bwfm.c revision 1.13 1 1.13 riastrad /* $NetBSD: bwfm.c,v 1.13 2018/09/01 22:01:03 riastradh Exp $ */
2 1.1 jmcneill /* $OpenBSD: bwfm.c,v 1.5 2017/10/16 22:27:16 patrick Exp $ */
3 1.1 jmcneill /*
4 1.1 jmcneill * Copyright (c) 2010-2016 Broadcom Corporation
5 1.1 jmcneill * Copyright (c) 2016,2017 Patrick Wildt <patrick (at) blueri.se>
6 1.1 jmcneill *
7 1.1 jmcneill * Permission to use, copy, modify, and/or distribute this software for any
8 1.1 jmcneill * purpose with or without fee is hereby granted, provided that the above
9 1.1 jmcneill * copyright notice and this permission notice appear in all copies.
10 1.1 jmcneill *
11 1.1 jmcneill * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
12 1.1 jmcneill * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
13 1.1 jmcneill * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
14 1.1 jmcneill * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
15 1.1 jmcneill * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16 1.1 jmcneill * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17 1.1 jmcneill * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18 1.1 jmcneill */
19 1.1 jmcneill
20 1.1 jmcneill #include <sys/param.h>
21 1.1 jmcneill #include <sys/systm.h>
22 1.1 jmcneill #include <sys/buf.h>
23 1.1 jmcneill #include <sys/kernel.h>
24 1.1 jmcneill #include <sys/device.h>
25 1.1 jmcneill #include <sys/queue.h>
26 1.1 jmcneill #include <sys/socket.h>
27 1.1 jmcneill #include <sys/kmem.h>
28 1.1 jmcneill #include <sys/workqueue.h>
29 1.1 jmcneill #include <sys/pcq.h>
30 1.1 jmcneill
31 1.1 jmcneill #include <net/bpf.h>
32 1.1 jmcneill #include <net/if.h>
33 1.1 jmcneill #include <net/if_dl.h>
34 1.1 jmcneill #include <net/if_media.h>
35 1.1 jmcneill #include <net/if_ether.h>
36 1.1 jmcneill
37 1.1 jmcneill #include <netinet/in.h>
38 1.1 jmcneill
39 1.1 jmcneill #include <net80211/ieee80211_var.h>
40 1.1 jmcneill
41 1.1 jmcneill #include <dev/ic/bwfmvar.h>
42 1.1 jmcneill #include <dev/ic/bwfmreg.h>
43 1.1 jmcneill
44 1.1 jmcneill /* #define BWFM_DEBUG */
45 1.1 jmcneill #ifdef BWFM_DEBUG
46 1.1 jmcneill #define DPRINTF(x) do { if (bwfm_debug > 0) printf x; } while (0)
47 1.1 jmcneill #define DPRINTFN(n, x) do { if (bwfm_debug >= (n)) printf x; } while (0)
48 1.1 jmcneill static int bwfm_debug = 1;
49 1.1 jmcneill #else
50 1.1 jmcneill #define DPRINTF(x) do { ; } while (0)
51 1.1 jmcneill #define DPRINTFN(n, x) do { ; } while (0)
52 1.1 jmcneill #endif
53 1.1 jmcneill
54 1.1 jmcneill #define DEVNAME(sc) device_xname((sc)->sc_dev)
55 1.1 jmcneill
56 1.1 jmcneill void bwfm_start(struct ifnet *);
57 1.1 jmcneill int bwfm_init(struct ifnet *);
58 1.1 jmcneill void bwfm_stop(struct ifnet *, int);
59 1.1 jmcneill void bwfm_watchdog(struct ifnet *);
60 1.1 jmcneill int bwfm_ioctl(struct ifnet *, u_long, void *);
61 1.1 jmcneill int bwfm_media_change(struct ifnet *);
62 1.1 jmcneill
63 1.1 jmcneill int bwfm_send_mgmt(struct ieee80211com *, struct ieee80211_node *,
64 1.1 jmcneill int, int);
65 1.1 jmcneill void bwfm_recv_mgmt(struct ieee80211com *, struct mbuf *,
66 1.1 jmcneill struct ieee80211_node *, int, int, uint32_t);
67 1.1 jmcneill int bwfm_key_set(struct ieee80211com *, const struct ieee80211_key *,
68 1.1 jmcneill const uint8_t *);
69 1.1 jmcneill int bwfm_key_delete(struct ieee80211com *, const struct ieee80211_key *);
70 1.1 jmcneill int bwfm_newstate(struct ieee80211com *, enum ieee80211_state, int);
71 1.1 jmcneill void bwfm_newstate_cb(struct bwfm_softc *, struct bwfm_cmd_newstate *);
72 1.4 jmcneill void bwfm_newassoc(struct ieee80211_node *, int);
73 1.1 jmcneill void bwfm_task(struct work *, void *);
74 1.1 jmcneill
75 1.1 jmcneill int bwfm_chip_attach(struct bwfm_softc *);
76 1.1 jmcneill int bwfm_chip_detach(struct bwfm_softc *, int);
77 1.1 jmcneill struct bwfm_core *bwfm_chip_get_core(struct bwfm_softc *, int);
78 1.1 jmcneill struct bwfm_core *bwfm_chip_get_pmu(struct bwfm_softc *);
79 1.1 jmcneill int bwfm_chip_ai_isup(struct bwfm_softc *, struct bwfm_core *);
80 1.1 jmcneill void bwfm_chip_ai_disable(struct bwfm_softc *, struct bwfm_core *,
81 1.1 jmcneill uint32_t, uint32_t);
82 1.1 jmcneill void bwfm_chip_ai_reset(struct bwfm_softc *, struct bwfm_core *,
83 1.1 jmcneill uint32_t, uint32_t, uint32_t);
84 1.1 jmcneill void bwfm_chip_dmp_erom_scan(struct bwfm_softc *);
85 1.1 jmcneill int bwfm_chip_dmp_get_regaddr(struct bwfm_softc *, uint32_t *,
86 1.1 jmcneill uint32_t *, uint32_t *);
87 1.11 maya int bwfm_chip_cr4_set_active(struct bwfm_softc *, const uint32_t);
88 1.1 jmcneill void bwfm_chip_cr4_set_passive(struct bwfm_softc *);
89 1.11 maya int bwfm_chip_ca7_set_active(struct bwfm_softc *, const uint32_t);
90 1.1 jmcneill void bwfm_chip_ca7_set_passive(struct bwfm_softc *);
91 1.11 maya int bwfm_chip_cm3_set_active(struct bwfm_softc *);
92 1.1 jmcneill void bwfm_chip_cm3_set_passive(struct bwfm_softc *);
93 1.11 maya void bwfm_chip_socram_ramsize(struct bwfm_softc *, struct bwfm_core *);
94 1.11 maya void bwfm_chip_sysmem_ramsize(struct bwfm_softc *, struct bwfm_core *);
95 1.11 maya void bwfm_chip_tcm_ramsize(struct bwfm_softc *, struct bwfm_core *);
96 1.11 maya void bwfm_chip_tcm_rambase(struct bwfm_softc *);
97 1.1 jmcneill
98 1.1 jmcneill int bwfm_proto_bcdc_query_dcmd(struct bwfm_softc *, int,
99 1.1 jmcneill int, char *, size_t *);
100 1.1 jmcneill int bwfm_proto_bcdc_set_dcmd(struct bwfm_softc *, int,
101 1.1 jmcneill int, char *, size_t);
102 1.1 jmcneill
103 1.1 jmcneill int bwfm_fwvar_cmd_get_data(struct bwfm_softc *, int, void *, size_t);
104 1.1 jmcneill int bwfm_fwvar_cmd_set_data(struct bwfm_softc *, int, void *, size_t);
105 1.1 jmcneill int bwfm_fwvar_cmd_get_int(struct bwfm_softc *, int, uint32_t *);
106 1.1 jmcneill int bwfm_fwvar_cmd_set_int(struct bwfm_softc *, int, uint32_t);
107 1.1 jmcneill int bwfm_fwvar_var_get_data(struct bwfm_softc *, const char *, void *, size_t);
108 1.1 jmcneill int bwfm_fwvar_var_set_data(struct bwfm_softc *, const char *, void *, size_t);
109 1.1 jmcneill int bwfm_fwvar_var_get_int(struct bwfm_softc *, const char *, uint32_t *);
110 1.1 jmcneill int bwfm_fwvar_var_set_int(struct bwfm_softc *, const char *, uint32_t);
111 1.1 jmcneill
112 1.1 jmcneill struct ieee80211_channel *bwfm_bss2chan(struct bwfm_softc *, struct bwfm_bss_info *);
113 1.1 jmcneill void bwfm_scan(struct bwfm_softc *);
114 1.1 jmcneill void bwfm_connect(struct bwfm_softc *);
115 1.1 jmcneill
116 1.11 maya void bwfm_rx(struct bwfm_softc *, struct mbuf *);
117 1.1 jmcneill void bwfm_rx_event(struct bwfm_softc *, char *, size_t);
118 1.1 jmcneill void bwfm_scan_node(struct bwfm_softc *, struct bwfm_bss_info *, size_t);
119 1.1 jmcneill
120 1.1 jmcneill uint8_t bwfm_2ghz_channels[] = {
121 1.1 jmcneill 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13,
122 1.1 jmcneill };
123 1.1 jmcneill uint8_t bwfm_5ghz_channels[] = {
124 1.1 jmcneill 34, 36, 38, 40, 42, 44, 46, 48, 52, 56, 60, 64, 100, 104, 108, 112,
125 1.1 jmcneill 116, 120, 124, 128, 132, 136, 140, 144, 149, 153, 157, 161, 165,
126 1.1 jmcneill };
127 1.1 jmcneill
128 1.1 jmcneill struct bwfm_proto_ops bwfm_proto_bcdc_ops = {
129 1.1 jmcneill .proto_query_dcmd = bwfm_proto_bcdc_query_dcmd,
130 1.1 jmcneill .proto_set_dcmd = bwfm_proto_bcdc_set_dcmd,
131 1.1 jmcneill };
132 1.1 jmcneill
133 1.1 jmcneill void
134 1.1 jmcneill bwfm_attach(struct bwfm_softc *sc)
135 1.1 jmcneill {
136 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
137 1.1 jmcneill struct ifnet *ifp = &sc->sc_if;
138 1.1 jmcneill struct bwfm_task *t;
139 1.1 jmcneill char fw_version[BWFM_DCMD_SMLEN];
140 1.1 jmcneill uint32_t bandlist[3];
141 1.1 jmcneill uint32_t tmp;
142 1.11 maya int i, j, error;
143 1.1 jmcneill
144 1.1 jmcneill error = workqueue_create(&sc->sc_taskq, DEVNAME(sc),
145 1.1 jmcneill bwfm_task, sc, PRI_NONE, IPL_NET, 0);
146 1.1 jmcneill if (error != 0) {
147 1.1 jmcneill printf("%s: could not create workqueue\n", DEVNAME(sc));
148 1.1 jmcneill return;
149 1.1 jmcneill }
150 1.1 jmcneill sc->sc_freetask = pcq_create(BWFM_TASK_COUNT, KM_SLEEP);
151 1.1 jmcneill for (i = 0; i < BWFM_TASK_COUNT; i++) {
152 1.1 jmcneill t = &sc->sc_task[i];
153 1.1 jmcneill t->t_sc = sc;
154 1.1 jmcneill pcq_put(sc->sc_freetask, t);
155 1.1 jmcneill }
156 1.1 jmcneill
157 1.5 jmcneill /* Stop the device in case it was previously initialized */
158 1.5 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_DOWN, 1);
159 1.5 jmcneill
160 1.1 jmcneill if (bwfm_fwvar_cmd_get_int(sc, BWFM_C_GET_VERSION, &tmp)) {
161 1.1 jmcneill printf("%s: could not read io type\n", DEVNAME(sc));
162 1.1 jmcneill return;
163 1.1 jmcneill } else
164 1.1 jmcneill sc->sc_io_type = tmp;
165 1.1 jmcneill if (bwfm_fwvar_var_get_data(sc, "cur_etheraddr", ic->ic_myaddr,
166 1.1 jmcneill sizeof(ic->ic_myaddr))) {
167 1.1 jmcneill printf("%s: could not read mac address\n", DEVNAME(sc));
168 1.1 jmcneill return;
169 1.1 jmcneill }
170 1.1 jmcneill
171 1.1 jmcneill memset(fw_version, 0, sizeof(fw_version));
172 1.1 jmcneill if (bwfm_fwvar_var_get_data(sc, "ver", fw_version, sizeof(fw_version)) == 0)
173 1.1 jmcneill printf("%s: %s", DEVNAME(sc), fw_version);
174 1.1 jmcneill printf("%s: address %s\n", DEVNAME(sc), ether_sprintf(ic->ic_myaddr));
175 1.1 jmcneill
176 1.1 jmcneill ic->ic_ifp = ifp;
177 1.1 jmcneill ic->ic_phytype = IEEE80211_T_OFDM;
178 1.1 jmcneill ic->ic_opmode = IEEE80211_M_STA;
179 1.1 jmcneill ic->ic_state = IEEE80211_S_INIT;
180 1.1 jmcneill
181 1.1 jmcneill ic->ic_caps =
182 1.1 jmcneill IEEE80211_C_WEP |
183 1.1 jmcneill IEEE80211_C_TKIP |
184 1.1 jmcneill IEEE80211_C_AES |
185 1.1 jmcneill IEEE80211_C_AES_CCM |
186 1.1 jmcneill #if notyet
187 1.1 jmcneill IEEE80211_C_MONITOR | /* monitor mode suported */
188 1.1 jmcneill IEEE80211_C_IBSS |
189 1.1 jmcneill IEEE80211_C_TXPMGT |
190 1.1 jmcneill IEEE80211_C_WME |
191 1.1 jmcneill #endif
192 1.1 jmcneill IEEE80211_C_SHSLOT | /* short slot time supported */
193 1.1 jmcneill IEEE80211_C_SHPREAMBLE | /* short preamble supported */
194 1.1 jmcneill IEEE80211_C_WPA | /* 802.11i */
195 1.1 jmcneill /* IEEE80211_C_WPA_4WAY */0; /* WPA 4-way handshake in hw */
196 1.1 jmcneill
197 1.1 jmcneill /* IBSS channel undefined for now. */
198 1.1 jmcneill ic->ic_ibss_chan = &ic->ic_channels[0];
199 1.1 jmcneill
