wl1271: Add config structure for connection management parameters
[safe/jmp/linux-2.6] / drivers / net / wireless / wl12xx / wl1271_cmd.c
1 /*
2  * This file is part of wl1271
3  *
4  * Copyright (C) 2009 Nokia Corporation
5  *
6  * Contact: Luciano Coelho <luciano.coelho@nokia.com>
7  *
8  * This program is free software; you can redistribute it and/or
9  * modify it under the terms of the GNU General Public License
10  * version 2 as published by the Free Software Foundation.
11  *
12  * This program is distributed in the hope that it will be useful, but
13  * WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
15  * General Public License for more details.
16  *
17  * You should have received a copy of the GNU General Public License
18  * along with this program; if not, write to the Free Software
19  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
20  * 02110-1301 USA
21  *
22  */
23
24 #include <linux/module.h>
25 #include <linux/platform_device.h>
26 #include <linux/crc7.h>
27 #include <linux/spi/spi.h>
28 #include <linux/etherdevice.h>
29
30 #include "wl1271.h"
31 #include "wl1271_reg.h"
32 #include "wl1271_spi.h"
33 #include "wl1271_acx.h"
34 #include "wl12xx_80211.h"
35 #include "wl1271_cmd.h"
36
37 /*
38  * send command to firmware
39  *
40  * @wl: wl struct
41  * @id: command id
42  * @buf: buffer containing the command, must work with dma
43  * @len: length of the buffer
44  */
45 int wl1271_cmd_send(struct wl1271 *wl, u16 id, void *buf, size_t len)
46 {
47         struct wl1271_cmd_header *cmd;
48         unsigned long timeout;
49         u32 intr;
50         int ret = 0;
51
52         cmd = buf;
53         cmd->id = id;
54         cmd->status = 0;
55
56         WARN_ON(len % 4 != 0);
57
58         wl1271_spi_write(wl, wl->cmd_box_addr, buf, len, false);
59
60         wl1271_spi_write32(wl, ACX_REG_INTERRUPT_TRIG, INTR_TRIG_CMD);
61
62         timeout = jiffies + msecs_to_jiffies(WL1271_COMMAND_TIMEOUT);
63
64         intr = wl1271_spi_read32(wl, ACX_REG_INTERRUPT_NO_CLEAR);
65         while (!(intr & WL1271_ACX_INTR_CMD_COMPLETE)) {
66                 if (time_after(jiffies, timeout)) {
67                         wl1271_error("command complete timeout");
68                         ret = -ETIMEDOUT;
69                         goto out;
70                 }
71
72                 msleep(1);
73
74                 intr = wl1271_spi_read32(wl, ACX_REG_INTERRUPT_NO_CLEAR);
75         }
76
77         wl1271_spi_write32(wl, ACX_REG_INTERRUPT_ACK,
78                            WL1271_ACX_INTR_CMD_COMPLETE);
79
80 out:
81         return ret;
82 }
83
84 int wl1271_cmd_cal_channel_tune(struct wl1271 *wl)
85 {
86         struct wl1271_cmd_cal_channel_tune *cmd;
87         int ret = 0;
88
89         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
90         if (!cmd)
91                 return -ENOMEM;
92
93         cmd->test.id = TEST_CMD_CHANNEL_TUNE;
94
95         cmd->band = WL1271_CHANNEL_TUNE_BAND_2_4;
96         /* set up any channel, 7 is in the middle of the range */
97         cmd->channel = 7;
98
99         ret = wl1271_cmd_test(wl, cmd, sizeof(*cmd), 0);
100         if (ret < 0)
101                 wl1271_warning("TEST_CMD_CHANNEL_TUNE failed");
102
103         kfree(cmd);
104         return ret;
105 }
106
107 int wl1271_cmd_cal_update_ref_point(struct wl1271 *wl)
108 {
109         struct wl1271_cmd_cal_update_ref_point *cmd;
110         int ret = 0;
111
112         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
113         if (!cmd)
114                 return -ENOMEM;
115
