1/*
2 * mac80211 glue code for mac80211 Prism54 drivers
3 *
4 * Copyright (c) 2006, Michael Wu <flamingice@sourmilk.net>
5 * Copyright (c) 2007-2009, Christian Lamparter <chunkeey@web.de>
6 * Copyright 2008, Johannes Berg <johannes@sipsolutions.net>
7 *
8 * Based on:
9 * - the islsm (softmac prism54) driver, which is:
10 *   Copyright 2004-2006 Jean-Baptiste Note <jbnote@gmail.com>, et al.
11 * - stlc45xx driver
12 *   Copyright (C) 2008 Nokia Corporation and/or its subsidiary(-ies).
13 *
14 * This program is free software; you can redistribute it and/or modify
15 * it under the terms of the GNU General Public License version 2 as
16 * published by the Free Software Foundation.
17 */
18
19#include <linux/slab.h>
20#include <linux/firmware.h>
21#include <linux/etherdevice.h>
22#include <linux/module.h>
23
24#include <net/mac80211.h>
25
26#include "p54.h"
27#include "lmac.h"
28
29static bool modparam_nohwcrypt;
30module_param_named(nohwcrypt, modparam_nohwcrypt, bool, S_IRUGO);
31MODULE_PARM_DESC(nohwcrypt, "Disable hardware encryption.");
32MODULE_AUTHOR("Michael Wu <flamingice@sourmilk.net>");
33MODULE_DESCRIPTION("Softmac Prism54 common code");
34MODULE_LICENSE("GPL");
35MODULE_ALIAS("prism54common");
36
37static int p54_sta_add_remove(struct ieee80211_hw *hw,
38			      struct ieee80211_vif *vif,
39			      struct ieee80211_sta *sta)
40{
41	struct p54_common *priv = hw->priv;
42
43	/*
44	 * Notify the firmware that we don't want or we don't
45	 * need to buffer frames for this station anymore.
46	 */
47
48	p54_sta_unlock(priv, sta->addr);
49
50	return 0;
51}
52
53static void p54_sta_notify(struct ieee80211_hw *dev, struct ieee80211_vif *vif,
54			      enum sta_notify_cmd notify_cmd,
55			      struct ieee80211_sta *sta)
56{
57	struct p54_common *priv = dev->priv;
58
59	switch (notify_cmd) {
60	case STA_NOTIFY_AWAKE:
61		/* update the firmware's filter table */
62		p54_sta_unlock(priv, sta->addr);
63		break;
64	default:
65		break;
66	}
67}
68
69static int p54_set_tim(struct ieee80211_hw *dev, struct ieee80211_sta *sta,
70			bool set)
71{
72	struct p54_common *priv = dev->priv;
73
74	return p54_update_beacon_tim(priv, sta->aid, set);
75}
76
77u8 *p54_find_ie(struct sk_buff *skb, u8 ie)
78{
79	struct ieee80211_mgmt *mgmt = (void *)skb->data;
80	u8 *pos, *end;
81
82	if (skb->len <= sizeof(mgmt))
83		return NULL;
84
85	pos = (u8 *)mgmt->u.beacon.variable;
86	end = skb->data + skb->len;
87	while (pos < end) {
88		if (pos + 2 + pos[1] > end)
89			return NULL;
90
91		if (pos[0] == ie)
92			return pos;
93
94		pos += 2 + pos[1];
95	}
96	return NULL;
97}
98
99static int p54_beacon_format_ie_tim(struct sk_buff *skb)
100{
101	/*
102	 * the good excuse for this mess is ... the firmware.
103	 * The dummy TIM MUST be at the end of the beacon frame,
104	 * because it'll be overwritten!
