GNU Linux-libre 4.19.264-gnu1
[releases.git] / drivers / net / wireless / rsi / rsi_91x_hal.c
1 /**
2  * Copyright (c) 2014 Redpine Signals Inc.
3  *
4  * Permission to use, copy, modify, and/or distribute this software for any
5  * purpose with or without fee is hereby granted, provided that the above
6  * copyright notice and this permission notice appear in all copies.
7  *
8  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15  */
16
17 #include <linux/firmware.h>
18 #include <net/bluetooth/bluetooth.h>
19 #include "rsi_mgmt.h"
20 #include "rsi_hal.h"
21 #include "rsi_sdio.h"
22 #include "rsi_common.h"
23
24 /* FLASH Firmware */
25 static struct ta_metadata metadata_flash_content[] = {
26         {"flash_content", 0x00010000},
27         {"/*(DEBLOBBED)*/", 0x00010000},
28         {"rsi/rs9113_wlan_bt_dual_mode.rps", 0x00010000},
29         {"flash_content", 0x00010000},
30         {"rsi/rs9113_ap_bt_dual_mode.rps", 0x00010000},
31
32 };
33
34 int rsi_send_pkt_to_bus(struct rsi_common *common, struct sk_buff *skb)
35 {
36         struct rsi_hw *adapter = common->priv;
37         int status;
38
39         if (common->coex_mode > 1)
40                 mutex_lock(&common->tx_bus_mutex);
41
42         status = adapter->host_intf_ops->write_pkt(common->priv,
43                                                    skb->data, skb->len);
44
45         if (common->coex_mode > 1)
46                 mutex_unlock(&common->tx_bus_mutex);
47
48         return status;
49 }
50
51 int rsi_prepare_mgmt_desc(struct rsi_common *common, struct sk_buff *skb)
52 {
53         struct rsi_hw *adapter = common->priv;
54         struct ieee80211_hdr *wh = NULL;
55         struct ieee80211_tx_info *info;
56         struct ieee80211_conf *conf = &adapter->hw->conf;
57         struct ieee80211_vif *vif;
58         struct rsi_mgmt_desc *mgmt_desc;
59         struct skb_info *tx_params;
60         struct rsi_xtended_desc *xtend_desc = NULL;
61         u8 header_size;
62         u32 dword_align_bytes = 0;
63
64         if (skb->len > MAX_MGMT_PKT_SIZE) {
65                 rsi_dbg(INFO_ZONE, "%s: Dropping mgmt pkt > 512\n", __func__);
66                 return -EINVAL;
67         }
68
69         info = IEEE80211_SKB_CB(skb);
70         tx_params = (struct skb_info *)info->driver_data;
71         vif = tx_params->vif;
72
73         /* Update header size */
74         header_size = FRAME_DESC_SZ + sizeof(struct rsi_xtended_desc);
75         if (header_size > skb_headroom(skb)) {
76                 rsi_dbg(ERR_ZONE,
77                         "%s: Failed to add extended descriptor\n",
78                         __func__);
79                 return -ENOSPC;
80         }
81         skb_push(skb, header_size);
82         dword_align_bytes = ((unsigned long)skb->data & 0x3f);
83         if (dword_align_bytes > skb_headroom(skb)) {
84                 rsi_dbg(ERR_ZONE,
85                         "%s: Failed to add dword align\n", __func__);
86                 return -ENOSPC;
87         }
88         skb_push(skb, dword_align_bytes);
89         header_size += dword_align_bytes;
90
91         tx_params->internal_hdr_size = header_size;
92         memset(&skb->data[0], 0, header_size);
93         wh = (struct ieee80211_hdr *)&skb->data[header_size];
94
95         mgmt_desc = (struct rsi_mgmt_desc *)skb->data;
96         xtend_desc = (struct rsi_xtended_desc *)&skb->data[FRAME_DESC_SZ];
97
98         rsi_set_len_qno(&mgmt_desc->len_qno, (skb->len - FRAME_DESC_SZ),
99                         RSI_WIFI_MGMT_Q);
100         mgmt_desc->frame_type = TX_DOT11_MGMT;
101         mgmt_desc->header_len = MIN_802_11_HDR_LEN;
102         mgmt_desc->xtend_desc_size = header_size - FRAME_DESC_SZ;
103         mgmt_desc->frame_info |= cpu_to_le16(RATE_INFO_ENABLE);
104         if (is_broadcast_ether_addr(wh->addr1))
105                 mgmt_desc->frame_info |= cpu_to_le16(RSI_BROADCAST_PKT);
106
107         mgmt_desc->seq_ctrl =
108                 cpu_to_le16(IEEE80211_SEQ_TO_SN(le16_to_cpu(wh->seq_ctrl)));
109         if ((common->band == NL80211_BAND_2GHZ) && !common->p2p_enabled)
110                 mgmt_desc->rate_info = cpu_to_le16(RSI_RATE_1);
111         else
112                 mgmt_desc->rate_info = cpu_to_le16(RSI_RATE_6);
113
114         if (conf_is_ht40(conf))
115                 mgmt_desc->bbp_info = cpu_to_le16(FULL40M_ENABLE);
116
117         if (ieee80211_is_probe_resp(wh->frame_control)) {
118                 mgmt_desc->misc_flags |= (RSI_ADD_DELTA_TSF_VAP_ID |