116         cmd->test.id = TEST_CMD_UPDATE_PD_REFERENCE_POINT;
117
118         /* FIXME: still waiting for the correct values */
119         cmd->ref_power    = 0;
120         cmd->ref_detector = 0;
121
122         cmd->sub_band     = WL1271_PD_REFERENCE_POINT_BAND_B_G;
123
124         ret = wl1271_cmd_test(wl, cmd, sizeof(*cmd), 0);
125         if (ret < 0)
126                 wl1271_warning("TEST_CMD_UPDATE_PD_REFERENCE_POINT failed");
127
128         kfree(cmd);
129         return ret;
130 }
131
132 int wl1271_cmd_cal_p2g(struct wl1271 *wl)
133 {
134         struct wl1271_cmd_cal_p2g *cmd;
135         int ret = 0;
136
137         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
138         if (!cmd)
139                 return -ENOMEM;
140
141         cmd->test.id = TEST_CMD_P2G_CAL;
142
143         cmd->sub_band_mask = WL1271_CAL_P2G_BAND_B_G;
144
145         ret = wl1271_cmd_test(wl, cmd, sizeof(*cmd), 0);
146         if (ret < 0)
147                 wl1271_warning("TEST_CMD_P2G_CAL failed");
148
149         kfree(cmd);
150         return ret;
151 }
152
153 int wl1271_cmd_cal(struct wl1271 *wl)
154 {
155         /*
156          * FIXME: we must make sure that we're not sleeping when calibration
157          * is done
158          */
159         int ret;
160
161         wl1271_notice("performing tx calibration");
162
163         ret = wl1271_cmd_cal_channel_tune(wl);
164         if (ret < 0)
165                 return ret;
166
167         ret = wl1271_cmd_cal_update_ref_point(wl);
168         if (ret < 0)
169                 return ret;
170
171         ret = wl1271_cmd_cal_p2g(wl);
172         if (ret < 0)
173                 return ret;
174
175         return ret;
176 }
177
178 int wl1271_cmd_join(struct wl1271 *wl)
179 {
180         static bool do_cal = true;
181         struct wl1271_cmd_join *join;
182         int ret, i;
183         u8 *bssid;
184
185         /* FIXME: remove when we get calibration from the factory */
186         if (do_cal) {
187                 ret = wl1271_cmd_cal(wl);
188                 if (ret < 0)
189                         wl1271_warning("couldn't calibrate");
190                 else
191                         do_cal = false;
192         }
193
194         /* FIXME: This is a workaround, because with the current stack, we
195          * cannot know when we have disassociated.  So, if we have already
196          * joined, we disconnect before joining again. */
197         if (wl->joined) {
198                 ret = wl1271_cmd_disconnect(wl);
199                 if (ret < 0) {
200                         wl1271_error("failed to disconnect before rejoining");
201                         goto out;
202                 }
203
204                 wl->joined = false;
205         }
206
207         join = kzalloc(sizeof(*join), GFP_KERNEL);
208         if (!join) {
209                 ret = -ENOMEM;
210                 goto out;
211         }
212
213         wl1271_debug(DEBUG_CMD, "cmd join");
214
215         /* Reverse order BSSID */
216         bssid = (u8 *) &join->bssid_lsb;
217         for (i = 0; i < ETH_ALEN; i++)
218                 bssid[i] = wl->bssid[ETH_ALEN - i - 1];
219
220         join->rx_config_options = wl->rx_config;
221         join->rx_filter_options = wl->rx_filter;
222
223         /*
224          * FIXME: disable temporarily all filters because after commit
225          * 9cef8737 "mac80211: fix managed mode BSSID handling" broke
226          * association. The filter logic needs to be implemented properly
227          * and once that is done, this hack can be removed.
