Kyle Swenson | 8d8f654 | 2021-03-15 11:02:55 -0600 | [diff] [blame^] | 1 | /****************************************************************************** |
| 2 | * |
| 3 | * This file is provided under a dual BSD/GPLv2 license. When using or |
| 4 | * redistributing this file, you may do so under either license. |
| 5 | * |
| 6 | * GPL LICENSE SUMMARY |
| 7 | * |
| 8 | * Copyright(c) 2012 - 2014 Intel Corporation. All rights reserved. |
| 9 | * Copyright(c) 2013 - 2015 Intel Mobile Communications GmbH |
| 10 | * |
| 11 | * This program is free software; you can redistribute it and/or modify |
| 12 | * it under the terms of version 2 of the GNU General Public License as |
| 13 | * published by the Free Software Foundation. |
| 14 | * |
| 15 | * This program is distributed in the hope that it will be useful, but |
| 16 | * WITHOUT ANY WARRANTY; without even the implied warranty of |
| 17 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU |
| 18 | * General Public License for more details. |
| 19 | * |
| 20 | * You should have received a copy of the GNU General Public License |
| 21 | * along with this program; if not, write to the Free Software |
| 22 | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110, |
| 23 | * USA |
| 24 | * |
| 25 | * The full GNU General Public License is included in this distribution |
| 26 | * in the file called COPYING. |
| 27 | * |
| 28 | * Contact Information: |
| 29 | * Intel Linux Wireless <ilw@linux.intel.com> |
| 30 | * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497 |
| 31 | * |
| 32 | * BSD LICENSE |
| 33 | * |
| 34 | * Copyright(c) 2012 - 2014 Intel Corporation. All rights reserved. |
| 35 | * Copyright(c) 2013 - 2015 Intel Mobile Communications GmbH |
| 36 | * All rights reserved. |
| 37 | * |
| 38 | * Redistribution and use in source and binary forms, with or without |
| 39 | * modification, are permitted provided that the following conditions |
| 40 | * are met: |
| 41 | * |
| 42 | * * Redistributions of source code must retain the above copyright |
| 43 | * notice, this list of conditions and the following disclaimer. |
| 44 | * * Redistributions in binary form must reproduce the above copyright |
| 45 | * notice, this list of conditions and the following disclaimer in |
| 46 | * the documentation and/or other materials provided with the |
| 47 | * distribution. |
| 48 | * * Neither the name Intel Corporation nor the names of its |
| 49 | * contributors may be used to endorse or promote products derived |
| 50 | * from this software without specific prior written permission. |
| 51 | * |
| 52 | * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS |
| 53 | * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT |
| 54 | * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR |
| 55 | * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT |
| 56 | * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
| 57 | * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT |
| 58 | * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, |
| 59 | * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY |
| 60 | * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
| 61 | * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
| 62 | * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
| 63 | * |
| 64 | *****************************************************************************/ |
| 65 | #include <linux/ieee80211.h> |
| 66 | #include <linux/etherdevice.h> |
| 67 | |
| 68 | #include "iwl-trans.h" |
| 69 | #include "iwl-eeprom-parse.h" |
| 70 | #include "mvm.h" |
| 71 | #include "sta.h" |
| 72 | |
| 73 | static void |
| 74 | iwl_mvm_bar_check_trigger(struct iwl_mvm *mvm, const u8 *addr, |
| 75 | u16 tid, u16 ssn) |
| 76 | { |
| 77 | struct iwl_fw_dbg_trigger_tlv *trig; |
| 78 | struct iwl_fw_dbg_trigger_ba *ba_trig; |
| 79 | |
| 80 | if (!iwl_fw_dbg_trigger_enabled(mvm->fw, FW_DBG_TRIGGER_BA)) |
| 81 | return; |
| 82 | |
| 83 | trig = iwl_fw_dbg_get_trigger(mvm->fw, FW_DBG_TRIGGER_BA); |
| 84 | ba_trig = (void *)trig->data; |
| 85 | |
| 86 | if (!iwl_fw_dbg_trigger_check_stop(mvm, NULL, trig)) |
| 87 | return; |
| 88 | |
| 89 | if (!(le16_to_cpu(ba_trig->tx_bar) & BIT(tid))) |
| 90 | return; |
| 91 | |
| 92 | iwl_mvm_fw_dbg_collect_trig(mvm, trig, |
| 93 | "BAR sent to %pM, tid %d, ssn %d", |
| 94 | addr, tid, ssn); |
| 95 | } |
| 96 | |
| 97 | /* |
| 98 | * Sets most of the Tx cmd's fields |
| 99 | */ |
| 100 | void iwl_mvm_set_tx_cmd(struct iwl_mvm *mvm, struct sk_buff *skb, |
| 101 | struct iwl_tx_cmd *tx_cmd, |
| 102 | struct ieee80211_tx_info *info, u8 sta_id) |
| 103 | { |
| 104 | struct ieee80211_hdr *hdr = (void *)skb->data; |
| 105 | __le16 fc = hdr->frame_control; |
| 106 | u32 tx_flags = le32_to_cpu(tx_cmd->tx_flags); |
| 107 | u32 len = skb->len + FCS_LEN; |
| 108 | u8 ac; |
| 109 | |
| 110 | if (!(info->flags & IEEE80211_TX_CTL_NO_ACK)) |
| 111 | tx_flags |= TX_CMD_FLG_ACK; |
| 112 | else |
| 113 | tx_flags &= ~TX_CMD_FLG_ACK; |
| 114 | |
| 115 | if (ieee80211_is_probe_resp(fc)) |
| 116 | tx_flags |= TX_CMD_FLG_TSF; |
| 117 | |
| 118 | if (ieee80211_has_morefrags(fc)) |
| 119 | tx_flags |= TX_CMD_FLG_MORE_FRAG; |
| 120 | |
| 121 | if (ieee80211_is_data_qos(fc)) { |
| 122 | u8 *qc = ieee80211_get_qos_ctl(hdr); |
| 123 | tx_cmd->tid_tspec = qc[0] & 0xf; |
| 124 | tx_flags &= ~TX_CMD_FLG_SEQ_CTL; |
| 125 | } else if (ieee80211_is_back_req(fc)) { |
| 126 | struct ieee80211_bar *bar = (void *)skb->data; |
