orinoco_usb.c 45 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762
  1. /*
  2. * USB Orinoco driver
  3. *
  4. * Copyright (c) 2003 Manuel Estrada Sainz
  5. *
  6. * The contents of this file are subject to the Mozilla Public License
  7. * Version 1.1 (the "License"); you may not use this file except in
  8. * compliance with the License. You may obtain a copy of the License
  9. * at http://www.mozilla.org/MPL/
  10. *
  11. * Software distributed under the License is distributed on an "AS IS"
  12. * basis, WITHOUT WARRANTY OF ANY KIND, either express or implied. See
  13. * the License for the specific language governing rights and
  14. * limitations under the License.
  15. *
  16. * Alternatively, the contents of this file may be used under the
  17. * terms of the GNU General Public License version 2 (the "GPL"), in
  18. * which case the provisions of the GPL are applicable instead of the
  19. * above. If you wish to allow the use of your version of this file
  20. * only under the terms of the GPL and not to allow others to use your
  21. * version of this file under the MPL, indicate your decision by
  22. * deleting the provisions above and replace them with the notice and
  23. * other provisions required by the GPL. If you do not delete the
  24. * provisions above, a recipient may use your version of this file
  25. * under either the MPL or the GPL.
  26. *
  27. * Queueing code based on linux-wlan-ng 0.2.1-pre5
  28. *
  29. * Copyright (C) 1999 AbsoluteValue Systems, Inc. All Rights Reserved.
  30. *
  31. * The license is the same as above.
  32. *
  33. * Initialy based on USB Skeleton driver - 0.7
  34. *
  35. * Copyright (c) 2001 Greg Kroah-Hartman (greg@kroah.com)
  36. *
  37. * This program is free software; you can redistribute it and/or
  38. * modify it under the terms of the GNU General Public License as
  39. * published by the Free Software Foundation; either version 2 of
  40. * the License, or (at your option) any later version.
  41. *
  42. * NOTE: The original USB Skeleton driver is GPL, but all that code is
  43. * gone so MPL/GPL applies.
  44. */
  45. #define DRIVER_NAME "orinoco_usb"
  46. #define PFX DRIVER_NAME ": "
  47. #include <linux/module.h>
  48. #include <linux/kernel.h>
  49. #include <linux/sched.h>
  50. #include <linux/signal.h>
  51. #include <linux/errno.h>
  52. #include <linux/poll.h>
  53. #include <linux/init.h>
  54. #include <linux/slab.h>
  55. #include <linux/fcntl.h>
  56. #include <linux/spinlock.h>
  57. #include <linux/list.h>
  58. #include <linux/usb.h>
  59. #include <linux/timer.h>
  60. #include <linux/netdevice.h>
  61. #include <linux/if_arp.h>
  62. #include <linux/etherdevice.h>
  63. #include <linux/wireless.h>
  64. #include <linux/firmware.h>
  65. #include "mic.h"
  66. #include "orinoco.h"
  67. #ifndef URB_ASYNC_UNLINK
  68. #define URB_ASYNC_UNLINK 0
  69. #endif
  70. /* 802.2 LLC/SNAP header used for Ethernet encapsulation over 802.11 */
  71. static const u8 encaps_hdr[] = {0xaa, 0xaa, 0x03, 0x00, 0x00, 0x00};
  72. #define ENCAPS_OVERHEAD (sizeof(encaps_hdr) + 2)
  73. struct header_struct {
  74. /* 802.3 */
  75. u8 dest[ETH_ALEN];
  76. u8 src[ETH_ALEN];
  77. __be16 len;
  78. /* 802.2 */
  79. u8 dsap;
  80. u8 ssap;
  81. u8 ctrl;
  82. /* SNAP */
  83. u8 oui[3];
  84. __be16 ethertype;
  85. } __packed;
  86. struct ez_usb_fw {
  87. u16 size;
  88. const u8 *code;
  89. };
  90. static struct ez_usb_fw firmware = {
  91. .size = 0,
  92. .code = NULL,
  93. };
  94. #ifdef CONFIG_USB_DEBUG
  95. static int debug = 1;
  96. #else
  97. static int debug;
  98. #endif
  99. /* Debugging macros */
  100. #undef dbg
  101. #define dbg(format, arg...) \
  102. do { if (debug) printk(KERN_DEBUG PFX "%s: " format "\n", \
  103. __func__ , ## arg); } while (0)
  104. #undef err
  105. #define err(format, arg...) \
  106. do { printk(KERN_ERR PFX format "\n", ## arg); } while (0)
  107. /* Module paramaters */
  108. module_param(debug, int, 0644);
  109. MODULE_PARM_DESC(debug, "Debug enabled or not");
  110. MODULE_FIRMWARE("orinoco_ezusb_fw");
  111. /*
  112. * Under some conditions, the card gets stuck and stops paying attention
  113. * to the world (i.e. data communication stalls) until we do something to
  114. * it. Sending an INQ_TALLIES command seems to be enough and should be
  115. * harmless otherwise. This behaviour has been observed when using the
  116. * driver on a systemimager client during installation. In the past a
  117. * timer was used to send INQ_TALLIES commands when there was no other
  118. * activity, but it was troublesome and was removed.
  119. */
  120. #define USB_COMPAQ_VENDOR_ID 0x049f /* Compaq Computer Corp. */
  121. #define USB_COMPAQ_WL215_ID 0x001f /* Compaq WL215 USB Adapter */
  122. #define USB_COMPAQ_W200_ID 0x0076 /* Compaq W200 USB Adapter */
  123. #define USB_HP_WL215_ID 0x0082 /* Compaq WL215 USB Adapter */
  124. #define USB_MELCO_VENDOR_ID 0x0411
  125. #define USB_BUFFALO_L11_ID 0x0006 /* BUFFALO WLI-USB-L11 */
  126. #define USB_BUFFALO_L11G_WR_ID 0x000B /* BUFFALO WLI-USB-L11G-WR */
  127. #define USB_BUFFALO_L11G_ID 0x000D /* BUFFALO WLI-USB-L11G */
  128. #define USB_LUCENT_VENDOR_ID 0x047E /* Lucent Technologies */
  129. #define USB_LUCENT_ORINOCO_ID 0x0300 /* Lucent/Agere Orinoco USB Client */
  130. #define USB_AVAYA8_VENDOR_ID 0x0D98
  131. #define USB_AVAYAE_VENDOR_ID 0x0D9E
  132. #define USB_AVAYA_WIRELESS_ID 0x0300 /* Avaya Wireless USB Card */
  133. #define USB_AGERE_VENDOR_ID 0x0D4E /* Agere Systems */
  134. #define USB_AGERE_MODEL0801_ID 0x1000 /* Wireless USB Card Model 0801 */
  135. #define USB_AGERE_MODEL0802_ID 0x1001 /* Wireless USB Card Model 0802 */
  136. #define USB_AGERE_REBRANDED_ID 0x047A /* WLAN USB Card */
  137. #define USB_ELSA_VENDOR_ID 0x05CC
  138. #define USB_ELSA_AIRLANCER_ID 0x3100 /* ELSA AirLancer USB-11 */
  139. #define USB_LEGEND_VENDOR_ID 0x0E7C
  140. #define USB_LEGEND_JOYNET_ID 0x0300 /* Joynet WLAN USB Card */
  141. #define USB_SAMSUNG_VENDOR_ID 0x04E8
  142. #define USB_SAMSUNG_SEW2001U1_ID 0x5002 /* Samsung SEW-2001u Card */
  143. #define USB_SAMSUNG_SEW2001U2_ID 0x5B11 /* Samsung SEW-2001u Card */
  144. #define USB_SAMSUNG_SEW2003U_ID 0x7011 /* Samsung SEW-2003U Card */
  145. #define USB_IGATE_VENDOR_ID 0x0681
  146. #define USB_IGATE_IGATE_11M_ID 0x0012 /* I-GATE 11M USB Card */
  147. #define USB_FUJITSU_VENDOR_ID 0x0BF8
  148. #define USB_FUJITSU_E1100_ID 0x1002 /* connect2AIR WLAN E-1100 USB */
  149. #define USB_2WIRE_VENDOR_ID 0x1630
  150. #define USB_2WIRE_WIRELESS_ID 0xff81 /* 2Wire Wireless USB adapter */
  151. #define EZUSB_REQUEST_FW_TRANS 0xA0
  152. #define EZUSB_REQUEST_TRIGER 0xAA
  153. #define EZUSB_REQUEST_TRIG_AC 0xAC
  154. #define EZUSB_CPUCS_REG 0x7F92
  155. #define EZUSB_RID_TX 0x0700
  156. #define EZUSB_RID_RX 0x0701
  157. #define EZUSB_RID_INIT1 0x0702
  158. #define EZUSB_RID_ACK 0x0710
  159. #define EZUSB_RID_READ_PDA 0x0800
  160. #define EZUSB_RID_PROG_INIT 0x0852
