(sta[1]) >> 16, le32toh(sta[1]) & 0xffff,
   2205 	    le32toh(sta[0]) & 0xffff));
   2206 
   2207 	s = splnet();
   2208 	/* count failed TX as errors */
   2209 	if_statadd(ifp, if_oerrors, le32toh(sta[0]) & 0xffff);
   2210 
   2211 	sc->amn.amn_retrycnt =
   2212 	    (le32toh(sta[0]) & 0xffff) +	/* failed TX count */
   2213 	    (le32toh(sta[1]) >> 16);		/* TX retransmission count */
   2214 
   2215 	sc->amn.amn_txcnt =
   2216 	    sc->amn.amn_retrycnt +
   2217 	    (le32toh(sta[1]) & 0xffff);		/* successful TX count */
   2218 
   2219 	ieee80211_amrr_choose(&sc->amrr, sc->sc_ic.ic_bss, &sc->amn);
   2220 	splx(s);
   2221 
   2222 skip:	callout_schedule(&sc->calib_to, hz);
   2223 }
   2224 
   2225 static void
   2226 run_newassoc(struct ieee80211_node *ni, int isnew)
   2227 {
   2228 	struct run_softc *sc = ni->ni_ic->ic_ifp->if_softc;
   2229 	struct run_node *rn = (void *)ni;
   2230 	struct ieee80211_rateset *rs = &ni->ni_rates;
   2231 	uint8_t rate;
   2232 	int ridx, i, j;
   2233 
   2234 	DPRINTF(("new assoc isnew=%d addr=%s\n",
   2235 	    isnew, ether_sprintf(ni->ni_macaddr)));
   2236 
   2237 	ieee80211_amrr_node_init(&sc->amrr, &sc->amn);
   2238 	/* start at lowest available bit-rate, AMRR will raise */
   2239 	ni->ni_txrate = 0;
   2240 
   2241 	for (i = 0; i < rs->rs_nrates; i++) {
   2242 		rate = rs->rs_rates[i] & IEEE80211_RATE_VAL;
   2243 		/* convert 802.11 rate to hardware rate index */
   2244 		for (ridx = 0; ridx < RT2860_RIDX_MAX; ridx++)
   2245 			if (rt2860_rates[ridx].rate == rate)
   2246 				break;
   2247 		rn->ridx[i] = ridx;
   2248 		/* determine rate of control response frames */
   2249 		for (j = i; j >= 0; j--) {
   2250 			if ((rs->rs_rates[j] & IEEE80211_RATE_BASIC) &&
   2251 			    rt2860_rates[rn->ridx[i]].phy ==
   2252 			    rt2860_rates[rn->ridx[j]].phy)
   2253 				break;
   2254 		}
   2255 		if (j >= 0) {
   2256 			rn->ctl_ridx[i] = rn->ridx[j];
   2257 		} else {
   2258 			/* no basic rate found, use mandatory one */
   2259 			rn->ctl_ridx[i] = rt2860_rates[ridx].ctl_ridx;
   2260 		}
   2261 		DPRINTF(("rate=0x%02x ridx=%d ctl_ridx=%d\n",
   2262 		    rs->rs_rates[i], rn->ridx[i], rn->ctl_ridx[i]));
   2263 	}
   2264 }
   2265 
   2266 /*
   2267  * Return the Rx chain with the highest RSSI for a given frame.
   2268  */
   2269 static __inline uint8_t
   2270 run_maxrssi_chain(struct run_softc *sc, const struct rt2860_rxwi *rxwi)
   2271 {
   2272 	uint8_t rxchain = 0;
   2273 
   2274 	if (sc->nrxchains > 1) {
   2275 		if (rxwi->rssi[1] > rxwi->rssi[rxchain])
   2276 			rxchain = 1;
   2277 		if (sc->nrxchains > 2)
   2278 			if (rxwi->rssi[2] > rxwi->rssi[rxchain])
   2279 				rxchain = 2;
   2280 	}
   2281 	return rxchain;
   2282 }
   2283 
   2284 static void
   2285 run_rx_frame(struct run_softc *sc, uint8_t *buf, int dmalen)
   2286 {
   2287 	struct ieee80211com *ic = &sc->sc_ic;
   2288 	struct ifnet *ifp = &sc->sc_if;
   2289 	struct ieee80211_frame *wh;
   2290 	struct ieee80211_node *ni;
   2291 	struct rt2870_rxd *rxd;
   2292 	struct rt2860_rxwi *rxwi;
   2293 	struct mbuf *m;
   2294 	uint32_t flags;
   2295 	uint16_t len, rxwisize, phy;
   2296 	uint8_t ant, rssi;
   2297 	int s;
   2298 #ifdef RUN_HWCRYPTO
   2299 	int decrypted = 0;
   2300 #endif
   2301 
   2302 	rxwi = (struct rt2860_rxwi *)buf;
   2303 	rxwisize = sizeof(struct rt2860_rxwi);
   2304 	if (sc->mac_ver == 0x5592)
   2305 		rxwisize += sizeof(uint64_t);
   2306 	else if (sc->mac_ver == 0x3593)
   2307 		rxwisize += sizeof(uint32_t);
   2308 	len = le16toh(rxwi->len) & 0xfff;
   2309 	if (__predict_false(len > dmalen)) {
   2310 		DPRINTF(("bad RXWI length %u > %u\n", len, dmalen));
   2311 		return;
   2312 	}
   2313 	/* Rx descriptor is located at the end */
   2314 	rxd = (struct rt2870_rxd *)(buf + dmalen);
   2315 	flags = le32toh(rxd->flags);
   2316 
   2317 	if (__predict_false(flags & (RT2860_RX_CRCERR | RT2860_RX_ICVERR))) {
   2318 		if_statinc(ifp, if_ierrors);
   2319 		return;
   2320 	}
   2321 
   2322 	wh = (struct ieee80211_frame *)(buf + rxwisize);
   2323 
   2324 	if (__predict_false((flags & RT2860_RX_MICERR))) {
   2325 		/* report MIC failures to net80211 for TKIP */
   2326 		ieee80211_notify_michael_failure(ic, wh, 0/* XXX */);
   2327 		if_statinc(ifp, if_ierrors);
   2328 		return;
   2329 	}
   2330 
   2331 	if (flags & RT2860_RX_L2PAD) {
   2332 		u_int hdrlen = ieee80211_hdrspace(ic, wh);
   2333 		memmove((uint8_t *)wh + 2, wh, hdrlen);
   2334 		wh = (struct ieee80211_frame *)((uint8_t *)wh + 2);
   2335 	}
   2336 
   2337 #ifdef RUN_HWCRYPTO
   2338 	if (wh->i_fc[1] & IEEE80211_FC1_WEP) {
   2339 		wh->i_fc[1] &= ~IEEE80211_FC1_WEP;
   2340 		decrypted = 1;
   2341 	}
   2342 #endif
   2343 
   2344 	/* could use m_devget but net80211 wants contig mgmt frames */
   2345 	MGETHDR(m, M_DONTWAIT, MT_DATA);
   2346 	if (__predict_false(m == NULL)) {
   2347 		if_statinc(ifp, if_ierrors);
   2348 		return;
   2349 	}
   2350 	if (len > MHLEN) {
   2351 		if (__predict_true(len <= MCLBYTES))
   2352 			MCLGET(m, M_DONTWAIT);
   2353 		if (__predict_false(!(m->m_flags & M_EXT))) {
   2354 			if_statinc(ifp, if_ierrors);
   2355 			m_freem(m);
   2356 			return;
   2357 		}
   2358 	}
   2359 	/* finalize mbuf */
   2360 	m_set_rcvif(m, ifp);
   2361 	memcpy(mtod(m, void *), wh, len);
   2362 	m->m_pkthdr.len = m->m_len = len;
   2363 
   2364 	ant = run_maxrssi_chain(sc, rxwi);
   2365 	rssi = rxwi->rssi[ant];
   2366 
   2367 	if (__predict_false(sc->sc_drvbpf != NULL)) {
   2368 		struct run_rx_radiotap_header *tap = &sc->sc_rxtap;
   2369 
   2370 		tap->wr_flags = 0;
   2371 		tap->wr_chan_freq = htole16(ic->ic_curchan->ic_freq);
   2372 		tap->wr_chan_flags = htole16(ic->ic_curchan->ic_flags);
   2373 		tap->wr_antsignal = rssi;
   2374 		tap->wr_antenna = ant;
   2375 		tap->wr_dbm_antsignal = run_rssi2dbm(sc, rssi, ant);
   2376 		tap->wr_rate = 2;	/* in case it can't be found below */
   2377 		phy = le16toh(rxwi->phy);
   2378 		switch (phy & RT2860_PHY_MODE) {
   2379 		case RT2860_PHY_CCK:
   2380 			switch ((phy & RT2860_PHY_MCS) & ~RT2860_PHY_SHPRE) {
   2381 			case 0:	tap->wr_rate =   2; break;
   2382 			case 1:	tap->wr_rate =   4; break;
   2383 			case 2:	tap->wr_rate =  11; break;
   2384 			case 3:	tap->wr_rate =  22; break;
   2385 			}
   2386 			if (phy & RT2860_PHY_SHPRE)
   2387 				tap->wr_flags |= IEEE80211_RADIOTAP_F_SHORTPRE;
   2388 			break;
   2389 		case RT2860_PHY_OFDM:
   2390 			switch (phy & RT2860_PHY_MCS) {
   2391 			case 0:	tap->wr_rate =  12; break;
   2392 			case 1:	tap->wr_rate =  18; break;
   2393 			case 2:	tap->wr_rate =  24; break;
   2394 			case 3:	tap->wr_rate =  36; break;
   2395 			case 4:	tap->wr_rate =  48; break;
   2396 			case 5:	tap->wr_rate =  72; break;
   2397 			case 6:	tap->wr_rate =  96; break;
   2398 			case 7:	tap->wr_rate = 108; break;
   2399 			}
   2400 			break;
   2401 		}
   2402 		bpf_mtap2(sc->sc_drvbpf, tap, sc->sc_rxtap_len, m, BPF_D_IN);
   2403 	}
   2404 
   2405 	s = splnet();
   2406 	ni = ieee80211_find_rxnode(ic, (struct ieee80211_frame_min *)wh);
   2407 #ifdef RUN_HWCRYPTO
   2408 	if (decrypted) {
   2409 		uint32_t icflags = ic->ic_flags;
   2410 
   2411 		ic->ic_flags &= ~IEEE80211_F_DROPUNENC; /* XXX */
   2412 		ieee80211_input(ic, m, ni, rssi, 0);
   2413 		ic->ic_flags = icflags;
   2414 	} else
   2415 #endif
   2416 	ieee80211_input(ic, m, ni, rssi, 0);
   2417 
   2418 	/* node is no longer needed */
   2419 	ieee80211_free_node(ni);
   2420 
   2421 	/*
   2422 	 * In HostAP mode, ieee80211_input() will enqueue packets in if_snd
   2423 	 * without calling if_start().
   2424 	 */
   2425 	if (!IFQ_IS_EMPTY(&ifp->if_snd) && !(ifp->if_flags & IFF_OACTIVE))
   2426 		run_start(ifp);
   2427 
   2428 	splx(s);
   2429 }
   2430 
   2431 static void
   2432 run_rxeof(struct usbd_xfer *xfer, void *priv, usbd_status status)
   2433 {
   2434 	struct run_rx_data *data = priv;
   2435 	struct run_softc *sc = data->sc;
   2436 	uint8_t *buf;
   2437 	uint32_t dmalen;
   2438 	int xferlen;
   2439 	uint16_t rxwisize;
   2440 
   2441 	if (__predict_false(sc->sc_flags & RUN_DETACHING))
   2442 		return;
   2443 
   2444 	rxwisize = sizeof(struct rt2860_rxwi);
   2445 	if (sc->mac_ver == 0x5592)
   2446 		rxwisize += sizeof(uint64_t);
   2447 	else if (sc->mac_ver == 0x3593)
   2448 		rxwisize += sizeof(uint32_t);
   2449 
   2450 	if (__predict_false(status != USBD_NORMAL_COMPLETION)) {
   2451 		DPRINTF(("RX status=%s\n", usbd_errstr(status)));
   2452 		if (status == USBD_STALLED)
   2453 			usbd_clear_endpoint_stall_async(sc->rxq.pipeh);
   2454 		if (status != USBD_CANCELLED)
   2455 			goto skip;
   2456 		return;
   2457 	}
   2458 	usbd_get_xfer_status(xfer, NULL, NULL, &xferlen, NULL);
   2459 
   2460 	if (__predict_false(xferlen < (int)(sizeof(uint32_t) +
   2461 	    rxwisize + sizeof(struct rt2870_rxd)))) {
   2462 		DPRINTF(("xfer too short %d\n", xferlen));
   2463 		goto skip;
   2464 	}
   2465 
   2466 	/* HW can aggregate multiple 802.11 frames in a single USB xfer */
   2467 	buf = data->buf;
   2468 	while (xferlen > 8) {
   2469 		dmalen = le32toh(*(uint32_t *)buf) & 0xffff;
   2470 
   2471 		if (__predict_false((dmalen >= (uint32_t)-8) || dmalen == 0 ||
   2472 		    (dmalen & 3) != 0)) {
   2473 			DPRINTF(("bad DMA length %u (%x)\n", dmalen, dmalen));
   2474 			break;
   2475 		}
   2476 		if (__predict_false(dmalen + 8 > (uint32_t)xferlen)) {
   2477 			DPRINTF(("bad DMA length %u > %d\n",
   2478 			    dmalen + 8, xferlen));
   2479 			break;
   2480 		}
   2481 		run_rx_frame(sc, buf + sizeof(uint32_t), dmalen);
   2482 		buf += dmalen + 8;
   2483 		xferlen -= dmalen + 8;
   2484 	}
   2485 
   2486 skip:	/* setup a new transfer */
   2487 	usbd_setup_xfer(xfer, data, data->buf, RUN_MAX_RXSZ,
   2488 	    USBD_SHORT_XFER_OK, USBD_NO_TIMEOUT, run_rxeof);
   2489 	status = usbd_transfer(xfer);
   2490 	if (status != USBD_NORMAL_COMPLETION &&
   2491 	    status != USBD_IN_PROGRESS)
   2492 		device_printf(sc->sc_dev, "requeuing rx failed: %s\n",
   2493 		    usbd_errstr(status));
   2494 }
   2495 
   2496 static void
   2497 run_txeof(struct usbd_xfer *xfer, void *priv, usbd_status status)
   2498 {
   2499 	struct run_tx_data *data = priv;
   2500 	struct run_softc *sc = data->sc;
   2501 	struct run_tx_ring *txq = &sc->txq[data->qid];
   2502 	struct ifnet *ifp = &sc->sc_if;
   2503 	int s;
   2504 
   2505 	s = splnet();
   2506 	txq->queued--;
   2507 	sc->qfullmsk &= ~(1 << data->qid);
   2508 
   2509 	if (__predict_false(status != USBD_NORMAL_COMPLETION)) {
   2510 		if (status == USBD_NOT_STARTED || status == USBD_CANCELLED)
   2511 			return;
   2512 
   2513 		DPRINTF(("%s: usb error on tx: %s\n",
   2514 			device_xname(sc->sc_dev), usbd_errstr(status)));
   2515 		if (status == USBD_STALLED)
   2516 			usbd_clear_endpoint_stall_async(txq->pipeh);
   2517 		if_statinc(ifp, if_oerrors);
   2518 		splx(s);
   2519 		return;
   2520 	}
   2521 
   2522 	sc->sc_tx_timer = 0;
   2523 	if_statinc(ifp, if_opackets);
   2524 	ifp->if_flags &= ~IFF_OACTIVE;
   2525 	run_start(ifp);
   2526 	splx(s);
   2527 }
   2528 
   2529 static int
   2530 run_tx(struct run_softc *sc, struct mbuf *m, struct ieee80211_node *ni)
   2531 {
   2532 	struct ieee80211com *ic = &sc->sc_ic;
   2533 	struct run_node *rn = (void *)ni;
   2534 	struct ieee80211_frame *wh;
   2535 #ifndef RUN_HWCRYPTO
   2536 	struct ieee80211_key *k;
   2537 #endif
   2538 	struct run_tx_ring *ring;
   2539 	struct run_tx_data *data;
   2540 	struct rt2870_txd *txd;
   2541 	struct rt2860_txwi *txwi;
   2542 	uint16_t qos, dur, mcs;
   2543 	uint16_t txwisize;
   2544 	uint8_t type, tid, qid;
   2545 	int hasqos, ridx, ctl_ridx, xferlen;
   2546 	uint8_t pad;
   2547 	usbd_status status;
   2548 
   2549 	wh = mtod(m, struct ieee80211_frame *);
   2550 
   2551 #ifndef RUN_HWCRYPTO
   2552 	if (wh->i_fc[1] & IEEE80211_FC1_WEP) {
   2553 		k = ieee80211_crypto_encap(ic, ni, m);
   2554 		if (k == NULL) {
   2555 			m_freem(m);
   2556 			return ENOBUFS;
   2557 		}
   2558 
   2559 		/* packet header may have moved, reset our local pointer */
   2560 		wh = mtod(m, struct ieee80211_frame *);
   2561 	}
   2562 #endif
   2563 	type = wh->i_fc[0] & IEEE80211_FC0_TYPE_MASK;
   2564 
   2565 	if ((hasqos = ieee80211_has_qos(wh))) {
   2566 		qos = ((struct ieee80211_qosframe *)wh)->i_qos[0];
   2567 		tid = qos & IEEE80211_QOS_TID;
   2568 		qid = TID_TO_WME_AC(tid);
   2569 	} else {
   2570 		qos = 0;
   2571 		tid = 0;
   2572 		qid = WME_AC_BE;
   2573 	}
   2574 	ring = &sc->txq[qid];
   2575 	data = &ring->data[ring->cur];
   2576 
   2577 	/* pickup a rate index */
   2578 	if (IEEE80211_IS_MULTICAST(wh->i_addr1) ||
   2579 	    type != IEEE80211_FC0_TYPE_DATA) {
   2580 		ridx = (ic->ic_curmode == IEEE80211_MODE_11A) ?
