iwl-scan.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550
  1. /******************************************************************************
  2. *
  3. * GPL LICENSE SUMMARY
  4. *
  5. * Copyright(c) 2008 - 2011 Intel Corporation. All rights reserved.
  6. *
  7. * This program is free software; you can redistribute it and/or modify
  8. * it under the terms of version 2 of the GNU General Public License as
  9. * published by the Free Software Foundation.
  10. *
  11. * This program is distributed in the hope that it will be useful, but
  12. * WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  14. * General Public License for more details.
  15. *
  16. * You should have received a copy of the GNU General Public License
  17. * along with this program; if not, write to the Free Software
  18. * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110,
  19. * USA
  20. *
  21. * The full GNU General Public License is included in this distribution
  22. * in the file called LICENSE.GPL.
  23. *
  24. * Contact Information:
  25. * Intel Linux Wireless <ilw@linux.intel.com>
  26. * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
  27. *****************************************************************************/
  28. #include <linux/slab.h>
  29. #include <linux/types.h>
  30. #include <linux/etherdevice.h>
  31. #include <linux/export.h>
  32. #include <net/mac80211.h>
  33. #include "iwl-eeprom.h"
  34. #include "iwl-dev.h"
  35. #include "iwl-core.h"
  36. #include "iwl-sta.h"
  37. #include "iwl-io.h"
  38. #include "iwl-helpers.h"
  39. /* For active scan, listen ACTIVE_DWELL_TIME (msec) on each channel after
  40. * sending probe req. This should be set long enough to hear probe responses
  41. * from more than one AP. */
  42. #define IWL_ACTIVE_DWELL_TIME_24 (30) /* all times in msec */
  43. #define IWL_ACTIVE_DWELL_TIME_52 (20)
  44. #define IWL_ACTIVE_DWELL_FACTOR_24GHZ (3)
  45. #define IWL_ACTIVE_DWELL_FACTOR_52GHZ (2)
  46. /* For passive scan, listen PASSIVE_DWELL_TIME (msec) on each channel.
  47. * Must be set longer than active dwell time.
  48. * For the most reliable scan, set > AP beacon interval (typically 100msec). */
  49. #define IWL_PASSIVE_DWELL_TIME_24 (20) /* all times in msec */
  50. #define IWL_PASSIVE_DWELL_TIME_52 (10)
  51. #define IWL_PASSIVE_DWELL_BASE (100)
  52. #define IWL_CHANNEL_TUNE_TIME 5
  53. static int iwl_legacy_send_scan_abort(struct iwl_priv *priv)
  54. {
  55. int ret;
  56. struct iwl_rx_packet *pkt;
  57. struct iwl_host_cmd cmd = {
  58. .id = REPLY_SCAN_ABORT_CMD,
  59. .flags = CMD_WANT_SKB,
  60. };
  61. /* Exit instantly with error when device is not ready
  62. * to receive scan abort command or it does not perform
  63. * hardware scan currently */
  64. if (!test_bit(STATUS_READY, &priv->status) ||
  65. !test_bit(STATUS_GEO_CONFIGURED, &priv->status) ||
  66. !test_bit(STATUS_SCAN_HW, &priv->status) ||
  67. test_bit(STATUS_FW_ERROR, &priv->status) ||
