bwfm.c revision 1.16 1 1.16 mlelstv /* $NetBSD: bwfm.c,v 1.16 2019/09/02 07:25:48 mlelstv Exp $ */
2 1.1 jmcneill /* $OpenBSD: bwfm.c,v 1.5 2017/10/16 22:27:16 patrick Exp $ */
3 1.1 jmcneill /*
4 1.1 jmcneill * Copyright (c) 2010-2016 Broadcom Corporation
5 1.1 jmcneill * Copyright (c) 2016,2017 Patrick Wildt <patrick (at) blueri.se>
6 1.1 jmcneill *
7 1.1 jmcneill * Permission to use, copy, modify, and/or distribute this software for any
8 1.1 jmcneill * purpose with or without fee is hereby granted, provided that the above
9 1.1 jmcneill * copyright notice and this permission notice appear in all copies.
10 1.1 jmcneill *
11 1.1 jmcneill * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
12 1.1 jmcneill * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
13 1.1 jmcneill * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
14 1.1 jmcneill * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
15 1.1 jmcneill * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16 1.1 jmcneill * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17 1.1 jmcneill * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18 1.1 jmcneill */
19 1.1 jmcneill
20 1.1 jmcneill #include <sys/param.h>
21 1.1 jmcneill #include <sys/systm.h>
22 1.1 jmcneill #include <sys/buf.h>
23 1.1 jmcneill #include <sys/kernel.h>
24 1.1 jmcneill #include <sys/device.h>
25 1.1 jmcneill #include <sys/queue.h>
26 1.1 jmcneill #include <sys/socket.h>
27 1.1 jmcneill #include <sys/kmem.h>
28 1.1 jmcneill #include <sys/workqueue.h>
29 1.1 jmcneill #include <sys/pcq.h>
30 1.1 jmcneill
31 1.1 jmcneill #include <net/bpf.h>
32 1.1 jmcneill #include <net/if.h>
33 1.1 jmcneill #include <net/if_dl.h>
34 1.1 jmcneill #include <net/if_media.h>
35 1.1 jmcneill #include <net/if_ether.h>
36 1.1 jmcneill
37 1.1 jmcneill #include <netinet/in.h>
38 1.1 jmcneill
39 1.1 jmcneill #include <net80211/ieee80211_var.h>
40 1.1 jmcneill
41 1.1 jmcneill #include <dev/ic/bwfmvar.h>
42 1.1 jmcneill #include <dev/ic/bwfmreg.h>
43 1.1 jmcneill
44 1.1 jmcneill /* #define BWFM_DEBUG */
45 1.1 jmcneill #ifdef BWFM_DEBUG
46 1.1 jmcneill #define DPRINTF(x) do { if (bwfm_debug > 0) printf x; } while (0)
47 1.1 jmcneill #define DPRINTFN(n, x) do { if (bwfm_debug >= (n)) printf x; } while (0)
48 1.1 jmcneill static int bwfm_debug = 1;
49 1.1 jmcneill #else
50 1.1 jmcneill #define DPRINTF(x) do { ; } while (0)
51 1.1 jmcneill #define DPRINTFN(n, x) do { ; } while (0)
52 1.1 jmcneill #endif
53 1.1 jmcneill
54 1.1 jmcneill #define DEVNAME(sc) device_xname((sc)->sc_dev)
55 1.1 jmcneill
56 1.1 jmcneill void bwfm_start(struct ifnet *);
57 1.1 jmcneill int bwfm_init(struct ifnet *);
58 1.1 jmcneill void bwfm_stop(struct ifnet *, int);
59 1.1 jmcneill void bwfm_watchdog(struct ifnet *);
60 1.1 jmcneill int bwfm_ioctl(struct ifnet *, u_long, void *);
61 1.1 jmcneill int bwfm_media_change(struct ifnet *);
62 1.1 jmcneill
63 1.1 jmcneill int bwfm_send_mgmt(struct ieee80211com *, struct ieee80211_node *,
64 1.1 jmcneill int, int);
65 1.1 jmcneill void bwfm_recv_mgmt(struct ieee80211com *, struct mbuf *,
66 1.1 jmcneill struct ieee80211_node *, int, int, uint32_t);
67 1.1 jmcneill int bwfm_key_set(struct ieee80211com *, const struct ieee80211_key *,
68 1.1 jmcneill const uint8_t *);
69 1.1 jmcneill int bwfm_key_delete(struct ieee80211com *, const struct ieee80211_key *);
70 1.1 jmcneill int bwfm_newstate(struct ieee80211com *, enum ieee80211_state, int);
71 1.1 jmcneill void bwfm_newstate_cb(struct bwfm_softc *, struct bwfm_cmd_newstate *);
72 1.4 jmcneill void bwfm_newassoc(struct ieee80211_node *, int);
73 1.1 jmcneill void bwfm_task(struct work *, void *);
74 1.1 jmcneill
75 1.1 jmcneill int bwfm_chip_attach(struct bwfm_softc *);
76 1.1 jmcneill int bwfm_chip_detach(struct bwfm_softc *, int);
77 1.1 jmcneill struct bwfm_core *bwfm_chip_get_core(struct bwfm_softc *, int);
78 1.1 jmcneill struct bwfm_core *bwfm_chip_get_pmu(struct bwfm_softc *);
79 1.1 jmcneill int bwfm_chip_ai_isup(struct bwfm_softc *, struct bwfm_core *);
80 1.1 jmcneill void bwfm_chip_ai_disable(struct bwfm_softc *, struct bwfm_core *,
81 1.1 jmcneill uint32_t, uint32_t);
82 1.1 jmcneill void bwfm_chip_ai_reset(struct bwfm_softc *, struct bwfm_core *,
83 1.1 jmcneill uint32_t, uint32_t, uint32_t);
84 1.1 jmcneill void bwfm_chip_dmp_erom_scan(struct bwfm_softc *);
85 1.1 jmcneill int bwfm_chip_dmp_get_regaddr(struct bwfm_softc *, uint32_t *,
86 1.1 jmcneill uint32_t *, uint32_t *);
87 1.11 maya int bwfm_chip_cr4_set_active(struct bwfm_softc *, const uint32_t);
88 1.1 jmcneill void bwfm_chip_cr4_set_passive(struct bwfm_softc *);
89 1.11 maya int bwfm_chip_ca7_set_active(struct bwfm_softc *, const uint32_t);
90 1.1 jmcneill void bwfm_chip_ca7_set_passive(struct bwfm_softc *);
91 1.11 maya int bwfm_chip_cm3_set_active(struct bwfm_softc *);
92 1.1 jmcneill void bwfm_chip_cm3_set_passive(struct bwfm_softc *);
93 1.11 maya void bwfm_chip_socram_ramsize(struct bwfm_softc *, struct bwfm_core *);
94 1.11 maya void bwfm_chip_sysmem_ramsize(struct bwfm_softc *, struct bwfm_core *);
95 1.11 maya void bwfm_chip_tcm_ramsize(struct bwfm_softc *, struct bwfm_core *);
96 1.11 maya void bwfm_chip_tcm_rambase(struct bwfm_softc *);
97 1.1 jmcneill
98 1.1 jmcneill int bwfm_proto_bcdc_query_dcmd(struct bwfm_softc *, int,
99 1.1 jmcneill int, char *, size_t *);
100 1.1 jmcneill int bwfm_proto_bcdc_set_dcmd(struct bwfm_softc *, int,
101 1.1 jmcneill int, char *, size_t);
102 1.1 jmcneill
103 1.1 jmcneill int bwfm_fwvar_cmd_get_data(struct bwfm_softc *, int, void *, size_t);
104 1.1 jmcneill int bwfm_fwvar_cmd_set_data(struct bwfm_softc *, int, void *, size_t);
105 1.1 jmcneill int bwfm_fwvar_cmd_get_int(struct bwfm_softc *, int, uint32_t *);
106 1.1 jmcneill int bwfm_fwvar_cmd_set_int(struct bwfm_softc *, int, uint32_t);
107 1.1 jmcneill int bwfm_fwvar_var_get_data(struct bwfm_softc *, const char *, void *, size_t);
108 1.1 jmcneill int bwfm_fwvar_var_set_data(struct bwfm_softc *, const char *, void *, size_t);
109 1.1 jmcneill int bwfm_fwvar_var_get_int(struct bwfm_softc *, const char *, uint32_t *);
110 1.1 jmcneill int bwfm_fwvar_var_set_int(struct bwfm_softc *, const char *, uint32_t);
111 1.1 jmcneill
112 1.1 jmcneill struct ieee80211_channel *bwfm_bss2chan(struct bwfm_softc *, struct bwfm_bss_info *);
113 1.1 jmcneill void bwfm_scan(struct bwfm_softc *);
114 1.1 jmcneill void bwfm_connect(struct bwfm_softc *);
115 1.1 jmcneill
116 1.11 maya void bwfm_rx(struct bwfm_softc *, struct mbuf *);
117 1.15 mlelstv void bwfm_rx_event(struct bwfm_softc *, struct mbuf *);
118 1.15 mlelstv void bwfm_rx_event_cb(struct bwfm_softc *, struct mbuf *);
119 1.1 jmcneill void bwfm_scan_node(struct bwfm_softc *, struct bwfm_bss_info *, size_t);
120 1.1 jmcneill
121 1.1 jmcneill uint8_t bwfm_2ghz_channels[] = {
122 1.1 jmcneill 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13,
123 1.1 jmcneill };
124 1.1 jmcneill uint8_t bwfm_5ghz_channels[] = {
125 1.1 jmcneill 34, 36, 38, 40, 42, 44, 46, 48, 52, 56, 60, 64, 100, 104, 108, 112,
126 1.1 jmcneill 116, 120, 124, 128, 132, 136, 140, 144, 149, 153, 157, 161, 165,
127 1.1 jmcneill };
128 1.1 jmcneill
129 1.1 jmcneill struct bwfm_proto_ops bwfm_proto_bcdc_ops = {
130 1.1 jmcneill .proto_query_dcmd = bwfm_proto_bcdc_query_dcmd,
131 1.1 jmcneill .proto_set_dcmd = bwfm_proto_bcdc_set_dcmd,
132 1.1 jmcneill };
133 1.1 jmcneill
134 1.1 jmcneill void
135 1.1 jmcneill bwfm_attach(struct bwfm_softc *sc)
136 1.1 jmcneill {
137 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
138 1.1 jmcneill struct ifnet *ifp = &sc->sc_if;
139 1.1 jmcneill struct bwfm_task *t;
140 1.1 jmcneill char fw_version[BWFM_DCMD_SMLEN];
141 1.1 jmcneill uint32_t bandlist[3];
142 1.1 jmcneill uint32_t tmp;
143 1.11 maya int i, j, error;
144 1.1 jmcneill
145 1.1 jmcneill error = workqueue_create(&sc->sc_taskq, DEVNAME(sc),
146 1.16 mlelstv bwfm_task, sc, PRI_NONE, IPL_NET, 0);
147 1.1 jmcneill if (error != 0) {
148 1.1 jmcneill printf("%s: could not create workqueue\n", DEVNAME(sc));
149 1.1 jmcneill return;
150 1.1 jmcneill }
151 1.1 jmcneill sc->sc_freetask = pcq_create(BWFM_TASK_COUNT, KM_SLEEP);
152 1.1 jmcneill for (i = 0; i < BWFM_TASK_COUNT; i++) {
153 1.1 jmcneill t = &sc->sc_task[i];
154 1.1 jmcneill t->t_sc = sc;
155 1.1 jmcneill pcq_put(sc->sc_freetask, t);
156 1.1 jmcneill }
157 1.1 jmcneill
158 1.5 jmcneill /* Stop the device in case it was previously initialized */
159 1.5 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_DOWN, 1);
160 1.5 jmcneill
161 1.1 jmcneill if (bwfm_fwvar_cmd_get_int(sc, BWFM_C_GET_VERSION, &tmp)) {
162 1.1 jmcneill printf("%s: could not read io type\n", DEVNAME(sc));
163 1.1 jmcneill return;
164 1.1 jmcneill } else
165 1.1 jmcneill sc->sc_io_type = tmp;
166 1.1 jmcneill if (bwfm_fwvar_var_get_data(sc, "cur_etheraddr", ic->ic_myaddr,
167 1.1 jmcneill sizeof(ic->ic_myaddr))) {
168 1.1 jmcneill printf("%s: could not read mac address\n", DEVNAME(sc));
169 1.1 jmcneill return;
170 1.1 jmcneill }
171 1.1 jmcneill
172 1.1 jmcneill memset(fw_version, 0, sizeof(fw_version));
173 1.1 jmcneill if (bwfm_fwvar_var_get_data(sc, "ver", fw_version, sizeof(fw_version)) == 0)
174 1.1 jmcneill printf("%s: %s", DEVNAME(sc), fw_version);
175 1.1 jmcneill printf("%s: address %s\n", DEVNAME(sc), ether_sprintf(ic->ic_myaddr));
176 1.1 jmcneill
177 1.1 jmcneill ic->ic_ifp = ifp;
178 1.1 jmcneill ic->ic_phytype = IEEE80211_T_OFDM;
179 1.1 jmcneill ic->ic_opmode = IEEE80211_M_STA;
180 1.1 jmcneill ic->ic_state = IEEE80211_S_INIT;
181 1.1 jmcneill
182 1.1 jmcneill ic->ic_caps =
183 1.1 jmcneill IEEE80211_C_WEP |
184 1.1 jmcneill IEEE80211_C_TKIP |
185 1.1 jmcneill IEEE80211_C_AES |
186 1.1 jmcneill IEEE80211_C_AES_CCM |
187 1.1 jmcneill #if notyet
188 1.1 jmcneill IEEE80211_C_MONITOR | /* monitor mode suported */
189 1.1 jmcneill IEEE80211_C_IBSS |
190 1.1 jmcneill IEEE80211_C_TXPMGT |
191 1.1 jmcneill IEEE80211_C_WME |
192 1.1 jmcneill #endif
193 1.1 jmcneill IEEE80211_C_SHSLOT | /* short slot time supported */