  161. #define EZUSB_RID_PROG_SET_ADDR 0x0853
  162. #define EZUSB_RID_PROG_BYTES 0x0854
  163. #define EZUSB_RID_PROG_END 0x0855
  164. #define EZUSB_RID_DOCMD 0x0860
  165. /* Recognize info frames */
  166. #define EZUSB_IS_INFO(id) ((id >= 0xF000) && (id <= 0xF2FF))
  167. #define EZUSB_MAGIC 0x0210
  168. #define EZUSB_FRAME_DATA 1
  169. #define EZUSB_FRAME_CONTROL 2
  170. #define DEF_TIMEOUT (3 * HZ)
  171. #define BULK_BUF_SIZE 2048
  172. #define MAX_DL_SIZE (BULK_BUF_SIZE - sizeof(struct ezusb_packet))
  173. #define FW_BUF_SIZE 64
  174. #define FW_VAR_OFFSET_PTR 0x359
  175. #define FW_VAR_VALUE 0
  176. #define FW_HOLE_START 0x100
  177. #define FW_HOLE_END 0x300
  178. struct ezusb_packet {
  179. __le16 magic; /* 0x0210 */
  180. u8 req_reply_count;
  181. u8 ans_reply_count;
  182. __le16 frame_type; /* 0x01 for data frames, 0x02 otherwise */
  183. __le16 size; /* transport size */
  184. __le16 crc; /* CRC up to here */
  185. __le16 hermes_len;
  186. __le16 hermes_rid;
  187. u8 data[0];
  188. } __packed;
  189. /* Table of devices that work or may work with this driver */
  190. static struct usb_device_id ezusb_table[] = {
  191. {USB_DEVICE(USB_COMPAQ_VENDOR_ID, USB_COMPAQ_WL215_ID)},
  192. {USB_DEVICE(USB_COMPAQ_VENDOR_ID, USB_HP_WL215_ID)},
  193. {USB_DEVICE(USB_COMPAQ_VENDOR_ID, USB_COMPAQ_W200_ID)},
  194. {USB_DEVICE(USB_MELCO_VENDOR_ID, USB_BUFFALO_L11_ID)},
  195. {USB_DEVICE(USB_MELCO_VENDOR_ID, USB_BUFFALO_L11G_WR_ID)},
  196. {USB_DEVICE(USB_MELCO_VENDOR_ID, USB_BUFFALO_L11G_ID)},
  197. {USB_DEVICE(USB_LUCENT_VENDOR_ID, USB_LUCENT_ORINOCO_ID)},
  198. {USB_DEVICE(USB_AVAYA8_VENDOR_ID, USB_AVAYA_WIRELESS_ID)},
  199. {USB_DEVICE(USB_AVAYAE_VENDOR_ID, USB_AVAYA_WIRELESS_ID)},
  200. {USB_DEVICE(USB_AGERE_VENDOR_ID, USB_AGERE_MODEL0801_ID)},
  201. {USB_DEVICE(USB_AGERE_VENDOR_ID, USB_AGERE_MODEL0802_ID)},
  202. {USB_DEVICE(USB_ELSA_VENDOR_ID, USB_ELSA_AIRLANCER_ID)},
  203. {USB_DEVICE(USB_LEGEND_VENDOR_ID, USB_LEGEND_JOYNET_ID)},
  204. {USB_DEVICE_VER(USB_SAMSUNG_VENDOR_ID, USB_SAMSUNG_SEW2001U1_ID,
  205. 0, 0)},
  206. {USB_DEVICE(USB_SAMSUNG_VENDOR_ID, USB_SAMSUNG_SEW2001U2_ID)},
  207. {USB_DEVICE(USB_SAMSUNG_VENDOR_ID, USB_SAMSUNG_SEW2003U_ID)},
  208. {USB_DEVICE(USB_IGATE_VENDOR_ID, USB_IGATE_IGATE_11M_ID)},
  209. {USB_DEVICE(USB_FUJITSU_VENDOR_ID, USB_FUJITSU_E1100_ID)},
  210. {USB_DEVICE(USB_2WIRE_VENDOR_ID, USB_2WIRE_WIRELESS_ID)},
  211. {USB_DEVICE(USB_AGERE_VENDOR_ID, USB_AGERE_REBRANDED_ID)},
  212. {} /* Terminating entry */
  213. };
  214. MODULE_DEVICE_TABLE(usb, ezusb_table);
  215. /* Structure to hold all of our device specific stuff */
  216. struct ezusb_priv {
  217. struct usb_device *udev;
  218. struct net_device *dev;
  219. struct mutex mtx;
  220. spinlock_t req_lock;
  221. struct list_head req_pending;
  222. struct list_head req_active;
  223. spinlock_t reply_count_lock;
  224. u16 hermes_reg_fake[0x40];
  225. u8 *bap_buf;
  226. struct urb *read_urb;
  227. int read_pipe;
  228. int write_pipe;
  229. u8 reply_count;
  230. };
  231. enum ezusb_state {
  232. EZUSB_CTX_START,
  233. EZUSB_CTX_QUEUED,
  234. EZUSB_CTX_REQ_SUBMITTED,
  235. EZUSB_CTX_REQ_COMPLETE,
  236. EZUSB_CTX_RESP_RECEIVED,
  237. EZUSB_CTX_REQ_TIMEOUT,
  238. EZUSB_CTX_REQ_FAILED,
  239. EZUSB_CTX_RESP_TIMEOUT,
  240. EZUSB_CTX_REQSUBMIT_FAIL,
  241. EZUSB_CTX_COMPLETE,
  242. };
  243. struct request_context {
  244. struct list_head list;
  245. atomic_t refcount;
  246. struct completion done; /* Signals that CTX is dead */
  247. int killed;
  248. struct urb *outurb; /* OUT for req pkt */
  249. struct ezusb_priv *upriv;
  250. struct ezusb_packet *buf;
  251. int buf_length;
  252. struct timer_list timer; /* Timeout handling */
  253. enum ezusb_state state; /* Current state */
  254. /* the RID that we will wait for */
  255. u16 out_rid;
  256. u16 in_rid;
  257. };
  258. /* Forward declarations */
  259. static void ezusb_ctx_complete(struct request_context *ctx);
  260. static void ezusb_req_queue_run(struct ezusb_priv *upriv);
  261. static void ezusb_bulk_in_callback(struct urb *urb);
  262. static inline u8 ezusb_reply_inc(u8 count)
  263. {
  264. if (count < 0x7F)
  265. return count + 1;
  266. else
  267. return 1;
  268. }
  269. static void ezusb_request_context_put(struct request_context *ctx)
  270. {
  271. if (!atomic_dec_and_test(&ctx->refcount))
  272. return;
  273. WARN_ON(!ctx->done.done);
  274. BUG_ON(ctx->outurb->status == -EINPROGRESS);
  275. BUG_ON(timer_pending(&ctx->timer));
  276. usb_free_urb(ctx->outurb);
  277. kfree(ctx->buf);
  278. kfree(ctx);
  279. }
  280. static inline void ezusb_mod_timer(struct ezusb_priv *upriv,
  281. struct timer_list *timer,
  282. unsigned long expire)
  283. {
  284. if (!upriv->udev)
  285. return;
  286. mod_timer(timer, expire);
  287. }
  288. static void ezusb_request_timerfn(u_long _ctx)
  289. {
  290. struct request_context *ctx = (void *) _ctx;
  291. ctx->outurb->transfer_flags |= URB_ASYNC_UNLINK;
  292. if (usb_unlink_urb(ctx->outurb) == -EINPROGRESS) {
  293. ctx->state = EZUSB_CTX_REQ_TIMEOUT;
  294. } else {
  295. ctx->state = EZUSB_CTX_RESP_TIMEOUT;
  296. dbg("couldn't unlink");
  297. atomic_inc(&ctx->refcount);
  298. ctx->killed = 1;
  299. ezusb_ctx_complete(ctx);
  300. ezusb_request_context_put(ctx);
  301. }
  302. };
  303. static struct request_context *ezusb_alloc_ctx(struct ezusb_priv *upriv,
  304. u16 out_rid, u16 in_rid)
  305. {
  306. struct request_context *ctx;
  307. ctx = kzalloc(sizeof(*ctx), GFP_ATOMIC);
  308. if (!ctx)
  309. return NULL;
  310. ctx->buf = kmalloc(BULK_BUF_SIZE, GFP_ATOMIC);
  311. if (!ctx->buf) {
  312. kfree(ctx);
  313. return NULL;
  314. }
  315. ctx->outurb = usb_alloc_urb(0, GFP_ATOMIC);
  316. if (!ctx->outurb) {
  317. kfree(ctx->buf);
  318. kfree(ctx);
  319. return NULL;
  320. }
  321. ctx->upriv = upriv;
  322. ctx->state = EZUSB_CTX_START;
  323. ctx->out_rid = out_rid;
  324. ctx->in_rid = in_rid;
  325. atomic_set(&ctx->refcount, 1);
  326. init_completion(&ctx->done);
  327. init_timer(&ctx->timer);
  328. ctx->timer.function = ezusb_request_timerfn;
  329. ctx->timer.data = (u_long) ctx;
  330. return ctx;
  331. }
  332. /* Hopefully the real complete_all will soon be exported, in the mean
  333. * while this should work. */
  334. static inline void ezusb_complete_all(struct completion *comp)
  335. {
  336. complete(comp);
  337. complete(comp);
  338. complete(comp);
  339. complete(comp);
  340. }
  341. static void ezusb_ctx_complete(struct request_context *ctx)
  342. {
  343. struct ezusb_priv *upriv = ctx->upriv;
  344. unsigned long flags;
  345. spin_lock_irqsave(&upriv->req_lock, flags);
  346. list_del_init(&ctx->list);
  347. if (upriv->udev) {
  348. spin_unlock_irqrestore(&upriv->req_lock, flags);
  349. ezusb_req_queue_run(upriv);
  350. spin_lock_irqsave(&upriv->req_lock, flags);
  351. }
  352. switch (ctx->state) {
  353. case EZUSB_CTX_COMPLETE:
  354. case EZUSB_CTX_REQSUBMIT_FAIL:
