12865d42cSLarry Finger /******************************************************************************
22865d42cSLarry Finger  * rtl8712_cmd.c
32865d42cSLarry Finger  *
42865d42cSLarry Finger  * Copyright(c) 2007 - 2010 Realtek Corporation. All rights reserved.
52865d42cSLarry Finger  * Linux device driver for RTL8192SU
62865d42cSLarry Finger  *
72865d42cSLarry Finger  * This program is free software; you can redistribute it and/or modify it
82865d42cSLarry Finger  * under the terms of version 2 of the GNU General Public License as
92865d42cSLarry Finger  * published by the Free Software Foundation.
102865d42cSLarry Finger  *
112865d42cSLarry Finger  * This program is distributed in the hope that it will be useful, but WITHOUT
122865d42cSLarry Finger  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
132865d42cSLarry Finger  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
142865d42cSLarry Finger  * more details.
152865d42cSLarry Finger  *
162865d42cSLarry Finger  * You should have received a copy of the GNU General Public License along with
172865d42cSLarry Finger  * this program; if not, write to the Free Software Foundation, Inc.,
182865d42cSLarry Finger  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
192865d42cSLarry Finger  *
202865d42cSLarry Finger  * Modifications for inclusion into the Linux staging tree are
212865d42cSLarry Finger  * Copyright(c) 2010 Larry Finger. All rights reserved.
222865d42cSLarry Finger  *
232865d42cSLarry Finger  * Contact information:
242865d42cSLarry Finger  * WLAN FAE <wlanfae@realtek.com>.
252865d42cSLarry Finger  * Larry Finger <Larry.Finger@lwfinger.net>
262865d42cSLarry Finger  *
272865d42cSLarry Finger  ******************************************************************************/
282865d42cSLarry Finger 
292865d42cSLarry Finger #define _RTL8712_CMD_C_
302865d42cSLarry Finger 
312865d42cSLarry Finger #include "osdep_service.h"
322865d42cSLarry Finger #include "drv_types.h"
332865d42cSLarry Finger #include "recv_osdep.h"
342865d42cSLarry Finger #include "mlme_osdep.h"
352865d42cSLarry Finger #include "rtl871x_byteorder.h"
362865d42cSLarry Finger #include "rtl871x_ioctl_set.h"
372865d42cSLarry Finger 
382865d42cSLarry Finger static void check_hw_pbc(struct _adapter *padapter)
392865d42cSLarry Finger {
402865d42cSLarry Finger 	u8	tmp1byte;
412865d42cSLarry Finger 
422865d42cSLarry Finger 	r8712_write8(padapter, MAC_PINMUX_CTRL, (GPIOMUX_EN | GPIOSEL_GPIO));
432865d42cSLarry Finger 	tmp1byte = r8712_read8(padapter, GPIO_IO_SEL);
442865d42cSLarry Finger 	tmp1byte &= ~(HAL_8192S_HW_GPIO_WPS_BIT);
452865d42cSLarry Finger 	r8712_write8(padapter, GPIO_IO_SEL, tmp1byte);
462865d42cSLarry Finger 	tmp1byte = r8712_read8(padapter, GPIO_CTRL);
472865d42cSLarry Finger 	if (tmp1byte == 0xff)
482865d42cSLarry Finger 		return ;
492865d42cSLarry Finger 	if (tmp1byte&HAL_8192S_HW_GPIO_WPS_BIT) {
502865d42cSLarry Finger 		/* Here we only set bPbcPressed to true
512865d42cSLarry Finger 		 * After trigger PBC, the variable will be set to false */
522865d42cSLarry Finger 		DBG_8712("CheckPbcGPIO - PBC is pressed !!!!\n");
532865d42cSLarry Finger 		/* 0 is the default value and it means the application monitors
542865d42cSLarry Finger 		 * the HW PBC doesn't privde its pid to driver. */
552865d42cSLarry Finger 		if (padapter->pid == 0)
562865d42cSLarry Finger 			return;
572865d42cSLarry Finger 		kill_pid(find_vpid(padapter->pid), SIGUSR1, 1);
582865d42cSLarry Finger 	}
592865d42cSLarry Finger }
602865d42cSLarry Finger 
612865d42cSLarry Finger /* query rx phy status from fw.
622865d42cSLarry Finger  * Adhoc mode: beacon.
