1 /*
2  * u_ether.c -- Ethernet-over-USB link layer utilities for Gadget stack
3  *
4  * Copyright (C) 2003-2005,2008 David Brownell
5  * Copyright (C) 2003-2004 Robert Schwebel, Benedikt Spranger
6  * Copyright (C) 2008 Nokia Corporation
7  *
8  * This program is free software; you can redistribute it and/or modify
9  * it under the terms of the GNU General Public License as published by
10  * the Free Software Foundation; either version 2 of the License, or
11  * (at your option) any later version.
12  */
13 
14 /* #define VERBOSE_DEBUG */
15 
16 #include <linux/kernel.h>
17 #include <linux/module.h>
18 #include <linux/gfp.h>
19 #include <linux/device.h>
20 #include <linux/ctype.h>
21 #include <linux/etherdevice.h>
22 #include <linux/ethtool.h>
23 #include <linux/if_vlan.h>
24 
25 #include "u_ether.h"
26 
27 
28 /*
29  * This component encapsulates the Ethernet link glue needed to provide
30  * one (!) network link through the USB gadget stack, normally "usb0".
31  *
32  * The control and data models are handled by the function driver which
33  * connects to this code; such as CDC Ethernet (ECM or EEM),
34  * "CDC Subset", or RNDIS.  That includes all descriptor and endpoint
35  * management.
36  *
37  * Link level addressing is handled by this component using module
38  * parameters; if no such parameters are provided, random link level
39  * addresses are used.  Each end of the link uses one address.  The
40  * host end address is exported in various ways, and is often recorded
41  * in configuration databases.
42  *
43  * The driver which assembles each configuration using such a link is
44  * responsible for ensuring that each configuration includes at most one
45  * instance of is network link.  (The network layer provides ways for
46  * this single "physical" link to be used by multiple virtual links.)
47  */
48 
49 #define UETH__VERSION	"29-May-2008"
50 
51 /* Experiments show that both Linux and Windows hosts allow up to 16k
52  * frame sizes. Set the max size to 15k+52 to prevent allocating 32k
53  * blocks and still have efficient handling. */
54 #define GETHER_MAX_ETH_FRAME_LEN 15412
55 
56 struct eth_dev {
57 	/* lock is held while accessing port_usb
58 	 */
59 	spinlock_t		lock;
60 	struct gether		*port_usb;
61 
62 	struct net_device	*net;
63 	struct usb_gadget	*gadget;
64 
65 	spinlock_t		req_lock;	/* guard {rx,tx}_reqs */
66 	struct list_head	tx_reqs, rx_reqs;
67 	atomic_t		tx_qlen;
68 
69 	struct sk_buff_head	rx_frames;
70 
71 	unsigned		qmult;
72 
73 	unsigned		header_len;
74 	struct sk_buff		*(*wrap)(struct gether *, struct sk_buff *skb);
75 	int			(*unwrap)(struct gether *,
76 						struct sk_buff *skb,
77 						struct sk_buff_head *list);
78 
79 	struct work_struct	work;
80 
81 	unsigned long		todo;
82 #define	WORK_RX_MEMORY		0
83 
84 	bool			zlp;
85 	bool			no_skb_reserve;
86 	u8			host_mac[ETH_ALEN];
87 	u8			dev_mac[ETH_ALEN];
88 };
89 
90 /*-------------------------------------------------------------------------*/
91 
92 #define RX_EXTRA	20	/* bytes guarding against rx overflows */
93 
94 #define DEFAULT_QLEN	2	/* double buffering by default */
95 
96 /* for dual-speed hardware, use deeper queues at high/super speed */
97 static inline int qlen(struct usb_gadget *gadget, unsigned qmult)
98 {
99 	if (gadget_is_dualspeed(gadget) && (gadget->speed == USB_SPEED_HIGH ||
100 					    gadget->speed == USB_SPEED_SUPER))
101 		return qmult * DEFAULT_QLEN;
102 	else
103 		return DEFAULT_QLEN;
104 }
105 
106 /*-------------------------------------------------------------------------*/
107 
108 /* REVISIT there must be a better way than having two sets
109  * of debug calls ...
