GNU Linux-libre 4.19.286-gnu1
[releases.git] / drivers / net / wireless / rsi / rsi_91x_hal.c
1 /**
2  * Copyright (c) 2014 Redpine Signals Inc.
3  *
4  * Permission to use, copy, modify, and/or distribute this software for any
5  * purpose with or without fee is hereby granted, provided that the above
6  * copyright notice and this permission notice appear in all copies.
7  *
8  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15  */
16
17 #include <linux/firmware.h>
18 #include <net/bluetooth/bluetooth.h>
19 #include "rsi_mgmt.h"
20 #include "rsi_hal.h"
21 #include "rsi_sdio.h"
22 #include "rsi_common.h"
23
24 /* FLASH Firmware */
25 static struct ta_metadata metadata_flash_content[] = {
26         {"flash_content", 0x00010000},
27         {"/*(DEBLOBBED)*/", 0x00010000},
28         {"rsi/rs9113_wlan_bt_dual_mode.rps", 0x00010000},
29         {"flash_content", 0x00010000},
30         {"rsi/rs9113_ap_bt_dual_mode.rps", 0x00010000},
31
32 };
33
34 int rsi_send_pkt_to_bus(struct rsi_common *common, struct sk_buff *skb)
35 {
36         struct rsi_hw *adapter = common->priv;
37         int status;
38
39         if (common->coex_mode > 1)
40                 mutex_lock(&common->tx_bus_mutex);
41
42         status = adapter->host_intf_ops->write_pkt(common->priv,
43                                                    skb->data, skb->len);
44
45         if (common->coex_mode > 1)
46                 mutex_unlock(&common->tx_bus_mutex);
47
48         return status;
49 }
50
51 int rsi_prepare_mgmt_desc(struct rsi_common *common, struct sk_buff *skb)
52 {
53         struct rsi_hw *adapter = common->priv;
54         struct ieee80211_hdr *wh = NULL;
55         struct ieee80211_tx_info *info;
56         struct ieee80211_conf *conf = &adapter->hw->conf;
57         struct ieee80211_vif *vif;
58         struct rsi_mgmt_desc *mgmt_desc;
59         struct skb_info *tx_params;
60         struct rsi_xtended_desc *xtend_desc = NULL;
61         u8 header_size;
62         u32 dword_align_bytes = 0;
63
64         if (skb->len > MAX_MGMT_PKT_SIZE) {
65                 rsi_dbg(INFO_ZONE, "%s: Dropping mgmt pkt > 512\n", __func__);
66                 return -EINVAL;
67         }
68
69         info = IEEE80211_SKB_CB(skb);
70         tx_params = (struct skb_info *)info->driver_data;
71         vif = tx_params->vif;
72
73         /* Update header size */
74         header_size = FRAME_DESC_SZ + sizeof(struct rsi_xtended_desc);
75         if (header_size > skb_headroom(skb)) {
76                 rsi_dbg(ERR_ZONE,
77                         "%s: Failed to add extended descriptor\n",
78                         __func__);
79                 return -ENOSPC;
80         }
81         skb_push(skb, header_size);
82         dword_align_bytes = ((unsigned long)skb->data & 0x3f);
83         if (dword_align_bytes > skb_headroom(skb)) {
84                 rsi_dbg(ERR_ZONE,
85                         "%s: Failed to add dword align\n", __func__);
86                 return -ENOSPC;
87         }
88         skb_push(skb, dword_align_bytes);
89         header_size += dword_align_bytes;
90
91         tx_params->internal_hdr_size = header_size;
92         memset(&skb->data[0], 0, header_size);
93         wh = (struct ieee80211_hdr *)&skb->data[header_size];
94
95         mgmt_desc = (struct rsi_mgmt_desc *)skb->data;
96         xtend_desc = (struct rsi_xtended_desc *)&skb->data[FRAME_DESC_SZ];
97
98         rsi_set_len_qno(&mgmt_desc->len_qno, (skb->len - FRAME_DESC_SZ),
99                         RSI_WIFI_MGMT_Q);
100         mgmt_desc->frame_type = TX_DOT11_MGMT;
101         mgmt_desc->header_len = MIN_802_11_HDR_LEN;
102         mgmt_desc->xtend_desc_size = header_size - FRAME_DESC_SZ;
103         mgmt_desc->frame_info |= cpu_to_le16(RATE_INFO_ENABLE);
104         if (is_broadcast_ether_addr(wh->addr1))
105                 mgmt_desc->frame_info |= cpu_to_le16(RSI_BROADCAST_PKT);
106
107         mgmt_desc->seq_ctrl =
108                 cpu_to_le16(IEEE80211_SEQ_TO_SN(le16_to_cpu(wh->seq_ctrl)));
109         if ((common->band == NL80211_BAND_2GHZ) && !common->p2p_enabled)
110                 mgmt_desc->rate_info = cpu_to_le16(RSI_RATE_1);
111         else
112                 mgmt_desc->rate_info = cpu_to_le16(RSI_RATE_6);
113
114         if (conf_is_ht40(conf))
115                 mgmt_desc->bbp_info = cpu_to_le16(FULL40M_ENABLE);
116
117         if (ieee80211_is_probe_resp(wh->frame_control)) {
118                 mgmt_desc->misc_flags |= (RSI_ADD_DELTA_TSF_VAP_ID |
