xref: /freebsd/sys/dev/wpi/if_wpi.c (revision 76039bc84fae9915788b54ff28fe0cc4876952d2)
16607310bSBenjamin Close /*-
26607310bSBenjamin Close  * Copyright (c) 2006,2007
36607310bSBenjamin Close  *	Damien Bergamini <damien.bergamini@free.fr>
46607310bSBenjamin Close  *	Benjamin Close <Benjamin.Close@clearchain.com>
56607310bSBenjamin Close  *
66607310bSBenjamin Close  * Permission to use, copy, modify, and distribute this software for any
76607310bSBenjamin Close  * purpose with or without fee is hereby granted, provided that the above
86607310bSBenjamin Close  * copyright notice and this permission notice appear in all copies.
96607310bSBenjamin Close  *
106607310bSBenjamin Close  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
116607310bSBenjamin Close  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
126607310bSBenjamin Close  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
136607310bSBenjamin Close  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
146607310bSBenjamin Close  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
156607310bSBenjamin Close  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
166607310bSBenjamin Close  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
176607310bSBenjamin Close  */
186607310bSBenjamin Close 
198b92cdc9SBenjamin Close #define VERSION "20071127"
206607310bSBenjamin Close 
216607310bSBenjamin Close #include <sys/cdefs.h>
226607310bSBenjamin Close __FBSDID("$FreeBSD$");
236607310bSBenjamin Close 
246607310bSBenjamin Close /*
256607310bSBenjamin Close  * Driver for Intel PRO/Wireless 3945ABG 802.11 network adapters.
266607310bSBenjamin Close  *
276607310bSBenjamin Close  * The 3945ABG network adapter doesn't use traditional hardware as
286607310bSBenjamin Close  * many other adaptors do. Instead at run time the eeprom is set into a known
296607310bSBenjamin Close  * state and told to load boot firmware. The boot firmware loads an init and a
306607310bSBenjamin Close  * main  binary firmware image into SRAM on the card via DMA.
316607310bSBenjamin Close  * Once the firmware is loaded, the driver/hw then
326bccea7cSRebecca Cran  * communicate by way of circular dma rings via the SRAM to the firmware.
336607310bSBenjamin Close  *
346607310bSBenjamin Close  * There is 6 memory rings. 1 command ring, 1 rx data ring & 4 tx data rings.
356607310bSBenjamin Close  * The 4 tx data rings allow for prioritization QoS.
366607310bSBenjamin Close  *
376607310bSBenjamin Close  * The rx data ring consists of 32 dma buffers. Two registers are used to
386607310bSBenjamin Close  * indicate where in the ring the driver and the firmware are up to. The
396607310bSBenjamin Close  * driver sets the initial read index (reg1) and the initial write index (reg2),
406607310bSBenjamin Close  * the firmware updates the read index (reg1) on rx of a packet and fires an
416607310bSBenjamin Close  * interrupt. The driver then processes the buffers starting at reg1 indicating
426607310bSBenjamin Close  * to the firmware which buffers have been accessed by updating reg2. At the
436607310bSBenjamin Close  * same time allocating new memory for the processed buffer.
446607310bSBenjamin Close  *
456607310bSBenjamin Close  * A similar thing happens with the tx rings. The difference is the firmware
466607310bSBenjamin Close  * stop processing buffers once the queue is full and until confirmation
476607310bSBenjamin Close  * of a successful transmition (tx_intr) has occurred.
486607310bSBenjamin Close  *
496607310bSBenjamin Close  * The command ring operates in the same manner as the tx queues.
506607310bSBenjamin Close  *
516607310bSBenjamin Close  * All communication direct to the card (ie eeprom) is classed as Stage1
526607310bSBenjamin Close  * communication
536607310bSBenjamin Close  *
546607310bSBenjamin Close  * All communication via the firmware to the card is classed as State2.
556607310bSBenjamin Close  * The firmware consists of 2 parts. A bootstrap firmware and a runtime
566607310bSBenjamin Close  * firmware. The bootstrap firmware and runtime firmware are loaded
576607310bSBenjamin Close  * from host memory via dma to the card then told to execute. From this point
586607310bSBenjamin Close  * on the majority of communications between the driver and the card goes
596607310bSBenjamin Close  * via the firmware.
606607310bSBenjamin Close  */
616607310bSBenjamin Close 
6281c2214dSAdrian Chadd #include "opt_wlan.h"
6381c2214dSAdrian Chadd 
646607310bSBenjamin Close #include <sys/param.h>
656607310bSBenjamin Close #include <sys/sysctl.h>
666607310bSBenjamin Close #include <sys/sockio.h>
676607310bSBenjamin Close #include <sys/mbuf.h>
686607310bSBenjamin Close #include <sys/kernel.h>
696607310bSBenjamin Close #include <sys/socket.h>
706607310bSBenjamin Close #include <sys/systm.h>
716607310bSBenjamin Close #include <sys/malloc.h>
726607310bSBenjamin Close #include <sys/queue.h>
736607310bSBenjamin Close #include <sys/taskqueue.h>
746607310bSBenjamin Close #include <sys/module.h>
756607310bSBenjamin Close #include <sys/bus.h>
766607310bSBenjamin Close #include <sys/endian.h>
776607310bSBenjamin Close #include <sys/linker.h>
786607310bSBenjamin Close #include <sys/firmware.h>
796607310bSBenjamin Close 
806607310bSBenjamin Close #include <machine/bus.h>
816607310bSBenjamin Close #include <machine/resource.h>
826607310bSBenjamin Close #include <sys/rman.h>
836607310bSBenjamin Close 
846607310bSBenjamin Close #include <dev/pci/pcireg.h>
856607310bSBenjamin Close #include <dev/pci/pcivar.h>
866607310bSBenjamin Close 
876607310bSBenjamin Close #include <net/bpf.h>
886607310bSBenjamin Close #include <net/if.h>
89*76039bc8SGleb Smirnoff #include <net/if_var.h>
906607310bSBenjamin Close #include <net/if_arp.h>
916607310bSBenjamin Close #include <net/ethernet.h>
926607310bSBenjamin Close #include <net/if_dl.h>
936607310bSBenjamin Close #include <net/if_media.h>
946607310bSBenjamin Close #include <net/if_types.h>
956607310bSBenjamin Close 
966607310bSBenjamin Close #include <net80211/ieee80211_var.h>
976607310bSBenjamin Close #include <net80211/ieee80211_radiotap.h>
986607310bSBenjamin Close #include <net80211/ieee80211_regdomain.h>
99b6108616SRui Paulo #include <net80211/ieee80211_ratectl.h>
1006607310bSBenjamin Close 
1016607310bSBenjamin Close #include <netinet/in.h>
1026607310bSBenjamin Close #include <netinet/in_systm.h>
1036607310bSBenjamin Close #include <netinet/in_var.h>
1046607310bSBenjamin Close #include <netinet/ip.h>
1056607310bSBenjamin Close #include <netinet/if_ether.h>
1066607310bSBenjamin Close 
1076607310bSBenjamin Close #include <dev/wpi/if_wpireg.h>
1086607310bSBenjamin Close #include <dev/wpi/if_wpivar.h>
1096607310bSBenjamin Close 
110afe0ec00SDoug Barton #define WPI_DEBUG
111afe0ec00SDoug Barton 
1126607310bSBenjamin Close #ifdef WPI_DEBUG
1136607310bSBenjamin Close #define DPRINTF(x)	do { if (wpi_debug != 0) printf x; } while (0)
1146607310bSBenjamin Close #define DPRINTFN(n, x)	do { if (wpi_debug & n) printf x; } while (0)
1156845408dSAndrew Thompson #define	WPI_DEBUG_SET	(wpi_debug != 0)
1166607310bSBenjamin Close 
1176607310bSBenjamin Close enum {
1186607310bSBenjamin Close 	WPI_DEBUG_UNUSED	= 0x00000001,   /* Unused */
1196607310bSBenjamin Close 	WPI_DEBUG_HW		= 0x00000002,   /* Stage 1 (eeprom) debugging */
1206607310bSBenjamin Close 	WPI_DEBUG_TX		= 0x00000004,   /* Stage 2 TX intrp debugging*/
1216607310bSBenjamin Close 	WPI_DEBUG_RX		= 0x00000008,   /* Stage 2 RX intrp debugging */
1226607310bSBenjamin Close 	WPI_DEBUG_CMD		= 0x00000010,   /* Stage 2 CMD intrp debugging*/
1236607310bSBenjamin Close 	WPI_DEBUG_FIRMWARE	= 0x00000020,   /* firmware(9) loading debug  */
1246607310bSBenjamin Close 	WPI_DEBUG_DMA		= 0x00000040,   /* DMA (de)allocations/syncs  */
1256607310bSBenjamin Close 	WPI_DEBUG_SCANNING	= 0x00000080,   /* Stage 2 Scanning debugging */
1266607310bSBenjamin Close 	WPI_DEBUG_NOTIFY	= 0x00000100,   /* State 2 Noftif intr debug */
1276607310bSBenjamin Close 	WPI_DEBUG_TEMP		= 0x00000200,   /* TXPower/Temp Calibration */
1286607310bSBenjamin Close 	WPI_DEBUG_OPS		= 0x00000400,   /* wpi_ops taskq debug */
1296607310bSBenjamin Close 	WPI_DEBUG_WATCHDOG	= 0x00000800,   /* Watch dog debug */
1306607310bSBenjamin Close 	WPI_DEBUG_ANY		= 0xffffffff
1316607310bSBenjamin Close };
1326607310bSBenjamin Close 
133afe0ec00SDoug Barton static int wpi_debug = 0;
1346607310bSBenjamin Close SYSCTL_INT(_debug, OID_AUTO, wpi, CTLFLAG_RW, &wpi_debug, 0, "wpi debug level");
1356845408dSAndrew Thompson TUNABLE_INT("debug.wpi", &wpi_debug);
1366607310bSBenjamin Close 
1376607310bSBenjamin Close #else
1386607310bSBenjamin Close #define DPRINTF(x)
1396607310bSBenjamin Close #define DPRINTFN(n, x)
1406845408dSAndrew Thompson #define WPI_DEBUG_SET	0
1416607310bSBenjamin Close #endif
1426607310bSBenjamin Close 
1436607310bSBenjamin Close struct wpi_ident {
1446607310bSBenjamin Close 	uint16_t	vendor;
1456607310bSBenjamin Close 	uint16_t	device;
1466607310bSBenjamin Close 	uint16_t	subdevice;
1476607310bSBenjamin Close 	const char	*name;
1486607310bSBenjamin Close };
1496607310bSBenjamin Close 
1506607310bSBenjamin Close static const struct wpi_ident wpi_ident_table[] = {
1516607310bSBenjamin Close 	/* The below entries support ABG regardless of the subid */
1526607310bSBenjamin Close 	{ 0x8086, 0x4222,    0x0, "Intel(R) PRO/Wireless 3945ABG" },
1536607310bSBenjamin Close 	{ 0x8086, 0x4227,    0x0, "Intel(R) PRO/Wireless 3945ABG" },
1546607310bSBenjamin Close 	/* The below entries only support BG */
15534f004ceSBenjamin Close 	{ 0x8086, 0x4222, 0x1005, "Intel(R) PRO/Wireless 3945BG"  },
15634f004ceSBenjamin Close 	{ 0x8086, 0x4222, 0x1034, "Intel(R) PRO/Wireless 3945BG"  },
15734f004ceSBenjamin Close 	{ 0x8086, 0x4227, 0x1014, "Intel(R) PRO/Wireless 3945BG"  },
15834f004ceSBenjamin Close 	{ 0x8086, 0x4222, 0x1044, "Intel(R) PRO/Wireless 3945BG"  },
1596607310bSBenjamin Close 	{ 0, 0, 0, NULL }
1606607310bSBenjamin Close };
1616607310bSBenjamin Close 
162b032f27cSSam Leffler static struct ieee80211vap *wpi_vap_create(struct ieee80211com *,
163fcd9500fSBernhard Schmidt 		    const char [IFNAMSIZ], int, enum ieee80211_opmode, int,
164fcd9500fSBernhard Schmidt 		    const uint8_t [IEEE80211_ADDR_LEN],
165fcd9500fSBernhard Schmidt 		    const uint8_t [IEEE80211_ADDR_LEN]);
166b032f27cSSam Leffler static void	wpi_vap_delete(struct ieee80211vap *);
1676607310bSBenjamin Close static int	wpi_dma_contig_alloc(struct wpi_softc *, struct wpi_dma_info *,
1686607310bSBenjamin Close 		    void **, bus_size_t, bus_size_t, int);
1696607310bSBenjamin Close static void	wpi_dma_contig_free(struct wpi_dma_info *);
1706607310bSBenjamin Close static void	wpi_dma_map_addr(void *, bus_dma_segment_t *, int, int);
1716607310bSBenjamin Close static int	wpi_alloc_shared(struct wpi_softc *);
1726607310bSBenjamin Close static void	wpi_free_shared(struct wpi_softc *);
1736607310bSBenjamin Close static int	wpi_alloc_rx_ring(struct wpi_softc *, struct wpi_rx_ring *);
1746607310bSBenjamin Close static void	wpi_reset_rx_ring(struct wpi_softc *, struct wpi_rx_ring *);
1756607310bSBenjamin Close static void	wpi_free_rx_ring(struct wpi_softc *, struct wpi_rx_ring *);
1766607310bSBenjamin Close static int	wpi_alloc_tx_ring(struct wpi_softc *, struct wpi_tx_ring *,
1776607310bSBenjamin Close 		    int, int);
1786607310bSBenjamin Close static void	wpi_reset_tx_ring(struct wpi_softc *, struct wpi_tx_ring *);
1796607310bSBenjamin Close static void	wpi_free_tx_ring(struct wpi_softc *, struct wpi_tx_ring *);
180b032f27cSSam Leffler static int	wpi_newstate(struct ieee80211vap *, enum ieee80211_state, int);
1816607310bSBenjamin Close static void	wpi_mem_lock(struct wpi_softc *);
1826607310bSBenjamin Close static void	wpi_mem_unlock(struct wpi_softc *);
1836607310bSBenjamin Close static uint32_t	wpi_mem_read(struct wpi_softc *, uint16_t);
1846607310bSBenjamin Close static void	wpi_mem_write(struct wpi_softc *, uint16_t, uint32_t);
1856607310bSBenjamin Close static void	wpi_mem_write_region_4(struct wpi_softc *, uint16_t,
1866607310bSBenjamin Close 		    const uint32_t *, int);
1876607310bSBenjamin Close static uint16_t	wpi_read_prom_data(struct wpi_softc *, uint32_t, void *, int);
1886607310bSBenjamin Close static int	wpi_alloc_fwmem(struct wpi_softc *);
1896607310bSBenjamin Close static void	wpi_free_fwmem(struct wpi_softc *);
1906607310bSBenjamin Close static int	wpi_load_firmware(struct wpi_softc *);
1916607310bSBenjamin Close static void	wpi_unload_firmware(struct wpi_softc *);
1926607310bSBenjamin Close static int	wpi_load_microcode(struct wpi_softc *, const uint8_t *, int);
1936607310bSBenjamin Close static void	wpi_rx_intr(struct wpi_softc *, struct wpi_rx_desc *,
1946607310bSBenjamin Close 		    struct wpi_rx_data *);
1956607310bSBenjamin Close static void	wpi_tx_intr(struct wpi_softc *, struct wpi_rx_desc *);
1966607310bSBenjamin Close static void	wpi_cmd_intr(struct wpi_softc *, struct wpi_rx_desc *);
1976607310bSBenjamin Close static void	wpi_notif_intr(struct wpi_softc *);
1986607310bSBenjamin Close static void	wpi_intr(void *);
1996607310bSBenjamin Close static uint8_t	wpi_plcp_signal(int);
20082f1b132SAndrew Thompson static void	wpi_watchdog(void *);
2016607310bSBenjamin Close static int	wpi_tx_data(struct wpi_softc *, struct mbuf *,
2026607310bSBenjamin Close 		    struct ieee80211_node *, int);
2036607310bSBenjamin Close static void	wpi_start(struct ifnet *);
204b032f27cSSam Leffler static void	wpi_start_locked(struct ifnet *);
205b032f27cSSam Leffler static int	wpi_raw_xmit(struct ieee80211_node *, struct mbuf *,
206b032f27cSSam Leffler 		    const struct ieee80211_bpf_params *);
2076607310bSBenjamin Close static void	wpi_scan_start(struct ieee80211com *);
2086607310bSBenjamin Close static void	wpi_scan_end(struct ieee80211com *);
2096607310bSBenjamin Close static void	wpi_set_channel(struct ieee80211com *);
210b032f27cSSam Leffler static void	wpi_scan_curchan(struct ieee80211_scan_state *, unsigned long);
211b032f27cSSam Leffler static void	wpi_scan_mindwell(struct ieee80211_scan_state *);
2126607310bSBenjamin Close static int	wpi_ioctl(struct ifnet *, u_long, caddr_t);
21329aca940SSam Leffler static void	wpi_read_eeprom(struct wpi_softc *,
21429aca940SSam Leffler 		    uint8_t macaddr[IEEE80211_ADDR_LEN]);
2156607310bSBenjamin Close static void	wpi_read_eeprom_channels(struct wpi_softc *, int);
2166607310bSBenjamin Close static void	wpi_read_eeprom_group(struct wpi_softc *, int);
2176607310bSBenjamin Close static int	wpi_cmd(struct wpi_softc *, int, const void *, int, int);
2186607310bSBenjamin Close static int	wpi_wme_update(struct ieee80211com *);
2196607310bSBenjamin Close static int	wpi_mrr_setup(struct wpi_softc *);
2206607310bSBenjamin Close static void	wpi_set_led(struct wpi_softc *, uint8_t, uint8_t, uint8_t);
2216607310bSBenjamin Close static void	wpi_enable_tsf(struct wpi_softc *, struct ieee80211_node *);
2226607310bSBenjamin Close #if 0
2236607310bSBenjamin Close static int	wpi_setup_beacon(struct wpi_softc *, struct ieee80211_node *);
2246607310bSBenjamin Close #endif
225b032f27cSSam Leffler static int	wpi_auth(struct wpi_softc *, struct ieee80211vap *);
226b032f27cSSam Leffler static int	wpi_run(struct wpi_softc *, struct ieee80211vap *);
2276607310bSBenjamin Close static int	wpi_scan(struct wpi_softc *);
2286607310bSBenjamin Close static int	wpi_config(struct wpi_softc *);
2296607310bSBenjamin Close static void	wpi_stop_master(struct wpi_softc *);
2306607310bSBenjamin Close static int	wpi_power_up(struct wpi_softc *);
2316607310bSBenjamin Close static int	wpi_reset(struct wpi_softc *);
2325efea30fSAndrew Thompson static void	wpi_hwreset(void *, int);
2335efea30fSAndrew Thompson static void	wpi_rfreset(void *, int);
2346607310bSBenjamin Close static void	wpi_hw_config(struct wpi_softc *);
2356607310bSBenjamin Close static void	wpi_init(void *);
23682f1b132SAndrew Thompson static void	wpi_init_locked(struct wpi_softc *, int);
2376607310bSBenjamin Close static void	wpi_stop(struct wpi_softc *);
2386607310bSBenjamin Close static void	wpi_stop_locked(struct wpi_softc *);
2396607310bSBenjamin Close 
2406607310bSBenjamin Close static int	wpi_set_txpower(struct wpi_softc *, struct ieee80211_channel *,
2416607310bSBenjamin Close 		    int);
2426607310bSBenjamin Close static void	wpi_calib_timeout(void *);
2436607310bSBenjamin Close static void	wpi_power_calibration(struct wpi_softc *, int);
2446607310bSBenjamin Close static int	wpi_get_power_index(struct wpi_softc *,
2456607310bSBenjamin Close 		    struct wpi_power_group *, struct ieee80211_channel *, int);
2466845408dSAndrew Thompson #ifdef WPI_DEBUG
2476607310bSBenjamin Close static const char *wpi_cmd_str(int);
2486845408dSAndrew Thompson #endif
2496607310bSBenjamin Close static int wpi_probe(device_t);
2506607310bSBenjamin Close static int wpi_attach(device_t);
2516607310bSBenjamin Close static int wpi_detach(device_t);
2526607310bSBenjamin Close static int wpi_shutdown(device_t);
2536607310bSBenjamin Close static int wpi_suspend(device_t);
2546607310bSBenjamin Close static int wpi_resume(device_t);
2556607310bSBenjamin Close 
2566607310bSBenjamin Close 
2576607310bSBenjamin Close static device_method_t wpi_methods[] = {
2586607310bSBenjamin Close 	/* Device interface */
2596607310bSBenjamin Close 	DEVMETHOD(device_probe,		wpi_probe),
2606607310bSBenjamin Close 	DEVMETHOD(device_attach,	wpi_attach),
2616607310bSBenjamin Close 	DEVMETHOD(device_detach,	wpi_detach),
2626607310bSBenjamin Close 	DEVMETHOD(device_shutdown,	wpi_shutdown),
2636607310bSBenjamin Close 	DEVMETHOD(device_suspend,	wpi_suspend),
2646607310bSBenjamin Close 	DEVMETHOD(device_resume,	wpi_resume),
2656607310bSBenjamin Close 
2666607310bSBenjamin Close 	{ 0, 0 }
2676607310bSBenjamin Close };
2686607310bSBenjamin Close 
2696607310bSBenjamin Close static driver_t wpi_driver = {
2706607310bSBenjamin Close 	"wpi",
2716607310bSBenjamin Close 	wpi_methods,
2726607310bSBenjamin Close 	sizeof (struct wpi_softc)
2736607310bSBenjamin Close };
2746607310bSBenjamin Close 
2756607310bSBenjamin Close static devclass_t wpi_devclass;
2766607310bSBenjamin Close 
2776607310bSBenjamin Close DRIVER_MODULE(wpi, pci, wpi_driver, wpi_devclass, 0, 0);
2786607310bSBenjamin Close 
279129145a4SBernhard Schmidt MODULE_VERSION(wpi, 1);
280129145a4SBernhard Schmidt 
2816607310bSBenjamin Close static const uint8_t wpi_ridx_to_plcp[] = {
2826607310bSBenjamin Close 	/* OFDM: IEEE Std 802.11a-1999, pp. 14 Table 80 */
2836607310bSBenjamin Close 	/* R1-R4 (ral/ural is R4-R1) */
2846607310bSBenjamin Close 	0xd, 0xf, 0x5, 0x7, 0x9, 0xb, 0x1, 0x3,
2856607310bSBenjamin Close 	/* CCK: device-dependent */
2866607310bSBenjamin Close 	10, 20, 55, 110
2876607310bSBenjamin Close };
2886607310bSBenjamin Close static const uint8_t wpi_ridx_to_rate[] = {
2896607310bSBenjamin Close 	12, 18, 24, 36, 48, 72, 96, 108, /* OFDM */
2906607310bSBenjamin Close 	2, 4, 11, 22 /*CCK */
2916607310bSBenjamin Close };
2926607310bSBenjamin Close 
2936607310bSBenjamin Close 
2946607310bSBenjamin Close static int
2956607310bSBenjamin Close wpi_probe(device_t dev)
2966607310bSBenjamin Close {
2976607310bSBenjamin Close 	const struct wpi_ident *ident;
2986607310bSBenjamin Close 
2996607310bSBenjamin Close 	for (ident = wpi_ident_table; ident->name != NULL; ident++) {
3006607310bSBenjamin Close 		if (pci_get_vendor(dev) == ident->vendor &&
3016607310bSBenjamin Close 		    pci_get_device(dev) == ident->device) {
3026607310bSBenjamin Close 			device_set_desc(dev, ident->name);
3036607310bSBenjamin Close 			return 0;
3046607310bSBenjamin Close 		}
3056607310bSBenjamin Close 	}
3066607310bSBenjamin Close 	return ENXIO;
3076607310bSBenjamin Close }
3086607310bSBenjamin Close 
3096607310bSBenjamin Close /**
3106607310bSBenjamin Close  * Load the firmare image from disk to the allocated dma buffer.
3116607310bSBenjamin Close  * we also maintain the reference to the firmware pointer as there
3126607310bSBenjamin Close  * is times where we may need to reload the firmware but we are not
3136607310bSBenjamin Close  * in a context that can access the filesystem (ie taskq cause by restart)
3146607310bSBenjamin Close  *
3156607310bSBenjamin Close  * @return 0 on success, an errno on failure
3166607310bSBenjamin Close  */
3176607310bSBenjamin Close static int
3186607310bSBenjamin Close wpi_load_firmware(struct wpi_softc *sc)
3196607310bSBenjamin Close {
3206607310bSBenjamin Close 	const struct firmware *fp;
3216607310bSBenjamin Close 	struct wpi_dma_info *dma = &sc->fw_dma;
3226607310bSBenjamin Close 	const struct wpi_firmware_hdr *hdr;
3236607310bSBenjamin Close 	const uint8_t *itext, *idata, *rtext, *rdata, *btext;
3246607310bSBenjamin Close 	uint32_t itextsz, idatasz, rtextsz, rdatasz, btextsz;
3256607310bSBenjamin Close 	int error;
3266607310bSBenjamin Close 
3276607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,
3286607310bSBenjamin Close 	    ("Attempting Loading Firmware from wpi_fw module\n"));
3296607310bSBenjamin Close 
3306607310bSBenjamin Close 	WPI_UNLOCK(sc);
3316607310bSBenjamin Close 
3326607310bSBenjamin Close 	if (sc->fw_fp == NULL && (sc->fw_fp = firmware_get("wpifw")) == NULL) {
3336607310bSBenjamin Close 		device_printf(sc->sc_dev,
3346607310bSBenjamin Close 		    "could not load firmware image 'wpifw'\n");
3356607310bSBenjamin Close 		error = ENOENT;
3366607310bSBenjamin Close 		WPI_LOCK(sc);
3376607310bSBenjamin Close 		goto fail;
3386607310bSBenjamin Close 	}
3396607310bSBenjamin Close 
3406607310bSBenjamin Close 	fp = sc->fw_fp;
3416607310bSBenjamin Close 
3426607310bSBenjamin Close 	WPI_LOCK(sc);
3436607310bSBenjamin Close 
3446607310bSBenjamin Close 	/* Validate the firmware is minimum a particular version */
3456607310bSBenjamin Close 	if (fp->version < WPI_FW_MINVERSION) {
3466607310bSBenjamin Close 	    device_printf(sc->sc_dev,
3476607310bSBenjamin Close 			   "firmware version is too old. Need %d, got %d\n",
3486607310bSBenjamin Close 			   WPI_FW_MINVERSION,
3496607310bSBenjamin Close 			   fp->version);
3506607310bSBenjamin Close 	    error = ENXIO;
3516607310bSBenjamin Close 	    goto fail;
3526607310bSBenjamin Close 	}
3536607310bSBenjamin Close 
3546607310bSBenjamin Close 	if (fp->datasize < sizeof (struct wpi_firmware_hdr)) {
3556607310bSBenjamin Close 		device_printf(sc->sc_dev,
3566607310bSBenjamin Close 		    "firmware file too short: %zu bytes\n", fp->datasize);
3576607310bSBenjamin Close 		error = ENXIO;
3586607310bSBenjamin Close 		goto fail;
3596607310bSBenjamin Close 	}
3606607310bSBenjamin Close 
3616607310bSBenjamin Close 	hdr = (const struct wpi_firmware_hdr *)fp->data;
3626607310bSBenjamin Close 
3636607310bSBenjamin Close 	/*     |  RUNTIME FIRMWARE   |    INIT FIRMWARE    | BOOT FW  |
3646607310bSBenjamin Close 	   |HDR|<--TEXT-->|<--DATA-->|<--TEXT-->|<--DATA-->|<--TEXT-->| */
3656607310bSBenjamin Close 
3666607310bSBenjamin Close 	rtextsz = le32toh(hdr->rtextsz);
3676607310bSBenjamin Close 	rdatasz = le32toh(hdr->rdatasz);
3686607310bSBenjamin Close 	itextsz = le32toh(hdr->itextsz);
3696607310bSBenjamin Close 	idatasz = le32toh(hdr->idatasz);
3706607310bSBenjamin Close 	btextsz = le32toh(hdr->btextsz);
3716607310bSBenjamin Close 
3726607310bSBenjamin Close 	/* check that all firmware segments are present */
3736607310bSBenjamin Close 	if (fp->datasize < sizeof (struct wpi_firmware_hdr) +
3746607310bSBenjamin Close 		rtextsz + rdatasz + itextsz + idatasz + btextsz) {
3756607310bSBenjamin Close 		device_printf(sc->sc_dev,
3766607310bSBenjamin Close 		    "firmware file too short: %zu bytes\n", fp->datasize);
3776607310bSBenjamin Close 		error = ENXIO; /* XXX appropriate error code? */
3786607310bSBenjamin Close 		goto fail;
3796607310bSBenjamin Close 	}
3806607310bSBenjamin Close 
3816607310bSBenjamin Close 	/* get pointers to firmware segments */
3826607310bSBenjamin Close 	rtext = (const uint8_t *)(hdr + 1);
3836607310bSBenjamin Close 	rdata = rtext + rtextsz;
3846607310bSBenjamin Close 	itext = rdata + rdatasz;
3856607310bSBenjamin Close 	idata = itext + itextsz;
3866607310bSBenjamin Close 	btext = idata + idatasz;
3876607310bSBenjamin Close 
3886607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,
3896607310bSBenjamin Close 	    ("Firmware Version: Major %d, Minor %d, Driver %d, \n"
3906607310bSBenjamin Close 	     "runtime (text: %u, data: %u) init (text: %u, data %u) boot (text %u)\n",
3916607310bSBenjamin Close 	     (le32toh(hdr->version) & 0xff000000) >> 24,
3926607310bSBenjamin Close 	     (le32toh(hdr->version) & 0x00ff0000) >> 16,
3936607310bSBenjamin Close 	     (le32toh(hdr->version) & 0x0000ffff),
3946607310bSBenjamin Close 	     rtextsz, rdatasz,
3956607310bSBenjamin Close 	     itextsz, idatasz, btextsz));
3966607310bSBenjamin Close 
3976607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,("rtext 0x%x\n", *(const uint32_t *)rtext));
3986607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,("rdata 0x%x\n", *(const uint32_t *)rdata));
3996607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,("itext 0x%x\n", *(const uint32_t *)itext));
4006607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,("idata 0x%x\n", *(const uint32_t *)idata));
4016607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,("btext 0x%x\n", *(const uint32_t *)btext));
4026607310bSBenjamin Close 
4036607310bSBenjamin Close 	/* sanity checks */
4046607310bSBenjamin Close 	if (rtextsz > WPI_FW_MAIN_TEXT_MAXSZ ||
4056607310bSBenjamin Close 	    rdatasz > WPI_FW_MAIN_DATA_MAXSZ ||
4066607310bSBenjamin Close 	    itextsz > WPI_FW_INIT_TEXT_MAXSZ ||
4076607310bSBenjamin Close 	    idatasz > WPI_FW_INIT_DATA_MAXSZ ||
4086607310bSBenjamin Close 	    btextsz > WPI_FW_BOOT_TEXT_MAXSZ ||
4096607310bSBenjamin Close 	    (btextsz & 3) != 0) {
4106607310bSBenjamin Close 		device_printf(sc->sc_dev, "firmware invalid\n");
4116607310bSBenjamin Close 		error = EINVAL;
4126607310bSBenjamin Close 		goto fail;
4136607310bSBenjamin Close 	}
4146607310bSBenjamin Close 
4156607310bSBenjamin Close 	/* copy initialization images into pre-allocated DMA-safe memory */
4166607310bSBenjamin Close 	memcpy(dma->vaddr, idata, idatasz);
4176607310bSBenjamin Close 	memcpy(dma->vaddr + WPI_FW_INIT_DATA_MAXSZ, itext, itextsz);
4186607310bSBenjamin Close 
4196607310bSBenjamin Close 	bus_dmamap_sync(dma->tag, dma->map, BUS_DMASYNC_PREWRITE);
4206607310bSBenjamin Close 
4216607310bSBenjamin Close 	/* tell adapter where to find initialization images */
4226607310bSBenjamin Close 	wpi_mem_lock(sc);
4236607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_DATA_BASE, dma->paddr);
4246607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_DATA_SIZE, idatasz);
4256607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_TEXT_BASE,
4266607310bSBenjamin Close 	    dma->paddr + WPI_FW_INIT_DATA_MAXSZ);
4276607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_TEXT_SIZE, itextsz);
4286607310bSBenjamin Close 	wpi_mem_unlock(sc);
4296607310bSBenjamin Close 
4306607310bSBenjamin Close 	/* load firmware boot code */
4316607310bSBenjamin Close 	if ((error = wpi_load_microcode(sc, btext, btextsz)) != 0) {
4326607310bSBenjamin Close 	    device_printf(sc->sc_dev, "Failed to load microcode\n");
4336607310bSBenjamin Close 	    goto fail;
4346607310bSBenjamin Close 	}
4356607310bSBenjamin Close 
4366607310bSBenjamin Close 	/* now press "execute" */
4376607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RESET, 0);
4386607310bSBenjamin Close 
4396607310bSBenjamin Close 	/* wait at most one second for the first alive notification */
4406607310bSBenjamin Close 	if ((error = msleep(sc, &sc->sc_mtx, PCATCH, "wpiinit", hz)) != 0) {
4416607310bSBenjamin Close 		device_printf(sc->sc_dev,
4426607310bSBenjamin Close 		    "timeout waiting for adapter to initialize\n");
4436607310bSBenjamin Close 		goto fail;
4446607310bSBenjamin Close 	}
4456607310bSBenjamin Close 
4466607310bSBenjamin Close 	/* copy runtime images into pre-allocated DMA-sage memory */
4476607310bSBenjamin Close 	memcpy(dma->vaddr, rdata, rdatasz);
4486607310bSBenjamin Close 	memcpy(dma->vaddr + WPI_FW_MAIN_DATA_MAXSZ, rtext, rtextsz);
4496607310bSBenjamin Close 	bus_dmamap_sync(dma->tag, dma->map, BUS_DMASYNC_PREWRITE);
4506607310bSBenjamin Close 
4516607310bSBenjamin Close 	/* tell adapter where to find runtime images */
4526607310bSBenjamin Close 	wpi_mem_lock(sc);
4536607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_DATA_BASE, dma->paddr);
4546607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_DATA_SIZE, rdatasz);
4556607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_TEXT_BASE,
4566607310bSBenjamin Close 	    dma->paddr + WPI_FW_MAIN_DATA_MAXSZ);
4576607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_TEXT_SIZE, WPI_FW_UPDATED | rtextsz);
4586607310bSBenjamin Close 	wpi_mem_unlock(sc);
4596607310bSBenjamin Close 
4606607310bSBenjamin Close 	/* wait at most one second for the first alive notification */
4616607310bSBenjamin Close 	if ((error = msleep(sc, &sc->sc_mtx, PCATCH, "wpiinit", hz)) != 0) {
4626607310bSBenjamin Close 		device_printf(sc->sc_dev,
4636607310bSBenjamin Close 		    "timeout waiting for adapter to initialize2\n");
4646607310bSBenjamin Close 		goto fail;
4656607310bSBenjamin Close 	}
4666607310bSBenjamin Close 
4676607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_FIRMWARE,
4686607310bSBenjamin Close 	    ("Firmware loaded to driver successfully\n"));
4696607310bSBenjamin Close 	return error;
4706607310bSBenjamin Close fail:
4716607310bSBenjamin Close 	wpi_unload_firmware(sc);
4726607310bSBenjamin Close 	return error;
4736607310bSBenjamin Close }
4746607310bSBenjamin Close 
4756607310bSBenjamin Close /**
4766607310bSBenjamin Close  * Free the referenced firmware image
4776607310bSBenjamin Close  */
4786607310bSBenjamin Close static void
4796607310bSBenjamin Close wpi_unload_firmware(struct wpi_softc *sc)
4806607310bSBenjamin Close {
4816607310bSBenjamin Close 
4826607310bSBenjamin Close 	if (sc->fw_fp) {
4836607310bSBenjamin Close 		WPI_UNLOCK(sc);
4846607310bSBenjamin Close 		firmware_put(sc->fw_fp, FIRMWARE_UNLOAD);
4856607310bSBenjamin Close 		WPI_LOCK(sc);
4866607310bSBenjamin Close 		sc->fw_fp = NULL;
4876607310bSBenjamin Close 	}
4886607310bSBenjamin Close }
4896607310bSBenjamin Close 
4906607310bSBenjamin Close static int
4916607310bSBenjamin Close wpi_attach(device_t dev)
4926607310bSBenjamin Close {
4936607310bSBenjamin Close 	struct wpi_softc *sc = device_get_softc(dev);
4946607310bSBenjamin Close 	struct ifnet *ifp;
495b032f27cSSam Leffler 	struct ieee80211com *ic;
4966607310bSBenjamin Close 	int ac, error, supportsa = 1;
4976607310bSBenjamin Close 	uint32_t tmp;
4986607310bSBenjamin Close 	const struct wpi_ident *ident;
49929aca940SSam Leffler 	uint8_t macaddr[IEEE80211_ADDR_LEN];
5006607310bSBenjamin Close 
5016607310bSBenjamin Close 	sc->sc_dev = dev;
5026607310bSBenjamin Close 
5036845408dSAndrew Thompson 	if (bootverbose || WPI_DEBUG_SET)
5046607310bSBenjamin Close 	    device_printf(sc->sc_dev,"Driver Revision %s\n", VERSION);
5056607310bSBenjamin Close 
5066607310bSBenjamin Close 	/*
5076607310bSBenjamin Close 	 * Some card's only support 802.11b/g not a, check to see if
5086607310bSBenjamin Close 	 * this is one such card. A 0x0 in the subdevice table indicates
5096607310bSBenjamin Close 	 * the entire subdevice range is to be ignored.
