if_malo_pcmcia.c revision 1.16.2.1 1 /* $NetBSD: if_malo_pcmcia.c,v 1.16.2.1 2018/07/28 04:37:57 pgoyette Exp $ */
2 /* $OpenBSD: if_malo.c,v 1.65 2009/03/29 21:53:53 sthen Exp $ */
3
4 /*
5 * Copyright (c) 2007 Marcus Glocker <mglocker (at) openbsd.org>
6 *
7 * Permission to use, copy, modify, and distribute this software for any
8 * purpose with or without fee is hereby granted, provided that the above
9 * copyright notice and this permission notice appear in all copies.
10 *
11 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
12 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
13 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
14 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
15 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18 */
19
20 #include <sys/cdefs.h>
21 __KERNEL_RCSID(0, "$NetBSD: if_malo_pcmcia.c,v 1.16.2.1 2018/07/28 04:37:57 pgoyette Exp $");
22
23 #ifdef _MODULE
24 #include <sys/module.h>
25 #endif
26
27 #include <sys/param.h>
28 #include <sys/bus.h>
29 #include <sys/condvar.h>
30 #include <sys/device.h>
31 #include <sys/intr.h>
32 #include <sys/kernel.h>
33 #include <sys/malloc.h>
34 #include <sys/mbuf.h>
35 #include <sys/mutex.h>
36 #include <sys/pmf.h>
37 #include <sys/proc.h>
38 #include <sys/socket.h>
39 #include <sys/sockio.h>
40 #include <sys/systm.h>
41
42 #include <net/bpf.h>
43 #include <net/if.h>
44 #include <net/if_dl.h>
45 #include <net/if_ether.h>
46 #include <net/if_media.h>
47 #include <net/if_llc.h>
48
49 #include <net80211/ieee80211_var.h>
50 #include <net80211/ieee80211_radiotap.h>
51
52 #include <dev/firmload.h>
53
54 #include <dev/pcmcia/pcmciareg.h>
55 #include <dev/pcmcia/pcmciavar.h>
56 #include <dev/pcmcia/pcmciadevs.h>
57
58 #include <dev/pcmcia/if_malo_pcmciavar.h>
59 #include <dev/pcmcia/if_malo_pcmciareg.h>
60
61 /*
62 * Driver for the Marvell 88W8385 chip (Compact Flash).
63 */
64
65 #ifdef CMALO_DEBUG
66 int cmalo_d = 1;
67 #define DPRINTF(l, x...) do { if ((l) <= cmalo_d) printf(x); } while (0)
68 #else
69 #define DPRINTF(l, x...) do {} while (0)
70 #endif
71
72 static int malo_pcmcia_match(device_t, cfdata_t, void *);
73 static void malo_pcmcia_attach(device_t, device_t, void *);
74 static int malo_pcmcia_detach(device_t, int);
75 static int malo_pcmcia_activate(device_t, devact_t);
76
77 static int malo_pcmcia_validate_config(struct pcmcia_config_entry *);
78
79 static int malo_pcmcia_enable(struct malo_softc *);
80 static void malo_pcmcia_disable(struct malo_softc *);
81
82 static void cmalo_attach(void *);
83 static void cmalo_detach(void *);
84 static int cmalo_intr(void *);
85 static void cmalo_softintr(void *);
86
87 static void cmalo_start(struct ifnet *);
88 static int cmalo_ioctl(struct ifnet *, u_long, void *);
89 static int cmalo_init(struct ifnet *);
90 static void cmalo_watchdog(struct ifnet *);
91 static int cmalo_media_change(struct ifnet *);
92 static int cmalo_newstate(struct ieee80211com *, enum ieee80211_state,
93 int);
94
95 static int firmware_load(const char *, const char *, uint8_t **, size_t *);
96 static int cmalo_fw_alloc(struct malo_softc *);
97 static void cmalo_fw_free(struct malo_softc *);
98 static int cmalo_fw_load_helper(struct malo_softc *);
99 static int cmalo_fw_load_main(struct malo_softc *);
100
101 static void cmalo_stop(struct malo_softc *);
102 static void cmalo_intr_mask(struct malo_softc *, int);
103 static void cmalo_rx(struct malo_softc *);
104 static int cmalo_tx(struct malo_softc *, struct mbuf *);
105 static void cmalo_tx_done(struct malo_softc *);
106 static void cmalo_event(struct malo_softc *);
107 static void cmalo_select_network(struct malo_softc *);
108 static void cmalo_reflect_network(struct malo_softc *);
109 static int cmalo_wep(struct malo_softc *);
110 static int cmalo_rate2bitmap(int);
111
112 static void cmalo_hexdump(void *, int);
113 static int cmalo_cmd_get_hwspec(struct malo_softc *);
114 static int cmalo_cmd_rsp_hwspec(struct malo_softc *);
115 static int cmalo_cmd_set_reset(struct malo_softc *);
116 static int cmalo_cmd_set_scan(struct malo_softc *);
117 static int cmalo_cmd_rsp_scan(struct malo_softc *);
118 static int cmalo_parse_elements(struct malo_softc *, uint8_t *, int, int);
119 static int cmalo_cmd_set_auth(struct malo_softc *);
120 static int cmalo_cmd_set_wep(struct malo_softc *, uint16_t,
121 struct ieee80211_key *);
122 static int cmalo_cmd_set_snmp(struct malo_softc *, uint16_t);
123 static int cmalo_cmd_set_radio(struct malo_softc *, uint16_t);
124 static int cmalo_cmd_set_channel(struct malo_softc *, uint16_t);
125 static int cmalo_cmd_set_txpower(struct malo_softc *, int16_t);
126 static int cmalo_cmd_set_antenna(struct malo_softc *, uint16_t);
127 static int cmalo_cmd_set_macctrl(struct malo_softc *);
128 static int cmalo_cmd_set_macaddr(struct malo_softc *, uint8_t *);
129 static int cmalo_cmd_set_assoc(struct malo_softc *);
130 static int cmalo_cmd_rsp_assoc(struct malo_softc *);
131 static int cmalo_cmd_set_rate(struct malo_softc *, int);
132 static int cmalo_cmd_request(struct malo_softc *, uint16_t, int);
133 static int cmalo_cmd_response(struct malo_softc *);
134
135 /*
136 * PCMCIA bus.
137 */
138 struct malo_pcmcia_softc {
139 struct malo_softc sc_malo;
140
141 struct pcmcia_function *sc_pf;
142 struct pcmcia_io_handle sc_pcioh;
143 int sc_io_window;
144 void *sc_ih;
145 };
146
147 CFATTACH_DECL_NEW(malo_pcmcia, sizeof(struct malo_pcmcia_softc),
148 malo_pcmcia_match, malo_pcmcia_attach, malo_pcmcia_detach,
149 malo_pcmcia_activate);
150
151
152 static int
153 malo_pcmcia_match(device_t parent, cfdata_t match, void *aux)
154 {
155 struct pcmcia_attach_args *pa = aux;
156
157 if (pa->manufacturer == PCMCIA_VENDOR_AMBICOM &&
158 pa->product == PCMCIA_PRODUCT_AMBICOM_WL54CF)
159 return 1;
160
161 return 0;
162 }
163
164 static void
165 malo_pcmcia_attach(device_t parent, device_t self, void *aux)
166 {
167 struct malo_pcmcia_softc *psc = device_private(self);
168 struct malo_softc *sc = &psc->sc_malo;
169 struct pcmcia_attach_args *pa = aux;
170 struct pcmcia_config_entry *cfe;
171 int error;
172
173 sc->sc_dev = self;
174 psc->sc_pf = pa->pf;
175
176 error = pcmcia_function_configure(pa->pf, malo_pcmcia_validate_config);
177 if (error) {
178 aprint_error_dev(self, "configure failed, error=%d\n", error);
179 return;
180 }
181
182 sc->sc_soft_ih = softint_establish(SOFTINT_NET, cmalo_softintr, sc);
183 if (sc->sc_soft_ih == NULL) {
184 aprint_error_dev(self, "couldn't establish softint\n");
185 return;
186 }
187
188 malo_pcmcia_enable(sc);
189
190 cfe = pa->pf->cfe;
191 sc->sc_iot = cfe->iospace[0].handle.iot;
192 sc->sc_ioh = cfe->iospace[0].handle.ioh;
193
194 cmalo_attach(sc);
195 if (!(sc->sc_flags & MALO_DEVICE_ATTACHED))
196 goto fail;
197
198 if (pmf_device_register(self, NULL, NULL))
199 pmf_class_network_register(self, &sc->sc_if);
200 else
201 aprint_error_dev(self, "couldn't establish power handler\n");
202
203 fail:
204 malo_pcmcia_disable(sc);
205
206 if (sc->sc_flags & MALO_DEVICE_ATTACHED)
207 return;
208
209 softint_disestablish(sc->sc_soft_ih);
210 sc->sc_soft_ih = NULL;
211
212 pcmcia_function_unconfigure(pa->pf);
213 return;
214 }
215
216 static int
217 malo_pcmcia_detach(device_t dev, int flags)
218 {
219 struct malo_pcmcia_softc *psc = device_private(dev);
220 struct malo_softc *sc = &psc->sc_malo;
221
222 cmalo_detach(sc);
223 malo_pcmcia_disable(sc);
224 softint_disestablish(sc->sc_soft_ih);
225 sc->sc_soft_ih = NULL;
226 pcmcia_function_unconfigure(psc->sc_pf);
227
228 return 0;
229 }
230
231 static int
232 malo_pcmcia_activate(device_t dev, devact_t act)
233 {
234 struct malo_pcmcia_softc *psc = device_private(dev);
235 struct malo_softc *sc = &psc->sc_malo;
236 struct ifnet *ifp = &sc->sc_if;
237 int s;
238
239 s = splnet();
240 switch (act) {
241 case DVACT_DEACTIVATE:
242 if_deactivate(ifp);
243 break;
244 default:
245 splx(s);
246 return EOPNOTSUPP;
247 }
248 splx(s);
249
250 return 0;
251 }
252
253
254 int
255 malo_pcmcia_validate_config(struct pcmcia_config_entry *cfe)
256 {
257
258 if (cfe->iftype != PCMCIA_IFTYPE_IO || cfe->num_iospace != 1)
259 return EINVAL;
260 /* Some cards have a memory space, but we don't use it. */
261 cfe->num_memspace = 0;
262 return 0;
263 }
264
265
266 static int
267 malo_pcmcia_enable(struct malo_softc *sc)
268 {
269 struct malo_pcmcia_softc *psc = (struct malo_pcmcia_softc *)sc;
270
271 /* establish interrupt */
272 psc->sc_ih = pcmcia_intr_establish(psc->sc_pf, IPL_NET, cmalo_intr, sc);
273 if (psc->sc_ih == NULL) {
274 aprint_error(": can't establish interrupt\n");
275 return -1;
276 }
277
278 if (pcmcia_function_enable(psc->sc_pf)) {
279 aprint_error(": can't enable function\n");
280 pcmcia_intr_disestablish(psc->sc_pf, psc->sc_ih);
281 return -1;
282 }
283 sc->sc_flags |= MALO_DEVICE_ENABLED;
284
285 return 0;
286 }
287
288 static void
289 malo_pcmcia_disable(struct malo_softc *sc)
290 {
291 struct malo_pcmcia_softc *psc = (struct malo_pcmcia_softc *)sc;
292
293 pcmcia_function_disable(psc->sc_pf);
294 if (psc->sc_ih)
295 pcmcia_intr_disestablish(psc->sc_pf, psc->sc_ih);
296 psc->sc_ih = NULL;
297 sc->sc_flags &= ~MALO_DEVICE_ENABLED;
298 }
299
300
301 /*
302 * Driver.
