xref: /linux/drivers/net/usb/usbnet.c (revision 998be0a4dbcaa796a05c7b52327f3a09c29d3662)
1 // SPDX-License-Identifier: GPL-2.0-or-later
2 /*
3  * USB Network driver infrastructure
4  * Copyright (C) 2000-2005 by David Brownell
5  * Copyright (C) 2003-2005 David Hollis <dhollis@davehollis.com>
6  */
7 
8 /*
9  * This is a generic "USB networking" framework that works with several
10  * kinds of full and high speed networking devices:  host-to-host cables,
11  * smart usb peripherals, and actual Ethernet adapters.
12  *
13  * These devices usually differ in terms of control protocols (if they
14  * even have one!) and sometimes they define new framing to wrap or batch
15  * Ethernet packets.  Otherwise, they talk to USB pretty much the same,
16  * so interface (un)binding, endpoint I/O queues, fault handling, and other
17  * issues can usefully be addressed by this framework.
18  */
19 
20 #include <linux/module.h>
21 #include <linux/hex.h>
22 #include <linux/init.h>
23 #include <linux/netdevice.h>
24 #include <linux/etherdevice.h>
25 #include <linux/ctype.h>
26 #include <linux/ethtool.h>
27 #include <linux/workqueue.h>
28 #include <linux/mii.h>
29 #include <linux/usb.h>
30 #include <linux/usb/usbnet.h>
31 #include <linux/slab.h>
32 #include <linux/kernel.h>
33 #include <linux/pm_runtime.h>
34 
35 /*-------------------------------------------------------------------------*/
36 
37 /*
38  * Nineteen USB 1.1 max size bulk transactions per frame (ms), max.
39  * Several dozen bytes of IPv4 data can fit in two such transactions.
40  * One maximum size Ethernet packet takes twenty four of them.
41  * For high speed, each frame comfortably fits almost 36 max size
42  * Ethernet packets (so queues should be bigger).
43  *
44  * The goal is to let the USB host controller be busy for 5msec or
45  * more before an irq is required, under load.  Jumbograms change
46  * the equation.
47  */
48 #define	MAX_QUEUE_MEMORY	(60 * 1518)
49 #define	RX_QLEN(dev)		((dev)->rx_qlen)
50 #define	TX_QLEN(dev)		((dev)->tx_qlen)
51 
52 // reawaken network queue this soon after stopping; else watchdog barks
53 #define TX_TIMEOUT_JIFFIES	(5*HZ)
54 
55 /* throttle rx/tx briefly after some faults, so hub_wq might disconnect()
56  * us (it polls at HZ/4 usually) before we report too many false errors.
57  */
58 #define THROTTLE_JIFFIES	(HZ/8)
59 
60 // between wakeups
61 #define UNLINK_TIMEOUT_MS	3
62 
63 /*-------------------------------------------------------------------------*/
64 
65 /* use ethtool to change the level for any given device */
66 static int msg_level = -1;
67 module_param (msg_level, int, 0);
68 MODULE_PARM_DESC (msg_level, "Override default message level");
69 
70 /*-------------------------------------------------------------------------*/
71 
72 static const char * const usbnet_event_names[] = {
73 	[EVENT_TX_HALT]		   = "EVENT_TX_HALT",
74 	[EVENT_RX_HALT]		   = "EVENT_RX_HALT",
75 	[EVENT_RX_MEMORY]	   = "EVENT_RX_MEMORY",
76 	[EVENT_STS_SPLIT]	   = "EVENT_STS_SPLIT",
77 	[EVENT_LINK_RESET]	   = "EVENT_LINK_RESET",
78 	[EVENT_RX_PAUSED]	   = "EVENT_RX_PAUSED",
79 	[EVENT_DEV_ASLEEP]	   = "EVENT_DEV_ASLEEP",
80 	[EVENT_DEV_OPEN]	   = "EVENT_DEV_OPEN",
81 	[EVENT_DEVICE_REPORT_IDLE] = "EVENT_DEVICE_REPORT_IDLE",
82 	[EVENT_NO_RUNTIME_PM]	   = "EVENT_NO_RUNTIME_PM",
83 	[EVENT_RX_KILL]		   = "EVENT_RX_KILL",
84 	[EVENT_LINK_CHANGE]	   = "EVENT_LINK_CHANGE",
85 	[EVENT_SET_RX_MODE]	   = "EVENT_SET_RX_MODE",
86 	[EVENT_NO_IP_ALIGN]	   = "EVENT_NO_IP_ALIGN",
87 };
88 
89 /* handles CDC Ethernet and many other network "bulk data" interfaces */
90 int usbnet_get_endpoints(struct usbnet *dev, struct usb_interface *intf)
91 {
92 	int				tmp;
93 	struct usb_host_interface	*alt = NULL;
94 	struct usb_host_endpoint	*in = NULL, *out = NULL;
95 	struct usb_host_endpoint	*status = NULL;
96 
97 	for (tmp = 0; tmp < intf->num_altsetting; tmp++) {
98 		unsigned	ep;
99 
100 		in = out = status = NULL;
101 		alt = intf->altsetting + tmp;
102 
103 		/* take the first altsetting with in-bulk + out-bulk;
104 		 * remember any status endpoint, just in case;
105 		 * ignore other endpoints and altsettings.
106 		 */
107 		for (ep = 0; ep < alt->desc.bNumEndpoints; ep++) {
108 			struct usb_host_endpoint	*e;
109 			int				intr = 0;
110 
111 			e = alt->endpoint + ep;
112 
113 			/* ignore endpoints which cannot transfer data */
114 			if (!usb_endpoint_maxp(&e->desc))
115 				continue;
116 
117 			switch (e->desc.bmAttributes) {
118 			case USB_ENDPOINT_XFER_INT:
119 				if (!usb_endpoint_dir_in(&e->desc))
120 					continue;
121 				intr = 1;
122 				fallthrough;
123 			case USB_ENDPOINT_XFER_BULK:
124 				break;
125 			default:
126 				continue;
127 			}
128 			if (usb_endpoint_dir_in(&e->desc)) {
129 				if (!intr && !in)
130 					in = e;
131 				else if (intr && !status)
132 					status = e;
133 			} else {
134 				if (!out)
135 					out = e;
136 			}
137 		}
138 		if (in && out)
139 			break;
140 	}
141 	if (!alt || !in || !out)
142 		return -EINVAL;
143 
144 	if (alt->desc.bAlternateSetting != 0 ||
145 	    !(dev->driver_info->flags & FLAG_NO_SETINT)) {
146 		tmp = usb_set_interface(dev->udev, alt->desc.bInterfaceNumber,
147 					alt->desc.bAlternateSetting);
148 		if (tmp < 0)
149 			return tmp;
150 	}
151 
152 	dev->in = usb_rcvbulkpipe(dev->udev,
153 				  in->desc.bEndpointAddress & USB_ENDPOINT_NUMBER_MASK);
154 	dev->out = usb_sndbulkpipe(dev->udev,
155 				   out->desc.bEndpointAddress & USB_ENDPOINT_NUMBER_MASK);
156 	dev->status = status;
157 	return 0;
158 }
159 EXPORT_SYMBOL_GPL(usbnet_get_endpoints);
160 
161 int usbnet_get_ethernet_addr(struct usbnet *dev, int iMACAddress)
162 {
163 	u8		addr[ETH_ALEN];
164 	int 		tmp = -1, ret;
165 	unsigned char	buf [13];
166 
167 	ret = usb_string(dev->udev, iMACAddress, buf, sizeof(buf));
168 	if (ret == 12)
169 		tmp = hex2bin(addr, buf, 6);
170 	if (tmp < 0) {
171 		dev_dbg(&dev->udev->dev,
172 			"bad MAC string %d fetch, %d\n", iMACAddress, tmp);
173 		if (ret >= 0)
174 			ret = -EINVAL;
175 		return ret;
176 	}
177 	eth_hw_addr_set(dev->net, addr);
178 	return 0;
179 }
180 EXPORT_SYMBOL_GPL(usbnet_get_ethernet_addr);
181 
182 static bool usbnet_needs_usb_name_format(struct usbnet *dev, struct net_device *net)
183 {
184 	/* Point to point devices which don't have a real MAC address
185 	 * (or report a fake local one) have historically used the usb%d
186 	 * naming. Preserve this..
187 	 */
188 	return (dev->driver_info->flags & FLAG_POINTTOPOINT) != 0 &&
189 		(is_zero_ether_addr(net->dev_addr) ||
190 		 is_local_ether_addr(net->dev_addr));
191 }
192 
193 static void intr_complete(struct urb *urb)
194 {
195 	struct usbnet	*dev = urb->context;
196 	int		status = urb->status;
197 
198 	switch (status) {
199 	/* success */
200 	case 0:
201 		dev->driver_info->status(dev, urb);
202 		break;
203 
204 	/* software-driven interface shutdown */
205 	case -ENOENT:		/* urb killed */
206 	case -ESHUTDOWN:	/* hardware gone */
207 		netif_dbg(dev, ifdown, dev->net,
208 			  "intr shutdown, code %d\n", status);
209 		return;
210 
211 	/* NOTE:  not throttling like RX/TX, since this endpoint
212 	 * already polls infrequently
213 	 */
214 	default:
215 		netdev_dbg(dev->net, "intr status %d\n", status);
216 		break;
217 	}
218 
219 	status = usb_submit_urb(urb, GFP_ATOMIC);
220 	if (status != 0)
221 		netif_err(dev, timer, dev->net,
222 			  "intr resubmit --> %d\n", status);
223 }
224 
225 static int init_status(struct usbnet *dev, struct usb_interface *intf)
226 {
227 	char		*buf = NULL;
228 	unsigned	pipe = 0;
229 	unsigned	maxp;
230 	unsigned	period;
231 
232 	if (!dev->driver_info->status)
233 		return 0;
234 
235 	pipe = usb_rcvintpipe(dev->udev,
236 			      dev->status->desc.bEndpointAddress
237 			      & USB_ENDPOINT_NUMBER_MASK);
238 	maxp = usb_maxpacket(dev->udev, pipe);
239 
240 	/* avoid 1 msec chatter:  min 8 msec poll rate */
241 	period = max ((int) dev->status->desc.bInterval,
242 		(dev->udev->speed == USB_SPEED_HIGH) ? 7 : 3);
243 
244 	buf = kmalloc(maxp, GFP_KERNEL);
245 	if (buf) {
246 		dev->interrupt = usb_alloc_urb(0, GFP_KERNEL);
247 		if (!dev->interrupt) {
248 			kfree(buf);
249 			return -ENOMEM;
250 		} else {
251 			usb_fill_int_urb(dev->interrupt, dev->udev, pipe,
252 					 buf, maxp, intr_complete, dev, period);
253 			dev->interrupt->transfer_flags |= URB_FREE_BUFFER;
254 			dev_dbg(&intf->dev,
255 				"status ep%din, %d bytes period %d\n",
256 				usb_pipeendpoint(pipe), maxp, period);
257 		}
258 	}
259 	return 0;
260 }
261 
262 /* Submit the interrupt URB if not previously submitted, increasing refcount */
263 int usbnet_status_start(struct usbnet *dev, gfp_t mem_flags)
264 {
265 	int ret = 0;
266 
267 	WARN_ON_ONCE(dev->interrupt == NULL);
268 	if (dev->interrupt) {
269 		mutex_lock(&dev->interrupt_mutex);
270 
271 		if (++dev->interrupt_count == 1)
272 			ret = usb_submit_urb(dev->interrupt, mem_flags);
273 
274 		dev_dbg(&dev->udev->dev, "incremented interrupt URB count to %d\n",
275 			dev->interrupt_count);
276 		mutex_unlock(&dev->interrupt_mutex);
277 	}
278 	return ret;
279 }
280 EXPORT_SYMBOL_GPL(usbnet_status_start);
281 
282 /* For resume; submit interrupt URB if previously submitted */
283 static int __usbnet_status_start_force(struct usbnet *dev, gfp_t mem_flags)
284 {
285 	int ret = 0;
286 
287 	mutex_lock(&dev->interrupt_mutex);
288 	if (dev->interrupt_count) {
289 		ret = usb_submit_urb(dev->interrupt, mem_flags);
290 		dev_dbg(&dev->udev->dev,
291 			"submitted interrupt URB for resume\n");
292 	}
293 	mutex_unlock(&dev->interrupt_mutex);
294 	return ret;
295 }
296 
297 /* Kill the interrupt URB if all submitters want it killed */
298 void usbnet_status_stop(struct usbnet *dev)
299 {
300 	if (dev->interrupt) {
301 		mutex_lock(&dev->interrupt_mutex);
302 		WARN_ON(dev->interrupt_count == 0);
303 
304 		if (dev->interrupt_count && --dev->interrupt_count == 0)
305 			usb_kill_urb(dev->interrupt);
306 
307 		dev_dbg(&dev->udev->dev,
308 			"decremented interrupt URB count to %d\n",
309 			dev->interrupt_count);
310 		mutex_unlock(&dev->interrupt_mutex);
311 	}
312 }
313 EXPORT_SYMBOL_GPL(usbnet_status_stop);
314 
315 /* For suspend; always kill interrupt URB */
316 static void __usbnet_status_stop_force(struct usbnet *dev)
317 {
318 	if (dev->interrupt) {
319 		mutex_lock(&dev->interrupt_mutex);
320 		usb_kill_urb(dev->interrupt);
321 		dev_dbg(&dev->udev->dev, "killed interrupt URB for suspend\n");
322 		mutex_unlock(&dev->interrupt_mutex);
323 	}
324 }
325 
326 /* Passes this packet up the stack, updating its accounting.