5106607310bSBenjamin Close 	 */
5116607310bSBenjamin Close 	for (ident = wpi_ident_table; ident->name != NULL; ident++) {
5126607310bSBenjamin Close 		if (ident->subdevice &&
5136607310bSBenjamin Close 		    pci_get_subdevice(dev) == ident->subdevice) {
5146607310bSBenjamin Close 		    supportsa = 0;
5156607310bSBenjamin Close 		    break;
5166607310bSBenjamin Close 		}
5176607310bSBenjamin Close 	}
5186607310bSBenjamin Close 
5196607310bSBenjamin Close 	/* Create the tasks that can be queued */
5205efea30fSAndrew Thompson 	TASK_INIT(&sc->sc_restarttask, 0, wpi_hwreset, sc);
5215efea30fSAndrew Thompson 	TASK_INIT(&sc->sc_radiotask, 0, wpi_rfreset, sc);
5226607310bSBenjamin Close 
5236607310bSBenjamin Close 	WPI_LOCK_INIT(sc);
5246607310bSBenjamin Close 
5256607310bSBenjamin Close 	callout_init_mtx(&sc->calib_to, &sc->sc_mtx, 0);
5266607310bSBenjamin Close 	callout_init_mtx(&sc->watchdog_to, &sc->sc_mtx, 0);
5276607310bSBenjamin Close 
5286607310bSBenjamin Close 	if (pci_get_powerstate(dev) != PCI_POWERSTATE_D0) {
5296607310bSBenjamin Close 		device_printf(dev, "chip is in D%d power mode "
5306607310bSBenjamin Close 		    "-- setting to D0\n", pci_get_powerstate(dev));
5316607310bSBenjamin Close 		pci_set_powerstate(dev, PCI_POWERSTATE_D0);
5326607310bSBenjamin Close 	}
5336607310bSBenjamin Close 
5346607310bSBenjamin Close 	/* disable the retry timeout register */
5356607310bSBenjamin Close 	pci_write_config(dev, 0x41, 0, 1);
5366607310bSBenjamin Close 
5376607310bSBenjamin Close 	/* enable bus-mastering */
5386607310bSBenjamin Close 	pci_enable_busmaster(dev);
5396607310bSBenjamin Close 
5406607310bSBenjamin Close 	sc->mem_rid = PCIR_BAR(0);
5416607310bSBenjamin Close 	sc->mem = bus_alloc_resource_any(dev, SYS_RES_MEMORY, &sc->mem_rid,
5426607310bSBenjamin Close 	    RF_ACTIVE);
5436607310bSBenjamin Close 	if (sc->mem == NULL) {
5446607310bSBenjamin Close 		device_printf(dev, "could not allocate memory resource\n");
5456607310bSBenjamin Close 		error = ENOMEM;
5466607310bSBenjamin Close 		goto fail;
5476607310bSBenjamin Close 	}
5486607310bSBenjamin Close 
5496607310bSBenjamin Close 	sc->sc_st = rman_get_bustag(sc->mem);
5506607310bSBenjamin Close 	sc->sc_sh = rman_get_bushandle(sc->mem);
5516607310bSBenjamin Close 
5526607310bSBenjamin Close 	sc->irq_rid = 0;
5536607310bSBenjamin Close 	sc->irq = bus_alloc_resource_any(dev, SYS_RES_IRQ, &sc->irq_rid,
5546607310bSBenjamin Close 	    RF_ACTIVE | RF_SHAREABLE);
5556607310bSBenjamin Close 	if (sc->irq == NULL) {
5566607310bSBenjamin Close 		device_printf(dev, "could not allocate interrupt resource\n");
5576607310bSBenjamin Close 		error = ENOMEM;
5586607310bSBenjamin Close 		goto fail;
5596607310bSBenjamin Close 	}
5606607310bSBenjamin Close 
5616607310bSBenjamin Close 	/*
5626607310bSBenjamin Close 	 * Allocate DMA memory for firmware transfers.
5636607310bSBenjamin Close 	 */
5646607310bSBenjamin Close 	if ((error = wpi_alloc_fwmem(sc)) != 0) {
5656607310bSBenjamin Close 		printf(": could not allocate firmware memory\n");
5666607310bSBenjamin Close 		error = ENOMEM;
5676607310bSBenjamin Close 		goto fail;
5686607310bSBenjamin Close 	}
5696607310bSBenjamin Close 
5706607310bSBenjamin Close 	/*
5716607310bSBenjamin Close 	 * Put adapter into a known state.
5726607310bSBenjamin Close 	 */
5736607310bSBenjamin Close 	if ((error = wpi_reset(sc)) != 0) {
5746607310bSBenjamin Close 		device_printf(dev, "could not reset adapter\n");
5756607310bSBenjamin Close 		goto fail;
5766607310bSBenjamin Close 	}
5776607310bSBenjamin Close 
5786607310bSBenjamin Close 	wpi_mem_lock(sc);
5796607310bSBenjamin Close 	tmp = wpi_mem_read(sc, WPI_MEM_PCIDEV);
5806845408dSAndrew Thompson 	if (bootverbose || WPI_DEBUG_SET)
5816607310bSBenjamin Close 	    device_printf(sc->sc_dev, "Hardware Revision (0x%X)\n", tmp);
5826607310bSBenjamin Close 
5836607310bSBenjamin Close 	wpi_mem_unlock(sc);
5846607310bSBenjamin Close 
5856607310bSBenjamin Close 	/* Allocate shared page */
5866607310bSBenjamin Close 	if ((error = wpi_alloc_shared(sc)) != 0) {
5876607310bSBenjamin Close 		device_printf(dev, "could not allocate shared page\n");
5886607310bSBenjamin Close 		goto fail;
5896607310bSBenjamin Close 	}
5906607310bSBenjamin Close 
5916607310bSBenjamin Close 	/* tx data queues  - 4 for QoS purposes */
5926607310bSBenjamin Close 	for (ac = 0; ac < WME_NUM_AC; ac++) {
5936607310bSBenjamin Close 		error = wpi_alloc_tx_ring(sc, &sc->txq[ac], WPI_TX_RING_COUNT, ac);
5946607310bSBenjamin Close 		if (error != 0) {
5956607310bSBenjamin Close 		    device_printf(dev, "could not allocate Tx ring %d\n",ac);
5966607310bSBenjamin Close 		    goto fail;
5976607310bSBenjamin Close 		}
5986607310bSBenjamin Close 	}
5996607310bSBenjamin Close 
6006607310bSBenjamin Close 	/* command queue to talk to the card's firmware */
6016607310bSBenjamin Close 	error = wpi_alloc_tx_ring(sc, &sc->cmdq, WPI_CMD_RING_COUNT, 4);
6026607310bSBenjamin Close 	if (error != 0) {
6036607310bSBenjamin Close 		device_printf(dev, "could not allocate command ring\n");
6046607310bSBenjamin Close 		goto fail;
6056607310bSBenjamin Close 	}
6066607310bSBenjamin Close 
6076607310bSBenjamin Close 	/* receive data queue */
6086607310bSBenjamin Close 	error = wpi_alloc_rx_ring(sc, &sc->rxq);
6096607310bSBenjamin Close 	if (error != 0) {
6106607310bSBenjamin Close 		device_printf(dev, "could not allocate Rx ring\n");
6116607310bSBenjamin Close 		goto fail;
6126607310bSBenjamin Close 	}
6136607310bSBenjamin Close 
614b032f27cSSam Leffler 	ifp = sc->sc_ifp = if_alloc(IFT_IEEE80211);
6156607310bSBenjamin Close 	if (ifp == NULL) {
6166607310bSBenjamin Close 		device_printf(dev, "can not if_alloc()\n");
6176607310bSBenjamin Close 		error = ENOMEM;
6186607310bSBenjamin Close 		goto fail;
6196607310bSBenjamin Close 	}
620b032f27cSSam Leffler 	ic = ifp->if_l2com;
6216607310bSBenjamin Close 
6226607310bSBenjamin Close 	ic->ic_ifp = ifp;
6236607310bSBenjamin Close 	ic->ic_phytype = IEEE80211_T_OFDM;	/* not only, but not used */
6246607310bSBenjamin Close 	ic->ic_opmode = IEEE80211_M_STA;	/* default to BSS mode */
6256607310bSBenjamin Close 
6266607310bSBenjamin Close 	/* set device capabilities */
6276607310bSBenjamin Close 	ic->ic_caps =
628c43feedeSSam Leffler 		  IEEE80211_C_STA		/* station mode supported */
629c43feedeSSam Leffler 		| IEEE80211_C_MONITOR		/* monitor mode supported */
6306607310bSBenjamin Close 		| IEEE80211_C_TXPMGT		/* tx power management */
6316607310bSBenjamin Close 		| IEEE80211_C_SHSLOT		/* short slot time supported */
6326607310bSBenjamin Close 		| IEEE80211_C_SHPREAMBLE	/* short preamble supported */
6336607310bSBenjamin Close 		| IEEE80211_C_WPA		/* 802.11i */
6346607310bSBenjamin Close /* XXX looks like WME is partly supported? */
6356607310bSBenjamin Close #if 0
6366607310bSBenjamin Close 		| IEEE80211_C_IBSS		/* IBSS mode support */
6376607310bSBenjamin Close 		| IEEE80211_C_BGSCAN		/* capable of bg scanning */
6386607310bSBenjamin Close 		| IEEE80211_C_WME		/* 802.11e */
6396607310bSBenjamin Close 		| IEEE80211_C_HOSTAP		/* Host access point mode */
6406607310bSBenjamin Close #endif
6416607310bSBenjamin Close 		;
6426607310bSBenjamin Close 
6436607310bSBenjamin Close 	/*
6446607310bSBenjamin Close 	 * Read in the eeprom and also setup the channels for
6456607310bSBenjamin Close 	 * net80211. We don't set the rates as net80211 does this for us
6466607310bSBenjamin Close 	 */
64729aca940SSam Leffler 	wpi_read_eeprom(sc, macaddr);
6486607310bSBenjamin Close 
6496845408dSAndrew Thompson 	if (bootverbose || WPI_DEBUG_SET) {
6506607310bSBenjamin Close 	    device_printf(sc->sc_dev, "Regulatory Domain: %.4s\n", sc->domain);
6516607310bSBenjamin Close 	    device_printf(sc->sc_dev, "Hardware Type: %c\n",
6526607310bSBenjamin Close 			  sc->type > 1 ? 'B': '?');
6536607310bSBenjamin Close 	    device_printf(sc->sc_dev, "Hardware Revision: %c\n",
6546607310bSBenjamin Close 			  ((le16toh(sc->rev) & 0xf0) == 0xd0) ? 'D': '?');
6556607310bSBenjamin Close 	    device_printf(sc->sc_dev, "SKU %s support 802.11a\n",
6566607310bSBenjamin Close 			  supportsa ? "does" : "does not");
6576607310bSBenjamin Close 
6586607310bSBenjamin Close 	    /* XXX hw_config uses the PCIDEV for the Hardware rev. Must check
6596607310bSBenjamin Close 	       what sc->rev really represents - benjsc 20070615 */
6606607310bSBenjamin Close 	}
6616607310bSBenjamin Close 
6626607310bSBenjamin Close 	if_initname(ifp, device_get_name(dev), device_get_unit(dev));
6636607310bSBenjamin Close 	ifp->if_softc = sc;
6646607310bSBenjamin Close 	ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
6656607310bSBenjamin Close 	ifp->if_init = wpi_init;
6666607310bSBenjamin Close 	ifp->if_ioctl = wpi_ioctl;
6676607310bSBenjamin Close 	ifp->if_start = wpi_start;
668e50d35e6SMaxim Sobolev 	IFQ_SET_MAXLEN(&ifp->if_snd, ifqmaxlen);
669e50d35e6SMaxim Sobolev 	ifp->if_snd.ifq_drv_maxlen = ifqmaxlen;
6706607310bSBenjamin Close 	IFQ_SET_READY(&ifp->if_snd);
6716607310bSBenjamin Close 
67229aca940SSam Leffler 	ieee80211_ifattach(ic, macaddr);
6736607310bSBenjamin Close 	/* override default methods */
674b032f27cSSam Leffler 	ic->ic_raw_xmit = wpi_raw_xmit;
6756607310bSBenjamin Close 	ic->ic_wme.wme_update = wpi_wme_update;
6766607310bSBenjamin Close 	ic->ic_scan_start = wpi_scan_start;
6776607310bSBenjamin Close 	ic->ic_scan_end = wpi_scan_end;
6786607310bSBenjamin Close 	ic->ic_set_channel = wpi_set_channel;
6796607310bSBenjamin Close 	ic->ic_scan_curchan = wpi_scan_curchan;
6806607310bSBenjamin Close 	ic->ic_scan_mindwell = wpi_scan_mindwell;
6816607310bSBenjamin Close 
682b032f27cSSam Leffler 	ic->ic_vap_create = wpi_vap_create;
683b032f27cSSam Leffler 	ic->ic_vap_delete = wpi_vap_delete;
6846607310bSBenjamin Close 
6855463c4a4SSam Leffler 	ieee80211_radiotap_attach(ic,
6865463c4a4SSam Leffler 	    &sc->sc_txtap.wt_ihdr, sizeof(sc->sc_txtap),
6875463c4a4SSam Leffler 		WPI_TX_RADIOTAP_PRESENT,
6885463c4a4SSam Leffler 	    &sc->sc_rxtap.wr_ihdr, sizeof(sc->sc_rxtap),
6895463c4a4SSam Leffler 		WPI_RX_RADIOTAP_PRESENT);
6906607310bSBenjamin Close 
6916607310bSBenjamin Close 	/*
6926607310bSBenjamin Close 	 * Hook our interrupt after all initialization is complete.
6936607310bSBenjamin Close 	 */
6946607310bSBenjamin Close 	error = bus_setup_intr(dev, sc->irq, INTR_TYPE_NET |INTR_MPSAFE,
69582f1b132SAndrew Thompson 	    NULL, wpi_intr, sc, &sc->sc_ih);
6966607310bSBenjamin Close 	if (error != 0) {
6976607310bSBenjamin Close 		device_printf(dev, "could not set up interrupt\n");
6986607310bSBenjamin Close 		goto fail;
6996607310bSBenjamin Close 	}
7006607310bSBenjamin Close 
70182f1b132SAndrew Thompson 	if (bootverbose)
7026607310bSBenjamin Close 		ieee80211_announce(ic);
7036607310bSBenjamin Close #ifdef XXX_DEBUG
7046607310bSBenjamin Close 	ieee80211_announce_channels(ic);
7056607310bSBenjamin Close #endif
7066607310bSBenjamin Close 	return 0;
7076607310bSBenjamin Close 
7086607310bSBenjamin Close fail:	wpi_detach(dev);
7096607310bSBenjamin Close 	return ENXIO;
7106607310bSBenjamin Close }
7116607310bSBenjamin Close 
7126607310bSBenjamin Close static int
7136607310bSBenjamin Close wpi_detach(device_t dev)
7146607310bSBenjamin Close {
7156607310bSBenjamin Close 	struct wpi_softc *sc = device_get_softc(dev);
716b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
7174e7ebd34SGavin Atkinson 	struct ieee80211com *ic;
7186607310bSBenjamin Close 	int ac;
7196607310bSBenjamin Close 
7204e7ebd34SGavin Atkinson 	if (ifp != NULL) {
7214e7ebd34SGavin Atkinson 		ic = ifp->if_l2com;
7224e7ebd34SGavin Atkinson 
7235efea30fSAndrew Thompson 		ieee80211_draintask(ic, &sc->sc_restarttask);
7245efea30fSAndrew Thompson 		ieee80211_draintask(ic, &sc->sc_radiotask);
7256607310bSBenjamin Close 		wpi_stop(sc);
7266607310bSBenjamin Close 		callout_drain(&sc->watchdog_to);
7276607310bSBenjamin Close 		callout_drain(&sc->calib_to);
7286607310bSBenjamin Close 		ieee80211_ifdetach(ic);
7296607310bSBenjamin Close 	}
7306607310bSBenjamin Close 
7316607310bSBenjamin Close 	WPI_LOCK(sc);
7326607310bSBenjamin Close 	if (sc->txq[0].data_dmat) {
7336607310bSBenjamin Close 		for (ac = 0; ac < WME_NUM_AC; ac++)
7346607310bSBenjamin Close 			wpi_free_tx_ring(sc, &sc->txq[ac]);
7356607310bSBenjamin Close 
7366607310bSBenjamin Close 		wpi_free_tx_ring(sc, &sc->cmdq);
7376607310bSBenjamin Close 		wpi_free_rx_ring(sc, &sc->rxq);
7386607310bSBenjamin Close 		wpi_free_shared(sc);
7396607310bSBenjamin Close 	}
7406607310bSBenjamin Close 
7416607310bSBenjamin Close 	if (sc->fw_fp != NULL) {
7426607310bSBenjamin Close 		wpi_unload_firmware(sc);
7436607310bSBenjamin Close 	}
7446607310bSBenjamin Close 
7456607310bSBenjamin Close 	if (sc->fw_dma.tag)
7466607310bSBenjamin Close 		wpi_free_fwmem(sc);
7476607310bSBenjamin Close 	WPI_UNLOCK(sc);
7486607310bSBenjamin Close 
7496607310bSBenjamin Close 	if (sc->irq != NULL) {
7506607310bSBenjamin Close 		bus_teardown_intr(dev, sc->irq, sc->sc_ih);
7516607310bSBenjamin Close 		bus_release_resource(dev, SYS_RES_IRQ, sc->irq_rid, sc->irq);
7526607310bSBenjamin Close 	}
7536607310bSBenjamin Close 
7546607310bSBenjamin Close 	if (sc->mem != NULL)
7556607310bSBenjamin Close 		bus_release_resource(dev, SYS_RES_MEMORY, sc->mem_rid, sc->mem);
7566607310bSBenjamin Close 
7576607310bSBenjamin Close 	if (ifp != NULL)
7586607310bSBenjamin Close 		if_free(ifp);
7596607310bSBenjamin Close 
7606607310bSBenjamin Close 	WPI_LOCK_DESTROY(sc);
7616607310bSBenjamin Close 
7626607310bSBenjamin Close 	return 0;
7636607310bSBenjamin Close }
7646607310bSBenjamin Close 
765b032f27cSSam Leffler static struct ieee80211vap *
766fcd9500fSBernhard Schmidt wpi_vap_create(struct ieee80211com *ic, const char name[IFNAMSIZ], int unit,
767fcd9500fSBernhard Schmidt     enum ieee80211_opmode opmode, int flags,
768b032f27cSSam Leffler     const uint8_t bssid[IEEE80211_ADDR_LEN],
769b032f27cSSam Leffler     const uint8_t mac[IEEE80211_ADDR_LEN])
770b032f27cSSam Leffler {
771b032f27cSSam Leffler 	struct wpi_vap *wvp;
772b032f27cSSam Leffler 	struct ieee80211vap *vap;
773b032f27cSSam Leffler 
774b032f27cSSam Leffler 	if (!TAILQ_EMPTY(&ic->ic_vaps))		/* only one at a time */
775b032f27cSSam Leffler 		return NULL;
776b032f27cSSam Leffler 	wvp = (struct wpi_vap *) malloc(sizeof(struct wpi_vap),
777b032f27cSSam Leffler 	    M_80211_VAP, M_NOWAIT | M_ZERO);
778b032f27cSSam Leffler 	if (wvp == NULL)
779b032f27cSSam Leffler 		return NULL;
780b032f27cSSam Leffler 	vap = &wvp->vap;
781b032f27cSSam Leffler 	ieee80211_vap_setup(ic, vap, name, unit, opmode, flags, bssid, mac);
782b032f27cSSam Leffler 	/* override with driver methods */
783b032f27cSSam Leffler 	wvp->newstate = vap->iv_newstate;
784b032f27cSSam Leffler 	vap->iv_newstate = wpi_newstate;
785b032f27cSSam Leffler 
786b6108616SRui Paulo 	ieee80211_ratectl_init(vap);
787b032f27cSSam Leffler 	/* complete setup */
788b032f27cSSam Leffler 	ieee80211_vap_attach(vap, ieee80211_media_change, ieee80211_media_status);
789b032f27cSSam Leffler 	ic->ic_opmode = opmode;
790b032f27cSSam Leffler 	return vap;
791b032f27cSSam Leffler }
792b032f27cSSam Leffler 
793b032f27cSSam Leffler static void
794b032f27cSSam Leffler wpi_vap_delete(struct ieee80211vap *vap)
795b032f27cSSam Leffler {
796b032f27cSSam Leffler 	struct wpi_vap *wvp = WPI_VAP(vap);
797b032f27cSSam Leffler 
798b6108616SRui Paulo 	ieee80211_ratectl_deinit(vap);
799b032f27cSSam Leffler 	ieee80211_vap_detach(vap);
800b032f27cSSam Leffler 	free(wvp, M_80211_VAP);
801b032f27cSSam Leffler }
802b032f27cSSam Leffler 
8036607310bSBenjamin Close static void
8046607310bSBenjamin Close wpi_dma_map_addr(void *arg, bus_dma_segment_t *segs, int nsegs, int error)
8056607310bSBenjamin Close {
8066607310bSBenjamin Close 	if (error != 0)
8076607310bSBenjamin Close 		return;
8086607310bSBenjamin Close 
8096607310bSBenjamin Close 	KASSERT(nsegs == 1, ("too many DMA segments, %d should be 1", nsegs));
8106607310bSBenjamin Close 
8116607310bSBenjamin Close 	*(bus_addr_t *)arg = segs[0].ds_addr;
8126607310bSBenjamin Close }
8136607310bSBenjamin Close 
81482f1b132SAndrew Thompson /*
81582f1b132SAndrew Thompson  * Allocates a contiguous block of dma memory of the requested size and
81682f1b132SAndrew Thompson  * alignment. Due to limitations of the FreeBSD dma subsystem as of 20071217,
81782f1b132SAndrew Thompson  * allocations greater than 4096 may fail. Hence if the requested alignment is
81882f1b132SAndrew Thompson  * greater we allocate 'alignment' size extra memory and shift the vaddr and
81982f1b132SAndrew Thompson  * paddr after the dma load. This bypasses the problem at the cost of a little
82082f1b132SAndrew Thompson  * more memory.
82182f1b132SAndrew Thompson  */
8226607310bSBenjamin Close static int
8236607310bSBenjamin Close wpi_dma_contig_alloc(struct wpi_softc *sc, struct wpi_dma_info *dma,
8246607310bSBenjamin Close     void **kvap, bus_size_t size, bus_size_t alignment, int flags)
8256607310bSBenjamin Close {
8266607310bSBenjamin Close 	int error;
82782f1b132SAndrew Thompson 	bus_size_t align;
82882f1b132SAndrew Thompson 	bus_size_t reqsize;
8296607310bSBenjamin Close 
8306607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_DMA,
83182f1b132SAndrew Thompson 	    ("Size: %zd - alignment %zd\n", size, alignment));
8326607310bSBenjamin Close 
8336607310bSBenjamin Close 	dma->size = size;
8346607310bSBenjamin Close 	dma->tag = NULL;
8356607310bSBenjamin Close 
83682f1b132SAndrew Thompson 	if (alignment > 4096) {
83782f1b132SAndrew Thompson 		align = PAGE_SIZE;
83882f1b132SAndrew Thompson 		reqsize = size + alignment;
83982f1b132SAndrew Thompson 	} else {
84082f1b132SAndrew Thompson 		align = alignment;
84182f1b132SAndrew Thompson 		reqsize = size;
84282f1b132SAndrew Thompson 	}
84382f1b132SAndrew Thompson 	error = bus_dma_tag_create(bus_get_dma_tag(sc->sc_dev), align,
8446607310bSBenjamin Close 	    0, BUS_SPACE_MAXADDR_32BIT, BUS_SPACE_MAXADDR,
84582f1b132SAndrew Thompson 	    NULL, NULL, reqsize,
84682f1b132SAndrew Thompson 	    1, reqsize, flags,
8476607310bSBenjamin Close 	    NULL, NULL, &dma->tag);
8486607310bSBenjamin Close 	if (error != 0) {
8496607310bSBenjamin Close 		device_printf(sc->sc_dev,
8506607310bSBenjamin Close 		    "could not create shared page DMA tag\n");
8516607310bSBenjamin Close 		goto fail;
8526607310bSBenjamin Close 	}
85382f1b132SAndrew Thompson 	error = bus_dmamem_alloc(dma->tag, (void **)&dma->vaddr_start,
8546607310bSBenjamin Close 	    flags | BUS_DMA_ZERO, &dma->map);
8556607310bSBenjamin Close 	if (error != 0) {
8566607310bSBenjamin Close 		device_printf(sc->sc_dev,
8576607310bSBenjamin Close 		    "could not allocate shared page DMA memory\n");
8586607310bSBenjamin Close 		goto fail;
8596607310bSBenjamin Close 	}
8606607310bSBenjamin Close 
86182f1b132SAndrew Thompson 	error = bus_dmamap_load(dma->tag, dma->map, dma->vaddr_start,
86282f1b132SAndrew Thompson 	    reqsize,  wpi_dma_map_addr, &dma->paddr_start, flags);
8636607310bSBenjamin Close 
86482f1b132SAndrew Thompson 	/* Save the original pointers so we can free all the memory */
86582f1b132SAndrew Thompson 	dma->paddr = dma->paddr_start;
86682f1b132SAndrew Thompson 	dma->vaddr = dma->vaddr_start;
86782f1b132SAndrew Thompson 
86882f1b132SAndrew Thompson 	/*
86982f1b132SAndrew Thompson 	 * Check the alignment and increment by 4096 until we get the
87082f1b132SAndrew Thompson 	 * requested alignment. Fail if can't obtain the alignment
87182f1b132SAndrew Thompson 	 * we requested.
87282f1b132SAndrew Thompson 	 */
87382f1b132SAndrew Thompson 	if ((dma->paddr & (alignment -1 )) != 0) {
87482f1b132SAndrew Thompson 		int i;
87582f1b132SAndrew Thompson 
87682f1b132SAndrew Thompson 		for (i = 0; i < alignment / 4096; i++) {
87782f1b132SAndrew Thompson 			if ((dma->paddr & (alignment - 1 )) == 0)
87882f1b132SAndrew Thompson 				break;
87982f1b132SAndrew Thompson 			dma->paddr += 4096;
88082f1b132SAndrew Thompson 			dma->vaddr += 4096;
88182f1b132SAndrew Thompson 		}
88282f1b132SAndrew Thompson 		if (i == alignment / 4096) {
88382f1b132SAndrew Thompson 			device_printf(sc->sc_dev,
88482f1b132SAndrew Thompson 			    "alignment requirement was not satisfied\n");
8856607310bSBenjamin Close 			goto fail;
8866607310bSBenjamin Close 		}
88782f1b132SAndrew Thompson 	}
8886607310bSBenjamin Close 
8896607310bSBenjamin Close 	if (error != 0) {
8906607310bSBenjamin Close 		device_printf(sc->sc_dev,
8916607310bSBenjamin Close 		    "could not load shared page DMA map\n");
8926607310bSBenjamin Close 		goto fail;
8936607310bSBenjamin Close 	}
8946607310bSBenjamin Close 
8956607310bSBenjamin Close 	if (kvap != NULL)
8966607310bSBenjamin Close 		*kvap = dma->vaddr;
8976607310bSBenjamin Close 
8986607310bSBenjamin Close 	return 0;
8996607310bSBenjamin Close 
9006607310bSBenjamin Close fail:
9016607310bSBenjamin Close 	wpi_dma_contig_free(dma);
9026607310bSBenjamin Close 	return error;
9036607310bSBenjamin Close }
9046607310bSBenjamin Close 
9056607310bSBenjamin Close static void
9066607310bSBenjamin Close wpi_dma_contig_free(struct wpi_dma_info *dma)
9076607310bSBenjamin Close {
9086607310bSBenjamin Close 	if (dma->tag) {
9096607310bSBenjamin Close 		if (dma->map != NULL) {
91082f1b132SAndrew Thompson 			if (dma->paddr_start != 0) {
9116607310bSBenjamin Close 				bus_dmamap_sync(dma->tag, dma->map,
9126607310bSBenjamin Close 				    BUS_DMASYNC_POSTREAD | BUS_DMASYNC_POSTWRITE);
9136607310bSBenjamin Close 				bus_dmamap_unload(dma->tag, dma->map);
9146607310bSBenjamin Close 			}
91582f1b132SAndrew Thompson 			bus_dmamem_free(dma->tag, &dma->vaddr_start, dma->map);
9166607310bSBenjamin Close 		}
9176607310bSBenjamin Close 		bus_dma_tag_destroy(dma->tag);
9186607310bSBenjamin Close 	}
9196607310bSBenjamin Close }
9206607310bSBenjamin Close 
9216607310bSBenjamin Close /*
9226607310bSBenjamin Close  * Allocate a shared page between host and NIC.