  355. case EZUSB_CTX_REQ_FAILED:
  356. case EZUSB_CTX_REQ_TIMEOUT:
  357. case EZUSB_CTX_RESP_TIMEOUT:
  358. spin_unlock_irqrestore(&upriv->req_lock, flags);
  359. if ((ctx->out_rid == EZUSB_RID_TX) && upriv->dev) {
  360. struct net_device *dev = upriv->dev;
  361. struct orinoco_private *priv = ndev_priv(dev);
  362. struct net_device_stats *stats = &priv->stats;
  363. if (ctx->state != EZUSB_CTX_COMPLETE)
  364. stats->tx_errors++;
  365. else
  366. stats->tx_packets++;
  367. netif_wake_queue(dev);
  368. }
  369. ezusb_complete_all(&ctx->done);
  370. ezusb_request_context_put(ctx);
  371. break;
  372. default:
  373. spin_unlock_irqrestore(&upriv->req_lock, flags);
  374. if (!upriv->udev) {
  375. /* This is normal, as all request contexts get flushed
  376. * when the device is disconnected */
  377. err("Called, CTX not terminating, but device gone");
  378. ezusb_complete_all(&ctx->done);
  379. ezusb_request_context_put(ctx);
  380. break;
  381. }
  382. err("Called, CTX not in terminating state.");
  383. /* Things are really bad if this happens. Just leak
  384. * the CTX because it may still be linked to the
  385. * queue or the OUT urb may still be active.
  386. * Just leaking at least prevents an Oops or Panic.
  387. */
  388. break;
  389. }
  390. }
  391. /**
  392. * ezusb_req_queue_run:
  393. * Description:
  394. * Note: Only one active CTX at any one time, because there's no
  395. * other (reliable) way to match the response URB to the correct
  396. * CTX.
  397. **/
  398. static void ezusb_req_queue_run(struct ezusb_priv *upriv)
  399. {
  400. unsigned long flags;
  401. struct request_context *ctx;
  402. int result;
  403. spin_lock_irqsave(&upriv->req_lock, flags);
  404. if (!list_empty(&upriv->req_active))
  405. goto unlock;
  406. if (list_empty(&upriv->req_pending))
  407. goto unlock;
  408. ctx =
  409. list_entry(upriv->req_pending.next, struct request_context,
  410. list);
  411. if (!ctx->upriv->udev)
  412. goto unlock;
  413. /* We need to split this off to avoid a race condition */
  414. list_move_tail(&ctx->list, &upriv->req_active);
  415. if (ctx->state == EZUSB_CTX_QUEUED) {
  416. atomic_inc(&ctx->refcount);
  417. result = usb_submit_urb(ctx->outurb, GFP_ATOMIC);
  418. if (result) {
  419. ctx->state = EZUSB_CTX_REQSUBMIT_FAIL;
  420. spin_unlock_irqrestore(&upriv->req_lock, flags);
  421. err("Fatal, failed to submit command urb."
  422. " error=%d\n", result);
  423. ezusb_ctx_complete(ctx);
  424. ezusb_request_context_put(ctx);
  425. goto done;
  426. }
  427. ctx->state = EZUSB_CTX_REQ_SUBMITTED;
  428. ezusb_mod_timer(ctx->upriv, &ctx->timer,
  429. jiffies + DEF_TIMEOUT);
  430. }
  431. unlock:
  432. spin_unlock_irqrestore(&upriv->req_lock, flags);
  433. done:
  434. return;
  435. }
  436. static void ezusb_req_enqueue_run(struct ezusb_priv *upriv,
  437. struct request_context *ctx)
  438. {
  439. unsigned long flags;
  440. spin_lock_irqsave(&upriv->req_lock, flags);
  441. if (!ctx->upriv->udev) {
  442. spin_unlock_irqrestore(&upriv->req_lock, flags);
  443. goto done;
  444. }
  445. atomic_inc(&ctx->refcount);
  446. list_add_tail(&ctx->list, &upriv->req_pending);
  447. spin_unlock_irqrestore(&upriv->req_lock, flags);
  448. ctx->state = EZUSB_CTX_QUEUED;
  449. ezusb_req_queue_run(upriv);
  450. done:
  451. return;
  452. }
  453. static void ezusb_request_out_callback(struct urb *urb)
  454. {
  455. unsigned long flags;
  456. enum ezusb_state state;
  457. struct request_context *ctx = urb->context;
  458. struct ezusb_priv *upriv = ctx->upriv;
  459. spin_lock_irqsave(&upriv->req_lock, flags);
  460. del_timer(&ctx->timer);
  461. if (ctx->killed) {
  462. spin_unlock_irqrestore(&upriv->req_lock, flags);
  463. pr_warning("interrupt called with dead ctx");
  464. goto out;
  465. }
  466. state = ctx->state;
  467. if (urb->status == 0) {
  468. switch (state) {
  469. case EZUSB_CTX_REQ_SUBMITTED:
  470. if (ctx->in_rid) {
  471. ctx->state = EZUSB_CTX_REQ_COMPLETE;
  472. /* reply URB still pending */
  473. ezusb_mod_timer(upriv, &ctx->timer,
  474. jiffies + DEF_TIMEOUT);
  475. spin_unlock_irqrestore(&upriv->req_lock,
  476. flags);
  477. break;
  478. }
  479. /* fall through */
  480. case EZUSB_CTX_RESP_RECEIVED:
  481. /* IN already received before this OUT-ACK */
  482. ctx->state = EZUSB_CTX_COMPLETE;
  483. spin_unlock_irqrestore(&upriv->req_lock, flags);
  484. ezusb_ctx_complete(ctx);
  485. break;
  486. default:
  487. spin_unlock_irqrestore(&upriv->req_lock, flags);
  488. err("Unexpected state(0x%x, %d) in OUT URB",
  489. state, urb->status);
  490. break;
  491. }
  492. } else {
  493. /* If someone cancels the OUT URB then its status
  494. * should be either -ECONNRESET or -ENOENT.
  495. */
  496. switch (state) {
  497. case EZUSB_CTX_REQ_SUBMITTED:
  498. case EZUSB_CTX_RESP_RECEIVED:
  499. ctx->state = EZUSB_CTX_REQ_FAILED;
  500. /* fall through */
  501. case EZUSB_CTX_REQ_FAILED:
  502. case EZUSB_CTX_REQ_TIMEOUT:
  503. spin_unlock_irqrestore(&upriv->req_lock, flags);
  504. ezusb_ctx_complete(ctx);
  505. break;
  506. default:
  507. spin_unlock_irqrestore(&upriv->req_lock, flags);
  508. err("Unexpected state(0x%x, %d) in OUT URB",
  509. state, urb->status);
  510. break;
  511. }
  512. }
  513. out:
  514. ezusb_request_context_put(ctx);
  515. }
  516. static void ezusb_request_in_callback(struct ezusb_priv *upriv,
  517. struct urb *urb)
  518. {
  519. struct ezusb_packet *ans = urb->transfer_buffer;
  520. struct request_context *ctx = NULL;
  521. enum ezusb_state state;
  522. unsigned long flags;
  523. /* Find the CTX on the active queue that requested this URB */
  524. spin_lock_irqsave(&upriv->req_lock, flags);
  525. if (upriv->udev) {
  526. struct list_head *item;
  527. list_for_each(item, &upriv->req_active) {
  528. struct request_context *c;
  529. int reply_count;
  530. c = list_entry(item, struct request_context, list);
  531. reply_count =
  532. ezusb_reply_inc(c->buf->req_reply_count);
  533. if ((ans->ans_reply_count == reply_count)
  534. && (le16_to_cpu(ans->hermes_rid) == c->in_rid)) {
  535. ctx = c;
  536. break;
  537. }
  538. dbg("Skipped (0x%x/0x%x) (%d/%d)",
  539. le16_to_cpu(ans->hermes_rid),
  540. c->in_rid, ans->ans_reply_count, reply_count);
  541. }
  542. }
  543. if (ctx == NULL) {
  544. spin_unlock_irqrestore(&upriv->req_lock, flags);
  545. err("%s: got unexpected RID: 0x%04X", __func__,
  546. le16_to_cpu(ans->hermes_rid));
  547. ezusb_req_queue_run(upriv);
  548. return;
  549. }
  550. /* The data we want is in the in buffer, exchange */
  551. urb->transfer_buffer = ctx->buf;
  552. ctx->buf = (void *) ans;
  553. ctx->buf_length = urb->actual_length;
  554. state = ctx->state;
  555. switch (state) {
  556. case EZUSB_CTX_REQ_SUBMITTED:
  557. /* We have received our response URB before
  558. * our request has been acknowledged. Do NOT
  559. * destroy our CTX yet, because our OUT URB
  560. * is still alive ...
