Back to home page

OSCL-LXR

 
 

    


0001 // SPDX-License-Identifier: GPL-2.0 OR BSD-3-Clause
0002 /*
0003  * Copyright (C) 2005-2014, 2018-2021 Intel Corporation
0004  * Copyright (C) 2013-2015 Intel Mobile Communications GmbH
0005  * Copyright (C) 2016-2017 Intel Deutschland GmbH
0006  */
0007 #include <linux/completion.h>
0008 #include <linux/dma-mapping.h>
0009 #include <linux/firmware.h>
0010 #include <linux/module.h>
0011 #include <linux/vmalloc.h>
0012 
0013 #include "iwl-drv.h"
0014 #include "iwl-csr.h"
0015 #include "iwl-debug.h"
0016 #include "iwl-trans.h"
0017 #include "iwl-op-mode.h"
0018 #include "iwl-agn-hw.h"
0019 #include "fw/img.h"
0020 #include "iwl-dbg-tlv.h"
0021 #include "iwl-config.h"
0022 #include "iwl-modparams.h"
0023 #include "fw/api/alive.h"
0024 #include "fw/api/mac.h"
0025 
0026 /******************************************************************************
0027  *
0028  * module boiler plate
0029  *
0030  ******************************************************************************/
0031 
0032 #define DRV_DESCRIPTION "Intel(R) Wireless WiFi driver for Linux"
0033 MODULE_DESCRIPTION(DRV_DESCRIPTION);
0034 MODULE_LICENSE("GPL");
0035 
0036 #ifdef CONFIG_IWLWIFI_DEBUGFS
0037 static struct dentry *iwl_dbgfs_root;
0038 #endif
0039 
0040 /**
0041  * struct iwl_drv - drv common data
0042  * @list: list of drv structures using this opmode
0043  * @fw: the iwl_fw structure
0044  * @op_mode: the running op_mode
0045  * @trans: transport layer
0046  * @dev: for debug prints only
0047  * @fw_index: firmware revision to try loading
0048  * @firmware_name: composite filename of ucode file to load
0049  * @request_firmware_complete: the firmware has been obtained from user space
0050  * @dbgfs_drv: debugfs root directory entry
0051  * @dbgfs_trans: debugfs transport directory entry
0052  * @dbgfs_op_mode: debugfs op_mode directory entry
0053  */
0054 struct iwl_drv {
0055     struct list_head list;
0056     struct iwl_fw fw;
0057 
0058     struct iwl_op_mode *op_mode;
0059     struct iwl_trans *trans;
0060     struct device *dev;
0061 
0062     int fw_index;                   /* firmware we're trying to load */
0063     char firmware_name[64];         /* name of firmware file to load */
0064 
0065     struct completion request_firmware_complete;
0066 
0067 #ifdef CONFIG_IWLWIFI_DEBUGFS
0068     struct dentry *dbgfs_drv;
0069     struct dentry *dbgfs_trans;
0070     struct dentry *dbgfs_op_mode;
0071 #endif
0072 };
0073 
0074 enum {
0075     DVM_OP_MODE,
0076     MVM_OP_MODE,
0077 };
0078 
0079 /* Protects the table contents, i.e. the ops pointer & drv list */
0080 static DEFINE_MUTEX(iwlwifi_opmode_table_mtx);
0081 static struct iwlwifi_opmode_table {
0082     const char *name;           /* name: iwldvm, iwlmvm, etc */
0083     const struct iwl_op_mode_ops *ops;  /* pointer to op_mode ops */
0084     struct list_head drv;       /* list of devices using this op_mode */
0085 } iwlwifi_opmode_table[] = {        /* ops set when driver is initialized */
0086     [DVM_OP_MODE] = { .name = "iwldvm", .ops = NULL },
0087     [MVM_OP_MODE] = { .name = "iwlmvm", .ops = NULL },
0088 };
0089 
0090 #define IWL_DEFAULT_SCAN_CHANNELS 40
0091 
0092 /*
0093  * struct fw_sec: Just for the image parsing process.
0094  * For the fw storage we are using struct fw_desc.
