if_urndis.c revision 1.9.4.16 1 /* $NetBSD: if_urndis.c,v 1.9.4.16 2017/02/05 13:40:46 skrll Exp $ */
2 /* $OpenBSD: if_urndis.c,v 1.31 2011/07/03 15:47:17 matthew Exp $ */
3
4 /*
5 * Copyright (c) 2010 Jonathan Armani <armani (at) openbsd.org>
6 * Copyright (c) 2010 Fabien Romano <fabien (at) openbsd.org>
7 * Copyright (c) 2010 Michael Knudsen <mk (at) openbsd.org>
8 * All rights reserved.
9 *
10 * Permission to use, copy, modify, and distribute this software for any
11 * purpose with or without fee is hereby granted, provided that the above
12 * copyright notice and this permission notice appear in all copies.
13 *
14 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
15 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
16 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
17 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
18 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
19 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
20 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
21 */
22
23 #include <sys/cdefs.h>
24 __KERNEL_RCSID(0, "$NetBSD: if_urndis.c,v 1.9.4.16 2017/02/05 13:40:46 skrll Exp $");
25
26 #ifdef _KERNEL_OPT
27 #include "opt_usb.h"
28 #endif
29
30 #include <sys/param.h>
31 #include <sys/systm.h>
32 #include <sys/sockio.h>
33 #include <sys/rwlock.h>
34 #include <sys/mbuf.h>
35 #include <sys/kmem.h>
36 #include <sys/kernel.h>
37 #include <sys/proc.h>
38 #include <sys/socket.h>
39 #include <sys/device.h>
40
41 #include <net/if.h>
42 #include <net/if_dl.h>
43 #include <net/if_media.h>
44 #include <net/if_ether.h>
45
46 #include <net/bpf.h>
47
48 #include <sys/bus.h>
49 #include <dev/usb/usb.h>
50 #include <dev/usb/usbdi.h>
51 #include <dev/usb/usbdi_util.h>
52 #include <dev/usb/usbdivar.h>
53 #include <dev/usb/usbdevs.h>
54 #include <dev/usb/usbcdc.h>
55
56 #include <dev/usb/if_urndisreg.h>
57
58 #ifdef URNDIS_DEBUG
59 #define DPRINTF(x) do { printf x; } while (0)
60 #else
61 #define DPRINTF(x)
62 #endif
63
64 #define DEVNAME(sc) (device_xname(sc->sc_dev))
65
66 #define ETHER_ALIGN 2
67 #define URNDIS_RESPONSE_LEN 0x400
68
69
70 static int urndis_newbuf(struct urndis_softc *, struct urndis_chain *);
71
72 static int urndis_ioctl(struct ifnet *, unsigned long, void *);
73 #if 0
74 static void urndis_watchdog(struct ifnet *);
75 #endif
76
77 static void urndis_start(struct ifnet *);
78 static void urndis_start_locked(struct ifnet *);
79 static void urndis_rxeof(struct usbd_xfer *, void *, usbd_status);
80 static void urndis_txeof(struct usbd_xfer *, void *, usbd_status);
81 static int urndis_rx_list_init(struct urndis_softc *);
82 static void urndis_rx_list_free(struct urndis_softc *);
83 static int urndis_tx_list_init(struct urndis_softc *);
84 static void urndis_tx_list_free(struct urndis_softc *);
85
86 static int urndis_init(struct ifnet *);
87 static int urndis_init_locked(struct ifnet *);
88 static void urndis_stop(struct ifnet *);
89 static void urndis_stop_locked(struct ifnet *);
90
91 static usbd_status urndis_ctrl_msg(struct urndis_softc *, uint8_t, uint8_t,
92 uint16_t, uint16_t, void *, size_t);
93 static usbd_status urndis_ctrl_send(struct urndis_softc *, void *, size_t);
94 static struct urndis_comp_hdr *urndis_ctrl_recv(struct urndis_softc *);
95
96 static uint32_t urndis_ctrl_handle(struct urndis_softc *,
97 struct urndis_comp_hdr *, void **, size_t *);
98 static uint32_t urndis_ctrl_handle_init(struct urndis_softc *,
99 const struct urndis_comp_hdr *);
100 static uint32_t urndis_ctrl_handle_query(struct urndis_softc *,
101 const struct urndis_comp_hdr *, void **, size_t *);
102 static uint32_t urndis_ctrl_handle_reset(struct urndis_softc *,
103 const struct urndis_comp_hdr *);
104
105 static uint32_t urndis_ctrl_init(struct urndis_softc *);
106 #if 0
107 static uint32_t urndis_ctrl_halt(struct urndis_softc *);
108 #endif
109 static uint32_t urndis_ctrl_query(struct urndis_softc *, uint32_t, void *,
110 size_t, void **, size_t *);
111 static uint32_t urndis_ctrl_set(struct urndis_softc *, uint32_t, void *,
112 size_t);
113 #if 0
114 static uint32_t urndis_ctrl_set_param(struct urndis_softc *, const char *,
115 uint32_t, void *, size_t);
116 static uint32_t urndis_ctrl_reset(struct urndis_softc *);
117 static uint32_t urndis_ctrl_keepalive(struct urndis_softc *);
118 #endif
119
120 static int urndis_encap(struct urndis_softc *, struct mbuf *, int);
121 static void urndis_decap(struct urndis_softc *, struct urndis_chain *,
122 uint32_t);
123
124 static int urndis_match(device_t, cfdata_t, void *);
125 static void urndis_attach(device_t, device_t, void *);
126 static int urndis_detach(device_t, int);
127 static int urndis_activate(device_t, enum devact);
128
129 CFATTACH_DECL_NEW(urndis, sizeof(struct urndis_softc),
130 urndis_match, urndis_attach, urndis_detach, urndis_activate);
131
132 /*
133 * Supported devices that we can't match by class IDs.
