1 // SPDX-License-Identifier: ISC
2 /*
3  * Copyright (c) 2014-2017 Qualcomm Atheros, Inc.
4  */
5 
6 #include "testmode.h"
7 
8 #include <net/netlink.h>
9 #include <linux/firmware.h>
10 
11 #include "debug.h"
12 #include "wmi.h"
13 #include "hif.h"
14 #include "hw.h"
15 #include "core.h"
16 
17 #include "testmode_i.h"
18 
19 static const struct nla_policy ath10k_tm_policy[ATH10K_TM_ATTR_MAX + 1] = {
20 	[ATH10K_TM_ATTR_CMD]		= { .type = NLA_U32 },
21 	[ATH10K_TM_ATTR_DATA]		= { .type = NLA_BINARY,
22 					    .len = ATH10K_TM_DATA_MAX_LEN },
23 	[ATH10K_TM_ATTR_WMI_CMDID]	= { .type = NLA_U32 },
24 	[ATH10K_TM_ATTR_VERSION_MAJOR]	= { .type = NLA_U32 },
25 	[ATH10K_TM_ATTR_VERSION_MINOR]	= { .type = NLA_U32 },
26 };
27 
28 /* Returns true if callee consumes the skb and the skb should be discarded.
29  * Returns false if skb is not used. Does not sleep.
30  */
31 bool ath10k_tm_event_wmi(struct ath10k *ar, u32 cmd_id, struct sk_buff *skb)
32 {
33 	struct sk_buff *nl_skb;
34 	bool consumed;
35 	int ret;
36 
37 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
38 		   "testmode event wmi cmd_id %d skb %pK skb->len %d\n",
39 		   cmd_id, skb, skb->len);
40 
41 	ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", skb->data, skb->len);
42 
43 	spin_lock_bh(&ar->data_lock);
44 
45 	if (!ar->testmode.utf_monitor) {
46 		consumed = false;
47 		goto out;
48 	}
49 
50 	/* Only testmode.c should be handling events from utf firmware,
51 	 * otherwise all sort of problems will arise as mac80211 operations
52 	 * are not initialised.
53 	 */
54 	consumed = true;
55 
56 	nl_skb = cfg80211_testmode_alloc_event_skb(ar->hw->wiphy,
57 						   2 * sizeof(u32) + skb->len,
58 						   GFP_ATOMIC);
59 	if (!nl_skb) {
60 		ath10k_warn(ar,
61 			    "failed to allocate skb for testmode wmi event\n");
62 		goto out;
63 	}
64 
65 	ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_CMD, ATH10K_TM_CMD_WMI);
66 	if (ret) {
67 		ath10k_warn(ar,
68 			    "failed to to put testmode wmi event cmd attribute: %d\n",
69 			    ret);
70 		kfree_skb(nl_skb);
71 		goto out;
72 	}
73 
74 	ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_WMI_CMDID, cmd_id);
75 	if (ret) {
76 		ath10k_warn(ar,
77 			    "failed to to put testmode wmi even cmd_id: %d\n",
78 			    ret);
79 		kfree_skb(nl_skb);
80 		goto out;
81 	}
82 
83 	ret = nla_put(nl_skb, ATH10K_TM_ATTR_DATA, skb->len, skb->data);
84 	if (ret) {
85 		ath10k_warn(ar,
86 			    "failed to copy skb to testmode wmi event: %d\n",
87 			    ret);
88 		kfree_skb(nl_skb);
89 		goto out;
90 	}
91 
92 	cfg80211_testmode_event(nl_skb, GFP_ATOMIC);
93 
94 out:
95 	spin_unlock_bh(&ar->data_lock);
96 
97 	return consumed;
98 }
99 
100 static int ath10k_tm_cmd_get_version(struct ath10k *ar, struct nlattr *tb[])
101 {
102 	struct sk_buff *skb;
103 	int ret;
104 
105 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
