2 * Copyright (c) 1997, 1998, 1999
3 * Bill Paul <wpaul@ctr.columbia.edu>. All rights reserved.
5 * Redistribution and use in source and binary forms, with or without
6 * modification, are permitted provided that the following conditions
8 * 1. Redistributions of source code must retain the above copyright
9 * notice, this list of conditions and the following disclaimer.
10 * 2. Redistributions in binary form must reproduce the above copyright
11 * notice, this list of conditions and the following disclaimer in the
12 * documentation and/or other materials provided with the distribution.
13 * 3. All advertising materials mentioning features or use of this software
14 * must display the following acknowledgement:
15 * This product includes software developed by Bill Paul.
16 * 4. Neither the name of the author nor the names of any co-contributors
17 * may be used to endorse or promote products derived from this software
18 * without specific prior written permission.
20 * THIS SOFTWARE IS PROVIDED BY Bill Paul AND CONTRIBUTORS ``AS IS'' AND
21 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL Bill Paul OR THE VOICES IN HIS HEAD
24 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
25 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
26 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
27 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
28 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
29 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
30 * THE POSSIBILITY OF SUCH DAMAGE.
32 * $FreeBSD: src/sys/dev/wi/if_wi.c,v 1.103.2.2 2002/08/02 07:11:34 imp Exp $
33 * $DragonFly: src/sys/dev/netif/owi/Attic/if_owi.c,v 1.7 2005/05/27 15:36:09 joerg Exp $
37 * Lucent WaveLAN/IEEE 802.11 PCMCIA driver for FreeBSD.
39 * Written by Bill Paul <wpaul@ctr.columbia.edu>
40 * Electrical Engineering Department
41 * Columbia University, New York City
45 * The WaveLAN/IEEE adapter is the second generation of the WaveLAN
46 * from Lucent. Unlike the older cards, the new ones are programmed
47 * entirely via a firmware-driven controller called the Hermes.
48 * Unfortunately, Lucent will not release the Hermes programming manual
49 * without an NDA (if at all). What they do release is an API library
50 * called the HCF (Hardware Control Functions) which is supposed to
51 * do the device-specific operations of a device driver for you. The
52 * publically available version of the HCF library (the 'HCF Light') is
53 * a) extremely gross, b) lacks certain features, particularly support
54 * for 802.11 frames, and c) is contaminated by the GNU Public License.
56 * This driver does not use the HCF or HCF Light at all. Instead, it
57 * programs the Hermes controller directly, using information gleaned
58 * from the HCF Light code and corresponding documentation.
60 * This driver supports the ISA, PCMCIA and PCI versions of the Lucent
61 * WaveLan cards (based on the Hermes chipset), as well as the newer
62 * Prism 2 chipsets with firmware from Intersil and Symbol.
65 #include <sys/param.h>
66 #include <sys/systm.h>
67 #if defined(__FreeBSD__) && __FreeBSD_version >= 500033
68 #include <sys/endian.h>
70 #include <sys/sockio.h>
73 #include <sys/kernel.h>
74 #include <sys/socket.h>
75 #include <sys/module.h>
77 #include <sys/random.h>
78 #include <sys/syslog.h>
79 #include <sys/sysctl.h>
81 #include <machine/bus.h>
82 #include <machine/resource.h>
83 #include <machine/clock.h>
87 #include <net/ifq_var.h>
88 #include <net/if_arp.h>
89 #include <net/ethernet.h>
90 #include <net/if_dl.h>
91 #include <net/if_media.h>
92 #include <net/if_types.h>
93 #include <netproto/802_11/ieee80211.h>
94 #include <netproto/802_11/ieee80211_ioctl.h>
95 #include <netproto/802_11/if_wavelan_ieee.h>
97 #include <netinet/in.h>
98 #include <netinet/in_systm.h>
99 #include <netinet/in_var.h>
100 #include <netinet/ip.h>
101 #include <netinet/if_ether.h>
105 #include "wi_hostap.h"
106 #include "if_wivar.h"
107 #include "if_wireg.h"
109 #define WI_CMD_DEBUG 0x0038 /* prism2 debug */
111 static void wi_intr(void *);
112 static void wi_reset(struct wi_softc *);
113 static int wi_ioctl(struct ifnet *, u_long, caddr_t, struct ucred *);
114 static void wi_init(void *);
115 static void wi_start(struct ifnet *);
116 static void wi_stop(struct wi_softc *);
117 static void wi_watchdog(struct ifnet *);
118 static void wi_rxeof(struct wi_softc *);
119 static void wi_txeof(struct wi_softc *, int);
120 static void wi_update_stats(struct wi_softc *);
121 static void wi_setmulti(struct wi_softc *);
123 static int wi_cmd(struct wi_softc *, int, int, int, int);
124 static int wi_read_record(struct wi_softc *, struct wi_ltv_gen *);
125 static int wi_write_record(struct wi_softc *, struct wi_ltv_gen *);
126 static int wi_read_data(struct wi_softc *, int, int, caddr_t, int);
127 static int wi_write_data(struct wi_softc *, int, int, caddr_t, int);
128 static int wi_seek(struct wi_softc *, int, int, int);
129 static int wi_alloc_nicmem(struct wi_softc *, int, int *);
130 static void wi_inquire(void *);
131 static void wi_setdef(struct wi_softc *, struct wi_req *);
135 void wi_cache_store(struct wi_softc *, struct mbuf *, unsigned short);
138 static int wi_get_cur_ssid(struct wi_softc *, char *, int *);
139 static void wi_get_id(struct wi_softc *);
140 static int wi_media_change(struct ifnet *);
141 static void wi_media_status(struct ifnet *, struct ifmediareq *);
143 static int wi_get_debug(struct wi_softc *, struct wi_req *);
144 static int wi_set_debug(struct wi_softc *, struct wi_req *);
146 DECLARE_DUMMY_MODULE(if_wi);
148 devclass_t owi_devclass;
150 static struct wi_card_ident wi_card_ident[] = {
151 /* CARD_ID CARD_NAME FIRM_TYPE */
152 { WI_NIC_LUCENT_ID, WI_NIC_LUCENT_STR, WI_LUCENT },
153 { WI_NIC_SONY_ID, WI_NIC_SONY_STR, WI_LUCENT },
154 { WI_NIC_LUCENT_EMB_ID, WI_NIC_LUCENT_EMB_STR, WI_LUCENT },
155 { WI_NIC_EVB2_ID, WI_NIC_EVB2_STR, WI_INTERSIL },
156 { WI_NIC_HWB3763_ID, WI_NIC_HWB3763_STR, WI_INTERSIL },
157 { WI_NIC_HWB3163_ID, WI_NIC_HWB3163_STR, WI_INTERSIL },
158 { WI_NIC_HWB3163B_ID, WI_NIC_HWB3163B_STR, WI_INTERSIL },
159 { WI_NIC_EVB3_ID, WI_NIC_EVB3_STR, WI_INTERSIL },
160 { WI_NIC_HWB1153_ID, WI_NIC_HWB1153_STR, WI_INTERSIL },
161 { WI_NIC_P2_SST_ID, WI_NIC_P2_SST_STR, WI_INTERSIL },
162 { WI_NIC_EVB2_SST_ID, WI_NIC_EVB2_SST_STR, WI_INTERSIL },
163 { WI_NIC_3842_EVA_ID, WI_NIC_3842_EVA_STR, WI_INTERSIL },
164 { WI_NIC_3842_PCMCIA_AMD_ID, WI_NIC_3842_PCMCIA_STR, WI_INTERSIL },
165 { WI_NIC_3842_PCMCIA_SST_ID, WI_NIC_3842_PCMCIA_STR, WI_INTERSIL },
166 { WI_NIC_3842_PCMCIA_ATM_ID, WI_NIC_3842_PCMCIA_STR, WI_INTERSIL },
167 { WI_NIC_3842_MINI_AMD_ID, WI_NIC_3842_MINI_STR, WI_INTERSIL },
168 { WI_NIC_3842_MINI_SST_ID, WI_NIC_3842_MINI_STR, WI_INTERSIL },
169 { WI_NIC_3842_MINI_ATM_ID, WI_NIC_3842_MINI_STR, WI_INTERSIL },
170 { WI_NIC_3842_PCI_AMD_ID, WI_NIC_3842_PCI_STR, WI_INTERSIL },
171 { WI_NIC_3842_PCI_SST_ID, WI_NIC_3842_PCI_STR, WI_INTERSIL },
172 { WI_NIC_3842_PCI_ATM_ID, WI_NIC_3842_PCI_STR, WI_INTERSIL },
173 { WI_NIC_P3_PCMCIA_AMD_ID, WI_NIC_P3_PCMCIA_STR, WI_INTERSIL },
174 { WI_NIC_P3_PCMCIA_SST_ID, WI_NIC_P3_PCMCIA_STR, WI_INTERSIL },
175 { WI_NIC_P3_MINI_AMD_ID, WI_NIC_P3_MINI_STR, WI_INTERSIL },
176 { WI_NIC_P3_MINI_SST_ID, WI_NIC_P3_MINI_STR, WI_INTERSIL },
181 owi_generic_detach(dev)
188 sc = device_get_softc(dev);
190 ifp = &sc->arpcom.ac_if;
193 device_printf(dev, "already unloaded\n");
200 /* Delete all remaining media. */
201 ifmedia_removeall(&sc->ifmedia);
204 bus_teardown_intr(dev, sc->irq, sc->wi_intrhand);
209 #if defined(__FreeBSD__) && __FreeBSD_version >= 500000
210 mtx_destroy(&sc->wi_mtx);
217 owi_generic_attach(device_t dev)
220 struct wi_ltv_macaddr mac;
221 struct wi_ltv_gen gen;
226 /* XXX maybe we need the splimp stuff here XXX */
227 sc = device_get_softc(dev);
228 ifp = &sc->arpcom.ac_if;
229 callout_init(&sc->wi_stat_timer);
231 error = bus_setup_intr(dev, sc->irq, INTR_TYPE_NET,
232 wi_intr, sc, &sc->wi_intrhand, NULL);
235 device_printf(dev, "bus_setup_intr() failed! (%d)\n", error);
240 #if defined(__FreeBSD__) && __FreeBSD_version >= 500000
241 mtx_init(&sc->wi_mtx, device_get_nameunit(dev), MTX_NETWORK_LOCK,
242 MTX_DEF | MTX_RECURSE);
250 * Read the station address.
251 * And do it twice. I've seen PRISM-based cards that return
252 * an error when trying to read it the first time, which causes
255 mac.wi_type = WI_RID_MAC_NODE;
257 wi_read_record(sc, (struct wi_ltv_gen *)&mac);
258 if ((error = wi_read_record(sc, (struct wi_ltv_gen *)&mac)) != 0) {
259 device_printf(dev, "mac read failed %d\n", error);
264 bcopy((char *)&mac.wi_mac_addr,
265 (char *)&sc->arpcom.ac_enaddr, ETHER_ADDR_LEN);
270 if_initname(ifp, "wi", sc->wi_unit);
271 ifp->if_mtu = ETHERMTU;
272 ifp->if_flags = IFF_BROADCAST | IFF_SIMPLEX | IFF_MULTICAST;
273 ifp->if_ioctl = wi_ioctl;
274 ifp->if_start = wi_start;
275 ifp->if_watchdog = wi_watchdog;
276 ifp->if_init = wi_init;
277 ifp->if_baudrate = 10000000;
278 ifq_set_maxlen(&ifp->if_snd, IFQ_MAXLEN);
279 ifq_set_ready(&ifp->if_snd);
281 bzero(sc->wi_node_name, sizeof(sc->wi_node_name));
282 bcopy(WI_DEFAULT_NODENAME, sc->wi_node_name,
283 sizeof(WI_DEFAULT_NODENAME) - 1);
285 bzero(sc->wi_net_name, sizeof(sc->wi_net_name));
286 bcopy(WI_DEFAULT_NETNAME, sc->wi_net_name,
287 sizeof(WI_DEFAULT_NETNAME) - 1);
289 bzero(sc->wi_ibss_name, sizeof(sc->wi_ibss_name));
290 bcopy(WI_DEFAULT_IBSS, sc->wi_ibss_name,
291 sizeof(WI_DEFAULT_IBSS) - 1);
293 sc->wi_portnum = WI_DEFAULT_PORT;
294 sc->wi_ptype = WI_PORTTYPE_BSS;
295 sc->wi_ap_density = WI_DEFAULT_AP_DENSITY;
296 sc->wi_rts_thresh = WI_DEFAULT_RTS_THRESH;
297 sc->wi_tx_rate = WI_DEFAULT_TX_RATE;
298 sc->wi_max_data_len = WI_DEFAULT_DATALEN;
299 sc->wi_create_ibss = WI_DEFAULT_CREATE_IBSS;
300 sc->wi_pm_enabled = WI_DEFAULT_PM_ENABLED;
301 sc->wi_max_sleep = WI_DEFAULT_MAX_SLEEP;
302 sc->wi_roaming = WI_DEFAULT_ROAMING;
303 sc->wi_authtype = WI_DEFAULT_AUTHTYPE;
304 sc->wi_authmode = IEEE80211_AUTH_OPEN;
307 * Read the default channel from the NIC. This may vary
308 * depending on the country where the NIC was purchased, so
309 * we can't hard-code a default and expect it to work for
312 gen.wi_type = WI_RID_OWN_CHNL;
314 wi_read_record(sc, &gen);
315 sc->wi_channel = gen.wi_val;
318 * Set flags based on firmware version.
