1 /*
2  * Copyright (c) 2014 Qualcomm Atheros, Inc.
3  *
4  * Permission to use, copy, modify, and/or distribute this software for any
5  * purpose with or without fee is hereby granted, provided that the above
6  * copyright notice and this permission notice appear in all copies.
7  *
8  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15  */
16 
17 #include "testmode.h"
18 
19 #include <net/netlink.h>
20 #include <linux/firmware.h>
21 
22 #include "debug.h"
23 #include "wmi.h"
24 #include "hif.h"
25 #include "hw.h"
26 
27 #include "testmode_i.h"
28 
29 static const struct nla_policy ath10k_tm_policy[ATH10K_TM_ATTR_MAX + 1] = {
30 	[ATH10K_TM_ATTR_CMD]		= { .type = NLA_U32 },
31 	[ATH10K_TM_ATTR_DATA]		= { .type = NLA_BINARY,
32 					    .len = ATH10K_TM_DATA_MAX_LEN },
33 	[ATH10K_TM_ATTR_WMI_CMDID]	= { .type = NLA_U32 },
34 	[ATH10K_TM_ATTR_VERSION_MAJOR]	= { .type = NLA_U32 },
35 	[ATH10K_TM_ATTR_VERSION_MINOR]	= { .type = NLA_U32 },
36 };
37 
38 /* Returns true if callee consumes the skb and the skb should be discarded.
39  * Returns false if skb is not used. Does not sleep.
40  */
41 bool ath10k_tm_event_wmi(struct ath10k *ar, u32 cmd_id, struct sk_buff *skb)
42 {
43 	struct sk_buff *nl_skb;
44 	bool consumed;
45 	int ret;
46 
47 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
48 		   "testmode event wmi cmd_id %d skb %p skb->len %d\n",
49 		   cmd_id, skb, skb->len);
50 
51 	ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", skb->data, skb->len);
52 
53 	spin_lock_bh(&ar->data_lock);
54 
55 	if (!ar->testmode.utf_monitor) {
56 		consumed = false;
57 		goto out;
58 	}
59 
60 	/* Only testmode.c should be handling events from utf firmware,
61 	 * otherwise all sort of problems will arise as mac80211 operations
62 	 * are not initialised.
63 	 */
64 	consumed = true;
65 
66 	nl_skb = cfg80211_testmode_alloc_event_skb(ar->hw->wiphy,
67 						   2 * sizeof(u32) + skb->len,
68 						   GFP_ATOMIC);
69 	if (!nl_skb) {
70 		ath10k_warn(ar,
71 			    "failed to allocate skb for testmode wmi event\n");
72 		goto out;
73 	}
74 
75 	ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_CMD, ATH10K_TM_CMD_WMI);
76 	if (ret) {
77 		ath10k_warn(ar,
78 			    "failed to to put testmode wmi event cmd attribute: %d\n",
79 			    ret);
80 		kfree_skb(nl_skb);
81 		goto out;
82 	}
83 
84 	ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_WMI_CMDID, cmd_id);
85 	if (ret) {
86 		ath10k_warn(ar,
87 			    "failed to to put testmode wmi even cmd_id: %d\n",
88 			    ret);
89 		kfree_skb(nl_skb);
90 		goto out;
91 	}
92 
93 	ret = nla_put(nl_skb, ATH10K_TM_ATTR_DATA, skb->len, skb->data);
94 	if (ret) {
95 		ath10k_warn(ar,
96 			    "failed to copy skb to testmode wmi event: %d\n",
97 			    ret);
98 		kfree_skb(nl_skb);
99 		goto out;
100 	}
101 
102 	cfg80211_testmode_event(nl_skb, GFP_ATOMIC);
103 
104 out:
