xref: /openbmc/linux/drivers/net/usb/usbnet.c (revision afc98d90)
1 /*
2  * USB Network driver infrastructure
3  * Copyright (C) 2000-2005 by David Brownell
4  * Copyright (C) 2003-2005 David Hollis <dhollis@davehollis.com>
5  *
6  * This program is free software; you can redistribute it and/or modify
7  * it under the terms of the GNU General Public License as published by
8  * the Free Software Foundation; either version 2 of the License, or
9  * (at your option) any later version.
10  *
11  * This program is distributed in the hope that it will be useful,
12  * but WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
14  * GNU General Public License for more details.
15  *
16  * You should have received a copy of the GNU General Public License
17  * along with this program; if not, see <http://www.gnu.org/licenses/>.
18  */
19 
20 /*
21  * This is a generic "USB networking" framework that works with several
22  * kinds of full and high speed networking devices:  host-to-host cables,
23  * smart usb peripherals, and actual Ethernet adapters.
24  *
25  * These devices usually differ in terms of control protocols (if they
26  * even have one!) and sometimes they define new framing to wrap or batch
27  * Ethernet packets.  Otherwise, they talk to USB pretty much the same,
28  * so interface (un)binding, endpoint I/O queues, fault handling, and other
29  * issues can usefully be addressed by this framework.
30  */
31 
32 // #define	DEBUG			// error path messages, extra info
33 // #define	VERBOSE			// more; success messages
34 
35 #include <linux/module.h>
36 #include <linux/init.h>
37 #include <linux/netdevice.h>
38 #include <linux/etherdevice.h>
39 #include <linux/ctype.h>
40 #include <linux/ethtool.h>
41 #include <linux/workqueue.h>
42 #include <linux/mii.h>
43 #include <linux/usb.h>
44 #include <linux/usb/usbnet.h>
45 #include <linux/slab.h>
46 #include <linux/kernel.h>
47 #include <linux/pm_runtime.h>
48 
49 #define DRIVER_VERSION		"22-Aug-2005"
50 
51 
52 /*-------------------------------------------------------------------------*/
53 
54 /*
55  * Nineteen USB 1.1 max size bulk transactions per frame (ms), max.
56  * Several dozen bytes of IPv4 data can fit in two such transactions.
57  * One maximum size Ethernet packet takes twenty four of them.
58  * For high speed, each frame comfortably fits almost 36 max size
59  * Ethernet packets (so queues should be bigger).
60  *
61  * The goal is to let the USB host controller be busy for 5msec or
62  * more before an irq is required, under load.  Jumbograms change
63  * the equation.
64  */
65 #define	MAX_QUEUE_MEMORY	(60 * 1518)
66 #define	RX_QLEN(dev)		((dev)->rx_qlen)
67 #define	TX_QLEN(dev)		((dev)->tx_qlen)
68 
69 // reawaken network queue this soon after stopping; else watchdog barks
70 #define TX_TIMEOUT_JIFFIES	(5*HZ)
71 
72 // throttle rx/tx briefly after some faults, so khubd might disconnect()
73 // us (it polls at HZ/4 usually) before we report too many false errors.
74 #define THROTTLE_JIFFIES	(HZ/8)
75 
76 // between wakeups
77 #define UNLINK_TIMEOUT_MS	3
78 
79 /*-------------------------------------------------------------------------*/
80 
81 // randomly generated ethernet address
82 static u8	node_id [ETH_ALEN];
83 
84 static const char driver_name [] = "usbnet";
85 
86 /* use ethtool to change the level for any given device */
87 static int msg_level = -1;
88 module_param (msg_level, int, 0);
89 MODULE_PARM_DESC (msg_level, "Override default message level");
90 
91 /*-------------------------------------------------------------------------*/
92 
93 /* handles CDC Ethernet and many other network "bulk data" interfaces */
94 int usbnet_get_endpoints(struct usbnet *dev, struct usb_interface *intf)
95 {
96 	int				tmp;
97 	struct usb_host_interface	*alt = NULL;
98 	struct usb_host_endpoint	*in = NULL, *out = NULL;
99 	struct usb_host_endpoint	*status = NULL;
100 
101 	for (tmp = 0; tmp < intf->num_altsetting; tmp++) {
102 		unsigned	ep;
103 
104 		in = out = status = NULL;
105 		alt = intf->altsetting + tmp;
106 
107 		/* take the first altsetting with in-bulk + out-bulk;
108 		 * remember any status endpoint, just in case;
109 		 * ignore other endpoints and altsettings.
110 		 */
111 		for (ep = 0; ep < alt->desc.bNumEndpoints; ep++) {
112 			struct usb_host_endpoint	*e;
113 			int				intr = 0;
114 
115 			e = alt->endpoint + ep;
116 			switch (e->desc.bmAttributes) {
117 			case USB_ENDPOINT_XFER_INT:
118 				if (!usb_endpoint_dir_in(&e->desc))
119 					continue;
120 				intr = 1;
121 				/* FALLTHROUGH */
122 			case USB_ENDPOINT_XFER_BULK:
123 				break;
124 			default:
125 				continue;
126 			}
127 			if (usb_endpoint_dir_in(&e->desc)) {
128 				if (!intr && !in)
129 					in = e;
130 				else if (intr && !status)
131 					status = e;
132 			} else {
133 				if (!out)
134 					out = e;
135 			}
136 		}
137 		if (in && out)
138 			break;
139 	}
140 	if (!alt || !in || !out)
141 		return -EINVAL;
142 
143 	if (alt->desc.bAlternateSetting != 0 ||
144 	    !(dev->driver_info->flags & FLAG_NO_SETINT)) {
145 		tmp = usb_set_interface (dev->udev, alt->desc.bInterfaceNumber,
146 				alt->desc.bAlternateSetting);
147 		if (tmp < 0)
148 			return tmp;
149 	}
150 
151 	dev->in = usb_rcvbulkpipe (dev->udev,
152 			in->desc.bEndpointAddress & USB_ENDPOINT_NUMBER_MASK);
153 	dev->out = usb_sndbulkpipe (dev->udev,
154 			out->desc.bEndpointAddress & USB_ENDPOINT_NUMBER_MASK);
155 	dev->status = status;
156 	return 0;
157 }
158 EXPORT_SYMBOL_GPL(usbnet_get_endpoints);
159 
160 int usbnet_get_ethernet_addr(struct usbnet *dev, int iMACAddress)
161 {
162 	int 		tmp, i;
163 	unsigned char	buf [13];
164 
165 	tmp = usb_string(dev->udev, iMACAddress, buf, sizeof buf);
166 	if (tmp != 12) {
167 		dev_dbg(&dev->udev->dev,
168 			"bad MAC string %d fetch, %d\n", iMACAddress, tmp);
169 		if (tmp >= 0)
170 			tmp = -EINVAL;
171 		return tmp;
172 	}
173 	for (i = tmp = 0; i < 6; i++, tmp += 2)
174 		dev->net->dev_addr [i] =
175 			(hex_to_bin(buf[tmp]) << 4) + hex_to_bin(buf[tmp + 1]);
176 	return 0;
177 }
178 EXPORT_SYMBOL_GPL(usbnet_get_ethernet_addr);
179 
180 static void intr_complete (struct urb *urb)
181 {
182 	struct usbnet	*dev = urb->context;
183 	int		status = urb->status;
184 
185 	switch (status) {
186 	/* success */
187 	case 0:
188 		dev->driver_info->status(dev, urb);
189 		break;
190 
191 	/* software-driven interface shutdown */
192 	case -ENOENT:		/* urb killed */
193 	case -ESHUTDOWN:	/* hardware gone */
194 		netif_dbg(dev, ifdown, dev->net,
195 			  "intr shutdown, code %d\n", status);
196 		return;
197 
198 	/* NOTE:  not throttling like RX/TX, since this endpoint
199 	 * already polls infrequently
200 	 */
201 	default:
202 		netdev_dbg(dev->net, "intr status %d\n", status);
203 		break;
204 	}
205 
206 	status = usb_submit_urb (urb, GFP_ATOMIC);
207 	if (status != 0)
208 		netif_err(dev, timer, dev->net,
209 			  "intr resubmit --> %d\n", status);
210 }
211 
212 static int init_status (struct usbnet *dev, struct usb_interface *intf)
213 {
214 	char		*buf = NULL;
215 	unsigned	pipe = 0;
216 	unsigned	maxp;
217 	unsigned	period;
218 
219 	if (!dev->driver_info->status)
220 		return 0;
221 
222 	pipe = usb_rcvintpipe (dev->udev,
223 			dev->status->desc.bEndpointAddress
224 				& USB_ENDPOINT_NUMBER_MASK);
225 	maxp = usb_maxpacket (dev->udev, pipe, 0);
226 
227 	/* avoid 1 msec chatter:  min 8 msec poll rate */
228 	period = max ((int) dev->status->desc.bInterval,
229 		(dev->udev->speed == USB_SPEED_HIGH) ? 7 : 3);
230 
231 	buf = kmalloc (maxp, GFP_KERNEL);
232 	if (buf) {
233 		dev->interrupt = usb_alloc_urb (0, GFP_KERNEL);
234 		if (!dev->interrupt) {
235 			kfree (buf);
236 			return -ENOMEM;
237 		} else {
238 			usb_fill_int_urb(dev->interrupt, dev->udev, pipe,
239 				buf, maxp, intr_complete, dev, period);
240 			dev->interrupt->transfer_flags |= URB_FREE_BUFFER;
241 			dev_dbg(&intf->dev,
242 				"status ep%din, %d bytes period %d\n",
243 				usb_pipeendpoint(pipe), maxp, period);
244 		}
245 	}
246 	return 0;
247 }
248 
249 /* Submit the interrupt URB if not previously submitted, increasing refcount */
250 int usbnet_status_start(struct usbnet *dev, gfp_t mem_flags)
251 {
252 	int ret = 0;
253 
254 	WARN_ON_ONCE(dev->interrupt == NULL);
255 	if (dev->interrupt) {
256 		mutex_lock(&dev->interrupt_mutex);
257 
258 		if (++dev->interrupt_count == 1)
259 			ret = usb_submit_urb(dev->interrupt, mem_flags);
260 
261 		dev_dbg(&dev->udev->dev, "incremented interrupt URB count to %d\n",
262 			dev->interrupt_count);
263 		mutex_unlock(&dev->interrupt_mutex);
264 	}
265 	return ret;
266 }
267 EXPORT_SYMBOL_GPL(usbnet_status_start);
268 
269 /* For resume; submit interrupt URB if previously submitted */
270 static int __usbnet_status_start_force(struct usbnet *dev, gfp_t mem_flags)
271 {
272 	int ret = 0;
273 
274 	mutex_lock(&dev->interrupt_mutex);
275 	if (dev->interrupt_count) {
276 		ret = usb_submit_urb(dev->interrupt, mem_flags);
277 		dev_dbg(&dev->udev->dev,
278 			"submitted interrupt URB for resume\n");
279 	}
280 	mutex_unlock(&dev->interrupt_mutex);
281 	return ret;
282 }
283 
284 /* Kill the interrupt URB if all submitters want it killed */
285 void usbnet_status_stop(struct usbnet *dev)
286 {
287 	if (dev->interrupt) {
288 		mutex_lock(&dev->interrupt_mutex);
289 		WARN_ON(dev->interrupt_count == 0);
290 
291 		if (dev->interrupt_count && --dev->interrupt_count == 0)
292 			usb_kill_urb(dev->interrupt);
293 
294 		dev_dbg(&dev->udev->dev,
295 			"decremented interrupt URB count to %d\n",
296 			dev->interrupt_count);
297 		mutex_unlock(&dev->interrupt_mutex);
298 	}
299 }
300 EXPORT_SYMBOL_GPL(usbnet_status_stop);
301 
302 /* For suspend; always kill interrupt URB */
303 static void __usbnet_status_stop_force(struct usbnet *dev)
304 {
305 	if (dev->interrupt) {
306 		mutex_lock(&dev->interrupt_mutex);
307 		usb_kill_urb(dev->interrupt);
308 		dev_dbg(&dev->udev->dev, "killed interrupt URB for suspend\n");
309 		mutex_unlock(&dev->interrupt_mutex);
310 	}
311 }
312 
313 /* Passes this packet up the stack, updating its accounting.
