fix a kmap leak in virtio_console
[linux/fpc-iii.git] / drivers / net / wireless / mwifiex / sta_rx.c
blob4651d676df380c16f9ec8577a1f97e4ab72a4b8c
1 /*
2 * Marvell Wireless LAN device driver: station RX data handling
4 * Copyright (C) 2011, Marvell International Ltd.
6 * This software file (the "File") is distributed by Marvell International
7 * Ltd. under the terms of the GNU General Public License Version 2, June 1991
8 * (the "License"). You may use, redistribute and/or modify this File in
9 * accordance with the terms and conditions of the License, a copy of which
10 * is available by writing to the Free Software Foundation, Inc.,
11 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA or on the
12 * worldwide web at http://www.gnu.org/licenses/old-licenses/gpl-2.0.txt.
14 * THE FILE IS DISTRIBUTED AS-IS, WITHOUT WARRANTY OF ANY KIND, AND THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE
16 * ARE EXPRESSLY DISCLAIMED. The License provides additional details about
17 * this warranty disclaimer.
20 #include <uapi/linux/ipv6.h>
21 #include <net/ndisc.h>
22 #include "decl.h"
23 #include "ioctl.h"
24 #include "util.h"
25 #include "fw.h"
26 #include "main.h"
27 #include "11n_aggr.h"
28 #include "11n_rxreorder.h"
30 /* This function checks if a frame is IPv4 ARP or IPv6 Neighbour advertisement
31 * frame. If frame has both source and destination mac address as same, this
32 * function drops such gratuitous frames.
34 static bool
35 mwifiex_discard_gratuitous_arp(struct mwifiex_private *priv,
36 struct sk_buff *skb)
38 const struct mwifiex_arp_eth_header *arp;
39 struct ethhdr *eth;
40 struct ipv6hdr *ipv6;
41 struct icmp6hdr *icmpv6;
43 eth = (struct ethhdr *)skb->data;
44 switch (ntohs(eth->h_proto)) {
45 case ETH_P_ARP:
46 arp = (void *)(skb->data + sizeof(struct ethhdr));
47 if (arp->hdr.ar_op == htons(ARPOP_REPLY) ||
48 arp->hdr.ar_op == htons(ARPOP_REQUEST)) {
49 if (!memcmp(arp->ar_sip, arp->ar_tip, 4))
50 return true;
52 break;
53 case ETH_P_IPV6:
54 ipv6 = (void *)(skb->data + sizeof(struct ethhdr));
55 icmpv6 = (void *)(skb->data + sizeof(struct ethhdr) +
56 sizeof(struct ipv6hdr));
57 if (NDISC_NEIGHBOUR_ADVERTISEMENT == icmpv6->icmp6_type) {
58 if (!memcmp(&ipv6->saddr, &ipv6->daddr,
59 sizeof(struct in6_addr)))
60 return true;
62 break;
63 default:
64 break;
67 return false;
71 * This function processes the received packet and forwards it
72 * to kernel/upper layer.
74 * This function parses through the received packet and determines
75 * if it is a debug packet or normal packet.
77 * For non-debug packets, the function chops off unnecessary leading
78 * header bytes, reconstructs the packet as an ethernet frame or
79 * 802.2/llc/snap frame as required, and sends it to kernel/upper layer.
81 * The completion callback is called after processing in complete.
83 int mwifiex_process_rx_packet(struct mwifiex_private *priv,
84 struct sk_buff *skb)
86 int ret;
87 struct rx_packet_hdr *rx_pkt_hdr;
88 struct rxpd *local_rx_pd;
89 int hdr_chop;
90 struct ethhdr *eth;
92 local_rx_pd = (struct rxpd *) (skb->data);
94 rx_pkt_hdr = (void *)local_rx_pd +
95 le16_to_cpu(local_rx_pd->rx_pkt_offset);
97 if ((!memcmp(&rx_pkt_hdr->rfc1042_hdr, bridge_tunnel_header,
98 sizeof(bridge_tunnel_header))) ||
99 (!memcmp(&rx_pkt_hdr->rfc1042_hdr, rfc1042_header,
100 sizeof(rfc1042_header)) &&
101 ntohs(rx_pkt_hdr->rfc1042_hdr.snap_type) != ETH_P_AARP &&
102 ntohs(rx_pkt_hdr->rfc1042_hdr.snap_type) != ETH_P_IPX)) {
104 * Replace the 803 header and rfc1042 header (llc/snap) with an
105 * EthernetII header, keep the src/dst and snap_type
106 * (ethertype).
107 * The firmware only passes up SNAP frames converting
108 * all RX Data from 802.11 to 802.2/LLC/SNAP frames.
109 * To create the Ethernet II, just move the src, dst address
110 * right before the snap_type.
