1 /*
2  * Copyright (c) 2014 Qualcomm Atheros, Inc.
3  *
4  * Permission to use, copy, modify, and/or distribute this software for any
5  * purpose with or without fee is hereby granted, provided that the above
6  * copyright notice and this permission notice appear in all copies.
7  *
8  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15  */
16 
17 #include "testmode.h"
18 
19 #include <net/netlink.h>
20 #include <linux/firmware.h>
21 
22 #include "debug.h"
23 #include "wmi.h"
24 #include "hif.h"
25 #include "hw.h"
26 
27 #include "testmode_i.h"
28 
29 static const struct nla_policy ath10k_tm_policy[ATH10K_TM_ATTR_MAX + 1] = {
30 	[ATH10K_TM_ATTR_CMD]		= { .type = NLA_U32 },
31 	[ATH10K_TM_ATTR_DATA]		= { .type = NLA_BINARY,
32 					    .len = ATH10K_TM_DATA_MAX_LEN },
33 	[ATH10K_TM_ATTR_WMI_CMDID]	= { .type = NLA_U32 },
34 	[ATH10K_TM_ATTR_VERSION_MAJOR]	= { .type = NLA_U32 },
35 	[ATH10K_TM_ATTR_VERSION_MINOR]	= { .type = NLA_U32 },
36 };
37 
38 /* Returns true if callee consumes the skb and the skb should be discarded.
39  * Returns false if skb is not used. Does not sleep.
40  */
41 bool ath10k_tm_event_wmi(struct ath10k *ar, u32 cmd_id, struct sk_buff *skb)
42 {
43 	struct sk_buff *nl_skb;
44 	bool consumed;
45 	int ret;
46 
47 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
48 		   "testmode event wmi cmd_id %d skb %p skb->len %d\n",
49 		   cmd_id, skb, skb->len);
50 
51 	ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", skb->data, skb->len);
52 
53 	spin_lock_bh(&ar->data_lock);
54 
55 	if (!ar->testmode.utf_monitor) {
56 		consumed = false;
57 		goto out;
58 	}
59 
60 	/* Only testmode.c should be handling events from utf firmware,
61 	 * otherwise all sort of problems will arise as mac80211 operations
62 	 * are not initialised.
63 	 */
64 	consumed = true;
65 
66 	nl_skb = cfg80211_testmode_alloc_event_skb(ar->hw->wiphy,
67 						   2 * sizeof(u32) + skb->len,
68 						   GFP_ATOMIC);
69 	if (!nl_skb) {
70 		ath10k_warn(ar,
71 			    "failed to allocate skb for testmode wmi event\n");
72 		goto out;
73 	}
74 
75 	ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_CMD, ATH10K_TM_CMD_WMI);
76 	if (ret) {
77 		ath10k_warn(ar,
78 			    "failed to to put testmode wmi event cmd attribute: %d\n",
79 			    ret);
80 		kfree_skb(nl_skb);
81 		goto out;
82 	}
83 
84 	ret = nla_put_u32(nl_skb, ATH10K_TM_ATTR_WMI_CMDID, cmd_id);
85 	if (ret) {
86 		ath10k_warn(ar,
87 			    "failed to to put testmode wmi even cmd_id: %d\n",
88 			    ret);
89 		kfree_skb(nl_skb);
90 		goto out;
91 	}
92 
93 	ret = nla_put(nl_skb, ATH10K_TM_ATTR_DATA, skb->len, skb->data);
94 	if (ret) {
95 		ath10k_warn(ar,
96 			    "failed to copy skb to testmode wmi event: %d\n",
97 			    ret);
98 		kfree_skb(nl_skb);
99 		goto out;
100 	}
101 
102 	cfg80211_testmode_event(nl_skb, GFP_ATOMIC);
103 
104 out:
105 	spin_unlock_bh(&ar->data_lock);
106 
107 	return consumed;
108 }
109 
110 static int ath10k_tm_cmd_get_version(struct ath10k *ar, struct nlattr *tb[])
111 {
112 	struct sk_buff *skb;
113 	int ret;
114 
115 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
116 		   "testmode cmd get version_major %d version_minor %d\n",
117 		   ATH10K_TESTMODE_VERSION_MAJOR,
118 		   ATH10K_TESTMODE_VERSION_MINOR);
119 