105 	spin_unlock_bh(&ar->data_lock);
106 
107 	return consumed;
108 }
109 
110 static int ath10k_tm_cmd_get_version(struct ath10k *ar, struct nlattr *tb[])
111 {
112 	struct sk_buff *skb;
113 	int ret;
114 
115 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
116 		   "testmode cmd get version_major %d version_minor %d\n",
117 		   ATH10K_TESTMODE_VERSION_MAJOR,
118 		   ATH10K_TESTMODE_VERSION_MINOR);
119 
120 	skb = cfg80211_testmode_alloc_reply_skb(ar->hw->wiphy,
121 						nla_total_size(sizeof(u32)));
122 	if (!skb)
123 		return -ENOMEM;
124 
125 	ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MAJOR,
126 			  ATH10K_TESTMODE_VERSION_MAJOR);
127 	if (ret) {
128 		kfree_skb(skb);
129 		return ret;
130 	}
131 
132 	ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MINOR,
133 			  ATH10K_TESTMODE_VERSION_MINOR);
134 	if (ret) {
135 		kfree_skb(skb);
136 		return ret;
137 	}
138 
139 	return cfg80211_testmode_reply(skb);
140 }
141 
142 static int ath10k_tm_fetch_utf_firmware_api_1(struct ath10k *ar,
143 					      struct ath10k_fw_file *fw_file)
144 {
145 	char filename[100];
146 	int ret;
147 
148 	snprintf(filename, sizeof(filename), "%s/%s",
149 		 ar->hw_params.fw.dir, ATH10K_FW_UTF_FILE);
150 
151 	/* load utf firmware image */
152 	ret = request_firmware(&fw_file->firmware, filename, ar->dev);
153 	if (ret) {
154 		ath10k_warn(ar, "failed to retrieve utf firmware '%s': %d\n",
155 			    filename, ret);
156 		return ret;
157 	}
158 
159 	/* We didn't find FW UTF API 1 ("utf.bin") does not advertise
160 	 * firmware features. Do an ugly hack where we force the firmware
161 	 * features to match with 10.1 branch so that wmi.c will use the
162 	 * correct WMI interface.
163 	 */
164 
165 	fw_file->wmi_op_version = ATH10K_FW_WMI_OP_VERSION_10_1;
166 	fw_file->htt_op_version = ATH10K_FW_HTT_OP_VERSION_10_1;
167 	fw_file->firmware_data = fw_file->firmware->data;
168 	fw_file->firmware_len = fw_file->firmware->size;
169 
170 	return 0;
171 }
172 
173 static int ath10k_tm_fetch_firmware(struct ath10k *ar)
174 {
175 	struct ath10k_fw_components *utf_mode_fw;
176 	int ret;
177 
178 	ret = ath10k_core_fetch_firmware_api_n(ar, ATH10K_FW_UTF_API2_FILE,
179 					       &ar->testmode.utf_mode_fw.fw_file);
180 	if (ret == 0) {
181 		ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using fw utf api 2");
182 		goto out;
183 	}
184 
185 	ret = ath10k_tm_fetch_utf_firmware_api_1(ar, &ar->testmode.utf_mode_fw.fw_file);
186 	if (ret) {
187 		ath10k_err(ar, "failed to fetch utf firmware binary: %d", ret);
188 		return ret;
189 	}
190 
191 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using utf api 1");
192 
193 out:
194 	utf_mode_fw = &ar->testmode.utf_mode_fw;
195 
196 	/* Use the same board data file as the normal firmware uses (but
197 	 * it's still "owned" by normal_mode_fw so we shouldn't free it.
