if_urndis.c revision 1.23 1 /* $NetBSD: if_urndis.c,v 1.23 2019/08/07 22:26:28 macallan Exp $ */
2 /* $OpenBSD: if_urndis.c,v 1.31 2011/07/03 15:47:17 matthew Exp $ */
3
4 /*
5 * Copyright (c) 2010 Jonathan Armani <armani (at) openbsd.org>
6 * Copyright (c) 2010 Fabien Romano <fabien (at) openbsd.org>
7 * Copyright (c) 2010 Michael Knudsen <mk (at) openbsd.org>
8 * All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
22
23 #include <sys/cdefs.h>
24 __KERNEL_RCSID(0, "$NetBSD: if_urndis.c,v 1.23 2019/08/07 22:26:28 macallan Exp $");
25
26 #ifdef _KERNEL_OPT
27 #include "opt_usb.h"
28 #endif
29
30 #include <sys/param.h>
31 #include <sys/systm.h>
32 #include <sys/sockio.h>
33 #include <sys/rwlock.h>
34 #include <sys/mbuf.h>
35 #include <sys/kmem.h>
36 #include <sys/kernel.h>
37 #include <sys/proc.h>
38 #include <sys/socket.h>
39 #include <sys/device.h>
40
41 #include <net/if.h>
42 #include <net/if_dl.h>
43 #include <net/if_media.h>
44 #include <net/if_ether.h>
45
46 #include <net/bpf.h>
47
48 #include <sys/bus.h>
49 #include <dev/usb/usb.h>
50 #include <dev/usb/usbdi.h>
51 #include <dev/usb/usbdi_util.h>
52 #include <dev/usb/usbdivar.h>
53 #include <dev/usb/usbdevs.h>
54 #include <dev/usb/usbcdc.h>
55
56 #include <dev/ic/rndisreg.h>
57
58 #define RNDIS_RX_LIST_CNT 1
59 #define RNDIS_TX_LIST_CNT 1
60 #define RNDIS_BUFSZ 1562
61
62 struct urndis_softc;
63
64 struct urndis_chain {
65 struct urndis_softc *sc_softc;
66 struct usbd_xfer *sc_xfer;
67 char *sc_buf;
68 struct mbuf *sc_mbuf;
69 };
70
71 struct urndis_cdata {
72 struct urndis_chain sc_rx_chain[RNDIS_RX_LIST_CNT];
73 struct urndis_chain sc_tx_chain[RNDIS_TX_LIST_CNT];
74 int sc_tx_cnt;
75 };
76
77 #define GET_IFP(sc) (&(sc)->sc_ec.ec_if)
78 struct urndis_softc {
79 device_t sc_dev;
80
81 char sc_attached;
82 int sc_dying;
83 struct ethercom sc_ec;
84
85 /* RNDIS device info */
86 uint32_t sc_filter;
87 uint32_t sc_maxppt;
88 uint32_t sc_maxtsz;
89 uint32_t sc_palign;
90
91 /* USB goo */
92 struct usbd_device * sc_udev;
93 int sc_ifaceno_ctl;
94 struct usbd_interface * sc_iface_ctl;
95 struct usbd_interface * sc_iface_data;
96
97 struct timeval sc_rx_notice;
98 int sc_bulkin_no;
99 struct usbd_pipe * sc_bulkin_pipe;
100 int sc_bulkout_no;
101 struct usbd_pipe * sc_bulkout_pipe;
102
103 struct urndis_cdata sc_data;
104 };
105
106 #ifdef URNDIS_DEBUG
107 #define DPRINTF(x) do { printf x; } while (0)
108 #else
109 #define DPRINTF(x)
110 #endif
111
112 #define DEVNAME(sc) (device_xname(sc->sc_dev))
113
114 #define URNDIS_RESPONSE_LEN 0x400
115
116
117 static int urndis_newbuf(struct urndis_softc *, struct urndis_chain *);
118
119 static int urndis_ioctl(struct ifnet *, unsigned long, void *);
120 #if 0
121 static void urndis_watchdog(struct ifnet *);
122 #endif
123
124 static void urndis_start(struct ifnet *);
125 static void urndis_rxeof(struct usbd_xfer *, void *, usbd_status);
126 static void urndis_txeof(struct usbd_xfer *, void *, usbd_status);
127 static int urndis_rx_list_init(struct urndis_softc *);
128 static int urndis_tx_list_init(struct urndis_softc *);
129
130 static int urndis_init(struct ifnet *);
131 static void urndis_stop(struct ifnet *);
132
133 static usbd_status urndis_ctrl_msg(struct urndis_softc *, uint8_t, uint8_t,
134 uint16_t, uint16_t, void *, size_t);
135 static usbd_status urndis_ctrl_send(struct urndis_softc *, void *, size_t);
136 static struct rndis_comp_hdr *urndis_ctrl_recv(struct urndis_softc *);
137
138 static uint32_t urndis_ctrl_handle(struct urndis_softc *,
139 struct rndis_comp_hdr *, void **, size_t *);
140 static uint32_t urndis_ctrl_handle_init(struct urndis_softc *,
141 const struct rndis_comp_hdr *);
142 static uint32_t urndis_ctrl_handle_query(struct urndis_softc *,
143 const struct rndis_comp_hdr *, void **, size_t *);
144 static uint32_t urndis_ctrl_handle_reset(struct urndis_softc *,
145 const struct rndis_comp_hdr *);
146
147 static uint32_t urndis_ctrl_init(struct urndis_softc *);
148 #if 0
149 static uint32_t urndis_ctrl_halt(struct urndis_softc *);
150 #endif
151 static uint32_t urndis_ctrl_query(struct urndis_softc *, uint32_t, void *,
152 size_t, void **, size_t *);
153 static uint32_t urndis_ctrl_set(struct urndis_softc *, uint32_t, void *,
154 size_t);
155 #if 0
156 static uint32_t urndis_ctrl_set_param(struct urndis_softc *, const char *,
157 uint32_t, void *, size_t);
158 static uint32_t urndis_ctrl_reset(struct urndis_softc *);
159 static uint32_t urndis_ctrl_keepalive(struct urndis_softc *);
160 #endif
161
162 static int urndis_encap(struct urndis_softc *, struct mbuf *, int);
163 static void urndis_decap(struct urndis_softc *, struct urndis_chain *,
164 uint32_t);
165
166 static int urndis_match(device_t, cfdata_t, void *);
167 static void urndis_attach(device_t, device_t, void *);
168 static int urndis_detach(device_t, int);
169 static int urndis_activate(device_t, enum devact);
170
171 CFATTACH_DECL_NEW(urndis, sizeof(struct urndis_softc),
172 urndis_match, urndis_attach, urndis_detach, urndis_activate);
173
174 /*
175 * Supported devices that we can't match by class IDs.
