xref: /freebsd/sys/dev/usb/wlan/if_upgt.c (revision ba2c1fbc03f312b978f76f7b6c67eec6afa80bf8)
1879f0effSWeongyo Jeong /*	$OpenBSD: if_upgt.c,v 1.35 2008/04/16 18:32:15 damien Exp $ */
2879f0effSWeongyo Jeong /*	$FreeBSD$ */
3879f0effSWeongyo Jeong 
4879f0effSWeongyo Jeong /*
5879f0effSWeongyo Jeong  * Copyright (c) 2007 Marcus Glocker <mglocker@openbsd.org>
6879f0effSWeongyo Jeong  *
7879f0effSWeongyo Jeong  * Permission to use, copy, modify, and distribute this software for any
8879f0effSWeongyo Jeong  * purpose with or without fee is hereby granted, provided that the above
9879f0effSWeongyo Jeong  * copyright notice and this permission notice appear in all copies.
10879f0effSWeongyo Jeong  *
11879f0effSWeongyo Jeong  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
12879f0effSWeongyo Jeong  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
13879f0effSWeongyo Jeong  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
14879f0effSWeongyo Jeong  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
15879f0effSWeongyo Jeong  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
16879f0effSWeongyo Jeong  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
17879f0effSWeongyo Jeong  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
18879f0effSWeongyo Jeong  */
19879f0effSWeongyo Jeong 
20879f0effSWeongyo Jeong #include <sys/param.h>
21879f0effSWeongyo Jeong #include <sys/systm.h>
22879f0effSWeongyo Jeong #include <sys/kernel.h>
23879f0effSWeongyo Jeong #include <sys/endian.h>
24879f0effSWeongyo Jeong #include <sys/firmware.h>
25879f0effSWeongyo Jeong #include <sys/linker.h>
26879f0effSWeongyo Jeong #include <sys/mbuf.h>
27879f0effSWeongyo Jeong #include <sys/malloc.h>
28879f0effSWeongyo Jeong #include <sys/module.h>
29879f0effSWeongyo Jeong #include <sys/socket.h>
30879f0effSWeongyo Jeong #include <sys/sockio.h>
31879f0effSWeongyo Jeong #include <sys/sysctl.h>
32879f0effSWeongyo Jeong 
33879f0effSWeongyo Jeong #include <net/if.h>
3476039bc8SGleb Smirnoff #include <net/if_var.h>
35879f0effSWeongyo Jeong #include <net/if_arp.h>
36879f0effSWeongyo Jeong #include <net/ethernet.h>
37879f0effSWeongyo Jeong #include <net/if_dl.h>
38879f0effSWeongyo Jeong #include <net/if_media.h>
39879f0effSWeongyo Jeong #include <net/if_types.h>
40879f0effSWeongyo Jeong 
41879f0effSWeongyo Jeong #include <sys/bus.h>
42879f0effSWeongyo Jeong #include <machine/bus.h>
43879f0effSWeongyo Jeong 
44879f0effSWeongyo Jeong #include <net80211/ieee80211_var.h>
45879f0effSWeongyo Jeong #include <net80211/ieee80211_phy.h>
46879f0effSWeongyo Jeong #include <net80211/ieee80211_radiotap.h>
47879f0effSWeongyo Jeong #include <net80211/ieee80211_regdomain.h>
48879f0effSWeongyo Jeong 
49879f0effSWeongyo Jeong #include <net/bpf.h>
50879f0effSWeongyo Jeong 
51879f0effSWeongyo Jeong #include <dev/usb/usb.h>
52ed6d949aSAndrew Thompson #include <dev/usb/usbdi.h>
53879f0effSWeongyo Jeong #include "usbdevs.h"
54879f0effSWeongyo Jeong 
55879f0effSWeongyo Jeong #include <dev/usb/wlan/if_upgtvar.h>
56879f0effSWeongyo Jeong 
57879f0effSWeongyo Jeong /*
58879f0effSWeongyo Jeong  * Driver for the USB PrismGT devices.
59879f0effSWeongyo Jeong  *
60879f0effSWeongyo Jeong  * For now just USB 2.0 devices with the GW3887 chipset are supported.
61879f0effSWeongyo Jeong  * The driver has been written based on the firmware version 2.13.1.0_LM87.
62879f0effSWeongyo Jeong  *
63879f0effSWeongyo Jeong  * TODO's:
64879f0effSWeongyo Jeong  * - MONITOR mode test.
65879f0effSWeongyo Jeong  * - Add HOSTAP mode.
66879f0effSWeongyo Jeong  * - Add IBSS mode.
67879f0effSWeongyo Jeong  * - Support the USB 1.0 devices (NET2280, ISL3880, ISL3886 chipsets).
68879f0effSWeongyo Jeong  *
69879f0effSWeongyo Jeong  * Parts of this driver has been influenced by reading the p54u driver
70879f0effSWeongyo Jeong  * written by Jean-Baptiste Note <jean-baptiste.note@m4x.org> and
71879f0effSWeongyo Jeong  * Sebastien Bourdeauducq <lekernel@prism54.org>.
72879f0effSWeongyo Jeong  */
73879f0effSWeongyo Jeong 
746472ac3dSEd Schouten static SYSCTL_NODE(_hw, OID_AUTO, upgt, CTLFLAG_RD, 0,
75879f0effSWeongyo Jeong     "USB PrismGT GW3887 driver parameters");
76879f0effSWeongyo Jeong 
77879f0effSWeongyo Jeong #ifdef UPGT_DEBUG
78879f0effSWeongyo Jeong int upgt_debug = 0;
79af3b2549SHans Petter Selasky SYSCTL_INT(_hw_upgt, OID_AUTO, debug, CTLFLAG_RWTUN, &upgt_debug,
80879f0effSWeongyo Jeong 	    0, "control debugging printfs");
81879f0effSWeongyo Jeong enum {
82879f0effSWeongyo Jeong 	UPGT_DEBUG_XMIT		= 0x00000001,	/* basic xmit operation */
83879f0effSWeongyo Jeong 	UPGT_DEBUG_RECV		= 0x00000002,	/* basic recv operation */
84879f0effSWeongyo Jeong 	UPGT_DEBUG_RESET	= 0x00000004,	/* reset processing */
85879f0effSWeongyo Jeong 	UPGT_DEBUG_INTR		= 0x00000008,	/* INTR */
86879f0effSWeongyo Jeong 	UPGT_DEBUG_TX_PROC	= 0x00000010,	/* tx ISR proc */
87879f0effSWeongyo Jeong 	UPGT_DEBUG_RX_PROC	= 0x00000020,	/* rx ISR proc */
88879f0effSWeongyo Jeong 	UPGT_DEBUG_STATE	= 0x00000040,	/* 802.11 state transitions */
89879f0effSWeongyo Jeong 	UPGT_DEBUG_STAT		= 0x00000080,	/* statistic */
90879f0effSWeongyo Jeong 	UPGT_DEBUG_FW		= 0x00000100,	/* firmware */
91879f0effSWeongyo Jeong 	UPGT_DEBUG_ANY		= 0xffffffff
92879f0effSWeongyo Jeong };
93879f0effSWeongyo Jeong #define	DPRINTF(sc, m, fmt, ...) do {				\
94879f0effSWeongyo Jeong 	if (sc->sc_debug & (m))					\
95879f0effSWeongyo Jeong 		printf(fmt, __VA_ARGS__);			\
96879f0effSWeongyo Jeong } while (0)
97879f0effSWeongyo Jeong #else
98879f0effSWeongyo Jeong #define	DPRINTF(sc, m, fmt, ...) do {				\
99879f0effSWeongyo Jeong 	(void) sc;						\
100879f0effSWeongyo Jeong } while (0)
101879f0effSWeongyo Jeong #endif
102879f0effSWeongyo Jeong 
103879f0effSWeongyo Jeong /*
104879f0effSWeongyo Jeong  * Prototypes.
105879f0effSWeongyo Jeong  */
106879f0effSWeongyo Jeong static device_probe_t upgt_match;
107879f0effSWeongyo Jeong static device_attach_t upgt_attach;
108879f0effSWeongyo Jeong static device_detach_t upgt_detach;
109879f0effSWeongyo Jeong static int	upgt_alloc_tx(struct upgt_softc *);
110879f0effSWeongyo Jeong static int	upgt_alloc_rx(struct upgt_softc *);
111879f0effSWeongyo Jeong static int	upgt_device_reset(struct upgt_softc *);
112879f0effSWeongyo Jeong static void	upgt_bulk_tx(struct upgt_softc *, struct upgt_data *);
113879f0effSWeongyo Jeong static int	upgt_fw_verify(struct upgt_softc *);
114879f0effSWeongyo Jeong static int	upgt_mem_init(struct upgt_softc *);
115879f0effSWeongyo Jeong static int	upgt_fw_load(struct upgt_softc *);
116879f0effSWeongyo Jeong static int	upgt_fw_copy(const uint8_t *, char *, int);
117879f0effSWeongyo Jeong static uint32_t	upgt_crc32_le(const void *, size_t);
118879f0effSWeongyo Jeong static struct mbuf *
119760bc48eSAndrew Thompson 		upgt_rxeof(struct usb_xfer *, struct upgt_data *, int *);
120879f0effSWeongyo Jeong static struct mbuf *
121879f0effSWeongyo Jeong 		upgt_rx(struct upgt_softc *, uint8_t *, int, int *);
122760bc48eSAndrew Thompson static void	upgt_txeof(struct usb_xfer *, struct upgt_data *);
123879f0effSWeongyo Jeong static int	upgt_eeprom_read(struct upgt_softc *);
124879f0effSWeongyo Jeong static int	upgt_eeprom_parse(struct upgt_softc *);
125879f0effSWeongyo Jeong static void	upgt_eeprom_parse_hwrx(struct upgt_softc *, uint8_t *);
126879f0effSWeongyo Jeong static void	upgt_eeprom_parse_freq3(struct upgt_softc *, uint8_t *, int);
127879f0effSWeongyo Jeong static void	upgt_eeprom_parse_freq4(struct upgt_softc *, uint8_t *, int);
128879f0effSWeongyo Jeong static void	upgt_eeprom_parse_freq6(struct upgt_softc *, uint8_t *, int);
129879f0effSWeongyo Jeong static uint32_t	upgt_chksum_le(const uint32_t *, size_t);
130879f0effSWeongyo Jeong static void	upgt_tx_done(struct upgt_softc *, uint8_t *);
131*ba2c1fbcSAdrian Chadd static void	upgt_init(void *);
132*ba2c1fbcSAdrian Chadd static void	upgt_init_locked(struct upgt_softc *);
133*ba2c1fbcSAdrian Chadd static int	upgt_ioctl(struct ifnet *, u_long, caddr_t);
134*ba2c1fbcSAdrian Chadd static void	upgt_start(struct ifnet *);
135879f0effSWeongyo Jeong static int	upgt_raw_xmit(struct ieee80211_node *, struct mbuf *,
136879f0effSWeongyo Jeong 		    const struct ieee80211_bpf_params *);
137879f0effSWeongyo Jeong static void	upgt_scan_start(struct ieee80211com *);
138879f0effSWeongyo Jeong static void	upgt_scan_end(struct ieee80211com *);
139879f0effSWeongyo Jeong static void	upgt_set_channel(struct ieee80211com *);
140879f0effSWeongyo Jeong static struct ieee80211vap *upgt_vap_create(struct ieee80211com *,
141fcd9500fSBernhard Schmidt 		    const char [IFNAMSIZ], int, enum ieee80211_opmode, int,
142fcd9500fSBernhard Schmidt 		    const uint8_t [IEEE80211_ADDR_LEN],
143fcd9500fSBernhard Schmidt 		    const uint8_t [IEEE80211_ADDR_LEN]);
144879f0effSWeongyo Jeong static void	upgt_vap_delete(struct ieee80211vap *);
145272f6adeSGleb Smirnoff static void	upgt_update_mcast(struct ieee80211com *);
146879f0effSWeongyo Jeong static uint8_t	upgt_rx_rate(struct upgt_softc *, const int);
147879f0effSWeongyo Jeong static void	upgt_set_multi(void *);
148879f0effSWeongyo Jeong static void	upgt_stop(struct upgt_softc *);
149879f0effSWeongyo Jeong static void	upgt_setup_rates(struct ieee80211vap *, struct ieee80211com *);
150879f0effSWeongyo Jeong static int	upgt_set_macfilter(struct upgt_softc *, uint8_t);
151879f0effSWeongyo Jeong static int	upgt_newstate(struct ieee80211vap *, enum ieee80211_state, int);
152879f0effSWeongyo Jeong static void	upgt_set_chan(struct upgt_softc *, struct ieee80211_channel *);
153879f0effSWeongyo Jeong static void	upgt_set_led(struct upgt_softc *, int);
154879f0effSWeongyo Jeong static void	upgt_set_led_blink(void *);
155879f0effSWeongyo Jeong static void	upgt_get_stats(struct upgt_softc *);
156879f0effSWeongyo Jeong static void	upgt_mem_free(struct upgt_softc *, uint32_t);
157879f0effSWeongyo Jeong static uint32_t	upgt_mem_alloc(struct upgt_softc *);
158879f0effSWeongyo Jeong static void	upgt_free_tx(struct upgt_softc *);
159879f0effSWeongyo Jeong static void	upgt_free_rx(struct upgt_softc *);
160879f0effSWeongyo Jeong static void	upgt_watchdog(void *);
161879f0effSWeongyo Jeong static void	upgt_abort_xfers(struct upgt_softc *);
162879f0effSWeongyo Jeong static void	upgt_abort_xfers_locked(struct upgt_softc *);
163879f0effSWeongyo Jeong static void	upgt_sysctl_node(struct upgt_softc *);
164879f0effSWeongyo Jeong static struct upgt_data *
165879f0effSWeongyo Jeong 		upgt_getbuf(struct upgt_softc *);
166879f0effSWeongyo Jeong static struct upgt_data *
167879f0effSWeongyo Jeong 		upgt_gettxbuf(struct upgt_softc *);
168879f0effSWeongyo Jeong static int	upgt_tx_start(struct upgt_softc *, struct mbuf *,
169879f0effSWeongyo Jeong 		    struct ieee80211_node *, struct upgt_data *);
170879f0effSWeongyo Jeong 
171879f0effSWeongyo Jeong static const char *upgt_fwname = "upgt-gw3887";
172879f0effSWeongyo Jeong 
173f1a16106SHans Petter Selasky static const STRUCT_USB_HOST_ID upgt_devs[] = {
174879f0effSWeongyo Jeong #define	UPGT_DEV(v,p) { USB_VP(USB_VENDOR_##v, USB_PRODUCT_##v##_##p) }
175879f0effSWeongyo Jeong 	/* version 2 devices */
176879f0effSWeongyo Jeong 	UPGT_DEV(ACCTON,	PRISM_GT),
177879f0effSWeongyo Jeong 	UPGT_DEV(BELKIN,	F5D7050),
178879f0effSWeongyo Jeong 	UPGT_DEV(CISCOLINKSYS,	WUSB54AG),
179879f0effSWeongyo Jeong 	UPGT_DEV(CONCEPTRONIC,	PRISM_GT),
180879f0effSWeongyo Jeong 	UPGT_DEV(DELL,		PRISM_GT_1),
181879f0effSWeongyo Jeong 	UPGT_DEV(DELL,		PRISM_GT_2),
182879f0effSWeongyo Jeong 	UPGT_DEV(FSC,		E5400),
183879f0effSWeongyo Jeong 	UPGT_DEV(GLOBESPAN,	PRISM_GT_1),
184879f0effSWeongyo Jeong 	UPGT_DEV(GLOBESPAN,	PRISM_GT_2),
1858723d2f4SMark Peek 	UPGT_DEV(NETGEAR,	WG111V1_2),
186879f0effSWeongyo Jeong 	UPGT_DEV(INTERSIL,	PRISM_GT),
187879f0effSWeongyo Jeong 	UPGT_DEV(SMC,		2862WG),
18833ba3721SAndrew Thompson 	UPGT_DEV(USR,		USR5422),
189879f0effSWeongyo Jeong 	UPGT_DEV(WISTRONNEWEB,	UR045G),
190879f0effSWeongyo Jeong 	UPGT_DEV(XYRATEX,	PRISM_GT_1),
191879f0effSWeongyo Jeong 	UPGT_DEV(XYRATEX,	PRISM_GT_2),
192879f0effSWeongyo Jeong 	UPGT_DEV(ZCOM,		XG703A),
193879f0effSWeongyo Jeong 	UPGT_DEV(ZCOM,		XM142)
194879f0effSWeongyo Jeong };
195879f0effSWeongyo Jeong 
196e0a69b51SAndrew Thompson static usb_callback_t upgt_bulk_rx_callback;
197e0a69b51SAndrew Thompson static usb_callback_t upgt_bulk_tx_callback;
198879f0effSWeongyo Jeong 
199760bc48eSAndrew Thompson static const struct usb_config upgt_config[UPGT_N_XFERS] = {
200879f0effSWeongyo Jeong 	[UPGT_BULK_TX] = {
201879f0effSWeongyo Jeong 		.type = UE_BULK,
202879f0effSWeongyo Jeong 		.endpoint = UE_ADDR_ANY,
203879f0effSWeongyo Jeong 		.direction = UE_DIR_OUT,
204c180b398SHans Petter Selasky 		.bufsize = MCLBYTES * UPGT_TX_MAXCOUNT,
205879f0effSWeongyo Jeong 		.flags = {
206879f0effSWeongyo Jeong 			.force_short_xfer = 1,
207879f0effSWeongyo Jeong 			.pipe_bof = 1
208879f0effSWeongyo Jeong 		},
209879f0effSWeongyo Jeong 		.callback = upgt_bulk_tx_callback,
210879f0effSWeongyo Jeong 		.timeout = UPGT_USB_TIMEOUT,	/* ms */
211879f0effSWeongyo Jeong 	},
212879f0effSWeongyo Jeong 	[UPGT_BULK_RX] = {
213879f0effSWeongyo Jeong 		.type = UE_BULK,
214879f0effSWeongyo Jeong 		.endpoint = UE_ADDR_ANY,
215879f0effSWeongyo Jeong 		.direction = UE_DIR_IN,
216c180b398SHans Petter Selasky 		.bufsize = MCLBYTES * UPGT_RX_MAXCOUNT,
217879f0effSWeongyo Jeong 		.flags = {
218879f0effSWeongyo Jeong 			.pipe_bof = 1,
219879f0effSWeongyo Jeong 			.short_xfer_ok = 1
220879f0effSWeongyo Jeong 		},
221879f0effSWeongyo Jeong 		.callback = upgt_bulk_rx_callback,
222879f0effSWeongyo Jeong 	},
223879f0effSWeongyo Jeong };
224879f0effSWeongyo Jeong 
225879f0effSWeongyo Jeong static int
226879f0effSWeongyo Jeong upgt_match(device_t dev)
227879f0effSWeongyo Jeong {
228760bc48eSAndrew Thompson 	struct usb_attach_arg *uaa = device_get_ivars(dev);
229879f0effSWeongyo Jeong 
230f29a0724SAndrew Thompson 	if (uaa->usb_mode != USB_MODE_HOST)
231879f0effSWeongyo Jeong 		return (ENXIO);
232879f0effSWeongyo Jeong 	if (uaa->info.bConfigIndex != UPGT_CONFIG_INDEX)
233879f0effSWeongyo Jeong 		return (ENXIO);
234879f0effSWeongyo Jeong 	if (uaa->info.bIfaceIndex != UPGT_IFACE_INDEX)
235879f0effSWeongyo Jeong 		return (ENXIO);
236879f0effSWeongyo Jeong 
237f1a16106SHans Petter Selasky 	return (usbd_lookup_id_by_uaa(upgt_devs, sizeof(upgt_devs), uaa));
238879f0effSWeongyo Jeong }
239879f0effSWeongyo Jeong 
240879f0effSWeongyo Jeong static int
241879f0effSWeongyo Jeong upgt_attach(device_t dev)
242879f0effSWeongyo Jeong {
243*ba2c1fbcSAdrian Chadd 	int error;
244*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic;
245*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp;
246879f0effSWeongyo Jeong 	struct upgt_softc *sc = device_get_softc(dev);
247760bc48eSAndrew Thompson 	struct usb_attach_arg *uaa = device_get_ivars(dev);
248879f0effSWeongyo Jeong 	uint8_t bands, iface_index = UPGT_IFACE_INDEX;
249879f0effSWeongyo Jeong 
250879f0effSWeongyo Jeong 	sc->sc_dev = dev;
251879f0effSWeongyo Jeong 	sc->sc_udev = uaa->device;
252879f0effSWeongyo Jeong #ifdef UPGT_DEBUG
253879f0effSWeongyo Jeong 	sc->sc_debug = upgt_debug;
254879f0effSWeongyo Jeong #endif
255a593f6b8SAndrew Thompson 	device_set_usb_desc(dev);
