Merge git://git.kernel.org/pub/scm/linux/kernel/git/steve/gfs2-3.0-fixes
[deliverable/linux.git] / drivers / net / wireless / prism54 / islpci_mgt.c
CommitLineData
1da177e4 1/*
1da177e4
LT
2 * Copyright (C) 2002 Intersil Americas Inc.
3 * Copyright 2004 Jens Maurer <Jens.Maurer@gmx.net>
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation; either version 2 of the License
8 *
9 * This program is distributed in the hope that it will be useful,
10 * but WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 * GNU General Public License for more details.
13 *
14 * You should have received a copy of the GNU General Public License
15 * along with this program; if not, write to the Free Software
16 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
17 *
18 */
19
1da177e4
LT
20#include <linux/netdevice.h>
21#include <linux/module.h>
22#include <linux/pci.h>
d43c36dc 23#include <linux/sched.h>
5a0e3ad6 24#include <linux/slab.h>
1da177e4
LT
25
26#include <asm/io.h>
1da177e4
LT
27#include <linux/if_arp.h>
28
29#include "prismcompat.h"
30#include "isl_38xx.h"
31#include "islpci_mgt.h"
32#include "isl_oid.h" /* additional types and defs for isl38xx fw */
33#include "isl_ioctl.h"
34
35#include <net/iw_handler.h>
36
37/******************************************************************************
38 Global variable definition section
39******************************************************************************/
40int pc_debug = VERBOSE;
41module_param(pc_debug, int, 0);
42
43/******************************************************************************
44 Driver general functions
45******************************************************************************/
46#if VERBOSE > SHOW_ERROR_MESSAGES
47void
48display_buffer(char *buffer, int length)
49{
50 if ((pc_debug & SHOW_BUFFER_CONTENTS) == 0)
51 return;
52
53 while (length > 0) {
54 printk("[%02x]", *buffer & 255);
55 length--;
56 buffer++;
57 }
58
59 printk("\n");
60}
61#endif
62
63/*****************************************************************************
64 Queue handling for management frames
65******************************************************************************/
66
67/*
68 * Helper function to create a PIMFOR management frame header.
69 */
70static void
71pimfor_encode_header(int operation, u32 oid, u32 length, pimfor_header_t *h)
72{
73 h->version = PIMFOR_VERSION;
74 h->operation = operation;
75 h->device_id = PIMFOR_DEV_ID_MHLI_MIB;
76 h->flags = 0;
77 h->oid = cpu_to_be32(oid);
78 h->length = cpu_to_be32(length);
79}
80
81/*
82 * Helper function to analyze a PIMFOR management frame header.
83 */
84static pimfor_header_t *
85pimfor_decode_header(void *data, int len)
86{
87 pimfor_header_t *h = data;
88
89 while ((void *) h < data + len) {
90 if (h->flags & PIMFOR_FLAG_LITTLE_ENDIAN) {
91 le32_to_cpus(&h->oid);
92 le32_to_cpus(&h->length);
93 } else {
94 be32_to_cpus(&h->oid);
95 be32_to_cpus(&h->length);
96 }
97 if (h->oid != OID_INL_TUNNEL)
98 return h;
99 h++;
100 }
101 return NULL;
102}
103
104/*
105 * Fill the receive queue for management frames with fresh buffers.
