2 * This file contains the handling of command
3 * responses as well as events generated by firmware.
5 #include <linux/slab.h>
6 #include <linux/delay.h>
7 #include <linux/sched.h>
8 #include <asm/unaligned.h>
9 #include <net/cfg80211.h>
15 * @brief This function handles disconnect event. it
16 * reports disconnect to upper layer, clean tx/rx packets,
17 * reset link state etc.
19 * @param priv A pointer to struct lbs_private structure
22 void lbs_mac_event_disconnected(struct lbs_private
*priv
)
24 if (priv
->connect_status
!= LBS_CONNECTED
)
27 lbs_deb_enter(LBS_DEB_ASSOC
);
30 * Cisco AP sends EAP failure and de-auth in less than 0.5 ms.
31 * It causes problem in the Supplicant
33 msleep_interruptible(1000);
35 if (priv
->wdev
->iftype
== NL80211_IFTYPE_STATION
)
36 lbs_send_disconnect_notification(priv
);
38 /* report disconnect to upper layer */
39 netif_stop_queue(priv
->dev
);
40 netif_carrier_off(priv
->dev
);
42 /* Free Tx and Rx packets */
43 kfree_skb(priv
->currenttxskb
);
44 priv
->currenttxskb
= NULL
;
45 priv
->tx_pending_len
= 0;
47 priv
->connect_status
= LBS_DISCONNECTED
;
49 if (priv
->psstate
!= PS_STATE_FULL_POWER
) {
50 /* make firmware to exit PS mode */
51 lbs_deb_cmd("disconnected, so exit PS mode\n");
52 lbs_ps_wakeup(priv
, 0);
54 lbs_deb_leave(LBS_DEB_ASSOC
);
57 static int lbs_ret_reg_access(struct lbs_private
*priv
,
58 u16 type
, struct cmd_ds_command
*resp
)
62 lbs_deb_enter(LBS_DEB_CMD
);
65 case CMD_RET(CMD_MAC_REG_ACCESS
):
67 struct cmd_ds_mac_reg_access
*reg
= &resp
->params
.macreg
;
69 priv
->offsetvalue
.offset
= (u32
)le16_to_cpu(reg
->offset
);
70 priv
->offsetvalue
.value
= le32_to_cpu(reg
->value
);
74 case CMD_RET(CMD_BBP_REG_ACCESS
):
76 struct cmd_ds_bbp_reg_access
*reg
= &resp
->params
.bbpreg
;
78 priv
->offsetvalue
.offset
= (u32
)le16_to_cpu(reg
->offset
);
79 priv
->offsetvalue
.value
= reg
->value
;
83 case CMD_RET(CMD_RF_REG_ACCESS
):
85 struct cmd_ds_rf_reg_access
*reg
= &resp
->params
.rfreg
;
87 priv
->offsetvalue
.offset
= (u32
)le16_to_cpu(reg
->offset
);
88 priv
->offsetvalue
.value
= reg
->value
;
96 lbs_deb_leave_args(LBS_DEB_CMD
, "ret %d", ret
);
101 * @brief This function parses countryinfo from AP and download country info to FW
102 * @param priv pointer to struct lbs_private
103 * @param resp pointer to command response buffer
106 static int lbs_ret_802_11d_domain_info(struct cmd_ds_command
*resp
)
108 struct cmd_ds_802_11d_domain_info
*domaininfo
=
109 &resp
->params
.domaininforesp
;
110 struct mrvl_ie_domain_param_set
*domain
= &domaininfo
->domain
;
111 u16 action
= le16_to_cpu(domaininfo
->action
);
115 lbs_deb_enter(LBS_DEB_11D
);
117 lbs_deb_hex(LBS_DEB_11D
, "domain info resp", (u8
*) resp
,
118 (int)le16_to_cpu(resp
->size
));
120 nr_triplet
= (le16_to_cpu(domain
->header
.len
) - COUNTRY_CODE_LEN
) /
121 sizeof(struct ieee80211_country_ie_triplet
);
123 lbs_deb_11d("domain info resp: nr_triplet %d\n", nr_triplet
);
125 if (nr_triplet
> MRVDRV_MAX_TRIPLET_802_11D
) {
126 lbs_deb_11d("invalid number of triplets returned!!\n");
131 case CMD_ACT_SET
: /*Proc set action */
137 lbs_deb_11d("invalid action:%d\n", domaininfo
->action
);
142 lbs_deb_leave_args(LBS_DEB_11D
, "ret %d", ret
);
146 static inline int handle_cmd_response(struct lbs_private
*priv
,
147 struct cmd_header
*cmd_response
)
149 struct cmd_ds_command
*resp
= (struct cmd_ds_command
*) cmd_response
;
152 uint16_t respcmd
= le16_to_cpu(resp
->command
);
154 lbs_deb_enter(LBS_DEB_HOST
);
157 case CMD_RET(CMD_MAC_REG_ACCESS
):
158 case CMD_RET(CMD_BBP_REG_ACCESS
):
159 case CMD_RET(CMD_RF_REG_ACCESS
):
160 ret
= lbs_ret_reg_access(priv
, respcmd
, resp
);
163 case CMD_RET(CMD_802_11_SET_AFC
