blob: e0d3e2dd1d82b6d172378bcb45b4c5c42be77aa5 [file] [log] [blame]
Tomas Winklera55360e2008-05-05 10:22:28 +08001/******************************************************************************
2 *
3 * Copyright(c) 2003 - 2008 Intel Corporation. All rights reserved.
4 *
5 * Portions of this file are derived from the ipw3945 project, as well
6 * as portions of the ieee80211 subsystem header files.
7 *
8 * This program is free software; you can redistribute it and/or modify it
9 * under the terms of version 2 of the GNU General Public License as
10 * published by the Free Software Foundation.
11 *
12 * This program is distributed in the hope that it will be useful, but WITHOUT
13 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
14 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
15 * more details.
16 *
17 * You should have received a copy of the GNU General Public License along with
18 * this program; if not, write to the Free Software Foundation, Inc.,
19 * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
20 *
21 * The full GNU General Public License is included in this distribution in the
22 * file called LICENSE.
23 *
24 * Contact Information:
25 * James P. Ketrenos <ipw2100-admin@linux.intel.com>
26 * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
27 *
28 *****************************************************************************/
29
Emmanuel Grumbach1781a072008-06-30 17:23:09 +080030#include <linux/etherdevice.h>
Tomas Winklera55360e2008-05-05 10:22:28 +080031#include <net/mac80211.h>
32#include "iwl-eeprom.h"
33#include "iwl-dev.h"
34#include "iwl-core.h"
35#include "iwl-sta.h"
36#include "iwl-io.h"
Tomas Winklerc1354752008-05-29 16:35:04 +080037#include "iwl-calib.h"
Tomas Winklera55360e2008-05-05 10:22:28 +080038#include "iwl-helpers.h"
39/************************** RX-FUNCTIONS ****************************/
40/*
41 * Rx theory of operation
42 *
43 * Driver allocates a circular buffer of Receive Buffer Descriptors (RBDs),
44 * each of which point to Receive Buffers to be filled by the NIC. These get
45 * used not only for Rx frames, but for any command response or notification
46 * from the NIC. The driver and NIC manage the Rx buffers by means
47 * of indexes into the circular buffer.
48 *
49 * Rx Queue Indexes
50 * The host/firmware share two index registers for managing the Rx buffers.
51 *
52 * The READ index maps to the first position that the firmware may be writing
53 * to -- the driver can read up to (but not including) this position and get
54 * good data.
55 * The READ index is managed by the firmware once the card is enabled.
56 *
57 * The WRITE index maps to the last position the driver has read from -- the
58 * position preceding WRITE is the last slot the firmware can place a packet.
59 *
60 * The queue is empty (no good data) if WRITE = READ - 1, and is full if
61 * WRITE = READ.
62 *
63 * During initialization, the host sets up the READ queue position to the first
64 * INDEX position, and WRITE to the last (READ - 1 wrapped)
65 *
66 * When the firmware places a packet in a buffer, it will advance the READ index
67 * and fire the RX interrupt. The driver can then query the READ index and
68 * process as many packets as possible, moving the WRITE index forward as it
69 * resets the Rx queue buffers with new memory.
70 *
71 * The management in the driver is as follows:
72 * + A list of pre-allocated SKBs is stored in iwl->rxq->rx_free. When
73 * iwl->rxq->free_count drops to or below RX_LOW_WATERMARK, work is scheduled
74 * to replenish the iwl->rxq->rx_free.
75 * + In iwl_rx_replenish (scheduled) if 'processed' != 'read' then the
76 * iwl->rxq is replenished and the READ INDEX is updated (updating the
77 * 'processed' and 'read' driver indexes as well)
78 * + A received packet is processed and handed to the kernel network stack,
79 * detached from the iwl->rxq. The driver 'processed' index is updated.
80 * + The Host/Firmware iwl->rxq is replenished at tasklet time from the rx_free
81 * list. If there are no allocated buffers in iwl->rxq->rx_free, the READ
82 * INDEX is not incremented and iwl->status(RX_STALLED) is set. If there
83 * were enough free buffers and RX_STALLED is set it is cleared.
84 *
85 *
86 * Driver sequence:
87 *
88 * iwl_rx_queue_alloc() Allocates rx_free
89 * iwl_rx_replenish() Replenishes rx_free list from rx_used, and calls
90 * iwl_rx_queue_restock
91 * iwl_rx_queue_restock() Moves available buffers from rx_free into Rx
92 * queue, updates firmware pointers, and updates
93 * the WRITE index. If insufficient rx_free buffers
94 * are available, schedules iwl_rx_replenish
95 *
96 * -- enable interrupts --
97 * ISR - iwl_rx() Detach iwl_rx_mem_buffers from pool up to the
98 * READ INDEX, detaching the SKB from the pool.
99 * Moves the packet buffer from queue to rx_used.
100 * Calls iwl_rx_queue_restock to refill any empty
101 * slots.
102 * ...
103 *
104 */
105
106/**
107 * iwl_rx_queue_space - Return number of free slots available in queue.
108 */
109int iwl_rx_queue_space(const struct iwl_rx_queue *q)
110{
111 int s = q->read - q->write;
112 if (s <= 0)
113 s += RX_QUEUE_SIZE;
114 /* keep some buffer to not confuse full and empty queue */
115 s -= 2;
116 if (s < 0)
117 s = 0;
118 return s;
119}
120EXPORT_SYMBOL(iwl_rx_queue_space);
121
122/**
123 * iwl_rx_queue_update_write_ptr - Update the write pointer for the RX queue
124 */
125int iwl_rx_queue_update_write_ptr(struct iwl_priv *priv, struct iwl_rx_queue *q)
126{
127 u32 reg = 0;
128 int ret = 0;
129 unsigned long flags;
130
131 spin_lock_irqsave(&q->lock, flags);
132
133 if (q->need_update == 0)
134 goto exit_unlock;
135
136 /* If power-saving is in use, make sure device is awake */
137 if (test_bit(STATUS_POWER_PMI, &priv->status)) {
138 reg = iwl_read32(priv, CSR_UCODE_DRV_GP1);
139
140 if (reg & CSR_UCODE_DRV_GP1_BIT_MAC_SLEEP) {
141 iwl_set_bit(priv, CSR_GP_CNTRL,
142 CSR_GP_CNTRL_REG_FLAG_MAC_ACCESS_REQ);
143 goto exit_unlock;
144 }
145
146 ret = iwl_grab_nic_access(priv);
147 if (ret)
148 goto exit_unlock;
149
150 /* Device expects a multiple of 8 */
151 iwl_write_direct32(priv, FH_RSCSR_CHNL0_WPTR,
152 q->write & ~0x7);
153 iwl_release_nic_access(priv);
154
155 /* Else device is assumed to be awake */
156 } else
157 /* Device expects a multiple of 8 */
158 iwl_write32(priv, FH_RSCSR_CHNL0_WPTR, q->write & ~0x7);
159
160
161 q->need_update = 0;
162
163 exit_unlock:
164 spin_unlock_irqrestore(&q->lock, flags);
165 return ret;
166}
167EXPORT_SYMBOL(iwl_rx_queue_update_write_ptr);
168/**
169 * iwl_dma_addr2rbd_ptr - convert a DMA address to a uCode read buffer ptr
170 */
171static inline __le32 iwl_dma_addr2rbd_ptr(struct iwl_priv *priv,
172 dma_addr_t dma_addr)
173{
174 return cpu_to_le32((u32)(dma_addr >> 8));
175}
176
177/**
178 * iwl_rx_queue_restock - refill RX queue from pre-allocated pool
179 *
180 * If there are slots in the RX queue that need to be restocked,
181 * and we have free pre-allocated buffers, fill the ranks as much
182 * as we can, pulling from rx_free.
183 *
184 * This moves the 'write' index forward to catch up with 'processed', and
185 * also updates the memory address in the firmware to reference the new
186 * target buffer.
