1b4c3e9b5SBjoern A. Zeeb // SPDX-License-Identifier: ISC
2b4c3e9b5SBjoern A. Zeeb /*
3b4c3e9b5SBjoern A. Zeeb * Copyright (c) 2014 Broadcom Corporation
4b4c3e9b5SBjoern A. Zeeb */
5b4c3e9b5SBjoern A. Zeeb
6b4c3e9b5SBjoern A. Zeeb #include <linux/vmalloc.h>
7b4c3e9b5SBjoern A. Zeeb #include <net/cfg80211.h>
8b4c3e9b5SBjoern A. Zeeb #include <net/netlink.h>
9b4c3e9b5SBjoern A. Zeeb
10b4c3e9b5SBjoern A. Zeeb #include <brcmu_wifi.h>
11b4c3e9b5SBjoern A. Zeeb #include "fwil_types.h"
12b4c3e9b5SBjoern A. Zeeb #include "core.h"
13b4c3e9b5SBjoern A. Zeeb #include "p2p.h"
14b4c3e9b5SBjoern A. Zeeb #include "debug.h"
15b4c3e9b5SBjoern A. Zeeb #include "cfg80211.h"
16b4c3e9b5SBjoern A. Zeeb #include "vendor.h"
17b4c3e9b5SBjoern A. Zeeb #include "fwil.h"
18b4c3e9b5SBjoern A. Zeeb
brcmf_cfg80211_vndr_cmds_dcmd_handler(struct wiphy * wiphy,struct wireless_dev * wdev,const void * data,int len)19b4c3e9b5SBjoern A. Zeeb static int brcmf_cfg80211_vndr_cmds_dcmd_handler(struct wiphy *wiphy,
20b4c3e9b5SBjoern A. Zeeb struct wireless_dev *wdev,
21b4c3e9b5SBjoern A. Zeeb const void *data, int len)
22b4c3e9b5SBjoern A. Zeeb {
23b4c3e9b5SBjoern A. Zeeb struct brcmf_cfg80211_vif *vif;
24b4c3e9b5SBjoern A. Zeeb struct brcmf_if *ifp;
25b4c3e9b5SBjoern A. Zeeb const struct brcmf_vndr_dcmd_hdr *cmdhdr = data;
26b4c3e9b5SBjoern A. Zeeb struct sk_buff *reply;
27b4c3e9b5SBjoern A. Zeeb unsigned int payload, ret_len;
28b4c3e9b5SBjoern A. Zeeb void *dcmd_buf = NULL, *wr_pointer;
29b4c3e9b5SBjoern A. Zeeb u16 msglen, maxmsglen = PAGE_SIZE - 0x100;
30b4c3e9b5SBjoern A. Zeeb int ret;
31b4c3e9b5SBjoern A. Zeeb
32b4c3e9b5SBjoern A. Zeeb if (len < sizeof(*cmdhdr)) {
33b4c3e9b5SBjoern A. Zeeb brcmf_err("vendor command too short: %d\n", len);
34b4c3e9b5SBjoern A. Zeeb return -EINVAL;
35b4c3e9b5SBjoern A. Zeeb }
36b4c3e9b5SBjoern A. Zeeb
37b4c3e9b5SBjoern A. Zeeb vif = container_of(wdev, struct brcmf_cfg80211_vif, wdev);
38b4c3e9b5SBjoern A. Zeeb ifp = vif->ifp;
39b4c3e9b5SBjoern A. Zeeb
40b4c3e9b5SBjoern A. Zeeb brcmf_dbg(TRACE, "ifidx=%d, cmd=%d\n", ifp->ifidx, cmdhdr->cmd);
41b4c3e9b5SBjoern A. Zeeb
42b4c3e9b5SBjoern A. Zeeb if (cmdhdr->offset > len) {
43b4c3e9b5SBjoern A. Zeeb brcmf_err("bad buffer offset %d > %d\n", cmdhdr->offset, len);
44b4c3e9b5SBjoern A. Zeeb return -EINVAL;
45b4c3e9b5SBjoern A. Zeeb }
46b4c3e9b5SBjoern A. Zeeb
47b4c3e9b5SBjoern A. Zeeb len -= cmdhdr->offset;
48b4c3e9b5SBjoern A. Zeeb ret_len = cmdhdr->len;
49b4c3e9b5SBjoern A. Zeeb if (ret_len > 0 || len > 0) {
50b4c3e9b5SBjoern A. Zeeb if (len > BRCMF_DCMD_MAXLEN) {
51b4c3e9b5SBjoern A. Zeeb brcmf_err("oversize input buffer %d\n", len);
52b4c3e9b5SBjoern A. Zeeb len = BRCMF_DCMD_MAXLEN;
53b4c3e9b5SBjoern A. Zeeb }
54b4c3e9b5SBjoern A. Zeeb if (ret_len > BRCMF_DCMD_MAXLEN) {
55b4c3e9b5SBjoern A. Zeeb brcmf_err("oversize return buffer %d\n", ret_len);
56b4c3e9b5SBjoern A. Zeeb ret_len = BRCMF_DCMD_MAXLEN;
57b4c3e9b5SBjoern A. Zeeb }
58b4c3e9b5SBjoern A. Zeeb payload = max_t(unsigned int, ret_len, len) + 1;
59b4c3e9b5SBjoern A. Zeeb dcmd_buf = vzalloc(payload);
60b4c3e9b5SBjoern A. Zeeb if (NULL == dcmd_buf)
61b4c3e9b5SBjoern A. Zeeb return -ENOMEM;
