]> git.proxmox.com Git - mirror_ubuntu-zesty-kernel.git/blame - drivers/net/wireless/mwifiex/sta_event.c
brcm80211: fix null pointer access
[mirror_ubuntu-zesty-kernel.git] / drivers / net / wireless / mwifiex / sta_event.c
CommitLineData
5e6e3a92
BZ
1/*
2 * Marvell Wireless LAN device driver: station event handling
3 *
4 * Copyright (C) 2011, Marvell International Ltd.
5 *
6 * This software file (the "File") is distributed by Marvell International
7 * Ltd. under the terms of the GNU General Public License Version 2, June 1991
8 * (the "License"). You may use, redistribute and/or modify this File in
9 * accordance with the terms and conditions of the License, a copy of which
10 * is available by writing to the Free Software Foundation, Inc.,
11 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA or on the
12 * worldwide web at http://www.gnu.org/licenses/old-licenses/gpl-2.0.txt.
13 *
14 * THE FILE IS DISTRIBUTED AS-IS, WITHOUT WARRANTY OF ANY KIND, AND THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE
16 * ARE EXPRESSLY DISCLAIMED. The License provides additional details about
17 * this warranty disclaimer.
18 */
19
20#include "decl.h"
21#include "ioctl.h"
22#include "util.h"
23#include "fw.h"
24#include "main.h"
25#include "wmm.h"
26#include "11n.h"
27
28/*
29 * This function resets the connection state.
30 *
31 * The function is invoked after receiving a disconnect event from firmware,
32 * and performs the following actions -
33 * - Set media status to disconnected
34 * - Clean up Tx and Rx packets
35 * - Resets SNR/NF/RSSI value in driver
36 * - Resets security configurations in driver
37 * - Enables auto data rate
38 * - Saves the previous SSID and BSSID so that they can
39 * be used for re-association, if required
40 * - Erases current SSID and BSSID information
41 * - Sends a disconnect event to upper layers/applications.
42 */
43void
8cc1d523 44mwifiex_reset_connect_state(struct mwifiex_private *priv, u16 reason_code)
5e6e3a92
BZ
45{
46 struct mwifiex_adapter *adapter = priv->adapter;
47
48 if (!priv->media_connected)
49 return;
50
51 dev_dbg(adapter->dev, "info: handles disconnect event\n");
52
53 priv->media_connected = false;
54
55 priv->scan_block = false;
56
57 /* Free Tx and Rx packets, report disconnect to upper layer */
58 mwifiex_clean_txrx(priv);
59
60 /* Reset SNR/NF/RSSI values */
61 priv->data_rssi_last = 0;
62 priv->data_nf_last = 0;
63 priv->data_rssi_avg = 0;
64 priv->data_nf_avg = 0;
65 priv->bcn_rssi_last = 0;
66 priv->bcn_nf_last = 0;
67 priv->bcn_rssi_avg = 0;
68 priv->bcn_nf_avg = 0;
69 priv->rxpd_rate = 0;
70 priv->rxpd_htinfo = 0;
71 priv->sec_info.wpa_enabled = false;
72 priv->sec_info.wpa2_enabled = false;
73 priv->wpa_ie_len = 0;
74
75 priv->sec_info.wapi_enabled = false;
76 priv->wapi_ie_len = 0;
77 priv->sec_info.wapi_key_on = false;
78
2be50b8d 79 priv->sec_info.encryption_mode = 0;