):
164 case CMD_RET(CMD_802_11_GET_AFC
):
165 spin_lock_irqsave(&priv
->driver_lock
, flags
);
166 memmove((void *)priv
->cur_cmd
->callback_arg
, &resp
->params
.afc
,
167 sizeof(struct cmd_ds_802_11_afc
));
168 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
172 case CMD_RET(CMD_802_11_BEACON_STOP
):
175 case CMD_RET(CMD_802_11D_DOMAIN_INFO
):
176 ret
= lbs_ret_802_11d_domain_info(resp
);
179 case CMD_RET(CMD_802_11_TPC_CFG
):
180 spin_lock_irqsave(&priv
->driver_lock
, flags
);
181 memmove((void *)priv
->cur_cmd
->callback_arg
, &resp
->params
.tpccfg
,
182 sizeof(struct cmd_ds_802_11_tpc_cfg
));
183 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
186 case CMD_RET(CMD_BT_ACCESS
):
187 spin_lock_irqsave(&priv
->driver_lock
, flags
);
188 if (priv
->cur_cmd
->callback_arg
)
189 memcpy((void *)priv
->cur_cmd
->callback_arg
,
190 &resp
->params
.bt
.addr1
, 2 * ETH_ALEN
);
191 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
193 case CMD_RET(CMD_FWT_ACCESS
):
194 spin_lock_irqsave(&priv
->driver_lock
, flags
);
195 if (priv
->cur_cmd
->callback_arg
)
196 memcpy((void *)priv
->cur_cmd
->callback_arg
, &resp
->params
.fwt
,
197 sizeof(resp
->params
.fwt
));
198 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
200 case CMD_RET(CMD_802_11_BEACON_CTRL
):
201 ret
= lbs_ret_802_11_bcn_ctrl(priv
, resp
);
205 lbs_pr_err("CMD_RESP: unknown cmd response 0x%04x\n",
206 le16_to_cpu(resp
->command
));
209 lbs_deb_leave(LBS_DEB_HOST
);
213 int lbs_process_command_response(struct lbs_private
*priv
, u8
*data
, u32 len
)
215 uint16_t respcmd
, curcmd
;
216 struct cmd_header
*resp
;
221 lbs_deb_enter(LBS_DEB_HOST
);
223 mutex_lock(&priv
->lock
);
224 spin_lock_irqsave(&priv
->driver_lock
, flags
);
226 if (!priv
->cur_cmd
) {
227 lbs_deb_host("CMD_RESP: cur_cmd is NULL\n");
229 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
234 curcmd
= le16_to_cpu(priv
->cur_cmd
->cmdbuf
->command
);
235 respcmd
= le16_to_cpu(resp
->command
);
236 result
= le16_to_cpu(resp
->result
);
238 lbs_deb_cmd("CMD_RESP: response 0x%04x, seq %d, size %d\n",
239 respcmd
, le16_to_cpu(resp
->seqnum
), len
);
240 lbs_deb_hex(LBS_DEB_CMD
, "CMD_RESP", (void *) resp
, len
);
242 if (resp
->seqnum
!= priv
->cur_cmd
->cmdbuf
->seqnum
) {
243 lbs_pr_info("Received CMD_RESP with invalid sequence %d (expected %d)\n",
244 le16_to_cpu(resp
->seqnum
), le16_to_cpu(priv
->cur_cmd
->cmdbuf
->seqnum
));
245 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
249 if (respcmd
!= CMD_RET(curcmd
) &&
250 respcmd
!= CMD_RET_802_11_ASSOCIATE
&& curcmd
!= CMD_802_11_ASSOCIATE
) {
251 lbs_pr_info("Invalid CMD_RESP %x to command %x!\n", respcmd
, curcmd
);
252 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
257 if (resp
->result
== cpu_to_le16(0x0004)) {
258 /* 0x0004 means -EAGAIN. Drop the response, let it time out
259 and be resubmitted */
260 lbs_pr_info("Firmware returns DEFER to command %x. Will let it time out...\n",
261 le16_to_cpu(resp
->command
));
262 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
267 /* Now we got response from FW, cancel the command timer */
268 del_timer(&priv
->command_timer
);
269 priv
->cmd_timed_out
= 0;
271 /* Store the response code to cur_cmd_retcode. */
272 priv
->cur_cmd_retcode
= result
;
274 if (respcmd
== CMD_RET(CMD_802_11_PS_MODE
)) {
275 struct cmd_ds_802_11_ps_mode
*psmode
= (void *) &resp
[1];
276 u16 action
= le16_to_cpu(psmode
->action
);
279 "CMD_RESP: PS_MODE cmd reply result 0x%x, action 0x%x\n",
283 lbs_deb_host("CMD_RESP: PS command failed with 0x%x\n",
286 * We should not re-try enter-ps command in
287 * ad-hoc mode. It takes place in
288 * lbs_execute_next_command().