632865d42cSLarry Finger  * Infrastructure mode: beacon , data. */
642865d42cSLarry Finger static void query_fw_rx_phy_status(struct _adapter *padapter)
652865d42cSLarry Finger {
662865d42cSLarry Finger 	u32 val32 = 0;
672865d42cSLarry Finger 	int pollingcnts = 50;
682865d42cSLarry Finger 
692865d42cSLarry Finger 	if (check_fwstate(&padapter->mlmepriv, _FW_LINKED) == true) {
702865d42cSLarry Finger 		r8712_write32(padapter, IOCMD_CTRL_REG, 0xf4000001);
712865d42cSLarry Finger 		msleep(100);
722865d42cSLarry Finger 		/* Wait FW complete IO Cmd */
732865d42cSLarry Finger 		while ((r8712_read32(padapter, IOCMD_CTRL_REG)) &&
742865d42cSLarry Finger 		       (pollingcnts > 0)) {
752865d42cSLarry Finger 			pollingcnts--;
762865d42cSLarry Finger 			msleep(20);
772865d42cSLarry Finger 		}
782865d42cSLarry Finger 		if (pollingcnts != 0)
792865d42cSLarry Finger 			val32 = r8712_read32(padapter, IOCMD_DATA_REG);
802865d42cSLarry Finger 		else /* time out */
812865d42cSLarry Finger 			val32 = 0;
822865d42cSLarry Finger 		val32 = val32 >> 4;
832865d42cSLarry Finger 		padapter->recvpriv.fw_rssi =
842865d42cSLarry Finger 			 (u8)r8712_signal_scale_mapping(val32);
852865d42cSLarry Finger 	}
862865d42cSLarry Finger }
872865d42cSLarry Finger 
882865d42cSLarry Finger /* check mlme, hw, phy, or dynamic algorithm status. */
892865d42cSLarry Finger static void StatusWatchdogCallback(struct _adapter *padapter)
902865d42cSLarry Finger {
912865d42cSLarry Finger 	check_hw_pbc(padapter);
922865d42cSLarry Finger 	query_fw_rx_phy_status(padapter);
932865d42cSLarry Finger }
942865d42cSLarry Finger 
952865d42cSLarry Finger static void r871x_internal_cmd_hdl(struct _adapter *padapter, u8 *pbuf)
962865d42cSLarry Finger {
972865d42cSLarry Finger 	struct drvint_cmd_parm *pdrvcmd;
982865d42cSLarry Finger 
992865d42cSLarry Finger 	if (!pbuf)
1002865d42cSLarry Finger 		return;
1012865d42cSLarry Finger 	pdrvcmd = (struct drvint_cmd_parm *)pbuf;
1022865d42cSLarry Finger 	switch (pdrvcmd->i_cid) {
1032865d42cSLarry Finger 	case WDG_WK_CID:
1042865d42cSLarry Finger 		StatusWatchdogCallback(padapter);
1052865d42cSLarry Finger 		break;
1062865d42cSLarry Finger 	default:
1072865d42cSLarry Finger 		break;
1082865d42cSLarry Finger 	}
1092865d42cSLarry Finger 	kfree(pdrvcmd->pbuf);
1102865d42cSLarry Finger }
1112865d42cSLarry Finger 
1122865d42cSLarry Finger static u8 read_macreg_hdl(struct _adapter *padapter, u8 *pbuf)
1132865d42cSLarry Finger {
1142865d42cSLarry Finger 	void (*pcmd_callback)(struct _adapter *dev, struct cmd_obj	*pcmd);
1152865d42cSLarry Finger 	struct cmd_obj *pcmd  = (struct cmd_obj *)pbuf;
1162865d42cSLarry Finger 
1172865d42cSLarry Finger 	/*  invoke cmd->callback function */
1182865d42cSLarry Finger 	pcmd_callback = cmd_callback[pcmd->cmdcode].callback;
1192865d42cSLarry Finger 	if (pcmd_callback == NULL)
1202865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
1212865d42cSLarry Finger 	else
1222865d42cSLarry Finger 		pcmd_callback(padapter, pcmd);
1232865d42cSLarry Finger 	return H2C_SUCCESS;
1242865d42cSLarry Finger }
1252865d42cSLarry Finger 