314  * Some link protocols batch packets, so their rx_fixup paths
315  * can return clones as well as just modify the original skb.
316  */
317 void usbnet_skb_return (struct usbnet *dev, struct sk_buff *skb)
318 {
319 	int	status;
320 
321 	if (test_bit(EVENT_RX_PAUSED, &dev->flags)) {
322 		skb_queue_tail(&dev->rxq_pause, skb);
323 		return;
324 	}
325 
326 	skb->protocol = eth_type_trans (skb, dev->net);
327 	dev->net->stats.rx_packets++;
328 	dev->net->stats.rx_bytes += skb->len;
329 
330 	netif_dbg(dev, rx_status, dev->net, "< rx, len %zu, type 0x%x\n",
331 		  skb->len + sizeof (struct ethhdr), skb->protocol);
332 	memset (skb->cb, 0, sizeof (struct skb_data));
333 
334 	if (skb_defer_rx_timestamp(skb))
335 		return;
336 
337 	status = netif_rx (skb);
338 	if (status != NET_RX_SUCCESS)
339 		netif_dbg(dev, rx_err, dev->net,
340 			  "netif_rx status %d\n", status);
341 }
342 EXPORT_SYMBOL_GPL(usbnet_skb_return);
343 
344 /* must be called if hard_mtu or rx_urb_size changed */
345 void usbnet_update_max_qlen(struct usbnet *dev)
346 {
347 	enum usb_device_speed speed = dev->udev->speed;
348 
349 	switch (speed) {
350 	case USB_SPEED_HIGH:
351 		dev->rx_qlen = MAX_QUEUE_MEMORY / dev->rx_urb_size;
352 		dev->tx_qlen = MAX_QUEUE_MEMORY / dev->hard_mtu;
353 		break;
354 	case USB_SPEED_SUPER:
355 		/*
356 		 * Not take default 5ms qlen for super speed HC to
357 		 * save memory, and iperf tests show 2.5ms qlen can
358 		 * work well
359 		 */
360 		dev->rx_qlen = 5 * MAX_QUEUE_MEMORY / dev->rx_urb_size;
361 		dev->tx_qlen = 5 * MAX_QUEUE_MEMORY / dev->hard_mtu;
362 		break;
363 	default:
364 		dev->rx_qlen = dev->tx_qlen = 4;
365 	}
366 }
367 EXPORT_SYMBOL_GPL(usbnet_update_max_qlen);
368 
369 
370 /*-------------------------------------------------------------------------
371  *
372  * Network Device Driver (peer link to "Host Device", from USB host)
373  *
374  *-------------------------------------------------------------------------*/
375 
376 int usbnet_change_mtu (struct net_device *net, int new_mtu)
377 {
378 	struct usbnet	*dev = netdev_priv(net);
379 	int		ll_mtu = new_mtu + net->hard_header_len;
380 	int		old_hard_mtu = dev->hard_mtu;
381 	int		old_rx_urb_size = dev->rx_urb_size;
382 
383 	if (new_mtu <= 0)
384 		return -EINVAL;
385 	// no second zero-length packet read wanted after mtu-sized packets
386 	if ((ll_mtu % dev->maxpacket) == 0)
387 		return -EDOM;
388 	net->mtu = new_mtu;
389 
390 	dev->hard_mtu = net->mtu + net->hard_header_len;
391 	if (dev->rx_urb_size == old_hard_mtu) {
392 		dev->rx_urb_size = dev->hard_mtu;
393 		if (dev->rx_urb_size > old_rx_urb_size)
394 			usbnet_unlink_rx_urbs(dev);
395 	}
396 
397 	/* max qlen depend on hard_mtu and rx_urb_size */
398 	usbnet_update_max_qlen(dev);
399 
400 	return 0;
401 }
402 EXPORT_SYMBOL_GPL(usbnet_change_mtu);
403 
404 /* The caller must hold list->lock */
405 static void __usbnet_queue_skb(struct sk_buff_head *list,
406 			struct sk_buff *newsk, enum skb_state state)
407 {
408 	struct skb_data *entry = (struct skb_data *) newsk->cb;
409 
410 	__skb_queue_tail(list, newsk);
411 	entry->state = state;
412 }
413 
414 /*-------------------------------------------------------------------------*/
415 
416 /* some LK 2.4 HCDs oopsed if we freed or resubmitted urbs from
417  * completion callbacks.  2.5 should have fixed those bugs...
418  */
419 
420 static enum skb_state defer_bh(struct usbnet *dev, struct sk_buff *skb,
421 		struct sk_buff_head *list, enum skb_state state)
422 {
423 	unsigned long		flags;
424 	enum skb_state 		old_state;
425 	struct skb_data *entry = (struct skb_data *) skb->cb;
426 
427 	spin_lock_irqsave(&list->lock, flags);
428 	old_state = entry->state;
429 	entry->state = state;
430 	__skb_unlink(skb, list);
431 	spin_unlock(&list->lock);
432 	spin_lock(&dev->done.lock);
433 	__skb_queue_tail(&dev->done, skb);
434 	if (dev->done.qlen == 1)
435 		tasklet_schedule(&dev->bh);
436 	spin_unlock_irqrestore(&dev->done.lock, flags);
437 	return old_state;
438 }
439 
440 /* some work can't be done in tasklets, so we use keventd
441  *
442  * NOTE:  annoying asymmetry:  if it's active, schedule_work() fails,
443  * but tasklet_schedule() doesn't.  hope the failure is rare.
444  */
445 void usbnet_defer_kevent (struct usbnet *dev, int work)
446 {
447 	set_bit (work, &dev->flags);
448 	if (!schedule_work (&dev->kevent)) {
449 		if (net_ratelimit())
450 			netdev_err(dev->net, "kevent %d may have been dropped\n", work);
451 	} else {
452 		netdev_dbg(dev->net, "kevent %d scheduled\n", work);
453 	}
454 }
455 EXPORT_SYMBOL_GPL(usbnet_defer_kevent);
456 
457 /*-------------------------------------------------------------------------*/
458 
459 static void rx_complete (struct urb *urb);
460 
461 static int rx_submit (struct usbnet *dev, struct urb *urb, gfp_t flags)
462 {
463 	struct sk_buff		*skb;
464 	struct skb_data		*entry;
465 	int			retval = 0;
466 	unsigned long		lockflags;
467 	size_t			size = dev->rx_urb_size;
468 
469 	/* prevent rx skb allocation when error ratio is high */
470 	if (test_bit(EVENT_RX_KILL, &dev->flags)) {
471 		usb_free_urb(urb);
472 		return -ENOLINK;
473 	}
474 
475 	skb = __netdev_alloc_skb_ip_align(dev->net, size, flags);
476 	if (!skb) {
477 		netif_dbg(dev, rx_err, dev->net, "no rx skb\n");
478 		usbnet_defer_kevent (dev, EVENT_RX_MEMORY);
479 		usb_free_urb (urb);
480 		return -ENOMEM;
481 	}
482 
483 	entry = (struct skb_data *) skb->cb;
484 	entry->urb = urb;
485 	entry->dev = dev;
486 	entry->length = 0;
487 
488 	usb_fill_bulk_urb (urb, dev->udev, dev->in,
489 		skb->data, size, rx_complete, skb);
490 
491 	spin_lock_irqsave (&dev->rxq.lock, lockflags);
492 
493 	if (netif_running (dev->net) &&
494 	    netif_device_present (dev->net) &&
495 	    !test_bit (EVENT_RX_HALT, &dev->flags) &&
496 	    !test_bit (EVENT_DEV_ASLEEP, &dev->flags)) {
497 		switch (retval = usb_submit_urb (urb, GFP_ATOMIC)) {
498 		case -EPIPE:
499 			usbnet_defer_kevent (dev, EVENT_RX_HALT);
500 			break;
501 		case -ENOMEM:
502 			usbnet_defer_kevent (dev, EVENT_RX_MEMORY);
503 			break;
504 		case -ENODEV:
505 			netif_dbg(dev, ifdown, dev->net, "device gone\n");
506 			netif_device_detach (dev->net);
507 			break;
508 		case -EHOSTUNREACH:
509 			retval = -ENOLINK;
510 			break;
511 		default:
512 			netif_dbg(dev, rx_err, dev->net,
513 				  "rx submit, %d\n", retval);
514 			tasklet_schedule (&dev->bh);
515 			break;
516 		case 0:
517 			__usbnet_queue_skb(&dev->rxq, skb, rx_start);
518 		}
519 	} else {
520 		netif_dbg(dev, ifdown, dev->net, "rx: stopped\n");
521 		retval = -ENOLINK;
522 	}
523 	spin_unlock_irqrestore (&dev->rxq.lock, lockflags);
524 	if (retval) {
525 		dev_kfree_skb_any (skb);
526 		usb_free_urb (urb);
527 	}
528 	return retval;
529 }
530 
531 
532 /*-------------------------------------------------------------------------*/
533 
534 static inline void rx_process (struct usbnet *dev, struct sk_buff *skb)
535 {
536 	if (dev->driver_info->rx_fixup &&
537 	    !dev->driver_info->rx_fixup (dev, skb)) {
538 		/* With RX_ASSEMBLE, rx_fixup() must update counters */
539 		if (!(dev->driver_info->flags & FLAG_RX_ASSEMBLE))
540 			dev->net->stats.rx_errors++;
541 		goto done;
542 	}
543 	// else network stack removes extra byte if we forced a short packet
544 
545 	if (skb->len) {
546 		/* all data was already cloned from skb inside the driver */
547 		if (dev->driver_info->flags & FLAG_MULTI_PACKET)
548 			dev_kfree_skb_any(skb);
549 		else
550 			usbnet_skb_return(dev, skb);
551 		return;
552 	}
553 
554 	netif_dbg(dev, rx_err, dev->net, "drop\n");
555 	dev->net->stats.rx_errors++;
556 done:
557 	skb_queue_tail(&dev->done, skb);
558 }
559 
560 /*-------------------------------------------------------------------------*/
561 
562 static void rx_complete (struct urb *urb)
563 {
564 	struct sk_buff		*skb = (struct sk_buff *) urb->context;
565 	struct skb_data		*entry = (struct skb_data *) skb->cb;
566 	struct usbnet		*dev = entry->dev;
567 	int			urb_status = urb->status;
568 	enum skb_state		state;
569 
570 	skb_put (skb, urb->actual_length);
571 	state = rx_done;
572 	entry->urb = NULL;
573 
574 	switch (urb_status) {
575 	/* success */
576 	case 0:
577 		if (skb->len < dev->net->hard_header_len) {
578 			state = rx_cleanup;
579 			dev->net->stats.rx_errors++;
580 			dev->net->stats.rx_length_errors++;
581 			netif_dbg(dev, rx_err, dev->net,
582 				  "rx length %d\n", skb->len);
583 		}
584 		break;
585 
586 	/* stalls need manual reset. this is rare ... except that
587 	 * when going through USB 2.0 TTs, unplug appears this way.