0095  */
0096 struct fw_sec {
0097     const void *data;       /* the sec data */
0098     size_t size;            /* section size */
0099     u32 offset;         /* offset of writing in the device */
0100 };
0101 
0102 static void iwl_free_fw_desc(struct iwl_drv *drv, struct fw_desc *desc)
0103 {
0104     vfree(desc->data);
0105     desc->data = NULL;
0106     desc->len = 0;
0107 }
0108 
0109 static void iwl_free_fw_img(struct iwl_drv *drv, struct fw_img *img)
0110 {
0111     int i;
0112     for (i = 0; i < img->num_sec; i++)
0113         iwl_free_fw_desc(drv, &img->sec[i]);
0114     kfree(img->sec);
0115 }
0116 
0117 static void iwl_dealloc_ucode(struct iwl_drv *drv)
0118 {
0119     int i;
0120 
0121     kfree(drv->fw.dbg.dest_tlv);
0122     for (i = 0; i < ARRAY_SIZE(drv->fw.dbg.conf_tlv); i++)
0123         kfree(drv->fw.dbg.conf_tlv[i]);
0124     for (i = 0; i < ARRAY_SIZE(drv->fw.dbg.trigger_tlv); i++)
0125         kfree(drv->fw.dbg.trigger_tlv[i]);
0126     kfree(drv->fw.dbg.mem_tlv);
0127     kfree(drv->fw.iml);
0128     kfree(drv->fw.ucode_capa.cmd_versions);
0129     kfree(drv->fw.phy_integration_ver);
0130 
0131     for (i = 0; i < IWL_UCODE_TYPE_MAX; i++)
0132         iwl_free_fw_img(drv, drv->fw.img + i);
0133 
0134     /* clear the data for the aborted load case */
0135     memset(&drv->fw, 0, sizeof(drv->fw));
0136 }
0137 
0138 static int iwl_alloc_fw_desc(struct iwl_drv *drv, struct fw_desc *desc,
0139                  struct fw_sec *sec)
0140 {
0141     void *data;
0142 
0143     desc->data = NULL;
0144 
0145     if (!sec || !sec->size)
0146         return -EINVAL;
0147 
0148     data = vmalloc(sec->size);
0149     if (!data)
0150         return -ENOMEM;
0151 
0152     desc->len = sec->size;
0153     desc->offset = sec->offset;
0154     memcpy(data, sec->data, desc->len);
0155     desc->data = data;
0156 
0157     return 0;
0158 }
0159 
0160 static void iwl_req_fw_callback(const struct firmware *ucode_raw,
0161                 void *context);
0162 
0163 static int iwl_request_firmware(struct iwl_drv *drv, bool first)
0164 {
0165     const struct iwl_cfg *cfg = drv->trans->cfg;
0166     char tag[8];
0167 
0168     if (drv->trans->trans_cfg->device_family == IWL_DEVICE_FAMILY_9000 &&
0169         (drv->trans->hw_rev_step != SILICON_B_STEP &&
0170          drv->trans->hw_rev_step != SILICON_C_STEP)) {
0171         IWL_ERR(drv,
0172             "Only HW steps B and C are currently supported (0x%0x)\n",
0173             drv->trans->hw_rev);
0174         return -EINVAL;
0175     }
0176 
0177     if (first) {
0178         drv->fw_index = cfg->ucode_api_max;
0179         sprintf(tag, "%d", drv->fw_index);
0180     } else {
0181         drv->fw_index--;
0182         sprintf(tag, "%d", drv->fw_index);
0183     }
0184 
0185     if (drv->fw_index < cfg->ucode_api_min) {
0186         IWL_ERR(drv, "no suitable firmware found!\n");
0187 
0188         if (cfg->ucode_api_min == cfg->ucode_api_max) {
0189             IWL_ERR(drv, "%s%d is required\n", cfg->fw_name_pre,
0190                 cfg->ucode_api_max);
0191         } else {
0192             IWL_ERR(drv, "minimum version required: %s%d\n",
0193                 cfg->fw_name_pre, cfg->ucode_api_min);
0194             IWL_ERR(drv, "maximum version supported: %s%d\n",
0195                 cfg->fw_name_pre, cfg->ucode_api_max);
0196         }
0197 
0198         IWL_ERR(drv,
0199             "check git://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git\n");
0200         return -ENOENT;
0201     }
0202 
0203     snprintf(drv->firmware_name, sizeof(drv->firmware_name), "%s%s.ucode",
0204          cfg->fw_name_pre, tag);
0205 
0206     IWL_DEBUG_FW_INFO(drv, "attempting to load firmware '%s'\n",
0207               drv->firmware_name);
0208 
0209     return request_firmware_nowait(THIS_MODULE, 1, drv->firmware_name,
0210                        drv->trans->dev,
0211                        GFP_KERNEL, drv, iwl_req_fw_callback);
0212 }
0213 
0214 struct fw_img_parsing {
0215     struct fw_sec *sec;
0216     int sec_counter;
0217 };
0218 
0219 /*
0220  * struct fw_sec_parsing: to extract fw section and it's offset from tlv
0221  */
0222 struct fw_sec_parsing {
0223     __le32 offset;
0224     const u8 data[];
0225 } __packed;
0226 
0227 /**
0228  * struct iwl_tlv_calib_data - parse the default calib data from TLV
0229  *
0230  * @ucode_type: the uCode to which the following default calib relates.
0231  * @calib: default calibrations.
