xref: /freebsd/sys/dev/bwn/if_bwn.c (revision 97cb52fa9aefd90fad38790fded50905aeeb9b9e)
1 /*-
2  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3  *
4  * Copyright (c) 2009-2010 Weongyo Jeong <weongyo@freebsd.org>
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer,
12  *    without modification.
13  * 2. Redistributions in binary form must reproduce at minimum a disclaimer
14  *    similar to the "NO WARRANTY" disclaimer below ("Disclaimer") and any
15  *    redistribution must be conditioned upon including a substantially
16  *    similar Disclaimer requirement for further binary redistribution.
17  *
18  * NO WARRANTY
19  * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
20  * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
21  * LIMITED TO, THE IMPLIED WARRANTIES OF NONINFRINGEMENT, MERCHANTIBILITY
22  * AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL
23  * THE COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR SPECIAL, EXEMPLARY,
24  * OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
25  * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
26  * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER
27  * IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
28  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
29  * THE POSSIBILITY OF SUCH DAMAGES.
30  */
31 
32 #include <sys/cdefs.h>
33 __FBSDID("$FreeBSD$");
34 
35 /*
36  * The Broadcom Wireless LAN controller driver.
37  */
38 
39 #include "opt_bwn.h"
40 #include "opt_wlan.h"
41 
42 #include <sys/param.h>
43 #include <sys/systm.h>
44 #include <sys/kernel.h>
45 #include <sys/malloc.h>
46 #include <sys/module.h>
47 #include <sys/endian.h>
48 #include <sys/errno.h>
49 #include <sys/firmware.h>
50 #include <sys/lock.h>
51 #include <sys/mutex.h>
52 #include <machine/bus.h>
53 #include <machine/resource.h>
54 #include <sys/bus.h>
55 #include <sys/rman.h>
56 #include <sys/socket.h>
57 #include <sys/sockio.h>
58 
59 #include <net/ethernet.h>
60 #include <net/if.h>
61 #include <net/if_var.h>
62 #include <net/if_arp.h>
63 #include <net/if_dl.h>
64 #include <net/if_llc.h>
65 #include <net/if_media.h>
66 #include <net/if_types.h>
67 
68 #include <dev/pci/pcivar.h>
69 #include <dev/pci/pcireg.h>
70 
71 #include <net80211/ieee80211_var.h>
72 #include <net80211/ieee80211_radiotap.h>
73 #include <net80211/ieee80211_regdomain.h>
74 #include <net80211/ieee80211_phy.h>
75 #include <net80211/ieee80211_ratectl.h>
76 
77 #include <dev/bwn/if_bwn_siba.h>
78 
79 #include <dev/bwn/if_bwnreg.h>
80 #include <dev/bwn/if_bwnvar.h>
81 
82 #include <dev/bwn/if_bwn_debug.h>
83 #include <dev/bwn/if_bwn_misc.h>
84 #include <dev/bwn/if_bwn_util.h>
85 #include <dev/bwn/if_bwn_phy_common.h>
86 #include <dev/bwn/if_bwn_phy_g.h>
87 #include <dev/bwn/if_bwn_phy_lp.h>
88 #include <dev/bwn/if_bwn_phy_n.h>
89 
90 static SYSCTL_NODE(_hw, OID_AUTO, bwn, CTLFLAG_RD, 0,
91     "Broadcom driver parameters");
92 
93 /*
94  * Tunable & sysctl variables.
95  */
96 
97 #ifdef BWN_DEBUG
98 static	int bwn_debug = 0;
99 SYSCTL_INT(_hw_bwn, OID_AUTO, debug, CTLFLAG_RWTUN, &bwn_debug, 0,
100     "Broadcom debugging printfs");
101 #endif
102 
103 static int	bwn_bfp = 0;		/* use "Bad Frames Preemption" */
104 SYSCTL_INT(_hw_bwn, OID_AUTO, bfp, CTLFLAG_RW, &bwn_bfp, 0,
105     "uses Bad Frames Preemption");
106 static int	bwn_bluetooth = 1;
107 SYSCTL_INT(_hw_bwn, OID_AUTO, bluetooth, CTLFLAG_RW, &bwn_bluetooth, 0,
108     "turns on Bluetooth Coexistence");
109 static int	bwn_hwpctl = 0;
110 SYSCTL_INT(_hw_bwn, OID_AUTO, hwpctl, CTLFLAG_RW, &bwn_hwpctl, 0,
111     "uses H/W power control");
112 static int	bwn_msi_disable = 0;		/* MSI disabled  */
113 TUNABLE_INT("hw.bwn.msi_disable", &bwn_msi_disable);
114 static int	bwn_usedma = 1;
115 SYSCTL_INT(_hw_bwn, OID_AUTO, usedma, CTLFLAG_RD, &bwn_usedma, 0,
116     "uses DMA");
117 TUNABLE_INT("hw.bwn.usedma", &bwn_usedma);
118 static int	bwn_wme = 1;
119 SYSCTL_INT(_hw_bwn, OID_AUTO, wme, CTLFLAG_RW, &bwn_wme, 0,
120     "uses WME support");
121 
122 static void	bwn_attach_pre(struct bwn_softc *);
123 static int	bwn_attach_post(struct bwn_softc *);
124 static void	bwn_sprom_bugfixes(device_t);
125 static int	bwn_init(struct bwn_softc *);
126 static void	bwn_parent(struct ieee80211com *);
127 static void	bwn_start(struct bwn_softc *);
128 static int	bwn_transmit(struct ieee80211com *, struct mbuf *);
129 static int	bwn_attach_core(struct bwn_mac *);
130 static int	bwn_phy_getinfo(struct bwn_mac *, int);
131 static int	bwn_chiptest(struct bwn_mac *);
132 static int	bwn_setup_channels(struct bwn_mac *, int, int);
133 static void	bwn_shm_ctlword(struct bwn_mac *, uint16_t,
134 		    uint16_t);
135 static void	bwn_addchannels(struct ieee80211_channel [], int, int *,
136 		    const struct bwn_channelinfo *, const uint8_t []);
137 static int	bwn_raw_xmit(struct ieee80211_node *, struct mbuf *,
138 		    const struct ieee80211_bpf_params *);
139 static void	bwn_updateslot(struct ieee80211com *);
140 static void	bwn_update_promisc(struct ieee80211com *);
141 static void	bwn_wme_init(struct bwn_mac *);
142 static int	bwn_wme_update(struct ieee80211com *);
143 static void	bwn_wme_clear(struct bwn_softc *);
144 static void	bwn_wme_load(struct bwn_mac *);
145 static void	bwn_wme_loadparams(struct bwn_mac *,
146 		    const struct wmeParams *, uint16_t);
147 static void	bwn_scan_start(struct ieee80211com *);
148 static void	bwn_scan_end(struct ieee80211com *);
149 static void	bwn_set_channel(struct ieee80211com *);
150 static struct ieee80211vap *bwn_vap_create(struct ieee80211com *,
151 		    const char [IFNAMSIZ], int, enum ieee80211_opmode, int,
152 		    const uint8_t [IEEE80211_ADDR_LEN],
153 		    const uint8_t [IEEE80211_ADDR_LEN]);
154 static void	bwn_vap_delete(struct ieee80211vap *);
155 static void	bwn_stop(struct bwn_softc *);
156 static int	bwn_core_init(struct bwn_mac *);
157 static void	bwn_core_start(struct bwn_mac *);
158 static void	bwn_core_exit(struct bwn_mac *);
159 static void	bwn_bt_disable(struct bwn_mac *);
160 static int	bwn_chip_init(struct bwn_mac *);
161 static void	bwn_set_txretry(struct bwn_mac *, int, int);
162 static void	bwn_rate_init(struct bwn_mac *);
163 static void	bwn_set_phytxctl(struct bwn_mac *);
164 static void	bwn_spu_setdelay(struct bwn_mac *, int);
165 static void	bwn_bt_enable(struct bwn_mac *);
166 static void	bwn_set_macaddr(struct bwn_mac *);
167 static void	bwn_crypt_init(struct bwn_mac *);
168 static void	bwn_chip_exit(struct bwn_mac *);
169 static int	bwn_fw_fillinfo(struct bwn_mac *);
170 static int	bwn_fw_loaducode(struct bwn_mac *);
171 static int	bwn_gpio_init(struct bwn_mac *);
172 static int	bwn_fw_loadinitvals(struct bwn_mac *);
173 static int	bwn_phy_init(struct bwn_mac *);
174 static void	bwn_set_txantenna(struct bwn_mac *, int);
175 static void	bwn_set_opmode(struct bwn_mac *);
176 static void	bwn_rate_write(struct bwn_mac *, uint16_t, int);
177 static uint8_t	bwn_plcp_getcck(const uint8_t);
178 static uint8_t	bwn_plcp_getofdm(const uint8_t);
179 static void	bwn_pio_init(struct bwn_mac *);
180 static uint16_t	bwn_pio_idx2base(struct bwn_mac *, int);
181 static void	bwn_pio_set_txqueue(struct bwn_mac *, struct bwn_pio_txqueue *,
182 		    int);
183 static void	bwn_pio_setupqueue_rx(struct bwn_mac *,
184 		    struct bwn_pio_rxqueue *, int);
185 static void	bwn_destroy_queue_tx(struct bwn_pio_txqueue *);
186 static uint16_t	bwn_pio_read_2(struct bwn_mac *, struct bwn_pio_txqueue *,
187 		    uint16_t);
188 static void	bwn_pio_cancel_tx_packets(struct bwn_pio_txqueue *);
189 static int	bwn_pio_rx(struct bwn_pio_rxqueue *);
190 static uint8_t	bwn_pio_rxeof(struct bwn_pio_rxqueue *);
191 static void	bwn_pio_handle_txeof(struct bwn_mac *,
192 		    const struct bwn_txstatus *);
193 static uint16_t	bwn_pio_rx_read_2(struct bwn_pio_rxqueue *, uint16_t);
194 static uint32_t	bwn_pio_rx_read_4(struct bwn_pio_rxqueue *, uint16_t);
195 static void	bwn_pio_rx_write_2(struct bwn_pio_rxqueue *, uint16_t,
196 		    uint16_t);
197 static void	bwn_pio_rx_write_4(struct bwn_pio_rxqueue *, uint16_t,
198 		    uint32_t);
199 static int	bwn_pio_tx_start(struct bwn_mac *, struct ieee80211_node *,
200 		    struct mbuf *);
201 static struct bwn_pio_txqueue *bwn_pio_select(struct bwn_mac *, uint8_t);
202 static uint32_t	bwn_pio_write_multi_4(struct bwn_mac *,
203 		    struct bwn_pio_txqueue *, uint32_t, const void *, int);
204 static void	bwn_pio_write_4(struct bwn_mac *, struct bwn_pio_txqueue *,
205 		    uint16_t, uint32_t);
206 static uint16_t	bwn_pio_write_multi_2(struct bwn_mac *,
207 		    struct bwn_pio_txqueue *, uint16_t, const void *, int);
208 static uint16_t	bwn_pio_write_mbuf_2(struct bwn_mac *,
209 		    struct bwn_pio_txqueue *, uint16_t, struct mbuf *);
210 static struct bwn_pio_txqueue *bwn_pio_parse_cookie(struct bwn_mac *,
211 		    uint16_t, struct bwn_pio_txpkt **);
212 static void	bwn_dma_init(struct bwn_mac *);
213 static void	bwn_dma_rxdirectfifo(struct bwn_mac *, int, uint8_t);
214 static int	bwn_dma_mask2type(uint64_t);
215 static uint64_t	bwn_dma_mask(struct bwn_mac *);
216 static uint16_t	bwn_dma_base(int, int);
217 static void	bwn_dma_ringfree(struct bwn_dma_ring **);
218 static void	bwn_dma_32_getdesc(struct bwn_dma_ring *,
219 		    int, struct bwn_dmadesc_generic **,
220 		    struct bwn_dmadesc_meta **);
221 static void	bwn_dma_32_setdesc(struct bwn_dma_ring *,
222 		    struct bwn_dmadesc_generic *, bus_addr_t, uint16_t, int,
223 		    int, int);
224 static void	bwn_dma_32_start_transfer(struct bwn_dma_ring *, int);
225 static void	bwn_dma_32_suspend(struct bwn_dma_ring *);
226 static void	bwn_dma_32_resume(struct bwn_dma_ring *);
227 static int	bwn_dma_32_get_curslot(struct bwn_dma_ring *);
228 static void	bwn_dma_32_set_curslot(struct bwn_dma_ring *, int);
229 static void	bwn_dma_64_getdesc(struct bwn_dma_ring *,
230 		    int, struct bwn_dmadesc_generic **,
231 		    struct bwn_dmadesc_meta **);
232 static void	bwn_dma_64_setdesc(struct bwn_dma_ring *,
233 		    struct bwn_dmadesc_generic *, bus_addr_t, uint16_t, int,
234 		    int, int);
235 static void	bwn_dma_64_start_transfer(struct bwn_dma_ring *, int);
236 static void	bwn_dma_64_suspend(struct bwn_dma_ring *);
237 static void	bwn_dma_64_resume(struct bwn_dma_ring *);
238 static int	bwn_dma_64_get_curslot(struct bwn_dma_ring *);
239 static void	bwn_dma_64_set_curslot(struct bwn_dma_ring *, int);
240 static int	bwn_dma_allocringmemory(struct bwn_dma_ring *);
241 static void	bwn_dma_setup(struct bwn_dma_ring *);
242 static void	bwn_dma_free_ringmemory(struct bwn_dma_ring *);
243 static void	bwn_dma_cleanup(struct bwn_dma_ring *);
244 static void	bwn_dma_free_descbufs(struct bwn_dma_ring *);
245 static int	bwn_dma_tx_reset(struct bwn_mac *, uint16_t, int);
246 static void	bwn_dma_rx(struct bwn_dma_ring *);
247 static int	bwn_dma_rx_reset(struct bwn_mac *, uint16_t, int);
248 static void	bwn_dma_free_descbuf(struct bwn_dma_ring *,
249 		    struct bwn_dmadesc_meta *);
250 static void	bwn_dma_set_redzone(struct bwn_dma_ring *, struct mbuf *);
251 static int	bwn_dma_gettype(struct bwn_mac *);
252 static void	bwn_dma_ring_addr(void *, bus_dma_segment_t *, int, int);
253 static int	bwn_dma_freeslot(struct bwn_dma_ring *);
254 static int	bwn_dma_nextslot(struct bwn_dma_ring *, int);
255 static void	bwn_dma_rxeof(struct bwn_dma_ring *, int *);
256 static int	bwn_dma_newbuf(struct bwn_dma_ring *,
257 		    struct bwn_dmadesc_generic *, struct bwn_dmadesc_meta *,
258 		    int);
259 static void	bwn_dma_buf_addr(void *, bus_dma_segment_t *, int,
260 		    bus_size_t, int);
261 static uint8_t	bwn_dma_check_redzone(struct bwn_dma_ring *, struct mbuf *);
262 static void	bwn_ratectl_tx_complete(const struct ieee80211_node *,
263 		    const struct bwn_txstatus *);
264 static void	bwn_dma_handle_txeof(struct bwn_mac *,
265 		    const struct bwn_txstatus *);
266 static int	bwn_dma_tx_start(struct bwn_mac *, struct ieee80211_node *,
267 		    struct mbuf *);
268 static int	bwn_dma_getslot(struct bwn_dma_ring *);
269 static struct bwn_dma_ring *bwn_dma_select(struct bwn_mac *,
270 		    uint8_t);
271 static int	bwn_dma_attach(struct bwn_mac *);
272 static struct bwn_dma_ring *bwn_dma_ringsetup(struct bwn_mac *,
273 		    int, int, int);
274 static struct bwn_dma_ring *bwn_dma_parse_cookie(struct bwn_mac *,
275 		    const struct bwn_txstatus *, uint16_t, int *);
276 static void	bwn_dma_free(struct bwn_mac *);
277 static int	bwn_fw_gets(struct bwn_mac *, enum bwn_fwtype);
278 static int	bwn_fw_get(struct bwn_mac *, enum bwn_fwtype,
279 		    const char *, struct bwn_fwfile *);
280 static void	bwn_release_firmware(struct bwn_mac *);
281 static void	bwn_do_release_fw(struct bwn_fwfile *);
282 static uint16_t	bwn_fwcaps_read(struct bwn_mac *);
283 static int	bwn_fwinitvals_write(struct bwn_mac *,
284 		    const struct bwn_fwinitvals *, size_t, size_t);
285 static uint16_t	bwn_ant2phy(int);
286 static void	bwn_mac_write_bssid(struct bwn_mac *);
287 static void	bwn_mac_setfilter(struct bwn_mac *, uint16_t,
288 		    const uint8_t *);
289 static void	bwn_key_dowrite(struct bwn_mac *, uint8_t, uint8_t,
290 		    const uint8_t *, size_t, const uint8_t *);
291 static void	bwn_key_macwrite(struct bwn_mac *, uint8_t,
292 		    const uint8_t *);
293 static void	bwn_key_write(struct bwn_mac *, uint8_t, uint8_t,
294 		    const uint8_t *);
295 static void	bwn_phy_exit(struct bwn_mac *);
296 static void	bwn_core_stop(struct bwn_mac *);
297 static int	bwn_switch_band(struct bwn_softc *,
298 		    struct ieee80211_channel *);
299 static void	bwn_phy_reset(struct bwn_mac *);
300 static int	bwn_newstate(struct ieee80211vap *, enum ieee80211_state, int);
301 static void	bwn_set_pretbtt(struct bwn_mac *);
302 static int	bwn_intr(void *);
303 static void	bwn_intrtask(void *, int);
304 static void	bwn_restart(struct bwn_mac *, const char *);
305 static void	bwn_intr_ucode_debug(struct bwn_mac *);
306 static void	bwn_intr_tbtt_indication(struct bwn_mac *);
307 static void	bwn_intr_atim_end(struct bwn_mac *);
308 static void	bwn_intr_beacon(struct bwn_mac *);
309 static void	bwn_intr_pmq(struct bwn_mac *);
310 static void	bwn_intr_noise(struct bwn_mac *);
311 static void	bwn_intr_txeof(struct bwn_mac *);
312 static void	bwn_hwreset(void *, int);
313 static void	bwn_handle_fwpanic(struct bwn_mac *);
314 static void	bwn_load_beacon0(struct bwn_mac *);
315 static void	bwn_load_beacon1(struct bwn_mac *);
316 static uint32_t	bwn_jssi_read(struct bwn_mac *);
317 static void	bwn_noise_gensample(struct bwn_mac *);
318 static void	bwn_handle_txeof(struct bwn_mac *,
319 		    const struct bwn_txstatus *);
320 static void	bwn_rxeof(struct bwn_mac *, struct mbuf *, const void *);
321 static void	bwn_phy_txpower_check(struct bwn_mac *, uint32_t);
322 static int	bwn_tx_start(struct bwn_softc *, struct ieee80211_node *,
323 		    struct mbuf *);
324 static int	bwn_tx_isfull(struct bwn_softc *, struct mbuf *);
325 static int	bwn_set_txhdr(struct bwn_mac *,
326 		    struct ieee80211_node *, struct mbuf *, struct bwn_txhdr *,
327 		    uint16_t);
328 static void	bwn_plcp_genhdr(struct bwn_plcp4 *, const uint16_t,
329 		    const uint8_t);
330 static uint8_t	bwn_antenna_sanitize(struct bwn_mac *, uint8_t);
331 static uint8_t	bwn_get_fbrate(uint8_t);
332 static void	bwn_txpwr(void *, int);
333 static void	bwn_tasks(void *);
334 static void	bwn_task_15s(struct bwn_mac *);
335 static void	bwn_task_30s(struct bwn_mac *);
336 static void	bwn_task_60s(struct bwn_mac *);
337 static int	bwn_plcp_get_ofdmrate(struct bwn_mac *, struct bwn_plcp6 *,
338 		    uint8_t);
339 static int	bwn_plcp_get_cckrate(struct bwn_mac *, struct bwn_plcp6 *);
340 static void	bwn_rx_radiotap(struct bwn_mac *, struct mbuf *,
341 		    const struct bwn_rxhdr4 *, struct bwn_plcp6 *, int,
342 		    int, int);
343 static void	bwn_tsf_read(struct bwn_mac *, uint64_t *);
344 static void	bwn_set_slot_time(struct bwn_mac *, uint16_t);
345 static void	bwn_watchdog(void *);
346 static void	bwn_dma_stop(struct bwn_mac *);
347 static void	bwn_pio_stop(struct bwn_mac *);
348 static void	bwn_dma_ringstop(struct bwn_dma_ring **);
349 static void	bwn_led_attach(struct bwn_mac *);
350 static void	bwn_led_newstate(struct bwn_mac *, enum ieee80211_state);
351 static void	bwn_led_event(struct bwn_mac *, int);
352 static void	bwn_led_blink_start(struct bwn_mac *, int, int);
353 static void	bwn_led_blink_next(void *);
354 static void	bwn_led_blink_end(void *);
355 static void	bwn_rfswitch(void *);
356 static void	bwn_rf_turnon(struct bwn_mac *);
357 static void	bwn_rf_turnoff(struct bwn_mac *);
358 static void	bwn_sysctl_node(struct bwn_softc *);
359 
360 static struct resource_spec bwn_res_spec_legacy[] = {
361 	{ SYS_RES_IRQ,		0,		RF_ACTIVE | RF_SHAREABLE },
362 	{ -1,			0,		0 }
363 };
364 
365 static struct resource_spec bwn_res_spec_msi[] = {
366 	{ SYS_RES_IRQ,		1,		RF_ACTIVE },
367 	{ -1,			0,		0 }
368 };
369 
370 static const struct bwn_channelinfo bwn_chantable_bg = {
371 	.channels = {
372 		{ 2412,  1, 30 }, { 2417,  2, 30 }, { 2422,  3, 30 },
373 		{ 2427,  4, 30 }, { 2432,  5, 30 }, { 2437,  6, 30 },
374 		{ 2442,  7, 30 }, { 2447,  8, 30 }, { 2452,  9, 30 },
375 		{ 2457, 10, 30 }, { 2462, 11, 30 }, { 2467, 12, 30 },
376 		{ 2472, 13, 30 }, { 2484, 14, 30 } },
377 	.nchannels = 14
378 };
379 
380 static const struct bwn_channelinfo bwn_chantable_a = {
381 	.channels = {
382 		{ 5170,  34, 30 }, { 5180,  36, 30 }, { 5190,  38, 30 },
383 		{ 5200,  40, 30 }, { 5210,  42, 30 }, { 5220,  44, 30 },
384 		{ 5230,  46, 30 }, { 5240,  48, 30 }, { 5260,  52, 30 },
385 		{ 5280,  56, 30 }, { 5300,  60, 30 }, { 5320,  64, 30 },
386 		{ 5500, 100, 30 }, { 5520, 104, 30 }, { 5540, 108, 30 },
387 		{ 5560, 112, 30 }, { 5580, 116, 30 }, { 5600, 120, 30 },
388 		{ 5620, 124, 30 }, { 5640, 128, 30 }, { 5660, 132, 30 },
389 		{ 5680, 136, 30 }, { 5700, 140, 30 }, { 5745, 149, 30 },
390 		{ 5765, 153, 30 }, { 5785, 157, 30 }, { 5805, 161, 30 },
391 		{ 5825, 165, 30 }, { 5920, 184, 30 }, { 5940, 188, 30 },
392 		{ 5960, 192, 30 }, { 5980, 196, 30 }, { 6000, 200, 30 },
393 		{ 6020, 204, 30 }, { 6040, 208, 30 }, { 6060, 212, 30 },
394 		{ 6080, 216, 30 } },
395 	.nchannels = 37
396 };
397 
398 #if 0
399 static const struct bwn_channelinfo bwn_chantable_n = {
400 	.channels = {
401 		{ 5160,  32, 30 }, { 5170,  34, 30 }, { 5180,  36, 30 },
402 		{ 5190,  38, 30 }, { 5200,  40, 30 }, { 5210,  42, 30 },
403 		{ 5220,  44, 30 }, { 5230,  46, 30 }, { 5240,  48, 30 },
404 		{ 5250,  50, 30 }, { 5260,  52, 30 }, { 5270,  54, 30 },
405 		{ 5280,  56, 30 }, { 5290,  58, 30 }, { 5300,  60, 30 },
406 		{ 5310,  62, 30 }, { 5320,  64, 30 }, { 5330,  66, 30 },
407 		{ 5340,  68, 30 }, { 5350,  70, 30 }, { 5360,  72, 30 },
408 		{ 5370,  74, 30 }, { 5380,  76, 30 }, { 5390,  78, 30 },
409 		{ 5400,  80, 30 }, { 5410,  82, 30 }, { 5420,  84, 30 },
410 		{ 5430,  86, 30 }, { 5440,  88, 30 }, { 5450,  90, 30 },
411 		{ 5460,  92, 30 }, { 5470,  94, 30 }, { 5480,  96, 30 },
412 		{ 5490,  98, 30 }, { 5500, 100, 30 }, { 5510, 102, 30 },
413 		{ 5520, 104, 30 }, { 5530, 106, 30 }, { 5540, 108, 30 },
414 		{ 5550, 110, 30 }, { 5560, 112, 30 }, { 5570, 114, 30 },
415 		{ 5580, 116, 30 }, { 5590, 118, 30 }, { 5600, 120, 30 },
416 		{ 5610, 122, 30 }, { 5620, 124, 30 }, { 5630, 126, 30 },
417 		{ 5640, 128, 30 }, { 5650, 130, 30 }, { 5660, 132, 30 },
418 		{ 5670, 134, 30 }, { 5680, 136, 30 }, { 5690, 138, 30 },
419 		{ 5700, 140, 30 }, { 5710, 142, 30 }, { 5720, 144, 30 },
420 		{ 5725, 145, 30 }, { 5730, 146, 30 }, { 5735, 147, 30 },
421 		{ 5740, 148, 30 }, { 5745, 149, 30 }, { 5750, 150, 30 },
422 		{ 5755, 151, 30 }, { 5760, 152, 30 }, { 5765, 153, 30 },
423 		{ 5770, 154, 30 }, { 5775, 155, 30 }, { 5780, 156, 30 },
424 		{ 5785, 157, 30 }, { 5790, 158, 30 }, { 5795, 159, 30 },
425 		{ 5800, 160, 30 }, { 5805, 161, 30 }, { 5810, 162, 30 },
426 		{ 5815, 163, 30 }, { 5820, 164, 30 }, { 5825, 165, 30 },
427 		{ 5830, 166, 30 }, { 5840, 168, 30 }, { 5850, 170, 30 },
428 		{ 5860, 172, 30 }, { 5870, 174, 30 }, { 5880, 176, 30 },
429 		{ 5890, 178, 30 }, { 5900, 180, 30 }, { 5910, 182, 30 },
430 		{ 5920, 184, 30 }, { 5930, 186, 30 }, { 5940, 188, 30 },
431 		{ 5950, 190, 30 }, { 5960, 192, 30 }, { 5970, 194, 30 },
432 		{ 5980, 196, 30 }, { 5990, 198, 30 }, { 6000, 200, 30 },
433 		{ 6010, 202, 30 }, { 6020, 204, 30 }, { 6030, 206, 30 },
434 		{ 6040, 208, 30 }, { 6050, 210, 30 }, { 6060, 212, 30 },
435 		{ 6070, 214, 30 }, { 6080, 216, 30 }, { 6090, 218, 30 },
436 		{ 6100, 220, 30 }, { 6110, 222, 30 }, { 6120, 224, 30 },
437 		{ 6130, 226, 30 }, { 6140, 228, 30 } },
438 	.nchannels = 110
439 };
440 #endif
441 
442 #define	VENDOR_LED_ACT(vendor)				\
443 {							\
444 	.vid = PCI_VENDOR_##vendor,			\
445 	.led_act = { BWN_VENDOR_LED_ACT_##vendor }	\
446 }
447 
448 static const struct {
449 	uint16_t	vid;
450 	uint8_t		led_act[BWN_LED_MAX];
451 } bwn_vendor_led_act[] = {
452 	VENDOR_LED_ACT(COMPAQ),
453 	VENDOR_LED_ACT(ASUSTEK)
454 };
455 
456 static const uint8_t bwn_default_led_act[BWN_LED_MAX] =
457 	{ BWN_VENDOR_LED_ACT_DEFAULT };
458 
459 #undef VENDOR_LED_ACT
460 
461 static const struct {
462 	int		on_dur;
463 	int		off_dur;
464 } bwn_led_duration[109] = {
465 	[0]	= { 400, 100 },
466 	[2]	= { 150, 75 },
467 	[4]	= { 90, 45 },
468 	[11]	= { 66, 34 },
469 	[12]	= { 53, 26 },
470 	[18]	= { 42, 21 },
471 	[22]	= { 35, 17 },
472 	[24]	= { 32, 16 },
473 	[36]	= { 21, 10 },
474 	[48]	= { 16, 8 },
475 	[72]	= { 11, 5 },
476 	[96]	= { 9, 4 },
477 	[108]	= { 7, 3 }
478 };
479 
480 static const uint16_t bwn_wme_shm_offsets[] = {
481 	[0] = BWN_WME_BESTEFFORT,
482 	[1] = BWN_WME_BACKGROUND,
483 	[2] = BWN_WME_VOICE,
484 	[3] = BWN_WME_VIDEO,
485 };
486 
487 static const struct siba_devid bwn_devs[] = {
488 	SIBA_DEV(BROADCOM, 80211, 5, "Revision 5"),
489 	SIBA_DEV(BROADCOM, 80211, 6, "Revision 6"),
490 	SIBA_DEV(BROADCOM, 80211, 7, "Revision 7"),
491 	SIBA_DEV(BROADCOM, 80211, 9, "Revision 9"),
492 	SIBA_DEV(BROADCOM, 80211, 10, "Revision 10"),
493 	SIBA_DEV(BROADCOM, 80211, 11, "Revision 11"),
494 	SIBA_DEV(BROADCOM, 80211, 12, "Revision 12"),
495 	SIBA_DEV(BROADCOM, 80211, 13, "Revision 13"),
496 	SIBA_DEV(BROADCOM, 80211, 15, "Revision 15"),
497 	SIBA_DEV(BROADCOM, 80211, 16, "Revision 16")
498 };
499 
500 static const struct bwn_bus_ops *
501 bwn_get_bus_ops(device_t dev)
502 {
503 #if BWN_USE_SIBA
504 	return (NULL);
505 #else
506 	devclass_t	bus_cls;
507 
508 	bus_cls = device_get_devclass(device_get_parent(dev));
509 	if (bus_cls == devclass_find("bhnd"))
510 		return (&bwn_bhnd_bus_ops);
511 	else
512 		return (&bwn_siba_bus_ops);
513 #endif
514 }
515 
516 static int
517 bwn_probe(device_t dev)
518 {
519 	struct bwn_softc	*sc;
520 	int			 i;
521 
522 	sc = device_get_softc(dev);
523 	sc->sc_bus_ops = bwn_get_bus_ops(dev);
524 
525 	for (i = 0; i < nitems(bwn_devs); i++) {
526 		if (siba_get_vendor(dev) == bwn_devs[i].sd_vendor &&
527 		    siba_get_device(dev) == bwn_devs[i].sd_device &&
528 		    siba_get_revid(dev) == bwn_devs[i].sd_rev)
529 			return (BUS_PROBE_DEFAULT);
530 	}
531 
532 	return (ENXIO);
533 }
534 
535 int
536 bwn_attach(device_t dev)
537 {
538 	struct bwn_mac *mac;
539 	struct bwn_softc *sc = device_get_softc(dev);
540 	int error, i, msic, reg;
541 
542 	sc->sc_dev = dev;
543 #ifdef BWN_DEBUG
544 	sc->sc_debug = bwn_debug;
545 #endif
546 
547 	sc->sc_bus_ops = bwn_get_bus_ops(dev);
548 	if ((error = BWN_BUS_OPS_ATTACH(dev))) {
549 		device_printf(sc->sc_dev,
550 		    "bus-specific initialization failed (%d)\n", error);
551 		return (error);
552 	}
553 
554 	if ((sc->sc_flags & BWN_FLAG_ATTACHED) == 0) {
555 		bwn_attach_pre(sc);
556 		bwn_sprom_bugfixes(dev);
557 		sc->sc_flags |= BWN_FLAG_ATTACHED;
558 	}
559 
560 	if (!TAILQ_EMPTY(&sc->sc_maclist)) {
561 		if (siba_get_pci_device(dev) != 0x4313 &&
562 		    siba_get_pci_device(dev) != 0x431a &&
563 		    siba_get_pci_device(dev) != 0x4321) {
564 			device_printf(sc->sc_dev,
565 			    "skip 802.11 cores\n");
566 			return (ENODEV);
567 		}
568 	}
569 
570 	mac = malloc(sizeof(*mac), M_DEVBUF, M_WAITOK | M_ZERO);
571 	mac->mac_sc = sc;
572 	mac->mac_status = BWN_MAC_STATUS_UNINIT;
573 	if (bwn_bfp != 0)
574 		mac->mac_flags |= BWN_MAC_FLAG_BADFRAME_PREEMP;
575 
576 	TASK_INIT(&mac->mac_hwreset, 0, bwn_hwreset, mac);
577 	TASK_INIT(&mac->mac_intrtask, 0, bwn_intrtask, mac);
578 	TASK_INIT(&mac->mac_txpower, 0, bwn_txpwr, mac);
579 
580 	error = bwn_attach_core(mac);
581 	if (error)
582 		goto fail0;
583 	bwn_led_attach(mac);
584 
585 	device_printf(sc->sc_dev, "WLAN (chipid %#x rev %u) "
586 	    "PHY (analog %d type %d rev %d) RADIO (manuf %#x ver %#x rev %d)\n",
587 	    siba_get_chipid(sc->sc_dev), siba_get_revid(sc->sc_dev),
588 	    mac->mac_phy.analog, mac->mac_phy.type, mac->mac_phy.rev,
589 	    mac->mac_phy.rf_manuf, mac->mac_phy.rf_ver,
590 	    mac->mac_phy.rf_rev);
591 	if (mac->mac_flags & BWN_MAC_FLAG_DMA)
592 		device_printf(sc->sc_dev, "DMA (%d bits)\n",
593 		    mac->mac_method.dma.dmatype);
594 	else
595 		device_printf(sc->sc_dev, "PIO\n");
596 
597 #ifdef	BWN_GPL_PHY
598 	device_printf(sc->sc_dev,
599 	    "Note: compiled with BWN_GPL_PHY; includes GPLv2 code\n");
600 #endif
601 
602 	/*
603 	 * setup PCI resources and interrupt.
604 	 */
605 	if (pci_find_cap(dev, PCIY_EXPRESS, &reg) == 0) {
606 		msic = pci_msi_count(dev);
607 		if (bootverbose)
608 			device_printf(sc->sc_dev, "MSI count : %d\n", msic);
609 	} else
610 		msic = 0;
611 
612 	mac->mac_intr_spec = bwn_res_spec_legacy;
613 	if (msic == BWN_MSI_MESSAGES && bwn_msi_disable == 0) {
614 		if (pci_alloc_msi(dev, &msic) == 0) {
615 			device_printf(sc->sc_dev,
616 			    "Using %d MSI messages\n", msic);
617 			mac->mac_intr_spec = bwn_res_spec_msi;
618 			mac->mac_msi = 1;
619 		}
620 	}
621 
622 	error = bus_alloc_resources(dev, mac->mac_intr_spec,
623 	    mac->mac_res_irq);
624 	if (error) {
625 		device_printf(sc->sc_dev,
626 		    "couldn't allocate IRQ resources (%d)\n", error);
627 		goto fail1;
628 	}
629 
630 	if (mac->mac_msi == 0)
631 		error = bus_setup_intr(dev, mac->mac_res_irq[0],
632 		    INTR_TYPE_NET | INTR_MPSAFE, bwn_intr, NULL, mac,
633 		    &mac->mac_intrhand[0]);
634 	else {
635 		for (i = 0; i < BWN_MSI_MESSAGES; i++) {
636 			error = bus_setup_intr(dev, mac->mac_res_irq[i],
637 			    INTR_TYPE_NET | INTR_MPSAFE, bwn_intr, NULL, mac,
638 			    &mac->mac_intrhand[i]);
639 			if (error != 0) {
640 				device_printf(sc->sc_dev,
641 				    "couldn't setup interrupt (%d)\n", error);
642 				break;
643 			}
644 		}
645 	}
646 
647 	TAILQ_INSERT_TAIL(&sc->sc_maclist, mac, mac_list);
648 
649 	/*
650 	 * calls attach-post routine
651 	 */
652 	if ((sc->sc_flags & BWN_FLAG_ATTACHED) != 0)
653 		bwn_attach_post(sc);
654 
655 	return (0);
656 fail1:
657 	if (msic == BWN_MSI_MESSAGES && bwn_msi_disable == 0)
658 		pci_release_msi(dev);
659 fail0:
660 	BWN_BUS_OPS_DETACH(dev);
661 	free(mac, M_DEVBUF);
662 	return (error);
663 }
664 
665 static int
666 bwn_is_valid_ether_addr(uint8_t *addr)
667 {
668 	char zero_addr[6] = { 0, 0, 0, 0, 0, 0 };
669 
670 	if ((addr[0] & 1) || (!bcmp(addr, zero_addr, ETHER_ADDR_LEN)))
671 		return (FALSE);
672 
673 	return (TRUE);
674 }
675 
676 static int
677 bwn_attach_post(struct bwn_softc *sc)
678 {
679 	struct ieee80211com *ic = &sc->sc_ic;
680 
681 	ic->ic_softc = sc;
682 	ic->ic_name = device_get_nameunit(sc->sc_dev);
683 	/* XXX not right but it's not used anywhere important */
684 	ic->ic_phytype = IEEE80211_T_OFDM;
685 	ic->ic_opmode = IEEE80211_M_STA;
686 	ic->ic_caps =
687 		  IEEE80211_C_STA		/* station mode supported */
688 		| IEEE80211_C_MONITOR		/* monitor mode */
689 		| IEEE80211_C_AHDEMO		/* adhoc demo mode */
690 		| IEEE80211_C_SHPREAMBLE	/* short preamble supported */
691 		| IEEE80211_C_SHSLOT		/* short slot time supported */
692 		| IEEE80211_C_WME		/* WME/WMM supported */
693 		| IEEE80211_C_WPA		/* capable of WPA1+WPA2 */
694 #if 0
695 		| IEEE80211_C_BGSCAN		/* capable of bg scanning */
696 #endif
697 		| IEEE80211_C_TXPMGT		/* capable of txpow mgt */
698 		;
699 
700 	ic->ic_flags_ext |= IEEE80211_FEXT_SWBMISS;	/* s/w bmiss */
701 
702 	IEEE80211_ADDR_COPY(ic->ic_macaddr,
703 	    bwn_is_valid_ether_addr(siba_sprom_get_mac_80211a(sc->sc_dev)) ?