106 */
107int
108islpci_mgmt_rx_fill(struct net_device *ndev)
109{
110 islpci_private *priv = netdev_priv(ndev);
111 isl38xx_control_block *cb = /* volatile not needed */
112 (isl38xx_control_block *) priv->control_block;
113 u32 curr = le32_to_cpu(cb->driver_curr_frag[ISL38XX_CB_RX_MGMTQ]);
114
115#if VERBOSE > SHOW_ERROR_MESSAGES
4a89852c 116 DEBUG(SHOW_FUNCTION_CALLS, "islpci_mgmt_rx_fill\n");
1da177e4
LT
117#endif
118
119 while (curr - priv->index_mgmt_rx < ISL38XX_CB_MGMT_QSIZE) {
120 u32 index = curr % ISL38XX_CB_MGMT_QSIZE;
121 struct islpci_membuf *buf = &priv->mgmt_rx[index];
122 isl38xx_fragment *frag = &cb->rx_data_mgmt[index];
123
124 if (buf->mem == NULL) {
125 buf->mem = kmalloc(MGMT_FRAME_SIZE, GFP_ATOMIC);
126 if (!buf->mem) {
127 printk(KERN_WARNING
128 "Error allocating management frame.\n");
129 return -ENOMEM;
130 }
131 buf->size = MGMT_FRAME_SIZE;
132 }
133 if (buf->pci_addr == 0) {
134 buf->pci_addr = pci_map_single(priv->pdev, buf->mem,
135 MGMT_FRAME_SIZE,
136 PCI_DMA_FROMDEVICE);
137 if (!buf->pci_addr) {
138 printk(KERN_WARNING
3fa63c7d 139 "Failed to make memory DMA'able.\n");
1da177e4
LT
140 return -ENOMEM;
141 }
142 }
143
144 /* be safe: always reset control block information */
145 frag->size = cpu_to_le16(MGMT_FRAME_SIZE);
146 frag->flags = 0;
147 frag->address = cpu_to_le32(buf->pci_addr);
148 curr++;
149
150 /* The fragment address in the control block must have
151 * been written before announcing the frame buffer to
152 * device */
153 wmb();
154 cb->driver_curr_frag[ISL38XX_CB_RX_MGMTQ] = cpu_to_le32(curr);
155 }
156 return 0;
157}
158
159/*
160 * Create and transmit a management frame using "operation" and "oid",
161 * with arguments data/length.
162 * We either return an error and free the frame, or we return 0 and
163 * islpci_mgt_cleanup_transmit() frees the frame in the tx-done
164 * interrupt.
165 */
166static int
167islpci_mgt_transmit(struct net_device *ndev, int operation, unsigned long oid,
168 void *data, int length)
169{
170 islpci_private *priv = netdev_priv(ndev);
171 isl38xx_control_block *cb =
172 (isl38xx_control_block *) priv->control_block;
173 void *p;
174 int err = -EINVAL;
175 unsigned long flags;
176 isl38xx_fragment *frag;
177 struct islpci_membuf buf;
178 u32 curr_frag;
179 int index;
180 int frag_len = length + PIMFOR_HEADER_SIZE;
181
182#if VERBOSE > SHOW_ERROR_MESSAGES
183 DEBUG(SHOW_FUNCTION_CALLS, "islpci_mgt_transmit\n");
184#endif
185
186 if (frag_len > MGMT_FRAME_SIZE) {
187 printk(KERN_DEBUG "%s: mgmt frame too large %d\n",
188 ndev->name, frag_len);
189 goto error;
190 }
191
192 err = -ENOMEM;
193 p = buf.mem = kmalloc(frag_len, GFP_KERNEL);
e404decb 194 if (!buf.mem)
1da177e4 195 goto error;
e404decb 196
1da177e4
LT
197 buf.size = frag_len;
198
199 /* create the header directly in the fragment data area */
200 pimfor_encode_header(operation, oid, length, (pimfor_header_t *) p);
201 p += PIMFOR_HEADER_SIZE;
202
203 if (data)
204 memcpy(p, data, length);
205 else
206 memset(p, 0, length);
207
208#if VERBOSE > SHOW_ERROR_MESSAGES
209 {
210 pimfor_header_t *h = buf.mem;
211 DEBUG(SHOW_PIMFOR_FRAMES,
4a89852c 212 "PIMFOR: op %i, oid 0x%08lx, device %i, flags 0x%x length 0x%x\n",
1da177e4
LT
213 h->operation, oid, h->device_id, h->flags, length);
214
215 /* display the buffer contents for debugging */
216 display_buffer((char *) h, sizeof (pimfor_header_t));
217 display_buffer(p, length);
218 }
219#endif
220
221 err = -ENOMEM;
222 buf.pci_addr = pci_map_single(priv->pdev, buf.mem, frag_len,
223 PCI_DMA_TODEVICE);
224 if (!buf.pci_addr) {
225 printk(KERN_WARNING "%s: cannot map PCI memory for mgmt\n",
