net: fix suspicious rcu_dereference_check in net/sched/sch_fq_codel.c
[cascardo/linux.git] / drivers / net / wireless / brcm80211 / brcmfmac / fweh.c
1 /*
2  * Copyright (c) 2012 Broadcom Corporation
3  *
4  * Permission to use, copy, modify, and/or distribute this software for any
5  * purpose with or without fee is hereby granted, provided that the above
6  * copyright notice and this permission notice appear in all copies.
7  *
8  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
11  * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
13  * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
14  * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15  */
16 #include <linux/netdevice.h>
17
18 #include "brcmu_wifi.h"
19 #include "brcmu_utils.h"
20
21 #include "dhd.h"
22 #include "dhd_dbg.h"
23 #include "tracepoint.h"
24 #include "fwsignal.h"
25 #include "fweh.h"
26 #include "fwil.h"
27
28 /**
29  * struct brcm_ethhdr - broadcom specific ether header.
30  *
31  * @subtype: subtype for this packet.
32  * @length: TODO: length of appended data.
33  * @version: version indication.
34  * @oui: OUI of this packet.
35  * @usr_subtype: subtype for this OUI.
36  */
37 struct brcm_ethhdr {
38         __be16 subtype;
39         __be16 length;
40         u8 version;
41         u8 oui[3];
42         __be16 usr_subtype;
43 } __packed;
44
45 struct brcmf_event_msg_be {
46         __be16 version;
47         __be16 flags;
48         __be32 event_type;
49         __be32 status;
50         __be32 reason;
51         __be32 auth_type;
52         __be32 datalen;
53         u8 addr[ETH_ALEN];
54         char ifname[IFNAMSIZ];
55         u8 ifidx;
56         u8 bsscfgidx;
57 } __packed;
58
59 /**
60  * struct brcmf_event - contents of broadcom event packet.
61  *
62  * @eth: standard ether header.
63  * @hdr: broadcom specific ether header.
64  * @msg: common part of the actual event message.
65  */
66 struct brcmf_event {
67         struct ethhdr eth;
68         struct brcm_ethhdr hdr;
69         struct brcmf_event_msg_be msg;
70 } __packed;
71
72 /**
73  * struct brcmf_fweh_queue_item - event item on event queue.
74  *
75  * @q: list element for queuing.
76  * @code: event code.
77  * @ifidx: interface index related to this event.
78  * @ifaddr: ethernet address for interface.
79  * @emsg: common parameters of the firmware event message.
80  * @data: event specific data part of the firmware event.
81  */
82 struct brcmf_fweh_queue_item {
83         struct list_head q;
84         enum brcmf_fweh_event_code code;
85         u8 ifidx;
86         u8 ifaddr[ETH_ALEN];
87         struct brcmf_event_msg_be emsg;
88         u8 data[0];
89 };
90
91 /**
92  * struct brcmf_fweh_event_name - code, name mapping entry.
93  */
94 struct brcmf_fweh_event_name {
95         enum brcmf_fweh_event_code code;
96         const char *name;
97 };
98
99 #ifdef DEBUG
100 #define BRCMF_ENUM_DEF(id, val) \
101         { val, #id },
102
103 /* array for mapping code to event name */
104 static struct brcmf_fweh_event_name fweh_event_names[] = {
105         BRCMF_FWEH_EVENT_ENUM_DEFLIST
106 };
107 #undef BRCMF_ENUM_DEF
108
109 /**
110  * brcmf_fweh_event_name() - returns name for given event code.
111  *
112  * @code: code to lookup.
113  */
114 static const char *brcmf_fweh_event_name(enum brcmf_fweh_event_code code)
115 {
116         int i;
117         for (i = 0; i < ARRAY_SIZE(fweh_event_names); i++) {
118                 if (fweh_event_names[i].code == code)
119                         return fweh_event_names[i].name;
120         }
121         return "unknown";
122 }
123 #else
124 static const char *brcmf_fweh_event_name(enum brcmf_fweh_event_code code)
125 {
126         return "nodebug";
127 }
128 #endif
129
130 /**
131  * brcmf_fweh_queue_event() - create and queue event.
132  *
133  * @fweh: firmware event handling info.
134  * @event: event queue entry.