5e6e3a92
BZ
80
81 /* Enable auto data rate */
82 priv->is_data_rate_auto = true;
83 priv->data_rate = 0;
84
eecd8250 85 if (priv->bss_mode == NL80211_IFTYPE_ADHOC) {
5e6e3a92
BZ
86 priv->adhoc_state = ADHOC_IDLE;
87 priv->adhoc_is_link_sensed = false;
88 }
89
90 /*
91 * Memorize the previous SSID and BSSID so
92 * it could be used for re-assoc
93 */
94
95 dev_dbg(adapter->dev, "info: previous SSID=%s, SSID len=%u\n",
500f747c 96 priv->prev_ssid.ssid, priv->prev_ssid.ssid_len);
5e6e3a92
BZ
97
98 dev_dbg(adapter->dev, "info: current SSID=%s, SSID len=%u\n",
500f747c
YAP
99 priv->curr_bss_params.bss_descriptor.ssid.ssid,
100 priv->curr_bss_params.bss_descriptor.ssid.ssid_len);
5e6e3a92
BZ
101
102 memcpy(&priv->prev_ssid,
103 &priv->curr_bss_params.bss_descriptor.ssid,
b9be5f39 104 sizeof(struct cfg80211_ssid));
5e6e3a92
BZ
105
106 memcpy(priv->prev_bssid,
107 priv->curr_bss_params.bss_descriptor.mac_address, ETH_ALEN);
108
109 /* Need to erase the current SSID and BSSID info */
110 memset(&priv->curr_bss_params, 0x00, sizeof(priv->curr_bss_params));
111
112 adapter->tx_lock_flag = false;
113 adapter->pps_uapsd_mode = false;
114
115 if (adapter->num_cmd_timeout && adapter->curr_cmd)
116 return;
117 priv->media_connected = false;
500f747c
YAP
118 dev_dbg(adapter->dev,
119 "info: successfully disconnected from %pM: reason code %d\n",
8cc1d523 120 priv->cfg_bssid, reason_code);
38c9d664 121 if (priv->bss_mode == NL80211_IFTYPE_STATION) {
8cc1d523
AK
122 cfg80211_disconnected(priv->netdev, reason_code, NULL, 0,
123 GFP_KERNEL);
5e6e3a92 124 }
38c9d664
AK
125 memset(priv->cfg_bssid, 0, ETH_ALEN);
126
47411a06 127 mwifiex_stop_net_dev_queue(priv->netdev, adapter);
5e6e3a92
BZ
128 if (netif_carrier_ok(priv->netdev))
129 netif_carrier_off(priv->netdev);
5e6e3a92
BZ
130}
131
132/*
133 * This function handles events generated by firmware.
134 *
135 * This is a generic function and handles all events.
136 *
137 * Event specific routines are called by this function based
138 * upon the generated event cause.
139 *
140 * For the following events, the function just forwards them to upper
141 * layers, optionally recording the change -
142 * - EVENT_LINK_SENSED
143 * - EVENT_MIC_ERR_UNICAST
144 * - EVENT_MIC_ERR_MULTICAST
145 * - EVENT_PORT_RELEASE
146 * - EVENT_RSSI_LOW
147 * - EVENT_SNR_LOW
148 * - EVENT_MAX_FAIL
149 * - EVENT_RSSI_HIGH
150 * - EVENT_SNR_HIGH
151 * - EVENT_DATA_RSSI_LOW
152 * - EVENT_DATA_SNR_LOW
153 * - EVENT_DATA_RSSI_HIGH
154 * - EVENT_DATA_SNR_HIGH
155 * - EVENT_LINK_QUALITY
156 * - EVENT_PRE_BEACON_LOST
157 * - EVENT_IBSS_COALESCED
158 * - EVENT_WEP_ICV_ERR
159 * - EVENT_BW_CHANGE
160 * - EVENT_HOSTWAKE_STAIE
161 *
162 * For the following events, no action is taken -
163 * - EVENT_MIB_CHANGED
164 * - EVENT_INIT_DONE
165 * - EVENT_DUMMY_HOST_WAKEUP_SIGNAL
166 *
167 * Rest of the supported events requires driver handling -