200 1.1 jmcneill if (bwfm_fwvar_cmd_get_data(sc, BWFM_C_GET_BANDLIST, bandlist,
201 1.1 jmcneill sizeof(bandlist))) {
202 1.1 jmcneill printf("%s: couldn't get supported band list\n", DEVNAME(sc));
203 1.1 jmcneill return;
204 1.1 jmcneill }
205 1.1 jmcneill const u_int nbands = le32toh(bandlist[0]);
206 1.1 jmcneill for (i = 1; i <= MIN(nbands, __arraycount(bandlist) - 1); i++) {
207 1.1 jmcneill switch (le32toh(bandlist[i])) {
208 1.1 jmcneill case BWFM_BAND_2G:
209 1.1 jmcneill ic->ic_sup_rates[IEEE80211_MODE_11B] = ieee80211_std_rateset_11b;
210 1.1 jmcneill ic->ic_sup_rates[IEEE80211_MODE_11G] = ieee80211_std_rateset_11g;
211 1.1 jmcneill
212 1.11 maya for (j = 0; j < __arraycount(bwfm_2ghz_channels); j++) {
213 1.11 maya uint8_t chan = bwfm_2ghz_channels[j];
214 1.1 jmcneill ic->ic_channels[chan].ic_freq =
215 1.1 jmcneill ieee80211_ieee2mhz(chan, IEEE80211_CHAN_2GHZ);
216 1.1 jmcneill ic->ic_channels[chan].ic_flags =
217 1.1 jmcneill IEEE80211_CHAN_CCK | IEEE80211_CHAN_OFDM |
218 1.1 jmcneill IEEE80211_CHAN_DYN | IEEE80211_CHAN_2GHZ;
219 1.1 jmcneill }
220 1.1 jmcneill break;
221 1.1 jmcneill case BWFM_BAND_5G:
222 1.1 jmcneill ic->ic_sup_rates[IEEE80211_MODE_11A] = ieee80211_std_rateset_11a;
223 1.1 jmcneill
224 1.11 maya for (j = 0; j < __arraycount(bwfm_5ghz_channels); j++) {
225 1.11 maya uint8_t chan = bwfm_5ghz_channels[j];
226 1.1 jmcneill ic->ic_channels[chan].ic_freq =
227 1.1 jmcneill ieee80211_ieee2mhz(chan, IEEE80211_CHAN_5GHZ);
228 1.1 jmcneill ic->ic_channels[chan].ic_flags =
229 1.1 jmcneill IEEE80211_CHAN_A;
230 1.1 jmcneill }
231 1.1 jmcneill break;
232 1.1 jmcneill }
233 1.1 jmcneill }
234 1.1 jmcneill
235 1.1 jmcneill ifp->if_softc = sc;
236 1.1 jmcneill ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
237 1.1 jmcneill ifp->if_init = bwfm_init;
238 1.1 jmcneill ifp->if_ioctl = bwfm_ioctl;
239 1.1 jmcneill ifp->if_start = bwfm_start;
240 1.1 jmcneill ifp->if_watchdog = bwfm_watchdog;
241 1.1 jmcneill IFQ_SET_READY(&ifp->if_snd);
242 1.1 jmcneill memcpy(ifp->if_xname, DEVNAME(sc), IFNAMSIZ);
243 1.1 jmcneill
244 1.3 msaitoh error = if_initialize(ifp);
245 1.3 msaitoh if (error != 0) {
246 1.3 msaitoh printf("%s: if_initialize failed(%d)\n", DEVNAME(sc), error);
247 1.3 msaitoh pcq_destroy(sc->sc_freetask);
248 1.3 msaitoh workqueue_destroy(sc->sc_taskq);
249 1.3 msaitoh
250 1.3 msaitoh return; /* Error */
251 1.3 msaitoh }
252 1.3 msaitoh
253 1.1 jmcneill ieee80211_ifattach(ic);
254 1.1 jmcneill ifp->if_percpuq = if_percpuq_create(ifp);
255 1.1 jmcneill if_deferred_start_init(ifp, NULL);
256 1.1 jmcneill if_register(ifp);
257 1.1 jmcneill
258 1.1 jmcneill sc->sc_newstate = ic->ic_newstate;
259 1.1 jmcneill ic->ic_newstate = bwfm_newstate;
260 1.4 jmcneill ic->ic_newassoc = bwfm_newassoc;
261 1.1 jmcneill ic->ic_send_mgmt = bwfm_send_mgmt;
262 1.1 jmcneill ic->ic_recv_mgmt = bwfm_recv_mgmt;
263 1.1 jmcneill ic->ic_crypto.cs_key_set = bwfm_key_set;
264 1.1 jmcneill ic->ic_crypto.cs_key_delete = bwfm_key_delete;
265 1.6 jmcneill ieee80211_media_init(ic, bwfm_media_change, ieee80211_media_status);
266 1.1 jmcneill
267 1.1 jmcneill ieee80211_announce(ic);
268 1.1 jmcneill
269 1.1 jmcneill sc->sc_if_attached = true;
270 1.1 jmcneill }
271 1.1 jmcneill
272 1.1 jmcneill int
273 1.1 jmcneill bwfm_detach(struct bwfm_softc *sc, int flags)
274 1.1 jmcneill {
275 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
276 1.1 jmcneill struct ifnet *ifp = ic->ic_ifp;
277 1.1 jmcneill
278 1.1 jmcneill if (sc->sc_if_attached) {
279 1.1 jmcneill bpf_detach(ifp);
280 1.1 jmcneill ieee80211_ifdetach(ic);
281 1.1 jmcneill if_detach(ifp);
282 1.1 jmcneill }
283 1.1 jmcneill
284 1.1 jmcneill if (sc->sc_taskq)
285 1.1 jmcneill workqueue_destroy(sc->sc_taskq);
286 1.1 jmcneill if (sc->sc_freetask)
287 1.1 jmcneill pcq_destroy(sc->sc_freetask);
288 1.1 jmcneill
289 1.1 jmcneill return 0;
290 1.1 jmcneill }
291 1.1 jmcneill
292 1.1 jmcneill void
293 1.1 jmcneill bwfm_start(struct ifnet *ifp)
294 1.1 jmcneill {
295 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
296 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
297 1.1 jmcneill struct mbuf *m;
298 1.1 jmcneill int error;
299 1.1 jmcneill
300 1.1 jmcneill if ((ifp->if_flags & (IFF_RUNNING | IFF_OACTIVE)) != IFF_RUNNING)
301 1.1 jmcneill return;
302 1.1 jmcneill
303 1.1 jmcneill /* TODO: return if no link? */
304 1.1 jmcneill
305 1.1 jmcneill for (;;) {
306 1.1 jmcneill struct ieee80211_node *ni;
307 1.1 jmcneill struct ether_header *eh;
308 1.1 jmcneill
309 1.1 jmcneill /* Discard management packets (fw handles this for us) */
310 1.1 jmcneill IF_DEQUEUE(&ic->ic_mgtq, m);
311 1.1 jmcneill if (m != NULL) {
312 1.1 jmcneill m_freem(m);
313 1.1 jmcneill continue;
314 1.1 jmcneill }
315 1.1 jmcneill
316 1.11 maya if (sc->sc_bus_ops->bs_txcheck(sc)) {
317 1.11 maya ifp->if_flags |= IFF_OACTIVE;
318 1.11 maya break;
319 1.11 maya }
320 1.11 maya
321 1.1 jmcneill IFQ_DEQUEUE(&ifp->if_snd, m);
322 1.1 jmcneill if (m == NULL)
323 1.1 jmcneill break;
324 1.1 jmcneill
325 1.1 jmcneill eh = mtod(m, struct ether_header *);
326 1.1 jmcneill ni = ieee80211_find_txnode(ic, eh->ether_dhost);
327 1.1 jmcneill if (ni == NULL) {
328 1.1 jmcneill ifp->if_oerrors++;
329 1.1 jmcneill m_freem(m);
330 1.1 jmcneill continue;
331 1.1 jmcneill }
332 1.1 jmcneill
333 1.1 jmcneill if (ieee80211_classify(ic, m, ni) != 0) {
334 1.1 jmcneill ifp->if_oerrors++;
335 1.1 jmcneill m_freem(m);
336 1.1 jmcneill ieee80211_free_node(ni);
337 1.1 jmcneill continue;
338 1.1 jmcneill }
339 1.1 jmcneill
340 1.13 riastrad error = sc->sc_bus_ops->bs_txdata(sc, &m);
341 1.1 jmcneill if (error == ENOBUFS) {
342 1.1 jmcneill IF_PREPEND(&ifp->if_snd, m);
343 1.1 jmcneill ifp->if_flags |= IFF_OACTIVE;
344 1.1 jmcneill break;
345 1.1 jmcneill }
346 1.1 jmcneill
347 1.1 jmcneill if (error != 0) {
348 1.1 jmcneill ifp->if_oerrors++;
349 1.1 jmcneill m_freem(m);
350 1.1 jmcneill if (ni != NULL)
351 1.1 jmcneill ieee80211_free_node(ni);
352 1.1 jmcneill } else {
353 1.12 msaitoh bpf_mtap3(ic->ic_rawbpf, m, BPF_D_OUT);
354 1.1 jmcneill }
355 1.1 jmcneill }
356 1.1 jmcneill }
357 1.1 jmcneill
358 1.1 jmcneill int
359 1.1 jmcneill bwfm_init(struct ifnet *ifp)
360 1.1 jmcneill {
361 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
362 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
363 1.1 jmcneill uint8_t evmask[BWFM_EVENT_MASK_LEN];
364 1.1 jmcneill struct bwfm_join_pref_params join_pref[2];
365 1.1 jmcneill
366 1.1 jmcneill if (bwfm_fwvar_var_set_int(sc, "mpc", 1)) {
367 1.1 jmcneill printf("%s: could not set mpc\n", DEVNAME(sc));
368 1.1 jmcneill return EIO;
369 1.1 jmcneill }
370 1.1 jmcneill
371 1.1 jmcneill /* Select target by RSSI (boost on 5GHz) */
372 1.1 jmcneill join_pref[0].type = BWFM_JOIN_PREF_RSSI_DELTA;
373 1.1 jmcneill join_pref[0].len = 2;
374 1.1 jmcneill join_pref[0].rssi_gain = BWFM_JOIN_PREF_RSSI_BOOST;
375 1.1 jmcneill join_pref[0].band = BWFM_JOIN_PREF_BAND_5G;
376 1.1 jmcneill join_pref[1].type = BWFM_JOIN_PREF_RSSI;
377 1.1 jmcneill join_pref[1].len = 2;
378 1.1 jmcneill join_pref[1].rssi_gain = 0;
379 1.1 jmcneill join_pref[1].band = 0;
380 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "join_pref", join_pref,
381 1.1 jmcneill sizeof(join_pref))) {
382 1.1 jmcneill printf("%s: could not set join pref\n", DEVNAME(sc));
383 1.1 jmcneill return EIO;
384 1.1 jmcneill }
385 1.1 jmcneill
386 1.1 jmcneill memset(evmask, 0, sizeof(evmask));
387 1.1 jmcneill
388 1.1 jmcneill #define ENABLE_EVENT(e) evmask[(e) / 8] |= 1 << ((e) % 8)
389 1.1 jmcneill /* Events used to drive the state machine */
390 1.1 jmcneill ENABLE_EVENT(BWFM_E_ASSOC);
391 1.1 jmcneill ENABLE_EVENT(BWFM_E_ESCAN_RESULT);
392 1.1 jmcneill ENABLE_EVENT(BWFM_E_SET_SSID);
393 1.1 jmcneill ENABLE_EVENT(BWFM_E_LINK);
394 1.1 jmcneill #undef ENABLE_EVENT
395 1.1 jmcneill
396 1.1 jmcneill #ifdef BWFM_DEBUG
397 1.1 jmcneill memset(evmask, 0xff, sizeof(evmask));
398 1.1 jmcneill #endif
399 1.1 jmcneill
400 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "event_msgs", evmask, sizeof(evmask))) {
401 1.1 jmcneill printf("%s: could not set event mask\n", DEVNAME(sc));
402 1.1 jmcneill return EIO;
403 1.1 jmcneill }
404 1.1 jmcneill
405 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_SCAN_CHANNEL_TIME,
406 1.1 jmcneill BWFM_DEFAULT_SCAN_CHANNEL_TIME)) {
407 1.1 jmcneill printf("%s: could not set scan channel time\n", DEVNAME(sc));
408 1.1 jmcneill return EIO;
409 1.1 jmcneill }
410 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_SCAN_UNASSOC_TIME,
411 1.1 jmcneill BWFM_DEFAULT_SCAN_UNASSOC_TIME)) {
412 1.1 jmcneill printf("%s: could not set scan unassoc time\n", DEVNAME(sc));
413 1.1 jmcneill return EIO;
414 1.1 jmcneill }
415 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_SCAN_PASSIVE_TIME,
416 1.1 jmcneill BWFM_DEFAULT_SCAN_PASSIVE_TIME)) {
417 1.1 jmcneill printf("%s: could not set scan passive time\n", DEVNAME(sc));
418 1.1 jmcneill return EIO;
419 1.1 jmcneill }
420 1.1 jmcneill
421 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PM, 2)) {
422 1.1 jmcneill printf("%s: could not set power\n", DEVNAME(sc));
423 1.1 jmcneill return EIO;
424 1.1 jmcneill }
425 1.1 jmcneill
426 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "txbf", 1);
427 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_UP, 0);
428 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_INFRA, 1);
429 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_AP, 0);
430 1.1 jmcneill
431 1.1 jmcneill /* Disable all offloading (ARP, NDP, TCP/UDP cksum). */
432 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "arp_ol", 0);
433 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "arpoe", 0);
434 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "ndoe", 0);
435 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "toe", 0);
436 1.1 jmcneill
437 1.7 jmcneill /* Accept all multicast frames. */
438 1.7 jmcneill bwfm_fwvar_var_set_int(sc, "allmulti", 1);
439 1.7 jmcneill
440 1.7 jmcneill /* Setup promiscuous mode */
441 1.7 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PROMISC,
442 1.7 jmcneill (ifp->if_flags & IFF_PROMISC) ? 1 : 0);
443 1.7 jmcneill
444 1.1 jmcneill /*
445 1.1 jmcneill * Tell the firmware supplicant that we are going to handle the
446 1.1 jmcneill * WPA handshake ourselves.