119                                           RSI_FETCH_RETRY_CNT_FRM_HST);
120 #define PROBE_RESP_RETRY_CNT    3
121                 xtend_desc->retry_cnt = PROBE_RESP_RETRY_CNT;
122         }
123
124         if (((vif->type == NL80211_IFTYPE_AP) ||
125              (vif->type == NL80211_IFTYPE_P2P_GO)) &&
126             (ieee80211_is_action(wh->frame_control))) {
127                 struct rsi_sta *rsta = rsi_find_sta(common, wh->addr1);
128
129                 if (rsta)
130                         mgmt_desc->sta_id = tx_params->sta_id;
131                 else
132                         return -EINVAL;
133         }
134         mgmt_desc->rate_info |=
135                 cpu_to_le16((tx_params->vap_id << RSI_DESC_VAP_ID_OFST) &
136                             RSI_DESC_VAP_ID_MASK);
137
138         return 0;
139 }
140
141 /* This function prepares descriptor for given data packet */
142 int rsi_prepare_data_desc(struct rsi_common *common, struct sk_buff *skb)
143 {
144         struct rsi_hw *adapter = common->priv;
145         struct ieee80211_vif *vif;
146         struct ieee80211_hdr *wh = NULL;
147         struct ieee80211_tx_info *info;
148         struct skb_info *tx_params;
149         struct rsi_data_desc *data_desc;
150         struct rsi_xtended_desc *xtend_desc;
151         u8 ieee80211_size = MIN_802_11_HDR_LEN;
152         u8 header_size;
153         u8 vap_id = 0;
154         u8 dword_align_bytes;
155         bool tx_eapol;
156         u16 seq_num;
157
158         info = IEEE80211_SKB_CB(skb);
159         vif = info->control.vif;
160         tx_params = (struct skb_info *)info->driver_data;
161
162         tx_eapol = IEEE80211_SKB_CB(skb)->control.flags &
163                    IEEE80211_TX_CTRL_PORT_CTRL_PROTO;
164
165         header_size = FRAME_DESC_SZ + sizeof(struct rsi_xtended_desc);
166         if (header_size > skb_headroom(skb)) {
167                 rsi_dbg(ERR_ZONE, "%s: Unable to send pkt\n", __func__);
168                 return -ENOSPC;
169         }
170         skb_push(skb, header_size);
171         dword_align_bytes = ((unsigned long)skb->data & 0x3f);
172         if (header_size > skb_headroom(skb)) {
173                 rsi_dbg(ERR_ZONE, "%s: Not enough headroom\n", __func__);
174                 return -ENOSPC;
175         }
176         skb_push(skb, dword_align_bytes);
177         header_size += dword_align_bytes;
178
179         tx_params->internal_hdr_size = header_size;
180         data_desc = (struct rsi_data_desc *)skb->data;
181         memset(data_desc, 0, header_size);
182
183         xtend_desc = (struct rsi_xtended_desc *)&skb->data[FRAME_DESC_SZ];
184         wh = (struct ieee80211_hdr *)&skb->data[header_size];
185         seq_num = IEEE80211_SEQ_TO_SN(le16_to_cpu(wh->seq_ctrl));
186
187         data_desc->xtend_desc_size = header_size - FRAME_DESC_SZ;
188
189         if (ieee80211_is_data_qos(wh->frame_control)) {
190                 ieee80211_size += 2;
191                 data_desc->mac_flags |= cpu_to_le16(RSI_QOS_ENABLE);
192         }
193
194         if (((vif->type == NL80211_IFTYPE_STATION) ||
195              (vif->type == NL80211_IFTYPE_P2P_CLIENT)) &&
196             (adapter->ps_state == PS_ENABLED))
197                 wh->frame_control |= cpu_to_le16(RSI_SET_PS_ENABLE);
198
199         if ((!(info->flags & IEEE80211_TX_INTFL_DONT_ENCRYPT)) &&
200             tx_params->have_key) {
201                 if (rsi_is_cipher_wep(common))
202                         ieee80211_size += 4;
203                 else
204                         ieee80211_size += 8;
205                 data_desc->mac_flags |= cpu_to_le16(RSI_ENCRYPT_PKT);
206         }
207         rsi_set_len_qno(&data_desc->len_qno, (skb->len - FRAME_DESC_SZ),
208                         RSI_WIFI_DATA_Q);
209         data_desc->header_len = ieee80211_size;
210
211         if (common->rate_config[common->band].fixed_enabled) {
212                 /* Send fixed rate */
213                 u16 fixed_rate = common->rate_config[common->band].fixed_hw_rate;
214
215                 data_desc->frame_info = cpu_to_le16(RATE_INFO_ENABLE);
216                 data_desc->rate_info = cpu_to_le16(fixed_rate);
217
218                 if (conf_is_ht40(&common->priv->hw->conf))
219                         data_desc->bbp_info = cpu_to_le16(FULL40M_ENABLE);
220
221                 if (common->vif_info[0].sgi && (fixed_rate & 0x100)) {
222                        /* Only MCS rates */
223                         data_desc->rate_info |=
224                                 cpu_to_le16(ENABLE_SHORTGI_RATE);