0232  */
0233 struct iwl_tlv_calib_data {
0234     __le32 ucode_type;
0235     struct iwl_tlv_calib_ctrl calib;
0236 } __packed;
0237 
0238 struct iwl_firmware_pieces {
0239     struct fw_img_parsing img[IWL_UCODE_TYPE_MAX];
0240 
0241     u32 init_evtlog_ptr, init_evtlog_size, init_errlog_ptr;
0242     u32 inst_evtlog_ptr, inst_evtlog_size, inst_errlog_ptr;
0243 
0244     /* FW debug data parsed for driver usage */
0245     bool dbg_dest_tlv_init;
0246     const u8 *dbg_dest_ver;
0247     union {
0248         const struct iwl_fw_dbg_dest_tlv *dbg_dest_tlv;
0249         const struct iwl_fw_dbg_dest_tlv_v1 *dbg_dest_tlv_v1;
0250     };
0251     const struct iwl_fw_dbg_conf_tlv *dbg_conf_tlv[FW_DBG_CONF_MAX];
0252     size_t dbg_conf_tlv_len[FW_DBG_CONF_MAX];
0253     const struct iwl_fw_dbg_trigger_tlv *dbg_trigger_tlv[FW_DBG_TRIGGER_MAX];
0254     size_t dbg_trigger_tlv_len[FW_DBG_TRIGGER_MAX];
0255     struct iwl_fw_dbg_mem_seg_tlv *dbg_mem_tlv;
0256     size_t n_mem_tlv;
0257 };
0258 
0259 /*
0260  * These functions are just to extract uCode section data from the pieces
0261  * structure.
0262  */
0263 static struct fw_sec *get_sec(struct iwl_firmware_pieces *pieces,
0264                   enum iwl_ucode_type type,
0265                   int  sec)
0266 {
0267     return &pieces->img[type].sec[sec];
0268 }
0269 
0270 static void alloc_sec_data(struct iwl_firmware_pieces *pieces,
0271                enum iwl_ucode_type type,
0272                int sec)
0273 {
0274     struct fw_img_parsing *img = &pieces->img[type];
0275     struct fw_sec *sec_memory;
0276     int size = sec + 1;
0277     size_t alloc_size = sizeof(*img->sec) * size;
0278 
0279     if (img->sec && img->sec_counter >= size)
0280         return;
0281 
0282     sec_memory = krealloc(img->sec, alloc_size, GFP_KERNEL);
0283     if (!sec_memory)
0284         return;
0285 
0286     img->sec = sec_memory;
0287     img->sec_counter = size;
0288 }
0289 
0290 static void set_sec_data(struct iwl_firmware_pieces *pieces,
0291              enum iwl_ucode_type type,
0292              int sec,
0293              const void *data)
0294 {
0295     alloc_sec_data(pieces, type, sec);
0296 
0297     pieces->img[type].sec[sec].data = data;
0298 }
0299 
0300 static void set_sec_size(struct iwl_firmware_pieces *pieces,
0301              enum iwl_ucode_type type,
0302              int sec,
0303              size_t size)
0304 {
0305     alloc_sec_data(pieces, type, sec);
0306 
0307     pieces->img[type].sec[sec].size = size;
0308 }
0309 
0310 static size_t get_sec_size(struct iwl_firmware_pieces *pieces,
0311                enum iwl_ucode_type type,
0312                int sec)
0313 {
0314     return pieces->img[type].sec[sec].size;
0315 }
0316 
0317 static void set_sec_offset(struct iwl_firmware_pieces *pieces,
0318                enum iwl_ucode_type type,
0319                int sec,
0320                u32 offset)
0321 {
0322     alloc_sec_data(pieces, type, sec);
0323 
0324     pieces->img[type].sec[sec].offset = offset;
0325 }
0326 
0327 /*
0328  * Gets uCode section from tlv.
