wl1271: Add config structure for TX path parameters
[linux-2.6.git] / drivers / net / wireless / wl12xx / wl1271_cmd.c
1 /*
2  * This file is part of wl1271
3  *
4  * Copyright (C) 2009 Nokia Corporation
5  *
6  * Contact: Luciano Coelho <luciano.coelho@nokia.com>
7  *
8  * This program is free software; you can redistribute it and/or
9  * modify it under the terms of the GNU General Public License
10  * version 2 as published by the Free Software Foundation.
11  *
12  * This program is distributed in the hope that it will be useful, but
13  * WITHOUT ANY WARRANTY; without even the implied warranty of
14  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
15  * General Public License for more details.
16  *
17  * You should have received a copy of the GNU General Public License
18  * along with this program; if not, write to the Free Software
19  * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
20  * 02110-1301 USA
21  *
22  */
23
24 #include <linux/module.h>
25 #include <linux/platform_device.h>
26 #include <linux/crc7.h>
27 #include <linux/spi/spi.h>
28 #include <linux/etherdevice.h>
29
30 #include "wl1271.h"
31 #include "wl1271_reg.h"
32 #include "wl1271_spi.h"
33 #include "wl1271_acx.h"
34 #include "wl12xx_80211.h"
35 #include "wl1271_cmd.h"
36
37 /*
38  * send command to firmware
39  *
40  * @wl: wl struct
41  * @id: command id
42  * @buf: buffer containing the command, must work with dma
43  * @len: length of the buffer
44  */
45 int wl1271_cmd_send(struct wl1271 *wl, u16 id, void *buf, size_t len)
46 {
47         struct wl1271_cmd_header *cmd;
48         unsigned long timeout;
49         u32 intr;
50         int ret = 0;
51
52         cmd = buf;
53         cmd->id = id;
54         cmd->status = 0;
55
56         WARN_ON(len % 4 != 0);
57
58         wl1271_spi_write(wl, wl->cmd_box_addr, buf, len, false);
59
60         wl1271_spi_write32(wl, ACX_REG_INTERRUPT_TRIG, INTR_TRIG_CMD);
61
62         timeout = jiffies + msecs_to_jiffies(WL1271_COMMAND_TIMEOUT);
63
64         intr = wl1271_spi_read32(wl, ACX_REG_INTERRUPT_NO_CLEAR);
65         while (!(intr & WL1271_ACX_INTR_CMD_COMPLETE)) {
66                 if (time_after(jiffies, timeout)) {
67                         wl1271_error("command complete timeout");
68                         ret = -ETIMEDOUT;
69                         goto out;
70                 }
71
72                 msleep(1);
73
74                 intr = wl1271_spi_read32(wl, ACX_REG_INTERRUPT_NO_CLEAR);
75         }
76
77         wl1271_spi_write32(wl, ACX_REG_INTERRUPT_ACK,
78                            WL1271_ACX_INTR_CMD_COMPLETE);
79
80 out:
81         return ret;
82 }
83
84 int wl1271_cmd_cal_channel_tune(struct wl1271 *wl)
85 {
86         struct wl1271_cmd_cal_channel_tune *cmd;
87         int ret = 0;
88
89         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
90         if (!cmd)
91                 return -ENOMEM;
92
93         cmd->test.id = TEST_CMD_CHANNEL_TUNE;
94
95         cmd->band = WL1271_CHANNEL_TUNE_BAND_2_4;
96         /* set up any channel, 7 is in the middle of the range */
97         cmd->channel = 7;
98
99         ret = wl1271_cmd_test(wl, cmd, sizeof(*cmd), 0);
100         if (ret < 0)
101                 wl1271_warning("TEST_CMD_CHANNEL_TUNE failed");
102
103         kfree(cmd);
104         return ret;
105 }
106
107 int wl1271_cmd_cal_update_ref_point(struct wl1271 *wl)
108 {
109         struct wl1271_cmd_cal_update_ref_point *cmd;
110         int ret = 0;
111
112         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
113         if (!cmd)
114                 return -ENOMEM;