303 */
304 static void
305 cmalo_attach(void *arg)
306 {
307 struct malo_softc *sc = arg;
308 struct ieee80211com *ic = &sc->sc_ic;
309 struct ifnet *ifp = &sc->sc_if;
310 int i, rv;
311
312 /* disable interrupts */
313 cmalo_intr_mask(sc, 0);
314
315 /* load firmware */
316 if (cmalo_fw_alloc(sc) != 0 ||
317 cmalo_fw_load_helper(sc) != 0 ||
318 cmalo_fw_load_main(sc) != 0) {
319 /* free firmware */
320 cmalo_fw_free(sc);
321 goto fail_1;
322 }
323 sc->sc_flags |= MALO_FW_LOADED;
324
325 /* allocate command buffer */
326 sc->sc_cmd = malloc(MALO_CMD_BUFFER_SIZE, M_DEVBUF, M_NOWAIT);
327
328 /* allocate data buffer */
329 sc->sc_data = malloc(MALO_DATA_BUFFER_SIZE, M_DEVBUF, M_NOWAIT);
330
331 /* enable interrupts */
332 cmalo_intr_mask(sc, 1);
333
334 /* we are context save here for FW commands */
335 sc->sc_cmd_ctxsave = 1;
336
337 mutex_init(&sc->sc_mtx, MUTEX_DEFAULT, IPL_VM);
338 cv_init(&sc->sc_cv, "malo");
339
340 /* get hardware specs */
341 cmalo_cmd_get_hwspec(sc);
342
343 /* setup interface */
344 ifp->if_softc = sc;
345 ifp->if_start = cmalo_start;
346 ifp->if_ioctl = cmalo_ioctl;
347 ifp->if_init = cmalo_init;
348 ifp->if_watchdog = cmalo_watchdog;
349 ifp->if_flags = IFF_SIMPLEX | IFF_BROADCAST | IFF_MULTICAST;
350 strlcpy(ifp->if_xname, device_xname(sc->sc_dev), IFNAMSIZ);
351 IFQ_SET_READY(&ifp->if_snd);
352
353 ic->ic_ifp = ifp;
354 ic->ic_phytype = IEEE80211_T_OFDM;
355 ic->ic_opmode = IEEE80211_M_STA;
356 ic->ic_state = IEEE80211_S_INIT;
357 ic->ic_caps = IEEE80211_C_MONITOR | IEEE80211_C_WEP;
358
359 ic->ic_sup_rates[IEEE80211_MODE_11B] = ieee80211_std_rateset_11b;
360 ic->ic_sup_rates[IEEE80211_MODE_11G] = ieee80211_std_rateset_11g;
361
362 for (i = 0; i <= 14; i++) {
363 ic->ic_channels[i].ic_freq =
364 ieee80211_ieee2mhz(i, IEEE80211_CHAN_2GHZ);
365 ic->ic_channels[i].ic_flags =
366 IEEE80211_CHAN_CCK | IEEE80211_CHAN_OFDM |
367 IEEE80211_CHAN_DYN | IEEE80211_CHAN_2GHZ;
368 }
369
370 /* attach interface */
371 rv = if_initialize(ifp);
372 if (rv != 0) {
373 aprint_error_dev(sc->sc_dev, "if_initialize failed(%d)\n", rv);
374 goto fail_2;
375 }
376 ieee80211_ifattach(ic);
377 /* Use common softint-based if_input */
378 ifp->if_percpuq = if_percpuq_create(ifp);
379 if_register(ifp);
380
381 sc->sc_newstate = ic->ic_newstate;
382 ic->ic_newstate = cmalo_newstate;
383 ieee80211_media_init(ic, cmalo_media_change, ieee80211_media_status);
384
385 /* second attach line */
386 aprint_normal_dev(sc->sc_dev, "address %s\n",
387 ether_sprintf(ic->ic_myaddr));
388
389 ieee80211_announce(ic);
390
391 /* device attached */
392 sc->sc_flags |= MALO_DEVICE_ATTACHED;
393
394 return;
395
396 fail_2:
397 cv_destroy(&sc->sc_cv);
398 mutex_destroy(&sc->sc_mtx);
399 free(sc->sc_cmd, M_DEVBUF);
400 free(sc->sc_data, M_DEVBUF);
401 fail_1:
402 cmalo_fw_free(sc);
403 }
404
405 static void
406 cmalo_detach(void *arg)
407 {
408 struct malo_softc *sc = arg;
409 struct ieee80211com *ic = &sc->sc_ic;
410 struct ifnet *ifp = &sc->sc_if;
411
412 if (!(sc->sc_flags & MALO_DEVICE_ATTACHED)) {
413 /* free firmware */
414 cmalo_fw_free(sc);
415
416 /* device was not properly attached */
417 return;
418 }
419
420 if (ifp->if_flags & IFF_RUNNING)
421 cmalo_stop(sc);
422
423 /* free command buffer */
424 if (sc->sc_cmd != NULL)
425 free(sc->sc_cmd, M_DEVBUF);
426
427 /* free data buffer */
428 if (sc->sc_data != NULL)
429 free(sc->sc_data, M_DEVBUF);
430
431 /* free firmware */
432 cmalo_fw_free(sc);
433
434 /* detach inferface */
435 ieee80211_ifdetach(ic);
436 if_detach(ifp);
437
438 mutex_destroy(&sc->sc_mtx);
439 cv_destroy(&sc->sc_cv);
440 }
441
442 static int
443 cmalo_intr(void *arg)
444 {
445 struct malo_softc *sc = arg;
446 uint16_t intr;
447
448 /* read interrupt reason */
449 intr = MALO_READ_2(sc, MALO_REG_HOST_INTR_CAUSE);
450 if (intr == 0)
451 /* interrupt not for us */
452 return 0;
453 if (intr == 0xffff)
454 /* card has been detached */
455 return 0;
456
457 /* disable interrupts */
458 cmalo_intr_mask(sc, 0);
459
460 DPRINTF(2, "%s: interrupt handler called (intr = 0x%04x)\n",
461 device_xname(sc->sc_dev), intr);
462
463 softint_schedule(sc->sc_soft_ih);
464 return 1;
465 }
466
467 static void
468 cmalo_softintr(void *arg)
469 {
470 struct malo_softc *sc = arg;
471 uint16_t intr;
472
473 /* read interrupt reason */
474 intr = MALO_READ_2(sc, MALO_REG_HOST_INTR_CAUSE);
475 if (intr == 0 || intr == 0xffff)
476 goto out;
477
478 /* acknowledge interrupt */
479 MALO_WRITE_2(sc, MALO_REG_HOST_INTR_CAUSE,
480 intr & MALO_VAL_HOST_INTR_MASK_ON);
481
482 if (intr & MALO_VAL_HOST_INTR_TX)
483 /* TX frame sent */
484 cmalo_tx_done(sc);
485 if (intr & MALO_VAL_HOST_INTR_RX)
486 /* RX frame received */
487 cmalo_rx(sc);
488 if (intr & MALO_VAL_HOST_INTR_CMD) {
489 /* command response */
490 mutex_enter(&sc->sc_mtx);
491 cv_signal(&sc->sc_cv);
492 mutex_exit(&sc->sc_mtx);
493 if (!sc->sc_cmd_ctxsave)
494 cmalo_cmd_response(sc);
495 }
496 if (intr & MALO_VAL_HOST_INTR_EVENT)
497 /* event */
498 cmalo_event(sc);
499
500 out:
501 /* enable interrupts */
502 cmalo_intr_mask(sc, 1);
503 }
504
505
506 /*
507 * Network functions
508 */
509 static void
510 cmalo_start(struct ifnet *ifp)
511 {
512 struct malo_softc *sc = ifp->if_softc;
513 struct mbuf *m;
514
515 /* don't transmit packets if interface is busy or down */
516 if ((ifp->if_flags & (IFF_RUNNING | IFF_OACTIVE)) != IFF_RUNNING)
517 return;
518
519 IFQ_POLL(&ifp->if_snd, m);
520 if (m == NULL)
521 return;
522
523 IFQ_DEQUEUE(&ifp->if_snd, m);
524
525 bpf_mtap(ifp, m, BPF_D_OUT);
526
527 if (cmalo_tx(sc, m) != 0)
528 ifp->if_oerrors++;
529 }
530
531 static int
532 cmalo_ioctl(struct ifnet *ifp, u_long cmd, void *data)
533 {
534 struct malo_softc *sc = ifp->if_softc;
535 struct ieee80211com *ic = &sc->sc_ic;
536 int s, error = 0;
537
538 s = splnet();
539
540 switch (cmd) {
541 case SIOCSIFFLAGS:
542 if ((error = ifioctl_common(ifp, cmd, data)) != 0)
543 break;
544 switch (ifp->if_flags & (IFF_UP | IFF_RUNNING)) {
545 case IFF_RUNNING:
546 cmalo_stop(sc);
547 break;
548
549 case IFF_UP:
550 cmalo_init(ifp);
551 break;
552
553 default:
554 break;
555 }
556 error = 0;
557 break;
558
559 case SIOCADDMULTI:
560 case SIOCDELMULTI:
561 if ((error = ether_ioctl(ifp, cmd, data)) == ENETRESET)
562 /* setup multicast filter, etc */
563 error = 0;
564 break;
565
566 default:
567 error = ieee80211_ioctl(ic, cmd, data);
568 break;
569 }
570
571 if (error == ENETRESET) {
572 if ((ifp->if_flags & (IFF_UP | IFF_RUNNING)) ==
573 (IFF_UP | IFF_RUNNING))
574 cmalo_init(ifp);
575 error = 0;
576 }
577
578 splx(s);
579
580 return error;
581 }
582
583 static int
584 cmalo_init(struct ifnet *ifp)
585 {
586 struct malo_softc *sc = ifp->if_softc;
587 struct ieee80211com *ic = &sc->sc_ic;
588
589 if (!(sc->sc_flags & MALO_DEVICE_ENABLED))
590 malo_pcmcia_enable(sc);
591
592 /* reload the firmware if necessary */
593 if (!(sc->sc_flags & MALO_FW_LOADED)) {
594 /* disable interrupts */
595 cmalo_intr_mask(sc, 0);
596
597 /* load firmware */
598 if (cmalo_fw_load_helper(sc) != 0)
599 return EIO;
600 if (cmalo_fw_load_main(sc) != 0)
601 return EIO;
602 sc->sc_flags |= MALO_FW_LOADED;
603
604 /* enable interrupts */
605 cmalo_intr_mask(sc, 1);
606 }
607
608 if (ifp->if_flags & IFF_RUNNING)
609 cmalo_stop(sc);
610
611 /* reset association state flag */
612 sc->sc_flags &= ~MALO_ASSOC_FAILED;
613
614 /* get current channel */
615 ic->ic_curchan = ic->ic_ibss_chan;
616 sc->sc_curchan = ieee80211_chan2ieee(ic, ic->ic_curchan);
617 DPRINTF(1, "%s: current channel is %d\n",
618 device_xname(sc->sc_dev), sc->sc_curchan);