135  */
136 static void brcmf_fweh_queue_event(struct brcmf_fweh_info *fweh,
137                                    struct brcmf_fweh_queue_item *event)
138 {
139         ulong flags;
140
141         spin_lock_irqsave(&fweh->evt_q_lock, flags);
142         list_add_tail(&event->q, &fweh->event_q);
143         spin_unlock_irqrestore(&fweh->evt_q_lock, flags);
144         schedule_work(&fweh->event_work);
145 }
146
147 static int brcmf_fweh_call_event_handler(struct brcmf_if *ifp,
148                                          enum brcmf_fweh_event_code code,
149                                          struct brcmf_event_msg *emsg,
150                                          void *data)
151 {
152         struct brcmf_fweh_info *fweh;
153         int err = -EINVAL;
154
155         if (ifp) {
156                 fweh = &ifp->drvr->fweh;
157
158                 /* handle the event if valid interface and handler */
159                 if (fweh->evt_handler[code])
160                         err = fweh->evt_handler[code](ifp, emsg, data);
161                 else
162                         brcmf_err("unhandled event %d ignored\n", code);
163         } else {
164                 brcmf_err("no interface object\n");
165         }
166         return err;
167 }
168
169 /**
170  * brcmf_fweh_handle_if_event() - handle IF event.
171  *
172  * @drvr: driver information object.
173  * @item: queue entry.
174  * @ifpp: interface object (may change upon ADD action).
175  */
176 static void brcmf_fweh_handle_if_event(struct brcmf_pub *drvr,
177                                        struct brcmf_event_msg *emsg,
178                                        void *data)
179 {
180         struct brcmf_if_event *ifevent = data;
181         struct brcmf_if *ifp;
182         int err = 0;
183
184         brcmf_dbg(EVENT, "action: %u idx: %u bsscfg: %u flags: %u role: %u\n",
185                   ifevent->action, ifevent->ifidx, ifevent->bssidx,
186                   ifevent->flags, ifevent->role);
187
188         /* The P2P Device interface event must not be ignored
189          * contrary to what firmware tells us. The only way to
190          * distinguish the P2P Device is by looking at the ifidx
191          * and bssidx received.
192          */
193         if (!(ifevent->ifidx == 0 && ifevent->bssidx == 1) &&
194             (ifevent->flags & BRCMF_E_IF_FLAG_NOIF)) {
195                 brcmf_dbg(EVENT, "event can be ignored\n");
196                 return;
197         }
198         if (ifevent->ifidx >= BRCMF_MAX_IFS) {
199                 brcmf_err("invalid interface index: %u\n",
200                           ifevent->ifidx);
201                 return;
202         }
203
204         ifp = drvr->iflist[ifevent->bssidx];
205
206         if (ifevent->action == BRCMF_E_IF_ADD) {
207                 brcmf_dbg(EVENT, "adding %s (%pM)\n", emsg->ifname,
208                           emsg->addr);
209                 ifp = brcmf_add_if(drvr, ifevent->bssidx, ifevent->ifidx,
210                                    emsg->ifname, emsg->addr);
211                 if (IS_ERR(ifp))
212                         return;
213                 brcmf_fws_add_interface(ifp);
214                 if (!drvr->fweh.evt_handler[BRCMF_E_IF])
215                         if (brcmf_net_attach(ifp, false) < 0)
216                                 return;
217         }
218
219         if (ifp && ifevent->action == BRCMF_E_IF_CHANGE)
220                 brcmf_fws_reset_interface(ifp);
221
222         err = brcmf_fweh_call_event_handler(ifp, emsg->event_code, emsg, data);
223
224         if (ifp && ifevent->action == BRCMF_E_IF_DEL) {
225                 brcmf_fws_del_interface(ifp);
226                 brcmf_del_if(drvr, ifevent->bssidx);
227         }
228 }
229
230 /**
231  * brcmf_fweh_dequeue_event() - get event from the queue.
232  *
233  * @fweh: firmware event handling info.
234  */
235 static struct brcmf_fweh_queue_item *
236 brcmf_fweh_dequeue_event(struct brcmf_fweh_info *fweh)
237 {
238         struct brcmf_fweh_queue_item *event = NULL;
239         ulong flags;
240
241         spin_lock_irqsave(&fweh->evt_q_lock, flags);
242         if (!list_empty(&fweh->event_q)) {
243                 event = list_first_entry(&fweh->event_q,
244                                          struct brcmf_fweh_queue_item, q);
245                 list_del(&event->q);
246         }
247         spin_unlock_irqrestore(&fweh->evt_q_lock, flags);
248
249         return event;
250 }
251
252 /**
253  * brcmf_fweh_event_worker() - firmware event worker.
