1 /******************************************************************************
2  *
3  * GPL LICENSE SUMMARY
4  *
5  * Copyright(c) 2008 - 2011 Intel Corporation. All rights reserved.
6  *
7  * This program is free software; you can redistribute it and/or modify
8  * it under the terms of version 2 of the GNU General Public License as
9  * published by the Free Software Foundation.
10  *
11  * This program is distributed in the hope that it will be useful, but
12  * WITHOUT ANY WARRANTY; without even the implied warranty of
13  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14  * General Public License for more details.
15  *
16  * You should have received a copy of the GNU General Public License
17  * along with this program; if not, write to the Free Software
18  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110,
19  * USA
20  *
21  * The full GNU General Public License is included in this distribution
22  * in the file called LICENSE.GPL.
23  *
24  * Contact Information:
25  *  Intel Linux Wireless <ilw@linux.intel.com>
26  * Intel Corporation, 5200 N.E. Elam Young Parkway, Hillsboro, OR 97124-6497
27  *****************************************************************************/
28 #include <linux/slab.h>
29 #include <linux/types.h>
30 #include <linux/etherdevice.h>
31 #include <net/mac80211.h>
32 
33 #include "iwl-eeprom.h"
34 #include "iwl-dev.h"
35 #include "iwl-core.h"
36 #include "iwl-sta.h"
37 #include "iwl-io.h"
38 #include "iwl-helpers.h"
39 
40 /* For active scan, listen ACTIVE_DWELL_TIME (msec) on each channel after
41  * sending probe req.  This should be set long enough to hear probe responses
42  * from more than one AP.  */
43 #define IWL_ACTIVE_DWELL_TIME_24    (30)       /* all times in msec */
44 #define IWL_ACTIVE_DWELL_TIME_52    (20)
45 
46 #define IWL_ACTIVE_DWELL_FACTOR_24GHZ (3)
47 #define IWL_ACTIVE_DWELL_FACTOR_52GHZ (2)
48 
49 /* For passive scan, listen PASSIVE_DWELL_TIME (msec) on each channel.
50  * Must be set longer than active dwell time.
51  * For the most reliable scan, set > AP beacon interval (typically 100msec). */
52 #define IWL_PASSIVE_DWELL_TIME_24   (20)       /* all times in msec */
53 #define IWL_PASSIVE_DWELL_TIME_52   (10)
54 #define IWL_PASSIVE_DWELL_BASE      (100)
55 #define IWL_CHANNEL_TUNE_TIME       5
56 
iwl_legacy_send_scan_abort(struct iwl_priv * priv)57 static int iwl_legacy_send_scan_abort(struct iwl_priv *priv)
58 {
59 	int ret;
60 	struct iwl_rx_packet *pkt;
61 	struct iwl_host_cmd cmd = {
62 		.id = REPLY_SCAN_ABORT_CMD,
63 		.flags = CMD_WANT_SKB,
64 	};
65 
66 	/* Exit instantly with error when device is not ready
67 	 * to receive scan abort command or it does not perform
68 	 * hardware scan currently */
69 	if (!test_bit(STATUS_READY, &priv->status) ||
70 	    !test_bit(STATUS_GEO_CONFIGURED, &priv->status) ||
71 	    !test_bit(STATUS_SCAN_HW, &priv->status) ||
72 	    test_bit(STATUS_FW_ERROR, &priv->status) ||
73 	    test_bit(STATUS_EXIT_PENDING, &priv->status))
74 		return -EIO;
75 
76 	ret = iwl_legacy_send_cmd_sync(priv, &cmd);
77 	if (ret)
78 		return ret;