225                 }
226         }
227
228         if (tx_eapol) {
229                 rsi_dbg(INFO_ZONE, "*** Tx EAPOL ***\n");
230
231                 data_desc->frame_info = cpu_to_le16(RATE_INFO_ENABLE);
232                 if (common->band == NL80211_BAND_5GHZ)
233                         data_desc->rate_info = cpu_to_le16(RSI_RATE_6);
234                 else
235                         data_desc->rate_info = cpu_to_le16(RSI_RATE_1);
236                 data_desc->mac_flags |= cpu_to_le16(RSI_REKEY_PURPOSE);
237                 data_desc->misc_flags |= RSI_FETCH_RETRY_CNT_FRM_HST;
238 #define EAPOL_RETRY_CNT 15
239                 xtend_desc->retry_cnt = EAPOL_RETRY_CNT;
240
241                 if (common->eapol4_confirm)
242                         skb->priority = VO_Q;
243                 else
244                         rsi_set_len_qno(&data_desc->len_qno,
245                                         (skb->len - FRAME_DESC_SZ),
246                                         RSI_WIFI_MGMT_Q);
247                 if (((skb->len - header_size) == EAPOL4_PACKET_LEN) ||
248                     ((skb->len - header_size) == EAPOL4_PACKET_LEN - 2)) {
249                         data_desc->misc_flags |=
250                                 RSI_DESC_REQUIRE_CFM_TO_HOST;
251                         xtend_desc->confirm_frame_type = EAPOL4_CONFIRM;
252                 }
253         }
254
255         data_desc->mac_flags |= cpu_to_le16(seq_num & 0xfff);
256         data_desc->qid_tid = ((skb->priority & 0xf) |
257                               ((tx_params->tid & 0xf) << 4));
258         data_desc->sta_id = tx_params->sta_id;
259
260         if ((is_broadcast_ether_addr(wh->addr1)) ||
261             (is_multicast_ether_addr(wh->addr1))) {
262                 data_desc->frame_info = cpu_to_le16(RATE_INFO_ENABLE);
263                 data_desc->frame_info |= cpu_to_le16(RSI_BROADCAST_PKT);
264                 data_desc->sta_id = vap_id;
265
266                 if ((vif->type == NL80211_IFTYPE_AP) ||
267                     (vif->type == NL80211_IFTYPE_P2P_GO)) {
268                         if (common->band == NL80211_BAND_5GHZ)
269                                 data_desc->rate_info = cpu_to_le16(RSI_RATE_6);
270                         else
271                                 data_desc->rate_info = cpu_to_le16(RSI_RATE_1);
272                 }
273         }
274         if (((vif->type == NL80211_IFTYPE_AP) ||
275              (vif->type == NL80211_IFTYPE_P2P_GO)) &&
276             (ieee80211_has_moredata(wh->frame_control)))
277                 data_desc->frame_info |= cpu_to_le16(MORE_DATA_PRESENT);
278
279         data_desc->rate_info |=
280                 cpu_to_le16((tx_params->vap_id << RSI_DESC_VAP_ID_OFST) &
281                             RSI_DESC_VAP_ID_MASK);
282
283         return 0;
284 }
285
286 /* This function sends received data packet from driver to device */
287 int rsi_send_data_pkt(struct rsi_common *common, struct sk_buff *skb)
288 {
289         struct rsi_hw *adapter = common->priv;
290         struct ieee80211_vif *vif;
291         struct ieee80211_tx_info *info;
292         struct skb_info *tx_params;
293         struct ieee80211_bss_conf *bss;
294         int status = -EINVAL;
295         u8 header_size;
296
297         if (!skb)
298                 return 0;
299         if (common->iface_down)
300                 goto err;
301
302         info = IEEE80211_SKB_CB(skb);
303         if (!info->control.vif)
304                 goto err;
305         vif = info->control.vif;
306         bss = &vif->bss_conf;
307         tx_params = (struct skb_info *)info->driver_data;
308         header_size = tx_params->internal_hdr_size;
309
310         if (((vif->type == NL80211_IFTYPE_STATION) ||
311              (vif->type == NL80211_IFTYPE_P2P_CLIENT)) &&
312             (!bss->assoc))
313                 goto err;
314
315         status = rsi_send_pkt_to_bus(common, skb);
316         if (status)
317                 rsi_dbg(ERR_ZONE, "%s: Failed to write pkt\n", __func__);
318
319 err:
320         ++common->tx_stats.total_tx_pkt_freed[skb->priority];
321         rsi_indicate_tx_status(adapter, skb, status);
322         return status;
323 }
324
325 /**
326  * rsi_send_mgmt_pkt() - This functions sends the received management packet
327  *                       from driver to device.
328  * @common: Pointer to the driver private structure.
329  * @skb: Pointer to the socket buffer structure.
330  *
331  * Return: status: 0 on success, -1 on failure.
