Home | History | Annotate | Line # | Download | only in usb
if_atu.c revision 1.2
      1  1.2  joff /*	$NetBSD: if_atu.c,v 1.2 2005/01/24 22:40:00 joff Exp $ */
      2  1.1  joff /*	$OpenBSD: if_atu.c,v 1.48 2004/12/30 01:53:21 dlg Exp $ */
      3  1.1  joff /*
      4  1.1  joff  * Copyright (c) 2003, 2004
      5  1.1  joff  *	Daan Vreeken <Danovitsch (at) Vitsch.net>.  All rights reserved.
      6  1.1  joff  *
      7  1.1  joff  * Redistribution and use in source and binary forms, with or without
      8  1.1  joff  * modification, are permitted provided that the following conditions
      9  1.1  joff  * are met:
     10  1.1  joff  * 1. Redistributions of source code must retain the above copyright
     11  1.1  joff  *    notice, this list of conditions and the following disclaimer.
     12  1.1  joff  * 2. Redistributions in binary form must reproduce the above copyright
     13  1.1  joff  *    notice, this list of conditions and the following disclaimer in the
     14  1.1  joff  *    documentation and/or other materials provided with the distribution.
     15  1.1  joff  * 3. All advertising materials mentioning features or use of this software
     16  1.1  joff  *    must display the following acknowledgement:
     17  1.1  joff  *	This product includes software developed by Daan Vreeken.
     18  1.1  joff  * 4. Neither the name of the author nor the names of any co-contributors
     19  1.1  joff  *    may be used to endorse or promote products derived from this software
     20  1.1  joff  *    without specific prior written permission.
     21  1.1  joff  *
     22  1.1  joff  * THIS SOFTWARE IS PROVIDED BY Daan Vreeken AND CONTRIBUTORS ``AS IS'' AND
     23  1.1  joff  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     24  1.1  joff  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     25  1.1  joff  * ARE DISCLAIMED.  IN NO EVENT SHALL Daan Vreeken OR THE VOICES IN HIS HEAD
     26  1.1  joff  * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
     27  1.1  joff  * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
     28  1.1  joff  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
     29  1.1  joff  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
     30  1.1  joff  * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     31  1.1  joff  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
     32  1.1  joff  * THE POSSIBILITY OF SUCH DAMAGE.
     33  1.1  joff  */
     34  1.1  joff 
     35  1.1  joff /*
     36  1.1  joff  * Atmel AT76c503 / AT76c503a / AT76c505 / AT76c505a  USB WLAN driver
     37  1.1  joff  * version 0.5 - 2004-08-03
     38  1.1  joff  *
     39  1.1  joff  * Originally written by Daan Vreeken <Danovitsch @ Vitsch . net>
     40  1.1  joff  *  http://vitsch.net/bsd/atuwi
     41  1.1  joff  *
     42  1.1  joff  * Contributed to by :
     43  1.1  joff  *  Chris Whitehouse, Alistair Phillips, Peter Pilka, Martijn van Buul,
     44  1.1  joff  *  Suihong Liang, Arjan van Leeuwen, Stuart Walsh
     45  1.1  joff  *
     46  1.1  joff  * Ported to OpenBSD by Theo de Raadt and David Gwynne.
     47  1.1  joff  * Ported to NetBSD by Jesse Off
     48  1.1  joff  */
     49  1.1  joff 
     50  1.1  joff #include <sys/cdefs.h>
     51  1.2  joff __KERNEL_RCSID(0, "$NetBSD: if_atu.c,v 1.2 2005/01/24 22:40:00 joff Exp $");
     52  1.1  joff 
     53  1.1  joff #include "bpfilter.h"
     54  1.1  joff 
     55  1.1  joff #include <sys/param.h>
     56  1.1  joff #include <sys/sockio.h>
     57  1.1  joff #include <sys/mbuf.h>
     58  1.1  joff #include <sys/kernel.h>
     59  1.1  joff #include <sys/socket.h>
     60  1.1  joff #include <sys/systm.h>
     61  1.1  joff #include <sys/malloc.h>
     62  1.1  joff #include <sys/kthread.h>
     63  1.1  joff #include <sys/queue.h>
     64  1.1  joff #include <sys/device.h>
     65  1.1  joff 
     66  1.1  joff #include <machine/bus.h>
     67  1.1  joff 
     68  1.1  joff #include <dev/usb/usb.h>
     69  1.1  joff #include <dev/usb/usbdi.h>
     70  1.1  joff #include <dev/usb/usbdi_util.h>
     71  1.1  joff #include <dev/usb/usbdivar.h>
     72  1.1  joff 
     73  1.1  joff #include <dev/usb/usbdevs.h>
     74  1.1  joff 
     75  1.1  joff #include <dev/microcode/atmel/atmel_intersil_fw.h>
     76  1.1  joff #include <dev/microcode/atmel/atmel_rfmd2958-smc_fw.h>
     77  1.1  joff #include <dev/microcode/atmel/atmel_rfmd2958_fw.h>
     78  1.1  joff #include <dev/microcode/atmel/atmel_rfmd_fw.h>
     79  1.1  joff 
     80  1.1  joff #if NBPFILTER > 0
     81  1.1  joff #define BPF_MTAP(ifp, m) bpf_mtap((ifp)->if_bpf, (m))
     82  1.1  joff #include <net/bpf.h>
     83  1.1  joff #endif
     84  1.1  joff 
     85  1.1  joff #include <net/if.h>
     86  1.1  joff #include <net/if_dl.h>
     87  1.1  joff #include <net/if_media.h>
     88  1.1  joff #include <net/if_ether.h>
     89  1.1  joff 
     90  1.1  joff #ifdef INET
     91  1.1  joff #include <netinet/in.h>
     92  1.1  joff #include <netinet/if_ether.h>
     93  1.1  joff #endif
     94  1.1  joff 
     95  1.1  joff #include <net80211/ieee80211_var.h>
     96  1.1  joff #include <net80211/ieee80211_radiotap.h>
     97  1.1  joff 
     98  1.1  joff #ifdef USB_DEBUG
     99  1.1  joff #define ATU_DEBUG
    100  1.1  joff #endif
    101  1.1  joff 
    102  1.1  joff #include <dev/usb/if_atureg.h>
    103  1.1  joff 
    104  1.1  joff #ifdef ATU_DEBUG
    105  1.1  joff #define DPRINTF(x)	do { if (atudebug) printf x; } while (0)
    106  1.1  joff #define DPRINTFN(n,x)	do { if (atudebug>(n)) printf x; } while (0)
    107  1.1  joff int atudebug = 1;
    108  1.1  joff #else
    109  1.1  joff #define DPRINTF(x)
    110  1.1  joff #define DPRINTFN(n,x)
    111  1.1  joff #endif
    112  1.1  joff 
    113  1.1  joff /*
    114  1.1  joff  * Various supported device vendors/products/radio type.
    115  1.1  joff  */
    116  1.1  joff struct atu_type atu_devs[] = {
    117  1.1  joff 	{ USB_VENDOR_ATMEL,	USB_PRODUCT_ATMEL_BW002,
    118  1.1  joff 	  RadioRFMD,		ATU_NO_QUIRK },
    119  1.1  joff 	{ USB_VENDOR_BELKIN,	USB_PRODUCT_BELKIN_F5D6050,
    120  1.1  joff 	  RadioRFMD,		ATU_NO_QUIRK },
    121  1.1  joff 	{ USB_VENDOR_ATMEL,	USB_PRODUCT_ATMEL_AT76C503A,
    122  1.1  joff 	  RadioIntersil,	ATU_NO_QUIRK },
    123  1.1  joff 	{ USB_VENDOR_LEXAR,	USB_PRODUCT_LEXAR_2662WAR,
    124  1.1  joff 	  RadioRFMD,		ATU_NO_QUIRK },
    125  1.1  joff 	{ USB_VENDOR_LINKSYS2,	USB_PRODUCT_LINKSYS2_WUSB11,
    126  1.1  joff 	  RadioRFMD,		ATU_NO_QUIRK },
    127  1.1  joff 	{ USB_VENDOR_LINKSYS3,	USB_PRODUCT_LINKSYS3_WUSB11V28,
    128  1.1  joff 	  RadioRFMD2958,	ATU_NO_QUIRK },
    129  1.1  joff 	{ USB_VENDOR_NETGEAR2,	USB_PRODUCT_NETGEAR2_MA101B,
    130  1.1  joff 	  RadioRFMD,		ATU_NO_QUIRK },
    131  1.1  joff 	{ USB_VENDOR_ACERP,	USB_PRODUCT_ACERP_AWL400,
    132  1.1  joff 	  RadioRFMD,		ATU_NO_QUIRK },
    133  1.1  joff 	{ USB_VENDOR_ATMEL,	USB_PRODUCT_ATMEL_WL1130,
    134  1.1  joff 	  RadioRFMD2958,	ATU_NO_QUIRK },
    135  1.1  joff 	{ USB_VENDOR_LINKSYS3,	USB_PRODUCT_LINKSYS3_WUSB11V28,
    136  1.1  joff 	  RadioRFMD2958,	ATU_NO_QUIRK },
    137  1.1  joff 	{ USB_VENDOR_AINCOMM,	USB_PRODUCT_AINCOMM_AWU2000B,
    138  1.1  joff 	  RadioRFMD2958,	ATU_NO_QUIRK },
    139  1.1  joff 	/* SMC2662 V.4 */
    140  1.1  joff 	{ USB_VENDOR_ATMEL,	USB_PRODUCT_ATMEL_AT76C505A,
    141  1.1  joff 	  RadioRFMD2958_SMC,	ATU_QUIRK_NO_REMAP | ATU_QUIRK_FW_DELAY },
    142  1.1  joff 	{ USB_VENDOR_ACERP,	USB_PRODUCT_ACERP_AWL300,
    143  1.1  joff 	  RadioIntersil,	ATU_NO_QUIRK },
    144  1.1  joff };
    145  1.1  joff 
    146  1.1  joff struct atu_radfirm {
    147  1.1  joff 	enum	atu_radio_type atur_type;
    148  1.1  joff 	unsigned char	*atur_internal;
    149  1.1  joff 	size_t		atur_internal_sz;
    150  1.1  joff 	unsigned char	*atur_external;
    151  1.1  joff 	size_t		atur_external_sz;
    152  1.1  joff } atu_radfirm[] = {
    153  1.1  joff 	{ RadioRFMD,
    154  1.1  joff 	  atmel_fw_rfmd_int,		sizeof(atmel_fw_rfmd_int),
    155  1.1  joff 	  atmel_fw_rfmd_ext,		sizeof(atmel_fw_rfmd_ext) },
    156  1.1  joff 	{ RadioRFMD2958,
    157  1.1  joff 	  atmel_fw_rfmd2958_int,	sizeof(atmel_fw_rfmd2958_int),
    158  1.1  joff 	  atmel_fw_rfmd2958_ext,	sizeof(atmel_fw_rfmd2958_ext) },
    159  1.1  joff 	{ RadioRFMD2958_SMC,
    160  1.1  joff 	  atmel_fw_rfmd2958_smc_int,	sizeof(atmel_fw_rfmd2958_smc_int),
    161  1.1  joff 	  atmel_fw_rfmd2958_smc_ext,	sizeof(atmel_fw_rfmd2958_smc_ext) },
    162  1.1  joff 	{ RadioIntersil,
    163  1.1  joff 	  atmel_fw_intersil_int,	sizeof(atmel_fw_intersil_int),
    164  1.1  joff 	  atmel_fw_intersil_ext,	sizeof(atmel_fw_intersil_ext) }
    165  1.1  joff };
    166  1.1  joff 
    167  1.1  joff int	atu_newbuf(struct atu_softc *, struct atu_chain *, struct mbuf *);
    168  1.1  joff void	atu_rxeof(usbd_xfer_handle, usbd_private_handle, usbd_status);
    169  1.1  joff void	atu_txeof(usbd_xfer_handle, usbd_private_handle, usbd_status);
    170  1.1  joff void	atu_start(struct ifnet *);
    171  1.1  joff int	atu_ioctl(struct ifnet *, u_long, caddr_t);
    172  1.1  joff int	atu_init(struct ifnet *);
    173  1.1  joff void	atu_stop(struct ifnet *, int);
    174  1.1  joff void	atu_watchdog(struct ifnet *);
    175  1.1  joff usbd_status atu_usb_request(struct atu_softc *sc, u_int8_t type,
    176  1.1  joff 	    u_int8_t request, u_int16_t value, u_int16_t index,
    177  1.1  joff 	    u_int16_t length, u_int8_t *data);
    178  1.1  joff int	atu_send_command(struct atu_softc *sc, u_int8_t *command, int size);
    179  1.1  joff int	atu_get_cmd_status(struct atu_softc *sc, u_int8_t cmd,
    180  1.1  joff 	    u_int8_t *status);
    181  1.1  joff int	atu_wait_completion(struct atu_softc *sc, u_int8_t cmd,
    182  1.1  joff 	    u_int8_t *status);
    183  1.1  joff int	atu_send_mib(struct atu_softc *sc, u_int8_t type,
    184  1.1  joff 	    u_int8_t size, u_int8_t index, void *data);
    185  1.1  joff int	atu_get_mib(struct atu_softc *sc, u_int8_t type,
    186  1.1  joff 	    u_int8_t size, u_int8_t index, u_int8_t *buf);
    187  1.1  joff #if 0
    188  1.1  joff int	atu_start_ibss(struct atu_softc *sc);
    189  1.1  joff #endif
    190  1.1  joff int	atu_start_scan(struct atu_softc *sc);
    191  1.1  joff int	atu_switch_radio(struct atu_softc *sc, int state);
    192  1.1  joff int	atu_initial_config(struct atu_softc *sc);
    193  1.1  joff int	atu_join(struct atu_softc *sc, struct ieee80211_node *node);
    194  1.1  joff int8_t	atu_get_dfu_state(struct atu_softc *sc);
    195  1.1  joff u_int8_t atu_get_opmode(struct atu_softc *sc, u_int8_t *mode);
    196  1.1  joff void	atu_internal_firmware(struct device *);
    197  1.1  joff void	atu_external_firmware(struct device *);
    198  1.1  joff int	atu_get_card_config(struct atu_softc *sc);
    199  1.1  joff int	atu_media_change(struct ifnet *ifp);
    200  1.1  joff void	atu_media_status(struct ifnet *ifp, struct ifmediareq *req);
    201  1.1  joff int	atu_tx_list_init(struct atu_softc *);
    202  1.1  joff int	atu_rx_list_init(struct atu_softc *);
    203  1.1  joff void	atu_xfer_list_free(struct atu_softc *sc, struct atu_chain *ch,
    204  1.1  joff 	    int listlen);
    205  1.1  joff int	atu_set_wepkey(struct atu_softc *sc, int nr, u_int8_t *key, int len);
    206  1.1  joff 
    207  1.1  joff #ifdef ATU_DEBUG
    208  1.1  joff void	atu_debug_print(struct atu_softc *sc);
    209  1.1  joff #endif
    210  1.1  joff 
    211  1.1  joff void atu_task(void *);
    212  1.1  joff int atu_newstate(struct ieee80211com *, enum ieee80211_state, int);
    213  1.1  joff int atu_tx_start(struct atu_softc *, struct ieee80211_node *,
    214  1.1  joff     struct atu_chain *, struct mbuf *);
    215  1.1  joff void atu_complete_attach(struct atu_softc *);
    216  1.1  joff u_int8_t atu_calculate_padding(int);
    217  1.1  joff 
    218  1.1  joff USB_DECLARE_DRIVER(atu);
    219  1.1  joff 
    220  1.1  joff usbd_status
    221  1.1  joff atu_usb_request(struct atu_softc *sc, u_int8_t type,
    222  1.1  joff     u_int8_t request, u_int16_t value, u_int16_t index, u_int16_t length,