704 	    siba_sprom_get_mac_80211a(sc->sc_dev) :
705 	    siba_sprom_get_mac_80211bg(sc->sc_dev));
706 
707 	/* call MI attach routine. */
708 	ieee80211_ifattach(ic);
709 
710 	ic->ic_headroom = sizeof(struct bwn_txhdr);
711 
712 	/* override default methods */
713 	ic->ic_raw_xmit = bwn_raw_xmit;
714 	ic->ic_updateslot = bwn_updateslot;
715 	ic->ic_update_promisc = bwn_update_promisc;
716 	ic->ic_wme.wme_update = bwn_wme_update;
717 	ic->ic_scan_start = bwn_scan_start;
718 	ic->ic_scan_end = bwn_scan_end;
719 	ic->ic_set_channel = bwn_set_channel;
720 	ic->ic_vap_create = bwn_vap_create;
721 	ic->ic_vap_delete = bwn_vap_delete;
722 	ic->ic_transmit = bwn_transmit;
723 	ic->ic_parent = bwn_parent;
724 
725 	ieee80211_radiotap_attach(ic,
726 	    &sc->sc_tx_th.wt_ihdr, sizeof(sc->sc_tx_th),
727 	    BWN_TX_RADIOTAP_PRESENT,
728 	    &sc->sc_rx_th.wr_ihdr, sizeof(sc->sc_rx_th),
729 	    BWN_RX_RADIOTAP_PRESENT);
730 
731 	bwn_sysctl_node(sc);
732 
733 	if (bootverbose)
734 		ieee80211_announce(ic);
735 	return (0);
736 }
737 
738 static void
739 bwn_phy_detach(struct bwn_mac *mac)
740 {
741 
742 	if (mac->mac_phy.detach != NULL)
743 		mac->mac_phy.detach(mac);
744 }
745 
746 int
747 bwn_detach(device_t dev)
748 {
749 	struct bwn_softc *sc = device_get_softc(dev);
750 	struct bwn_mac *mac = sc->sc_curmac;
751 	struct ieee80211com *ic = &sc->sc_ic;
752 	int i;
753 
754 	sc->sc_flags |= BWN_FLAG_INVALID;
755 
756 	if (device_is_attached(sc->sc_dev)) {
757 		BWN_LOCK(sc);
758 		bwn_stop(sc);
759 		BWN_UNLOCK(sc);
760 		bwn_dma_free(mac);
761 		callout_drain(&sc->sc_led_blink_ch);
762 		callout_drain(&sc->sc_rfswitch_ch);
763 		callout_drain(&sc->sc_task_ch);
764 		callout_drain(&sc->sc_watchdog_ch);
765 		bwn_phy_detach(mac);
766 		ieee80211_draintask(ic, &mac->mac_hwreset);
767 		ieee80211_draintask(ic, &mac->mac_txpower);
768 		ieee80211_ifdetach(ic);
769 	}
770 	taskqueue_drain(sc->sc_tq, &mac->mac_intrtask);
771 	taskqueue_free(sc->sc_tq);
772 
773 	for (i = 0; i < BWN_MSI_MESSAGES; i++) {
774 		if (mac->mac_intrhand[i] != NULL) {
775 			bus_teardown_intr(dev, mac->mac_res_irq[i],
776 			    mac->mac_intrhand[i]);
777 			mac->mac_intrhand[i] = NULL;
778 		}
779 	}
780 	bus_release_resources(dev, mac->mac_intr_spec, mac->mac_res_irq);
781 	if (mac->mac_msi != 0)
782 		pci_release_msi(dev);
783 	mbufq_drain(&sc->sc_snd);
784 	bwn_release_firmware(mac);
785 	BWN_LOCK_DESTROY(sc);
786 	BWN_BUS_OPS_DETACH(dev);
787 	return (0);
788 }
789 
790 static void
791 bwn_attach_pre(struct bwn_softc *sc)
792 {
793 
794 	BWN_LOCK_INIT(sc);
795 	TAILQ_INIT(&sc->sc_maclist);
796 	callout_init_mtx(&sc->sc_rfswitch_ch, &sc->sc_mtx, 0);
797 	callout_init_mtx(&sc->sc_task_ch, &sc->sc_mtx, 0);
798 	callout_init_mtx(&sc->sc_watchdog_ch, &sc->sc_mtx, 0);
799 	mbufq_init(&sc->sc_snd, ifqmaxlen);
800 	sc->sc_tq = taskqueue_create_fast("bwn_taskq", M_NOWAIT,
801 		taskqueue_thread_enqueue, &sc->sc_tq);
802 	taskqueue_start_threads(&sc->sc_tq, 1, PI_NET,
803 		"%s taskq", device_get_nameunit(sc->sc_dev));
804 }
805 
806 static void
807 bwn_sprom_bugfixes(device_t dev)
808 {
809 #define	BWN_ISDEV(_vendor, _device, _subvendor, _subdevice)		\
810 	((siba_get_pci_vendor(dev) == PCI_VENDOR_##_vendor) &&		\
811 	 (siba_get_pci_device(dev) == _device) &&			\
812 	 (siba_get_pci_subvendor(dev) == PCI_VENDOR_##_subvendor) &&	\
813 	 (siba_get_pci_subdevice(dev) == _subdevice))
814 
815 	if (siba_get_pci_subvendor(dev) == PCI_VENDOR_APPLE &&
816 	    siba_get_pci_subdevice(dev) == 0x4e &&
817 	    siba_get_pci_revid(dev) > 0x40)
818 		siba_sprom_set_bf_lo(dev,
819 		    siba_sprom_get_bf_lo(dev) | BWN_BFL_PACTRL);
820 	if (siba_get_pci_subvendor(dev) == SIBA_BOARDVENDOR_DELL &&
821 	    siba_get_chipid(dev) == 0x4301 && siba_get_pci_revid(dev) == 0x74)
822 		siba_sprom_set_bf_lo(dev,
823 		    siba_sprom_get_bf_lo(dev) | BWN_BFL_BTCOEXIST);
824 	if (siba_get_type(dev) == SIBA_TYPE_PCI) {
825 		if (BWN_ISDEV(BROADCOM, 0x4318, ASUSTEK, 0x100f) ||
826 		    BWN_ISDEV(BROADCOM, 0x4320, DELL, 0x0003) ||
827 		    BWN_ISDEV(BROADCOM, 0x4320, HP, 0x12f8) ||
828 		    BWN_ISDEV(BROADCOM, 0x4320, LINKSYS, 0x0013) ||
829 		    BWN_ISDEV(BROADCOM, 0x4320, LINKSYS, 0x0014) ||
830 		    BWN_ISDEV(BROADCOM, 0x4320, LINKSYS, 0x0015) ||
831 		    BWN_ISDEV(BROADCOM, 0x4320, MOTOROLA, 0x7010))
832 			siba_sprom_set_bf_lo(dev,
833 			    siba_sprom_get_bf_lo(dev) & ~BWN_BFL_BTCOEXIST);
834 	}
835 #undef	BWN_ISDEV
836 }
837 
838 static void
839 bwn_parent(struct ieee80211com *ic)
840 {
841 	struct bwn_softc *sc = ic->ic_softc;
842 	int startall = 0;
843 
844 	BWN_LOCK(sc);
845 	if (ic->ic_nrunning > 0) {
846 		if ((sc->sc_flags & BWN_FLAG_RUNNING) == 0) {
847 			bwn_init(sc);
848 			startall = 1;
849 		} else
850 			bwn_update_promisc(ic);
851 	} else if (sc->sc_flags & BWN_FLAG_RUNNING)
852 		bwn_stop(sc);
853 	BWN_UNLOCK(sc);
854 
855 	if (startall)
856 		ieee80211_start_all(ic);
857 }
858 
859 static int
860 bwn_transmit(struct ieee80211com *ic, struct mbuf *m)
861 {
862 	struct bwn_softc *sc = ic->ic_softc;
863 	int error;
864 
865 	BWN_LOCK(sc);
866 	if ((sc->sc_flags & BWN_FLAG_RUNNING) == 0) {
867 		BWN_UNLOCK(sc);
868 		return (ENXIO);
869 	}
870 	error = mbufq_enqueue(&sc->sc_snd, m);
871 	if (error) {
872 		BWN_UNLOCK(sc);
873 		return (error);
874 	}
875 	bwn_start(sc);
876 	BWN_UNLOCK(sc);
877 	return (0);
878 }
879 
880 static void
881 bwn_start(struct bwn_softc *sc)
882 {
883 	struct bwn_mac *mac = sc->sc_curmac;
884 	struct ieee80211_frame *wh;
885 	struct ieee80211_node *ni;
886 	struct ieee80211_key *k;
887 	struct mbuf *m;
888 
889 	BWN_ASSERT_LOCKED(sc);
890 
891 	if ((sc->sc_flags & BWN_FLAG_RUNNING) == 0 || mac == NULL ||
892 	    mac->mac_status < BWN_MAC_STATUS_STARTED)
893 		return;
894 
895 	while ((m = mbufq_dequeue(&sc->sc_snd)) != NULL) {
896 		if (bwn_tx_isfull(sc, m))
897 			break;
898 		ni = (struct ieee80211_node *) m->m_pkthdr.rcvif;
899 		if (ni == NULL) {
900 			device_printf(sc->sc_dev, "unexpected NULL ni\n");
901 			m_freem(m);
902 			counter_u64_add(sc->sc_ic.ic_oerrors, 1);
903 			continue;
904 		}
905 		wh = mtod(m, struct ieee80211_frame *);
906 		if (wh->i_fc[1] & IEEE80211_FC1_PROTECTED) {
907 			k = ieee80211_crypto_encap(ni, m);
908 			if (k == NULL) {
909 				if_inc_counter(ni->ni_vap->iv_ifp,
910 				    IFCOUNTER_OERRORS, 1);
911 				ieee80211_free_node(ni);
912 				m_freem(m);
913 				continue;
914 			}
915 		}
916 		wh = NULL;	/* Catch any invalid use */
917 		if (bwn_tx_start(sc, ni, m) != 0) {
918 			if (ni != NULL) {
919 				if_inc_counter(ni->ni_vap->iv_ifp,
920 				    IFCOUNTER_OERRORS, 1);
921 				ieee80211_free_node(ni);
922 			}
923 			continue;
924 		}
925 		sc->sc_watchdog_timer = 5;
926 	}
927 }
928 
929 static int
930 bwn_tx_isfull(struct bwn_softc *sc, struct mbuf *m)
931 {
932 	struct bwn_dma_ring *dr;
933 	struct bwn_mac *mac = sc->sc_curmac;
934 	struct bwn_pio_txqueue *tq;
935 	int pktlen = roundup(m->m_pkthdr.len + BWN_HDRSIZE(mac), 4);
936 
937 	BWN_ASSERT_LOCKED(sc);
938 
939 	if (mac->mac_flags & BWN_MAC_FLAG_DMA) {
940 		dr = bwn_dma_select(mac, M_WME_GETAC(m));
941 		if (dr->dr_stop == 1 ||
942 		    bwn_dma_freeslot(dr) < BWN_TX_SLOTS_PER_FRAME) {
943 			dr->dr_stop = 1;
944 			goto full;
945 		}
946 	} else {
947 		tq = bwn_pio_select(mac, M_WME_GETAC(m));
948 		if (tq->tq_free == 0 || pktlen > tq->tq_size ||
949 		    pktlen > (tq->tq_size - tq->tq_used))
950 			goto full;
951 	}
952 	return (0);
953 full:
954 	mbufq_prepend(&sc->sc_snd, m);
955 	return (1);
956 }
957 
958 static int
959 bwn_tx_start(struct bwn_softc *sc, struct ieee80211_node *ni, struct mbuf *m)
960 {
961 	struct bwn_mac *mac = sc->sc_curmac;
962 	int error;
963 
964 	BWN_ASSERT_LOCKED(sc);
965 
966 	if (m->m_pkthdr.len < IEEE80211_MIN_LEN || mac == NULL) {
967 		m_freem(m);
968 		return (ENXIO);
969 	}
970 
971 	error = (mac->mac_flags & BWN_MAC_FLAG_DMA) ?
972 	    bwn_dma_tx_start(mac, ni, m) : bwn_pio_tx_start(mac, ni, m);
973 	if (error) {
974 		m_freem(m);
975 		return (error);
976 	}
977 	return (0);
978 }
979 
980 static int
981 bwn_pio_tx_start(struct bwn_mac *mac, struct ieee80211_node *ni, struct mbuf *m)
982 {
983 	struct bwn_pio_txpkt *tp;
984 	struct bwn_pio_txqueue *tq = bwn_pio_select(mac, M_WME_GETAC(m));
985 	struct bwn_softc *sc = mac->mac_sc;
986 	struct bwn_txhdr txhdr;
987 	struct mbuf *m_new;
988 	uint32_t ctl32;
989 	int error;
990 	uint16_t ctl16;
991 
992 	BWN_ASSERT_LOCKED(sc);
993 
994 	/* XXX TODO send packets after DTIM */
995 
996 	KASSERT(!TAILQ_EMPTY(&tq->tq_pktlist), ("%s: fail", __func__));
997 	tp = TAILQ_FIRST(&tq->tq_pktlist);
998 	tp->tp_ni = ni;
999 	tp->tp_m = m;
1000 
1001 	error = bwn_set_txhdr(mac, ni, m, &txhdr, BWN_PIO_COOKIE(tq, tp));
1002 	if (error) {
1003 		device_printf(sc->sc_dev, "tx fail\n");
1004 		return (error);
1005 	}
1006 
1007 	TAILQ_REMOVE(&tq->tq_pktlist, tp, tp_list);
1008 	tq->tq_used += roundup(m->m_pkthdr.len + BWN_HDRSIZE(mac), 4);
1009 	tq->tq_free--;
1010 
1011 	if (siba_get_revid(sc->sc_dev) >= 8) {
1012 		/*
1013 		 * XXX please removes m_defrag(9)
1014 		 */
1015 		m_new = m_defrag(m, M_NOWAIT);
1016 		if (m_new == NULL) {
1017 			device_printf(sc->sc_dev,
1018 			    "%s: can't defrag TX buffer\n",
1019 			    __func__);
1020 			return (ENOBUFS);
1021 		}
1022 		if (m_new->m_next != NULL)
1023 			device_printf(sc->sc_dev,
1024 			    "TODO: fragmented packets for PIO\n");
1025 		tp->tp_m = m_new;
1026 
1027 		/* send HEADER */
1028 		ctl32 = bwn_pio_write_multi_4(mac, tq,
1029 		    (BWN_PIO_READ_4(mac, tq, BWN_PIO8_TXCTL) |
1030 			BWN_PIO8_TXCTL_FRAMEREADY) & ~BWN_PIO8_TXCTL_EOF,
1031 		    (const uint8_t *)&txhdr, BWN_HDRSIZE(mac));
1032 		/* send BODY */
1033 		ctl32 = bwn_pio_write_multi_4(mac, tq, ctl32,
1034 		    mtod(m_new, const void *), m_new->m_pkthdr.len);
1035 		bwn_pio_write_4(mac, tq, BWN_PIO_TXCTL,
1036 		    ctl32 | BWN_PIO8_TXCTL_EOF);
1037 	} else {
1038 		ctl16 = bwn_pio_write_multi_2(mac, tq,
1039 		    (bwn_pio_read_2(mac, tq, BWN_PIO_TXCTL) |
1040 			BWN_PIO_TXCTL_FRAMEREADY) & ~BWN_PIO_TXCTL_EOF,
1041 		    (const uint8_t *)&txhdr, BWN_HDRSIZE(mac));
1042 		ctl16 = bwn_pio_write_mbuf_2(mac, tq, ctl16, m);
1043 		BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXCTL,
1044 		    ctl16 | BWN_PIO_TXCTL_EOF);
1045 	}
1046 
1047 	return (0);
1048 }
1049 
1050 static struct bwn_pio_txqueue *
1051 bwn_pio_select(struct bwn_mac *mac, uint8_t prio)
1052 {
1053 
1054 	if ((mac->mac_flags & BWN_MAC_FLAG_WME) == 0)
1055 		return (&mac->mac_method.pio.wme[WME_AC_BE]);
1056 
1057 	switch (prio) {
1058 	case 0:
1059 		return (&mac->mac_method.pio.wme[WME_AC_BE]);
1060 	case 1:
1061 		return (&mac->mac_method.pio.wme[WME_AC_BK]);
1062 	case 2:
1063 		return (&mac->mac_method.pio.wme[WME_AC_VI]);
1064 	case 3:
1065 		return (&mac->mac_method.pio.wme[WME_AC_VO]);
1066 	}
1067 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
1068 	return (NULL);
1069 }
1070 
1071 static int
1072 bwn_dma_tx_start(struct bwn_mac *mac, struct ieee80211_node *ni, struct mbuf *m)
1073 {
1074 #define	BWN_GET_TXHDRCACHE(slot)					\
1075 	&(txhdr_cache[(slot / BWN_TX_SLOTS_PER_FRAME) * BWN_HDRSIZE(mac)])
1076 	struct bwn_dma *dma = &mac->mac_method.dma;
1077 	struct bwn_dma_ring *dr = bwn_dma_select(mac, M_WME_GETAC(m));
1078 	struct bwn_dmadesc_generic *desc;
1079 	struct bwn_dmadesc_meta *mt;
1080 	struct bwn_softc *sc = mac->mac_sc;
1081 	uint8_t *txhdr_cache = (uint8_t *)dr->dr_txhdr_cache;
1082 	int error, slot, backup[2] = { dr->dr_curslot, dr->dr_usedslot };
1083 
1084 	BWN_ASSERT_LOCKED(sc);
1085 	KASSERT(!dr->dr_stop, ("%s:%d: fail", __func__, __LINE__));
1086 
1087 	/* XXX send after DTIM */
1088 
1089 	slot = bwn_dma_getslot(dr);
1090 	dr->getdesc(dr, slot, &desc, &mt);
1091 	KASSERT(mt->mt_txtype == BWN_DMADESC_METATYPE_HEADER,
1092 	    ("%s:%d: fail", __func__, __LINE__));
1093 
1094 	error = bwn_set_txhdr(dr->dr_mac, ni, m,
1095 	    (struct bwn_txhdr *)BWN_GET_TXHDRCACHE(slot),
1096 	    BWN_DMA_COOKIE(dr, slot));
1097 	if (error)
1098 		goto fail;
1099 	error = bus_dmamap_load(dr->dr_txring_dtag, mt->mt_dmap,
1100 	    BWN_GET_TXHDRCACHE(slot), BWN_HDRSIZE(mac), bwn_dma_ring_addr,
1101 	    &mt->mt_paddr, BUS_DMA_NOWAIT);
1102 	if (error) {
1103 		device_printf(sc->sc_dev, "%s: can't load TX buffer (1) %d\n",
1104 		    __func__, error);
1105 		goto fail;
1106 	}
1107 	bus_dmamap_sync(dr->dr_txring_dtag, mt->mt_dmap,
1108 	    BUS_DMASYNC_PREWRITE);
1109 	dr->setdesc(dr, desc, mt->mt_paddr, BWN_HDRSIZE(mac), 1, 0, 0);
1110 	bus_dmamap_sync(dr->dr_ring_dtag, dr->dr_ring_dmap,
1111 	    BUS_DMASYNC_PREWRITE);
1112 
1113 	slot = bwn_dma_getslot(dr);
1114 	dr->getdesc(dr, slot, &desc, &mt);
1115 	KASSERT(mt->mt_txtype == BWN_DMADESC_METATYPE_BODY &&
1116 	    mt->mt_islast == 1, ("%s:%d: fail", __func__, __LINE__));
1117 	mt->mt_m = m;
1118 	mt->mt_ni = ni;
1119 
1120 	error = bus_dmamap_load_mbuf(dma->txbuf_dtag, mt->mt_dmap, m,
1121 	    bwn_dma_buf_addr, &mt->mt_paddr, BUS_DMA_NOWAIT);
1122 	if (error && error != EFBIG) {
1123 		device_printf(sc->sc_dev, "%s: can't load TX buffer (1) %d\n",
1124 		    __func__, error);
1125 		goto fail;
1126 	}
1127 	if (error) {    /* error == EFBIG */
1128 		struct mbuf *m_new;
1129 
1130 		m_new = m_defrag(m, M_NOWAIT);
1131 		if (m_new == NULL) {
1132 			device_printf(sc->sc_dev,
1133 			    "%s: can't defrag TX buffer\n",
1134 			    __func__);
1135 			error = ENOBUFS;
1136 			goto fail;
1137 		} else {
1138 			m = m_new;
1139 		}
1140 
1141 		mt->mt_m = m;
1142 		error = bus_dmamap_load_mbuf(dma->txbuf_dtag, mt->mt_dmap,
1143 		    m, bwn_dma_buf_addr, &mt->mt_paddr, BUS_DMA_NOWAIT);
1144 		if (error) {
1145 			device_printf(sc->sc_dev,
1146 			    "%s: can't load TX buffer (2) %d\n",
1147 			    __func__, error);
1148 			goto fail;
1149 		}
1150 	}
1151 	bus_dmamap_sync(dma->txbuf_dtag, mt->mt_dmap, BUS_DMASYNC_PREWRITE);
1152 	dr->setdesc(dr, desc, mt->mt_paddr, m->m_pkthdr.len, 0, 1, 1);
1153 	bus_dmamap_sync(dr->dr_ring_dtag, dr->dr_ring_dmap,
1154 	    BUS_DMASYNC_PREWRITE);
1155 
1156 	/* XXX send after DTIM */
1157 
1158 	dr->start_transfer(dr, bwn_dma_nextslot(dr, slot));
1159 	return (0);
1160 fail:
1161 	dr->dr_curslot = backup[0];
1162 	dr->dr_usedslot = backup[1];
1163 	return (error);
1164 #undef BWN_GET_TXHDRCACHE
1165 }
1166 
1167 static void
1168 bwn_watchdog(void *arg)
1169 {
1170 	struct bwn_softc *sc = arg;
1171 
1172 	if (sc->sc_watchdog_timer != 0 && --sc->sc_watchdog_timer == 0) {
1173 		device_printf(sc->sc_dev, "device timeout\n");
1174 		counter_u64_add(sc->sc_ic.ic_oerrors, 1);
1175 	}
1176 	callout_schedule(&sc->sc_watchdog_ch, hz);
1177 }
1178 
1179 static int
1180 bwn_attach_core(struct bwn_mac *mac)
1181 {
1182 	struct bwn_softc *sc = mac->mac_sc;
1183 	int error, have_bg = 0, have_a = 0;
1184 	uint32_t high;
1185 
1186 	KASSERT(siba_get_revid(sc->sc_dev) >= 5,
1187 	    ("unsupported revision %d", siba_get_revid(sc->sc_dev)));
1188 
1189 	siba_powerup(sc->sc_dev, 0);
1190 	high = siba_read_4(sc->sc_dev, SIBA_TGSHIGH);
1191 	have_a = (high & BWN_TGSHIGH_HAVE_5GHZ) ? 1 : 0;
1192 	have_bg = (high & BWN_TGSHIGH_HAVE_2GHZ) ? 1 : 0;
1193 	if (high & BWN_TGSHIGH_DUALPHY) {
1194 		have_bg = 1;
1195 		have_a = 1;
1196 	}
1197 
1198 #if 0
1199 	device_printf(sc->sc_dev, "%s: high=0x%08x, have_a=%d, have_bg=%d,"
1200 	    " deviceid=0x%04x, siba_deviceid=0x%04x\n",
1201 	    __func__,
1202 	    high,
1203 	    have_a,
1204 	    have_bg,
1205 	    siba_get_pci_device(sc->sc_dev),
1206 	    siba_get_chipid(sc->sc_dev));
1207 #endif
1208 
1209 	/*
1210 	 * Guess at whether it has A-PHY or G-PHY.
1211 	 * This is just used for resetting the core to probe things;
1212 	 * we will re-guess once it's all up and working.
1213 	 */
1214 	bwn_reset_core(mac, have_bg);
1215 
1216 	/*
1217 	 * Get the PHY version.
1218 	 */
1219 	error = bwn_phy_getinfo(mac, have_bg);
1220 	if (error)
1221 		goto fail;
1222 
1223 	/*
1224 	 * This is the whitelist of devices which we "believe"
1225 	 * the SPROM PHY config from.  The rest are "guessed".
1226 	 */
1227 	if (siba_get_pci_device(sc->sc_dev) != 0x4312 &&
1228 	    siba_get_pci_device(sc->sc_dev) != 0x4315 &&
1229 	    siba_get_pci_device(sc->sc_dev) != 0x4319 &&
1230 	    siba_get_pci_device(sc->sc_dev) != 0x4324 &&
1231 	    siba_get_pci_device(sc->sc_dev) != 0x4328 &&
1232 	    siba_get_pci_device(sc->sc_dev) != 0x432b) {
1233 		have_a = have_bg = 0;
1234 		if (mac->mac_phy.type == BWN_PHYTYPE_A)
1235 			have_a = 1;
1236 		else if (mac->mac_phy.type == BWN_PHYTYPE_G ||
1237 		    mac->mac_phy.type == BWN_PHYTYPE_N ||
1238 		    mac->mac_phy.type == BWN_PHYTYPE_LP)
1239 			have_bg = 1;
1240 		else
1241 			KASSERT(0 == 1, ("%s: unknown phy type (%d)", __func__,
1242 			    mac->mac_phy.type));
1243 	}
1244 
1245 	/*
1246 	 * XXX The PHY-G support doesn't do 5GHz operation.
1247 	 */
1248 	if (mac->mac_phy.type != BWN_PHYTYPE_LP &&
1249 	    mac->mac_phy.type != BWN_PHYTYPE_N) {
1250 		device_printf(sc->sc_dev,
1251 		    "%s: forcing 2GHz only; no dual-band support for PHY\n",
1252 		    __func__);
1253 		have_a = 0;
1254 		have_bg = 1;
1255 	}
1256 
1257 	mac->mac_phy.phy_n = NULL;
1258 
1259 	if (mac->mac_phy.type == BWN_PHYTYPE_G) {
1260 		mac->mac_phy.attach = bwn_phy_g_attach;
1261 		mac->mac_phy.detach = bwn_phy_g_detach;
1262 		mac->mac_phy.prepare_hw = bwn_phy_g_prepare_hw;
1263 		mac->mac_phy.init_pre = bwn_phy_g_init_pre;
1264 		mac->mac_phy.init = bwn_phy_g_init;
1265 		mac->mac_phy.exit = bwn_phy_g_exit;
1266 		mac->mac_phy.phy_read = bwn_phy_g_read;
1267 		mac->mac_phy.phy_write = bwn_phy_g_write;
1268 		mac->mac_phy.rf_read = bwn_phy_g_rf_read;
1269 		mac->mac_phy.rf_write = bwn_phy_g_rf_write;
1270 		mac->mac_phy.use_hwpctl = bwn_phy_g_hwpctl;
1271 		mac->mac_phy.rf_onoff = bwn_phy_g_rf_onoff;
1272 		mac->mac_phy.switch_analog = bwn_phy_switch_analog;
1273 		mac->mac_phy.switch_channel = bwn_phy_g_switch_channel;
1274 		mac->mac_phy.get_default_chan = bwn_phy_g_get_default_chan;
1275 		mac->mac_phy.set_antenna = bwn_phy_g_set_antenna;
1276 		mac->mac_phy.set_im = bwn_phy_g_im;
1277 		mac->mac_phy.recalc_txpwr = bwn_phy_g_recalc_txpwr;
1278 		mac->mac_phy.set_txpwr = bwn_phy_g_set_txpwr;
1279 		mac->mac_phy.task_15s = bwn_phy_g_task_15s;
1280 		mac->mac_phy.task_60s = bwn_phy_g_task_60s;
1281 	} else if (mac->mac_phy.type == BWN_PHYTYPE_LP) {
1282 		mac->mac_phy.init_pre = bwn_phy_lp_init_pre;
1283 		mac->mac_phy.init = bwn_phy_lp_init;
1284 		mac->mac_phy.phy_read = bwn_phy_lp_read;
1285 		mac->mac_phy.phy_write = bwn_phy_lp_write;
1286 		mac->mac_phy.phy_maskset = bwn_phy_lp_maskset;
1287 		mac->mac_phy.rf_read = bwn_phy_lp_rf_read;
1288 		mac->mac_phy.rf_write = bwn_phy_lp_rf_write;
1289 		mac->mac_phy.rf_onoff = bwn_phy_lp_rf_onoff;
1290 		mac->mac_phy.switch_analog = bwn_phy_lp_switch_analog;
1291 		mac->mac_phy.switch_channel = bwn_phy_lp_switch_channel;
1292 		mac->mac_phy.get_default_chan = bwn_phy_lp_get_default_chan;
1293 		mac->mac_phy.set_antenna = bwn_phy_lp_set_antenna;
1294 		mac->mac_phy.task_60s = bwn_phy_lp_task_60s;
1295 	} else if (mac->mac_phy.type == BWN_PHYTYPE_N) {
1296 		mac->mac_phy.attach = bwn_phy_n_attach;
1297 		mac->mac_phy.detach = bwn_phy_n_detach;
1298 		mac->mac_phy.prepare_hw = bwn_phy_n_prepare_hw;
1299 		mac->mac_phy.init_pre = bwn_phy_n_init_pre;
1300 		mac->mac_phy.init = bwn_phy_n_init;
1301 		mac->mac_phy.exit = bwn_phy_n_exit;
1302 		mac->mac_phy.phy_read = bwn_phy_n_read;
1303 		mac->mac_phy.phy_write = bwn_phy_n_write;
1304 		mac->mac_phy.rf_read = bwn_phy_n_rf_read;
1305 		mac->mac_phy.rf_write = bwn_phy_n_rf_write;
1306 		mac->mac_phy.use_hwpctl = bwn_phy_n_hwpctl;
1307 		mac->mac_phy.rf_onoff = bwn_phy_n_rf_onoff;
1308 		mac->mac_phy.switch_analog = bwn_phy_n_switch_analog;
1309 		mac->mac_phy.switch_channel = bwn_phy_n_switch_channel;
1310 		mac->mac_phy.get_default_chan = bwn_phy_n_get_default_chan;
1311 		mac->mac_phy.set_antenna = bwn_phy_n_set_antenna;
1312 		mac->mac_phy.set_im = bwn_phy_n_im;
1313 		mac->mac_phy.recalc_txpwr = bwn_phy_n_recalc_txpwr;
1314 		mac->mac_phy.set_txpwr = bwn_phy_n_set_txpwr;
1315 		mac->mac_phy.task_15s = bwn_phy_n_task_15s;
1316 		mac->mac_phy.task_60s = bwn_phy_n_task_60s;
1317 	} else {
1318 		device_printf(sc->sc_dev, "unsupported PHY type (%d)\n",
1319 		    mac->mac_phy.type);
1320 		error = ENXIO;
1321 		goto fail;
1322 	}
1323 
1324 	mac->mac_phy.gmode = have_bg;
1325 	if (mac->mac_phy.attach != NULL) {
1326 		error = mac->mac_phy.attach(mac);
1327 		if (error) {
1328 			device_printf(sc->sc_dev, "failed\n");
1329 			goto fail;
1330 		}
1331 	}
1332 
1333 	bwn_reset_core(mac, have_bg);
1334 
1335 	error = bwn_chiptest(mac);
1336 	if (error)
1337 		goto fail;
1338 	error = bwn_setup_channels(mac, have_bg, have_a);
1339 	if (error) {
1340 		device_printf(sc->sc_dev, "failed to setup channels\n");
1341 		goto fail;
1342 	}
1343 
1344 	if (sc->sc_curmac == NULL)
1345 		sc->sc_curmac = mac;
1346 
1347 	error = bwn_dma_attach(mac);
1348 	if (error != 0) {
1349 		device_printf(sc->sc_dev, "failed to initialize DMA\n");
1350 		goto fail;
1351 	}
1352 
1353 	mac->mac_phy.switch_analog(mac, 0);
1354 
1355 	siba_dev_down(sc->sc_dev, 0);
1356 fail:
1357 	siba_powerdown(sc->sc_dev);
1358 	bwn_release_firmware(mac);
1359 	return (error);
1360 }
1361 
1362 /*
1363  * Reset - SIBA.
1364  */
1365 void
1366 bwn_reset_core(struct bwn_mac *mac, int g_mode)
1367 {
1368 	struct bwn_softc *sc = mac->mac_sc;
1369 	uint32_t low, ctl;
1370 	uint32_t flags = 0;
1371 
1372 	DPRINTF(sc, BWN_DEBUG_RESET, "%s: g_mode=%d\n", __func__, g_mode);
1373 
1374 	flags |= (BWN_TGSLOW_PHYCLOCK_ENABLE | BWN_TGSLOW_PHYRESET);
1375 	if (g_mode)
1376 		flags |= BWN_TGSLOW_SUPPORT_G;
1377 
1378 	/* XXX N-PHY only; and hard-code to 20MHz for now */
1379 	if (mac->mac_phy.type == BWN_PHYTYPE_N)
1380 		flags |= BWN_TGSLOW_PHY_BANDWIDTH_20MHZ;
1381 
1382 	siba_dev_up(sc->sc_dev, flags);
1383 	DELAY(2000);
1384 
1385 	/* Take PHY out of reset */
1386 	low = (siba_read_4(sc->sc_dev, SIBA_TGSLOW) | SIBA_TGSLOW_FGC) &
1387 	    ~(BWN_TGSLOW_PHYRESET | BWN_TGSLOW_PHYCLOCK_ENABLE);
1388 	siba_write_4(sc->sc_dev, SIBA_TGSLOW, low);
1389 	siba_read_4(sc->sc_dev, SIBA_TGSLOW);
1390 	DELAY(2000);
1391 	low &= ~SIBA_TGSLOW_FGC;
1392 	low |= BWN_TGSLOW_PHYCLOCK_ENABLE;
1393 	siba_write_4(sc->sc_dev, SIBA_TGSLOW, low);
1394 	siba_read_4(sc->sc_dev, SIBA_TGSLOW);
1395 	DELAY(2000);
1396 
1397 	if (mac->mac_phy.switch_analog != NULL)
1398 		mac->mac_phy.switch_analog(mac, 1);
1399 
1400 	ctl = BWN_READ_4(mac, BWN_MACCTL) & ~BWN_MACCTL_GMODE;
1401 	if (g_mode)
1402 		ctl |= BWN_MACCTL_GMODE;
1403 	BWN_WRITE_4(mac, BWN_MACCTL, ctl | BWN_MACCTL_IHR_ON);
1404 }
1405 
1406 static int
1407 bwn_phy_getinfo(struct bwn_mac *mac, int gmode)
1408 {
1409 	struct bwn_phy *phy = &mac->mac_phy;
1410 	struct bwn_softc *sc = mac->mac_sc;
1411 	uint32_t tmp;
1412 
1413 	/* PHY */
1414 	tmp = BWN_READ_2(mac, BWN_PHYVER);
1415 	phy->gmode = gmode;
1416 	phy->rf_on = 1;
1417 	phy->analog = (tmp & BWN_PHYVER_ANALOG) >> 12;
1418 	phy->type = (tmp & BWN_PHYVER_TYPE) >> 8;
1419 	phy->rev = (tmp & BWN_PHYVER_VERSION);
1420 	if ((phy->type == BWN_PHYTYPE_A && phy->rev >= 4) ||
1421 	    (phy->type == BWN_PHYTYPE_B && phy->rev != 2 &&
1422 		phy->rev != 4 && phy->rev != 6 && phy->rev != 7) ||
1423 	    (phy->type == BWN_PHYTYPE_G && phy->rev > 9) ||
1424 	    (phy->type == BWN_PHYTYPE_N && phy->rev > 4) ||
1425 	    (phy->type == BWN_PHYTYPE_LP && phy->rev > 2))
1426 		goto unsupphy;
1427 
1428 	/* RADIO */
1429 	if (siba_get_chipid(sc->sc_dev) == 0x4317) {
1430 		if (siba_get_chiprev(sc->sc_dev) == 0)
1431 			tmp = 0x3205017f;
1432 		else if (siba_get_chiprev(sc->sc_dev) == 1)
1433 			tmp = 0x4205017f;
1434 		else
1435 			tmp = 0x5205017f;
1436 	} else {
1437 		BWN_WRITE_2(mac, BWN_RFCTL, BWN_RFCTL_ID);
1438 		tmp = BWN_READ_2(mac, BWN_RFDATALO);
1439 		BWN_WRITE_2(mac, BWN_RFCTL, BWN_RFCTL_ID);
1440 		tmp |= (uint32_t)BWN_READ_2(mac, BWN_RFDATAHI) << 16;
1441 	}
1442 	phy->rf_rev = (tmp & 0xf0000000) >> 28;
1443 	phy->rf_ver = (tmp & 0x0ffff000) >> 12;
1444 	phy->rf_manuf = (tmp & 0x00000fff);
1445 
1446 	/*
1447 	 * For now, just always do full init (ie, what bwn has traditionally
1448 	 * done)
1449 	 */
1450 	phy->phy_do_full_init = 1;
1451 
1452 	if (phy->rf_manuf != 0x17f)	/* 0x17f is broadcom */
1453 		goto unsupradio;
1454 	if ((phy->type == BWN_PHYTYPE_A && (phy->rf_ver != 0x2060 ||
1455 	     phy->rf_rev != 1 || phy->rf_manuf != 0x17f)) ||
1456 	    (phy->type == BWN_PHYTYPE_B && (phy->rf_ver & 0xfff0) != 0x2050) ||
1457 	    (phy->type == BWN_PHYTYPE_G && phy->rf_ver != 0x2050) ||
1458 	    (phy->type == BWN_PHYTYPE_N &&
1459 	     phy->rf_ver != 0x2055 && phy->rf_ver != 0x2056) ||
1460 	    (phy->type == BWN_PHYTYPE_LP &&
1461 	     phy->rf_ver != 0x2062 && phy->rf_ver != 0x2063))
1462 		goto unsupradio;
1463 
1464 	return (0);
1465 unsupphy:
1466 	device_printf(sc->sc_dev, "unsupported PHY (type %#x, rev %#x, "
1467 	    "analog %#x)\n",
1468 	    phy->type, phy->rev, phy->analog);
1469 	return (ENXIO);
1470 unsupradio:
1471 	device_printf(sc->sc_dev, "unsupported radio (manuf %#x, ver %#x, "
1472 	    "rev %#x)\n",
1473 	    phy->rf_manuf, phy->rf_ver, phy->rf_rev);
1474 	return (ENXIO);
1475 }
1476 
1477 static int
1478 bwn_chiptest(struct bwn_mac *mac)
1479 {
1480 #define	TESTVAL0	0x55aaaa55
1481 #define	TESTVAL1	0xaa5555aa
1482 	struct bwn_softc *sc = mac->mac_sc;
1483 	uint32_t v, backup;
1484 
1485 	BWN_LOCK(sc);
1486 
1487 	backup = bwn_shm_read_4(mac, BWN_SHARED, 0);
1488 
1489 	bwn_shm_write_4(mac, BWN_SHARED, 0, TESTVAL0);
1490 	if (bwn_shm_read_4(mac, BWN_SHARED, 0) != TESTVAL0)
1491 		goto error;
1492 	bwn_shm_write_4(mac, BWN_SHARED, 0, TESTVAL1);
1493 	if (bwn_shm_read_4(mac, BWN_SHARED, 0) != TESTVAL1)
1494 		goto error;
1495 
1496 	bwn_shm_write_4(mac, BWN_SHARED, 0, backup);
1497 
1498 	if ((siba_get_revid(sc->sc_dev) >= 3) &&
1499 	    (siba_get_revid(sc->sc_dev) <= 10)) {
1500 		BWN_WRITE_2(mac, BWN_TSF_CFP_START, 0xaaaa);
1501 		BWN_WRITE_4(mac, BWN_TSF_CFP_START, 0xccccbbbb);
1502 		if (BWN_READ_2(mac, BWN_TSF_CFP_START_LOW) != 0xbbbb)
1503 			goto error;
1504 		if (BWN_READ_2(mac, BWN_TSF_CFP_START_HIGH) != 0xcccc)
1505 			goto error;
1506 	}
1507 	BWN_WRITE_4(mac, BWN_TSF_CFP_START, 0);
1508 
1509 	v = BWN_READ_4(mac, BWN_MACCTL) | BWN_MACCTL_GMODE;
1510 	if (v != (BWN_MACCTL_GMODE | BWN_MACCTL_IHR_ON))
1511 		goto error;
1512 
1513 	BWN_UNLOCK(sc);
1514 	return (0);
1515 error:
1516 	BWN_UNLOCK(sc);
1517 	device_printf(sc->sc_dev, "failed to validate the chipaccess\n");
1518 	return (ENODEV);
1519 }
1520 
1521 static int
1522 bwn_setup_channels(struct bwn_mac *mac, int have_bg, int have_a)
1523 {
1524 	struct bwn_softc *sc = mac->mac_sc;
1525 	struct ieee80211com *ic = &sc->sc_ic;
1526 	uint8_t bands[IEEE80211_MODE_BYTES];
1527 
1528 	memset(ic->ic_channels, 0, sizeof(ic->ic_channels));
1529 	ic->ic_nchans = 0;
1530 
1531 	DPRINTF(sc, BWN_DEBUG_EEPROM, "%s: called; bg=%d, a=%d\n",
1532 	    __func__,
1533 	    have_bg,
1534 	    have_a);
1535 
1536 	if (have_bg) {
1537 		memset(bands, 0, sizeof(bands));
1538 		setbit(bands, IEEE80211_MODE_11B);
1539 		setbit(bands, IEEE80211_MODE_11G);
1540 		bwn_addchannels(ic->ic_channels, IEEE80211_CHAN_MAX,
1541 		    &ic->ic_nchans, &bwn_chantable_bg, bands);
1542 	}
1543 
1544 	if (have_a) {
1545 		memset(bands, 0, sizeof(bands));
1546 		setbit(bands, IEEE80211_MODE_11A);
1547 		bwn_addchannels(ic->ic_channels, IEEE80211_CHAN_MAX,
1548 		    &ic->ic_nchans, &bwn_chantable_a, bands);
1549 	}
1550 
1551 	mac->mac_phy.supports_2ghz = have_bg;
1552 	mac->mac_phy.supports_5ghz = have_a;
1553 
1554 	return (ic->ic_nchans == 0 ? ENXIO : 0);
1555 }
1556 
1557 uint32_t
1558 bwn_shm_read_4(struct bwn_mac *mac, uint16_t way, uint16_t offset)
1559 {
1560 	uint32_t ret;
1561 
1562 	BWN_ASSERT_LOCKED(mac->mac_sc);
1563 
1564 	if (way == BWN_SHARED) {
1565 		KASSERT((offset & 0x0001) == 0,
1566 		    ("%s:%d warn", __func__, __LINE__));
1567 		if (offset & 0x0003) {
1568 			bwn_shm_ctlword(mac, way, offset >> 2);
1569 			ret = BWN_READ_2(mac, BWN_SHM_DATA_UNALIGNED);
1570 			ret <<= 16;
1571 			bwn_shm_ctlword(mac, way, (offset >> 2) + 1);
1572 			ret |= BWN_READ_2(mac, BWN_SHM_DATA);
1573 			goto out;
1574 		}
1575 		offset >>= 2;
1576 	}
1577 	bwn_shm_ctlword(mac, way, offset);
1578 	ret = BWN_READ_4(mac, BWN_SHM_DATA);
1579 out:
1580 	return (ret);
1581 }
1582 
1583 uint16_t
1584 bwn_shm_read_2(struct bwn_mac *mac, uint16_t way, uint16_t offset)
1585 {
1586 	uint16_t ret;
1587 
1588 	BWN_ASSERT_LOCKED(mac->mac_sc);
1589 
1590 	if (way == BWN_SHARED) {
1591 		KASSERT((offset & 0x0001) == 0,
1592 		    ("%s:%d warn", __func__, __LINE__));
1593 		if (offset & 0x0003) {
1594 			bwn_shm_ctlword(mac, way, offset >> 2);
1595 			ret = BWN_READ_2(mac, BWN_SHM_DATA_UNALIGNED);
1596 			goto out;
1597 		}
1598 		offset >>= 2;
1599 	}
1600 	bwn_shm_ctlword(mac, way, offset);
1601 	ret = BWN_READ_2(mac, BWN_SHM_DATA);
1602 out:
1603 
1604 	return (ret);
1605 }
1606 
1607 static void
1608 bwn_shm_ctlword(struct bwn_mac *mac, uint16_t way,
1609     uint16_t offset)
1610 {
1611 	uint32_t control;
1612 
1613 	control = way;
1614 	control <<= 16;
1615 	control |= offset;
1616 	BWN_WRITE_4(mac, BWN_SHM_CONTROL, control);
1617 }
1618 
1619 void
1620 bwn_shm_write_4(struct bwn_mac *mac, uint16_t way, uint16_t offset,
1621     uint32_t value)
1622 {
1623 	BWN_ASSERT_LOCKED(mac->mac_sc);
1624 
1625 	if (way == BWN_SHARED) {
1626 		KASSERT((offset & 0x0001) == 0,
1627 		    ("%s:%d warn", __func__, __LINE__));
1628 		if (offset & 0x0003) {
1629 			bwn_shm_ctlword(mac, way, offset >> 2);
1630 			BWN_WRITE_2(mac, BWN_SHM_DATA_UNALIGNED,
1631 				    (value >> 16) & 0xffff);
1632 			bwn_shm_ctlword(mac, way, (offset >> 2) + 1);
1633 			BWN_WRITE_2(mac, BWN_SHM_DATA, value & 0xffff);
1634 			return;
1635 		}
1636 		offset >>= 2;
1637 	}
1638 	bwn_shm_ctlword(mac, way, offset);
1639 	BWN_WRITE_4(mac, BWN_SHM_DATA, value);
1640 }
1641 
1642 void
1643 bwn_shm_write_2(struct bwn_mac *mac, uint16_t way, uint16_t offset,
1644     uint16_t value)
1645 {
1646 	BWN_ASSERT_LOCKED(mac->mac_sc);
1647 
1648 	if (way == BWN_SHARED) {
1649 		KASSERT((offset & 0x0001) == 0,
1650 		    ("%s:%d warn", __func__, __LINE__));
1651 		if (offset & 0x0003) {
1652 			bwn_shm_ctlword(mac, way, offset >> 2);
1653 			BWN_WRITE_2(mac, BWN_SHM_DATA_UNALIGNED, value);
1654 			return;
1655 		}
1656 		offset >>= 2;
1657 	}
1658 	bwn_shm_ctlword(mac, way, offset);
1659 	BWN_WRITE_2(mac, BWN_SHM_DATA, value);
1660 }
1661 
1662 static void
1663 bwn_addchannels(struct ieee80211_channel chans[], int maxchans, int *nchans,
1664     const struct bwn_channelinfo *ci, const uint8_t bands[])
1665 {
1666 	int i, error;
1667 
1668 	for (i = 0, error = 0; i < ci->nchannels && error == 0; i++) {
1669 		const struct bwn_channel *hc = &ci->channels[i];
1670 
1671 		error = ieee80211_add_channel(chans, maxchans, nchans,
1672 		    hc->ieee, hc->freq, hc->maxTxPow, 0, bands);
1673 	}
1674 }
1675 
1676 static int
1677 bwn_raw_xmit(struct ieee80211_node *ni, struct mbuf *m,
1678 	const struct ieee80211_bpf_params *params)
1679 {
1680 	struct ieee80211com *ic = ni->ni_ic;
1681 	struct bwn_softc *sc = ic->ic_softc;
1682 	struct bwn_mac *mac = sc->sc_curmac;
1683 	int error;
1684 
1685 	if ((sc->sc_flags & BWN_FLAG_RUNNING) == 0 ||
1686 	    mac->mac_status < BWN_MAC_STATUS_STARTED) {
1687 		m_freem(m);
1688 		return (ENETDOWN);
1689 	}
1690 
1691 	BWN_LOCK(sc);
1692 	if (bwn_tx_isfull(sc, m)) {
1693 		m_freem(m);
1694 		BWN_UNLOCK(sc);
1695 		return (ENOBUFS);
1696 	}
1697 
1698 	error = bwn_tx_start(sc, ni, m);
1699 	if (error == 0)
1700 		sc->sc_watchdog_timer = 5;
1701 	BWN_UNLOCK(sc);
1702 	return (error);
1703 }
1704 
1705 /*
1706  * Callback from the 802.11 layer to update the slot time
1707  * based on the current setting.  We use it to notify the
1708  * firmware of ERP changes and the f/w takes care of things
1709  * like slot time and preamble.