110  */
111 
112 #undef DBG
113 #undef VDBG
114 #undef ERROR
115 #undef INFO
116 
117 #define xprintk(d, level, fmt, args...) \
118 	printk(level "%s: " fmt , (d)->net->name , ## args)
119 
120 #ifdef DEBUG
121 #undef DEBUG
122 #define DBG(dev, fmt, args...) \
123 	xprintk(dev , KERN_DEBUG , fmt , ## args)
124 #else
125 #define DBG(dev, fmt, args...) \
126 	do { } while (0)
127 #endif /* DEBUG */
128 
129 #ifdef VERBOSE_DEBUG
130 #define VDBG	DBG
131 #else
132 #define VDBG(dev, fmt, args...) \
133 	do { } while (0)
134 #endif /* DEBUG */
135 
136 #define ERROR(dev, fmt, args...) \
137 	xprintk(dev , KERN_ERR , fmt , ## args)
138 #define INFO(dev, fmt, args...) \
139 	xprintk(dev , KERN_INFO , fmt , ## args)
140 
141 /*-------------------------------------------------------------------------*/
142 
143 /* NETWORK DRIVER HOOKUP (to the layer above this driver) */
144 
145 static int ueth_change_mtu(struct net_device *net, int new_mtu)
146 {
147 	if (new_mtu <= ETH_HLEN || new_mtu > GETHER_MAX_ETH_FRAME_LEN)
148 		return -ERANGE;
149 	net->mtu = new_mtu;
150 
151 	return 0;
152 }
153 
154 static void eth_get_drvinfo(struct net_device *net, struct ethtool_drvinfo *p)
155 {
156 	struct eth_dev *dev = netdev_priv(net);
157 
158 	strlcpy(p->driver, "g_ether", sizeof(p->driver));
159 	strlcpy(p->version, UETH__VERSION, sizeof(p->version));
160 	strlcpy(p->fw_version, dev->gadget->name, sizeof(p->fw_version));
161 	strlcpy(p->bus_info, dev_name(&dev->gadget->dev), sizeof(p->bus_info));
162 }
163 
164 /* REVISIT can also support:
165  *   - WOL (by tracking suspends and issuing remote wakeup)
166  *   - msglevel (implies updated messaging)
167  *   - ... probably more ethtool ops
168  */
169 
170 static const struct ethtool_ops ops = {
171 	.get_drvinfo = eth_get_drvinfo,
172 	.get_link = ethtool_op_get_link,
173 };
174 
175 static void defer_kevent(struct eth_dev *dev, int flag)
176 {
177 	if (test_and_set_bit(flag, &dev->todo))
178 		return;
179 	if (!schedule_work(&dev->work))
180 		ERROR(dev, "kevent %d may have been dropped\n", flag);
181 	else
182 		DBG(dev, "kevent %d scheduled\n", flag);
183 }
184 
185 static void rx_complete(struct usb_ep *ep, struct usb_request *req);
186 
187 static int
188 rx_submit(struct eth_dev *dev, struct usb_request *req, gfp_t gfp_flags)
189 {
190 	struct sk_buff	*skb;
191 	int		retval = -ENOMEM;
192 	size_t		size = 0;
193 	struct usb_ep	*out;
194 	unsigned long	flags;
195 
196 	spin_lock_irqsave(&dev->lock, flags);
197 	if (dev->port_usb)
198 		out = dev->port_usb->out_ep;
199 	else
200 		out = NULL;
201 	spin_unlock_irqrestore(&dev->lock, flags);
202 
203 	if (!out)
204 		return -ENOTCONN;
205 
206 
207 	/* Padding up to RX_EXTRA handles minor disagreements with host.
208 	 * Normally we use the USB "terminate on short read" convention;
209 	 * so allow up to (N*maxpacket), since that memory is normally
210 	 * already allocated.  Some hardware doesn't deal well with short
211 	 * reads (e.g. DMA must be N*maxpacket), so for now don't trim a
212 	 * byte off the end (to force hardware errors on overflow).
213 	 *
214 	 * RNDIS uses internal framing, and explicitly allows senders to
215 	 * pad to end-of-packet.  That's potentially nice for speed, but
216 	 * means receivers can't recover lost synch on their own (because
217 	 * new packets don't only start after a short RX).
218 	 */
219 	size += sizeof(struct ethhdr) + dev->net->mtu + RX_EXTRA;
220 	size += dev->port_usb->header_len;
221 	size += out->maxpacket - 1;
222 	size -= size % out->maxpacket;
223 
224 	if (dev->port_usb->is_fixed)
225 		size = max_t(size_t, size, dev->port_usb->fixed_out_len);
226 
227 	skb = alloc_skb(size + NET_IP_ALIGN, gfp_flags);
228 	if (skb == NULL) {
229 		DBG(dev, "no rx skb\n");
230 		goto enomem;
231 	}
232 
233 	/* Some platforms perform better when IP packets are aligned,
234 	 * but on at least one, checksumming fails otherwise.  Note:
235 	 * RNDIS headers involve variable numbers of LE32 values.
236 	 */
237 	if (likely(!dev->no_skb_reserve))
238 		skb_reserve(skb, NET_IP_ALIGN);
239 
240 	req->buf = skb->data;
241 	req->length = size;
242 	req->complete = rx_complete;
243 	req->context = skb;
244 
245 	retval = usb_ep_queue(out, req, gfp_flags);
246 	if (retval == -ENOMEM)
247 enomem:
248 		defer_kevent(dev, WORK_RX_MEMORY);
249 	if (retval) {
250 		DBG(dev, "rx submit --> %d\n", retval);
251 		if (skb)
252 			dev_kfree_skb_any(skb);
253 		spin_lock_irqsave(&dev->req_lock, flags);
254 		list_add(&req->list, &dev->rx_reqs);
255 		spin_unlock_irqrestore(&dev->req_lock, flags);
256 	}
257 	return retval;
258 }
259 
260 static void rx_complete(struct usb_ep *ep, struct usb_request *req)
261 {
262 	struct sk_buff	*skb = req->context, *skb2;
263 	struct eth_dev	*dev = ep->driver_data;
264 	int		status = req->status;
265 
266 	switch (status) {
267 
268 	/* normal completion */
269 	case 0:
270 		skb_put(skb, req->actual);
271 
272 		if (dev->unwrap) {
273 			unsigned long	flags;
274 
275 			spin_lock_irqsave(&dev->lock, flags);
276 			if (dev->port_usb) {
277 				status = dev->unwrap(dev->port_usb,
278 							skb,
279 							&dev->rx_frames);
280 			} else {
281 				dev_kfree_skb_any(skb);
282 				status = -ENOTCONN;
283 			}
284 			spin_unlock_irqrestore(&dev->lock, flags);
285 		} else {
286 			skb_queue_tail(&dev->rx_frames, skb);
287 		}
288 		skb = NULL;
289 
290 		skb2 = skb_dequeue(&dev->rx_frames);
291 		while (skb2) {
292 			if (status < 0
293 					|| ETH_HLEN > skb2->len
294 					|| skb2->len > GETHER_MAX_ETH_FRAME_LEN) {
295 				dev->net->stats.rx_errors++;
296 				dev->net->stats.rx_length_errors++;
297 				DBG(dev, "rx length %d\n", skb2->len);
298 				dev_kfree_skb_any(skb2);
299 				goto next_frame;
300 			}
301 			skb2->protocol = eth_type_trans(skb2, dev->net);
302 			dev->net->stats.rx_packets++;
303 			dev->net->stats.rx_bytes += skb2->len;
304 
305 			/* no buffer copies needed, unless hardware can't
306 			 * use skb buffers.