106 		   "testmode cmd get version_major %d version_minor %d\n",
107 		   ATH10K_TESTMODE_VERSION_MAJOR,
108 		   ATH10K_TESTMODE_VERSION_MINOR);
109 
110 	skb = cfg80211_testmode_alloc_reply_skb(ar->hw->wiphy,
111 						nla_total_size(sizeof(u32)));
112 	if (!skb)
113 		return -ENOMEM;
114 
115 	ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MAJOR,
116 			  ATH10K_TESTMODE_VERSION_MAJOR);
117 	if (ret) {
118 		kfree_skb(skb);
119 		return ret;
120 	}
121 
122 	ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MINOR,
123 			  ATH10K_TESTMODE_VERSION_MINOR);
124 	if (ret) {
125 		kfree_skb(skb);
126 		return ret;
127 	}
128 
129 	ret = nla_put_u32(skb, ATH10K_TM_ATTR_WMI_OP_VERSION,
130 			  ar->normal_mode_fw.fw_file.wmi_op_version);
131 	if (ret) {
132 		kfree_skb(skb);
133 		return ret;
134 	}
135 
136 	return cfg80211_testmode_reply(skb);
137 }
138 
139 static int ath10k_tm_fetch_utf_firmware_api_1(struct ath10k *ar,
140 					      struct ath10k_fw_file *fw_file)
141 {
142 	char filename[100];
143 	int ret;
144 
145 	snprintf(filename, sizeof(filename), "%s/%s",
146 		 ar->hw_params.fw.dir, ATH10K_FW_UTF_FILE);
147 
148 	/* load utf firmware image */
149 	ret = firmware_request_nowarn(&fw_file->firmware, filename, ar->dev);
150 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode fw request '%s': %d\n",
151 		   filename, ret);
152 
153 	if (ret) {
154 		ath10k_warn(ar, "failed to retrieve utf firmware '%s': %d\n",
155 			    filename, ret);
156 		return ret;
157 	}
158 
159 	/* We didn't find FW UTF API 1 ("utf.bin") does not advertise
160 	 * firmware features. Do an ugly hack where we force the firmware
161 	 * features to match with 10.1 branch so that wmi.c will use the
162 	 * correct WMI interface.
163 	 */
164 
165 	fw_file->wmi_op_version = ATH10K_FW_WMI_OP_VERSION_10_1;
166 	fw_file->htt_op_version = ATH10K_FW_HTT_OP_VERSION_10_1;
167 	fw_file->firmware_data = fw_file->firmware->data;
168 	fw_file->firmware_len = fw_file->firmware->size;
169 
170 	return 0;
171 }
172 
173 static int ath10k_tm_fetch_firmware(struct ath10k *ar)
174 {
175 	struct ath10k_fw_components *utf_mode_fw;
176 	int ret;
177 
178 	ret = ath10k_core_fetch_firmware_api_n(ar, ATH10K_FW_UTF_API2_FILE,
179 					       &ar->testmode.utf_mode_fw.fw_file);
180 	if (ret == 0) {
181 		ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using fw utf api 2");
182 		goto out;
183 	}
184 
185 	ret = ath10k_tm_fetch_utf_firmware_api_1(ar, &ar->testmode.utf_mode_fw.fw_file);
186 	if (ret) {
187 		ath10k_err(ar, "failed to fetch utf firmware binary: %d", ret);
188 		return ret;
189 	}
190 
191 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode using utf api 1");
192 
193 out:
194 	utf_mode_fw = &ar->testmode.utf_mode_fw;
195 
196 	/* Use the same board data file as the normal firmware uses (but
197 	 * it's still "owned" by normal_mode_fw so we shouldn't free it.