0329  */
0330 static int iwl_store_ucode_sec(struct iwl_firmware_pieces *pieces,
0331                    const void *data, enum iwl_ucode_type type,
0332                    int size)
0333 {
0334     struct fw_img_parsing *img;
0335     struct fw_sec *sec;
0336     const struct fw_sec_parsing *sec_parse;
0337     size_t alloc_size;
0338 
0339     if (WARN_ON(!pieces || !data || type >= IWL_UCODE_TYPE_MAX))
0340         return -1;
0341 
0342     sec_parse = (const struct fw_sec_parsing *)data;
0343 
0344     img = &pieces->img[type];
0345 
0346     alloc_size = sizeof(*img->sec) * (img->sec_counter + 1);
0347     sec = krealloc(img->sec, alloc_size, GFP_KERNEL);
0348     if (!sec)
0349         return -ENOMEM;
0350     img->sec = sec;
0351 
0352     sec = &img->sec[img->sec_counter];
0353 
0354     sec->offset = le32_to_cpu(sec_parse->offset);
0355     sec->data = sec_parse->data;
0356     sec->size = size - sizeof(sec_parse->offset);
0357 
0358     ++img->sec_counter;
0359 
0360     return 0;
0361 }
0362 
0363 static int iwl_set_default_calib(struct iwl_drv *drv, const u8 *data)
0364 {
0365     const struct iwl_tlv_calib_data *def_calib =
0366                     (const struct iwl_tlv_calib_data *)data;
0367     u32 ucode_type = le32_to_cpu(def_calib->ucode_type);
0368     if (ucode_type >= IWL_UCODE_TYPE_MAX) {
0369         IWL_ERR(drv, "Wrong ucode_type %u for default calibration.\n",
0370             ucode_type);
0371         return -EINVAL;
0372     }
0373     drv->fw.default_calib[ucode_type].flow_trigger =
0374         def_calib->calib.flow_trigger;
0375     drv->fw.default_calib[ucode_type].event_trigger =
0376         def_calib->calib.event_trigger;
0377 
0378     return 0;
0379 }
0380 
0381 static void iwl_set_ucode_api_flags(struct iwl_drv *drv, const u8 *data,
0382                     struct iwl_ucode_capabilities *capa)
0383 {
0384     const struct iwl_ucode_api *ucode_api = (const void *)data;
0385     u32 api_index = le32_to_cpu(ucode_api->api_index);
0386     u32 api_flags = le32_to_cpu(ucode_api->api_flags);
0387     int i;
0388 
0389     if (api_index >= DIV_ROUND_UP(NUM_IWL_UCODE_TLV_API, 32)) {
0390         IWL_WARN(drv,
0391              "api flags index %d larger than supported by driver\n",
0392              api_index);
0393         return;
0394     }
0395 
0396     for (i = 0; i < 32; i++) {
0397         if (api_flags & BIT(i))
0398             __set_bit(i + 32 * api_index, capa->_api);
0399     }
0400 }
0401 
0402 static void iwl_set_ucode_capabilities(struct iwl_drv *drv, const u8 *data,
0403                        struct iwl_ucode_capabilities *capa)
0404 {
0405     const struct iwl_ucode_capa *ucode_capa = (const void *)data;
0406     u32 api_index = le32_to_cpu(ucode_capa->api_index);
0407     u32 api_flags = le32_to_cpu(ucode_capa->api_capa);
0408     int i;
0409 
0410     if (api_index >= DIV_ROUND_UP(NUM_IWL_UCODE_TLV_CAPA, 32)) {
0411         IWL_WARN(drv,
0412              "capa flags index %d larger than supported by driver\n",
0413              api_index);
0414         return;
0415     }
0416 
0417     for (i = 0; i < 32; i++) {
0418         if (api_flags & BIT(i))
0419             __set_bit(i + 32 * api_index, capa->_capa);
0420     }
0421 }
0422 
0423 static const char *iwl_reduced_fw_name(struct iwl_drv *drv)
0424 {
0425     const char *name = drv->firmware_name;
0426 
0427     if (strncmp(name, "iwlwifi-", 8) == 0)
0428         name += 8;
0429 
0430     return name;
0431 }
0432 
0433 static int iwl_parse_v1_v2_firmware(struct iwl_drv *drv,
0434                     const struct firmware *ucode_raw,
0435                     struct iwl_firmware_pieces *pieces)
0436 {
0437     const struct iwl_ucode_header *ucode = (const void *)ucode_raw->data;
0438     u32 api_ver, hdr_size, build;
0439     char buildstr[25];
0440     const u8 *src;
0441 
0442     drv->fw.ucode_ver = le32_to_cpu(ucode->ver);
0443     api_ver = IWL_UCODE_API(drv->fw.ucode_ver);
0444 
0445     switch (api_ver) {
0446     default:
0447         hdr_size = 28;
0448         if (ucode_raw->size < hdr_size) {
0449             IWL_ERR(drv, "File size too small!\n");
0450             return -EINVAL;
0451         }
0452         build = le32_to_cpu(ucode->u.v2.build);
0453         set_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_INST,
0454                  le32_to_cpu(ucode->u.v2.inst_size));