    223  1.1  joff     u_int8_t *data)
    224  1.1  joff {
    225  1.1  joff 	usb_device_request_t	req;
    226  1.1  joff 	usbd_xfer_handle	xfer;
    227  1.1  joff 	usbd_status		err;
    228  1.1  joff 	int			total_len = 0, s;
    229  1.1  joff 
    230  1.1  joff 	req.bmRequestType = type;
    231  1.1  joff 	req.bRequest = request;
    232  1.1  joff 	USETW(req.wValue, value);
    233  1.1  joff 	USETW(req.wIndex, index);
    234  1.1  joff 	USETW(req.wLength, length);
    235  1.1  joff 
    236  1.1  joff #ifdef ATU_DEBUG
    237  1.1  joff 	if (atudebug) {
    238  1.1  joff 		DPRINTFN(20, ("%s: req=%02x val=%02x ind=%02x "
    239  1.1  joff 		    "len=%02x\n", USBDEVNAME(sc->atu_dev), request,
    240  1.1  joff 		    value, index, length));
    241  1.1  joff 	}
    242  1.1  joff #endif /* ATU_DEBUG */
    243  1.1  joff 
    244  1.1  joff 	s = splnet();
    245  1.1  joff 
    246  1.1  joff 	xfer = usbd_alloc_xfer(sc->atu_udev);
    247  1.1  joff 	usbd_setup_default_xfer(xfer, sc->atu_udev, 0, 500000, &req, data,
    248  1.1  joff 	    length, USBD_SHORT_XFER_OK, 0);
    249  1.1  joff 
    250  1.1  joff 	err = usbd_sync_transfer(xfer);
    251  1.1  joff 
    252  1.1  joff 	usbd_get_xfer_status(xfer, NULL, NULL, &total_len, NULL);
    253  1.1  joff 
    254  1.1  joff #ifdef ATU_DEBUG
    255  1.1  joff 	if (atudebug) {
    256  1.1  joff 		if (type & UT_READ) {
    257  1.1  joff 			DPRINTFN(20, ("%s: transfered 0x%x bytes in\n",
    258  1.1  joff 			    USBDEVNAME(sc->atu_dev), total_len));
    259  1.1  joff 		} else {
    260  1.1  joff 			if (total_len != length)
    261  1.1  joff 				DPRINTF(("%s: wrote only %x bytes\n",
    262  1.1  joff 				    USBDEVNAME(sc->atu_dev), total_len));
    263  1.1  joff 		}
    264  1.1  joff 	}
    265  1.1  joff #endif /* ATU_DEBUG */
    266  1.1  joff 
    267  1.1  joff 	usbd_free_xfer(xfer);
    268  1.1  joff 
    269  1.1  joff 	splx(s);
    270  1.1  joff 	return(err);
    271  1.1  joff }
    272  1.1  joff 
    273  1.1  joff int
    274  1.1  joff atu_send_command(struct atu_softc *sc, u_int8_t *command, int size)
    275  1.1  joff {
    276  1.1  joff 	return atu_usb_request(sc, UT_WRITE_VENDOR_DEVICE, 0x0e, 0x0000,
    277  1.1  joff 	    0x0000, size, command);
    278  1.1  joff }
    279  1.1  joff 
    280  1.1  joff int
    281  1.1  joff atu_get_cmd_status(struct atu_softc *sc, u_int8_t cmd, u_int8_t *status)
    282  1.1  joff {
    283  1.1  joff 	/*
    284  1.1  joff 	 * all other drivers (including Windoze) request 40 bytes of status
    285  1.1  joff 	 * and get a short-xfer of just 6 bytes. we can save 34 bytes of
    286  1.1  joff 	 * buffer if we just request those 6 bytes in the first place :)
    287  1.1  joff 	 */
    288  1.1  joff 	/*
    289  1.1  joff 	return atu_usb_request(sc, UT_READ_VENDOR_INTERFACE, 0x22, cmd,
    290  1.1  joff 	    0x0000, 40, status);
    291  1.1  joff 	*/
    292  1.1  joff 	return atu_usb_request(sc, UT_READ_VENDOR_INTERFACE, 0x22, cmd,
    293  1.1  joff 	    0x0000, 6, status);
    294  1.1  joff }
    295  1.1  joff 
    296  1.1  joff int
    297  1.1  joff atu_wait_completion(struct atu_softc *sc, u_int8_t cmd, u_int8_t *status)
    298  1.1  joff {
    299  1.1  joff 	int			idle_count = 0, err;
    300  1.1  joff 	u_int8_t		statusreq[6];
    301  1.1  joff 
    302  1.1  joff 	DPRINTFN(15, ("%s: wait-completion: cmd=%02x\n",
    303  1.1  joff 	    USBDEVNAME(sc->atu_dev), cmd));
    304  1.1  joff 
    305  1.1  joff 	while (1) {
    306  1.1  joff 		err = atu_get_cmd_status(sc, cmd, statusreq);
    307  1.1  joff 		if (err)
    308  1.1  joff 			return err;
    309  1.1  joff 
    310  1.1  joff #ifdef ATU_DEBUG
    311  1.1  joff 		if (atudebug) {
    312  1.1  joff 			DPRINTFN(20, ("%s: status=%s cmd=%02x\n",
    313  1.1  joff 			    USBDEVNAME(sc->atu_dev),
    314  1.1  joff 			ether_sprintf(statusreq), cmd));
    315  1.1  joff 		}
    316  1.1  joff #endif /* ATU_DEBUG */
    317  1.1  joff 
    318  1.1  joff 		/*
    319  1.1  joff 		 * during normal operations waiting on STATUS_IDLE
    320  1.1  joff 		 * will never happen more than once
    321  1.1  joff 		 */
    322  1.1  joff 		if ((statusreq[5] == STATUS_IDLE) && (idle_count++ > 20)) {
    323  1.1  joff 			DPRINTF(("%s: idle_count > 20!\n",
    324  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
    325  1.1  joff 			return 0;
    326  1.1  joff 		}
    327  1.1  joff 
    328  1.1  joff 		if ((statusreq[5] != STATUS_IN_PROGRESS) &&
    329  1.1  joff 		    (statusreq[5] != STATUS_IDLE)) {
    330  1.1  joff 			if (status != NULL)
    331  1.1  joff 				*status = statusreq[5];
    332  1.1  joff 			return 0;
    333  1.1  joff 		}
    334  1.1  joff 		usbd_delay_ms(sc->atu_udev, 25);
    335  1.1  joff 	}
    336  1.1  joff }
    337  1.1  joff 
    338  1.1  joff int
    339  1.1  joff atu_send_mib(struct atu_softc *sc, u_int8_t type, u_int8_t size,
    340  1.1  joff     u_int8_t index, void *data)
    341  1.1  joff {
    342  1.1  joff 	int				err;
    343  1.1  joff 	struct atu_cmd_set_mib		request;
    344  1.1  joff 
    345  1.1  joff 	/*
    346  1.1  joff 	 * We don't construct a MIB packet first and then memcpy it into an
    347  1.1  joff 	 * Atmel-command-packet, we just construct it the right way at once :)
    348  1.1  joff 	 */
    349  1.1  joff 
    350  1.1  joff 	memset(&request, 0, sizeof(request));
    351  1.1  joff 
    352  1.1  joff 	request.AtCmd = CMD_SET_MIB;
    353  1.1  joff 	USETW(request.AtSize, size + 4);
    354  1.1  joff 
    355  1.1  joff 	request.MIBType = type;
    356  1.1  joff 	request.MIBSize = size;
    357  1.1  joff 	request.MIBIndex = index;
    358  1.1  joff 	request.MIBReserved = 0;
    359  1.1  joff 
    360  1.1  joff 	/*
    361  1.1  joff 	 * For 1 and 2 byte requests we assume a direct value,
    362  1.1  joff 	 * everything bigger than 2 bytes we assume a pointer to the data
    363  1.1  joff 	 */
    364  1.1  joff 	switch (size) {
    365  1.1  joff 	case 0:
    366  1.1  joff 		break;
    367  1.1  joff 	case 1:
    368  1.1  joff 		request.data[0]=(long)data & 0x000000ff;
    369  1.1  joff 		break;
    370  1.1  joff 	case 2:
    371  1.1  joff 		request.data[0]=(long)data & 0x000000ff;
    372  1.1  joff 		request.data[1]=(long)data >> 8;
    373  1.1  joff 		break;
    374  1.1  joff 	default:
    375  1.1  joff 		memcpy(request.data, data, size);
    376  1.1  joff 		break;
    377  1.1  joff 	}
    378  1.1  joff 
    379  1.1  joff 	err = atu_usb_request(sc, UT_WRITE_VENDOR_DEVICE, 0x0e, 0x0000,
    380  1.1  joff 	    0x0000, size+8, (uByte *)&request);
    381  1.1  joff 	if (err)
    382  1.1  joff 		return (err);
    383  1.1  joff 
    384  1.1  joff 	DPRINTFN(15, ("%s: sendmib : waitcompletion...\n",
    385  1.1  joff 	    USBDEVNAME(sc->atu_dev)));
    386  1.1  joff 	return atu_wait_completion(sc, CMD_SET_MIB, NULL);
    387  1.1  joff }
    388  1.1  joff 
    389  1.1  joff int
    390  1.1  joff atu_get_mib(struct atu_softc *sc, u_int8_t type, u_int8_t size,
    391  1.1  joff     u_int8_t index, u_int8_t *buf)
    392  1.1  joff {
    393  1.1  joff 
    394  1.1  joff 	/* linux/at76c503.c - 478 */
    395  1.1  joff 	return atu_usb_request(sc, UT_READ_VENDOR_INTERFACE, 0x033,
    396  1.1  joff 	    type << 8, index, size, buf);
    397  1.1  joff }
    398  1.1  joff 
    399  1.1  joff #if 0
    400  1.1  joff int
    401  1.1  joff atu_start_ibss(struct atu_softc *sc)
    402  1.1  joff {
    403  1.1  joff 	int				err;
    404  1.1  joff 	struct atu_cmd_start_ibss	Request;
    405  1.1  joff 
    406  1.1  joff 	Request.Cmd = CMD_START_IBSS;
    407  1.1  joff 	Request.Reserved = 0;
    408  1.1  joff 	Request.Size = sizeof(Request) - 4;
    409  1.1  joff 
    410  1.1  joff 	memset(Request.BSSID, 0x00, sizeof(Request.BSSID));
    411  1.1  joff 	memset(Request.SSID, 0x00, sizeof(Request.SSID));
    412  1.1  joff 	memcpy(Request.SSID, sc->atu_ssid, sc->atu_ssidlen);
    413  1.1  joff 	Request.SSIDSize = sc->atu_ssidlen;
    414  1.1  joff 	if (sc->atu_desired_channel != IEEE80211_CHAN_ANY)
    415  1.1  joff 		Request.Channel = (u_int8_t)sc->atu_desired_channel;
    416  1.1  joff 	else
    417  1.1  joff 		Request.Channel = ATU_DEFAULT_CHANNEL;
    418  1.1  joff 	Request.BSSType = AD_HOC_MODE;
    419  1.1  joff 	memset(Request.Res, 0x00, sizeof(Request.Res));
    420  1.1  joff 
    421  1.1  joff 	/* Write config to adapter */
    422  1.1  joff 	err = atu_send_command(sc, (u_int8_t *)&Request, sizeof(Request));
    423  1.1  joff 	if (err) {
    424  1.1  joff 		DPRINTF(("%s: start ibss failed!\n",
    425  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    426  1.1  joff 		return err;
    427  1.1  joff 	}
    428  1.1  joff 
    429  1.1  joff 	/* Wait for the adapter to do it's thing */
    430  1.1  joff 	err = atu_wait_completion(sc, CMD_START_IBSS, NULL);
    431  1.1  joff 	if (err) {
    432  1.1  joff 		DPRINTF(("%s: error waiting for start_ibss\n",
    433  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    434  1.1  joff 		return err;
    435  1.1  joff 	}
    436  1.1  joff 
    437  1.1  joff 	/* Get the current BSSID */
    438  1.1  joff 	err = atu_get_mib(sc, MIB_MAC_MGMT__CURRENT_BSSID, sc->atu_bssid);
    439  1.1  joff 	if (err) {
    440  1.1  joff 		DPRINTF(("%s: could not get BSSID!\n",
    441  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    442  1.1  joff 		return err;
    443  1.1  joff 	}
    444  1.1  joff 
    445  1.1  joff 	DPRINTF(("%s: started a new IBSS (BSSID=%s)\n",
    446  1.1  joff 	    USBDEVNAME(sc->atu_dev), ether_sprintf(sc->atu_bssid)));
    447  1.1  joff 	return 0;
    448  1.1  joff }
    449  1.1  joff #endif
    450  1.1  joff 
    451  1.1  joff int
    452  1.1  joff atu_start_scan(struct atu_softc *sc)
    453  1.1  joff {
    454  1.1  joff 	struct atu_cmd_do_scan		Scan;
    455  1.1  joff 	usbd_status			err;
    456  1.1  joff 	int				Cnt;
    457  1.1  joff 
    458  1.1  joff 	memset(&Scan, 0, sizeof(Scan));
    459  1.1  joff 
    460  1.1  joff 	Scan.Cmd = CMD_START_SCAN;
    461  1.1  joff 	Scan.Reserved = 0;
    462  1.1  joff 	USETW(Scan.Size, sizeof(Scan) - 4);
    463  1.1  joff 
    464  1.1  joff 	/* use the broadcast BSSID (in active scan) */
    465  1.1  joff 	for (Cnt=0; Cnt<6; Cnt++)
    466  1.1  joff 		Scan.BSSID[Cnt] = 0xff;
    467  1.1  joff 
    468  1.1  joff 	memset(Scan.SSID, 0x00, sizeof(Scan.SSID));
    469  1.1  joff 	memcpy(Scan.SSID, sc->atu_ssid, sc->atu_ssidlen);
    470  1.1  joff 	Scan.SSID_Len = sc->atu_ssidlen;
    471  1.1  joff 
    472  1.1  joff 	/* default values for scan */
    473  1.1  joff 	Scan.ScanType = ATU_SCAN_ACTIVE;
    474  1.1  joff 	if (sc->atu_desired_channel != IEEE80211_CHAN_ANY)
    475  1.1  joff 		Scan.Channel = (u_int8_t)sc->atu_desired_channel;
    476  1.1  joff 	else
    477  1.1  joff 		Scan.Channel = sc->atu_channel;
    478  1.1  joff 
    479  1.1  joff 	/* we like scans to be quick :) */
    480  1.1  joff 	/* the time we wait before sending probe's */
    481  1.1  joff 	USETW(Scan.ProbeDelay, 0);
    482  1.1  joff 	/* the time we stay on one channel */
    483  1.1  joff 	USETW(Scan.MinChannelTime, 100);
    484  1.1  joff 	USETW(Scan.MaxChannelTime, 200);
    485  1.1  joff 	/* wether or not we scan all channels */
    486  1.1  joff 	Scan.InternationalScan = 0xc1;
    487  1.1  joff 
    488  1.1  joff #ifdef ATU_DEBUG
    489  1.1  joff 	if (atudebug) {
    490  1.1  joff 		DPRINTFN(20, ("%s: scan cmd len=%02lx\n",
    491  1.2  joff 		    USBDEVNAME(sc->atu_dev), (unsigned long)sizeof(Scan)));
    492  1.1  joff 	}
    493  1.1  joff #endif /* ATU_DEBUG */
    494  1.1  joff 
    495  1.1  joff 	/* Write config to adapter */
    496  1.1  joff 	err = atu_send_command(sc, (u_int8_t *)&Scan, sizeof(Scan));
    497  1.1  joff 	if (err)
    498  1.1  joff 		return err;
    499  1.1  joff 
    500  1.1  joff 	/*
    501  1.1  joff 	 * We don't wait for the command to finish... the mgmt-thread will do
    502  1.1  joff 	 * that for us
    503  1.1  joff 	 */