105	 */
106	u8 *tim;
107	u8 dtim_len;
108	u8 dtim_period;
109	u8 *next;
110
111	tim = p54_find_ie(skb, WLAN_EID_TIM);
112	if (!tim)
113		return 0;
114
115	dtim_len = tim[1];
116	dtim_period = tim[3];
117	next = tim + 2 + dtim_len;
118
119	if (dtim_len < 3)
120		return -EINVAL;
121
122	memmove(tim, next, skb_tail_pointer(skb) - next);
123	tim = skb_tail_pointer(skb) - (dtim_len + 2);
124
125	/* add the dummy at the end */
126	tim[0] = WLAN_EID_TIM;
127	tim[1] = 3;
128	tim[2] = 0;
129	tim[3] = dtim_period;
130	tim[4] = 0;
131
132	if (dtim_len > 3)
133		skb_trim(skb, skb->len - (dtim_len - 3));
134
135	return 0;
136}
137
138static int p54_beacon_update(struct p54_common *priv,
139			struct ieee80211_vif *vif)
140{
141	struct ieee80211_tx_control control = { };
142	struct sk_buff *beacon;
143	int ret;
144
145	beacon = ieee80211_beacon_get(priv->hw, vif);
146	if (!beacon)
147		return -ENOMEM;
148	ret = p54_beacon_format_ie_tim(beacon);
149	if (ret)
150		return ret;
151
152	/*
153	 * During operation, the firmware takes care of beaconing.
154	 * The driver only needs to upload a new beacon template, once
155	 * the template was changed by the stack or userspace.
156	 *
157	 * LMAC API 3.2.2 also specifies that the driver does not need
158	 * to cancel the old beacon template by hand, instead the firmware
159	 * will release the previous one through the feedback mechanism.
160	 */
161	p54_tx_80211(priv->hw, &control, beacon);
162	priv->tsf_high32 = 0;
163	priv->tsf_low32 = 0;
164
165	return 0;
166}
167
168static int p54_start(struct ieee80211_hw *dev)
169{
170	struct p54_common *priv = dev->priv;
171	int err;
172
173	mutex_lock(&priv->conf_mutex);
174	err = priv->open(dev);
175	if (err)
176		goto out;
177	P54_SET_QUEUE(priv->qos_params[0], 0x0002, 0x0003, 0x0007, 47);
178	P54_SET_QUEUE(priv->qos_params[1], 0x0002, 0x0007, 0x000f, 94);
179	P54_SET_QUEUE(priv->qos_params[2], 0x0003, 0x000f, 0x03ff, 0);
180	P54_SET_QUEUE(priv->qos_params[3], 0x0007, 0x000f, 0x03ff, 0);
181	err = p54_set_edcf(priv);
182	if (err)
183		goto out;
184
185	eth_broadcast_addr(priv->bssid);
186	priv->mode = NL80211_IFTYPE_MONITOR;
187	err = p54_setup_mac(priv);
188	if (err) {
189		priv->mode = NL80211_IFTYPE_UNSPECIFIED;
190		goto out;
191	}
192
193	ieee80211_queue_delayed_work(dev, &priv->work, 0);
194
195	priv->softled_state = 0;
196	err = p54_set_leds(priv);
197
198out:
199	mutex_unlock(&priv->conf_mutex);
200	return err;
201}
202
203static void p54_stop(struct ieee80211_hw *dev)
204{
205	struct p54_common *priv = dev->priv;
206	int i;
207
208	priv->mode = NL80211_IFTYPE_UNSPECIFIED;
209	priv->softled_state = 0;
210	cancel_delayed_work_sync(&priv->work);
211	mutex_lock(&priv->conf_mutex);
212	p54_set_leds(priv);
213	priv->stop(dev);
214	skb_queue_purge(&priv->tx_pending);
215	skb_queue_purge(&priv->tx_queue);
216	for (i = 0; i < P54_QUEUE_NUM; i++) {
217		priv->tx_stats[i].count = 0;
218		priv->tx_stats[i].len = 0;
219	}
220
221	priv->beacon_req_id = cpu_to_le32(0);
222	priv->tsf_high32 = priv->tsf_low32 = 0;
223	mutex_unlock(&priv->conf_mutex);
224}
225