619
620 /* setup device */
621 if (cmalo_cmd_set_macctrl(sc) != 0)
622 return EIO;
623 if (cmalo_cmd_set_txpower(sc, 15) != 0)
624 return EIO;
625 if (cmalo_cmd_set_antenna(sc, 1) != 0)
626 return EIO;
627 if (cmalo_cmd_set_antenna(sc, 2) != 0)
628 return EIO;
629 if (cmalo_cmd_set_radio(sc, 1) != 0)
630 return EIO;
631 if (cmalo_cmd_set_channel(sc, sc->sc_curchan) != 0)
632 return EIO;
633 if (cmalo_cmd_set_rate(sc, ic->ic_fixed_rate) != 0)
634 return EIO;
635 if (cmalo_cmd_set_snmp(sc, MALO_OID_RTSTRESH) != 0)
636 return EIO;
637 if (cmalo_cmd_set_snmp(sc, MALO_OID_SHORTRETRY) != 0)
638 return EIO;
639 if (cmalo_cmd_set_snmp(sc, MALO_OID_FRAGTRESH) != 0)
640 return EIO;
641 IEEE80211_ADDR_COPY(ic->ic_myaddr, CLLADDR(ifp->if_sadl));
642 if (cmalo_cmd_set_macaddr(sc, ic->ic_myaddr) != 0)
643 return EIO;
644 if (ic->ic_flags & IEEE80211_F_PRIVACY)
645 if (cmalo_wep(sc) != 0)
646 return EIO;
647
648 /* device up */
649 ifp->if_flags |= IFF_RUNNING;
650 ifp->if_flags &= ~IFF_OACTIVE;
651
652 /* start network */
653 if (ic->ic_opmode != IEEE80211_M_MONITOR)
654 ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
655 if (sc->sc_flags & MALO_ASSOC_FAILED)
656 ieee80211_new_state(ic, IEEE80211_S_INIT, -1);
657 else
658 ieee80211_new_state(ic, IEEE80211_S_RUN, -1);
659
660 /* we are not context save anymore for FW commands */
661 sc->sc_cmd_ctxsave = 0;
662
663 return 0;
664 }
665
666 static void
667 cmalo_watchdog(struct ifnet *ifp)
668 {
669 DPRINTF(2, "watchdog timeout\n");
670
671 /* accept TX packets again */
672 ifp->if_flags &= ~IFF_OACTIVE;
673 }
674
675 static int
676 cmalo_media_change(struct ifnet *ifp)
677 {
678 int error;
679
680 if ((error = ieee80211_media_change(ifp)) != ENETRESET)
681 return error;
682
683 if ((ifp->if_flags & (IFF_UP | IFF_RUNNING)) == (IFF_UP | IFF_RUNNING))
684 cmalo_init(ifp);
685
686 return 0;
687 }
688
689 static int
690 cmalo_newstate(struct ieee80211com *ic, enum ieee80211_state nstate, int arg)
691 {
692 struct malo_softc *sc = ic->ic_ifp->if_softc;
693 enum ieee80211_state ostate;
694
695 ostate = ic->ic_state;
696
697 if (ostate == nstate)
698 goto out;
699
700 switch (nstate) {
701 case IEEE80211_S_INIT:
702 DPRINTF(1, "%s: newstate is IEEE80211_S_INIT\n",
703 device_xname(sc->sc_dev));
704 break;
705 case IEEE80211_S_SCAN:
706 DPRINTF(1, "%s: newstate is IEEE80211_S_SCAN\n",
707 device_xname(sc->sc_dev));
708 cmalo_cmd_set_scan(sc);
709 if (!sc->sc_net_num) {
710 /* no networks found */
711 DPRINTF(1, "%s: no networks found\n",
712 device_xname(sc->sc_dev));
713 break;
714 }
715 cmalo_select_network(sc);
716 cmalo_cmd_set_auth(sc);
717 cmalo_cmd_set_assoc(sc);
718 break;
719 case IEEE80211_S_AUTH:
720 DPRINTF(1, "%s: newstate is IEEE80211_S_AUTH\n",
721 device_xname(sc->sc_dev));
722 break;
723 case IEEE80211_S_ASSOC:
724 DPRINTF(1, "%s: newstate is IEEE80211_S_ASSOC\n",
725 device_xname(sc->sc_dev));
726 break;
727 case IEEE80211_S_RUN:
728 DPRINTF(1, "%s: newstate is IEEE80211_S_RUN\n",
729 device_xname(sc->sc_dev));
730 cmalo_reflect_network(sc);
731 break;
732 default:
733 break;
734 }
735
736 out:
737 return sc->sc_newstate(ic, nstate, arg);
738 }
739
740
741 static int
742 firmware_load(const char *dname, const char *iname, uint8_t **ucodep,
743 size_t *sizep)
744 {
745 firmware_handle_t fh;
746 int error;
747
748 if ((error = firmware_open(dname, iname, &fh)) != 0)
749 return error;
750 *sizep = firmware_get_size(fh);
751 if ((*ucodep = firmware_malloc(*sizep)) == NULL) {
752 firmware_close(fh);
753 return ENOMEM;
754 }
755 if ((error = firmware_read(fh, 0, *ucodep, *sizep)) != 0)
756 firmware_free(*ucodep, *sizep);
757 firmware_close(fh);
758
759 return error;
760 }
761
762 static int
763 cmalo_fw_alloc(struct malo_softc *sc)
764 {
765 const char *name_h = "malo8385-h";
766 const char *name_m = "malo8385-m";
767 int error;
768
769 if (sc->sc_fw_h == NULL) {
770 /* read helper firmware image */
771 error = firmware_load("malo", name_h, &sc->sc_fw_h,
772 &sc->sc_fw_h_size);
773 if (error != 0) {
774 aprint_error_dev(sc->sc_dev,
775 "error %d, could not read firmware %s\n",
776 error, name_h);
777 return EIO;
778 }
779 }
780
781 if (sc->sc_fw_m == NULL) {
782 /* read main firmware image */
783 error = firmware_load("malo", name_m, &sc->sc_fw_m,
784 &sc->sc_fw_m_size);
785 if (error != 0) {
786 aprint_error_dev(sc->sc_dev,
787 "error %d, could not read firmware %s\n",
788 error, name_m);
789 return EIO;
790 }
791 }
792
793 return 0;
794 }
795
796 static void
797 cmalo_fw_free(struct malo_softc *sc)
798 {
799
800 if (sc->sc_fw_h != NULL) {
801 firmware_free(sc->sc_fw_h, sc->sc_fw_h_size);
802 sc->sc_fw_h = NULL;
803 }
804
805 if (sc->sc_fw_m != NULL) {
806 firmware_free(sc->sc_fw_m, sc->sc_fw_m_size);
807 sc->sc_fw_m = NULL;
808 }
809 }
810
811 static int
812 cmalo_fw_load_helper(struct malo_softc *sc)
813 {
814 uint8_t val8;
815 uint16_t bsize, *uc;
816 int offset, i;
817
818 /* verify if the card is ready for firmware download */
819 val8 = MALO_READ_1(sc, MALO_REG_SCRATCH);
820 if (val8 == MALO_VAL_SCRATCH_FW_LOADED)
821 /* firmware already loaded */
822 return 0;
823 if (val8 != MALO_VAL_SCRATCH_READY) {
824 /* bad register value */
825 aprint_error_dev(sc->sc_dev,
826 "device not ready for FW download\n");
827 return EIO;
828 }
829
830 /* download the helper firmware */
831 for (offset = 0; offset < sc->sc_fw_h_size; offset += bsize) {
832 if (sc->sc_fw_h_size - offset >= MALO_FW_HELPER_BSIZE)
833 bsize = MALO_FW_HELPER_BSIZE;
834 else
835 bsize = sc->sc_fw_h_size - offset;
836
837 /* send a block in words and confirm it */
838 DPRINTF(3, "%s: download helper FW block (%d bytes, %d off)\n",
839 device_xname(sc->sc_dev), bsize, offset);
840 MALO_WRITE_2(sc, MALO_REG_CMD_WRITE_LEN, bsize);
841 uc = (uint16_t *)(sc->sc_fw_h + offset);
842 for (i = 0; i < bsize / 2; i++)
843 MALO_WRITE_2(sc, MALO_REG_CMD_WRITE, htole16(uc[i]));
844 MALO_WRITE_1(sc, MALO_REG_HOST_STATUS, MALO_VAL_CMD_DL_OVER);
845 MALO_WRITE_2(sc, MALO_REG_CARD_INTR_CAUSE,
846 MALO_VAL_CMD_DL_OVER);
847
848 /* poll for an acknowledgement */
849 for (i = 0; i < 50; i++) {
850 if (MALO_READ_1(sc, MALO_REG_CARD_STATUS) ==
851 MALO_VAL_CMD_DL_OVER)
852 break;
853 delay(1000);
854 }
855 if (i == 50) {
856 aprint_error_dev(sc->sc_dev,
857 "timeout while helper FW block download\n");
858 return EIO;
859 }
860 }
861
862 /* helper firmware download done */
863 MALO_WRITE_2(sc, MALO_REG_CMD_WRITE_LEN, 0);
864 MALO_WRITE_1(sc, MALO_REG_HOST_STATUS, MALO_VAL_CMD_DL_OVER);
865 MALO_WRITE_2(sc, MALO_REG_CARD_INTR_CAUSE, MALO_VAL_CMD_DL_OVER);
866 DPRINTF(1, "%s: helper FW downloaded\n", device_xname(sc->sc_dev));
867
868 return 0;
869 }
870
871 static int
872 cmalo_fw_load_main(struct malo_softc *sc)
873 {
874 uint16_t val16, bsize = 0, *uc;
875 int offset, i, retry = 0;
876
877 /* verify if the helper firmware has been loaded correctly */
878 for (i = 0; i < 10; i++) {
879 if (MALO_READ_1(sc, MALO_REG_RBAL) == MALO_FW_HELPER_LOADED)
880 break;
881 delay(1000);
882 }
883 if (i == 10) {
884 aprint_error_dev(sc->sc_dev, "helper FW not loaded\n");
885 return EIO;
886 }
887 DPRINTF(1, "%s: helper FW loaded successfully\n",
888 device_xname(sc->sc_dev));
889
890 /* download the main firmware */
891 for (offset = 0; offset < sc->sc_fw_m_size; offset += bsize) {
892 val16 = MALO_READ_2(sc, MALO_REG_RBAL);
893 /*
894 * If the helper firmware serves us an odd integer then
895 * something went wrong and we retry to download the last
896 * block until we receive a good integer again, or give up.