194 1.1 jmcneill IEEE80211_C_SHPREAMBLE | /* short preamble supported */
195 1.1 jmcneill IEEE80211_C_WPA | /* 802.11i */
196 1.1 jmcneill /* IEEE80211_C_WPA_4WAY */0; /* WPA 4-way handshake in hw */
197 1.1 jmcneill
198 1.1 jmcneill /* IBSS channel undefined for now. */
199 1.1 jmcneill ic->ic_ibss_chan = &ic->ic_channels[0];
200 1.1 jmcneill
201 1.1 jmcneill if (bwfm_fwvar_cmd_get_data(sc, BWFM_C_GET_BANDLIST, bandlist,
202 1.1 jmcneill sizeof(bandlist))) {
203 1.1 jmcneill printf("%s: couldn't get supported band list\n", DEVNAME(sc));
204 1.1 jmcneill return;
205 1.1 jmcneill }
206 1.1 jmcneill const u_int nbands = le32toh(bandlist[0]);
207 1.1 jmcneill for (i = 1; i <= MIN(nbands, __arraycount(bandlist) - 1); i++) {
208 1.1 jmcneill switch (le32toh(bandlist[i])) {
209 1.1 jmcneill case BWFM_BAND_2G:
210 1.1 jmcneill ic->ic_sup_rates[IEEE80211_MODE_11B] = ieee80211_std_rateset_11b;
211 1.1 jmcneill ic->ic_sup_rates[IEEE80211_MODE_11G] = ieee80211_std_rateset_11g;
212 1.1 jmcneill
213 1.11 maya for (j = 0; j < __arraycount(bwfm_2ghz_channels); j++) {
214 1.11 maya uint8_t chan = bwfm_2ghz_channels[j];
215 1.1 jmcneill ic->ic_channels[chan].ic_freq =
216 1.1 jmcneill ieee80211_ieee2mhz(chan, IEEE80211_CHAN_2GHZ);
217 1.1 jmcneill ic->ic_channels[chan].ic_flags =
218 1.1 jmcneill IEEE80211_CHAN_CCK | IEEE80211_CHAN_OFDM |
219 1.1 jmcneill IEEE80211_CHAN_DYN | IEEE80211_CHAN_2GHZ;
220 1.1 jmcneill }
221 1.1 jmcneill break;
222 1.1 jmcneill case BWFM_BAND_5G:
223 1.1 jmcneill ic->ic_sup_rates[IEEE80211_MODE_11A] = ieee80211_std_rateset_11a;
224 1.1 jmcneill
225 1.11 maya for (j = 0; j < __arraycount(bwfm_5ghz_channels); j++) {
226 1.11 maya uint8_t chan = bwfm_5ghz_channels[j];
227 1.1 jmcneill ic->ic_channels[chan].ic_freq =
228 1.1 jmcneill ieee80211_ieee2mhz(chan, IEEE80211_CHAN_5GHZ);
229 1.1 jmcneill ic->ic_channels[chan].ic_flags =
230 1.1 jmcneill IEEE80211_CHAN_A;
231 1.1 jmcneill }
232 1.1 jmcneill break;
233 1.1 jmcneill }
234 1.1 jmcneill }
235 1.1 jmcneill
236 1.1 jmcneill ifp->if_softc = sc;
237 1.1 jmcneill ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
238 1.1 jmcneill ifp->if_init = bwfm_init;
239 1.1 jmcneill ifp->if_ioctl = bwfm_ioctl;
240 1.1 jmcneill ifp->if_start = bwfm_start;
241 1.14 maya ifp->if_stop = bwfm_stop;
242 1.1 jmcneill ifp->if_watchdog = bwfm_watchdog;
243 1.1 jmcneill IFQ_SET_READY(&ifp->if_snd);
244 1.1 jmcneill memcpy(ifp->if_xname, DEVNAME(sc), IFNAMSIZ);
245 1.1 jmcneill
246 1.3 msaitoh error = if_initialize(ifp);
247 1.3 msaitoh if (error != 0) {
248 1.3 msaitoh printf("%s: if_initialize failed(%d)\n", DEVNAME(sc), error);
249 1.3 msaitoh pcq_destroy(sc->sc_freetask);
250 1.3 msaitoh workqueue_destroy(sc->sc_taskq);
251 1.3 msaitoh
252 1.3 msaitoh return; /* Error */
253 1.3 msaitoh }
254 1.3 msaitoh
255 1.1 jmcneill ieee80211_ifattach(ic);
256 1.1 jmcneill ifp->if_percpuq = if_percpuq_create(ifp);
257 1.1 jmcneill if_deferred_start_init(ifp, NULL);
258 1.1 jmcneill if_register(ifp);
259 1.1 jmcneill
260 1.1 jmcneill sc->sc_newstate = ic->ic_newstate;
261 1.1 jmcneill ic->ic_newstate = bwfm_newstate;
262 1.4 jmcneill ic->ic_newassoc = bwfm_newassoc;
263 1.1 jmcneill ic->ic_send_mgmt = bwfm_send_mgmt;
264 1.1 jmcneill ic->ic_recv_mgmt = bwfm_recv_mgmt;
265 1.1 jmcneill ic->ic_crypto.cs_key_set = bwfm_key_set;
266 1.1 jmcneill ic->ic_crypto.cs_key_delete = bwfm_key_delete;
267 1.6 jmcneill ieee80211_media_init(ic, bwfm_media_change, ieee80211_media_status);
268 1.1 jmcneill
269 1.1 jmcneill ieee80211_announce(ic);
270 1.1 jmcneill
271 1.1 jmcneill sc->sc_if_attached = true;
272 1.1 jmcneill }
273 1.1 jmcneill
274 1.1 jmcneill int
275 1.1 jmcneill bwfm_detach(struct bwfm_softc *sc, int flags)
276 1.1 jmcneill {
277 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
278 1.1 jmcneill struct ifnet *ifp = ic->ic_ifp;
279 1.1 jmcneill
280 1.1 jmcneill if (sc->sc_if_attached) {
281 1.1 jmcneill bpf_detach(ifp);
282 1.1 jmcneill ieee80211_ifdetach(ic);
283 1.1 jmcneill if_detach(ifp);
284 1.1 jmcneill }
285 1.1 jmcneill
286 1.1 jmcneill if (sc->sc_taskq)
287 1.1 jmcneill workqueue_destroy(sc->sc_taskq);
288 1.1 jmcneill if (sc->sc_freetask)
289 1.1 jmcneill pcq_destroy(sc->sc_freetask);
290 1.1 jmcneill
291 1.1 jmcneill return 0;
292 1.1 jmcneill }
293 1.1 jmcneill
294 1.1 jmcneill void
295 1.1 jmcneill bwfm_start(struct ifnet *ifp)
296 1.1 jmcneill {
297 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
298 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
299 1.1 jmcneill struct mbuf *m;
300 1.1 jmcneill int error;
301 1.1 jmcneill
302 1.1 jmcneill if ((ifp->if_flags & (IFF_RUNNING | IFF_OACTIVE)) != IFF_RUNNING)
303 1.1 jmcneill return;
304 1.1 jmcneill
305 1.1 jmcneill /* TODO: return if no link? */
306 1.1 jmcneill
307 1.1 jmcneill for (;;) {
308 1.1 jmcneill /* Discard management packets (fw handles this for us) */
309 1.1 jmcneill IF_DEQUEUE(&ic->ic_mgtq, m);
310 1.1 jmcneill if (m != NULL) {
311 1.1 jmcneill m_freem(m);
312 1.1 jmcneill continue;
313 1.1 jmcneill }
314 1.1 jmcneill
315 1.11 maya if (sc->sc_bus_ops->bs_txcheck(sc)) {
316 1.11 maya ifp->if_flags |= IFF_OACTIVE;
317 1.11 maya break;
318 1.11 maya }
319 1.11 maya
320 1.1 jmcneill IFQ_DEQUEUE(&ifp->if_snd, m);
321 1.1 jmcneill if (m == NULL)
322 1.1 jmcneill break;
323 1.1 jmcneill
324 1.13 riastrad error = sc->sc_bus_ops->bs_txdata(sc, &m);
325 1.1 jmcneill if (error == ENOBUFS) {
326 1.1 jmcneill IF_PREPEND(&ifp->if_snd, m);
327 1.1 jmcneill ifp->if_flags |= IFF_OACTIVE;
328 1.1 jmcneill break;
329 1.1 jmcneill }
330 1.1 jmcneill if (error != 0) {
331 1.1 jmcneill ifp->if_oerrors++;
332 1.1 jmcneill m_freem(m);
333 1.15 mlelstv continue;
334 1.1 jmcneill }
335 1.15 mlelstv
336 1.15 mlelstv bpf_mtap(ifp, m, BPF_D_OUT);
337 1.1 jmcneill }
338 1.1 jmcneill }
339 1.1 jmcneill
340 1.1 jmcneill int
341 1.1 jmcneill bwfm_init(struct ifnet *ifp)
342 1.1 jmcneill {
343 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
344 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
345 1.1 jmcneill uint8_t evmask[BWFM_EVENT_MASK_LEN];
346 1.1 jmcneill struct bwfm_join_pref_params join_pref[2];
347 1.1 jmcneill
348 1.1 jmcneill if (bwfm_fwvar_var_set_int(sc, "mpc", 1)) {
349 1.1 jmcneill printf("%s: could not set mpc\n", DEVNAME(sc));
350 1.1 jmcneill return EIO;
351 1.1 jmcneill }
352 1.1 jmcneill
353 1.1 jmcneill /* Select target by RSSI (boost on 5GHz) */
354 1.1 jmcneill join_pref[0].type = BWFM_JOIN_PREF_RSSI_DELTA;
355 1.1 jmcneill join_pref[0].len = 2;
356 1.1 jmcneill join_pref[0].rssi_gain = BWFM_JOIN_PREF_RSSI_BOOST;
357 1.1 jmcneill join_pref[0].band = BWFM_JOIN_PREF_BAND_5G;
358 1.1 jmcneill join_pref[1].type = BWFM_JOIN_PREF_RSSI;
359 1.1 jmcneill join_pref[1].len = 2;
360 1.1 jmcneill join_pref[1].rssi_gain = 0;
361 1.1 jmcneill join_pref[1].band = 0;
362 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "join_pref", join_pref,
363 1.1 jmcneill sizeof(join_pref))) {
364 1.1 jmcneill printf("%s: could not set join pref\n", DEVNAME(sc));
365 1.1 jmcneill return EIO;
366 1.1 jmcneill }
367 1.1 jmcneill
368 1.1 jmcneill memset(evmask, 0, sizeof(evmask));
369 1.1 jmcneill
370 1.1 jmcneill #define ENABLE_EVENT(e) evmask[(e) / 8] |= 1 << ((e) % 8)
371 1.1 jmcneill /* Events used to drive the state machine */
372 1.1 jmcneill ENABLE_EVENT(BWFM_E_ASSOC);
373 1.1 jmcneill ENABLE_EVENT(BWFM_E_ESCAN_RESULT);
374 1.1 jmcneill ENABLE_EVENT(BWFM_E_SET_SSID);
375 1.1 jmcneill ENABLE_EVENT(BWFM_E_LINK);
376 1.1 jmcneill #undef ENABLE_EVENT
377 1.1 jmcneill
378 1.1 jmcneill #ifdef BWFM_DEBUG
379 1.1 jmcneill memset(evmask, 0xff, sizeof(evmask));
380 1.1 jmcneill #endif
381 1.1 jmcneill
382 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "event_msgs", evmask, sizeof(evmask))) {
383 1.1 jmcneill printf("%s: could not set event mask\n", DEVNAME(sc));
384 1.1 jmcneill return EIO;
385 1.1 jmcneill }
386 1.1 jmcneill
387 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_SCAN_CHANNEL_TIME,
388 1.1 jmcneill BWFM_DEFAULT_SCAN_CHANNEL_TIME)) {
389 1.1 jmcneill printf("%s: could not set scan channel time\n", DEVNAME(sc));
390 1.1 jmcneill return EIO;
391 1.1 jmcneill }
392 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_SCAN_UNASSOC_TIME,
393 1.1 jmcneill BWFM_DEFAULT_SCAN_UNASSOC_TIME)) {
394 1.1 jmcneill printf("%s: could not set scan unassoc time\n", DEVNAME(sc));
395 1.1 jmcneill return EIO;
396 1.1 jmcneill }
397 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_SCAN_PASSIVE_TIME,
398 1.1 jmcneill BWFM_DEFAULT_SCAN_PASSIVE_TIME)) {
399 1.1 jmcneill printf("%s: could not set scan passive time\n", DEVNAME(sc));
400 1.1 jmcneill return EIO;
401 1.1 jmcneill }
402 1.1 jmcneill
403 1.1 jmcneill if (bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PM, 2)) {
404 1.1 jmcneill printf("%s: could not set power\n", DEVNAME(sc));
405 1.1 jmcneill return EIO;
406 1.1 jmcneill }
407 1.1 jmcneill
408 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "txbf", 1);
409 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_UP, 0);
410 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_INFRA, 1);
411 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_AP, 0);
412 1.1 jmcneill
413 1.1 jmcneill /* Disable all offloading (ARP, NDP, TCP/UDP cksum). */
414 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "arp_ol", 0);
415 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "arpoe", 0);
416 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "ndoe", 0);
417 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "toe", 0);
418 1.1 jmcneill
419 1.7 jmcneill /* Accept all multicast frames. */
420 1.7 jmcneill bwfm_fwvar_var_set_int(sc, "allmulti", 1);
421 1.7 jmcneill
422 1.7 jmcneill /* Setup promiscuous mode */
423 1.7 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PROMISC,
424 1.7 jmcneill (ifp->if_flags & IFF_PROMISC) ? 1 : 0);
425 1.7 jmcneill
426 1.1 jmcneill /*
427 1.1 jmcneill * Tell the firmware supplicant that we are going to handle the
428 1.1 jmcneill * WPA handshake ourselves.
