241af7fe44bb6320485899f1ccca561f1a08ca60
[safe/jmp/linux-2.6] / drivers / net / wireless / libertas / main.c
1 /**
2   * This file contains the major functions in WLAN
3   * driver. It includes init, exit, open, close and main
4   * thread etc..
5   */
6
7 #include <linux/moduleparam.h>
8 #include <linux/delay.h>
9 #include <linux/etherdevice.h>
10 #include <linux/netdevice.h>
11 #include <linux/if_arp.h>
12 #include <linux/kthread.h>
13 #include <linux/kfifo.h>
14 #include <linux/stddef.h>
15 #include <linux/ieee80211.h>
16 #include <net/iw_handler.h>
17
18 #include "host.h"
19 #include "decl.h"
20 #include "dev.h"
21 #include "wext.h"
22 #include "debugfs.h"
23 #include "scan.h"
24 #include "assoc.h"
25 #include "cmd.h"
26
27 #define DRIVER_RELEASE_VERSION "323.p0"
28 const char lbs_driver_version[] = "COMM-USB8388-" DRIVER_RELEASE_VERSION
29 #ifdef  DEBUG
30     "-dbg"
31 #endif
32     "";
33
34
35 /* Module parameters */
36 unsigned int lbs_debug;
37 EXPORT_SYMBOL_GPL(lbs_debug);
38 module_param_named(libertas_debug, lbs_debug, int, 0644);
39
40
41 /* This global structure is used to send the confirm_sleep command as
42  * fast as possible down to the firmware. */
43 struct cmd_confirm_sleep confirm_sleep;
44
45
46 #define LBS_TX_PWR_DEFAULT              20      /*100mW */
47 #define LBS_TX_PWR_US_DEFAULT           20      /*100mW */
48 #define LBS_TX_PWR_JP_DEFAULT           16      /*50mW */
49 #define LBS_TX_PWR_FR_DEFAULT           20      /*100mW */
50 #define LBS_TX_PWR_EMEA_DEFAULT 20      /*100mW */
51
52 /* Format { channel, frequency (MHz), maxtxpower } */
53 /* band: 'B/G', region: USA FCC/Canada IC */
54 static struct chan_freq_power channel_freq_power_US_BG[] = {
55         {1, 2412, LBS_TX_PWR_US_DEFAULT},
56         {2, 2417, LBS_TX_PWR_US_DEFAULT},
57         {3, 2422, LBS_TX_PWR_US_DEFAULT},
58         {4, 2427, LBS_TX_PWR_US_DEFAULT},
59         {5, 2432, LBS_TX_PWR_US_DEFAULT},
60         {6, 2437, LBS_TX_PWR_US_DEFAULT},
61         {7, 2442, LBS_TX_PWR_US_DEFAULT},
62         {8, 2447, LBS_TX_PWR_US_DEFAULT},
63         {9, 2452, LBS_TX_PWR_US_DEFAULT},
64         {10, 2457, LBS_TX_PWR_US_DEFAULT},
65         {11, 2462, LBS_TX_PWR_US_DEFAULT}
66 };
67
68 /* band: 'B/G', region: Europe ETSI */
69 static struct chan_freq_power channel_freq_power_EU_BG[] = {
70         {1, 2412, LBS_TX_PWR_EMEA_DEFAULT},
71         {2, 2417, LBS_TX_PWR_EMEA_DEFAULT},
72         {3, 2422, LBS_TX_PWR_EMEA_DEFAULT},
73         {4, 2427, LBS_TX_PWR_EMEA_DEFAULT},
74         {5, 2432, LBS_TX_PWR_EMEA_DEFAULT},
75         {6, 2437, LBS_TX_PWR_EMEA_DEFAULT},
76         {7, 2442, LBS_TX_PWR_EMEA_DEFAULT},
77         {8, 2447, LBS_TX_PWR_EMEA_DEFAULT},
78         {9, 2452, LBS_TX_PWR_EMEA_DEFAULT},
79         {10, 2457, LBS_TX_PWR_EMEA_DEFAULT},
80         {11, 2462, LBS_TX_PWR_EMEA_DEFAULT},
81         {12, 2467, LBS_TX_PWR_EMEA_DEFAULT},
82         {13, 2472, LBS_TX_PWR_EMEA_DEFAULT}
83 };
84
85 /* band: 'B/G', region: Spain */
86 static struct chan_freq_power channel_freq_power_SPN_BG[] = {
87         {10, 2457, LBS_TX_PWR_DEFAULT},
88         {11, 2462, LBS_TX_PWR_DEFAULT}
89 };
90
91 /* band: 'B/G', region: France */
92 static struct chan_freq_power channel_freq_power_FR_BG[] = {
93         {10, 2457, LBS_TX_PWR_FR_DEFAULT},
94         {11, 2462, LBS_TX_PWR_FR_DEFAULT},
95         {12, 2467, LBS_TX_PWR_FR_DEFAULT},
96         {13, 2472, LBS_TX_PWR_FR_DEFAULT}
97 };
98
99 /* band: 'B/G', region: Japan */
100 static struct chan_freq_power channel_freq_power_JPN_BG[] = {
101         {1, 2412, LBS_TX_PWR_JP_DEFAULT},
102         {2, 2417, LBS_TX_PWR_JP_DEFAULT},
103         {3, 2422, LBS_TX_PWR_JP_DEFAULT},
104         {4, 2427, LBS_TX_PWR_JP_DEFAULT},
105         {5, 2432, LBS_TX_PWR_JP_DEFAULT},
106         {6, 2437, LBS_TX_PWR_JP_DEFAULT},
107         {7, 2442, LBS_TX_PWR_JP_DEFAULT},
108         {8, 2447, LBS_TX_PWR_JP_DEFAULT},
109         {9, 2452, LBS_TX_PWR_JP_DEFAULT},
110         {10, 2457, LBS_TX_PWR_JP_DEFAULT},
111         {11, 2462, LBS_TX_PWR_JP_DEFAULT},
112         {12, 2467, LBS_TX_PWR_JP_DEFAULT},
113         {13, 2472, LBS_TX_PWR_JP_DEFAULT},
114         {14, 2484, LBS_TX_PWR_JP_DEFAULT}
115 };
116
117 /**
118  * the structure for channel, frequency and power
119  */
120 struct region_cfp_table {
121         u8 region;
122         struct chan_freq_power *cfp_BG;
123         int cfp_no_BG;
124 };
125
126 /**
127  * the structure for the mapping between region and CFP
128  */
129 static struct region_cfp_table region_cfp_table[] = {
130         {0x10,                  /*US FCC */
131          channel_freq_power_US_BG,
132          ARRAY_SIZE(channel_freq_power_US_BG),
133          }
134         ,
135         {0x20,                  /*CANADA IC */
136          channel_freq_power_US_BG,
137          ARRAY_SIZE(channel_freq_power_US_BG),
138          }
139         ,
140         {0x30, /*EU*/ channel_freq_power_EU_BG,
141          ARRAY_SIZE(channel_freq_power_EU_BG),
142          }
143         ,
144         {0x31, /*SPAIN*/ channel_freq_power_SPN_BG,
145          ARRAY_SIZE(channel_freq_power_SPN_BG),
146          }
147         ,
148         {0x32, /*FRANCE*/ channel_freq_power_FR_BG,
149          ARRAY_SIZE(channel_freq_power_FR_BG),
150          }
151         ,
152         {0x40, /*JAPAN*/ channel_freq_power_JPN_BG,
153          ARRAY_SIZE(channel_freq_power_JPN_BG),
154          }
155         ,
156 /*Add new region here */
157 };
158
159 /**
160  * the table to keep region code
161  */
162 u16 lbs_region_code_to_index[MRVDRV_MAX_REGION_CODE] =
163     { 0x10, 0x20, 0x30, 0x31, 0x32, 0x40 };
164
165 /**
166  * 802.11b/g supported bitrates (in 500Kb/s units)
167  */
168 u8 lbs_bg_rates[MAX_RATES] =
169     { 0x02, 0x04, 0x0b, 0x16, 0x0c, 0x12, 0x18, 0x24, 0x30, 0x48, 0x60, 0x6c,
170 0x00, 0x00 };
171
172 /**
173  * FW rate table.  FW refers to rates by their index in this table, not by the
174  * rate value itself.  Values of 0x00 are
175  * reserved positions.
