1 /* $OpenBSD: if_iwi.c,v 1.144 2020/07/10 13:22:20 patrick Exp $ */ 2 3 /*- 4 * Copyright (c) 2004-2008 5 * Damien Bergamini <damien.bergamini@free.fr>. All rights reserved. 6 * 7 * Permission to use, copy, modify, and distribute this software for any 8 * purpose with or without fee is hereby granted, provided that the above 9 * copyright notice and this permission notice appear in all copies. 10 * 11 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 12 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 13 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 14 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 15 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 16 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 17 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 18 */ 19 20 /* 21 * Driver for Intel PRO/Wireless 2200BG/2915ABG 802.11 network adapters. 22 */ 23 24 #include "bpfilter.h" 25 26 #include <sys/param.h> 27 #include <sys/sockio.h> 28 #include <sys/mbuf.h> 29 #include <sys/kernel.h> 30 #include <sys/rwlock.h> 31 #include <sys/socket.h> 32 #include <sys/systm.h> 33 #include <sys/conf.h> 34 #include <sys/device.h> 35 #include <sys/task.h> 36 #include <sys/endian.h> 37 38 #include <machine/bus.h> 39 #include <machine/intr.h> 40 41 #include <dev/pci/pcireg.h> 42 #include <dev/pci/pcivar.h> 43 #include <dev/pci/pcidevs.h> 44 45 #if NBPFILTER > 0 46 #include <net/bpf.h> 47 #endif 48 #include <net/if.h> 49 #include <net/if_dl.h> 50 #include <net/if_media.h> 51 52 #include <netinet/in.h> 53 #include <netinet/if_ether.h> 54 55 #include <net80211/ieee80211_var.h> 56 #include <net80211/ieee80211_radiotap.h> 57 58 #include <dev/pci/if_iwireg.h> 59 #include <dev/pci/if_iwivar.h> 60 61 const struct pci_matchid iwi_devices[] = { 62 { PCI_VENDOR_INTEL, PCI_PRODUCT_INTEL_PRO_WL_2200BG }, 63 { PCI_VENDOR_INTEL, PCI_PRODUCT_INTEL_PRO_WL_2225BG }, 64 { PCI_VENDOR_INTEL, PCI_PRODUCT_INTEL_PRO_WL_2915ABG_1 }, 65 { PCI_VENDOR_INTEL, PCI_PRODUCT_INTEL_PRO_WL_2915ABG_2 } 66 }; 67 68 int iwi_match(struct device *, void *, void *); 69 void iwi_attach(struct device *, struct device *, void *); 70 int iwi_activate(struct device *, int); 71 void iwi_wakeup(struct iwi_softc *); 72 void iwi_init_task(void *); 73 int iwi_alloc_cmd_ring(struct iwi_softc *, struct iwi_cmd_ring *); 74 void iwi_reset_cmd_ring(struct iwi_softc *, struct iwi_cmd_ring *); 75 void iwi_free_cmd_ring(struct iwi_softc *, struct iwi_cmd_ring *); 76 int iwi_alloc_tx_ring(struct iwi_softc *, struct iwi_tx_ring *, 77 int); 78 void iwi_reset_tx_ring(struct iwi_softc *, struct iwi_tx_ring *); 79 void iwi_free_tx_ring(struct iwi_softc *, struct iwi_tx_ring *); 80 int iwi_alloc_rx_ring(struct iwi_softc *, struct iwi_rx_ring *); 81 void iwi_reset_rx_ring(struct iwi_softc *, struct iwi_rx_ring *); 82 void iwi_free_rx_ring(struct iwi_softc *, struct iwi_rx_ring *); 83 int iwi_media_change(struct ifnet *); 84 void iwi_media_status(struct ifnet *, struct ifmediareq *); 85 uint16_t iwi_read_prom_word(struct iwi_softc *, uint8_t); 86 int iwi_find_txnode(struct iwi_softc *, const uint8_t *); 87 int iwi_newstate(struct ieee80211com *, enum ieee80211_state, int); 88 uint8_t iwi_rate(int); 89 void iwi_frame_intr(struct iwi_softc *, struct iwi_rx_data *, 90 struct iwi_frame *, struct mbuf_list *); 91 void iwi_notification_intr(struct iwi_softc *, struct iwi_rx_data *, 92 struct iwi_notif *); 93 void iwi_rx_intr(struct iwi_softc *); 94 void iwi_tx_intr(struct iwi_softc *, struct iwi_tx_ring *); 95 int iwi_intr(void *); 96 int iwi_cmd(struct iwi_softc *, uint8_t, void *, uint8_t, int); 97 int iwi_send_mgmt(struct ieee80211com *, struct ieee80211_node *, 98 int, int, int); 99 int iwi_tx_start(struct ifnet *, struct mbuf *, 100 struct ieee80211_node *); 101 void iwi_start(struct ifnet *); 102 void iwi_watchdog(struct ifnet *); 103 int iwi_ioctl(struct ifnet *, u_long, caddr_t); 104 void iwi_stop_master(struct iwi_softc *); 105 int iwi_reset(struct iwi_softc *); 106 int iwi_load_ucode(struct iwi_softc *, const char *, int); 107 int iwi_load_firmware(struct iwi_softc *, const char *, int); 108 int iwi_config(struct iwi_softc *); 109 void iwi_update_edca(struct ieee80211com *); 110 int iwi_set_chan(struct iwi_softc *, struct ieee80211_channel *); 111 int iwi_scan(struct iwi_softc *); 112 int iwi_auth_and_assoc(struct iwi_softc *); 113 int iwi_init(struct ifnet *); 114 void iwi_stop(struct ifnet *, int); 115 116 static __inline uint8_t 117 MEM_READ_1(struct iwi_softc *sc, uint32_t addr) 118 { 119 CSR_WRITE_4(sc, IWI_CSR_INDIRECT_ADDR, addr); 120 return CSR_READ_1(sc, IWI_CSR_INDIRECT_DATA); 121 } 122 123 static __inline uint32_t 124 MEM_READ_4(struct iwi_softc *sc, uint32_t addr) 125 { 126 CSR_WRITE_4(sc, IWI_CSR_INDIRECT_ADDR, addr); 127 return CSR_READ_4(sc, IWI_CSR_INDIRECT_DATA); 128 } 129 130 #ifdef IWI_DEBUG 131 #define DPRINTF(x) do { if (iwi_debug > 0) printf x; } while (0) 132 #define DPRINTFN(n, x) do { if (iwi_debug >= (n)) printf x; } while (0) 133 int iwi_debug = 0; 134 #else 135 #define DPRINTF(x) 136 #define DPRINTFN(n, x) 137 #endif 138 139 struct cfattach iwi_ca = { 140 sizeof (struct iwi_softc), iwi_match, iwi_attach, NULL, 141 iwi_activate 142 }; 143 144 int 145 iwi_match(struct device *parent, void *match, void *aux) 146 { 147 return pci_matchbyid((struct pci_attach_args *)aux, iwi_devices, 148 nitems(iwi_devices)); 149 } 150 151 /* Base Address Register */ 152 #define IWI_PCI_BAR0 0x10 153 154 void 155 iwi_attach(struct device *parent, struct device *self, void *aux) 156 { 157 struct iwi_softc *sc = (struct iwi_softc *)self; 158 struct ieee80211com *ic = &sc->sc_ic; 159 struct ifnet *ifp = &ic->ic_if; 160 struct pci_attach_args *pa = aux; 161 const char *intrstr; 162 bus_space_tag_t memt; 163 bus_space_handle_t memh; 164 pci_intr_handle_t ih; 165 pcireg_t data; 166 uint16_t val; 167 int error, ac, i; 168 169 sc->sc_pct = pa->pa_pc; 170 sc->sc_pcitag = pa->pa_tag; 171 172 /* clear device specific PCI configuration register 0x41 */ 173 data = pci_conf_read(sc->sc_pct, sc->sc_pcitag, 0x40); 174 data &= ~0x0000ff00; 175 pci_conf_write(sc->sc_pct, sc->sc_pcitag, 0x40, data); 176 177 /* map the register window */ 178 error = pci_mapreg_map(pa, IWI_PCI_BAR0, PCI_MAPREG_TYPE_MEM | 179 PCI_MAPREG_MEM_TYPE_32BIT, 0, &memt, &memh, NULL, &sc->sc_sz, 0); 180 if (error != 0) { 181 printf(": can't map mem space\n"); 182 return; 183 } 184 185 sc->sc_st = memt; 186 sc->sc_sh = memh; 187 sc->sc_dmat = pa->pa_dmat; 188 189 if (pci_intr_map(pa, &ih) != 0) { 190 printf(": can't map interrupt\n"); 191 return; 192 } 193 194 intrstr = pci_intr_string(sc->sc_pct, ih); 195 sc->sc_ih = pci_intr_establish(sc->sc_pct, ih, IPL_NET, iwi_intr, sc, 196 sc->sc_dev.dv_xname); 197 if (sc->sc_ih == NULL) { 198 printf(": can't establish interrupt"); 199 if (intrstr != NULL) 200 printf(" at %s", intrstr); 201 printf("\n"); 202 return; 203 } 204 printf(": %s", intrstr); 205 206 if (iwi_reset(sc) != 0) { 207 printf(": could not reset adapter\n"); 208 return; 209 } 210 211 /* 212 * Allocate rings. 213 */ 214 if (iwi_alloc_cmd_ring(sc, &sc->cmdq) != 0) { 215 printf(": could not allocate Cmd ring\n"); 216 return; 217 } 218 for (ac = 0; ac < EDCA_NUM_AC; ac++) { 219 if (iwi_alloc_tx_ring(sc, &sc->txq[ac], ac) != 0) { 220 printf(": could not allocate Tx ring %d\n", ac); 221 goto fail; 222 } 223 } 224 if (iwi_alloc_rx_ring(sc, &sc->rxq) != 0) { 225 printf(": could not allocate Rx ring\n"); 226 goto fail; 227 } 228 229 ic->ic_phytype = IEEE80211_T_OFDM; /* not only, but not used */ 230 ic->ic_opmode = IEEE80211_M_STA; /* default to BSS mode */ 231 ic->ic_state = IEEE80211_S_INIT; 232 233 /* set device capabilities */ 234 ic->ic_caps = 235 #ifndef IEEE80211_STA_ONLY 236 IEEE80211_C_IBSS | /* IBSS mode supported */ 237 #endif 238 IEEE80211_C_MONITOR | /* monitor mode supported */ 239 IEEE80211_C_TXPMGT | /* tx power management */ 240 IEEE80211_C_SHPREAMBLE | /* short preamble supported */ 241 IEEE80211_C_SHSLOT | /* short slot time supported */ 242 IEEE80211_C_WEP | /* s/w WEP */ 243 IEEE80211_C_RSN | /* WPA/RSN supported */ 244 IEEE80211_C_SCANALL; /* h/w scanning */ 245 246 /* read MAC address from EEPROM */ 247 val = iwi_read_prom_word(sc, IWI_EEPROM_MAC + 0); 248 ic->ic_myaddr[0] = val & 0xff; 249 ic->ic_myaddr[1] = val >> 8; 250 val = iwi_read_prom_word(sc, IWI_EEPROM_MAC + 1); 