1710  */
1711 static void
1712 bwn_updateslot(struct ieee80211com *ic)
1713 {
1714 	struct bwn_softc *sc = ic->ic_softc;
1715 	struct bwn_mac *mac;
1716 
1717 	BWN_LOCK(sc);
1718 	if (sc->sc_flags & BWN_FLAG_RUNNING) {
1719 		mac = (struct bwn_mac *)sc->sc_curmac;
1720 		bwn_set_slot_time(mac, IEEE80211_GET_SLOTTIME(ic));
1721 	}
1722 	BWN_UNLOCK(sc);
1723 }
1724 
1725 /*
1726  * Callback from the 802.11 layer after a promiscuous mode change.
1727  * Note this interface does not check the operating mode as this
1728  * is an internal callback and we are expected to honor the current
1729  * state (e.g. this is used for setting the interface in promiscuous
1730  * mode when operating in hostap mode to do ACS).
1731  */
1732 static void
1733 bwn_update_promisc(struct ieee80211com *ic)
1734 {
1735 	struct bwn_softc *sc = ic->ic_softc;
1736 	struct bwn_mac *mac = sc->sc_curmac;
1737 
1738 	BWN_LOCK(sc);
1739 	mac = sc->sc_curmac;
1740 	if (mac != NULL && mac->mac_status >= BWN_MAC_STATUS_INITED) {
1741 		if (ic->ic_promisc > 0)
1742 			sc->sc_filters |= BWN_MACCTL_PROMISC;
1743 		else
1744 			sc->sc_filters &= ~BWN_MACCTL_PROMISC;
1745 		bwn_set_opmode(mac);
1746 	}
1747 	BWN_UNLOCK(sc);
1748 }
1749 
1750 /*
1751  * Callback from the 802.11 layer to update WME parameters.
1752  */
1753 static int
1754 bwn_wme_update(struct ieee80211com *ic)
1755 {
1756 	struct bwn_softc *sc = ic->ic_softc;
1757 	struct bwn_mac *mac = sc->sc_curmac;
1758 	struct wmeParams *wmep;
1759 	int i;
1760 
1761 	BWN_LOCK(sc);
1762 	mac = sc->sc_curmac;
1763 	if (mac != NULL && mac->mac_status >= BWN_MAC_STATUS_INITED) {
1764 		bwn_mac_suspend(mac);
1765 		for (i = 0; i < N(sc->sc_wmeParams); i++) {
1766 			wmep = &ic->ic_wme.wme_chanParams.cap_wmeParams[i];
1767 			bwn_wme_loadparams(mac, wmep, bwn_wme_shm_offsets[i]);
1768 		}
1769 		bwn_mac_enable(mac);
1770 	}
1771 	BWN_UNLOCK(sc);
1772 	return (0);
1773 }
1774 
1775 static void
1776 bwn_scan_start(struct ieee80211com *ic)
1777 {
1778 	struct bwn_softc *sc = ic->ic_softc;
1779 	struct bwn_mac *mac;
1780 
1781 	BWN_LOCK(sc);
1782 	mac = sc->sc_curmac;
1783 	if (mac != NULL && mac->mac_status >= BWN_MAC_STATUS_INITED) {
1784 		sc->sc_filters |= BWN_MACCTL_BEACON_PROMISC;
1785 		bwn_set_opmode(mac);
1786 		/* disable CFP update during scan */
1787 		bwn_hf_write(mac, bwn_hf_read(mac) | BWN_HF_SKIP_CFP_UPDATE);
1788 	}
1789 	BWN_UNLOCK(sc);
1790 }
1791 
1792 static void
1793 bwn_scan_end(struct ieee80211com *ic)
1794 {
1795 	struct bwn_softc *sc = ic->ic_softc;
1796 	struct bwn_mac *mac;
1797 
1798 	BWN_LOCK(sc);
1799 	mac = sc->sc_curmac;
1800 	if (mac != NULL && mac->mac_status >= BWN_MAC_STATUS_INITED) {
1801 		sc->sc_filters &= ~BWN_MACCTL_BEACON_PROMISC;
1802 		bwn_set_opmode(mac);
1803 		bwn_hf_write(mac, bwn_hf_read(mac) & ~BWN_HF_SKIP_CFP_UPDATE);
1804 	}
1805 	BWN_UNLOCK(sc);
1806 }
1807 
1808 static void
1809 bwn_set_channel(struct ieee80211com *ic)
1810 {
1811 	struct bwn_softc *sc = ic->ic_softc;
1812 	struct bwn_mac *mac = sc->sc_curmac;
1813 	struct bwn_phy *phy = &mac->mac_phy;
1814 	int chan, error;
1815 
1816 	BWN_LOCK(sc);
1817 
1818 	error = bwn_switch_band(sc, ic->ic_curchan);
1819 	if (error)
1820 		goto fail;
1821 	bwn_mac_suspend(mac);
1822 	bwn_set_txretry(mac, BWN_RETRY_SHORT, BWN_RETRY_LONG);
1823 	chan = ieee80211_chan2ieee(ic, ic->ic_curchan);
1824 	if (chan != phy->chan)
1825 		bwn_switch_channel(mac, chan);
1826 
1827 	/* TX power level */
1828 	if (ic->ic_curchan->ic_maxpower != 0 &&
1829 	    ic->ic_curchan->ic_maxpower != phy->txpower) {
1830 		phy->txpower = ic->ic_curchan->ic_maxpower / 2;
1831 		bwn_phy_txpower_check(mac, BWN_TXPWR_IGNORE_TIME |
1832 		    BWN_TXPWR_IGNORE_TSSI);
1833 	}
1834 
1835 	bwn_set_txantenna(mac, BWN_ANT_DEFAULT);
1836 	if (phy->set_antenna)
1837 		phy->set_antenna(mac, BWN_ANT_DEFAULT);
1838 
1839 	if (sc->sc_rf_enabled != phy->rf_on) {
1840 		if (sc->sc_rf_enabled) {
1841 			bwn_rf_turnon(mac);
1842 			if (!(mac->mac_flags & BWN_MAC_FLAG_RADIO_ON))
1843 				device_printf(sc->sc_dev,
1844 				    "please turn on the RF switch\n");
1845 		} else
1846 			bwn_rf_turnoff(mac);
1847 	}
1848 
1849 	bwn_mac_enable(mac);
1850 
1851 fail:
1852 	/*
1853 	 * Setup radio tap channel freq and flags
1854 	 */
1855 	sc->sc_tx_th.wt_chan_freq = sc->sc_rx_th.wr_chan_freq =
1856 		htole16(ic->ic_curchan->ic_freq);
1857 	sc->sc_tx_th.wt_chan_flags = sc->sc_rx_th.wr_chan_flags =
1858 		htole16(ic->ic_curchan->ic_flags & 0xffff);
1859 
1860 	BWN_UNLOCK(sc);
1861 }
1862 
1863 static struct ieee80211vap *
1864 bwn_vap_create(struct ieee80211com *ic, const char name[IFNAMSIZ], int unit,
1865     enum ieee80211_opmode opmode, int flags,
1866     const uint8_t bssid[IEEE80211_ADDR_LEN],
1867     const uint8_t mac[IEEE80211_ADDR_LEN])
1868 {
1869 	struct ieee80211vap *vap;
1870 	struct bwn_vap *bvp;
1871 
1872 	switch (opmode) {
1873 	case IEEE80211_M_HOSTAP:
1874 	case IEEE80211_M_MBSS:
1875 	case IEEE80211_M_STA:
1876 	case IEEE80211_M_WDS:
1877 	case IEEE80211_M_MONITOR:
1878 	case IEEE80211_M_IBSS:
1879 	case IEEE80211_M_AHDEMO:
1880 		break;
1881 	default:
1882 		return (NULL);
1883 	}
1884 
1885 	bvp = malloc(sizeof(struct bwn_vap), M_80211_VAP, M_WAITOK | M_ZERO);
1886 	vap = &bvp->bv_vap;
1887 	ieee80211_vap_setup(ic, vap, name, unit, opmode, flags, bssid);
1888 	/* override with driver methods */
1889 	bvp->bv_newstate = vap->iv_newstate;
1890 	vap->iv_newstate = bwn_newstate;
1891 
1892 	/* override max aid so sta's cannot assoc when we're out of sta id's */
1893 	vap->iv_max_aid = BWN_STAID_MAX;
1894 
1895 	ieee80211_ratectl_init(vap);
1896 
1897 	/* complete setup */
1898 	ieee80211_vap_attach(vap, ieee80211_media_change,
1899 	    ieee80211_media_status, mac);
1900 	return (vap);
1901 }
1902 
1903 static void
1904 bwn_vap_delete(struct ieee80211vap *vap)
1905 {
1906 	struct bwn_vap *bvp = BWN_VAP(vap);
1907 
1908 	ieee80211_ratectl_deinit(vap);
1909 	ieee80211_vap_detach(vap);
1910 	free(bvp, M_80211_VAP);
1911 }
1912 
1913 static int
1914 bwn_init(struct bwn_softc *sc)
1915 {
1916 	struct bwn_mac *mac;
1917 	int error;
1918 
1919 	BWN_ASSERT_LOCKED(sc);
1920 
1921 	DPRINTF(sc, BWN_DEBUG_RESET, "%s: called\n", __func__);
1922 
1923 	bzero(sc->sc_bssid, IEEE80211_ADDR_LEN);
1924 	sc->sc_flags |= BWN_FLAG_NEED_BEACON_TP;
1925 	sc->sc_filters = 0;
1926 	bwn_wme_clear(sc);
1927 	sc->sc_beacons[0] = sc->sc_beacons[1] = 0;
1928 	sc->sc_rf_enabled = 1;
1929 
1930 	mac = sc->sc_curmac;
1931 	if (mac->mac_status == BWN_MAC_STATUS_UNINIT) {
1932 		error = bwn_core_init(mac);
1933 		if (error != 0)
1934 			return (error);
1935 	}
1936 	if (mac->mac_status == BWN_MAC_STATUS_INITED)
1937 		bwn_core_start(mac);
1938 
1939 	bwn_set_opmode(mac);
1940 	bwn_set_pretbtt(mac);
1941 	bwn_spu_setdelay(mac, 0);
1942 	bwn_set_macaddr(mac);
1943 
1944 	sc->sc_flags |= BWN_FLAG_RUNNING;
1945 	callout_reset(&sc->sc_rfswitch_ch, hz, bwn_rfswitch, sc);
1946 	callout_reset(&sc->sc_watchdog_ch, hz, bwn_watchdog, sc);
1947 
1948 	return (0);
1949 }
1950 
1951 static void
1952 bwn_stop(struct bwn_softc *sc)
1953 {
1954 	struct bwn_mac *mac = sc->sc_curmac;
1955 
1956 	BWN_ASSERT_LOCKED(sc);
1957 
1958 	DPRINTF(sc, BWN_DEBUG_RESET, "%s: called\n", __func__);
1959 
1960 	if (mac->mac_status >= BWN_MAC_STATUS_INITED) {
1961 		/* XXX FIXME opmode not based on VAP */
1962 		bwn_set_opmode(mac);
1963 		bwn_set_macaddr(mac);
1964 	}
1965 
1966 	if (mac->mac_status >= BWN_MAC_STATUS_STARTED)
1967 		bwn_core_stop(mac);
1968 
1969 	callout_stop(&sc->sc_led_blink_ch);
1970 	sc->sc_led_blinking = 0;
1971 
1972 	bwn_core_exit(mac);
1973 	sc->sc_rf_enabled = 0;
1974 
1975 	sc->sc_flags &= ~BWN_FLAG_RUNNING;
1976 }
1977 
1978 static void
1979 bwn_wme_clear(struct bwn_softc *sc)
1980 {
1981 #define	MS(_v, _f)	(((_v) & _f) >> _f##_S)
1982 	struct wmeParams *p;
1983 	unsigned int i;
1984 
1985 	KASSERT(N(bwn_wme_shm_offsets) == N(sc->sc_wmeParams),
1986 	    ("%s:%d: fail", __func__, __LINE__));
1987 
1988 	for (i = 0; i < N(sc->sc_wmeParams); i++) {
1989 		p = &(sc->sc_wmeParams[i]);
1990 
1991 		switch (bwn_wme_shm_offsets[i]) {
1992 		case BWN_WME_VOICE:
1993 			p->wmep_txopLimit = 0;
1994 			p->wmep_aifsn = 2;
1995 			/* XXX FIXME: log2(cwmin) */
1996 			p->wmep_logcwmin = MS(0x0001, WME_PARAM_LOGCWMIN);
1997 			p->wmep_logcwmax = MS(0x0001, WME_PARAM_LOGCWMAX);
1998 			break;
1999 		case BWN_WME_VIDEO:
2000 			p->wmep_txopLimit = 0;
2001 			p->wmep_aifsn = 2;
2002 			/* XXX FIXME: log2(cwmin) */
2003 			p->wmep_logcwmin = MS(0x0001, WME_PARAM_LOGCWMIN);
2004 			p->wmep_logcwmax = MS(0x0001, WME_PARAM_LOGCWMAX);
2005 			break;
2006 		case BWN_WME_BESTEFFORT:
2007 			p->wmep_txopLimit = 0;
2008 			p->wmep_aifsn = 3;
2009 			/* XXX FIXME: log2(cwmin) */
2010 			p->wmep_logcwmin = MS(0x0001, WME_PARAM_LOGCWMIN);
2011 			p->wmep_logcwmax = MS(0x03ff, WME_PARAM_LOGCWMAX);
2012 			break;
2013 		case BWN_WME_BACKGROUND:
2014 			p->wmep_txopLimit = 0;
2015 			p->wmep_aifsn = 7;
2016 			/* XXX FIXME: log2(cwmin) */
2017 			p->wmep_logcwmin = MS(0x0001, WME_PARAM_LOGCWMIN);
2018 			p->wmep_logcwmax = MS(0x03ff, WME_PARAM_LOGCWMAX);
2019 			break;
2020 		default:
2021 			KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
2022 		}
2023 	}
2024 }
2025 
2026 static int
2027 bwn_core_init(struct bwn_mac *mac)
2028 {
2029 	struct bwn_softc *sc = mac->mac_sc;
2030 	uint64_t hf;
2031 	int error;
2032 
2033 	KASSERT(mac->mac_status == BWN_MAC_STATUS_UNINIT,
2034 	    ("%s:%d: fail", __func__, __LINE__));
2035 
2036 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: called\n", __func__);
2037 
2038 	siba_powerup(sc->sc_dev, 0);
2039 	if (!siba_dev_isup(sc->sc_dev))
2040 		bwn_reset_core(mac, mac->mac_phy.gmode);
2041 
2042 	mac->mac_flags &= ~BWN_MAC_FLAG_DFQVALID;
2043 	mac->mac_flags |= BWN_MAC_FLAG_RADIO_ON;
2044 	mac->mac_phy.hwpctl = (bwn_hwpctl) ? 1 : 0;
2045 	BWN_GETTIME(mac->mac_phy.nexttime);
2046 	mac->mac_phy.txerrors = BWN_TXERROR_MAX;
2047 	bzero(&mac->mac_stats, sizeof(mac->mac_stats));
2048 	mac->mac_stats.link_noise = -95;
2049 	mac->mac_reason_intr = 0;
2050 	bzero(mac->mac_reason, sizeof(mac->mac_reason));
2051 	mac->mac_intr_mask = BWN_INTR_MASKTEMPLATE;
2052 #ifdef BWN_DEBUG
2053 	if (sc->sc_debug & BWN_DEBUG_XMIT)
2054 		mac->mac_intr_mask &= ~BWN_INTR_PHY_TXERR;
2055 #endif
2056 	mac->mac_suspended = 1;
2057 	mac->mac_task_state = 0;
2058 	memset(&mac->mac_noise, 0, sizeof(mac->mac_noise));
2059 
2060 	mac->mac_phy.init_pre(mac);
2061 
2062 	siba_pcicore_intr(sc->sc_dev);
2063 
2064 	siba_fix_imcfglobug(sc->sc_dev);
2065 	bwn_bt_disable(mac);
2066 	if (mac->mac_phy.prepare_hw) {
2067 		error = mac->mac_phy.prepare_hw(mac);
2068 		if (error)
2069 			goto fail0;
2070 	}
2071 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: chip_init\n", __func__);
2072 	error = bwn_chip_init(mac);
2073 	if (error)
2074 		goto fail0;
2075 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_COREREV,
2076 	    siba_get_revid(sc->sc_dev));
2077 	hf = bwn_hf_read(mac);
2078 	if (mac->mac_phy.type == BWN_PHYTYPE_G) {
2079 		hf |= BWN_HF_GPHY_SYM_WORKAROUND;
2080 		if (siba_sprom_get_bf_lo(sc->sc_dev) & BWN_BFL_PACTRL)
2081 			hf |= BWN_HF_PAGAINBOOST_OFDM_ON;
2082 		if (mac->mac_phy.rev == 1)
2083 			hf |= BWN_HF_GPHY_DC_CANCELFILTER;
2084 	}
2085 	if (mac->mac_phy.rf_ver == 0x2050) {
2086 		if (mac->mac_phy.rf_rev < 6)
2087 			hf |= BWN_HF_FORCE_VCO_RECALC;
2088 		if (mac->mac_phy.rf_rev == 6)
2089 			hf |= BWN_HF_4318_TSSI;
2090 	}
2091 	if (siba_sprom_get_bf_lo(sc->sc_dev) & BWN_BFL_CRYSTAL_NOSLOW)
2092 		hf |= BWN_HF_SLOWCLOCK_REQ_OFF;
2093 	if ((siba_get_type(sc->sc_dev) == SIBA_TYPE_PCI) &&
2094 	    (siba_get_pcicore_revid(sc->sc_dev) <= 10))
2095 		hf |= BWN_HF_PCI_SLOWCLOCK_WORKAROUND;
2096 	hf &= ~BWN_HF_SKIP_CFP_UPDATE;
2097 	bwn_hf_write(mac, hf);
2098 
2099 	/* Tell the firmware about the MAC capabilities */
2100 	if (siba_get_revid(sc->sc_dev) >= 13) {
2101 		uint32_t cap;
2102 		cap = BWN_READ_4(mac, BWN_MAC_HW_CAP);
2103 		DPRINTF(sc, BWN_DEBUG_RESET,
2104 		    "%s: hw capabilities: 0x%08x\n",
2105 		    __func__, cap);
2106 		bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_MACHW_L,
2107 		    cap & 0xffff);
2108 		bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_MACHW_H,
2109 		    (cap >> 16) & 0xffff);
2110 	}
2111 
2112 	bwn_set_txretry(mac, BWN_RETRY_SHORT, BWN_RETRY_LONG);
2113 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_SHORT_RETRY_FALLBACK, 3);
2114 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_LONG_RETRY_FALLBACK, 2);
2115 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_PROBE_RESP_MAXTIME, 1);
2116 
2117 	bwn_rate_init(mac);
2118 	bwn_set_phytxctl(mac);
2119 
2120 	bwn_shm_write_2(mac, BWN_SCRATCH, BWN_SCRATCH_CONT_MIN,
2121 	    (mac->mac_phy.type == BWN_PHYTYPE_B) ? 0x1f : 0xf);
2122 	bwn_shm_write_2(mac, BWN_SCRATCH, BWN_SCRATCH_CONT_MAX, 0x3ff);
2123 
2124 	if (siba_get_type(sc->sc_dev) == SIBA_TYPE_PCMCIA || bwn_usedma == 0)
2125 		bwn_pio_init(mac);
2126 	else
2127 		bwn_dma_init(mac);
2128 	bwn_wme_init(mac);
2129 	bwn_spu_setdelay(mac, 1);
2130 	bwn_bt_enable(mac);
2131 
2132 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: powerup\n", __func__);
2133 	siba_powerup(sc->sc_dev,
2134 	    !(siba_sprom_get_bf_lo(sc->sc_dev) & BWN_BFL_CRYSTAL_NOSLOW));
2135 	bwn_set_macaddr(mac);
2136 	bwn_crypt_init(mac);
2137 
2138 	/* XXX LED initializatin */
2139 
2140 	mac->mac_status = BWN_MAC_STATUS_INITED;
2141 
2142 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: done\n", __func__);
2143 	return (error);
2144 
2145 fail0:
2146 	siba_powerdown(sc->sc_dev);
2147 	KASSERT(mac->mac_status == BWN_MAC_STATUS_UNINIT,
2148 	    ("%s:%d: fail", __func__, __LINE__));
2149 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: fail\n", __func__);
2150 	return (error);
2151 }
2152 
2153 static void
2154 bwn_core_start(struct bwn_mac *mac)
2155 {
2156 	struct bwn_softc *sc = mac->mac_sc;
2157 	uint32_t tmp;
2158 
2159 	KASSERT(mac->mac_status == BWN_MAC_STATUS_INITED,
2160 	    ("%s:%d: fail", __func__, __LINE__));
2161 
2162 	if (siba_get_revid(sc->sc_dev) < 5)
2163 		return;
2164 
2165 	while (1) {
2166 		tmp = BWN_READ_4(mac, BWN_XMITSTAT_0);
2167 		if (!(tmp & 0x00000001))
2168 			break;
2169 		tmp = BWN_READ_4(mac, BWN_XMITSTAT_1);
2170 	}
2171 
2172 	bwn_mac_enable(mac);
2173 	BWN_WRITE_4(mac, BWN_INTR_MASK, mac->mac_intr_mask);
2174 	callout_reset(&sc->sc_task_ch, hz * 15, bwn_tasks, mac);
2175 
2176 	mac->mac_status = BWN_MAC_STATUS_STARTED;
2177 }
2178 
2179 static void
2180 bwn_core_exit(struct bwn_mac *mac)
2181 {
2182 	struct bwn_softc *sc = mac->mac_sc;
2183 	uint32_t macctl;
2184 
2185 	BWN_ASSERT_LOCKED(mac->mac_sc);
2186 
2187 	KASSERT(mac->mac_status <= BWN_MAC_STATUS_INITED,
2188 	    ("%s:%d: fail", __func__, __LINE__));
2189 
2190 	if (mac->mac_status != BWN_MAC_STATUS_INITED)
2191 		return;
2192 	mac->mac_status = BWN_MAC_STATUS_UNINIT;
2193 
2194 	macctl = BWN_READ_4(mac, BWN_MACCTL);
2195 	macctl &= ~BWN_MACCTL_MCODE_RUN;
2196 	macctl |= BWN_MACCTL_MCODE_JMP0;
2197 	BWN_WRITE_4(mac, BWN_MACCTL, macctl);
2198 
2199 	bwn_dma_stop(mac);
2200 	bwn_pio_stop(mac);
2201 	bwn_chip_exit(mac);
2202 	mac->mac_phy.switch_analog(mac, 0);
2203 	siba_dev_down(sc->sc_dev, 0);
2204 	siba_powerdown(sc->sc_dev);
2205 }
2206 
2207 static void
2208 bwn_bt_disable(struct bwn_mac *mac)
2209 {
2210 	struct bwn_softc *sc = mac->mac_sc;
2211 
2212 	(void)sc;
2213 	/* XXX do nothing yet */
2214 }
2215 
2216 static int
2217 bwn_chip_init(struct bwn_mac *mac)
2218 {
2219 	struct bwn_softc *sc = mac->mac_sc;
2220 	struct bwn_phy *phy = &mac->mac_phy;
2221 	uint32_t macctl;
2222 	int error;
2223 
2224 	macctl = BWN_MACCTL_IHR_ON | BWN_MACCTL_SHM_ON | BWN_MACCTL_STA;
2225 	if (phy->gmode)
2226 		macctl |= BWN_MACCTL_GMODE;
2227 	BWN_WRITE_4(mac, BWN_MACCTL, macctl);
2228 
2229 	error = bwn_fw_fillinfo(mac);
2230 	if (error)
2231 		return (error);
2232 	error = bwn_fw_loaducode(mac);
2233 	if (error)
2234 		return (error);
2235 
2236 	error = bwn_gpio_init(mac);
2237 	if (error)
2238 		return (error);
2239 
2240 	error = bwn_fw_loadinitvals(mac);
2241 	if (error) {
2242 		siba_gpio_set(sc->sc_dev, 0);
2243 		return (error);
2244 	}
2245 	phy->switch_analog(mac, 1);
2246 	error = bwn_phy_init(mac);
2247 	if (error) {
2248 		siba_gpio_set(sc->sc_dev, 0);
2249 		return (error);
2250 	}
2251 	if (phy->set_im)
2252 		phy->set_im(mac, BWN_IMMODE_NONE);
2253 	if (phy->set_antenna)
2254 		phy->set_antenna(mac, BWN_ANT_DEFAULT);
2255 	bwn_set_txantenna(mac, BWN_ANT_DEFAULT);
2256 
2257 	if (phy->type == BWN_PHYTYPE_B)
2258 		BWN_WRITE_2(mac, 0x005e, BWN_READ_2(mac, 0x005e) | 0x0004);
2259 	BWN_WRITE_4(mac, 0x0100, 0x01000000);
2260 	if (siba_get_revid(sc->sc_dev) < 5)
2261 		BWN_WRITE_4(mac, 0x010c, 0x01000000);
2262 
2263 	BWN_WRITE_4(mac, BWN_MACCTL,
2264 	    BWN_READ_4(mac, BWN_MACCTL) & ~BWN_MACCTL_STA);
2265 	BWN_WRITE_4(mac, BWN_MACCTL,
2266 	    BWN_READ_4(mac, BWN_MACCTL) | BWN_MACCTL_STA);
2267 	bwn_shm_write_2(mac, BWN_SHARED, 0x0074, 0x0000);
2268 
2269 	bwn_set_opmode(mac);
2270 	if (siba_get_revid(sc->sc_dev) < 3) {
2271 		BWN_WRITE_2(mac, 0x060e, 0x0000);
2272 		BWN_WRITE_2(mac, 0x0610, 0x8000);
2273 		BWN_WRITE_2(mac, 0x0604, 0x0000);
2274 		BWN_WRITE_2(mac, 0x0606, 0x0200);
2275 	} else {
2276 		BWN_WRITE_4(mac, 0x0188, 0x80000000);
2277 		BWN_WRITE_4(mac, 0x018c, 0x02000000);
2278 	}
2279 	BWN_WRITE_4(mac, BWN_INTR_REASON, 0x00004000);
2280 	BWN_WRITE_4(mac, BWN_DMA0_INTR_MASK, 0x0001dc00);
2281 	BWN_WRITE_4(mac, BWN_DMA1_INTR_MASK, 0x0000dc00);
2282 	BWN_WRITE_4(mac, BWN_DMA2_INTR_MASK, 0x0000dc00);
2283 	BWN_WRITE_4(mac, BWN_DMA3_INTR_MASK, 0x0001dc00);
2284 	BWN_WRITE_4(mac, BWN_DMA4_INTR_MASK, 0x0000dc00);
2285 	BWN_WRITE_4(mac, BWN_DMA5_INTR_MASK, 0x0000dc00);
2286 
2287 	bwn_mac_phy_clock_set(mac, true);
2288 
2289 	/* SIBA powerup */
2290 	BWN_WRITE_2(mac, BWN_POWERUP_DELAY, siba_get_cc_powerdelay(sc->sc_dev));
2291 	return (error);
2292 }
2293 
2294 /* read hostflags */
2295 uint64_t
2296 bwn_hf_read(struct bwn_mac *mac)
2297 {
2298 	uint64_t ret;
2299 
2300 	ret = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_HFHI);
2301 	ret <<= 16;
2302 	ret |= bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_HFMI);
2303 	ret <<= 16;
2304 	ret |= bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_HFLO);
2305 	return (ret);
2306 }
2307 
2308 void
2309 bwn_hf_write(struct bwn_mac *mac, uint64_t value)
2310 {
2311 
2312 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_HFLO,
2313 	    (value & 0x00000000ffffull));
2314 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_HFMI,
2315 	    (value & 0x0000ffff0000ull) >> 16);
2316 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_HFHI,
2317 	    (value & 0xffff00000000ULL) >> 32);
2318 }
2319 
2320 static void
2321 bwn_set_txretry(struct bwn_mac *mac, int s, int l)
2322 {
2323 
2324 	bwn_shm_write_2(mac, BWN_SCRATCH, BWN_SCRATCH_SHORT_RETRY, MIN(s, 0xf));
2325 	bwn_shm_write_2(mac, BWN_SCRATCH, BWN_SCRATCH_LONG_RETRY, MIN(l, 0xf));
2326 }
2327 
2328 static void
2329 bwn_rate_init(struct bwn_mac *mac)
2330 {
2331 
2332 	switch (mac->mac_phy.type) {
2333 	case BWN_PHYTYPE_A:
2334 	case BWN_PHYTYPE_G:
2335 	case BWN_PHYTYPE_LP:
2336 	case BWN_PHYTYPE_N:
2337 		bwn_rate_write(mac, BWN_OFDM_RATE_6MB, 1);
2338 		bwn_rate_write(mac, BWN_OFDM_RATE_12MB, 1);
2339 		bwn_rate_write(mac, BWN_OFDM_RATE_18MB, 1);
2340 		bwn_rate_write(mac, BWN_OFDM_RATE_24MB, 1);
2341 		bwn_rate_write(mac, BWN_OFDM_RATE_36MB, 1);
2342 		bwn_rate_write(mac, BWN_OFDM_RATE_48MB, 1);
2343 		bwn_rate_write(mac, BWN_OFDM_RATE_54MB, 1);
2344 		if (mac->mac_phy.type == BWN_PHYTYPE_A)
2345 			break;
2346 		/* FALLTHROUGH */
2347 	case BWN_PHYTYPE_B:
2348 		bwn_rate_write(mac, BWN_CCK_RATE_1MB, 0);
2349 		bwn_rate_write(mac, BWN_CCK_RATE_2MB, 0);
2350 		bwn_rate_write(mac, BWN_CCK_RATE_5MB, 0);
2351 		bwn_rate_write(mac, BWN_CCK_RATE_11MB, 0);
2352 		break;
2353 	default:
2354 		KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
2355 	}
2356 }
2357 
2358 static void
2359 bwn_rate_write(struct bwn_mac *mac, uint16_t rate, int ofdm)
2360 {
2361 	uint16_t offset;
2362 
2363 	if (ofdm) {
2364 		offset = 0x480;
2365 		offset += (bwn_plcp_getofdm(rate) & 0x000f) * 2;
2366 	} else {
2367 		offset = 0x4c0;
2368 		offset += (bwn_plcp_getcck(rate) & 0x000f) * 2;
2369 	}
2370 	bwn_shm_write_2(mac, BWN_SHARED, offset + 0x20,
2371 	    bwn_shm_read_2(mac, BWN_SHARED, offset));
2372 }
2373 
2374 static uint8_t
2375 bwn_plcp_getcck(const uint8_t bitrate)
2376 {
2377 
2378 	switch (bitrate) {
2379 	case BWN_CCK_RATE_1MB:
2380 		return (0x0a);
2381 	case BWN_CCK_RATE_2MB:
2382 		return (0x14);
2383 	case BWN_CCK_RATE_5MB:
2384 		return (0x37);
2385 	case BWN_CCK_RATE_11MB:
2386 		return (0x6e);
2387 	}
2388 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
2389 	return (0);
2390 }
2391 
2392 static uint8_t
2393 bwn_plcp_getofdm(const uint8_t bitrate)
2394 {
2395 
2396 	switch (bitrate) {
2397 	case BWN_OFDM_RATE_6MB:
2398 		return (0xb);
2399 	case BWN_OFDM_RATE_9MB:
2400 		return (0xf);
2401 	case BWN_OFDM_RATE_12MB:
2402 		return (0xa);
2403 	case BWN_OFDM_RATE_18MB:
2404 		return (0xe);
2405 	case BWN_OFDM_RATE_24MB:
2406 		return (0x9);
2407 	case BWN_OFDM_RATE_36MB:
2408 		return (0xd);
2409 	case BWN_OFDM_RATE_48MB:
2410 		return (0x8);
2411 	case BWN_OFDM_RATE_54MB:
2412 		return (0xc);
2413 	}
2414 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
2415 	return (0);
2416 }
2417 
2418 static void
2419 bwn_set_phytxctl(struct bwn_mac *mac)
2420 {
2421 	uint16_t ctl;
2422 
2423 	ctl = (BWN_TX_PHY_ENC_CCK | BWN_TX_PHY_ANT01AUTO |
2424 	    BWN_TX_PHY_TXPWR);
2425 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_BEACON_PHYCTL, ctl);
2426 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_ACKCTS_PHYCTL, ctl);
2427 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_PROBE_RESP_PHYCTL, ctl);
2428 }
2429 
2430 static void
2431 bwn_pio_init(struct bwn_mac *mac)
2432 {
2433 	struct bwn_pio *pio = &mac->mac_method.pio;
2434 
2435 	BWN_WRITE_4(mac, BWN_MACCTL, BWN_READ_4(mac, BWN_MACCTL)
2436 	    & ~BWN_MACCTL_BIGENDIAN);
2437 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_RX_PADOFFSET, 0);
2438 
2439 	bwn_pio_set_txqueue(mac, &pio->wme[WME_AC_BK], 0);
2440 	bwn_pio_set_txqueue(mac, &pio->wme[WME_AC_BE], 1);
2441 	bwn_pio_set_txqueue(mac, &pio->wme[WME_AC_VI], 2);
2442 	bwn_pio_set_txqueue(mac, &pio->wme[WME_AC_VO], 3);
2443 	bwn_pio_set_txqueue(mac, &pio->mcast, 4);
2444 	bwn_pio_setupqueue_rx(mac, &pio->rx, 0);
2445 }
2446 
2447 static void
2448 bwn_pio_set_txqueue(struct bwn_mac *mac, struct bwn_pio_txqueue *tq,
2449     int index)
2450 {
2451 	struct bwn_pio_txpkt *tp;
2452 	struct bwn_softc *sc = mac->mac_sc;
2453 	unsigned int i;
2454 
2455 	tq->tq_base = bwn_pio_idx2base(mac, index) + BWN_PIO_TXQOFFSET(mac);
2456 	tq->tq_index = index;
2457 
2458 	tq->tq_free = BWN_PIO_MAX_TXPACKETS;
2459 	if (siba_get_revid(sc->sc_dev) >= 8)
2460 		tq->tq_size = 1920;
2461 	else {
2462 		tq->tq_size = bwn_pio_read_2(mac, tq, BWN_PIO_TXQBUFSIZE);
2463 		tq->tq_size -= 80;
2464 	}
2465 
2466 	TAILQ_INIT(&tq->tq_pktlist);
2467 	for (i = 0; i < N(tq->tq_pkts); i++) {
2468 		tp = &(tq->tq_pkts[i]);
2469 		tp->tp_index = i;
2470 		tp->tp_queue = tq;
2471 		TAILQ_INSERT_TAIL(&tq->tq_pktlist, tp, tp_list);
2472 	}
2473 }
2474 
2475 static uint16_t
2476 bwn_pio_idx2base(struct bwn_mac *mac, int index)
2477 {
2478 	struct bwn_softc *sc = mac->mac_sc;
2479 	static const uint16_t bases[] = {
2480 		BWN_PIO_BASE0,
2481 		BWN_PIO_BASE1,
2482 		BWN_PIO_BASE2,
2483 		BWN_PIO_BASE3,
2484 		BWN_PIO_BASE4,
2485 		BWN_PIO_BASE5,
2486 		BWN_PIO_BASE6,
2487 		BWN_PIO_BASE7,
2488 	};
2489 	static const uint16_t bases_rev11[] = {
2490 		BWN_PIO11_BASE0,
2491 		BWN_PIO11_BASE1,
2492 		BWN_PIO11_BASE2,
2493 		BWN_PIO11_BASE3,
2494 		BWN_PIO11_BASE4,
2495 		BWN_PIO11_BASE5,
2496 	};
2497 
2498 	if (siba_get_revid(sc->sc_dev) >= 11) {
2499 		if (index >= N(bases_rev11))
2500 			device_printf(sc->sc_dev, "%s: warning\n", __func__);
2501 		return (bases_rev11[index]);
2502 	}
2503 	if (index >= N(bases))
2504 		device_printf(sc->sc_dev, "%s: warning\n", __func__);
2505 	return (bases[index]);
2506 }
2507 
2508 static void
2509 bwn_pio_setupqueue_rx(struct bwn_mac *mac, struct bwn_pio_rxqueue *prq,
2510     int index)
2511 {
2512 	struct bwn_softc *sc = mac->mac_sc;
2513 
2514 	prq->prq_mac = mac;
2515 	prq->prq_rev = siba_get_revid(sc->sc_dev);
2516 	prq->prq_base = bwn_pio_idx2base(mac, index) + BWN_PIO_RXQOFFSET(mac);
2517 	bwn_dma_rxdirectfifo(mac, index, 1);
2518 }
2519 
2520 static void
2521 bwn_destroy_pioqueue_tx(struct bwn_pio_txqueue *tq)
2522 {
2523 	if (tq == NULL)
2524 		return;
2525 	bwn_pio_cancel_tx_packets(tq);
2526 }
2527 
2528 static void
2529 bwn_destroy_queue_tx(struct bwn_pio_txqueue *pio)
2530 {
2531 
2532 	bwn_destroy_pioqueue_tx(pio);
2533 }
2534 
2535 static uint16_t
2536 bwn_pio_read_2(struct bwn_mac *mac, struct bwn_pio_txqueue *tq,
2537     uint16_t offset)
2538 {
2539 
2540 	return (BWN_READ_2(mac, tq->tq_base + offset));
2541 }
2542 
2543 static void
2544 bwn_dma_rxdirectfifo(struct bwn_mac *mac, int idx, uint8_t enable)
2545 {
2546 	uint32_t ctl;
2547 	int type;
2548 	uint16_t base;
2549 
2550 	type = bwn_dma_mask2type(bwn_dma_mask(mac));
2551 	base = bwn_dma_base(type, idx);
2552 	if (type == BWN_DMA_64BIT) {
2553 		ctl = BWN_READ_4(mac, base + BWN_DMA64_RXCTL);
2554 		ctl &= ~BWN_DMA64_RXDIRECTFIFO;
2555 		if (enable)
2556 			ctl |= BWN_DMA64_RXDIRECTFIFO;
2557 		BWN_WRITE_4(mac, base + BWN_DMA64_RXCTL, ctl);
2558 	} else {
2559 		ctl = BWN_READ_4(mac, base + BWN_DMA32_RXCTL);
2560 		ctl &= ~BWN_DMA32_RXDIRECTFIFO;
2561 		if (enable)
2562 			ctl |= BWN_DMA32_RXDIRECTFIFO;
2563 		BWN_WRITE_4(mac, base + BWN_DMA32_RXCTL, ctl);
2564 	}
2565 }
2566 
2567 static uint64_t
2568 bwn_dma_mask(struct bwn_mac *mac)
2569 {
2570 	uint32_t tmp;
2571 	uint16_t base;
2572 
2573 	tmp = BWN_READ_4(mac, SIBA_TGSHIGH);
2574 	if (tmp & SIBA_TGSHIGH_DMA64)
2575 		return (BWN_DMA_BIT_MASK(64));
2576 	base = bwn_dma_base(0, 0);
2577 	BWN_WRITE_4(mac, base + BWN_DMA32_TXCTL, BWN_DMA32_TXADDREXT_MASK);
2578 	tmp = BWN_READ_4(mac, base + BWN_DMA32_TXCTL);
2579 	if (tmp & BWN_DMA32_TXADDREXT_MASK)
2580 		return (BWN_DMA_BIT_MASK(32));
2581 
2582 	return (BWN_DMA_BIT_MASK(30));
2583 }
2584 
2585 static int
2586 bwn_dma_mask2type(uint64_t dmamask)
2587 {
2588 
2589 	if (dmamask == BWN_DMA_BIT_MASK(30))
2590 		return (BWN_DMA_30BIT);
2591 	if (dmamask == BWN_DMA_BIT_MASK(32))
2592 		return (BWN_DMA_32BIT);
2593 	if (dmamask == BWN_DMA_BIT_MASK(64))
2594 		return (BWN_DMA_64BIT);
2595 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
2596 	return (BWN_DMA_30BIT);
2597 }
2598 
2599 static void
2600 bwn_pio_cancel_tx_packets(struct bwn_pio_txqueue *tq)
2601 {
2602 	struct bwn_pio_txpkt *tp;
2603 	unsigned int i;
2604 
2605 	for (i = 0; i < N(tq->tq_pkts); i++) {
2606 		tp = &(tq->tq_pkts[i]);
2607 		if (tp->tp_m) {
2608 			m_freem(tp->tp_m);
2609 			tp->tp_m = NULL;
2610 		}
2611 	}
2612 }
2613 
2614 static uint16_t
2615 bwn_dma_base(int type, int controller_idx)
2616 {
2617 	static const uint16_t map64[] = {
2618 		BWN_DMA64_BASE0,
2619 		BWN_DMA64_BASE1,
2620 		BWN_DMA64_BASE2,
2621 		BWN_DMA64_BASE3,
2622 		BWN_DMA64_BASE4,
2623 		BWN_DMA64_BASE5,
2624 	};
2625 	static const uint16_t map32[] = {
2626 		BWN_DMA32_BASE0,
2627 		BWN_DMA32_BASE1,
2628 		BWN_DMA32_BASE2,
2629 		BWN_DMA32_BASE3,
2630 		BWN_DMA32_BASE4,
2631 		BWN_DMA32_BASE5,
2632 	};
2633 
2634 	if (type == BWN_DMA_64BIT) {
2635 		KASSERT(controller_idx >= 0 && controller_idx < N(map64),
2636 		    ("%s:%d: fail", __func__, __LINE__));
2637 		return (map64[controller_idx]);
2638 	}
2639 	KASSERT(controller_idx >= 0 && controller_idx < N(map32),
2640 	    ("%s:%d: fail", __func__, __LINE__));
2641 	return (map32[controller_idx]);
2642 }
2643 
2644 static void
2645 bwn_dma_init(struct bwn_mac *mac)
2646 {
2647 	struct bwn_dma *dma = &mac->mac_method.dma;
2648 
2649 	/* setup TX DMA channels. */
2650 	bwn_dma_setup(dma->wme[WME_AC_BK]);
2651 	bwn_dma_setup(dma->wme[WME_AC_BE]);
2652 	bwn_dma_setup(dma->wme[WME_AC_VI]);
2653 	bwn_dma_setup(dma->wme[WME_AC_VO]);
2654 	bwn_dma_setup(dma->mcast);
2655 	/* setup RX DMA channel. */
2656 	bwn_dma_setup(dma->rx);
2657 }
2658 
2659 static struct bwn_dma_ring *
2660 bwn_dma_ringsetup(struct bwn_mac *mac, int controller_index,
2661     int for_tx, int type)
2662 {
2663 	struct bwn_dma *dma = &mac->mac_method.dma;
2664 	struct bwn_dma_ring *dr;
2665 	struct bwn_dmadesc_generic *desc;
2666 	struct bwn_dmadesc_meta *mt;
2667 	struct bwn_softc *sc = mac->mac_sc;
2668 	int error, i;
2669 
2670 	dr = malloc(sizeof(*dr), M_DEVBUF, M_NOWAIT | M_ZERO);
2671 	if (dr == NULL)
2672 		goto out;
2673 	dr->dr_numslots = BWN_RXRING_SLOTS;
2674 	if (for_tx)
2675 		dr->dr_numslots = BWN_TXRING_SLOTS;
2676 
2677 	dr->dr_meta = malloc(dr->dr_numslots * sizeof(struct bwn_dmadesc_meta),
2678 	    M_DEVBUF, M_NOWAIT | M_ZERO);
2679 	if (dr->dr_meta == NULL)
2680 		goto fail0;
2681 
2682 	dr->dr_type = type;
2683 	dr->dr_mac = mac;
2684 	dr->dr_base = bwn_dma_base(type, controller_index);
2685 	dr->dr_index = controller_index;
2686 	if (type == BWN_DMA_64BIT) {
2687 		dr->getdesc = bwn_dma_64_getdesc;
2688 		dr->setdesc = bwn_dma_64_setdesc;
2689 		dr->start_transfer = bwn_dma_64_start_transfer;
2690 		dr->suspend = bwn_dma_64_suspend;
2691 		dr->resume = bwn_dma_64_resume;
2692 		dr->get_curslot = bwn_dma_64_get_curslot;
2693 		dr->set_curslot = bwn_dma_64_set_curslot;
2694 	} else {
2695 		dr->getdesc = bwn_dma_32_getdesc;
2696 		dr->setdesc = bwn_dma_32_setdesc;
2697 		dr->start_transfer = bwn_dma_32_start_transfer;
2698 		dr->suspend = bwn_dma_32_suspend;
2699 		dr->resume = bwn_dma_32_resume;
2700 		dr->get_curslot = bwn_dma_32_get_curslot;
2701 		dr->set_curslot = bwn_dma_32_set_curslot;
2702 	}
2703 	if (for_tx) {
2704 		dr->dr_tx = 1;
2705 		dr->dr_curslot = -1;
2706 	} else {
2707 		if (dr->dr_index == 0) {
2708 			switch (mac->mac_fw.fw_hdr_format) {