  561. */
  562. ctx->state = EZUSB_CTX_RESP_RECEIVED;
  563. spin_unlock_irqrestore(&upriv->req_lock, flags);
  564. /* Let the machine continue running. */
  565. break;
  566. case EZUSB_CTX_REQ_COMPLETE:
  567. /* This is the usual path: our request
  568. * has already been acknowledged, and
  569. * we have now received the reply.
  570. */
  571. ctx->state = EZUSB_CTX_COMPLETE;
  572. /* Stop the intimer */
  573. del_timer(&ctx->timer);
  574. spin_unlock_irqrestore(&upriv->req_lock, flags);
  575. /* Call the completion handler */
  576. ezusb_ctx_complete(ctx);
  577. break;
  578. default:
  579. spin_unlock_irqrestore(&upriv->req_lock, flags);
  580. pr_warning("Matched IN URB, unexpected context state(0x%x)",
  581. state);
  582. /* Throw this CTX away and try submitting another */
  583. del_timer(&ctx->timer);
  584. ctx->outurb->transfer_flags |= URB_ASYNC_UNLINK;
  585. usb_unlink_urb(ctx->outurb);
  586. ezusb_req_queue_run(upriv);
  587. break;
  588. } /* switch */
  589. }
  590. static void ezusb_req_ctx_wait(struct ezusb_priv *upriv,
  591. struct request_context *ctx)
  592. {
  593. switch (ctx->state) {
  594. case EZUSB_CTX_QUEUED:
  595. case EZUSB_CTX_REQ_SUBMITTED:
  596. case EZUSB_CTX_REQ_COMPLETE:
  597. case EZUSB_CTX_RESP_RECEIVED:
  598. if (in_softirq()) {
  599. /* If we get called from a timer, timeout timers don't
  600. * get the chance to run themselves. So we make sure
  601. * that we don't sleep for ever */
  602. int msecs = DEF_TIMEOUT * (1000 / HZ);
  603. while (!ctx->done.done && msecs--)
  604. udelay(1000);
  605. } else {
  606. wait_event_interruptible(ctx->done.wait,
  607. ctx->done.done);
  608. }
  609. break;
  610. default:
  611. /* Done or failed - nothing to wait for */
  612. break;
  613. }
  614. }
  615. static inline u16 build_crc(struct ezusb_packet *data)
  616. {
  617. u16 crc = 0;
  618. u8 *bytes = (u8 *)data;
  619. int i;
  620. for (i = 0; i < 8; i++)
  621. crc = (crc << 1) + bytes[i];
  622. return crc;
  623. }
  624. /**
  625. * ezusb_fill_req:
  626. *
  627. * if data == NULL and length > 0 the data is assumed to be already in
  628. * the target buffer and only the header is filled.
  629. *
  630. */
  631. static int ezusb_fill_req(struct ezusb_packet *req, u16 length, u16 rid,
  632. const void *data, u16 frame_type, u8 reply_count)
  633. {
  634. int total_size = sizeof(*req) + length;
  635. BUG_ON(total_size > BULK_BUF_SIZE);
  636. req->magic = cpu_to_le16(EZUSB_MAGIC);
  637. req->req_reply_count = reply_count;
  638. req->ans_reply_count = 0;
  639. req->frame_type = cpu_to_le16(frame_type);
  640. req->size = cpu_to_le16(length + 4);
  641. req->crc = cpu_to_le16(build_crc(req));
  642. req->hermes_len = cpu_to_le16(HERMES_BYTES_TO_RECLEN(length));
  643. req->hermes_rid = cpu_to_le16(rid);
  644. if (data)
  645. memcpy(req->data, data, length);
  646. return total_size;
  647. }
  648. static int ezusb_submit_in_urb(struct ezusb_priv *upriv)
  649. {
  650. int retval = 0;
  651. void *cur_buf = upriv->read_urb->transfer_buffer;
  652. if (upriv->read_urb->status == -EINPROGRESS) {
  653. dbg("urb busy, not resubmiting");
  654. retval = -EBUSY;
  655. goto exit;
  656. }
  657. usb_fill_bulk_urb(upriv->read_urb, upriv->udev, upriv->read_pipe,
  658. cur_buf, BULK_BUF_SIZE,
  659. ezusb_bulk_in_callback, upriv);
  660. upriv->read_urb->transfer_flags = 0;
  661. retval = usb_submit_urb(upriv->read_urb, GFP_ATOMIC);
  662. if (retval)
  663. err("%s submit failed %d", __func__, retval);
  664. exit:
  665. return retval;
  666. }
  667. static inline int ezusb_8051_cpucs(struct ezusb_priv *upriv, int reset)
  668. {
  669. u8 res_val = reset; /* avoid argument promotion */
  670. if (!upriv->udev) {
  671. err("%s: !upriv->udev", __func__);
  672. return -EFAULT;
  673. }
  674. return usb_control_msg(upriv->udev,
  675. usb_sndctrlpipe(upriv->udev, 0),
  676. EZUSB_REQUEST_FW_TRANS,
  677. USB_TYPE_VENDOR | USB_RECIP_DEVICE |
  678. USB_DIR_OUT, EZUSB_CPUCS_REG, 0, &res_val,
  679. sizeof(res_val), DEF_TIMEOUT);
  680. }
  681. static int ezusb_firmware_download(struct ezusb_priv *upriv,
  682. struct ez_usb_fw *fw)
  683. {
  684. u8 fw_buffer[FW_BUF_SIZE];
  685. int retval, addr;
  686. int variant_offset;
  687. /*
  688. * This byte is 1 and should be replaced with 0. The offset is
  689. * 0x10AD in version 0.0.6. The byte in question should follow
  690. * the end of the code pointed to by the jump in the beginning
  691. * of the firmware. Also, it is read by code located at 0x358.
