]> err.no Git - linux-2.6/blob - drivers/net/wireless/iwlwifi/iwl-rx.c
iwlwifi: setup compressed BA handler
[linux-2.6] / drivers / net / wireless / iwlwifi / iwl-rx.c
1 /******************************************************************************
2  *
3  * Copyright(c) 2003 - 2008 Intel Corporation. All rights reserved.
4  *
5  * Portions of this file are derived from the ipw3945 project, as well
6  * as portions of the ieee80211 subsystem header files.
7  *
8  * This program is free software; you can redistribute it and/or modify it
9  * under the terms of version 2 of the GNU General Public License as
10  * published by the Free Software Foundation.
11  *
12  * This program is distributed in the hope that it will be useful, but WITHOUT
13  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
14  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License for
15  * more details.
16  *
17  * You should have received a copy of the GNU General Public License along with
18  * this program; if not, write to the Free Software Foundation, Inc.,
19  * 51 Franklin Street, Fifth Floor, Boston, MA 02110, USA
20  *
21  * The full GNU General Public License is included in this distribution in the
22  * file called LICENSE.
23  *
24  * Contact Information:
25  * James P. Ketrenos <ipw2100-admin@linux.intel.com>
26  * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
27  *
28  *****************************************************************************/
29
30 #include <linux/etherdevice.h>
31 #include <net/mac80211.h>
32 #include "iwl-eeprom.h"
33 #include "iwl-dev.h"
34 #include "iwl-core.h"
35 #include "iwl-sta.h"
36 #include "iwl-io.h"
37 #include "iwl-calib.h"
38 #include "iwl-helpers.h"
39 /************************** RX-FUNCTIONS ****************************/
40 /*
41  * Rx theory of operation
42  *
43  * Driver allocates a circular buffer of Receive Buffer Descriptors (RBDs),
44  * each of which point to Receive Buffers to be filled by the NIC.  These get
45  * used not only for Rx frames, but for any command response or notification
46  * from the NIC.  The driver and NIC manage the Rx buffers by means
47  * of indexes into the circular buffer.
48  *
49  * Rx Queue Indexes
50  * The host/firmware share two index registers for managing the Rx buffers.
51  *
52  * The READ index maps to the first position that the firmware may be writing
53  * to -- the driver can read up to (but not including) this position and get
54  * good data.
55  * The READ index is managed by the firmware once the card is enabled.
56  *
57  * The WRITE index maps to the last position the driver has read from -- the
58  * position preceding WRITE is the last slot the firmware can place a packet.
59  *
60  * The queue is empty (no good data) if WRITE = READ - 1, and is full if
61  * WRITE = READ.
62  *
63  * During initialization, the host sets up the READ queue position to the first
64  * INDEX position, and WRITE to the last (READ - 1 wrapped)
65  *
66  * When the firmware places a packet in a buffer, it will advance the READ index
67  * and fire the RX interrupt.  The driver can then query the READ index and
68  * process as many packets as possible, moving the WRITE index forward as it
69  * resets the Rx queue buffers with new memory.
70  *
71  * The management in the driver is as follows:
72  * + A list of pre-allocated SKBs is stored in iwl->rxq->rx_free.  When
73  *   iwl->rxq->free_count drops to or below RX_LOW_WATERMARK, work is scheduled
74  *   to replenish the iwl->rxq->rx_free.
75  * + In iwl_rx_replenish (scheduled) if 'processed' != 'read' then the
76  *   iwl->rxq is replenished and the READ INDEX is updated (updating the
77  *   'processed' and 'read' driver indexes as well)
78  * + A received packet is processed and handed to the kernel network stack,
79  *   detached from the iwl->rxq.  The driver 'processed' index is updated.
80  * + The Host/Firmware iwl->rxq is replenished at tasklet time from the rx_free
81  *   list. If there are no allocated buffers in iwl->rxq->rx_free, the READ
82  *   INDEX is not incremented and iwl->status(RX_STALLED) is set.  If there
83  *   were enough free buffers and RX_STALLED is set it is cleared.
84  *
85  *
86  * Driver sequence:
87  *
88  * iwl_rx_queue_alloc()   Allocates rx_free
89  * iwl_rx_replenish()     Replenishes rx_free list from rx_used, and calls
90  *                            iwl_rx_queue_restock
91  * iwl_rx_queue_restock() Moves available buffers from rx_free into Rx
92  *                            queue, updates firmware pointers, and updates
93  *                            the WRITE index.  If insufficient rx_free buffers
94  *                            are available, schedules iwl_rx_replenish
95  *
96  * -- enable interrupts --
97  * ISR - iwl_rx()         Detach iwl_rx_mem_buffers from pool up to the
98  *                            READ INDEX, detaching the SKB from the pool.
99  *                            Moves the packet buffer from queue to rx_used.
100  *                            Calls iwl_rx_queue_restock to refill any empty
101  *                            slots.
102  * ...
103  *
104  */
105
106 /**
107  * iwl_rx_queue_space - Return number of free slots available in queue.
108  */
109 int iwl_rx_queue_space(const struct iwl_rx_queue *q)
110 {
111         int s = q->read - q->write;
112         if (s <= 0)
113                 s += RX_QUEUE_SIZE;
114         /* keep some buffer to not confuse full and empty queue */
115         s -= 2;
116         if (s < 0)
117                 s = 0;
118         return s;
119 }
120 EXPORT_SYMBOL(iwl_rx_queue_space);
121
122 /**
123  * iwl_rx_queue_update_write_ptr - Update the write pointer for the RX queue
124  */
125 int iwl_rx_queue_update_write_ptr(struct iwl_priv *priv, struct iwl_rx_queue *q)
126 {
127         u32 reg = 0;
128         int ret = 0;
129         unsigned long flags;
130
131         spin_lock_irqsave(&q->lock, flags);
132
133         if (q->need_update == 0)
134                 goto exit_unlock;
135
136         /* If power-saving is in use, make sure device is awake */
137         if (test_bit(STATUS_POWER_PMI, &priv->status)) {
138                 reg = iwl_read32(priv, CSR_UCODE_DRV_GP1);
139
140                 if (reg & CSR_UCODE_DRV_GP1_BIT_MAC_SLEEP) {
141                         iwl_set_bit(priv, CSR_GP_CNTRL,
142                                     CSR_GP_CNTRL_REG_FLAG_MAC_ACCESS_REQ);
143                         goto exit_unlock;
144                 }
145
146                 ret = iwl_grab_nic_access(priv);
147                 if (ret)
148                         goto exit_unlock;
149
150                 /* Device expects a multiple of 8 */
151                 iwl_write_direct32(priv, FH_RSCSR_CHNL0_WPTR,
152                                      q->write & ~0x7);
153                 iwl_release_nic_access(priv);
154
155         /* Else device is assumed to be awake */
156         } else
157                 /* Device expects a multiple of 8 */
158                 iwl_write32(priv, FH_RSCSR_CHNL0_WPTR, q->write & ~0x7);
159
160
161         q->need_update = 0;
162
163  exit_unlock:
164         spin_unlock_irqrestore(&q->lock, flags);
165         return ret;
166 }
167 EXPORT_SYMBOL(iwl_rx_queue_update_write_ptr);
168 /**
169  * iwl_dma_addr2rbd_ptr - convert a DMA address to a uCode read buffer ptr
170  */
171 static inline __le32 iwl_dma_addr2rbd_ptr(struct iwl_priv *priv,
172                                           dma_addr_t dma_addr)
173 {
174         return cpu_to_le32((u32)(dma_addr >> 8));
175 }
176
177 /**
178  * iwl_rx_queue_restock - refill RX queue from pre-allocated pool
179  *
180  * If there are slots in the RX queue that need to be restocked,
181  * and we have free pre-allocated buffers, fill the ranks as much
182  * as we can, pulling from rx_free.