256879f0effSWeongyo Jeong 
257879f0effSWeongyo Jeong 	mtx_init(&sc->sc_mtx, device_get_nameunit(sc->sc_dev), MTX_NETWORK_LOCK,
258879f0effSWeongyo Jeong 	    MTX_DEF);
259879f0effSWeongyo Jeong 	callout_init(&sc->sc_led_ch, 0);
260879f0effSWeongyo Jeong 	callout_init(&sc->sc_watchdog_ch, 0);
261879f0effSWeongyo Jeong 
262a593f6b8SAndrew Thompson 	error = usbd_transfer_setup(uaa->device, &iface_index, sc->sc_xfer,
263879f0effSWeongyo Jeong 	    upgt_config, UPGT_N_XFERS, sc, &sc->sc_mtx);
264879f0effSWeongyo Jeong 	if (error) {
265879f0effSWeongyo Jeong 		device_printf(dev, "could not allocate USB transfers, "
266a593f6b8SAndrew Thompson 		    "err=%s\n", usbd_errstr(error));
2672d8a425bSHans Petter Selasky 		goto fail1;
268879f0effSWeongyo Jeong 	}
269879f0effSWeongyo Jeong 
270c180b398SHans Petter Selasky 	sc->sc_rx_dma_buf = usbd_xfer_get_frame_buffer(
271c180b398SHans Petter Selasky 	    sc->sc_xfer[UPGT_BULK_RX], 0);
272c180b398SHans Petter Selasky 	sc->sc_tx_dma_buf = usbd_xfer_get_frame_buffer(
273c180b398SHans Petter Selasky 	    sc->sc_xfer[UPGT_BULK_TX], 0);
274c180b398SHans Petter Selasky 
2752d8a425bSHans Petter Selasky 	/* Setup TX and RX buffers */
2762d8a425bSHans Petter Selasky 	error = upgt_alloc_tx(sc);
2772d8a425bSHans Petter Selasky 	if (error)
2782d8a425bSHans Petter Selasky 		goto fail2;
2792d8a425bSHans Petter Selasky 	error = upgt_alloc_rx(sc);
2802d8a425bSHans Petter Selasky 	if (error)
2812d8a425bSHans Petter Selasky 		goto fail3;
2822d8a425bSHans Petter Selasky 
283*ba2c1fbcSAdrian Chadd 	ifp = sc->sc_ifp = if_alloc(IFT_IEEE80211);
284*ba2c1fbcSAdrian Chadd 	if (ifp == NULL) {
285*ba2c1fbcSAdrian Chadd 		device_printf(dev, "can not if_alloc()\n");
286*ba2c1fbcSAdrian Chadd 		goto fail4;
287*ba2c1fbcSAdrian Chadd 	}
288*ba2c1fbcSAdrian Chadd 
289879f0effSWeongyo Jeong 	/* Initialize the device.  */
290879f0effSWeongyo Jeong 	error = upgt_device_reset(sc);
291879f0effSWeongyo Jeong 	if (error)
292*ba2c1fbcSAdrian Chadd 		goto fail5;
293879f0effSWeongyo Jeong 	/* Verify the firmware.  */
294879f0effSWeongyo Jeong 	error = upgt_fw_verify(sc);
295879f0effSWeongyo Jeong 	if (error)
296*ba2c1fbcSAdrian Chadd 		goto fail5;
297879f0effSWeongyo Jeong 	/* Calculate device memory space.  */
298879f0effSWeongyo Jeong 	if (sc->sc_memaddr_frame_start == 0 || sc->sc_memaddr_frame_end == 0) {
299879f0effSWeongyo Jeong 		device_printf(dev,
300767cb2e2SAndrew Thompson 		    "could not find memory space addresses on FW\n");
301879f0effSWeongyo Jeong 		error = EIO;
302*ba2c1fbcSAdrian Chadd 		goto fail5;
303879f0effSWeongyo Jeong 	}
304879f0effSWeongyo Jeong 	sc->sc_memaddr_frame_end -= UPGT_MEMSIZE_RX + 1;
305879f0effSWeongyo Jeong 	sc->sc_memaddr_rx_start = sc->sc_memaddr_frame_end + 1;
306879f0effSWeongyo Jeong 
307879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "memory address frame start=0x%08x\n",
308879f0effSWeongyo Jeong 	    sc->sc_memaddr_frame_start);
309879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "memory address frame end=0x%08x\n",
310879f0effSWeongyo Jeong 	    sc->sc_memaddr_frame_end);
311879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "memory address rx start=0x%08x\n",
312879f0effSWeongyo Jeong 	    sc->sc_memaddr_rx_start);
313879f0effSWeongyo Jeong 
314879f0effSWeongyo Jeong 	upgt_mem_init(sc);
315879f0effSWeongyo Jeong 
316879f0effSWeongyo Jeong 	/* Load the firmware.  */
317879f0effSWeongyo Jeong 	error = upgt_fw_load(sc);
318879f0effSWeongyo Jeong 	if (error)
319*ba2c1fbcSAdrian Chadd 		goto fail5;
320879f0effSWeongyo Jeong 
321879f0effSWeongyo Jeong 	/* Read the whole EEPROM content and parse it.  */
322879f0effSWeongyo Jeong 	error = upgt_eeprom_read(sc);
323879f0effSWeongyo Jeong 	if (error)
324*ba2c1fbcSAdrian Chadd 		goto fail5;
325879f0effSWeongyo Jeong 	error = upgt_eeprom_parse(sc);
326879f0effSWeongyo Jeong 	if (error)
327*ba2c1fbcSAdrian Chadd 		goto fail5;
328879f0effSWeongyo Jeong 
329879f0effSWeongyo Jeong 	/* all works related with the device have done here. */
330879f0effSWeongyo Jeong 	upgt_abort_xfers(sc);
331879f0effSWeongyo Jeong 
332*ba2c1fbcSAdrian Chadd 	/* Setup the 802.11 device.  */
333*ba2c1fbcSAdrian Chadd 	ifp->if_softc = sc;
334*ba2c1fbcSAdrian Chadd 	if_initname(ifp, "upgt", device_get_unit(sc->sc_dev));
335*ba2c1fbcSAdrian Chadd 	ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
336*ba2c1fbcSAdrian Chadd 	ifp->if_init = upgt_init;
337*ba2c1fbcSAdrian Chadd 	ifp->if_ioctl = upgt_ioctl;
338*ba2c1fbcSAdrian Chadd 	ifp->if_start = upgt_start;
339*ba2c1fbcSAdrian Chadd 	IFQ_SET_MAXLEN(&ifp->if_snd, ifqmaxlen);
340*ba2c1fbcSAdrian Chadd 	IFQ_SET_READY(&ifp->if_snd);
341*ba2c1fbcSAdrian Chadd 
342*ba2c1fbcSAdrian Chadd 	ic = ifp->if_l2com;
343*ba2c1fbcSAdrian Chadd 	ic->ic_ifp = ifp;
34459686fe9SGleb Smirnoff 	ic->ic_softc = sc;
345c8550c02SGleb Smirnoff 	ic->ic_name = device_get_nameunit(dev);
346879f0effSWeongyo Jeong 	ic->ic_phytype = IEEE80211_T_OFDM;	/* not only, but not used */
347879f0effSWeongyo Jeong 	ic->ic_opmode = IEEE80211_M_STA;
348879f0effSWeongyo Jeong 	/* set device capabilities */
349879f0effSWeongyo Jeong 	ic->ic_caps =
350879f0effSWeongyo Jeong 		  IEEE80211_C_STA		/* station mode */
351879f0effSWeongyo Jeong 		| IEEE80211_C_MONITOR		/* monitor mode */
352879f0effSWeongyo Jeong 		| IEEE80211_C_SHPREAMBLE	/* short preamble supported */
353879f0effSWeongyo Jeong 	        | IEEE80211_C_SHSLOT		/* short slot time supported */
354879f0effSWeongyo Jeong 		| IEEE80211_C_BGSCAN		/* capable of bg scanning */
355879f0effSWeongyo Jeong 	        | IEEE80211_C_WPA		/* 802.11i */
356879f0effSWeongyo Jeong 		;
357879f0effSWeongyo Jeong 
358879f0effSWeongyo Jeong 	bands = 0;
359879f0effSWeongyo Jeong 	setbit(&bands, IEEE80211_MODE_11B);
360879f0effSWeongyo Jeong 	setbit(&bands, IEEE80211_MODE_11G);
361879f0effSWeongyo Jeong 	ieee80211_init_channels(ic, NULL, &bands);
362879f0effSWeongyo Jeong 
363*ba2c1fbcSAdrian Chadd 	ieee80211_ifattach(ic, sc->sc_myaddr);
364879f0effSWeongyo Jeong 	ic->ic_raw_xmit = upgt_raw_xmit;
365879f0effSWeongyo Jeong 	ic->ic_scan_start = upgt_scan_start;
366879f0effSWeongyo Jeong 	ic->ic_scan_end = upgt_scan_end;
367879f0effSWeongyo Jeong 	ic->ic_set_channel = upgt_set_channel;
368*ba2c1fbcSAdrian Chadd 
369879f0effSWeongyo Jeong 	ic->ic_vap_create = upgt_vap_create;
370879f0effSWeongyo Jeong 	ic->ic_vap_delete = upgt_vap_delete;
371879f0effSWeongyo Jeong 	ic->ic_update_mcast = upgt_update_mcast;
372879f0effSWeongyo Jeong 
3735463c4a4SSam Leffler 	ieee80211_radiotap_attach(ic,
3745463c4a4SSam Leffler 	    &sc->sc_txtap.wt_ihdr, sizeof(sc->sc_txtap),
3755463c4a4SSam Leffler 		UPGT_TX_RADIOTAP_PRESENT,
3765463c4a4SSam Leffler 	    &sc->sc_rxtap.wr_ihdr, sizeof(sc->sc_rxtap),
3775463c4a4SSam Leffler 		UPGT_RX_RADIOTAP_PRESENT);
378879f0effSWeongyo Jeong 
379879f0effSWeongyo Jeong 	upgt_sysctl_node(sc);
380879f0effSWeongyo Jeong 
381879f0effSWeongyo Jeong 	if (bootverbose)
382879f0effSWeongyo Jeong 		ieee80211_announce(ic);
383879f0effSWeongyo Jeong 
384879f0effSWeongyo Jeong 	return (0);
385879f0effSWeongyo Jeong 
386*ba2c1fbcSAdrian Chadd fail5:	if_free(ifp);
3872d8a425bSHans Petter Selasky fail4:	upgt_free_rx(sc);
3882d8a425bSHans Petter Selasky fail3:	upgt_free_tx(sc);
3892d8a425bSHans Petter Selasky fail2:	usbd_transfer_unsetup(sc->sc_xfer, UPGT_N_XFERS);
390879f0effSWeongyo Jeong fail1:	mtx_destroy(&sc->sc_mtx);
391879f0effSWeongyo Jeong 
392879f0effSWeongyo Jeong 	return (error);
393879f0effSWeongyo Jeong }
394879f0effSWeongyo Jeong 
395879f0effSWeongyo Jeong static void
396760bc48eSAndrew Thompson upgt_txeof(struct usb_xfer *xfer, struct upgt_data *data)
397879f0effSWeongyo Jeong {
398*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = usbd_xfer_softc(xfer);
399*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
400*ba2c1fbcSAdrian Chadd 	struct mbuf *m;
401879f0effSWeongyo Jeong 
402*ba2c1fbcSAdrian Chadd 	UPGT_ASSERT_LOCKED(sc);
403*ba2c1fbcSAdrian Chadd 
404*ba2c1fbcSAdrian Chadd 	/*
405*ba2c1fbcSAdrian Chadd 	 * Do any tx complete callback.  Note this must be done before releasing
406*ba2c1fbcSAdrian Chadd 	 * the node reference.
407*ba2c1fbcSAdrian Chadd 	 */
408879f0effSWeongyo Jeong 	if (data->m) {
409*ba2c1fbcSAdrian Chadd 		m = data->m;
410*ba2c1fbcSAdrian Chadd 		if (m->m_flags & M_TXCB) {
411879f0effSWeongyo Jeong 			/* XXX status? */
412*ba2c1fbcSAdrian Chadd 			ieee80211_process_callback(data->ni, m, 0);
413*ba2c1fbcSAdrian Chadd 		}
414*ba2c1fbcSAdrian Chadd 		m_freem(m);
415879f0effSWeongyo Jeong 		data->m = NULL;
416*ba2c1fbcSAdrian Chadd 	}
417*ba2c1fbcSAdrian Chadd 	if (data->ni) {
418*ba2c1fbcSAdrian Chadd 		ieee80211_free_node(data->ni);
419879f0effSWeongyo Jeong 		data->ni = NULL;
420879f0effSWeongyo Jeong 	}
421*ba2c1fbcSAdrian Chadd 	if_inc_counter(ifp, IFCOUNTER_OPACKETS, 1);
422879f0effSWeongyo Jeong }
423879f0effSWeongyo Jeong 
424879f0effSWeongyo Jeong static void
425879f0effSWeongyo Jeong upgt_get_stats(struct upgt_softc *sc)
426879f0effSWeongyo Jeong {
427879f0effSWeongyo Jeong 	struct upgt_data *data_cmd;
428879f0effSWeongyo Jeong 	struct upgt_lmac_mem *mem;
429879f0effSWeongyo Jeong 	struct upgt_lmac_stats *stats;
430879f0effSWeongyo Jeong 
431879f0effSWeongyo Jeong 	data_cmd = upgt_getbuf(sc);
432879f0effSWeongyo Jeong 	if (data_cmd == NULL) {
4337ae432c0SNick Hibma 		device_printf(sc->sc_dev, "%s: out of buffers.\n", __func__);
434879f0effSWeongyo Jeong 		return;
435879f0effSWeongyo Jeong 	}
436879f0effSWeongyo Jeong 
437879f0effSWeongyo Jeong 	/*
438879f0effSWeongyo Jeong 	 * Transmit the URB containing the CMD data.
439879f0effSWeongyo Jeong 	 */
440271ae033SHans Petter Selasky 	memset(data_cmd->buf, 0, MCLBYTES);
441879f0effSWeongyo Jeong 
442879f0effSWeongyo Jeong 	mem = (struct upgt_lmac_mem *)data_cmd->buf;
443879f0effSWeongyo Jeong 	mem->addr = htole32(sc->sc_memaddr_frame_start +
444879f0effSWeongyo Jeong 	    UPGT_MEMSIZE_FRAME_HEAD);
445879f0effSWeongyo Jeong 
446879f0effSWeongyo Jeong 	stats = (struct upgt_lmac_stats *)(mem + 1);
447879f0effSWeongyo Jeong 
448879f0effSWeongyo Jeong 	stats->header1.flags = 0;
449879f0effSWeongyo Jeong 	stats->header1.type = UPGT_H1_TYPE_CTRL;
450879f0effSWeongyo Jeong 	stats->header1.len = htole16(
451879f0effSWeongyo Jeong 	    sizeof(struct upgt_lmac_stats) - sizeof(struct upgt_lmac_header));
452879f0effSWeongyo Jeong 
453879f0effSWeongyo Jeong 	stats->header2.reqid = htole32(sc->sc_memaddr_frame_start);
454879f0effSWeongyo Jeong 	stats->header2.type = htole16(UPGT_H2_TYPE_STATS);
455879f0effSWeongyo Jeong 	stats->header2.flags = 0;
456879f0effSWeongyo Jeong 
457879f0effSWeongyo Jeong 	data_cmd->buflen = sizeof(*mem) + sizeof(*stats);
458879f0effSWeongyo Jeong 
459879f0effSWeongyo Jeong 	mem->chksum = upgt_chksum_le((uint32_t *)stats,
460879f0effSWeongyo Jeong 	    data_cmd->buflen - sizeof(*mem));
461879f0effSWeongyo Jeong 
462879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data_cmd);
463879f0effSWeongyo Jeong }
464879f0effSWeongyo Jeong 
465*ba2c1fbcSAdrian Chadd static int
466*ba2c1fbcSAdrian Chadd upgt_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data)
467879f0effSWeongyo Jeong {
468*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = ifp->if_softc;
469*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
470*ba2c1fbcSAdrian Chadd 	struct ifreq *ifr = (struct ifreq *) data;
471*ba2c1fbcSAdrian Chadd 	int error;
472645e4d17SHans Petter Selasky 	int startall = 0;
473645e4d17SHans Petter Selasky 
474645e4d17SHans Petter Selasky 	UPGT_LOCK(sc);
475*ba2c1fbcSAdrian Chadd 	error = (sc->sc_flags & UPGT_FLAG_DETACHED) ? ENXIO : 0;
476645e4d17SHans Petter Selasky 	UPGT_UNLOCK(sc);
477*ba2c1fbcSAdrian Chadd 	if (error)
478*ba2c1fbcSAdrian Chadd 		return (error);
479*ba2c1fbcSAdrian Chadd 
480*ba2c1fbcSAdrian Chadd 	switch (cmd) {
481*ba2c1fbcSAdrian Chadd 	case SIOCSIFFLAGS:
482*ba2c1fbcSAdrian Chadd 		if (ifp->if_flags & IFF_UP) {
483*ba2c1fbcSAdrian Chadd 			if (ifp->if_drv_flags & IFF_DRV_RUNNING) {
484*ba2c1fbcSAdrian Chadd 				if ((ifp->if_flags ^ sc->sc_if_flags) &
485*ba2c1fbcSAdrian Chadd 				    (IFF_ALLMULTI | IFF_PROMISC))
486879f0effSWeongyo Jeong 					upgt_set_multi(sc);
487879f0effSWeongyo Jeong 			} else {
488879f0effSWeongyo Jeong 				upgt_init(sc);
489879f0effSWeongyo Jeong 				startall = 1;
490879f0effSWeongyo Jeong 			}
491*ba2c1fbcSAdrian Chadd 		} else {
492*ba2c1fbcSAdrian Chadd 			if (ifp->if_drv_flags & IFF_DRV_RUNNING)
493879f0effSWeongyo Jeong 				upgt_stop(sc);
494*ba2c1fbcSAdrian Chadd 		}
495*ba2c1fbcSAdrian Chadd 		sc->sc_if_flags = ifp->if_flags;
496879f0effSWeongyo Jeong 		if (startall)
497879f0effSWeongyo Jeong 			ieee80211_start_all(ic);
498*ba2c1fbcSAdrian Chadd 		break;
499*ba2c1fbcSAdrian Chadd 	case SIOCGIFMEDIA:
500*ba2c1fbcSAdrian Chadd 		error = ifmedia_ioctl(ifp, ifr, &ic->ic_media, cmd);
501*ba2c1fbcSAdrian Chadd 		break;
502*ba2c1fbcSAdrian Chadd 	case SIOCGIFADDR:
503*ba2c1fbcSAdrian Chadd 		error = ether_ioctl(ifp, cmd, data);
504*ba2c1fbcSAdrian Chadd 		break;
505*ba2c1fbcSAdrian Chadd 	default:
506*ba2c1fbcSAdrian Chadd 		error = EINVAL;
507*ba2c1fbcSAdrian Chadd 		break;
508*ba2c1fbcSAdrian Chadd 	}
509*ba2c1fbcSAdrian Chadd 	return error;
510*ba2c1fbcSAdrian Chadd }
511*ba2c1fbcSAdrian Chadd 
512*ba2c1fbcSAdrian Chadd static void
513*ba2c1fbcSAdrian Chadd upgt_stop_locked(struct upgt_softc *sc)
514*ba2c1fbcSAdrian Chadd {
515*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
516*ba2c1fbcSAdrian Chadd 
517*ba2c1fbcSAdrian Chadd 	UPGT_ASSERT_LOCKED(sc);
518*ba2c1fbcSAdrian Chadd 
519*ba2c1fbcSAdrian Chadd 	if (ifp->if_drv_flags & IFF_DRV_RUNNING)
520*ba2c1fbcSAdrian Chadd 		upgt_set_macfilter(sc, IEEE80211_S_INIT);
521*ba2c1fbcSAdrian Chadd 	upgt_abort_xfers_locked(sc);
522879f0effSWeongyo Jeong }
523879f0effSWeongyo Jeong 
524879f0effSWeongyo Jeong static void
525879f0effSWeongyo Jeong upgt_stop(struct upgt_softc *sc)
526879f0effSWeongyo Jeong {
527*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
528879f0effSWeongyo Jeong 
529*ba2c1fbcSAdrian Chadd 	UPGT_LOCK(sc);
530*ba2c1fbcSAdrian Chadd 	upgt_stop_locked(sc);
531*ba2c1fbcSAdrian Chadd 	UPGT_UNLOCK(sc);
532879f0effSWeongyo Jeong 
533879f0effSWeongyo Jeong 	/* device down */
534879f0effSWeongyo Jeong 	sc->sc_tx_timer = 0;
535*ba2c1fbcSAdrian Chadd 	ifp->if_drv_flags &= ~(IFF_DRV_RUNNING | IFF_DRV_OACTIVE);
536879f0effSWeongyo Jeong 	sc->sc_flags &= ~UPGT_FLAG_INITDONE;
537879f0effSWeongyo Jeong }
538879f0effSWeongyo Jeong 
539879f0effSWeongyo Jeong static void
540879f0effSWeongyo Jeong upgt_set_led(struct upgt_softc *sc, int action)
541879f0effSWeongyo Jeong {
542879f0effSWeongyo Jeong 	struct upgt_data *data_cmd;
543879f0effSWeongyo Jeong 	struct upgt_lmac_mem *mem;
544879f0effSWeongyo Jeong 	struct upgt_lmac_led *led;
545879f0effSWeongyo Jeong 
546879f0effSWeongyo Jeong 	data_cmd = upgt_getbuf(sc);
547879f0effSWeongyo Jeong 	if (data_cmd == NULL) {
548879f0effSWeongyo Jeong 		device_printf(sc->sc_dev, "%s: out of buffers.\n", __func__);
549879f0effSWeongyo Jeong 		return;
550879f0effSWeongyo Jeong 	}
551879f0effSWeongyo Jeong 
552879f0effSWeongyo Jeong 	/*
553879f0effSWeongyo Jeong 	 * Transmit the URB containing the CMD data.