176 */
177 static const struct usb_devno urndis_devs[] = {
178 { USB_VENDOR_HTC, USB_PRODUCT_HTC_ANDROID },
179 { USB_VENDOR_SAMSUNG, USB_PRODUCT_SAMSUNG_ANDROID2 },
180 { USB_VENDOR_SAMSUNG, USB_PRODUCT_SAMSUNG_ANDROID },
181 };
182
183 static usbd_status
184 urndis_ctrl_msg(struct urndis_softc *sc, uint8_t rt, uint8_t r,
185 uint16_t index, uint16_t value, void *buf, size_t buflen)
186 {
187 usb_device_request_t req;
188
189 req.bmRequestType = rt;
190 req.bRequest = r;
191 USETW(req.wValue, value);
192 USETW(req.wIndex, index);
193 USETW(req.wLength, buflen);
194
195 return usbd_do_request(sc->sc_udev, &req, buf);
196 }
197
198 static usbd_status
199 urndis_ctrl_send(struct urndis_softc *sc, void *buf, size_t len)
200 {
201 usbd_status err;
202
203 if (sc->sc_dying)
204 return(0);
205
206 err = urndis_ctrl_msg(sc, UT_WRITE_CLASS_INTERFACE, UR_GET_STATUS,
207 sc->sc_ifaceno_ctl, 0, buf, len);
208
209 if (err != USBD_NORMAL_COMPLETION)
210 printf("%s: %s\n", DEVNAME(sc), usbd_errstr(err));
211
212 return err;
213 }
214
215 static struct rndis_comp_hdr *
216 urndis_ctrl_recv(struct urndis_softc *sc)
217 {
218 struct rndis_comp_hdr *hdr;
219 char *buf;
220 usbd_status err;
221
222 buf = kmem_alloc(URNDIS_RESPONSE_LEN, KM_SLEEP);
223 err = urndis_ctrl_msg(sc, UT_READ_CLASS_INTERFACE, UR_CLEAR_FEATURE,
224 sc->sc_ifaceno_ctl, 0, buf, URNDIS_RESPONSE_LEN);
225
226 if (err != USBD_NORMAL_COMPLETION && err != USBD_SHORT_XFER) {
227 printf("%s: %s\n", DEVNAME(sc), usbd_errstr(err));
228 kmem_free(buf, URNDIS_RESPONSE_LEN);
229 return NULL;
230 }
231
232 hdr = (struct rndis_comp_hdr *)buf;
233 DPRINTF(("%s: urndis_ctrl_recv: type 0x%x len %u\n",
234 DEVNAME(sc),
235 le32toh(hdr->rm_type),
236 le32toh(hdr->rm_len)));
237
238 if (le32toh(hdr->rm_len) > URNDIS_RESPONSE_LEN) {
239 printf("%s: ctrl message error: wrong size %u > %u\n",
240 DEVNAME(sc),
241 le32toh(hdr->rm_len),
242 URNDIS_RESPONSE_LEN);
243 kmem_free(buf, URNDIS_RESPONSE_LEN);
244 return NULL;
245 }
246
247 return hdr;
248 }
249
250 static uint32_t
251 urndis_ctrl_handle(struct urndis_softc *sc, struct rndis_comp_hdr *hdr,
252 void **buf, size_t *bufsz)
253 {
254 uint32_t rval;
255
256 DPRINTF(("%s: urndis_ctrl_handle\n", DEVNAME(sc)));
257
258 if (buf && bufsz) {
259 *buf = NULL;
260 *bufsz = 0;
261 }
262
263 switch (le32toh(hdr->rm_type)) {
264 case REMOTE_NDIS_INITIALIZE_CMPLT:
265 rval = urndis_ctrl_handle_init(sc, hdr);
266 break;
267
268 case REMOTE_NDIS_QUERY_CMPLT:
269 rval = urndis_ctrl_handle_query(sc, hdr, buf, bufsz);
270 break;
271
272 case REMOTE_NDIS_RESET_CMPLT:
273 rval = urndis_ctrl_handle_reset(sc, hdr);
274 break;
275
276 case REMOTE_NDIS_KEEPALIVE_CMPLT:
277 case REMOTE_NDIS_SET_CMPLT:
278 rval = le32toh(hdr->rm_status);
279 break;
280
281 default:
282 printf("%s: ctrl message error: unknown event 0x%x\n",
283 DEVNAME(sc), le32toh(hdr->rm_type));
284 rval = RNDIS_STATUS_FAILURE;
285 }
286
287 kmem_free(hdr, URNDIS_RESPONSE_LEN);
288
289 return rval;
290 }
291
292 static uint32_t
293 urndis_ctrl_handle_init(struct urndis_softc *sc,
294 const struct rndis_comp_hdr *hdr)
295 {
296 const struct rndis_init_comp *msg;
297
298 msg = (const struct rndis_init_comp *) hdr;
299
300 DPRINTF(("%s: urndis_ctrl_handle_init: len %u rid %u status 0x%x "
301 "ver_major %u ver_minor %u devflags 0x%x medium 0x%x pktmaxcnt %u "
302 "pktmaxsz %u align %u aflistoffset %u aflistsz %u\n",
303 DEVNAME(sc),
304 le32toh(msg->rm_len),
305 le32toh(msg->rm_rid),
306 le32toh(msg->rm_status),
307 le32toh(msg->rm_ver_major),
308 le32toh(msg->rm_ver_minor),
309 le32toh(msg->rm_devflags),
310 le32toh(msg->rm_medium),
311 le32toh(msg->rm_pktmaxcnt),
312 le32toh(msg->rm_pktmaxsz),
313 le32toh(msg->rm_align),
314 le32toh(msg->rm_aflistoffset),
315 le32toh(msg->rm_aflistsz)));
316
317 if (le32toh(msg->rm_status) != RNDIS_STATUS_SUCCESS) {
318 printf("%s: init failed 0x%x\n",
319 DEVNAME(sc),
320 le32toh(msg->rm_status));
321
322 return le32toh(msg->rm_status);
323 }
324
325 if (le32toh(msg->rm_devflags) != RNDIS_DF_CONNECTIONLESS) {
326 printf("%s: wrong device type (current type: 0x%x)\n",
327 DEVNAME(sc),
328 le32toh(msg->rm_devflags));
329
330 return RNDIS_STATUS_FAILURE;
331 }
332
333 if (le32toh(msg->rm_medium) != RNDIS_MEDIUM_802_3) {
334 printf("%s: medium not 802.3 (current medium: 0x%x)\n",
335 DEVNAME(sc), le32toh(msg->rm_medium));
336
337 return RNDIS_STATUS_FAILURE;
338 }
339
340 if (le32toh(msg->rm_ver_major) != RNDIS_MAJOR_VERSION ||
341 le32toh(msg->rm_ver_minor) != RNDIS_MINOR_VERSION) {
342 printf("%s: version not %u.%u (current version: %u.%u)\n",
343 DEVNAME(sc), RNDIS_MAJOR_VERSION, RNDIS_MINOR_VERSION,
344 le32toh(msg->rm_ver_major), le32toh(msg->rm_ver_minor));
345
346 return RNDIS_STATUS_FAILURE;
347 }
348
349 sc->sc_maxppt = le32toh(msg->rm_pktmaxcnt);
350 sc->sc_maxtsz = le32toh(msg->rm_pktmaxsz);
351 sc->sc_palign = 1U << le32toh(msg->rm_align);
352
353 return le32toh(msg->rm_status);
354 }
355
356 static uint32_t
357 urndis_ctrl_handle_query(struct urndis_softc *sc,
358 const struct rndis_comp_hdr *hdr, void **buf, size_t *bufsz)
359 {
360 const struct rndis_query_comp *msg;
361
362 msg = (const struct rndis_query_comp *) hdr;
363
364 DPRINTF(("%s: urndis_ctrl_handle_query: len %u rid %u status 0x%x "
365 "buflen %u bufoff %u\n",
366 DEVNAME(sc),
367 le32toh(msg->rm_len),
368 le32toh(msg->rm_rid),
369 le32toh(msg->rm_status),