62b4c3e9b5SBjoern A. Zeeb
63*902136e0SBjoern A. Zeeb #if defined(__linux__)
64b4c3e9b5SBjoern A. Zeeb memcpy(dcmd_buf, (void *)cmdhdr + cmdhdr->offset, len);
65b4c3e9b5SBjoern A. Zeeb *(char *)(dcmd_buf + len) = '\0';
66*902136e0SBjoern A. Zeeb #elif defined(__FreeBSD__)
67*902136e0SBjoern A. Zeeb memcpy(dcmd_buf, (void *)((uintptr_t)cmdhdr + cmdhdr->offset), len);
68*902136e0SBjoern A. Zeeb *(char *)((uintptr_t)dcmd_buf + len) = '\0';
69*902136e0SBjoern A. Zeeb #endif
70b4c3e9b5SBjoern A. Zeeb }
71b4c3e9b5SBjoern A. Zeeb
72b4c3e9b5SBjoern A. Zeeb if (cmdhdr->set)
73b4c3e9b5SBjoern A. Zeeb ret = brcmf_fil_cmd_data_set(ifp, cmdhdr->cmd, dcmd_buf,
74b4c3e9b5SBjoern A. Zeeb ret_len);
75b4c3e9b5SBjoern A. Zeeb else
76b4c3e9b5SBjoern A. Zeeb ret = brcmf_fil_cmd_data_get(ifp, cmdhdr->cmd, dcmd_buf,
77b4c3e9b5SBjoern A. Zeeb ret_len);
78b4c3e9b5SBjoern A. Zeeb if (ret != 0)
79b4c3e9b5SBjoern A. Zeeb goto exit;
80b4c3e9b5SBjoern A. Zeeb
81b4c3e9b5SBjoern A. Zeeb wr_pointer = dcmd_buf;
82b4c3e9b5SBjoern A. Zeeb while (ret_len > 0) {
83b4c3e9b5SBjoern A. Zeeb msglen = ret_len > maxmsglen ? maxmsglen : ret_len;
84b4c3e9b5SBjoern A. Zeeb ret_len -= msglen;
85b4c3e9b5SBjoern A. Zeeb payload = msglen + sizeof(msglen);
86b4c3e9b5SBjoern A. Zeeb reply = cfg80211_vendor_cmd_alloc_reply_skb(wiphy, payload);
87b4c3e9b5SBjoern A. Zeeb if (NULL == reply) {
88b4c3e9b5SBjoern A. Zeeb ret = -ENOMEM;
89b4c3e9b5SBjoern A. Zeeb break;
90b4c3e9b5SBjoern A. Zeeb }
91b4c3e9b5SBjoern A. Zeeb
92b4c3e9b5SBjoern A. Zeeb if (nla_put(reply, BRCMF_NLATTR_DATA, msglen, wr_pointer) ||
93b4c3e9b5SBjoern A. Zeeb nla_put_u16(reply, BRCMF_NLATTR_LEN, msglen)) {
94b4c3e9b5SBjoern A. Zeeb kfree_skb(reply);
95b4c3e9b5SBjoern A. Zeeb ret = -ENOBUFS;
96b4c3e9b5SBjoern A. Zeeb break;
97b4c3e9b5SBjoern A. Zeeb }
98b4c3e9b5SBjoern A. Zeeb
99b4c3e9b5SBjoern A. Zeeb ret = cfg80211_vendor_cmd_reply(reply);
100b4c3e9b5SBjoern A. Zeeb if (ret)
101b4c3e9b5SBjoern A. Zeeb break;
102b4c3e9b5SBjoern A. Zeeb
103*902136e0SBjoern A. Zeeb #if defined(__linux__)
104b4c3e9b5SBjoern A. Zeeb wr_pointer += msglen;
105*902136e0SBjoern A. Zeeb #elif defined(__FreeBSD__)
106*902136e0SBjoern A. Zeeb wr_pointer = (void *)((uintptr_t)wr_pointer + msglen);
107*902136e0SBjoern A. Zeeb #endif
108b4c3e9b5SBjoern A. Zeeb }
109b4c3e9b5SBjoern A. Zeeb
110b4c3e9b5SBjoern A. Zeeb exit:
111b4c3e9b5SBjoern A. Zeeb vfree(dcmd_buf);
112b4c3e9b5SBjoern A. Zeeb
113b4c3e9b5SBjoern A. Zeeb return ret;
114b4c3e9b5SBjoern A. Zeeb }
115b4c3e9b5SBjoern A. Zeeb
116b4c3e9b5SBjoern A. Zeeb const struct wiphy_vendor_command brcmf_vendor_cmds[] = {
117b4c3e9b5SBjoern A. Zeeb {
118b4c3e9b5SBjoern A. Zeeb {
119b4c3e9b5SBjoern A. Zeeb .vendor_id = BROADCOM_OUI,
120b4c3e9b5SBjoern A. Zeeb .subcmd = BRCMF_VNDR_CMDS_DCMD
121b4c3e9b5SBjoern A. Zeeb },
122b4c3e9b5SBjoern A. Zeeb .flags = WIPHY_VENDOR_CMD_NEED_WDEV |
123b4c3e9b5SBjoern A. Zeeb WIPHY_VENDOR_CMD_NEED_NETDEV,
124b4c3e9b5SBjoern A. Zeeb .policy = VENDOR_CMD_RAW_DATA,
125b4c3e9b5SBjoern A. Zeeb .doit = brcmf_cfg80211_vndr_cmds_dcmd_handler
126b4c3e9b5SBjoern A. Zeeb },
127b4c3e9b5SBjoern A. Zeeb };
128