| 127 | u16 control = le16_to_cpu(bar->control); |
| 128 | u16 ssn = le16_to_cpu(bar->start_seq_num); |
| 129 | |
| 130 | tx_flags |= TX_CMD_FLG_ACK | TX_CMD_FLG_BAR; |
| 131 | tx_cmd->tid_tspec = (control & |
| 132 | IEEE80211_BAR_CTRL_TID_INFO_MASK) >> |
| 133 | IEEE80211_BAR_CTRL_TID_INFO_SHIFT; |
| 134 | WARN_ON_ONCE(tx_cmd->tid_tspec >= IWL_MAX_TID_COUNT); |
| 135 | iwl_mvm_bar_check_trigger(mvm, bar->ra, tx_cmd->tid_tspec, |
| 136 | ssn); |
| 137 | } else { |
| 138 | tx_cmd->tid_tspec = IWL_TID_NON_QOS; |
| 139 | if (info->flags & IEEE80211_TX_CTL_ASSIGN_SEQ) |
| 140 | tx_flags |= TX_CMD_FLG_SEQ_CTL; |
| 141 | else |
| 142 | tx_flags &= ~TX_CMD_FLG_SEQ_CTL; |
| 143 | } |
| 144 | |
| 145 | /* Default to 0 (BE) when tid_spec is set to IWL_TID_NON_QOS */ |
| 146 | if (tx_cmd->tid_tspec < IWL_MAX_TID_COUNT) |
| 147 | ac = tid_to_mac80211_ac[tx_cmd->tid_tspec]; |
| 148 | else |
| 149 | ac = tid_to_mac80211_ac[0]; |
| 150 | |
| 151 | tx_flags |= iwl_mvm_bt_coex_tx_prio(mvm, hdr, info, ac) << |
| 152 | TX_CMD_FLG_BT_PRIO_POS; |
| 153 | |
| 154 | if (ieee80211_is_mgmt(fc)) { |
| 155 | if (ieee80211_is_assoc_req(fc) || ieee80211_is_reassoc_req(fc)) |
| 156 | tx_cmd->pm_frame_timeout = cpu_to_le16(PM_FRAME_ASSOC); |
| 157 | else if (ieee80211_is_action(fc)) |
| 158 | tx_cmd->pm_frame_timeout = cpu_to_le16(PM_FRAME_NONE); |
| 159 | else |
| 160 | tx_cmd->pm_frame_timeout = cpu_to_le16(PM_FRAME_MGMT); |
| 161 | |
| 162 | /* The spec allows Action frames in A-MPDU, we don't support |
| 163 | * it |
| 164 | */ |
| 165 | WARN_ON_ONCE(info->flags & IEEE80211_TX_CTL_AMPDU); |
| 166 | } else if (info->control.flags & IEEE80211_TX_CTRL_PORT_CTRL_PROTO) { |
| 167 | tx_cmd->pm_frame_timeout = cpu_to_le16(PM_FRAME_MGMT); |
| 168 | } else { |
| 169 | tx_cmd->pm_frame_timeout = cpu_to_le16(PM_FRAME_NONE); |
| 170 | } |
| 171 | |
| 172 | if (ieee80211_is_data(fc) && len > mvm->rts_threshold && |
| 173 | !is_multicast_ether_addr(ieee80211_get_DA(hdr))) |
| 174 | tx_flags |= TX_CMD_FLG_PROT_REQUIRE; |
| 175 | |
| 176 | if (fw_has_capa(&mvm->fw->ucode_capa, |
| 177 | IWL_UCODE_TLV_CAPA_TXPOWER_INSERTION_SUPPORT) && |
| 178 | ieee80211_action_contains_tpc(skb)) |
| 179 | tx_flags |= TX_CMD_FLG_WRITE_TX_POWER; |
| 180 | |
| 181 | tx_cmd->tx_flags = cpu_to_le32(tx_flags); |
| 182 | /* Total # bytes to be transmitted */ |
| 183 | tx_cmd->len = cpu_to_le16((u16)skb->len); |
| 184 | tx_cmd->next_frame_len = 0; |
| 185 | tx_cmd->life_time = cpu_to_le32(TX_CMD_LIFE_TIME_INFINITE); |
| 186 | tx_cmd->sta_id = sta_id; |
| 187 | } |
| 188 | |
| 189 | /* |
| 190 | * Sets the fields in the Tx cmd that are rate related |
| 191 | */ |
| 192 | void iwl_mvm_set_tx_cmd_rate(struct iwl_mvm *mvm, struct iwl_tx_cmd *tx_cmd, |
| 193 | struct ieee80211_tx_info *info, |
| 194 | struct ieee80211_sta *sta, __le16 fc) |
| 195 | { |
| 196 | u32 rate_flags; |
| 197 | int rate_idx; |
| 198 | u8 rate_plcp; |
| 199 | |
| 200 | /* Set retry limit on RTS packets */ |
| 201 | tx_cmd->rts_retry_limit = IWL_RTS_DFAULT_RETRY_LIMIT; |
| 202 | |
| 203 | /* Set retry limit on DATA packets and Probe Responses*/ |
| 204 | if (ieee80211_is_probe_resp(fc)) { |
| 205 | tx_cmd->data_retry_limit = IWL_MGMT_DFAULT_RETRY_LIMIT; |
| 206 | tx_cmd->rts_retry_limit = |
| 207 | min(tx_cmd->data_retry_limit, tx_cmd->rts_retry_limit); |
| 208 | } else if (ieee80211_is_back_req(fc)) { |
| 209 | tx_cmd->data_retry_limit = IWL_BAR_DFAULT_RETRY_LIMIT; |
| 210 | } else { |
| 211 | tx_cmd->data_retry_limit = IWL_DEFAULT_TX_RETRY; |
| 212 | } |
| 213 | |
| 214 | /* |
| 215 | * for data packets, rate info comes from the table inside the fw. This |
| 216 | * table is controlled by LINK_QUALITY commands |
| 217 | */ |
| 218 | |
| 219 | if (ieee80211_is_data(fc) && sta) { |
| 220 | tx_cmd->initial_rate_index = 0; |
| 221 | tx_cmd->tx_flags |= cpu_to_le32(TX_CMD_FLG_STA_RATE); |
| 222 | return; |
| 223 | } else if (ieee80211_is_back_req(fc)) { |
| 224 | tx_cmd->tx_flags |= |
| 225 | cpu_to_le32(TX_CMD_FLG_ACK | TX_CMD_FLG_BAR); |
| 226 | } |
| 227 | |
| 228 | /* HT rate doesn't make sense for a non data frame */ |
| 229 | WARN_ONCE(info->control.rates[0].flags & IEEE80211_TX_RC_MCS, |
| 230 | "Got an HT rate (flags:0x%x/mcs:%d) for a non data frame (fc:0x%x)\n", |
| 231 | info->control.rates[0].flags, |
| 232 | info->control.rates[0].idx, |
| 233 | le16_to_cpu(fc)); |
| 234 | |
| 235 | rate_idx = info->control.rates[0].idx; |
| 236 | /* if the rate isn't a well known legacy rate, take the lowest one */ |
| 237 | if (rate_idx < 0 || rate_idx > IWL_RATE_COUNT_LEGACY) |
| 238 | rate_idx = rate_lowest_index( |
| 239 | &mvm->nvm_data->bands[info->band], sta); |
| 240 | |
| 241 | /* For 5 GHZ band, remap mac80211 rate indices into driver indices */ |
| 242 | if (info->band == IEEE80211_BAND_5GHZ) |
| 243 | rate_idx += IWL_FIRST_OFDM_RATE; |
| 244 | |
| 245 | /* For 2.4 GHZ band, check that there is no need to remap */ |
| 246 | BUILD_BUG_ON(IWL_FIRST_CCK_RATE != 0); |
| 247 | |
| 248 | /* Get PLCP rate for tx_cmd->rate_n_flags */ |
| 249 | rate_plcp = iwl_mvm_mac80211_idx_to_hwrate(rate_idx); |
| 250 | |
| 251 | mvm->mgmt_last_antenna_idx = |
| 252 | iwl_mvm_next_antenna(mvm, iwl_mvm_get_valid_tx_ant(mvm), |
| 253 | mvm->mgmt_last_antenna_idx); |
| 254 | |
| 255 | if (info->band == IEEE80211_BAND_2GHZ && |
| 256 | !iwl_mvm_bt_coex_is_shared_ant_avail(mvm)) |
| 257 | rate_flags = mvm->cfg->non_shared_ant << RATE_MCS_ANT_POS; |
