1 /* 2 * Copyright (c) 2014 Qualcomm Atheros, Inc. 3 * 4 * Permission to use, copy, modify, and/or distribute this software for any 5 * purpose with or without fee is hereby granted, provided that the above 6 * copyright notice and this permission notice appear in all copies. 7 * 8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 15 */ 16 17 #include "testmode.h" 18 19 #include <net/netlink.h> 20 #include <linux/firmware.h> 21 22 #include "debug.h" 23 #include "wmi.h" 24 #include "hif.h" 25 #include "hw.h" 26 #include "core.h" 27 28 #include "testmode_i.h" 29 30 static const struct nla_policy ath10k_tm_policy[ATH10K_TM_ATTR_MAX + 1] = { 31 [ATH10K_TM_ATTR_CMD] = { .type = NLA_U32 }, 32 [ATH10K_TM_ATTR_DATA] = { .type = NLA_BINARY, 33 .len = ATH10K_TM_DATA_MAX_LEN }, 34 [ATH10K_TM_ATTR_WMI_CMDID] = { .type = NLA_U32 }, 35 [ATH10K_TM_ATTR_VERSION_MAJOR] = { .type = NLA_U32 }, 36 [ATH10K_TM_ATTR_VERSION_MINOR] = { .type = NLA_U32 }, 37 }; 38 39 /* Returns true if callee consumes the skb and the skb should be discarded. 40 * Returns false if skb is not used. Does not sleep. 41 */ 42 bool ath10k_tm_event_wmi(struct ath10k *ar, u32 cmd_id, struct sk_buff *skb) 43 { 44 struct sk_buff *nl_skb; 45 bool consumed; 46 int ret; 47 48 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 49 "testmode event wmi cmd_id %d skb %pK skb->len %d\n", 50 cmd_id, skb, skb->len); 51 52 ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", skb->data, skb->len); 53 54 spin_lock_bh(&ar->data_lock); 55 56 if (!ar->testmode.utf_monitor) { 57 consumed = false; 58 goto out; 59 } 60 61 /* Only testmode.c should be handling events from utf firmware, 62 * otherwise all sort of problems will arise as mac80211 operations 63 * are not initialised. 64 */ 65 consumed = true; 66 67 nl_skb = cfg80211_testmode_alloc_event_skb(ar->hw->wiphy, 68 2 * sizeof(u32) + skb->len, 69 GFP_ATOMIC); 70 if (!nl_skb) { 71 ath10k_warn(ar, 72 "failed to allocate skb for testmode wmi event\n"); 73 goto out; 74 } 75 76 ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_CMD, ATH10K_TM_CMD_WMI); 77 if (ret) { 78 ath10k_warn(ar, 79 "failed to to put testmode wmi event cmd attribute: %d\n", 80 ret); 81 kfree_skb(nl_skb); 82 goto out; 83 } 84 85 ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_WMI_CMDID, cmd_id); 86 if (ret) { 87 ath10k_warn(ar, 88 "failed to to put testmode wmi even cmd_id: %d\n", 89 ret); 90 kfree_skb(nl_skb); 91 goto out; 92 } 93 94 ret = nla_put(nl_skb, ATH10K_TM_ATTR_DATA, skb->len, skb->data); 95 if (ret) { 96 ath10k_warn(ar, 97 "failed to copy skb to testmode wmi event: %d\n", 98 ret); 99 kfree_skb(nl_skb); 100 goto out; 101 } 102 103 cfg80211_testmode_event(nl_skb, GFP_ATOMIC); 104 105 out: 106 spin_unlock_bh(&ar->data_lock); 107 108 return consumed; 109 } 110 111 static int ath10k_tm_cmd_get_version(struct ath10k *ar, struct nlattr *tb[]) 112 { 113 struct sk_buff *skb; 114 int ret; 115 116 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 117 "testmode cmd get version_major %d version_minor %d\n", 118 ATH10K_TESTMODE_VERSION_MAJOR, 119 ATH10K_TESTMODE_VERSION_MINOR); 120 121 skb = cfg80211_testmode_alloc_reply_skb(ar->hw->wiphy, 122 nla_total_size(sizeof(u32))); 123 if (!skb) 124 return -ENOMEM; 125 126 ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MAJOR, 127 ATH10K_TESTMODE_VERSION_MAJOR); 128 if (ret) { 129 kfree_skb(skb); 130 return ret; 131 } 132 133 ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MINOR, 134 ATH10K_TESTMODE_VERSION_MINOR); 135 if (ret) { 136 kfree_skb(skb); 137 return ret; 138 } 139 140 return cfg80211_testmode_reply(skb); 141 } 142 143 static int ath10k_tm_fetch_utf_firmware_api_1(struct ath10k *ar, 144 struct ath10k_fw_file *fw_file) 145 { 146 char filename[100]; 147 int ret; 148 149 snprintf(filename, sizeof(filename), "%s/%s", 150 ar->hw_params.fw.dir, ATH10K_FW_UTF_FILE); 151 152 /* load utf firmware image */ 153 ret = request_firmware_direct(&fw_file->firmware, filename, ar->dev); 154 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode fw request '%s': %d\n", 155 filename, ret); 156 157 if (ret) { 158 ath10k_warn(ar, "failed to retrieve utf firmware '%s': %d\n", 159 filename, ret); 160 return ret; 161 } 162 163 /* We didn't find FW UTF API 1 ("utf.bin") does not advertise 164 * firmware features. Do an ugly hack where we force the firmware 165 * features to match with 10.1 branch so that wmi.c will use the 166 * correct WMI interface. 167 */ 168 169 fw_file->wmi_op_version = ATH10K_FW_WMI_OP_VERSION_10_1; 170 fw_file->htt_op_version = ATH10K_FW_HTT_OP_VERSION_10_1; 171 fw_file->firmware_data = fw_file->firmware->data; 172 fw_file->firmware_len = fw_file->firmware->size; 173 174 return 0; 175 } 176 177 static int ath10k_tm_fetch_firmware(struct ath10k *ar) 178 { 179 struct ath10k_fw_components *utf_mode_fw; 180 int ret; 181 182 ret = ath10k_core_fetch_firmware_api_n(ar, ATH10K_FW_UTF_API2_FILE, 183 &ar->testmode.utf_mode_fw.fw_file); 184 if (ret == 0) { 185 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using fw utf api 2"); 186 goto out; 187 } 188 189 ret = ath10k_tm_fetch_utf_firmware_api_1(ar, &ar->testmode.utf_mode_fw.fw_file); 190 if (ret) { 191 ath10k_err(ar, "failed to fetch utf firmware binary: %d", ret); 192 return ret; 193 } 194 195 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using utf api 1"); 196 197 out: 198 utf_mode_fw = &ar->testmode.utf_mode_fw; 199 200 /* Use the same board data file as the normal firmware uses (but 201 * it's still "owned" by normal_mode_fw so we shouldn't free it. 202 */ 203 utf_mode_fw->board_data = ar->normal_mode_fw.board_data; 204 utf_mode_fw->board_len = ar->normal_mode_fw.board_len; 205 206 if (!utf_mode_fw->fw_file.otp_data) { 207 ath10k_info(ar, "utf.bin didn't contain otp binary, taking it from the normal mode firmware"); 208 utf_mode_fw->fw_file.otp_data = ar->normal_mode_fw.fw_file.otp_data; 209 utf_mode_fw->fw_file.otp_len = ar->normal_mode_fw.fw_file.otp_len; 210 } 211 212 return 0; 213 } 214 215 static