1262865d42cSLarry Finger static u8 write_macreg_hdl(struct _adapter *padapter, u8 *pbuf)
1272865d42cSLarry Finger {
1282865d42cSLarry Finger 	void (*pcmd_callback)(struct _adapter *dev, struct cmd_obj	*pcmd);
1292865d42cSLarry Finger 	struct cmd_obj *pcmd  = (struct cmd_obj *)pbuf;
1302865d42cSLarry Finger 
1312865d42cSLarry Finger 	/*  invoke cmd->callback function */
1322865d42cSLarry Finger 	pcmd_callback = cmd_callback[pcmd->cmdcode].callback;
1332865d42cSLarry Finger 	if (pcmd_callback == NULL)
1342865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
1352865d42cSLarry Finger 	else
1362865d42cSLarry Finger 		pcmd_callback(padapter, pcmd);
1372865d42cSLarry Finger 	return H2C_SUCCESS;
1382865d42cSLarry Finger }
1392865d42cSLarry Finger 
1402865d42cSLarry Finger static u8 read_bbreg_hdl(struct _adapter *padapter, u8 *pbuf)
1412865d42cSLarry Finger {
1422865d42cSLarry Finger 	u32 val;
1432865d42cSLarry Finger 	void (*pcmd_callback)(struct _adapter *dev, struct cmd_obj	*pcmd);
1442865d42cSLarry Finger 	struct readBB_parm *prdbbparm;
1452865d42cSLarry Finger 	struct cmd_obj *pcmd  = (struct cmd_obj *)pbuf;
1462865d42cSLarry Finger 
1472865d42cSLarry Finger 	prdbbparm = (struct readBB_parm *)pcmd->parmbuf;
1482865d42cSLarry Finger 	if (pcmd->rsp && pcmd->rspsz > 0)
1492865d42cSLarry Finger 		memcpy(pcmd->rsp, (u8 *)&val, pcmd->rspsz);
1502865d42cSLarry Finger 	pcmd_callback = cmd_callback[pcmd->cmdcode].callback;
1512865d42cSLarry Finger 	if (pcmd_callback == NULL)
1522865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
1532865d42cSLarry Finger 	else
1542865d42cSLarry Finger 		pcmd_callback(padapter, pcmd);
1552865d42cSLarry Finger 	return H2C_SUCCESS;
1562865d42cSLarry Finger }
1572865d42cSLarry Finger 
1582865d42cSLarry Finger static u8 write_bbreg_hdl(struct _adapter *padapter, u8 *pbuf)
1592865d42cSLarry Finger {
1602865d42cSLarry Finger 	void (*pcmd_callback)(struct _adapter *dev, struct cmd_obj *pcmd);
1612865d42cSLarry Finger 	struct writeBB_parm *pwritebbparm;
1622865d42cSLarry Finger 	struct cmd_obj *pcmd  = (struct cmd_obj *)pbuf;
1632865d42cSLarry Finger 
1642865d42cSLarry Finger 	pwritebbparm = (struct writeBB_parm *)pcmd->parmbuf;
1652865d42cSLarry Finger 	pcmd_callback = cmd_callback[pcmd->cmdcode].callback;
1662865d42cSLarry Finger 	if (pcmd_callback == NULL)
1672865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
1682865d42cSLarry Finger 	else
1692865d42cSLarry Finger 		pcmd_callback(padapter, pcmd);
1702865d42cSLarry Finger 	return H2C_SUCCESS;
1712865d42cSLarry Finger }
1722865d42cSLarry Finger 
1732865d42cSLarry Finger static u8 read_rfreg_hdl(struct _adapter *padapter, u8 *pbuf)
1742865d42cSLarry Finger {
1752865d42cSLarry Finger 	u32 val;
1762865d42cSLarry Finger 	void (*pcmd_callback)(struct _adapter *dev, struct cmd_obj *pcmd);
1772865d42cSLarry Finger 	struct readRF_parm *prdrfparm;
1782865d42cSLarry Finger 	struct cmd_obj *pcmd  = (struct cmd_obj *)pbuf;
1792865d42cSLarry Finger 
1802865d42cSLarry Finger 	prdrfparm = (struct readRF_parm *)pcmd->parmbuf;