119                                           RSI_FETCH_RETRY_CNT_FRM_HST);
120 #define PROBE_RESP_RETRY_CNT    3
121                 xtend_desc->retry_cnt = PROBE_RESP_RETRY_CNT;
122         }
123
124         if (((vif->type == NL80211_IFTYPE_AP) ||
125              (vif->type == NL80211_IFTYPE_P2P_GO)) &&
126             (ieee80211_is_action(wh->frame_control))) {
127                 struct rsi_sta *rsta = rsi_find_sta(common, wh->addr1);
128
129                 if (rsta)
130                         mgmt_desc->sta_id = tx_params->sta_id;
131                 else
132                         return -EINVAL;
133         }
134         mgmt_desc->rate_info |=
135                 cpu_to_le16((tx_params->vap_id << RSI_DESC_VAP_ID_OFST) &
136                             RSI_DESC_VAP_ID_MASK);
137
138         return 0;
139 }
140
141 /* This function prepares descriptor for given data packet */
142 int rsi_prepare_data_desc(struct rsi_common *common, struct sk_buff *skb)
143 {
144         struct rsi_hw *adapter = common->priv;
145         struct ieee80211_vif *vif;
146         struct ieee80211_hdr *wh = NULL;
147         struct ieee80211_tx_info *info;
148         struct skb_info *tx_params;
149         struct rsi_data_desc *data_desc;
150         struct rsi_xtended_desc *xtend_desc;
151         u8 ieee80211_size = MIN_802_11_HDR_LEN;
152         u8 header_size;
153         u8 vap_id = 0;
154         u8 dword_align_bytes;
155         u16 seq_num;
156
157         info = IEEE80211_SKB_CB(skb);
158         vif = info->control.vif;
159         tx_params = (struct skb_info *)info->driver_data;
160
161         header_size = FRAME_DESC_SZ + sizeof(struct rsi_xtended_desc);
162         if (header_size > skb_headroom(skb)) {
163                 rsi_dbg(ERR_ZONE, "%s: Unable to send pkt\n", __func__);
164                 return -ENOSPC;
165         }
166         skb_push(skb, header_size);
167         dword_align_bytes = ((unsigned long)skb->data & 0x3f);
168         if (header_size > skb_headroom(skb)) {
169                 rsi_dbg(ERR_ZONE, "%s: Not enough headroom\n", __func__);
170                 return -ENOSPC;
171         }
172         skb_push(skb, dword_align_bytes);
173         header_size += dword_align_bytes;
174
175         tx_params->internal_hdr_size = header_size;
176         data_desc = (struct rsi_data_desc *)skb->data;
177         memset(data_desc, 0, header_size);
178
179         xtend_desc = (struct rsi_xtended_desc *)&skb->data[FRAME_DESC_SZ];
180         wh = (struct ieee80211_hdr *)&skb->data[header_size];
181         seq_num = IEEE80211_SEQ_TO_SN(le16_to_cpu(wh->seq_ctrl));
182
183         data_desc->xtend_desc_size = header_size - FRAME_DESC_SZ;
184
185         if (ieee80211_is_data_qos(wh->frame_control)) {
186                 ieee80211_size += 2;
187                 data_desc->mac_flags |= cpu_to_le16(RSI_QOS_ENABLE);
188         }
189
190         if (((vif->type == NL80211_IFTYPE_STATION) ||
191              (vif->type == NL80211_IFTYPE_P2P_CLIENT)) &&
192             (adapter->ps_state == PS_ENABLED))
193                 wh->frame_control |= cpu_to_le16(RSI_SET_PS_ENABLE);
194
195         if ((!(info->flags & IEEE80211_TX_INTFL_DONT_ENCRYPT)) &&
196             tx_params->have_key) {
197                 if (rsi_is_cipher_wep(common))
198                         ieee80211_size += 4;
199                 else
200                         ieee80211_size += 8;
201                 data_desc->mac_flags |= cpu_to_le16(RSI_ENCRYPT_PKT);
202         }
203         rsi_set_len_qno(&data_desc->len_qno, (skb->len - FRAME_DESC_SZ),
204                         RSI_WIFI_DATA_Q);
205         data_desc->header_len = ieee80211_size;
206
207         if (common->rate_config[common->band].fixed_enabled) {
208                 /* Send fixed rate */
209                 u16 fixed_rate = common->rate_config[common->band].fixed_hw_rate;
210
211                 data_desc->frame_info = cpu_to_le16(RATE_INFO_ENABLE);
212                 data_desc->rate_info = cpu_to_le16(fixed_rate);
213
214                 if (conf_is_ht40(&common->priv->hw->conf))
215                         data_desc->bbp_info = cpu_to_le16(FULL40M_ENABLE);
216
217                 if (common->vif_info[0].sgi && (fixed_rate & 0x100)) {
218                        /* Only MCS rates */
219                         data_desc->rate_info |=
220                                 cpu_to_le16(ENABLE_SHORTGI_RATE);
221                 }
222         }
223
