2 * This file contains the handling of command
3 * responses as well as events generated by firmware.
5 #include <linux/delay.h>
6 #include <linux/if_arp.h>
7 #include <linux/netdevice.h>
9 #include <net/iw_handler.h>
19 * @brief This function handles disconnect event. it
20 * reports disconnect to upper layer, clean tx/rx packets,
21 * reset link state etc.
23 * @param priv A pointer to struct lbs_private structure
26 void lbs_mac_event_disconnected(struct lbs_private *priv)
28 union iwreq_data wrqu;
30 if (priv->connect_status != LBS_CONNECTED)
33 lbs_deb_enter(LBS_DEB_ASSOC);
35 memset(wrqu.ap_addr.sa_data, 0x00, ETH_ALEN);
36 wrqu.ap_addr.sa_family = ARPHRD_ETHER;
39 * Cisco AP sends EAP failure and de-auth in less than 0.5 ms.
40 * It causes problem in the Supplicant
43 msleep_interruptible(1000);
44 wireless_send_event(priv->dev, SIOCGIWAP, &wrqu, NULL);
46 /* report disconnect to upper layer */
47 netif_stop_queue(priv->dev);
48 netif_carrier_off(priv->dev);
50 /* Free Tx and Rx packets */
51 kfree_skb(priv->currenttxskb);
52 priv->currenttxskb = NULL;
53 priv->tx_pending_len = 0;
55 /* reset SNR/NF/RSSI values */
56 memset(priv->SNR, 0x00, sizeof(priv->SNR));
57 memset(priv->NF, 0x00, sizeof(priv->NF));
58 memset(priv->RSSI, 0x00, sizeof(priv->RSSI));
59 memset(priv->rawSNR, 0x00, sizeof(priv->rawSNR));
60 memset(priv->rawNF, 0x00, sizeof(priv->rawNF));
63 priv->connect_status = LBS_DISCONNECTED;
65 /* Clear out associated SSID and BSSID since connection is
68 memset(&priv->curbssparams.bssid, 0, ETH_ALEN);
69 memset(&priv->curbssparams.ssid, 0, IW_ESSID_MAX_SIZE);
70 priv->curbssparams.ssid_len = 0;
72 if (priv->psstate != PS_STATE_FULL_POWER) {
73 /* make firmware to exit PS mode */
74 lbs_deb_cmd("disconnected, so exit PS mode\n");
75 lbs_ps_wakeup(priv, 0);
77 lbs_deb_leave(LBS_DEB_ASSOC);
81 * @brief This function handles MIC failure event.
83 * @param priv A pointer to struct lbs_private structure
84 * @para event the event id
87 static void handle_mic_failureevent(struct lbs_private *priv, u32 event)
91 lbs_deb_enter(LBS_DEB_CMD);
92 memset(buf, 0, sizeof(buf));
94 sprintf(buf, "%s", "MLME-MICHAELMICFAILURE.indication ");
96 if (event == MACREG_INT_CODE_MIC_ERR_UNICAST) {
97 strcat(buf, "unicast ");
99 strcat(buf, "multicast ");
102 lbs_send_iwevcustom_event(priv, buf);
103 lbs_deb_leave(LBS_DEB_CMD);
106 static int lbs_ret_reg_access(struct lbs_private *priv,
107 u16 type, struct cmd_ds_command *resp)
111 lbs_deb_enter(LBS_DEB_CMD);
114 case CMD_RET(CMD_MAC_REG_ACCESS):
116 struct cmd_ds_mac_reg_access *reg = &resp->params.macreg;
118 priv->offsetvalue.offset = (u32)le16_to_cpu(reg->offset);
119 priv->offsetvalue.value = le32_to_cpu(reg->value);