1812865d42cSLarry Finger 	if (pcmd->rsp && pcmd->rspsz > 0)
1822865d42cSLarry Finger 		memcpy(pcmd->rsp, (u8 *)&val, pcmd->rspsz);
1832865d42cSLarry Finger 	pcmd_callback = cmd_callback[pcmd->cmdcode].callback;
1842865d42cSLarry Finger 	if (pcmd_callback == NULL)
1852865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
1862865d42cSLarry Finger 	else
1872865d42cSLarry Finger 		pcmd_callback(padapter, pcmd);
1882865d42cSLarry Finger 	return H2C_SUCCESS;
1892865d42cSLarry Finger }
1902865d42cSLarry Finger 
1912865d42cSLarry Finger static u8 write_rfreg_hdl(struct _adapter *padapter, u8 *pbuf)
1922865d42cSLarry Finger {
1932865d42cSLarry Finger 	void (*pcmd_callback)(struct _adapter *dev, struct cmd_obj *pcmd);
1942865d42cSLarry Finger 	struct writeRF_parm *pwriterfparm;
1952865d42cSLarry Finger 	struct cmd_obj *pcmd  = (struct cmd_obj *)pbuf;
1962865d42cSLarry Finger 
1972865d42cSLarry Finger 	pwriterfparm = (struct writeRF_parm *)pcmd->parmbuf;
1982865d42cSLarry Finger 	pcmd_callback = cmd_callback[pcmd->cmdcode].callback;
1992865d42cSLarry Finger 	if (pcmd_callback == NULL)
2002865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
2012865d42cSLarry Finger 	else
2022865d42cSLarry Finger 		pcmd_callback(padapter, pcmd);
2032865d42cSLarry Finger 	return H2C_SUCCESS;
2042865d42cSLarry Finger }
2052865d42cSLarry Finger 
2062865d42cSLarry Finger static u8 sys_suspend_hdl(struct _adapter *padapter, u8 *pbuf)
2072865d42cSLarry Finger {
2082865d42cSLarry Finger 	struct cmd_obj *pcmd  = (struct cmd_obj *)pbuf;
2092865d42cSLarry Finger 	struct usb_suspend_parm *psetusbsuspend;
2102865d42cSLarry Finger 
2112865d42cSLarry Finger 	psetusbsuspend = (struct usb_suspend_parm *)pcmd->parmbuf;
2122865d42cSLarry Finger 	r8712_free_cmd_obj(pcmd);
2132865d42cSLarry Finger 	return H2C_SUCCESS;
2142865d42cSLarry Finger }
2152865d42cSLarry Finger 
2162865d42cSLarry Finger static struct cmd_obj *cmd_hdl_filter(struct _adapter *padapter,
2172865d42cSLarry Finger 				      struct cmd_obj *pcmd)
2182865d42cSLarry Finger {
2192865d42cSLarry Finger 	struct cmd_obj *pcmd_r;
2202865d42cSLarry Finger 
2212865d42cSLarry Finger 	if (pcmd == NULL)
2222865d42cSLarry Finger 		return pcmd;
2232865d42cSLarry Finger 	pcmd_r = NULL;
2242865d42cSLarry Finger 
2252865d42cSLarry Finger 	switch (pcmd->cmdcode) {
2262865d42cSLarry Finger 	case GEN_CMD_CODE(_Read_MACREG):
2272865d42cSLarry Finger 		read_macreg_hdl(padapter, (u8 *)pcmd);
2282865d42cSLarry Finger 		pcmd_r = pcmd;
2292865d42cSLarry Finger 		break;
2302865d42cSLarry Finger 	case GEN_CMD_CODE(_Write_MACREG):
2312865d42cSLarry Finger 		write_macreg_hdl(padapter, (u8 *)pcmd);
2322865d42cSLarry Finger 		pcmd_r = pcmd;
2332865d42cSLarry Finger 		break;
2342865d42cSLarry Finger 	case GEN_CMD_CODE(_Read_BBREG):
2352865d42cSLarry Finger 		read_bbreg_hdl(padapter, (u8 *)pcmd);
2362865d42cSLarry Finger 		break;
2372865d42cSLarry Finger 	case GEN_CMD_CODE(_Write_BBREG):
2382865d42cSLarry Finger 		write_bbreg_hdl(padapter, (u8 *)pcmd);
2392865d42cSLarry Finger 		break;
2402865d42cSLarry Finger 	case GEN_CMD_CODE(_Read_RFREG):