115
116         cmd->test.id = TEST_CMD_UPDATE_PD_REFERENCE_POINT;
117
118         /* FIXME: still waiting for the correct values */
119         cmd->ref_power    = 0;
120         cmd->ref_detector = 0;
121
122         cmd->sub_band     = WL1271_PD_REFERENCE_POINT_BAND_B_G;
123
124         ret = wl1271_cmd_test(wl, cmd, sizeof(*cmd), 0);
125         if (ret < 0)
126                 wl1271_warning("TEST_CMD_UPDATE_PD_REFERENCE_POINT failed");
127
128         kfree(cmd);
129         return ret;
130 }
131
132 int wl1271_cmd_cal_p2g(struct wl1271 *wl)
133 {
134         struct wl1271_cmd_cal_p2g *cmd;
135         int ret = 0;
136
137         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
138         if (!cmd)
139                 return -ENOMEM;
140
141         cmd->test.id = TEST_CMD_P2G_CAL;
142
143         cmd->sub_band_mask = WL1271_CAL_P2G_BAND_B_G;
144
145         ret = wl1271_cmd_test(wl, cmd, sizeof(*cmd), 0);
146         if (ret < 0)
147                 wl1271_warning("TEST_CMD_P2G_CAL failed");
148
149         kfree(cmd);
150         return ret;
151 }
152
153 int wl1271_cmd_cal(struct wl1271 *wl)
154 {
155         /*
156          * FIXME: we must make sure that we're not sleeping when calibration
157          * is done
158          */
159         int ret;
160
161         wl1271_notice("performing tx calibration");
162
163         ret = wl1271_cmd_cal_channel_tune(wl);
164         if (ret < 0)
165                 return ret;
166
167         ret = wl1271_cmd_cal_update_ref_point(wl);
168         if (ret < 0)
169                 return ret;
170
171         ret = wl1271_cmd_cal_p2g(wl);
172         if (ret < 0)
173                 return ret;
174
175         return ret;
176 }
177
178 int wl1271_cmd_join(struct wl1271 *wl)
179 {
180         static bool do_cal = true;
181         struct wl1271_cmd_join *join;
182         int ret, i;
183         u8 *bssid;
184
185         /* FIXME: remove when we get calibration from the factory */
186         if (do_cal) {
187                 ret = wl1271_cmd_cal(wl);
188                 if (ret < 0)
189                         wl1271_warning("couldn't calibrate");
190                 else
191                         do_cal = false;
192         }
193
194         /* FIXME: This is a workaround, because with the current stack, we
195          * cannot know when we have disassociated.  So, if we have already
196          * joined, we disconnect before joining again. */
197         if (wl->joined) {
198                 ret = wl1271_cmd_disconnect(wl);
199                 if (ret < 0) {
200                         wl1271_error("failed to disconnect before rejoining");
201                         goto out;
202                 }
203
204                 wl->joined = false;
205         }
206
207         join = kzalloc(sizeof(*join), GFP_KERNEL);
208         if (!join) {
209                 ret = -ENOMEM;
210                 goto out;
211         }
212
213         wl1271_debug(DEBUG_CMD, "cmd join");
214
215         /* Reverse order BSSID */
216         bssid = (u8 *) &join->bssid_lsb;
217         for (i = 0; i < ETH_ALEN; i++)
218                 bssid[i] = wl->bssid[ETH_ALEN - i - 1];
219
220         join->rx_config_options = wl->rx_config;
221         join->rx_filter_options = wl->rx_filter;
222
223         /*
224          * FIXME: disable temporarily all filters because after commit
225          * 9cef8737 "mac80211: fix managed mode BSSID handling" broke
226          * association. The filter logic needs to be implemented properly
227          * and once that is done, this hack can be removed.