254  *
255  * @work: worker object.
256  */
257 static void brcmf_fweh_event_worker(struct work_struct *work)
258 {
259         struct brcmf_pub *drvr;
260         struct brcmf_if *ifp;
261         struct brcmf_fweh_info *fweh;
262         struct brcmf_fweh_queue_item *event;
263         int err = 0;
264         struct brcmf_event_msg_be *emsg_be;
265         struct brcmf_event_msg emsg;
266
267         fweh = container_of(work, struct brcmf_fweh_info, event_work);
268         drvr = container_of(fweh, struct brcmf_pub, fweh);
269
270         while ((event = brcmf_fweh_dequeue_event(fweh))) {
271                 brcmf_dbg(EVENT, "event %s (%u) ifidx %u bsscfg %u addr %pM\n",
272                           brcmf_fweh_event_name(event->code), event->code,
273                           event->emsg.ifidx, event->emsg.bsscfgidx,
274                           event->emsg.addr);
275
276                 /* convert event message */
277                 emsg_be = &event->emsg;
278                 emsg.version = be16_to_cpu(emsg_be->version);
279                 emsg.flags = be16_to_cpu(emsg_be->flags);
280                 emsg.event_code = event->code;
281                 emsg.status = be32_to_cpu(emsg_be->status);
282                 emsg.reason = be32_to_cpu(emsg_be->reason);
283                 emsg.auth_type = be32_to_cpu(emsg_be->auth_type);
284                 emsg.datalen = be32_to_cpu(emsg_be->datalen);
285                 memcpy(emsg.addr, emsg_be->addr, ETH_ALEN);
286                 memcpy(emsg.ifname, emsg_be->ifname, sizeof(emsg.ifname));
287                 emsg.ifidx = emsg_be->ifidx;
288                 emsg.bsscfgidx = emsg_be->bsscfgidx;
289
290                 brcmf_dbg(EVENT, "  version %u flags %u status %u reason %u\n",
291                           emsg.version, emsg.flags, emsg.status, emsg.reason);
292                 brcmf_dbg_hex_dump(BRCMF_EVENT_ON(), event->data,
293                                    min_t(u32, emsg.datalen, 64),
294                                    "event payload, len=%d\n", emsg.datalen);
295
296                 /* special handling of interface event */
297                 if (event->code == BRCMF_E_IF) {
298                         brcmf_fweh_handle_if_event(drvr, &emsg, event->data);
299                         goto event_free;
300                 }
301
302                 if ((event->code == BRCMF_E_TDLS_PEER_EVENT) &&
303                     (emsg.bsscfgidx == 1))
304                         ifp = drvr->iflist[0];
305                 else
306                         ifp = drvr->iflist[emsg.bsscfgidx];
307                 err = brcmf_fweh_call_event_handler(ifp, event->code, &emsg,
308                                                     event->data);
309                 if (err) {
310                         brcmf_err("event handler failed (%d)\n",
311                                   event->code);
312                         err = 0;
313                 }
314 event_free:
315                 kfree(event);
316         }
317 }
318
319 /**
320  * brcmf_fweh_attach() - initialize firmware event handling.
321  *
322  * @drvr: driver information object.
323  */
324 void brcmf_fweh_attach(struct brcmf_pub *drvr)
325 {
326         struct brcmf_fweh_info *fweh = &drvr->fweh;
327         INIT_WORK(&fweh->event_work, brcmf_fweh_event_worker);
328         spin_lock_init(&fweh->evt_q_lock);
329         INIT_LIST_HEAD(&fweh->event_q);
330 }
331
332 /**
333  * brcmf_fweh_detach() - cleanup firmware event handling.
334  *
335  * @drvr: driver information object.
336  */
337 void brcmf_fweh_detach(struct brcmf_pub *drvr)
338 {
339         struct brcmf_fweh_info *fweh = &drvr->fweh;
340         struct brcmf_if *ifp = drvr->iflist[0];
341         s8 eventmask[BRCMF_EVENTING_MASK_LEN];
342
343         if (ifp) {
344                 /* clear all events */
345                 memset(eventmask, 0, BRCMF_EVENTING_MASK_LEN);
346                 (void)brcmf_fil_iovar_data_set(ifp, "event_msgs",
347                                                eventmask,
348                                                BRCMF_EVENTING_MASK_LEN);
349         }
350         /* cancel the worker */
351         cancel_work_sync(&fweh->event_work);
352         WARN_ON(!list_empty(&fweh->event_q));
353         memset(fweh->evt_handler, 0, sizeof(fweh->evt_handler));
354 }
355
356 /**
357  * brcmf_fweh_register() - register handler for given event code.