327  * Some link protocols batch packets, so their rx_fixup paths
328  * can return clones as well as just modify the original skb.
329  */
330 void usbnet_skb_return(struct usbnet *dev, struct sk_buff *skb)
331 {
332 	struct pcpu_sw_netstats *stats64 = this_cpu_ptr(dev->net->tstats);
333 	unsigned long flags;
334 	int	status;
335 
336 	if (test_bit(EVENT_RX_PAUSED, &dev->flags)) {
337 		skb_queue_tail(&dev->rxq_pause, skb);
338 		return;
339 	}
340 
341 	/* only update if unset to allow minidriver rx_fixup override */
342 	if (skb->protocol == 0)
343 		skb->protocol = eth_type_trans(skb, dev->net);
344 
345 	flags = u64_stats_update_begin_irqsave(&stats64->syncp);
346 	u64_stats_inc(&stats64->rx_packets);
347 	u64_stats_add(&stats64->rx_bytes, skb->len);
348 	u64_stats_update_end_irqrestore(&stats64->syncp, flags);
349 
350 	netif_dbg(dev, rx_status, dev->net, "< rx, len %zu, type 0x%x\n",
351 		  skb->len + sizeof(struct ethhdr), skb->protocol);
352 	memset(skb->cb, 0, sizeof(struct skb_data));
353 
354 	if (skb_defer_rx_timestamp(skb))
355 		return;
356 
357 	status = netif_rx (skb);
358 	if (status != NET_RX_SUCCESS)
359 		netif_dbg(dev, rx_err, dev->net,
360 			  "netif_rx status %d\n", status);
361 }
362 EXPORT_SYMBOL_GPL(usbnet_skb_return);
363 
364 /* must be called if hard_mtu or rx_urb_size changed */
365 void usbnet_update_max_qlen(struct usbnet *dev)
366 {
367 	enum usb_device_speed speed = dev->udev->speed;
368 
369 	if (!dev->rx_urb_size || !dev->hard_mtu)
370 		goto insanity;
371 	switch (speed) {
372 	case USB_SPEED_HIGH:
373 		dev->rx_qlen = MAX_QUEUE_MEMORY / dev->rx_urb_size;
374 		dev->tx_qlen = MAX_QUEUE_MEMORY / dev->hard_mtu;
375 		break;
376 	case USB_SPEED_SUPER:
377 	case USB_SPEED_SUPER_PLUS:
378 		/*
379 		 * Not take default 5ms qlen for super speed HC to
380 		 * save memory, and iperf tests show 2.5ms qlen can
381 		 * work well
382 		 */
383 		dev->rx_qlen = 5 * MAX_QUEUE_MEMORY / dev->rx_urb_size;
384 		dev->tx_qlen = 5 * MAX_QUEUE_MEMORY / dev->hard_mtu;
385 		break;
386 	default:
387 insanity:
388 		dev->rx_qlen = dev->tx_qlen = 4;
389 	}
390 }
391 EXPORT_SYMBOL_GPL(usbnet_update_max_qlen);
392 
393 
394 /*-------------------------------------------------------------------------
395  *
396  * Network Device Driver (peer link to "Host Device", from USB host)
397  *
398  *-------------------------------------------------------------------------*/
399 
400 int usbnet_change_mtu(struct net_device *net, int new_mtu)
401 {
402 	struct usbnet	*dev = netdev_priv(net);
403 	int		ll_mtu = new_mtu + net->hard_header_len;
404 	int		old_hard_mtu = dev->hard_mtu;
405 	int		old_rx_urb_size = dev->rx_urb_size;
406 
407 	// no second zero-length packet read wanted after mtu-sized packets
408 	if ((ll_mtu % dev->maxpacket) == 0)
409 		return -EDOM;
410 	WRITE_ONCE(net->mtu, new_mtu);
411 
412 	dev->hard_mtu = net->mtu + net->hard_header_len;
413 	if (dev->rx_urb_size == old_hard_mtu) {
414 		dev->rx_urb_size = dev->hard_mtu;
415 		if (dev->rx_urb_size > old_rx_urb_size) {
416 			usbnet_pause_rx(dev);
417 			usbnet_unlink_rx_urbs(dev);
418 			usbnet_resume_rx(dev);
419 		}
420 	}
421 
422 	/* max qlen depend on hard_mtu and rx_urb_size */
423 	usbnet_update_max_qlen(dev);
424 
425 	return 0;
426 }
427 EXPORT_SYMBOL_GPL(usbnet_change_mtu);
428 
429 /* The caller must hold list->lock */
430 static void __usbnet_queue_skb(struct sk_buff_head *list,
431 			struct sk_buff *newsk, enum skb_state state)
432 {
433 	struct skb_data *entry = (struct skb_data *) newsk->cb;
434 
435 	__skb_queue_tail(list, newsk);
436 	entry->state = state;
437 }
438 
439 /*-------------------------------------------------------------------------*/
440 
441 /* some LK 2.4 HCDs oopsed if we freed or resubmitted urbs from
442  * completion callbacks.  2.5 should have fixed those bugs...
443  */
444 
445 static enum skb_state defer_bh(struct usbnet *dev, struct sk_buff *skb,
446 		struct sk_buff_head *list, enum skb_state state)
447 {
448 	unsigned long		flags;
449 	enum skb_state 		old_state;
450 	struct skb_data *entry = (struct skb_data *) skb->cb;
451 
452 	spin_lock_irqsave(&list->lock, flags);
453 	old_state = entry->state;
454 	entry->state = state;
455 	__skb_unlink(skb, list);
456 
457 	/* defer_bh() is never called with list == &dev->done.
458 	 * spin_lock_nested() tells lockdep that it is OK to take
459 	 * dev->done.lock here with list->lock held.
460 	 */
461 	spin_lock_nested(&dev->done.lock, SINGLE_DEPTH_NESTING);
462 
463 	__skb_queue_tail(&dev->done, skb);
464 	if (dev->done.qlen == 1)
465 		queue_work(system_bh_wq, &dev->bh_work);
466 	spin_unlock(&dev->done.lock);
467 	spin_unlock_irqrestore(&list->lock, flags);
468 	return old_state;
469 }
470 
471 /* some work can't be done in tasklets, so we use keventd
472  *
473  * NOTE:  annoying asymmetry:  if it's active, schedule_work() fails,
474  * but tasklet_schedule() doesn't.  hope the failure is rare.
475  */
476 void usbnet_defer_kevent(struct usbnet *dev, int work)
477 {
478 	set_bit (work, &dev->flags);
479 	if (!usbnet_going_away(dev)) {
480 		if (!schedule_work(&dev->kevent))
481 			netdev_dbg(dev->net,
482 				   "kevent %s may have been dropped\n",
483 				   usbnet_event_names[work]);
484 		else
485 			netdev_dbg(dev->net,
486 				   "kevent %s scheduled\n", usbnet_event_names[work]);
487 	}
488 }
489 EXPORT_SYMBOL_GPL(usbnet_defer_kevent);
490 
491 /*-------------------------------------------------------------------------*/
492 
493 static void rx_complete(struct urb *urb);
494 
495 static int rx_submit(struct usbnet *dev, struct urb *urb, gfp_t flags)
496 {
497 	struct sk_buff		*skb;
498 	struct skb_data		*entry;
499 	int			retval = 0;
500 	unsigned long		lockflags;
501 	size_t			size = dev->rx_urb_size;
502 
503 	/* prevent rx skb allocation when error ratio is high */
504 	if (test_bit(EVENT_RX_KILL, &dev->flags)) {
505 		usb_free_urb(urb);
506 		return -ENOLINK;
507 	}
508 
509 	if (test_bit(EVENT_NO_IP_ALIGN, &dev->flags))
510 		skb = __netdev_alloc_skb(dev->net, size, flags);
511 	else
512 		skb = __netdev_alloc_skb_ip_align(dev->net, size, flags);
513 	if (!skb) {
514 		netif_dbg(dev, rx_err, dev->net, "no rx skb\n");
515 		usbnet_defer_kevent(dev, EVENT_RX_MEMORY);
516 		usb_free_urb(urb);
517 		return -ENOMEM;
518 	}
519 
520 	entry = (struct skb_data *) skb->cb;
521 	entry->urb = urb;
522 	entry->dev = dev;
523 	entry->length = 0;
524 
525 	usb_fill_bulk_urb(urb, dev->udev, dev->in,
526 			  skb->data, size, rx_complete, skb);
527 
528 	spin_lock_irqsave(&dev->rxq.lock, lockflags);
529 
530 	if (netif_running(dev->net) &&
531 	    netif_device_present(dev->net) &&
532 	    test_bit(EVENT_DEV_OPEN, &dev->flags) &&
533 	    !test_bit(EVENT_RX_HALT, &dev->flags) &&
534 	    !test_bit(EVENT_DEV_ASLEEP, &dev->flags) &&
535 	    !usbnet_going_away(dev)) {
536 		switch (retval = usb_submit_urb(urb, GFP_ATOMIC)) {
537 		case -EPIPE:
538 			usbnet_defer_kevent(dev, EVENT_RX_HALT);
539 			break;
540 		case -ENOMEM:
541 			usbnet_defer_kevent(dev, EVENT_RX_MEMORY);
542 			break;
543 		case -ENODEV:
544 			netif_dbg(dev, ifdown, dev->net, "device gone\n");
545 			netif_device_detach(dev->net);
546 			break;
547 		case -EHOSTUNREACH:
548 			retval = -ENOLINK;
549 			break;
550 		default:
551 			netif_dbg(dev, rx_err, dev->net,
552 				  "rx submit, %d\n", retval);
553 			queue_work(system_bh_wq, &dev->bh_work);
554 			break;
555 		case 0:
556 			__usbnet_queue_skb(&dev->rxq, skb, rx_start);
557 		}
558 	} else {
559 		netif_dbg(dev, ifdown, dev->net, "rx: stopped\n");
560 		retval = -ENOLINK;
561 	}
562 	spin_unlock_irqrestore(&dev->rxq.lock, lockflags);
563 	if (retval) {
564 		dev_kfree_skb_any(skb);
565 		usb_free_urb(urb);
566 	}
567 	return retval;
568 }
569 
570 
571 /*-------------------------------------------------------------------------*/
572 
573 static inline int rx_process(struct usbnet *dev, struct sk_buff *skb)
574 {
575 	if (dev->driver_info->rx_fixup &&
576 	    !dev->driver_info->rx_fixup(dev, skb)) {
577 		/* With RX_ASSEMBLE, rx_fixup() must update counters */
578 		if (!(dev->driver_info->flags & FLAG_RX_ASSEMBLE))
579 			dev->net->stats.rx_errors++;
580 		return -EPROTO;
581 	}
582 	// else network stack removes extra byte if we forced a short packet
583 
584 	/* all data was already cloned from skb inside the driver */
585 	if (dev->driver_info->flags & FLAG_MULTI_PACKET)
586 		return -EALREADY;
587 
588 	if (skb->len < ETH_HLEN) {
589 		dev->net->stats.rx_errors++;
590 		dev->net->stats.rx_length_errors++;
591 		netif_dbg(dev, rx_err, dev->net, "rx length %d\n", skb->len);
592 		return -EPROTO;
593 	}
594 
595 	usbnet_skb_return(dev, skb);
596 	return 0;
597 }
598 
599 /*-------------------------------------------------------------------------*/
600 
601 static void rx_complete(struct urb *urb)
602 {
603 	struct sk_buff		*skb = (struct sk_buff *) urb->context;
604 	struct skb_data		*entry = (struct skb_data *) skb->cb;
605 	struct usbnet		*dev = entry->dev;
606 	int			urb_status = urb->status;
607 	enum skb_state		state;
608 
609 	skb_put(skb, urb->actual_length);
610 	state = rx_done;
611 	entry->urb = NULL;
612 
613 	switch (urb_status) {
614 	/* success */
615 	case 0:
616 		break;
617 
618 	/* stalls need manual reset. this is rare ... except that
619 	 * when going through USB 2.0 TTs, unplug appears this way.