198 	 */
199 	utf_mode_fw->board_data = ar->normal_mode_fw.board_data;
200 	utf_mode_fw->board_len = ar->normal_mode_fw.board_len;
201 
202 	if (!utf_mode_fw->fw_file.otp_data) {
203 		ath10k_info(ar, "utf.bin didn't contain otp binary, taking it from the normal mode firmware");
204 		utf_mode_fw->fw_file.otp_data = ar->normal_mode_fw.fw_file.otp_data;
205 		utf_mode_fw->fw_file.otp_len = ar->normal_mode_fw.fw_file.otp_len;
206 	}
207 
208 	return 0;
209 }
210 
211 static int ath10k_tm_cmd_utf_start(struct ath10k *ar, struct nlattr *tb[])
212 {
213 	const char *ver;
214 	int ret;
215 
216 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf start\n");
217 
218 	mutex_lock(&ar->conf_mutex);
219 
220 	if (ar->state == ATH10K_STATE_UTF) {
221 		ret = -EALREADY;
222 		goto err;
223 	}
224 
225 	/* start utf only when the driver is not in use  */
226 	if (ar->state != ATH10K_STATE_OFF) {
227 		ret = -EBUSY;
228 		goto err;
229 	}
230 
231 	if (WARN_ON(ar->testmode.utf_mode_fw.fw_file.firmware != NULL)) {
232 		/* utf image is already downloaded, it shouldn't be */
233 		ret = -EEXIST;
234 		goto err;
235 	}
236 
237 	ret = ath10k_tm_fetch_firmware(ar);
238 	if (ret) {
239 		ath10k_err(ar, "failed to fetch UTF firmware: %d", ret);
240 		goto err;
241 	}
242 
243 	if (ar->testmode.utf_mode_fw.fw_file.codeswap_data &&
244 	    ar->testmode.utf_mode_fw.fw_file.codeswap_len) {
245 		ret = ath10k_swap_code_seg_init(ar,
246 						&ar->testmode.utf_mode_fw.fw_file);
247 		if (ret) {
248 			ath10k_warn(ar,
249 				    "failed to init utf code swap segment: %d\n",
250 				    ret);
251 			goto err_release_utf_mode_fw;
252 		}
253 	}
254 
255 	spin_lock_bh(&ar->data_lock);
256 	ar->testmode.utf_monitor = true;
257 	spin_unlock_bh(&ar->data_lock);
258 
259 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode wmi version %d\n",
260 		   ar->testmode.utf_mode_fw.fw_file.wmi_op_version);
261 
262 	ret = ath10k_hif_power_up(ar, ATH10K_FIRMWARE_MODE_UTF);
263 	if (ret) {
264 		ath10k_err(ar, "failed to power up hif (testmode): %d\n", ret);
265 		ar->state = ATH10K_STATE_OFF;
266 		goto err_release_utf_mode_fw;
267 	}
268 
269 	ret = ath10k_core_start(ar, ATH10K_FIRMWARE_MODE_UTF,
270 				&ar->testmode.utf_mode_fw);
271 	if (ret) {
272 		ath10k_err(ar, "failed to start core (testmode): %d\n", ret);
273 		ar->state = ATH10K_STATE_OFF;
274 		goto err_power_down;
275 	}
276 
277 	ar->state = ATH10K_STATE_UTF;
278 
279 	if (strlen(ar->testmode.utf_mode_fw.fw_file.fw_version) > 0)
280 		ver = ar->testmode.utf_mode_fw.fw_file.fw_version;
281 	else
282 		ver = "API 1";
283 
284 	ath10k_info(ar, "UTF firmware %s started\n", ver);
285 
286 	mutex_unlock(&ar->conf_mutex);
287 
288 	return 0;
289 
290 err_power_down:
291 	ath10k_hif_power_down(ar);
292 
293 err_release_utf_mode_fw:
294 	if (ar->testmode.utf_mode_fw.fw_file.codeswap_data &&
295 	    ar->testmode.utf_mode_fw.fw_file.codeswap_len)
296 		ath10k_swap_code_seg_release(ar,
297 					     &ar->testmode.utf_mode_fw.fw_file);
298 
299 	release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware);
300 	ar->testmode.utf_mode_fw.fw_file.firmware = NULL;
301 
302 err:
303 	mutex_unlock(&ar->conf_mutex);
304 
305 	return ret;
306 }
307 
308 static void __ath10k_tm_cmd_utf_stop(struct ath10k *ar)
309 {
310 	lockdep_assert_held(&ar->conf_mutex);
311 
312 	ath10k_core_stop(ar);
313 	ath10k_hif_power_down(ar);
314 
315 	spin_lock_bh(&ar->data_lock);