307 			 */
308 			status = netif_rx(skb2);
309 next_frame:
310 			skb2 = skb_dequeue(&dev->rx_frames);
311 		}
312 		break;
313 
314 	/* software-driven interface shutdown */
315 	case -ECONNRESET:		/* unlink */
316 	case -ESHUTDOWN:		/* disconnect etc */
317 		VDBG(dev, "rx shutdown, code %d\n", status);
318 		goto quiesce;
319 
320 	/* for hardware automagic (such as pxa) */
321 	case -ECONNABORTED:		/* endpoint reset */
322 		DBG(dev, "rx %s reset\n", ep->name);
323 		defer_kevent(dev, WORK_RX_MEMORY);
324 quiesce:
325 		dev_kfree_skb_any(skb);
326 		goto clean;
327 
328 	/* data overrun */
329 	case -EOVERFLOW:
330 		dev->net->stats.rx_over_errors++;
331 		/* FALLTHROUGH */
332 
333 	default:
334 		dev->net->stats.rx_errors++;
335 		DBG(dev, "rx status %d\n", status);
336 		break;
337 	}
338 
339 	if (skb)
340 		dev_kfree_skb_any(skb);
341 	if (!netif_running(dev->net)) {
342 clean:
343 		spin_lock(&dev->req_lock);
344 		list_add(&req->list, &dev->rx_reqs);
345 		spin_unlock(&dev->req_lock);
346 		req = NULL;
347 	}
348 	if (req)
349 		rx_submit(dev, req, GFP_ATOMIC);
350 }
351 
352 static int prealloc(struct list_head *list, struct usb_ep *ep, unsigned n)
353 {
354 	unsigned		i;
355 	struct usb_request	*req;
356 
357 	if (!n)
358 		return -ENOMEM;
359 
360 	/* queue/recycle up to N requests */
361 	i = n;
362 	list_for_each_entry(req, list, list) {
363 		if (i-- == 0)
364 			goto extra;
365 	}
366 	while (i--) {
367 		req = usb_ep_alloc_request(ep, GFP_ATOMIC);
368 		if (!req)
369 			return list_empty(list) ? -ENOMEM : 0;
370 		list_add(&req->list, list);
371 	}
372 	return 0;
373 
374 extra:
375 	/* free extras */
376 	for (;;) {
377 		struct list_head	*next;
378 
379 		next = req->list.next;
380 		list_del(&req->list);
381 		usb_ep_free_request(ep, req);
382 
383 		if (next == list)
384 			break;
385 
386 		req = container_of(next, struct usb_request, list);
387 	}
388 	return 0;
389 }
390 
391 static int alloc_requests(struct eth_dev *dev, struct gether *link, unsigned n)
392 {
393 	int	status;
394 
395 	spin_lock(&dev->req_lock);
396 	status = prealloc(&dev->tx_reqs, link->in_ep, n);
397 	if (status < 0)
398 		goto fail;
399 	status = prealloc(&dev->rx_reqs, link->out_ep, n);
400 	if (status < 0)
401 		goto fail;
402 	goto done;
403 fail:
404 	DBG(dev, "can't alloc requests\n");
405 done:
406 	spin_unlock(&dev->req_lock);
407 	return status;
408 }
409 
410 static void rx_fill(struct eth_dev *dev, gfp_t gfp_flags)
411 {
412 	struct usb_request	*req;
413 	unsigned long		flags;
414 
415 	/* fill unused rxq slots with some skb */
416 	spin_lock_irqsave(&dev->req_lock, flags);
417 	while (!list_empty(&dev->rx_reqs)) {
418 		req = container_of(dev->rx_reqs.next,
419 				struct usb_request, list);
420 		list_del_init(&req->list);
421 		spin_unlock_irqrestore(&dev->req_lock, flags);
422 
423 		if (rx_submit(dev, req, gfp_flags) < 0) {
424 			defer_kevent(dev, WORK_RX_MEMORY);
425 			return;
426 		}
427 
428 		spin_lock_irqsave(&dev->req_lock, flags);
429 	}
430 	spin_unlock_irqrestore(&dev->req_lock, flags);
431 }
432 
433 static void eth_work(struct work_struct *work)
434 {
435 	struct eth_dev	*dev = container_of(work, struct eth_dev, work);
436 
437 	if (test_and_clear_bit(WORK_RX_MEMORY, &dev->todo)) {
438 		if (netif_running(dev->net))
439 			rx_fill(dev, GFP_KERNEL);
440 	}
441 
442 	if (dev->todo)
443 		DBG(dev, "work done, flags = 0x%lx\n", dev->todo);
444 }
445 
446 static void tx_complete(struct usb_ep *ep, struct usb_request *req)
447 {
448 	struct sk_buff	*skb = req->context;
449 	struct eth_dev	*dev = ep->driver_data;
450 
451 	switch (req->status) {
452 	default:
453 		dev->net->stats.tx_errors++;
454 		VDBG(dev, "tx err %d\n", req->status);
455 		/* FALLTHROUGH */
456 	case -ECONNRESET:		/* unlink */