79 
80 	pkt = (struct iwl_rx_packet *)cmd.reply_page;
81 	if (pkt->u.status != CAN_ABORT_STATUS) {
82 		/* The scan abort will return 1 for success or
83 		 * 2 for "failure".  A failure condition can be
84 		 * due to simply not being in an active scan which
85 		 * can occur if we send the scan abort before we
86 		 * the microcode has notified us that a scan is
87 		 * completed. */
88 		IWL_DEBUG_SCAN(priv, "SCAN_ABORT ret %d.\n", pkt->u.status);
89 		ret = -EIO;
90 	}
91 
92 	iwl_legacy_free_pages(priv, cmd.reply_page);
93 	return ret;
94 }
95 
iwl_legacy_complete_scan(struct iwl_priv * priv,bool aborted)96 static void iwl_legacy_complete_scan(struct iwl_priv *priv, bool aborted)
97 {
98 	/* check if scan was requested from mac80211 */
99 	if (priv->scan_request) {
100 		IWL_DEBUG_SCAN(priv, "Complete scan in mac80211\n");
101 		ieee80211_scan_completed(priv->hw, aborted);
102 	}
103 
104 	priv->is_internal_short_scan = false;
105 	priv->scan_vif = NULL;
106 	priv->scan_request = NULL;
107 }
108 
iwl_legacy_force_scan_end(struct iwl_priv * priv)109 void iwl_legacy_force_scan_end(struct iwl_priv *priv)
110 {
111 	lockdep_assert_held(&priv->mutex);
112 
113 	if (!test_bit(STATUS_SCANNING, &priv->status)) {
114 		IWL_DEBUG_SCAN(priv, "Forcing scan end while not scanning\n");
115 		return;
116 	}
117 
118 	IWL_DEBUG_SCAN(priv, "Forcing scan end\n");
119 	clear_bit(STATUS_SCANNING, &priv->status);
120 	clear_bit(STATUS_SCAN_HW, &priv->status);
121 	clear_bit(STATUS_SCAN_ABORTING, &priv->status);
122 	iwl_legacy_complete_scan(priv, true);
123 }
124 
iwl_legacy_do_scan_abort(struct iwl_priv * priv)125 static void iwl_legacy_do_scan_abort(struct iwl_priv *priv)
126 {
127 	int ret;
128 
129 	lockdep_assert_held(&priv->mutex);
130 
131 	if (!test_bit(STATUS_SCANNING, &priv->status)) {
132 		IWL_DEBUG_SCAN(priv, "Not performing scan to abort\n");
133 		return;
134 	}
135 
136 	if (test_and_set_bit(STATUS_SCAN_ABORTING, &priv->status)) {
137 		IWL_DEBUG_SCAN(priv, "Scan abort in progress\n");
138 		return;
139 	}
140 
141 	ret = iwl_legacy_send_scan_abort(priv);
142 	if (ret) {
143 		IWL_DEBUG_SCAN(priv, "Send scan abort failed %d\n", ret);
144 		iwl_legacy_force_scan_end(priv);
145 	} else
146 		IWL_DEBUG_SCAN(priv, "Successfully send scan abort\n");
147 }
148 
149 /**
150  * iwl_scan_cancel - Cancel any currently executing HW scan
151  */
iwl_legacy_scan_cancel(struct iwl_priv * priv)152 int iwl_legacy_scan_cancel(struct iwl_priv *priv)
153 {
154 	IWL_DEBUG_SCAN(priv, "Queuing abort scan\n");
155 	queue_work(priv->workqueue, &priv->abort_scan);
156 	return 0;
157 }
158 EXPORT_SYMBOL(iwl_legacy_scan_cancel);
159 
160 /**
161  * iwl_legacy_scan_cancel_timeout - Cancel any currently executing HW scan
162  * @ms: amount of time to wait (in milliseconds) for scan to abort
163  *
164  */
iwl_legacy_scan_cancel_timeout(struct iwl_priv * priv,unsigned long ms)165 int iwl_legacy_scan_cancel_timeout(struct iwl_priv *priv, unsigned long ms)
166 {
167 	unsigned long timeout = jiffies + msecs_to_jiffies(ms);
168 
169 	lockdep_assert_held(&priv->mutex);
170 