9236607310bSBenjamin Close  */
9246607310bSBenjamin Close static int
9256607310bSBenjamin Close wpi_alloc_shared(struct wpi_softc *sc)
9266607310bSBenjamin Close {
9276607310bSBenjamin Close 	int error;
9286607310bSBenjamin Close 
9296607310bSBenjamin Close 	error = wpi_dma_contig_alloc(sc, &sc->shared_dma,
9306607310bSBenjamin Close 	    (void **)&sc->shared, sizeof (struct wpi_shared),
9316607310bSBenjamin Close 	    PAGE_SIZE,
9326607310bSBenjamin Close 	    BUS_DMA_NOWAIT);
9336607310bSBenjamin Close 
9346607310bSBenjamin Close 	if (error != 0) {
9356607310bSBenjamin Close 		device_printf(sc->sc_dev,
9366607310bSBenjamin Close 		    "could not allocate shared area DMA memory\n");
9376607310bSBenjamin Close 	}
9386607310bSBenjamin Close 
9396607310bSBenjamin Close 	return error;
9406607310bSBenjamin Close }
9416607310bSBenjamin Close 
9426607310bSBenjamin Close static void
9436607310bSBenjamin Close wpi_free_shared(struct wpi_softc *sc)
9446607310bSBenjamin Close {
9456607310bSBenjamin Close 	wpi_dma_contig_free(&sc->shared_dma);
9466607310bSBenjamin Close }
9476607310bSBenjamin Close 
9486607310bSBenjamin Close static int
9496607310bSBenjamin Close wpi_alloc_rx_ring(struct wpi_softc *sc, struct wpi_rx_ring *ring)
9506607310bSBenjamin Close {
9516607310bSBenjamin Close 
9526607310bSBenjamin Close 	int i, error;
9536607310bSBenjamin Close 
9546607310bSBenjamin Close 	ring->cur = 0;
9556607310bSBenjamin Close 
9566607310bSBenjamin Close 	error = wpi_dma_contig_alloc(sc, &ring->desc_dma,
9576607310bSBenjamin Close 	    (void **)&ring->desc, WPI_RX_RING_COUNT * sizeof (uint32_t),
9586607310bSBenjamin Close 	    WPI_RING_DMA_ALIGN, BUS_DMA_NOWAIT);
9596607310bSBenjamin Close 
9606607310bSBenjamin Close 	if (error != 0) {
9616607310bSBenjamin Close 		device_printf(sc->sc_dev,
96282f1b132SAndrew Thompson 		    "%s: could not allocate rx ring DMA memory, error %d\n",
96382f1b132SAndrew Thompson 		    __func__, error);
96482f1b132SAndrew Thompson 		goto fail;
96582f1b132SAndrew Thompson 	}
96682f1b132SAndrew Thompson 
96782f1b132SAndrew Thompson         error = bus_dma_tag_create(bus_get_dma_tag(sc->sc_dev), 1, 0,
96882f1b132SAndrew Thompson 	    BUS_SPACE_MAXADDR_32BIT,
96982f1b132SAndrew Thompson             BUS_SPACE_MAXADDR, NULL, NULL, MJUMPAGESIZE, 1,
97082f1b132SAndrew Thompson             MJUMPAGESIZE, BUS_DMA_NOWAIT, NULL, NULL, &ring->data_dmat);
97182f1b132SAndrew Thompson         if (error != 0) {
97282f1b132SAndrew Thompson                 device_printf(sc->sc_dev,
97382f1b132SAndrew Thompson 		    "%s: bus_dma_tag_create_failed, error %d\n",
97482f1b132SAndrew Thompson 		    __func__, error);
9756607310bSBenjamin Close                 goto fail;
9766607310bSBenjamin Close         }
9776607310bSBenjamin Close 
9786607310bSBenjamin Close 	/*
97982f1b132SAndrew Thompson 	 * Setup Rx buffers.
9806607310bSBenjamin Close 	 */
9816607310bSBenjamin Close 	for (i = 0; i < WPI_RX_RING_COUNT; i++) {
98282f1b132SAndrew Thompson 		struct wpi_rx_data *data = &ring->data[i];
98382f1b132SAndrew Thompson 		struct mbuf *m;
98482f1b132SAndrew Thompson 		bus_addr_t paddr;
9856607310bSBenjamin Close 
98682f1b132SAndrew Thompson 		error = bus_dmamap_create(ring->data_dmat, 0, &data->map);
98782f1b132SAndrew Thompson 		if (error != 0) {
9886607310bSBenjamin Close 			device_printf(sc->sc_dev,
98982f1b132SAndrew Thompson 			    "%s: bus_dmamap_create failed, error %d\n",
99082f1b132SAndrew Thompson 			    __func__, error);
9916607310bSBenjamin Close 			goto fail;
9926607310bSBenjamin Close 		}
993c6499eccSGleb Smirnoff 		m = m_getjcl(M_NOWAIT, MT_DATA, M_PKTHDR, MJUMPAGESIZE);
99482f1b132SAndrew Thompson 		if (m == NULL) {
9956607310bSBenjamin Close 			device_printf(sc->sc_dev,
99682f1b132SAndrew Thompson 			   "%s: could not allocate rx mbuf\n", __func__);
99782f1b132SAndrew Thompson 			error = ENOMEM;
9986607310bSBenjamin Close 			goto fail;
9996607310bSBenjamin Close 		}
100082f1b132SAndrew Thompson 		/* map page */
100182f1b132SAndrew Thompson 		error = bus_dmamap_load(ring->data_dmat, data->map,
100282f1b132SAndrew Thompson 		    mtod(m, caddr_t), MJUMPAGESIZE,
100382f1b132SAndrew Thompson 		    wpi_dma_map_addr, &paddr, BUS_DMA_NOWAIT);
100482f1b132SAndrew Thompson 		if (error != 0 && error != EFBIG) {
100582f1b132SAndrew Thompson 			device_printf(sc->sc_dev,
100682f1b132SAndrew Thompson 			    "%s: bus_dmamap_load failed, error %d\n",
100782f1b132SAndrew Thompson 			    __func__, error);
100882f1b132SAndrew Thompson 			m_freem(m);
100982f1b132SAndrew Thompson 			error = ENOMEM;	/* XXX unique code */
10106607310bSBenjamin Close 			goto fail;
10116607310bSBenjamin Close 		}
101282f1b132SAndrew Thompson 		bus_dmamap_sync(ring->data_dmat, data->map,
10136607310bSBenjamin Close 		    BUS_DMASYNC_PREWRITE);
10146607310bSBenjamin Close 
101582f1b132SAndrew Thompson 		data->m = m;
101682f1b132SAndrew Thompson 		ring->desc[i] = htole32(paddr);
101782f1b132SAndrew Thompson 	}
101882f1b132SAndrew Thompson 	bus_dmamap_sync(ring->desc_dma.tag, ring->desc_dma.map,
101982f1b132SAndrew Thompson 	    BUS_DMASYNC_PREWRITE);
10206607310bSBenjamin Close 	return 0;
10216607310bSBenjamin Close fail:
10226607310bSBenjamin Close 	wpi_free_rx_ring(sc, ring);
10236607310bSBenjamin Close 	return error;
10246607310bSBenjamin Close }
10256607310bSBenjamin Close 
10266607310bSBenjamin Close static void
10276607310bSBenjamin Close wpi_reset_rx_ring(struct wpi_softc *sc, struct wpi_rx_ring *ring)
10286607310bSBenjamin Close {
10296607310bSBenjamin Close 	int ntries;
10306607310bSBenjamin Close 
10316607310bSBenjamin Close 	wpi_mem_lock(sc);
10326607310bSBenjamin Close 
10336607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RX_CONFIG, 0);
10346607310bSBenjamin Close 
10356607310bSBenjamin Close 	for (ntries = 0; ntries < 100; ntries++) {
10366607310bSBenjamin Close 		if (WPI_READ(sc, WPI_RX_STATUS) & WPI_RX_IDLE)
10376607310bSBenjamin Close 			break;
10386607310bSBenjamin Close 		DELAY(10);
10396607310bSBenjamin Close 	}
10406607310bSBenjamin Close 
10416607310bSBenjamin Close 	wpi_mem_unlock(sc);
10426607310bSBenjamin Close 
10436607310bSBenjamin Close #ifdef WPI_DEBUG
10446845408dSAndrew Thompson 	if (ntries == 100 && wpi_debug > 0)
10456607310bSBenjamin Close 		device_printf(sc->sc_dev, "timeout resetting Rx ring\n");
10466607310bSBenjamin Close #endif
10476607310bSBenjamin Close 
10486607310bSBenjamin Close 	ring->cur = 0;
10496607310bSBenjamin Close }
10506607310bSBenjamin Close 
10516607310bSBenjamin Close static void
10526607310bSBenjamin Close wpi_free_rx_ring(struct wpi_softc *sc, struct wpi_rx_ring *ring)
10536607310bSBenjamin Close {
10546607310bSBenjamin Close 	int i;
10556607310bSBenjamin Close 
10566607310bSBenjamin Close 	wpi_dma_contig_free(&ring->desc_dma);
10576607310bSBenjamin Close 
1058a71ad787SBernhard Schmidt 	for (i = 0; i < WPI_RX_RING_COUNT; i++) {
1059a71ad787SBernhard Schmidt 		struct wpi_rx_data *data = &ring->data[i];
1060a71ad787SBernhard Schmidt 
1061a71ad787SBernhard Schmidt 		if (data->m != NULL) {
1062a71ad787SBernhard Schmidt 			bus_dmamap_sync(ring->data_dmat, data->map,
1063a71ad787SBernhard Schmidt 			    BUS_DMASYNC_POSTREAD);
1064a71ad787SBernhard Schmidt 			bus_dmamap_unload(ring->data_dmat, data->map);
1065a71ad787SBernhard Schmidt 			m_freem(data->m);
1066a71ad787SBernhard Schmidt 		}
1067a71ad787SBernhard Schmidt 		if (data->map != NULL)
1068a71ad787SBernhard Schmidt 			bus_dmamap_destroy(ring->data_dmat, data->map);
1069a71ad787SBernhard Schmidt 	}
10706607310bSBenjamin Close }
10716607310bSBenjamin Close 
10726607310bSBenjamin Close static int
10736607310bSBenjamin Close wpi_alloc_tx_ring(struct wpi_softc *sc, struct wpi_tx_ring *ring, int count,
10746607310bSBenjamin Close 	int qid)
10756607310bSBenjamin Close {
10766607310bSBenjamin Close 	struct wpi_tx_data *data;
10776607310bSBenjamin Close 	int i, error;
10786607310bSBenjamin Close 
10796607310bSBenjamin Close 	ring->qid = qid;
10806607310bSBenjamin Close 	ring->count = count;
10816607310bSBenjamin Close 	ring->queued = 0;
10826607310bSBenjamin Close 	ring->cur = 0;
10836607310bSBenjamin Close 	ring->data = NULL;
10846607310bSBenjamin Close 
10856607310bSBenjamin Close 	error = wpi_dma_contig_alloc(sc, &ring->desc_dma,
10866607310bSBenjamin Close 		(void **)&ring->desc, count * sizeof (struct wpi_tx_desc),
10876607310bSBenjamin Close 		WPI_RING_DMA_ALIGN, BUS_DMA_NOWAIT);
10886607310bSBenjamin Close 
10896607310bSBenjamin Close 	if (error != 0) {
10906607310bSBenjamin Close 	    device_printf(sc->sc_dev, "could not allocate tx dma memory\n");
10916607310bSBenjamin Close 	    goto fail;
10926607310bSBenjamin Close 	}
10936607310bSBenjamin Close 
10946607310bSBenjamin Close 	/* update shared page with ring's base address */
10956607310bSBenjamin Close 	sc->shared->txbase[qid] = htole32(ring->desc_dma.paddr);
10966607310bSBenjamin Close 
10976607310bSBenjamin Close 	error = wpi_dma_contig_alloc(sc, &ring->cmd_dma, (void **)&ring->cmd,
10986607310bSBenjamin Close 		count * sizeof (struct wpi_tx_cmd), WPI_RING_DMA_ALIGN,
10996607310bSBenjamin Close 		BUS_DMA_NOWAIT);
11006607310bSBenjamin Close 
11016607310bSBenjamin Close 	if (error != 0) {
11026607310bSBenjamin Close 		device_printf(sc->sc_dev,
11036607310bSBenjamin Close 		    "could not allocate tx command DMA memory\n");
11046607310bSBenjamin Close 		goto fail;
11056607310bSBenjamin Close 	}
11066607310bSBenjamin Close 
11076607310bSBenjamin Close 	ring->data = malloc(count * sizeof (struct wpi_tx_data), M_DEVBUF,
11086607310bSBenjamin Close 	    M_NOWAIT | M_ZERO);
11096607310bSBenjamin Close 	if (ring->data == NULL) {
11106607310bSBenjamin Close 		device_printf(sc->sc_dev,
11116607310bSBenjamin Close 		    "could not allocate tx data slots\n");
11126607310bSBenjamin Close 		goto fail;
11136607310bSBenjamin Close 	}
11146607310bSBenjamin Close 
11156607310bSBenjamin Close 	error = bus_dma_tag_create(bus_get_dma_tag(sc->sc_dev), 1, 0,
11166607310bSBenjamin Close 	    BUS_SPACE_MAXADDR_32BIT, BUS_SPACE_MAXADDR, NULL, NULL, MCLBYTES,
11176607310bSBenjamin Close 	    WPI_MAX_SCATTER - 1, MCLBYTES, BUS_DMA_NOWAIT, NULL, NULL,
11186607310bSBenjamin Close 	    &ring->data_dmat);
11196607310bSBenjamin Close 	if (error != 0) {
11206607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not create data DMA tag\n");
11216607310bSBenjamin Close 		goto fail;
11226607310bSBenjamin Close 	}
11236607310bSBenjamin Close 
11246607310bSBenjamin Close 	for (i = 0; i < count; i++) {
11256607310bSBenjamin Close 		data = &ring->data[i];
11266607310bSBenjamin Close 
11276607310bSBenjamin Close 		error = bus_dmamap_create(ring->data_dmat, 0, &data->map);
11286607310bSBenjamin Close 		if (error != 0) {
11296607310bSBenjamin Close 			device_printf(sc->sc_dev,
11306607310bSBenjamin Close 			    "could not create tx buf DMA map\n");
11316607310bSBenjamin Close 			goto fail;
11326607310bSBenjamin Close 		}
11336607310bSBenjamin Close 		bus_dmamap_sync(ring->data_dmat, data->map,
11346607310bSBenjamin Close 		    BUS_DMASYNC_PREWRITE);
11356607310bSBenjamin Close 	}
11366607310bSBenjamin Close 
11376607310bSBenjamin Close 	return 0;
11386607310bSBenjamin Close 
113982f1b132SAndrew Thompson fail:
114082f1b132SAndrew Thompson 	wpi_free_tx_ring(sc, ring);
11416607310bSBenjamin Close 	return error;
11426607310bSBenjamin Close }
11436607310bSBenjamin Close 
11446607310bSBenjamin Close static void
11456607310bSBenjamin Close wpi_reset_tx_ring(struct wpi_softc *sc, struct wpi_tx_ring *ring)
11466607310bSBenjamin Close {
11476607310bSBenjamin Close 	struct wpi_tx_data *data;
11486607310bSBenjamin Close 	int i, ntries;
11496607310bSBenjamin Close 
11506607310bSBenjamin Close 	wpi_mem_lock(sc);
11516607310bSBenjamin Close 
11526607310bSBenjamin Close 	WPI_WRITE(sc, WPI_TX_CONFIG(ring->qid), 0);
11536607310bSBenjamin Close 	for (ntries = 0; ntries < 100; ntries++) {
11546607310bSBenjamin Close 		if (WPI_READ(sc, WPI_TX_STATUS) & WPI_TX_IDLE(ring->qid))
11556607310bSBenjamin Close 			break;
11566607310bSBenjamin Close 		DELAY(10);
11576607310bSBenjamin Close 	}
11586607310bSBenjamin Close #ifdef WPI_DEBUG
11596845408dSAndrew Thompson 	if (ntries == 100 && wpi_debug > 0)
11606607310bSBenjamin Close 		device_printf(sc->sc_dev, "timeout resetting Tx ring %d\n",
11616607310bSBenjamin Close 		    ring->qid);
11626607310bSBenjamin Close #endif
11636607310bSBenjamin Close 	wpi_mem_unlock(sc);
11646607310bSBenjamin Close 
11656607310bSBenjamin Close 	for (i = 0; i < ring->count; i++) {
11666607310bSBenjamin Close 		data = &ring->data[i];
11676607310bSBenjamin Close 
11686607310bSBenjamin Close 		if (data->m != NULL) {
11696607310bSBenjamin Close 			bus_dmamap_unload(ring->data_dmat, data->map);
11706607310bSBenjamin Close 			m_freem(data->m);
11716607310bSBenjamin Close 			data->m = NULL;
11726607310bSBenjamin Close 		}
11736607310bSBenjamin Close 	}
11746607310bSBenjamin Close 
11756607310bSBenjamin Close 	ring->queued = 0;
11766607310bSBenjamin Close 	ring->cur = 0;
11776607310bSBenjamin Close }
11786607310bSBenjamin Close 
11796607310bSBenjamin Close static void
11806607310bSBenjamin Close wpi_free_tx_ring(struct wpi_softc *sc, struct wpi_tx_ring *ring)
11816607310bSBenjamin Close {
11826607310bSBenjamin Close 	struct wpi_tx_data *data;
11836607310bSBenjamin Close 	int i;
11846607310bSBenjamin Close 
11856607310bSBenjamin Close 	wpi_dma_contig_free(&ring->desc_dma);
11866607310bSBenjamin Close 	wpi_dma_contig_free(&ring->cmd_dma);
11876607310bSBenjamin Close 
11886607310bSBenjamin Close 	if (ring->data != NULL) {
11896607310bSBenjamin Close 		for (i = 0; i < ring->count; i++) {
11906607310bSBenjamin Close 			data = &ring->data[i];
11916607310bSBenjamin Close 
11926607310bSBenjamin Close 			if (data->m != NULL) {
11936607310bSBenjamin Close 				bus_dmamap_sync(ring->data_dmat, data->map,
11946607310bSBenjamin Close 				    BUS_DMASYNC_POSTWRITE);
11956607310bSBenjamin Close 				bus_dmamap_unload(ring->data_dmat, data->map);
11966607310bSBenjamin Close 				m_freem(data->m);
11976607310bSBenjamin Close 				data->m = NULL;
11986607310bSBenjamin Close 			}
11996607310bSBenjamin Close 		}
12006607310bSBenjamin Close 		free(ring->data, M_DEVBUF);
12016607310bSBenjamin Close 	}
12026607310bSBenjamin Close 
12036607310bSBenjamin Close 	if (ring->data_dmat != NULL)
12046607310bSBenjamin Close 		bus_dma_tag_destroy(ring->data_dmat);
12056607310bSBenjamin Close }
12066607310bSBenjamin Close 
12076607310bSBenjamin Close static int
12086607310bSBenjamin Close wpi_shutdown(device_t dev)
12096607310bSBenjamin Close {
12106607310bSBenjamin Close 	struct wpi_softc *sc = device_get_softc(dev);
12116607310bSBenjamin Close 
12126607310bSBenjamin Close 	WPI_LOCK(sc);
12136607310bSBenjamin Close 	wpi_stop_locked(sc);
12146607310bSBenjamin Close 	wpi_unload_firmware(sc);
12156607310bSBenjamin Close 	WPI_UNLOCK(sc);
12166607310bSBenjamin Close 
12176607310bSBenjamin Close 	return 0;
12186607310bSBenjamin Close }
12196607310bSBenjamin Close 
12206607310bSBenjamin Close static int
12216607310bSBenjamin Close wpi_suspend(device_t dev)
12226607310bSBenjamin Close {
12236607310bSBenjamin Close 	struct wpi_softc *sc = device_get_softc(dev);
1224ada977b1SBernhard Schmidt 	struct ieee80211com *ic = sc->sc_ifp->if_l2com;
12256607310bSBenjamin Close 
1226ada977b1SBernhard Schmidt 	ieee80211_suspend_all(ic);
12276607310bSBenjamin Close 	return 0;
12286607310bSBenjamin Close }
12296607310bSBenjamin Close 
12306607310bSBenjamin Close static int
12316607310bSBenjamin Close wpi_resume(device_t dev)
12326607310bSBenjamin Close {
12336607310bSBenjamin Close 	struct wpi_softc *sc = device_get_softc(dev);
1234ada977b1SBernhard Schmidt 	struct ieee80211com *ic = sc->sc_ifp->if_l2com;
12356607310bSBenjamin Close 
12366607310bSBenjamin Close 	pci_write_config(dev, 0x41, 0, 1);
12376607310bSBenjamin Close 
1238ada977b1SBernhard Schmidt 	ieee80211_resume_all(ic);
12396607310bSBenjamin Close 	return 0;
12406607310bSBenjamin Close }
12416607310bSBenjamin Close 
12426607310bSBenjamin Close /**
12436607310bSBenjamin Close  * Called by net80211 when ever there is a change to 80211 state machine
12446607310bSBenjamin Close  */
12456607310bSBenjamin Close static int
1246b032f27cSSam Leffler wpi_newstate(struct ieee80211vap *vap, enum ieee80211_state nstate, int arg)
12476607310bSBenjamin Close {
1248b032f27cSSam Leffler 	struct wpi_vap *wvp = WPI_VAP(vap);
1249b032f27cSSam Leffler 	struct ieee80211com *ic = vap->iv_ic;
12506607310bSBenjamin Close 	struct ifnet *ifp = ic->ic_ifp;
12516607310bSBenjamin Close 	struct wpi_softc *sc = ifp->if_softc;
1252b032f27cSSam Leffler 	int error;
12536607310bSBenjamin Close 
1254b032f27cSSam Leffler 	DPRINTF(("%s: %s -> %s flags 0x%x\n", __func__,
1255b032f27cSSam Leffler 		ieee80211_state_name[vap->iv_state],
1256b032f27cSSam Leffler 		ieee80211_state_name[nstate], sc->flags));
12576607310bSBenjamin Close 
12585efea30fSAndrew Thompson 	IEEE80211_UNLOCK(ic);
12595efea30fSAndrew Thompson 	WPI_LOCK(sc);
12603934c8a5SBernhard Schmidt 	if (nstate == IEEE80211_S_SCAN && vap->iv_state != IEEE80211_S_INIT) {
12613934c8a5SBernhard Schmidt 		/*
12623934c8a5SBernhard Schmidt 		 * On !INIT -> SCAN transitions, we need to clear any possible
12633934c8a5SBernhard Schmidt 		 * knowledge about associations.
12643934c8a5SBernhard Schmidt 		 */
12653934c8a5SBernhard Schmidt 		error = wpi_config(sc);
12663934c8a5SBernhard Schmidt 		if (error != 0) {
12673934c8a5SBernhard Schmidt 			device_printf(sc->sc_dev,
12683934c8a5SBernhard Schmidt 			    "%s: device config failed, error %d\n",
12693934c8a5SBernhard Schmidt 			    __func__, error);
12703934c8a5SBernhard Schmidt 		}
12713934c8a5SBernhard Schmidt 	}
12723934c8a5SBernhard Schmidt 	if (nstate == IEEE80211_S_AUTH ||
12733934c8a5SBernhard Schmidt 	    (nstate == IEEE80211_S_ASSOC && vap->iv_state == IEEE80211_S_RUN)) {
12743934c8a5SBernhard Schmidt 		/*
12753934c8a5SBernhard Schmidt 		 * The node must be registered in the firmware before auth.
12763934c8a5SBernhard Schmidt 		 * Also the associd must be cleared on RUN -> ASSOC
12773934c8a5SBernhard Schmidt 		 * transitions.
12783934c8a5SBernhard Schmidt 		 */
12795efea30fSAndrew Thompson 		error = wpi_auth(sc, vap);
12805efea30fSAndrew Thompson 		if (error != 0) {
12815efea30fSAndrew Thompson 			device_printf(sc->sc_dev,
12825efea30fSAndrew Thompson 			    "%s: could not move to auth state, error %d\n",
12835efea30fSAndrew Thompson 			    __func__, error);
12845efea30fSAndrew Thompson 		}
12856607310bSBenjamin Close 	}
1286b032f27cSSam Leffler 	if (nstate == IEEE80211_S_RUN && vap->iv_state != IEEE80211_S_RUN) {
12875efea30fSAndrew Thompson 		error = wpi_run(sc, vap);
12885efea30fSAndrew Thompson 		if (error != 0) {
12895efea30fSAndrew Thompson 			device_printf(sc->sc_dev,
12905efea30fSAndrew Thompson 			    "%s: could not move to run state, error %d\n",
12915efea30fSAndrew Thompson 			    __func__, error);
12925efea30fSAndrew Thompson 		}
12936607310bSBenjamin Close 	}
1294b032f27cSSam Leffler 	if (nstate == IEEE80211_S_RUN) {
1295b032f27cSSam Leffler 		/* RUN -> RUN transition; just restart the timers */
1296b032f27cSSam Leffler 		wpi_calib_timeout(sc);
1297b032f27cSSam Leffler 		/* XXX split out rate control timer */
1298b032f27cSSam Leffler 	}
12995efea30fSAndrew Thompson 	WPI_UNLOCK(sc);
13005efea30fSAndrew Thompson 	IEEE80211_LOCK(ic);
1301b032f27cSSam Leffler 	return wvp->newstate(vap, nstate, arg);
13026607310bSBenjamin Close }
13036607310bSBenjamin Close 
13046607310bSBenjamin Close /*
13056607310bSBenjamin Close  * Grab exclusive access to NIC memory.
13066607310bSBenjamin Close  */
13076607310bSBenjamin Close static void
13086607310bSBenjamin Close wpi_mem_lock(struct wpi_softc *sc)
13096607310bSBenjamin Close {
13106607310bSBenjamin Close 	int ntries;
13116607310bSBenjamin Close 	uint32_t tmp;
13126607310bSBenjamin Close 
13136607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_GPIO_CTL);
13146607310bSBenjamin Close 	WPI_WRITE(sc, WPI_GPIO_CTL, tmp | WPI_GPIO_MAC);
13156607310bSBenjamin Close 
13166607310bSBenjamin Close 	/* spin until we actually get the lock */
13176607310bSBenjamin Close 	for (ntries = 0; ntries < 100; ntries++) {
13186607310bSBenjamin Close 		if ((WPI_READ(sc, WPI_GPIO_CTL) &
13196607310bSBenjamin Close 			(WPI_GPIO_CLOCK | WPI_GPIO_SLEEP)) == WPI_GPIO_CLOCK)
13206607310bSBenjamin Close 			break;
13216607310bSBenjamin Close 		DELAY(10);
13226607310bSBenjamin Close 	}
13236607310bSBenjamin Close 	if (ntries == 100)
13246607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not lock memory\n");
13256607310bSBenjamin Close }
13266607310bSBenjamin Close 
13276607310bSBenjamin Close /*
13286607310bSBenjamin Close  * Release lock on NIC memory.
13296607310bSBenjamin Close  */
13306607310bSBenjamin Close static void
13316607310bSBenjamin Close wpi_mem_unlock(struct wpi_softc *sc)
13326607310bSBenjamin Close {
13336607310bSBenjamin Close 	uint32_t tmp = WPI_READ(sc, WPI_GPIO_CTL);
13346607310bSBenjamin Close 	WPI_WRITE(sc, WPI_GPIO_CTL, tmp & ~WPI_GPIO_MAC);
13356607310bSBenjamin Close }
13366607310bSBenjamin Close 
13376607310bSBenjamin Close static uint32_t
13386607310bSBenjamin Close wpi_mem_read(struct wpi_softc *sc, uint16_t addr)
13396607310bSBenjamin Close {
13406607310bSBenjamin Close 	WPI_WRITE(sc, WPI_READ_MEM_ADDR, WPI_MEM_4 | addr);
13416607310bSBenjamin Close 	return WPI_READ(sc, WPI_READ_MEM_DATA);
13426607310bSBenjamin Close }
13436607310bSBenjamin Close 
13446607310bSBenjamin Close static void
13456607310bSBenjamin Close wpi_mem_write(struct wpi_softc *sc, uint16_t addr, uint32_t data)
13466607310bSBenjamin Close {
13476607310bSBenjamin Close 	WPI_WRITE(sc, WPI_WRITE_MEM_ADDR, WPI_MEM_4 | addr);
13486607310bSBenjamin Close 	WPI_WRITE(sc, WPI_WRITE_MEM_DATA, data);
13496607310bSBenjamin Close }
13506607310bSBenjamin Close 
13516607310bSBenjamin Close static void
13526607310bSBenjamin Close wpi_mem_write_region_4(struct wpi_softc *sc, uint16_t addr,
13536607310bSBenjamin Close     const uint32_t *data, int wlen)
13546607310bSBenjamin Close {
13556607310bSBenjamin Close 	for (; wlen > 0; wlen--, data++, addr+=4)
13566607310bSBenjamin Close 		wpi_mem_write(sc, addr, *data);
13576607310bSBenjamin Close }
13586607310bSBenjamin Close 
13596607310bSBenjamin Close /*
13606607310bSBenjamin Close  * Read data from the EEPROM.  We access EEPROM through the MAC instead of
13616607310bSBenjamin Close  * using the traditional bit-bang method. Data is read up until len bytes have
13626607310bSBenjamin Close  * been obtained.
13636607310bSBenjamin Close  */
13646607310bSBenjamin Close static uint16_t
13656607310bSBenjamin Close wpi_read_prom_data(struct wpi_softc *sc, uint32_t addr, void *data, int len)
13666607310bSBenjamin Close {
13676607310bSBenjamin Close 	int ntries;
13686607310bSBenjamin Close 	uint32_t val;
13696607310bSBenjamin Close 	uint8_t *out = data;
13706607310bSBenjamin Close 
13716607310bSBenjamin Close 	wpi_mem_lock(sc);
13726607310bSBenjamin Close 
13736607310bSBenjamin Close 	for (; len > 0; len -= 2, addr++) {
13746607310bSBenjamin Close 		WPI_WRITE(sc, WPI_EEPROM_CTL, addr << 2);
13756607310bSBenjamin Close 
13766607310bSBenjamin Close 		for (ntries = 0; ntries < 10; ntries++) {
13776607310bSBenjamin Close 			if ((val = WPI_READ(sc, WPI_EEPROM_CTL)) & WPI_EEPROM_READY)
13786607310bSBenjamin Close 				break;
13796607310bSBenjamin Close 			DELAY(5);
13806607310bSBenjamin Close 		}
13816607310bSBenjamin Close 
13826607310bSBenjamin Close 		if (ntries == 10) {
13836607310bSBenjamin Close 			device_printf(sc->sc_dev, "could not read EEPROM\n");
13846607310bSBenjamin Close 			return ETIMEDOUT;
13856607310bSBenjamin Close 		}
13866607310bSBenjamin Close 
13876607310bSBenjamin Close 		*out++= val >> 16;
13886607310bSBenjamin Close 		if (len > 1)
13896607310bSBenjamin Close 			*out ++= val >> 24;
13906607310bSBenjamin Close 	}
13916607310bSBenjamin Close 
13926607310bSBenjamin Close 	wpi_mem_unlock(sc);
13936607310bSBenjamin Close 
13946607310bSBenjamin Close 	return 0;
13956607310bSBenjamin Close }
13966607310bSBenjamin Close 
13976607310bSBenjamin Close /*
13986607310bSBenjamin Close  * The firmware text and data segments are transferred to the NIC using DMA.