2412865d42cSLarry Finger 		read_rfreg_hdl(padapter, (u8 *)pcmd);
2422865d42cSLarry Finger 		break;
2432865d42cSLarry Finger 	case GEN_CMD_CODE(_Write_RFREG):
2442865d42cSLarry Finger 		write_rfreg_hdl(padapter, (u8 *)pcmd);
2452865d42cSLarry Finger 		break;
2462865d42cSLarry Finger 	case GEN_CMD_CODE(_SetUsbSuspend):
2472865d42cSLarry Finger 		sys_suspend_hdl(padapter, (u8 *)pcmd);
2482865d42cSLarry Finger 		break;
2492865d42cSLarry Finger 	case GEN_CMD_CODE(_JoinBss):
2502865d42cSLarry Finger 		r8712_joinbss_reset(padapter);
2512865d42cSLarry Finger 		/* Before set JoinBss_CMD to FW, driver must ensure FW is in
2522865d42cSLarry Finger 		 * PS_MODE_ACTIVE. Directly write rpwm to radio on and assign
2532865d42cSLarry Finger 		 * new pwr_mode to Driver, instead of use workitem to change
2542865d42cSLarry Finger 		 * state. */
2552865d42cSLarry Finger 		if (padapter->pwrctrlpriv.pwr_mode > PS_MODE_ACTIVE) {
2562865d42cSLarry Finger 			padapter->pwrctrlpriv.pwr_mode = PS_MODE_ACTIVE;
2572865d42cSLarry Finger 			_enter_pwrlock(&(padapter->pwrctrlpriv.lock));
2582865d42cSLarry Finger 			r8712_set_rpwm(padapter, PS_STATE_S4);
2592865d42cSLarry Finger 			up(&(padapter->pwrctrlpriv.lock));
2602865d42cSLarry Finger 		}
2612865d42cSLarry Finger 		pcmd_r = pcmd;
2622865d42cSLarry Finger 		break;
2632865d42cSLarry Finger 	case _DRV_INT_CMD_:
2642865d42cSLarry Finger 		r871x_internal_cmd_hdl(padapter, pcmd->parmbuf);
2652865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
2662865d42cSLarry Finger 		pcmd_r = NULL;
2672865d42cSLarry Finger 		break;
2682865d42cSLarry Finger 	default:
2692865d42cSLarry Finger 		pcmd_r = pcmd;
2702865d42cSLarry Finger 		break;
2712865d42cSLarry Finger 	}
2722865d42cSLarry Finger 	return pcmd_r; /* if returning pcmd_r == NULL, pcmd must be free. */
2732865d42cSLarry Finger }
2742865d42cSLarry Finger 
2752865d42cSLarry Finger static u8 check_cmd_fifo(struct _adapter *padapter, uint sz)
2762865d42cSLarry Finger {
2772865d42cSLarry Finger 	u8 res = _SUCCESS;
2782865d42cSLarry Finger 	return res;
2792865d42cSLarry Finger }
2802865d42cSLarry Finger 
2812865d42cSLarry Finger u8 r8712_fw_cmd(struct _adapter *pAdapter, u32 cmd)
2822865d42cSLarry Finger {
2832865d42cSLarry Finger 	int pollingcnts = 50;
2842865d42cSLarry Finger 
2852865d42cSLarry Finger 	r8712_write32(pAdapter, IOCMD_CTRL_REG, cmd);
2862865d42cSLarry Finger 	msleep(100);
2872865d42cSLarry Finger 	while ((0 != r8712_read32(pAdapter, IOCMD_CTRL_REG)) &&
2882865d42cSLarry Finger 	       (pollingcnts > 0)) {
2892865d42cSLarry Finger 		pollingcnts--;
2902865d42cSLarry Finger 		msleep(20);
2912865d42cSLarry Finger 	}
2922865d42cSLarry Finger 	if (pollingcnts == 0)
2932865d42cSLarry Finger 		return false;
2942865d42cSLarry Finger 	return true;
2952865d42cSLarry Finger }
2962865d42cSLarry Finger 
2972865d42cSLarry Finger void r8712_fw_cmd_data(struct _adapter *pAdapter, u32 *value, u8 flag)
2982865d42cSLarry Finger {
2992865d42cSLarry Finger 	if (flag == 0)	/* set */
3002865d42cSLarry Finger 		r8712_write32(pAdapter, IOCMD_DATA_REG, *value);