554879f0effSWeongyo Jeong 	 */
555271ae033SHans Petter Selasky 	memset(data_cmd->buf, 0, MCLBYTES);
556879f0effSWeongyo Jeong 
557879f0effSWeongyo Jeong 	mem = (struct upgt_lmac_mem *)data_cmd->buf;
558879f0effSWeongyo Jeong 	mem->addr = htole32(sc->sc_memaddr_frame_start +
559879f0effSWeongyo Jeong 	    UPGT_MEMSIZE_FRAME_HEAD);
560879f0effSWeongyo Jeong 
561879f0effSWeongyo Jeong 	led = (struct upgt_lmac_led *)(mem + 1);
562879f0effSWeongyo Jeong 
563879f0effSWeongyo Jeong 	led->header1.flags = UPGT_H1_FLAGS_TX_NO_CALLBACK;
564879f0effSWeongyo Jeong 	led->header1.type = UPGT_H1_TYPE_CTRL;
565879f0effSWeongyo Jeong 	led->header1.len = htole16(
566879f0effSWeongyo Jeong 	    sizeof(struct upgt_lmac_led) -
567879f0effSWeongyo Jeong 	    sizeof(struct upgt_lmac_header));
568879f0effSWeongyo Jeong 
569879f0effSWeongyo Jeong 	led->header2.reqid = htole32(sc->sc_memaddr_frame_start);
570879f0effSWeongyo Jeong 	led->header2.type = htole16(UPGT_H2_TYPE_LED);
571879f0effSWeongyo Jeong 	led->header2.flags = 0;
572879f0effSWeongyo Jeong 
573879f0effSWeongyo Jeong 	switch (action) {
574879f0effSWeongyo Jeong 	case UPGT_LED_OFF:
575879f0effSWeongyo Jeong 		led->mode = htole16(UPGT_LED_MODE_SET);
576879f0effSWeongyo Jeong 		led->action_fix = 0;
577879f0effSWeongyo Jeong 		led->action_tmp = htole16(UPGT_LED_ACTION_OFF);
578879f0effSWeongyo Jeong 		led->action_tmp_dur = 0;
579879f0effSWeongyo Jeong 		break;
580879f0effSWeongyo Jeong 	case UPGT_LED_ON:
581879f0effSWeongyo Jeong 		led->mode = htole16(UPGT_LED_MODE_SET);
582879f0effSWeongyo Jeong 		led->action_fix = 0;
583879f0effSWeongyo Jeong 		led->action_tmp = htole16(UPGT_LED_ACTION_ON);
584879f0effSWeongyo Jeong 		led->action_tmp_dur = 0;
585879f0effSWeongyo Jeong 		break;
586879f0effSWeongyo Jeong 	case UPGT_LED_BLINK:
587879f0effSWeongyo Jeong 		if (sc->sc_state != IEEE80211_S_RUN) {
588879f0effSWeongyo Jeong 			STAILQ_INSERT_TAIL(&sc->sc_tx_inactive, data_cmd, next);
589879f0effSWeongyo Jeong 			return;
590879f0effSWeongyo Jeong 		}
591879f0effSWeongyo Jeong 		if (sc->sc_led_blink) {
592879f0effSWeongyo Jeong 			/* previous blink was not finished */
593879f0effSWeongyo Jeong 			STAILQ_INSERT_TAIL(&sc->sc_tx_inactive, data_cmd, next);
594879f0effSWeongyo Jeong 			return;
595879f0effSWeongyo Jeong 		}
596879f0effSWeongyo Jeong 		led->mode = htole16(UPGT_LED_MODE_SET);
597879f0effSWeongyo Jeong 		led->action_fix = htole16(UPGT_LED_ACTION_OFF);
598879f0effSWeongyo Jeong 		led->action_tmp = htole16(UPGT_LED_ACTION_ON);
599879f0effSWeongyo Jeong 		led->action_tmp_dur = htole16(UPGT_LED_ACTION_TMP_DUR);
600879f0effSWeongyo Jeong 		/* lock blink */
601879f0effSWeongyo Jeong 		sc->sc_led_blink = 1;
602879f0effSWeongyo Jeong 		callout_reset(&sc->sc_led_ch, hz, upgt_set_led_blink, sc);
603879f0effSWeongyo Jeong 		break;
604879f0effSWeongyo Jeong 	default:
605879f0effSWeongyo Jeong 		STAILQ_INSERT_TAIL(&sc->sc_tx_inactive, data_cmd, next);
606879f0effSWeongyo Jeong 		return;
607879f0effSWeongyo Jeong 	}
608879f0effSWeongyo Jeong 
609879f0effSWeongyo Jeong 	data_cmd->buflen = sizeof(*mem) + sizeof(*led);
610879f0effSWeongyo Jeong 
611879f0effSWeongyo Jeong 	mem->chksum = upgt_chksum_le((uint32_t *)led,
612879f0effSWeongyo Jeong 	    data_cmd->buflen - sizeof(*mem));
613879f0effSWeongyo Jeong 
614879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data_cmd);
615879f0effSWeongyo Jeong }
616879f0effSWeongyo Jeong 
617879f0effSWeongyo Jeong static void
618879f0effSWeongyo Jeong upgt_set_led_blink(void *arg)
619879f0effSWeongyo Jeong {
620879f0effSWeongyo Jeong 	struct upgt_softc *sc = arg;
621879f0effSWeongyo Jeong 
622879f0effSWeongyo Jeong 	/* blink finished, we are ready for a next one */
623879f0effSWeongyo Jeong 	sc->sc_led_blink = 0;
624879f0effSWeongyo Jeong }
625879f0effSWeongyo Jeong 
626879f0effSWeongyo Jeong static void
627*ba2c1fbcSAdrian Chadd upgt_init(void *priv)
628879f0effSWeongyo Jeong {
629*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = priv;
630*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
631*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
632*ba2c1fbcSAdrian Chadd 
633*ba2c1fbcSAdrian Chadd 	UPGT_LOCK(sc);
634*ba2c1fbcSAdrian Chadd 	upgt_init_locked(sc);
635*ba2c1fbcSAdrian Chadd 	UPGT_UNLOCK(sc);
636*ba2c1fbcSAdrian Chadd 
637*ba2c1fbcSAdrian Chadd 	if (ifp->if_drv_flags & IFF_DRV_RUNNING)
638*ba2c1fbcSAdrian Chadd 		ieee80211_start_all(ic);		/* start all vap's */
639*ba2c1fbcSAdrian Chadd }
640*ba2c1fbcSAdrian Chadd 
641*ba2c1fbcSAdrian Chadd static void
642*ba2c1fbcSAdrian Chadd upgt_init_locked(struct upgt_softc *sc)
643*ba2c1fbcSAdrian Chadd {
644*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
645879f0effSWeongyo Jeong 
646879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
647879f0effSWeongyo Jeong 
648*ba2c1fbcSAdrian Chadd 	if (ifp->if_drv_flags & IFF_DRV_RUNNING)
649*ba2c1fbcSAdrian Chadd 		upgt_stop_locked(sc);
650879f0effSWeongyo Jeong 
651a593f6b8SAndrew Thompson 	usbd_transfer_start(sc->sc_xfer[UPGT_BULK_RX]);
652879f0effSWeongyo Jeong 
653879f0effSWeongyo Jeong 	(void)upgt_set_macfilter(sc, IEEE80211_S_SCAN);
654879f0effSWeongyo Jeong 
655*ba2c1fbcSAdrian Chadd 	ifp->if_drv_flags &= ~IFF_DRV_OACTIVE;
656*ba2c1fbcSAdrian Chadd 	ifp->if_drv_flags |= IFF_DRV_RUNNING;
657879f0effSWeongyo Jeong 	sc->sc_flags |= UPGT_FLAG_INITDONE;
658879f0effSWeongyo Jeong 
659879f0effSWeongyo Jeong 	callout_reset(&sc->sc_watchdog_ch, hz, upgt_watchdog, sc);
660879f0effSWeongyo Jeong }
661879f0effSWeongyo Jeong 
662879f0effSWeongyo Jeong static int
663879f0effSWeongyo Jeong upgt_set_macfilter(struct upgt_softc *sc, uint8_t state)
664879f0effSWeongyo Jeong {
665*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
666*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
667879f0effSWeongyo Jeong 	struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
66813226c4cSAndrew Thompson 	struct ieee80211_node *ni;
669879f0effSWeongyo Jeong 	struct upgt_data *data_cmd;
670879f0effSWeongyo Jeong 	struct upgt_lmac_mem *mem;
671879f0effSWeongyo Jeong 	struct upgt_lmac_filter *filter;
672*ba2c1fbcSAdrian Chadd 	uint8_t broadcast[] = { 0xff, 0xff, 0xff, 0xff, 0xff, 0xff };
673879f0effSWeongyo Jeong 
674879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
675879f0effSWeongyo Jeong 
676879f0effSWeongyo Jeong 	data_cmd = upgt_getbuf(sc);
677879f0effSWeongyo Jeong 	if (data_cmd == NULL) {
678879f0effSWeongyo Jeong 		device_printf(sc->sc_dev, "out of TX buffers.\n");
679879f0effSWeongyo Jeong 		return (ENOBUFS);
680879f0effSWeongyo Jeong 	}
681879f0effSWeongyo Jeong 
682879f0effSWeongyo Jeong 	/*
683879f0effSWeongyo Jeong 	 * Transmit the URB containing the CMD data.
684879f0effSWeongyo Jeong 	 */
685271ae033SHans Petter Selasky 	memset(data_cmd->buf, 0, MCLBYTES);
686879f0effSWeongyo Jeong 
687879f0effSWeongyo Jeong 	mem = (struct upgt_lmac_mem *)data_cmd->buf;
688879f0effSWeongyo Jeong 	mem->addr = htole32(sc->sc_memaddr_frame_start +
689879f0effSWeongyo Jeong 	    UPGT_MEMSIZE_FRAME_HEAD);
690879f0effSWeongyo Jeong 
691879f0effSWeongyo Jeong 	filter = (struct upgt_lmac_filter *)(mem + 1);
692879f0effSWeongyo Jeong 
693879f0effSWeongyo Jeong 	filter->header1.flags = UPGT_H1_FLAGS_TX_NO_CALLBACK;
694879f0effSWeongyo Jeong 	filter->header1.type = UPGT_H1_TYPE_CTRL;
695879f0effSWeongyo Jeong 	filter->header1.len = htole16(
696879f0effSWeongyo Jeong 	    sizeof(struct upgt_lmac_filter) -
697879f0effSWeongyo Jeong 	    sizeof(struct upgt_lmac_header));
698879f0effSWeongyo Jeong 
699879f0effSWeongyo Jeong 	filter->header2.reqid = htole32(sc->sc_memaddr_frame_start);
700879f0effSWeongyo Jeong 	filter->header2.type = htole16(UPGT_H2_TYPE_MACFILTER);
701879f0effSWeongyo Jeong 	filter->header2.flags = 0;
702879f0effSWeongyo Jeong 
703879f0effSWeongyo Jeong 	switch (state) {
704879f0effSWeongyo Jeong 	case IEEE80211_S_INIT:
705879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_STATE, "%s: set MAC filter to INIT\n",
706879f0effSWeongyo Jeong 		    __func__);
707879f0effSWeongyo Jeong 		filter->type = htole16(UPGT_FILTER_TYPE_RESET);
708879f0effSWeongyo Jeong 		break;
709879f0effSWeongyo Jeong 	case IEEE80211_S_SCAN:
710879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_STATE,
711879f0effSWeongyo Jeong 		    "set MAC filter to SCAN (bssid %s)\n",
712*ba2c1fbcSAdrian Chadd 		    ether_sprintf(broadcast));
713879f0effSWeongyo Jeong 		filter->type = htole16(UPGT_FILTER_TYPE_NONE);
714*ba2c1fbcSAdrian Chadd 		IEEE80211_ADDR_COPY(filter->dst, sc->sc_myaddr);
715*ba2c1fbcSAdrian Chadd 		IEEE80211_ADDR_COPY(filter->src, broadcast);
716879f0effSWeongyo Jeong 		filter->unknown1 = htole16(UPGT_FILTER_UNKNOWN1);
717879f0effSWeongyo Jeong 		filter->rxaddr = htole32(sc->sc_memaddr_rx_start);
718879f0effSWeongyo Jeong 		filter->unknown2 = htole16(UPGT_FILTER_UNKNOWN2);
719879f0effSWeongyo Jeong 		filter->rxhw = htole32(sc->sc_eeprom_hwrx);
720879f0effSWeongyo Jeong 		filter->unknown3 = htole16(UPGT_FILTER_UNKNOWN3);
721879f0effSWeongyo Jeong 		break;
722879f0effSWeongyo Jeong 	case IEEE80211_S_RUN:
7238d8bdb01SAndrew Thompson 		ni = ieee80211_ref_node(vap->iv_bss);
724879f0effSWeongyo Jeong 		/* XXX monitor mode isn't tested yet.  */
725879f0effSWeongyo Jeong 		if (vap->iv_opmode == IEEE80211_M_MONITOR) {
726879f0effSWeongyo Jeong 			filter->type = htole16(UPGT_FILTER_TYPE_MONITOR);
727*ba2c1fbcSAdrian Chadd 			IEEE80211_ADDR_COPY(filter->dst, sc->sc_myaddr);
728879f0effSWeongyo Jeong 			IEEE80211_ADDR_COPY(filter->src, ni->ni_bssid);
729879f0effSWeongyo Jeong 			filter->unknown1 = htole16(UPGT_FILTER_MONITOR_UNKNOWN1);
730879f0effSWeongyo Jeong 			filter->rxaddr = htole32(sc->sc_memaddr_rx_start);
731879f0effSWeongyo Jeong 			filter->unknown2 = htole16(UPGT_FILTER_MONITOR_UNKNOWN2);
732879f0effSWeongyo Jeong 			filter->rxhw = htole32(sc->sc_eeprom_hwrx);
733879f0effSWeongyo Jeong 			filter->unknown3 = htole16(UPGT_FILTER_MONITOR_UNKNOWN3);
734879f0effSWeongyo Jeong 		} else {
735879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_STATE,
736879f0effSWeongyo Jeong 			    "set MAC filter to RUN (bssid %s)\n",
737879f0effSWeongyo Jeong 			    ether_sprintf(ni->ni_bssid));
738879f0effSWeongyo Jeong 			filter->type = htole16(UPGT_FILTER_TYPE_STA);
739*ba2c1fbcSAdrian Chadd 			IEEE80211_ADDR_COPY(filter->dst, sc->sc_myaddr);
740879f0effSWeongyo Jeong 			IEEE80211_ADDR_COPY(filter->src, ni->ni_bssid);
741879f0effSWeongyo Jeong 			filter->unknown1 = htole16(UPGT_FILTER_UNKNOWN1);
742879f0effSWeongyo Jeong 			filter->rxaddr = htole32(sc->sc_memaddr_rx_start);
743879f0effSWeongyo Jeong 			filter->unknown2 = htole16(UPGT_FILTER_UNKNOWN2);
744879f0effSWeongyo Jeong 			filter->rxhw = htole32(sc->sc_eeprom_hwrx);
745879f0effSWeongyo Jeong 			filter->unknown3 = htole16(UPGT_FILTER_UNKNOWN3);
746879f0effSWeongyo Jeong 		}
7478d8bdb01SAndrew Thompson 		ieee80211_free_node(ni);
748879f0effSWeongyo Jeong 		break;
749879f0effSWeongyo Jeong 	default:
750879f0effSWeongyo Jeong 		device_printf(sc->sc_dev,
751767cb2e2SAndrew Thompson 		    "MAC filter does not know that state\n");
752879f0effSWeongyo Jeong 		break;
753879f0effSWeongyo Jeong 	}
754879f0effSWeongyo Jeong 
755879f0effSWeongyo Jeong 	data_cmd->buflen = sizeof(*mem) + sizeof(*filter);
756879f0effSWeongyo Jeong 
757879f0effSWeongyo Jeong 	mem->chksum = upgt_chksum_le((uint32_t *)filter,
758879f0effSWeongyo Jeong 	    data_cmd->buflen - sizeof(*mem));
759879f0effSWeongyo Jeong 
760879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data_cmd);
761879f0effSWeongyo Jeong 
762879f0effSWeongyo Jeong 	return (0);
763879f0effSWeongyo Jeong }
764879f0effSWeongyo Jeong 
765879f0effSWeongyo Jeong static void
766879f0effSWeongyo Jeong upgt_setup_rates(struct ieee80211vap *vap, struct ieee80211com *ic)
767879f0effSWeongyo Jeong {
768*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = ic->ic_ifp;
769*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = ifp->if_softc;
770879f0effSWeongyo Jeong 	const struct ieee80211_txparam *tp;
771879f0effSWeongyo Jeong 
772879f0effSWeongyo Jeong 	/*
773879f0effSWeongyo Jeong 	 * 0x01 = OFMD6   0x10 = DS1
774879f0effSWeongyo Jeong 	 * 0x04 = OFDM9   0x11 = DS2
775879f0effSWeongyo Jeong 	 * 0x06 = OFDM12  0x12 = DS5
776879f0effSWeongyo Jeong 	 * 0x07 = OFDM18  0x13 = DS11
777879f0effSWeongyo Jeong 	 * 0x08 = OFDM24
778879f0effSWeongyo Jeong 	 * 0x09 = OFDM36
779879f0effSWeongyo Jeong 	 * 0x0a = OFDM48
780879f0effSWeongyo Jeong 	 * 0x0b = OFDM54
781879f0effSWeongyo Jeong 	 */
782879f0effSWeongyo Jeong 	const uint8_t rateset_auto_11b[] =
783879f0effSWeongyo Jeong 	    { 0x13, 0x13, 0x12, 0x11, 0x11, 0x10, 0x10, 0x10 };
784879f0effSWeongyo Jeong 	const uint8_t rateset_auto_11g[] =
785879f0effSWeongyo Jeong 	    { 0x0b, 0x0a, 0x09, 0x08, 0x07, 0x06, 0x04, 0x01 };
786879f0effSWeongyo Jeong 	const uint8_t rateset_fix_11bg[] =
787879f0effSWeongyo Jeong 	    { 0x10, 0x11, 0x12, 0x13, 0x01, 0x04, 0x06, 0x07,
788879f0effSWeongyo Jeong 	      0x08, 0x09, 0x0a, 0x0b };
789879f0effSWeongyo Jeong 
790879f0effSWeongyo Jeong 	tp = &vap->iv_txparms[ieee80211_chan2mode(ic->ic_curchan)];
791879f0effSWeongyo Jeong 
792879f0effSWeongyo Jeong 	/* XXX */
793879f0effSWeongyo Jeong 	if (tp->ucastrate == IEEE80211_FIXED_RATE_NONE) {
794879f0effSWeongyo Jeong 		/*
795879f0effSWeongyo Jeong 		 * Automatic rate control is done by the device.
796879f0effSWeongyo Jeong 		 * We just pass the rateset from which the device
797879f0effSWeongyo Jeong 		 * will pickup a rate.
798879f0effSWeongyo Jeong 		 */
799879f0effSWeongyo Jeong 		if (ic->ic_curmode == IEEE80211_MODE_11B)
800271ae033SHans Petter Selasky 			memcpy(sc->sc_cur_rateset, rateset_auto_11b,
801879f0effSWeongyo Jeong 			    sizeof(sc->sc_cur_rateset));
802879f0effSWeongyo Jeong 		if (ic->ic_curmode == IEEE80211_MODE_11G ||
803879f0effSWeongyo Jeong 		    ic->ic_curmode == IEEE80211_MODE_AUTO)
804271ae033SHans Petter Selasky 			memcpy(sc->sc_cur_rateset, rateset_auto_11g,
805879f0effSWeongyo Jeong 			    sizeof(sc->sc_cur_rateset));
806879f0effSWeongyo Jeong 	} else {
807879f0effSWeongyo Jeong 		/* set a fixed rate */
808879f0effSWeongyo Jeong 		memset(sc->sc_cur_rateset, rateset_fix_11bg[tp->ucastrate],
809879f0effSWeongyo Jeong 		    sizeof(sc->sc_cur_rateset));
810879f0effSWeongyo Jeong 	}
811879f0effSWeongyo Jeong }
812879f0effSWeongyo Jeong 
813879f0effSWeongyo Jeong static void
814879f0effSWeongyo Jeong upgt_set_multi(void *arg)
815879f0effSWeongyo Jeong {
816*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = arg;
817*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
818879f0effSWeongyo Jeong 
819*ba2c1fbcSAdrian Chadd 	if (!(ifp->if_flags & IFF_UP))
820*ba2c1fbcSAdrian Chadd 		return;
821879f0effSWeongyo Jeong 
822*ba2c1fbcSAdrian Chadd 	/*
823*ba2c1fbcSAdrian Chadd 	 * XXX don't know how to set a device.  Lack of docs.  Just try to set
824*ba2c1fbcSAdrian Chadd 	 * IFF_ALLMULTI flag here.
