1 /* 2 * Copyright (c) 2014 Qualcomm Atheros, Inc. 3 * 4 * Permission to use, copy, modify, and/or distribute this software for any 5 * purpose with or without fee is hereby granted, provided that the above 6 * copyright notice and this permission notice appear in all copies. 7 * 8 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES 9 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF 10 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR 11 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES 12 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN 13 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 14 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 15 */ 16 17 #include "testmode.h" 18 19 #include <net/netlink.h> 20 #include <linux/firmware.h> 21 22 #include "debug.h" 23 #include "wmi.h" 24 #include "hif.h" 25 #include "hw.h" 26 27 #include "testmode_i.h" 28 29 static const struct nla_policy ath10k_tm_policy[ATH10K_TM_ATTR_MAX + 1] = { 30 [ATH10K_TM_ATTR_CMD] = { .type = NLA_U32 }, 31 [ATH10K_TM_ATTR_DATA] = { .type = NLA_BINARY, 32 .len = ATH10K_TM_DATA_MAX_LEN }, 33 [ATH10K_TM_ATTR_WMI_CMDID] = { .type = NLA_U32 }, 34 [ATH10K_TM_ATTR_VERSION_MAJOR] = { .type = NLA_U32 }, 35 [ATH10K_TM_ATTR_VERSION_MINOR] = { .type = NLA_U32 }, 36 }; 37 38 /* Returns true if callee consumes the skb and the skb should be discarded. 39 * Returns false if skb is not used. Does not sleep. 40 */ 41 bool ath10k_tm_event_wmi(struct ath10k *ar, u32 cmd_id, struct sk_buff *skb) 42 { 43 struct sk_buff *nl_skb; 44 bool consumed; 45 int ret; 46 47 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 48 "testmode event wmi cmd_id %d skb %p skb->len %d\n", 49 cmd_id, skb, skb->len); 50 51 ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", skb->data, skb->len); 52 53 spin_lock_bh(&ar->data_lock); 54 55 if (!ar->testmode.utf_monitor) { 56 consumed = false; 57 goto out; 58 } 59 60 /* Only testmode.c should be handling events from utf firmware, 61 * otherwise all sort of problems will arise as mac80211 operations 62 * are not initialised. 63 */ 64 consumed = true; 65 66 nl_skb = cfg80211_testmode_alloc_event_skb(ar->hw->wiphy, 67 2 * sizeof(u32) + skb->len, 68 GFP_ATOMIC); 69 if (!nl_skb) { 70 ath10k_warn(ar, 71 "failed to allocate skb for testmode wmi event\n"); 72 goto out; 73 } 74 75 ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_CMD, ATH10K_TM_CMD_WMI); 76 if (ret) { 77 ath10k_warn(ar, 78 "failed to to put testmode wmi event cmd attribute: %d\n", 79 ret); 80 kfree_skb(nl_skb); 81 goto out; 82 } 83 84 ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_WMI_CMDID, cmd_id); 85 if (ret) { 86 ath10k_warn(ar, 87 "failed to to put testmode wmi even cmd_id: %d\n", 88 ret); 89 kfree_skb(nl_skb); 90 goto out; 91 } 92 93 ret = nla_put(nl_skb, ATH10K_TM_ATTR_DATA, skb->len, skb->data); 94 if (ret) { 95 ath10k_warn(ar, 96 "failed to copy skb to testmode wmi event: %d\n", 97 ret); 98 kfree_skb(nl_skb); 99 goto out; 100 } 101 102 cfg80211_testmode_event(nl_skb, GFP_ATOMIC); 103 104 out: 105 