332  */
333 int rsi_send_mgmt_pkt(struct rsi_common *common,
334                       struct sk_buff *skb)
335 {
336         struct rsi_hw *adapter = common->priv;
337         struct ieee80211_bss_conf *bss;
338         struct ieee80211_hdr *wh;
339         struct ieee80211_tx_info *info;
340         struct skb_info *tx_params;
341         struct rsi_mgmt_desc *mgmt_desc;
342         struct rsi_xtended_desc *xtend_desc;
343         int status = -E2BIG;
344         u8 header_size;
345
346         info = IEEE80211_SKB_CB(skb);
347         tx_params = (struct skb_info *)info->driver_data;
348         header_size = tx_params->internal_hdr_size;
349
350         if (tx_params->flags & INTERNAL_MGMT_PKT) {
351                 status = adapter->host_intf_ops->write_pkt(common->priv,
352                                                            (u8 *)skb->data,
353                                                            skb->len);
354                 if (status) {
355                         rsi_dbg(ERR_ZONE,
356                                 "%s: Failed to write the packet\n", __func__);
357                 }
358                 dev_kfree_skb(skb);
359                 return status;
360         }
361
362         bss = &info->control.vif->bss_conf;
363         wh = (struct ieee80211_hdr *)&skb->data[header_size];
364         mgmt_desc = (struct rsi_mgmt_desc *)skb->data;
365         xtend_desc = (struct rsi_xtended_desc *)&skb->data[FRAME_DESC_SZ];
366
367         /* Indicate to firmware to give cfm for probe */
368         if (ieee80211_is_probe_req(wh->frame_control) && !bss->assoc) {
369                 rsi_dbg(INFO_ZONE,
370                         "%s: blocking mgmt queue\n", __func__);
371                 mgmt_desc->misc_flags = RSI_DESC_REQUIRE_CFM_TO_HOST;
372                 xtend_desc->confirm_frame_type = PROBEREQ_CONFIRM;
373                 common->mgmt_q_block = true;
374                 rsi_dbg(INFO_ZONE, "Mgmt queue blocked\n");
375         }
376
377         status = rsi_send_pkt_to_bus(common, skb);
378         if (status)
379                 rsi_dbg(ERR_ZONE, "%s: Failed to write the packet\n", __func__);
380
381         rsi_indicate_tx_status(common->priv, skb, status);
382         return status;
383 }
384
385 int rsi_send_bt_pkt(struct rsi_common *common, struct sk_buff *skb)
386 {
387         int status = -EINVAL;
388         u8 header_size = 0;
389         struct rsi_bt_desc *bt_desc;
390         u8 queueno = ((skb->data[1] >> 4) & 0xf);
391
392         if (queueno == RSI_BT_MGMT_Q) {
393                 status = rsi_send_pkt_to_bus(common, skb);
394                 if (status)
395                         rsi_dbg(ERR_ZONE, "%s: Failed to write bt mgmt pkt\n",
396                                 __func__);
397                 goto out;
398         }
399         header_size = FRAME_DESC_SZ;
400         if (header_size > skb_headroom(skb)) {
401                 rsi_dbg(ERR_ZONE, "%s: Not enough headroom\n", __func__);
402                 status = -ENOSPC;
403                 goto out;
404         }
405         skb_push(skb, header_size);
406         memset(skb->data, 0, header_size);
407         bt_desc = (struct rsi_bt_desc *)skb->data;
408
409         rsi_set_len_qno(&bt_desc->len_qno, (skb->len - FRAME_DESC_SZ),
410                         RSI_BT_DATA_Q);
411         bt_desc->bt_pkt_type = cpu_to_le16(bt_cb(skb)->pkt_type);
412
413         status = rsi_send_pkt_to_bus(common, skb);
414         if (status)
415                 rsi_dbg(ERR_ZONE, "%s: Failed to write bt pkt\n", __func__);
416
417 out:
418         dev_kfree_skb(skb);
419         return status;
420 }
421
422 int rsi_prepare_beacon(struct rsi_common *common, struct sk_buff *skb)
423 {
424         struct rsi_hw *adapter = (struct rsi_hw *)common->priv;
425         struct rsi_data_desc *bcn_frm;
426         struct ieee80211_hw *hw = common->priv->hw;
427         struct ieee80211_conf *conf = &hw->conf;
428         struct ieee80211_vif *vif;
429         struct sk_buff *mac_bcn;
430         u8 vap_id = 0, i;
431         u16 tim_offset = 0;
432
433         for (i = 0; i < RSI_MAX_VIFS; i++) {
434                 vif = adapter->vifs[i];
435                 if (!vif)
436                         continue;
437                 if ((vif->type == NL80211_IFTYPE_AP) ||
438                     (vif->type == NL80211_IFTYPE_P2P_GO))
439                         break;
440         }
441         if (!vif)
442                 return -EINVAL;
443         mac_bcn = ieee80211_beacon_get_tim(adapter->hw,
444                                            vif,
445                                            &tim_offset, NULL);
446         if (!mac_bcn) {
447                 rsi_dbg(ERR_ZONE, "Failed to get beacon from mac80211\n");
448                 return -EINVAL;
449         }
450
451         common->beacon_cnt++;
452         bcn_frm = (struct rsi_data_desc *)skb->data;
453         rsi_set_len_qno(&bcn_frm->len_qno, mac_bcn->len, RSI_WIFI_DATA_Q);
454         bcn_frm->header_len = MIN_802_11_HDR_LEN;
455         bcn_frm->frame_info = cpu_to_le16(RSI_DATA_DESC_MAC_BBP_INFO |
456                                           RSI_DATA_DESC_NO_ACK_IND |
457                                           RSI_DATA_DESC_BEACON_FRAME |
458                                           RSI_DATA_DESC_INSERT_TSF |
459                                           RSI_DATA_DESC_INSERT_SEQ_NO |