320 switch (sc->sc_firmware_type) {
322 sc->wi_flags |= WI_FLAGS_HAS_ROAMING;
323 if (sc->sc_sta_firmware_ver >= 60000)
324 sc->wi_flags |= WI_FLAGS_HAS_MOR;
325 if (sc->sc_sta_firmware_ver >= 60006) {
326 sc->wi_flags |= WI_FLAGS_HAS_IBSS;
327 sc->wi_flags |= WI_FLAGS_HAS_CREATE_IBSS;
329 sc->wi_ibss_port = htole16(1);
332 sc->wi_flags |= WI_FLAGS_HAS_ROAMING;
333 if (sc->sc_sta_firmware_ver >= 800) {
334 sc->wi_flags |= WI_FLAGS_HAS_IBSS;
335 sc->wi_flags |= WI_FLAGS_HAS_CREATE_IBSS;
338 * version 0.8.3 and newer are the only ones that are known
339 * to currently work. Earlier versions can be made to work,
340 * at least according to the Linux driver.
342 if (sc->sc_sta_firmware_ver >= 803)
343 sc->wi_flags |= WI_FLAGS_HAS_HOSTAP;
344 sc->wi_ibss_port = htole16(0);
347 sc->wi_flags |= WI_FLAGS_HAS_DIVERSITY;
348 if (sc->sc_sta_firmware_ver >= 20000)
349 sc->wi_flags |= WI_FLAGS_HAS_IBSS;
350 /* Older Symbol firmware does not support IBSS creation. */
351 if (sc->sc_sta_firmware_ver >= 25000)
352 sc->wi_flags |= WI_FLAGS_HAS_CREATE_IBSS;
353 sc->wi_ibss_port = htole16(4);
358 * Find out if we support WEP on this card.
360 gen.wi_type = WI_RID_WEP_AVAIL;
362 wi_read_record(sc, &gen);
363 sc->wi_has_wep = gen.wi_val;
366 device_printf(sc->dev, "wi_has_wep = %d\n", sc->wi_has_wep);
369 * Find supported rates.
371 gen.wi_type = WI_RID_DATA_RATES;
373 if (wi_read_record(sc, &gen))
374 sc->wi_supprates = WI_SUPPRATES_1M | WI_SUPPRATES_2M |
375 WI_SUPPRATES_5M | WI_SUPPRATES_11M;
377 sc->wi_supprates = gen.wi_val;
379 bzero((char *)&sc->wi_stats, sizeof(sc->wi_stats));
384 ifmedia_init(&sc->ifmedia, 0, wi_media_change, wi_media_status);
385 #define ADD(m, c) ifmedia_add(&sc->ifmedia, (m), (c), NULL)
386 if (sc->wi_supprates & WI_SUPPRATES_1M) {
387 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS1, 0, 0), 0);
388 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS1,
389 IFM_IEEE80211_ADHOC, 0), 0);
390 if (sc->wi_flags & WI_FLAGS_HAS_IBSS)
391 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS1,
392 IFM_IEEE80211_IBSS, 0), 0);
393 if (sc->wi_flags & WI_FLAGS_HAS_CREATE_IBSS)
394 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS1,
395 IFM_IEEE80211_IBSSMASTER, 0), 0);
396 if (sc->wi_flags & WI_FLAGS_HAS_HOSTAP)
397 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS1,
398 IFM_IEEE80211_HOSTAP, 0), 0);
400 if (sc->wi_supprates & WI_SUPPRATES_2M) {
401 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS2, 0, 0), 0);
402 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS2,
403 IFM_IEEE80211_ADHOC, 0), 0);
404 if (sc->wi_flags & WI_FLAGS_HAS_IBSS)
405 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS2,
406 IFM_IEEE80211_IBSS, 0), 0);
407 if (sc->wi_flags & WI_FLAGS_HAS_CREATE_IBSS)
408 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS2,
409 IFM_IEEE80211_IBSSMASTER, 0), 0);
410 if (sc->wi_flags & WI_FLAGS_HAS_HOSTAP)
411 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS2,
412 IFM_IEEE80211_HOSTAP, 0), 0);
414 if (sc->wi_supprates & WI_SUPPRATES_5M) {
415 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS5, 0, 0), 0);
416 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS5,
417 IFM_IEEE80211_ADHOC, 0), 0);
418 if (sc->wi_flags & WI_FLAGS_HAS_IBSS)
419 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS5,
420 IFM_IEEE80211_IBSS, 0), 0);
421 if (sc->wi_flags & WI_FLAGS_HAS_CREATE_IBSS)
422 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS5,
423 IFM_IEEE80211_IBSSMASTER, 0), 0);
424 if (sc->wi_flags & WI_FLAGS_HAS_HOSTAP)
425 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS5,
426 IFM_IEEE80211_HOSTAP, 0), 0);
428 if (sc->wi_supprates & WI_SUPPRATES_11M) {
429 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS11, 0, 0), 0);
430 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS11,
431 IFM_IEEE80211_ADHOC, 0), 0);
432 if (sc->wi_flags & WI_FLAGS_HAS_IBSS)
433 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS11,
434 IFM_IEEE80211_IBSS, 0), 0);
435 if (sc->wi_flags & WI_FLAGS_HAS_CREATE_IBSS)
436 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS11,
437 IFM_IEEE80211_IBSSMASTER, 0), 0);
438 if (sc->wi_flags & WI_FLAGS_HAS_HOSTAP)
439 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_IEEE80211_DS11,
440 IFM_IEEE80211_HOSTAP, 0), 0);
441 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_MANUAL, 0, 0), 0);
443 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_AUTO, IFM_IEEE80211_ADHOC, 0), 0);
444 if (sc->wi_flags & WI_FLAGS_HAS_IBSS)
445 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_AUTO, IFM_IEEE80211_IBSS,
447 if (sc->wi_flags & WI_FLAGS_HAS_CREATE_IBSS)
448 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_AUTO,
449 IFM_IEEE80211_IBSSMASTER, 0), 0);
450 if (sc->wi_flags & WI_FLAGS_HAS_HOSTAP)
451 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_AUTO,
452 IFM_IEEE80211_HOSTAP, 0), 0);
453 ADD(IFM_MAKEWORD(IFM_IEEE80211, IFM_AUTO, 0, 0), 0);
455 ifmedia_set(&sc->ifmedia, IFM_MAKEWORD(IFM_IEEE80211, IFM_AUTO, 0, 0));
458 * Call MI attach routine.
460 ether_ifattach(ifp, sc->arpcom.ac_enaddr);
470 struct wi_ltv_ver ver;
471 struct wi_card_ident *id;
473 /* getting chip identity */
474 memset(&ver, 0, sizeof(ver));
475 ver.wi_type = WI_RID_CARD_ID;
477 wi_read_record(sc, (struct wi_ltv_gen *)&ver);
478 device_printf(sc->dev, "using ");
479 sc->sc_firmware_type = WI_NOTYPE;
480 for (id = wi_card_ident; id->card_name != NULL; id++) {
481 if (le16toh(ver.wi_ver[0]) == id->card_id) {
482 printf("%s", id->card_name);
483 sc->sc_firmware_type = id->firm_type;
487 if (sc->sc_firmware_type == WI_NOTYPE) {
488 if (le16toh(ver.wi_ver[0]) & 0x8000) {
489 printf("Unknown PRISM2 chip");
490 sc->sc_firmware_type = WI_INTERSIL;
492 printf("Unknown Lucent chip");
493 sc->sc_firmware_type = WI_LUCENT;
497 if (sc->sc_firmware_type != WI_LUCENT) {
498 /* get primary firmware version */
499 memset(&ver, 0, sizeof(ver));
500 ver.wi_type = WI_RID_PRI_IDENTITY;
502 wi_read_record(sc, (struct wi_ltv_gen *)&ver);
503 ver.wi_ver[1] = le16toh(ver.wi_ver[1]);
504 ver.wi_ver[2] = le16toh(ver.wi_ver[2]);
505 ver.wi_ver[3] = le16toh(ver.wi_ver[3]);
506 sc->sc_pri_firmware_ver = ver.wi_ver[2] * 10000 +
507 ver.wi_ver[3] * 100 + ver.wi_ver[1];
510 /* get station firmware version */
511 memset(&ver, 0, sizeof(ver));
512 ver.wi_type = WI_RID_STA_IDENTITY;
514 wi_read_record(sc, (struct wi_ltv_gen *)&ver);
515 ver.wi_ver[1] = le16toh(ver.wi_ver[1]);
516 ver.wi_ver[2] = le16toh(ver.wi_ver[2]);
517 ver.wi_ver[3] = le16toh(ver.wi_ver[3]);
518 sc->sc_sta_firmware_ver = ver.wi_ver[2] * 10000 +
519 ver.wi_ver[3] * 100 + ver.wi_ver[1];
520 if (sc->sc_firmware_type == WI_INTERSIL &&
521 (sc->sc_sta_firmware_ver == 10102 ||
522 sc->sc_sta_firmware_ver == 20102)) {
523 struct wi_ltv_str sver;
526 memset(&sver, 0, sizeof(sver));
527 sver.wi_type = WI_RID_SYMBOL_IDENTITY;
529 /* value should be the format like "V2.00-11" */
530 if (wi_read_record(sc, (struct wi_ltv_gen *)&sver) == 0 &&
531 *(p = (char *)sver.wi_str) >= 'A' &&
532 p[2] == '.' && p[5] == '-' && p[8] == '\0') {
533 sc->sc_firmware_type = WI_SYMBOL;
534 sc->sc_sta_firmware_ver = (p[1] - '0') * 10000 +
535 (p[3] - '0') * 1000 + (p[4] - '0') * 100 +
536 (p[6] - '0') * 10 + (p[7] - '0');
540 device_printf(sc->dev, "%s Firmware: ",
541 sc->sc_firmware_type == WI_LUCENT ? "Lucent" :
542 (sc->sc_firmware_type == WI_SYMBOL ? "Symbol" : "Intersil"));
545 * The primary firmware is only valid on Prism based chipsets
546 * (INTERSIL or SYMBOL).
548 if (sc->sc_firmware_type != WI_LUCENT)
549 printf("Primary %u.%02u.%02u, ", sc->sc_pri_firmware_ver / 10000,
550 (sc->sc_pri_firmware_ver % 10000) / 100,
551 sc->sc_pri_firmware_ver % 100);
552 printf("Station %u.%02u.%02u\n",
553 sc->sc_sta_firmware_ver / 10000, (sc->sc_sta_firmware_ver % 10000) / 100,
554 sc->sc_sta_firmware_ver % 100);
563 struct ether_header *eh;
567 ifp = &sc->arpcom.ac_if;
569 id = CSR_READ_2(sc, WI_RX_FID);
572 * if we have the procframe flag set, disregard all this and just
573 * read the data from the device.