187 */
188int iwl_rx_queue_restock(struct iwl_priv *priv)
189{
190 struct iwl_rx_queue *rxq = &priv->rxq;
191 struct list_head *element;
192 struct iwl_rx_mem_buffer *rxb;
193 unsigned long flags;
194 int write;
195 int ret = 0;
196
197 spin_lock_irqsave(&rxq->lock, flags);
198 write = rxq->write & ~0x7;
199 while ((iwl_rx_queue_space(rxq) > 0) && (rxq->free_count)) {
200 /* Get next free Rx buffer, remove from free list */
201 element = rxq->rx_free.next;
202 rxb = list_entry(element, struct iwl_rx_mem_buffer, list);
203 list_del(element);
204
205 /* Point to Rx buffer via next RBD in circular buffer */
206 rxq->bd[rxq->write] = iwl_dma_addr2rbd_ptr(priv, rxb->dma_addr);
207 rxq->queue[rxq->write] = rxb;
208 rxq->write = (rxq->write + 1) & RX_QUEUE_MASK;
209 rxq->free_count--;
210 }
211 spin_unlock_irqrestore(&rxq->lock, flags);
212 /* If the pre-allocated buffer pool is dropping low, schedule to
213 * refill it */
214 if (rxq->free_count <= RX_LOW_WATERMARK)
215 queue_work(priv->workqueue, &priv->rx_replenish);
216
217
218 /* If we've added more space for the firmware to place data, tell it.
219 * Increment device's write pointer in multiples of 8. */
220 if ((write != (rxq->write & ~0x7))
221 || (abs(rxq->write - rxq->read) > 7)) {
222 spin_lock_irqsave(&rxq->lock, flags);
223 rxq->need_update = 1;
224 spin_unlock_irqrestore(&rxq->lock, flags);
225 ret = iwl_rx_queue_update_write_ptr(priv, rxq);
226 }
227
228 return ret;
229}
230EXPORT_SYMBOL(iwl_rx_queue_restock);
231
232
233/**
234 * iwl_rx_replenish - Move all used packet from rx_used to rx_free
235 *
236 * When moving to rx_free an SKB is allocated for the slot.
237 *
238 * Also restock the Rx queue via iwl_rx_queue_restock.
239 * This is called as a scheduled work item (except for during initialization)
240 */
241void iwl_rx_allocate(struct iwl_priv *priv)
242{
243 struct iwl_rx_queue *rxq = &priv->rxq;
244 struct list_head *element;
245 struct iwl_rx_mem_buffer *rxb;
246 unsigned long flags;
247 spin_lock_irqsave(&rxq->lock, flags);
248 while (!list_empty(&rxq->rx_used)) {
249 element = rxq->rx_used.next;
250 rxb = list_entry(element, struct iwl_rx_mem_buffer, list);
251
252 /* Alloc a new receive buffer */
253 rxb->skb = alloc_skb(priv->hw_params.rx_buf_size,
254 __GFP_NOWARN | GFP_ATOMIC);
255 if (!rxb->skb) {
256 if (net_ratelimit())
257 printk(KERN_CRIT DRV_NAME
258 ": Can not allocate SKB buffers\n");
259 /* We don't reschedule replenish work here -- we will
260 * call the restock method and if it still needs
261 * more buffers it will schedule replenish */
262 break;
263 }
264 priv->alloc_rxb_skb++;
265 list_del(element);
266
267 /* Get physical address of RB/SKB */
268 rxb->dma_addr =
269 pci_map_single(priv->pci_dev, rxb->skb->data,
270 priv->hw_params.rx_buf_size, PCI_DMA_FROMDEVICE);
271 list_add_tail(&rxb->list, &rxq->rx_free);
272 rxq->free_count++;
273 }
274 spin_unlock_irqrestore(&rxq->lock, flags);
275}
276EXPORT_SYMBOL(iwl_rx_allocate);
277
278void iwl_rx_replenish(struct iwl_priv *priv)
279{
280 unsigned long flags;
281
282 iwl_rx_allocate(priv);
283
284 spin_lock_irqsave(&priv->lock, flags);
285 iwl_rx_queue_restock(priv);
286 spin_unlock_irqrestore(&priv->lock, flags);
287}
288EXPORT_SYMBOL(iwl_rx_replenish);
289
290
291/* Assumes that the skb field of the buffers in 'pool' is kept accurate.
292 * If an SKB has been detached, the POOL needs to have its SKB set to NULL
293 * This free routine walks the list of POOL entries and if SKB is set to
294 * non NULL it is unmapped and freed
295 */
296void iwl_rx_queue_free(struct iwl_priv *priv, struct iwl_rx_queue *rxq)
297{
298 int i;
299 for (i = 0; i < RX_QUEUE_SIZE + RX_FREE_BUFFERS; i++) {
300 if (rxq->pool[i].skb != NULL) {
301 pci_unmap_single(priv->pci_dev,
302 rxq->pool[i].dma_addr,
303 priv->hw_params.rx_buf_size,
304 PCI_DMA_FROMDEVICE);
305 dev_kfree_skb(rxq->pool[i].skb);
306 }
307 }
308
309 pci_free_consistent(priv->pci_dev, 4 * RX_QUEUE_SIZE, rxq->bd,
310 rxq->dma_addr);
311 rxq->bd = NULL;
312}
313EXPORT_SYMBOL(iwl_rx_queue_free);
314
315int iwl_rx_queue_alloc(struct iwl_priv *priv)
316{
317 struct iwl_rx_queue *rxq = &priv->rxq;
318 struct pci_dev *dev = priv->pci_dev;
319 int i;
320
321 spin_lock_init(&rxq->lock);
322 INIT_LIST_HEAD(&rxq->rx_free);
323 INIT_LIST_HEAD(&rxq->rx_used);
324
325 /* Alloc the circular buffer of Read Buffer Descriptors (RBDs) */
326 rxq->bd = pci_alloc_consistent(dev, 4 * RX_QUEUE_SIZE, &rxq->dma_addr);
327 if (!rxq->bd)
328 return -ENOMEM;
329
330 /* Fill the rx_used queue with _all_ of the Rx buffers */
331 for (i = 0; i < RX_FREE_BUFFERS + RX_QUEUE_SIZE; i++)
332 list_add_tail(&rxq->pool[i].list, &rxq->rx_used);
333
334 /* Set us so that we have processed and used all buffers, but have
335 * not restocked the Rx queue with fresh buffers */
336 rxq->read = rxq->write = 0;
337 rxq->free_count = 0;
338 rxq->need_update = 0;
339 return 0;
340}
341EXPORT_SYMBOL(iwl_rx_queue_alloc);
342
343void iwl_rx_queue_reset(struct iwl_priv *priv, struct iwl_rx_queue *rxq)
344{
345 unsigned long flags;
346 int i;
347 spin_lock_irqsave(&rxq->lock, flags);
348 INIT_LIST_HEAD(&rxq->rx_free);
349 INIT_LIST_HEAD(&rxq->rx_used);
350 /* Fill the rx_used queue with _all_ of the Rx buffers */
351 for (i = 0; i < RX_FREE_BUFFERS + RX_QUEUE_SIZE; i++) {
352 /* In the reset function, these buffers may have been allocated
353 * to an SKB, so we need to unmap and free potential storage */
354 if (rxq->pool[i].skb != NULL) {
355 pci_unmap_single(priv->pci_dev,
356 rxq->pool[i].dma_addr,
357 priv->hw_params.rx_buf_size,
358 PCI_DMA_FROMDEVICE);
359 priv->alloc_rxb_skb--;
360 dev_kfree_skb(rxq->pool[i].skb);
361 rxq->pool[i].skb = NULL;
362 }
363 list_add_tail(&rxq->pool[i].list, &rxq->rx_used);
364 }
365
366 /* Set us so that we have processed and used all buffers, but have
367 * not restocked the Rx queue with fresh buffers */
368 rxq->read = rxq->write = 0;
369 rxq->free_count = 0;
370 spin_unlock_irqrestore(&rxq->lock, flags);
371}
372EXPORT_SYMBOL(iwl_rx_queue_reset);