171 	IWL_DEBUG_SCAN(priv, "Scan cancel timeout\n");
172 
173 	iwl_legacy_do_scan_abort(priv);
174 
175 	while (time_before_eq(jiffies, timeout)) {
176 		if (!test_bit(STATUS_SCAN_HW, &priv->status))
177 			break;
178 		msleep(20);
179 	}
180 
181 	return test_bit(STATUS_SCAN_HW, &priv->status);
182 }
183 EXPORT_SYMBOL(iwl_legacy_scan_cancel_timeout);
184 
185 /* Service response to REPLY_SCAN_CMD (0x80) */
iwl_legacy_rx_reply_scan(struct iwl_priv * priv,struct iwl_rx_mem_buffer * rxb)186 static void iwl_legacy_rx_reply_scan(struct iwl_priv *priv,
187 			      struct iwl_rx_mem_buffer *rxb)
188 {
189 #ifdef CONFIG_IWLWIFI_LEGACY_DEBUG
190 	struct iwl_rx_packet *pkt = rxb_addr(rxb);
191 	struct iwl_scanreq_notification *notif =
192 	    (struct iwl_scanreq_notification *)pkt->u.raw;
193 
194 	IWL_DEBUG_SCAN(priv, "Scan request status = 0x%x\n", notif->status);
195 #endif
196 }
197 
198 /* Service SCAN_START_NOTIFICATION (0x82) */
iwl_legacy_rx_scan_start_notif(struct iwl_priv * priv,struct iwl_rx_mem_buffer * rxb)199 static void iwl_legacy_rx_scan_start_notif(struct iwl_priv *priv,
200 				    struct iwl_rx_mem_buffer *rxb)
201 {
202 	struct iwl_rx_packet *pkt = rxb_addr(rxb);
203 	struct iwl_scanstart_notification *notif =
204 	    (struct iwl_scanstart_notification *)pkt->u.raw;
205 	priv->scan_start_tsf = le32_to_cpu(notif->tsf_low);
206 	IWL_DEBUG_SCAN(priv, "Scan start: "
207 		       "%d [802.11%s] "
208 		       "(TSF: 0x%08X:%08X) - %d (beacon timer %u)\n",
209 		       notif->channel,
210 		       notif->band ? "bg" : "a",
211 		       le32_to_cpu(notif->tsf_high),
212 		       le32_to_cpu(notif->tsf_low),
213 		       notif->status, notif->beacon_timer);
214 }
215 
216 /* Service SCAN_RESULTS_NOTIFICATION (0x83) */
iwl_legacy_rx_scan_results_notif(struct iwl_priv * priv,struct iwl_rx_mem_buffer * rxb)217 static void iwl_legacy_rx_scan_results_notif(struct iwl_priv *priv,
218 				      struct iwl_rx_mem_buffer *rxb)
219 {
220 #ifdef CONFIG_IWLWIFI_LEGACY_DEBUG
221 	struct iwl_rx_packet *pkt = rxb_addr(rxb);
222 	struct iwl_scanresults_notification *notif =
223 	    (struct iwl_scanresults_notification *)pkt->u.raw;
224 
225 	IWL_DEBUG_SCAN(priv, "Scan ch.res: "
226 		       "%d [802.11%s] "
227 		       "(TSF: 0x%08X:%08X) - %d "
228 		       "elapsed=%lu usec\n",
229 		       notif->channel,
230 		       notif->band ? "bg" : "a",
231 		       le32_to_cpu(notif->tsf_high),
232 		       le32_to_cpu(notif->tsf_low),
233 		       le32_to_cpu(notif->statistics[0]),
234 		       le32_to_cpu(notif->tsf_low) - priv->scan_start_tsf);
235 #endif
236 }
237 
238 /* Service SCAN_COMPLETE_NOTIFICATION (0x84) */
iwl_legacy_rx_scan_complete_notif(struct iwl_priv * priv,struct iwl_rx_mem_buffer * rxb)239 static void iwl_legacy_rx_scan_complete_notif(struct iwl_priv *priv,
240 				       struct iwl_rx_mem_buffer *rxb)
241 {
242 
243 #ifdef CONFIG_IWLWIFI_LEGACY_DEBUG
244 	struct iwl_rx_packet *pkt = rxb_addr(rxb);
245 	struct iwl_scancomplete_notification *scan_notif = (void *)pkt->u.raw;
246 #endif
247 
248 	IWL_DEBUG_SCAN(priv,