575 if (sc->wi_procframe || sc->wi_debug.wi_monitor) {
576 struct wi_frame *rx_frame;
579 /* first allocate mbuf for packet storage */
580 MGETHDR(m, MB_DONTWAIT, MT_DATA);
585 MCLGET(m, MB_DONTWAIT);
586 if (!(m->m_flags & M_EXT)) {
592 m->m_pkthdr.rcvif = ifp;
594 /* now read wi_frame first so we know how much data to read */
595 if (wi_read_data(sc, id, 0, mtod(m, caddr_t),
596 sizeof(struct wi_frame))) {
602 rx_frame = mtod(m, struct wi_frame *);
604 switch ((rx_frame->wi_status & WI_STAT_MAC_PORT) >> 8) {
606 switch (rx_frame->wi_frame_ctl & WI_FCTL_FTYPE) {
608 hdrlen = WI_DATA_HDRLEN;
609 datlen = rx_frame->wi_dat_len + WI_FCS_LEN;
612 hdrlen = WI_MGMT_HDRLEN;
613 datlen = rx_frame->wi_dat_len + WI_FCS_LEN;
617 * prism2 cards don't pass control packets
618 * down properly or consistently, so we'll only
619 * pass down the header.
621 hdrlen = WI_CTL_HDRLEN;
625 device_printf(sc->dev, "received packet of "
626 "unknown type on port 7\n");
633 hdrlen = WI_DATA_HDRLEN;
634 datlen = rx_frame->wi_dat_len + WI_FCS_LEN;
637 device_printf(sc->dev, "received packet on invalid "
638 "port (wi_status=0x%x)\n", rx_frame->wi_status);
644 if ((hdrlen + datlen + 2) > MCLBYTES) {
645 device_printf(sc->dev, "oversized packet received "
646 "(wi_dat_len=%d, wi_status=0x%x)\n",
647 datlen, rx_frame->wi_status);
653 if (wi_read_data(sc, id, hdrlen, mtod(m, caddr_t) + hdrlen,
660 m->m_pkthdr.len = m->m_len = hdrlen + datlen;
664 /* Handle BPF listeners. */
669 struct wi_frame rx_frame;
671 /* First read in the frame header */
672 if (wi_read_data(sc, id, 0, (caddr_t)&rx_frame,
678 if (rx_frame.wi_status & WI_STAT_ERRSTAT) {
683 MGETHDR(m, MB_DONTWAIT, MT_DATA);
688 MCLGET(m, MB_DONTWAIT);
689 if (!(m->m_flags & M_EXT)) {
695 eh = mtod(m, struct ether_header *);
696 m->m_pkthdr.rcvif = ifp;
698 if (rx_frame.wi_status == WI_STAT_MGMT &&
699 sc->wi_ptype == WI_PORTTYPE_AP) {
700 if ((WI_802_11_OFFSET_RAW + rx_frame.wi_dat_len + 2) >
702 device_printf(sc->dev, "oversized mgmt packet "
703 "received in hostap mode "
704 "(wi_dat_len=%d, wi_status=0x%x)\n",
705 rx_frame.wi_dat_len, rx_frame.wi_status);
711 /* Put the whole header in there. */
712 bcopy(&rx_frame, mtod(m, void *),
713 sizeof(struct wi_frame));
714 if (wi_read_data(sc, id, WI_802_11_OFFSET_RAW,
715 mtod(m, caddr_t) + WI_802_11_OFFSET_RAW,
716 rx_frame.wi_dat_len + 2)) {
721 m->m_pkthdr.len = m->m_len =
722 WI_802_11_OFFSET_RAW + rx_frame.wi_dat_len;
723 /* XXX: consider giving packet to bhp? */
724 owihap_mgmt_input(sc, &rx_frame, m);
728 if (rx_frame.wi_status == WI_STAT_1042 ||
729 rx_frame.wi_status == WI_STAT_TUNNEL ||
730 rx_frame.wi_status == WI_STAT_WMP_MSG) {
731 if((rx_frame.wi_dat_len + WI_SNAPHDR_LEN) > MCLBYTES) {
732 device_printf(sc->dev,
733 "oversized packet received "
734 "(wi_dat_len=%d, wi_status=0x%x)\n",
735 rx_frame.wi_dat_len, rx_frame.wi_status);
740 m->m_pkthdr.len = m->m_len =
741 rx_frame.wi_dat_len + WI_SNAPHDR_LEN;
744 bcopy((char *)&rx_frame.wi_addr1,
745 (char *)&eh->ether_dhost, ETHER_ADDR_LEN);
746 if (sc->wi_ptype == WI_PORTTYPE_ADHOC) {
747 bcopy((char *)&rx_frame.wi_addr2,
748 (char *)&eh->ether_shost, ETHER_ADDR_LEN);
750 bcopy((char *)&rx_frame.wi_addr3,
751 (char *)&eh->ether_shost, ETHER_ADDR_LEN);
754 bcopy((char *)&rx_frame.wi_dst_addr,
755 (char *)&eh->ether_dhost, ETHER_ADDR_LEN);
756 bcopy((char *)&rx_frame.wi_src_addr,
757 (char *)&eh->ether_shost, ETHER_ADDR_LEN);
760 bcopy((char *)&rx_frame.wi_type,
761 (char *)&eh->ether_type, ETHER_TYPE_LEN);
763 if (wi_read_data(sc, id, WI_802_11_OFFSET,
764 mtod(m, caddr_t) + sizeof(struct ether_header),
771 if((rx_frame.wi_dat_len +
772 sizeof(struct ether_header)) > MCLBYTES) {
773 device_printf(sc->dev,
774 "oversized packet received "
775 "(wi_dat_len=%d, wi_status=0x%x)\n",
776 rx_frame.wi_dat_len, rx_frame.wi_status);
781 m->m_pkthdr.len = m->m_len =
782 rx_frame.wi_dat_len + sizeof(struct ether_header);
784 if (wi_read_data(sc, id, WI_802_3_OFFSET,
785 mtod(m, caddr_t), m->m_len + 2)) {
794 if (sc->wi_ptype == WI_PORTTYPE_AP) {
796 * Give host AP code first crack at data
797 * packets. If it decides to handle it (or
798 * drop it), it will return a non-zero.
799 * Otherwise, it is destined for this host.
801 if (owihap_data_input(sc, &rx_frame, m))
804 /* Receive packet. */
806 wi_cache_store(sc, m, rx_frame.wi_q_info);
808 (*ifp->if_input)(ifp, m);
819 ifp = &sc->arpcom.ac_if;
822 ifp->if_flags &= ~IFF_OACTIVE;
824 if (status & WI_EV_TX_EXC)
841 ifp = &sc->arpcom.ac_if;
843 callout_reset(&sc->wi_stat_timer, hz* 60, wi_inquire, sc);
845 /* Don't do this while we're transmitting */
846 if (ifp->if_flags & IFF_OACTIVE)
850 wi_cmd(sc, WI_CMD_INQUIRE, WI_INFO_COUNTERS, 0, 0);
860 struct wi_ltv_gen gen;
867 ifp = &sc->arpcom.ac_if;
869 id = CSR_READ_2(sc, WI_INFO_FID);
871 wi_read_data(sc, id, 0, (char *)&gen, 4);
874 * if we just got our scan results, copy it over into the scan buffer
875 * so we can return it to anyone that asks for it. (add a little
876 * compatibility with the prism2 scanning mechanism)
878 if (gen.wi_type == WI_INFO_SCAN_RESULTS)
880 sc->wi_scanbuf_len = gen.wi_len;
881 wi_read_data(sc, id, 4, (char *)sc->wi_scanbuf,
882 sc->wi_scanbuf_len * 2);
886 else if (gen.wi_type != WI_INFO_COUNTERS)
889 len = (gen.wi_len - 1 < sizeof(sc->wi_stats) / 4) ?
890 gen.wi_len - 1 : sizeof(sc->wi_stats) / 4;
891 ptr = (u_int32_t *)&sc->wi_stats;
893 for (i = 0; i < len - 1; i++) {
894 t = CSR_READ_2(sc, WI_DATA1);
895 #ifdef WI_HERMES_STATS_WAR
902 ifp->if_collisions = sc->wi_stats.wi_tx_single_retries +
903 sc->wi_stats.wi_tx_multi_retries +
904 sc->wi_stats.wi_tx_retry_limit;
913 struct wi_softc *sc = xsc;
920 ifp = &sc->arpcom.ac_if;
922 if (sc->wi_gone || !(ifp->if_flags & IFF_UP)) {
923 CSR_WRITE_2(sc, WI_EVENT_ACK, 0xFFFF);
924 CSR_WRITE_2(sc, WI_INT_EN, 0);
929 /* Disable interrupts. */
930 CSR_WRITE_2(sc, WI_INT_EN, 0);
932 status = CSR_READ_2(sc, WI_EVENT_STAT);
933 CSR_WRITE_2(sc, WI_EVENT_ACK, ~WI_INTRS);
935 if (status & WI_EV_RX) {
937 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_RX);
940 if (status & WI_EV_TX) {
941 wi_txeof(sc, status);
942 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_TX);
945 if (status & WI_EV_ALLOC) {
948 id = CSR_READ_2(sc, WI_ALLOC_FID);
949 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_ALLOC);
950 if (id == sc->wi_tx_data_id)
951 wi_txeof(sc, status);
954 if (status & WI_EV_INFO) {
956 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_INFO);
959 if (status & WI_EV_TX_EXC) {
960 wi_txeof(sc, status);
961 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_TX_EXC);
964 if (status & WI_EV_INFO_DROP) {
965 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_INFO_DROP);
968 /* Re-enable interrupts. */
969 CSR_WRITE_2(sc, WI_INT_EN, WI_INTRS);
971 if (!ifq_is_empty(&ifp->if_snd)) {
981 wi_cmd(sc, cmd, val0, val1, val2)
989 static volatile int count = 0;
992 panic("Hey partner, hold on there!");
995 /* wait for the busy bit to clear */
996 for (i = 500; i > 0; i--) { /* 5s */
997 if (!(CSR_READ_2(sc, WI_COMMAND) & WI_CMD_BUSY)) {
1000 DELAY(10*1000); /* 10 m sec */
1003 device_printf(sc->dev, "wi_cmd: busy bit won't clear.\n" );
1008 CSR_WRITE_2(sc, WI_PARAM0, val0);
1009 CSR_WRITE_2(sc, WI_PARAM1, val1);
1010 CSR_WRITE_2(sc, WI_PARAM2, val2);
1011 CSR_WRITE_2(sc, WI_COMMAND, cmd);
1013 for (i = 0; i < WI_TIMEOUT; i++) {
1015 * Wait for 'command complete' bit to be
1016 * set in the event status register.
1018 s = CSR_READ_2(sc, WI_EVENT_STAT);
1019 if (s & WI_EV_CMD) {
1020 /* Ack the event and read result code. */
1021 s = CSR_READ_2(sc, WI_STATUS);
1022 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_CMD);
1024 if ((s & WI_CMD_CODE_MASK) != (cmd & WI_CMD_CODE_MASK))
1027 if (s & WI_STAT_CMD_RESULT) {
1037 if (i == WI_TIMEOUT) {
1038 device_printf(sc->dev,
1039 "timeout in wi_cmd 0x%04x; event status 0x%04x\n", cmd, s);
1047 struct wi_softc *sc;
1049 #define WI_INIT_TRIES 3
1053 /* Symbol firmware cannot be initialized more than once */
1054 if (sc->sc_firmware_type == WI_SYMBOL && sc->sc_enabled)
1056 if (sc->sc_firmware_type == WI_SYMBOL)
1059 tries = WI_INIT_TRIES;
1061 for (i = 0; i < tries; i++) {
1062 if (wi_cmd(sc, WI_CMD_INI, 0, 0, 0) == 0)
1064 DELAY(WI_DELAY * 1000);
1069 device_printf(sc->dev, "init failed\n");
1073 CSR_WRITE_2(sc, WI_INT_EN, 0);
1074 CSR_WRITE_2(sc, WI_EVENT_ACK, 0xFFFF);
1076 /* Calibrate timer. */
1077 WI_SETVAL(WI_RID_TICK_TIME, 8);
1083 * Read an LTV record from the NIC.
1086 wi_read_record(sc, ltv)
1087 struct wi_softc *sc;
1088 struct wi_ltv_gen *ltv;
1092 struct wi_ltv_gen *oltv, p2ltv;
1095 if (sc->sc_firmware_type != WI_LUCENT) {
1096 switch (ltv->wi_type) {
1097 case WI_RID_ENCRYPTION:
1098 p2ltv.wi_type = WI_RID_P2_ENCRYPTION;
1102 case WI_RID_TX_CRYPT_KEY:
1103 p2ltv.wi_type = WI_RID_P2_TX_CRYPT_KEY;
1107 case WI_RID_ROAMING_MODE:
1108 if (sc->sc_firmware_type == WI_INTERSIL)
1113 case WI_RID_MICROWAVE_OVEN:
1120 /* Tell the NIC to enter record read mode. */
1121 if (wi_cmd(sc, WI_CMD_ACCESS|WI_ACCESS_READ, ltv->wi_type, 0, 0))
1124 /* Seek to the record. */
1125 if (wi_seek(sc, ltv->wi_type, 0, WI_BAP1))
1129 * Read the length and record type and make sure they
1130 * match what we expect (this verifies that we have enough
1131 * room to hold all of the returned data).