825*ba2c1fbcSAdrian Chadd 	 */
826*ba2c1fbcSAdrian Chadd 	ifp->if_flags |= IFF_ALLMULTI;
827879f0effSWeongyo Jeong }
828879f0effSWeongyo Jeong 
829879f0effSWeongyo Jeong static void
830*ba2c1fbcSAdrian Chadd upgt_start(struct ifnet *ifp)
831879f0effSWeongyo Jeong {
832*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = ifp->if_softc;
833879f0effSWeongyo Jeong 	struct upgt_data *data_tx;
834879f0effSWeongyo Jeong 	struct ieee80211_node *ni;
835879f0effSWeongyo Jeong 	struct mbuf *m;
836879f0effSWeongyo Jeong 
837*ba2c1fbcSAdrian Chadd 	if ((ifp->if_drv_flags & IFF_DRV_RUNNING) == 0)
838879f0effSWeongyo Jeong 		return;
839879f0effSWeongyo Jeong 
840*ba2c1fbcSAdrian Chadd 	UPGT_LOCK(sc);
841*ba2c1fbcSAdrian Chadd 	for (;;) {
842*ba2c1fbcSAdrian Chadd 		IFQ_DRV_DEQUEUE(&ifp->if_snd, m);
843*ba2c1fbcSAdrian Chadd 		if (m == NULL)
844*ba2c1fbcSAdrian Chadd 			break;
845*ba2c1fbcSAdrian Chadd 
846879f0effSWeongyo Jeong 		data_tx = upgt_gettxbuf(sc);
847879f0effSWeongyo Jeong 		if (data_tx == NULL) {
848*ba2c1fbcSAdrian Chadd 			IFQ_DRV_PREPEND(&ifp->if_snd, m);
849879f0effSWeongyo Jeong 			break;
850879f0effSWeongyo Jeong 		}
851879f0effSWeongyo Jeong 
852879f0effSWeongyo Jeong 		ni = (struct ieee80211_node *)m->m_pkthdr.rcvif;
853879f0effSWeongyo Jeong 		m->m_pkthdr.rcvif = NULL;
854879f0effSWeongyo Jeong 
855879f0effSWeongyo Jeong 		if (upgt_tx_start(sc, m, ni, data_tx) != 0) {
856879f0effSWeongyo Jeong 			STAILQ_INSERT_HEAD(&sc->sc_tx_inactive, data_tx, next);
857879f0effSWeongyo Jeong 			UPGT_STAT_INC(sc, st_tx_inactive);
858879f0effSWeongyo Jeong 			ieee80211_free_node(ni);
859*ba2c1fbcSAdrian Chadd 			if_inc_counter(ifp, IFCOUNTER_OERRORS, 1);
860879f0effSWeongyo Jeong 			continue;
861879f0effSWeongyo Jeong 		}
862879f0effSWeongyo Jeong 		sc->sc_tx_timer = 5;
863879f0effSWeongyo Jeong 	}
864*ba2c1fbcSAdrian Chadd 	UPGT_UNLOCK(sc);
865879f0effSWeongyo Jeong }
866879f0effSWeongyo Jeong 
867879f0effSWeongyo Jeong static int
868879f0effSWeongyo Jeong upgt_raw_xmit(struct ieee80211_node *ni, struct mbuf *m,
869879f0effSWeongyo Jeong 	const struct ieee80211_bpf_params *params)
870879f0effSWeongyo Jeong {
871879f0effSWeongyo Jeong 	struct ieee80211com *ic = ni->ni_ic;
872*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = ic->ic_ifp;
873*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = ifp->if_softc;
874879f0effSWeongyo Jeong 	struct upgt_data *data_tx = NULL;
875879f0effSWeongyo Jeong 
876879f0effSWeongyo Jeong 	/* prevent management frames from being sent if we're not ready */
877*ba2c1fbcSAdrian Chadd 	if (!(ifp->if_drv_flags & IFF_DRV_RUNNING)) {
878879f0effSWeongyo Jeong 		m_freem(m);
879879f0effSWeongyo Jeong 		ieee80211_free_node(ni);
880879f0effSWeongyo Jeong 		return ENETDOWN;
881879f0effSWeongyo Jeong 	}
882879f0effSWeongyo Jeong 
883*ba2c1fbcSAdrian Chadd 	UPGT_LOCK(sc);
884879f0effSWeongyo Jeong 	data_tx = upgt_gettxbuf(sc);
885879f0effSWeongyo Jeong 	if (data_tx == NULL) {
886879f0effSWeongyo Jeong 		ieee80211_free_node(ni);
887879f0effSWeongyo Jeong 		m_freem(m);
888879f0effSWeongyo Jeong 		UPGT_UNLOCK(sc);
889879f0effSWeongyo Jeong 		return (ENOBUFS);
890879f0effSWeongyo Jeong 	}
891879f0effSWeongyo Jeong 
892879f0effSWeongyo Jeong 	if (upgt_tx_start(sc, m, ni, data_tx) != 0) {
893879f0effSWeongyo Jeong 		STAILQ_INSERT_HEAD(&sc->sc_tx_inactive, data_tx, next);
894879f0effSWeongyo Jeong 		UPGT_STAT_INC(sc, st_tx_inactive);
895879f0effSWeongyo Jeong 		ieee80211_free_node(ni);
896*ba2c1fbcSAdrian Chadd 		if_inc_counter(ifp, IFCOUNTER_OERRORS, 1);
897879f0effSWeongyo Jeong 		UPGT_UNLOCK(sc);
898879f0effSWeongyo Jeong 		return (EIO);
899879f0effSWeongyo Jeong 	}
900879f0effSWeongyo Jeong 	UPGT_UNLOCK(sc);
901879f0effSWeongyo Jeong 
902879f0effSWeongyo Jeong 	sc->sc_tx_timer = 5;
903879f0effSWeongyo Jeong 	return (0);
904879f0effSWeongyo Jeong }
905879f0effSWeongyo Jeong 
906879f0effSWeongyo Jeong static void
907879f0effSWeongyo Jeong upgt_watchdog(void *arg)
908879f0effSWeongyo Jeong {
909879f0effSWeongyo Jeong 	struct upgt_softc *sc = arg;
910*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
911879f0effSWeongyo Jeong 
912879f0effSWeongyo Jeong 	if (sc->sc_tx_timer > 0) {
913879f0effSWeongyo Jeong 		if (--sc->sc_tx_timer == 0) {
914879f0effSWeongyo Jeong 			device_printf(sc->sc_dev, "watchdog timeout\n");
915*ba2c1fbcSAdrian Chadd 			/* upgt_init(ifp); XXX needs a process context ? */
916*ba2c1fbcSAdrian Chadd 			if_inc_counter(ifp, IFCOUNTER_OERRORS, 1);
917879f0effSWeongyo Jeong 			return;
918879f0effSWeongyo Jeong 		}
919879f0effSWeongyo Jeong 		callout_reset(&sc->sc_watchdog_ch, hz, upgt_watchdog, sc);
920879f0effSWeongyo Jeong 	}
921879f0effSWeongyo Jeong }
922879f0effSWeongyo Jeong 
923879f0effSWeongyo Jeong static uint32_t
924879f0effSWeongyo Jeong upgt_mem_alloc(struct upgt_softc *sc)
925879f0effSWeongyo Jeong {
926879f0effSWeongyo Jeong 	int i;
927879f0effSWeongyo Jeong 
928879f0effSWeongyo Jeong 	for (i = 0; i < sc->sc_memory.pages; i++) {
929879f0effSWeongyo Jeong 		if (sc->sc_memory.page[i].used == 0) {
930879f0effSWeongyo Jeong 			sc->sc_memory.page[i].used = 1;
931879f0effSWeongyo Jeong 			return (sc->sc_memory.page[i].addr);
932879f0effSWeongyo Jeong 		}
933879f0effSWeongyo Jeong 	}
934879f0effSWeongyo Jeong 
935879f0effSWeongyo Jeong 	return (0);
936879f0effSWeongyo Jeong }
937879f0effSWeongyo Jeong 
938879f0effSWeongyo Jeong static void
939879f0effSWeongyo Jeong upgt_scan_start(struct ieee80211com *ic)
940879f0effSWeongyo Jeong {
941879f0effSWeongyo Jeong 	/* do nothing.  */
942879f0effSWeongyo Jeong }
943879f0effSWeongyo Jeong 
944879f0effSWeongyo Jeong static void
945879f0effSWeongyo Jeong upgt_scan_end(struct ieee80211com *ic)
946879f0effSWeongyo Jeong {
947879f0effSWeongyo Jeong 	/* do nothing.  */
948879f0effSWeongyo Jeong }
949879f0effSWeongyo Jeong 
950879f0effSWeongyo Jeong static void
951879f0effSWeongyo Jeong upgt_set_channel(struct ieee80211com *ic)
952879f0effSWeongyo Jeong {
953*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = ic->ic_ifp->if_softc;
954879f0effSWeongyo Jeong 
955879f0effSWeongyo Jeong 	UPGT_LOCK(sc);
956879f0effSWeongyo Jeong 	upgt_set_chan(sc, ic->ic_curchan);
957879f0effSWeongyo Jeong 	UPGT_UNLOCK(sc);
958879f0effSWeongyo Jeong }
959879f0effSWeongyo Jeong 
960879f0effSWeongyo Jeong static void
961879f0effSWeongyo Jeong upgt_set_chan(struct upgt_softc *sc, struct ieee80211_channel *c)
962879f0effSWeongyo Jeong {
963*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
964*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
965879f0effSWeongyo Jeong 	struct upgt_data *data_cmd;
966879f0effSWeongyo Jeong 	struct upgt_lmac_mem *mem;
967879f0effSWeongyo Jeong 	struct upgt_lmac_channel *chan;
968879f0effSWeongyo Jeong 	int channel;
969879f0effSWeongyo Jeong 
970879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
971879f0effSWeongyo Jeong 
972879f0effSWeongyo Jeong 	channel = ieee80211_chan2ieee(ic, c);
973879f0effSWeongyo Jeong 	if (channel == 0 || channel == IEEE80211_CHAN_ANY) {
974879f0effSWeongyo Jeong 		/* XXX should NEVER happen */
975879f0effSWeongyo Jeong 		device_printf(sc->sc_dev,
976879f0effSWeongyo Jeong 		    "%s: invalid channel %x\n", __func__, channel);
977879f0effSWeongyo Jeong 		return;
978879f0effSWeongyo Jeong 	}
979879f0effSWeongyo Jeong 
980879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_STATE, "%s: channel %d\n", __func__, channel);
981879f0effSWeongyo Jeong 
982879f0effSWeongyo Jeong 	data_cmd = upgt_getbuf(sc);
983879f0effSWeongyo Jeong 	if (data_cmd == NULL) {
984879f0effSWeongyo Jeong 		device_printf(sc->sc_dev, "%s: out of buffers.\n", __func__);
985879f0effSWeongyo Jeong 		return;
986879f0effSWeongyo Jeong 	}
987879f0effSWeongyo Jeong 	/*
988879f0effSWeongyo Jeong 	 * Transmit the URB containing the CMD data.
989879f0effSWeongyo Jeong 	 */
990271ae033SHans Petter Selasky 	memset(data_cmd->buf, 0, MCLBYTES);
991879f0effSWeongyo Jeong 
992879f0effSWeongyo Jeong 	mem = (struct upgt_lmac_mem *)data_cmd->buf;
993879f0effSWeongyo Jeong 	mem->addr = htole32(sc->sc_memaddr_frame_start +
994879f0effSWeongyo Jeong 	    UPGT_MEMSIZE_FRAME_HEAD);
995879f0effSWeongyo Jeong 
996879f0effSWeongyo Jeong 	chan = (struct upgt_lmac_channel *)(mem + 1);
997879f0effSWeongyo Jeong 
998879f0effSWeongyo Jeong 	chan->header1.flags = UPGT_H1_FLAGS_TX_NO_CALLBACK;
999879f0effSWeongyo Jeong 	chan->header1.type = UPGT_H1_TYPE_CTRL;
1000879f0effSWeongyo Jeong 	chan->header1.len = htole16(
1001879f0effSWeongyo Jeong 	    sizeof(struct upgt_lmac_channel) - sizeof(struct upgt_lmac_header));
1002879f0effSWeongyo Jeong 
1003879f0effSWeongyo Jeong 	chan->header2.reqid = htole32(sc->sc_memaddr_frame_start);
1004879f0effSWeongyo Jeong 	chan->header2.type = htole16(UPGT_H2_TYPE_CHANNEL);
1005879f0effSWeongyo Jeong 	chan->header2.flags = 0;
1006879f0effSWeongyo Jeong 
1007879f0effSWeongyo Jeong 	chan->unknown1 = htole16(UPGT_CHANNEL_UNKNOWN1);
1008879f0effSWeongyo Jeong 	chan->unknown2 = htole16(UPGT_CHANNEL_UNKNOWN2);
1009879f0effSWeongyo Jeong 	chan->freq6 = sc->sc_eeprom_freq6[channel];
1010879f0effSWeongyo Jeong 	chan->settings = sc->sc_eeprom_freq6_settings;
1011879f0effSWeongyo Jeong 	chan->unknown3 = UPGT_CHANNEL_UNKNOWN3;
1012879f0effSWeongyo Jeong 
1013271ae033SHans Petter Selasky 	memcpy(chan->freq3_1, &sc->sc_eeprom_freq3[channel].data,
1014879f0effSWeongyo Jeong 	    sizeof(chan->freq3_1));
1015271ae033SHans Petter Selasky 	memcpy(chan->freq4, &sc->sc_eeprom_freq4[channel],
1016879f0effSWeongyo Jeong 	    sizeof(sc->sc_eeprom_freq4[channel]));
1017271ae033SHans Petter Selasky 	memcpy(chan->freq3_2, &sc->sc_eeprom_freq3[channel].data,
1018879f0effSWeongyo Jeong 	    sizeof(chan->freq3_2));
1019879f0effSWeongyo Jeong 
1020879f0effSWeongyo Jeong 	data_cmd->buflen = sizeof(*mem) + sizeof(*chan);
1021879f0effSWeongyo Jeong 
1022879f0effSWeongyo Jeong 	mem->chksum = upgt_chksum_le((uint32_t *)chan,
1023879f0effSWeongyo Jeong 	    data_cmd->buflen - sizeof(*mem));
1024879f0effSWeongyo Jeong 
1025879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data_cmd);
1026879f0effSWeongyo Jeong }
1027879f0effSWeongyo Jeong 
1028879f0effSWeongyo Jeong static struct ieee80211vap *
1029fcd9500fSBernhard Schmidt upgt_vap_create(struct ieee80211com *ic, const char name[IFNAMSIZ], int unit,
1030fcd9500fSBernhard Schmidt     enum ieee80211_opmode opmode, int flags,
1031879f0effSWeongyo Jeong     const uint8_t bssid[IEEE80211_ADDR_LEN],
1032879f0effSWeongyo Jeong     const uint8_t mac[IEEE80211_ADDR_LEN])
1033879f0effSWeongyo Jeong {
1034879f0effSWeongyo Jeong 	struct upgt_vap *uvp;
1035879f0effSWeongyo Jeong 	struct ieee80211vap *vap;
1036879f0effSWeongyo Jeong 
1037879f0effSWeongyo Jeong 	if (!TAILQ_EMPTY(&ic->ic_vaps))		/* only one at a time */
1038879f0effSWeongyo Jeong 		return NULL;
1039879f0effSWeongyo Jeong 	uvp = (struct upgt_vap *) malloc(sizeof(struct upgt_vap),
1040879f0effSWeongyo Jeong 	    M_80211_VAP, M_NOWAIT | M_ZERO);
1041879f0effSWeongyo Jeong 	if (uvp == NULL)
1042879f0effSWeongyo Jeong 		return NULL;
1043879f0effSWeongyo Jeong 	vap = &uvp->vap;
1044879f0effSWeongyo Jeong 	/* enable s/w bmiss handling for sta mode */
1045bb2f69e8SHans Petter Selasky 
1046bb2f69e8SHans Petter Selasky 	if (ieee80211_vap_setup(ic, vap, name, unit, opmode,
1047*ba2c1fbcSAdrian Chadd 	    flags | IEEE80211_CLONE_NOBEACONS, bssid, mac) != 0) {
1048bb2f69e8SHans Petter Selasky 		/* out of memory */
1049bb2f69e8SHans Petter Selasky 		free(uvp, M_80211_VAP);
1050bb2f69e8SHans Petter Selasky 		return (NULL);
1051bb2f69e8SHans Petter Selasky 	}
1052879f0effSWeongyo Jeong 
1053879f0effSWeongyo Jeong 	/* override state transition machine */
1054879f0effSWeongyo Jeong 	uvp->newstate = vap->iv_newstate;
1055879f0effSWeongyo Jeong 	vap->iv_newstate = upgt_newstate;
1056879f0effSWeongyo Jeong 
1057879f0effSWeongyo Jeong 	/* setup device rates */
1058879f0effSWeongyo Jeong 	upgt_setup_rates(vap, ic);
1059879f0effSWeongyo Jeong 
1060879f0effSWeongyo Jeong 	/* complete setup */
1061879f0effSWeongyo Jeong 	ieee80211_vap_attach(vap, ieee80211_media_change,
1062*ba2c1fbcSAdrian Chadd 	    ieee80211_media_status);
1063879f0effSWeongyo Jeong 	ic->ic_opmode = opmode;
1064879f0effSWeongyo Jeong 	return vap;
1065879f0effSWeongyo Jeong }
1066879f0effSWeongyo Jeong 
1067879f0effSWeongyo Jeong static int
1068879f0effSWeongyo Jeong upgt_newstate(struct ieee80211vap *vap, enum ieee80211_state nstate, int arg)
1069879f0effSWeongyo Jeong {
1070879f0effSWeongyo Jeong 	struct upgt_vap *uvp = UPGT_VAP(vap);
1071879f0effSWeongyo Jeong 	struct ieee80211com *ic = vap->iv_ic;
1072*ba2c1fbcSAdrian Chadd 	struct upgt_softc *sc = ic->ic_ifp->if_softc;
1073879f0effSWeongyo Jeong 
1074879f0effSWeongyo Jeong 	/* do it in a process context */
1075879f0effSWeongyo Jeong 	sc->sc_state = nstate;
1076879f0effSWeongyo Jeong 
1077879f0effSWeongyo Jeong 	IEEE80211_UNLOCK(ic);
1078879f0effSWeongyo Jeong 	UPGT_LOCK(sc);
1079879f0effSWeongyo Jeong 	callout_stop(&sc->sc_led_ch);
1080879f0effSWeongyo Jeong 	callout_stop(&sc->sc_watchdog_ch);
1081879f0effSWeongyo Jeong 
1082879f0effSWeongyo Jeong 	switch (nstate) {
1083879f0effSWeongyo Jeong 	case IEEE80211_S_INIT:
1084879f0effSWeongyo Jeong 		/* do not accept any frames if the device is down */
1085879f0effSWeongyo Jeong 		(void)upgt_set_macfilter(sc, sc->sc_state);
1086879f0effSWeongyo Jeong 		upgt_set_led(sc, UPGT_LED_OFF);
1087879f0effSWeongyo Jeong 		break;
1088879f0effSWeongyo Jeong 	case IEEE80211_S_SCAN:
1089879f0effSWeongyo Jeong 		upgt_set_chan(sc, ic->ic_curchan);
1090879f0effSWeongyo Jeong 		break;
1091879f0effSWeongyo Jeong 	case IEEE80211_S_AUTH:
1092879f0effSWeongyo Jeong 		upgt_set_chan(sc, ic->ic_curchan);
1093879f0effSWeongyo Jeong 		break;
1094879f0effSWeongyo Jeong 	case IEEE80211_S_ASSOC:
1095879f0effSWeongyo Jeong 		break;
1096879f0effSWeongyo Jeong 	case IEEE80211_S_RUN:
1097879f0effSWeongyo Jeong 		upgt_set_macfilter(sc, sc->sc_state);
1098879f0effSWeongyo Jeong 		upgt_set_led(sc, UPGT_LED_ON);
1099879f0effSWeongyo Jeong 		break;
1100879f0effSWeongyo Jeong 	default:
1101879f0effSWeongyo Jeong 		break;
1102879f0effSWeongyo Jeong 	}
1103879f0effSWeongyo Jeong 	UPGT_UNLOCK(sc);
1104879f0effSWeongyo Jeong 	IEEE80211_LOCK(ic);
1105879f0effSWeongyo Jeong 	return (uvp->newstate(vap, nstate, arg));
1106879f0effSWeongyo Jeong }
1107879f0effSWeongyo Jeong 
1108879f0effSWeongyo Jeong static void
1109879f0effSWeongyo Jeong upgt_vap_delete(struct ieee80211vap *vap)
1110879f0effSWeongyo Jeong {
1111879f0effSWeongyo Jeong 	struct upgt_vap *uvp = UPGT_VAP(vap);
1112879f0effSWeongyo Jeong 
1113879f0effSWeongyo Jeong 	ieee80211_vap_detach(vap);
1114879f0effSWeongyo Jeong 	free(uvp, M_80211_VAP);
1115879f0effSWeongyo Jeong }
1116879f0effSWeongyo Jeong 
1117879f0effSWeongyo Jeong static void
1118272f6adeSGleb Smirnoff upgt_update_mcast(struct ieee80211com *ic)
1119879f0effSWeongyo Jeong {
1120272f6adeSGleb Smirnoff 	struct upgt_softc *sc = ic->ic_softc;
1121879f0effSWeongyo Jeong 
1122879f0effSWeongyo Jeong 	upgt_set_multi(sc);
1123879f0effSWeongyo Jeong }
1124879f0effSWeongyo Jeong 
1125879f0effSWeongyo Jeong static int
1126879f0effSWeongyo Jeong upgt_eeprom_parse(struct upgt_softc *sc)
1127879f0effSWeongyo Jeong {
1128879f0effSWeongyo Jeong 	struct upgt_eeprom_header *eeprom_header;
1129879f0effSWeongyo Jeong 	struct upgt_eeprom_option *eeprom_option;
1130879f0effSWeongyo Jeong 	uint16_t option_len;
1131879f0effSWeongyo Jeong 	uint16_t option_type;
1132879f0effSWeongyo Jeong 	uint16_t preamble_len;
1133879f0effSWeongyo Jeong 	int option_end = 0;
1134879f0effSWeongyo Jeong 
1135879f0effSWeongyo Jeong 	/* calculate eeprom options start offset */
1136879f0effSWeongyo Jeong 	eeprom_header = (struct upgt_eeprom_header *)sc->sc_eeprom;
1137879f0effSWeongyo Jeong 	preamble_len = le16toh(eeprom_header->preamble_len);
1138879f0effSWeongyo Jeong 	eeprom_option = (struct upgt_eeprom_option *)(sc->sc_eeprom +
1139879f0effSWeongyo Jeong 	    (sizeof(struct upgt_eeprom_header) + preamble_len));
1140879f0effSWeongyo Jeong 
1141879f0effSWeongyo Jeong 	while (!option_end) {
11421b9c9ab2SHans Petter Selasky 
11431b9c9ab2SHans Petter Selasky 		/* sanity check */
11441b9c9ab2SHans Petter Selasky 		if (eeprom_option >= (struct upgt_eeprom_option *)
11451b9c9ab2SHans Petter Selasky 		    (sc->sc_eeprom + UPGT_EEPROM_SIZE)) {
11461b9c9ab2SHans Petter Selasky 			return (EINVAL);
11471b9c9ab2SHans Petter Selasky 		}
11481b9c9ab2SHans Petter Selasky 
1149879f0effSWeongyo Jeong 		/* the eeprom option length is stored in words */
1150879f0effSWeongyo Jeong 		option_len =
1151879f0effSWeongyo Jeong 		    (le16toh(eeprom_option->len) - 1) * sizeof(uint16_t);
1152879f0effSWeongyo Jeong 		option_type =
1153879f0effSWeongyo Jeong 		    le16toh(eeprom_option->type);
1154879f0effSWeongyo Jeong 
11551b9c9ab2SHans Petter Selasky 		/* sanity check */
11561b9c9ab2SHans Petter Selasky 		if (option_len == 0 || option_len >= UPGT_EEPROM_SIZE)
11571b9c9ab2SHans Petter Selasky 			return (EINVAL);
11581b9c9ab2SHans Petter Selasky 
1159879f0effSWeongyo Jeong 		switch (option_type) {
1160879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_NAME:
1161879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1162879f0effSWeongyo Jeong 			    "EEPROM name len=%d\n", option_len);
1163879f0effSWeongyo Jeong 			break;
1164879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_SERIAL:
1165879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1166879f0effSWeongyo Jeong 			    "EEPROM serial len=%d\n", option_len);
1167879f0effSWeongyo Jeong 			break;
1168879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_MAC:
1169879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1170879f0effSWeongyo Jeong 			    "EEPROM mac len=%d\n", option_len);
1171879f0effSWeongyo Jeong 
1172*ba2c1fbcSAdrian Chadd 			IEEE80211_ADDR_COPY(sc->sc_myaddr, eeprom_option->data);
1173879f0effSWeongyo Jeong 			break;
1174879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_HWRX:
1175879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1176879f0effSWeongyo Jeong 			    "EEPROM hwrx len=%d\n", option_len);
1177879f0effSWeongyo Jeong 
1178879f0effSWeongyo Jeong 			upgt_eeprom_parse_hwrx(sc, eeprom_option->data);
1179879f0effSWeongyo Jeong 			break;
1180879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_CHIP:
1181879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1182879f0effSWeongyo Jeong 			    "EEPROM chip len=%d\n", option_len);
1183879f0effSWeongyo Jeong 			break;
1184879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_FREQ3:
1185879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1186879f0effSWeongyo Jeong 			    "EEPROM freq3 len=%d\n", option_len);