228          */
229         join->rx_config_options = 0;
230         join->rx_filter_options = WL1271_DEFAULT_RX_FILTER;
231
232         join->basic_rate_set = CONF_HW_BIT_RATE_1MBPS | CONF_HW_BIT_RATE_2MBPS |
233                 CONF_HW_BIT_RATE_5_5MBPS | CONF_HW_BIT_RATE_11MBPS;
234
235         join->beacon_interval = WL1271_DEFAULT_BEACON_INT;
236         join->dtim_interval = WL1271_DEFAULT_DTIM_PERIOD;
237         join->bss_type = wl->bss_type;
238         join->channel = wl->channel;
239         join->ssid_len = wl->ssid_len;
240         memcpy(join->ssid, wl->ssid, wl->ssid_len);
241         join->ctrl = WL1271_JOIN_CMD_CTRL_TX_FLUSH;
242
243         /* increment the session counter */
244         wl->session_counter++;
245         if (wl->session_counter >= SESSION_COUNTER_MAX)
246                 wl->session_counter = 0;
247
248         join->ctrl |= wl->session_counter << WL1271_JOIN_CMD_TX_SESSION_OFFSET;
249
250         /* reset TX security counters */
251         wl->tx_security_last_seq = 0;
252         wl->tx_security_seq_16 = 0;
253         wl->tx_security_seq_32 = 0;
254
255         ret = wl1271_cmd_send(wl, CMD_START_JOIN, join, sizeof(*join));
256         if (ret < 0) {
257                 wl1271_error("failed to initiate cmd join");
258                 goto out_free;
259         }
260
261         wl->joined = true;
262
263         /*
264          * ugly hack: we should wait for JOIN_EVENT_COMPLETE_ID but to
265          * simplify locking we just sleep instead, for now
266          */
267         msleep(10);
268
269 out_free:
270         kfree(join);
271
272 out:
273         return ret;
274 }
275
276 /**
277  * send test command to firmware
278  *
279  * @wl: wl struct
280  * @buf: buffer containing the command, with all headers, must work with dma
281  * @len: length of the buffer
282  * @answer: is answer needed
283  */
284 int wl1271_cmd_test(struct wl1271 *wl, void *buf, size_t buf_len, u8 answer)
285 {
286         int ret;
287
288         wl1271_debug(DEBUG_CMD, "cmd test");
289
290         ret = wl1271_cmd_send(wl, CMD_TEST, buf, buf_len);
291
292         if (ret < 0) {
293                 wl1271_warning("TEST command failed");
294                 return ret;
295         }
296
297         if (answer) {
298                 struct wl1271_command *cmd_answer;
299
300                 /*
301                  * The test command got in, we can read the answer.
302                  * The answer would be a wl1271_command, where the
303                  * parameter array contains the actual answer.
304                  */
305                 wl1271_spi_read(wl, wl->cmd_box_addr, buf, buf_len, false);
306
307                 cmd_answer = buf;
308
309                 if (cmd_answer->header.status != CMD_STATUS_SUCCESS)
310                         wl1271_error("TEST command answer error: %d",
311                                      cmd_answer->header.status);
312         }
313
314         return 0;
315 }
316
317 /**
318  * read acx from firmware
319  *
320  * @wl: wl struct
321  * @id: acx id
322  * @buf: buffer for the response, including all headers, must work with dma
323  * @len: lenght of buf
324  */
325 int wl1271_cmd_interrogate(struct wl1271 *wl, u16 id, void *buf, size_t len)
326 {
327         struct acx_header *acx = buf;
328         int ret;
329
330         wl1271_debug(DEBUG_CMD, "cmd interrogate");
331
332         acx->id = id;
333
334         /* payload length, does not include any headers */
335         acx->len = len - sizeof(*acx);
336
337         ret = wl1271_cmd_send(wl, CMD_INTERROGATE, acx, sizeof(*acx));
338         if (ret < 0) {