1133 len = CSR_READ_2(sc, WI_DATA1);
1134 if (len > ltv->wi_len)
1136 code = CSR_READ_2(sc, WI_DATA1);
1137 if (code != ltv->wi_type)
1141 ltv->wi_type = code;
1143 /* Now read the data. */
1145 for (i = 0; i < ltv->wi_len - 1; i++)
1146 ptr[i] = CSR_READ_2(sc, WI_DATA1);
1148 if (ltv->wi_type == WI_RID_PORTTYPE && sc->wi_ptype == WI_PORTTYPE_IBSS
1149 && ltv->wi_val == sc->wi_ibss_port) {
1151 * Convert vendor IBSS port type to WI_PORTTYPE_IBSS.
1152 * Since Lucent uses port type 1 for BSS *and* IBSS we
1153 * have to rely on wi_ptype to distinguish this for us.
1155 ltv->wi_val = htole16(WI_PORTTYPE_IBSS);
1156 } else if (sc->sc_firmware_type != WI_LUCENT) {
1157 switch (oltv->wi_type) {
1158 case WI_RID_TX_RATE:
1159 case WI_RID_CUR_TX_RATE:
1160 switch (ltv->wi_val) {
1161 case 1: oltv->wi_val = 1; break;
1162 case 2: oltv->wi_val = 2; break;
1163 case 3: oltv->wi_val = 6; break;
1164 case 4: oltv->wi_val = 5; break;
1165 case 7: oltv->wi_val = 7; break;
1166 case 8: oltv->wi_val = 11; break;
1167 case 15: oltv->wi_val = 3; break;
1168 default: oltv->wi_val = 0x100 + ltv->wi_val; break;
1171 case WI_RID_ENCRYPTION:
1173 if (ltv->wi_val & 0x01)
1178 case WI_RID_TX_CRYPT_KEY:
1180 oltv->wi_val = ltv->wi_val;
1182 case WI_RID_CNFAUTHMODE:
1184 if (le16toh(ltv->wi_val) & 0x01)
1185 oltv->wi_val = htole16(1);
1186 else if (le16toh(ltv->wi_val) & 0x02)
1187 oltv->wi_val = htole16(2);
1196 * Same as read, except we inject data instead of reading it.
1199 wi_write_record(sc, ltv)
1200 struct wi_softc *sc;
1201 struct wi_ltv_gen *ltv;
1205 struct wi_ltv_gen p2ltv;
1207 if (ltv->wi_type == WI_RID_PORTTYPE &&
1208 le16toh(ltv->wi_val) == WI_PORTTYPE_IBSS) {
1209 /* Convert WI_PORTTYPE_IBSS to vendor IBSS port type. */
1210 p2ltv.wi_type = WI_RID_PORTTYPE;
1212 p2ltv.wi_val = sc->wi_ibss_port;
1214 } else if (sc->sc_firmware_type != WI_LUCENT) {
1215 switch (ltv->wi_type) {
1216 case WI_RID_TX_RATE:
1217 p2ltv.wi_type = WI_RID_TX_RATE;
1219 switch (ltv->wi_val) {
1220 case 1: p2ltv.wi_val = 1; break;
1221 case 2: p2ltv.wi_val = 2; break;
1222 case 3: p2ltv.wi_val = 15; break;
1223 case 5: p2ltv.wi_val = 4; break;
1224 case 6: p2ltv.wi_val = 3; break;
1225 case 7: p2ltv.wi_val = 7; break;
1226 case 11: p2ltv.wi_val = 8; break;
1227 default: return EINVAL;
1231 case WI_RID_ENCRYPTION:
1232 p2ltv.wi_type = WI_RID_P2_ENCRYPTION;
1234 if (le16toh(ltv->wi_val)) {
1235 p2ltv.wi_val =htole16(PRIVACY_INVOKED |
1236 EXCLUDE_UNENCRYPTED);
1237 if (sc->wi_ptype == WI_PORTTYPE_AP)
1239 * Disable tx encryption...
1242 p2ltv.wi_val |= htole16(HOST_ENCRYPT);
1245 htole16(HOST_ENCRYPT | HOST_DECRYPT);
1248 case WI_RID_TX_CRYPT_KEY:
1249 p2ltv.wi_type = WI_RID_P2_TX_CRYPT_KEY;
1251 p2ltv.wi_val = ltv->wi_val;
1254 case WI_RID_DEFLT_CRYPT_KEYS:
1258 struct wi_ltv_str ws;
1259 struct wi_ltv_keys *wk =
1260 (struct wi_ltv_keys *)ltv;
1262 keylen = wk->wi_keys[sc->wi_tx_key].wi_keylen;
1264 for (i = 0; i < 4; i++) {
1265 bzero(&ws, sizeof(ws));
1266 ws.wi_len = (keylen > 5) ? 8 : 4;
1267 ws.wi_type = WI_RID_P2_CRYPT_KEY0 + i;
1269 &wk->wi_keys[i].wi_keydat, keylen);
1270 error = wi_write_record(sc,
1271 (struct wi_ltv_gen *)&ws);
1277 case WI_RID_CNFAUTHMODE:
1278 p2ltv.wi_type = WI_RID_CNFAUTHMODE;
1280 if (le16toh(ltv->wi_val) == 1)
1281 p2ltv.wi_val = htole16(0x01);
1282 else if (le16toh(ltv->wi_val) == 2)
1283 p2ltv.wi_val = htole16(0x02);
1286 case WI_RID_ROAMING_MODE:
1287 if (sc->sc_firmware_type == WI_INTERSIL)
1291 case WI_RID_MICROWAVE_OVEN:
1297 switch (ltv->wi_type) {
1298 case WI_RID_TX_RATE:
1299 switch (ltv->wi_val) {
1300 case 1: ltv->wi_val = 1; break; /* 1Mb/s fixed */
1301 case 2: ltv->wi_val = 2; break; /* 2Mb/s fixed */
1302 case 3: ltv->wi_val = 3; break; /* 11Mb/s auto */
1303 case 5: ltv->wi_val = 4; break; /* 5.5Mb/s fixed */
1304 case 6: ltv->wi_val = 6; break; /* 2Mb/s auto */
1305 case 7: ltv->wi_val = 7; break; /* 5.5Mb/s auto */
1306 case 11: ltv->wi_val = 5; break; /* 11Mb/s fixed */
1307 default: return EINVAL;
1312 if (wi_seek(sc, ltv->wi_type, 0, WI_BAP1))
1315 CSR_WRITE_2(sc, WI_DATA1, ltv->wi_len);
1316 CSR_WRITE_2(sc, WI_DATA1, ltv->wi_type);
1319 for (i = 0; i < ltv->wi_len - 1; i++)
1320 CSR_WRITE_2(sc, WI_DATA1, ptr[i]);
1322 if (wi_cmd(sc, WI_CMD_ACCESS|WI_ACCESS_WRITE, ltv->wi_type, 0, 0))
1329 wi_seek(sc, id, off, chan)
1330 struct wi_softc *sc;
1347 device_printf(sc->dev, "invalid data path: %x\n", chan);
1351 CSR_WRITE_2(sc, selreg, id);
1352 CSR_WRITE_2(sc, offreg, off);
1354 for (i = 0; i < WI_TIMEOUT; i++) {
1355 status = CSR_READ_2(sc, offreg);
1356 if (!(status & (WI_OFF_BUSY|WI_OFF_ERR)))
1361 if (i == WI_TIMEOUT) {
1362 device_printf(sc->dev, "timeout in wi_seek to %x/%x; last status %x\n",
1371 wi_read_data(sc, id, off, buf, len)
1372 struct wi_softc *sc;
1380 if (wi_seek(sc, id, off, WI_BAP1))
1383 ptr = (u_int16_t *)buf;
1384 for (i = 0; i < len / 2; i++)
1385 ptr[i] = CSR_READ_2(sc, WI_DATA1);
1391 * According to the comments in the HCF Light code, there is a bug in
1392 * the Hermes (or possibly in certain Hermes firmware revisions) where
1393 * the chip's internal autoincrement counter gets thrown off during
1394 * data writes: the autoincrement is missed, causing one data word to
1395 * be overwritten and subsequent words to be written to the wrong memory
1396 * locations. The end result is that we could end up transmitting bogus
1397 * frames without realizing it. The workaround for this is to write a
1398 * couple of extra guard words after the end of the transfer, then
1399 * attempt to read then back. If we fail to locate the guard words where
1400 * we expect them, we preform the transfer over again.