226 ndev->name);
227 goto error_free;
228 }
229
230 /* Protect the control block modifications against interrupts. */
231 spin_lock_irqsave(&priv->slock, flags);
232 curr_frag = le32_to_cpu(cb->driver_curr_frag[ISL38XX_CB_TX_MGMTQ]);
233 if (curr_frag - priv->index_mgmt_tx >= ISL38XX_CB_MGMT_QSIZE) {
234 printk(KERN_WARNING "%s: mgmt tx queue is still full\n",
235 ndev->name);
236 goto error_unlock;
237 }
238
239 /* commit the frame to the tx device queue */
240 index = curr_frag % ISL38XX_CB_MGMT_QSIZE;
241 priv->mgmt_tx[index] = buf;
242 frag = &cb->tx_data_mgmt[index];
243 frag->size = cpu_to_le16(frag_len);
244 frag->flags = 0; /* for any other than the last fragment, set to 1 */
245 frag->address = cpu_to_le32(buf.pci_addr);
246
247 /* The fragment address in the control block must have
248 * been written before announcing the frame buffer to
249 * device */
250 wmb();
251 cb->driver_curr_frag[ISL38XX_CB_TX_MGMTQ] = cpu_to_le32(curr_frag + 1);
252 spin_unlock_irqrestore(&priv->slock, flags);
253
254 /* trigger the device */
255 islpci_trigger(priv);
256 return 0;
257
258 error_unlock:
259 spin_unlock_irqrestore(&priv->slock, flags);
260 error_free:
261 kfree(buf.mem);
262 error:
263 return err;
264}
265
266/*
267 * Receive a management frame from the device.
268 * This can be an arbitrary number of traps, and at most one response
269 * frame for a previous request sent via islpci_mgt_transmit().
270 */
271int
272islpci_mgt_receive(struct net_device *ndev)
273{
274 islpci_private *priv = netdev_priv(ndev);
275 isl38xx_control_block *cb =
276 (isl38xx_control_block *) priv->control_block;
277 u32 curr_frag;
278
279#if VERBOSE > SHOW_ERROR_MESSAGES
4a89852c 280 DEBUG(SHOW_FUNCTION_CALLS, "islpci_mgt_receive\n");
1da177e4
LT
281#endif
282
283 /* Only once per interrupt, determine fragment range to
284 * process. This avoids an endless loop (i.e. lockup) if
285 * frames come in faster than we can process them. */
286 curr_frag = le32_to_cpu(cb->device_curr_frag[ISL38XX_CB_RX_MGMTQ]);
287 barrier();
288
289 for (; priv->index_mgmt_rx < curr_frag; priv->index_mgmt_rx++) {
290 pimfor_header_t *header;
291 u32 index = priv->index_mgmt_rx % ISL38XX_CB_MGMT_QSIZE;
292 struct islpci_membuf *buf = &priv->mgmt_rx[index];
293 u16 frag_len;
294 int size;
295 struct islpci_mgmtframe *frame;
296
297 /* I have no idea (and no documentation) if flags != 0
298 * is possible. Drop the frame, reuse the buffer. */
299 if (le16_to_cpu(cb->rx_data_mgmt[index].flags) != 0) {
300 printk(KERN_WARNING "%s: unknown flags 0x%04x\n",
301 ndev->name,
302 le16_to_cpu(cb->rx_data_mgmt[index].flags));
303 continue;
304 }
305
306 /* The device only returns the size of the header(s) here. */
307 frag_len = le16_to_cpu(cb->rx_data_mgmt[index].size);
308
309 /*
310 * We appear to have no way to tell the device the
311 * size of a receive buffer. Thus, if this check
312 * triggers, we likely have kernel heap corruption. */
313 if (frag_len > MGMT_FRAME_SIZE) {
314 printk(KERN_WARNING
315 "%s: Bogus packet size of %d (%#x).\n",
316 ndev->name, frag_len, frag_len);
317 frag_len = MGMT_FRAME_SIZE;
318 }
319
320 /* Ensure the results of device DMA are visible to the CPU. */
321 pci_dma_sync_single_for_cpu(priv->pdev, buf->pci_addr,
322 buf->size, PCI_DMA_FROMDEVICE);
323
324 /* Perform endianess conversion for PIMFOR header in-place. */
325 header = pimfor_decode_header(buf->mem, frag_len);
326 if (!header) {
327 printk(KERN_WARNING "%s: no PIMFOR header found\n",
328 ndev->name);
329 continue;
330 }
331
332 /* The device ID from the PIMFOR packet received from
333 * the MVC is always 0. We forward a sensible device_id.