588 	 * we avoid the highspeed version of the ETIMEDOUT/EILSEQ
589 	 * storm, recovering as needed.
590 	 */
591 	case -EPIPE:
592 		dev->net->stats.rx_errors++;
593 		usbnet_defer_kevent (dev, EVENT_RX_HALT);
594 		// FALLTHROUGH
595 
596 	/* software-driven interface shutdown */
597 	case -ECONNRESET:		/* async unlink */
598 	case -ESHUTDOWN:		/* hardware gone */
599 		netif_dbg(dev, ifdown, dev->net,
600 			  "rx shutdown, code %d\n", urb_status);
601 		goto block;
602 
603 	/* we get controller i/o faults during khubd disconnect() delays.
604 	 * throttle down resubmits, to avoid log floods; just temporarily,
605 	 * so we still recover when the fault isn't a khubd delay.
606 	 */
607 	case -EPROTO:
608 	case -ETIME:
609 	case -EILSEQ:
610 		dev->net->stats.rx_errors++;
611 		if (!timer_pending (&dev->delay)) {
612 			mod_timer (&dev->delay, jiffies + THROTTLE_JIFFIES);
613 			netif_dbg(dev, link, dev->net,
614 				  "rx throttle %d\n", urb_status);
615 		}
616 block:
617 		state = rx_cleanup;
618 		entry->urb = urb;
619 		urb = NULL;
620 		break;
621 
622 	/* data overrun ... flush fifo? */
623 	case -EOVERFLOW:
624 		dev->net->stats.rx_over_errors++;
625 		// FALLTHROUGH
626 
627 	default:
628 		state = rx_cleanup;
629 		dev->net->stats.rx_errors++;
630 		netif_dbg(dev, rx_err, dev->net, "rx status %d\n", urb_status);
631 		break;
632 	}
633 
634 	/* stop rx if packet error rate is high */
635 	if (++dev->pkt_cnt > 30) {
636 		dev->pkt_cnt = 0;
637 		dev->pkt_err = 0;
638 	} else {
639 		if (state == rx_cleanup)
640 			dev->pkt_err++;
641 		if (dev->pkt_err > 20)
642 			set_bit(EVENT_RX_KILL, &dev->flags);
643 	}
644 
645 	state = defer_bh(dev, skb, &dev->rxq, state);
646 
647 	if (urb) {
648 		if (netif_running (dev->net) &&
649 		    !test_bit (EVENT_RX_HALT, &dev->flags) &&
650 		    state != unlink_start) {
651 			rx_submit (dev, urb, GFP_ATOMIC);
652 			usb_mark_last_busy(dev->udev);
653 			return;
654 		}
655 		usb_free_urb (urb);
656 	}
657 	netif_dbg(dev, rx_err, dev->net, "no read resubmitted\n");
658 }
659 
660 /*-------------------------------------------------------------------------*/
661 void usbnet_pause_rx(struct usbnet *dev)
662 {
663 	set_bit(EVENT_RX_PAUSED, &dev->flags);
664 
665 	netif_dbg(dev, rx_status, dev->net, "paused rx queue enabled\n");
666 }
667 EXPORT_SYMBOL_GPL(usbnet_pause_rx);
668 
669 void usbnet_resume_rx(struct usbnet *dev)
670 {
671 	struct sk_buff *skb;
672 	int num = 0;
673 
674 	clear_bit(EVENT_RX_PAUSED, &dev->flags);
675 
676 	while ((skb = skb_dequeue(&dev->rxq_pause)) != NULL) {
677 		usbnet_skb_return(dev, skb);
678 		num++;
679 	}
680 
681 	tasklet_schedule(&dev->bh);
682 
683 	netif_dbg(dev, rx_status, dev->net,
684 		  "paused rx queue disabled, %d skbs requeued\n", num);
685 }
686 EXPORT_SYMBOL_GPL(usbnet_resume_rx);
687 
688 void usbnet_purge_paused_rxq(struct usbnet *dev)
689 {
690 	skb_queue_purge(&dev->rxq_pause);
691 }
692 EXPORT_SYMBOL_GPL(usbnet_purge_paused_rxq);
693 
694 /*-------------------------------------------------------------------------*/
695 
696 // unlink pending rx/tx; completion handlers do all other cleanup
697 
698 static int unlink_urbs (struct usbnet *dev, struct sk_buff_head *q)
699 {
700 	unsigned long		flags;
701 	struct sk_buff		*skb;
702 	int			count = 0;
703 
704 	spin_lock_irqsave (&q->lock, flags);
705 	while (!skb_queue_empty(q)) {
706 		struct skb_data		*entry;
707 		struct urb		*urb;
708 		int			retval;
709 
710 		skb_queue_walk(q, skb) {
711 			entry = (struct skb_data *) skb->cb;
712 			if (entry->state != unlink_start)
713 				goto found;
714 		}
715 		break;
716 found:
717 		entry->state = unlink_start;
718 		urb = entry->urb;
719 
720 		/*
721 		 * Get reference count of the URB to avoid it to be
722 		 * freed during usb_unlink_urb, which may trigger
723 		 * use-after-free problem inside usb_unlink_urb since
724 		 * usb_unlink_urb is always racing with .complete
725 		 * handler(include defer_bh).
726 		 */
727 		usb_get_urb(urb);
728 		spin_unlock_irqrestore(&q->lock, flags);
729 		// during some PM-driven resume scenarios,
730 		// these (async) unlinks complete immediately
731 		retval = usb_unlink_urb (urb);
732 		if (retval != -EINPROGRESS && retval != 0)
733 			netdev_dbg(dev->net, "unlink urb err, %d\n", retval);
734 		else
735 			count++;
736 		usb_put_urb(urb);
737 		spin_lock_irqsave(&q->lock, flags);
738 	}
739 	spin_unlock_irqrestore (&q->lock, flags);
740 	return count;
741 }
742 
743 // Flush all pending rx urbs
744 // minidrivers may need to do this when the MTU changes
745 
746 void usbnet_unlink_rx_urbs(struct usbnet *dev)
747 {
748 	if (netif_running(dev->net)) {
749 		(void) unlink_urbs (dev, &dev->rxq);
750 		tasklet_schedule(&dev->bh);
751 	}
752 }
753 EXPORT_SYMBOL_GPL(usbnet_unlink_rx_urbs);
754 
755 /*-------------------------------------------------------------------------*/
756 
757 // precondition: never called in_interrupt
758 static void usbnet_terminate_urbs(struct usbnet *dev)
759 {
760 	DECLARE_WAIT_QUEUE_HEAD_ONSTACK(unlink_wakeup);
761 	DECLARE_WAITQUEUE(wait, current);
762 	int temp;
763 
764 	/* ensure there are no more active urbs */
765 	add_wait_queue(&unlink_wakeup, &wait);
766 	set_current_state(TASK_UNINTERRUPTIBLE);
767 	dev->wait = &unlink_wakeup;
768 	temp = unlink_urbs(dev, &dev->txq) +
769 		unlink_urbs(dev, &dev->rxq);
770 
771 	/* maybe wait for deletions to finish. */
772 	while (!skb_queue_empty(&dev->rxq)
773 		&& !skb_queue_empty(&dev->txq)
774 		&& !skb_queue_empty(&dev->done)) {
775 			schedule_timeout(msecs_to_jiffies(UNLINK_TIMEOUT_MS));
776 			set_current_state(TASK_UNINTERRUPTIBLE);
777 			netif_dbg(dev, ifdown, dev->net,
778 				  "waited for %d urb completions\n", temp);
779 	}
780 	set_current_state(TASK_RUNNING);
781 	dev->wait = NULL;
782 	remove_wait_queue(&unlink_wakeup, &wait);
783 }
784 
785 int usbnet_stop (struct net_device *net)
786 {
787 	struct usbnet		*dev = netdev_priv(net);
788 	struct driver_info	*info = dev->driver_info;
789 	int			retval;
790 
791 	clear_bit(EVENT_DEV_OPEN, &dev->flags);
792 	netif_stop_queue (net);
793 
794 	netif_info(dev, ifdown, dev->net,
795 		   "stop stats: rx/tx %lu/%lu, errs %lu/%lu\n",
796 		   net->stats.rx_packets, net->stats.tx_packets,
797 		   net->stats.rx_errors, net->stats.tx_errors);
798 
799 	/* allow minidriver to stop correctly (wireless devices to turn off
800 	 * radio etc) */
801 	if (info->stop) {
802 		retval = info->stop(dev);
803 		if (retval < 0)
804 			netif_info(dev, ifdown, dev->net,
805 				   "stop fail (%d) usbnet usb-%s-%s, %s\n",
806 				   retval,
807 				   dev->udev->bus->bus_name, dev->udev->devpath,
808 				   info->description);
809 	}
810 
811 	if (!(info->flags & FLAG_AVOID_UNLINK_URBS))
812 		usbnet_terminate_urbs(dev);
813 
814 	usbnet_status_stop(dev);
815 
816 	usbnet_purge_paused_rxq(dev);
817 
818 	/* deferred work (task, timer, softirq) must also stop.