429 1.1 jmcneill */
430 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "sup_wpa", 0);
431 1.1 jmcneill
432 1.1 jmcneill ifp->if_flags |= IFF_RUNNING;
433 1.1 jmcneill ifp->if_flags &= ~IFF_OACTIVE;
434 1.1 jmcneill
435 1.1 jmcneill if (ic->ic_opmode != IEEE80211_M_MONITOR) {
436 1.1 jmcneill if (ic->ic_roaming != IEEE80211_ROAMING_MANUAL)
437 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
438 1.1 jmcneill } else {
439 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_RUN, -1);
440 1.1 jmcneill }
441 1.1 jmcneill
442 1.1 jmcneill return 0;
443 1.1 jmcneill }
444 1.1 jmcneill
445 1.1 jmcneill void
446 1.1 jmcneill bwfm_stop(struct ifnet *ifp, int disable)
447 1.1 jmcneill {
448 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
449 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
450 1.1 jmcneill
451 1.1 jmcneill sc->sc_tx_timer = 0;
452 1.1 jmcneill ifp->if_timer = 0;
453 1.1 jmcneill ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
454 1.1 jmcneill
455 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_DOWN, 1);
456 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PM, 0);
457 1.1 jmcneill
458 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_INIT, -1);
459 1.1 jmcneill }
460 1.1 jmcneill
461 1.1 jmcneill void
462 1.1 jmcneill bwfm_watchdog(struct ifnet *ifp)
463 1.1 jmcneill {
464 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
465 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
466 1.1 jmcneill
467 1.1 jmcneill ifp->if_timer = 0;
468 1.1 jmcneill
469 1.1 jmcneill if (sc->sc_tx_timer > 0) {
470 1.1 jmcneill if (--sc->sc_tx_timer == 0) {
471 1.1 jmcneill printf("%s: device timeout\n", DEVNAME(sc));
472 1.1 jmcneill ifp->if_oerrors++;
473 1.1 jmcneill return;
474 1.1 jmcneill }
475 1.1 jmcneill ifp->if_timer = 1;
476 1.1 jmcneill }
477 1.1 jmcneill ieee80211_watchdog(ic);
478 1.1 jmcneill }
479 1.1 jmcneill
480 1.1 jmcneill int
481 1.1 jmcneill bwfm_ioctl(struct ifnet *ifp, u_long cmd, void *data)
482 1.1 jmcneill {
483 1.1 jmcneill struct bwfm_softc *sc = ifp->if_softc;
484 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
485 1.1 jmcneill int s, error = 0;
486 1.1 jmcneill
487 1.1 jmcneill s = splnet();
488 1.1 jmcneill
489 1.1 jmcneill switch (cmd) {
490 1.1 jmcneill case SIOCSIFFLAGS:
491 1.1 jmcneill if ((error = ifioctl_common(ifp, cmd, data)) != 0)
492 1.1 jmcneill break;
493 1.1 jmcneill switch (ifp->if_flags & (IFF_UP | IFF_RUNNING)) {
494 1.1 jmcneill case IFF_UP | IFF_RUNNING:
495 1.1 jmcneill break;
496 1.1 jmcneill case IFF_UP:
497 1.1 jmcneill bwfm_init(ifp);
498 1.1 jmcneill break;
499 1.1 jmcneill case IFF_RUNNING:
500 1.1 jmcneill bwfm_stop(ifp, 1);
501 1.1 jmcneill break;
502 1.1 jmcneill case 0:
503 1.1 jmcneill break;
504 1.1 jmcneill }
505 1.1 jmcneill break;
506 1.1 jmcneill
507 1.1 jmcneill case SIOCADDMULTI:
508 1.1 jmcneill case SIOCDELMULTI:
509 1.1 jmcneill if ((error = ether_ioctl(ifp, cmd, data)) == ENETRESET) {
510 1.1 jmcneill /* setup multicast filter, etc */
511 1.1 jmcneill error = 0;
512 1.1 jmcneill }
513 1.1 jmcneill break;
514 1.1 jmcneill
515 1.1 jmcneill default:
516 1.1 jmcneill error = ieee80211_ioctl(ic, cmd, data);
517 1.1 jmcneill }
518 1.1 jmcneill
519 1.1 jmcneill if (error == ENETRESET) {
520 1.1 jmcneill if ((ifp->if_flags & IFF_UP) != 0 &&
521 1.1 jmcneill (ifp->if_flags & IFF_RUNNING) != 0 &&
522 1.1 jmcneill ic->ic_roaming != IEEE80211_ROAMING_MANUAL) {
523 1.1 jmcneill bwfm_init(ifp);
524 1.1 jmcneill }
525 1.1 jmcneill error = 0;
526 1.1 jmcneill }
527 1.1 jmcneill
528 1.1 jmcneill splx(s);
529 1.1 jmcneill
530 1.1 jmcneill return error;
531 1.1 jmcneill }
532 1.1 jmcneill
533 1.1 jmcneill int
534 1.1 jmcneill bwfm_send_mgmt(struct ieee80211com *ic, struct ieee80211_node *ni,
535 1.1 jmcneill int type, int arg)
536 1.1 jmcneill {
537 1.1 jmcneill return 0;
538 1.1 jmcneill }
539 1.1 jmcneill
540 1.1 jmcneill void
541 1.1 jmcneill bwfm_recv_mgmt(struct ieee80211com *ic, struct mbuf *m0,
542 1.1 jmcneill struct ieee80211_node *ni, int subtype, int rssi, uint32_t rstamp)
543 1.1 jmcneill {
544 1.1 jmcneill }
545 1.1 jmcneill
546 1.1 jmcneill int
547 1.1 jmcneill bwfm_key_set(struct ieee80211com *ic, const struct ieee80211_key *wk,
548 1.1 jmcneill const uint8_t mac[IEEE80211_ADDR_LEN])
549 1.1 jmcneill {
550 1.1 jmcneill struct bwfm_softc *sc = ic->ic_ifp->if_softc;
551 1.1 jmcneill struct bwfm_task *t;
552 1.1 jmcneill
553 1.1 jmcneill t = pcq_get(sc->sc_freetask);
554 1.1 jmcneill if (t == NULL) {
555 1.1 jmcneill printf("%s: no free tasks\n", DEVNAME(sc));
556 1.1 jmcneill return 0;
557 1.1 jmcneill }
558 1.1 jmcneill
559 1.1 jmcneill t->t_cmd = BWFM_TASK_KEY_SET;
560 1.1 jmcneill t->t_key.key = wk;
561 1.1 jmcneill memcpy(t->t_key.mac, mac, sizeof(t->t_key.mac));
562 1.1 jmcneill workqueue_enqueue(sc->sc_taskq, (struct work *)t, NULL);
563 1.1 jmcneill return 1;
564 1.1 jmcneill }
565 1.1 jmcneill
566 1.1 jmcneill static void
567 1.1 jmcneill bwfm_key_set_cb(struct bwfm_softc *sc, struct bwfm_cmd_key *ck)
568 1.1 jmcneill {
569 1.1 jmcneill const struct ieee80211_key *wk = ck->key;
570 1.1 jmcneill const uint8_t *mac = ck->mac;
571 1.1 jmcneill struct bwfm_wsec_key wsec_key;
572 1.1 jmcneill uint32_t wsec_enable, wsec;
573 1.1 jmcneill bool ext_key;
574 1.1 jmcneill
575 1.1 jmcneill #ifdef BWFM_DEBUG
576 1.1 jmcneill printf("key_set: key cipher %s len %d: ", wk->wk_cipher->ic_name, wk->wk_keylen);
577 1.1 jmcneill for (int j = 0; j < sizeof(wk->wk_key); j++)
578 1.1 jmcneill printf("%02x", wk->wk_key[j]);
579 1.1 jmcneill #endif
580 1.1 jmcneill
581 1.1 jmcneill if ((wk->wk_flags & IEEE80211_KEY_GROUP) == 0 &&
582 1.1 jmcneill wk->wk_cipher->ic_cipher != IEEE80211_CIPHER_WEP) {
583 1.1 jmcneill ext_key = true;
584 1.1 jmcneill } else {
585 1.1 jmcneill ext_key = false;
586 1.1 jmcneill }
587 1.1 jmcneill
588 1.1 jmcneill #ifdef BWFM_DEBUG
589 1.1 jmcneill printf(", ext_key = %d", ext_key);
590 1.1 jmcneill printf(", mac = %02x:%02x:%02x:%02x:%02x:%02x",
591 1.1 jmcneill mac[0], mac[1], mac[2], mac[3], mac[4], mac[5]);
592 1.1 jmcneill printf("\n");
593 1.1 jmcneill #endif
594 1.1 jmcneill
595 1.1 jmcneill memset(&wsec_key, 0, sizeof(wsec_key));
596 1.1 jmcneill if (ext_key && !IEEE80211_IS_MULTICAST(mac))
597 1.1 jmcneill memcpy(wsec_key.ea, mac, sizeof(wsec_key.ea));
598 1.1 jmcneill wsec_key.index = htole32(wk->wk_keyix);
599 1.1 jmcneill wsec_key.len = htole32(wk->wk_keylen);
600 1.1 jmcneill memcpy(wsec_key.data, wk->wk_key, sizeof(wsec_key.data));
601 1.1 jmcneill if (!ext_key)
602 1.1 jmcneill wsec_key.flags = htole32(BWFM_PRIMARY_KEY);
603 1.1 jmcneill
604 1.1 jmcneill switch (wk->wk_cipher->ic_cipher) {
605 1.1 jmcneill case IEEE80211_CIPHER_WEP:
606 1.1 jmcneill if (wk->wk_keylen == 5)
607 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_WEP1);
608 1.1 jmcneill else if (wk->wk_keylen == 13)
609 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_WEP128);
610 1.1 jmcneill else
611 1.1 jmcneill return;
612 1.1 jmcneill wsec_enable = BWFM_WSEC_WEP;
613 1.1 jmcneill break;
614 1.1 jmcneill case IEEE80211_CIPHER_TKIP:
615 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_TKIP);
616 1.1 jmcneill wsec_enable = BWFM_WSEC_TKIP;
617 1.1 jmcneill break;
618 1.1 jmcneill case IEEE80211_CIPHER_AES_CCM:
619 1.1 jmcneill wsec_key.algo = htole32(BWFM_CRYPTO_ALGO_AES_CCM);
620 1.1 jmcneill wsec_enable = BWFM_WSEC_AES;
621 1.1 jmcneill break;
622 1.1 jmcneill default:
623 1.1 jmcneill printf("%s: %s: cipher %s not supported\n", DEVNAME(sc),
624 1.1 jmcneill __func__, wk->wk_cipher->ic_name);
625 1.1 jmcneill return;
626 1.1 jmcneill }
627 1.1 jmcneill
628 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "wsec_key", &wsec_key, sizeof(wsec_key)))
629 1.1 jmcneill return;
630 1.1 jmcneill
631 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wpa_auth", BWFM_WPA_AUTH_WPA2_PSK);
632 1.1 jmcneill
633 1.1 jmcneill bwfm_fwvar_var_get_int(sc, "wsec", &wsec);
634 1.1 jmcneill wsec |= wsec_enable;
635 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wsec", wsec);
636 1.1 jmcneill }
637 1.1 jmcneill
638 1.1 jmcneill int
639 1.1 jmcneill bwfm_key_delete(struct ieee80211com *ic, const struct ieee80211_key *wk)
640 1.1 jmcneill {
641 1.1 jmcneill struct bwfm_softc *sc = ic->ic_ifp->if_softc;
642 1.1 jmcneill struct bwfm_task *t;
643 1.1 jmcneill
644 1.1 jmcneill t = pcq_get(sc->sc_freetask);
645 1.1 jmcneill if (t == NULL) {
646 1.1 jmcneill printf("%s: no free tasks\n", DEVNAME(sc));
647 1.1 jmcneill return 0;
648 1.1 jmcneill }
649 1.1 jmcneill
650 1.1 jmcneill t->t_cmd = BWFM_TASK_KEY_DELETE;
651 1.1 jmcneill t->t_key.key = wk;
652 1.1 jmcneill memset(t->t_key.mac, 0, sizeof(t->t_key.mac));
653 1.1 jmcneill workqueue_enqueue(sc->sc_taskq, (struct work *)t, NULL);
654 1.1 jmcneill
655 1.1 jmcneill return 1;
656 1.1 jmcneill }
657 1.1 jmcneill
658 1.1 jmcneill static void
659 1.1 jmcneill bwfm_key_delete_cb(struct bwfm_softc *sc, struct bwfm_cmd_key *ck)
660 1.1 jmcneill {
661 1.1 jmcneill const struct ieee80211_key *wk = ck->key;
662 1.1 jmcneill struct bwfm_wsec_key wsec_key;
663 1.1 jmcneill
664 1.1 jmcneill memset(&wsec_key, 0, sizeof(wsec_key));
665 1.1 jmcneill wsec_key.index = htole32(wk->wk_keyix);
666 1.1 jmcneill wsec_key.flags = htole32(BWFM_PRIMARY_KEY);
667 1.1 jmcneill
668 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "wsec_key", &wsec_key, sizeof(wsec_key)))
669 1.1 jmcneill return;
670 1.1 jmcneill }
671 1.1 jmcneill
672 1.1 jmcneill int
673 1.1 jmcneill bwfm_newstate(struct ieee80211com *ic, enum ieee80211_state nstate, int arg)
674 1.1 jmcneill {
675 1.1 jmcneill struct bwfm_softc *sc = ic->ic_ifp->if_softc;
676 1.1 jmcneill struct bwfm_task *t;
677 1.1 jmcneill
678 1.1 jmcneill t = pcq_get(sc->sc_freetask);
679 1.1 jmcneill if (t == NULL) {
680 1.1 jmcneill printf("%s: no free tasks\n", DEVNAME(sc));
681 1.1 jmcneill return EIO;
682 1.1 jmcneill }
683 1.1 jmcneill
684 1.1 jmcneill t->t_cmd = BWFM_TASK_NEWSTATE;
685 1.1 jmcneill t->t_newstate.state = nstate;
686 1.1 jmcneill t->t_newstate.arg = arg;
687 1.1 jmcneill workqueue_enqueue(sc->sc_taskq, (struct work *)t, NULL);
688 1.1 jmcneill
689 1.1 jmcneill return 0;
690 1.1 jmcneill }
691 1.1 jmcneill
692 1.1 jmcneill void
693 1.1 jmcneill bwfm_newstate_cb(struct bwfm_softc *sc, struct bwfm_cmd_newstate *cmd)
694 1.1 jmcneill {
695 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
696 1.1 jmcneill enum ieee80211_state ostate = ic->ic_state;
697 1.1 jmcneill enum ieee80211_state nstate = cmd->state;
698 1.1 jmcneill int s;
699 1.1 jmcneill
700 1.1 jmcneill DPRINTF(("%s: newstate %d -> %d\n", DEVNAME(sc), ostate, nstate));
701 1.1 jmcneill
702 1.1 jmcneill s = splnet();
703 1.1 jmcneill
704 1.1 jmcneill switch (nstate) {
705 1.1 jmcneill case IEEE80211_S_INIT:
706 1.1 jmcneill break;
707 1.1 jmcneill
708 1.1 jmcneill case IEEE80211_S_SCAN:
709 1.1 jmcneill if (ostate != IEEE80211_S_SCAN) {
710 1.1 jmcneill /* Start of scanning */
711 1.1 jmcneill bwfm_scan(sc);
712 1.1 jmcneill }