460                                           RATE_INFO_ENABLE);
461         bcn_frm->rate_info = cpu_to_le16(vap_id << 14);
462         bcn_frm->qid_tid = BEACON_HW_Q;
463
464         if (conf_is_ht40_plus(conf)) {
465                 bcn_frm->bbp_info = cpu_to_le16(LOWER_20_ENABLE);
466                 bcn_frm->bbp_info |= cpu_to_le16(LOWER_20_ENABLE >> 12);
467         } else if (conf_is_ht40_minus(conf)) {
468                 bcn_frm->bbp_info = cpu_to_le16(UPPER_20_ENABLE);
469                 bcn_frm->bbp_info |= cpu_to_le16(UPPER_20_ENABLE >> 12);
470         }
471
472         if (common->band == NL80211_BAND_2GHZ)
473                 bcn_frm->rate_info |= cpu_to_le16(RSI_RATE_1);
474         else
475                 bcn_frm->rate_info |= cpu_to_le16(RSI_RATE_6);
476
477         if (mac_bcn->data[tim_offset + 2] == 0)
478                 bcn_frm->frame_info |= cpu_to_le16(RSI_DATA_DESC_DTIM_BEACON);
479
480         memcpy(&skb->data[FRAME_DESC_SZ], mac_bcn->data, mac_bcn->len);
481         skb_put(skb, mac_bcn->len + FRAME_DESC_SZ);
482
483         dev_kfree_skb(mac_bcn);
484
485         return 0;
486 }
487
488 static void bl_cmd_timeout(struct timer_list *t)
489 {
490         struct rsi_hw *adapter = from_timer(adapter, t, bl_cmd_timer);
491
492         adapter->blcmd_timer_expired = true;
493         del_timer(&adapter->bl_cmd_timer);
494 }
495
496 static int bl_start_cmd_timer(struct rsi_hw *adapter, u32 timeout)
497 {
498         timer_setup(&adapter->bl_cmd_timer, bl_cmd_timeout, 0);
499         adapter->bl_cmd_timer.expires = (msecs_to_jiffies(timeout) + jiffies);
500
501         adapter->blcmd_timer_expired = false;
502         add_timer(&adapter->bl_cmd_timer);
503
504         return 0;
505 }
506
507 static int bl_stop_cmd_timer(struct rsi_hw *adapter)
508 {
509         adapter->blcmd_timer_expired = false;
510         if (timer_pending(&adapter->bl_cmd_timer))
511                 del_timer(&adapter->bl_cmd_timer);
512
513         return 0;
514 }
515
516 static int bl_write_cmd(struct rsi_hw *adapter, u8 cmd, u8 exp_resp,
517                         u16 *cmd_resp)
518 {
519         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
520         u32 regin_val = 0, regout_val = 0;
521         u32 regin_input = 0;
522         u8 output = 0;
523         int status;
524
525         regin_input = (REGIN_INPUT | adapter->priv->coex_mode);
526
527         while (!adapter->blcmd_timer_expired) {
528                 regin_val = 0;
529                 status = hif_ops->master_reg_read(adapter, SWBL_REGIN,
530                                                   &regin_val, 2);
531                 if (status < 0) {
532                         rsi_dbg(ERR_ZONE,
533                                 "%s: Command %0x REGIN reading failed..\n",
534                                 __func__, cmd);
535                         return status;
536                 }
537                 mdelay(1);
538                 if ((regin_val >> 12) != REGIN_VALID)
539                         break;
540         }
541         if (adapter->blcmd_timer_expired) {
542                 rsi_dbg(ERR_ZONE,
543                         "%s: Command %0x REGIN reading timed out..\n",
544                         __func__, cmd);
545                 return -ETIMEDOUT;
546         }
547
548         rsi_dbg(INFO_ZONE,
549                 "Issuing write to Regin val:%0x sending cmd:%0x\n",
550                 regin_val, (cmd | regin_input << 8));
551         status = hif_ops->master_reg_write(adapter, SWBL_REGIN,
552                                            (cmd | regin_input << 8), 2);
553         if (status < 0)
554                 return status;
555         mdelay(1);
556
557         if (cmd == LOAD_HOSTED_FW || cmd == JUMP_TO_ZERO_PC) {
558                 /* JUMP_TO_ZERO_PC doesn't expect
559                  * any response. So return from here
560                  */
561                 return 0;
562         }
563
564         while (!adapter->blcmd_timer_expired) {
565                 regout_val = 0;
566                 status = hif_ops->master_reg_read(adapter, SWBL_REGOUT,
567                                              &regout_val, 2);
568                 if (status < 0) {
569                         rsi_dbg(ERR_ZONE,
570                                 "%s: Command %0x REGOUT reading failed..\n",
571                                 __func__, cmd);
572                         return status;
573                 }
574                 mdelay(1);
575                 if ((regout_val >> 8) == REGOUT_VALID)
576                         break;
577         }
578         if (adapter->blcmd_timer_expired) {
579                 rsi_dbg(ERR_ZONE,
580                         "%s: Command %0x REGOUT reading timed out..\n",
581                         __func__, cmd);
582                 return status;
583         }
584
585         *cmd_resp = ((u16 *)&regout_val)[0] & 0xffff;
586
587         output = ((u8 *)&regout_val)[0] & 0xff;
588
589         status = hif_ops->master_reg_write(adapter, SWBL_REGOUT,
590                                            (cmd | REGOUT_INVALID << 8), 2);
591         if (status < 0) {
592                 rsi_dbg(ERR_ZONE,
593                         "%s: Command %0x REGOUT writing failed..\n",
594                         __func__, cmd);
595                 return status;
596         }
597         mdelay(1);
598
599         if (output != exp_resp) {