0455         set_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_DATA,
0456                  le32_to_cpu(ucode->u.v2.data_size));
0457         set_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST,
0458                  le32_to_cpu(ucode->u.v2.init_size));
0459         set_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA,
0460                  le32_to_cpu(ucode->u.v2.init_data_size));
0461         src = ucode->u.v2.data;
0462         break;
0463     case 0:
0464     case 1:
0465     case 2:
0466         hdr_size = 24;
0467         if (ucode_raw->size < hdr_size) {
0468             IWL_ERR(drv, "File size too small!\n");
0469             return -EINVAL;
0470         }
0471         build = 0;
0472         set_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_INST,
0473                  le32_to_cpu(ucode->u.v1.inst_size));
0474         set_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_DATA,
0475                  le32_to_cpu(ucode->u.v1.data_size));
0476         set_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST,
0477                  le32_to_cpu(ucode->u.v1.init_size));
0478         set_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA,
0479                  le32_to_cpu(ucode->u.v1.init_data_size));
0480         src = ucode->u.v1.data;
0481         break;
0482     }
0483 
0484     if (build)
0485         sprintf(buildstr, " build %u", build);
0486     else
0487         buildstr[0] = '\0';
0488 
0489     snprintf(drv->fw.fw_version,
0490          sizeof(drv->fw.fw_version),
0491          "%u.%u.%u.%u%s %s",
0492          IWL_UCODE_MAJOR(drv->fw.ucode_ver),
0493          IWL_UCODE_MINOR(drv->fw.ucode_ver),
0494          IWL_UCODE_API(drv->fw.ucode_ver),
0495          IWL_UCODE_SERIAL(drv->fw.ucode_ver),
0496          buildstr, iwl_reduced_fw_name(drv));
0497 
0498     /* Verify size of file vs. image size info in file's header */
0499 
0500     if (ucode_raw->size != hdr_size +
0501         get_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_INST) +
0502         get_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_DATA) +
0503         get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST) +
0504         get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA)) {
0505 
0506         IWL_ERR(drv,
0507             "uCode file size %d does not match expected size\n",
0508             (int)ucode_raw->size);
0509         return -EINVAL;
0510     }
0511 
0512 
0513     set_sec_data(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_INST, src);
0514     src += get_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_INST);
0515     set_sec_offset(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_INST,
0516                IWLAGN_RTC_INST_LOWER_BOUND);
0517     set_sec_data(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_DATA, src);
0518     src += get_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_DATA);
0519     set_sec_offset(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_DATA,
0520                IWLAGN_RTC_DATA_LOWER_BOUND);
0521     set_sec_data(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST, src);
0522     src += get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST);
0523     set_sec_offset(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST,
0524                IWLAGN_RTC_INST_LOWER_BOUND);
0525     set_sec_data(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA, src);
0526     src += get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA);
0527     set_sec_offset(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA,
0528                IWLAGN_RTC_DATA_LOWER_BOUND);
0529     return 0;
0530 }
0531 
0532 static void iwl_drv_set_dump_exclude(struct iwl_drv *drv,
0533                      enum iwl_ucode_tlv_type tlv_type,
0534                      const void *tlv_data, u32 tlv_len)
0535 {
0536     const struct iwl_fw_dump_exclude *fw = tlv_data;
0537     struct iwl_dump_exclude *excl;
0538 
0539     if (tlv_len < sizeof(*fw))
0540         return;
0541 
0542     if (tlv_type == IWL_UCODE_TLV_SEC_TABLE_ADDR) {
0543         excl = &drv->fw.dump_excl[0];
0544 
0545         /* second time we find this, it's for WoWLAN */
0546         if (excl->addr)
0547             excl = &drv->fw.dump_excl_wowlan[0];
0548     } else if (fw_has_capa(&drv->fw.ucode_capa,
0549                    IWL_UCODE_TLV_CAPA_CNSLDTD_D3_D0_IMG)) {