| 258 | else |
| 259 | rate_flags = |
| 260 | BIT(mvm->mgmt_last_antenna_idx) << RATE_MCS_ANT_POS; |
| 261 | |
| 262 | /* Set CCK flag as needed */ |
| 263 | if ((rate_idx >= IWL_FIRST_CCK_RATE) && (rate_idx <= IWL_LAST_CCK_RATE)) |
| 264 | rate_flags |= RATE_MCS_CCK_MSK; |
| 265 | |
| 266 | /* Set the rate in the TX cmd */ |
| 267 | tx_cmd->rate_n_flags = cpu_to_le32((u32)rate_plcp | rate_flags); |
| 268 | } |
| 269 | |
| 270 | /* |
| 271 | * Sets the fields in the Tx cmd that are crypto related |
| 272 | */ |
| 273 | static void iwl_mvm_set_tx_cmd_crypto(struct iwl_mvm *mvm, |
| 274 | struct ieee80211_tx_info *info, |
| 275 | struct iwl_tx_cmd *tx_cmd, |
| 276 | struct sk_buff *skb_frag, |
| 277 | int hdrlen) |
| 278 | { |
| 279 | struct ieee80211_key_conf *keyconf = info->control.hw_key; |
| 280 | u8 *crypto_hdr = skb_frag->data + hdrlen; |
| 281 | u64 pn; |
| 282 | |
| 283 | switch (keyconf->cipher) { |
| 284 | case WLAN_CIPHER_SUITE_CCMP: |
| 285 | case WLAN_CIPHER_SUITE_CCMP_256: |
| 286 | iwl_mvm_set_tx_cmd_ccmp(info, tx_cmd); |
| 287 | pn = atomic64_inc_return(&keyconf->tx_pn); |
| 288 | crypto_hdr[0] = pn; |
| 289 | crypto_hdr[2] = 0; |
| 290 | crypto_hdr[3] = 0x20 | (keyconf->keyidx << 6); |
| 291 | crypto_hdr[1] = pn >> 8; |
| 292 | crypto_hdr[4] = pn >> 16; |
| 293 | crypto_hdr[5] = pn >> 24; |
| 294 | crypto_hdr[6] = pn >> 32; |
| 295 | crypto_hdr[7] = pn >> 40; |
| 296 | break; |
| 297 | |
| 298 | case WLAN_CIPHER_SUITE_TKIP: |
| 299 | tx_cmd->sec_ctl = TX_CMD_SEC_TKIP; |
| 300 | ieee80211_get_tkip_p2k(keyconf, skb_frag, tx_cmd->key); |
| 301 | break; |
| 302 | |
| 303 | case WLAN_CIPHER_SUITE_WEP104: |
| 304 | tx_cmd->sec_ctl |= TX_CMD_SEC_KEY128; |
| 305 | /* fall through */ |
| 306 | case WLAN_CIPHER_SUITE_WEP40: |
| 307 | tx_cmd->sec_ctl |= TX_CMD_SEC_WEP | |
| 308 | ((keyconf->keyidx << TX_CMD_SEC_WEP_KEY_IDX_POS) & |
| 309 | TX_CMD_SEC_WEP_KEY_IDX_MSK); |
| 310 | |
| 311 | memcpy(&tx_cmd->key[3], keyconf->key, keyconf->keylen); |
| 312 | break; |
| 313 | default: |
| 314 | tx_cmd->sec_ctl |= TX_CMD_SEC_EXT; |
| 315 | } |
| 316 | } |
| 317 | |
| 318 | /* |
| 319 | * Allocates and sets the Tx cmd the driver data pointers in the skb |
| 320 | */ |
| 321 | static struct iwl_device_cmd * |
| 322 | iwl_mvm_set_tx_params(struct iwl_mvm *mvm, struct sk_buff *skb, |
| 323 | int hdrlen, struct ieee80211_sta *sta, u8 sta_id) |
| 324 | { |
| 325 | struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data; |
| 326 | struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb); |
| 327 | struct iwl_device_cmd *dev_cmd; |
| 328 | struct iwl_tx_cmd *tx_cmd; |
| 329 | |
| 330 | dev_cmd = iwl_trans_alloc_tx_cmd(mvm->trans); |
| 331 | |
| 332 | if (unlikely(!dev_cmd)) |
| 333 | return NULL; |
| 334 | |
| 335 | memset(dev_cmd, 0, sizeof(*dev_cmd)); |
| 336 | dev_cmd->hdr.cmd = TX_CMD; |
| 337 | tx_cmd = (struct iwl_tx_cmd *)dev_cmd->payload; |
| 338 | |
| 339 | if (info->control.hw_key) |
| 340 | iwl_mvm_set_tx_cmd_crypto(mvm, info, tx_cmd, skb, hdrlen); |
| 341 | |
| 342 | iwl_mvm_set_tx_cmd(mvm, skb, tx_cmd, info, sta_id); |
| 343 | |
| 344 | iwl_mvm_set_tx_cmd_rate(mvm, tx_cmd, info, sta, hdr->frame_control); |
| 345 | |
| 346 | memset(&info->status, 0, sizeof(info->status)); |
| 347 | |
| 348 | info->driver_data[0] = NULL; |
| 349 | info->driver_data[1] = dev_cmd; |
| 350 | |
| 351 | return dev_cmd; |
| 352 | } |
| 353 | |
| 354 | int iwl_mvm_tx_skb_non_sta(struct iwl_mvm *mvm, struct sk_buff *skb) |
| 355 | { |
| 356 | struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data; |
| 357 | struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb); |
| 358 | struct iwl_device_cmd *dev_cmd; |
| 359 | struct iwl_tx_cmd *tx_cmd; |
| 360 | u8 sta_id; |
| 361 | int hdrlen = ieee80211_hdrlen(hdr->frame_control); |
| 362 | |
| 363 | if (WARN_ON_ONCE(info->flags & IEEE80211_TX_CTL_AMPDU)) |
| 364 | return -1; |
| 365 | |
| 366 | if (WARN_ON_ONCE(info->flags & IEEE80211_TX_CTL_SEND_AFTER_DTIM && |
| 367 | (!info->control.vif || |
| 368 | info->hw_queue != info->control.vif->cab_queue))) |
| 369 | return -1; |
| 370 | |
| 371 | /* |
| 372 | * IWL_MVM_OFFCHANNEL_QUEUE is used for ROC packets that can be used |
| 373 | * in 2 different types of vifs, P2P & STATION. P2P uses the offchannel |
| 374 | * queue. STATION (HS2.0) uses the auxiliary context of the FW, |
| 375 | * and hence needs to be sent on the aux queue |
| 376 | */ |
| 377 | if (IEEE80211_SKB_CB(skb)->hw_queue == IWL_MVM_OFFCHANNEL_QUEUE && |
| 378 | info->control.vif->type == NL80211_IFTYPE_STATION) |
| 379 | IEEE80211_SKB_CB(skb)->hw_queue = mvm->aux_queue; |
| 380 | |
| 381 | /* |
| 382 | * If the interface on which the frame is sent is the P2P_DEVICE |
| 383 | * or an AP/GO interface use the broadcast station associated |
| 384 | * with it; otherwise if the interface is a managed interface |
| 385 | * use the AP station associated with it for multicast traffic |
| 386 | * (this is not possible for unicast packets as a TLDS discovery |
| 387 | * response are sent without a station entry); otherwise use the |
| 388 | * AUX station. |
| 389 | */ |
| 390 | sta_id = mvm->aux_sta.sta_id; |
| 391 | if (info->control.vif) { |
| 392 | struct iwl_mvm_vif *mvmvif = |
| 393 | iwl_mvm_vif_from_mac80211(info->control.vif); |
| 394 | |
| 395 | if (info->control.vif->type == NL80211_IFTYPE_P2P_DEVICE || |
| 396 | info->control.vif->type == NL80211_IFTYPE_AP) |
| 397 | sta_id = mvmvif->bcast_sta.sta_id; |