370 le32toh(msg->rm_infobuflen),
371 le32toh(msg->rm_infobufoffset)));
372
373 if (buf && bufsz) {
374 *buf = NULL;
375 *bufsz = 0;
376 }
377
378 if (le32toh(msg->rm_status) != RNDIS_STATUS_SUCCESS) {
379 printf("%s: query failed 0x%x\n",
380 DEVNAME(sc),
381 le32toh(msg->rm_status));
382
383 return le32toh(msg->rm_status);
384 }
385
386 if (le32toh(msg->rm_infobuflen) + le32toh(msg->rm_infobufoffset) +
387 RNDIS_HEADER_OFFSET > le32toh(msg->rm_len)) {
388 printf("%s: ctrl message error: invalid query info "
389 "len/offset/end_position(%u/%u/%u) -> "
390 "go out of buffer limit %u\n",
391 DEVNAME(sc),
392 le32toh(msg->rm_infobuflen),
393 le32toh(msg->rm_infobufoffset),
394 le32toh(msg->rm_infobuflen) +
395 le32toh(msg->rm_infobufoffset) + (uint32_t)RNDIS_HEADER_OFFSET,
396 le32toh(msg->rm_len));
397 return RNDIS_STATUS_FAILURE;
398 }
399
400 if (buf && bufsz) {
401 const char *p;
402
403 *buf = kmem_alloc(le32toh(msg->rm_infobuflen), KM_SLEEP);
404 *bufsz = le32toh(msg->rm_infobuflen);
405
406 p = (const char *)&msg->rm_rid;
407 p += le32toh(msg->rm_infobufoffset);
408 memcpy(*buf, p, le32toh(msg->rm_infobuflen));
409 }
410
411 return le32toh(msg->rm_status);
412 }
413
414 static uint32_t
415 urndis_ctrl_handle_reset(struct urndis_softc *sc,
416 const struct rndis_comp_hdr *hdr)
417 {
418 const struct rndis_reset_comp *msg;
419 uint32_t rval;
420
421 msg = (const struct rndis_reset_comp *) hdr;
422
423 rval = le32toh(msg->rm_status);
424
425 DPRINTF(("%s: urndis_ctrl_handle_reset: len %u status 0x%x "
426 "adrreset %u\n",
427 DEVNAME(sc),
428 le32toh(msg->rm_len),
429 rval,
430 le32toh(msg->rm_adrreset)));
431
432 if (rval != RNDIS_STATUS_SUCCESS) {
433 printf("%s: reset failed 0x%x\n", DEVNAME(sc), rval);
434 return rval;
435 }
436
437 if (le32toh(msg->rm_adrreset) != 0) {
438 uint32_t filter;
439
440 filter = htole32(sc->sc_filter);
441 rval = urndis_ctrl_set(sc, OID_GEN_CURRENT_PACKET_FILTER,
442 &filter, sizeof(filter));
443 if (rval != RNDIS_STATUS_SUCCESS) {
444 printf("%s: unable to reset data filters\n",
445 DEVNAME(sc));
446 return rval;
447 }
448 }
449
450 return rval;
451 }
452
453 static uint32_t
454 urndis_ctrl_init(struct urndis_softc *sc)
455 {
456 struct rndis_init_req *msg;
457 uint32_t rval;
458 struct rndis_comp_hdr *hdr;
459
460 msg = kmem_alloc(sizeof(*msg), KM_SLEEP);
461 msg->rm_type = htole32(REMOTE_NDIS_INITIALIZE_MSG);
462 msg->rm_len = htole32(sizeof(*msg));
463 msg->rm_rid = htole32(0);
464 msg->rm_ver_major = htole32(RNDIS_MAJOR_VERSION);
465 msg->rm_ver_minor = htole32(RNDIS_MINOR_VERSION);
466 msg->rm_max_xfersz = htole32(RNDIS_BUFSZ);
467
468 DPRINTF(("%s: urndis_ctrl_init send: type %u len %u rid %u ver_major %u "
469 "ver_minor %u max_xfersz %u\n",
470 DEVNAME(sc),
471 le32toh(msg->rm_type),
472 le32toh(msg->rm_len),
473 le32toh(msg->rm_rid),
474 le32toh(msg->rm_ver_major),
475 le32toh(msg->rm_ver_minor),
476 le32toh(msg->rm_max_xfersz)));
477
478 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
479 kmem_free(msg, sizeof(*msg));
480
481 if (rval != RNDIS_STATUS_SUCCESS) {
482 printf("%s: init failed\n", DEVNAME(sc));
483 return rval;
484 }
485
486 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
487 printf("%s: unable to get init response\n", DEVNAME(sc));
488 return RNDIS_STATUS_FAILURE;
489 }
490 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
491
492 return rval;
493 }
494
495 #if 0
496 static uint32_t
497 urndis_ctrl_halt(struct urndis_softc *sc)
498 {
499 struct rndis_halt_req *msg;
500 uint32_t rval;
501
502 msg = kmem_alloc(sizeof(*msg), KM_SLEEP);
503 msg->rm_type = htole32(REMOTE_NDIS_HALT_MSG);
504 msg->rm_len = htole32(sizeof(*msg));
505 msg->rm_rid = 0;
506
507 DPRINTF(("%s: urndis_ctrl_halt send: type %u len %u rid %u\n",
508 DEVNAME(sc),
509 le32toh(msg->rm_type),
510 le32toh(msg->rm_len),
511 le32toh(msg->rm_rid)));
512
513 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
514 kmem_free(msg, sizeof(*msg));
515
516 if (rval != RNDIS_STATUS_SUCCESS)
517 printf("%s: halt failed\n", DEVNAME(sc));
518
519 return rval;
520 }
521 #endif
522
523 static uint32_t
524 urndis_ctrl_query(struct urndis_softc *sc, uint32_t oid,
525 void *qbuf, size_t qlen,
526 void **rbuf, size_t *rbufsz)
527 {
528 struct rndis_query_req *msg;
529 uint32_t rval;
530 struct rndis_comp_hdr *hdr;
531
532 msg = kmem_alloc(sizeof(*msg) + qlen, KM_SLEEP);
533 msg->rm_type = htole32(REMOTE_NDIS_QUERY_MSG);
534 msg->rm_len = htole32(sizeof(*msg) + qlen);
535 msg->rm_rid = 0; /* XXX */
536 msg->rm_oid = htole32(oid);
537 msg->rm_infobuflen = htole32(qlen);
538 if (qlen != 0) {
539 msg->rm_infobufoffset = htole32(20);
540 memcpy((char*)msg + 20, qbuf, qlen);
541 } else
542 msg->rm_infobufoffset = 0;
543 msg->rm_devicevchdl = 0;
544
545 DPRINTF(("%s: urndis_ctrl_query send: type %u len %u rid %u oid 0x%x "
546 "infobuflen %u infobufoffset %u devicevchdl %u\n",
547 DEVNAME(sc),
548 le32toh(msg->rm_type),
549 le32toh(msg->rm_len),
550 le32toh(msg->rm_rid),
551 le32toh(msg->rm_oid),
552 le32toh(msg->rm_infobuflen),
553 le32toh(msg->rm_infobufoffset),
554 le32toh(msg->rm_devicevchdl)));
555
556 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
557 kmem_free(msg, sizeof(*msg) + qlen);
558
559 if (rval != RNDIS_STATUS_SUCCESS) {
560 printf("%s: query failed\n", DEVNAME(sc));
561 return rval;
562 }
563
564 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