339                 wl1271_error("INTERROGATE command failed");
340                 goto out;
341         }
342
343         /* the interrogate command got in, we can read the answer */
344         wl1271_spi_read(wl, wl->cmd_box_addr, buf, len, false);
345
346         acx = buf;
347         if (acx->cmd.status != CMD_STATUS_SUCCESS)
348                 wl1271_error("INTERROGATE command error: %d",
349                              acx->cmd.status);
350
351 out:
352         return ret;
353 }
354
355 /**
356  * write acx value to firmware
357  *
358  * @wl: wl struct
359  * @id: acx id
360  * @buf: buffer containing acx, including all headers, must work with dma
361  * @len: length of buf
362  */
363 int wl1271_cmd_configure(struct wl1271 *wl, u16 id, void *buf, size_t len)
364 {
365         struct acx_header *acx = buf;
366         int ret;
367
368         wl1271_debug(DEBUG_CMD, "cmd configure");
369
370         acx->id = id;
371
372         /* payload length, does not include any headers */
373         acx->len = len - sizeof(*acx);
374
375         ret = wl1271_cmd_send(wl, CMD_CONFIGURE, acx, len);
376         if (ret < 0) {
377                 wl1271_warning("CONFIGURE command NOK");
378                 return ret;
379         }
380
381         return 0;
382 }
383
384 int wl1271_cmd_data_path(struct wl1271 *wl, u8 channel, bool enable)
385 {
386         struct cmd_enabledisable_path *cmd;
387         int ret;
388         u16 cmd_rx, cmd_tx;
389
390         wl1271_debug(DEBUG_CMD, "cmd data path");
391
392         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
393         if (!cmd) {
394                 ret = -ENOMEM;
395                 goto out;
396         }
397
398         cmd->channel = channel;
399
400         if (enable) {
401                 cmd_rx = CMD_ENABLE_RX;
402                 cmd_tx = CMD_ENABLE_TX;
403         } else {
404                 cmd_rx = CMD_DISABLE_RX;
405                 cmd_tx = CMD_DISABLE_TX;
406         }
407
408         ret = wl1271_cmd_send(wl, cmd_rx, cmd, sizeof(*cmd));
409         if (ret < 0) {
410                 wl1271_error("rx %s cmd for channel %d failed",
411                              enable ? "start" : "stop", channel);
412                 goto out;
413         }
414
415         wl1271_debug(DEBUG_BOOT, "rx %s cmd channel %d",
416                      enable ? "start" : "stop", channel);
417
418         ret = wl1271_cmd_send(wl, cmd_tx, cmd, sizeof(*cmd));
419         if (ret < 0) {
420                 wl1271_error("tx %s cmd for channel %d failed",
421                              enable ? "start" : "stop", channel);
422                 return ret;
423         }
424
425         wl1271_debug(DEBUG_BOOT, "tx %s cmd channel %d",
426                      enable ? "start" : "stop", channel);
427
428 out:
429         kfree(cmd);
430         return ret;
431 }
432
433 int wl1271_cmd_ps_mode(struct wl1271 *wl, u8 ps_mode)
434 {
435         struct wl1271_cmd_ps_params *ps_params = NULL;
436         int ret = 0;
437
438         /* FIXME: this should be in ps.c */
439         ret = wl1271_acx_wake_up_conditions(wl, WAKE_UP_EVENT_DTIM_BITMAP,
440                                             wl->listen_int);
441         if (ret < 0) {
442                 wl1271_error("couldn't set wake up conditions");
443                 goto out;
444         }
445
446         wl1271_debug(DEBUG_CMD, "cmd set ps mode");
447
448         ps_params = kzalloc(sizeof(*ps_params), GFP_KERNEL);
449         if (!ps_params) {
450                 ret = -ENOMEM;
451                 goto out;
452         }
453
454         ps_params->ps_mode = ps_mode;