  692. */
  693. variant_offset = be16_to_cpup((__be16 *) &fw->code[FW_VAR_OFFSET_PTR]);
  694. if (variant_offset >= fw->size) {
  695. printk(KERN_ERR PFX "Invalid firmware variant offset: "
  696. "0x%04x\n", variant_offset);
  697. retval = -EINVAL;
  698. goto fail;
  699. }
  700. retval = ezusb_8051_cpucs(upriv, 1);
  701. if (retval < 0)
  702. goto fail;
  703. for (addr = 0; addr < fw->size; addr += FW_BUF_SIZE) {
  704. /* 0x100-0x300 should be left alone, it contains card
  705. * specific data, like USB enumeration information */
  706. if ((addr >= FW_HOLE_START) && (addr < FW_HOLE_END))
  707. continue;
  708. memcpy(fw_buffer, &fw->code[addr], FW_BUF_SIZE);
  709. if (variant_offset >= addr &&
  710. variant_offset < addr + FW_BUF_SIZE) {
  711. dbg("Patching card_variant byte at 0x%04X",
  712. variant_offset);
  713. fw_buffer[variant_offset - addr] = FW_VAR_VALUE;
  714. }
  715. retval = usb_control_msg(upriv->udev,
  716. usb_sndctrlpipe(upriv->udev, 0),
  717. EZUSB_REQUEST_FW_TRANS,
  718. USB_TYPE_VENDOR | USB_RECIP_DEVICE
  719. | USB_DIR_OUT,
  720. addr, 0x0,
  721. fw_buffer, FW_BUF_SIZE,
  722. DEF_TIMEOUT);
  723. if (retval < 0)
  724. goto fail;
  725. }
  726. retval = ezusb_8051_cpucs(upriv, 0);
  727. if (retval < 0)
  728. goto fail;
  729. goto exit;
  730. fail:
  731. printk(KERN_ERR PFX "Firmware download failed, error %d\n",
  732. retval);
  733. exit:
  734. return retval;
  735. }
  736. static int ezusb_access_ltv(struct ezusb_priv *upriv,
  737. struct request_context *ctx,
  738. u16 length, const void *data, u16 frame_type,
  739. void *ans_buff, int ans_size, u16 *ans_length)
  740. {
  741. int req_size;
  742. int retval = 0;
  743. enum ezusb_state state;
  744. BUG_ON(in_irq());
  745. if (!upriv->udev) {
  746. dbg("Device disconnected");
  747. return -ENODEV;
  748. }
  749. if (upriv->read_urb->status != -EINPROGRESS)
  750. err("%s: in urb not pending", __func__);
  751. /* protect upriv->reply_count, guarantee sequential numbers */
  752. spin_lock_bh(&upriv->reply_count_lock);
  753. req_size = ezusb_fill_req(ctx->buf, length, ctx->out_rid, data,
  754. frame_type, upriv->reply_count);
  755. usb_fill_bulk_urb(ctx->outurb, upriv->udev, upriv->write_pipe,
  756. ctx->buf, req_size,
  757. ezusb_request_out_callback, ctx);
  758. if (ctx->in_rid)
  759. upriv->reply_count = ezusb_reply_inc(upriv->reply_count);
  760. ezusb_req_enqueue_run(upriv, ctx);
  761. spin_unlock_bh(&upriv->reply_count_lock);
  762. if (ctx->in_rid)
  763. ezusb_req_ctx_wait(upriv, ctx);
  764. state = ctx->state;
  765. switch (state) {
  766. case EZUSB_CTX_COMPLETE:
  767. retval = ctx->outurb->status;
  768. break;
  769. case EZUSB_CTX_QUEUED:
  770. case EZUSB_CTX_REQ_SUBMITTED:
  771. if (!ctx->in_rid)
  772. break;
  773. default:
  774. err("%s: Unexpected context state %d", __func__,
  775. state);
  776. /* fall though */
  777. case EZUSB_CTX_REQ_TIMEOUT:
  778. case EZUSB_CTX_REQ_FAILED:
  779. case EZUSB_CTX_RESP_TIMEOUT:
  780. case EZUSB_CTX_REQSUBMIT_FAIL:
  781. printk(KERN_ERR PFX "Access failed, resetting (state %d,"
  782. " reply_count %d)\n", state, upriv->reply_count);
  783. upriv->reply_count = 0;
  784. if (state == EZUSB_CTX_REQ_TIMEOUT
  785. || state == EZUSB_CTX_RESP_TIMEOUT) {
  786. printk(KERN_ERR PFX "ctx timed out\n");
  787. retval = -ETIMEDOUT;
  788. } else {
  789. printk(KERN_ERR PFX "ctx failed\n");
  790. retval = -EFAULT;
  791. }
  792. goto exit;
  793. break;
  794. }
  795. if (ctx->in_rid) {
  796. struct ezusb_packet *ans = ctx->buf;
  797. int exp_len;
  798. if (ans->hermes_len != 0)
  799. exp_len = le16_to_cpu(ans->hermes_len) * 2 + 12;
  800. else
  801. exp_len = 14;
  802. if (exp_len != ctx->buf_length) {
  803. err("%s: length mismatch for RID 0x%04x: "
  804. "expected %d, got %d", __func__,
  805. ctx->in_rid, exp_len, ctx->buf_length);
  806. retval = -EIO;
  807. goto exit;
  808. }
  809. if (ans_buff)
  810. memcpy(ans_buff, ans->data,
  811. min_t(int, exp_len, ans_size));
  812. if (ans_length)
  813. *ans_length = le16_to_cpu(ans->hermes_len);
  814. }
  815. exit:
  816. ezusb_request_context_put(ctx);
  817. return retval;
  818. }
  819. static int ezusb_write_ltv(struct hermes *hw, int bap, u16 rid,
  820. u16 length, const void *data)
  821. {
  822. struct ezusb_priv *upriv = hw->priv;
  823. u16 frame_type;
  824. struct request_context *ctx;
  825. if (length == 0)
  826. return -EINVAL;
  827. length = HERMES_RECLEN_TO_BYTES(length);
  828. /* On memory mapped devices HERMES_RID_CNFGROUPADDRESSES can be
  829. * set to be empty, but the USB bridge doesn't like it */
  830. if (length == 0)
  831. return 0;
  832. ctx = ezusb_alloc_ctx(upriv, rid, EZUSB_RID_ACK);
  833. if (!ctx)
  834. return -ENOMEM;
  835. if (rid == EZUSB_RID_TX)
  836. frame_type = EZUSB_FRAME_DATA;
  837. else
  838. frame_type = EZUSB_FRAME_CONTROL;
  839. return ezusb_access_ltv(upriv, ctx, length, data, frame_type,
  840. NULL, 0, NULL);
  841. }
  842. static int ezusb_read_ltv(struct hermes *hw, int bap, u16 rid,
  843. unsigned bufsize, u16 *length, void *buf)
  844. {
  845. struct ezusb_priv *upriv = hw->priv;
  846. struct request_context *ctx;
  847. if ((bufsize < 0) || (bufsize % 2))
  848. return -EINVAL;
  849. ctx = ezusb_alloc_ctx(upriv, rid, rid);
  850. if (!ctx)
  851. return -ENOMEM;
  852. return ezusb_access_ltv(upriv, ctx, 0, NULL, EZUSB_FRAME_CONTROL,
  853. buf, bufsize, length);
  854. }
  855. static int ezusb_doicmd_wait(struct hermes *hw, u16 cmd, u16 parm0, u16 parm1,
  856. u16 parm2, struct hermes_response *resp)
  857. {
  858. struct ezusb_priv *upriv = hw->priv;
  859. struct request_context *ctx;
  860. __le16 data[4] = {
  861. cpu_to_le16(cmd),
  862. cpu_to_le16(parm0),
  863. cpu_to_le16(parm1),
  864. cpu_to_le16(parm2),
  865. };
  866. dbg("0x%04X, parm0 0x%04X, parm1 0x%04X, parm2 0x%04X",
  867. cmd, parm0, parm1, parm2);
  868. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_DOCMD, EZUSB_RID_ACK);
  869. if (!ctx)
  870. return -ENOMEM;
  871. return ezusb_access_ltv(upriv, ctx, sizeof(data), &data,
  872. EZUSB_FRAME_CONTROL, NULL, 0, NULL);
  873. }
  874. static int ezusb_docmd_wait(struct hermes *hw, u16 cmd, u16 parm0,
  875. struct hermes_response *resp)
  876. {
  877. struct ezusb_priv *upriv = hw->priv;
  878. struct request_context *ctx;
  879. __le16 data[4] = {
  880. cpu_to_le16(cmd),
  881. cpu_to_le16(parm0),
  882. 0,
  883. 0,
  884. };
  885. dbg("0x%04X, parm0 0x%04X", cmd, parm0);
  886. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_DOCMD, EZUSB_RID_ACK);
  887. if (!ctx)
  888. return -ENOMEM;
  889. return ezusb_access_ltv(upriv, ctx, sizeof(data), &data,
  890. EZUSB_FRAME_CONTROL, NULL, 0, NULL);
  891. }
  892. static int ezusb_bap_pread(struct hermes *hw, int bap,
  893. void *buf, int len, u16 id, u16 offset)
  894. {
  895. struct ezusb_priv *upriv = hw->priv;
  896. struct ezusb_packet *ans = (void *) upriv->read_urb->transfer_buffer;
  897. int actual_length = upriv->read_urb->actual_length;
  898. if (id == EZUSB_RID_RX) {
  899. if ((sizeof(*ans) + offset + len) > actual_length) {
  900. printk(KERN_ERR PFX "BAP read beyond buffer end "
  901. "in rx frame\n");
  902. return -EINVAL;
  903. }
  904. memcpy(buf, ans->data + offset, len);
  905. return 0;
  906. }
  907. if (EZUSB_IS_INFO(id)) {
  908. /* Include 4 bytes for length/type */
  909. if ((sizeof(*ans) + offset + len - 4) > actual_length) {
  910. printk(KERN_ERR PFX "BAP read beyond buffer end "
  911. "in info frame\n");
  912. return -EFAULT;
  913. }
  914. memcpy(buf, ans->data + offset - 4, len);
  915. } else {
  916. printk(KERN_ERR PFX "Unexpected fid 0x%04x\n", id);
  917. return -EINVAL;
  918. }
  919. return 0;
  920. }
  921. static int ezusb_read_pda(struct hermes *hw, __le16 *pda,
  922. u32 pda_addr, u16 pda_len)
  923. {
  924. struct ezusb_priv *upriv = hw->priv;
  925. struct request_context *ctx;
  926. __le16 data[] = {
  927. cpu_to_le16(pda_addr & 0xffff),
  928. cpu_to_le16(pda_len - 4)
  929. };
  930. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_READ_PDA, EZUSB_RID_READ_PDA);
  931. if (!ctx)
  932. return -ENOMEM;
  933. /* wl_lkm does not include PDA size in the PDA area.