168 * - EVENT_DEAUTHENTICATED
169 * - EVENT_DISASSOCIATED
170 * - EVENT_LINK_LOST
171 * - EVENT_PS_SLEEP
172 * - EVENT_PS_AWAKE
173 * - EVENT_DEEP_SLEEP_AWAKE
174 * - EVENT_HS_ACT_REQ
175 * - EVENT_ADHOC_BCN_LOST
176 * - EVENT_BG_SCAN_REPORT
177 * - EVENT_WMM_STATUS_CHANGE
178 * - EVENT_ADDBA
179 * - EVENT_DELBA
180 * - EVENT_BA_STREAM_TIEMOUT
181 * - EVENT_AMSDU_AGGR_CTRL
182 */
183int mwifiex_process_sta_event(struct mwifiex_private *priv)
184{
185 struct mwifiex_adapter *adapter = priv->adapter;
3d99d987 186 int ret = 0;
5e6e3a92 187 u32 eventcause = adapter->event_cause;
8cc1d523 188 u16 ctrl, reason_code;
5e6e3a92
BZ
189
190 switch (eventcause) {
191 case EVENT_DUMMY_HOST_WAKEUP_SIGNAL:
500f747c
YAP
192 dev_err(adapter->dev,
193 "invalid EVENT: DUMMY_HOST_WAKEUP_SIGNAL, ignore it\n");
5e6e3a92
BZ
194 break;
195 case EVENT_LINK_SENSED:
196 dev_dbg(adapter->dev, "event: LINK_SENSED\n");
197 if (!netif_carrier_ok(priv->netdev))
198 netif_carrier_on(priv->netdev);
47411a06 199 mwifiex_wake_up_net_dev_queue(priv->netdev, adapter);
5e6e3a92
BZ
200 break;
201
202 case EVENT_DEAUTHENTICATED:
203 dev_dbg(adapter->dev, "event: Deauthenticated\n");
204 adapter->dbg.num_event_deauth++;
8cc1d523
AK
205 if (priv->media_connected) {
206 reason_code =
207 le16_to_cpu(*(__le16 *)adapter->event_body);
208 mwifiex_reset_connect_state(priv, reason_code);
209 }
5e6e3a92
BZ
210 break;
211
212 case EVENT_DISASSOCIATED:
213 dev_dbg(adapter->dev, "event: Disassociated\n");
214 adapter->dbg.num_event_disassoc++;
8cc1d523
AK
215 if (priv->media_connected) {
216 reason_code =
217 le16_to_cpu(*(__le16 *)adapter->event_body);
218 mwifiex_reset_connect_state(priv, reason_code);
219 }
5e6e3a92
BZ
220 break;
221
222 case EVENT_LINK_LOST:
223 dev_dbg(adapter->dev, "event: Link lost\n");
224 adapter->dbg.num_event_link_lost++;
8cc1d523
AK
225 if (priv->media_connected) {
226 reason_code =
227 le16_to_cpu(*(__le16 *)adapter->event_body);
228 mwifiex_reset_connect_state(priv, reason_code);
229 }
5e6e3a92
BZ
230 break;
231
232 case EVENT_PS_SLEEP:
233 dev_dbg(adapter->dev, "info: EVENT: SLEEP\n");
234
235 adapter->ps_state = PS_STATE_PRE_SLEEP;
236
237 mwifiex_check_ps_cond(adapter);
238 break;
239
240 case EVENT_PS_AWAKE:
241 dev_dbg(adapter->dev, "info: EVENT: AWAKE\n");
242 if (!adapter->pps_uapsd_mode &&
500f747c 243 priv->media_connected && adapter->sleep_period.period) {
5e6e3a92
BZ
244 adapter->pps_uapsd_mode = true;
245 dev_dbg(adapter->dev,
246 "event: PPS/UAPSD mode activated\n");
247 }
248 adapter->tx_lock_flag = false;
249 if (adapter->pps_uapsd_mode && adapter->gen_null_pkt) {
250 if (mwifiex_check_last_packet_indication(priv)) {
500f747c
YAP
251 if (adapter->data_sent) {
252 adapter->ps_state = PS_STATE_AWAKE;
253 adapter->pm_wakeup_card_req = false;
254 adapter->pm_wakeup_fw_try = false;
255 break;
256 }
257 if (!mwifiex_send_null_packet
258 (priv,
