1 // SPDX-License-Identifier: GPL-2.0
2 /******************************************************************************
5 * Copyright(c) 2007 - 2010 Realtek Corporation. All rights reserved.
6 * Linux device driver for RTL8192SU
8 * Modifications for inclusion into the Linux staging tree are
9 * Copyright(c) 2010 Larry Finger. All rights reserved.
11 * Contact information:
12 * WLAN FAE <wlanfae@realtek.com>
13 * Larry Finger <Larry.Finger@lwfinger.net>
15 ******************************************************************************/
17 #define _RTL871X_RECV_C_
20 #include <linux/if_ether.h>
21 #include <linux/etherdevice.h>
22 #include <linux/ieee80211.h>
23 #include <net/cfg80211.h>
25 #include "osdep_service.h"
26 #include "drv_types.h"
27 #include "recv_osdep.h"
28 #include "mlme_osdep.h"
33 static const u8 SNAP_ETH_TYPE_IPX[2] = {0x81, 0x37};
35 /* Datagram Delivery Protocol */
36 static const u8 SNAP_ETH_TYPE_APPLETALK_AARP[2] = {0x80, 0xf3};
38 void _r8712_init_sta_recv_priv(struct sta_recv_priv *psta_recvpriv)
40 memset((u8 *)psta_recvpriv, 0, sizeof(struct sta_recv_priv));
41 spin_lock_init(&psta_recvpriv->lock);
42 _init_queue(&psta_recvpriv->defrag_q);
45 int _r8712_init_recv_priv(struct recv_priv *precvpriv,
46 struct _adapter *padapter)
50 union recv_frame *precvframe;
52 memset((unsigned char *)precvpriv, 0, sizeof(struct recv_priv));
53 spin_lock_init(&precvpriv->lock);
54 _init_queue(&precvpriv->free_recv_queue);
55 _init_queue(&precvpriv->recv_pending_queue);
56 precvpriv->adapter = padapter;
57 precvpriv->free_recvframe_cnt = NR_RECVFRAME;
58 precvpriv->pallocated_frame_buf = kzalloc(NR_RECVFRAME *
59 sizeof(union recv_frame) + RXFRAME_ALIGN_SZ,
61 if (!precvpriv->pallocated_frame_buf)
63 precvpriv->precv_frame_buf = precvpriv->pallocated_frame_buf +
65 ((addr_t)(precvpriv->pallocated_frame_buf) &
66 (RXFRAME_ALIGN_SZ - 1));
67 precvframe = (union recv_frame *)precvpriv->precv_frame_buf;
68 for (i = 0; i < NR_RECVFRAME; i++) {
69 INIT_LIST_HEAD(&(precvframe->u.list));
70 list_add_tail(&(precvframe->u.list),
71 &(precvpriv->free_recv_queue.queue));
72 r8712_os_recv_resource_alloc(padapter, precvframe);
73 precvframe->u.hdr.adapter = padapter;
76 precvpriv->rx_pending_cnt = 1;
77 ret = r8712_init_recv_priv(precvpriv, padapter);
79 kfree(precvpriv->pallocated_frame_buf);
84 void _r8712_free_recv_priv(struct recv_priv *precvpriv)
86 kfree(precvpriv->pallocated_frame_buf);
87 r8712_free_recv_priv(precvpriv);
90 union recv_frame *r8712_alloc_recvframe(struct __queue *pfree_recv_queue)
93 union recv_frame *precvframe;
94 struct _adapter *padapter;
95 struct recv_priv *precvpriv;
97 spin_lock_irqsave(&pfree_recv_queue->lock, irqL);
98 precvframe = list_first_entry_or_null(&pfree_recv_queue->queue,
99 union recv_frame, u.hdr.list);
101 list_del_init(&precvframe->u.hdr.list);
102 padapter = precvframe->u.hdr.adapter;
104 precvpriv = &padapter->recvpriv;