134 */
135 static const struct usb_devno urndis_devs[] = {
136 { USB_VENDOR_HTC, USB_PRODUCT_HTC_ANDROID },
137 { USB_VENDOR_SAMSUNG, USB_PRODUCT_SAMSUNG_ANDROID2 },
138 };
139
140 static usbd_status
141 urndis_ctrl_msg(struct urndis_softc *sc, uint8_t rt, uint8_t r,
142 uint16_t index, uint16_t value, void *buf, size_t buflen)
143 {
144 usb_device_request_t req;
145
146 req.bmRequestType = rt;
147 req.bRequest = r;
148 USETW(req.wValue, value);
149 USETW(req.wIndex, index);
150 USETW(req.wLength, buflen);
151
152 return usbd_do_request(sc->sc_udev, &req, buf);
153 }
154
155 static usbd_status
156 urndis_ctrl_send(struct urndis_softc *sc, void *buf, size_t len)
157 {
158 usbd_status err;
159
160 if (sc->sc_dying)
161 return(0);
162
163 err = urndis_ctrl_msg(sc, UT_WRITE_CLASS_INTERFACE, UR_GET_STATUS,
164 sc->sc_ifaceno_ctl, 0, buf, len);
165
166 if (err != USBD_NORMAL_COMPLETION)
167 printf("%s: %s\n", DEVNAME(sc), usbd_errstr(err));
168
169 return err;
170 }
171
172 static struct urndis_comp_hdr *
173 urndis_ctrl_recv(struct urndis_softc *sc)
174 {
175 struct urndis_comp_hdr *hdr;
176 char *buf;
177 usbd_status err;
178
179 buf = kmem_alloc(URNDIS_RESPONSE_LEN, KM_SLEEP);
180 if (buf == NULL) {
181 printf("%s: out of memory\n", DEVNAME(sc));
182 return NULL;
183 }
184
185 err = urndis_ctrl_msg(sc, UT_READ_CLASS_INTERFACE, UR_CLEAR_FEATURE,
186 sc->sc_ifaceno_ctl, 0, buf, URNDIS_RESPONSE_LEN);
187
188 if (err != USBD_NORMAL_COMPLETION && err != USBD_SHORT_XFER) {
189 printf("%s: %s\n", DEVNAME(sc), usbd_errstr(err));
190 kmem_free(buf, URNDIS_RESPONSE_LEN);
191 return NULL;
192 }
193
194 hdr = (struct urndis_comp_hdr *)buf;
195 DPRINTF(("%s: urndis_ctrl_recv: type 0x%x len %u\n",
196 DEVNAME(sc),
197 le32toh(hdr->rm_type),
198 le32toh(hdr->rm_len)));
199
200 if (le32toh(hdr->rm_len) > URNDIS_RESPONSE_LEN) {
201 printf("%s: ctrl message error: wrong size %u > %u\n",
202 DEVNAME(sc),
203 le32toh(hdr->rm_len),
204 URNDIS_RESPONSE_LEN);
205 kmem_free(buf, URNDIS_RESPONSE_LEN);
206 return NULL;
207 }
208
209 return hdr;
210 }
211
212 static uint32_t
213 urndis_ctrl_handle(struct urndis_softc *sc, struct urndis_comp_hdr *hdr,
214 void **buf, size_t *bufsz)
215 {
216 uint32_t rval;
217
218 DPRINTF(("%s: urndis_ctrl_handle\n", DEVNAME(sc)));
219
220 if (buf && bufsz) {
221 *buf = NULL;
222 *bufsz = 0;
223 }
224
225 switch (le32toh(hdr->rm_type)) {
226 case REMOTE_NDIS_INITIALIZE_CMPLT:
227 rval = urndis_ctrl_handle_init(sc, hdr);
228 break;
229
230 case REMOTE_NDIS_QUERY_CMPLT:
231 rval = urndis_ctrl_handle_query(sc, hdr, buf, bufsz);
232 break;
233
234 case REMOTE_NDIS_RESET_CMPLT:
235 rval = urndis_ctrl_handle_reset(sc, hdr);
236 break;
237
238 case REMOTE_NDIS_KEEPALIVE_CMPLT:
239 case REMOTE_NDIS_SET_CMPLT:
240 rval = le32toh(hdr->rm_status);
241 break;
242
243 default:
244 printf("%s: ctrl message error: unknown event 0x%x\n",
245 DEVNAME(sc), le32toh(hdr->rm_type));
246 rval = RNDIS_STATUS_FAILURE;
247 }
248
249 kmem_free(hdr, URNDIS_RESPONSE_LEN);
250
251 return rval;
252 }
253
254 static uint32_t
255 urndis_ctrl_handle_init(struct urndis_softc *sc,
256 const struct urndis_comp_hdr *hdr)
257 {
258 const struct urndis_init_comp *msg;
259
260 msg = (const struct urndis_init_comp *) hdr;
261
262 DPRINTF(("%s: urndis_ctrl_handle_init: len %u rid %u status 0x%x "
263 "ver_major %u ver_minor %u devflags 0x%x medium 0x%x pktmaxcnt %u "
264 "pktmaxsz %u align %u aflistoffset %u aflistsz %u\n",
265 DEVNAME(sc),
266 le32toh(msg->rm_len),
267 le32toh(msg->rm_rid),
268 le32toh(msg->rm_status),
269 le32toh(msg->rm_ver_major),
270 le32toh(msg->rm_ver_minor),
271 le32toh(msg->rm_devflags),
272 le32toh(msg->rm_medium),
273 le32toh(msg->rm_pktmaxcnt),
274 le32toh(msg->rm_pktmaxsz),
275 le32toh(msg->rm_align),
276 le32toh(msg->rm_aflistoffset),
277 le32toh(msg->rm_aflistsz)));
278
279 if (le32toh(msg->rm_status) != RNDIS_STATUS_SUCCESS) {
280 printf("%s: init failed 0x%x\n",
281 DEVNAME(sc),
282 le32toh(msg->rm_status));
283
284 return le32toh(msg->rm_status);
285 }
286
287 if (le32toh(msg->rm_devflags) != RNDIS_DF_CONNECTIONLESS) {
288 printf("%s: wrong device type (current type: 0x%x)\n",
289 DEVNAME(sc),
290 le32toh(msg->rm_devflags));
291
292 return RNDIS_STATUS_FAILURE;
293 }
294
295 if (le32toh(msg->rm_medium) != RNDIS_MEDIUM_802_3) {
296 printf("%s: medium not 802.3 (current medium: 0x%x)\n",
297 DEVNAME(sc), le32toh(msg->rm_medium));
298
299 return RNDIS_STATUS_FAILURE;
300 }
301
302 sc->sc_lim_pktsz = le32toh(msg->rm_pktmaxsz);
303
304 return le32toh(msg->rm_status);
305 }
306
307 static uint32_t
308 urndis_ctrl_handle_query(struct urndis_softc *sc,
309 const struct urndis_comp_hdr *hdr, void **buf, size_t *bufsz)
310 {
311 const struct urndis_query_comp *msg;
312
313 msg = (const struct urndis_query_comp *) hdr;
314
315 DPRINTF(("%s: urndis_ctrl_handle_query: len %u rid %u status 0x%x "
316 "buflen %u bufoff %u\n",
317 DEVNAME(sc),
318 le32toh(msg->rm_len),
319 le32toh(msg->rm_rid),
320 le32toh(msg->rm_status),
321 le32toh(msg->rm_infobuflen),
322 le32toh(msg->rm_infobufoffset)));
323
324 if (buf && bufsz) {
325 *buf = NULL;
326 *bufsz = 0;
327 }
328
329 if (le32toh(msg->rm_status) != RNDIS_STATUS_SUCCESS) {
330 printf("%s: query failed 0x%x\n",
331 DEVNAME(sc),
332 le32toh(msg->rm_status));
333
334 return le32toh(msg->rm_status);
335 }
336
337 if (le32toh(msg->rm_infobuflen) + le32toh(msg->rm_infobufoffset) +
338 RNDIS_HEADER_OFFSET > le32toh(msg->rm_len)) {
339 printf("%s: ctrl message error: invalid query info "
340 "len/offset/end_position(%u/%u/%u) -> "
341 "go out of buffer limit %u\n",
342 DEVNAME(sc),
343 le32toh(msg->rm_infobuflen),