249 			"Scan complete: %d channels (TSF 0x%08X:%08X) - %d\n",
250 		       scan_notif->scanned_channels,
251 		       scan_notif->tsf_low,
252 		       scan_notif->tsf_high, scan_notif->status);
253 
254 	/* The HW is no longer scanning */
255 	clear_bit(STATUS_SCAN_HW, &priv->status);
256 
257 	IWL_DEBUG_SCAN(priv, "Scan on %sGHz took %dms\n",
258 		       (priv->scan_band == IEEE80211_BAND_2GHZ) ? "2.4" : "5.2",
259 		       jiffies_to_msecs(jiffies - priv->scan_start));
260 
261 	queue_work(priv->workqueue, &priv->scan_completed);
262 }
263 
iwl_legacy_setup_rx_scan_handlers(struct iwl_priv * priv)264 void iwl_legacy_setup_rx_scan_handlers(struct iwl_priv *priv)
265 {
266 	/* scan handlers */
267 	priv->rx_handlers[REPLY_SCAN_CMD] = iwl_legacy_rx_reply_scan;
268 	priv->rx_handlers[SCAN_START_NOTIFICATION] =
269 					iwl_legacy_rx_scan_start_notif;
270 	priv->rx_handlers[SCAN_RESULTS_NOTIFICATION] =
271 					iwl_legacy_rx_scan_results_notif;
272 	priv->rx_handlers[SCAN_COMPLETE_NOTIFICATION] =
273 					iwl_legacy_rx_scan_complete_notif;
274 }
275 EXPORT_SYMBOL(iwl_legacy_setup_rx_scan_handlers);
276 
iwl_legacy_get_active_dwell_time(struct iwl_priv * priv,enum ieee80211_band band,u8 n_probes)277 inline u16 iwl_legacy_get_active_dwell_time(struct iwl_priv *priv,
278 				     enum ieee80211_band band,
279 				     u8 n_probes)
280 {
281 	if (band == IEEE80211_BAND_5GHZ)
282 		return IWL_ACTIVE_DWELL_TIME_52 +
283 			IWL_ACTIVE_DWELL_FACTOR_52GHZ * (n_probes + 1);
284 	else
285 		return IWL_ACTIVE_DWELL_TIME_24 +
286 			IWL_ACTIVE_DWELL_FACTOR_24GHZ * (n_probes + 1);
287 }
288 EXPORT_SYMBOL(iwl_legacy_get_active_dwell_time);
289 
iwl_legacy_get_passive_dwell_time(struct iwl_priv * priv,enum ieee80211_band band,struct ieee80211_vif * vif)290 u16 iwl_legacy_get_passive_dwell_time(struct iwl_priv *priv,
291 			       enum ieee80211_band band,
292 			       struct ieee80211_vif *vif)
293 {
294 	struct iwl_rxon_context *ctx;
295 	u16 passive = (band == IEEE80211_BAND_2GHZ) ?
296 	    IWL_PASSIVE_DWELL_BASE + IWL_PASSIVE_DWELL_TIME_24 :
297 	    IWL_PASSIVE_DWELL_BASE + IWL_PASSIVE_DWELL_TIME_52;
298 
299 	if (iwl_legacy_is_any_associated(priv)) {
300 		/*
301 		 * If we're associated, we clamp the maximum passive
302 		 * dwell time to be 98% of the smallest beacon interval
303 		 * (minus 2 * channel tune time)
304 		 */
305 		for_each_context(priv, ctx) {
306 			u16 value;
307 
308 			if (!iwl_legacy_is_associated_ctx(ctx))
309 				continue;
310 			value = ctx->vif ? ctx->vif->bss_conf.beacon_int : 0;
311 			if ((value > IWL_PASSIVE_DWELL_BASE) || !value)
312 				value = IWL_PASSIVE_DWELL_BASE;
313 			value = (value * 98) / 100 - IWL_CHANNEL_TUNE_TIME * 2;
314 			passive = min(value, passive);
315 		}
316 	}
317 
318 	return passive;
319 }
320 EXPORT_SYMBOL(iwl_legacy_get_passive_dwell_time);
321 
iwl_legacy_init_scan_params(struct iwl_priv * priv)322 void iwl_legacy_init_scan_params(struct iwl_priv *priv)
323 {
324 	u8 ant_idx = fls(priv->hw_params.valid_tx_ant) - 1;
325 	if (!priv->scan_tx_ant[IEEE80211_BAND_5GHZ])
326 		priv->scan_tx_ant[IEEE80211_BAND_5GHZ] = ant_idx;