13996607310bSBenjamin Close  * The driver just copies the firmware into DMA-safe memory and tells the NIC
14006607310bSBenjamin Close  * where to find it.  Once the NIC has copied the firmware into its internal
14016607310bSBenjamin Close  * memory, we can free our local copy in the driver.
14026607310bSBenjamin Close  */
14036607310bSBenjamin Close static int
14046607310bSBenjamin Close wpi_load_microcode(struct wpi_softc *sc, const uint8_t *fw, int size)
14056607310bSBenjamin Close {
14066607310bSBenjamin Close 	int error, ntries;
14076607310bSBenjamin Close 
14086607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_HW,("Loading microcode  size 0x%x\n", size));
14096607310bSBenjamin Close 
14106607310bSBenjamin Close 	size /= sizeof(uint32_t);
14116607310bSBenjamin Close 
14126607310bSBenjamin Close 	wpi_mem_lock(sc);
14136607310bSBenjamin Close 
14146607310bSBenjamin Close 	wpi_mem_write_region_4(sc, WPI_MEM_UCODE_BASE,
14156607310bSBenjamin Close 	    (const uint32_t *)fw, size);
14166607310bSBenjamin Close 
14176607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_UCODE_SRC, 0);
14186607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_UCODE_DST, WPI_FW_TEXT);
14196607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_UCODE_SIZE, size);
14206607310bSBenjamin Close 
14216607310bSBenjamin Close 	/* run microcode */
14226607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_UCODE_CTL, WPI_UC_RUN);
14236607310bSBenjamin Close 
14246607310bSBenjamin Close 	/* wait while the adapter is busy copying the firmware */
14256607310bSBenjamin Close 	for (error = 0, ntries = 0; ntries < 1000; ntries++) {
14266607310bSBenjamin Close 		uint32_t status = WPI_READ(sc, WPI_TX_STATUS);
14276607310bSBenjamin Close 		DPRINTFN(WPI_DEBUG_HW,
14286607310bSBenjamin Close 		    ("firmware status=0x%x, val=0x%x, result=0x%x\n", status,
14296607310bSBenjamin Close 		     WPI_TX_IDLE(6), status & WPI_TX_IDLE(6)));
14306607310bSBenjamin Close 		if (status & WPI_TX_IDLE(6)) {
14316607310bSBenjamin Close 			DPRINTFN(WPI_DEBUG_HW,
14326607310bSBenjamin Close 			    ("Status Match! - ntries = %d\n", ntries));
14336607310bSBenjamin Close 			break;
14346607310bSBenjamin Close 		}
14356607310bSBenjamin Close 		DELAY(10);
14366607310bSBenjamin Close 	}
14376607310bSBenjamin Close 	if (ntries == 1000) {
14386607310bSBenjamin Close 		device_printf(sc->sc_dev, "timeout transferring firmware\n");
14396607310bSBenjamin Close 		error = ETIMEDOUT;
14406607310bSBenjamin Close 	}
14416607310bSBenjamin Close 
14426607310bSBenjamin Close 	/* start the microcode executing */
14436607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_UCODE_CTL, WPI_UC_ENABLE);
14446607310bSBenjamin Close 
14456607310bSBenjamin Close 	wpi_mem_unlock(sc);
14466607310bSBenjamin Close 
14476607310bSBenjamin Close 	return (error);
14486607310bSBenjamin Close }
14496607310bSBenjamin Close 
14506607310bSBenjamin Close static void
14516607310bSBenjamin Close wpi_rx_intr(struct wpi_softc *sc, struct wpi_rx_desc *desc,
14526607310bSBenjamin Close 	struct wpi_rx_data *data)
14536607310bSBenjamin Close {
1454b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
1455b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
14566607310bSBenjamin Close 	struct wpi_rx_ring *ring = &sc->rxq;
14576607310bSBenjamin Close 	struct wpi_rx_stat *stat;
14586607310bSBenjamin Close 	struct wpi_rx_head *head;
14596607310bSBenjamin Close 	struct wpi_rx_tail *tail;
14606607310bSBenjamin Close 	struct ieee80211_node *ni;
14616607310bSBenjamin Close 	struct mbuf *m, *mnew;
146282f1b132SAndrew Thompson 	bus_addr_t paddr;
146382f1b132SAndrew Thompson 	int error;
14646607310bSBenjamin Close 
14656607310bSBenjamin Close 	stat = (struct wpi_rx_stat *)(desc + 1);
14666607310bSBenjamin Close 
14676607310bSBenjamin Close 	if (stat->len > WPI_STAT_MAXLEN) {
14686607310bSBenjamin Close 		device_printf(sc->sc_dev, "invalid rx statistic header\n");
14696607310bSBenjamin Close 		ifp->if_ierrors++;
14706607310bSBenjamin Close 		return;
14716607310bSBenjamin Close 	}
14726607310bSBenjamin Close 
1473a71ad787SBernhard Schmidt 	bus_dmamap_sync(ring->data_dmat, data->map, BUS_DMASYNC_POSTREAD);
14746607310bSBenjamin Close 	head = (struct wpi_rx_head *)((caddr_t)(stat + 1) + stat->len);
14756607310bSBenjamin Close 	tail = (struct wpi_rx_tail *)((caddr_t)(head + 1) + le16toh(head->len));
14766607310bSBenjamin Close 
14776607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_RX, ("rx intr: idx=%d len=%d stat len=%d rssi=%d "
14786607310bSBenjamin Close 	    "rate=%x chan=%d tstamp=%ju\n", ring->cur, le32toh(desc->len),
14796607310bSBenjamin Close 	    le16toh(head->len), (int8_t)stat->rssi, head->rate, head->chan,
14806607310bSBenjamin Close 	    (uintmax_t)le64toh(tail->tstamp)));
14816607310bSBenjamin Close 
1482fcec677dSJuli Mallett 	/* discard Rx frames with bad CRC early */
1483fcec677dSJuli Mallett 	if ((le32toh(tail->flags) & WPI_RX_NOERROR) != WPI_RX_NOERROR) {
1484fcec677dSJuli Mallett 		DPRINTFN(WPI_DEBUG_RX, ("%s: rx flags error %x\n", __func__,
1485fcec677dSJuli Mallett 		    le32toh(tail->flags)));
1486fcec677dSJuli Mallett 		ifp->if_ierrors++;
1487fcec677dSJuli Mallett 		return;
1488fcec677dSJuli Mallett 	}
1489fcec677dSJuli Mallett 	if (le16toh(head->len) < sizeof (struct ieee80211_frame)) {
1490fcec677dSJuli Mallett 		DPRINTFN(WPI_DEBUG_RX, ("%s: frame too short: %d\n", __func__,
1491fcec677dSJuli Mallett 		    le16toh(head->len)));
1492fcec677dSJuli Mallett 		ifp->if_ierrors++;
1493fcec677dSJuli Mallett 		return;
1494fcec677dSJuli Mallett 	}
1495fcec677dSJuli Mallett 
149682f1b132SAndrew Thompson 	/* XXX don't need mbuf, just dma buffer */
1497c6499eccSGleb Smirnoff 	mnew = m_getjcl(M_NOWAIT, MT_DATA, M_PKTHDR, MJUMPAGESIZE);
149882f1b132SAndrew Thompson 	if (mnew == NULL) {
149982f1b132SAndrew Thompson 		DPRINTFN(WPI_DEBUG_RX, ("%s: no mbuf to restock ring\n",
150082f1b132SAndrew Thompson 		    __func__));
150182f1b132SAndrew Thompson 		ifp->if_ierrors++;
150282f1b132SAndrew Thompson 		return;
150382f1b132SAndrew Thompson 	}
1504a71ad787SBernhard Schmidt 	bus_dmamap_unload(ring->data_dmat, data->map);
1505a71ad787SBernhard Schmidt 
150682f1b132SAndrew Thompson 	error = bus_dmamap_load(ring->data_dmat, data->map,
150782f1b132SAndrew Thompson 	    mtod(mnew, caddr_t), MJUMPAGESIZE,
150882f1b132SAndrew Thompson 	    wpi_dma_map_addr, &paddr, BUS_DMA_NOWAIT);
150982f1b132SAndrew Thompson 	if (error != 0 && error != EFBIG) {
151082f1b132SAndrew Thompson 		device_printf(sc->sc_dev,
151182f1b132SAndrew Thompson 		    "%s: bus_dmamap_load failed, error %d\n", __func__, error);
151282f1b132SAndrew Thompson 		m_freem(mnew);
151382f1b132SAndrew Thompson 		ifp->if_ierrors++;
151482f1b132SAndrew Thompson 		return;
151582f1b132SAndrew Thompson 	}
151682f1b132SAndrew Thompson 	bus_dmamap_sync(ring->data_dmat, data->map, BUS_DMASYNC_PREWRITE);
15176607310bSBenjamin Close 
151882f1b132SAndrew Thompson 	/* finalize mbuf and swap in new one */
151982f1b132SAndrew Thompson 	m = data->m;
15206607310bSBenjamin Close 	m->m_pkthdr.rcvif = ifp;
15216607310bSBenjamin Close 	m->m_data = (caddr_t)(head + 1);
15226607310bSBenjamin Close 	m->m_pkthdr.len = m->m_len = le16toh(head->len);
15236607310bSBenjamin Close 
15246607310bSBenjamin Close 	data->m = mnew;
15256607310bSBenjamin Close 	/* update Rx descriptor */
152682f1b132SAndrew Thompson 	ring->desc[ring->cur] = htole32(paddr);
15276607310bSBenjamin Close 
15285463c4a4SSam Leffler 	if (ieee80211_radiotap_active(ic)) {
15296607310bSBenjamin Close 		struct wpi_rx_radiotap_header *tap = &sc->sc_rxtap;
15306607310bSBenjamin Close 
15316607310bSBenjamin Close 		tap->wr_flags = 0;
15326607310bSBenjamin Close 		tap->wr_chan_freq =
15336607310bSBenjamin Close 			htole16(ic->ic_channels[head->chan].ic_freq);
15346607310bSBenjamin Close 		tap->wr_chan_flags =
15356607310bSBenjamin Close 			htole16(ic->ic_channels[head->chan].ic_flags);
15366607310bSBenjamin Close 		tap->wr_dbm_antsignal = (int8_t)(stat->rssi - WPI_RSSI_OFFSET);
15376607310bSBenjamin Close 		tap->wr_dbm_antnoise = (int8_t)le16toh(stat->noise);
15386607310bSBenjamin Close 		tap->wr_tsft = tail->tstamp;
15396607310bSBenjamin Close 		tap->wr_antenna = (le16toh(head->flags) >> 4) & 0xf;
15406607310bSBenjamin Close 		switch (head->rate) {
15416607310bSBenjamin Close 		/* CCK rates */
15426607310bSBenjamin Close 		case  10: tap->wr_rate =   2; break;
15436607310bSBenjamin Close 		case  20: tap->wr_rate =   4; break;
15446607310bSBenjamin Close 		case  55: tap->wr_rate =  11; break;
15456607310bSBenjamin Close 		case 110: tap->wr_rate =  22; break;
15466607310bSBenjamin Close 		/* OFDM rates */
15476607310bSBenjamin Close 		case 0xd: tap->wr_rate =  12; break;
15486607310bSBenjamin Close 		case 0xf: tap->wr_rate =  18; break;
15496607310bSBenjamin Close 		case 0x5: tap->wr_rate =  24; break;
15506607310bSBenjamin Close 		case 0x7: tap->wr_rate =  36; break;
15516607310bSBenjamin Close 		case 0x9: tap->wr_rate =  48; break;
15526607310bSBenjamin Close 		case 0xb: tap->wr_rate =  72; break;
15536607310bSBenjamin Close 		case 0x1: tap->wr_rate =  96; break;
15546607310bSBenjamin Close 		case 0x3: tap->wr_rate = 108; break;
15556607310bSBenjamin Close 		/* unknown rate: should not happen */
15566607310bSBenjamin Close 		default:  tap->wr_rate =   0;
15576607310bSBenjamin Close 		}
15586607310bSBenjamin Close 		if (le16toh(head->flags) & 0x4)
15596607310bSBenjamin Close 			tap->wr_flags |= IEEE80211_RADIOTAP_F_SHORTPRE;
15606607310bSBenjamin Close 	}
15616607310bSBenjamin Close 
15626607310bSBenjamin Close 	WPI_UNLOCK(sc);
15636607310bSBenjamin Close 
156482f1b132SAndrew Thompson 	ni = ieee80211_find_rxnode(ic, mtod(m, struct ieee80211_frame_min *));
1565b032f27cSSam Leffler 	if (ni != NULL) {
15665463c4a4SSam Leffler 		(void) ieee80211_input(ni, m, stat->rssi, 0);
15676607310bSBenjamin Close 		ieee80211_free_node(ni);
1568b032f27cSSam Leffler 	} else
15695463c4a4SSam Leffler 		(void) ieee80211_input_all(ic, m, stat->rssi, 0);
1570b032f27cSSam Leffler 
15716607310bSBenjamin Close 	WPI_LOCK(sc);
15726607310bSBenjamin Close }
15736607310bSBenjamin Close 
15746607310bSBenjamin Close static void
15756607310bSBenjamin Close wpi_tx_intr(struct wpi_softc *sc, struct wpi_rx_desc *desc)
15766607310bSBenjamin Close {
1577b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
15786607310bSBenjamin Close 	struct wpi_tx_ring *ring = &sc->txq[desc->qid & 0x3];
15796607310bSBenjamin Close 	struct wpi_tx_data *txdata = &ring->data[desc->idx];
15806607310bSBenjamin Close 	struct wpi_tx_stat *stat = (struct wpi_tx_stat *)(desc + 1);
1581b6108616SRui Paulo 	struct ieee80211_node *ni = txdata->ni;
1582b6108616SRui Paulo 	struct ieee80211vap *vap = ni->ni_vap;
1583b6108616SRui Paulo 	int retrycnt = 0;
15846607310bSBenjamin Close 
15856607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_TX, ("tx done: qid=%d idx=%d retries=%d nkill=%d "
15866607310bSBenjamin Close 	    "rate=%x duration=%d status=%x\n", desc->qid, desc->idx,
15876607310bSBenjamin Close 	    stat->ntries, stat->nkill, stat->rate, le32toh(stat->duration),
15886607310bSBenjamin Close 	    le32toh(stat->status)));
15896607310bSBenjamin Close 
15906607310bSBenjamin Close 	/*
15916607310bSBenjamin Close 	 * Update rate control statistics for the node.
15926607310bSBenjamin Close 	 * XXX we should not count mgmt frames since they're always sent at
15936607310bSBenjamin Close 	 * the lowest available bit-rate.
15946607310bSBenjamin Close 	 * XXX frames w/o ACK shouldn't be used either
15956607310bSBenjamin Close 	 */
15966607310bSBenjamin Close 	if (stat->ntries > 0) {
1597607158ebSJuli Mallett 		DPRINTFN(WPI_DEBUG_TX, ("%d retries\n", stat->ntries));
1598b6108616SRui Paulo 		retrycnt = 1;
15996607310bSBenjamin Close 	}
1600b6108616SRui Paulo 	ieee80211_ratectl_tx_complete(vap, ni, IEEE80211_RATECTL_TX_SUCCESS,
1601b6108616SRui Paulo 	    &retrycnt, NULL);
16026607310bSBenjamin Close 
16036607310bSBenjamin Close 	/* XXX oerrors should only count errors !maxtries */
16046607310bSBenjamin Close 	if ((le32toh(stat->status) & 0xff) != 1)
16056607310bSBenjamin Close 		ifp->if_oerrors++;
16066607310bSBenjamin Close 	else
16076607310bSBenjamin Close 		ifp->if_opackets++;
16086607310bSBenjamin Close 
16096607310bSBenjamin Close 	bus_dmamap_sync(ring->data_dmat, txdata->map, BUS_DMASYNC_POSTWRITE);
16106607310bSBenjamin Close 	bus_dmamap_unload(ring->data_dmat, txdata->map);
16116607310bSBenjamin Close 	/* XXX handle M_TXCB? */
16126607310bSBenjamin Close 	m_freem(txdata->m);
16136607310bSBenjamin Close 	txdata->m = NULL;
16146607310bSBenjamin Close 	ieee80211_free_node(txdata->ni);
16156607310bSBenjamin Close 	txdata->ni = NULL;
16166607310bSBenjamin Close 
16176607310bSBenjamin Close 	ring->queued--;
16186607310bSBenjamin Close 
16196607310bSBenjamin Close 	sc->sc_tx_timer = 0;
16206607310bSBenjamin Close 	ifp->if_drv_flags &= ~IFF_DRV_OACTIVE;
1621b032f27cSSam Leffler 	wpi_start_locked(ifp);
16226607310bSBenjamin Close }
16236607310bSBenjamin Close 
16246607310bSBenjamin Close static void
16256607310bSBenjamin Close wpi_cmd_intr(struct wpi_softc *sc, struct wpi_rx_desc *desc)
16266607310bSBenjamin Close {
16276607310bSBenjamin Close 	struct wpi_tx_ring *ring = &sc->cmdq;
16286607310bSBenjamin Close 	struct wpi_tx_data *data;
16296607310bSBenjamin Close 
16306607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_CMD, ("cmd notification qid=%x idx=%d flags=%x "
16316607310bSBenjamin Close 				 "type=%s len=%d\n", desc->qid, desc->idx,
16326607310bSBenjamin Close 				 desc->flags, wpi_cmd_str(desc->type),
16336607310bSBenjamin Close 				 le32toh(desc->len)));
16346607310bSBenjamin Close 
16356607310bSBenjamin Close 	if ((desc->qid & 7) != 4)
16366607310bSBenjamin Close 		return;	/* not a command ack */
16376607310bSBenjamin Close 
16386607310bSBenjamin Close 	data = &ring->data[desc->idx];
16396607310bSBenjamin Close 
16406607310bSBenjamin Close 	/* if the command was mapped in a mbuf, free it */
16416607310bSBenjamin Close 	if (data->m != NULL) {
16426607310bSBenjamin Close 		bus_dmamap_unload(ring->data_dmat, data->map);
16436607310bSBenjamin Close 		m_freem(data->m);
16446607310bSBenjamin Close 		data->m = NULL;
16456607310bSBenjamin Close 	}
16466607310bSBenjamin Close 
16476607310bSBenjamin Close 	sc->flags &= ~WPI_FLAG_BUSY;
16486607310bSBenjamin Close 	wakeup(&ring->cmd[desc->idx]);
16496607310bSBenjamin Close }
16506607310bSBenjamin Close 
16516607310bSBenjamin Close static void
16526607310bSBenjamin Close wpi_notif_intr(struct wpi_softc *sc)
16536607310bSBenjamin Close {
1654b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
1655b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
16566607310bSBenjamin Close 	struct wpi_rx_desc *desc;
16576607310bSBenjamin Close 	struct wpi_rx_data *data;
16586607310bSBenjamin Close 	uint32_t hw;
16596607310bSBenjamin Close 
1660f015cb78SBernhard Schmidt 	bus_dmamap_sync(sc->shared_dma.tag, sc->shared_dma.map,
1661f015cb78SBernhard Schmidt 	    BUS_DMASYNC_POSTREAD);
1662f015cb78SBernhard Schmidt 
16636607310bSBenjamin Close 	hw = le32toh(sc->shared->next);
16646607310bSBenjamin Close 	while (sc->rxq.cur != hw) {
16656607310bSBenjamin Close 		data = &sc->rxq.data[sc->rxq.cur];
1666f015cb78SBernhard Schmidt 
1667f015cb78SBernhard Schmidt 		bus_dmamap_sync(sc->rxq.data_dmat, data->map,
1668f015cb78SBernhard Schmidt 		    BUS_DMASYNC_POSTREAD);
16696607310bSBenjamin Close 		desc = (void *)data->m->m_ext.ext_buf;
16706607310bSBenjamin Close 
16716607310bSBenjamin Close 		DPRINTFN(WPI_DEBUG_NOTIFY,
16726607310bSBenjamin Close 			 ("notify qid=%x idx=%d flags=%x type=%d len=%d\n",
16736607310bSBenjamin Close 			  desc->qid,
16746607310bSBenjamin Close 			  desc->idx,
16756607310bSBenjamin Close 			  desc->flags,
16766607310bSBenjamin Close 			  desc->type,
16776607310bSBenjamin Close 			  le32toh(desc->len)));
16786607310bSBenjamin Close 
16796607310bSBenjamin Close 		if (!(desc->qid & 0x80))	/* reply to a command */
16806607310bSBenjamin Close 			wpi_cmd_intr(sc, desc);
16816607310bSBenjamin Close 
16826607310bSBenjamin Close 		switch (desc->type) {
16836607310bSBenjamin Close 		case WPI_RX_DONE:
16846607310bSBenjamin Close 			/* a 802.11 frame was received */
16856607310bSBenjamin Close 			wpi_rx_intr(sc, desc, data);
16866607310bSBenjamin Close 			break;
16876607310bSBenjamin Close 
16886607310bSBenjamin Close 		case WPI_TX_DONE:
16896607310bSBenjamin Close 			/* a 802.11 frame has been transmitted */
16906607310bSBenjamin Close 			wpi_tx_intr(sc, desc);
16916607310bSBenjamin Close 			break;
16926607310bSBenjamin Close 
16936607310bSBenjamin Close 		case WPI_UC_READY:
16946607310bSBenjamin Close 		{
16956607310bSBenjamin Close 			struct wpi_ucode_info *uc =
16966607310bSBenjamin Close 				(struct wpi_ucode_info *)(desc + 1);
16976607310bSBenjamin Close 
16986607310bSBenjamin Close 			/* the microcontroller is ready */
16996607310bSBenjamin Close 			DPRINTF(("microcode alive notification version %x "
17006607310bSBenjamin Close 				"alive %x\n", le32toh(uc->version),
17016607310bSBenjamin Close 				le32toh(uc->valid)));
17026607310bSBenjamin Close 
17036607310bSBenjamin Close 			if (le32toh(uc->valid) != 1) {
17046607310bSBenjamin Close 				device_printf(sc->sc_dev,
17056607310bSBenjamin Close 				    "microcontroller initialization failed\n");
17066607310bSBenjamin Close 				wpi_stop_locked(sc);
17076607310bSBenjamin Close 			}
17086607310bSBenjamin Close 			break;
17096607310bSBenjamin Close 		}
17106607310bSBenjamin Close 		case WPI_STATE_CHANGED:
17116607310bSBenjamin Close 		{
17126607310bSBenjamin Close 			uint32_t *status = (uint32_t *)(desc + 1);
17136607310bSBenjamin Close 
17146607310bSBenjamin Close 			/* enabled/disabled notification */
17156607310bSBenjamin Close 			DPRINTF(("state changed to %x\n", le32toh(*status)));
17166607310bSBenjamin Close 
17176607310bSBenjamin Close 			if (le32toh(*status) & 1) {
17186607310bSBenjamin Close 				device_printf(sc->sc_dev,
17196607310bSBenjamin Close 				    "Radio transmitter is switched off\n");
17206607310bSBenjamin Close 				sc->flags |= WPI_FLAG_HW_RADIO_OFF;
172182f1b132SAndrew Thompson 				ifp->if_drv_flags &= ~IFF_DRV_RUNNING;
172282f1b132SAndrew Thompson 				/* Disable firmware commands */
172382f1b132SAndrew Thompson 				WPI_WRITE(sc, WPI_UCODE_SET, WPI_DISABLE_CMD);
17246607310bSBenjamin Close 			}
17256607310bSBenjamin Close 			break;
17266607310bSBenjamin Close 		}
17276607310bSBenjamin Close 		case WPI_START_SCAN:
17286607310bSBenjamin Close 		{
17296845408dSAndrew Thompson #ifdef WPI_DEBUG
17306607310bSBenjamin Close 			struct wpi_start_scan *scan =
17316607310bSBenjamin Close 				(struct wpi_start_scan *)(desc + 1);
17326845408dSAndrew Thompson #endif
17336607310bSBenjamin Close 
17346607310bSBenjamin Close 			DPRINTFN(WPI_DEBUG_SCANNING,
17356607310bSBenjamin Close 				 ("scanning channel %d status %x\n",
17366607310bSBenjamin Close 			    scan->chan, le32toh(scan->status)));
17376607310bSBenjamin Close 			break;
17386607310bSBenjamin Close 		}
17396607310bSBenjamin Close 		case WPI_STOP_SCAN:
17406607310bSBenjamin Close 		{
17416845408dSAndrew Thompson #ifdef WPI_DEBUG
17426607310bSBenjamin Close 			struct wpi_stop_scan *scan =
17436607310bSBenjamin Close 				(struct wpi_stop_scan *)(desc + 1);
17446845408dSAndrew Thompson #endif
1745b032f27cSSam Leffler 			struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
17466607310bSBenjamin Close 
17476607310bSBenjamin Close 			DPRINTFN(WPI_DEBUG_SCANNING,
17486607310bSBenjamin Close 			    ("scan finished nchan=%d status=%d chan=%d\n",
17496607310bSBenjamin Close 			     scan->nchan, scan->status, scan->chan));
17506607310bSBenjamin Close 
175182f1b132SAndrew Thompson 			sc->sc_scan_timer = 0;
1752b032f27cSSam Leffler 			ieee80211_scan_next(vap);
17536607310bSBenjamin Close 			break;
17546607310bSBenjamin Close 		}
1755a7099588SBenjamin Close 		case WPI_MISSED_BEACON:
1756a7099588SBenjamin Close 		{
1757a7099588SBenjamin Close 			struct wpi_missed_beacon *beacon =
1758a7099588SBenjamin Close 				(struct wpi_missed_beacon *)(desc + 1);
1759b032f27cSSam Leffler 			struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
1760a7099588SBenjamin Close 
176182f1b132SAndrew Thompson 			if (le32toh(beacon->consecutive) >=
1762b032f27cSSam Leffler 			    vap->iv_bmissthreshold) {
1763a7099588SBenjamin Close 				DPRINTF(("Beacon miss: %u >= %u\n",
1764a7099588SBenjamin Close 					 le32toh(beacon->consecutive),
1765b032f27cSSam Leffler 					 vap->iv_bmissthreshold));
17665efea30fSAndrew Thompson 				ieee80211_beacon_miss(ic);
1767a7099588SBenjamin Close 			}
176882f1b132SAndrew Thompson 			break;
1769a7099588SBenjamin Close 		}
17706607310bSBenjamin Close 		}
17716607310bSBenjamin Close 
17726607310bSBenjamin Close 		sc->rxq.cur = (sc->rxq.cur + 1) % WPI_RX_RING_COUNT;
17736607310bSBenjamin Close 	}
17746607310bSBenjamin Close 
17756607310bSBenjamin Close 	/* tell the firmware what we have processed */
17766607310bSBenjamin Close 	hw = (hw == 0) ? WPI_RX_RING_COUNT - 1 : hw - 1;
17776607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RX_WIDX, hw & ~7);
17786607310bSBenjamin Close }
17796607310bSBenjamin Close 
17806607310bSBenjamin Close static void
17816607310bSBenjamin Close wpi_intr(void *arg)
17826607310bSBenjamin Close {
17836607310bSBenjamin Close 	struct wpi_softc *sc = arg;
17846607310bSBenjamin Close 	uint32_t r;
17856607310bSBenjamin Close 
17866607310bSBenjamin Close 	WPI_LOCK(sc);
17876607310bSBenjamin Close 
17886607310bSBenjamin Close 	r = WPI_READ(sc, WPI_INTR);
17896607310bSBenjamin Close 	if (r == 0 || r == 0xffffffff) {
17906607310bSBenjamin Close 		WPI_UNLOCK(sc);
17916607310bSBenjamin Close 		return;
17926607310bSBenjamin Close 	}
17936607310bSBenjamin Close 
17946607310bSBenjamin Close 	/* disable interrupts */
17956607310bSBenjamin Close 	WPI_WRITE(sc, WPI_MASK, 0);
17966607310bSBenjamin Close 	/* ack interrupts */
17976607310bSBenjamin Close 	WPI_WRITE(sc, WPI_INTR, r);
17986607310bSBenjamin Close 
17996607310bSBenjamin Close 	if (r & (WPI_SW_ERROR | WPI_HW_ERROR)) {
18005efea30fSAndrew Thompson 		struct ifnet *ifp = sc->sc_ifp;
18015efea30fSAndrew Thompson 		struct ieee80211com *ic = ifp->if_l2com;
1802e1d2045eSAndrew Thompson 		struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
18035efea30fSAndrew Thompson 
18046607310bSBenjamin Close 		device_printf(sc->sc_dev, "fatal firmware error\n");
18056607310bSBenjamin Close 		DPRINTFN(6,("(%s)\n", (r & WPI_SW_ERROR) ? "(Software Error)" :
18066607310bSBenjamin Close 				"(Hardware Error)"));
1807e1d2045eSAndrew Thompson 		if (vap != NULL)
1808e1d2045eSAndrew Thompson 			ieee80211_cancel_scan(vap);
18095efea30fSAndrew Thompson 		ieee80211_runtask(ic, &sc->sc_restarttask);
18106607310bSBenjamin Close 		sc->flags &= ~WPI_FLAG_BUSY;
18116607310bSBenjamin Close 		WPI_UNLOCK(sc);
18126607310bSBenjamin Close 		return;
18136607310bSBenjamin Close 	}
18146607310bSBenjamin Close 
18156607310bSBenjamin Close 	if (r & WPI_RX_INTR)
18166607310bSBenjamin Close 		wpi_notif_intr(sc);
18176607310bSBenjamin Close 
18186607310bSBenjamin Close 	if (r & WPI_ALIVE_INTR)	/* firmware initialized */
18196607310bSBenjamin Close 		wakeup(sc);
18206607310bSBenjamin Close 
18216607310bSBenjamin Close 	/* re-enable interrupts */
18226607310bSBenjamin Close 	if (sc->sc_ifp->if_flags & IFF_UP)
18236607310bSBenjamin Close 		WPI_WRITE(sc, WPI_MASK, WPI_INTR_MASK);
18246607310bSBenjamin Close 
18256607310bSBenjamin Close 	WPI_UNLOCK(sc);
18266607310bSBenjamin Close }
18276607310bSBenjamin Close 
18286607310bSBenjamin Close static uint8_t
18296607310bSBenjamin Close wpi_plcp_signal(int rate)
18306607310bSBenjamin Close {
18316607310bSBenjamin Close 	switch (rate) {
18326607310bSBenjamin Close 	/* CCK rates (returned values are device-dependent) */
18336607310bSBenjamin Close 	case 2:		return 10;
18346607310bSBenjamin Close 	case 4:		return 20;
18356607310bSBenjamin Close 	case 11:	return 55;
18366607310bSBenjamin Close 	case 22:	return 110;
18376607310bSBenjamin Close 
18386607310bSBenjamin Close 	/* OFDM rates (cf IEEE Std 802.11a-1999, pp. 14 Table 80) */
18396607310bSBenjamin Close 	/* R1-R4 (ral/ural is R4-R1) */
18406607310bSBenjamin Close 	case 12:	return 0xd;
18416607310bSBenjamin Close 	case 18:	return 0xf;
18426607310bSBenjamin Close 	case 24:	return 0x5;
18436607310bSBenjamin Close 	case 36:	return 0x7;
18446607310bSBenjamin Close 	case 48:	return 0x9;
18456607310bSBenjamin Close 	case 72:	return 0xb;
18466607310bSBenjamin Close 	case 96:	return 0x1;
18476607310bSBenjamin Close 	case 108:	return 0x3;
18486607310bSBenjamin Close 
18496607310bSBenjamin Close 	/* unsupported rates (should not get there) */
18506607310bSBenjamin Close 	default:	return 0;
18516607310bSBenjamin Close 	}
18526607310bSBenjamin Close }
18536607310bSBenjamin Close 
18546607310bSBenjamin Close /* quickly determine if a given rate is CCK or OFDM */
18556607310bSBenjamin Close #define WPI_RATE_IS_OFDM(rate) ((rate) >= 12 && (rate) != 22)
18566607310bSBenjamin Close 
18576607310bSBenjamin Close /*
18586607310bSBenjamin Close  * Construct the data packet for a transmit buffer and acutally put
18596607310bSBenjamin Close  * the buffer onto the transmit ring, kicking the card to process the
18606607310bSBenjamin Close  * the buffer.