819 	 * can't flush_scheduled_work() until we drop rtnl (later),
820 	 * else workers could deadlock; so make workers a NOP.
821 	 */
822 	dev->flags = 0;
823 	del_timer_sync (&dev->delay);
824 	tasklet_kill (&dev->bh);
825 	if (info->manage_power &&
826 	    !test_and_clear_bit(EVENT_NO_RUNTIME_PM, &dev->flags))
827 		info->manage_power(dev, 0);
828 	else
829 		usb_autopm_put_interface(dev->intf);
830 
831 	return 0;
832 }
833 EXPORT_SYMBOL_GPL(usbnet_stop);
834 
835 /*-------------------------------------------------------------------------*/
836 
837 // posts reads, and enables write queuing
838 
839 // precondition: never called in_interrupt
840 
841 int usbnet_open (struct net_device *net)
842 {
843 	struct usbnet		*dev = netdev_priv(net);
844 	int			retval;
845 	struct driver_info	*info = dev->driver_info;
846 
847 	if ((retval = usb_autopm_get_interface(dev->intf)) < 0) {
848 		netif_info(dev, ifup, dev->net,
849 			   "resumption fail (%d) usbnet usb-%s-%s, %s\n",
850 			   retval,
851 			   dev->udev->bus->bus_name,
852 			   dev->udev->devpath,
853 			   info->description);
854 		goto done_nopm;
855 	}
856 
857 	// put into "known safe" state
858 	if (info->reset && (retval = info->reset (dev)) < 0) {
859 		netif_info(dev, ifup, dev->net,
860 			   "open reset fail (%d) usbnet usb-%s-%s, %s\n",
861 			   retval,
862 			   dev->udev->bus->bus_name,
863 			   dev->udev->devpath,
864 			   info->description);
865 		goto done;
866 	}
867 
868 	/* hard_mtu or rx_urb_size may change in reset() */
869 	usbnet_update_max_qlen(dev);
870 
871 	// insist peer be connected
872 	if (info->check_connect && (retval = info->check_connect (dev)) < 0) {
873 		netif_dbg(dev, ifup, dev->net, "can't open; %d\n", retval);
874 		goto done;
875 	}
876 
877 	/* start any status interrupt transfer */
878 	if (dev->interrupt) {
879 		retval = usbnet_status_start(dev, GFP_KERNEL);
880 		if (retval < 0) {
881 			netif_err(dev, ifup, dev->net,
882 				  "intr submit %d\n", retval);
883 			goto done;
884 		}
885 	}
886 
887 	set_bit(EVENT_DEV_OPEN, &dev->flags);
888 	netif_start_queue (net);
889 	netif_info(dev, ifup, dev->net,
890 		   "open: enable queueing (rx %d, tx %d) mtu %d %s framing\n",
891 		   (int)RX_QLEN(dev), (int)TX_QLEN(dev),
892 		   dev->net->mtu,
893 		   (dev->driver_info->flags & FLAG_FRAMING_NC) ? "NetChip" :
894 		   (dev->driver_info->flags & FLAG_FRAMING_GL) ? "GeneSys" :
895 		   (dev->driver_info->flags & FLAG_FRAMING_Z) ? "Zaurus" :
896 		   (dev->driver_info->flags & FLAG_FRAMING_RN) ? "RNDIS" :
897 		   (dev->driver_info->flags & FLAG_FRAMING_AX) ? "ASIX" :
898 		   "simple");
899 
900 	/* reset rx error state */
901 	dev->pkt_cnt = 0;
902 	dev->pkt_err = 0;
903 	clear_bit(EVENT_RX_KILL, &dev->flags);
904 
905 	// delay posting reads until we're fully open
906 	tasklet_schedule (&dev->bh);
907 	if (info->manage_power) {
908 		retval = info->manage_power(dev, 1);
909 		if (retval < 0) {
910 			retval = 0;
911 			set_bit(EVENT_NO_RUNTIME_PM, &dev->flags);
912 		} else {
913 			usb_autopm_put_interface(dev->intf);
914 		}
915 	}
916 	return retval;
917 done:
918 	usb_autopm_put_interface(dev->intf);
919 done_nopm:
920 	return retval;
921 }
922 EXPORT_SYMBOL_GPL(usbnet_open);
923 
924 /*-------------------------------------------------------------------------*/
925 
926 /* ethtool methods; minidrivers may need to add some more, but
927  * they'll probably want to use this base set.
928  */
929 
930 int usbnet_get_settings (struct net_device *net, struct ethtool_cmd *cmd)
931 {
932 	struct usbnet *dev = netdev_priv(net);
933 
934 	if (!dev->mii.mdio_read)
935 		return -EOPNOTSUPP;
936 
937 	return mii_ethtool_gset(&dev->mii, cmd);
938 }
939 EXPORT_SYMBOL_GPL(usbnet_get_settings);
940 
941 int usbnet_set_settings (struct net_device *net, struct ethtool_cmd *cmd)
942 {
943 	struct usbnet *dev = netdev_priv(net);
944 	int retval;
945 
946 	if (!dev->mii.mdio_write)
947 		return -EOPNOTSUPP;
948 
949 	retval = mii_ethtool_sset(&dev->mii, cmd);
950 
951 	/* link speed/duplex might have changed */
952 	if (dev->driver_info->link_reset)
953 		dev->driver_info->link_reset(dev);
954 
955 	/* hard_mtu or rx_urb_size may change in link_reset() */
956 	usbnet_update_max_qlen(dev);
957 
958 	return retval;
959 
960 }
961 EXPORT_SYMBOL_GPL(usbnet_set_settings);
962 
963 u32 usbnet_get_link (struct net_device *net)
964 {
965 	struct usbnet *dev = netdev_priv(net);
966 
967 	/* If a check_connect is defined, return its result */
968 	if (dev->driver_info->check_connect)
969 		return dev->driver_info->check_connect (dev) == 0;
970 
971 	/* if the device has mii operations, use those */
972 	if (dev->mii.mdio_read)
973 		return mii_link_ok(&dev->mii);
974 
975 	/* Otherwise, dtrt for drivers calling netif_carrier_{on,off} */
976 	return ethtool_op_get_link(net);
977 }
978 EXPORT_SYMBOL_GPL(usbnet_get_link);
979 
980 int usbnet_nway_reset(struct net_device *net)
981 {
982 	struct usbnet *dev = netdev_priv(net);
983 
984 	if (!dev->mii.mdio_write)
985 		return -EOPNOTSUPP;
986 
987 	return mii_nway_restart(&dev->mii);
988 }
989 EXPORT_SYMBOL_GPL(usbnet_nway_reset);
990 
991 void usbnet_get_drvinfo (struct net_device *net, struct ethtool_drvinfo *info)
992 {
993 	struct usbnet *dev = netdev_priv(net);
994 
995 	strlcpy (info->driver, dev->driver_name, sizeof info->driver);
996 	strlcpy (info->version, DRIVER_VERSION, sizeof info->version);
997 	strlcpy (info->fw_version, dev->driver_info->description,
998 		sizeof info->fw_version);
999 	usb_make_path (dev->udev, info->bus_info, sizeof info->bus_info);
1000 }
1001 EXPORT_SYMBOL_GPL(usbnet_get_drvinfo);
1002 
1003 u32 usbnet_get_msglevel (struct net_device *net)
1004 {
1005 	struct usbnet *dev = netdev_priv(net);
1006 
1007 	return dev->msg_enable;
1008 }
1009 EXPORT_SYMBOL_GPL(usbnet_get_msglevel);
1010 
1011 void usbnet_set_msglevel (struct net_device *net, u32 level)
1012 {
1013 	struct usbnet *dev = netdev_priv(net);
1014 
1015 	dev->msg_enable = level;
1016 }
1017 EXPORT_SYMBOL_GPL(usbnet_set_msglevel);
1018 
1019 /* drivers may override default ethtool_ops in their bind() routine */
1020 static const struct ethtool_ops usbnet_ethtool_ops = {
1021 	.get_settings		= usbnet_get_settings,
1022 	.set_settings		= usbnet_set_settings,
1023 	.get_link		= usbnet_get_link,
1024 	.nway_reset		= usbnet_nway_reset,
1025 	.get_drvinfo		= usbnet_get_drvinfo,
1026 	.get_msglevel		= usbnet_get_msglevel,
1027 	.set_msglevel		= usbnet_set_msglevel,
1028 	.get_ts_info		= ethtool_op_get_ts_info,
1029 };
1030 
1031 /*-------------------------------------------------------------------------*/
1032 
1033 static void __handle_link_change(struct usbnet *dev)
1034 {
1035 	if (!test_bit(EVENT_DEV_OPEN, &dev->flags))
1036 		return;
1037 
1038 	if (!netif_carrier_ok(dev->net)) {
1039 		/* kill URBs for reading packets to save bus bandwidth */
1040 		unlink_urbs(dev, &dev->rxq);
1041 
1042 		/*
1043 		 * tx_timeout will unlink URBs for sending packets and
1044 		 * tx queue is stopped by netcore after link becomes off
1045 		 */
1046 	} else {
1047 		/* submitting URBs for reading packets */
1048 		tasklet_schedule(&dev->bh);
1049 	}
1050 
1051 	/* hard_mtu or rx_urb_size may change during link change */
1052 	usbnet_update_max_qlen(dev);
1053 
1054 	clear_bit(EVENT_LINK_CHANGE, &dev->flags);
1055 }
1056 
1057 /* work that cannot be done in interrupt context uses keventd.