344 le32toh(msg->rm_infobufoffset),
345 le32toh(msg->rm_infobuflen) +
346 le32toh(msg->rm_infobufoffset) + (uint32_t)RNDIS_HEADER_OFFSET,
347 le32toh(msg->rm_len));
348 return RNDIS_STATUS_FAILURE;
349 }
350
351 if (buf && bufsz) {
352 *buf = kmem_alloc(le32toh(msg->rm_infobuflen), KM_SLEEP);
353 if (*buf == NULL) {
354 printf("%s: out of memory\n", DEVNAME(sc));
355 return RNDIS_STATUS_FAILURE;
356 } else {
357 const char *p;
358 *bufsz = le32toh(msg->rm_infobuflen);
359
360 p = (const char *)&msg->rm_rid;
361 p += le32toh(msg->rm_infobufoffset);
362 memcpy(*buf, p, le32toh(msg->rm_infobuflen));
363 }
364 }
365
366 return le32toh(msg->rm_status);
367 }
368
369 static uint32_t
370 urndis_ctrl_handle_reset(struct urndis_softc *sc,
371 const struct urndis_comp_hdr *hdr)
372 {
373 const struct urndis_reset_comp *msg;
374 uint32_t rval;
375
376 msg = (const struct urndis_reset_comp *) hdr;
377
378 rval = le32toh(msg->rm_status);
379
380 DPRINTF(("%s: urndis_ctrl_handle_reset: len %u status 0x%x "
381 "adrreset %u\n",
382 DEVNAME(sc),
383 le32toh(msg->rm_len),
384 rval,
385 le32toh(msg->rm_adrreset)));
386
387 if (rval != RNDIS_STATUS_SUCCESS) {
388 printf("%s: reset failed 0x%x\n", DEVNAME(sc), rval);
389 return rval;
390 }
391
392 if (le32toh(msg->rm_adrreset) != 0) {
393 uint32_t filter;
394
395 filter = htole32(sc->sc_filter);
396 rval = urndis_ctrl_set(sc, OID_GEN_CURRENT_PACKET_FILTER,
397 &filter, sizeof(filter));
398 if (rval != RNDIS_STATUS_SUCCESS) {
399 printf("%s: unable to reset data filters\n",
400 DEVNAME(sc));
401 return rval;
402 }
403 }
404
405 return rval;
406 }
407
408 static uint32_t
409 urndis_ctrl_init(struct urndis_softc *sc)
410 {
411 struct urndis_init_req *msg;
412 uint32_t rval;
413 struct urndis_comp_hdr *hdr;
414
415 msg = kmem_alloc(sizeof(*msg), KM_SLEEP);
416 if (msg == NULL) {
417 printf("%s: out of memory\n", DEVNAME(sc));
418 return RNDIS_STATUS_FAILURE;
419 }
420
421 msg->rm_type = htole32(REMOTE_NDIS_INITIALIZE_MSG);
422 msg->rm_len = htole32(sizeof(*msg));
423 msg->rm_rid = htole32(0);
424 msg->rm_ver_major = htole32(1);
425 msg->rm_ver_minor = htole32(1);
426 msg->rm_max_xfersz = htole32(RNDIS_BUFSZ);
427
428 DPRINTF(("%s: urndis_ctrl_init send: type %u len %u rid %u ver_major %u "
429 "ver_minor %u max_xfersz %u\n",
430 DEVNAME(sc),
431 le32toh(msg->rm_type),
432 le32toh(msg->rm_len),
433 le32toh(msg->rm_rid),
434 le32toh(msg->rm_ver_major),
435 le32toh(msg->rm_ver_minor),
436 le32toh(msg->rm_max_xfersz)));
437
438 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
439 kmem_free(msg, sizeof(*msg));
440
441 if (rval != RNDIS_STATUS_SUCCESS) {
442 printf("%s: init failed\n", DEVNAME(sc));
443 return rval;
444 }
445
446 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
447 printf("%s: unable to get init response\n", DEVNAME(sc));
448 return RNDIS_STATUS_FAILURE;
449 }
450 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
451
452 return rval;
453 }
454
455 #if 0
456 static uint32_t
457 urndis_ctrl_halt(struct urndis_softc *sc)
458 {
459 struct urndis_halt_req *msg;
460 uint32_t rval;
461
462 msg = kmem_alloc(sizeof(*msg), KM_SLEEP);
463 if (msg == NULL) {
464 printf("%s: out of memory\n", DEVNAME(sc));
465 return RNDIS_STATUS_FAILURE;
466 }
467
468 msg->rm_type = htole32(REMOTE_NDIS_HALT_MSG);
469 msg->rm_len = htole32(sizeof(*msg));
470 msg->rm_rid = 0;
471
472 DPRINTF(("%s: urndis_ctrl_halt send: type %u len %u rid %u\n",
473 DEVNAME(sc),
474 le32toh(msg->rm_type),
475 le32toh(msg->rm_len),
476 le32toh(msg->rm_rid)));
477
478 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
479 kmem_free(msg, sizeof(*msg));
480
481 if (rval != RNDIS_STATUS_SUCCESS)
482 printf("%s: halt failed\n", DEVNAME(sc));
483
484 return rval;
485 }
486 #endif
487
488 static uint32_t
489 urndis_ctrl_query(struct urndis_softc *sc, uint32_t oid,
490 void *qbuf, size_t qlen,
491 void **rbuf, size_t *rbufsz)
492 {
493 struct urndis_query_req *msg;
494 uint32_t rval;
495 struct urndis_comp_hdr *hdr;
496
497 msg = kmem_alloc(sizeof(*msg) + qlen, KM_SLEEP);
498 if (msg == NULL) {
499 printf("%s: out of memory\n", DEVNAME(sc));
500 return RNDIS_STATUS_FAILURE;
501 }
502
503 msg->rm_type = htole32(REMOTE_NDIS_QUERY_MSG);
504 msg->rm_len = htole32(sizeof(*msg) + qlen);
505 msg->rm_rid = 0; /* XXX */
506 msg->rm_oid = htole32(oid);
507 msg->rm_infobuflen = htole32(qlen);
508 if (qlen != 0) {
509 msg->rm_infobufoffset = htole32(20);
510 memcpy((char*)msg + 20, qbuf, qlen);
511 } else
512 msg->rm_infobufoffset = 0;
513 msg->rm_devicevchdl = 0;
514
515 DPRINTF(("%s: urndis_ctrl_query send: type %u len %u rid %u oid 0x%x "
516 "infobuflen %u infobufoffset %u devicevchdl %u\n",
517 DEVNAME(sc),
518 le32toh(msg->rm_type),
519 le32toh(msg->rm_len),
520 le32toh(msg->rm_rid),
521 le32toh(msg->rm_oid),
522 le32toh(msg->rm_infobuflen),
523 le32toh(msg->rm_infobufoffset),
524 le32toh(msg->rm_devicevchdl)));
525
526 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
527 kmem_free(msg, sizeof(*msg) + qlen);
528
529 if (rval != RNDIS_STATUS_SUCCESS) {
530 printf("%s: query failed\n", DEVNAME(sc));
531 return rval;
532 }
533
534 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
535 printf("%s: unable to get query response\n", DEVNAME(sc));
536 return RNDIS_STATUS_FAILURE;
537 }
538 rval = urndis_ctrl_handle(sc, hdr, rbuf, rbufsz);
539
540 return rval;
541 }
542
543 static uint32_t
544 urndis_ctrl_set(struct urndis_softc *sc, uint32_t oid, void *buf, size_t len)
545 {
546 struct urndis_set_req *msg;
547 uint32_t rval;
548 struct urndis_comp_hdr *hdr;
549
550 msg = kmem_alloc(sizeof(*msg) + len, KM_SLEEP);
551 if (msg == NULL) {