105 if (pfree_recv_queue == &precvpriv->free_recv_queue)
106 precvpriv->free_recvframe_cnt--;
109 spin_unlock_irqrestore(&pfree_recv_queue->lock, irqL);
114 * caller : defrag; recvframe_chk_defrag in recv_thread (passive)
115 * pframequeue: defrag_queue : will be accessed in recv_thread (passive)
116 * using spin_lock to protect
118 void r8712_free_recvframe_queue(struct __queue *pframequeue,
119 struct __queue *pfree_recv_queue)
121 union recv_frame *precvframe;
122 struct list_head *plist, *phead;
124 spin_lock(&pframequeue->lock);
125 phead = &pframequeue->queue;
127 while (!end_of_queue_search(phead, plist)) {
128 precvframe = container_of(plist, union recv_frame, u.list);
130 r8712_free_recvframe(precvframe, pfree_recv_queue);
132 spin_unlock(&pframequeue->lock);
135 sint r8712_recvframe_chkmic(struct _adapter *adapter,
136 union recv_frame *precvframe)
138 sint i, res = _SUCCESS;
142 u8 *pframe, *payload, *pframemic;
143 u8 *mickey, idx, *iv;
144 struct sta_info *stainfo;
145 struct rx_pkt_attrib *prxattrib = &precvframe->u.hdr.attrib;
146 struct security_priv *psecuritypriv = &adapter->securitypriv;
148 stainfo = r8712_get_stainfo(&adapter->stapriv, &prxattrib->ta[0]);
149 if (prxattrib->encrypt == _TKIP_) {
150 /* calculate mic code */
152 if (is_multicast_ether_addr(prxattrib->ra)) {
153 iv = precvframe->u.hdr.rx_data +
156 mickey = &psecuritypriv->XGrprxmickey[(((idx >>
157 6) & 0x3)) - 1].skey[0];
158 if (!psecuritypriv->binstallGrpkey)
161 mickey = &stainfo->tkiprxmickey.skey[0];
163 /*icv_len included the mic code*/
164 datalen = precvframe->u.hdr.len - prxattrib->hdrlen -
165 prxattrib->iv_len - prxattrib->icv_len - 8;
166 pframe = precvframe->u.hdr.rx_data;
167 payload = pframe + prxattrib->hdrlen +
169 seccalctkipmic(mickey, pframe, payload, datalen,
171 (unsigned char)prxattrib->priority);
172 pframemic = payload + datalen;
174 for (i = 0; i < 8; i++) {
175 if (miccode[i] != *(pframemic + i))
179 if (prxattrib->bdecrypted)
180 r8712_handle_tkip_mic_err(adapter,
181 (u8)is_multicast_ether_addr(prxattrib->ra));
185 if (!psecuritypriv->bcheck_grpkey &&
186 is_multicast_ether_addr(prxattrib->ra))
187 psecuritypriv->bcheck_grpkey = true;
189 recvframe_pull_tail(precvframe, 8);
195 /* decrypt and set the ivlen,icvlen of the recv_frame */
196 union recv_frame *r8712_decryptor(struct _adapter *padapter,
197 union recv_frame *precv_frame)
199 struct rx_pkt_attrib *prxattrib = &precv_frame->u.hdr.attrib;
200 struct security_priv *psecuritypriv = &padapter->securitypriv;
201 union recv_frame *return_packet = precv_frame;
203 if ((prxattrib->encrypt > 0) && ((prxattrib->bdecrypted == 0) ||
204 psecuritypriv->sw_decrypt)) {
205 psecuritypriv->hw_decrypted = false;
206 switch (prxattrib->encrypt) {
209 r8712_wep_decrypt(padapter, (u8 *)precv_frame);
212 r8712_tkip_decrypt(padapter, (u8 *)precv_frame);
215 r8712_aes_decrypt(padapter, (u8 *)precv_frame);