373
Ron Rindjunsky1053d352008-05-05 10:22:43 +0800374int iwl_rx_init(struct iwl_priv *priv, struct iwl_rx_queue *rxq)
375{
376 int ret;
377 unsigned long flags;
378 unsigned int rb_size;
379
380 spin_lock_irqsave(&priv->lock, flags);
381 ret = iwl_grab_nic_access(priv);
382 if (ret) {
383 spin_unlock_irqrestore(&priv->lock, flags);
384 return ret;
385 }
386
387 if (priv->cfg->mod_params->amsdu_size_8K)
388 rb_size = FH_RCSR_RX_CONFIG_REG_VAL_RB_SIZE_8K;
389 else
390 rb_size = FH_RCSR_RX_CONFIG_REG_VAL_RB_SIZE_4K;
391
392 /* Stop Rx DMA */
393 iwl_write_direct32(priv, FH_MEM_RCSR_CHNL0_CONFIG_REG, 0);
394
395 /* Reset driver's Rx queue write index */
396 iwl_write_direct32(priv, FH_RSCSR_CHNL0_RBDCB_WPTR_REG, 0);
397
398 /* Tell device where to find RBD circular buffer in DRAM */
399 iwl_write_direct32(priv, FH_RSCSR_CHNL0_RBDCB_BASE_REG,
400 rxq->dma_addr >> 8);
401
402 /* Tell device where in DRAM to update its Rx status */
403 iwl_write_direct32(priv, FH_RSCSR_CHNL0_STTS_WPTR_REG,
Ron Rindjunskyd67f5482008-05-05 10:22:49 +0800404 (priv->shared_phys + priv->rb_closed_offset) >> 4);
Ron Rindjunsky1053d352008-05-05 10:22:43 +0800405
406 /* Enable Rx DMA, enable host interrupt, Rx buffer size 4k, 256 RBDs */
407 iwl_write_direct32(priv, FH_MEM_RCSR_CHNL0_CONFIG_REG,
408 FH_RCSR_RX_CONFIG_CHNL_EN_ENABLE_VAL |
409 FH_RCSR_CHNL0_RX_CONFIG_IRQ_DEST_INT_HOST_VAL |
410 rb_size |
411 /* 0x10 << 4 | */
412 (RX_QUEUE_SIZE_LOG <<
413 FH_RCSR_RX_CONFIG_RBDCB_SIZE_BITSHIFT));
414
415 /*
416 * iwl_write32(priv,CSR_INT_COAL_REG,0);
417 */
418
419 iwl_release_nic_access(priv);
420 spin_unlock_irqrestore(&priv->lock, flags);
421
422 return 0;
423}
424
Tomas Winklerb3bbacb2008-05-29 16:35:01 +0800425int iwl_rxq_stop(struct iwl_priv *priv)
426{
427 int ret;
428 unsigned long flags;
429
430 spin_lock_irqsave(&priv->lock, flags);
431 ret = iwl_grab_nic_access(priv);
432 if (unlikely(ret)) {
433 spin_unlock_irqrestore(&priv->lock, flags);
434 return ret;
435 }
436
437 /* stop Rx DMA */
438 iwl_write_direct32(priv, FH_MEM_RCSR_CHNL0_CONFIG_REG, 0);
439 ret = iwl_poll_direct_bit(priv, FH_MEM_RSSR_RX_STATUS_REG,
440 (1 << 24), 1000);
441 if (ret < 0)
442 IWL_ERROR("Can't stop Rx DMA.\n");
443
444 iwl_release_nic_access(priv);
445 spin_unlock_irqrestore(&priv->lock, flags);
446
447 return 0;
448}
449EXPORT_SYMBOL(iwl_rxq_stop);
450
Tomas Winklerc1354752008-05-29 16:35:04 +0800451void iwl_rx_missed_beacon_notif(struct iwl_priv *priv,
452 struct iwl_rx_mem_buffer *rxb)
453
454{
Tomas Winklerc1354752008-05-29 16:35:04 +0800455 struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
456 struct iwl4965_missed_beacon_notif *missed_beacon;
457
458 missed_beacon = &pkt->u.missed_beacon;
459 if (le32_to_cpu(missed_beacon->consequtive_missed_beacons) > 5) {
460 IWL_DEBUG_CALIB("missed bcn cnsq %d totl %d rcd %d expctd %d\n",
461 le32_to_cpu(missed_beacon->consequtive_missed_beacons),
462 le32_to_cpu(missed_beacon->total_missed_becons),
463 le32_to_cpu(missed_beacon->num_recvd_beacons),
464 le32_to_cpu(missed_beacon->num_expected_beacons));
465 if (!test_bit(STATUS_SCANNING, &priv->status))
466 iwl_init_sensitivity(priv);
467 }
Tomas Winklerc1354752008-05-29 16:35:04 +0800468}
469EXPORT_SYMBOL(iwl_rx_missed_beacon_notif);
Emmanuel Grumbach8f91aec2008-06-30 17:23:07 +0800470
471
472/* Calculate noise level, based on measurements during network silence just
473 * before arriving beacon. This measurement can be done only if we know
474 * exactly when to expect beacons, therefore only when we're associated. */
475static void iwl_rx_calc_noise(struct iwl_priv *priv)
476{
477 struct statistics_rx_non_phy *rx_info
478 = &(priv->statistics.rx.general);
479 int num_active_rx = 0;
480 int total_silence = 0;
481 int bcn_silence_a =
482 le32_to_cpu(rx_info->beacon_silence_rssi_a) & IN_BAND_FILTER;
483 int bcn_silence_b =
484 le32_to_cpu(rx_info->beacon_silence_rssi_b) & IN_BAND_FILTER;
485 int bcn_silence_c =
486 le32_to_cpu(rx_info->beacon_silence_rssi_c) & IN_BAND_FILTER;
487
488 if (bcn_silence_a) {
489 total_silence += bcn_silence_a;
490 num_active_rx++;
491 }
492 if (bcn_silence_b) {
493 total_silence += bcn_silence_b;
494 num_active_rx++;
495 }
496 if (bcn_silence_c) {
497 total_silence += bcn_silence_c;
498 num_active_rx++;
499 }
500
501 /* Average among active antennas */
502 if (num_active_rx)
503 priv->last_rx_noise = (total_silence / num_active_rx) - 107;
504 else
505 priv->last_rx_noise = IWL_NOISE_MEAS_NOT_AVAILABLE;
506
507 IWL_DEBUG_CALIB("inband silence a %u, b %u, c %u, dBm %d\n",
508 bcn_silence_a, bcn_silence_b, bcn_silence_c,
509 priv->last_rx_noise);
510}
511
512#define REG_RECALIB_PERIOD (60)
513
514void iwl_rx_statistics(struct iwl_priv *priv,
515 struct iwl_rx_mem_buffer *rxb)
516{
517 struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
518
519 IWL_DEBUG_RX("Statistics notification received (%d vs %d).\n",
520 (int)sizeof(priv->statistics), pkt->len);
521
522 memcpy(&priv->statistics, &pkt->u.stats, sizeof(priv->statistics));
523
524 set_bit(STATUS_STATISTICS, &priv->status);
525
526 /* Reschedule the statistics timer to occur in
527 * REG_RECALIB_PERIOD seconds to ensure we get a
528 * thermal update even if the uCode doesn't give
529 * us one */
530 mod_timer(&priv->statistics_periodic, jiffies +
531 msecs_to_jiffies(REG_RECALIB_PERIOD * 1000));
532
533 if (unlikely(!test_bit(STATUS_SCANNING, &priv->status)) &&
534 (pkt->hdr.cmd == STATISTICS_NOTIFICATION)) {
535 iwl_rx_calc_noise(priv);
536 queue_work(priv->workqueue, &priv->run_time_calib_work);
537 }
538
539 iwl_leds_background(priv);
540
541 if (priv->cfg->ops->lib->temperature)
542 priv->cfg->ops->lib->temperature(priv, &pkt->u.stats);
543}
544EXPORT_SYMBOL(iwl_rx_statistics);
Emmanuel Grumbach1781a072008-06-30 17:23:09 +0800545
546#define PERFECT_RSSI (-20) /* dBm */
547#define WORST_RSSI (-95) /* dBm */
548#define RSSI_RANGE (PERFECT_RSSI - WORST_RSSI)
549
550/* Calculate an indication of rx signal quality (a percentage, not dBm!).