18616607310bSBenjamin Close  */
18626607310bSBenjamin Close static int
18636607310bSBenjamin Close wpi_tx_data(struct wpi_softc *sc, struct mbuf *m0, struct ieee80211_node *ni,
18646607310bSBenjamin Close 	int ac)
18656607310bSBenjamin Close {
1866b032f27cSSam Leffler 	struct ieee80211vap *vap = ni->ni_vap;
1867b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
1868b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
186982f1b132SAndrew Thompson 	const struct chanAccParams *cap = &ic->ic_wme.wme_chanParams;
18706607310bSBenjamin Close 	struct wpi_tx_ring *ring = &sc->txq[ac];
18716607310bSBenjamin Close 	struct wpi_tx_desc *desc;
18726607310bSBenjamin Close 	struct wpi_tx_data *data;
18736607310bSBenjamin Close 	struct wpi_tx_cmd *cmd;
18746607310bSBenjamin Close 	struct wpi_cmd_data *tx;
18756607310bSBenjamin Close 	struct ieee80211_frame *wh;
1876b032f27cSSam Leffler 	const struct ieee80211_txparam *tp;
18776607310bSBenjamin Close 	struct ieee80211_key *k;
18786607310bSBenjamin Close 	struct mbuf *mnew;
187982f1b132SAndrew Thompson 	int i, error, nsegs, rate, hdrlen, ismcast;
18806607310bSBenjamin Close 	bus_dma_segment_t segs[WPI_MAX_SCATTER];
18816607310bSBenjamin Close 
18826607310bSBenjamin Close 	desc = &ring->desc[ring->cur];
18836607310bSBenjamin Close 	data = &ring->data[ring->cur];
18846607310bSBenjamin Close 
18856607310bSBenjamin Close 	wh = mtod(m0, struct ieee80211_frame *);
18866607310bSBenjamin Close 
188782f1b132SAndrew Thompson 	hdrlen = ieee80211_hdrsize(wh);
188882f1b132SAndrew Thompson 	ismcast = IEEE80211_IS_MULTICAST(wh->i_addr1);
18896607310bSBenjamin Close 
18906607310bSBenjamin Close 	if (wh->i_fc[1] & IEEE80211_FC1_WEP) {
1891b032f27cSSam Leffler 		k = ieee80211_crypto_encap(ni, m0);
189282f1b132SAndrew Thompson 		if (k == NULL) {
18936607310bSBenjamin Close 			m_freem(m0);
18946607310bSBenjamin Close 			return ENOBUFS;
18956607310bSBenjamin Close 		}
18966607310bSBenjamin Close 		/* packet header may have moved, reset our local pointer */
18976607310bSBenjamin Close 		wh = mtod(m0, struct ieee80211_frame *);
18986607310bSBenjamin Close 	}
18996607310bSBenjamin Close 
19006607310bSBenjamin Close 	cmd = &ring->cmd[ring->cur];
19016607310bSBenjamin Close 	cmd->code = WPI_CMD_TX_DATA;
19026607310bSBenjamin Close 	cmd->flags = 0;
19036607310bSBenjamin Close 	cmd->qid = ring->qid;
19046607310bSBenjamin Close 	cmd->idx = ring->cur;
19056607310bSBenjamin Close 
19066607310bSBenjamin Close 	tx = (struct wpi_cmd_data *)cmd->data;
190782f1b132SAndrew Thompson 	tx->flags = htole32(WPI_TX_AUTO_SEQ);
190882f1b132SAndrew Thompson 	tx->timeout = htole16(0);
190982f1b132SAndrew Thompson 	tx->ofdm_mask = 0xff;
191082f1b132SAndrew Thompson 	tx->cck_mask = 0x0f;
191182f1b132SAndrew Thompson 	tx->lifetime = htole32(WPI_LIFETIME_INFINITE);
191282f1b132SAndrew Thompson 	tx->id = ismcast ? WPI_ID_BROADCAST : WPI_ID_BSS;
191382f1b132SAndrew Thompson 	tx->len = htole16(m0->m_pkthdr.len);
19146607310bSBenjamin Close 
1915810df801SSam Leffler 	if (!ismcast) {
191682f1b132SAndrew Thompson 		if ((ni->ni_flags & IEEE80211_NODE_QOS) == 0 ||
191782f1b132SAndrew Thompson 		    !cap->cap_wmeParams[ac].wmep_noackPolicy)
19186607310bSBenjamin Close 			tx->flags |= htole32(WPI_TX_NEED_ACK);
1919b032f27cSSam Leffler 		if (m0->m_pkthdr.len + IEEE80211_CRC_LEN > vap->iv_rtsthreshold) {
19206607310bSBenjamin Close 			tx->flags |= htole32(WPI_TX_NEED_RTS|WPI_TX_FULL_TXOP);
192182f1b132SAndrew Thompson 			tx->rts_ntries = 7;
192282f1b132SAndrew Thompson 		}
19236607310bSBenjamin Close 	}
192482f1b132SAndrew Thompson 	/* pick a rate */
1925b032f27cSSam Leffler 	tp = &vap->iv_txparms[ieee80211_chan2mode(ni->ni_chan)];
1926b032f27cSSam Leffler 	if ((wh->i_fc[0] & IEEE80211_FC0_TYPE_MASK) == IEEE80211_FC0_TYPE_MGT) {
19276607310bSBenjamin Close 		uint8_t subtype = wh->i_fc[0] & IEEE80211_FC0_SUBTYPE_MASK;
19286607310bSBenjamin Close 		/* tell h/w to set timestamp in probe responses */
19296607310bSBenjamin Close 		if (subtype == IEEE80211_FC0_SUBTYPE_PROBE_RESP)
19306607310bSBenjamin Close 			tx->flags |= htole32(WPI_TX_INSERT_TSTAMP);
19316607310bSBenjamin Close 		if (subtype == IEEE80211_FC0_SUBTYPE_ASSOC_REQ ||
19326607310bSBenjamin Close 		    subtype == IEEE80211_FC0_SUBTYPE_REASSOC_REQ)
19336607310bSBenjamin Close 			tx->timeout = htole16(3);
19346607310bSBenjamin Close 		else
19356607310bSBenjamin Close 			tx->timeout = htole16(2);
1936b032f27cSSam Leffler 		rate = tp->mgmtrate;
193782f1b132SAndrew Thompson 	} else if (ismcast) {
1938b032f27cSSam Leffler 		rate = tp->mcastrate;
1939b032f27cSSam Leffler 	} else if (tp->ucastrate != IEEE80211_FIXED_RATE_NONE) {
1940b032f27cSSam Leffler 		rate = tp->ucastrate;
194182f1b132SAndrew Thompson 	} else {
1942b6108616SRui Paulo 		(void) ieee80211_ratectl_rate(ni, NULL, 0);
1943b032f27cSSam Leffler 		rate = ni->ni_txrate;
194482f1b132SAndrew Thompson 	}
19456607310bSBenjamin Close 	tx->rate = wpi_plcp_signal(rate);
19466607310bSBenjamin Close 
19476607310bSBenjamin Close 	/* be very persistant at sending frames out */
1948b032f27cSSam Leffler #if 0
1949b032f27cSSam Leffler 	tx->data_ntries = tp->maxretry;
1950b032f27cSSam Leffler #else
1951b032f27cSSam Leffler 	tx->data_ntries = 15;		/* XXX way too high */
1952b032f27cSSam Leffler #endif
19536607310bSBenjamin Close 
19545463c4a4SSam Leffler 	if (ieee80211_radiotap_active_vap(vap)) {
195582f1b132SAndrew Thompson 		struct wpi_tx_radiotap_header *tap = &sc->sc_txtap;
195682f1b132SAndrew Thompson 		tap->wt_flags = 0;
195782f1b132SAndrew Thompson 		tap->wt_rate = rate;
195882f1b132SAndrew Thompson 		tap->wt_hwqueue = ac;
195982f1b132SAndrew Thompson 		if (wh->i_fc[1] & IEEE80211_FC1_WEP)
196082f1b132SAndrew Thompson 			tap->wt_flags |= IEEE80211_RADIOTAP_F_WEP;
1961b032f27cSSam Leffler 
19625463c4a4SSam Leffler 		ieee80211_radiotap_tx(vap, m0);
196382f1b132SAndrew Thompson 	}
19646607310bSBenjamin Close 
19656607310bSBenjamin Close 	/* save and trim IEEE802.11 header */
19666607310bSBenjamin Close 	m_copydata(m0, 0, hdrlen, (caddr_t)&tx->wh);
19676607310bSBenjamin Close 	m_adj(m0, hdrlen);
19686607310bSBenjamin Close 
19696607310bSBenjamin Close 	error = bus_dmamap_load_mbuf_sg(ring->data_dmat, data->map, m0, segs,
19706607310bSBenjamin Close 	    &nsegs, BUS_DMA_NOWAIT);
19716607310bSBenjamin Close 	if (error != 0 && error != EFBIG) {
19726607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not map mbuf (error %d)\n",
19736607310bSBenjamin Close 		    error);
19746607310bSBenjamin Close 		m_freem(m0);
19756607310bSBenjamin Close 		return error;
19766607310bSBenjamin Close 	}
19776607310bSBenjamin Close 	if (error != 0) {
1978304a4c6fSJohn Baldwin 		/* XXX use m_collapse */
1979c6499eccSGleb Smirnoff 		mnew = m_defrag(m0, M_NOWAIT);
19806607310bSBenjamin Close 		if (mnew == NULL) {
19816607310bSBenjamin Close 			device_printf(sc->sc_dev,
19826607310bSBenjamin Close 			    "could not defragment mbuf\n");
19836607310bSBenjamin Close 			m_freem(m0);
19846607310bSBenjamin Close 			return ENOBUFS;
19856607310bSBenjamin Close 		}
19866607310bSBenjamin Close 		m0 = mnew;
19876607310bSBenjamin Close 
19886607310bSBenjamin Close 		error = bus_dmamap_load_mbuf_sg(ring->data_dmat, data->map,
19896607310bSBenjamin Close 		    m0, segs, &nsegs, BUS_DMA_NOWAIT);
19906607310bSBenjamin Close 		if (error != 0) {
19916607310bSBenjamin Close 			device_printf(sc->sc_dev,
19926607310bSBenjamin Close 			    "could not map mbuf (error %d)\n", error);
19936607310bSBenjamin Close 			m_freem(m0);
19946607310bSBenjamin Close 			return error;
19956607310bSBenjamin Close 		}
19966607310bSBenjamin Close 	}
19976607310bSBenjamin Close 
19986607310bSBenjamin Close 	data->m = m0;
19996607310bSBenjamin Close 	data->ni = ni;
20006607310bSBenjamin Close 
20016607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_TX, ("sending data: qid=%d idx=%d len=%d nsegs=%d\n",
20026607310bSBenjamin Close 	    ring->qid, ring->cur, m0->m_pkthdr.len, nsegs));
20036607310bSBenjamin Close 
20046607310bSBenjamin Close 	/* first scatter/gather segment is used by the tx data command */
20056607310bSBenjamin Close 	desc->flags = htole32(WPI_PAD32(m0->m_pkthdr.len) << 28 |
20066607310bSBenjamin Close 	    (1 + nsegs) << 24);
20076607310bSBenjamin Close 	desc->segs[0].addr = htole32(ring->cmd_dma.paddr +
20086607310bSBenjamin Close 	    ring->cur * sizeof (struct wpi_tx_cmd));
20096607310bSBenjamin Close 	desc->segs[0].len  = htole32(4 + sizeof (struct wpi_cmd_data));
20106607310bSBenjamin Close 	for (i = 1; i <= nsegs; i++) {
20116607310bSBenjamin Close 		desc->segs[i].addr = htole32(segs[i - 1].ds_addr);
20126607310bSBenjamin Close 		desc->segs[i].len  = htole32(segs[i - 1].ds_len);
20136607310bSBenjamin Close 	}
20146607310bSBenjamin Close 
20156607310bSBenjamin Close 	bus_dmamap_sync(ring->data_dmat, data->map, BUS_DMASYNC_PREWRITE);
20166607310bSBenjamin Close 	bus_dmamap_sync(ring->desc_dma.tag, ring->desc_dma.map,
20176607310bSBenjamin Close 	    BUS_DMASYNC_PREWRITE);
20186607310bSBenjamin Close 
20196607310bSBenjamin Close 	ring->queued++;
20206607310bSBenjamin Close 
20216607310bSBenjamin Close 	/* kick ring */
20226607310bSBenjamin Close 	ring->cur = (ring->cur + 1) % WPI_TX_RING_COUNT;
20236607310bSBenjamin Close 	WPI_WRITE(sc, WPI_TX_WIDX, ring->qid << 8 | ring->cur);
20246607310bSBenjamin Close 
20256607310bSBenjamin Close 	return 0;
20266607310bSBenjamin Close }
20276607310bSBenjamin Close 
20286607310bSBenjamin Close /**
20296607310bSBenjamin Close  * Process data waiting to be sent on the IFNET output queue
20306607310bSBenjamin Close  */
20316607310bSBenjamin Close static void
20326607310bSBenjamin Close wpi_start(struct ifnet *ifp)
20336607310bSBenjamin Close {
20346607310bSBenjamin Close 	struct wpi_softc *sc = ifp->if_softc;
2035b032f27cSSam Leffler 
2036b032f27cSSam Leffler 	WPI_LOCK(sc);
2037b032f27cSSam Leffler 	wpi_start_locked(ifp);
2038b032f27cSSam Leffler 	WPI_UNLOCK(sc);
2039b032f27cSSam Leffler }
2040b032f27cSSam Leffler 
2041b032f27cSSam Leffler static void
2042b032f27cSSam Leffler wpi_start_locked(struct ifnet *ifp)
2043b032f27cSSam Leffler {
2044b032f27cSSam Leffler 	struct wpi_softc *sc = ifp->if_softc;
20456607310bSBenjamin Close 	struct ieee80211_node *ni;
2046b032f27cSSam Leffler 	struct mbuf *m;
2047b032f27cSSam Leffler 	int ac;
2048b032f27cSSam Leffler 
2049b032f27cSSam Leffler 	WPI_LOCK_ASSERT(sc);
20506607310bSBenjamin Close 
205182f1b132SAndrew Thompson 	if ((ifp->if_drv_flags & IFF_DRV_RUNNING) == 0)
205282f1b132SAndrew Thompson 		return;
205382f1b132SAndrew Thompson 
20546607310bSBenjamin Close 	for (;;) {
2055fcec677dSJuli Mallett 		IFQ_DRV_DEQUEUE(&ifp->if_snd, m);
2056b032f27cSSam Leffler 		if (m == NULL)
20576607310bSBenjamin Close 			break;
2058b032f27cSSam Leffler 		ac = M_WME_GETAC(m);
20596607310bSBenjamin Close 		if (sc->txq[ac].queued > sc->txq[ac].count - 8) {
20606607310bSBenjamin Close 			/* there is no place left in this ring */
2061b032f27cSSam Leffler 			IFQ_DRV_PREPEND(&ifp->if_snd, m);
20626607310bSBenjamin Close 			ifp->if_drv_flags |= IFF_DRV_OACTIVE;
20636607310bSBenjamin Close 			break;
20646607310bSBenjamin Close 		}
2065b032f27cSSam Leffler 		ni = (struct ieee80211_node *) m->m_pkthdr.rcvif;
2066b032f27cSSam Leffler 		if (wpi_tx_data(sc, m, ni, ac) != 0) {
20676607310bSBenjamin Close 			ieee80211_free_node(ni);
20686607310bSBenjamin Close 			ifp->if_oerrors++;
20696607310bSBenjamin Close 			break;
20706607310bSBenjamin Close 		}
20716607310bSBenjamin Close 		sc->sc_tx_timer = 5;
2072b032f27cSSam Leffler 	}
20736607310bSBenjamin Close }
20746607310bSBenjamin Close 
2075b032f27cSSam Leffler static int
2076b032f27cSSam Leffler wpi_raw_xmit(struct ieee80211_node *ni, struct mbuf *m,
2077b032f27cSSam Leffler 	const struct ieee80211_bpf_params *params)
2078b032f27cSSam Leffler {
2079b032f27cSSam Leffler 	struct ieee80211com *ic = ni->ni_ic;
2080b032f27cSSam Leffler 	struct ifnet *ifp = ic->ic_ifp;
2081b032f27cSSam Leffler 	struct wpi_softc *sc = ifp->if_softc;
2082b032f27cSSam Leffler 
2083b032f27cSSam Leffler 	/* prevent management frames from being sent if we're not ready */
2084b032f27cSSam Leffler 	if (!(ifp->if_drv_flags & IFF_DRV_RUNNING)) {
2085b032f27cSSam Leffler 		m_freem(m);
2086b032f27cSSam Leffler 		ieee80211_free_node(ni);
2087b032f27cSSam Leffler 		return ENETDOWN;
2088b032f27cSSam Leffler 	}
2089b032f27cSSam Leffler 	WPI_LOCK(sc);
2090b032f27cSSam Leffler 
2091b032f27cSSam Leffler 	/* management frames go into ring 0 */
2092b032f27cSSam Leffler 	if (sc->txq[0].queued > sc->txq[0].count - 8) {
2093b032f27cSSam Leffler 		ifp->if_drv_flags |= IFF_DRV_OACTIVE;
2094b032f27cSSam Leffler 		m_freem(m);
20956607310bSBenjamin Close 		WPI_UNLOCK(sc);
2096b032f27cSSam Leffler 		ieee80211_free_node(ni);
2097b032f27cSSam Leffler 		return ENOBUFS;		/* XXX */
2098b032f27cSSam Leffler 	}
2099b032f27cSSam Leffler 
2100b032f27cSSam Leffler 	ifp->if_opackets++;
2101b032f27cSSam Leffler 	if (wpi_tx_data(sc, m, ni, 0) != 0)
2102b032f27cSSam Leffler 		goto bad;
2103b032f27cSSam Leffler 	sc->sc_tx_timer = 5;
2104b032f27cSSam Leffler 	callout_reset(&sc->watchdog_to, hz, wpi_watchdog, sc);
2105b032f27cSSam Leffler 
2106b032f27cSSam Leffler 	WPI_UNLOCK(sc);
2107b032f27cSSam Leffler 	return 0;
2108b032f27cSSam Leffler bad:
2109b032f27cSSam Leffler 	ifp->if_oerrors++;
2110b032f27cSSam Leffler 	WPI_UNLOCK(sc);
2111b032f27cSSam Leffler 	ieee80211_free_node(ni);
2112b032f27cSSam Leffler 	return EIO;		/* XXX */
21136607310bSBenjamin Close }
21146607310bSBenjamin Close 
21156607310bSBenjamin Close static int
21166607310bSBenjamin Close wpi_ioctl(struct ifnet *ifp, u_long cmd, caddr_t data)
21176607310bSBenjamin Close {
21186607310bSBenjamin Close 	struct wpi_softc *sc = ifp->if_softc;
2119b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
2120b032f27cSSam Leffler 	struct ifreq *ifr = (struct ifreq *) data;
2121b032f27cSSam Leffler 	int error = 0, startall = 0;
21226607310bSBenjamin Close 
21236607310bSBenjamin Close 	switch (cmd) {
21246607310bSBenjamin Close 	case SIOCSIFFLAGS:
212531a8c1edSAndrew Thompson 		WPI_LOCK(sc);
21266607310bSBenjamin Close 		if ((ifp->if_flags & IFF_UP)) {
2127b032f27cSSam Leffler 			if (!(ifp->if_drv_flags & IFF_DRV_RUNNING)) {
212882f1b132SAndrew Thompson 				wpi_init_locked(sc, 0);
2129b032f27cSSam Leffler 				startall = 1;
2130b032f27cSSam Leffler 			}
213182f1b132SAndrew Thompson 		} else if ((ifp->if_drv_flags & IFF_DRV_RUNNING) ||
213282f1b132SAndrew Thompson 			   (sc->flags & WPI_FLAG_HW_RADIO_OFF))
21336607310bSBenjamin Close 			wpi_stop_locked(sc);
21346607310bSBenjamin Close 		WPI_UNLOCK(sc);
2135b032f27cSSam Leffler 		if (startall)
2136b032f27cSSam Leffler 			ieee80211_start_all(ic);
213731a8c1edSAndrew Thompson 		break;
213831a8c1edSAndrew Thompson 	case SIOCGIFMEDIA:
213931a8c1edSAndrew Thompson 		error = ifmedia_ioctl(ifp, ifr, &ic->ic_media, cmd);
214031a8c1edSAndrew Thompson 		break;
214131a8c1edSAndrew Thompson 	case SIOCGIFADDR:
214231a8c1edSAndrew Thompson 		error = ether_ioctl(ifp, cmd, data);
214331a8c1edSAndrew Thompson 		break;
214431a8c1edSAndrew Thompson 	default:
214531a8c1edSAndrew Thompson 		error = EINVAL;
214631a8c1edSAndrew Thompson 		break;
214731a8c1edSAndrew Thompson 	}
21486607310bSBenjamin Close 	return error;
21496607310bSBenjamin Close }
21506607310bSBenjamin Close 
21516607310bSBenjamin Close /*
21526607310bSBenjamin Close  * Extract various information from EEPROM.
21536607310bSBenjamin Close  */
21546607310bSBenjamin Close static void
215529aca940SSam Leffler wpi_read_eeprom(struct wpi_softc *sc, uint8_t macaddr[IEEE80211_ADDR_LEN])
21566607310bSBenjamin Close {
21576607310bSBenjamin Close 	int i;
21586607310bSBenjamin Close 
21596607310bSBenjamin Close 	/* read the hardware capabilities, revision and SKU type */
21606607310bSBenjamin Close 	wpi_read_prom_data(sc, WPI_EEPROM_CAPABILITIES, &sc->cap,1);
21616607310bSBenjamin Close 	wpi_read_prom_data(sc, WPI_EEPROM_REVISION, &sc->rev,2);
21626607310bSBenjamin Close 	wpi_read_prom_data(sc, WPI_EEPROM_TYPE, &sc->type, 1);
21636607310bSBenjamin Close 
21646607310bSBenjamin Close 	/* read the regulatory domain */
21656607310bSBenjamin Close 	wpi_read_prom_data(sc, WPI_EEPROM_DOMAIN, sc->domain, 4);
21666607310bSBenjamin Close 
21676607310bSBenjamin Close 	/* read in the hw MAC address */
216829aca940SSam Leffler 	wpi_read_prom_data(sc, WPI_EEPROM_MAC, macaddr, 6);
21696607310bSBenjamin Close 
21706607310bSBenjamin Close 	/* read the list of authorized channels */
21716607310bSBenjamin Close 	for (i = 0; i < WPI_CHAN_BANDS_COUNT; i++)
21726607310bSBenjamin Close 		wpi_read_eeprom_channels(sc,i);
21736607310bSBenjamin Close 
21746607310bSBenjamin Close 	/* read the power level calibration info for each group */
21756607310bSBenjamin Close 	for (i = 0; i < WPI_POWER_GROUPS_COUNT; i++)
21766607310bSBenjamin Close 		wpi_read_eeprom_group(sc,i);
21776607310bSBenjamin Close }
21786607310bSBenjamin Close 
21796607310bSBenjamin Close /*
21806607310bSBenjamin Close  * Send a command to the firmware.
21816607310bSBenjamin Close  */
21826607310bSBenjamin Close static int
21836607310bSBenjamin Close wpi_cmd(struct wpi_softc *sc, int code, const void *buf, int size, int async)
21846607310bSBenjamin Close {
21856607310bSBenjamin Close 	struct wpi_tx_ring *ring = &sc->cmdq;
21866607310bSBenjamin Close 	struct wpi_tx_desc *desc;
21876607310bSBenjamin Close 	struct wpi_tx_cmd *cmd;
21886607310bSBenjamin Close 
21896607310bSBenjamin Close #ifdef WPI_DEBUG
21906607310bSBenjamin Close 	if (!async) {
21916607310bSBenjamin Close 		WPI_LOCK_ASSERT(sc);
21926607310bSBenjamin Close 	}
21936607310bSBenjamin Close #endif
21946607310bSBenjamin Close 
21956607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_CMD,("wpi_cmd %d size %d async %d\n", code, size,
21966607310bSBenjamin Close 		    async));
21976607310bSBenjamin Close 
21986607310bSBenjamin Close 	if (sc->flags & WPI_FLAG_BUSY) {
21996607310bSBenjamin Close 		device_printf(sc->sc_dev, "%s: cmd %d not sent, busy\n",
22006607310bSBenjamin Close 		    __func__, code);
22016607310bSBenjamin Close 		return EAGAIN;
22026607310bSBenjamin Close 	}
22036607310bSBenjamin Close 	sc->flags|= WPI_FLAG_BUSY;
22046607310bSBenjamin Close 
22056607310bSBenjamin Close 	KASSERT(size <= sizeof cmd->data, ("command %d too large: %d bytes",
22066607310bSBenjamin Close 	    code, size));
22076607310bSBenjamin Close 
22086607310bSBenjamin Close 	desc = &ring->desc[ring->cur];
22096607310bSBenjamin Close 	cmd = &ring->cmd[ring->cur];
22106607310bSBenjamin Close 
22116607310bSBenjamin Close 	cmd->code = code;
22126607310bSBenjamin Close 	cmd->flags = 0;
22136607310bSBenjamin Close 	cmd->qid = ring->qid;
22146607310bSBenjamin Close 	cmd->idx = ring->cur;
22156607310bSBenjamin Close 	memcpy(cmd->data, buf, size);
22166607310bSBenjamin Close 
22176607310bSBenjamin Close 	desc->flags = htole32(WPI_PAD32(size) << 28 | 1 << 24);
22186607310bSBenjamin Close 	desc->segs[0].addr = htole32(ring->cmd_dma.paddr +
22196607310bSBenjamin Close 		ring->cur * sizeof (struct wpi_tx_cmd));
22206607310bSBenjamin Close 	desc->segs[0].len  = htole32(4 + size);
22216607310bSBenjamin Close 
22226607310bSBenjamin Close 	/* kick cmd ring */
22236607310bSBenjamin Close 	ring->cur = (ring->cur + 1) % WPI_CMD_RING_COUNT;
22246607310bSBenjamin Close 	WPI_WRITE(sc, WPI_TX_WIDX, ring->qid << 8 | ring->cur);
22256607310bSBenjamin Close 
22266607310bSBenjamin Close 	if (async) {
22276607310bSBenjamin Close 		sc->flags &= ~ WPI_FLAG_BUSY;
22286607310bSBenjamin Close 		return 0;
22296607310bSBenjamin Close 	}
22306607310bSBenjamin Close 
22316607310bSBenjamin Close 	return msleep(cmd, &sc->sc_mtx, PCATCH, "wpicmd", hz);
22326607310bSBenjamin Close }
22336607310bSBenjamin Close 
22346607310bSBenjamin Close static int
22356607310bSBenjamin Close wpi_wme_update(struct ieee80211com *ic)
22366607310bSBenjamin Close {
22376607310bSBenjamin Close #define WPI_EXP2(v)	htole16((1 << (v)) - 1)
22386607310bSBenjamin Close #define WPI_USEC(v)	htole16(IEEE80211_TXOP_TO_US(v))
22396607310bSBenjamin Close 	struct wpi_softc *sc = ic->ic_ifp->if_softc;
22406607310bSBenjamin Close 	const struct wmeParams *wmep;
22416607310bSBenjamin Close 	struct wpi_wme_setup wme;
22426607310bSBenjamin Close 	int ac;
22436607310bSBenjamin Close 
22446607310bSBenjamin Close 	/* don't override default WME values if WME is not actually enabled */
22456607310bSBenjamin Close 	if (!(ic->ic_flags & IEEE80211_F_WME))
22466607310bSBenjamin Close 		return 0;
22476607310bSBenjamin Close 
22486607310bSBenjamin Close 	wme.flags = 0;
22496607310bSBenjamin Close 	for (ac = 0; ac < WME_NUM_AC; ac++) {
22506607310bSBenjamin Close 		wmep = &ic->ic_wme.wme_chanParams.cap_wmeParams[ac];
22516607310bSBenjamin Close 		wme.ac[ac].aifsn = wmep->wmep_aifsn;
22526607310bSBenjamin Close 		wme.ac[ac].cwmin = WPI_EXP2(wmep->wmep_logcwmin);
22536607310bSBenjamin Close 		wme.ac[ac].cwmax = WPI_EXP2(wmep->wmep_logcwmax);
22546607310bSBenjamin Close 		wme.ac[ac].txop  = WPI_USEC(wmep->wmep_txopLimit);
22556607310bSBenjamin Close 
22566607310bSBenjamin Close 		DPRINTF(("setting WME for queue %d aifsn=%d cwmin=%d cwmax=%d "
22576607310bSBenjamin Close 		    "txop=%d\n", ac, wme.ac[ac].aifsn, wme.ac[ac].cwmin,
22586607310bSBenjamin Close 		    wme.ac[ac].cwmax, wme.ac[ac].txop));
22596607310bSBenjamin Close 	}
22606607310bSBenjamin Close 	return wpi_cmd(sc, WPI_CMD_SET_WME, &wme, sizeof wme, 1);
22616607310bSBenjamin Close #undef WPI_USEC
22626607310bSBenjamin Close #undef WPI_EXP2
22636607310bSBenjamin Close }
22646607310bSBenjamin Close 
22656607310bSBenjamin Close /*
22666607310bSBenjamin Close  * Configure h/w multi-rate retries.
22676607310bSBenjamin Close  */
22686607310bSBenjamin Close static int
22696607310bSBenjamin Close wpi_mrr_setup(struct wpi_softc *sc)
22706607310bSBenjamin Close {
2271b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
2272b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
22736607310bSBenjamin Close 	struct wpi_mrr_setup mrr;
22746607310bSBenjamin Close 	int i, error;
22756607310bSBenjamin Close 
22766607310bSBenjamin Close 	memset(&mrr, 0, sizeof (struct wpi_mrr_setup));
22776607310bSBenjamin Close 
22786607310bSBenjamin Close 	/* CCK rates (not used with 802.11a) */
22796607310bSBenjamin Close 	for (i = WPI_CCK1; i <= WPI_CCK11; i++) {
22806607310bSBenjamin Close 		mrr.rates[i].flags = 0;
22816607310bSBenjamin Close 		mrr.rates[i].signal = wpi_ridx_to_plcp[i];
22826607310bSBenjamin Close 		/* fallback to the immediate lower CCK rate (if any) */
22836607310bSBenjamin Close 		mrr.rates[i].next = (i == WPI_CCK1) ? WPI_CCK1 : i - 1;
22846607310bSBenjamin Close 		/* try one time at this rate before falling back to "next" */
22856607310bSBenjamin Close 		mrr.rates[i].ntries = 1;
22866607310bSBenjamin Close 	}
22876607310bSBenjamin Close 
22886607310bSBenjamin Close 	/* OFDM rates (not used with 802.11b) */
22896607310bSBenjamin Close 	for (i = WPI_OFDM6; i <= WPI_OFDM54; i++) {
22906607310bSBenjamin Close 		mrr.rates[i].flags = 0;
22916607310bSBenjamin Close 		mrr.rates[i].signal = wpi_ridx_to_plcp[i];
22926607310bSBenjamin Close 		/* fallback to the immediate lower OFDM rate (if any) */
22936607310bSBenjamin Close 		/* we allow fallback from OFDM/6 to CCK/2 in 11b/g mode */
22946607310bSBenjamin Close 		mrr.rates[i].next = (i == WPI_OFDM6) ?
22956607310bSBenjamin Close 		    ((ic->ic_curmode == IEEE80211_MODE_11A) ?