358  *
359  * @drvr: driver information object.
360  * @code: event code.
361  * @handler: handler for the given event code.
362  */
363 int brcmf_fweh_register(struct brcmf_pub *drvr, enum brcmf_fweh_event_code code,
364                         brcmf_fweh_handler_t handler)
365 {
366         if (drvr->fweh.evt_handler[code]) {
367                 brcmf_err("event code %d already registered\n", code);
368                 return -ENOSPC;
369         }
370         drvr->fweh.evt_handler[code] = handler;
371         brcmf_dbg(TRACE, "event handler registered for %s\n",
372                   brcmf_fweh_event_name(code));
373         return 0;
374 }
375
376 /**
377  * brcmf_fweh_unregister() - remove handler for given code.
378  *
379  * @drvr: driver information object.
380  * @code: event code.
381  */
382 void brcmf_fweh_unregister(struct brcmf_pub *drvr,
383                            enum brcmf_fweh_event_code code)
384 {
385         brcmf_dbg(TRACE, "event handler cleared for %s\n",
386                   brcmf_fweh_event_name(code));
387         drvr->fweh.evt_handler[code] = NULL;
388 }
389
390 /**
391  * brcmf_fweh_activate_events() - enables firmware events registered.
392  *
393  * @ifp: primary interface object.
394  */
395 int brcmf_fweh_activate_events(struct brcmf_if *ifp)
396 {
397         int i, err;
398         s8 eventmask[BRCMF_EVENTING_MASK_LEN];
399
400         for (i = 0; i < BRCMF_E_LAST; i++) {
401                 if (ifp->drvr->fweh.evt_handler[i]) {
402                         brcmf_dbg(EVENT, "enable event %s\n",
403                                   brcmf_fweh_event_name(i));
404                         setbit(eventmask, i);
405                 }
406         }
407
408         /* want to handle IF event as well */
409         brcmf_dbg(EVENT, "enable event IF\n");
410         setbit(eventmask, BRCMF_E_IF);
411
412         err = brcmf_fil_iovar_data_set(ifp, "event_msgs",
413                                        eventmask, BRCMF_EVENTING_MASK_LEN);
414         if (err)
415                 brcmf_err("Set event_msgs error (%d)\n", err);
416
417         return err;
418 }
419
420 /**
421  * brcmf_fweh_process_event() - process skb as firmware event.
422  *
423  * @drvr: driver information object.
424  * @event_packet: event packet to process.
425  *
426  * If the packet buffer contains a firmware event message it will
427  * dispatch the event to a registered handler (using worker).
428  */
429 void brcmf_fweh_process_event(struct brcmf_pub *drvr,
430                               struct brcmf_event *event_packet)
431 {
432         enum brcmf_fweh_event_code code;
433         struct brcmf_fweh_info *fweh = &drvr->fweh;
434         struct brcmf_fweh_queue_item *event;
435         gfp_t alloc_flag = GFP_KERNEL;
436         void *data;
437         u32 datalen;
438
439         /* get event info */
440         code = get_unaligned_be32(&event_packet->msg.event_type);
441         datalen = get_unaligned_be32(&event_packet->msg.datalen);
442         data = &event_packet[1];
443
444         if (code >= BRCMF_E_LAST)
445                 return;
446
447         if (code != BRCMF_E_IF && !fweh->evt_handler[code])
448                 return;
449
450         if (in_interrupt())
451                 alloc_flag = GFP_ATOMIC;
452
453         event = kzalloc(sizeof(*event) + datalen, alloc_flag);
454         if (!event)
455                 return;
456
457         event->code = code;
458         event->ifidx = event_packet->msg.ifidx;
459
460         /* use memcpy to get aligned event message */
461         memcpy(&event->emsg, &event_packet->msg, sizeof(event->emsg));
462         memcpy(event->data, data, datalen);
463         memcpy(event->ifaddr, event_packet->eth.h_dest, ETH_ALEN);
464
465         brcmf_fweh_queue_event(fweh, event);
466 }