    504  1.1  joff 	/*
    505  1.1  joff 	err = atu_wait_completion(sc, CMD_START_SCAN, NULL);
    506  1.1  joff 	if (err)
    507  1.1  joff 		return err;
    508  1.1  joff 	*/
    509  1.1  joff 	return 0;
    510  1.1  joff }
    511  1.1  joff 
    512  1.1  joff int
    513  1.1  joff atu_switch_radio(struct atu_softc *sc, int state)
    514  1.1  joff {
    515  1.1  joff 	usbd_status		err;
    516  1.1  joff 	struct atu_cmd		CmdRadio;
    517  1.1  joff 
    518  1.1  joff 	if (sc->atu_radio == RadioIntersil) {
    519  1.1  joff 		/*
    520  1.1  joff 		 * Intersil doesn't seem to need/support switching the radio
    521  1.1  joff 		 * on/off
    522  1.1  joff 		 */
    523  1.1  joff 		return 0;
    524  1.1  joff 	}
    525  1.1  joff 
    526  1.1  joff 	memset(&CmdRadio, 0, sizeof(CmdRadio));
    527  1.1  joff 	CmdRadio.Cmd = CMD_RADIO_ON;
    528  1.1  joff 
    529  1.1  joff 	if (sc->atu_radio_on != state) {
    530  1.1  joff 		if (state == 0)
    531  1.1  joff 			CmdRadio.Cmd = CMD_RADIO_OFF;
    532  1.1  joff 
    533  1.1  joff 		err = atu_send_command(sc, (u_int8_t *)&CmdRadio,
    534  1.1  joff 		    sizeof(CmdRadio));
    535  1.1  joff 		if (err)
    536  1.1  joff 			return err;
    537  1.1  joff 
    538  1.1  joff 		err = atu_wait_completion(sc, CmdRadio.Cmd, NULL);
    539  1.1  joff 		if (err)
    540  1.1  joff 			return err;
    541  1.1  joff 
    542  1.1  joff 		DPRINTFN(10, ("%s: radio turned %s\n",
    543  1.1  joff 		    USBDEVNAME(sc->atu_dev), state ? "on" : "off"));
    544  1.1  joff 		sc->atu_radio_on = state;
    545  1.1  joff 	}
    546  1.1  joff 	return 0;
    547  1.1  joff }
    548  1.1  joff 
    549  1.1  joff int
    550  1.1  joff atu_initial_config(struct atu_softc *sc)
    551  1.1  joff {
    552  1.1  joff 	struct ieee80211com		*ic = &sc->sc_ic;
    553  1.1  joff 	usbd_status			err;
    554  1.1  joff /*	u_int8_t			rates[4] = {0x82, 0x84, 0x8B, 0x96};*/
    555  1.1  joff 	u_int8_t			rates[4] = {0x82, 0x04, 0x0B, 0x16};
    556  1.1  joff 	struct atu_cmd_card_config	cmd;
    557  1.1  joff 	u_int8_t			reg_domain;
    558  1.1  joff 
    559  1.1  joff 	DPRINTFN(10, ("%s: sending mac-addr\n", USBDEVNAME(sc->atu_dev)));
    560  1.1  joff 	err = atu_send_mib(sc, MIB_MAC_ADDR__ADDR, ic->ic_myaddr);
    561  1.1  joff 	if (err) {
    562  1.1  joff 		DPRINTF(("%s: error setting mac-addr\n",
    563  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    564  1.1  joff 		return err;
    565  1.1  joff 	}
    566  1.1  joff 
    567  1.1  joff 	/*
    568  1.1  joff 	DPRINTF(("%s: sending reg-domain\n", USBDEVNAME(sc->atu_dev)));
    569  1.1  joff 	err = atu_send_mib(sc, MIB_PHY__REG_DOMAIN, NR(0x30));
    570  1.1  joff 	if (err) {
    571  1.1  joff 		DPRINTF(("%s: error setting mac-addr\n",
    572  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    573  1.1  joff 		return err;
    574  1.1  joff 	}
    575  1.1  joff 	*/
    576  1.1  joff 
    577  1.1  joff 	memset(&cmd, 0, sizeof(cmd));
    578  1.1  joff 	cmd.Cmd = CMD_STARTUP;
    579  1.1  joff 	cmd.Reserved = 0;
    580  1.1  joff 	USETW(cmd.Size, sizeof(cmd) - 4);
    581  1.1  joff 
    582  1.1  joff 	if (sc->atu_desired_channel != IEEE80211_CHAN_ANY)
    583  1.1  joff 		cmd.Channel = (u_int8_t)sc->atu_desired_channel;
    584  1.1  joff 	else
    585  1.1  joff 		cmd.Channel = sc->atu_channel;
    586  1.1  joff 	cmd.AutoRateFallback = 1;
    587  1.1  joff 	memcpy(cmd.BasicRateSet, rates, 4);
    588  1.1  joff 
    589  1.1  joff 	/* ShortRetryLimit should be 7 according to 802.11 spec */
    590  1.1  joff 	cmd.ShortRetryLimit = 7;
    591  1.1  joff 	USETW(cmd.RTS_Threshold, 2347);
    592  1.1  joff 	USETW(cmd.FragThreshold, 2346);
    593  1.1  joff 
    594  1.1  joff 	/* Doesn't seem to work, but we'll set it to 1 anyway */
    595  1.1  joff 	cmd.PromiscuousMode = 1;
    596  1.1  joff 
    597  1.1  joff 	/* this goes into the beacon we transmit */
    598  1.1  joff 	if (sc->atu_encrypt == ATU_WEP_OFF)
    599  1.1  joff 		cmd.PrivacyInvoked = 0;
    600  1.1  joff 	else
    601  1.1  joff 		cmd.PrivacyInvoked = 1;
    602  1.1  joff 
    603  1.1  joff 	cmd.ExcludeUnencrypted = 0;
    604  1.1  joff 	cmd.EncryptionType = sc->atu_wepkeylen;
    605  1.1  joff 
    606  1.1  joff 	/* Setting the SSID here doesn't seem to do anything */
    607  1.1  joff 	memset(cmd.SSID, 0, sizeof(cmd.SSID));
    608  1.1  joff 	memcpy(cmd.SSID, sc->atu_ssid, sc->atu_ssidlen);
    609  1.1  joff 	cmd.SSID_Len = sc->atu_ssidlen;
    610  1.1  joff 
    611  1.1  joff 	cmd.WEP_DefaultKeyID = sc->atu_wepkey;
    612  1.1  joff 	memcpy(cmd.WEP_DefaultKey, sc->atu_wepkeys,
    613  1.1  joff 	    sizeof(cmd.WEP_DefaultKey));
    614  1.1  joff 
    615  1.1  joff 	cmd.ShortPreamble = 1;
    616  1.1  joff 	cmd.ShortPreamble = 0;
    617  1.1  joff 	USETW(cmd.BeaconPeriod, 100);
    618  1.1  joff 	/* cmd.BeaconPeriod = 65535; */
    619  1.1  joff 
    620  1.1  joff 	/*
    621  1.1  joff 	 * TODO:
    622  1.1  joff 	 * read reg domain MIB_PHY @ 0x17 (1 byte), (reply = 0x30)
    623  1.1  joff 	 * we should do something usefull with this info. right now it's just
    624  1.1  joff 	 * ignored
    625  1.1  joff 	 */
    626  1.1  joff 	err = atu_get_mib(sc, MIB_PHY__REG_DOMAIN, &reg_domain);
    627  1.1  joff 	if (err) {
    628  1.1  joff 		DPRINTF(("%s: could not get regdomain!\n",
    629  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    630  1.1  joff 	} else {
    631  1.1  joff 		DPRINTF(("%s: in reg domain 0x%x according to the "
    632  1.1  joff 		    "adapter\n", USBDEVNAME(sc->atu_dev), reg_domain));
    633  1.1  joff 	}
    634  1.1  joff 
    635  1.1  joff #ifdef ATU_DEBUG
    636  1.1  joff 	if (atudebug) {
    637  1.1  joff 		DPRINTFN(20, ("%s: configlen=%02lx\n", USBDEVNAME(sc->atu_dev),
    638  1.2  joff 		    (unsigned long)sizeof(cmd)));
    639  1.1  joff 	}
    640  1.1  joff #endif /* ATU_DEBUG */
    641  1.1  joff 
    642  1.1  joff 	/* Windoze : driver says exclude-unencrypted=1 & encr-type=1 */
    643  1.1  joff 
    644  1.1  joff 	err = atu_send_command(sc, (u_int8_t *)&cmd, sizeof(cmd));
    645  1.1  joff 	if (err)
    646  1.1  joff 		return err;
    647  1.1  joff 	err = atu_wait_completion(sc, CMD_STARTUP, NULL);
    648  1.1  joff 	if (err)
    649  1.1  joff 		return err;
    650  1.1  joff 
    651  1.1  joff 	/* Turn on radio now */
    652  1.1  joff 	err = atu_switch_radio(sc, 1);
    653  1.1  joff 	if (err)
    654  1.1  joff 		return err;
    655  1.1  joff 
    656  1.1  joff 	/* preamble type = short */
    657  1.1  joff 	err = atu_send_mib(sc, MIB_LOCAL__PREAMBLE, NR(PREAMBLE_SHORT));
    658  1.1  joff 	if (err)
    659  1.1  joff 		return err;
    660  1.1  joff 
    661  1.1  joff 	/* frag = 1536 */
    662  1.1  joff 	err = atu_send_mib(sc, MIB_MAC__FRAG, NR(2346));
    663  1.1  joff 	if (err)
    664  1.1  joff 		return err;
    665  1.1  joff 
    666  1.1  joff 	/* rts = 1536 */
    667  1.1  joff 	err = atu_send_mib(sc, MIB_MAC__RTS, NR(2347));
    668  1.1  joff 	if (err)
    669  1.1  joff 		return err;
    670  1.1  joff 
    671  1.1  joff 	/* auto rate fallback = 1 */
    672  1.1  joff 	err = atu_send_mib(sc, MIB_LOCAL__AUTO_RATE_FALLBACK, NR(1));
    673  1.1  joff 	if (err)
    674  1.1  joff 		return err;
    675  1.1  joff 
    676  1.1  joff 	/* power mode = full on, no power saving */
    677  1.1  joff 	err = atu_send_mib(sc, MIB_MAC_MGMT__POWER_MODE,
    678  1.1  joff 	    NR(POWER_MODE_ACTIVE));
    679  1.1  joff 	if (err)
    680  1.1  joff 		return err;
    681  1.1  joff 
    682  1.1  joff 	DPRINTFN(10, ("%s: completed initial config\n",
    683  1.1  joff 	   USBDEVNAME(sc->atu_dev)));
    684  1.1  joff 	return 0;
    685  1.1  joff }
    686  1.1  joff 
    687  1.1  joff int
    688  1.1  joff atu_join(struct atu_softc *sc, struct ieee80211_node *node)
    689  1.1  joff {
    690  1.1  joff 	struct atu_cmd_join		join;
    691  1.1  joff 	u_int8_t			status;
    692  1.1  joff 	usbd_status			err;
    693  1.1  joff 
    694  1.1  joff 	memset(&join, 0, sizeof(join));
    695  1.1  joff 
    696  1.1  joff 	join.Cmd = CMD_JOIN;
    697  1.1  joff 	join.Reserved = 0x00;
    698  1.1  joff 	USETW(join.Size, sizeof(join) - 4);
    699  1.1  joff 
    700  1.1  joff 	DPRINTFN(15, ("%s: pre-join sc->atu_bssid=%s\n",
    701  1.1  joff 	    USBDEVNAME(sc->atu_dev), ether_sprintf(sc->atu_bssid)));
    702  1.1  joff 	DPRINTFN(15, ("%s: mode=%d\n", USBDEVNAME(sc->atu_dev),
    703  1.1  joff 	    sc->atu_mode));
    704  1.1  joff 	memcpy(join.bssid, node->ni_bssid, IEEE80211_ADDR_LEN);
    705  1.1  joff 	memset(join.essid, 0x00, 32);
    706  1.1  joff 	memcpy(join.essid, node->ni_essid, node->ni_esslen);
    707  1.1  joff 	join.essid_size = node->ni_esslen;
    708  1.1  joff 	if (node->ni_capinfo & IEEE80211_CAPINFO_IBSS)
    709  1.1  joff 		join.bss_type = AD_HOC_MODE;
    710  1.1  joff 	else
    711  1.1  joff 		join.bss_type = INFRASTRUCTURE_MODE;
    712  1.1  joff 	join.channel = ieee80211_chan2ieee(&sc->sc_ic, node->ni_chan);
    713  1.1  joff 
    714  1.1  joff 	USETW(join.timeout, ATU_JOIN_TIMEOUT);
    715  1.1  joff 	join.reserved = 0x00;
    716  1.1  joff 
    717  1.1  joff 	DPRINTFN(10, ("%s: trying to join BSSID=%s\n",
    718  1.1  joff 	    USBDEVNAME(sc->atu_dev), ether_sprintf(join.bssid)));
    719  1.1  joff 	err = atu_send_command(sc, (u_int8_t *)&join, sizeof(join));
    720  1.1  joff 	if (err) {
    721  1.1  joff 		DPRINTF(("%s: ERROR trying to join IBSS\n",
    722  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    723  1.1  joff 		return err;
    724  1.1  joff 	}
    725  1.1  joff 	err = atu_wait_completion(sc, CMD_JOIN, &status);
    726  1.1  joff 	if (err) {
    727  1.1  joff 		DPRINTF(("%s: error joining BSS!\n",
    728  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    729  1.1  joff 		return err;
    730  1.1  joff 	}
    731  1.1  joff 	if (status != STATUS_COMPLETE) {
    732  1.1  joff 		DPRINTF(("%s: error joining... [status=%02x]\n",
    733  1.1  joff 		    USBDEVNAME(sc->atu_dev), status));
    734  1.1  joff 		return status;
    735  1.1  joff 	} else {
    736  1.1  joff 		DPRINTFN(10, ("%s: joined BSS\n", USBDEVNAME(sc->atu_dev)));
    737  1.1  joff 	}
    738  1.1  joff 	return err;
    739  1.1  joff }
    740  1.1  joff 
    741  1.1  joff /*
    742  1.1  joff  * Get the state of the DFU unit
    743  1.1  joff  */
    744  1.1  joff int8_t
    745  1.1  joff atu_get_dfu_state(struct atu_softc *sc)
    746  1.1  joff {
    747  1.1  joff 	u_int8_t	state;
    748  1.1  joff 
    749  1.1  joff 	if (atu_usb_request(sc, DFU_GETSTATE, 0, 0, 1, &state))
    750  1.1  joff 		return -1;
    751  1.1  joff 	return state;
    752  1.1  joff }
    753  1.1  joff 
    754  1.1  joff /*
    755  1.1  joff  * Get MAC opmode
    756  1.1  joff  */
    757  1.1  joff u_int8_t
    758  1.1  joff atu_get_opmode(struct atu_softc *sc, u_int8_t *mode)
    759  1.1  joff {
    760  1.1  joff 
    761  1.1  joff 	return atu_usb_request(sc, UT_READ_VENDOR_INTERFACE, 0x33, 0x0001,
    762  1.1  joff 	    0x0000, 1, mode);
    763  1.1  joff }
    764  1.1  joff 
    765  1.1  joff /*
    766  1.1  joff  * Upload the internal firmware into the device
    767  1.1  joff  */
    768  1.1  joff void
    769  1.1  joff atu_internal_firmware(struct device *arg)
    770  1.1  joff {
    771  1.1  joff 	struct atu_softc *sc = (struct atu_softc *)arg;
    772  1.1  joff 	u_char	state, *ptr = NULL, *firm = NULL, status[6];
    773  1.1  joff 	int block_size, block = 0, err, i;
    774  1.1  joff 	size_t	bytes_left = 0;
    775  1.1  joff 
    776  1.1  joff 	/*
    777  1.1  joff 	 * Uploading firmware is done with the DFU (Device Firmware Upgrade)
    778  1.1  joff 	 * interface. See "Universal Serial Bus - Device Class Specification
    779  1.1  joff 	 * for Device Firmware Upgrade" pdf for details of the protocol.
    780  1.1  joff 	 * Maybe this could be moved to a seperate 'firmware driver' once more
    781  1.1  joff 	 * device drivers need it... For now we'll just do it here.
