iwl-scan.c 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545
  1. /******************************************************************************
  2. *
  3. * GPL LICENSE SUMMARY
  4. *
  5. * Copyright(c) 2008 - 2011 Intel Corporation. All rights reserved.
  6. *
  7. * This program is free software; you can redistribute it and/or modify
  8. * it under the terms of version 2 of the GNU General Public License as
  9. * published by the Free Software Foundation.
  10. *
  11. * This program is distributed in the hope that it will be useful, but
  12. * WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU General Public License
  17. * along with this program; if not, write to the Free Software
  18. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110,
  19. * USA
  20. *
  21. * The full GNU General Public License is included in this distribution
  22. * in the file called LICENSE.GPL.
  23. *
  24. * Contact Information:
  25. * Intel Linux Wireless <ilw@linux.intel.com>
  26. * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
  27. *****************************************************************************/
  28. #include <linux/slab.h>
  29. #include <linux/types.h>
  30. #include <linux/etherdevice.h>
  31. #include <net/mac80211.h>
  32. #include "iwl-eeprom.h"
  33. #include "iwl-dev.h"
  34. #include "iwl-core.h"
  35. #include "iwl-sta.h"
  36. #include "iwl-io.h"
  37. #include "iwl-helpers.h"
  38. /* For active scan, listen ACTIVE_DWELL_TIME (msec) on each channel after
  39. * sending probe req. This should be set long enough to hear probe responses
  40. * from more than one AP. */
  41. #define IL_ACTIVE_DWELL_TIME_24 (30) /* all times in msec */
  42. #define IL_ACTIVE_DWELL_TIME_52 (20)
  43. #define IL_ACTIVE_DWELL_FACTOR_24GHZ (3)
  44. #define IL_ACTIVE_DWELL_FACTOR_52GHZ (2)
  45. /* For passive scan, listen PASSIVE_DWELL_TIME (msec) on each channel.
  46. * Must be set longer than active dwell time.
  47. * For the most reliable scan, set > AP beacon interval (typically 100msec). */
  48. #define IL_PASSIVE_DWELL_TIME_24 (20) /* all times in msec */
  49. #define IL_PASSIVE_DWELL_TIME_52 (10)
  50. #define IL_PASSIVE_DWELL_BASE (100)
  51. #define IL_CHANNEL_TUNE_TIME 5
  52. static int il_send_scan_abort(struct il_priv *il)
  53. {
  54. int ret;
  55. struct il_rx_pkt *pkt;
  56. struct il_host_cmd cmd = {
  57. .id = C_SCAN_ABORT,
  58. .flags = CMD_WANT_SKB,
  59. };
  60. /* Exit instantly with error when device is not ready
  61. * to receive scan abort command or it does not perform
  62. * hardware scan currently */
  63. if (!test_bit(S_READY, &il->status) ||
  64. !test_bit(S_GEO_CONFIGURED, &il->status) ||
  65. !test_bit(S_SCAN_HW, &il->status) ||
  66. test_bit(S_FW_ERROR, &il->status) ||
  67. test_bit(S_EXIT_PENDING, &il->status))
  68. return -EIO;
  69. ret = il_send_cmd_sync(il, &cmd);
  70. if (ret)
  71. return ret;
  72. pkt = (struct il_rx_pkt *)cmd.reply_page;
  73. if (pkt->u.status != CAN_ABORT_STATUS) {
  74. /* The scan abort will return 1 for success or
  75. * 2 for "failure". A failure condition can be