457 	case -ESHUTDOWN:		/* disconnect etc */
458 		break;
459 	case 0:
460 		dev->net->stats.tx_bytes += skb->len;
461 	}
462 	dev->net->stats.tx_packets++;
463 
464 	spin_lock(&dev->req_lock);
465 	list_add(&req->list, &dev->tx_reqs);
466 	spin_unlock(&dev->req_lock);
467 	dev_kfree_skb_any(skb);
468 
469 	atomic_dec(&dev->tx_qlen);
470 	if (netif_carrier_ok(dev->net))
471 		netif_wake_queue(dev->net);
472 }
473 
474 static inline int is_promisc(u16 cdc_filter)
475 {
476 	return cdc_filter & USB_CDC_PACKET_TYPE_PROMISCUOUS;
477 }
478 
479 static netdev_tx_t eth_start_xmit(struct sk_buff *skb,
480 					struct net_device *net)
481 {
482 	struct eth_dev		*dev = netdev_priv(net);
483 	int			length = 0;
484 	int			retval;
485 	struct usb_request	*req = NULL;
486 	unsigned long		flags;
487 	struct usb_ep		*in;
488 	u16			cdc_filter;
489 
490 	spin_lock_irqsave(&dev->lock, flags);
491 	if (dev->port_usb) {
492 		in = dev->port_usb->in_ep;
493 		cdc_filter = dev->port_usb->cdc_filter;
494 	} else {
495 		in = NULL;
496 		cdc_filter = 0;
497 	}
498 	spin_unlock_irqrestore(&dev->lock, flags);
499 
500 	if (skb && !in) {
501 		dev_kfree_skb_any(skb);
502 		return NETDEV_TX_OK;
503 	}
504 
505 	/* apply outgoing CDC or RNDIS filters */
506 	if (skb && !is_promisc(cdc_filter)) {
507 		u8		*dest = skb->data;
508 
509 		if (is_multicast_ether_addr(dest)) {
510 			u16	type;
511 
512 			/* ignores USB_CDC_PACKET_TYPE_MULTICAST and host
513 			 * SET_ETHERNET_MULTICAST_FILTERS requests
514 			 */
515 			if (is_broadcast_ether_addr(dest))
516 				type = USB_CDC_PACKET_TYPE_BROADCAST;
517 			else
518 				type = USB_CDC_PACKET_TYPE_ALL_MULTICAST;
519 			if (!(cdc_filter & type)) {
520 				dev_kfree_skb_any(skb);
521 				return NETDEV_TX_OK;
522 			}
523 		}
524 		/* ignores USB_CDC_PACKET_TYPE_DIRECTED */
525 	}
526 
527 	spin_lock_irqsave(&dev->req_lock, flags);
528 	/*
529 	 * this freelist can be empty if an interrupt triggered disconnect()
530 	 * and reconfigured the gadget (shutting down this queue) after the
531 	 * network stack decided to xmit but before we got the spinlock.
532 	 */
533 	if (list_empty(&dev->tx_reqs)) {
534 		spin_unlock_irqrestore(&dev->req_lock, flags);
535 		return NETDEV_TX_BUSY;
536 	}
537 
538 	req = container_of(dev->tx_reqs.next, struct usb_request, list);
539 	list_del(&req->list);
540 
541 	/* temporarily stop TX queue when the freelist empties */
542 	if (list_empty(&dev->tx_reqs))
543 		netif_stop_queue(net);
544 	spin_unlock_irqrestore(&dev->req_lock, flags);
545 
546 	/* no buffer copies needed, unless the network stack did it
547 	 * or the hardware can't use skb buffers.
548 	 * or there's not enough space for extra headers we need
549 	 */
550 	if (dev->wrap) {
551 		unsigned long	flags;
552 
553 		spin_lock_irqsave(&dev->lock, flags);
554 		if (dev->port_usb)
555 			skb = dev->wrap(dev->port_usb, skb);
556 		spin_unlock_irqrestore(&dev->lock, flags);
557 		if (!skb) {
558 			/* Multi frame CDC protocols may store the frame for
559 			 * later which is not a dropped frame.
560 			 */
561 			if (dev->port_usb &&
562 					dev->port_usb->supports_multi_frame)
563 				goto multiframe;
564 			goto drop;
565 		}
566 	}
567 
568 	length = skb->len;
569 	req->buf = skb->data;
570 	req->context = skb;
571 	req->complete = tx_complete;
572 
573 	/* NCM requires no zlp if transfer is dwNtbInMaxSize */
574 	if (dev->port_usb &&
575 	    dev->port_usb->is_fixed &&
576 	    length == dev->port_usb->fixed_in_len &&
577 	    (length % in->maxpacket) == 0)
578 		req->zero = 0;
579 	else
580 		req->zero = 1;
581 
582 	/* use zlp framing on tx for strict CDC-Ether conformance,
583 	 * though any robust network rx path ignores extra padding.
584 	 * and some hardware doesn't like to write zlps.