551 * See http://www.ces.clemson.edu/linux/signal_quality.shtml for info
552 * about formulas used below. */
553static int iwl_calc_sig_qual(int rssi_dbm, int noise_dbm)
554{
555 int sig_qual;
556 int degradation = PERFECT_RSSI - rssi_dbm;
557
558 /* If we get a noise measurement, use signal-to-noise ratio (SNR)
559 * as indicator; formula is (signal dbm - noise dbm).
560 * SNR at or above 40 is a great signal (100%).
561 * Below that, scale to fit SNR of 0 - 40 dB within 0 - 100% indicator.
562 * Weakest usable signal is usually 10 - 15 dB SNR. */
563 if (noise_dbm) {
564 if (rssi_dbm - noise_dbm >= 40)
565 return 100;
566 else if (rssi_dbm < noise_dbm)
567 return 0;
568 sig_qual = ((rssi_dbm - noise_dbm) * 5) / 2;
569
570 /* Else use just the signal level.
571 * This formula is a least squares fit of data points collected and
572 * compared with a reference system that had a percentage (%) display
573 * for signal quality. */
574 } else
575 sig_qual = (100 * (RSSI_RANGE * RSSI_RANGE) - degradation *
576 (15 * RSSI_RANGE + 62 * degradation)) /
577 (RSSI_RANGE * RSSI_RANGE);
578
579 if (sig_qual > 100)
580 sig_qual = 100;
581 else if (sig_qual < 1)
582 sig_qual = 0;
583
584 return sig_qual;
585}
586
587#ifdef CONFIG_IWLWIFI_DEBUG
588
589/**
590 * iwl_dbg_report_frame - dump frame to syslog during debug sessions
591 *
592 * You may hack this function to show different aspects of received frames,
593 * including selective frame dumps.
594 * group100 parameter selects whether to show 1 out of 100 good frames.
595 *
596 * TODO: This was originally written for 3945, need to audit for
597 * proper operation with 4965.
598 */
599static void iwl_dbg_report_frame(struct iwl_priv *priv,
600 struct iwl_rx_packet *pkt,
601 struct ieee80211_hdr *header, int group100)
602{
603 u32 to_us;
604 u32 print_summary = 0;
605 u32 print_dump = 0; /* set to 1 to dump all frames' contents */
606 u32 hundred = 0;
607 u32 dataframe = 0;
608 __le16 fc;
609 u16 seq_ctl;
610 u16 channel;
611 u16 phy_flags;
612 int rate_sym;
613 u16 length;
614 u16 status;
615 u16 bcn_tmr;
616 u32 tsf_low;
617 u64 tsf;
618 u8 rssi;
619 u8 agc;
620 u16 sig_avg;
621 u16 noise_diff;
622 struct iwl4965_rx_frame_stats *rx_stats = IWL_RX_STATS(pkt);
623 struct iwl4965_rx_frame_hdr *rx_hdr = IWL_RX_HDR(pkt);
624 struct iwl4965_rx_frame_end *rx_end = IWL_RX_END(pkt);
625 u8 *data = IWL_RX_DATA(pkt);
626
627 if (likely(!(priv->debug_level & IWL_DL_RX)))
628 return;
629
630 /* MAC header */
631 fc = header->frame_control;
632 seq_ctl = le16_to_cpu(header->seq_ctrl);
633
634 /* metadata */
635 channel = le16_to_cpu(rx_hdr->channel);
636 phy_flags = le16_to_cpu(rx_hdr->phy_flags);
637 rate_sym = rx_hdr->rate;
638 length = le16_to_cpu(rx_hdr->len);
639
640 /* end-of-frame status and timestamp */
641 status = le32_to_cpu(rx_end->status);
642 bcn_tmr = le32_to_cpu(rx_end->beacon_timestamp);
643 tsf_low = le64_to_cpu(rx_end->timestamp) & 0x0ffffffff;
644 tsf = le64_to_cpu(rx_end->timestamp);
645
646 /* signal statistics */
647 rssi = rx_stats->rssi;
648 agc = rx_stats->agc;
649 sig_avg = le16_to_cpu(rx_stats->sig_avg);
650 noise_diff = le16_to_cpu(rx_stats->noise_diff);
651
652 to_us = !compare_ether_addr(header->addr1, priv->mac_addr);
653
654 /* if data frame is to us and all is good,
655 * (optionally) print summary for only 1 out of every 100 */
656 if (to_us && (fc & ~cpu_to_le16(IEEE80211_FCTL_PROTECTED)) ==
657 cpu_to_le16(IEEE80211_FCTL_FROMDS | IEEE80211_FTYPE_DATA)) {
658 dataframe = 1;
659 if (!group100)
660 print_summary = 1; /* print each frame */
661 else if (priv->framecnt_to_us < 100) {
662 priv->framecnt_to_us++;
663 print_summary = 0;
664 } else {
665 priv->framecnt_to_us = 0;
666 print_summary = 1;
667 hundred = 1;
668 }
669 } else {
670 /* print summary for all other frames */
671 print_summary = 1;
672 }
673
674 if (print_summary) {
675 char *title;
676 int rate_idx;
677 u32 bitrate;
678
679 if (hundred)
680 title = "100Frames";
681 else if (ieee80211_has_retry(fc))
682 title = "Retry";
683 else if (ieee80211_is_assoc_resp(fc))
684 title = "AscRsp";
685 else if (ieee80211_is_reassoc_resp(fc))
686 title = "RasRsp";
687 else if (ieee80211_is_probe_resp(fc)) {
688 title = "PrbRsp";
689 print_dump = 1; /* dump frame contents */
690 } else if (ieee80211_is_beacon(fc)) {
691 title = "Beacon";
692 print_dump = 1; /* dump frame contents */
693 } else if (ieee80211_is_atim(fc))
694 title = "ATIM";
695 else if (ieee80211_is_auth(fc))
696 title = "Auth";
697 else if (ieee80211_is_deauth(fc))
698 title = "DeAuth";
699 else if (ieee80211_is_disassoc(fc))
700 title = "DisAssoc";
701 else
702 title = "Frame";
703
704 rate_idx = iwl_hwrate_to_plcp_idx(rate_sym);
705 if (unlikely(rate_idx == -1))
706 bitrate = 0;
707 else
708 bitrate = iwl_rates[rate_idx].ieee / 2;
709
710 /* print frame summary.