290 if (priv
->wdev
->iftype
== NL80211_IFTYPE_MONITOR
&&
291 action
== CMD_SUBCMD_ENTER_PS
)
292 priv
->psmode
= LBS802_11POWERMODECAM
;
293 } else if (action
== CMD_SUBCMD_ENTER_PS
) {
294 priv
->needtowakeup
= 0;
295 priv
->psstate
= PS_STATE_AWAKE
;
297 lbs_deb_host("CMD_RESP: ENTER_PS command response\n");
298 if (priv
->connect_status
!= LBS_CONNECTED
) {
300 * When Deauth Event received before Enter_PS command
301 * response, We need to wake up the firmware.
304 "disconnected, invoking lbs_ps_wakeup\n");
306 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
307 mutex_unlock(&priv
->lock
);
308 lbs_ps_wakeup(priv
, 0);
309 mutex_lock(&priv
->lock
);
310 spin_lock_irqsave(&priv
->driver_lock
, flags
);
312 } else if (action
== CMD_SUBCMD_EXIT_PS
) {
313 priv
->needtowakeup
= 0;
314 priv
->psstate
= PS_STATE_FULL_POWER
;
315 lbs_deb_host("CMD_RESP: EXIT_PS command response\n");
317 lbs_deb_host("CMD_RESP: PS action 0x%X\n", action
);
320 lbs_complete_command(priv
, priv
->cur_cmd
, result
);
321 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
327 /* If the command is not successful, cleanup and return failure */
328 if ((result
!= 0 || !(respcmd
& 0x8000))) {
329 lbs_deb_host("CMD_RESP: error 0x%04x in command reply 0x%04x\n",
332 * Handling errors here
335 case CMD_RET(CMD_GET_HW_SPEC
):
336 case CMD_RET(CMD_802_11_RESET
):
337 lbs_deb_host("CMD_RESP: reset failed\n");
341 lbs_complete_command(priv
, priv
->cur_cmd
, result
);
342 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
348 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
350 if (priv
->cur_cmd
&& priv
->cur_cmd
->callback
) {
351 ret
= priv
->cur_cmd
->callback(priv
, priv
->cur_cmd
->callback_arg
,
354 ret
= handle_cmd_response(priv
, resp
);
356 spin_lock_irqsave(&priv
->driver_lock
, flags
);
359 /* Clean up and Put current command back to cmdfreeq */
360 lbs_complete_command(priv
, priv
->cur_cmd
, result
);
362 spin_unlock_irqrestore(&priv
->driver_lock
, flags
);
365 mutex_unlock(&priv
->lock
);
366 lbs_deb_leave_args(LBS_DEB_HOST
, "ret %d", ret
);
370 int lbs_process_event(struct lbs_private
*priv
, u32 event
)
373 struct cmd_header cmd
;
375 lbs_deb_enter(LBS_DEB_CMD
);
378 case MACREG_INT_CODE_LINK_SENSED
:
379 lbs_deb_cmd("EVENT: link sensed\n");
382 case MACREG_INT_CODE_DEAUTHENTICATED
:
383 lbs_deb_cmd("EVENT: deauthenticated\n");
384 lbs_mac_event_disconnected(priv
);
387 case MACREG_INT_CODE_DISASSOCIATED
:
388 lbs_deb_cmd("EVENT: disassociated\n");
389 lbs_mac_event_disconnected(priv
);
392 case MACREG_INT_CODE_LINK_LOST_NO_SCAN
:
393 lbs_deb_cmd("EVENT: link lost\n");