176  */
177 static u8 fw_data_rates[MAX_RATES] =
178     { 0x02, 0x04, 0x0B, 0x16, 0x00, 0x0C, 0x12,
179       0x18, 0x24, 0x30, 0x48, 0x60, 0x6C, 0x00
180 };
181
182 /**
183  *  @brief use index to get the data rate
184  *
185  *  @param idx                The index of data rate
186  *  @return                     data rate or 0
187  */
188 u32 lbs_fw_index_to_data_rate(u8 idx)
189 {
190         if (idx >= sizeof(fw_data_rates))
191                 idx = 0;
192         return fw_data_rates[idx];
193 }
194
195 /**
196  *  @brief use rate to get the index
197  *
198  *  @param rate                 data rate
199  *  @return                     index or 0
200  */
201 u8 lbs_data_rate_to_fw_index(u32 rate)
202 {
203         u8 i;
204
205         if (!rate)
206                 return 0;
207
208         for (i = 0; i < sizeof(fw_data_rates); i++) {
209                 if (rate == fw_data_rates[i])
210                         return i;
211         }
212         return 0;
213 }
214
215 /**
216  * Attributes exported through sysfs
217  */
218
219 /**
220  * @brief Get function for sysfs attribute anycast_mask
221  */
222 static ssize_t lbs_anycast_get(struct device *dev,
223                 struct device_attribute *attr, char * buf)
224 {
225         struct lbs_private *priv = netdev_priv(to_net_dev(dev));
226         struct cmd_ds_mesh_access mesh_access;
227         int ret;
228
229         memset(&mesh_access, 0, sizeof(mesh_access));
230
231         ret = lbs_mesh_access(priv, CMD_ACT_MESH_GET_ANYCAST, &mesh_access);
232         if (ret)
233                 return ret;
234
235         return snprintf(buf, 12, "0x%X\n", le32_to_cpu(mesh_access.data[0]));
236 }
237
238 /**
239  * @brief Set function for sysfs attribute anycast_mask
240  */
241 static ssize_t lbs_anycast_set(struct device *dev,
242                 struct device_attribute *attr, const char * buf, size_t count)
243 {
244         struct lbs_private *priv = netdev_priv(to_net_dev(dev));
245         struct cmd_ds_mesh_access mesh_access;
246         uint32_t datum;
247         int ret;
248
249         memset(&mesh_access, 0, sizeof(mesh_access));
250         sscanf(buf, "%x", &datum);
251         mesh_access.data[0] = cpu_to_le32(datum);
252
253         ret = lbs_mesh_access(priv, CMD_ACT_MESH_SET_ANYCAST, &mesh_access);
254         if (ret)
255                 return ret;
256
257         return strlen(buf);
258 }
259
260 static int lbs_add_rtap(struct lbs_private *priv);
261 static void lbs_remove_rtap(struct lbs_private *priv);
262 static int lbs_add_mesh(struct lbs_private *priv);
263 static void lbs_remove_mesh(struct lbs_private *priv);
264
265
266 /**
267  * Get function for sysfs attribute rtap
268  */
269 static ssize_t lbs_rtap_get(struct device *dev,
270                 struct device_attribute *attr, char * buf)
271 {
272         struct lbs_private *priv = netdev_priv(to_net_dev(dev));
273         return snprintf(buf, 5, "0x%X\n", priv->monitormode);
274 }
275
276 /**
277  *  Set function for sysfs attribute rtap
278  */
279 static ssize_t lbs_rtap_set(struct device *dev,
280                 struct device_attribute *attr, const char * buf, size_t count)
281 {
282         int monitor_mode;
283         struct lbs_private *priv = netdev_priv(to_net_dev(dev));
284
285         sscanf(buf, "%x", &monitor_mode);
286         if (monitor_mode) {
287                 if (priv->monitormode == monitor_mode)
288                         return strlen(buf);
289                 if (!priv->monitormode) {
290                         if (priv->infra_open || priv->mesh_open)
291                                 return -EBUSY;
292                         if (priv->mode == IW_MODE_INFRA)
293                                 lbs_cmd_80211_deauthenticate(priv,
294                                                              priv->curbssparams.bssid,
295                                                              WLAN_REASON_DEAUTH_LEAVING);
296                         else if (priv->mode == IW_MODE_ADHOC)
297                                 lbs_adhoc_stop(priv);
298                         lbs_add_rtap(priv);
299                 }
300                 priv->monitormode = monitor_mode;
301         } else {
302                 if (!priv->monitormode)
303                         return strlen(buf);
304                 priv->monitormode = 0;
305                 lbs_remove_rtap(priv);
306
307                 if (priv->currenttxskb) {
308                         dev_kfree_skb_any(priv->currenttxskb);
309                         priv->currenttxskb = NULL;
310                 }
311
312                 /* Wake queues, command thread, etc. */
313                 lbs_host_to_card_done(priv);
314         }
315
316         lbs_prepare_and_send_command(priv,
317                         CMD_802_11_MONITOR_MODE, CMD_ACT_SET,
318                         CMD_OPTION_WAITFORRSP, 0, &priv->monitormode);
319         return strlen(buf);
320 }
321
322 /**
323  * lbs_rtap attribute to be exported per ethX interface
324  * through sysfs (/sys/class/net/ethX/lbs_rtap)
325  */
326 static DEVICE_ATTR(lbs_rtap, 0644, lbs_rtap_get, lbs_rtap_set );
327
328 /**
329  * Get function for sysfs attribute mesh
330  */
331 static ssize_t lbs_mesh_get(struct device *dev,
332                 struct device_attribute *attr, char * buf)
333 {
334         struct lbs_private *priv = netdev_priv(to_net_dev(dev));
335         return snprintf(buf, 5, "0x%X\n", !!priv->mesh_dev);
336 }
337
338 /**
339  *  Set function for sysfs attribute mesh
340  */
341 static ssize_t lbs_mesh_set(struct device *dev,
342                 struct device_attribute *attr, const char * buf, size_t count)
343 {
344         struct lbs_private *priv = netdev_priv(to_net_dev(dev));
345         int enable;
346         int ret, action = CMD_ACT_MESH_CONFIG_STOP;
347
348         sscanf(buf, "%x", &enable);
349         enable = !!enable;
350         if (enable == !!priv->mesh_dev)
351                 return count;
352         if (enable)
353                 action = CMD_ACT_MESH_CONFIG_START;
354         ret = lbs_mesh_config(priv, action, priv->curbssparams.channel);
355         if (ret)
356                 return ret;
357
358         if (enable)
359                 lbs_add_mesh(priv);
360         else
361                 lbs_remove_mesh(priv);
362
363         return count;
364 }
365
366 /**
367  * lbs_mesh attribute to be exported per ethX interface
368  * through sysfs (/sys/class/net/ethX/lbs_mesh)
369  */
370 static DEVICE_ATTR(lbs_mesh, 0644, lbs_mesh_get, lbs_mesh_set);
371
372 /**
373  * anycast_mask attribute to be exported per mshX interface
374  * through sysfs (/sys/class/net/mshX/anycast_mask)
375  */
376 static DEVICE_ATTR(anycast_mask, 0644, lbs_anycast_get, lbs_anycast_set);
377
378 static struct attribute *lbs_mesh_sysfs_entries[] = {
379         &dev_attr_anycast_mask.attr,
380         NULL,
381 };
382
383 static struct attribute_group lbs_mesh_attr_group = {
384         .attrs = lbs_mesh_sysfs_entries,
385 };
386
387 /**
388  *  @brief This function opens the ethX or mshX interface
389  *
390  *  @param dev     A pointer to net_device structure
391  *  @return        0 or -EBUSY if monitor mode active
392  */
393 static int lbs_dev_open(struct net_device *dev)
394 {
395         struct lbs_private *priv = netdev_priv(dev) ;
396         int ret = 0;
397
398         lbs_deb_enter(LBS_DEB_NET);
399
400         spin_lock_irq(&priv->driver_lock);
401
402         if (priv->monitormode) {
403                 ret = -EBUSY;
404                 goto out;
405         }
406
407         if (dev == priv->mesh_dev) {
408                 priv->mesh_open = 1;
409                 priv->mesh_connect_status = LBS_CONNECTED;
410                 netif_carrier_on(dev);
411         } else {
412                 priv->infra_open = 1;
413
414                 if (priv->connect_status == LBS_CONNECTED)
415                         netif_carrier_on(dev);
416                 else
417                         netif_carrier_off(dev);
418         }
419
420         if (!priv->tx_pending_len)
421                 netif_wake_queue(dev);
422  out:
423
424         spin_unlock_irq(&priv->driver_lock);
425         lbs_deb_leave_args(LBS_DEB_NET, "ret %d", ret);
426         return ret;
427 }
428
429 /**
430  *  @brief This function closes the mshX interface
431  *
432  *  @param dev     A pointer to net_device structure
433  *  @return        0
434  */
435 static int lbs_mesh_stop(struct net_device *dev)
436 {
437         struct lbs_private *priv = dev->ml_priv;