228          */
229         join->rx_config_options = 0;
230         join->rx_filter_options = WL1271_DEFAULT_RX_FILTER;
231
232         join->basic_rate_set = CONF_HW_BIT_RATE_1MBPS | CONF_HW_BIT_RATE_2MBPS |
233                 CONF_HW_BIT_RATE_5_5MBPS | CONF_HW_BIT_RATE_11MBPS;
234
235         join->beacon_interval = WL1271_DEFAULT_BEACON_INT;
236         join->dtim_interval = WL1271_DEFAULT_DTIM_PERIOD;
237         join->bss_type = wl->bss_type;
238         join->channel = wl->channel;
239         join->ssid_len = wl->ssid_len;
240         memcpy(join->ssid, wl->ssid, wl->ssid_len);
241         join->ctrl = WL1271_JOIN_CMD_CTRL_TX_FLUSH;
242
243         /* increment the session counter */
244         wl->session_counter++;
245         if (wl->session_counter >= SESSION_COUNTER_MAX)
246                 wl->session_counter = 0;
247
248         join->ctrl |= wl->session_counter << WL1271_JOIN_CMD_TX_SESSION_OFFSET;
249
250         /* reset TX security counters */
251         wl->tx_security_last_seq = 0;
252         wl->tx_security_seq_16 = 0;
253         wl->tx_security_seq_32 = 0;
254
255         ret = wl1271_cmd_send(wl, CMD_START_JOIN, join, sizeof(*join));
256         if (ret < 0) {
257                 wl1271_error("failed to initiate cmd join");
258                 goto out_free;
259         }
260
261         wl->joined = true;
262
263         /*
264          * ugly hack: we should wait for JOIN_EVENT_COMPLETE_ID but to
265          * simplify locking we just sleep instead, for now
266          */
267         msleep(10);
268
269 out_free:
270         kfree(join);
271
272 out:
273         return ret;
274 }
275
276 /**
277  * send test command to firmware
278  *
279  * @wl: wl struct
280  * @buf: buffer containing the command, with all headers, must work with dma
281  * @len: length of the buffer
282  * @answer: is answer needed
283  */
284 int wl1271_cmd_test(struct wl1271 *wl, void *buf, size_t buf_len, u8 answer)
285 {
286         int ret;
287
288         wl1271_debug(DEBUG_CMD, "cmd test");
289
290         ret = wl1271_cmd_send(wl, CMD_TEST, buf, buf_len);
291
292         if (ret < 0) {
293                 wl1271_warning("TEST command failed");
294                 return ret;
295         }
296
297         if (answer) {
298                 struct wl1271_command *cmd_answer;
299
300                 /*
301                  * The test command got in, we can read the answer.
302                  * The answer would be a wl1271_command, where the
303                  * parameter array contains the actual answer.