123 case CMD_RET(CMD_BBP_REG_ACCESS):
125 struct cmd_ds_bbp_reg_access *reg = &resp->params.bbpreg;
127 priv->offsetvalue.offset = (u32)le16_to_cpu(reg->offset);
128 priv->offsetvalue.value = reg->value;
132 case CMD_RET(CMD_RF_REG_ACCESS):
134 struct cmd_ds_rf_reg_access *reg = &resp->params.rfreg;
136 priv->offsetvalue.offset = (u32)le16_to_cpu(reg->offset);
137 priv->offsetvalue.value = reg->value;
145 lbs_deb_leave_args(LBS_DEB_CMD, "ret %d", ret);
149 static int lbs_ret_802_11_snmp_mib(struct lbs_private *priv,
150 struct cmd_ds_command *resp)
152 struct cmd_ds_802_11_snmp_mib *smib = &resp->params.smib;
153 u16 oid = le16_to_cpu(smib->oid);
154 u16 querytype = le16_to_cpu(smib->querytype);
156 lbs_deb_enter(LBS_DEB_CMD);
158 lbs_deb_cmd("SNMP_RESP: oid 0x%x, querytype 0x%x\n", oid,
160 lbs_deb_cmd("SNMP_RESP: Buf size %d\n", le16_to_cpu(smib->bufsize));
162 if (querytype == CMD_ACT_GET) {
166 le16_to_cpu(*((__le16 *)(smib->value)));
167 lbs_deb_cmd("SNMP_RESP: frag threshold %u\n",
172 le16_to_cpu(*((__le16 *)(smib->value)));
173 lbs_deb_cmd("SNMP_RESP: rts threshold %u\n",
176 case SHORT_RETRYLIM_I:
178 le16_to_cpu(*((__le16 *)(smib->value)));
179 lbs_deb_cmd("SNMP_RESP: tx retry count %u\n",
187 lbs_deb_enter(LBS_DEB_CMD);
191 static int lbs_ret_802_11_rssi(struct lbs_private *priv,
192 struct cmd_ds_command *resp)
194 struct cmd_ds_802_11_rssi_rsp *rssirsp = &resp->params.rssirsp;
196 lbs_deb_enter(LBS_DEB_CMD);
198 /* store the non average value */
199 priv->SNR[TYPE_BEACON][TYPE_NOAVG] = le16_to_cpu(rssirsp->SNR);
200 priv->NF[TYPE_BEACON][TYPE_NOAVG] = le16_to_cpu(rssirsp->noisefloor);
202 priv->SNR[TYPE_BEACON][TYPE_AVG] = le16_to_cpu(rssirsp->avgSNR);
203 priv->NF[TYPE_BEACON][TYPE_AVG] = le16_to_cpu(rssirsp->avgnoisefloor);
205 priv->RSSI[TYPE_BEACON][TYPE_NOAVG] =
206 CAL_RSSI(priv->SNR[TYPE_BEACON][TYPE_NOAVG],
207 priv->NF[TYPE_BEACON][TYPE_NOAVG]);
209 priv->RSSI[TYPE_BEACON][TYPE_AVG] =
210 CAL_RSSI(priv->SNR[TYPE_BEACON][TYPE_AVG] / AVG_SCALE,
211 priv->NF[TYPE_BEACON][TYPE_AVG] / AVG_SCALE);
213 lbs_deb_cmd("RSSI: beacon %d, avg %d\n",
214 priv->RSSI[TYPE_BEACON][TYPE_NOAVG],
215 priv->RSSI[TYPE_BEACON][TYPE_AVG]);
217 lbs_deb_leave(LBS_DEB_CMD);
221 static int lbs_ret_802_11_bcn_ctrl(struct lbs_private * priv,
222 struct cmd_ds_command *resp)
224 struct cmd_ds_802_11_beacon_control *bcn_ctrl =
225 &resp->params.bcn_ctrl;
227 lbs_deb_enter(LBS_DEB_CMD);
229 if (bcn_ctrl->action == CMD_ACT_GET) {
230 priv->beacon_enable = (u8) le16_to_cpu(bcn_ctrl->beacon_enable);
231 priv->beacon_period = le16_to_cpu(bcn_ctrl->beacon_period);
234 lbs_deb_enter(LBS_DEB_CMD);
238 static inline int handle_cmd_response(struct lbs_private *priv,