183  *
184  * This moves the 'write' index forward to catch up with 'processed', and
185  * also updates the memory address in the firmware to reference the new
186  * target buffer.
187  */
188 int iwl_rx_queue_restock(struct iwl_priv *priv)
189 {
190         struct iwl_rx_queue *rxq = &priv->rxq;
191         struct list_head *element;
192         struct iwl_rx_mem_buffer *rxb;
193         unsigned long flags;
194         int write;
195         int ret = 0;
196
197         spin_lock_irqsave(&rxq->lock, flags);
198         write = rxq->write & ~0x7;
199         while ((iwl_rx_queue_space(rxq) > 0) && (rxq->free_count)) {
200                 /* Get next free Rx buffer, remove from free list */
201                 element = rxq->rx_free.next;
202                 rxb = list_entry(element, struct iwl_rx_mem_buffer, list);
203                 list_del(element);
204
205                 /* Point to Rx buffer via next RBD in circular buffer */
206                 rxq->bd[rxq->write] = iwl_dma_addr2rbd_ptr(priv, rxb->dma_addr);
207                 rxq->queue[rxq->write] = rxb;
208                 rxq->write = (rxq->write + 1) & RX_QUEUE_MASK;
209                 rxq->free_count--;
210         }
211         spin_unlock_irqrestore(&rxq->lock, flags);
212         /* If the pre-allocated buffer pool is dropping low, schedule to
213          * refill it */
214         if (rxq->free_count <= RX_LOW_WATERMARK)
215                 queue_work(priv->workqueue, &priv->rx_replenish);
216
217
218         /* If we've added more space for the firmware to place data, tell it.
219          * Increment device's write pointer in multiples of 8. */
220         if ((write != (rxq->write & ~0x7))
221             || (abs(rxq->write - rxq->read) > 7)) {
222                 spin_lock_irqsave(&rxq->lock, flags);
223                 rxq->need_update = 1;
224                 spin_unlock_irqrestore(&rxq->lock, flags);
225                 ret = iwl_rx_queue_update_write_ptr(priv, rxq);
226         }
227
228         return ret;
229 }
230 EXPORT_SYMBOL(iwl_rx_queue_restock);
231
232
233 /**
234  * iwl_rx_replenish - Move all used packet from rx_used to rx_free
235  *
236  * When moving to rx_free an SKB is allocated for the slot.
237  *
238  * Also restock the Rx queue via iwl_rx_queue_restock.
239  * This is called as a scheduled work item (except for during initialization)
240  */
241 void iwl_rx_allocate(struct iwl_priv *priv)
242 {
243         struct iwl_rx_queue *rxq = &priv->rxq;
244         struct list_head *element;
245         struct iwl_rx_mem_buffer *rxb;
246         unsigned long flags;
247         spin_lock_irqsave(&rxq->lock, flags);
248         while (!list_empty(&rxq->rx_used)) {
249                 element = rxq->rx_used.next;
250                 rxb = list_entry(element, struct iwl_rx_mem_buffer, list);
251
252                 /* Alloc a new receive buffer */
253                 rxb->skb = alloc_skb(priv->hw_params.rx_buf_size,
254                                 __GFP_NOWARN | GFP_ATOMIC);
255                 if (!rxb->skb) {
256                         if (net_ratelimit())
257                                 printk(KERN_CRIT DRV_NAME
258                                        ": Can not allocate SKB buffers\n");
259                         /* We don't reschedule replenish work here -- we will
260                          * call the restock method and if it still needs
261                          * more buffers it will schedule replenish */
262                         break;
263                 }
264                 priv->alloc_rxb_skb++;
265                 list_del(element);
266
267                 /* Get physical address of RB/SKB */
268                 rxb->dma_addr =
269                     pci_map_single(priv->pci_dev, rxb->skb->data,
270                            priv->hw_params.rx_buf_size, PCI_DMA_FROMDEVICE);
271                 list_add_tail(&rxb->list, &rxq->rx_free);
272                 rxq->free_count++;
273         }
274         spin_unlock_irqrestore(&rxq->lock, flags);
275 }
276 EXPORT_SYMBOL(iwl_rx_allocate);
277
278 void iwl_rx_replenish(struct iwl_priv *priv)
279 {
280         unsigned long flags;
281
282         iwl_rx_allocate(priv);
283
284         spin_lock_irqsave(&priv->lock, flags);
285         iwl_rx_queue_restock(priv);
286         spin_unlock_irqrestore(&priv->lock, flags);
287 }
288 EXPORT_SYMBOL(iwl_rx_replenish);
289
290
291 /* Assumes that the skb field of the buffers in 'pool' is kept accurate.
292  * If an SKB has been detached, the POOL needs to have its SKB set to NULL
293  * This free routine walks the list of POOL entries and if SKB is set to
294  * non NULL it is unmapped and freed
295  */
296 void iwl_rx_queue_free(struct iwl_priv *priv, struct iwl_rx_queue *rxq)
297 {
298         int i;
299         for (i = 0; i < RX_QUEUE_SIZE + RX_FREE_BUFFERS; i++) {
300                 if (rxq->pool[i].skb != NULL) {
301                         pci_unmap_single(priv->pci_dev,
302                                          rxq->pool[i].dma_addr,
303                                          priv->hw_params.rx_buf_size,
304                                          PCI_DMA_FROMDEVICE);
305                         dev_kfree_skb(rxq->pool[i].skb);
306                 }
307         }
308
309         pci_free_consistent(priv->pci_dev, 4 * RX_QUEUE_SIZE, rxq->bd,
310                             rxq->dma_addr);
311         rxq->bd = NULL;
312 }
313 EXPORT_SYMBOL(iwl_rx_queue_free);
314
315 int iwl_rx_queue_alloc(struct iwl_priv *priv)
316 {
317         struct iwl_rx_queue *rxq = &priv->rxq;
318         struct pci_dev *dev = priv->pci_dev;
319         int i;
320
321         spin_lock_init(&rxq->lock);
322         INIT_LIST_HEAD(&rxq->rx_free);
323         INIT_LIST_HEAD(&rxq->rx_used);
324
325         /* Alloc the circular buffer of Read Buffer Descriptors (RBDs) */
326         rxq->bd = pci_alloc_consistent(dev, 4 * RX_QUEUE_SIZE, &rxq->dma_addr);
327         if (!rxq->bd)
328                 return -ENOMEM;
329
330         /* Fill the rx_used queue with _all_ of the Rx buffers */
331         for (i = 0; i < RX_FREE_BUFFERS + RX_QUEUE_SIZE; i++)
332                 list_add_tail(&rxq->pool[i].list, &rxq->rx_used);
333
334         /* Set us so that we have processed and used all buffers, but have
335          * not restocked the Rx queue with fresh buffers */
336         rxq->read = rxq->write = 0;
337         rxq->free_count = 0;
338         rxq->need_update = 0;
339         return 0;
340 }
341 EXPORT_SYMBOL(iwl_rx_queue_alloc);
342
343 void iwl_rx_queue_reset(struct iwl_priv *priv, struct iwl_rx_queue *rxq)
344 {
345         unsigned long flags;
346         int i;
347         spin_lock_irqsave(&rxq->lock, flags);
348         INIT_LIST_HEAD(&rxq->rx_free);
349         INIT_LIST_HEAD(&rxq->rx_used);
350         /* Fill the rx_used queue with _all_ of the Rx buffers */
351         for (i = 0; i < RX_FREE_BUFFERS + RX_QUEUE_SIZE; i++) {
352                 /* In the reset function, these buffers may have been allocated
353                  * to an SKB, so we need to unmap and free potential storage */
354                 if (rxq->pool[i].skb != NULL) {
355                         pci_unmap_single(priv->pci_dev,