spin_unlock_bh(&ar->data_lock); 106 107 return consumed; 108 } 109 110 static int ath10k_tm_cmd_get_version(struct ath10k *ar, struct nlattr *tb[]) 111 { 112 struct sk_buff *skb; 113 int ret; 114 115 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 116 "testmode cmd get version_major %d version_minor %d\n", 117 ATH10K_TESTMODE_VERSION_MAJOR, 118 ATH10K_TESTMODE_VERSION_MINOR); 119 120 skb = cfg80211_testmode_alloc_reply_skb(ar->hw->wiphy, 121 nla_total_size(sizeof(u32))); 122 if (!skb) 123 return -ENOMEM; 124 125 ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MAJOR, 126 ATH10K_TESTMODE_VERSION_MAJOR); 127 if (ret) { 128 kfree_skb(skb); 129 return ret; 130 } 131 132 ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MINOR, 133 ATH10K_TESTMODE_VERSION_MINOR); 134 if (ret) { 135 kfree_skb(skb); 136 return ret; 137 } 138 139 return cfg80211_testmode_reply(skb); 140 } 141 142 static int ath10k_tm_fetch_utf_firmware_api_2(struct ath10k *ar, 143 struct ath10k_fw_file *fw_file) 144 { 145 size_t len, magic_len, ie_len; 146 struct ath10k_fw_ie *hdr; 147 char filename[100]; 148 __le32 *version; 149 const u8 *data; 150 int ie_id, ret; 151 152 snprintf(filename, sizeof(filename), "%s/%s", 153 ar->hw_params.fw.dir, ATH10K_FW_UTF_API2_FILE); 154 155 /* load utf firmware image */ 156 ret = request_firmware(&fw_file->firmware, filename, ar->dev); 157 if (ret) { 158 ath10k_warn(ar, "failed to retrieve utf firmware '%s': %d\n", 159 filename, ret); 160 return ret; 161 } 162 163 data = fw_file->firmware->data; 164 len = fw_file->firmware->size; 165 166 /* FIXME: call release_firmware() in error cases */ 167 168 /* magic also includes the null byte, check that as well */ 169 magic_len = strlen(ATH10K_FIRMWARE_MAGIC) + 1; 170 171 if (len < magic_len) { 172 ath10k_err(ar, "utf firmware file is too small to contain magic\n"); 173 ret = -EINVAL; 174 goto err; 175 } 176 177 if (memcmp(data, ATH10K_FIRMWARE_MAGIC, magic_len) != 0) { 178 ath10k_err(ar, "invalid firmware magic\n"); 179 ret = -EINVAL; 180 goto err; 181 } 182 183 /* jump over the padding */ 184 magic_len = ALIGN(magic_len, 4); 185 186 len -= magic_len; 187 data += magic_len; 188 189 /* loop elements */ 190 while (len > sizeof(struct ath10k_fw_ie)) { 191 hdr = (struct ath10k_fw_ie *)data; 192 193 ie_id = le32_to_cpu(hdr->id); 194 ie_len = le32_to_cpu(hdr->len); 195 196 len -= sizeof(*hdr); 197 data += sizeof(*hdr); 198 199 if (len < ie_len) { 200 ath10k_err(ar, "invalid length for FW IE %d (%zu < %zu)\n", 201 ie_id, len, ie_len); 202 ret = -EINVAL; 203 goto err; 204 } 205 206 switch (ie_id) { 207 case ATH10K_FW_IE_FW_VERSION: 208 if (ie_len > sizeof(fw_file->fw_version) - 1) 209 break; 210 211 memcpy(fw_file->fw_version, data, ie_len); 212 fw_file->fw_version[ie_len] = '\0'; 213 214 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 215 "testmode found fw utf version %s\n", 216 fw_file->fw_version); 217 break; 218 case ATH10K_FW_IE_TIMESTAMP: 219 /* ignore timestamp, but don't warn about it either */ 220 break; 221 case ATH10K_FW_IE_FW_IMAGE: 