220 } else if (prxattrib->bdecrypted == 1) {
221 psecuritypriv->hw_decrypted = true;
223 return return_packet;
226 /*###set the security information in the recv_frame */
227 union recv_frame *r8712_portctrl(struct _adapter *adapter,
228 union recv_frame *precv_frame)
232 struct recv_frame_hdr *pfhdr;
233 struct sta_info *psta;
234 struct sta_priv *pstapriv;
235 union recv_frame *prtnframe;
238 pstapriv = &adapter->stapriv;
239 ptr = precv_frame->u.hdr.rx_data;
240 pfhdr = &precv_frame->u.hdr;
241 psta_addr = pfhdr->attrib.ta;
242 psta = r8712_get_stainfo(pstapriv, psta_addr);
243 auth_alg = adapter->securitypriv.AuthAlgrthm;
246 ptr = ptr + pfhdr->attrib.hdrlen + LLC_HEADER_SIZE;
247 ether_type = get_unaligned_be16(ptr);
249 if (psta && psta->ieee8021x_blocked) {
251 * only accept EAPOL frame
253 if (ether_type == 0x888e) {
254 prtnframe = precv_frame;
257 r8712_free_recvframe(precv_frame,
258 &adapter->recvpriv.free_recv_queue);
263 * check decryption status, and decrypt the
266 prtnframe = precv_frame;
267 /* check is the EAPOL frame or not (Rekey) */
268 if (ether_type == 0x888e) {
270 prtnframe = precv_frame;
274 prtnframe = precv_frame;
279 static sint recv_decache(union recv_frame *precv_frame, u8 bretry,
280 struct stainfo_rxcache *prxcache)
282 sint tid = precv_frame->u.hdr.attrib.priority;
283 u16 seq_ctrl = ((precv_frame->u.hdr.attrib.seq_num & 0xffff) << 4) |
284 (precv_frame->u.hdr.attrib.frag_num & 0xf);
288 if (seq_ctrl == prxcache->tid_rxseq[tid])
290 prxcache->tid_rxseq[tid] = seq_ctrl;
294 static sint sta2sta_data_frame(struct _adapter *adapter,
295 union recv_frame *precv_frame,
296 struct sta_info **psta)
298 u8 *ptr = precv_frame->u.hdr.rx_data;
300 struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
301 struct sta_priv *pstapriv = &adapter->stapriv;
302 struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
303 u8 *mybssid = get_bssid(pmlmepriv);
304 u8 *myhwaddr = myid(&adapter->eeprompriv);
306 bool bmcast = is_multicast_ether_addr(pattrib->dst);
308 if (check_fwstate(pmlmepriv, WIFI_ADHOC_STATE) ||
309 check_fwstate(pmlmepriv, WIFI_ADHOC_MASTER_STATE)) {
310 /* filter packets that SA is myself or multicast or broadcast */
311 if (!memcmp(myhwaddr, pattrib->src, ETH_ALEN))
313 if ((memcmp(myhwaddr, pattrib->dst, ETH_ALEN)) && (!bmcast))
315 if (is_zero_ether_addr(pattrib->bssid) ||
316 is_zero_ether_addr(mybssid) ||
317 (memcmp(pattrib->bssid, mybssid, ETH_ALEN)))
319 sta_addr = pattrib->src;
320 } else if (check_fwstate(pmlmepriv, WIFI_STATION_STATE)) {
321 /* For Station mode, sa and bssid should always be BSSID,
322 * and DA is my mac-address
324 if (memcmp(pattrib->bssid, pattrib->src, ETH_ALEN))
326 sta_addr = pattrib->bssid;
327 } else if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
329 /* For AP mode, if DA == MCAST, then BSSID should
332 if (!is_multicast_ether_addr(pattrib->bssid))
334 } else { /* not mc-frame */