897 */
898 if (val16 & 0x0001) {
899 if (retry > MALO_FW_MAIN_MAXRETRY) {
900 aprint_error_dev(sc->sc_dev,
901 "main FW download failed\n");
902 return EIO;
903 }
904 retry++;
905 offset -= bsize;
906 } else {
907 retry = 0;
908 bsize = val16;
909 }
910
911 /* send a block in words and confirm it */
912 DPRINTF(3, "%s: download main FW block (%d bytes, %d off)\n",
913 device_xname(sc->sc_dev), bsize, offset);
914 MALO_WRITE_2(sc, MALO_REG_CMD_WRITE_LEN, bsize);
915 uc = (uint16_t *)(sc->sc_fw_m + offset);
916 for (i = 0; i < bsize / 2; i++)
917 MALO_WRITE_2(sc, MALO_REG_CMD_WRITE, htole16(uc[i]));
918 MALO_WRITE_1(sc, MALO_REG_HOST_STATUS, MALO_VAL_CMD_DL_OVER);
919 MALO_WRITE_2(sc, MALO_REG_CARD_INTR_CAUSE,
920 MALO_VAL_CMD_DL_OVER);
921
922 /* poll for an acknowledgement */
923 for (i = 0; i < 5000; i++) {
924 if (MALO_READ_1(sc, MALO_REG_CARD_STATUS) ==
925 MALO_VAL_CMD_DL_OVER)
926 break;
927 }
928 if (i == 5000) {
929 aprint_error_dev(sc->sc_dev,
930 "timeout while main FW block download\n");
931 return EIO;
932 }
933 }
934
935 DPRINTF(1, "%s: main FW downloaded\n", device_xname(sc->sc_dev));
936
937 /* verify if the main firmware has been loaded correctly */
938 for (i = 0; i < 500; i++) {
939 if (MALO_READ_1(sc, MALO_REG_SCRATCH) ==
940 MALO_VAL_SCRATCH_FW_LOADED)
941 break;
942 delay(1000);
943 }
944 if (i == 500) {
945 aprint_error_dev(sc->sc_dev, "main FW not loaded\n");
946 return EIO;
947 }
948
949 DPRINTF(1, "%s: main FW loaded successfully\n",
950 device_xname(sc->sc_dev));
951
952 return 0;
953 }
954
955 static void
956 cmalo_stop(struct malo_softc *sc)
957 {
958 struct ieee80211com *ic = &sc->sc_ic;
959 struct ifnet *ifp = &sc->sc_if;
960
961 /* device down */
962 ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
963
964 /* change device back to initial state */
965 ieee80211_new_state(ic, IEEE80211_S_INIT, -1);
966
967 /* reset device */
968 cmalo_cmd_set_reset(sc);
969 sc->sc_flags &= ~MALO_FW_LOADED;
970
971 if (sc->sc_flags & MALO_DEVICE_ENABLED)
972 malo_pcmcia_disable(sc);
973
974 DPRINTF(1, "%s: device down\n", device_xname(sc->sc_dev));
975 }
976
977 static void
978 cmalo_intr_mask(struct malo_softc *sc, int enable)
979 {
980 uint16_t val16;
981
982 val16 = MALO_READ_2(sc, MALO_REG_HOST_INTR_MASK);
983
984 DPRINTF(3, "%s: intr mask changed from 0x%04x ",
985 device_xname(sc->sc_dev), val16);
986
987 if (enable)
988 MALO_WRITE_2(sc, MALO_REG_HOST_INTR_MASK,
989 val16 & ~MALO_VAL_HOST_INTR_MASK_ON);
990 else
991 MALO_WRITE_2(sc, MALO_REG_HOST_INTR_MASK,
992 val16 | MALO_VAL_HOST_INTR_MASK_ON);
993
994 val16 = MALO_READ_2(sc, MALO_REG_HOST_INTR_MASK);
995
996 DPRINTF(3, "to 0x%04x\n", val16);
997 }
998
999 static void
1000 cmalo_rx(struct malo_softc *sc)
1001 {
1002 struct ieee80211com *ic = &sc->sc_ic;
1003 struct ifnet *ifp = &sc->sc_if;
1004 struct malo_rx_desc *rxdesc;
1005 struct mbuf *m;
1006 uint8_t *data;
1007 uint16_t psize;
1008 int i;
1009
1010 /* read the whole RX packet which is always 802.3 */
1011 psize = MALO_READ_2(sc, MALO_REG_DATA_READ_LEN);
1012 if (psize > MALO_DATA_BUFFER_SIZE) {
1013 aprint_error_dev(sc->sc_dev,
1014 "received data too large: %dbyte\n", psize);
1015 return;
1016 }
1017
1018 MALO_READ_MULTI_2(sc, MALO_REG_DATA_READ,
1019 (uint16_t *)sc->sc_data, psize / sizeof(uint16_t));
1020 if (psize & 0x0001)
1021 sc->sc_data[psize - 1] = MALO_READ_1(sc, MALO_REG_DATA_READ);
1022 MALO_WRITE_1(sc, MALO_REG_HOST_STATUS, MALO_VAL_RX_DL_OVER);
1023 MALO_WRITE_2(sc, MALO_REG_CARD_INTR_CAUSE, MALO_VAL_RX_DL_OVER);
1024
1025 /* access RX packet descriptor */
1026 rxdesc = (struct malo_rx_desc *)sc->sc_data;
1027 rxdesc->status = le16toh(rxdesc->status);
1028 rxdesc->pkglen = le16toh(rxdesc->pkglen);
1029 rxdesc->pkgoffset = le32toh(rxdesc->pkgoffset);
1030
1031 DPRINTF(2, "RX status=%d, pkglen=%d, pkgoffset=%d\n",
1032 rxdesc->status, rxdesc->pkglen, rxdesc->pkgoffset);
1033
1034 if (rxdesc->status != MALO_RX_STATUS_OK)
1035 /* RX packet is not OK */
1036 return;
1037
1038 /* remove the LLC / SNAP header */
1039 data = sc->sc_data + rxdesc->pkgoffset;
1040 i = (ETHER_ADDR_LEN * 2) + sizeof(struct llc);
1041 memcpy(data + (ETHER_ADDR_LEN * 2), data + i, rxdesc->pkglen - i);
1042 rxdesc->pkglen -= sizeof(struct llc);
1043
1044 #define ETHER_ALIGN 2 /* XXX */
1045 /* prepare mbuf */
1046 m = m_devget(sc->sc_data + rxdesc->pkgoffset,
1047 rxdesc->pkglen, ETHER_ALIGN, ifp, NULL);
1048 if (m == NULL) {
1049 DPRINTF(1, "RX m_devget failed\n");
1050 ifp->if_ierrors++;
1051 return;
1052 }
1053
1054 /* push the frame up to the network stack if not in monitor mode */
1055 if (ic->ic_opmode != IEEE80211_M_MONITOR) {
1056 if_percpuq_enqueue(ifp->if_percpuq, m);
1057 } else {
1058 /* XXX: we don't do anything with it? */
1059 m_freem(m);
1060 }
1061 }
1062
1063 static int
1064 cmalo_tx(struct malo_softc *sc, struct mbuf *m)
1065 {
1066 struct ifnet *ifp = &sc->sc_if;
1067 struct malo_tx_desc *txdesc = (struct malo_tx_desc *)sc->sc_data;
1068 uint8_t *data;
1069 uint16_t psize;
1070
1071 memset(sc->sc_data, 0, sizeof(*txdesc));
1072 psize = sizeof(*txdesc) + m->m_pkthdr.len;
1073 data = mtod(m, uint8_t *);
1074
1075 /* prepare TX descriptor */
1076 txdesc->pkgoffset = htole32(sizeof(*txdesc));
1077 txdesc->pkglen = htole16(m->m_pkthdr.len);
1078 memcpy(txdesc->dstaddr, data, ETHER_ADDR_LEN);
1079
1080 /* copy mbuf data to the buffer */
1081 m_copydata(m, 0, m->m_pkthdr.len, sc->sc_data + sizeof(*txdesc));
1082 m_freem(m);
1083
1084 /* send TX packet to the device */
1085 MALO_WRITE_2(sc, MALO_REG_DATA_WRITE_LEN, psize);
1086 MALO_WRITE_MULTI_2(sc, MALO_REG_DATA_WRITE,
1087 (uint16_t *)sc->sc_data, psize / sizeof(uint16_t));
1088 if (psize & 0x0001) {
1089 data = sc->sc_data;
1090 MALO_WRITE_1(sc, MALO_REG_DATA_WRITE, data[psize - 1]);
1091 }
1092 MALO_WRITE_1(sc, MALO_REG_HOST_STATUS, MALO_VAL_TX_DL_OVER);
1093 MALO_WRITE_2(sc, MALO_REG_CARD_INTR_CAUSE, MALO_VAL_TX_DL_OVER);
1094
1095 ifp->if_flags |= IFF_OACTIVE;
1096 ifp->if_timer = 5;
1097
1098 DPRINTF(2, "%s: TX status=%d, pkglen=%d, pkgoffset=%zd\n",
1099 device_xname(sc->sc_dev), txdesc->status, le16toh(txdesc->pkglen),
1100 sizeof(*txdesc));
1101
1102 return 0;
1103 }
1104
1105 static void
1106 cmalo_tx_done(struct malo_softc *sc)
1107 {
1108 struct ifnet *ifp = &sc->sc_if;
1109 int s;
1110
1111 DPRINTF(2, "%s: TX done\n", device_xname(sc->sc_dev));
1112
1113 s = splnet();
1114 ifp->if_opackets++;
1115 ifp->if_flags &= ~IFF_OACTIVE;
1116 ifp->if_timer = 0;
1117 cmalo_start(ifp);
1118 splx(s);
1119 }
1120
1121 static void
1122 cmalo_event(struct malo_softc *sc)
1123 {
1124 uint16_t event;
1125
1126 /* read event reason */
1127 event = MALO_READ_2(sc, MALO_REG_CARD_STATUS);
1128 event &= MALO_VAL_CARD_STATUS_MASK;
1129 event = event >> 8;
1130
1131 switch (event) {
1132 case MALO_EVENT_DEAUTH:
1133 DPRINTF(1, "%s: got deauthentication event (0x%04x)\n",
1134 device_xname(sc->sc_dev), event);
1135 /* try to associate again */
1136 cmalo_cmd_set_assoc(sc);
1137 break;
1138 case MALO_EVENT_DISASSOC:
1139 DPRINTF(1, "%s: got disassociation event (0x%04x)\n",
1140 device_xname(sc->sc_dev), event);
1141 /* try to associate again */
1142 cmalo_cmd_set_assoc(sc);
1143 break;
1144 default:
1145 DPRINTF(1, "%s: got unknown event (0x%04x)\n",
1146 device_xname(sc->sc_dev), event);
1147 break;
1148 }
1149
1150 /* acknowledge event */
1151 MALO_WRITE_2(sc, MALO_REG_CARD_INTR_CAUSE, MALO_VAL_HOST_INTR_EVENT);
1152 }
1153
1154 static void
1155 cmalo_select_network(struct malo_softc *sc)
1156 {