222 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 223 "testmode found fw image ie (%zd B)\n", 224 ie_len); 225 226 fw_file->firmware_data = data; 227 fw_file->firmware_len = ie_len; 228 break; 229 case ATH10K_FW_IE_WMI_OP_VERSION: 230 if (ie_len != sizeof(u32)) 231 break; 232 version = (__le32 *)data; 233 ar->testmode.op_version = le32_to_cpup(version); 234 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode found fw ie wmi op version %d\n", 235 ar->testmode.op_version); 236 break; 237 default: 238 ath10k_warn(ar, "Unknown testmode FW IE: %u\n", 239 le32_to_cpu(hdr->id)); 240 break; 241 } 242 /* jump over the padding */ 243 ie_len = ALIGN(ie_len, 4); 244 245 len -= ie_len; 246 data += ie_len; 247 } 248 249 if (!fw_file->firmware_data || !fw_file->firmware_len) { 250 ath10k_err(ar, "No ATH10K_FW_IE_FW_IMAGE found\n"); 251 ret = -EINVAL; 252 goto err; 253 } 254 255 return 0; 256 257 err: 258 release_firmware(fw_file->firmware); 259 260 return ret; 261 } 262 263 static int ath10k_tm_fetch_utf_firmware_api_1(struct ath10k *ar, 264 struct ath10k_fw_file *fw_file) 265 { 266 char filename[100]; 267 int ret; 268 269 snprintf(filename, sizeof(filename), "%s/%s", 270 ar->hw_params.fw.dir, ATH10K_FW_UTF_FILE); 271 272 /* load utf firmware image */ 273 ret = request_firmware(&fw_file->firmware, filename, ar->dev); 274 if (ret) { 275 ath10k_warn(ar, "failed to retrieve utf firmware '%s': %d\n", 276 filename, ret); 277 return ret; 278 } 279 280 /* We didn't find FW UTF API 1 ("utf.bin") does not advertise 281 * firmware features. Do an ugly hack where we force the firmware 282 * features to match with 10.1 branch so that wmi.c will use the 283 * correct WMI interface. 284 */ 285 286 ar->testmode.op_version = ATH10K_FW_WMI_OP_VERSION_10_1; 287 fw_file->firmware_data = fw_file->firmware->data; 288 fw_file->firmware_len = fw_file->firmware->size; 289 290 return 0; 291 } 292 293 static int ath10k_tm_fetch_firmware(struct ath10k *ar) 294 { 295 struct ath10k_fw_components *utf_mode_fw; 296 int ret; 297 298 ret = ath10k_tm_fetch_utf_firmware_api_2(ar, &ar->testmode.utf_mode_fw.fw_file); 299 if (ret == 0) { 300 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using fw utf api 2"); 301 goto out; 302 } 303 304 ret = ath10k_tm_fetch_utf_firmware_api_1(ar, &ar->testmode.utf_mode_fw.fw_file); 305 if (ret) { 306 ath10k_err(ar, "failed to fetch utf firmware binary: %d", ret); 307 return ret; 308 } 309 310 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using utf api 1"); 311 312 out: 313 utf_mode_fw = &ar->testmode.utf_mode_fw; 314 315 /* Use the same board data file as the normal firmware uses (but 316 * it's still "owned" by normal_mode_fw so we shouldn't free it. 317 */ 318 utf_mode_fw->board_data = ar->normal_mode_fw.board_data; 319 utf_mode_fw->board_len = ar->normal_mode_fw.board_len; 320 321 if (!utf_mode_fw->fw_file.otp_data) { 322 ath10k_info(ar, "utf.bin didn't contain otp binary, taking it from the normal mode firmware"); 323 utf_mode_fw->fw_file.otp_data = ar->normal_mode_fw.fw_file.otp_data; 