    782  1.1  joff 	 *
    783  1.1  joff 	 * Just for your information, the Atmel's DFU descriptor looks like
    784  1.1  joff 	 * this:
    785  1.1  joff 	 *
    786  1.1  joff 	 * 07		size
    787  1.1  joff 	 * 21		type
    788  1.1  joff 	 * 01		capabilities : only firmware download, need reset
    789  1.1  joff 	 *		  after download
    790  1.1  joff 	 * 13 05	detach timeout : max 1299ms between DFU_DETACH and
    791  1.1  joff 	 *		  reset
    792  1.1  joff 	 * 00 04	max bytes of firmware per transaction : 1024
    793  1.1  joff 	 */
    794  1.1  joff 
    795  1.1  joff 	/* Choose the right firmware for the device */
    796  1.1  joff 	for (i = 0; i < sizeof(atu_radfirm)/sizeof(atu_radfirm[0]); i++)
    797  1.1  joff 		if (sc->atu_radio == atu_radfirm[i].atur_type) {
    798  1.1  joff 			firm = atu_radfirm[i].atur_internal;
    799  1.1  joff 			bytes_left = atu_radfirm[i].atur_internal_sz;
    800  1.1  joff 		}
    801  1.1  joff 
    802  1.1  joff 	if (firm == NULL) {
    803  1.1  joff 		printf("%s: no firmware found\n", USBDEVNAME(sc->atu_dev));
    804  1.1  joff 		return;
    805  1.1  joff 	}
    806  1.1  joff 
    807  1.1  joff 	ptr = firm;
    808  1.1  joff 	state = atu_get_dfu_state(sc);
    809  1.1  joff 
    810  1.1  joff 	while (block >= 0 && state > 0) {
    811  1.1  joff 		switch (state) {
    812  1.1  joff 		case DFUState_DnLoadSync:
    813  1.1  joff 			/* get DFU status */
    814  1.1  joff 			err = atu_usb_request(sc, DFU_GETSTATUS, 0, 0 , 6,
    815  1.1  joff 			    status);
    816  1.1  joff 			if (err) {
    817  1.1  joff 				DPRINTF(("%s: dfu_getstatus failed!\n",
    818  1.1  joff 				    USBDEVNAME(sc->atu_dev)));
    819  1.1  joff 				return;
    820  1.1  joff 			}
    821  1.1  joff 			/* success means state => DnLoadIdle */
    822  1.1  joff 			state = DFUState_DnLoadIdle;
    823  1.1  joff 			continue;
    824  1.1  joff 			break;
    825  1.1  joff 
    826  1.1  joff 		case DFUState_DFUIdle:
    827  1.1  joff 		case DFUState_DnLoadIdle:
    828  1.1  joff 			if (bytes_left>=DFU_MaxBlockSize)
    829  1.1  joff 				block_size = DFU_MaxBlockSize;
    830  1.1  joff 			else
    831  1.1  joff 				block_size = bytes_left;
    832  1.1  joff 			DPRINTFN(15, ("%s: firmware block %d\n",
    833  1.1  joff 			    USBDEVNAME(sc->atu_dev), block));
    834  1.1  joff 
    835  1.1  joff 			err = atu_usb_request(sc, DFU_DNLOAD, block++, 0,
    836  1.1  joff 			    block_size, ptr);
    837  1.1  joff 			if (err) {
    838  1.1  joff 				DPRINTF(("%s: dfu_dnload failed\n",
    839  1.1  joff 				    USBDEVNAME(sc->atu_dev)));
    840  1.1  joff 				return;
    841  1.1  joff 			}
    842  1.1  joff 
    843  1.1  joff 			ptr += block_size;
    844  1.1  joff 			bytes_left -= block_size;
    845  1.1  joff 			if (block_size == 0)
    846  1.1  joff 				block = -1;
    847  1.1  joff 			break;
    848  1.1  joff 
    849  1.1  joff 		default:
    850  1.1  joff 			usbd_delay_ms(sc->atu_udev, 100);
    851  1.1  joff 			DPRINTFN(20, ("%s: sleeping for a while\n",
    852  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
    853  1.1  joff 			break;
    854  1.1  joff 		}
    855  1.1  joff 
    856  1.1  joff 		state = atu_get_dfu_state(sc);
    857  1.1  joff 	}
    858  1.1  joff 
    859  1.1  joff 	if (state != DFUState_ManifestSync) {
    860  1.1  joff 		DPRINTF(("%s: state != manifestsync... eek!\n",
    861  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    862  1.1  joff 	}
    863  1.1  joff 
    864  1.1  joff 	err = atu_usb_request(sc, DFU_GETSTATUS, 0, 0, 6, status);
    865  1.1  joff 	if (err) {
    866  1.1  joff 		DPRINTF(("%s: dfu_getstatus failed!\n",
    867  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
    868  1.1  joff 		return;
    869  1.1  joff 	}
    870  1.1  joff 
    871  1.1  joff 	DPRINTFN(15, ("%s: sending remap\n", USBDEVNAME(sc->atu_dev)));
    872  1.1  joff 	err = atu_usb_request(sc, DFU_REMAP, 0, 0, 0, NULL);
    873  1.1  joff 	if ((err) && (! sc->atu_quirk & ATU_QUIRK_NO_REMAP)) {
    874  1.1  joff 		DPRINTF(("%s: remap failed!\n", USBDEVNAME(sc->atu_dev)));
    875  1.1  joff 		return;
    876  1.1  joff 	}
    877  1.1  joff 
    878  1.1  joff 	/* after a lot of trying and measuring I found out the device needs
    879  1.1  joff 	 * about 56 miliseconds after sending the remap command before
    880  1.1  joff 	 * it's ready to communicate again. So we'll wait just a little bit
    881  1.1  joff 	 * longer than that to be sure...
    882  1.1  joff 	 */
    883  1.1  joff 	usbd_delay_ms(sc->atu_udev, 56+100);
    884  1.1  joff 
    885  1.1  joff 	printf("%s: reattaching after firmware upload\n",
    886  1.1  joff 	    USBDEVNAME(sc->atu_dev));
    887  1.1  joff 	usb_needs_reattach(sc->atu_udev);
    888  1.1  joff }
    889  1.1  joff 
    890  1.1  joff void
    891  1.1  joff atu_external_firmware(struct device *arg)
    892  1.1  joff {
    893  1.1  joff 	struct atu_softc *sc = (struct atu_softc *)arg;
    894  1.1  joff 	u_char	*ptr = NULL, *firm = NULL;
    895  1.1  joff 	int	block_size, block = 0, err, i;
    896  1.1  joff 	size_t	bytes_left = 0;
    897  1.1  joff 
    898  1.1  joff 	for (i = 0; i < sizeof(atu_radfirm)/sizeof(atu_radfirm[0]); i++)
    899  1.1  joff 		if (sc->atu_radio == atu_radfirm[i].atur_type) {
    900  1.1  joff 			firm = atu_radfirm[i].atur_external;
    901  1.1  joff 			bytes_left = atu_radfirm[i].atur_external_sz;
    902  1.1  joff 		}
    903  1.1  joff 
    904  1.1  joff 	if (firm == NULL) {
    905  1.1  joff 		printf("%s: no firmware found\n", USBDEVNAME(sc->atu_dev));
    906  1.1  joff 		return;
    907  1.1  joff 	}
    908  1.1  joff 	ptr = firm;
    909  1.1  joff 
    910  1.1  joff 	while (bytes_left) {
    911  1.1  joff 		if (bytes_left > 1024)
    912  1.1  joff 			block_size = 1024;
    913  1.1  joff 		else
    914  1.1  joff 			block_size = bytes_left;
    915  1.1  joff 
    916  1.1  joff 		DPRINTFN(15, ("%s: block:%d size:%d\n",
    917  1.1  joff 		    USBDEVNAME(sc->atu_dev), block, block_size));
    918  1.1  joff 		err = atu_usb_request(sc, UT_WRITE_VENDOR_DEVICE, 0x0e,
    919  1.1  joff 		    0x0802, block, block_size, ptr);
    920  1.1  joff 		if (err) {
    921  1.1  joff 			DPRINTF(("%s: could not load external firmware "
    922  1.1  joff 			    "block\n", USBDEVNAME(sc->atu_dev)));
    923  1.1  joff 			return;
    924  1.1  joff 		}
    925  1.1  joff 
    926  1.1  joff 		ptr += block_size;
    927  1.1  joff 		block++;
    928  1.1  joff 		bytes_left -= block_size;
    929  1.1  joff 	}
    930  1.1  joff 
    931  1.1  joff 	err = atu_usb_request(sc, UT_WRITE_VENDOR_DEVICE, 0x0e, 0x0802,
    932  1.1  joff 	    block, 0, NULL);
    933  1.1  joff 	if (err) {
    934  1.1  joff 		DPRINTF(("%s: could not load last zero-length firmware "
    935  1.1  joff 		    "block\n", USBDEVNAME(sc->atu_dev)));
    936  1.1  joff 		return;
    937  1.1  joff 	}
    938  1.1  joff 
    939  1.1  joff 	/*
    940  1.1  joff 	 * The SMC2662w V.4 seems to require some time to do it's thing with
    941  1.1  joff 	 * the external firmware... 20 ms isn't enough, but 21 ms works 100
    942  1.1  joff 	 * times out of 100 tries. We'll wait a bit longer just to be sure
    943  1.1  joff 	 */
    944  1.1  joff 	if (sc->atu_quirk & ATU_QUIRK_FW_DELAY)
    945  1.1  joff 		usbd_delay_ms(sc->atu_udev, 21 + 100);
    946  1.1  joff 
    947  1.1  joff 	DPRINTFN(10, ("%s: external firmware upload done\n",
    948  1.1  joff 	    USBDEVNAME(sc->atu_dev)));
    949  1.1  joff 	/* complete configuration after the firmwares have been uploaded */
    950  1.1  joff 	atu_complete_attach(sc);
    951  1.1  joff }
    952  1.1  joff 
    953  1.1  joff int
    954  1.1  joff atu_get_card_config(struct atu_softc *sc)
    955  1.1  joff {
    956  1.1  joff 	struct ieee80211com		*ic = &sc->sc_ic;
    957  1.1  joff 	struct atu_rfmd_conf		rfmd_conf;
    958  1.1  joff 	struct atu_intersil_conf	intersil_conf;
    959  1.1  joff 	int				err;
    960  1.1  joff 
    961  1.1  joff 	switch (sc->atu_radio) {
    962  1.1  joff 
    963  1.1  joff 	case RadioRFMD:
    964  1.1  joff 	case RadioRFMD2958:
    965  1.1  joff 	case RadioRFMD2958_SMC:
    966  1.1  joff 		err = atu_usb_request(sc, UT_READ_VENDOR_INTERFACE, 0x33,
    967  1.1  joff 		    0x0a02, 0x0000, sizeof(rfmd_conf),
    968  1.1  joff 		    (u_int8_t *)&rfmd_conf);
    969  1.1  joff 		if (err) {
    970  1.1  joff 			DPRINTF(("%s: could not get rfmd config!\n",
    971  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
    972  1.1  joff 			return err;
    973  1.1  joff 		}
    974  1.1  joff 		memcpy(ic->ic_myaddr, rfmd_conf.MACAddr, IEEE80211_ADDR_LEN);
    975  1.1  joff 		break;
    976  1.1  joff 
    977  1.1  joff 	case RadioIntersil:
    978  1.1  joff 		err = atu_usb_request(sc, UT_READ_VENDOR_INTERFACE, 0x33,
    979  1.1  joff 		    0x0902, 0x0000, sizeof(intersil_conf),
    980  1.1  joff 		    (u_int8_t *)&intersil_conf);
    981  1.1  joff 		if (err) {
    982  1.1  joff 			DPRINTF(("%s: could not get intersil config!\n",
    983  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
    984  1.1  joff 			return err;
    985  1.1  joff 		}
    986  1.1  joff 		memcpy(ic->ic_myaddr, intersil_conf.MACAddr,
    987  1.1  joff 		    IEEE80211_ADDR_LEN);
    988  1.1  joff 		break;
    989  1.1  joff 	}
    990  1.1  joff 	return 0;
    991  1.1  joff }
    992  1.1  joff 
    993  1.1  joff /*
    994  1.1  joff  * Probe for an AT76c503 chip.
    995  1.1  joff  */
    996  1.1  joff USB_MATCH(atu)
    997  1.1  joff {
    998  1.1  joff 	USB_MATCH_START(atu, uaa);
    999  1.1  joff 	int			i;
   1000  1.1  joff 
   1001  1.1  joff 	if (!uaa->iface)
   1002  1.1  joff 		return(UMATCH_NONE);
   1003  1.1  joff 
   1004  1.1  joff 	for (i = 0; i < sizeof(atu_devs)/sizeof(atu_devs[0]); i++) {
   1005  1.1  joff 		struct atu_type *t = &atu_devs[i];
   1006  1.1  joff 
   1007  1.1  joff 		if (uaa->vendor == t->atu_vid &&
   1008  1.1  joff 		    uaa->product == t->atu_pid) {
   1009  1.1  joff 			return(UMATCH_VENDOR_PRODUCT);
   1010  1.1  joff 		}
   1011  1.1  joff 	}
   1012  1.1  joff 	return(UMATCH_NONE);
   1013  1.1  joff }
   1014  1.1  joff 
   1015  1.1  joff int
   1016  1.1  joff atu_media_change(struct ifnet *ifp)
   1017  1.1  joff {
   1018  1.1  joff #ifdef ATU_DEBUG
   1019  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   1020  1.1  joff #endif /* ATU_DEBUG */
   1021  1.1  joff 	int			err;
   1022  1.1  joff 
   1023  1.1  joff 	DPRINTFN(10, ("%s: atu_media_change\n", USBDEVNAME(sc->atu_dev)));
   1024  1.1  joff 
   1025  1.1  joff 	err = ieee80211_media_change(ifp);
   1026  1.1  joff 	if (err == ENETRESET) {
   1027  1.1  joff 		if ((ifp->if_flags & (IFF_RUNNING|IFF_UP)) ==
   1028  1.1  joff 		    (IFF_RUNNING|IFF_UP))
   1029  1.1  joff 			atu_init(ifp);
   1030  1.1  joff 		err = 0;
   1031  1.1  joff 	}
   1032  1.1  joff 
   1033  1.1  joff 	return (err);
   1034  1.1  joff }
   1035  1.1  joff 
   1036  1.1  joff void
   1037  1.1  joff atu_media_status(struct ifnet *ifp, struct ifmediareq *req)
   1038  1.1  joff {
   1039  1.1  joff #ifdef ATU_DEBUG
   1040  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   1041  1.1  joff #endif /* ATU_DEBUG */
   1042  1.1  joff 
   1043  1.1  joff 	DPRINTFN(10, ("%s: atu_media_status\n", USBDEVNAME(sc->atu_dev)));
   1044  1.1  joff 
   1045  1.1  joff 	ieee80211_media_status(ifp, req);
   1046  1.1  joff }
   1047  1.1  joff 
   1048  1.1  joff void
   1049  1.1  joff atu_task(void *arg)
   1050  1.1  joff {
   1051  1.1  joff 	struct atu_softc	*sc = (struct atu_softc *)arg;
   1052  1.1  joff 	struct ieee80211com	*ic = &sc->sc_ic;
   1053  1.1  joff 	usbd_status		err;
   1054  1.1  joff 	int			s;
   1055  1.1  joff 
   1056  1.1  joff 	DPRINTFN(10, ("%s: atu_task\n", USBDEVNAME(sc->atu_dev)));
   1057  1.1  joff 
   1058  1.1  joff 	if (sc->sc_state != ATU_S_OK)
   1059  1.1  joff 		return;
   1060  1.1  joff 
   1061  1.1  joff 	switch (sc->sc_cmd) {
   1062  1.1  joff 	case ATU_C_SCAN:
   1063  1.1  joff 
   1064  1.1  joff 		err = atu_start_scan(sc);
   1065  1.1  joff 		if (err) {
   1066  1.1  joff 			DPRINTFN(1, ("%s: atu_init: couldn't start scan!\n",
   1067  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1068  1.1  joff 			return;
   1069  1.1  joff 		}
   1070  1.1  joff 
   1071  1.1  joff 		err = atu_wait_completion(sc, CMD_START_SCAN, NULL);
   1072  1.1  joff 		if (err) {
   1073  1.1  joff 			DPRINTF(("%s: atu_init: error waiting for scan\n",
   1074  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1075  1.1  joff 			return;
   1076  1.1  joff 		}
   1077  1.1  joff 
   1078  1.1  joff 		DPRINTF(("%s: ==========================> END OF SCAN!\n",
   1079  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1080  1.1  joff 
   1081  1.1  joff 		s = splnet();
   1082  1.1  joff 		/* ieee80211_next_scan(ifp); */
   1083  1.1  joff 		ieee80211_end_scan(ic);
   1084  1.1  joff 		splx(s);
   1085  1.1  joff 
   1086  1.1  joff 		DPRINTF(("%s: ----------------------======> END OF SCAN2!\n",
   1087  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1088  1.1  joff 		break;
   1089  1.1  joff 
   1090  1.1  joff 	case ATU_C_JOIN:
   1091  1.1  joff 		atu_join(sc, ic->ic_bss);
   1092  1.1  joff 	}
   1093  1.1  joff }
   1094  1.1  joff 
   1095  1.1  joff int
   1096  1.1  joff atu_newstate(struct ieee80211com *ic, enum ieee80211_state nstate, int arg)
   1097  1.1  joff {
   1098  1.1  joff 	struct ifnet		*ifp = &ic->ic_if;
   1099  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   1100  1.1  joff 	enum ieee80211_state	ostate = ic->ic_state;
   1101  1.1  joff 
   1102  1.1  joff 	DPRINTFN(10, ("%s: atu_newstate: %s -> %s\n", USBDEVNAME(sc->atu_dev),
   1103  1.1  joff 	    ieee80211_state_name[ostate], ieee80211_state_name[nstate]));
   1104  1.1  joff 
   1105  1.1  joff 	switch (nstate) {
   1106  1.1  joff 	case IEEE80211_S_SCAN:
   1107  1.1  joff 		memcpy(ic->ic_chan_scan, ic->ic_chan_active,
   1108  1.1  joff 		    sizeof(ic->ic_chan_active));
   1109  1.1  joff 		ieee80211_free_allnodes(ic);
   1110  1.1  joff 
   1111  1.1  joff 		/* tell the event thread that we want a scan */
   1112  1.1  joff 		sc->sc_cmd = ATU_C_SCAN;
   1113  1.1  joff 		usb_add_task(sc->atu_udev, &sc->sc_task);
   1114  1.1  joff 
   1115  1.1  joff 		/* handle this ourselves */
   1116  1.1  joff 		ic->ic_state = nstate;
   1117  1.1  joff 		return (0);
   1118  1.1  joff 
   1119  1.1  joff 	case IEEE80211_S_AUTH:
   1120  1.1  joff 	case IEEE80211_S_RUN:
   1121  1.1  joff 		if (ostate == IEEE80211_S_SCAN) {
   1122  1.1  joff 			sc->sc_cmd = ATU_C_JOIN;
   1123  1.1  joff 			usb_add_task(sc->atu_udev, &sc->sc_task);
   1124  1.1  joff 		}
   1125  1.1  joff 		break;
   1126  1.1  joff 	default:
   1127  1.1  joff 		/* nothing to do */
   1128  1.1  joff 		break;
   1129  1.1  joff 	}
   1130  1.1  joff 
   1131  1.1  joff 	return (*sc->sc_newstate)(ic, nstate, arg);
   1132  1.1  joff }
   1133  1.1  joff 
   1134  1.1  joff /*
   1135  1.1  joff  * Attach the interface. Allocate softc structures, do
   1136  1.1  joff  * setup and ethernet/BPF attach.