1157 struct ieee80211com *ic = &sc->sc_ic;
1158 int i, best_rssi;
1159
1160 /* reset last selected network */
1161 sc->sc_net_cur = 0;
1162
1163 /* get desired network */
1164 if (ic->ic_des_esslen) {
1165 for (i = 0; i < sc->sc_net_num; i++) {
1166 if (!strcmp(ic->ic_des_essid, sc->sc_net[i].ssid)) {
1167 sc->sc_net_cur = i;
1168 DPRINTF(1, "%s: desired network found (%s)\n",
1169 device_xname(sc->sc_dev),
1170 ic->ic_des_essid);
1171 return;
1172 }
1173 }
1174 DPRINTF(1, "%s: desired network not found in scan results "
1175 "(%s)\n",
1176 device_xname(sc->sc_dev), ic->ic_des_essid);
1177 }
1178
1179 /* get network with best signal strength */
1180 best_rssi = sc->sc_net[0].rssi;
1181 for (i = 0; i < sc->sc_net_num; i++) {
1182 if (best_rssi < sc->sc_net[i].rssi) {
1183 best_rssi = sc->sc_net[i].rssi;
1184 sc->sc_net_cur = i;
1185 }
1186 }
1187 DPRINTF(1, "%s: best network found (%s)\n",
1188 device_xname(sc->sc_dev), sc->sc_net[sc->sc_net_cur].ssid);
1189 }
1190
1191 static void
1192 cmalo_reflect_network(struct malo_softc *sc)
1193 {
1194 struct ieee80211com *ic = &sc->sc_ic;
1195 uint8_t chan;
1196
1197 /* reflect active network to our 80211 stack */
1198
1199 /* BSSID */
1200 IEEE80211_ADDR_COPY(ic->ic_bss->ni_bssid,
1201 sc->sc_net[sc->sc_net_cur].bssid);
1202
1203 /* SSID */
1204 ic->ic_bss->ni_esslen = strlen(sc->sc_net[sc->sc_net_cur].ssid);
1205 memcpy(ic->ic_bss->ni_essid, sc->sc_net[sc->sc_net_cur].ssid,
1206 ic->ic_bss->ni_esslen);
1207
1208 /* channel */
1209 chan = sc->sc_net[sc->sc_net_cur].channel;
1210 ic->ic_curchan = &ic->ic_channels[chan];
1211 }
1212
1213 static int
1214 cmalo_wep(struct malo_softc *sc)
1215 {
1216 struct ieee80211com *ic = &sc->sc_ic;
1217 int i;
1218
1219 for (i = 0; i < IEEE80211_WEP_NKID; i++) {
1220 struct ieee80211_key *key = &ic->ic_crypto.cs_nw_keys[i];
1221
1222 if (!key->wk_keylen)
1223 continue;
1224
1225 DPRINTF(1, "%s: setting wep key for index %d\n",
1226 device_xname(sc->sc_dev), i);
1227
1228 cmalo_cmd_set_wep(sc, i, key);
1229 }
1230
1231 return 0;
1232 }
1233
1234 static int
1235 cmalo_rate2bitmap(int rate)
1236 {
1237 switch (rate) {
1238 /* CCK rates */
1239 case 0: return MALO_RATE_BITMAP_DS1;
1240 case 1: return MALO_RATE_BITMAP_DS2;
1241 case 2: return MALO_RATE_BITMAP_DS5;
1242 case 3: return MALO_RATE_BITMAP_DS11;
1243
1244 /* OFDM rates */
1245 case 4: return MALO_RATE_BITMAP_OFDM6;
1246 case 5: return MALO_RATE_BITMAP_OFDM9;
1247 case 6: return MALO_RATE_BITMAP_OFDM12;
1248 case 7: return MALO_RATE_BITMAP_OFDM18;
1249 case 8: return MALO_RATE_BITMAP_OFDM24;
1250 case 9: return MALO_RATE_BITMAP_OFDM36;
1251 case 10: return MALO_RATE_BITMAP_OFDM48;
1252 case 11: return MALO_RATE_BITMAP_OFDM54;
1253
1254 /* unknown rate: should not happen */
1255 default: return 0;
1256 }
1257 }
1258
1259 static void
1260 cmalo_hexdump(void *buf, int len)
1261 {
1262 #ifdef CMALO_DEBUG
1263 int i;
1264
1265 if (cmalo_d >= 2) {
1266 for (i = 0; i < len; i++) {
1267 if (i % 16 == 0)
1268 printf("%s%5i:", i ? "\n" : "", i);
1269 if (i % 4 == 0)
1270 printf(" ");
1271 printf("%02x", (int)*((u_char *)buf + i));
1272 }
1273 printf("\n");
1274 }
1275 #endif
1276 }
1277
1278 static int
1279 cmalo_cmd_get_hwspec(struct malo_softc *sc)
1280 {
1281 struct malo_cmd_header *hdr;
1282 struct malo_cmd_body_spec *body;
1283 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1284
1285 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1286 hdr->cmd = htole16(MALO_CMD_HWSPEC);
1287 hdr->size = htole16(sizeof(*body));
1288 hdr->seqnum = htole16(1);
1289 hdr->result = 0;
1290
1291 body = (struct malo_cmd_body_spec *)(hdr + 1);
1292 memset(body, 0, sizeof(*body));
1293 /* set all bits for MAC address, otherwise we won't get one back */
1294 memset(body->macaddr, 0xff, ETHER_ADDR_LEN);
1295
1296 /* process command request */
1297 if (cmalo_cmd_request(sc, psize, 0) != 0)
1298 return EIO;
1299
1300 /* process command repsonse */
1301 cmalo_cmd_response(sc);
1302
1303 return 0;
1304 }
1305
1306 static int
1307 cmalo_cmd_rsp_hwspec(struct malo_softc *sc)
1308 {
1309 struct ieee80211com *ic = &sc->sc_ic;
1310 struct malo_cmd_header *hdr = (struct malo_cmd_header *)sc->sc_cmd;
1311 struct malo_cmd_body_spec *body;
1312 int i;
1313
1314 body = (struct malo_cmd_body_spec *)(hdr + 1);
1315
1316 /* get our MAC address */
1317 for (i = 0; i < ETHER_ADDR_LEN; i++)
1318 ic->ic_myaddr[i] = body->macaddr[i];
1319
1320 return 0;
1321 }
1322
1323 static int
1324 cmalo_cmd_set_reset(struct malo_softc *sc)
1325 {
1326 struct malo_cmd_header *hdr = (struct malo_cmd_header *)sc->sc_cmd;
1327 const uint16_t psize = sizeof(*hdr);
1328
1329 hdr->cmd = htole16(MALO_CMD_RESET);
1330 hdr->size = 0;
1331 hdr->seqnum = htole16(1);
1332 hdr->result = 0;
1333
1334 /* process command request */
1335 if (cmalo_cmd_request(sc, psize, 1) != 0)
1336 return EIO;
1337
1338 /* give the device some time to finish the reset */
1339 delay(100);
1340
1341 return 0;
1342 }
1343
1344 static int
1345 cmalo_cmd_set_scan(struct malo_softc *sc)
1346 {
1347 struct ieee80211com *ic = &sc->sc_ic;
1348 struct malo_cmd_header *hdr;
1349 struct malo_cmd_body_scan *body;
1350 struct malo_cmd_tlv_ssid *body_ssid;
1351 struct malo_cmd_tlv_chanlist *body_chanlist;
1352 struct malo_cmd_tlv_rates *body_rates;
1353 uint16_t psize;
1354 int i;
1355
1356 psize = sizeof(*hdr) + sizeof(*body) +
1357 sizeof(*body_ssid) + sizeof(*body_chanlist) + sizeof(*body_rates);
1358
1359 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1360 hdr->cmd = htole16(MALO_CMD_SCAN);
1361 hdr->seqnum = htole16(1);
1362 hdr->result = 0;
1363
1364 body = (struct malo_cmd_body_scan *)(hdr + 1);
1365 body->bsstype = 0x03; /* any BSS */
1366 memset(body->bssid, 0xff, ETHER_ADDR_LEN);
1367
1368 body_ssid = (struct malo_cmd_tlv_ssid *)(body + 1);
1369 body_ssid->type = htole16(MALO_TLV_TYPE_SSID);
1370 body_ssid->size = htole16(0);
1371
1372 body_chanlist = (struct malo_cmd_tlv_chanlist *)(body_ssid + 1);
1373 body_chanlist->type = htole16(MALO_TLV_TYPE_CHANLIST);
1374 body_chanlist->size = htole16(sizeof(body_chanlist->data));
1375 for (i = 0; i < CHANNELS; i++) {
1376 body_chanlist->data[i].radiotype = 0x00;
1377 body_chanlist->data[i].channumber = (i + 1);
1378 body_chanlist->data[i].scantype = 0x00; /* active */
1379 body_chanlist->data[i].minscantime = htole16(0);
1380 body_chanlist->data[i].maxscantime = htole16(100);
1381 }
1382
1383 body_rates = (struct malo_cmd_tlv_rates *)(body_chanlist + 1);
1384 body_rates->type = htole16(MALO_TLV_TYPE_RATES);
1385 body_rates->size =
1386 htole16(ic->ic_sup_rates[IEEE80211_MODE_11B].rs_nrates);
1387 memcpy(body_rates->data, ic->ic_sup_rates[IEEE80211_MODE_11B].rs_rates,
1388 ic->ic_sup_rates[IEEE80211_MODE_11B].rs_nrates);
1389 psize += le16toh(body_rates->size);
1390
1391 memset((char *)(body_rates + 1) + le16toh(body_rates->size), 0,
1392 sizeof(struct malo_cmd_tlv_numprobes));
1393
1394 hdr->size = htole16(psize - sizeof(*hdr));
1395
1396 /* process command request */
1397 if (cmalo_cmd_request(sc, psize, 0) != 0)
1398 return EIO;
1399
1400 /* process command repsonse */
1401 cmalo_cmd_response(sc);
1402
1403 return 0;
1404 }
1405
1406 static int
1407 cmalo_cmd_rsp_scan(struct malo_softc *sc)
1408 {
1409 struct malo_cmd_header *hdr = (struct malo_cmd_header *)sc->sc_cmd;
1410 struct malo_cmd_body_rsp_scan *body;
1411 struct malo_cmd_body_rsp_scan_set *set;
1412 int i;
1413
1414 memset(sc->sc_net, 0, sizeof(sc->sc_net));
1415
1416 body = (struct malo_cmd_body_rsp_scan *)(hdr + 1);