447 1.1 jmcneill */
448 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "sup_wpa", 0);
449 1.1 jmcneill
450 1.1 jmcneill ifp->if_flags |= IFF_RUNNING;
451 1.1 jmcneill ifp->if_flags &= ~IFF_OACTIVE;
452 1.1 jmcneill
453 1.1 jmcneill if (ic->ic_opmode != IEEE80211_M_MONITOR) {
454 1.1 jmcneill if (ic->ic_roaming != IEEE80211_ROAMING_MANUAL)
455 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
456 1.1 jmcneill } else {
457 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_RUN, -1);
458 1.1 jmcneill }
459 1.1 jmcneill
460 1.1 jmcneill return 0;
461 1.1 jmcneill }
462 1.1 jmcneill
463 1.1 jmcneill void
464 1.1 jmcneill bwfm_stop(struct ifnet *ifp, int disable)
465 1.1 jmcneill {
466 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
467 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
468 1.1 jmcneill
469 1.1 jmcneill sc->sc_tx_timer = 0;
470 1.1 jmcneill ifp->if_timer = 0;
471 1.1 jmcneill ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
472 1.1 jmcneill
473 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_DOWN, 1);
474 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PM, 0);
475 1.1 jmcneill
476 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_INIT, -1);
477 1.1 jmcneill }
478 1.1 jmcneill
479 1.1 jmcneill void
480 1.1 jmcneill bwfm_watchdog(struct ifnet *ifp)
481 1.1 jmcneill {
482 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
483 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
484 1.1 jmcneill
485 1.1 jmcneill ifp->if_timer = 0;
486 1.1 jmcneill
487 1.1 jmcneill if (sc->sc_tx_timer > 0) {
488 1.1 jmcneill if (--sc->sc_tx_timer == 0) {
489 1.1 jmcneill printf("%s: device timeout\n", DEVNAME(sc));
490 1.1 jmcneill ifp->if_oerrors++;
491 1.1 jmcneill return;
492 1.1 jmcneill }
493 1.1 jmcneill ifp->if_timer = 1;
494 1.1 jmcneill }
495 1.1 jmcneill ieee80211_watchdog(ic);
496 1.1 jmcneill }
497 1.1 jmcneill
498 1.1 jmcneill int
499 1.1 jmcneill bwfm_ioctl(struct ifnet *ifp, u_long cmd, void *data)
500 1.1 jmcneill {
501 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
502 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
503 1.1 jmcneill int s, error = 0;
504 1.1 jmcneill
505 1.1 jmcneill s = splnet();
506 1.1 jmcneill
507 1.1 jmcneill switch (cmd) {
508 1.1 jmcneill case SIOCSIFFLAGS:
509 1.1 jmcneill if ((error = ifioctl_common(ifp, cmd, data)) != 0)
510 1.1 jmcneill break;
511 1.1 jmcneill switch (ifp->if_flags & (IFF_UP | IFF_RUNNING)) {
512 1.1 jmcneill case IFF_UP | IFF_RUNNING:
513 1.1 jmcneill break;
514 1.1 jmcneill case IFF_UP:
515 1.1 jmcneill bwfm_init(ifp);
516 1.1 jmcneill break;
517 1.1 jmcneill case IFF_RUNNING:
518 1.1 jmcneill bwfm_stop(ifp, 1);
519 1.1 jmcneill break;
520 1.1 jmcneill case 0:
521 1.1 jmcneill break;
522 1.1 jmcneill }
523 1.1 jmcneill break;
524 1.1 jmcneill
525 1.1 jmcneill case SIOCADDMULTI:
526 1.1 jmcneill case SIOCDELMULTI:
527 1.1 jmcneill if ((error = ether_ioctl(ifp, cmd, data)) == ENETRESET) {
528 1.1 jmcneill /* setup multicast filter, etc */
529 1.1 jmcneill error = 0;
530 1.1 jmcneill }
531 1.1 jmcneill break;
532 1.1 jmcneill
533 1.1 jmcneill default:
534 1.1 jmcneill error = ieee80211_ioctl(ic, cmd, data);
535 1.1 jmcneill }
536 1.1 jmcneill
537 1.1 jmcneill if (error == ENETRESET) {
538 1.1 jmcneill if ((ifp->if_flags & IFF_UP) != 0 &&
539 1.1 jmcneill (ifp->if_flags & IFF_RUNNING) != 0 &&
540 1.1 jmcneill ic->ic_roaming != IEEE80211_ROAMING_MANUAL) {
541 1.1 jmcneill bwfm_init(ifp);
542 1.1 jmcneill }
543 1.1 jmcneill error = 0;
544 1.1 jmcneill }
545 1.1 jmcneill
546 1.1 jmcneill splx(s);
547 1.1 jmcneill
548 1.1 jmcneill return error;
549 1.1 jmcneill }
550 1.1 jmcneill
551 1.1 jmcneill int
552 1.1 jmcneill bwfm_send_mgmt(struct ieee80211com *ic, struct ieee80211_node *ni,
553 1.1 jmcneill int type, int arg)
554 1.1 jmcneill {
555 1.1 jmcneill return 0;
556 1.1 jmcneill }
557 1.1 jmcneill
558 1.1 jmcneill void
559 1.1 jmcneill bwfm_recv_mgmt(struct ieee80211com *ic, struct mbuf *m0,
560 1.1 jmcneill struct ieee80211_node *ni, int subtype, int rssi, uint32_t rstamp)
561 1.1 jmcneill {
562 1.1 jmcneill }
563 1.1 jmcneill
564 1.1 jmcneill int
565 1.1 jmcneill bwfm_key_set(struct ieee80211com *ic, const struct ieee80211_key *wk,
566 1.1 jmcneill const uint8_t mac[IEEE80211_ADDR_LEN])
567 1.1 jmcneill {
568 1.1 jmcneill struct bwfm_softc *sc = ic->ic_ifp->if_softc;
569 1.1 jmcneill struct bwfm_task *t;
570 1.1 jmcneill
571 1.1 jmcneill t = pcq_get(sc->sc_freetask);
572 1.1 jmcneill if (t == NULL) {
573 1.1 jmcneill printf("%s: no free tasks\n", DEVNAME(sc));
574 1.1 jmcneill return 0;
575 1.1 jmcneill }
576 1.1 jmcneill
577 1.1 jmcneill t->t_cmd = BWFM_TASK_KEY_SET;
578 1.1 jmcneill t->t_key.key = wk;
579 1.1 jmcneill memcpy(t->t_key.mac, mac, sizeof(t->t_key.mac));
580 1.1 jmcneill workqueue_enqueue(sc->sc_taskq, (struct work *)t, NULL);
581 1.1 jmcneill return 1;
582 1.1 jmcneill }
583 1.1 jmcneill
584 1.1 jmcneill static void
585 1.1 jmcneill bwfm_key_set_cb(struct bwfm_softc *sc, struct bwfm_cmd_key *ck)
586 1.1 jmcneill {
587 1.1 jmcneill const struct ieee80211_key *wk = ck->key;
588 1.1 jmcneill const uint8_t *mac = ck->mac;
589 1.1 jmcneill struct bwfm_wsec_key wsec_key;
590 1.1 jmcneill uint32_t wsec_enable, wsec;
591 1.1 jmcneill bool ext_key;
592 1.1 jmcneill
593 1.1 jmcneill #ifdef BWFM_DEBUG
594 1.1 jmcneill printf("key_set: key cipher %s len %d: ", wk->wk_cipher->ic_name, wk->wk_keylen);
595 1.1 jmcneill for (int j = 0; j < sizeof(wk->wk_key); j++)
596 1.1 jmcneill printf("%02x", wk->wk_key[j]);
597 1.1 jmcneill #endif
598 1.1 jmcneill
599 1.1 jmcneill if ((wk->wk_flags & IEEE80211_KEY_GROUP) == 0 &&
600 1.1 jmcneill wk->wk_cipher->ic_cipher != IEEE80211_CIPHER_WEP) {
601 1.1 jmcneill ext_key = true;
602 1.1 jmcneill } else {
603 1.1 jmcneill ext_key = false;
604 1.1 jmcneill }
605 1.1 jmcneill
606 1.1 jmcneill #ifdef BWFM_DEBUG
607 1.1 jmcneill printf(", ext_key = %d", ext_key);
608 1.1 jmcneill printf(", mac = %02x:%02x:%02x:%02x:%02x:%02x",
609 1.1 jmcneill mac[0], mac[1], mac[2], mac[3], mac[4], mac[5]);
610 1.1 jmcneill printf("\n");
611 1.1 jmcneill #endif
612 1.1 jmcneill
613 1.1 jmcneill memset(&wsec_key, 0, sizeof(wsec_key));
614 1.1 jmcneill if (ext_key && !IEEE80211_IS_MULTICAST(mac))
615 1.1 jmcneill memcpy(wsec_key.ea, mac, sizeof(wsec_key.ea));
616 1.1 jmcneill wsec_key.index = htole32(wk->wk_keyix);
617 1.1 jmcneill wsec_key.len = htole32(wk->wk_keylen);
618 1.1 jmcneill memcpy(wsec_key.data, wk->wk_key, sizeof(wsec_key.data));
619 1.1 jmcneill if (!ext_key)
620 1.1 jmcneill wsec_key.flags = htole32(BWFM_PRIMARY_KEY);
621 1.1 jmcneill
622 1.1 jmcneill switch (wk->wk_cipher->ic_cipher) {
623 1.1 jmcneill case IEEE80211_CIPHER_WEP:
624 1.1 jmcneill if (wk->wk_keylen == 5)
625 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_WEP1);
626 1.1 jmcneill else if (wk->wk_keylen == 13)
627 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_WEP128);
628 1.1 jmcneill else
629 1.1 jmcneill return;
630 1.1 jmcneill wsec_enable = BWFM_WSEC_WEP;
631 1.1 jmcneill break;
632 1.1 jmcneill case IEEE80211_CIPHER_TKIP:
633 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_TKIP);
634 1.1 jmcneill wsec_enable = BWFM_WSEC_TKIP;
635 1.1 jmcneill break;
636 1.1 jmcneill case IEEE80211_CIPHER_AES_CCM:
637 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_AES_CCM);
638 1.1 jmcneill wsec_enable = BWFM_WSEC_AES;
639 1.1 jmcneill break;
640 1.1 jmcneill default:
641 1.1 jmcneill printf("%s: %s: cipher %s not supported\n", DEVNAME(sc),
642 1.1 jmcneill __func__, wk->wk_cipher->ic_name);
643 1.1 jmcneill return;
644 1.1 jmcneill }
645 1.1 jmcneill
646 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "wsec_key", &wsec_key, sizeof(wsec_key)))
647 1.1 jmcneill return;
648 1.1 jmcneill
649 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wpa_auth", BWFM_WPA_AUTH_WPA2_PSK);
650 1.1 jmcneill
651 1.1 jmcneill bwfm_fwvar_var_get_int(sc, "wsec", &wsec);
652 1.1 jmcneill wsec |= wsec_enable;
653 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wsec", wsec);
654 1.1 jmcneill }
655 1.1 jmcneill
656 1.1 jmcneill int
657 1.1 jmcneill bwfm_key_delete(struct ieee80211com *ic, const struct ieee80211_key *wk)
658 1.1 jmcneill {
659 1.1 jmcneill struct bwfm_softc *sc = ic->ic_ifp->if_softc;
660 1.1 jmcneill struct bwfm_task *t;
661 1.1 jmcneill
662 1.1 jmcneill t = pcq_get(sc->sc_freetask);
663 1.1 jmcneill if (t == NULL) {
664 1.1 jmcneill printf("%s: no free tasks\n", DEVNAME(sc));
665 1.1 jmcneill return 0;
666 1.1 jmcneill }
667 1.1 jmcneill
668 1.1 jmcneill t->t_cmd = BWFM_TASK_KEY_DELETE;
669 1.1 jmcneill t->t_key.key = wk;
670 1.1 jmcneill memset(t->t_key.mac, 0, sizeof(t->t_key.mac));
671 1.1 jmcneill workqueue_enqueue(sc->sc_taskq, (struct work *)t, NULL);
672 1.1 jmcneill
673 1.1 jmcneill return 1;
674 1.1 jmcneill }
675 1.1 jmcneill
676 1.1 jmcneill static void
677 1.1 jmcneill bwfm_key_delete_cb(struct bwfm_softc *sc, struct bwfm_cmd_key *ck)
678 1.1 jmcneill {
679 1.1 jmcneill const struct ieee80211_key *wk = ck->key;
680 1.1 jmcneill struct bwfm_wsec_key wsec_key;
681 1.1 jmcneill
682 1.1 jmcneill memset(&wsec_key, 0, sizeof(wsec_key));
683 1.1 jmcneill wsec_key.index = htole32(wk->wk_keyix);
684 1.1 jmcneill wsec_key.flags = htole32(BWFM_PRIMARY_KEY);
685 1.1 jmcneill
686 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "wsec_key", &wsec_key, sizeof(wsec_key)))
687 1.1 jmcneill return;
688 1.1 jmcneill }
689 1.1 jmcneill
690 1.1 jmcneill int
691 1.1 jmcneill bwfm_newstate(struct ieee80211com *ic, enum ieee80211_state nstate, int arg)
692 1.1 jmcneill {
693 1.1 jmcneill struct bwfm_softc *sc = ic->ic_ifp->if_softc;
694 1.1 jmcneill struct bwfm_task *t;
695 1.1 jmcneill
696 1.1 jmcneill t = pcq_get(sc->sc_freetask);
697 1.1 jmcneill if (t == NULL) {
698 1.1 jmcneill printf("%s: no free tasks\n", DEVNAME(sc));
699 1.1 jmcneill return EIO;
700 1.1 jmcneill }
701 1.1 jmcneill
702 1.1 jmcneill t->t_cmd = BWFM_TASK_NEWSTATE;
703 1.1 jmcneill t->t_newstate.state = nstate;
704 1.1 jmcneill t->t_newstate.arg = arg;
705 1.1 jmcneill workqueue_enqueue(sc->sc_taskq, (struct work *)t, NULL);
706 1.1 jmcneill
707 1.1 jmcneill return 0;
708 1.1 jmcneill }
709 1.1 jmcneill
710 1.1 jmcneill void
711 1.1 jmcneill bwfm_newstate_cb(struct bwfm_softc *sc, struct bwfm_cmd_newstate *cmd)
712 1.1 jmcneill {
713 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
714 1.1 jmcneill enum ieee80211_state ostate = ic->ic_state;
715 1.1 jmcneill enum ieee80211_state nstate = cmd->state;