585 	 */
586 	if (req->zero && !dev->zlp && (length % in->maxpacket) == 0)
587 		length++;
588 
589 	req->length = length;
590 
591 	/* throttle high/super speed IRQ rate back slightly */
592 	if (gadget_is_dualspeed(dev->gadget))
593 		req->no_interrupt = (dev->gadget->speed == USB_SPEED_HIGH ||
594 				     dev->gadget->speed == USB_SPEED_SUPER)
595 			? ((atomic_read(&dev->tx_qlen) % dev->qmult) != 0)
596 			: 0;
597 
598 	retval = usb_ep_queue(in, req, GFP_ATOMIC);
599 	switch (retval) {
600 	default:
601 		DBG(dev, "tx queue err %d\n", retval);
602 		break;
603 	case 0:
604 		netif_trans_update(net);
605 		atomic_inc(&dev->tx_qlen);
606 	}
607 
608 	if (retval) {
609 		dev_kfree_skb_any(skb);
610 drop:
611 		dev->net->stats.tx_dropped++;
612 multiframe:
613 		spin_lock_irqsave(&dev->req_lock, flags);
614 		if (list_empty(&dev->tx_reqs))
615 			netif_start_queue(net);
616 		list_add(&req->list, &dev->tx_reqs);
617 		spin_unlock_irqrestore(&dev->req_lock, flags);
618 	}
619 	return NETDEV_TX_OK;
620 }
621 
622 /*-------------------------------------------------------------------------*/
623 
624 static void eth_start(struct eth_dev *dev, gfp_t gfp_flags)
625 {
626 	DBG(dev, "%s\n", __func__);
627 
628 	/* fill the rx queue */
629 	rx_fill(dev, gfp_flags);
630 
631 	/* and open the tx floodgates */
632 	atomic_set(&dev->tx_qlen, 0);
633 	netif_wake_queue(dev->net);
634 }
635 
636 static int eth_open(struct net_device *net)
637 {
638 	struct eth_dev	*dev = netdev_priv(net);
639 	struct gether	*link;
640 
641 	DBG(dev, "%s\n", __func__);
642 	if (netif_carrier_ok(dev->net))
643 		eth_start(dev, GFP_KERNEL);
644 
645 	spin_lock_irq(&dev->lock);
646 	link = dev->port_usb;
647 	if (link && link->open)
648 		link->open(link);
649 	spin_unlock_irq(&dev->lock);
650 
651 	return 0;
652 }
653 
654 static int eth_stop(struct net_device *net)
655 {
656 	struct eth_dev	*dev = netdev_priv(net);
657 	unsigned long	flags;
658 
659 	VDBG(dev, "%s\n", __func__);
660 	netif_stop_queue(net);
661 
662 	DBG(dev, "stop stats: rx/tx %ld/%ld, errs %ld/%ld\n",
663 		dev->net->stats.rx_packets, dev->net->stats.tx_packets,
664 		dev->net->stats.rx_errors, dev->net->stats.tx_errors
665 		);
666 
667 	/* ensure there are no more active requests */
668 	spin_lock_irqsave(&dev->lock, flags);
669 	if (dev->port_usb) {
670 		struct gether	*link = dev->port_usb;
671 		const struct usb_endpoint_descriptor *in;
672 		const struct usb_endpoint_descriptor *out;
673 
674 		if (link->close)
675 			link->close(link);
676 
677 		/* NOTE:  we have no abort-queue primitive we could use
678 		 * to cancel all pending I/O.  Instead, we disable then
679 		 * reenable the endpoints ... this idiom may leave toggle
680 		 * wrong, but that's a self-correcting error.
681 		 *
682 		 * REVISIT:  we *COULD* just let the transfers complete at
683 		 * their own pace; the network stack can handle old packets.
684 		 * For the moment we leave this here, since it works.
685 		 */
686 		in = link->in_ep->desc;
687 		out = link->out_ep->desc;
688 		usb_ep_disable(link->in_ep);
689 		usb_ep_disable(link->out_ep);
690 		if (netif_carrier_ok(net)) {
691 			DBG(dev, "host still using in/out endpoints\n");
692 			link->in_ep->desc = in;
693 			link->out_ep->desc = out;
694 			usb_ep_enable(link->in_ep);
695 			usb_ep_enable(link->out_ep);
696 		}
697 	}
698 	spin_unlock_irqrestore(&dev->lock, flags);
699 
700 	return 0;
701 }
702 
703 /*-------------------------------------------------------------------------*/
704 
705 static int get_ether_addr(const char *str, u8 *dev_addr)
706 {
707 	if (str) {
708 		unsigned	i;
709 
710 		for (i = 0; i < 6; i++) {
711 			unsigned char num;
712 
713 			if ((*str == '.') || (*str == ':'))
714 				str++;
715 			num = hex_to_bin(*str++) << 4;
716 			num |= hex_to_bin(*str++);
717 			dev_addr [i] = num;
718 		}
719 		if (is_valid_ether_addr(dev_addr))
720 			return 0;
721 	}
722 	eth_random_addr(dev_addr);
723 	return 1;
724 }
725 
726 static int get_ether_addr_str(u8 dev_addr[ETH_ALEN], char *str, int len)
727 {
728 	if (len < 18)
729 		return -EINVAL;
730 
731 	snprintf(str, len, "%pM", dev_addr);
732 	return 18;
733 }
734 
735 static const struct net_device_ops eth_netdev_ops = {
736 	.ndo_open		= eth_open,
737 	.ndo_stop		= eth_stop,
738 	.ndo_start_xmit		= eth_start_xmit,
739 	.ndo_change_mtu		= ueth_change_mtu,
740 	.ndo_set_mac_address 	= eth_mac_addr,
741 	.ndo_validate_addr	= eth_validate_addr,
742 };
743 
744 static struct device_type gadget_type = {
745 	.name	= "gadget",
746 };
747 
748 /**
749  * gether_setup_name - initialize one ethernet-over-usb link
750  * @g: gadget to associated with these links
751  * @ethaddr: NULL, or a buffer in which the ethernet address of the
752  *	host side of the link is recorded
753  * @netname: name for network device (for example, "usb")
754  * Context: may sleep
755  *
756  * This sets up the single network link that may be exported by a
757  * gadget driver using this framework.  The link layer addresses are
758  * set up using module parameters.