  934. * We will pad the information into pda, so other routines
  935. * don't have to be modified */
  936. pda[0] = cpu_to_le16(pda_len - 2);
  937. /* Includes CFG_PROD_DATA but not itself */
  938. pda[1] = cpu_to_le16(0x0800); /* CFG_PROD_DATA */
  939. return ezusb_access_ltv(upriv, ctx, sizeof(data), &data,
  940. EZUSB_FRAME_CONTROL, &pda[2], pda_len - 4,
  941. NULL);
  942. }
  943. static int ezusb_program_init(struct hermes *hw, u32 entry_point)
  944. {
  945. struct ezusb_priv *upriv = hw->priv;
  946. struct request_context *ctx;
  947. __le32 data = cpu_to_le32(entry_point);
  948. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_PROG_INIT, EZUSB_RID_ACK);
  949. if (!ctx)
  950. return -ENOMEM;
  951. return ezusb_access_ltv(upriv, ctx, sizeof(data), &data,
  952. EZUSB_FRAME_CONTROL, NULL, 0, NULL);
  953. }
  954. static int ezusb_program_end(struct hermes *hw)
  955. {
  956. struct ezusb_priv *upriv = hw->priv;
  957. struct request_context *ctx;
  958. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_PROG_END, EZUSB_RID_ACK);
  959. if (!ctx)
  960. return -ENOMEM;
  961. return ezusb_access_ltv(upriv, ctx, 0, NULL,
  962. EZUSB_FRAME_CONTROL, NULL, 0, NULL);
  963. }
  964. static int ezusb_program_bytes(struct hermes *hw, const char *buf,
  965. u32 addr, u32 len)
  966. {
  967. struct ezusb_priv *upriv = hw->priv;
  968. struct request_context *ctx;
  969. __le32 data = cpu_to_le32(addr);
  970. int err;
  971. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_PROG_SET_ADDR, EZUSB_RID_ACK);
  972. if (!ctx)
  973. return -ENOMEM;
  974. err = ezusb_access_ltv(upriv, ctx, sizeof(data), &data,
  975. EZUSB_FRAME_CONTROL, NULL, 0, NULL);
  976. if (err)
  977. return err;
  978. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_PROG_BYTES, EZUSB_RID_ACK);
  979. if (!ctx)
  980. return -ENOMEM;
  981. return ezusb_access_ltv(upriv, ctx, len, buf,
  982. EZUSB_FRAME_CONTROL, NULL, 0, NULL);
  983. }
  984. static int ezusb_program(struct hermes *hw, const char *buf,
  985. u32 addr, u32 len)
  986. {
  987. u32 ch_addr;
  988. u32 ch_len;
  989. int err = 0;
  990. /* We can only send 2048 bytes out of the bulk xmit at a time,
  991. * so we have to split any programming into chunks of <2048
  992. * bytes. */
  993. ch_len = (len < MAX_DL_SIZE) ? len : MAX_DL_SIZE;
  994. ch_addr = addr;
  995. while (ch_addr < (addr + len)) {
  996. pr_debug("Programming subblock of length %d "
  997. "to address 0x%08x. Data @ %p\n",
  998. ch_len, ch_addr, &buf[ch_addr - addr]);
  999. err = ezusb_program_bytes(hw, &buf[ch_addr - addr],
  1000. ch_addr, ch_len);
  1001. if (err)
  1002. break;
  1003. ch_addr += ch_len;
  1004. ch_len = ((addr + len - ch_addr) < MAX_DL_SIZE) ?
  1005. (addr + len - ch_addr) : MAX_DL_SIZE;
  1006. }
  1007. return err;
  1008. }
  1009. static netdev_tx_t ezusb_xmit(struct sk_buff *skb, struct net_device *dev)
  1010. {
  1011. struct orinoco_private *priv = ndev_priv(dev);
  1012. struct net_device_stats *stats = &priv->stats;
  1013. struct ezusb_priv *upriv = priv->card;
  1014. u8 mic[MICHAEL_MIC_LEN + 1];
  1015. int err = 0;
  1016. int tx_control;
  1017. unsigned long flags;
  1018. struct request_context *ctx;
  1019. u8 *buf;
  1020. int tx_size;
  1021. if (!netif_running(dev)) {
  1022. printk(KERN_ERR "%s: Tx on stopped device!\n",
  1023. dev->name);
  1024. return NETDEV_TX_BUSY;
  1025. }
  1026. if (netif_queue_stopped(dev)) {
  1027. printk(KERN_DEBUG "%s: Tx while transmitter busy!\n",
  1028. dev->name);
  1029. return NETDEV_TX_BUSY;
  1030. }
  1031. if (orinoco_lock(priv, &flags) != 0) {
  1032. printk(KERN_ERR
  1033. "%s: ezusb_xmit() called while hw_unavailable\n",
  1034. dev->name);
  1035. return NETDEV_TX_BUSY;
  1036. }
  1037. if (!netif_carrier_ok(dev) ||
  1038. (priv->iw_mode == NL80211_IFTYPE_MONITOR)) {
  1039. /* Oops, the firmware hasn't established a connection,
  1040. silently drop the packet (this seems to be the
  1041. safest approach). */
  1042. goto drop;
  1043. }
  1044. /* Check packet length */
  1045. if (skb->len < ETH_HLEN)
  1046. goto drop;
  1047. ctx = ezusb_alloc_ctx(upriv, EZUSB_RID_TX, 0);
  1048. if (!ctx)
  1049. goto busy;
  1050. memset(ctx->buf, 0, BULK_BUF_SIZE);
  1051. buf = ctx->buf->data;
  1052. tx_control = 0;
  1053. err = orinoco_process_xmit_skb(skb, dev, priv, &tx_control,
  1054. &mic[0]);
  1055. if (err)
  1056. goto drop;
  1057. {
  1058. __le16 *tx_cntl = (__le16 *)buf;
  1059. *tx_cntl = cpu_to_le16(tx_control);
  1060. buf += sizeof(*tx_cntl);
  1061. }
  1062. memcpy(buf, skb->data, skb->len);
  1063. buf += skb->len;
  1064. if (tx_control & HERMES_TXCTRL_MIC) {
  1065. u8 *m = mic;
  1066. /* Mic has been offset so it can be copied to an even
  1067. * address. We're copying eveything anyway, so we
  1068. * don't need to copy that first byte. */
  1069. if (skb->len % 2)
  1070. m++;
  1071. memcpy(buf, m, MICHAEL_MIC_LEN);
  1072. buf += MICHAEL_MIC_LEN;
  1073. }
  1074. /* Finally, we actually initiate the send */
  1075. netif_stop_queue(dev);
  1076. /* The card may behave better if we send evenly sized usb transfers */
  1077. tx_size = ALIGN(buf - ctx->buf->data, 2);
  1078. err = ezusb_access_ltv(upriv, ctx, tx_size, NULL,
  1079. EZUSB_FRAME_DATA, NULL, 0, NULL);
  1080. if (err) {
  1081. netif_start_queue(dev);
  1082. if (net_ratelimit())
  1083. printk(KERN_ERR "%s: Error %d transmitting packet\n",
  1084. dev->name, err);
  1085. goto busy;
  1086. }
  1087. dev->trans_start = jiffies;
  1088. stats->tx_bytes += skb->len;
  1089. goto ok;
  1090. drop:
  1091. stats->tx_errors++;
  1092. stats->tx_dropped++;
  1093. ok:
  1094. orinoco_unlock(priv, &flags);
  1095. dev_kfree_skb(skb);
  1096. return NETDEV_TX_OK;
  1097. busy:
  1098. orinoco_unlock(priv, &flags);
  1099. return NETDEV_TX_BUSY;
  1100. }
  1101. static int ezusb_allocate(struct hermes *hw, u16 size, u16 *fid)
  1102. {
  1103. *fid = EZUSB_RID_TX;
  1104. return 0;
  1105. }
  1106. static int ezusb_hard_reset(struct orinoco_private *priv)
  1107. {
  1108. struct ezusb_priv *upriv = priv->card;
  1109. int retval = ezusb_8051_cpucs(upriv, 1);
  1110. if (retval < 0) {
  1111. err("Failed to reset");
  1112. return retval;
  1113. }
  1114. retval = ezusb_8051_cpucs(upriv, 0);
  1115. if (retval < 0) {
  1116. err("Failed to unreset");
  1117. return retval;
  1118. }
  1119. dbg("sending control message");
  1120. retval = usb_control_msg(upriv->udev,
  1121. usb_sndctrlpipe(upriv->udev, 0),
  1122. EZUSB_REQUEST_TRIGER,