394 lbs_mac_event_disconnected(priv
);
397 case MACREG_INT_CODE_PS_SLEEP
:
398 lbs_deb_cmd("EVENT: ps sleep\n");
400 /* handle unexpected PS SLEEP event */
401 if (priv
->psstate
== PS_STATE_FULL_POWER
) {
403 "EVENT: in FULL POWER mode, ignoreing PS_SLEEP\n");
406 priv
->psstate
= PS_STATE_PRE_SLEEP
;
408 lbs_ps_confirm_sleep(priv
);
412 case MACREG_INT_CODE_HOST_AWAKE
:
413 lbs_deb_cmd("EVENT: host awake\n");
414 if (priv
->reset_deep_sleep_wakeup
)
415 priv
->reset_deep_sleep_wakeup(priv
);
416 priv
->is_deep_sleep
= 0;
417 lbs_cmd_async(priv
, CMD_802_11_WAKEUP_CONFIRM
, &cmd
,
419 priv
->is_host_sleep_activated
= 0;
420 wake_up_interruptible(&priv
->host_sleep_q
);
423 case MACREG_INT_CODE_DEEP_SLEEP_AWAKE
:
424 if (priv
->reset_deep_sleep_wakeup
)
425 priv
->reset_deep_sleep_wakeup(priv
);
426 lbs_deb_cmd("EVENT: ds awake\n");
427 priv
->is_deep_sleep
= 0;
428 priv
->wakeup_dev_required
= 0;
429 wake_up_interruptible(&priv
->ds_awake_q
);
432 case MACREG_INT_CODE_PS_AWAKE
:
433 lbs_deb_cmd("EVENT: ps awake\n");
434 /* handle unexpected PS AWAKE event */
435 if (priv
->psstate
== PS_STATE_FULL_POWER
) {
437 "EVENT: In FULL POWER mode - ignore PS AWAKE\n");
441 priv
->psstate
= PS_STATE_AWAKE
;
443 if (priv
->needtowakeup
) {
445 * wait for the command processing to finish
446 * before resuming sending
447 * priv->needtowakeup will be set to FALSE
450 lbs_deb_cmd("waking up ...\n");
451 lbs_ps_wakeup(priv
, 0);
455 case MACREG_INT_CODE_MIC_ERR_UNICAST
:
456 lbs_deb_cmd("EVENT: UNICAST MIC ERROR\n");
457 lbs_send_mic_failureevent(priv
, event
);
460 case MACREG_INT_CODE_MIC_ERR_MULTICAST
:
461 lbs_deb_cmd("EVENT: MULTICAST MIC ERROR\n");
462 lbs_send_mic_failureevent(priv
, event
);
465 case MACREG_INT_CODE_MIB_CHANGED
:
466 lbs_deb_cmd("EVENT: MIB CHANGED\n");
468 case MACREG_INT_CODE_INIT_DONE
:
469 lbs_deb_cmd("EVENT: INIT DONE\n");
471 case MACREG_INT_CODE_ADHOC_BCN_LOST
:
472 lbs_deb_cmd("EVENT: ADHOC beacon lost\n");
474 case MACREG_INT_CODE_RSSI_LOW
:
475 lbs_pr_alert("EVENT: rssi low\n");
477 case MACREG_INT_CODE_SNR_LOW
:
478 lbs_pr_alert("EVENT: snr low\n");
480 case MACREG_INT_CODE_MAX_FAIL
:
481 lbs_pr_alert("EVENT: max fail\n");
483 case MACREG_INT_CODE_RSSI_HIGH
:
484 lbs_pr_alert("EVENT: rssi high\n");
486 case MACREG_INT_CODE_SNR_HIGH
:
487 lbs_pr_alert("EVENT: snr high\n");
490 case MACREG_INT_CODE_MESH_AUTO_STARTED
:
491 /* Ignore spurious autostart events */
492 lbs_pr_info("EVENT: MESH_AUTO_STARTED (ignoring)\n");
496 lbs_pr_alert("EVENT: unknown event id %d\n", event
);
500 lbs_deb_leave_args(LBS_DEB_CMD
, "ret %d", ret
);