   2581 		    RT2860_RIDX_OFDM6 : RT2860_RIDX_CCK1;
   2582 		ctl_ridx = rt2860_rates[ridx].ctl_ridx;
   2583 	} else if (ic->ic_fixed_rate != IEEE80211_FIXED_RATE_NONE) {
   2584 		ridx = sc->fixed_ridx;
   2585 		ctl_ridx = rt2860_rates[ridx].ctl_ridx;
   2586 	} else {
   2587 		ridx = rn->ridx[ni->ni_txrate];
   2588 		ctl_ridx = rn->ctl_ridx[ni->ni_txrate];
   2589 	}
   2590 
   2591 	/* get MCS code from rate index */
   2592 	mcs = rt2860_rates[ridx].mcs;
   2593 
   2594 	txwisize = sizeof(struct rt2860_txwi);
   2595 	if (sc->mac_ver == 0x5592)
   2596 		txwisize += sizeof(uint32_t);
   2597 	xferlen = txwisize + m->m_pkthdr.len;
   2598 
   2599 	/* roundup to 32-bit alignment */
   2600 	xferlen = (xferlen + 3) & ~3;
   2601 
   2602 	txd = (struct rt2870_txd *)data->buf;
   2603 	txd->flags = RT2860_TX_QSEL_EDCA;
   2604 	txd->len = htole16(xferlen);
   2605 
   2606 	/*
   2607 	 * Ether both are true or both are false, the header
   2608 	 * are nicely aligned to 32-bit. So, no L2 padding.
   2609 	 */
   2610 	if (IEEE80211_HAS_ADDR4(wh) == IEEE80211_QOS_HAS_SEQ(wh))
   2611 		pad = 0;
   2612 	else
   2613 		pad = 2;
   2614 
   2615 	/* setup TX Wireless Information */
   2616 	txwi = (struct rt2860_txwi *)(txd + 1);
   2617 	txwi->flags = 0;
   2618 	txwi->xflags = hasqos ? 0 : RT2860_TX_NSEQ;
   2619 	txwi->wcid = (type == IEEE80211_FC0_TYPE_DATA) ?
   2620 	    RUN_AID2WCID(ni->ni_associd) : 0xff;
   2621 	txwi->len = htole16(m->m_pkthdr.len - pad);
   2622 	if (rt2860_rates[ridx].phy == IEEE80211_T_DS) {
   2623 		txwi->phy = htole16(RT2860_PHY_CCK);
   2624 		if (ridx != RT2860_RIDX_CCK1 &&
   2625 		    (ic->ic_flags & IEEE80211_F_SHPREAMBLE))
   2626 			mcs |= RT2860_PHY_SHPRE;
   2627 	} else
   2628 		mcs |= RT2860_PHY_OFDM;
   2629 	txwi->phy = htole16(mcs);
   2630 
   2631 	txwi->txop = RT2860_TX_TXOP_BACKOFF;
   2632 
   2633 	if (!IEEE80211_IS_MULTICAST(wh->i_addr1) &&
   2634 	    (!hasqos || (qos & IEEE80211_QOS_ACKPOLICY) !=
   2635 	    IEEE80211_QOS_ACKPOLICY_NOACK)) {
   2636 		txwi->xflags |= RT2860_TX_ACK;
   2637 		if (ic->ic_flags & IEEE80211_F_SHPREAMBLE)
   2638 			dur = rt2860_rates[ctl_ridx].sp_ack_dur;
   2639 		else
   2640 			dur = rt2860_rates[ctl_ridx].lp_ack_dur;
   2641 		*(uint16_t *)wh->i_dur = htole16(dur);
   2642 	}
   2643 
   2644 #ifndef IEEE80211_STA_ONLY
   2645 	/* ask MAC to insert timestamp into probe responses */
   2646 	if ((wh->i_fc[0] &
   2647 	    (IEEE80211_FC0_TYPE_MASK | IEEE80211_FC0_SUBTYPE_MASK)) ==
   2648 	    (IEEE80211_FC0_TYPE_MGT | IEEE80211_FC0_SUBTYPE_PROBE_RESP))
   2649 	    /* NOTE: beacons do not pass through tx_data() */
   2650 		txwi->flags |= RT2860_TX_TS;
   2651 #endif
   2652 
   2653 	if (__predict_false(sc->sc_drvbpf != NULL)) {
   2654 		struct run_tx_radiotap_header *tap = &sc->sc_txtap;
   2655 
   2656 		tap->wt_flags = 0;
   2657 		tap->wt_rate = rt2860_rates[ridx].rate;
   2658 		tap->wt_chan_freq = htole16(ic->ic_curchan->ic_freq);
   2659 		tap->wt_chan_flags = htole16(ic->ic_curchan->ic_flags);
   2660 		tap->wt_hwqueue = qid;
   2661 		if (mcs & RT2860_PHY_SHPRE)
   2662 			tap->wt_flags |= IEEE80211_RADIOTAP_F_SHORTPRE;
   2663 
   2664 		bpf_mtap2(sc->sc_drvbpf, tap, sc->sc_txtap_len, m, BPF_D_OUT);
   2665 	}
   2666 
   2667 	m_copydata(m, 0, m->m_pkthdr.len, ((uint8_t *)txwi) + txwisize);
   2668 	m_freem(m);
   2669 
   2670 	xferlen += sizeof(*txd) + 4;
   2671 
   2672 	usbd_setup_xfer(data->xfer, data, data->buf, xferlen,
   2673 	    USBD_FORCE_SHORT_XFER, RUN_TX_TIMEOUT, run_txeof);
   2674 	status = usbd_transfer(data->xfer);
   2675 	if (__predict_false(status != USBD_IN_PROGRESS &&
   2676 	    status != USBD_NORMAL_COMPLETION)) {
   2677 		device_printf(sc->sc_dev, "queuing tx failed: %s\n",
   2678 		    usbd_errstr(status));
   2679 		return EIO;
   2680 	}
   2681 
   2682 	ieee80211_free_node(ni);
   2683 
   2684 	ring->cur = (ring->cur + 1) % RUN_TX_RING_COUNT;
   2685 	if (++ring->queued >= RUN_TX_RING_COUNT)
   2686 		sc->qfullmsk |= 1 << qid;
   2687 
   2688 	return 0;
   2689 }
   2690 
   2691 static void
   2692 run_start(struct ifnet *ifp)
   2693 {
   2694 	struct run_softc *sc = ifp->if_softc;
   2695 	struct ieee80211com *ic = &sc->sc_ic;
   2696 	struct ether_header *eh;
   2697 	struct ieee80211_node *ni;
   2698 	struct mbuf *m;
   2699 
   2700 	if ((ifp->if_flags & (IFF_RUNNING | IFF_OACTIVE)) != IFF_RUNNING)
   2701 		return;
   2702 
   2703 	for (;;) {
   2704 		if (sc->qfullmsk != 0) {
   2705 			ifp->if_flags |= IFF_OACTIVE;
   2706 			break;
   2707 		}
   2708 		/* send pending management frames first */
   2709 		IF_DEQUEUE(&ic->ic_mgtq, m);
   2710 		if (m != NULL) {
   2711 			ni = M_GETCTX(m, struct ieee80211_node *);
   2712 			M_CLEARCTX(m);
   2713 			goto sendit;
   2714 		}
   2715 		if (ic->ic_state != IEEE80211_S_RUN)
   2716 			break;
   2717 
   2718 		/* encapsulate and send data frames */
   2719 		IFQ_DEQUEUE(&ifp->if_snd, m);
   2720 		if (m == NULL)
   2721 			break;
   2722 		if (m->m_len < (int)sizeof(*eh) &&
   2723 		    (m = m_pullup(m, sizeof(*eh))) == NULL) {
   2724 			if_statinc(ifp, if_oerrors);
   2725 			continue;
   2726 		}
   2727 
   2728 		eh = mtod(m, struct ether_header *);
   2729 		ni = ieee80211_find_txnode(ic, eh->ether_dhost);
   2730 		if (ni == NULL) {
   2731 			m_freem(m);
   2732 			if_statinc(ifp, if_oerrors);
   2733 			continue;
   2734 		}
   2735 
   2736 		bpf_mtap(ifp, m, BPF_D_OUT);
   2737 
   2738 		if ((m = ieee80211_encap(ic, m, ni)) == NULL) {
   2739 			ieee80211_free_node(ni);
   2740 			if_statinc(ifp, if_oerrors);
   2741 			continue;
   2742 		}
   2743 sendit:
   2744 		bpf_mtap3(ic->ic_rawbpf, m, BPF_D_OUT);
   2745 
   2746 		if (run_tx(sc, m, ni) != 0) {
   2747 			ieee80211_free_node(ni);
   2748 			if_statinc(ifp, if_oerrors);
   2749 			continue;
   2750 		}
   2751 
   2752 		sc->sc_tx_timer = 5;
   2753 		ifp->if_timer = 1;
   2754 	}
   2755 }
   2756 
   2757 static void
   2758 run_watchdog(struct ifnet *ifp)
   2759 {
   2760 	struct run_softc *sc = ifp->if_softc;
   2761 	struct ieee80211com *ic = &sc->sc_ic;
   2762 
   2763 	ifp->if_timer = 0;
   2764 
   2765 	if (sc->sc_tx_timer > 0) {
   2766 		if (--sc->sc_tx_timer == 0) {
   2767 			device_printf(sc->sc_dev, "device timeout\n");
   2768 			/* run_init(ifp); XXX needs a process context! */
   2769 			if_statinc(ifp, if_oerrors);
   2770 			return;
   2771 		}
   2772 		ifp->if_timer = 1;
   2773 	}
   2774 
   2775 	ieee80211_watchdog(ic);
   2776 }
   2777 
   2778 static int
   2779 run_ioctl(struct ifnet *ifp, u_long cmd, void *data)
   2780 {
   2781 	struct run_softc *sc = ifp->if_softc;
   2782 	struct ieee80211com *ic = &sc->sc_ic;
   2783 	int s, error = 0;
   2784 
   2785 	s = splnet();
   2786 
   2787 	switch (cmd) {
   2788 	case SIOCSIFFLAGS:
   2789 		if ((error = ifioctl_common(ifp, cmd, data)) != 0)
   2790 			break;
   2791 		switch (ifp->if_flags & (IFF_UP|IFF_RUNNING)) {
   2792 		case IFF_UP|IFF_RUNNING:
   2793 			break;
   2794 		case IFF_UP:
   2795 			run_init(ifp);
   2796 			break;
   2797 		case IFF_RUNNING:
   2798 			run_stop(ifp, 1);
   2799 			break;
   2800 		case 0:
   2801 			break;
   2802 		}
   2803 		break;
   2804 
   2805 	case SIOCADDMULTI:
   2806 	case SIOCDELMULTI:
   2807 		if ((error = ether_ioctl(ifp, cmd, data)) == ENETRESET) {
   2808 			/* setup multicast filter, etc */
   2809 			error = 0;
   2810 		}
   2811 		break;
   2812 
   2813 	default:
   2814 		error = ieee80211_ioctl(ic, cmd, data);
   2815 		break;
   2816 	}
   2817 
   2818 	if (error == ENETRESET) {
   2819 		if ((ifp->if_flags & (IFF_UP | IFF_RUNNING)) ==
   2820 		    (IFF_UP | IFF_RUNNING)) {
   2821 			run_init(ifp);
   2822 		}
   2823 		error = 0;
   2824 	}
   2825 
   2826 	splx(s);
   2827 
   2828 	return error;
   2829 }
   2830 
   2831 static void
   2832 run_select_chan_group(struct run_softc *sc, int group)
   2833 {
   2834 	uint32_t tmp;
   2835 	uint8_t agc;
   2836 
   2837 	run_bbp_write(sc, 62, 0x37 - sc->lna[group]);
   2838 	run_bbp_write(sc, 63, 0x37 - sc->lna[group]);
   2839 	run_bbp_write(sc, 64, 0x37 - sc->lna[group]);
   2840 	if (sc->mac_ver < 0x3572)
   2841 		run_bbp_write(sc, 86, 0x00);
   2842 
   2843 	if (sc->mac_ver == 0x3593) {
   2844 		run_bbp_write(sc, 77, 0x98);
   2845 		run_bbp_write(sc, 83, (group == 0) ? 0x8a : 0x9a);
   2846 	}
   2847 
   2848 	if (group == 0) {
   2849 		if (sc->ext_2ghz_lna) {
   2850 			if (sc->mac_ver >= 0x5390)
   2851 				run_bbp_write(sc, 75, 0x52);
   2852 			else {
   2853 				run_bbp_write(sc, 82, 0x62);
   2854 				run_bbp_write(sc, 75, 0x46);
   2855 			}
   2856 		} else {
   2857 			if (sc->mac_ver == 0x5592) {
   2858 				run_bbp_write(sc, 79, 0x1c);
   2859 				run_bbp_write(sc, 80, 0x0e);
   2860 				run_bbp_write(sc, 81, 0x3a);
   2861 				run_bbp_write(sc, 82, 0x62);
   2862 
   2863 				run_bbp_write(sc, 195, 0x80);
   2864 				run_bbp_write(sc, 196, 0xe0);
   2865 				run_bbp_write(sc, 195, 0x81);
   2866 				run_bbp_write(sc, 196, 0x1f);
   2867 				run_bbp_write(sc, 195, 0x82);
   2868 				run_bbp_write(sc, 196, 0x38);
   2869 				run_bbp_write(sc, 195, 0x83);
   2870 				run_bbp_write(sc, 196, 0x32);
   2871 				run_bbp_write(sc, 195, 0x85);
   2872 				run_bbp_write(sc, 196, 0x28);
   2873 				run_bbp_write(sc, 195, 0x86);
   2874 				run_bbp_write(sc, 196, 0x19);
   2875 			} else if (sc->mac_ver >= 0x5390) {
   2876 				run_bbp_write(sc, 75, 0x50);
   2877 			} else {
   2878 				run_bbp_write(sc, 82,
   2879 				    (sc->mac_ver == 0x3593) ? 0x62 : 0x84);
   2880 				run_bbp_write(sc, 75, 0x50);
   2881 			}
   2882 		}
   2883 	} else {
   2884 		if (sc->mac_ver == 0x5592) {
   2885 			run_bbp_write(sc, 79, 0x18);
   2886 			run_bbp_write(sc, 80, 0x08);
   2887 			run_bbp_write(sc, 81, 0x38);
   2888 			run_bbp_write(sc, 82, 0x92);
   2889 
   2890 			run_bbp_write(sc, 195, 0x80);
   2891 			run_bbp_write(sc, 196, 0xf0);
   2892 			run_bbp_write(sc, 195, 0x81);
   2893 			run_bbp_write(sc, 196, 0x1e);
   2894 			run_bbp_write(sc, 195, 0x82);
   2895 			run_bbp_write(sc, 196, 0x28);
   2896 			run_bbp_write(sc, 195, 0x83);
   2897 			run_bbp_write(sc, 196, 0x20);
   2898 			run_bbp_write(sc, 195, 0x85);
   2899 			run_bbp_write(sc, 196, 0x7f);
   2900 			run_bbp_write(sc, 195, 0x86);
   2901 			run_bbp_write(sc, 196, 0x7f);
   2902 		} else if (sc->mac_ver == 0x3572)
   2903 			run_bbp_write(sc, 82, 0x94);
   2904 		else
   2905 			run_bbp_write(sc, 82,
   2906 			    (sc->mac_ver == 0x3593) ? 0x82 : 0xf2);
   2907 		if (sc->ext_5ghz_lna)
   2908 			run_bbp_write(sc, 75, 0x46);
   2909 		else
   2910 			run_bbp_write(sc, 75, 0x50);
   2911 	}
   2912 
   2913 	run_read(sc, RT2860_TX_BAND_CFG, &tmp);
   2914 	tmp &= ~(RT2860_5G_BAND_SEL_N | RT2860_5G_BAND_SEL_P);
   2915 	tmp |= (group == 0) ? RT2860_5G_BAND_SEL_N : RT2860_5G_BAND_SEL_P;
   2916 	run_write(sc, RT2860_TX_BAND_CFG, tmp);
   2917 
   2918 	/* enable appropriate Power Amplifiers and Low Noise Amplifiers */
   2919 	tmp = RT2860_RFTR_EN | RT2860_TRSW_EN | RT2860_LNA_PE0_EN;
   2920 	if (sc->mac_ver == 0x3593)
   2921 		tmp |= RT3593_LNA_PE_G2_EN | RT3593_LNA_PE_A2_EN;