1058  *
1059  * NOTE:  with 2.5 we could do more of this using completion callbacks,
1060  * especially now that control transfers can be queued.
1061  */
1062 static void
1063 kevent (struct work_struct *work)
1064 {
1065 	struct usbnet		*dev =
1066 		container_of(work, struct usbnet, kevent);
1067 	int			status;
1068 
1069 	/* usb_clear_halt() needs a thread context */
1070 	if (test_bit (EVENT_TX_HALT, &dev->flags)) {
1071 		unlink_urbs (dev, &dev->txq);
1072 		status = usb_autopm_get_interface(dev->intf);
1073 		if (status < 0)
1074 			goto fail_pipe;
1075 		status = usb_clear_halt (dev->udev, dev->out);
1076 		usb_autopm_put_interface(dev->intf);
1077 		if (status < 0 &&
1078 		    status != -EPIPE &&
1079 		    status != -ESHUTDOWN) {
1080 			if (netif_msg_tx_err (dev))
1081 fail_pipe:
1082 				netdev_err(dev->net, "can't clear tx halt, status %d\n",
1083 					   status);
1084 		} else {
1085 			clear_bit (EVENT_TX_HALT, &dev->flags);
1086 			if (status != -ESHUTDOWN)
1087 				netif_wake_queue (dev->net);
1088 		}
1089 	}
1090 	if (test_bit (EVENT_RX_HALT, &dev->flags)) {
1091 		unlink_urbs (dev, &dev->rxq);
1092 		status = usb_autopm_get_interface(dev->intf);
1093 		if (status < 0)
1094 			goto fail_halt;
1095 		status = usb_clear_halt (dev->udev, dev->in);
1096 		usb_autopm_put_interface(dev->intf);
1097 		if (status < 0 &&
1098 		    status != -EPIPE &&
1099 		    status != -ESHUTDOWN) {
1100 			if (netif_msg_rx_err (dev))
1101 fail_halt:
1102 				netdev_err(dev->net, "can't clear rx halt, status %d\n",
1103 					   status);
1104 		} else {
1105 			clear_bit (EVENT_RX_HALT, &dev->flags);
1106 			tasklet_schedule (&dev->bh);
1107 		}
1108 	}
1109 
1110 	/* tasklet could resubmit itself forever if memory is tight */
1111 	if (test_bit (EVENT_RX_MEMORY, &dev->flags)) {
1112 		struct urb	*urb = NULL;
1113 		int resched = 1;
1114 
1115 		if (netif_running (dev->net))
1116 			urb = usb_alloc_urb (0, GFP_KERNEL);
1117 		else
1118 			clear_bit (EVENT_RX_MEMORY, &dev->flags);
1119 		if (urb != NULL) {
1120 			clear_bit (EVENT_RX_MEMORY, &dev->flags);
1121 			status = usb_autopm_get_interface(dev->intf);
1122 			if (status < 0) {
1123 				usb_free_urb(urb);
1124 				goto fail_lowmem;
1125 			}
1126 			if (rx_submit (dev, urb, GFP_KERNEL) == -ENOLINK)
1127 				resched = 0;
1128 			usb_autopm_put_interface(dev->intf);
1129 fail_lowmem:
1130 			if (resched)
1131 				tasklet_schedule (&dev->bh);
1132 		}
1133 	}
1134 
1135 	if (test_bit (EVENT_LINK_RESET, &dev->flags)) {
1136 		struct driver_info	*info = dev->driver_info;
1137 		int			retval = 0;
1138 
1139 		clear_bit (EVENT_LINK_RESET, &dev->flags);
1140 		status = usb_autopm_get_interface(dev->intf);
1141 		if (status < 0)
1142 			goto skip_reset;
1143 		if(info->link_reset && (retval = info->link_reset(dev)) < 0) {
1144 			usb_autopm_put_interface(dev->intf);
1145 skip_reset:
1146 			netdev_info(dev->net, "link reset failed (%d) usbnet usb-%s-%s, %s\n",
1147 				    retval,
1148 				    dev->udev->bus->bus_name,
1149 				    dev->udev->devpath,
1150 				    info->description);
1151 		} else {
1152 			usb_autopm_put_interface(dev->intf);
1153 		}
1154 
1155 		/* handle link change from link resetting */
1156 		__handle_link_change(dev);
1157 	}
1158 
1159 	if (test_bit (EVENT_LINK_CHANGE, &dev->flags))
1160 		__handle_link_change(dev);
1161 
1162 	if (dev->flags)
1163 		netdev_dbg(dev->net, "kevent done, flags = 0x%lx\n", dev->flags);
1164 }
1165 
1166 /*-------------------------------------------------------------------------*/
1167 
1168 static void tx_complete (struct urb *urb)
1169 {
1170 	struct sk_buff		*skb = (struct sk_buff *) urb->context;
1171 	struct skb_data		*entry = (struct skb_data *) skb->cb;
1172 	struct usbnet		*dev = entry->dev;
1173 
1174 	if (urb->status == 0) {
1175 		if (!(dev->driver_info->flags & FLAG_MULTI_PACKET))
1176 			dev->net->stats.tx_packets++;
1177 		dev->net->stats.tx_bytes += entry->length;
1178 	} else {
1179 		dev->net->stats.tx_errors++;
1180 
1181 		switch (urb->status) {
1182 		case -EPIPE:
1183 			usbnet_defer_kevent (dev, EVENT_TX_HALT);
1184 			break;
1185 
1186 		/* software-driven interface shutdown */
1187 		case -ECONNRESET:		// async unlink
1188 		case -ESHUTDOWN:		// hardware gone
1189 			break;
1190 
1191 		// like rx, tx gets controller i/o faults during khubd delays
1192 		// and so it uses the same throttling mechanism.
1193 		case -EPROTO:
1194 		case -ETIME:
1195 		case -EILSEQ:
1196 			usb_mark_last_busy(dev->udev);
1197 			if (!timer_pending (&dev->delay)) {
1198 				mod_timer (&dev->delay,
1199 					jiffies + THROTTLE_JIFFIES);
1200 				netif_dbg(dev, link, dev->net,
1201 					  "tx throttle %d\n", urb->status);
1202 			}
1203 			netif_stop_queue (dev->net);
1204 			break;
1205 		default:
1206 			netif_dbg(dev, tx_err, dev->net,
1207 				  "tx err %d\n", entry->urb->status);
1208 			break;
1209 		}
1210 	}
1211 
1212 	usb_autopm_put_interface_async(dev->intf);
1213 	(void) defer_bh(dev, skb, &dev->txq, tx_done);
1214 }
1215 
1216 /*-------------------------------------------------------------------------*/
1217 
1218 void usbnet_tx_timeout (struct net_device *net)
1219 {
1220 	struct usbnet		*dev = netdev_priv(net);
1221 
1222 	unlink_urbs (dev, &dev->txq);
1223 	tasklet_schedule (&dev->bh);
1224 
1225 	// FIXME: device recovery -- reset?
1226 }
1227 EXPORT_SYMBOL_GPL(usbnet_tx_timeout);
1228 
1229 /*-------------------------------------------------------------------------*/
1230 
1231 static int build_dma_sg(const struct sk_buff *skb, struct urb *urb)
1232 {
1233 	unsigned num_sgs, total_len = 0;
1234 	int i, s = 0;
1235 
1236 	num_sgs = skb_shinfo(skb)->nr_frags + 1;
1237 	if (num_sgs == 1)
1238 		return 0;
1239 
1240 	/* reserve one for zero packet */
1241 	urb->sg = kmalloc((num_sgs + 1) * sizeof(struct scatterlist),
1242 			  GFP_ATOMIC);
1243 	if (!urb->sg)
1244 		return -ENOMEM;
1245 
1246 	urb->num_sgs = num_sgs;
1247 	sg_init_table(urb->sg, urb->num_sgs + 1);
1248 
1249 	sg_set_buf(&urb->sg[s++], skb->data, skb_headlen(skb));
1250 	total_len += skb_headlen(skb);
1251 
1252 	for (i = 0; i < skb_shinfo(skb)->nr_frags; i++) {
1253 		struct skb_frag_struct *f = &skb_shinfo(skb)->frags[i];
1254 
1255 		total_len += skb_frag_size(f);
1256 		sg_set_page(&urb->sg[i + s], f->page.p, f->size,
1257 				f->page_offset);
1258 	}
1259 	urb->transfer_buffer_length = total_len;
1260 
1261 	return 1;
1262 }
1263 
1264 netdev_tx_t usbnet_start_xmit (struct sk_buff *skb,
1265 				     struct net_device *net)
1266 {
1267 	struct usbnet		*dev = netdev_priv(net);
1268 	int			length;
1269 	struct urb		*urb = NULL;
1270 	struct skb_data		*entry;
1271 	struct driver_info	*info = dev->driver_info;
1272 	unsigned long		flags;
1273 	int retval;
1274 
1275 	if (skb)
1276 		skb_tx_timestamp(skb);
1277 
1278 	// some devices want funky USB-level framing, for
1279 	// win32 driver (usually) and/or hardware quirks
1280 	if (info->tx_fixup) {
1281 		skb = info->tx_fixup (dev, skb, GFP_ATOMIC);
1282 		if (!skb) {
1283 			/* packet collected; minidriver waiting for more */
1284 			if (info->flags & FLAG_MULTI_PACKET)
1285 				goto not_drop;
1286 			netif_dbg(dev, tx_err, dev->net, "can't tx_fixup skb\n");
1287 			goto drop;
1288 		}
1289 	}
1290 
1291 	if (!(urb = usb_alloc_urb (0, GFP_ATOMIC))) {
1292 		netif_dbg(dev, tx_err, dev->net, "no urb\n");
1293 		goto drop;
1294 	}
1295 
1296 	entry = (struct skb_data *) skb->cb;
1297 	entry->urb = urb;
1298 	entry->dev = dev;
1299 
1300 	usb_fill_bulk_urb (urb, dev->udev, dev->out,
1301 			skb->data, skb->len, tx_complete, skb);
1302 	if (dev->can_dma_sg) {
1303 		if (build_dma_sg(skb, urb) < 0)
1304 			goto drop;
1305 	}
1306 	length = urb->transfer_buffer_length;
1307 
1308 	/* don't assume the hardware handles USB_ZERO_PACKET
1309 	 * NOTE:  strictly conforming cdc-ether devices should expect
1310 	 * the ZLP here, but ignore the one-byte packet.