259 MWIFIEX_TxPD_POWER_MGMT_NULL_PACKET |
260 MWIFIEX_TxPD_POWER_MGMT_LAST_PACKET))
5e6e3a92
BZ
261 adapter->ps_state =
262 PS_STATE_SLEEP;
263 return 0;
5e6e3a92
BZ
264 }
265 }
266 adapter->ps_state = PS_STATE_AWAKE;
267 adapter->pm_wakeup_card_req = false;
268 adapter->pm_wakeup_fw_try = false;
269
270 break;
271
272 case EVENT_DEEP_SLEEP_AWAKE:
273 adapter->if_ops.wakeup_complete(adapter);
274 dev_dbg(adapter->dev, "event: DS_AWAKE\n");
275 if (adapter->is_deep_sleep)
276 adapter->is_deep_sleep = false;
277 break;
278
279 case EVENT_HS_ACT_REQ:
280 dev_dbg(adapter->dev, "event: HS_ACT_REQ\n");
600f5d90
AK
281 ret = mwifiex_send_cmd_async(priv,
282 HostCmd_CMD_802_11_HS_CFG_ENH,
283 0, 0, NULL);
5e6e3a92
BZ
284 break;
285
286 case EVENT_MIC_ERR_UNICAST:
287 dev_dbg(adapter->dev, "event: UNICAST MIC ERROR\n");
9c7ff737
AK
288 cfg80211_michael_mic_failure(priv->netdev, priv->cfg_bssid,
289 NL80211_KEYTYPE_PAIRWISE,
290 -1, NULL, GFP_KERNEL);
5e6e3a92
BZ
291 break;
292
293 case EVENT_MIC_ERR_MULTICAST:
294 dev_dbg(adapter->dev, "event: MULTICAST MIC ERROR\n");
9c7ff737
AK
295 cfg80211_michael_mic_failure(priv->netdev, priv->cfg_bssid,
296 NL80211_KEYTYPE_GROUP,
297 -1, NULL, GFP_KERNEL);
5e6e3a92
BZ
298 break;
299 case EVENT_MIB_CHANGED:
300 case EVENT_INIT_DONE:
301 break;
302
303 case EVENT_ADHOC_BCN_LOST:
304 dev_dbg(adapter->dev, "event: ADHOC_BCN_LOST\n");
305 priv->adhoc_is_link_sensed = false;
306 mwifiex_clean_txrx(priv);
47411a06 307 mwifiex_stop_net_dev_queue(priv->netdev, adapter);
5e6e3a92
BZ
308 if (netif_carrier_ok(priv->netdev))
309 netif_carrier_off(priv->netdev);
310 break;
311
312 case EVENT_BG_SCAN_REPORT:
313 dev_dbg(adapter->dev, "event: BGS_REPORT\n");
600f5d90
AK
314 ret = mwifiex_send_cmd_async(priv,
315 HostCmd_CMD_802_11_BG_SCAN_QUERY,
316 HostCmd_ACT_GEN_GET, 0, NULL);
5e6e3a92
BZ
317 break;
318
319 case EVENT_PORT_RELEASE:
320 dev_dbg(adapter->dev, "event: PORT RELEASE\n");
321 break;
322
323 case EVENT_WMM_STATUS_CHANGE:
324 dev_dbg(adapter->dev, "event: WMM status changed\n");
600f5d90
AK
325 ret = mwifiex_send_cmd_async(priv, HostCmd_CMD_WMM_GET_STATUS,
326 0, 0, NULL);
5e6e3a92
BZ
327 break;
328
329 case EVENT_RSSI_LOW:
fa444bf8
AK
330 cfg80211_cqm_rssi_notify(priv->netdev,
331 NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW,
332 GFP_KERNEL);
333 mwifiex_send_cmd_async(priv, HostCmd_CMD_RSSI_INFO,
334 HostCmd_ACT_GEN_GET, 0, NULL);
335 priv->subsc_evt_rssi_state = RSSI_LOW_RECVD;
5e6e3a92
BZ
336 dev_dbg(adapter->dev, "event: Beacon RSSI_LOW\n");
337 break;
338 case EVENT_SNR_LOW:
339 dev_dbg(adapter->dev, "event: Beacon SNR_LOW\n");
340 break;
341 case EVENT_MAX_FAIL:
342 dev_dbg(adapter->dev, "event: MAX_FAIL\n");
343 break;
344 case EVENT_RSSI_HIGH:
fa444bf8
AK
345 cfg80211_cqm_rssi_notify(priv->netdev,
346 NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH,
347 GFP_KERNEL);
348 mwifiex_send_cmd_async(priv, HostCmd_CMD_RSSI_INFO,