334 * Not that anyone upstream would care... */
335 header->device_id = priv->ndev->ifindex;
336
337#if VERBOSE > SHOW_ERROR_MESSAGES
338 DEBUG(SHOW_PIMFOR_FRAMES,
4a89852c 339 "PIMFOR: op %i, oid 0x%08x, device %i, flags 0x%x length 0x%x\n",
1da177e4
LT
340 header->operation, header->oid, header->device_id,
341 header->flags, header->length);
342
343 /* display the buffer contents for debugging */
344 display_buffer((char *) header, PIMFOR_HEADER_SIZE);
345 display_buffer((char *) header + PIMFOR_HEADER_SIZE,
346 header->length);
347#endif
348
349 /* nobody sends these */
350 if (header->flags & PIMFOR_FLAG_APPLIC_ORIGIN) {
351 printk(KERN_DEBUG
352 "%s: errant PIMFOR application frame\n",
353 ndev->name);
354 continue;
355 }
356
357 /* Determine frame size, skipping OID_INL_TUNNEL headers. */
358 size = PIMFOR_HEADER_SIZE + header->length;
359 frame = kmalloc(sizeof (struct islpci_mgmtframe) + size,
360 GFP_ATOMIC);
361 if (!frame) {
362 printk(KERN_WARNING
363 "%s: Out of memory, cannot handle oid 0x%08x\n",
364 ndev->name, header->oid);
365 continue;
366 }
367 frame->ndev = ndev;
368 memcpy(&frame->buf, header, size);
369 frame->header = (pimfor_header_t *) frame->buf;
370 frame->data = frame->buf + PIMFOR_HEADER_SIZE;
371
372#if VERBOSE > SHOW_ERROR_MESSAGES
373 DEBUG(SHOW_PIMFOR_FRAMES,
374 "frame: header: %p, data: %p, size: %d\n",
375 frame->header, frame->data, size);
376#endif
377
378 if (header->operation == PIMFOR_OP_TRAP) {
379#if VERBOSE > SHOW_ERROR_MESSAGES
380 printk(KERN_DEBUG
381 "TRAP: oid 0x%x, device %i, flags 0x%x length %i\n",
382 header->oid, header->device_id, header->flags,
383 header->length);
384#endif
385
386 /* Create work to handle trap out of interrupt
387 * context. */
c4028958 388 INIT_WORK(&frame->ws, prism54_process_trap);
1da177e4
LT
389 schedule_work(&frame->ws);
390
391 } else {
392 /* Signal the one waiting process that a response
393 * has been received. */
394 if ((frame = xchg(&priv->mgmt_received, frame)) != NULL) {
395 printk(KERN_WARNING
396 "%s: mgmt response not collected\n",
397 ndev->name);
398 kfree(frame);
399 }
400#if VERBOSE > SHOW_ERROR_MESSAGES
401 DEBUG(SHOW_TRACING, "Wake up Mgmt Queue\n");
402#endif
403 wake_up(&priv->mgmt_wqueue);
404 }
405
406 }
407
408 return 0;
409}
410
411/*
412 * Cleanup the transmit queue by freeing all frames handled by the device.