324 utf_mode_fw->fw_file.otp_len = ar->normal_mode_fw.fw_file.otp_len; 325 } 326 327 return 0; 328 } 329 330 static int ath10k_tm_cmd_utf_start(struct ath10k *ar, struct nlattr *tb[]) 331 { 332 const char *ver; 333 int ret; 334 335 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf start\n"); 336 337 mutex_lock(&ar->conf_mutex); 338 339 if (ar->state == ATH10K_STATE_UTF) { 340 ret = -EALREADY; 341 goto err; 342 } 343 344 /* start utf only when the driver is not in use */ 345 if (ar->state != ATH10K_STATE_OFF) { 346 ret = -EBUSY; 347 goto err; 348 } 349 350 if (WARN_ON(ar->testmode.utf_mode_fw.fw_file.firmware != NULL)) { 351 /* utf image is already downloaded, it shouldn't be */ 352 ret = -EEXIST; 353 goto err; 354 } 355 356 ret = ath10k_tm_fetch_firmware(ar); 357 if (ret) { 358 ath10k_err(ar, "failed to fetch UTF firmware: %d", ret); 359 goto err; 360 } 361 362 spin_lock_bh(&ar->data_lock); 363 ar->testmode.utf_monitor = true; 364 spin_unlock_bh(&ar->data_lock); 365 BUILD_BUG_ON(sizeof(ar->fw_features) != 366 sizeof(ar->testmode.orig_fw_features)); 367 368 memcpy(ar->testmode.orig_fw_features, ar->fw_features, 369 sizeof(ar->fw_features)); 370 ar->testmode.orig_wmi_op_version = ar->wmi.op_version; 371 memset(ar->fw_features, 0, sizeof(ar->fw_features)); 372 373 ar->wmi.op_version = ar->testmode.op_version; 374 375 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode wmi version %d\n", 376 ar->wmi.op_version); 377 378 ret = ath10k_hif_power_up(ar); 379 if (ret) { 380 ath10k_err(ar, "failed to power up hif (testmode): %d\n", ret); 381 ar->state = ATH10K_STATE_OFF; 382 goto err_fw_features; 383 } 384 385 ret = ath10k_core_start(ar, ATH10K_FIRMWARE_MODE_UTF, 386 &ar->testmode.utf_mode_fw); 387 if (ret) { 388 ath10k_err(ar, "failed to start core (testmode): %d\n", ret); 389 ar->state = ATH10K_STATE_OFF; 390 goto err_power_down; 391 } 392 393 ar->state = ATH10K_STATE_UTF; 394 395 if (strlen(ar->testmode.utf_mode_fw.fw_file.fw_version) > 0) 396 ver = ar->testmode.utf_mode_fw.fw_file.fw_version; 397 else 398 ver = "API 1"; 399 400 ath10k_info(ar, "UTF firmware %s started\n", ver); 401 402 mutex_unlock(&ar->conf_mutex); 403 404 return 0; 405 406 err_power_down: 407 ath10k_hif_power_down(ar); 408 409 err_fw_features: 410 /* return the original firmware features */ 411 memcpy(ar->fw_features, ar->testmode.orig_fw_features, 412 sizeof(ar->fw_features)); 413 ar->wmi.op_version = ar->testmode.orig_wmi_op_version; 414 415 release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware); 416 ar->testmode.utf_mode_fw.fw_file.firmware = NULL; 417 418 err: 419 mutex_unlock(&ar->conf_mutex); 420 421 return ret; 422 } 423 424 static void __ath10k_tm_cmd_utf_stop(struct ath10k *ar) 425 { 426 lockdep_assert_held(&ar->conf_mutex); 427 428 ath10k_core_stop(ar); 429 ath10k_hif_power_down(ar); 430 431 spin_lock_bh(&ar->data_lock); 432 433 ar->testmode.utf_monitor = false; 434 435 spin_unlock_bh(&ar->data_lock); 436 437 /* return the original firmware features */ 438 memcpy(ar->fw_features, ar->testmode.orig_fw_features, 