  1123. USB_TYPE_VENDOR | USB_RECIP_DEVICE |
  1124. USB_DIR_OUT, 0x0, 0x0, NULL, 0,
  1125. DEF_TIMEOUT);
  1126. if (retval < 0) {
  1127. err("EZUSB_REQUEST_TRIGER failed retval %d", retval);
  1128. return retval;
  1129. }
  1130. #if 0
  1131. dbg("Sending EZUSB_REQUEST_TRIG_AC");
  1132. retval = usb_control_msg(upriv->udev,
  1133. usb_sndctrlpipe(upriv->udev, 0),
  1134. EZUSB_REQUEST_TRIG_AC,
  1135. USB_TYPE_VENDOR | USB_RECIP_DEVICE |
  1136. USB_DIR_OUT, 0x00FA, 0x0, NULL, 0,
  1137. DEF_TIMEOUT);
  1138. if (retval < 0) {
  1139. err("EZUSB_REQUEST_TRIG_AC failed retval %d", retval);
  1140. return retval;
  1141. }
  1142. #endif
  1143. return 0;
  1144. }
  1145. static int ezusb_init(struct hermes *hw)
  1146. {
  1147. struct ezusb_priv *upriv = hw->priv;
  1148. int retval;
  1149. BUG_ON(in_interrupt());
  1150. BUG_ON(!upriv);
  1151. upriv->reply_count = 0;
  1152. /* Write the MAGIC number on the simulated registers to keep
  1153. * orinoco.c happy */
  1154. hermes_write_regn(hw, SWSUPPORT0, HERMES_MAGIC);
  1155. hermes_write_regn(hw, RXFID, EZUSB_RID_RX);
  1156. usb_kill_urb(upriv->read_urb);
  1157. ezusb_submit_in_urb(upriv);
  1158. retval = ezusb_write_ltv(hw, 0, EZUSB_RID_INIT1,
  1159. HERMES_BYTES_TO_RECLEN(2), "\x10\x00");
  1160. if (retval < 0) {
  1161. printk(KERN_ERR PFX "EZUSB_RID_INIT1 error %d\n", retval);
  1162. return retval;
  1163. }
  1164. retval = ezusb_docmd_wait(hw, HERMES_CMD_INIT, 0, NULL);
  1165. if (retval < 0) {
  1166. printk(KERN_ERR PFX "HERMES_CMD_INIT error %d\n", retval);
  1167. return retval;
  1168. }
  1169. return 0;
  1170. }
  1171. static void ezusb_bulk_in_callback(struct urb *urb)
  1172. {
  1173. struct ezusb_priv *upriv = (struct ezusb_priv *) urb->context;
  1174. struct ezusb_packet *ans = urb->transfer_buffer;
  1175. u16 crc;
  1176. u16 hermes_rid;
  1177. if (upriv->udev == NULL) {
  1178. dbg("disconnected");
  1179. return;
  1180. }
  1181. if (urb->status == -ETIMEDOUT) {
  1182. /* When a device gets unplugged we get this every time
  1183. * we resubmit, flooding the logs. Since we don't use
  1184. * USB timeouts, it shouldn't happen any other time*/
  1185. pr_warning("%s: urb timed out, not resubmiting", __func__);
  1186. return;
  1187. }
  1188. if (urb->status == -ECONNABORTED) {
  1189. pr_warning("%s: connection abort, resubmiting urb",
  1190. __func__);
  1191. goto resubmit;
  1192. }
  1193. if ((urb->status == -EILSEQ)
  1194. || (urb->status == -ENOENT)
  1195. || (urb->status == -ECONNRESET)) {
  1196. dbg("status %d, not resubmiting", urb->status);
  1197. return;
  1198. }
  1199. if (urb->status)
  1200. dbg("status: %d length: %d",
  1201. urb->status, urb->actual_length);
  1202. if (urb->actual_length < sizeof(*ans)) {
  1203. err("%s: short read, ignoring", __func__);
  1204. goto resubmit;
  1205. }
  1206. crc = build_crc(ans);
  1207. if (le16_to_cpu(ans->crc) != crc) {
  1208. err("CRC error, ignoring packet");
  1209. goto resubmit;
  1210. }
  1211. hermes_rid = le16_to_cpu(ans->hermes_rid);
  1212. if ((hermes_rid != EZUSB_RID_RX) && !EZUSB_IS_INFO(hermes_rid)) {
  1213. ezusb_request_in_callback(upriv, urb);
  1214. } else if (upriv->dev) {
  1215. struct net_device *dev = upriv->dev;
  1216. struct orinoco_private *priv = ndev_priv(dev);
  1217. struct hermes *hw = &priv->hw;
  1218. if (hermes_rid == EZUSB_RID_RX) {
  1219. __orinoco_ev_rx(dev, hw);
  1220. } else {
  1221. hermes_write_regn(hw, INFOFID,
  1222. le16_to_cpu(ans->hermes_rid));
  1223. __orinoco_ev_info(dev, hw);
  1224. }
  1225. }
  1226. resubmit:
  1227. if (upriv->udev)
  1228. ezusb_submit_in_urb(upriv);
  1229. }
  1230. static inline void ezusb_delete(struct ezusb_priv *upriv)
  1231. {
  1232. struct net_device *dev;
  1233. struct list_head *item;
  1234. struct list_head *tmp_item;
  1235. unsigned long flags;
  1236. BUG_ON(in_interrupt());
  1237. BUG_ON(!upriv);
  1238. dev = upriv->dev;
  1239. mutex_lock(&upriv->mtx);
  1240. upriv->udev = NULL; /* No timer will be rearmed from here */
  1241. usb_kill_urb(upriv->read_urb);
  1242. spin_lock_irqsave(&upriv->req_lock, flags);
  1243. list_for_each_safe(item, tmp_item, &upriv->req_active) {
  1244. struct request_context *ctx;
  1245. int err;
  1246. ctx = list_entry(item, struct request_context, list);
  1247. atomic_inc(&ctx->refcount);
  1248. ctx->outurb->transfer_flags |= URB_ASYNC_UNLINK;
  1249. err = usb_unlink_urb(ctx->outurb);
  1250. spin_unlock_irqrestore(&upriv->req_lock, flags);
  1251. if (err == -EINPROGRESS)
  1252. wait_for_completion(&ctx->done);
  1253. del_timer_sync(&ctx->timer);
  1254. /* FIXME: there is an slight chance for the irq handler to
  1255. * be running */
  1256. if (!list_empty(&ctx->list))
  1257. ezusb_ctx_complete(ctx);
  1258. ezusb_request_context_put(ctx);
  1259. spin_lock_irqsave(&upriv->req_lock, flags);
  1260. }
  1261. spin_unlock_irqrestore(&upriv->req_lock, flags);
  1262. list_for_each_safe(item, tmp_item, &upriv->req_pending)
  1263. ezusb_ctx_complete(list_entry(item,
  1264. struct request_context, list));
  1265. if (upriv->read_urb && upriv->read_urb->status == -EINPROGRESS)
  1266. printk(KERN_ERR PFX "Some URB in progress\n");
  1267. mutex_unlock(&upriv->mtx);
  1268. if (upriv->read_urb) {
  1269. kfree(upriv->read_urb->transfer_buffer);
  1270. usb_free_urb(upriv->read_urb);
  1271. }
  1272. kfree(upriv->bap_buf);
  1273. if (upriv->dev) {
  1274. struct orinoco_private *priv = ndev_priv(upriv->dev);
  1275. orinoco_if_del(priv);
  1276. free_orinocodev(priv);
  1277. }
  1278. }
  1279. static void ezusb_lock_irqsave(spinlock_t *lock,
  1280. unsigned long *flags) __acquires(lock)
  1281. {
  1282. spin_lock_bh(lock);
  1283. }
  1284. static void ezusb_unlock_irqrestore(spinlock_t *lock,
  1285. unsigned long *flags) __releases(lock)
  1286. {
  1287. spin_unlock_bh(lock);
  1288. }
  1289. static void ezusb_lock_irq(spinlock_t *lock) __acquires(lock)
  1290. {
  1291. spin_lock_bh(lock);
  1292. }
  1293. static void ezusb_unlock_irq(spinlock_t *lock) __releases(lock)
  1294. {
  1295. spin_unlock_bh(lock);
  1296. }
  1297. static const struct hermes_ops ezusb_ops = {
  1298. .init = ezusb_init,
  1299. .cmd_wait = ezusb_docmd_wait,
  1300. .init_cmd_wait = ezusb_doicmd_wait,
  1301. .allocate = ezusb_allocate,
  1302. .read_ltv = ezusb_read_ltv,
  1303. .write_ltv = ezusb_write_ltv,
  1304. .bap_pread = ezusb_bap_pread,
  1305. .read_pda = ezusb_read_pda,
  1306. .program_init = ezusb_program_init,
  1307. .program_end = ezusb_program_end,