438
439         lbs_deb_enter(LBS_DEB_MESH);
440         spin_lock_irq(&priv->driver_lock);
441
442         priv->mesh_open = 0;
443         priv->mesh_connect_status = LBS_DISCONNECTED;
444
445         netif_stop_queue(dev);
446         netif_carrier_off(dev);
447
448         spin_unlock_irq(&priv->driver_lock);
449
450         schedule_work(&priv->mcast_work);
451
452         lbs_deb_leave(LBS_DEB_MESH);
453         return 0;
454 }
455
456 /**
457  *  @brief This function closes the ethX interface
458  *
459  *  @param dev     A pointer to net_device structure
460  *  @return        0
461  */
462 static int lbs_eth_stop(struct net_device *dev)
463 {
464         struct lbs_private *priv = netdev_priv(dev);
465
466         lbs_deb_enter(LBS_DEB_NET);
467
468         spin_lock_irq(&priv->driver_lock);
469         priv->infra_open = 0;
470         netif_stop_queue(dev);
471         spin_unlock_irq(&priv->driver_lock);
472
473         schedule_work(&priv->mcast_work);
474
475         lbs_deb_leave(LBS_DEB_NET);
476         return 0;
477 }
478
479 static void lbs_tx_timeout(struct net_device *dev)
480 {
481         struct lbs_private *priv = netdev_priv(dev);
482
483         lbs_deb_enter(LBS_DEB_TX);
484
485         lbs_pr_err("tx watch dog timeout\n");
486
487         dev->trans_start = jiffies;
488
489         if (priv->currenttxskb)
490                 lbs_send_tx_feedback(priv, 0);
491
492         /* XX: Shouldn't we also call into the hw-specific driver
493            to kick it somehow? */
494         lbs_host_to_card_done(priv);
495
496         /* More often than not, this actually happens because the
497            firmware has crapped itself -- rather than just a very
498            busy medium. So send a harmless command, and if/when
499            _that_ times out, we'll kick it in the head. */
500         lbs_prepare_and_send_command(priv, CMD_802_11_RSSI, 0,
501                                      0, 0, NULL);
502
503         lbs_deb_leave(LBS_DEB_TX);
504 }
505
506 void lbs_host_to_card_done(struct lbs_private *priv)
507 {
508         unsigned long flags;
509
510         lbs_deb_enter(LBS_DEB_THREAD);
511
512         spin_lock_irqsave(&priv->driver_lock, flags);
513
514         priv->dnld_sent = DNLD_RES_RECEIVED;
515
516         /* Wake main thread if commands are pending */
517         if (!priv->cur_cmd || priv->tx_pending_len > 0)
518                 wake_up_interruptible(&priv->waitq);
519
520         spin_unlock_irqrestore(&priv->driver_lock, flags);
521         lbs_deb_leave(LBS_DEB_THREAD);
522 }
523 EXPORT_SYMBOL_GPL(lbs_host_to_card_done);
524
525 /**
526  *  @brief This function returns the network statistics
527  *
528  *  @param dev     A pointer to struct lbs_private structure
529  *  @return        A pointer to net_device_stats structure
530  */
531 static struct net_device_stats *lbs_get_stats(struct net_device *dev)
532 {
533         struct lbs_private *priv = netdev_priv(dev);
534
535         lbs_deb_enter(LBS_DEB_NET);
536         return &priv->stats;
537 }
538
539 static int lbs_set_mac_address(struct net_device *dev, void *addr)
540 {
541         int ret = 0;
542         struct lbs_private *priv = netdev_priv(dev);
543         struct sockaddr *phwaddr = addr;
544         struct cmd_ds_802_11_mac_address cmd;
545
546         lbs_deb_enter(LBS_DEB_NET);
547
548         /* In case it was called from the mesh device */
549         dev = priv->dev;
550
551         cmd.hdr.size = cpu_to_le16(sizeof(cmd));
552         cmd.action = cpu_to_le16(CMD_ACT_SET);
553         memcpy(cmd.macadd, phwaddr->sa_data, ETH_ALEN);
554
555         ret = lbs_cmd_with_response(priv, CMD_802_11_MAC_ADDRESS, &cmd);
556         if (ret) {
557                 lbs_deb_net("set MAC address failed\n");
558                 goto done;
559         }
560
561         memcpy(priv->current_addr, phwaddr->sa_data, ETH_ALEN);
562         memcpy(dev->dev_addr, phwaddr->sa_data, ETH_ALEN);
563         if (priv->mesh_dev)
564                 memcpy(priv->mesh_dev->dev_addr, phwaddr->sa_data, ETH_ALEN);
565
566 done:
567         lbs_deb_leave_args(LBS_DEB_NET, "ret %d", ret);
568         return ret;
569 }
570
571
572 static inline int mac_in_list(unsigned char *list, int list_len,
573                               unsigned char *mac)
574 {
575         while (list_len) {
576                 if (!memcmp(list, mac, ETH_ALEN))
577                         return 1;
578                 list += ETH_ALEN;
579                 list_len--;
580         }
581         return 0;
582 }
583
584
585 static int lbs_add_mcast_addrs(struct cmd_ds_mac_multicast_adr *cmd,
586                                struct net_device *dev, int nr_addrs)
587 {
588         int i = nr_addrs;
589         struct dev_mc_list *mc_list;
590
591         if ((dev->flags & (IFF_UP|IFF_MULTICAST)) != (IFF_UP|IFF_MULTICAST))
592                 return nr_addrs;
593
594         netif_addr_lock_bh(dev);
595         for (mc_list = dev->mc_list; mc_list; mc_list = mc_list->next) {
596                 if (mac_in_list(cmd->maclist, nr_addrs, mc_list->dmi_addr)) {
597                         lbs_deb_net("mcast address %s:%pM skipped\n", dev->name,
598                                     mc_list->dmi_addr);
599                         continue;
600                 }
601
602                 if (i == MRVDRV_MAX_MULTICAST_LIST_SIZE)
603                         break;
604                 memcpy(&cmd->maclist[6*i], mc_list->dmi_addr, ETH_ALEN);
605                 lbs_deb_net("mcast address %s:%pM added to filter\n", dev->name,
606                             mc_list->dmi_addr);
607                 i++;
608         }
609         netif_addr_unlock_bh(dev);
610         if (mc_list)
611                 return -EOVERFLOW;
612
613         return i;
614 }
615
616 static void lbs_set_mcast_worker(struct work_struct *work)
617 {
618         struct lbs_private *priv = container_of(work, struct lbs_private, mcast_work);
619         struct cmd_ds_mac_multicast_adr mcast_cmd;
620         int dev_flags;
621         int nr_addrs;
622         int old_mac_control = priv->mac_control;
623
624         lbs_deb_enter(LBS_DEB_NET);
625
626         dev_flags = priv->dev->flags;
627         if (priv->mesh_dev)
628                 dev_flags |= priv->mesh_dev->flags;
629
630         if (dev_flags & IFF_PROMISC) {
631                 priv->mac_control |= CMD_ACT_MAC_PROMISCUOUS_ENABLE;
632                 priv->mac_control &= ~(CMD_ACT_MAC_ALL_MULTICAST_ENABLE |
633                                        CMD_ACT_MAC_MULTICAST_ENABLE);
634                 goto out_set_mac_control;
635         } else if (dev_flags & IFF_ALLMULTI) {
636         do_allmulti:
637                 priv->mac_control |= CMD_ACT_MAC_ALL_MULTICAST_ENABLE;
638                 priv->mac_control &= ~(CMD_ACT_MAC_PROMISCUOUS_ENABLE |
639                                        CMD_ACT_MAC_MULTICAST_ENABLE);
640                 goto out_set_mac_control;
641         }
642
643         /* Once for priv->dev, again for priv->mesh_dev if it exists */
644         nr_addrs = lbs_add_mcast_addrs(&mcast_cmd, priv->dev, 0);
645         if (nr_addrs >= 0 && priv->mesh_dev)
646                 nr_addrs = lbs_add_mcast_addrs(&mcast_cmd, priv->mesh_dev, nr_addrs);
647         if (nr_addrs < 0)
648                 goto do_allmulti;
649
650         if (nr_addrs) {
651                 int size = offsetof(struct cmd_ds_mac_multicast_adr,
652                                     maclist[6*nr_addrs]);
653
654                 mcast_cmd.action = cpu_to_le16(CMD_ACT_SET);
655                 mcast_cmd.hdr.size = cpu_to_le16(size);
656                 mcast_cmd.nr_of_adrs = cpu_to_le16(nr_addrs);
657
658                 lbs_cmd_async(priv, CMD_MAC_MULTICAST_ADR, &mcast_cmd.hdr, size);
659
660                 priv->mac_control |= CMD_ACT_MAC_MULTICAST_ENABLE;
661         } else
662                 priv->mac_control &= ~CMD_ACT_MAC_MULTICAST_ENABLE;
663
664         priv->mac_control &= ~(CMD_ACT_MAC_PROMISCUOUS_ENABLE |
665                                CMD_ACT_MAC_ALL_MULTICAST_ENABLE);
666  out_set_mac_control:
667         if (priv->mac_control != old_mac_control)
668                 lbs_set_mac_control(priv);
669
670         lbs_deb_leave(LBS_DEB_NET);
671 }
672
673 static void lbs_set_multicast_list(struct net_device *dev)
674 {
675         struct lbs_private *priv = netdev_priv(dev);
676
677         schedule_work(&priv->mcast_work);
678 }
679
680 /**
681  *  @brief This function handles the major jobs in the LBS driver.