226static int p54_add_interface(struct ieee80211_hw *dev,
227			     struct ieee80211_vif *vif)
228{
229	struct p54_common *priv = dev->priv;
230	int err;
231
232	vif->driver_flags |= IEEE80211_VIF_BEACON_FILTER;
233
234	mutex_lock(&priv->conf_mutex);
235	if (priv->mode != NL80211_IFTYPE_MONITOR) {
236		mutex_unlock(&priv->conf_mutex);
237		return -EOPNOTSUPP;
238	}
239
240	priv->vif = vif;
241
242	switch (vif->type) {
243	case NL80211_IFTYPE_STATION:
244	case NL80211_IFTYPE_ADHOC:
245	case NL80211_IFTYPE_AP:
246	case NL80211_IFTYPE_MESH_POINT:
247		priv->mode = vif->type;
248		break;
249	default:
250		mutex_unlock(&priv->conf_mutex);
251		return -EOPNOTSUPP;
252	}
253
254	memcpy(priv->mac_addr, vif->addr, ETH_ALEN);
255	err = p54_setup_mac(priv);
256	mutex_unlock(&priv->conf_mutex);
257	return err;
258}
259
260static void p54_remove_interface(struct ieee80211_hw *dev,
261				 struct ieee80211_vif *vif)
262{
263	struct p54_common *priv = dev->priv;
264
265	mutex_lock(&priv->conf_mutex);
266	priv->vif = NULL;
267
268	/*
269	 * LMAC API 3.2.2 states that any active beacon template must be
270	 * canceled by the driver before attempting a mode transition.
271	 */
272	if (le32_to_cpu(priv->beacon_req_id) != 0) {
273		p54_tx_cancel(priv, priv->beacon_req_id);
274		wait_for_completion_interruptible_timeout(&priv->beacon_comp, HZ);
275	}
276	priv->mode = NL80211_IFTYPE_MONITOR;
277	eth_zero_addr(priv->mac_addr);
278	eth_zero_addr(priv->bssid);
279	p54_setup_mac(priv);
280	mutex_unlock(&priv->conf_mutex);
281}
282
283static int p54_wait_for_stats(struct ieee80211_hw *dev)
284{
285	struct p54_common *priv = dev->priv;
286	int ret;
287
288	priv->update_stats = true;
289	ret = p54_fetch_statistics(priv);
290	if (ret)
291		return ret;
292
293	ret = wait_for_completion_interruptible_timeout(&priv->stat_comp, HZ);
294	if (ret == 0)
295		return -ETIMEDOUT;
296
297	return 0;
298}
299
300static void p54_reset_stats(struct p54_common *priv)
301{
302	struct ieee80211_channel *chan = priv->curchan;
303
304	if (chan) {
305		struct survey_info *info = &priv->survey[chan->hw_value];
306
307		/* only reset channel statistics, don't touch .filled, etc. */
308		info->time = 0;
309		info->time_busy = 0;
310		info->time_tx = 0;
311	}
312
313	priv->update_stats = true;
314	priv->survey_raw.active = 0;
315	priv->survey_raw.cca = 0;
316	priv->survey_raw.tx = 0;
317}
318
319static int p54_config(struct ieee80211_hw *dev, u32 changed)
320{
321	int ret = 0;
322	struct p54_common *priv = dev->priv;
323	struct ieee80211_conf *conf = &dev->conf;
324
325	mutex_lock(&priv->conf_mutex);
326	if (changed & IEEE80211_CONF_CHANGE_POWER)
327		priv->output_power = conf->power_level << 2;
328	if (changed & IEEE80211_CONF_CHANGE_CHANNEL) {
329		struct ieee80211_channel *oldchan;
330		WARN_ON(p54_wait_for_stats(dev));
331		oldchan = priv->curchan;
332		priv->curchan = NULL;
333		ret = p54_scan(priv, P54_SCAN_EXIT, 0);
334		if (ret) {
335			priv->curchan = oldchan;
336			goto out;
337		}
338		/*
339		 * TODO: Use the LM_SCAN_TRAP to determine the current
340		 * operating channel.