552 printf("%s: out of memory\n", DEVNAME(sc));
553 return RNDIS_STATUS_FAILURE;
554 }
555
556 msg->rm_type = htole32(REMOTE_NDIS_SET_MSG);
557 msg->rm_len = htole32(sizeof(*msg) + len);
558 msg->rm_rid = 0; /* XXX */
559 msg->rm_oid = htole32(oid);
560 msg->rm_infobuflen = htole32(len);
561 if (len != 0) {
562 msg->rm_infobufoffset = htole32(20);
563 memcpy((char*)msg + 20, buf, len);
564 } else
565 msg->rm_infobufoffset = 0;
566 msg->rm_devicevchdl = 0;
567
568 DPRINTF(("%s: urndis_ctrl_set send: type %u len %u rid %u oid 0x%x "
569 "infobuflen %u infobufoffset %u devicevchdl %u\n",
570 DEVNAME(sc),
571 le32toh(msg->rm_type),
572 le32toh(msg->rm_len),
573 le32toh(msg->rm_rid),
574 le32toh(msg->rm_oid),
575 le32toh(msg->rm_infobuflen),
576 le32toh(msg->rm_infobufoffset),
577 le32toh(msg->rm_devicevchdl)));
578
579 rval = urndis_ctrl_send(sc, msg, sizeof(*msg));
580 kmem_free(msg, sizeof(*msg) + len);
581
582 if (rval != RNDIS_STATUS_SUCCESS) {
583 printf("%s: set failed\n", DEVNAME(sc));
584 return rval;
585 }
586
587 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
588 printf("%s: unable to get set response\n", DEVNAME(sc));
589 return RNDIS_STATUS_FAILURE;
590 }
591 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
592 if (rval != RNDIS_STATUS_SUCCESS)
593 printf("%s: set failed 0x%x\n", DEVNAME(sc), rval);
594
595 return rval;
596 }
597
598 #if 0
599 static uint32_t
600 urndis_ctrl_set_param(struct urndis_softc *sc,
601 const char *name,
602 uint32_t type,
603 void *buf,
604 size_t len)
605 {
606 struct urndis_set_parameter *param;
607 uint32_t rval;
608 size_t namelen, tlen;
609
610 if (name)
611 namelen = strlen(name);
612 else
613 namelen = 0;
614 tlen = sizeof(*param) + len + namelen;
615 param = kmem_alloc(tlen, KM_SLEEP);
616 if (param == NULL) {
617 printf("%s: out of memory\n", DEVNAME(sc));
618 return RNDIS_STATUS_FAILURE;
619 }
620
621 param->rm_namelen = htole32(namelen);
622 param->rm_valuelen = htole32(len);
623 param->rm_type = htole32(type);
624 if (namelen != 0) {
625 param->rm_nameoffset = htole32(20);
626 memcpy(param + 20, name, namelen);
627 } else
628 param->rm_nameoffset = 0;
629 if (len != 0) {
630 param->rm_valueoffset = htole32(20 + namelen);
631 memcpy(param + 20 + namelen, buf, len);
632 } else
633 param->rm_valueoffset = 0;
634
635 DPRINTF(("%s: urndis_ctrl_set_param send: nameoffset %u namelen %u "
636 "type 0x%x valueoffset %u valuelen %u\n",
637 DEVNAME(sc),
638 le32toh(param->rm_nameoffset),
639 le32toh(param->rm_namelen),
640 le32toh(param->rm_type),
641 le32toh(param->rm_valueoffset),
642 le32toh(param->rm_valuelen)));
643
644 rval = urndis_ctrl_set(sc, OID_GEN_RNDIS_CONFIG_PARAMETER, param, tlen);
645 kmem_free(param, tlen);
646 if (rval != RNDIS_STATUS_SUCCESS)
647 printf("%s: set param failed 0x%x\n", DEVNAME(sc), rval);
648
649 return rval;
650 }
651
652 /* XXX : adrreset, get it from response */
653 static uint32_t
654 urndis_ctrl_reset(struct urndis_softc *sc)
655 {
656 struct urndis_reset_req *reset;
657 uint32_t rval;
658 struct urndis_comp_hdr *hdr;
659
660 reset = kmem_alloc(sizeof(*reset), KM_SLEEP);
661 if (reset == NULL) {
662 printf("%s: out of memory\n", DEVNAME(sc));
663 return RNDIS_STATUS_FAILURE;
664 }
665
666 reset->rm_type = htole32(REMOTE_NDIS_RESET_MSG);
667 reset->rm_len = htole32(sizeof(*reset));
668 reset->rm_rid = 0; /* XXX rm_rid == reserved ... remove ? */
669
670 DPRINTF(("%s: urndis_ctrl_reset send: type %u len %u rid %u\n",
671 DEVNAME(sc),
672 le32toh(reset->rm_type),
673 le32toh(reset->rm_len),
674 le32toh(reset->rm_rid)));
675
676 rval = urndis_ctrl_send(sc, reset, sizeof(*reset));
677 kmem_free(reset, sizeof(*reset));
678
679 if (rval != RNDIS_STATUS_SUCCESS) {
680 printf("%s: reset failed\n", DEVNAME(sc));
681 return rval;
682 }
683
684 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
685 printf("%s: unable to get reset response\n", DEVNAME(sc));
686 return RNDIS_STATUS_FAILURE;
687 }
688 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
689
690 return rval;
691 }
692
693 static uint32_t
694 urndis_ctrl_keepalive(struct urndis_softc *sc)
695 {
696 struct urndis_keepalive_req *keep;
697 uint32_t rval;
698 struct urndis_comp_hdr *hdr;
699
700 keep = kmem_alloc(sizeof(*keep), KM_SLEEP);
701 if (keep == NULL) {
702 printf("%s: out of memory\n", DEVNAME(sc));
703 return RNDIS_STATUS_FAILURE;
704 }
705
706 keep->rm_type = htole32(REMOTE_NDIS_KEEPALIVE_MSG);
707 keep->rm_len = htole32(sizeof(*keep));
708 keep->rm_rid = 0; /* XXX rm_rid == reserved ... remove ? */
709
710 DPRINTF(("%s: urndis_ctrl_keepalive: type %u len %u rid %u\n",
711 DEVNAME(sc),
712 le32toh(keep->rm_type),
713 le32toh(keep->rm_len),
714 le32toh(keep->rm_rid)));
715
716 rval = urndis_ctrl_send(sc, keep, sizeof(*keep));
717 kmem_free(keep, sizeof(*keep));
718
719 if (rval != RNDIS_STATUS_SUCCESS) {
720 printf("%s: keepalive failed\n", DEVNAME(sc));
721 return rval;
722 }
723
724 if ((hdr = urndis_ctrl_recv(sc)) == NULL) {
725 printf("%s: unable to get keepalive response\n", DEVNAME(sc));
726 return RNDIS_STATUS_FAILURE;
727 }
728 rval = urndis_ctrl_handle(sc, hdr, NULL, NULL);
729 if (rval != RNDIS_STATUS_SUCCESS) {
730 printf("%s: keepalive failed 0x%x\n", DEVNAME(sc), rval);
731 urndis_ctrl_reset(sc);
732 }
733
734 return rval;
735 }
736 #endif
737
738 static int
739 urndis_encap(struct urndis_softc *sc, struct mbuf *m, int idx)
740 {
741 struct urndis_chain *c;
742 usbd_status err;
743 struct urndis_packet_msg *msg;
744
745 c = &sc->sc_data.sc_tx_chain[idx];
746
747 msg = (struct urndis_packet_msg *)c->sc_buf;
748
749 memset(msg, 0, sizeof(*msg));
750 msg->rm_type = htole32(REMOTE_NDIS_PACKET_MSG);