120 	skb = cfg80211_testmode_alloc_reply_skb(ar->hw->wiphy,
121 						nla_total_size(sizeof(u32)));
122 	if (!skb)
123 		return -ENOMEM;
124 
125 	ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MAJOR,
126 			  ATH10K_TESTMODE_VERSION_MAJOR);
127 	if (ret) {
128 		kfree_skb(skb);
129 		return ret;
130 	}
131 
132 	ret = nla_put_u32(skb, ATH10K_TM_ATTR_VERSION_MINOR,
133 			  ATH10K_TESTMODE_VERSION_MINOR);
134 	if (ret) {
135 		kfree_skb(skb);
136 		return ret;
137 	}
138 
139 	return cfg80211_testmode_reply(skb);
140 }
141 
142 static int ath10k_tm_cmd_utf_start(struct ath10k *ar, struct nlattr *tb[])
143 {
144 	char filename[100];
145 	int ret;
146 
147 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf start\n");
148 
149 	mutex_lock(&ar->conf_mutex);
150 
151 	if (ar->state == ATH10K_STATE_UTF) {
152 		ret = -EALREADY;
153 		goto err;
154 	}
155 
156 	/* start utf only when the driver is not in use  */
157 	if (ar->state != ATH10K_STATE_OFF) {
158 		ret = -EBUSY;
159 		goto err;
160 	}
161 
162 	if (WARN_ON(ar->testmode.utf != NULL)) {
163 		/* utf image is already downloaded, it shouldn't be */
164 		ret = -EEXIST;
165 		goto err;
166 	}
167 
168 	snprintf(filename, sizeof(filename), "%s/%s",
169 		 ar->hw_params.fw.dir, ATH10K_FW_UTF_FILE);
170 
171 	/* load utf firmware image */
172 	ret = request_firmware(&ar->testmode.utf, filename, ar->dev);
173 	if (ret) {
174 		ath10k_warn(ar, "failed to retrieve utf firmware '%s': %d\n",
175 			    filename, ret);
176 		goto err;
177 	}
178 
179 	spin_lock_bh(&ar->data_lock);
180 
181 	ar->testmode.utf_monitor = true;
182 
183 	spin_unlock_bh(&ar->data_lock);
184 
185 	BUILD_BUG_ON(sizeof(ar->fw_features) !=
186 		     sizeof(ar->testmode.orig_fw_features));
187 
188 	memcpy(ar->testmode.orig_fw_features, ar->fw_features,
189 	       sizeof(ar->fw_features));
190 
191 	/* utf.bin firmware image does not advertise firmware features. Do
192 	 * an ugly hack where we force the firmware features so that wmi.c
193 	 * will use the correct WMI interface.
194 	 */
195 	memset(ar->fw_features, 0, sizeof(ar->fw_features));
196 	__set_bit(ATH10K_FW_FEATURE_WMI_10X, ar->fw_features);
197 
198 	ret = ath10k_hif_power_up(ar);
199 	if (ret) {
200 		ath10k_err(ar, "failed to power up hif (testmode): %d\n", ret);
201 		ar->state = ATH10K_STATE_OFF;
202 		goto err_fw_features;
203 	}
204 
205 	ret = ath10k_core_start(ar, ATH10K_FIRMWARE_MODE_UTF);
206 	if (ret) {
207 		ath10k_err(ar, "failed to start core (testmode): %d\n", ret);
208 		ar->state = ATH10K_STATE_OFF;
209 		goto err_power_down;
210 	}
211 
212 	ar->state = ATH10K_STATE_UTF;
213 
214 	ath10k_info(ar, "UTF firmware started\n");
215 
216 	mutex_unlock(&ar->conf_mutex);
217 
218 	return 0;
219 
220 err_power_down:
221 	ath10k_hif_power_down(ar);
222 
223 err_fw_features:
224 	/* return the original firmware features */
225 	memcpy(ar->fw_features, ar->testmode.orig_fw_features,
226 	       sizeof(ar->fw_features));
227 
228 	release_firmware(ar->testmode.utf);
229 	ar->testmode.utf = NULL;
230 
231 err:
232 	mutex_unlock(&ar->conf_mutex);
233 
234 	return ret;
235 }
236 
237 static void __ath10k_tm_cmd_utf_stop(struct ath10k *ar)
238 {
239 	lockdep_assert_held(&ar->conf_mutex);
240 
241 	ath10k_core_stop(ar);
242 	ath10k_hif_power_down(ar);
243 
244 	spin_lock_bh(&ar->data_lock);