341		 */
342		priv->curchan = priv->hw->conf.chandef.chan;
343		p54_reset_stats(priv);
344		WARN_ON(p54_fetch_statistics(priv));
345	}
346	if (changed & IEEE80211_CONF_CHANGE_PS) {
347		WARN_ON(p54_wait_for_stats(dev));
348		ret = p54_set_ps(priv);
349		if (ret)
350			goto out;
351		WARN_ON(p54_wait_for_stats(dev));
352	}
353	if (changed & IEEE80211_CONF_CHANGE_IDLE) {
354		WARN_ON(p54_wait_for_stats(dev));
355		ret = p54_setup_mac(priv);
356		if (ret)
357			goto out;
358		WARN_ON(p54_wait_for_stats(dev));
359	}
360
361out:
362	mutex_unlock(&priv->conf_mutex);
363	return ret;
364}
365
366static u64 p54_prepare_multicast(struct ieee80211_hw *dev,
367				 struct netdev_hw_addr_list *mc_list)
368{
369	struct p54_common *priv = dev->priv;
370	struct netdev_hw_addr *ha;
371	int i;
372
373	BUILD_BUG_ON(ARRAY_SIZE(priv->mc_maclist) !=
374		ARRAY_SIZE(((struct p54_group_address_table *)NULL)->mac_list));
375	/*
376	 * The first entry is reserved for the global broadcast MAC.
377	 * Otherwise the firmware will drop it and ARP will no longer work.
378	 */
379	i = 1;
380	priv->mc_maclist_num = netdev_hw_addr_list_count(mc_list) + i;
381	netdev_hw_addr_list_for_each(ha, mc_list) {
382		memcpy(&priv->mc_maclist[i], ha->addr, ETH_ALEN);
383		i++;
384		if (i >= ARRAY_SIZE(priv->mc_maclist))
385			break;
386	}
387
388	return 1; /* update */
389}
390
391static void p54_configure_filter(struct ieee80211_hw *dev,
392				 unsigned int changed_flags,
393				 unsigned int *total_flags,
394				 u64 multicast)
395{
396	struct p54_common *priv = dev->priv;
397
398	*total_flags &= FIF_PROMISC_IN_BSS |
399			FIF_ALLMULTI |
400			FIF_OTHER_BSS;
401
402	priv->filter_flags = *total_flags;
403
404	if (changed_flags & (FIF_PROMISC_IN_BSS | FIF_OTHER_BSS))
405		p54_setup_mac(priv);
406
407	if (changed_flags & FIF_ALLMULTI || multicast)
408		p54_set_groupfilter(priv);
409}
410
411static int p54_conf_tx(struct ieee80211_hw *dev,
412		       struct ieee80211_vif *vif, u16 queue,
413		       const struct ieee80211_tx_queue_params *params)
414{
415	struct p54_common *priv = dev->priv;
416	int ret;
417
418	mutex_lock(&priv->conf_mutex);
419	if (queue < dev->queues) {
420		P54_SET_QUEUE(priv->qos_params[queue], params->aifs,
421			params->cw_min, params->cw_max, params->txop);
422		ret = p54_set_edcf(priv);
423	} else
424		ret = -EINVAL;
425	mutex_unlock(&priv->conf_mutex);
426	return ret;
427}
428
429static void p54_work(struct work_struct *work)
430{
431	struct p54_common *priv = container_of(work, struct p54_common,
432					       work.work);
433
434	if (unlikely(priv->mode == NL80211_IFTYPE_UNSPECIFIED))
435		return ;
436
437	/*
438	 * TODO: walk through tx_queue and do the following tasks
439	 * 	1. initiate bursts.
440	 *      2. cancel stuck frames / reset the device if necessary.