251 ic->ic_myaddr[2] = val & 0xff; 252 ic->ic_myaddr[3] = val >> 8; 253 val = iwi_read_prom_word(sc, IWI_EEPROM_MAC + 2); 254 ic->ic_myaddr[4] = val & 0xff; 255 ic->ic_myaddr[5] = val >> 8; 256 257 printf(", address %s\n", ether_sprintf(ic->ic_myaddr)); 258 259 if (PCI_PRODUCT(pa->pa_id) >= PCI_PRODUCT_INTEL_PRO_WL_2915ABG_1) { 260 /* set supported .11a rates */ 261 ic->ic_sup_rates[IEEE80211_MODE_11A] = 262 ieee80211_std_rateset_11a; 263 264 /* set supported .11a channels */ 265 for (i = 36; i <= 64; i += 4) { 266 ic->ic_channels[i].ic_freq = 267 ieee80211_ieee2mhz(i, IEEE80211_CHAN_5GHZ); 268 ic->ic_channels[i].ic_flags = IEEE80211_CHAN_A; 269 } 270 for (i = 149; i <= 165; i += 4) { 271 ic->ic_channels[i].ic_freq = 272 ieee80211_ieee2mhz(i, IEEE80211_CHAN_5GHZ); 273 ic->ic_channels[i].ic_flags = IEEE80211_CHAN_A; 274 } 275 } 276 277 /* set supported .11b and .11g rates */ 278 ic->ic_sup_rates[IEEE80211_MODE_11B] = ieee80211_std_rateset_11b; 279 ic->ic_sup_rates[IEEE80211_MODE_11G] = ieee80211_std_rateset_11g; 280 281 /* set supported .11b and .11g channels (1 through 14) */ 282 for (i = 1; i <= 14; i++) { 283 ic->ic_channels[i].ic_freq = 284 ieee80211_ieee2mhz(i, IEEE80211_CHAN_2GHZ); 285 ic->ic_channels[i].ic_flags = 286 IEEE80211_CHAN_CCK | IEEE80211_CHAN_OFDM | 287 IEEE80211_CHAN_DYN | IEEE80211_CHAN_2GHZ; 288 } 289 290 /* IBSS channel undefined for now */ 291 ic->ic_ibss_chan = &ic->ic_channels[0]; 292 293 ifp->if_softc = sc; 294 ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST; 295 ifp->if_ioctl = iwi_ioctl; 296 ifp->if_start = iwi_start; 297 ifp->if_watchdog = iwi_watchdog; 298 bcopy(sc->sc_dev.dv_xname, ifp->if_xname, IFNAMSIZ); 299 300 if_attach(ifp); 301 ieee80211_ifattach(ifp); 302 /* override state transition machine */ 303 sc->sc_newstate = ic->ic_newstate; 304 ic->ic_newstate = iwi_newstate; 305 ic->ic_send_mgmt = iwi_send_mgmt; 306 ieee80211_media_init(ifp, iwi_media_change, iwi_media_status); 307 308 #if NBPFILTER > 0 309 bpfattach(&sc->sc_drvbpf, ifp, DLT_IEEE802_11_RADIO, 310 sizeof (struct ieee80211_frame) + IEEE80211_RADIOTAP_HDRLEN); 311 312 sc->sc_rxtap_len = sizeof sc->sc_rxtapu; 313 sc->sc_rxtap.wr_ihdr.it_len = htole16(sc->sc_rxtap_len); 314 sc->sc_rxtap.wr_ihdr.it_present = htole32(IWI_RX_RADIOTAP_PRESENT); 315 316 sc->sc_txtap_len = sizeof sc->sc_txtapu; 317 sc->sc_txtap.wt_ihdr.it_len = htole16(sc->sc_txtap_len); 318 sc->sc_txtap.wt_ihdr.it_present = htole32(IWI_TX_RADIOTAP_PRESENT); 319 #endif 320 321 rw_init(&sc->sc_rwlock, "iwilock"); 322 task_set(&sc->init_task, iwi_init_task, sc); 323 return; 324 325 fail: while (--ac >= 0) 326 iwi_free_tx_ring(sc, &sc->txq[ac]); 327 iwi_free_cmd_ring(sc, &sc->cmdq); 328 } 329 330 int 331 iwi_activate(struct device *self, int act) 332 { 333 struct iwi_softc *sc = (struct iwi_softc *)self; 334 struct ifnet *ifp = &sc->sc_ic.ic_if; 335 336 switch (act) { 337 case DVACT_SUSPEND: 338 if (ifp->if_flags & IFF_RUNNING) 339 iwi_stop(ifp, 0); 340 break; 341 case DVACT_WAKEUP: 342 iwi_wakeup(sc); 343 break; 344 } 345 346 return 0; 347 } 348 349 void 350 iwi_wakeup(struct iwi_softc *sc) 351 { 352 pcireg_t data; 353 354 /* clear device specific PCI configuration register 0x41 */ 355 data = pci_conf_read(sc->sc_pct, sc->sc_pcitag, 0x40); 356 data &= ~0x0000ff00; 357 pci_conf_write(sc->sc_pct, sc->sc_pcitag, 0x40, data); 358 359 iwi_init_task(sc); 360 } 361 362 void 363 iwi_init_task(void *arg1) 364 { 365 struct iwi_softc *sc = arg1; 366 struct ifnet *ifp = &sc->sc_ic.ic_if; 367 int s; 368 369 rw_enter_write(&sc->sc_rwlock); 370 s = splnet(); 371 372 if ((ifp->if_flags & (IFF_UP | IFF_RUNNING)) == IFF_UP) 373 iwi_init(ifp); 374 375 splx(s); 376 rw_exit_write(&sc->sc_rwlock); 377 } 378 379 int 380 iwi_alloc_cmd_ring(struct iwi_softc *sc, struct iwi_cmd_ring *ring) 381 { 382 int nsegs, error; 383 384 ring->queued = 0; 385 ring->cur = ring->next = 0; 386 387 error = bus_dmamap_create(sc->sc_dmat, 388 sizeof (struct iwi_cmd_desc) * IWI_CMD_RING_COUNT, 1, 389 sizeof (struct iwi_cmd_desc) * IWI_CMD_RING_COUNT, 0, 390 BUS_DMA_NOWAIT, &ring->map); 391 if (error != 0) { 392 printf("%s: could not create cmd ring DMA map\n", 393 sc->sc_dev.dv_xname); 394 goto fail; 395 } 396 397 error = bus_dmamem_alloc(sc->sc_dmat, 398 sizeof (struct iwi_cmd_desc) * IWI_CMD_RING_COUNT, PAGE_SIZE, 0, 399 &ring->seg, 1, &nsegs, BUS_DMA_NOWAIT | BUS_DMA_ZERO); 400 if (error != 0) { 401 printf("%s: could not allocate cmd ring DMA memory\n", 402 sc->sc_dev.dv_xname); 403 goto fail; 404 } 405 406 error = bus_dmamem_map(sc->sc_dmat, &ring->seg, nsegs, 407 sizeof (struct iwi_cmd_desc) * IWI_CMD_RING_COUNT, 408 (caddr_t *)&ring->desc, BUS_DMA_NOWAIT); 409 if (error != 0) { 410 printf("%s: can't map cmd ring DMA memory\n", 411 sc->sc_dev.dv_xname); 412 goto fail; 413 } 414 415 error = bus_dmamap_load(sc->sc_dmat, ring->map, ring->desc, 416 sizeof (struct iwi_cmd_desc) * IWI_CMD_RING_COUNT, NULL, 417 BUS_DMA_NOWAIT); 418 if (error != 0) { 419 printf("%s: could not load cmd ring DMA map\n", 420 sc->sc_dev.dv_xname); 421 goto fail; 422 } 423 424 return 0; 425 426 fail: iwi_free_cmd_ring(sc, ring); 427 return error; 428 } 429 430 void 431 iwi_reset_cmd_ring(struct iwi_softc *sc, struct iwi_cmd_ring *ring) 432 { 433 ring->queued = 0; 434 ring->cur = ring->next = 0; 435 } 436 437 void 438 iwi_free_cmd_ring(struct iwi_softc *sc, struct iwi_cmd_ring *ring) 439 { 440 if (ring->map != NULL) { 441 if (ring->desc != NULL) { 442 bus_dmamap_unload(sc->sc_dmat, ring->map); 443 bus_dmamem_unmap(sc->sc_dmat, (caddr_t)ring->desc, 444 sizeof (struct iwi_cmd_desc) * IWI_CMD_RING_COUNT); 445 bus_dmamem_free(sc->sc_dmat, &ring->seg, 1); 446 } 447 bus_dmamap_destroy(sc->sc_dmat, ring->map); 448 } 449 } 450 451 int 452 iwi_alloc_tx_ring(struct iwi_softc *sc, struct iwi_tx_ring *ring, int ac) 453 { 454 struct iwi_tx_data *data; 455 int i, nsegs, error; 456 457 ring->queued = 0; 458 ring->cur = ring->next = 0; 459 ring->csr_ridx = IWI_CSR_TX_RIDX(ac); 460 ring->csr_widx = IWI_CSR_TX_WIDX(ac); 461 462 error = bus_dmamap_create(sc->sc_dmat, 463 sizeof (struct iwi_tx_desc) * IWI_TX_RING_COUNT, 1, 464 sizeof (struct iwi_tx_desc) * IWI_TX_RING_COUNT, 0, BUS_DMA_NOWAIT, 465 &ring->map); 466 if (error != 0) { 467 printf("%s: could not create tx ring DMA map\n", 468 sc->sc_dev.dv_xname); 469 goto fail; 470 } 471 472 error = bus_dmamem_alloc(sc->sc_dmat, 473 sizeof (struct iwi_tx_desc) * IWI_TX_RING_COUNT, PAGE_SIZE, 0, 474 &ring->seg, 1, &nsegs, BUS_DMA_NOWAIT | BUS_DMA_ZERO); 475 if (error != 0) { 476 printf("%s: could not allocate tx ring DMA memory\n", 477 sc->sc_dev.dv_xname); 478 goto fail; 479 } 480 481 error = bus_dmamem_map(sc->sc_dmat, &ring->seg, nsegs, 482 sizeof (struct iwi_tx_desc) * IWI_TX_RING_COUNT, 483 (caddr_t *)&ring->desc, BUS_DMA_NOWAIT); 484 if (error != 0) { 485 printf("%s: can't map tx ring DMA memory\n", 486 sc->sc_dev.dv_xname); 487 goto fail; 488 } 489 490 error = bus_dmamap_load(sc->sc_dmat, ring->map, ring->desc, 491 sizeof (struct iwi_tx_desc) * IWI_TX_RING_COUNT, NULL, 492 BUS_DMA_NOWAIT); 493 if (error != 0) { 494 printf("%s: could not load tx ring DMA map\n", 495 sc->sc_dev.dv_xname); 496 goto fail; 497 } 498 499 for (i = 0; i < IWI_TX_RING_COUNT; i++) { 500 data = &ring->data[i]; 501 502 error = bus_dmamap_create(sc->sc_dmat, MCLBYTES, 503 IWI_MAX_SCATTER, MCLBYTES, 0, BUS_DMA_NOWAIT, &data->map); 504 if (error != 0) { 505 printf("%s: could not create tx buf DMA map\n", 506 sc->sc_dev.dv_xname); 507 goto fail; 508 } 509 } 510 511 return 0; 512 513 fail: iwi_free_tx_ring(sc, ring); 514 return error; 515 } 516 517 void 518 iwi_reset_tx_ring(struct iwi_softc *sc, struct iwi_tx_ring *ring) 519 { 520 struct iwi_tx_data *data; 521 int i; 522 523 for (i = 0; i < IWI_TX_RING_COUNT; i++) { 524 data = &ring->data[i]; 525 526 if (data->m != NULL) { 527 bus_dmamap_unload(sc->sc_dmat, data->map); 528 m_freem(data->m); 529 data->m = NULL; 530 } 531 } 532 533 ring->queued = 0; 534 ring->cur = ring->next = 0; 535 } 536 537 void 538 iwi_free_tx_ring(struct iwi_softc *sc, struct iwi_tx_ring *ring) 539 { 540 struct iwi_tx_data *data; 541 int i; 542 543 if (ring->map != NULL) { 544 if (ring->desc != NULL) { 545 bus_dmamap_unload(sc->sc_dmat, ring->map); 546 bus_dmamem_unmap(sc->sc_dmat, (caddr_t)ring->desc, 547 sizeof (struct iwi_tx_desc) * IWI_TX_RING_COUNT); 548 bus_dmamem_free(sc->sc_dmat, &ring->seg, 1); 549 } 550 bus_dmamap_destroy(sc->sc_dmat, ring->map); 551 } 552 553 for (i = 0; i < IWI_TX_RING_COUNT; i++) { 554 data = &ring->data[i]; 555 556 if (data->m != NULL) { 557 bus_dmamap_unload(sc->sc_dmat, data->map); 558 m_freem(data->m); 559 } 560 bus_dmamap_destroy(sc->sc_dmat, data->map); 561 } 562 } 563 564 int 565 iwi_alloc_rx_ring(struct iwi_softc *sc, struct iwi_rx_ring *ring) 566 { 567 struct iwi_rx_data *data; 568 int i, error; 569 570 ring->cur = 0; 571 572 for (i = 0; i < IWI_RX_RING_COUNT; i++) { 573 data = &sc->rxq.data[i]; 574 575 error = bus_dmamap_create(sc->sc_dmat, MCLBYTES, 1, MCLBYTES, 576 0, BUS_DMA_NOWAIT, &data->map); 577 if (error != 0) { 578 printf("%s: could not create rx buf DMA map\n", 579 sc->sc_dev.dv_xname); 580 goto fail; 581 } 582 583 MGETHDR(data->m, M_DONTWAIT, MT_DATA); 584 if (data->m == NULL) { 585 printf("%s: could not allocate rx mbuf\n", 586 sc->sc_dev.dv_xname); 587 error = ENOMEM; 588 goto fail; 589 } 590 MCLGET(data->m, M_DONTWAIT); 591 if (!