| 398 | else if (info->control.vif->type == NL80211_IFTYPE_STATION && |
| 399 | is_multicast_ether_addr(hdr->addr1)) { |
| 400 | u8 ap_sta_id = ACCESS_ONCE(mvmvif->ap_sta_id); |
| 401 | |
| 402 | if (ap_sta_id != IWL_MVM_STATION_COUNT) |
| 403 | sta_id = ap_sta_id; |
| 404 | } |
| 405 | } |
| 406 | |
| 407 | IWL_DEBUG_TX(mvm, "station Id %d, queue=%d\n", sta_id, info->hw_queue); |
| 408 | |
| 409 | dev_cmd = iwl_mvm_set_tx_params(mvm, skb, hdrlen, NULL, sta_id); |
| 410 | if (!dev_cmd) |
| 411 | return -1; |
| 412 | |
| 413 | /* From now on, we cannot access info->control */ |
| 414 | tx_cmd = (struct iwl_tx_cmd *)dev_cmd->payload; |
| 415 | |
| 416 | /* Copy MAC header from skb into command buffer */ |
| 417 | memcpy(tx_cmd->hdr, hdr, hdrlen); |
| 418 | |
| 419 | if (iwl_trans_tx(mvm->trans, skb, dev_cmd, info->hw_queue)) { |
| 420 | iwl_trans_free_tx_cmd(mvm->trans, dev_cmd); |
| 421 | return -1; |
| 422 | } |
| 423 | |
| 424 | /* |
| 425 | * Increase the pending frames counter, so that later when a reply comes |
| 426 | * in and the counter is decreased - we don't start getting negative |
| 427 | * values. |
| 428 | * Note that we don't need to make sure it isn't agg'd, since we're |
| 429 | * TXing non-sta |
| 430 | */ |
| 431 | atomic_inc(&mvm->pending_frames[sta_id]); |
| 432 | |
| 433 | return 0; |
| 434 | } |
| 435 | |
| 436 | /* |
| 437 | * Sets the fields in the Tx cmd that are crypto related |
| 438 | */ |
| 439 | int iwl_mvm_tx_skb(struct iwl_mvm *mvm, struct sk_buff *skb, |
| 440 | struct ieee80211_sta *sta) |
| 441 | { |
| 442 | struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data; |
| 443 | struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb); |
| 444 | struct iwl_mvm_sta *mvmsta; |
| 445 | struct iwl_device_cmd *dev_cmd; |
| 446 | struct iwl_tx_cmd *tx_cmd; |
| 447 | __le16 fc; |
| 448 | u16 seq_number = 0; |
| 449 | u8 tid = IWL_MAX_TID_COUNT; |
| 450 | u8 txq_id = info->hw_queue; |
| 451 | bool is_data_qos = false, is_ampdu = false; |
| 452 | int hdrlen; |
| 453 | |
| 454 | mvmsta = iwl_mvm_sta_from_mac80211(sta); |
| 455 | fc = hdr->frame_control; |
| 456 | hdrlen = ieee80211_hdrlen(fc); |
| 457 | |
| 458 | if (WARN_ON_ONCE(!mvmsta)) |
| 459 | return -1; |
| 460 | |
| 461 | if (WARN_ON_ONCE(mvmsta->sta_id == IWL_MVM_STATION_COUNT)) |
| 462 | return -1; |
| 463 | |
| 464 | dev_cmd = iwl_mvm_set_tx_params(mvm, skb, hdrlen, sta, mvmsta->sta_id); |
| 465 | if (!dev_cmd) |
| 466 | goto drop; |
| 467 | |
| 468 | tx_cmd = (struct iwl_tx_cmd *)dev_cmd->payload; |
| 469 | /* From now on, we cannot access info->control */ |
| 470 | |
| 471 | /* |
| 472 | * we handle that entirely ourselves -- for uAPSD the firmware |
| 473 | * will always send a notification, and for PS-Poll responses |
| 474 | * we'll notify mac80211 when getting frame status |
| 475 | */ |
| 476 | info->flags &= ~IEEE80211_TX_STATUS_EOSP; |
| 477 | |
| 478 | spin_lock(&mvmsta->lock); |
| 479 | |
| 480 | if (ieee80211_is_data_qos(fc) && !ieee80211_is_qos_nullfunc(fc)) { |
| 481 | u8 *qc = NULL; |
| 482 | qc = ieee80211_get_qos_ctl(hdr); |
| 483 | tid = qc[0] & IEEE80211_QOS_CTL_TID_MASK; |
| 484 | if (WARN_ON_ONCE(tid >= IWL_MAX_TID_COUNT)) |
| 485 | goto drop_unlock_sta; |
| 486 | |
| 487 | seq_number = mvmsta->tid_data[tid].seq_number; |
| 488 | seq_number &= IEEE80211_SCTL_SEQ; |
| 489 | hdr->seq_ctrl &= cpu_to_le16(IEEE80211_SCTL_FRAG); |
| 490 | hdr->seq_ctrl |= cpu_to_le16(seq_number); |
| 491 | is_data_qos = true; |
| 492 | is_ampdu = info->flags & IEEE80211_TX_CTL_AMPDU; |
| 493 | } |
| 494 | |
| 495 | /* Copy MAC header from skb into command buffer */ |
| 496 | memcpy(tx_cmd->hdr, hdr, hdrlen); |
| 497 | |
| 498 | WARN_ON_ONCE(info->flags & IEEE80211_TX_CTL_SEND_AFTER_DTIM); |
| 499 | |
| 500 | if (sta->tdls) { |
| 501 | /* default to TID 0 for non-QoS packets */ |
| 502 | u8 tdls_tid = tid == IWL_MAX_TID_COUNT ? 0 : tid; |
| 503 | |
| 504 | txq_id = mvmsta->hw_queue[tid_to_mac80211_ac[tdls_tid]]; |
| 505 | } |
| 506 | |
| 507 | if (is_ampdu) { |
| 508 | if (WARN_ON_ONCE(mvmsta->tid_data[tid].state != IWL_AGG_ON)) |
| 509 | goto drop_unlock_sta; |
| 510 | txq_id = mvmsta->tid_data[tid].txq_id; |
| 511 | } |
| 512 | |
| 513 | IWL_DEBUG_TX(mvm, "TX to [%d|%d] Q:%d - seq: 0x%x\n", mvmsta->sta_id, |
| 514 | tid, txq_id, IEEE80211_SEQ_TO_SN(seq_number)); |
| 515 | |
| 516 | if (iwl_trans_tx(mvm->trans, skb, dev_cmd, txq_id)) |
| 517 | goto drop_unlock_sta; |
| 518 | |
| 519 | if (is_data_qos && !ieee80211_has_morefrags(fc)) |
| 520 | mvmsta->tid_data[tid].seq_number = seq_number + 0x10; |
| 521 | |
| 522 | spin_unlock(&mvmsta->lock); |
| 523 | |
| 524 | if (txq_id < mvm->first_agg_queue) |
| 525 | atomic_inc(&mvm->pending_frames[mvmsta->sta_id]); |
| 526 | |
| 527 | return 0; |
| 528 | |
| 529 | drop_unlock_sta: |
| 530 | iwl_trans_free_tx_cmd(mvm->trans, dev_cmd); |
| 531 | spin_unlock(&mvmsta->lock); |
| 532 | drop: |
| 533 | return -1; |
| 534 | } |
| 535 | |
| 536 | static void iwl_mvm_check_ratid_empty(struct iwl_mvm *mvm, |
| 537 | struct ieee80211_sta *sta, u8 tid) |
| 538 | { |
| 539 | struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta); |
| 540 | struct iwl_mvm_tid_data *tid_data = &mvmsta->tid_data[tid]; |
| 541 | struct ieee80211_vif *vif = mvmsta->vif; |
| 542 | |
| 543 | lockdep_assert_held(&mvmsta->lock); |
| 544 | |
| 545 | if ((tid_data->state == IWL_AGG_ON || |
| 546 | tid_data->state == IWL_EMPTYING_HW_QUEUE_DELBA) && |