441	 */
442
443	mutex_lock(&priv->conf_mutex);
444	WARN_ON_ONCE(p54_fetch_statistics(priv));
445	mutex_unlock(&priv->conf_mutex);
446}
447
448static int p54_get_stats(struct ieee80211_hw *dev,
449			 struct ieee80211_low_level_stats *stats)
450{
451	struct p54_common *priv = dev->priv;
452
453	memcpy(stats, &priv->stats, sizeof(*stats));
454	return 0;
455}
456
457static void p54_bss_info_changed(struct ieee80211_hw *dev,
458				 struct ieee80211_vif *vif,
459				 struct ieee80211_bss_conf *info,
460				 u32 changed)
461{
462	struct p54_common *priv = dev->priv;
463
464	mutex_lock(&priv->conf_mutex);
465	if (changed & BSS_CHANGED_BSSID) {
466		memcpy(priv->bssid, info->bssid, ETH_ALEN);
467		p54_setup_mac(priv);
468	}
469
470	if (changed & BSS_CHANGED_BEACON) {
471		p54_scan(priv, P54_SCAN_EXIT, 0);
472		p54_setup_mac(priv);
473		p54_beacon_update(priv, vif);
474		p54_set_edcf(priv);
475	}
476
477	if (changed & (BSS_CHANGED_ERP_SLOT | BSS_CHANGED_BEACON)) {
478		priv->use_short_slot = info->use_short_slot;
479		p54_set_edcf(priv);
480	}
481	if (changed & BSS_CHANGED_BASIC_RATES) {
482		if (dev->conf.chandef.chan->band == IEEE80211_BAND_5GHZ)
483			priv->basic_rate_mask = (info->basic_rates << 4);
484		else
485			priv->basic_rate_mask = info->basic_rates;
486		p54_setup_mac(priv);
487		if (priv->fw_var >= 0x500)
488			p54_scan(priv, P54_SCAN_EXIT, 0);
489	}
490	if (changed & BSS_CHANGED_ASSOC) {
491		if (info->assoc) {
492			priv->aid = info->aid;
493			priv->wakeup_timer = info->beacon_int *
494					     info->dtim_period * 5;
495			p54_setup_mac(priv);
496		} else {
497			priv->wakeup_timer = 500;
498			priv->aid = 0;
499		}
500	}
501
502	mutex_unlock(&priv->conf_mutex);
503}
504
505static int p54_set_key(struct ieee80211_hw *dev, enum set_key_cmd cmd,
506		       struct ieee80211_vif *vif, struct ieee80211_sta *sta,
507		       struct ieee80211_key_conf *key)
508{
509	struct p54_common *priv = dev->priv;
510	int slot, ret = 0;
511	u8 algo = 0;
512	u8 *addr = NULL;
513
514	if (modparam_nohwcrypt)
515		return -EOPNOTSUPP;
516
517	if (key->flags & IEEE80211_KEY_FLAG_RX_MGMT) {
518		/*
519		 * Unfortunately most/all firmwares are trying to decrypt
520		 * incoming management frames if a suitable key can be found.
521		 * However, in doing so the data in these frames gets
522		 * corrupted. So, we can't have firmware supported crypto
523		 * offload in this case.
524		 */
525		return -EOPNOTSUPP;
526	}
527
528	mutex_lock(&priv->conf_mutex);
529	if (cmd == SET_KEY) {
530		switch (key->cipher) {
531		case WLAN_CIPHER_SUITE_TKIP:
532			if (!(priv->privacy_caps & (BR_DESC_PRIV_CAP_MICHAEL |
533			      BR_DESC_PRIV_CAP_TKIP))) {
534				ret = -EOPNOTSUPP;
535				goto out_unlock;
536			}
537			key->flags |= IEEE80211_KEY_FLAG_GENERATE_IV;
538			algo = P54_CRYPTO_TKIPMICHAEL;
539			break;
540		case WLAN_CIPHER_SUITE_WEP40:
541		case WLAN_CIPHER_SUITE_WEP104:
542			if (!(priv->privacy_caps & BR_DESC_PRIV_CAP_WEP)) {
543				ret = -EOPNOTSUPP;
544				goto out_unlock;
545			}
546			key->flags |= IEEE80211_KEY_FLAG_GENERATE_IV;
547			algo = P54_CRYPTO_WEP;
548			break;
549		case WLAN_CIPHER_SUITE_CCMP:
550			if (!(priv->privacy_caps & BR_DESC_PRIV_CAP_AESCCMP)) {
551				ret = -EOPNOTSUPP;
552				goto out_unlock;
553			}
554			key->flags |= IEEE80211_KEY_FLAG_GENERATE_IV;
555			algo = P54_CRYPTO_AESCCMP;
556			break;
557		default:
558			ret = -EOPNOTSUPP;
559			goto out_unlock;
560		}
561		slot = bitmap_find_free_region(priv->used_rxkeys,
562					       priv->rx_keycache_size, 0);
563
564		if (slot < 0) {
565			/*
566			 * The device supports the chosen algorithm, but the
567			 * firmware does not provide enough key slots to store
568			 * all of them.