1187879f0effSWeongyo Jeong 
1188879f0effSWeongyo Jeong 			upgt_eeprom_parse_freq3(sc, eeprom_option->data,
1189879f0effSWeongyo Jeong 			    option_len);
1190879f0effSWeongyo Jeong 			break;
1191879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_FREQ4:
1192879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1193879f0effSWeongyo Jeong 			    "EEPROM freq4 len=%d\n", option_len);
1194879f0effSWeongyo Jeong 
1195879f0effSWeongyo Jeong 			upgt_eeprom_parse_freq4(sc, eeprom_option->data,
1196879f0effSWeongyo Jeong 			    option_len);
1197879f0effSWeongyo Jeong 			break;
1198879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_FREQ5:
1199879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1200879f0effSWeongyo Jeong 			    "EEPROM freq5 len=%d\n", option_len);
1201879f0effSWeongyo Jeong 			break;
1202879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_FREQ6:
1203879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1204879f0effSWeongyo Jeong 			    "EEPROM freq6 len=%d\n", option_len);
1205879f0effSWeongyo Jeong 
1206879f0effSWeongyo Jeong 			upgt_eeprom_parse_freq6(sc, eeprom_option->data,
1207879f0effSWeongyo Jeong 			    option_len);
1208879f0effSWeongyo Jeong 			break;
1209879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_END:
1210879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1211879f0effSWeongyo Jeong 			    "EEPROM end len=%d\n", option_len);
1212879f0effSWeongyo Jeong 			option_end = 1;
1213879f0effSWeongyo Jeong 			break;
1214879f0effSWeongyo Jeong 		case UPGT_EEPROM_TYPE_OFF:
1215879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1216767cb2e2SAndrew Thompson 			    "%s: EEPROM off without end option\n", __func__);
1217879f0effSWeongyo Jeong 			return (EIO);
1218879f0effSWeongyo Jeong 		default:
1219879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1220879f0effSWeongyo Jeong 			    "EEPROM unknown type 0x%04x len=%d\n",
1221879f0effSWeongyo Jeong 			    option_type, option_len);
1222879f0effSWeongyo Jeong 			break;
1223879f0effSWeongyo Jeong 		}
1224879f0effSWeongyo Jeong 
1225879f0effSWeongyo Jeong 		/* jump to next EEPROM option */
1226879f0effSWeongyo Jeong 		eeprom_option = (struct upgt_eeprom_option *)
1227879f0effSWeongyo Jeong 		    (eeprom_option->data + option_len);
1228879f0effSWeongyo Jeong 	}
1229879f0effSWeongyo Jeong 	return (0);
1230879f0effSWeongyo Jeong }
1231879f0effSWeongyo Jeong 
1232879f0effSWeongyo Jeong static void
1233879f0effSWeongyo Jeong upgt_eeprom_parse_freq3(struct upgt_softc *sc, uint8_t *data, int len)
1234879f0effSWeongyo Jeong {
1235879f0effSWeongyo Jeong 	struct upgt_eeprom_freq3_header *freq3_header;
1236879f0effSWeongyo Jeong 	struct upgt_lmac_freq3 *freq3;
12371b9c9ab2SHans Petter Selasky 	int i;
12381b9c9ab2SHans Petter Selasky 	int elements;
12391b9c9ab2SHans Petter Selasky 	int flags;
1240879f0effSWeongyo Jeong 	unsigned channel;
1241879f0effSWeongyo Jeong 
1242879f0effSWeongyo Jeong 	freq3_header = (struct upgt_eeprom_freq3_header *)data;
1243879f0effSWeongyo Jeong 	freq3 = (struct upgt_lmac_freq3 *)(freq3_header + 1);
1244879f0effSWeongyo Jeong 
1245879f0effSWeongyo Jeong 	flags = freq3_header->flags;
1246879f0effSWeongyo Jeong 	elements = freq3_header->elements;
1247879f0effSWeongyo Jeong 
1248879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "flags=0x%02x elements=%d\n",
1249879f0effSWeongyo Jeong 	    flags, elements);
1250879f0effSWeongyo Jeong 
12511b9c9ab2SHans Petter Selasky 	if (elements >= (int)(UPGT_EEPROM_SIZE / sizeof(freq3[0])))
12521b9c9ab2SHans Petter Selasky 		return;
12531b9c9ab2SHans Petter Selasky 
1254879f0effSWeongyo Jeong 	for (i = 0; i < elements; i++) {
1255879f0effSWeongyo Jeong 		channel = ieee80211_mhz2ieee(le16toh(freq3[i].freq), 0);
12566d917491SHans Petter Selasky 		if (channel >= IEEE80211_CHAN_MAX)
1257879f0effSWeongyo Jeong 			continue;
1258879f0effSWeongyo Jeong 
1259879f0effSWeongyo Jeong 		sc->sc_eeprom_freq3[channel] = freq3[i];
1260879f0effSWeongyo Jeong 
1261879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_FW, "frequence=%d, channel=%d\n",
1262879f0effSWeongyo Jeong 		    le16toh(sc->sc_eeprom_freq3[channel].freq), channel);
1263879f0effSWeongyo Jeong 	}
1264879f0effSWeongyo Jeong }
1265879f0effSWeongyo Jeong 
1266879f0effSWeongyo Jeong void
1267879f0effSWeongyo Jeong upgt_eeprom_parse_freq4(struct upgt_softc *sc, uint8_t *data, int len)
1268879f0effSWeongyo Jeong {
1269879f0effSWeongyo Jeong 	struct upgt_eeprom_freq4_header *freq4_header;
1270879f0effSWeongyo Jeong 	struct upgt_eeprom_freq4_1 *freq4_1;
1271879f0effSWeongyo Jeong 	struct upgt_eeprom_freq4_2 *freq4_2;
12721b9c9ab2SHans Petter Selasky 	int i;
12731b9c9ab2SHans Petter Selasky 	int j;
12741b9c9ab2SHans Petter Selasky 	int elements;
12751b9c9ab2SHans Petter Selasky 	int settings;
12761b9c9ab2SHans Petter Selasky 	int flags;
1277879f0effSWeongyo Jeong 	unsigned channel;
1278879f0effSWeongyo Jeong 
1279879f0effSWeongyo Jeong 	freq4_header = (struct upgt_eeprom_freq4_header *)data;
1280879f0effSWeongyo Jeong 	freq4_1 = (struct upgt_eeprom_freq4_1 *)(freq4_header + 1);
1281879f0effSWeongyo Jeong 	flags = freq4_header->flags;
1282879f0effSWeongyo Jeong 	elements = freq4_header->elements;
1283879f0effSWeongyo Jeong 	settings = freq4_header->settings;
1284879f0effSWeongyo Jeong 
1285879f0effSWeongyo Jeong 	/* we need this value later */
1286879f0effSWeongyo Jeong 	sc->sc_eeprom_freq6_settings = freq4_header->settings;
1287879f0effSWeongyo Jeong 
1288879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "flags=0x%02x elements=%d settings=%d\n",
1289879f0effSWeongyo Jeong 	    flags, elements, settings);
1290879f0effSWeongyo Jeong 
12911b9c9ab2SHans Petter Selasky 	if (elements >= (int)(UPGT_EEPROM_SIZE / sizeof(freq4_1[0])))
12921b9c9ab2SHans Petter Selasky 		return;
12931b9c9ab2SHans Petter Selasky 
1294879f0effSWeongyo Jeong 	for (i = 0; i < elements; i++) {
1295879f0effSWeongyo Jeong 		channel = ieee80211_mhz2ieee(le16toh(freq4_1[i].freq), 0);
12966d917491SHans Petter Selasky 		if (channel >= IEEE80211_CHAN_MAX)
1297879f0effSWeongyo Jeong 			continue;
1298879f0effSWeongyo Jeong 
1299879f0effSWeongyo Jeong 		freq4_2 = (struct upgt_eeprom_freq4_2 *)freq4_1[i].data;
1300879f0effSWeongyo Jeong 		for (j = 0; j < settings; j++) {
1301879f0effSWeongyo Jeong 			sc->sc_eeprom_freq4[channel][j].cmd = freq4_2[j];
1302879f0effSWeongyo Jeong 			sc->sc_eeprom_freq4[channel][j].pad = 0;
1303879f0effSWeongyo Jeong 		}
1304879f0effSWeongyo Jeong 
1305879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_FW, "frequence=%d, channel=%d\n",
1306879f0effSWeongyo Jeong 		    le16toh(freq4_1[i].freq), channel);
1307879f0effSWeongyo Jeong 	}
1308879f0effSWeongyo Jeong }
1309879f0effSWeongyo Jeong 
1310879f0effSWeongyo Jeong void
1311879f0effSWeongyo Jeong upgt_eeprom_parse_freq6(struct upgt_softc *sc, uint8_t *data, int len)
1312879f0effSWeongyo Jeong {
1313879f0effSWeongyo Jeong 	struct upgt_lmac_freq6 *freq6;
13141b9c9ab2SHans Petter Selasky 	int i;
13151b9c9ab2SHans Petter Selasky 	int elements;
1316879f0effSWeongyo Jeong 	unsigned channel;
1317879f0effSWeongyo Jeong 
1318879f0effSWeongyo Jeong 	freq6 = (struct upgt_lmac_freq6 *)data;
1319879f0effSWeongyo Jeong 	elements = len / sizeof(struct upgt_lmac_freq6);
1320879f0effSWeongyo Jeong 
1321879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "elements=%d\n", elements);
1322879f0effSWeongyo Jeong 
13231b9c9ab2SHans Petter Selasky 	if (elements >= (int)(UPGT_EEPROM_SIZE / sizeof(freq6[0])))
13241b9c9ab2SHans Petter Selasky 		return;
13251b9c9ab2SHans Petter Selasky 
1326879f0effSWeongyo Jeong 	for (i = 0; i < elements; i++) {
1327879f0effSWeongyo Jeong 		channel = ieee80211_mhz2ieee(le16toh(freq6[i].freq), 0);
13286d917491SHans Petter Selasky 		if (channel >= IEEE80211_CHAN_MAX)
1329879f0effSWeongyo Jeong 			continue;
1330879f0effSWeongyo Jeong 
1331879f0effSWeongyo Jeong 		sc->sc_eeprom_freq6[channel] = freq6[i];
1332879f0effSWeongyo Jeong 
1333879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_FW, "frequence=%d, channel=%d\n",
1334879f0effSWeongyo Jeong 		    le16toh(sc->sc_eeprom_freq6[channel].freq), channel);
1335879f0effSWeongyo Jeong 	}
1336879f0effSWeongyo Jeong }
1337879f0effSWeongyo Jeong 
1338879f0effSWeongyo Jeong static void
1339879f0effSWeongyo Jeong upgt_eeprom_parse_hwrx(struct upgt_softc *sc, uint8_t *data)
1340879f0effSWeongyo Jeong {
1341879f0effSWeongyo Jeong 	struct upgt_eeprom_option_hwrx *option_hwrx;
1342879f0effSWeongyo Jeong 
1343879f0effSWeongyo Jeong 	option_hwrx = (struct upgt_eeprom_option_hwrx *)data;
1344879f0effSWeongyo Jeong 
1345879f0effSWeongyo Jeong 	sc->sc_eeprom_hwrx = option_hwrx->rxfilter - UPGT_EEPROM_RX_CONST;
1346879f0effSWeongyo Jeong 
1347879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "hwrx option value=0x%04x\n",
1348879f0effSWeongyo Jeong 	    sc->sc_eeprom_hwrx);
1349879f0effSWeongyo Jeong }
1350879f0effSWeongyo Jeong 
1351879f0effSWeongyo Jeong static int
1352879f0effSWeongyo Jeong upgt_eeprom_read(struct upgt_softc *sc)
1353879f0effSWeongyo Jeong {
1354879f0effSWeongyo Jeong 	struct upgt_data *data_cmd;
1355879f0effSWeongyo Jeong 	struct upgt_lmac_mem *mem;
1356879f0effSWeongyo Jeong 	struct upgt_lmac_eeprom	*eeprom;
1357879f0effSWeongyo Jeong 	int block, error, offset;
1358879f0effSWeongyo Jeong 
1359879f0effSWeongyo Jeong 	UPGT_LOCK(sc);
1360a593f6b8SAndrew Thompson 	usb_pause_mtx(&sc->sc_mtx, 100);
1361879f0effSWeongyo Jeong 
1362879f0effSWeongyo Jeong 	offset = 0;
1363879f0effSWeongyo Jeong 	block = UPGT_EEPROM_BLOCK_SIZE;
1364879f0effSWeongyo Jeong 	while (offset < UPGT_EEPROM_SIZE) {
1365879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_FW,
1366879f0effSWeongyo Jeong 		    "request EEPROM block (offset=%d, len=%d)\n", offset, block);
1367879f0effSWeongyo Jeong 
1368879f0effSWeongyo Jeong 		data_cmd = upgt_getbuf(sc);
1369879f0effSWeongyo Jeong 		if (data_cmd == NULL) {
1370879f0effSWeongyo Jeong 			UPGT_UNLOCK(sc);
1371879f0effSWeongyo Jeong 			return (ENOBUFS);
1372879f0effSWeongyo Jeong 		}
1373879f0effSWeongyo Jeong 
1374879f0effSWeongyo Jeong 		/*
1375879f0effSWeongyo Jeong 		 * Transmit the URB containing the CMD data.
1376879f0effSWeongyo Jeong 		 */
1377271ae033SHans Petter Selasky 		memset(data_cmd->buf, 0, MCLBYTES);
1378879f0effSWeongyo Jeong 
1379879f0effSWeongyo Jeong 		mem = (struct upgt_lmac_mem *)data_cmd->buf;
1380879f0effSWeongyo Jeong 		mem->addr = htole32(sc->sc_memaddr_frame_start +
1381879f0effSWeongyo Jeong 		    UPGT_MEMSIZE_FRAME_HEAD);
1382879f0effSWeongyo Jeong 
1383879f0effSWeongyo Jeong 		eeprom = (struct upgt_lmac_eeprom *)(mem + 1);
1384879f0effSWeongyo Jeong 		eeprom->header1.flags = 0;
1385879f0effSWeongyo Jeong 		eeprom->header1.type = UPGT_H1_TYPE_CTRL;
1386879f0effSWeongyo Jeong 		eeprom->header1.len = htole16((
1387879f0effSWeongyo Jeong 		    sizeof(struct upgt_lmac_eeprom) -
1388879f0effSWeongyo Jeong 		    sizeof(struct upgt_lmac_header)) + block);
1389879f0effSWeongyo Jeong 
1390879f0effSWeongyo Jeong 		eeprom->header2.reqid = htole32(sc->sc_memaddr_frame_start);
1391879f0effSWeongyo Jeong 		eeprom->header2.type = htole16(UPGT_H2_TYPE_EEPROM);
1392879f0effSWeongyo Jeong 		eeprom->header2.flags = 0;
1393879f0effSWeongyo Jeong 
1394879f0effSWeongyo Jeong 		eeprom->offset = htole16(offset);
1395879f0effSWeongyo Jeong 		eeprom->len = htole16(block);
1396879f0effSWeongyo Jeong 
1397879f0effSWeongyo Jeong 		data_cmd->buflen = sizeof(*mem) + sizeof(*eeprom) + block;
1398879f0effSWeongyo Jeong 
1399879f0effSWeongyo Jeong 		mem->chksum = upgt_chksum_le((uint32_t *)eeprom,
1400879f0effSWeongyo Jeong 		    data_cmd->buflen - sizeof(*mem));
1401879f0effSWeongyo Jeong 		upgt_bulk_tx(sc, data_cmd);
1402879f0effSWeongyo Jeong 
1403879f0effSWeongyo Jeong 		error = mtx_sleep(sc, &sc->sc_mtx, 0, "eeprom_request", hz);
1404879f0effSWeongyo Jeong 		if (error != 0) {
1405879f0effSWeongyo Jeong 			device_printf(sc->sc_dev,
1406767cb2e2SAndrew Thompson 			    "timeout while waiting for EEPROM data\n");
1407879f0effSWeongyo Jeong 			UPGT_UNLOCK(sc);
1408879f0effSWeongyo Jeong 			return (EIO);
1409879f0effSWeongyo Jeong 		}
1410879f0effSWeongyo Jeong 
1411879f0effSWeongyo Jeong 		offset += block;
1412879f0effSWeongyo Jeong 		if (UPGT_EEPROM_SIZE - offset < block)
1413879f0effSWeongyo Jeong 			block = UPGT_EEPROM_SIZE - offset;
1414879f0effSWeongyo Jeong 	}
1415879f0effSWeongyo Jeong 
1416879f0effSWeongyo Jeong 	UPGT_UNLOCK(sc);
1417879f0effSWeongyo Jeong 	return (0);
1418879f0effSWeongyo Jeong }
1419879f0effSWeongyo Jeong 
1420879f0effSWeongyo Jeong /*
1421879f0effSWeongyo Jeong  * When a rx data came in the function returns a mbuf and a rssi values.
1422879f0effSWeongyo Jeong  */
1423879f0effSWeongyo Jeong static struct mbuf *
1424760bc48eSAndrew Thompson upgt_rxeof(struct usb_xfer *xfer, struct upgt_data *data, int *rssi)
1425879f0effSWeongyo Jeong {
1426879f0effSWeongyo Jeong 	struct mbuf *m = NULL;
1427ed6d949aSAndrew Thompson 	struct upgt_softc *sc = usbd_xfer_softc(xfer);
1428879f0effSWeongyo Jeong 	struct upgt_lmac_header *header;
1429879f0effSWeongyo Jeong 	struct upgt_lmac_eeprom *eeprom;
1430879f0effSWeongyo Jeong 	uint8_t h1_type;
1431879f0effSWeongyo Jeong 	uint16_t h2_type;
1432ed6d949aSAndrew Thompson 	int actlen, sumlen;
1433ed6d949aSAndrew Thompson 
1434ed6d949aSAndrew Thompson 	usbd_xfer_status(xfer, &actlen, &sumlen, NULL, NULL);
1435879f0effSWeongyo Jeong 
1436879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
1437879f0effSWeongyo Jeong 
1438ed6d949aSAndrew Thompson 	if (actlen < 1)
1439879f0effSWeongyo Jeong 		return (NULL);
1440879f0effSWeongyo Jeong 
1441879f0effSWeongyo Jeong 	/* Check only at the very beginning.  */
1442879f0effSWeongyo Jeong 	if (!(sc->sc_flags & UPGT_FLAG_FWLOADED) &&
1443879f0effSWeongyo Jeong 	    (memcmp(data->buf, "OK", 2) == 0)) {
1444879f0effSWeongyo Jeong 		sc->sc_flags |= UPGT_FLAG_FWLOADED;
1445879f0effSWeongyo Jeong 		wakeup_one(sc);
1446879f0effSWeongyo Jeong 		return (NULL);
1447879f0effSWeongyo Jeong 	}
1448879f0effSWeongyo Jeong 
14496d917491SHans Petter Selasky 	if (actlen < (int)UPGT_RX_MINSZ)
1450879f0effSWeongyo Jeong 		return (NULL);
1451879f0effSWeongyo Jeong 
1452879f0effSWeongyo Jeong 	/*
1453879f0effSWeongyo Jeong 	 * Check what type of frame came in.
1454879f0effSWeongyo Jeong 	 */
1455879f0effSWeongyo Jeong 	header = (struct upgt_lmac_header *)(data->buf + 4);
1456879f0effSWeongyo Jeong 
1457879f0effSWeongyo Jeong 	h1_type = header->header1.type;
1458879f0effSWeongyo Jeong 	h2_type = le16toh(header->header2.type);
1459879f0effSWeongyo Jeong 
1460879f0effSWeongyo Jeong 	if (h1_type == UPGT_H1_TYPE_CTRL && h2_type == UPGT_H2_TYPE_EEPROM) {
1461879f0effSWeongyo Jeong 		eeprom = (struct upgt_lmac_eeprom *)(data->buf + 4);
1462879f0effSWeongyo Jeong 		uint16_t eeprom_offset = le16toh(eeprom->offset);
1463879f0effSWeongyo Jeong 		uint16_t eeprom_len = le16toh(eeprom->len);
1464879f0effSWeongyo Jeong 
1465879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_FW,
1466879f0effSWeongyo Jeong 		    "received EEPROM block (offset=%d, len=%d)\n",
1467879f0effSWeongyo Jeong 		    eeprom_offset, eeprom_len);
1468879f0effSWeongyo Jeong 
1469271ae033SHans Petter Selasky 		memcpy(sc->sc_eeprom + eeprom_offset,
1470271ae033SHans Petter Selasky 		    data->buf + sizeof(struct upgt_lmac_eeprom) + 4,
1471271ae033SHans Petter Selasky 		    eeprom_len);
1472879f0effSWeongyo Jeong 
1473879f0effSWeongyo Jeong 		/* EEPROM data has arrived in time, wakeup.  */
1474879f0effSWeongyo Jeong 		wakeup(sc);
1475879f0effSWeongyo Jeong 	} else if (h1_type == UPGT_H1_TYPE_CTRL &&
1476879f0effSWeongyo Jeong 	    h2_type == UPGT_H2_TYPE_TX_DONE) {
1477879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_XMIT, "%s: received 802.11 TX done\n",
1478879f0effSWeongyo Jeong 		    __func__);
1479879f0effSWeongyo Jeong 		upgt_tx_done(sc, data->buf + 4);
1480879f0effSWeongyo Jeong 	} else if (h1_type == UPGT_H1_TYPE_RX_DATA ||
1481879f0effSWeongyo Jeong 	    h1_type == UPGT_H1_TYPE_RX_DATA_MGMT) {
1482879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_RECV, "%s: received 802.11 RX data\n",
1483879f0effSWeongyo Jeong 		    __func__);
1484879f0effSWeongyo Jeong 		m = upgt_rx(sc, data->buf + 4, le16toh(header->header1.len),
1485879f0effSWeongyo Jeong 		    rssi);
1486879f0effSWeongyo Jeong 	} else if (h1_type == UPGT_H1_TYPE_CTRL &&
1487879f0effSWeongyo Jeong 	    h2_type == UPGT_H2_TYPE_STATS) {
1488879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_STAT, "%s: received statistic data\n",
1489879f0effSWeongyo Jeong 		    __func__);
1490879f0effSWeongyo Jeong 		/* TODO: what could we do with the statistic data? */
1491879f0effSWeongyo Jeong 	} else {
1492879f0effSWeongyo Jeong 		/* ignore unknown frame types */
1493879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_INTR,
1494879f0effSWeongyo Jeong 		    "received unknown frame type 0x%02x\n",
1495879f0effSWeongyo Jeong 		    header->header1.type);
1496879f0effSWeongyo Jeong 	}
1497879f0effSWeongyo Jeong 	return (m);
1498879f0effSWeongyo Jeong }
1499879f0effSWeongyo Jeong 
1500879f0effSWeongyo Jeong /*
1501879f0effSWeongyo Jeong  * The firmware awaits a checksum for each frame we send to it.
1502879f0effSWeongyo Jeong  * The algorithm used therefor is uncommon but somehow similar to CRC32.
1503879f0effSWeongyo Jeong  */
1504879f0effSWeongyo Jeong static uint32_t
1505879f0effSWeongyo Jeong upgt_chksum_le(const uint32_t *buf, size_t size)
1506879f0effSWeongyo Jeong {
15076d917491SHans Petter Selasky 	size_t i;
1508879f0effSWeongyo Jeong 	uint32_t crc = 0;
1509879f0effSWeongyo Jeong 
1510879f0effSWeongyo Jeong 	for (i = 0; i < size; i += sizeof(uint32_t)) {
1511879f0effSWeongyo Jeong 		crc = htole32(crc ^ *buf++);
1512879f0effSWeongyo Jeong 		crc = htole32((crc >> 5) ^ (crc << 3));
1513879f0effSWeongyo Jeong 	}
1514879f0effSWeongyo Jeong 
1515879f0effSWeongyo Jeong 	return (crc);
1516879f0effSWeongyo Jeong }
1517879f0effSWeongyo Jeong 
1518879f0effSWeongyo Jeong static struct mbuf *
1519879f0effSWeongyo Jeong upgt_rx(struct upgt_softc *sc, uint8_t *data, int pkglen, int *rssi)
1520879f0effSWeongyo Jeong {
1521*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
1522*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
1523879f0effSWeongyo Jeong 	struct upgt_lmac_rx_desc *rxdesc;
1524879f0effSWeongyo Jeong 	struct mbuf *m;
1525879f0effSWeongyo Jeong 
1526879f0effSWeongyo Jeong 	/*
1527879f0effSWeongyo Jeong 	 * don't pass packets to the ieee80211 framework if the driver isn't
1528879f0effSWeongyo Jeong 	 * RUNNING.