   1137  1.1  joff  */
   1138  1.1  joff USB_ATTACH(atu)
   1139  1.1  joff {
   1140  1.1  joff 	USB_ATTACH_START(atu, sc, uaa);
   1141  1.1  joff 	char				devinfo[1024];
   1142  1.1  joff 	usbd_status			err;
   1143  1.1  joff 	usbd_device_handle		dev = uaa->device;
   1144  1.1  joff 	u_int8_t			mode, channel;
   1145  1.1  joff 	int i;
   1146  1.1  joff 
   1147  1.1  joff 	sc->sc_state = ATU_S_UNCONFIG;
   1148  1.1  joff 
   1149  1.1  joff 	usbd_devinfo(uaa->device, 0, devinfo, sizeof devinfo);
   1150  1.1  joff 	USB_ATTACH_SETUP;
   1151  1.1  joff 	printf("%s: %s\n", USBDEVNAME(sc->atu_dev), devinfo);
   1152  1.1  joff 
   1153  1.1  joff 	err = usbd_set_config_no(dev, ATU_CONFIG_NO, 1);
   1154  1.1  joff 	if (err) {
   1155  1.1  joff 		printf("%s: setting config no failed\n",
   1156  1.1  joff 		    USBDEVNAME(sc->atu_dev));
   1157  1.1  joff 		USB_ATTACH_ERROR_RETURN;
   1158  1.1  joff 	}
   1159  1.1  joff 
   1160  1.1  joff 	err = usbd_device2interface_handle(dev, ATU_IFACE_IDX, &sc->atu_iface);
   1161  1.1  joff 	if (err) {
   1162  1.1  joff 		printf("%s: getting interface handle failed\n",
   1163  1.1  joff 		    USBDEVNAME(sc->atu_dev));
   1164  1.1  joff 		USB_ATTACH_ERROR_RETURN;
   1165  1.1  joff 	}
   1166  1.1  joff 
   1167  1.1  joff 	sc->atu_unit = self->dv_unit;
   1168  1.1  joff 	sc->atu_udev = dev;
   1169  1.1  joff 
   1170  1.1  joff 	/*
   1171  1.1  joff 	 * look up the radio_type for the device
   1172  1.1  joff 	 * basically does the same as USB_MATCH
   1173  1.1  joff 	 */
   1174  1.1  joff 	for (i = 0; i < sizeof(atu_devs)/sizeof(atu_devs[0]); i++) {
   1175  1.1  joff 		struct atu_type *t = &atu_devs[i];
   1176  1.1  joff 
   1177  1.1  joff 		if (uaa->vendor == t->atu_vid &&
   1178  1.1  joff 		    uaa->product == t->atu_pid) {
   1179  1.1  joff 			sc->atu_radio = t->atu_radio;
   1180  1.1  joff 			sc->atu_quirk = t->atu_quirk;
   1181  1.1  joff 		}
   1182  1.1  joff 	}
   1183  1.1  joff 
   1184  1.1  joff 	/*
   1185  1.1  joff 	 * Check in the interface descriptor if we're in DFU mode
   1186  1.1  joff 	 * If we're in DFU mode, we upload the external firmware
   1187  1.1  joff 	 * If we're not, the PC must have rebooted without power-cycling
   1188  1.1  joff 	 * the device.. I've tried this out, a reboot only requeres the
   1189  1.1  joff 	 * external firmware to be reloaded :)
   1190  1.1  joff 	 *
   1191  1.1  joff 	 * Hmm. The at76c505a doesn't report a DFU descriptor when it's
   1192  1.1  joff 	 * in DFU mode... Let's just try to get the opmode
   1193  1.1  joff 	 */
   1194  1.1  joff 	err = atu_get_opmode(sc, &mode);
   1195  1.1  joff 	DPRINTFN(20, ("%s: opmode: %d\n", USBDEVNAME(sc->atu_dev), mode));
   1196  1.1  joff 	if (err || (mode != MODE_NETCARD && mode != MODE_NOFLASHNETCARD)) {
   1197  1.1  joff 		DPRINTF(("%s: starting internal firmware download\n",
   1198  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1199  1.1  joff 
   1200  1.1  joff 		atu_internal_firmware((struct device *)sc);
   1201  1.1  joff 		/*
   1202  1.1  joff 		 * atu_internal_firmware will cause a reset of the device
   1203  1.1  joff 		 * so we don't want to do any more configuration after this
   1204  1.1  joff 		 * point.
   1205  1.1  joff 		 */
   1206  1.1  joff 		USB_ATTACH_SUCCESS_RETURN;
   1207  1.1  joff 	}
   1208  1.1  joff 
   1209  1.1  joff 	uaa->iface = sc->atu_iface;
   1210  1.1  joff 
   1211  1.1  joff 	if (mode != MODE_NETCARD) {
   1212  1.1  joff 		DPRINTFN(15, ("%s: device needs external firmware\n",
   1213  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1214  1.1  joff 
   1215  1.1  joff 		if (mode != MODE_NOFLASHNETCARD) {
   1216  1.1  joff 			DPRINTF(("%s: unexpected opmode=%d\n",
   1217  1.1  joff 			    USBDEVNAME(sc->atu_dev), mode));
   1218  1.1  joff 		}
   1219  1.1  joff 
   1220  1.1  joff 		/*
   1221  1.1  joff 		 * There is no difference in opmode before and after external
   1222  1.1  joff 		 * firmware upload with the SMC2662 V.4 . So instead we'll try
   1223  1.1  joff 		 * to read the channel number. If we succeed, external
   1224  1.1  joff 		 * firmwaremust have been already uploaded...
   1225  1.1  joff 		 */
   1226  1.1  joff 		if (sc->atu_radio != RadioIntersil) {
   1227  1.1  joff 			err = atu_get_mib(sc, MIB_PHY__CHANNEL, &channel);
   1228  1.1  joff 			if (!err) {
   1229  1.1  joff 				DPRINTF(("%s: external firmware has already"
   1230  1.1  joff 				    " been downloaded\n",
   1231  1.1  joff 				    USBDEVNAME(sc->atu_dev)));
   1232  1.1  joff 				atu_complete_attach(sc);
   1233  1.1  joff 				USB_ATTACH_SUCCESS_RETURN;
   1234  1.1  joff 			}
   1235  1.1  joff 		}
   1236  1.1  joff 
   1237  1.1  joff 		atu_external_firmware((struct device *)sc);
   1238  1.1  joff 
   1239  1.1  joff 		/*
   1240  1.1  joff 		 * atu_external_firmware will call atu_complete_attach after
   1241  1.1  joff 		 * it's finished so we can just return.
   1242  1.1  joff 		 */
   1243  1.1  joff 	} else {
   1244  1.1  joff 		/* all the firmwares are in place, so complete the attach */
   1245  1.1  joff 		atu_complete_attach(sc);
   1246  1.1  joff 	}
   1247  1.1  joff 
   1248  1.1  joff 	USB_ATTACH_SUCCESS_RETURN;
   1249  1.1  joff }
   1250  1.1  joff 
   1251  1.1  joff void
   1252  1.1  joff atu_complete_attach(struct atu_softc *sc)
   1253  1.1  joff {
   1254  1.1  joff 	struct ieee80211com		*ic = &sc->sc_ic;
   1255  1.1  joff 	struct ifnet			*ifp = &ic->ic_if;
   1256  1.1  joff 	usb_interface_descriptor_t	*id;
   1257  1.1  joff 	usb_endpoint_descriptor_t	*ed;
   1258  1.1  joff 	usbd_status			err;
   1259  1.1  joff 	int				i;
   1260  1.1  joff #ifdef ATU_DEBUG
   1261  1.1  joff 	struct atu_fw			fw;
   1262  1.1  joff #endif
   1263  1.1  joff 
   1264  1.1  joff 	id = usbd_get_interface_descriptor(sc->atu_iface);
   1265  1.1  joff 
   1266  1.1  joff 	/* Find endpoints. */
   1267  1.1  joff 	for (i = 0; i < id->bNumEndpoints; i++) {
   1268  1.1  joff 		ed = usbd_interface2endpoint_descriptor(sc->atu_iface, i);
   1269  1.1  joff 		if (!ed) {
   1270  1.1  joff 			DPRINTF(("%s: num_endp:%d\n", USBDEVNAME(sc->atu_dev),
   1271  1.1  joff 			    sc->atu_iface->idesc->bNumEndpoints));
   1272  1.1  joff 			DPRINTF(("%s: couldn't get ep %d\n",
   1273  1.1  joff 			    USBDEVNAME(sc->atu_dev), i));
   1274  1.1  joff 			return;
   1275  1.1  joff 		}
   1276  1.1  joff 		if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN &&
   1277  1.1  joff 		    UE_GET_XFERTYPE(ed->bmAttributes) == UE_BULK) {
   1278  1.1  joff 			sc->atu_ed[ATU_ENDPT_RX] = ed->bEndpointAddress;
   1279  1.1  joff 		} else if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_OUT &&
   1280  1.1  joff 			   UE_GET_XFERTYPE(ed->bmAttributes) == UE_BULK) {
   1281  1.1  joff 			sc->atu_ed[ATU_ENDPT_TX] = ed->bEndpointAddress;
   1282  1.1  joff 		}
   1283  1.1  joff 	}
   1284  1.1  joff 
   1285  1.1  joff 	/* read device config & get MAC address */
   1286  1.1  joff 	err = atu_get_card_config(sc);
   1287  1.1  joff 	if (err) {
   1288  1.1  joff 		printf("\n%s: could not get card cfg!\n",
   1289  1.1  joff 		    USBDEVNAME(sc->atu_dev));
   1290  1.1  joff 		return;
   1291  1.1  joff 	}
   1292  1.1  joff 
   1293  1.1  joff #ifdef ATU_DEBUG
   1294  1.1  joff 	/* DEBUG : try to get firmware version */
   1295  1.1  joff 	err = atu_get_mib(sc, MIB_FW_VERSION, sizeof(fw), 0,
   1296  1.1  joff 	    (u_int8_t *)&fw);
   1297  1.1  joff 	if (!err) {
   1298  1.1  joff 		DPRINTFN(15, ("%s: firmware: maj:%d min:%d patch:%d "
   1299  1.1  joff 		    "build:%d\n", USBDEVNAME(sc->atu_dev), fw.major, fw.minor,
   1300  1.1  joff 		    fw.patch, fw.build));
   1301  1.1  joff 	} else {
   1302  1.1  joff 		DPRINTF(("%s: get firmware version failed\n",
   1303  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1304  1.1  joff 	}
   1305  1.1  joff #endif /* ATU_DEBUG */
   1306  1.1  joff 
   1307  1.1  joff 	/* Show the world our MAC address */
   1308  1.1  joff 	printf("%s: MAC address %s\n", USBDEVNAME(sc->atu_dev),
   1309  1.1  joff 	    ether_sprintf(ic->ic_myaddr));
   1310  1.1  joff 
   1311  1.1  joff 	sc->atu_cdata.atu_tx_inuse = 0;
   1312  1.1  joff 	sc->atu_encrypt = ATU_WEP_OFF;
   1313  1.1  joff 	sc->atu_wepkeylen = ATU_WEP_104BITS;
   1314  1.1  joff 	sc->atu_wepkey = 0;
   1315  1.1  joff 
   1316  1.1  joff 	bzero(sc->atu_bssid, ETHER_ADDR_LEN);
   1317  1.1  joff 	sc->atu_ssidlen = strlen(ATU_DEFAULT_SSID);
   1318  1.1  joff 	memcpy(sc->atu_ssid, ATU_DEFAULT_SSID, sc->atu_ssidlen);
   1319  1.1  joff 	sc->atu_channel = ATU_DEFAULT_CHANNEL;
   1320  1.1  joff 	sc->atu_desired_channel = IEEE80211_CHAN_ANY;
   1321  1.1  joff 	sc->atu_mode = INFRASTRUCTURE_MODE;
   1322  1.1  joff 	sc->atu_encrypt = ATU_WEP_OFF;
   1323  1.1  joff 
   1324  1.1  joff 	ic->ic_softc = sc;
   1325  1.1  joff 	ic->ic_phytype = IEEE80211_T_DS;
   1326  1.1  joff 	ic->ic_opmode = IEEE80211_M_STA;
   1327  1.1  joff 	ic->ic_state = IEEE80211_S_INIT;
   1328  1.1  joff #ifdef FIXME
   1329  1.1  joff 	ic->ic_caps = IEEE80211_C_IBSS | IEEE80211_C_WEP | IEEE80211_C_SCANALL;
   1330  1.1  joff #else
   1331  1.1  joff 	ic->ic_caps = IEEE80211_C_IBSS | IEEE80211_C_WEP;
   1332  1.1  joff #endif
   1333  1.1  joff 
   1334  1.1  joff 	i = 0;
   1335  1.1  joff 	ic->ic_sup_rates[IEEE80211_MODE_11B].rs_rates[i++] = 2;
   1336  1.1  joff 	ic->ic_sup_rates[IEEE80211_MODE_11B].rs_rates[i++] = 4;
   1337  1.1  joff 	ic->ic_sup_rates[IEEE80211_MODE_11B].rs_rates[i++] = 11;
   1338  1.1  joff 	ic->ic_sup_rates[IEEE80211_MODE_11B].rs_rates[i++] = 22;
   1339  1.1  joff 	ic->ic_sup_rates[IEEE80211_MODE_11B].rs_nrates = i;
   1340  1.1  joff 
   1341  1.1  joff 	for (i = 1; i <= 14; i++) {
   1342  1.1  joff 		ic->ic_channels[i].ic_flags = IEEE80211_CHAN_B |
   1343  1.1  joff 		    IEEE80211_CHAN_PASSIVE;
   1344  1.1  joff 		ic->ic_channels[i].ic_freq = ieee80211_ieee2mhz(i,
   1345  1.1  joff 		    ic->ic_channels[i].ic_flags);
   1346  1.1  joff 	}
   1347  1.1  joff 
   1348  1.1  joff 	ic->ic_ibss_chan = &ic->ic_channels[0];
   1349  1.1  joff 
   1350  1.1  joff 	ifp->if_softc = sc;
   1351  1.1  joff 	memcpy(ifp->if_xname, USBDEVNAME(sc->atu_dev), IFNAMSIZ);
   1352  1.1  joff 	ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
   1353  1.1  joff 	ifp->if_init = atu_init;
   1354  1.1  joff 	ifp->if_stop = atu_stop;
   1355  1.1  joff 	ifp->if_start = atu_start;
   1356  1.1  joff 	ifp->if_ioctl = atu_ioctl;
   1357  1.1  joff 	ifp->if_watchdog = atu_watchdog;
   1358  1.1  joff 	ifp->if_mtu = ATU_DEFAULT_MTU;
   1359  1.1  joff 	IFQ_SET_READY(&ifp->if_snd);
   1360  1.1  joff 
   1361  1.1  joff 	/* Call MI attach routine. */
   1362  1.1  joff 	if_attach(ifp);
   1363  1.1  joff 	ieee80211_ifattach(ifp);
   1364  1.1  joff 
   1365  1.1  joff 	sc->sc_newstate = ic->ic_newstate;
   1366  1.1  joff 	ic->ic_newstate = atu_newstate;
   1367  1.1  joff 
   1368  1.1  joff 	/* setup ifmedia interface */
   1369  1.1  joff 	ieee80211_media_init(ifp, atu_media_change, atu_media_status);
   1370  1.1  joff 
   1371  1.1  joff 	usb_init_task(&sc->sc_task, atu_task, sc);
   1372  1.1  joff 
   1373  1.1  joff 	sc->sc_state = ATU_S_OK;
   1374  1.1  joff }
   1375  1.1  joff 
   1376  1.1  joff USB_DETACH(atu)
   1377  1.1  joff {
   1378  1.1  joff 	USB_DETACH_START(atu, sc);
   1379  1.1  joff 	struct ifnet		*ifp = &sc->sc_ic.ic_if;
   1380  1.1  joff 
   1381  1.1  joff 	DPRINTFN(10, ("%s: atu_detach state=%d\n", USBDEVNAME(sc->atu_dev),
   1382  1.1  joff 	    sc->sc_state));
   1383  1.1  joff 
   1384  1.1  joff 	if (sc->sc_state != ATU_S_UNCONFIG) {
   1385  1.1  joff 		atu_stop(ifp, 1);
   1386  1.1  joff 
   1387  1.1  joff 		ieee80211_ifdetach(ifp);
   1388  1.1  joff 		if_detach(ifp);
   1389  1.1  joff 
   1390  1.1  joff 		if (sc->atu_ep[ATU_ENDPT_TX] != NULL)
   1391  1.1  joff 			usbd_abort_pipe(sc->atu_ep[ATU_ENDPT_TX]);
   1392  1.1  joff 		if (sc->atu_ep[ATU_ENDPT_RX] != NULL)
   1393  1.1  joff 			usbd_abort_pipe(sc->atu_ep[ATU_ENDPT_RX]);
   1394  1.1  joff 
   1395  1.1  joff 		usb_rem_task(sc->atu_udev, &sc->sc_task);
   1396  1.1  joff 	}
   1397  1.1  joff 
   1398  1.1  joff 	return(0);
   1399  1.1  joff }
   1400  1.1  joff 
   1401  1.1  joff int
   1402  1.1  joff atu_activate(device_ptr_t self, enum devact act)
   1403  1.1  joff {
   1404  1.1  joff 	struct atu_softc *sc = (struct atu_softc *)self;
   1405  1.1  joff 
   1406  1.1  joff 	switch (act) {
   1407  1.1  joff 	case DVACT_ACTIVATE:
   1408  1.1  joff 		return (EOPNOTSUPP);
   1409  1.1  joff 		break;
   1410  1.1  joff 	case DVACT_DEACTIVATE:
   1411  1.1  joff 		if (sc->sc_state != ATU_S_UNCONFIG) {
   1412  1.1  joff 			if_deactivate(&sc->atu_ec.ec_if);
   1413  1.1  joff 			sc->sc_state = ATU_S_DEAD;
   1414  1.1  joff 		}
   1415  1.1  joff 		break;
   1416  1.1  joff 	}
   1417  1.1  joff 	return (0);
   1418  1.1  joff }
   1419  1.1  joff 
   1420  1.1  joff /*
   1421  1.1  joff  * Initialize an RX descriptor and attach an MBUF cluster.