565 printf("%s: unable to get query response\n", DEVNAME(sc));
566 return RNDIS_STATUS_FAILURE;
567 }
568 rval = urndis_ctrl_handle(sc, hdr, rbuf, rbufsz);
569
570 return rval;
571 }
572
573 static uint32_t
574 urndis_ctrl_set(struct urndis_softc *sc, uint32_t oid, void *buf, size_t len)
575 {
576 struct rndis_set_req *msg;
577 uint32_t rval;
578 struct rndis_comp_hdr *hdr;
579
580 msg = kmem_alloc(sizeof(*msg) + len, KM_SLEEP);
581 msg->rm_type = htole32(REMOTE_NDIS_SET_MSG);
582 msg->rm_len = htole32(sizeof(*msg) + len);
583 msg->rm_rid = 0; /* XXX */
584 msg->rm_oid = htole32(oid);
585 msg->rm_infobuflen = htole32(len);
586 if (len != 0) {
587 msg->rm_infobufoffset = htole32(20);
588 memcpy((char*)msg + 20, buf, len);
589 } else
590 msg->rm_infobufoffset = 0;
591 msg->rm_devicevchdl = 0;
592
593 DPRINTF(("%s: urndis_ctrl_set send: type %u len %u rid %u oid 0x%x "
594 "infobuflen %u infobufoffset %u devicevchdl %u\n",
595 DEVNAME(sc),
596 le32toh(msg->rm_type),
597 le32toh(msg->rm_len),
598 le32toh(msg->rm_rid),
599 le32toh(msg->rm_oid),
600 le32toh(msg->rm_infobuflen),
601 le32toh(msg->rm_infobufoffset),
602 le32toh(msg->rm_devicevchdl)));
603
604 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
605 kmem_free(msg, sizeof(*msg) + len);
606
607 if (rval != RNDIS_STATUS_SUCCESS) {
608 printf("%s: set failed\n", DEVNAME(sc));
609 return rval;
610 }
611
612 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
613 printf("%s: unable to get set response\n", DEVNAME(sc));
614 return RNDIS_STATUS_FAILURE;
615 }
616 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
617 if (rval != RNDIS_STATUS_SUCCESS)
618 printf("%s: set failed 0x%x\n", DEVNAME(sc), rval);
619
620 return rval;
621 }
622
623 #if 0
624 static uint32_t
625 urndis_ctrl_set_param(struct urndis_softc *sc,
626 const char *name,
627 uint32_t type,
628 void *buf,
629 size_t len)
630 {
631 struct rndis_set_parameter *param;
632 uint32_t rval;
633 size_t namelen, tlen;
634
635 if (name)
636 namelen = strlen(name);
637 else
638 namelen = 0;
639 tlen = sizeof(*param) + len + namelen;
640 param = kmem_alloc(tlen, KM_SLEEP);
641 param->rm_namelen = htole32(namelen);
642 param->rm_valuelen = htole32(len);
643 param->rm_type = htole32(type);
644 if (namelen != 0) {
645 param->rm_nameoffset = htole32(20);
646 memcpy(param + 20, name, namelen);
647 } else
648 param->rm_nameoffset = 0;
649 if (len != 0) {
650 param->rm_valueoffset = htole32(20 + namelen);
651 memcpy(param + 20 + namelen, buf, len);
652 } else
653 param->rm_valueoffset = 0;
654
655 DPRINTF(("%s: urndis_ctrl_set_param send: nameoffset %u namelen %u "
656 "type 0x%x valueoffset %u valuelen %u\n",
657 DEVNAME(sc),
658 le32toh(param->rm_nameoffset),
659 le32toh(param->rm_namelen),
660 le32toh(param->rm_type),
661 le32toh(param->rm_valueoffset),
662 le32toh(param->rm_valuelen)));
663
664 rval = urndis_ctrl_set(sc, OID_GEN_RNDIS_CONFIG_PARAMETER, param, tlen);
665 kmem_free(param, tlen);
666 if (rval != RNDIS_STATUS_SUCCESS)
667 printf("%s: set param failed 0x%x\n", DEVNAME(sc), rval);
668
669 return rval;
670 }
671
672 /* XXX : adrreset, get it from response */
673 static uint32_t
674 urndis_ctrl_reset(struct urndis_softc *sc)
675 {
676 struct rndis_reset_req *reset;
677 uint32_t rval;
678 struct rndis_comp_hdr *hdr;
679
680 reset = kmem_alloc(sizeof(*reset), KM_SLEEP);
681 reset->rm_type = htole32(REMOTE_NDIS_RESET_MSG);
682 reset->rm_len = htole32(sizeof(*reset));
683 reset->rm_rid = 0; /* XXX rm_rid == reserved ... remove ? */
684
685 DPRINTF(("%s: urndis_ctrl_reset send: type %u len %u rid %u\n",
686 DEVNAME(sc),
687 le32toh(reset->rm_type),
688 le32toh(reset->rm_len),
689 le32toh(reset->rm_rid)));
690
691 rval = urndis_ctrl_send(sc, reset, sizeof(*reset));
692 kmem_free(reset, sizeof(*reset));
693
694 if (rval != RNDIS_STATUS_SUCCESS) {
695 printf("%s: reset failed\n", DEVNAME(sc));
696 return rval;
697 }
698
699 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
700 printf("%s: unable to get reset response\n", DEVNAME(sc));
701 return RNDIS_STATUS_FAILURE;
702 }
703 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
704
705 return rval;
706 }
707
708 static uint32_t
709 urndis_ctrl_keepalive(struct urndis_softc *sc)
710 {
711 struct rndis_keepalive_req *keep;
712 uint32_t rval;
713 struct rndis_comp_hdr *hdr;
714
715 keep = kmem_alloc(sizeof(*keep), KM_SLEEP);
716 keep->rm_type = htole32(REMOTE_NDIS_KEEPALIVE_MSG);
717 keep->rm_len = htole32(sizeof(*keep));
718 keep->rm_rid = 0; /* XXX rm_rid == reserved ... remove ? */
719
720 DPRINTF(("%s: urndis_ctrl_keepalive: type %u len %u rid %u\n",
721 DEVNAME(sc),
722 le32toh(keep->rm_type),
723 le32toh(keep->rm_len),
724 le32toh(keep->rm_rid)));
725
726 rval = urndis_ctrl_send(sc, keep, sizeof(*keep));
727 kmem_free(keep, sizeof(*keep));
728
729 if (rval != RNDIS_STATUS_SUCCESS) {
730 printf("%s: keepalive failed\n", DEVNAME(sc));
731 return rval;
732 }
733
734 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
735 printf("%s: unable to get keepalive response\n", DEVNAME(sc));
736 return RNDIS_STATUS_FAILURE;
737 }
738 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
739 if (rval != RNDIS_STATUS_SUCCESS) {
740 printf("%s: keepalive failed 0x%x\n", DEVNAME(sc), rval);
741 urndis_ctrl_reset(sc);
742 }
743
744 return rval;
745 }
746 #endif
747
748 static int
749 urndis_encap(struct urndis_softc *sc, struct mbuf *m, int idx)