327 	if (!priv->scan_tx_ant[IEEE80211_BAND_2GHZ])
328 		priv->scan_tx_ant[IEEE80211_BAND_2GHZ] = ant_idx;
329 }
330 EXPORT_SYMBOL(iwl_legacy_init_scan_params);
331 
iwl_legacy_scan_initiate(struct iwl_priv * priv,struct ieee80211_vif * vif,bool internal,enum ieee80211_band band)332 static int __must_check iwl_legacy_scan_initiate(struct iwl_priv *priv,
333 					  struct ieee80211_vif *vif,
334 					  bool internal,
335 					  enum ieee80211_band band)
336 {
337 	int ret;
338 
339 	lockdep_assert_held(&priv->mutex);
340 
341 	if (WARN_ON(!priv->cfg->ops->utils->request_scan))
342 		return -EOPNOTSUPP;
343 
344 	cancel_delayed_work(&priv->scan_check);
345 
346 	if (!iwl_legacy_is_ready_rf(priv)) {
347 		IWL_WARN(priv, "Request scan called when driver not ready.\n");
348 		return -EIO;
349 	}
350 
351 	if (test_bit(STATUS_SCAN_HW, &priv->status)) {
352 		IWL_DEBUG_SCAN(priv,
353 			"Multiple concurrent scan requests in parallel.\n");
354 		return -EBUSY;
355 	}
356 
357 	if (test_bit(STATUS_SCAN_ABORTING, &priv->status)) {
358 		IWL_DEBUG_SCAN(priv, "Scan request while abort pending.\n");
359 		return -EBUSY;
360 	}
361 
362 	IWL_DEBUG_SCAN(priv, "Starting %sscan...\n",
363 			internal ? "internal short " : "");
364 
365 	set_bit(STATUS_SCANNING, &priv->status);
366 	priv->is_internal_short_scan = internal;
367 	priv->scan_start = jiffies;
368 	priv->scan_band = band;
369 
370 	ret = priv->cfg->ops->utils->request_scan(priv, vif);
371 	if (ret) {
372 		clear_bit(STATUS_SCANNING, &priv->status);
373 		priv->is_internal_short_scan = false;
374 		return ret;
375 	}
376 
377 	queue_delayed_work(priv->workqueue, &priv->scan_check,
378 			   IWL_SCAN_CHECK_WATCHDOG);
379 
380 	return 0;
381 }
382 
iwl_legacy_mac_hw_scan(struct ieee80211_hw * hw,struct ieee80211_vif * vif,struct cfg80211_scan_request * req)383 int iwl_legacy_mac_hw_scan(struct ieee80211_hw *hw,
384 		    struct ieee80211_vif *vif,
385 		    struct cfg80211_scan_request *req)
386 {
387 	struct iwl_priv *priv = hw->priv;
388 	int ret;
389 
390 	IWL_DEBUG_MAC80211(priv, "enter\n");
391 
392 	if (req->n_channels == 0)
393 		return -EINVAL;
394 
395 	mutex_lock(&priv->mutex);
396 
397 	if (test_bit(STATUS_SCANNING, &priv->status) &&
398 	    !priv->is_internal_short_scan) {
399 		IWL_DEBUG_SCAN(priv, "Scan already in progress.\n");
400 		ret = -EAGAIN;
401 		goto out_unlock;
402 	}
403 
404 	/* mac80211 will only ask for one band at a time */
405 	priv->scan_request = req;
406 	priv->scan_vif = vif;
407 
408 	/*
409 	 * If an internal scan is in progress, just set
410 	 * up the scan_request as per above.
411 	 */
412 	if (priv->is_internal_short_scan) {
413 		IWL_DEBUG_SCAN(priv, "SCAN request during internal scan\n");
414 		ret = 0;
415 	} else
416 		ret = iwl_legacy_scan_initiate(priv, vif, false,
417 					req->channels[0]->band);
418 
419 	IWL_DEBUG_MAC80211(priv, "leave\n");
420 
421 out_unlock:
422 	mutex_unlock(&priv->mutex);
423 
424 	return ret;
425 }
426 EXPORT_SYMBOL(iwl_legacy_mac_hw_scan);
427 
428 /*
429  * internal short scan, this function should only been called while associated.