int ath10k_tm_cmd_utf_start(struct ath10k *ar, struct nlattr *tb[]) 216 { 217 const char *ver; 218 int ret; 219 220 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf start\n"); 221 222 mutex_lock(&ar->conf_mutex); 223 224 if (ar->state == ATH10K_STATE_UTF) { 225 ret = -EALREADY; 226 goto err; 227 } 228 229 /* start utf only when the driver is not in use */ 230 if (ar->state != ATH10K_STATE_OFF) { 231 ret = -EBUSY; 232 goto err; 233 } 234 235 if (WARN_ON(ar->testmode.utf_mode_fw.fw_file.firmware != NULL)) { 236 /* utf image is already downloaded, it shouldn't be */ 237 ret = -EEXIST; 238 goto err; 239 } 240 241 ret = ath10k_tm_fetch_firmware(ar); 242 if (ret) { 243 ath10k_err(ar, "failed to fetch UTF firmware: %d", ret); 244 goto err; 245 } 246 247 if (ar->testmode.utf_mode_fw.fw_file.codeswap_data && 248 ar->testmode.utf_mode_fw.fw_file.codeswap_len) { 249 ret = ath10k_swap_code_seg_init(ar, 250 &ar->testmode.utf_mode_fw.fw_file); 251 if (ret) { 252 ath10k_warn(ar, 253 "failed to init utf code swap segment: %d\n", 254 ret); 255 goto err_release_utf_mode_fw; 256 } 257 } 258 259 spin_lock_bh(&ar->data_lock); 260 ar->testmode.utf_monitor = true; 261 spin_unlock_bh(&ar->data_lock); 262 263 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode wmi version %d\n", 264 ar->testmode.utf_mode_fw.fw_file.wmi_op_version); 265 266 ret = ath10k_hif_power_up(ar); 267 if (ret) { 268 ath10k_err(ar, "failed to power up hif (testmode): %d\n", ret); 269 ar->state = ATH10K_STATE_OFF; 270 goto err_release_utf_mode_fw; 271 } 272 273 ret = ath10k_core_start(ar, ATH10K_FIRMWARE_MODE_UTF, 274 &ar->testmode.utf_mode_fw); 275 if (ret) { 276 ath10k_err(ar, "failed to start core (testmode): %d\n", ret); 277 ar->state = ATH10K_STATE_OFF; 278 goto err_power_down; 279 } 280 281 ar->state = ATH10K_STATE_UTF; 282 283 if (strlen(ar->testmode.utf_mode_fw.fw_file.fw_version) > 0) 284 ver = ar->testmode.utf_mode_fw.fw_file.fw_version; 285 else 286 ver = "API 1"; 287 288 ath10k_info(ar, "UTF firmware %s started\n", ver); 289 290 mutex_unlock(&ar->conf_mutex); 291 292 return 0; 293 294 err_power_down: 295 ath10k_hif_power_down(ar); 296 297 err_release_utf_mode_fw: 298 if (ar->testmode.utf_mode_fw.fw_file.codeswap_data && 299 ar->testmode.utf_mode_fw.fw_file.codeswap_len) 300 ath10k_swap_code_seg_release(ar, 301 &ar->testmode.utf_mode_fw.fw_file); 302 303 release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware); 304 ar->testmode.utf_mode_fw.fw_file.firmware = NULL; 305 306 err: 307 mutex_unlock(&ar->conf_mutex); 308 309 return ret; 310 } 311 312 static void __ath10k_tm_cmd_utf_stop(struct ath10k *ar) 313 { 314 lockdep_assert_held(&ar->conf_mutex); 315 316 ath10k_core_stop(ar); 317 ath10k_hif_power_down(ar); 318 319 spin_lock_bh(&ar->data_lock); 320 321 ar->testmode.utf_monitor = false; 322 323 spin_unlock_bh(&ar->data_lock); 324 325 if (ar->testmode.utf_mode_fw.fw_file.codeswap_data && 326 ar->testmode.utf_mode_fw.fw_file.codeswap_len) 327 ath10k_swap_code_seg_release(ar, 