600                 rsi_dbg(ERR_ZONE,
601                         "%s: Recvd resp %x for cmd %0x\n",
602                         __func__, output, cmd);
603                 return -EINVAL;
604         }
605         rsi_dbg(INFO_ZONE,
606                 "%s: Recvd Expected resp %x for cmd %0x\n",
607                 __func__, output, cmd);
608
609         return 0;
610 }
611
612 static int bl_cmd(struct rsi_hw *adapter, u8 cmd, u8 exp_resp, char *str)
613 {
614         u16 regout_val = 0;
615         u32 timeout;
616         int status;
617
618         if ((cmd == EOF_REACHED) || (cmd == PING_VALID) || (cmd == PONG_VALID))
619                 timeout = BL_BURN_TIMEOUT;
620         else
621                 timeout = BL_CMD_TIMEOUT;
622
623         bl_start_cmd_timer(adapter, timeout);
624         status = bl_write_cmd(adapter, cmd, exp_resp, &regout_val);
625         if (status < 0) {
626                 bl_stop_cmd_timer(adapter);
627                 rsi_dbg(ERR_ZONE,
628                         "%s: Command %s (%0x) writing failed..\n",
629                         __func__, str, cmd);
630                 return status;
631         }
632         bl_stop_cmd_timer(adapter);
633         return 0;
634 }
635
636 #define CHECK_SUM_OFFSET 20
637 #define LEN_OFFSET 8
638 #define ADDR_OFFSET 16
639 static int bl_write_header(struct rsi_hw *adapter, u8 *flash_content,
640                            u32 content_size)
641 {
642         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
643         struct bl_header *bl_hdr;
644         u32 write_addr, write_len;
645         int status;
646
647         bl_hdr = kzalloc(sizeof(*bl_hdr), GFP_KERNEL);
648         if (!bl_hdr)
649                 return -ENOMEM;
650
651         bl_hdr->flags = 0;
652         bl_hdr->image_no = cpu_to_le32(adapter->priv->coex_mode);
653         bl_hdr->check_sum =
654                 cpu_to_le32(*(u32 *)&flash_content[CHECK_SUM_OFFSET]);
655         bl_hdr->flash_start_address =
656                 cpu_to_le32(*(u32 *)&flash_content[ADDR_OFFSET]);
657         bl_hdr->flash_len = cpu_to_le32(*(u32 *)&flash_content[LEN_OFFSET]);
658         write_len = sizeof(struct bl_header);
659
660         if (adapter->rsi_host_intf == RSI_HOST_INTF_USB) {
661                 write_addr = PING_BUFFER_ADDRESS;
662                 status = hif_ops->write_reg_multiple(adapter, write_addr,
663                                                  (u8 *)bl_hdr, write_len);
664                 if (status < 0) {
665                         rsi_dbg(ERR_ZONE,
666                                 "%s: Failed to load Version/CRC structure\n",
667                                 __func__);
668                         goto fail;
669                 }
670         } else {
671                 write_addr = PING_BUFFER_ADDRESS >> 16;
672                 status = hif_ops->master_access_msword(adapter, write_addr);
673                 if (status < 0) {
674                         rsi_dbg(ERR_ZONE,
675                                 "%s: Unable to set ms word to common reg\n",
676                                 __func__);
677                         goto fail;
678                 }
679                 write_addr = RSI_SD_REQUEST_MASTER |
680                              (PING_BUFFER_ADDRESS & 0xFFFF);
681                 status = hif_ops->write_reg_multiple(adapter, write_addr,
682                                                  (u8 *)bl_hdr, write_len);
683                 if (status < 0) {
684                         rsi_dbg(ERR_ZONE,
685                                 "%s: Failed to load Version/CRC structure\n",
686                                 __func__);
687                         goto fail;
688                 }
689         }
690         status = 0;
691 fail:
692         kfree(bl_hdr);
693         return status;
694 }
695
696 static u32 read_flash_capacity(struct rsi_hw *adapter)
697 {
698         u32 flash_sz = 0;
699
700         if ((adapter->host_intf_ops->master_reg_read(adapter, FLASH_SIZE_ADDR,
701                                                      &flash_sz, 2)) < 0) {
702                 rsi_dbg(ERR_ZONE,
703                         "%s: Flash size reading failed..\n",
704                         __func__);
705                 return 0;
706         }
707         rsi_dbg(INIT_ZONE, "Flash capacity: %d KiloBytes\n", flash_sz);
708
709         return (flash_sz * 1024); /* Return size in kbytes */
710 }
711
712 static int ping_pong_write(struct rsi_hw *adapter, u8 cmd, u8 *addr, u32 size)
713 {
714         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
715         u32 block_size = adapter->block_size;
716         u32 cmd_addr;
717         u16 cmd_resp, cmd_req;
718         u8 *str;
719         int status;
720
721         if (cmd == PING_WRITE) {
722                 cmd_addr = PING_BUFFER_ADDRESS;
723                 cmd_resp = PONG_AVAIL;
724                 cmd_req = PING_VALID;
725                 str = "PING_VALID";
726         } else {
727                 cmd_addr = PONG_BUFFER_ADDRESS;
728                 cmd_resp = PING_AVAIL;
729                 cmd_req = PONG_VALID;
730                 str = "PONG_VALID";
731         }
732
733         status = hif_ops->load_data_master_write(adapter, cmd_addr, size,
734                                             block_size, addr);
735         if (status) {
736                 rsi_dbg(ERR_ZONE, "%s: Unable to write blk at addr %0x\n",