356                                          rxq->pool[i].dma_addr,
357                                          priv->hw_params.rx_buf_size,
358                                          PCI_DMA_FROMDEVICE);
359                         priv->alloc_rxb_skb--;
360                         dev_kfree_skb(rxq->pool[i].skb);
361                         rxq->pool[i].skb = NULL;
362                 }
363                 list_add_tail(&rxq->pool[i].list, &rxq->rx_used);
364         }
365
366         /* Set us so that we have processed and used all buffers, but have
367          * not restocked the Rx queue with fresh buffers */
368         rxq->read = rxq->write = 0;
369         rxq->free_count = 0;
370         spin_unlock_irqrestore(&rxq->lock, flags);
371 }
372 EXPORT_SYMBOL(iwl_rx_queue_reset);
373
374 int iwl_rx_init(struct iwl_priv *priv, struct iwl_rx_queue *rxq)
375 {
376         int ret;
377         unsigned long flags;
378         unsigned int rb_size;
379
380         spin_lock_irqsave(&priv->lock, flags);
381         ret = iwl_grab_nic_access(priv);
382         if (ret) {
383                 spin_unlock_irqrestore(&priv->lock, flags);
384                 return ret;
385         }
386
387         if (priv->cfg->mod_params->amsdu_size_8K)
388                 rb_size = FH_RCSR_RX_CONFIG_REG_VAL_RB_SIZE_8K;
389         else
390                 rb_size = FH_RCSR_RX_CONFIG_REG_VAL_RB_SIZE_4K;
391
392         /* Stop Rx DMA */
393         iwl_write_direct32(priv, FH_MEM_RCSR_CHNL0_CONFIG_REG, 0);
394
395         /* Reset driver's Rx queue write index */
396         iwl_write_direct32(priv, FH_RSCSR_CHNL0_RBDCB_WPTR_REG, 0);
397
398         /* Tell device where to find RBD circular buffer in DRAM */
399         iwl_write_direct32(priv, FH_RSCSR_CHNL0_RBDCB_BASE_REG,
400                            rxq->dma_addr >> 8);
401
402         /* Tell device where in DRAM to update its Rx status */
403         iwl_write_direct32(priv, FH_RSCSR_CHNL0_STTS_WPTR_REG,
404                            (priv->shared_phys + priv->rb_closed_offset) >> 4);
405
406         /* Enable Rx DMA, enable host interrupt, Rx buffer size 4k, 256 RBDs */
407         iwl_write_direct32(priv, FH_MEM_RCSR_CHNL0_CONFIG_REG,
408                            FH_RCSR_RX_CONFIG_CHNL_EN_ENABLE_VAL |
409                            FH_RCSR_CHNL0_RX_CONFIG_IRQ_DEST_INT_HOST_VAL |
410                            rb_size |
411                              /* 0x10 << 4 | */
412                            (RX_QUEUE_SIZE_LOG <<
413                               FH_RCSR_RX_CONFIG_RBDCB_SIZE_BITSHIFT));
414
415         /*
416          * iwl_write32(priv,CSR_INT_COAL_REG,0);
417          */
418
419         iwl_release_nic_access(priv);
420         spin_unlock_irqrestore(&priv->lock, flags);
421
422         return 0;
423 }
424
425 int iwl_rxq_stop(struct iwl_priv *priv)
426 {
427         int ret;
428         unsigned long flags;
429
430         spin_lock_irqsave(&priv->lock, flags);
431         ret = iwl_grab_nic_access(priv);
432         if (unlikely(ret)) {
433                 spin_unlock_irqrestore(&priv->lock, flags);
434                 return ret;
435         }
436
437         /* stop Rx DMA */
438         iwl_write_direct32(priv, FH_MEM_RCSR_CHNL0_CONFIG_REG, 0);
439         ret = iwl_poll_direct_bit(priv, FH_MEM_RSSR_RX_STATUS_REG,
440                                      (1 << 24), 1000);
441         if (ret < 0)
442                 IWL_ERROR("Can't stop Rx DMA.\n");
443
444         iwl_release_nic_access(priv);
445         spin_unlock_irqrestore(&priv->lock, flags);
446
447         return 0;
448 }
449 EXPORT_SYMBOL(iwl_rxq_stop);
450
451 void iwl_rx_missed_beacon_notif(struct iwl_priv *priv,
452                                 struct iwl_rx_mem_buffer *rxb)
453
454 {
455         struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
456         struct iwl4965_missed_beacon_notif *missed_beacon;
457
458         missed_beacon = &pkt->u.missed_beacon;
459         if (le32_to_cpu(missed_beacon->consequtive_missed_beacons) > 5) {
460                 IWL_DEBUG_CALIB("missed bcn cnsq %d totl %d rcd %d expctd %d\n",
461                     le32_to_cpu(missed_beacon->consequtive_missed_beacons),
462                     le32_to_cpu(missed_beacon->total_missed_becons),
463                     le32_to_cpu(missed_beacon->num_recvd_beacons),
464                     le32_to_cpu(missed_beacon->num_expected_beacons));
465                 if (!test_bit(STATUS_SCANNING, &priv->status))
466                         iwl_init_sensitivity(priv);
467         }
468 }
469 EXPORT_SYMBOL(iwl_rx_missed_beacon_notif);
470
471
472 /* Calculate noise level, based on measurements during network silence just
473  *   before arriving beacon.  This measurement can be done only if we know
474  *   exactly when to expect beacons, therefore only when we're associated. */
475 static void iwl_rx_calc_noise(struct iwl_priv *priv)
476 {
477         struct statistics_rx_non_phy *rx_info
478                                 = &(priv->statistics.rx.general);
479         int num_active_rx = 0;
480         int total_silence = 0;
481         int bcn_silence_a =
482                 le32_to_cpu(rx_info->beacon_silence_rssi_a) & IN_BAND_FILTER;
483         int bcn_silence_b =
484                 le32_to_cpu(rx_info->beacon_silence_rssi_b) & IN_BAND_FILTER;
485         int bcn_silence_c =
486                 le32_to_cpu(rx_info->beacon_silence_rssi_c) & IN_BAND_FILTER;
487
488         if (bcn_silence_a) {
489                 total_silence += bcn_silence_a;
490                 num_active_rx++;
491         }
492         if (bcn_silence_b) {
493                 total_silence += bcn_silence_b;
494                 num_active_rx++;
495         }
496         if (bcn_silence_c) {
497                 total_silence += bcn_silence_c;
498                 num_active_rx++;
499         }
500
501         /* Average among active antennas */
502         if (num_active_rx)
503                 priv->last_rx_noise = (total_silence / num_active_rx) - 107;
504         else
505                 priv->last_rx_noise = IWL_NOISE_MEAS_NOT_AVAILABLE;
506
507         IWL_DEBUG_CALIB("inband silence a %u, b %u, c %u, dBm %d\n",
508                         bcn_silence_a, bcn_silence_b, bcn_silence_c,
509                         priv->last_rx_noise);
510 }
511
512 #define REG_RECALIB_PERIOD (60)
513
514 void iwl_rx_statistics(struct iwl_priv *priv,
515                               struct iwl_rx_mem_buffer *rxb)
516 {
517         struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
518
519         IWL_DEBUG_RX("Statistics notification received (%d vs %d).\n",
520                      (int)sizeof(priv->statistics), pkt->len);
521
522         memcpy(&priv->statistics, &pkt->u.stats, sizeof(priv->statistics));
523
524         set_bit(STATUS_STATISTICS, &priv->status);
525
526         /* Reschedule the statistics timer to occur in
527          * REG_RECALIB_PERIOD seconds to ensure we get a
528          * thermal update even if the uCode doesn't give
529          * us one */
530         mod_timer(&priv->statistics_periodic, jiffies +
531                   msecs_to_jiffies(REG_RECALIB_PERIOD * 1000));
532
533         if (unlikely(!test_bit(STATUS_SCANNING, &priv->status)) &&