1403 wi_write_data(sc, id, off, buf, len)
1404 struct wi_softc *sc;
1411 #ifdef WI_HERMES_AUTOINC_WAR
1418 if (wi_seek(sc, id, off, WI_BAP0))
1421 ptr = (u_int16_t *)buf;
1422 for (i = 0; i < (len / 2); i++)
1423 CSR_WRITE_2(sc, WI_DATA0, ptr[i]);
1425 #ifdef WI_HERMES_AUTOINC_WAR
1426 CSR_WRITE_2(sc, WI_DATA0, 0x1234);
1427 CSR_WRITE_2(sc, WI_DATA0, 0x5678);
1429 if (wi_seek(sc, id, off + len, WI_BAP0))
1432 if (CSR_READ_2(sc, WI_DATA0) != 0x1234 ||
1433 CSR_READ_2(sc, WI_DATA0) != 0x5678) {
1436 device_printf(sc->dev, "wi_write_data device timeout\n");
1445 * Allocate a region of memory inside the NIC and zero
1449 wi_alloc_nicmem(sc, len, id)
1450 struct wi_softc *sc;
1456 if (wi_cmd(sc, WI_CMD_ALLOC_MEM, len, 0, 0)) {
1457 device_printf(sc->dev,
1458 "failed to allocate %d bytes on NIC\n", len);
1462 for (i = 0; i < WI_TIMEOUT; i++) {
1463 if (CSR_READ_2(sc, WI_EVENT_STAT) & WI_EV_ALLOC)
1468 if (i == WI_TIMEOUT) {
1469 device_printf(sc->dev, "time out allocating memory on card\n");
1473 CSR_WRITE_2(sc, WI_EVENT_ACK, WI_EV_ALLOC);
1474 *id = CSR_READ_2(sc, WI_ALLOC_FID);
1476 if (wi_seek(sc, *id, 0, WI_BAP0)) {
1477 device_printf(sc->dev, "seek failed while allocating memory on card\n");
1481 for (i = 0; i < len / 2; i++)
1482 CSR_WRITE_2(sc, WI_DATA0, 0);
1489 struct wi_softc *sc;
1493 struct ifmultiaddr *ifma;
1494 struct wi_ltv_mcast mcast;
1496 ifp = &sc->arpcom.ac_if;
1498 bzero((char *)&mcast, sizeof(mcast));
1500 mcast.wi_type = WI_RID_MCAST_LIST;
1501 mcast.wi_len = (3 * 16) + 1;
1503 if (ifp->if_flags & IFF_ALLMULTI || ifp->if_flags & IFF_PROMISC) {
1504 wi_write_record(sc, (struct wi_ltv_gen *)&mcast);
1508 #if defined(__DragonFly__) || __FreeBSD_version < 500000
1509 LIST_FOREACH(ifma, &ifp->if_multiaddrs, ifma_link) {
1511 TAILQ_FOREACH(ifma, &ifp->if_multiaddrs, ifma_link) {
1513 if (ifma->ifma_addr->sa_family != AF_LINK)
1516 bcopy(LLADDR((struct sockaddr_dl *)ifma->ifma_addr),
1517 (char *)&mcast.wi_mcast[i], ETHER_ADDR_LEN);
1520 bzero((char *)&mcast, sizeof(mcast));
1525 mcast.wi_len = (i * 3) + 1;
1526 wi_write_record(sc, (struct wi_ltv_gen *)&mcast);
1533 struct wi_softc *sc;
1534 struct wi_req *wreq;
1536 struct sockaddr_dl *sdl;
1540 ifp = &sc->arpcom.ac_if;
1542 switch(wreq->wi_type) {
1543 case WI_RID_MAC_NODE:
1544 ifa = ifaddr_byindex(ifp->if_index);
1545 sdl = (struct sockaddr_dl *)ifa->ifa_addr;
1546 bcopy((char *)&wreq->wi_val, (char *)&sc->arpcom.ac_enaddr,
1548 bcopy((char *)&wreq->wi_val, LLADDR(sdl), ETHER_ADDR_LEN);
1550 case WI_RID_PORTTYPE:
1551 sc->wi_ptype = le16toh(wreq->wi_val[0]);
1553 case WI_RID_TX_RATE:
1554 sc->wi_tx_rate = le16toh(wreq->wi_val[0]);
1556 case WI_RID_MAX_DATALEN:
1557 sc->wi_max_data_len = le16toh(wreq->wi_val[0]);
1559 case WI_RID_RTS_THRESH:
1560 sc->wi_rts_thresh = le16toh(wreq->wi_val[0]);
1562 case WI_RID_SYSTEM_SCALE:
1563 sc->wi_ap_density = le16toh(wreq->wi_val[0]);
1565 case WI_RID_CREATE_IBSS:
1566 sc->wi_create_ibss = le16toh(wreq->wi_val[0]);
1568 case WI_RID_OWN_CHNL:
1569 sc->wi_channel = le16toh(wreq->wi_val[0]);
1571 case WI_RID_NODENAME:
1572 bzero(sc->wi_node_name, sizeof(sc->wi_node_name));
1573 bcopy((char *)&wreq->wi_val[1], sc->wi_node_name, 30);
1575 case WI_RID_DESIRED_SSID:
1576 bzero(sc->wi_net_name, sizeof(sc->wi_net_name));
1577 bcopy((char *)&wreq->wi_val[1], sc->wi_net_name, 30);
1579 case WI_RID_OWN_SSID:
1580 bzero(sc->wi_ibss_name, sizeof(sc->wi_ibss_name));
1581 bcopy((char *)&wreq->wi_val[1], sc->wi_ibss_name, 30);
1583 case WI_RID_PM_ENABLED:
1584 sc->wi_pm_enabled = le16toh(wreq->wi_val[0]);
1586 case WI_RID_MICROWAVE_OVEN:
1587 sc->wi_mor_enabled = le16toh(wreq->wi_val[0]);
1589 case WI_RID_MAX_SLEEP:
1590 sc->wi_max_sleep = le16toh(wreq->wi_val[0]);
1592 case WI_RID_CNFAUTHMODE:
1593 sc->wi_authtype = le16toh(wreq->wi_val[0]);
1595 case WI_RID_ROAMING_MODE:
1596 sc->wi_roaming = le16toh(wreq->wi_val[0]);
1598 case WI_RID_ENCRYPTION:
1599 sc->wi_use_wep = le16toh(wreq->wi_val[0]);
1601 case WI_RID_TX_CRYPT_KEY:
1602 sc->wi_tx_key = le16toh(wreq->wi_val[0]);
1604 case WI_RID_DEFLT_CRYPT_KEYS:
1605 bcopy((char *)wreq, (char *)&sc->wi_keys,
1606 sizeof(struct wi_ltv_keys));
1612 /* Reinitialize WaveLAN. */
1619 wi_ioctl(ifp, command, data, cr)
1627 u_int8_t tmpkey[14];
1628 char tmpssid[IEEE80211_NWID_LEN];
1629 struct wi_softc *sc;
1632 struct ieee80211req *ireq;
1637 ifr = (struct ifreq *)data;
1638 ireq = (struct ieee80211req *)data;
1648 * Can't do promisc and hostap at the same time. If all that's
1649 * changing is the promisc flag, try to short-circuit a call to
1650 * wi_init() by just setting PROMISC in the hardware.
1652 if (ifp->if_flags & IFF_UP) {
1653 if (sc->wi_ptype != WI_PORTTYPE_AP &&
1654 ifp->if_flags & IFF_RUNNING) {
1655 if (ifp->if_flags & IFF_PROMISC &&
1656 !(sc->wi_if_flags & IFF_PROMISC)) {
1657 WI_SETVAL(WI_RID_PROMISC, 1);
1658 } else if (!(ifp->if_flags & IFF_PROMISC) &&
1659 sc->wi_if_flags & IFF_PROMISC) {
1660 WI_SETVAL(WI_RID_PROMISC, 0);
1668 if (ifp->if_flags & IFF_RUNNING) {
1672 sc->wi_if_flags = ifp->if_flags;
1677 error = ifmedia_ioctl(ifp, ifr, &sc->ifmedia, command);
1685 error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
1688 if (wreq.wi_len > WI_MAX_DATALEN) {
1692 /* Don't show WEP keys to non-root users. */
1693 if (wreq.wi_type == WI_RID_DEFLT_CRYPT_KEYS &&
1694 suser_cred(cr, NULL_CRED_OKAY))
1696 if (wreq.wi_type == WI_RID_IFACE_STATS) {
1697 bcopy((char *)&sc->wi_stats, (char *)&wreq.wi_val,
1698 sizeof(sc->wi_stats));
1699 wreq.wi_len = (sizeof(sc->wi_stats) / 2) + 1;
1700 } else if (wreq.wi_type == WI_RID_DEFLT_CRYPT_KEYS) {
1701 bcopy((char *)&sc->wi_keys, (char *)&wreq,
1702 sizeof(struct wi_ltv_keys));
1705 else if (wreq.wi_type == WI_RID_ZERO_CACHE) {
1706 sc->wi_sigitems = sc->wi_nextitem = 0;
1707 } else if (wreq.wi_type == WI_RID_READ_CACHE) {
1708 char *pt = (char *)&wreq.wi_val;
1709 bcopy((char *)&sc->wi_sigitems,
1710 (char *)pt, sizeof(int));
1711 pt += (sizeof (int));
1712 wreq.wi_len = sizeof(int) / 2;
1713 bcopy((char *)&sc->wi_sigcache, (char *)pt,
1714 sizeof(struct wi_sigcache) * sc->wi_sigitems);
1715 wreq.wi_len += ((sizeof(struct wi_sigcache) *
1716 sc->wi_sigitems) / 2) + 1;
1719 else if (wreq.wi_type == WI_RID_PROCFRAME) {
1721 wreq.wi_val[0] = sc->wi_procframe;
1722 } else if (wreq.wi_type == WI_RID_PRISM2) {
1724 wreq.wi_val[0] = sc->sc_firmware_type != WI_LUCENT;
1725 } else if (wreq.wi_type == WI_RID_SCAN_RES &&
1726 sc->sc_firmware_type == WI_LUCENT) {
1727 memcpy((char *)wreq.wi_val, (char *)sc->wi_scanbuf,
1728 sc->wi_scanbuf_len * 2);
1729 wreq.wi_len = sc->wi_scanbuf_len;
1731 if (wi_read_record(sc, (struct wi_ltv_gen *)&wreq)) {
1736 error = copyout(&wreq, ifr->ifr_data, sizeof(wreq));
1739 if ((error = suser_cred(cr, NULL_CRED_OKAY)))
1741 error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
1744 if (wreq.wi_len > WI_MAX_DATALEN) {
1748 if (wreq.wi_type == WI_RID_IFACE_STATS) {
1751 } else if (wreq.wi_type == WI_RID_MGMT_XMIT) {
1752 error = owi_mgmt_xmit(sc, (caddr_t)&wreq.wi_val,
1754 } else if (wreq.wi_type == WI_RID_PROCFRAME) {
1755 sc->wi_procframe = wreq.wi_val[0];
1757 * if we're getting a scan request from a wavelan card
1758 * (non-prism2), send out a cmd_inquire to the card to scan
1759 * results for the scan will be received through the info
1760 * interrupt handler. otherwise the scan request can be
1761 * directly handled by a prism2 card's rid interface.
1763 } else if (wreq.wi_type == WI_RID_SCAN_REQ &&
1764 sc->sc_firmware_type == WI_LUCENT) {
1765 wi_cmd(sc, WI_CMD_INQUIRE, WI_INFO_SCAN_RESULTS, 0, 0);
1767 error = wi_write_record(sc, (struct wi_ltv_gen *)&wreq);
1769 wi_setdef(sc, &wreq);
1772 case SIOCGPRISM2DEBUG:
1773 error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
1776 if (!(ifp->if_flags & IFF_RUNNING) ||
1777 sc->sc_firmware_type == WI_LUCENT) {
1781 error = wi_get_debug(sc, &wreq);
1783 error = copyout(&wreq, ifr->ifr_data, sizeof(wreq));
1785 case SIOCSPRISM2DEBUG:
1786 if ((error = suser_cred(cr, NULL_CRED_OKAY)))
1788 error = copyin(ifr->ifr_data, &wreq, sizeof(wreq));
1791 error = wi_set_debug(sc, &wreq);
1794 switch(ireq->i_type) {
1795 case IEEE80211_IOC_SSID:
1796 if(ireq->i_val == -1) {
1797 bzero(tmpssid, IEEE80211_NWID_LEN);
1798 error = wi_get_cur_ssid(sc, tmpssid, &len);
1801 error = copyout(tmpssid, ireq->i_data,
1802 IEEE80211_NWID_LEN);
1804 } else if (ireq->i_val == 0) {
1805 error = copyout(sc->wi_net_name,
1807 IEEE80211_NWID_LEN);
1808 ireq->i_len = IEEE80211_NWID_LEN;
1812 case IEEE80211_IOC_NUMSSIDS:
1815 case IEEE80211_IOC_WEP:
1816 if(!sc->wi_has_wep) {
1817 ireq->i_val = IEEE80211_WEP_NOSUP;
1819 if(sc->wi_use_wep) {
1821 IEEE80211_WEP_MIXED;
1828 case IEEE80211_IOC_WEPKEY:
1829 if(!sc->wi_has_wep ||
1830 ireq->i_val < 0 || ireq->i_val > 3) {
1834 len = sc->wi_keys.wi_keys[ireq->i_val].wi_keylen;
1835 if (suser_cred(cr, NULL_CRED_OKAY))
1836 bcopy(sc->wi_keys.wi_keys[ireq->i_val].wi_keydat,
1842 error = copyout(tmpkey, ireq->i_data, len);
1845 case IEEE80211_IOC_NUMWEPKEYS:
1851 case IEEE80211_IOC_WEPTXKEY:
1855 ireq->i_val = sc->wi_tx_key;
1857 case IEEE80211_IOC_AUTHMODE:
1858 ireq->i_val = sc->wi_authmode;
1860 case IEEE80211_IOC_STATIONNAME:
1861 error = copyout(sc->wi_node_name,
1862 ireq->i_data, IEEE80211_NWID_LEN);
1863 ireq->i_len = IEEE80211_NWID_LEN;
1865 case IEEE80211_IOC_CHANNEL:
1866 wreq.wi_type = WI_RID_CURRENT_CHAN;
1867 wreq.wi_len = WI_MAX_DATALEN;
1868 if (wi_read_record(sc, (struct wi_ltv_gen *)&wreq))
1871 ireq->i_val = wreq.wi_val[0];
1874 case IEEE80211_IOC_POWERSAVE:
1875 if(sc->wi_pm_enabled)
1876 ireq->i_val = IEEE80211_POWERSAVE_ON;
1878 ireq->i_val = IEEE80211_POWERSAVE_OFF;
1880 case IEEE80211_IOC_POWERSAVESLEEP:
1881 ireq->i_val = sc->wi_max_sleep;
1888 if ((error = suser_cred(cr, NULL_CRED_OKAY)))
1890 switch(ireq->i_type) {
1891 case IEEE80211_IOC_SSID:
1892 if (ireq->i_val != 0 ||
1893 ireq->i_len > IEEE80211_NWID_LEN) {
1897 /* We set both of them */
1898 bzero(sc->wi_net_name, IEEE80211_NWID_LEN);
1899 error = copyin(ireq->i_data,
1900 sc->wi_net_name, ireq->i_len);
1901 bcopy(sc->wi_net_name, sc->wi_ibss_name, IEEE80211_NWID_LEN);
1903 case IEEE80211_IOC_WEP:
1905 * These cards only support one mode so
1906 * we just turn wep on what ever is
1907 * passed in if it's not OFF.