(data->m->m_flags & M_EXT)) { 592 m_freem(data->m); 593 data->m = NULL; 594 printf("%s: could not allocate rx mbuf cluster\n", 595 sc->sc_dev.dv_xname); 596 error = ENOMEM; 597 goto fail; 598 } 599 600 error = bus_dmamap_load(sc->sc_dmat, data->map, 601 mtod(data->m, void *), MCLBYTES, NULL, BUS_DMA_NOWAIT); 602 if (error != 0) { 603 printf("%s: could not load rx buf DMA map\n", 604 sc->sc_dev.dv_xname); 605 goto fail; 606 } 607 608 data->reg = IWI_CSR_RX_BASE + i * 4; 609 } 610 611 return 0; 612 613 fail: iwi_free_rx_ring(sc, ring); 614 return error; 615 } 616 617 void 618 iwi_reset_rx_ring(struct iwi_softc *sc, struct iwi_rx_ring *ring) 619 { 620 ring->cur = 0; 621 } 622 623 void 624 iwi_free_rx_ring(struct iwi_softc *sc, struct iwi_rx_ring *ring) 625 { 626 struct iwi_rx_data *data; 627 int i; 628 629 for (i = 0; i < IWI_RX_RING_COUNT; i++) { 630 data = &sc->rxq.data[i]; 631 632 if (data->m != NULL) { 633 bus_dmamap_unload(sc->sc_dmat, data->map); 634 m_freem(data->m); 635 } 636 bus_dmamap_destroy(sc->sc_dmat, data->map); 637 } 638 } 639 640 int 641 iwi_media_change(struct ifnet *ifp) 642 { 643 int error; 644 645 error = ieee80211_media_change(ifp); 646 if (error != ENETRESET) 647 return error; 648 649 if ((ifp->if_flags & (IFF_UP | IFF_RUNNING)) == (IFF_UP | IFF_RUNNING)) 650 error = iwi_init(ifp); 651 652 return error; 653 } 654 655 void 656 iwi_media_status(struct ifnet *ifp, struct ifmediareq *imr) 657 { 658 struct iwi_softc *sc = ifp->if_softc; 659 struct ieee80211com *ic = &sc->sc_ic; 660 uint32_t val; 661 int rate; 662 663 imr->ifm_status = IFM_AVALID; 664 imr->ifm_active = IFM_IEEE80211; 665 if (ic->ic_state == IEEE80211_S_RUN) 666 imr->ifm_status |= IFM_ACTIVE; 667 668 /* read current transmission rate from adapter */ 669 val = CSR_READ_4(sc, IWI_CSR_CURRENT_TX_RATE); 670 /* convert PLCP signal to 802.11 rate */ 671 rate = iwi_rate(val); 672 673 imr->ifm_active |= ieee80211_rate2media(ic, rate, ic->ic_curmode); 674 switch (ic->ic_opmode) { 675 case IEEE80211_M_STA: 676 break; 677 #ifndef IEEE80211_STA_ONLY 678 case IEEE80211_M_IBSS: 679 imr->ifm_active |= IFM_IEEE80211_ADHOC; 680 break; 681 #endif 682 case IEEE80211_M_MONITOR: 683 imr->ifm_active |= IFM_IEEE80211_MONITOR; 684 break; 685 default: 686 /* should not get there */ 687 break; 688 } 689 } 690 691 #ifndef IEEE80211_STA_ONLY 692 /* 693 * This is only used for IBSS mode where the firmware expect an index to an 694 * internal node table instead of a destination address. 695 */ 696 int 697 iwi_find_txnode(struct iwi_softc *sc, const uint8_t *macaddr) 698 { 699 struct iwi_node node; 700 int i; 701 702 for (i = 0; i < sc->nsta; i++) 703 if (IEEE80211_ADDR_EQ(sc->sta[i], macaddr)) 704 return i; /* already existing node */ 705 706 if (i == IWI_MAX_NODE) 707 return -1; /* no place left in neighbor table */ 708 709 /* save this new node in our softc table */ 710 IEEE80211_ADDR_COPY(sc->sta[i], macaddr); 711 sc->nsta = i; 712 713 /* write node information into NIC memory */ 714 bzero(&node, sizeof node); 715 IEEE80211_ADDR_COPY(node.bssid, macaddr); 716 717 CSR_WRITE_REGION_1(sc, IWI_CSR_NODE_BASE + i * sizeof node, 718 (uint8_t *)&node, sizeof node); 719 720 return i; 721 } 722 #endif 723 724 int 725 iwi_newstate(struct ieee80211com *ic, enum ieee80211_state nstate, int arg) 726 { 727 struct iwi_softc *sc = ic->ic_softc; 728 enum ieee80211_state ostate; 729 uint32_t tmp; 730 731 ostate = ic->ic_state; 732 733 switch (nstate) { 734 case IEEE80211_S_SCAN: 735 iwi_scan(sc); 736 break; 737 738 case IEEE80211_S_AUTH: 739 iwi_auth_and_assoc(sc); 740 break; 741 742 case IEEE80211_S_RUN: 743 #ifndef IEEE80211_STA_ONLY 744 if (ic->ic_opmode == IEEE80211_M_IBSS) { 745 sc->nsta = 0; /* flush IBSS nodes */ 746 ieee80211_new_state(ic, IEEE80211_S_AUTH, -1); 747 } else 748 #endif 749 if (ic->ic_opmode == IEEE80211_M_MONITOR) 750 iwi_set_chan(sc, ic->ic_ibss_chan); 751 752 /* assoc led on */ 753 tmp = MEM_READ_4(sc, IWI_MEM_EVENT_CTL) & IWI_LED_MASK; 754 MEM_WRITE_4(sc, IWI_MEM_EVENT_CTL, tmp | IWI_LED_ASSOC); 755 break; 756 757 case IEEE80211_S_INIT: 758 if (ostate != IEEE80211_S_RUN) 759 break; 760 761 /* assoc led off */ 762 tmp = MEM_READ_4(sc, IWI_MEM_EVENT_CTL) & IWI_LED_MASK; 763 MEM_WRITE_4(sc, IWI_MEM_EVENT_CTL, tmp & ~IWI_LED_ASSOC); 764 break; 765 766 case IEEE80211_S_ASSOC: 767 break; 768 } 769 770 ic->ic_state = nstate; 771 return 0; 772 } 773 774 /* 775 * Read 16 bits at address 'addr' from the serial EEPROM. 776 * DON'T PLAY WITH THIS CODE UNLESS YOU KNOW *EXACTLY* WHAT YOU'RE DOING! 777 */ 778 uint16_t 779 iwi_read_prom_word(struct iwi_softc *sc, uint8_t addr) 780 { 781 uint32_t tmp; 782 uint16_t val; 783 int n; 784 785 /* clock C once before the first command */ 786 IWI_EEPROM_CTL(sc, 0); 787 IWI_EEPROM_CTL(sc, IWI_EEPROM_S); 788 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | IWI_EEPROM_C); 789 IWI_EEPROM_CTL(sc, IWI_EEPROM_S); 790 791 /* write start bit (1) */ 792 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | IWI_EEPROM_D); 793 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | IWI_EEPROM_D | IWI_EEPROM_C); 794 795 /* write READ opcode (10) */ 796 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | IWI_EEPROM_D); 797 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | IWI_EEPROM_D | IWI_EEPROM_C); 798 IWI_EEPROM_CTL(sc, IWI_EEPROM_S); 799 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | IWI_EEPROM_C); 800 801 /* write address A7-A0 */ 802 for (n = 7; n >= 0; n--) { 803 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | 804 (((addr >> n) & 1) << IWI_EEPROM_SHIFT_D)); 805 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | 806 (((addr >> n) & 1) << IWI_EEPROM_SHIFT_D) | IWI_EEPROM_C); 807 } 808 809 IWI_EEPROM_CTL(sc, IWI_EEPROM_S); 810 811 /* read data Q15-Q0 */ 812 val = 0; 813 for (n = 15; n >= 0; n--) { 814 IWI_EEPROM_CTL(sc, IWI_EEPROM_S | IWI_EEPROM_C); 815 IWI_EEPROM_CTL(sc, IWI_EEPROM_S); 816 tmp = MEM_READ_4(sc, IWI_MEM_EEPROM_CTL); 817 val |= ((tmp & IWI_EEPROM_Q) >> IWI_EEPROM_SHIFT_Q) << n; 818 } 819 820 IWI_EEPROM_CTL(sc, 0); 821 822 /* clear Chip Select and clock C */ 823 IWI_EEPROM_CTL(sc, IWI_EEPROM_S); 824 IWI_EEPROM_CTL(sc, 0); 825 IWI_EEPROM_CTL(sc, IWI_EEPROM_C); 826 827 return val; 828 } 829 830 uint8_t 831 iwi_rate(int plcp) 832 { 833 switch (plcp) { 834 /* CCK rates (values are device-dependent) */ 835 case 10: return 2; 836 case 20: return 4; 837 case 55: return 11; 838 case 110: return 22; 839 840 /* OFDM rates (cf IEEE Std 802.11a-1999, pp. 14 Table 80) */ 841 case 0xd: return 12; 842 case 0xf: return 18; 843 case 0x5: return 24; 844 case 0x7: return 36; 845 case 0x9: return 48; 846 case 0xb: return 72; 847 case 0x1: return 96; 848 case 0x3: return 108; 849 850 /* unknown rate: should not happen */ 851 default: return 0; 852 } 853 } 854 855 void 856 iwi_frame_intr(struct iwi_softc *sc, struct iwi_rx_data *data, 857 struct iwi_frame *frame, struct mbuf_list *ml) 858 { 859 struct ieee80211com *ic = &sc->sc_ic; 860 struct ifnet *ifp = &ic->ic_if; 861 struct mbuf *mnew, *m; 862 struct ieee80211_frame *wh; 863 struct ieee80211_rxinfo rxi; 864 struct ieee80211_node *ni; 865 int error; 866 867 DPRINTFN(5, ("received frame len=%u chan=%u rssi=%u\n", 868 letoh16(frame->len), frame->chan, frame->rssi_dbm)); 869 870 if (letoh16(frame->len) < sizeof (struct ieee80211_frame_min) || 871 letoh16(frame->len) > MCLBYTES) { 872 DPRINTF(("%s: bad frame length\n", sc->sc_dev.dv_xname)); 873 ifp->if_ierrors++; 874 return; 875 } 876 877 /* 878 * Try to allocate a new mbuf for this ring element and load it before 879 * processing the current mbuf. If the ring element cannot be loaded, 880 * drop the received packet and reuse the old mbuf. In the unlikely 881 * case that the old mbuf can't be reloaded either, explicitly panic. 