534             (pkt->hdr.cmd == STATISTICS_NOTIFICATION)) {
535                 iwl_rx_calc_noise(priv);
536                 queue_work(priv->workqueue, &priv->run_time_calib_work);
537         }
538
539         iwl_leds_background(priv);
540
541         if (priv->cfg->ops->lib->temperature)
542                 priv->cfg->ops->lib->temperature(priv, &pkt->u.stats);
543 }
544 EXPORT_SYMBOL(iwl_rx_statistics);
545
546 #define PERFECT_RSSI (-20) /* dBm */
547 #define WORST_RSSI (-95)   /* dBm */
548 #define RSSI_RANGE (PERFECT_RSSI - WORST_RSSI)
549
550 /* Calculate an indication of rx signal quality (a percentage, not dBm!).
551  * See http://www.ces.clemson.edu/linux/signal_quality.shtml for info
552  *   about formulas used below. */
553 static int iwl_calc_sig_qual(int rssi_dbm, int noise_dbm)
554 {
555         int sig_qual;
556         int degradation = PERFECT_RSSI - rssi_dbm;
557
558         /* If we get a noise measurement, use signal-to-noise ratio (SNR)
559          * as indicator; formula is (signal dbm - noise dbm).
560          * SNR at or above 40 is a great signal (100%).
561          * Below that, scale to fit SNR of 0 - 40 dB within 0 - 100% indicator.
562          * Weakest usable signal is usually 10 - 15 dB SNR. */
563         if (noise_dbm) {
564                 if (rssi_dbm - noise_dbm >= 40)
565                         return 100;
566                 else if (rssi_dbm < noise_dbm)
567                         return 0;
568                 sig_qual = ((rssi_dbm - noise_dbm) * 5) / 2;
569
570         /* Else use just the signal level.
571          * This formula is a least squares fit of data points collected and
572          *   compared with a reference system that had a percentage (%) display
573          *   for signal quality. */
574         } else
575                 sig_qual = (100 * (RSSI_RANGE * RSSI_RANGE) - degradation *
576                             (15 * RSSI_RANGE + 62 * degradation)) /
577                            (RSSI_RANGE * RSSI_RANGE);
578
579         if (sig_qual > 100)
580                 sig_qual = 100;
581         else if (sig_qual < 1)
582                 sig_qual = 0;
583
584         return sig_qual;
585 }
586
587 #ifdef CONFIG_IWLWIFI_DEBUG
588
589 /**
590  * iwl_dbg_report_frame - dump frame to syslog during debug sessions
591  *
592  * You may hack this function to show different aspects of received frames,
593  * including selective frame dumps.
594  * group100 parameter selects whether to show 1 out of 100 good frames.
595  *
596  * TODO:  This was originally written for 3945, need to audit for
597  *        proper operation with 4965.
598  */
599 static void iwl_dbg_report_frame(struct iwl_priv *priv,
600                       struct iwl_rx_packet *pkt,
601                       struct ieee80211_hdr *header, int group100)
602 {
603         u32 to_us;
604         u32 print_summary = 0;
605         u32 print_dump = 0;     /* set to 1 to dump all frames' contents */
606         u32 hundred = 0;
607         u32 dataframe = 0;
608         __le16 fc;
609         u16 seq_ctl;
610         u16 channel;
611         u16 phy_flags;
612         int rate_sym;
613         u16 length;
614         u16 status;
615         u16 bcn_tmr;
616         u32 tsf_low;
617         u64 tsf;
618         u8 rssi;
619         u8 agc;
620         u16 sig_avg;
621         u16 noise_diff;
622         struct iwl4965_rx_frame_stats *rx_stats = IWL_RX_STATS(pkt);
623         struct iwl4965_rx_frame_hdr *rx_hdr = IWL_RX_HDR(pkt);
624         struct iwl4965_rx_frame_end *rx_end = IWL_RX_END(pkt);
625         u8 *data = IWL_RX_DATA(pkt);
626
627         if (likely(!(priv->debug_level & IWL_DL_RX)))
628                 return;
629
630         /* MAC header */
631         fc = header->frame_control;
632         seq_ctl = le16_to_cpu(header->seq_ctrl);
633
634         /* metadata */
635         channel = le16_to_cpu(rx_hdr->channel);
636         phy_flags = le16_to_cpu(rx_hdr->phy_flags);
637         rate_sym = rx_hdr->rate;
638         length = le16_to_cpu(rx_hdr->len);
639
640         /* end-of-frame status and timestamp */
641         status = le32_to_cpu(rx_end->status);
642         bcn_tmr = le32_to_cpu(rx_end->beacon_timestamp);
643         tsf_low = le64_to_cpu(rx_end->timestamp) & 0x0ffffffff;
644         tsf = le64_to_cpu(rx_end->timestamp);
645
646         /* signal statistics */
647         rssi = rx_stats->rssi;
648         agc = rx_stats->agc;
649         sig_avg = le16_to_cpu(rx_stats->sig_avg);
650         noise_diff = le16_to_cpu(rx_stats->noise_diff);
651
652         to_us = !compare_ether_addr(header->addr1, priv->mac_addr);
653
654         /* if data frame is to us and all is good,
655          *   (optionally) print summary for only 1 out of every 100 */
656         if (to_us && (fc & ~cpu_to_le16(IEEE80211_FCTL_PROTECTED)) ==
657             cpu_to_le16(IEEE80211_FCTL_FROMDS | IEEE80211_FTYPE_DATA)) {
658                 dataframe = 1;
659                 if (!group100)
660                         print_summary = 1;      /* print each frame */
661                 else if (priv->framecnt_to_us < 100) {
662                         priv->framecnt_to_us++;
663                         print_summary = 0;
664                 } else {
665                         priv->framecnt_to_us = 0;
666                         print_summary = 1;
667                         hundred = 1;
668                 }
669         } else {
670                 /* print summary for all other frames */
671                 print_summary = 1;
672         }
673
674         if (print_summary) {
675                 char *title;
676                 int rate_idx;
677                 u32 bitrate;
678
679                 if (hundred)
680                         title = "100Frames";
681                 else if (ieee80211_has_retry(fc))
682                         title = "Retry";
683                 else if (ieee80211_is_assoc_resp(fc))
684                         title = "AscRsp";
685                 else if (ieee80211_is_reassoc_resp(fc))
686                         title = "RasRsp";
687                 else if (ieee80211_is_probe_resp(fc)) {
688                         title = "PrbRsp";
689                         print_dump = 1; /* dump frame contents */
690                 } else if (ieee80211_is_beacon(fc)) {
691                         title = "Beacon";
692                         print_dump = 1; /* dump frame contents */
693                 } else if (ieee80211_is_atim(fc))
694                         title = "ATIM";
695                 else if (ieee80211_is_auth(fc))
696                         title = "Auth";
697                 else if (ieee80211_is_deauth(fc))
698                         title = "DeAuth";
699                 else if (ieee80211_is_disassoc(fc))
700                         title = "DisAssoc";
701                 else
702                         title = "Frame";
703
704                 rate_idx = iwl_hwrate_to_plcp_idx(rate_sym);
705                 if (unlikely(rate_idx == -1))
706                         bitrate = 0;
707                 else
708                         bitrate = iwl_rates[rate_idx].ieee / 2;
709
710                 /* print frame summary.