   2922 	if (sc->nrxchains > 1)
   2923 		tmp |= RT2860_LNA_PE1_EN;
   2924 	if (group == 0) {	/* 2GHz */
   2925 		tmp |= RT2860_PA_PE_G0_EN;
   2926 		if (sc->ntxchains > 1)
   2927 			tmp |= RT2860_PA_PE_G1_EN;
   2928 	} else {		/* 5GHz */
   2929 		tmp |= RT2860_PA_PE_A0_EN;
   2930 		if (sc->ntxchains > 1)
   2931 			tmp |= RT2860_PA_PE_A1_EN;
   2932 		if (sc->mac_ver == 0x3593) {
   2933 			if (sc->ntxchains > 2)
   2934 				tmp |= RT3593_PA_PE_G2_EN;
   2935 		}
   2936 	}
   2937 	if (sc->mac_ver == 0x3572) {
   2938 		run_rt3070_rf_write(sc, 8, 0x00);
   2939 		run_write(sc, RT2860_TX_PIN_CFG, tmp);
   2940 		run_rt3070_rf_write(sc, 8, 0x80);
   2941 	} else
   2942 		run_write(sc, RT2860_TX_PIN_CFG, tmp);
   2943 
   2944 	if (sc->mac_ver == 0x5592) {
   2945 		run_bbp_write(sc, 195, 0x8d);
   2946 		run_bbp_write(sc, 196, 0x1a);
   2947 	}
   2948 
   2949 	if (sc->mac_ver == 0x3593) {
   2950 		run_read(sc, RT2860_GPIO_CTRL, &tmp);
   2951 		tmp &= ~0x01010000;
   2952 		if (group == 0)
   2953 			tmp |= 0x00010000;
   2954 		tmp = (tmp & ~0x00009090) | 0x00000090;
   2955 		run_write(sc, RT2860_GPIO_CTRL, tmp);
   2956 	}
   2957 
   2958 	/* set initial AGC value */
   2959 	if (group == 0) {       /* 2GHz band */
   2960 		if (sc->mac_ver >= 0x3070)
   2961 			agc = 0x1c + sc->lna[0] * 2;
   2962 		else
   2963 			agc = 0x2e + sc->lna[0];
   2964 	} else {		/* 5GHz band */
   2965 		if (sc->mac_ver == 0x3572)
   2966 			agc = 0x22 + (sc->lna[group] * 5) / 3;
   2967 		else
   2968 			agc = 0x32 + (sc->lna[group] * 5) / 3;
   2969 	}
   2970 	run_set_agc(sc, agc);
   2971 }
   2972 
   2973 static void
   2974 run_rt2870_set_chan(struct run_softc *sc, u_int chan)
   2975 {
   2976 	const struct rfprog *rfprog = rt2860_rf2850;
   2977 	uint32_t r2, r3, r4;
   2978 	int8_t txpow1, txpow2;
   2979 	int i;
   2980 
   2981 	/* find the settings for this channel (we know it exists) */
   2982 	for (i = 0; rfprog[i].chan != chan; i++);
   2983 
   2984 	r2 = rfprog[i].r2;
   2985 	if (sc->ntxchains == 1)
   2986 		r2 |= 1 << 12;		/* 1T: disable Tx chain 2 */
   2987 	if (sc->nrxchains == 1)
   2988 		r2 |= 1 << 15 | 1 << 4;	/* 1R: disable Rx chains 2 & 3 */
   2989 	else if (sc->nrxchains == 2)
   2990 		r2 |= 1 << 4;		/* 2R: disable Rx chain 3 */
   2991 
   2992 	/* use Tx power values from EEPROM */
   2993 	txpow1 = sc->txpow1[i];
   2994 	txpow2 = sc->txpow2[i];
   2995 	if (chan > 14) {
   2996 		if (txpow1 >= 0)
   2997 			txpow1 = txpow1 << 1 | 1;
   2998 		else
   2999 			txpow1 = (7 + txpow1) << 1;
   3000 		if (txpow2 >= 0)
   3001 			txpow2 = txpow2 << 1 | 1;
   3002 		else
   3003 			txpow2 = (7 + txpow2) << 1;
   3004 	}
   3005 	r3 = rfprog[i].r3 | txpow1 << 7;
   3006 	r4 = rfprog[i].r4 | sc->freq << 13 | txpow2 << 4;
   3007 
   3008 	run_rt2870_rf_write(sc, RT2860_RF1, rfprog[i].r1);
   3009 	run_rt2870_rf_write(sc, RT2860_RF2, r2);
   3010 	run_rt2870_rf_write(sc, RT2860_RF3, r3);
   3011 	run_rt2870_rf_write(sc, RT2860_RF4, r4);
   3012 
   3013 	usbd_delay_ms(sc->sc_udev, 10);
   3014 
   3015 	run_rt2870_rf_write(sc, RT2860_RF1, rfprog[i].r1);
   3016 	run_rt2870_rf_write(sc, RT2860_RF2, r2);
   3017 	run_rt2870_rf_write(sc, RT2860_RF3, r3 | 1);
   3018 	run_rt2870_rf_write(sc, RT2860_RF4, r4);
   3019 
   3020 	usbd_delay_ms(sc->sc_udev, 10);
   3021 
   3022 	run_rt2870_rf_write(sc, RT2860_RF1, rfprog[i].r1);
   3023 	run_rt2870_rf_write(sc, RT2860_RF2, r2);
   3024 	run_rt2870_rf_write(sc, RT2860_RF3, r3);
   3025 	run_rt2870_rf_write(sc, RT2860_RF4, r4);
   3026 }
   3027 
   3028 static void
   3029 run_rt3070_set_chan(struct run_softc *sc, u_int chan)
   3030 {
   3031 	int8_t txpow1, txpow2;
   3032 	uint8_t rf;
   3033 	int i;
   3034 
   3035 	KASSERT(chan >= 1 && chan <= 14);	/* RT3070 is 2GHz only */
   3036 
   3037 	/* find the settings for this channel (we know it exists) */
   3038 	for (i = 0; rt2860_rf2850[i].chan != chan; i++)
   3039 		continue;
   3040 
   3041 	/* use Tx power values from EEPROM */
   3042 	txpow1 = sc->txpow1[i];
   3043 	txpow2 = sc->txpow2[i];
   3044 
   3045 	run_rt3070_rf_write(sc, 2, rt3070_freqs[i].n);
   3046 	run_rt3070_rf_write(sc, 3, rt3070_freqs[i].k);
   3047 	run_rt3070_rf_read(sc, 6, &rf);
   3048 	rf = (rf & ~0x03) | rt3070_freqs[i].r;
   3049 	run_rt3070_rf_write(sc, 6, rf);
   3050 
   3051 	/* set Tx0 power */
   3052 	run_rt3070_rf_read(sc, 12, &rf);
   3053 	rf = (rf & ~0x1f) | txpow1;
   3054 	run_rt3070_rf_write(sc, 12, rf);
   3055 
   3056 	/* set Tx1 power */
   3057 	run_rt3070_rf_read(sc, 13, &rf);
   3058 	rf = (rf & ~0x1f) | txpow2;
   3059 	run_rt3070_rf_write(sc, 13, rf);
   3060 
   3061 	run_rt3070_rf_read(sc, 1, &rf);
   3062 	rf &= ~0xfc;
   3063 	if (sc->ntxchains == 1)
   3064 		rf |= 1 << 7 | 1 << 5;	/* 1T: disable Tx chains 2 & 3 */
   3065 	else if (sc->ntxchains == 2)
   3066 		rf |= 1 << 7;		/* 2T: disable Tx chain 3 */
   3067 	if (sc->nrxchains == 1)
   3068 		rf |= 1 << 6 | 1 << 4;	/* 1R: disable Rx chains 2 & 3 */
   3069 	else if (sc->nrxchains == 2)
   3070 		rf |= 1 << 6;		/* 2R: disable Rx chain 3 */
   3071 	run_rt3070_rf_write(sc, 1, rf);
   3072 
   3073 	/* set RF offset */
   3074 	run_rt3070_rf_read(sc, 23, &rf);
   3075 	rf = (rf & ~0x7f) | sc->freq;
   3076 	run_rt3070_rf_write(sc, 23, rf);
   3077 
   3078 	/* program RF filter */
   3079 	run_rt3070_rf_read(sc, 24, &rf);        /* Tx */
   3080 	rf = (rf & ~0x3f) | sc->rf24_20mhz;
   3081 	run_rt3070_rf_write(sc, 24, rf);
   3082 	run_rt3070_rf_read(sc, 31, &rf);        /* Rx */
   3083 	rf = (rf & ~0x3f) | sc->rf24_20mhz;
   3084 	run_rt3070_rf_write(sc, 31, rf);
   3085 
   3086 	/* enable RF tuning */
   3087 	run_rt3070_rf_read(sc, 7, &rf);
   3088 	run_rt3070_rf_write(sc, 7, rf | 0x01);
   3089 }
   3090 
   3091 static void
   3092 run_rt3572_set_chan(struct run_softc *sc, u_int chan)
   3093 {
   3094 	int8_t txpow1, txpow2;
   3095 	uint32_t tmp;
   3096 	uint8_t rf;
   3097 	int i;
   3098 
   3099 	/* find the settings for this channel (we know it exists) */
   3100 	for (i = 0; rt2860_rf2850[i].chan != chan; i++);
   3101 
   3102 	/* use Tx power values from EEPROM */
   3103 	txpow1 = sc->txpow1[i];
   3104 	txpow2 = sc->txpow2[i];
   3105 
   3106 	if (chan <= 14) {
   3107 		run_bbp_write(sc, 25, sc->bbp25);
   3108 		run_bbp_write(sc, 26, sc->bbp26);
   3109 	} else {
   3110 		/* enable IQ phase correction */
   3111 		run_bbp_write(sc, 25, 0x09);
   3112 		run_bbp_write(sc, 26, 0xff);
   3113 	}
   3114 
   3115 	run_rt3070_rf_write(sc, 2, rt3070_freqs[i].n);
   3116 	run_rt3070_rf_write(sc, 3, rt3070_freqs[i].k);
   3117 	run_rt3070_rf_read(sc, 6, &rf);
   3118 	rf  = (rf & ~0x0f) | rt3070_freqs[i].r;
   3119 	rf |= (chan <= 14) ? 0x08 : 0x04;
   3120 	run_rt3070_rf_write(sc, 6, rf);
   3121 
   3122 	/* set PLL mode */
   3123 	run_rt3070_rf_read(sc, 5, &rf);
   3124 	rf &= ~(0x08 | 0x04);
   3125 	rf |= (chan <= 14) ? 0x04 : 0x08;
   3126 	run_rt3070_rf_write(sc, 5, rf);
   3127 
   3128 	/* set Tx power for chain 0 */
   3129 	if (chan <= 14)
   3130 		rf = 0x60 | txpow1;
   3131 	else
   3132 		rf = 0xe0 | (txpow1 & 0xc) << 1 | (txpow1 & 0x3);
   3133 	run_rt3070_rf_write(sc, 12, rf);
   3134 
   3135 	/* set Tx power for chain 1 */
   3136 	if (chan <= 14)
   3137 		rf = 0x60 | txpow2;
   3138 	else
   3139 		rf = 0xe0 | (txpow2 & 0xc) << 1 | (txpow2 & 0x3);
   3140 	run_rt3070_rf_write(sc, 13, rf);
   3141 
   3142 	/* set Tx/Rx streams */
   3143 	run_rt3070_rf_read(sc, 1, &rf);
   3144 	rf &= ~0xfc;
   3145 	if (sc->ntxchains == 1)
   3146 		rf |= 1 << 7 | 1 << 5;	/* 1T: disable Tx chains 2 & 3 */
   3147 	else if (sc->ntxchains == 2)
   3148 		rf |= 1 << 7;		/* 2T: disable Tx chain 3 */
   3149 	if (sc->nrxchains == 1)
   3150 		rf |= 1 << 6 | 1 << 4;	/* 1R: disable Rx chains 2 & 3 */
   3151 	else if (sc->nrxchains == 2)
   3152 		rf |= 1 << 6;		/* 2R: disable Rx chain 3 */
   3153 	run_rt3070_rf_write(sc, 1, rf);
   3154 
   3155 	/* set RF offset */
   3156 	run_rt3070_rf_read(sc, 23, &rf);
   3157 	rf = (rf & ~0x7f) | sc->freq;
   3158 	run_rt3070_rf_write(sc, 23, rf);
   3159 
   3160 	/* program RF filter */
   3161 	rf = sc->rf24_20mhz;
   3162 	run_rt3070_rf_write(sc, 24, rf);	/* Tx */
   3163 	run_rt3070_rf_write(sc, 31, rf);	/* Rx */
   3164 
   3165 	/* enable RF tuning */
   3166 	run_rt3070_rf_read(sc, 7, &rf);
   3167 	rf = (chan <= 14) ? 0xd8 : ((rf & ~0xc8) | 0x14);
   3168 	run_rt3070_rf_write(sc, 7, rf);
   3169 
   3170 	/* TSSI */
   3171 	rf = (chan <= 14) ? 0xc3 : 0xc0;
   3172 	run_rt3070_rf_write(sc, 9, rf);
   3173 
   3174 	/* set loop filter 1 */
   3175 	run_rt3070_rf_write(sc, 10, 0xf1);
   3176 	/* set loop filter 2 */
   3177 	run_rt3070_rf_write(sc, 11, (chan <= 14) ? 0xb9 : 0x00);
   3178 
   3179 	/* set tx_mx2_ic */
   3180 	run_rt3070_rf_write(sc, 15, (chan <= 14) ? 0x53 : 0x43);
   3181 	/* set tx_mx1_ic */
   3182 	if (chan <= 14)
   3183 		rf = 0x48 | sc->txmixgain_2ghz;
   3184 	else
   3185 		rf = 0x78 | sc->txmixgain_5ghz;
   3186 	run_rt3070_rf_write(sc, 16, rf);
   3187 
   3188 	/* set tx_lo1 */
   3189 	run_rt3070_rf_write(sc, 17, 0x23);
   3190 	/* set tx_lo2 */
   3191 	if (chan <= 14)
   3192 		rf = 0x93;
   3193 	else if (chan <= 64)
   3194 		rf = 0xb7;
   3195 	else if (chan <= 128)
   3196 		rf = 0x74;
   3197 	else
   3198 		rf = 0x72;
   3199 	run_rt3070_rf_write(sc, 19, rf);
   3200 
   3201 	/* set rx_lo1 */
   3202 	if (chan <= 14)
   3203 		rf = 0xb3;
   3204 	else if (chan <= 64)
   3205 		rf = 0xf6;
   3206 	else if (chan <= 128)
   3207 		rf = 0xf4;
   3208 	else
   3209 		rf = 0xf3;
   3210 	run_rt3070_rf_write(sc, 20, rf);
   3211 
   3212 	/* set pfd_delay */
   3213 	if (chan <= 14)
   3214 		rf = 0x15;
   3215 	else if (chan <= 64)
   3216 		rf = 0x3d;
   3217 	else
   3218 		rf = 0x01;
   3219 	run_rt3070_rf_write(sc, 25, rf);
   3220 
   3221 	/* set rx_lo2 */
   3222 	run_rt3070_rf_write(sc, 26, (chan <= 14) ? 0x85 : 0x87);
   3223 	/* set ldo_rf_vc */
   3224 	run_rt3070_rf_write(sc, 27, (chan <= 14) ? 0x00 : 0x01);
   3225 	/* set drv_cc */
   3226 	run_rt3070_rf_write(sc, 29, (chan <= 14) ? 0x9b : 0x9f);
   3227 
   3228 	run_read(sc, RT2860_GPIO_CTRL, &tmp);
   3229 	tmp &= ~0x8080;
   3230 	if (chan <= 14)
   3231 		tmp |= 0x80;
   3232 	run_write(sc, RT2860_GPIO_CTRL, tmp);
   3233 
   3234 	/* enable RF tuning */
   3235 	run_rt3070_rf_read(sc, 7, &rf);
   3236 	run_rt3070_rf_write(sc, 7, rf | 0x01);
   3237 
   3238 	usbd_delay_ms(sc->sc_udev, 2);
   3239 }
   3240 
   3241 static void
   3242 run_rt3593_set_chan(struct run_softc *sc, u_int chan)
   3243 {
   3244 	int8_t txpow1, txpow2, txpow3;
   3245 	uint8_t h20mhz, rf;
   3246 	int i;
   3247 
   3248 	/* find the settings for this channel (we know it exists) */
   3249 	for (i = 0; rt2860_rf2850[i].chan != chan; i++);
   3250 
   3251 	/* use Tx power values from EEPROM */
   3252 	txpow1 = sc->txpow1[i];
   3253 	txpow2 = sc->txpow2[i];
   3254 	txpow3 = (sc->ntxchains == 3) ? sc->txpow3[i] : 0;
   3255 
   3256 	if (chan <= 14) {
   3257 		run_bbp_write(sc, 25, sc->bbp25);
   3258 		run_bbp_write(sc, 26, sc->bbp26);
   3259 	} else {
   3260 		/* Enable IQ phase correction. */