751 msg->rm_len = htole32(sizeof(*msg) + m->m_pkthdr.len);
752
753 msg->rm_dataoffset = htole32(RNDIS_DATA_OFFSET);
754 msg->rm_datalen = htole32(m->m_pkthdr.len);
755
756 m_copydata(m, 0, m->m_pkthdr.len,
757 ((char*)msg + RNDIS_DATA_OFFSET + RNDIS_HEADER_OFFSET));
758
759 DPRINTF(("%s: urndis_encap type 0x%x len %u data(off %u len %u)\n",
760 DEVNAME(sc),
761 le32toh(msg->rm_type),
762 le32toh(msg->rm_len),
763 le32toh(msg->rm_dataoffset),
764 le32toh(msg->rm_datalen)));
765
766 c->sc_mbuf = m;
767
768 usbd_setup_xfer(c->sc_xfer, c, c->sc_buf, le32toh(msg->rm_len),
769 USBD_FORCE_SHORT_XFER, 10000, urndis_txeof);
770
771 /* Transmit */
772 err = usbd_transfer(c->sc_xfer);
773 if (err != USBD_IN_PROGRESS) {
774 urndis_stop(GET_IFP(sc));
775 return(EIO);
776 }
777
778 sc->sc_data.sc_tx_cnt++;
779
780 return(0);
781 }
782
783 static void
784 urndis_decap(struct urndis_softc *sc, struct urndis_chain *c, uint32_t len)
785 {
786 struct mbuf *m;
787 struct urndis_packet_msg *msg;
788 struct ifnet *ifp;
789 int s;
790 int offset;
791
792 ifp = GET_IFP(sc);
793 offset = 0;
794
795 while (len > 0) {
796 msg = (struct urndis_packet_msg *)((char*)c->sc_buf + offset);
797 m = c->sc_mbuf;
798
799 DPRINTF(("%s: urndis_decap buffer size left %u\n", DEVNAME(sc),
800 len));
801
802 if (len < sizeof(*msg)) {
803 printf("%s: urndis_decap invalid buffer len %u < "
804 "minimum header %zu\n",
805 DEVNAME(sc),
806 len,
807 sizeof(*msg));
808 return;
809 }
810
811 DPRINTF(("%s: urndis_decap len %u data(off:%u len:%u) "
812 "oobdata(off:%u len:%u nb:%u) perpacket(off:%u len:%u)\n",
813 DEVNAME(sc),
814 le32toh(msg->rm_len),
815 le32toh(msg->rm_dataoffset),
816 le32toh(msg->rm_datalen),
817 le32toh(msg->rm_oobdataoffset),
818 le32toh(msg->rm_oobdatalen),
819 le32toh(msg->rm_oobdataelements),
820 le32toh(msg->rm_pktinfooffset),
821 le32toh(msg->rm_pktinfooffset)));
822
823 if (le32toh(msg->rm_type) != REMOTE_NDIS_PACKET_MSG) {
824 printf("%s: urndis_decap invalid type 0x%x != 0x%x\n",
825 DEVNAME(sc),
826 le32toh(msg->rm_type),
827 REMOTE_NDIS_PACKET_MSG);
828 return;
829 }
830 if (le32toh(msg->rm_len) < sizeof(*msg)) {
831 printf("%s: urndis_decap invalid msg len %u < %zu\n",
832 DEVNAME(sc),
833 le32toh(msg->rm_len),
834 sizeof(*msg));
835 return;
836 }
837 if (le32toh(msg->rm_len) > len) {
838 printf("%s: urndis_decap invalid msg len %u > buffer "
839 "len %u\n",
840 DEVNAME(sc),
841 le32toh(msg->rm_len),
842 len);
843 return;
844 }
845
846 if (le32toh(msg->rm_dataoffset) +
847 le32toh(msg->rm_datalen) + RNDIS_HEADER_OFFSET
848 > le32toh(msg->rm_len)) {
849 printf("%s: urndis_decap invalid data "
850 "len/offset/end_position(%u/%u/%u) -> "
851 "go out of receive buffer limit %u\n",
852 DEVNAME(sc),
853 le32toh(msg->rm_datalen),
854 le32toh(msg->rm_dataoffset),
855 le32toh(msg->rm_dataoffset) +
856 le32toh(msg->rm_datalen) + (uint32_t)RNDIS_HEADER_OFFSET,
857 le32toh(msg->rm_len));
858 return;
859 }
860
861 if (le32toh(msg->rm_datalen) < sizeof(struct ether_header)) {
862 ifp->if_ierrors++;
863 printf("%s: urndis_decap invalid ethernet size "
864 "%d < %zu\n",
865 DEVNAME(sc),
866 le32toh(msg->rm_datalen),
867 sizeof(struct ether_header));
868 return;
869 }
870
871 memcpy(mtod(m, char*),
872 ((char*)&msg->rm_dataoffset + le32toh(msg->rm_dataoffset)),
873 le32toh(msg->rm_datalen));
874 m->m_pkthdr.len = m->m_len = le32toh(msg->rm_datalen);
875
876 m_set_rcvif(m, ifp);
877
878 s = splnet();
879
880 if (urndis_newbuf(sc, c) == ENOBUFS) {
881 ifp->if_ierrors++;
882 } else {
883
884 bpf_mtap(ifp, m);
885
886 if_percpuq_enqueue(sc->urndis_ipq, m);
887 }
888 splx(s);
889
890 offset += le32toh(msg->rm_len);
891 len -= le32toh(msg->rm_len);
892 }
893 }
894
895 static int
896 urndis_newbuf(struct urndis_softc *sc, struct urndis_chain *c)
897 {
898 struct mbuf *m_new = NULL;
899
900 MGETHDR(m_new, M_DONTWAIT, MT_DATA);
901 if (m_new == NULL) {
902 printf("%s: no memory for rx list -- packet dropped!\n",
903 DEVNAME(sc));
904 return ENOBUFS;
905 }
906 MCLGET(m_new, M_DONTWAIT);
907 if (!(m_new->m_flags & M_EXT)) {
908 printf("%s: no memory for rx list -- packet dropped!\n",
909 DEVNAME(sc));
910 m_freem(m_new);
911 return ENOBUFS;
912 }
913 m_new->m_len = m_new->m_pkthdr.len = MCLBYTES;
914
915 m_adj(m_new, ETHER_ALIGN);
916 c->sc_mbuf = m_new;
917 return 0;
918 }
919
920 static int
921 urndis_rx_list_init(struct urndis_softc *sc)
922 {
923 struct urndis_cdata *cd;
924 struct urndis_chain *c;
925 int i;
926
927 cd = &sc->sc_data;
928 for (i = 0; i < RNDIS_RX_LIST_CNT; i++) {
929 c = &cd->sc_rx_chain[i];
930 c->sc_softc = sc;
931 c->sc_idx = i;
932
933 if (urndis_newbuf(sc, c) == ENOBUFS)
934 return ENOBUFS;
935
936 if (c->sc_xfer == NULL) {
937 int err = usbd_create_xfer(sc->sc_bulkin_pipe,
938 RNDIS_BUFSZ, USBD_SHORT_XFER_OK, 0, &c->sc_xfer);
939 if (err)
940 return err;
941 c->sc_buf = usbd_get_buffer(c->sc_xfer);
942 }
943 }
944
945 return 0;
946 }
947
948 static void
949 urndis_rx_list_free(struct urndis_softc *sc)
950 {
951 for (int i = 0; i < RNDIS_RX_LIST_CNT; i++) {
952 if (sc->sc_data.sc_rx_chain[i].sc_mbuf != NULL) {
953 m_freem(sc->sc_data.sc_rx_chain[i].sc_mbuf);
954 sc->sc_data.sc_rx_chain[i].sc_mbuf = NULL;
955 }
956 if (sc->sc_data.sc_rx_chain[i].sc_xfer != NULL) {
957 usbd_destroy_xfer(sc->sc_data.sc_rx_chain[i].sc_xfer);
958 sc->sc_data.sc_rx_chain[i].sc_xfer = NULL;
959 }
960 }
961 }
962
963 static int
964 urndis_tx_list_init(struct urndis_softc *sc)
965 {
966 struct urndis_cdata *cd;
967 struct urndis_chain *c;
968 int i;
969
970 cd = &sc->sc_data;
971 for (i = 0; i < RNDIS_TX_LIST_CNT; i++) {
972 c = &cd->sc_tx_chain[i];