   1422  1.1  joff  */
   1423  1.1  joff int
   1424  1.1  joff atu_newbuf(struct atu_softc *sc, struct atu_chain *c, struct mbuf *m)
   1425  1.1  joff {
   1426  1.1  joff 	struct mbuf		*m_new = NULL;
   1427  1.1  joff 
   1428  1.1  joff 	if (m == NULL) {
   1429  1.1  joff 		MGETHDR(m_new, M_DONTWAIT, MT_DATA);
   1430  1.1  joff 		if (m_new == NULL) {
   1431  1.1  joff 			DPRINTF(("%s: no memory for rx list\n",
   1432  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1433  1.1  joff 			return(ENOBUFS);
   1434  1.1  joff 		}
   1435  1.1  joff 
   1436  1.1  joff 		MCLGET(m_new, M_DONTWAIT);
   1437  1.1  joff 		if (!(m_new->m_flags & M_EXT)) {
   1438  1.1  joff 			DPRINTF(("%s: no memory for rx list\n",
   1439  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1440  1.1  joff 			m_freem(m_new);
   1441  1.1  joff 			return(ENOBUFS);
   1442  1.1  joff 		}
   1443  1.1  joff 		m_new->m_len = m_new->m_pkthdr.len = MCLBYTES;
   1444  1.1  joff 	} else {
   1445  1.1  joff 		m_new = m;
   1446  1.1  joff 		m_new->m_len = m_new->m_pkthdr.len = MCLBYTES;
   1447  1.1  joff 		m_new->m_data = m_new->m_ext.ext_buf;
   1448  1.1  joff 	}
   1449  1.1  joff 	c->atu_mbuf = m_new;
   1450  1.1  joff 	return(0);
   1451  1.1  joff }
   1452  1.1  joff 
   1453  1.1  joff int
   1454  1.1  joff atu_rx_list_init(struct atu_softc *sc)
   1455  1.1  joff {
   1456  1.1  joff 	struct atu_cdata	*cd = &sc->atu_cdata;
   1457  1.1  joff 	struct atu_chain	*c;
   1458  1.1  joff 	int			i;
   1459  1.1  joff 
   1460  1.1  joff 	DPRINTFN(15, ("%s: atu_rx_list_init: enter\n",
   1461  1.1  joff 	    USBDEVNAME(sc->atu_dev)));
   1462  1.1  joff 
   1463  1.1  joff 	for (i = 0; i < ATU_RX_LIST_CNT; i++) {
   1464  1.1  joff 		c = &cd->atu_rx_chain[i];
   1465  1.1  joff 		c->atu_sc = sc;
   1466  1.1  joff 		c->atu_idx = i;
   1467  1.1  joff 		if (c->atu_xfer == NULL) {
   1468  1.1  joff 			c->atu_xfer = usbd_alloc_xfer(sc->atu_udev);
   1469  1.1  joff 			if (c->atu_xfer == NULL)
   1470  1.1  joff 				return (ENOBUFS);
   1471  1.1  joff 			c->atu_buf = usbd_alloc_buffer(c->atu_xfer,
   1472  1.1  joff 			    ATU_RX_BUFSZ);
   1473  1.1  joff 			if (c->atu_buf == NULL) /* XXX free xfer */
   1474  1.1  joff 				return (ENOBUFS);
   1475  1.1  joff 			if (atu_newbuf(sc, c, NULL) == ENOBUFS) /* XXX free? */
   1476  1.1  joff 				return(ENOBUFS);
   1477  1.1  joff 		}
   1478  1.1  joff 	}
   1479  1.1  joff 	return (0);
   1480  1.1  joff }
   1481  1.1  joff 
   1482  1.1  joff int
   1483  1.1  joff atu_tx_list_init(struct atu_softc *sc)
   1484  1.1  joff {
   1485  1.1  joff 	struct atu_cdata	*cd = &sc->atu_cdata;
   1486  1.1  joff 	struct atu_chain	*c;
   1487  1.1  joff 	int			i;
   1488  1.1  joff 
   1489  1.1  joff 	DPRINTFN(15, ("%s: atu_tx_list_init\n",
   1490  1.1  joff 	    USBDEVNAME(sc->atu_dev)));
   1491  1.1  joff 
   1492  1.1  joff 	SLIST_INIT(&cd->atu_tx_free);
   1493  1.1  joff 	sc->atu_cdata.atu_tx_inuse = 0;
   1494  1.1  joff 
   1495  1.1  joff 	for (i = 0; i < ATU_TX_LIST_CNT; i++) {
   1496  1.1  joff 		c = &cd->atu_tx_chain[i];
   1497  1.1  joff 		c->atu_sc = sc;
   1498  1.1  joff 		c->atu_idx = i;
   1499  1.1  joff 		if (c->atu_xfer == NULL) {
   1500  1.1  joff 			c->atu_xfer = usbd_alloc_xfer(sc->atu_udev);
   1501  1.1  joff 			if (c->atu_xfer == NULL)
   1502  1.1  joff 				return(ENOBUFS);
   1503  1.1  joff 			c->atu_mbuf = NULL;
   1504  1.1  joff 			c->atu_buf = usbd_alloc_buffer(c->atu_xfer,
   1505  1.1  joff 			    ATU_TX_BUFSZ);
   1506  1.1  joff 			if (c->atu_buf == NULL)
   1507  1.1  joff 				return(ENOBUFS); /* XXX free xfer */
   1508  1.1  joff 			SLIST_INSERT_HEAD(&cd->atu_tx_free, c, atu_list);
   1509  1.1  joff 		}
   1510  1.1  joff 	}
   1511  1.1  joff 	return(0);
   1512  1.1  joff }
   1513  1.1  joff 
   1514  1.1  joff void
   1515  1.1  joff atu_xfer_list_free(struct atu_softc *sc, struct atu_chain *ch,
   1516  1.1  joff     int listlen)
   1517  1.1  joff {
   1518  1.1  joff 	int			i;
   1519  1.1  joff 
   1520  1.1  joff 	/* Free resources. */
   1521  1.1  joff 	for (i = 0; i < listlen; i++) {
   1522  1.1  joff 		if (ch[i].atu_buf != NULL)
   1523  1.1  joff 			ch[i].atu_buf = NULL;
   1524  1.1  joff 		if (ch[i].atu_mbuf != NULL) {
   1525  1.1  joff 			m_freem(ch[i].atu_mbuf);
   1526  1.1  joff 			ch[i].atu_mbuf = NULL;
   1527  1.1  joff 		}
   1528  1.1  joff 		if (ch[i].atu_xfer != NULL) {
   1529  1.1  joff 			usbd_free_xfer(ch[i].atu_xfer);
   1530  1.1  joff 			ch[i].atu_xfer = NULL;
   1531  1.1  joff 		}
   1532  1.1  joff 	}
   1533  1.1  joff }
   1534  1.1  joff 
   1535  1.1  joff /*
   1536  1.1  joff  * A frame has been uploaded: pass the resulting mbuf chain up to
   1537  1.1  joff  * the higher level protocols.
   1538  1.1  joff  */
   1539  1.1  joff void
   1540  1.1  joff atu_rxeof(usbd_xfer_handle xfer, usbd_private_handle priv, usbd_status status)
   1541  1.1  joff {
   1542  1.1  joff 	struct atu_chain	*c = (struct atu_chain *)priv;
   1543  1.1  joff 	struct atu_softc	*sc = c->atu_sc;
   1544  1.1  joff 	struct ieee80211com	*ic = &sc->sc_ic;
   1545  1.1  joff 	struct ifnet		*ifp = &ic->ic_if;
   1546  1.1  joff 	struct atu_rx_hdr	*h;
   1547  1.1  joff 	struct ieee80211_frame	*wh;
   1548  1.1  joff 	struct ieee80211_node	*ni;
   1549  1.1  joff 	struct mbuf		*m;
   1550  1.1  joff 	u_int32_t		len;
   1551  1.1  joff 	int			s;
   1552  1.1  joff 
   1553  1.1  joff 	DPRINTFN(25, ("%s: atu_rxeof\n", USBDEVNAME(sc->atu_dev)));
   1554  1.1  joff 
   1555  1.1  joff 	if (sc->sc_state != ATU_S_OK)
   1556  1.1  joff 		return;
   1557  1.1  joff 
   1558  1.1  joff 	if ((ifp->if_flags & (IFF_RUNNING|IFF_UP)) != (IFF_RUNNING|IFF_UP))
   1559  1.1  joff 		goto done;
   1560  1.1  joff 
   1561  1.1  joff 	if (status != USBD_NORMAL_COMPLETION) {
   1562  1.1  joff 		DPRINTF(("%s: status != USBD_NORMAL_COMPLETION\n",
   1563  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1564  1.1  joff 		if (status == USBD_NOT_STARTED || status == USBD_CANCELLED) {
   1565  1.1  joff 			return;
   1566  1.1  joff 		}
   1567  1.1  joff #if 0
   1568  1.1  joff 		if (status == USBD_IOERROR) {
   1569  1.1  joff 			DPRINTF(("%s: rx: EEK! lost device?\n",
   1570  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1571  1.1  joff 
   1572  1.1  joff 			/*
   1573  1.1  joff 			 * My experience with USBD_IOERROR is that trying to
   1574  1.1  joff 			 * restart the transfer will always fail and we'll
   1575  1.1  joff 			 * keep on looping restarting transfers untill someone
   1576  1.1  joff 			 * pulls the plug of the device.
   1577  1.1  joff 			 * So we don't restart the transfer, but just let it
   1578  1.1  joff 			 * die... If someone knows of a situation where we can
   1579  1.1  joff 			 * recover from USBD_IOERROR, let me know.
   1580  1.1  joff 			 */
   1581  1.1  joff 			splx(s);
   1582  1.1  joff 			return;
   1583  1.1  joff 		}
   1584  1.1  joff #endif /* 0 */
   1585  1.1  joff 
   1586  1.1  joff 		if (usbd_ratecheck(&sc->atu_rx_notice)) {
   1587  1.1  joff 			DPRINTF(("%s: usb error on rx: %s\n",
   1588  1.1  joff 			    USBDEVNAME(sc->atu_dev), usbd_errstr(status)));
   1589  1.1  joff 		}
   1590  1.1  joff 		if (status == USBD_STALLED)
   1591  1.1  joff 			usbd_clear_endpoint_stall(
   1592  1.1  joff 			    sc->atu_ep[ATU_ENDPT_RX]);
   1593  1.1  joff 		goto done;
   1594  1.1  joff 	}
   1595  1.1  joff 
   1596  1.1  joff 	usbd_get_xfer_status(xfer, NULL, NULL, &len, NULL);
   1597  1.1  joff 
   1598  1.1  joff 	if (len <= 1) {
   1599  1.1  joff 		DPRINTF(("%s: atu_rxeof: too short\n",
   1600  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1601  1.1  joff 		goto done;
   1602  1.1  joff 	}
   1603  1.1  joff 
   1604  1.1  joff 	h = (struct atu_rx_hdr *)c->atu_buf;
   1605  1.1  joff 	len = UGETW(h->length) - 4; /* XXX magic number */
   1606  1.1  joff 
   1607  1.1  joff 	m = c->atu_mbuf;
   1608  1.1  joff 	memcpy(mtod(m, char *), c->atu_buf + ATU_RX_HDRLEN, len);
   1609  1.1  joff 	m->m_pkthdr.rcvif = ifp;
   1610  1.1  joff 	m->m_pkthdr.len = m->m_len = len;
   1611  1.1  joff 
   1612  1.1  joff 	wh = mtod(m, struct ieee80211_frame *);
   1613  1.1  joff 	ni = ieee80211_find_rxnode(ic, wh);
   1614  1.1  joff 
   1615  1.1  joff 	ifp->if_ipackets++;
   1616  1.1  joff 
   1617  1.1  joff 	s = splnet();
   1618  1.1  joff 
   1619  1.1  joff 	if (atu_newbuf(sc, c, NULL) == ENOBUFS) {
   1620  1.1  joff 		ifp->if_ierrors++;
   1621  1.1  joff 		goto done1; /* XXX if we can't allocate, why restart it? */
   1622  1.1  joff 	}
   1623  1.1  joff 
   1624  1.1  joff #if NBPFILTER > 0
   1625  1.1  joff 	if (ifp->if_bpf)
   1626  1.1  joff 		bpf_mtap(ifp->if_bpf, m);
   1627  1.1  joff #endif
   1628  1.1  joff 
   1629  1.1  joff 	ieee80211_input(ifp, m, ni, h->rssi, UGETDW(h->rx_time));
   1630  1.1  joff 
   1631  1.1  joff 	if (ni == ic->ic_bss)
   1632  1.1  joff 		ieee80211_unref_node(&ni);
   1633  1.1  joff 	else
   1634  1.1  joff 		ieee80211_release_node(ic, ni);
   1635  1.1  joff done1:
   1636  1.1  joff 	splx(s);
   1637  1.1  joff done:
   1638  1.1  joff 	/* Setup new transfer. */
   1639  1.1  joff 	usbd_setup_xfer(c->atu_xfer, sc->atu_ep[ATU_ENDPT_RX], c, c->atu_buf,
   1640  1.1  joff 	    ATU_RX_BUFSZ, USBD_SHORT_XFER_OK | USBD_NO_COPY, USBD_NO_TIMEOUT,
   1641  1.1  joff 		atu_rxeof);
   1642  1.1  joff 	usbd_transfer(c->atu_xfer);
   1643  1.1  joff }
   1644  1.1  joff 
   1645  1.1  joff /*
   1646  1.1  joff  * A frame was downloaded to the chip. It's safe for us to clean up
   1647  1.1  joff  * the list buffers.