716 1.1 jmcneill int s;
717 1.1 jmcneill
718 1.1 jmcneill DPRINTF(("%s: newstate %d -> %d\n", DEVNAME(sc), ostate, nstate));
719 1.1 jmcneill
720 1.1 jmcneill s = splnet();
721 1.1 jmcneill
722 1.1 jmcneill switch (nstate) {
723 1.1 jmcneill case IEEE80211_S_INIT:
724 1.1 jmcneill break;
725 1.1 jmcneill
726 1.1 jmcneill case IEEE80211_S_SCAN:
727 1.1 jmcneill if (ostate != IEEE80211_S_SCAN) {
728 1.1 jmcneill /* Start of scanning */
729 1.1 jmcneill bwfm_scan(sc);
730 1.1 jmcneill }
731 1.1 jmcneill break;
732 1.1 jmcneill
733 1.1 jmcneill case IEEE80211_S_AUTH:
734 1.1 jmcneill bwfm_connect(sc);
735 1.1 jmcneill break;
736 1.1 jmcneill
737 1.1 jmcneill case IEEE80211_S_ASSOC:
738 1.1 jmcneill break;
739 1.1 jmcneill
740 1.1 jmcneill case IEEE80211_S_RUN:
741 1.1 jmcneill break;
742 1.1 jmcneill }
743 1.1 jmcneill
744 1.1 jmcneill sc->sc_newstate(ic, nstate, cmd->arg);
745 1.1 jmcneill
746 1.1 jmcneill splx(s);
747 1.1 jmcneill }
748 1.1 jmcneill
749 1.1 jmcneill void
750 1.4 jmcneill bwfm_newassoc(struct ieee80211_node *ni, int isnew)
751 1.4 jmcneill {
752 1.4 jmcneill /* Firmware handles rate adaptation for us */
753 1.4 jmcneill ni->ni_txrate = 0;
754 1.4 jmcneill }
755 1.4 jmcneill
756 1.4 jmcneill void
757 1.1 jmcneill bwfm_task(struct work *wk, void *arg)
758 1.1 jmcneill {
759 1.1 jmcneill struct bwfm_task *t = (struct bwfm_task *)wk;
760 1.1 jmcneill struct bwfm_softc *sc = t->t_sc;
761 1.1 jmcneill
762 1.1 jmcneill switch (t->t_cmd) {
763 1.1 jmcneill case BWFM_TASK_NEWSTATE:
764 1.1 jmcneill bwfm_newstate_cb(sc, &t->t_newstate);
765 1.1 jmcneill break;
766 1.1 jmcneill case BWFM_TASK_KEY_SET:
767 1.1 jmcneill bwfm_key_set_cb(sc, &t->t_key);
768 1.1 jmcneill break;
769 1.1 jmcneill case BWFM_TASK_KEY_DELETE:
770 1.1 jmcneill bwfm_key_delete_cb(sc, &t->t_key);
771 1.1 jmcneill break;
772 1.1 jmcneill default:
773 1.1 jmcneill panic("bwfm: unknown task command %d", t->t_cmd);
774 1.1 jmcneill }
775 1.1 jmcneill
776 1.1 jmcneill pcq_put(sc->sc_freetask, t);
777 1.1 jmcneill }
778 1.1 jmcneill
779 1.1 jmcneill int
780 1.1 jmcneill bwfm_media_change(struct ifnet *ifp)
781 1.1 jmcneill {
782 1.1 jmcneill return 0;
783 1.1 jmcneill }
784 1.1 jmcneill
785 1.1 jmcneill /* Chip initialization (SDIO, PCIe) */
786 1.1 jmcneill int
787 1.1 jmcneill bwfm_chip_attach(struct bwfm_softc *sc)
788 1.1 jmcneill {
789 1.1 jmcneill struct bwfm_core *core;
790 1.1 jmcneill int need_socram = 0;
791 1.1 jmcneill int has_socram = 0;
792 1.1 jmcneill int cpu_found = 0;
793 1.1 jmcneill uint32_t val;
794 1.1 jmcneill
795 1.1 jmcneill LIST_INIT(&sc->sc_chip.ch_list);
796 1.1 jmcneill
797 1.1 jmcneill if (sc->sc_buscore_ops->bc_prepare(sc) != 0) {
798 1.1 jmcneill printf("%s: failed buscore prepare\n", DEVNAME(sc));
799 1.1 jmcneill return 1;
800 1.1 jmcneill }
801 1.1 jmcneill
802 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc,
803 1.1 jmcneill BWFM_CHIP_BASE + BWFM_CHIP_REG_CHIPID);
804 1.1 jmcneill sc->sc_chip.ch_chip = BWFM_CHIP_CHIPID_ID(val);
805 1.1 jmcneill sc->sc_chip.ch_chiprev = BWFM_CHIP_CHIPID_REV(val);
806 1.1 jmcneill
807 1.1 jmcneill if ((sc->sc_chip.ch_chip > 0xa000) || (sc->sc_chip.ch_chip < 0x4000))
808 1.1 jmcneill snprintf(sc->sc_chip.ch_name, sizeof(sc->sc_chip.ch_name),
809 1.1 jmcneill "%d", sc->sc_chip.ch_chip);
810 1.1 jmcneill else
811 1.1 jmcneill snprintf(sc->sc_chip.ch_name, sizeof(sc->sc_chip.ch_name),
812 1.1 jmcneill "%x", sc->sc_chip.ch_chip);
813 1.1 jmcneill
814 1.1 jmcneill switch (BWFM_CHIP_CHIPID_TYPE(val))
815 1.1 jmcneill {
816 1.1 jmcneill case BWFM_CHIP_CHIPID_TYPE_SOCI_SB:
817 1.1 jmcneill printf("%s: SoC interconnect SB not implemented\n",
818 1.1 jmcneill DEVNAME(sc));
819 1.1 jmcneill return 1;
820 1.1 jmcneill case BWFM_CHIP_CHIPID_TYPE_SOCI_AI:
821 1.1 jmcneill sc->sc_chip.ch_core_isup = bwfm_chip_ai_isup;
822 1.1 jmcneill sc->sc_chip.ch_core_disable = bwfm_chip_ai_disable;
823 1.1 jmcneill sc->sc_chip.ch_core_reset = bwfm_chip_ai_reset;
824 1.1 jmcneill bwfm_chip_dmp_erom_scan(sc);
825 1.1 jmcneill break;
826 1.1 jmcneill default:
827 1.1 jmcneill printf("%s: SoC interconnect %d unknown\n",
828 1.1 jmcneill DEVNAME(sc), BWFM_CHIP_CHIPID_TYPE(val));
829 1.1 jmcneill return 1;
830 1.1 jmcneill }
831 1.1 jmcneill
832 1.1 jmcneill LIST_FOREACH(core, &sc->sc_chip.ch_list, co_link) {
833 1.1 jmcneill DPRINTF(("%s: 0x%x:%-2d base 0x%08x wrap 0x%08x\n",
834 1.1 jmcneill DEVNAME(sc), core->co_id, core->co_rev,
835 1.1 jmcneill core->co_base, core->co_wrapbase));
836 1.1 jmcneill
837 1.1 jmcneill switch (core->co_id) {
838 1.1 jmcneill case BWFM_AGENT_CORE_ARM_CM3:
839 1.1 jmcneill need_socram = true;
840 1.1 jmcneill /* FALLTHROUGH */
841 1.1 jmcneill case BWFM_AGENT_CORE_ARM_CR4:
842 1.1 jmcneill case BWFM_AGENT_CORE_ARM_CA7:
843 1.1 jmcneill cpu_found = true;
844 1.1 jmcneill break;
845 1.1 jmcneill case BWFM_AGENT_INTERNAL_MEM:
846 1.1 jmcneill has_socram = true;
847 1.1 jmcneill break;
848 1.1 jmcneill default:
849 1.1 jmcneill break;
850 1.1 jmcneill }
851 1.1 jmcneill }
852 1.1 jmcneill
853 1.1 jmcneill if (!cpu_found) {
854 1.1 jmcneill printf("%s: CPU core not detected\n", DEVNAME(sc));
855 1.1 jmcneill return 1;
856 1.1 jmcneill }
857 1.1 jmcneill if (need_socram && !has_socram) {
858 1.1 jmcneill printf("%s: RAM core not provided\n", DEVNAME(sc));
859 1.1 jmcneill return 1;
860 1.1 jmcneill }
861 1.1 jmcneill
862 1.11 maya bwfm_chip_set_passive(sc);
863 1.1 jmcneill
864 1.1 jmcneill if (sc->sc_buscore_ops->bc_reset) {
865 1.1 jmcneill sc->sc_buscore_ops->bc_reset(sc);
866 1.11 maya bwfm_chip_set_passive(sc);
867 1.1 jmcneill }
868 1.1 jmcneill
869 1.11 maya if ((core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4)) != NULL) {
870 1.11 maya bwfm_chip_tcm_ramsize(sc, core);
871 1.11 maya bwfm_chip_tcm_rambase(sc);
872 1.11 maya } else if ((core = bwfm_chip_get_core(sc, BWFM_AGENT_SYS_MEM)) != NULL) {
873 1.11 maya bwfm_chip_sysmem_ramsize(sc, core);
874 1.11 maya bwfm_chip_tcm_rambase(sc);
875 1.11 maya } else if ((core = bwfm_chip_get_core(sc, BWFM_AGENT_INTERNAL_MEM)) != NULL) {
876 1.11 maya bwfm_chip_socram_ramsize(sc, core);
877 1.11 maya }
878 1.1 jmcneill
879 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_CHIPCOMMON);
880 1.1 jmcneill sc->sc_chip.ch_cc_caps = sc->sc_buscore_ops->bc_read(sc,
881 1.1 jmcneill core->co_base + BWFM_CHIP_REG_CAPABILITIES);
882 1.1 jmcneill sc->sc_chip.ch_cc_caps_ext = sc->sc_buscore_ops->bc_read(sc,
883 1.1 jmcneill core->co_base + BWFM_CHIP_REG_CAPABILITIES_EXT);
884 1.1 jmcneill
885 1.1 jmcneill core = bwfm_chip_get_pmu(sc);
886 1.1 jmcneill if (sc->sc_chip.ch_cc_caps & BWFM_CHIP_REG_CAPABILITIES_PMU) {
887 1.1 jmcneill sc->sc_chip.ch_pmucaps = sc->sc_buscore_ops->bc_read(sc,
888 1.1 jmcneill core->co_base + BWFM_CHIP_REG_PMUCAPABILITIES);
889 1.1 jmcneill sc->sc_chip.ch_pmurev = sc->sc_chip.ch_pmucaps &
890 1.1 jmcneill BWFM_CHIP_REG_PMUCAPABILITIES_REV_MASK;
891 1.1 jmcneill }
892 1.1 jmcneill
893 1.1 jmcneill if (sc->sc_buscore_ops->bc_setup)
894 1.1 jmcneill sc->sc_buscore_ops->bc_setup(sc);
895 1.1 jmcneill
896 1.1 jmcneill return 0;
897 1.1 jmcneill }
898 1.1 jmcneill
899 1.1 jmcneill struct bwfm_core *
900 1.1 jmcneill bwfm_chip_get_core(struct bwfm_softc *sc, int id)
901 1.1 jmcneill {
902 1.1 jmcneill struct bwfm_core *core;
903 1.1 jmcneill
904 1.1 jmcneill LIST_FOREACH(core, &sc->sc_chip.ch_list, co_link) {
905 1.1 jmcneill if (core->co_id == id)
906 1.1 jmcneill return core;
907 1.1 jmcneill }
908 1.1 jmcneill
909 1.1 jmcneill return NULL;
910 1.1 jmcneill }
911 1.1 jmcneill
912 1.1 jmcneill struct bwfm_core *
913 1.1 jmcneill bwfm_chip_get_pmu(struct bwfm_softc *sc)
914 1.1 jmcneill {
915 1.1 jmcneill struct bwfm_core *cc, *pmu;
916 1.1 jmcneill
917 1.1 jmcneill cc = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_CHIPCOMMON);
918 1.1 jmcneill if (cc->co_rev >= 35 && sc->sc_chip.ch_cc_caps_ext &
919 1.1 jmcneill BWFM_CHIP_REG_CAPABILITIES_EXT_AOB_PRESENT) {
920 1.1 jmcneill pmu = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_PMU);
921 1.1 jmcneill if (pmu)
922 1.1 jmcneill return pmu;
923 1.1 jmcneill }
924 1.1 jmcneill
925 1.1 jmcneill return cc;
926 1.1 jmcneill }
927 1.1 jmcneill
928 1.1 jmcneill /* Functions for the AI interconnect */
929 1.1 jmcneill int
930 1.1 jmcneill bwfm_chip_ai_isup(struct bwfm_softc *sc, struct bwfm_core *core)
931 1.1 jmcneill {
932 1.1 jmcneill uint32_t ioctl, reset;
933 1.1 jmcneill
934 1.1 jmcneill ioctl = sc->sc_buscore_ops->bc_read(sc,
935 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
936 1.1 jmcneill reset = sc->sc_buscore_ops->bc_read(sc,
937 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL);
938 1.1 jmcneill
939 1.1 jmcneill if (((ioctl & (BWFM_AGENT_IOCTL_FGC | BWFM_AGENT_IOCTL_CLK)) ==
940 1.1 jmcneill BWFM_AGENT_IOCTL_CLK) &&
941 1.1 jmcneill ((reset & BWFM_AGENT_RESET_CTL_RESET) == 0))
942 1.1 jmcneill return 1;
943 1.1 jmcneill
944 1.1 jmcneill return 0;
945 1.1 jmcneill }
946 1.1 jmcneill
947 1.1 jmcneill void
948 1.1 jmcneill bwfm_chip_ai_disable(struct bwfm_softc *sc, struct bwfm_core *core,
949 1.1 jmcneill uint32_t prereset, uint32_t reset)
950 1.1 jmcneill {
951 1.1 jmcneill uint32_t val;
952 1.1 jmcneill int i;
953 1.1 jmcneill
954 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc,
955 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL);
956 1.1 jmcneill if ((val & BWFM_AGENT_RESET_CTL_RESET) == 0) {
957 1.1 jmcneill
958 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
959 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL,
960 1.1 jmcneill prereset | BWFM_AGENT_IOCTL_FGC | BWFM_AGENT_IOCTL_CLK);
961 1.1 jmcneill sc->sc_buscore_ops->bc_read(sc,
962 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
963 1.1 jmcneill
964 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
965 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL,
966 1.1 jmcneill BWFM_AGENT_RESET_CTL_RESET);
967 1.1 jmcneill delay(20);
968 1.1 jmcneill
969 1.1 jmcneill for (i = 300; i > 0; i--) {
970 1.1 jmcneill if (sc->sc_buscore_ops->bc_read(sc,
971 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL) ==
972 1.1 jmcneill BWFM_AGENT_RESET_CTL_RESET)
973 1.1 jmcneill break;
974 1.1 jmcneill }
975 1.1 jmcneill if (i == 0)
976 1.1 jmcneill printf("%s: timeout on core reset\n", DEVNAME(sc));
977 1.1 jmcneill }
978 1.1 jmcneill
979 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
980 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL,
981 1.1 jmcneill reset | BWFM_AGENT_IOCTL_FGC | BWFM_AGENT_IOCTL_CLK);