3012865d42cSLarry Finger 	else		/* query */
3022865d42cSLarry Finger 		*value = r8712_read32(pAdapter, IOCMD_DATA_REG);
3032865d42cSLarry Finger }
3042865d42cSLarry Finger 
3052865d42cSLarry Finger int r8712_cmd_thread(void *context)
3062865d42cSLarry Finger {
3072865d42cSLarry Finger 	struct cmd_obj *pcmd;
3082865d42cSLarry Finger 	unsigned int cmdsz, wr_sz, *pcmdbuf, *prspbuf;
3092865d42cSLarry Finger 	struct tx_desc *pdesc;
3102865d42cSLarry Finger 	void (*pcmd_callback)(struct _adapter *dev, struct cmd_obj *pcmd);
3112865d42cSLarry Finger 	struct _adapter *padapter = (struct _adapter *)context;
3122865d42cSLarry Finger 	struct	cmd_priv	*pcmdpriv = &(padapter->cmdpriv);
3132865d42cSLarry Finger 
3142865d42cSLarry Finger 	thread_enter(padapter);
3152865d42cSLarry Finger 	while (1) {
3162865d42cSLarry Finger 		if ((_down_sema(&(pcmdpriv->cmd_queue_sema))) == _FAIL)
3172865d42cSLarry Finger 			break;
3182865d42cSLarry Finger 		if ((padapter->bDriverStopped == true) ||
3192865d42cSLarry Finger 		    (padapter->bSurpriseRemoved == true))
3202865d42cSLarry Finger 			break;
3212865d42cSLarry Finger 		if (r8712_register_cmd_alive(padapter) != _SUCCESS)
3222865d42cSLarry Finger 			continue;
3232865d42cSLarry Finger _next:
3242865d42cSLarry Finger 		pcmd = r8712_dequeue_cmd(&(pcmdpriv->cmd_queue));
3252865d42cSLarry Finger 		if (!(pcmd)) {
3262865d42cSLarry Finger 			r8712_unregister_cmd_alive(padapter);
3272865d42cSLarry Finger 			continue;
3282865d42cSLarry Finger 		}
3292865d42cSLarry Finger 		pcmdbuf = (unsigned int *)pcmdpriv->cmd_buf;
3302865d42cSLarry Finger 		prspbuf = (unsigned int *)pcmdpriv->rsp_buf;
3312865d42cSLarry Finger 		pdesc = (struct tx_desc *)pcmdbuf;
3322865d42cSLarry Finger 		memset(pdesc, 0, TXDESC_SIZE);
3332865d42cSLarry Finger 		pcmd = cmd_hdl_filter(padapter, pcmd);
3342865d42cSLarry Finger 		if (pcmd) { /* if pcmd != NULL, cmd will be handled by f/w */
3352865d42cSLarry Finger 			struct dvobj_priv *pdvobj = (struct dvobj_priv *)
3362865d42cSLarry Finger 						    &padapter->dvobjpriv;
3372865d42cSLarry Finger 			u8 blnPending = 0;
3382865d42cSLarry Finger 			pcmdpriv->cmd_issued_cnt++;
3392865d42cSLarry Finger 			cmdsz = _RND8((pcmd->cmdsz)); /* _RND8	*/
3402865d42cSLarry Finger 			wr_sz = TXDESC_SIZE + 8 + cmdsz;
3412865d42cSLarry Finger 			pdesc->txdw0 |= cpu_to_le32((wr_sz-TXDESC_SIZE) &
3422865d42cSLarry Finger 						     0x0000ffff);
3432865d42cSLarry Finger 			if (pdvobj->ishighspeed) {
3442865d42cSLarry Finger 				if ((wr_sz % 512) == 0)
3452865d42cSLarry Finger 					blnPending = 1;
3462865d42cSLarry Finger 			} else {
3472865d42cSLarry Finger 				if ((wr_sz % 64) == 0)
3482865d42cSLarry Finger 					blnPending = 1;
3492865d42cSLarry Finger 			}
3502865d42cSLarry Finger 			if (blnPending) /* 32 bytes for TX Desc - 8 offset */
3512865d42cSLarry Finger 				pdesc->txdw0 |= cpu_to_le32(((TXDESC_SIZE +
3522865d42cSLarry Finger 						OFFSET_SZ + 8) << OFFSET_SHT) &
3532865d42cSLarry Finger 						0x00ff0000);
3542865d42cSLarry Finger 			else {
3552865d42cSLarry Finger 				pdesc->txdw0 |= cpu_to_le32(((TXDESC_SIZE +