569			 * But encryption offload for outgoing frames is always
570			 * possible, so we just pretend that the upload was
571			 * successful and do the decryption in software.
572			 */
573
574			/* mark the key as invalid. */
575			key->hw_key_idx = 0xff;
576			goto out_unlock;
577		}
578
579		key->flags |= IEEE80211_KEY_FLAG_RESERVE_TAILROOM;
580	} else {
581		slot = key->hw_key_idx;
582
583		if (slot == 0xff) {
584			/* This key was not uploaded into the rx key cache. */
585
586			goto out_unlock;
587		}
588
589		bitmap_release_region(priv->used_rxkeys, slot, 0);
590		algo = 0;
591	}
592
593	if (sta)
594		addr = sta->addr;
595
596	ret = p54_upload_key(priv, algo, slot, key->keyidx,
597			     key->keylen, addr, key->key);
598	if (ret) {
599		bitmap_release_region(priv->used_rxkeys, slot, 0);
600		ret = -EOPNOTSUPP;
601		goto out_unlock;
602	}
603
604	key->hw_key_idx = slot;
605
606out_unlock:
607	mutex_unlock(&priv->conf_mutex);
608	return ret;
609}
610
611static int p54_get_survey(struct ieee80211_hw *dev, int idx,
612				struct survey_info *survey)
613{
614	struct p54_common *priv = dev->priv;
615	struct ieee80211_channel *chan;
616	int err, tries;
617	bool in_use = false;
618
619	if (idx >= priv->chan_num)
620		return -ENOENT;
621
622#define MAX_TRIES 1
623	for (tries = 0; tries < MAX_TRIES; tries++) {
624		chan = priv->curchan;
625		if (chan && chan->hw_value == idx) {
626			mutex_lock(&priv->conf_mutex);
627			err = p54_wait_for_stats(dev);
628			mutex_unlock(&priv->conf_mutex);
629			if (err)
630				return err;
631
632			in_use = true;
633		}
634
635		memcpy(survey, &priv->survey[idx], sizeof(*survey));
636
637		if (in_use) {
638			/* test if the reported statistics are valid. */
639			if  (survey->time != 0) {
640				survey->filled |= SURVEY_INFO_IN_USE;
641			} else {
642				/*
643				 * hw/fw has not accumulated enough sample sets.
644				 * Wait for 100ms, this ought to be enough to
645				 * to get at least one non-null set of channel
646				 * usage statistics.
647				 */
648				msleep(100);
649				continue;
650			}
651		}
652		return 0;
653	}
654	return -ETIMEDOUT;
655#undef MAX_TRIES
656}
657
658static unsigned int p54_flush_count(struct p54_common *priv)
659{
660	unsigned int total = 0, i;
661
662	BUILD_BUG_ON(P54_QUEUE_NUM > ARRAY_SIZE(priv->tx_stats));
663
664	/*
665	 * Because the firmware has the sole control over any frames
666	 * in the P54_QUEUE_BEACON or P54_QUEUE_SCAN queues, they
667	 * don't really count as pending or active.