2709 			case BWN_FW_HDR_351:
2710 			case BWN_FW_HDR_410:
2711 				dr->dr_rx_bufsize =
2712 				    BWN_DMA0_RX_BUFFERSIZE_FW351;
2713 				dr->dr_frameoffset =
2714 				    BWN_DMA0_RX_FRAMEOFFSET_FW351;
2715 				break;
2716 			case BWN_FW_HDR_598:
2717 				dr->dr_rx_bufsize =
2718 				    BWN_DMA0_RX_BUFFERSIZE_FW598;
2719 				dr->dr_frameoffset =
2720 				    BWN_DMA0_RX_FRAMEOFFSET_FW598;
2721 				break;
2722 			}
2723 		} else
2724 			KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
2725 	}
2726 
2727 	error = bwn_dma_allocringmemory(dr);
2728 	if (error)
2729 		goto fail2;
2730 
2731 	if (for_tx) {
2732 		/*
2733 		 * Assumption: BWN_TXRING_SLOTS can be divided by
2734 		 * BWN_TX_SLOTS_PER_FRAME
2735 		 */
2736 		KASSERT(BWN_TXRING_SLOTS % BWN_TX_SLOTS_PER_FRAME == 0,
2737 		    ("%s:%d: fail", __func__, __LINE__));
2738 
2739 		dr->dr_txhdr_cache = contigmalloc(
2740 		    (dr->dr_numslots / BWN_TX_SLOTS_PER_FRAME) *
2741 		    BWN_MAXTXHDRSIZE, M_DEVBUF, M_ZERO,
2742 		    0, BUS_SPACE_MAXADDR, 8, 0);
2743 		if (dr->dr_txhdr_cache == NULL) {
2744 			device_printf(sc->sc_dev,
2745 			    "can't allocate TX header DMA memory\n");
2746 			goto fail1;
2747 		}
2748 
2749 		/*
2750 		 * Create TX ring DMA stuffs
2751 		 */
2752 		error = bus_dma_tag_create(dma->parent_dtag,
2753 				    BWN_ALIGN, 0,
2754 				    BUS_SPACE_MAXADDR,
2755 				    BUS_SPACE_MAXADDR,
2756 				    NULL, NULL,
2757 				    BWN_HDRSIZE(mac),
2758 				    1,
2759 				    BUS_SPACE_MAXSIZE_32BIT,
2760 				    0,
2761 				    NULL, NULL,
2762 				    &dr->dr_txring_dtag);
2763 		if (error) {
2764 			device_printf(sc->sc_dev,
2765 			    "can't create TX ring DMA tag: TODO frees\n");
2766 			goto fail2;
2767 		}
2768 
2769 		for (i = 0; i < dr->dr_numslots; i += 2) {
2770 			dr->getdesc(dr, i, &desc, &mt);
2771 
2772 			mt->mt_txtype = BWN_DMADESC_METATYPE_HEADER;
2773 			mt->mt_m = NULL;
2774 			mt->mt_ni = NULL;
2775 			mt->mt_islast = 0;
2776 			error = bus_dmamap_create(dr->dr_txring_dtag, 0,
2777 			    &mt->mt_dmap);
2778 			if (error) {
2779 				device_printf(sc->sc_dev,
2780 				     "can't create RX buf DMA map\n");
2781 				goto fail2;
2782 			}
2783 
2784 			dr->getdesc(dr, i + 1, &desc, &mt);
2785 
2786 			mt->mt_txtype = BWN_DMADESC_METATYPE_BODY;
2787 			mt->mt_m = NULL;
2788 			mt->mt_ni = NULL;
2789 			mt->mt_islast = 1;
2790 			error = bus_dmamap_create(dma->txbuf_dtag, 0,
2791 			    &mt->mt_dmap);
2792 			if (error) {
2793 				device_printf(sc->sc_dev,
2794 				     "can't create RX buf DMA map\n");
2795 				goto fail2;
2796 			}
2797 		}
2798 	} else {
2799 		error = bus_dmamap_create(dma->rxbuf_dtag, 0,
2800 		    &dr->dr_spare_dmap);
2801 		if (error) {
2802 			device_printf(sc->sc_dev,
2803 			    "can't create RX buf DMA map\n");
2804 			goto out;		/* XXX wrong! */
2805 		}
2806 
2807 		for (i = 0; i < dr->dr_numslots; i++) {
2808 			dr->getdesc(dr, i, &desc, &mt);
2809 
2810 			error = bus_dmamap_create(dma->rxbuf_dtag, 0,
2811 			    &mt->mt_dmap);
2812 			if (error) {
2813 				device_printf(sc->sc_dev,
2814 				    "can't create RX buf DMA map\n");
2815 				goto out;	/* XXX wrong! */
2816 			}
2817 			error = bwn_dma_newbuf(dr, desc, mt, 1);
2818 			if (error) {
2819 				device_printf(sc->sc_dev,
2820 				    "failed to allocate RX buf\n");
2821 				goto out;	/* XXX wrong! */
2822 			}
2823 		}
2824 
2825 		bus_dmamap_sync(dr->dr_ring_dtag, dr->dr_ring_dmap,
2826 		    BUS_DMASYNC_PREWRITE);
2827 
2828 		dr->dr_usedslot = dr->dr_numslots;
2829 	}
2830 
2831       out:
2832 	return (dr);
2833 
2834 fail2:
2835 	if (dr->dr_txhdr_cache != NULL) {
2836 		contigfree(dr->dr_txhdr_cache,
2837 		    (dr->dr_numslots / BWN_TX_SLOTS_PER_FRAME) *
2838 		    BWN_MAXTXHDRSIZE, M_DEVBUF);
2839 	}
2840 fail1:
2841 	free(dr->dr_meta, M_DEVBUF);
2842 fail0:
2843 	free(dr, M_DEVBUF);
2844 	return (NULL);
2845 }
2846 
2847 static void
2848 bwn_dma_ringfree(struct bwn_dma_ring **dr)
2849 {
2850 
2851 	if (dr == NULL)
2852 		return;
2853 
2854 	bwn_dma_free_descbufs(*dr);
2855 	bwn_dma_free_ringmemory(*dr);
2856 
2857 	if ((*dr)->dr_txhdr_cache != NULL) {
2858 		contigfree((*dr)->dr_txhdr_cache,
2859 		    ((*dr)->dr_numslots / BWN_TX_SLOTS_PER_FRAME) *
2860 		    BWN_MAXTXHDRSIZE, M_DEVBUF);
2861 	}
2862 	free((*dr)->dr_meta, M_DEVBUF);
2863 	free(*dr, M_DEVBUF);
2864 
2865 	*dr = NULL;
2866 }
2867 
2868 static void
2869 bwn_dma_32_getdesc(struct bwn_dma_ring *dr, int slot,
2870     struct bwn_dmadesc_generic **gdesc, struct bwn_dmadesc_meta **meta)
2871 {
2872 	struct bwn_dmadesc32 *desc;
2873 
2874 	*meta = &(dr->dr_meta[slot]);
2875 	desc = dr->dr_ring_descbase;
2876 	desc = &(desc[slot]);
2877 
2878 	*gdesc = (struct bwn_dmadesc_generic *)desc;
2879 }
2880 
2881 static void
2882 bwn_dma_32_setdesc(struct bwn_dma_ring *dr,
2883     struct bwn_dmadesc_generic *desc, bus_addr_t dmaaddr, uint16_t bufsize,
2884     int start, int end, int irq)
2885 {
2886 	struct bwn_dmadesc32 *descbase = dr->dr_ring_descbase;
2887 	struct bwn_softc *sc = dr->dr_mac->mac_sc;
2888 	uint32_t addr, addrext, ctl;
2889 	int slot;
2890 
2891 	slot = (int)(&(desc->dma.dma32) - descbase);
2892 	KASSERT(slot >= 0 && slot < dr->dr_numslots,
2893 	    ("%s:%d: fail", __func__, __LINE__));
2894 
2895 	addr = (uint32_t) (dmaaddr & ~SIBA_DMA_TRANSLATION_MASK);
2896 	addrext = (uint32_t) (dmaaddr & SIBA_DMA_TRANSLATION_MASK) >> 30;
2897 	addr |= siba_dma_translation(sc->sc_dev);
2898 	ctl = bufsize & BWN_DMA32_DCTL_BYTECNT;
2899 	if (slot == dr->dr_numslots - 1)
2900 		ctl |= BWN_DMA32_DCTL_DTABLEEND;
2901 	if (start)
2902 		ctl |= BWN_DMA32_DCTL_FRAMESTART;
2903 	if (end)
2904 		ctl |= BWN_DMA32_DCTL_FRAMEEND;
2905 	if (irq)
2906 		ctl |= BWN_DMA32_DCTL_IRQ;
2907 	ctl |= (addrext << BWN_DMA32_DCTL_ADDREXT_SHIFT)
2908 	    & BWN_DMA32_DCTL_ADDREXT_MASK;
2909 
2910 	desc->dma.dma32.control = htole32(ctl);
2911 	desc->dma.dma32.address = htole32(addr);
2912 }
2913 
2914 static void
2915 bwn_dma_32_start_transfer(struct bwn_dma_ring *dr, int slot)
2916 {
2917 
2918 	BWN_DMA_WRITE(dr, BWN_DMA32_TXINDEX,
2919 	    (uint32_t)(slot * sizeof(struct bwn_dmadesc32)));
2920 }
2921 
2922 static void
2923 bwn_dma_32_suspend(struct bwn_dma_ring *dr)
2924 {
2925 
2926 	BWN_DMA_WRITE(dr, BWN_DMA32_TXCTL,
2927 	    BWN_DMA_READ(dr, BWN_DMA32_TXCTL) | BWN_DMA32_TXSUSPEND);
2928 }
2929 
2930 static void
2931 bwn_dma_32_resume(struct bwn_dma_ring *dr)
2932 {
2933 
2934 	BWN_DMA_WRITE(dr, BWN_DMA32_TXCTL,
2935 	    BWN_DMA_READ(dr, BWN_DMA32_TXCTL) & ~BWN_DMA32_TXSUSPEND);
2936 }
2937 
2938 static int
2939 bwn_dma_32_get_curslot(struct bwn_dma_ring *dr)
2940 {
2941 	uint32_t val;
2942 
2943 	val = BWN_DMA_READ(dr, BWN_DMA32_RXSTATUS);
2944 	val &= BWN_DMA32_RXDPTR;
2945 
2946 	return (val / sizeof(struct bwn_dmadesc32));
2947 }
2948 
2949 static void
2950 bwn_dma_32_set_curslot(struct bwn_dma_ring *dr, int slot)
2951 {
2952 
2953 	BWN_DMA_WRITE(dr, BWN_DMA32_RXINDEX,
2954 	    (uint32_t) (slot * sizeof(struct bwn_dmadesc32)));
2955 }
2956 
2957 static void
2958 bwn_dma_64_getdesc(struct bwn_dma_ring *dr, int slot,
2959     struct bwn_dmadesc_generic **gdesc, struct bwn_dmadesc_meta **meta)
2960 {
2961 	struct bwn_dmadesc64 *desc;
2962 
2963 	*meta = &(dr->dr_meta[slot]);
2964 	desc = dr->dr_ring_descbase;
2965 	desc = &(desc[slot]);
2966 
2967 	*gdesc = (struct bwn_dmadesc_generic *)desc;
2968 }
2969 
2970 static void
2971 bwn_dma_64_setdesc(struct bwn_dma_ring *dr,
2972     struct bwn_dmadesc_generic *desc, bus_addr_t dmaaddr, uint16_t bufsize,
2973     int start, int end, int irq)
2974 {
2975 	struct bwn_dmadesc64 *descbase = dr->dr_ring_descbase;
2976 	struct bwn_softc *sc = dr->dr_mac->mac_sc;
2977 	int slot;
2978 	uint32_t ctl0 = 0, ctl1 = 0;
2979 	uint32_t addrlo, addrhi;
2980 	uint32_t addrext;
2981 
2982 	slot = (int)(&(desc->dma.dma64) - descbase);
2983 	KASSERT(slot >= 0 && slot < dr->dr_numslots,
2984 	    ("%s:%d: fail", __func__, __LINE__));
2985 
2986 	addrlo = (uint32_t) (dmaaddr & 0xffffffff);
2987 	addrhi = (((uint64_t) dmaaddr >> 32) & ~SIBA_DMA_TRANSLATION_MASK);
2988 	addrext = (((uint64_t) dmaaddr >> 32) & SIBA_DMA_TRANSLATION_MASK) >>
2989 	    30;
2990 	addrhi |= (siba_dma_translation(sc->sc_dev) << 1);
2991 	if (slot == dr->dr_numslots - 1)
2992 		ctl0 |= BWN_DMA64_DCTL0_DTABLEEND;
2993 	if (start)
2994 		ctl0 |= BWN_DMA64_DCTL0_FRAMESTART;
2995 	if (end)
2996 		ctl0 |= BWN_DMA64_DCTL0_FRAMEEND;
2997 	if (irq)
2998 		ctl0 |= BWN_DMA64_DCTL0_IRQ;
2999 	ctl1 |= bufsize & BWN_DMA64_DCTL1_BYTECNT;
3000 	ctl1 |= (addrext << BWN_DMA64_DCTL1_ADDREXT_SHIFT)
3001 	    & BWN_DMA64_DCTL1_ADDREXT_MASK;
3002 
3003 	desc->dma.dma64.control0 = htole32(ctl0);
3004 	desc->dma.dma64.control1 = htole32(ctl1);
3005 	desc->dma.dma64.address_low = htole32(addrlo);
3006 	desc->dma.dma64.address_high = htole32(addrhi);
3007 }
3008 
3009 static void
3010 bwn_dma_64_start_transfer(struct bwn_dma_ring *dr, int slot)
3011 {
3012 
3013 	BWN_DMA_WRITE(dr, BWN_DMA64_TXINDEX,
3014 	    (uint32_t)(slot * sizeof(struct bwn_dmadesc64)));
3015 }
3016 
3017 static void
3018 bwn_dma_64_suspend(struct bwn_dma_ring *dr)
3019 {
3020 
3021 	BWN_DMA_WRITE(dr, BWN_DMA64_TXCTL,
3022 	    BWN_DMA_READ(dr, BWN_DMA64_TXCTL) | BWN_DMA64_TXSUSPEND);
3023 }
3024 
3025 static void
3026 bwn_dma_64_resume(struct bwn_dma_ring *dr)
3027 {
3028 
3029 	BWN_DMA_WRITE(dr, BWN_DMA64_TXCTL,
3030 	    BWN_DMA_READ(dr, BWN_DMA64_TXCTL) & ~BWN_DMA64_TXSUSPEND);
3031 }
3032 
3033 static int
3034 bwn_dma_64_get_curslot(struct bwn_dma_ring *dr)
3035 {
3036 	uint32_t val;
3037 
3038 	val = BWN_DMA_READ(dr, BWN_DMA64_RXSTATUS);
3039 	val &= BWN_DMA64_RXSTATDPTR;
3040 
3041 	return (val / sizeof(struct bwn_dmadesc64));
3042 }
3043 
3044 static void
3045 bwn_dma_64_set_curslot(struct bwn_dma_ring *dr, int slot)
3046 {
3047 
3048 	BWN_DMA_WRITE(dr, BWN_DMA64_RXINDEX,
3049 	    (uint32_t)(slot * sizeof(struct bwn_dmadesc64)));
3050 }
3051 
3052 static int
3053 bwn_dma_allocringmemory(struct bwn_dma_ring *dr)
3054 {
3055 	struct bwn_mac *mac = dr->dr_mac;
3056 	struct bwn_dma *dma = &mac->mac_method.dma;
3057 	struct bwn_softc *sc = mac->mac_sc;
3058 	int error;
3059 
3060 	error = bus_dma_tag_create(dma->parent_dtag,
3061 			    BWN_ALIGN, 0,
3062 			    BUS_SPACE_MAXADDR,
3063 			    BUS_SPACE_MAXADDR,
3064 			    NULL, NULL,
3065 			    BWN_DMA_RINGMEMSIZE,
3066 			    1,
3067 			    BUS_SPACE_MAXSIZE_32BIT,
3068 			    0,
3069 			    NULL, NULL,
3070 			    &dr->dr_ring_dtag);
3071 	if (error) {
3072 		device_printf(sc->sc_dev,
3073 		    "can't create TX ring DMA tag: TODO frees\n");
3074 		return (-1);
3075 	}
3076 
3077 	error = bus_dmamem_alloc(dr->dr_ring_dtag,
3078 	    &dr->dr_ring_descbase, BUS_DMA_WAITOK | BUS_DMA_ZERO,
3079 	    &dr->dr_ring_dmap);
3080 	if (error) {
3081 		device_printf(sc->sc_dev,
3082 		    "can't allocate DMA mem: TODO frees\n");
3083 		return (-1);
3084 	}
3085 	error = bus_dmamap_load(dr->dr_ring_dtag, dr->dr_ring_dmap,
3086 	    dr->dr_ring_descbase, BWN_DMA_RINGMEMSIZE,
3087 	    bwn_dma_ring_addr, &dr->dr_ring_dmabase, BUS_DMA_NOWAIT);
3088 	if (error) {
3089 		device_printf(sc->sc_dev,
3090 		    "can't load DMA mem: TODO free\n");
3091 		return (-1);
3092 	}
3093 
3094 	return (0);
3095 }
3096 
3097 static void
3098 bwn_dma_setup(struct bwn_dma_ring *dr)
3099 {
3100 	struct bwn_softc *sc = dr->dr_mac->mac_sc;
3101 	uint64_t ring64;
3102 	uint32_t addrext, ring32, value;
3103 	uint32_t trans = siba_dma_translation(sc->sc_dev);
3104 
3105 	if (dr->dr_tx) {
3106 		dr->dr_curslot = -1;
3107 
3108 		if (dr->dr_type == BWN_DMA_64BIT) {
3109 			ring64 = (uint64_t)(dr->dr_ring_dmabase);
3110 			addrext = ((ring64 >> 32) & SIBA_DMA_TRANSLATION_MASK)
3111 			    >> 30;
3112 			value = BWN_DMA64_TXENABLE;
3113 			value |= (addrext << BWN_DMA64_TXADDREXT_SHIFT)
3114 			    & BWN_DMA64_TXADDREXT_MASK;
3115 			BWN_DMA_WRITE(dr, BWN_DMA64_TXCTL, value);
3116 			BWN_DMA_WRITE(dr, BWN_DMA64_TXRINGLO,
3117 			    (ring64 & 0xffffffff));
3118 			BWN_DMA_WRITE(dr, BWN_DMA64_TXRINGHI,
3119 			    ((ring64 >> 32) &
3120 			    ~SIBA_DMA_TRANSLATION_MASK) | (trans << 1));
3121 		} else {
3122 			ring32 = (uint32_t)(dr->dr_ring_dmabase);
3123 			addrext = (ring32 & SIBA_DMA_TRANSLATION_MASK) >> 30;
3124 			value = BWN_DMA32_TXENABLE;
3125 			value |= (addrext << BWN_DMA32_TXADDREXT_SHIFT)
3126 			    & BWN_DMA32_TXADDREXT_MASK;
3127 			BWN_DMA_WRITE(dr, BWN_DMA32_TXCTL, value);
3128 			BWN_DMA_WRITE(dr, BWN_DMA32_TXRING,
3129 			    (ring32 & ~SIBA_DMA_TRANSLATION_MASK) | trans);
3130 		}
3131 		return;
3132 	}
3133 
3134 	/*
3135 	 * set for RX
3136 	 */
3137 	dr->dr_usedslot = dr->dr_numslots;
3138 
3139 	if (dr->dr_type == BWN_DMA_64BIT) {
3140 		ring64 = (uint64_t)(dr->dr_ring_dmabase);
3141 		addrext = ((ring64 >> 32) & SIBA_DMA_TRANSLATION_MASK) >> 30;
3142 		value = (dr->dr_frameoffset << BWN_DMA64_RXFROFF_SHIFT);
3143 		value |= BWN_DMA64_RXENABLE;
3144 		value |= (addrext << BWN_DMA64_RXADDREXT_SHIFT)
3145 		    & BWN_DMA64_RXADDREXT_MASK;
3146 		BWN_DMA_WRITE(dr, BWN_DMA64_RXCTL, value);
3147 		BWN_DMA_WRITE(dr, BWN_DMA64_RXRINGLO, (ring64 & 0xffffffff));
3148 		BWN_DMA_WRITE(dr, BWN_DMA64_RXRINGHI,
3149 		    ((ring64 >> 32) & ~SIBA_DMA_TRANSLATION_MASK)
3150 		    | (trans << 1));
3151 		BWN_DMA_WRITE(dr, BWN_DMA64_RXINDEX, dr->dr_numslots *
3152 		    sizeof(struct bwn_dmadesc64));
3153 	} else {
3154 		ring32 = (uint32_t)(dr->dr_ring_dmabase);
3155 		addrext = (ring32 & SIBA_DMA_TRANSLATION_MASK) >> 30;
3156 		value = (dr->dr_frameoffset << BWN_DMA32_RXFROFF_SHIFT);
3157 		value |= BWN_DMA32_RXENABLE;
3158 		value |= (addrext << BWN_DMA32_RXADDREXT_SHIFT)
3159 		    & BWN_DMA32_RXADDREXT_MASK;
3160 		BWN_DMA_WRITE(dr, BWN_DMA32_RXCTL, value);
3161 		BWN_DMA_WRITE(dr, BWN_DMA32_RXRING,
3162 		    (ring32 & ~SIBA_DMA_TRANSLATION_MASK) | trans);
3163 		BWN_DMA_WRITE(dr, BWN_DMA32_RXINDEX, dr->dr_numslots *
3164 		    sizeof(struct bwn_dmadesc32));
3165 	}
3166 }
3167 
3168 static void
3169 bwn_dma_free_ringmemory(struct bwn_dma_ring *dr)
3170 {
3171 
3172 	bus_dmamap_unload(dr->dr_ring_dtag, dr->dr_ring_dmap);
3173 	bus_dmamem_free(dr->dr_ring_dtag, dr->dr_ring_descbase,
3174 	    dr->dr_ring_dmap);
3175 }
3176 
3177 static void
3178 bwn_dma_cleanup(struct bwn_dma_ring *dr)
3179 {
3180 
3181 	if (dr->dr_tx) {
3182 		bwn_dma_tx_reset(dr->dr_mac, dr->dr_base, dr->dr_type);
3183 		if (dr->dr_type == BWN_DMA_64BIT) {
3184 			BWN_DMA_WRITE(dr, BWN_DMA64_TXRINGLO, 0);
3185 			BWN_DMA_WRITE(dr, BWN_DMA64_TXRINGHI, 0);
3186 		} else
3187 			BWN_DMA_WRITE(dr, BWN_DMA32_TXRING, 0);
3188 	} else {
3189 		bwn_dma_rx_reset(dr->dr_mac, dr->dr_base, dr->dr_type);
3190 		if (dr->dr_type == BWN_DMA_64BIT) {
3191 			BWN_DMA_WRITE(dr, BWN_DMA64_RXRINGLO, 0);
3192 			BWN_DMA_WRITE(dr, BWN_DMA64_RXRINGHI, 0);
3193 		} else
3194 			BWN_DMA_WRITE(dr, BWN_DMA32_RXRING, 0);
3195 	}
3196 }
3197 
3198 static void
3199 bwn_dma_free_descbufs(struct bwn_dma_ring *dr)
3200 {
3201 	struct bwn_dmadesc_generic *desc;
3202 	struct bwn_dmadesc_meta *meta;
3203 	struct bwn_mac *mac = dr->dr_mac;
3204 	struct bwn_dma *dma = &mac->mac_method.dma;
3205 	struct bwn_softc *sc = mac->mac_sc;
3206 	int i;
3207 
3208 	if (!dr->dr_usedslot)
3209 		return;
3210 	for (i = 0; i < dr->dr_numslots; i++) {
3211 		dr->getdesc(dr, i, &desc, &meta);
3212 
3213 		if (meta->mt_m == NULL) {
3214 			if (!dr->dr_tx)
3215 				device_printf(sc->sc_dev, "%s: not TX?\n",
3216 				    __func__);
3217 			continue;
3218 		}
3219 		if (dr->dr_tx) {
3220 			if (meta->mt_txtype == BWN_DMADESC_METATYPE_HEADER)
3221 				bus_dmamap_unload(dr->dr_txring_dtag,
3222 				    meta->mt_dmap);
3223 			else if (meta->mt_txtype == BWN_DMADESC_METATYPE_BODY)
3224 				bus_dmamap_unload(dma->txbuf_dtag,
3225 				    meta->mt_dmap);
3226 		} else
3227 			bus_dmamap_unload(dma->rxbuf_dtag, meta->mt_dmap);
3228 		bwn_dma_free_descbuf(dr, meta);
3229 	}
3230 }
3231 
3232 static int
3233 bwn_dma_tx_reset(struct bwn_mac *mac, uint16_t base,
3234     int type)
3235 {
3236 	struct bwn_softc *sc = mac->mac_sc;
3237 	uint32_t value;
3238 	int i;
3239 	uint16_t offset;
3240 
3241 	for (i = 0; i < 10; i++) {
3242 		offset = (type == BWN_DMA_64BIT) ? BWN_DMA64_TXSTATUS :
3243 		    BWN_DMA32_TXSTATUS;
3244 		value = BWN_READ_4(mac, base + offset);
3245 		if (type == BWN_DMA_64BIT) {
3246 			value &= BWN_DMA64_TXSTAT;
3247 			if (value == BWN_DMA64_TXSTAT_DISABLED ||
3248 			    value == BWN_DMA64_TXSTAT_IDLEWAIT ||
3249 			    value == BWN_DMA64_TXSTAT_STOPPED)
3250 				break;
3251 		} else {
3252 			value &= BWN_DMA32_TXSTATE;
3253 			if (value == BWN_DMA32_TXSTAT_DISABLED ||
3254 			    value == BWN_DMA32_TXSTAT_IDLEWAIT ||
3255 			    value == BWN_DMA32_TXSTAT_STOPPED)
3256 				break;
3257 		}
3258 		DELAY(1000);
3259 	}
3260 	offset = (type == BWN_DMA_64BIT) ? BWN_DMA64_TXCTL : BWN_DMA32_TXCTL;
3261 	BWN_WRITE_4(mac, base + offset, 0);
3262 	for (i = 0; i < 10; i++) {
3263 		offset = (type == BWN_DMA_64BIT) ? BWN_DMA64_TXSTATUS :
3264 						   BWN_DMA32_TXSTATUS;
3265 		value = BWN_READ_4(mac, base + offset);
3266 		if (type == BWN_DMA_64BIT) {
3267 			value &= BWN_DMA64_TXSTAT;
3268 			if (value == BWN_DMA64_TXSTAT_DISABLED) {
3269 				i = -1;
3270 				break;
3271 			}
3272 		} else {
3273 			value &= BWN_DMA32_TXSTATE;
3274 			if (value == BWN_DMA32_TXSTAT_DISABLED) {
3275 				i = -1;
3276 				break;
3277 			}
3278 		}
3279 		DELAY(1000);
3280 	}
3281 	if (i != -1) {
3282 		device_printf(sc->sc_dev, "%s: timed out\n", __func__);
3283 		return (ENODEV);
3284 	}
3285 	DELAY(1000);
3286 
3287 	return (0);
3288 }
3289 
3290 static int
3291 bwn_dma_rx_reset(struct bwn_mac *mac, uint16_t base,
3292     int type)
3293 {
3294 	struct bwn_softc *sc = mac->mac_sc;
3295 	uint32_t value;
3296 	int i;
3297 	uint16_t offset;
3298 
3299 	offset = (type == BWN_DMA_64BIT) ? BWN_DMA64_RXCTL : BWN_DMA32_RXCTL;
3300 	BWN_WRITE_4(mac, base + offset, 0);
3301 	for (i = 0; i < 10; i++) {
3302 		offset = (type == BWN_DMA_64BIT) ? BWN_DMA64_RXSTATUS :
3303 		    BWN_DMA32_RXSTATUS;
3304 		value = BWN_READ_4(mac, base + offset);
3305 		if (type == BWN_DMA_64BIT) {
3306 			value &= BWN_DMA64_RXSTAT;
3307 			if (value == BWN_DMA64_RXSTAT_DISABLED) {
3308 				i = -1;
3309 				break;
3310 			}
3311 		} else {
3312 			value &= BWN_DMA32_RXSTATE;
3313 			if (value == BWN_DMA32_RXSTAT_DISABLED) {
3314 				i = -1;
3315 				break;
3316 			}
3317 		}
3318 		DELAY(1000);
3319 	}
3320 	if (i != -1) {
3321 		device_printf(sc->sc_dev, "%s: timed out\n", __func__);
3322 		return (ENODEV);
3323 	}
3324 
3325 	return (0);
3326 }
3327 
3328 static void
3329 bwn_dma_free_descbuf(struct bwn_dma_ring *dr,
3330     struct bwn_dmadesc_meta *meta)
3331 {
3332 
3333 	if (meta->mt_m != NULL) {
3334 		m_freem(meta->mt_m);
3335 		meta->mt_m = NULL;
3336 	}
3337 	if (meta->mt_ni != NULL) {
3338 		ieee80211_free_node(meta->mt_ni);
3339 		meta->mt_ni = NULL;
3340 	}
3341 }
3342 
3343 static void
3344 bwn_dma_set_redzone(struct bwn_dma_ring *dr, struct mbuf *m)
3345 {
3346 	struct bwn_rxhdr4 *rxhdr;
3347 	unsigned char *frame;
3348 
3349 	rxhdr = mtod(m, struct bwn_rxhdr4 *);
3350 	rxhdr->frame_len = 0;
3351 
3352 	KASSERT(dr->dr_rx_bufsize >= dr->dr_frameoffset +
3353 	    sizeof(struct bwn_plcp6) + 2,
3354 	    ("%s:%d: fail", __func__, __LINE__));
3355 	frame = mtod(m, char *) + dr->dr_frameoffset;
3356 	memset(frame, 0xff, sizeof(struct bwn_plcp6) + 2 /* padding */);
3357 }
3358 
3359 static uint8_t
3360 bwn_dma_check_redzone(struct bwn_dma_ring *dr, struct mbuf *m)
3361 {
3362 	unsigned char *f = mtod(m, char *) + dr->dr_frameoffset;
3363 
3364 	return ((f[0] & f[1] & f[2] & f[3] & f[4] & f[5] & f[6] & f[7])
3365 	    == 0xff);
3366 }
3367 
3368 static void
3369 bwn_wme_init(struct bwn_mac *mac)
3370 {
3371 
3372 	bwn_wme_load(mac);
3373 
3374 	/* enable WME support. */
3375 	bwn_hf_write(mac, bwn_hf_read(mac) | BWN_HF_EDCF);
3376 	BWN_WRITE_2(mac, BWN_IFSCTL, BWN_READ_2(mac, BWN_IFSCTL) |
3377 	    BWN_IFSCTL_USE_EDCF);
3378 }
3379 
3380 static void
3381 bwn_spu_setdelay(struct bwn_mac *mac, int idle)
3382 {
3383 	struct bwn_softc *sc = mac->mac_sc;
3384 	struct ieee80211com *ic = &sc->sc_ic;
3385 	uint16_t delay;	/* microsec */
3386 
3387 	delay = (mac->mac_phy.type == BWN_PHYTYPE_A) ? 3700 : 1050;
3388 	if (ic->ic_opmode == IEEE80211_M_IBSS || idle)
3389 		delay = 500;
3390 	if ((mac->mac_phy.rf_ver == 0x2050) && (mac->mac_phy.rf_rev == 8))
3391 		delay = max(delay, (uint16_t)2400);
3392 
3393 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_SPU_WAKEUP, delay);
3394 }
3395 
3396 static void
3397 bwn_bt_enable(struct bwn_mac *mac)
3398 {
3399 	struct bwn_softc *sc = mac->mac_sc;
3400 	uint64_t hf;
3401 
3402 	if (bwn_bluetooth == 0)
3403 		return;
3404 	if ((siba_sprom_get_bf_lo(sc->sc_dev) & BWN_BFL_BTCOEXIST) == 0)
3405 		return;
3406 	if (mac->mac_phy.type != BWN_PHYTYPE_B && !mac->mac_phy.gmode)
3407 		return;
3408 
3409 	hf = bwn_hf_read(mac);
3410 	if (siba_sprom_get_bf_lo(sc->sc_dev) & BWN_BFL_BTCMOD)
3411 		hf |= BWN_HF_BT_COEXISTALT;
3412 	else
3413 		hf |= BWN_HF_BT_COEXIST;
3414 	bwn_hf_write(mac, hf);
3415 }
3416 
3417 static void
3418 bwn_set_macaddr(struct bwn_mac *mac)
3419 {
3420 
3421 	bwn_mac_write_bssid(mac);
3422 	bwn_mac_setfilter(mac, BWN_MACFILTER_SELF,
3423 	    mac->mac_sc->sc_ic.ic_macaddr);
3424 }
3425 
3426 static void
3427 bwn_clear_keys(struct bwn_mac *mac)
3428 {
3429 	int i;
3430 
3431 	for (i = 0; i < mac->mac_max_nr_keys; i++) {
3432 		KASSERT(i >= 0 && i < mac->mac_max_nr_keys,
3433 		    ("%s:%d: fail", __func__, __LINE__));
3434 
3435 		bwn_key_dowrite(mac, i, BWN_SEC_ALGO_NONE,
3436 		    NULL, BWN_SEC_KEYSIZE, NULL);
3437 		if ((i <= 3) && !BWN_SEC_NEWAPI(mac)) {
3438 			bwn_key_dowrite(mac, i + 4, BWN_SEC_ALGO_NONE,
3439 			    NULL, BWN_SEC_KEYSIZE, NULL);
3440 		}
3441 		mac->mac_key[i].keyconf = NULL;
3442 	}
3443 }
3444 
3445 static void
3446 bwn_crypt_init(struct bwn_mac *mac)
3447 {
3448 	struct bwn_softc *sc = mac->mac_sc;
3449 
3450 	mac->mac_max_nr_keys = (siba_get_revid(sc->sc_dev) >= 5) ? 58 : 20;
3451 	KASSERT(mac->mac_max_nr_keys <= N(mac->mac_key),
3452 	    ("%s:%d: fail", __func__, __LINE__));
3453 	mac->mac_ktp = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_KEY_TABLEP);
3454 	mac->mac_ktp *= 2;
3455 	if (siba_get_revid(sc->sc_dev) >= 5)
3456 		BWN_WRITE_2(mac, BWN_RCMTA_COUNT, mac->mac_max_nr_keys - 8);
3457 	bwn_clear_keys(mac);
3458 }
3459 
3460 static void
3461 bwn_chip_exit(struct bwn_mac *mac)
3462 {
3463 	struct bwn_softc *sc = mac->mac_sc;
3464 
3465 	bwn_phy_exit(mac);
3466 	siba_gpio_set(sc->sc_dev, 0);
3467 }
3468 
3469 static int
3470 bwn_fw_fillinfo(struct bwn_mac *mac)
3471 {
3472 	int error;
3473 
3474 	error = bwn_fw_gets(mac, BWN_FWTYPE_DEFAULT);
3475 	if (error == 0)
3476 		return (0);
3477 	error = bwn_fw_gets(mac, BWN_FWTYPE_OPENSOURCE);
3478 	if (error == 0)
3479 		return (0);
3480 	return (error);
3481 }
3482 
3483 static int
3484 bwn_gpio_init(struct bwn_mac *mac)
3485 {
3486 	struct bwn_softc *sc = mac->mac_sc;
3487 	uint32_t mask = 0x1f, set = 0xf, value;
3488 
3489 	BWN_WRITE_4(mac, BWN_MACCTL,
3490 	    BWN_READ_4(mac, BWN_MACCTL) & ~BWN_MACCTL_GPOUT_MASK);
3491 	BWN_WRITE_2(mac, BWN_GPIO_MASK,
3492 	    BWN_READ_2(mac, BWN_GPIO_MASK) | 0x000f);
3493 
3494 	if (siba_get_chipid(sc->sc_dev) == 0x4301) {
3495 		mask |= 0x0060;
3496 		set |= 0x0060;
3497 	}
3498 	if (siba_sprom_get_bf_lo(sc->sc_dev) & BWN_BFL_PACTRL) {
3499 		BWN_WRITE_2(mac, BWN_GPIO_MASK,
3500 		    BWN_READ_2(mac, BWN_GPIO_MASK) | 0x0200);
3501 		mask |= 0x0200;
3502 		set |= 0x0200;
3503 	}
3504 	if (siba_get_revid(sc->sc_dev) >= 2)
3505 		mask |= 0x0010;
3506 
3507 	value = siba_gpio_get(sc->sc_dev);
3508 	if (value == -1)
3509 		return (0);
3510 	siba_gpio_set(sc->sc_dev, (value & mask) | set);
3511 
3512 	return (0);
3513 }
3514 
3515 static int
3516 bwn_fw_loadinitvals(struct bwn_mac *mac)
3517 {
3518 #define	GETFWOFFSET(fwp, offset)				\
3519 	((const struct bwn_fwinitvals *)((const char *)fwp.fw->data + offset))
3520 	const size_t hdr_len = sizeof(struct bwn_fwhdr);
3521 	const struct bwn_fwhdr *hdr;
3522 	struct bwn_fw *fw = &mac->mac_fw;
3523 	int error;
3524 
3525 	hdr = (const struct bwn_fwhdr *)(fw->initvals.fw->data);
3526 	error = bwn_fwinitvals_write(mac, GETFWOFFSET(fw->initvals, hdr_len),
3527 	    be32toh(hdr->size), fw->initvals.fw->datasize - hdr_len);
3528 	if (error)
3529 		return (error);
3530 	if (fw->initvals_band.fw) {
3531 		hdr = (const struct bwn_fwhdr *)(fw->initvals_band.fw->data);
3532 		error = bwn_fwinitvals_write(mac,
3533 		    GETFWOFFSET(fw->initvals_band, hdr_len),
3534 		    be32toh(hdr->size),
3535 		    fw->initvals_band.fw->datasize - hdr_len);
3536 	}
3537 	return (error);
3538 #undef GETFWOFFSET
3539 }
3540 
3541 static int
3542 bwn_phy_init(struct bwn_mac *mac)
3543 {
3544 	struct bwn_softc *sc = mac->mac_sc;
3545 	int error;
3546 
3547 	mac->mac_phy.chan = mac->mac_phy.get_default_chan(mac);
3548 	mac->mac_phy.rf_onoff(mac, 1);
3549 	error = mac->mac_phy.init(mac);
3550 	if (error) {
3551 		device_printf(sc->sc_dev, "PHY init failed\n");
3552 		goto fail0;
3553 	}
3554 	error = bwn_switch_channel(mac,
3555 	    mac->mac_phy.get_default_chan(mac));
3556 	if (error) {
3557 		device_printf(sc->sc_dev,
3558 		    "failed to switch default channel\n");
3559 		goto fail1;
3560 	}
3561 	return (0);
3562 fail1:
3563 	if (mac->mac_phy.exit)
3564 		mac->mac_phy.exit(mac);
3565 fail0:
3566 	mac->mac_phy.rf_onoff(mac, 0);
3567 
3568 	return (error);
3569 }
3570 
3571 static void
3572 bwn_set_txantenna(struct bwn_mac *mac, int antenna)
3573 {
3574 	uint16_t ant;
3575 	uint16_t tmp;
3576 
3577 	ant = bwn_ant2phy(antenna);
3578 
3579 	/* For ACK/CTS */
3580 	tmp = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_ACKCTS_PHYCTL);
3581 	tmp = (tmp & ~BWN_TX_PHY_ANT) | ant;
3582 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_ACKCTS_PHYCTL, tmp);
3583 	/* For Probe Resposes */
3584 	tmp = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_PROBE_RESP_PHYCTL);
3585 	tmp = (tmp & ~BWN_TX_PHY_ANT) | ant;
3586 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_PROBE_RESP_PHYCTL, tmp);
3587 }
3588 
3589 static void
3590 bwn_set_opmode(struct bwn_mac *mac)
3591 {
3592 	struct bwn_softc *sc = mac->mac_sc;
3593 	struct ieee80211com *ic = &sc->sc_ic;
3594 	uint32_t ctl;
3595 	uint16_t cfp_pretbtt;
3596 
3597 	ctl = BWN_READ_4(mac, BWN_MACCTL);
3598 	ctl &= ~(BWN_MACCTL_HOSTAP | BWN_MACCTL_PASS_CTL |
3599 	    BWN_MACCTL_PASS_BADPLCP | BWN_MACCTL_PASS_BADFCS |
3600 	    BWN_MACCTL_PROMISC | BWN_MACCTL_BEACON_PROMISC);
3601 	ctl |= BWN_MACCTL_STA;
3602 
3603 	if (ic->ic_opmode == IEEE80211_M_HOSTAP ||
3604 	    ic->ic_opmode == IEEE80211_M_MBSS)
3605 		ctl |= BWN_MACCTL_HOSTAP;
3606 	else if (ic->ic_opmode == IEEE80211_M_IBSS)
3607 		ctl &= ~BWN_MACCTL_STA;
3608 	ctl |= sc->sc_filters;
3609 
3610 	if (siba_get_revid(sc->sc_dev) <= 4)
3611 		ctl |= BWN_MACCTL_PROMISC;
3612 
3613 	BWN_WRITE_4(mac, BWN_MACCTL, ctl);
3614 
3615 	cfp_pretbtt = 2;
3616 	if ((ctl & BWN_MACCTL_STA) && !(ctl & BWN_MACCTL_HOSTAP)) {
3617 		if (siba_get_chipid(sc->sc_dev) == 0x4306 &&
3618 		    siba_get_chiprev(sc->sc_dev) == 3)
3619 			cfp_pretbtt = 100;
3620 		else
3621 			cfp_pretbtt = 50;
3622 	}
3623 	BWN_WRITE_2(mac, 0x612, cfp_pretbtt);
3624 }
3625 
3626 static int
3627 bwn_dma_gettype(struct bwn_mac *mac)
3628 {
3629 	uint32_t tmp;
3630 	uint16_t base;
3631 
3632 	tmp = BWN_READ_4(mac, SIBA_TGSHIGH);
3633 	if (tmp & SIBA_TGSHIGH_DMA64)
3634 		return (BWN_DMA_64BIT);
3635 	base = bwn_dma_base(0, 0);
3636 	BWN_WRITE_4(mac, base + BWN_DMA32_TXCTL, BWN_DMA32_TXADDREXT_MASK);
3637 	tmp = BWN_READ_4(mac, base + BWN_DMA32_TXCTL);
3638 	if (tmp & BWN_DMA32_TXADDREXT_MASK)
3639 		return (BWN_DMA_32BIT);
3640 
3641 	return (BWN_DMA_30BIT);
3642 }
3643 
3644 static void
3645 bwn_dma_ring_addr(void *arg, bus_dma_segment_t *seg, int nseg, int error)
3646 {
3647 	if (!error) {
3648 		KASSERT(nseg == 1, ("too many segments(%d)\n", nseg));
3649 		*((bus_addr_t *)arg) = seg->ds_addr;
3650 	}
3651 }
3652 
3653 void
3654 bwn_dummy_transmission(struct bwn_mac *mac, int ofdm, int paon)
3655 {
3656 	struct bwn_phy *phy = &mac->mac_phy;
3657 	struct bwn_softc *sc = mac->mac_sc;
3658 	unsigned int i, max_loop;
3659 	uint16_t value;
3660 	uint32_t buffer[5] = {
3661 		0x00000000, 0x00d40000, 0x00000000, 0x01000000, 0x00000000
3662 	};
3663 
3664 	if (ofdm) {
3665 		max_loop = 0x1e;
3666 		buffer[0] = 0x000201cc;
3667 	} else {
3668 		max_loop = 0xfa;
3669 		buffer[0] = 0x000b846e;
3670 	}
3671 
3672 	BWN_ASSERT_LOCKED(mac->mac_sc);
3673 
3674 	for (i = 0; i < 5; i++)
3675 		bwn_ram_write(mac, i * 4, buffer[i]);
3676 
3677 	BWN_WRITE_2(mac, 0x0568, 0x0000);
3678 	BWN_WRITE_2(mac, 0x07c0,
3679 	    (siba_get_revid(sc->sc_dev) < 11) ? 0x0000 : 0x0100);
3680 
3681 	value = (ofdm ? 0x41 : 0x40);
3682 	BWN_WRITE_2(mac, 0x050c, value);
3683 
3684 	if (phy->type == BWN_PHYTYPE_N || phy->type == BWN_PHYTYPE_LP ||
3685 	    phy->type == BWN_PHYTYPE_LCN)
3686 		BWN_WRITE_2(mac, 0x0514, 0x1a02);
3687 	BWN_WRITE_2(mac, 0x0508, 0x0000);
3688 	BWN_WRITE_2(mac, 0x050a, 0x0000);
3689 	BWN_WRITE_2(mac, 0x054c, 0x0000);
3690 	BWN_WRITE_2(mac, 0x056a, 0x0014);
3691 	BWN_WRITE_2(mac, 0x0568, 0x0826);
3692 	BWN_WRITE_2(mac, 0x0500, 0x0000);
3693 
3694 	/* XXX TODO: n phy pa override? */
3695 
3696 	switch (phy->type) {
3697 	case BWN_PHYTYPE_N:
3698 	case BWN_PHYTYPE_LCN:
3699 		BWN_WRITE_2(mac, 0x0502, 0x00d0);
3700 		break;
3701 	case BWN_PHYTYPE_LP:
3702 		BWN_WRITE_2(mac, 0x0502, 0x0050);
3703 		break;
3704 	default:
3705 		BWN_WRITE_2(mac, 0x0502, 0x0030);
3706 		break;
3707 	}
3708 
3709 	/* flush */
3710 	BWN_READ_2(mac, 0x0502);
3711 
3712 	if (phy->rf_ver == 0x2050 && phy->rf_rev <= 0x5)
3713 		BWN_RF_WRITE(mac, 0x0051, 0x0017);
3714 	for (i = 0x00; i < max_loop; i++) {
3715 		value = BWN_READ_2(mac, 0x050e);
3716 		if (value & 0x0080)
3717 			break;
3718 		DELAY(10);
3719 	}
3720 	for (i = 0x00; i < 0x0a; i++) {
3721 		value = BWN_READ_2(mac, 0x050e);
3722 		if (value & 0x0400)
3723 			break;
3724 		DELAY(10);
3725 	}