620 	 * we avoid the highspeed version of the ETIMEDOUT/EILSEQ
621 	 * storm, recovering as needed.
622 	 */
623 	case -EPIPE:
624 		dev->net->stats.rx_errors++;
625 		usbnet_defer_kevent(dev, EVENT_RX_HALT);
626 		fallthrough;
627 
628 	/* software-driven interface shutdown */
629 	case -ECONNRESET:		/* async unlink */
630 	case -ESHUTDOWN:		/* hardware gone */
631 		netif_dbg(dev, ifdown, dev->net,
632 			  "rx shutdown, code %d\n", urb_status);
633 		goto block;
634 
635 	/* we get controller i/o faults during hub_wq disconnect() delays.
636 	 * throttle down resubmits, to avoid log floods; just temporarily,
637 	 * so we still recover when the fault isn't a hub_wq delay.
638 	 */
639 	case -EPROTO:
640 	case -ETIME:
641 	case -EILSEQ:
642 		dev->net->stats.rx_errors++;
643 		if (!timer_pending(&dev->delay)) {
644 			mod_timer(&dev->delay, jiffies + THROTTLE_JIFFIES);
645 			netif_dbg(dev, link, dev->net,
646 				  "rx throttle %d\n", urb_status);
647 		}
648 block:
649 		state = rx_cleanup;
650 		entry->urb = urb;
651 		urb = NULL;
652 		break;
653 
654 	/* data overrun ... flush fifo? */
655 	case -EOVERFLOW:
656 		dev->net->stats.rx_over_errors++;
657 		fallthrough;
658 
659 	default:
660 		state = rx_cleanup;
661 		dev->net->stats.rx_errors++;
662 		netif_dbg(dev, rx_err, dev->net, "rx status %d\n", urb_status);
663 		break;
664 	}
665 
666 	/* stop rx if packet error rate is high */
667 	if (++dev->pkt_cnt > 30) {
668 		dev->pkt_cnt = 0;
669 		dev->pkt_err = 0;
670 	} else {
671 		if (state == rx_cleanup)
672 			dev->pkt_err++;
673 		if (dev->pkt_err > 20)
674 			set_bit(EVENT_RX_KILL, &dev->flags);
675 	}
676 
677 	state = defer_bh(dev, skb, &dev->rxq, state);
678 
679 	if (urb) {
680 		if (netif_running(dev->net) &&
681 		    !test_bit(EVENT_RX_HALT, &dev->flags) &&
682 		    state != unlink_start) {
683 			rx_submit(dev, urb, GFP_ATOMIC);
684 			usb_mark_last_busy(dev->udev);
685 			return;
686 		}
687 		usb_free_urb(urb);
688 	}
689 	netif_dbg(dev, rx_err, dev->net, "no read resubmitted\n");
690 }
691 
692 /*-------------------------------------------------------------------------*/
693 void usbnet_pause_rx(struct usbnet *dev)
694 {
695 	set_bit(EVENT_RX_PAUSED, &dev->flags);
696 
697 	netif_dbg(dev, rx_status, dev->net, "paused rx queue enabled\n");
698 }
699 EXPORT_SYMBOL_GPL(usbnet_pause_rx);
700 
701 void usbnet_resume_rx(struct usbnet *dev)
702 {
703 	struct sk_buff *skb;
704 	int num = 0;
705 
706 	local_bh_disable();
707 	clear_bit(EVENT_RX_PAUSED, &dev->flags);
708 
709 	while ((skb = skb_dequeue(&dev->rxq_pause)) != NULL) {
710 		usbnet_skb_return(dev, skb);
711 		num++;
712 	}
713 
714 	queue_work(system_bh_wq, &dev->bh_work);
715 	local_bh_enable();
716 
717 	netif_dbg(dev, rx_status, dev->net,
718 		  "paused rx queue disabled, %d skbs requeued\n", num);
719 }
720 EXPORT_SYMBOL_GPL(usbnet_resume_rx);
721 
722 void usbnet_purge_paused_rxq(struct usbnet *dev)
723 {
724 	skb_queue_purge(&dev->rxq_pause);
725 }
726 EXPORT_SYMBOL_GPL(usbnet_purge_paused_rxq);
727 
728 /*-------------------------------------------------------------------------*/
729 
730 // unlink pending rx/tx; completion handlers do all other cleanup
731 
732 static int unlink_urbs(struct usbnet *dev, struct sk_buff_head *q)
733 {
734 	unsigned long		flags;
735 	struct sk_buff		*skb;
736 	int			count = 0;
737 
738 	spin_lock_irqsave (&q->lock, flags);
739 	while (!skb_queue_empty(q)) {
740 		struct skb_data		*entry;
741 		struct urb		*urb;
742 		int			retval;
743 
744 		skb_queue_walk(q, skb) {
745 			entry = (struct skb_data *) skb->cb;
746 			if (entry->state != unlink_start)
747 				goto found;
748 		}
749 		break;
750 found:
751 		entry->state = unlink_start;
752 		urb = entry->urb;
753 
754 		/*
755 		 * Get reference count of the URB to avoid it to be
756 		 * freed during usb_unlink_urb, which may trigger
757 		 * use-after-free problem inside usb_unlink_urb since
758 		 * usb_unlink_urb is always racing with .complete
759 		 * handler(include defer_bh).
760 		 */
761 		usb_get_urb(urb);
762 		spin_unlock_irqrestore(&q->lock, flags);
763 		// during some PM-driven resume scenarios,
764 		// these (async) unlinks complete immediately
765 		retval = usb_unlink_urb(urb);
766 		if (retval != -EINPROGRESS && retval != 0)
767 			netdev_dbg(dev->net, "unlink urb err, %d\n", retval);
768 		else
769 			count++;
770 		usb_put_urb(urb);
771 		spin_lock_irqsave(&q->lock, flags);
772 	}
773 	spin_unlock_irqrestore(&q->lock, flags);
774 	return count;
775 }
776 
777 // Flush all pending rx urbs
778 // minidrivers may need to do this when the MTU changes
779 
780 void usbnet_unlink_rx_urbs(struct usbnet *dev)
781 {
782 	if (netif_running(dev->net)) {
783 		(void) unlink_urbs (dev, &dev->rxq);
784 		queue_work(system_bh_wq, &dev->bh_work);
785 	}
786 }
787 EXPORT_SYMBOL_GPL(usbnet_unlink_rx_urbs);
788 
789 /*-------------------------------------------------------------------------*/
790 
791 static void wait_skb_queue_empty(struct sk_buff_head *q)
792 {
793 	unsigned long flags;
794 
795 	spin_lock_irqsave(&q->lock, flags);
796 	while (!skb_queue_empty(q)) {
797 		spin_unlock_irqrestore(&q->lock, flags);
798 		schedule_timeout(msecs_to_jiffies(UNLINK_TIMEOUT_MS));
799 		set_current_state(TASK_UNINTERRUPTIBLE);
800 		spin_lock_irqsave(&q->lock, flags);
801 	}
802 	spin_unlock_irqrestore(&q->lock, flags);
803 }
804 
805 // precondition: never called in_interrupt
806 static void usbnet_terminate_urbs(struct usbnet *dev)
807 {
808 	DECLARE_WAITQUEUE(wait, current);
809 	int temp;
810 
811 	/* ensure there are no more active urbs */
812 	add_wait_queue(&dev->wait, &wait);
813 	set_current_state(TASK_UNINTERRUPTIBLE);
814 	temp = unlink_urbs(dev, &dev->txq) +
815 		unlink_urbs(dev, &dev->rxq);
816 
817 	/* maybe wait for deletions to finish. */
818 	wait_skb_queue_empty(&dev->rxq);
819 	wait_skb_queue_empty(&dev->txq);
820 	wait_skb_queue_empty(&dev->done);
821 	netif_dbg(dev, ifdown, dev->net,
822 		  "waited for %d urb completions\n", temp);
823 	set_current_state(TASK_RUNNING);
824 	remove_wait_queue(&dev->wait, &wait);
825 }
826 
827 int usbnet_stop(struct net_device *net)
828 {
829 	struct usbnet		*dev = netdev_priv(net);
830 	const struct driver_info *info = dev->driver_info;
831 	int			retval, pm, mpn;
832 
833 	clear_bit(EVENT_DEV_OPEN, &dev->flags);
834 	netif_stop_queue(net);
835 
836 	netif_info(dev, ifdown, dev->net,
837 		   "stop stats: rx/tx %lu/%lu, errs %lu/%lu\n",
838 		   net->stats.rx_packets, net->stats.tx_packets,
839 		   net->stats.rx_errors, net->stats.tx_errors);
840 
841 	/* to not race resume */
842 	pm = usb_autopm_get_interface(dev->intf);
843 	/* allow minidriver to stop correctly (wireless devices to turn off
844 	 * radio etc) */
845 	if (info->stop) {
846 		retval = info->stop(dev);
847 		if (retval < 0)
848 			netif_info(dev, ifdown, dev->net,
849 				   "stop fail (%d) usbnet usb-%s-%s, %s\n",
850 				   retval,
851 				   dev->udev->bus->bus_name, dev->udev->devpath,
852 				   info->description);
853 	}
854 
855 	if (!(info->flags & FLAG_AVOID_UNLINK_URBS))
856 		usbnet_terminate_urbs(dev);
857 
858 	usbnet_status_stop(dev);
859 
860 	usbnet_purge_paused_rxq(dev);
861 
862 	mpn = !test_and_clear_bit(EVENT_NO_RUNTIME_PM, &dev->flags);
863 
864 	/* deferred work (timer, softirq, task) must also stop */
865 	dev->flags = 0;
866 	timer_delete_sync(&dev->delay);
867 	cancel_work_sync(&dev->bh_work);
868 	cancel_work_sync(&dev->kevent);
869 
870 	/* We have cyclic dependencies. Those calls are needed
871 	 * to break a cycle. We cannot fall into the gaps because
872 	 * we have a flag
873 	 */
874 	cancel_work_sync(&dev->bh_work);
875 	timer_delete_sync(&dev->delay);
876 	cancel_work_sync(&dev->kevent);
877 
878 	netdev_reset_queue(net);
879 
880 	if (!pm)
881 		usb_autopm_put_interface(dev->intf);
882 
883 	if (info->manage_power && mpn)
884 		info->manage_power(dev, 0);
885 	else
886 		usb_autopm_put_interface(dev->intf);
887 
888 	return 0;
889 }
890 EXPORT_SYMBOL_GPL(usbnet_stop);
891 
892 /*-------------------------------------------------------------------------*/
893 
894 // posts reads, and enables write queuing
895 
896 // precondition: never called in_interrupt
897 
898 int usbnet_open(struct net_device *net)
899 {
900 	struct usbnet		*dev = netdev_priv(net);
901 	int			retval;
902 	const struct driver_info *info = dev->driver_info;
903 
904 	if ((retval = usb_autopm_get_interface(dev->intf)) < 0) {