668	 */
669	for (i = P54_QUEUE_MGMT; i < P54_QUEUE_NUM; i++)
670		total += priv->tx_stats[i].len;
671	return total;
672}
673
674static void p54_flush(struct ieee80211_hw *dev, struct ieee80211_vif *vif,
675		      u32 queues, bool drop)
676{
677	struct p54_common *priv = dev->priv;
678	unsigned int total, i;
679
680	/*
681	 * Currently, it wouldn't really matter if we wait for one second
682	 * or 15 minutes. But once someone gets around and completes the
683	 * TODOs [ancel stuck frames / reset device] in p54_work, it will
684	 * suddenly make sense to wait that long.
685	 */
686	i = P54_STATISTICS_UPDATE * 2 / 20;
687
688	/*
689	 * In this case no locking is required because as we speak the
690	 * queues have already been stopped and no new frames can sneak
691	 * up from behind.
692	 */
693	while ((total = p54_flush_count(priv) && i--)) {
694		/* waste time */
695		msleep(20);
696	}
697
698	WARN(total, "tx flush timeout, unresponsive firmware");
699}
700
701static void p54_set_coverage_class(struct ieee80211_hw *dev,
702				   s16 coverage_class)
703{
704	struct p54_common *priv = dev->priv;
705
706	mutex_lock(&priv->conf_mutex);
707	/* support all coverage class values as in 802.11-2007 Table 7-27 */
708	priv->coverage_class = clamp_t(u8, coverage_class, 0, 31);
709	p54_set_edcf(priv);
710	mutex_unlock(&priv->conf_mutex);
711}
712
713static const struct ieee80211_ops p54_ops = {
714	.tx			= p54_tx_80211,
715	.start			= p54_start,
716	.stop			= p54_stop,
717	.add_interface		= p54_add_interface,
718	.remove_interface	= p54_remove_interface,
719	.set_tim		= p54_set_tim,
720	.sta_notify		= p54_sta_notify,
721	.sta_add		= p54_sta_add_remove,
722	.sta_remove		= p54_sta_add_remove,
723	.set_key		= p54_set_key,
724	.config			= p54_config,
725	.flush			= p54_flush,
726	.bss_info_changed	= p54_bss_info_changed,
727	.prepare_multicast	= p54_prepare_multicast,
728	.configure_filter	= p54_configure_filter,
729	.conf_tx		= p54_conf_tx,
730	.get_stats		= p54_get_stats,
731	.get_survey		= p54_get_survey,
732	.set_coverage_class	= p54_set_coverage_class,
733};
734
735struct ieee80211_hw *p54_init_common(size_t priv_data_len)
736{
737	struct ieee80211_hw *dev;
738	struct p54_common *priv;
739
740	dev = ieee80211_alloc_hw(priv_data_len, &p54_ops);
741	if (!dev)
742		return NULL;
743
744	priv = dev->priv;
745	priv->hw = dev;
746	priv->mode = NL80211_IFTYPE_UNSPECIFIED;
747	priv->basic_rate_mask = 0x15f;
748	spin_lock_init(&priv->tx_stats_lock);
749	skb_queue_head_init(&priv->tx_queue);
750	skb_queue_head_init(&priv->tx_pending);
751	dev->flags = IEEE80211_HW_RX_INCLUDES_FCS |
752		     IEEE80211_HW_SIGNAL_DBM |
753		     IEEE80211_HW_SUPPORTS_PS |
754		     IEEE80211_HW_PS_NULLFUNC_STACK |
755		     IEEE80211_HW_MFP_CAPABLE |
756		     IEEE80211_HW_REPORTS_TX_ACK_STATUS;
757
758	dev->wiphy->interface_modes = BIT(NL80211_IFTYPE_STATION) |
759				      BIT(NL80211_IFTYPE_ADHOC) |
760				      BIT(NL80211_IFTYPE_AP) |
761				      BIT(NL80211_IFTYPE_MESH_POINT);
762
763	priv->beacon_req_id = cpu_to_le32(0);
764	priv->tx_stats[P54_QUEUE_BEACON].limit = 1;
765	priv->tx_stats[P54_QUEUE_FWSCAN].limit = 1;
766	priv->tx_stats[P54_QUEUE_MGMT].limit = 3;
767	priv->tx_stats[P54_QUEUE_CAB].limit = 3;
768	priv->tx_stats[P54_QUEUE_DATA].limit = 5;
769	dev->queues = 1;
770	priv->noise = -94;
771	/*
772	 * We support at most 8 tries no matter which rate they're at,
773	 * we cannot support max_rates * max_rate_tries as we set it
774	 * here, but setting it correctly to 4/2 or so would limit us
775	 * artificially if the RC algorithm wants just two rates, so
776	 * let's say 4/7, we'll redistribute it at TX time, see the
777	 * comments there.