224         if (skb->protocol == cpu_to_be16(ETH_P_PAE)) {
225                 rsi_dbg(INFO_ZONE, "*** Tx EAPOL ***\n");
226
227                 data_desc->frame_info = cpu_to_le16(RATE_INFO_ENABLE);
228                 if (common->band == NL80211_BAND_5GHZ)
229                         data_desc->rate_info = cpu_to_le16(RSI_RATE_6);
230                 else
231                         data_desc->rate_info = cpu_to_le16(RSI_RATE_1);
232                 data_desc->mac_flags |= cpu_to_le16(RSI_REKEY_PURPOSE);
233                 data_desc->misc_flags |= RSI_FETCH_RETRY_CNT_FRM_HST;
234 #define EAPOL_RETRY_CNT 15
235                 xtend_desc->retry_cnt = EAPOL_RETRY_CNT;
236
237                 if (common->eapol4_confirm)
238                         skb->priority = VO_Q;
239                 else
240                         rsi_set_len_qno(&data_desc->len_qno,
241                                         (skb->len - FRAME_DESC_SZ),
242                                         RSI_WIFI_MGMT_Q);
243                 if (((skb->len - header_size) == EAPOL4_PACKET_LEN) ||
244                     ((skb->len - header_size) == EAPOL4_PACKET_LEN - 2)) {
245                         data_desc->misc_flags |=
246                                 RSI_DESC_REQUIRE_CFM_TO_HOST;
247                         xtend_desc->confirm_frame_type = EAPOL4_CONFIRM;
248                 }
249         }
250
251         data_desc->mac_flags |= cpu_to_le16(seq_num & 0xfff);
252         data_desc->qid_tid = ((skb->priority & 0xf) |
253                               ((tx_params->tid & 0xf) << 4));
254         data_desc->sta_id = tx_params->sta_id;
255
256         if ((is_broadcast_ether_addr(wh->addr1)) ||
257             (is_multicast_ether_addr(wh->addr1))) {
258                 data_desc->frame_info = cpu_to_le16(RATE_INFO_ENABLE);
259                 data_desc->frame_info |= cpu_to_le16(RSI_BROADCAST_PKT);
260                 data_desc->sta_id = vap_id;
261
262                 if ((vif->type == NL80211_IFTYPE_AP) ||
263                     (vif->type == NL80211_IFTYPE_P2P_GO)) {
264                         if (common->band == NL80211_BAND_5GHZ)
265                                 data_desc->rate_info = cpu_to_le16(RSI_RATE_6);
266                         else
267                                 data_desc->rate_info = cpu_to_le16(RSI_RATE_1);
268                 }
269         }
270         if (((vif->type == NL80211_IFTYPE_AP) ||
271              (vif->type == NL80211_IFTYPE_P2P_GO)) &&
272             (ieee80211_has_moredata(wh->frame_control)))
273                 data_desc->frame_info |= cpu_to_le16(MORE_DATA_PRESENT);
274
275         data_desc->rate_info |=
276                 cpu_to_le16((tx_params->vap_id << RSI_DESC_VAP_ID_OFST) &
277                             RSI_DESC_VAP_ID_MASK);
278
279         return 0;
280 }
281
282 /* This function sends received data packet from driver to device */
283 int rsi_send_data_pkt(struct rsi_common *common, struct sk_buff *skb)
284 {
285         struct rsi_hw *adapter = common->priv;
286         struct ieee80211_vif *vif;
287         struct ieee80211_tx_info *info;
288         struct skb_info *tx_params;
289         struct ieee80211_bss_conf *bss;
290         int status = -EINVAL;
291         u8 header_size;
292
293         if (!skb)
294                 return 0;
295         if (common->iface_down)
296                 goto err;
297
298         info = IEEE80211_SKB_CB(skb);
299         if (!info->control.vif)
300                 goto err;
301         vif = info->control.vif;
302         bss = &vif->bss_conf;
303         tx_params = (struct skb_info *)info->driver_data;
304         header_size = tx_params->internal_hdr_size;
305
306         if (((vif->type == NL80211_IFTYPE_STATION) ||
307              (vif->type == NL80211_IFTYPE_P2P_CLIENT)) &&
308             (!bss->assoc))
309                 goto err;
310
311         status = rsi_send_pkt_to_bus(common, skb);
312         if (status)
313                 rsi_dbg(ERR_ZONE, "%s: Failed to write pkt\n", __func__);
314
315 err:
316         ++common->tx_stats.total_tx_pkt_freed[skb->priority];
317         rsi_indicate_tx_status(adapter, skb, status);
318         return status;
319 }
320
321 /**
322  * rsi_send_mgmt_pkt() - This functions sends the received management packet
323  *                       from driver to device.
324  * @common: Pointer to the driver private structure.
325  * @skb: Pointer to the socket buffer structure.
326  *
327  * Return: status: 0 on success, -1 on failure.