   1648  1.1  joff  */
   1649  1.1  joff void
   1650  1.1  joff atu_txeof(usbd_xfer_handle xfer, usbd_private_handle priv, usbd_status status)
   1651  1.1  joff {
   1652  1.1  joff 	struct atu_chain	*c = (struct atu_chain *)priv;
   1653  1.1  joff 	struct atu_softc	*sc = c->atu_sc;
   1654  1.1  joff 	struct ifnet		*ifp = &sc->sc_ic.ic_if;
   1655  1.1  joff 	usbd_status		err;
   1656  1.1  joff 	int			s;
   1657  1.1  joff 
   1658  1.1  joff 	DPRINTFN(25, ("%s: atu_txeof status=%d\n", USBDEVNAME(sc->atu_dev),
   1659  1.1  joff 	    status));
   1660  1.1  joff 
   1661  1.1  joff 	if (status != USBD_NORMAL_COMPLETION) {
   1662  1.1  joff 		if (status == USBD_NOT_STARTED || status == USBD_CANCELLED)
   1663  1.1  joff 			return;
   1664  1.1  joff 
   1665  1.1  joff 		DPRINTF(("%s: usb error on tx: %s\n", USBDEVNAME(sc->atu_dev),
   1666  1.1  joff 		    usbd_errstr(status)));
   1667  1.1  joff 		if (status == USBD_STALLED)
   1668  1.1  joff 			usbd_clear_endpoint_stall(sc->atu_ep[ATU_ENDPT_TX]);
   1669  1.1  joff 		return;
   1670  1.1  joff 	}
   1671  1.1  joff 
   1672  1.1  joff 	usbd_get_xfer_status(c->atu_xfer, NULL, NULL, NULL, &err);
   1673  1.1  joff 
   1674  1.1  joff 	if (err)
   1675  1.1  joff 		ifp->if_oerrors++;
   1676  1.1  joff 	else
   1677  1.1  joff 		ifp->if_opackets++;
   1678  1.1  joff 
   1679  1.1  joff 	m_freem(c->atu_mbuf);
   1680  1.1  joff 	c->atu_mbuf = NULL;
   1681  1.1  joff 
   1682  1.1  joff 	s = splnet();
   1683  1.1  joff 	SLIST_INSERT_HEAD(&sc->atu_cdata.atu_tx_free, c, atu_list);
   1684  1.1  joff 	sc->atu_cdata.atu_tx_inuse--;
   1685  1.1  joff 	if (sc->atu_cdata.atu_tx_inuse == 0)
   1686  1.1  joff 		ifp->if_timer = 0;
   1687  1.1  joff 	ifp->if_flags &= ~IFF_OACTIVE;
   1688  1.1  joff 	splx(s);
   1689  1.1  joff 
   1690  1.1  joff 	atu_start(ifp);
   1691  1.1  joff }
   1692  1.1  joff 
   1693  1.1  joff u_int8_t
   1694  1.1  joff atu_calculate_padding(int size)
   1695  1.1  joff {
   1696  1.1  joff 	size %= 64;
   1697  1.1  joff 
   1698  1.1  joff 	if (size < 50)
   1699  1.1  joff 		return (50 - size);
   1700  1.1  joff 	if (size >=61)
   1701  1.1  joff 		return (64 + 50 - size);
   1702  1.1  joff 	return (0);
   1703  1.1  joff }
   1704  1.1  joff 
   1705  1.1  joff int
   1706  1.1  joff atu_tx_start(struct atu_softc *sc, struct ieee80211_node *ni,
   1707  1.1  joff     struct atu_chain *c, struct mbuf *m)
   1708  1.1  joff {
   1709  1.1  joff 	struct ifnet		*ifp = &sc->sc_ic.ic_if;
   1710  1.1  joff 	int			len;
   1711  1.1  joff 	struct atu_tx_hdr	*h;
   1712  1.1  joff 	usbd_status		err;
   1713  1.1  joff 	u_int8_t		pad;
   1714  1.1  joff 
   1715  1.1  joff 	DPRINTFN(25, ("%s: atu_tx_start\n", USBDEVNAME(sc->atu_dev)));
   1716  1.1  joff 
   1717  1.1  joff 	/* Don't try to send when we're shutting down the driver */
   1718  1.1  joff 	if (sc->sc_state != ATU_S_OK)
   1719  1.1  joff 		return(EIO);
   1720  1.1  joff 
   1721  1.1  joff 	/*
   1722  1.1  joff 	 * Copy the mbuf data into a contiguous buffer, leaving
   1723  1.1  joff 	 * enough room for the atmel headers
   1724  1.1  joff 	 */
   1725  1.1  joff 	len = m->m_pkthdr.len;
   1726  1.1  joff 
   1727  1.1  joff 	m_copydata(m, 0, m->m_pkthdr.len, c->atu_buf + ATU_TX_HDRLEN);
   1728  1.1  joff 
   1729  1.1  joff 	h = (struct atu_tx_hdr *)c->atu_buf;
   1730  1.1  joff 	memset(h, 0, ATU_TX_HDRLEN);
   1731  1.1  joff 	USETW(h->length, len);
   1732  1.1  joff 	h->tx_rate = 4; /* XXX rate = auto */
   1733  1.1  joff 	len += ATU_TX_HDRLEN;
   1734  1.1  joff 
   1735  1.1  joff 	pad = atu_calculate_padding(len);
   1736  1.1  joff 	len += pad;
   1737  1.1  joff 	h->padding = pad;
   1738  1.1  joff 
   1739  1.1  joff 	c->atu_length = len;
   1740  1.1  joff 	c->atu_mbuf = m;
   1741  1.1  joff 
   1742  1.1  joff 	usbd_setup_xfer(c->atu_xfer, sc->atu_ep[ATU_ENDPT_TX],
   1743  1.1  joff 	    c, c->atu_buf, c->atu_length, USBD_NO_COPY, ATU_TX_TIMEOUT,
   1744  1.1  joff 	    atu_txeof);
   1745  1.1  joff 
   1746  1.1  joff 	/* Let's get this thing into the air! */
   1747  1.1  joff 	c->atu_in_xfer = 1;
   1748  1.1  joff 	err = usbd_transfer(c->atu_xfer);
   1749  1.1  joff 	if (err != USBD_IN_PROGRESS) {
   1750  1.1  joff 		atu_stop(ifp, 0);
   1751  1.1  joff 		return(EIO);
   1752  1.1  joff 	}
   1753  1.1  joff 
   1754  1.1  joff 	return (0);
   1755  1.1  joff }
   1756  1.1  joff 
   1757  1.1  joff void
   1758  1.1  joff atu_start(struct ifnet *ifp)
   1759  1.1  joff {
   1760  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   1761  1.1  joff 	struct ieee80211com	*ic = &sc->sc_ic;
   1762  1.1  joff 	struct atu_cdata	*cd = &sc->atu_cdata;
   1763  1.1  joff 	struct ieee80211_node	*ni;
   1764  1.1  joff 	struct ieee80211_frame	*wh;
   1765  1.1  joff 	struct atu_chain	*c;
   1766  1.1  joff 	struct mbuf		*m = NULL;
   1767  1.1  joff 	int			s;
   1768  1.1  joff 
   1769  1.1  joff 	DPRINTFN(25, ("%s: atu_start: enter\n", USBDEVNAME(sc->atu_dev)));
   1770  1.1  joff 
   1771  1.1  joff 	s = splnet();
   1772  1.1  joff 	if (ifp->if_flags & IFF_OACTIVE) {
   1773  1.1  joff 		DPRINTFN(30, ("%s: atu_start: IFF_OACTIVE\n",
   1774  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1775  1.1  joff 		splx(s);
   1776  1.1  joff 		return;
   1777  1.1  joff 	}
   1778  1.1  joff 
   1779  1.1  joff 	for (;;) {
   1780  1.1  joff 		/* grab a TX buffer */
   1781  1.1  joff 		s = splnet();
   1782  1.1  joff 		c = SLIST_FIRST(&cd->atu_tx_free);
   1783  1.1  joff 		if (c != NULL) {
   1784  1.1  joff 			SLIST_REMOVE_HEAD(&cd->atu_tx_free, atu_list);
   1785  1.1  joff 			cd->atu_tx_inuse++;
   1786  1.1  joff 			if (cd->atu_tx_inuse == ATU_TX_LIST_CNT)
   1787  1.1  joff 				ifp->if_flags |= IFF_OACTIVE;
   1788  1.1  joff 		}
   1789  1.1  joff 		splx(s);
   1790  1.1  joff 		if (c == NULL) {
   1791  1.1  joff 			DPRINTFN(10, ("%s: out of tx xfers\n",
   1792  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1793  1.1  joff 			ifp->if_flags |= IFF_OACTIVE;
   1794  1.1  joff 			break;
   1795  1.1  joff 		}
   1796  1.1  joff 
   1797  1.1  joff 		/*
   1798  1.1  joff 		 * Poll the management queue for frames, it has priority over
   1799  1.1  joff 		 * normal data frames.
   1800  1.1  joff 		 */
   1801  1.1  joff 		IF_DEQUEUE(&ic->ic_mgtq, m);
   1802  1.1  joff 		if (m == NULL) {
   1803  1.1  joff 			DPRINTFN(10, ("%s: atu_start: data packet\n",
   1804  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1805  1.1  joff 			if (ic->ic_state != IEEE80211_S_RUN) {
   1806  1.1  joff 				DPRINTFN(25, ("%s: no data till running\n",
   1807  1.1  joff 				    USBDEVNAME(sc->atu_dev)));
   1808  1.1  joff 				/* put the xfer back on the list */
   1809  1.1  joff 				s = splnet();
   1810  1.1  joff 				SLIST_INSERT_HEAD(&cd->atu_tx_free, c,
   1811  1.1  joff 				    atu_list);
   1812  1.1  joff 				cd->atu_tx_inuse--;
   1813  1.1  joff 				splx(s);
   1814  1.1  joff 				break;
   1815  1.1  joff 			}
   1816  1.1  joff 
   1817  1.1  joff 			IF_DEQUEUE(&ifp->if_snd, m);
   1818  1.1  joff 			if (m == NULL) {
   1819  1.1  joff 				DPRINTFN(25, ("%s: nothing to send\n",
   1820  1.1  joff 				    USBDEVNAME(sc->atu_dev)));
   1821  1.1  joff 				s = splnet();
   1822  1.1  joff 				SLIST_INSERT_HEAD(&cd->atu_tx_free, c,
   1823  1.1  joff 				    atu_list);
   1824  1.1  joff 				cd->atu_tx_inuse--;
   1825  1.1  joff 				splx(s);
   1826  1.1  joff 				break;
   1827  1.1  joff 			}
   1828  1.1  joff 
   1829  1.1  joff 			/* XXX bpf listener goes here */
   1830  1.1  joff 
   1831  1.1  joff 			m = ieee80211_encap(ifp, m, &ni);
   1832  1.1  joff 			if (m == NULL)
   1833  1.1  joff 				goto bad;
   1834  1.1  joff 			wh = mtod(m, struct ieee80211_frame *);
   1835  1.1  joff 		} else {
   1836  1.1  joff 			DPRINTFN(25, ("%s: atu_start: mgmt packet\n",
   1837  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   1838  1.1  joff 
   1839  1.1  joff 			/*
   1840  1.1  joff 			 * Hack!  The referenced node pointer is in the
   1841  1.1  joff 			 * rcvif field of the packet header.  This is
   1842  1.1  joff 			 * placed there by ieee80211_mgmt_output because
   1843  1.1  joff 			 * we need to hold the reference with the frame
   1844  1.1  joff 			 * and there's no other way (other than packet
   1845  1.1  joff 			 * tags which we consider too expensive to use)
   1846  1.1  joff 			 * to pass it along.
   1847  1.1  joff 			 */
   1848  1.1  joff 			ni = (struct ieee80211_node *)m->m_pkthdr.rcvif;
   1849  1.1  joff 			m->m_pkthdr.rcvif = NULL;
   1850  1.1  joff 
   1851  1.1  joff 			wh = mtod(m, struct ieee80211_frame *);
   1852  1.1  joff 			/* sc->sc_stats.ast_tx_mgmt++; */
   1853  1.1  joff 		}
   1854  1.1  joff 
   1855  1.1  joff 		if (atu_tx_start(sc, ni, c, m)) {
   1856  1.1  joff bad:
   1857  1.1  joff 			s = splnet();
   1858  1.1  joff 			SLIST_INSERT_HEAD(&cd->atu_tx_free, c,
   1859  1.1  joff 			    atu_list);
   1860  1.1  joff 			cd->atu_tx_inuse--;
   1861  1.1  joff 			splx(s);
   1862  1.1  joff 			/* ifp_if_oerrors++; */
   1863  1.1  joff 			if (ni != NULL && ni != ic->ic_bss)
   1864  1.1  joff 				/* reclaim node */
   1865  1.1  joff 				ieee80211_release_node(ic, ni);
   1866  1.1  joff 			continue;
   1867  1.1  joff 		}
   1868  1.1  joff 		ifp->if_timer = 5;
   1869  1.1  joff 	}
   1870  1.1  joff }
   1871  1.1  joff 
   1872  1.1  joff int
   1873  1.1  joff atu_init(struct ifnet *ifp)
   1874  1.1  joff {
   1875  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   1876  1.1  joff 	struct ieee80211com	*ic = &sc->sc_ic;
   1877  1.1  joff 	struct atu_chain	*c;
   1878  1.1  joff 	usbd_status		err;
   1879  1.1  joff 	int			i, s;
   1880  1.1  joff 
   1881  1.1  joff 	s = splnet();
   1882  1.1  joff 
   1883  1.1  joff 	DPRINTFN(10, ("%s: atu_init\n", USBDEVNAME(sc->atu_dev)));
   1884  1.1  joff 
   1885  1.1  joff 	if (ifp->if_flags & IFF_RUNNING) {
   1886  1.1  joff 		splx(s);
   1887  1.1  joff 		return(0);
   1888  1.1  joff 	}
   1889  1.1  joff 
   1890  1.1  joff 	/* Init TX ring */
   1891  1.1  joff 	if (atu_tx_list_init(sc))
   1892  1.1  joff 		printf("%s: tx list init failed\n", USBDEVNAME(sc->atu_dev));
   1893  1.1  joff 
   1894  1.1  joff 	/* Init RX ring */
   1895  1.1  joff 	if (atu_rx_list_init(sc))
   1896  1.1  joff 		printf("%s: rx list init failed\n", USBDEVNAME(sc->atu_dev));
   1897  1.1  joff 
   1898  1.1  joff 	/* Load the multicast filter. */
   1899  1.1  joff 	/*atu_setmulti(sc); */
   1900  1.1  joff 
   1901  1.1  joff 	/* Open RX and TX pipes. */
   1902  1.1  joff 	err = usbd_open_pipe(sc->atu_iface, sc->atu_ed[ATU_ENDPT_RX],
   1903  1.1  joff 	    USBD_EXCLUSIVE_USE, &sc->atu_ep[ATU_ENDPT_RX]);
   1904  1.1  joff 	if (err) {
   1905  1.1  joff 		DPRINTF(("%s: open rx pipe failed: %s\n",
   1906  1.1  joff 		    USBDEVNAME(sc->atu_dev), usbd_errstr(err)));
   1907  1.1  joff 		splx(s);
   1908  1.1  joff 		return(EIO);
   1909  1.1  joff 	}
   1910  1.1  joff 
   1911  1.1  joff 	err = usbd_open_pipe(sc->atu_iface, sc->atu_ed[ATU_ENDPT_TX],
   1912  1.1  joff 	    USBD_EXCLUSIVE_USE, &sc->atu_ep[ATU_ENDPT_TX]);
   1913  1.1  joff 	if (err) {
   1914  1.1  joff 		DPRINTF(("%s: open tx pipe failed: %s\n",
   1915  1.1  joff 		    USBDEVNAME(sc->atu_dev), usbd_errstr(err)));
   1916  1.1  joff 		splx(s);
   1917  1.1  joff 		return(EIO);
   1918  1.1  joff 	}
   1919  1.1  joff 
   1920  1.1  joff 	/* Start up the receive pipe. */
   1921  1.1  joff 	for (i = 0; i < ATU_RX_LIST_CNT; i++) {
   1922  1.1  joff 		c = &sc->atu_cdata.atu_rx_chain[i];
   1923  1.1  joff 
   1924  1.1  joff 		usbd_setup_xfer(c->atu_xfer, sc->atu_ep[ATU_ENDPT_RX], c,
   1925  1.1  joff 		    c->atu_buf, ATU_RX_BUFSZ, USBD_SHORT_XFER_OK | USBD_NO_COPY,
   1926  1.1  joff 		    USBD_NO_TIMEOUT, atu_rxeof);
   1927  1.1  joff 		usbd_transfer(c->atu_xfer);
   1928  1.1  joff 	}
   1929  1.1  joff 
   1930  1.1  joff 	DPRINTFN(10, ("%s: starting up using MAC=%s\n",