  68. test_bit(STATUS_EXIT_PENDING, &priv->status))
  69. return -EIO;
  70. ret = iwl_legacy_send_cmd_sync(priv, &cmd);
  71. if (ret)
  72. return ret;
  73. pkt = (struct iwl_rx_packet *)cmd.reply_page;
  74. if (pkt->u.status != CAN_ABORT_STATUS) {
  75. /* The scan abort will return 1 for success or
  76. * 2 for "failure". A failure condition can be
  77. * due to simply not being in an active scan which
  78. * can occur if we send the scan abort before we
  79. * the microcode has notified us that a scan is
  80. * completed. */
  81. IWL_DEBUG_SCAN(priv, "SCAN_ABORT ret %d.\n", pkt->u.status);
  82. ret = -EIO;
  83. }
  84. iwl_legacy_free_pages(priv, cmd.reply_page);
  85. return ret;
  86. }
  87. static void iwl_legacy_complete_scan(struct iwl_priv *priv, bool aborted)
  88. {
  89. /* check if scan was requested from mac80211 */
  90. if (priv->scan_request) {
  91. IWL_DEBUG_SCAN(priv, "Complete scan in mac80211\n");
  92. ieee80211_scan_completed(priv->hw, aborted);
  93. }
  94. priv->scan_vif = NULL;
  95. priv->scan_request = NULL;
  96. }
  97. void iwl_legacy_force_scan_end(struct iwl_priv *priv)
  98. {
  99. lockdep_assert_held(&priv->mutex);
  100. if (!test_bit(STATUS_SCANNING, &priv->status)) {
  101. IWL_DEBUG_SCAN(priv, "Forcing scan end while not scanning\n");
  102. return;
  103. }
  104. IWL_DEBUG_SCAN(priv, "Forcing scan end\n");
  105. clear_bit(STATUS_SCANNING, &priv->status);
  106. clear_bit(STATUS_SCAN_HW, &priv->status);
  107. clear_bit(STATUS_SCAN_ABORTING, &priv->status);
  108. iwl_legacy_complete_scan(priv, true);
  109. }
  110. static void iwl_legacy_do_scan_abort(struct iwl_priv *priv)
  111. {
  112. int ret;
  113. lockdep_assert_held(&priv->mutex);
  114. if (!test_bit(STATUS_SCANNING, &priv->status)) {
  115. IWL_DEBUG_SCAN(priv, "Not performing scan to abort\n");
  116. return;
  117. }
  118. if (test_and_set_bit(STATUS_SCAN_ABORTING, &priv->status)) {
  119. IWL_DEBUG_SCAN(priv, "Scan abort in progress\n");
  120. return;
  121. }
  122. ret = iwl_legacy_send_scan_abort(priv);
  123. if (ret) {
  124. IWL_DEBUG_SCAN(priv, "Send scan abort failed %d\n", ret);
  125. iwl_legacy_force_scan_end(priv);
  126. } else
  127. IWL_DEBUG_SCAN(priv, "Successfully send scan abort\n");
  128. }
  129. /**
  130. * iwl_scan_cancel - Cancel any currently executing HW scan
  131. */
  132. int iwl_legacy_scan_cancel(struct iwl_priv *priv)
  133. {
  134. IWL_DEBUG_SCAN(priv, "Queuing abort scan\n");
  135. queue_work(priv->workqueue, &priv->abort_scan);
  136. return 0;
  137. }
  138. EXPORT_SYMBOL(iwl_legacy_scan_cancel);
  139. /**
  140. * iwl_legacy_scan_cancel_timeout - Cancel any currently executing HW scan
  141. * @ms: amount of time to wait (in milliseconds) for scan to abort
  142. *
  143. */
  144. int iwl_legacy_scan_cancel_timeout(struct iwl_priv *priv, unsigned long ms)
  145. {
  146. unsigned long timeout = jiffies + msecs_to_jiffies(ms);