328  */
329 int rsi_send_mgmt_pkt(struct rsi_common *common,
330                       struct sk_buff *skb)
331 {
332         struct rsi_hw *adapter = common->priv;
333         struct ieee80211_bss_conf *bss;
334         struct ieee80211_hdr *wh;
335         struct ieee80211_tx_info *info;
336         struct skb_info *tx_params;
337         struct rsi_mgmt_desc *mgmt_desc;
338         struct rsi_xtended_desc *xtend_desc;
339         int status = -E2BIG;
340         u8 header_size;
341
342         info = IEEE80211_SKB_CB(skb);
343         tx_params = (struct skb_info *)info->driver_data;
344         header_size = tx_params->internal_hdr_size;
345
346         if (tx_params->flags & INTERNAL_MGMT_PKT) {
347                 status = adapter->host_intf_ops->write_pkt(common->priv,
348                                                            (u8 *)skb->data,
349                                                            skb->len);
350                 if (status) {
351                         rsi_dbg(ERR_ZONE,
352                                 "%s: Failed to write the packet\n", __func__);
353                 }
354                 dev_kfree_skb(skb);
355                 return status;
356         }
357
358         bss = &info->control.vif->bss_conf;
359         wh = (struct ieee80211_hdr *)&skb->data[header_size];
360         mgmt_desc = (struct rsi_mgmt_desc *)skb->data;
361         xtend_desc = (struct rsi_xtended_desc *)&skb->data[FRAME_DESC_SZ];
362
363         /* Indicate to firmware to give cfm for probe */
364         if (ieee80211_is_probe_req(wh->frame_control) && !bss->assoc) {
365                 rsi_dbg(INFO_ZONE,
366                         "%s: blocking mgmt queue\n", __func__);
367                 mgmt_desc->misc_flags = RSI_DESC_REQUIRE_CFM_TO_HOST;
368                 xtend_desc->confirm_frame_type = PROBEREQ_CONFIRM;
369                 common->mgmt_q_block = true;
370                 rsi_dbg(INFO_ZONE, "Mgmt queue blocked\n");
371         }
372
373         status = rsi_send_pkt_to_bus(common, skb);
374         if (status)
375                 rsi_dbg(ERR_ZONE, "%s: Failed to write the packet\n", __func__);
376
377         rsi_indicate_tx_status(common->priv, skb, status);
378         return status;
379 }
380
381 int rsi_send_bt_pkt(struct rsi_common *common, struct sk_buff *skb)
382 {
383         int status = -EINVAL;
384         u8 header_size = 0;
385         struct rsi_bt_desc *bt_desc;
386         u8 queueno = ((skb->data[1] >> 4) & 0xf);
387
388         if (queueno == RSI_BT_MGMT_Q) {
389                 status = rsi_send_pkt_to_bus(common, skb);
390                 if (status)
391                         rsi_dbg(ERR_ZONE, "%s: Failed to write bt mgmt pkt\n",
392                                 __func__);
393                 goto out;
394         }
395         header_size = FRAME_DESC_SZ;
396         if (header_size > skb_headroom(skb)) {
397                 rsi_dbg(ERR_ZONE, "%s: Not enough headroom\n", __func__);
398                 status = -ENOSPC;
399                 goto out;
400         }
401         skb_push(skb, header_size);
402         memset(skb->data, 0, header_size);
403         bt_desc = (struct rsi_bt_desc *)skb->data;
404
405         rsi_set_len_qno(&bt_desc->len_qno, (skb->len - FRAME_DESC_SZ),
406                         RSI_BT_DATA_Q);
407         bt_desc->bt_pkt_type = cpu_to_le16(bt_cb(skb)->pkt_type);
408
409         status = rsi_send_pkt_to_bus(common, skb);
410         if (status)
411                 rsi_dbg(ERR_ZONE, "%s: Failed to write bt pkt\n", __func__);
412
413 out:
414         dev_kfree_skb(skb);
415         return status;
416 }
417
418 int rsi_prepare_beacon(struct rsi_common *common, struct sk_buff *skb)
419 {
420         struct rsi_hw *adapter = (struct rsi_hw *)common->priv;
421         struct rsi_data_desc *bcn_frm;
422         struct ieee80211_hw *hw = common->priv->hw;
423         struct ieee80211_conf *conf = &hw->conf;
424         struct ieee80211_vif *vif;
425         struct sk_buff *mac_bcn;
426         u8 vap_id = 0, i;
427         u16 tim_offset = 0;
428
429         for (i = 0; i < RSI_MAX_VIFS; i++) {
430                 vif = adapter->vifs[i];
431                 if (!vif)
432                         continue;
433                 if ((vif->type == NL80211_IFTYPE_AP) ||
434                     (vif->type == NL80211_IFTYPE_P2P_GO))
435                         break;
436         }
437         if (!vif)
438                 return -EINVAL;
439         mac_bcn = ieee80211_beacon_get_tim(adapter->hw,
440                                            vif,
441                                            &tim_offset, NULL);
442         if (!mac_bcn) {
443                 rsi_dbg(ERR_ZONE, "Failed to get beacon from mac80211\n");
444                 return -EINVAL;
445         }
446
447         common->beacon_cnt++;
448         bcn_frm = (struct rsi_data_desc *)skb->data;
449         rsi_set_len_qno(&bcn_frm->len_qno, mac_bcn->len, RSI_WIFI_DATA_Q);
450         bcn_frm->header_len = MIN_802_11_HDR_LEN;
451         bcn_frm->frame_info = cpu_to_le16(RSI_DATA_DESC_MAC_BBP_INFO |
452                                           RSI_DATA_DESC_NO_ACK_IND |
453                                           RSI_DATA_DESC_BEACON_FRAME |
454                                           RSI_DATA_DESC_INSERT_TSF |
455                                           RSI_DATA_DESC_INSERT_SEQ_NO |