713 1.1 jmcneill break;
714 1.1 jmcneill
715 1.1 jmcneill case IEEE80211_S_AUTH:
716 1.1 jmcneill bwfm_connect(sc);
717 1.1 jmcneill break;
718 1.1 jmcneill
719 1.1 jmcneill case IEEE80211_S_ASSOC:
720 1.1 jmcneill break;
721 1.1 jmcneill
722 1.1 jmcneill case IEEE80211_S_RUN:
723 1.1 jmcneill break;
724 1.1 jmcneill }
725 1.1 jmcneill
726 1.1 jmcneill sc->sc_newstate(ic, nstate, cmd->arg);
727 1.1 jmcneill
728 1.1 jmcneill splx(s);
729 1.1 jmcneill }
730 1.1 jmcneill
731 1.1 jmcneill void
732 1.4 jmcneill bwfm_newassoc(struct ieee80211_node *ni, int isnew)
733 1.4 jmcneill {
734 1.4 jmcneill /* Firmware handles rate adaptation for us */
735 1.4 jmcneill ni->ni_txrate = 0;
736 1.4 jmcneill }
737 1.4 jmcneill
738 1.4 jmcneill void
739 1.1 jmcneill bwfm_task(struct work *wk, void *arg)
740 1.1 jmcneill {
741 1.1 jmcneill struct bwfm_task *t = (struct bwfm_task *)wk;
742 1.1 jmcneill struct bwfm_softc *sc = t->t_sc;
743 1.1 jmcneill
744 1.1 jmcneill switch (t->t_cmd) {
745 1.1 jmcneill case BWFM_TASK_NEWSTATE:
746 1.1 jmcneill bwfm_newstate_cb(sc, &t->t_newstate);
747 1.1 jmcneill break;
748 1.1 jmcneill case BWFM_TASK_KEY_SET:
749 1.1 jmcneill bwfm_key_set_cb(sc, &t->t_key);
750 1.1 jmcneill break;
751 1.1 jmcneill case BWFM_TASK_KEY_DELETE:
752 1.1 jmcneill bwfm_key_delete_cb(sc, &t->t_key);
753 1.1 jmcneill break;
754 1.15 mlelstv case BWFM_TASK_RX_EVENT:
755 1.15 mlelstv bwfm_rx_event_cb(sc, t->t_mbuf);
756 1.15 mlelstv break;
757 1.1 jmcneill default:
758 1.1 jmcneill panic("bwfm: unknown task command %d", t->t_cmd);
759 1.1 jmcneill }
760 1.1 jmcneill
761 1.1 jmcneill pcq_put(sc->sc_freetask, t);
762 1.1 jmcneill }
763 1.1 jmcneill
764 1.1 jmcneill int
765 1.1 jmcneill bwfm_media_change(struct ifnet *ifp)
766 1.1 jmcneill {
767 1.1 jmcneill return 0;
768 1.1 jmcneill }
769 1.1 jmcneill
770 1.1 jmcneill /* Chip initialization (SDIO, PCIe) */
771 1.1 jmcneill int
772 1.1 jmcneill bwfm_chip_attach(struct bwfm_softc *sc)
773 1.1 jmcneill {
774 1.1 jmcneill struct bwfm_core *core;
775 1.1 jmcneill int need_socram = 0;
776 1.1 jmcneill int has_socram = 0;
777 1.1 jmcneill int cpu_found = 0;
778 1.1 jmcneill uint32_t val;
779 1.1 jmcneill
780 1.1 jmcneill LIST_INIT(&sc->sc_chip.ch_list);
781 1.1 jmcneill
782 1.1 jmcneill if (sc->sc_buscore_ops->bc_prepare(sc) != 0) {
783 1.1 jmcneill printf("%s: failed buscore prepare\n", DEVNAME(sc));
784 1.1 jmcneill return 1;
785 1.1 jmcneill }
786 1.1 jmcneill
787 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc,
788 1.1 jmcneill BWFM_CHIP_BASE + BWFM_CHIP_REG_CHIPID);
789 1.1 jmcneill sc->sc_chip.ch_chip = BWFM_CHIP_CHIPID_ID(val);
790 1.1 jmcneill sc->sc_chip.ch_chiprev = BWFM_CHIP_CHIPID_REV(val);
791 1.1 jmcneill
792 1.1 jmcneill if ((sc->sc_chip.ch_chip > 0xa000) || (sc->sc_chip.ch_chip < 0x4000))
793 1.1 jmcneill snprintf(sc->sc_chip.ch_name, sizeof(sc->sc_chip.ch_name),
794 1.1 jmcneill "%d", sc->sc_chip.ch_chip);
795 1.1 jmcneill else
796 1.1 jmcneill snprintf(sc->sc_chip.ch_name, sizeof(sc->sc_chip.ch_name),
797 1.1 jmcneill "%x", sc->sc_chip.ch_chip);
798 1.1 jmcneill
799 1.1 jmcneill switch (BWFM_CHIP_CHIPID_TYPE(val))
800 1.1 jmcneill {
801 1.1 jmcneill case BWFM_CHIP_CHIPID_TYPE_SOCI_SB:
802 1.1 jmcneill printf("%s: SoC interconnect SB not implemented\n",
803 1.1 jmcneill DEVNAME(sc));
804 1.1 jmcneill return 1;
805 1.1 jmcneill case BWFM_CHIP_CHIPID_TYPE_SOCI_AI:
806 1.1 jmcneill sc->sc_chip.ch_core_isup = bwfm_chip_ai_isup;
807 1.1 jmcneill sc->sc_chip.ch_core_disable = bwfm_chip_ai_disable;
808 1.1 jmcneill sc->sc_chip.ch_core_reset = bwfm_chip_ai_reset;
809 1.1 jmcneill bwfm_chip_dmp_erom_scan(sc);
810 1.1 jmcneill break;
811 1.1 jmcneill default:
812 1.1 jmcneill printf("%s: SoC interconnect %d unknown\n",
813 1.1 jmcneill DEVNAME(sc), BWFM_CHIP_CHIPID_TYPE(val));
814 1.1 jmcneill return 1;
815 1.1 jmcneill }
816 1.1 jmcneill
817 1.1 jmcneill LIST_FOREACH(core, &sc->sc_chip.ch_list, co_link) {
818 1.1 jmcneill DPRINTF(("%s: 0x%x:%-2d base 0x%08x wrap 0x%08x\n",
819 1.1 jmcneill DEVNAME(sc), core->co_id, core->co_rev,
820 1.1 jmcneill core->co_base, core->co_wrapbase));
821 1.1 jmcneill
822 1.1 jmcneill switch (core->co_id) {
823 1.1 jmcneill case BWFM_AGENT_CORE_ARM_CM3:
824 1.1 jmcneill need_socram = true;
825 1.1 jmcneill /* FALLTHROUGH */
826 1.1 jmcneill case BWFM_AGENT_CORE_ARM_CR4:
827 1.1 jmcneill case BWFM_AGENT_CORE_ARM_CA7:
828 1.1 jmcneill cpu_found = true;
829 1.1 jmcneill break;
830 1.1 jmcneill case BWFM_AGENT_INTERNAL_MEM:
831 1.1 jmcneill has_socram = true;
832 1.1 jmcneill break;
833 1.1 jmcneill default:
834 1.1 jmcneill break;
835 1.1 jmcneill }
836 1.1 jmcneill }
837 1.1 jmcneill
838 1.1 jmcneill if (!cpu_found) {
839 1.1 jmcneill printf("%s: CPU core not detected\n", DEVNAME(sc));
840 1.1 jmcneill return 1;
841 1.1 jmcneill }
842 1.1 jmcneill if (need_socram && !has_socram) {
843 1.1 jmcneill printf("%s: RAM core not provided\n", DEVNAME(sc));
844 1.1 jmcneill return 1;
845 1.1 jmcneill }
846 1.1 jmcneill
847 1.11 maya bwfm_chip_set_passive(sc);
848 1.1 jmcneill
849 1.1 jmcneill if (sc->sc_buscore_ops->bc_reset) {
850 1.1 jmcneill sc->sc_buscore_ops->bc_reset(sc);
851 1.11 maya bwfm_chip_set_passive(sc);
852 1.1 jmcneill }
853 1.1 jmcneill
854 1.11 maya if ((core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4)) != NULL) {
855 1.11 maya bwfm_chip_tcm_ramsize(sc, core);
856 1.11 maya bwfm_chip_tcm_rambase(sc);
857 1.11 maya } else if ((core = bwfm_chip_get_core(sc, BWFM_AGENT_SYS_MEM)) != NULL) {
858 1.11 maya bwfm_chip_sysmem_ramsize(sc, core);
859 1.11 maya bwfm_chip_tcm_rambase(sc);
860 1.11 maya } else if ((core = bwfm_chip_get_core(sc, BWFM_AGENT_INTERNAL_MEM)) != NULL) {
861 1.11 maya bwfm_chip_socram_ramsize(sc, core);
862 1.11 maya }
863 1.1 jmcneill
864 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_CHIPCOMMON);
865 1.1 jmcneill sc->sc_chip.ch_cc_caps = sc->sc_buscore_ops->bc_read(sc,
866 1.1 jmcneill core->co_base + BWFM_CHIP_REG_CAPABILITIES);
867 1.1 jmcneill sc->sc_chip.ch_cc_caps_ext = sc->sc_buscore_ops->bc_read(sc,
868 1.1 jmcneill core->co_base + BWFM_CHIP_REG_CAPABILITIES_EXT);
869 1.1 jmcneill
870 1.1 jmcneill core = bwfm_chip_get_pmu(sc);
871 1.1 jmcneill if (sc->sc_chip.ch_cc_caps & BWFM_CHIP_REG_CAPABILITIES_PMU) {
872 1.1 jmcneill sc->sc_chip.ch_pmucaps = sc->sc_buscore_ops->bc_read(sc,
873 1.1 jmcneill core->co_base + BWFM_CHIP_REG_PMUCAPABILITIES);
874 1.1 jmcneill sc->sc_chip.ch_pmurev = sc->sc_chip.ch_pmucaps &
875 1.1 jmcneill BWFM_CHIP_REG_PMUCAPABILITIES_REV_MASK;
876 1.1 jmcneill }
877 1.1 jmcneill
878 1.1 jmcneill if (sc->sc_buscore_ops->bc_setup)
879 1.1 jmcneill sc->sc_buscore_ops->bc_setup(sc);
880 1.1 jmcneill
881 1.1 jmcneill return 0;
882 1.1 jmcneill }
883 1.1 jmcneill
884 1.1 jmcneill struct bwfm_core *
885 1.1 jmcneill bwfm_chip_get_core(struct bwfm_softc *sc, int id)
886 1.1 jmcneill {
887 1.1 jmcneill struct bwfm_core *core;
888 1.1 jmcneill
889 1.1 jmcneill LIST_FOREACH(core, &sc->sc_chip.ch_list, co_link) {
890 1.1 jmcneill if (core->co_id == id)
891 1.1 jmcneill return core;
892 1.1 jmcneill }
893 1.1 jmcneill
894 1.1 jmcneill return NULL;
895 1.1 jmcneill }
896 1.1 jmcneill
897 1.1 jmcneill struct bwfm_core *
898 1.1 jmcneill bwfm_chip_get_pmu(struct bwfm_softc *sc)
899 1.1 jmcneill {
900 1.1 jmcneill struct bwfm_core *cc, *pmu;
901 1.1 jmcneill
902 1.1 jmcneill cc = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_CHIPCOMMON);
903 1.1 jmcneill if (cc->co_rev >= 35 && sc->sc_chip.ch_cc_caps_ext &
904 1.1 jmcneill BWFM_CHIP_REG_CAPABILITIES_EXT_AOB_PRESENT) {
905 1.1 jmcneill pmu = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_PMU);
906 1.1 jmcneill if (pmu)
907 1.1 jmcneill return pmu;
908 1.1 jmcneill }
909 1.1 jmcneill
910 1.1 jmcneill return cc;
911 1.1 jmcneill }
912 1.1 jmcneill
913 1.1 jmcneill /* Functions for the AI interconnect */
914 1.1 jmcneill int
915 1.1 jmcneill bwfm_chip_ai_isup(struct bwfm_softc *sc, struct bwfm_core *core)
916 1.1 jmcneill {
917 1.1 jmcneill uint32_t ioctl, reset;
918 1.1 jmcneill
919 1.1 jmcneill ioctl = sc->sc_buscore_ops->bc_read(sc,
920 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
921 1.1 jmcneill reset = sc->sc_buscore_ops->bc_read(sc,
922 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL);
923 1.1 jmcneill
924 1.1 jmcneill if (((ioctl & (BWFM_AGENT_IOCTL_FGC | BWFM_AGENT_IOCTL_CLK)) ==
925 1.1 jmcneill BWFM_AGENT_IOCTL_CLK) &&
926 1.1 jmcneill ((reset & BWFM_AGENT_RESET_CTL_RESET) == 0))
927 1.1 jmcneill return 1;
928 1.1 jmcneill
929 1.1 jmcneill return 0;
930 1.1 jmcneill }
931 1.1 jmcneill
932 1.1 jmcneill void
933 1.1 jmcneill bwfm_chip_ai_disable(struct bwfm_softc *sc, struct bwfm_core *core,
934 1.1 jmcneill uint32_t prereset, uint32_t reset)
935 1.1 jmcneill {
936 1.1 jmcneill uint32_t val;
937 1.1 jmcneill int i;
938 1.1 jmcneill
939 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc,
940 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL);
941 1.1 jmcneill if ((val & BWFM_AGENT_RESET_CTL_RESET) == 0) {
942 1.1 jmcneill
943 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
944 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL,
945 1.1 jmcneill prereset | BWFM_AGENT_IOCTL_FGC | BWFM_AGENT_IOCTL_CLK);
946 1.1 jmcneill sc->sc_buscore_ops->bc_read(sc,
947 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
948 1.1 jmcneill
949 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
950 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL,
951 1.1 jmcneill BWFM_AGENT_RESET_CTL_RESET);
952 1.1 jmcneill delay(20);
953 1.1 jmcneill
954 1.1 jmcneill for (i = 300; i > 0; i--) {
955 1.1 jmcneill if (sc->sc_buscore_ops->bc_read(sc,
956 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL) ==
957 1.1 jmcneill BWFM_AGENT_RESET_CTL_RESET)
958 1.1 jmcneill break;
959 1.1 jmcneill }
960 1.1 jmcneill if (i == 0)
961 1.1 jmcneill printf("%s: timeout on core reset\n", DEVNAME(sc));
962 1.1 jmcneill }
963 1.1 jmcneill
964 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
965 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL,
966 1.1 jmcneill reset | BWFM_AGENT_IOCTL_FGC | BWFM_AGENT_IOCTL_CLK);
967 1.1 jmcneill sc->sc_buscore_ops->bc_read(sc,
968 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
969 1.1 jmcneill }
970 1.1 jmcneill
971 1.1 jmcneill void
972 1.1 jmcneill bwfm_chip_ai_reset(struct bwfm_softc *sc, struct bwfm_core *core,
973 1.1 jmcneill uint32_t prereset, uint32_t reset, uint32_t postreset)
974 1.1 jmcneill {
975 1.1 jmcneill int i;
976 1.1 jmcneill
977 1.1 jmcneill bwfm_chip_ai_disable(sc, core, prereset, reset);
978 1.1 jmcneill
979 1.1 jmcneill for (i = 50; i > 0; i--) {
980 1.1 jmcneill if ((sc->sc_buscore_ops->bc_read(sc,
981 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL) &
982 1.1 jmcneill BWFM_AGENT_RESET_CTL_RESET) == 0)
983 1.1 jmcneill break;
984 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
985 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_RESET_CTL, 0);
986 1.1 jmcneill delay(60);
987 1.1 jmcneill }