| 547 | iwl_mvm_tid_queued(tid_data) == 0) { |
| 548 | /* |
| 549 | * Now that this aggregation queue is empty tell mac80211 so it |
| 550 | * knows we no longer have frames buffered for the station on |
| 551 | * this TID (for the TIM bitmap calculation.) |
| 552 | */ |
| 553 | ieee80211_sta_set_buffered(sta, tid, false); |
| 554 | } |
| 555 | |
| 556 | if (tid_data->ssn != tid_data->next_reclaimed) |
| 557 | return; |
| 558 | |
| 559 | switch (tid_data->state) { |
| 560 | case IWL_EMPTYING_HW_QUEUE_ADDBA: |
| 561 | IWL_DEBUG_TX_QUEUES(mvm, |
| 562 | "Can continue addBA flow ssn = next_recl = %d\n", |
| 563 | tid_data->next_reclaimed); |
| 564 | tid_data->state = IWL_AGG_STARTING; |
| 565 | ieee80211_start_tx_ba_cb_irqsafe(vif, sta->addr, tid); |
| 566 | break; |
| 567 | |
| 568 | case IWL_EMPTYING_HW_QUEUE_DELBA: |
| 569 | IWL_DEBUG_TX_QUEUES(mvm, |
| 570 | "Can continue DELBA flow ssn = next_recl = %d\n", |
| 571 | tid_data->next_reclaimed); |
| 572 | iwl_mvm_disable_txq(mvm, tid_data->txq_id, |
| 573 | vif->hw_queue[tid_to_mac80211_ac[tid]], tid, |
| 574 | CMD_ASYNC); |
| 575 | tid_data->state = IWL_AGG_OFF; |
| 576 | ieee80211_stop_tx_ba_cb_irqsafe(vif, sta->addr, tid); |
| 577 | break; |
| 578 | |
| 579 | default: |
| 580 | break; |
| 581 | } |
| 582 | } |
| 583 | |
| 584 | #ifdef CONFIG_IWLWIFI_DEBUG |
| 585 | const char *iwl_mvm_get_tx_fail_reason(u32 status) |
| 586 | { |
| 587 | #define TX_STATUS_FAIL(x) case TX_STATUS_FAIL_ ## x: return #x |
| 588 | #define TX_STATUS_POSTPONE(x) case TX_STATUS_POSTPONE_ ## x: return #x |
| 589 | |
| 590 | switch (status & TX_STATUS_MSK) { |
| 591 | case TX_STATUS_SUCCESS: |
| 592 | return "SUCCESS"; |
| 593 | TX_STATUS_POSTPONE(DELAY); |
| 594 | TX_STATUS_POSTPONE(FEW_BYTES); |
| 595 | TX_STATUS_POSTPONE(BT_PRIO); |
| 596 | TX_STATUS_POSTPONE(QUIET_PERIOD); |
| 597 | TX_STATUS_POSTPONE(CALC_TTAK); |
| 598 | TX_STATUS_FAIL(INTERNAL_CROSSED_RETRY); |
| 599 | TX_STATUS_FAIL(SHORT_LIMIT); |
| 600 | TX_STATUS_FAIL(LONG_LIMIT); |
| 601 | TX_STATUS_FAIL(UNDERRUN); |
| 602 | TX_STATUS_FAIL(DRAIN_FLOW); |
| 603 | TX_STATUS_FAIL(RFKILL_FLUSH); |
| 604 | TX_STATUS_FAIL(LIFE_EXPIRE); |
| 605 | TX_STATUS_FAIL(DEST_PS); |
| 606 | TX_STATUS_FAIL(HOST_ABORTED); |
| 607 | TX_STATUS_FAIL(BT_RETRY); |
| 608 | TX_STATUS_FAIL(STA_INVALID); |
| 609 | TX_STATUS_FAIL(FRAG_DROPPED); |
| 610 | TX_STATUS_FAIL(TID_DISABLE); |
| 611 | TX_STATUS_FAIL(FIFO_FLUSHED); |
| 612 | TX_STATUS_FAIL(SMALL_CF_POLL); |
| 613 | TX_STATUS_FAIL(FW_DROP); |
| 614 | TX_STATUS_FAIL(STA_COLOR_MISMATCH); |
| 615 | } |
| 616 | |
| 617 | return "UNKNOWN"; |
| 618 | |
| 619 | #undef TX_STATUS_FAIL |
| 620 | #undef TX_STATUS_POSTPONE |
| 621 | } |
| 622 | #endif /* CONFIG_IWLWIFI_DEBUG */ |
| 623 | |
| 624 | void iwl_mvm_hwrate_to_tx_rate(u32 rate_n_flags, |
| 625 | enum ieee80211_band band, |
| 626 | struct ieee80211_tx_rate *r) |
| 627 | { |
| 628 | if (rate_n_flags & RATE_HT_MCS_GF_MSK) |
| 629 | r->flags |= IEEE80211_TX_RC_GREEN_FIELD; |
| 630 | switch (rate_n_flags & RATE_MCS_CHAN_WIDTH_MSK) { |
| 631 | case RATE_MCS_CHAN_WIDTH_20: |
| 632 | break; |
| 633 | case RATE_MCS_CHAN_WIDTH_40: |
| 634 | r->flags |= IEEE80211_TX_RC_40_MHZ_WIDTH; |
| 635 | break; |
| 636 | case RATE_MCS_CHAN_WIDTH_80: |
| 637 | r->flags |= IEEE80211_TX_RC_80_MHZ_WIDTH; |
| 638 | break; |
| 639 | case RATE_MCS_CHAN_WIDTH_160: |
| 640 | r->flags |= IEEE80211_TX_RC_160_MHZ_WIDTH; |
| 641 | break; |
| 642 | } |
| 643 | if (rate_n_flags & RATE_MCS_SGI_MSK) |
| 644 | r->flags |= IEEE80211_TX_RC_SHORT_GI; |
| 645 | if (rate_n_flags & RATE_MCS_HT_MSK) { |
| 646 | r->flags |= IEEE80211_TX_RC_MCS; |
| 647 | r->idx = rate_n_flags & RATE_HT_MCS_INDEX_MSK; |
| 648 | } else if (rate_n_flags & RATE_MCS_VHT_MSK) { |
| 649 | ieee80211_rate_set_vht( |
| 650 | r, rate_n_flags & RATE_VHT_MCS_RATE_CODE_MSK, |
| 651 | ((rate_n_flags & RATE_VHT_MCS_NSS_MSK) >> |
| 652 | RATE_VHT_MCS_NSS_POS) + 1); |
| 653 | r->flags |= IEEE80211_TX_RC_VHT_MCS; |
| 654 | } else { |
| 655 | r->idx = iwl_mvm_legacy_rate_to_mac80211_idx(rate_n_flags, |
| 656 | band); |
| 657 | } |
| 658 | } |
| 659 | |
| 660 | /** |
| 661 | * translate ucode response to mac80211 tx status control values |
| 662 | */ |
| 663 | static void iwl_mvm_hwrate_to_tx_status(u32 rate_n_flags, |
| 664 | struct ieee80211_tx_info *info) |
| 665 | { |
| 666 | struct ieee80211_tx_rate *r = &info->status.rates[0]; |
| 667 | |
| 668 | info->status.antenna = |
| 669 | ((rate_n_flags & RATE_MCS_ANT_ABC_MSK) >> RATE_MCS_ANT_POS); |
| 670 | iwl_mvm_hwrate_to_tx_rate(rate_n_flags, info->band, r); |
| 671 | } |
| 672 | |
| 673 | static void iwl_mvm_rx_tx_cmd_single(struct iwl_mvm *mvm, |
| 674 | struct iwl_rx_packet *pkt) |
| 675 | { |
| 676 | struct ieee80211_sta *sta; |
| 677 | u16 sequence = le16_to_cpu(pkt->hdr.sequence); |
| 678 | int txq_id = SEQ_TO_QUEUE(sequence); |
| 679 | struct iwl_mvm_tx_resp *tx_resp = (void *)pkt->data; |
| 680 | int sta_id = IWL_MVM_TX_RES_GET_RA(tx_resp->ra_tid); |
| 681 | int tid = IWL_MVM_TX_RES_GET_TID(tx_resp->ra_tid); |
| 682 | u32 status = le16_to_cpu(tx_resp->status.status); |
| 683 | u16 ssn = iwl_mvm_get_scd_ssn(tx_resp); |
| 684 | struct iwl_mvm_sta *mvmsta; |
| 685 | struct sk_buff_head skbs; |
| 686 | u8 skb_freed = 0; |
| 687 | u16 next_reclaimed, seq_ctl; |
| 688 | |
| 689 | __skb_queue_head_init(&skbs); |
| 690 | |
| 691 | seq_ctl = le16_to_cpu(tx_resp->seq_ctl); |
| 692 | |
| 693 | /* we can free until ssn % q.n_bd not inclusive */ |