711 * MAC addresses show just the last byte (for brevity),
712 * but you can hack it to show more, if you'd like to. */
713 if (dataframe)
714 IWL_DEBUG_RX("%s: mhd=0x%04x, dst=0x%02x, "
715 "len=%u, rssi=%d, chnl=%d, rate=%u, \n",
716 title, le16_to_cpu(fc), header->addr1[5],
717 length, rssi, channel, bitrate);
718 else {
719 /* src/dst addresses assume managed mode */
720 IWL_DEBUG_RX("%s: 0x%04x, dst=0x%02x, "
721 "src=0x%02x, rssi=%u, tim=%lu usec, "
722 "phy=0x%02x, chnl=%d\n",
723 title, le16_to_cpu(fc), header->addr1[5],
724 header->addr3[5], rssi,
725 tsf_low - priv->scan_start_tsf,
726 phy_flags, channel);
727 }
728 }
729 if (print_dump)
730 iwl_print_hex_dump(priv, IWL_DL_RX, data, length);
731}
732#else
733static inline void iwl_dbg_report_frame(struct iwl_priv *priv,
734 struct iwl_rx_packet *pkt,
735 struct ieee80211_hdr *header,
736 int group100)
737{
738}
739#endif
740
741static void iwl_add_radiotap(struct iwl_priv *priv,
742 struct sk_buff *skb,
743 struct iwl4965_rx_phy_res *rx_start,
744 struct ieee80211_rx_status *stats,
745 u32 ampdu_status)
746{
747 s8 signal = stats->signal;
748 s8 noise = 0;
749 int rate = stats->rate_idx;
750 u64 tsf = stats->mactime;
751 __le16 antenna;
752 __le16 phy_flags_hw = rx_start->phy_flags;
753 struct iwl4965_rt_rx_hdr {
754 struct ieee80211_radiotap_header rt_hdr;
755 __le64 rt_tsf; /* TSF */
756 u8 rt_flags; /* radiotap packet flags */
757 u8 rt_rate; /* rate in 500kb/s */
758 __le16 rt_channelMHz; /* channel in MHz */
759 __le16 rt_chbitmask; /* channel bitfield */
760 s8 rt_dbmsignal; /* signal in dBm, kluged to signed */
761 s8 rt_dbmnoise;
762 u8 rt_antenna; /* antenna number */
763 } __attribute__ ((packed)) *iwl4965_rt;
764
765 /* TODO: We won't have enough headroom for HT frames. Fix it later. */
766 if (skb_headroom(skb) < sizeof(*iwl4965_rt)) {
767 if (net_ratelimit())
768 printk(KERN_ERR "not enough headroom [%d] for "
769 "radiotap head [%zd]\n",
770 skb_headroom(skb), sizeof(*iwl4965_rt));
771 return;
772 }
773
774 /* put radiotap header in front of 802.11 header and data */
775 iwl4965_rt = (void *)skb_push(skb, sizeof(*iwl4965_rt));
776
777 /* initialise radiotap header */
778 iwl4965_rt->rt_hdr.it_version = PKTHDR_RADIOTAP_VERSION;
779 iwl4965_rt->rt_hdr.it_pad = 0;
780
781 /* total header + data */
782 put_unaligned(cpu_to_le16(sizeof(*iwl4965_rt)),
783 &iwl4965_rt->rt_hdr.it_len);
784
785 /* Indicate all the fields we add to the radiotap header */
786 put_unaligned(cpu_to_le32((1 << IEEE80211_RADIOTAP_TSFT) |
787 (1 << IEEE80211_RADIOTAP_FLAGS) |
788 (1 << IEEE80211_RADIOTAP_RATE) |
789 (1 << IEEE80211_RADIOTAP_CHANNEL) |
790 (1 << IEEE80211_RADIOTAP_DBM_ANTSIGNAL) |
791 (1 << IEEE80211_RADIOTAP_DBM_ANTNOISE) |
792 (1 << IEEE80211_RADIOTAP_ANTENNA)),
793 &iwl4965_rt->rt_hdr.it_present);
794
795 /* Zero the flags, we'll add to them as we go */
796 iwl4965_rt->rt_flags = 0;
797
798 put_unaligned(cpu_to_le64(tsf), &iwl4965_rt->rt_tsf);
799
800 iwl4965_rt->rt_dbmsignal = signal;
801 iwl4965_rt->rt_dbmnoise = noise;
802
803 /* Convert the channel frequency and set the flags */
804 put_unaligned(cpu_to_le16(stats->freq), &iwl4965_rt->rt_channelMHz);
805 if (!(phy_flags_hw & RX_RES_PHY_FLAGS_BAND_24_MSK))
806 put_unaligned(cpu_to_le16(IEEE80211_CHAN_OFDM |
807 IEEE80211_CHAN_5GHZ),
808 &iwl4965_rt->rt_chbitmask);
809 else if (phy_flags_hw & RX_RES_PHY_FLAGS_MOD_CCK_MSK)
810 put_unaligned(cpu_to_le16(IEEE80211_CHAN_CCK |
811 IEEE80211_CHAN_2GHZ),
812 &iwl4965_rt->rt_chbitmask);
813 else /* 802.11g */
814 put_unaligned(cpu_to_le16(IEEE80211_CHAN_OFDM |
815 IEEE80211_CHAN_2GHZ),
816 &iwl4965_rt->rt_chbitmask);
817
818 if (rate == -1)
819 iwl4965_rt->rt_rate = 0;
820 else
821 iwl4965_rt->rt_rate = iwl_rates[rate].ieee;
822
823 /*
824 * "antenna number"
825 *
826 * It seems that the antenna field in the phy flags value
827 * is actually a bitfield. This is undefined by radiotap,
828 * it wants an actual antenna number but I always get "7"
829 * for most legacy frames I receive indicating that the
830 * same frame was received on all three RX chains.
831 *
832 * I think this field should be removed in favour of a
833 * new 802.11n radiotap field "RX chains" that is defined
834 * as a bitmask.
835 */
836 antenna = phy_flags_hw & RX_RES_PHY_FLAGS_ANTENNA_MSK;
837 iwl4965_rt->rt_antenna = le16_to_cpu(antenna) >> 4;
838
839 /* set the preamble flag if appropriate */
840 if (phy_flags_hw & RX_RES_PHY_FLAGS_SHORT_PREAMBLE_MSK)
841 iwl4965_rt->rt_flags |= IEEE80211_RADIOTAP_F_SHORTPRE;
842
843 stats->flag |= RX_FLAG_RADIOTAP;
844}
845
846static void iwl_update_rx_stats(struct iwl_priv *priv, u16 fc, u16 len)
847{
848 /* 0 - mgmt, 1 - cnt, 2 - data */
849 int idx = (fc & IEEE80211_FCTL_FTYPE) >> 2;
850 priv->rx_stats[idx].cnt++;
851 priv->rx_stats[idx].bytes += len;
852}
853
854/*
855 * returns non-zero if packet should be dropped
856 */
857static int iwl_set_decrypted_flag(struct iwl_priv *priv,
858 struct ieee80211_hdr *hdr,
859 u32 decrypt_res,
860 struct ieee80211_rx_status *stats)
861{
862 u16 fc = le16_to_cpu(hdr->frame_control);
863
864 if (priv->active_rxon.filter_flags & RXON_FILTER_DIS_DECRYPT_MSK)
865 return 0;
866
867 if (!(fc & IEEE80211_FCTL_PROTECTED))
868 return 0;
869
870 IWL_DEBUG_RX("decrypt_res:0x%x\n", decrypt_res);
871 switch (decrypt_res & RX_RES_STATUS_SEC_TYPE_MSK) {
872 case RX_RES_STATUS_SEC_TYPE_TKIP:
873 /* The uCode has got a bad phase 1 Key, pushes the packet.