  76. * due to simply not being in an active scan which
  77. * can occur if we send the scan abort before we
  78. * the microcode has notified us that a scan is
  79. * completed. */
  80. D_SCAN("SCAN_ABORT ret %d.\n", pkt->u.status);
  81. ret = -EIO;
  82. }
  83. il_free_pages(il, cmd.reply_page);
  84. return ret;
  85. }
  86. static void il_complete_scan(struct il_priv *il, bool aborted)
  87. {
  88. /* check if scan was requested from mac80211 */
  89. if (il->scan_request) {
  90. D_SCAN("Complete scan in mac80211\n");
  91. ieee80211_scan_completed(il->hw, aborted);
  92. }
  93. il->scan_vif = NULL;
  94. il->scan_request = NULL;
  95. }
  96. void il_force_scan_end(struct il_priv *il)
  97. {
  98. lockdep_assert_held(&il->mutex);
  99. if (!test_bit(S_SCANNING, &il->status)) {
  100. D_SCAN("Forcing scan end while not scanning\n");
  101. return;
  102. }
  103. D_SCAN("Forcing scan end\n");
  104. clear_bit(S_SCANNING, &il->status);
  105. clear_bit(S_SCAN_HW, &il->status);
  106. clear_bit(S_SCAN_ABORTING, &il->status);
  107. il_complete_scan(il, true);
  108. }
  109. static void il_do_scan_abort(struct il_priv *il)
  110. {
  111. int ret;
  112. lockdep_assert_held(&il->mutex);
  113. if (!test_bit(S_SCANNING, &il->status)) {
  114. D_SCAN("Not performing scan to abort\n");
  115. return;
  116. }
  117. if (test_and_set_bit(S_SCAN_ABORTING, &il->status)) {
  118. D_SCAN("Scan abort in progress\n");
  119. return;
  120. }
  121. ret = il_send_scan_abort(il);
  122. if (ret) {
  123. D_SCAN("Send scan abort failed %d\n", ret);
  124. il_force_scan_end(il);
  125. } else
  126. D_SCAN("Successfully send scan abort\n");
  127. }
  128. /**
  129. * il_scan_cancel - Cancel any currently executing HW scan
  130. */
  131. int il_scan_cancel(struct il_priv *il)
  132. {
  133. D_SCAN("Queuing abort scan\n");
  134. queue_work(il->workqueue, &il->abort_scan);
  135. return 0;
  136. }
  137. EXPORT_SYMBOL(il_scan_cancel);
  138. /**
  139. * il_scan_cancel_timeout - Cancel any currently executing HW scan
  140. * @ms: amount of time to wait (in milliseconds) for scan to abort
  141. *
  142. */
  143. int il_scan_cancel_timeout(struct il_priv *il, unsigned long ms)
  144. {
  145. unsigned long timeout = jiffies + msecs_to_jiffies(ms);
  146. lockdep_assert_held(&il->mutex);
  147. D_SCAN("Scan cancel timeout\n");
  148. il_do_scan_abort(il);
  149. while (time_before_eq(jiffies, timeout)) {
  150. if (!test_bit(S_SCAN_HW, &il->status))
  151. break;
  152. msleep(20);
  153. }
  154. return test_bit(S_SCAN_HW, &il->status);
  155. }
  156. EXPORT_SYMBOL(il_scan_cancel_timeout);
  157. /* Service response to C_SCAN (0x80) */
  158. static void il_hdl_scan(struct il_priv *il,
  159. struct il_rx_buf *rxb)
  160. {
  161. #ifdef CONFIG_IWLEGACY_DEBUG
  162. struct il_rx_pkt *pkt = rxb_addr(rxb);
  163. struct il_scanreq_notification *notif =
  164. (struct il_scanreq_notification *)pkt->u.raw;
  165. D_SCAN("Scan request status = 0x%x\n", notif->status);
  166. #endif
  167. }
  168. /* Service N_SCAN_START (0x82) */
  169. static void il_rx_scan_start_notif(struct il_priv *il,