1417 body->bufsize = le16toh(body->bufsize);
1418
1419 DPRINTF(1, "bufsize=%d, APs=%d\n", body->bufsize, body->numofset);
1420 sc->sc_net_num = body->numofset;
1421
1422 set = (struct malo_cmd_body_rsp_scan_set *)(body + 1);
1423
1424 /* cycle through found networks */
1425 for (i = 0; i < body->numofset; i++) {
1426 set->size = le16toh(set->size);
1427 set->beaconintvl = le16toh(set->beaconintvl);
1428 set->capinfo = le16toh(set->capinfo);
1429
1430 DPRINTF(1, "size=%d, bssid=%s, rssi=%d, beaconintvl=%d, "
1431 "capinfo=0x%04x\n",
1432 set->size, ether_sprintf(set->bssid), set->rssi,
1433 set->beaconintvl, set->capinfo);
1434
1435 /* save scan results */
1436 memcpy(sc->sc_net[i].bssid, set->bssid, sizeof(set->bssid));
1437 sc->sc_net[i].rssi = set->rssi;
1438 memcpy(sc->sc_net[i].timestamp, set->timestamp,
1439 sizeof(set->timestamp));
1440 sc->sc_net[i].beaconintvl = set->beaconintvl;
1441 sc->sc_net[i].capinfo = set->capinfo;
1442
1443 cmalo_parse_elements(sc, set->data,
1444 set->size - (sizeof(*set) - sizeof(set->size)), i);
1445
1446 set = (struct malo_cmd_body_rsp_scan_set *)
1447 ((char *)set + sizeof(set->size) + set->size);
1448 }
1449
1450 return 0;
1451 }
1452
1453 static int
1454 cmalo_parse_elements(struct malo_softc *sc, uint8_t *buf, int size, int pos)
1455 {
1456 uint8_t eid, len;
1457 int i;
1458
1459 DPRINTF(2, "element_size=%d, element_pos=%d\n", size, pos);
1460
1461 for (i = 0; i < size; ) {
1462 eid = *(uint8_t *)(buf + i);
1463 i++;
1464 len = *(uint8_t *)(buf + i);
1465 i++;
1466 DPRINTF(2, "eid=%d, len=%d, ", eid, len);
1467
1468 switch (eid) {
1469 case IEEE80211_ELEMID_SSID:
1470 memcpy(sc->sc_net[pos].ssid, buf + i, len);
1471 DPRINTF(2, "ssid=%s\n", sc->sc_net[pos].ssid);
1472 break;
1473 case IEEE80211_ELEMID_RATES:
1474 memcpy(sc->sc_net[pos].rates, buf + i, len);
1475 DPRINTF(2, "rates\n");
1476 break;
1477 case IEEE80211_ELEMID_DSPARMS:
1478 sc->sc_net[pos].channel = *(uint8_t *)(buf + i);
1479 DPRINTF(2, "chnl=%d\n", sc->sc_net[pos].channel);
1480 break;
1481 default:
1482 DPRINTF(2, "unknown\n");
1483 break;
1484 }
1485
1486 i += len;
1487 }
1488
1489 return 0;
1490 }
1491
1492 static int
1493 cmalo_cmd_set_auth(struct malo_softc *sc)
1494 {
1495 struct malo_cmd_header *hdr;
1496 struct malo_cmd_body_auth *body;
1497 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1498
1499 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1500 hdr->cmd = htole16(MALO_CMD_AUTH);
1501 hdr->size = htole16(sizeof(*body));
1502 hdr->seqnum = htole16(1);
1503 hdr->result = 0;
1504
1505 body = (struct malo_cmd_body_auth *)(hdr + 1);
1506 memcpy(body->peermac, sc->sc_net[sc->sc_net_cur].bssid, ETHER_ADDR_LEN);
1507 body->authtype = 0;
1508
1509 /* process command request */
1510 if (cmalo_cmd_request(sc, psize, 0) != 0)
1511 return EIO;
1512
1513 /* process command repsonse */
1514 cmalo_cmd_response(sc);
1515
1516 return 0;
1517 }
1518
1519 static int
1520 cmalo_cmd_set_wep(struct malo_softc *sc, uint16_t index,
1521 struct ieee80211_key *key)
1522 {
1523 struct malo_cmd_header *hdr;
1524 struct malo_cmd_body_wep *body;
1525 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1526
1527 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1528 hdr->cmd = htole16(MALO_CMD_WEP);
1529 hdr->size = htole16(sizeof(*body));
1530 hdr->seqnum = htole16(1);
1531 hdr->result = 0;
1532
1533 body = (struct malo_cmd_body_wep *)(hdr + 1);
1534 memset(body, 0, sizeof(*body));
1535 body->action = htole16(MALO_WEP_ACTION_TYPE_ADD);
1536 body->key_index = htole16(index);
1537
1538 if (body->key_index == 0) {
1539 if (key->wk_keylen > 5)
1540 body->key_type_1 = MALO_WEP_KEY_TYPE_104BIT;
1541 else
1542 body->key_type_1 = MALO_WEP_KEY_TYPE_40BIT;
1543 memcpy(body->key_value_1, key->wk_key, key->wk_keylen);
1544 }
1545 if (body->key_index == 1) {
1546 if (key->wk_keylen > 5)
1547 body->key_type_2 = MALO_WEP_KEY_TYPE_104BIT;
1548 else
1549 body->key_type_2 = MALO_WEP_KEY_TYPE_40BIT;
1550 memcpy(body->key_value_2, key->wk_key, key->wk_keylen);
1551 }
1552 if (body->key_index == 2) {
1553 if (key->wk_keylen > 5)
1554 body->key_type_3 = MALO_WEP_KEY_TYPE_104BIT;
1555 else
1556 body->key_type_3 = MALO_WEP_KEY_TYPE_40BIT;
1557 memcpy(body->key_value_3, key->wk_key, key->wk_keylen);
1558 }
1559 if (body->key_index == 3) {
1560 if (key->wk_keylen > 5)
1561 body->key_type_4 = MALO_WEP_KEY_TYPE_104BIT;
1562 else
1563 body->key_type_4 = MALO_WEP_KEY_TYPE_40BIT;
1564 memcpy(body->key_value_4, key->wk_key, key->wk_keylen);
1565 }
1566
1567 /* process command request */
1568 if (cmalo_cmd_request(sc, psize, 0) != 0)
1569 return EIO;
1570
1571 /* process command repsonse */
1572 cmalo_cmd_response(sc);
1573
1574 return 0;
1575 }
1576
1577 static int
1578 cmalo_cmd_set_snmp(struct malo_softc *sc, uint16_t oid)
1579 {
1580 struct malo_cmd_header *hdr;
1581 struct malo_cmd_body_snmp *body;
1582 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1583
1584 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1585 hdr->cmd = htole16(MALO_CMD_SNMP);
1586 hdr->size = htole16(sizeof(*body));
1587 hdr->seqnum = htole16(1);
1588 hdr->result = 0;
1589
1590 body = (struct malo_cmd_body_snmp *)(hdr + 1);
1591 memset(body, 0, sizeof(*body));
1592 body->action = htole16(1);
1593
1594 switch (oid) {
1595 case MALO_OID_RTSTRESH:
1596 body->oid = htole16(MALO_OID_RTSTRESH);
1597 body->size = htole16(2);
1598 *(uint16_t *)body->data = htole16(2347);
1599 break;
1600 case MALO_OID_SHORTRETRY:
1601 body->oid = htole16(MALO_OID_SHORTRETRY);
1602 body->size = htole16(2);
1603 *(uint16_t *)body->data = htole16(4);
1604 break;
1605 case MALO_OID_FRAGTRESH:
1606 body->oid = htole16(MALO_OID_FRAGTRESH);
1607 body->size = htole16(2);
1608 *(uint16_t *)body->data = htole16(2346);
1609 break;
1610 case MALO_OID_80211D:
1611 body->oid = htole16(MALO_OID_80211D);
1612 body->size = htole16(2);
1613 *(uint16_t *)body->data = htole16(1);
1614 break;
1615 default:
1616 break;
1617 }
1618
1619 /* process command request */
1620 if (cmalo_cmd_request(sc, psize, 0) != 0)
1621 return EIO;
1622
1623 /* process command repsonse */
1624 cmalo_cmd_response(sc);
1625
1626 return 0;
1627 }
1628
1629 static int
1630 cmalo_cmd_set_radio(struct malo_softc *sc, uint16_t control)
1631 {
1632 struct malo_cmd_header *hdr;
1633 struct malo_cmd_body_radio *body;
1634 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1635
1636 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1637 hdr->cmd = htole16(MALO_CMD_RADIO);
1638 hdr->size = htole16(sizeof(*body));
1639 hdr->seqnum = htole16(1);
1640 hdr->result = 0;
1641
1642 body = (struct malo_cmd_body_radio *)(hdr + 1);
1643 body->action = htole16(1);
1644 if (control)
1645 body->control =
1646 htole16(MALO_CMD_RADIO_ON | MALO_CMD_RADIO_AUTO_P);
1647 else
1648 body->control = 0;
1649
1650 /* process command request */
1651 if (cmalo_cmd_request(sc, psize, 0) != 0)
1652 return EIO;
1653
1654 /* process command repsonse */
1655 cmalo_cmd_response(sc);
1656
1657 return 0;
1658 }
1659
1660 static int
1661 cmalo_cmd_set_channel(struct malo_softc *sc, uint16_t channel)
1662 {
1663 struct malo_cmd_header *hdr;
1664 struct malo_cmd_body_channel *body;
1665 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1666
1667 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1668 hdr->cmd = htole16(MALO_CMD_CHANNEL);
1669 hdr->size = htole16(sizeof(*body));
1670 hdr->seqnum = htole16(1);
1671 hdr->result = 0;
1672
1673 body = (struct malo_cmd_body_channel *)(hdr + 1);
1674 memset(body, 0, sizeof(*body));