316 
317 	ar->testmode.utf_monitor = false;
318 
319 	spin_unlock_bh(&ar->data_lock);
320 
321 	if (ar->testmode.utf_mode_fw.fw_file.codeswap_data &&
322 	    ar->testmode.utf_mode_fw.fw_file.codeswap_len)
323 		ath10k_swap_code_seg_release(ar,
324 					     &ar->testmode.utf_mode_fw.fw_file);
325 
326 	release_firmware(ar->testmode.utf_mode_fw.fw_file.firmware);
327 	ar->testmode.utf_mode_fw.fw_file.firmware = NULL;
328 
329 	ar->state = ATH10K_STATE_OFF;
330 }
331 
332 static int ath10k_tm_cmd_utf_stop(struct ath10k *ar, struct nlattr *tb[])
333 {
334 	int ret;
335 
336 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf stop\n");
337 
338 	mutex_lock(&ar->conf_mutex);
339 
340 	if (ar->state != ATH10K_STATE_UTF) {
341 		ret = -ENETDOWN;
342 		goto out;
343 	}
344 
345 	__ath10k_tm_cmd_utf_stop(ar);
346 
347 	ret = 0;
348 
349 	ath10k_info(ar, "UTF firmware stopped\n");
350 
351 out:
352 	mutex_unlock(&ar->conf_mutex);
353 	return ret;
354 }
355 
356 static int ath10k_tm_cmd_wmi(struct ath10k *ar, struct nlattr *tb[])
357 {
358 	struct sk_buff *skb;
359 	int ret, buf_len;
360 	u32 cmd_id;
361 	void *buf;
362 
363 	mutex_lock(&ar->conf_mutex);
364 
365 	if (ar->state != ATH10K_STATE_UTF) {
366 		ret = -ENETDOWN;
367 		goto out;
368 	}
369 
370 	if (!tb[ATH10K_TM_ATTR_DATA]) {
371 		ret = -EINVAL;
372 		goto out;
373 	}
374 
375 	if (!tb[ATH10K_TM_ATTR_WMI_CMDID]) {
376 		ret = -EINVAL;
377 		goto out;
378 	}
379 
380 	buf = nla_data(tb[ATH10K_TM_ATTR_DATA]);
381 	buf_len = nla_len(tb[ATH10K_TM_ATTR_DATA]);
382 	cmd_id = nla_get_u32(tb[ATH10K_TM_ATTR_WMI_CMDID]);
383 
384 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
385 		   "testmode cmd wmi cmd_id %d buf %pK buf_len %d\n",
386 		   cmd_id, buf, buf_len);
387 
388 	ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", buf, buf_len);
389 
390 	skb = ath10k_wmi_alloc_skb(ar, buf_len);
391 	if (!skb) {
392 		ret = -ENOMEM;
393 		goto out;
394 	}
395 
396 	memcpy(skb->data, buf, buf_len);
397 
398 	ret = ath10k_wmi_cmd_send(ar, skb, cmd_id);
399 	if (ret) {
400 		ath10k_warn(ar, "failed to transmit wmi command (testmode): %d\n",
401 			    ret);
402 		goto out;
403 	}
404 
405 	ret = 0;
406 
407 out:
408 	mutex_unlock(&ar->conf_mutex);
409 	return ret;
410 }
411 
412 int ath10k_tm_cmd(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
413 		  void *data, int len)
414 {
415 	struct ath10k *ar = hw->priv;
416 	struct nlattr *tb[ATH10K_TM_ATTR_MAX + 1];
417 	int ret;
418 
419 	ret = nla_parse(tb, ATH10K_TM_ATTR_MAX, data, len, ath10k_tm_policy,
420 			NULL);
421 	if (ret)
422 		return ret;
423 
424 	if (!tb[ATH10K_TM_ATTR_CMD])
425 		return -EINVAL;
426 
427 	switch (nla_get_u32(tb[ATH10K_TM_ATTR_CMD])) {
428 	case ATH10K_TM_CMD_GET_VERSION:
429 		return ath10k_tm_cmd_get_version(ar, tb);
430 	case ATH10K_TM_CMD_UTF_START:
431 		return ath10k_tm_cmd_utf_start(ar, tb);
432 	case ATH10K_TM_CMD_UTF_STOP:
433 		return ath10k_tm_cmd_utf_stop(ar, tb);
434 	case ATH10K_TM_CMD_WMI:
435 		return ath10k_tm_cmd_wmi(ar, tb);
436 	default:
437 		return -EOPNOTSUPP;
438 	}
439 }
440 
441 void ath10k_testmode_destroy(struct ath10k *ar)
442 {
443 	mutex_lock(&ar->conf_mutex);
444 
445 	if (ar->state != ATH10K_STATE_UTF) {
446 		/* utf firmware is not running, nothing to do */
447 		goto out;
448 	}
449 
450 	__ath10k_tm_cmd_utf_stop(ar);
451 
452 out:
453 	mutex_unlock(&ar->conf_mutex);
454 }
455