245 
246 	ar->testmode.utf_monitor = false;
247 
248 	spin_unlock_bh(&ar->data_lock);
249 
250 	/* return the original firmware features */
251 	memcpy(ar->fw_features, ar->testmode.orig_fw_features,
252 	       sizeof(ar->fw_features));
253 
254 	release_firmware(ar->testmode.utf);
255 	ar->testmode.utf = NULL;
256 
257 	ar->state = ATH10K_STATE_OFF;
258 }
259 
260 static int ath10k_tm_cmd_utf_stop(struct ath10k *ar, struct nlattr *tb[])
261 {
262 	int ret;
263 
264 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE, "testmode cmd utf stop\n");
265 
266 	mutex_lock(&ar->conf_mutex);
267 
268 	if (ar->state != ATH10K_STATE_UTF) {
269 		ret = -ENETDOWN;
270 		goto out;
271 	}
272 
273 	__ath10k_tm_cmd_utf_stop(ar);
274 
275 	ret = 0;
276 
277 	ath10k_info(ar, "UTF firmware stopped\n");
278 
279 out:
280 	mutex_unlock(&ar->conf_mutex);
281 	return ret;
282 }
283 
284 static int ath10k_tm_cmd_wmi(struct ath10k *ar, struct nlattr *tb[])
285 {
286 	struct sk_buff *skb;
287 	int ret, buf_len;
288 	u32 cmd_id;
289 	void *buf;
290 
291 	mutex_lock(&ar->conf_mutex);
292 
293 	if (ar->state != ATH10K_STATE_UTF) {
294 		ret = -ENETDOWN;
295 		goto out;
296 	}
297 
298 	if (!tb[ATH10K_TM_ATTR_DATA]) {
299 		ret = -EINVAL;
300 		goto out;
301 	}
302 
303 	if (!tb[ATH10K_TM_ATTR_WMI_CMDID]) {
304 		ret = -EINVAL;
305 		goto out;
306 	}
307 
308 	buf = nla_data(tb[ATH10K_TM_ATTR_DATA]);
309 	buf_len = nla_len(tb[ATH10K_TM_ATTR_DATA]);
310 	cmd_id = nla_get_u32(tb[ATH10K_TM_ATTR_WMI_CMDID]);
311 
312 	ath10k_dbg(ar, ATH10K_DBG_TESTMODE,
313 		   "testmode cmd wmi cmd_id %d buf %p buf_len %d\n",
314 		   cmd_id, buf, buf_len);
315 
316 	ath10k_dbg_dump(ar, ATH10K_DBG_TESTMODE, NULL, "", buf, buf_len);
317 
318 	skb = ath10k_wmi_alloc_skb(ar, buf_len);
319 	if (!skb) {
320 		ret = -ENOMEM;
321 		goto out;
322 	}
323 
324 	memcpy(skb->data, buf, buf_len);
325 
326 	ret = ath10k_wmi_cmd_send(ar, skb, cmd_id);
327 	if (ret) {
328 		ath10k_warn(ar, "failed to transmit wmi command (testmode): %d\n",
329 			    ret);
330 		goto out;
331 	}
332 
333 	ret = 0;
334 
335 out:
336 	mutex_unlock(&ar->conf_mutex);
337 	return ret;
338 }
339 
340 int ath10k_tm_cmd(struct ieee80211_hw *hw, struct ieee80211_vif *vif,
341 		  void *data, int len)
342 {
343 	struct ath10k *ar = hw->priv;
344 	struct nlattr *tb[ATH10K_TM_ATTR_MAX + 1];
345 	int ret;
346 
347 	ret = nla_parse(tb, ATH10K_TM_ATTR_MAX, data, len,
348 			ath10k_tm_policy);
349 	if (ret)
350 		return ret;
351 
352 	if (!tb[ATH10K_TM_ATTR_CMD])
353 		return -EINVAL;
354 
355 	switch (nla_get_u32(tb[ATH10K_TM_ATTR_CMD])) {
356 	case ATH10K_TM_CMD_GET_VERSION:
357 		return ath10k_tm_cmd_get_version(ar, tb);
358 	case ATH10K_TM_CMD_UTF_START:
359 		return ath10k_tm_cmd_utf_start(ar, tb);
360 	case ATH10K_TM_CMD_UTF_STOP:
361 		return ath10k_tm_cmd_utf_stop(ar, tb);
362 	case ATH10K_TM_CMD_WMI:
363 		return ath10k_tm_cmd_wmi(ar, tb);
364 	default:
365 		return -EOPNOTSUPP;
366 	}
367 }
368 
369 void ath10k_testmode_destroy(struct ath10k *ar)
370 {
371 	mutex_lock(&ar->conf_mutex);
372 
373 	if (ar->state != ATH10K_STATE_UTF) {
374 		/* utf firmware is not running, nothing to do */
375 		goto out;
376 	}
377 
378 	__ath10k_tm_cmd_utf_stop(ar);
379 
380 out:
381 	mutex_unlock(&ar->conf_mutex);
382 }
383