973 c->sc_softc = sc;
974 c->sc_idx = i;
975 c->sc_mbuf = NULL;
976 if (c->sc_xfer == NULL) {
977 int err = usbd_create_xfer(sc->sc_bulkout_pipe,
978 RNDIS_BUFSZ, USBD_FORCE_SHORT_XFER, 0, &c->sc_xfer);
979 if (err)
980 return err;
981 c->sc_buf = usbd_get_buffer(c->sc_xfer);
982 }
983 }
984 return 0;
985 }
986
987 static void
988 urndis_tx_list_free(struct urndis_softc *sc)
989 {
990 for (int i = 0; i < RNDIS_TX_LIST_CNT; i++) {
991 if (sc->sc_data.sc_tx_chain[i].sc_mbuf != NULL) {
992 m_freem(sc->sc_data.sc_tx_chain[i].sc_mbuf);
993 sc->sc_data.sc_tx_chain[i].sc_mbuf = NULL;
994 }
995 if (sc->sc_data.sc_tx_chain[i].sc_xfer != NULL) {
996 usbd_destroy_xfer(sc->sc_data.sc_tx_chain[i].sc_xfer);
997 sc->sc_data.sc_tx_chain[i].sc_xfer = NULL;
998 }
999 }
1000 }
1001
1002 static int
1003 urndis_ioctl(struct ifnet *ifp, unsigned long command, void *data)
1004 {
1005 struct urndis_softc *sc;
1006 int s, error;
1007
1008 sc = ifp->if_softc;
1009 error = 0;
1010
1011 if (sc->sc_dying)
1012 return EIO;
1013
1014 s = splnet();
1015
1016 error = ether_ioctl(ifp, command, data);
1017
1018 if (error == ENETRESET)
1019 error = 0;
1020
1021 splx(s);
1022 return error;
1023 }
1024
1025 #if 0
1026 static void
1027 urndis_watchdog(struct ifnet *ifp)
1028 {
1029 struct urndis_softc *sc;
1030
1031 sc = ifp->if_softc;
1032
1033 if (sc->sc_dying)
1034 return;
1035
1036 ifp->if_oerrors++;
1037 printf("%s: watchdog timeout\n", DEVNAME(sc));
1038
1039 urndis_ctrl_keepalive(sc);
1040 }
1041 #endif
1042
1043 static int
1044 urndis_init(struct ifnet *ifp)
1045 {
1046 struct urndis_softc *sc = ifp->if_softc;
1047
1048 mutex_enter(&sc->sc_lock);
1049 int ret = urndis_init_locked(ifp);
1050 mutex_exit(&sc->sc_lock);
1051
1052 return ret;
1053 }
1054
1055 static int
1056 urndis_init_locked(struct ifnet *ifp)
1057 {
1058 struct urndis_softc *sc;
1059 int i;
1060 int err;
1061 usbd_status usberr;
1062
1063 sc = ifp->if_softc;
1064
1065 if (ifp->if_flags & IFF_RUNNING)
1066 return 0;
1067
1068 err = urndis_ctrl_init(sc);
1069 if (err != RNDIS_STATUS_SUCCESS)
1070 return EIO;
1071
1072 usberr = usbd_open_pipe(sc->sc_iface_data, sc->sc_bulkin_no,
1073 USBD_EXCLUSIVE_USE, &sc->sc_bulkin_pipe);
1074 if (usberr) {
1075 printf("%s: open rx pipe failed: %s\n", DEVNAME(sc),
1076 usbd_errstr(err));
1077 goto fail;
1078 }
1079
1080 usberr = usbd_open_pipe(sc->sc_iface_data, sc->sc_bulkout_no,
1081 USBD_EXCLUSIVE_USE, &sc->sc_bulkout_pipe);
1082 if (usberr) {
1083 printf("%s: open tx pipe failed: %s\n", DEVNAME(sc),
1084 usbd_errstr(err));
1085 goto fail2;
1086 }
1087
1088 err = urndis_tx_list_init(sc);
1089 if (err) {
1090 printf("%s: tx list init failed\n",
1091 DEVNAME(sc));
1092 goto fail3;
1093 }
1094
1095 err = urndis_rx_list_init(sc);
1096 if (err) {
1097 printf("%s: rx list init failed\n",
1098 DEVNAME(sc));
1099 goto fail4;
1100 }
1101
1102 for (i = 0; i < RNDIS_RX_LIST_CNT; i++) {
1103 struct urndis_chain *c;
1104
1105 c = &sc->sc_data.sc_rx_chain[i];
1106
1107 usbd_setup_xfer(c->sc_xfer, c, c->sc_buf, RNDIS_BUFSZ,
1108 USBD_SHORT_XFER_OK, USBD_NO_TIMEOUT, urndis_rxeof);
1109 usbd_transfer(c->sc_xfer);
1110 }
1111
1112 ifp->if_flags |= IFF_RUNNING;
1113 ifp->if_flags &= ~IFF_OACTIVE;
1114
1115 return 0;
1116
1117 fail4:
1118 urndis_tx_list_free(sc);
1119 fail3:
1120 usbd_close_pipe(sc->sc_bulkout_pipe);
1121 fail2:
1122 usbd_close_pipe(sc->sc_bulkin_pipe);
1123 fail:
1124 return EIO;
1125 }
1126
1127 static void
1128 urndis_stop(struct ifnet *ifp)
1129 {
1130 struct urndis_softc *sc = ifp->if_softc;
1131
1132 mutex_enter(&sc->sc_lock);
1133 urndis_stop_locked(ifp);
1134 mutex_exit(&sc->sc_lock);
1135 }
1136
1137 static void
1138 urndis_stop_locked(struct ifnet *ifp)
1139 {
1140 struct urndis_softc *sc;
1141 usbd_status err;
1142
1143 sc = ifp->if_softc;
1144
1145 ifp->if_timer = 0;
1146 ifp->if_flags &= ~(IFF_RUNNING | IFF_OACTIVE);
1147
1148 if (sc->sc_bulkin_pipe != NULL) {
1149 err = usbd_abort_pipe(sc->sc_bulkin_pipe);
1150 if (err)
1151 printf("%s: abort rx pipe failed: %s\n",
1152 DEVNAME(sc), usbd_errstr(err));
1153 }
1154
1155 if (sc->sc_bulkout_pipe != NULL) {
1156 err = usbd_abort_pipe(sc->sc_bulkout_pipe);
1157 if (err)
1158 printf("%s: abort tx pipe failed: %s\n",
1159 DEVNAME(sc), usbd_errstr(err));
1160 }
1161
1162 urndis_tx_list_free(sc);
1163
1164 urndis_rx_list_free(sc);
1165
1166 /* Close pipes. */
1167 if (sc->sc_bulkin_pipe != NULL) {
1168 err = usbd_close_pipe(sc->sc_bulkin_pipe);
1169 if (err)
1170 printf("%s: close rx pipe failed: %s\n",
1171 DEVNAME(sc), usbd_errstr(err));
1172 sc->sc_bulkin_pipe = NULL;
1173 }
1174
1175 if (sc->sc_bulkout_pipe != NULL) {
1176 err = usbd_close_pipe(sc->sc_bulkout_pipe);
1177 if (err)
1178 printf("%s: close tx pipe failed: %s\n",
1179 DEVNAME(sc), usbd_errstr(err));
1180 sc->sc_bulkout_pipe = NULL;
1181 }
1182 }
1183
1184 static void
1185 urndis_start(struct ifnet *ifp)
1186 {
1187 struct urndis_softc *sc = ifp->if_softc;
1188 KASSERT(ifp->if_extflags & IFEF_START_MPSAFE);
1189
1190 mutex_enter(&sc->sc_txlock);
1191 urndis_start_locked(ifp);
1192 mutex_exit(&sc->sc_txlock);
1193 }
1194
1195 static void
1196 urndis_start_locked(struct ifnet *ifp)
1197 {
1198 struct urndis_softc *sc;
1199 struct mbuf *m_head = NULL;
1200
1201 sc = ifp->if_softc;
1202
1203 if (sc->sc_dying || (ifp->if_flags & IFF_OACTIVE))
1204 return;
1205
1206 IFQ_POLL(&ifp->if_snd, m_head);
1207 if (m_head == NULL)
1208 return;
1209
1210 if (urndis_encap(sc, m_head, 0)) {
1211 ifp->if_flags |= IFF_OACTIVE;
1212 return;
1213 }
1214 IFQ_DEQUEUE(&ifp->if_snd, m_head);
1215
1216 /*
1217 * If there's a BPF listener, bounce a copy of this frame
1218 * to him.