882 */ 883 MGETHDR(mnew, M_DONTWAIT, MT_DATA); 884 if (mnew == NULL) { 885 ifp->if_ierrors++; 886 return; 887 } 888 MCLGET(mnew, M_DONTWAIT); 889 if (!(mnew->m_flags & M_EXT)) { 890 m_freem(mnew); 891 ifp->if_ierrors++; 892 return; 893 } 894 895 bus_dmamap_unload(sc->sc_dmat, data->map); 896 897 error = bus_dmamap_load(sc->sc_dmat, data->map, mtod(mnew, void *), 898 MCLBYTES, NULL, BUS_DMA_NOWAIT); 899 if (error != 0) { 900 m_freem(mnew); 901 902 /* try to reload the old mbuf */ 903 error = bus_dmamap_load(sc->sc_dmat, data->map, 904 mtod(data->m, void *), MCLBYTES, NULL, BUS_DMA_NOWAIT); 905 if (error != 0) { 906 /* very unlikely that it will fail... */ 907 panic("%s: could not load old rx mbuf", 908 sc->sc_dev.dv_xname); 909 } 910 CSR_WRITE_4(sc, data->reg, data->map->dm_segs[0].ds_addr); 911 ifp->if_ierrors++; 912 return; 913 } 914 915 m = data->m; 916 data->m = mnew; 917 CSR_WRITE_4(sc, data->reg, data->map->dm_segs[0].ds_addr); 918 919 /* finalize mbuf */ 920 m->m_pkthdr.len = m->m_len = sizeof (struct iwi_hdr) + 921 sizeof (struct iwi_frame) + letoh16(frame->len); 922 m_adj(m, sizeof (struct iwi_hdr) + sizeof (struct iwi_frame)); 923 924 #if NBPFILTER > 0 925 if (sc->sc_drvbpf != NULL) { 926 struct iwi_rx_radiotap_header *tap = &sc->sc_rxtap; 927 928 tap->wr_flags = 0; 929 tap->wr_rate = iwi_rate(frame->rate); 930 tap->wr_chan_freq = 931 htole16(ic->ic_channels[frame->chan].ic_freq); 932 tap->wr_chan_flags = 933 htole16(ic->ic_channels[frame->chan].ic_flags); 934 tap->wr_antsignal = frame->signal; 935 tap->wr_antenna = frame->antenna & 0x3; 936 if (frame->antenna & 0x40) 937 tap->wr_flags |= IEEE80211_RADIOTAP_F_SHORTPRE; 938 939 bpf_mtap_hdr(sc->sc_drvbpf, tap, sc->sc_rxtap_len, 940 m, BPF_DIRECTION_IN); 941 } 942 #endif 943 944 wh = mtod(m, struct ieee80211_frame *); 945 ni = ieee80211_find_rxnode(ic, wh); 946 947 /* send the frame to the upper layer */ 948 rxi.rxi_flags = 0; 949 rxi.rxi_rssi = frame->rssi_dbm; 950 rxi.rxi_tstamp = 0; /* unused */ 951 ieee80211_inputm(ifp, m, ni, &rxi, ml); 952 953 /* node is no longer needed */ 954 ieee80211_release_node(ic, ni); 955 } 956 957 void 958 iwi_notification_intr(struct iwi_softc *sc, struct iwi_rx_data *data, 959 struct iwi_notif *notif) 960 { 961 struct ieee80211com *ic = &sc->sc_ic; 962 struct ieee80211_node *ni = ic->ic_bss; 963 struct ifnet *ifp = &ic->ic_if; 964 965 switch (notif->type) { 966 case IWI_NOTIF_TYPE_SCAN_CHANNEL: 967 { 968 #ifdef IWI_DEBUG 969 struct iwi_notif_scan_channel *chan = 970 (struct iwi_notif_scan_channel *)(notif + 1); 971 #endif 972 DPRINTFN(2, ("Scanning channel (%u)\n", chan->nchan)); 973 break; 974 } 975 case IWI_NOTIF_TYPE_SCAN_COMPLETE: 976 { 977 #ifdef IWI_DEBUG 978 struct iwi_notif_scan_complete *scan = 979 (struct iwi_notif_scan_complete *)(notif + 1); 980 #endif 981 DPRINTFN(2, ("Scan completed (%u, %u)\n", scan->nchan, 982 scan->status)); 983 984 /* monitor mode uses scan to set the channel ... */ 985 if (ic->ic_opmode != IEEE80211_M_MONITOR) 986 ieee80211_end_scan(ifp); 987 else 988 iwi_set_chan(sc, ic->ic_ibss_chan); 989 break; 990 } 991 case IWI_NOTIF_TYPE_AUTHENTICATION: 992 { 993 struct iwi_notif_authentication *auth = 994 (struct iwi_notif_authentication *)(notif + 1); 995 996 DPRINTFN(2, ("Authentication (%u)\n", auth->state)); 997 998 switch (auth->state) { 999 case IWI_AUTHENTICATED: 1000 ieee80211_new_state(ic, IEEE80211_S_ASSOC, -1); 1001 break; 1002 1003 case IWI_DEAUTHENTICATED: 1004 break; 1005 1006 default: 1007 printf("%s: unknown authentication state %u\n", 1008 sc->sc_dev.dv_xname, auth->state); 1009 } 1010 break; 1011 } 1012 case IWI_NOTIF_TYPE_ASSOCIATION: 1013 { 1014 struct iwi_notif_association *assoc = 1015 (struct iwi_notif_association *)(notif + 1); 1016 1017 DPRINTFN(2, ("Association (%u, %u)\n", assoc->state, 1018 assoc->status)); 1019 1020 switch (assoc->state) { 1021 case IWI_AUTHENTICATED: 1022 /* re-association, do nothing */ 1023 break; 1024 1025 case IWI_ASSOCIATED: 1026 if (ic->ic_flags & IEEE80211_F_RSNON) 1027 ni->ni_rsn_supp_state = RSNA_SUPP_PTKSTART; 1028 ieee80211_new_state(ic, IEEE80211_S_RUN, -1); 1029 break; 1030 1031 case IWI_DEASSOCIATED: 1032 ieee80211_begin_scan(ifp); 1033 break; 1034 1035 default: 1036 printf("%s: unknown association state %u\n", 1037 sc->sc_dev.dv_xname, assoc->state); 1038 } 1039 break; 1040 } 1041 case IWI_NOTIF_TYPE_BEACON: 1042 { 1043 struct iwi_notif_beacon *beacon = 1044 (struct iwi_notif_beacon *)(notif + 1); 1045 1046 if (letoh32(beacon->status) == IWI_BEACON_MISSED) { 1047 /* XXX should roam when too many beacons missed */ 1048 DPRINTFN(2, ("%s: %u beacon(s) missed\n", 1049 sc->sc_dev.dv_xname, letoh32(beacon->count))); 1050 } 1051 break; 1052 } 1053 case IWI_NOTIF_TYPE_BAD_LINK: 1054 DPRINTFN(2, ("link deterioration detected\n")); 1055 break; 1056 1057 case IWI_NOTIF_TYPE_NOISE: 1058 DPRINTFN(5, ("Measured noise %u\n", 1059 letoh32(*(uint32_t *)(notif + 1)) & 0xff)); 1060 break; 1061 1062 default: 1063 DPRINTFN(5, ("Notification (%u)\n", notif->type)); 1064 } 1065 } 1066 1067 void 1068 iwi_rx_intr(struct iwi_softc *sc) 1069 { 1070 struct mbuf_list ml = MBUF_LIST_INITIALIZER(); 1071 struct iwi_rx_data *data; 1072 struct iwi_hdr *hdr; 1073 uint32_t hw; 1074 1075 hw = CSR_READ_4(sc, IWI_CSR_RX_RIDX); 1076 1077 for (; sc->rxq.cur != hw;) { 1078 data = &sc->rxq.data[sc->rxq.cur]; 1079 1080 bus_dmamap_sync(sc->sc_dmat, data->map, 0, MCLBYTES, 1081 BUS_DMASYNC_POSTREAD); 1082 1083 hdr = mtod(data->m, struct iwi_hdr *); 1084 1085 switch (hdr->type) { 1086 case IWI_HDR_TYPE_FRAME: 1087 iwi_frame_intr(sc, data, 1088 (struct iwi_frame *)(hdr + 1), &ml); 1089 break; 1090 1091 case IWI_HDR_TYPE_NOTIF: 1092 iwi_notification_intr(sc, data, 1093 (struct iwi_notif *)(hdr + 1)); 1094 break; 1095 1096 default: 1097 printf("%s: unknown hdr type %u\n", 1098 sc->sc_dev.dv_xname, hdr->type); 1099 } 1100 1101 sc->rxq.cur = (sc->rxq.cur + 1) % IWI_RX_RING_COUNT; 1102 } 1103 if_input(&sc->sc_ic.ic_if, &ml); 1104 1105 /* tell the firmware what we have processed */ 1106 hw = (hw == 0) ? IWI_RX_RING_COUNT - 1 : hw - 1; 1107 CSR_WRITE_4(sc, IWI_CSR_RX_WIDX, hw); 1108 } 1109 1110 void 1111 iwi_tx_intr(struct iwi_softc *sc, struct iwi_tx_ring *txq) 1112 { 1113 struct ieee80211com *ic = &sc->sc_ic; 1114 struct ifnet *ifp = &ic->ic_if; 1115 struct iwi_tx_data *data; 1116 uint32_t hw; 1117 1118 hw = CSR_READ_4(sc, txq->csr_ridx); 1119 1120 for (; txq->next != hw;) { 1121 data = &txq->data[txq->next]; 1122 1123 bus_dmamap_unload(sc->sc_dmat, data->map); 1124 m_freem(data->m); 1125 data->m = NULL; 1126 ieee80211_release_node(ic, data->ni); 1127 data->ni = NULL; 1128 1129 txq->queued--; 1130 txq->next = (txq->next + 1) % IWI_TX_RING_COUNT; 1131 } 1132 1133 sc->sc_tx_timer = 0; 1134 ifq_clr_oactive(&ifp->if_snd); 1135 (*ifp->if_start)(ifp); 1136 } 1137 1138 int 1139 iwi_intr(void *arg) 1140 { 1141 struct iwi_softc *sc = arg; 1142 struct ifnet *ifp = &sc->sc_ic.ic_if; 1143 uint32_t r; 1144 1145 if ((r = CSR_READ_4(sc, IWI_CSR_INTR)) == 0 || r == 0xffffffff) 1146 return 0; 1147 1148 /* disable interrupts */ 1149 CSR_WRITE_4(sc, IWI_CSR_INTR_MASK, 0); 1150 1151 /* acknowledge interrupts */ 1152 CSR_WRITE_4(sc, IWI_CSR_INTR, r); 1153 1154 if (r & IWI_INTR_FATAL_ERROR) { 1155 printf("%s: fatal firmware error\n", sc->sc_dev.dv_xname); 1156 iwi_stop(ifp, 1); 1157 task_add(systq, &sc->init_task); 1158 return 1; 1159 } 1160 1161 if (r & IWI_INTR_FW_INITED) 1162 wakeup(sc); 1163 1164 if (r & IWI_INTR_RADIO_OFF) { 1165 DPRINTF(("radio transmitter off\n")); 1166 iwi_stop(ifp, 1); 1167 return 1; 1168 } 1169 1170 if (r & IWI_INTR_CMD_DONE) { 1171 /* kick next pending command if any */ 1172 sc->cmdq.next = (sc->cmdq.next + 1) % IWI_CMD_RING_COUNT; 1173 if (--sc->cmdq.queued > 0) 1174 CSR_WRITE_4(sc, IWI_CSR_CMD_WIDX, sc->cmdq.next); 1175 1176 wakeup(sc); 1177 } 1178 1179 if (r & IWI_INTR_TX1_DONE) 1180 iwi_tx_intr(sc, &sc->txq[0]); 1181 1182 if (r & IWI_INTR_TX2_DONE) 