3726 	for (i = 0x00; i < 0x19; i++) {
3727 		value = BWN_READ_2(mac, 0x0690);
3728 		if (!(value & 0x0100))
3729 			break;
3730 		DELAY(10);
3731 	}
3732 	if (phy->rf_ver == 0x2050 && phy->rf_rev <= 0x5)
3733 		BWN_RF_WRITE(mac, 0x0051, 0x0037);
3734 }
3735 
3736 void
3737 bwn_ram_write(struct bwn_mac *mac, uint16_t offset, uint32_t val)
3738 {
3739 	uint32_t macctl;
3740 
3741 	KASSERT(offset % 4 == 0, ("%s:%d: fail", __func__, __LINE__));
3742 
3743 	macctl = BWN_READ_4(mac, BWN_MACCTL);
3744 	if (macctl & BWN_MACCTL_BIGENDIAN)
3745 		printf("TODO: need swap\n");
3746 
3747 	BWN_WRITE_4(mac, BWN_RAM_CONTROL, offset);
3748 	BWN_BARRIER(mac, BUS_SPACE_BARRIER_WRITE);
3749 	BWN_WRITE_4(mac, BWN_RAM_DATA, val);
3750 }
3751 
3752 void
3753 bwn_mac_suspend(struct bwn_mac *mac)
3754 {
3755 	struct bwn_softc *sc = mac->mac_sc;
3756 	int i;
3757 	uint32_t tmp;
3758 
3759 	KASSERT(mac->mac_suspended >= 0,
3760 	    ("%s:%d: fail", __func__, __LINE__));
3761 
3762 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: suspended=%d\n",
3763 	    __func__, mac->mac_suspended);
3764 
3765 	if (mac->mac_suspended == 0) {
3766 		bwn_psctl(mac, BWN_PS_AWAKE);
3767 		BWN_WRITE_4(mac, BWN_MACCTL,
3768 			    BWN_READ_4(mac, BWN_MACCTL)
3769 			    & ~BWN_MACCTL_ON);
3770 		BWN_READ_4(mac, BWN_MACCTL);
3771 		for (i = 35; i; i--) {
3772 			tmp = BWN_READ_4(mac, BWN_INTR_REASON);
3773 			if (tmp & BWN_INTR_MAC_SUSPENDED)
3774 				goto out;
3775 			DELAY(10);
3776 		}
3777 		for (i = 40; i; i--) {
3778 			tmp = BWN_READ_4(mac, BWN_INTR_REASON);
3779 			if (tmp & BWN_INTR_MAC_SUSPENDED)
3780 				goto out;
3781 			DELAY(1000);
3782 		}
3783 		device_printf(sc->sc_dev, "MAC suspend failed\n");
3784 	}
3785 out:
3786 	mac->mac_suspended++;
3787 }
3788 
3789 void
3790 bwn_mac_enable(struct bwn_mac *mac)
3791 {
3792 	struct bwn_softc *sc = mac->mac_sc;
3793 	uint16_t state;
3794 
3795 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: suspended=%d\n",
3796 	    __func__, mac->mac_suspended);
3797 
3798 	state = bwn_shm_read_2(mac, BWN_SHARED,
3799 	    BWN_SHARED_UCODESTAT);
3800 	if (state != BWN_SHARED_UCODESTAT_SUSPEND &&
3801 	    state != BWN_SHARED_UCODESTAT_SLEEP) {
3802 		DPRINTF(sc, BWN_DEBUG_FW,
3803 		    "%s: warn: firmware state (%d)\n",
3804 		    __func__, state);
3805 	}
3806 
3807 	mac->mac_suspended--;
3808 	KASSERT(mac->mac_suspended >= 0,
3809 	    ("%s:%d: fail", __func__, __LINE__));
3810 	if (mac->mac_suspended == 0) {
3811 		BWN_WRITE_4(mac, BWN_MACCTL,
3812 		    BWN_READ_4(mac, BWN_MACCTL) | BWN_MACCTL_ON);
3813 		BWN_WRITE_4(mac, BWN_INTR_REASON, BWN_INTR_MAC_SUSPENDED);
3814 		BWN_READ_4(mac, BWN_MACCTL);
3815 		BWN_READ_4(mac, BWN_INTR_REASON);
3816 		bwn_psctl(mac, 0);
3817 	}
3818 }
3819 
3820 void
3821 bwn_psctl(struct bwn_mac *mac, uint32_t flags)
3822 {
3823 	struct bwn_softc *sc = mac->mac_sc;
3824 	int i;
3825 	uint16_t ucstat;
3826 
3827 	KASSERT(!((flags & BWN_PS_ON) && (flags & BWN_PS_OFF)),
3828 	    ("%s:%d: fail", __func__, __LINE__));
3829 	KASSERT(!((flags & BWN_PS_AWAKE) && (flags & BWN_PS_ASLEEP)),
3830 	    ("%s:%d: fail", __func__, __LINE__));
3831 
3832 	/* XXX forcibly awake and hwps-off */
3833 
3834 	BWN_WRITE_4(mac, BWN_MACCTL,
3835 	    (BWN_READ_4(mac, BWN_MACCTL) | BWN_MACCTL_AWAKE) &
3836 	    ~BWN_MACCTL_HWPS);
3837 	BWN_READ_4(mac, BWN_MACCTL);
3838 	if (siba_get_revid(sc->sc_dev) >= 5) {
3839 		for (i = 0; i < 100; i++) {
3840 			ucstat = bwn_shm_read_2(mac, BWN_SHARED,
3841 			    BWN_SHARED_UCODESTAT);
3842 			if (ucstat != BWN_SHARED_UCODESTAT_SLEEP)
3843 				break;
3844 			DELAY(10);
3845 		}
3846 	}
3847 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: ucstat=%d\n", __func__,
3848 	    ucstat);
3849 }
3850 
3851 static int
3852 bwn_fw_gets(struct bwn_mac *mac, enum bwn_fwtype type)
3853 {
3854 	struct bwn_softc *sc = mac->mac_sc;
3855 	struct bwn_fw *fw = &mac->mac_fw;
3856 	const uint8_t rev = siba_get_revid(sc->sc_dev);
3857 	const char *filename;
3858 	uint32_t high;
3859 	int error;
3860 
3861 	/* microcode */
3862 	filename = NULL;
3863 	switch (rev) {
3864 	case 42:
3865 		if (mac->mac_phy.type == BWN_PHYTYPE_AC)
3866 			filename = "ucode42";
3867 		break;
3868 	case 40:
3869 		if (mac->mac_phy.type == BWN_PHYTYPE_AC)
3870 			filename = "ucode40";
3871 		break;
3872 	case 33:
3873 		if (mac->mac_phy.type == BWN_PHYTYPE_LCN40)
3874 			filename = "ucode33_lcn40";
3875 		break;
3876 	case 30:
3877 		if (mac->mac_phy.type == BWN_PHYTYPE_N)
3878 			filename = "ucode30_mimo";
3879 		break;
3880 	case 29:
3881 		if (mac->mac_phy.type == BWN_PHYTYPE_HT)
3882 			filename = "ucode29_mimo";
3883 		break;
3884 	case 26:
3885 		if (mac->mac_phy.type == BWN_PHYTYPE_HT)
3886 			filename = "ucode26_mimo";
3887 		break;
3888 	case 28:
3889 	case 25:
3890 		if (mac->mac_phy.type == BWN_PHYTYPE_N)
3891 			filename = "ucode25_mimo";
3892 		else if (mac->mac_phy.type == BWN_PHYTYPE_LCN)
3893 			filename = "ucode25_lcn";
3894 		break;
3895 	case 24:
3896 		if (mac->mac_phy.type == BWN_PHYTYPE_LCN)
3897 			filename = "ucode24_lcn";
3898 		break;
3899 	case 23:
3900 		if (mac->mac_phy.type == BWN_PHYTYPE_N)
3901 			filename = "ucode16_mimo";
3902 		break;
3903 	case 16:
3904 	case 17:
3905 	case 18:
3906 	case 19:
3907 		if (mac->mac_phy.type == BWN_PHYTYPE_N)
3908 			filename = "ucode16_mimo";
3909 		else if (mac->mac_phy.type == BWN_PHYTYPE_LP)
3910 			filename = "ucode16_lp";
3911 		break;
3912 	case 15:
3913 		filename = "ucode15";
3914 		break;
3915 	case 14:
3916 		filename = "ucode14";
3917 		break;
3918 	case 13:
3919 		filename = "ucode13";
3920 		break;
3921 	case 12:
3922 	case 11:
3923 		filename = "ucode11";
3924 		break;
3925 	case 10:
3926 	case 9:
3927 	case 8:
3928 	case 7:
3929 	case 6:
3930 	case 5:
3931 		filename = "ucode5";
3932 		break;
3933 	default:
3934 		device_printf(sc->sc_dev, "no ucode for rev %d\n", rev);
3935 		bwn_release_firmware(mac);
3936 		return (EOPNOTSUPP);
3937 	}
3938 
3939 	device_printf(sc->sc_dev, "ucode fw: %s\n", filename);
3940 	error = bwn_fw_get(mac, type, filename, &fw->ucode);
3941 	if (error) {
3942 		bwn_release_firmware(mac);
3943 		return (error);
3944 	}
3945 
3946 	/* PCM */
3947 	KASSERT(fw->no_pcmfile == 0, ("%s:%d fail", __func__, __LINE__));
3948 	if (rev >= 5 && rev <= 10) {
3949 		error = bwn_fw_get(mac, type, "pcm5", &fw->pcm);
3950 		if (error == ENOENT)
3951 			fw->no_pcmfile = 1;
3952 		else if (error) {
3953 			bwn_release_firmware(mac);
3954 			return (error);
3955 		}
3956 	} else if (rev < 11) {
3957 		device_printf(sc->sc_dev, "no PCM for rev %d\n", rev);
3958 		bwn_release_firmware(mac);
3959 		return (EOPNOTSUPP);
3960 	}
3961 
3962 	/* initvals */
3963 	high = siba_read_4(sc->sc_dev, SIBA_TGSHIGH);
3964 	switch (mac->mac_phy.type) {
3965 	case BWN_PHYTYPE_A:
3966 		if (rev < 5 || rev > 10)
3967 			goto fail1;
3968 		if (high & BWN_TGSHIGH_HAVE_2GHZ)
3969 			filename = "a0g1initvals5";
3970 		else
3971 			filename = "a0g0initvals5";
3972 		break;
3973 	case BWN_PHYTYPE_G:
3974 		if (rev >= 5 && rev <= 10)
3975 			filename = "b0g0initvals5";
3976 		else if (rev >= 13)
3977 			filename = "b0g0initvals13";
3978 		else
3979 			goto fail1;
3980 		break;
3981 	case BWN_PHYTYPE_LP:
3982 		if (rev == 13)
3983 			filename = "lp0initvals13";
3984 		else if (rev == 14)
3985 			filename = "lp0initvals14";
3986 		else if (rev >= 15)
3987 			filename = "lp0initvals15";
3988 		else
3989 			goto fail1;
3990 		break;
3991 	case BWN_PHYTYPE_N:
3992 		if (rev == 30)
3993 			filename = "n16initvals30";
3994 		else if (rev == 28 || rev == 25)
3995 			filename = "n0initvals25";
3996 		else if (rev == 24)
3997 			filename = "n0initvals24";
3998 		else if (rev == 23)
3999 			filename = "n0initvals16";
4000 		else if (rev >= 16 && rev <= 18)
4001 			filename = "n0initvals16";
4002 		else if (rev >= 11 && rev <= 12)
4003 			filename = "n0initvals11";
4004 		else
4005 			goto fail1;
4006 		break;
4007 	default:
4008 		goto fail1;
4009 	}
4010 	error = bwn_fw_get(mac, type, filename, &fw->initvals);
4011 	if (error) {
4012 		bwn_release_firmware(mac);
4013 		return (error);
4014 	}
4015 
4016 	/* bandswitch initvals */
4017 	switch (mac->mac_phy.type) {
4018 	case BWN_PHYTYPE_A:
4019 		if (rev >= 5 && rev <= 10) {
4020 			if (high & BWN_TGSHIGH_HAVE_2GHZ)
4021 				filename = "a0g1bsinitvals5";
4022 			else
4023 				filename = "a0g0bsinitvals5";
4024 		} else if (rev >= 11)
4025 			filename = NULL;
4026 		else
4027 			goto fail1;
4028 		break;
4029 	case BWN_PHYTYPE_G:
4030 		if (rev >= 5 && rev <= 10)
4031 			filename = "b0g0bsinitvals5";
4032 		else if (rev >= 11)
4033 			filename = NULL;
4034 		else
4035 			goto fail1;
4036 		break;
4037 	case BWN_PHYTYPE_LP:
4038 		if (rev == 13)
4039 			filename = "lp0bsinitvals13";
4040 		else if (rev == 14)
4041 			filename = "lp0bsinitvals14";
4042 		else if (rev >= 15)
4043 			filename = "lp0bsinitvals15";
4044 		else
4045 			goto fail1;
4046 		break;
4047 	case BWN_PHYTYPE_N:
4048 		if (rev == 30)
4049 			filename = "n16bsinitvals30";
4050 		else if (rev == 28 || rev == 25)
4051 			filename = "n0bsinitvals25";
4052 		else if (rev == 24)
4053 			filename = "n0bsinitvals24";
4054 		else if (rev == 23)
4055 			filename = "n0bsinitvals16";
4056 		else if (rev >= 16 && rev <= 18)
4057 			filename = "n0bsinitvals16";
4058 		else if (rev >= 11 && rev <= 12)
4059 			filename = "n0bsinitvals11";
4060 		else
4061 			goto fail1;
4062 		break;
4063 	default:
4064 		device_printf(sc->sc_dev, "unknown phy (%d)\n",
4065 		    mac->mac_phy.type);
4066 		goto fail1;
4067 	}
4068 	error = bwn_fw_get(mac, type, filename, &fw->initvals_band);
4069 	if (error) {
4070 		bwn_release_firmware(mac);
4071 		return (error);
4072 	}
4073 	return (0);
4074 fail1:
4075 	device_printf(sc->sc_dev, "no INITVALS for rev %d, phy.type %d\n",
4076 	    rev, mac->mac_phy.type);
4077 	bwn_release_firmware(mac);
4078 	return (EOPNOTSUPP);
4079 }
4080 
4081 static int
4082 bwn_fw_get(struct bwn_mac *mac, enum bwn_fwtype type,
4083     const char *name, struct bwn_fwfile *bfw)
4084 {
4085 	const struct bwn_fwhdr *hdr;
4086 	struct bwn_softc *sc = mac->mac_sc;
4087 	const struct firmware *fw;
4088 	char namebuf[64];
4089 
4090 	if (name == NULL) {
4091 		bwn_do_release_fw(bfw);
4092 		return (0);
4093 	}
4094 	if (bfw->filename != NULL) {
4095 		if (bfw->type == type && (strcmp(bfw->filename, name) == 0))
4096 			return (0);
4097 		bwn_do_release_fw(bfw);
4098 	}
4099 
4100 	snprintf(namebuf, sizeof(namebuf), "bwn%s_v4_%s%s",
4101 	    (type == BWN_FWTYPE_OPENSOURCE) ? "-open" : "",
4102 	    (mac->mac_phy.type == BWN_PHYTYPE_LP) ? "lp_" : "", name);
4103 	/* XXX Sleeping on "fwload" with the non-sleepable locks held */
4104 	fw = firmware_get(namebuf);
4105 	if (fw == NULL) {
4106 		device_printf(sc->sc_dev, "the fw file(%s) not found\n",
4107 		    namebuf);
4108 		return (ENOENT);
4109 	}
4110 	if (fw->datasize < sizeof(struct bwn_fwhdr))
4111 		goto fail;
4112 	hdr = (const struct bwn_fwhdr *)(fw->data);
4113 	switch (hdr->type) {
4114 	case BWN_FWTYPE_UCODE:
4115 	case BWN_FWTYPE_PCM:
4116 		if (be32toh(hdr->size) !=
4117 		    (fw->datasize - sizeof(struct bwn_fwhdr)))
4118 			goto fail;
4119 		/* FALLTHROUGH */
4120 	case BWN_FWTYPE_IV:
4121 		if (hdr->ver != 1)
4122 			goto fail;
4123 		break;
4124 	default:
4125 		goto fail;
4126 	}
4127 	bfw->filename = name;
4128 	bfw->fw = fw;
4129 	bfw->type = type;
4130 	return (0);
4131 fail:
4132 	device_printf(sc->sc_dev, "the fw file(%s) format error\n", namebuf);
4133 	if (fw != NULL)
4134 		firmware_put(fw, FIRMWARE_UNLOAD);
4135 	return (EPROTO);
4136 }
4137 
4138 static void
4139 bwn_release_firmware(struct bwn_mac *mac)
4140 {
4141 
4142 	bwn_do_release_fw(&mac->mac_fw.ucode);
4143 	bwn_do_release_fw(&mac->mac_fw.pcm);
4144 	bwn_do_release_fw(&mac->mac_fw.initvals);
4145 	bwn_do_release_fw(&mac->mac_fw.initvals_band);
4146 }
4147 
4148 static void
4149 bwn_do_release_fw(struct bwn_fwfile *bfw)
4150 {
4151 
4152 	if (bfw->fw != NULL)
4153 		firmware_put(bfw->fw, FIRMWARE_UNLOAD);
4154 	bfw->fw = NULL;
4155 	bfw->filename = NULL;
4156 }
4157 
4158 static int
4159 bwn_fw_loaducode(struct bwn_mac *mac)
4160 {
4161 #define	GETFWOFFSET(fwp, offset)	\
4162 	((const uint32_t *)((const char *)fwp.fw->data + offset))
4163 #define	GETFWSIZE(fwp, offset)	\
4164 	((fwp.fw->datasize - offset) / sizeof(uint32_t))
4165 	struct bwn_softc *sc = mac->mac_sc;
4166 	const uint32_t *data;
4167 	unsigned int i;
4168 	uint32_t ctl;
4169 	uint16_t date, fwcaps, time;
4170 	int error = 0;
4171 
4172 	ctl = BWN_READ_4(mac, BWN_MACCTL);
4173 	ctl |= BWN_MACCTL_MCODE_JMP0;
4174 	KASSERT(!(ctl & BWN_MACCTL_MCODE_RUN), ("%s:%d: fail", __func__,
4175 	    __LINE__));
4176 	BWN_WRITE_4(mac, BWN_MACCTL, ctl);
4177 	for (i = 0; i < 64; i++)
4178 		bwn_shm_write_2(mac, BWN_SCRATCH, i, 0);
4179 	for (i = 0; i < 4096; i += 2)
4180 		bwn_shm_write_2(mac, BWN_SHARED, i, 0);
4181 
4182 	data = GETFWOFFSET(mac->mac_fw.ucode, sizeof(struct bwn_fwhdr));
4183 	bwn_shm_ctlword(mac, BWN_UCODE | BWN_SHARED_AUTOINC, 0x0000);
4184 	for (i = 0; i < GETFWSIZE(mac->mac_fw.ucode, sizeof(struct bwn_fwhdr));
4185 	     i++) {
4186 		BWN_WRITE_4(mac, BWN_SHM_DATA, be32toh(data[i]));
4187 		DELAY(10);
4188 	}
4189 
4190 	if (mac->mac_fw.pcm.fw) {
4191 		data = GETFWOFFSET(mac->mac_fw.pcm, sizeof(struct bwn_fwhdr));
4192 		bwn_shm_ctlword(mac, BWN_HW, 0x01ea);
4193 		BWN_WRITE_4(mac, BWN_SHM_DATA, 0x00004000);
4194 		bwn_shm_ctlword(mac, BWN_HW, 0x01eb);
4195 		for (i = 0; i < GETFWSIZE(mac->mac_fw.pcm,
4196 		    sizeof(struct bwn_fwhdr)); i++) {
4197 			BWN_WRITE_4(mac, BWN_SHM_DATA, be32toh(data[i]));
4198 			DELAY(10);
4199 		}
4200 	}
4201 
4202 	BWN_WRITE_4(mac, BWN_INTR_REASON, BWN_INTR_ALL);
4203 	BWN_WRITE_4(mac, BWN_MACCTL,
4204 	    (BWN_READ_4(mac, BWN_MACCTL) & ~BWN_MACCTL_MCODE_JMP0) |
4205 	    BWN_MACCTL_MCODE_RUN);
4206 
4207 	for (i = 0; i < 21; i++) {
4208 		if (BWN_READ_4(mac, BWN_INTR_REASON) == BWN_INTR_MAC_SUSPENDED)
4209 			break;
4210 		if (i >= 20) {
4211 			device_printf(sc->sc_dev, "ucode timeout\n");
4212 			error = ENXIO;
4213 			goto error;
4214 		}
4215 		DELAY(50000);
4216 	}
4217 	BWN_READ_4(mac, BWN_INTR_REASON);
4218 
4219 	mac->mac_fw.rev = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_UCODE_REV);
4220 	if (mac->mac_fw.rev <= 0x128) {
4221 		device_printf(sc->sc_dev, "the firmware is too old\n");
4222 		error = EOPNOTSUPP;
4223 		goto error;
4224 	}
4225 
4226 	/*
4227 	 * Determine firmware header version; needed for TX/RX packet
4228 	 * handling.
4229 	 */
4230 	if (mac->mac_fw.rev >= 598)
4231 		mac->mac_fw.fw_hdr_format = BWN_FW_HDR_598;
4232 	else if (mac->mac_fw.rev >= 410)
4233 		mac->mac_fw.fw_hdr_format = BWN_FW_HDR_410;
4234 	else
4235 		mac->mac_fw.fw_hdr_format = BWN_FW_HDR_351;
4236 
4237 	/*
4238 	 * We don't support rev 598 or later; that requires
4239 	 * another round of changes to the TX/RX descriptor
4240 	 * and status layout.
4241 	 *
4242 	 * So, complain this is the case and exit out, rather
4243 	 * than attaching and then failing.
4244 	 */
4245 #if 0
4246 	if (mac->mac_fw.fw_hdr_format == BWN_FW_HDR_598) {
4247 		device_printf(sc->sc_dev,
4248 		    "firmware is too new (>=598); not supported\n");
4249 		error = EOPNOTSUPP;
4250 		goto error;
4251 	}
4252 #endif
4253 
4254 	mac->mac_fw.patch = bwn_shm_read_2(mac, BWN_SHARED,
4255 	    BWN_SHARED_UCODE_PATCH);
4256 	date = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_UCODE_DATE);
4257 	mac->mac_fw.opensource = (date == 0xffff);
4258 	if (bwn_wme != 0)
4259 		mac->mac_flags |= BWN_MAC_FLAG_WME;
4260 	mac->mac_flags |= BWN_MAC_FLAG_HWCRYPTO;
4261 
4262 	time = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_UCODE_TIME);
4263 	if (mac->mac_fw.opensource == 0) {
4264 		device_printf(sc->sc_dev,
4265 		    "firmware version (rev %u patch %u date %#x time %#x)\n",
4266 		    mac->mac_fw.rev, mac->mac_fw.patch, date, time);
4267 		if (mac->mac_fw.no_pcmfile)
4268 			device_printf(sc->sc_dev,
4269 			    "no HW crypto acceleration due to pcm5\n");
4270 	} else {
4271 		mac->mac_fw.patch = time;
4272 		fwcaps = bwn_fwcaps_read(mac);
4273 		if (!(fwcaps & BWN_FWCAPS_HWCRYPTO) || mac->mac_fw.no_pcmfile) {
4274 			device_printf(sc->sc_dev,
4275 			    "disabling HW crypto acceleration\n");
4276 			mac->mac_flags &= ~BWN_MAC_FLAG_HWCRYPTO;
4277 		}
4278 		if (!(fwcaps & BWN_FWCAPS_WME)) {
4279 			device_printf(sc->sc_dev, "disabling WME support\n");
4280 			mac->mac_flags &= ~BWN_MAC_FLAG_WME;
4281 		}
4282 	}
4283 
4284 	if (BWN_ISOLDFMT(mac))
4285 		device_printf(sc->sc_dev, "using old firmware image\n");
4286 
4287 	return (0);
4288 
4289 error:
4290 	BWN_WRITE_4(mac, BWN_MACCTL,
4291 	    (BWN_READ_4(mac, BWN_MACCTL) & ~BWN_MACCTL_MCODE_RUN) |
4292 	    BWN_MACCTL_MCODE_JMP0);
4293 
4294 	return (error);
4295 #undef GETFWSIZE
4296 #undef GETFWOFFSET
4297 }
4298 
4299 /* OpenFirmware only */
4300 static uint16_t
4301 bwn_fwcaps_read(struct bwn_mac *mac)
4302 {
4303 
4304 	KASSERT(mac->mac_fw.opensource == 1,
4305 	    ("%s:%d: fail", __func__, __LINE__));
4306 	return (bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_FWCAPS));
4307 }
4308 
4309 static int
4310 bwn_fwinitvals_write(struct bwn_mac *mac, const struct bwn_fwinitvals *ivals,
4311     size_t count, size_t array_size)
4312 {
4313 #define	GET_NEXTIV16(iv)						\
4314 	((const struct bwn_fwinitvals *)((const uint8_t *)(iv) +	\
4315 	    sizeof(uint16_t) + sizeof(uint16_t)))
4316 #define	GET_NEXTIV32(iv)						\
4317 	((const struct bwn_fwinitvals *)((const uint8_t *)(iv) +	\
4318 	    sizeof(uint16_t) + sizeof(uint32_t)))
4319 	struct bwn_softc *sc = mac->mac_sc;
4320 	const struct bwn_fwinitvals *iv;
4321 	uint16_t offset;
4322 	size_t i;
4323 	uint8_t bit32;
4324 
4325 	KASSERT(sizeof(struct bwn_fwinitvals) == 6,
4326 	    ("%s:%d: fail", __func__, __LINE__));
4327 	iv = ivals;
4328 	for (i = 0; i < count; i++) {
4329 		if (array_size < sizeof(iv->offset_size))
4330 			goto fail;
4331 		array_size -= sizeof(iv->offset_size);
4332 		offset = be16toh(iv->offset_size);
4333 		bit32 = (offset & BWN_FWINITVALS_32BIT) ? 1 : 0;
4334 		offset &= BWN_FWINITVALS_OFFSET_MASK;
4335 		if (offset >= 0x1000)
4336 			goto fail;
4337 		if (bit32) {
4338 			if (array_size < sizeof(iv->data.d32))
4339 				goto fail;
4340 			array_size -= sizeof(iv->data.d32);
4341 			BWN_WRITE_4(mac, offset, be32toh(iv->data.d32));
4342 			iv = GET_NEXTIV32(iv);
4343 		} else {
4344 
4345 			if (array_size < sizeof(iv->data.d16))
4346 				goto fail;
4347 			array_size -= sizeof(iv->data.d16);
4348 			BWN_WRITE_2(mac, offset, be16toh(iv->data.d16));
4349 
4350 			iv = GET_NEXTIV16(iv);
4351 		}
4352 	}
4353 	if (array_size != 0)
4354 		goto fail;
4355 	return (0);
4356 fail:
4357 	device_printf(sc->sc_dev, "initvals: invalid format\n");
4358 	return (EPROTO);
4359 #undef GET_NEXTIV16
4360 #undef GET_NEXTIV32
4361 }
4362 
4363 int
4364 bwn_switch_channel(struct bwn_mac *mac, int chan)
4365 {
4366 	struct bwn_phy *phy = &(mac->mac_phy);
4367 	struct bwn_softc *sc = mac->mac_sc;
4368 	struct ieee80211com *ic = &sc->sc_ic;
4369 	uint16_t channelcookie, savedcookie;
4370 	int error;
4371 
4372 	if (chan == 0xffff)
4373 		chan = phy->get_default_chan(mac);
4374 
4375 	channelcookie = chan;
4376 	if (IEEE80211_IS_CHAN_5GHZ(ic->ic_curchan))
4377 		channelcookie |= 0x100;
4378 	savedcookie = bwn_shm_read_2(mac, BWN_SHARED, BWN_SHARED_CHAN);
4379 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_CHAN, channelcookie);
4380 	error = phy->switch_channel(mac, chan);
4381 	if (error)
4382 		goto fail;
4383 
4384 	mac->mac_phy.chan = chan;
4385 	DELAY(8000);
4386 	return (0);
4387 fail:
4388 	device_printf(sc->sc_dev, "failed to switch channel\n");
4389 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_CHAN, savedcookie);
4390 	return (error);
4391 }
4392 
4393 static uint16_t
4394 bwn_ant2phy(int antenna)
4395 {
4396 
4397 	switch (antenna) {
4398 	case BWN_ANT0:
4399 		return (BWN_TX_PHY_ANT0);
4400 	case BWN_ANT1:
4401 		return (BWN_TX_PHY_ANT1);
4402 	case BWN_ANT2:
4403 		return (BWN_TX_PHY_ANT2);
4404 	case BWN_ANT3:
4405 		return (BWN_TX_PHY_ANT3);
4406 	case BWN_ANTAUTO:
4407 		return (BWN_TX_PHY_ANT01AUTO);
4408 	}
4409 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
4410 	return (0);
4411 }
4412 
4413 static void
4414 bwn_wme_load(struct bwn_mac *mac)
4415 {
4416 	struct bwn_softc *sc = mac->mac_sc;
4417 	int i;
4418 
4419 	KASSERT(N(bwn_wme_shm_offsets) == N(sc->sc_wmeParams),
4420 	    ("%s:%d: fail", __func__, __LINE__));
4421 
4422 	bwn_mac_suspend(mac);
4423 	for (i = 0; i < N(sc->sc_wmeParams); i++)
4424 		bwn_wme_loadparams(mac, &(sc->sc_wmeParams[i]),
4425 		    bwn_wme_shm_offsets[i]);
4426 	bwn_mac_enable(mac);
4427 }
4428 
4429 static void
4430 bwn_wme_loadparams(struct bwn_mac *mac,
4431     const struct wmeParams *p, uint16_t shm_offset)
4432 {
4433 #define	SM(_v, _f)      (((_v) << _f##_S) & _f)
4434 	struct bwn_softc *sc = mac->mac_sc;
4435 	uint16_t params[BWN_NR_WMEPARAMS];
4436 	int slot, tmp;
4437 	unsigned int i;
4438 
4439 	slot = BWN_READ_2(mac, BWN_RNG) &
4440 	    SM(p->wmep_logcwmin, WME_PARAM_LOGCWMIN);
4441 
4442 	memset(&params, 0, sizeof(params));
4443 
4444 	DPRINTF(sc, BWN_DEBUG_WME, "wmep_txopLimit %d wmep_logcwmin %d "
4445 	    "wmep_logcwmax %d wmep_aifsn %d\n", p->wmep_txopLimit,
4446 	    p->wmep_logcwmin, p->wmep_logcwmax, p->wmep_aifsn);
4447 
4448 	params[BWN_WMEPARAM_TXOP] = p->wmep_txopLimit * 32;
4449 	params[BWN_WMEPARAM_CWMIN] = SM(p->wmep_logcwmin, WME_PARAM_LOGCWMIN);
4450 	params[BWN_WMEPARAM_CWMAX] = SM(p->wmep_logcwmax, WME_PARAM_LOGCWMAX);
4451 	params[BWN_WMEPARAM_CWCUR] = SM(p->wmep_logcwmin, WME_PARAM_LOGCWMIN);
4452 	params[BWN_WMEPARAM_AIFS] = p->wmep_aifsn;
4453 	params[BWN_WMEPARAM_BSLOTS] = slot;
4454 	params[BWN_WMEPARAM_REGGAP] = slot + p->wmep_aifsn;
4455 
4456 	for (i = 0; i < N(params); i++) {
4457 		if (i == BWN_WMEPARAM_STATUS) {
4458 			tmp = bwn_shm_read_2(mac, BWN_SHARED,
4459 			    shm_offset + (i * 2));
4460 			tmp |= 0x100;
4461 			bwn_shm_write_2(mac, BWN_SHARED, shm_offset + (i * 2),
4462 			    tmp);
4463 		} else {
4464 			bwn_shm_write_2(mac, BWN_SHARED, shm_offset + (i * 2),
4465 			    params[i]);
4466 		}
4467 	}
4468 }
4469 
4470 static void
4471 bwn_mac_write_bssid(struct bwn_mac *mac)
4472 {
4473 	struct bwn_softc *sc = mac->mac_sc;
4474 	uint32_t tmp;
4475 	int i;
4476 	uint8_t mac_bssid[IEEE80211_ADDR_LEN * 2];
4477 
4478 	bwn_mac_setfilter(mac, BWN_MACFILTER_BSSID, sc->sc_bssid);
4479 	memcpy(mac_bssid, sc->sc_ic.ic_macaddr, IEEE80211_ADDR_LEN);
4480 	memcpy(mac_bssid + IEEE80211_ADDR_LEN, sc->sc_bssid,
4481 	    IEEE80211_ADDR_LEN);
4482 
4483 	for (i = 0; i < N(mac_bssid); i += sizeof(uint32_t)) {
4484 		tmp = (uint32_t) (mac_bssid[i + 0]);
4485 		tmp |= (uint32_t) (mac_bssid[i + 1]) << 8;
4486 		tmp |= (uint32_t) (mac_bssid[i + 2]) << 16;
4487 		tmp |= (uint32_t) (mac_bssid[i + 3]) << 24;
4488 		bwn_ram_write(mac, 0x20 + i, tmp);
4489 	}
4490 }
4491 
4492 static void
4493 bwn_mac_setfilter(struct bwn_mac *mac, uint16_t offset,
4494     const uint8_t *macaddr)
4495 {
4496 	static const uint8_t zero[IEEE80211_ADDR_LEN] = { 0 };
4497 	uint16_t data;
4498 
4499 	if (!mac)
4500 		macaddr = zero;
4501 
4502 	offset |= 0x0020;
4503 	BWN_WRITE_2(mac, BWN_MACFILTER_CONTROL, offset);
4504 
4505 	data = macaddr[0];
4506 	data |= macaddr[1] << 8;
4507 	BWN_WRITE_2(mac, BWN_MACFILTER_DATA, data);
4508 	data = macaddr[2];
4509 	data |= macaddr[3] << 8;
4510 	BWN_WRITE_2(mac, BWN_MACFILTER_DATA, data);
4511 	data = macaddr[4];
4512 	data |= macaddr[5] << 8;
4513 	BWN_WRITE_2(mac, BWN_MACFILTER_DATA, data);
4514 }
4515 
4516 static void
4517 bwn_key_dowrite(struct bwn_mac *mac, uint8_t index, uint8_t algorithm,
4518     const uint8_t *key, size_t key_len, const uint8_t *mac_addr)
4519 {
4520 	uint8_t buf[BWN_SEC_KEYSIZE] = { 0, };
4521 	uint8_t per_sta_keys_start = 8;
4522 
4523 	if (BWN_SEC_NEWAPI(mac))
4524 		per_sta_keys_start = 4;
4525 
4526 	KASSERT(index < mac->mac_max_nr_keys,
4527 	    ("%s:%d: fail", __func__, __LINE__));
4528 	KASSERT(key_len <= BWN_SEC_KEYSIZE,
4529 	    ("%s:%d: fail", __func__, __LINE__));
4530 
4531 	if (index >= per_sta_keys_start)
4532 		bwn_key_macwrite(mac, index, NULL);
4533 	if (key)
4534 		memcpy(buf, key, key_len);
4535 	bwn_key_write(mac, index, algorithm, buf);
4536 	if (index >= per_sta_keys_start)
4537 		bwn_key_macwrite(mac, index, mac_addr);
4538 
4539 	mac->mac_key[index].algorithm = algorithm;
4540 }
4541 
4542 static void
4543 bwn_key_macwrite(struct bwn_mac *mac, uint8_t index, const uint8_t *addr)
4544 {
4545 	struct bwn_softc *sc = mac->mac_sc;
4546 	uint32_t addrtmp[2] = { 0, 0 };
4547 	uint8_t start = 8;
4548 
4549 	if (BWN_SEC_NEWAPI(mac))
4550 		start = 4;
4551 
4552 	KASSERT(index >= start,
4553 	    ("%s:%d: fail", __func__, __LINE__));
4554 	index -= start;
4555 
4556 	if (addr) {
4557 		addrtmp[0] = addr[0];
4558 		addrtmp[0] |= ((uint32_t) (addr[1]) << 8);
4559 		addrtmp[0] |= ((uint32_t) (addr[2]) << 16);
4560 		addrtmp[0] |= ((uint32_t) (addr[3]) << 24);
4561 		addrtmp[1] = addr[4];
4562 		addrtmp[1] |= ((uint32_t) (addr[5]) << 8);
4563 	}
4564 
4565 	if (siba_get_revid(sc->sc_dev) >= 5) {
4566 		bwn_shm_write_4(mac, BWN_RCMTA, (index * 2) + 0, addrtmp[0]);
4567 		bwn_shm_write_2(mac, BWN_RCMTA, (index * 2) + 1, addrtmp[1]);
4568 	} else {
4569 		if (index >= 8) {
4570 			bwn_shm_write_4(mac, BWN_SHARED,
4571 			    BWN_SHARED_PSM + (index * 6) + 0, addrtmp[0]);
4572 			bwn_shm_write_2(mac, BWN_SHARED,
4573 			    BWN_SHARED_PSM + (index * 6) + 4, addrtmp[1]);
4574 		}
4575 	}
4576 }
4577 
4578 static void
4579 bwn_key_write(struct bwn_mac *mac, uint8_t index, uint8_t algorithm,
4580     const uint8_t *key)
4581 {
4582 	unsigned int i;
4583 	uint32_t offset;
4584 	uint16_t kidx, value;
4585 
4586 	kidx = BWN_SEC_KEY2FW(mac, index);
4587 	bwn_shm_write_2(mac, BWN_SHARED,
4588 	    BWN_SHARED_KEYIDX_BLOCK + (kidx * 2), (kidx << 4) | algorithm);
4589 
4590 	offset = mac->mac_ktp + (index * BWN_SEC_KEYSIZE);
4591 	for (i = 0; i < BWN_SEC_KEYSIZE; i += 2) {
4592 		value = key[i];
4593 		value |= (uint16_t)(key[i + 1]) << 8;
4594 		bwn_shm_write_2(mac, BWN_SHARED, offset + i, value);
4595 	}
4596 }
4597 
4598 static void
4599 bwn_phy_exit(struct bwn_mac *mac)
4600 {
4601 
4602 	mac->mac_phy.rf_onoff(mac, 0);
4603 	if (mac->mac_phy.exit != NULL)
4604 		mac->mac_phy.exit(mac);
4605 }
4606 
4607 static void
4608 bwn_dma_free(struct bwn_mac *mac)
4609 {
4610 	struct bwn_dma *dma;
4611 
4612 	if ((mac->mac_flags & BWN_MAC_FLAG_DMA) == 0)
4613 		return;
4614 	dma = &mac->mac_method.dma;
4615 
4616 	bwn_dma_ringfree(&dma->rx);
4617 	bwn_dma_ringfree(&dma->wme[WME_AC_BK]);
4618 	bwn_dma_ringfree(&dma->wme[WME_AC_BE]);
4619 	bwn_dma_ringfree(&dma->wme[WME_AC_VI]);
4620 	bwn_dma_ringfree(&dma->wme[WME_AC_VO]);
4621 	bwn_dma_ringfree(&dma->mcast);
4622 }
4623 
4624 static void
4625 bwn_core_stop(struct bwn_mac *mac)
4626 {
4627 	struct bwn_softc *sc = mac->mac_sc;
4628 
4629 	BWN_ASSERT_LOCKED(sc);
4630 
4631 	if (mac->mac_status < BWN_MAC_STATUS_STARTED)
4632 		return;
4633 
4634 	callout_stop(&sc->sc_rfswitch_ch);
4635 	callout_stop(&sc->sc_task_ch);
4636 	callout_stop(&sc->sc_watchdog_ch);
4637 	sc->sc_watchdog_timer = 0;
4638 	BWN_WRITE_4(mac, BWN_INTR_MASK, 0);
4639 	BWN_READ_4(mac, BWN_INTR_MASK);
4640 	bwn_mac_suspend(mac);
4641 
4642 	mac->mac_status = BWN_MAC_STATUS_INITED;
4643 }
4644 
4645 static int
4646 bwn_switch_band(struct bwn_softc *sc, struct ieee80211_channel *chan)
4647 {
4648 	struct bwn_mac *up_dev = NULL;
4649 	struct bwn_mac *down_dev;
4650 	struct bwn_mac *mac;
4651 	int err, status;
4652 	uint8_t gmode;
4653 
4654 	BWN_ASSERT_LOCKED(sc);
4655 
4656 	TAILQ_FOREACH(mac, &sc->sc_maclist, mac_list) {
4657 		if (IEEE80211_IS_CHAN_2GHZ(chan) &&
4658 		    mac->mac_phy.supports_2ghz) {
4659 			up_dev = mac;
4660 			gmode = 1;
4661 		} else if (IEEE80211_IS_CHAN_5GHZ(chan) &&
4662 		    mac->mac_phy.supports_5ghz) {
4663 			up_dev = mac;
4664 			gmode = 0;
4665 		} else {
4666 			KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
4667 			return (EINVAL);
4668 		}
4669 		if (up_dev != NULL)
4670 			break;
4671 	}
4672 	if (up_dev == NULL) {
4673 		device_printf(sc->sc_dev, "Could not find a device\n");
4674 		return (ENODEV);
4675 	}
4676 	if (up_dev == sc->sc_curmac && sc->sc_curmac->mac_phy.gmode == gmode)
4677 		return (0);
4678 
4679 	DPRINTF(sc, BWN_DEBUG_RF | BWN_DEBUG_PHY | BWN_DEBUG_RESET,
4680 	    "switching to %s-GHz band\n",
4681 	    IEEE80211_IS_CHAN_2GHZ(chan) ? "2" : "5");
4682 
4683 	down_dev = sc->sc_curmac;
4684 	status = down_dev->mac_status;
4685 	if (status >= BWN_MAC_STATUS_STARTED)
4686 		bwn_core_stop(down_dev);
4687 	if (status >= BWN_MAC_STATUS_INITED)
4688 		bwn_core_exit(down_dev);
4689 
4690 	if (down_dev != up_dev)
4691 		bwn_phy_reset(down_dev);
4692 
4693 	up_dev->mac_phy.gmode = gmode;
4694 	if (status >= BWN_MAC_STATUS_INITED) {
4695 		err = bwn_core_init(up_dev);
4696 		if (err) {
4697 			device_printf(sc->sc_dev,
4698 			    "fatal: failed to initialize for %s-GHz\n",
4699 			    IEEE80211_IS_CHAN_2GHZ(chan) ? "2" : "5");
4700 			goto fail;
4701 		}
4702 	}
4703 	if (status >= BWN_MAC_STATUS_STARTED)
4704 		bwn_core_start(up_dev);
4705 	KASSERT(up_dev->mac_status == status, ("%s: fail", __func__));
4706 	sc->sc_curmac = up_dev;
4707 
4708 	return (0);
4709 fail:
4710 	sc->sc_curmac = NULL;
4711 	return (err);
4712 }
4713 
4714 static void
4715 bwn_rf_turnon(struct bwn_mac *mac)
4716 {
4717 
4718 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: called\n", __func__);
4719 
4720 	bwn_mac_suspend(mac);
4721 	mac->mac_phy.rf_onoff(mac, 1);
4722 	mac->mac_phy.rf_on = 1;
4723 	bwn_mac_enable(mac);
4724 }
4725 
4726 static void
4727 bwn_rf_turnoff(struct bwn_mac *mac)
4728 {
4729 
4730 	DPRINTF(mac->mac_sc, BWN_DEBUG_RESET, "%s: called\n", __func__);
4731 
4732 	bwn_mac_suspend(mac);
4733 	mac->mac_phy.rf_onoff(mac, 0);
4734 	mac->mac_phy.rf_on = 0;
4735 	bwn_mac_enable(mac);
4736 }
4737 
4738 /*
4739  * PHY reset.