304                  */
305                 wl1271_spi_read(wl, wl->cmd_box_addr, buf, buf_len, false);
306
307                 cmd_answer = buf;
308
309                 if (cmd_answer->header.status != CMD_STATUS_SUCCESS)
310                         wl1271_error("TEST command answer error: %d",
311                                      cmd_answer->header.status);
312         }
313
314         return 0;
315 }
316
317 /**
318  * read acx from firmware
319  *
320  * @wl: wl struct
321  * @id: acx id
322  * @buf: buffer for the response, including all headers, must work with dma
323  * @len: lenght of buf
324  */
325 int wl1271_cmd_interrogate(struct wl1271 *wl, u16 id, void *buf, size_t len)
326 {
327         struct acx_header *acx = buf;
328         int ret;
329
330         wl1271_debug(DEBUG_CMD, "cmd interrogate");
331
332         acx->id = id;
333
334         /* payload length, does not include any headers */
335         acx->len = len - sizeof(*acx);
336
337         ret = wl1271_cmd_send(wl, CMD_INTERROGATE, acx, sizeof(*acx));
338         if (ret < 0) {
339                 wl1271_error("INTERROGATE command failed");
340                 goto out;
341         }
342
343         /* the interrogate command got in, we can read the answer */
344         wl1271_spi_read(wl, wl->cmd_box_addr, buf, len, false);
345
346         acx = buf;
347         if (acx->cmd.status != CMD_STATUS_SUCCESS)
348                 wl1271_error("INTERROGATE command error: %d",
349                              acx->cmd.status);
350
351 out:
352         return ret;
353 }
354
355 /**
356  * write acx value to firmware
357  *
358  * @wl: wl struct
359  * @id: acx id
360  * @buf: buffer containing acx, including all headers, must work with dma
361  * @len: length of buf
362  */
363 int wl1271_cmd_configure(struct wl1271 *wl, u16 id, void *buf, size_t len)
364 {
365         struct acx_header *acx = buf;
366         int ret;
367
368         wl1271_debug(DEBUG_CMD, "cmd configure");
369
370         acx->id = id;
371
372         /* payload length, does not include any headers */
373         acx->len = len - sizeof(*acx);
374
375         ret = wl1271_cmd_send(wl, CMD_CONFIGURE, acx, len);
376         if (ret < 0) {
377                 wl1271_warning("CONFIGURE command NOK");
378                 return ret;
379         }
380
381         return 0;
382 }
383
384 int wl1271_cmd_data_path(struct wl1271 *wl, u8 channel, bool enable)
385 {
386         struct cmd_enabledisable_path *cmd;
387         int ret;
388         u16 cmd_rx, cmd_tx;
389
390         wl1271_debug(DEBUG_CMD, "cmd data path");
391
392         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
393         if (!cmd) {
394                 ret = -ENOMEM;
395                 goto out;
396         }
397
398         cmd->channel = channel;
399
400         if (enable) {
401                 cmd_rx = CMD_ENABLE_RX;
402                 cmd_tx = CMD_ENABLE_TX;
403         } else {
404                 cmd_rx = CMD_DISABLE_RX;
405                 cmd_tx = CMD_DISABLE_TX;
406         }
407
408         ret = wl1271_cmd_send(wl, cmd_rx, cmd, sizeof(*cmd));
409         if (ret < 0) {
410                 wl1271_error("rx %s cmd for channel %d failed",
411                              enable ? "start" : "stop", channel);
412                 goto out;
413         }
414
415         wl1271_debug(DEBUG_BOOT, "rx %s cmd channel %d",
416                      enable ? "start" : "stop", channel);
417
418         ret = wl1271_cmd_send(wl, cmd_tx, cmd, sizeof(*cmd));
419         if (ret < 0) {
420                 wl1271_error("tx %s cmd for channel %d failed",
421                              enable ? "start" : "stop", channel);
422                 return ret;
423         }
424
425         wl1271_debug(DEBUG_BOOT, "tx %s cmd channel %d",