413 */
414void
415islpci_mgt_cleanup_transmit(struct net_device *ndev)
416{
417 islpci_private *priv = netdev_priv(ndev);
418 isl38xx_control_block *cb = /* volatile not needed */
419 (isl38xx_control_block *) priv->control_block;
420 u32 curr_frag;
421
422#if VERBOSE > SHOW_ERROR_MESSAGES
423 DEBUG(SHOW_FUNCTION_CALLS, "islpci_mgt_cleanup_transmit\n");
424#endif
425
426 /* Only once per cleanup, determine fragment range to
427 * process. This avoids an endless loop (i.e. lockup) if
428 * the device became confused, incrementing device_curr_frag
429 * rapidly. */
430 curr_frag = le32_to_cpu(cb->device_curr_frag[ISL38XX_CB_TX_MGMTQ]);
431 barrier();
432
433 for (; priv->index_mgmt_tx < curr_frag; priv->index_mgmt_tx++) {
434 int index = priv->index_mgmt_tx % ISL38XX_CB_MGMT_QSIZE;
435 struct islpci_membuf *buf = &priv->mgmt_tx[index];
436 pci_unmap_single(priv->pdev, buf->pci_addr, buf->size,
437 PCI_DMA_TODEVICE);
438 buf->pci_addr = 0;
439 kfree(buf->mem);
440 buf->mem = NULL;
441 buf->size = 0;
442 }
443}
444
445/*
446 * Perform one request-response transaction to the device.
447 */
448int
449islpci_mgt_transaction(struct net_device *ndev,
450 int operation, unsigned long oid,
451 void *senddata, int sendlen,
452 struct islpci_mgmtframe **recvframe)
453{
454 islpci_private *priv = netdev_priv(ndev);
3173c890 455 const long wait_cycle_jiffies = msecs_to_jiffies(ISL38XX_WAIT_CYCLE * 10);
1da177e4
LT
456 long timeout_left = ISL38XX_MAX_WAIT_CYCLES * wait_cycle_jiffies;
457 int err;
458 DEFINE_WAIT(wait);
459
460 *recvframe = NULL;
461
1b34fd39 462 if (mutex_lock_interruptible(&priv->mgmt_lock))
1da177e4
LT
463 return -ERESTARTSYS;
464
465 prepare_to_wait(&priv->mgmt_wqueue, &wait, TASK_UNINTERRUPTIBLE);
466 err = islpci_mgt_transmit(ndev, operation, oid, senddata, sendlen);
467 if (err)
468 goto out;
469
470 err = -ETIMEDOUT;
471 while (timeout_left > 0) {
472 int timeleft;
473 struct islpci_mgmtframe *frame;
474
3173c890 475 timeleft = schedule_timeout_uninterruptible(wait_cycle_jiffies);
1da177e4
LT
476 frame = xchg(&priv->mgmt_received, NULL);
477 if (frame) {
478 if (frame->header->oid == oid) {
479 *recvframe = frame;
480 err = 0;
481 goto out;
482 } else {
483 printk(KERN_DEBUG
484 "%s: expecting oid 0x%x, received 0x%x.\n",
485 ndev->name, (unsigned int) oid,
486 frame->header->oid);
487 kfree(frame);
488 frame = NULL;
489 }
490 }
491 if (timeleft == 0) {
492 printk(KERN_DEBUG
493 "%s: timeout waiting for mgmt response %lu, "
494 "triggering device\n",
495 ndev->name, timeout_left);
496 islpci_trigger(priv);
497 }
498 timeout_left += timeleft - wait_cycle_jiffies;
499 }
500 printk(KERN_WARNING "%s: timeout waiting for mgmt response\n",
501 ndev->name);
502
93b2dd12 503 /* TODO: we should reset the device here */
1da177e4
LT
504 out:
505 finish_wait(&priv->mgmt_wqueue, &wait);
1b34fd39 506 mutex_unlock(&priv->mgmt_lock);
1da177e4
LT
507 return err;
508}
509
This page took 0.855998 seconds and 5 git commands to generate.