1675 body->action = htole16(1);
1676 body->channel = htole16(channel);
1677
1678 /* process command request */
1679 if (cmalo_cmd_request(sc, psize, 0) != 0)
1680 return EIO;
1681
1682 /* process command repsonse */
1683 cmalo_cmd_response(sc);
1684
1685 return 0;
1686 }
1687
1688
1689 static int
1690 cmalo_cmd_set_txpower(struct malo_softc *sc, int16_t txpower)
1691 {
1692 struct malo_cmd_header *hdr;
1693 struct malo_cmd_body_txpower *body;
1694 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1695
1696 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1697 hdr->cmd = htole16(MALO_CMD_TXPOWER);
1698 hdr->size = htole16(sizeof(*body));
1699 hdr->seqnum = htole16(1);
1700 hdr->result = 0;
1701
1702 body = (struct malo_cmd_body_txpower *)(hdr + 1);
1703 body->action = htole16(1);
1704 body->txpower = htole16(txpower);
1705
1706 /* process command request */
1707 if (cmalo_cmd_request(sc, psize, 0) != 0)
1708 return EIO;
1709
1710 /* process command repsonse */
1711 cmalo_cmd_response(sc);
1712
1713 return 0;
1714 }
1715
1716 static int
1717 cmalo_cmd_set_antenna(struct malo_softc *sc, uint16_t action)
1718 {
1719 struct malo_cmd_header *hdr;
1720 struct malo_cmd_body_antenna *body;
1721 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1722
1723 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1724 hdr->cmd = htole16(MALO_CMD_ANTENNA);
1725 hdr->size = htole16(sizeof(*body));
1726 hdr->seqnum = htole16(1);
1727 hdr->result = 0;
1728
1729 body = (struct malo_cmd_body_antenna *)(hdr + 1);
1730 /* 1 = set RX, 2 = set TX */
1731 body->action = htole16(action);
1732
1733 switch (action) {
1734 case 1:
1735 /* set RX antenna */
1736 body->antenna_mode = htole16(0xffff);
1737 break;
1738
1739 case 2:
1740 /* set TX antenna */
1741 body->antenna_mode = htole16(2);
1742 break;
1743
1744 default:
1745 body->antenna_mode = 0;
1746 break;
1747 }
1748
1749 /* process command request */
1750 if (cmalo_cmd_request(sc, psize, 0) != 0)
1751 return EIO;
1752
1753 /* process command repsonse */
1754 cmalo_cmd_response(sc);
1755
1756 return 0;
1757 }
1758
1759 static int
1760 cmalo_cmd_set_macctrl(struct malo_softc *sc)
1761 {
1762 struct ieee80211com *ic = &sc->sc_ic;
1763 struct malo_cmd_header *hdr;
1764 struct malo_cmd_body_macctrl *body;
1765 uint16_t psize;
1766
1767 psize = sizeof(*hdr) + sizeof(*body);
1768
1769 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1770 hdr->cmd = htole16(MALO_CMD_MACCTRL);
1771 hdr->size = htole16(sizeof(*body));
1772 hdr->seqnum = htole16(1);
1773 hdr->result = 0;
1774
1775 body = (struct malo_cmd_body_macctrl *)(hdr + 1);
1776 memset(body, 0, sizeof(*body));
1777 body->action = htole16(MALO_CMD_MACCTRL_RX_ON | MALO_CMD_MACCTRL_TX_ON);
1778 if (ic->ic_opmode == IEEE80211_M_MONITOR)
1779 body->action |= htole16(MALO_CMD_MACCTRL_PROMISC_ON);
1780
1781 /* process command request */
1782 if (cmalo_cmd_request(sc, psize, 0) != 0)
1783 return EIO;
1784
1785 /* process command repsonse */
1786 cmalo_cmd_response(sc);
1787
1788 return 0;
1789 }
1790
1791 static int
1792 cmalo_cmd_set_macaddr(struct malo_softc *sc, uint8_t *macaddr)
1793 {
1794 struct malo_cmd_header *hdr;
1795 struct malo_cmd_body_macaddr *body;
1796 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1797
1798 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1799 hdr->cmd = htole16(MALO_CMD_MACADDR);
1800 hdr->size = htole16(sizeof(*body));
1801 hdr->seqnum = htole16(1);
1802 hdr->result = 0;
1803
1804 body = (struct malo_cmd_body_macaddr *)(hdr + 1);
1805 body->action = htole16(1);
1806 memcpy(body->macaddr, macaddr, ETHER_ADDR_LEN);
1807
1808 /* process command request */
1809 if (cmalo_cmd_request(sc, psize, 0) != 0)
1810 return EIO;
1811
1812 /* process command repsonse */
1813 cmalo_cmd_response(sc);
1814
1815 return 0;
1816 }
1817
1818 static int
1819 cmalo_cmd_set_assoc(struct malo_softc *sc)
1820 {
1821 struct malo_cmd_header *hdr;
1822 struct malo_cmd_body_assoc *body;
1823 struct malo_cmd_tlv_ssid *body_ssid;
1824 struct malo_cmd_tlv_phy *body_phy;
1825 struct malo_cmd_tlv_cf *body_cf;
1826 struct malo_cmd_tlv_rates *body_rates;
1827 struct malo_cmd_tlv_passeid *body_passeid;
1828 uint16_t psize;
1829
1830 psize = sizeof(*hdr) + sizeof(*body) + sizeof(*body_ssid) +
1831 sizeof(body_phy) + sizeof(*body_cf) + sizeof(*body_rates);
1832
1833 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1834 hdr->cmd = htole16(MALO_CMD_ASSOC);
1835 hdr->seqnum = htole16(1);
1836 hdr->result = 0;
1837
1838 body = (struct malo_cmd_body_assoc *)(hdr + 1);
1839 memset(body, 0, sizeof(*body));
1840 memcpy(body->peermac, sc->sc_net[sc->sc_net_cur].bssid, ETHER_ADDR_LEN);
1841 body->capinfo = htole16(sc->sc_net[sc->sc_net_cur].capinfo);
1842 body->listenintrv = htole16(10);
1843
1844 body_ssid = (struct malo_cmd_tlv_ssid *)(body + 1);
1845 body_ssid->type = htole16(MALO_TLV_TYPE_SSID);
1846 body_ssid->size = htole16(strlen(sc->sc_net[sc->sc_net_cur].ssid));
1847 memcpy(body_ssid->data, sc->sc_net[sc->sc_net_cur].ssid,
1848 le16toh(body_ssid->size));
1849 psize += le16toh(body_ssid->size);
1850
1851 body_phy = (struct malo_cmd_tlv_phy *)
1852 ((char *)(body_ssid + 1) + le16toh(body_ssid->size));
1853 body_phy->type = htole16(MALO_TLV_TYPE_PHY);
1854 body_phy->size = htole16(1);
1855 body_phy->data[0] = sc->sc_net[sc->sc_net_cur].channel;
1856 psize += le16toh(body_phy->size);
1857
1858 body_cf = (struct malo_cmd_tlv_cf *)
1859 ((char *)(body_phy + 1) + le16toh(body_phy->size));
1860 body_cf->type = htole16(MALO_TLV_TYPE_CF);
1861 body_cf->size = htole16(0);
1862
1863 body_rates = (struct malo_cmd_tlv_rates *)(body_cf + 1);
1864 body_rates->type = htole16(MALO_TLV_TYPE_RATES);
1865 body_rates->size = htole16(strlen(sc->sc_net[sc->sc_net_cur].rates));
1866 memcpy(body_rates->data, sc->sc_net[sc->sc_net_cur].rates,
1867 le16toh(body_rates->size));
1868 psize += le16toh(body_rates->size);
1869
1870 /* hack to correct FW's wrong generated rates-element-id */
1871 body_passeid = (struct malo_cmd_tlv_passeid *)
1872 ((char *)(body_rates + 1) + le16toh(body_rates->size));
1873 body_passeid->type = htole16(MALO_TLV_TYPE_PASSEID);
1874 body_passeid->size = body_rates->size;
1875 memcpy(body_passeid->data, body_rates->data, le16toh(body_rates->size));
1876 psize += le16toh(body_passeid->size);
1877
1878 hdr->size = htole16(psize - sizeof(*hdr));
1879
1880 /* process command request */
1881 if (!sc->sc_cmd_ctxsave) {
1882 if (cmalo_cmd_request(sc, psize, 1) != 0)
1883 return EIO;
1884 return 0;
1885 }
1886 if (cmalo_cmd_request(sc, psize, 0) != 0)
1887 return EIO;
1888
1889 /* process command repsonse */
1890 cmalo_cmd_response(sc);
1891
1892 return 0;
1893 }
1894
1895 static int
1896 cmalo_cmd_rsp_assoc(struct malo_softc *sc)
1897 {
1898 struct malo_cmd_header *hdr = (struct malo_cmd_header *)sc->sc_cmd;
1899 struct malo_cmd_body_rsp_assoc *body;
1900
1901 body = (struct malo_cmd_body_rsp_assoc *)(hdr + 1);
1902
1903 if (body->status) {
1904 DPRINTF(1, "%s: association failed (status %d)\n",
1905 device_xname(sc->sc_dev), body->status);
1906 sc->sc_flags |= MALO_ASSOC_FAILED;
1907 } else
1908 DPRINTF(1, "%s: association successful\n",
1909 device_xname(sc->sc_dev));
1910
1911 return 0;
1912 }
1913
1914 static int
1915 cmalo_cmd_set_rate(struct malo_softc *sc, int rate)
1916 {
1917 struct malo_cmd_header *hdr;
1918 struct malo_cmd_body_rate *body;
1919 const uint16_t psize = sizeof(*hdr) + sizeof(*body);
1920
1921 hdr = (struct malo_cmd_header *)sc->sc_cmd;
1922 hdr->cmd = htole16(MALO_CMD_RATE);