4740  */
4741 static void
4742 bwn_phy_reset(struct bwn_mac *mac)
4743 {
4744 	struct bwn_softc *sc = mac->mac_sc;
4745 
4746 	siba_write_4(sc->sc_dev, SIBA_TGSLOW,
4747 	    ((siba_read_4(sc->sc_dev, SIBA_TGSLOW) & ~BWN_TGSLOW_SUPPORT_G) |
4748 	     BWN_TGSLOW_PHYRESET) | SIBA_TGSLOW_FGC);
4749 	DELAY(1000);
4750 	siba_write_4(sc->sc_dev, SIBA_TGSLOW,
4751 	    (siba_read_4(sc->sc_dev, SIBA_TGSLOW) & ~SIBA_TGSLOW_FGC));
4752 	DELAY(1000);
4753 }
4754 
4755 static int
4756 bwn_newstate(struct ieee80211vap *vap, enum ieee80211_state nstate, int arg)
4757 {
4758 	struct bwn_vap *bvp = BWN_VAP(vap);
4759 	struct ieee80211com *ic= vap->iv_ic;
4760 	enum ieee80211_state ostate = vap->iv_state;
4761 	struct bwn_softc *sc = ic->ic_softc;
4762 	struct bwn_mac *mac = sc->sc_curmac;
4763 	int error;
4764 
4765 	DPRINTF(sc, BWN_DEBUG_STATE, "%s: %s -> %s\n", __func__,
4766 	    ieee80211_state_name[vap->iv_state],
4767 	    ieee80211_state_name[nstate]);
4768 
4769 	error = bvp->bv_newstate(vap, nstate, arg);
4770 	if (error != 0)
4771 		return (error);
4772 
4773 	BWN_LOCK(sc);
4774 
4775 	bwn_led_newstate(mac, nstate);
4776 
4777 	/*
4778 	 * Clear the BSSID when we stop a STA
4779 	 */
4780 	if (vap->iv_opmode == IEEE80211_M_STA) {
4781 		if (ostate == IEEE80211_S_RUN && nstate != IEEE80211_S_RUN) {
4782 			/*
4783 			 * Clear out the BSSID.  If we reassociate to
4784 			 * the same AP, this will reinialize things
4785 			 * correctly...
4786 			 */
4787 			if (ic->ic_opmode == IEEE80211_M_STA &&
4788 			    (sc->sc_flags & BWN_FLAG_INVALID) == 0) {
4789 				memset(sc->sc_bssid, 0, IEEE80211_ADDR_LEN);
4790 				bwn_set_macaddr(mac);
4791 			}
4792 		}
4793 	}
4794 
4795 	if (vap->iv_opmode == IEEE80211_M_MONITOR ||
4796 	    vap->iv_opmode == IEEE80211_M_AHDEMO) {
4797 		/* XXX nothing to do? */
4798 	} else if (nstate == IEEE80211_S_RUN) {
4799 		memcpy(sc->sc_bssid, vap->iv_bss->ni_bssid, IEEE80211_ADDR_LEN);
4800 		bwn_set_opmode(mac);
4801 		bwn_set_pretbtt(mac);
4802 		bwn_spu_setdelay(mac, 0);
4803 		bwn_set_macaddr(mac);
4804 	}
4805 
4806 	BWN_UNLOCK(sc);
4807 
4808 	return (error);
4809 }
4810 
4811 static void
4812 bwn_set_pretbtt(struct bwn_mac *mac)
4813 {
4814 	struct bwn_softc *sc = mac->mac_sc;
4815 	struct ieee80211com *ic = &sc->sc_ic;
4816 	uint16_t pretbtt;
4817 
4818 	if (ic->ic_opmode == IEEE80211_M_IBSS)
4819 		pretbtt = 2;
4820 	else
4821 		pretbtt = (mac->mac_phy.type == BWN_PHYTYPE_A) ? 120 : 250;
4822 	bwn_shm_write_2(mac, BWN_SHARED, BWN_SHARED_PRETBTT, pretbtt);
4823 	BWN_WRITE_2(mac, BWN_TSF_CFP_PRETBTT, pretbtt);
4824 }
4825 
4826 static int
4827 bwn_intr(void *arg)
4828 {
4829 	struct bwn_mac *mac = arg;
4830 	struct bwn_softc *sc = mac->mac_sc;
4831 	uint32_t reason;
4832 
4833 	if (mac->mac_status < BWN_MAC_STATUS_STARTED ||
4834 	    (sc->sc_flags & BWN_FLAG_INVALID))
4835 		return (FILTER_STRAY);
4836 
4837 	DPRINTF(sc, BWN_DEBUG_INTR, "%s: called\n", __func__);
4838 
4839 	reason = BWN_READ_4(mac, BWN_INTR_REASON);
4840 	if (reason == 0xffffffff)	/* shared IRQ */
4841 		return (FILTER_STRAY);
4842 	reason &= mac->mac_intr_mask;
4843 	if (reason == 0)
4844 		return (FILTER_HANDLED);
4845 	DPRINTF(sc, BWN_DEBUG_INTR, "%s: reason=0x%08x\n", __func__, reason);
4846 
4847 	mac->mac_reason[0] = BWN_READ_4(mac, BWN_DMA0_REASON) & 0x0001dc00;
4848 	mac->mac_reason[1] = BWN_READ_4(mac, BWN_DMA1_REASON) & 0x0000dc00;
4849 	mac->mac_reason[2] = BWN_READ_4(mac, BWN_DMA2_REASON) & 0x0000dc00;
4850 	mac->mac_reason[3] = BWN_READ_4(mac, BWN_DMA3_REASON) & 0x0001dc00;
4851 	mac->mac_reason[4] = BWN_READ_4(mac, BWN_DMA4_REASON) & 0x0000dc00;
4852 	BWN_WRITE_4(mac, BWN_INTR_REASON, reason);
4853 	BWN_WRITE_4(mac, BWN_DMA0_REASON, mac->mac_reason[0]);
4854 	BWN_WRITE_4(mac, BWN_DMA1_REASON, mac->mac_reason[1]);
4855 	BWN_WRITE_4(mac, BWN_DMA2_REASON, mac->mac_reason[2]);
4856 	BWN_WRITE_4(mac, BWN_DMA3_REASON, mac->mac_reason[3]);
4857 	BWN_WRITE_4(mac, BWN_DMA4_REASON, mac->mac_reason[4]);
4858 
4859 	/* Disable interrupts. */
4860 	BWN_WRITE_4(mac, BWN_INTR_MASK, 0);
4861 
4862 	mac->mac_reason_intr = reason;
4863 
4864 	BWN_BARRIER(mac, BUS_SPACE_BARRIER_READ);
4865 	BWN_BARRIER(mac, BUS_SPACE_BARRIER_WRITE);
4866 
4867 	taskqueue_enqueue(sc->sc_tq, &mac->mac_intrtask);
4868 	return (FILTER_HANDLED);
4869 }
4870 
4871 static void
4872 bwn_intrtask(void *arg, int npending)
4873 {
4874 	struct bwn_mac *mac = arg;
4875 	struct bwn_softc *sc = mac->mac_sc;
4876 	uint32_t merged = 0;
4877 	int i, tx = 0, rx = 0;
4878 
4879 	BWN_LOCK(sc);
4880 	if (mac->mac_status < BWN_MAC_STATUS_STARTED ||
4881 	    (sc->sc_flags & BWN_FLAG_INVALID)) {
4882 		BWN_UNLOCK(sc);
4883 		return;
4884 	}
4885 
4886 	for (i = 0; i < N(mac->mac_reason); i++)
4887 		merged |= mac->mac_reason[i];
4888 
4889 	if (mac->mac_reason_intr & BWN_INTR_MAC_TXERR)
4890 		device_printf(sc->sc_dev, "MAC trans error\n");
4891 
4892 	if (mac->mac_reason_intr & BWN_INTR_PHY_TXERR) {
4893 		DPRINTF(sc, BWN_DEBUG_INTR, "%s: PHY trans error\n", __func__);
4894 		mac->mac_phy.txerrors--;
4895 		if (mac->mac_phy.txerrors == 0) {
4896 			mac->mac_phy.txerrors = BWN_TXERROR_MAX;
4897 			bwn_restart(mac, "PHY TX errors");
4898 		}
4899 	}
4900 
4901 	if (merged & (BWN_DMAINTR_FATALMASK | BWN_DMAINTR_NONFATALMASK)) {
4902 		if (merged & BWN_DMAINTR_FATALMASK) {
4903 			device_printf(sc->sc_dev,
4904 			    "Fatal DMA error: %#x %#x %#x %#x %#x %#x\n",
4905 			    mac->mac_reason[0], mac->mac_reason[1],
4906 			    mac->mac_reason[2], mac->mac_reason[3],
4907 			    mac->mac_reason[4], mac->mac_reason[5]);
4908 			bwn_restart(mac, "DMA error");
4909 			BWN_UNLOCK(sc);
4910 			return;
4911 		}
4912 		if (merged & BWN_DMAINTR_NONFATALMASK) {
4913 			device_printf(sc->sc_dev,
4914 			    "DMA error: %#x %#x %#x %#x %#x %#x\n",
4915 			    mac->mac_reason[0], mac->mac_reason[1],
4916 			    mac->mac_reason[2], mac->mac_reason[3],
4917 			    mac->mac_reason[4], mac->mac_reason[5]);
4918 		}
4919 	}
4920 
4921 	if (mac->mac_reason_intr & BWN_INTR_UCODE_DEBUG)
4922 		bwn_intr_ucode_debug(mac);
4923 	if (mac->mac_reason_intr & BWN_INTR_TBTT_INDI)
4924 		bwn_intr_tbtt_indication(mac);
4925 	if (mac->mac_reason_intr & BWN_INTR_ATIM_END)
4926 		bwn_intr_atim_end(mac);
4927 	if (mac->mac_reason_intr & BWN_INTR_BEACON)
4928 		bwn_intr_beacon(mac);
4929 	if (mac->mac_reason_intr & BWN_INTR_PMQ)
4930 		bwn_intr_pmq(mac);
4931 	if (mac->mac_reason_intr & BWN_INTR_NOISESAMPLE_OK)
4932 		bwn_intr_noise(mac);
4933 
4934 	if (mac->mac_flags & BWN_MAC_FLAG_DMA) {
4935 		if (mac->mac_reason[0] & BWN_DMAINTR_RX_DONE) {
4936 			bwn_dma_rx(mac->mac_method.dma.rx);
4937 			rx = 1;
4938 		}
4939 	} else
4940 		rx = bwn_pio_rx(&mac->mac_method.pio.rx);
4941 
4942 	KASSERT(!(mac->mac_reason[1] & BWN_DMAINTR_RX_DONE), ("%s", __func__));
4943 	KASSERT(!(mac->mac_reason[2] & BWN_DMAINTR_RX_DONE), ("%s", __func__));
4944 	KASSERT(!(mac->mac_reason[3] & BWN_DMAINTR_RX_DONE), ("%s", __func__));
4945 	KASSERT(!(mac->mac_reason[4] & BWN_DMAINTR_RX_DONE), ("%s", __func__));
4946 	KASSERT(!(mac->mac_reason[5] & BWN_DMAINTR_RX_DONE), ("%s", __func__));
4947 
4948 	if (mac->mac_reason_intr & BWN_INTR_TX_OK) {
4949 		bwn_intr_txeof(mac);
4950 		tx = 1;
4951 	}
4952 
4953 	BWN_WRITE_4(mac, BWN_INTR_MASK, mac->mac_intr_mask);
4954 
4955 	if (sc->sc_blink_led != NULL && sc->sc_led_blink) {
4956 		int evt = BWN_LED_EVENT_NONE;
4957 
4958 		if (tx && rx) {
4959 			if (sc->sc_rx_rate > sc->sc_tx_rate)
4960 				evt = BWN_LED_EVENT_RX;
4961 			else
4962 				evt = BWN_LED_EVENT_TX;
4963 		} else if (tx) {
4964 			evt = BWN_LED_EVENT_TX;
4965 		} else if (rx) {
4966 			evt = BWN_LED_EVENT_RX;
4967 		} else if (rx == 0) {
4968 			evt = BWN_LED_EVENT_POLL;
4969 		}
4970 
4971 		if (evt != BWN_LED_EVENT_NONE)
4972 			bwn_led_event(mac, evt);
4973        }
4974 
4975 	if (mbufq_first(&sc->sc_snd) != NULL)
4976 		bwn_start(sc);
4977 
4978 	BWN_BARRIER(mac, BUS_SPACE_BARRIER_READ);
4979 	BWN_BARRIER(mac, BUS_SPACE_BARRIER_WRITE);
4980 
4981 	BWN_UNLOCK(sc);
4982 }
4983 
4984 static void
4985 bwn_restart(struct bwn_mac *mac, const char *msg)
4986 {
4987 	struct bwn_softc *sc = mac->mac_sc;
4988 	struct ieee80211com *ic = &sc->sc_ic;
4989 
4990 	if (mac->mac_status < BWN_MAC_STATUS_INITED)
4991 		return;
4992 
4993 	device_printf(sc->sc_dev, "HW reset: %s\n", msg);
4994 	ieee80211_runtask(ic, &mac->mac_hwreset);
4995 }
4996 
4997 static void
4998 bwn_intr_ucode_debug(struct bwn_mac *mac)
4999 {
5000 	struct bwn_softc *sc = mac->mac_sc;
5001 	uint16_t reason;
5002 
5003 	if (mac->mac_fw.opensource == 0)
5004 		return;
5005 
5006 	reason = bwn_shm_read_2(mac, BWN_SCRATCH, BWN_DEBUGINTR_REASON_REG);
5007 	switch (reason) {
5008 	case BWN_DEBUGINTR_PANIC:
5009 		bwn_handle_fwpanic(mac);
5010 		break;
5011 	case BWN_DEBUGINTR_DUMP_SHM:
5012 		device_printf(sc->sc_dev, "BWN_DEBUGINTR_DUMP_SHM\n");
5013 		break;
5014 	case BWN_DEBUGINTR_DUMP_REGS:
5015 		device_printf(sc->sc_dev, "BWN_DEBUGINTR_DUMP_REGS\n");
5016 		break;
5017 	case BWN_DEBUGINTR_MARKER:
5018 		device_printf(sc->sc_dev, "BWN_DEBUGINTR_MARKER\n");
5019 		break;
5020 	default:
5021 		device_printf(sc->sc_dev,
5022 		    "ucode debug unknown reason: %#x\n", reason);
5023 	}
5024 
5025 	bwn_shm_write_2(mac, BWN_SCRATCH, BWN_DEBUGINTR_REASON_REG,
5026 	    BWN_DEBUGINTR_ACK);
5027 }
5028 
5029 static void
5030 bwn_intr_tbtt_indication(struct bwn_mac *mac)
5031 {
5032 	struct bwn_softc *sc = mac->mac_sc;
5033 	struct ieee80211com *ic = &sc->sc_ic;
5034 
5035 	if (ic->ic_opmode != IEEE80211_M_HOSTAP)
5036 		bwn_psctl(mac, 0);
5037 	if (ic->ic_opmode == IEEE80211_M_IBSS)
5038 		mac->mac_flags |= BWN_MAC_FLAG_DFQVALID;
5039 }
5040 
5041 static void
5042 bwn_intr_atim_end(struct bwn_mac *mac)
5043 {
5044 
5045 	if (mac->mac_flags & BWN_MAC_FLAG_DFQVALID) {
5046 		BWN_WRITE_4(mac, BWN_MACCMD,
5047 		    BWN_READ_4(mac, BWN_MACCMD) | BWN_MACCMD_DFQ_VALID);
5048 		mac->mac_flags &= ~BWN_MAC_FLAG_DFQVALID;
5049 	}
5050 }
5051 
5052 static void
5053 bwn_intr_beacon(struct bwn_mac *mac)
5054 {
5055 	struct bwn_softc *sc = mac->mac_sc;
5056 	struct ieee80211com *ic = &sc->sc_ic;
5057 	uint32_t cmd, beacon0, beacon1;
5058 
5059 	if (ic->ic_opmode == IEEE80211_M_HOSTAP ||
5060 	    ic->ic_opmode == IEEE80211_M_MBSS)
5061 		return;
5062 
5063 	mac->mac_intr_mask &= ~BWN_INTR_BEACON;
5064 
5065 	cmd = BWN_READ_4(mac, BWN_MACCMD);
5066 	beacon0 = (cmd & BWN_MACCMD_BEACON0_VALID);
5067 	beacon1 = (cmd & BWN_MACCMD_BEACON1_VALID);
5068 
5069 	if (beacon0 && beacon1) {
5070 		BWN_WRITE_4(mac, BWN_INTR_REASON, BWN_INTR_BEACON);
5071 		mac->mac_intr_mask |= BWN_INTR_BEACON;
5072 		return;
5073 	}
5074 
5075 	if (sc->sc_flags & BWN_FLAG_NEED_BEACON_TP) {
5076 		sc->sc_flags &= ~BWN_FLAG_NEED_BEACON_TP;
5077 		bwn_load_beacon0(mac);
5078 		bwn_load_beacon1(mac);
5079 		cmd = BWN_READ_4(mac, BWN_MACCMD);
5080 		cmd |= BWN_MACCMD_BEACON0_VALID;
5081 		BWN_WRITE_4(mac, BWN_MACCMD, cmd);
5082 	} else {
5083 		if (!beacon0) {
5084 			bwn_load_beacon0(mac);
5085 			cmd = BWN_READ_4(mac, BWN_MACCMD);
5086 			cmd |= BWN_MACCMD_BEACON0_VALID;
5087 			BWN_WRITE_4(mac, BWN_MACCMD, cmd);
5088 		} else if (!beacon1) {
5089 			bwn_load_beacon1(mac);
5090 			cmd = BWN_READ_4(mac, BWN_MACCMD);
5091 			cmd |= BWN_MACCMD_BEACON1_VALID;
5092 			BWN_WRITE_4(mac, BWN_MACCMD, cmd);
5093 		}
5094 	}
5095 }
5096 
5097 static void
5098 bwn_intr_pmq(struct bwn_mac *mac)
5099 {
5100 	uint32_t tmp;
5101 
5102 	while (1) {
5103 		tmp = BWN_READ_4(mac, BWN_PS_STATUS);
5104 		if (!(tmp & 0x00000008))
5105 			break;
5106 	}
5107 	BWN_WRITE_2(mac, BWN_PS_STATUS, 0x0002);
5108 }
5109 
5110 static void
5111 bwn_intr_noise(struct bwn_mac *mac)
5112 {
5113 	struct bwn_phy_g *pg = &mac->mac_phy.phy_g;
5114 	uint16_t tmp;
5115 	uint8_t noise[4];
5116 	uint8_t i, j;
5117 	int32_t average;
5118 
5119 	if (mac->mac_phy.type != BWN_PHYTYPE_G)
5120 		return;
5121 
5122 	KASSERT(mac->mac_noise.noi_running, ("%s: fail", __func__));
5123 	*((uint32_t *)noise) = htole32(bwn_jssi_read(mac));
5124 	if (noise[0] == 0x7f || noise[1] == 0x7f || noise[2] == 0x7f ||
5125 	    noise[3] == 0x7f)
5126 		goto new;
5127 
5128 	KASSERT(mac->mac_noise.noi_nsamples < 8,
5129 	    ("%s:%d: fail", __func__, __LINE__));
5130 	i = mac->mac_noise.noi_nsamples;
5131 	noise[0] = MIN(MAX(noise[0], 0), N(pg->pg_nrssi_lt) - 1);
5132 	noise[1] = MIN(MAX(noise[1], 0), N(pg->pg_nrssi_lt) - 1);
5133 	noise[2] = MIN(MAX(noise[2], 0), N(pg->pg_nrssi_lt) - 1);
5134 	noise[3] = MIN(MAX(noise[3], 0), N(pg->pg_nrssi_lt) - 1);
5135 	mac->mac_noise.noi_samples[i][0] = pg->pg_nrssi_lt[noise[0]];
5136 	mac->mac_noise.noi_samples[i][1] = pg->pg_nrssi_lt[noise[1]];
5137 	mac->mac_noise.noi_samples[i][2] = pg->pg_nrssi_lt[noise[2]];
5138 	mac->mac_noise.noi_samples[i][3] = pg->pg_nrssi_lt[noise[3]];
5139 	mac->mac_noise.noi_nsamples++;
5140 	if (mac->mac_noise.noi_nsamples == 8) {
5141 		average = 0;
5142 		for (i = 0; i < 8; i++) {
5143 			for (j = 0; j < 4; j++)
5144 				average += mac->mac_noise.noi_samples[i][j];
5145 		}
5146 		average = (((average / 32) * 125) + 64) / 128;
5147 		tmp = (bwn_shm_read_2(mac, BWN_SHARED, 0x40c) / 128) & 0x1f;
5148 		if (tmp >= 8)
5149 			average += 2;
5150 		else
5151 			average -= 25;
5152 		average -= (tmp == 8) ? 72 : 48;
5153 
5154 		mac->mac_stats.link_noise = average;
5155 		mac->mac_noise.noi_running = 0;
5156 		return;
5157 	}
5158 new:
5159 	bwn_noise_gensample(mac);
5160 }
5161 
5162 static int
5163 bwn_pio_rx(struct bwn_pio_rxqueue *prq)
5164 {
5165 	struct bwn_mac *mac = prq->prq_mac;
5166 	struct bwn_softc *sc = mac->mac_sc;
5167 	unsigned int i;
5168 
5169 	BWN_ASSERT_LOCKED(sc);
5170 
5171 	if (mac->mac_status < BWN_MAC_STATUS_STARTED)
5172 		return (0);
5173 
5174 	for (i = 0; i < 5000; i++) {
5175 		if (bwn_pio_rxeof(prq) == 0)
5176 			break;
5177 	}
5178 	if (i >= 5000)
5179 		device_printf(sc->sc_dev, "too many RX frames in PIO mode\n");
5180 	return ((i > 0) ? 1 : 0);
5181 }
5182 
5183 static void
5184 bwn_dma_rx(struct bwn_dma_ring *dr)
5185 {
5186 	int slot, curslot;
5187 
5188 	KASSERT(!dr->dr_tx, ("%s:%d: fail", __func__, __LINE__));
5189 	curslot = dr->get_curslot(dr);
5190 	KASSERT(curslot >= 0 && curslot < dr->dr_numslots,
5191 	    ("%s:%d: fail", __func__, __LINE__));
5192 
5193 	slot = dr->dr_curslot;
5194 	for (; slot != curslot; slot = bwn_dma_nextslot(dr, slot))
5195 		bwn_dma_rxeof(dr, &slot);
5196 
5197 	bus_dmamap_sync(dr->dr_ring_dtag, dr->dr_ring_dmap,
5198 	    BUS_DMASYNC_PREWRITE);
5199 
5200 	dr->set_curslot(dr, slot);
5201 	dr->dr_curslot = slot;
5202 }
5203 
5204 static void
5205 bwn_intr_txeof(struct bwn_mac *mac)
5206 {
5207 	struct bwn_txstatus stat;
5208 	uint32_t stat0, stat1;
5209 	uint16_t tmp;
5210 
5211 	BWN_ASSERT_LOCKED(mac->mac_sc);
5212 
5213 	while (1) {
5214 		stat0 = BWN_READ_4(mac, BWN_XMITSTAT_0);
5215 		if (!(stat0 & 0x00000001))
5216 			break;
5217 		stat1 = BWN_READ_4(mac, BWN_XMITSTAT_1);
5218 
5219 		DPRINTF(mac->mac_sc, BWN_DEBUG_XMIT,
5220 		    "%s: stat0=0x%08x, stat1=0x%08x\n",
5221 		    __func__,
5222 		    stat0,
5223 		    stat1);
5224 
5225 		stat.cookie = (stat0 >> 16);
5226 		stat.seq = (stat1 & 0x0000ffff);
5227 		stat.phy_stat = ((stat1 & 0x00ff0000) >> 16);
5228 		tmp = (stat0 & 0x0000ffff);
5229 		stat.framecnt = ((tmp & 0xf000) >> 12);
5230 		stat.rtscnt = ((tmp & 0x0f00) >> 8);
5231 		stat.sreason = ((tmp & 0x001c) >> 2);
5232 		stat.pm = (tmp & 0x0080) ? 1 : 0;
5233 		stat.im = (tmp & 0x0040) ? 1 : 0;
5234 		stat.ampdu = (tmp & 0x0020) ? 1 : 0;
5235 		stat.ack = (tmp & 0x0002) ? 1 : 0;
5236 
5237 		DPRINTF(mac->mac_sc, BWN_DEBUG_XMIT,
5238 		    "%s: cookie=%d, seq=%d, phystat=0x%02x, framecnt=%d, "
5239 		    "rtscnt=%d, sreason=%d, pm=%d, im=%d, ampdu=%d, ack=%d\n",
5240 		    __func__,
5241 		    stat.cookie,
5242 		    stat.seq,
5243 		    stat.phy_stat,
5244 		    stat.framecnt,
5245 		    stat.rtscnt,
5246 		    stat.sreason,
5247 		    stat.pm,
5248 		    stat.im,
5249 		    stat.ampdu,
5250 		    stat.ack);
5251 
5252 		bwn_handle_txeof(mac, &stat);
5253 	}
5254 }
5255 
5256 static void
5257 bwn_hwreset(void *arg, int npending)
5258 {
5259 	struct bwn_mac *mac = arg;
5260 	struct bwn_softc *sc = mac->mac_sc;
5261 	int error = 0;
5262 	int prev_status;
5263 
5264 	BWN_LOCK(sc);
5265 
5266 	prev_status = mac->mac_status;
5267 	if (prev_status >= BWN_MAC_STATUS_STARTED)
5268 		bwn_core_stop(mac);
5269 	if (prev_status >= BWN_MAC_STATUS_INITED)
5270 		bwn_core_exit(mac);
5271 
5272 	if (prev_status >= BWN_MAC_STATUS_INITED) {
5273 		error = bwn_core_init(mac);
5274 		if (error)
5275 			goto out;
5276 	}
5277 	if (prev_status >= BWN_MAC_STATUS_STARTED)
5278 		bwn_core_start(mac);
5279 out:
5280 	if (error) {
5281 		device_printf(sc->sc_dev, "%s: failed (%d)\n", __func__, error);
5282 		sc->sc_curmac = NULL;
5283 	}
5284 	BWN_UNLOCK(sc);
5285 }
5286 
5287 static void
5288 bwn_handle_fwpanic(struct bwn_mac *mac)
5289 {
5290 	struct bwn_softc *sc = mac->mac_sc;
5291 	uint16_t reason;
5292 
5293 	reason = bwn_shm_read_2(mac, BWN_SCRATCH, BWN_FWPANIC_REASON_REG);
5294 	device_printf(sc->sc_dev,"fw panic (%u)\n", reason);
5295 
5296 	if (reason == BWN_FWPANIC_RESTART)
5297 		bwn_restart(mac, "ucode panic");
5298 }
5299 
5300 static void
5301 bwn_load_beacon0(struct bwn_mac *mac)
5302 {
5303 
5304 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
5305 }
5306 
5307 static void
5308 bwn_load_beacon1(struct bwn_mac *mac)
5309 {
5310 
5311 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
5312 }
5313 
5314 static uint32_t
5315 bwn_jssi_read(struct bwn_mac *mac)
5316 {
5317 	uint32_t val = 0;
5318 
5319 	val = bwn_shm_read_2(mac, BWN_SHARED, 0x08a);
5320 	val <<= 16;
5321 	val |= bwn_shm_read_2(mac, BWN_SHARED, 0x088);
5322 
5323 	return (val);
5324 }
5325 
5326 static void
5327 bwn_noise_gensample(struct bwn_mac *mac)
5328 {
5329 	uint32_t jssi = 0x7f7f7f7f;
5330 
5331 	bwn_shm_write_2(mac, BWN_SHARED, 0x088, (jssi & 0x0000ffff));
5332 	bwn_shm_write_2(mac, BWN_SHARED, 0x08a, (jssi & 0xffff0000) >> 16);
5333 	BWN_WRITE_4(mac, BWN_MACCMD,
5334 	    BWN_READ_4(mac, BWN_MACCMD) | BWN_MACCMD_BGNOISE);
5335 }
5336 
5337 static int
5338 bwn_dma_freeslot(struct bwn_dma_ring *dr)
5339 {
5340 	BWN_ASSERT_LOCKED(dr->dr_mac->mac_sc);
5341 
5342 	return (dr->dr_numslots - dr->dr_usedslot);
5343 }
5344 
5345 static int
5346 bwn_dma_nextslot(struct bwn_dma_ring *dr, int slot)
5347 {
5348 	BWN_ASSERT_LOCKED(dr->dr_mac->mac_sc);
5349 
5350 	KASSERT(slot >= -1 && slot <= dr->dr_numslots - 1,
5351 	    ("%s:%d: fail", __func__, __LINE__));
5352 	if (slot == dr->dr_numslots - 1)
5353 		return (0);
5354 	return (slot + 1);
5355 }
5356 
5357 static void
5358 bwn_dma_rxeof(struct bwn_dma_ring *dr, int *slot)
5359 {
5360 	struct bwn_mac *mac = dr->dr_mac;
5361 	struct bwn_softc *sc = mac->mac_sc;
5362 	struct bwn_dma *dma = &mac->mac_method.dma;
5363 	struct bwn_dmadesc_generic *desc;
5364 	struct bwn_dmadesc_meta *meta;
5365 	struct bwn_rxhdr4 *rxhdr;
5366 	struct mbuf *m;
5367 	uint32_t macstat;
5368 	int32_t tmp;
5369 	int cnt = 0;
5370 	uint16_t len;
5371 
5372 	dr->getdesc(dr, *slot, &desc, &meta);
5373 
5374 	bus_dmamap_sync(dma->rxbuf_dtag, meta->mt_dmap, BUS_DMASYNC_POSTREAD);
5375 	m = meta->mt_m;
5376 
5377 	if (bwn_dma_newbuf(dr, desc, meta, 0)) {
5378 		counter_u64_add(sc->sc_ic.ic_ierrors, 1);
5379 		return;
5380 	}
5381 
5382 	rxhdr = mtod(m, struct bwn_rxhdr4 *);
5383 	len = le16toh(rxhdr->frame_len);
5384 	if (len <= 0) {
5385 		counter_u64_add(sc->sc_ic.ic_ierrors, 1);
5386 		return;
5387 	}
5388 	if (bwn_dma_check_redzone(dr, m)) {
5389 		device_printf(sc->sc_dev, "redzone error.\n");
5390 		bwn_dma_set_redzone(dr, m);
5391 		bus_dmamap_sync(dma->rxbuf_dtag, meta->mt_dmap,
5392 		    BUS_DMASYNC_PREWRITE);
5393 		return;
5394 	}
5395 	if (len > dr->dr_rx_bufsize) {
5396 		tmp = len;
5397 		while (1) {
5398 			dr->getdesc(dr, *slot, &desc, &meta);
5399 			bwn_dma_set_redzone(dr, meta->mt_m);
5400 			bus_dmamap_sync(dma->rxbuf_dtag, meta->mt_dmap,
5401 			    BUS_DMASYNC_PREWRITE);
5402 			*slot = bwn_dma_nextslot(dr, *slot);
5403 			cnt++;
5404 			tmp -= dr->dr_rx_bufsize;
5405 			if (tmp <= 0)
5406 				break;
5407 		}
5408 		device_printf(sc->sc_dev, "too small buffer "
5409 		       "(len %u buffer %u dropped %d)\n",
5410 		       len, dr->dr_rx_bufsize, cnt);
5411 		return;
5412 	}
5413 
5414 	switch (mac->mac_fw.fw_hdr_format) {
5415 	case BWN_FW_HDR_351:
5416 	case BWN_FW_HDR_410:
5417 		macstat = le32toh(rxhdr->ps4.r351.mac_status);
5418 		break;
5419 	case BWN_FW_HDR_598:
5420 		macstat = le32toh(rxhdr->ps4.r598.mac_status);
5421 		break;
5422 	}
5423 
5424 	if (macstat & BWN_RX_MAC_FCSERR) {
5425 		if (!(mac->mac_sc->sc_filters & BWN_MACCTL_PASS_BADFCS)) {
5426 			device_printf(sc->sc_dev, "RX drop\n");
5427 			return;
5428 		}
5429 	}
5430 
5431 	m->m_len = m->m_pkthdr.len = len + dr->dr_frameoffset;
5432 	m_adj(m, dr->dr_frameoffset);
5433 
5434 	bwn_rxeof(dr->dr_mac, m, rxhdr);
5435 }
5436 
5437 static void
5438 bwn_handle_txeof(struct bwn_mac *mac, const struct bwn_txstatus *status)
5439 {
5440 	struct bwn_softc *sc = mac->mac_sc;
5441 	struct bwn_stats *stats = &mac->mac_stats;
5442 
5443 	BWN_ASSERT_LOCKED(mac->mac_sc);
5444 
5445 	if (status->im)
5446 		device_printf(sc->sc_dev, "TODO: STATUS IM\n");
5447 	if (status->ampdu)
5448 		device_printf(sc->sc_dev, "TODO: STATUS AMPDU\n");
5449 	if (status->rtscnt) {
5450 		if (status->rtscnt == 0xf)
5451 			stats->rtsfail++;
5452 		else
5453 			stats->rts++;
5454 	}
5455 
5456 	if (mac->mac_flags & BWN_MAC_FLAG_DMA) {
5457 		bwn_dma_handle_txeof(mac, status);
5458 	} else {
5459 		bwn_pio_handle_txeof(mac, status);
5460 	}
5461 
5462 	bwn_phy_txpower_check(mac, 0);
5463 }
5464 
5465 static uint8_t
5466 bwn_pio_rxeof(struct bwn_pio_rxqueue *prq)
5467 {
5468 	struct bwn_mac *mac = prq->prq_mac;
5469 	struct bwn_softc *sc = mac->mac_sc;
5470 	struct bwn_rxhdr4 rxhdr;
5471 	struct mbuf *m;
5472 	uint32_t ctl32, macstat, v32;
5473 	unsigned int i, padding;
5474 	uint16_t ctl16, len, totlen, v16;
5475 	unsigned char *mp;
5476 	char *data;
5477 
5478 	memset(&rxhdr, 0, sizeof(rxhdr));
5479 
5480 	if (prq->prq_rev >= 8) {
5481 		ctl32 = bwn_pio_rx_read_4(prq, BWN_PIO8_RXCTL);
5482 		if (!(ctl32 & BWN_PIO8_RXCTL_FRAMEREADY))
5483 			return (0);
5484 		bwn_pio_rx_write_4(prq, BWN_PIO8_RXCTL,
5485 		    BWN_PIO8_RXCTL_FRAMEREADY);
5486 		for (i = 0; i < 10; i++) {
5487 			ctl32 = bwn_pio_rx_read_4(prq, BWN_PIO8_RXCTL);
5488 			if (ctl32 & BWN_PIO8_RXCTL_DATAREADY)
5489 				goto ready;
5490 			DELAY(10);
5491 		}
5492 	} else {
5493 		ctl16 = bwn_pio_rx_read_2(prq, BWN_PIO_RXCTL);
5494 		if (!(ctl16 & BWN_PIO_RXCTL_FRAMEREADY))
5495 			return (0);
5496 		bwn_pio_rx_write_2(prq, BWN_PIO_RXCTL,
5497 		    BWN_PIO_RXCTL_FRAMEREADY);
5498 		for (i = 0; i < 10; i++) {
5499 			ctl16 = bwn_pio_rx_read_2(prq, BWN_PIO_RXCTL);
5500 			if (ctl16 & BWN_PIO_RXCTL_DATAREADY)
5501 				goto ready;
5502 			DELAY(10);
5503 		}
5504 	}
5505 	device_printf(sc->sc_dev, "%s: timed out\n", __func__);
5506 	return (1);
5507 ready:
5508 	if (prq->prq_rev >= 8)
5509 		siba_read_multi_4(sc->sc_dev, &rxhdr, sizeof(rxhdr),
5510 		    prq->prq_base + BWN_PIO8_RXDATA);
5511 	else
5512 		siba_read_multi_2(sc->sc_dev, &rxhdr, sizeof(rxhdr),
5513 		    prq->prq_base + BWN_PIO_RXDATA);
5514 	len = le16toh(rxhdr.frame_len);
5515 	if (len > 0x700) {
5516 		device_printf(sc->sc_dev, "%s: len is too big\n", __func__);
5517 		goto error;
5518 	}
5519 	if (len == 0) {
5520 		device_printf(sc->sc_dev, "%s: len is 0\n", __func__);
5521 		goto error;
5522 	}
5523 
5524 	switch (mac->mac_fw.fw_hdr_format) {
5525 	case BWN_FW_HDR_351:
5526 	case BWN_FW_HDR_410:
5527 		macstat = le32toh(rxhdr.ps4.r351.mac_status);
5528 		break;
5529 	case BWN_FW_HDR_598:
5530 		macstat = le32toh(rxhdr.ps4.r598.mac_status);
5531 		break;
5532 	}
5533 
5534 	if (macstat & BWN_RX_MAC_FCSERR) {
5535 		if (!(mac->mac_sc->sc_filters & BWN_MACCTL_PASS_BADFCS)) {
5536 			device_printf(sc->sc_dev, "%s: FCS error", __func__);
5537 			goto error;
5538 		}
5539 	}
5540 
5541 	padding = (macstat & BWN_RX_MAC_PADDING) ? 2 : 0;
5542 	totlen = len + padding;
5543 	KASSERT(totlen <= MCLBYTES, ("too big..\n"));
5544 	m = m_getcl(M_NOWAIT, MT_DATA, M_PKTHDR);
5545 	if (m == NULL) {
5546 		device_printf(sc->sc_dev, "%s: out of memory", __func__);
5547 		goto error;
5548 	}
5549 	mp = mtod(m, unsigned char *);
5550 	if (prq->prq_rev >= 8) {
5551 		siba_read_multi_4(sc->sc_dev, mp, (totlen & ~3),
5552 		    prq->prq_base + BWN_PIO8_RXDATA);
5553 		if (totlen & 3) {
5554 			v32 = bwn_pio_rx_read_4(prq, BWN_PIO8_RXDATA);
5555 			data = &(mp[totlen - 1]);
5556 			switch (totlen & 3) {
5557 			case 3:
5558 				*data = (v32 >> 16);
5559 				data--;
5560 			case 2:
5561 				*data = (v32 >> 8);
5562 				data--;
5563 			case 1:
5564 				*data = v32;
5565 			}
5566 		}
5567 	} else {
5568 		siba_read_multi_2(sc->sc_dev, mp, (totlen & ~1),
5569 		    prq->prq_base + BWN_PIO_RXDATA);
5570 		if (totlen & 1) {
5571 			v16 = bwn_pio_rx_read_2(prq, BWN_PIO_RXDATA);
5572 			mp[totlen - 1] = v16;
5573 		}
5574 	}
5575 
5576 	m->m_len = m->m_pkthdr.len = totlen;
5577 
5578 	bwn_rxeof(prq->prq_mac, m, &rxhdr);
5579 
5580 	return (1);
5581 error:
5582 	if (prq->prq_rev >= 8)
5583 		bwn_pio_rx_write_4(prq, BWN_PIO8_RXCTL,
5584 		    BWN_PIO8_RXCTL_DATAREADY);
5585 	else
5586 		bwn_pio_rx_write_2(prq, BWN_PIO_RXCTL, BWN_PIO_RXCTL_DATAREADY);
5587 	return (1);
5588 }
5589 
5590 static int
5591 bwn_dma_newbuf(struct bwn_dma_ring *dr, struct bwn_dmadesc_generic *desc,
5592     struct bwn_dmadesc_meta *meta, int init)
5593 {
5594 	struct bwn_mac *mac = dr->dr_mac;
5595 	struct bwn_dma *dma = &mac->mac_method.dma;
5596 	struct bwn_rxhdr4 *hdr;
5597 	bus_dmamap_t map;
5598 	bus_addr_t paddr;
5599 	struct mbuf *m;
5600 	int error;
5601 
5602 	m = m_getcl(M_NOWAIT, MT_DATA, M_PKTHDR);
5603 	if (m == NULL) {
5604 		error = ENOBUFS;
5605 
5606 		/*
5607 		 * If the NIC is up and running, we need to:
5608 		 * - Clear RX buffer's header.