682  *  It handles all events generated by firmware, RX data received
683  *  from firmware and TX data sent from kernel.
684  *
685  *  @param data    A pointer to lbs_thread structure
686  *  @return        0
687  */
688 static int lbs_thread(void *data)
689 {
690         struct net_device *dev = data;
691         struct lbs_private *priv = netdev_priv(dev);
692         wait_queue_t wait;
693
694         lbs_deb_enter(LBS_DEB_THREAD);
695
696         init_waitqueue_entry(&wait, current);
697
698         for (;;) {
699                 int shouldsleep;
700                 u8 resp_idx;
701
702                 lbs_deb_thread("1: currenttxskb %p, dnld_sent %d\n",
703                                 priv->currenttxskb, priv->dnld_sent);
704
705                 add_wait_queue(&priv->waitq, &wait);
706                 set_current_state(TASK_INTERRUPTIBLE);
707                 spin_lock_irq(&priv->driver_lock);
708
709                 if (kthread_should_stop())
710                         shouldsleep = 0;        /* Bye */
711                 else if (priv->surpriseremoved)
712                         shouldsleep = 1;        /* We need to wait until we're _told_ to die */
713                 else if (priv->psstate == PS_STATE_SLEEP)
714                         shouldsleep = 1;        /* Sleep mode. Nothing we can do till it wakes */
715                 else if (priv->cmd_timed_out)
716                         shouldsleep = 0;        /* Command timed out. Recover */
717                 else if (!priv->fw_ready)
718                         shouldsleep = 1;        /* Firmware not ready. We're waiting for it */
719                 else if (priv->dnld_sent)
720                         shouldsleep = 1;        /* Something is en route to the device already */
721                 else if (priv->tx_pending_len > 0)
722                         shouldsleep = 0;        /* We've a packet to send */
723                 else if (priv->resp_len[priv->resp_idx])
724                         shouldsleep = 0;        /* We have a command response */
725                 else if (priv->cur_cmd)
726                         shouldsleep = 1;        /* Can't send a command; one already running */
727                 else if (!list_empty(&priv->cmdpendingq))
728                         shouldsleep = 0;        /* We have a command to send */
729                 else if (__kfifo_len(priv->event_fifo))
730                         shouldsleep = 0;        /* We have an event to process */
731                 else
732                         shouldsleep = 1;        /* No command */
733
734                 if (shouldsleep) {
735                         lbs_deb_thread("sleeping, connect_status %d, "
736                                 "psmode %d, psstate %d\n",
737                                 priv->connect_status,
738                                 priv->psmode, priv->psstate);
739                         spin_unlock_irq(&priv->driver_lock);
740                         schedule();
741                 } else
742                         spin_unlock_irq(&priv->driver_lock);
743
744                 lbs_deb_thread("2: currenttxskb %p, dnld_send %d\n",
745                                priv->currenttxskb, priv->dnld_sent);
746
747                 set_current_state(TASK_RUNNING);
748                 remove_wait_queue(&priv->waitq, &wait);
749
750                 lbs_deb_thread("3: currenttxskb %p, dnld_sent %d\n",
751                                priv->currenttxskb, priv->dnld_sent);
752
753                 if (kthread_should_stop()) {
754                         lbs_deb_thread("break from main thread\n");
755                         break;
756                 }
757
758                 if (priv->surpriseremoved) {
759                         lbs_deb_thread("adapter removed; waiting to die...\n");
760                         continue;
761                 }
762
763                 lbs_deb_thread("4: currenttxskb %p, dnld_sent %d\n",
764                        priv->currenttxskb, priv->dnld_sent);
765
766                 /* Process any pending command response */
767                 spin_lock_irq(&priv->driver_lock);
768                 resp_idx = priv->resp_idx;
769                 if (priv->resp_len[resp_idx]) {
770                         spin_unlock_irq(&priv->driver_lock);
771                         lbs_process_command_response(priv,
772                                 priv->resp_buf[resp_idx],
773                                 priv->resp_len[resp_idx]);
774                         spin_lock_irq(&priv->driver_lock);
775                         priv->resp_len[resp_idx] = 0;
776                 }
777                 spin_unlock_irq(&priv->driver_lock);
778
779                 /* command timeout stuff */
780                 if (priv->cmd_timed_out && priv->cur_cmd) {
781                         struct cmd_ctrl_node *cmdnode = priv->cur_cmd;
782
783                         if (++priv->nr_retries > 3) {
784                                 lbs_pr_info("Excessive timeouts submitting "
785                                         "command 0x%04x\n",
786                                         le16_to_cpu(cmdnode->cmdbuf->command));
787                                 lbs_complete_command(priv, cmdnode, -ETIMEDOUT);
788                                 priv->nr_retries = 0;
789                                 if (priv->reset_card)
790                                         priv->reset_card(priv);
791                         } else {
792                                 priv->cur_cmd = NULL;
793                                 priv->dnld_sent = DNLD_RES_RECEIVED;
794                                 lbs_pr_info("requeueing command 0x%04x due "
795                                         "to timeout (#%d)\n",
796                                         le16_to_cpu(cmdnode->cmdbuf->command),
797                                         priv->nr_retries);
798
799                                 /* Stick it back at the _top_ of the pending queue
800                                    for immediate resubmission */
801                                 list_add(&cmdnode->list, &priv->cmdpendingq);
802                         }
803                 }
804                 priv->cmd_timed_out = 0;
805
806                 /* Process hardware events, e.g. card removed, link lost */
807                 spin_lock_irq(&priv->driver_lock);
808                 while (__kfifo_len(priv->event_fifo)) {
809                         u32 event;
810
811                         __kfifo_get(priv->event_fifo, (unsigned char *) &event,
812                                 sizeof(event));
813                         spin_unlock_irq(&priv->driver_lock);
814                         lbs_process_event(priv, event);
815                         spin_lock_irq(&priv->driver_lock);