737                         __func__, *addr);
738                 return status;
739         }
740
741         status = bl_cmd(adapter, cmd_req, cmd_resp, str);
742         if (status)
743                 return status;
744
745         return 0;
746 }
747
748 static int auto_fw_upgrade(struct rsi_hw *adapter, u8 *flash_content,
749                            u32 content_size)
750 {
751         u8 cmd;
752         u32 temp_content_size, num_flash, index;
753         u32 flash_start_address;
754         int status;
755
756         if (content_size > MAX_FLASH_FILE_SIZE) {
757                 rsi_dbg(ERR_ZONE,
758                         "%s: Flash Content size is more than 400K %u\n",
759                         __func__, MAX_FLASH_FILE_SIZE);
760                 return -EINVAL;
761         }
762
763         flash_start_address = *(u32 *)&flash_content[FLASH_START_ADDRESS];
764         rsi_dbg(INFO_ZONE, "flash start address: %08x\n", flash_start_address);
765
766         if (flash_start_address < FW_IMAGE_MIN_ADDRESS) {
767                 rsi_dbg(ERR_ZONE,
768                         "%s: Fw image Flash Start Address is less than 64K\n",
769                         __func__);
770                 return -EINVAL;
771         }
772
773         if (flash_start_address % FLASH_SECTOR_SIZE) {
774                 rsi_dbg(ERR_ZONE,
775                         "%s: Flash Start Address is not multiple of 4K\n",
776                         __func__);
777                 return -EINVAL;
778         }
779
780         if ((flash_start_address + content_size) > adapter->flash_capacity) {
781                 rsi_dbg(ERR_ZONE,
782                         "%s: Flash Content will cross max flash size\n",
783                         __func__);
784                 return -EINVAL;
785         }
786
787         temp_content_size  = content_size;
788         num_flash = content_size / FLASH_WRITE_CHUNK_SIZE;
789
790         rsi_dbg(INFO_ZONE, "content_size: %d, num_flash: %d\n",
791                 content_size, num_flash);
792
793         for (index = 0; index <= num_flash; index++) {
794                 rsi_dbg(INFO_ZONE, "flash index: %d\n", index);
795                 if (index != num_flash) {
796                         content_size = FLASH_WRITE_CHUNK_SIZE;
797                         rsi_dbg(INFO_ZONE, "QSPI content_size:%d\n",
798                                 content_size);
799                 } else {
800                         content_size =
801                                 temp_content_size % FLASH_WRITE_CHUNK_SIZE;
802                         rsi_dbg(INFO_ZONE,
803                                 "Writing last sector content_size:%d\n",
804                                 content_size);
805                         if (!content_size) {
806                                 rsi_dbg(INFO_ZONE, "instruction size zero\n");
807                                 break;
808                         }
809                 }
810
811                 if (index % 2)
812                         cmd = PING_WRITE;
813                 else
814                         cmd = PONG_WRITE;
815
816                 status = ping_pong_write(adapter, cmd, flash_content,
817                                          content_size);
818                 if (status) {
819                         rsi_dbg(ERR_ZONE, "%s: Unable to load %d block\n",
820                                 __func__, index);
821                         return status;
822                 }
823
824                 rsi_dbg(INFO_ZONE,
825                         "%s: Successfully loaded %d instructions\n",
826                         __func__, index);
827                 flash_content += content_size;
828         }
829
830         status = bl_cmd(adapter, EOF_REACHED, FW_LOADING_SUCCESSFUL,
831                         "EOF_REACHED");
832         if (status)
833                 return status;
834
835         rsi_dbg(INFO_ZONE, "FW loading is done and FW is running..\n");
836         return 0;
837 }
838
839 static int rsi_load_firmware(struct rsi_hw *adapter)
840 {
841         struct rsi_common *common = adapter->priv;
842         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
843         const struct firmware *fw_entry = NULL;
844         u32 regout_val = 0, content_size;
845         u16 tmp_regout_val = 0;
846         struct ta_metadata *metadata_p;
847         int status;
848
849         bl_start_cmd_timer(adapter, BL_CMD_TIMEOUT);
850
851         while (!adapter->blcmd_timer_expired) {
852                 status = hif_ops->master_reg_read(adapter, SWBL_REGOUT,
853                                               &regout_val, 2);
854                 if (status < 0) {
855                         bl_stop_cmd_timer(adapter);
856                         rsi_dbg(ERR_ZONE,
857                                 "%s: REGOUT read failed\n", __func__);
858                         return status;
859                 }
860                 mdelay(1);
861                 if ((regout_val >> 8) == REGOUT_VALID)
862                         break;
863         }
864         if (adapter->blcmd_timer_expired) {
865                 rsi_dbg(ERR_ZONE, "%s: REGOUT read timedout\n", __func__);
866                 rsi_dbg(ERR_ZONE,
867                         "%s: Soft boot loader not present\n", __func__);
868                 return -ETIMEDOUT;
869         }
870         bl_stop_cmd_timer(adapter);
871