1529879f0effSWeongyo Jeong 	 */
1530*ba2c1fbcSAdrian Chadd 	if (!(ifp->if_drv_flags & IFF_DRV_RUNNING))
1531879f0effSWeongyo Jeong 		return (NULL);
1532879f0effSWeongyo Jeong 
1533879f0effSWeongyo Jeong 	/* access RX packet descriptor */
1534879f0effSWeongyo Jeong 	rxdesc = (struct upgt_lmac_rx_desc *)data;
1535879f0effSWeongyo Jeong 
1536879f0effSWeongyo Jeong 	/* create mbuf which is suitable for strict alignment archs */
1537879f0effSWeongyo Jeong 	KASSERT((pkglen + ETHER_ALIGN) < MCLBYTES,
1538879f0effSWeongyo Jeong 	    ("A current mbuf storage is small (%d)", pkglen + ETHER_ALIGN));
1539c6499eccSGleb Smirnoff 	m = m_getcl(M_NOWAIT, MT_DATA, M_PKTHDR);
1540879f0effSWeongyo Jeong 	if (m == NULL) {
1541767cb2e2SAndrew Thompson 		device_printf(sc->sc_dev, "could not create RX mbuf\n");
1542879f0effSWeongyo Jeong 		return (NULL);
1543879f0effSWeongyo Jeong 	}
1544879f0effSWeongyo Jeong 	m_adj(m, ETHER_ALIGN);
1545271ae033SHans Petter Selasky 	memcpy(mtod(m, char *), rxdesc->data, pkglen);
1546879f0effSWeongyo Jeong 	/* trim FCS */
1547879f0effSWeongyo Jeong 	m->m_len = m->m_pkthdr.len = pkglen - IEEE80211_CRC_LEN;
1548*ba2c1fbcSAdrian Chadd 	m->m_pkthdr.rcvif = ifp;
1549879f0effSWeongyo Jeong 
15505463c4a4SSam Leffler 	if (ieee80211_radiotap_active(ic)) {
1551879f0effSWeongyo Jeong 		struct upgt_rx_radiotap_header *tap = &sc->sc_rxtap;
1552879f0effSWeongyo Jeong 
1553879f0effSWeongyo Jeong 		tap->wr_flags = 0;
1554879f0effSWeongyo Jeong 		tap->wr_rate = upgt_rx_rate(sc, rxdesc->rate);
1555879f0effSWeongyo Jeong 		tap->wr_antsignal = rxdesc->rssi;
1556879f0effSWeongyo Jeong 	}
1557*ba2c1fbcSAdrian Chadd 	if_inc_counter(ifp, IFCOUNTER_IPACKETS, 1);
1558879f0effSWeongyo Jeong 
1559879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_RX_PROC, "%s: RX done\n", __func__);
1560879f0effSWeongyo Jeong 	*rssi = rxdesc->rssi;
1561879f0effSWeongyo Jeong 	return (m);
1562879f0effSWeongyo Jeong }
1563879f0effSWeongyo Jeong 
1564879f0effSWeongyo Jeong static uint8_t
1565879f0effSWeongyo Jeong upgt_rx_rate(struct upgt_softc *sc, const int rate)
1566879f0effSWeongyo Jeong {
1567*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
1568*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
1569879f0effSWeongyo Jeong 	static const uint8_t cck_upgt2rate[4] = { 2, 4, 11, 22 };
1570879f0effSWeongyo Jeong 	static const uint8_t ofdm_upgt2rate[12] =
1571879f0effSWeongyo Jeong 	    { 2, 4, 11, 22, 12, 18, 24, 36, 48, 72, 96, 108 };
1572879f0effSWeongyo Jeong 
1573879f0effSWeongyo Jeong 	if (ic->ic_curmode == IEEE80211_MODE_11B &&
1574879f0effSWeongyo Jeong 	    !(rate < 0 || rate > 3))
1575879f0effSWeongyo Jeong 		return cck_upgt2rate[rate & 0xf];
1576879f0effSWeongyo Jeong 
1577879f0effSWeongyo Jeong 	if (ic->ic_curmode == IEEE80211_MODE_11G &&
1578879f0effSWeongyo Jeong 	    !(rate < 0 || rate > 11))
1579879f0effSWeongyo Jeong 		return ofdm_upgt2rate[rate & 0xf];
1580879f0effSWeongyo Jeong 
1581879f0effSWeongyo Jeong 	return (0);
1582879f0effSWeongyo Jeong }
1583879f0effSWeongyo Jeong 
1584879f0effSWeongyo Jeong static void
1585879f0effSWeongyo Jeong upgt_tx_done(struct upgt_softc *sc, uint8_t *data)
1586879f0effSWeongyo Jeong {
1587*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
1588879f0effSWeongyo Jeong 	struct upgt_lmac_tx_done_desc *desc;
1589879f0effSWeongyo Jeong 	int i, freed = 0;
1590879f0effSWeongyo Jeong 
1591879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
1592879f0effSWeongyo Jeong 
1593879f0effSWeongyo Jeong 	desc = (struct upgt_lmac_tx_done_desc *)data;
1594879f0effSWeongyo Jeong 
1595879f0effSWeongyo Jeong 	for (i = 0; i < UPGT_TX_MAXCOUNT; i++) {
1596879f0effSWeongyo Jeong 		struct upgt_data *data_tx = &sc->sc_tx_data[i];
1597879f0effSWeongyo Jeong 
1598879f0effSWeongyo Jeong 		if (data_tx->addr == le32toh(desc->header2.reqid)) {
1599879f0effSWeongyo Jeong 			upgt_mem_free(sc, data_tx->addr);
1600879f0effSWeongyo Jeong 			data_tx->ni = NULL;
1601879f0effSWeongyo Jeong 			data_tx->addr = 0;
1602879f0effSWeongyo Jeong 			data_tx->m = NULL;
1603879f0effSWeongyo Jeong 
1604879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_TX_PROC,
1605879f0effSWeongyo Jeong 			    "TX done: memaddr=0x%08x, status=0x%04x, rssi=%d, ",
1606879f0effSWeongyo Jeong 			    le32toh(desc->header2.reqid),
1607879f0effSWeongyo Jeong 			    le16toh(desc->status), le16toh(desc->rssi));
1608879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_TX_PROC, "seq=%d\n",
1609879f0effSWeongyo Jeong 			    le16toh(desc->seq));
1610879f0effSWeongyo Jeong 
1611879f0effSWeongyo Jeong 			freed++;
1612879f0effSWeongyo Jeong 		}
1613879f0effSWeongyo Jeong 	}
1614879f0effSWeongyo Jeong 
1615879f0effSWeongyo Jeong 	if (freed != 0) {
161679d2c5e8SGleb Smirnoff 		sc->sc_tx_timer = 0;
1617*ba2c1fbcSAdrian Chadd 		ifp->if_drv_flags &= ~IFF_DRV_OACTIVE;
1618*ba2c1fbcSAdrian Chadd 		UPGT_UNLOCK(sc);
1619*ba2c1fbcSAdrian Chadd 		upgt_start(ifp);
1620879f0effSWeongyo Jeong 		UPGT_LOCK(sc);
1621879f0effSWeongyo Jeong 	}
1622879f0effSWeongyo Jeong }
1623879f0effSWeongyo Jeong 
1624879f0effSWeongyo Jeong static void
1625879f0effSWeongyo Jeong upgt_mem_free(struct upgt_softc *sc, uint32_t addr)
1626879f0effSWeongyo Jeong {
1627879f0effSWeongyo Jeong 	int i;
1628879f0effSWeongyo Jeong 
1629879f0effSWeongyo Jeong 	for (i = 0; i < sc->sc_memory.pages; i++) {
1630879f0effSWeongyo Jeong 		if (sc->sc_memory.page[i].addr == addr) {
1631879f0effSWeongyo Jeong 			sc->sc_memory.page[i].used = 0;
1632879f0effSWeongyo Jeong 			return;
1633879f0effSWeongyo Jeong 		}
1634879f0effSWeongyo Jeong 	}
1635879f0effSWeongyo Jeong 
1636879f0effSWeongyo Jeong 	device_printf(sc->sc_dev,
1637767cb2e2SAndrew Thompson 	    "could not free memory address 0x%08x\n", addr);
1638879f0effSWeongyo Jeong }
1639879f0effSWeongyo Jeong 
1640879f0effSWeongyo Jeong static int
1641879f0effSWeongyo Jeong upgt_fw_load(struct upgt_softc *sc)
1642879f0effSWeongyo Jeong {
1643879f0effSWeongyo Jeong 	const struct firmware *fw;
1644879f0effSWeongyo Jeong 	struct upgt_data *data_cmd;
1645879f0effSWeongyo Jeong 	struct upgt_fw_x2_header *x2;
1646879f0effSWeongyo Jeong 	char start_fwload_cmd[] = { 0x3c, 0x0d };
16476d917491SHans Petter Selasky 	int error = 0;
16486d917491SHans Petter Selasky 	size_t offset;
16496d917491SHans Petter Selasky 	int bsize;
16506d917491SHans Petter Selasky 	int n;
1651879f0effSWeongyo Jeong 	uint32_t crc32;
1652879f0effSWeongyo Jeong 
1653879f0effSWeongyo Jeong 	fw = firmware_get(upgt_fwname);
1654879f0effSWeongyo Jeong 	if (fw == NULL) {
1655767cb2e2SAndrew Thompson 		device_printf(sc->sc_dev, "could not read microcode %s\n",
1656879f0effSWeongyo Jeong 		    upgt_fwname);
1657879f0effSWeongyo Jeong 		return (EIO);
1658879f0effSWeongyo Jeong 	}
1659879f0effSWeongyo Jeong 
1660879f0effSWeongyo Jeong 	UPGT_LOCK(sc);
1661879f0effSWeongyo Jeong 
1662879f0effSWeongyo Jeong 	/* send firmware start load command */
1663879f0effSWeongyo Jeong 	data_cmd = upgt_getbuf(sc);
1664879f0effSWeongyo Jeong 	if (data_cmd == NULL) {
1665879f0effSWeongyo Jeong 		error = ENOBUFS;
1666879f0effSWeongyo Jeong 		goto fail;
1667879f0effSWeongyo Jeong 	}
1668879f0effSWeongyo Jeong 	data_cmd->buflen = sizeof(start_fwload_cmd);
1669271ae033SHans Petter Selasky 	memcpy(data_cmd->buf, start_fwload_cmd, data_cmd->buflen);
1670879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data_cmd);
1671879f0effSWeongyo Jeong 
1672879f0effSWeongyo Jeong 	/* send X2 header */
1673879f0effSWeongyo Jeong 	data_cmd = upgt_getbuf(sc);
1674879f0effSWeongyo Jeong 	if (data_cmd == NULL) {
1675879f0effSWeongyo Jeong 		error = ENOBUFS;
1676879f0effSWeongyo Jeong 		goto fail;
1677879f0effSWeongyo Jeong 	}
1678879f0effSWeongyo Jeong 	data_cmd->buflen = sizeof(struct upgt_fw_x2_header);
1679879f0effSWeongyo Jeong 	x2 = (struct upgt_fw_x2_header *)data_cmd->buf;
1680271ae033SHans Petter Selasky 	memcpy(x2->signature, UPGT_X2_SIGNATURE, UPGT_X2_SIGNATURE_SIZE);
1681879f0effSWeongyo Jeong 	x2->startaddr = htole32(UPGT_MEMADDR_FIRMWARE_START);
1682879f0effSWeongyo Jeong 	x2->len = htole32(fw->datasize);
1683879f0effSWeongyo Jeong 	x2->crc = upgt_crc32_le((uint8_t *)data_cmd->buf +
1684879f0effSWeongyo Jeong 	    UPGT_X2_SIGNATURE_SIZE,
1685879f0effSWeongyo Jeong 	    sizeof(struct upgt_fw_x2_header) - UPGT_X2_SIGNATURE_SIZE -
1686879f0effSWeongyo Jeong 	    sizeof(uint32_t));
1687879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data_cmd);
1688879f0effSWeongyo Jeong 
1689879f0effSWeongyo Jeong 	/* download firmware */
1690879f0effSWeongyo Jeong 	for (offset = 0; offset < fw->datasize; offset += bsize) {
1691879f0effSWeongyo Jeong 		if (fw->datasize - offset > UPGT_FW_BLOCK_SIZE)
1692879f0effSWeongyo Jeong 			bsize = UPGT_FW_BLOCK_SIZE;
1693879f0effSWeongyo Jeong 		else
1694879f0effSWeongyo Jeong 			bsize = fw->datasize - offset;
1695879f0effSWeongyo Jeong 
1696879f0effSWeongyo Jeong 		data_cmd = upgt_getbuf(sc);
1697879f0effSWeongyo Jeong 		if (data_cmd == NULL) {
1698879f0effSWeongyo Jeong 			error = ENOBUFS;
1699879f0effSWeongyo Jeong 			goto fail;
1700879f0effSWeongyo Jeong 		}
1701879f0effSWeongyo Jeong 		n = upgt_fw_copy((const uint8_t *)fw->data + offset,
1702879f0effSWeongyo Jeong 		    data_cmd->buf, bsize);
1703879f0effSWeongyo Jeong 		data_cmd->buflen = bsize;
1704879f0effSWeongyo Jeong 		upgt_bulk_tx(sc, data_cmd);
1705879f0effSWeongyo Jeong 
1706879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_FW, "FW offset=%d, read=%d, sent=%d\n",
1707879f0effSWeongyo Jeong 		    offset, n, bsize);
1708879f0effSWeongyo Jeong 		bsize = n;
1709879f0effSWeongyo Jeong 	}
1710879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "%s: firmware downloaded\n", __func__);
1711879f0effSWeongyo Jeong 
1712879f0effSWeongyo Jeong 	/* load firmware */
1713879f0effSWeongyo Jeong 	data_cmd = upgt_getbuf(sc);
1714879f0effSWeongyo Jeong 	if (data_cmd == NULL) {
1715879f0effSWeongyo Jeong 		error = ENOBUFS;
1716879f0effSWeongyo Jeong 		goto fail;
1717879f0effSWeongyo Jeong 	}
1718879f0effSWeongyo Jeong 	crc32 = upgt_crc32_le(fw->data, fw->datasize);
1719879f0effSWeongyo Jeong 	*((uint32_t *)(data_cmd->buf)    ) = crc32;
1720879f0effSWeongyo Jeong 	*((uint8_t  *)(data_cmd->buf) + 4) = 'g';
1721879f0effSWeongyo Jeong 	*((uint8_t  *)(data_cmd->buf) + 5) = '\r';
1722879f0effSWeongyo Jeong 	data_cmd->buflen = 6;
1723879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data_cmd);
1724879f0effSWeongyo Jeong 
1725879f0effSWeongyo Jeong 	/* waiting 'OK' response.  */
1726a593f6b8SAndrew Thompson 	usbd_transfer_start(sc->sc_xfer[UPGT_BULK_RX]);
1727879f0effSWeongyo Jeong 	error = mtx_sleep(sc, &sc->sc_mtx, 0, "upgtfw", 2 * hz);
1728879f0effSWeongyo Jeong 	if (error != 0) {
1729767cb2e2SAndrew Thompson 		device_printf(sc->sc_dev, "firmware load failed\n");
1730879f0effSWeongyo Jeong 		error = EIO;
1731879f0effSWeongyo Jeong 	}
1732879f0effSWeongyo Jeong 
1733879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "%s: firmware loaded\n", __func__);
1734879f0effSWeongyo Jeong fail:
1735879f0effSWeongyo Jeong 	UPGT_UNLOCK(sc);
1736879f0effSWeongyo Jeong 	firmware_put(fw, FIRMWARE_UNLOAD);
1737879f0effSWeongyo Jeong 	return (error);
1738879f0effSWeongyo Jeong }
1739879f0effSWeongyo Jeong 
1740879f0effSWeongyo Jeong static uint32_t
1741879f0effSWeongyo Jeong upgt_crc32_le(const void *buf, size_t size)
1742879f0effSWeongyo Jeong {
1743879f0effSWeongyo Jeong 	uint32_t crc;
1744879f0effSWeongyo Jeong 
1745879f0effSWeongyo Jeong 	crc = ether_crc32_le(buf, size);
1746879f0effSWeongyo Jeong 
1747879f0effSWeongyo Jeong 	/* apply final XOR value as common for CRC-32 */
1748879f0effSWeongyo Jeong 	crc = htole32(crc ^ 0xffffffffU);
1749879f0effSWeongyo Jeong 
1750879f0effSWeongyo Jeong 	return (crc);
1751879f0effSWeongyo Jeong }
1752879f0effSWeongyo Jeong 
1753879f0effSWeongyo Jeong /*
1754879f0effSWeongyo Jeong  * While copying the version 2 firmware, we need to replace two characters:
1755879f0effSWeongyo Jeong  *
1756879f0effSWeongyo Jeong  * 0x7e -> 0x7d 0x5e
1757879f0effSWeongyo Jeong  * 0x7d -> 0x7d 0x5d
1758879f0effSWeongyo Jeong  */
1759879f0effSWeongyo Jeong static int
1760879f0effSWeongyo Jeong upgt_fw_copy(const uint8_t *src, char *dst, int size)
1761879f0effSWeongyo Jeong {
1762879f0effSWeongyo Jeong 	int i, j;
1763879f0effSWeongyo Jeong 
1764879f0effSWeongyo Jeong 	for (i = 0, j = 0; i < size && j < size; i++) {
1765879f0effSWeongyo Jeong 		switch (src[i]) {
1766879f0effSWeongyo Jeong 		case 0x7e:
1767879f0effSWeongyo Jeong 			dst[j] = 0x7d;
1768879f0effSWeongyo Jeong 			j++;
1769879f0effSWeongyo Jeong 			dst[j] = 0x5e;
1770879f0effSWeongyo Jeong 			j++;
1771879f0effSWeongyo Jeong 			break;
1772879f0effSWeongyo Jeong 		case 0x7d:
1773879f0effSWeongyo Jeong 			dst[j] = 0x7d;
1774879f0effSWeongyo Jeong 			j++;
1775879f0effSWeongyo Jeong 			dst[j] = 0x5d;
1776879f0effSWeongyo Jeong 			j++;
1777879f0effSWeongyo Jeong 			break;
1778879f0effSWeongyo Jeong 		default:
1779879f0effSWeongyo Jeong 			dst[j] = src[i];
1780879f0effSWeongyo Jeong 			j++;
1781879f0effSWeongyo Jeong 			break;
1782879f0effSWeongyo Jeong 		}
1783879f0effSWeongyo Jeong 	}
1784879f0effSWeongyo Jeong 
1785879f0effSWeongyo Jeong 	return (i);
1786879f0effSWeongyo Jeong }
1787879f0effSWeongyo Jeong 
1788879f0effSWeongyo Jeong static int
1789879f0effSWeongyo Jeong upgt_mem_init(struct upgt_softc *sc)
1790879f0effSWeongyo Jeong {
1791879f0effSWeongyo Jeong 	int i;
1792879f0effSWeongyo Jeong 
1793879f0effSWeongyo Jeong 	for (i = 0; i < UPGT_MEMORY_MAX_PAGES; i++) {
1794879f0effSWeongyo Jeong 		sc->sc_memory.page[i].used = 0;
1795879f0effSWeongyo Jeong 
1796879f0effSWeongyo Jeong 		if (i == 0) {
1797879f0effSWeongyo Jeong 			/*
1798879f0effSWeongyo Jeong 			 * The first memory page is always reserved for
1799879f0effSWeongyo Jeong 			 * command data.
1800879f0effSWeongyo Jeong 			 */
1801879f0effSWeongyo Jeong 			sc->sc_memory.page[i].addr =
1802879f0effSWeongyo Jeong 			    sc->sc_memaddr_frame_start + MCLBYTES;
1803879f0effSWeongyo Jeong 		} else {
1804879f0effSWeongyo Jeong 			sc->sc_memory.page[i].addr =
1805879f0effSWeongyo Jeong 			    sc->sc_memory.page[i - 1].addr + MCLBYTES;
1806879f0effSWeongyo Jeong 		}
1807879f0effSWeongyo Jeong 
1808879f0effSWeongyo Jeong 		if (sc->sc_memory.page[i].addr + MCLBYTES >=
1809879f0effSWeongyo Jeong 		    sc->sc_memaddr_frame_end)
1810879f0effSWeongyo Jeong 			break;
1811879f0effSWeongyo Jeong 
1812879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_FW, "memory address page %d=0x%08x\n",
1813879f0effSWeongyo Jeong 		    i, sc->sc_memory.page[i].addr);
1814879f0effSWeongyo Jeong 	}
1815879f0effSWeongyo Jeong 
1816879f0effSWeongyo Jeong 	sc->sc_memory.pages = i;
1817879f0effSWeongyo Jeong 
1818879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "memory pages=%d\n", sc->sc_memory.pages);
1819879f0effSWeongyo Jeong 	return (0);
1820879f0effSWeongyo Jeong }
1821879f0effSWeongyo Jeong 
1822879f0effSWeongyo Jeong static int
1823879f0effSWeongyo Jeong upgt_fw_verify(struct upgt_softc *sc)
1824879f0effSWeongyo Jeong {
1825879f0effSWeongyo Jeong 	const struct firmware *fw;
1826879f0effSWeongyo Jeong 	const struct upgt_fw_bra_option *bra_opt;
1827879f0effSWeongyo Jeong 	const struct upgt_fw_bra_descr *descr;
1828879f0effSWeongyo Jeong 	const uint8_t *p;
1829879f0effSWeongyo Jeong 	const uint32_t *uc;
1830879f0effSWeongyo Jeong 	uint32_t bra_option_type, bra_option_len;
18316d917491SHans Petter Selasky 	size_t offset;
18326d917491SHans Petter Selasky 	int bra_end = 0;
18336d917491SHans Petter Selasky 	int error = 0;
1834879f0effSWeongyo Jeong 
1835879f0effSWeongyo Jeong 	fw = firmware_get(upgt_fwname);
1836879f0effSWeongyo Jeong 	if (fw == NULL) {
1837767cb2e2SAndrew Thompson 		device_printf(sc->sc_dev, "could not read microcode %s\n",
1838879f0effSWeongyo Jeong 		    upgt_fwname);
1839879f0effSWeongyo Jeong 		return EIO;
1840879f0effSWeongyo Jeong 	}
1841879f0effSWeongyo Jeong 
1842879f0effSWeongyo Jeong 	/*
1843879f0effSWeongyo Jeong 	 * Seek to beginning of Boot Record Area (BRA).