   3261 		run_bbp_write(sc, 25, 0x09);
   3262 		run_bbp_write(sc, 26, 0xff);
   3263 	}
   3264 
   3265 	run_rt3070_rf_write(sc, 8, rt3070_freqs[i].n);
   3266 	run_rt3070_rf_write(sc, 9, rt3070_freqs[i].k & 0x0f);
   3267 	run_rt3070_rf_read(sc, 11, &rf);
   3268 	rf = (rf & ~0x03) | (rt3070_freqs[i].r & 0x03);
   3269 	run_rt3070_rf_write(sc, 11, rf);
   3270 
   3271 	/* Set pll_idoh. */
   3272 	run_rt3070_rf_read(sc, 11, &rf);
   3273 	rf &= ~0x4c;
   3274 	rf |= (chan <= 14) ? 0x44 : 0x48;
   3275 	run_rt3070_rf_write(sc, 11, rf);
   3276 
   3277 	if (chan <= 14)
   3278 		rf = txpow1 & 0x1f;
   3279 	else
   3280 		rf = 0x40 | ((txpow1 & 0x18) << 1) | (txpow1 & 0x07);
   3281 	run_rt3070_rf_write(sc, 53, rf);
   3282 
   3283 	if (chan <= 14)
   3284 		rf = txpow2 & 0x1f;
   3285 	else
   3286 		rf = 0x40 | ((txpow2 & 0x18) << 1) | (txpow2 & 0x07);
   3287 	run_rt3070_rf_write(sc, 55, rf);
   3288 
   3289 	if (chan <= 14)
   3290 		rf = txpow3 & 0x1f;
   3291 	else
   3292 		rf = 0x40 | ((txpow3 & 0x18) << 1) | (txpow3 & 0x07);
   3293 	run_rt3070_rf_write(sc, 54, rf);
   3294 
   3295 	rf = RT3070_RF_BLOCK | RT3070_PLL_PD;
   3296 	if (sc->ntxchains == 3)
   3297 		rf |= RT3070_TX0_PD | RT3070_TX1_PD | RT3070_TX2_PD;
   3298 	else
   3299 		rf |= RT3070_TX0_PD | RT3070_TX1_PD;
   3300 	rf |= RT3070_RX0_PD | RT3070_RX1_PD | RT3070_RX2_PD;
   3301 	run_rt3070_rf_write(sc, 1, rf);
   3302 
   3303 	run_adjust_freq_offset(sc);
   3304 
   3305 	run_rt3070_rf_write(sc, 31, (chan <= 14) ? 0xa0 : 0x80);
   3306 
   3307 	h20mhz = (sc->rf24_20mhz & 0x20) >> 5;
   3308 	run_rt3070_rf_read(sc, 30, &rf);
   3309 	rf = (rf & ~0x06) | (h20mhz << 1) | (h20mhz << 2);
   3310 	run_rt3070_rf_write(sc, 30, rf);
   3311 
   3312 	run_rt3070_rf_read(sc, 36, &rf);
   3313 	if (chan <= 14)
   3314 		rf |= 0x80;
   3315 	else
   3316 		rf &= ~0x80;
   3317 	run_rt3070_rf_write(sc, 36, rf);
   3318 
   3319 	/* Set vcolo_bs. */
   3320 	run_rt3070_rf_write(sc, 34, (chan <= 14) ? 0x3c : 0x20);
   3321 	/* Set pfd_delay. */
   3322 	run_rt3070_rf_write(sc, 12, (chan <= 14) ? 0x1a : 0x12);
   3323 
   3324 	/* Set vco bias current control. */
   3325 	run_rt3070_rf_read(sc, 6, &rf);
   3326 	rf &= ~0xc0;
   3327 	if (chan <= 14)
   3328 		rf |= 0x40;
   3329 	else if (chan <= 128)
   3330 		rf |= 0x80;
   3331 	else
   3332 		rf |= 0x40;
   3333 	run_rt3070_rf_write(sc, 6, rf);
   3334 
   3335 	run_rt3070_rf_read(sc, 30, &rf);
   3336 	rf = (rf & ~0x18) | 0x10;
   3337 	run_rt3070_rf_write(sc, 30, rf);
   3338 
   3339 	run_rt3070_rf_write(sc, 10, (chan <= 14) ? 0xd3 : 0xd8);
   3340 	run_rt3070_rf_write(sc, 13, (chan <= 14) ? 0x12 : 0x23);
   3341 
   3342 	run_rt3070_rf_read(sc, 51, &rf);
   3343 	rf = (rf & ~0x03) | 0x01;
   3344 	run_rt3070_rf_write(sc, 51, rf);
   3345 	/* Set tx_mx1_cc. */
   3346 	run_rt3070_rf_read(sc, 51, &rf);
   3347 	rf &= ~0x1c;
   3348 	rf |= (chan <= 14) ? 0x14 : 0x10;
   3349 	run_rt3070_rf_write(sc, 51, rf);
   3350 	/* Set tx_mx1_ic. */
   3351 	run_rt3070_rf_read(sc, 51, &rf);
   3352 	rf &= ~0xe0;
   3353 	rf |= (chan <= 14) ? 0x60 : 0x40;
   3354 	run_rt3070_rf_write(sc, 51, rf);
   3355 	/* Set tx_lo1_ic. */
   3356 	run_rt3070_rf_read(sc, 49, &rf);
   3357 	rf &= ~0x1c;
   3358 	rf |= (chan <= 14) ? 0x0c : 0x08;
   3359 	run_rt3070_rf_write(sc, 49, rf);
   3360 	/* Set tx_lo1_en. */
   3361 	run_rt3070_rf_read(sc, 50, &rf);
   3362 	run_rt3070_rf_write(sc, 50, rf & ~0x20);
   3363 	/* Set drv_cc. */
   3364 	run_rt3070_rf_read(sc, 57, &rf);
   3365 	rf &= ~0xfc;
   3366 	rf |= (chan <= 14) ?  0x6c : 0x3c;
   3367 	run_rt3070_rf_write(sc, 57, rf);
   3368 	/* Set rx_mix1_ic, rxa_lnactr, lna_vc, lna_inbias_en and lna_en. */
   3369 	run_rt3070_rf_write(sc, 44, (chan <= 14) ? 0x93 : 0x9b);
   3370 	/* Set drv_gnd_a, tx_vga_cc_a and tx_mx2_gain. */
   3371 	run_rt3070_rf_write(sc, 52, (chan <= 14) ? 0x45 : 0x05);
   3372 	/* Enable VCO calibration. */
   3373 	run_rt3070_rf_read(sc, 3, &rf);
   3374 	rf &= ~RT5390_VCOCAL;
   3375 	rf |= (chan <= 14) ? RT5390_VCOCAL : 0xbe;
   3376 	run_rt3070_rf_write(sc, 3, rf);
   3377 
   3378 	if (chan <= 14)
   3379 		rf = 0x23;
   3380 	else if (chan <= 64)
   3381 		rf = 0x36;
   3382 	else if (chan <= 128)
   3383 		rf = 0x32;
   3384 	else
   3385 		rf = 0x30;
   3386 	run_rt3070_rf_write(sc, 39, rf);
   3387 	if (chan <= 14)
   3388 		rf = 0xbb;
   3389 	else if (chan <= 64)
   3390 		rf = 0xeb;
   3391 	else if (chan <= 128)
   3392 		rf = 0xb3;
   3393 	else
   3394 		rf = 0x9b;
   3395 	run_rt3070_rf_write(sc, 45, rf);
   3396 
   3397 	/* Set FEQ/AEQ control. */
   3398 	run_bbp_write(sc, 105, 0x34);
   3399 }
   3400 
   3401 static void
   3402 run_rt5390_set_chan(struct run_softc *sc, u_int chan)
   3403 {
   3404 	int8_t txpow1, txpow2;
   3405 	uint8_t rf;
   3406 	int i;
   3407 
   3408 	/* find the settings for this channel (we know it exists) */
   3409 	for (i = 0; rt2860_rf2850[i].chan != chan; i++);
   3410 
   3411 	/* use Tx power values from EEPROM */
   3412 	txpow1 = sc->txpow1[i];
   3413 	txpow2 = sc->txpow2[i];
   3414 
   3415 	run_rt3070_rf_write(sc, 8, rt3070_freqs[i].n);
   3416 	run_rt3070_rf_write(sc, 9, rt3070_freqs[i].k & 0x0f);
   3417 	run_rt3070_rf_read(sc, 11, &rf);
   3418 	rf = (rf & ~0x03) | (rt3070_freqs[i].r & 0x03);
   3419 	run_rt3070_rf_write(sc, 11, rf);
   3420 
   3421 	run_rt3070_rf_read(sc, 49, &rf);
   3422 	rf = (rf & ~0x3f) | (txpow1 & 0x3f);
   3423 	/* The valid range of the RF R49 is 0x00 to 0x27. */
   3424 	if ((rf & 0x3f) > 0x27)
   3425 		rf = (rf & ~0x3f) | 0x27;
   3426 	run_rt3070_rf_write(sc, 49, rf);
   3427 
   3428 	if (sc->mac_ver == 0x5392) {
   3429 		run_rt3070_rf_read(sc, 50, &rf);
   3430 		rf = (rf & ~0x3f) | (txpow2 & 0x3f);
   3431 		/* The valid range of the RF R50 is 0x00 to 0x27. */
   3432 		if ((rf & 0x3f) > 0x27)
   3433 			rf = (rf & ~0x3f) | 0x27;
   3434 		run_rt3070_rf_write(sc, 50, rf);
   3435 	}
   3436 
   3437 	run_rt3070_rf_read(sc, 1, &rf);
   3438 	rf |= RT3070_RF_BLOCK | RT3070_PLL_PD | RT3070_RX0_PD | RT3070_TX0_PD;
   3439 	if (sc->mac_ver == 0x5392)
   3440 		rf |= RT3070_RX1_PD | RT3070_TX1_PD;
   3441 	run_rt3070_rf_write(sc, 1, rf);
   3442 
   3443 	if (sc->mac_ver != 0x5392) {
   3444 		run_rt3070_rf_read(sc, 2, &rf);
   3445 		rf |= 0x80;
   3446 		run_rt3070_rf_write(sc, 2, rf);
   3447 		usbd_delay_ms(sc->sc_udev, 10);
   3448 		rf &= 0x7f;
   3449 		run_rt3070_rf_write(sc, 2, rf);
   3450 	}
   3451 
   3452 	run_adjust_freq_offset(sc);
   3453 
   3454 	if (sc->mac_ver == 0x5392) {
   3455 		/* Fix for RT5392C. */
   3456 		if (sc->mac_rev >= 0x0223) {
   3457 			if (chan <= 4)
   3458 				rf = 0x0f;
   3459 			else if (chan >= 5 && chan <= 7)
   3460 				rf = 0x0e;
   3461 			else
   3462 				rf = 0x0d;
   3463 			run_rt3070_rf_write(sc, 23, rf);
   3464 
   3465 			if (chan <= 4)
   3466 				rf = 0x0c;
   3467 			else if (chan == 5)
   3468 				rf = 0x0b;
   3469 			else if (chan >= 6 && chan <= 7)
   3470 				rf = 0x0a;
   3471 			else if (chan >= 8 && chan <= 10)
   3472 				rf = 0x09;
   3473 			else
   3474 				rf = 0x08;
   3475 			run_rt3070_rf_write(sc, 59, rf);
   3476 		} else {
   3477 			if (chan <= 11)
   3478 				rf = 0x0f;
   3479 			else
   3480 				rf = 0x0b;
   3481 			run_rt3070_rf_write(sc, 59, rf);
   3482 		}
   3483 	} else {
   3484 		/* Fix for RT5390F. */
   3485 		if (sc->mac_rev >= 0x0502) {
   3486 			if (chan <= 11)
   3487 				rf = 0x43;
   3488 			else
   3489 				rf = 0x23;
   3490 			run_rt3070_rf_write(sc, 55, rf);
   3491 
   3492 			if (chan <= 11)
   3493 				rf = 0x0f;
   3494 			else if (chan == 12)
   3495 				rf = 0x0d;
   3496 			else
   3497 				rf = 0x0b;
   3498 			run_rt3070_rf_write(sc, 59, rf);
   3499 		} else {
   3500 			run_rt3070_rf_write(sc, 55, 0x44);
   3501 			run_rt3070_rf_write(sc, 59, 0x8f);
   3502 		}
   3503 	}
   3504 
   3505 	/* Enable VCO calibration. */
   3506 	run_rt3070_rf_read(sc, 3, &rf);
   3507 	rf |= RT5390_VCOCAL;
   3508 	run_rt3070_rf_write(sc, 3, rf);
   3509 }
   3510 
   3511 static void
   3512 run_rt5592_set_chan(struct run_softc *sc, u_int chan)
   3513 {
   3514 	const struct rt5592_freqs *freqs;
   3515 	uint32_t tmp;
   3516 	uint8_t reg, rf, txpow_bound;
   3517 	int8_t txpow1, txpow2;
   3518 	int i;
   3519 
   3520 	run_read(sc, RT5592_DEBUG_INDEX, &tmp);
   3521 	freqs = (tmp & RT5592_SEL_XTAL) ?
   3522 	    rt5592_freqs_40mhz : rt5592_freqs_20mhz;
   3523 
   3524 	/* find the settings for this channel (we know it exists) */
   3525 	for (i = 0; rt2860_rf2850[i].chan != chan; i++, freqs++);
   3526 
   3527 	/* use Tx power values from EEPROM */
   3528 	txpow1 = sc->txpow1[i];
   3529 	txpow2 = sc->txpow2[i];
   3530 
   3531 	run_read(sc, RT3070_LDO_CFG0, &tmp);
   3532 	tmp &= ~0x1c000000;
   3533 	if (chan > 14)
   3534 		tmp |= 0x14000000;
   3535 	run_write(sc, RT3070_LDO_CFG0, tmp);
   3536 
   3537 	/* N setting. */
   3538 	run_rt3070_rf_write(sc, 8, freqs->n & 0xff);
   3539 	run_rt3070_rf_read(sc, 9, &rf);
   3540 	rf &= ~(1 << 4);
   3541 	rf |= ((freqs->n & 0x0100) >> 8) << 4;
   3542 	run_rt3070_rf_write(sc, 9, rf);
   3543 
   3544 	/* K setting. */
   3545 	run_rt3070_rf_read(sc, 9, &rf);
   3546 	rf &= ~0x0f;
   3547 	rf |= (freqs->k & 0x0f);
   3548 	run_rt3070_rf_write(sc, 9, rf);
   3549 
   3550 	/* Mode setting. */
   3551 	run_rt3070_rf_read(sc, 11, &rf);
   3552 	rf &= ~0x0c;
   3553 	rf |= ((freqs->m - 0x8) & 0x3) << 2;
   3554 	run_rt3070_rf_write(sc, 11, rf);
   3555 	run_rt3070_rf_read(sc, 9, &rf);
   3556 	rf &= ~(1 << 7);
   3557 	rf |= (((freqs->m - 0x8) & 0x4) >> 2) << 7;
   3558 	run_rt3070_rf_write(sc, 9, rf);
   3559 
   3560 	/* R setting. */
   3561 	run_rt3070_rf_read(sc, 11, &rf);
   3562 	rf &= ~0x03;
   3563 	rf |= (freqs->r - 0x1);
   3564 	run_rt3070_rf_write(sc, 11, rf);
   3565 
   3566 	if (chan <= 14) {
   3567 		/* Initialize RF registers for 2GHZ. */
   3568 		for (i = 0; i < (int)__arraycount(rt5592_2ghz_def_rf); i++) {
   3569 			run_rt3070_rf_write(sc, rt5592_2ghz_def_rf[i].reg,
   3570 			    rt5592_2ghz_def_rf[i].val);
   3571 		}
   3572 
   3573 		rf = (chan <= 10) ? 0x07 : 0x06;
   3574 		run_rt3070_rf_write(sc, 23, rf);
   3575 		run_rt3070_rf_write(sc, 59, rf);
   3576 
   3577 		run_rt3070_rf_write(sc, 55, 0x43);
   3578 
   3579 		/*
   3580 		 * RF R49/R50 Tx power ALC code.
   3581 		 * G-band bit<7:6>=1:0, bit<5:0> range from 0x0 ~ 0x27.
   3582 		 */
   3583 		reg = 2;
   3584 		txpow_bound = 0x27;
   3585 	} else {
   3586 		/* Initialize RF registers for 5GHZ. */
   3587 		for (i = 0; i < (int)__arraycount(rt5592_5ghz_def_rf); i++) {
   3588 			run_rt3070_rf_write(sc, rt5592_5ghz_def_rf[i].reg,
   3589 			    rt5592_5ghz_def_rf[i].val);
   3590 		}
   3591 		for (i = 0; i < (int)__arraycount(rt5592_chan_5ghz); i++) {
   3592 			if (chan >= rt5592_chan_5ghz[i].firstchan &&
   3593 			    chan <= rt5592_chan_5ghz[i].lastchan) {
   3594 				run_rt3070_rf_write(sc, rt5592_chan_5ghz[i].reg,
   3595 				    rt5592_chan_5ghz[i].val);
   3596 			}
   3597 		}
   3598 
   3599 		/*
   3600 		 * RF R49/R50 Tx power ALC code.
   3601 		 * A-band bit<7:6>=1:1, bit<5:0> range from 0x0 ~ 0x2b.