239 struct cmd_header *cmd_response)
241 struct cmd_ds_command *resp = (struct cmd_ds_command *) cmd_response;
244 uint16_t respcmd = le16_to_cpu(resp->command);
246 lbs_deb_enter(LBS_DEB_HOST);
249 case CMD_RET(CMD_MAC_REG_ACCESS):
250 case CMD_RET(CMD_BBP_REG_ACCESS):
251 case CMD_RET(CMD_RF_REG_ACCESS):
252 ret = lbs_ret_reg_access(priv, respcmd, resp);
255 case CMD_RET_802_11_ASSOCIATE:
256 case CMD_RET(CMD_802_11_ASSOCIATE):
257 case CMD_RET(CMD_802_11_REASSOCIATE):
258 ret = lbs_ret_80211_associate(priv, resp);
261 case CMD_RET(CMD_802_11_DISASSOCIATE):
262 case CMD_RET(CMD_802_11_DEAUTHENTICATE):
263 ret = lbs_ret_80211_disassociate(priv);
266 case CMD_RET(CMD_802_11_AD_HOC_START):
267 case CMD_RET(CMD_802_11_AD_HOC_JOIN):
268 ret = lbs_ret_80211_ad_hoc_start(priv, resp);
271 case CMD_RET(CMD_802_11_SNMP_MIB):
272 ret = lbs_ret_802_11_snmp_mib(priv, resp);
275 case CMD_RET(CMD_802_11_SET_AFC):
276 case CMD_RET(CMD_802_11_GET_AFC):
277 spin_lock_irqsave(&priv->driver_lock, flags);
278 memmove((void *)priv->cur_cmd->callback_arg, &resp->params.afc,
279 sizeof(struct cmd_ds_802_11_afc));
280 spin_unlock_irqrestore(&priv->driver_lock, flags);
284 case CMD_RET(CMD_802_11_RESET):
285 case CMD_RET(CMD_802_11_AUTHENTICATE):
286 case CMD_RET(CMD_802_11_BEACON_STOP):
289 case CMD_RET(CMD_802_11_RSSI):
290 ret = lbs_ret_802_11_rssi(priv, resp);
293 case CMD_RET(CMD_802_11_AD_HOC_STOP):
294 ret = lbs_ret_80211_ad_hoc_stop(priv);
297 case CMD_RET(CMD_802_11D_DOMAIN_INFO):
298 ret = lbs_ret_802_11d_domain_info(resp);
301 case CMD_RET(CMD_802_11_TPC_CFG):
302 spin_lock_irqsave(&priv->driver_lock, flags);
303 memmove((void *)priv->cur_cmd->callback_arg, &resp->params.tpccfg,
304 sizeof(struct cmd_ds_802_11_tpc_cfg));
305 spin_unlock_irqrestore(&priv->driver_lock, flags);
307 case CMD_RET(CMD_802_11_LED_GPIO_CTRL):
308 spin_lock_irqsave(&priv->driver_lock, flags);
309 memmove((void *)priv->cur_cmd->callback_arg, &resp->params.ledgpio,
310 sizeof(struct cmd_ds_802_11_led_ctrl));
311 spin_unlock_irqrestore(&priv->driver_lock, flags);
314 case CMD_RET(CMD_GET_TSF):
315 spin_lock_irqsave(&priv->driver_lock, flags);
316 memcpy((void *)priv->cur_cmd->callback_arg,
317 &resp->params.gettsf.tsfvalue, sizeof(u64));
318 spin_unlock_irqrestore(&priv->driver_lock, flags);
320 case CMD_RET(CMD_BT_ACCESS):
321 spin_lock_irqsave(&priv->driver_lock, flags);
322 if (priv->cur_cmd->callback_arg)
323 memcpy((void *)priv->cur_cmd->callback_arg,
324 &resp->params.bt.addr1, 2 * ETH_ALEN);
325 spin_unlock_irqrestore(&priv->driver_lock, flags);
327 case CMD_RET(CMD_FWT_ACCESS):
328 spin_lock_irqsave(&priv->driver_lock, flags);