1923 hdr->size = htole16(sizeof(*body));
1924 hdr->seqnum = htole16(1);
1925 hdr->result = 0;
1926
1927 body = (struct malo_cmd_body_rate *)(hdr + 1);
1928 body->action = htole16(1);
1929 if (rate == IEEE80211_FIXED_RATE_NONE) {
1930 body->hwauto = htole16(1);
1931 body->ratebitmap = htole16(MALO_RATE_BITMAP_AUTO);
1932 } else {
1933 body->hwauto = 0;
1934 body->ratebitmap = htole16(cmalo_rate2bitmap(rate));
1935 }
1936
1937 /* process command request */
1938 if (cmalo_cmd_request(sc, psize, 0) != 0)
1939 return EIO;
1940
1941 /* process command repsonse */
1942 cmalo_cmd_response(sc);
1943
1944 return 0;
1945 }
1946
1947 static int
1948 cmalo_cmd_request(struct malo_softc *sc, uint16_t psize, int no_response)
1949 {
1950 uint8_t *cmd;
1951
1952 mutex_enter(&sc->sc_mtx);
1953
1954 cmalo_hexdump(sc->sc_cmd, psize);
1955
1956 /* send command request */
1957 MALO_WRITE_2(sc, MALO_REG_CMD_WRITE_LEN, psize);
1958 MALO_WRITE_MULTI_2(sc, MALO_REG_CMD_WRITE,
1959 (uint16_t *)sc->sc_cmd, psize / sizeof(uint16_t));
1960 if (psize & 0x0001) {
1961 cmd = sc->sc_cmd;
1962 MALO_WRITE_1(sc, MALO_REG_CMD_WRITE, cmd[psize - 1]);
1963 }
1964 MALO_WRITE_1(sc, MALO_REG_HOST_STATUS, MALO_VAL_CMD_DL_OVER);
1965 MALO_WRITE_2(sc, MALO_REG_CARD_INTR_CAUSE, MALO_VAL_CMD_DL_OVER);
1966
1967 if (no_response) {
1968 mutex_exit(&sc->sc_mtx);
1969
1970 /* we don't expect a response */
1971 return 0;
1972 }
1973
1974 /* wait for the command response */
1975 if (cv_timedwait_sig(&sc->sc_cv, &sc->sc_mtx, 500) == EWOULDBLOCK) {
1976 mutex_exit(&sc->sc_mtx);
1977 aprint_error_dev(sc->sc_dev,
1978 "timeout while waiting for cmd response\n");
1979 return EIO;
1980 }
1981 mutex_exit(&sc->sc_mtx);
1982
1983 return 0;
1984 }
1985
1986 static int
1987 cmalo_cmd_response(struct malo_softc *sc)
1988 {
1989 struct malo_cmd_header *hdr = (struct malo_cmd_header *)sc->sc_cmd;
1990 uint16_t psize;
1991 int s;
1992
1993 s = splnet();
1994
1995 #ifdef CMALO_DEBUG
1996 memset(sc->sc_cmd, 0, MALO_CMD_BUFFER_SIZE);
1997 #endif
1998
1999 /* read the whole command response */
2000 psize = MALO_READ_2(sc, MALO_REG_CMD_READ_LEN);
2001 if (psize > MALO_CMD_BUFFER_SIZE) {
2002 aprint_error_dev(sc->sc_dev,
2003 "command response too large: %dbyte\n", psize);
2004 splx(s);
2005 return EIO;
2006 }
2007
2008 MALO_READ_MULTI_2(sc, MALO_REG_CMD_READ,
2009 (uint16_t *)sc->sc_cmd, psize / sizeof(uint16_t));
2010 if (psize & 0x0001)
2011 sc->sc_cmd[psize - 1] = MALO_READ_1(sc, MALO_REG_CMD_READ);
2012
2013 cmalo_hexdump(sc->sc_cmd, psize);
2014
2015 /*
2016 * We convert the header values into the machines correct endianess,
2017 * so we don't have to le16toh() all over the code. The body is
2018 * kept in the cards order, little endian. We need to take care
2019 * about the body endianess in the corresponding response routines.
2020 */
2021 hdr->cmd = le16toh(hdr->cmd);
2022 hdr->size = le16toh(hdr->size);
2023 hdr->seqnum = le16toh(hdr->seqnum);
2024 hdr->result = le16toh(hdr->result);
2025
2026 /* check for a valid command response */
2027 if (!(hdr->cmd & MALO_CMD_RESP)) {
2028 aprint_error_dev(sc->sc_dev,
2029 "got invalid command response (0x%04x)\n", hdr->cmd);
2030 splx(s);
2031 return EIO;
2032 }
2033 hdr->cmd &= ~MALO_CMD_RESP;
2034
2035 /* association cmd response is special */
2036 if (hdr->cmd == 0x0012)
2037 hdr->cmd = MALO_CMD_ASSOC;
2038
2039 /* to which command does the response belong */
2040 switch (hdr->cmd) {
2041 case MALO_CMD_HWSPEC:
2042 DPRINTF(1, "%s: got hwspec cmd response\n",
2043 device_xname(sc->sc_dev));
2044 cmalo_cmd_rsp_hwspec(sc);
2045 break;
2046 case MALO_CMD_RESET:
2047 /* reset will not send back a response */
2048 break;
2049 case MALO_CMD_SCAN:
2050 DPRINTF(1, "%s: got scan cmd response\n",
2051 device_xname(sc->sc_dev));
2052 cmalo_cmd_rsp_scan(sc);
2053 break;
2054 case MALO_CMD_AUTH:
2055 /* do nothing */
2056 DPRINTF(1, "%s: got auth cmd response\n",
2057 device_xname(sc->sc_dev));
2058 break;
2059 case MALO_CMD_WEP:
2060 /* do nothing */
2061 DPRINTF(1, "%s: got wep cmd response\n",
2062 device_xname(sc->sc_dev));
2063 break;
2064 case MALO_CMD_SNMP:
2065 /* do nothing */
2066 DPRINTF(1, "%s: got snmp cmd response\n",
2067 device_xname(sc->sc_dev));
2068 break;
2069 case MALO_CMD_RADIO:
2070 /* do nothing */
2071 DPRINTF(1, "%s: got radio cmd response\n",
2072 device_xname(sc->sc_dev));
2073 break;
2074 case MALO_CMD_CHANNEL:
2075 /* do nothing */
2076 DPRINTF(1, "%s: got channel cmd response\n",
2077 device_xname(sc->sc_dev));
2078 break;
2079 case MALO_CMD_TXPOWER:
2080 /* do nothing */
2081 DPRINTF(1, "%s: got txpower cmd response\n",
2082 device_xname(sc->sc_dev));
2083 break;
2084 case MALO_CMD_ANTENNA:
2085 /* do nothing */
2086 DPRINTF(1, "%s: got antenna cmd response\n",
2087 device_xname(sc->sc_dev));
2088 break;
2089 case MALO_CMD_MACCTRL:
2090 /* do nothing */
2091 DPRINTF(1, "%s: got macctrl cmd response\n",
2092 device_xname(sc->sc_dev));
2093 break;
2094 case MALO_CMD_MACADDR:
2095 /* do nothing */
2096 DPRINTF(1, "%s: got macaddr cmd response\n",
2097 device_xname(sc->sc_dev));
2098 break;
2099 case MALO_CMD_ASSOC:
2100 /* do nothing */
2101 DPRINTF(1, "%s: got assoc cmd response\n",
2102 device_xname(sc->sc_dev));
2103 cmalo_cmd_rsp_assoc(sc);
2104 break;
2105 case MALO_CMD_80211D:
2106 /* do nothing */
2107 DPRINTF(1, "%s: got 80211d cmd response\n",
2108 device_xname(sc->sc_dev));
2109 break;
2110 case MALO_CMD_BGSCAN_CONFIG:
2111 /* do nothing */
2112 DPRINTF(1, "%s: got bgscan config cmd response\n",
2113 device_xname(sc->sc_dev));
2114 break;
2115 case MALO_CMD_BGSCAN_QUERY:
2116 /* do nothing */
2117 DPRINTF(1, "%s: got bgscan query cmd response\n",
2118 device_xname(sc->sc_dev));
2119 break;
2120 case MALO_CMD_RATE:
2121 /* do nothing */
2122 DPRINTF(1, "%s: got rate cmd response\n",
2123 device_xname(sc->sc_dev));
2124 break;
2125 default:
2126 aprint_error_dev(sc->sc_dev,
2127 "got unknown cmd response (0x%04x)\n", hdr->cmd);
2128 break;
2129 }
2130
2131 splx(s);
2132
2133 return 0;
2134 }
2135
2136 #ifdef _MODULE
2137
2138 MODULE(MODULE_CLASS_DRIVER, malo_pcmcia, NULL);
2139
2140 CFDRIVER_DECL(malo_pcmcia, DV_IFNET, NULL);
2141 extern struct cfattach malo_pcmcia_ca;
2142 static int malo_pcmcialoc[] = { -1 };
2143 static struct cfparent pcmciaparent = {
2144 "pcmcia", NULL, DVUNIT_ANY
2145 };
2146 static struct cfdata malo_pcmcia_cfdata[] = {
2147 {
2148 .cf_name = "malo_pcmcia",
2149 .cf_atname = "malo",
2150 .cf_unit = 0,
2151 .cf_fstate = FSTATE_STAR,
2152 .cf_loc = malo_pcmcialoc,
2153 .cf_flags = 0,
2154 .cf_pspec = &pcmciaparent,
2155 },
2156 { NULL }
2157 };
2158
2159 static int
2160 malo_pcmcia_modcmd(modcmd_t cmd, void *arg)
2161 {
2162 int err;
2163
2164 switch (cmd) {
2165 case MODULE_CMD_INIT:
2166 err = config_cfdriver_attach(&malo_pcmcia_cd);
2167 if (err)
2168 return err;
2169 err = config_cfattach_attach("malo_pcmcia", &malo_pcmcia_ca);
2170 if (err) {
2171 config_cfdriver_detach(&malo_pcmcia_cd);
2172 return err;
2173 }
2174 err = config_cfdata_attach(malo_pcmcia_cfdata, 1);
2175 if (err) {
2176 config_cfattach_detach("malo_pcmcia", &malo_pcmcia_ca);
2177 config_cfdriver_detach(&malo_pcmcia_cd);
2178 return err;
2179 }
2180 return 0;
2181 case MODULE_CMD_FINI:
2182 err = config_cfdata_detach(malo_pcmcia_cfdata);
2183 if (err)
2184 return err;
2185 config_cfattach_detach("malo_pcmcia", &malo_pcmcia_ca);
2186 config_cfdriver_detach(&malo_pcmcia_cd);
2187 return 0;
2188 default:
2189 return ENOTTY;
2190 }
2191 }
2192 #endif
2193