  147. lockdep_assert_held(&priv->mutex);
  148. IWL_DEBUG_SCAN(priv, "Scan cancel timeout\n");
  149. iwl_legacy_do_scan_abort(priv);
  150. while (time_before_eq(jiffies, timeout)) {
  151. if (!test_bit(STATUS_SCAN_HW, &priv->status))
  152. break;
  153. msleep(20);
  154. }
  155. return test_bit(STATUS_SCAN_HW, &priv->status);
  156. }
  157. EXPORT_SYMBOL(iwl_legacy_scan_cancel_timeout);
  158. /* Service response to REPLY_SCAN_CMD (0x80) */
  159. static void iwl_legacy_rx_reply_scan(struct iwl_priv *priv,
  160. struct iwl_rx_mem_buffer *rxb)
  161. {
  162. #ifdef CONFIG_IWLWIFI_LEGACY_DEBUG
  163. struct iwl_rx_packet *pkt = rxb_addr(rxb);
  164. struct iwl_scanreq_notification *notif =
  165. (struct iwl_scanreq_notification *)pkt->u.raw;
  166. IWL_DEBUG_SCAN(priv, "Scan request status = 0x%x\n", notif->status);
  167. #endif
  168. }
  169. /* Service SCAN_START_NOTIFICATION (0x82) */
  170. static void iwl_legacy_rx_scan_start_notif(struct iwl_priv *priv,
  171. struct iwl_rx_mem_buffer *rxb)
  172. {
  173. struct iwl_rx_packet *pkt = rxb_addr(rxb);
  174. struct iwl_scanstart_notification *notif =
  175. (struct iwl_scanstart_notification *)pkt->u.raw;
  176. priv->scan_start_tsf = le32_to_cpu(notif->tsf_low);
  177. IWL_DEBUG_SCAN(priv, "Scan start: "
  178. "%d [802.11%s] "
  179. "(TSF: 0x%08X:%08X) - %d (beacon timer %u)\n",
  180. notif->channel,
  181. notif->band ? "bg" : "a",
  182. le32_to_cpu(notif->tsf_high),
  183. le32_to_cpu(notif->tsf_low),
  184. notif->status, notif->beacon_timer);
  185. }
  186. /* Service SCAN_RESULTS_NOTIFICATION (0x83) */
  187. static void iwl_legacy_rx_scan_results_notif(struct iwl_priv *priv,
  188. struct iwl_rx_mem_buffer *rxb)
  189. {
  190. #ifdef CONFIG_IWLWIFI_LEGACY_DEBUG
  191. struct iwl_rx_packet *pkt = rxb_addr(rxb);
  192. struct iwl_scanresults_notification *notif =
  193. (struct iwl_scanresults_notification *)pkt->u.raw;
  194. IWL_DEBUG_SCAN(priv, "Scan ch.res: "
  195. "%d [802.11%s] "
  196. "(TSF: 0x%08X:%08X) - %d "
  197. "elapsed=%lu usec\n",
  198. notif->channel,
  199. notif->band ? "bg" : "a",
  200. le32_to_cpu(notif->tsf_high),
  201. le32_to_cpu(notif->tsf_low),
  202. le32_to_cpu(notif->statistics[0]),
  203. le32_to_cpu(notif->tsf_low) - priv->scan_start_tsf);
  204. #endif
  205. }
  206. /* Service SCAN_COMPLETE_NOTIFICATION (0x84) */
  207. static void iwl_legacy_rx_scan_complete_notif(struct iwl_priv *priv,
  208. struct iwl_rx_mem_buffer *rxb)
  209. {
  210. #ifdef CONFIG_IWLWIFI_LEGACY_DEBUG
  211. struct iwl_rx_packet *pkt = rxb_addr(rxb);
  212. struct iwl_scancomplete_notification *scan_notif = (void *)pkt->u.raw;
  213. #endif
  214. IWL_DEBUG_SCAN(priv,
  215. "Scan complete: %d channels (TSF 0x%08X:%08X) - %d\n",
  216. scan_notif->scanned_channels,
  217. scan_notif->tsf_low,
  218. scan_notif->tsf_high, scan_notif->status);
  219. /* The HW is no longer scanning */
  220. clear_bit(STATUS_SCAN_HW, &priv->status);