3562865d42cSLarry Finger 							      OFFSET_SZ) <<
3572865d42cSLarry Finger 							      OFFSET_SHT) &
3582865d42cSLarry Finger 							      0x00ff0000);
3592865d42cSLarry Finger 			}
3602865d42cSLarry Finger 			pdesc->txdw0 |= cpu_to_le32(OWN | FSG | LSG);
3612865d42cSLarry Finger 			pdesc->txdw1 |= cpu_to_le32((0x13 << QSEL_SHT) &
3622865d42cSLarry Finger 						    0x00001f00);
3632865d42cSLarry Finger 			pcmdbuf += (TXDESC_SIZE >> 2);
3642865d42cSLarry Finger 			*pcmdbuf = cpu_to_le32((cmdsz & 0x0000ffff) |
3652865d42cSLarry Finger 					       (pcmd->cmdcode << 16) |
3662865d42cSLarry Finger 					       (pcmdpriv->cmd_seq << 24));
3672865d42cSLarry Finger 			pcmdbuf += 2 ; /* 8 bytes aligment */
3682865d42cSLarry Finger 			memcpy((u8 *)pcmdbuf, pcmd->parmbuf, pcmd->cmdsz);
3692865d42cSLarry Finger 			while (check_cmd_fifo(padapter, wr_sz) == _FAIL) {
3702865d42cSLarry Finger 				if ((padapter->bDriverStopped == true) ||
3712865d42cSLarry Finger 				    (padapter->bSurpriseRemoved == true))
3722865d42cSLarry Finger 					break;
3732865d42cSLarry Finger 				msleep(100);
3742865d42cSLarry Finger 				continue;
3752865d42cSLarry Finger 			}
3762865d42cSLarry Finger 			if (blnPending)
3772865d42cSLarry Finger 				wr_sz += 8;   /* Append 8 bytes */
3782865d42cSLarry Finger 			r8712_write_mem(padapter, RTL8712_DMA_H2CCMD, wr_sz,
3792865d42cSLarry Finger 				       (u8 *)pdesc);
3802865d42cSLarry Finger 			pcmdpriv->cmd_seq++;
3812865d42cSLarry Finger 			if (pcmd->cmdcode == GEN_CMD_CODE(_CreateBss)) {
3822865d42cSLarry Finger 				pcmd->res = H2C_SUCCESS;
3832865d42cSLarry Finger 				pcmd_callback = cmd_callback[pcmd->
3842865d42cSLarry Finger 						cmdcode].callback;
3852865d42cSLarry Finger 				if (pcmd_callback)
3862865d42cSLarry Finger 					pcmd_callback(padapter, pcmd);
3872865d42cSLarry Finger 				continue;
3882865d42cSLarry Finger 			}
3892865d42cSLarry Finger 			if (pcmd->cmdcode == GEN_CMD_CODE(_SetPwrMode)) {
3902865d42cSLarry Finger 				if (padapter->pwrctrlpriv.bSleep) {
3912865d42cSLarry Finger 					_enter_pwrlock(&(padapter->
3922865d42cSLarry Finger 						       pwrctrlpriv.lock));
3932865d42cSLarry Finger 					r8712_set_rpwm(padapter, PS_STATE_S2);
3942865d42cSLarry Finger 					up(&padapter->pwrctrlpriv.lock);
3952865d42cSLarry Finger 				}
3962865d42cSLarry Finger 			}
3972865d42cSLarry Finger 			r8712_free_cmd_obj(pcmd);
3982865d42cSLarry Finger 			if (_queue_empty(&(pcmdpriv->cmd_queue))) {
3992865d42cSLarry Finger 				r8712_unregister_cmd_alive(padapter);
4002865d42cSLarry Finger 				continue;
4012865d42cSLarry Finger 			} else
4022865d42cSLarry Finger 				goto _next;
4032865d42cSLarry Finger 		} else
4042865d42cSLarry Finger 			goto _next;
4052865d42cSLarry Finger 		flush_signals_thread();
4062865d42cSLarry Finger 	}
4072865d42cSLarry Finger 	/* free all cmd_obj resources */
4082865d42cSLarry Finger 	do {
4092865d42cSLarry Finger 		pcmd = r8712_dequeue_cmd(&(pcmdpriv->cmd_queue));
4102865d42cSLarry Finger 		if (pcmd == NULL)
4112865d42cSLarry Finger 			break;