905 		netif_info(dev, ifup, dev->net,
906 			   "resumption fail (%d) usbnet usb-%s-%s, %s\n",
907 			   retval,
908 			   dev->udev->bus->bus_name,
909 			   dev->udev->devpath,
910 			   info->description);
911 		goto done_nopm;
912 	}
913 
914 	// put into "known safe" state
915 	if (info->reset) {
916 		retval = info->reset(dev);
917 		if (retval < 0) {
918 			netif_info(dev, ifup, dev->net,
919 				   "open reset fail (%d) usbnet usb-%s-%s, %s\n",
920 				   retval,
921 				   dev->udev->bus->bus_name,
922 				   dev->udev->devpath,
923 				   info->description);
924 			goto done;
925 		}
926 	}
927 
928 	/* hard_mtu or rx_urb_size may change in reset() */
929 	usbnet_update_max_qlen(dev);
930 
931 	// insist peer be connected
932 	if (info->check_connect) {
933 		retval = info->check_connect(dev);
934 		if (retval < 0) {
935 			netif_err(dev, ifup, dev->net, "can't open; %d\n", retval);
936 			goto done;
937 		}
938 	}
939 
940 	/* start any status interrupt transfer */
941 	if (dev->interrupt) {
942 		retval = usbnet_status_start(dev, GFP_KERNEL);
943 		if (retval < 0) {
944 			netif_err(dev, ifup, dev->net,
945 				  "intr submit %d\n", retval);
946 			goto done;
947 		}
948 	}
949 
950 	set_bit(EVENT_DEV_OPEN, &dev->flags);
951 	netdev_reset_queue(net);
952 	netif_start_queue (net);
953 	netif_info(dev, ifup, dev->net,
954 		   "open: enable queueing (rx %d, tx %d) mtu %d %s framing\n",
955 		   (int)RX_QLEN(dev), (int)TX_QLEN(dev),
956 		   dev->net->mtu,
957 		   (dev->driver_info->flags & FLAG_FRAMING_NC) ? "NetChip" :
958 		   (dev->driver_info->flags & FLAG_FRAMING_GL) ? "GeneSys" :
959 		   (dev->driver_info->flags & FLAG_FRAMING_Z) ? "Zaurus" :
960 		   (dev->driver_info->flags & FLAG_FRAMING_RN) ? "RNDIS" :
961 		   (dev->driver_info->flags & FLAG_FRAMING_AX) ? "ASIX" :
962 		   "simple");
963 
964 	/* reset rx error state */
965 	dev->pkt_cnt = 0;
966 	dev->pkt_err = 0;
967 	clear_bit(EVENT_RX_KILL, &dev->flags);
968 
969 	// delay posting reads until we're fully open
970 	queue_work(system_bh_wq, &dev->bh_work);
971 	if (info->manage_power) {
972 		retval = info->manage_power(dev, 1);
973 		if (retval < 0) {
974 			retval = 0;
975 			set_bit(EVENT_NO_RUNTIME_PM, &dev->flags);
976 		} else {
977 			usb_autopm_put_interface(dev->intf);
978 		}
979 	}
980 	return retval;
981 done:
982 	usb_autopm_put_interface(dev->intf);
983 done_nopm:
984 	return retval;
985 }
986 EXPORT_SYMBOL_GPL(usbnet_open);
987 
988 /*-------------------------------------------------------------------------*/
989 
990 /* ethtool methods; minidrivers may need to add some more, but
991  * they'll probably want to use this base set.
992  */
993 
994 /* These methods are written on the assumption that the device
995  * uses MII
996  */
997 int usbnet_get_link_ksettings_mii(struct net_device *net,
998 			      struct ethtool_link_ksettings *cmd)
999 {
1000 	struct usbnet *dev = netdev_priv(net);
1001 
1002 	if (!dev->mii.mdio_read)
1003 		return -EOPNOTSUPP;
1004 
1005 	mii_ethtool_get_link_ksettings(&dev->mii, cmd);
1006 
1007 	return 0;
1008 }
1009 EXPORT_SYMBOL_GPL(usbnet_get_link_ksettings_mii);
1010 
1011 int usbnet_get_link_ksettings_internal(struct net_device *net,
1012 					struct ethtool_link_ksettings *cmd)
1013 {
1014 	struct usbnet *dev = netdev_priv(net);
1015 
1016 	/* the assumption that speed is equal on tx and rx
1017 	 * is deeply engrained into the networking layer.
1018 	 * For wireless stuff it is not true.
1019 	 * We assume that rx_speed matters more.
1020 	 */
1021 	if (dev->rx_speed != SPEED_UNSET)
1022 		cmd->base.speed = dev->rx_speed / 1000000;
1023 	else if (dev->tx_speed != SPEED_UNSET)
1024 		cmd->base.speed = dev->tx_speed / 1000000;
1025 	else
1026 		cmd->base.speed = SPEED_UNKNOWN;
1027 
1028 	/* The standard "Universal Serial Bus Class Definitions
1029 	 * for Communications Devices v1.2" does not specify
1030 	 * anything about duplex status.
1031 	 * So set it DUPLEX_UNKNOWN instead of default DUPLEX_HALF.
1032 	 */
1033 	cmd->base.duplex = DUPLEX_UNKNOWN;
1034 
1035 	return 0;
1036 }
1037 EXPORT_SYMBOL_GPL(usbnet_get_link_ksettings_internal);
1038 
1039 int usbnet_set_link_ksettings_mii(struct net_device *net,
1040 			      const struct ethtool_link_ksettings *cmd)
1041 {
1042 	struct usbnet *dev = netdev_priv(net);
1043 	int retval;
1044 
1045 	if (!dev->mii.mdio_write)
1046 		return -EOPNOTSUPP;
1047 
1048 	retval = mii_ethtool_set_link_ksettings(&dev->mii, cmd);
1049 
1050 	/* link speed/duplex might have changed */
1051 	if (dev->driver_info->link_reset)
1052 		dev->driver_info->link_reset(dev);
1053 
1054 	/* hard_mtu or rx_urb_size may change in link_reset() */
1055 	usbnet_update_max_qlen(dev);
1056 
1057 	return retval;
1058 }
1059 EXPORT_SYMBOL_GPL(usbnet_set_link_ksettings_mii);
1060 
1061 u32 usbnet_get_link(struct net_device *net)
1062 {
1063 	struct usbnet *dev = netdev_priv(net);
1064 
1065 	/* If a check_connect is defined, return its result */
1066 	if (dev->driver_info->check_connect)
1067 		return dev->driver_info->check_connect(dev) == 0;
1068 
1069 	/* if the device has mii operations, use those */
1070 	if (dev->mii.mdio_read)
1071 		return mii_link_ok(&dev->mii);
1072 
1073 	/* Otherwise, dtrt for drivers calling netif_carrier_{on,off} */
1074 	return ethtool_op_get_link(net);
1075 }
1076 EXPORT_SYMBOL_GPL(usbnet_get_link);
1077 
1078 int usbnet_nway_reset(struct net_device *net)
1079 {
1080 	struct usbnet *dev = netdev_priv(net);
1081 
1082 	if (!dev->mii.mdio_write)
1083 		return -EOPNOTSUPP;
1084 
1085 	return mii_nway_restart(&dev->mii);
1086 }
1087 EXPORT_SYMBOL_GPL(usbnet_nway_reset);
1088 
1089 void usbnet_get_drvinfo(struct net_device *net, struct ethtool_drvinfo *info)
1090 {
1091 	struct usbnet *dev = netdev_priv(net);
1092 
1093 	strscpy(info->driver, dev->driver_name, sizeof(info->driver));
1094 	strscpy(info->fw_version, dev->driver_info->description,
1095 		sizeof(info->fw_version));
1096 	usb_make_path(dev->udev, info->bus_info, sizeof(info->bus_info));
1097 }
1098 EXPORT_SYMBOL_GPL(usbnet_get_drvinfo);
1099 
1100 u32 usbnet_get_msglevel(struct net_device *net)
1101 {
1102 	struct usbnet *dev = netdev_priv(net);
1103 
1104 	return dev->msg_enable;
1105 }
1106 EXPORT_SYMBOL_GPL(usbnet_get_msglevel);
1107 
1108 void usbnet_set_msglevel(struct net_device *net, u32 level)
1109 {
1110 	struct usbnet *dev = netdev_priv(net);
1111 
1112 	dev->msg_enable = level;
1113 }
1114 EXPORT_SYMBOL_GPL(usbnet_set_msglevel);
1115 
1116 /* drivers may override default ethtool_ops in their bind() routine */
1117 static const struct ethtool_ops usbnet_ethtool_ops = {
1118 	.get_link		= usbnet_get_link,
1119 	.nway_reset		= usbnet_nway_reset,
1120 	.get_drvinfo		= usbnet_get_drvinfo,
1121 	.get_msglevel		= usbnet_get_msglevel,
1122 	.set_msglevel		= usbnet_set_msglevel,
1123 	.get_ts_info		= ethtool_op_get_ts_info,
1124 	.get_link_ksettings	= usbnet_get_link_ksettings_mii,
1125 	.set_link_ksettings	= usbnet_set_link_ksettings_mii,
1126 };
1127 
1128 /*-------------------------------------------------------------------------*/
1129 
1130 static void __handle_link_change(struct usbnet *dev)
1131 {
1132 	if (!test_bit(EVENT_DEV_OPEN, &dev->flags))
1133 		return;
1134 
1135 	if (test_and_clear_bit(EVENT_LINK_CARRIER_ON, &dev->flags))
1136 		netif_carrier_on(dev->net);
1137 
1138 	if (!netif_carrier_ok(dev->net)) {
1139 		/* kill URBs for reading packets to save bus bandwidth */
1140 		unlink_urbs(dev, &dev->rxq);
1141 
1142 		/*
1143 		 * tx_timeout will unlink URBs for sending packets and
1144 		 * tx queue is stopped by netcore after link becomes off
1145 		 */
1146 	} else {
1147 		/* submitting URBs for reading packets */
1148 		queue_work(system_bh_wq, &dev->bh_work);
1149 	}
1150 
1151 	/* hard_mtu or rx_urb_size may change during link change */
1152 	usbnet_update_max_qlen(dev);
1153 
1154 	clear_bit(EVENT_LINK_CHANGE, &dev->flags);
1155 }
1156 
1157 void usbnet_set_rx_mode(struct net_device *net)
1158 {
1159 	struct usbnet		*dev = netdev_priv(net);
1160 
1161 	usbnet_defer_kevent(dev, EVENT_SET_RX_MODE);
1162 }
1163 EXPORT_SYMBOL_GPL(usbnet_set_rx_mode);
1164 
1165 static void __handle_set_rx_mode(struct usbnet *dev)
1166 {
1167 	if (dev->driver_info->set_rx_mode)
1168 		(dev->driver_info->set_rx_mode)(dev);
1169 
1170 	clear_bit(EVENT_SET_RX_MODE, &dev->flags);
1171 }
1172 
1173 /* work that cannot be done in interrupt context uses keventd.