198 	 */
199 	utf_mode_fw->board_data = ar->normal_mode_fw.board_data;
200 	utf_mode_fw->board_len = ar->normal_mode_fw.board_len;
201 
202 	if (!utf_mode_fw->fw_file.otp_data) {
203 		ath10k_info(ar, "utf.bin didn't contain otp binary, taking it from the normal mode firmware");
204 		utf_mode_fw->fw_file.otp_data = ar->normal_mode_fw.fw_file.otp_data;
205 		utf_mode_fw->fw_file.otp_len = ar->normal_mode_fw.fw_file.otp_len;
206 	}
207 
208 	return 0;
209 }
210 
211 static int ath10k_tm_cmd_utf_start(struct ath10k *ar, struct nlattr *tb[])
212 {
213 	const char *ver;
214 	int ret;
215 
216 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf start\n");
217 
218 	mutex_lock(&ar->conf_mutex);
219 
220 	if (ar->state == ATH10K_STATE_UTF) {
221 		ret = -EALREADY;
222 		goto err;
223 	}
224 
225 	/* start utf only when the driver is not in use  */
226 	if (ar->state != ATH10K_STATE_OFF) {
227 		ret = -EBUSY;
228 		goto err;
229 	}
230 
231 	if (WARN_ON(ar->testmode.utf_mode_fw.fw_file.firmware != NULL)) {
232 		/* utf image is already downloaded, it shouldn't be */
233 		ret = -EEXIST;
234 		goto err;
235 	}
236 
237 	ret = ath10k_tm_fetch_firmware(ar);
238 	if (ret) {
239 		ath10k_err(ar, "failed to fetch UTF firmware: %d", ret);
240 		goto err;
241 	}
242 
243 	spin_lock_bh(&ar->data_lock);
244 	ar->testmode.utf_monitor = true;
245 	spin_unlock_bh(&ar->data_lock);
246 
247 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode wmi version %d\n",
248 		   ar->testmode.utf_mode_fw.fw_file.wmi_op_version);
249 
250 	ret = ath10k_hif_power_up(ar);
251 	if (ret) {
252 		ath10k_err(ar, "failed to power up hif (testmode): %d\n", ret);
253 		ar->state = ATH10K_STATE_OFF;
254 		goto err_release_utf_mode_fw;
255 	}
256 
257 	ret = ath10k_core_start(ar, ATH10K_FIRMWARE_MODE_UTF,
258 				&ar->testmode.utf_mode_fw);
259 	if (ret) {
260 		ath10k_err(ar, "failed to start core (testmode): %d\n", ret);
261 		ar->state = ATH10K_STATE_OFF;
262 		goto err_power_down;
263 	}
264 
265 	ar->state = ATH10K_STATE_UTF;
266 
267 	if (strlen(ar->testmode.utf_mode_fw.fw_file.fw_version) > 0)
268 		ver = ar->testmode.utf_mode_fw.fw_file.fw_version;
269 	else
270 		ver = "API 1";
271 
272 	ath10k_info(ar, "UTF firmware %s started\n", ver);
273 
274 	mutex_unlock(&ar->conf_mutex);
275 
276 	return 0;
277 
278 err_power_down:
279 	ath10k_hif_power_down(ar);
280 
281 err_release_utf_mode_fw:
282 	release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware);
283 	ar->testmode.utf_mode_fw.fw_file.firmware = NULL;
284 
285 err:
286 	mutex_unlock(&ar->conf_mutex);
287 
288 	return ret;
289 }
290 
291 static void __ath10k_tm_cmd_utf_stop(struct ath10k *ar)
292 {
293 	lockdep_assert_held(&ar->conf_mutex);
294 
295 	ath10k_core_stop(ar);
296 	ath10k_hif_power_down(ar);
297 
298 	spin_lock_bh(&ar->data_lock);
299 
300 	ar->testmode.utf_monitor = false;
301 
302 	spin_unlock_bh(&ar->data_lock);
303 
304 	release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware);