988 1.1 jmcneill if (i == 0)
989 1.1 jmcneill printf("%s: timeout on core reset\n", DEVNAME(sc));
990 1.1 jmcneill
991 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
992 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL,
993 1.1 jmcneill postreset | BWFM_AGENT_IOCTL_CLK);
994 1.1 jmcneill sc->sc_buscore_ops->bc_read(sc,
995 1.1 jmcneill core->co_wrapbase + BWFM_AGENT_IOCTL);
996 1.1 jmcneill }
997 1.1 jmcneill
998 1.1 jmcneill void
999 1.1 jmcneill bwfm_chip_dmp_erom_scan(struct bwfm_softc *sc)
1000 1.1 jmcneill {
1001 1.1 jmcneill uint32_t erom, val, base, wrap;
1002 1.1 jmcneill uint8_t type = 0;
1003 1.1 jmcneill uint16_t id;
1004 1.1 jmcneill uint8_t nmw, nsw, rev;
1005 1.1 jmcneill struct bwfm_core *core;
1006 1.1 jmcneill
1007 1.1 jmcneill erom = sc->sc_buscore_ops->bc_read(sc,
1008 1.1 jmcneill BWFM_CHIP_BASE + BWFM_CHIP_REG_EROMPTR);
1009 1.1 jmcneill while (type != BWFM_DMP_DESC_EOT) {
1010 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, erom);
1011 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1012 1.1 jmcneill erom += 4;
1013 1.1 jmcneill
1014 1.1 jmcneill if (type != BWFM_DMP_DESC_COMPONENT)
1015 1.1 jmcneill continue;
1016 1.1 jmcneill
1017 1.1 jmcneill id = (val & BWFM_DMP_COMP_PARTNUM)
1018 1.1 jmcneill >> BWFM_DMP_COMP_PARTNUM_S;
1019 1.1 jmcneill
1020 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, erom);
1021 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1022 1.1 jmcneill erom += 4;
1023 1.1 jmcneill
1024 1.1 jmcneill if (type != BWFM_DMP_DESC_COMPONENT) {
1025 1.1 jmcneill printf("%s: not component descriptor\n", DEVNAME(sc));
1026 1.1 jmcneill return;
1027 1.1 jmcneill }
1028 1.1 jmcneill
1029 1.1 jmcneill nmw = (val & BWFM_DMP_COMP_NUM_MWRAP)
1030 1.1 jmcneill >> BWFM_DMP_COMP_NUM_MWRAP_S;
1031 1.1 jmcneill nsw = (val & BWFM_DMP_COMP_NUM_SWRAP)
1032 1.1 jmcneill >> BWFM_DMP_COMP_NUM_SWRAP_S;
1033 1.1 jmcneill rev = (val & BWFM_DMP_COMP_REVISION)
1034 1.1 jmcneill >> BWFM_DMP_COMP_REVISION_S;
1035 1.1 jmcneill
1036 1.1 jmcneill if (nmw + nsw == 0 && id != BWFM_AGENT_CORE_PMU)
1037 1.1 jmcneill continue;
1038 1.1 jmcneill
1039 1.1 jmcneill if (bwfm_chip_dmp_get_regaddr(sc, &erom, &base, &wrap))
1040 1.1 jmcneill continue;
1041 1.1 jmcneill
1042 1.1 jmcneill core = kmem_alloc(sizeof(*core), KM_SLEEP);
1043 1.1 jmcneill core->co_id = id;
1044 1.1 jmcneill core->co_base = base;
1045 1.1 jmcneill core->co_wrapbase = wrap;
1046 1.1 jmcneill core->co_rev = rev;
1047 1.1 jmcneill LIST_INSERT_HEAD(&sc->sc_chip.ch_list, core, co_link);
1048 1.1 jmcneill }
1049 1.1 jmcneill }
1050 1.1 jmcneill
1051 1.1 jmcneill int
1052 1.1 jmcneill bwfm_chip_dmp_get_regaddr(struct bwfm_softc *sc, uint32_t *erom,
1053 1.1 jmcneill uint32_t *base, uint32_t *wrap)
1054 1.1 jmcneill {
1055 1.1 jmcneill uint8_t type = 0, mpnum __unused = 0;
1056 1.1 jmcneill uint8_t stype, sztype, wraptype;
1057 1.1 jmcneill uint32_t val;
1058 1.1 jmcneill
1059 1.1 jmcneill *base = 0;
1060 1.1 jmcneill *wrap = 0;
1061 1.1 jmcneill
1062 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, *erom);
1063 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1064 1.1 jmcneill if (type == BWFM_DMP_DESC_MASTER_PORT) {
1065 1.1 jmcneill mpnum = (val & BWFM_DMP_MASTER_PORT_NUM)
1066 1.1 jmcneill >> BWFM_DMP_MASTER_PORT_NUM_S;
1067 1.1 jmcneill wraptype = BWFM_DMP_SLAVE_TYPE_MWRAP;
1068 1.1 jmcneill *erom += 4;
1069 1.1 jmcneill } else if ((type & ~BWFM_DMP_DESC_ADDRSIZE_GT32) ==
1070 1.1 jmcneill BWFM_DMP_DESC_ADDRESS)
1071 1.1 jmcneill wraptype = BWFM_DMP_SLAVE_TYPE_SWRAP;
1072 1.1 jmcneill else
1073 1.1 jmcneill return 1;
1074 1.1 jmcneill
1075 1.1 jmcneill do {
1076 1.1 jmcneill do {
1077 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, *erom);
1078 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1079 1.1 jmcneill if (type == BWFM_DMP_DESC_COMPONENT)
1080 1.1 jmcneill return 0;
1081 1.1 jmcneill if (type == BWFM_DMP_DESC_EOT)
1082 1.1 jmcneill return 1;
1083 1.1 jmcneill *erom += 4;
1084 1.1 jmcneill } while ((type & ~BWFM_DMP_DESC_ADDRSIZE_GT32) !=
1085 1.1 jmcneill BWFM_DMP_DESC_ADDRESS);
1086 1.1 jmcneill
1087 1.1 jmcneill if (type & BWFM_DMP_DESC_ADDRSIZE_GT32)
1088 1.1 jmcneill *erom += 4;
1089 1.1 jmcneill
1090 1.1 jmcneill sztype = (val & BWFM_DMP_SLAVE_SIZE_TYPE)
1091 1.1 jmcneill >> BWFM_DMP_SLAVE_SIZE_TYPE_S;
1092 1.1 jmcneill if (sztype == BWFM_DMP_SLAVE_SIZE_DESC) {
1093 1.1 jmcneill val = sc->sc_buscore_ops->bc_read(sc, *erom);
1094 1.1 jmcneill type = val & BWFM_DMP_DESC_MASK;
1095 1.1 jmcneill if (type & BWFM_DMP_DESC_ADDRSIZE_GT32)
1096 1.1 jmcneill *erom += 8;
1097 1.1 jmcneill else
1098 1.1 jmcneill *erom += 4;
1099 1.1 jmcneill }
1100 1.1 jmcneill if (sztype != BWFM_DMP_SLAVE_SIZE_4K)
1101 1.1 jmcneill continue;
1102 1.1 jmcneill
1103 1.1 jmcneill stype = (val & BWFM_DMP_SLAVE_TYPE) >> BWFM_DMP_SLAVE_TYPE_S;
1104 1.1 jmcneill if (*base == 0 && stype == BWFM_DMP_SLAVE_TYPE_SLAVE)
1105 1.1 jmcneill *base = val & BWFM_DMP_SLAVE_ADDR_BASE;
1106 1.1 jmcneill if (*wrap == 0 && stype == wraptype)
1107 1.1 jmcneill *wrap = val & BWFM_DMP_SLAVE_ADDR_BASE;
1108 1.1 jmcneill } while (*base == 0 || *wrap == 0);
1109 1.1 jmcneill
1110 1.1 jmcneill return 0;
1111 1.1 jmcneill }
1112 1.1 jmcneill
1113 1.1 jmcneill /* Core configuration */
1114 1.11 maya int
1115 1.11 maya bwfm_chip_set_active(struct bwfm_softc *sc, const uint32_t rstvec)
1116 1.11 maya {
1117 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4) != NULL)
1118 1.11 maya return bwfm_chip_cr4_set_active(sc, rstvec);
1119 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7) != NULL)
1120 1.11 maya return bwfm_chip_ca7_set_active(sc, rstvec);
1121 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3) != NULL)
1122 1.11 maya return bwfm_chip_cm3_set_active(sc);
1123 1.11 maya return 1;
1124 1.11 maya }
1125 1.11 maya
1126 1.11 maya void
1127 1.11 maya bwfm_chip_set_passive(struct bwfm_softc *sc)
1128 1.11 maya {
1129 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4) != NULL) {
1130 1.11 maya bwfm_chip_cr4_set_passive(sc);
1131 1.11 maya return;
1132 1.11 maya }
1133 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7) != NULL) {
1134 1.11 maya bwfm_chip_ca7_set_passive(sc);
1135 1.11 maya return;
1136 1.11 maya }
1137 1.11 maya if (bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3) != NULL) {
1138 1.11 maya bwfm_chip_cm3_set_passive(sc);
1139 1.11 maya return;
1140 1.11 maya }
1141 1.11 maya }
1142 1.11 maya
1143 1.11 maya int
1144 1.11 maya bwfm_chip_cr4_set_active(struct bwfm_softc *sc, const uint32_t rstvec)
1145 1.11 maya {
1146 1.11 maya struct bwfm_core *core;
1147 1.11 maya
1148 1.11 maya sc->sc_buscore_ops->bc_activate(sc, rstvec);
1149 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4);
1150 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1151 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT, 0, 0);
1152 1.11 maya
1153 1.11 maya return 0;
1154 1.11 maya }
1155 1.11 maya
1156 1.1 jmcneill void
1157 1.1 jmcneill bwfm_chip_cr4_set_passive(struct bwfm_softc *sc)
1158 1.1 jmcneill {
1159 1.11 maya struct bwfm_core *core;
1160 1.11 maya uint32_t val;
1161 1.11 maya
1162 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CR4);
1163 1.11 maya val = sc->sc_buscore_ops->bc_read(sc,
1164 1.11 maya core->co_wrapbase + BWFM_AGENT_IOCTL);
1165 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1166 1.11 maya val & BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1167 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1168 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT);
1169 1.11 maya
1170 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_80211);
1171 1.11 maya sc->sc_chip.ch_core_reset(sc, core, BWFM_AGENT_D11_IOCTL_PHYRESET |
1172 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN, BWFM_AGENT_D11_IOCTL_PHYCLOCKEN,
1173 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN);
1174 1.11 maya }
1175 1.11 maya
1176 1.11 maya int
1177 1.11 maya bwfm_chip_ca7_set_active(struct bwfm_softc *sc, const uint32_t rstvec)
1178 1.11 maya {
1179 1.11 maya struct bwfm_core *core;
1180 1.11 maya
1181 1.11 maya sc->sc_buscore_ops->bc_activate(sc, rstvec);
1182 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7);
1183 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1184 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT, 0, 0);
1185 1.11 maya
1186 1.11 maya return 0;
1187 1.1 jmcneill }
1188 1.1 jmcneill
1189 1.1 jmcneill void
1190 1.1 jmcneill bwfm_chip_ca7_set_passive(struct bwfm_softc *sc)
1191 1.1 jmcneill {
1192 1.11 maya struct bwfm_core *core;
1193 1.11 maya uint32_t val;
1194 1.11 maya
1195 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CA7);
1196 1.11 maya val = sc->sc_buscore_ops->bc_read(sc,
1197 1.11 maya core->co_wrapbase + BWFM_AGENT_IOCTL);
1198 1.11 maya sc->sc_chip.ch_core_reset(sc, core,
1199 1.11 maya val & BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1200 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT,
1201 1.11 maya BWFM_AGENT_IOCTL_ARMCR4_CPUHALT);
1202 1.11 maya
1203 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_80211);
1204 1.11 maya sc->sc_chip.ch_core_reset(sc, core, BWFM_AGENT_D11_IOCTL_PHYRESET |
1205 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN, BWFM_AGENT_D11_IOCTL_PHYCLOCKEN,
1206 1.11 maya BWFM_AGENT_D11_IOCTL_PHYCLOCKEN);
1207 1.11 maya }
1208 1.11 maya
1209 1.11 maya int
1210 1.11 maya bwfm_chip_cm3_set_active(struct bwfm_softc *sc)
1211 1.11 maya {
1212 1.11 maya struct bwfm_core *core;
1213 1.11 maya
1214 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_INTERNAL_MEM);
1215 1.11 maya if (!sc->sc_chip.ch_core_isup(sc, core))
1216 1.11 maya return 1;
1217 1.11 maya
1218 1.11 maya sc->sc_buscore_ops->bc_activate(sc, 0);
1219 1.11 maya
1220 1.11 maya core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3);
1221 1.11 maya sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1222 1.11 maya
1223 1.11 maya return 0;
1224 1.1 jmcneill }
1225 1.1 jmcneill
1226 1.1 jmcneill void
1227 1.1 jmcneill bwfm_chip_cm3_set_passive(struct bwfm_softc *sc)
1228 1.1 jmcneill {
1229 1.1 jmcneill struct bwfm_core *core;
1230 1.1 jmcneill
1231 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_ARM_CM3);
1232 1.1 jmcneill sc->sc_chip.ch_core_disable(sc, core, 0, 0);
1233 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_80211);
1234 1.1 jmcneill sc->sc_chip.ch_core_reset(sc, core, BWFM_AGENT_D11_IOCTL_PHYRESET |
1235 1.1 jmcneill BWFM_AGENT_D11_IOCTL_PHYCLOCKEN, BWFM_AGENT_D11_IOCTL_PHYCLOCKEN,
1236 1.1 jmcneill BWFM_AGENT_D11_IOCTL_PHYCLOCKEN);
1237 1.1 jmcneill core = bwfm_chip_get_core(sc, BWFM_AGENT_INTERNAL_MEM);
1238 1.1 jmcneill sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1239 1.1 jmcneill
1240 1.1 jmcneill if (sc->sc_chip.ch_chip == BRCM_CC_43430_CHIP_ID) {
1241 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
1242 1.1 jmcneill core->co_base + BWFM_SOCRAM_BANKIDX, 3);
1243 1.1 jmcneill sc->sc_buscore_ops->bc_write(sc,
1244 1.1 jmcneill core->co_base + BWFM_SOCRAM_BANKPDA, 0);