874 * Decryption will be done in SW. */
875 if ((decrypt_res & RX_RES_STATUS_DECRYPT_TYPE_MSK) ==
876 RX_RES_STATUS_BAD_KEY_TTAK)
877 break;
878
879 case RX_RES_STATUS_SEC_TYPE_WEP:
880 if ((decrypt_res & RX_RES_STATUS_DECRYPT_TYPE_MSK) ==
881 RX_RES_STATUS_BAD_ICV_MIC) {
882 /* bad ICV, the packet is destroyed since the
883 * decryption is inplace, drop it */
884 IWL_DEBUG_RX("Packet destroyed\n");
885 return -1;
886 }
887 case RX_RES_STATUS_SEC_TYPE_CCMP:
888 if ((decrypt_res & RX_RES_STATUS_DECRYPT_TYPE_MSK) ==
889 RX_RES_STATUS_DECRYPT_OK) {
890 IWL_DEBUG_RX("hw decrypt successfully!!!\n");
891 stats->flag |= RX_FLAG_DECRYPTED;
892 }
893 break;
894
895 default:
896 break;
897 }
898 return 0;
899}
900
901static u32 iwl_translate_rx_status(struct iwl_priv *priv, u32 decrypt_in)
902{
903 u32 decrypt_out = 0;
904
905 if ((decrypt_in & RX_RES_STATUS_STATION_FOUND) ==
906 RX_RES_STATUS_STATION_FOUND)
907 decrypt_out |= (RX_RES_STATUS_STATION_FOUND |
908 RX_RES_STATUS_NO_STATION_INFO_MISMATCH);
909
910 decrypt_out |= (decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK);
911
912 /* packet was not encrypted */
913 if ((decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK) ==
914 RX_RES_STATUS_SEC_TYPE_NONE)
915 return decrypt_out;
916
917 /* packet was encrypted with unknown alg */
918 if ((decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK) ==
919 RX_RES_STATUS_SEC_TYPE_ERR)
920 return decrypt_out;
921
922 /* decryption was not done in HW */
923 if ((decrypt_in & RX_MPDU_RES_STATUS_DEC_DONE_MSK) !=
924 RX_MPDU_RES_STATUS_DEC_DONE_MSK)
925 return decrypt_out;
926
927 switch (decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK) {
928
929 case RX_RES_STATUS_SEC_TYPE_CCMP:
930 /* alg is CCM: check MIC only */
931 if (!(decrypt_in & RX_MPDU_RES_STATUS_MIC_OK))
932 /* Bad MIC */
933 decrypt_out |= RX_RES_STATUS_BAD_ICV_MIC;
934 else
935 decrypt_out |= RX_RES_STATUS_DECRYPT_OK;
936
937 break;
938
939 case RX_RES_STATUS_SEC_TYPE_TKIP:
940 if (!(decrypt_in & RX_MPDU_RES_STATUS_TTAK_OK)) {
941 /* Bad TTAK */
942 decrypt_out |= RX_RES_STATUS_BAD_KEY_TTAK;
943 break;
944 }
945 /* fall through if TTAK OK */
946 default:
947 if (!(decrypt_in & RX_MPDU_RES_STATUS_ICV_OK))
948 decrypt_out |= RX_RES_STATUS_BAD_ICV_MIC;
949 else
950 decrypt_out |= RX_RES_STATUS_DECRYPT_OK;
951 break;
952 };
953
954 IWL_DEBUG_RX("decrypt_in:0x%x decrypt_out = 0x%x\n",
955 decrypt_in, decrypt_out);
956
957 return decrypt_out;
958}
959
960static void iwl_handle_data_packet(struct iwl_priv *priv, int is_data,
961 int include_phy,
962 struct iwl_rx_mem_buffer *rxb,
963 struct ieee80211_rx_status *stats)
964{
965 struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
966 struct iwl4965_rx_phy_res *rx_start = (include_phy) ?
967 (struct iwl4965_rx_phy_res *)&(pkt->u.raw[0]) : NULL;
968 struct ieee80211_hdr *hdr;
969 u16 len;
970 __le32 *rx_end;
971 unsigned int skblen;
972 u32 ampdu_status;
973 u32 ampdu_status_legacy;
974
975 if (!include_phy && priv->last_phy_res[0])
976 rx_start = (struct iwl4965_rx_phy_res *)&priv->last_phy_res[1];
977
978 if (!rx_start) {
979 IWL_ERROR("MPDU frame without a PHY data\n");
980 return;
981 }
982 if (include_phy) {
983 hdr = (struct ieee80211_hdr *)((u8 *) &rx_start[1] +
984 rx_start->cfg_phy_cnt);
985
986 len = le16_to_cpu(rx_start->byte_count);
987
988 rx_end = (__le32 *) ((u8 *) &pkt->u.raw[0] +
989 sizeof(struct iwl4965_rx_phy_res) +
990 rx_start->cfg_phy_cnt + len);
991
992 } else {
993 struct iwl4965_rx_mpdu_res_start *amsdu =
994 (struct iwl4965_rx_mpdu_res_start *)pkt->u.raw;
995
996 hdr = (struct ieee80211_hdr *)(pkt->u.raw +
997 sizeof(struct iwl4965_rx_mpdu_res_start));
998 len = le16_to_cpu(amsdu->byte_count);
999 rx_start->byte_count = amsdu->byte_count;
1000 rx_end = (__le32 *) (((u8 *) hdr) + len);
1001 }
1002 /* In monitor mode allow 802.11 ACk frames (10 bytes) */
1003 if (len > priv->hw_params.max_pkt_size ||
1004 len < ((priv->iw_mode == IEEE80211_IF_TYPE_MNTR) ? 10 : 16)) {
1005 IWL_WARNING("byte count out of range [16,4K] : %d\n", len);
1006 return;
1007 }
1008
1009 ampdu_status = le32_to_cpu(*rx_end);
1010 skblen = ((u8 *) rx_end - (u8 *) &pkt->u.raw[0]) + sizeof(u32);
1011
1012 if (!include_phy) {
1013 /* New status scheme, need to translate */
1014 ampdu_status_legacy = ampdu_status;
1015 ampdu_status = iwl_translate_rx_status(priv, ampdu_status);
1016 }
1017
1018 /* start from MAC */
1019 skb_reserve(rxb->skb, (void *)hdr - (void *)pkt);
1020 skb_put(rxb->skb, len); /* end where data ends */
1021
1022 /* We only process data packets if the interface is open */
1023 if (unlikely(!priv->is_open)) {
1024 IWL_DEBUG_DROP_LIMIT
1025 ("Dropping packet while interface is not open.\n");
1026 return;
1027 }
1028
1029 stats->flag = 0;
1030 hdr = (struct ieee80211_hdr *)rxb->skb->data;
1031
1032 /* in case of HW accelerated crypto and bad decryption, drop */
1033 if (!priv->hw_params.sw_crypto &&
1034 iwl_set_decrypted_flag(priv, hdr, ampdu_status, stats))
1035 return;
1036
1037 if (priv->add_radiotap)
1038 iwl_add_radiotap(priv, rxb->skb, rx_start, stats, ampdu_status);
1039
1040 iwl_update_rx_stats(priv, le16_to_cpu(hdr->frame_control), len);
1041 ieee80211_rx_irqsafe(priv->hw, rxb->skb, stats);
1042 priv->alloc_rxb_skb--;
1043 rxb->skb = NULL;
1044}
1045
1046/* Calc max signal level (dBm) among 3 possible receivers */
1047static int iwl_calc_rssi(struct iwl_priv *priv,
1048 struct iwl4965_rx_phy_res *rx_resp)
1049{
1050 /* data from PHY/DSP regarding signal strength, etc.,
1051 * contents are always there, not configurable by host. */
1052 struct iwl4965_rx_non_cfg_phy *ncphy =
1053 (struct iwl4965_rx_non_cfg_phy *)rx_resp->non_cfg_phy;
1054 u32 agc = (le16_to_cpu(ncphy->agc_info) & IWL_AGC_DB_MASK)
1055 >> IWL_AGC_DB_POS;
1056
1057 u32 valid_antennae =
1058 (le16_to_cpu(rx_resp->phy_flags) & RX_PHY_FLAGS_ANTENNAE_MASK)
1059 >> RX_PHY_FLAGS_ANTENNAE_OFFSET;
1060 u8 max_rssi = 0;
1061 u32 i;
1062
1063 /* Find max rssi among 3 possible receivers.