456                                           RATE_INFO_ENABLE);
457         bcn_frm->rate_info = cpu_to_le16(vap_id << 14);
458         bcn_frm->qid_tid = BEACON_HW_Q;
459
460         if (conf_is_ht40_plus(conf)) {
461                 bcn_frm->bbp_info = cpu_to_le16(LOWER_20_ENABLE);
462                 bcn_frm->bbp_info |= cpu_to_le16(LOWER_20_ENABLE >> 12);
463         } else if (conf_is_ht40_minus(conf)) {
464                 bcn_frm->bbp_info = cpu_to_le16(UPPER_20_ENABLE);
465                 bcn_frm->bbp_info |= cpu_to_le16(UPPER_20_ENABLE >> 12);
466         }
467
468         if (common->band == NL80211_BAND_2GHZ)
469                 bcn_frm->rate_info |= cpu_to_le16(RSI_RATE_1);
470         else
471                 bcn_frm->rate_info |= cpu_to_le16(RSI_RATE_6);
472
473         if (mac_bcn->data[tim_offset + 2] == 0)
474                 bcn_frm->frame_info |= cpu_to_le16(RSI_DATA_DESC_DTIM_BEACON);
475
476         memcpy(&skb->data[FRAME_DESC_SZ], mac_bcn->data, mac_bcn->len);
477         skb_put(skb, mac_bcn->len + FRAME_DESC_SZ);
478
479         dev_kfree_skb(mac_bcn);
480
481         return 0;
482 }
483
484 static void bl_cmd_timeout(struct timer_list *t)
485 {
486         struct rsi_hw *adapter = from_timer(adapter, t, bl_cmd_timer);
487
488         adapter->blcmd_timer_expired = true;
489         del_timer(&adapter->bl_cmd_timer);
490 }
491
492 static int bl_start_cmd_timer(struct rsi_hw *adapter, u32 timeout)
493 {
494         timer_setup(&adapter->bl_cmd_timer, bl_cmd_timeout, 0);
495         adapter->bl_cmd_timer.expires = (msecs_to_jiffies(timeout) + jiffies);
496
497         adapter->blcmd_timer_expired = false;
498         add_timer(&adapter->bl_cmd_timer);
499
500         return 0;
501 }
502
503 static int bl_stop_cmd_timer(struct rsi_hw *adapter)
504 {
505         adapter->blcmd_timer_expired = false;
506         if (timer_pending(&adapter->bl_cmd_timer))
507                 del_timer(&adapter->bl_cmd_timer);
508
509         return 0;
510 }
511
512 static int bl_write_cmd(struct rsi_hw *adapter, u8 cmd, u8 exp_resp,
513                         u16 *cmd_resp)
514 {
515         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
516         u32 regin_val = 0, regout_val = 0;
517         u32 regin_input = 0;
518         u8 output = 0;
519         int status;
520
521         regin_input = (REGIN_INPUT | adapter->priv->coex_mode);
522
523         while (!adapter->blcmd_timer_expired) {
524                 regin_val = 0;
525                 status = hif_ops->master_reg_read(adapter, SWBL_REGIN,
526                                                   &regin_val, 2);
527                 if (status < 0) {
528                         rsi_dbg(ERR_ZONE,
529                                 "%s: Command %0x REGIN reading failed..\n",
530                                 __func__, cmd);
531                         return status;
532                 }
533                 mdelay(1);
534                 if ((regin_val >> 12) != REGIN_VALID)
535                         break;
536         }
537         if (adapter->blcmd_timer_expired) {
538                 rsi_dbg(ERR_ZONE,
539                         "%s: Command %0x REGIN reading timed out..\n",
540                         __func__, cmd);
541                 return -ETIMEDOUT;
542         }
543
544         rsi_dbg(INFO_ZONE,
545                 "Issuing write to Regin val:%0x sending cmd:%0x\n",
546                 regin_val, (cmd | regin_input << 8));
547         status = hif_ops->master_reg_write(adapter, SWBL_REGIN,
548                                            (cmd | regin_input << 8), 2);
549         if (status < 0)
550                 return status;
551         mdelay(1);
552
553         if (cmd == LOAD_HOSTED_FW || cmd == JUMP_TO_ZERO_PC) {
554                 /* JUMP_TO_ZERO_PC doesn't expect
555                  * any response. So return from here
556                  */
557                 return 0;
558         }
559
560         while (!adapter->blcmd_timer_expired) {
561                 regout_val = 0;
562                 status = hif_ops->master_reg_read(adapter, SWBL_REGOUT,
563                                              &regout_val, 2);
564                 if (status < 0) {
565                         rsi_dbg(ERR_ZONE,
566                                 "%s: Command %0x REGOUT reading failed..\n",
567                                 __func__, cmd);
568                         return status;
569                 }
570                 mdelay(1);
571                 if ((regout_val >> 8) == REGOUT_VALID)
572                         break;
573         }
574         if (adapter->blcmd_timer_expired) {
575                 rsi_dbg(ERR_ZONE,
576                         "%s: Command %0x REGOUT reading timed out..\n",
577                         __func__, cmd);
578                 return status;
579         }
580
581         *cmd_resp = ((u16 *)&regout_val)[0] & 0xffff;
582
583         output = ((u8 *)&regout_val)[0] & 0xff;
584
585         status = hif_ops->master_reg_write(adapter, SWBL_REGOUT,
586                                            (cmd | REGOUT_INVALID << 8), 2);
587         if (status < 0) {
588                 rsi_dbg(ERR_ZONE,
589                         "%s: Command %0x REGOUT writing failed..\n",
590                         __func__, cmd);
591                 return status;
592         }
593         mdelay(1);
594
595         if (output != exp_resp) {