455         ps_params->send_null_data = 1;
456         ps_params->retries = 5;
457         ps_params->hang_over_period = 128;
458         ps_params->null_data_rate = 1; /* 1 Mbps */
459
460         ret = wl1271_cmd_send(wl, CMD_SET_PS_MODE, ps_params,
461                               sizeof(*ps_params));
462         if (ret < 0) {
463                 wl1271_error("cmd set_ps_mode failed");
464                 goto out;
465         }
466
467 out:
468         kfree(ps_params);
469         return ret;
470 }
471
472 int wl1271_cmd_read_memory(struct wl1271 *wl, u32 addr, void *answer,
473                            size_t len)
474 {
475         struct cmd_read_write_memory *cmd;
476         int ret = 0;
477
478         wl1271_debug(DEBUG_CMD, "cmd read memory");
479
480         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
481         if (!cmd) {
482                 ret = -ENOMEM;
483                 goto out;
484         }
485
486         WARN_ON(len > MAX_READ_SIZE);
487         len = min_t(size_t, len, MAX_READ_SIZE);
488
489         cmd->addr = addr;
490         cmd->size = len;
491
492         ret = wl1271_cmd_send(wl, CMD_READ_MEMORY, cmd, sizeof(*cmd));
493         if (ret < 0) {
494                 wl1271_error("read memory command failed: %d", ret);
495                 goto out;
496         }
497
498         /* the read command got in, we can now read the answer */
499         wl1271_spi_read(wl, wl->cmd_box_addr, cmd, sizeof(*cmd), false);
500
501         if (cmd->header.status != CMD_STATUS_SUCCESS)
502                 wl1271_error("error in read command result: %d",
503                              cmd->header.status);
504
505         memcpy(answer, cmd->value, len);
506
507 out:
508         kfree(cmd);
509         return ret;
510 }
511
512 int wl1271_cmd_scan(struct wl1271 *wl, u8 *ssid, size_t len,
513                     u8 active_scan, u8 high_prio, u8 num_channels,
514                     u8 probe_requests)
515 {
516
517         struct wl1271_cmd_trigger_scan_to *trigger = NULL;
518         struct wl1271_cmd_scan *params = NULL;
519         int i, ret;
520         u16 scan_options = 0;
521
522         if (wl->scanning)
523                 return -EINVAL;
524
525         params = kzalloc(sizeof(*params), GFP_KERNEL);
526         if (!params)
527                 return -ENOMEM;
528
529         params->params.rx_config_options = cpu_to_le32(CFG_RX_ALL_GOOD);
530         params->params.rx_filter_options =
531                 cpu_to_le32(CFG_RX_PRSP_EN | CFG_RX_MGMT_EN | CFG_RX_BCN_EN);
532
533         if (!active_scan)
534                 scan_options |= WL1271_SCAN_OPT_PASSIVE;
535         if (high_prio)
536                 scan_options |= WL1271_SCAN_OPT_PRIORITY_HIGH;
537         params->params.scan_options = scan_options;
538
539         params->params.num_channels = num_channels;
540         params->params.num_probe_requests = probe_requests;
541         params->params.tx_rate = cpu_to_le32(CONF_HW_BIT_RATE_2MBPS);
542         params->params.tid_trigger = 0;
543         params->params.scan_tag = WL1271_SCAN_DEFAULT_TAG;
544
545         for (i = 0; i < num_channels; i++) {
546                 params->channels[i].min_duration =
547                         cpu_to_le32(WL1271_SCAN_CHAN_MIN_DURATION);
548                 params->channels[i].max_duration =
549                         cpu_to_le32(WL1271_SCAN_CHAN_MAX_DURATION);
550                 memset(&params->channels[i].bssid_lsb, 0xff, 4);
551                 memset(&params->channels[i].bssid_msb, 0xff, 2);
552                 params->channels[i].early_termination = 0;