335 /* For AP mode, if DA is non-MCAST, then it must be
336 * BSSID, and bssid == BSSID
338 if (memcmp(pattrib->bssid, pattrib->dst, ETH_ALEN))
340 sta_addr = pattrib->src;
342 } else if (check_fwstate(pmlmepriv, WIFI_MP_STATE)) {
343 memcpy(pattrib->dst, GetAddr1Ptr(ptr), ETH_ALEN);
344 memcpy(pattrib->src, GetAddr2Ptr(ptr), ETH_ALEN);
345 memcpy(pattrib->bssid, GetAddr3Ptr(ptr), ETH_ALEN);
346 memcpy(pattrib->ra, pattrib->dst, ETH_ALEN);
347 memcpy(pattrib->ta, pattrib->src, ETH_ALEN);
353 *psta = r8712_get_bcmc_stainfo(adapter);
355 *psta = r8712_get_stainfo(pstapriv, sta_addr); /* get ap_info */
357 if (check_fwstate(pmlmepriv, WIFI_MP_STATE))
358 adapter->mppriv.rx_pktloss++;
364 static sint ap2sta_data_frame(struct _adapter *adapter,
365 union recv_frame *precv_frame,
366 struct sta_info **psta)
368 u8 *ptr = precv_frame->u.hdr.rx_data;
369 struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
370 struct sta_priv *pstapriv = &adapter->stapriv;
371 struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
372 u8 *mybssid = get_bssid(pmlmepriv);
373 u8 *myhwaddr = myid(&adapter->eeprompriv);
374 bool bmcast = is_multicast_ether_addr(pattrib->dst);
376 if (check_fwstate(pmlmepriv, WIFI_STATION_STATE) &&
377 check_fwstate(pmlmepriv, _FW_LINKED)) {
378 /* if NULL-frame, drop packet */
379 if ((GetFrameSubType(ptr)) == (IEEE80211_FTYPE_DATA | IEEE80211_STYPE_NULLFUNC))
381 /* drop QoS-SubType Data, including QoS NULL,
384 if ((GetFrameSubType(ptr) & WIFI_QOS_DATA_TYPE) ==
385 WIFI_QOS_DATA_TYPE) {
386 if (GetFrameSubType(ptr) & (BIT(4) | BIT(5) | BIT(6)))
390 /* filter packets that SA is myself or multicast or broadcast */
391 if (!memcmp(myhwaddr, pattrib->src, ETH_ALEN))
394 /* da should be for me */
395 if ((memcmp(myhwaddr, pattrib->dst, ETH_ALEN)) && (!bmcast))
398 if (is_zero_ether_addr(pattrib->bssid) ||
399 is_zero_ether_addr(mybssid) ||
400 (memcmp(pattrib->bssid, mybssid, ETH_ALEN)))
403 *psta = r8712_get_bcmc_stainfo(adapter);
405 *psta = r8712_get_stainfo(pstapriv, pattrib->bssid);
408 } else if (check_fwstate(pmlmepriv, WIFI_MP_STATE) &&
409 check_fwstate(pmlmepriv, _FW_LINKED)) {
410 memcpy(pattrib->dst, GetAddr1Ptr(ptr), ETH_ALEN);
411 memcpy(pattrib->src, GetAddr2Ptr(ptr), ETH_ALEN);
412 memcpy(pattrib->bssid, GetAddr3Ptr(ptr), ETH_ALEN);
413 memcpy(pattrib->ra, pattrib->dst, ETH_ALEN);
414 memcpy(pattrib->ta, pattrib->src, ETH_ALEN);
415 memcpy(pattrib->bssid, mybssid, ETH_ALEN);
416 *psta = r8712_get_stainfo(pstapriv, pattrib->bssid);
425 static sint sta2ap_data_frame(struct _adapter *adapter,
426 union recv_frame *precv_frame,
427 struct sta_info **psta)
429 struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
430 struct sta_priv *pstapriv = &adapter->stapriv;
431 struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
432 unsigned char *mybssid = get_bssid(pmlmepriv);
434 if (check_fwstate(pmlmepriv, WIFI_AP_STATE)) {