430  * It will reset and tune the radio to prevent possible RF related problem
431  */
iwl_legacy_internal_short_hw_scan(struct iwl_priv * priv)432 void iwl_legacy_internal_short_hw_scan(struct iwl_priv *priv)
433 {
434 	queue_work(priv->workqueue, &priv->start_internal_scan);
435 }
436 
iwl_legacy_bg_start_internal_scan(struct work_struct * work)437 static void iwl_legacy_bg_start_internal_scan(struct work_struct *work)
438 {
439 	struct iwl_priv *priv =
440 		container_of(work, struct iwl_priv, start_internal_scan);
441 
442 	IWL_DEBUG_SCAN(priv, "Start internal scan\n");
443 
444 	mutex_lock(&priv->mutex);
445 
446 	if (priv->is_internal_short_scan == true) {
447 		IWL_DEBUG_SCAN(priv, "Internal scan already in progress\n");
448 		goto unlock;
449 	}
450 
451 	if (test_bit(STATUS_SCANNING, &priv->status)) {
452 		IWL_DEBUG_SCAN(priv, "Scan already in progress.\n");
453 		goto unlock;
454 	}
455 
456 	if (iwl_legacy_scan_initiate(priv, NULL, true, priv->band))
457 		IWL_DEBUG_SCAN(priv, "failed to start internal short scan\n");
458  unlock:
459 	mutex_unlock(&priv->mutex);
460 }
461 
iwl_legacy_bg_scan_check(struct work_struct * data)462 static void iwl_legacy_bg_scan_check(struct work_struct *data)
463 {
464 	struct iwl_priv *priv =
465 	    container_of(data, struct iwl_priv, scan_check.work);
466 
467 	IWL_DEBUG_SCAN(priv, "Scan check work\n");
468 
469 	/* Since we are here firmware does not finish scan and
470 	 * most likely is in bad shape, so we don't bother to
471 	 * send abort command, just force scan complete to mac80211 */
472 	mutex_lock(&priv->mutex);
473 	iwl_legacy_force_scan_end(priv);
474 	mutex_unlock(&priv->mutex);
475 }
476 
477 /**
478  * iwl_legacy_fill_probe_req - fill in all required fields and IE for probe request
479  */
480 
481 u16
iwl_legacy_fill_probe_req(struct iwl_priv * priv,struct ieee80211_mgmt * frame,const u8 * ta,const u8 * ies,int ie_len,int left)482 iwl_legacy_fill_probe_req(struct iwl_priv *priv, struct ieee80211_mgmt *frame,
483 		       const u8 *ta, const u8 *ies, int ie_len, int left)
484 {
485 	int len = 0;
486 	u8 *pos = NULL;
487 
488 	/* Make sure there is enough space for the probe request,
489 	 * two mandatory IEs and the data */
490 	left -= 24;
491 	if (left < 0)
492 		return 0;
493 
494 	frame->frame_control = cpu_to_le16(IEEE80211_STYPE_PROBE_REQ);
495 	memcpy(frame->da, iwlegacy_bcast_addr, ETH_ALEN);
496 	memcpy(frame->sa, ta, ETH_ALEN);
497 	memcpy(frame->bssid, iwlegacy_bcast_addr, ETH_ALEN);
498 	frame->seq_ctrl = 0;
499 
500 	len += 24;
501 
502 	/* ...next IE... */
503 	pos = &frame->u.probe_req.variable[0];
504 
505 	/* fill in our indirect SSID IE */
506 	left -= 2;
507 	if (left < 0)
508 		return 0;
509 	*pos++ = WLAN_EID_SSID;
510 	*pos++ = 0;
511 
512 	len += 2;
513 
514 	if (WARN_ON(left < ie_len))
515 		return len;
516 
517 	if (ies && ie_len) {
518 		memcpy(pos, ies, ie_len);
519 		len += ie_len;
520 	}
521 
522 	return (u16)len;
523 }
524 EXPORT_SYMBOL(iwl_legacy_fill_probe_req);
525 
iwl_legacy_bg_abort_scan(struct work_struct * work)526 static void iwl_legacy_bg_abort_scan(struct work_struct *work)
527 {
528 	struct iwl_priv *priv = container_of(work, struct iwl_priv, abort_scan);