1174  *
1175  * NOTE:  with 2.5 we could do more of this using completion callbacks,
1176  * especially now that control transfers can be queued.
1177  */
1178 static void
1179 usbnet_deferred_kevent(struct work_struct *work)
1180 {
1181 	struct usbnet		*dev =
1182 		container_of(work, struct usbnet, kevent);
1183 	int			status;
1184 
1185 	/* usb_clear_halt() needs a thread context */
1186 	if (test_bit(EVENT_TX_HALT, &dev->flags)) {
1187 		unlink_urbs(dev, &dev->txq);
1188 		status = usb_autopm_get_interface(dev->intf);
1189 		if (status < 0)
1190 			goto fail_pipe;
1191 		status = usb_clear_halt(dev->udev, dev->out);
1192 		usb_autopm_put_interface(dev->intf);
1193 		if (status < 0 &&
1194 		    status != -EPIPE &&
1195 		    status != -ESHUTDOWN) {
1196 			if (netif_msg_tx_err(dev))
1197 fail_pipe:
1198 				netdev_err(dev->net, "can't clear tx halt, status %d\n",
1199 					   status);
1200 		} else {
1201 			clear_bit(EVENT_TX_HALT, &dev->flags);
1202 			if (status != -ESHUTDOWN)
1203 				netif_wake_queue(dev->net);
1204 		}
1205 	}
1206 	if (test_bit(EVENT_RX_HALT, &dev->flags)) {
1207 		unlink_urbs(dev, &dev->rxq);
1208 		status = usb_autopm_get_interface(dev->intf);
1209 		if (status < 0)
1210 			goto fail_halt;
1211 		status = usb_clear_halt(dev->udev, dev->in);
1212 		usb_autopm_put_interface(dev->intf);
1213 		if (status < 0 &&
1214 		    status != -EPIPE &&
1215 		    status != -ESHUTDOWN) {
1216 			if (netif_msg_rx_err(dev))
1217 fail_halt:
1218 				netdev_err(dev->net, "can't clear rx halt, status %d\n",
1219 					   status);
1220 		} else {
1221 			clear_bit(EVENT_RX_HALT, &dev->flags);
1222 			if (!usbnet_going_away(dev))
1223 				queue_work(system_bh_wq, &dev->bh_work);
1224 		}
1225 	}
1226 
1227 	/* work could resubmit itself forever if memory is tight */
1228 	if (test_bit(EVENT_RX_MEMORY, &dev->flags)) {
1229 		struct urb	*urb = NULL;
1230 		int resched = 1;
1231 
1232 		if (netif_running(dev->net))
1233 			urb = usb_alloc_urb(0, GFP_KERNEL);
1234 		else
1235 			clear_bit(EVENT_RX_MEMORY, &dev->flags);
1236 		if (urb != NULL) {
1237 			clear_bit(EVENT_RX_MEMORY, &dev->flags);
1238 			status = usb_autopm_get_interface(dev->intf);
1239 			if (status < 0) {
1240 				usb_free_urb(urb);
1241 				goto fail_lowmem;
1242 			}
1243 			if (rx_submit(dev, urb, GFP_KERNEL) == -ENOLINK)
1244 				resched = 0;
1245 			usb_autopm_put_interface(dev->intf);
1246 fail_lowmem:
1247 			if (resched)
1248 				if (!usbnet_going_away(dev))
1249 					queue_work(system_bh_wq, &dev->bh_work);
1250 		}
1251 	}
1252 
1253 	if (test_bit (EVENT_LINK_RESET, &dev->flags)) {
1254 		const struct driver_info *info = dev->driver_info;
1255 		int			retval = 0;
1256 
1257 		clear_bit(EVENT_LINK_RESET, &dev->flags);
1258 		status = usb_autopm_get_interface(dev->intf);
1259 		if (status < 0)
1260 			goto skip_reset;
1261 		if(info->link_reset && (retval = info->link_reset(dev)) < 0) {
1262 			usb_autopm_put_interface(dev->intf);
1263 skip_reset:
1264 			netdev_info(dev->net, "link reset failed (%d) usbnet usb-%s-%s, %s\n",
1265 				    retval,
1266 				    dev->udev->bus->bus_name,
1267 				    dev->udev->devpath,
1268 				    info->description);
1269 		} else {
1270 			usb_autopm_put_interface(dev->intf);
1271 		}
1272 
1273 		/* handle link change from link resetting */
1274 		__handle_link_change(dev);
1275 	}
1276 
1277 	if (test_bit(EVENT_LINK_CHANGE, &dev->flags))
1278 		__handle_link_change(dev);
1279 
1280 	if (test_bit(EVENT_SET_RX_MODE, &dev->flags))
1281 		__handle_set_rx_mode(dev);
1282 
1283 
1284 	if (dev->flags)
1285 		netdev_dbg(dev->net, "kevent done, flags = 0x%lx\n", dev->flags);
1286 }
1287 
1288 /*-------------------------------------------------------------------------*/
1289 
1290 static void tx_complete(struct urb *urb)
1291 {
1292 	struct sk_buff		*skb = (struct sk_buff *) urb->context;
1293 	struct skb_data		*entry = (struct skb_data *) skb->cb;
1294 	struct usbnet		*dev = entry->dev;
1295 
1296 	if (urb->status == 0) {
1297 		struct pcpu_sw_netstats *stats64 = this_cpu_ptr(dev->net->tstats);
1298 		unsigned long flags;
1299 
1300 		flags = u64_stats_update_begin_irqsave(&stats64->syncp);
1301 		u64_stats_add(&stats64->tx_packets, entry->packets);
1302 		u64_stats_add(&stats64->tx_bytes, entry->length);
1303 		u64_stats_update_end_irqrestore(&stats64->syncp, flags);
1304 	} else {
1305 		dev->net->stats.tx_errors++;
1306 
1307 		switch (urb->status) {
1308 		case -EPIPE:
1309 			usbnet_defer_kevent(dev, EVENT_TX_HALT);
1310 			break;
1311 
1312 		/* software-driven interface shutdown */
1313 		case -ECONNRESET:		// async unlink
1314 		case -ESHUTDOWN:		// hardware gone
1315 			break;
1316 
1317 		/* like rx, tx gets controller i/o faults during hub_wq
1318 		 * delays and so it uses the same throttling mechanism.
1319 		 */
1320 		case -EPROTO:
1321 		case -ETIME:
1322 		case -EILSEQ:
1323 			usb_mark_last_busy(dev->udev);
1324 			if (!timer_pending(&dev->delay)) {
1325 				mod_timer(&dev->delay,
1326 					  jiffies + THROTTLE_JIFFIES);
1327 				netif_dbg(dev, link, dev->net,
1328 					  "tx throttle %d\n", urb->status);
1329 			}
1330 			netif_stop_queue(dev->net);
1331 			break;
1332 		default:
1333 			netif_dbg(dev, tx_err, dev->net,
1334 				  "tx err %d\n", entry->urb->status);
1335 			break;
1336 		}
1337 	}
1338 
1339 	usb_autopm_put_interface_async(dev->intf);
1340 	(void) defer_bh(dev, skb, &dev->txq, tx_done);
1341 }
1342 
1343 /*-------------------------------------------------------------------------*/
1344 
1345 void usbnet_tx_timeout(struct net_device *net, unsigned int txqueue)
1346 {
1347 	struct usbnet		*dev = netdev_priv(net);
1348 
1349 	unlink_urbs(dev, &dev->txq);
1350 	queue_work(system_bh_wq, &dev->bh_work);
1351 	/* this needs to be handled individually because the generic layer
1352 	 * doesn't know what is sufficient and could not restore private
1353 	 * information if a remedy of an unconditional reset were used.
1354 	 */
1355 	if (dev->driver_info->recover)
1356 		(dev->driver_info->recover)(dev);
1357 }
1358 EXPORT_SYMBOL_GPL(usbnet_tx_timeout);
1359 
1360 /*-------------------------------------------------------------------------*/
1361 
1362 static int build_dma_sg(const struct sk_buff *skb, struct urb *urb)
1363 {
1364 	unsigned num_sgs, total_len = 0;
1365 	int i, s = 0;
1366 
1367 	num_sgs = skb_shinfo(skb)->nr_frags + 1;
1368 	if (num_sgs == 1)
1369 		return 0;
1370 
1371 	/* reserve one for zero packet */
1372 	urb->sg = kmalloc_array(num_sgs + 1, sizeof(struct scatterlist),
1373 				GFP_ATOMIC);
1374 	if (!urb->sg)
1375 		return -ENOMEM;
1376 
1377 	urb->num_sgs = num_sgs;
1378 	sg_init_table(urb->sg, urb->num_sgs + 1);
1379 
1380 	sg_set_buf(&urb->sg[s++], skb->data, skb_headlen(skb));
1381 	total_len += skb_headlen(skb);
1382 
1383 	for (i = 0; i < skb_shinfo(skb)->nr_frags; i++) {
1384 		skb_frag_t *f = &skb_shinfo(skb)->frags[i];
1385 
1386 		total_len += skb_frag_size(f);
1387 		sg_set_page(&urb->sg[i + s], skb_frag_page(f), skb_frag_size(f),
1388 			    skb_frag_off(f));
1389 	}
1390 	urb->transfer_buffer_length = total_len;
1391 
1392 	return 1;
1393 }
1394 
1395 netdev_tx_t usbnet_start_xmit(struct sk_buff *skb, struct net_device *net)
1396 {
1397 	struct usbnet		*dev = netdev_priv(net);
1398 	unsigned int			length;
1399 	struct urb		*urb = NULL;
1400 	struct skb_data		*entry;
1401 	const struct driver_info *info = dev->driver_info;
1402 	unsigned long		flags;
1403 	int retval;
1404 
1405 	if (skb)
1406 		skb_tx_timestamp(skb);
1407 
1408 	// some devices want funky USB-level framing, for
1409 	// win32 driver (usually) and/or hardware quirks
1410 	if (info->tx_fixup) {
1411 		skb = info->tx_fixup(dev, skb, GFP_ATOMIC);
1412 		if (!skb) {
1413 			/* packet collected; minidriver waiting for more */
1414 			if (info->flags & FLAG_MULTI_PACKET)
1415 				goto not_drop;
1416 			netif_dbg(dev, tx_err, dev->net, "can't tx_fixup skb\n");
1417 			goto drop;
1418 		}
1419 	}
1420 
1421 	urb = usb_alloc_urb(0, GFP_ATOMIC);
1422 	if (!urb) {
1423 		netif_dbg(dev, tx_err, dev->net, "no urb\n");
1424 		goto drop;
1425 	}
1426 
1427 	entry = (struct skb_data *) skb->cb;
1428 	entry->urb = urb;
1429 	entry->dev = dev;
1430 
1431 	usb_fill_bulk_urb(urb, dev->udev, dev->out,
1432 			  skb->data, skb->len, tx_complete, skb);
1433 	if (dev->can_dma_sg) {
1434 		if (build_dma_sg(skb, urb) < 0)
1435 			goto drop;
1436 	}
1437 	length = urb->transfer_buffer_length;
1438 
1439 	/* don't assume the hardware handles USB_ZERO_PACKET
1440 	 * NOTE:  strictly conforming cdc-ether devices should expect
1441 	 * the ZLP here, but ignore the one-byte packet.