1245 1.1 jmcneill }
1246 1.1 jmcneill }
1247 1.1 jmcneill
1248 1.15 mlelstv int
1249 1.15 mlelstv bwfm_chip_sr_capable(struct bwfm_softc *sc)
1250 1.15 mlelstv {
1251 1.15 mlelstv struct bwfm_core *core;
1252 1.15 mlelstv uint32_t reg;
1253 1.15 mlelstv
1254 1.15 mlelstv if (sc->sc_chip.ch_pmurev < 17)
1255 1.15 mlelstv return 0;
1256 1.15 mlelstv
1257 1.15 mlelstv switch (sc->sc_chip.ch_chip) {
1258 1.15 mlelstv case BRCM_CC_4345_CHIP_ID:
1259 1.15 mlelstv case BRCM_CC_4354_CHIP_ID:
1260 1.15 mlelstv case BRCM_CC_4356_CHIP_ID:
1261 1.15 mlelstv core = bwfm_chip_get_pmu(sc);
1262 1.15 mlelstv sc->sc_buscore_ops->bc_write(sc, core->co_base +
1263 1.15 mlelstv BWFM_CHIP_REG_CHIPCONTROL_ADDR, 3);
1264 1.15 mlelstv reg = sc->sc_buscore_ops->bc_read(sc, core->co_base +
1265 1.15 mlelstv BWFM_CHIP_REG_CHIPCONTROL_DATA);
1266 1.15 mlelstv return (reg & (1 << 2)) != 0;
1267 1.15 mlelstv case BRCM_CC_43241_CHIP_ID:
1268 1.15 mlelstv case BRCM_CC_4335_CHIP_ID:
1269 1.15 mlelstv case BRCM_CC_4339_CHIP_ID:
1270 1.15 mlelstv core = bwfm_chip_get_pmu(sc);
1271 1.15 mlelstv sc->sc_buscore_ops->bc_write(sc, core->co_base +
1272 1.15 mlelstv BWFM_CHIP_REG_CHIPCONTROL_ADDR, 3);
1273 1.15 mlelstv reg = sc->sc_buscore_ops->bc_read(sc, core->co_base +
1274 1.15 mlelstv BWFM_CHIP_REG_CHIPCONTROL_DATA);
1275 1.15 mlelstv return reg != 0;
1276 1.15 mlelstv case BRCM_CC_43430_CHIP_ID:
1277 1.15 mlelstv core = bwfm_chip_get_core(sc, BWFM_AGENT_CORE_CHIPCOMMON);
1278 1.15 mlelstv reg = sc->sc_buscore_ops->bc_read(sc, core->co_base +
1279 1.15 mlelstv BWFM_CHIP_REG_SR_CONTROL1);
1280 1.15 mlelstv return reg != 0;
1281 1.15 mlelstv default:
1282 1.15 mlelstv core = bwfm_chip_get_pmu(sc);
1283 1.15 mlelstv reg = sc->sc_buscore_ops->bc_read(sc, core->co_base +
1284 1.15 mlelstv BWFM_CHIP_REG_PMUCAPABILITIES_EXT);
1285 1.15 mlelstv if ((reg & BWFM_CHIP_REG_PMUCAPABILITIES_SR_SUPP) == 0)
1286 1.15 mlelstv return 0;
1287 1.15 mlelstv reg = sc->sc_buscore_ops->bc_read(sc, core->co_base +
1288 1.15 mlelstv BWFM_CHIP_REG_RETENTION_CTL);
1289 1.15 mlelstv return (reg & (BWFM_CHIP_REG_RETENTION_CTL_MACPHY_DIS |
1290 1.15 mlelstv BWFM_CHIP_REG_RETENTION_CTL_LOGIC_DIS)) == 0;
1291 1.15 mlelstv }
1292 1.15 mlelstv }
1293 1.15 mlelstv
1294 1.11 maya /* RAM size helpers */
1295 1.11 maya void
1296 1.11 maya bwfm_chip_socram_ramsize(struct bwfm_softc *sc, struct bwfm_core *core)
1297 1.11 maya {
1298 1.11 maya uint32_t coreinfo, nb, lss, banksize, bankinfo;
1299 1.11 maya uint32_t ramsize = 0, srsize = 0;
1300 1.11 maya int i;
1301 1.11 maya
1302 1.11 maya if (!sc->sc_chip.ch_core_isup(sc, core))
1303 1.11 maya sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1304 1.11 maya
1305 1.11 maya coreinfo = sc->sc_buscore_ops->bc_read(sc,
1306 1.11 maya core->co_base + BWFM_SOCRAM_COREINFO);
1307 1.11 maya nb = (coreinfo & BWFM_SOCRAM_COREINFO_SRNB_MASK)
1308 1.11 maya >> BWFM_SOCRAM_COREINFO_SRNB_SHIFT;
1309 1.11 maya
1310 1.11 maya if (core->co_rev <= 7 || core->co_rev == 12) {
1311 1.11 maya banksize = coreinfo & BWFM_SOCRAM_COREINFO_SRBSZ_MASK;
1312 1.11 maya lss = (coreinfo & BWFM_SOCRAM_COREINFO_LSS_MASK)
1313 1.11 maya >> BWFM_SOCRAM_COREINFO_LSS_SHIFT;
1314 1.11 maya if (lss != 0)
1315 1.11 maya nb--;
1316 1.11 maya ramsize = nb * (1 << (banksize + BWFM_SOCRAM_COREINFO_SRBSZ_BASE));
1317 1.11 maya if (lss != 0)
1318 1.11 maya ramsize += (1 << ((lss - 1) + BWFM_SOCRAM_COREINFO_SRBSZ_BASE));
1319 1.11 maya } else {
1320 1.11 maya for (i = 0; i < nb; i++) {
1321 1.11 maya sc->sc_buscore_ops->bc_write(sc,
1322 1.11 maya core->co_base + BWFM_SOCRAM_BANKIDX,
1323 1.11 maya (BWFM_SOCRAM_BANKIDX_MEMTYPE_RAM <<
1324 1.11 maya BWFM_SOCRAM_BANKIDX_MEMTYPE_SHIFT) | i);
1325 1.11 maya bankinfo = sc->sc_buscore_ops->bc_read(sc,
1326 1.11 maya core->co_base + BWFM_SOCRAM_BANKINFO);
1327 1.11 maya banksize = ((bankinfo & BWFM_SOCRAM_BANKINFO_SZMASK) + 1)
1328 1.11 maya * BWFM_SOCRAM_BANKINFO_SZBASE;
1329 1.11 maya ramsize += banksize;
1330 1.11 maya if (bankinfo & BWFM_SOCRAM_BANKINFO_RETNTRAM_MASK)
1331 1.11 maya srsize += banksize;
1332 1.11 maya }
1333 1.11 maya }
1334 1.11 maya
1335 1.11 maya switch (sc->sc_chip.ch_chip) {
1336 1.11 maya case BRCM_CC_4334_CHIP_ID:
1337 1.11 maya if (sc->sc_chip.ch_chiprev < 2)
1338 1.11 maya srsize = 32 * 1024;
1339 1.11 maya break;
1340 1.11 maya case BRCM_CC_43430_CHIP_ID:
1341 1.11 maya srsize = 64 * 1024;
1342 1.11 maya break;
1343 1.11 maya default:
1344 1.11 maya break;
1345 1.11 maya }
1346 1.11 maya
1347 1.11 maya sc->sc_chip.ch_ramsize = ramsize;
1348 1.11 maya sc->sc_chip.ch_srsize = srsize;
1349 1.11 maya }
1350 1.11 maya
1351 1.11 maya void
1352 1.11 maya bwfm_chip_sysmem_ramsize(struct bwfm_softc *sc, struct bwfm_core *core)
1353 1.11 maya {
1354 1.11 maya uint32_t coreinfo, nb, banksize, bankinfo;
1355 1.11 maya uint32_t ramsize = 0;
1356 1.11 maya int i;
1357 1.11 maya
1358 1.11 maya if (!sc->sc_chip.ch_core_isup(sc, core))
1359 1.11 maya sc->sc_chip.ch_core_reset(sc, core, 0, 0, 0);
1360 1.11 maya
1361 1.11 maya coreinfo = sc->sc_buscore_ops->bc_read(sc,
1362 1.11 maya core->co_base + BWFM_SOCRAM_COREINFO);
1363 1.11 maya nb = (coreinfo & BWFM_SOCRAM_COREINFO_SRNB_MASK)
1364 1.11 maya >> BWFM_SOCRAM_COREINFO_SRNB_SHIFT;
1365 1.11 maya
1366 1.11 maya for (i = 0; i < nb; i++) {
1367 1.11 maya sc->sc_buscore_ops->bc_write(sc,
1368 1.11 maya core->co_base + BWFM_SOCRAM_BANKIDX,
1369 1.11 maya (BWFM_SOCRAM_BANKIDX_MEMTYPE_RAM <<
1370 1.11 maya BWFM_SOCRAM_BANKIDX_MEMTYPE_SHIFT) | i);
1371 1.11 maya bankinfo = sc->sc_buscore_ops->bc_read(sc,
1372 1.11 maya core->co_base + BWFM_SOCRAM_BANKINFO);
1373 1.11 maya banksize = ((bankinfo & BWFM_SOCRAM_BANKINFO_SZMASK) + 1)
1374 1.11 maya * BWFM_SOCRAM_BANKINFO_SZBASE;
1375 1.11 maya ramsize += banksize;
1376 1.11 maya }
1377 1.11 maya
1378 1.11 maya sc->sc_chip.ch_ramsize = ramsize;
1379 1.11 maya }
1380 1.11 maya
1381 1.11 maya void
1382 1.11 maya bwfm_chip_tcm_ramsize(struct bwfm_softc *sc, struct bwfm_core *core)
1383 1.11 maya {
1384 1.11 maya uint32_t cap, nab, nbb, totb, bxinfo, ramsize = 0;
1385 1.11 maya int i;
1386 1.11 maya
1387 1.11 maya cap = sc->sc_buscore_ops->bc_read(sc, core->co_base + BWFM_ARMCR4_CAP);
1388 1.11 maya nab = (cap & BWFM_ARMCR4_CAP_TCBANB_MASK) >> BWFM_ARMCR4_CAP_TCBANB_SHIFT;
1389 1.11 maya nbb = (cap & BWFM_ARMCR4_CAP_TCBBNB_MASK) >> BWFM_ARMCR4_CAP_TCBBNB_SHIFT;
1390 1.11 maya totb = nab + nbb;
1391 1.11 maya
1392 1.11 maya for (i = 0; i < totb; i++) {
1393 1.11 maya sc->sc_buscore_ops->bc_write(sc,
1394 1.11 maya core->co_base + BWFM_ARMCR4_BANKIDX, i);
1395 1.11 maya bxinfo = sc->sc_buscore_ops->bc_read(sc,
1396 1.11 maya core->co_base + BWFM_ARMCR4_BANKINFO);
1397 1.11 maya ramsize += ((bxinfo & BWFM_ARMCR4_BANKINFO_BSZ_MASK) + 1) *
1398 1.11 maya BWFM_ARMCR4_BANKINFO_BSZ_MULT;
1399 1.11 maya }
1400 1.11 maya
1401 1.11 maya sc->sc_chip.ch_ramsize = ramsize;
1402 1.11 maya }
1403 1.11 maya
1404 1.11 maya void
1405 1.11 maya bwfm_chip_tcm_rambase(struct bwfm_softc *sc)
1406 1.11 maya {
1407 1.11 maya switch (sc->sc_chip.ch_chip) {
1408 1.11 maya case BRCM_CC_4345_CHIP_ID:
1409 1.11 maya sc->sc_chip.ch_rambase = 0x198000;
1410 1.11 maya break;
1411 1.11 maya case BRCM_CC_4335_CHIP_ID:
1412 1.11 maya case BRCM_CC_4339_CHIP_ID:
1413 1.11 maya case BRCM_CC_4350_CHIP_ID:
1414 1.11 maya case BRCM_CC_4354_CHIP_ID:
1415 1.11 maya case BRCM_CC_4356_CHIP_ID:
1416 1.11 maya case BRCM_CC_43567_CHIP_ID:
1417 1.11 maya case BRCM_CC_43569_CHIP_ID:
1418 1.11 maya case BRCM_CC_43570_CHIP_ID:
1419 1.11 maya case BRCM_CC_4358_CHIP_ID:
1420 1.11 maya case BRCM_CC_4359_CHIP_ID:
1421 1.11 maya case BRCM_CC_43602_CHIP_ID:
1422 1.11 maya case BRCM_CC_4371_CHIP_ID:
1423 1.11 maya sc->sc_chip.ch_rambase = 0x180000;
1424 1.11 maya break;
1425 1.11 maya case BRCM_CC_43465_CHIP_ID:
1426 1.11 maya case BRCM_CC_43525_CHIP_ID:
1427 1.11 maya case BRCM_CC_4365_CHIP_ID:
1428 1.11 maya case BRCM_CC_4366_CHIP_ID:
1429 1.11 maya sc->sc_chip.ch_rambase = 0x200000;
1430 1.11 maya break;
1431 1.11 maya case CY_CC_4373_CHIP_ID:
1432 1.11 maya sc->sc_chip.ch_rambase = 0x160000;
1433 1.11 maya break;
1434 1.11 maya default:
1435 1.11 maya printf("%s: unknown chip: %d\n", DEVNAME(sc),
1436 1.11 maya sc->sc_chip.ch_chip);
1437 1.11 maya break;
1438 1.11 maya }
1439 1.11 maya }
1440 1.11 maya
1441 1.1 jmcneill /* BCDC protocol implementation */
1442 1.1 jmcneill int
1443 1.1 jmcneill bwfm_proto_bcdc_query_dcmd(struct bwfm_softc *sc, int ifidx,
1444 1.1 jmcneill int cmd, char *buf, size_t *len)
1445 1.1 jmcneill {
1446 1.1 jmcneill struct bwfm_proto_bcdc_dcmd *dcmd;
1447 1.1 jmcneill size_t size = sizeof(dcmd->hdr) + *len;
1448 1.1 jmcneill static int reqid = 0;
1449 1.1 jmcneill int ret = 1;
1450 1.1 jmcneill
1451 1.1 jmcneill reqid++;
1452 1.1 jmcneill
1453 1.1 jmcneill dcmd = kmem_zalloc(sizeof(*dcmd), KM_SLEEP);
1454 1.1 jmcneill if (*len > sizeof(dcmd->buf))
1455 1.1 jmcneill goto err;
1456 1.1 jmcneill
1457 1.1 jmcneill dcmd->hdr.cmd = htole32(cmd);
1458 1.1 jmcneill dcmd->hdr.len = htole32(*len);
1459 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_GET;
1460 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_ID_SET(reqid);
1461 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_IF_SET(ifidx);
1462 1.1 jmcneill dcmd->hdr.flags = htole32(dcmd->hdr.flags);
1463 1.1 jmcneill memcpy(&dcmd->buf, buf, *len);
1464 1.1 jmcneill
1465 1.1 jmcneill if (sc->sc_bus_ops->bs_txctl(sc, (void *)dcmd,
1466 1.1 jmcneill sizeof(dcmd->hdr) + *len)) {
1467 1.1 jmcneill DPRINTF(("%s: tx failed\n", DEVNAME(sc)));
1468 1.1 jmcneill goto err;
1469 1.1 jmcneill }
1470 1.1 jmcneill
1471 1.1 jmcneill do {
1472 1.1 jmcneill if (sc->sc_bus_ops->bs_rxctl(sc, (void *)dcmd, &size)) {
1473 1.1 jmcneill DPRINTF(("%s: rx failed\n", DEVNAME(sc)));
1474 1.1 jmcneill goto err;
1475 1.1 jmcneill }
1476 1.1 jmcneill dcmd->hdr.cmd = le32toh(dcmd->hdr.cmd);
1477 1.1 jmcneill dcmd->hdr.len = le32toh(dcmd->hdr.len);
1478 1.1 jmcneill dcmd->hdr.flags = le32toh(dcmd->hdr.flags);
1479 1.1 jmcneill dcmd->hdr.status = le32toh(dcmd->hdr.status);
1480 1.1 jmcneill } while (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid);
1481 1.1 jmcneill
1482 1.1 jmcneill if (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid) {
1483 1.1 jmcneill printf("%s: unexpected request id\n", DEVNAME(sc));
1484 1.1 jmcneill goto err;
1485 1.1 jmcneill }
1486 1.1 jmcneill
1487 1.1 jmcneill if (buf) {
1488 1.1 jmcneill if (size < *len)
1489 1.1 jmcneill *len = size;
1490 1.1 jmcneill memcpy(buf, dcmd->buf, *len);
1491 1.1 jmcneill }
1492 1.1 jmcneill
1493 1.1 jmcneill if (dcmd->hdr.flags & BWFM_BCDC_DCMD_ERROR)
1494 1.1 jmcneill ret = dcmd->hdr.status;
1495 1.1 jmcneill else
1496 1.1 jmcneill ret = 0;
1497 1.1 jmcneill err:
1498 1.1 jmcneill kmem_free(dcmd, sizeof(*dcmd));
1499 1.1 jmcneill return ret;
1500 1.1 jmcneill }
1501 1.1 jmcneill
1502 1.1 jmcneill int
1503 1.1 jmcneill bwfm_proto_bcdc_set_dcmd(struct bwfm_softc *sc, int ifidx,
1504 1.1 jmcneill int cmd, char *buf, size_t len)