0550         /* IWL_UCODE_TLV_D3_KEK_KCK_ADDR is regular image */
0551         excl = &drv->fw.dump_excl[0];
0552     } else {
0553         /* IWL_UCODE_TLV_D3_KEK_KCK_ADDR is WoWLAN image */
0554         excl = &drv->fw.dump_excl_wowlan[0];
0555     }
0556 
0557     if (excl->addr)
0558         excl++;
0559 
0560     if (excl->addr) {
0561         IWL_DEBUG_FW_INFO(drv, "found too many excludes in fw file\n");
0562         return;
0563     }
0564 
0565     excl->addr = le32_to_cpu(fw->addr) & ~FW_ADDR_CACHE_CONTROL;
0566     excl->size = le32_to_cpu(fw->size);
0567 }
0568 
0569 static void iwl_parse_dbg_tlv_assert_tables(struct iwl_drv *drv,
0570                         const struct iwl_ucode_tlv *tlv)
0571 {
0572     const struct iwl_fw_ini_region_tlv *region;
0573     u32 length = le32_to_cpu(tlv->length);
0574     u32 addr;
0575 
0576     if (length < offsetof(typeof(*region), special_mem) +
0577              sizeof(region->special_mem))
0578         return;
0579 
0580     region = (const void *)tlv->data;
0581     addr = le32_to_cpu(region->special_mem.base_addr);
0582     addr += le32_to_cpu(region->special_mem.offset);
0583     addr &= ~FW_ADDR_CACHE_CONTROL;
0584 
0585     if (region->type != IWL_FW_INI_REGION_SPECIAL_DEVICE_MEMORY)
0586         return;
0587 
0588     switch (region->sub_type) {
0589     case IWL_FW_INI_REGION_DEVICE_MEMORY_SUBTYPE_UMAC_ERROR_TABLE:
0590         drv->trans->dbg.umac_error_event_table = addr;
0591         drv->trans->dbg.error_event_table_tlv_status |=
0592             IWL_ERROR_EVENT_TABLE_UMAC;
0593         break;
0594     case IWL_FW_INI_REGION_DEVICE_MEMORY_SUBTYPE_LMAC_1_ERROR_TABLE:
0595         drv->trans->dbg.lmac_error_event_table[0] = addr;
0596         drv->trans->dbg.error_event_table_tlv_status |=
0597             IWL_ERROR_EVENT_TABLE_LMAC1;
0598         break;
0599     case IWL_FW_INI_REGION_DEVICE_MEMORY_SUBTYPE_LMAC_2_ERROR_TABLE:
0600         drv->trans->dbg.lmac_error_event_table[1] = addr;
0601         drv->trans->dbg.error_event_table_tlv_status |=
0602             IWL_ERROR_EVENT_TABLE_LMAC2;
0603         break;
0604     case IWL_FW_INI_REGION_DEVICE_MEMORY_SUBTYPE_TCM_1_ERROR_TABLE:
0605         drv->trans->dbg.tcm_error_event_table[0] = addr;
0606         drv->trans->dbg.error_event_table_tlv_status |=
0607             IWL_ERROR_EVENT_TABLE_TCM1;
0608         break;
0609     case IWL_FW_INI_REGION_DEVICE_MEMORY_SUBTYPE_TCM_2_ERROR_TABLE:
0610         drv->trans->dbg.tcm_error_event_table[1] = addr;
0611         drv->trans->dbg.error_event_table_tlv_status |=
0612             IWL_ERROR_EVENT_TABLE_TCM2;
0613         break;
0614     case IWL_FW_INI_REGION_DEVICE_MEMORY_SUBTYPE_RCM_1_ERROR_TABLE:
0615         drv->trans->dbg.rcm_error_event_table[0] = addr;
0616         drv->trans->dbg.error_event_table_tlv_status |=
0617             IWL_ERROR_EVENT_TABLE_RCM1;
0618         break;
0619     case IWL_FW_INI_REGION_DEVICE_MEMORY_SUBTYPE_RCM_2_ERROR_TABLE:
0620         drv->trans->dbg.rcm_error_event_table[1] = addr;
0621         drv->trans->dbg.error_event_table_tlv_status |=
0622             IWL_ERROR_EVENT_TABLE_RCM2;
0623         break;
0624     default:
0625         break;
0626     }
0627 }
0628 
0629 static int iwl_parse_tlv_firmware(struct iwl_drv *drv,
0630                 const struct firmware *ucode_raw,
0631                 struct iwl_firmware_pieces *pieces,
0632                 struct iwl_ucode_capabilities *capa,
0633                 bool *usniffer_images)
0634 {
0635     const struct iwl_tlv_ucode_header *ucode = (const void *)ucode_raw->data;
0636     const struct iwl_ucode_tlv *tlv;
0637     size_t len = ucode_raw->size;
0638     const u8 *data;
0639     u32 tlv_len;
0640     u32 usniffer_img;
0641     enum iwl_ucode_tlv_type tlv_type;
0642     const u8 *tlv_data;
0643     char buildstr[25];
0644     u32 build, paging_mem_size;
0645     int num_of_cpus;
0646     bool usniffer_req = false;
0647 
0648     if (len < sizeof(*ucode)) {
0649         IWL_ERR(drv, "uCode has invalid length: %zd\n", len);
0650         return -EINVAL;
0651     }
0652 
0653     if (ucode->magic != cpu_to_le32(IWL_TLV_UCODE_MAGIC)) {
0654         IWL_ERR(drv, "invalid uCode magic: 0X%x\n",
0655             le32_to_cpu(ucode->magic));
0656         return -EINVAL;
0657     }
0658 
0659     drv->fw.ucode_ver = le32_to_cpu(ucode->ver);