1844879f0effSWeongyo Jeong 	 */
1845879f0effSWeongyo Jeong 	for (offset = 0; offset < fw->datasize; offset += sizeof(*uc)) {
1846879f0effSWeongyo Jeong 		uc = (const uint32_t *)((const uint8_t *)fw->data + offset);
1847879f0effSWeongyo Jeong 		if (*uc == 0)
1848879f0effSWeongyo Jeong 			break;
1849879f0effSWeongyo Jeong 	}
1850879f0effSWeongyo Jeong 	for (; offset < fw->datasize; offset += sizeof(*uc)) {
1851879f0effSWeongyo Jeong 		uc = (const uint32_t *)((const uint8_t *)fw->data + offset);
1852879f0effSWeongyo Jeong 		if (*uc != 0)
1853879f0effSWeongyo Jeong 			break;
1854879f0effSWeongyo Jeong 	}
1855879f0effSWeongyo Jeong 	if (offset == fw->datasize) {
1856879f0effSWeongyo Jeong 		device_printf(sc->sc_dev,
1857767cb2e2SAndrew Thompson 		    "firmware Boot Record Area not found\n");
1858879f0effSWeongyo Jeong 		error = EIO;
1859879f0effSWeongyo Jeong 		goto fail;
1860879f0effSWeongyo Jeong 	}
1861879f0effSWeongyo Jeong 
1862879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW,
1863879f0effSWeongyo Jeong 	    "firmware Boot Record Area found at offset %d\n", offset);
1864879f0effSWeongyo Jeong 
1865879f0effSWeongyo Jeong 	/*
1866879f0effSWeongyo Jeong 	 * Parse Boot Record Area (BRA) options.
1867879f0effSWeongyo Jeong 	 */
1868879f0effSWeongyo Jeong 	while (offset < fw->datasize && bra_end == 0) {
1869879f0effSWeongyo Jeong 		/* get current BRA option */
1870879f0effSWeongyo Jeong 		p = (const uint8_t *)fw->data + offset;
1871879f0effSWeongyo Jeong 		bra_opt = (const struct upgt_fw_bra_option *)p;
1872879f0effSWeongyo Jeong 		bra_option_type = le32toh(bra_opt->type);
1873879f0effSWeongyo Jeong 		bra_option_len = le32toh(bra_opt->len) * sizeof(*uc);
1874879f0effSWeongyo Jeong 
1875879f0effSWeongyo Jeong 		switch (bra_option_type) {
1876879f0effSWeongyo Jeong 		case UPGT_BRA_TYPE_FW:
1877879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW, "UPGT_BRA_TYPE_FW len=%d\n",
1878879f0effSWeongyo Jeong 			    bra_option_len);
1879879f0effSWeongyo Jeong 
1880879f0effSWeongyo Jeong 			if (bra_option_len != UPGT_BRA_FWTYPE_SIZE) {
1881879f0effSWeongyo Jeong 				device_printf(sc->sc_dev,
1882767cb2e2SAndrew Thompson 				    "wrong UPGT_BRA_TYPE_FW len\n");
1883879f0effSWeongyo Jeong 				error = EIO;
1884879f0effSWeongyo Jeong 				goto fail;
1885879f0effSWeongyo Jeong 			}
1886879f0effSWeongyo Jeong 			if (memcmp(UPGT_BRA_FWTYPE_LM86, bra_opt->data,
1887879f0effSWeongyo Jeong 			    bra_option_len) == 0) {
1888879f0effSWeongyo Jeong 				sc->sc_fw_type = UPGT_FWTYPE_LM86;
1889879f0effSWeongyo Jeong 				break;
1890879f0effSWeongyo Jeong 			}
1891879f0effSWeongyo Jeong 			if (memcmp(UPGT_BRA_FWTYPE_LM87, bra_opt->data,
1892879f0effSWeongyo Jeong 			    bra_option_len) == 0) {
1893879f0effSWeongyo Jeong 				sc->sc_fw_type = UPGT_FWTYPE_LM87;
1894879f0effSWeongyo Jeong 				break;
1895879f0effSWeongyo Jeong 			}
1896879f0effSWeongyo Jeong 			device_printf(sc->sc_dev,
1897767cb2e2SAndrew Thompson 			    "unsupported firmware type\n");
1898879f0effSWeongyo Jeong 			error = EIO;
1899879f0effSWeongyo Jeong 			goto fail;
1900879f0effSWeongyo Jeong 		case UPGT_BRA_TYPE_VERSION:
1901879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1902879f0effSWeongyo Jeong 			    "UPGT_BRA_TYPE_VERSION len=%d\n", bra_option_len);
1903879f0effSWeongyo Jeong 			break;
1904879f0effSWeongyo Jeong 		case UPGT_BRA_TYPE_DEPIF:
1905879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1906879f0effSWeongyo Jeong 			    "UPGT_BRA_TYPE_DEPIF len=%d\n", bra_option_len);
1907879f0effSWeongyo Jeong 			break;
1908879f0effSWeongyo Jeong 		case UPGT_BRA_TYPE_EXPIF:
1909879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1910879f0effSWeongyo Jeong 			    "UPGT_BRA_TYPE_EXPIF len=%d\n", bra_option_len);
1911879f0effSWeongyo Jeong 			break;
1912879f0effSWeongyo Jeong 		case UPGT_BRA_TYPE_DESCR:
1913879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1914879f0effSWeongyo Jeong 			    "UPGT_BRA_TYPE_DESCR len=%d\n", bra_option_len);
1915879f0effSWeongyo Jeong 
1916879f0effSWeongyo Jeong 			descr = (const struct upgt_fw_bra_descr *)bra_opt->data;
1917879f0effSWeongyo Jeong 
1918879f0effSWeongyo Jeong 			sc->sc_memaddr_frame_start =
1919879f0effSWeongyo Jeong 			    le32toh(descr->memaddr_space_start);
1920879f0effSWeongyo Jeong 			sc->sc_memaddr_frame_end =
1921879f0effSWeongyo Jeong 			    le32toh(descr->memaddr_space_end);
1922879f0effSWeongyo Jeong 
1923879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1924879f0effSWeongyo Jeong 			    "memory address space start=0x%08x\n",
1925879f0effSWeongyo Jeong 			    sc->sc_memaddr_frame_start);
1926879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW,
1927879f0effSWeongyo Jeong 			    "memory address space end=0x%08x\n",
1928879f0effSWeongyo Jeong 			    sc->sc_memaddr_frame_end);
1929879f0effSWeongyo Jeong 			break;
1930879f0effSWeongyo Jeong 		case UPGT_BRA_TYPE_END:
1931879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW, "UPGT_BRA_TYPE_END len=%d\n",
1932879f0effSWeongyo Jeong 			    bra_option_len);
1933879f0effSWeongyo Jeong 			bra_end = 1;
1934879f0effSWeongyo Jeong 			break;
1935879f0effSWeongyo Jeong 		default:
1936879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_FW, "unknown BRA option len=%d\n",
1937879f0effSWeongyo Jeong 			    bra_option_len);
1938879f0effSWeongyo Jeong 			error = EIO;
1939879f0effSWeongyo Jeong 			goto fail;
1940879f0effSWeongyo Jeong 		}
1941879f0effSWeongyo Jeong 
1942879f0effSWeongyo Jeong 		/* jump to next BRA option */
1943879f0effSWeongyo Jeong 		offset += sizeof(struct upgt_fw_bra_option) + bra_option_len;
1944879f0effSWeongyo Jeong 	}
1945879f0effSWeongyo Jeong 
1946879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "%s: firmware verified", __func__);
1947879f0effSWeongyo Jeong fail:
1948879f0effSWeongyo Jeong 	firmware_put(fw, FIRMWARE_UNLOAD);
1949879f0effSWeongyo Jeong 	return (error);
1950879f0effSWeongyo Jeong }
1951879f0effSWeongyo Jeong 
1952879f0effSWeongyo Jeong static void
1953879f0effSWeongyo Jeong upgt_bulk_tx(struct upgt_softc *sc, struct upgt_data *data)
1954879f0effSWeongyo Jeong {
1955879f0effSWeongyo Jeong 
1956879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
1957879f0effSWeongyo Jeong 
1958879f0effSWeongyo Jeong 	STAILQ_INSERT_TAIL(&sc->sc_tx_pending, data, next);
1959879f0effSWeongyo Jeong 	UPGT_STAT_INC(sc, st_tx_pending);
1960a593f6b8SAndrew Thompson 	usbd_transfer_start(sc->sc_xfer[UPGT_BULK_TX]);
1961879f0effSWeongyo Jeong }
1962879f0effSWeongyo Jeong 
1963879f0effSWeongyo Jeong static int
1964879f0effSWeongyo Jeong upgt_device_reset(struct upgt_softc *sc)
1965879f0effSWeongyo Jeong {
1966879f0effSWeongyo Jeong 	struct upgt_data *data;
1967879f0effSWeongyo Jeong 	char init_cmd[] = { 0x7e, 0x7e, 0x7e, 0x7e };
1968879f0effSWeongyo Jeong 
1969879f0effSWeongyo Jeong 	UPGT_LOCK(sc);
1970879f0effSWeongyo Jeong 
1971879f0effSWeongyo Jeong 	data = upgt_getbuf(sc);
1972879f0effSWeongyo Jeong 	if (data == NULL) {
1973879f0effSWeongyo Jeong 		UPGT_UNLOCK(sc);
1974879f0effSWeongyo Jeong 		return (ENOBUFS);
1975879f0effSWeongyo Jeong 	}
1976271ae033SHans Petter Selasky 	memcpy(data->buf, init_cmd, sizeof(init_cmd));
1977879f0effSWeongyo Jeong 	data->buflen = sizeof(init_cmd);
1978879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data);
1979a593f6b8SAndrew Thompson 	usb_pause_mtx(&sc->sc_mtx, 100);
1980879f0effSWeongyo Jeong 
1981879f0effSWeongyo Jeong 	UPGT_UNLOCK(sc);
1982879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_FW, "%s: device initialized\n", __func__);
1983879f0effSWeongyo Jeong 	return (0);
1984879f0effSWeongyo Jeong }
1985879f0effSWeongyo Jeong 
1986879f0effSWeongyo Jeong static int
1987879f0effSWeongyo Jeong upgt_alloc_tx(struct upgt_softc *sc)
1988879f0effSWeongyo Jeong {
1989879f0effSWeongyo Jeong 	int i;
1990879f0effSWeongyo Jeong 
1991879f0effSWeongyo Jeong 	STAILQ_INIT(&sc->sc_tx_active);
1992879f0effSWeongyo Jeong 	STAILQ_INIT(&sc->sc_tx_inactive);
1993879f0effSWeongyo Jeong 	STAILQ_INIT(&sc->sc_tx_pending);
1994879f0effSWeongyo Jeong 
1995879f0effSWeongyo Jeong 	for (i = 0; i < UPGT_TX_MAXCOUNT; i++) {
1996879f0effSWeongyo Jeong 		struct upgt_data *data = &sc->sc_tx_data[i];
1997c180b398SHans Petter Selasky 		data->buf = ((uint8_t *)sc->sc_tx_dma_buf) + (i * MCLBYTES);
1998879f0effSWeongyo Jeong 		STAILQ_INSERT_TAIL(&sc->sc_tx_inactive, data, next);
1999879f0effSWeongyo Jeong 		UPGT_STAT_INC(sc, st_tx_inactive);
2000879f0effSWeongyo Jeong 	}
2001879f0effSWeongyo Jeong 
2002879f0effSWeongyo Jeong 	return (0);
2003879f0effSWeongyo Jeong }
2004879f0effSWeongyo Jeong 
2005879f0effSWeongyo Jeong static int
2006879f0effSWeongyo Jeong upgt_alloc_rx(struct upgt_softc *sc)
2007879f0effSWeongyo Jeong {
2008879f0effSWeongyo Jeong 	int i;
2009879f0effSWeongyo Jeong 
2010879f0effSWeongyo Jeong 	STAILQ_INIT(&sc->sc_rx_active);
2011879f0effSWeongyo Jeong 	STAILQ_INIT(&sc->sc_rx_inactive);
2012879f0effSWeongyo Jeong 
2013879f0effSWeongyo Jeong 	for (i = 0; i < UPGT_RX_MAXCOUNT; i++) {
2014879f0effSWeongyo Jeong 		struct upgt_data *data = &sc->sc_rx_data[i];
2015c180b398SHans Petter Selasky 		data->buf = ((uint8_t *)sc->sc_rx_dma_buf) + (i * MCLBYTES);
2016879f0effSWeongyo Jeong 		STAILQ_INSERT_TAIL(&sc->sc_rx_inactive, data, next);
2017879f0effSWeongyo Jeong 	}
2018879f0effSWeongyo Jeong 	return (0);
2019879f0effSWeongyo Jeong }
2020879f0effSWeongyo Jeong 
2021879f0effSWeongyo Jeong static int
2022879f0effSWeongyo Jeong upgt_detach(device_t dev)
2023879f0effSWeongyo Jeong {
2024879f0effSWeongyo Jeong 	struct upgt_softc *sc = device_get_softc(dev);
2025*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
2026*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
2027645e4d17SHans Petter Selasky 	unsigned int x;
2028879f0effSWeongyo Jeong 
2029645e4d17SHans Petter Selasky 	/*
2030645e4d17SHans Petter Selasky 	 * Prevent further allocations from RX/TX/CMD
2031645e4d17SHans Petter Selasky 	 * data lists and ioctls
2032645e4d17SHans Petter Selasky 	 */
2033645e4d17SHans Petter Selasky 	UPGT_LOCK(sc);
2034645e4d17SHans Petter Selasky 	sc->sc_flags |= UPGT_FLAG_DETACHED;
2035645e4d17SHans Petter Selasky 
2036645e4d17SHans Petter Selasky 	STAILQ_INIT(&sc->sc_tx_active);
2037645e4d17SHans Petter Selasky 	STAILQ_INIT(&sc->sc_tx_inactive);
2038645e4d17SHans Petter Selasky 	STAILQ_INIT(&sc->sc_tx_pending);
2039645e4d17SHans Petter Selasky 
2040645e4d17SHans Petter Selasky 	STAILQ_INIT(&sc->sc_rx_active);
2041645e4d17SHans Petter Selasky 	STAILQ_INIT(&sc->sc_rx_inactive);
2042*ba2c1fbcSAdrian Chadd 	UPGT_UNLOCK(sc);
2043879f0effSWeongyo Jeong 
2044879f0effSWeongyo Jeong 	upgt_stop(sc);
2045879f0effSWeongyo Jeong 
2046879f0effSWeongyo Jeong 	callout_drain(&sc->sc_led_ch);
2047879f0effSWeongyo Jeong 	callout_drain(&sc->sc_watchdog_ch);
2048879f0effSWeongyo Jeong 
2049645e4d17SHans Petter Selasky 	/* drain USB transfers */
2050645e4d17SHans Petter Selasky 	for (x = 0; x != UPGT_N_XFERS; x++)
2051645e4d17SHans Petter Selasky 		usbd_transfer_drain(sc->sc_xfer[x]);
2052c180b398SHans Petter Selasky 
2053645e4d17SHans Petter Selasky 	/* free data buffers */
2054645e4d17SHans Petter Selasky 	UPGT_LOCK(sc);
2055879f0effSWeongyo Jeong 	upgt_free_rx(sc);
2056879f0effSWeongyo Jeong 	upgt_free_tx(sc);
2057645e4d17SHans Petter Selasky 	UPGT_UNLOCK(sc);
2058879f0effSWeongyo Jeong 
2059645e4d17SHans Petter Selasky 	/* free USB transfers and some data buffers */
2060645e4d17SHans Petter Selasky 	usbd_transfer_unsetup(sc->sc_xfer, UPGT_N_XFERS);
2061645e4d17SHans Petter Selasky 
2062645e4d17SHans Petter Selasky 	ieee80211_ifdetach(ic);
2063*ba2c1fbcSAdrian Chadd 	if_free(ifp);
2064879f0effSWeongyo Jeong 	mtx_destroy(&sc->sc_mtx);
2065879f0effSWeongyo Jeong 
2066879f0effSWeongyo Jeong 	return (0);
2067879f0effSWeongyo Jeong }
2068879f0effSWeongyo Jeong 
2069879f0effSWeongyo Jeong static void
2070879f0effSWeongyo Jeong upgt_free_rx(struct upgt_softc *sc)
2071879f0effSWeongyo Jeong {
2072879f0effSWeongyo Jeong 	int i;
2073879f0effSWeongyo Jeong 
2074879f0effSWeongyo Jeong 	for (i = 0; i < UPGT_RX_MAXCOUNT; i++) {
2075879f0effSWeongyo Jeong 		struct upgt_data *data = &sc->sc_rx_data[i];
2076879f0effSWeongyo Jeong 
2077c180b398SHans Petter Selasky 		data->buf = NULL;
2078879f0effSWeongyo Jeong 		data->ni = NULL;
2079879f0effSWeongyo Jeong 	}
2080879f0effSWeongyo Jeong }
2081879f0effSWeongyo Jeong 
2082879f0effSWeongyo Jeong static void
2083879f0effSWeongyo Jeong upgt_free_tx(struct upgt_softc *sc)
2084879f0effSWeongyo Jeong {
2085879f0effSWeongyo Jeong 	int i;
2086879f0effSWeongyo Jeong 
2087879f0effSWeongyo Jeong 	for (i = 0; i < UPGT_TX_MAXCOUNT; i++) {
2088879f0effSWeongyo Jeong 		struct upgt_data *data = &sc->sc_tx_data[i];
2089879f0effSWeongyo Jeong 
2090645e4d17SHans Petter Selasky 		if (data->ni != NULL)
2091645e4d17SHans Petter Selasky 			ieee80211_free_node(data->ni);
2092645e4d17SHans Petter Selasky 
2093c180b398SHans Petter Selasky 		data->buf = NULL;
2094879f0effSWeongyo Jeong 		data->ni = NULL;
2095879f0effSWeongyo Jeong 	}
2096879f0effSWeongyo Jeong }
2097879f0effSWeongyo Jeong 
2098879f0effSWeongyo Jeong static void
2099879f0effSWeongyo Jeong upgt_abort_xfers_locked(struct upgt_softc *sc)
2100879f0effSWeongyo Jeong {
2101879f0effSWeongyo Jeong 	int i;
2102879f0effSWeongyo Jeong 
2103879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
2104879f0effSWeongyo Jeong 	/* abort any pending transfers */
2105879f0effSWeongyo Jeong 	for (i = 0; i < UPGT_N_XFERS; i++)
2106a593f6b8SAndrew Thompson 		usbd_transfer_stop(sc->sc_xfer[i]);
2107879f0effSWeongyo Jeong }
2108879f0effSWeongyo Jeong 
2109879f0effSWeongyo Jeong static void
2110879f0effSWeongyo Jeong upgt_abort_xfers(struct upgt_softc *sc)
2111879f0effSWeongyo Jeong {
2112879f0effSWeongyo Jeong 
2113879f0effSWeongyo Jeong 	UPGT_LOCK(sc);
2114879f0effSWeongyo Jeong 	upgt_abort_xfers_locked(sc);
2115879f0effSWeongyo Jeong 	UPGT_UNLOCK(sc);
2116879f0effSWeongyo Jeong }
2117879f0effSWeongyo Jeong 
2118879f0effSWeongyo Jeong #define	UPGT_SYSCTL_STAT_ADD32(c, h, n, p, d)	\
2119879f0effSWeongyo Jeong 	    SYSCTL_ADD_UINT(c, h, OID_AUTO, n, CTLFLAG_RD, p, 0, d)
2120879f0effSWeongyo Jeong 
2121879f0effSWeongyo Jeong static void
2122879f0effSWeongyo Jeong upgt_sysctl_node(struct upgt_softc *sc)
2123879f0effSWeongyo Jeong {
2124879f0effSWeongyo Jeong 	struct sysctl_ctx_list *ctx;
2125879f0effSWeongyo Jeong 	struct sysctl_oid_list *child;
2126879f0effSWeongyo Jeong 	struct sysctl_oid *tree;
2127879f0effSWeongyo Jeong 	struct upgt_stat *stats;
2128879f0effSWeongyo Jeong 
2129879f0effSWeongyo Jeong 	stats = &sc->sc_stat;
2130879f0effSWeongyo Jeong 	ctx = device_get_sysctl_ctx(sc->sc_dev);
2131879f0effSWeongyo Jeong 	child = SYSCTL_CHILDREN(device_get_sysctl_tree(sc->sc_dev));
2132879f0effSWeongyo Jeong 
2133879f0effSWeongyo Jeong 	tree = SYSCTL_ADD_NODE(ctx, child, OID_AUTO, "stats", CTLFLAG_RD,
2134879f0effSWeongyo Jeong 	    NULL, "UPGT statistics");
2135879f0effSWeongyo Jeong 	child = SYSCTL_CHILDREN(tree);
2136879f0effSWeongyo Jeong 	UPGT_SYSCTL_STAT_ADD32(ctx, child, "tx_active",
2137879f0effSWeongyo Jeong 	    &stats->st_tx_active, "Active numbers in TX queue");
2138879f0effSWeongyo Jeong 	UPGT_SYSCTL_STAT_ADD32(ctx, child, "tx_inactive",
2139879f0effSWeongyo Jeong 	    &stats->st_tx_inactive, "Inactive numbers in TX queue");
2140879f0effSWeongyo Jeong 	UPGT_SYSCTL_STAT_ADD32(ctx, child, "tx_pending",
2141879f0effSWeongyo Jeong 	    &stats->st_tx_pending, "Pending numbers in TX queue");
2142879f0effSWeongyo Jeong }
2143879f0effSWeongyo Jeong 
2144879f0effSWeongyo Jeong #undef UPGT_SYSCTL_STAT_ADD32
2145879f0effSWeongyo Jeong 
2146879f0effSWeongyo Jeong static struct upgt_data *
2147879f0effSWeongyo Jeong _upgt_getbuf(struct upgt_softc *sc)
2148879f0effSWeongyo Jeong {
2149879f0effSWeongyo Jeong 	struct upgt_data *bf;
2150879f0effSWeongyo Jeong 
2151879f0effSWeongyo Jeong 	bf = STAILQ_FIRST(&sc->sc_tx_inactive);
2152879f0effSWeongyo Jeong 	if (bf != NULL) {
2153879f0effSWeongyo Jeong 		STAILQ_REMOVE_HEAD(&sc->sc_tx_inactive, next);
2154879f0effSWeongyo Jeong 		UPGT_STAT_DEC(sc, st_tx_inactive);
2155879f0effSWeongyo Jeong 	} else
2156879f0effSWeongyo Jeong 		bf = NULL;
2157879f0effSWeongyo Jeong 	if (bf == NULL)
2158879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_XMIT, "%s: %s\n", __func__,
2159879f0effSWeongyo Jeong 		    "out of xmit buffers");
2160879f0effSWeongyo Jeong 	return (bf);
2161879f0effSWeongyo Jeong }
2162879f0effSWeongyo Jeong 
2163879f0effSWeongyo Jeong static struct upgt_data *
2164879f0effSWeongyo Jeong upgt_getbuf(struct upgt_softc *sc)
2165879f0effSWeongyo Jeong {
2166879f0effSWeongyo Jeong 	struct upgt_data *bf;
2167879f0effSWeongyo Jeong 
2168879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
2169879f0effSWeongyo Jeong 
2170879f0effSWeongyo Jeong 	bf = _upgt_getbuf(sc);
2171*ba2c1fbcSAdrian Chadd 	if (bf == NULL) {
2172*ba2c1fbcSAdrian Chadd 		struct ifnet *ifp = sc->sc_ifp;
2173*ba2c1fbcSAdrian Chadd 
2174879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_XMIT, "%s: stop queue\n", __func__);
2175*ba2c1fbcSAdrian Chadd 		ifp->if_drv_flags |= IFF_DRV_OACTIVE;
2176*ba2c1fbcSAdrian Chadd 	}
2177879f0effSWeongyo Jeong 
2178879f0effSWeongyo Jeong 	return (bf);
2179879f0effSWeongyo Jeong }
2180879f0effSWeongyo Jeong 
2181879f0effSWeongyo Jeong static struct upgt_data *
2182879f0effSWeongyo Jeong upgt_gettxbuf(struct upgt_softc *sc)
2183879f0effSWeongyo Jeong {
2184879f0effSWeongyo Jeong 	struct upgt_data *bf;
2185879f0effSWeongyo Jeong 
2186879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
2187879f0effSWeongyo Jeong 
2188879f0effSWeongyo Jeong 	bf = upgt_getbuf(sc);
2189879f0effSWeongyo Jeong 	if (bf == NULL)
2190879f0effSWeongyo Jeong 		return (NULL);
2191879f0effSWeongyo Jeong 
2192879f0effSWeongyo Jeong 	bf->addr = upgt_mem_alloc(sc);
2193879f0effSWeongyo Jeong 	if (bf->addr == 0) {
2194*ba2c1fbcSAdrian Chadd 		struct ifnet *ifp = sc->sc_ifp;
2195*ba2c1fbcSAdrian Chadd 
2196879f0effSWeongyo Jeong 		DPRINTF(sc, UPGT_DEBUG_XMIT, "%s: no free prism memory!\n",
2197879f0effSWeongyo Jeong 		    __func__);
2198879f0effSWeongyo Jeong 		STAILQ_INSERT_HEAD(&sc->sc_tx_inactive, bf, next);
2199879f0effSWeongyo Jeong 		UPGT_STAT_INC(sc, st_tx_inactive);
2200*ba2c1fbcSAdrian Chadd 		if (!(ifp->if_drv_flags & IFF_DRV_OACTIVE))
2201*ba2c1fbcSAdrian Chadd 			ifp->if_drv_flags |= IFF_DRV_OACTIVE;
2202879f0effSWeongyo Jeong 		return (NULL);
2203879f0effSWeongyo Jeong 	}
2204879f0effSWeongyo Jeong 	return (bf);
2205879f0effSWeongyo Jeong }
2206879f0effSWeongyo Jeong 
2207879f0effSWeongyo Jeong static int
2208879f0effSWeongyo Jeong upgt_tx_start(struct upgt_softc *sc, struct mbuf *m, struct ieee80211_node *ni,
2209879f0effSWeongyo Jeong     struct upgt_data *data)
2210879f0effSWeongyo Jeong {
22115463c4a4SSam Leffler 	struct ieee80211vap *vap = ni->ni_vap;
2212879f0effSWeongyo Jeong 	int error = 0, len;
2213879f0effSWeongyo Jeong 	struct ieee80211_frame *wh;
2214879f0effSWeongyo Jeong 	struct ieee80211_key *k;
2215*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
2216879f0effSWeongyo Jeong 	struct upgt_lmac_mem *mem;
2217879f0effSWeongyo Jeong 	struct upgt_lmac_tx_desc *txdesc;
2218879f0effSWeongyo Jeong 
2219879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
2220879f0effSWeongyo Jeong 
2221879f0effSWeongyo Jeong 	upgt_set_led(sc, UPGT_LED_BLINK);
2222879f0effSWeongyo Jeong 
2223879f0effSWeongyo Jeong 	/*
2224879f0effSWeongyo Jeong 	 * Software crypto.