596                 rsi_dbg(ERR_ZONE,
597                         "%s: Recvd resp %x for cmd %0x\n",
598                         __func__, output, cmd);
599                 return -EINVAL;
600         }
601         rsi_dbg(INFO_ZONE,
602                 "%s: Recvd Expected resp %x for cmd %0x\n",
603                 __func__, output, cmd);
604
605         return 0;
606 }
607
608 static int bl_cmd(struct rsi_hw *adapter, u8 cmd, u8 exp_resp, char *str)
609 {
610         u16 regout_val = 0;
611         u32 timeout;
612         int status;
613
614         if ((cmd == EOF_REACHED) || (cmd == PING_VALID) || (cmd == PONG_VALID))
615                 timeout = BL_BURN_TIMEOUT;
616         else
617                 timeout = BL_CMD_TIMEOUT;
618
619         bl_start_cmd_timer(adapter, timeout);
620         status = bl_write_cmd(adapter, cmd, exp_resp, &regout_val);
621         if (status < 0) {
622                 bl_stop_cmd_timer(adapter);
623                 rsi_dbg(ERR_ZONE,
624                         "%s: Command %s (%0x) writing failed..\n",
625                         __func__, str, cmd);
626                 return status;
627         }
628         bl_stop_cmd_timer(adapter);
629         return 0;
630 }
631
632 #define CHECK_SUM_OFFSET 20
633 #define LEN_OFFSET 8
634 #define ADDR_OFFSET 16
635 static int bl_write_header(struct rsi_hw *adapter, u8 *flash_content,
636                            u32 content_size)
637 {
638         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
639         struct bl_header *bl_hdr;
640         u32 write_addr, write_len;
641         int status;
642
643         bl_hdr = kzalloc(sizeof(*bl_hdr), GFP_KERNEL);
644         if (!bl_hdr)
645                 return -ENOMEM;
646
647         bl_hdr->flags = 0;
648         bl_hdr->image_no = cpu_to_le32(adapter->priv->coex_mode);
649         bl_hdr->check_sum =
650                 cpu_to_le32(*(u32 *)&flash_content[CHECK_SUM_OFFSET]);
651         bl_hdr->flash_start_address =
652                 cpu_to_le32(*(u32 *)&flash_content[ADDR_OFFSET]);
653         bl_hdr->flash_len = cpu_to_le32(*(u32 *)&flash_content[LEN_OFFSET]);
654         write_len = sizeof(struct bl_header);
655
656         if (adapter->rsi_host_intf == RSI_HOST_INTF_USB) {
657                 write_addr = PING_BUFFER_ADDRESS;
658                 status = hif_ops->write_reg_multiple(adapter, write_addr,
659                                                  (u8 *)bl_hdr, write_len);
660                 if (status < 0) {
661                         rsi_dbg(ERR_ZONE,
662                                 "%s: Failed to load Version/CRC structure\n",
663                                 __func__);
664                         goto fail;
665                 }
666         } else {
667                 write_addr = PING_BUFFER_ADDRESS >> 16;
668                 status = hif_ops->master_access_msword(adapter, write_addr);
669                 if (status < 0) {
670                         rsi_dbg(ERR_ZONE,
671                                 "%s: Unable to set ms word to common reg\n",
672                                 __func__);
673                         goto fail;
674                 }
675                 write_addr = RSI_SD_REQUEST_MASTER |
676                              (PING_BUFFER_ADDRESS & 0xFFFF);
677                 status = hif_ops->write_reg_multiple(adapter, write_addr,
678                                                  (u8 *)bl_hdr, write_len);
679                 if (status < 0) {
680                         rsi_dbg(ERR_ZONE,
681                                 "%s: Failed to load Version/CRC structure\n",
682                                 __func__);
683                         goto fail;
684                 }
685         }
686         status = 0;
687 fail:
688         kfree(bl_hdr);
689         return status;
690 }
691
692 static u32 read_flash_capacity(struct rsi_hw *adapter)
693 {
694         u32 flash_sz = 0;
695
696         if ((adapter->host_intf_ops->master_reg_read(adapter, FLASH_SIZE_ADDR,
697                                                      &flash_sz, 2)) < 0) {
698                 rsi_dbg(ERR_ZONE,
699                         "%s: Flash size reading failed..\n",
700                         __func__);
701                 return 0;
702         }
703         rsi_dbg(INIT_ZONE, "Flash capacity: %d KiloBytes\n", flash_sz);
704
705         return (flash_sz * 1024); /* Return size in kbytes */
706 }
707
708 static int ping_pong_write(struct rsi_hw *adapter, u8 cmd, u8 *addr, u32 size)
709 {
710         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
711         u32 block_size = adapter->block_size;
712         u32 cmd_addr;
713         u16 cmd_resp, cmd_req;
714         u8 *str;
715         int status;
716
717         if (cmd == PING_WRITE) {
718                 cmd_addr = PING_BUFFER_ADDRESS;
719                 cmd_resp = PONG_AVAIL;
720                 cmd_req = PING_VALID;
721                 str = "PING_VALID";
722         } else {
723                 cmd_addr = PONG_BUFFER_ADDRESS;
724                 cmd_resp = PING_AVAIL;
725                 cmd_req = PONG_VALID;
726                 str = "PONG_VALID";
727         }
728
729         status = hif_ops->load_data_master_write(adapter, cmd_addr, size,
730                                             block_size, addr);
731         if (status) {
732                 rsi_dbg(ERR_ZONE, "%s: Unable to write blk at addr %0x\n",