750 {
751 struct urndis_chain *c;
752 usbd_status err;
753 struct rndis_packet_msg *msg;
754
755 c = &sc->sc_data.sc_tx_chain[idx];
756
757 msg = (struct rndis_packet_msg *)c->sc_buf;
758
759 memset(msg, 0, sizeof(*msg));
760 msg->rm_type = htole32(REMOTE_NDIS_PACKET_MSG);
761 msg->rm_len = htole32(sizeof(*msg) + m->m_pkthdr.len);
762
763 msg->rm_dataoffset = htole32(RNDIS_DATA_OFFSET);
764 msg->rm_datalen = htole32(m->m_pkthdr.len);
765
766 m_copydata(m, 0, m->m_pkthdr.len,
767 ((char*)msg + RNDIS_DATA_OFFSET + RNDIS_HEADER_OFFSET));
768
769 DPRINTF(("%s: urndis_encap type 0x%x len %u data(off %u len %u)\n",
770 DEVNAME(sc),
771 le32toh(msg->rm_type),
772 le32toh(msg->rm_len),
773 le32toh(msg->rm_dataoffset),
774 le32toh(msg->rm_datalen)));
775
776 c->sc_mbuf = m;
777
778 usbd_setup_xfer(c->sc_xfer, c, c->sc_buf, le32toh(msg->rm_len),
779 USBD_FORCE_SHORT_XFER, 10000, urndis_txeof);
780
781 /* Transmit */
782 err = usbd_transfer(c->sc_xfer);
783 if (err != USBD_IN_PROGRESS) {
784 urndis_stop(GET_IFP(sc));
785 return(EIO);
786 }
787
788 sc->sc_data.sc_tx_cnt++;
789
790 return(0);
791 }
792
793 static void
794 urndis_decap(struct urndis_softc *sc, struct urndis_chain *c, uint32_t len)
795 {
796 struct mbuf *m;
797 struct rndis_packet_msg *msg;
798 struct ifnet *ifp;
799 int s;
800 int offset;
801
802 ifp = GET_IFP(sc);
803 offset = 0;
804
805 while (len > 1) {
806 msg = (struct rndis_packet_msg *)((char*)c->sc_buf + offset);
807 m = c->sc_mbuf;
808
809 DPRINTF(("%s: urndis_decap buffer size left %u\n", DEVNAME(sc),
810 len));
811
812 if (len < sizeof(*msg)) {
813 printf("%s: urndis_decap invalid buffer len %u < "
814 "minimum header %zu\n",
815 DEVNAME(sc),
816 len,
817 sizeof(*msg));
818 return;
819 }
820
821 DPRINTF(("%s: urndis_decap len %u data(off:%u len:%u) "
822 "oobdata(off:%u len:%u nb:%u) perpacket(off:%u len:%u)\n",
823 DEVNAME(sc),
824 le32toh(msg->rm_len),
825 le32toh(msg->rm_dataoffset),
826 le32toh(msg->rm_datalen),
827 le32toh(msg->rm_oobdataoffset),
828 le32toh(msg->rm_oobdatalen),
829 le32toh(msg->rm_oobdataelements),
830 le32toh(msg->rm_pktinfooffset),
831 le32toh(msg->rm_pktinfooffset)));
832
833 if (le32toh(msg->rm_type) != REMOTE_NDIS_PACKET_MSG) {
834 printf("%s: urndis_decap invalid type 0x%x != 0x%x\n",
835 DEVNAME(sc),
836 le32toh(msg->rm_type),
837 REMOTE_NDIS_PACKET_MSG);
838 return;
839 }
840 if (le32toh(msg->rm_len) < sizeof(*msg)) {
841 printf("%s: urndis_decap invalid msg len %u < %zu\n",
842 DEVNAME(sc),
843 le32toh(msg->rm_len),
844 sizeof(*msg));
845 return;
846 }
847 if (le32toh(msg->rm_len) > len) {
848 printf("%s: urndis_decap invalid msg len %u > buffer "
849 "len %u\n",
850 DEVNAME(sc),
851 le32toh(msg->rm_len),
852 len);
853 return;
854 }
855
856 if (le32toh(msg->rm_dataoffset) +
857 le32toh(msg->rm_datalen) + RNDIS_HEADER_OFFSET
858 > le32toh(msg->rm_len)) {
859 printf("%s: urndis_decap invalid data "
860 "len/offset/end_position(%u/%u/%u) -> "
861 "go out of receive buffer limit %u\n",
862 DEVNAME(sc),
863 le32toh(msg->rm_datalen),
864 le32toh(msg->rm_dataoffset),
865 le32toh(msg->rm_dataoffset) +
866 le32toh(msg->rm_datalen) + (uint32_t)RNDIS_HEADER_OFFSET,
867 le32toh(msg->rm_len));
868 return;
869 }
870
871 if (le32toh(msg->rm_datalen) < sizeof(struct ether_header)) {
872 ifp->if_ierrors++;
873 printf("%s: urndis_decap invalid ethernet size "
874 "%d < %zu\n",
875 DEVNAME(sc),
876 le32toh(msg->rm_datalen),
877 sizeof(struct ether_header));
878 return;
879 }
880
881 memcpy(mtod(m, char*),
882 ((char*)&msg->rm_dataoffset + le32toh(msg->rm_dataoffset)),
883 le32toh(msg->rm_datalen));
884 m->m_pkthdr.len = m->m_len = le32toh(msg->rm_datalen);
885
886 m_set_rcvif(m, ifp);
887
888 s = splnet();
889
890 if (urndis_newbuf(sc, c) == ENOBUFS) {
891 ifp->if_ierrors++;
892 } else {
893 if_percpuq_enqueue(ifp->if_percpuq, m);
894 }
895 splx(s);
896
897 offset += le32toh(msg->rm_len);
898 len -= le32toh(msg->rm_len);
899 }
900 }
901
902 static int
903 urndis_newbuf(struct urndis_softc *sc, struct urndis_chain *c)
904 {
905 struct mbuf *m_new = NULL;
906
907 MGETHDR(m_new, M_DONTWAIT, MT_DATA);
908 if (m_new == NULL) {
909 printf("%s: no memory for rx list -- packet dropped!\n",
910 DEVNAME(sc));
911 return ENOBUFS;
912 }
913 MCLGET(m_new, M_DONTWAIT);
914 if (!(m_new->m_flags & M_EXT)) {
915 printf("%s: no memory for rx list -- packet dropped!\n",
916 DEVNAME(sc));
917 m_freem(m_new);
918 return ENOBUFS;
919 }
920 m_new->m_len = m_new->m_pkthdr.len = MCLBYTES;
921
922 m_adj(m_new, ETHER_ALIGN);
923 c->sc_mbuf = m_new;
924 return 0;
925 }
926
927 static int
928 urndis_rx_list_init(struct urndis_softc *sc)
929 {
930 struct urndis_cdata *cd;
931 struct urndis_chain *c;
932 int i;
933
934 cd = &sc->sc_data;
935 for (i = 0; i < RNDIS_RX_LIST_CNT; i++) {
936 c = &cd->sc_rx_chain[i];
937 c->sc_softc = sc;
938
939 if (urndis_newbuf(sc, c) == ENOBUFS)
940 return ENOBUFS;
941
942 if (c->sc_xfer == NULL) {
943 int err = usbd_create_xfer(sc->sc_bulkin_pipe,
944 RNDIS_BUFSZ, 0, 0, &c->sc_xfer);
945 if (err)
946 return err;
947 c->sc_buf = usbd_get_buffer(c->sc_xfer);
948 }
949 }
950
951 return 0;
952 }
953
954 static int
955 urndis_tx_list_init(struct urndis_softc *sc)
956 {
957 struct urndis_cdata *cd;
958 struct urndis_chain *c;
959 int i;
960
961 cd = &sc->sc_data;
962 for (i = 0; i < RNDIS_TX_LIST_CNT; i++) {
963 c = &cd->sc_tx_chain[i];