1909 if (ireq->i_val == IEEE80211_WEP_OFF) {
1915 case IEEE80211_IOC_WEPKEY:
1916 if (ireq->i_val < 0 || ireq->i_val > 3 ||
1921 bzero(sc->wi_keys.wi_keys[ireq->i_val].wi_keydat, 13);
1922 error = copyin(ireq->i_data,
1923 sc->wi_keys.wi_keys[ireq->i_val].wi_keydat,
1927 sc->wi_keys.wi_keys[ireq->i_val].wi_keylen =
1930 case IEEE80211_IOC_WEPTXKEY:
1931 if (ireq->i_val < 0 || ireq->i_val > 3) {
1935 sc->wi_tx_key = ireq->i_val;
1937 case IEEE80211_IOC_AUTHMODE:
1938 sc->wi_authmode = ireq->i_val;
1940 case IEEE80211_IOC_STATIONNAME:
1941 if (ireq->i_len > 32) {
1945 bzero(sc->wi_node_name, 32);
1946 error = copyin(ireq->i_data,
1947 sc->wi_node_name, ireq->i_len);
1949 case IEEE80211_IOC_CHANNEL:
1951 * The actual range is 1-14, but if you
1952 * set it to 0 you get the default. So
1953 * we let that work too.
1955 if (ireq->i_val < 0 || ireq->i_val > 14) {
1959 sc->wi_channel = ireq->i_val;
1961 case IEEE80211_IOC_POWERSAVE:
1962 switch (ireq->i_val) {
1963 case IEEE80211_POWERSAVE_OFF:
1964 sc->wi_pm_enabled = 0;
1966 case IEEE80211_POWERSAVE_ON:
1967 sc->wi_pm_enabled = 1;
1974 case IEEE80211_IOC_POWERSAVESLEEP:
1975 if (ireq->i_val < 0) {
1979 sc->wi_max_sleep = ireq->i_val;
1986 /* Reinitialize WaveLAN. */
1990 case SIOCHOSTAP_ADD:
1991 case SIOCHOSTAP_DEL:
1992 case SIOCHOSTAP_GET:
1993 case SIOCHOSTAP_GETALL:
1994 case SIOCHOSTAP_GFLAGS:
1995 case SIOCHOSTAP_SFLAGS:
1996 /* Send all Host AP specific ioctl's to Host AP code. */
1997 error = owihap_ioctl(sc, command, data);
2000 error = ether_ioctl(ifp, command, data);
2013 struct wi_softc *sc = xsc;
2014 struct ifnet *ifp = &sc->arpcom.ac_if;
2015 struct wi_ltv_macaddr mac;
2026 if (ifp->if_flags & IFF_RUNNING)
2031 /* Program max data length. */
2032 WI_SETVAL(WI_RID_MAX_DATALEN, sc->wi_max_data_len);
2034 /* Set the port type. */
2035 WI_SETVAL(WI_RID_PORTTYPE, sc->wi_ptype);
2037 /* Enable/disable IBSS creation. */
2038 WI_SETVAL(WI_RID_CREATE_IBSS, sc->wi_create_ibss);
2040 /* Program the RTS/CTS threshold. */
2041 WI_SETVAL(WI_RID_RTS_THRESH, sc->wi_rts_thresh);
2043 /* Program the TX rate */
2044 WI_SETVAL(WI_RID_TX_RATE, sc->wi_tx_rate);
2046 /* Access point density */
2047 WI_SETVAL(WI_RID_SYSTEM_SCALE, sc->wi_ap_density);
2049 /* Power Management Enabled */
2050 WI_SETVAL(WI_RID_PM_ENABLED, sc->wi_pm_enabled);
2052 /* Power Managment Max Sleep */
2053 WI_SETVAL(WI_RID_MAX_SLEEP, sc->wi_max_sleep);
2056 WI_SETVAL(WI_RID_ROAMING_MODE, sc->wi_roaming);
2058 /* Specify the IBSS name */
2059 WI_SETSTR(WI_RID_OWN_SSID, sc->wi_ibss_name);
2061 /* Specify the network name */
2062 WI_SETSTR(WI_RID_DESIRED_SSID, sc->wi_net_name);
2064 /* Specify the frequency to use */
2065 WI_SETVAL(WI_RID_OWN_CHNL, sc->wi_channel);
2067 /* Program the nodename. */
2068 WI_SETSTR(WI_RID_NODENAME, sc->wi_node_name);
2070 /* Specify the authentication mode. */
2071 WI_SETVAL(WI_RID_CNFAUTHMODE, sc->wi_authmode);
2073 /* Set our MAC address. */
2075 mac.wi_type = WI_RID_MAC_NODE;
2076 bcopy((char *)&sc->arpcom.ac_enaddr,
2077 (char *)&mac.wi_mac_addr, ETHER_ADDR_LEN);
2078 wi_write_record(sc, (struct wi_ltv_gen *)&mac);
2081 * Initialize promisc mode.
2082 * Being in the Host-AP mode causes
2083 * great deal of pain if promisc mode is set.
2084 * Therefore we avoid confusing the firmware
2085 * and always reset promisc mode in Host-AP regime,
2086 * it shows us all the packets anyway.
2088 if (sc->wi_ptype != WI_PORTTYPE_AP && ifp->if_flags & IFF_PROMISC)
2089 WI_SETVAL(WI_RID_PROMISC, 1);
2091 WI_SETVAL(WI_RID_PROMISC, 0);
2093 /* Configure WEP. */
2094 if (sc->wi_has_wep) {
2095 WI_SETVAL(WI_RID_ENCRYPTION, sc->wi_use_wep);
2096 WI_SETVAL(WI_RID_TX_CRYPT_KEY, sc->wi_tx_key);
2097 sc->wi_keys.wi_len = (sizeof(struct wi_ltv_keys) / 2) + 1;
2098 sc->wi_keys.wi_type = WI_RID_DEFLT_CRYPT_KEYS;
2099 wi_write_record(sc, (struct wi_ltv_gen *)&sc->wi_keys);
2100 if (sc->sc_firmware_type != WI_LUCENT && sc->wi_use_wep) {
2102 * ONLY HWB3163 EVAL-CARD Firmware version
2103 * less than 0.8 variant2
2105 * If promiscuous mode disable, Prism2 chip
2106 * does not work with WEP.
2107 * It is under investigation for details.
2108 * (ichiro@netbsd.org)
2110 * And make sure that we don't need to do it
2111 * in hostap mode, since it interferes with
2112 * the above hostap workaround.
2114 if (sc->wi_ptype != WI_PORTTYPE_AP &&
2115 sc->sc_firmware_type == WI_INTERSIL &&
2116 sc->sc_sta_firmware_ver < 802 ) {
2117 /* firm ver < 0.8 variant 2 */
2118 WI_SETVAL(WI_RID_PROMISC, 1);
2120 WI_SETVAL(WI_RID_CNFAUTHMODE, sc->wi_authtype);
2124 /* Set multicast filter. */
2127 /* Enable desired port */
2128 wi_cmd(sc, WI_CMD_ENABLE | sc->wi_portnum, 0, 0, 0);
2130 if (wi_alloc_nicmem(sc, ETHER_MAX_LEN + sizeof(struct wi_frame) + 8, &id))
2131 device_printf(sc->dev, "tx buffer allocation failed\n");
2132 sc->wi_tx_data_id = id;
2134 if (wi_alloc_nicmem(sc, ETHER_MAX_LEN + sizeof(struct wi_frame) + 8, &id))
2135 device_printf(sc->dev, "mgmt. buffer allocation failed\n");
2136 sc->wi_tx_mgmt_id = id;
2138 /* enable interrupts */
2139 CSR_WRITE_2(sc, WI_INT_EN, WI_INTRS);
2143 ifp->if_flags |= IFF_RUNNING;
2144 ifp->if_flags &= ~IFF_OACTIVE;
2146 callout_reset(&sc->wi_stat_timer, hz * 60, wi_inquire, sc);
2152 #define RC4STATE 256
2153 #define RC4KEYLEN 16
2154 #define RC4SWAP(x,y) \
2155 do { u_int8_t t = state[x]; state[x] = state[y]; state[y] = t; } while(0)
2158 wi_do_hostencrypt(struct wi_softc *sc, caddr_t buf, int len)
2160 u_int32_t i, crc, klen;
2161 u_int8_t state[RC4STATE], key[RC4KEYLEN];
2162 u_int8_t x, y, *dat;
2164 if (!sc->wi_icv_flag) {
2165 sc->wi_icv = arc4random();
2170 * Skip 'bad' IVs from Fluhrer/Mantin/Shamir:
2171 * (B, 255, N) with 3 <= B < 8
2173 if (sc->wi_icv >= 0x03ff00 &&
2174 (sc->wi_icv & 0xf8ff00) == 0x00ff00)
2175 sc->wi_icv += 0x000100;
2177 /* prepend 24bit IV to tx key, byte order does not matter */
2178 key[0] = sc->wi_icv >> 16;
2179 key[1] = sc->wi_icv >> 8;
2180 key[2] = sc->wi_icv;
2182 klen = sc->wi_keys.wi_keys[sc->wi_tx_key].wi_keylen +
2183 IEEE80211_WEP_IVLEN;
2184 klen = (klen >= RC4KEYLEN) ? RC4KEYLEN : RC4KEYLEN/2;
2185 bcopy((char *)&sc->wi_keys.wi_keys[sc->wi_tx_key].wi_keydat,
2186 (char *)key + IEEE80211_WEP_IVLEN, klen - IEEE80211_WEP_IVLEN);
2190 for (i = 0; i < RC4STATE; i++)
2192 for (i = 0; i < RC4STATE; i++) {
2193 y = (key[x] + state[i] + y) % RC4STATE;
2198 /* output: IV, tx keyid, rc4(data), rc4(crc32(data)) */
2203 dat[3] = sc->wi_tx_key << 6; /* pad and keyid */
2206 /* compute rc4 over data, crc32 over data */
2209 for (i = 0; i < len; i++) {
2210 x = (x + 1) % RC4STATE;
2211 y = (state[x] + y) % RC4STATE;
2213 crc = crc32_tab[(crc ^ dat[i]) & 0xff] ^ (crc >> 8);
2214 dat[i] ^= state[(state[x] + state[y]) % RC4STATE];
2219 /* append little-endian crc32 and encrypt */
2224 for (i = 0; i < IEEE80211_WEP_CRCLEN; i++) {
2225 x = (x + 1) % RC4STATE;
2226 y = (state[x] + y) % RC4STATE;
2228 dat[i] ^= state[(state[x] + state[y]) % RC4STATE];
2236 struct wi_softc *sc;
2238 struct wi_frame tx_frame;
2239 struct ether_header *eh;
2251 if (ifp->if_flags & IFF_OACTIVE) {
2257 m0 = ifq_dequeue(&ifp->if_snd);
2263 bzero((char *)&tx_frame, sizeof(tx_frame));
2264 tx_frame.wi_frame_ctl = htole16(WI_FTYPE_DATA);
2265 id = sc->wi_tx_data_id;
2266 eh = mtod(m0, struct ether_header *);
2268 if (sc->wi_ptype == WI_PORTTYPE_AP) {
2269 if (!owihap_check_tx(&sc->wi_hostap_info,
2270 eh->ether_dhost, &tx_frame.wi_tx_rate)) {
2271 if (ifp->if_flags & IFF_DEBUG)
2272 printf("wi_start: dropping unassoc "
2273 "dst %6D\n", eh->ether_dhost, ":");
2279 * Use RFC1042 encoding for IP and ARP datagrams,
2280 * 802.3 for anything else.