435 /* For AP mode, if DA is non-MCAST, then it must be BSSID,
437 * For AP mode, RA=BSSID, TX=STA(SRC_ADDR), A3=DST_ADDR
439 if (memcmp(pattrib->bssid, mybssid, ETH_ALEN))
441 *psta = r8712_get_stainfo(pstapriv, pattrib->src);
448 static sint validate_recv_ctrl_frame(struct _adapter *adapter,
449 union recv_frame *precv_frame)
454 static sint validate_recv_mgnt_frame(struct _adapter *adapter,
455 union recv_frame *precv_frame)
460 static sint validate_recv_data_frame(struct _adapter *adapter,
461 union recv_frame *precv_frame)
465 u8 *psa, *pda, *pbssid;
466 struct sta_info *psta = NULL;
467 u8 *ptr = precv_frame->u.hdr.rx_data;
468 struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
469 struct security_priv *psecuritypriv = &adapter->securitypriv;
471 bretry = GetRetry(ptr);
472 pda = ieee80211_get_DA((struct ieee80211_hdr *)ptr);
473 psa = ieee80211_get_SA((struct ieee80211_hdr *)ptr);
474 pbssid = get_hdr_bssid(ptr);
477 memcpy(pattrib->dst, pda, ETH_ALEN);
478 memcpy(pattrib->src, psa, ETH_ALEN);
479 memcpy(pattrib->bssid, pbssid, ETH_ALEN);
480 switch (pattrib->to_fr_ds) {
482 memcpy(pattrib->ra, pda, ETH_ALEN);
483 memcpy(pattrib->ta, psa, ETH_ALEN);
484 res = sta2sta_data_frame(adapter, precv_frame, &psta);
487 memcpy(pattrib->ra, pda, ETH_ALEN);
488 memcpy(pattrib->ta, pbssid, ETH_ALEN);
489 res = ap2sta_data_frame(adapter, precv_frame, &psta);
492 memcpy(pattrib->ra, pbssid, ETH_ALEN);
493 memcpy(pattrib->ta, psa, ETH_ALEN);
494 res = sta2ap_data_frame(adapter, precv_frame, &psta);
497 memcpy(pattrib->ra, GetAddr1Ptr(ptr), ETH_ALEN);
498 memcpy(pattrib->ta, GetAddr2Ptr(ptr), ETH_ALEN);
507 precv_frame->u.hdr.psta = psta;
509 /* parsing QC field */
510 if (pattrib->qos == 1) {
511 pattrib->priority = GetPriority((ptr + 24));
512 pattrib->ack_policy = GetAckpolicy((ptr + 24));
513 pattrib->amsdu = GetAMsdu((ptr + 24));
514 pattrib->hdrlen = pattrib->to_fr_ds == 3 ? 32 : 26;
516 pattrib->priority = 0;
517 pattrib->hdrlen = (pattrib->to_fr_ds == 3) ? 30 : 24;
520 if (pattrib->order)/*HT-CTRL 11n*/
521 pattrib->hdrlen += 4;
522 precv_frame->u.hdr.preorder_ctrl =
523 &psta->recvreorder_ctrl[pattrib->priority];
525 /* decache, drop duplicate recv packets */
526 if (recv_decache(precv_frame, bretry, &psta->sta_recvpriv.rxcache) ==
530 if (pattrib->privacy) {
531 GET_ENCRY_ALGO(psecuritypriv, psta, pattrib->encrypt,
532 is_multicast_ether_addr(pattrib->ra));
533 SET_ICE_IV_LEN(pattrib->iv_len, pattrib->icv_len,
536 pattrib->encrypt = 0;
537 pattrib->iv_len = pattrib->icv_len = 0;
542 sint r8712_validate_recv_frame(struct _adapter *adapter,
543 union recv_frame *precv_frame)
545 /*shall check frame subtype, to / from ds, da, bssid */
546 /*then call check if rx seq/frag. duplicated.*/
550 sint retval = _SUCCESS;
551 struct rx_pkt_attrib *pattrib = &precv_frame->u.hdr.attrib;
553 u8 *ptr = precv_frame->u.hdr.rx_data;
554 u8 ver = (unsigned char)(*ptr) & 0x3;