   3602 		 */
   3603 		reg = 3;
   3604 		txpow_bound = 0x2b;
   3605 	}
   3606 
   3607 	/* RF R49 ch0 Tx power ALC code. */
   3608 	run_rt3070_rf_read(sc, 49, &rf);
   3609 	rf &= ~0xc0;
   3610 	rf |= (reg << 6);
   3611 	rf = (rf & ~0x3f) | (txpow1 & 0x3f);
   3612 	if ((rf & 0x3f) > txpow_bound)
   3613 		rf = (rf & ~0x3f) | txpow_bound;
   3614 	run_rt3070_rf_write(sc, 49, rf);
   3615 
   3616 	/* RF R50 ch1 Tx power ALC code. */
   3617 	run_rt3070_rf_read(sc, 50, &rf);
   3618 	rf &= ~(1 << 7 | 1 << 6);
   3619 	rf |= (reg << 6);
   3620 	rf = (rf & ~0x3f) | (txpow2 & 0x3f);
   3621 	if ((rf & 0x3f) > txpow_bound)
   3622 		rf = (rf & ~0x3f) | txpow_bound;
   3623 	run_rt3070_rf_write(sc, 50, rf);
   3624 
   3625 	/* Enable RF_BLOCK, PLL_PD, RX0_PD, and TX0_PD. */
   3626 	run_rt3070_rf_read(sc, 1, &rf);
   3627 	rf |= (RT3070_RF_BLOCK | RT3070_PLL_PD | RT3070_RX0_PD | RT3070_TX0_PD);
   3628 	if (sc->ntxchains > 1)
   3629 		rf |= RT3070_TX1_PD;
   3630 	if (sc->nrxchains > 1)
   3631 		rf |= RT3070_RX1_PD;
   3632 	run_rt3070_rf_write(sc, 1, rf);
   3633 
   3634 	run_rt3070_rf_write(sc, 6, 0xe4);
   3635 
   3636 	run_rt3070_rf_write(sc, 30, 0x10);
   3637 	run_rt3070_rf_write(sc, 31, 0x80);
   3638 	run_rt3070_rf_write(sc, 32, 0x80);
   3639 
   3640 	run_adjust_freq_offset(sc);
   3641 
   3642 	/* Enable VCO calibration. */
   3643 	run_rt3070_rf_read(sc, 3, &rf);
   3644 	rf |= RT5390_VCOCAL;
   3645 	run_rt3070_rf_write(sc, 3, rf);
   3646 }
   3647 
   3648 static void
   3649 run_iq_calib(struct run_softc *sc, u_int chan)
   3650 {
   3651 	uint16_t val;
   3652 
   3653 	/* Tx0 IQ gain. */
   3654 	run_bbp_write(sc, 158, 0x2c);
   3655 	if (chan <= 14)
   3656 		run_efuse_read(sc, RT5390_EEPROM_IQ_GAIN_CAL_TX0_2GHZ, &val, 1);
   3657 	else if (chan <= 64) {
   3658 		run_efuse_read(sc,
   3659 		    RT5390_EEPROM_IQ_GAIN_CAL_TX0_CH36_TO_CH64_5GHZ,
   3660 		    &val, 1);
   3661 	} else if (chan <= 138) {
   3662 		run_efuse_read(sc,
   3663 		    RT5390_EEPROM_IQ_GAIN_CAL_TX0_CH100_TO_CH138_5GHZ,
   3664 		    &val, 1);
   3665 	} else if (chan <= 165) {
   3666 		run_efuse_read(sc,
   3667 	    RT5390_EEPROM_IQ_GAIN_CAL_TX0_CH140_TO_CH165_5GHZ,
   3668 		    &val, 1);
   3669 	} else
   3670 		val = 0;
   3671 	run_bbp_write(sc, 159, val);
   3672 
   3673 	/* Tx0 IQ phase. */
   3674 	run_bbp_write(sc, 158, 0x2d);
   3675 	if (chan <= 14) {
   3676 		run_efuse_read(sc, RT5390_EEPROM_IQ_PHASE_CAL_TX0_2GHZ,
   3677 		    &val, 1);
   3678 	} else if (chan <= 64) {
   3679 		run_efuse_read(sc,
   3680 		    RT5390_EEPROM_IQ_PHASE_CAL_TX0_CH36_TO_CH64_5GHZ,
   3681 		    &val, 1);
   3682 	} else if (chan <= 138) {
   3683 		run_efuse_read(sc,
   3684 		    RT5390_EEPROM_IQ_PHASE_CAL_TX0_CH100_TO_CH138_5GHZ,
   3685 		    &val, 1);
   3686 	} else if (chan <= 165) {
   3687 		run_efuse_read(sc,
   3688 		    RT5390_EEPROM_IQ_PHASE_CAL_TX0_CH140_TO_CH165_5GHZ,
   3689 		    &val, 1);
   3690 	} else
   3691 		val = 0;
   3692 	run_bbp_write(sc, 159, val);
   3693 
   3694 	/* Tx1 IQ gain. */
   3695 	run_bbp_write(sc, 158, 0x4a);
   3696 	if (chan <= 14) {
   3697 		run_efuse_read(sc, RT5390_EEPROM_IQ_GAIN_CAL_TX1_2GHZ,
   3698 		    &val, 1);
   3699 	} else if (chan <= 64) {
   3700 		run_efuse_read(sc,
   3701 		    RT5390_EEPROM_IQ_GAIN_CAL_TX1_CH36_TO_CH64_5GHZ,
   3702 		    &val, 1);
   3703 	} else if (chan <= 138) {
   3704 		run_efuse_read(sc,
   3705 		    RT5390_EEPROM_IQ_GAIN_CAL_TX1_CH100_TO_CH138_5GHZ,
   3706 		    &val, 1);
   3707 	} else if (chan <= 165) {
   3708 		run_efuse_read(sc,
   3709 		    RT5390_EEPROM_IQ_GAIN_CAL_TX1_CH140_TO_CH165_5GHZ,
   3710 		    &val, 1);
   3711 	} else
   3712 		val = 0;
   3713 	run_bbp_write(sc, 159, val);
   3714 
   3715 	/* Tx1 IQ phase. */
   3716 	run_bbp_write(sc, 158, 0x4b);
   3717 	if (chan <= 14) {
   3718 		run_efuse_read(sc, RT5390_EEPROM_IQ_PHASE_CAL_TX1_2GHZ,
   3719 		    &val, 1);
   3720 	} else if (chan <= 64) {
   3721 		run_efuse_read(sc,
   3722 		    RT5390_EEPROM_IQ_PHASE_CAL_TX1_CH36_TO_CH64_5GHZ,
   3723 		    &val, 1);
   3724 	} else if (chan <= 138) {
   3725 		run_efuse_read(sc,
   3726 		    RT5390_EEPROM_IQ_PHASE_CAL_TX1_CH100_TO_CH138_5GHZ,
   3727 		    &val, 1);
   3728 	} else if (chan <= 165) {
   3729 		run_efuse_read(sc,
   3730 		    RT5390_EEPROM_IQ_PHASE_CAL_TX1_CH140_TO_CH165_5GHZ,
   3731 		    &val, 1);
   3732 	} else
   3733 		val = 0;
   3734 	run_bbp_write(sc, 159, val);
   3735 
   3736 	/* RF IQ compensation control. */
   3737 	run_bbp_write(sc, 158, 0x04);
   3738 	run_efuse_read(sc, RT5390_EEPROM_RF_IQ_COMPENSATION_CTL,
   3739 	    &val, 1);
   3740 	run_bbp_write(sc, 159, val);
   3741 
   3742 	/* RF IQ imbalance compensation control. */
   3743 	run_bbp_write(sc, 158, 0x03);
   3744 	run_efuse_read(sc,
   3745 	    RT5390_EEPROM_RF_IQ_IMBALANCE_COMPENSATION_CTL, &val, 1);
   3746 	run_bbp_write(sc, 159, val);
   3747 }
   3748 
   3749 static void
   3750 run_set_agc(struct run_softc *sc, uint8_t agc)
   3751 {
   3752 	uint8_t bbp;
   3753 
   3754 	if (sc->mac_ver == 0x3572) {
   3755 		run_bbp_read(sc, 27, &bbp);
   3756 		bbp &= ~(0x3 << 5);
   3757 		run_bbp_write(sc, 27, bbp | 0 << 5);	/* select Rx0 */
   3758 		run_bbp_write(sc, 66, agc);
   3759 		run_bbp_write(sc, 27, bbp | 1 << 5);	/* select Rx1 */
   3760 		run_bbp_write(sc, 66, agc);
   3761 	} else
   3762 		run_bbp_write(sc, 66, agc);
   3763 }
   3764 
   3765 static void
   3766 run_set_rx_antenna(struct run_softc *sc, int aux)
   3767 {
   3768 	uint32_t tmp;
   3769 	uint8_t bbp152;
   3770 
   3771 	if (aux) {
   3772 		if (sc->rf_rev == RT5390_RF_5370) {
   3773 			run_bbp_read(sc, 152, &bbp152);
   3774 			bbp152 &= ~0x80;
   3775 			run_bbp_write(sc, 152, bbp152);
   3776 		} else {
   3777 			run_mcu_cmd(sc, RT2860_MCU_CMD_ANTSEL, 0);
   3778 			run_read(sc, RT2860_GPIO_CTRL, &tmp);
   3779 			tmp &= ~0x0808;
   3780 			tmp |= 0x08;
   3781 			run_write(sc, RT2860_GPIO_CTRL, tmp);
   3782 		}
   3783 	} else {
   3784 		if (sc->rf_rev == RT5390_RF_5370) {
   3785 			run_bbp_read(sc, 152, &bbp152);
   3786 			bbp152 |= 0x80;
   3787 			run_bbp_write(sc, 152, bbp152);
   3788 		} else {
   3789 			run_mcu_cmd(sc, RT2860_MCU_CMD_ANTSEL, !aux);
   3790 			run_read(sc, RT2860_GPIO_CTRL, &tmp);
   3791 			tmp &= ~0x0808;
   3792 			run_write(sc, RT2860_GPIO_CTRL, tmp);
   3793 		}
   3794 	}
   3795 }
   3796 
   3797 static int
   3798 run_set_chan(struct run_softc *sc, struct ieee80211_channel *c)
   3799 {
   3800 	struct ieee80211com *ic = &sc->sc_ic;
   3801 	u_int chan, group;
   3802 
   3803 	chan = ieee80211_chan2ieee(ic, c);
   3804 	if (chan == 0 || chan == IEEE80211_CHAN_ANY)
   3805 		return EINVAL;
   3806 
   3807 	if (sc->mac_ver == 0x5592)
   3808 		run_rt5592_set_chan(sc, chan);
   3809 	else if (sc->mac_ver >= 0x5390)
   3810 		run_rt5390_set_chan(sc, chan);
   3811 	else if (sc->mac_ver == 0x3593)
   3812 		run_rt3593_set_chan(sc, chan);
   3813 	else if (sc->mac_ver == 0x3572)
   3814 		run_rt3572_set_chan(sc, chan);
   3815 	else if (sc->mac_ver >= 0x3070)
   3816 		run_rt3070_set_chan(sc, chan);
   3817 	else
   3818 		run_rt2870_set_chan(sc, chan);
   3819 
   3820 	/* determine channel group */
   3821 	if (chan <= 14)
   3822 		group = 0;
   3823 	else if (chan <= 64)
   3824 		group = 1;
   3825 	else if (chan <= 128)
   3826 		group = 2;
   3827 	else
   3828 		group = 3;
   3829 
   3830 	/* XXX necessary only when group has changed! */
   3831 	run_select_chan_group(sc, group);
   3832 
   3833 	usbd_delay_ms(sc->sc_udev, 10);
   3834 
   3835 	/* Perform IQ calibration. */
   3836 	if (sc->mac_ver >= 0x5392)
   3837 		run_iq_calib(sc, chan);
   3838 
   3839 	return 0;
   3840 }
   3841 
   3842 static void
   3843 run_updateprot(struct run_softc *sc)
   3844 {
   3845 	struct ieee80211com *ic = &sc->sc_ic;
   3846 	uint32_t tmp;
   3847 
   3848 	tmp = RT2860_RTSTH_EN | RT2860_PROT_NAV_SHORT | RT2860_TXOP_ALLOW_ALL;
   3849 	/* setup protection frame rate (MCS code) */
   3850 	tmp |= (ic->ic_curmode == IEEE80211_MODE_11A) ?
   3851 	    rt2860_rates[RT2860_RIDX_OFDM6].mcs | RT2860_PHY_OFDM :
   3852 	    rt2860_rates[RT2860_RIDX_CCK11].mcs;
   3853 
   3854 	/* CCK frames don't require protection */
   3855 	run_write(sc, RT2860_CCK_PROT_CFG, tmp);
   3856 	if (ic->ic_flags & IEEE80211_F_USEPROT) {
   3857 		if (ic->ic_protmode == IEEE80211_PROT_RTSCTS)
   3858 			tmp |= RT2860_PROT_CTRL_RTS_CTS;
   3859 		else if (ic->ic_protmode == IEEE80211_PROT_CTSONLY)
   3860 			tmp |= RT2860_PROT_CTRL_CTS;
   3861 	}
   3862 	run_write(sc, RT2860_OFDM_PROT_CFG, tmp);
   3863 }
   3864 
   3865 static void
   3866 run_enable_tsf_sync(struct run_softc *sc)
   3867 {
   3868 	struct ieee80211com *ic = &sc->sc_ic;
   3869 	uint32_t tmp;
   3870 
   3871 	run_read(sc, RT2860_BCN_TIME_CFG, &tmp);
   3872 	tmp &= ~0x1fffff;
   3873 	tmp |= ic->ic_bss->ni_intval * 16;
   3874 	tmp |= RT2860_TSF_TIMER_EN | RT2860_TBTT_TIMER_EN;
   3875 	if (ic->ic_opmode == IEEE80211_M_STA) {
   3876 		/*
   3877 		 * Local TSF is always updated with remote TSF on beacon
   3878 		 * reception.
   3879 		 */
   3880 		tmp |= 1 << RT2860_TSF_SYNC_MODE_SHIFT;
   3881 	}
   3882 #ifndef IEEE80211_STA_ONLY
   3883 	else if (ic->ic_opmode == IEEE80211_M_IBSS) {
   3884 		tmp |= RT2860_BCN_TX_EN;
   3885 		/*
   3886 		 * Local TSF is updated with remote TSF on beacon reception
   3887 		 * only if the remote TSF is greater than local TSF.
   3888 		 */
   3889 		tmp |= 2 << RT2860_TSF_SYNC_MODE_SHIFT;
   3890 	} else if (ic->ic_opmode == IEEE80211_M_HOSTAP) {
   3891 		tmp |= RT2860_BCN_TX_EN;
   3892 		/* SYNC with nobody */
   3893 		tmp |= 3 << RT2860_TSF_SYNC_MODE_SHIFT;
   3894 	}
   3895 #endif
   3896 	run_write(sc, RT2860_BCN_TIME_CFG, tmp);
   3897 }
   3898 
   3899 static void
   3900 run_enable_mrr(struct run_softc *sc)
   3901 {
   3902 #define CCK(mcs)	(mcs)
   3903 #define OFDM(mcs)	(1 << 3 | (mcs))
   3904 	run_write(sc, RT2860_LG_FBK_CFG0,
   3905 	    OFDM(6) << 28 |	/* 54->48 */
   3906 	    OFDM(5) << 24 |	/* 48->36 */
   3907 	    OFDM(4) << 20 |	/* 36->24 */
   3908 	    OFDM(3) << 16 |	/* 24->18 */
   3909 	    OFDM(2) << 12 |	/* 18->12 */
   3910 	    OFDM(1) <<  8 |	/* 12-> 9 */
   3911 	    OFDM(0) <<  4 |	/*  9-> 6 */
   3912 	    OFDM(0));		/*  6-> 6 */
   3913 
   3914 	run_write(sc, RT2860_LG_FBK_CFG1,
   3915 	    CCK(2) << 12 |	/* 11->5.5 */
   3916 	    CCK(1) <<  8 |	/* 5.5-> 2 */
   3917 	    CCK(0) <<  4 |	/*   2-> 1 */
   3918 	    CCK(0));		/*   1-> 1 */
   3919 #undef OFDM
   3920 #undef CCK
   3921 }
   3922 
   3923 static void
   3924 run_set_txpreamble(struct run_softc *sc)
   3925 {
   3926 	uint32_t tmp;
   3927 
   3928 	run_read(sc, RT2860_AUTO_RSP_CFG, &tmp);
   3929 	if (sc->sc_ic.ic_flags & IEEE80211_F_SHPREAMBLE)
   3930 		tmp |= RT2860_CCK_SHORT_EN;
   3931 	else
   3932 		tmp &= ~RT2860_CCK_SHORT_EN;
   3933 	run_write(sc, RT2860_AUTO_RSP_CFG, tmp);
   3934 }
   3935 
   3936 static void
   3937 run_set_basicrates(struct run_softc *sc)
   3938 {
   3939 	struct ieee80211com *ic = &sc->sc_ic;
   3940 
   3941 	/* set basic rates mask */
   3942 	if (ic->ic_curmode == IEEE80211_MODE_11B)
   3943 		run_write(sc, RT2860_LEGACY_BASIC_RATE, 0x003);
   3944 	else if (ic->ic_curmode == IEEE80211_MODE_11A)
   3945 		run_write(sc, RT2860_LEGACY_BASIC_RATE, 0x150);
   3946 	else	/* 11g */
   3947 		run_write(sc, RT2860_LEGACY_BASIC_RATE, 0x15f);
   3948 }
   3949 
   3950 static void
   3951 run_set_leds(struct run_softc *sc, uint16_t which)
   3952 {
   3953 
   3954 	(void)run_mcu_cmd(sc, RT2860_MCU_CMD_LEDS,