964 c->sc_softc = sc;
965 c->sc_mbuf = NULL;
966 if (c->sc_xfer == NULL) {
967 int err = usbd_create_xfer(sc->sc_bulkout_pipe,
968 RNDIS_BUFSZ, USBD_FORCE_SHORT_XFER, 0, &c->sc_xfer);
969 if (err)
970 return err;
971 c->sc_buf = usbd_get_buffer(c->sc_xfer);
972 }
973 }
974 return 0;
975 }
976
977 static int
978 urndis_ioctl(struct ifnet *ifp, unsigned long command, void *data)
979 {
980 struct urndis_softc *sc;
981 int s, error;
982
983 sc = ifp->if_softc;
984 error = 0;
985
986 if (sc->sc_dying)
987 return EIO;
988
989 s = splnet();
990
991 switch(command) {
992 case SIOCSIFFLAGS:
993 if ((error = ifioctl_common(ifp, command, data)) != 0)
994 break;
995 if (ifp->if_flags & IFF_UP) {
996 if (!(ifp->if_flags & IFF_RUNNING))
997 urndis_init(ifp);
998 } else {
999 if (ifp->if_flags & IFF_RUNNING)
1000 urndis_stop(ifp);
1001 }
1002 error = 0;
1003 break;
1004
1005 default:
1006 error = ether_ioctl(ifp, command, data);
1007 break;
1008 }
1009
1010 if (error == ENETRESET)
1011 error = 0;
1012
1013 splx(s);
1014 return error;
1015 }
1016
1017 #if 0
1018 static void
1019 urndis_watchdog(struct ifnet *ifp)
1020 {
1021 struct urndis_softc *sc;
1022
1023 sc = ifp->if_softc;
1024
1025 if (sc->sc_dying)
1026 return;
1027
1028 ifp->if_oerrors++;
1029 printf("%s: watchdog timeout\n", DEVNAME(sc));
1030
1031 urndis_ctrl_keepalive(sc);
1032 }
1033 #endif
1034
1035 static int
1036 urndis_init(struct ifnet *ifp)
1037 {
1038 struct urndis_softc *sc;
1039 int i, s;
1040 int err;
1041 usbd_status usberr;
1042
1043 sc = ifp->if_softc;
1044
1045 if (ifp->if_flags & IFF_RUNNING)
1046 return 0;
1047
1048 err = urndis_ctrl_init(sc);
1049 if (err != RNDIS_STATUS_SUCCESS)
1050 return EIO;
1051
1052 s = splnet();
1053
1054 usberr = usbd_open_pipe(sc->sc_iface_data, sc->sc_bulkin_no,
1055 USBD_EXCLUSIVE_USE, &sc->sc_bulkin_pipe);
1056 if (usberr) {
1057 printf("%s: open rx pipe failed: %s\n", DEVNAME(sc),
1058 usbd_errstr(err));
1059 splx(s);
1060 return EIO;
1061 }
1062
1063 usberr = usbd_open_pipe(sc->sc_iface_data, sc->sc_bulkout_no,
1064 USBD_EXCLUSIVE_USE, &sc->sc_bulkout_pipe);
1065 if (usberr) {
1066 printf("%s: open tx pipe failed: %s\n", DEVNAME(sc),
1067 usbd_errstr(err));
1068 splx(s);
1069 return EIO;
1070 }
1071
1072 err = urndis_tx_list_init(sc);
1073 if (err) {
1074 printf("%s: tx list init failed\n",
1075 DEVNAME(sc));
1076 splx(s);
1077 return err;
1078 }
1079
1080 err = urndis_rx_list_init(sc);
1081 if (err) {
1082 printf("%s: rx list init failed\n",
1083 DEVNAME(sc));
1084 splx(s);
1085 return err;
1086 }
1087
1088 for (i = 0; i < RNDIS_RX_LIST_CNT; i++) {
1089 struct urndis_chain *c;
1090
1091 c = &sc->sc_data.sc_rx_chain[i];
1092
1093 usbd_setup_xfer(c->sc_xfer, c, c->sc_buf, RNDIS_BUFSZ,
1094 USBD_SHORT_XFER_OK, USBD_NO_TIMEOUT, urndis_rxeof);
1095 usbd_transfer(c->sc_xfer);
1096 }
1097
1098 ifp->if_flags |= IFF_RUNNING;
1099 ifp->if_flags &= ~IFF_OACTIVE;
1100
1101 splx(s);
1102 return 0;
1103 }
1104
1105 static void
1106 urndis_stop(struct ifnet *ifp)
1107 {
1108 struct urndis_softc *sc;
1109 usbd_status err;
1110 int i;
1111
1112 sc = ifp->if_softc;
1113
1114 ifp->if_timer = 0;
1115 ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
1116
1117 if (sc->sc_bulkin_pipe != NULL) {
1118 err = usbd_abort_pipe(sc->sc_bulkin_pipe);
1119 if (err)
1120 printf("%s: abort rx pipe failed: %s\n",
1121 DEVNAME(sc), usbd_errstr(err));
1122 }
1123
1124 if (sc->sc_bulkout_pipe != NULL) {
1125 err = usbd_abort_pipe(sc->sc_bulkout_pipe);
1126 if (err)
1127 printf("%s: abort tx pipe failed: %s\n",
1128 DEVNAME(sc), usbd_errstr(err));
1129 }
1130
1131 for (i = 0; i < RNDIS_RX_LIST_CNT; i++) {
1132 if (sc->sc_data.sc_rx_chain[i].sc_mbuf != NULL) {
1133 m_freem(sc->sc_data.sc_rx_chain[i].sc_mbuf);
1134 sc->sc_data.sc_rx_chain[i].sc_mbuf = NULL;
1135 }
1136 if (sc->sc_data.sc_rx_chain[i].sc_xfer != NULL) {
1137 usbd_destroy_xfer(sc->sc_data.sc_rx_chain[i].sc_xfer);
1138 sc->sc_data.sc_rx_chain[i].sc_xfer = NULL;
1139 }
1140 }
1141
1142 for (i = 0; i < RNDIS_TX_LIST_CNT; i++) {
1143 if (sc->sc_data.sc_tx_chain[i].sc_mbuf != NULL) {
1144 m_freem(sc->sc_data.sc_tx_chain[i].sc_mbuf);
1145 sc->sc_data.sc_tx_chain[i].sc_mbuf = NULL;
1146 }
1147 if (sc->sc_data.sc_tx_chain[i].sc_xfer != NULL) {
1148 usbd_destroy_xfer(sc->sc_data.sc_tx_chain[i].sc_xfer);
1149 sc->sc_data.sc_tx_chain[i].sc_xfer = NULL;
1150 }
1151 }
1152
1153 /* Close pipes. */
1154 if (sc->sc_bulkin_pipe != NULL) {
1155 err = usbd_close_pipe(sc->sc_bulkin_pipe);
1156 if (err)
1157 printf("%s: close rx pipe failed: %s\n",
1158 DEVNAME(sc), usbd_errstr(err));
1159 sc->sc_bulkin_pipe = NULL;
1160 }
1161
1162 if (sc->sc_bulkout_pipe != NULL) {
1163 err = usbd_close_pipe(sc->sc_bulkout_pipe);
1164 if (err)
1165 printf("%s: close tx pipe failed: %s\n",
1166 DEVNAME(sc), usbd_errstr(err));
1167 sc->sc_bulkout_pipe = NULL;
1168 }
1169 }
1170
1171 static void
1172 urndis_start(struct ifnet *ifp)
1173 {
1174 struct urndis_softc *sc;
1175 struct mbuf *m_head = NULL;
1176
1177 sc = ifp->if_softc;
1178
1179 if (sc->sc_dying || (ifp->if_flags & IFF_OACTIVE))
1180 return;
1181
1182 IFQ_POLL(&ifp->if_snd, m_head);
1183 if (m_head == NULL)
1184 return;
1185
1186 if (urndis_encap(sc, m_head, 0)) {
1187 ifp->if_flags |= IFF_OACTIVE;
1188 return;
1189 }
1190 IFQ_DEQUEUE(&ifp->if_snd, m_head);
1191
1192 /*
1193 * If there's a BPF listener, bounce a copy of this frame
1194 * to him.