1442 	 * NOTE2: CDC NCM specification is different from CDC ECM when
1443 	 * handling ZLP/short packets, so cdc_ncm driver will make short
1444 	 * packet itself if needed.
1445 	 */
1446 	if (length % dev->maxpacket == 0) {
1447 		if (!(info->flags & FLAG_SEND_ZLP)) {
1448 			if (!(info->flags & FLAG_MULTI_PACKET)) {
1449 				length++;
1450 				if (skb_tailroom(skb) && !urb->num_sgs) {
1451 					skb->data[skb->len] = 0;
1452 					__skb_put(skb, 1);
1453 				} else if (urb->num_sgs)
1454 					sg_set_buf(&urb->sg[urb->num_sgs++],
1455 							dev->padding_pkt, 1);
1456 			}
1457 		} else
1458 			urb->transfer_flags |= URB_ZERO_PACKET;
1459 	}
1460 	urb->transfer_buffer_length = length;
1461 
1462 	if (info->flags & FLAG_MULTI_PACKET) {
1463 		/* Driver has set number of packets and a length delta.
1464 		 * Calculate the complete length and ensure that it's
1465 		 * positive.
1466 		 */
1467 		entry->length += length;
1468 		if (WARN_ON_ONCE(entry->length <= 0))
1469 			entry->length = length;
1470 	} else {
1471 		usbnet_set_skb_tx_stats(skb, 1, length);
1472 	}
1473 
1474 	spin_lock_irqsave(&dev->txq.lock, flags);
1475 	retval = usb_autopm_get_interface_async(dev->intf);
1476 	if (retval < 0) {
1477 		spin_unlock_irqrestore(&dev->txq.lock, flags);
1478 		goto drop;
1479 	}
1480 	if (netif_queue_stopped(net)) {
1481 		usb_autopm_put_interface_async(dev->intf);
1482 		spin_unlock_irqrestore(&dev->txq.lock, flags);
1483 		goto drop;
1484 	}
1485 
1486 #ifdef CONFIG_PM
1487 	/* if this triggers the device is still a sleep */
1488 	if (test_bit(EVENT_DEV_ASLEEP, &dev->flags)) {
1489 		/* transmission will be done in resume */
1490 		usb_anchor_urb(urb, &dev->deferred);
1491 		/* no use to process more packets */
1492 		netif_stop_queue(net);
1493 		usb_put_urb(urb);
1494 		spin_unlock_irqrestore(&dev->txq.lock, flags);
1495 		netdev_dbg(dev->net, "Delaying transmission for resumption\n");
1496 		goto deferred;
1497 	}
1498 #endif
1499 
1500 	switch ((retval = usb_submit_urb (urb, GFP_ATOMIC))) {
1501 	case -EPIPE:
1502 		netif_stop_queue(net);
1503 		usbnet_defer_kevent(dev, EVENT_TX_HALT);
1504 		usb_autopm_put_interface_async(dev->intf);
1505 		break;
1506 	default:
1507 		usb_autopm_put_interface_async(dev->intf);
1508 		netif_dbg(dev, tx_err, dev->net,
1509 			  "tx: submit urb err %d\n", retval);
1510 		break;
1511 	case 0:
1512 		netif_trans_update(net);
1513 		__usbnet_queue_skb(&dev->txq, skb, tx_start);
1514 		netdev_sent_queue(net, skb->len);
1515 		if (dev->txq.qlen >= TX_QLEN (dev))
1516 			netif_stop_queue (net);
1517 	}
1518 	spin_unlock_irqrestore(&dev->txq.lock, flags);
1519 
1520 	if (retval) {
1521 		netif_dbg(dev, tx_err, dev->net, "drop, code %d\n", retval);
1522 drop:
1523 		dev->net->stats.tx_dropped++;
1524 not_drop:
1525 		if (skb)
1526 			dev_kfree_skb_any(skb);
1527 		if (urb) {
1528 			kfree(urb->sg);
1529 			usb_free_urb(urb);
1530 		}
1531 	} else
1532 		netif_dbg(dev, tx_queued, dev->net,
1533 			  "> tx, len %u, type 0x%x\n", length, skb->protocol);
1534 #ifdef CONFIG_PM
1535 deferred:
1536 #endif
1537 	return NETDEV_TX_OK;
1538 }
1539 EXPORT_SYMBOL_GPL(usbnet_start_xmit);
1540 
1541 static int rx_alloc_submit(struct usbnet *dev, gfp_t flags)
1542 {
1543 	struct urb	*urb;
1544 	int		i;
1545 	int		ret = 0;
1546 
1547 	/* don't refill the queue all at once */
1548 	for (i = 0; i < 10 && dev->rxq.qlen < RX_QLEN(dev); i++) {
1549 		urb = usb_alloc_urb(0, flags);
1550 		if (urb != NULL) {
1551 			ret = rx_submit(dev, urb, flags);
1552 			if (ret)
1553 				goto err;
1554 		} else {
1555 			ret = -ENOMEM;
1556 			goto err;
1557 		}
1558 	}
1559 err:
1560 	return ret;
1561 }
1562 
1563 static inline void usb_free_skb(struct sk_buff *skb)
1564 {
1565 	struct skb_data *entry = (struct skb_data *)skb->cb;
1566 
1567 	usb_free_urb(entry->urb);
1568 	dev_kfree_skb(skb);
1569 }
1570 
1571 /*-------------------------------------------------------------------------*/
1572 
1573 // work (work deferred from completions, in_irq) or timer
1574 
1575 static void usbnet_bh(struct timer_list *t)
1576 {
1577 	struct usbnet		*dev = timer_container_of(dev, t, delay);
1578 	unsigned int bytes_compl = 0, pkts_compl = 0;
1579 	struct sk_buff		*skb;
1580 	struct skb_data		*entry;
1581 
1582 	while ((skb = skb_dequeue (&dev->done))) {
1583 		entry = (struct skb_data *) skb->cb;
1584 		switch (entry->state) {
1585 		case rx_done:
1586 			if (rx_process(dev, skb))
1587 				usb_free_skb(skb);
1588 			continue;
1589 		case tx_done:
1590 			bytes_compl += skb->len;
1591 			pkts_compl++;
1592 			kfree(entry->urb->sg);
1593 			fallthrough;
1594 		case rx_cleanup:
1595 			usb_free_skb(skb);
1596 			continue;
1597 		default:
1598 			netdev_dbg(dev->net, "bogus skb state %d\n", entry->state);
1599 		}
1600 	}
1601 
1602 	spin_lock_bh(&dev->bql_spinlock);
1603 	netdev_completed_queue(dev->net, pkts_compl, bytes_compl);
1604 	spin_unlock_bh(&dev->bql_spinlock);
1605 
1606 	/* restart RX again after disabling due to high error rate */
1607 	clear_bit(EVENT_RX_KILL, &dev->flags);
1608 
1609 	/* waiting for all pending urbs to complete?
1610 	 * only then can we forgo submitting anew
1611 	 */
1612 	if (waitqueue_active(&dev->wait)) {
1613 		if (dev->txq.qlen + dev->rxq.qlen + dev->done.qlen == 0)
1614 			wake_up_all(&dev->wait);
1615 
1616 	// or are we maybe short a few urbs?
1617 	} else if (netif_running (dev->net) &&
1618 		   netif_device_present (dev->net) &&
1619 		   netif_carrier_ok(dev->net) &&
1620 		   !usbnet_going_away(dev) &&
1621 		   !timer_pending(&dev->delay) &&
1622 		   !test_bit(EVENT_RX_PAUSED, &dev->flags) &&
1623 		   !test_bit(EVENT_RX_HALT, &dev->flags)) {
1624 		int	temp = dev->rxq.qlen;
1625 
1626 		if (temp < RX_QLEN(dev)) {
1627 			if (rx_alloc_submit(dev, GFP_ATOMIC) == -ENOLINK)
1628 				return;
1629 			if (temp != dev->rxq.qlen)
1630 				netif_dbg(dev, link, dev->net,
1631 					  "rxqlen %d --> %d\n",
1632 					  temp, dev->rxq.qlen);
1633 			if (dev->rxq.qlen < RX_QLEN(dev))
1634 				queue_work(system_bh_wq, &dev->bh_work);
1635 		}
1636 		if (dev->txq.qlen < TX_QLEN (dev))
1637 			netif_wake_queue(dev->net);
1638 	}
1639 }
1640 
1641 static void usbnet_bh_work(struct work_struct *work)
1642 {
1643 	struct usbnet *dev = from_work(dev, work, bh_work);
1644 
1645 	usbnet_bh(&dev->delay);
1646 }
1647 
1648 
1649 /*-------------------------------------------------------------------------
1650  *
1651  * USB Device Driver support
1652  *
1653  *-------------------------------------------------------------------------*/
1654 
1655 // precondition: never called in_interrupt
1656 
1657 void usbnet_disconnect(struct usb_interface *intf)
1658 {
1659 	struct usbnet		*dev;
1660 	struct usb_device	*xdev;
1661 	struct net_device	*net;
1662 	struct urb		*urb;
1663 
1664 	dev = usb_get_intfdata(intf);
1665 	usb_set_intfdata(intf, NULL);
1666 	if (!dev)
1667 		return;
1668 	usbnet_mark_going_away(dev);
1669 
1670 	xdev = interface_to_usbdev(intf);
1671 
1672 	netif_info(dev, probe, dev->net, "unregister '%s' usb-%s-%s, %s\n",
1673 		   intf->dev.driver->name,
1674 		   xdev->bus->bus_name, xdev->devpath,
1675 		   dev->driver_info->description);
1676 
1677 	net = dev->net;
1678 	unregister_netdev(net);
1679 
1680 	cancel_work_sync(&dev->kevent);
1681 
1682 	while ((urb = usb_get_from_anchor(&dev->deferred))) {
1683 		dev_kfree_skb(urb->context);
1684 		kfree(urb->sg);
1685 		usb_free_urb(urb);
1686 	}
1687 
1688 	if (dev->driver_info->unbind)
1689 		dev->driver_info->unbind(dev, intf);
1690 
1691 	usb_kill_urb(dev->interrupt);
1692 	usb_free_urb(dev->interrupt);
1693 	kfree(dev->padding_pkt);
1694 
1695 	free_netdev(net);
1696 }
1697 EXPORT_SYMBOL_GPL(usbnet_disconnect);
1698 
1699 static const struct net_device_ops usbnet_netdev_ops = {
1700 	.ndo_open		= usbnet_open,
1701 	.ndo_stop		= usbnet_stop,
1702 	.ndo_start_xmit		= usbnet_start_xmit,
1703 	.ndo_tx_timeout		= usbnet_tx_timeout,
1704 	.ndo_set_rx_mode	= usbnet_set_rx_mode,
1705 	.ndo_change_mtu		= usbnet_change_mtu,
1706 	.ndo_set_mac_address 	= eth_mac_addr,
1707 	.ndo_validate_addr	= eth_validate_addr,
1708 };
1709 
1710 /*-------------------------------------------------------------------------*/
1711 
1712 // precondition: never called in_interrupt
1713 
1714 static const struct device_type wlan_type = {
1715 	.name	= "wlan",
1716 };
1717 
1718 static const struct device_type wwan_type = {
1719 	.name	= "wwan",
1720 };
1721 
1722 int
1723 usbnet_probe(struct usb_interface *udev, const struct usb_device_id *prod)
1724 {
1725 	struct usbnet			*dev;
1726 	struct net_device		*net;
1727 	struct usb_host_interface	*interface;
1728 	const struct driver_info	*info;
1729 	struct usb_device		*xdev;
1730 	int				status;
1731 	const char			*name;
1732 	struct usb_driver 	*driver = to_usb_driver(udev->dev.driver);
1733 
1734 	/* usbnet already took usb runtime pm, so have to enable the feature
1735 	 * for usb interface, otherwise usb_autopm_get_interface may return
1736 	 * failure if RUNTIME_PM is enabled.