| 694 | iwl_trans_reclaim(mvm->trans, txq_id, ssn, &skbs); |
| 695 | |
| 696 | while (!skb_queue_empty(&skbs)) { |
| 697 | struct sk_buff *skb = __skb_dequeue(&skbs); |
| 698 | struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb); |
| 699 | |
| 700 | skb_freed++; |
| 701 | |
| 702 | iwl_trans_free_tx_cmd(mvm->trans, info->driver_data[1]); |
| 703 | |
| 704 | memset(&info->status, 0, sizeof(info->status)); |
| 705 | |
| 706 | info->flags &= ~IEEE80211_TX_CTL_AMPDU; |
| 707 | |
| 708 | /* inform mac80211 about what happened with the frame */ |
| 709 | switch (status & TX_STATUS_MSK) { |
| 710 | case TX_STATUS_SUCCESS: |
| 711 | case TX_STATUS_DIRECT_DONE: |
| 712 | info->flags |= IEEE80211_TX_STAT_ACK; |
| 713 | break; |
| 714 | case TX_STATUS_FAIL_DEST_PS: |
| 715 | info->flags |= IEEE80211_TX_STAT_TX_FILTERED; |
| 716 | break; |
| 717 | default: |
| 718 | break; |
| 719 | } |
| 720 | |
| 721 | info->status.rates[0].count = tx_resp->failure_frame + 1; |
| 722 | iwl_mvm_hwrate_to_tx_status(le32_to_cpu(tx_resp->initial_rate), |
| 723 | info); |
| 724 | info->status.status_driver_data[1] = |
| 725 | (void *)(uintptr_t)le32_to_cpu(tx_resp->initial_rate); |
| 726 | |
| 727 | /* Single frame failure in an AMPDU queue => send BAR */ |
| 728 | if (txq_id >= mvm->first_agg_queue && |
| 729 | !(info->flags & IEEE80211_TX_STAT_ACK) && |
| 730 | !(info->flags & IEEE80211_TX_STAT_TX_FILTERED)) |
| 731 | info->flags |= IEEE80211_TX_STAT_AMPDU_NO_BACK; |
| 732 | |
| 733 | /* W/A FW bug: seq_ctl is wrong when the status isn't success */ |
| 734 | if (status != TX_STATUS_SUCCESS) { |
| 735 | struct ieee80211_hdr *hdr = (void *)skb->data; |
| 736 | seq_ctl = le16_to_cpu(hdr->seq_ctrl); |
| 737 | } |
| 738 | |
| 739 | /* |
| 740 | * TODO: this is not accurate if we are freeing more than one |
| 741 | * packet. |
| 742 | */ |
| 743 | info->status.tx_time = |
| 744 | le16_to_cpu(tx_resp->wireless_media_time); |
| 745 | BUILD_BUG_ON(ARRAY_SIZE(info->status.status_driver_data) < 1); |
| 746 | info->status.status_driver_data[0] = |
| 747 | (void *)(uintptr_t)tx_resp->reduced_tpc; |
| 748 | |
| 749 | ieee80211_tx_status(mvm->hw, skb); |
| 750 | } |
| 751 | |
| 752 | if (txq_id >= mvm->first_agg_queue) { |
| 753 | /* If this is an aggregation queue, we use the ssn since: |
| 754 | * ssn = wifi seq_num % 256. |
| 755 | * The seq_ctl is the sequence control of the packet to which |
| 756 | * this Tx response relates. But if there is a hole in the |
| 757 | * bitmap of the BA we received, this Tx response may allow to |
| 758 | * reclaim the hole and all the subsequent packets that were |
| 759 | * already acked. In that case, seq_ctl != ssn, and the next |
| 760 | * packet to be reclaimed will be ssn and not seq_ctl. In that |
| 761 | * case, several packets will be reclaimed even if |
| 762 | * frame_count = 1. |
| 763 | * |
| 764 | * The ssn is the index (% 256) of the latest packet that has |
| 765 | * treated (acked / dropped) + 1. |
| 766 | */ |
| 767 | next_reclaimed = ssn; |
| 768 | } else { |
| 769 | /* The next packet to be reclaimed is the one after this one */ |
| 770 | next_reclaimed = IEEE80211_SEQ_TO_SN(seq_ctl + 0x10); |
| 771 | } |
| 772 | |
| 773 | IWL_DEBUG_TX_REPLY(mvm, |
| 774 | "TXQ %d status %s (0x%08x)\n", |
| 775 | txq_id, iwl_mvm_get_tx_fail_reason(status), status); |
| 776 | |
| 777 | IWL_DEBUG_TX_REPLY(mvm, |
| 778 | "\t\t\t\tinitial_rate 0x%x retries %d, idx=%d ssn=%d next_reclaimed=0x%x seq_ctl=0x%x\n", |
| 779 | le32_to_cpu(tx_resp->initial_rate), |
| 780 | tx_resp->failure_frame, SEQ_TO_INDEX(sequence), |
| 781 | ssn, next_reclaimed, seq_ctl); |
| 782 | |
| 783 | rcu_read_lock(); |
| 784 | |
| 785 | sta = rcu_dereference(mvm->fw_id_to_mac_id[sta_id]); |
| 786 | /* |
| 787 | * sta can't be NULL otherwise it'd mean that the sta has been freed in |
| 788 | * the firmware while we still have packets for it in the Tx queues. |
| 789 | */ |
| 790 | if (WARN_ON_ONCE(!sta)) |
| 791 | goto out; |
| 792 | |
| 793 | if (!IS_ERR(sta)) { |
| 794 | mvmsta = iwl_mvm_sta_from_mac80211(sta); |
| 795 | |
| 796 | if (tid != IWL_TID_NON_QOS) { |
| 797 | struct iwl_mvm_tid_data *tid_data = |
| 798 | &mvmsta->tid_data[tid]; |
| 799 | |
| 800 | spin_lock_bh(&mvmsta->lock); |
| 801 | tid_data->next_reclaimed = next_reclaimed; |
| 802 | IWL_DEBUG_TX_REPLY(mvm, "Next reclaimed packet:%d\n", |
| 803 | next_reclaimed); |
| 804 | iwl_mvm_check_ratid_empty(mvm, sta, tid); |
| 805 | spin_unlock_bh(&mvmsta->lock); |
| 806 | } |
| 807 | |
| 808 | if (mvmsta->next_status_eosp) { |
| 809 | mvmsta->next_status_eosp = false; |
| 810 | ieee80211_sta_eosp(sta); |
| 811 | } |
| 812 | } else { |
| 813 | mvmsta = NULL; |
| 814 | } |
| 815 | |
| 816 | /* |
| 817 | * If the txq is not an AMPDU queue, there is no chance we freed |
| 818 | * several skbs. Check that out... |
| 819 | */ |
| 820 | if (txq_id >= mvm->first_agg_queue) |
| 821 | goto out; |
| 822 | |
| 823 | /* We can't free more than one frame at once on a shared queue */ |
| 824 | WARN_ON(skb_freed > 1); |
| 825 | |
| 826 | /* If we have still frames for this STA nothing to do here */ |
| 827 | if (!atomic_sub_and_test(skb_freed, &mvm->pending_frames[sta_id])) |
| 828 | goto out; |
| 829 | |
| 830 | if (mvmsta && mvmsta->vif->type == NL80211_IFTYPE_AP) { |
| 831 | |
| 832 | /* |
| 833 | * If there are no pending frames for this STA and |
| 834 | * the tx to this station is not disabled, notify |