759  *
760  * Returns an eth_dev pointer on success, or an ERR_PTR on failure.
761  */
762 struct eth_dev *gether_setup_name(struct usb_gadget *g,
763 		const char *dev_addr, const char *host_addr,
764 		u8 ethaddr[ETH_ALEN], unsigned qmult, const char *netname)
765 {
766 	struct eth_dev		*dev;
767 	struct net_device	*net;
768 	int			status;
769 
770 	net = alloc_etherdev(sizeof *dev);
771 	if (!net)
772 		return ERR_PTR(-ENOMEM);
773 
774 	dev = netdev_priv(net);
775 	spin_lock_init(&dev->lock);
776 	spin_lock_init(&dev->req_lock);
777 	INIT_WORK(&dev->work, eth_work);
778 	INIT_LIST_HEAD(&dev->tx_reqs);
779 	INIT_LIST_HEAD(&dev->rx_reqs);
780 
781 	skb_queue_head_init(&dev->rx_frames);
782 
783 	/* network device setup */
784 	dev->net = net;
785 	dev->qmult = qmult;
786 	snprintf(net->name, sizeof(net->name), "%s%%d", netname);
787 
788 	if (get_ether_addr(dev_addr, net->dev_addr))
789 		dev_warn(&g->dev,
790 			"using random %s ethernet address\n", "self");
791 	if (get_ether_addr(host_addr, dev->host_mac))
792 		dev_warn(&g->dev,
793 			"using random %s ethernet address\n", "host");
794 
795 	if (ethaddr)
796 		memcpy(ethaddr, dev->host_mac, ETH_ALEN);
797 
798 	net->netdev_ops = &eth_netdev_ops;
799 
800 	net->ethtool_ops = &ops;
801 
802 	dev->gadget = g;
803 	SET_NETDEV_DEV(net, &g->dev);
804 	SET_NETDEV_DEVTYPE(net, &gadget_type);
805 
806 	status = register_netdev(net);
807 	if (status < 0) {
808 		dev_dbg(&g->dev, "register_netdev failed, %d\n", status);
809 		free_netdev(net);
810 		dev = ERR_PTR(status);
811 	} else {
812 		INFO(dev, "MAC %pM\n", net->dev_addr);
813 		INFO(dev, "HOST MAC %pM\n", dev->host_mac);
814 
815 		/*
816 		 * two kinds of host-initiated state changes:
817 		 *  - iff DATA transfer is active, carrier is "on"
818 		 *  - tx queueing enabled if open *and* carrier is "on"
819 		 */
820 		netif_carrier_off(net);
821 	}
822 
823 	return dev;
824 }
825 EXPORT_SYMBOL_GPL(gether_setup_name);
826 
827 struct net_device *gether_setup_name_default(const char *netname)
828 {
829 	struct net_device	*net;
830 	struct eth_dev		*dev;
831 
832 	net = alloc_etherdev(sizeof(*dev));
833 	if (!net)
834 		return ERR_PTR(-ENOMEM);
835 
836 	dev = netdev_priv(net);
837 	spin_lock_init(&dev->lock);
838 	spin_lock_init(&dev->req_lock);
839 	INIT_WORK(&dev->work, eth_work);
840 	INIT_LIST_HEAD(&dev->tx_reqs);
841 	INIT_LIST_HEAD(&dev->rx_reqs);
842 
843 	skb_queue_head_init(&dev->rx_frames);
844 
845 	/* network device setup */
846 	dev->net = net;
847 	dev->qmult = QMULT_DEFAULT;
848 	snprintf(net->name, sizeof(net->name), "%s%%d", netname);
849 
850 	eth_random_addr(dev->dev_mac);
851 	pr_warn("using random %s ethernet address\n", "self");
852 	eth_random_addr(dev->host_mac);
853 	pr_warn("using random %s ethernet address\n", "host");
854 
855 	net->netdev_ops = &eth_netdev_ops;
856 
857 	net->ethtool_ops = &ops;
858 	SET_NETDEV_DEVTYPE(net, &gadget_type);
859 
860 	return net;
861 }
862 EXPORT_SYMBOL_GPL(gether_setup_name_default);
863 
864 int gether_register_netdev(struct net_device *net)
865 {
866 	struct eth_dev *dev;
867 	struct usb_gadget *g;
868 	struct sockaddr sa;
869 	int status;
870 
871 	if (!net->dev.parent)
872 		return -EINVAL;
873 	dev = netdev_priv(net);
874 	g = dev->gadget;
875 	status = register_netdev(net);
876 	if (status < 0) {
877 		dev_dbg(&g->dev, "register_netdev failed, %d\n", status);
878 		return status;
879 	} else {
880 		INFO(dev, "HOST MAC %pM\n", dev->host_mac);
881 
882 		/* two kinds of host-initiated state changes:
883 		 *  - iff DATA transfer is active, carrier is "on"
884 		 *  - tx queueing enabled if open *and* carrier is "on"
885 		 */
886 		netif_carrier_off(net);
887 	}
888 	sa.sa_family = net->type;
889 	memcpy(sa.sa_data, dev->dev_mac, ETH_ALEN);
890 	rtnl_lock();
891 	status = dev_set_mac_address(net, &sa);
892 	rtnl_unlock();
893 	if (status)