816                 }
817                 spin_unlock_irq(&priv->driver_lock);
818
819                 if (!priv->fw_ready)
820                         continue;
821
822                 /* Check if we need to confirm Sleep Request received previously */
823                 if (priv->psstate == PS_STATE_PRE_SLEEP &&
824                     !priv->dnld_sent && !priv->cur_cmd) {
825                         if (priv->connect_status == LBS_CONNECTED) {
826                                 lbs_deb_thread("pre-sleep, currenttxskb %p, "
827                                         "dnld_sent %d, cur_cmd %p\n",
828                                         priv->currenttxskb, priv->dnld_sent,
829                                         priv->cur_cmd);
830
831                                 lbs_ps_confirm_sleep(priv);
832                         } else {
833                                 /* workaround for firmware sending
834                                  * deauth/linkloss event immediately
835                                  * after sleep request; remove this
836                                  * after firmware fixes it
837                                  */
838                                 priv->psstate = PS_STATE_AWAKE;
839                                 lbs_pr_alert("ignore PS_SleepConfirm in "
840                                         "non-connected state\n");
841                         }
842                 }
843
844                 /* The PS state is changed during processing of Sleep Request
845                  * event above
846                  */
847                 if ((priv->psstate == PS_STATE_SLEEP) ||
848                     (priv->psstate == PS_STATE_PRE_SLEEP))
849                         continue;
850
851                 /* Execute the next command */
852                 if (!priv->dnld_sent && !priv->cur_cmd)
853                         lbs_execute_next_command(priv);
854
855                 /* Wake-up command waiters which can't sleep in
856                  * lbs_prepare_and_send_command
857                  */
858                 if (!list_empty(&priv->cmdpendingq))
859                         wake_up_all(&priv->cmd_pending);
860
861                 spin_lock_irq(&priv->driver_lock);
862                 if (!priv->dnld_sent && priv->tx_pending_len > 0) {
863                         int ret = priv->hw_host_to_card(priv, MVMS_DAT,
864                                                         priv->tx_pending_buf,
865                                                         priv->tx_pending_len);
866                         if (ret) {
867                                 lbs_deb_tx("host_to_card failed %d\n", ret);
868                                 priv->dnld_sent = DNLD_RES_RECEIVED;
869                         }
870                         priv->tx_pending_len = 0;
871                         if (!priv->currenttxskb) {
872                                 /* We can wake the queues immediately if we aren't
873                                    waiting for TX feedback */
874                                 if (priv->connect_status == LBS_CONNECTED)
875                                         netif_wake_queue(priv->dev);
876                                 if (priv->mesh_dev &&
877                                     priv->mesh_connect_status == LBS_CONNECTED)
878                                         netif_wake_queue(priv->mesh_dev);
879                         }
880                 }
881                 spin_unlock_irq(&priv->driver_lock);
882         }
883
884         del_timer(&priv->command_timer);
885         wake_up_all(&priv->cmd_pending);
886
887         lbs_deb_leave(LBS_DEB_THREAD);
888         return 0;
889 }
890
891 static int lbs_suspend_callback(struct lbs_private *priv, unsigned long dummy,
892                                 struct cmd_header *cmd)
893 {
894         lbs_deb_enter(LBS_DEB_FW);
895
896         netif_device_detach(priv->dev);
897         if (priv->mesh_dev)
898                 netif_device_detach(priv->mesh_dev);
899
900         priv->fw_ready = 0;
901         lbs_deb_leave(LBS_DEB_FW);
902         return 0;
903 }
904
905 int lbs_suspend(struct lbs_private *priv)
906 {
907         struct cmd_header cmd;
908         int ret;
909
910         lbs_deb_enter(LBS_DEB_FW);
911
912         if (priv->wol_criteria == 0xffffffff) {
913                 lbs_pr_info("Suspend attempt without configuring wake params!\n");
914                 return -EINVAL;
915         }
916
917         memset(&cmd, 0, sizeof(cmd));
918
919         ret = __lbs_cmd(priv, CMD_802_11_HOST_SLEEP_ACTIVATE, &cmd,
920                         sizeof(cmd), lbs_suspend_callback, 0);
921         if (ret)
922                 lbs_pr_info("HOST_SLEEP_ACTIVATE failed: %d\n", ret);
923
924         lbs_deb_leave_args(LBS_DEB_FW, "ret %d", ret);
925         return ret;
926 }
927 EXPORT_SYMBOL_GPL(lbs_suspend);
928
929 void lbs_resume(struct lbs_private *priv)
930 {
931         lbs_deb_enter(LBS_DEB_FW);
932
933         priv->fw_ready = 1;
934
935         /* Firmware doesn't seem to give us RX packets any more
936            until we send it some command. Might as well update */
937         lbs_prepare_and_send_command(priv, CMD_802_11_RSSI, 0,
938                                      0, 0, NULL);
939
940         netif_device_attach(priv->dev);
941         if (priv->mesh_dev)
942                 netif_device_attach(priv->mesh_dev);
943
944         lbs_deb_leave(LBS_DEB_FW);
945 }
946 EXPORT_SYMBOL_GPL(lbs_resume);
947
948 /**
949  *  @brief This function downloads firmware image, gets
950  *  HW spec from firmware and set basic parameters to
951  *  firmware.
952  *
953  *  @param priv    A pointer to struct lbs_private structure
954  *  @return        0 or -1
955  */
956 static int lbs_setup_firmware(struct lbs_private *priv)
957 {
958         int ret = -1;
959         s16 curlevel = 0, minlevel = 0, maxlevel = 0;
960
961         lbs_deb_enter(LBS_DEB_FW);
962
963         /* Read MAC address from firmware */
964         memset(priv->current_addr, 0xff, ETH_ALEN);
965         ret = lbs_update_hw_spec(priv);
966         if (ret)
967                 goto done;
968
969         /* Read power levels if available */
970         ret = lbs_get_tx_power(priv, &curlevel, &minlevel, &maxlevel);
971         if (ret == 0) {
972                 priv->txpower_cur = curlevel;
973                 priv->txpower_min = minlevel;
974                 priv->txpower_max = maxlevel;
975         }
976
977         lbs_set_mac_control(priv);
978 done:
979         lbs_deb_leave_args(LBS_DEB_FW, "ret %d", ret);
980         return ret;
981 }
982
983 /**
984  *  This function handles the timeout of command sending.
985  *  It will re-send the same command again.