1183 iwi_tx_intr(sc, &sc->txq[1]); 1184 1185 if (r & IWI_INTR_TX3_DONE) 1186 iwi_tx_intr(sc, &sc->txq[2]); 1187 1188 if (r & IWI_INTR_TX4_DONE) 1189 iwi_tx_intr(sc, &sc->txq[3]); 1190 1191 if (r & IWI_INTR_RX_DONE) 1192 iwi_rx_intr(sc); 1193 1194 /* re-enable interrupts */ 1195 CSR_WRITE_4(sc, IWI_CSR_INTR_MASK, IWI_INTR_MASK); 1196 1197 return 1; 1198 } 1199 1200 int 1201 iwi_cmd(struct iwi_softc *sc, uint8_t type, void *data, uint8_t len, int async) 1202 { 1203 struct iwi_cmd_desc *desc; 1204 1205 desc = &sc->cmdq.desc[sc->cmdq.cur]; 1206 desc->hdr.type = IWI_HDR_TYPE_COMMAND; 1207 desc->hdr.flags = IWI_HDR_FLAG_IRQ; 1208 desc->type = type; 1209 desc->len = len; 1210 bcopy(data, desc->data, len); 1211 1212 bus_dmamap_sync(sc->sc_dmat, sc->cmdq.map, 1213 sc->cmdq.cur * sizeof (struct iwi_cmd_desc), 1214 sizeof (struct iwi_cmd_desc), BUS_DMASYNC_PREWRITE); 1215 1216 DPRINTFN(2, ("sending command idx=%u type=%u len=%u\n", sc->cmdq.cur, 1217 type, len)); 1218 1219 sc->cmdq.cur = (sc->cmdq.cur + 1) % IWI_CMD_RING_COUNT; 1220 1221 /* don't kick cmd immediately if another async command is pending */ 1222 if (++sc->cmdq.queued == 1) { 1223 sc->cmdq.next = sc->cmdq.cur; 1224 CSR_WRITE_4(sc, IWI_CSR_CMD_WIDX, sc->cmdq.next); 1225 } 1226 1227 return async ? 0 : tsleep_nsec(sc, PCATCH, "iwicmd", SEC_TO_NSEC(1)); 1228 } 1229 1230 /* ARGSUSED */ 1231 int 1232 iwi_send_mgmt(struct ieee80211com *ic, struct ieee80211_node *ni, int type, 1233 int arg1, int arg2) 1234 { 1235 return EOPNOTSUPP; 1236 } 1237 1238 int 1239 iwi_tx_start(struct ifnet *ifp, struct mbuf *m0, struct ieee80211_node *ni) 1240 { 1241 struct iwi_softc *sc = ifp->if_softc; 1242 struct ieee80211com *ic = &sc->sc_ic; 1243 struct ieee80211_frame *wh; 1244 struct ieee80211_key *k; 1245 struct iwi_tx_data *data; 1246 struct iwi_tx_desc *desc; 1247 struct iwi_tx_ring *txq = &sc->txq[0]; 1248 int hdrlen, error, i, station = 0; 1249 1250 wh = mtod(m0, struct ieee80211_frame *); 1251 1252 if (wh->i_fc[1] & IEEE80211_FC1_PROTECTED) { 1253 k = ieee80211_get_txkey(ic, wh, ni); 1254 1255 if ((m0 = ieee80211_encrypt(ic, m0, k)) == NULL) 1256 return ENOBUFS; 1257 1258 /* packet header may have moved, reset our local pointer */ 1259 wh = mtod(m0, struct ieee80211_frame *); 1260 } 1261 1262 #if NBPFILTER > 0 1263 if (sc->sc_drvbpf != NULL) { 1264 struct iwi_tx_radiotap_header *tap = &sc->sc_txtap; 1265 1266 tap->wt_flags = 0; 1267 tap->wt_chan_freq = htole16(ic->ic_bss->ni_chan->ic_freq); 1268 tap->wt_chan_flags = htole16(ic->ic_bss->ni_chan->ic_flags); 1269 1270 bpf_mtap_hdr(sc->sc_drvbpf, tap, sc->sc_txtap_len, 1271 m0, BPF_DIRECTION_OUT); 1272 } 1273 #endif 1274 1275 data = &txq->data[txq->cur]; 1276 desc = &txq->desc[txq->cur]; 1277 1278 /* copy and trim IEEE802.11 header */ 1279 hdrlen = ieee80211_get_hdrlen(wh); 1280 bcopy(wh, &desc->wh, hdrlen); 1281 m_adj(m0, hdrlen); 1282 1283 #ifndef IEEE80211_STA_ONLY 1284 if (ic->ic_opmode == IEEE80211_M_IBSS) { 1285 station = iwi_find_txnode(sc, desc->wh.i_addr1); 1286 if (station == -1) { 1287 m_freem(m0); 1288 ieee80211_release_node(ic, ni); 1289 ifp->if_oerrors++; 1290 return 0; 1291 } 1292 } 1293 #endif 1294 1295 error = bus_dmamap_load_mbuf(sc->sc_dmat, data->map, m0, 1296 BUS_DMA_NOWAIT); 1297 if (error != 0 && error != EFBIG) { 1298 printf("%s: can't map mbuf (error %d)\n", 1299 sc->sc_dev.dv_xname, error); 1300 m_freem(m0); 1301 return error; 1302 } 1303 if (error != 0) { 1304 /* too many fragments, linearize */ 1305 if (m_defrag(m0, M_DONTWAIT)) { 1306 m_freem(m0); 1307 return ENOBUFS; 1308 } 1309 error = bus_dmamap_load_mbuf(sc->sc_dmat, data->map, m0, 1310 BUS_DMA_NOWAIT); 1311 if (error != 0) { 1312 printf("%s: can't map mbuf (error %d)\n", 1313 sc->sc_dev.dv_xname, error); 1314 m_freem(m0); 1315 return error; 1316 } 1317 } 1318 1319 data->m = m0; 1320 data->ni = ni; 1321 1322 desc->hdr.type = IWI_HDR_TYPE_DATA; 1323 desc->hdr.flags = IWI_HDR_FLAG_IRQ; 1324 desc->cmd = IWI_DATA_CMD_TX; 1325 desc->len = htole16(m0->m_pkthdr.len); 1326 desc->station = station; 1327 desc->flags = IWI_DATA_FLAG_NO_WEP; 1328 desc->xflags = 0; 1329 1330 if (!IEEE80211_IS_MULTICAST(desc->wh.i_addr1)) 1331 desc->flags |= IWI_DATA_FLAG_NEED_ACK; 1332 1333 if (ic->ic_flags & IEEE80211_F_SHPREAMBLE) 1334 desc->flags |= IWI_DATA_FLAG_SHPREAMBLE; 1335 1336 if ((desc->wh.i_fc[0] & 1337 (IEEE80211_FC0_TYPE_MASK | IEEE80211_FC0_SUBTYPE_QOS)) == 1338 (IEEE80211_FC0_TYPE_DATA | IEEE80211_FC0_SUBTYPE_QOS)) 1339 desc->xflags |= IWI_DATA_XFLAG_QOS; 1340 1341 if (ic->ic_curmode == IEEE80211_MODE_11B) 1342 desc->xflags |= IWI_DATA_XFLAG_CCK; 1343 1344 desc->nseg = htole32(data->map->dm_nsegs); 1345 for (i = 0; i < data->map->dm_nsegs; i++) { 1346 desc->seg_addr[i] = htole32(data->map->dm_segs[i].ds_addr); 1347 desc->seg_len[i] = htole16(data->map->dm_segs[i].ds_len); 1348 } 1349 1350 bus_dmamap_sync(sc->sc_dmat, data->map, 0, data->map->dm_mapsize, 1351 BUS_DMASYNC_PREWRITE); 1352 bus_dmamap_sync(sc->sc_dmat, txq->map, 1353 txq->cur * sizeof (struct iwi_tx_desc), 1354 sizeof (struct iwi_tx_desc), BUS_DMASYNC_PREWRITE); 1355 1356 DPRINTFN(5, ("sending data frame idx=%u len=%u nseg=%u\n", txq->cur, 1357 letoh16(desc->len), data->map->dm_nsegs)); 1358 1359 txq->queued++; 1360 txq->cur = (txq->cur + 1) % IWI_TX_RING_COUNT; 1361 CSR_WRITE_4(sc, txq->csr_widx, txq->cur); 1362 1363 return 0; 1364 } 1365 1366 void 1367 iwi_start(struct ifnet *ifp) 1368 { 1369 struct iwi_softc *sc = ifp->if_softc; 1370 struct ieee80211com *ic = &sc->sc_ic; 1371 struct mbuf *m0; 1372 struct ieee80211_node *ni; 1373 1374 if (ic->ic_state != IEEE80211_S_RUN) 1375 return; 1376 1377 for (;;) { 1378 if (sc->txq[0].queued + IWI_MAX_NSEG + 2 >= IWI_TX_RING_COUNT) { 1379 ifq_set_oactive(&ifp->if_snd); 1380 break; 1381 } 1382 1383 m0 = ifq_dequeue(&ifp->if_snd); 1384 if (m0 == NULL) 1385 break; 1386 1387 #if NBPFILTER > 0 1388 if (ifp->if_bpf != NULL) 1389 bpf_mtap(ifp->if_bpf, m0, BPF_DIRECTION_OUT); 1390 #endif 1391 1392 m0 = ieee80211_encap(ifp, m0, &ni); 1393 if (m0 == NULL) 1394 continue; 1395 1396 #if NBPFILTER > 0 1397 if (ic->ic_rawbpf != NULL) 1398 bpf_mtap(ic->ic_rawbpf, m0, BPF_DIRECTION_OUT); 1399 #endif 1400 1401 if (iwi_tx_start(ifp, m0, ni) != 0) { 1402 if (ni != NULL) 1403 ieee80211_release_node(ic, ni); 1404 ifp->if_oerrors++; 1405 break; 1406 } 1407 1408 /* start watchdog timer */ 1409 sc->sc_tx_timer = 5; 1410 ifp->if_timer = 1; 1411 } 1412 } 1413 1414 void 1415 iwi_watchdog(struct ifnet *ifp) 1416 { 1417 struct iwi_softc *sc = ifp->if_softc; 1418 1419 ifp->if_timer = 0; 1420 1421 if (sc->sc_tx_timer > 0) { 1422 if (--sc->sc_tx_timer == 0) { 1423 printf("%s: device timeout\n", sc->sc_dev.dv_xname); 1424 iwi_stop(ifp, 1); 1425 ifp->if_oerrors++; 1426 return; 1427 } 1428 ifp->if_timer = 1; 1429 } 1430 1431 ieee80211_watchdog(ifp); 1432 } 1433 1434 int 1435 iwi_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data) 1436 { 1437 struct iwi_softc *sc = ifp->if_softc; 1438 int s, error = 0; 1439 1440 error = rw_enter(&sc->sc_rwlock, RW_WRITE | RW_INTR); 1441 if (error) 1442 return error; 1443 s = splnet(); 1444 1445 switch (cmd) { 1446 case SIOCSIFADDR: 1447 ifp->if_flags |= IFF_UP; 1448 /* FALLTHROUGH */ 1449 case SIOCSIFFLAGS: 1450 if (ifp->if_flags & IFF_UP) { 1451 if (!(ifp->if_flags & IFF_RUNNING)) 1452 iwi_init(ifp); 1453 } else { 1454 if (ifp->if_flags & IFF_RUNNING) 1455 iwi_stop(ifp, 1); 1456 } 1457 break; 1458 1459 case SIOCG80211TXPOWER: 1460 /* 1461 * If the hardware radio transmitter switch is off, report a 1462 * tx power of IEEE80211_TXPOWER_MIN to indicate that radio 1463 * transmitter is killed. 1464 */ 1465 ((struct ieee80211_txpower *)data)->i_val = 1466 (CSR_READ_4(sc, IWI_CSR_IO) & IWI_IO_RADIO_ENABLED) ? 