2282 if (ntohs(eh->ether_type) > ETHER_MAX_LEN) {
2283 bcopy((char *)&eh->ether_dhost,
2284 (char *)&tx_frame.wi_addr1, ETHER_ADDR_LEN);
2285 if (sc->wi_ptype == WI_PORTTYPE_AP) {
2286 tx_frame.wi_tx_ctl = WI_ENC_TX_MGMT; /* XXX */
2287 tx_frame.wi_frame_ctl |= WI_FCTL_FROMDS;
2289 tx_frame.wi_frame_ctl |= WI_FCTL_WEP;
2290 bcopy((char *)&sc->arpcom.ac_enaddr,
2291 (char *)&tx_frame.wi_addr2, ETHER_ADDR_LEN);
2292 bcopy((char *)&eh->ether_shost,
2293 (char *)&tx_frame.wi_addr3, ETHER_ADDR_LEN);
2296 bcopy((char *)&eh->ether_shost,
2297 (char *)&tx_frame.wi_addr2, ETHER_ADDR_LEN);
2298 bcopy((char *)&eh->ether_dhost,
2299 (char *)&tx_frame.wi_dst_addr, ETHER_ADDR_LEN);
2300 bcopy((char *)&eh->ether_shost,
2301 (char *)&tx_frame.wi_src_addr, ETHER_ADDR_LEN);
2303 tx_frame.wi_dat_len = m0->m_pkthdr.len - WI_SNAPHDR_LEN;
2304 tx_frame.wi_dat[0] = htons(WI_SNAP_WORD0);
2305 tx_frame.wi_dat[1] = htons(WI_SNAP_WORD1);
2306 tx_frame.wi_len = htons(m0->m_pkthdr.len - WI_SNAPHDR_LEN);
2307 tx_frame.wi_type = eh->ether_type;
2309 if (sc->wi_ptype == WI_PORTTYPE_AP && sc->wi_use_wep) {
2310 /* Do host encryption. */
2311 bcopy(&tx_frame.wi_dat[0], &sc->wi_txbuf[4], 8);
2312 m_copydata(m0, sizeof(struct ether_header),
2313 m0->m_pkthdr.len - sizeof(struct ether_header),
2314 (caddr_t)&sc->wi_txbuf[12]);
2315 wi_do_hostencrypt(sc, &sc->wi_txbuf[0],
2316 tx_frame.wi_dat_len);
2317 tx_frame.wi_dat_len += IEEE80211_WEP_IVLEN +
2318 IEEE80211_WEP_KIDLEN + IEEE80211_WEP_CRCLEN;
2319 wi_write_data(sc, id, 0, (caddr_t)&tx_frame,
2320 sizeof(struct wi_frame));
2321 wi_write_data(sc, id, WI_802_11_OFFSET_RAW,
2322 (caddr_t)&sc->wi_txbuf, (m0->m_pkthdr.len -
2323 sizeof(struct ether_header)) + 18);
2325 m_copydata(m0, sizeof(struct ether_header),
2326 m0->m_pkthdr.len - sizeof(struct ether_header),
2327 (caddr_t)&sc->wi_txbuf);
2328 wi_write_data(sc, id, 0, (caddr_t)&tx_frame,
2329 sizeof(struct wi_frame));
2330 wi_write_data(sc, id, WI_802_11_OFFSET,
2331 (caddr_t)&sc->wi_txbuf, (m0->m_pkthdr.len -
2332 sizeof(struct ether_header)) + 2);
2335 tx_frame.wi_dat_len = m0->m_pkthdr.len;
2337 if (sc->wi_ptype == WI_PORTTYPE_AP && sc->wi_use_wep) {
2338 /* Do host encryption. */
2339 printf( "XXX: host encrypt not implemented for 802.3\n" );
2341 eh->ether_type = htons(m0->m_pkthdr.len -
2343 m_copydata(m0, 0, m0->m_pkthdr.len,
2344 (caddr_t)&sc->wi_txbuf);
2346 wi_write_data(sc, id, 0, (caddr_t)&tx_frame,
2347 sizeof(struct wi_frame));
2348 wi_write_data(sc, id, WI_802_3_OFFSET,
2349 (caddr_t)&sc->wi_txbuf, m0->m_pkthdr.len + 2);
2354 * If there's a BPF listner, bounce a copy of
2355 * this frame to him. Also, don't send this to the bpf sniffer
2356 * if we're in procframe or monitor sniffing mode.
2358 if (!(sc->wi_procframe || sc->wi_debug.wi_monitor))
2363 if (wi_cmd(sc, WI_CMD_TX|WI_RECLAIM, id, 0, 0))
2364 device_printf(sc->dev, "xmit failed\n");
2366 ifp->if_flags |= IFF_OACTIVE;
2369 * Set a timeout in case the chip goes out to lunch.
2378 owi_mgmt_xmit(sc, data, len)
2379 struct wi_softc *sc;
2383 struct wi_frame tx_frame;
2385 struct wi_80211_hdr *hdr;
2391 hdr = (struct wi_80211_hdr *)data;
2392 dptr = data + sizeof(struct wi_80211_hdr);
2394 bzero((char *)&tx_frame, sizeof(tx_frame));
2395 id = sc->wi_tx_mgmt_id;
2397 bcopy((char *)hdr, (char *)&tx_frame.wi_frame_ctl,
2398 sizeof(struct wi_80211_hdr));
2400 tx_frame.wi_tx_ctl = WI_ENC_TX_MGMT;
2401 tx_frame.wi_dat_len = len - sizeof(struct wi_80211_hdr);
2402 tx_frame.wi_len = htons(tx_frame.wi_dat_len);
2404 wi_write_data(sc, id, 0, (caddr_t)&tx_frame, sizeof(struct wi_frame));
2405 wi_write_data(sc, id, WI_802_11_OFFSET_RAW, dptr,
2406 len - sizeof(struct wi_80211_hdr) + 2);
2408 if (wi_cmd(sc, WI_CMD_TX|WI_RECLAIM, id, 0, 0)) {
2409 device_printf(sc->dev, "xmit failed\n");
2418 struct wi_softc *sc;
2430 owihap_shutdown(sc);
2432 ifp = &sc->arpcom.ac_if;
2435 * If the card is gone and the memory port isn't mapped, we will
2436 * (hopefully) get 0xffff back from the status read, which is not
2437 * a valid status value.
2439 if (CSR_READ_2(sc, WI_STATUS) != 0xffff) {
2440 CSR_WRITE_2(sc, WI_INT_EN, 0);
2441 wi_cmd(sc, WI_CMD_DISABLE|sc->wi_portnum, 0, 0, 0);
2444 callout_stop(&sc->wi_stat_timer);
2446 ifp->if_flags &= ~(IFF_RUNNING|IFF_OACTIVE);
2456 struct wi_softc *sc;
2460 device_printf(sc->dev, "watchdog timeout\n");
2474 struct wi_softc *sc = device_get_softc(dev);
2476 if (sc->wi_bus_type != WI_BUS_PCI_NATIVE) {
2477 sc->iobase_rid = rid;
2478 sc->iobase = bus_alloc_resource(dev, SYS_RES_IOPORT,
2479 &sc->iobase_rid, 0, ~0, (1 << 6),
2480 rman_make_alignment_flags(1 << 6) | RF_ACTIVE);
2482 device_printf(dev, "No I/O space?!\n");
2486 sc->wi_io_addr = rman_get_start(sc->iobase);
2487 sc->wi_btag = rman_get_bustag(sc->iobase);
2488 sc->wi_bhandle = rman_get_bushandle(sc->iobase);
2491 sc->mem = bus_alloc_resource_any(dev, SYS_RES_MEMORY,
2492 &sc->mem_rid, RF_ACTIVE);
2495 device_printf(dev, "No Mem space on prism2.5?\n");
2499 sc->wi_btag = rman_get_bustag(sc->mem);
2500 sc->wi_bhandle = rman_get_bushandle(sc->mem);
2505 sc->irq = bus_alloc_resource_any(dev, SYS_RES_IRQ, &sc->irq_rid,
2507 ((sc->wi_bus_type == WI_BUS_PCCARD) ? 0 : RF_SHAREABLE));
2511 device_printf(dev, "No irq?!\n");
2516 sc->wi_unit = device_get_unit(dev);
2525 struct wi_softc *sc = device_get_softc(dev);
2527 if (sc->iobase != NULL) {
2528 bus_release_resource(dev, SYS_RES_IOPORT, sc->iobase_rid, sc->iobase);
2531 if (sc->irq != NULL) {
2532 bus_release_resource(dev, SYS_RES_IRQ, sc->irq_rid, sc->irq);
2535 if (sc->mem != NULL) {
2536 bus_release_resource(dev, SYS_RES_MEMORY, sc->mem_rid, sc->mem);
2547 struct wi_softc *sc;
2549 sc = device_get_softc(dev);
2556 /* wavelan signal strength cache code.
2557 * store signal/noise/quality on per MAC src basis in
2558 * a small fixed cache. The cache wraps if > MAX slots
2559 * used. The cache may be zeroed out to start over.
2560 * Two simple filters exist to reduce computation:
2561 * 1. ip only (literally 0x800) which may be used
2562 * to ignore some packets. It defaults to ip only.
2563 * it could be used to focus on broadcast, non-IP 802.11 beacons.
2564 * 2. multicast/broadcast only. This may be used to
2565 * ignore unicast packets and only cache signal strength
2566 * for multicast/broadcast packets (beacons); e.g., Mobile-IP
2567 * beacons and not unicast traffic.
2569 * The cache stores (MAC src(index), IP src (major clue), signal,
2572 * No apologies for storing IP src here. It's easy and saves much
2573 * trouble elsewhere. The cache is assumed to be INET dependent,
2574 * although it need not be.
2577 #ifdef documentation
2579 int owi_sigitems; /* number of cached entries */
2580 struct wi_sigcache owi_sigcache[MAXWICACHE]; /* array of cache entries */
2581 int owi_nextitem; /* index/# of entries */
2586 /* control variables for cache filtering. Basic idea is
2587 * to reduce cost (e.g., to only Mobile-IP agent beacons
2588 * which are broadcast or multicast). Still you might
2589 * want to measure signal strength with unicast ping packets
2590 * on a pt. to pt. ant. setup.
2592 /* set true if you want to limit cache items to broadcast/mcast
2593 * only packets (not unicast). Useful for mobile-ip beacons which
2594 * are broadcast/multicast at network layer. Default is all packets
2595 * so ping/unicast will work say with pt. to pt. antennae setup.
2597 static int wi_cache_mcastonly = 0;
2598 SYSCTL_INT(_machdep, OID_AUTO, owi_cache_mcastonly, CTLFLAG_RW,
2599 &wi_cache_mcastonly, 0, "");
2601 /* set true if you want to limit cache items to IP packets only
2603 static int wi_cache_iponly = 1;
2604 SYSCTL_INT(_machdep, OID_AUTO, owi_cache_iponly, CTLFLAG_RW,
2605 &wi_cache_iponly, 0, "");
2608 * Original comments:
2610 * wi_cache_store, per rx packet store signal
2611 * strength in MAC (src) indexed cache.
2613 * follows linux driver in how signal strength is computed.
2614 * In ad hoc mode, we use the rx_quality field.
2615 * signal and noise are trimmed to fit in the range from 47..138.
2616 * rx_quality field MSB is signal strength.
2617 * rx_quality field LSB is noise.
2618 * "quality" is (signal - noise) as is log value.
2619 * note: quality CAN be negative.
2621 * In BSS mode, we use the RID for communication quality.
2622 * TBD: BSS mode is currently untested.
2626 * Actually, we use the rx_quality field all the time for both "ad-hoc"
2627 * and BSS modes. Why? Because reading an RID is really, really expensive:
2628 * there's a bunch of PIO operations that have to be done to read a record
2629 * from the NIC, and reading the comms quality RID each time a packet is
2630 * received can really hurt performance. We don't have to do this anyway:
2631 * the comms quality field only reflects the values in the rx_quality field
2632 * anyway. The comms quality RID is only meaningful in infrastructure mode,
2633 * but the values it contains are updated based on the rx_quality from
2634 * frames received from the access point.
2636 * Also, according to Lucent, the signal strength and noise level values
2637 * can be converted to dBms by subtracting 149, so I've modified the code
2638 * to do that instead of the scaling it did originally.
2641 wi_cache_store(struct wi_softc *sc, struct mbuf *m, unsigned short rx_quality)
2643 struct ether_header *eh = mtod(m, struct ether_header *);
2644 struct ip *ip = NULL;
2646 static int cache_slot = 0; /* use this cache entry */
2647 static int wrapindex = 0; /* next "free" cache entry */
2653 * 2. configurable filter to throw out unicast packets,
2654 * keep multicast only.
2657 if ((ntohs(eh->ether_type) == ETHERTYPE_IP))
2658 ip = (struct ip *)(mtod(m, uint8_t *) + ETHER_HDR_LEN);
2659 else if (wi_cache_iponly)
2663 * filter for broadcast/multicast only
2665 if (wi_cache_mcastonly && ((eh->ether_dhost[0] & 1) == 0)) {
2670 printf("wi%d: q value %x (MSB=0x%x, LSB=0x%x) \n", sc->wi_unit,
2671 rx_quality & 0xffff, rx_quality >> 8, rx_quality & 0xff);
2676 * do a linear search for a matching MAC address
2677 * in the cache table
2678 * . MAC address is 6 bytes,
2679 * . var w_nextitem holds total number of entries already cached
2681 for(i = 0; i < sc->wi_nextitem; i++) {
2682 if (! bcmp(eh->ether_shost , sc->wi_sigcache[i].macsrc, 6 )) {
2685 * so we already have this entry,
2693 * did we find a matching mac address?