1311 	 * NOTE2: CDC NCM specification is different from CDC ECM when
1312 	 * handling ZLP/short packets, so cdc_ncm driver will make short
1313 	 * packet itself if needed.
1314 	 */
1315 	if (length % dev->maxpacket == 0) {
1316 		if (!(info->flags & FLAG_SEND_ZLP)) {
1317 			if (!(info->flags & FLAG_MULTI_PACKET)) {
1318 				length++;
1319 				if (skb_tailroom(skb) && !urb->num_sgs) {
1320 					skb->data[skb->len] = 0;
1321 					__skb_put(skb, 1);
1322 				} else if (urb->num_sgs)
1323 					sg_set_buf(&urb->sg[urb->num_sgs++],
1324 							dev->padding_pkt, 1);
1325 			}
1326 		} else
1327 			urb->transfer_flags |= URB_ZERO_PACKET;
1328 	}
1329 	entry->length = urb->transfer_buffer_length = length;
1330 
1331 	spin_lock_irqsave(&dev->txq.lock, flags);
1332 	retval = usb_autopm_get_interface_async(dev->intf);
1333 	if (retval < 0) {
1334 		spin_unlock_irqrestore(&dev->txq.lock, flags);
1335 		goto drop;
1336 	}
1337 
1338 #ifdef CONFIG_PM
1339 	/* if this triggers the device is still a sleep */
1340 	if (test_bit(EVENT_DEV_ASLEEP, &dev->flags)) {
1341 		/* transmission will be done in resume */
1342 		usb_anchor_urb(urb, &dev->deferred);
1343 		/* no use to process more packets */
1344 		netif_stop_queue(net);
1345 		usb_put_urb(urb);
1346 		spin_unlock_irqrestore(&dev->txq.lock, flags);
1347 		netdev_dbg(dev->net, "Delaying transmission for resumption\n");
1348 		goto deferred;
1349 	}
1350 #endif
1351 
1352 	switch ((retval = usb_submit_urb (urb, GFP_ATOMIC))) {
1353 	case -EPIPE:
1354 		netif_stop_queue (net);
1355 		usbnet_defer_kevent (dev, EVENT_TX_HALT);
1356 		usb_autopm_put_interface_async(dev->intf);
1357 		break;
1358 	default:
1359 		usb_autopm_put_interface_async(dev->intf);
1360 		netif_dbg(dev, tx_err, dev->net,
1361 			  "tx: submit urb err %d\n", retval);
1362 		break;
1363 	case 0:
1364 		net->trans_start = jiffies;
1365 		__usbnet_queue_skb(&dev->txq, skb, tx_start);
1366 		if (dev->txq.qlen >= TX_QLEN (dev))
1367 			netif_stop_queue (net);
1368 	}
1369 	spin_unlock_irqrestore (&dev->txq.lock, flags);
1370 
1371 	if (retval) {
1372 		netif_dbg(dev, tx_err, dev->net, "drop, code %d\n", retval);
1373 drop:
1374 		dev->net->stats.tx_dropped++;
1375 not_drop:
1376 		if (skb)
1377 			dev_kfree_skb_any (skb);
1378 		if (urb) {
1379 			kfree(urb->sg);
1380 			usb_free_urb(urb);
1381 		}
1382 	} else
1383 		netif_dbg(dev, tx_queued, dev->net,
1384 			  "> tx, len %d, type 0x%x\n", length, skb->protocol);
1385 #ifdef CONFIG_PM
1386 deferred:
1387 #endif
1388 	return NETDEV_TX_OK;
1389 }
1390 EXPORT_SYMBOL_GPL(usbnet_start_xmit);
1391 
1392 static int rx_alloc_submit(struct usbnet *dev, gfp_t flags)
1393 {
1394 	struct urb	*urb;
1395 	int		i;
1396 	int		ret = 0;
1397 
1398 	/* don't refill the queue all at once */
1399 	for (i = 0; i < 10 && dev->rxq.qlen < RX_QLEN(dev); i++) {
1400 		urb = usb_alloc_urb(0, flags);
1401 		if (urb != NULL) {
1402 			ret = rx_submit(dev, urb, flags);
1403 			if (ret)
1404 				goto err;
1405 		} else {
1406 			ret = -ENOMEM;
1407 			goto err;
1408 		}
1409 	}
1410 err:
1411 	return ret;
1412 }
1413 
1414 /*-------------------------------------------------------------------------*/
1415 
1416 // tasklet (work deferred from completions, in_irq) or timer
1417 
1418 static void usbnet_bh (unsigned long param)
1419 {
1420 	struct usbnet		*dev = (struct usbnet *) param;
1421 	struct sk_buff		*skb;
1422 	struct skb_data		*entry;
1423 
1424 	while ((skb = skb_dequeue (&dev->done))) {
1425 		entry = (struct skb_data *) skb->cb;
1426 		switch (entry->state) {
1427 		case rx_done:
1428 			entry->state = rx_cleanup;
1429 			rx_process (dev, skb);
1430 			continue;
1431 		case tx_done:
1432 			kfree(entry->urb->sg);
1433 		case rx_cleanup:
1434 			usb_free_urb (entry->urb);
1435 			dev_kfree_skb (skb);
1436 			continue;
1437 		default:
1438 			netdev_dbg(dev->net, "bogus skb state %d\n", entry->state);
1439 		}
1440 	}
1441 
1442 	/* restart RX again after disabling due to high error rate */
1443 	clear_bit(EVENT_RX_KILL, &dev->flags);
1444 
1445 	// waiting for all pending urbs to complete?
1446 	if (dev->wait) {
1447 		if ((dev->txq.qlen + dev->rxq.qlen + dev->done.qlen) == 0) {
1448 			wake_up (dev->wait);
1449 		}
1450 
1451 	// or are we maybe short a few urbs?
1452 	} else if (netif_running (dev->net) &&
1453 		   netif_device_present (dev->net) &&
1454 		   netif_carrier_ok(dev->net) &&
1455 		   !timer_pending (&dev->delay) &&
1456 		   !test_bit (EVENT_RX_HALT, &dev->flags)) {
1457 		int	temp = dev->rxq.qlen;
1458 
1459 		if (temp < RX_QLEN(dev)) {
1460 			if (rx_alloc_submit(dev, GFP_ATOMIC) == -ENOLINK)
1461 				return;
1462 			if (temp != dev->rxq.qlen)
1463 				netif_dbg(dev, link, dev->net,
1464 					  "rxqlen %d --> %d\n",
1465 					  temp, dev->rxq.qlen);
1466 			if (dev->rxq.qlen < RX_QLEN(dev))
1467 				tasklet_schedule (&dev->bh);
1468 		}
1469 		if (dev->txq.qlen < TX_QLEN (dev))
1470 			netif_wake_queue (dev->net);
1471 	}
1472 }
1473 
1474 
1475 /*-------------------------------------------------------------------------
1476  *
1477  * USB Device Driver support
1478  *
1479  *-------------------------------------------------------------------------*/
1480 
1481 // precondition: never called in_interrupt
1482 
1483 void usbnet_disconnect (struct usb_interface *intf)
1484 {
1485 	struct usbnet		*dev;
1486 	struct usb_device	*xdev;
1487 	struct net_device	*net;
1488 
1489 	dev = usb_get_intfdata(intf);
1490 	usb_set_intfdata(intf, NULL);
1491 	if (!dev)
1492 		return;
1493 
1494 	xdev = interface_to_usbdev (intf);
1495 
1496 	netif_info(dev, probe, dev->net, "unregister '%s' usb-%s-%s, %s\n",
1497 		   intf->dev.driver->name,
1498 		   xdev->bus->bus_name, xdev->devpath,
1499 		   dev->driver_info->description);
1500 
1501 	net = dev->net;
1502 	unregister_netdev (net);
1503 
1504 	cancel_work_sync(&dev->kevent);
1505 
1506 	usb_scuttle_anchored_urbs(&dev->deferred);
1507 
1508 	if (dev->driver_info->unbind)
1509 		dev->driver_info->unbind (dev, intf);
1510 
1511 	usb_kill_urb(dev->interrupt);
1512 	usb_free_urb(dev->interrupt);
1513 	kfree(dev->padding_pkt);
1514 
1515 	free_netdev(net);
1516 }
1517 EXPORT_SYMBOL_GPL(usbnet_disconnect);
1518 
1519 static const struct net_device_ops usbnet_netdev_ops = {
1520 	.ndo_open		= usbnet_open,
1521 	.ndo_stop		= usbnet_stop,
1522 	.ndo_start_xmit		= usbnet_start_xmit,
1523 	.ndo_tx_timeout		= usbnet_tx_timeout,
1524 	.ndo_change_mtu		= usbnet_change_mtu,
1525 	.ndo_set_mac_address 	= eth_mac_addr,
1526 	.ndo_validate_addr	= eth_validate_addr,
1527 };
1528 
1529 /*-------------------------------------------------------------------------*/
1530 
1531 // precondition: never called in_interrupt
1532 
1533 static struct device_type wlan_type = {
1534 	.name	= "wlan",
1535 };
1536 
1537 static struct device_type wwan_type = {
1538 	.name	= "wwan",
1539 };
1540 
1541 int
1542 usbnet_probe (struct usb_interface *udev, const struct usb_device_id *prod)
1543 {
1544 	struct usbnet			*dev;
1545 	struct net_device		*net;
1546 	struct usb_host_interface	*interface;
1547 	struct driver_info		*info;
1548 	struct usb_device		*xdev;
1549 	int				status;
1550 	const char			*name;
1551 	struct usb_driver 	*driver = to_usb_driver(udev->dev.driver);
1552 
1553 	/* usbnet already took usb runtime pm, so have to enable the feature
1554 	 * for usb interface, otherwise usb_autopm_get_interface may return
1555 	 * failure if RUNTIME_PM is enabled.