  170. struct il_rx_buf *rxb)
  171. {
  172. struct il_rx_pkt *pkt = rxb_addr(rxb);
  173. struct il_scanstart_notification *notif =
  174. (struct il_scanstart_notification *)pkt->u.raw;
  175. il->scan_start_tsf = le32_to_cpu(notif->tsf_low);
  176. D_SCAN("Scan start: "
  177. "%d [802.11%s] "
  178. "(TSF: 0x%08X:%08X) - %d (beacon timer %u)\n",
  179. notif->channel,
  180. notif->band ? "bg" : "a",
  181. le32_to_cpu(notif->tsf_high),
  182. le32_to_cpu(notif->tsf_low),
  183. notif->status, notif->beacon_timer);
  184. }
  185. /* Service N_SCAN_RESULTS (0x83) */
  186. static void il_rx_scan_results_notif(struct il_priv *il,
  187. struct il_rx_buf *rxb)
  188. {
  189. #ifdef CONFIG_IWLEGACY_DEBUG
  190. struct il_rx_pkt *pkt = rxb_addr(rxb);
  191. struct il_scanresults_notification *notif =
  192. (struct il_scanresults_notification *)pkt->u.raw;
  193. D_SCAN("Scan ch.res: "
  194. "%d [802.11%s] "
  195. "(TSF: 0x%08X:%08X) - %d "
  196. "elapsed=%lu usec\n",
  197. notif->channel,
  198. notif->band ? "bg" : "a",
  199. le32_to_cpu(notif->tsf_high),
  200. le32_to_cpu(notif->tsf_low),
  201. le32_to_cpu(notif->stats[0]),
  202. le32_to_cpu(notif->tsf_low) - il->scan_start_tsf);
  203. #endif
  204. }
  205. /* Service N_SCAN_COMPLETE (0x84) */
  206. static void il_rx_scan_complete_notif(struct il_priv *il,
  207. struct il_rx_buf *rxb)
  208. {
  209. #ifdef CONFIG_IWLEGACY_DEBUG
  210. struct il_rx_pkt *pkt = rxb_addr(rxb);
  211. struct il_scancomplete_notification *scan_notif = (void *)pkt->u.raw;
  212. #endif
  213. D_SCAN(
  214. "Scan complete: %d channels (TSF 0x%08X:%08X) - %d\n",
  215. scan_notif->scanned_channels,
  216. scan_notif->tsf_low,
  217. scan_notif->tsf_high, scan_notif->status);
  218. /* The HW is no longer scanning */
  219. clear_bit(S_SCAN_HW, &il->status);
  220. D_SCAN("Scan on %sGHz took %dms\n",
  221. (il->scan_band == IEEE80211_BAND_2GHZ) ? "2.4" : "5.2",
  222. jiffies_to_msecs(jiffies - il->scan_start));
  223. queue_work(il->workqueue, &il->scan_completed);
  224. }
  225. void il_setup_rx_scan_handlers(struct il_priv *il)
  226. {
  227. /* scan handlers */
  228. il->handlers[C_SCAN] = il_hdl_scan;
  229. il->handlers[N_SCAN_START] =
  230. il_rx_scan_start_notif;
  231. il->handlers[N_SCAN_RESULTS] =
  232. il_rx_scan_results_notif;
  233. il->handlers[N_SCAN_COMPLETE] =
  234. il_rx_scan_complete_notif;
  235. }
  236. EXPORT_SYMBOL(il_setup_rx_scan_handlers);
  237. inline u16 il_get_active_dwell_time(struct il_priv *il,
  238. enum ieee80211_band band,
  239. u8 n_probes)
  240. {
  241. if (band == IEEE80211_BAND_5GHZ)
  242. return IL_ACTIVE_DWELL_TIME_52 +
  243. IL_ACTIVE_DWELL_FACTOR_52GHZ * (n_probes + 1);
  244. else
  245. return IL_ACTIVE_DWELL_TIME_24 +
  246. IL_ACTIVE_DWELL_FACTOR_24GHZ * (n_probes + 1);
  247. }
  248. EXPORT_SYMBOL(il_get_active_dwell_time);
  249. u16 il_get_passive_dwell_time(struct il_priv *il,
  250. enum ieee80211_band band,
  251. struct ieee80211_vif *vif)
  252. {
  253. struct il_rxon_context *ctx = &il->ctx;
  254. u16 value;
  255. u16 passive = (band == IEEE80211_BAND_2GHZ) ?