  1308. .program = ezusb_program,
  1309. .lock_irqsave = ezusb_lock_irqsave,
  1310. .unlock_irqrestore = ezusb_unlock_irqrestore,
  1311. .lock_irq = ezusb_lock_irq,
  1312. .unlock_irq = ezusb_unlock_irq,
  1313. };
  1314. static const struct net_device_ops ezusb_netdev_ops = {
  1315. .ndo_open = orinoco_open,
  1316. .ndo_stop = orinoco_stop,
  1317. .ndo_start_xmit = ezusb_xmit,
  1318. .ndo_set_rx_mode = orinoco_set_multicast_list,
  1319. .ndo_change_mtu = orinoco_change_mtu,
  1320. .ndo_set_mac_address = eth_mac_addr,
  1321. .ndo_validate_addr = eth_validate_addr,
  1322. .ndo_tx_timeout = orinoco_tx_timeout,
  1323. .ndo_get_stats = orinoco_get_stats,
  1324. };
  1325. static int ezusb_probe(struct usb_interface *interface,
  1326. const struct usb_device_id *id)
  1327. {
  1328. struct usb_device *udev = interface_to_usbdev(interface);
  1329. struct orinoco_private *priv;
  1330. struct hermes *hw;
  1331. struct ezusb_priv *upriv = NULL;
  1332. struct usb_interface_descriptor *iface_desc;
  1333. struct usb_endpoint_descriptor *ep;
  1334. const struct firmware *fw_entry;
  1335. int retval = 0;
  1336. int i;
  1337. priv = alloc_orinocodev(sizeof(*upriv), &udev->dev,
  1338. ezusb_hard_reset, NULL);
  1339. if (!priv) {
  1340. err("Couldn't allocate orinocodev");
  1341. goto exit;
  1342. }
  1343. hw = &priv->hw;
  1344. upriv = priv->card;
  1345. mutex_init(&upriv->mtx);
  1346. spin_lock_init(&upriv->reply_count_lock);
  1347. spin_lock_init(&upriv->req_lock);
  1348. INIT_LIST_HEAD(&upriv->req_pending);
  1349. INIT_LIST_HEAD(&upriv->req_active);
  1350. upriv->udev = udev;
  1351. hw->iobase = (void __force __iomem *) &upriv->hermes_reg_fake;
  1352. hw->reg_spacing = HERMES_16BIT_REGSPACING;
  1353. hw->priv = upriv;
  1354. hw->ops = &ezusb_ops;
  1355. /* set up the endpoint information */
  1356. /* check out the endpoints */
  1357. iface_desc = &interface->altsetting[0].desc;
  1358. for (i = 0; i < iface_desc->bNumEndpoints; ++i) {
  1359. ep = &interface->altsetting[0].endpoint[i].desc;
  1360. if (((ep->bEndpointAddress & USB_ENDPOINT_DIR_MASK)
  1361. == USB_DIR_IN) &&
  1362. ((ep->bmAttributes & USB_ENDPOINT_XFERTYPE_MASK)
  1363. == USB_ENDPOINT_XFER_BULK)) {
  1364. /* we found a bulk in endpoint */
  1365. if (upriv->read_urb != NULL) {
  1366. pr_warning("Found a second bulk in ep, ignored");
  1367. continue;
  1368. }
  1369. upriv->read_urb = usb_alloc_urb(0, GFP_KERNEL);
  1370. if (!upriv->read_urb) {
  1371. err("No free urbs available");
  1372. goto error;
  1373. }
  1374. if (le16_to_cpu(ep->wMaxPacketSize) != 64)
  1375. pr_warning("bulk in: wMaxPacketSize!= 64");
  1376. if (ep->bEndpointAddress != (2 | USB_DIR_IN))
  1377. pr_warning("bulk in: bEndpointAddress: %d",
  1378. ep->bEndpointAddress);
  1379. upriv->read_pipe = usb_rcvbulkpipe(udev,
  1380. ep->
  1381. bEndpointAddress);
  1382. upriv->read_urb->transfer_buffer =
  1383. kmalloc(BULK_BUF_SIZE, GFP_KERNEL);
  1384. if (!upriv->read_urb->transfer_buffer) {
  1385. err("Couldn't allocate IN buffer");
  1386. goto error;
  1387. }
  1388. }
  1389. if (((ep->bEndpointAddress & USB_ENDPOINT_DIR_MASK)
  1390. == USB_DIR_OUT) &&
  1391. ((ep->bmAttributes & USB_ENDPOINT_XFERTYPE_MASK)
  1392. == USB_ENDPOINT_XFER_BULK)) {
  1393. /* we found a bulk out endpoint */
  1394. if (upriv->bap_buf != NULL) {
  1395. pr_warning("Found a second bulk out ep, ignored");
  1396. continue;
  1397. }
  1398. if (le16_to_cpu(ep->wMaxPacketSize) != 64)
  1399. pr_warning("bulk out: wMaxPacketSize != 64");
  1400. if (ep->bEndpointAddress != 2)
  1401. pr_warning("bulk out: bEndpointAddress: %d",
  1402. ep->bEndpointAddress);
  1403. upriv->write_pipe = usb_sndbulkpipe(udev,
  1404. ep->
  1405. bEndpointAddress);
  1406. upriv->bap_buf = kmalloc(BULK_BUF_SIZE, GFP_KERNEL);
  1407. if (!upriv->bap_buf) {
  1408. err("Couldn't allocate bulk_out_buffer");
  1409. goto error;
  1410. }
  1411. }
  1412. }
  1413. if (!upriv->bap_buf || !upriv->read_urb) {
  1414. err("Didn't find the required bulk endpoints");
  1415. goto error;
  1416. }
  1417. if (request_firmware(&fw_entry, "orinoco_ezusb_fw",
  1418. &interface->dev) == 0) {
  1419. firmware.size = fw_entry->size;
  1420. firmware.code = fw_entry->data;
  1421. }
  1422. if (firmware.size && firmware.code) {
  1423. ezusb_firmware_download(upriv, &firmware);
  1424. } else {
  1425. err("No firmware to download");
  1426. goto error;
  1427. }
  1428. if (ezusb_hard_reset(priv) < 0) {
  1429. err("Cannot reset the device");
  1430. goto error;
  1431. }
  1432. /* If the firmware is already downloaded orinoco.c will call
  1433. * ezusb_init but if the firmware is not already there, that will make
  1434. * the kernel very unstable, so we try initializing here and quit in
  1435. * case of error */
  1436. if (ezusb_init(hw) < 0) {
  1437. err("Couldn't initialize the device");
  1438. err("Firmware may not be downloaded or may be wrong.");
  1439. goto error;
  1440. }
  1441. /* Initialise the main driver */
  1442. if (orinoco_init(priv) != 0) {
  1443. err("orinoco_init() failed\n");
  1444. goto error;
  1445. }
  1446. if (orinoco_if_add(priv, 0, 0, &ezusb_netdev_ops) != 0) {
  1447. upriv->dev = NULL;
  1448. err("%s: orinoco_if_add() failed", __func__);
  1449. goto error;
  1450. }
  1451. upriv->dev = priv->ndev;
  1452. goto exit;
  1453. error:
  1454. ezusb_delete(upriv);
  1455. if (upriv->dev) {
  1456. /* upriv->dev was 0, so ezusb_delete() didn't free it */
  1457. free_orinocodev(priv);
  1458. }
  1459. upriv = NULL;
  1460. retval = -EFAULT;
  1461. exit:
  1462. if (fw_entry) {
  1463. firmware.code = NULL;
  1464. firmware.size = 0;
  1465. release_firmware(fw_entry);
  1466. }
  1467. usb_set_intfdata(interface, upriv);
  1468. return retval;
  1469. }
  1470. static void ezusb_disconnect(struct usb_interface *intf)
  1471. {
  1472. struct ezusb_priv *upriv = usb_get_intfdata(intf);
  1473. usb_set_intfdata(intf, NULL);
  1474. ezusb_delete(upriv);
  1475. printk(KERN_INFO PFX "Disconnected\n");
  1476. }
  1477. /* usb specific object needed to register this driver with the usb subsystem */
  1478. static struct usb_driver orinoco_driver = {
  1479. .name = DRIVER_NAME,
  1480. .probe = ezusb_probe,
  1481. .disconnect = ezusb_disconnect,
  1482. .id_table = ezusb_table,
  1483. };
  1484. module_usb_driver(orinoco_driver);
  1485. MODULE_AUTHOR("Manuel Estrada Sainz");
  1486. MODULE_DESCRIPTION("Driver for Orinoco wireless LAN cards using EZUSB bridge");
  1487. MODULE_LICENSE("Dual MPL/GPL");