986  */
987 static void command_timer_fn(unsigned long data)
988 {
989         struct lbs_private *priv = (struct lbs_private *)data;
990         unsigned long flags;
991
992         lbs_deb_enter(LBS_DEB_CMD);
993         spin_lock_irqsave(&priv->driver_lock, flags);
994
995         if (!priv->cur_cmd)
996                 goto out;
997
998         lbs_pr_info("command 0x%04x timed out\n",
999                 le16_to_cpu(priv->cur_cmd->cmdbuf->command));
1000
1001         priv->cmd_timed_out = 1;
1002         wake_up_interruptible(&priv->waitq);
1003 out:
1004         spin_unlock_irqrestore(&priv->driver_lock, flags);
1005         lbs_deb_leave(LBS_DEB_CMD);
1006 }
1007
1008 static void lbs_sync_channel_worker(struct work_struct *work)
1009 {
1010         struct lbs_private *priv = container_of(work, struct lbs_private,
1011                 sync_channel);
1012
1013         lbs_deb_enter(LBS_DEB_MAIN);
1014         if (lbs_update_channel(priv))
1015                 lbs_pr_info("Channel synchronization failed.");
1016         lbs_deb_leave(LBS_DEB_MAIN);
1017 }
1018
1019
1020 static int lbs_init_adapter(struct lbs_private *priv)
1021 {
1022         size_t bufsize;
1023         int i, ret = 0;
1024
1025         lbs_deb_enter(LBS_DEB_MAIN);
1026
1027         /* Allocate buffer to store the BSSID list */
1028         bufsize = MAX_NETWORK_COUNT * sizeof(struct bss_descriptor);
1029         priv->networks = kzalloc(bufsize, GFP_KERNEL);
1030         if (!priv->networks) {
1031                 lbs_pr_err("Out of memory allocating beacons\n");
1032                 ret = -1;
1033                 goto out;
1034         }
1035
1036         /* Initialize scan result lists */
1037         INIT_LIST_HEAD(&priv->network_free_list);
1038         INIT_LIST_HEAD(&priv->network_list);
1039         for (i = 0; i < MAX_NETWORK_COUNT; i++) {
1040                 list_add_tail(&priv->networks[i].list,
1041                               &priv->network_free_list);
1042         }
1043
1044         memset(priv->current_addr, 0xff, ETH_ALEN);
1045
1046         priv->connect_status = LBS_DISCONNECTED;
1047         priv->mesh_connect_status = LBS_DISCONNECTED;
1048         priv->secinfo.auth_mode = IW_AUTH_ALG_OPEN_SYSTEM;
1049         priv->mode = IW_MODE_INFRA;
1050         priv->curbssparams.channel = DEFAULT_AD_HOC_CHANNEL;
1051         priv->mac_control = CMD_ACT_MAC_RX_ON | CMD_ACT_MAC_TX_ON;
1052         priv->radio_on = 1;
1053         priv->enablehwauto = 1;
1054         priv->capability = WLAN_CAPABILITY_SHORT_PREAMBLE;
1055         priv->psmode = LBS802_11POWERMODECAM;
1056         priv->psstate = PS_STATE_FULL_POWER;
1057
1058         mutex_init(&priv->lock);
1059
1060         setup_timer(&priv->command_timer, command_timer_fn,
1061                 (unsigned long)priv);
1062
1063         INIT_LIST_HEAD(&priv->cmdfreeq);
1064         INIT_LIST_HEAD(&priv->cmdpendingq);
1065
1066         spin_lock_init(&priv->driver_lock);
1067         init_waitqueue_head(&priv->cmd_pending);
1068
1069         /* Allocate the command buffers */
1070         if (lbs_allocate_cmd_buffer(priv)) {
1071                 lbs_pr_err("Out of memory allocating command buffers\n");
1072                 ret = -ENOMEM;
1073                 goto out;
1074         }
1075         priv->resp_idx = 0;
1076         priv->resp_len[0] = priv->resp_len[1] = 0;
1077
1078         /* Create the event FIFO */
1079         priv->event_fifo = kfifo_alloc(sizeof(u32) * 16, GFP_KERNEL, NULL);
1080         if (IS_ERR(priv->event_fifo)) {
1081                 lbs_pr_err("Out of memory allocating event FIFO buffer\n");
1082                 ret = -ENOMEM;
1083                 goto out;
1084         }
1085
1086 out:
1087         lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
1088
1089         return ret;
1090 }
1091
1092 static void lbs_free_adapter(struct lbs_private *priv)
1093 {
1094         lbs_deb_enter(LBS_DEB_MAIN);
1095
1096         lbs_free_cmd_buffer(priv);
1097         if (priv->event_fifo)
1098                 kfifo_free(priv->event_fifo);
1099         del_timer(&priv->command_timer);
1100         kfree(priv->networks);
1101         priv->networks = NULL;
1102
1103         lbs_deb_leave(LBS_DEB_MAIN);
1104 }
1105
1106 /**
1107  * @brief This function adds the card. it will probe the
1108  * card, allocate the lbs_priv and initialize the device.
1109  *
1110  *  @param card    A pointer to card
1111  *  @return        A pointer to struct lbs_private structure
1112  */
1113 struct lbs_private *lbs_add_card(void *card, struct device *dmdev)
1114 {
1115         struct net_device *dev = NULL;
1116         struct lbs_private *priv = NULL;
1117
1118         lbs_deb_enter(LBS_DEB_MAIN);
1119
1120         /* Allocate an Ethernet device and register it */
1121         dev = alloc_etherdev(sizeof(struct lbs_private));
1122         if (!dev) {
1123                 lbs_pr_err("init ethX device failed\n");
1124                 goto done;
1125         }
1126         priv = netdev_priv(dev);
1127
1128         if (lbs_init_adapter(priv)) {
1129                 lbs_pr_err("failed to initialize adapter structure.\n");
1130                 goto err_init_adapter;
1131         }
1132
1133         priv->dev = dev;
1134         priv->card = card;
1135         priv->mesh_open = 0;
1136         priv->infra_open = 0;
1137
1138         /* Setup the OS Interface to our functions */
1139         dev->open = lbs_dev_open;
1140         dev->hard_start_xmit = lbs_hard_start_xmit;
1141         dev->stop = lbs_eth_stop;
1142         dev->set_mac_address = lbs_set_mac_address;
1143         dev->tx_timeout = lbs_tx_timeout;
1144         dev->get_stats = lbs_get_stats;
1145         dev->watchdog_timeo = 5 * HZ;
1146         dev->ethtool_ops = &lbs_ethtool_ops;
1147 #ifdef  WIRELESS_EXT
1148         dev->wireless_handlers = (struct iw_handler_def *)&lbs_handler_def;
1149 #endif
1150         dev->flags |= IFF_BROADCAST | IFF_MULTICAST;
1151         dev->set_multicast_list = lbs_set_multicast_list;
1152
1153         SET_NETDEV_DEV(dev, dmdev);
1154
1155         priv->rtap_net_dev = NULL;
1156
1157         lbs_deb_thread("Starting main thread...\n");
1158         init_waitqueue_head(&priv->waitq);
1159         priv->main_thread = kthread_run(lbs_thread, dev, "lbs_main");
1160         if (IS_ERR(priv->main_thread)) {
1161                 lbs_deb_thread("Error creating main thread.\n");
1162                 goto err_init_adapter;
1163         }
1164
1165         priv->work_thread = create_singlethread_workqueue("lbs_worker");
1166         INIT_DELAYED_WORK(&priv->assoc_work, lbs_association_worker);
1167         INIT_DELAYED_WORK(&priv->scan_work, lbs_scan_worker);
1168         INIT_WORK(&priv->mcast_work, lbs_set_mcast_worker);
1169         INIT_WORK(&priv->sync_channel, lbs_sync_channel_worker);
1170
1171         sprintf(priv->mesh_ssid, "mesh");
1172         priv->mesh_ssid_len = 4;
1173
1174         priv->wol_criteria = 0xffffffff;
1175         priv->wol_gpio = 0xff;
1176
1177         goto done;
1178
1179 err_init_adapter:
1180         lbs_free_adapter(priv);
1181         free_netdev(dev);
1182         priv = NULL;
1183
1184 done:
1185         lbs_deb_leave_args(LBS_DEB_MAIN, "priv %p", priv);
1186         return priv;
1187 }
1188 EXPORT_SYMBOL_GPL(lbs_add_card);
1189
1190
1191 void lbs_remove_card(struct lbs_private *priv)
1192 {
1193         struct net_device *dev = priv->dev;
1194         union iwreq_data wrqu;
1195
1196         lbs_deb_enter(LBS_DEB_MAIN);
1197
1198         lbs_remove_mesh(priv);
1199         lbs_remove_rtap(priv);
1200
1201         dev = priv->dev;
1202
1203         cancel_delayed_work_sync(&priv->scan_work);
1204         cancel_delayed_work_sync(&priv->assoc_work);
1205         cancel_work_sync(&priv->mcast_work);
1206
1207         /* worker thread destruction blocks on the in-flight command which
1208          * should have been cleared already in lbs_stop_card().
1209          */
1210         lbs_deb_main("destroying worker thread\n");
1211         destroy_workqueue(priv->work_thread);
1212         lbs_deb_main("done destroying worker thread\n");
1213
1214         if (priv->psmode == LBS802_11POWERMODEMAX_PSP) {
1215                 priv->psmode = LBS802_11POWERMODECAM;
1216                 lbs_ps_wakeup(priv, CMD_OPTION_WAITFORRSP);
1217         }
1218
1219         memset(wrqu.ap_addr.sa_data, 0xaa, ETH_ALEN);
1220         wrqu.ap_addr.sa_family = ARPHRD_ETHER;
1221         wireless_send_event(priv->dev, SIOCGIWAP, &wrqu, NULL);
1222
1223         /* Stop the thread servicing the interrupts */
1224         priv->surpriseremoved = 1;
1225         kthread_stop(priv->main_thread);
1226
1227         lbs_free_adapter(priv);
1228
1229         priv->dev = NULL;
1230         free_netdev(dev);
1231
1232         lbs_deb_leave(LBS_DEB_MAIN);
1233 }
1234 EXPORT_SYMBOL_GPL(lbs_remove_card);
1235
1236
1237 int lbs_start_card(struct lbs_private *priv)
1238 {
1239         struct net_device *dev = priv->dev;
1240         int ret = -1;
1241
1242         lbs_deb_enter(LBS_DEB_MAIN);
1243
1244         /* poke the firmware */
1245         ret = lbs_setup_firmware(priv);
1246         if (ret)
1247                 goto done;
1248
1249         /* init 802.11d */
1250         lbs_init_11d(priv);
1251
1252         if (register_netdev(dev)) {
1253                 lbs_pr_err("cannot register ethX device\n");
1254                 goto done;
1255         }
1256
1257         lbs_update_channel(priv);
1258
1259         /* 5.0.16p0 is known to NOT support any mesh */
1260         if (priv->fwrelease > 0x05001000) {
1261                 /* Enable mesh, if supported, and work out which TLV it uses.