  256. IL_PASSIVE_DWELL_BASE + IL_PASSIVE_DWELL_TIME_24 :
  257. IL_PASSIVE_DWELL_BASE + IL_PASSIVE_DWELL_TIME_52;
  258. if (il_is_any_associated(il)) {
  259. /*
  260. * If we're associated, we clamp the maximum passive
  261. * dwell time to be 98% of the smallest beacon interval
  262. * (minus 2 * channel tune time)
  263. */
  264. value = ctx->vif ? ctx->vif->bss_conf.beacon_int : 0;
  265. if (value > IL_PASSIVE_DWELL_BASE || !value)
  266. value = IL_PASSIVE_DWELL_BASE;
  267. value = (value * 98) / 100 - IL_CHANNEL_TUNE_TIME * 2;
  268. passive = min(value, passive);
  269. }
  270. return passive;
  271. }
  272. EXPORT_SYMBOL(il_get_passive_dwell_time);
  273. void il_init_scan_params(struct il_priv *il)
  274. {
  275. u8 ant_idx = fls(il->hw_params.valid_tx_ant) - 1;
  276. if (!il->scan_tx_ant[IEEE80211_BAND_5GHZ])
  277. il->scan_tx_ant[IEEE80211_BAND_5GHZ] = ant_idx;
  278. if (!il->scan_tx_ant[IEEE80211_BAND_2GHZ])
  279. il->scan_tx_ant[IEEE80211_BAND_2GHZ] = ant_idx;
  280. }
  281. EXPORT_SYMBOL(il_init_scan_params);
  282. static int il_scan_initiate(struct il_priv *il,
  283. struct ieee80211_vif *vif)
  284. {
  285. int ret;
  286. lockdep_assert_held(&il->mutex);
  287. if (WARN_ON(!il->cfg->ops->utils->request_scan))
  288. return -EOPNOTSUPP;
  289. cancel_delayed_work(&il->scan_check);
  290. if (!il_is_ready_rf(il)) {
  291. IL_WARN("Request scan called when driver not ready.\n");
  292. return -EIO;
  293. }
  294. if (test_bit(S_SCAN_HW, &il->status)) {
  295. D_SCAN(
  296. "Multiple concurrent scan requests in parallel.\n");
  297. return -EBUSY;
  298. }
  299. if (test_bit(S_SCAN_ABORTING, &il->status)) {
  300. D_SCAN("Scan request while abort pending.\n");
  301. return -EBUSY;
  302. }
  303. D_SCAN("Starting scan...\n");
  304. set_bit(S_SCANNING, &il->status);
  305. il->scan_start = jiffies;
  306. ret = il->cfg->ops->utils->request_scan(il, vif);
  307. if (ret) {
  308. clear_bit(S_SCANNING, &il->status);
  309. return ret;
  310. }
  311. queue_delayed_work(il->workqueue, &il->scan_check,
  312. IL_SCAN_CHECK_WATCHDOG);
  313. return 0;
  314. }
  315. int il_mac_hw_scan(struct ieee80211_hw *hw,
  316. struct ieee80211_vif *vif,
  317. struct cfg80211_scan_request *req)
  318. {
  319. struct il_priv *il = hw->priv;
  320. int ret;
  321. D_MAC80211("enter\n");
  322. if (req->n_channels == 0)
  323. return -EINVAL;
  324. mutex_lock(&il->mutex);
  325. if (test_bit(S_SCANNING, &il->status)) {
  326. D_SCAN("Scan already in progress.\n");
  327. ret = -EAGAIN;
  328. goto out_unlock;
  329. }
  330. /* mac80211 will only ask for one band at a time */
  331. il->scan_request = req;
  332. il->scan_vif = vif;
  333. il->scan_band = req->channels[0]->band;
  334. ret = il_scan_initiate(il, vif);
  335. D_MAC80211("leave\n");
  336. out_unlock:
  337. mutex_unlock(&il->mutex);
  338. return ret;
  339. }
  340. EXPORT_SYMBOL(il_mac_hw_scan);
  341. static void il_bg_scan_check(struct work_struct *data)
  342. {
  343. struct il_priv *il =
  344. container_of(data, struct il_priv, scan_check.work);
  345. D_SCAN("Scan check work\n");
  346. /* Since we are here firmware does not finish scan and
  347. * most likely is in bad shape, so we don't bother to
  348. * send abort command, just force scan complete to mac80211 */
  349. mutex_lock(&il->mutex);
  350. il_force_scan_end(il);