982 1.1 jmcneill sc->sc_buscore_ops->bc_read(sc,
983 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
984 1.1 jmcneill }
985 1.1 jmcneill
986 1.1 jmcneill void
987 1.1 jmcneill bwfm_chip_ai_reset(struct bwfm_softc *sc, struct bwfm_core *core,
988 1.1 jmcneill uint32_t prereset, uint32_t reset, uint32_t postreset)
989 1.1 jmcneill {
990 1.1 jmcneill int i;
991 1.1 jmcneill
992 1.1 jmcneill bwfm_chip_ai_disable(sc, core, prereset, reset);
993 1.1 jmcneill
994 1.1 jmcneill for (i = 50; i > 0; i--) {
995 1.1 jmcneill if ((sc->sc_buscore_ops->bc_read(sc,
996 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL) &
997 1.1 jmcneill BWFM_AGENT_RESET_CTL_RESET) == 0)
998 1.1 jmcneill break;
999 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
1000 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL, 0);
1001 1.1 jmcneill delay(60);
1002 1.1 jmcneill }
1003 1.1 jmcneill if (i == 0)
1004 1.1 jmcneill printf("%s: timeout on core reset\n", DEVNAME(sc));
1005 1.1 jmcneill
1006 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
1007 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL,
1008 1.1 jmcneill postreset | BWFM_AGENT_IOCTL_CLK);
1009 1.1 jmcneill sc->sc_buscore_ops->bc_read(sc,
1010 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
1011 1.1 jmcneill }
1012 1.1 jmcneill
1013 1.1 jmcneill void
1014 1.1 jmcneill bwfm_chip_dmp_erom_scan(struct bwfm_softc *sc)
1015 1.1 jmcneill {
1016 1.1 jmcneill uint32_t erom, val, base, wrap;
1017 1.1 jmcneill uint8_t type = 0;
1018 1.1 jmcneill uint16_t id;
1019 1.1 jmcneill uint8_t nmw, nsw, rev;
1020 1.1 jmcneill struct bwfm_core *core;
1021 1.1 jmcneill
1022 1.1 jmcneill erom = sc->sc_buscore_ops->bc_read(sc,
1023 1.1 jmcneill BWFM_CHIP_BASE + BWFM_CHIP_REG_EROMPTR);
1024 1.1 jmcneill while (type != BWFM_DMP_DESC_EOT) {
1025 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, erom);
1026 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1027 1.1 jmcneill erom += 4;
1028 1.1 jmcneill
1029 1.1 jmcneill if (type != BWFM_DMP_DESC_COMPONENT)
1030 1.1 jmcneill continue;
1031 1.1 jmcneill
1032 1.1 jmcneill id = (val & BWFM_DMP_COMP_PARTNUM)
1033 1.1 jmcneill >> BWFM_DMP_COMP_PARTNUM_S;
1034 1.1 jmcneill
1035 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, erom);
1036 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1037 1.1 jmcneill erom += 4;
1038 1.1 jmcneill
1039 1.1 jmcneill if (type != BWFM_DMP_DESC_COMPONENT) {
1040 1.1 jmcneill printf("%s: not component descriptor\n", DEVNAME(sc));
1041 1.1 jmcneill return;
1042 1.1 jmcneill }
1043 1.1 jmcneill
1044 1.1 jmcneill nmw = (val & BWFM_DMP_COMP_NUM_MWRAP)
1045 1.1 jmcneill >> BWFM_DMP_COMP_NUM_MWRAP_S;
1046 1.1 jmcneill nsw = (val & BWFM_DMP_COMP_NUM_SWRAP)
1047 1.1 jmcneill >> BWFM_DMP_COMP_NUM_SWRAP_S;
1048 1.1 jmcneill rev = (val & BWFM_DMP_COMP_REVISION)
1049 1.1 jmcneill >> BWFM_DMP_COMP_REVISION_S;
1050 1.1 jmcneill
1051 1.1 jmcneill if (nmw + nsw == 0 && id != BWFM_AGENT_CORE_PMU)
1052 1.1 jmcneill continue;
1053 1.1 jmcneill
1054 1.1 jmcneill if (bwfm_chip_dmp_get_regaddr(sc, &erom, &base, &wrap))
1055 1.1 jmcneill continue;
1056 1.1 jmcneill
1057 1.1 jmcneill core = kmem_alloc(sizeof(*core), KM_SLEEP);
1058 1.1 jmcneill core->co_id = id;
1059 1.1 jmcneill core->co_base = base;
1060 1.1 jmcneill core->co_wrapbase = wrap;
1061 1.1 jmcneill core->co_rev = rev;
1062 1.1 jmcneill LIST_INSERT_HEAD(&sc->sc_chip.ch_list, core, co_link);
1063 1.1 jmcneill }
1064 1.1 jmcneill }
1065 1.1 jmcneill
1066 1.1 jmcneill int
1067 1.1 jmcneill bwfm_chip_dmp_get_regaddr(struct bwfm_softc *sc, uint32_t *erom,
1068 1.1 jmcneill uint32_t *base, uint32_t *wrap)
1069 1.1 jmcneill {
1070 1.1 jmcneill uint8_t type = 0, mpnum __unused = 0;
1071 1.1 jmcneill uint8_t stype, sztype, wraptype;
1072 1.1 jmcneill uint32_t val;
1073 1.1 jmcneill
1074 1.1 jmcneill *base = 0;
1075 1.1 jmcneill *wrap = 0;
1076 1.1 jmcneill
1077 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, *erom);
1078 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1079 1.1 jmcneill if (type == BWFM_DMP_DESC_MASTER_PORT) {
1080 1.1 jmcneill mpnum = (val & BWFM_DMP_MASTER_PORT_NUM)
1081 1.1 jmcneill >> BWFM_DMP_MASTER_PORT_NUM_S;
1082 1.1 jmcneill wraptype = BWFM_DMP_SLAVE_TYPE_MWRAP;
1083 1.1 jmcneill *erom += 4;
1084 1.1 jmcneill } else if ((type & ~BWFM_DMP_DESC_ADDRSIZE_GT32) ==
1085 1.1 jmcneill BWFM_DMP_DESC_ADDRESS)
1086 1.1 jmcneill wraptype = BWFM_DMP_SLAVE_TYPE_SWRAP;
1087 1.1 jmcneill else
1088 1.1 jmcneill return 1;
1089 1.1 jmcneill
1090 1.1 jmcneill do {
1091 1.1 jmcneill do {
1092 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, *erom);
1093 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1094 1.1 jmcneill if (type == BWFM_DMP_DESC_COMPONENT)
1095 1.1 jmcneill return 0;
1096 1.1 jmcneill if (type == BWFM_DMP_DESC_EOT)
1097 1.1 jmcneill return 1;
1098 1.1 jmcneill *erom += 4;
1099 1.1 jmcneill } while ((type & ~BWFM_DMP_DESC_ADDRSIZE_GT32) !=
1100 1.1 jmcneill BWFM_DMP_DESC_ADDRESS);
1101 1.1 jmcneill
1102 1.1 jmcneill if (type & BWFM_DMP_DESC_ADDRSIZE_GT32)
1103 1.1 jmcneill *erom += 4;
1104 1.1 jmcneill
1105 1.1 jmcneill sztype = (val & BWFM_DMP_SLAVE_SIZE_TYPE)
1106 1.1 jmcneill >> BWFM_DMP_SLAVE_SIZE_TYPE_S;
1107 1.1 jmcneill if (sztype == BWFM_DMP_SLAVE_SIZE_DESC) {
1108 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, *erom);
1109 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1110 1.1 jmcneill if (type & BWFM_DMP_DESC_ADDRSIZE_GT32)
1111 1.1 jmcneill *erom += 8;
1112 1.1 jmcneill else
1113 1.1 jmcneill *erom += 4;
1114 1.1 jmcneill }
1115 1.1 jmcneill if (sztype != BWFM_DMP_SLAVE_SIZE_4K)
1116 1.1 jmcneill continue;
1117 1.1 jmcneill
1118 1.1 jmcneill stype = (val & BWFM_DMP_SLAVE_TYPE) >> BWFM_DMP_SLAVE_TYPE_S;
1119 1.1 jmcneill if (*base == 0 && stype == BWFM_DMP_SLAVE_TYPE_SLAVE)
1120 1.1 jmcneill *base = val & BWFM_DMP_SLAVE_ADDR_BASE;
1121 1.1 jmcneill if (*wrap == 0 && stype == wraptype)
1122 1.1 jmcneill *wrap = val & BWFM_DMP_SLAVE_ADDR_BASE;
1123 1.1 jmcneill } while (*base == 0 || *wrap == 0);
1124 1.1 jmcneill
1125 1.1 jmcneill return 0;
1126 1.1 jmcneill }
1127 1.1 jmcneill
1128 1.1 jmcneill /* Core configuration */
1129 1.11 maya int
1130 1.11 maya bwfm_chip_set_active(struct bwfm_softc *sc, const uint32_t rstvec)
1131 1.11 maya {
1132 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4) != NULL)
1133 1.11 maya return bwfm_chip_cr4_set_active(sc, rstvec);
1134 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7) != NULL)
1135 1.11 maya return bwfm_chip_ca7_set_active(sc, rstvec);
1136 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3) != NULL)
1137 1.11 maya return bwfm_chip_cm3_set_active(sc);
1138 1.11 maya return 1;
1139 1.11 maya }
1140 1.11 maya
1141 1.11 maya void
1142 1.11 maya bwfm_chip_set_passive(struct bwfm_softc *sc)
1143 1.11 maya {
1144 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4) != NULL) {
1145 1.11 maya bwfm_chip_cr4_set_passive(sc);
1146 1.11 maya return;
1147 1.11 maya }
1148 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7) != NULL) {
1149 1.11 maya bwfm_chip_ca7_set_passive(sc);
1150 1.11 maya return;
1151 1.11 maya }
1152 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3) != NULL) {
1153 1.11 maya bwfm_chip_cm3_set_passive(sc);
1154 1.11 maya return;
1155 1.11 maya }
1156 1.11 maya }
1157 1.11 maya
1158 1.11 maya int
1159 1.11 maya bwfm_chip_cr4_set_active(struct bwfm_softc *sc, const uint32_t rstvec)
1160 1.11 maya {
1161 1.11 maya struct bwfm_core *core;
1162 1.11 maya
1163 1.11 maya sc->sc_buscore_ops->bc_activate(sc, rstvec);
1164 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4);
1165 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1166 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT, 0, 0);
1167 1.11 maya
1168 1.11 maya return 0;
1169 1.11 maya }
1170 1.11 maya
1171 1.1 jmcneill void
1172 1.1 jmcneill bwfm_chip_cr4_set_passive(struct bwfm_softc *sc)
1173 1.1 jmcneill {
1174 1.11 maya struct bwfm_core *core;
1175 1.11 maya uint32_t val;
1176 1.11 maya
1177 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4);
1178 1.11 maya val = sc->sc_buscore_ops->bc_read(sc,
1179 1.11 maya core->co_wrapbase + BWFM_AGENT_IOCTL);
1180 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1181 1.11 maya val & BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1182 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1183 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT);
1184 1.11 maya
1185 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_80211);
1186 1.11 maya sc->sc_chip.ch_core_reset(sc, core, BWFM_AGENT_D11_IOCTL_PHYRESET |
1187 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN, BWFM_AGENT_D11_IOCTL_PHYCLOCKEN,
1188 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN);
1189 1.11 maya }
1190 1.11 maya
1191 1.11 maya int
1192 1.11 maya bwfm_chip_ca7_set_active(struct bwfm_softc *sc, const uint32_t rstvec)
1193 1.11 maya {
1194 1.11 maya struct bwfm_core *core;
1195 1.11 maya
1196 1.11 maya sc->sc_buscore_ops->bc_activate(sc, rstvec);
1197 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7);
1198 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1199 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT, 0, 0);
1200 1.11 maya
1201 1.11 maya return 0;
1202 1.1 jmcneill }
1203 1.1 jmcneill
1204 1.1 jmcneill void
1205 1.1 jmcneill bwfm_chip_ca7_set_passive(struct bwfm_softc *sc)
1206 1.1 jmcneill {
1207 1.11 maya struct bwfm_core *core;
1208 1.11 maya uint32_t val;
1209 1.11 maya
1210 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7);
1211 1.11 maya val = sc->sc_buscore_ops->bc_read(sc,
1212 1.11 maya core->co_wrapbase + BWFM_AGENT_IOCTL);
1213 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1214 1.11 maya val & BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1215 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1216 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT);
1217 1.11 maya
1218 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_80211);
1219 1.11 maya sc->sc_chip.ch_core_reset(sc, core, BWFM_AGENT_D11_IOCTL_PHYRESET |
1220 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN, BWFM_AGENT_D11_IOCTL_PHYCLOCKEN,
1221 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN);
1222 1.11 maya }
1223 1.11 maya
1224 1.11 maya int
1225 1.11 maya bwfm_chip_cm3_set_active(struct bwfm_softc *sc)
1226 1.11 maya {
1227 1.11 maya struct bwfm_core *core;
1228 1.11 maya
1229 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_INTERNAL_MEM);
1230 1.11 maya if (!sc->sc_chip.ch_core_isup(sc, core))