426                      enable ? "start" : "stop", channel);
427
428 out:
429         kfree(cmd);
430         return ret;
431 }
432
433 int wl1271_cmd_ps_mode(struct wl1271 *wl, u8 ps_mode)
434 {
435         struct wl1271_cmd_ps_params *ps_params = NULL;
436         int ret = 0;
437
438         /* FIXME: this should be in ps.c */
439         ret = wl1271_acx_wake_up_conditions(wl);
440         if (ret < 0) {
441                 wl1271_error("couldn't set wake up conditions");
442                 goto out;
443         }
444
445         wl1271_debug(DEBUG_CMD, "cmd set ps mode");
446
447         ps_params = kzalloc(sizeof(*ps_params), GFP_KERNEL);
448         if (!ps_params) {
449                 ret = -ENOMEM;
450                 goto out;
451         }
452
453         ps_params->ps_mode = ps_mode;
454         ps_params->send_null_data = 1;
455         ps_params->retries = 5;
456         ps_params->hang_over_period = 128;
457         ps_params->null_data_rate = 1; /* 1 Mbps */
458
459         ret = wl1271_cmd_send(wl, CMD_SET_PS_MODE, ps_params,
460                               sizeof(*ps_params));
461         if (ret < 0) {
462                 wl1271_error("cmd set_ps_mode failed");
463                 goto out;
464         }
465
466 out:
467         kfree(ps_params);
468         return ret;
469 }
470
471 int wl1271_cmd_read_memory(struct wl1271 *wl, u32 addr, void *answer,
472                            size_t len)
473 {
474         struct cmd_read_write_memory *cmd;
475         int ret = 0;
476
477         wl1271_debug(DEBUG_CMD, "cmd read memory");
478
479         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
480         if (!cmd) {
481                 ret = -ENOMEM;
482                 goto out;
483         }
484
485         WARN_ON(len > MAX_READ_SIZE);
486         len = min_t(size_t, len, MAX_READ_SIZE);
487
488         cmd->addr = addr;
489         cmd->size = len;
490
491         ret = wl1271_cmd_send(wl, CMD_READ_MEMORY, cmd, sizeof(*cmd));
492         if (ret < 0) {
493                 wl1271_error("read memory command failed: %d", ret);
494                 goto out;
495         }
496
497         /* the read command got in, we can now read the answer */
498         wl1271_spi_read(wl, wl->cmd_box_addr, cmd, sizeof(*cmd), false);
499
500         if (cmd->header.status != CMD_STATUS_SUCCESS)
501                 wl1271_error("error in read command result: %d",
502                              cmd->header.status);
503
504         memcpy(answer, cmd->value, len);
505
506 out:
507         kfree(cmd);
508         return ret;
509 }
510
511 int wl1271_cmd_scan(struct wl1271 *wl, u8 *ssid, size_t len,
512                     u8 active_scan, u8 high_prio, u8 num_channels,
513                     u8 probe_requests)
514 {
515
516         struct wl1271_cmd_trigger_scan_to *trigger = NULL;
517         struct wl1271_cmd_scan *params = NULL;
518         int i, ret;
519         u16 scan_options = 0;
520
521         if (wl->scanning)
522                 return -EINVAL;
523
524         params = kzalloc(sizeof(*params), GFP_KERNEL);
525         if (!params)
526                 return -ENOMEM;
527
528         params->params.rx_config_options = cpu_to_le32(CFG_RX_ALL_GOOD);
529         params->params.rx_filter_options =
530                 cpu_to_le32(CFG_RX_PRSP_EN | CFG_RX_MGMT_EN | CFG_RX_BCN_EN);
531
532         if (!active_scan)
533                 scan_options |= WL1271_SCAN_OPT_PASSIVE;
534         if (high_prio)
535                 scan_options |= WL1271_SCAN_OPT_PRIORITY_HIGH;
536         params->params.scan_options = scan_options;
537
538         params->params.num_channels = num_channels;
539         params->params.num_probe_requests = probe_requests;
540         params->params.tx_rate = cpu_to_le32(CONF_HW_BIT_RATE_2MBPS);
541         params->params.tid_trigger = 0;