349 HostCmd_ACT_GEN_GET, 0, NULL);
350 priv->subsc_evt_rssi_state = RSSI_HIGH_RECVD;
5e6e3a92
BZ
351 dev_dbg(adapter->dev, "event: Beacon RSSI_HIGH\n");
352 break;
353 case EVENT_SNR_HIGH:
354 dev_dbg(adapter->dev, "event: Beacon SNR_HIGH\n");
355 break;
356 case EVENT_DATA_RSSI_LOW:
357 dev_dbg(adapter->dev, "event: Data RSSI_LOW\n");
358 break;
359 case EVENT_DATA_SNR_LOW:
360 dev_dbg(adapter->dev, "event: Data SNR_LOW\n");
361 break;
362 case EVENT_DATA_RSSI_HIGH:
363 dev_dbg(adapter->dev, "event: Data RSSI_HIGH\n");
364 break;
365 case EVENT_DATA_SNR_HIGH:
366 dev_dbg(adapter->dev, "event: Data SNR_HIGH\n");
367 break;
368 case EVENT_LINK_QUALITY:
369 dev_dbg(adapter->dev, "event: Link Quality\n");
370 break;
371 case EVENT_PRE_BEACON_LOST:
372 dev_dbg(adapter->dev, "event: Pre-Beacon Lost\n");
373 break;
374 case EVENT_IBSS_COALESCED:
375 dev_dbg(adapter->dev, "event: IBSS_COALESCED\n");
600f5d90 376 ret = mwifiex_send_cmd_async(priv,
5e6e3a92 377 HostCmd_CMD_802_11_IBSS_COALESCING_STATUS,
600f5d90 378 HostCmd_ACT_GEN_GET, 0, NULL);
5e6e3a92
BZ
379 break;
380 case EVENT_ADDBA:
381 dev_dbg(adapter->dev, "event: ADDBA Request\n");
600f5d90
AK
382 mwifiex_send_cmd_async(priv, HostCmd_CMD_11N_ADDBA_RSP,
383 HostCmd_ACT_GEN_SET, 0,
384 adapter->event_body);
5e6e3a92
BZ
385 break;
386 case EVENT_DELBA:
387 dev_dbg(adapter->dev, "event: DELBA Request\n");
388 mwifiex_11n_delete_ba_stream(priv, adapter->event_body);
389 break;
390 case EVENT_BA_STREAM_TIEMOUT:
391 dev_dbg(adapter->dev, "event: BA Stream timeout\n");
392 mwifiex_11n_ba_stream_timeout(priv,
393 (struct host_cmd_ds_11n_batimeout
394 *)
395 adapter->event_body);
396 break;
397 case EVENT_AMSDU_AGGR_CTRL:
8dd4372e
BZ
398 ctrl = le16_to_cpu(*(__le16 *)adapter->event_body);
399 dev_dbg(adapter->dev, "event: AMSDU_AGGR_CTRL %d\n", ctrl);
400
5e6e3a92 401 adapter->tx_buf_size =
8dd4372e 402 min_t(u16, adapter->curr_tx_buf_size, ctrl);
5e6e3a92 403 dev_dbg(adapter->dev, "event: tx_buf_size %d\n",
500f747c 404 adapter->tx_buf_size);
5e6e3a92
BZ
405 break;
406
407 case EVENT_WEP_ICV_ERR:
408 dev_dbg(adapter->dev, "event: WEP ICV error\n");
409 break;
410
411 case EVENT_BW_CHANGE:
412 dev_dbg(adapter->dev, "event: BW Change\n");
413 break;
414
415 case EVENT_HOSTWAKE_STAIE:
416 dev_dbg(adapter->dev, "event: HOSTWAKE_STAIE %d\n", eventcause);
417 break;
e568634a 418
eab1c76b
SP
419 case EVENT_REMAIN_ON_CHAN_EXPIRED:
420 dev_dbg(adapter->dev, "event: Remain on channel expired\n");
421 cfg80211_remain_on_channel_expired(priv->wdev,
422 priv->roc_cfg.cookie,
423 &priv->roc_cfg.chan,
eab1c76b
SP
424 GFP_ATOMIC);
425
426 memset(&priv->roc_cfg, 0x00, sizeof(struct mwifiex_roc_cfg));
427
428 break;
429
5e6e3a92
BZ
430 default:
431 dev_dbg(adapter->dev, "event: unknown event id: %#x\n",
500f747c 432 eventcause);
5e6e3a92
BZ
433 break;
434 }
435
436 return ret;
437}