1556 	 */
1557 	if (!driver->supports_autosuspend) {
1558 		driver->supports_autosuspend = 1;
1559 		pm_runtime_enable(&udev->dev);
1560 	}
1561 
1562 	name = udev->dev.driver->name;
1563 	info = (struct driver_info *) prod->driver_info;
1564 	if (!info) {
1565 		dev_dbg (&udev->dev, "blacklisted by %s\n", name);
1566 		return -ENODEV;
1567 	}
1568 	xdev = interface_to_usbdev (udev);
1569 	interface = udev->cur_altsetting;
1570 
1571 	status = -ENOMEM;
1572 
1573 	// set up our own records
1574 	net = alloc_etherdev(sizeof(*dev));
1575 	if (!net)
1576 		goto out;
1577 
1578 	/* netdev_printk() needs this so do it as early as possible */
1579 	SET_NETDEV_DEV(net, &udev->dev);
1580 
1581 	dev = netdev_priv(net);
1582 	dev->udev = xdev;
1583 	dev->intf = udev;
1584 	dev->driver_info = info;
1585 	dev->driver_name = name;
1586 	dev->msg_enable = netif_msg_init (msg_level, NETIF_MSG_DRV
1587 				| NETIF_MSG_PROBE | NETIF_MSG_LINK);
1588 	skb_queue_head_init (&dev->rxq);
1589 	skb_queue_head_init (&dev->txq);
1590 	skb_queue_head_init (&dev->done);
1591 	skb_queue_head_init(&dev->rxq_pause);
1592 	dev->bh.func = usbnet_bh;
1593 	dev->bh.data = (unsigned long) dev;
1594 	INIT_WORK (&dev->kevent, kevent);
1595 	init_usb_anchor(&dev->deferred);
1596 	dev->delay.function = usbnet_bh;
1597 	dev->delay.data = (unsigned long) dev;
1598 	init_timer (&dev->delay);
1599 	mutex_init (&dev->phy_mutex);
1600 	mutex_init(&dev->interrupt_mutex);
1601 	dev->interrupt_count = 0;
1602 
1603 	dev->net = net;
1604 	strcpy (net->name, "usb%d");
1605 	memcpy (net->dev_addr, node_id, sizeof node_id);
1606 
1607 	/* rx and tx sides can use different message sizes;
1608 	 * bind() should set rx_urb_size in that case.
1609 	 */
1610 	dev->hard_mtu = net->mtu + net->hard_header_len;
1611 #if 0
1612 // dma_supported() is deeply broken on almost all architectures
1613 	// possible with some EHCI controllers
1614 	if (dma_supported (&udev->dev, DMA_BIT_MASK(64)))
1615 		net->features |= NETIF_F_HIGHDMA;
1616 #endif
1617 
1618 	net->netdev_ops = &usbnet_netdev_ops;
1619 	net->watchdog_timeo = TX_TIMEOUT_JIFFIES;
1620 	net->ethtool_ops = &usbnet_ethtool_ops;
1621 
1622 	// allow device-specific bind/init procedures
1623 	// NOTE net->name still not usable ...
1624 	if (info->bind) {
1625 		status = info->bind (dev, udev);
1626 		if (status < 0)
1627 			goto out1;
1628 
1629 		// heuristic:  "usb%d" for links we know are two-host,
1630 		// else "eth%d" when there's reasonable doubt.  userspace
1631 		// can rename the link if it knows better.
1632 		if ((dev->driver_info->flags & FLAG_ETHER) != 0 &&
1633 		    ((dev->driver_info->flags & FLAG_POINTTOPOINT) == 0 ||
1634 		     (net->dev_addr [0] & 0x02) == 0))
1635 			strcpy (net->name, "eth%d");
1636 		/* WLAN devices should always be named "wlan%d" */
1637 		if ((dev->driver_info->flags & FLAG_WLAN) != 0)
1638 			strcpy(net->name, "wlan%d");
1639 		/* WWAN devices should always be named "wwan%d" */
1640 		if ((dev->driver_info->flags & FLAG_WWAN) != 0)
1641 			strcpy(net->name, "wwan%d");
1642 
1643 		/* devices that cannot do ARP */
1644 		if ((dev->driver_info->flags & FLAG_NOARP) != 0)
1645 			net->flags |= IFF_NOARP;
1646 
1647 		/* maybe the remote can't receive an Ethernet MTU */
1648 		if (net->mtu > (dev->hard_mtu - net->hard_header_len))
1649 			net->mtu = dev->hard_mtu - net->hard_header_len;
1650 	} else if (!info->in || !info->out)
1651 		status = usbnet_get_endpoints (dev, udev);
1652 	else {
1653 		dev->in = usb_rcvbulkpipe (xdev, info->in);
1654 		dev->out = usb_sndbulkpipe (xdev, info->out);
1655 		if (!(info->flags & FLAG_NO_SETINT))
1656 			status = usb_set_interface (xdev,
1657 				interface->desc.bInterfaceNumber,
1658 				interface->desc.bAlternateSetting);
1659 		else
1660 			status = 0;
1661 
1662 	}
1663 	if (status >= 0 && dev->status)
1664 		status = init_status (dev, udev);
1665 	if (status < 0)
1666 		goto out3;
1667 
1668 	if (!dev->rx_urb_size)
1669 		dev->rx_urb_size = dev->hard_mtu;
1670 	dev->maxpacket = usb_maxpacket (dev->udev, dev->out, 1);
1671 
1672 	/* let userspace know we have a random address */
1673 	if (ether_addr_equal(net->dev_addr, node_id))
1674 		net->addr_assign_type = NET_ADDR_RANDOM;
1675 
1676 	if ((dev->driver_info->flags & FLAG_WLAN) != 0)
1677 		SET_NETDEV_DEVTYPE(net, &wlan_type);
1678 	if ((dev->driver_info->flags & FLAG_WWAN) != 0)
1679 		SET_NETDEV_DEVTYPE(net, &wwan_type);
1680 
1681 	/* initialize max rx_qlen and tx_qlen */
1682 	usbnet_update_max_qlen(dev);
1683 
1684 	if (dev->can_dma_sg && !(info->flags & FLAG_SEND_ZLP) &&
1685 		!(info->flags & FLAG_MULTI_PACKET)) {
1686 		dev->padding_pkt = kzalloc(1, GFP_KERNEL);
1687 		if (!dev->padding_pkt) {
1688 			status = -ENOMEM;
1689 			goto out4;
1690 		}
1691 	}
1692 
1693 	status = register_netdev (net);
1694 	if (status)
1695 		goto out5;
1696 	netif_info(dev, probe, dev->net,
1697 		   "register '%s' at usb-%s-%s, %s, %pM\n",
1698 		   udev->dev.driver->name,
1699 		   xdev->bus->bus_name, xdev->devpath,
1700 		   dev->driver_info->description,
1701 		   net->dev_addr);
1702 
1703 	// ok, it's ready to go.
1704 	usb_set_intfdata (udev, dev);
1705 
1706 	netif_device_attach (net);
1707 
1708 	if (dev->driver_info->flags & FLAG_LINK_INTR)
1709 		usbnet_link_change(dev, 0, 0);
1710 
1711 	return 0;
1712 
1713 out5:
1714 	kfree(dev->padding_pkt);
1715 out4:
1716 	usb_free_urb(dev->interrupt);
1717 out3:
1718 	if (info->unbind)
1719 		info->unbind (dev, udev);
1720 out1:
1721 	free_netdev(net);
1722 out:
1723 	return status;
1724 }
1725 EXPORT_SYMBOL_GPL(usbnet_probe);
1726 
1727 /*-------------------------------------------------------------------------*/
1728 
1729 /*
1730  * suspend the whole driver as soon as the first interface is suspended
1731  * resume only when the last interface is resumed
1732  */
1733 
1734 int usbnet_suspend (struct usb_interface *intf, pm_message_t message)
1735 {
1736 	struct usbnet		*dev = usb_get_intfdata(intf);
1737 
1738 	if (!dev->suspend_count++) {
1739 		spin_lock_irq(&dev->txq.lock);
1740 		/* don't autosuspend while transmitting */
1741 		if (dev->txq.qlen && PMSG_IS_AUTO(message)) {
1742 			dev->suspend_count--;
1743 			spin_unlock_irq(&dev->txq.lock);
1744 			return -EBUSY;
1745 		} else {
1746 			set_bit(EVENT_DEV_ASLEEP, &dev->flags);
1747 			spin_unlock_irq(&dev->txq.lock);
1748 		}
1749 		/*
1750 		 * accelerate emptying of the rx and queues, to avoid
1751 		 * having everything error out.