2225879f0effSWeongyo Jeong 	 */
2226879f0effSWeongyo Jeong 	wh = mtod(m, struct ieee80211_frame *);
22275945b5f5SKevin Lo 	if (wh->i_fc[1] & IEEE80211_FC1_PROTECTED) {
2228879f0effSWeongyo Jeong 		k = ieee80211_crypto_encap(ni, m);
2229879f0effSWeongyo Jeong 		if (k == NULL) {
2230879f0effSWeongyo Jeong 			device_printf(sc->sc_dev,
2231879f0effSWeongyo Jeong 			    "ieee80211_crypto_encap returns NULL.\n");
2232879f0effSWeongyo Jeong 			error = EIO;
2233879f0effSWeongyo Jeong 			goto done;
2234879f0effSWeongyo Jeong 		}
2235879f0effSWeongyo Jeong 
2236879f0effSWeongyo Jeong 		/* in case packet header moved, reset pointer */
2237879f0effSWeongyo Jeong 		wh = mtod(m, struct ieee80211_frame *);
2238879f0effSWeongyo Jeong 	}
2239879f0effSWeongyo Jeong 
2240879f0effSWeongyo Jeong 	/* Transmit the URB containing the TX data.  */
2241271ae033SHans Petter Selasky 	memset(data->buf, 0, MCLBYTES);
2242879f0effSWeongyo Jeong 	mem = (struct upgt_lmac_mem *)data->buf;
2243879f0effSWeongyo Jeong 	mem->addr = htole32(data->addr);
2244879f0effSWeongyo Jeong 	txdesc = (struct upgt_lmac_tx_desc *)(mem + 1);
2245879f0effSWeongyo Jeong 
2246879f0effSWeongyo Jeong 	if ((wh->i_fc[0] & IEEE80211_FC0_TYPE_MASK) ==
2247879f0effSWeongyo Jeong 	    IEEE80211_FC0_TYPE_MGT) {
2248879f0effSWeongyo Jeong 		/* mgmt frames  */
2249879f0effSWeongyo Jeong 		txdesc->header1.flags = UPGT_H1_FLAGS_TX_MGMT;
2250879f0effSWeongyo Jeong 		/* always send mgmt frames at lowest rate (DS1) */
2251879f0effSWeongyo Jeong 		memset(txdesc->rates, 0x10, sizeof(txdesc->rates));
2252879f0effSWeongyo Jeong 	} else {
2253879f0effSWeongyo Jeong 		/* data frames  */
2254879f0effSWeongyo Jeong 		txdesc->header1.flags = UPGT_H1_FLAGS_TX_DATA;
2255271ae033SHans Petter Selasky 		memcpy(txdesc->rates, sc->sc_cur_rateset, sizeof(txdesc->rates));
2256879f0effSWeongyo Jeong 	}
2257879f0effSWeongyo Jeong 	txdesc->header1.type = UPGT_H1_TYPE_TX_DATA;
2258879f0effSWeongyo Jeong 	txdesc->header1.len = htole16(m->m_pkthdr.len);
2259879f0effSWeongyo Jeong 	txdesc->header2.reqid = htole32(data->addr);
2260879f0effSWeongyo Jeong 	txdesc->header2.type = htole16(UPGT_H2_TYPE_TX_ACK_YES);
2261879f0effSWeongyo Jeong 	txdesc->header2.flags = htole16(UPGT_H2_FLAGS_TX_ACK_YES);
2262879f0effSWeongyo Jeong 	txdesc->type = htole32(UPGT_TX_DESC_TYPE_DATA);
2263879f0effSWeongyo Jeong 	txdesc->pad3[0] = UPGT_TX_DESC_PAD3_SIZE;
2264879f0effSWeongyo Jeong 
22655463c4a4SSam Leffler 	if (ieee80211_radiotap_active_vap(vap)) {
2266879f0effSWeongyo Jeong 		struct upgt_tx_radiotap_header *tap = &sc->sc_txtap;
2267879f0effSWeongyo Jeong 
2268879f0effSWeongyo Jeong 		tap->wt_flags = 0;
2269879f0effSWeongyo Jeong 		tap->wt_rate = 0;	/* XXX where to get from? */
2270879f0effSWeongyo Jeong 
22715463c4a4SSam Leffler 		ieee80211_radiotap_tx(vap, m);
2272879f0effSWeongyo Jeong 	}
2273879f0effSWeongyo Jeong 
2274879f0effSWeongyo Jeong 	/* copy frame below our TX descriptor header */
2275879f0effSWeongyo Jeong 	m_copydata(m, 0, m->m_pkthdr.len,
2276879f0effSWeongyo Jeong 	    data->buf + (sizeof(*mem) + sizeof(*txdesc)));
2277879f0effSWeongyo Jeong 	/* calculate frame size */
2278879f0effSWeongyo Jeong 	len = sizeof(*mem) + sizeof(*txdesc) + m->m_pkthdr.len;
2279879f0effSWeongyo Jeong 	/* we need to align the frame to a 4 byte boundary */
2280879f0effSWeongyo Jeong 	len = (len + 3) & ~3;
2281879f0effSWeongyo Jeong 	/* calculate frame checksum */
2282879f0effSWeongyo Jeong 	mem->chksum = upgt_chksum_le((uint32_t *)txdesc, len - sizeof(*mem));
2283879f0effSWeongyo Jeong 	data->ni = ni;
2284879f0effSWeongyo Jeong 	data->m = m;
2285879f0effSWeongyo Jeong 	data->buflen = len;
2286879f0effSWeongyo Jeong 
2287879f0effSWeongyo Jeong 	DPRINTF(sc, UPGT_DEBUG_XMIT, "%s: TX start data sending (%d bytes)\n",
2288879f0effSWeongyo Jeong 	    __func__, len);
2289879f0effSWeongyo Jeong 	KASSERT(len <= MCLBYTES, ("mbuf is small for saving data"));
2290879f0effSWeongyo Jeong 
2291879f0effSWeongyo Jeong 	upgt_bulk_tx(sc, data);
2292879f0effSWeongyo Jeong done:
2293879f0effSWeongyo Jeong 	/*
2294879f0effSWeongyo Jeong 	 * If we don't regulary read the device statistics, the RX queue
2295879f0effSWeongyo Jeong 	 * will stall.  It's strange, but it works, so we keep reading
2296879f0effSWeongyo Jeong 	 * the statistics here.  *shrug*
2297879f0effSWeongyo Jeong 	 */
2298*ba2c1fbcSAdrian Chadd 	if (!(ifp->if_get_counter(ifp, IFCOUNTER_OPACKETS) %
2299a001989dSGleb Smirnoff 	    UPGT_TX_STAT_INTERVAL))
2300879f0effSWeongyo Jeong 		upgt_get_stats(sc);
2301879f0effSWeongyo Jeong 
2302879f0effSWeongyo Jeong 	return (error);
2303879f0effSWeongyo Jeong }
2304879f0effSWeongyo Jeong 
2305879f0effSWeongyo Jeong static void
2306ed6d949aSAndrew Thompson upgt_bulk_rx_callback(struct usb_xfer *xfer, usb_error_t error)
2307879f0effSWeongyo Jeong {
2308ed6d949aSAndrew Thompson 	struct upgt_softc *sc = usbd_xfer_softc(xfer);
2309*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
2310*ba2c1fbcSAdrian Chadd 	struct ieee80211com *ic = ifp->if_l2com;
2311879f0effSWeongyo Jeong 	struct ieee80211_frame *wh;
2312879f0effSWeongyo Jeong 	struct ieee80211_node *ni;
2313879f0effSWeongyo Jeong 	struct mbuf *m = NULL;
2314879f0effSWeongyo Jeong 	struct upgt_data *data;
2315879f0effSWeongyo Jeong 	int8_t nf;
2316879f0effSWeongyo Jeong 	int rssi = -1;
2317879f0effSWeongyo Jeong 
2318879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
2319879f0effSWeongyo Jeong 
2320879f0effSWeongyo Jeong 	switch (USB_GET_STATE(xfer)) {
2321879f0effSWeongyo Jeong 	case USB_ST_TRANSFERRED:
2322879f0effSWeongyo Jeong 		data = STAILQ_FIRST(&sc->sc_rx_active);
2323879f0effSWeongyo Jeong 		if (data == NULL)
2324879f0effSWeongyo Jeong 			goto setup;
2325879f0effSWeongyo Jeong 		STAILQ_REMOVE_HEAD(&sc->sc_rx_active, next);
2326879f0effSWeongyo Jeong 		m = upgt_rxeof(xfer, data, &rssi);
2327879f0effSWeongyo Jeong 		STAILQ_INSERT_TAIL(&sc->sc_rx_inactive, data, next);
2328879f0effSWeongyo Jeong 		/* FALLTHROUGH */
2329879f0effSWeongyo Jeong 	case USB_ST_SETUP:
2330879f0effSWeongyo Jeong setup:
2331879f0effSWeongyo Jeong 		data = STAILQ_FIRST(&sc->sc_rx_inactive);
2332879f0effSWeongyo Jeong 		if (data == NULL)
2333879f0effSWeongyo Jeong 			return;
2334879f0effSWeongyo Jeong 		STAILQ_REMOVE_HEAD(&sc->sc_rx_inactive, next);
2335879f0effSWeongyo Jeong 		STAILQ_INSERT_TAIL(&sc->sc_rx_active, data, next);
2336c180b398SHans Petter Selasky 		usbd_xfer_set_frame_data(xfer, 0, data->buf, MCLBYTES);
2337a593f6b8SAndrew Thompson 		usbd_transfer_submit(xfer);
2338879f0effSWeongyo Jeong 
2339879f0effSWeongyo Jeong 		/*
2340879f0effSWeongyo Jeong 		 * To avoid LOR we should unlock our private mutex here to call
2341879f0effSWeongyo Jeong 		 * ieee80211_input() because here is at the end of a USB
2342879f0effSWeongyo Jeong 		 * callback and safe to unlock.
2343879f0effSWeongyo Jeong 		 */
2344879f0effSWeongyo Jeong 		UPGT_UNLOCK(sc);
2345879f0effSWeongyo Jeong 		if (m != NULL) {
2346879f0effSWeongyo Jeong 			wh = mtod(m, struct ieee80211_frame *);
2347879f0effSWeongyo Jeong 			ni = ieee80211_find_rxnode(ic,
2348879f0effSWeongyo Jeong 			    (struct ieee80211_frame_min *)wh);
2349879f0effSWeongyo Jeong 			nf = -95;	/* XXX */
2350879f0effSWeongyo Jeong 			if (ni != NULL) {
23515463c4a4SSam Leffler 				(void) ieee80211_input(ni, m, rssi, nf);
2352879f0effSWeongyo Jeong 				/* node is no longer needed */
2353879f0effSWeongyo Jeong 				ieee80211_free_node(ni);
2354879f0effSWeongyo Jeong 			} else
23555463c4a4SSam Leffler 				(void) ieee80211_input_all(ic, m, rssi, nf);
2356879f0effSWeongyo Jeong 			m = NULL;
2357879f0effSWeongyo Jeong 		}
2358*ba2c1fbcSAdrian Chadd 		if ((ifp->if_drv_flags & IFF_DRV_OACTIVE) == 0 &&
2359*ba2c1fbcSAdrian Chadd 		    !IFQ_IS_EMPTY(&ifp->if_snd))
2360*ba2c1fbcSAdrian Chadd 			upgt_start(ifp);
2361879f0effSWeongyo Jeong 		UPGT_LOCK(sc);
2362879f0effSWeongyo Jeong 		break;
2363879f0effSWeongyo Jeong 	default:
2364879f0effSWeongyo Jeong 		/* needs it to the inactive queue due to a error.  */
2365879f0effSWeongyo Jeong 		data = STAILQ_FIRST(&sc->sc_rx_active);
2366879f0effSWeongyo Jeong 		if (data != NULL) {
2367879f0effSWeongyo Jeong 			STAILQ_REMOVE_HEAD(&sc->sc_rx_active, next);
2368879f0effSWeongyo Jeong 			STAILQ_INSERT_TAIL(&sc->sc_rx_inactive, data, next);
2369879f0effSWeongyo Jeong 		}
2370ed6d949aSAndrew Thompson 		if (error != USB_ERR_CANCELLED) {
2371ed6d949aSAndrew Thompson 			usbd_xfer_set_stall(xfer);
2372*ba2c1fbcSAdrian Chadd 			if_inc_counter(ifp, IFCOUNTER_IERRORS, 1);
2373879f0effSWeongyo Jeong 			goto setup;
2374879f0effSWeongyo Jeong 		}
2375879f0effSWeongyo Jeong 		break;
2376879f0effSWeongyo Jeong 	}
2377879f0effSWeongyo Jeong }
2378879f0effSWeongyo Jeong 
2379879f0effSWeongyo Jeong static void
2380ed6d949aSAndrew Thompson upgt_bulk_tx_callback(struct usb_xfer *xfer, usb_error_t error)
2381879f0effSWeongyo Jeong {
2382ed6d949aSAndrew Thompson 	struct upgt_softc *sc = usbd_xfer_softc(xfer);
2383*ba2c1fbcSAdrian Chadd 	struct ifnet *ifp = sc->sc_ifp;
2384879f0effSWeongyo Jeong 	struct upgt_data *data;
2385879f0effSWeongyo Jeong 
2386879f0effSWeongyo Jeong 	UPGT_ASSERT_LOCKED(sc);
2387879f0effSWeongyo Jeong 	switch (USB_GET_STATE(xfer)) {
2388879f0effSWeongyo Jeong 	case USB_ST_TRANSFERRED:
2389879f0effSWeongyo Jeong 		data = STAILQ_FIRST(&sc->sc_tx_active);
2390879f0effSWeongyo Jeong 		if (data == NULL)
2391879f0effSWeongyo Jeong 			goto setup;
2392879f0effSWeongyo Jeong 		STAILQ_REMOVE_HEAD(&sc->sc_tx_active, next);
2393879f0effSWeongyo Jeong 		UPGT_STAT_DEC(sc, st_tx_active);
2394879f0effSWeongyo Jeong 		upgt_txeof(xfer, data);
2395879f0effSWeongyo Jeong 		STAILQ_INSERT_TAIL(&sc->sc_tx_inactive, data, next);
2396879f0effSWeongyo Jeong 		UPGT_STAT_INC(sc, st_tx_inactive);
2397879f0effSWeongyo Jeong 		/* FALLTHROUGH */
2398879f0effSWeongyo Jeong 	case USB_ST_SETUP:
2399879f0effSWeongyo Jeong setup:
2400879f0effSWeongyo Jeong 		data = STAILQ_FIRST(&sc->sc_tx_pending);
2401879f0effSWeongyo Jeong 		if (data == NULL) {
2402879f0effSWeongyo Jeong 			DPRINTF(sc, UPGT_DEBUG_XMIT, "%s: empty pending queue\n",
2403879f0effSWeongyo Jeong 			    __func__);
2404879f0effSWeongyo Jeong 			return;
2405879f0effSWeongyo Jeong 		}
2406879f0effSWeongyo Jeong 		STAILQ_REMOVE_HEAD(&sc->sc_tx_pending, next);
2407879f0effSWeongyo Jeong 		UPGT_STAT_DEC(sc, st_tx_pending);
2408879f0effSWeongyo Jeong 		STAILQ_INSERT_TAIL(&sc->sc_tx_active, data, next);
2409879f0effSWeongyo Jeong 		UPGT_STAT_INC(sc, st_tx_active);
2410879f0effSWeongyo Jeong 
2411ed6d949aSAndrew Thompson 		usbd_xfer_set_frame_data(xfer, 0, data->buf, data->buflen);
2412a593f6b8SAndrew Thompson 		usbd_transfer_submit(xfer);
2413*ba2c1fbcSAdrian Chadd 		UPGT_UNLOCK(sc);
2414*ba2c1fbcSAdrian Chadd 		upgt_start(ifp);
2415*ba2c1fbcSAdrian Chadd 		UPGT_LOCK(sc);
2416879f0effSWeongyo Jeong 		break;
2417879f0effSWeongyo Jeong 	default:
2418879f0effSWeongyo Jeong 		data = STAILQ_FIRST(&sc->sc_tx_active);
2419879f0effSWeongyo Jeong 		if (data == NULL)
2420879f0effSWeongyo Jeong 			goto setup;
2421879f0effSWeongyo Jeong 		if (data->ni != NULL) {
2422879f0effSWeongyo Jeong 			ieee80211_free_node(data->ni);
2423879f0effSWeongyo Jeong 			data->ni = NULL;
2424*ba2c1fbcSAdrian Chadd 			if_inc_counter(ifp, IFCOUNTER_OERRORS, 1);
2425879f0effSWeongyo Jeong 		}
2426ed6d949aSAndrew Thompson 		if (error != USB_ERR_CANCELLED) {
2427ed6d949aSAndrew Thompson 			usbd_xfer_set_stall(xfer);
2428879f0effSWeongyo Jeong 			goto setup;
2429879f0effSWeongyo Jeong 		}
2430879f0effSWeongyo Jeong 		break;
2431879f0effSWeongyo Jeong 	}
2432879f0effSWeongyo Jeong }
2433879f0effSWeongyo Jeong 
2434879f0effSWeongyo Jeong static device_method_t upgt_methods[] = {
2435879f0effSWeongyo Jeong         /* Device interface */
2436879f0effSWeongyo Jeong         DEVMETHOD(device_probe, upgt_match),
2437879f0effSWeongyo Jeong         DEVMETHOD(device_attach, upgt_attach),
2438879f0effSWeongyo Jeong         DEVMETHOD(device_detach, upgt_detach),
2439c180b398SHans Petter Selasky 	DEVMETHOD_END
2440879f0effSWeongyo Jeong };
2441879f0effSWeongyo Jeong 
2442879f0effSWeongyo Jeong static driver_t upgt_driver = {
24436d917491SHans Petter Selasky 	.name = "upgt",
24446d917491SHans Petter Selasky 	.methods = upgt_methods,
24456d917491SHans Petter Selasky 	.size = sizeof(struct upgt_softc)
2446879f0effSWeongyo Jeong };
2447879f0effSWeongyo Jeong 
2448879f0effSWeongyo Jeong static devclass_t upgt_devclass;
2449879f0effSWeongyo Jeong 
2450879f0effSWeongyo Jeong DRIVER_MODULE(if_upgt, uhub, upgt_driver, upgt_devclass, NULL, 0);
2451879f0effSWeongyo Jeong MODULE_VERSION(if_upgt, 1);
2452879f0effSWeongyo Jeong MODULE_DEPEND(if_upgt, usb, 1, 1, 1);
2453879f0effSWeongyo Jeong MODULE_DEPEND(if_upgt, wlan, 1, 1, 1);
2454879f0effSWeongyo Jeong MODULE_DEPEND(if_upgt, upgtfw_fw, 1, 1, 1);
2455