4122865d42cSLarry Finger 		r8712_free_cmd_obj(pcmd);
4132865d42cSLarry Finger 	} while (1);
4142865d42cSLarry Finger 	up(&pcmdpriv->terminate_cmdthread_sema);
4152865d42cSLarry Finger 	thread_exit();
4162865d42cSLarry Finger }
4172865d42cSLarry Finger 
4182865d42cSLarry Finger void r8712_event_handle(struct _adapter *padapter, uint *peventbuf)
4192865d42cSLarry Finger {
4202865d42cSLarry Finger 	u8 evt_code, evt_seq;
4212865d42cSLarry Finger 	u16 evt_sz;
4222865d42cSLarry Finger 	void (*event_callback)(struct _adapter *dev, u8 *pbuf);
4232865d42cSLarry Finger 	struct	evt_priv *pevt_priv = &(padapter->evtpriv);
4242865d42cSLarry Finger 
4252865d42cSLarry Finger 	if (peventbuf == NULL)
4262865d42cSLarry Finger 		goto _abort_event_;
4272865d42cSLarry Finger 	evt_sz = (u16)(le32_to_cpu(*peventbuf) & 0xffff);
4282865d42cSLarry Finger 	evt_seq = (u8)((le32_to_cpu(*peventbuf) >> 24) & 0x7f);
4292865d42cSLarry Finger 	evt_code = (u8)((le32_to_cpu(*peventbuf) >> 16) & 0xff);
4302865d42cSLarry Finger 	/* checking event sequence... */
4312865d42cSLarry Finger 	if ((evt_seq & 0x7f) != pevt_priv->event_seq) {
4322865d42cSLarry Finger 		pevt_priv->event_seq = ((evt_seq + 1) & 0x7f);
4332865d42cSLarry Finger 		goto _abort_event_;
4342865d42cSLarry Finger 	}
4352865d42cSLarry Finger 	/* checking if event code is valid */
4362865d42cSLarry Finger 	if (evt_code >= MAX_C2HEVT) {
4372865d42cSLarry Finger 		pevt_priv->event_seq = ((evt_seq+1) & 0x7f);
4382865d42cSLarry Finger 		goto _abort_event_;
4392865d42cSLarry Finger 	} else if ((evt_code == GEN_EVT_CODE(_Survey)) &&
4402865d42cSLarry Finger 		   (evt_sz > sizeof(struct wlan_bssid_ex))) {
4412865d42cSLarry Finger 		pevt_priv->event_seq = ((evt_seq+1)&0x7f);
4422865d42cSLarry Finger 		goto _abort_event_;
4432865d42cSLarry Finger 	}
4442865d42cSLarry Finger 	/* checking if event size match the event parm size */
4452865d42cSLarry Finger 	if ((wlanevents[evt_code].parmsize) &&
4462865d42cSLarry Finger 	    (wlanevents[evt_code].parmsize != evt_sz)) {
4472865d42cSLarry Finger 		pevt_priv->event_seq = ((evt_seq+1)&0x7f);
4482865d42cSLarry Finger 		goto _abort_event_;
4492865d42cSLarry Finger 	} else if ((evt_sz == 0) && (evt_code != GEN_EVT_CODE(_WPS_PBC))) {
4502865d42cSLarry Finger 		pevt_priv->event_seq = ((evt_seq+1)&0x7f);
4512865d42cSLarry Finger 		goto _abort_event_;
4522865d42cSLarry Finger 	}
4532865d42cSLarry Finger 	pevt_priv->event_seq++;	/* update evt_seq */
4542865d42cSLarry Finger 	if (pevt_priv->event_seq > 127)
4552865d42cSLarry Finger 		pevt_priv->event_seq = 0;
4562865d42cSLarry Finger 	peventbuf = peventbuf + 2; /* move to event content, 8 bytes aligment */
4572865d42cSLarry Finger 	if (peventbuf) {
4582865d42cSLarry Finger 		event_callback = wlanevents[evt_code].event_callback;
4592865d42cSLarry Finger 		if (event_callback)
4602865d42cSLarry Finger 			event_callback(padapter, (u8 *)peventbuf);
4612865d42cSLarry Finger 	}
4622865d42cSLarry Finger 	pevt_priv->evt_done_cnt++;
4632865d42cSLarry Finger _abort_event_:
4642865d42cSLarry Finger 	return;
4652865d42cSLarry Finger }
466