| 835 | * mac80211 that this station can now wake up in its |
| 836 | * STA table. |
| 837 | * If mvmsta is not NULL, sta is valid. |
| 838 | */ |
| 839 | |
| 840 | spin_lock_bh(&mvmsta->lock); |
| 841 | |
| 842 | if (!mvmsta->disable_tx) |
| 843 | ieee80211_sta_block_awake(mvm->hw, sta, false); |
| 844 | |
| 845 | spin_unlock_bh(&mvmsta->lock); |
| 846 | } |
| 847 | |
| 848 | if (PTR_ERR(sta) == -EBUSY || PTR_ERR(sta) == -ENOENT) { |
| 849 | /* |
| 850 | * We are draining and this was the last packet - pre_rcu_remove |
| 851 | * has been called already. We might be after the |
| 852 | * synchronize_net already. |
| 853 | * Don't rely on iwl_mvm_rm_sta to see the empty Tx queues. |
| 854 | */ |
| 855 | set_bit(sta_id, mvm->sta_drained); |
| 856 | schedule_work(&mvm->sta_drained_wk); |
| 857 | } |
| 858 | |
| 859 | out: |
| 860 | rcu_read_unlock(); |
| 861 | } |
| 862 | |
| 863 | #ifdef CONFIG_IWLWIFI_DEBUG |
| 864 | #define AGG_TX_STATE_(x) case AGG_TX_STATE_ ## x: return #x |
| 865 | static const char *iwl_get_agg_tx_status(u16 status) |
| 866 | { |
| 867 | switch (status & AGG_TX_STATE_STATUS_MSK) { |
| 868 | AGG_TX_STATE_(TRANSMITTED); |
| 869 | AGG_TX_STATE_(UNDERRUN); |
| 870 | AGG_TX_STATE_(BT_PRIO); |
| 871 | AGG_TX_STATE_(FEW_BYTES); |
| 872 | AGG_TX_STATE_(ABORT); |
| 873 | AGG_TX_STATE_(LAST_SENT_TTL); |
| 874 | AGG_TX_STATE_(LAST_SENT_TRY_CNT); |
| 875 | AGG_TX_STATE_(LAST_SENT_BT_KILL); |
| 876 | AGG_TX_STATE_(SCD_QUERY); |
| 877 | AGG_TX_STATE_(TEST_BAD_CRC32); |
| 878 | AGG_TX_STATE_(RESPONSE); |
| 879 | AGG_TX_STATE_(DUMP_TX); |
| 880 | AGG_TX_STATE_(DELAY_TX); |
| 881 | } |
| 882 | |
| 883 | return "UNKNOWN"; |
| 884 | } |
| 885 | |
| 886 | static void iwl_mvm_rx_tx_cmd_agg_dbg(struct iwl_mvm *mvm, |
| 887 | struct iwl_rx_packet *pkt) |
| 888 | { |
| 889 | struct iwl_mvm_tx_resp *tx_resp = (void *)pkt->data; |
| 890 | struct agg_tx_status *frame_status = &tx_resp->status; |
| 891 | int i; |
| 892 | |
| 893 | for (i = 0; i < tx_resp->frame_count; i++) { |
| 894 | u16 fstatus = le16_to_cpu(frame_status[i].status); |
| 895 | |
| 896 | IWL_DEBUG_TX_REPLY(mvm, |
| 897 | "status %s (0x%04x), try-count (%d) seq (0x%x)\n", |
| 898 | iwl_get_agg_tx_status(fstatus), |
| 899 | fstatus & AGG_TX_STATE_STATUS_MSK, |
| 900 | (fstatus & AGG_TX_STATE_TRY_CNT_MSK) >> |
| 901 | AGG_TX_STATE_TRY_CNT_POS, |
| 902 | le16_to_cpu(frame_status[i].sequence)); |
| 903 | } |
| 904 | } |
| 905 | #else |
| 906 | static void iwl_mvm_rx_tx_cmd_agg_dbg(struct iwl_mvm *mvm, |
| 907 | struct iwl_rx_packet *pkt) |
| 908 | {} |
| 909 | #endif /* CONFIG_IWLWIFI_DEBUG */ |
| 910 | |
| 911 | static void iwl_mvm_rx_tx_cmd_agg(struct iwl_mvm *mvm, |
| 912 | struct iwl_rx_packet *pkt) |
| 913 | { |
| 914 | struct iwl_mvm_tx_resp *tx_resp = (void *)pkt->data; |
| 915 | int sta_id = IWL_MVM_TX_RES_GET_RA(tx_resp->ra_tid); |
| 916 | int tid = IWL_MVM_TX_RES_GET_TID(tx_resp->ra_tid); |
| 917 | u16 sequence = le16_to_cpu(pkt->hdr.sequence); |
| 918 | struct ieee80211_sta *sta; |
| 919 | |
| 920 | if (WARN_ON_ONCE(SEQ_TO_QUEUE(sequence) < mvm->first_agg_queue)) |
| 921 | return; |
| 922 | |
| 923 | if (WARN_ON_ONCE(tid == IWL_TID_NON_QOS)) |
| 924 | return; |
| 925 | |
| 926 | iwl_mvm_rx_tx_cmd_agg_dbg(mvm, pkt); |
| 927 | |
| 928 | rcu_read_lock(); |
| 929 | |
| 930 | sta = rcu_dereference(mvm->fw_id_to_mac_id[sta_id]); |
| 931 | |
| 932 | if (!WARN_ON_ONCE(IS_ERR_OR_NULL(sta))) { |
| 933 | struct iwl_mvm_sta *mvmsta = iwl_mvm_sta_from_mac80211(sta); |
| 934 | mvmsta->tid_data[tid].rate_n_flags = |
| 935 | le32_to_cpu(tx_resp->initial_rate); |
| 936 | mvmsta->tid_data[tid].reduced_tpc = tx_resp->reduced_tpc; |
| 937 | mvmsta->tid_data[tid].tx_time = |
| 938 | le16_to_cpu(tx_resp->wireless_media_time); |
| 939 | } |
| 940 | |
| 941 | rcu_read_unlock(); |
| 942 | } |
| 943 | |
| 944 | void iwl_mvm_rx_tx_cmd(struct iwl_mvm *mvm, struct iwl_rx_cmd_buffer *rxb) |
| 945 | { |
| 946 | struct iwl_rx_packet *pkt = rxb_addr(rxb); |
| 947 | struct iwl_mvm_tx_resp *tx_resp = (void *)pkt->data; |
| 948 | |
| 949 | if (tx_resp->frame_count == 1) |
| 950 | iwl_mvm_rx_tx_cmd_single(mvm, pkt); |
| 951 | else |
| 952 | iwl_mvm_rx_tx_cmd_agg(mvm, pkt); |
| 953 | } |
| 954 | |
| 955 | static void iwl_mvm_tx_info_from_ba_notif(struct ieee80211_tx_info *info, |
| 956 | struct iwl_mvm_ba_notif *ba_notif, |
| 957 | struct iwl_mvm_tid_data *tid_data) |
| 958 | { |
| 959 | info->flags |= IEEE80211_TX_STAT_AMPDU; |
| 960 | info->status.ampdu_ack_len = ba_notif->txed_2_done; |
| 961 | info->status.ampdu_len = ba_notif->txed; |
| 962 | iwl_mvm_hwrate_to_tx_status(tid_data->rate_n_flags, |
| 963 | info); |
| 964 | /* TODO: not accounted if the whole A-MPDU failed */ |
| 965 | info->status.tx_time = tid_data->tx_time; |
| 966 | info->status.status_driver_data[0] = |
| 967 | (void *)(uintptr_t)tid_data->reduced_tpc; |
| 968 | info->status.status_driver_data[1] = |
| 969 | (void *)(uintptr_t)tid_data->rate_n_flags; |
| 970 | } |
| 971 | |
| 972 | void iwl_mvm_rx_ba_notif(struct iwl_mvm *mvm, struct iwl_rx_cmd_buffer *rxb) |
| 973 | { |
| 974 | struct iwl_rx_packet *pkt = rxb_addr(rxb); |
| 975 | struct iwl_mvm_ba_notif *ba_notif = (void *)pkt->data; |
| 976 | struct sk_buff_head reclaimed_skbs; |
| 977 | struct iwl_mvm_tid_data *tid_data; |
| 978 | struct ieee80211_sta *sta; |
| 979 | struct iwl_mvm_sta *mvmsta; |
| 980 | struct sk_buff *skb; |
| 981 | int sta_id, tid, freed; |
| 982 | /* "flow" corresponds to Tx queue */ |