559 type = GetFrameType(ptr);
560 subtype = GetFrameSubType(ptr); /*bit(7)~bit(2)*/
561 pattrib->to_fr_ds = get_tofr_ds(ptr);
562 pattrib->frag_num = GetFragNum(ptr);
563 pattrib->seq_num = GetSequence(ptr);
564 pattrib->pw_save = GetPwrMgt(ptr);
565 pattrib->mfrag = GetMFrag(ptr);
566 pattrib->mdata = GetMData(ptr);
567 pattrib->privacy = GetPrivacy(ptr);
568 pattrib->order = GetOrder(ptr);
570 case IEEE80211_FTYPE_MGMT:
571 retval = validate_recv_mgnt_frame(adapter, precv_frame);
573 case IEEE80211_FTYPE_CTL:
574 retval = validate_recv_ctrl_frame(adapter, precv_frame);
576 case IEEE80211_FTYPE_DATA:
577 pattrib->qos = (subtype & BIT(7)) ? 1 : 0;
578 retval = validate_recv_data_frame(adapter, precv_frame);
586 int r8712_wlanhdr_to_ethhdr(union recv_frame *precvframe)
588 /*remove the wlanhdr and add the eth_hdr*/
593 struct ieee80211_snap_hdr *psnap;
594 struct _adapter *adapter = precvframe->u.hdr.adapter;
595 struct mlme_priv *pmlmepriv = &adapter->mlmepriv;
597 u8 *ptr = precvframe->u.hdr.rx_data; /*point to frame_ctrl field*/
598 struct rx_pkt_attrib *pattrib = &precvframe->u.hdr.attrib;
600 if (pattrib->encrypt)
601 recvframe_pull_tail(precvframe, pattrib->icv_len);
602 psnap = (struct ieee80211_snap_hdr *)(ptr + pattrib->hdrlen +
604 psnap_type = ptr + pattrib->hdrlen + pattrib->iv_len + SNAP_SIZE;
605 /* convert hdr + possible LLC headers into Ethernet header */
606 if ((!memcmp(psnap, (void *)rfc1042_header, SNAP_SIZE) &&
607 (memcmp(psnap_type, (void *)SNAP_ETH_TYPE_IPX, 2)) &&
608 (memcmp(psnap_type, (void *)SNAP_ETH_TYPE_APPLETALK_AARP, 2))) ||
609 !memcmp(psnap, (void *)bridge_tunnel_header, SNAP_SIZE)) {
610 /* remove RFC1042 or Bridge-Tunnel encapsulation and
615 /* Leave Ethernet header part of hdr and full payload */
618 rmv_len = pattrib->hdrlen + pattrib->iv_len +
619 (bsnaphdr ? SNAP_SIZE : 0);
620 len = precvframe->u.hdr.len - rmv_len;
621 if (check_fwstate(pmlmepriv, WIFI_MP_STATE)) {
625 /* append rx status for mp test packets */
626 ptr = recvframe_pull(precvframe, (rmv_len -
627 sizeof(struct ethhdr) + 2) - 24);
630 memcpy(ptr, get_rxmem(precvframe), 24);
633 ptr = recvframe_pull(precvframe, (rmv_len -
634 sizeof(struct ethhdr) + (bsnaphdr ? 2 : 0)));
639 memcpy(ptr, pattrib->dst, ETH_ALEN);
640 memcpy(ptr + ETH_ALEN, pattrib->src, ETH_ALEN);
642 __be16 be_tmp = htons(len);
644 memcpy(ptr + 12, &be_tmp, 2);
649 void r8712_recv_entry(union recv_frame *precvframe)
651 struct _adapter *padapter;
652 struct recv_priv *precvpriv;
656 padapter = precvframe->u.hdr.adapter;
657 precvpriv = &(padapter->recvpriv);
659 padapter->ledpriv.LedControlHandler(padapter, LED_CTL_RX);
661 ret = recv_func(padapter, precvframe);
663 goto _recv_entry_drop;
664 precvpriv->rx_pkts++;
665 precvpriv->rx_bytes += (uint)(precvframe->u.hdr.rx_tail -
666 precvframe->u.hdr.rx_data);
669 precvpriv->rx_drop++;
670 padapter->mppriv.rx_pktloss = precvpriv->rx_drop;