1195 */
1196 bpf_mtap(ifp, m_head, BPF_D_OUT);
1197
1198 ifp->if_flags |= IFF_OACTIVE;
1199
1200 /*
1201 * Set a timeout in case the chip goes out to lunch.
1202 */
1203 ifp->if_timer = 5;
1204
1205 return;
1206 }
1207
1208 static void
1209 urndis_rxeof(struct usbd_xfer *xfer,
1210 void *priv,
1211 usbd_status status)
1212 {
1213 struct urndis_chain *c;
1214 struct urndis_softc *sc;
1215 struct ifnet *ifp;
1216 uint32_t total_len;
1217
1218 c = priv;
1219 sc = c->sc_softc;
1220 ifp = GET_IFP(sc);
1221 total_len = 0;
1222
1223 if (sc->sc_dying || !(ifp->if_flags & IFF_RUNNING))
1224 return;
1225
1226 if (status != USBD_NORMAL_COMPLETION) {
1227 if (status == USBD_NOT_STARTED || status == USBD_CANCELLED)
1228 return;
1229 if (usbd_ratecheck(&sc->sc_rx_notice)) {
1230 printf("%s: usb errors on rx: %s\n",
1231 DEVNAME(sc), usbd_errstr(status));
1232 }
1233 if (status == USBD_STALLED)
1234 usbd_clear_endpoint_stall_async(sc->sc_bulkin_pipe);
1235
1236 goto done;
1237 }
1238
1239 usbd_get_xfer_status(xfer, NULL, NULL, &total_len, NULL);
1240 urndis_decap(sc, c, total_len);
1241
1242 done:
1243 /* Setup new transfer. */
1244 usbd_setup_xfer(c->sc_xfer, c, c->sc_buf, RNDIS_BUFSZ,
1245 USBD_SHORT_XFER_OK, USBD_NO_TIMEOUT, urndis_rxeof);
1246 usbd_transfer(c->sc_xfer);
1247 }
1248
1249 static void
1250 urndis_txeof(struct usbd_xfer *xfer,
1251 void *priv,
1252 usbd_status status)
1253 {
1254 struct urndis_chain *c;
1255 struct urndis_softc *sc;
1256 struct ifnet *ifp;
1257 usbd_status err;
1258 int s;
1259
1260 c = priv;
1261 sc = c->sc_softc;
1262 ifp = GET_IFP(sc);
1263
1264 DPRINTF(("%s: urndis_txeof\n", DEVNAME(sc)));
1265
1266 if (sc->sc_dying)
1267 return;
1268
1269 s = splnet();
1270
1271 ifp->if_timer = 0;
1272 ifp->if_flags &= ~IFF_OACTIVE;
1273
1274 if (status != USBD_NORMAL_COMPLETION) {
1275 if (status == USBD_NOT_STARTED || status == USBD_CANCELLED) {
1276 splx(s);
1277 return;
1278 }
1279 ifp->if_oerrors++;
1280 printf("%s: usb error on tx: %s\n", DEVNAME(sc),
1281 usbd_errstr(status));
1282 if (status == USBD_STALLED)
1283 usbd_clear_endpoint_stall_async(sc->sc_bulkout_pipe);
1284 splx(s);
1285 return;
1286 }
1287
1288 usbd_get_xfer_status(c->sc_xfer, NULL, NULL, NULL, &err);
1289
1290 if (c->sc_mbuf != NULL) {
1291 m_freem(c->sc_mbuf);
1292 c->sc_mbuf = NULL;
1293 }
1294
1295 if (err)
1296 ifp->if_oerrors++;
1297 else
1298 ifp->if_opackets++;
1299
1300 if (IFQ_IS_EMPTY(&ifp->if_snd) == 0)
1301 urndis_start(ifp);
1302
1303 splx(s);
1304 }
1305
1306 static int
1307 urndis_match(device_t parent, cfdata_t match, void *aux)
1308 {
1309 struct usbif_attach_arg *uiaa = aux;
1310 usb_interface_descriptor_t *id;
1311
1312 if (!uiaa->uiaa_iface)
1313 return UMATCH_NONE;
1314
1315 id = usbd_get_interface_descriptor(uiaa->uiaa_iface);
1316 if (id == NULL)
1317 return UMATCH_NONE;
1318
1319 if (id->bInterfaceClass == UICLASS_WIRELESS &&
1320 id->bInterfaceSubClass == UISUBCLASS_RF &&
1321 id->bInterfaceProtocol == UIPROTO_RNDIS)
1322 return UMATCH_IFACECLASS_IFACESUBCLASS_IFACEPROTO;
1323
1324 return usb_lookup(urndis_devs, uiaa->uiaa_vendor, uiaa->uiaa_product) != NULL ?