872         rsi_dbg(INFO_ZONE, "Received Board Version Number: %x\n",
873                 (regout_val & 0xff));
874
875         status = hif_ops->master_reg_write(adapter, SWBL_REGOUT,
876                                         (REGOUT_INVALID | REGOUT_INVALID << 8),
877                                         2);
878         if (status < 0) {
879                 rsi_dbg(ERR_ZONE, "%s: REGOUT writing failed..\n", __func__);
880                 return status;
881         }
882         mdelay(1);
883
884         status = bl_cmd(adapter, CONFIG_AUTO_READ_MODE, CMD_PASS,
885                         "AUTO_READ_CMD");
886         if (status < 0)
887                 return status;
888
889         adapter->flash_capacity = read_flash_capacity(adapter);
890         if (adapter->flash_capacity <= 0) {
891                 rsi_dbg(ERR_ZONE,
892                         "%s: Unable to read flash size from EEPROM\n",
893                         __func__);
894                 return -EINVAL;
895         }
896
897         metadata_p = &metadata_flash_content[adapter->priv->coex_mode];
898
899         rsi_dbg(INIT_ZONE, "%s: Loading file %s\n", __func__, metadata_p->name);
900         adapter->fw_file_name = metadata_p->name;
901
902         status = reject_firmware(&fw_entry, metadata_p->name, adapter->device);
903         if (status < 0) {
904                 rsi_dbg(ERR_ZONE, "%s: Failed to open file %s\n",
905                         __func__, metadata_p->name);
906                 return status;
907         }
908         content_size = fw_entry->size;
909         rsi_dbg(INFO_ZONE, "FW Length = %d bytes\n", content_size);
910
911         /* Get the firmware version */
912         common->lmac_ver.ver.info.fw_ver[0] =
913                 fw_entry->data[LMAC_VER_OFFSET] & 0xFF;
914         common->lmac_ver.ver.info.fw_ver[1] =
915                 fw_entry->data[LMAC_VER_OFFSET + 1] & 0xFF;
916         common->lmac_ver.major = fw_entry->data[LMAC_VER_OFFSET + 2] & 0xFF;
917         common->lmac_ver.release_num =
918                 fw_entry->data[LMAC_VER_OFFSET + 3] & 0xFF;
919         common->lmac_ver.minor = fw_entry->data[LMAC_VER_OFFSET + 4] & 0xFF;
920         common->lmac_ver.patch_num = 0;
921         rsi_print_version(common);
922
923         status = bl_write_header(adapter, (u8 *)fw_entry->data, content_size);
924         if (status) {
925                 rsi_dbg(ERR_ZONE,
926                         "%s: RPS Image header loading failed\n",
927                         __func__);
928                 goto fail;
929         }
930
931         bl_start_cmd_timer(adapter, BL_CMD_TIMEOUT);
932         status = bl_write_cmd(adapter, CHECK_CRC, CMD_PASS, &tmp_regout_val);
933         if (status) {
934                 bl_stop_cmd_timer(adapter);
935                 rsi_dbg(ERR_ZONE,
936                         "%s: CHECK_CRC Command writing failed..\n",
937                         __func__);
938                 if ((tmp_regout_val & 0xff) == CMD_FAIL) {
939                         rsi_dbg(ERR_ZONE,
940                                 "CRC Fail.. Proceeding to Upgrade mode\n");
941                         goto fw_upgrade;
942                 }
943         }
944         bl_stop_cmd_timer(adapter);
945
946         status = bl_cmd(adapter, POLLING_MODE, CMD_PASS, "POLLING_MODE");
947         if (status)
948                 goto fail;
949
950 load_image_cmd:
951         status = bl_cmd(adapter, LOAD_HOSTED_FW, LOADING_INITIATED,
952                         "LOAD_HOSTED_FW");
953         if (status)
954                 goto fail;
955         rsi_dbg(INFO_ZONE, "Load Image command passed..\n");
956         goto success;
957
958 fw_upgrade:
959         status = bl_cmd(adapter, BURN_HOSTED_FW, SEND_RPS_FILE, "FW_UPGRADE");
960         if (status)
961                 goto fail;
962
963         rsi_dbg(INFO_ZONE, "Burn Command Pass.. Upgrading the firmware\n");
964
965         status = auto_fw_upgrade(adapter, (u8 *)fw_entry->data, content_size);
966         if (status == 0) {
967                 rsi_dbg(ERR_ZONE, "Firmware upgradation Done\n");
968                 goto load_image_cmd;
969         }
970         rsi_dbg(ERR_ZONE, "Firmware upgrade failed\n");
971
972         status = bl_cmd(adapter, CONFIG_AUTO_READ_MODE, CMD_PASS,
973                         "AUTO_READ_MODE");
974         if (status)
975                 goto fail;
976
977 success:
978         rsi_dbg(ERR_ZONE, "***** Firmware Loading successful *****\n");
979         release_firmware(fw_entry);
980         return 0;
981
982 fail:
983         rsi_dbg(ERR_ZONE, "##### Firmware loading failed #####\n");
984         release_firmware(fw_entry);
985         return status;
986 }
987
988 int rsi_hal_device_init(struct rsi_hw *adapter)
989 {
990         struct rsi_common *common = adapter->priv;
991
992         switch (adapter->device_model) {
993         case RSI_DEV_9113:
994                 if (rsi_load_firmware(adapter)) {
995                         rsi_dbg(ERR_ZONE,
996                                 "%s: Failed to load TA instructions\n",
997                                 __func__);
998                         return -EINVAL;
999                 }
1000                 break;
1001         default:
1002                 return -EINVAL;
1003         }
1004         common->fsm_state = FSM_CARD_NOT_READY;
1005
1006         return 0;
1007 }
1008 EXPORT_SYMBOL_GPL(rsi_hal_device_init);
1009