   3955 	    which | (sc->leds & 0x7f));
   3956 }
   3957 
   3958 static void
   3959 run_set_bssid(struct run_softc *sc, const uint8_t *bssid)
   3960 {
   3961 
   3962 	run_write(sc, RT2860_MAC_BSSID_DW0,
   3963 	    bssid[0] | bssid[1] << 8 | bssid[2] << 16 | bssid[3] << 24);
   3964 	run_write(sc, RT2860_MAC_BSSID_DW1,
   3965 	    bssid[4] | bssid[5] << 8);
   3966 }
   3967 
   3968 static void
   3969 run_set_macaddr(struct run_softc *sc, const uint8_t *addr)
   3970 {
   3971 
   3972 	run_write(sc, RT2860_MAC_ADDR_DW0,
   3973 	    addr[0] | addr[1] << 8 | addr[2] << 16 | addr[3] << 24);
   3974 	run_write(sc, RT2860_MAC_ADDR_DW1,
   3975 	    addr[4] | addr[5] << 8 | 0xff << 16);
   3976 }
   3977 
   3978 static void
   3979 run_updateslot(struct ifnet *ifp)
   3980 {
   3981 
   3982 	/* do it in a process context */
   3983 	run_do_async(ifp->if_softc, run_updateslot_cb, NULL, 0);
   3984 }
   3985 
   3986 /* ARGSUSED */
   3987 static void
   3988 run_updateslot_cb(struct run_softc *sc, void *arg)
   3989 {
   3990 	uint32_t tmp;
   3991 
   3992 	run_read(sc, RT2860_BKOFF_SLOT_CFG, &tmp);
   3993 	tmp &= ~0xff;
   3994 	tmp |= (sc->sc_ic.ic_flags & IEEE80211_F_SHSLOT) ? 9 : 20;
   3995 	run_write(sc, RT2860_BKOFF_SLOT_CFG, tmp);
   3996 }
   3997 
   3998 static int8_t
   3999 run_rssi2dbm(struct run_softc *sc, uint8_t rssi, uint8_t rxchain)
   4000 {
   4001 	struct ieee80211com *ic = &sc->sc_ic;
   4002 	struct ieee80211_channel *c = ic->ic_curchan;
   4003 	int delta;
   4004 
   4005 	if (IEEE80211_IS_CHAN_5GHZ(c)) {
   4006 		u_int chan = ieee80211_chan2ieee(ic, c);
   4007 		delta = sc->rssi_5ghz[rxchain];
   4008 
   4009 		/* determine channel group */
   4010 		if (chan <= 64)
   4011 			delta -= sc->lna[1];
   4012 		else if (chan <= 128)
   4013 			delta -= sc->lna[2];
   4014 		else
   4015 			delta -= sc->lna[3];
   4016 	} else
   4017 		delta = sc->rssi_2ghz[rxchain] - sc->lna[0];
   4018 
   4019 	return -12 - delta - rssi;
   4020 }
   4021 
   4022 static void
   4023 run_rt5390_bbp_init(struct run_softc *sc)
   4024 {
   4025 	u_int i;
   4026 	uint8_t bbp;
   4027 
   4028 	/* Apply maximum likelihood detection for 2 stream case. */
   4029 	run_bbp_read(sc, 105, &bbp);
   4030 	if (sc->nrxchains > 1)
   4031 		run_bbp_write(sc, 105, bbp | RT5390_MLD);
   4032 
   4033 	/* Avoid data lost and CRC error. */
   4034 	run_bbp_read(sc, 4, &bbp);
   4035 	run_bbp_write(sc, 4, bbp | RT5390_MAC_IF_CTRL);
   4036 
   4037 	if (sc->mac_ver == 0x5592) {
   4038 		for (i = 0; i < (int)__arraycount(rt5592_def_bbp); i++) {
   4039 			run_bbp_write(sc, rt5592_def_bbp[i].reg,
   4040 			    rt5592_def_bbp[i].val);
   4041 		}
   4042 		for (i = 0; i < (int)__arraycount(rt5592_bbp_r196); i++) {
   4043 			run_bbp_write(sc, 195, i + 0x80);
   4044 			run_bbp_write(sc, 196, rt5592_bbp_r196[i]);
   4045 		}
   4046 	} else {
   4047 		for (i = 0; i < (int)__arraycount(rt5390_def_bbp); i++) {
   4048 			run_bbp_write(sc, rt5390_def_bbp[i].reg,
   4049 			    rt5390_def_bbp[i].val);
   4050 		}
   4051 	}
   4052 	if (sc->mac_ver == 0x5392) {
   4053 		run_bbp_write(sc, 88, 0x90);
   4054 		run_bbp_write(sc, 95, 0x9a);
   4055 		run_bbp_write(sc, 98, 0x12);
   4056 		run_bbp_write(sc, 106, 0x12);
   4057 		run_bbp_write(sc, 134, 0xd0);
   4058 		run_bbp_write(sc, 135, 0xf6);
   4059 		run_bbp_write(sc, 148, 0x84);
   4060 	}
   4061 
   4062 	run_bbp_read(sc, 152, &bbp);
   4063 	run_bbp_write(sc, 152, bbp | 0x80);
   4064 
   4065 	/* Fix BBP254 for RT5592C. */
   4066 	if (sc->mac_ver == 0x5592 && sc->mac_rev >= 0x0221) {
   4067 		run_bbp_read(sc, 254, &bbp);
   4068 		run_bbp_write(sc, 254, bbp | 0x80);
   4069 	}
   4070 
   4071 	/* Disable hardware antenna diversity. */
   4072 	if (sc->mac_ver == 0x5390)
   4073 		run_bbp_write(sc, 154, 0);
   4074 
   4075 	/* Initialize Rx CCK/OFDM frequency offset report. */
   4076 	run_bbp_write(sc, 142, 1);
   4077 	run_bbp_write(sc, 143, 57);
   4078 }
   4079 
   4080 static int
   4081 run_bbp_init(struct run_softc *sc)
   4082 {
   4083 	int i, error, ntries;
   4084 	uint8_t bbp0;
   4085 
   4086 	/* wait for BBP to wake up */
   4087 	for (ntries = 0; ntries < 20; ntries++) {
   4088 		if ((error = run_bbp_read(sc, 0, &bbp0)) != 0)
   4089 			return error;
   4090 		if (bbp0 != 0 && bbp0 != 0xff)
   4091 			break;
   4092 	}
   4093 	if (ntries == 20)
   4094 		return ETIMEDOUT;
   4095 
   4096 	/* initialize BBP registers to default values */
   4097 	if (sc->mac_ver >= 0x5390)
   4098 		run_rt5390_bbp_init(sc);
   4099 	else {
   4100 		for (i = 0; i < (int)__arraycount(rt2860_def_bbp); i++) {
   4101 			run_bbp_write(sc, rt2860_def_bbp[i].reg,
   4102 			    rt2860_def_bbp[i].val);
   4103 		}
   4104 	}
   4105 
   4106 	if (sc->mac_ver == 0x3593) {
   4107 		run_bbp_write(sc, 79, 0x13);
   4108 		run_bbp_write(sc, 80, 0x05);
   4109 		run_bbp_write(sc, 81, 0x33);
   4110 		run_bbp_write(sc, 86, 0x46);
   4111 		run_bbp_write(sc, 137, 0x0f);
   4112 	}
   4113 
   4114 	/* fix BBP84 for RT2860E */
   4115 	if (sc->mac_ver == 0x2860 && sc->mac_rev != 0x0101)
   4116 		run_bbp_write(sc, 84, 0x19);
   4117 
   4118 	if (sc->mac_ver >= 0x3070 && (sc->mac_ver != 0x3593 &&
   4119 	    sc->mac_ver != 0x5592)) {
   4120 		run_bbp_write(sc, 79, 0x13);
   4121 		run_bbp_write(sc, 80, 0x05);
   4122 		run_bbp_write(sc, 81, 0x33);
   4123 	} else if (sc->mac_ver == 0x2860 && sc->mac_rev == 0x0100) {
   4124 		run_bbp_write(sc, 69, 0x16);
   4125 		run_bbp_write(sc, 73, 0x12);
   4126 	}
   4127 	return 0;
   4128 }
   4129 
   4130 static int
   4131 run_rt3070_rf_init(struct run_softc *sc)
   4132 {
   4133 	uint32_t tmp;
   4134 	uint8_t rf, target, bbp4;
   4135 	int i;
   4136 
   4137 	run_rt3070_rf_read(sc, 30, &rf);
   4138 	/* toggle RF R30 bit 7 */
   4139 	run_rt3070_rf_write(sc, 30, rf | 0x80);
   4140 	usbd_delay_ms(sc->sc_udev, 10);
   4141 	run_rt3070_rf_write(sc, 30, rf & ~0x80);
   4142 
   4143 	/* initialize RF registers to default value */
   4144 	if (sc->mac_ver == 0x3572) {
   4145 		for (i = 0; i < (int)__arraycount(rt3572_def_rf); i++) {
   4146 			run_rt3070_rf_write(sc, rt3572_def_rf[i].reg,
   4147 			    rt3572_def_rf[i].val);
   4148 		}
   4149 	} else {
   4150 		for (i = 0; i < (int)__arraycount(rt3070_def_rf); i++) {
   4151 			run_rt3070_rf_write(sc, rt3070_def_rf[i].reg,
   4152 			    rt3070_def_rf[i].val);
   4153 		}
   4154 	}
   4155 	if (sc->mac_ver == 0x3572) {
   4156 		run_rt3070_rf_read(sc, 6, &rf);
   4157 		run_rt3070_rf_write(sc, 6, rf | 0x40);
   4158 		run_rt3070_rf_write(sc, 31, 0x14);
   4159 
   4160 		run_read(sc, RT3070_LDO_CFG0, &tmp);
   4161 		tmp &= ~0x1f000000;
   4162 		if (sc->mac_rev < 0x0211 && sc->patch_dac)
   4163 			tmp |= 0x0d000000;	/* 1.3V */
   4164 		else
   4165 			tmp |= 0x01000000;	/* 1.2V */
   4166 		run_write(sc, RT3070_LDO_CFG0, tmp);
   4167 	} else if (sc->mac_ver == 0x3071) {
   4168 		run_rt3070_rf_read(sc, 6, &rf);
   4169 		run_rt3070_rf_write(sc, 6, rf | 0x40);
   4170 		run_rt3070_rf_write(sc, 31, 0x14);
   4171 
   4172 		run_read(sc, RT3070_LDO_CFG0, &tmp);
   4173 		tmp &= ~0x1f000000;
   4174 		if (sc->mac_rev < 0x0211)
   4175 			tmp |= 0x0d000000;	/* 1.35V */
   4176 		else
   4177 			tmp |= 0x01000000;	/* 1.2V */
   4178 		run_write(sc, RT3070_LDO_CFG0, tmp);
   4179 
   4180 		/* patch LNA_PE_G1 */
   4181 		run_read(sc, RT3070_GPIO_SWITCH, &tmp);
   4182 		run_write(sc, RT3070_GPIO_SWITCH, tmp & ~0x20);
   4183 	} else if (sc->mac_ver == 0x3070 && sc->mac_rev < 0x0201) {
   4184 		/*
   4185 		 * Change voltage from 1.2V to 1.35V for RT3070.
   4186 		 * The DAC issue (RT3070_LD0_CFG0) has been fixed
   4187 		 * in RT3070(F).
   4188 		 */
   4189 		run_read(sc, RT3070_LDO_CFG0, &tmp);
   4190 		tmp = (tmp & ~0x0f000000) | 0x0d000000;
   4191 		run_write(sc, RT3070_LDO_CFG0, tmp);
   4192 	}
   4193 
   4194 	/* select 20MHz bandwidth */
   4195 	run_rt3070_rf_read(sc, 31, &rf);
   4196 	run_rt3070_rf_write(sc, 31, rf & ~0x20);
   4197 
   4198 	/* calibrate filter for 20MHz bandwidth */
   4199 	sc->rf24_20mhz = 0x1f;	/* default value */
   4200 	target = (sc->mac_ver < 0x3071) ? 0x16 : 0x13;
   4201 	run_rt3070_filter_calib(sc, 0x07, target, &sc->rf24_20mhz);
   4202 
   4203 	/* select 40MHz bandwidth */
   4204 	run_bbp_read(sc, 4, &bbp4);
   4205 	run_bbp_write(sc, 4, (bbp4 & ~0x08) | 0x10);
   4206 	run_rt3070_rf_read(sc, 31, &rf);
   4207 	run_rt3070_rf_write(sc, 31, rf | 0x20);
   4208 
   4209 	/* calibrate filter for 40MHz bandwidth */
   4210 	sc->rf24_40mhz = 0x2f;	/* default value */
   4211 	target = (sc->mac_ver < 0x3071) ? 0x19 : 0x15;
   4212 	run_rt3070_filter_calib(sc, 0x27, target, &sc->rf24_40mhz);
   4213 
   4214 	/* go back to 20MHz bandwidth */
   4215 	run_bbp_read(sc, 4, &bbp4);
   4216 	run_bbp_write(sc, 4, bbp4 & ~0x18);
   4217 
   4218 	if (sc->mac_ver == 0x3572) {
   4219 		/* save default BBP registers 25 and 26 values */
   4220 		run_bbp_read(sc, 25, &sc->bbp25);
   4221 		run_bbp_read(sc, 26, &sc->bbp26);
   4222 	} else if (sc->mac_rev < 0x0211)
   4223 		run_rt3070_rf_write(sc, 27, 0x03);
   4224 
   4225 	run_read(sc, RT3070_OPT_14, &tmp);
   4226 	run_write(sc, RT3070_OPT_14, tmp | 1);
   4227 
   4228 	if (sc->mac_ver == 0x3070 || sc->mac_ver == 0x3071) {
   4229 		run_rt3070_rf_read(sc, 17, &rf);
   4230 		rf &= ~RT3070_TX_LO1;
   4231 		if ((sc->mac_ver == 0x3070 ||
   4232 		     (sc->mac_ver == 0x3071 && sc->mac_rev >= 0x0211)) &&
   4233 		    !sc->ext_2ghz_lna)
   4234 			rf |= 0x20;	/* fix for long range Rx issue */
   4235 		if (sc->txmixgain_2ghz >= 1)
   4236 			rf = (rf & ~0x7) | sc->txmixgain_2ghz;
   4237 		run_rt3070_rf_write(sc, 17, rf);
   4238 	}
   4239 	if (sc->mac_ver == 0x3071) {
   4240 		run_rt3070_rf_read(sc, 1, &rf);
   4241 		rf &= ~(RT3070_RX0_PD | RT3070_TX0_PD);
   4242 		rf |= RT3070_RF_BLOCK | RT3070_RX1_PD | RT3070_TX1_PD;
   4243 		run_rt3070_rf_write(sc, 1, rf);
   4244 
   4245 		run_rt3070_rf_read(sc, 15, &rf);
   4246 		run_rt3070_rf_write(sc, 15, rf & ~RT3070_TX_LO2);
   4247 
   4248 		run_rt3070_rf_read(sc, 20, &rf);
   4249 		run_rt3070_rf_write(sc, 20, rf & ~RT3070_RX_LO1);
   4250 
   4251 		run_rt3070_rf_read(sc, 21, &rf);
   4252 		run_rt3070_rf_write(sc, 21, rf & ~RT3070_RX_LO2);
   4253 	}
   4254 	if (sc->mac_ver == 0x3070 || sc->mac_ver == 0x3071) {
   4255 		/* fix Tx to Rx IQ glitch by raising RF voltage */
   4256 		run_rt3070_rf_read(sc, 27, &rf);
   4257 		rf &= ~0x77;
   4258 		if (sc->mac_rev < 0x0211)
   4259 			rf |= 0x03;
   4260 		run_rt3070_rf_write(sc, 27, rf);
   4261 	}
   4262 	return 0;
   4263 }
   4264 
   4265 static int
   4266 run_rt3593_rf_init(struct run_softc *sc)
   4267 {
   4268 	uint32_t tmp;
   4269 	uint8_t rf;
   4270 	int i;
   4271 
   4272 	/* Disable the GPIO bits 4 and 7 for LNA PE control. */
   4273 	run_read(sc, RT3070_GPIO_SWITCH, &tmp);
   4274 	tmp &= ~(1 << 4 | 1 << 7);
   4275 	run_write(sc, RT3070_GPIO_SWITCH, tmp);
   4276 
   4277 	/* Initialize RF registers to default value. */
   4278 	for (i = 0; i < __arraycount(rt3593_def_rf); i++) {
   4279 		run_rt3070_rf_write(sc, rt3593_def_rf[i].reg,
   4280 			rt3593_def_rf[i].val);
   4281 	}
   4282 
   4283 	/* Toggle RF R2 to initiate calibration. */
   4284 	run_rt3070_rf_write(sc, 2, RT5390_RESCAL);
   4285 
   4286 	/* Initialize RF frequency offset. */
   4287 	run_adjust_freq_offset(sc);
   4288 
   4289 	run_rt3070_rf_read(sc, 18, &rf);
   4290 	run_rt3070_rf_write(sc, 18, rf | RT3593_AUTOTUNE_BYPASS);
   4291 
   4292 	/*
   4293 	 * Increase voltage from 1.2V to 1.35V, wait for 1 msec to
   4294 	 * decrease voltage back to 1.2V.