22966607310bSBenjamin Close 			WPI_OFDM6 : WPI_CCK2) :
22976607310bSBenjamin Close 		    i - 1;
22986607310bSBenjamin Close 		/* try one time at this rate before falling back to "next" */
22996607310bSBenjamin Close 		mrr.rates[i].ntries = 1;
23006607310bSBenjamin Close 	}
23016607310bSBenjamin Close 
23026607310bSBenjamin Close 	/* setup MRR for control frames */
2303797b9146SBernhard Schmidt 	mrr.which = WPI_MRR_CTL;
23046607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_MRR_SETUP, &mrr, sizeof mrr, 0);
23056607310bSBenjamin Close 	if (error != 0) {
23066607310bSBenjamin Close 		device_printf(sc->sc_dev,
23076607310bSBenjamin Close 		    "could not setup MRR for control frames\n");
23086607310bSBenjamin Close 		return error;
23096607310bSBenjamin Close 	}
23106607310bSBenjamin Close 
23116607310bSBenjamin Close 	/* setup MRR for data frames */
2312797b9146SBernhard Schmidt 	mrr.which = WPI_MRR_DATA;
23136607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_MRR_SETUP, &mrr, sizeof mrr, 0);
23146607310bSBenjamin Close 	if (error != 0) {
23156607310bSBenjamin Close 		device_printf(sc->sc_dev,
23166607310bSBenjamin Close 		    "could not setup MRR for data frames\n");
23176607310bSBenjamin Close 		return error;
23186607310bSBenjamin Close 	}
23196607310bSBenjamin Close 
23206607310bSBenjamin Close 	return 0;
23216607310bSBenjamin Close }
23226607310bSBenjamin Close 
23236607310bSBenjamin Close static void
23246607310bSBenjamin Close wpi_set_led(struct wpi_softc *sc, uint8_t which, uint8_t off, uint8_t on)
23256607310bSBenjamin Close {
23266607310bSBenjamin Close 	struct wpi_cmd_led led;
23276607310bSBenjamin Close 
23286607310bSBenjamin Close 	led.which = which;
23296607310bSBenjamin Close 	led.unit = htole32(100000);	/* on/off in unit of 100ms */
23306607310bSBenjamin Close 	led.off = off;
23316607310bSBenjamin Close 	led.on = on;
23326607310bSBenjamin Close 
23336607310bSBenjamin Close 	(void)wpi_cmd(sc, WPI_CMD_SET_LED, &led, sizeof led, 1);
23346607310bSBenjamin Close }
23356607310bSBenjamin Close 
23366607310bSBenjamin Close static void
23376607310bSBenjamin Close wpi_enable_tsf(struct wpi_softc *sc, struct ieee80211_node *ni)
23386607310bSBenjamin Close {
23396607310bSBenjamin Close 	struct wpi_cmd_tsf tsf;
23406607310bSBenjamin Close 	uint64_t val, mod;
23416607310bSBenjamin Close 
23426607310bSBenjamin Close 	memset(&tsf, 0, sizeof tsf);
23436607310bSBenjamin Close 	memcpy(&tsf.tstamp, ni->ni_tstamp.data, 8);
23446607310bSBenjamin Close 	tsf.bintval = htole16(ni->ni_intval);
23456607310bSBenjamin Close 	tsf.lintval = htole16(10);
23466607310bSBenjamin Close 
23476607310bSBenjamin Close 	/* compute remaining time until next beacon */
23486607310bSBenjamin Close 	val = (uint64_t)ni->ni_intval  * 1024;	/* msec -> usec */
23496607310bSBenjamin Close 	mod = le64toh(tsf.tstamp) % val;
23506607310bSBenjamin Close 	tsf.binitval = htole32((uint32_t)(val - mod));
23516607310bSBenjamin Close 
23526607310bSBenjamin Close 	if (wpi_cmd(sc, WPI_CMD_TSF, &tsf, sizeof tsf, 1) != 0)
23536607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not enable TSF\n");
23546607310bSBenjamin Close }
23556607310bSBenjamin Close 
23566607310bSBenjamin Close #if 0
23576607310bSBenjamin Close /*
23586607310bSBenjamin Close  * Build a beacon frame that the firmware will broadcast periodically in
23596607310bSBenjamin Close  * IBSS or HostAP modes.
23606607310bSBenjamin Close  */
23616607310bSBenjamin Close static int
23626607310bSBenjamin Close wpi_setup_beacon(struct wpi_softc *sc, struct ieee80211_node *ni)
23636607310bSBenjamin Close {
2364b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
2365b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
23666607310bSBenjamin Close 	struct wpi_tx_ring *ring = &sc->cmdq;
23676607310bSBenjamin Close 	struct wpi_tx_desc *desc;
23686607310bSBenjamin Close 	struct wpi_tx_data *data;
23696607310bSBenjamin Close 	struct wpi_tx_cmd *cmd;
23706607310bSBenjamin Close 	struct wpi_cmd_beacon *bcn;
23716607310bSBenjamin Close 	struct ieee80211_beacon_offsets bo;
23726607310bSBenjamin Close 	struct mbuf *m0;
23736607310bSBenjamin Close 	bus_addr_t physaddr;
23746607310bSBenjamin Close 	int error;
23756607310bSBenjamin Close 
23766607310bSBenjamin Close 	desc = &ring->desc[ring->cur];
23776607310bSBenjamin Close 	data = &ring->data[ring->cur];
23786607310bSBenjamin Close 
23796607310bSBenjamin Close 	m0 = ieee80211_beacon_alloc(ic, ni, &bo);
23806607310bSBenjamin Close 	if (m0 == NULL) {
23816607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not allocate beacon frame\n");
23826607310bSBenjamin Close 		return ENOMEM;
23836607310bSBenjamin Close 	}
23846607310bSBenjamin Close 
23856607310bSBenjamin Close 	cmd = &ring->cmd[ring->cur];
23866607310bSBenjamin Close 	cmd->code = WPI_CMD_SET_BEACON;
23876607310bSBenjamin Close 	cmd->flags = 0;
23886607310bSBenjamin Close 	cmd->qid = ring->qid;
23896607310bSBenjamin Close 	cmd->idx = ring->cur;
23906607310bSBenjamin Close 
23916607310bSBenjamin Close 	bcn = (struct wpi_cmd_beacon *)cmd->data;
23926607310bSBenjamin Close 	memset(bcn, 0, sizeof (struct wpi_cmd_beacon));
23936607310bSBenjamin Close 	bcn->id = WPI_ID_BROADCAST;
23946607310bSBenjamin Close 	bcn->ofdm_mask = 0xff;
23956607310bSBenjamin Close 	bcn->cck_mask = 0x0f;
23966607310bSBenjamin Close 	bcn->lifetime = htole32(WPI_LIFETIME_INFINITE);
23976607310bSBenjamin Close 	bcn->len = htole16(m0->m_pkthdr.len);
23986607310bSBenjamin Close 	bcn->rate = (ic->ic_curmode == IEEE80211_MODE_11A) ?
23996607310bSBenjamin Close 		wpi_plcp_signal(12) : wpi_plcp_signal(2);
24006607310bSBenjamin Close 	bcn->flags = htole32(WPI_TX_AUTO_SEQ | WPI_TX_INSERT_TSTAMP);
24016607310bSBenjamin Close 
24026607310bSBenjamin Close 	/* save and trim IEEE802.11 header */
24036607310bSBenjamin Close 	m_copydata(m0, 0, sizeof (struct ieee80211_frame), (caddr_t)&bcn->wh);
24046607310bSBenjamin Close 	m_adj(m0, sizeof (struct ieee80211_frame));
24056607310bSBenjamin Close 
24066607310bSBenjamin Close 	/* assume beacon frame is contiguous */
24076607310bSBenjamin Close 	error = bus_dmamap_load(ring->data_dmat, data->map, mtod(m0, void *),
24086607310bSBenjamin Close 	    m0->m_pkthdr.len, wpi_dma_map_addr, &physaddr, 0);
24096607310bSBenjamin Close 	if (error != 0) {
24106607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not map beacon\n");
24116607310bSBenjamin Close 		m_freem(m0);
24126607310bSBenjamin Close 		return error;
24136607310bSBenjamin Close 	}
24146607310bSBenjamin Close 
24156607310bSBenjamin Close 	data->m = m0;
24166607310bSBenjamin Close 
24176607310bSBenjamin Close 	/* first scatter/gather segment is used by the beacon command */
24186607310bSBenjamin Close 	desc->flags = htole32(WPI_PAD32(m0->m_pkthdr.len) << 28 | 2 << 24);
24196607310bSBenjamin Close 	desc->segs[0].addr = htole32(ring->cmd_dma.paddr +
24206607310bSBenjamin Close 		ring->cur * sizeof (struct wpi_tx_cmd));
24216607310bSBenjamin Close 	desc->segs[0].len  = htole32(4 + sizeof (struct wpi_cmd_beacon));
24226607310bSBenjamin Close 	desc->segs[1].addr = htole32(physaddr);
24236607310bSBenjamin Close 	desc->segs[1].len  = htole32(m0->m_pkthdr.len);
24246607310bSBenjamin Close 
24256607310bSBenjamin Close 	/* kick cmd ring */
24266607310bSBenjamin Close 	ring->cur = (ring->cur + 1) % WPI_CMD_RING_COUNT;
24276607310bSBenjamin Close 	WPI_WRITE(sc, WPI_TX_WIDX, ring->qid << 8 | ring->cur);
24286607310bSBenjamin Close 
24296607310bSBenjamin Close 	return 0;
24306607310bSBenjamin Close }
24316607310bSBenjamin Close #endif
24326607310bSBenjamin Close 
24336607310bSBenjamin Close static int
2434b032f27cSSam Leffler wpi_auth(struct wpi_softc *sc, struct ieee80211vap *vap)
24356607310bSBenjamin Close {
2436b032f27cSSam Leffler 	struct ieee80211com *ic = vap->iv_ic;
2437b032f27cSSam Leffler 	struct ieee80211_node *ni = vap->iv_bss;
24386607310bSBenjamin Close 	struct wpi_node_info node;
24396607310bSBenjamin Close 	int error;
24406607310bSBenjamin Close 
244182f1b132SAndrew Thompson 
24426607310bSBenjamin Close 	/* update adapter's configuration */
244382f1b132SAndrew Thompson 	sc->config.associd = 0;
244482f1b132SAndrew Thompson 	sc->config.filter &= ~htole32(WPI_FILTER_BSS);
24456607310bSBenjamin Close 	IEEE80211_ADDR_COPY(sc->config.bssid, ni->ni_bssid);
24466607310bSBenjamin Close 	sc->config.chan = ieee80211_chan2ieee(ic, ni->ni_chan);
24476607310bSBenjamin Close 	if (IEEE80211_IS_CHAN_2GHZ(ni->ni_chan)) {
24486607310bSBenjamin Close 		sc->config.flags |= htole32(WPI_CONFIG_AUTO |
24496607310bSBenjamin Close 		    WPI_CONFIG_24GHZ);
245096241066SBernhard Schmidt 	} else {
245196241066SBernhard Schmidt 		sc->config.flags &= ~htole32(WPI_CONFIG_AUTO |
245296241066SBernhard Schmidt 		    WPI_CONFIG_24GHZ);
24536607310bSBenjamin Close 	}
2454b032f27cSSam Leffler 	if (IEEE80211_IS_CHAN_A(ni->ni_chan)) {
24556607310bSBenjamin Close 		sc->config.cck_mask  = 0;
24566607310bSBenjamin Close 		sc->config.ofdm_mask = 0x15;
2457b032f27cSSam Leffler 	} else if (IEEE80211_IS_CHAN_B(ni->ni_chan)) {
24586607310bSBenjamin Close 		sc->config.cck_mask  = 0x03;
24596607310bSBenjamin Close 		sc->config.ofdm_mask = 0;
2460b032f27cSSam Leffler 	} else {
2461b032f27cSSam Leffler 		/* XXX assume 802.11b/g */
24626607310bSBenjamin Close 		sc->config.cck_mask  = 0x0f;
24636607310bSBenjamin Close 		sc->config.ofdm_mask = 0x15;
24646607310bSBenjamin Close 	}
24656607310bSBenjamin Close 
24666607310bSBenjamin Close 	DPRINTF(("config chan %d flags %x cck %x ofdm %x\n", sc->config.chan,
24676607310bSBenjamin Close 		sc->config.flags, sc->config.cck_mask, sc->config.ofdm_mask));
24686607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_CONFIGURE, &sc->config,
24696607310bSBenjamin Close 		sizeof (struct wpi_config), 1);
24706607310bSBenjamin Close 	if (error != 0) {
24716607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not configure\n");
24726607310bSBenjamin Close 		return error;
24736607310bSBenjamin Close 	}
24746607310bSBenjamin Close 
24756607310bSBenjamin Close 	/* configuration has changed, set Tx power accordingly */
24766607310bSBenjamin Close 	if ((error = wpi_set_txpower(sc, ni->ni_chan, 1)) != 0) {
24776607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not set Tx power\n");
24786607310bSBenjamin Close 		return error;
24796607310bSBenjamin Close 	}
24806607310bSBenjamin Close 
24816607310bSBenjamin Close 	/* add default node */
24826607310bSBenjamin Close 	memset(&node, 0, sizeof node);
24836607310bSBenjamin Close 	IEEE80211_ADDR_COPY(node.bssid, ni->ni_bssid);
24846607310bSBenjamin Close 	node.id = WPI_ID_BSS;
24856607310bSBenjamin Close 	node.rate = (ic->ic_curmode == IEEE80211_MODE_11A) ?
24866607310bSBenjamin Close 	    wpi_plcp_signal(12) : wpi_plcp_signal(2);
24876607310bSBenjamin Close 	node.action = htole32(WPI_ACTION_SET_RATE);
24886607310bSBenjamin Close 	node.antenna = WPI_ANTENNA_BOTH;
24896607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_ADD_NODE, &node, sizeof node, 1);
249082f1b132SAndrew Thompson 	if (error != 0)
24916607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not add BSS node\n");
249282f1b132SAndrew Thompson 
249382f1b132SAndrew Thompson 	return (error);
249482f1b132SAndrew Thompson }
249582f1b132SAndrew Thompson 
249682f1b132SAndrew Thompson static int
2497b032f27cSSam Leffler wpi_run(struct wpi_softc *sc, struct ieee80211vap *vap)
249882f1b132SAndrew Thompson {
2499b032f27cSSam Leffler 	struct ieee80211com *ic = vap->iv_ic;
2500b032f27cSSam Leffler 	struct ieee80211_node *ni = vap->iv_bss;
250182f1b132SAndrew Thompson 	int error;
250282f1b132SAndrew Thompson 
2503b032f27cSSam Leffler 	if (vap->iv_opmode == IEEE80211_M_MONITOR) {
2504b032f27cSSam Leffler 		/* link LED blinks while monitoring */
2505b032f27cSSam Leffler 		wpi_set_led(sc, WPI_LED_LINK, 5, 5);
2506b032f27cSSam Leffler 		return 0;
2507b032f27cSSam Leffler 	}
2508b032f27cSSam Leffler 
250982f1b132SAndrew Thompson 	wpi_enable_tsf(sc, ni);
251082f1b132SAndrew Thompson 
251182f1b132SAndrew Thompson 	/* update adapter's configuration */
251282f1b132SAndrew Thompson 	sc->config.associd = htole16(ni->ni_associd & ~0xc000);
251382f1b132SAndrew Thompson 	/* short preamble/slot time are negotiated when associating */
251482f1b132SAndrew Thompson 	sc->config.flags &= ~htole32(WPI_CONFIG_SHPREAMBLE |
251582f1b132SAndrew Thompson 	    WPI_CONFIG_SHSLOT);
251682f1b132SAndrew Thompson 	if (ic->ic_flags & IEEE80211_F_SHSLOT)
251782f1b132SAndrew Thompson 		sc->config.flags |= htole32(WPI_CONFIG_SHSLOT);
251882f1b132SAndrew Thompson 	if (ic->ic_flags & IEEE80211_F_SHPREAMBLE)
251982f1b132SAndrew Thompson 		sc->config.flags |= htole32(WPI_CONFIG_SHPREAMBLE);
252082f1b132SAndrew Thompson 	sc->config.filter |= htole32(WPI_FILTER_BSS);
252182f1b132SAndrew Thompson 
252282f1b132SAndrew Thompson 	/* XXX put somewhere HC_QOS_SUPPORT_ASSOC + HC_IBSS_START */
252382f1b132SAndrew Thompson 
252482f1b132SAndrew Thompson 	DPRINTF(("config chan %d flags %x\n", sc->config.chan,
252582f1b132SAndrew Thompson 		    sc->config.flags));
252682f1b132SAndrew Thompson 	error = wpi_cmd(sc, WPI_CMD_CONFIGURE, &sc->config, sizeof (struct
252782f1b132SAndrew Thompson 		    wpi_config), 1);
252882f1b132SAndrew Thompson 	if (error != 0) {
252982f1b132SAndrew Thompson 		device_printf(sc->sc_dev, "could not update configuration\n");
25306607310bSBenjamin Close 		return error;
25316607310bSBenjamin Close 	}
25326607310bSBenjamin Close 
2533b032f27cSSam Leffler 	error = wpi_set_txpower(sc, ni->ni_chan, 1);
253482f1b132SAndrew Thompson 	if (error != 0) {
253582f1b132SAndrew Thompson 		device_printf(sc->sc_dev, "could set txpower\n");
253682f1b132SAndrew Thompson 		return error;
253782f1b132SAndrew Thompson 	}
25386607310bSBenjamin Close 
253982f1b132SAndrew Thompson 	/* link LED always on while associated */
254082f1b132SAndrew Thompson 	wpi_set_led(sc, WPI_LED_LINK, 0, 1);
254182f1b132SAndrew Thompson 
254282f1b132SAndrew Thompson 	/* start automatic rate control timer */
2543b032f27cSSam Leffler 	callout_reset(&sc->calib_to, 60*hz, wpi_calib_timeout, sc);
254482f1b132SAndrew Thompson 
254582f1b132SAndrew Thompson 	return (error);
25466607310bSBenjamin Close }
25476607310bSBenjamin Close 
25486607310bSBenjamin Close /*
25496607310bSBenjamin Close  * Send a scan request to the firmware.  Since this command is huge, we map it
25506607310bSBenjamin Close  * into a mbufcluster instead of using the pre-allocated set of commands. Note,
25516607310bSBenjamin Close  * much of this code is similar to that in wpi_cmd but because we must manually
25526607310bSBenjamin Close  * construct the probe & channels, we duplicate what's needed here. XXX In the
25536607310bSBenjamin Close  * future, this function should be modified to use wpi_cmd to help cleanup the
25546607310bSBenjamin Close  * code base.
25556607310bSBenjamin Close  */
25566607310bSBenjamin Close static int
25576607310bSBenjamin Close wpi_scan(struct wpi_softc *sc)
25586607310bSBenjamin Close {
2559b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
2560b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
256182f1b132SAndrew Thompson 	struct ieee80211_scan_state *ss = ic->ic_scan;
25626607310bSBenjamin Close 	struct wpi_tx_ring *ring = &sc->cmdq;
25636607310bSBenjamin Close 	struct wpi_tx_desc *desc;
25646607310bSBenjamin Close 	struct wpi_tx_data *data;
25656607310bSBenjamin Close 	struct wpi_tx_cmd *cmd;
25666607310bSBenjamin Close 	struct wpi_scan_hdr *hdr;
25676607310bSBenjamin Close 	struct wpi_scan_chan *chan;
25686607310bSBenjamin Close 	struct ieee80211_frame *wh;
25696607310bSBenjamin Close 	struct ieee80211_rateset *rs;
25706607310bSBenjamin Close 	struct ieee80211_channel *c;
25716607310bSBenjamin Close 	enum ieee80211_phymode mode;
25726607310bSBenjamin Close 	uint8_t *frm;
257382f1b132SAndrew Thompson 	int nrates, pktlen, error, i, nssid;
25746607310bSBenjamin Close 	bus_addr_t physaddr;
25756607310bSBenjamin Close 
25766607310bSBenjamin Close 	desc = &ring->desc[ring->cur];
25776607310bSBenjamin Close 	data = &ring->data[ring->cur];
25786607310bSBenjamin Close 
2579c6499eccSGleb Smirnoff 	data->m = m_getcl(M_NOWAIT, MT_DATA, M_PKTHDR);
25806607310bSBenjamin Close 	if (data->m == NULL) {
25816607310bSBenjamin Close 		device_printf(sc->sc_dev,
25826607310bSBenjamin Close 		    "could not allocate mbuf for scan command\n");
25836607310bSBenjamin Close 		return ENOMEM;
25846607310bSBenjamin Close 	}
25856607310bSBenjamin Close 
25866607310bSBenjamin Close 	cmd = mtod(data->m, struct wpi_tx_cmd *);
25876607310bSBenjamin Close 	cmd->code = WPI_CMD_SCAN;
25886607310bSBenjamin Close 	cmd->flags = 0;
25896607310bSBenjamin Close 	cmd->qid = ring->qid;
25906607310bSBenjamin Close 	cmd->idx = ring->cur;
25916607310bSBenjamin Close 
25926607310bSBenjamin Close 	hdr = (struct wpi_scan_hdr *)cmd->data;
25936607310bSBenjamin Close 	memset(hdr, 0, sizeof(struct wpi_scan_hdr));
25946607310bSBenjamin Close 
25956607310bSBenjamin Close 	/*
25966607310bSBenjamin Close 	 * Move to the next channel if no packets are received within 5 msecs
25976607310bSBenjamin Close 	 * after sending the probe request (this helps to reduce the duration
25986607310bSBenjamin Close 	 * of active scans).
25996607310bSBenjamin Close 	 */
26006607310bSBenjamin Close 	hdr->quiet = htole16(5);
26016607310bSBenjamin Close 	hdr->threshold = htole16(1);
26026607310bSBenjamin Close 
26036607310bSBenjamin Close 	if (IEEE80211_IS_CHAN_A(ic->ic_curchan)) {
26046607310bSBenjamin Close 		/* send probe requests at 6Mbps */
26056607310bSBenjamin Close 		hdr->tx.rate = wpi_ridx_to_plcp[WPI_OFDM6];
26066607310bSBenjamin Close 
26076607310bSBenjamin Close 		/* Enable crc checking */
26086607310bSBenjamin Close 		hdr->promotion = htole16(1);
26096607310bSBenjamin Close 	} else {
26106607310bSBenjamin Close 		hdr->flags = htole32(WPI_CONFIG_24GHZ | WPI_CONFIG_AUTO);
26116607310bSBenjamin Close 		/* send probe requests at 1Mbps */
26126607310bSBenjamin Close 		hdr->tx.rate = wpi_ridx_to_plcp[WPI_CCK1];
26136607310bSBenjamin Close 	}
26146607310bSBenjamin Close 	hdr->tx.id = WPI_ID_BROADCAST;
26156607310bSBenjamin Close 	hdr->tx.lifetime = htole32(WPI_LIFETIME_INFINITE);
26166607310bSBenjamin Close 	hdr->tx.flags = htole32(WPI_TX_AUTO_SEQ);
26176607310bSBenjamin Close 
2618b032f27cSSam Leffler 	memset(hdr->scan_essids, 0, sizeof(hdr->scan_essids));
261982f1b132SAndrew Thompson 	nssid = MIN(ss->ss_nssid, WPI_SCAN_MAX_ESSIDS);
262082f1b132SAndrew Thompson 	for (i = 0; i < nssid; i++) {
262182f1b132SAndrew Thompson 		hdr->scan_essids[i].id = IEEE80211_ELEMID_SSID;
262282f1b132SAndrew Thompson 		hdr->scan_essids[i].esslen = MIN(ss->ss_ssid[i].len, 32);
262382f1b132SAndrew Thompson 		memcpy(hdr->scan_essids[i].essid, ss->ss_ssid[i].ssid,
262482f1b132SAndrew Thompson 		    hdr->scan_essids[i].esslen);
26256845408dSAndrew Thompson #ifdef WPI_DEBUG
26266607310bSBenjamin Close 		if (wpi_debug & WPI_DEBUG_SCANNING) {
26276607310bSBenjamin Close 			printf("Scanning Essid: ");
2628b032f27cSSam Leffler 			ieee80211_print_essid(hdr->scan_essids[i].essid,
2629b032f27cSSam Leffler 			    hdr->scan_essids[i].esslen);
26306607310bSBenjamin Close 			printf("\n");
26316607310bSBenjamin Close 		}
26326845408dSAndrew Thompson #endif
263382f1b132SAndrew Thompson 	}
26346607310bSBenjamin Close 
26356607310bSBenjamin Close 	/*
26366607310bSBenjamin Close 	 * Build a probe request frame.  Most of the following code is a
26376607310bSBenjamin Close 	 * copy & paste of what is done in net80211.
26386607310bSBenjamin Close 	 */
26396607310bSBenjamin Close 	wh = (struct ieee80211_frame *)&hdr->scan_essids[4];
26406607310bSBenjamin Close 	wh->i_fc[0] = IEEE80211_FC0_VERSION_0 | IEEE80211_FC0_TYPE_MGT |
26416607310bSBenjamin Close 		IEEE80211_FC0_SUBTYPE_PROBE_REQ;
26426607310bSBenjamin Close 	wh->i_fc[1] = IEEE80211_FC1_DIR_NODS;
26436607310bSBenjamin Close 	IEEE80211_ADDR_COPY(wh->i_addr1, ifp->if_broadcastaddr);
264429aca940SSam Leffler 	IEEE80211_ADDR_COPY(wh->i_addr2, IF_LLADDR(ifp));
26456607310bSBenjamin Close 	IEEE80211_ADDR_COPY(wh->i_addr3, ifp->if_broadcastaddr);
26466607310bSBenjamin Close 	*(u_int16_t *)&wh->i_dur[0] = 0;	/* filled by h/w */
26476607310bSBenjamin Close 	*(u_int16_t *)&wh->i_seq[0] = 0;	/* filled by h/w */
26486607310bSBenjamin Close 
26496607310bSBenjamin Close 	frm = (uint8_t *)(wh + 1);
26506607310bSBenjamin Close 
26516607310bSBenjamin Close 	/* add essid IE, the hardware will fill this in for us */
26526607310bSBenjamin Close 	*frm++ = IEEE80211_ELEMID_SSID;
26536607310bSBenjamin Close 	*frm++ = 0;
26546607310bSBenjamin Close 
26556607310bSBenjamin Close 	mode = ieee80211_chan2mode(ic->ic_curchan);
26566607310bSBenjamin Close 	rs = &ic->ic_sup_rates[mode];
26576607310bSBenjamin Close 
26586607310bSBenjamin Close 	/* add supported rates IE */
26596607310bSBenjamin Close 	*frm++ = IEEE80211_ELEMID_RATES;
26606607310bSBenjamin Close 	nrates = rs->rs_nrates;
26616607310bSBenjamin Close 	if (nrates > IEEE80211_RATE_SIZE)
26626607310bSBenjamin Close 		nrates = IEEE80211_RATE_SIZE;
26636607310bSBenjamin Close 	*frm++ = nrates;
26646607310bSBenjamin Close 	memcpy(frm, rs->rs_rates, nrates);
26656607310bSBenjamin Close 	frm += nrates;
26666607310bSBenjamin Close 
26676607310bSBenjamin Close 	/* add supported xrates IE */
26686607310bSBenjamin Close 	if (rs->rs_nrates > IEEE80211_RATE_SIZE) {
26696607310bSBenjamin Close 		nrates = rs->rs_nrates - IEEE80211_RATE_SIZE;
26706607310bSBenjamin Close 		*frm++ = IEEE80211_ELEMID_XRATES;
26716607310bSBenjamin Close 		*frm++ = nrates;
26726607310bSBenjamin Close 		memcpy(frm, rs->rs_rates + IEEE80211_RATE_SIZE, nrates);
26736607310bSBenjamin Close 		frm += nrates;
26746607310bSBenjamin Close 	}
26756607310bSBenjamin Close 
26766607310bSBenjamin Close 	/* setup length of probe request */
26776607310bSBenjamin Close 	hdr->tx.len = htole16(frm - (uint8_t *)wh);
26786607310bSBenjamin Close 
26796607310bSBenjamin Close 	/*
26806607310bSBenjamin Close 	 * Construct information about the channel that we
26816607310bSBenjamin Close 	 * want to scan. The firmware expects this to be directly
26826607310bSBenjamin Close 	 * after the scan probe request
26836607310bSBenjamin Close 	 */
26846607310bSBenjamin Close 	c = ic->ic_curchan;
26856607310bSBenjamin Close 	chan = (struct wpi_scan_chan *)frm;
26866607310bSBenjamin Close 	chan->chan = ieee80211_chan2ieee(ic, c);
26876607310bSBenjamin Close 	chan->flags = 0;
26886607310bSBenjamin Close 	if (!(c->ic_flags & IEEE80211_CHAN_PASSIVE)) {
26896607310bSBenjamin Close 		chan->flags |= WPI_CHAN_ACTIVE;
2690b032f27cSSam Leffler 		if (nssid != 0)
26916607310bSBenjamin Close 			chan->flags |= WPI_CHAN_DIRECT;
26926607310bSBenjamin Close 	}
26936607310bSBenjamin Close 	chan->gain_dsp = 0x6e; /* Default level */
26946607310bSBenjamin Close 	if (IEEE80211_IS_CHAN_5GHZ(c)) {
26956607310bSBenjamin Close 		chan->active = htole16(10);
2696b032f27cSSam Leffler 		chan->passive = htole16(ss->ss_maxdwell);
26976607310bSBenjamin Close 		chan->gain_radio = 0x3b;
26986607310bSBenjamin Close 	} else {
26996607310bSBenjamin Close 		chan->active = htole16(20);
2700b032f27cSSam Leffler 		chan->passive = htole16(ss->ss_maxdwell);
27016607310bSBenjamin Close 		chan->gain_radio = 0x28;
27026607310bSBenjamin Close 	}
27036607310bSBenjamin Close 
27046607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_SCANNING,
27056607310bSBenjamin Close 	    ("Scanning %u Passive: %d\n",
27066607310bSBenjamin Close 	     chan->chan,
27076607310bSBenjamin Close 	     c->ic_flags & IEEE80211_CHAN_PASSIVE));
27086607310bSBenjamin Close 
27096607310bSBenjamin Close 	hdr->nchan++;
27106607310bSBenjamin Close 	chan++;
27116607310bSBenjamin Close 
27126607310bSBenjamin Close 	frm += sizeof (struct wpi_scan_chan);
27136607310bSBenjamin Close #if 0
27146607310bSBenjamin Close 	// XXX All Channels....
27156607310bSBenjamin Close 	for (c  = &ic->ic_channels[1];
27166607310bSBenjamin Close 	     c <= &ic->ic_channels[IEEE80211_CHAN_MAX]; c++) {
27176607310bSBenjamin Close 		if ((c->ic_flags & ic->ic_curchan->ic_flags) != ic->ic_curchan->ic_flags)
27186607310bSBenjamin Close 			continue;
27196607310bSBenjamin Close 
27206607310bSBenjamin Close 		chan->chan = ieee80211_chan2ieee(ic, c);
27216607310bSBenjamin Close 		chan->flags = 0;
27226607310bSBenjamin Close 		if (!(c->ic_flags & IEEE80211_CHAN_PASSIVE)) {
27236607310bSBenjamin Close 		    chan->flags |= WPI_CHAN_ACTIVE;
27246607310bSBenjamin Close 		    if (ic->ic_des_ssid[0].len != 0)
27256607310bSBenjamin Close 			chan->flags |= WPI_CHAN_DIRECT;
27266607310bSBenjamin Close 		}
27276607310bSBenjamin Close 		chan->gain_dsp = 0x6e; /* Default level */
27286607310bSBenjamin Close 		if (IEEE80211_IS_CHAN_5GHZ(c)) {
27296607310bSBenjamin Close 			chan->active = htole16(10);
27306607310bSBenjamin Close 			chan->passive = htole16(110);
27316607310bSBenjamin Close 			chan->gain_radio = 0x3b;
27326607310bSBenjamin Close 		} else {
27336607310bSBenjamin Close 			chan->active = htole16(20);
27346607310bSBenjamin Close 			chan->passive = htole16(120);
27356607310bSBenjamin Close 			chan->gain_radio = 0x28;
27366607310bSBenjamin Close 		}
27376607310bSBenjamin Close 
27386607310bSBenjamin Close 		DPRINTFN(WPI_DEBUG_SCANNING,
27396607310bSBenjamin Close 			 ("Scanning %u Passive: %d\n",
27406607310bSBenjamin Close 			  chan->chan,
27416607310bSBenjamin Close 			  c->ic_flags & IEEE80211_CHAN_PASSIVE));
27426607310bSBenjamin Close 
27436607310bSBenjamin Close 		hdr->nchan++;
27446607310bSBenjamin Close 		chan++;
27456607310bSBenjamin Close 
27466607310bSBenjamin Close 		frm += sizeof (struct wpi_scan_chan);
27476607310bSBenjamin Close 	}
27486607310bSBenjamin Close #endif
27496607310bSBenjamin Close 
27506607310bSBenjamin Close 	hdr->len = htole16(frm - (uint8_t *)hdr);
27516607310bSBenjamin Close 	pktlen = frm - (uint8_t *)cmd;
27526607310bSBenjamin Close 
27536607310bSBenjamin Close 	error = bus_dmamap_load(ring->data_dmat, data->map, cmd, pktlen,
27546607310bSBenjamin Close 	    wpi_dma_map_addr, &physaddr, BUS_DMA_NOWAIT);
27556607310bSBenjamin Close 	if (error != 0) {
27566607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not map scan command\n");
27576607310bSBenjamin Close 		m_freem(data->m);
27586607310bSBenjamin Close 		data->m = NULL;
27596607310bSBenjamin Close 		return error;
27606607310bSBenjamin Close 	}
27616607310bSBenjamin Close 
27626607310bSBenjamin Close 	desc->flags = htole32(WPI_PAD32(pktlen) << 28 | 1 << 24);
27636607310bSBenjamin Close 	desc->segs[0].addr = htole32(physaddr);
27646607310bSBenjamin Close 	desc->segs[0].len  = htole32(pktlen);
27656607310bSBenjamin Close 
27666607310bSBenjamin Close 	bus_dmamap_sync(ring->desc_dma.tag, ring->desc_dma.map,
27676607310bSBenjamin Close 	    BUS_DMASYNC_PREWRITE);
27686607310bSBenjamin Close 	bus_dmamap_sync(ring->data_dmat, data->map, BUS_DMASYNC_PREWRITE);
27696607310bSBenjamin Close 
27706607310bSBenjamin Close 	/* kick cmd ring */
27716607310bSBenjamin Close 	ring->cur = (ring->cur + 1) % WPI_CMD_RING_COUNT;
27726607310bSBenjamin Close 	WPI_WRITE(sc, WPI_TX_WIDX, ring->qid << 8 | ring->cur);
27736607310bSBenjamin Close 
277482f1b132SAndrew Thompson 	sc->sc_scan_timer = 5;
27756607310bSBenjamin Close 	return 0;	/* will be notified async. of failure/success */
27766607310bSBenjamin Close }
27776607310bSBenjamin Close 
27786607310bSBenjamin Close /**
27796607310bSBenjamin Close  * Configure the card to listen to a particular channel, this transisions the
27806607310bSBenjamin Close  * card in to being able to receive frames from remote devices.