1467 sc->sc_ic.ic_txpower : IEEE80211_TXPOWER_MIN; 1468 break; 1469 1470 default: 1471 error = ieee80211_ioctl(ifp, cmd, data); 1472 } 1473 1474 if (error == ENETRESET) { 1475 if ((ifp->if_flags & (IFF_UP | IFF_RUNNING)) == 1476 (IFF_UP | IFF_RUNNING)) 1477 iwi_init(ifp); 1478 error = 0; 1479 } 1480 1481 splx(s); 1482 rw_exit_write(&sc->sc_rwlock); 1483 return error; 1484 } 1485 1486 void 1487 iwi_stop_master(struct iwi_softc *sc) 1488 { 1489 uint32_t tmp; 1490 int ntries; 1491 1492 /* disable interrupts */ 1493 CSR_WRITE_4(sc, IWI_CSR_INTR_MASK, 0); 1494 1495 CSR_WRITE_4(sc, IWI_CSR_RST, IWI_RST_STOP_MASTER); 1496 for (ntries = 0; ntries < 5; ntries++) { 1497 if (CSR_READ_4(sc, IWI_CSR_RST) & IWI_RST_MASTER_DISABLED) 1498 break; 1499 DELAY(10); 1500 } 1501 if (ntries == 5) { 1502 printf("%s: timeout waiting for master\n", 1503 sc->sc_dev.dv_xname); 1504 } 1505 1506 tmp = CSR_READ_4(sc, IWI_CSR_RST); 1507 CSR_WRITE_4(sc, IWI_CSR_RST, tmp | IWI_RST_PRINCETON_RESET); 1508 } 1509 1510 int 1511 iwi_reset(struct iwi_softc *sc) 1512 { 1513 uint32_t tmp; 1514 int i, ntries; 1515 1516 iwi_stop_master(sc); 1517 1518 /* move adapter to D0 state */ 1519 tmp = CSR_READ_4(sc, IWI_CSR_CTL); 1520 CSR_WRITE_4(sc, IWI_CSR_CTL, tmp | IWI_CTL_INIT); 1521 1522 CSR_WRITE_4(sc, IWI_CSR_READ_INT, IWI_READ_INT_INIT_HOST); 1523 1524 /* wait for clock stabilization */ 1525 for (ntries = 0; ntries < 1000; ntries++) { 1526 if (CSR_READ_4(sc, IWI_CSR_CTL) & IWI_CTL_CLOCK_READY) 1527 break; 1528 DELAY(200); 1529 } 1530 if (ntries == 1000) { 1531 printf("%s: timeout waiting for clock stabilization\n", 1532 sc->sc_dev.dv_xname); 1533 return ETIMEDOUT; 1534 } 1535 1536 tmp = CSR_READ_4(sc, IWI_CSR_RST); 1537 CSR_WRITE_4(sc, IWI_CSR_RST, tmp | IWI_RST_SW_RESET); 1538 1539 DELAY(10); 1540 1541 tmp = CSR_READ_4(sc, IWI_CSR_CTL); 1542 CSR_WRITE_4(sc, IWI_CSR_CTL, tmp | IWI_CTL_INIT); 1543 1544 /* clear NIC memory */ 1545 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_ADDR, 0); 1546 for (i = 0; i < 0xc000; i++) 1547 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_DATA, 0); 1548 1549 return 0; 1550 } 1551 1552 int 1553 iwi_load_ucode(struct iwi_softc *sc, const char *data, int size) 1554 { 1555 const uint16_t *w; 1556 uint32_t tmp; 1557 int ntries, i; 1558 1559 tmp = CSR_READ_4(sc, IWI_CSR_RST); 1560 CSR_WRITE_4(sc, IWI_CSR_RST, tmp | IWI_RST_STOP_MASTER); 1561 for (ntries = 0; ntries < 5; ntries++) { 1562 if (CSR_READ_4(sc, IWI_CSR_RST) & IWI_RST_MASTER_DISABLED) 1563 break; 1564 DELAY(10); 1565 } 1566 if (ntries == 5) { 1567 printf("%s: timeout waiting for master\n", 1568 sc->sc_dev.dv_xname); 1569 return ETIMEDOUT; 1570 } 1571 1572 MEM_WRITE_4(sc, 0x3000e0, 0x80000000); 1573 DELAY(5000); 1574 1575 tmp = CSR_READ_4(sc, IWI_CSR_RST); 1576 CSR_WRITE_4(sc, IWI_CSR_RST, tmp & ~IWI_RST_PRINCETON_RESET); 1577 1578 DELAY(5000); 1579 MEM_WRITE_4(sc, 0x3000e0, 0); 1580 DELAY(1000); 1581 MEM_WRITE_4(sc, IWI_MEM_EVENT_CTL, 1); 1582 DELAY(1000); 1583 MEM_WRITE_4(sc, IWI_MEM_EVENT_CTL, 0); 1584 DELAY(1000); 1585 MEM_WRITE_1(sc, 0x200000, 0x00); 1586 MEM_WRITE_1(sc, 0x200000, 0x40); 1587 DELAY(1000); 1588 1589 /* adapter is buggy, we must set the address for each word */ 1590 for (w = (const uint16_t *)data; size > 0; w++, size -= 2) 1591 MEM_WRITE_2(sc, 0x200010, htole16(*w)); 1592 1593 MEM_WRITE_1(sc, 0x200000, 0x00); 1594 MEM_WRITE_1(sc, 0x200000, 0x80); 1595 1596 /* wait until we get an answer */ 1597 for (ntries = 0; ntries < 100; ntries++) { 1598 if (MEM_READ_1(sc, 0x200000) & 1) 1599 break; 1600 DELAY(100); 1601 } 1602 if (ntries == 100) { 1603 printf("%s: timeout waiting for ucode to initialize\n", 1604 sc->sc_dev.dv_xname); 1605 return ETIMEDOUT; 1606 } 1607 1608 /* read the answer or the firmware will not initialize properly */ 1609 for (i = 0; i < 7; i++) 1610 MEM_READ_4(sc, 0x200004); 1611 1612 MEM_WRITE_1(sc, 0x200000, 0x00); 1613 1614 return 0; 1615 } 1616 1617 /* macro to handle unaligned little endian data in firmware image */ 1618 #define GETLE32(p) ((p)[0] | (p)[1] << 8 | (p)[2] << 16 | (p)[3] << 24) 1619 1620 int 1621 iwi_load_firmware(struct iwi_softc *sc, const char *data, int size) 1622 { 1623 bus_dmamap_t map; 1624 bus_dma_segment_t seg; 1625 caddr_t virtaddr; 1626 u_char *p, *end; 1627 uint32_t sentinel, tmp, ctl, src, dst, sum, len, mlen; 1628 int ntries, nsegs, error; 1629 1630 /* allocate DMA memory to store firmware image */ 1631 error = bus_dmamap_create(sc->sc_dmat, size, 1, size, 0, 1632 BUS_DMA_NOWAIT, &map); 1633 if (error != 0) { 1634 printf("%s: could not create firmware DMA map\n", 1635 sc->sc_dev.dv_xname); 1636 goto fail1; 1637 } 1638 1639 error = bus_dmamem_alloc(sc->sc_dmat, size, PAGE_SIZE, 0, &seg, 1, 1640 &nsegs, BUS_DMA_NOWAIT); 1641 if (error != 0) { 1642 printf("%s: could not allocate firmware DMA memory\n", 1643 sc->sc_dev.dv_xname); 1644 goto fail2; 1645 } 1646 1647 error = bus_dmamem_map(sc->sc_dmat, &seg, nsegs, size, &virtaddr, 1648 BUS_DMA_NOWAIT); 1649 if (error != 0) { 1650 printf("%s: can't map firmware DMA memory\n", 1651 sc->sc_dev.dv_xname); 1652 goto fail3; 1653 } 1654 1655 error = bus_dmamap_load(sc->sc_dmat, map, virtaddr, size, NULL, 1656 BUS_DMA_NOWAIT); 1657 if (error != 0) { 1658 printf("%s: could not load firmware DMA map\n", 1659 sc->sc_dev.dv_xname); 1660 goto fail4; 1661 } 1662 1663 /* copy firmware image to DMA memory */ 1664 bcopy(data, virtaddr, size); 1665 1666 /* make sure the adapter will get up-to-date values */ 1667 bus_dmamap_sync(sc->sc_dmat, map, 0, size, BUS_DMASYNC_PREWRITE); 1668 1669 /* tell the adapter where the command blocks are stored */ 1670 MEM_WRITE_4(sc, 0x3000a0, 0x27000); 1671 1672 /* 1673 * Store command blocks into adapter's internal memory using register 1674 * indirections. The adapter will read the firmware image through DMA 1675 * using information stored in command blocks. 1676 */ 1677 src = map->dm_segs[0].ds_addr; 1678 p = virtaddr; 1679 end = p + size; 1680 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_ADDR, 0x27000); 1681 1682 while (p < end) { 1683 dst = GETLE32(p); p += 4; src += 4; 1684 len = GETLE32(p); p += 4; src += 4; 1685 p += len; 1686 1687 while (len > 0) { 1688 mlen = min(len, IWI_CB_MAXDATALEN); 1689 1690 ctl = IWI_CB_DEFAULT_CTL | mlen; 1691 sum = ctl ^ src ^ dst; 1692 1693 /* write a command block */ 1694 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_DATA, ctl); 1695 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_DATA, src); 1696 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_DATA, dst); 1697 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_DATA, sum); 1698 1699 src += mlen; 1700 dst += mlen; 1701 len -= mlen; 1702 } 1703 } 1704 1705 /* write a fictive final command block (sentinel) */ 1706 sentinel = CSR_READ_4(sc, IWI_CSR_AUTOINC_ADDR); 1707 CSR_WRITE_4(sc, IWI_CSR_AUTOINC_DATA, 0); 1708 1709 tmp = CSR_READ_4(sc, IWI_CSR_RST); 1710 tmp &= ~(IWI_RST_MASTER_DISABLED | IWI_RST_STOP_MASTER); 1711 CSR_WRITE_4(sc, IWI_CSR_RST, tmp); 1712 1713 /* tell the adapter to start processing command blocks */ 1714 MEM_WRITE_4(sc, 0x3000a4, 0x540100); 1715 1716 /* wait until the adapter has processed all command blocks */ 1717 for (ntries = 0; ntries < 400; ntries++) { 1718 if (MEM_READ_4(sc, 0x3000d0) >= sentinel) 1719 break; 1720 DELAY(100); 1721 } 1722 if (ntries == 400) { 1723 printf("%s: timeout processing cb\n", sc->sc_dev.dv_xname); 1724 error = ETIMEDOUT; 1725 goto fail5; 1726 } 1727 1728 /* we're done with command blocks processing */ 1729 MEM_WRITE_4(sc, 0x3000a4, 0x540c00); 1730 1731 /* allow interrupts so we know when the firmware is inited */ 1732 CSR_WRITE_4(sc, IWI_CSR_INTR_MASK, IWI_INTR_MASK); 1733 1734 /* tell the adapter to initialize the firmware */ 1735 CSR_WRITE_4(sc, IWI_CSR_RST, 0); 1736 1737 tmp = CSR_READ_4(sc, IWI_CSR_CTL); 1738 CSR_WRITE_4(sc, IWI_CSR_CTL, tmp | IWI_CTL_ALLOW_STANDBY); 1739 1740 /* wait at most one second for firmware initialization to complete */ 1741 if ((error = tsleep_nsec(sc, PCATCH, "iwiinit", SEC_TO_NSEC(1))) != 0) { 1742 printf("%s: timeout waiting for firmware initialization to " 1743 "complete\n", sc->sc_dev.dv_xname); 1744 goto fail5; 1745 } 1746 1747 fail5: bus_dmamap_sync(sc->sc_dmat, map, 0, size, BUS_DMASYNC_POSTWRITE); 1748 bus_dmamap_unload(sc->sc_dmat, map); 1749 fail4: bus_dmamem_unmap(sc->sc_dmat, virtaddr, size); 1750 fail3: bus_dmamem_free(sc->sc_dmat, &seg, 1); 1751 fail2: bus_dmamap_destroy(sc->sc_dmat, map); 1752 fail1: return error; 1753 } 1754 1755 int 1756 iwi_config(struct iwi_softc *sc) 1757 { 1758 struct ieee80211com *ic = &sc->sc_ic; 1759 struct ifnet *ifp = &ic->ic_if; 1760 struct iwi_configuration config; 1761 struct iwi_rateset rs; 1762 struct iwi_txpower power; 1763 uint32_t data; 1764 int error, nchan, i; 1765 1766 IEEE80211_ADDR_COPY(ic->ic_myaddr, LLADDR(ifp->if_sadl)); 1767 DPRINTF(("Setting MAC address to %s\n", ether_sprintf(ic->ic_myaddr))); 1768 error = iwi_cmd(sc, IWI_CMD_SET_MAC_ADDRESS, ic->ic_myaddr, 1769 IEEE80211_ADDR_LEN, 0); 1770 if (error != 0) 1771 return error; 1772 1773 bzero(&config, sizeof config); 1774 config.multicast_enabled = 1; 1775 config.silence_threshold = 30; 1776 config.report_noise = 1; 1777 config.answer_pbreq = 1778 #ifndef IEEE80211_STA_ONLY 1779 (ic->ic_opmode == IEEE80211_M_IBSS) ? 