1064 * These values are measured by the digital signal processor (DSP).
1065 * They should stay fairly constant even as the signal strength varies,
1066 * if the radio's automatic gain control (AGC) is working right.
1067 * AGC value (see below) will provide the "interesting" info. */
1068 for (i = 0; i < 3; i++)
1069 if (valid_antennae & (1 << i))
1070 max_rssi = max(ncphy->rssi_info[i << 1], max_rssi);
1071
1072 IWL_DEBUG_STATS("Rssi In A %d B %d C %d Max %d AGC dB %d\n",
1073 ncphy->rssi_info[0], ncphy->rssi_info[2], ncphy->rssi_info[4],
1074 max_rssi, agc);
1075
1076 /* dBm = max_rssi dB - agc dB - constant.
1077 * Higher AGC (higher radio gain) means lower signal. */
1078 return max_rssi - agc - IWL_RSSI_OFFSET;
1079}
1080
1081static void iwl_sta_modify_ps_wake(struct iwl_priv *priv, int sta_id)
1082{
1083 unsigned long flags;
1084
1085 spin_lock_irqsave(&priv->sta_lock, flags);
1086 priv->stations[sta_id].sta.station_flags &= ~STA_FLG_PWR_SAVE_MSK;
1087 priv->stations[sta_id].sta.station_flags_msk = STA_FLG_PWR_SAVE_MSK;
1088 priv->stations[sta_id].sta.sta.modify_mask = 0;
1089 priv->stations[sta_id].sta.mode = STA_CONTROL_MODIFY_MSK;
1090 spin_unlock_irqrestore(&priv->sta_lock, flags);
1091
1092 iwl_send_add_sta(priv, &priv->stations[sta_id].sta, CMD_ASYNC);
1093}
1094
1095static void iwl_update_ps_mode(struct iwl_priv *priv, u16 ps_bit, u8 *addr)
1096{
1097 /* FIXME: need locking over ps_status ??? */
1098 u8 sta_id = iwl_find_station(priv, addr);
1099
1100 if (sta_id != IWL_INVALID_STATION) {
1101 u8 sta_awake = priv->stations[sta_id].
1102 ps_status == STA_PS_STATUS_WAKE;
1103
1104 if (sta_awake && ps_bit)
1105 priv->stations[sta_id].ps_status = STA_PS_STATUS_SLEEP;
1106 else if (!sta_awake && !ps_bit) {
1107 iwl_sta_modify_ps_wake(priv, sta_id);
1108 priv->stations[sta_id].ps_status = STA_PS_STATUS_WAKE;
1109 }
1110 }
1111}
1112
1113#define IWL_PACKET_RETRY_TIME HZ
1114
1115static int iwl_is_duplicate_packet(struct iwl_priv *priv,
1116 struct ieee80211_hdr *header)
1117{
1118 u16 sc = le16_to_cpu(header->seq_ctrl);
1119 u16 seq = (sc & IEEE80211_SCTL_SEQ) >> 4;
1120 u16 frag = sc & IEEE80211_SCTL_FRAG;
1121 u16 *last_seq, *last_frag;
1122 unsigned long *last_time;
1123
1124 switch (priv->iw_mode) {
1125 case IEEE80211_IF_TYPE_IBSS:{
1126 struct list_head *p;
1127 struct iwl4965_ibss_seq *entry = NULL;
1128 u8 *mac = header->addr2;
1129 int index = mac[5] & (IWL_IBSS_MAC_HASH_SIZE - 1);
1130
1131 __list_for_each(p, &priv->ibss_mac_hash[index]) {
1132 entry = list_entry(p, struct iwl4965_ibss_seq, list);
1133 if (!compare_ether_addr(entry->mac, mac))
1134 break;
1135 }
1136 if (p == &priv->ibss_mac_hash[index]) {
1137 entry = kzalloc(sizeof(*entry), GFP_ATOMIC);
1138 if (!entry) {
1139 IWL_ERROR("Cannot malloc new mac entry\n");
1140 return 0;
1141 }
1142 memcpy(entry->mac, mac, ETH_ALEN);
1143 entry->seq_num = seq;
1144 entry->frag_num = frag;
1145 entry->packet_time = jiffies;
1146 list_add(&entry->list, &priv->ibss_mac_hash[index]);
1147 return 0;
1148 }
1149 last_seq = &entry->seq_num;
1150 last_frag = &entry->frag_num;
1151 last_time = &entry->packet_time;
1152 break;
1153 }
1154 case IEEE80211_IF_TYPE_STA:
1155 last_seq = &priv->last_seq_num;
1156 last_frag = &priv->last_frag_num;
1157 last_time = &priv->last_packet_time;
1158 break;
1159 default:
1160 return 0;
1161 }
1162 if ((*last_seq == seq) &&
1163 time_after(*last_time + IWL_PACKET_RETRY_TIME, jiffies)) {
1164 if (*last_frag == frag)
1165 goto drop;
1166 if (*last_frag + 1 != frag)
1167 /* out-of-order fragment */
1168 goto drop;
1169 } else
1170 *last_seq = seq;
1171
1172 *last_frag = frag;
1173 *last_time = jiffies;
1174 return 0;
1175
1176 drop:
1177 return 1;
1178}
1179
1180static int iwl_is_network_packet(struct iwl_priv *priv,
1181 struct ieee80211_hdr *header)
1182{
1183 /* Filter incoming packets to determine if they are targeted toward
1184 * this network, discarding packets coming from ourselves */
1185 switch (priv->iw_mode) {
1186 case IEEE80211_IF_TYPE_IBSS: /* Header: Dest. | Source | BSSID */
1187 /* packets from our adapter are dropped (echo) */
1188 if (!compare_ether_addr(header->addr2, priv->mac_addr))
1189 return 0;
1190 /* {broad,multi}cast packets to our IBSS go through */
1191 if (is_multicast_ether_addr(header->addr1))
1192 return !compare_ether_addr(header->addr3, priv->bssid);
1193 /* packets to our adapter go through */
1194 return !compare_ether_addr(header->addr1, priv->mac_addr);
1195 case IEEE80211_IF_TYPE_STA: /* Header: Dest. | AP{BSSID} | Source */
1196 /* packets from our adapter are dropped (echo) */
1197 if (!compare_ether_addr(header->addr3, priv->mac_addr))
1198 return 0;
1199 /* {broad,multi}cast packets to our BSS go through */
1200 if (is_multicast_ether_addr(header->addr1))
1201 return !compare_ether_addr(header->addr2, priv->bssid);
1202 /* packets to our adapter go through */
1203 return !compare_ether_addr(header->addr1, priv->mac_addr);
1204 default:
1205 break;
1206 }
1207
1208 return 1;
1209}
1210
1211/* Called for REPLY_RX (legacy ABG frames), or
1212 * REPLY_RX_MPDU_CMD (HT high-throughput N frames). */
1213void iwl_rx_reply_rx(struct iwl_priv *priv,
1214 struct iwl_rx_mem_buffer *rxb)
1215{
1216 struct ieee80211_hdr *header;
1217 struct ieee80211_rx_status rx_status;
1218 struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
1219 /* Use phy data (Rx signal strength, etc.) contained within
1220 * this rx packet for legacy frames,
1221 * or phy data cached from REPLY_RX_PHY_CMD for HT frames. */
1222 int include_phy = (pkt->hdr.cmd == REPLY_RX);
1223 struct iwl4965_rx_phy_res *rx_start = (include_phy) ?
1224 (struct iwl4965_rx_phy_res *)&(pkt->u.raw[0]) :
1225 (struct iwl4965_rx_phy_res *)&priv->last_phy_res[1];
1226 __le32 *rx_end;
1227 unsigned int len = 0;
1228 u16 fc;
1229 u8 network_packet;
1230
1231 rx_status.mactime = le64_to_cpu(rx_start->timestamp);
1232 rx_status.freq =
1233 ieee80211_channel_to_frequency(le16_to_cpu(rx_start->channel));
1234 rx_status.band = (rx_start->phy_flags & RX_RES_PHY_FLAGS_BAND_24_MSK) ?