  221. IWL_DEBUG_SCAN(priv, "Scan on %sGHz took %dms\n",
  222. (priv->scan_band == IEEE80211_BAND_2GHZ) ? "2.4" : "5.2",
  223. jiffies_to_msecs(jiffies - priv->scan_start));
  224. queue_work(priv->workqueue, &priv->scan_completed);
  225. }
  226. void iwl_legacy_setup_rx_scan_handlers(struct iwl_priv *priv)
  227. {
  228. /* scan handlers */
  229. priv->rx_handlers[REPLY_SCAN_CMD] = iwl_legacy_rx_reply_scan;
  230. priv->rx_handlers[SCAN_START_NOTIFICATION] =
  231. iwl_legacy_rx_scan_start_notif;
  232. priv->rx_handlers[SCAN_RESULTS_NOTIFICATION] =
  233. iwl_legacy_rx_scan_results_notif;
  234. priv->rx_handlers[SCAN_COMPLETE_NOTIFICATION] =
  235. iwl_legacy_rx_scan_complete_notif;
  236. }
  237. EXPORT_SYMBOL(iwl_legacy_setup_rx_scan_handlers);
  238. inline u16 iwl_legacy_get_active_dwell_time(struct iwl_priv *priv,
  239. enum ieee80211_band band,
  240. u8 n_probes)
  241. {
  242. if (band == IEEE80211_BAND_5GHZ)
  243. return IWL_ACTIVE_DWELL_TIME_52 +
  244. IWL_ACTIVE_DWELL_FACTOR_52GHZ * (n_probes + 1);
  245. else
  246. return IWL_ACTIVE_DWELL_TIME_24 +
  247. IWL_ACTIVE_DWELL_FACTOR_24GHZ * (n_probes + 1);
  248. }
  249. EXPORT_SYMBOL(iwl_legacy_get_active_dwell_time);
  250. u16 iwl_legacy_get_passive_dwell_time(struct iwl_priv *priv,
  251. enum ieee80211_band band,
  252. struct ieee80211_vif *vif)
  253. {
  254. struct iwl_rxon_context *ctx;
  255. u16 passive = (band == IEEE80211_BAND_2GHZ) ?
  256. IWL_PASSIVE_DWELL_BASE + IWL_PASSIVE_DWELL_TIME_24 :
  257. IWL_PASSIVE_DWELL_BASE + IWL_PASSIVE_DWELL_TIME_52;
  258. if (iwl_legacy_is_any_associated(priv)) {
  259. /*
  260. * If we're associated, we clamp the maximum passive
  261. * dwell time to be 98% of the smallest beacon interval
  262. * (minus 2 * channel tune time)
  263. */
  264. for_each_context(priv, ctx) {
  265. u16 value;
  266. if (!iwl_legacy_is_associated_ctx(ctx))
  267. continue;
  268. value = ctx->vif ? ctx->vif->bss_conf.beacon_int : 0;
  269. if ((value > IWL_PASSIVE_DWELL_BASE) || !value)
  270. value = IWL_PASSIVE_DWELL_BASE;
  271. value = (value * 98) / 100 - IWL_CHANNEL_TUNE_TIME * 2;
  272. passive = min(value, passive);
  273. }
  274. }
  275. return passive;
  276. }
  277. EXPORT_SYMBOL(iwl_legacy_get_passive_dwell_time);
  278. void iwl_legacy_init_scan_params(struct iwl_priv *priv)
  279. {
  280. u8 ant_idx = fls(priv->hw_params.valid_tx_ant) - 1;
  281. if (!priv->scan_tx_ant[IEEE80211_BAND_5GHZ])
  282. priv->scan_tx_ant[IEEE80211_BAND_5GHZ] = ant_idx;
  283. if (!priv->scan_tx_ant[IEEE80211_BAND_2GHZ])
  284. priv->scan_tx_ant[IEEE80211_BAND_2GHZ] = ant_idx;
  285. }
  286. EXPORT_SYMBOL(iwl_legacy_init_scan_params);
  287. static int iwl_legacy_scan_initiate(struct iwl_priv *priv,
  288. struct ieee80211_vif *vif)
  289. {
  290. int ret;
  291. lockdep_assert_held(&priv->mutex);
  292. if (WARN_ON(!priv->cfg->ops->utils->request_scan))
  293. return -EOPNOTSUPP;
  294. cancel_delayed_work(&priv->scan_check);