542         params->params.scan_tag = WL1271_SCAN_DEFAULT_TAG;
543
544         for (i = 0; i < num_channels; i++) {
545                 params->channels[i].min_duration =
546                         cpu_to_le32(WL1271_SCAN_CHAN_MIN_DURATION);
547                 params->channels[i].max_duration =
548                         cpu_to_le32(WL1271_SCAN_CHAN_MAX_DURATION);
549                 memset(&params->channels[i].bssid_lsb, 0xff, 4);
550                 memset(&params->channels[i].bssid_msb, 0xff, 2);
551                 params->channels[i].early_termination = 0;
552                 params->channels[i].tx_power_att = WL1271_SCAN_CURRENT_TX_PWR;
553                 params->channels[i].channel = i + 1;
554         }
555
556         if (len && ssid) {
557                 params->params.ssid_len = len;
558                 memcpy(params->params.ssid, ssid, len);
559         }
560
561         ret = wl1271_cmd_build_probe_req(wl, ssid, len);
562         if (ret < 0) {
563                 wl1271_error("PROBE request template failed");
564                 goto out;
565         }
566
567         trigger = kzalloc(sizeof(*trigger), GFP_KERNEL);
568         if (!trigger) {
569                 ret = -ENOMEM;
570                 goto out;
571         }
572
573         /* disable the timeout */
574         trigger->timeout = 0;
575
576         ret = wl1271_cmd_send(wl, CMD_TRIGGER_SCAN_TO, trigger,
577                               sizeof(*trigger));
578         if (ret < 0) {
579                 wl1271_error("trigger scan to failed for hw scan");
580                 goto out;
581         }
582
583         wl1271_dump(DEBUG_SCAN, "SCAN: ", params, sizeof(*params));
584
585         wl->scanning = true;
586
587         ret = wl1271_cmd_send(wl, CMD_SCAN, params, sizeof(*params));
588         if (ret < 0) {
589                 wl1271_error("SCAN failed");
590                 goto out;
591         }
592
593         wl1271_spi_read(wl, wl->cmd_box_addr, params, sizeof(*params),
594                         false);
595
596         if (params->header.status != CMD_STATUS_SUCCESS) {
597                 wl1271_error("Scan command error: %d",
598                              params->header.status);
599                 wl->scanning = false;
600                 ret = -EIO;
601                 goto out;
602         }
603
604 out:
605         kfree(params);
606         return ret;
607 }
608
609 int wl1271_cmd_template_set(struct wl1271 *wl, u16 template_id,
610                             void *buf, size_t buf_len)
611 {
612         struct wl1271_cmd_template_set *cmd;
613         int ret = 0;
614
615         wl1271_debug(DEBUG_CMD, "cmd template_set %d", template_id);
616
617         WARN_ON(buf_len > WL1271_CMD_TEMPL_MAX_SIZE);
618         buf_len = min_t(size_t, buf_len, WL1271_CMD_TEMPL_MAX_SIZE);
619
620         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
621         if (!cmd) {
622                 ret = -ENOMEM;
623                 goto out;
624         }
625
626         cmd->len = cpu_to_le16(buf_len);
627         cmd->template_type = template_id;
628         cmd->enabled_rates = wl->conf.tx.rc_conf.enabled_rates;
629         cmd->short_retry_limit = wl->conf.tx.rc_conf.short_retry_limit;
630         cmd->long_retry_limit = wl->conf.tx.rc_conf.long_retry_limit;
631
632         if (buf)
633                 memcpy(cmd->template_data, buf, buf_len);
634
635         ret = wl1271_cmd_send(wl, CMD_SET_TEMPLATE, cmd, sizeof(*cmd));
636         if (ret < 0) {
637                 wl1271_warning("cmd set_template failed: %d", ret);
638                 goto out_free;
639         }
640
641 out_free:
642         kfree(cmd);
643
644 out:
645         return ret;
646 }
647
648 static int wl1271_build_basic_rates(char *rates)
649 {
650         u8 index = 0;
651