1262                    0x100 + 291 is an unofficial value used in 5.110.20.pXX
1263                    0x100 + 37 is the official value used in 5.110.21.pXX
1264                    but we check them in that order because 20.pXX doesn't
1265                    give an error -- it just silently fails. */
1266
1267                 /* 5.110.20.pXX firmware will fail the command if the channel
1268                    doesn't match the existing channel. But only if the TLV
1269                    is correct. If the channel is wrong, _BOTH_ versions will
1270                    give an error to 0x100+291, and allow 0x100+37 to succeed.
1271                    It's just that 5.110.20.pXX will not have done anything
1272                    useful */
1273
1274                 priv->mesh_tlv = 0x100 + 291;
1275                 if (lbs_mesh_config(priv, CMD_ACT_MESH_CONFIG_START,
1276                                     priv->curbssparams.channel)) {
1277                         priv->mesh_tlv = 0x100 + 37;
1278                         if (lbs_mesh_config(priv, CMD_ACT_MESH_CONFIG_START,
1279                                             priv->curbssparams.channel))
1280                                 priv->mesh_tlv = 0;
1281                 }
1282                 if (priv->mesh_tlv) {
1283                         lbs_add_mesh(priv);
1284
1285                         if (device_create_file(&dev->dev, &dev_attr_lbs_mesh))
1286                                 lbs_pr_err("cannot register lbs_mesh attribute\n");
1287
1288                         /* While rtap isn't related to mesh, only mesh-enabled
1289                          * firmware implements the rtap functionality via
1290                          * CMD_802_11_MONITOR_MODE.
1291                          */
1292                         if (device_create_file(&dev->dev, &dev_attr_lbs_rtap))
1293                                 lbs_pr_err("cannot register lbs_rtap attribute\n");
1294                 }
1295         }
1296
1297         lbs_debugfs_init_one(priv, dev);
1298
1299         lbs_pr_info("%s: Marvell WLAN 802.11 adapter\n", dev->name);
1300
1301         ret = 0;
1302
1303 done:
1304         lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
1305         return ret;
1306 }
1307 EXPORT_SYMBOL_GPL(lbs_start_card);
1308
1309
1310 void lbs_stop_card(struct lbs_private *priv)
1311 {
1312         struct net_device *dev = priv->dev;
1313         struct cmd_ctrl_node *cmdnode;
1314         unsigned long flags;
1315
1316         lbs_deb_enter(LBS_DEB_MAIN);
1317
1318         if (!priv)
1319                 goto out;
1320
1321         netif_stop_queue(priv->dev);
1322         netif_carrier_off(priv->dev);
1323
1324         lbs_debugfs_remove_one(priv);
1325         if (priv->mesh_tlv) {
1326                 device_remove_file(&dev->dev, &dev_attr_lbs_mesh);
1327                 device_remove_file(&dev->dev, &dev_attr_lbs_rtap);
1328         }
1329
1330         /* Delete the timeout of the currently processing command */
1331         del_timer_sync(&priv->command_timer);
1332
1333         /* Flush pending command nodes */
1334         spin_lock_irqsave(&priv->driver_lock, flags);
1335         lbs_deb_main("clearing pending commands\n");
1336         list_for_each_entry(cmdnode, &priv->cmdpendingq, list) {
1337                 cmdnode->result = -ENOENT;
1338                 cmdnode->cmdwaitqwoken = 1;
1339                 wake_up_interruptible(&cmdnode->cmdwait_q);
1340         }
1341
1342         /* Flush the command the card is currently processing */
1343         if (priv->cur_cmd) {
1344                 lbs_deb_main("clearing current command\n");
1345                 priv->cur_cmd->result = -ENOENT;
1346                 priv->cur_cmd->cmdwaitqwoken = 1;
1347                 wake_up_interruptible(&priv->cur_cmd->cmdwait_q);
1348         }
1349         lbs_deb_main("done clearing commands\n");
1350         spin_unlock_irqrestore(&priv->driver_lock, flags);
1351
1352         unregister_netdev(dev);
1353
1354 out:
1355         lbs_deb_leave(LBS_DEB_MAIN);
1356 }
1357 EXPORT_SYMBOL_GPL(lbs_stop_card);
1358
1359
1360 /**
1361  * @brief This function adds mshX interface
1362  *
1363  *  @param priv    A pointer to the struct lbs_private structure
1364  *  @return        0 if successful, -X otherwise
1365  */
1366 static int lbs_add_mesh(struct lbs_private *priv)
1367 {
1368         struct net_device *mesh_dev = NULL;
1369         int ret = 0;
1370
1371         lbs_deb_enter(LBS_DEB_MESH);
1372
1373         /* Allocate a virtual mesh device */
1374         if (!(mesh_dev = alloc_netdev(0, "msh%d", ether_setup))) {
1375                 lbs_deb_mesh("init mshX device failed\n");
1376                 ret = -ENOMEM;
1377                 goto done;
1378         }
1379         mesh_dev->ml_priv = priv;
1380         priv->mesh_dev = mesh_dev;
1381
1382         mesh_dev->open = lbs_dev_open;
1383         mesh_dev->hard_start_xmit = lbs_hard_start_xmit;
1384         mesh_dev->stop = lbs_mesh_stop;
1385         mesh_dev->get_stats = lbs_get_stats;
1386         mesh_dev->set_mac_address = lbs_set_mac_address;
1387         mesh_dev->ethtool_ops = &lbs_ethtool_ops;
1388         memcpy(mesh_dev->dev_addr, priv->dev->dev_addr,
1389                         sizeof(priv->dev->dev_addr));
1390
1391         SET_NETDEV_DEV(priv->mesh_dev, priv->dev->dev.parent);
1392
1393 #ifdef  WIRELESS_EXT
1394         mesh_dev->wireless_handlers = (struct iw_handler_def *)&mesh_handler_def;
1395 #endif
1396         mesh_dev->flags |= IFF_BROADCAST | IFF_MULTICAST;
1397         mesh_dev->set_multicast_list = lbs_set_multicast_list;
1398         /* Register virtual mesh interface */
1399         ret = register_netdev(mesh_dev);
1400         if (ret) {
1401                 lbs_pr_err("cannot register mshX virtual interface\n");
1402                 goto err_free;
1403         }
1404
1405         ret = sysfs_create_group(&(mesh_dev->dev.kobj), &lbs_mesh_attr_group);
1406         if (ret)
1407                 goto err_unregister;
1408
1409         lbs_persist_config_init(mesh_dev);
1410
1411         /* Everything successful */
1412         ret = 0;
1413         goto done;
1414
1415 err_unregister:
1416         unregister_netdev(mesh_dev);
1417
1418 err_free:
1419         free_netdev(mesh_dev);
1420
1421 done:
1422         lbs_deb_leave_args(LBS_DEB_MESH, "ret %d", ret);
1423         return ret;
1424 }
1425
1426 static void lbs_remove_mesh(struct lbs_private *priv)
1427 {
1428         struct net_device *mesh_dev;
1429
1430
1431         mesh_dev = priv->mesh_dev;
1432         if (!mesh_dev)
1433                 return;
1434
1435         lbs_deb_enter(LBS_DEB_MESH);
1436         netif_stop_queue(mesh_dev);
1437         netif_carrier_off(mesh_dev);
1438         sysfs_remove_group(&(mesh_dev->dev.kobj), &lbs_mesh_attr_group);
1439         lbs_persist_config_remove(mesh_dev);
1440         unregister_netdev(mesh_dev);
1441         priv->mesh_dev = NULL;
1442         free_netdev(mesh_dev);
1443         lbs_deb_leave(LBS_DEB_MESH);
1444 }
1445
1446 /**
1447  *  @brief This function finds the CFP in
1448  *  region_cfp_table based on region and band parameter.