1 : 1780 #endif 1781 0; 1782 DPRINTF(("Configuring adapter\n")); 1783 error = iwi_cmd(sc, IWI_CMD_SET_CONFIG, &config, sizeof config, 0); 1784 if (error != 0) 1785 return error; 1786 1787 data = htole32(IWI_POWER_MODE_CAM); 1788 DPRINTF(("Setting power mode to %u\n", letoh32(data))); 1789 error = iwi_cmd(sc, IWI_CMD_SET_POWER_MODE, &data, sizeof data, 0); 1790 if (error != 0) 1791 return error; 1792 1793 data = htole32(ic->ic_rtsthreshold); 1794 DPRINTF(("Setting RTS threshold to %u\n", letoh32(data))); 1795 error = iwi_cmd(sc, IWI_CMD_SET_RTS_THRESHOLD, &data, sizeof data, 0); 1796 if (error != 0) 1797 return error; 1798 1799 data = htole32(ic->ic_fragthreshold); 1800 DPRINTF(("Setting fragmentation threshold to %u\n", letoh32(data))); 1801 error = iwi_cmd(sc, IWI_CMD_SET_FRAG_THRESHOLD, &data, sizeof data, 0); 1802 if (error != 0) 1803 return error; 1804 1805 /* 1806 * Set default Tx power for 802.11b/g and 802.11a channels. 1807 */ 1808 nchan = 0; 1809 for (i = 0; i <= IEEE80211_CHAN_MAX; i++) { 1810 if (!IEEE80211_IS_CHAN_2GHZ(&ic->ic_channels[i])) 1811 continue; 1812 power.chan[nchan].chan = i; 1813 power.chan[nchan].power = IWI_TXPOWER_MAX; 1814 nchan++; 1815 } 1816 power.nchan = nchan; 1817 1818 power.mode = IWI_MODE_11G; 1819 DPRINTF(("Setting .11g channels tx power\n")); 1820 error = iwi_cmd(sc, IWI_CMD_SET_TX_POWER, &power, sizeof power, 0); 1821 if (error != 0) 1822 return error; 1823 1824 power.mode = IWI_MODE_11B; 1825 DPRINTF(("Setting .11b channels tx power\n")); 1826 error = iwi_cmd(sc, IWI_CMD_SET_TX_POWER, &power, sizeof power, 0); 1827 if (error != 0) 1828 return error; 1829 1830 nchan = 0; 1831 for (i = 0; i <= IEEE80211_CHAN_MAX; i++) { 1832 if (!IEEE80211_IS_CHAN_5GHZ(&ic->ic_channels[i])) 1833 continue; 1834 power.chan[nchan].chan = i; 1835 power.chan[nchan].power = IWI_TXPOWER_MAX; 1836 nchan++; 1837 } 1838 power.nchan = nchan; 1839 1840 if (nchan > 0) { /* 2915ABG only */ 1841 power.mode = IWI_MODE_11A; 1842 DPRINTF(("Setting .11a channels tx power\n")); 1843 error = iwi_cmd(sc, IWI_CMD_SET_TX_POWER, &power, sizeof power, 1844 0); 1845 if (error != 0) 1846 return error; 1847 } 1848 1849 rs.mode = IWI_MODE_11G; 1850 rs.type = IWI_RATESET_TYPE_SUPPORTED; 1851 rs.nrates = ic->ic_sup_rates[IEEE80211_MODE_11G].rs_nrates; 1852 bcopy(ic->ic_sup_rates[IEEE80211_MODE_11G].rs_rates, rs.rates, 1853 rs.nrates); 1854 DPRINTF(("Setting .11bg supported rates (%u)\n", rs.nrates)); 1855 error = iwi_cmd(sc, IWI_CMD_SET_RATES, &rs, sizeof rs, 0); 1856 if (error != 0) 1857 return error; 1858 1859 rs.mode = IWI_MODE_11A; 1860 rs.type = IWI_RATESET_TYPE_SUPPORTED; 1861 rs.nrates = ic->ic_sup_rates[IEEE80211_MODE_11A].rs_nrates; 1862 bcopy(ic->ic_sup_rates[IEEE80211_MODE_11A].rs_rates, rs.rates, 1863 rs.nrates); 1864 DPRINTF(("Setting .11a supported rates (%u)\n", rs.nrates)); 1865 error = iwi_cmd(sc, IWI_CMD_SET_RATES, &rs, sizeof rs, 0); 1866 if (error != 0) 1867 return error; 1868 1869 /* if we have a desired ESSID, set it now */ 1870 if (ic->ic_des_esslen != 0) { 1871 #ifdef IWI_DEBUG 1872 if (iwi_debug > 0) { 1873 printf("Setting desired ESSID to "); 1874 ieee80211_print_essid(ic->ic_des_essid, 1875 ic->ic_des_esslen); 1876 printf("\n"); 1877 } 1878 #endif 1879 error = iwi_cmd(sc, IWI_CMD_SET_ESSID, ic->ic_des_essid, 1880 ic->ic_des_esslen, 0); 1881 if (error != 0) 1882 return error; 1883 } 1884 1885 arc4random_buf(&data, sizeof data); 1886 DPRINTF(("Setting random seed to %u\n", data)); 1887 error = iwi_cmd(sc, IWI_CMD_SET_RANDOM_SEED, &data, sizeof data, 0); 1888 if (error != 0) 1889 return error; 1890 1891 /* enable adapter */ 1892 DPRINTF(("Enabling adapter\n")); 1893 return iwi_cmd(sc, IWI_CMD_ENABLE, NULL, 0, 0); 1894 } 1895 1896 void 1897 iwi_update_edca(struct ieee80211com *ic) 1898 { 1899 #define IWI_EXP2(v) htole16((1 << (v)) - 1) 1900 #define IWI_TXOP(v) IEEE80211_TXOP_TO_US(v) 1901 struct iwi_softc *sc = ic->ic_softc; 1902 struct iwi_qos_cmd cmd; 1903 struct iwi_qos_params *qos; 1904 struct ieee80211_edca_ac_params *edca = ic->ic_edca_ac; 1905 int aci; 1906 1907 /* set default QoS parameters for CCK */ 1908 qos = &cmd.cck; 1909 for (aci = 0; aci < EDCA_NUM_AC; aci++) { 1910 qos->cwmin[aci] = IWI_EXP2(iwi_cck[aci].ac_ecwmin); 1911 qos->cwmax[aci] = IWI_EXP2(iwi_cck[aci].ac_ecwmax); 1912 qos->txop [aci] = IWI_TXOP(iwi_cck[aci].ac_txoplimit); 1913 qos->aifsn[aci] = iwi_cck[aci].ac_aifsn; 1914 qos->acm [aci] = 0; 1915 } 1916 /* set default QoS parameters for OFDM */ 1917 qos = &cmd.ofdm; 1918 for (aci = 0; aci < EDCA_NUM_AC; aci++) { 1919 qos->cwmin[aci] = IWI_EXP2(iwi_ofdm[aci].ac_ecwmin); 1920 qos->cwmax[aci] = IWI_EXP2(iwi_ofdm[aci].ac_ecwmax); 1921 qos->txop [aci] = IWI_TXOP(iwi_ofdm[aci].ac_txoplimit); 1922 qos->aifsn[aci] = iwi_ofdm[aci].ac_aifsn; 1923 qos->acm [aci] = 0; 1924 } 1925 /* set current QoS parameters */ 1926 qos = &cmd.current; 1927 for (aci = 0; aci < EDCA_NUM_AC; aci++) { 1928 qos->cwmin[aci] = IWI_EXP2(edca[aci].ac_ecwmin); 1929 qos->cwmax[aci] = IWI_EXP2(edca[aci].ac_ecwmax); 1930 qos->txop [aci] = IWI_TXOP(edca[aci].ac_txoplimit); 1931 qos->aifsn[aci] = edca[aci].ac_aifsn; 1932 qos->acm [aci] = 0; 1933 } 1934 1935 DPRINTF(("Setting QoS parameters\n")); 1936 (void)iwi_cmd(sc, IWI_CMD_SET_QOS_PARAMS, &cmd, sizeof cmd, 1); 1937 #undef IWI_EXP2 1938 #undef IWI_TXOP 1939 } 1940 1941 int 1942 iwi_set_chan(struct iwi_softc *sc, struct ieee80211_channel *chan) 1943 { 1944 struct ieee80211com *ic = &sc->sc_ic; 1945 struct iwi_scan scan; 1946 1947 bzero(&scan, sizeof scan); 1948 memset(scan.type, IWI_SCAN_TYPE_PASSIVE, sizeof scan.type); 1949 scan.passive = htole16(2000); 1950 scan.channels[0] = 1 | 1951 (IEEE80211_IS_CHAN_5GHZ(chan) ? IWI_CHAN_5GHZ : IWI_CHAN_2GHZ); 1952 scan.channels[1] = ieee80211_chan2ieee(ic, chan); 1953 1954 DPRINTF(("Setting channel to %u\n", ieee80211_chan2ieee(ic, chan))); 1955 return iwi_cmd(sc, IWI_CMD_SCAN, &scan, sizeof scan, 1); 1956 } 1957 1958 int 1959 iwi_scan(struct iwi_softc *sc) 1960 { 1961 struct ieee80211com *ic = &sc->sc_ic; 1962 struct iwi_scan scan; 1963 uint8_t *p; 1964 int i, count; 1965 1966 bzero(&scan, sizeof scan); 1967 1968 if (ic->ic_des_esslen != 0) { 1969 scan.bdirected = htole16(40); 1970 memset(scan.type, IWI_SCAN_TYPE_BDIRECTED, sizeof scan.type); 1971 } else { 1972 scan.broadcast = htole16(40); 1973 memset(scan.type, IWI_SCAN_TYPE_BROADCAST, sizeof scan.type); 1974 } 1975 1976 p = scan.channels; 1977 count = 0; 1978 for (i = 0; i <= IEEE80211_CHAN_MAX; i++) { 1979 if (IEEE80211_IS_CHAN_5GHZ(&ic->ic_channels[i])) { 1980 *++p = i; 1981 count++; 1982 } 1983 } 1984 *(p - count) = IWI_CHAN_5GHZ | count; 1985 1986 p = (count > 0) ? p + 1 : scan.channels; 1987 count = 0; 1988 for (i = 0; i <= IEEE80211_CHAN_MAX; i++) { 1989 if (IEEE80211_IS_CHAN_2GHZ(&ic->ic_channels[i])) { 1990 *++p = i; 1991 count++; 1992 } 1993 } 1994 *(p - count) = IWI_CHAN_2GHZ | count; 1995 1996 DPRINTF(("Start scanning\n")); 1997 return iwi_cmd(sc, IWI_CMD_SCAN, &scan, sizeof scan, 1); 1998 } 1999 2000 int 2001 iwi_auth_and_assoc(struct iwi_softc *sc) 2002 { 2003 struct ieee80211com *ic = &sc->sc_ic; 2004 struct ieee80211_node *ni = ic->ic_bss; 2005 struct iwi_configuration config; 2006 struct iwi_associate assoc; 2007 struct iwi_rateset rs; 2008 uint8_t *frm; 2009 uint32_t data; 2010 uint16_t capinfo; 2011 uint8_t buf[64]; /* XXX max WPA/RSN/WMM IE length */ 2012 int error; 2013 2014 /* update adapter configuration */ 2015 bzero(&config, sizeof config); 2016 config.multicast_enabled = 1; 2017 config.disable_unicast_decryption = 1; 2018 config.disable_multicast_decryption = 1; 2019 config.silence_threshold = 30; 2020 config.report_noise = 1; 2021 config.allow_mgt = 1; 2022 config.answer_pbreq = 2023 #ifndef IEEE80211_STA_ONLY 2024 (ic->ic_opmode == IEEE80211_M_IBSS) ? 