1235 IEEE80211_BAND_2GHZ : IEEE80211_BAND_5GHZ;
1236 rx_status.rate_idx =
1237 iwl_hwrate_to_plcp_idx(le32_to_cpu(rx_start->rate_n_flags));
1238 if (rx_status.band == IEEE80211_BAND_5GHZ)
1239 rx_status.rate_idx -= IWL_FIRST_OFDM_RATE;
1240
1241 rx_status.antenna = 0;
1242 rx_status.flag = 0;
1243
1244 if ((unlikely(rx_start->cfg_phy_cnt > 20))) {
1245 IWL_DEBUG_DROP("dsp size out of range [0,20]: %d/n",
1246 rx_start->cfg_phy_cnt);
1247 return;
1248 }
1249
1250 if (!include_phy) {
1251 if (priv->last_phy_res[0])
1252 rx_start = (struct iwl4965_rx_phy_res *)
1253 &priv->last_phy_res[1];
1254 else
1255 rx_start = NULL;
1256 }
1257
1258 if (!rx_start) {
1259 IWL_ERROR("MPDU frame without a PHY data\n");
1260 return;
1261 }
1262
1263 if (include_phy) {
1264 header = (struct ieee80211_hdr *)((u8 *) &rx_start[1]
1265 + rx_start->cfg_phy_cnt);
1266
1267 len = le16_to_cpu(rx_start->byte_count);
1268 rx_end = (__le32 *)(pkt->u.raw + rx_start->cfg_phy_cnt +
1269 sizeof(struct iwl4965_rx_phy_res) + len);
1270 } else {
1271 struct iwl4965_rx_mpdu_res_start *amsdu =
1272 (struct iwl4965_rx_mpdu_res_start *)pkt->u.raw;
1273
1274 header = (void *)(pkt->u.raw +
1275 sizeof(struct iwl4965_rx_mpdu_res_start));
1276 len = le16_to_cpu(amsdu->byte_count);
1277 rx_end = (__le32 *) (pkt->u.raw +
1278 sizeof(struct iwl4965_rx_mpdu_res_start) + len);
1279 }
1280
1281 if (!(*rx_end & RX_RES_STATUS_NO_CRC32_ERROR) ||
1282 !(*rx_end & RX_RES_STATUS_NO_RXE_OVERFLOW)) {
1283 IWL_DEBUG_RX("Bad CRC or FIFO: 0x%08X.\n",
1284 le32_to_cpu(*rx_end));
1285 return;
1286 }
1287
1288 priv->ucode_beacon_time = le32_to_cpu(rx_start->beacon_time_stamp);
1289
1290 /* Find max signal strength (dBm) among 3 antenna/receiver chains */
1291 rx_status.signal = iwl_calc_rssi(priv, rx_start);
1292
1293 /* Meaningful noise values are available only from beacon statistics,
1294 * which are gathered only when associated, and indicate noise
1295 * only for the associated network channel ...
1296 * Ignore these noise values while scanning (other channels) */
1297 if (iwl_is_associated(priv) &&
1298 !test_bit(STATUS_SCANNING, &priv->status)) {
1299 rx_status.noise = priv->last_rx_noise;
1300 rx_status.qual = iwl_calc_sig_qual(rx_status.signal,
1301 rx_status.noise);
1302 } else {
1303 rx_status.noise = IWL_NOISE_MEAS_NOT_AVAILABLE;
1304 rx_status.qual = iwl_calc_sig_qual(rx_status.signal, 0);
1305 }
1306
1307 /* Reset beacon noise level if not associated. */
1308 if (!iwl_is_associated(priv))
1309 priv->last_rx_noise = IWL_NOISE_MEAS_NOT_AVAILABLE;
1310
1311 /* Set "1" to report good data frames in groups of 100 */
1312 /* FIXME: need to optimze the call: */
1313 iwl_dbg_report_frame(priv, pkt, header, 1);
1314
1315 IWL_DEBUG_STATS_LIMIT("Rssi %d, noise %d, qual %d, TSF %llu\n",
1316 rx_status.signal, rx_status.noise, rx_status.signal,
1317 (unsigned long long)rx_status.mactime);
1318
1319
1320 if (priv->iw_mode == IEEE80211_IF_TYPE_MNTR) {
1321 iwl_handle_data_packet(priv, 1, include_phy,
1322 rxb, &rx_status);
1323 return;
1324 }
1325
1326 network_packet = iwl_is_network_packet(priv, header);
1327 if (network_packet) {
1328 priv->last_rx_rssi = rx_status.signal;
1329 priv->last_beacon_time = priv->ucode_beacon_time;
1330 priv->last_tsf = le64_to_cpu(rx_start->timestamp);
1331 }
1332
1333 fc = le16_to_cpu(header->frame_control);
1334 switch (fc & IEEE80211_FCTL_FTYPE) {
1335 case IEEE80211_FTYPE_MGMT:
1336 if (priv->iw_mode == IEEE80211_IF_TYPE_AP)
1337 iwl_update_ps_mode(priv, fc & IEEE80211_FCTL_PM,
1338 header->addr2);
1339 iwl_handle_data_packet(priv, 0, include_phy, rxb, &rx_status);
1340 break;
1341
1342 case IEEE80211_FTYPE_CTL:
1343 switch (fc & IEEE80211_FCTL_STYPE) {
1344 case IEEE80211_STYPE_BACK_REQ:
1345 IWL_DEBUG_HT("IEEE80211_STYPE_BACK_REQ arrived\n");
1346 iwl_handle_data_packet(priv, 0, include_phy,
1347 rxb, &rx_status);
1348 break;
1349 default:
1350 break;
1351 }
1352 break;
1353
1354 case IEEE80211_FTYPE_DATA: {
1355 DECLARE_MAC_BUF(mac1);
1356 DECLARE_MAC_BUF(mac2);
1357 DECLARE_MAC_BUF(mac3);
1358
1359 if (priv->iw_mode == IEEE80211_IF_TYPE_AP)
1360 iwl_update_ps_mode(priv, fc & IEEE80211_FCTL_PM,
1361 header->addr2);
1362
1363 if (unlikely(!network_packet))
1364 IWL_DEBUG_DROP("Dropping (non network): "
1365 "%s, %s, %s\n",
1366 print_mac(mac1, header->addr1),
1367 print_mac(mac2, header->addr2),
1368 print_mac(mac3, header->addr3));
1369 else if (unlikely(iwl_is_duplicate_packet(priv, header)))
1370 IWL_DEBUG_DROP("Dropping (dup): %s, %s, %s\n",
1371 print_mac(mac1, header->addr1),
1372 print_mac(mac2, header->addr2),
1373 print_mac(mac3, header->addr3));
1374 else
1375 iwl_handle_data_packet(priv, 1, include_phy, rxb,
1376 &rx_status);
1377 break;
1378 }
1379 default:
1380 break;
1381
1382 }
1383}
1384EXPORT_SYMBOL(iwl_rx_reply_rx);
1385
1386/* Cache phy data (Rx signal strength, etc) for HT frame (REPLY_RX_PHY_CMD).
1387 * This will be used later in iwl_rx_reply_rx() for REPLY_RX_MPDU_CMD. */
1388void iwl_rx_reply_rx_phy(struct iwl_priv *priv,
1389 struct iwl_rx_mem_buffer *rxb)
1390{
1391 struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
1392 priv->last_phy_res[0] = 1;
1393 memcpy(&priv->last_phy_res[1], &(pkt->u.raw[0]),
1394 sizeof(struct iwl4965_rx_phy_res));
1395}
1396EXPORT_SYMBOL(iwl_rx_reply_rx_phy);