1325 UMATCH_VENDOR_PRODUCT : UMATCH_NONE;
1326 }
1327
1328 static void
1329 urndis_attach(device_t parent, device_t self, void *aux)
1330 {
1331 struct urndis_softc *sc;
1332 struct usbif_attach_arg *uiaa;
1333 struct ifnet *ifp;
1334 usb_interface_descriptor_t *id;
1335 usb_endpoint_descriptor_t *ed;
1336 usb_config_descriptor_t *cd;
1337 const usb_cdc_union_descriptor_t *ud;
1338 const usb_cdc_header_descriptor_t *desc;
1339 usbd_desc_iter_t iter;
1340 int if_ctl, if_data;
1341 int i, j, altcnt;
1342 int s;
1343 u_char eaddr[ETHER_ADDR_LEN];
1344 void *buf;
1345 size_t bufsz;
1346 uint32_t filter;
1347 char *devinfop;
1348
1349 sc = device_private(self);
1350 uiaa = aux;
1351 sc->sc_dev = self;
1352 sc->sc_udev = uiaa->uiaa_device;
1353
1354 aprint_naive("\n");
1355 aprint_normal("\n");
1356
1357 devinfop = usbd_devinfo_alloc(uiaa->uiaa_device, 0);
1358 aprint_normal_dev(self, "%s\n", devinfop);
1359 usbd_devinfo_free(devinfop);
1360
1361 sc->sc_iface_ctl = uiaa->uiaa_iface;
1362 id = usbd_get_interface_descriptor(sc->sc_iface_ctl);
1363 if_ctl = id->bInterfaceNumber;
1364 sc->sc_ifaceno_ctl = if_ctl;
1365 if_data = -1;
1366
1367 usb_desc_iter_init(sc->sc_udev, &iter);
1368 while ((desc = (const void *)usb_desc_iter_next(&iter)) != NULL) {
1369
1370 if (desc->bDescriptorType != UDESC_CS_INTERFACE) {
1371 continue;
1372 }
1373 switch (desc->bDescriptorSubtype) {
1374 case UDESCSUB_CDC_UNION:
1375 /* XXX bail out when found first? */
1376 ud = (const usb_cdc_union_descriptor_t *)desc;
1377 if (if_data == -1)
1378 if_data = ud->bSlaveInterface[0];
1379 break;
1380 }
1381 }
1382
1383 if (if_data == -1) {
1384 DPRINTF(("urndis_attach: no union interface\n"));
1385 sc->sc_iface_data = sc->sc_iface_ctl;
1386 } else {
1387 DPRINTF(("urndis_attach: union interface: ctl %u, data %u\n",
1388 if_ctl, if_data));
1389 for (i = 0; i < uiaa->uiaa_nifaces; i++) {
1390 if (uiaa->uiaa_ifaces[i] != NULL) {
1391 id = usbd_get_interface_descriptor(
1392 uiaa->uiaa_ifaces[i]);
1393 if (id != NULL && id->bInterfaceNumber ==
1394 if_data) {
1395 sc->sc_iface_data = uiaa->uiaa_ifaces[i];
1396 uiaa->uiaa_ifaces[i] = NULL;
1397 }
1398 }
1399 }
1400 }
1401
1402 if (sc->sc_iface_data == NULL) {
1403 aprint_error("%s: no data interface\n", DEVNAME(sc));
1404 return;
1405 }
1406
1407 id = usbd_get_interface_descriptor(sc->sc_iface_data);
1408 cd = usbd_get_config_descriptor(sc->sc_udev);
1409 altcnt = usbd_get_no_alts(cd, id->bInterfaceNumber);
1410
1411 for (j = 0; j < altcnt; j++) {
1412 if (usbd_set_interface(sc->sc_iface_data, j)) {
1413 aprint_error("%s: interface alternate setting %u "
1414 "failed\n", DEVNAME(sc), j);
1415 return;
1416 }
1417 /* Find endpoints. */
1418 id = usbd_get_interface_descriptor(sc->sc_iface_data);
1419 sc->sc_bulkin_no = sc->sc_bulkout_no = -1;
1420 for (i = 0; i < id->bNumEndpoints; i++) {
1421 ed = usbd_interface2endpoint_descriptor(
1422 sc->sc_iface_data, i);
1423 if (!ed) {
1424 aprint_error("%s: no descriptor for bulk "
1425 "endpoint %u\n", DEVNAME(sc), i);
1426 return;
1427 }
1428 if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN &&
1429 UE_GET_XFERTYPE(ed->bmAttributes) == UE_BULK) {
1430 sc->sc_bulkin_no = ed->bEndpointAddress;
1431 }
1432 else if (
1433 UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_OUT &&
1434 UE_GET_XFERTYPE(ed->bmAttributes) == UE_BULK) {
1435 sc->sc_bulkout_no = ed->bEndpointAddress;
1436 }
1437 }
1438
1439 if (sc->sc_bulkin_no != -1 && sc->sc_bulkout_no != -1) {
1440 DPRINTF(("%s: in=0x%x, out=0x%x\n",
1441 DEVNAME(sc),
1442 sc->sc_bulkin_no,
1443 sc->sc_bulkout_no));
1444 goto found;
1445 }
1446 }
1447
1448 if (sc->sc_bulkin_no == -1)
1449 aprint_error("%s: could not find data bulk in\n", DEVNAME(sc));
1450 if (sc->sc_bulkout_no == -1 )
1451 aprint_error("%s: could not find data bulk out\n",DEVNAME(sc));
1452 return;
1453
1454 found:
1455
1456 ifp = GET_IFP(sc);
1457 ifp->if_softc = sc;
1458 ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
1459 ifp->if_start = urndis_start;
1460 ifp->if_ioctl = urndis_ioctl;
1461 ifp->if_init = urndis_init;
1462 #if 0
1463 ifp->if_watchdog = urndis_watchdog;
1464 #endif
1465
1466 strlcpy(ifp->if_xname, DEVNAME(sc), IFNAMSIZ);
1467
1468 IFQ_SET_READY(&ifp->if_snd);
1469
1470 urndis_init(ifp);
1471
1472 s = splnet();
1473
1474 if (urndis_ctrl_query(sc, OID_802_3_PERMANENT_ADDRESS, NULL, 0,
1475 &buf, &bufsz) != RNDIS_STATUS_SUCCESS) {
1476 aprint_error("%s: unable to get hardware address\n",
1477 DEVNAME(sc));
1478 urndis_stop(ifp);
1479 splx(s);
1480 return;
1481 }
1482
1483 if (bufsz == ETHER_ADDR_LEN) {
1484 memcpy(eaddr, buf, ETHER_ADDR_LEN);
1485 aprint_normal("%s: address %s\n", DEVNAME(sc),
1486 ether_sprintf(eaddr));
1487 kmem_free(buf, bufsz);
1488 } else {
1489 aprint_error("%s: invalid address\n", DEVNAME(sc));
1490 kmem_free(buf, bufsz);
1491 urndis_stop(ifp);
1492 splx(s);
1493 return;
1494 }
1495
1496 /* Initialize packet filter */
1497 sc->sc_filter = RNDIS_PACKET_TYPE_BROADCAST;
1498 sc->sc_filter |= RNDIS_PACKET_TYPE_ALL_MULTICAST;
1499 filter = htole32(sc->sc_filter);
1500 if (urndis_ctrl_set(sc, OID_GEN_CURRENT_PACKET_FILTER, &filter,
1501 sizeof(filter)) != RNDIS_STATUS_SUCCESS) {
1502 aprint_error("%s: unable to set data filters\n", DEVNAME(sc));
1503 urndis_stop(ifp);
1504 splx(s);
1505 return;
1506 }
1507
1508 if_attach(ifp);
1509 ether_ifattach(ifp, eaddr);
1510 sc->sc_attached = 1;
1511
1512 splx(s);
1513 }
1514
1515 static int
1516 urndis_detach(device_t self, int flags)
1517 {
1518 struct urndis_softc *sc;
1519 struct ifnet *ifp;
1520 int s;
1521
1522 sc = device_private(self);
1523
1524 DPRINTF(("urndis_detach: %s flags %u\n", DEVNAME(sc),
1525 flags));
1526
1527 if (!sc->sc_attached)
1528 return 0;
1529
1530 s = splusb();
1531
1532 ifp = GET_IFP(sc);
1533
1534 if (ifp->if_softc != NULL) {
1535 ether_ifdetach(ifp);
1536 if_detach(ifp);
1537 }
1538
1539 urndis_stop(ifp);
1540 sc->sc_attached = 0;
1541
1542 splx(s);
1543
1544 return 0;
1545 }
1546
1547 static int
1548 urndis_activate(device_t self, enum devact act)
1549 {
1550 struct urndis_softc *sc;
1551
1552 sc = device_private(self);
1553
1554 switch (act) {
1555 case DVACT_DEACTIVATE:
1556 sc->sc_dying = 1;
1557 return 0;
1558 }
1559
1560 return EOPNOTSUPP;
1561 }
1562