  295. if (!iwl_legacy_is_ready_rf(priv)) {
  296. IWL_WARN(priv, "Request scan called when driver not ready.\n");
  297. return -EIO;
  298. }
  299. if (test_bit(STATUS_SCAN_HW, &priv->status)) {
  300. IWL_DEBUG_SCAN(priv,
  301. "Multiple concurrent scan requests in parallel.\n");
  302. return -EBUSY;
  303. }
  304. if (test_bit(STATUS_SCAN_ABORTING, &priv->status)) {
  305. IWL_DEBUG_SCAN(priv, "Scan request while abort pending.\n");
  306. return -EBUSY;
  307. }
  308. IWL_DEBUG_SCAN(priv, "Starting scan...\n");
  309. set_bit(STATUS_SCANNING, &priv->status);
  310. priv->scan_start = jiffies;
  311. ret = priv->cfg->ops->utils->request_scan(priv, vif);
  312. if (ret) {
  313. clear_bit(STATUS_SCANNING, &priv->status);
  314. return ret;
  315. }
  316. queue_delayed_work(priv->workqueue, &priv->scan_check,
  317. IWL_SCAN_CHECK_WATCHDOG);
  318. return 0;
  319. }
  320. int iwl_legacy_mac_hw_scan(struct ieee80211_hw *hw,
  321. struct ieee80211_vif *vif,
  322. struct cfg80211_scan_request *req)
  323. {
  324. struct iwl_priv *priv = hw->priv;
  325. int ret;
  326. IWL_DEBUG_MAC80211(priv, "enter\n");
  327. if (req->n_channels == 0)
  328. return -EINVAL;
  329. mutex_lock(&priv->mutex);
  330. if (test_bit(STATUS_SCANNING, &priv->status)) {
  331. IWL_DEBUG_SCAN(priv, "Scan already in progress.\n");
  332. ret = -EAGAIN;
  333. goto out_unlock;
  334. }
  335. /* mac80211 will only ask for one band at a time */
  336. priv->scan_request = req;
  337. priv->scan_vif = vif;
  338. priv->scan_band = req->channels[0]->band;
  339. ret = iwl_legacy_scan_initiate(priv, vif);
  340. IWL_DEBUG_MAC80211(priv, "leave\n");
  341. out_unlock:
  342. mutex_unlock(&priv->mutex);
  343. return ret;
  344. }
  345. EXPORT_SYMBOL(iwl_legacy_mac_hw_scan);
  346. static void iwl_legacy_bg_scan_check(struct work_struct *data)
  347. {
  348. struct iwl_priv *priv =
  349. container_of(data, struct iwl_priv, scan_check.work);
  350. IWL_DEBUG_SCAN(priv, "Scan check work\n");
  351. /* Since we are here firmware does not finish scan and
  352. * most likely is in bad shape, so we don't bother to
  353. * send abort command, just force scan complete to mac80211 */
  354. mutex_lock(&priv->mutex);
  355. iwl_legacy_force_scan_end(priv);
  356. mutex_unlock(&priv->mutex);
  357. }
  358. /**
  359. * iwl_legacy_fill_probe_req - fill in all required fields and IE for probe request
  360. */
  361. u16
  362. iwl_legacy_fill_probe_req(struct iwl_priv *priv, struct ieee80211_mgmt *frame,
  363. const u8 *ta, const u8 *ies, int ie_len, int left)
  364. {
  365. int len = 0;
  366. u8 *pos = NULL;
  367. /* Make sure there is enough space for the probe request,
  368. * two mandatory IEs and the data */
  369. left -= 24;
  370. if (left < 0)
  371. return 0;
  372. frame->frame_control = cpu_to_le16(IEEE80211_STYPE_PROBE_REQ);
  373. memcpy(frame->da, iwlegacy_bcast_addr, ETH_ALEN);
  374. memcpy(frame->sa, ta, ETH_ALEN);