27816607310bSBenjamin Close  */
27826607310bSBenjamin Close static int
27836607310bSBenjamin Close wpi_config(struct wpi_softc *sc)
27846607310bSBenjamin Close {
2785b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
2786b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
27876607310bSBenjamin Close 	struct wpi_power power;
27886607310bSBenjamin Close 	struct wpi_bluetooth bluetooth;
27896607310bSBenjamin Close 	struct wpi_node_info node;
27906607310bSBenjamin Close 	int error;
27916607310bSBenjamin Close 
27926607310bSBenjamin Close 	/* set power mode */
27936607310bSBenjamin Close 	memset(&power, 0, sizeof power);
27946607310bSBenjamin Close 	power.flags = htole32(WPI_POWER_CAM|0x8);
27956607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_SET_POWER_MODE, &power, sizeof power, 0);
27966607310bSBenjamin Close 	if (error != 0) {
27976607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not set power mode\n");
27986607310bSBenjamin Close 		return error;
27996607310bSBenjamin Close 	}
28006607310bSBenjamin Close 
28016607310bSBenjamin Close 	/* configure bluetooth coexistence */
28026607310bSBenjamin Close 	memset(&bluetooth, 0, sizeof bluetooth);
28036607310bSBenjamin Close 	bluetooth.flags = 3;
28046607310bSBenjamin Close 	bluetooth.lead = 0xaa;
28056607310bSBenjamin Close 	bluetooth.kill = 1;
28066607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_BLUETOOTH, &bluetooth, sizeof bluetooth,
28076607310bSBenjamin Close 	    0);
28086607310bSBenjamin Close 	if (error != 0) {
28096607310bSBenjamin Close 		device_printf(sc->sc_dev,
28106607310bSBenjamin Close 		    "could not configure bluetooth coexistence\n");
28116607310bSBenjamin Close 		return error;
28126607310bSBenjamin Close 	}
28136607310bSBenjamin Close 
28146607310bSBenjamin Close 	/* configure adapter */
28156607310bSBenjamin Close 	memset(&sc->config, 0, sizeof (struct wpi_config));
281629aca940SSam Leffler 	IEEE80211_ADDR_COPY(sc->config.myaddr, IF_LLADDR(ifp));
28176607310bSBenjamin Close 	/*set default channel*/
28186607310bSBenjamin Close 	sc->config.chan = htole16(ieee80211_chan2ieee(ic, ic->ic_curchan));
28196607310bSBenjamin Close 	sc->config.flags = htole32(WPI_CONFIG_TSF);
28206607310bSBenjamin Close 	if (IEEE80211_IS_CHAN_2GHZ(ic->ic_curchan)) {
28216607310bSBenjamin Close 		sc->config.flags |= htole32(WPI_CONFIG_AUTO |
28226607310bSBenjamin Close 		    WPI_CONFIG_24GHZ);
28236607310bSBenjamin Close 	}
28246607310bSBenjamin Close 	sc->config.filter = 0;
28256607310bSBenjamin Close 	switch (ic->ic_opmode) {
28266607310bSBenjamin Close 	case IEEE80211_M_STA:
28276607310bSBenjamin Close 	case IEEE80211_M_WDS:	/* No know setup, use STA for now */
28286607310bSBenjamin Close 		sc->config.mode = WPI_MODE_STA;
28296607310bSBenjamin Close 		sc->config.filter |= htole32(WPI_FILTER_MULTICAST);
28306607310bSBenjamin Close 		break;
28316607310bSBenjamin Close 	case IEEE80211_M_IBSS:
28326607310bSBenjamin Close 	case IEEE80211_M_AHDEMO:
28336607310bSBenjamin Close 		sc->config.mode = WPI_MODE_IBSS;
28346607310bSBenjamin Close 		sc->config.filter |= htole32(WPI_FILTER_BEACON |
28356607310bSBenjamin Close 					     WPI_FILTER_MULTICAST);
28366607310bSBenjamin Close 		break;
28376607310bSBenjamin Close 	case IEEE80211_M_HOSTAP:
28386607310bSBenjamin Close 		sc->config.mode = WPI_MODE_HOSTAP;
28396607310bSBenjamin Close 		break;
28406607310bSBenjamin Close 	case IEEE80211_M_MONITOR:
28416607310bSBenjamin Close 		sc->config.mode = WPI_MODE_MONITOR;
28426607310bSBenjamin Close 		sc->config.filter |= htole32(WPI_FILTER_MULTICAST |
28436607310bSBenjamin Close 			WPI_FILTER_CTL | WPI_FILTER_PROMISC);
28446607310bSBenjamin Close 		break;
2845820e6a1fSRui Paulo 	default:
2846820e6a1fSRui Paulo 		device_printf(sc->sc_dev, "unknown opmode %d\n", ic->ic_opmode);
2847820e6a1fSRui Paulo 		return EINVAL;
28486607310bSBenjamin Close 	}
28496607310bSBenjamin Close 	sc->config.cck_mask  = 0x0f;	/* not yet negotiated */
28506607310bSBenjamin Close 	sc->config.ofdm_mask = 0xff;	/* not yet negotiated */
28516607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_CONFIGURE, &sc->config,
28526607310bSBenjamin Close 		sizeof (struct wpi_config), 0);
28536607310bSBenjamin Close 	if (error != 0) {
28546607310bSBenjamin Close 		device_printf(sc->sc_dev, "configure command failed\n");
28556607310bSBenjamin Close 		return error;
28566607310bSBenjamin Close 	}
28576607310bSBenjamin Close 
28586607310bSBenjamin Close 	/* configuration has changed, set Tx power accordingly */
28596607310bSBenjamin Close 	if ((error = wpi_set_txpower(sc, ic->ic_curchan, 0)) != 0) {
28606607310bSBenjamin Close 	    device_printf(sc->sc_dev, "could not set Tx power\n");
28616607310bSBenjamin Close 	    return error;
28626607310bSBenjamin Close 	}
28636607310bSBenjamin Close 
28646607310bSBenjamin Close 	/* add broadcast node */
28656607310bSBenjamin Close 	memset(&node, 0, sizeof node);
28666607310bSBenjamin Close 	IEEE80211_ADDR_COPY(node.bssid, ifp->if_broadcastaddr);
28676607310bSBenjamin Close 	node.id = WPI_ID_BROADCAST;
28686607310bSBenjamin Close 	node.rate = wpi_plcp_signal(2);
28696607310bSBenjamin Close 	error = wpi_cmd(sc, WPI_CMD_ADD_NODE, &node, sizeof node, 0);
28706607310bSBenjamin Close 	if (error != 0) {
28716607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not add broadcast node\n");
28726607310bSBenjamin Close 		return error;
28736607310bSBenjamin Close 	}
28746607310bSBenjamin Close 
28756607310bSBenjamin Close 	/* Setup rate scalling */
28766607310bSBenjamin Close 	error = wpi_mrr_setup(sc);
28776607310bSBenjamin Close 	if (error != 0) {
28786607310bSBenjamin Close 		device_printf(sc->sc_dev, "could not setup MRR\n");
28796607310bSBenjamin Close 		return error;
28806607310bSBenjamin Close 	}
28816607310bSBenjamin Close 
28826607310bSBenjamin Close 	return 0;
28836607310bSBenjamin Close }
28846607310bSBenjamin Close 
28856607310bSBenjamin Close static void
28866607310bSBenjamin Close wpi_stop_master(struct wpi_softc *sc)
28876607310bSBenjamin Close {
28886607310bSBenjamin Close 	uint32_t tmp;
28896607310bSBenjamin Close 	int ntries;
28906607310bSBenjamin Close 
28916607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_HW,("Disabling Firmware execution\n"));
28926607310bSBenjamin Close 
28936607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_RESET);
28946607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RESET, tmp | WPI_STOP_MASTER | WPI_NEVO_RESET);
28956607310bSBenjamin Close 
28966607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_GPIO_CTL);
28976607310bSBenjamin Close 	if ((tmp & WPI_GPIO_PWR_STATUS) == WPI_GPIO_PWR_SLEEP)
28986607310bSBenjamin Close 		return;	/* already asleep */
28996607310bSBenjamin Close 
29006607310bSBenjamin Close 	for (ntries = 0; ntries < 100; ntries++) {
29016607310bSBenjamin Close 		if (WPI_READ(sc, WPI_RESET) & WPI_MASTER_DISABLED)
29026607310bSBenjamin Close 			break;
29036607310bSBenjamin Close 		DELAY(10);
29046607310bSBenjamin Close 	}
29056607310bSBenjamin Close 	if (ntries == 100) {
29066607310bSBenjamin Close 		device_printf(sc->sc_dev, "timeout waiting for master\n");
29076607310bSBenjamin Close 	}
29086607310bSBenjamin Close }
29096607310bSBenjamin Close 
29106607310bSBenjamin Close static int
29116607310bSBenjamin Close wpi_power_up(struct wpi_softc *sc)
29126607310bSBenjamin Close {
29136607310bSBenjamin Close 	uint32_t tmp;
29146607310bSBenjamin Close 	int ntries;
29156607310bSBenjamin Close 
29166607310bSBenjamin Close 	wpi_mem_lock(sc);
29176607310bSBenjamin Close 	tmp = wpi_mem_read(sc, WPI_MEM_POWER);
29186607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_POWER, tmp & ~0x03000000);
29196607310bSBenjamin Close 	wpi_mem_unlock(sc);
29206607310bSBenjamin Close 
29216607310bSBenjamin Close 	for (ntries = 0; ntries < 5000; ntries++) {
29226607310bSBenjamin Close 		if (WPI_READ(sc, WPI_GPIO_STATUS) & WPI_POWERED)
29236607310bSBenjamin Close 			break;
29246607310bSBenjamin Close 		DELAY(10);
29256607310bSBenjamin Close 	}
29266607310bSBenjamin Close 	if (ntries == 5000) {
29276607310bSBenjamin Close 		device_printf(sc->sc_dev,
29286607310bSBenjamin Close 		    "timeout waiting for NIC to power up\n");
29296607310bSBenjamin Close 		return ETIMEDOUT;
29306607310bSBenjamin Close 	}
29316607310bSBenjamin Close 	return 0;
29326607310bSBenjamin Close }
29336607310bSBenjamin Close 
29346607310bSBenjamin Close static int
29356607310bSBenjamin Close wpi_reset(struct wpi_softc *sc)
29366607310bSBenjamin Close {
29376607310bSBenjamin Close 	uint32_t tmp;
29386607310bSBenjamin Close 	int ntries;
29396607310bSBenjamin Close 
29406607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_HW,
29416607310bSBenjamin Close 	    ("Resetting the card - clearing any uploaded firmware\n"));
29426607310bSBenjamin Close 
29436607310bSBenjamin Close 	/* clear any pending interrupts */
29446607310bSBenjamin Close 	WPI_WRITE(sc, WPI_INTR, 0xffffffff);
29456607310bSBenjamin Close 
29466607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_PLL_CTL);
29476607310bSBenjamin Close 	WPI_WRITE(sc, WPI_PLL_CTL, tmp | WPI_PLL_INIT);
29486607310bSBenjamin Close 
29496607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_CHICKEN);
29506607310bSBenjamin Close 	WPI_WRITE(sc, WPI_CHICKEN, tmp | WPI_CHICKEN_RXNOLOS);
29516607310bSBenjamin Close 
29526607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_GPIO_CTL);
29536607310bSBenjamin Close 	WPI_WRITE(sc, WPI_GPIO_CTL, tmp | WPI_GPIO_INIT);
29546607310bSBenjamin Close 
29556607310bSBenjamin Close 	/* wait for clock stabilization */
29566607310bSBenjamin Close 	for (ntries = 0; ntries < 25000; ntries++) {
29576607310bSBenjamin Close 		if (WPI_READ(sc, WPI_GPIO_CTL) & WPI_GPIO_CLOCK)
29586607310bSBenjamin Close 			break;
29596607310bSBenjamin Close 		DELAY(10);
29606607310bSBenjamin Close 	}
29616607310bSBenjamin Close 	if (ntries == 25000) {
29626607310bSBenjamin Close 		device_printf(sc->sc_dev,
29636607310bSBenjamin Close 		    "timeout waiting for clock stabilization\n");
29646607310bSBenjamin Close 		return ETIMEDOUT;
29656607310bSBenjamin Close 	}
29666607310bSBenjamin Close 
29676607310bSBenjamin Close 	/* initialize EEPROM */
29686607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_EEPROM_STATUS);
29696607310bSBenjamin Close 
29706607310bSBenjamin Close 	if ((tmp & WPI_EEPROM_VERSION) == 0) {
29716607310bSBenjamin Close 		device_printf(sc->sc_dev, "EEPROM not found\n");
29726607310bSBenjamin Close 		return EIO;
29736607310bSBenjamin Close 	}
29746607310bSBenjamin Close 	WPI_WRITE(sc, WPI_EEPROM_STATUS, tmp & ~WPI_EEPROM_LOCKED);
29756607310bSBenjamin Close 
29766607310bSBenjamin Close 	return 0;
29776607310bSBenjamin Close }
29786607310bSBenjamin Close 
29796607310bSBenjamin Close static void
29806607310bSBenjamin Close wpi_hw_config(struct wpi_softc *sc)
29816607310bSBenjamin Close {
29826607310bSBenjamin Close 	uint32_t rev, hw;
29836607310bSBenjamin Close 
29846607310bSBenjamin Close 	/* voodoo from the Linux "driver".. */
29856607310bSBenjamin Close 	hw = WPI_READ(sc, WPI_HWCONFIG);
29866607310bSBenjamin Close 
29876607310bSBenjamin Close 	rev = pci_read_config(sc->sc_dev, PCIR_REVID, 1);
29886607310bSBenjamin Close 	if ((rev & 0xc0) == 0x40)
29896607310bSBenjamin Close 		hw |= WPI_HW_ALM_MB;
29906607310bSBenjamin Close 	else if (!(rev & 0x80))
29916607310bSBenjamin Close 		hw |= WPI_HW_ALM_MM;
29926607310bSBenjamin Close 
29936607310bSBenjamin Close 	if (sc->cap == 0x80)
29946607310bSBenjamin Close 		hw |= WPI_HW_SKU_MRC;
29956607310bSBenjamin Close 
29966607310bSBenjamin Close 	hw &= ~WPI_HW_REV_D;
29976607310bSBenjamin Close 	if ((le16toh(sc->rev) & 0xf0) == 0xd0)
29986607310bSBenjamin Close 		hw |= WPI_HW_REV_D;
29996607310bSBenjamin Close 
30006607310bSBenjamin Close 	if (sc->type > 1)
30016607310bSBenjamin Close 		hw |= WPI_HW_TYPE_B;
30026607310bSBenjamin Close 
30036607310bSBenjamin Close 	WPI_WRITE(sc, WPI_HWCONFIG, hw);
30046607310bSBenjamin Close }
30056607310bSBenjamin Close 
30066607310bSBenjamin Close static void
300782f1b132SAndrew Thompson wpi_rfkill_resume(struct wpi_softc *sc)
300882f1b132SAndrew Thompson {
300982f1b132SAndrew Thompson 	struct ifnet *ifp = sc->sc_ifp;
3010b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
3011b032f27cSSam Leffler 	struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
301282f1b132SAndrew Thompson 	int ntries;
301382f1b132SAndrew Thompson 
301482f1b132SAndrew Thompson 	/* enable firmware again */
301582f1b132SAndrew Thompson 	WPI_WRITE(sc, WPI_UCODE_CLR, WPI_RADIO_OFF);
301682f1b132SAndrew Thompson 	WPI_WRITE(sc, WPI_UCODE_CLR, WPI_DISABLE_CMD);
301782f1b132SAndrew Thompson 
301882f1b132SAndrew Thompson 	/* wait for thermal sensors to calibrate */
301982f1b132SAndrew Thompson 	for (ntries = 0; ntries < 1000; ntries++) {
302082f1b132SAndrew Thompson 		if ((sc->temp = (int)WPI_READ(sc, WPI_TEMPERATURE)) != 0)
302182f1b132SAndrew Thompson 			break;
302282f1b132SAndrew Thompson 		DELAY(10);
302382f1b132SAndrew Thompson 	}
302482f1b132SAndrew Thompson 
302582f1b132SAndrew Thompson 	if (ntries == 1000) {
302682f1b132SAndrew Thompson 		device_printf(sc->sc_dev,
302782f1b132SAndrew Thompson 		    "timeout waiting for thermal calibration\n");
302882f1b132SAndrew Thompson 		return;
302982f1b132SAndrew Thompson 	}
303082f1b132SAndrew Thompson 	DPRINTFN(WPI_DEBUG_TEMP,("temperature %d\n", sc->temp));
303182f1b132SAndrew Thompson 
303282f1b132SAndrew Thompson 	if (wpi_config(sc) != 0) {
303382f1b132SAndrew Thompson 		device_printf(sc->sc_dev, "device config failed\n");
303482f1b132SAndrew Thompson 		return;
303582f1b132SAndrew Thompson 	}
303682f1b132SAndrew Thompson 
303782f1b132SAndrew Thompson 	ifp->if_drv_flags &= ~IFF_DRV_OACTIVE;
303882f1b132SAndrew Thompson 	ifp->if_drv_flags |= IFF_DRV_RUNNING;
303982f1b132SAndrew Thompson 	sc->flags &= ~WPI_FLAG_HW_RADIO_OFF;
304082f1b132SAndrew Thompson 
3041b032f27cSSam Leffler 	if (vap != NULL) {
3042b032f27cSSam Leffler 		if ((ic->ic_flags & IEEE80211_F_SCAN) == 0) {
3043b032f27cSSam Leffler 			if (vap->iv_opmode != IEEE80211_M_MONITOR) {
30445efea30fSAndrew Thompson 				ieee80211_beacon_miss(ic);
304582f1b132SAndrew Thompson 				wpi_set_led(sc, WPI_LED_LINK, 0, 1);
3046b032f27cSSam Leffler 			} else
3047b032f27cSSam Leffler 				wpi_set_led(sc, WPI_LED_LINK, 5, 5);
3048b032f27cSSam Leffler 		} else {
3049b032f27cSSam Leffler 			ieee80211_scan_next(vap);
3050b032f27cSSam Leffler 			wpi_set_led(sc, WPI_LED_LINK, 20, 2);
3051b032f27cSSam Leffler 		}
305282f1b132SAndrew Thompson 	}
305382f1b132SAndrew Thompson 
305482f1b132SAndrew Thompson 	callout_reset(&sc->watchdog_to, hz, wpi_watchdog, sc);
305582f1b132SAndrew Thompson }
305682f1b132SAndrew Thompson 
305782f1b132SAndrew Thompson static void
305882f1b132SAndrew Thompson wpi_init_locked(struct wpi_softc *sc, int force)
305982f1b132SAndrew Thompson {
3060b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
30616607310bSBenjamin Close 	uint32_t tmp;
306282f1b132SAndrew Thompson 	int ntries, qid;
30636607310bSBenjamin Close 
30646607310bSBenjamin Close 	wpi_stop_locked(sc);
30656607310bSBenjamin Close 	(void)wpi_reset(sc);
30666607310bSBenjamin Close 
30676607310bSBenjamin Close 	wpi_mem_lock(sc);
30686607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_CLOCK1, 0xa00);
30696607310bSBenjamin Close 	DELAY(20);
30706607310bSBenjamin Close 	tmp = wpi_mem_read(sc, WPI_MEM_PCIDEV);
30716607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_PCIDEV, tmp | 0x800);
30726607310bSBenjamin Close 	wpi_mem_unlock(sc);
30736607310bSBenjamin Close 
30746607310bSBenjamin Close 	(void)wpi_power_up(sc);
30756607310bSBenjamin Close 	wpi_hw_config(sc);
30766607310bSBenjamin Close 
30776607310bSBenjamin Close 	/* init Rx ring */
30786607310bSBenjamin Close 	wpi_mem_lock(sc);
30796607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RX_BASE, sc->rxq.desc_dma.paddr);
30806607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RX_RIDX_PTR, sc->shared_dma.paddr +
30816607310bSBenjamin Close 	    offsetof(struct wpi_shared, next));
30826607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RX_WIDX, (WPI_RX_RING_COUNT - 1) & ~7);
30836607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RX_CONFIG, 0xa9601010);
30846607310bSBenjamin Close 	wpi_mem_unlock(sc);
30856607310bSBenjamin Close 
30866607310bSBenjamin Close 	/* init Tx rings */
30876607310bSBenjamin Close 	wpi_mem_lock(sc);
30886607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_MODE, 2); /* bypass mode */
30896607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_RA, 1);   /* enable RA0 */
30906607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_TXCFG, 0x3f); /* enable all 6 Tx rings */
30916607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_BYPASS1, 0x10000);
30926607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_BYPASS2, 0x30002);
30936607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_MAGIC4, 4);
30946607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_MAGIC5, 5);
30956607310bSBenjamin Close 
30966607310bSBenjamin Close 	WPI_WRITE(sc, WPI_TX_BASE_PTR, sc->shared_dma.paddr);
30976607310bSBenjamin Close 	WPI_WRITE(sc, WPI_MSG_CONFIG, 0xffff05a5);
30986607310bSBenjamin Close 
30996607310bSBenjamin Close 	for (qid = 0; qid < 6; qid++) {
31006607310bSBenjamin Close 		WPI_WRITE(sc, WPI_TX_CTL(qid), 0);
31016607310bSBenjamin Close 		WPI_WRITE(sc, WPI_TX_BASE(qid), 0);
31026607310bSBenjamin Close 		WPI_WRITE(sc, WPI_TX_CONFIG(qid), 0x80200008);
31036607310bSBenjamin Close 	}
31046607310bSBenjamin Close 	wpi_mem_unlock(sc);
31056607310bSBenjamin Close 
31066607310bSBenjamin Close 	/* clear "radio off" and "disable command" bits (reversed logic) */
31076607310bSBenjamin Close 	WPI_WRITE(sc, WPI_UCODE_CLR, WPI_RADIO_OFF);
31086607310bSBenjamin Close 	WPI_WRITE(sc, WPI_UCODE_CLR, WPI_DISABLE_CMD);
31096607310bSBenjamin Close 	sc->flags &= ~WPI_FLAG_HW_RADIO_OFF;
31106607310bSBenjamin Close 
31116607310bSBenjamin Close 	/* clear any pending interrupts */
31126607310bSBenjamin Close 	WPI_WRITE(sc, WPI_INTR, 0xffffffff);
31136607310bSBenjamin Close 
31146607310bSBenjamin Close 	/* enable interrupts */
31156607310bSBenjamin Close 	WPI_WRITE(sc, WPI_MASK, WPI_INTR_MASK);
31166607310bSBenjamin Close 
31176607310bSBenjamin Close 	WPI_WRITE(sc, WPI_UCODE_CLR, WPI_RADIO_OFF);
31186607310bSBenjamin Close 	WPI_WRITE(sc, WPI_UCODE_CLR, WPI_RADIO_OFF);
31196607310bSBenjamin Close 
312082f1b132SAndrew Thompson 	if ((wpi_load_firmware(sc)) != 0) {
31216607310bSBenjamin Close 	    device_printf(sc->sc_dev,
31226607310bSBenjamin Close 		"A problem occurred loading the firmware to the driver\n");
31236607310bSBenjamin Close 	    return;
31246607310bSBenjamin Close 	}
31256607310bSBenjamin Close 
31266607310bSBenjamin Close 	/* At this point the firmware is up and running. If the hardware
31276607310bSBenjamin Close 	 * RF switch is turned off thermal calibration will fail, though
31286607310bSBenjamin Close 	 * the card is still happy to continue to accept commands, catch
312982f1b132SAndrew Thompson 	 * this case and schedule a task to watch for it to be turned on.
31306607310bSBenjamin Close 	 */
31316607310bSBenjamin Close 	wpi_mem_lock(sc);
31326607310bSBenjamin Close 	tmp = wpi_mem_read(sc, WPI_MEM_HW_RADIO_OFF);
31336607310bSBenjamin Close 	wpi_mem_unlock(sc);
31346607310bSBenjamin Close 
31356607310bSBenjamin Close 	if (!(tmp & 0x1)) {
31366607310bSBenjamin Close 		sc->flags |= WPI_FLAG_HW_RADIO_OFF;
31376607310bSBenjamin Close 		device_printf(sc->sc_dev,"Radio Transmitter is switched off\n");
313882f1b132SAndrew Thompson 		goto out;
31396607310bSBenjamin Close 	}
31406607310bSBenjamin Close 
31416607310bSBenjamin Close 	/* wait for thermal sensors to calibrate */
31426607310bSBenjamin Close 	for (ntries = 0; ntries < 1000; ntries++) {
31436607310bSBenjamin Close 		if ((sc->temp = (int)WPI_READ(sc, WPI_TEMPERATURE)) != 0)
31446607310bSBenjamin Close 			break;
31456607310bSBenjamin Close 		DELAY(10);
31466607310bSBenjamin Close 	}
31476607310bSBenjamin Close 
31486607310bSBenjamin Close 	if (ntries == 1000) {
31496607310bSBenjamin Close 		device_printf(sc->sc_dev,
31506607310bSBenjamin Close 		    "timeout waiting for thermal sensors calibration\n");
31516607310bSBenjamin Close 		return;
31526607310bSBenjamin Close 	}
31536607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_TEMP,("temperature %d\n", sc->temp));
31546607310bSBenjamin Close 
315582f1b132SAndrew Thompson 	if (wpi_config(sc) != 0) {
315682f1b132SAndrew Thompson 		device_printf(sc->sc_dev, "device config failed\n");
315782f1b132SAndrew Thompson 		return;
315882f1b132SAndrew Thompson 	}
315982f1b132SAndrew Thompson 
31606607310bSBenjamin Close 	ifp->if_drv_flags &= ~IFF_DRV_OACTIVE;
31616607310bSBenjamin Close 	ifp->if_drv_flags |= IFF_DRV_RUNNING;
316282f1b132SAndrew Thompson out:
316382f1b132SAndrew Thompson 	callout_reset(&sc->watchdog_to, hz, wpi_watchdog, sc);
31646607310bSBenjamin Close }
31656607310bSBenjamin Close 
31666607310bSBenjamin Close static void
3167b032f27cSSam Leffler wpi_init(void *arg)
31686607310bSBenjamin Close {
3169b032f27cSSam Leffler 	struct wpi_softc *sc = arg;
3170b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
3171b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
31726607310bSBenjamin Close 
31736607310bSBenjamin Close 	WPI_LOCK(sc);
3174b032f27cSSam Leffler 	wpi_init_locked(sc, 0);
31756607310bSBenjamin Close 	WPI_UNLOCK(sc);
31766607310bSBenjamin Close 
3177b032f27cSSam Leffler 	if (ifp->if_drv_flags & IFF_DRV_RUNNING)
3178b032f27cSSam Leffler 		ieee80211_start_all(ic);		/* start all vaps */
31796607310bSBenjamin Close }
3180b032f27cSSam Leffler 
31816607310bSBenjamin Close static void
31826607310bSBenjamin Close wpi_stop_locked(struct wpi_softc *sc)
31836607310bSBenjamin Close {
3184b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
31856607310bSBenjamin Close 	uint32_t tmp;
31866607310bSBenjamin Close 	int ac;
31876607310bSBenjamin Close 
318882f1b132SAndrew Thompson 	sc->sc_tx_timer = 0;
318982f1b132SAndrew Thompson 	sc->sc_scan_timer = 0;
31906607310bSBenjamin Close 	ifp->if_drv_flags &= ~(IFF_DRV_RUNNING | IFF_DRV_OACTIVE);
319182f1b132SAndrew Thompson 	sc->flags &= ~WPI_FLAG_HW_RADIO_OFF;
319282f1b132SAndrew Thompson 	callout_stop(&sc->watchdog_to);
319382f1b132SAndrew Thompson 	callout_stop(&sc->calib_to);
319482f1b132SAndrew Thompson 
31956607310bSBenjamin Close 
31966607310bSBenjamin Close 	/* disable interrupts */
31976607310bSBenjamin Close 	WPI_WRITE(sc, WPI_MASK, 0);
31986607310bSBenjamin Close 	WPI_WRITE(sc, WPI_INTR, WPI_INTR_MASK);
31996607310bSBenjamin Close 	WPI_WRITE(sc, WPI_INTR_STATUS, 0xff);
32006607310bSBenjamin Close 	WPI_WRITE(sc, WPI_INTR_STATUS, 0x00070000);
32016607310bSBenjamin Close 
32026607310bSBenjamin Close 	wpi_mem_lock(sc);
32036607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_MODE, 0);
32046607310bSBenjamin Close 	wpi_mem_unlock(sc);
32056607310bSBenjamin Close 
32066607310bSBenjamin Close 	/* reset all Tx rings */
32076607310bSBenjamin Close 	for (ac = 0; ac < 4; ac++)
32086607310bSBenjamin Close 		wpi_reset_tx_ring(sc, &sc->txq[ac]);
32096607310bSBenjamin Close 	wpi_reset_tx_ring(sc, &sc->cmdq);
32106607310bSBenjamin Close 
32116607310bSBenjamin Close 	/* reset Rx ring */
32126607310bSBenjamin Close 	wpi_reset_rx_ring(sc, &sc->rxq);
32136607310bSBenjamin Close 
32146607310bSBenjamin Close 	wpi_mem_lock(sc);
32156607310bSBenjamin Close 	wpi_mem_write(sc, WPI_MEM_CLOCK2, 0x200);
32166607310bSBenjamin Close 	wpi_mem_unlock(sc);
32176607310bSBenjamin Close 
32186607310bSBenjamin Close 	DELAY(5);
32196607310bSBenjamin Close 
32206607310bSBenjamin Close 	wpi_stop_master(sc);
32216607310bSBenjamin Close 
32226607310bSBenjamin Close 	tmp = WPI_READ(sc, WPI_RESET);
32236607310bSBenjamin Close 	WPI_WRITE(sc, WPI_RESET, tmp | WPI_SW_RESET);
32246607310bSBenjamin Close 	sc->flags &= ~WPI_FLAG_BUSY;
32256607310bSBenjamin Close }
32266607310bSBenjamin Close 
32276607310bSBenjamin Close static void
3228b032f27cSSam Leffler wpi_stop(struct wpi_softc *sc)
32296607310bSBenjamin Close {
3230b032f27cSSam Leffler 	WPI_LOCK(sc);
3231b032f27cSSam Leffler 	wpi_stop_locked(sc);
3232b032f27cSSam Leffler 	WPI_UNLOCK(sc);
32336607310bSBenjamin Close }
32346607310bSBenjamin Close 
32356607310bSBenjamin Close static void
32366607310bSBenjamin Close wpi_calib_timeout(void *arg)
32376607310bSBenjamin Close {
32386607310bSBenjamin Close 	struct wpi_softc *sc = arg;
3239b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
3240b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
3241b032f27cSSam Leffler 	struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
32426607310bSBenjamin Close 	int temp;
324382f1b132SAndrew Thompson 
3244b032f27cSSam Leffler 	if (vap->iv_state != IEEE80211_S_RUN)
324582f1b132SAndrew Thompson 		return;
32466607310bSBenjamin Close 
32476607310bSBenjamin Close 	/* update sensor data */
32486607310bSBenjamin Close 	temp = (int)WPI_READ(sc, WPI_TEMPERATURE);
32496607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_TEMP,("Temp in calibration is: %d\n", temp));
32506607310bSBenjamin Close 
32516607310bSBenjamin Close 	wpi_power_calibration(sc, temp);
32526607310bSBenjamin Close 
3253b032f27cSSam Leffler 	callout_reset(&sc->calib_to, 60*hz, wpi_calib_timeout, sc);
32546607310bSBenjamin Close }
32556607310bSBenjamin Close 
32566607310bSBenjamin Close /*
32576607310bSBenjamin Close  * This function is called periodically (every 60 seconds) to adjust output
32586607310bSBenjamin Close  * power to temperature changes.