553                 params->channels[i].tx_power_att = WL1271_SCAN_CURRENT_TX_PWR;
554                 params->channels[i].channel = i + 1;
555         }
556
557         if (len && ssid) {
558                 params->params.ssid_len = len;
559                 memcpy(params->params.ssid, ssid, len);
560         }
561
562         ret = wl1271_cmd_build_probe_req(wl, ssid, len);
563         if (ret < 0) {
564                 wl1271_error("PROBE request template failed");
565                 goto out;
566         }
567
568         trigger = kzalloc(sizeof(*trigger), GFP_KERNEL);
569         if (!trigger) {
570                 ret = -ENOMEM;
571                 goto out;
572         }
573
574         /* disable the timeout */
575         trigger->timeout = 0;
576
577         ret = wl1271_cmd_send(wl, CMD_TRIGGER_SCAN_TO, trigger,
578                               sizeof(*trigger));
579         if (ret < 0) {
580                 wl1271_error("trigger scan to failed for hw scan");
581                 goto out;
582         }
583
584         wl1271_dump(DEBUG_SCAN, "SCAN: ", params, sizeof(*params));
585
586         wl->scanning = true;
587
588         ret = wl1271_cmd_send(wl, CMD_SCAN, params, sizeof(*params));
589         if (ret < 0) {
590                 wl1271_error("SCAN failed");
591                 goto out;
592         }
593
594         wl1271_spi_read(wl, wl->cmd_box_addr, params, sizeof(*params),
595                         false);
596
597         if (params->header.status != CMD_STATUS_SUCCESS) {
598                 wl1271_error("Scan command error: %d",
599                              params->header.status);
600                 wl->scanning = false;
601                 ret = -EIO;
602                 goto out;
603         }
604
605 out:
606         kfree(params);
607         return ret;
608 }
609
610 int wl1271_cmd_template_set(struct wl1271 *wl, u16 template_id,
611                             void *buf, size_t buf_len)
612 {
613         struct wl1271_cmd_template_set *cmd;
614         int ret = 0;
615
616         wl1271_debug(DEBUG_CMD, "cmd template_set %d", template_id);
617
618         WARN_ON(buf_len > WL1271_CMD_TEMPL_MAX_SIZE);
619         buf_len = min_t(size_t, buf_len, WL1271_CMD_TEMPL_MAX_SIZE);
620
621         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
622         if (!cmd) {
623                 ret = -ENOMEM;
624                 goto out;
625         }
626
627         cmd->len = cpu_to_le16(buf_len);
628         cmd->template_type = template_id;
629         cmd->enabled_rates = wl->conf.tx.rc_conf.enabled_rates;
630         cmd->short_retry_limit = wl->conf.tx.rc_conf.short_retry_limit;
631         cmd->long_retry_limit = wl->conf.tx.rc_conf.long_retry_limit;
632
633         if (buf)
634                 memcpy(cmd->template_data, buf, buf_len);
635
636         ret = wl1271_cmd_send(wl, CMD_SET_TEMPLATE, cmd, sizeof(*cmd));
637         if (ret < 0) {
638                 wl1271_warning("cmd set_template failed: %d", ret);
639                 goto out_free;
640         }
641
642 out_free:
643         kfree(cmd);
644
645 out:
646         return ret;
647 }
648
649 static int wl1271_build_basic_rates(char *rates)
650 {
651         u8 index = 0;
652
653         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_1MB;
654         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_2MB;
655         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_5MB;
656         rates[index++] = IEEE80211_BASIC_RATE_MASK | IEEE80211_CCK_RATE_11MB;
657
658         return index;
659 }
660
661 static int wl1271_build_extended_rates(char *rates)
662 {
663         u8 index = 0;