| 983 | u16 scd_flow = le16_to_cpu(ba_notif->scd_flow); |
| 984 | /* "ssn" is start of block-ack Tx window, corresponds to index |
| 985 | * (in Tx queue's circular buffer) of first TFD/frame in window */ |
| 986 | u16 ba_resp_scd_ssn = le16_to_cpu(ba_notif->scd_ssn); |
| 987 | |
| 988 | sta_id = ba_notif->sta_id; |
| 989 | tid = ba_notif->tid; |
| 990 | |
| 991 | if (WARN_ONCE(sta_id >= IWL_MVM_STATION_COUNT || |
| 992 | tid >= IWL_MAX_TID_COUNT, |
| 993 | "sta_id %d tid %d", sta_id, tid)) |
| 994 | return; |
| 995 | |
| 996 | rcu_read_lock(); |
| 997 | |
| 998 | sta = rcu_dereference(mvm->fw_id_to_mac_id[sta_id]); |
| 999 | |
| 1000 | /* Reclaiming frames for a station that has been deleted ? */ |
| 1001 | if (WARN_ON_ONCE(IS_ERR_OR_NULL(sta))) { |
| 1002 | rcu_read_unlock(); |
| 1003 | return; |
| 1004 | } |
| 1005 | |
| 1006 | mvmsta = iwl_mvm_sta_from_mac80211(sta); |
| 1007 | tid_data = &mvmsta->tid_data[tid]; |
| 1008 | |
| 1009 | if (tid_data->txq_id != scd_flow) { |
| 1010 | IWL_ERR(mvm, |
| 1011 | "invalid BA notification: Q %d, tid %d, flow %d\n", |
| 1012 | tid_data->txq_id, tid, scd_flow); |
| 1013 | rcu_read_unlock(); |
| 1014 | return; |
| 1015 | } |
| 1016 | |
| 1017 | spin_lock_bh(&mvmsta->lock); |
| 1018 | |
| 1019 | __skb_queue_head_init(&reclaimed_skbs); |
| 1020 | |
| 1021 | /* |
| 1022 | * Release all TFDs before the SSN, i.e. all TFDs in front of |
| 1023 | * block-ack window (we assume that they've been successfully |
| 1024 | * transmitted ... if not, it's too late anyway). |
| 1025 | */ |
| 1026 | iwl_trans_reclaim(mvm->trans, scd_flow, ba_resp_scd_ssn, |
| 1027 | &reclaimed_skbs); |
| 1028 | |
| 1029 | IWL_DEBUG_TX_REPLY(mvm, |
| 1030 | "BA_NOTIFICATION Received from %pM, sta_id = %d\n", |
| 1031 | (u8 *)&ba_notif->sta_addr_lo32, |
| 1032 | ba_notif->sta_id); |
| 1033 | IWL_DEBUG_TX_REPLY(mvm, |
| 1034 | "TID = %d, SeqCtl = %d, bitmap = 0x%llx, scd_flow = %d, scd_ssn = %d sent:%d, acked:%d\n", |
| 1035 | ba_notif->tid, le16_to_cpu(ba_notif->seq_ctl), |
| 1036 | (unsigned long long)le64_to_cpu(ba_notif->bitmap), |
| 1037 | scd_flow, ba_resp_scd_ssn, ba_notif->txed, |
| 1038 | ba_notif->txed_2_done); |
| 1039 | |
| 1040 | tid_data->next_reclaimed = ba_resp_scd_ssn; |
| 1041 | |
| 1042 | iwl_mvm_check_ratid_empty(mvm, sta, tid); |
| 1043 | |
| 1044 | freed = 0; |
| 1045 | |
| 1046 | skb_queue_walk(&reclaimed_skbs, skb) { |
| 1047 | struct ieee80211_hdr *hdr = (void *)skb->data; |
| 1048 | struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb); |
| 1049 | |
| 1050 | if (ieee80211_is_data_qos(hdr->frame_control)) |
| 1051 | freed++; |
| 1052 | else |
| 1053 | WARN_ON_ONCE(1); |
| 1054 | |
| 1055 | iwl_trans_free_tx_cmd(mvm->trans, info->driver_data[1]); |
| 1056 | |
| 1057 | memset(&info->status, 0, sizeof(info->status)); |
| 1058 | /* Packet was transmitted successfully, failures come as single |
| 1059 | * frames because before failing a frame the firmware transmits |
| 1060 | * it without aggregation at least once. |
| 1061 | */ |
| 1062 | info->flags |= IEEE80211_TX_STAT_ACK; |
| 1063 | |
| 1064 | /* this is the first skb we deliver in this batch */ |
| 1065 | /* put the rate scaling data there */ |
| 1066 | if (freed == 1) |
| 1067 | iwl_mvm_tx_info_from_ba_notif(info, ba_notif, tid_data); |
| 1068 | } |
| 1069 | |
| 1070 | spin_unlock_bh(&mvmsta->lock); |
| 1071 | |
| 1072 | /* We got a BA notif with 0 acked or scd_ssn didn't progress which is |
| 1073 | * possible (i.e. first MPDU in the aggregation wasn't acked) |
| 1074 | * Still it's important to update RS about sent vs. acked. |
| 1075 | */ |
| 1076 | if (skb_queue_empty(&reclaimed_skbs)) { |
| 1077 | struct ieee80211_tx_info ba_info = {}; |
| 1078 | struct ieee80211_chanctx_conf *chanctx_conf = NULL; |
| 1079 | |
| 1080 | if (mvmsta->vif) |
| 1081 | chanctx_conf = |
| 1082 | rcu_dereference(mvmsta->vif->chanctx_conf); |
| 1083 | |
| 1084 | if (WARN_ON_ONCE(!chanctx_conf)) |
| 1085 | goto out; |
| 1086 | |
| 1087 | ba_info.band = chanctx_conf->def.chan->band; |
| 1088 | iwl_mvm_tx_info_from_ba_notif(&ba_info, ba_notif, tid_data); |
| 1089 | |
| 1090 | IWL_DEBUG_TX_REPLY(mvm, "No reclaim. Update rs directly\n"); |
| 1091 | iwl_mvm_rs_tx_status(mvm, sta, tid, &ba_info); |
| 1092 | } |
| 1093 | |
| 1094 | out: |
| 1095 | rcu_read_unlock(); |
| 1096 | |
| 1097 | while (!skb_queue_empty(&reclaimed_skbs)) { |
| 1098 | skb = __skb_dequeue(&reclaimed_skbs); |
| 1099 | ieee80211_tx_status(mvm->hw, skb); |
| 1100 | } |
| 1101 | } |
| 1102 | |
| 1103 | /* |
| 1104 | * Note that there are transports that buffer frames before they reach |
| 1105 | * the firmware. This means that after flush_tx_path is called, the |
| 1106 | * queue might not be empty. The race-free way to handle this is to: |
| 1107 | * 1) set the station as draining |
| 1108 | * 2) flush the Tx path |
| 1109 | * 3) wait for the transport queues to be empty |
| 1110 | */ |
| 1111 | int iwl_mvm_flush_tx_path(struct iwl_mvm *mvm, u32 tfd_msk, u32 flags) |
| 1112 | { |
| 1113 | int ret; |
| 1114 | struct iwl_tx_path_flush_cmd flush_cmd = { |
| 1115 | .queues_ctl = cpu_to_le32(tfd_msk), |
| 1116 | .flush_ctl = cpu_to_le16(DUMP_TX_FIFO_FLUSH), |
| 1117 | }; |
| 1118 | |
| 1119 | ret = iwl_mvm_send_cmd_pdu(mvm, TXPATH_FLUSH, flags, |
| 1120 | sizeof(flush_cmd), &flush_cmd); |
| 1121 | if (ret) |
| 1122 | IWL_ERR(mvm, "Failed to send flush command (%d)\n", ret); |
| 1123 | return ret; |
| 1124 | } |