439 sizeof(ar->fw_features)); 440 ar->wmi.op_version = ar->testmode.orig_wmi_op_version; 441 442 release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware); 443 ar->testmode.utf_mode_fw.fw_file.firmware = NULL; 444 445 ar->state = ATH10K_STATE_OFF; 446 } 447 448 static int ath10k_tm_cmd_utf_stop(struct ath10k *ar, struct nlattr *tb[]) 449 { 450 int ret; 451 452 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf stop\n"); 453 454 mutex_lock(&ar->conf_mutex); 455 456 if (ar->state != ATH10K_STATE_UTF) { 457 ret = -ENETDOWN; 458 goto out; 459 } 460 461 __ath10k_tm_cmd_utf_stop(ar); 462 463 ret = 0; 464 465 ath10k_info(ar, "UTF firmware stopped\n"); 466 467 out: 468 mutex_unlock(&ar->conf_mutex); 469 return ret; 470 } 471 472 static int ath10k_tm_cmd_wmi(struct ath10k *ar, struct nlattr *tb[]) 473 { 474 struct sk_buff *skb; 475 int ret, buf_len; 476 u32 cmd_id; 477 void *buf; 478 479 mutex_lock(&ar->conf_mutex); 480 481 if (ar->state != ATH10K_STATE_UTF) { 482 ret = -ENETDOWN; 483 goto out; 484 } 485 486 if (!tb[ATH10K_TM_ATTR_DATA]) { 487 ret = -EINVAL; 488 goto out; 489 } 490 491 if (!tb[ATH10K_TM_ATTR_WMI_CMDID]) { 492 ret = -EINVAL; 493 goto out; 494 } 495 496 buf = nla_data(tb[ATH10K_TM_ATTR_DATA]); 497 buf_len = nla_len(tb[ATH10K_TM_ATTR_DATA]); 498 cmd_id = nla_get_u32(tb[ATH10K_TM_ATTR_WMI_CMDID]); 499 500 ath10k_dbg(ar, ATH10K_DBG_TESTMODE, 501 "testmode cmd wmi cmd_id %d buf %p buf_len %d\n", 502 cmd_id, buf, buf_len); 503 504 ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", buf, buf_len); 505 506 skb = ath10k_wmi_alloc_skb(ar, buf_len); 507 if (!skb) { 508 ret = -ENOMEM; 509 goto out; 510 } 511 512 memcpy(skb->data, buf, buf_len); 513 514 ret = ath10k_wmi_cmd_send(ar, skb, cmd_id); 515 if (ret) { 516 ath10k_warn(ar, "failed to transmit wmi command (testmode): %d\n", 517 ret); 518 goto out; 519 } 520 521 ret = 0; 522 523 out: 524 mutex_unlock(&ar->conf_mutex); 525 return ret; 526 } 527 528 int ath10k_tm_cmd(struct ieee80211_hw *hw, struct ieee80211_vif *vif, 529 void *data, int len) 530 { 531 struct ath10k *ar = hw->priv; 532 struct nlattr *tb[ATH10K_TM_ATTR_MAX + 1]; 533 int ret; 534 535 ret = nla_parse(tb, ATH10K_TM_ATTR_MAX, data, len, 536 ath10k_tm_policy); 537 if (ret) 538 return ret; 539 540 if (!tb[ATH10K_TM_ATTR_CMD]) 541 return -EINVAL; 542 543 switch (nla_get_u32(tb[ATH10K_TM_ATTR_CMD])) { 544 case ATH10K_TM_CMD_GET_VERSION: 545 return ath10k_tm_cmd_get_version(ar, tb); 546 case ATH10K_TM_CMD_UTF_START: 547 return ath10k_tm_cmd_utf_start(ar, tb); 548 case ATH10K_TM_CMD_UTF_STOP: 549 return ath10k_tm_cmd_utf_stop(ar, tb); 550 case ATH10K_TM_CMD_WMI: 551 return ath10k_tm_cmd_wmi(ar, tb); 552 default: 553 return -EOPNOTSUPP; 554 } 555 } 556 557 void ath10k_testmode_destroy(struct ath10k *ar) 558 { 559 mutex_lock(&ar->conf_mutex); 560 561 if (ar->state != ATH10K_STATE_UTF) { 562 /* utf firmware is not running, nothing to do */ 563 goto out; 564 } 565 566 __ath10k_tm_cmd_utf_stop(ar); 567 568 out: 569 mutex_unlock(&ar->conf_mutex); 570 } 571