112 eth = (struct ethhdr *)
113 ((u8 *) &rx_pkt_hdr->eth803_hdr
114 + sizeof(rx_pkt_hdr->eth803_hdr) +
115 sizeof(rx_pkt_hdr->rfc1042_hdr)
116 - sizeof(rx_pkt_hdr->eth803_hdr.h_dest)
117 - sizeof(rx_pkt_hdr->eth803_hdr.h_source)
118 - sizeof(rx_pkt_hdr->rfc1042_hdr.snap_type));
120 memcpy(eth->h_source, rx_pkt_hdr->eth803_hdr.h_source,
121 sizeof(eth->h_source));
122 memcpy(eth->h_dest, rx_pkt_hdr->eth803_hdr.h_dest,
123 sizeof(eth->h_dest));
125 /* Chop off the rxpd + the excess memory from the 802.2/llc/snap
126 header that was removed. */
127 hdr_chop = (u8 *) eth - (u8 *) local_rx_pd;
128 } else {
129 /* Chop off the rxpd */
130 hdr_chop = (u8 *) &rx_pkt_hdr->eth803_hdr -
131 (u8 *) local_rx_pd;
134 /* Chop off the leading header bytes so the it points to the start of
135 either the reconstructed EthII frame or the 802.2/llc/snap frame */
136 skb_pull(skb, hdr_chop);
138 if (priv->hs2_enabled &&
139 mwifiex_discard_gratuitous_arp(priv, skb)) {
140 dev_dbg(priv->adapter->dev, "Bypassed Gratuitous ARP\n");
141 dev_kfree_skb_any(skb);
142 return 0;
145 priv->rxpd_rate = local_rx_pd->rx_rate;
147 priv->rxpd_htinfo = local_rx_pd->ht_info;
149 ret = mwifiex_recv_packet(priv, skb);
150 if (ret == -1)
151 dev_err(priv->adapter->dev, "recv packet failed\n");
153 return ret;
157 * This function processes the received buffer.
159 * The function looks into the RxPD and performs sanity tests on the
160 * received buffer to ensure its a valid packet, before processing it
161 * further. If the packet is determined to be aggregated, it is
162 * de-aggregated accordingly. Non-unicast packets are sent directly to
163 * the kernel/upper layers. Unicast packets are handed over to the
164 * Rx reordering routine if 11n is enabled.
166 * The completion callback is called after processing in complete.
168 int mwifiex_process_sta_rx_packet(struct mwifiex_private *priv,
169 struct sk_buff *skb)
171 struct mwifiex_adapter *adapter = priv->adapter;
172 int ret = 0;
173 struct rxpd *local_rx_pd;
174 struct rx_packet_hdr *rx_pkt_hdr;
175 u8 ta[ETH_ALEN];
176 u16 rx_pkt_type, rx_pkt_offset, rx_pkt_length, seq_num;
178 local_rx_pd = (struct rxpd *) (skb->data);
179 rx_pkt_type = le16_to_cpu(local_rx_pd->rx_pkt_type);
180 rx_pkt_offset = le16_to_cpu(local_rx_pd->rx_pkt_offset);
181 rx_pkt_length = le16_to_cpu(local_rx_pd->rx_pkt_length);
182 seq_num = le16_to_cpu(local_rx_pd->seq_num);
184 rx_pkt_hdr = (void *)local_rx_pd + rx_pkt_offset;
186 if ((rx_pkt_offset + rx_pkt_length) > (u16) skb->len) {
187 dev_err(adapter->dev,
188 "wrong rx packet: len=%d, rx_pkt_offset=%d, rx_pkt_length=%d\n",
189 skb->len, rx_pkt_offset, rx_pkt_length);
190 priv->stats.rx_dropped++;
191 dev_kfree_skb_any(skb);
192 return ret;
195 if (rx_pkt_type == PKT_TYPE_AMSDU) {
196 struct sk_buff_head list;
197 struct sk_buff *rx_skb;
199 __skb_queue_head_init(&list);
201 skb_pull(skb, rx_pkt_offset);
202 skb_trim(skb, rx_pkt_length);
204 ieee80211_amsdu_to_8023s(skb, &list, priv->curr_addr,
205 priv->wdev->iftype, 0, false);
207 while (!skb_queue_empty(&list)) {
208 rx_skb = __skb_dequeue(&list);
209 ret = mwifiex_recv_packet(priv, rx_skb);
210 if (ret == -1)
211 dev_err(adapter->dev, "Rx of A-MSDU failed");
213 return 0;
214 } else if (rx_pkt_type == PKT_TYPE_MGMT) {
215 ret = mwifiex_process_mgmt_packet(priv, skb);
216 if (ret)
217 dev_err(adapter->dev, "Rx of mgmt packet failed");
218 dev_kfree_skb_any(skb);
219 return ret;
223 * If the packet is not an unicast packet then send the packet
224 * directly to os. Don't pass thru rx reordering
226 if (!IS_11N_ENABLED(priv) ||
227 !ether_addr_equal_unaligned(priv->curr_addr, rx_pkt_hdr->eth803_hdr.h_dest)) {
228 mwifiex_process_rx_packet(priv, skb);
229 return ret;
232 if (mwifiex_queuing_ra_based(priv)) {
233 memcpy(ta, rx_pkt_hdr->eth803_hdr.h_source, ETH_ALEN);
234 } else {
235 if (rx_pkt_type != PKT_TYPE_BAR)
236 priv->rx_seq[local_rx_pd->priority] = seq_num;
237 memcpy(ta, priv->curr_bss_params.bss_descriptor.mac_address,
238 ETH_ALEN);
241 /* Reorder and send to OS */
242 ret = mwifiex_11n_rx_reorder_pkt(priv, seq_num, local_rx_pd->priority,
243 ta, (u8) rx_pkt_type, skb);
245 if (ret || (rx_pkt_type == PKT_TYPE_BAR))
246 dev_kfree_skb_any(skb);
248 if (ret)
249 priv->stats.rx_dropped++;
251 return ret;