652         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_1MB;
653         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_2MB;
654         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_5MB;
655         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_11MB;
656
657         return index;
658 }
659
660 static int wl1271_build_extended_rates(char *rates)
661 {
662         u8 index = 0;
663
664         rates[index++] = IEEE80211_OFDM_RATE_6MB;
665         rates[index++] = IEEE80211_OFDM_RATE_9MB;
666         rates[index++] = IEEE80211_OFDM_RATE_12MB;
667         rates[index++] = IEEE80211_OFDM_RATE_18MB;
668         rates[index++] = IEEE80211_OFDM_RATE_24MB;
669         rates[index++] = IEEE80211_OFDM_RATE_36MB;
670         rates[index++] = IEEE80211_OFDM_RATE_48MB;
671         rates[index++] = IEEE80211_OFDM_RATE_54MB;
672
673         return index;
674 }
675
676 int wl1271_cmd_build_null_data(struct wl1271 *wl)
677 {
678         struct wl12xx_null_data_template template;
679
680         if (!is_zero_ether_addr(wl->bssid)) {
681                 memcpy(template.header.da, wl->bssid, ETH_ALEN);
682                 memcpy(template.header.bssid, wl->bssid, ETH_ALEN);
683         } else {
684                 memset(template.header.da, 0xff, ETH_ALEN);
685                 memset(template.header.bssid, 0xff, ETH_ALEN);
686         }
687
688         memcpy(template.header.sa, wl->mac_addr, ETH_ALEN);
689         template.header.frame_ctl = cpu_to_le16(IEEE80211_FTYPE_DATA |
690                                                 IEEE80211_STYPE_NULLFUNC);
691
692         return wl1271_cmd_template_set(wl, CMD_TEMPL_NULL_DATA, &template,
693                                        sizeof(template));
694
695 }
696
697 int wl1271_cmd_build_ps_poll(struct wl1271 *wl, u16 aid)
698 {
699         struct wl12xx_ps_poll_template template;
700
701         memcpy(template.bssid, wl->bssid, ETH_ALEN);
702         memcpy(template.ta, wl->mac_addr, ETH_ALEN);
703
704         /* aid in PS-Poll has its two MSBs each set to 1 */
705         template.aid = cpu_to_le16(1 << 15 | 1 << 14 | aid);
706
707         template.fc = cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_PSPOLL);
708
709         return wl1271_cmd_template_set(wl, CMD_TEMPL_PS_POLL, &template,
710                                        sizeof(template));
711
712 }
713
714 int wl1271_cmd_build_probe_req(struct wl1271 *wl, u8 *ssid, size_t ssid_len)
715 {
716         struct wl12xx_probe_req_template template;
717         struct wl12xx_ie_rates *rates;
718         char *ptr;
719         u16 size;
720
721         ptr = (char *)&template;
722         size = sizeof(struct ieee80211_header);
723
724         memset(template.header.da, 0xff, ETH_ALEN);
725         memset(template.header.bssid, 0xff, ETH_ALEN);
726         memcpy(template.header.sa, wl->mac_addr, ETH_ALEN);
727         template.header.frame_ctl = cpu_to_le16(IEEE80211_STYPE_PROBE_REQ);
728
729         /* IEs */
730         /* SSID */
731         template.ssid.header.id = WLAN_EID_SSID;
732         template.ssid.header.len = ssid_len;
733         if (ssid_len && ssid)
734                 memcpy(template.ssid.ssid, ssid, ssid_len);
735         size += sizeof(struct wl12xx_ie_header) + ssid_len;
736         ptr += size;
737
738         /* Basic Rates */
739         rates = (struct wl12xx_ie_rates *)ptr;
740         rates->header.id = WLAN_EID_SUPP_RATES;
741         rates->header.len = wl1271_build_basic_rates(rates->rates);
742         size += sizeof(struct wl12xx_ie_header) + rates->header.len;
743         ptr += sizeof(struct wl12xx_ie_header) + rates->header.len;
744
745         /* Extended rates */
746         rates = (struct wl12xx_ie_rates *)ptr;
747         rates->header.id = WLAN_EID_EXT_SUPP_RATES;
748         rates->header.len = wl1271_build_extended_rates(rates->rates);