   4295 	 */
   4296 	run_read(sc, RT3070_LDO_CFG0, &tmp);
   4297 	tmp = (tmp & ~0x1f000000) | 0x0d000000;
   4298 	run_write(sc, RT3070_LDO_CFG0, tmp);
   4299 	usbd_delay_ms(sc->sc_udev, 1);
   4300 	tmp = (tmp & ~0x1f000000) | 0x01000000;
   4301 	run_write(sc, RT3070_LDO_CFG0, tmp);
   4302 
   4303 	sc->rf24_20mhz = 0x1f;
   4304 	sc->rf24_40mhz = 0x2f;
   4305 
   4306 	/* Save default BBP registers 25 and 26 values. */
   4307 	run_bbp_read(sc, 25, &sc->bbp25);
   4308 	run_bbp_read(sc, 26, &sc->bbp26);
   4309 
   4310 	run_read(sc, RT3070_OPT_14, &tmp);
   4311 	run_write(sc, RT3070_OPT_14, tmp | 1);
   4312 	return 0;
   4313 }
   4314 
   4315 static int
   4316 run_rt5390_rf_init(struct run_softc *sc)
   4317 {
   4318 	uint32_t tmp;
   4319 	uint8_t rf;
   4320 	int i;
   4321 
   4322 	/* Toggle RF R2 to initiate calibration. */
   4323 	if (sc->mac_ver == 0x5390) {
   4324 		run_rt3070_rf_read(sc, 2, &rf);
   4325 		run_rt3070_rf_write(sc, 2, rf | RT5390_RESCAL);
   4326 		usbd_delay_ms(sc->sc_udev, 10);
   4327 		run_rt3070_rf_write(sc, 2, rf & ~RT5390_RESCAL);
   4328 	} else {
   4329 		run_rt3070_rf_write(sc, 2, RT5390_RESCAL);
   4330 		usbd_delay_ms(sc->sc_udev, 10);
   4331 	}
   4332 
   4333 	/* Initialize RF registers to default value. */
   4334 	if (sc->mac_ver == 0x5592) {
   4335 		for (i = 0; i < __arraycount(rt5592_def_rf); i++) {
   4336 			run_rt3070_rf_write(sc, rt5592_def_rf[i].reg,
   4337 			    rt5592_def_rf[i].val);
   4338 		}
   4339 		/* Initialize RF frequency offset. */
   4340 		run_adjust_freq_offset(sc);
   4341 	} else if (sc->mac_ver == 0x5392) {
   4342 		for (i = 0; i < __arraycount(rt5392_def_rf); i++) {
   4343 			run_rt3070_rf_write(sc, rt5392_def_rf[i].reg,
   4344 			    rt5392_def_rf[i].val);
   4345 		}
   4346 		if (sc->mac_rev >= 0x0223) {
   4347 			run_rt3070_rf_write(sc, 23, 0x0f);
   4348 			run_rt3070_rf_write(sc, 24, 0x3e);
   4349 			run_rt3070_rf_write(sc, 51, 0x32);
   4350 			run_rt3070_rf_write(sc, 53, 0x22);
   4351 			run_rt3070_rf_write(sc, 56, 0xc1);
   4352 			run_rt3070_rf_write(sc, 59, 0x0f);
   4353 		}
   4354 	} else {
   4355 		for (i = 0; i < __arraycount(rt5390_def_rf); i++) {
   4356 			run_rt3070_rf_write(sc, rt5390_def_rf[i].reg,
   4357 			    rt5390_def_rf[i].val);
   4358 		}
   4359 		if (sc->mac_rev >= 0x0502) {
   4360 			run_rt3070_rf_write(sc, 6, 0xe0);
   4361 			run_rt3070_rf_write(sc, 25, 0x80);
   4362 			run_rt3070_rf_write(sc, 46, 0x73);
   4363 			run_rt3070_rf_write(sc, 53, 0x00);
   4364 			run_rt3070_rf_write(sc, 56, 0x42);
   4365 			run_rt3070_rf_write(sc, 61, 0xd1);
   4366 		}
   4367 	}
   4368 
   4369 	sc->rf24_20mhz = 0x1f;  /* default value */
   4370 	sc->rf24_40mhz = (sc->mac_ver == 0x5592) ? 0 : 0x2f;
   4371 
   4372 	if (sc->mac_rev < 0x0211)
   4373 		run_rt3070_rf_write(sc, 27, 0x3);
   4374 
   4375 	run_read(sc, RT3070_OPT_14, &tmp);
   4376 	run_write(sc, RT3070_OPT_14, tmp | 1);
   4377 	return 0;
   4378 }
   4379 
   4380 static int
   4381 run_rt3070_filter_calib(struct run_softc *sc, uint8_t init, uint8_t target,
   4382     uint8_t *val)
   4383 {
   4384 	uint8_t rf22, rf24;
   4385 	uint8_t bbp55_pb, bbp55_sb, delta;
   4386 	int ntries;
   4387 
   4388 	/* program filter */
   4389 	run_rt3070_rf_read(sc, 24, &rf24);
   4390 	rf24 = (rf24 & 0xc0) | init;    /* initial filter value */
   4391 	run_rt3070_rf_write(sc, 24, rf24);
   4392 
   4393 	/* enable baseband loopback mode */
   4394 	run_rt3070_rf_read(sc, 22, &rf22);
   4395 	run_rt3070_rf_write(sc, 22, rf22 | 0x01);
   4396 
   4397 	/* set power and frequency of passband test tone */
   4398 	run_bbp_write(sc, 24, 0x00);
   4399 	for (ntries = 0; ntries < 100; ntries++) {
   4400 		/* transmit test tone */
   4401 		run_bbp_write(sc, 25, 0x90);
   4402 		usbd_delay_ms(sc->sc_udev, 10);
   4403 		/* read received power */
   4404 		run_bbp_read(sc, 55, &bbp55_pb);
   4405 		if (bbp55_pb != 0)
   4406 			break;
   4407 	}
   4408 	if (ntries == 100)
   4409 		return ETIMEDOUT;
   4410 
   4411 	/* set power and frequency of stopband test tone */
   4412 	run_bbp_write(sc, 24, 0x06);
   4413 	for (ntries = 0; ntries < 100; ntries++) {
   4414 		/* transmit test tone */
   4415 		run_bbp_write(sc, 25, 0x90);
   4416 		usbd_delay_ms(sc->sc_udev, 10);
   4417 		/* read received power */
   4418 		run_bbp_read(sc, 55, &bbp55_sb);
   4419 
   4420 		delta = bbp55_pb - bbp55_sb;
   4421 		if (delta > target)
   4422 			break;
   4423 
   4424 		/* reprogram filter */
   4425 		rf24++;
   4426 		run_rt3070_rf_write(sc, 24, rf24);
   4427 	}
   4428 	if (ntries < 100) {
   4429 		if (rf24 != init)
   4430 			rf24--;	/* backtrack */
   4431 		*val = rf24;
   4432 		run_rt3070_rf_write(sc, 24, rf24);
   4433 	}
   4434 
   4435 	/* restore initial state */
   4436 	run_bbp_write(sc, 24, 0x00);
   4437 
   4438 	/* disable baseband loopback mode */
   4439 	run_rt3070_rf_read(sc, 22, &rf22);
   4440 	run_rt3070_rf_write(sc, 22, rf22 & ~0x01);
   4441 
   4442 	return 0;
   4443 }
   4444 
   4445 static void
   4446 run_rt3070_rf_setup(struct run_softc *sc)
   4447 {
   4448 	uint8_t bbp, rf;
   4449 	int i;
   4450 
   4451 	if (sc->mac_ver == 0x3572) {
   4452 		/* enable DC filter */
   4453 		if (sc->mac_rev >= 0x0201)
   4454 			run_bbp_write(sc, 103, 0xc0);
   4455 
   4456 		run_bbp_read(sc, 138, &bbp);
   4457 		if (sc->ntxchains == 1)
   4458 			bbp |= 0x20;	/* turn off DAC1 */
   4459 		if (sc->nrxchains == 1)
   4460 			bbp &= ~0x02;	/* turn off ADC1 */
   4461 		run_bbp_write(sc, 138, bbp);
   4462 
   4463 		if (sc->mac_rev >= 0x0211) {
   4464 			/* improve power consumption */
   4465 			run_bbp_read(sc, 31, &bbp);
   4466 			run_bbp_write(sc, 31, bbp & ~0x03);
   4467 		}
   4468 
   4469 		run_rt3070_rf_read(sc, 16, &rf);
   4470 		rf = (rf & ~0x07) | sc->txmixgain_2ghz;
   4471 		run_rt3070_rf_write(sc, 16, rf);
   4472 	} else if (sc->mac_ver == 0x3071) {
   4473 		/* enable DC filter */
   4474 		if (sc->mac_rev >= 0x0201)
   4475 			run_bbp_write(sc, 103, 0xc0);
   4476 
   4477 		run_bbp_read(sc, 138, &bbp);
   4478 		if (sc->ntxchains == 1)
   4479 			bbp |= 0x20;	/* turn off DAC1 */
   4480 		if (sc->nrxchains == 1)
   4481 			bbp &= ~0x02;	/* turn off ADC1 */
   4482 		run_bbp_write(sc, 138, bbp);
   4483 
   4484 		if (sc->mac_rev >= 0x0211) {
   4485 			/* improve power consumption */
   4486 			run_bbp_read(sc, 31, &bbp);
   4487 			run_bbp_write(sc, 31, bbp & ~0x03);
   4488 		}
   4489 
   4490 		run_write(sc, RT2860_TX_SW_CFG1, 0);
   4491 		if (sc->mac_rev < 0x0211) {
   4492 			run_write(sc, RT2860_TX_SW_CFG2,
   4493 			    sc->patch_dac ? 0x2c : 0x0f);
   4494 		} else
   4495 			run_write(sc, RT2860_TX_SW_CFG2, 0);
   4496 	} else if (sc->mac_ver == 0x3070) {
   4497 		if (sc->mac_rev >= 0x0201) {
   4498 			/* enable DC filter */
   4499 			run_bbp_write(sc, 103, 0xc0);
   4500 
   4501 			/* improve power consumption */
   4502 			run_bbp_read(sc, 31, &bbp);
   4503 			run_bbp_write(sc, 31, bbp & ~0x03);
   4504 		}
   4505 
   4506 		if (sc->mac_rev < 0x0211) {
   4507 			run_write(sc, RT2860_TX_SW_CFG1, 0);
   4508 			run_write(sc, RT2860_TX_SW_CFG2, 0x2c);
   4509 		} else
   4510 			run_write(sc, RT2860_TX_SW_CFG2, 0);
   4511 	}
   4512 
   4513 	/* initialize RF registers from ROM for >=RT3071*/
   4514 	if (sc->mac_ver >= 0x3071) {
   4515 		for (i = 0; i < 10; i++) {
   4516 			if (sc->rf[i].reg == 0 || sc->rf[i].reg == 0xff)
   4517 				continue;
   4518 			run_rt3070_rf_write(sc, sc->rf[i].reg, sc->rf[i].val);
   4519 		}
   4520 	}
   4521 }
   4522 
   4523 static void
   4524 run_rt3593_rf_setup(struct run_softc *sc)
   4525 {
   4526 	uint8_t bbp, rf;
   4527 
   4528 	if (sc->mac_rev >= 0x0211) {
   4529 		/* Enable DC filter. */
   4530 		run_bbp_write(sc, 103, 0xc0);
   4531 	}
   4532 	run_write(sc, RT2860_TX_SW_CFG1, 0);
   4533 	if (sc->mac_rev < 0x0211) {
   4534 		run_write(sc, RT2860_TX_SW_CFG2,
   4535 		    sc->patch_dac ? 0x2c : 0x0f);
   4536 	} else
   4537 		run_write(sc, RT2860_TX_SW_CFG2, 0);
   4538 
   4539 	run_rt3070_rf_read(sc, 50, &rf);
   4540 	run_rt3070_rf_write(sc, 50, rf & ~RT3593_TX_LO2);
   4541 
   4542 	run_rt3070_rf_read(sc, 51, &rf);
   4543 	rf = (rf & ~(RT3593_TX_LO1 | 0x0c)) |
   4544 	    ((sc->txmixgain_2ghz & 0x07) << 2);
   4545 	run_rt3070_rf_write(sc, 51, rf);
   4546 
   4547 	run_rt3070_rf_read(sc, 38, &rf);
   4548 	run_rt3070_rf_write(sc, 38, rf & ~RT5390_RX_LO1);
   4549 
   4550 	run_rt3070_rf_read(sc, 39, &rf);
   4551 	run_rt3070_rf_write(sc, 39, rf & ~RT5390_RX_LO2);
   4552 
   4553 	run_rt3070_rf_read(sc, 1, &rf);
   4554 	run_rt3070_rf_write(sc, 1, rf & ~(RT3070_RF_BLOCK | RT3070_PLL_PD));
   4555 
   4556 	run_rt3070_rf_read(sc, 30, &rf);
   4557 	rf = (rf & ~0x18) | 0x10;
   4558 	run_rt3070_rf_write(sc, 30, rf);
   4559 
   4560 	/* Apply maximum likelihood detection for 2 stream case. */
   4561 	run_bbp_read(sc, 105, &bbp);
   4562 	if (sc->nrxchains > 1)
   4563 		run_bbp_write(sc, 105, bbp | RT5390_MLD);
   4564 
   4565 	/* Avoid data lost and CRC error. */
   4566 	run_bbp_read(sc, 4, &bbp);
   4567 	run_bbp_write(sc, 4, bbp | RT5390_MAC_IF_CTRL);
   4568 
   4569 	run_bbp_write(sc, 92, 0x02);
   4570 	run_bbp_write(sc, 82, 0x82);
   4571 	run_bbp_write(sc, 106, 0x05);
   4572 	run_bbp_write(sc, 104, 0x92);
   4573 	run_bbp_write(sc, 88, 0x90);
   4574 	run_bbp_write(sc, 148, 0xc8);
   4575 	run_bbp_write(sc, 47, 0x48);
   4576 	run_bbp_write(sc, 120, 0x50);
   4577 
   4578 	run_bbp_write(sc, 163, 0x9d);
   4579 
   4580 	/* SNR mapping. */
   4581 	run_bbp_write(sc, 142, 0x06);
   4582 	run_bbp_write(sc, 143, 0xa0);
   4583 	run_bbp_write(sc, 142, 0x07);
   4584 	run_bbp_write(sc, 143, 0xa1);
   4585 	run_bbp_write(sc, 142, 0x08);
   4586 	run_bbp_write(sc, 143, 0xa2);
   4587 
   4588 	run_bbp_write(sc, 31, 0x08);
   4589 	run_bbp_write(sc, 68, 0x0b);
   4590 	run_bbp_write(sc, 105, 0x04);
   4591 }
   4592 
   4593 static void
   4594 run_rt5390_rf_setup(struct run_softc *sc)
   4595 {
   4596 	uint8_t bbp, rf;
   4597 
   4598 	if (sc->mac_rev >= 0x0211) {
   4599 		/* Enable DC filter. */
   4600 		run_bbp_write(sc, 103, 0xc0);
   4601 
   4602 		if (sc->mac_ver != 0x5592) {
   4603 			/* Improve power consumption. */
   4604 			run_bbp_read(sc, 31, &bbp);
   4605 			run_bbp_write(sc, 31, bbp & ~0x03);
   4606 		}
   4607 	}
   4608 
   4609 	run_bbp_read(sc, 138, &bbp);
   4610 	if (sc->ntxchains == 1)
   4611 		bbp |= 0x20;    /* turn off DAC1 */
   4612 	if (sc->nrxchains == 1)
   4613 		bbp &= ~0x02;   /* turn off ADC1 */
   4614 	run_bbp_write(sc, 138, bbp);
   4615 
   4616 	run_rt3070_rf_read(sc, 38, &rf);
   4617 	run_rt3070_rf_write(sc, 38, rf & ~RT5390_RX_LO1);
   4618 
   4619 	run_rt3070_rf_read(sc, 39, &rf);
   4620 	run_rt3070_rf_write(sc, 39, rf & ~RT5390_RX_LO2);
   4621 
   4622 	/* Avoid data lost and CRC error. */
   4623 	run_bbp_read(sc, 4, &bbp);
   4624 	run_bbp_write(sc, 4, bbp | RT5390_MAC_IF_CTRL);
   4625 
   4626 	run_rt3070_rf_read(sc, 30, &rf);
   4627 	rf = (rf & ~0x18) | 0x10;
   4628 	run_rt3070_rf_write(sc, 30, rf);
   4629 
   4630 	if (sc->mac_ver != 0x5592) {
   4631 		run_write(sc, RT2860_TX_SW_CFG1, 0);
   4632 		if (sc->mac_rev < 0x0211) {
   4633 			run_write(sc, RT2860_TX_SW_CFG2,
   4634 			    sc->patch_dac ? 0x2c : 0x0f);
   4635 		} else
   4636 			run_write(sc, RT2860_TX_SW_CFG2, 0);
   4637 	}
   4638 }
   4639 
   4640 static int
   4641 run_txrx_enable(struct run_softc *sc)
   4642 {
   4643 	uint32_t tmp;
   4644 	int error, ntries;
   4645 
   4646 	run_write(sc, RT2860_MAC_SYS_CTRL, RT2860_MAC_TX_EN);
   4647 	for (ntries = 0; ntries < 200; ntries++) {
   4648 		if ((error = run_read(sc, RT2860_WPDMA_GLO_CFG, &tmp)) != 0)
   4649 			return error;
   4650 		if ((tmp & (RT2860_TX_DMA_BUSY | RT2860_RX_DMA_BUSY)) == 0)
   4651 			break;
   4652 		usbd_delay_ms(sc->sc_udev, 50);
   4653 	}
   4654 	if (ntries == 200)
   4655 		return ETIMEDOUT;
   4656 
   4657 	usbd_delay_ms(sc->sc_udev, 50);
   4658 
   4659 	tmp |= RT2860_RX_DMA_EN | RT2860_TX_DMA_EN | RT2860_TX_WB_DDONE;
   4660 	run_write(sc, RT2860_WPDMA_GLO_CFG, tmp);
   4661 
   4662 	/* enable Rx bulk aggregation (set timeout and limit) */
   4663 	tmp = RT2860_USB_TX_EN | RT2860_USB_RX_EN | RT2860_USB_RX_AGG_EN |
   4664 	    RT2860_USB_RX_AGG_TO(128) | RT2860_USB_RX_AGG_LMT(2);
   4665 	run_write(sc, RT2860_USB_DMA_CFG, tmp);
   4666 
   4667 	/* set Rx filter */
   4668 	tmp = RT2860_DROP_CRC_ERR | RT2860_DROP_PHY_ERR;
   4669 	if (sc->sc_ic.ic_opmode != IEEE80211_M_MONITOR) {
   4670 		tmp |= RT2860_DROP_UC_NOME | RT2860_DROP_DUPL |
   4671 		    RT2860_DROP_CTS | RT2860_DROP_BA | RT2860_DROP_ACK |
   4672 		    RT2860_DROP_VER_ERR | RT2860_DROP_CTRL_RSV |
   4673 		    RT2860_DROP_CFACK | RT2860_DROP_CFEND;
   4674 		if (sc->sc_ic.ic_opmode == IEEE80211_M_STA)
   4675 			tmp |= RT2860_DROP_RTS | RT2860_DROP_PSPOLL;
   4676 	}
   4677 	run_write(sc, RT2860_RX_FILTR_CFG, tmp);
   4678 
   4679 	run_write(sc, RT2860_MAC_SYS_CTRL,
   4680 	    RT2860_MAC_RX_EN | RT2860_MAC_TX_EN);
   4681 
   4682 	return 0;
   4683 }
   4684 
   4685 static int
   4686 run_adjust_freq_offset(struct run_softc *sc)
   4687 {
   4688 	uint8_t rf, tmp;
   4689 
   4690 	run_rt3070_rf_read(sc, 17, &rf);
   4691 	tmp = rf;
   4692 	rf = (rf & ~0x7f) | (sc->freq & 0x7f);