32596607310bSBenjamin Close  */
32606607310bSBenjamin Close static void
32616607310bSBenjamin Close wpi_power_calibration(struct wpi_softc *sc, int temp)
32626607310bSBenjamin Close {
3263b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
3264b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
3265b032f27cSSam Leffler 	struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
3266b032f27cSSam Leffler 
32676607310bSBenjamin Close 	/* sanity-check read value */
32686607310bSBenjamin Close 	if (temp < -260 || temp > 25) {
32696607310bSBenjamin Close 		/* this can't be correct, ignore */
32706607310bSBenjamin Close 		DPRINTFN(WPI_DEBUG_TEMP,
32716607310bSBenjamin Close 		    ("out-of-range temperature reported: %d\n", temp));
32726607310bSBenjamin Close 		return;
32736607310bSBenjamin Close 	}
32746607310bSBenjamin Close 
32756607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_TEMP,("temperature %d->%d\n", sc->temp, temp));
32766607310bSBenjamin Close 
32776607310bSBenjamin Close 	/* adjust Tx power if need be */
32786607310bSBenjamin Close 	if (abs(temp - sc->temp) <= 6)
32796607310bSBenjamin Close 		return;
32806607310bSBenjamin Close 
32816607310bSBenjamin Close 	sc->temp = temp;
32826607310bSBenjamin Close 
3283b032f27cSSam Leffler 	if (wpi_set_txpower(sc, vap->iv_bss->ni_chan, 1) != 0) {
32846607310bSBenjamin Close 		/* just warn, too bad for the automatic calibration... */
32856607310bSBenjamin Close 		device_printf(sc->sc_dev,"could not adjust Tx power\n");
32866607310bSBenjamin Close 	}
32876607310bSBenjamin Close }
32886607310bSBenjamin Close 
32896607310bSBenjamin Close /**
32906607310bSBenjamin Close  * Read the eeprom to find out what channels are valid for the given
32916607310bSBenjamin Close  * band and update net80211 with what we find.
32926607310bSBenjamin Close  */
32936607310bSBenjamin Close static void
32946607310bSBenjamin Close wpi_read_eeprom_channels(struct wpi_softc *sc, int n)
32956607310bSBenjamin Close {
3296b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
3297b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
32986607310bSBenjamin Close 	const struct wpi_chan_band *band = &wpi_bands[n];
32996607310bSBenjamin Close 	struct wpi_eeprom_chan channels[WPI_MAX_CHAN_PER_BAND];
33006845408dSAndrew Thompson 	struct ieee80211_channel *c;
33016845408dSAndrew Thompson 	int chan, i, passive;
33026607310bSBenjamin Close 
33036607310bSBenjamin Close 	wpi_read_prom_data(sc, band->addr, channels,
33046607310bSBenjamin Close 	    band->nchan * sizeof (struct wpi_eeprom_chan));
33056607310bSBenjamin Close 
33066607310bSBenjamin Close 	for (i = 0; i < band->nchan; i++) {
33076607310bSBenjamin Close 		if (!(channels[i].flags & WPI_EEPROM_CHAN_VALID)) {
33086607310bSBenjamin Close 			DPRINTFN(WPI_DEBUG_HW,
33096607310bSBenjamin Close 			    ("Channel Not Valid: %d, band %d\n",
33106607310bSBenjamin Close 			     band->chan[i],n));
33116607310bSBenjamin Close 			continue;
33126607310bSBenjamin Close 		}
33136607310bSBenjamin Close 
33146607310bSBenjamin Close 		passive = 0;
33156607310bSBenjamin Close 		chan = band->chan[i];
33166845408dSAndrew Thompson 		c = &ic->ic_channels[ic->ic_nchans++];
33176607310bSBenjamin Close 
33186607310bSBenjamin Close 		/* is active scan allowed on this channel? */
33196607310bSBenjamin Close 		if (!(channels[i].flags & WPI_EEPROM_CHAN_ACTIVE)) {
33206607310bSBenjamin Close 			passive = IEEE80211_CHAN_PASSIVE;
33216607310bSBenjamin Close 		}
33226607310bSBenjamin Close 
33236607310bSBenjamin Close 		if (n == 0) {	/* 2GHz band */
33246845408dSAndrew Thompson 			c->ic_ieee = chan;
33256845408dSAndrew Thompson 			c->ic_freq = ieee80211_ieee2mhz(chan,
33266845408dSAndrew Thompson 			    IEEE80211_CHAN_2GHZ);
33276845408dSAndrew Thompson 			c->ic_flags = IEEE80211_CHAN_B | passive;
33286845408dSAndrew Thompson 
33296845408dSAndrew Thompson 			c = &ic->ic_channels[ic->ic_nchans++];
33306845408dSAndrew Thompson 			c->ic_ieee = chan;
33316845408dSAndrew Thompson 			c->ic_freq = ieee80211_ieee2mhz(chan,
33326845408dSAndrew Thompson 			    IEEE80211_CHAN_2GHZ);
33336845408dSAndrew Thompson 			c->ic_flags = IEEE80211_CHAN_G | passive;
33346607310bSBenjamin Close 
33356607310bSBenjamin Close 		} else {	/* 5GHz band */
33366607310bSBenjamin Close 			/*
33376607310bSBenjamin Close 			 * Some 3945ABG adapters support channels 7, 8, 11
33386607310bSBenjamin Close 			 * and 12 in the 2GHz *and* 5GHz bands.
33396607310bSBenjamin Close 			 * Because of limitations in our net80211(9) stack,
33406607310bSBenjamin Close 			 * we can't support these channels in 5GHz band.
33416607310bSBenjamin Close 			 * XXX not true; just need to map to proper frequency
33426607310bSBenjamin Close 			 */
33436607310bSBenjamin Close 			if (chan <= 14)
33446607310bSBenjamin Close 				continue;
33456607310bSBenjamin Close 
33466845408dSAndrew Thompson 			c->ic_ieee = chan;
33476845408dSAndrew Thompson 			c->ic_freq = ieee80211_ieee2mhz(chan,
33486845408dSAndrew Thompson 			    IEEE80211_CHAN_5GHZ);
33496845408dSAndrew Thompson 			c->ic_flags = IEEE80211_CHAN_A | passive;
33506607310bSBenjamin Close 		}
33516607310bSBenjamin Close 
33526607310bSBenjamin Close 		/* save maximum allowed power for this channel */
33536607310bSBenjamin Close 		sc->maxpwr[chan] = channels[i].maxpwr;
33546607310bSBenjamin Close 
33556607310bSBenjamin Close #if 0
33566607310bSBenjamin Close 		// XXX We can probably use this an get rid of maxpwr - ben 20070617
33576607310bSBenjamin Close 		ic->ic_channels[chan].ic_maxpower = channels[i].maxpwr;
33586607310bSBenjamin Close 		//ic->ic_channels[chan].ic_minpower...
33596607310bSBenjamin Close 		//ic->ic_channels[chan].ic_maxregtxpower...
33606607310bSBenjamin Close #endif
33616607310bSBenjamin Close 
33626845408dSAndrew Thompson 		DPRINTF(("adding chan %d (%dMHz) flags=0x%x maxpwr=%d"
33636845408dSAndrew Thompson 		    " passive=%d, offset %d\n", chan, c->ic_freq,
33646845408dSAndrew Thompson 		    channels[i].flags, sc->maxpwr[chan],
33656845408dSAndrew Thompson 		    (c->ic_flags & IEEE80211_CHAN_PASSIVE) != 0,
33666845408dSAndrew Thompson 		    ic->ic_nchans));
33676607310bSBenjamin Close 	}
33686607310bSBenjamin Close }
33696607310bSBenjamin Close 
33706607310bSBenjamin Close static void
33716607310bSBenjamin Close wpi_read_eeprom_group(struct wpi_softc *sc, int n)
33726607310bSBenjamin Close {
33736607310bSBenjamin Close 	struct wpi_power_group *group = &sc->groups[n];
33746607310bSBenjamin Close 	struct wpi_eeprom_group rgroup;
33756607310bSBenjamin Close 	int i;
33766607310bSBenjamin Close 
33776607310bSBenjamin Close 	wpi_read_prom_data(sc, WPI_EEPROM_POWER_GRP + n * 32, &rgroup,
33786607310bSBenjamin Close 	    sizeof rgroup);
33796607310bSBenjamin Close 
33806607310bSBenjamin Close 	/* save power group information */
33816607310bSBenjamin Close 	group->chan   = rgroup.chan;
33826607310bSBenjamin Close 	group->maxpwr = rgroup.maxpwr;
33836607310bSBenjamin Close 	/* temperature at which the samples were taken */
33846607310bSBenjamin Close 	group->temp   = (int16_t)le16toh(rgroup.temp);
33856607310bSBenjamin Close 
33866607310bSBenjamin Close 	DPRINTF(("power group %d: chan=%d maxpwr=%d temp=%d\n", n,
33876607310bSBenjamin Close 		    group->chan, group->maxpwr, group->temp));
33886607310bSBenjamin Close 
33896607310bSBenjamin Close 	for (i = 0; i < WPI_SAMPLES_COUNT; i++) {
33906607310bSBenjamin Close 		group->samples[i].index = rgroup.samples[i].index;
33916607310bSBenjamin Close 		group->samples[i].power = rgroup.samples[i].power;
33926607310bSBenjamin Close 
33936607310bSBenjamin Close 		DPRINTF(("\tsample %d: index=%d power=%d\n", i,
33946607310bSBenjamin Close 			    group->samples[i].index, group->samples[i].power));
33956607310bSBenjamin Close 	}
33966607310bSBenjamin Close }
33976607310bSBenjamin Close 
33986607310bSBenjamin Close /*
33996607310bSBenjamin Close  * Update Tx power to match what is defined for channel `c'.
34006607310bSBenjamin Close  */
34016607310bSBenjamin Close static int
34026607310bSBenjamin Close wpi_set_txpower(struct wpi_softc *sc, struct ieee80211_channel *c, int async)
34036607310bSBenjamin Close {
3404b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
3405b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
34066607310bSBenjamin Close 	struct wpi_power_group *group;
34076607310bSBenjamin Close 	struct wpi_cmd_txpower txpower;
34086607310bSBenjamin Close 	u_int chan;
34096607310bSBenjamin Close 	int i;
34106607310bSBenjamin Close 
34116607310bSBenjamin Close 	/* get channel number */
34126607310bSBenjamin Close 	chan = ieee80211_chan2ieee(ic, c);
34136607310bSBenjamin Close 
34146607310bSBenjamin Close 	/* find the power group to which this channel belongs */
34156607310bSBenjamin Close 	if (IEEE80211_IS_CHAN_5GHZ(c)) {
34166607310bSBenjamin Close 		for (group = &sc->groups[1]; group < &sc->groups[4]; group++)
34176607310bSBenjamin Close 			if (chan <= group->chan)
34186607310bSBenjamin Close 				break;
34196607310bSBenjamin Close 	} else
34206607310bSBenjamin Close 		group = &sc->groups[0];
34216607310bSBenjamin Close 
34226607310bSBenjamin Close 	memset(&txpower, 0, sizeof txpower);
34236607310bSBenjamin Close 	txpower.band = IEEE80211_IS_CHAN_5GHZ(c) ? 0 : 1;
34246607310bSBenjamin Close 	txpower.channel = htole16(chan);
34256607310bSBenjamin Close 
34266607310bSBenjamin Close 	/* set Tx power for all OFDM and CCK rates */
34276607310bSBenjamin Close 	for (i = 0; i <= 11 ; i++) {
34286607310bSBenjamin Close 		/* retrieve Tx power for this channel/rate combination */
34296607310bSBenjamin Close 		int idx = wpi_get_power_index(sc, group, c,
34306607310bSBenjamin Close 		    wpi_ridx_to_rate[i]);
34316607310bSBenjamin Close 
34326607310bSBenjamin Close 		txpower.rates[i].rate = wpi_ridx_to_plcp[i];
34336607310bSBenjamin Close 
34346607310bSBenjamin Close 		if (IEEE80211_IS_CHAN_5GHZ(c)) {
34356607310bSBenjamin Close 			txpower.rates[i].gain_radio = wpi_rf_gain_5ghz[idx];
34366607310bSBenjamin Close 			txpower.rates[i].gain_dsp = wpi_dsp_gain_5ghz[idx];
34376607310bSBenjamin Close 		} else {
34386607310bSBenjamin Close 			txpower.rates[i].gain_radio = wpi_rf_gain_2ghz[idx];
34396607310bSBenjamin Close 			txpower.rates[i].gain_dsp = wpi_dsp_gain_2ghz[idx];
34406607310bSBenjamin Close 		}
34416607310bSBenjamin Close 		DPRINTFN(WPI_DEBUG_TEMP,("chan %d/rate %d: power index %d\n",
34426607310bSBenjamin Close 			    chan, wpi_ridx_to_rate[i], idx));
34436607310bSBenjamin Close 	}
34446607310bSBenjamin Close 
34456607310bSBenjamin Close 	return wpi_cmd(sc, WPI_CMD_TXPOWER, &txpower, sizeof txpower, async);
34466607310bSBenjamin Close }
34476607310bSBenjamin Close 
34486607310bSBenjamin Close /*
34496607310bSBenjamin Close  * Determine Tx power index for a given channel/rate combination.
34506607310bSBenjamin Close  * This takes into account the regulatory information from EEPROM and the
34516607310bSBenjamin Close  * current temperature.
34526607310bSBenjamin Close  */
34536607310bSBenjamin Close static int
34546607310bSBenjamin Close wpi_get_power_index(struct wpi_softc *sc, struct wpi_power_group *group,
34556607310bSBenjamin Close     struct ieee80211_channel *c, int rate)
34566607310bSBenjamin Close {
34576607310bSBenjamin Close /* fixed-point arithmetic division using a n-bit fractional part */
34586607310bSBenjamin Close #define fdivround(a, b, n)      \
34596607310bSBenjamin Close 	((((1 << n) * (a)) / (b) + (1 << n) / 2) / (1 << n))
34606607310bSBenjamin Close 
34616607310bSBenjamin Close /* linear interpolation */
34626607310bSBenjamin Close #define interpolate(x, x1, y1, x2, y2, n)       \
34636607310bSBenjamin Close 	((y1) + fdivround(((x) - (x1)) * ((y2) - (y1)), (x2) - (x1), n))
34646607310bSBenjamin Close 
3465b032f27cSSam Leffler 	struct ifnet *ifp = sc->sc_ifp;
3466b032f27cSSam Leffler 	struct ieee80211com *ic = ifp->if_l2com;
34676607310bSBenjamin Close 	struct wpi_power_sample *sample;
34686607310bSBenjamin Close 	int pwr, idx;
34696607310bSBenjamin Close 	u_int chan;
34706607310bSBenjamin Close 
34716607310bSBenjamin Close 	/* get channel number */
34726607310bSBenjamin Close 	chan = ieee80211_chan2ieee(ic, c);
34736607310bSBenjamin Close 
34746607310bSBenjamin Close 	/* default power is group's maximum power - 3dB */
34756607310bSBenjamin Close 	pwr = group->maxpwr / 2;
34766607310bSBenjamin Close 
34776607310bSBenjamin Close 	/* decrease power for highest OFDM rates to reduce distortion */
34786607310bSBenjamin Close 	switch (rate) {
34796607310bSBenjamin Close 		case 72:	/* 36Mb/s */
34806607310bSBenjamin Close 			pwr -= IEEE80211_IS_CHAN_2GHZ(c) ? 0 :  5;
34816607310bSBenjamin Close 			break;
34826607310bSBenjamin Close 		case 96:	/* 48Mb/s */
34836607310bSBenjamin Close 			pwr -= IEEE80211_IS_CHAN_2GHZ(c) ? 7 : 10;
34846607310bSBenjamin Close 			break;
34856607310bSBenjamin Close 		case 108:	/* 54Mb/s */
34866607310bSBenjamin Close 			pwr -= IEEE80211_IS_CHAN_2GHZ(c) ? 9 : 12;
34876607310bSBenjamin Close 			break;
34886607310bSBenjamin Close 	}
34896607310bSBenjamin Close 
34906607310bSBenjamin Close 	/* never exceed channel's maximum allowed Tx power */
34916607310bSBenjamin Close 	pwr = min(pwr, sc->maxpwr[chan]);
34926607310bSBenjamin Close 
34936607310bSBenjamin Close 	/* retrieve power index into gain tables from samples */
34946607310bSBenjamin Close 	for (sample = group->samples; sample < &group->samples[3]; sample++)
34956607310bSBenjamin Close 		if (pwr > sample[1].power)
34966607310bSBenjamin Close 			break;
34976607310bSBenjamin Close 	/* fixed-point linear interpolation using a 19-bit fractional part */
34986607310bSBenjamin Close 	idx = interpolate(pwr, sample[0].power, sample[0].index,
34996607310bSBenjamin Close 	    sample[1].power, sample[1].index, 19);
35006607310bSBenjamin Close 
35016607310bSBenjamin Close 	/*
35026607310bSBenjamin Close 	 *  Adjust power index based on current temperature
35036607310bSBenjamin Close 	 *	- if colder than factory-calibrated: decreate output power
35046607310bSBenjamin Close 	 *	- if warmer than factory-calibrated: increase output power
35056607310bSBenjamin Close 	 */
35066607310bSBenjamin Close 	idx -= (sc->temp - group->temp) * 11 / 100;
35076607310bSBenjamin Close 
35086607310bSBenjamin Close 	/* decrease power for CCK rates (-5dB) */
35096607310bSBenjamin Close 	if (!WPI_RATE_IS_OFDM(rate))
35106607310bSBenjamin Close 		idx += 10;
35116607310bSBenjamin Close 
35126607310bSBenjamin Close 	/* keep power index in a valid range */
35136607310bSBenjamin Close 	if (idx < 0)
35146607310bSBenjamin Close 		return 0;
35156607310bSBenjamin Close 	if (idx > WPI_MAX_PWR_INDEX)
35166607310bSBenjamin Close 		return WPI_MAX_PWR_INDEX;
35176607310bSBenjamin Close 	return idx;
35186607310bSBenjamin Close 
35196607310bSBenjamin Close #undef interpolate
35206607310bSBenjamin Close #undef fdivround
35216607310bSBenjamin Close }
35226607310bSBenjamin Close 
35236607310bSBenjamin Close /**
35246607310bSBenjamin Close  * Called by net80211 framework to indicate that a scan
35256607310bSBenjamin Close  * is starting. This function doesn't actually do the scan,
35266607310bSBenjamin Close  * wpi_scan_curchan starts things off. This function is more
35276607310bSBenjamin Close  * of an early warning from the framework we should get ready
35286607310bSBenjamin Close  * for the scan.
35296607310bSBenjamin Close  */
35306607310bSBenjamin Close static void
35316607310bSBenjamin Close wpi_scan_start(struct ieee80211com *ic)
35326607310bSBenjamin Close {
35336607310bSBenjamin Close 	struct ifnet *ifp = ic->ic_ifp;
35346607310bSBenjamin Close 	struct wpi_softc *sc = ifp->if_softc;
35356607310bSBenjamin Close 
35365efea30fSAndrew Thompson 	WPI_LOCK(sc);
35375efea30fSAndrew Thompson 	wpi_set_led(sc, WPI_LED_LINK, 20, 2);
35385efea30fSAndrew Thompson 	WPI_UNLOCK(sc);
35396607310bSBenjamin Close }
35406607310bSBenjamin Close 
35416607310bSBenjamin Close /**
35426607310bSBenjamin Close  * Called by the net80211 framework, indicates that the
35436607310bSBenjamin Close  * scan has ended. If there is a scan in progress on the card
35446607310bSBenjamin Close  * then it should be aborted.
35456607310bSBenjamin Close  */
35466607310bSBenjamin Close static void
35476607310bSBenjamin Close wpi_scan_end(struct ieee80211com *ic)
35486607310bSBenjamin Close {
35495efea30fSAndrew Thompson 	/* XXX ignore */
35506607310bSBenjamin Close }
35516607310bSBenjamin Close 
35526607310bSBenjamin Close /**
35536607310bSBenjamin Close  * Called by the net80211 framework to indicate to the driver
35546607310bSBenjamin Close  * that the channel should be changed
35556607310bSBenjamin Close  */
35566607310bSBenjamin Close static void
35576607310bSBenjamin Close wpi_set_channel(struct ieee80211com *ic)
35586607310bSBenjamin Close {
35596607310bSBenjamin Close 	struct ifnet *ifp = ic->ic_ifp;
35606607310bSBenjamin Close 	struct wpi_softc *sc = ifp->if_softc;
35615efea30fSAndrew Thompson 	int error;
35626607310bSBenjamin Close 
356382f1b132SAndrew Thompson 	/*
356482f1b132SAndrew Thompson 	 * Only need to set the channel in Monitor mode. AP scanning and auth
356582f1b132SAndrew Thompson 	 * are already taken care of by their respective firmware commands.
356682f1b132SAndrew Thompson 	 */
35675efea30fSAndrew Thompson 	if (ic->ic_opmode == IEEE80211_M_MONITOR) {
35686a9e69dbSBernhard Schmidt 		WPI_LOCK(sc);
35695efea30fSAndrew Thompson 		error = wpi_config(sc);
35706a9e69dbSBernhard Schmidt 		WPI_UNLOCK(sc);
35715efea30fSAndrew Thompson 		if (error != 0)
35725efea30fSAndrew Thompson 			device_printf(sc->sc_dev,
35735efea30fSAndrew Thompson 			    "error %d settting channel\n", error);
35745efea30fSAndrew Thompson 	}
35756607310bSBenjamin Close }
35766607310bSBenjamin Close 
35776607310bSBenjamin Close /**
35786607310bSBenjamin Close  * Called by net80211 to indicate that we need to scan the current
35796607310bSBenjamin Close  * channel. The channel is previously be set via the wpi_set_channel
35806607310bSBenjamin Close  * callback.
35816607310bSBenjamin Close  */
35826607310bSBenjamin Close static void
3583b032f27cSSam Leffler wpi_scan_curchan(struct ieee80211_scan_state *ss, unsigned long maxdwell)
35846607310bSBenjamin Close {
3585b032f27cSSam Leffler 	struct ieee80211vap *vap = ss->ss_vap;
3586b032f27cSSam Leffler 	struct ifnet *ifp = vap->iv_ic->ic_ifp;
35876607310bSBenjamin Close 	struct wpi_softc *sc = ifp->if_softc;
35886607310bSBenjamin Close 
35895efea30fSAndrew Thompson 	WPI_LOCK(sc);
35905efea30fSAndrew Thompson 	if (wpi_scan(sc))
35915efea30fSAndrew Thompson 		ieee80211_cancel_scan(vap);
35925efea30fSAndrew Thompson 	WPI_UNLOCK(sc);
35936607310bSBenjamin Close }
35946607310bSBenjamin Close 
35956607310bSBenjamin Close /**
35966607310bSBenjamin Close  * Called by the net80211 framework to indicate
35976607310bSBenjamin Close  * the minimum dwell time has been met, terminate the scan.
35986607310bSBenjamin Close  * We don't actually terminate the scan as the firmware will notify
35996607310bSBenjamin Close  * us when it's finished and we have no way to interrupt it.
36006607310bSBenjamin Close  */
36016607310bSBenjamin Close static void
3602b032f27cSSam Leffler wpi_scan_mindwell(struct ieee80211_scan_state *ss)
36036607310bSBenjamin Close {
36046607310bSBenjamin Close 	/* NB: don't try to abort scan; wait for firmware to finish */
36056607310bSBenjamin Close }
36066607310bSBenjamin Close 
36076607310bSBenjamin Close static void
36085efea30fSAndrew Thompson wpi_hwreset(void *arg, int pending)
36096607310bSBenjamin Close {
36105efea30fSAndrew Thompson 	struct wpi_softc *sc = arg;
36116607310bSBenjamin Close 
36126607310bSBenjamin Close 	WPI_LOCK(sc);
361382f1b132SAndrew Thompson 	wpi_init_locked(sc, 0);
361482f1b132SAndrew Thompson 	WPI_UNLOCK(sc);
36155efea30fSAndrew Thompson }
361682f1b132SAndrew Thompson 
36175efea30fSAndrew Thompson static void
36185efea30fSAndrew Thompson wpi_rfreset(void *arg, int pending)
36195efea30fSAndrew Thompson {
36205efea30fSAndrew Thompson 	struct wpi_softc *sc = arg;
36215efea30fSAndrew Thompson 
36225efea30fSAndrew Thompson 	WPI_LOCK(sc);
362382f1b132SAndrew Thompson 	wpi_rfkill_resume(sc);
362482f1b132SAndrew Thompson 	WPI_UNLOCK(sc);
36256607310bSBenjamin Close }
36266607310bSBenjamin Close 
36276607310bSBenjamin Close /*
36286607310bSBenjamin Close  * Allocate DMA-safe memory for firmware transfer.
36296607310bSBenjamin Close  */
36306607310bSBenjamin Close static int
36316607310bSBenjamin Close wpi_alloc_fwmem(struct wpi_softc *sc)
36326607310bSBenjamin Close {
36336607310bSBenjamin Close 	/* allocate enough contiguous space to store text and data */
36346607310bSBenjamin Close 	return wpi_dma_contig_alloc(sc, &sc->fw_dma, NULL,
36356607310bSBenjamin Close 	    WPI_FW_MAIN_TEXT_MAXSZ + WPI_FW_MAIN_DATA_MAXSZ, 1,
36366607310bSBenjamin Close 	    BUS_DMA_NOWAIT);
36376607310bSBenjamin Close }
36386607310bSBenjamin Close 
36396607310bSBenjamin Close static void
36406607310bSBenjamin Close wpi_free_fwmem(struct wpi_softc *sc)
36416607310bSBenjamin Close {
36426607310bSBenjamin Close 	wpi_dma_contig_free(&sc->fw_dma);
36436607310bSBenjamin Close }
36446607310bSBenjamin Close 
36456607310bSBenjamin Close /**
364682f1b132SAndrew Thompson  * Called every second, wpi_watchdog used by the watch dog timer
36476607310bSBenjamin Close  * to check that the card is still alive
36486607310bSBenjamin Close  */
36496607310bSBenjamin Close static void
365082f1b132SAndrew Thompson wpi_watchdog(void *arg)
36516607310bSBenjamin Close {
36526607310bSBenjamin Close 	struct wpi_softc *sc = arg;
365382f1b132SAndrew Thompson 	struct ifnet *ifp = sc->sc_ifp;
36545efea30fSAndrew Thompson 	struct ieee80211com *ic = ifp->if_l2com;
365582f1b132SAndrew Thompson 	uint32_t tmp;
36566607310bSBenjamin Close 
36576607310bSBenjamin Close 	DPRINTFN(WPI_DEBUG_WATCHDOG,("Watchdog: tick\n"));
36586607310bSBenjamin Close 
365982f1b132SAndrew Thompson 	if (sc->flags & WPI_FLAG_HW_RADIO_OFF) {
366082f1b132SAndrew Thompson 		/* No need to lock firmware memory */
366182f1b132SAndrew Thompson 		tmp = wpi_mem_read(sc, WPI_MEM_HW_RADIO_OFF);
366282f1b132SAndrew Thompson 
366382f1b132SAndrew Thompson 		if ((tmp & 0x1) == 0) {
366482f1b132SAndrew Thompson 			/* Radio kill switch is still off */
366582f1b132SAndrew Thompson 			callout_reset(&sc->watchdog_to, hz, wpi_watchdog, sc);
366682f1b132SAndrew Thompson 			return;
366782f1b132SAndrew Thompson 		}
366882f1b132SAndrew Thompson 
366982f1b132SAndrew Thompson 		device_printf(sc->sc_dev, "Hardware Switch Enabled\n");
36705efea30fSAndrew Thompson 		ieee80211_runtask(ic, &sc->sc_radiotask);
367182f1b132SAndrew Thompson 		return;
367282f1b132SAndrew Thompson 	}
367382f1b132SAndrew Thompson 
367482f1b132SAndrew Thompson 	if (sc->sc_tx_timer > 0) {
367582f1b132SAndrew Thompson 		if (--sc->sc_tx_timer == 0) {
367682f1b132SAndrew Thompson 			device_printf(sc->sc_dev,"device timeout\n");
367782f1b132SAndrew Thompson 			ifp->if_oerrors++;
36785efea30fSAndrew Thompson 			ieee80211_runtask(ic, &sc->sc_restarttask);
367982f1b132SAndrew Thompson 		}
368082f1b132SAndrew Thompson 	}
368182f1b132SAndrew Thompson 	if (sc->sc_scan_timer > 0) {
3682b032f27cSSam Leffler 		struct ieee80211vap *vap = TAILQ_FIRST(&ic->ic_vaps);
3683b032f27cSSam Leffler 		if (--sc->sc_scan_timer == 0 && vap != NULL) {
368482f1b132SAndrew Thompson 			device_printf(sc->sc_dev,"scan timeout\n");
3685b032f27cSSam Leffler 			ieee80211_cancel_scan(vap);
36865efea30fSAndrew Thompson 			ieee80211_runtask(ic, &sc->sc_restarttask);
368782f1b132SAndrew Thompson 		}
368882f1b132SAndrew Thompson 	}
368982f1b132SAndrew Thompson 
369082f1b132SAndrew Thompson 	if (ifp->if_drv_flags & IFF_DRV_RUNNING)
369182f1b132SAndrew Thompson 		callout_reset(&sc->watchdog_to, hz, wpi_watchdog, sc);
36926607310bSBenjamin Close }
36936607310bSBenjamin Close 
36946607310bSBenjamin Close #ifdef WPI_DEBUG
36956607310bSBenjamin Close static const char *wpi_cmd_str(int cmd)
36966607310bSBenjamin Close {
36976607310bSBenjamin Close 	switch (cmd) {
36986607310bSBenjamin Close 	case WPI_DISABLE_CMD:	return "WPI_DISABLE_CMD";
36996607310bSBenjamin Close 	case WPI_CMD_CONFIGURE:	return "WPI_CMD_CONFIGURE";
37006607310bSBenjamin Close 	case WPI_CMD_ASSOCIATE:	return "WPI_CMD_ASSOCIATE";
37016607310bSBenjamin Close 	case WPI_CMD_SET_WME:	return "WPI_CMD_SET_WME";
37026607310bSBenjamin Close 	case WPI_CMD_TSF:	return "WPI_CMD_TSF";
37036607310bSBenjamin Close 	case WPI_CMD_ADD_NODE:	return "WPI_CMD_ADD_NODE";
37046607310bSBenjamin Close 	case WPI_CMD_TX_DATA:	return "WPI_CMD_TX_DATA";
37056607310bSBenjamin Close 	case WPI_CMD_MRR_SETUP:	return "WPI_CMD_MRR_SETUP";
37066607310bSBenjamin Close 	case WPI_CMD_SET_LED:	return "WPI_CMD_SET_LED";
37076607310bSBenjamin Close 	case WPI_CMD_SET_POWER_MODE: return "WPI_CMD_SET_POWER_MODE";
37086607310bSBenjamin Close 	case WPI_CMD_SCAN:	return "WPI_CMD_SCAN";
37096607310bSBenjamin Close 	case WPI_CMD_SET_BEACON:return "WPI_CMD_SET_BEACON";
37106607310bSBenjamin Close 	case WPI_CMD_TXPOWER:	return "WPI_CMD_TXPOWER";
37116607310bSBenjamin Close 	case WPI_CMD_BLUETOOTH:	return "WPI_CMD_BLUETOOTH";
37126607310bSBenjamin Close 
37136607310bSBenjamin Close 	default:
37146607310bSBenjamin Close 		KASSERT(1, ("Unknown Command: %d\n", cmd));
3715b032f27cSSam Leffler 		return "UNKNOWN CMD";	/* Make the compiler happy */
37166607310bSBenjamin Close 	}
37176607310bSBenjamin Close }
37186607310bSBenjamin Close #endif
37196607310bSBenjamin Close 
37206607310bSBenjamin Close MODULE_DEPEND(wpi, pci,  1, 1, 1);
37216607310bSBenjamin Close MODULE_DEPEND(wpi, wlan, 1, 1, 1);
37226607310bSBenjamin Close MODULE_DEPEND(wpi, firmware, 1, 1, 1);
3723