1505 1.1 jmcneill {
1506 1.1 jmcneill struct bwfm_proto_bcdc_dcmd *dcmd;
1507 1.1 jmcneill size_t size = sizeof(dcmd->hdr) + len;
1508 1.1 jmcneill int reqid = 0;
1509 1.1 jmcneill int ret = 1;
1510 1.1 jmcneill
1511 1.1 jmcneill reqid++;
1512 1.1 jmcneill
1513 1.1 jmcneill dcmd = kmem_zalloc(sizeof(*dcmd), KM_SLEEP);
1514 1.1 jmcneill if (len > sizeof(dcmd->buf))
1515 1.1 jmcneill goto err;
1516 1.1 jmcneill
1517 1.1 jmcneill dcmd->hdr.cmd = htole32(cmd);
1518 1.1 jmcneill dcmd->hdr.len = htole32(len);
1519 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_SET;
1520 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_ID_SET(reqid);
1521 1.1 jmcneill dcmd->hdr.flags |= BWFM_BCDC_DCMD_IF_SET(ifidx);
1522 1.1 jmcneill dcmd->hdr.flags = htole32(dcmd->hdr.flags);
1523 1.1 jmcneill memcpy(&dcmd->buf, buf, len);
1524 1.1 jmcneill
1525 1.1 jmcneill if (sc->sc_bus_ops->bs_txctl(sc, (void *)dcmd, size)) {
1526 1.1 jmcneill DPRINTF(("%s: tx failed\n", DEVNAME(sc)));
1527 1.1 jmcneill goto err;
1528 1.1 jmcneill }
1529 1.1 jmcneill
1530 1.1 jmcneill do {
1531 1.1 jmcneill if (sc->sc_bus_ops->bs_rxctl(sc, (void *)dcmd, &size)) {
1532 1.1 jmcneill DPRINTF(("%s: rx failed\n", DEVNAME(sc)));
1533 1.1 jmcneill goto err;
1534 1.1 jmcneill }
1535 1.1 jmcneill dcmd->hdr.cmd = le32toh(dcmd->hdr.cmd);
1536 1.1 jmcneill dcmd->hdr.len = le32toh(dcmd->hdr.len);
1537 1.1 jmcneill dcmd->hdr.flags = le32toh(dcmd->hdr.flags);
1538 1.1 jmcneill dcmd->hdr.status = le32toh(dcmd->hdr.status);
1539 1.1 jmcneill } while (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid);
1540 1.1 jmcneill
1541 1.1 jmcneill if (BWFM_BCDC_DCMD_ID_GET(dcmd->hdr.flags) != reqid) {
1542 1.1 jmcneill printf("%s: unexpected request id\n", DEVNAME(sc));
1543 1.1 jmcneill goto err;
1544 1.1 jmcneill }
1545 1.1 jmcneill
1546 1.1 jmcneill if (dcmd->hdr.flags & BWFM_BCDC_DCMD_ERROR)
1547 1.1 jmcneill return dcmd->hdr.status;
1548 1.1 jmcneill
1549 1.1 jmcneill ret = 0;
1550 1.1 jmcneill err:
1551 1.1 jmcneill kmem_free(dcmd, sizeof(*dcmd));
1552 1.1 jmcneill return ret;
1553 1.1 jmcneill }
1554 1.1 jmcneill
1555 1.1 jmcneill /* FW Variable code */
1556 1.1 jmcneill int
1557 1.1 jmcneill bwfm_fwvar_cmd_get_data(struct bwfm_softc *sc, int cmd, void *data, size_t len)
1558 1.1 jmcneill {
1559 1.1 jmcneill return sc->sc_proto_ops->proto_query_dcmd(sc, 0, cmd, data, &len);
1560 1.1 jmcneill }
1561 1.1 jmcneill
1562 1.1 jmcneill int
1563 1.1 jmcneill bwfm_fwvar_cmd_set_data(struct bwfm_softc *sc, int cmd, void *data, size_t len)
1564 1.1 jmcneill {
1565 1.1 jmcneill return sc->sc_proto_ops->proto_set_dcmd(sc, 0, cmd, data, len);
1566 1.1 jmcneill }
1567 1.1 jmcneill
1568 1.1 jmcneill int
1569 1.1 jmcneill bwfm_fwvar_cmd_get_int(struct bwfm_softc *sc, int cmd, uint32_t *data)
1570 1.1 jmcneill {
1571 1.1 jmcneill int ret;
1572 1.1 jmcneill ret = bwfm_fwvar_cmd_get_data(sc, cmd, data, sizeof(*data));
1573 1.1 jmcneill *data = le32toh(*data);
1574 1.1 jmcneill return ret;
1575 1.1 jmcneill }
1576 1.1 jmcneill
1577 1.1 jmcneill int
1578 1.1 jmcneill bwfm_fwvar_cmd_set_int(struct bwfm_softc *sc, int cmd, uint32_t data)
1579 1.1 jmcneill {
1580 1.1 jmcneill data = htole32(data);
1581 1.1 jmcneill return bwfm_fwvar_cmd_set_data(sc, cmd, &data, sizeof(data));
1582 1.1 jmcneill }
1583 1.1 jmcneill
1584 1.1 jmcneill int
1585 1.1 jmcneill bwfm_fwvar_var_get_data(struct bwfm_softc *sc, const char *name, void *data, size_t len)
1586 1.1 jmcneill {
1587 1.1 jmcneill char *buf;
1588 1.1 jmcneill int ret;
1589 1.1 jmcneill
1590 1.1 jmcneill buf = kmem_alloc(strlen(name) + 1 + len, KM_SLEEP);
1591 1.1 jmcneill memcpy(buf, name, strlen(name) + 1);
1592 1.1 jmcneill memcpy(buf + strlen(name) + 1, data, len);
1593 1.1 jmcneill ret = bwfm_fwvar_cmd_get_data(sc, BWFM_C_GET_VAR,
1594 1.1 jmcneill buf, strlen(name) + 1 + len);
1595 1.1 jmcneill memcpy(data, buf, len);
1596 1.1 jmcneill kmem_free(buf, strlen(name) + 1 + len);
1597 1.1 jmcneill return ret;
1598 1.1 jmcneill }
1599 1.1 jmcneill
1600 1.1 jmcneill int
1601 1.1 jmcneill bwfm_fwvar_var_set_data(struct bwfm_softc *sc, const char *name, void *data, size_t len)
1602 1.1 jmcneill {
1603 1.1 jmcneill char *buf;
1604 1.1 jmcneill int ret;
1605 1.1 jmcneill
1606 1.1 jmcneill buf = kmem_alloc(strlen(name) + 1 + len, KM_SLEEP);
1607 1.1 jmcneill memcpy(buf, name, strlen(name) + 1);
1608 1.1 jmcneill memcpy(buf + strlen(name) + 1, data, len);
1609 1.1 jmcneill ret = bwfm_fwvar_cmd_set_data(sc, BWFM_C_SET_VAR,
1610 1.1 jmcneill buf, strlen(name) + 1 + len);
1611 1.1 jmcneill kmem_free(buf, strlen(name) + 1 + len);
1612 1.1 jmcneill return ret;
1613 1.1 jmcneill }
1614 1.1 jmcneill
1615 1.1 jmcneill int
1616 1.1 jmcneill bwfm_fwvar_var_get_int(struct bwfm_softc *sc, const char *name, uint32_t *data)
1617 1.1 jmcneill {
1618 1.1 jmcneill int ret;
1619 1.1 jmcneill ret = bwfm_fwvar_var_get_data(sc, name, data, sizeof(*data));
1620 1.1 jmcneill *data = le32toh(*data);
1621 1.1 jmcneill return ret;
1622 1.1 jmcneill }
1623 1.1 jmcneill
1624 1.1 jmcneill int
1625 1.1 jmcneill bwfm_fwvar_var_set_int(struct bwfm_softc *sc, const char *name, uint32_t data)
1626 1.1 jmcneill {
1627 1.1 jmcneill data = htole32(data);
1628 1.1 jmcneill return bwfm_fwvar_var_set_data(sc, name, &data, sizeof(data));
1629 1.1 jmcneill }
1630 1.1 jmcneill
1631 1.1 jmcneill /* 802.11 code */
1632 1.1 jmcneill void
1633 1.1 jmcneill bwfm_scan(struct bwfm_softc *sc)
1634 1.1 jmcneill {
1635 1.1 jmcneill struct bwfm_escan_params *params;
1636 1.1 jmcneill uint32_t nssid = 0, nchannel = 0;
1637 1.1 jmcneill size_t params_size;
1638 1.1 jmcneill
1639 1.1 jmcneill #if 0
1640 1.1 jmcneill /* Active scan is used for scanning for an SSID */
1641 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PASSIVE_SCAN, 0);
1642 1.1 jmcneill #endif
1643 1.1 jmcneill bwfm_fwvar_cmd_set_int(sc, BWFM_C_SET_PASSIVE_SCAN, 1);
1644 1.1 jmcneill
1645 1.1 jmcneill params_size = sizeof(*params);
1646 1.1 jmcneill params_size += sizeof(uint32_t) * ((nchannel + 1) / 2);
1647 1.1 jmcneill params_size += sizeof(struct bwfm_ssid) * nssid;
1648 1.1 jmcneill
1649 1.1 jmcneill params = kmem_zalloc(params_size, KM_SLEEP);
1650 1.1 jmcneill memset(params->scan_params.bssid, 0xff,
1651 1.1 jmcneill sizeof(params->scan_params.bssid));
1652 1.1 jmcneill params->scan_params.bss_type = 2;
1653 1.1 jmcneill params->scan_params.nprobes = htole32(-1);
1654 1.1 jmcneill params->scan_params.active_time = htole32(-1);
1655 1.1 jmcneill params->scan_params.passive_time = htole32(-1);
1656 1.1 jmcneill params->scan_params.home_time = htole32(-1);
1657 1.1 jmcneill params->version = htole32(BWFM_ESCAN_REQ_VERSION);
1658 1.1 jmcneill params->action = htole16(WL_ESCAN_ACTION_START);
1659 1.1 jmcneill params->sync_id = htole16(0x1234);
1660 1.1 jmcneill
1661 1.1 jmcneill #if 0
1662 1.1 jmcneill /* Scan a specific channel */
1663 1.1 jmcneill params->scan_params.channel_list[0] = htole16(
1664 1.1 jmcneill (1 & 0xff) << 0 |
1665 1.1 jmcneill (3 & 0x3) << 8 |
1666 1.1 jmcneill (2 & 0x3) << 10 |
1667 1.1 jmcneill (2 & 0x3) << 12
1668 1.1 jmcneill );
1669 1.1 jmcneill params->scan_params.channel_num = htole32(
1670 1.1 jmcneill (1 & 0xffff) << 0
1671 1.1 jmcneill );
1672 1.1 jmcneill #endif
1673 1.1 jmcneill
1674 1.1 jmcneill bwfm_fwvar_var_set_data(sc, "escan", params, params_size);
1675 1.1 jmcneill kmem_free(params, params_size);
1676 1.1 jmcneill }
1677 1.1 jmcneill
1678 1.1 jmcneill static __inline int
1679 1.1 jmcneill bwfm_iswpaoui(const uint8_t *frm)
1680 1.1 jmcneill {
1681 1.1 jmcneill return frm[1] > 3 && le32dec(frm+2) == ((WPA_OUI_TYPE<<24)|WPA_OUI);
1682 1.1 jmcneill }
1683 1.1 jmcneill
1684 1.1 jmcneill /*
1685 1.1 jmcneill * Derive wireless security settings from WPA/RSN IE.
1686 1.1 jmcneill */
1687 1.1 jmcneill static uint32_t
1688 1.1 jmcneill bwfm_get_wsec(struct bwfm_softc *sc)
1689 1.1 jmcneill {
1690 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1691 1.1 jmcneill uint8_t *wpa = ic->ic_opt_ie;
1692 1.1 jmcneill
1693 1.1 jmcneill KASSERT(ic->ic_opt_ie_len > 0);
1694 1.1 jmcneill
1695 1.1 jmcneill if (wpa[0] != IEEE80211_ELEMID_RSN) {
1696 1.1 jmcneill if (ic->ic_opt_ie_len < 12)
1697 1.1 jmcneill return BWFM_WSEC_NONE;
1698 1.1 jmcneill
1699 1.1 jmcneill /* non-RSN IE, expect that we are doing WPA1 */
1700 1.1 jmcneill if ((ic->ic_flags & IEEE80211_F_WPA1) == 0)
1701 1.1 jmcneill return BWFM_WSEC_NONE;
1702 1.1 jmcneill
1703 1.1 jmcneill /* Must contain WPA OUI */
1704 1.1 jmcneill if (!bwfm_iswpaoui(wpa))
1705 1.1 jmcneill return BWFM_WSEC_NONE;
1706 1.1 jmcneill
1707 1.1 jmcneill switch (le32dec(wpa + 8)) {
1708 1.1 jmcneill case ((WPA_CSE_TKIP<<24)|WPA_OUI):
1709 1.1 jmcneill return BWFM_WSEC_TKIP;
1710 1.1 jmcneill case ((WPA_CSE_CCMP<<24)|WPA_OUI):
1711 1.1 jmcneill return BWFM_WSEC_AES;
1712 1.1 jmcneill default:
1713 1.1 jmcneill return BWFM_WSEC_NONE;
1714 1.1 jmcneill }
1715 1.1 jmcneill } else {
1716 1.1 jmcneill if (ic->ic_opt_ie_len < 14)
1717 1.1 jmcneill return BWFM_WSEC_NONE;
1718 1.1 jmcneill
1719 1.1 jmcneill /* RSN IE, expect that we are doing WPA2 */
1720 1.1 jmcneill if ((ic->ic_flags & IEEE80211_F_WPA2) == 0)
1721 1.1 jmcneill return BWFM_WSEC_NONE;
1722 1.1 jmcneill
1723 1.1 jmcneill switch (le32dec(wpa + 10)) {
1724 1.1 jmcneill case ((RSN_CSE_TKIP<<24)|RSN_OUI):
1725 1.1 jmcneill return BWFM_WSEC_TKIP;
1726 1.1 jmcneill case ((RSN_CSE_CCMP<<24)|RSN_OUI):
1727 1.1 jmcneill return BWFM_WSEC_AES;
1728 1.1 jmcneill default:
1729 1.1 jmcneill return BWFM_WSEC_NONE;
1730 1.1 jmcneill }
1731 1.1 jmcneill }
1732 1.1 jmcneill }
1733 1.1 jmcneill
1734 1.1 jmcneill void
1735 1.1 jmcneill bwfm_connect(struct bwfm_softc *sc)
1736 1.1 jmcneill {
1737 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1738 1.1 jmcneill struct ieee80211_node *ni = ic->ic_bss;
1739 1.1 jmcneill struct bwfm_ext_join_params *params;
1740 1.1 jmcneill
1741 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_WPA) {
1742 1.1 jmcneill uint32_t wsec = 0;
1743 1.1 jmcneill uint32_t wpa = 0;
1744 1.1 jmcneill
1745 1.1 jmcneill if (ic->ic_opt_ie_len)
1746 1.1 jmcneill bwfm_fwvar_var_set_data(sc, "wpaie", ic->ic_opt_ie, ic->ic_opt_ie_len);
1747 1.1 jmcneill
1748 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_WPA1)
1749 1.1 jmcneill wpa |= BWFM_WPA_AUTH_WPA_PSK;
1750 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_WPA2)
1751 1.1 jmcneill wpa |= BWFM_WPA_AUTH_WPA2_PSK;
1752 1.1 jmcneill
1753 1.1 jmcneill wsec |= bwfm_get_wsec(sc);
1754 1.1 jmcneill
1755 1.1 jmcneill DPRINTF(("%s: WPA enabled, ic_flags = 0x%x, wpa 0x%x, wsec 0x%x\n",
1756 1.1 jmcneill DEVNAME(sc), ic->ic_flags, wpa, wsec));
1757 1.1 jmcneill
1758 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wpa_auth", wpa);
1759 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wsec", wsec);
1760 1.1 jmcneill } else {
1761 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wpa_auth", BWFM_WPA_AUTH_DISABLED);
1762 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "wsec", BWFM_WSEC_NONE);