305 	ar->testmode.utf_mode_fw.fw_file.firmware = NULL;
306 
307 	ar->state = ATH10K_STATE_OFF;
308 }
309 
310 static int ath10k_tm_cmd_utf_stop(struct ath10k *ar, struct nlattr *tb[])
311 {
312 	int ret;
313 
314 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf stop\n");
315 
316 	mutex_lock(&ar->conf_mutex);
317 
318 	if (ar->state != ATH10K_STATE_UTF) {
319 		ret = -ENETDOWN;
320 		goto out;
321 	}
322 
323 	__ath10k_tm_cmd_utf_stop(ar);
324 
325 	ret = 0;
326 
327 	ath10k_info(ar, "UTF firmware stopped\n");
328 
329 out:
330 	mutex_unlock(&ar->conf_mutex);
331 	return ret;
332 }
333 
334 static int ath10k_tm_cmd_wmi(struct ath10k *ar, struct nlattr *tb[])
335 {
336 	struct sk_buff *skb;
337 	int ret, buf_len;
338 	u32 cmd_id;
339 	void *buf;
340 
341 	mutex_lock(&ar->conf_mutex);
342 
343 	if (ar->state != ATH10K_STATE_UTF) {
344 		ret = -ENETDOWN;
345 		goto out;
346 	}
347 
348 	if (!tb[ATH10K_TM_ATTR_DATA]) {
349 		ret = -EINVAL;
350 		goto out;
351 	}
352 
353 	if (!tb[ATH10K_TM_ATTR_WMI_CMDID]) {
354 		ret = -EINVAL;
355 		goto out;
356 	}
357 
358 	buf = nla_data(tb[ATH10K_TM_ATTR_DATA]);
359 	buf_len = nla_len(tb[ATH10K_TM_ATTR_DATA]);
360 	cmd_id = nla_get_u32(tb[ATH10K_TM_ATTR_WMI_CMDID]);
361 
362 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
363 		   "testmode cmd wmi cmd_id %d buf %p buf_len %d\n",
364 		   cmd_id, buf, buf_len);
365 
366 	ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", buf, buf_len);
367 
368 	skb = ath10k_wmi_alloc_skb(ar, buf_len);
369 	if (!skb) {
370 		ret = -ENOMEM;
371 		goto out;
372 	}
373 
374 	memcpy(skb->data, buf, buf_len);
375 
376 	ret = ath10k_wmi_cmd_send(ar, skb, cmd_id);
377 	if (ret) {
378 		ath10k_warn(ar, "failed to transmit wmi command (testmode): %d\n",
379 			    ret);
380 		goto out;
381 	}
382 
383 	ret = 0;
384 
385 out:
386 	mutex_unlock(&ar->conf_mutex);
387 	return ret;
388 }
389 
390 int ath10k_tm_cmd(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
391 		  void *data, int len)
392 {
393 	struct ath10k *ar = hw->priv;
394 	struct nlattr *tb[ATH10K_TM_ATTR_MAX + 1];
395 	int ret;
396 
397 	ret = nla_parse(tb, ATH10K_TM_ATTR_MAX, data, len,
398 			ath10k_tm_policy);
399 	if (ret)
400 		return ret;
401 
402 	if (!tb[ATH10K_TM_ATTR_CMD])
403 		return -EINVAL;
404 
405 	switch (nla_get_u32(tb[ATH10K_TM_ATTR_CMD])) {
406 	case ATH10K_TM_CMD_GET_VERSION:
407 		return ath10k_tm_cmd_get_version(ar, tb);
408 	case ATH10K_TM_CMD_UTF_START:
409 		return ath10k_tm_cmd_utf_start(ar, tb);
410 	case ATH10K_TM_CMD_UTF_STOP:
411 		return ath10k_tm_cmd_utf_stop(ar, tb);
412 	case ATH10K_TM_CMD_WMI:
413 		return ath10k_tm_cmd_wmi(ar, tb);
414 	default:
415 		return -EOPNOTSUPP;
416 	}
417 }
418 
419 void ath10k_testmode_destroy(struct ath10k *ar)
420 {
421 	mutex_lock(&ar->conf_mutex);
422 
423 	if (ar->state != ATH10K_STATE_UTF) {
424 		/* utf firmware is not running, nothing to do */
425 		goto out;
426 	}
427 
428 	__ath10k_tm_cmd_utf_stop(ar);
429 
430 out:
431 	mutex_unlock(&ar->conf_mutex);
432 }
433