1752 		 */
1753 		netif_device_detach (dev->net);
1754 		usbnet_terminate_urbs(dev);
1755 		__usbnet_status_stop_force(dev);
1756 
1757 		/*
1758 		 * reattach so runtime management can use and
1759 		 * wake the device
1760 		 */
1761 		netif_device_attach (dev->net);
1762 	}
1763 	return 0;
1764 }
1765 EXPORT_SYMBOL_GPL(usbnet_suspend);
1766 
1767 int usbnet_resume (struct usb_interface *intf)
1768 {
1769 	struct usbnet		*dev = usb_get_intfdata(intf);
1770 	struct sk_buff          *skb;
1771 	struct urb              *res;
1772 	int                     retval;
1773 
1774 	if (!--dev->suspend_count) {
1775 		/* resume interrupt URB if it was previously submitted */
1776 		__usbnet_status_start_force(dev, GFP_NOIO);
1777 
1778 		spin_lock_irq(&dev->txq.lock);
1779 		while ((res = usb_get_from_anchor(&dev->deferred))) {
1780 
1781 			skb = (struct sk_buff *)res->context;
1782 			retval = usb_submit_urb(res, GFP_ATOMIC);
1783 			if (retval < 0) {
1784 				dev_kfree_skb_any(skb);
1785 				kfree(res->sg);
1786 				usb_free_urb(res);
1787 				usb_autopm_put_interface_async(dev->intf);
1788 			} else {
1789 				dev->net->trans_start = jiffies;
1790 				__skb_queue_tail(&dev->txq, skb);
1791 			}
1792 		}
1793 
1794 		smp_mb();
1795 		clear_bit(EVENT_DEV_ASLEEP, &dev->flags);
1796 		spin_unlock_irq(&dev->txq.lock);
1797 
1798 		if (test_bit(EVENT_DEV_OPEN, &dev->flags)) {
1799 			/* handle remote wakeup ASAP */
1800 			if (!dev->wait &&
1801 				netif_device_present(dev->net) &&
1802 				!timer_pending(&dev->delay) &&
1803 				!test_bit(EVENT_RX_HALT, &dev->flags))
1804 					rx_alloc_submit(dev, GFP_NOIO);
1805 
1806 			if (!(dev->txq.qlen >= TX_QLEN(dev)))
1807 				netif_tx_wake_all_queues(dev->net);
1808 			tasklet_schedule (&dev->bh);
1809 		}
1810 	}
1811 
1812 	if (test_and_clear_bit(EVENT_DEVICE_REPORT_IDLE, &dev->flags))
1813 		usb_autopm_get_interface_no_resume(intf);
1814 
1815 	return 0;
1816 }
1817 EXPORT_SYMBOL_GPL(usbnet_resume);
1818 
1819 /*
1820  * Either a subdriver implements manage_power, then it is assumed to always
1821  * be ready to be suspended or it reports the readiness to be suspended
1822  * explicitly
1823  */
1824 void usbnet_device_suggests_idle(struct usbnet *dev)
1825 {
1826 	if (!test_and_set_bit(EVENT_DEVICE_REPORT_IDLE, &dev->flags)) {
1827 		dev->intf->needs_remote_wakeup = 1;
1828 		usb_autopm_put_interface_async(dev->intf);
1829 	}
1830 }
1831 EXPORT_SYMBOL(usbnet_device_suggests_idle);
1832 
1833 /*
1834  * For devices that can do without special commands
1835  */
1836 int usbnet_manage_power(struct usbnet *dev, int on)
1837 {
1838 	dev->intf->needs_remote_wakeup = on;
1839 	return 0;
1840 }
1841 EXPORT_SYMBOL(usbnet_manage_power);
1842 
1843 void usbnet_link_change(struct usbnet *dev, bool link, bool need_reset)
1844 {
1845 	/* update link after link is reseted */
1846 	if (link && !need_reset)
1847 		netif_carrier_on(dev->net);
1848 	else
1849 		netif_carrier_off(dev->net);
1850 
1851 	if (need_reset && link)
1852 		usbnet_defer_kevent(dev, EVENT_LINK_RESET);
1853 	else
1854 		usbnet_defer_kevent(dev, EVENT_LINK_CHANGE);
1855 }
1856 EXPORT_SYMBOL(usbnet_link_change);
1857 
1858 /*-------------------------------------------------------------------------*/
1859 static int __usbnet_read_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
1860 			     u16 value, u16 index, void *data, u16 size)
1861 {
1862 	void *buf = NULL;
1863 	int err = -ENOMEM;
1864 
1865 	netdev_dbg(dev->net, "usbnet_read_cmd cmd=0x%02x reqtype=%02x"
1866 		   " value=0x%04x index=0x%04x size=%d\n",
1867 		   cmd, reqtype, value, index, size);
1868 
1869 	if (data) {
1870 		buf = kmalloc(size, GFP_KERNEL);
1871 		if (!buf)
1872 			goto out;
1873 	}
1874 
1875 	err = usb_control_msg(dev->udev, usb_rcvctrlpipe(dev->udev, 0),
1876 			      cmd, reqtype, value, index, buf, size,
1877 			      USB_CTRL_GET_TIMEOUT);
1878 	if (err > 0 && err <= size)
1879 		memcpy(data, buf, err);
1880 	kfree(buf);
1881 out:
1882 	return err;
1883 }
1884 
1885 static int __usbnet_write_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
1886 			      u16 value, u16 index, const void *data,
1887 			      u16 size)
1888 {
1889 	void *buf = NULL;
1890 	int err = -ENOMEM;
1891 
1892 	netdev_dbg(dev->net, "usbnet_write_cmd cmd=0x%02x reqtype=%02x"
1893 		   " value=0x%04x index=0x%04x size=%d\n",
1894 		   cmd, reqtype, value, index, size);
1895 
1896 	if (data) {
1897 		buf = kmemdup(data, size, GFP_KERNEL);
1898 		if (!buf)
1899 			goto out;
1900 	}
1901 
1902 	err = usb_control_msg(dev->udev, usb_sndctrlpipe(dev->udev, 0),
1903 			      cmd, reqtype, value, index, buf, size,
1904 			      USB_CTRL_SET_TIMEOUT);
1905 	kfree(buf);
1906 
1907 out:
1908 	return err;
1909 }
1910 
1911 /*
1912  * The function can't be called inside suspend/resume callback,
1913  * otherwise deadlock will be caused.
1914  */
1915 int usbnet_read_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
1916 		    u16 value, u16 index, void *data, u16 size)
1917 {
1918 	int ret;
1919 
1920 	if (usb_autopm_get_interface(dev->intf) < 0)
1921 		return -ENODEV;
1922 	ret = __usbnet_read_cmd(dev, cmd, reqtype, value, index,
1923 				data, size);
1924 	usb_autopm_put_interface(dev->intf);
1925 	return ret;
1926 }
1927 EXPORT_SYMBOL_GPL(usbnet_read_cmd);
1928 
1929 /*
1930  * The function can't be called inside suspend/resume callback,
1931  * otherwise deadlock will be caused.
1932  */
1933 int usbnet_write_cmd(struct usbnet *dev, u8 cmd, u8 reqtype,
1934 		     u16 value, u16 index, const void *data, u16 size)
1935 {
1936 	int ret;
1937 
1938 	if (usb_autopm_get_interface(dev->intf) < 0)
1939 		return -ENODEV;
1940 	ret = __usbnet_write_cmd(dev, cmd, reqtype, value, index,
1941 				 data, size);
1942 	usb_autopm_put_interface(dev->intf);
1943 	return ret;
1944 }
1945 EXPORT_SYMBOL_GPL(usbnet_write_cmd);
1946 
1947 /*
1948  * The function can be called inside suspend/resume callback safely
1949  * and should only be called by suspend/resume callback generally.
1950  */
1951 int usbnet_read_cmd_nopm(struct usbnet *dev, u8 cmd, u8 reqtype,
1952 			  u16 value, u16 index, void *data, u16 size)
1953 {
1954 	return __usbnet_read_cmd(dev, cmd, reqtype, value, index,
1955 				 data, size);
1956 }
1957 EXPORT_SYMBOL_GPL(usbnet_read_cmd_nopm);
1958 
1959 /*
1960  * The function can be called inside suspend/resume callback safely
1961  * and should only be called by suspend/resume callback generally.
1962  */
1963 int usbnet_write_cmd_nopm(struct usbnet *dev, u8 cmd, u8 reqtype,
1964 			  u16 value, u16 index, const void *data,
1965 			  u16 size)
1966 {
1967 	return __usbnet_write_cmd(dev, cmd, reqtype, value, index,
1968 				  data, size);
1969 }
1970 EXPORT_SYMBOL_GPL(usbnet_write_cmd_nopm);
1971 
1972 static void usbnet_async_cmd_cb(struct urb *urb)
1973 {
1974 	struct usb_ctrlrequest *req = (struct usb_ctrlrequest *)urb->context;
1975 	int status = urb->status;
1976 
1977 	if (status < 0)
1978 		dev_dbg(&urb->dev->dev, "%s failed with %d",
1979 			__func__, status);
1980 
1981 	kfree(req);
1982 	usb_free_urb(urb);
1983 }
1984 
1985 /*
1986  * The caller must make sure that device can't be put into suspend
1987  * state until the control URB completes.
1988  */
1989 int usbnet_write_cmd_async(struct usbnet *dev, u8 cmd, u8 reqtype,
1990 			   u16 value, u16 index, const void *data, u16 size)
1991 {
1992 	struct usb_ctrlrequest *req = NULL;
1993 	struct urb *urb;
1994 	int err = -ENOMEM;
1995 	void *buf = NULL;
1996 
1997 	netdev_dbg(dev->net, "usbnet_write_cmd cmd=0x%02x reqtype=%02x"
1998 		   " value=0x%04x index=0x%04x size=%d\n",
1999 		   cmd, reqtype, value, index, size);
2000 
2001 	urb = usb_alloc_urb(0, GFP_ATOMIC);
2002 	if (!urb) {
2003 		netdev_err(dev->net, "Error allocating URB in"
2004 			   " %s!\n", __func__);
2005 		goto fail;
2006 	}
2007 
2008 	if (data) {
2009 		buf = kmemdup(data, size, GFP_ATOMIC);
2010 		if (!buf) {
2011 			netdev_err(dev->net, "Error allocating buffer"
2012 				   " in %s!\n", __func__);
2013 			goto fail_free;
2014 		}
2015 	}
2016 
2017 	req = kmalloc(sizeof(struct usb_ctrlrequest), GFP_ATOMIC);
2018 	if (!req)
2019 		goto fail_free_buf;
2020 
2021 	req->bRequestType = reqtype;
2022 	req->bRequest = cmd;
2023 	req->wValue = cpu_to_le16(value);
2024 	req->wIndex = cpu_to_le16(index);
2025 	req->wLength = cpu_to_le16(size);
2026 
2027 	usb_fill_control_urb(urb, dev->udev,
2028 			     usb_sndctrlpipe(dev->udev, 0),
2029 			     (void *)req, buf, size,
2030 			     usbnet_async_cmd_cb, req);
2031 	urb->transfer_flags |= URB_FREE_BUFFER;
2032 
2033 	err = usb_submit_urb(urb, GFP_ATOMIC);
2034 	if (err < 0) {
2035 		netdev_err(dev->net, "Error submitting the control"
2036 			   " message: status=%d\n", err);
2037 		goto fail_free;
2038 	}
2039 	return 0;
2040 
2041 fail_free_buf:
2042 	kfree(buf);
2043 fail_free:
2044 	kfree(req);
2045 	usb_free_urb(urb);
2046 fail:
2047 	return err;
2048 
2049 }
2050 EXPORT_SYMBOL_GPL(usbnet_write_cmd_async);
2051 /*-------------------------------------------------------------------------*/
2052 
2053 static int __init usbnet_init(void)
2054 {
2055 	/* Compiler should optimize this out. */
2056 	BUILD_BUG_ON(
2057 		FIELD_SIZEOF(struct sk_buff, cb) < sizeof(struct skb_data));
2058 
2059 	eth_random_addr(node_id);
2060 	return 0;
2061 }
2062 module_init(usbnet_init);
2063 
2064 static void __exit usbnet_exit(void)
2065 {
2066 }
2067 module_exit(usbnet_exit);
2068 
2069 MODULE_AUTHOR("David Brownell");
2070 MODULE_DESCRIPTION("USB network driver framework");
2071 MODULE_LICENSE("GPL");
2072