749         size += sizeof(struct wl12xx_ie_header) + rates->header.len;
750
751         wl1271_dump(DEBUG_SCAN, "PROBE REQ: ", &template, size);
752
753         return wl1271_cmd_template_set(wl, CMD_TEMPL_CFG_PROBE_REQ_2_4,
754                                        &template, size);
755 }
756
757 int wl1271_cmd_set_default_wep_key(struct wl1271 *wl, u8 id)
758 {
759         struct wl1271_cmd_set_keys *cmd;
760         int ret = 0;
761
762         wl1271_debug(DEBUG_CMD, "cmd set_default_wep_key %d", id);
763
764         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
765         if (!cmd) {
766                 ret = -ENOMEM;
767                 goto out;
768         }
769
770         cmd->id = id;
771         cmd->key_action = KEY_SET_ID;
772         cmd->key_type = KEY_WEP;
773
774         ret = wl1271_cmd_send(wl, CMD_SET_KEYS, cmd, sizeof(*cmd));
775         if (ret < 0) {
776                 wl1271_warning("cmd set_default_wep_key failed: %d", ret);
777                 goto out;
778         }
779
780 out:
781         kfree(cmd);
782
783         return ret;
784 }
785
786 int wl1271_cmd_set_key(struct wl1271 *wl, u16 action, u8 id, u8 key_type,
787                        u8 key_size, const u8 *key, const u8 *addr,
788                        u32 tx_seq_32, u16 tx_seq_16)
789 {
790         struct wl1271_cmd_set_keys *cmd;
791         int ret = 0;
792
793         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
794         if (!cmd) {
795                 ret = -ENOMEM;
796                 goto out;
797         }
798
799         if (key_type != KEY_WEP)
800                 memcpy(cmd->addr, addr, ETH_ALEN);
801
802         cmd->key_action = action;
803         cmd->key_size = key_size;
804         cmd->key_type = key_type;
805
806         cmd->ac_seq_num16[0] = tx_seq_16;
807         cmd->ac_seq_num32[0] = tx_seq_32;
808
809         /* we have only one SSID profile */
810         cmd->ssid_profile = 0;
811
812         cmd->id = id;
813
814         if (key_type == KEY_TKIP) {
815                 /*
816                  * We get the key in the following form:
817                  * TKIP (16 bytes) - TX MIC (8 bytes) - RX MIC (8 bytes)
818                  * but the target is expecting:
819                  * TKIP - RX MIC - TX MIC
820                  */
821                 memcpy(cmd->key, key, 16);
822                 memcpy(cmd->key + 16, key + 24, 8);
823                 memcpy(cmd->key + 24, key + 16, 8);
824
825         } else {
826                 memcpy(cmd->key, key, key_size);
827         }
828
829         wl1271_dump(DEBUG_CRYPT, "TARGET KEY: ", cmd, sizeof(*cmd));
830
831         ret = wl1271_cmd_send(wl, CMD_SET_KEYS, cmd, sizeof(*cmd));
832         if (ret < 0) {
833                 wl1271_warning("could not set keys");
834                 goto out;
835         }
836
837 out:
838         kfree(cmd);
839
840         return ret;
841 }
842
843 int wl1271_cmd_disconnect(struct wl1271 *wl)
844 {
845         struct wl1271_cmd_disconnect *cmd;
846         int ret = 0;
847
848         wl1271_debug(DEBUG_CMD, "cmd disconnect");
849
850         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
851         if (!cmd) {
852                 ret = -ENOMEM;
853                 goto out;
854         }
855
856         cmd->rx_config_options = wl->rx_config;
857         cmd->rx_filter_options = wl->rx_filter;
858         /* disconnect reason is not used in immediate disconnections */
859         cmd->type = DISCONNECT_IMMEDIATE;
860
861         ret = wl1271_cmd_send(wl, CMD_DISCONNECT, cmd, sizeof(*cmd));
862         if (ret < 0) {
863                 wl1271_error("failed to send disconnect command");
864                 goto out_free;
865         }
866
867 out_free:
868         kfree(cmd);
869
870 out:
871         return ret;
872 }