778	 */
779	dev->max_rates = 4;
780	dev->max_rate_tries = 7;
781	dev->extra_tx_headroom = sizeof(struct p54_hdr) + 4 +
782				 sizeof(struct p54_tx_data);
783
784	/*
785	 * For now, disable PS by default because it affects
786	 * link stability significantly.
787	 */
788	dev->wiphy->flags &= ~WIPHY_FLAG_PS_ON_BY_DEFAULT;
789
790	mutex_init(&priv->conf_mutex);
791	mutex_init(&priv->eeprom_mutex);
792	init_completion(&priv->stat_comp);
793	init_completion(&priv->eeprom_comp);
794	init_completion(&priv->beacon_comp);
795	INIT_DELAYED_WORK(&priv->work, p54_work);
796
797	eth_broadcast_addr(priv->mc_maclist[0]);
798	priv->curchan = NULL;
799	p54_reset_stats(priv);
800	return dev;
801}
802EXPORT_SYMBOL_GPL(p54_init_common);
803
804int p54_register_common(struct ieee80211_hw *dev, struct device *pdev)
805{
806	struct p54_common __maybe_unused *priv = dev->priv;
807	int err;
808
809	err = ieee80211_register_hw(dev);
810	if (err) {
811		dev_err(pdev, "Cannot register device (%d).\n", err);
812		return err;
813	}
814	priv->registered = true;
815
816#ifdef CONFIG_P54_LEDS
817	err = p54_init_leds(priv);
818	if (err) {
819		p54_unregister_common(dev);
820		return err;
821	}
822#endif /* CONFIG_P54_LEDS */
823
824	dev_info(pdev, "is registered as '%s'\n", wiphy_name(dev->wiphy));
825	return 0;
826}
827EXPORT_SYMBOL_GPL(p54_register_common);
828
829void p54_free_common(struct ieee80211_hw *dev)
830{
831	struct p54_common *priv = dev->priv;
832	unsigned int i;
833
834	for (i = 0; i < IEEE80211_NUM_BANDS; i++)
835		kfree(priv->band_table[i]);
836
837	kfree(priv->iq_autocal);
838	kfree(priv->output_limit);
839	kfree(priv->curve_data);
840	kfree(priv->rssi_db);
841	kfree(priv->used_rxkeys);
842	kfree(priv->survey);
843	priv->iq_autocal = NULL;
844	priv->output_limit = NULL;
845	priv->curve_data = NULL;
846	priv->rssi_db = NULL;
847	priv->used_rxkeys = NULL;
848	priv->survey = NULL;
849	ieee80211_free_hw(dev);
850}
851EXPORT_SYMBOL_GPL(p54_free_common);
852
853void p54_unregister_common(struct ieee80211_hw *dev)
854{
855	struct p54_common *priv = dev->priv;
856
857#ifdef CONFIG_P54_LEDS
858	p54_unregister_leds(priv);
859#endif /* CONFIG_P54_LEDS */
860
861	if (priv->registered) {
862		priv->registered = false;
863		ieee80211_unregister_hw(dev);
864	}
865
866	mutex_destroy(&priv->conf_mutex);
867	mutex_destroy(&priv->eeprom_mutex);
868}
869EXPORT_SYMBOL_GPL(p54_unregister_common);
870