894 		pr_warn("cannot set self ethernet address: %d\n", status);
895 	else
896 		INFO(dev, "MAC %pM\n", dev->dev_mac);
897 
898 	return status;
899 }
900 EXPORT_SYMBOL_GPL(gether_register_netdev);
901 
902 void gether_set_gadget(struct net_device *net, struct usb_gadget *g)
903 {
904 	struct eth_dev *dev;
905 
906 	dev = netdev_priv(net);
907 	dev->gadget = g;
908 	SET_NETDEV_DEV(net, &g->dev);
909 }
910 EXPORT_SYMBOL_GPL(gether_set_gadget);
911 
912 int gether_set_dev_addr(struct net_device *net, const char *dev_addr)
913 {
914 	struct eth_dev *dev;
915 	u8 new_addr[ETH_ALEN];
916 
917 	dev = netdev_priv(net);
918 	if (get_ether_addr(dev_addr, new_addr))
919 		return -EINVAL;
920 	memcpy(dev->dev_mac, new_addr, ETH_ALEN);
921 	return 0;
922 }
923 EXPORT_SYMBOL_GPL(gether_set_dev_addr);
924 
925 int gether_get_dev_addr(struct net_device *net, char *dev_addr, int len)
926 {
927 	struct eth_dev *dev;
928 
929 	dev = netdev_priv(net);
930 	return get_ether_addr_str(dev->dev_mac, dev_addr, len);
931 }
932 EXPORT_SYMBOL_GPL(gether_get_dev_addr);
933 
934 int gether_set_host_addr(struct net_device *net, const char *host_addr)
935 {
936 	struct eth_dev *dev;
937 	u8 new_addr[ETH_ALEN];
938 
939 	dev = netdev_priv(net);
940 	if (get_ether_addr(host_addr, new_addr))
941 		return -EINVAL;
942 	memcpy(dev->host_mac, new_addr, ETH_ALEN);
943 	return 0;
944 }
945 EXPORT_SYMBOL_GPL(gether_set_host_addr);
946 
947 int gether_get_host_addr(struct net_device *net, char *host_addr, int len)
948 {
949 	struct eth_dev *dev;
950 
951 	dev = netdev_priv(net);
952 	return get_ether_addr_str(dev->host_mac, host_addr, len);
953 }
954 EXPORT_SYMBOL_GPL(gether_get_host_addr);
955 
956 int gether_get_host_addr_cdc(struct net_device *net, char *host_addr, int len)
957 {
958 	struct eth_dev *dev;
959 
960 	if (len < 13)
961 		return -EINVAL;
962 
963 	dev = netdev_priv(net);
964 	snprintf(host_addr, len, "%pm", dev->host_mac);
965 
966 	return strlen(host_addr);
967 }
968 EXPORT_SYMBOL_GPL(gether_get_host_addr_cdc);
969 
970 void gether_get_host_addr_u8(struct net_device *net, u8 host_mac[ETH_ALEN])
971 {
972 	struct eth_dev *dev;
973 
974 	dev = netdev_priv(net);
975 	memcpy(host_mac, dev->host_mac, ETH_ALEN);
976 }
977 EXPORT_SYMBOL_GPL(gether_get_host_addr_u8);
978 
979 void gether_set_qmult(struct net_device *net, unsigned qmult)
980 {
981 	struct eth_dev *dev;
982 
983 	dev = netdev_priv(net);
984 	dev->qmult = qmult;
985 }
986 EXPORT_SYMBOL_GPL(gether_set_qmult);
987 
988 unsigned gether_get_qmult(struct net_device *net)
989 {
990 	struct eth_dev *dev;
991 
992 	dev = netdev_priv(net);
993 	return dev->qmult;
994 }
995 EXPORT_SYMBOL_GPL(gether_get_qmult);
996 
997 int gether_get_ifname(struct net_device *net, char *name, int len)
998 {
999 	rtnl_lock();
1000 	strlcpy(name, netdev_name(net), len);
1001 	rtnl_unlock();
1002 	return strlen(name);
1003 }
1004 EXPORT_SYMBOL_GPL(gether_get_ifname);
1005 
1006 /**
1007  * gether_cleanup - remove Ethernet-over-USB device
1008  * Context: may sleep
1009  *
1010  * This is called to free all resources allocated by @gether_setup().
1011  */
1012 void gether_cleanup(struct eth_dev *dev)
1013 {
1014 	if (!dev)
1015 		return;
1016 
1017 	unregister_netdev(dev->net);
1018 	flush_work(&dev->work);
1019 	free_netdev(dev->net);
1020 }
1021 EXPORT_SYMBOL_GPL(gether_cleanup);
1022 
1023 /**
1024  * gether_connect - notify network layer that USB link is active
1025  * @link: the USB link, set up with endpoints, descriptors matching
1026  *	current device speed, and any framing wrapper(s) set up.
1027  * Context: irqs blocked
1028  *
1029  * This is called to activate endpoints and let the network layer know
1030  * the connection is active ("carrier detect").  It may cause the I/O
1031  * queues to open and start letting network packets flow, but will in
1032  * any case activate the endpoints so that they respond properly to the
1033  * USB host.