1737 	 */
1738 	if (!driver->supports_autosuspend) {
1739 		driver->supports_autosuspend = 1;
1740 		pm_runtime_enable(&udev->dev);
1741 	}
1742 
1743 	name = udev->dev.driver->name;
1744 	info = (const struct driver_info *) prod->driver_info;
1745 	if (!info) {
1746 		dev_dbg (&udev->dev, "blacklisted by %s\n", name);
1747 		return -ENODEV;
1748 	}
1749 	xdev = interface_to_usbdev(udev);
1750 	interface = udev->cur_altsetting;
1751 
1752 	status = -ENOMEM;
1753 
1754 	// set up our own records
1755 	net = alloc_etherdev(sizeof(*dev));
1756 	if (!net)
1757 		goto out;
1758 
1759 	/* netdev_printk() needs this so do it as early as possible */
1760 	SET_NETDEV_DEV(net, &udev->dev);
1761 
1762 	dev = netdev_priv(net);
1763 	dev->udev = xdev;
1764 	dev->intf = udev;
1765 	dev->driver_info = info;
1766 	dev->driver_name = name;
1767 	dev->rx_speed = SPEED_UNSET;
1768 	dev->tx_speed = SPEED_UNSET;
1769 
1770 	dev->msg_enable = netif_msg_init (msg_level, NETIF_MSG_DRV
1771 				| NETIF_MSG_PROBE | NETIF_MSG_LINK);
1772 	init_waitqueue_head(&dev->wait);
1773 	skb_queue_head_init (&dev->rxq);
1774 	skb_queue_head_init (&dev->txq);
1775 	skb_queue_head_init (&dev->done);
1776 	skb_queue_head_init(&dev->rxq_pause);
1777 	spin_lock_init(&dev->bql_spinlock);
1778 	INIT_WORK(&dev->bh_work, usbnet_bh_work);
1779 	INIT_WORK(&dev->kevent, usbnet_deferred_kevent);
1780 	init_usb_anchor(&dev->deferred);
1781 	timer_setup(&dev->delay, usbnet_bh, 0);
1782 	mutex_init(&dev->phy_mutex);
1783 	mutex_init(&dev->interrupt_mutex);
1784 	dev->interrupt_count = 0;
1785 
1786 	dev->net = net;
1787 	strscpy(net->name, "usb%d", sizeof(net->name));
1788 
1789 	/* rx and tx sides can use different message sizes;
1790 	 * bind() should set rx_urb_size in that case.
1791 	 */
1792 	dev->hard_mtu = net->mtu + net->hard_header_len;
1793 	net->min_mtu = 0;
1794 	net->max_mtu = ETH_MAX_MTU;
1795 
1796 	net->netdev_ops = &usbnet_netdev_ops;
1797 	net->watchdog_timeo = TX_TIMEOUT_JIFFIES;
1798 	net->ethtool_ops = &usbnet_ethtool_ops;
1799 	net->pcpu_stat_type = NETDEV_PCPU_STAT_TSTATS;
1800 
1801 	// allow device-specific bind/init procedures
1802 	// NOTE net->name still not usable ...
1803 	if (info->bind) {
1804 		status = info->bind(dev, udev);
1805 		if (status < 0)
1806 			goto out1;
1807 
1808 		/* heuristic: rename to "eth%d" if we are not sure this link
1809 		 * is two-host (these links keep "usb%d")
1810 		 */
1811 		if ((dev->driver_info->flags & FLAG_ETHER) != 0 &&
1812 		    !usbnet_needs_usb_name_format(dev, net))
1813 			strscpy(net->name, "eth%d", sizeof(net->name));
1814 		/* WLAN devices should always be named "wlan%d" */
1815 		if ((dev->driver_info->flags & FLAG_WLAN) != 0)
1816 			strscpy(net->name, "wlan%d", sizeof(net->name));
1817 		/* WWAN devices should always be named "wwan%d" */
1818 		if ((dev->driver_info->flags & FLAG_WWAN) != 0)
1819 			strscpy(net->name, "wwan%d", sizeof(net->name));
1820 
1821 		/* devices that cannot do ARP */
1822 		if ((dev->driver_info->flags & FLAG_NOARP) != 0)
1823 			net->flags |= IFF_NOARP;
1824 
1825 		/* maybe the remote can't receive an Ethernet MTU */
1826 		if (net->mtu > (dev->hard_mtu - net->hard_header_len))
1827 			net->mtu = dev->hard_mtu - net->hard_header_len;
1828 	} else if (!info->in || !info->out)
1829 		status = usbnet_get_endpoints(dev, udev);
1830 	else {
1831 		u8 ep_addrs[3] = {
1832 			info->in + USB_DIR_IN, info->out + USB_DIR_OUT, 0
1833 		};
1834 
1835 		dev->in = usb_rcvbulkpipe(xdev, info->in);
1836 		dev->out = usb_sndbulkpipe(xdev, info->out);
1837 		if (!(info->flags & FLAG_NO_SETINT))
1838 			status = usb_set_interface(xdev,
1839 						   interface->desc.bInterfaceNumber,
1840 						   interface->desc.bAlternateSetting);
1841 		else
1842 			status = 0;
1843 
1844 		if (status == 0 && !usb_check_bulk_endpoints(udev, ep_addrs))
1845 			status = -EINVAL;
1846 	}
1847 	if (status >= 0 && dev->status)
1848 		status = init_status(dev, udev);
1849 	if (status < 0)
1850 		goto out3;
1851 
1852 	if (!dev->rx_urb_size)
1853 		dev->rx_urb_size = dev->hard_mtu;
1854 	dev->maxpacket = usb_maxpacket(dev->udev, dev->out);
1855 	if (dev->maxpacket == 0) {
1856 		/* that is a broken device */
1857 		status = -ENODEV;
1858 		goto out4;
1859 	}
1860 
1861 	/* this flags the device for user space */
1862 	if (!is_valid_ether_addr(net->dev_addr))
1863 		eth_hw_addr_random(net);
1864 
1865 	if ((dev->driver_info->flags & FLAG_WLAN) != 0)
1866 		SET_NETDEV_DEVTYPE(net, &wlan_type);
1867 	if ((dev->driver_info->flags & FLAG_WWAN) != 0)
1868 		SET_NETDEV_DEVTYPE(net, &wwan_type);
1869 
1870 	/* initialize max rx_qlen and tx_qlen */
1871 	usbnet_update_max_qlen(dev);
1872 
1873 	if (dev->can_dma_sg && !(info->flags & FLAG_SEND_ZLP) &&
1874 		!(info->flags & FLAG_MULTI_PACKET)) {
1875 		dev->padding_pkt = kzalloc(1, GFP_KERNEL);
1876 		if (!dev->padding_pkt) {
1877 			status = -ENOMEM;
1878 			goto out4;
1879 		}
1880 	}
1881 
1882 	status = register_netdev(net);
1883 	if (status)
1884 		goto out5;
1885 	netif_info(dev, probe, dev->net,
1886 		   "register '%s' at usb-%s-%s, %s, %pM\n",
1887 		   udev->dev.driver->name,
1888 		   xdev->bus->bus_name, xdev->devpath,
1889 		   dev->driver_info->description,
1890 		   net->dev_addr);
1891 
1892 	// ok, it's ready to go.
1893 	usb_set_intfdata(udev, dev);
1894 
1895 	netif_device_attach(net);
1896 
1897 	if (dev->driver_info->flags & FLAG_LINK_INTR)
1898 		usbnet_link_change(dev, 0, 0);
1899 
1900 	return 0;
1901 
1902 out5:
1903 	kfree(dev->padding_pkt);
1904 out4:
1905 	usb_free_urb(dev->interrupt);
1906 out3:
1907 	if (info->unbind)
1908 		info->unbind(dev, udev);
1909 out1:
1910 	/* subdrivers must undo all they did in bind() if they
1911 	 * fail it, but we may fail later and a deferred kevent
1912 	 * may trigger an error resubmitting itself and, worse,
1913 	 * schedule a timer. So we kill it all just in case.
1914 	 */
1915 	usbnet_mark_going_away(dev);
1916 	cancel_work_sync(&dev->kevent);
1917 	timer_delete_sync(&dev->delay);
1918 	free_netdev(net);
1919 out:
1920 	return status;
1921 }
1922 EXPORT_SYMBOL_GPL(usbnet_probe);
1923 
1924 /*-------------------------------------------------------------------------*/
1925 
1926 /*
1927  * suspend the whole driver as soon as the first interface is suspended
1928  * resume only when the last interface is resumed
1929  */
1930 
1931 int usbnet_suspend(struct usb_interface *intf, pm_message_t message)
1932 {
1933 	struct usbnet		*dev = usb_get_intfdata(intf);
1934 
1935 	if (!dev->suspend_count++) {
1936 		spin_lock_irq(&dev->txq.lock);
1937 		/* don't autosuspend while transmitting */
1938 		if (dev->txq.qlen && PMSG_IS_AUTO(message)) {
1939 			dev->suspend_count--;
1940 			spin_unlock_irq(&dev->txq.lock);
1941 			return -EBUSY;
1942 		} else {
1943 			set_bit(EVENT_DEV_ASLEEP, &dev->flags);
1944 			spin_unlock_irq(&dev->txq.lock);
1945 		}
1946 		/*
1947 		 * accelerate emptying of the rx and queues, to avoid
1948 		 * having everything error out.