1231 1.11 maya return 1;
1232 1.11 maya
1233 1.11 maya sc->sc_buscore_ops->bc_activate(sc, 0);
1234 1.11 maya
1235 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3);
1236 1.11 maya sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1237 1.11 maya
1238 1.11 maya return 0;
1239 1.1 jmcneill }
1240 1.1 jmcneill
1241 1.1 jmcneill void
1242 1.1 jmcneill bwfm_chip_cm3_set_passive(struct bwfm_softc *sc)
1243 1.1 jmcneill {
1244 1.1 jmcneill struct bwfm_core *core;
1245 1.1 jmcneill
1246 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3);
1247 1.1 jmcneill sc->sc_chip.ch_core_disable(sc, core, 0, 0);
1248 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_80211);
1249 1.1 jmcneill sc->sc_chip.ch_core_reset(sc, core, BWFM_AGENT_D11_IOCTL_PHYRESET |
1250 1.1 jmcneill BWFM_AGENT_D11_IOCTL_PHYCLOCKEN, BWFM_AGENT_D11_IOCTL_PHYCLOCKEN,
1251 1.1 jmcneill BWFM_AGENT_D11_IOCTL_PHYCLOCKEN);
1252 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_INTERNAL_MEM);
1253 1.1 jmcneill sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1254 1.1 jmcneill
1255 1.1 jmcneill if (sc->sc_chip.ch_chip == BRCM_CC_43430_CHIP_ID) {
1256 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
1257 1.1 jmcneill core->co_base + BWFM_SOCRAM_BANKIDX, 3);
1258 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
1259 1.1 jmcneill core->co_base + BWFM_SOCRAM_BANKPDA, 0);
1260 1.1 jmcneill }
1261 1.1 jmcneill }
1262 1.1 jmcneill
1263 1.11 maya /* RAM size helpers */
1264 1.11 maya void
1265 1.11 maya bwfm_chip_socram_ramsize(struct bwfm_softc *sc, struct bwfm_core *core)
1266 1.11 maya {
1267 1.11 maya uint32_t coreinfo, nb, lss, banksize, bankinfo;
1268 1.11 maya uint32_t ramsize = 0, srsize = 0;
1269 1.11 maya int i;
1270 1.11 maya
1271 1.11 maya if (!sc->sc_chip.ch_core_isup(sc, core))
1272 1.11 maya sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1273 1.11 maya
1274 1.11 maya coreinfo = sc->sc_buscore_ops->bc_read(sc,
1275 1.11 maya core->co_base + BWFM_SOCRAM_COREINFO);
1276 1.11 maya nb = (coreinfo & BWFM_SOCRAM_COREINFO_SRNB_MASK)
1277 1.11 maya >> BWFM_SOCRAM_COREINFO_SRNB_SHIFT;
1278 1.11 maya
1279 1.11 maya if (core->co_rev <= 7 || core->co_rev == 12) {
1280 1.11 maya banksize = coreinfo & BWFM_SOCRAM_COREINFO_SRBSZ_MASK;
1281 1.11 maya lss = (coreinfo & BWFM_SOCRAM_COREINFO_LSS_MASK)
1282 1.11 maya >> BWFM_SOCRAM_COREINFO_LSS_SHIFT;
1283 1.11 maya if (lss != 0)
1284 1.11 maya nb--;
1285 1.11 maya ramsize = nb * (1 << (banksize + BWFM_SOCRAM_COREINFO_SRBSZ_BASE));
1286 1.11 maya if (lss != 0)
1287 1.11 maya ramsize += (1 << ((lss - 1) + BWFM_SOCRAM_COREINFO_SRBSZ_BASE));
1288 1.11 maya } else {
1289 1.11 maya for (i = 0; i < nb; i++) {
1290 1.11 maya sc->sc_buscore_ops->bc_write(sc,
1291 1.11 maya core->co_base + BWFM_SOCRAM_BANKIDX,
1292 1.11 maya (BWFM_SOCRAM_BANKIDX_MEMTYPE_RAM <<
1293 1.11 maya BWFM_SOCRAM_BANKIDX_MEMTYPE_SHIFT) | i);
1294 1.11 maya bankinfo = sc->sc_buscore_ops->bc_read(sc,
1295 1.11 maya core->co_base + BWFM_SOCRAM_BANKINFO);
1296 1.11 maya banksize = ((bankinfo & BWFM_SOCRAM_BANKINFO_SZMASK) + 1)
1297 1.11 maya * BWFM_SOCRAM_BANKINFO_SZBASE;
1298 1.11 maya ramsize += banksize;
1299 1.11 maya if (bankinfo & BWFM_SOCRAM_BANKINFO_RETNTRAM_MASK)
1300 1.11 maya srsize += banksize;
1301 1.11 maya }
1302 1.11 maya }
1303 1.11 maya
1304 1.11 maya switch (sc->sc_chip.ch_chip) {
1305 1.11 maya case BRCM_CC_4334_CHIP_ID:
1306 1.11 maya if (sc->sc_chip.ch_chiprev < 2)
1307 1.11 maya srsize = 32 * 1024;
1308 1.11 maya break;
1309 1.11 maya case BRCM_CC_43430_CHIP_ID:
1310 1.11 maya srsize = 64 * 1024;
1311 1.11 maya break;
1312 1.11 maya default:
1313 1.11 maya break;
1314 1.11 maya }
1315 1.11 maya
1316 1.11 maya sc->sc_chip.ch_ramsize = ramsize;
1317 1.11 maya sc->sc_chip.ch_srsize = srsize;
1318 1.11 maya }
1319 1.11 maya
1320 1.11 maya void
1321 1.11 maya bwfm_chip_sysmem_ramsize(struct bwfm_softc *sc, struct bwfm_core *core)
1322 1.11 maya {
1323 1.11 maya uint32_t coreinfo, nb, banksize, bankinfo;
1324 1.11 maya uint32_t ramsize = 0;
1325 1.11 maya int i;
1326 1.11 maya
1327 1.11 maya if (!sc->sc_chip.ch_core_isup(sc, core))
1328 1.11 maya sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1329 1.11 maya
1330 1.11 maya coreinfo = sc->sc_buscore_ops->bc_read(sc,
1331 1.11 maya core->co_base + BWFM_SOCRAM_COREINFO);
1332 1.11 maya nb = (coreinfo & BWFM_SOCRAM_COREINFO_SRNB_MASK)
1333 1.11 maya >> BWFM_SOCRAM_COREINFO_SRNB_SHIFT;
1334 1.11 maya
1335 1.11 maya for (i = 0; i < nb; i++) {
1336 1.11 maya sc->sc_buscore_ops->bc_write(sc,
1337 1.11 maya core->co_base + BWFM_SOCRAM_BANKIDX,
1338 1.11 maya (BWFM_SOCRAM_BANKIDX_MEMTYPE_RAM <<
1339 1.11 maya BWFM_SOCRAM_BANKIDX_MEMTYPE_SHIFT) | i);
1340 1.11 maya bankinfo = sc->sc_buscore_ops->bc_read(sc,
1341 1.11 maya core->co_base + BWFM_SOCRAM_BANKINFO);
1342 1.11 maya banksize = ((bankinfo & BWFM_SOCRAM_BANKINFO_SZMASK) + 1)
1343 1.11 maya * BWFM_SOCRAM_BANKINFO_SZBASE;
1344 1.11 maya ramsize += banksize;
1345 1.11 maya }
1346 1.11 maya
1347 1.11 maya sc->sc_chip.ch_ramsize = ramsize;
1348 1.11 maya }
1349 1.11 maya
1350 1.11 maya void
1351 1.11 maya bwfm_chip_tcm_ramsize(struct bwfm_softc *sc, struct bwfm_core *core)
1352 1.11 maya {
1353 1.11 maya uint32_t cap, nab, nbb, totb, bxinfo, ramsize = 0;
1354 1.11 maya int i;
1355 1.11 maya
1356 1.11 maya cap = sc->sc_buscore_ops->bc_read(sc, core->co_base + BWFM_ARMCR4_CAP);
1357 1.11 maya nab = (cap & BWFM_ARMCR4_CAP_TCBANB_MASK) >> BWFM_ARMCR4_CAP_TCBANB_SHIFT;
1358 1.11 maya nbb = (cap & BWFM_ARMCR4_CAP_TCBBNB_MASK) >> BWFM_ARMCR4_CAP_TCBBNB_SHIFT;
1359 1.11 maya totb = nab + nbb;
1360 1.11 maya
1361 1.11 maya for (i = 0; i < totb; i++) {
1362 1.11 maya sc->sc_buscore_ops->bc_write(sc,
1363 1.11 maya core->co_base + BWFM_ARMCR4_BANKIDX, i);
1364 1.11 maya bxinfo = sc->sc_buscore_ops->bc_read(sc,
1365 1.11 maya core->co_base + BWFM_ARMCR4_BANKINFO);
1366 1.11 maya ramsize += ((bxinfo & BWFM_ARMCR4_BANKINFO_BSZ_MASK) + 1) *
1367 1.11 maya BWFM_ARMCR4_BANKINFO_BSZ_MULT;
1368 1.11 maya }
1369 1.11 maya
1370 1.11 maya sc->sc_chip.ch_ramsize = ramsize;
1371 1.11 maya }
1372 1.11 maya
1373 1.11 maya void
1374 1.11 maya bwfm_chip_tcm_rambase(struct bwfm_softc *sc)
1375 1.11 maya {
1376 1.11 maya switch (sc->sc_chip.ch_chip) {
1377 1.11 maya case BRCM_CC_4345_CHIP_ID:
1378 1.11 maya sc->sc_chip.ch_rambase = 0x198000;
1379 1.11 maya break;
1380 1.11 maya case BRCM_CC_4335_CHIP_ID:
1381 1.11 maya case BRCM_CC_4339_CHIP_ID:
1382 1.11 maya case BRCM_CC_4350_CHIP_ID:
1383 1.11 maya case BRCM_CC_4354_CHIP_ID:
1384 1.11 maya case BRCM_CC_4356_CHIP_ID:
1385 1.11 maya case BRCM_CC_43567_CHIP_ID:
1386 1.11 maya case BRCM_CC_43569_CHIP_ID:
1387 1.11 maya case BRCM_CC_43570_CHIP_ID:
1388 1.11 maya case BRCM_CC_4358_CHIP_ID:
1389 1.11 maya case BRCM_CC_4359_CHIP_ID:
1390 1.11 maya case BRCM_CC_43602_CHIP_ID:
1391 1.11 maya case BRCM_CC_4371_CHIP_ID:
1392 1.11 maya sc->sc_chip.ch_rambase = 0x180000;
1393 1.11 maya break;
1394 1.11 maya case BRCM_CC_43465_CHIP_ID:
1395 1.11 maya case BRCM_CC_43525_CHIP_ID:
1396 1.11 maya case BRCM_CC_4365_CHIP_ID:
1397 1.11 maya case BRCM_CC_4366_CHIP_ID:
1398 1.11 maya sc->sc_chip.ch_rambase = 0x200000;
1399 1.11 maya break;
1400 1.11 maya case CY_CC_4373_CHIP_ID:
1401 1.11 maya sc->sc_chip.ch_rambase = 0x160000;
1402 1.11 maya break;
1403 1.11 maya default:
1404 1.11 maya printf("%s: unknown chip: %d\n", DEVNAME(sc),
1405 1.11 maya sc->sc_chip.ch_chip);
1406 1.11 maya break;
1407 1.11 maya }
1408 1.11 maya }
1409 1.11 maya
1410 1.1 jmcneill /* BCDC protocol implementation */
1411 1.1 jmcneill int
1412 1.1 jmcneill bwfm_proto_bcdc_query_dcmd(struct bwfm_softc *sc, int ifidx,
1413 1.1 jmcneill int cmd, char *buf, size_t *len)
1414 1.1 jmcneill {
1415 1.1 jmcneill struct bwfm_proto_bcdc_dcmd *dcmd;
1416 1.1 jmcneill size_t size = sizeof(dcmd->hdr) + *len;
1417 1.1 jmcneill static int reqid = 0;
1418 1.1 jmcneill int ret = 1;
1419 1.1 jmcneill
1420 1.1 jmcneill reqid++;
1421 1.1 jmcneill
1422 1.1 jmcneill dcmd = kmem_zalloc(sizeof(*dcmd), KM_SLEEP);
1423 1.1 jmcneill if (*len > sizeof(dcmd->buf))
1424 1.1 jmcneill goto err;
1425 1.1 jmcneill
1426 1.1 jmcneill dcmd->hdr.cmd = htole32(cmd);
1427 1.1 jmcneill dcmd->hdr.len = htole32(*len);
1428 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_GET;
1429 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_ID_SET(reqid);
1430 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_IF_SET(ifidx);
1431 1.1 jmcneill dcmd->hdr.flags = htole32(dcmd->hdr.flags);
1432 1.1 jmcneill memcpy(&dcmd->buf, buf, *len);
1433 1.1 jmcneill
1434 1.1 jmcneill if (sc->sc_bus_ops->bs_txctl(sc, (void *)dcmd,
1435 1.1 jmcneill sizeof(dcmd->hdr) + *len)) {
1436 1.1 jmcneill DPRINTF(("%s: tx failed\n", DEVNAME(sc)));
1437 1.1 jmcneill goto err;
1438 1.1 jmcneill }
1439 1.1 jmcneill
1440 1.1 jmcneill do {
1441 1.1 jmcneill if (sc->sc_bus_ops->bs_rxctl(sc, (void *)dcmd, &size)) {
1442 1.1 jmcneill DPRINTF(("%s: rx failed\n", DEVNAME(sc)));
1443 1.1 jmcneill goto err;
1444 1.1 jmcneill }
1445 1.1 jmcneill dcmd->hdr.cmd = le32toh(dcmd->hdr.cmd);
1446 1.1 jmcneill dcmd->hdr.len = le32toh(dcmd->hdr.len);
1447 1.1 jmcneill dcmd->hdr.flags = le32toh(dcmd->hdr.flags);
1448 1.1 jmcneill dcmd->hdr.status = le32toh(dcmd->hdr.status);
1449 1.1 jmcneill } while (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid);
1450 1.1 jmcneill
1451 1.1 jmcneill if (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid) {
1452 1.1 jmcneill printf("%s: unexpected request id\n", DEVNAME(sc));
1453 1.1 jmcneill goto err;
1454 1.1 jmcneill }
1455 1.1 jmcneill
1456 1.1 jmcneill if (buf) {
1457 1.1 jmcneill if (size > *len)
1458 1.1 jmcneill size = *len;
1459 1.1 jmcneill if (size < *len)
1460 1.1 jmcneill *len = size;
1461 1.1 jmcneill memcpy(buf, dcmd->buf, *len);
1462 1.1 jmcneill }
1463 1.1 jmcneill
1464 1.1 jmcneill if (dcmd->hdr.flags & BWFM_BCDC_DCMD_ERROR)
1465 1.1 jmcneill ret = dcmd->hdr.status;
1466 1.1 jmcneill else
1467 1.1 jmcneill ret = 0;
1468 1.1 jmcneill err:
1469 1.1 jmcneill kmem_free(dcmd, sizeof(*dcmd));
1470 1.1 jmcneill return ret;
1471 1.1 jmcneill }
1472 1.1 jmcneill
1473 1.1 jmcneill int
1474 1.1 jmcneill bwfm_proto_bcdc_set_dcmd(struct bwfm_softc *sc, int ifidx,
1475 1.1 jmcneill int cmd, char *buf, size_t len)
1476 1.1 jmcneill {
1477 1.1 jmcneill struct bwfm_proto_bcdc_dcmd *dcmd;
1478 1.1 jmcneill size_t size = sizeof(dcmd->hdr) + len;
1479 1.1 jmcneill int reqid = 0;
1480 1.1 jmcneill int ret = 1;
1481 1.1 jmcneill