  375. memcpy(frame->bssid, iwlegacy_bcast_addr, ETH_ALEN);
  376. frame->seq_ctrl = 0;
  377. len += 24;
  378. /* ...next IE... */
  379. pos = &frame->u.probe_req.variable[0];
  380. /* fill in our indirect SSID IE */
  381. left -= 2;
  382. if (left < 0)
  383. return 0;
  384. *pos++ = WLAN_EID_SSID;
  385. *pos++ = 0;
  386. len += 2;
  387. if (WARN_ON(left < ie_len))
  388. return len;
  389. if (ies && ie_len) {
  390. memcpy(pos, ies, ie_len);
  391. len += ie_len;
  392. }
  393. return (u16)len;
  394. }
  395. EXPORT_SYMBOL(iwl_legacy_fill_probe_req);
  396. static void iwl_legacy_bg_abort_scan(struct work_struct *work)
  397. {
  398. struct iwl_priv *priv = container_of(work, struct iwl_priv, abort_scan);
  399. IWL_DEBUG_SCAN(priv, "Abort scan work\n");
  400. /* We keep scan_check work queued in case when firmware will not
  401. * report back scan completed notification */
  402. mutex_lock(&priv->mutex);
  403. iwl_legacy_scan_cancel_timeout(priv, 200);
  404. mutex_unlock(&priv->mutex);
  405. }
  406. static void iwl_legacy_bg_scan_completed(struct work_struct *work)
  407. {
  408. struct iwl_priv *priv =
  409. container_of(work, struct iwl_priv, scan_completed);
  410. bool aborted;
  411. IWL_DEBUG_SCAN(priv, "Completed scan.\n");
  412. cancel_delayed_work(&priv->scan_check);
  413. mutex_lock(&priv->mutex);
  414. aborted = test_and_clear_bit(STATUS_SCAN_ABORTING, &priv->status);
  415. if (aborted)
  416. IWL_DEBUG_SCAN(priv, "Aborted scan completed.\n");
  417. if (!test_and_clear_bit(STATUS_SCANNING, &priv->status)) {
  418. IWL_DEBUG_SCAN(priv, "Scan already completed.\n");
  419. goto out_settings;
  420. }
  421. iwl_legacy_complete_scan(priv, aborted);
  422. out_settings:
  423. /* Can we still talk to firmware ? */
  424. if (!iwl_legacy_is_ready_rf(priv))
  425. goto out;
  426. /*
  427. * We do not commit power settings while scan is pending,
  428. * do it now if the settings changed.
  429. */
  430. iwl_legacy_power_set_mode(priv, &priv->power_data.sleep_cmd_next, false);
  431. iwl_legacy_set_tx_power(priv, priv->tx_power_next, false);
  432. priv->cfg->ops->utils->post_scan(priv);
  433. out:
  434. mutex_unlock(&priv->mutex);
  435. }
  436. void iwl_legacy_setup_scan_deferred_work(struct iwl_priv *priv)
  437. {
  438. INIT_WORK(&priv->scan_completed, iwl_legacy_bg_scan_completed);
  439. INIT_WORK(&priv->abort_scan, iwl_legacy_bg_abort_scan);
  440. INIT_DELAYED_WORK(&priv->scan_check, iwl_legacy_bg_scan_check);
  441. }
  442. EXPORT_SYMBOL(iwl_legacy_setup_scan_deferred_work);
  443. void iwl_legacy_cancel_scan_deferred_work(struct iwl_priv *priv)
  444. {
  445. cancel_work_sync(&priv->abort_scan);
  446. cancel_work_sync(&priv->scan_completed);
  447. if (cancel_delayed_work_sync(&priv->scan_check)) {
  448. mutex_lock(&priv->mutex);
  449. iwl_legacy_force_scan_end(priv);
  450. mutex_unlock(&priv->mutex);
  451. }
  452. }
  453. EXPORT_SYMBOL(iwl_legacy_cancel_scan_deferred_work);