328 &ar->testmode.utf_mode_fw.fw_file); 329 330 release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware); 331 ar->testmode.utf_mode_fw.fw_file.firmware = NULL; 332 333 ar->state = ATH10K_STATE_OFF; 334 } 335 336 static int ath10k_tm_cmd_utf_stop(struct ath10k *ar, struct nlattr *tb[]) 337 { 338 int ret; 339 340 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf stop\n"); 341 342 mutex_lock(&ar->conf_mutex); 343 344 if (ar->state != ATH10K_STATE_UTF) { 345 ret = -ENETDOWN; 346 goto out; 347 } 348 349 __ath10k_tm_cmd_utf_stop(ar); 350 351 ret = 0; 352 353 ath10k_info(ar, "UTF firmware stopped\n"); 354 355 out: 356 mutex_unlock(&ar->conf_mutex); 357 return ret; 358 } 359 360 static int ath10k_tm_cmd_wmi(struct ath10k *ar, struct nlattr *tb[]) 361 { 362 struct sk_buff *skb; 363 int ret, buf_len; 364 u32 cmd_id; 365 void *buf; 366 367 mutex_lock(&ar->conf_mutex); 368 369 if (ar->state != ATH10K_STATE_UTF) { 370 ret = -ENETDOWN; 371 goto out; 372 } 373 374 if (!tb[ATH10K_TM_ATTR_DATA]) { 375 ret = -EINVAL; 376 goto out; 377 } 378 379 if (!tb[ATH10K_TM_ATTR_WMI_CMDID]) { 380 ret = -EINVAL; 381 goto out; 382 } 383 384 buf = nla_data(tb[ATH10K_TM_ATTR_DATA]); 385 buf_len = nla_len(tb[ATH10K_TM_ATTR_DATA]); 386 cmd_id = nla_get_u32(tb[ATH10K_TM_ATTR_WMI_CMDID]); 387 388 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 389 "testmode cmd wmi cmd_id %d buf %pK buf_len %d\n", 390 cmd_id, buf, buf_len); 391 392 ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", buf, buf_len); 393 394 skb = ath10k_wmi_alloc_skb(ar, buf_len); 395 if (!skb) { 396 ret = -ENOMEM; 397 goto out; 398 } 399 400 memcpy(skb->data, buf, buf_len); 401 402 ret = ath10k_wmi_cmd_send(ar, skb, cmd_id); 403 if (ret) { 404 ath10k_warn(ar, "failed to transmit wmi command (testmode): %d\n", 405 ret); 406 goto out; 407 } 408 409 ret = 0; 410 411 out: 412 mutex_unlock(&ar->conf_mutex); 413 return ret; 414 } 415 416 int ath10k_tm_cmd(struct ieee80211_hw *hw, struct ieee80211_vif *vif, 417 void *data, int len) 418 { 419 struct ath10k *ar = hw->priv; 420 struct nlattr *tb[ATH10K_TM_ATTR_MAX + 1]; 421 int ret; 422 423 ret = nla_parse(tb, ATH10K_TM_ATTR_MAX, data, len, ath10k_tm_policy, 424 NULL); 425 if (ret) 426 return ret; 427 428 if (!tb[ATH10K_TM_ATTR_CMD]) 429 return -EINVAL; 430 431 switch (nla_get_u32(tb[ATH10K_TM_ATTR_CMD])) { 432 case ATH10K_TM_CMD_GET_VERSION: 433 return ath10k_tm_cmd_get_version(ar, tb); 434 case ATH10K_TM_CMD_UTF_START: 435 return ath10k_tm_cmd_utf_start(ar, tb); 436 case ATH10K_TM_CMD_UTF_STOP: 437 return ath10k_tm_cmd_utf_stop(ar, tb); 438 case ATH10K_TM_CMD_WMI: 439 return ath10k_tm_cmd_wmi(ar, tb); 440 default: 441 return -EOPNOTSUPP; 442 } 443 } 444 445 void ath10k_testmode_destroy(struct ath10k *ar) 446 { 447 mutex_lock(&ar->conf_mutex); 448 449 if (ar->state != ATH10K_STATE_UTF) { 450 /* utf firmware is not running, nothing to do */ 451 goto out; 452 } 453 454 __ath10k_tm_cmd_utf_stop(ar); 455 456 out: 457 mutex_unlock(&ar->conf_mutex); 458 } 459