711                  * MAC addresses show just the last byte (for brevity),
712                  *    but you can hack it to show more, if you'd like to. */
713                 if (dataframe)
714                         IWL_DEBUG_RX("%s: mhd=0x%04x, dst=0x%02x, "
715                                      "len=%u, rssi=%d, chnl=%d, rate=%u, \n",
716                                      title, le16_to_cpu(fc), header->addr1[5],
717                                      length, rssi, channel, bitrate);
718                 else {
719                         /* src/dst addresses assume managed mode */
720                         IWL_DEBUG_RX("%s: 0x%04x, dst=0x%02x, "
721                                      "src=0x%02x, rssi=%u, tim=%lu usec, "
722                                      "phy=0x%02x, chnl=%d\n",
723                                      title, le16_to_cpu(fc), header->addr1[5],
724                                      header->addr3[5], rssi,
725                                      tsf_low - priv->scan_start_tsf,
726                                      phy_flags, channel);
727                 }
728         }
729         if (print_dump)
730                 iwl_print_hex_dump(priv, IWL_DL_RX, data, length);
731 }
732 #else
733 static inline void iwl_dbg_report_frame(struct iwl_priv *priv,
734                                             struct iwl_rx_packet *pkt,
735                                             struct ieee80211_hdr *header,
736                                             int group100)
737 {
738 }
739 #endif
740
741 static void iwl_add_radiotap(struct iwl_priv *priv,
742                                  struct sk_buff *skb,
743                                  struct iwl4965_rx_phy_res *rx_start,
744                                  struct ieee80211_rx_status *stats,
745                                  u32 ampdu_status)
746 {
747         s8 signal = stats->signal;
748         s8 noise = 0;
749         int rate = stats->rate_idx;
750         u64 tsf = stats->mactime;
751         __le16 antenna;
752         __le16 phy_flags_hw = rx_start->phy_flags;
753         struct iwl4965_rt_rx_hdr {
754                 struct ieee80211_radiotap_header rt_hdr;
755                 __le64 rt_tsf;          /* TSF */
756                 u8 rt_flags;            /* radiotap packet flags */
757                 u8 rt_rate;             /* rate in 500kb/s */
758                 __le16 rt_channelMHz;   /* channel in MHz */
759                 __le16 rt_chbitmask;    /* channel bitfield */
760                 s8 rt_dbmsignal;        /* signal in dBm, kluged to signed */
761                 s8 rt_dbmnoise;
762                 u8 rt_antenna;          /* antenna number */
763         } __attribute__ ((packed)) *iwl4965_rt;
764
765         /* TODO: We won't have enough headroom for HT frames. Fix it later. */
766         if (skb_headroom(skb) < sizeof(*iwl4965_rt)) {
767                 if (net_ratelimit())
768                         printk(KERN_ERR "not enough headroom [%d] for "
769                                "radiotap head [%zd]\n",
770                                skb_headroom(skb), sizeof(*iwl4965_rt));
771                 return;
772         }
773
774         /* put radiotap header in front of 802.11 header and data */
775         iwl4965_rt = (void *)skb_push(skb, sizeof(*iwl4965_rt));
776
777         /* initialise radiotap header */
778         iwl4965_rt->rt_hdr.it_version = PKTHDR_RADIOTAP_VERSION;
779         iwl4965_rt->rt_hdr.it_pad = 0;
780
781         /* total header + data */
782         put_unaligned(cpu_to_le16(sizeof(*iwl4965_rt)),
783                       &iwl4965_rt->rt_hdr.it_len);
784
785         /* Indicate all the fields we add to the radiotap header */
786         put_unaligned(cpu_to_le32((1 << IEEE80211_RADIOTAP_TSFT) |
787                                   (1 << IEEE80211_RADIOTAP_FLAGS) |
788                                   (1 << IEEE80211_RADIOTAP_RATE) |
789                                   (1 << IEEE80211_RADIOTAP_CHANNEL) |
790                                   (1 << IEEE80211_RADIOTAP_DBM_ANTSIGNAL) |
791                                   (1 << IEEE80211_RADIOTAP_DBM_ANTNOISE) |
792                                   (1 << IEEE80211_RADIOTAP_ANTENNA)),
793                       &iwl4965_rt->rt_hdr.it_present);
794
795         /* Zero the flags, we'll add to them as we go */
796         iwl4965_rt->rt_flags = 0;
797
798         put_unaligned(cpu_to_le64(tsf), &iwl4965_rt->rt_tsf);
799
800         iwl4965_rt->rt_dbmsignal = signal;
801         iwl4965_rt->rt_dbmnoise = noise;
802
803         /* Convert the channel frequency and set the flags */
804         put_unaligned(cpu_to_le16(stats->freq), &iwl4965_rt->rt_channelMHz);
805         if (!(phy_flags_hw & RX_RES_PHY_FLAGS_BAND_24_MSK))
806                 put_unaligned(cpu_to_le16(IEEE80211_CHAN_OFDM |
807                                           IEEE80211_CHAN_5GHZ),
808                               &iwl4965_rt->rt_chbitmask);
809         else if (phy_flags_hw & RX_RES_PHY_FLAGS_MOD_CCK_MSK)
810                 put_unaligned(cpu_to_le16(IEEE80211_CHAN_CCK |
811                                           IEEE80211_CHAN_2GHZ),
812                               &iwl4965_rt->rt_chbitmask);
813         else    /* 802.11g */
814                 put_unaligned(cpu_to_le16(IEEE80211_CHAN_OFDM |
815                                           IEEE80211_CHAN_2GHZ),
816                               &iwl4965_rt->rt_chbitmask);
817
818         if (rate == -1)
819                 iwl4965_rt->rt_rate = 0;
820         else
821                 iwl4965_rt->rt_rate = iwl_rates[rate].ieee;
822
823         /*
824          * "antenna number"
825          *
826          * It seems that the antenna field in the phy flags value
827          * is actually a bitfield. This is undefined by radiotap,
828          * it wants an actual antenna number but I always get "7"
829          * for most legacy frames I receive indicating that the
830          * same frame was received on all three RX chains.