1034  *
1035  * Verify net_device pointer returned using IS_ERR().  If it doesn't
1036  * indicate some error code (negative errno), ep->driver_data values
1037  * have been overwritten.
1038  */
1039 struct net_device *gether_connect(struct gether *link)
1040 {
1041 	struct eth_dev		*dev = link->ioport;
1042 	int			result = 0;
1043 
1044 	if (!dev)
1045 		return ERR_PTR(-EINVAL);
1046 
1047 	link->in_ep->driver_data = dev;
1048 	result = usb_ep_enable(link->in_ep);
1049 	if (result != 0) {
1050 		DBG(dev, "enable %s --> %d\n",
1051 			link->in_ep->name, result);
1052 		goto fail0;
1053 	}
1054 
1055 	link->out_ep->driver_data = dev;
1056 	result = usb_ep_enable(link->out_ep);
1057 	if (result != 0) {
1058 		DBG(dev, "enable %s --> %d\n",
1059 			link->out_ep->name, result);
1060 		goto fail1;
1061 	}
1062 
1063 	if (result == 0)
1064 		result = alloc_requests(dev, link, qlen(dev->gadget,
1065 					dev->qmult));
1066 
1067 	if (result == 0) {
1068 		dev->zlp = link->is_zlp_ok;
1069 		dev->no_skb_reserve = link->no_skb_reserve;
1070 		DBG(dev, "qlen %d\n", qlen(dev->gadget, dev->qmult));
1071 
1072 		dev->header_len = link->header_len;
1073 		dev->unwrap = link->unwrap;
1074 		dev->wrap = link->wrap;
1075 
1076 		spin_lock(&dev->lock);
1077 		dev->port_usb = link;
1078 		if (netif_running(dev->net)) {
1079 			if (link->open)
1080 				link->open(link);
1081 		} else {
1082 			if (link->close)
1083 				link->close(link);
1084 		}
1085 		spin_unlock(&dev->lock);
1086 
1087 		netif_carrier_on(dev->net);
1088 		if (netif_running(dev->net))
1089 			eth_start(dev, GFP_ATOMIC);
1090 
1091 	/* on error, disable any endpoints  */
1092 	} else {
1093 		(void) usb_ep_disable(link->out_ep);
1094 fail1:
1095 		(void) usb_ep_disable(link->in_ep);
1096 	}
1097 fail0:
1098 	/* caller is responsible for cleanup on error */
1099 	if (result < 0)
1100 		return ERR_PTR(result);
1101 	return dev->net;
1102 }
1103 EXPORT_SYMBOL_GPL(gether_connect);
1104 
1105 /**
1106  * gether_disconnect - notify network layer that USB link is inactive
1107  * @link: the USB link, on which gether_connect() was called
1108  * Context: irqs blocked
1109  *
1110  * This is called to deactivate endpoints and let the network layer know
1111  * the connection went inactive ("no carrier").
1112  *
1113  * On return, the state is as if gether_connect() had never been called.
1114  * The endpoints are inactive, and accordingly without active USB I/O.
1115  * Pointers to endpoint descriptors and endpoint private data are nulled.
1116  */
1117 void gether_disconnect(struct gether *link)
1118 {
1119 	struct eth_dev		*dev = link->ioport;
1120 	struct usb_request	*req;
1121 
1122 	WARN_ON(!dev);
1123 	if (!dev)
1124 		return;
1125 
1126 	DBG(dev, "%s\n", __func__);
1127 
1128 	netif_stop_queue(dev->net);
1129 	netif_carrier_off(dev->net);
1130 
1131 	/* disable endpoints, forcing (synchronous) completion
1132 	 * of all pending i/o.  then free the request objects
1133 	 * and forget about the endpoints.
1134 	 */
1135 	usb_ep_disable(link->in_ep);
1136 	spin_lock(&dev->req_lock);
1137 	while (!list_empty(&dev->tx_reqs)) {
1138 		req = container_of(dev->tx_reqs.next,
1139 					struct usb_request, list);
1140 		list_del(&req->list);
1141 
1142 		spin_unlock(&dev->req_lock);
1143 		usb_ep_free_request(link->in_ep, req);
1144 		spin_lock(&dev->req_lock);
1145 	}
1146 	spin_unlock(&dev->req_lock);
1147 	link->in_ep->desc = NULL;
1148 
1149 	usb_ep_disable(link->out_ep);
1150 	spin_lock(&dev->req_lock);
1151 	while (!list_empty(&dev->rx_reqs)) {
1152 		req = container_of(dev->rx_reqs.next,
1153 					struct usb_request, list);
1154 		list_del(&req->list);
1155 
1156 		spin_unlock(&dev->req_lock);
1157 		usb_ep_free_request(link->out_ep, req);
1158 		spin_lock(&dev->req_lock);
1159 	}
1160 	spin_unlock(&dev->req_lock);
1161 	link->out_ep->desc = NULL;
1162 
1163 	/* finish forgetting about this USB link episode */
1164 	dev->header_len = 0;
1165 	dev->unwrap = NULL;
1166 	dev->wrap = NULL;
1167 
1168 	spin_lock(&dev->lock);
1169 	dev->port_usb = NULL;
1170 	spin_unlock(&dev->lock);
1171 }
1172 EXPORT_SYMBOL_GPL(gether_disconnect);
1173 
1174 MODULE_LICENSE("GPL");
1175 MODULE_AUTHOR("David Brownell");
1176