5609 		 * - Restore RX descriptor settings.
5610 		 */
5611 		if (init)
5612 			return (error);
5613 		else
5614 			goto back;
5615 	}
5616 	m->m_len = m->m_pkthdr.len = MCLBYTES;
5617 
5618 	bwn_dma_set_redzone(dr, m);
5619 
5620 	/*
5621 	 * Try to load RX buf into temporary DMA map
5622 	 */
5623 	error = bus_dmamap_load_mbuf(dma->rxbuf_dtag, dr->dr_spare_dmap, m,
5624 	    bwn_dma_buf_addr, &paddr, BUS_DMA_NOWAIT);
5625 	if (error) {
5626 		m_freem(m);
5627 
5628 		/*
5629 		 * See the comment above
5630 		 */
5631 		if (init)
5632 			return (error);
5633 		else
5634 			goto back;
5635 	}
5636 
5637 	if (!init)
5638 		bus_dmamap_unload(dma->rxbuf_dtag, meta->mt_dmap);
5639 	meta->mt_m = m;
5640 	meta->mt_paddr = paddr;
5641 
5642 	/*
5643 	 * Swap RX buf's DMA map with the loaded temporary one
5644 	 */
5645 	map = meta->mt_dmap;
5646 	meta->mt_dmap = dr->dr_spare_dmap;
5647 	dr->dr_spare_dmap = map;
5648 
5649 back:
5650 	/*
5651 	 * Clear RX buf header
5652 	 */
5653 	hdr = mtod(meta->mt_m, struct bwn_rxhdr4 *);
5654 	bzero(hdr, sizeof(*hdr));
5655 	bus_dmamap_sync(dma->rxbuf_dtag, meta->mt_dmap,
5656 	    BUS_DMASYNC_PREWRITE);
5657 
5658 	/*
5659 	 * Setup RX buf descriptor
5660 	 */
5661 	dr->setdesc(dr, desc, meta->mt_paddr, meta->mt_m->m_len -
5662 	    sizeof(*hdr), 0, 0, 0);
5663 	return (error);
5664 }
5665 
5666 static void
5667 bwn_dma_buf_addr(void *arg, bus_dma_segment_t *seg, int nseg,
5668 		 bus_size_t mapsz __unused, int error)
5669 {
5670 
5671 	if (!error) {
5672 		KASSERT(nseg == 1, ("too many segments(%d)\n", nseg));
5673 		*((bus_addr_t *)arg) = seg->ds_addr;
5674 	}
5675 }
5676 
5677 static int
5678 bwn_hwrate2ieeerate(int rate)
5679 {
5680 
5681 	switch (rate) {
5682 	case BWN_CCK_RATE_1MB:
5683 		return (2);
5684 	case BWN_CCK_RATE_2MB:
5685 		return (4);
5686 	case BWN_CCK_RATE_5MB:
5687 		return (11);
5688 	case BWN_CCK_RATE_11MB:
5689 		return (22);
5690 	case BWN_OFDM_RATE_6MB:
5691 		return (12);
5692 	case BWN_OFDM_RATE_9MB:
5693 		return (18);
5694 	case BWN_OFDM_RATE_12MB:
5695 		return (24);
5696 	case BWN_OFDM_RATE_18MB:
5697 		return (36);
5698 	case BWN_OFDM_RATE_24MB:
5699 		return (48);
5700 	case BWN_OFDM_RATE_36MB:
5701 		return (72);
5702 	case BWN_OFDM_RATE_48MB:
5703 		return (96);
5704 	case BWN_OFDM_RATE_54MB:
5705 		return (108);
5706 	default:
5707 		printf("Ooops\n");
5708 		return (0);
5709 	}
5710 }
5711 
5712 /*
5713  * Post process the RX provided RSSI.
5714  *
5715  * Valid for A, B, G, LP PHYs.
5716  */
5717 static int8_t
5718 bwn_rx_rssi_calc(struct bwn_mac *mac, uint8_t in_rssi,
5719     int ofdm, int adjust_2053, int adjust_2050)
5720 {
5721 	struct bwn_phy *phy = &mac->mac_phy;
5722 	struct bwn_phy_g *gphy = &phy->phy_g;
5723 	int tmp;
5724 
5725 	switch (phy->rf_ver) {
5726 	case 0x2050:
5727 		if (ofdm) {
5728 			tmp = in_rssi;
5729 			if (tmp > 127)
5730 				tmp -= 256;
5731 			tmp = tmp * 73 / 64;
5732 			if (adjust_2050)
5733 				tmp += 25;
5734 			else
5735 				tmp -= 3;
5736 		} else {
5737 			if (siba_sprom_get_bf_lo(mac->mac_sc->sc_dev)
5738 			    & BWN_BFL_RSSI) {
5739 				if (in_rssi > 63)
5740 					in_rssi = 63;
5741 				tmp = gphy->pg_nrssi_lt[in_rssi];
5742 				tmp = (31 - tmp) * -131 / 128 - 57;
5743 			} else {
5744 				tmp = in_rssi;
5745 				tmp = (31 - tmp) * -149 / 128 - 68;
5746 			}
5747 			if (phy->type == BWN_PHYTYPE_G && adjust_2050)
5748 				tmp += 25;
5749 		}
5750 		break;
5751 	case 0x2060:
5752 		if (in_rssi > 127)
5753 			tmp = in_rssi - 256;
5754 		else
5755 			tmp = in_rssi;
5756 		break;
5757 	default:
5758 		tmp = in_rssi;
5759 		tmp = (tmp - 11) * 103 / 64;
5760 		if (adjust_2053)
5761 			tmp -= 109;
5762 		else
5763 			tmp -= 83;
5764 	}
5765 
5766 	return (tmp);
5767 }
5768 
5769 static void
5770 bwn_rxeof(struct bwn_mac *mac, struct mbuf *m, const void *_rxhdr)
5771 {
5772 	const struct bwn_rxhdr4 *rxhdr = _rxhdr;
5773 	struct bwn_plcp6 *plcp;
5774 	struct bwn_softc *sc = mac->mac_sc;
5775 	struct ieee80211_frame_min *wh;
5776 	struct ieee80211_node *ni;
5777 	struct ieee80211com *ic = &sc->sc_ic;
5778 	uint32_t macstat;
5779 	int padding, rate, rssi = 0, noise = 0, type;
5780 	uint16_t phytype, phystat0, phystat3, chanstat;
5781 	unsigned char *mp = mtod(m, unsigned char *);
5782 	static int rx_mac_dec_rpt = 0;
5783 
5784 	BWN_ASSERT_LOCKED(sc);
5785 
5786 	phystat0 = le16toh(rxhdr->phy_status0);
5787 
5788 	/*
5789 	 * XXX Note: phy_status3 doesn't exist for HT-PHY; it's only
5790 	 * used for LP-PHY.
5791 	 */
5792 	phystat3 = le16toh(rxhdr->ps3.lp.phy_status3);
5793 
5794 	switch (mac->mac_fw.fw_hdr_format) {
5795 	case BWN_FW_HDR_351:
5796 	case BWN_FW_HDR_410:
5797 		macstat = le32toh(rxhdr->ps4.r351.mac_status);
5798 		chanstat = le16toh(rxhdr->ps4.r351.channel);
5799 		break;
5800 	case BWN_FW_HDR_598:
5801 		macstat = le32toh(rxhdr->ps4.r598.mac_status);
5802 		chanstat = le16toh(rxhdr->ps4.r598.channel);
5803 		break;
5804 	}
5805 
5806 
5807 	phytype = chanstat & BWN_RX_CHAN_PHYTYPE;
5808 
5809 	if (macstat & BWN_RX_MAC_FCSERR)
5810 		device_printf(sc->sc_dev, "TODO RX: RX_FLAG_FAILED_FCS_CRC\n");
5811 	if (phystat0 & (BWN_RX_PHYST0_PLCPHCF | BWN_RX_PHYST0_PLCPFV))
5812 		device_printf(sc->sc_dev, "TODO RX: RX_FLAG_FAILED_PLCP_CRC\n");
5813 	if (macstat & BWN_RX_MAC_DECERR)
5814 		goto drop;
5815 
5816 	padding = (macstat & BWN_RX_MAC_PADDING) ? 2 : 0;
5817 	if (m->m_pkthdr.len < (sizeof(struct bwn_plcp6) + padding)) {
5818 		device_printf(sc->sc_dev, "frame too short (length=%d)\n",
5819 		    m->m_pkthdr.len);
5820 		goto drop;
5821 	}
5822 	plcp = (struct bwn_plcp6 *)(mp + padding);
5823 	m_adj(m, sizeof(struct bwn_plcp6) + padding);
5824 	if (m->m_pkthdr.len < IEEE80211_MIN_LEN) {
5825 		device_printf(sc->sc_dev, "frame too short (length=%d)\n",
5826 		    m->m_pkthdr.len);
5827 		goto drop;
5828 	}
5829 	wh = mtod(m, struct ieee80211_frame_min *);
5830 
5831 	if (macstat & BWN_RX_MAC_DEC && rx_mac_dec_rpt++ < 50)
5832 		device_printf(sc->sc_dev,
5833 		    "RX decryption attempted (old %d keyidx %#x)\n",
5834 		    BWN_ISOLDFMT(mac),
5835 		    (macstat & BWN_RX_MAC_KEYIDX) >> BWN_RX_MAC_KEYIDX_SHIFT);
5836 
5837 	if (phystat0 & BWN_RX_PHYST0_OFDM)
5838 		rate = bwn_plcp_get_ofdmrate(mac, plcp,
5839 		    phytype == BWN_PHYTYPE_A);
5840 	else
5841 		rate = bwn_plcp_get_cckrate(mac, plcp);
5842 	if (rate == -1) {
5843 		if (!(mac->mac_sc->sc_filters & BWN_MACCTL_PASS_BADPLCP))
5844 			goto drop;
5845 	}
5846 	sc->sc_rx_rate = bwn_hwrate2ieeerate(rate);
5847 
5848 	/* rssi/noise */
5849 	switch (phytype) {
5850 	case BWN_PHYTYPE_A:
5851 	case BWN_PHYTYPE_B:
5852 	case BWN_PHYTYPE_G:
5853 	case BWN_PHYTYPE_LP:
5854 		rssi = bwn_rx_rssi_calc(mac, rxhdr->phy.abg.rssi,
5855 		    !! (phystat0 & BWN_RX_PHYST0_OFDM),
5856 		    !! (phystat0 & BWN_RX_PHYST0_GAINCTL),
5857 		    !! (phystat3 & BWN_RX_PHYST3_TRSTATE));
5858 		break;
5859 	case BWN_PHYTYPE_N:
5860 		/* Broadcom has code for min/avg, but always used max */
5861 		if (rxhdr->phy.n.power0 == 16 || rxhdr->phy.n.power0 == 32)
5862 			rssi = max(rxhdr->phy.n.power1, rxhdr->ps2.n.power2);
5863 		else
5864 			rssi = max(rxhdr->phy.n.power0, rxhdr->phy.n.power1);
5865 #if 0
5866 		DPRINTF(mac->mac_sc, BWN_DEBUG_RECV,
5867 		    "%s: power0=%d, power1=%d, power2=%d\n",
5868 		    __func__,
5869 		    rxhdr->phy.n.power0,
5870 		    rxhdr->phy.n.power1,
5871 		    rxhdr->ps2.n.power2);
5872 #endif
5873 		break;
5874 	default:
5875 		/* XXX TODO: implement rssi for other PHYs */
5876 		break;
5877 	}
5878 
5879 	/*
5880 	 * RSSI here is absolute, not relative to the noise floor.
5881 	 */
5882 	noise = mac->mac_stats.link_noise;
5883 	rssi = rssi - noise;
5884 
5885 	/* RX radio tap */
5886 	if (ieee80211_radiotap_active(ic))
5887 		bwn_rx_radiotap(mac, m, rxhdr, plcp, rate, rssi, noise);
5888 	m_adj(m, -IEEE80211_CRC_LEN);
5889 
5890 	BWN_UNLOCK(sc);
5891 
5892 	ni = ieee80211_find_rxnode(ic, wh);
5893 	if (ni != NULL) {
5894 		type = ieee80211_input(ni, m, rssi, noise);
5895 		ieee80211_free_node(ni);
5896 	} else
5897 		type = ieee80211_input_all(ic, m, rssi, noise);
5898 
5899 	BWN_LOCK(sc);
5900 	return;
5901 drop:
5902 	device_printf(sc->sc_dev, "%s: dropped\n", __func__);
5903 }
5904 
5905 static void
5906 bwn_ratectl_tx_complete(const struct ieee80211_node *ni,
5907     const struct bwn_txstatus *status)
5908 {
5909 	struct ieee80211_ratectl_tx_status txs;
5910 	int retrycnt = 0;
5911 
5912 	/*
5913 	 * If we don't get an ACK, then we should log the
5914 	 * full framecnt.  That may be 0 if it's a PHY
5915 	 * failure, so ensure that gets logged as some
5916 	 * retry attempt.
5917 	 */
5918 	txs.flags = IEEE80211_RATECTL_STATUS_LONG_RETRY;
5919 	if (status->ack) {
5920 		txs.status = IEEE80211_RATECTL_TX_SUCCESS;
5921 		retrycnt = status->framecnt - 1;
5922 	} else {
5923 		txs.status = IEEE80211_RATECTL_TX_FAIL_UNSPECIFIED;
5924 		retrycnt = status->framecnt;
5925 		if (retrycnt == 0)
5926 			retrycnt = 1;
5927 	}
5928 	txs.long_retries = retrycnt;
5929 	ieee80211_ratectl_tx_complete(ni, &txs);
5930 }
5931 
5932 static void
5933 bwn_dma_handle_txeof(struct bwn_mac *mac,
5934     const struct bwn_txstatus *status)
5935 {
5936 	struct bwn_dma *dma = &mac->mac_method.dma;
5937 	struct bwn_dma_ring *dr;
5938 	struct bwn_dmadesc_generic *desc;
5939 	struct bwn_dmadesc_meta *meta;
5940 	struct bwn_softc *sc = mac->mac_sc;
5941 	int slot;
5942 
5943 	BWN_ASSERT_LOCKED(sc);
5944 
5945 	dr = bwn_dma_parse_cookie(mac, status, status->cookie, &slot);
5946 	if (dr == NULL) {
5947 		device_printf(sc->sc_dev, "failed to parse cookie\n");
5948 		return;
5949 	}
5950 	KASSERT(dr->dr_tx, ("%s:%d: fail", __func__, __LINE__));
5951 
5952 	while (1) {
5953 		KASSERT(slot >= 0 && slot < dr->dr_numslots,
5954 		    ("%s:%d: fail", __func__, __LINE__));
5955 		dr->getdesc(dr, slot, &desc, &meta);
5956 
5957 		if (meta->mt_txtype == BWN_DMADESC_METATYPE_HEADER)
5958 			bus_dmamap_unload(dr->dr_txring_dtag, meta->mt_dmap);
5959 		else if (meta->mt_txtype == BWN_DMADESC_METATYPE_BODY)
5960 			bus_dmamap_unload(dma->txbuf_dtag, meta->mt_dmap);
5961 
5962 		if (meta->mt_islast) {
5963 			KASSERT(meta->mt_m != NULL,
5964 			    ("%s:%d: fail", __func__, __LINE__));
5965 
5966 			bwn_ratectl_tx_complete(meta->mt_ni, status);
5967 			ieee80211_tx_complete(meta->mt_ni, meta->mt_m, 0);
5968 			meta->mt_ni = NULL;
5969 			meta->mt_m = NULL;
5970 		} else
5971 			KASSERT(meta->mt_m == NULL,
5972 			    ("%s:%d: fail", __func__, __LINE__));
5973 
5974 		dr->dr_usedslot--;
5975 		if (meta->mt_islast)
5976 			break;
5977 		slot = bwn_dma_nextslot(dr, slot);
5978 	}
5979 	sc->sc_watchdog_timer = 0;
5980 	if (dr->dr_stop) {
5981 		KASSERT(bwn_dma_freeslot(dr) >= BWN_TX_SLOTS_PER_FRAME,
5982 		    ("%s:%d: fail", __func__, __LINE__));
5983 		dr->dr_stop = 0;
5984 	}
5985 }
5986 
5987 static void
5988 bwn_pio_handle_txeof(struct bwn_mac *mac,
5989     const struct bwn_txstatus *status)
5990 {
5991 	struct bwn_pio_txqueue *tq;
5992 	struct bwn_pio_txpkt *tp = NULL;
5993 	struct bwn_softc *sc = mac->mac_sc;
5994 
5995 	BWN_ASSERT_LOCKED(sc);
5996 
5997 	tq = bwn_pio_parse_cookie(mac, status->cookie, &tp);
5998 	if (tq == NULL)
5999 		return;
6000 
6001 	tq->tq_used -= roundup(tp->tp_m->m_pkthdr.len + BWN_HDRSIZE(mac), 4);
6002 	tq->tq_free++;
6003 
6004 	/* XXX ieee80211_tx_complete()? */
6005 	if (tp->tp_ni != NULL) {
6006 		/*
6007 		 * Do any tx complete callback.  Note this must
6008 		 * be done before releasing the node reference.
6009 		 */
6010 
6011 		bwn_ratectl_tx_complete(tp->tp_ni, status);
6012 		if (tp->tp_m->m_flags & M_TXCB)
6013 			ieee80211_process_callback(tp->tp_ni, tp->tp_m, 0);
6014 		ieee80211_free_node(tp->tp_ni);
6015 		tp->tp_ni = NULL;
6016 	}
6017 	m_freem(tp->tp_m);
6018 	tp->tp_m = NULL;
6019 	TAILQ_INSERT_TAIL(&tq->tq_pktlist, tp, tp_list);
6020 
6021 	sc->sc_watchdog_timer = 0;
6022 }
6023 
6024 static void
6025 bwn_phy_txpower_check(struct bwn_mac *mac, uint32_t flags)
6026 {
6027 	struct bwn_softc *sc = mac->mac_sc;
6028 	struct bwn_phy *phy = &mac->mac_phy;
6029 	struct ieee80211com *ic = &sc->sc_ic;
6030 	unsigned long now;
6031 	bwn_txpwr_result_t result;
6032 
6033 	BWN_GETTIME(now);
6034 
6035 	if (!(flags & BWN_TXPWR_IGNORE_TIME) && ieee80211_time_before(now, phy->nexttime))
6036 		return;
6037 	phy->nexttime = now + 2 * 1000;
6038 
6039 	if (siba_get_pci_subvendor(sc->sc_dev) == SIBA_BOARDVENDOR_BCM &&
6040 	    siba_get_pci_subdevice(sc->sc_dev) == SIBA_BOARD_BU4306)
6041 		return;
6042 
6043 	if (phy->recalc_txpwr != NULL) {
6044 		result = phy->recalc_txpwr(mac,
6045 		    (flags & BWN_TXPWR_IGNORE_TSSI) ? 1 : 0);
6046 		if (result == BWN_TXPWR_RES_DONE)
6047 			return;
6048 		KASSERT(result == BWN_TXPWR_RES_NEED_ADJUST,
6049 		    ("%s: fail", __func__));
6050 		KASSERT(phy->set_txpwr != NULL, ("%s: fail", __func__));
6051 
6052 		ieee80211_runtask(ic, &mac->mac_txpower);
6053 	}
6054 }
6055 
6056 static uint16_t
6057 bwn_pio_rx_read_2(struct bwn_pio_rxqueue *prq, uint16_t offset)
6058 {
6059 
6060 	return (BWN_READ_2(prq->prq_mac, prq->prq_base + offset));
6061 }
6062 
6063 static uint32_t
6064 bwn_pio_rx_read_4(struct bwn_pio_rxqueue *prq, uint16_t offset)
6065 {
6066 
6067 	return (BWN_READ_4(prq->prq_mac, prq->prq_base + offset));
6068 }
6069 
6070 static void
6071 bwn_pio_rx_write_2(struct bwn_pio_rxqueue *prq, uint16_t offset, uint16_t value)
6072 {
6073 
6074 	BWN_WRITE_2(prq->prq_mac, prq->prq_base + offset, value);
6075 }
6076 
6077 static void
6078 bwn_pio_rx_write_4(struct bwn_pio_rxqueue *prq, uint16_t offset, uint32_t value)
6079 {
6080 
6081 	BWN_WRITE_4(prq->prq_mac, prq->prq_base + offset, value);
6082 }
6083 
6084 static int
6085 bwn_ieeerate2hwrate(struct bwn_softc *sc, int rate)
6086 {
6087 
6088 	switch (rate) {
6089 	/* OFDM rates (cf IEEE Std 802.11a-1999, pp. 14 Table 80) */
6090 	case 12:
6091 		return (BWN_OFDM_RATE_6MB);
6092 	case 18:
6093 		return (BWN_OFDM_RATE_9MB);
6094 	case 24:
6095 		return (BWN_OFDM_RATE_12MB);
6096 	case 36:
6097 		return (BWN_OFDM_RATE_18MB);
6098 	case 48:
6099 		return (BWN_OFDM_RATE_24MB);
6100 	case 72:
6101 		return (BWN_OFDM_RATE_36MB);
6102 	case 96:
6103 		return (BWN_OFDM_RATE_48MB);
6104 	case 108:
6105 		return (BWN_OFDM_RATE_54MB);
6106 	/* CCK rates (NB: not IEEE std, device-specific) */
6107 	case 2:
6108 		return (BWN_CCK_RATE_1MB);
6109 	case 4:
6110 		return (BWN_CCK_RATE_2MB);
6111 	case 11:
6112 		return (BWN_CCK_RATE_5MB);
6113 	case 22:
6114 		return (BWN_CCK_RATE_11MB);
6115 	}
6116 
6117 	device_printf(sc->sc_dev, "unsupported rate %d\n", rate);
6118 	return (BWN_CCK_RATE_1MB);
6119 }
6120 
6121 static uint16_t
6122 bwn_set_txhdr_phyctl1(struct bwn_mac *mac, uint8_t bitrate)
6123 {
6124 	struct bwn_phy *phy = &mac->mac_phy;
6125 	uint16_t control = 0;
6126 	uint16_t bw;
6127 
6128 	/* XXX TODO: this is for LP phy, what about N-PHY, etc? */
6129 	bw = BWN_TXH_PHY1_BW_20;
6130 
6131 	if (BWN_ISCCKRATE(bitrate) && phy->type != BWN_PHYTYPE_LP) {
6132 		control = bw;
6133 	} else {
6134 		control = bw;
6135 		/* Figure out coding rate and modulation */
6136 		/* XXX TODO: table-ize, for MCS transmit */
6137 		/* Note: this is BWN_*_RATE values */
6138 		switch (bitrate) {
6139 		case BWN_CCK_RATE_1MB:
6140 			control |= 0;
6141 			break;
6142 		case BWN_CCK_RATE_2MB:
6143 			control |= 1;
6144 			break;
6145 		case BWN_CCK_RATE_5MB:
6146 			control |= 2;
6147 			break;
6148 		case BWN_CCK_RATE_11MB:
6149 			control |= 3;
6150 			break;
6151 		case BWN_OFDM_RATE_6MB:
6152 			control |= BWN_TXH_PHY1_CRATE_1_2;
6153 			control |= BWN_TXH_PHY1_MODUL_BPSK;
6154 			break;
6155 		case BWN_OFDM_RATE_9MB:
6156 			control |= BWN_TXH_PHY1_CRATE_3_4;
6157 			control |= BWN_TXH_PHY1_MODUL_BPSK;
6158 			break;
6159 		case BWN_OFDM_RATE_12MB:
6160 			control |= BWN_TXH_PHY1_CRATE_1_2;
6161 			control |= BWN_TXH_PHY1_MODUL_QPSK;
6162 			break;
6163 		case BWN_OFDM_RATE_18MB:
6164 			control |= BWN_TXH_PHY1_CRATE_3_4;
6165 			control |= BWN_TXH_PHY1_MODUL_QPSK;
6166 			break;
6167 		case BWN_OFDM_RATE_24MB:
6168 			control |= BWN_TXH_PHY1_CRATE_1_2;
6169 			control |= BWN_TXH_PHY1_MODUL_QAM16;
6170 			break;
6171 		case BWN_OFDM_RATE_36MB:
6172 			control |= BWN_TXH_PHY1_CRATE_3_4;
6173 			control |= BWN_TXH_PHY1_MODUL_QAM16;
6174 			break;
6175 		case BWN_OFDM_RATE_48MB:
6176 			control |= BWN_TXH_PHY1_CRATE_1_2;
6177 			control |= BWN_TXH_PHY1_MODUL_QAM64;
6178 			break;
6179 		case BWN_OFDM_RATE_54MB:
6180 			control |= BWN_TXH_PHY1_CRATE_3_4;
6181 			control |= BWN_TXH_PHY1_MODUL_QAM64;
6182 			break;
6183 		default:
6184 			break;
6185 		}
6186 		control |= BWN_TXH_PHY1_MODE_SISO;
6187 	}
6188 
6189 	return control;
6190 }
6191 
6192 static int
6193 bwn_set_txhdr(struct bwn_mac *mac, struct ieee80211_node *ni,
6194     struct mbuf *m, struct bwn_txhdr *txhdr, uint16_t cookie)
6195 {
6196 	const struct bwn_phy *phy = &mac->mac_phy;
6197 	struct bwn_softc *sc = mac->mac_sc;
6198 	struct ieee80211_frame *wh;
6199 	struct ieee80211_frame *protwh;
6200 	struct ieee80211_frame_cts *cts;
6201 	struct ieee80211_frame_rts *rts;
6202 	const struct ieee80211_txparam *tp = ni->ni_txparms;
6203 	struct ieee80211vap *vap = ni->ni_vap;
6204 	struct ieee80211com *ic = &sc->sc_ic;
6205 	struct mbuf *mprot;
6206 	unsigned int len;
6207 	uint32_t macctl = 0;
6208 	int protdur, rts_rate, rts_rate_fb, ismcast, isshort, rix, type;
6209 	uint16_t phyctl = 0;
6210 	uint8_t rate, rate_fb;
6211 	int fill_phy_ctl1 = 0;
6212 
6213 	wh = mtod(m, struct ieee80211_frame *);
6214 	memset(txhdr, 0, sizeof(*txhdr));
6215 
6216 	type = wh->i_fc[0] & IEEE80211_FC0_TYPE_MASK;
6217 	ismcast = IEEE80211_IS_MULTICAST(wh->i_addr1);
6218 	isshort = (ic->ic_flags & IEEE80211_F_SHPREAMBLE) != 0;
6219 
6220 	if ((phy->type == BWN_PHYTYPE_N) || (phy->type == BWN_PHYTYPE_LP)
6221 	    || (phy->type == BWN_PHYTYPE_HT))
6222 		fill_phy_ctl1 = 1;
6223 
6224 	/*
6225 	 * Find TX rate
6226 	 */
6227 	if (type != IEEE80211_FC0_TYPE_DATA || (m->m_flags & M_EAPOL))
6228 		rate = rate_fb = tp->mgmtrate;
6229 	else if (ismcast)
6230 		rate = rate_fb = tp->mcastrate;
6231 	else if (tp->ucastrate != IEEE80211_FIXED_RATE_NONE)
6232 		rate = rate_fb = tp->ucastrate;
6233 	else {
6234 		rix = ieee80211_ratectl_rate(ni, NULL, 0);
6235 		rate = ni->ni_txrate;
6236 
6237 		if (rix > 0)
6238 			rate_fb = ni->ni_rates.rs_rates[rix - 1] &
6239 			    IEEE80211_RATE_VAL;
6240 		else
6241 			rate_fb = rate;
6242 	}
6243 
6244 	sc->sc_tx_rate = rate;
6245 
6246 	/* Note: this maps the select ieee80211 rate to hardware rate */
6247 	rate = bwn_ieeerate2hwrate(sc, rate);
6248 	rate_fb = bwn_ieeerate2hwrate(sc, rate_fb);
6249 
6250 	txhdr->phyrate = (BWN_ISOFDMRATE(rate)) ? bwn_plcp_getofdm(rate) :
6251 	    bwn_plcp_getcck(rate);
6252 	bcopy(wh->i_fc, txhdr->macfc, sizeof(txhdr->macfc));
6253 	bcopy(wh->i_addr1, txhdr->addr1, IEEE80211_ADDR_LEN);
6254 
6255 	/* XXX rate/rate_fb is the hardware rate */
6256 	if ((rate_fb == rate) ||
6257 	    (*(u_int16_t *)wh->i_dur & htole16(0x8000)) ||
6258 	    (*(u_int16_t *)wh->i_dur == htole16(0)))
6259 		txhdr->dur_fb = *(u_int16_t *)wh->i_dur;
6260 	else
6261 		txhdr->dur_fb = ieee80211_compute_duration(ic->ic_rt,
6262 		    m->m_pkthdr.len, rate, isshort);
6263 
6264 	/* XXX TX encryption */
6265 
6266 	switch (mac->mac_fw.fw_hdr_format) {
6267 	case BWN_FW_HDR_351:
6268 		bwn_plcp_genhdr((struct bwn_plcp4 *)(&txhdr->body.r351.plcp),
6269 		    m->m_pkthdr.len + IEEE80211_CRC_LEN, rate);
6270 		break;
6271 	case BWN_FW_HDR_410:
6272 		bwn_plcp_genhdr((struct bwn_plcp4 *)(&txhdr->body.r410.plcp),
6273 		    m->m_pkthdr.len + IEEE80211_CRC_LEN, rate);
6274 		break;
6275 	case BWN_FW_HDR_598:
6276 		bwn_plcp_genhdr((struct bwn_plcp4 *)(&txhdr->body.r598.plcp),
6277 		    m->m_pkthdr.len + IEEE80211_CRC_LEN, rate);
6278 		break;
6279 	}
6280 
6281 	bwn_plcp_genhdr((struct bwn_plcp4 *)(&txhdr->plcp_fb),
6282 	    m->m_pkthdr.len + IEEE80211_CRC_LEN, rate_fb);
6283 
6284 	txhdr->eftypes |= (BWN_ISOFDMRATE(rate_fb)) ? BWN_TX_EFT_FB_OFDM :
6285 	    BWN_TX_EFT_FB_CCK;
6286 	txhdr->chan = phy->chan;
6287 	phyctl |= (BWN_ISOFDMRATE(rate)) ? BWN_TX_PHY_ENC_OFDM :
6288 	    BWN_TX_PHY_ENC_CCK;
6289 	/* XXX preamble? obey net80211 */
6290 	if (isshort && (rate == BWN_CCK_RATE_2MB || rate == BWN_CCK_RATE_5MB ||
6291 	     rate == BWN_CCK_RATE_11MB))
6292 		phyctl |= BWN_TX_PHY_SHORTPRMBL;
6293 
6294 	if (! phy->gmode)
6295 		macctl |= BWN_TX_MAC_5GHZ;
6296 
6297 	/* XXX TX antenna selection */
6298 
6299 	switch (bwn_antenna_sanitize(mac, 0)) {
6300 	case 0:
6301 		phyctl |= BWN_TX_PHY_ANT01AUTO;
6302 		break;
6303 	case 1:
6304 		phyctl |= BWN_TX_PHY_ANT0;
6305 		break;
6306 	case 2:
6307 		phyctl |= BWN_TX_PHY_ANT1;
6308 		break;
6309 	case 3:
6310 		phyctl |= BWN_TX_PHY_ANT2;
6311 		break;
6312 	case 4:
6313 		phyctl |= BWN_TX_PHY_ANT3;
6314 		break;
6315 	default:
6316 		KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
6317 	}
6318 
6319 	if (!ismcast)
6320 		macctl |= BWN_TX_MAC_ACK;
6321 
6322 	macctl |= (BWN_TX_MAC_HWSEQ | BWN_TX_MAC_START_MSDU);
6323 	if (!IEEE80211_IS_MULTICAST(wh->i_addr1) &&
6324 	    m->m_pkthdr.len + IEEE80211_CRC_LEN > vap->iv_rtsthreshold)
6325 		macctl |= BWN_TX_MAC_LONGFRAME;
6326 
6327 	if (ic->ic_flags & IEEE80211_F_USEPROT) {
6328 		/* Note: don't fall back to CCK rates for 5G */
6329 		if (phy->gmode)
6330 			rts_rate = BWN_CCK_RATE_1MB;
6331 		else
6332 			rts_rate = BWN_OFDM_RATE_6MB;
6333 		rts_rate_fb = bwn_get_fbrate(rts_rate);
6334 
6335 		/* XXX 'rate' here is hardware rate now, not the net80211 rate */
6336 		protdur = ieee80211_compute_duration(ic->ic_rt,
6337 		    m->m_pkthdr.len, rate, isshort) +
6338 		    + ieee80211_ack_duration(ic->ic_rt, rate, isshort);
6339 
6340 		if (ic->ic_protmode == IEEE80211_PROT_CTSONLY) {
6341 
6342 			switch (mac->mac_fw.fw_hdr_format) {
6343 			case BWN_FW_HDR_351:
6344 				cts = (struct ieee80211_frame_cts *)
6345 				    txhdr->body.r351.rts_frame;
6346 				break;
6347 			case BWN_FW_HDR_410:
6348 				cts = (struct ieee80211_frame_cts *)
6349 				    txhdr->body.r410.rts_frame;
6350 				break;
6351 			case BWN_FW_HDR_598:
6352 				cts = (struct ieee80211_frame_cts *)
6353 				    txhdr->body.r598.rts_frame;
6354 				break;
6355 			}
6356 
6357 			mprot = ieee80211_alloc_cts(ic, ni->ni_vap->iv_myaddr,
6358 			    protdur);
6359 			KASSERT(mprot != NULL, ("failed to alloc mbuf\n"));
6360 			bcopy(mtod(mprot, uint8_t *), (uint8_t *)cts,
6361 			    mprot->m_pkthdr.len);
6362 			m_freem(mprot);
6363 			macctl |= BWN_TX_MAC_SEND_CTSTOSELF;
6364 			len = sizeof(struct ieee80211_frame_cts);
6365 		} else {
6366 			switch (mac->mac_fw.fw_hdr_format) {
6367 			case BWN_FW_HDR_351:
6368 				rts = (struct ieee80211_frame_rts *)
6369 				    txhdr->body.r351.rts_frame;
6370 				break;
6371 			case BWN_FW_HDR_410:
6372 				rts = (struct ieee80211_frame_rts *)
6373 				    txhdr->body.r410.rts_frame;
6374 				break;
6375 			case BWN_FW_HDR_598:
6376 				rts = (struct ieee80211_frame_rts *)
6377 				    txhdr->body.r598.rts_frame;
6378 				break;
6379 			}
6380 
6381 			/* XXX rate/rate_fb is the hardware rate */
6382 			protdur += ieee80211_ack_duration(ic->ic_rt, rate,
6383 			    isshort);
6384 			mprot = ieee80211_alloc_rts(ic, wh->i_addr1,
6385 			    wh->i_addr2, protdur);
6386 			KASSERT(mprot != NULL, ("failed to alloc mbuf\n"));
6387 			bcopy(mtod(mprot, uint8_t *), (uint8_t *)rts,
6388 			    mprot->m_pkthdr.len);
6389 			m_freem(mprot);
6390 			macctl |= BWN_TX_MAC_SEND_RTSCTS;
6391 			len = sizeof(struct ieee80211_frame_rts);
6392 		}
6393 		len += IEEE80211_CRC_LEN;
6394 
6395 		switch (mac->mac_fw.fw_hdr_format) {
6396 		case BWN_FW_HDR_351:
6397 			bwn_plcp_genhdr((struct bwn_plcp4 *)
6398 			    &txhdr->body.r351.rts_plcp, len, rts_rate);
6399 			break;
6400 		case BWN_FW_HDR_410:
6401 			bwn_plcp_genhdr((struct bwn_plcp4 *)
6402 			    &txhdr->body.r410.rts_plcp, len, rts_rate);
6403 			break;
6404 		case BWN_FW_HDR_598:
6405 			bwn_plcp_genhdr((struct bwn_plcp4 *)
6406 			    &txhdr->body.r598.rts_plcp, len, rts_rate);
6407 			break;
6408 		}
6409 
6410 		bwn_plcp_genhdr((struct bwn_plcp4 *)&txhdr->rts_plcp_fb, len,
6411 		    rts_rate_fb);
6412 
6413 		switch (mac->mac_fw.fw_hdr_format) {
6414 		case BWN_FW_HDR_351:
6415 			protwh = (struct ieee80211_frame *)
6416 			    &txhdr->body.r351.rts_frame;
6417 			break;
6418 		case BWN_FW_HDR_410:
6419 			protwh = (struct ieee80211_frame *)
6420 			    &txhdr->body.r410.rts_frame;
6421 			break;
6422 		case BWN_FW_HDR_598:
6423 			protwh = (struct ieee80211_frame *)
6424 			    &txhdr->body.r598.rts_frame;
6425 			break;
6426 		}
6427 
6428 		txhdr->rts_dur_fb = *(u_int16_t *)protwh->i_dur;
6429 
6430 		if (BWN_ISOFDMRATE(rts_rate)) {
6431 			txhdr->eftypes |= BWN_TX_EFT_RTS_OFDM;
6432 			txhdr->phyrate_rts = bwn_plcp_getofdm(rts_rate);
6433 		} else {
6434 			txhdr->eftypes |= BWN_TX_EFT_RTS_CCK;
6435 			txhdr->phyrate_rts = bwn_plcp_getcck(rts_rate);
6436 		}
6437 		txhdr->eftypes |= (BWN_ISOFDMRATE(rts_rate_fb)) ?