329 if (priv->cur_cmd->callback_arg)
330 memcpy((void *)priv->cur_cmd->callback_arg, &resp->params.fwt,
331 sizeof(resp->params.fwt));
332 spin_unlock_irqrestore(&priv->driver_lock, flags);
334 case CMD_RET(CMD_802_11_BEACON_CTRL):
335 ret = lbs_ret_802_11_bcn_ctrl(priv, resp);
339 lbs_pr_err("CMD_RESP: unknown cmd response 0x%04x\n",
340 le16_to_cpu(resp->command));
343 lbs_deb_leave(LBS_DEB_HOST);
347 int lbs_process_command_response(struct lbs_private *priv, u8 *data, u32 len)
349 uint16_t respcmd, curcmd;
350 struct cmd_header *resp;
355 lbs_deb_enter(LBS_DEB_HOST);
357 mutex_lock(&priv->lock);
358 spin_lock_irqsave(&priv->driver_lock, flags);
360 if (!priv->cur_cmd) {
361 lbs_deb_host("CMD_RESP: cur_cmd is NULL\n");
363 spin_unlock_irqrestore(&priv->driver_lock, flags);
368 curcmd = le16_to_cpu(priv->cur_cmd->cmdbuf->command);
369 respcmd = le16_to_cpu(resp->command);
370 result = le16_to_cpu(resp->result);
372 lbs_deb_cmd("CMD_RESP: response 0x%04x, seq %d, size %d\n",
373 respcmd, le16_to_cpu(resp->seqnum), len);
374 lbs_deb_hex(LBS_DEB_CMD, "CMD_RESP", (void *) resp, len);
376 if (resp->seqnum != priv->cur_cmd->cmdbuf->seqnum) {
377 lbs_pr_info("Received CMD_RESP with invalid sequence %d (expected %d)\n",
378 le16_to_cpu(resp->seqnum), le16_to_cpu(priv->cur_cmd->cmdbuf->seqnum));
379 spin_unlock_irqrestore(&priv->driver_lock, flags);
383 if (respcmd != CMD_RET(curcmd) &&
384 respcmd != CMD_RET_802_11_ASSOCIATE && curcmd != CMD_802_11_ASSOCIATE) {
385 lbs_pr_info("Invalid CMD_RESP %x to command %x!\n", respcmd, curcmd);
386 spin_unlock_irqrestore(&priv->driver_lock, flags);
391 if (resp->result == cpu_to_le16(0x0004)) {
392 /* 0x0004 means -EAGAIN. Drop the response, let it time out
393 and be resubmitted */
394 lbs_pr_info("Firmware returns DEFER to command %x. Will let it time out...\n",
395 le16_to_cpu(resp->command));
396 spin_unlock_irqrestore(&priv->driver_lock, flags);
401 /* Now we got response from FW, cancel the command timer */
402 del_timer(&priv->command_timer);
403 priv->cmd_timed_out = 0;
404 if (priv->nr_retries) {
405 lbs_pr_info("Received result %x to command %x after %d retries\n",
406 result, curcmd, priv->nr_retries);
407 priv->nr_retries = 0;
410 /* Store the response code to cur_cmd_retcode. */
411 priv->cur_cmd_retcode = result;
413 if (respcmd == CMD_RET(CMD_802_11_PS_MODE)) {
414 struct cmd_ds_802_11_ps_mode *psmode = (void *) &resp[1];
415 u16 action = le16_to_cpu(psmode->action);
418 "CMD_RESP: PS_MODE cmd reply result 0x%x, action 0x%x\n",
422 lbs_deb_host("CMD_RESP: PS command failed with 0x%x\n",
425 * We should not re-try enter-ps command in
426 * ad-hoc mode. It takes place in
427 * lbs_execute_next_command().