831          *
832          * I think this field should be removed in favour of a
833          * new 802.11n radiotap field "RX chains" that is defined
834          * as a bitmask.
835          */
836         antenna = phy_flags_hw & RX_RES_PHY_FLAGS_ANTENNA_MSK;
837         iwl4965_rt->rt_antenna = le16_to_cpu(antenna) >> 4;
838
839         /* set the preamble flag if appropriate */
840         if (phy_flags_hw & RX_RES_PHY_FLAGS_SHORT_PREAMBLE_MSK)
841                 iwl4965_rt->rt_flags |= IEEE80211_RADIOTAP_F_SHORTPRE;
842
843         stats->flag |= RX_FLAG_RADIOTAP;
844 }
845
846 static void iwl_update_rx_stats(struct iwl_priv *priv, u16 fc, u16 len)
847 {
848         /* 0 - mgmt, 1 - cnt, 2 - data */
849         int idx = (fc & IEEE80211_FCTL_FTYPE) >> 2;
850         priv->rx_stats[idx].cnt++;
851         priv->rx_stats[idx].bytes += len;
852 }
853
854 /*
855  * returns non-zero if packet should be dropped
856  */
857 static int iwl_set_decrypted_flag(struct iwl_priv *priv,
858                                       struct ieee80211_hdr *hdr,
859                                       u32 decrypt_res,
860                                       struct ieee80211_rx_status *stats)
861 {
862         u16 fc = le16_to_cpu(hdr->frame_control);
863
864         if (priv->active_rxon.filter_flags & RXON_FILTER_DIS_DECRYPT_MSK)
865                 return 0;
866
867         if (!(fc & IEEE80211_FCTL_PROTECTED))
868                 return 0;
869
870         IWL_DEBUG_RX("decrypt_res:0x%x\n", decrypt_res);
871         switch (decrypt_res & RX_RES_STATUS_SEC_TYPE_MSK) {
872         case RX_RES_STATUS_SEC_TYPE_TKIP:
873                 /* The uCode has got a bad phase 1 Key, pushes the packet.
874                  * Decryption will be done in SW. */
875                 if ((decrypt_res & RX_RES_STATUS_DECRYPT_TYPE_MSK) ==
876                     RX_RES_STATUS_BAD_KEY_TTAK)
877                         break;
878
879         case RX_RES_STATUS_SEC_TYPE_WEP:
880                 if ((decrypt_res & RX_RES_STATUS_DECRYPT_TYPE_MSK) ==
881                     RX_RES_STATUS_BAD_ICV_MIC) {
882                         /* bad ICV, the packet is destroyed since the
883                          * decryption is inplace, drop it */
884                         IWL_DEBUG_RX("Packet destroyed\n");
885                         return -1;
886                 }
887         case RX_RES_STATUS_SEC_TYPE_CCMP:
888                 if ((decrypt_res & RX_RES_STATUS_DECRYPT_TYPE_MSK) ==
889                     RX_RES_STATUS_DECRYPT_OK) {
890                         IWL_DEBUG_RX("hw decrypt successfully!!!\n");
891                         stats->flag |= RX_FLAG_DECRYPTED;
892                 }
893                 break;
894
895         default:
896                 break;
897         }
898         return 0;
899 }
900
901 static u32 iwl_translate_rx_status(struct iwl_priv *priv, u32 decrypt_in)
902 {
903         u32 decrypt_out = 0;
904
905         if ((decrypt_in & RX_RES_STATUS_STATION_FOUND) ==
906                                         RX_RES_STATUS_STATION_FOUND)
907                 decrypt_out |= (RX_RES_STATUS_STATION_FOUND |
908                                 RX_RES_STATUS_NO_STATION_INFO_MISMATCH);
909
910         decrypt_out |= (decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK);
911
912         /* packet was not encrypted */
913         if ((decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK) ==
914                                         RX_RES_STATUS_SEC_TYPE_NONE)
915                 return decrypt_out;
916
917         /* packet was encrypted with unknown alg */
918         if ((decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK) ==
919                                         RX_RES_STATUS_SEC_TYPE_ERR)
920                 return decrypt_out;
921
922         /* decryption was not done in HW */
923         if ((decrypt_in & RX_MPDU_RES_STATUS_DEC_DONE_MSK) !=
924                                         RX_MPDU_RES_STATUS_DEC_DONE_MSK)
925                 return decrypt_out;
926
927         switch (decrypt_in & RX_RES_STATUS_SEC_TYPE_MSK) {
928
929         case RX_RES_STATUS_SEC_TYPE_CCMP:
930                 /* alg is CCM: check MIC only */
931                 if (!(decrypt_in & RX_MPDU_RES_STATUS_MIC_OK))
932                         /* Bad MIC */
933                         decrypt_out |= RX_RES_STATUS_BAD_ICV_MIC;
934                 else
935                         decrypt_out |= RX_RES_STATUS_DECRYPT_OK;
936
937                 break;
938
939         case RX_RES_STATUS_SEC_TYPE_TKIP:
940                 if (!(decrypt_in & RX_MPDU_RES_STATUS_TTAK_OK)) {
941                         /* Bad TTAK */
942                         decrypt_out |= RX_RES_STATUS_BAD_KEY_TTAK;
943                         break;
944                 }
945                 /* fall through if TTAK OK */
946         default:
947                 if (!(decrypt_in & RX_MPDU_RES_STATUS_ICV_OK))
948                         decrypt_out |= RX_RES_STATUS_BAD_ICV_MIC;
949                 else
950                         decrypt_out |= RX_RES_STATUS_DECRYPT_OK;
951                 break;
952         };
953
954         IWL_DEBUG_RX("decrypt_in:0x%x  decrypt_out = 0x%x\n",
955                                         decrypt_in, decrypt_out);
956
957         return decrypt_out;
958 }
959
960 static void iwl_pass_packet_to_mac80211(struct iwl_priv *priv,
961                                        int include_phy,
962                                        struct iwl_rx_mem_buffer *rxb,
963                                        struct ieee80211_rx_status *stats)
964 {
965         struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
966         struct iwl4965_rx_phy_res *rx_start = (include_phy) ?