1482 1.1 jmcneill reqid++;
1483 1.1 jmcneill
1484 1.1 jmcneill dcmd = kmem_zalloc(sizeof(*dcmd), KM_SLEEP);
1485 1.1 jmcneill if (len > sizeof(dcmd->buf))
1486 1.1 jmcneill goto err;
1487 1.1 jmcneill
1488 1.1 jmcneill dcmd->hdr.cmd = htole32(cmd);
1489 1.1 jmcneill dcmd->hdr.len = htole32(len);
1490 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_SET;
1491 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_ID_SET(reqid);
1492 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_IF_SET(ifidx);
1493 1.1 jmcneill dcmd->hdr.flags = htole32(dcmd->hdr.flags);
1494 1.1 jmcneill memcpy(&dcmd->buf, buf, len);
1495 1.1 jmcneill
1496 1.1 jmcneill if (sc->sc_bus_ops->bs_txctl(sc, (void *)dcmd, size)) {
1497 1.1 jmcneill DPRINTF(("%s: tx failed\n", DEVNAME(sc)));
1498 1.1 jmcneill goto err;
1499 1.1 jmcneill }
1500 1.1 jmcneill
1501 1.1 jmcneill do {
1502 1.1 jmcneill if (sc->sc_bus_ops->bs_rxctl(sc, (void *)dcmd, &size)) {
1503 1.1 jmcneill DPRINTF(("%s: rx failed\n", DEVNAME(sc)));
1504 1.1 jmcneill goto err;
1505 1.1 jmcneill }
1506 1.1 jmcneill dcmd->hdr.cmd = le32toh(dcmd->hdr.cmd);
1507 1.1 jmcneill dcmd->hdr.len = le32toh(dcmd->hdr.len);
1508 1.1 jmcneill dcmd->hdr.flags = le32toh(dcmd->hdr.flags);
1509 1.1 jmcneill dcmd->hdr.status = le32toh(dcmd->hdr.status);
1510 1.1 jmcneill } while (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid);
1511 1.1 jmcneill
1512 1.1 jmcneill if (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid) {
1513 1.1 jmcneill printf("%s: unexpected request id\n", DEVNAME(sc));
1514 1.1 jmcneill goto err;
1515 1.1 jmcneill }
1516 1.1 jmcneill
1517 1.1 jmcneill if (dcmd->hdr.flags & BWFM_BCDC_DCMD_ERROR)
1518 1.1 jmcneill return dcmd->hdr.status;
1519 1.1 jmcneill
1520 1.1 jmcneill ret = 0;
1521 1.1 jmcneill err:
1522 1.1 jmcneill kmem_free(dcmd, sizeof(*dcmd));
1523 1.1 jmcneill return ret;
1524 1.1 jmcneill }
1525 1.1 jmcneill
1526 1.1 jmcneill /* FW Variable code */
1527 1.1 jmcneill int
1528 1.1 jmcneill bwfm_fwvar_cmd_get_data(struct bwfm_softc *sc, int cmd, void *data, size_t len)
1529 1.1 jmcneill {
1530 1.1 jmcneill return sc->sc_proto_ops->proto_query_dcmd(sc, 0, cmd, data, &len);
1531 1.1 jmcneill }
1532 1.1 jmcneill
1533 1.1 jmcneill int
1534 1.1 jmcneill bwfm_fwvar_cmd_set_data(struct bwfm_softc *sc, int cmd, void *data, size_t len)
1535 1.1 jmcneill {
1536 1.1 jmcneill return sc->sc_proto_ops->proto_set_dcmd(sc, 0, cmd, data, len);
1537 1.1 jmcneill }
1538 1.1 jmcneill
1539 1.1 jmcneill int
1540 1.1 jmcneill bwfm_fwvar_cmd_get_int(struct bwfm_softc *sc, int cmd, uint32_t *data)
1541 1.1 jmcneill {
1542 1.1 jmcneill int ret;
1543 1.1 jmcneill ret = bwfm_fwvar_cmd_get_data(sc, cmd, data, sizeof(*data));
1544 1.1 jmcneill *data = le32toh(*data);
1545 1.1 jmcneill return ret;
1546 1.1 jmcneill }
1547 1.1 jmcneill
1548 1.1 jmcneill int
1549 1.1 jmcneill bwfm_fwvar_cmd_set_int(struct bwfm_softc *sc, int cmd, uint32_t data)
1550 1.1 jmcneill {
1551 1.1 jmcneill data = htole32(data);
1552 1.1 jmcneill return bwfm_fwvar_cmd_set_data(sc, cmd, &data, sizeof(data));
1553 1.1 jmcneill }
1554 1.1 jmcneill
1555 1.1 jmcneill int
1556 1.1 jmcneill bwfm_fwvar_var_get_data(struct bwfm_softc *sc, const char *name, void *data, size_t len)
1557 1.1 jmcneill {
1558 1.1 jmcneill char *buf;
1559 1.1 jmcneill int ret;
1560 1.1 jmcneill
1561 1.1 jmcneill buf = kmem_alloc(strlen(name) + 1 + len, KM_SLEEP);
1562 1.1 jmcneill memcpy(buf, name, strlen(name) + 1);
1563 1.1 jmcneill memcpy(buf + strlen(name) + 1, data, len);
1564 1.1 jmcneill ret = bwfm_fwvar_cmd_get_data(sc, BWFM_C_GET_VAR,
1565 1.1 jmcneill buf, strlen(name) + 1 + len);
1566 1.1 jmcneill memcpy(data, buf, len);
1567 1.1 jmcneill kmem_free(buf, strlen(name) + 1 + len);
1568 1.1 jmcneill return ret;
1569 1.1 jmcneill }
1570 1.1 jmcneill
1571 1.1 jmcneill int
1572 1.1 jmcneill bwfm_fwvar_var_set_data(struct bwfm_softc *sc, const char *name, void *data, size_t len)
1573 1.1 jmcneill {
1574 1.1 jmcneill char *buf;
1575 1.1 jmcneill int ret;
1576 1.1 jmcneill
1577 1.1 jmcneill buf = kmem_alloc(strlen(name) + 1 + len, KM_SLEEP);
1578 1.1 jmcneill memcpy(buf, name, strlen(name) + 1);
1579 1.1 jmcneill memcpy(buf + strlen(name) + 1, data, len);
1580 1.1 jmcneill ret = bwfm_fwvar_cmd_set_data(sc, BWFM_C_SET_VAR,
1581 1.1 jmcneill buf, strlen(name) + 1 + len);
1582 1.1 jmcneill kmem_free(buf, strlen(name) + 1 + len);
1583 1.1 jmcneill return ret;
1584 1.1 jmcneill }
1585 1.1 jmcneill
1586 1.1 jmcneill int
1587 1.1 jmcneill bwfm_fwvar_var_get_int(struct bwfm_softc *sc, const char *name, uint32_t *data)
1588 1.1 jmcneill {
1589 1.1 jmcneill int ret;
1590 1.1 jmcneill ret = bwfm_fwvar_var_get_data(sc, name, data, sizeof(*data));
1591 1.1 jmcneill *data = le32toh(*data);
1592 1.1 jmcneill return ret;
1593 1.1 jmcneill }
1594 1.1 jmcneill
1595 1.1 jmcneill int
1596 1.1 jmcneill bwfm_fwvar_var_set_int(struct bwfm_softc *sc, const char *name, uint32_t data)
1597 1.1 jmcneill {
1598 1.1 jmcneill data = htole32(data);
1599 1.1 jmcneill return bwfm_fwvar_var_set_data(sc, name, &data, sizeof(data));
1600 1.1 jmcneill }
1601 1.1 jmcneill
1602 1.1 jmcneill /* 802.11 code */
1603 1.1 jmcneill void
1604 1.1 jmcneill bwfm_scan(struct bwfm_softc *sc)
1605 1.1 jmcneill {
1606 1.1 jmcneill struct bwfm_escan_params *params;
1607 1.1 jmcneill uint32_t nssid = 0, nchannel = 0;
1608 1.1 jmcneill size_t params_size;
1609 1.1 jmcneill
1610 1.1 jmcneill #if 0
1611 1.1 jmcneill /* Active scan is used for scanning for an SSID */
1612 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PASSIVE_SCAN, 0);
1613 1.1 jmcneill #endif
1614 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PASSIVE_SCAN, 1);
1615 1.1 jmcneill
1616 1.1 jmcneill params_size = sizeof(*params);
1617 1.1 jmcneill params_size += sizeof(uint32_t) * ((nchannel + 1) / 2);
1618 1.1 jmcneill params_size += sizeof(struct bwfm_ssid) * nssid;
1619 1.1 jmcneill
1620 1.1 jmcneill params = kmem_zalloc(params_size, KM_SLEEP);
1621 1.1 jmcneill memset(params->scan_params.bssid, 0xff,
1622 1.1 jmcneill sizeof(params->scan_params.bssid));
1623 1.1 jmcneill params->scan_params.bss_type = 2;
1624 1.1 jmcneill params->scan_params.nprobes = htole32(-1);
1625 1.1 jmcneill params->scan_params.active_time = htole32(-1);
1626 1.1 jmcneill params->scan_params.passive_time = htole32(-1);
1627 1.1 jmcneill params->scan_params.home_time = htole32(-1);
1628 1.1 jmcneill params->version = htole32(BWFM_ESCAN_REQ_VERSION);
1629 1.1 jmcneill params->action = htole16(WL_ESCAN_ACTION_START);
1630 1.1 jmcneill params->sync_id = htole16(0x1234);
1631 1.1 jmcneill
1632 1.1 jmcneill #if 0
1633 1.1 jmcneill /* Scan a specific channel */
1634 1.1 jmcneill params->scan_params.channel_list[0] = htole16(
1635 1.1 jmcneill (1 & 0xff) << 0 |
1636 1.1 jmcneill (3 & 0x3) << 8 |
1637 1.1 jmcneill (2 & 0x3) << 10 |
1638 1.1 jmcneill (2 & 0x3) << 12
1639 1.1 jmcneill );
1640 1.1 jmcneill params->scan_params.channel_num = htole32(
1641 1.1 jmcneill (1 & 0xffff) << 0
1642 1.1 jmcneill );
1643 1.1 jmcneill #endif
1644 1.1 jmcneill
1645 1.1 jmcneill bwfm_fwvar_var_set_data(sc, "escan", params, params_size);
1646 1.1 jmcneill kmem_free(params, params_size);
1647 1.1 jmcneill }
1648 1.1 jmcneill
1649 1.1 jmcneill static __inline int
1650 1.1 jmcneill bwfm_iswpaoui(const uint8_t *frm)
1651 1.1 jmcneill {
1652 1.1 jmcneill return frm[1] > 3 && le32dec(frm+2) == ((WPA_OUI_TYPE<<24)|WPA_OUI);
1653 1.1 jmcneill }
1654 1.1 jmcneill
1655 1.1 jmcneill /*
1656 1.1 jmcneill * Derive wireless security settings from WPA/RSN IE.
1657 1.1 jmcneill */
1658 1.1 jmcneill static uint32_t
1659 1.1 jmcneill bwfm_get_wsec(struct bwfm_softc *sc)
1660 1.1 jmcneill {
1661 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1662 1.1 jmcneill uint8_t *wpa = ic->ic_opt_ie;
1663 1.1 jmcneill
1664 1.1 jmcneill KASSERT(ic->ic_opt_ie_len > 0);
1665 1.1 jmcneill
1666 1.1 jmcneill if (wpa[0] != IEEE80211_ELEMID_RSN) {
1667 1.1 jmcneill if (ic->ic_opt_ie_len < 12)
1668 1.1 jmcneill return BWFM_WSEC_NONE;
1669 1.1 jmcneill
1670 1.1 jmcneill /* non-RSN IE, expect that we are doing WPA1 */
1671 1.1 jmcneill if ((ic->ic_flags & IEEE80211_F_WPA1) == 0)
1672 1.1 jmcneill return BWFM_WSEC_NONE;
1673 1.1 jmcneill
1674 1.1 jmcneill /* Must contain WPA OUI */
1675 1.1 jmcneill if (!bwfm_iswpaoui(wpa))
1676 1.1 jmcneill return BWFM_WSEC_NONE;
1677 1.1 jmcneill
1678 1.1 jmcneill switch (le32dec(wpa + 8)) {
1679 1.1 jmcneill case ((WPA_CSE_TKIP<<24)|WPA_OUI):
1680 1.1 jmcneill return BWFM_WSEC_TKIP;
1681 1.1 jmcneill case ((WPA_CSE_CCMP<<24)|WPA_OUI):
1682 1.1 jmcneill return BWFM_WSEC_AES;
1683 1.1 jmcneill default:
1684 1.1 jmcneill return BWFM_WSEC_NONE;
1685 1.1 jmcneill }
1686 1.1 jmcneill } else {
1687 1.1 jmcneill if (ic->ic_opt_ie_len < 14)
1688 1.1 jmcneill return BWFM_WSEC_NONE;
1689 1.1 jmcneill
1690 1.1 jmcneill /* RSN IE, expect that we are doing WPA2 */
1691 1.1 jmcneill if ((ic->ic_flags & IEEE80211_F_WPA2) == 0)
1692 1.1 jmcneill return BWFM_WSEC_NONE;
1693 1.1 jmcneill
1694 1.1 jmcneill switch (le32dec(wpa + 10)) {
1695 1.1 jmcneill case ((RSN_CSE_TKIP<<24)|RSN_OUI):
1696 1.1 jmcneill return BWFM_WSEC_TKIP;
1697 1.1 jmcneill case ((RSN_CSE_CCMP<<24)|RSN_OUI):
1698 1.1 jmcneill return BWFM_WSEC_AES;
1699 1.1 jmcneill default:
1700 1.1 jmcneill return BWFM_WSEC_NONE;
1701 1.1 jmcneill }
1702 1.1 jmcneill }
1703 1.1 jmcneill }
1704 1.1 jmcneill
1705 1.1 jmcneill void
1706 1.1 jmcneill bwfm_connect(struct bwfm_softc *sc)
1707 1.1 jmcneill {
1708 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1709 1.1 jmcneill struct ieee80211_node *ni = ic->ic_bss;
1710 1.1 jmcneill struct bwfm_ext_join_params *params;
1711 1.1 jmcneill
1712 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_WPA) {
1713 1.1 jmcneill uint32_t wsec = 0;
1714 1.1 jmcneill uint32_t wpa = 0;
1715 1.1 jmcneill
1716 1.1 jmcneill if (ic->ic_opt_ie_len)
1717 1.1 jmcneill bwfm_fwvar_var_set_data(sc, "wpaie", ic->ic_opt_ie, ic->ic_opt_ie_len);
1718 1.1 jmcneill
1719 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_WPA1)
1720 1.1 jmcneill wpa |= BWFM_WPA_AUTH_WPA_PSK;
1721 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_WPA2)
1722 1.1 jmcneill wpa |= BWFM_WPA_AUTH_WPA2_PSK;
1723 1.1 jmcneill
1724 1.1 jmcneill wsec |= bwfm_get_wsec(sc);
1725 1.1 jmcneill
1726 1.1 jmcneill DPRINTF(("%s: WPA enabled, ic_flags = 0x%x, wpa 0x%x, wsec 0x%x\n",
1727 1.1 jmcneill DEVNAME(sc), ic->ic_flags, wpa, wsec));
1728 1.1 jmcneill
1729 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wpa_auth", wpa);