2694 * if yes, then overwrite a previously existing cache entry
2696 if (i < sc->wi_nextitem ) {
2700 * else, have a new address entry,so
2701 * add this new entry,
2702 * if table full, then we need to replace LRU entry
2707 * check for space in cache table
2708 * note: wi_nextitem also holds number of entries
2709 * added in the cache table
2711 if ( sc->wi_nextitem < MAXWICACHE ) {
2712 cache_slot = sc->wi_nextitem;
2714 sc->wi_sigitems = sc->wi_nextitem;
2716 /* no space found, so simply wrap with wrap index
2717 * and "zap" the next entry
2720 if (wrapindex == MAXWICACHE) {
2723 cache_slot = wrapindex++;
2728 * invariant: cache_slot now points at some slot
2731 if (cache_slot < 0 || cache_slot >= MAXWICACHE) {
2732 log(LOG_ERR, "wi_cache_store, bad index: %d of "
2733 "[0..%d], gross cache error\n",
2734 cache_slot, MAXWICACHE);
2739 * store items in cache
2740 * .ip source address
2745 sc->wi_sigcache[cache_slot].ipsrc = ip->ip_src.s_addr;
2746 bcopy( eh->ether_shost, sc->wi_sigcache[cache_slot].macsrc, 6);
2748 sig = (rx_quality >> 8) & 0xFF;
2749 noise = rx_quality & 0xFF;
2750 sc->wi_sigcache[cache_slot].signal = sig - 149;
2751 sc->wi_sigcache[cache_slot].noise = noise - 149;
2752 sc->wi_sigcache[cache_slot].quality = sig - noise;
2759 wi_get_cur_ssid(sc, ssid, len)
2760 struct wi_softc *sc;
2767 wreq.wi_len = WI_MAX_DATALEN;
2768 switch (sc->wi_ptype) {
2769 case WI_PORTTYPE_AP:
2770 *len = IEEE80211_NWID_LEN;
2771 bcopy(sc->wi_net_name, ssid, IEEE80211_NWID_LEN);
2773 case WI_PORTTYPE_ADHOC:
2774 wreq.wi_type = WI_RID_CURRENT_SSID;
2775 error = wi_read_record(sc, (struct wi_ltv_gen *)&wreq);
2778 if (wreq.wi_val[0] > IEEE80211_NWID_LEN) {
2782 *len = wreq.wi_val[0];
2783 bcopy(&wreq.wi_val[1], ssid, IEEE80211_NWID_LEN);
2785 case WI_PORTTYPE_BSS:
2786 wreq.wi_type = WI_RID_COMMQUAL;
2787 error = wi_read_record(sc, (struct wi_ltv_gen *)&wreq);
2790 if (wreq.wi_val[0] != 0) /* associated */ {
2791 wreq.wi_type = WI_RID_CURRENT_SSID;
2792 wreq.wi_len = WI_MAX_DATALEN;
2793 error = wi_read_record(sc, (struct wi_ltv_gen *)&wreq);
2796 if (wreq.wi_val[0] > IEEE80211_NWID_LEN) {
2800 *len = wreq.wi_val[0];
2801 bcopy(&wreq.wi_val[1], ssid, IEEE80211_NWID_LEN);
2803 *len = IEEE80211_NWID_LEN;
2804 bcopy(sc->wi_net_name, ssid, IEEE80211_NWID_LEN);
2816 wi_media_change(ifp)
2819 struct wi_softc *sc = ifp->if_softc;
2820 int otype = sc->wi_ptype;
2821 int orate = sc->wi_tx_rate;
2822 int ocreate_ibss = sc->wi_create_ibss;
2824 if ((sc->ifmedia.ifm_cur->ifm_media & IFM_IEEE80211_HOSTAP) &&
2825 sc->sc_firmware_type != WI_INTERSIL)
2828 sc->wi_create_ibss = 0;
2830 switch (sc->ifmedia.ifm_cur->ifm_media & IFM_OMASK) {
2832 sc->wi_ptype = WI_PORTTYPE_BSS;
2834 case IFM_IEEE80211_ADHOC:
2835 sc->wi_ptype = WI_PORTTYPE_ADHOC;
2837 case IFM_IEEE80211_HOSTAP:
2838 sc->wi_ptype = WI_PORTTYPE_AP;
2840 case IFM_IEEE80211_IBSSMASTER:
2841 case IFM_IEEE80211_IBSSMASTER|IFM_IEEE80211_IBSS:
2842 if (!(sc->wi_flags & WI_FLAGS_HAS_CREATE_IBSS))
2844 sc->wi_create_ibss = 1;
2846 case IFM_IEEE80211_IBSS:
2847 sc->wi_ptype = WI_PORTTYPE_IBSS;
2850 /* Invalid combination. */
2854 switch (IFM_SUBTYPE(sc->ifmedia.ifm_cur->ifm_media)) {
2855 case IFM_IEEE80211_DS1:
2858 case IFM_IEEE80211_DS2:
2861 case IFM_IEEE80211_DS5:
2864 case IFM_IEEE80211_DS11:
2865 sc->wi_tx_rate = 11;
2872 if (ocreate_ibss != sc->wi_create_ibss || otype != sc->wi_ptype ||
2873 orate != sc->wi_tx_rate)
2880 wi_media_status(ifp, imr)
2882 struct ifmediareq *imr;
2885 struct wi_softc *sc = ifp->if_softc;
2887 if (sc->wi_tx_rate == 3) {
2888 imr->ifm_active = IFM_IEEE80211|IFM_AUTO;
2889 if (sc->wi_ptype == WI_PORTTYPE_ADHOC)
2890 imr->ifm_active |= IFM_IEEE80211_ADHOC;
2891 else if (sc->wi_ptype == WI_PORTTYPE_AP)
2892 imr->ifm_active |= IFM_IEEE80211_HOSTAP;
2893 else if (sc->wi_ptype == WI_PORTTYPE_IBSS) {
2894 if (sc->wi_create_ibss)
2895 imr->ifm_active |= IFM_IEEE80211_IBSSMASTER;
2897 imr->ifm_active |= IFM_IEEE80211_IBSS;
2899 wreq.wi_type = WI_RID_CUR_TX_RATE;
2900 wreq.wi_len = WI_MAX_DATALEN;
2901 if (wi_read_record(sc, (struct wi_ltv_gen *)&wreq) == 0) {
2902 switch(wreq.wi_val[0]) {
2904 imr->ifm_active |= IFM_IEEE80211_DS1;
2907 imr->ifm_active |= IFM_IEEE80211_DS2;
2910 imr->ifm_active |= IFM_IEEE80211_DS5;
2913 imr->ifm_active |= IFM_IEEE80211_DS11;
2918 imr->ifm_active = sc->ifmedia.ifm_cur->ifm_media;
2921 imr->ifm_status = IFM_AVALID;
2922 if (sc->wi_ptype == WI_PORTTYPE_ADHOC ||
2923 sc->wi_ptype == WI_PORTTYPE_IBSS)
2925 * XXX: It would be nice if we could give some actually
2926 * useful status like whether we joined another IBSS or
2927 * created one ourselves.
2929 imr->ifm_status |= IFM_ACTIVE;
2930 else if (sc->wi_ptype == WI_PORTTYPE_AP)
2931 imr->ifm_status |= IFM_ACTIVE;
2933 wreq.wi_type = WI_RID_COMMQUAL;
2934 wreq.wi_len = WI_MAX_DATALEN;
2935 if (wi_read_record(sc, (struct wi_ltv_gen *)&wreq) == 0 &&
2936 wreq.wi_val[0] != 0)
2937 imr->ifm_status |= IFM_ACTIVE;
2942 wi_get_debug(sc, wreq)
2943 struct wi_softc *sc;
2944 struct wi_req *wreq;
2950 switch (wreq->wi_type) {
2951 case WI_DEBUG_SLEEP:
2953 wreq->wi_val[0] = sc->wi_debug.wi_sleep;
2955 case WI_DEBUG_DELAYSUPP:
2957 wreq->wi_val[0] = sc->wi_debug.wi_delaysupp;
2959 case WI_DEBUG_TXSUPP:
2961 wreq->wi_val[0] = sc->wi_debug.wi_txsupp;
2963 case WI_DEBUG_MONITOR:
2965 wreq->wi_val[0] = sc->wi_debug.wi_monitor;
2967 case WI_DEBUG_LEDTEST:
2969 wreq->wi_val[0] = sc->wi_debug.wi_ledtest;
2970 wreq->wi_val[1] = sc->wi_debug.wi_ledtest_param0;
2971 wreq->wi_val[2] = sc->wi_debug.wi_ledtest_param1;
2973 case WI_DEBUG_CONTTX:
2975 wreq->wi_val[0] = sc->wi_debug.wi_conttx;
2976 wreq->wi_val[1] = sc->wi_debug.wi_conttx_param0;
2978 case WI_DEBUG_CONTRX:
2980 wreq->wi_val[0] = sc->wi_debug.wi_contrx;
2982 case WI_DEBUG_SIGSTATE:
2984 wreq->wi_val[0] = sc->wi_debug.wi_sigstate;
2985 wreq->wi_val[1] = sc->wi_debug.wi_sigstate_param0;
2987 case WI_DEBUG_CONFBITS:
2989 wreq->wi_val[0] = sc->wi_debug.wi_confbits;
2990 wreq->wi_val[1] = sc->wi_debug.wi_confbits_param0;
3001 wi_set_debug(sc, wreq)
3002 struct wi_softc *sc;
3003 struct wi_req *wreq;
3006 u_int16_t cmd, param0 = 0, param1 = 0;
3008 switch (wreq->wi_type) {
3009 case WI_DEBUG_RESET:
3011 case WI_DEBUG_CALENABLE:
3013 case WI_DEBUG_SLEEP:
3014 sc->wi_debug.wi_sleep = 1;
3017 sc->wi_debug.wi_sleep = 0;
3020 param0 = wreq->wi_val[0];
3022 case WI_DEBUG_DELAYSUPP:
3023 sc->wi_debug.wi_delaysupp = 1;
3025 case WI_DEBUG_TXSUPP:
3026 sc->wi_debug.wi_txsupp = 1;
3028 case WI_DEBUG_MONITOR:
3029 sc->wi_debug.wi_monitor = 1;
3031 case WI_DEBUG_LEDTEST:
3032 param0 = wreq->wi_val[0];
3033 param1 = wreq->wi_val[1];
3034 sc->wi_debug.wi_ledtest = 1;
3035 sc->wi_debug.wi_ledtest_param0 = param0;
3036 sc->wi_debug.wi_ledtest_param1 = param1;
3038 case WI_DEBUG_CONTTX:
3039 param0 = wreq->wi_val[0];
3040 sc->wi_debug.wi_conttx = 1;
3041 sc->wi_debug.wi_conttx_param0 = param0;
3043 case WI_DEBUG_STOPTEST:
3044 sc->wi_debug.wi_delaysupp = 0;
3045 sc->wi_debug.wi_txsupp = 0;
3046 sc->wi_debug.wi_monitor = 0;
3047 sc->wi_debug.wi_ledtest = 0;
3048 sc->wi_debug.wi_ledtest_param0 = 0;
3049 sc->wi_debug.wi_ledtest_param1 = 0;
3050 sc->wi_debug.wi_conttx = 0;
3051 sc->wi_debug.wi_conttx_param0 = 0;
3052 sc->wi_debug.wi_contrx = 0;
3053 sc->wi_debug.wi_sigstate = 0;
3054 sc->wi_debug.wi_sigstate_param0 = 0;
3056 case WI_DEBUG_CONTRX:
3057 sc->wi_debug.wi_contrx = 1;
3059 case WI_DEBUG_SIGSTATE:
3060 param0 = wreq->wi_val[0];
3061 sc->wi_debug.wi_sigstate = 1;
3062 sc->wi_debug.wi_sigstate_param0 = param0;
3064 case WI_DEBUG_CONFBITS:
3065 param0 = wreq->wi_val[0];
3066 param1 = wreq->wi_val[1];
3067 sc->wi_debug.wi_confbits = param0;
3068 sc->wi_debug.wi_confbits_param0 = param1;
3078 cmd = WI_CMD_DEBUG | (wreq->wi_type << 8);
3079 error = wi_cmd(sc, cmd, param0, param1, 0);