967             (struct iwl4965_rx_phy_res *)&(pkt->u.raw[0]) : NULL;
968         struct ieee80211_hdr *hdr;
969         u16 len;
970         __le32 *rx_end;
971         unsigned int skblen;
972         u32 ampdu_status;
973         u32 ampdu_status_legacy;
974
975         if (!include_phy && priv->last_phy_res[0])
976                 rx_start = (struct iwl4965_rx_phy_res *)&priv->last_phy_res[1];
977
978         if (!rx_start) {
979                 IWL_ERROR("MPDU frame without a PHY data\n");
980                 return;
981         }
982         if (include_phy) {
983                 hdr = (struct ieee80211_hdr *)((u8 *) &rx_start[1] +
984                                                rx_start->cfg_phy_cnt);
985
986                 len = le16_to_cpu(rx_start->byte_count);
987
988                 rx_end = (__le32 *) ((u8 *) &pkt->u.raw[0] +
989                                   sizeof(struct iwl4965_rx_phy_res) +
990                                   rx_start->cfg_phy_cnt + len);
991
992         } else {
993                 struct iwl4965_rx_mpdu_res_start *amsdu =
994                     (struct iwl4965_rx_mpdu_res_start *)pkt->u.raw;
995
996                 hdr = (struct ieee80211_hdr *)(pkt->u.raw +
997                                sizeof(struct iwl4965_rx_mpdu_res_start));
998                 len =  le16_to_cpu(amsdu->byte_count);
999                 rx_start->byte_count = amsdu->byte_count;
1000                 rx_end = (__le32 *) (((u8 *) hdr) + len);
1001         }
1002
1003         ampdu_status = le32_to_cpu(*rx_end);
1004         skblen = ((u8 *) rx_end - (u8 *) &pkt->u.raw[0]) + sizeof(u32);
1005
1006         if (!include_phy) {
1007                 /* New status scheme, need to translate */
1008                 ampdu_status_legacy = ampdu_status;
1009                 ampdu_status = iwl_translate_rx_status(priv, ampdu_status);
1010         }
1011
1012         /* start from MAC */
1013         skb_reserve(rxb->skb, (void *)hdr - (void *)pkt);
1014         skb_put(rxb->skb, len); /* end where data ends */
1015
1016         /* We only process data packets if the interface is open */
1017         if (unlikely(!priv->is_open)) {
1018                 IWL_DEBUG_DROP_LIMIT
1019                     ("Dropping packet while interface is not open.\n");
1020                 return;
1021         }
1022
1023         stats->flag = 0;
1024         hdr = (struct ieee80211_hdr *)rxb->skb->data;
1025
1026         /*  in case of HW accelerated crypto and bad decryption, drop */
1027         if (!priv->hw_params.sw_crypto &&
1028             iwl_set_decrypted_flag(priv, hdr, ampdu_status, stats))
1029                 return;
1030
1031         if (priv->add_radiotap)
1032                 iwl_add_radiotap(priv, rxb->skb, rx_start, stats, ampdu_status);
1033
1034         iwl_update_rx_stats(priv, le16_to_cpu(hdr->frame_control), len);
1035         ieee80211_rx_irqsafe(priv->hw, rxb->skb, stats);
1036         priv->alloc_rxb_skb--;
1037         rxb->skb = NULL;
1038 }
1039
1040 /* Calc max signal level (dBm) among 3 possible receivers */
1041 static int iwl_calc_rssi(struct iwl_priv *priv,
1042                              struct iwl4965_rx_phy_res *rx_resp)
1043 {
1044         /* data from PHY/DSP regarding signal strength, etc.,
1045          *   contents are always there, not configurable by host.  */
1046         struct iwl4965_rx_non_cfg_phy *ncphy =
1047             (struct iwl4965_rx_non_cfg_phy *)rx_resp->non_cfg_phy;
1048         u32 agc = (le16_to_cpu(ncphy->agc_info) & IWL_AGC_DB_MASK)
1049                         >> IWL_AGC_DB_POS;
1050
1051         u32 valid_antennae =
1052             (le16_to_cpu(rx_resp->phy_flags) & RX_PHY_FLAGS_ANTENNAE_MASK)
1053                         >> RX_PHY_FLAGS_ANTENNAE_OFFSET;
1054         u8 max_rssi = 0;
1055         u32 i;
1056
1057         /* Find max rssi among 3 possible receivers.
1058          * These values are measured by the digital signal processor (DSP).
1059          * They should stay fairly constant even as the signal strength varies,
1060          *   if the radio's automatic gain control (AGC) is working right.
1061          * AGC value (see below) will provide the "interesting" info. */
1062         for (i = 0; i < 3; i++)
1063                 if (valid_antennae & (1 << i))
1064                         max_rssi = max(ncphy->rssi_info[i << 1], max_rssi);
1065
1066         IWL_DEBUG_STATS("Rssi In A %d B %d C %d Max %d AGC dB %d\n",
1067                 ncphy->rssi_info[0], ncphy->rssi_info[2], ncphy->rssi_info[4],
1068                 max_rssi, agc);
1069
1070         /* dBm = max_rssi dB - agc dB - constant.
1071          * Higher AGC (higher radio gain) means lower signal. */
1072         return max_rssi - agc - IWL_RSSI_OFFSET;
1073 }
1074
1075 static void iwl_sta_modify_ps_wake(struct iwl_priv *priv, int sta_id)
1076 {
1077         unsigned long flags;
1078
1079         spin_lock_irqsave(&priv->sta_lock, flags);
1080         priv->stations[sta_id].sta.station_flags &= ~STA_FLG_PWR_SAVE_MSK;
1081         priv->stations[sta_id].sta.station_flags_msk = STA_FLG_PWR_SAVE_MSK;
1082         priv->stations[sta_id].sta.sta.modify_mask = 0;
1083         priv->stations[sta_id].sta.mode = STA_CONTROL_MODIFY_MSK;
1084         spin_unlock_irqrestore(&priv->sta_lock, flags);
1085
1086         iwl_send_add_sta(priv, &priv->stations[sta_id].sta, CMD_ASYNC);
1087 }
1088
1089 static void iwl_update_ps_mode(struct iwl_priv *priv, u16 ps_bit, u8 *addr)
1090 {
1091         /* FIXME: need locking over ps_status ??? */
1092         u8 sta_id = iwl_find_station(priv, addr);
1093
1094         if (sta_id != IWL_INVALID_STATION) {
1095                 u8 sta_awake = priv->stations[sta_id].
1096                                 ps_status == STA_PS_STATUS_WAKE;
1097
1098                 if (sta_awake && ps_bit)
1099                         priv->stations[sta_id].ps_status = STA_PS_STATUS_SLEEP;
1100                 else if (!sta_awake && !ps_bit) {
1101                         iwl_sta_modify_ps_wake(priv, sta_id);
1102                         priv->stations[sta_id].ps_status = STA_PS_STATUS_WAKE;
1103                 }
1104         }
1105 }
1106
1107 /* This is necessary only for a number of statistics, see the caller. */
1108 static int iwl_is_network_packet(struct iwl_priv *priv,
1109                 struct ieee80211_hdr *header)
1110 {
1111         /* Filter incoming packets to determine if they are targeted toward
1112          * this network, discarding packets coming from ourselves */
1113         switch (priv->iw_mode) {
1114         case IEEE80211_IF_TYPE_IBSS: /* Header: Dest. | Source    | BSSID */
1115                 /* packets to our IBSS update information */
1116                 return !compare_ether_addr(header->addr3, priv->bssid);
1117         case IEEE80211_IF_TYPE_STA: /* Header: Dest. | AP{BSSID} | Source */
1118                 /* packets to our IBSS update information */
1119                 return !compare_ether_addr(header->addr2, priv->bssid);
1120         default:
1121                 return 1;
1122         }
1123 }
1124
1125 /* Called for REPLY_RX (legacy ABG frames), or
1126  * REPLY_RX_MPDU_CMD (HT high-throughput N frames). */
1127 void iwl_rx_reply_rx(struct iwl_priv *priv,
1128                                 struct iwl_rx_mem_buffer *rxb)
1129 {
1130         struct ieee80211_hdr *header;
1131         struct ieee80211_rx_status rx_status;
1132         struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
1133         /* Use phy data (Rx signal strength, etc.) contained within
1134          *   this rx packet for legacy frames,
1135          *   or phy data cached from REPLY_RX_PHY_CMD for HT frames. */
1136         int include_phy = (pkt->hdr.cmd == REPLY_RX);
1137         struct iwl4965_rx_phy_res *rx_start = (include_phy) ?