664
665         rates[index++] = IEEE80211_OFDM_RATE_6MB;
666         rates[index++] = IEEE80211_OFDM_RATE_9MB;
667         rates[index++] = IEEE80211_OFDM_RATE_12MB;
668         rates[index++] = IEEE80211_OFDM_RATE_18MB;
669         rates[index++] = IEEE80211_OFDM_RATE_24MB;
670         rates[index++] = IEEE80211_OFDM_RATE_36MB;
671         rates[index++] = IEEE80211_OFDM_RATE_48MB;
672         rates[index++] = IEEE80211_OFDM_RATE_54MB;
673
674         return index;
675 }
676
677 int wl1271_cmd_build_null_data(struct wl1271 *wl)
678 {
679         struct wl12xx_null_data_template template;
680
681         if (!is_zero_ether_addr(wl->bssid)) {
682                 memcpy(template.header.da, wl->bssid, ETH_ALEN);
683                 memcpy(template.header.bssid, wl->bssid, ETH_ALEN);
684         } else {
685                 memset(template.header.da, 0xff, ETH_ALEN);
686                 memset(template.header.bssid, 0xff, ETH_ALEN);
687         }
688
689         memcpy(template.header.sa, wl->mac_addr, ETH_ALEN);
690         template.header.frame_ctl = cpu_to_le16(IEEE80211_FTYPE_DATA |
691                                                 IEEE80211_STYPE_NULLFUNC);
692
693         return wl1271_cmd_template_set(wl, CMD_TEMPL_NULL_DATA, &template,
694                                        sizeof(template));
695
696 }
697
698 int wl1271_cmd_build_ps_poll(struct wl1271 *wl, u16 aid)
699 {
700         struct wl12xx_ps_poll_template template;
701
702         memcpy(template.bssid, wl->bssid, ETH_ALEN);
703         memcpy(template.ta, wl->mac_addr, ETH_ALEN);
704
705         /* aid in PS-Poll has its two MSBs each set to 1 */
706         template.aid = cpu_to_le16(1 << 15 | 1 << 14 | aid);
707
708         template.fc = cpu_to_le16(IEEE80211_FTYPE_CTL | IEEE80211_STYPE_PSPOLL);
709
710         return wl1271_cmd_template_set(wl, CMD_TEMPL_PS_POLL, &template,
711                                        sizeof(template));
712
713 }
714
715 int wl1271_cmd_build_probe_req(struct wl1271 *wl, u8 *ssid, size_t ssid_len)
716 {
717         struct wl12xx_probe_req_template template;
718         struct wl12xx_ie_rates *rates;
719         char *ptr;
720         u16 size;
721
722         ptr = (char *)&template;
723         size = sizeof(struct ieee80211_header);
724
725         memset(template.header.da, 0xff, ETH_ALEN);
726         memset(template.header.bssid, 0xff, ETH_ALEN);
727         memcpy(template.header.sa, wl->mac_addr, ETH_ALEN);
728         template.header.frame_ctl = cpu_to_le16(IEEE80211_STYPE_PROBE_REQ);
729
730         /* IEs */
731         /* SSID */
732         template.ssid.header.id = WLAN_EID_SSID;
733         template.ssid.header.len = ssid_len;
734         if (ssid_len && ssid)
735                 memcpy(template.ssid.ssid, ssid, ssid_len);
736         size += sizeof(struct wl12xx_ie_header) + ssid_len;
737         ptr += size;
738
739         /* Basic Rates */
740         rates = (struct wl12xx_ie_rates *)ptr;
741         rates->header.id = WLAN_EID_SUPP_RATES;
742         rates->header.len = wl1271_build_basic_rates(rates->rates);
743         size += sizeof(struct wl12xx_ie_header) + rates->header.len;
744         ptr += sizeof(struct wl12xx_ie_header) + rates->header.len;
745
746         /* Extended rates */
747         rates = (struct wl12xx_ie_rates *)ptr;
748         rates->header.id = WLAN_EID_EXT_SUPP_RATES;
749         rates->header.len = wl1271_build_extended_rates(rates->rates);
750         size += sizeof(struct wl12xx_ie_header) + rates->header.len;
751
752         wl1271_dump(DEBUG_SCAN, "PROBE REQ: ", &template, size);
753