733                         __func__, *addr);
734                 return status;
735         }
736
737         status = bl_cmd(adapter, cmd_req, cmd_resp, str);
738         if (status)
739                 return status;
740
741         return 0;
742 }
743
744 static int auto_fw_upgrade(struct rsi_hw *adapter, u8 *flash_content,
745                            u32 content_size)
746 {
747         u8 cmd;
748         u32 temp_content_size, num_flash, index;
749         u32 flash_start_address;
750         int status;
751
752         if (content_size > MAX_FLASH_FILE_SIZE) {
753                 rsi_dbg(ERR_ZONE,
754                         "%s: Flash Content size is more than 400K %u\n",
755                         __func__, MAX_FLASH_FILE_SIZE);
756                 return -EINVAL;
757         }
758
759         flash_start_address = *(u32 *)&flash_content[FLASH_START_ADDRESS];
760         rsi_dbg(INFO_ZONE, "flash start address: %08x\n", flash_start_address);
761
762         if (flash_start_address < FW_IMAGE_MIN_ADDRESS) {
763                 rsi_dbg(ERR_ZONE,
764                         "%s: Fw image Flash Start Address is less than 64K\n",
765                         __func__);
766                 return -EINVAL;
767         }
768
769         if (flash_start_address % FLASH_SECTOR_SIZE) {
770                 rsi_dbg(ERR_ZONE,
771                         "%s: Flash Start Address is not multiple of 4K\n",
772                         __func__);
773                 return -EINVAL;
774         }
775
776         if ((flash_start_address + content_size) > adapter->flash_capacity) {
777                 rsi_dbg(ERR_ZONE,
778                         "%s: Flash Content will cross max flash size\n",
779                         __func__);
780                 return -EINVAL;
781         }
782
783         temp_content_size  = content_size;
784         num_flash = content_size / FLASH_WRITE_CHUNK_SIZE;
785
786         rsi_dbg(INFO_ZONE, "content_size: %d, num_flash: %d\n",
787                 content_size, num_flash);
788
789         for (index = 0; index <= num_flash; index++) {
790                 rsi_dbg(INFO_ZONE, "flash index: %d\n", index);
791                 if (index != num_flash) {
792                         content_size = FLASH_WRITE_CHUNK_SIZE;
793                         rsi_dbg(INFO_ZONE, "QSPI content_size:%d\n",
794                                 content_size);
795                 } else {
796                         content_size =
797                                 temp_content_size % FLASH_WRITE_CHUNK_SIZE;
798                         rsi_dbg(INFO_ZONE,
799                                 "Writing last sector content_size:%d\n",
800                                 content_size);
801                         if (!content_size) {
802                                 rsi_dbg(INFO_ZONE, "instruction size zero\n");
803                                 break;
804                         }
805                 }
806
807                 if (index % 2)
808                         cmd = PING_WRITE;
809                 else
810                         cmd = PONG_WRITE;
811
812                 status = ping_pong_write(adapter, cmd, flash_content,
813                                          content_size);
814                 if (status) {
815                         rsi_dbg(ERR_ZONE, "%s: Unable to load %d block\n",
816                                 __func__, index);
817                         return status;
818                 }
819
820                 rsi_dbg(INFO_ZONE,
821                         "%s: Successfully loaded %d instructions\n",
822                         __func__, index);
823                 flash_content += content_size;
824         }
825
826         status = bl_cmd(adapter, EOF_REACHED, FW_LOADING_SUCCESSFUL,
827                         "EOF_REACHED");
828         if (status)
829                 return status;
830
831         rsi_dbg(INFO_ZONE, "FW loading is done and FW is running..\n");
832         return 0;
833 }
834
835 static int rsi_load_firmware(struct rsi_hw *adapter)
836 {
837         struct rsi_common *common = adapter->priv;
838         struct rsi_host_intf_ops *hif_ops = adapter->host_intf_ops;
839         const struct firmware *fw_entry = NULL;
840         u32 regout_val = 0, content_size;
841         u16 tmp_regout_val = 0;
842         struct ta_metadata *metadata_p;
843         int status;
844
845         bl_start_cmd_timer(adapter, BL_CMD_TIMEOUT);
846
847         while (!adapter->blcmd_timer_expired) {
848                 status = hif_ops->master_reg_read(adapter, SWBL_REGOUT,
849                                               &regout_val, 2);
850                 if (status < 0) {
851                         bl_stop_cmd_timer(adapter);
852                         rsi_dbg(ERR_ZONE,
853                                 "%s: REGOUT read failed\n", __func__);
854                         return status;
855                 }
856                 mdelay(1);
857                 if ((regout_val >> 8) == REGOUT_VALID)
858                         break;
859         }
860         if (adapter->blcmd_timer_expired) {
861                 rsi_dbg(ERR_ZONE, "%s: REGOUT read timedout\n", __func__);
862                 rsi_dbg(ERR_ZONE,
863                         "%s: Soft boot loader not present\n", __func__);
864                 return -ETIMEDOUT;
865         }
866         bl_stop_cmd_timer(adapter);
867