429 if (priv->mode == IW_MODE_ADHOC &&
430 action == CMD_SUBCMD_ENTER_PS)
431 priv->psmode = LBS802_11POWERMODECAM;
432 } else if (action == CMD_SUBCMD_ENTER_PS) {
433 priv->needtowakeup = 0;
434 priv->psstate = PS_STATE_AWAKE;
436 lbs_deb_host("CMD_RESP: ENTER_PS command response\n");
437 if (priv->connect_status != LBS_CONNECTED) {
439 * When Deauth Event received before Enter_PS command
440 * response, We need to wake up the firmware.
443 "disconnected, invoking lbs_ps_wakeup\n");
445 spin_unlock_irqrestore(&priv->driver_lock, flags);
446 mutex_unlock(&priv->lock);
447 lbs_ps_wakeup(priv, 0);
448 mutex_lock(&priv->lock);
449 spin_lock_irqsave(&priv->driver_lock, flags);
451 } else if (action == CMD_SUBCMD_EXIT_PS) {
452 priv->needtowakeup = 0;
453 priv->psstate = PS_STATE_FULL_POWER;
454 lbs_deb_host("CMD_RESP: EXIT_PS command response\n");
456 lbs_deb_host("CMD_RESP: PS action 0x%X\n", action);
459 lbs_complete_command(priv, priv->cur_cmd, result);
460 spin_unlock_irqrestore(&priv->driver_lock, flags);
466 /* If the command is not successful, cleanup and return failure */
467 if ((result != 0 || !(respcmd & 0x8000))) {
468 lbs_deb_host("CMD_RESP: error 0x%04x in command reply 0x%04x\n",
471 * Handling errors here
474 case CMD_RET(CMD_GET_HW_SPEC):
475 case CMD_RET(CMD_802_11_RESET):
476 lbs_deb_host("CMD_RESP: reset failed\n");
480 lbs_complete_command(priv, priv->cur_cmd, result);
481 spin_unlock_irqrestore(&priv->driver_lock, flags);
487 spin_unlock_irqrestore(&priv->driver_lock, flags);
489 if (priv->cur_cmd && priv->cur_cmd->callback) {
490 ret = priv->cur_cmd->callback(priv, priv->cur_cmd->callback_arg,
493 ret = handle_cmd_response(priv, resp);
495 spin_lock_irqsave(&priv->driver_lock, flags);
498 /* Clean up and Put current command back to cmdfreeq */
499 lbs_complete_command(priv, priv->cur_cmd, result);
501 spin_unlock_irqrestore(&priv->driver_lock, flags);
504 mutex_unlock(&priv->lock);
505 lbs_deb_leave_args(LBS_DEB_HOST, "ret %d", ret);
509 static int lbs_send_confirmwake(struct lbs_private *priv)
511 struct cmd_header cmd;
514 lbs_deb_enter(LBS_DEB_HOST);
516 cmd.command = cpu_to_le16(CMD_802_11_WAKEUP_CONFIRM);
517 cmd.size = cpu_to_le16(sizeof(cmd));
518 cmd.seqnum = cpu_to_le16(++priv->seqnum);
521 lbs_deb_hex(LBS_DEB_HOST, "wake confirm", (u8 *) &cmd,
524 ret = priv->hw_host_to_card(priv, MVMS_CMD, (u8 *) &cmd, sizeof(cmd));
526 lbs_pr_alert("SEND_WAKEC_CMD: Host to Card failed for Confirm Wake\n");
528 lbs_deb_leave_args(LBS_DEB_HOST, "ret %d", ret);
532 int lbs_process_event(struct lbs_private *priv, u32 event)
536 lbs_deb_enter(LBS_DEB_CMD);
539 case MACREG_INT_CODE_LINK_SENSED:
540 lbs_deb_cmd("EVENT: link sensed\n");
543 case MACREG_INT_CODE_DEAUTHENTICATED:
544 lbs_deb_cmd("EVENT: deauthenticated\n");
545 lbs_mac_event_disconnected(priv);
548 case MACREG_INT_CODE_DISASSOCIATED:
549 lbs_deb_cmd("EVENT: disassociated\n");
550 lbs_mac_event_disconnected(priv);
553 case MACREG_INT_CODE_LINK_LOST_NO_SCAN:
554 lbs_deb_cmd("EVENT: link lost\n");
555 lbs_mac_event_disconnected(priv);
558 case MACREG_INT_CODE_PS_SLEEP:
559 lbs_deb_cmd("EVENT: ps sleep\n");
561 /* handle unexpected PS SLEEP event */
562 if (priv->psstate == PS_STATE_FULL_POWER) {
564 "EVENT: in FULL POWER mode, ignoreing PS_SLEEP\n");
567 priv->psstate = PS_STATE_PRE_SLEEP;
569 lbs_ps_confirm_sleep(priv);
573 case MACREG_INT_CODE_HOST_AWAKE:
574 lbs_deb_cmd("EVENT: host awake\n");
575 lbs_send_confirmwake(priv);
578 case MACREG_INT_CODE_PS_AWAKE:
579 lbs_deb_cmd("EVENT: ps awake\n");
580 /* handle unexpected PS AWAKE event */
581 if (priv->psstate == PS_STATE_FULL_POWER) {
583 "EVENT: In FULL POWER mode - ignore PS AWAKE\n");
587 priv->psstate = PS_STATE_AWAKE;
589 if (priv->needtowakeup) {
591 * wait for the command processing to finish
592 * before resuming sending
593 * priv->needtowakeup will be set to FALSE
596 lbs_deb_cmd("waking up ...\n");
597 lbs_ps_wakeup(priv, 0);
601 case MACREG_INT_CODE_MIC_ERR_UNICAST:
602 lbs_deb_cmd("EVENT: UNICAST MIC ERROR\n");
603 handle_mic_failureevent(priv, MACREG_INT_CODE_MIC_ERR_UNICAST);
606 case MACREG_INT_CODE_MIC_ERR_MULTICAST:
607 lbs_deb_cmd("EVENT: MULTICAST MIC ERROR\n");
608 handle_mic_failureevent(priv, MACREG_INT_CODE_MIC_ERR_MULTICAST);
611 case MACREG_INT_CODE_MIB_CHANGED:
612 lbs_deb_cmd("EVENT: MIB CHANGED\n");
614 case MACREG_INT_CODE_INIT_DONE:
615 lbs_deb_cmd("EVENT: INIT DONE\n");
617 case MACREG_INT_CODE_ADHOC_BCN_LOST:
618 lbs_deb_cmd("EVENT: ADHOC beacon lost\n");
620 case MACREG_INT_CODE_RSSI_LOW:
621 lbs_pr_alert("EVENT: rssi low\n");
623 case MACREG_INT_CODE_SNR_LOW:
624 lbs_pr_alert("EVENT: snr low\n");
626 case MACREG_INT_CODE_MAX_FAIL:
627 lbs_pr_alert("EVENT: max fail\n");
629 case MACREG_INT_CODE_RSSI_HIGH:
630 lbs_pr_alert("EVENT: rssi high\n");
632 case MACREG_INT_CODE_SNR_HIGH:
633 lbs_pr_alert("EVENT: snr high\n");
636 case MACREG_INT_CODE_MESH_AUTO_STARTED:
637 /* Ignore spurious autostart events if autostart is disabled */
638 if (!priv->mesh_autostart_enabled) {
639 lbs_pr_info("EVENT: MESH_AUTO_STARTED (ignoring)\n");
642 lbs_pr_info("EVENT: MESH_AUTO_STARTED\n");
643 priv->mesh_connect_status = LBS_CONNECTED;
644 if (priv->mesh_open) {
645 netif_carrier_on(priv->mesh_dev);
646 if (!priv->tx_pending_len)
647 netif_wake_queue(priv->mesh_dev);
649 priv->mode = IW_MODE_ADHOC;
650 schedule_work(&priv->sync_channel);
654 lbs_pr_alert("EVENT: unknown event id %d\n", event);
658 lbs_deb_leave_args(LBS_DEB_CMD, "ret %d", ret);