529 
530 	IWL_DEBUG_SCAN(priv, "Abort scan work\n");
531 
532 	/* We keep scan_check work queued in case when firmware will not
533 	 * report back scan completed notification */
534 	mutex_lock(&priv->mutex);
535 	iwl_legacy_scan_cancel_timeout(priv, 200);
536 	mutex_unlock(&priv->mutex);
537 }
538 
iwl_legacy_bg_scan_completed(struct work_struct * work)539 static void iwl_legacy_bg_scan_completed(struct work_struct *work)
540 {
541 	struct iwl_priv *priv =
542 	    container_of(work, struct iwl_priv, scan_completed);
543 	bool aborted;
544 
545 	IWL_DEBUG_SCAN(priv, "Completed %sscan.\n",
546 		       priv->is_internal_short_scan ? "internal short " : "");
547 
548 	cancel_delayed_work(&priv->scan_check);
549 
550 	mutex_lock(&priv->mutex);
551 
552 	aborted = test_and_clear_bit(STATUS_SCAN_ABORTING, &priv->status);
553 	if (aborted)
554 		IWL_DEBUG_SCAN(priv, "Aborted scan completed.\n");
555 
556 	if (!test_and_clear_bit(STATUS_SCANNING, &priv->status)) {
557 		IWL_DEBUG_SCAN(priv, "Scan already completed.\n");
558 		goto out_settings;
559 	}
560 
561 	if (priv->is_internal_short_scan && !aborted) {
562 		int err;
563 
564 		/* Check if mac80211 requested scan during our internal scan */
565 		if (priv->scan_request == NULL)
566 			goto out_complete;
567 
568 		/* If so request a new scan */
569 		err = iwl_legacy_scan_initiate(priv, priv->scan_vif, false,
570 					priv->scan_request->channels[0]->band);
571 		if (err) {
572 			IWL_DEBUG_SCAN(priv,
573 				"failed to initiate pending scan: %d\n", err);
574 			aborted = true;
575 			goto out_complete;
576 		}
577 
578 		goto out;
579 	}
580 
581 out_complete:
582 	iwl_legacy_complete_scan(priv, aborted);
583 
584 out_settings:
585 	/* Can we still talk to firmware ? */
586 	if (!iwl_legacy_is_ready_rf(priv))
587 		goto out;
588 
589 	/*
590 	 * We do not commit power settings while scan is pending,
591 	 * do it now if the settings changed.
592 	 */
593 	iwl_legacy_power_set_mode(priv, &priv->power_data.sleep_cmd_next,
594 								false);
595 	iwl_legacy_set_tx_power(priv, priv->tx_power_next, false);
596 
597 	priv->cfg->ops->utils->post_scan(priv);
598 
599 out:
600 	mutex_unlock(&priv->mutex);
601 }
602 
iwl_legacy_setup_scan_deferred_work(struct iwl_priv * priv)603 void iwl_legacy_setup_scan_deferred_work(struct iwl_priv *priv)
604 {
605 	INIT_WORK(&priv->scan_completed, iwl_legacy_bg_scan_completed);
606 	INIT_WORK(&priv->abort_scan, iwl_legacy_bg_abort_scan);
607 	INIT_WORK(&priv->start_internal_scan,
608 				iwl_legacy_bg_start_internal_scan);
609 	INIT_DELAYED_WORK(&priv->scan_check, iwl_legacy_bg_scan_check);
610 }
611 EXPORT_SYMBOL(iwl_legacy_setup_scan_deferred_work);
612 
iwl_legacy_cancel_scan_deferred_work(struct iwl_priv * priv)613 void iwl_legacy_cancel_scan_deferred_work(struct iwl_priv *priv)
614 {
615 	cancel_work_sync(&priv->start_internal_scan);
616 	cancel_work_sync(&priv->abort_scan);
617 	cancel_work_sync(&priv->scan_completed);
618 
619 	if (cancel_delayed_work_sync(&priv->scan_check)) {
620 		mutex_lock(&priv->mutex);
621 		iwl_legacy_force_scan_end(priv);
622 		mutex_unlock(&priv->mutex);
623 	}
624 }
625 EXPORT_SYMBOL(iwl_legacy_cancel_scan_deferred_work);
626