1219 */
1220 bpf_mtap(ifp, m_head);
1221
1222 ifp->if_flags |= IFF_OACTIVE;
1223
1224 /*
1225 * Set a timeout in case the chip goes out to lunch.
1226 */
1227 ifp->if_timer = 5;
1228
1229 return;
1230 }
1231
1232 static void
1233 urndis_rxeof(struct usbd_xfer *xfer,
1234 void *priv,
1235 usbd_status status)
1236 {
1237 struct urndis_chain *c;
1238 struct urndis_softc *sc;
1239 struct ifnet *ifp;
1240 uint32_t total_len;
1241
1242 c = priv;
1243 sc = c->sc_softc;
1244 ifp = GET_IFP(sc);
1245 total_len = 0;
1246
1247 if (sc->sc_dying || !(ifp->if_flags & IFF_RUNNING))
1248 return;
1249
1250 if (status != USBD_NORMAL_COMPLETION) {
1251 if (status == USBD_NOT_STARTED || status == USBD_CANCELLED)
1252 return;
1253 if (usbd_ratecheck(&sc->sc_rx_notice)) {
1254 printf("%s: usb errors on rx: %s\n",
1255 DEVNAME(sc), usbd_errstr(status));
1256 }
1257 if (status == USBD_STALLED)
1258 usbd_clear_endpoint_stall_async(sc->sc_bulkin_pipe);
1259
1260 goto done;
1261 }
1262
1263 usbd_get_xfer_status(xfer, NULL, NULL, &total_len, NULL);
1264 urndis_decap(sc, c, total_len);
1265
1266 done:
1267 /* Setup new transfer. */
1268 usbd_setup_xfer(c->sc_xfer, c, c->sc_buf, RNDIS_BUFSZ,
1269 USBD_SHORT_XFER_OK, USBD_NO_TIMEOUT, urndis_rxeof);
1270 usbd_transfer(c->sc_xfer);
1271 }
1272
1273 static void
1274 urndis_txeof(struct usbd_xfer *xfer,
1275 void *priv,
1276 usbd_status status)
1277 {
1278 struct urndis_chain *c;
1279 struct urndis_softc *sc;
1280 struct ifnet *ifp;
1281 usbd_status err;
1282 int s;
1283
1284 c = priv;
1285 sc = c->sc_softc;
1286 ifp = GET_IFP(sc);
1287
1288 DPRINTF(("%s: urndis_txeof\n", DEVNAME(sc)));
1289
1290 if (sc->sc_dying)
1291 return;
1292
1293 s = splnet();
1294
1295 ifp->if_timer = 0;
1296 ifp->if_flags &= ~IFF_OACTIVE;
1297
1298 if (status != USBD_NORMAL_COMPLETION) {
1299 if (status == USBD_NOT_STARTED || status == USBD_CANCELLED) {
1300 splx(s);
1301 return;
1302 }
1303 ifp->if_oerrors++;
1304 printf("%s: usb error on tx: %s\n", DEVNAME(sc),
1305 usbd_errstr(status));
1306 if (status == USBD_STALLED)
1307 usbd_clear_endpoint_stall_async(sc->sc_bulkout_pipe);
1308 splx(s);
1309 return;
1310 }
1311
1312 usbd_get_xfer_status(c->sc_xfer, NULL, NULL, NULL, &err);
1313
1314 if (c->sc_mbuf != NULL) {
1315 m_freem(c->sc_mbuf);
1316 c->sc_mbuf = NULL;
1317 }
1318
1319 if (err)
1320 ifp->if_oerrors++;
1321 else
1322 ifp->if_opackets++;
1323
1324 if (IFQ_IS_EMPTY(&ifp->if_snd) == 0)
1325 urndis_start(ifp);
1326
1327 splx(s);
1328 }
1329
1330 static int
1331 urndis_match(device_t parent, cfdata_t match, void *aux)
1332 {
1333 struct usbif_attach_arg *uiaa = aux;
1334 usb_interface_descriptor_t *id;
1335
1336 if (!uiaa->uiaa_iface)
1337 return UMATCH_NONE;
1338
1339 id = usbd_get_interface_descriptor(uiaa->uiaa_iface);
1340 if (id == NULL)
1341 return UMATCH_NONE;
1342
1343 if (id->bInterfaceClass == UICLASS_WIRELESS &&
1344 id->bInterfaceSubClass == UISUBCLASS_RF &&
1345 id->bInterfaceProtocol == UIPROTO_RNDIS)
1346 return UMATCH_IFACECLASS_IFACESUBCLASS_IFACEPROTO;
1347
1348 return usb_lookup(urndis_devs, uiaa->uiaa_vendor, uiaa->uiaa_product) != NULL ?