1763 1.1 jmcneill }
1764 1.1 jmcneill
1765 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "auth", BWFM_AUTH_OPEN);
1766 1.1 jmcneill bwfm_fwvar_var_set_int(sc, "mfp", BWFM_MFP_NONE);
1767 1.1 jmcneill
1768 1.1 jmcneill if (ni->ni_esslen && ni->ni_esslen < BWFM_MAX_SSID_LEN) {
1769 1.1 jmcneill params = kmem_zalloc(sizeof(*params), KM_SLEEP);
1770 1.1 jmcneill memcpy(params->ssid.ssid, ni->ni_essid, ni->ni_esslen);
1771 1.1 jmcneill params->ssid.len = htole32(ni->ni_esslen);
1772 1.1 jmcneill memcpy(params->assoc.bssid, ni->ni_bssid, sizeof(params->assoc.bssid));
1773 1.1 jmcneill params->scan.scan_type = -1;
1774 1.1 jmcneill params->scan.nprobes = htole32(-1);
1775 1.1 jmcneill params->scan.active_time = htole32(-1);
1776 1.1 jmcneill params->scan.passive_time = htole32(-1);
1777 1.1 jmcneill params->scan.home_time = htole32(-1);
1778 1.1 jmcneill if (bwfm_fwvar_var_set_data(sc, "join", params, sizeof(*params))) {
1779 1.1 jmcneill struct bwfm_join_params join;
1780 1.1 jmcneill memset(&join, 0, sizeof(join));
1781 1.1 jmcneill memcpy(join.ssid.ssid, ni->ni_essid, ni->ni_esslen);
1782 1.1 jmcneill join.ssid.len = htole32(ni->ni_esslen);
1783 1.1 jmcneill memcpy(join.assoc.bssid, ni->ni_bssid, sizeof(join.assoc.bssid));
1784 1.1 jmcneill bwfm_fwvar_cmd_set_data(sc, BWFM_C_SET_SSID, &join,
1785 1.1 jmcneill sizeof(join));
1786 1.1 jmcneill }
1787 1.1 jmcneill kmem_free(params, sizeof(*params));
1788 1.1 jmcneill }
1789 1.1 jmcneill }
1790 1.1 jmcneill
1791 1.1 jmcneill void
1792 1.11 maya bwfm_rx(struct bwfm_softc *sc, struct mbuf *m)
1793 1.1 jmcneill {
1794 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1795 1.1 jmcneill struct ifnet *ifp = ic->ic_ifp;
1796 1.11 maya struct bwfm_event *e = mtod(m, struct bwfm_event *);
1797 1.1 jmcneill int s;
1798 1.1 jmcneill
1799 1.11 maya if (m->m_len >= sizeof(e->ehdr) &&
1800 1.1 jmcneill ntohs(e->ehdr.ether_type) == BWFM_ETHERTYPE_LINK_CTL &&
1801 1.1 jmcneill memcmp(BWFM_BRCM_OUI, e->hdr.oui, sizeof(e->hdr.oui)) == 0 &&
1802 1.11 maya ntohs(e->hdr.usr_subtype) == BWFM_BRCM_SUBTYPE_EVENT) {
1803 1.15 mlelstv bwfm_rx_event(sc, m);
1804 1.15 mlelstv // m_freem(m);
1805 1.1 jmcneill return;
1806 1.1 jmcneill }
1807 1.1 jmcneill
1808 1.1 jmcneill s = splnet();
1809 1.1 jmcneill
1810 1.15 mlelstv //if ((ifp->if_flags & IFF_RUNNING) != 0) {
1811 1.1 jmcneill m_set_rcvif(m, ifp);
1812 1.1 jmcneill if_percpuq_enqueue(ifp->if_percpuq, m);
1813 1.15 mlelstv //}
1814 1.15 mlelstv
1815 1.15 mlelstv splx(s);
1816 1.15 mlelstv }
1817 1.15 mlelstv
1818 1.15 mlelstv void
1819 1.15 mlelstv bwfm_rx_event(struct bwfm_softc *sc, struct mbuf *m)
1820 1.15 mlelstv {
1821 1.15 mlelstv struct bwfm_task *t;
1822 1.15 mlelstv
1823 1.15 mlelstv t = pcq_get(sc->sc_freetask);
1824 1.15 mlelstv if (t == NULL) {
1825 1.15 mlelstv m_freem(m);
1826 1.15 mlelstv printf("%s: no free tasks\n", DEVNAME(sc));
1827 1.15 mlelstv return;
1828 1.1 jmcneill }
1829 1.1 jmcneill
1830 1.15 mlelstv t->t_cmd = BWFM_TASK_RX_EVENT;
1831 1.15 mlelstv t->t_mbuf = m;
1832 1.15 mlelstv workqueue_enqueue(sc->sc_taskq, (struct work*)t, NULL);
1833 1.1 jmcneill }
1834 1.1 jmcneill
1835 1.1 jmcneill void
1836 1.15 mlelstv bwfm_rx_event_cb(struct bwfm_softc *sc, struct mbuf *m)
1837 1.1 jmcneill {
1838 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1839 1.15 mlelstv struct bwfm_event *e = mtod(m, void *);
1840 1.15 mlelstv size_t len = m->m_len;
1841 1.1 jmcneill int s;
1842 1.1 jmcneill
1843 1.15 mlelstv DPRINTF(("%s: event %p len %lu datalen %u code %u status %u"
1844 1.15 mlelstv " reason %u\n", __func__, e, len, ntohl(e->msg.datalen),
1845 1.1 jmcneill ntohl(e->msg.event_type), ntohl(e->msg.status),
1846 1.1 jmcneill ntohl(e->msg.reason)));
1847 1.1 jmcneill
1848 1.15 mlelstv if (ntohl(e->msg.event_type) >= BWFM_E_LAST) {
1849 1.15 mlelstv m_freem(m);
1850 1.1 jmcneill return;
1851 1.15 mlelstv }
1852 1.1 jmcneill
1853 1.1 jmcneill switch (ntohl(e->msg.event_type)) {
1854 1.1 jmcneill case BWFM_E_ESCAN_RESULT: {
1855 1.15 mlelstv struct bwfm_escan_results *res = (void *)&e[1];
1856 1.1 jmcneill struct bwfm_bss_info *bss;
1857 1.1 jmcneill int i;
1858 1.1 jmcneill if (ntohl(e->msg.status) != BWFM_E_STATUS_PARTIAL) {
1859 1.1 jmcneill /* Scan complete */
1860 1.1 jmcneill s = splnet();
1861 1.1 jmcneill if (ic->ic_opmode != IEEE80211_M_MONITOR)
1862 1.1 jmcneill ieee80211_end_scan(ic);
1863 1.1 jmcneill splx(s);
1864 1.1 jmcneill break;
1865 1.1 jmcneill }
1866 1.1 jmcneill len -= sizeof(*e);
1867 1.1 jmcneill if (len < sizeof(*res) || len < le32toh(res->buflen)) {
1868 1.15 mlelstv m_freem(m);
1869 1.1 jmcneill printf("%s: results too small\n", DEVNAME(sc));
1870 1.1 jmcneill return;
1871 1.1 jmcneill }
1872 1.1 jmcneill len -= sizeof(*res);
1873 1.1 jmcneill if (len < le16toh(res->bss_count) * sizeof(struct bwfm_bss_info)) {
1874 1.15 mlelstv m_freem(m);
1875 1.1 jmcneill printf("%s: results too small\n", DEVNAME(sc));
1876 1.1 jmcneill return;
1877 1.1 jmcneill }
1878 1.1 jmcneill bss = &res->bss_info[0];
1879 1.1 jmcneill for (i = 0; i < le16toh(res->bss_count); i++) {
1880 1.2 jmcneill /* Fix alignment of bss_info */
1881 1.2 jmcneill union {
1882 1.2 jmcneill struct bwfm_bss_info bss_info;
1883 1.2 jmcneill uint8_t padding[BWFM_BSS_INFO_BUFLEN];
1884 1.2 jmcneill } bss_buf;
1885 1.2 jmcneill if (len > sizeof(bss_buf)) {
1886 1.2 jmcneill printf("%s: bss_info buffer too big\n", DEVNAME(sc));
1887 1.2 jmcneill } else {
1888 1.2 jmcneill memcpy(&bss_buf, &res->bss_info[i], len);
1889 1.2 jmcneill bwfm_scan_node(sc, &bss_buf.bss_info, len);
1890 1.2 jmcneill }
1891 1.1 jmcneill len -= sizeof(*bss) + le32toh(bss->length);
1892 1.1 jmcneill bss = (void *)(((uintptr_t)bss) + le32toh(bss->length));
1893 1.1 jmcneill if (len <= 0)
1894 1.1 jmcneill break;
1895 1.1 jmcneill }
1896 1.1 jmcneill break;
1897 1.1 jmcneill }
1898 1.1 jmcneill
1899 1.1 jmcneill case BWFM_E_SET_SSID:
1900 1.1 jmcneill if (ntohl(e->msg.status) == BWFM_E_STATUS_SUCCESS) {
1901 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_RUN, -1);
1902 1.1 jmcneill } else {
1903 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
1904 1.1 jmcneill }
1905 1.1 jmcneill break;
1906 1.1 jmcneill
1907 1.1 jmcneill case BWFM_E_ASSOC:
1908 1.1 jmcneill if (ntohl(e->msg.status) == BWFM_E_STATUS_SUCCESS) {
1909 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_ASSOC, -1);
1910 1.1 jmcneill } else {
1911 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
1912 1.1 jmcneill }
1913 1.1 jmcneill break;
1914 1.1 jmcneill
1915 1.1 jmcneill case BWFM_E_LINK:
1916 1.1 jmcneill if (ntohl(e->msg.status) == BWFM_E_STATUS_SUCCESS &&
1917 1.1 jmcneill ntohl(e->msg.reason) == 0)
1918 1.1 jmcneill break;
1919 1.11 maya
1920 1.1 jmcneill /* Link status has changed */
1921 1.1 jmcneill ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
1922 1.1 jmcneill break;
1923 1.1 jmcneill
1924 1.1 jmcneill default:
1925 1.1 jmcneill break;
1926 1.1 jmcneill }
1927 1.15 mlelstv
1928 1.15 mlelstv m_freem(m);
1929 1.1 jmcneill }
1930 1.1 jmcneill
1931 1.1 jmcneill void
1932 1.1 jmcneill bwfm_scan_node(struct bwfm_softc *sc, struct bwfm_bss_info *bss, size_t len)
1933 1.1 jmcneill {
1934 1.1 jmcneill struct ieee80211com *ic = &sc->sc_ic;
1935 1.1 jmcneill struct ieee80211_frame wh;
1936 1.1 jmcneill struct ieee80211_scanparams scan;
1937 1.1 jmcneill uint8_t rates[sizeof(bss->rates) + 2];
1938 1.1 jmcneill uint8_t ssid[sizeof(bss->ssid) + 2];
1939 1.1 jmcneill uint8_t *frm, *sfrm, *efrm;
1940 1.1 jmcneill uint64_t tsf;
1941 1.1 jmcneill
1942 1.1 jmcneill tsf = 0;
1943 1.1 jmcneill sfrm = ((uint8_t *)bss) + le16toh(bss->ie_offset);
1944 1.1 jmcneill efrm = sfrm + le32toh(bss->ie_length);
1945 1.1 jmcneill
1946 1.1 jmcneill /* Fake a wireless header with the scan result's BSSID */
1947 1.1 jmcneill memset(&wh, 0, sizeof(wh));
1948 1.1 jmcneill IEEE80211_ADDR_COPY(wh.i_addr2, bss->bssid);
1949 1.1 jmcneill IEEE80211_ADDR_COPY(wh.i_addr3, bss->bssid);
1950 1.1 jmcneill
1951 1.1 jmcneill if (efrm - sfrm < 12) {
1952 1.1 jmcneill ic->ic_stats.is_rx_elem_toosmall++;
1953 1.1 jmcneill return;
1954 1.1 jmcneill }
1955 1.1 jmcneill
1956 1.1 jmcneill rates[0] = 0;
1957 1.1 jmcneill rates[1] = le32toh(bss->nrates);
1958 1.1 jmcneill memcpy(&rates[2], bss->rates, sizeof(bss->rates));
1959 1.1 jmcneill
1960 1.1 jmcneill ssid[0] = 0;
1961 1.1 jmcneill ssid[1] = bss->ssid_len;
1962 1.1 jmcneill memcpy(&ssid[2], bss->ssid, sizeof(bss->ssid));
1963 1.1 jmcneill
1964 1.1 jmcneill /* Build scan result */
1965 1.1 jmcneill memset(&scan, 0, sizeof(scan));
1966 1.10 maxv scan.sp_tstamp = (uint8_t *)&tsf;
1967 1.10 maxv scan.sp_bintval = le16toh(bss->beacon_period);
1968 1.10 maxv scan.sp_capinfo = le16toh(bss->capability);
1969 1.10 maxv scan.sp_bchan = ieee80211_chan2ieee(ic, ic->ic_curchan);
1970 1.10 maxv scan.sp_chan = scan.sp_bchan;
1971 1.10 maxv scan.sp_rates = rates;
1972 1.10 maxv scan.sp_ssid = ssid;
1973 1.1 jmcneill
1974 1.1 jmcneill for (frm = sfrm; frm < efrm; frm += frm[1] + 2) {
1975 1.1 jmcneill switch (frm[0]) {
1976 1.1 jmcneill case IEEE80211_ELEMID_COUNTRY:
1977 1.10 maxv scan.sp_country = frm;
1978 1.1 jmcneill break;
1979 1.1 jmcneill case IEEE80211_ELEMID_FHPARMS:
1980 1.1 jmcneill if (ic->ic_phytype == IEEE80211_T_FH) {
1981 1.8 maxv if (frm + 6 >= efrm)
1982 1.8 maxv break;
1983 1.10 maxv scan.sp_fhdwell = le16dec(&frm[2]);
1984 1.10 maxv scan.sp_chan = IEEE80211_FH_CHAN(frm[4], frm[5]);
1985 1.10 maxv scan.sp_fhindex = frm[6];
1986 1.1 jmcneill }
1987 1.1 jmcneill break;
1988 1.1 jmcneill case IEEE80211_ELEMID_DSPARMS:
1989 1.8 maxv if (ic->ic_phytype != IEEE80211_T_FH) {
1990 1.8 maxv if (frm + 2 >= efrm)
1991 1.8 maxv break;
1992 1.10 maxv scan.sp_chan = frm[2];
1993 1.8 maxv }
1994 1.1 jmcneill break;
1995 1.1 jmcneill case IEEE80211_ELEMID_TIM:
1996 1.10 maxv scan.sp_tim = frm;
1997 1.10 maxv scan.sp_timoff = frm - sfrm;
1998 1.1 jmcneill break;
1999 1.1 jmcneill case IEEE80211_ELEMID_XRATES:
2000 1.10 maxv scan.sp_xrates = frm;
2001 1.1 jmcneill break;
2002 1.1 jmcneill case IEEE80211_ELEMID_ERP:
2003 1.8 maxv if (frm + 1 >= efrm)
2004 1.8 maxv break;
2005 1.1 jmcneill if (frm[1] != 1) {
2006 1.1 jmcneill ic->ic_stats.is_rx_elem_toobig++;
2007 1.1 jmcneill break;
2008 1.1 jmcneill }
2009 1.10 maxv scan.sp_erp = frm[2];
2010 1.1 jmcneill break;
2011 1.1 jmcneill case IEEE80211_ELEMID_RSN:
2012 1.10 maxv scan.sp_wpa = frm;
2013 1.1 jmcneill break;
2014 1.1 jmcneill case IEEE80211_ELEMID_VENDOR:
2015 1.8 maxv if (frm + 1 >= efrm)
2016 1.8 maxv break;
2017 1.8 maxv if (frm + frm[1] + 2 >= efrm)
2018 1.8 maxv break;
2019 1.1 jmcneill if (bwfm_iswpaoui(frm))
2020 1.10 maxv scan.sp_wpa = frm;
2021 1.1 jmcneill break;
2022 1.1 jmcneill }
2023 1.9 maxv if (frm + 1 >= efrm)
2024 1.9 maxv break;
2025 1.1 jmcneill }
2026 1.1 jmcneill
2027 1.1 jmcneill if (ic->ic_flags & IEEE80211_F_SCAN)
2028 1.1 jmcneill ieee80211_add_scan(ic, &scan, &wh, IEEE80211_FC0_SUBTYPE_BEACON,
2029 1.1 jmcneill le32toh(bss->rssi), 0);
2030 1.1 jmcneill }
2031