1730 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wsec", wsec);
1731 1.1 jmcneill } else {
1732 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wpa_auth", BWFM_WPA_AUTH_DISABLED);
1733 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wsec", BWFM_WSEC_NONE);
1734 1.1 jmcneill }
1735 1.1 jmcneill
1736 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "auth", BWFM_AUTH_OPEN);
1737 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "mfp", BWFM_MFP_NONE);
1738 1.1 jmcneill
1739 1.1 jmcneill if (ni->ni_esslen && ni->ni_esslen < BWFM_MAX_SSID_LEN) {
1740 1.1 jmcneill params = kmem_zalloc(sizeof(*params), KM_SLEEP);
1741 1.1 jmcneill memcpy(params->ssid.ssid, ni->ni_essid, ni->ni_esslen);
1742 1.1 jmcneill params->ssid.len = htole32(ni->ni_esslen);
1743 1.1 jmcneill memcpy(params->assoc.bssid, ni->ni_bssid, sizeof(params->assoc.bssid));
1744 1.1 jmcneill params->scan.scan_type = -1;
1745 1.1 jmcneill params->scan.nprobes = htole32(-1);
1746 1.1 jmcneill params->scan.active_time = htole32(-1);
1747 1.1 jmcneill params->scan.passive_time = htole32(-1);
1748 1.1 jmcneill params->scan.home_time = htole32(-1);
1749 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "join", params, sizeof(*params))) {
1750 1.1 jmcneill struct bwfm_join_params join;
1751 1.1 jmcneill memset(&join, 0, sizeof(join));
1752 1.1 jmcneill memcpy(join.ssid.ssid, ni->ni_essid, ni->ni_esslen);
1753 1.1 jmcneill join.ssid.len = htole32(ni->ni_esslen);
1754 1.1 jmcneill memcpy(join.assoc.bssid, ni->ni_bssid, sizeof(join.assoc.bssid));
1755 1.1 jmcneill bwfm_fwvar_cmd_set_data(sc, BWFM_C_SET_SSID, &join,
1756 1.1 jmcneill sizeof(join));
1757 1.1 jmcneill }
1758 1.1 jmcneill kmem_free(params, sizeof(*params));
1759 1.1 jmcneill }
1760 1.1 jmcneill }
1761 1.1 jmcneill
1762 1.1 jmcneill void
1763 1.11 maya bwfm_rx(struct bwfm_softc *sc, struct mbuf *m)
1764 1.1 jmcneill {
1765 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1766 1.1 jmcneill struct ifnet *ifp = ic->ic_ifp;
1767 1.11 maya struct bwfm_event *e = mtod(m, struct bwfm_event *);
1768 1.1 jmcneill int s;
1769 1.1 jmcneill
1770 1.11 maya if (m->m_len >= sizeof(e->ehdr) &&
1771 1.1 jmcneill ntohs(e->ehdr.ether_type) == BWFM_ETHERTYPE_LINK_CTL &&
1772 1.1 jmcneill memcmp(BWFM_BRCM_OUI, e->hdr.oui, sizeof(e->hdr.oui)) == 0 &&
1773 1.11 maya ntohs(e->hdr.usr_subtype) == BWFM_BRCM_SUBTYPE_EVENT) {
1774 1.11 maya bwfm_rx_event(sc, mtod(m, char *), m->m_len);
1775 1.11 maya m_freem(m);
1776 1.1 jmcneill return;
1777 1.1 jmcneill }
1778 1.1 jmcneill
1779 1.1 jmcneill s = splnet();
1780 1.1 jmcneill
1781 1.1 jmcneill if ((ifp->if_flags & IFF_RUNNING) != 0) {
1782 1.1 jmcneill m_set_rcvif(m, ifp);
1783 1.1 jmcneill if_percpuq_enqueue(ifp->if_percpuq, m);
1784 1.1 jmcneill }
1785 1.1 jmcneill
1786 1.1 jmcneill splx(s);
1787 1.1 jmcneill }
1788 1.1 jmcneill
1789 1.1 jmcneill void
1790 1.1 jmcneill bwfm_rx_event(struct bwfm_softc *sc, char *buf, size_t len)
1791 1.1 jmcneill {
1792 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1793 1.1 jmcneill struct bwfm_event *e = (void *)buf;
1794 1.1 jmcneill int s;
1795 1.1 jmcneill
1796 1.1 jmcneill DPRINTF(("%s: buf %p len %lu datalen %u code %u status %u"
1797 1.1 jmcneill " reason %u\n", __func__, buf, len, ntohl(e->msg.datalen),
1798 1.1 jmcneill ntohl(e->msg.event_type), ntohl(e->msg.status),
1799 1.1 jmcneill ntohl(e->msg.reason)));
1800 1.1 jmcneill
1801 1.1 jmcneill if (ntohl(e->msg.event_type) >= BWFM_E_LAST)
1802 1.1 jmcneill return;
1803 1.1 jmcneill
1804 1.1 jmcneill switch (ntohl(e->msg.event_type)) {
1805 1.1 jmcneill case BWFM_E_ESCAN_RESULT: {
1806 1.1 jmcneill struct bwfm_escan_results *res = (void *)(buf + sizeof(*e));
1807 1.1 jmcneill struct bwfm_bss_info *bss;
1808 1.1 jmcneill int i;
1809 1.1 jmcneill if (ntohl(e->msg.status) != BWFM_E_STATUS_PARTIAL) {
1810 1.1 jmcneill /* Scan complete */
1811 1.1 jmcneill s = splnet();
1812 1.1 jmcneill if (ic->ic_opmode != IEEE80211_M_MONITOR)
1813 1.1 jmcneill ieee80211_end_scan(ic);
1814 1.1 jmcneill splx(s);
1815 1.1 jmcneill break;
1816 1.1 jmcneill }
1817 1.1 jmcneill len -= sizeof(*e);
1818 1.1 jmcneill if (len < sizeof(*res) || len < le32toh(res->buflen)) {
1819 1.1 jmcneill printf("%s: results too small\n", DEVNAME(sc));
1820 1.1 jmcneill return;
1821 1.1 jmcneill }
1822 1.1 jmcneill len -= sizeof(*res);
1823 1.1 jmcneill if (len < le16toh(res->bss_count) * sizeof(struct bwfm_bss_info)) {
1824 1.1 jmcneill printf("%s: results too small\n", DEVNAME(sc));
1825 1.1 jmcneill return;
1826 1.1 jmcneill }
1827 1.1 jmcneill bss = &res->bss_info[0];
1828 1.1 jmcneill for (i = 0; i < le16toh(res->bss_count); i++) {
1829 1.2 jmcneill /* Fix alignment of bss_info */
1830 1.2 jmcneill union {
1831 1.2 jmcneill struct bwfm_bss_info bss_info;
1832 1.2 jmcneill uint8_t padding[BWFM_BSS_INFO_BUFLEN];
1833 1.2 jmcneill } bss_buf;
1834 1.2 jmcneill if (len > sizeof(bss_buf)) {
1835 1.2 jmcneill printf("%s: bss_info buffer too big\n", DEVNAME(sc));
1836 1.2 jmcneill } else {
1837 1.2 jmcneill memcpy(&bss_buf, &res->bss_info[i], len);
1838 1.2 jmcneill bwfm_scan_node(sc, &bss_buf.bss_info, len);
1839 1.2 jmcneill }
1840 1.1 jmcneill len -= sizeof(*bss) + le32toh(bss->length);
1841 1.1 jmcneill bss = (void *)(((uintptr_t)bss) + le32toh(bss->length));
1842 1.1 jmcneill if (len <= 0)
1843 1.1 jmcneill break;
1844 1.1 jmcneill }
1845 1.1 jmcneill break;
1846 1.1 jmcneill }
1847 1.1 jmcneill
1848 1.1 jmcneill case BWFM_E_SET_SSID:
1849 1.1 jmcneill if (ntohl(e->msg.status) == BWFM_E_STATUS_SUCCESS) {
1850 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_RUN, -1);
1851 1.1 jmcneill } else {
1852 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
1853 1.1 jmcneill }
1854 1.1 jmcneill break;
1855 1.1 jmcneill
1856 1.1 jmcneill case BWFM_E_ASSOC:
1857 1.1 jmcneill if (ntohl(e->msg.status) == BWFM_E_STATUS_SUCCESS) {
1858 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_ASSOC, -1);
1859 1.1 jmcneill } else {
1860 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
1861 1.1 jmcneill }
1862 1.1 jmcneill break;
1863 1.1 jmcneill
1864 1.1 jmcneill case BWFM_E_LINK:
1865 1.1 jmcneill if (ntohl(e->msg.status) == BWFM_E_STATUS_SUCCESS &&
1866 1.1 jmcneill ntohl(e->msg.reason) == 0)
1867 1.1 jmcneill break;
1868 1.11 maya
1869 1.1 jmcneill /* Link status has changed */
1870 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
1871 1.1 jmcneill break;
1872 1.1 jmcneill
1873 1.1 jmcneill default:
1874 1.1 jmcneill break;
1875 1.1 jmcneill }
1876 1.1 jmcneill }
1877 1.1 jmcneill
1878 1.1 jmcneill void
1879 1.1 jmcneill bwfm_scan_node(struct bwfm_softc *sc, struct bwfm_bss_info *bss, size_t len)
1880 1.1 jmcneill {
1881 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1882 1.1 jmcneill struct ieee80211_frame wh;
1883 1.1 jmcneill struct ieee80211_scanparams scan;
1884 1.1 jmcneill uint8_t rates[sizeof(bss->rates) + 2];
1885 1.1 jmcneill uint8_t ssid[sizeof(bss->ssid) + 2];
1886 1.1 jmcneill uint8_t *frm, *sfrm, *efrm;
1887 1.1 jmcneill uint64_t tsf;
1888 1.1 jmcneill
1889 1.1 jmcneill tsf = 0;
1890 1.1 jmcneill sfrm = ((uint8_t *)bss) + le16toh(bss->ie_offset);
1891 1.1 jmcneill efrm = sfrm + le32toh(bss->ie_length);
1892 1.1 jmcneill
1893 1.1 jmcneill /* Fake a wireless header with the scan result's BSSID */
1894 1.1 jmcneill memset(&wh, 0, sizeof(wh));
1895 1.1 jmcneill IEEE80211_ADDR_COPY(wh.i_addr2, bss->bssid);
1896 1.1 jmcneill IEEE80211_ADDR_COPY(wh.i_addr3, bss->bssid);
1897 1.1 jmcneill
1898 1.1 jmcneill if (efrm - sfrm < 12) {
1899 1.1 jmcneill ic->ic_stats.is_rx_elem_toosmall++;
1900 1.1 jmcneill return;
1901 1.1 jmcneill }
1902 1.1 jmcneill
1903 1.1 jmcneill rates[0] = 0;
1904 1.1 jmcneill rates[1] = le32toh(bss->nrates);
1905 1.1 jmcneill memcpy(&rates[2], bss->rates, sizeof(bss->rates));
1906 1.1 jmcneill
1907 1.1 jmcneill ssid[0] = 0;
1908 1.1 jmcneill ssid[1] = bss->ssid_len;
1909 1.1 jmcneill memcpy(&ssid[2], bss->ssid, sizeof(bss->ssid));
1910 1.1 jmcneill
1911 1.1 jmcneill /* Build scan result */
1912 1.1 jmcneill memset(&scan, 0, sizeof(scan));
1913 1.10 maxv scan.sp_tstamp = (uint8_t *)&tsf;
1914 1.10 maxv scan.sp_bintval = le16toh(bss->beacon_period);
1915 1.10 maxv scan.sp_capinfo = le16toh(bss->capability);
1916 1.10 maxv scan.sp_bchan = ieee80211_chan2ieee(ic, ic->ic_curchan);
1917 1.10 maxv scan.sp_chan = scan.sp_bchan;
1918 1.10 maxv scan.sp_rates = rates;
1919 1.10 maxv scan.sp_ssid = ssid;
1920 1.1 jmcneill
1921 1.1 jmcneill for (frm = sfrm; frm < efrm; frm += frm[1] + 2) {
1922 1.1 jmcneill switch (frm[0]) {
1923 1.1 jmcneill case IEEE80211_ELEMID_COUNTRY:
1924 1.10 maxv scan.sp_country = frm;
1925 1.1 jmcneill break;
1926 1.1 jmcneill case IEEE80211_ELEMID_FHPARMS:
1927 1.1 jmcneill if (ic->ic_phytype == IEEE80211_T_FH) {
1928 1.8 maxv if (frm + 6 >= efrm)
1929 1.8 maxv break;
1930 1.10 maxv scan.sp_fhdwell = le16dec(&frm[2]);
1931 1.10 maxv scan.sp_chan = IEEE80211_FH_CHAN(frm[4], frm[5]);
1932 1.10 maxv scan.sp_fhindex = frm[6];
1933 1.1 jmcneill }
1934 1.1 jmcneill break;
1935 1.1 jmcneill case IEEE80211_ELEMID_DSPARMS:
1936 1.8 maxv if (ic->ic_phytype != IEEE80211_T_FH) {
1937 1.8 maxv if (frm + 2 >= efrm)
1938 1.8 maxv break;
1939 1.10 maxv scan.sp_chan = frm[2];
1940 1.8 maxv }
1941 1.1 jmcneill break;
1942 1.1 jmcneill case IEEE80211_ELEMID_TIM:
1943 1.10 maxv scan.sp_tim = frm;
1944 1.10 maxv scan.sp_timoff = frm - sfrm;
1945 1.1 jmcneill break;
1946 1.1 jmcneill case IEEE80211_ELEMID_XRATES:
1947 1.10 maxv scan.sp_xrates = frm;
1948 1.1 jmcneill break;
1949 1.1 jmcneill case IEEE80211_ELEMID_ERP:
1950 1.8 maxv if (frm + 1 >= efrm)
1951 1.8 maxv break;
1952 1.1 jmcneill if (frm[1] != 1) {
1953 1.1 jmcneill ic->ic_stats.is_rx_elem_toobig++;
1954 1.1 jmcneill break;
1955 1.1 jmcneill }
1956 1.10 maxv scan.sp_erp = frm[2];
1957 1.1 jmcneill break;
1958 1.1 jmcneill case IEEE80211_ELEMID_RSN:
1959 1.10 maxv scan.sp_wpa = frm;
1960 1.1 jmcneill break;
1961 1.1 jmcneill case IEEE80211_ELEMID_VENDOR:
1962 1.8 maxv if (frm + 1 >= efrm)
1963 1.8 maxv break;
1964 1.8 maxv if (frm + frm[1] + 2 >= efrm)
1965 1.8 maxv break;
1966 1.1 jmcneill if (bwfm_iswpaoui(frm))
1967 1.10 maxv scan.sp_wpa = frm;
1968 1.1 jmcneill break;
1969 1.1 jmcneill }
1970 1.9 maxv if (frm + 1 >= efrm)
1971 1.9 maxv break;
1972 1.1 jmcneill }
1973 1.1 jmcneill
1974 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_SCAN)
1975 1.1 jmcneill ieee80211_add_scan(ic, &scan, &wh, IEEE80211_FC0_SUBTYPE_BEACON,
1976 1.1 jmcneill le32toh(bss->rssi), 0);
1977 1.1 jmcneill }
1978