   4693 	rf = MIN(rf, 0x5f);
   4694 
   4695 	if (tmp != rf)
   4696 		run_mcu_cmd(sc, 0x74, (tmp << 8 ) | rf);
   4697 
   4698 	return 0;
   4699 }
   4700 
   4701 static int
   4702 run_init(struct ifnet *ifp)
   4703 {
   4704 	struct run_softc *sc = ifp->if_softc;
   4705 	struct ieee80211com *ic = &sc->sc_ic;
   4706 	uint32_t tmp;
   4707 	uint8_t bbp1, bbp3;
   4708 	int i, error, qid, ridx, ntries;
   4709 	usbd_status status;
   4710 
   4711 	for (ntries = 0; ntries < 100; ntries++) {
   4712 		if ((error = run_read(sc, RT2860_ASIC_VER_ID, &tmp)) != 0)
   4713 			goto fail;
   4714 		if (tmp != 0 && tmp != 0xffffffff)
   4715 			break;
   4716 		usbd_delay_ms(sc->sc_udev, 10);
   4717 	}
   4718 	if (ntries == 100) {
   4719 		error = ETIMEDOUT;
   4720 		goto fail;
   4721 	}
   4722 
   4723 	if ((sc->sc_flags & RUN_FWLOADED) == 0 &&
   4724 	    (error = run_load_microcode(sc)) != 0) {
   4725 		device_printf(sc->sc_dev,
   4726 		    "could not load 8051 microcode\n");
   4727 		goto fail;
   4728 	}
   4729 
   4730 	if (ifp->if_flags & IFF_RUNNING)
   4731 		run_stop(ifp, 0);
   4732 
   4733 	/* init host command ring */
   4734 	sc->cmdq.cur = sc->cmdq.next = sc->cmdq.queued = 0;
   4735 
   4736 	/* init Tx rings (4 EDCAs) */
   4737 	for (qid = 0; qid < 4; qid++) {
   4738 		if ((error = run_alloc_tx_ring(sc, qid)) != 0)
   4739 			goto fail;
   4740 	}
   4741 	/* init Rx ring */
   4742 	if ((error = run_alloc_rx_ring(sc)) != 0)
   4743 		goto fail;
   4744 
   4745 	IEEE80211_ADDR_COPY(ic->ic_myaddr, CLLADDR(ifp->if_sadl));
   4746 	run_set_macaddr(sc, ic->ic_myaddr);
   4747 
   4748 	for (ntries = 0; ntries < 100; ntries++) {
   4749 		if ((error = run_read(sc, RT2860_WPDMA_GLO_CFG, &tmp)) != 0)
   4750 			goto fail;
   4751 		if ((tmp & (RT2860_TX_DMA_BUSY | RT2860_RX_DMA_BUSY)) == 0)
   4752 			break;
   4753 		usbd_delay_ms(sc->sc_udev, 10);
   4754 	}
   4755 	if (ntries == 100) {
   4756 		device_printf(sc->sc_dev,
   4757 		    "timeout waiting for DMA engine\n");
   4758 		error = ETIMEDOUT;
   4759 		goto fail;
   4760 	}
   4761 	tmp &= 0xff0;
   4762 	tmp |= RT2860_TX_WB_DDONE;
   4763 	run_write(sc, RT2860_WPDMA_GLO_CFG, tmp);
   4764 
   4765 	/* turn off PME_OEN to solve high-current issue */
   4766 	run_read(sc, RT2860_SYS_CTRL, &tmp);
   4767 	run_write(sc, RT2860_SYS_CTRL, tmp & ~RT2860_PME_OEN);
   4768 
   4769 	run_write(sc, RT2860_MAC_SYS_CTRL,
   4770 	    RT2860_BBP_HRST | RT2860_MAC_SRST);
   4771 	run_write(sc, RT2860_USB_DMA_CFG, 0);
   4772 
   4773 	if ((error = run_reset(sc)) != 0) {
   4774 		device_printf(sc->sc_dev, "could not reset chipset\n");
   4775 		goto fail;
   4776 	}
   4777 
   4778 	run_write(sc, RT2860_MAC_SYS_CTRL, 0);
   4779 
   4780 	/* init Tx power for all Tx rates (from EEPROM) */
   4781 	for (ridx = 0; ridx < 5; ridx++) {
   4782 		if (sc->txpow20mhz[ridx] == 0xffffffff)
   4783 			continue;
   4784 		run_write(sc, RT2860_TX_PWR_CFG(ridx), sc->txpow20mhz[ridx]);
   4785 	}
   4786 
   4787 	for (i = 0; i < (int)__arraycount(rt2870_def_mac); i++)
   4788 		run_write(sc, rt2870_def_mac[i].reg, rt2870_def_mac[i].val);
   4789 	run_write(sc, RT2860_WMM_AIFSN_CFG, 0x00002273);
   4790 	run_write(sc, RT2860_WMM_CWMIN_CFG, 0x00002344);
   4791 	run_write(sc, RT2860_WMM_CWMAX_CFG, 0x000034aa);
   4792 
   4793 	if (sc->mac_ver >= 0x5390) {
   4794 		run_write(sc, RT2860_TX_SW_CFG0,
   4795 		    4 << RT2860_DLY_PAPE_EN_SHIFT | 4);
   4796 		if (sc->mac_ver >= 0x5392) {
   4797 			run_write(sc, RT2860_MAX_LEN_CFG, 0x00002fff);
   4798 			if (sc->mac_ver == 0x5592) {
   4799 				run_write(sc, RT2860_HT_FBK_CFG1, 0xedcba980);
   4800 				run_write(sc, RT2860_TXOP_HLDR_ET, 0x00000082);
   4801 			} else {
   4802 				run_write(sc, RT2860_HT_FBK_CFG1, 0xedcb4980);
   4803 				run_write(sc, RT2860_LG_FBK_CFG0, 0xedcba322);
   4804 			}
   4805 		}
   4806 	} else if (sc->mac_ver >= 0x3593) {
   4807 		run_write(sc, RT2860_TX_SW_CFG0,
   4808 		    4 << RT2860_DLY_PAPE_EN_SHIFT | 2);
   4809 	} else if (sc->mac_ver >= 0x3070) {
   4810 		/* set delay of PA_PE assertion to 1us (unit of 0.25us) */
   4811 		run_write(sc, RT2860_TX_SW_CFG0,
   4812 		    4 << RT2860_DLY_PAPE_EN_SHIFT);
   4813 	}
   4814 
   4815 	/* wait while MAC is busy */
   4816 	for (ntries = 0; ntries < 100; ntries++) {
   4817 		if ((error = run_read(sc, RT2860_MAC_STATUS_REG, &tmp)) != 0)
   4818 			goto fail;
   4819 		if (!(tmp & (RT2860_RX_STATUS_BUSY | RT2860_TX_STATUS_BUSY)))
   4820 			break;
   4821 		DELAY(1000);
   4822 	}
   4823 	if (ntries == 100) {
   4824 		error = ETIMEDOUT;
   4825 		goto fail;
   4826 	}
   4827 
   4828 	/* clear Host to MCU mailbox */
   4829 	run_write(sc, RT2860_H2M_BBPAGENT, 0);
   4830 	run_write(sc, RT2860_H2M_MAILBOX, 0);
   4831 	usbd_delay_ms(sc->sc_udev, 10);
   4832 
   4833 	if ((error = run_bbp_init(sc)) != 0) {
   4834 		device_printf(sc->sc_dev, "could not initialize BBP\n");
   4835 		goto fail;
   4836 	}
   4837 
   4838 	/* abort TSF synchronization */
   4839 	run_read(sc, RT2860_BCN_TIME_CFG, &tmp);
   4840 	tmp &= ~(RT2860_BCN_TX_EN | RT2860_TSF_TIMER_EN |
   4841 	    RT2860_TBTT_TIMER_EN);
   4842 	run_write(sc, RT2860_BCN_TIME_CFG, tmp);
   4843 
   4844 	/* clear RX WCID search table */
   4845 	run_set_region_4(sc, RT2860_WCID_ENTRY(0), 0, 512);
   4846 	/* clear Pair-wise key table */
   4847 	run_set_region_4(sc, RT2860_PKEY(0), 0, 2048);
   4848 	/* clear IV/EIV table */
   4849 	run_set_region_4(sc, RT2860_IVEIV(0), 0, 512);
   4850 	/* clear WCID attribute table */
   4851 	run_set_region_4(sc, RT2860_WCID_ATTR(0), 0, 8 * 32);
   4852 	/* clear shared key table */
   4853 	run_set_region_4(sc, RT2860_SKEY(0, 0), 0, 8 * 32);
   4854 	/* clear shared key mode */
   4855 	run_set_region_4(sc, RT2860_SKEY_MODE_0_7, 0, 4);
   4856 
   4857 	/* clear RX WCID search table */
   4858 	run_set_region_4(sc, RT2860_WCID_ENTRY(0), 0, 512);
   4859 	/* clear WCID attribute table */
   4860 	run_set_region_4(sc, RT2860_WCID_ATTR(0), 0, 8 * 32);
   4861 
   4862 	run_read(sc, RT2860_US_CYC_CNT, &tmp);
   4863 	tmp = (tmp & ~0xff) | 0x1e;
   4864 	run_write(sc, RT2860_US_CYC_CNT, tmp);
   4865 
   4866 	if (sc->mac_rev != 0x0101)
   4867 		run_write(sc, RT2860_TXOP_CTRL_CFG, 0x0000583f);
   4868 
   4869 	run_write(sc, RT2860_WMM_TXOP0_CFG, 0);
   4870 	run_write(sc, RT2860_WMM_TXOP1_CFG, 48 << 16 | 96);
   4871 
   4872 	/* write vendor-specific BBP values (from EEPROM) */
   4873 	if (sc->mac_ver < 0x3593) {
   4874 		for (i = 0; i < 10; i++) {
   4875 			if (sc->bbp[i].reg == 0 || sc->bbp[i].reg == 0xff)
   4876 				continue;
   4877 			run_bbp_write(sc, sc->bbp[i].reg, sc->bbp[i].val);
   4878 		}
   4879 	}
   4880 
   4881 	/* select Main antenna for 1T1R devices */
   4882 	if (sc->rf_rev == RT3070_RF_3020 || sc->rf_rev == RT5390_RF_5370)
   4883 		run_set_rx_antenna(sc, 0);
   4884 
   4885 	/* send LEDs operating mode to microcontroller */
   4886 	(void)run_mcu_cmd(sc, RT2860_MCU_CMD_LED1, sc->led[0]);
   4887 	(void)run_mcu_cmd(sc, RT2860_MCU_CMD_LED2, sc->led[1]);
   4888 	(void)run_mcu_cmd(sc, RT2860_MCU_CMD_LED3, sc->led[2]);
   4889 
   4890 	if (sc->mac_ver >= 0x5390)
   4891 		run_rt5390_rf_init(sc);
   4892 	else if (sc->mac_ver == 0x3593)
   4893 		run_rt3593_rf_init(sc);
   4894 	else if (sc->mac_ver >= 0x3070)
   4895 		run_rt3070_rf_init(sc);
   4896 
   4897 	/* disable non-existing Rx chains */
   4898 	run_bbp_read(sc, 3, &bbp3);
   4899 	bbp3 &= ~(1 << 3 | 1 << 4);
   4900 	if (sc->nrxchains == 2)
   4901 		bbp3 |= 1 << 3;
   4902 	else if (sc->nrxchains == 3)
   4903 		bbp3 |= 1 << 4;
   4904 	run_bbp_write(sc, 3, bbp3);
   4905 
   4906 	/* disable non-existing Tx chains */
   4907 	run_bbp_read(sc, 1, &bbp1);
   4908 	if (sc->ntxchains == 1)
   4909 		bbp1 &= ~(1 << 3 | 1 << 4);
   4910 	run_bbp_write(sc, 1, bbp1);
   4911 
   4912 	if (sc->mac_ver >= 0x5390)
   4913 		run_rt5390_rf_setup(sc);
   4914 	else if (sc->mac_ver == 0x3593)
   4915 		run_rt3593_rf_setup(sc);
   4916 	else if (sc->mac_ver >= 0x3070)
   4917 		run_rt3070_rf_setup(sc);
   4918 
   4919 	/* select default channel */
   4920 	run_set_chan(sc, ic->ic_curchan);
   4921 
   4922 	/* setup initial protection mode */
   4923 	run_updateprot(sc);
   4924 
   4925 	/* turn radio LED on */
   4926 	run_set_leds(sc, RT2860_LED_RADIO);
   4927 
   4928 #ifdef RUN_HWCRYPTO
   4929 	if (ic->ic_flags & IEEE80211_F_PRIVACY) {
   4930 		/* install WEP keys */
   4931 		for (i = 0; i < IEEE80211_WEP_NKID; i++)
   4932 			(void)run_set_key(ic, &ic->ic_crypto.cs_nw_keys[i],
   4933 			    NULL);
   4934 	}
   4935 #endif
   4936 
   4937 	for (i = 0; i < RUN_RX_RING_COUNT; i++) {
   4938 		struct run_rx_data *data = &sc->rxq.data[i];
   4939 
   4940 		usbd_setup_xfer(data->xfer, data, data->buf, RUN_MAX_RXSZ,
   4941 		    USBD_SHORT_XFER_OK, USBD_NO_TIMEOUT, run_rxeof);
   4942 		status = usbd_transfer(data->xfer);
   4943 		if (status != USBD_NORMAL_COMPLETION &&
   4944 		    status != USBD_IN_PROGRESS) {
   4945 			device_printf(sc->sc_dev, "queuing rx failed: %s\n",
   4946 			    usbd_errstr(status));
   4947 			error = EIO;
   4948 			goto fail;
   4949 		}
   4950 	}
   4951 
   4952 	if ((error = run_txrx_enable(sc)) != 0)
   4953 		goto fail;
   4954 
   4955 	ifp->if_flags &= ~IFF_OACTIVE;
   4956 	ifp->if_flags |= IFF_RUNNING;
   4957 
   4958 	if (ic->ic_opmode == IEEE80211_M_MONITOR)
   4959 		ieee80211_new_state(ic, IEEE80211_S_RUN, -1);
   4960 	else
   4961 		ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
   4962 
   4963 	if (error != 0)
   4964 fail:		run_stop(ifp, 1);
   4965 	return error;
   4966 }
   4967 
   4968 static void
   4969 run_stop(struct ifnet *ifp, int disable)
   4970 {
   4971 	struct run_softc *sc = ifp->if_softc;
   4972 	struct ieee80211com *ic = &sc->sc_ic;
   4973 	uint32_t tmp;
   4974 	int ntries, qid;
   4975 
   4976 	if (ifp->if_flags & IFF_RUNNING)
   4977 		run_set_leds(sc, 0);	/* turn all LEDs off */
   4978 
   4979 	sc->sc_tx_timer = 0;
   4980 	ifp->if_timer = 0;
   4981 	ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
   4982 
   4983 	callout_stop(&sc->scan_to);
   4984 	callout_stop(&sc->calib_to);
   4985 
   4986 	ieee80211_new_state(ic, IEEE80211_S_INIT, -1);
   4987 	/* wait for all queued asynchronous commands to complete */
   4988 	while (sc->cmdq.queued > 0)
   4989 		tsleep(&sc->cmdq, 0, "cmdq", 0);
   4990 
   4991 	/* disable Tx/Rx */
   4992 	run_read(sc, RT2860_MAC_SYS_CTRL, &tmp);
   4993 	tmp &= ~(RT2860_MAC_RX_EN | RT2860_MAC_TX_EN);
   4994 	run_write(sc, RT2860_MAC_SYS_CTRL, tmp);
   4995 
   4996 	/* wait for pending Tx to complete */
   4997 	for (ntries = 0; ntries < 100; ntries++) {
   4998 		if (run_read(sc, RT2860_TXRXQ_PCNT, &tmp) != 0)
   4999 			break;
   5000 		if ((tmp & RT2860_TX2Q_PCNT_MASK) == 0)
   5001 			break;
   5002 	}
   5003 	DELAY(1000);
   5004 	run_write(sc, RT2860_USB_DMA_CFG, 0);
   5005 
   5006 	/* reset adapter */
   5007 	run_write(sc, RT2860_MAC_SYS_CTRL, RT2860_BBP_HRST | RT2860_MAC_SRST);
   5008 	run_write(sc, RT2860_MAC_SYS_CTRL, 0);
   5009 
   5010 	/* reset Tx and Rx rings */
   5011 	sc->qfullmsk = 0;
   5012 	for (qid = 0; qid < 4; qid++)
   5013 		run_free_tx_ring(sc, qid);
   5014 	run_free_rx_ring(sc);
   5015 }
   5016 
   5017 #ifndef IEEE80211_STA_ONLY
   5018 static int
   5019 run_setup_beacon(struct run_softc *sc)
   5020 {
   5021 	struct ieee80211com *ic = &sc->sc_ic;
   5022 	struct rt2860_txwi txwi;
   5023 	struct mbuf *m;
   5024 	uint16_t txwisize;
   5025 	int ridx;
   5026 
   5027 	if ((m = ieee80211_beacon_alloc(ic, ic->ic_bss, &sc->sc_bo)) == NULL)
   5028 		return ENOBUFS;
   5029 
   5030 	memset(&txwi, 0, sizeof(txwi));
   5031 	txwi.wcid = 0xff;
   5032 	txwi.len = htole16(m->m_pkthdr.len);
   5033 	/* send beacons at the lowest available rate */
   5034 	ridx = (ic->ic_curmode == IEEE80211_MODE_11A) ?
   5035 	    RT2860_RIDX_OFDM6 : RT2860_RIDX_CCK1;
   5036 	txwi.phy = htole16(rt2860_rates[ridx].mcs);
   5037 	if (rt2860_rates[ridx].phy == IEEE80211_T_OFDM)
   5038 		txwi.phy |= htole16(RT2860_PHY_OFDM);
   5039 	txwi.txop = RT2860_TX_TXOP_HT;
   5040 	txwi.flags = RT2860_TX_TS;
   5041 
   5042 	txwisize = (sc->mac_ver == 0x5592) ?
   5043 	    sizeof(txwi) + sizeof(uint32_t) : sizeof(txwi);
   5044 	run_write_region_1(sc, RT2860_BCN_BASE(0),
   5045 	    (uint8_t *)&txwi, txwisize);
   5046 	run_write_region_1(sc, RT2860_BCN_BASE(0) + txwisize,
   5047 	    mtod(m, uint8_t *), (m->m_pkthdr.len + 1) & ~1);
   5048 
   5049 	m_freem(m);
   5050 
   5051 	return 0;
   5052 }
   5053 #endif
   5054 
   5055 MODULE(MODULE_CLASS_DRIVER, if_run, NULL);
   5056 
   5057 #ifdef _MODULE
   5058 #include "ioconf.c"
   5059 #endif
   5060 
   5061 static int
   5062 if_run_modcmd(modcmd_t cmd, void *arg)
   5063 {
   5064 	int error = 0;
   5065 
   5066 	switch (cmd) {
   5067 	case MODULE_CMD_INIT:
   5068 #ifdef _MODULE
   5069 		error = config_init_component(cfdriver_ioconf_run,
   5070 		    cfattach_ioconf_run, cfdata_ioconf_run);
   5071 #endif
   5072 		return error;
   5073 	case MODULE_CMD_FINI:
   5074 #ifdef _MODULE
   5075 		error = config_fini_component(cfdriver_ioconf_run,
   5076 		    cfattach_ioconf_run, cfdata_ioconf_run);
   5077 #endif
   5078 		return error;
   5079 	default:
   5080 		return ENOTTY;
   5081 	}
   5082 }
   5083