1138                 (struct iwl4965_rx_phy_res *)&(pkt->u.raw[0]) :
1139                 (struct iwl4965_rx_phy_res *)&priv->last_phy_res[1];
1140         __le32 *rx_end;
1141         unsigned int len = 0;
1142         u16 fc;
1143         u8 network_packet;
1144
1145         rx_status.mactime = le64_to_cpu(rx_start->timestamp);
1146         rx_status.freq =
1147                 ieee80211_channel_to_frequency(le16_to_cpu(rx_start->channel));
1148         rx_status.band = (rx_start->phy_flags & RX_RES_PHY_FLAGS_BAND_24_MSK) ?
1149                                 IEEE80211_BAND_2GHZ : IEEE80211_BAND_5GHZ;
1150         rx_status.rate_idx =
1151                 iwl_hwrate_to_plcp_idx(le32_to_cpu(rx_start->rate_n_flags));
1152         if (rx_status.band == IEEE80211_BAND_5GHZ)
1153                 rx_status.rate_idx -= IWL_FIRST_OFDM_RATE;
1154
1155         rx_status.antenna = 0;
1156         rx_status.flag = 0;
1157
1158         if ((unlikely(rx_start->cfg_phy_cnt > 20))) {
1159                 IWL_DEBUG_DROP("dsp size out of range [0,20]: %d/n",
1160                                 rx_start->cfg_phy_cnt);
1161                 return;
1162         }
1163
1164         if (!include_phy) {
1165                 if (priv->last_phy_res[0])
1166                         rx_start = (struct iwl4965_rx_phy_res *)
1167                                 &priv->last_phy_res[1];
1168                 else
1169                         rx_start = NULL;
1170         }
1171
1172         if (!rx_start) {
1173                 IWL_ERROR("MPDU frame without a PHY data\n");
1174                 return;
1175         }
1176
1177         if (include_phy) {
1178                 header = (struct ieee80211_hdr *)((u8 *) &rx_start[1]
1179                                                   + rx_start->cfg_phy_cnt);
1180
1181                 len = le16_to_cpu(rx_start->byte_count);
1182                 rx_end = (__le32 *)(pkt->u.raw + rx_start->cfg_phy_cnt +
1183                                   sizeof(struct iwl4965_rx_phy_res) + len);
1184         } else {
1185                 struct iwl4965_rx_mpdu_res_start *amsdu =
1186                         (struct iwl4965_rx_mpdu_res_start *)pkt->u.raw;
1187
1188                 header = (void *)(pkt->u.raw +
1189                         sizeof(struct iwl4965_rx_mpdu_res_start));
1190                 len = le16_to_cpu(amsdu->byte_count);
1191                 rx_end = (__le32 *) (pkt->u.raw +
1192                         sizeof(struct iwl4965_rx_mpdu_res_start) + len);
1193         }
1194
1195         if (!(*rx_end & RX_RES_STATUS_NO_CRC32_ERROR) ||
1196             !(*rx_end & RX_RES_STATUS_NO_RXE_OVERFLOW)) {
1197                 IWL_DEBUG_RX("Bad CRC or FIFO: 0x%08X.\n",
1198                                 le32_to_cpu(*rx_end));
1199                 return;
1200         }
1201
1202         priv->ucode_beacon_time = le32_to_cpu(rx_start->beacon_time_stamp);
1203
1204         /* Find max signal strength (dBm) among 3 antenna/receiver chains */
1205         rx_status.signal = iwl_calc_rssi(priv, rx_start);
1206
1207         /* Meaningful noise values are available only from beacon statistics,
1208          *   which are gathered only when associated, and indicate noise
1209          *   only for the associated network channel ...
1210          * Ignore these noise values while scanning (other channels) */
1211         if (iwl_is_associated(priv) &&
1212             !test_bit(STATUS_SCANNING, &priv->status)) {
1213                 rx_status.noise = priv->last_rx_noise;
1214                 rx_status.qual = iwl_calc_sig_qual(rx_status.signal,
1215                                                          rx_status.noise);
1216         } else {
1217                 rx_status.noise = IWL_NOISE_MEAS_NOT_AVAILABLE;
1218                 rx_status.qual = iwl_calc_sig_qual(rx_status.signal, 0);
1219         }
1220
1221         /* Reset beacon noise level if not associated. */
1222         if (!iwl_is_associated(priv))
1223                 priv->last_rx_noise = IWL_NOISE_MEAS_NOT_AVAILABLE;
1224
1225         /* Set "1" to report good data frames in groups of 100 */
1226         /* FIXME: need to optimze the call: */
1227         iwl_dbg_report_frame(priv, pkt, header, 1);
1228
1229         IWL_DEBUG_STATS_LIMIT("Rssi %d, noise %d, qual %d, TSF %llu\n",
1230                 rx_status.signal, rx_status.noise, rx_status.signal,
1231                 (unsigned long long)rx_status.mactime);
1232
1233         /* Take shortcut when only in monitor mode */
1234         if (priv->iw_mode == IEEE80211_IF_TYPE_MNTR) {
1235                 iwl_pass_packet_to_mac80211(priv, include_phy,
1236                                                  rxb, &rx_status);
1237                 return;
1238         }
1239
1240         network_packet = iwl_is_network_packet(priv, header);
1241         if (network_packet) {
1242                 priv->last_rx_rssi = rx_status.signal;
1243                 priv->last_beacon_time =  priv->ucode_beacon_time;
1244                 priv->last_tsf = le64_to_cpu(rx_start->timestamp);
1245         }
1246
1247         fc = le16_to_cpu(header->frame_control);
1248         switch (fc & IEEE80211_FCTL_FTYPE) {
1249         case IEEE80211_FTYPE_MGMT:
1250         case IEEE80211_FTYPE_DATA:
1251                 if (priv->iw_mode == IEEE80211_IF_TYPE_AP)
1252                         iwl_update_ps_mode(priv, fc  & IEEE80211_FCTL_PM,
1253                                                 header->addr2);
1254                 /* fall through */
1255         default:
1256                         iwl_pass_packet_to_mac80211(priv, include_phy, rxb,
1257                                    &rx_status);
1258                 break;
1259
1260         }
1261 }
1262 EXPORT_SYMBOL(iwl_rx_reply_rx);
1263
1264 /* Cache phy data (Rx signal strength, etc) for HT frame (REPLY_RX_PHY_CMD).
1265  * This will be used later in iwl_rx_reply_rx() for REPLY_RX_MPDU_CMD. */
1266 void iwl_rx_reply_rx_phy(struct iwl_priv *priv,
1267                                     struct iwl_rx_mem_buffer *rxb)
1268 {
1269         struct iwl_rx_packet *pkt = (struct iwl_rx_packet *)rxb->skb->data;
1270         priv->last_phy_res[0] = 1;
1271         memcpy(&priv->last_phy_res[1], &(pkt->u.raw[0]),
1272                sizeof(struct iwl4965_rx_phy_res));
1273 }
1274 EXPORT_SYMBOL(iwl_rx_reply_rx_phy);