0660     memcpy(drv->fw.human_readable, ucode->human_readable,
0661            sizeof(drv->fw.human_readable));
0662     build = le32_to_cpu(ucode->build);
0663 
0664     if (build)
0665         sprintf(buildstr, " build %u", build);
0666     else
0667         buildstr[0] = '\0';
0668 
0669     snprintf(drv->fw.fw_version,
0670          sizeof(drv->fw.fw_version),
0671          "%u.%u.%u.%u%s %s",
0672          IWL_UCODE_MAJOR(drv->fw.ucode_ver),
0673          IWL_UCODE_MINOR(drv->fw.ucode_ver),
0674          IWL_UCODE_API(drv->fw.ucode_ver),
0675          IWL_UCODE_SERIAL(drv->fw.ucode_ver),
0676          buildstr, iwl_reduced_fw_name(drv));
0677 
0678     data = ucode->data;
0679 
0680     len -= sizeof(*ucode);
0681 
0682     while (len >= sizeof(*tlv)) {
0683         len -= sizeof(*tlv);
0684 
0685         tlv = (const void *)data;
0686         tlv_len = le32_to_cpu(tlv->length);
0687         tlv_type = le32_to_cpu(tlv->type);
0688         tlv_data = tlv->data;
0689 
0690         if (len < tlv_len) {
0691             IWL_ERR(drv, "invalid TLV len: %zd/%u\n",
0692                 len, tlv_len);
0693             return -EINVAL;
0694         }
0695         len -= ALIGN(tlv_len, 4);
0696         data += sizeof(*tlv) + ALIGN(tlv_len, 4);
0697 
0698         switch (tlv_type) {
0699         case IWL_UCODE_TLV_INST:
0700             set_sec_data(pieces, IWL_UCODE_REGULAR,
0701                      IWL_UCODE_SECTION_INST, tlv_data);
0702             set_sec_size(pieces, IWL_UCODE_REGULAR,
0703                      IWL_UCODE_SECTION_INST, tlv_len);
0704             set_sec_offset(pieces, IWL_UCODE_REGULAR,
0705                        IWL_UCODE_SECTION_INST,
0706                        IWLAGN_RTC_INST_LOWER_BOUND);
0707             break;
0708         case IWL_UCODE_TLV_DATA:
0709             set_sec_data(pieces, IWL_UCODE_REGULAR,
0710                      IWL_UCODE_SECTION_DATA, tlv_data);
0711             set_sec_size(pieces, IWL_UCODE_REGULAR,
0712                      IWL_UCODE_SECTION_DATA, tlv_len);
0713             set_sec_offset(pieces, IWL_UCODE_REGULAR,
0714                        IWL_UCODE_SECTION_DATA,
0715                        IWLAGN_RTC_DATA_LOWER_BOUND);
0716             break;
0717         case IWL_UCODE_TLV_INIT:
0718             set_sec_data(pieces, IWL_UCODE_INIT,
0719                      IWL_UCODE_SECTION_INST, tlv_data);
0720             set_sec_size(pieces, IWL_UCODE_INIT,
0721                      IWL_UCODE_SECTION_INST, tlv_len);
0722             set_sec_offset(pieces, IWL_UCODE_INIT,
0723                        IWL_UCODE_SECTION_INST,
0724                        IWLAGN_RTC_INST_LOWER_BOUND);
0725             break;
0726         case IWL_UCODE_TLV_INIT_DATA:
0727             set_sec_data(pieces, IWL_UCODE_INIT,
0728                      IWL_UCODE_SECTION_DATA, tlv_data);
0729             set_sec_size(pieces, IWL_UCODE_INIT,
0730                      IWL_UCODE_SECTION_DATA, tlv_len);
0731             set_sec_offset(pieces, IWL_UCODE_INIT,
0732                        IWL_UCODE_SECTION_DATA,
0733                        IWLAGN_RTC_DATA_LOWER_BOUND);
0734             break;
0735         case IWL_UCODE_TLV_BOOT:
0736             IWL_ERR(drv, "Found unexpected BOOT ucode\n");
0737             break;
0738         case IWL_UCODE_TLV_PROBE_MAX_LEN:
0739             if (tlv_len != sizeof(u32))
0740                 goto invalid_tlv_len;
0741             capa->max_probe_length =
0742                     le32_to_cpup((const __le32 *)tlv_data);
0743             break;
0744         case IWL_UCODE_TLV_PAN:
0745             if (tlv_len)
0746                 goto invalid_tlv_len;
0747             capa->flags |= IWL_UCODE_TLV_FLAGS_PAN;
0748             break;
0749         case IWL_UCODE_TLV_FLAGS:
0750             /* must be at least one u32 */
0751             if (tlv_len < sizeof(u32))
0752                 goto invalid_tlv_len;
0753             /* and a proper number of u32s */
0754             if (tlv_len % sizeof(u32))
0755                 goto invalid_tlv_len;
0756             /*
0757              * This driver only reads the first u32 as
0758              * right now no more features are defined,
0759              * if that changes then either the driver
0760              * will not work with the new firmware, or
0761              * it'll not take advantage of new features.