1449  *
1450  *  @param region  The region code
1451  *  @param band    The band
1452  *  @param cfp_no  A pointer to CFP number
1453  *  @return        A pointer to CFP
1454  */
1455 struct chan_freq_power *lbs_get_region_cfp_table(u8 region, int *cfp_no)
1456 {
1457         int i, end;
1458
1459         lbs_deb_enter(LBS_DEB_MAIN);
1460
1461         end = ARRAY_SIZE(region_cfp_table);
1462
1463         for (i = 0; i < end ; i++) {
1464                 lbs_deb_main("region_cfp_table[i].region=%d\n",
1465                         region_cfp_table[i].region);
1466                 if (region_cfp_table[i].region == region) {
1467                         *cfp_no = region_cfp_table[i].cfp_no_BG;
1468                         lbs_deb_leave(LBS_DEB_MAIN);
1469                         return region_cfp_table[i].cfp_BG;
1470                 }
1471         }
1472
1473         lbs_deb_leave_args(LBS_DEB_MAIN, "ret NULL");
1474         return NULL;
1475 }
1476
1477 int lbs_set_regiontable(struct lbs_private *priv, u8 region, u8 band)
1478 {
1479         int ret = 0;
1480         int i = 0;
1481
1482         struct chan_freq_power *cfp;
1483         int cfp_no;
1484
1485         lbs_deb_enter(LBS_DEB_MAIN);
1486
1487         memset(priv->region_channel, 0, sizeof(priv->region_channel));
1488
1489         cfp = lbs_get_region_cfp_table(region, &cfp_no);
1490         if (cfp != NULL) {
1491                 priv->region_channel[i].nrcfp = cfp_no;
1492                 priv->region_channel[i].CFP = cfp;
1493         } else {
1494                 lbs_deb_main("wrong region code %#x in band B/G\n",
1495                        region);
1496                 ret = -1;
1497                 goto out;
1498         }
1499         priv->region_channel[i].valid = 1;
1500         priv->region_channel[i].region = region;
1501         priv->region_channel[i].band = band;
1502         i++;
1503 out:
1504         lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
1505         return ret;
1506 }
1507
1508 void lbs_queue_event(struct lbs_private *priv, u32 event)
1509 {
1510         unsigned long flags;
1511
1512         lbs_deb_enter(LBS_DEB_THREAD);
1513         spin_lock_irqsave(&priv->driver_lock, flags);
1514
1515         if (priv->psstate == PS_STATE_SLEEP)
1516                 priv->psstate = PS_STATE_AWAKE;
1517
1518         __kfifo_put(priv->event_fifo, (unsigned char *) &event, sizeof(u32));
1519
1520         wake_up_interruptible(&priv->waitq);
1521
1522         spin_unlock_irqrestore(&priv->driver_lock, flags);
1523         lbs_deb_leave(LBS_DEB_THREAD);
1524 }
1525 EXPORT_SYMBOL_GPL(lbs_queue_event);
1526
1527 void lbs_notify_command_response(struct lbs_private *priv, u8 resp_idx)
1528 {
1529         lbs_deb_enter(LBS_DEB_THREAD);
1530
1531         if (priv->psstate == PS_STATE_SLEEP)
1532                 priv->psstate = PS_STATE_AWAKE;
1533
1534         /* Swap buffers by flipping the response index */
1535         BUG_ON(resp_idx > 1);
1536         priv->resp_idx = resp_idx;
1537
1538         wake_up_interruptible(&priv->waitq);
1539
1540         lbs_deb_leave(LBS_DEB_THREAD);
1541 }
1542 EXPORT_SYMBOL_GPL(lbs_notify_command_response);
1543
1544 static int __init lbs_init_module(void)
1545 {
1546         lbs_deb_enter(LBS_DEB_MAIN);
1547         memset(&confirm_sleep, 0, sizeof(confirm_sleep));
1548         confirm_sleep.hdr.command = cpu_to_le16(CMD_802_11_PS_MODE);
1549         confirm_sleep.hdr.size = cpu_to_le16(sizeof(confirm_sleep));
1550         confirm_sleep.action = cpu_to_le16(CMD_SUBCMD_SLEEP_CONFIRMED);
1551         lbs_debugfs_init();
1552         lbs_deb_leave(LBS_DEB_MAIN);
1553         return 0;
1554 }
1555
1556 static void __exit lbs_exit_module(void)
1557 {
1558         lbs_deb_enter(LBS_DEB_MAIN);
1559         lbs_debugfs_remove();
1560         lbs_deb_leave(LBS_DEB_MAIN);
1561 }
1562
1563 /*
1564  * rtap interface support fuctions
1565  */
1566
1567 static int lbs_rtap_open(struct net_device *dev)
1568 {
1569         /* Yes, _stop_ the queue. Because we don't support injection */
1570         lbs_deb_enter(LBS_DEB_MAIN);
1571         netif_carrier_off(dev);
1572         netif_stop_queue(dev);
1573         lbs_deb_leave(LBS_DEB_LEAVE);
1574         return 0;
1575 }
1576
1577 static int lbs_rtap_stop(struct net_device *dev)
1578 {
1579         lbs_deb_enter(LBS_DEB_MAIN);
1580         lbs_deb_leave(LBS_DEB_MAIN);
1581         return 0;
1582 }
1583
1584 static int lbs_rtap_hard_start_xmit(struct sk_buff *skb, struct net_device *dev)
1585 {
1586         netif_stop_queue(dev);
1587         return NETDEV_TX_BUSY;
1588 }
1589
1590 static struct net_device_stats *lbs_rtap_get_stats(struct net_device *dev)
1591 {
1592         struct lbs_private *priv = dev->ml_priv;
1593         lbs_deb_enter(LBS_DEB_NET);
1594         return &priv->stats;
1595 }
1596
1597
1598 static void lbs_remove_rtap(struct lbs_private *priv)
1599 {
1600         lbs_deb_enter(LBS_DEB_MAIN);
1601         if (priv->rtap_net_dev == NULL)
1602                 goto out;
1603         unregister_netdev(priv->rtap_net_dev);
1604         free_netdev(priv->rtap_net_dev);
1605         priv->rtap_net_dev = NULL;
1606 out:
1607         lbs_deb_leave(LBS_DEB_MAIN);
1608 }
1609
1610 static int lbs_add_rtap(struct lbs_private *priv)
1611 {
1612         int ret = 0;
1613         struct net_device *rtap_dev;
1614
1615         lbs_deb_enter(LBS_DEB_MAIN);
1616         if (priv->rtap_net_dev) {
1617                 ret = -EPERM;
1618                 goto out;
1619         }
1620
1621         rtap_dev = alloc_netdev(0, "rtap%d", ether_setup);
1622         if (rtap_dev == NULL) {
1623                 ret = -ENOMEM;
1624                 goto out;
1625         }
1626
1627         memcpy(rtap_dev->dev_addr, priv->current_addr, ETH_ALEN);
1628         rtap_dev->type = ARPHRD_IEEE80211_RADIOTAP;
1629         rtap_dev->open = lbs_rtap_open;
1630         rtap_dev->stop = lbs_rtap_stop;
1631         rtap_dev->get_stats = lbs_rtap_get_stats;
1632         rtap_dev->hard_start_xmit = lbs_rtap_hard_start_xmit;
1633         rtap_dev->ml_priv = priv;
1634         SET_NETDEV_DEV(rtap_dev, priv->dev->dev.parent);
1635
1636         ret = register_netdev(rtap_dev);
1637         if (ret) {
1638                 free_netdev(rtap_dev);
1639                 goto out;
1640         }
1641         priv->rtap_net_dev = rtap_dev;
1642
1643 out:
1644         lbs_deb_leave_args(LBS_DEB_MAIN, "ret %d", ret);
1645         return ret;
1646 }
1647
1648 module_init(lbs_init_module);
1649 module_exit(lbs_exit_module);
1650
1651 MODULE_DESCRIPTION("Libertas WLAN Driver Library");
1652 MODULE_AUTHOR("Marvell International Ltd.");
1653 MODULE_LICENSE("GPL");