6438 		    BWN_TX_EFT_RTS_FBOFDM : BWN_TX_EFT_RTS_FBCCK;
6439 
6440 		if (fill_phy_ctl1) {
6441 			txhdr->phyctl_1rts = htole16(bwn_set_txhdr_phyctl1(mac, rts_rate));
6442 			txhdr->phyctl_1rtsfb = htole16(bwn_set_txhdr_phyctl1(mac, rts_rate_fb));
6443 		}
6444 	}
6445 
6446 	if (fill_phy_ctl1) {
6447 		txhdr->phyctl_1 = htole16(bwn_set_txhdr_phyctl1(mac, rate));
6448 		txhdr->phyctl_1fb = htole16(bwn_set_txhdr_phyctl1(mac, rate_fb));
6449 	}
6450 
6451 	switch (mac->mac_fw.fw_hdr_format) {
6452 	case BWN_FW_HDR_351:
6453 		txhdr->body.r351.cookie = htole16(cookie);
6454 		break;
6455 	case BWN_FW_HDR_410:
6456 		txhdr->body.r410.cookie = htole16(cookie);
6457 		break;
6458 	case BWN_FW_HDR_598:
6459 		txhdr->body.r598.cookie = htole16(cookie);
6460 		break;
6461 	}
6462 
6463 	txhdr->macctl = htole32(macctl);
6464 	txhdr->phyctl = htole16(phyctl);
6465 
6466 	/*
6467 	 * TX radio tap
6468 	 */
6469 	if (ieee80211_radiotap_active_vap(vap)) {
6470 		sc->sc_tx_th.wt_flags = 0;
6471 		if (wh->i_fc[1] & IEEE80211_FC1_PROTECTED)
6472 			sc->sc_tx_th.wt_flags |= IEEE80211_RADIOTAP_F_WEP;
6473 		if (isshort &&
6474 		    (rate == BWN_CCK_RATE_2MB || rate == BWN_CCK_RATE_5MB ||
6475 		     rate == BWN_CCK_RATE_11MB))
6476 			sc->sc_tx_th.wt_flags |= IEEE80211_RADIOTAP_F_SHORTPRE;
6477 		sc->sc_tx_th.wt_rate = rate;
6478 
6479 		ieee80211_radiotap_tx(vap, m);
6480 	}
6481 
6482 	return (0);
6483 }
6484 
6485 static void
6486 bwn_plcp_genhdr(struct bwn_plcp4 *plcp, const uint16_t octets,
6487     const uint8_t rate)
6488 {
6489 	uint32_t d, plen;
6490 	uint8_t *raw = plcp->o.raw;
6491 
6492 	if (BWN_ISOFDMRATE(rate)) {
6493 		d = bwn_plcp_getofdm(rate);
6494 		KASSERT(!(octets & 0xf000),
6495 		    ("%s:%d: fail", __func__, __LINE__));
6496 		d |= (octets << 5);
6497 		plcp->o.data = htole32(d);
6498 	} else {
6499 		plen = octets * 16 / rate;
6500 		if ((octets * 16 % rate) > 0) {
6501 			plen++;
6502 			if ((rate == BWN_CCK_RATE_11MB)
6503 			    && ((octets * 8 % 11) < 4)) {
6504 				raw[1] = 0x84;
6505 			} else
6506 				raw[1] = 0x04;
6507 		} else
6508 			raw[1] = 0x04;
6509 		plcp->o.data |= htole32(plen << 16);
6510 		raw[0] = bwn_plcp_getcck(rate);
6511 	}
6512 }
6513 
6514 static uint8_t
6515 bwn_antenna_sanitize(struct bwn_mac *mac, uint8_t n)
6516 {
6517 	struct bwn_softc *sc = mac->mac_sc;
6518 	uint8_t mask;
6519 
6520 	if (n == 0)
6521 		return (0);
6522 	if (mac->mac_phy.gmode)
6523 		mask = siba_sprom_get_ant_bg(sc->sc_dev);
6524 	else
6525 		mask = siba_sprom_get_ant_a(sc->sc_dev);
6526 	if (!(mask & (1 << (n - 1))))
6527 		return (0);
6528 	return (n);
6529 }
6530 
6531 /*
6532  * Return a fallback rate for the given rate.
6533  *
6534  * Note: Don't fall back from OFDM to CCK.
6535  */
6536 static uint8_t
6537 bwn_get_fbrate(uint8_t bitrate)
6538 {
6539 	switch (bitrate) {
6540 	/* CCK */
6541 	case BWN_CCK_RATE_1MB:
6542 		return (BWN_CCK_RATE_1MB);
6543 	case BWN_CCK_RATE_2MB:
6544 		return (BWN_CCK_RATE_1MB);
6545 	case BWN_CCK_RATE_5MB:
6546 		return (BWN_CCK_RATE_2MB);
6547 	case BWN_CCK_RATE_11MB:
6548 		return (BWN_CCK_RATE_5MB);
6549 
6550 	/* OFDM */
6551 	case BWN_OFDM_RATE_6MB:
6552 		return (BWN_OFDM_RATE_6MB);
6553 	case BWN_OFDM_RATE_9MB:
6554 		return (BWN_OFDM_RATE_6MB);
6555 	case BWN_OFDM_RATE_12MB:
6556 		return (BWN_OFDM_RATE_9MB);
6557 	case BWN_OFDM_RATE_18MB:
6558 		return (BWN_OFDM_RATE_12MB);
6559 	case BWN_OFDM_RATE_24MB:
6560 		return (BWN_OFDM_RATE_18MB);
6561 	case BWN_OFDM_RATE_36MB:
6562 		return (BWN_OFDM_RATE_24MB);
6563 	case BWN_OFDM_RATE_48MB:
6564 		return (BWN_OFDM_RATE_36MB);
6565 	case BWN_OFDM_RATE_54MB:
6566 		return (BWN_OFDM_RATE_48MB);
6567 	}
6568 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
6569 	return (0);
6570 }
6571 
6572 static uint32_t
6573 bwn_pio_write_multi_4(struct bwn_mac *mac, struct bwn_pio_txqueue *tq,
6574     uint32_t ctl, const void *_data, int len)
6575 {
6576 	struct bwn_softc *sc = mac->mac_sc;
6577 	uint32_t value = 0;
6578 	const uint8_t *data = _data;
6579 
6580 	ctl |= BWN_PIO8_TXCTL_0_7 | BWN_PIO8_TXCTL_8_15 |
6581 	    BWN_PIO8_TXCTL_16_23 | BWN_PIO8_TXCTL_24_31;
6582 	bwn_pio_write_4(mac, tq, BWN_PIO8_TXCTL, ctl);
6583 
6584 	siba_write_multi_4(sc->sc_dev, data, (len & ~3),
6585 	    tq->tq_base + BWN_PIO8_TXDATA);
6586 	if (len & 3) {
6587 		ctl &= ~(BWN_PIO8_TXCTL_8_15 | BWN_PIO8_TXCTL_16_23 |
6588 		    BWN_PIO8_TXCTL_24_31);
6589 		data = &(data[len - 1]);
6590 		switch (len & 3) {
6591 		case 3:
6592 			ctl |= BWN_PIO8_TXCTL_16_23;
6593 			value |= (uint32_t)(*data) << 16;
6594 			data--;
6595 		case 2:
6596 			ctl |= BWN_PIO8_TXCTL_8_15;
6597 			value |= (uint32_t)(*data) << 8;
6598 			data--;
6599 		case 1:
6600 			value |= (uint32_t)(*data);
6601 		}
6602 		bwn_pio_write_4(mac, tq, BWN_PIO8_TXCTL, ctl);
6603 		bwn_pio_write_4(mac, tq, BWN_PIO8_TXDATA, value);
6604 	}
6605 
6606 	return (ctl);
6607 }
6608 
6609 static void
6610 bwn_pio_write_4(struct bwn_mac *mac, struct bwn_pio_txqueue *tq,
6611     uint16_t offset, uint32_t value)
6612 {
6613 
6614 	BWN_WRITE_4(mac, tq->tq_base + offset, value);
6615 }
6616 
6617 static uint16_t
6618 bwn_pio_write_multi_2(struct bwn_mac *mac, struct bwn_pio_txqueue *tq,
6619     uint16_t ctl, const void *_data, int len)
6620 {
6621 	struct bwn_softc *sc = mac->mac_sc;
6622 	const uint8_t *data = _data;
6623 
6624 	ctl |= BWN_PIO_TXCTL_WRITELO | BWN_PIO_TXCTL_WRITEHI;
6625 	BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXCTL, ctl);
6626 
6627 	siba_write_multi_2(sc->sc_dev, data, (len & ~1),
6628 	    tq->tq_base + BWN_PIO_TXDATA);
6629 	if (len & 1) {
6630 		ctl &= ~BWN_PIO_TXCTL_WRITEHI;
6631 		BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXCTL, ctl);
6632 		BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXDATA, data[len - 1]);
6633 	}
6634 
6635 	return (ctl);
6636 }
6637 
6638 static uint16_t
6639 bwn_pio_write_mbuf_2(struct bwn_mac *mac, struct bwn_pio_txqueue *tq,
6640     uint16_t ctl, struct mbuf *m0)
6641 {
6642 	int i, j = 0;
6643 	uint16_t data = 0;
6644 	const uint8_t *buf;
6645 	struct mbuf *m = m0;
6646 
6647 	ctl |= BWN_PIO_TXCTL_WRITELO | BWN_PIO_TXCTL_WRITEHI;
6648 	BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXCTL, ctl);
6649 
6650 	for (; m != NULL; m = m->m_next) {
6651 		buf = mtod(m, const uint8_t *);
6652 		for (i = 0; i < m->m_len; i++) {
6653 			if (!((j++) % 2))
6654 				data |= buf[i];
6655 			else {
6656 				data |= (buf[i] << 8);
6657 				BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXDATA, data);
6658 				data = 0;
6659 			}
6660 		}
6661 	}
6662 	if (m0->m_pkthdr.len % 2) {
6663 		ctl &= ~BWN_PIO_TXCTL_WRITEHI;
6664 		BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXCTL, ctl);
6665 		BWN_PIO_WRITE_2(mac, tq, BWN_PIO_TXDATA, data);
6666 	}
6667 
6668 	return (ctl);
6669 }
6670 
6671 static void
6672 bwn_set_slot_time(struct bwn_mac *mac, uint16_t time)
6673 {
6674 
6675 	/* XXX should exit if 5GHz band .. */
6676 	if (mac->mac_phy.type != BWN_PHYTYPE_G)
6677 		return;
6678 
6679 	BWN_WRITE_2(mac, 0x684, 510 + time);
6680 	/* Disabled in Linux b43, can adversely effect performance */
6681 #if 0
6682 	bwn_shm_write_2(mac, BWN_SHARED, 0x0010, time);
6683 #endif
6684 }
6685 
6686 static struct bwn_dma_ring *
6687 bwn_dma_select(struct bwn_mac *mac, uint8_t prio)
6688 {
6689 
6690 	if ((mac->mac_flags & BWN_MAC_FLAG_WME) == 0)
6691 		return (mac->mac_method.dma.wme[WME_AC_BE]);
6692 
6693 	switch (prio) {
6694 	case 3:
6695 		return (mac->mac_method.dma.wme[WME_AC_VO]);
6696 	case 2:
6697 		return (mac->mac_method.dma.wme[WME_AC_VI]);
6698 	case 0:
6699 		return (mac->mac_method.dma.wme[WME_AC_BE]);
6700 	case 1:
6701 		return (mac->mac_method.dma.wme[WME_AC_BK]);
6702 	}
6703 	KASSERT(0 == 1, ("%s:%d: fail", __func__, __LINE__));
6704 	return (NULL);
6705 }
6706 
6707 static int
6708 bwn_dma_getslot(struct bwn_dma_ring *dr)
6709 {
6710 	int slot;
6711 
6712 	BWN_ASSERT_LOCKED(dr->dr_mac->mac_sc);
6713 
6714 	KASSERT(dr->dr_tx, ("%s:%d: fail", __func__, __LINE__));
6715 	KASSERT(!(dr->dr_stop), ("%s:%d: fail", __func__, __LINE__));
6716 	KASSERT(bwn_dma_freeslot(dr) != 0, ("%s:%d: fail", __func__, __LINE__));
6717 
6718 	slot = bwn_dma_nextslot(dr, dr->dr_curslot);
6719 	KASSERT(!(slot & ~0x0fff), ("%s:%d: fail", __func__, __LINE__));
6720 	dr->dr_curslot = slot;
6721 	dr->dr_usedslot++;
6722 
6723 	return (slot);
6724 }
6725 
6726 static struct bwn_pio_txqueue *
6727 bwn_pio_parse_cookie(struct bwn_mac *mac, uint16_t cookie,
6728     struct bwn_pio_txpkt **pack)
6729 {
6730 	struct bwn_pio *pio = &mac->mac_method.pio;
6731 	struct bwn_pio_txqueue *tq = NULL;
6732 	unsigned int index;
6733 
6734 	switch (cookie & 0xf000) {
6735 	case 0x1000:
6736 		tq = &pio->wme[WME_AC_BK];
6737 		break;
6738 	case 0x2000:
6739 		tq = &pio->wme[WME_AC_BE];
6740 		break;
6741 	case 0x3000:
6742 		tq = &pio->wme[WME_AC_VI];
6743 		break;
6744 	case 0x4000:
6745 		tq = &pio->wme[WME_AC_VO];
6746 		break;
6747 	case 0x5000:
6748 		tq = &pio->mcast;
6749 		break;
6750 	}
6751 	KASSERT(tq != NULL, ("%s:%d: fail", __func__, __LINE__));
6752 	if (tq == NULL)
6753 		return (NULL);
6754 	index = (cookie & 0x0fff);
6755 	KASSERT(index < N(tq->tq_pkts), ("%s:%d: fail", __func__, __LINE__));
6756 	if (index >= N(tq->tq_pkts))
6757 		return (NULL);
6758 	*pack = &tq->tq_pkts[index];
6759 	KASSERT(*pack != NULL, ("%s:%d: fail", __func__, __LINE__));
6760 	return (tq);
6761 }
6762 
6763 static void
6764 bwn_txpwr(void *arg, int npending)
6765 {
6766 	struct bwn_mac *mac = arg;
6767 	struct bwn_softc *sc;
6768 
6769 	if (mac == NULL)
6770 		return;
6771 
6772 	sc = mac->mac_sc;
6773 
6774 	BWN_LOCK(sc);
6775 	if (mac->mac_status >= BWN_MAC_STATUS_STARTED &&
6776 	    mac->mac_phy.set_txpwr != NULL)
6777 		mac->mac_phy.set_txpwr(mac);
6778 	BWN_UNLOCK(sc);
6779 }
6780 
6781 static void
6782 bwn_task_15s(struct bwn_mac *mac)
6783 {
6784 	uint16_t reg;
6785 
6786 	if (mac->mac_fw.opensource) {
6787 		reg = bwn_shm_read_2(mac, BWN_SCRATCH, BWN_WATCHDOG_REG);
6788 		if (reg) {
6789 			bwn_restart(mac, "fw watchdog");
6790 			return;
6791 		}
6792 		bwn_shm_write_2(mac, BWN_SCRATCH, BWN_WATCHDOG_REG, 1);
6793 	}
6794 	if (mac->mac_phy.task_15s)
6795 		mac->mac_phy.task_15s(mac);
6796 
6797 	mac->mac_phy.txerrors = BWN_TXERROR_MAX;
6798 }
6799 
6800 static void
6801 bwn_task_30s(struct bwn_mac *mac)
6802 {
6803 
6804 	if (mac->mac_phy.type != BWN_PHYTYPE_G || mac->mac_noise.noi_running)
6805 		return;
6806 	mac->mac_noise.noi_running = 1;
6807 	mac->mac_noise.noi_nsamples = 0;
6808 
6809 	bwn_noise_gensample(mac);
6810 }
6811 
6812 static void
6813 bwn_task_60s(struct bwn_mac *mac)
6814 {
6815 
6816 	if (mac->mac_phy.task_60s)
6817 		mac->mac_phy.task_60s(mac);
6818 	bwn_phy_txpower_check(mac, BWN_TXPWR_IGNORE_TIME);
6819 }
6820 
6821 static void
6822 bwn_tasks(void *arg)
6823 {
6824 	struct bwn_mac *mac = arg;
6825 	struct bwn_softc *sc = mac->mac_sc;
6826 
6827 	BWN_ASSERT_LOCKED(sc);
6828 	if (mac->mac_status != BWN_MAC_STATUS_STARTED)
6829 		return;
6830 
6831 	if (mac->mac_task_state % 4 == 0)
6832 		bwn_task_60s(mac);
6833 	if (mac->mac_task_state % 2 == 0)
6834 		bwn_task_30s(mac);
6835 	bwn_task_15s(mac);
6836 
6837 	mac->mac_task_state++;
6838 	callout_reset(&sc->sc_task_ch, hz * 15, bwn_tasks, mac);
6839 }
6840 
6841 static int
6842 bwn_plcp_get_ofdmrate(struct bwn_mac *mac, struct bwn_plcp6 *plcp, uint8_t a)
6843 {
6844 	struct bwn_softc *sc = mac->mac_sc;
6845 
6846 	KASSERT(a == 0, ("not support APHY\n"));
6847 
6848 	switch (plcp->o.raw[0] & 0xf) {
6849 	case 0xb:
6850 		return (BWN_OFDM_RATE_6MB);
6851 	case 0xf:
6852 		return (BWN_OFDM_RATE_9MB);
6853 	case 0xa:
6854 		return (BWN_OFDM_RATE_12MB);
6855 	case 0xe:
6856 		return (BWN_OFDM_RATE_18MB);
6857 	case 0x9:
6858 		return (BWN_OFDM_RATE_24MB);
6859 	case 0xd:
6860 		return (BWN_OFDM_RATE_36MB);
6861 	case 0x8:
6862 		return (BWN_OFDM_RATE_48MB);
6863 	case 0xc:
6864 		return (BWN_OFDM_RATE_54MB);
6865 	}
6866 	device_printf(sc->sc_dev, "incorrect OFDM rate %d\n",
6867 	    plcp->o.raw[0] & 0xf);
6868 	return (-1);
6869 }
6870 
6871 static int
6872 bwn_plcp_get_cckrate(struct bwn_mac *mac, struct bwn_plcp6 *plcp)
6873 {
6874 	struct bwn_softc *sc = mac->mac_sc;
6875 
6876 	switch (plcp->o.raw[0]) {
6877 	case 0x0a:
6878 		return (BWN_CCK_RATE_1MB);
6879 	case 0x14:
6880 		return (BWN_CCK_RATE_2MB);
6881 	case 0x37:
6882 		return (BWN_CCK_RATE_5MB);
6883 	case 0x6e:
6884 		return (BWN_CCK_RATE_11MB);
6885 	}
6886 	device_printf(sc->sc_dev, "incorrect CCK rate %d\n", plcp->o.raw[0]);
6887 	return (-1);
6888 }
6889 
6890 static void
6891 bwn_rx_radiotap(struct bwn_mac *mac, struct mbuf *m,
6892     const struct bwn_rxhdr4 *rxhdr, struct bwn_plcp6 *plcp, int rate,
6893     int rssi, int noise)
6894 {
6895 	struct bwn_softc *sc = mac->mac_sc;
6896 	const struct ieee80211_frame_min *wh;
6897 	uint64_t tsf;
6898 	uint16_t low_mactime_now;
6899 	uint16_t mt;
6900 
6901 	if (htole16(rxhdr->phy_status0) & BWN_RX_PHYST0_SHORTPRMBL)
6902 		sc->sc_rx_th.wr_flags |= IEEE80211_RADIOTAP_F_SHORTPRE;
6903 
6904 	wh = mtod(m, const struct ieee80211_frame_min *);
6905 	if (wh->i_fc[1] & IEEE80211_FC1_PROTECTED)
6906 		sc->sc_rx_th.wr_flags |= IEEE80211_RADIOTAP_F_WEP;
6907 
6908 	bwn_tsf_read(mac, &tsf);
6909 	low_mactime_now = tsf;
6910 	tsf = tsf & ~0xffffULL;
6911 
6912 	switch (mac->mac_fw.fw_hdr_format) {
6913 	case BWN_FW_HDR_351:
6914 	case BWN_FW_HDR_410:
6915 		mt = le16toh(rxhdr->ps4.r351.mac_time);
6916 		break;
6917 	case BWN_FW_HDR_598:
6918 		mt = le16toh(rxhdr->ps4.r598.mac_time);
6919 		break;
6920 	}
6921 
6922 	tsf += mt;
6923 	if (low_mactime_now < mt)
6924 		tsf -= 0x10000;
6925 
6926 	sc->sc_rx_th.wr_tsf = tsf;
6927 	sc->sc_rx_th.wr_rate = rate;
6928 	sc->sc_rx_th.wr_antsignal = rssi;
6929 	sc->sc_rx_th.wr_antnoise = noise;
6930 }
6931 
6932 static void
6933 bwn_tsf_read(struct bwn_mac *mac, uint64_t *tsf)
6934 {
6935 	uint32_t low, high;
6936 
6937 	KASSERT(siba_get_revid(mac->mac_sc->sc_dev) >= 3,
6938 	    ("%s:%d: fail", __func__, __LINE__));
6939 
6940 	low = BWN_READ_4(mac, BWN_REV3PLUS_TSF_LOW);
6941 	high = BWN_READ_4(mac, BWN_REV3PLUS_TSF_HIGH);
6942 	*tsf = high;
6943 	*tsf <<= 32;
6944 	*tsf |= low;
6945 }
6946 
6947 static int
6948 bwn_dma_attach(struct bwn_mac *mac)
6949 {
6950 	struct bwn_dma *dma = &mac->mac_method.dma;
6951 	struct bwn_softc *sc = mac->mac_sc;
6952 	bus_addr_t lowaddr = 0;
6953 	int error;
6954 
6955 	if (siba_get_type(sc->sc_dev) == SIBA_TYPE_PCMCIA || bwn_usedma == 0)
6956 		return (0);
6957 
6958 	KASSERT(siba_get_revid(sc->sc_dev) >= 5, ("%s: fail", __func__));
6959 
6960 	mac->mac_flags |= BWN_MAC_FLAG_DMA;
6961 
6962 	dma->dmatype = bwn_dma_gettype(mac);
6963 	if (dma->dmatype == BWN_DMA_30BIT)
6964 		lowaddr = BWN_BUS_SPACE_MAXADDR_30BIT;
6965 	else if (dma->dmatype == BWN_DMA_32BIT)
6966 		lowaddr = BUS_SPACE_MAXADDR_32BIT;
6967 	else
6968 		lowaddr = BUS_SPACE_MAXADDR;
6969 
6970 	/*
6971 	 * Create top level DMA tag
6972 	 */
6973 	error = bus_dma_tag_create(bus_get_dma_tag(sc->sc_dev),	/* parent */
6974 			       BWN_ALIGN, 0,		/* alignment, bounds */
6975 			       lowaddr,			/* lowaddr */
6976 			       BUS_SPACE_MAXADDR,	/* highaddr */
6977 			       NULL, NULL,		/* filter, filterarg */
6978 			       BUS_SPACE_MAXSIZE,	/* maxsize */
6979 			       BUS_SPACE_UNRESTRICTED,	/* nsegments */
6980 			       BUS_SPACE_MAXSIZE,	/* maxsegsize */
6981 			       0,			/* flags */
6982 			       NULL, NULL,		/* lockfunc, lockarg */
6983 			       &dma->parent_dtag);
6984 	if (error) {
6985 		device_printf(sc->sc_dev, "can't create parent DMA tag\n");
6986 		return (error);
6987 	}
6988 
6989 	/*
6990 	 * Create TX/RX mbuf DMA tag
6991 	 */
6992 	error = bus_dma_tag_create(dma->parent_dtag,
6993 				1,
6994 				0,
6995 				BUS_SPACE_MAXADDR,
6996 				BUS_SPACE_MAXADDR,
6997 				NULL, NULL,
6998 				MCLBYTES,
6999 				1,
7000 				BUS_SPACE_MAXSIZE_32BIT,
7001 				0,
7002 				NULL, NULL,
7003 				&dma->rxbuf_dtag);
7004 	if (error) {
7005 		device_printf(sc->sc_dev, "can't create mbuf DMA tag\n");
7006 		goto fail0;
7007 	}
7008 	error = bus_dma_tag_create(dma->parent_dtag,
7009 				1,
7010 				0,
7011 				BUS_SPACE_MAXADDR,
7012 				BUS_SPACE_MAXADDR,
7013 				NULL, NULL,
7014 				MCLBYTES,
7015 				1,
7016 				BUS_SPACE_MAXSIZE_32BIT,
7017 				0,
7018 				NULL, NULL,
7019 				&dma->txbuf_dtag);
7020 	if (error) {
7021 		device_printf(sc->sc_dev, "can't create mbuf DMA tag\n");
7022 		goto fail1;
7023 	}
7024 
7025 	dma->wme[WME_AC_BK] = bwn_dma_ringsetup(mac, 0, 1, dma->dmatype);
7026 	if (!dma->wme[WME_AC_BK])
7027 		goto fail2;
7028 
7029 	dma->wme[WME_AC_BE] = bwn_dma_ringsetup(mac, 1, 1, dma->dmatype);
7030 	if (!dma->wme[WME_AC_BE])
7031 		goto fail3;
7032 
7033 	dma->wme[WME_AC_VI] = bwn_dma_ringsetup(mac, 2, 1, dma->dmatype);
7034 	if (!dma->wme[WME_AC_VI])
7035 		goto fail4;
7036 
7037 	dma->wme[WME_AC_VO] = bwn_dma_ringsetup(mac, 3, 1, dma->dmatype);
7038 	if (!dma->wme[WME_AC_VO])
7039 		goto fail5;
7040 
7041 	dma->mcast = bwn_dma_ringsetup(mac, 4, 1, dma->dmatype);
7042 	if (!dma->mcast)
7043 		goto fail6;
7044 	dma->rx = bwn_dma_ringsetup(mac, 0, 0, dma->dmatype);
7045 	if (!dma->rx)
7046 		goto fail7;
7047 
7048 	return (error);
7049 
7050 fail7:	bwn_dma_ringfree(&dma->mcast);
7051 fail6:	bwn_dma_ringfree(&dma->wme[WME_AC_VO]);
7052 fail5:	bwn_dma_ringfree(&dma->wme[WME_AC_VI]);
7053 fail4:	bwn_dma_ringfree(&dma->wme[WME_AC_BE]);
7054 fail3:	bwn_dma_ringfree(&dma->wme[WME_AC_BK]);
7055 fail2:	bus_dma_tag_destroy(dma->txbuf_dtag);
7056 fail1:	bus_dma_tag_destroy(dma->rxbuf_dtag);
7057 fail0:	bus_dma_tag_destroy(dma->parent_dtag);
7058 	return (error);
7059 }
7060 
7061 static struct bwn_dma_ring *
7062 bwn_dma_parse_cookie(struct bwn_mac *mac, const struct bwn_txstatus *status,
7063     uint16_t cookie, int *slot)
7064 {
7065 	struct bwn_dma *dma = &mac->mac_method.dma;
7066 	struct bwn_dma_ring *dr;
7067 	struct bwn_softc *sc = mac->mac_sc;
7068 
7069 	BWN_ASSERT_LOCKED(mac->mac_sc);
7070 
7071 	switch (cookie & 0xf000) {
7072 	case 0x1000:
7073 		dr = dma->wme[WME_AC_BK];
7074 		break;
7075 	case 0x2000:
7076 		dr = dma->wme[WME_AC_BE];
7077 		break;
7078 	case 0x3000:
7079 		dr = dma->wme[WME_AC_VI];
7080 		break;
7081 	case 0x4000:
7082 		dr = dma->wme[WME_AC_VO];
7083 		break;
7084 	case 0x5000:
7085 		dr = dma->mcast;
7086 		break;
7087 	default:
7088 		dr = NULL;
7089 		KASSERT(0 == 1,
7090 		    ("invalid cookie value %d", cookie & 0xf000));
7091 	}
7092 	*slot = (cookie & 0x0fff);
7093 	if (*slot < 0 || *slot >= dr->dr_numslots) {
7094 		/*
7095 		 * XXX FIXME: sometimes H/W returns TX DONE events duplicately
7096 		 * that it occurs events which have same H/W sequence numbers.
7097 		 * When it's occurred just prints a WARNING msgs and ignores.
7098 		 */
7099 		KASSERT(status->seq == dma->lastseq,
7100 		    ("%s:%d: fail", __func__, __LINE__));
7101 		device_printf(sc->sc_dev,
7102 		    "out of slot ranges (0 < %d < %d)\n", *slot,
7103 		    dr->dr_numslots);
7104 		return (NULL);
7105 	}
7106 	dma->lastseq = status->seq;
7107 	return (dr);
7108 }
7109 
7110 static void
7111 bwn_dma_stop(struct bwn_mac *mac)
7112 {
7113 	struct bwn_dma *dma;
7114 
7115 	if ((mac->mac_flags & BWN_MAC_FLAG_DMA) == 0)
7116 		return;
7117 	dma = &mac->mac_method.dma;
7118 
7119 	bwn_dma_ringstop(&dma->rx);
7120 	bwn_dma_ringstop(&dma->wme[WME_AC_BK]);
7121 	bwn_dma_ringstop(&dma->wme[WME_AC_BE]);
7122 	bwn_dma_ringstop(&dma->wme[WME_AC_VI]);
7123 	bwn_dma_ringstop(&dma->wme[WME_AC_VO]);
7124 	bwn_dma_ringstop(&dma->mcast);
7125 }
7126 
7127 static void
7128 bwn_dma_ringstop(struct bwn_dma_ring **dr)
7129 {
7130 
7131 	if (dr == NULL)
7132 		return;
7133 
7134 	bwn_dma_cleanup(*dr);
7135 }
7136 
7137 static void
7138 bwn_pio_stop(struct bwn_mac *mac)
7139 {
7140 	struct bwn_pio *pio;
7141 
7142 	if (mac->mac_flags & BWN_MAC_FLAG_DMA)
7143 		return;
7144 	pio = &mac->mac_method.pio;
7145 
7146 	bwn_destroy_queue_tx(&pio->mcast);
7147 	bwn_destroy_queue_tx(&pio->wme[WME_AC_VO]);
7148 	bwn_destroy_queue_tx(&pio->wme[WME_AC_VI]);
7149 	bwn_destroy_queue_tx(&pio->wme[WME_AC_BE]);
7150 	bwn_destroy_queue_tx(&pio->wme[WME_AC_BK]);
7151 }
7152 
7153 static void
7154 bwn_led_attach(struct bwn_mac *mac)
7155 {
7156 	struct bwn_softc *sc = mac->mac_sc;
7157 	const uint8_t *led_act = NULL;
7158 	uint16_t val[BWN_LED_MAX];
7159 	int i;
7160 
7161 	sc->sc_led_idle = (2350 * hz) / 1000;
7162 	sc->sc_led_blink = 1;
7163 
7164 	for (i = 0; i < N(bwn_vendor_led_act); ++i) {
7165 		if (siba_get_pci_subvendor(sc->sc_dev) ==
7166 		    bwn_vendor_led_act[i].vid) {
7167 			led_act = bwn_vendor_led_act[i].led_act;
7168 			break;
7169 		}
7170 	}
7171 	if (led_act == NULL)
7172 		led_act = bwn_default_led_act;
7173 
7174 	val[0] = siba_sprom_get_gpio0(sc->sc_dev);
7175 	val[1] = siba_sprom_get_gpio1(sc->sc_dev);
7176 	val[2] = siba_sprom_get_gpio2(sc->sc_dev);
7177 	val[3] = siba_sprom_get_gpio3(sc->sc_dev);
7178 
7179 	for (i = 0; i < BWN_LED_MAX; ++i) {
7180 		struct bwn_led *led = &sc->sc_leds[i];
7181 
7182 		if (val[i] == 0xff) {
7183 			led->led_act = led_act[i];
7184 		} else {
7185 			if (val[i] & BWN_LED_ACT_LOW)
7186 				led->led_flags |= BWN_LED_F_ACTLOW;
7187 			led->led_act = val[i] & BWN_LED_ACT_MASK;
7188 		}
7189 		led->led_mask = (1 << i);
7190 
7191 		if (led->led_act == BWN_LED_ACT_BLINK_SLOW ||
7192 		    led->led_act == BWN_LED_ACT_BLINK_POLL ||
7193 		    led->led_act == BWN_LED_ACT_BLINK) {
7194 			led->led_flags |= BWN_LED_F_BLINK;
7195 			if (led->led_act == BWN_LED_ACT_BLINK_POLL)
7196 				led->led_flags |= BWN_LED_F_POLLABLE;
7197 			else if (led->led_act == BWN_LED_ACT_BLINK_SLOW)
7198 				led->led_flags |= BWN_LED_F_SLOW;
7199 
7200 			if (sc->sc_blink_led == NULL) {
7201 				sc->sc_blink_led = led;
7202 				if (led->led_flags & BWN_LED_F_SLOW)
7203 					BWN_LED_SLOWDOWN(sc->sc_led_idle);
7204 			}
7205 		}
7206 
7207 		DPRINTF(sc, BWN_DEBUG_LED,
7208 		    "%dth led, act %d, lowact %d\n", i,
7209 		    led->led_act, led->led_flags & BWN_LED_F_ACTLOW);
7210 	}
7211 	callout_init_mtx(&sc->sc_led_blink_ch, &sc->sc_mtx, 0);
7212 }
7213 
7214 static __inline uint16_t
7215 bwn_led_onoff(const struct bwn_led *led, uint16_t val, int on)
7216 {
7217 
7218 	if (led->led_flags & BWN_LED_F_ACTLOW)
7219 		on = !on;
7220 	if (on)
7221 		val |= led->led_mask;
7222 	else
7223 		val &= ~led->led_mask;
7224 	return val;
7225 }
7226 
7227 static void
7228 bwn_led_newstate(struct bwn_mac *mac, enum ieee80211_state nstate)
7229 {
7230 	struct bwn_softc *sc = mac->mac_sc;
7231 	struct ieee80211com *ic = &sc->sc_ic;
7232 	uint16_t val;
7233 	int i;
7234 
7235 	if (nstate == IEEE80211_S_INIT) {
7236 		callout_stop(&sc->sc_led_blink_ch);
7237 		sc->sc_led_blinking = 0;
7238 	}
7239 
7240 	if ((sc->sc_flags & BWN_FLAG_RUNNING) == 0)
7241 		return;
7242 
7243 	val = BWN_READ_2(mac, BWN_GPIO_CONTROL);
7244 	for (i = 0; i < BWN_LED_MAX; ++i) {
7245 		struct bwn_led *led = &sc->sc_leds[i];
7246 		int on;
7247 
7248 		if (led->led_act == BWN_LED_ACT_UNKN ||
7249 		    led->led_act == BWN_LED_ACT_NULL)
7250 			continue;
7251 
7252 		if ((led->led_flags & BWN_LED_F_BLINK) &&
7253 		    nstate != IEEE80211_S_INIT)
7254 			continue;
7255 
7256 		switch (led->led_act) {
7257 		case BWN_LED_ACT_ON:    /* Always on */
7258 			on = 1;
7259 			break;
7260 		case BWN_LED_ACT_OFF:   /* Always off */
7261 		case BWN_LED_ACT_5GHZ:  /* TODO: 11A */
7262 			on = 0;
7263 			break;
7264 		default:
7265 			on = 1;
7266 			switch (nstate) {
7267 			case IEEE80211_S_INIT:
7268 				on = 0;
7269 				break;
7270 			case IEEE80211_S_RUN:
7271 				if (led->led_act == BWN_LED_ACT_11G &&
7272 				    ic->ic_curmode != IEEE80211_MODE_11G)
7273 					on = 0;
7274 				break;
7275 			default:
7276 				if (led->led_act == BWN_LED_ACT_ASSOC)
7277 					on = 0;
7278 				break;
7279 			}
7280 			break;
7281 		}
7282 
7283 		val = bwn_led_onoff(led, val, on);
7284 	}
7285 	BWN_WRITE_2(mac, BWN_GPIO_CONTROL, val);
7286 }
7287 
7288 static void
7289 bwn_led_event(struct bwn_mac *mac, int event)
7290 {
7291 	struct bwn_softc *sc = mac->mac_sc;
7292 	struct bwn_led *led = sc->sc_blink_led;
7293 	int rate;
7294 
7295 	if (event == BWN_LED_EVENT_POLL) {
7296 		if ((led->led_flags & BWN_LED_F_POLLABLE) == 0)
7297 			return;
7298 		if (ticks - sc->sc_led_ticks < sc->sc_led_idle)
7299 			return;
7300 	}
7301 
7302 	sc->sc_led_ticks = ticks;
7303 	if (sc->sc_led_blinking)
7304 		return;
7305 
7306 	switch (event) {
7307 	case BWN_LED_EVENT_RX:
7308 		rate = sc->sc_rx_rate;
7309 		break;
7310 	case BWN_LED_EVENT_TX:
7311 		rate = sc->sc_tx_rate;
7312 		break;
7313 	case BWN_LED_EVENT_POLL:
7314 		rate = 0;
7315 		break;
7316 	default:
7317 		panic("unknown LED event %d\n", event);
7318 		break;
7319 	}
7320 	bwn_led_blink_start(mac, bwn_led_duration[rate].on_dur,
7321 	    bwn_led_duration[rate].off_dur);
7322 }
7323 
7324 static void
7325 bwn_led_blink_start(struct bwn_mac *mac, int on_dur, int off_dur)
7326 {
7327 	struct bwn_softc *sc = mac->mac_sc;
7328 	struct bwn_led *led = sc->sc_blink_led;
7329 	uint16_t val;
7330 
7331 	val = BWN_READ_2(mac, BWN_GPIO_CONTROL);
7332 	val = bwn_led_onoff(led, val, 1);
7333 	BWN_WRITE_2(mac, BWN_GPIO_CONTROL, val);
7334 
7335 	if (led->led_flags & BWN_LED_F_SLOW) {
7336 		BWN_LED_SLOWDOWN(on_dur);
7337 		BWN_LED_SLOWDOWN(off_dur);
7338 	}
7339 
7340 	sc->sc_led_blinking = 1;
7341 	sc->sc_led_blink_offdur = off_dur;
7342 
7343 	callout_reset(&sc->sc_led_blink_ch, on_dur, bwn_led_blink_next, mac);
7344 }
7345 
7346 static void
7347 bwn_led_blink_next(void *arg)
7348 {
7349 	struct bwn_mac *mac = arg;
7350 	struct bwn_softc *sc = mac->mac_sc;
7351 	uint16_t val;
7352 
7353 	val = BWN_READ_2(mac, BWN_GPIO_CONTROL);
7354 	val = bwn_led_onoff(sc->sc_blink_led, val, 0);
7355 	BWN_WRITE_2(mac, BWN_GPIO_CONTROL, val);
7356 
7357 	callout_reset(&sc->sc_led_blink_ch, sc->sc_led_blink_offdur,
7358 	    bwn_led_blink_end, mac);
7359 }
7360 
7361 static void
7362 bwn_led_blink_end(void *arg)
7363 {
7364 	struct bwn_mac *mac = arg;
7365 	struct bwn_softc *sc = mac->mac_sc;
7366 
7367 	sc->sc_led_blinking = 0;
7368 }
7369 
7370 static int
7371 bwn_suspend(device_t dev)
7372 {
7373 	struct bwn_softc *sc = device_get_softc(dev);
7374 
7375 	BWN_LOCK(sc);
7376 	bwn_stop(sc);
7377 	BWN_UNLOCK(sc);
7378 	return (0);
7379 }
7380 
7381 static int
7382 bwn_resume(device_t dev)
7383 {
7384 	struct bwn_softc *sc = device_get_softc(dev);
7385 	int error = EDOOFUS;
7386 
7387 	BWN_LOCK(sc);
7388 	if (sc->sc_ic.ic_nrunning > 0)
7389 		error = bwn_init(sc);
7390 	BWN_UNLOCK(sc);
7391 	if (error == 0)
7392 		ieee80211_start_all(&sc->sc_ic);
7393 	return (0);
7394 }
7395 
7396 static void
7397 bwn_rfswitch(void *arg)
7398 {
7399 	struct bwn_softc *sc = arg;
7400 	struct bwn_mac *mac = sc->sc_curmac;
7401 	int cur = 0, prev = 0;
7402 
7403 	KASSERT(mac->mac_status >= BWN_MAC_STATUS_STARTED,
7404 	    ("%s: invalid MAC status %d", __func__, mac->mac_status));
7405 
7406 	if (mac->mac_phy.rev >= 3 || mac->mac_phy.type == BWN_PHYTYPE_LP
7407 	    || mac->mac_phy.type == BWN_PHYTYPE_N) {
7408 		if (!(BWN_READ_4(mac, BWN_RF_HWENABLED_HI)
7409 			& BWN_RF_HWENABLED_HI_MASK))
7410 			cur = 1;
7411 	} else {
7412 		if (BWN_READ_2(mac, BWN_RF_HWENABLED_LO)
7413 		    & BWN_RF_HWENABLED_LO_MASK)
7414 			cur = 1;
7415 	}
7416 
7417 	if (mac->mac_flags & BWN_MAC_FLAG_RADIO_ON)
7418 		prev = 1;
7419 
7420 	DPRINTF(sc, BWN_DEBUG_RESET, "%s: called; cur=%d, prev=%d\n",
7421 	    __func__, cur, prev);
7422 
7423 	if (cur != prev) {
7424 		if (cur)
7425 			mac->mac_flags |= BWN_MAC_FLAG_RADIO_ON;
7426 		else
7427 			mac->mac_flags &= ~BWN_MAC_FLAG_RADIO_ON;
7428 
7429 		device_printf(sc->sc_dev,
7430 		    "status of RF switch is changed to %s\n",
7431 		    cur ? "ON" : "OFF");
7432 		if (cur != mac->mac_phy.rf_on) {
7433 			if (cur)
7434 				bwn_rf_turnon(mac);
7435 			else
7436 				bwn_rf_turnoff(mac);
7437 		}
7438 	}
7439 
7440 	callout_schedule(&sc->sc_rfswitch_ch, hz);
7441 }
7442 
7443 static void
7444 bwn_sysctl_node(struct bwn_softc *sc)
7445 {
7446 	device_t dev = sc->sc_dev;
7447 	struct bwn_mac *mac;
7448 	struct bwn_stats *stats;
7449 
7450 	/* XXX assume that count of MAC is only 1. */
7451 
7452 	if ((mac = sc->sc_curmac) == NULL)
7453 		return;
7454 	stats = &mac->mac_stats;
7455 
7456 	SYSCTL_ADD_INT(device_get_sysctl_ctx(dev),
7457 	    SYSCTL_CHILDREN(device_get_sysctl_tree(dev)), OID_AUTO,
7458 	    "linknoise", CTLFLAG_RW, &stats->rts, 0, "Noise level");
7459 	SYSCTL_ADD_INT(device_get_sysctl_ctx(dev),
7460 	    SYSCTL_CHILDREN(device_get_sysctl_tree(dev)), OID_AUTO,
7461 	    "rts", CTLFLAG_RW, &stats->rts, 0, "RTS");
7462 	SYSCTL_ADD_INT(device_get_sysctl_ctx(dev),
7463 	    SYSCTL_CHILDREN(device_get_sysctl_tree(dev)), OID_AUTO,
7464 	    "rtsfail", CTLFLAG_RW, &stats->rtsfail, 0, "RTS failed to send");
7465 
7466 #ifdef BWN_DEBUG
7467 	SYSCTL_ADD_UINT(device_get_sysctl_ctx(dev),
7468 	    SYSCTL_CHILDREN(device_get_sysctl_tree(dev)), OID_AUTO,
7469 	    "debug", CTLFLAG_RW, &sc->sc_debug, 0, "Debug flags");
7470 #endif
7471 }
7472 
7473 static device_method_t bwn_methods[] = {
7474 	/* Device interface */
7475 	DEVMETHOD(device_probe,		bwn_probe),
7476 	DEVMETHOD(device_attach,	bwn_attach),
7477 	DEVMETHOD(device_detach,	bwn_detach),
7478 	DEVMETHOD(device_suspend,	bwn_suspend),
7479 	DEVMETHOD(device_resume,	bwn_resume),
7480 	DEVMETHOD_END
7481 };
7482 driver_t bwn_driver = {
7483 	"bwn",
7484 	bwn_methods,
7485 	sizeof(struct bwn_softc)
7486 };
7487 static devclass_t bwn_devclass;
7488 DRIVER_MODULE(bwn, siba_bwn, bwn_driver, bwn_devclass, 0, 0);
7489 MODULE_DEPEND(bwn, siba_bwn, 1, 1, 1);
7490 MODULE_DEPEND(bwn, gpiobus, 1, 1, 1);
7491 MODULE_DEPEND(bwn, wlan, 1, 1, 1);		/* 802.11 media layer */
7492 MODULE_DEPEND(bwn, firmware, 1, 1, 1);		/* firmware support */
7493 MODULE_DEPEND(bwn, wlan_amrr, 1, 1, 1);
7494 MODULE_VERSION(bwn, 1);
7495