1949 		 */
1950 		netif_device_detach(dev->net);
1951 		usbnet_terminate_urbs(dev);
1952 		__usbnet_status_stop_force(dev);
1953 
1954 		/*
1955 		 * reattach so runtime management can use and
1956 		 * wake the device
1957 		 */
1958 		netif_device_attach(dev->net);
1959 	}
1960 	return 0;
1961 }
1962 EXPORT_SYMBOL_GPL(usbnet_suspend);
1963 
1964 int usbnet_resume(struct usb_interface *intf)
1965 {
1966 	struct usbnet		*dev = usb_get_intfdata(intf);
1967 	struct sk_buff          *skb;
1968 	struct urb              *res;
1969 	int                     retval;
1970 
1971 	if (!--dev->suspend_count) {
1972 		/* resume interrupt URB if it was previously submitted */
1973 		__usbnet_status_start_force(dev, GFP_NOIO);
1974 
1975 		spin_lock_irq(&dev->txq.lock);
1976 		while ((res = usb_get_from_anchor(&dev->deferred))) {
1977 
1978 			skb = (struct sk_buff *)res->context;
1979 			retval = usb_submit_urb(res, GFP_ATOMIC);
1980 			if (retval < 0) {
1981 				dev_kfree_skb_any(skb);
1982 				kfree(res->sg);
1983 				usb_free_urb(res);
1984 				usb_autopm_put_interface_async(dev->intf);
1985 			} else {
1986 				netif_trans_update(dev->net);
1987 				__skb_queue_tail(&dev->txq, skb);
1988 			}
1989 		}
1990 
1991 		smp_mb();
1992 		clear_bit(EVENT_DEV_ASLEEP, &dev->flags);
1993 		spin_unlock_irq(&dev->txq.lock);
1994 
1995 		if (test_bit(EVENT_DEV_OPEN, &dev->flags)) {
1996 			/* handle remote wakeup ASAP
1997 			 * we cannot race against stop
1998 			 */
1999 			if (netif_device_present(dev->net) &&
2000 				!timer_pending(&dev->delay) &&
2001 				!test_bit(EVENT_RX_HALT, &dev->flags))
2002 					rx_alloc_submit(dev, GFP_NOIO);
2003 
2004 			if (!(dev->txq.qlen >= TX_QLEN(dev)))
2005 				netif_tx_wake_all_queues(dev->net);
2006 			queue_work(system_bh_wq, &dev->bh_work);
2007 		}
2008 	}
2009 
2010 	if (test_and_clear_bit(EVENT_DEVICE_REPORT_IDLE, &dev->flags))
2011 		usb_autopm_get_interface_no_resume(intf);
2012 
2013 	return 0;
2014 }
2015 EXPORT_SYMBOL_GPL(usbnet_resume);
2016 
2017 /*
2018  * Either a subdriver implements manage_power, then it is assumed to always
2019  * be ready to be suspended or it reports the readiness to be suspended
2020  * explicitly
2021  */
2022 void usbnet_device_suggests_idle(struct usbnet *dev)
2023 {
2024 	if (!test_and_set_bit(EVENT_DEVICE_REPORT_IDLE, &dev->flags)) {
2025 		dev->intf->needs_remote_wakeup = 1;
2026 		usb_autopm_put_interface_async(dev->intf);
2027 	}
2028 }
2029 EXPORT_SYMBOL(usbnet_device_suggests_idle);
2030 
2031 /*
2032  * For devices that can do without special commands
2033  */
2034 int usbnet_manage_power(struct usbnet *dev, int on)
2035 {
2036 	dev->intf->needs_remote_wakeup = on;
2037 	return 0;
2038 }
2039 EXPORT_SYMBOL(usbnet_manage_power);
2040 
2041 void usbnet_link_change(struct usbnet *dev, bool link, bool need_reset)
2042 {
2043 	/* update link after link is reseted */
2044 	if (link && !need_reset) {
2045 		set_bit(EVENT_LINK_CARRIER_ON, &dev->flags);
2046 	} else {
2047 		clear_bit(EVENT_LINK_CARRIER_ON, &dev->flags);
2048 		netif_carrier_off(dev->net);
2049 	}
2050 
2051 	if (need_reset && link)
2052 		usbnet_defer_kevent(dev, EVENT_LINK_RESET);
2053 	else
2054 		usbnet_defer_kevent(dev, EVENT_LINK_CHANGE);
2055 }
2056 EXPORT_SYMBOL(usbnet_link_change);
2057 
2058 /*-------------------------------------------------------------------------*/
2059 static int __usbnet_read_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
2060 			     u16 value, u16 index, void *data, u16 size)
2061 {
2062 	void *buf = NULL;
2063 	int err = -ENOMEM;
2064 
2065 	netdev_dbg(dev->net, "usbnet_read_cmd cmd=0x%02x reqtype=%02x"
2066 		   " value=0x%04x index=0x%04x size=%d\n",
2067 		   cmd, reqtype, value, index, size);
2068 
2069 	if (size) {
2070 		buf = kmalloc(size, GFP_NOIO);
2071 		if (!buf)
2072 			goto out;
2073 	}
2074 
2075 	err = usb_control_msg(dev->udev, usb_rcvctrlpipe(dev->udev, 0),
2076 			      cmd, reqtype, value, index, buf, size,
2077 			      USB_CTRL_GET_TIMEOUT);
2078 	if (err > 0 && err <= size) {
2079 		if (data)
2080 			memcpy(data, buf, err);
2081 		else
2082 			netdev_dbg(dev->net,
2083 				   "Huh? Data requested but thrown away.\n");
2084 	}
2085 	kfree(buf);
2086 out:
2087 	return err;
2088 }
2089 
2090 static int __usbnet_write_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
2091 			      u16 value, u16 index, const void *data,
2092 			      u16 size)
2093 {
2094 	void *buf = NULL;
2095 	int err = -ENOMEM;
2096 
2097 	netdev_dbg(dev->net, "usbnet_write_cmd cmd=0x%02x reqtype=%02x"
2098 		   " value=0x%04x index=0x%04x size=%d\n",
2099 		   cmd, reqtype, value, index, size);
2100 
2101 	if (data) {
2102 		buf = kmemdup(data, size, GFP_NOIO);
2103 		if (!buf)
2104 			goto out;
2105 	} else {
2106         if (size) {
2107             WARN_ON_ONCE(1);
2108             err = -EINVAL;
2109             goto out;
2110         }
2111     }
2112 
2113 	err = usb_control_msg(dev->udev, usb_sndctrlpipe(dev->udev, 0),
2114 			      cmd, reqtype, value, index, buf, size,
2115 			      USB_CTRL_SET_TIMEOUT);
2116 	kfree(buf);
2117 
2118 out:
2119 	return err;
2120 }
2121 
2122 /*
2123  * The function can't be called inside suspend/resume callback,
2124  * otherwise deadlock will be caused.
2125  */
2126 int usbnet_read_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
2127 		    u16 value, u16 index, void *data, u16 size)
2128 {
2129 	int ret;
2130 
2131 	if (usb_autopm_get_interface(dev->intf) < 0)
2132 		return -ENODEV;
2133 	ret = __usbnet_read_cmd(dev, cmd, reqtype, value, index,
2134 				data, size);
2135 	usb_autopm_put_interface(dev->intf);
2136 	return ret;
2137 }
2138 EXPORT_SYMBOL_GPL(usbnet_read_cmd);
2139 
2140 /*
2141  * The function can't be called inside suspend/resume callback,
2142  * otherwise deadlock will be caused.
2143  */
2144 int usbnet_write_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
2145 		     u16 value, u16 index, const void *data, u16 size)
2146 {
2147 	int ret;
2148 
2149 	if (usb_autopm_get_interface(dev->intf) < 0)
2150 		return -ENODEV;
2151 	ret = __usbnet_write_cmd(dev, cmd, reqtype, value, index,
2152 				 data, size);
2153 	usb_autopm_put_interface(dev->intf);
2154 	return ret;
2155 }
2156 EXPORT_SYMBOL_GPL(usbnet_write_cmd);
2157 
2158 /*
2159  * The function can be called inside suspend/resume callback safely
2160  * and should only be called by suspend/resume callback generally.
2161  */
2162 int usbnet_read_cmd_nopm(struct usbnet *dev, u8 cmd, u8 reqtype,
2163 			  u16 value, u16 index, void *data, u16 size)
2164 {
2165 	return __usbnet_read_cmd(dev, cmd, reqtype, value, index,
2166 				 data, size);
2167 }
2168 EXPORT_SYMBOL_GPL(usbnet_read_cmd_nopm);
2169 
2170 /*
2171  * The function can be called inside suspend/resume callback safely
2172  * and should only be called by suspend/resume callback generally.
2173  */
2174 int usbnet_write_cmd_nopm(struct usbnet *dev, u8 cmd, u8 reqtype,
2175 			  u16 value, u16 index, const void *data,
2176 			  u16 size)
2177 {
2178 	return __usbnet_write_cmd(dev, cmd, reqtype, value, index,
2179 				  data, size);
2180 }
2181 EXPORT_SYMBOL_GPL(usbnet_write_cmd_nopm);
2182 
2183 static void usbnet_async_cmd_cb(struct urb *urb)
2184 {
2185 	struct usb_ctrlrequest *req = (struct usb_ctrlrequest *)urb->context;
2186 	int status = urb->status;
2187 
2188 	if (status < 0)
2189 		dev_dbg(&urb->dev->dev, "%s failed with %d",
2190 			__func__, status);
2191 
2192 	kfree(req);
2193 	usb_free_urb(urb);
2194 }
2195 
2196 /*
2197  * The caller must make sure that device can't be put into suspend
2198  * state until the control URB completes.
2199  */
2200 int usbnet_write_cmd_async(struct usbnet *dev, u8 cmd, u8 reqtype,
2201 			   u16 value, u16 index, const void *data, u16 size)
2202 {
2203 	struct usb_ctrlrequest *req;
2204 	struct urb *urb;
2205 	int err = -ENOMEM;
2206 	void *buf = NULL;
2207 
2208 	netdev_dbg(dev->net, "usbnet_write_cmd cmd=0x%02x reqtype=%02x"
2209 		   " value=0x%04x index=0x%04x size=%d\n",
2210 		   cmd, reqtype, value, index, size);
2211 
2212 	urb = usb_alloc_urb(0, GFP_ATOMIC);
2213 	if (!urb)
2214 		goto fail;
2215 
2216 	if (data) {
2217 		buf = kmemdup(data, size, GFP_ATOMIC);
2218 		if (!buf) {
2219 			netdev_err(dev->net, "Error allocating buffer"
2220 				   " in %s!\n", __func__);
2221 			goto fail_free_urb;
2222 		}
2223 	}
2224 
2225 	req = kmalloc(sizeof(struct usb_ctrlrequest), GFP_ATOMIC);
2226 	if (!req)
2227 		goto fail_free_buf;
2228 
2229 	req->bRequestType = reqtype;
2230 	req->bRequest = cmd;
2231 	req->wValue = cpu_to_le16(value);
2232 	req->wIndex = cpu_to_le16(index);
2233 	req->wLength = cpu_to_le16(size);
2234 
2235 	usb_fill_control_urb(urb, dev->udev,
2236 			     usb_sndctrlpipe(dev->udev, 0),
2237 			     (void *)req, buf, size,
2238 			     usbnet_async_cmd_cb, req);
2239 	urb->transfer_flags |= URB_FREE_BUFFER;
2240 
2241 	err = usb_submit_urb(urb, GFP_ATOMIC);
2242 	if (err < 0) {
2243 		netdev_err(dev->net, "Error submitting the control"
2244 			   " message: status=%d\n", err);
2245 		goto fail_free_all;
2246 	}
2247 	return 0;
2248 
2249 fail_free_all:
2250 	kfree(req);
2251 fail_free_buf:
2252 	kfree(buf);
2253 	/*
2254 	 * avoid a double free
2255 	 * needed because the flag can be set only
2256 	 * after filling the URB
2257 	 */
2258 	urb->transfer_flags = 0;
2259 fail_free_urb:
2260 	usb_free_urb(urb);
2261 fail:
2262 	return err;
2263 
2264 }
2265 EXPORT_SYMBOL_GPL(usbnet_write_cmd_async);
2266 /*-------------------------------------------------------------------------*/
2267 
2268 static int __init usbnet_init(void)
2269 {
2270 	/* Compiler should optimize this out. */
2271 	BUILD_BUG_ON(
2272 		sizeof_field(struct sk_buff, cb) < sizeof(struct skb_data));
2273 
2274 	return 0;
2275 }
2276 module_init(usbnet_init);
2277 
2278 static void __exit usbnet_exit(void)
2279 {
2280 }
2281 module_exit(usbnet_exit);
2282 
2283 MODULE_AUTHOR("David Brownell");
2284 MODULE_DESCRIPTION("USB network driver framework");
2285 MODULE_LICENSE("GPL");
2286