1349 UMATCH_VENDOR_PRODUCT : UMATCH_NONE;
1350 }
1351
1352 static void
1353 urndis_attach(device_t parent, device_t self, void *aux)
1354 {
1355 struct urndis_softc *sc;
1356 struct usbif_attach_arg *uiaa;
1357 struct ifnet *ifp;
1358 usb_interface_descriptor_t *id;
1359 usb_endpoint_descriptor_t *ed;
1360 usb_config_descriptor_t *cd;
1361 const usb_cdc_union_descriptor_t *ud;
1362 const usb_cdc_header_descriptor_t *desc;
1363 usbd_desc_iter_t iter;
1364 int if_ctl, if_data;
1365 int i, j, altcnt;
1366 u_char eaddr[ETHER_ADDR_LEN];
1367 void *buf;
1368 size_t bufsz;
1369 uint32_t filter;
1370 char *devinfop;
1371
1372 sc = device_private(self);
1373 uiaa = aux;
1374 sc->sc_dev = self;
1375 sc->sc_udev = uiaa->uiaa_device;
1376
1377 aprint_naive("\n");
1378 aprint_normal("\n");
1379
1380 devinfop = usbd_devinfo_alloc(uiaa->uiaa_device, 0);
1381 aprint_normal_dev(self, "%s\n", devinfop);
1382 usbd_devinfo_free(devinfop);
1383
1384 sc->sc_iface_ctl = uiaa->uiaa_iface;
1385 id = usbd_get_interface_descriptor(sc->sc_iface_ctl);
1386 if_ctl = id->bInterfaceNumber;
1387 sc->sc_ifaceno_ctl = if_ctl;
1388 if_data = -1;
1389
1390 usb_desc_iter_init(sc->sc_udev, &iter);
1391 while ((desc = (const void *)usb_desc_iter_next(&iter)) != NULL) {
1392
1393 if (desc->bDescriptorType != UDESC_CS_INTERFACE) {
1394 continue;
1395 }
1396 switch (desc->bDescriptorSubtype) {
1397 case UDESCSUB_CDC_UNION:
1398 /* XXX bail out when found first? */
1399 ud = (const usb_cdc_union_descriptor_t *)desc;
1400 if (if_data == -1)
1401 if_data = ud->bSlaveInterface[0];
1402 break;
1403 }
1404 }
1405
1406 if (if_data == -1) {
1407 DPRINTF(("urndis_attach: no union interface\n"));
1408 sc->sc_iface_data = sc->sc_iface_ctl;
1409 } else {
1410 DPRINTF(("urndis_attach: union interface: ctl %u, data %u\n",
1411 if_ctl, if_data));
1412 for (i = 0; i < uiaa->uiaa_nifaces; i++) {
1413 if (uiaa->uiaa_ifaces[i] != NULL) {
1414 id = usbd_get_interface_descriptor(
1415 uiaa->uiaa_ifaces[i]);
1416 if (id != NULL && id->bInterfaceNumber ==
1417 if_data) {
1418 sc->sc_iface_data = uiaa->uiaa_ifaces[i];
1419 uiaa->uiaa_ifaces[i] = NULL;
1420 }
1421 }
1422 }
1423 }
1424
1425 if (sc->sc_iface_data == NULL) {
1426 aprint_error("%s: no data interface\n", DEVNAME(sc));
1427 return;
1428 }
1429
1430 id = usbd_get_interface_descriptor(sc->sc_iface_data);
1431 cd = usbd_get_config_descriptor(sc->sc_udev);
1432 altcnt = usbd_get_no_alts(cd, id->bInterfaceNumber);
1433
1434 for (j = 0; j < altcnt; j++) {
1435 if (usbd_set_interface(sc->sc_iface_data, j)) {
1436 aprint_error("%s: interface alternate setting %u "
1437 "failed\n", DEVNAME(sc), j);
1438 return;
1439 }
1440 /* Find endpoints. */
1441 id = usbd_get_interface_descriptor(sc->sc_iface_data);
1442 sc->sc_bulkin_no = sc->sc_bulkout_no = -1;
1443 for (i = 0; i < id->bNumEndpoints; i++) {
1444 ed = usbd_interface2endpoint_descriptor(
1445 sc->sc_iface_data, i);
1446 if (!ed) {
1447 aprint_error("%s: no descriptor for bulk "
1448 "endpoint %u\n", DEVNAME(sc), i);
1449 return;
1450 }
1451 if (UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_IN &&
1452 UE_GET_XFERTYPE(ed->bmAttributes) == UE_BULK) {
1453 sc->sc_bulkin_no = ed->bEndpointAddress;
1454 }
1455 else if (
1456 UE_GET_DIR(ed->bEndpointAddress) == UE_DIR_OUT &&
1457 UE_GET_XFERTYPE(ed->bmAttributes) == UE_BULK) {
1458 sc->sc_bulkout_no = ed->bEndpointAddress;
1459 }
1460 }
1461
1462 if (sc->sc_bulkin_no != -1 && sc->sc_bulkout_no != -1) {
1463 DPRINTF(("%s: in=0x%x, out=0x%x\n",
1464 DEVNAME(sc),
1465 sc->sc_bulkin_no,
1466 sc->sc_bulkout_no));
1467 goto found;
1468 }
1469 }
1470
1471 if (sc->sc_bulkin_no == -1)
1472 aprint_error("%s: could not find data bulk in\n", DEVNAME(sc));
1473 if (sc->sc_bulkout_no == -1 )
1474 aprint_error("%s: could not find data bulk out\n",DEVNAME(sc));
1475 return;
1476
1477 found:
1478 mutex_init(&sc->sc_lock, MUTEX_DEFAULT, IPL_NONE);
1479 mutex_init(&sc->sc_txlock, MUTEX_DEFAULT, IPL_SOFTUSB);
1480 mutex_init(&sc->sc_rxlock, MUTEX_DEFAULT, IPL_SOFTUSB);
1481
1482 ifp = GET_IFP(sc);
1483 ifp->if_softc = sc;
1484 ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
1485 ifp->if_extflags = IFEF_START_MPSAFE;
1486 ifp->if_start = urndis_start;
1487 ifp->if_ioctl = urndis_ioctl;
1488 ifp->if_init = urndis_init;
1489 #if 0
1490 ifp->if_watchdog = urndis_watchdog;
1491 #endif
1492
1493 strlcpy(ifp->if_xname, DEVNAME(sc), IFNAMSIZ);
1494
1495 IFQ_SET_READY(&ifp->if_snd);
1496
1497 urndis_init(ifp);
1498
1499 if (urndis_ctrl_query(sc, OID_802_3_PERMANENT_ADDRESS, NULL, 0,
1500 &buf, &bufsz) != RNDIS_STATUS_SUCCESS) {
1501 aprint_error("%s: unable to get hardware address\n",
1502 DEVNAME(sc));
1503 urndis_stop(ifp);
1504 goto fail;
1505 }
1506
1507 if (bufsz == ETHER_ADDR_LEN) {
1508 memcpy(eaddr, buf, ETHER_ADDR_LEN);
1509 aprint_normal("%s: address %s\n", DEVNAME(sc),
1510 ether_sprintf(eaddr));
1511 kmem_free(buf, bufsz);
1512 } else {
1513 aprint_error("%s: invalid address\n", DEVNAME(sc));
1514 kmem_free(buf, bufsz);
1515 urndis_stop(ifp);
1516 goto fail;
1517 }
1518
1519 /* Initialize packet filter */
1520 sc->sc_filter = RNDIS_PACKET_TYPE_BROADCAST;
1521 sc->sc_filter |= RNDIS_PACKET_TYPE_ALL_MULTICAST;
1522 filter = htole32(sc->sc_filter);
1523 if (urndis_ctrl_set(sc, OID_GEN_CURRENT_PACKET_FILTER, &filter,
1524 sizeof(filter)) != RNDIS_STATUS_SUCCESS) {
1525 aprint_error("%s: unable to set data filters\n", DEVNAME(sc));
1526 urndis_stop(ifp);
1527 goto fail;
1528 }
1529
1530 if_initialize(ifp);
1531 sc->urndis_ipq = if_percpuq_create(&sc->sc_ec.ec_if);
1532 ether_ifattach(ifp, eaddr);
1533 if_register(ifp);
1534
1535 sc->sc_attached = 1;
1536 return;
1537
1538 fail:
1539 mutex_destroy(&sc->sc_lock);
1540 mutex_destroy(&sc->sc_txlock);
1541 mutex_destroy(&sc->sc_rxlock);
1542 }
1543
1544 static int
1545 urndis_detach(device_t self, int flags)
1546 {
1547 struct urndis_softc *sc;
1548 struct ifnet *ifp;
1549 int s;
1550
1551 sc = device_private(self);
1552
1553 DPRINTF(("urndis_detach: %s flags %u\n", DEVNAME(sc),
1554 flags));
1555
1556 if (!sc->sc_attached)
1557 return 0;
1558
1559 s = splusb();
1560
1561 ifp = GET_IFP(sc);
1562
1563 if (ifp->if_softc != NULL) {
1564 ether_ifdetach(ifp);
1565 if_detach(ifp);
1566 }
1567
1568 urndis_stop(ifp);
1569
1570 mutex_destroy(&sc->sc_rxlock);
1571 mutex_destroy(&sc->sc_txlock);
1572 mutex_destroy(&sc->sc_lock);
1573
1574 sc->sc_attached = 0;
1575
1576 splx(s);
1577
1578 return 0;
1579 }
1580
1581 static int
1582 urndis_activate(device_t self, enum devact act)
1583 {
1584 struct urndis_softc *sc;
1585
1586 sc = device_private(self);
1587
1588 switch (act) {
1589 case DVACT_DEACTIVATE:
1590 sc->sc_dying = 1;
1591 return 0;
1592 }
1593
1594 return EOPNOTSUPP;
1595 }
1596
1597