754         return wl1271_cmd_template_set(wl, CMD_TEMPL_CFG_PROBE_REQ_2_4,
755                                        &template, size);
756 }
757
758 int wl1271_cmd_set_default_wep_key(struct wl1271 *wl, u8 id)
759 {
760         struct wl1271_cmd_set_keys *cmd;
761         int ret = 0;
762
763         wl1271_debug(DEBUG_CMD, "cmd set_default_wep_key %d", id);
764
765         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
766         if (!cmd) {
767                 ret = -ENOMEM;
768                 goto out;
769         }
770
771         cmd->id = id;
772         cmd->key_action = KEY_SET_ID;
773         cmd->key_type = KEY_WEP;
774
775         ret = wl1271_cmd_send(wl, CMD_SET_KEYS, cmd, sizeof(*cmd));
776         if (ret < 0) {
777                 wl1271_warning("cmd set_default_wep_key failed: %d", ret);
778                 goto out;
779         }
780
781 out:
782         kfree(cmd);
783
784         return ret;
785 }
786
787 int wl1271_cmd_set_key(struct wl1271 *wl, u16 action, u8 id, u8 key_type,
788                        u8 key_size, const u8 *key, const u8 *addr,
789                        u32 tx_seq_32, u16 tx_seq_16)
790 {
791         struct wl1271_cmd_set_keys *cmd;
792         int ret = 0;
793
794         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
795         if (!cmd) {
796                 ret = -ENOMEM;
797                 goto out;
798         }
799
800         if (key_type != KEY_WEP)
801                 memcpy(cmd->addr, addr, ETH_ALEN);
802
803         cmd->key_action = action;
804         cmd->key_size = key_size;
805         cmd->key_type = key_type;
806
807         cmd->ac_seq_num16[0] = tx_seq_16;
808         cmd->ac_seq_num32[0] = tx_seq_32;
809
810         /* we have only one SSID profile */
811         cmd->ssid_profile = 0;
812
813         cmd->id = id;
814
815         if (key_type == KEY_TKIP) {
816                 /*
817                  * We get the key in the following form:
818                  * TKIP (16 bytes) - TX MIC (8 bytes) - RX MIC (8 bytes)
819                  * but the target is expecting:
820                  * TKIP - RX MIC - TX MIC
821                  */
822                 memcpy(cmd->key, key, 16);
823                 memcpy(cmd->key + 16, key + 24, 8);
824                 memcpy(cmd->key + 24, key + 16, 8);
825
826         } else {
827                 memcpy(cmd->key, key, key_size);
828         }
829
830         wl1271_dump(DEBUG_CRYPT, "TARGET KEY: ", cmd, sizeof(*cmd));
831
832         ret = wl1271_cmd_send(wl, CMD_SET_KEYS, cmd, sizeof(*cmd));
833         if (ret < 0) {
834                 wl1271_warning("could not set keys");
835                 goto out;
836         }
837
838 out:
839         kfree(cmd);
840
841         return ret;
842 }
843
844 int wl1271_cmd_disconnect(struct wl1271 *wl)
845 {
846         struct wl1271_cmd_disconnect *cmd;
847         int ret = 0;
848
849         wl1271_debug(DEBUG_CMD, "cmd disconnect");
850
851         cmd = kzalloc(sizeof(*cmd), GFP_KERNEL);
852         if (!cmd) {
853                 ret = -ENOMEM;
854                 goto out;
855         }
856
857         cmd->rx_config_options = wl->rx_config;
858         cmd->rx_filter_options = wl->rx_filter;
859         /* disconnect reason is not used in immediate disconnections */
860         cmd->type = DISCONNECT_IMMEDIATE;
861
862         ret = wl1271_cmd_send(wl, CMD_DISCONNECT, cmd, sizeof(*cmd));
863         if (ret < 0) {
864                 wl1271_error("failed to send disconnect command");
865                 goto out_free;
866         }
867
868 out_free:
869         kfree(cmd);
870
871 out:
872         return ret;
873 }