868         rsi_dbg(INFO_ZONE, "Received Board Version Number: %x\n",
869                 (regout_val & 0xff));
870
871         status = hif_ops->master_reg_write(adapter, SWBL_REGOUT,
872                                         (REGOUT_INVALID | REGOUT_INVALID << 8),
873                                         2);
874         if (status < 0) {
875                 rsi_dbg(ERR_ZONE, "%s: REGOUT writing failed..\n", __func__);
876                 return status;
877         }
878         mdelay(1);
879
880         status = bl_cmd(adapter, CONFIG_AUTO_READ_MODE, CMD_PASS,
881                         "AUTO_READ_CMD");
882         if (status < 0)
883                 return status;
884
885         adapter->flash_capacity = read_flash_capacity(adapter);
886         if (adapter->flash_capacity <= 0) {
887                 rsi_dbg(ERR_ZONE,
888                         "%s: Unable to read flash size from EEPROM\n",
889                         __func__);
890                 return -EINVAL;
891         }
892
893         metadata_p = &metadata_flash_content[adapter->priv->coex_mode];
894
895         rsi_dbg(INIT_ZONE, "%s: Loading file %s\n", __func__, metadata_p->name);
896         adapter->fw_file_name = metadata_p->name;
897
898         status = reject_firmware(&fw_entry, metadata_p->name, adapter->device);
899         if (status < 0) {
900                 rsi_dbg(ERR_ZONE, "%s: Failed to open file %s\n",
901                         __func__, metadata_p->name);
902                 return status;
903         }
904         content_size = fw_entry->size;
905         rsi_dbg(INFO_ZONE, "FW Length = %d bytes\n", content_size);
906
907         /* Get the firmware version */
908         common->lmac_ver.ver.info.fw_ver[0] =
909                 fw_entry->data[LMAC_VER_OFFSET] & 0xFF;
910         common->lmac_ver.ver.info.fw_ver[1] =
911                 fw_entry->data[LMAC_VER_OFFSET + 1] & 0xFF;
912         common->lmac_ver.major = fw_entry->data[LMAC_VER_OFFSET + 2] & 0xFF;
913         common->lmac_ver.release_num =
914                 fw_entry->data[LMAC_VER_OFFSET + 3] & 0xFF;
915         common->lmac_ver.minor = fw_entry->data[LMAC_VER_OFFSET + 4] & 0xFF;
916         common->lmac_ver.patch_num = 0;
917         rsi_print_version(common);
918
919         status = bl_write_header(adapter, (u8 *)fw_entry->data, content_size);
920         if (status) {
921                 rsi_dbg(ERR_ZONE,
922                         "%s: RPS Image header loading failed\n",
923                         __func__);
924                 goto fail;
925         }
926
927         bl_start_cmd_timer(adapter, BL_CMD_TIMEOUT);
928         status = bl_write_cmd(adapter, CHECK_CRC, CMD_PASS, &tmp_regout_val);
929         if (status) {
930                 bl_stop_cmd_timer(adapter);
931                 rsi_dbg(ERR_ZONE,
932                         "%s: CHECK_CRC Command writing failed..\n",
933                         __func__);
934                 if ((tmp_regout_val & 0xff) == CMD_FAIL) {
935                         rsi_dbg(ERR_ZONE,
936                                 "CRC Fail.. Proceeding to Upgrade mode\n");
937                         goto fw_upgrade;
938                 }
939         }
940         bl_stop_cmd_timer(adapter);
941
942         status = bl_cmd(adapter, POLLING_MODE, CMD_PASS, "POLLING_MODE");
943         if (status)
944                 goto fail;
945
946 load_image_cmd:
947         status = bl_cmd(adapter, LOAD_HOSTED_FW, LOADING_INITIATED,
948                         "LOAD_HOSTED_FW");
949         if (status)
950                 goto fail;
951         rsi_dbg(INFO_ZONE, "Load Image command passed..\n");
952         goto success;
953
954 fw_upgrade:
955         status = bl_cmd(adapter, BURN_HOSTED_FW, SEND_RPS_FILE, "FW_UPGRADE");
956         if (status)
957                 goto fail;
958
959         rsi_dbg(INFO_ZONE, "Burn Command Pass.. Upgrading the firmware\n");
960
961         status = auto_fw_upgrade(adapter, (u8 *)fw_entry->data, content_size);
962         if (status == 0) {
963                 rsi_dbg(ERR_ZONE, "Firmware upgradation Done\n");
964                 goto load_image_cmd;
965         }
966         rsi_dbg(ERR_ZONE, "Firmware upgrade failed\n");
967
968         status = bl_cmd(adapter, CONFIG_AUTO_READ_MODE, CMD_PASS,
969                         "AUTO_READ_MODE");
970         if (status)
971                 goto fail;
972
973 success:
974         rsi_dbg(ERR_ZONE, "***** Firmware Loading successful *****\n");
975         release_firmware(fw_entry);
976         return 0;
977
978 fail:
979         rsi_dbg(ERR_ZONE, "##### Firmware loading failed #####\n");
980         release_firmware(fw_entry);
981         return status;
982 }
983
984 int rsi_hal_device_init(struct rsi_hw *adapter)
985 {
986         struct rsi_common *common = adapter->priv;
987
988         switch (adapter->device_model) {
989         case RSI_DEV_9113:
990                 if (rsi_load_firmware(adapter)) {
991                         rsi_dbg(ERR_ZONE,
992                                 "%s: Failed to load TA instructions\n",
993                                 __func__);
994                         return -EINVAL;
995                 }
996                 break;
997         default:
998                 return -EINVAL;
999         }
1000         common->fsm_state = FSM_CARD_NOT_READY;
1001
1002         return 0;
1003 }
1004 EXPORT_SYMBOL_GPL(rsi_hal_device_init);
1005