1 : 2025 #endif 2026 0; 2027 if (ic->ic_curmode == IEEE80211_MODE_11G) 2028 config.bg_autodetection = 1; 2029 DPRINTF(("Configuring adapter\n")); 2030 error = iwi_cmd(sc, IWI_CMD_SET_CONFIG, &config, sizeof config, 1); 2031 if (error != 0) 2032 return error; 2033 2034 #ifdef IWI_DEBUG 2035 if (iwi_debug > 0) { 2036 printf("Setting ESSID to "); 2037 ieee80211_print_essid(ni->ni_essid, ni->ni_esslen); 2038 printf("\n"); 2039 } 2040 #endif 2041 error = iwi_cmd(sc, IWI_CMD_SET_ESSID, ni->ni_essid, ni->ni_esslen, 1); 2042 if (error != 0) 2043 return error; 2044 2045 /* the rate set has already been "negotiated" */ 2046 rs.mode = IEEE80211_IS_CHAN_5GHZ(ni->ni_chan) ? IWI_MODE_11A : 2047 IWI_MODE_11G; 2048 rs.type = IWI_RATESET_TYPE_NEGOTIATED; 2049 rs.nrates = ni->ni_rates.rs_nrates; 2050 if (rs.nrates > sizeof rs.rates) { 2051 #ifdef DIAGNOSTIC 2052 /* should not happen since the rates are negotiated */ 2053 printf("%s: XXX too many rates (count=%d, last=%d)\n", 2054 sc->sc_dev.dv_xname, ni->ni_rates.rs_nrates, 2055 ni->ni_rates.rs_rates[ni->ni_rates.rs_nrates - 1] & 2056 IEEE80211_RATE_VAL); 2057 #endif 2058 rs.nrates = sizeof rs.rates; 2059 } 2060 bcopy(ni->ni_rates.rs_rates, rs.rates, rs.nrates); 2061 DPRINTF(("Setting negotiated rates (%u)\n", rs.nrates)); 2062 error = iwi_cmd(sc, IWI_CMD_SET_RATES, &rs, sizeof rs, 1); 2063 if (error != 0) 2064 return error; 2065 2066 data = htole32(ni->ni_rssi); 2067 DPRINTF(("Setting sensitivity to %d\n", (int8_t)ni->ni_rssi)); 2068 error = iwi_cmd(sc, IWI_CMD_SET_SENSITIVITY, &data, sizeof data, 1); 2069 if (error != 0) 2070 return error; 2071 2072 if (ic->ic_flags & IEEE80211_F_QOS) { 2073 iwi_update_edca(ic); 2074 2075 frm = ieee80211_add_qos_capability(buf, ic); 2076 DPRINTF(("Setting QoS Capability IE length %d\n", frm - buf)); 2077 error = iwi_cmd(sc, IWI_CMD_SET_QOS_CAP, buf, frm - buf, 1); 2078 if (error != 0) 2079 return error; 2080 } 2081 if (ic->ic_flags & IEEE80211_F_RSNON) { 2082 /* tell firmware to add WPA/RSN IE to (re)assoc request */ 2083 if (ni->ni_rsnprotos == IEEE80211_PROTO_RSN) 2084 frm = ieee80211_add_rsn(buf, ic, ni); 2085 else 2086 frm = ieee80211_add_wpa(buf, ic, ni); 2087 DPRINTF(("Setting RSN IE length %d\n", frm - buf)); 2088 error = iwi_cmd(sc, IWI_CMD_SET_OPTIE, buf, frm - buf, 1); 2089 if (error != 0) 2090 return error; 2091 } 2092 2093 bzero(&assoc, sizeof assoc); 2094 #ifndef IEEE80211_STA_ONLY 2095 if (ic->ic_flags & IEEE80211_F_SIBSS) 2096 assoc.type = IWI_ASSOC_SIBSS; 2097 else 2098 #endif 2099 assoc.type = IWI_ASSOC_ASSOCIATE; 2100 assoc.policy = 0; 2101 if (ic->ic_flags & IEEE80211_F_RSNON) 2102 assoc.policy |= htole16(IWI_ASSOC_POLICY_RSN); 2103 if (ic->ic_flags & IEEE80211_F_QOS) 2104 assoc.policy |= htole16(IWI_ASSOC_POLICY_QOS); 2105 if (ic->ic_curmode == IEEE80211_MODE_11A) 2106 assoc.mode = IWI_MODE_11A; 2107 else if (ic->ic_curmode == IEEE80211_MODE_11B) 2108 assoc.mode = IWI_MODE_11B; 2109 else /* assume 802.11b/g */ 2110 assoc.mode = IWI_MODE_11G; 2111 assoc.chan = ieee80211_chan2ieee(ic, ni->ni_chan); 2112 if ((ic->ic_flags & IEEE80211_F_SHPREAMBLE) && 2113 IEEE80211_IS_CHAN_2GHZ(ni->ni_chan)) 2114 assoc.plen = IWI_ASSOC_SHPREAMBLE; 2115 bcopy(ni->ni_tstamp, assoc.tstamp, 8); 2116 capinfo = IEEE80211_CAPINFO_ESS; 2117 if (ic->ic_flags & IEEE80211_F_WEPON) 2118 capinfo |= IEEE80211_CAPINFO_PRIVACY; 2119 if ((ic->ic_flags & IEEE80211_F_SHPREAMBLE) && 2120 IEEE80211_IS_CHAN_2GHZ(ni->ni_chan)) 2121 capinfo |= IEEE80211_CAPINFO_SHORT_PREAMBLE; 2122 if (ic->ic_caps & IEEE80211_C_SHSLOT) 2123 capinfo |= IEEE80211_CAPINFO_SHORT_SLOTTIME; 2124 assoc.capinfo = htole16(capinfo); 2125 2126 assoc.lintval = htole16(ic->ic_lintval); 2127 assoc.intval = htole16(ni->ni_intval); 2128 IEEE80211_ADDR_COPY(assoc.bssid, ni->ni_bssid); 2129 #ifndef IEEE80211_STA_ONLY 2130 if (ic->ic_opmode == IEEE80211_M_IBSS) 2131 IEEE80211_ADDR_COPY(assoc.dst, etherbroadcastaddr); 2132 else 2133 #endif 2134 IEEE80211_ADDR_COPY(assoc.dst, ni->ni_bssid); 2135 2136 DPRINTF(("Trying to associate to %s channel %u auth %u\n", 2137 ether_sprintf(assoc.bssid), assoc.chan, assoc.auth)); 2138 return iwi_cmd(sc, IWI_CMD_ASSOCIATE, &assoc, sizeof assoc, 1); 2139 } 2140 2141 int 2142 iwi_init(struct ifnet *ifp) 2143 { 2144 struct iwi_softc *sc = ifp->if_softc; 2145 struct ieee80211com *ic = &sc->sc_ic; 2146 struct iwi_firmware_hdr *hdr; 2147 const char *name, *fw; 2148 u_char *data; 2149 size_t size; 2150 int i, ac, error; 2151 2152 iwi_stop(ifp, 0); 2153 2154 if ((error = iwi_reset(sc)) != 0) { 2155 printf("%s: could not reset adapter\n", sc->sc_dev.dv_xname); 2156 goto fail1; 2157 } 2158 2159 switch (ic->ic_opmode) { 2160 case IEEE80211_M_STA: 2161 name = "iwi-bss"; 2162 break; 2163 #ifndef IEEE80211_STA_ONLY 2164 case IEEE80211_M_IBSS: 2165 case IEEE80211_M_AHDEMO: 2166 name = "iwi-ibss"; 2167 break; 2168 #endif 2169 case IEEE80211_M_MONITOR: 2170 name = "iwi-monitor"; 2171 break; 2172 default: 2173 /* should not get there */ 2174 error = EINVAL; 2175 goto fail1; 2176 } 2177 2178 if ((error = loadfirmware(name, &data, &size)) != 0) { 2179 printf("%s: error %d, could not read firmware %s\n", 2180 sc->sc_dev.dv_xname, error, name); 2181 goto fail1; 2182 } 2183 if (size < sizeof (struct iwi_firmware_hdr)) { 2184 printf("%s: firmware image too short: %zu bytes\n", 2185 sc->sc_dev.dv_xname, size); 2186 error = EINVAL; 2187 goto fail2; 2188 } 2189 hdr = (struct iwi_firmware_hdr *)data; 2190 2191 if (hdr->vermaj < 3 || hdr->bootsz == 0 || hdr->ucodesz == 0 || 2192 hdr->mainsz == 0) { 2193 printf("%s: firmware image too old (need at least 3.0)\n", 2194 sc->sc_dev.dv_xname); 2195 error = EINVAL; 2196 goto fail2; 2197 } 2198 2199 if (size < sizeof (struct iwi_firmware_hdr) + letoh32(hdr->bootsz) + 2200 letoh32(hdr->ucodesz) + letoh32(hdr->mainsz)) { 2201 printf("%s: firmware image too short: %zu bytes\n", 2202 sc->sc_dev.dv_xname, size); 2203 error = EINVAL; 2204 goto fail2; 2205 } 2206 2207 fw = (const char *)data + sizeof (struct iwi_firmware_hdr); 2208 if ((error = iwi_load_firmware(sc, fw, letoh32(hdr->bootsz))) != 0) { 2209 printf("%s: could not load boot firmware\n", 2210 sc->sc_dev.dv_xname); 2211 goto fail2; 2212 } 2213 2214 fw = (const char *)data + sizeof (struct iwi_firmware_hdr) + 2215 letoh32(hdr->bootsz); 2216 if ((error = iwi_load_ucode(sc, fw, letoh32(hdr->ucodesz))) != 0) { 2217 printf("%s: could not load microcode\n", sc->sc_dev.dv_xname); 2218 goto fail2; 2219 } 2220 2221 iwi_stop_master(sc); 2222 2223 CSR_WRITE_4(sc, IWI_CSR_CMD_BASE, sc->cmdq.map->dm_segs[0].ds_addr); 2224 CSR_WRITE_4(sc, IWI_CSR_CMD_SIZE, IWI_CMD_RING_COUNT); 2225 CSR_WRITE_4(sc, IWI_CSR_CMD_WIDX, sc->cmdq.cur); 2226 2227 for (ac = 0; ac < EDCA_NUM_AC; ac++) { 2228 CSR_WRITE_4(sc, IWI_CSR_TX_BASE(ac), 2229 sc->txq[ac].map->dm_segs[0].ds_addr); 2230 CSR_WRITE_4(sc, IWI_CSR_TX_SIZE(ac), IWI_TX_RING_COUNT); 2231 CSR_WRITE_4(sc, IWI_CSR_TX_WIDX(ac), sc->txq[ac].cur); 2232 } 2233 2234 for (i = 0; i < IWI_RX_RING_COUNT; i++) { 2235 struct iwi_rx_data *data = &sc->rxq.data[i]; 2236 CSR_WRITE_4(sc, data->reg, data->map->dm_segs[0].ds_addr); 2237 } 2238 2239 CSR_WRITE_4(sc, IWI_CSR_RX_WIDX, IWI_RX_RING_COUNT - 1); 2240 2241 fw = (const char *)data + sizeof (struct iwi_firmware_hdr) + 2242 letoh32(hdr->bootsz) + letoh32(hdr->ucodesz); 2243 if ((error = iwi_load_firmware(sc, fw, letoh32(hdr->mainsz))) != 0) { 2244 printf("%s: could not load main firmware\n", 2245 sc->sc_dev.dv_xname); 2246 goto fail2; 2247 } 2248 2249 free(data, M_DEVBUF, size); 2250 2251 if ((error = iwi_config(sc)) != 0) { 2252 printf("%s: device configuration failed\n", 2253 sc->sc_dev.dv_xname); 2254 goto fail1; 2255 } 2256 2257 ifq_clr_oactive(&ifp->if_snd); 2258 ifp->if_flags |= IFF_RUNNING; 2259 2260 if (ic->ic_opmode != IEEE80211_M_MONITOR) 2261 ieee80211_begin_scan(ifp); 2262 else 2263 ieee80211_new_state(ic, IEEE80211_S_RUN, -1); 2264 2265 return 0; 2266 2267 fail2: free(data, M_DEVBUF, size); 2268 fail1: iwi_stop(ifp, 0); 2269 return error; 2270 } 2271 2272 void 2273 iwi_stop(struct ifnet *ifp, int disable) 2274 { 2275 struct iwi_softc *sc = ifp->if_softc; 2276 struct ieee80211com *ic = &sc->sc_ic; 2277 int ac; 2278 2279 sc->sc_tx_timer = 0; 2280 ifp->if_timer = 0; 2281 ifp->if_flags &= ~IFF_RUNNING; 2282 ifq_clr_oactive(&ifp->if_snd); 2283 2284 ieee80211_new_state(ic, IEEE80211_S_INIT, -1); 2285 2286 iwi_stop_master(sc); 2287 2288 CSR_WRITE_4(sc, IWI_CSR_RST, IWI_RST_SW_RESET); 2289 2290 /* reset rings */ 2291 iwi_reset_cmd_ring(sc, &sc->cmdq); 2292 for (ac = 0; ac < EDCA_NUM_AC; ac++) 2293 iwi_reset_tx_ring(sc, &sc->txq[ac]); 2294 iwi_reset_rx_ring(sc, &sc->rxq); 2295 } 2296 2297 struct cfdriver iwi_cd = { 2298 NULL, "iwi", DV_IFNET 2299 }; 2300