  351. mutex_unlock(&il->mutex);
  352. }
  353. /**
  354. * il_fill_probe_req - fill in all required fields and IE for probe request
  355. */
  356. u16
  357. il_fill_probe_req(struct il_priv *il, struct ieee80211_mgmt *frame,
  358. const u8 *ta, const u8 *ies, int ie_len, int left)
  359. {
  360. int len = 0;
  361. u8 *pos = NULL;
  362. /* Make sure there is enough space for the probe request,
  363. * two mandatory IEs and the data */
  364. left -= 24;
  365. if (left < 0)
  366. return 0;
  367. frame->frame_control = cpu_to_le16(IEEE80211_STYPE_PROBE_REQ);
  368. memcpy(frame->da, il_bcast_addr, ETH_ALEN);
  369. memcpy(frame->sa, ta, ETH_ALEN);
  370. memcpy(frame->bssid, il_bcast_addr, ETH_ALEN);
  371. frame->seq_ctrl = 0;
  372. len += 24;
  373. /* ...next IE... */
  374. pos = &frame->u.probe_req.variable[0];
  375. /* fill in our indirect SSID IE */
  376. left -= 2;
  377. if (left < 0)
  378. return 0;
  379. *pos++ = WLAN_EID_SSID;
  380. *pos++ = 0;
  381. len += 2;
  382. if (WARN_ON(left < ie_len))
  383. return len;
  384. if (ies && ie_len) {
  385. memcpy(pos, ies, ie_len);
  386. len += ie_len;
  387. }
  388. return (u16)len;
  389. }
  390. EXPORT_SYMBOL(il_fill_probe_req);
  391. static void il_bg_abort_scan(struct work_struct *work)
  392. {
  393. struct il_priv *il = container_of(work, struct il_priv, abort_scan);
  394. D_SCAN("Abort scan work\n");
  395. /* We keep scan_check work queued in case when firmware will not
  396. * report back scan completed notification */
  397. mutex_lock(&il->mutex);
  398. il_scan_cancel_timeout(il, 200);
  399. mutex_unlock(&il->mutex);
  400. }
  401. static void il_bg_scan_completed(struct work_struct *work)
  402. {
  403. struct il_priv *il =
  404. container_of(work, struct il_priv, scan_completed);
  405. bool aborted;
  406. D_SCAN("Completed scan.\n");
  407. cancel_delayed_work(&il->scan_check);
  408. mutex_lock(&il->mutex);
  409. aborted = test_and_clear_bit(S_SCAN_ABORTING, &il->status);
  410. if (aborted)
  411. D_SCAN("Aborted scan completed.\n");
  412. if (!test_and_clear_bit(S_SCANNING, &il->status)) {
  413. D_SCAN("Scan already completed.\n");
  414. goto out_settings;
  415. }
  416. il_complete_scan(il, aborted);
  417. out_settings:
  418. /* Can we still talk to firmware ? */
  419. if (!il_is_ready_rf(il))
  420. goto out;
  421. /*
  422. * We do not commit power settings while scan is pending,
  423. * do it now if the settings changed.
  424. */
  425. il_power_set_mode(il, &il->power_data.sleep_cmd_next, false);
  426. il_set_tx_power(il, il->tx_power_next, false);
  427. il->cfg->ops->utils->post_scan(il);
  428. out:
  429. mutex_unlock(&il->mutex);
  430. }
  431. void il_setup_scan_deferred_work(struct il_priv *il)
  432. {
  433. INIT_WORK(&il->scan_completed, il_bg_scan_completed);
  434. INIT_WORK(&il->abort_scan, il_bg_abort_scan);
  435. INIT_DELAYED_WORK(&il->scan_check, il_bg_scan_check);
  436. }
  437. EXPORT_SYMBOL(il_setup_scan_deferred_work);
  438. void il_cancel_scan_deferred_work(struct il_priv *il)
  439. {
  440. cancel_work_sync(&il->abort_scan);
  441. cancel_work_sync(&il->scan_completed);
  442. if (cancel_delayed_work_sync(&il->scan_check)) {
  443. mutex_lock(&il->mutex);
  444. il_force_scan_end(il);
  445. mutex_unlock(&il->mutex);
  446. }
  447. }
  448. EXPORT_SYMBOL(il_cancel_scan_deferred_work);