   1931  1.1  joff 	    USBDEVNAME(sc->atu_dev), ether_sprintf(ic->ic_myaddr)));
   1932  1.1  joff 
   1933  1.1  joff 	/* Do initial setup */
   1934  1.1  joff 	err = atu_initial_config(sc);
   1935  1.1  joff 	if (err) {
   1936  1.1  joff 		DPRINTF(("%s: initial config failed!\n",
   1937  1.1  joff 		    USBDEVNAME(sc->atu_dev)));
   1938  1.1  joff 		splx(s);
   1939  1.1  joff 		return(EIO);
   1940  1.1  joff 	}
   1941  1.1  joff 	DPRINTFN(10, ("%s: initialised transceiver\n",
   1942  1.1  joff 	    USBDEVNAME(sc->atu_dev)));
   1943  1.1  joff 
   1944  1.1  joff 	/* sc->atu_rxfilt = ATU_RXFILT_UNICAST|ATU_RXFILT_BROADCAST; */
   1945  1.1  joff 
   1946  1.1  joff 	/* If we want promiscuous mode, set the allframes bit. */
   1947  1.1  joff 	/*
   1948  1.1  joff 	if (ifp->if_flags & IFF_PROMISC)
   1949  1.1  joff 		sc->atu_rxfilt |= ATU_RXFILT_PROMISC;
   1950  1.1  joff 	*/
   1951  1.1  joff 
   1952  1.1  joff 	ifp->if_flags |= IFF_RUNNING;
   1953  1.1  joff 	ifp->if_flags &= ~IFF_OACTIVE;
   1954  1.1  joff 	splx(s);
   1955  1.1  joff 
   1956  1.1  joff 	/* XXX the following HAS to be replaced */
   1957  1.1  joff 	s = splnet();
   1958  1.1  joff 	err = ieee80211_new_state(ic, IEEE80211_S_SCAN, -1);
   1959  1.1  joff 	if (err)
   1960  1.1  joff 		DPRINTFN(1, ("%s: atu_init: error calling "
   1961  1.1  joff 		    "ieee80211_net_state", USBDEVNAME(sc->atu_dev)));
   1962  1.1  joff 	splx(s);
   1963  1.1  joff 
   1964  1.1  joff 	return 0;
   1965  1.1  joff }
   1966  1.1  joff 
   1967  1.1  joff #ifdef ATU_DEBUG
   1968  1.1  joff void
   1969  1.1  joff atu_debug_print(struct atu_softc *sc)
   1970  1.1  joff {
   1971  1.1  joff 	usbd_status		err;
   1972  1.1  joff 	u_int8_t		tmp[32];
   1973  1.1  joff 
   1974  1.1  joff 	/* DEBUG */
   1975  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_MGMT__CURRENT_BSSID, tmp)))
   1976  1.1  joff 		return;
   1977  1.1  joff 	DPRINTF(("%s: DEBUG: current BSSID=%s\n", USBDEVNAME(sc->atu_dev),
   1978  1.1  joff 	    ether_sprintf(tmp)));
   1979  1.1  joff 
   1980  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_MGMT__BEACON_PERIOD, tmp)))
   1981  1.1  joff 		return;
   1982  1.1  joff 	DPRINTF(("%s: DEBUG: beacon period=%d\n", USBDEVNAME(sc->atu_dev),
   1983  1.1  joff 	    tmp[0]));
   1984  1.1  joff 
   1985  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_WEP__PRIVACY_INVOKED, tmp)))
   1986  1.1  joff 		return;
   1987  1.1  joff 	DPRINTF(("%s: DEBUG: privacy invoked=%d\n", USBDEVNAME(sc->atu_dev),
   1988  1.1  joff 	    tmp[0]));
   1989  1.1  joff 
   1990  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_WEP__ENCR_LEVEL, tmp)))
   1991  1.1  joff 		return;
   1992  1.1  joff 	DPRINTF(("%s: DEBUG: encr_level=%d\n", USBDEVNAME(sc->atu_dev),
   1993  1.1  joff 	    tmp[0]));
   1994  1.1  joff 
   1995  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_WEP__ICV_ERROR_COUNT, tmp)))
   1996  1.1  joff 		return;
   1997  1.1  joff 	DPRINTF(("%s: DEBUG: icv error count=%d\n", USBDEVNAME(sc->atu_dev),
   1998  1.1  joff 	    *(short *)tmp));
   1999  1.1  joff 
   2000  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_WEP__EXCLUDED_COUNT, tmp)))
   2001  1.1  joff 		return;
   2002  1.1  joff 	DPRINTF(("%s: DEBUG: wep excluded count=%d\n",
   2003  1.1  joff 	    USBDEVNAME(sc->atu_dev), *(short *)tmp));
   2004  1.1  joff 
   2005  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_MGMT__POWER_MODE, tmp)))
   2006  1.1  joff 		return;
   2007  1.1  joff 	DPRINTF(("%s: DEBUG: power mode=%d\n", USBDEVNAME(sc->atu_dev),
   2008  1.1  joff 	    tmp[0]));
   2009  1.1  joff 
   2010  1.1  joff 	if ((err = atu_get_mib(sc, MIB_PHY__CHANNEL, tmp)))
   2011  1.1  joff 		return;
   2012  1.1  joff 	DPRINTF(("%s: DEBUG: channel=%d\n", USBDEVNAME(sc->atu_dev), tmp[0]));
   2013  1.1  joff 
   2014  1.1  joff 	if ((err = atu_get_mib(sc, MIB_PHY__REG_DOMAIN, tmp)))
   2015  1.1  joff 		return;
   2016  1.1  joff 	DPRINTF(("%s: DEBUG: reg domain=%d\n", USBDEVNAME(sc->atu_dev),
   2017  1.1  joff 	    tmp[0]));
   2018  1.1  joff 
   2019  1.1  joff 	if ((err = atu_get_mib(sc, MIB_LOCAL__SSID_SIZE, tmp)))
   2020  1.1  joff 		return;
   2021  1.1  joff 	DPRINTF(("%s: DEBUG: ssid size=%d\n", USBDEVNAME(sc->atu_dev),
   2022  1.1  joff 	    tmp[0]));
   2023  1.1  joff 
   2024  1.1  joff 	if ((err = atu_get_mib(sc, MIB_LOCAL__BEACON_ENABLE, tmp)))
   2025  1.1  joff 		return;
   2026  1.1  joff 	DPRINTF(("%s: DEBUG: beacon enable=%d\n", USBDEVNAME(sc->atu_dev),
   2027  1.1  joff 	    tmp[0]));
   2028  1.1  joff 
   2029  1.1  joff 	if ((err = atu_get_mib(sc, MIB_LOCAL__AUTO_RATE_FALLBACK, tmp)))
   2030  1.1  joff 		return;
   2031  1.1  joff 	DPRINTF(("%s: DEBUG: auto rate fallback=%d\n",
   2032  1.1  joff 	    USBDEVNAME(sc->atu_dev), tmp[0]));
   2033  1.1  joff 
   2034  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_ADDR__ADDR, tmp)))
   2035  1.1  joff 		return;
   2036  1.1  joff 	DPRINTF(("%s: DEBUG: mac addr=%s\n", USBDEVNAME(sc->atu_dev),
   2037  1.1  joff 	    ether_sprintf(tmp)));
   2038  1.1  joff 
   2039  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC__DESIRED_SSID, tmp)))
   2040  1.1  joff 		return;
   2041  1.1  joff 	DPRINTF(("%s: DEBUG: desired ssid=%s\n", USBDEVNAME(sc->atu_dev),
   2042  1.1  joff 	    tmp));
   2043  1.1  joff 
   2044  1.1  joff 	if ((err = atu_get_mib(sc, MIB_MAC_MGMT__CURRENT_ESSID, tmp)))
   2045  1.1  joff 		return;
   2046  1.1  joff 	DPRINTF(("%s: DEBUG: current ESSID=%s\n", USBDEVNAME(sc->atu_dev),
   2047  1.1  joff 	    tmp));
   2048  1.1  joff }
   2049  1.1  joff #endif /* ATU_DEBUG */
   2050  1.1  joff int
   2051  1.1  joff atu_set_wepkey(struct atu_softc *sc, int nr, u_int8_t *key, int len)
   2052  1.1  joff {
   2053  1.1  joff 	if ((len != 5) && (len != 13))
   2054  1.1  joff 		return EINVAL;
   2055  1.1  joff 
   2056  1.1  joff 	DPRINTFN(10, ("%s: changed wepkey %d (len=%d)\n",
   2057  1.1  joff 	    USBDEVNAME(sc->atu_dev), nr, len));
   2058  1.1  joff 
   2059  1.1  joff 	memcpy(sc->atu_wepkeys[nr], key, len);
   2060  1.1  joff 	if (len == 13)
   2061  1.1  joff 		sc->atu_wepkeylen = ATU_WEP_104BITS;
   2062  1.1  joff 	else
   2063  1.1  joff 		sc->atu_wepkeylen = ATU_WEP_40BITS;
   2064  1.1  joff 
   2065  1.1  joff 	atu_send_mib(sc, MIB_MAC_WEP__ENCR_LEVEL, NR(sc->atu_wepkeylen));
   2066  1.1  joff 	return atu_send_mib(sc, MIB_MAC_WEP__KEYS(nr), key);
   2067  1.1  joff }
   2068  1.1  joff 
   2069  1.1  joff int
   2070  1.1  joff atu_ioctl(struct ifnet *ifp, u_long command, caddr_t data)
   2071  1.1  joff {
   2072  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   2073  1.1  joff 	struct ifreq		*ifr = (struct ifreq *)data;
   2074  1.1  joff 	struct ieee80211com	*ic = &sc->sc_ic;
   2075  1.1  joff 	int			err = 0, s;
   2076  1.1  joff 
   2077  1.1  joff 	s = splnet();
   2078  1.1  joff 	switch (command) {
   2079  1.1  joff 	case SIOCSIFMEDIA:
   2080  1.1  joff 	case SIOCGIFMEDIA:
   2081  1.1  joff 		err = ifmedia_ioctl(ifp, ifr, &ic->ic_media, command);
   2082  1.1  joff 		break;
   2083  1.1  joff 
   2084  1.1  joff 	default:
   2085  1.1  joff 		DPRINTFN(15, ("%s: ieee80211_ioctl (%lu)\n",
   2086  1.1  joff 		    USBDEVNAME(sc->atu_dev), command));
   2087  1.1  joff 		err = ieee80211_ioctl(ifp, command, data);
   2088  1.1  joff 		break;
   2089  1.1  joff 	}
   2090  1.1  joff 
   2091  1.1  joff 	if (err == ENETRESET) {
   2092  1.1  joff 		if ((ifp->if_flags & (IFF_RUNNING|IFF_UP)) ==
   2093  1.1  joff 		    (IFF_RUNNING|IFF_UP)) {
   2094  1.1  joff 			DPRINTF(("%s: atu_ioctl(): netreset\n",
   2095  1.1  joff 			    USBDEVNAME(sc->atu_dev)));
   2096  1.1  joff 			atu_init(ifp);
   2097  1.1  joff 		}
   2098  1.1  joff 		err = 0;
   2099  1.1  joff 	}
   2100  1.1  joff 
   2101  1.1  joff 	splx(s);
   2102  1.1  joff 	return (err);
   2103  1.1  joff }
   2104  1.1  joff 
   2105  1.1  joff void
   2106  1.1  joff atu_watchdog(struct ifnet *ifp)
   2107  1.1  joff {
   2108  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   2109  1.1  joff 	struct atu_chain	*c;
   2110  1.1  joff 	usbd_status		stat;
   2111  1.1  joff 	int			cnt, s;
   2112  1.1  joff 
   2113  1.1  joff 	DPRINTF(("%s: atu_watchdog\n", USBDEVNAME(sc->atu_dev)));
   2114  1.1  joff 
   2115  1.1  joff 	ifp->if_timer = 0;
   2116  1.1  joff 
   2117  1.1  joff 	if (sc->sc_state != ATU_S_OK)
   2118  1.1  joff 		return;
   2119  1.1  joff 
   2120  1.1  joff 	sc = ifp->if_softc;
   2121  1.1  joff 	s = splnet();
   2122  1.1  joff 	ifp->if_oerrors++;
   2123  1.1  joff 	DPRINTF(("%s: watchdog timeout\n", USBDEVNAME(sc->atu_dev)));
   2124  1.1  joff 
   2125  1.1  joff 	/*
   2126  1.1  joff 	 * TODO:
   2127  1.1  joff 	 * we should change this since we have multiple TX tranfers...
   2128  1.1  joff 	 */
   2129  1.1  joff 	for (cnt = 0; cnt < ATU_TX_LIST_CNT; cnt++) {
   2130  1.1  joff 		c = &sc->atu_cdata.atu_tx_chain[cnt];
   2131  1.1  joff 		if (c->atu_in_xfer) {
   2132  1.1  joff 			usbd_get_xfer_status(c->atu_xfer, NULL, NULL, NULL,
   2133  1.1  joff 			    &stat);
   2134  1.1  joff 			atu_txeof(c->atu_xfer, c, stat);
   2135  1.1  joff 		}
   2136  1.1  joff 	}
   2137  1.1  joff 
   2138  1.1  joff 	if (ifp->if_snd.ifq_head != NULL)
   2139  1.1  joff 		atu_start(ifp);
   2140  1.1  joff 	splx(s);
   2141  1.1  joff 
   2142  1.1  joff 	ieee80211_watchdog(ifp);
   2143  1.1  joff }
   2144  1.1  joff 
   2145  1.1  joff /*
   2146  1.1  joff  * Stop the adapter and free any mbufs allocated to the
   2147  1.1  joff  * RX and TX lists.
   2148  1.1  joff  */
   2149  1.1  joff void
   2150  1.1  joff atu_stop(struct ifnet *ifp, int disable)
   2151  1.1  joff {
   2152  1.1  joff 	struct atu_softc	*sc = ifp->if_softc;
   2153  1.1  joff 	struct atu_cdata	*cd;
   2154  1.1  joff 	usbd_status		err;
   2155  1.1  joff 	int s;
   2156  1.1  joff 
   2157  1.1  joff 	s = splnet();
   2158  1.1  joff 	ifp->if_timer = 0;
   2159  1.1  joff 
   2160  1.1  joff 	/* Stop transfers. */
   2161  1.1  joff 	if (sc->atu_ep[ATU_ENDPT_RX] != NULL) {
   2162  1.1  joff 		err = usbd_abort_pipe(sc->atu_ep[ATU_ENDPT_RX]);
   2163  1.1  joff 		if (err) {
   2164  1.1  joff 			DPRINTF(("%s: abort rx pipe failed: %s\n",
   2165  1.1  joff 			    USBDEVNAME(sc->atu_dev), usbd_errstr(err)));
   2166  1.1  joff 		}
   2167  1.1  joff 		err = usbd_close_pipe(sc->atu_ep[ATU_ENDPT_RX]);
   2168  1.1  joff 		if (err) {
   2169  1.1  joff 			DPRINTF(("%s: close rx pipe failed: %s\n",
   2170  1.1  joff 			    USBDEVNAME(sc->atu_dev), usbd_errstr(err)));
   2171  1.1  joff 		}
   2172  1.1  joff 		sc->atu_ep[ATU_ENDPT_RX] = NULL;
   2173  1.1  joff 	}
   2174  1.1  joff 
   2175  1.1  joff 	if (sc->atu_ep[ATU_ENDPT_TX] != NULL) {
   2176  1.1  joff 		err = usbd_abort_pipe(sc->atu_ep[ATU_ENDPT_TX]);
   2177  1.1  joff 		if (err) {
   2178  1.1  joff 			DPRINTF(("%s: abort tx pipe failed: %s\n",
   2179  1.1  joff 			    USBDEVNAME(sc->atu_dev), usbd_errstr(err)));
   2180  1.1  joff 		}
   2181  1.1  joff 		err = usbd_close_pipe(sc->atu_ep[ATU_ENDPT_TX]);
   2182  1.1  joff 		if (err) {
   2183  1.1  joff 			DPRINTF(("%s: close tx pipe failed: %s\n",
   2184  1.1  joff 			    USBDEVNAME(sc->atu_dev), usbd_errstr(err)));
   2185  1.1  joff 		}
   2186  1.1  joff 		sc->atu_ep[ATU_ENDPT_TX] = NULL;
   2187  1.1  joff 	}
   2188  1.1  joff 
   2189  1.1  joff 	/* Free RX/TX/MGMT list resources. */
   2190  1.1  joff 	cd = &sc->atu_cdata;
   2191  1.1  joff 	atu_xfer_list_free(sc, cd->atu_rx_chain, ATU_RX_LIST_CNT);
   2192  1.1  joff 	atu_xfer_list_free(sc, cd->atu_tx_chain, ATU_TX_LIST_CNT);
   2193  1.1  joff 
   2194  1.1  joff 	/* Let's be nice and turn off the radio before we leave */
   2195  1.1  joff 	atu_switch_radio(sc, 0);
   2196  1.1  joff 
   2197  1.1  joff 	ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
   2198  1.1  joff 	splx(s);
   2199  1.1  joff }
   2200