0762              */
0763             capa->flags = le32_to_cpup((const __le32 *)tlv_data);
0764             break;
0765         case IWL_UCODE_TLV_API_CHANGES_SET:
0766             if (tlv_len != sizeof(struct iwl_ucode_api))
0767                 goto invalid_tlv_len;
0768             iwl_set_ucode_api_flags(drv, tlv_data, capa);
0769             break;
0770         case IWL_UCODE_TLV_ENABLED_CAPABILITIES:
0771             if (tlv_len != sizeof(struct iwl_ucode_capa))
0772                 goto invalid_tlv_len;
0773             iwl_set_ucode_capabilities(drv, tlv_data, capa);
0774             break;
0775         case IWL_UCODE_TLV_INIT_EVTLOG_PTR:
0776             if (tlv_len != sizeof(u32))
0777                 goto invalid_tlv_len;
0778             pieces->init_evtlog_ptr =
0779                     le32_to_cpup((const __le32 *)tlv_data);
0780             break;
0781         case IWL_UCODE_TLV_INIT_EVTLOG_SIZE:
0782             if (tlv_len != sizeof(u32))
0783                 goto invalid_tlv_len;
0784             pieces->init_evtlog_size =
0785                     le32_to_cpup((const __le32 *)tlv_data);
0786             break;
0787         case IWL_UCODE_TLV_INIT_ERRLOG_PTR:
0788             if (tlv_len != sizeof(u32))
0789                 goto invalid_tlv_len;
0790             pieces->init_errlog_ptr =
0791                     le32_to_cpup((const __le32 *)tlv_data);
0792             break;
0793         case IWL_UCODE_TLV_RUNT_EVTLOG_PTR:
0794             if (tlv_len != sizeof(u32))
0795                 goto invalid_tlv_len;
0796             pieces->inst_evtlog_ptr =
0797                     le32_to_cpup((const __le32 *)tlv_data);
0798             break;
0799         case IWL_UCODE_TLV_RUNT_EVTLOG_SIZE:
0800             if (tlv_len != sizeof(u32))
0801                 goto invalid_tlv_len;
0802             pieces->inst_evtlog_size =
0803                     le32_to_cpup((const __le32 *)tlv_data);
0804             break;
0805         case IWL_UCODE_TLV_RUNT_ERRLOG_PTR:
0806             if (tlv_len != sizeof(u32))
0807                 goto invalid_tlv_len;
0808             pieces->inst_errlog_ptr =
0809                     le32_to_cpup((const __le32 *)tlv_data);
0810             break;
0811         case IWL_UCODE_TLV_ENHANCE_SENS_TBL:
0812             if (tlv_len)
0813                 goto invalid_tlv_len;
0814             drv->fw.enhance_sensitivity_table = true;
0815             break;
0816         case IWL_UCODE_TLV_WOWLAN_INST:
0817             set_sec_data(pieces, IWL_UCODE_WOWLAN,
0818                      IWL_UCODE_SECTION_INST, tlv_data);
0819             set_sec_size(pieces, IWL_UCODE_WOWLAN,
0820                      IWL_UCODE_SECTION_INST, tlv_len);
0821             set_sec_offset(pieces, IWL_UCODE_WOWLAN,
0822                        IWL_UCODE_SECTION_INST,
0823                        IWLAGN_RTC_INST_LOWER_BOUND);
0824             break;
0825         case IWL_UCODE_TLV_WOWLAN_DATA:
0826             set_sec_data(pieces, IWL_UCODE_WOWLAN,
0827                      IWL_UCODE_SECTION_DATA, tlv_data);
0828             set_sec_size(pieces, IWL_UCODE_WOWLAN,
0829                      IWL_UCODE_SECTION_DATA, tlv_len);
0830             set_sec_offset(pieces, IWL_UCODE_WOWLAN,
0831                        IWL_UCODE_SECTION_DATA,
0832                        IWLAGN_RTC_DATA_LOWER_BOUND);
0833             break;
0834         case IWL_UCODE_TLV_PHY_CALIBRATION_SIZE:
0835             if (tlv_len != sizeof(u32))
0836                 goto invalid_tlv_len;
0837             capa->standard_phy_calibration_size =
0838                     le32_to_cpup((const __le32 *)tlv_data);
0839             break;
0840         case IWL_UCODE_TLV_SEC_RT:
0841             iwl_store_ucode_sec(pieces, tlv_data, IWL_UCODE_REGULAR,
0842                         tlv_len);
0843             drv->fw.type = IWL_FW_MVM;
0844             break;
0845         case IWL_UCODE_TLV_SEC_INIT:
0846             iwl_store_ucode_sec(pieces, tlv_data, IWL_UCODE_INIT,
0847                         tlv_len);
0848             drv->fw.type = IWL_FW_MVM;
0849             break;
0850         case IWL_UCODE_TLV_SEC_WOWLAN:
0851             iwl_store_ucode_sec(pieces, tlv_data, IWL_UCODE_WOWLAN,
0852                         tlv_len);
0853             drv->fw.type = IWL_FW_MVM;
0854             break;
0855         case IWL_UCODE_TLV_DEF_CALIB:
0856             if (tlv_len != sizeof(struct iwl_tlv_calib_data))
0857                 goto invalid_tlv_len;
0858             if (iwl_set_default_calib(drv, tlv_data))
0859                 goto tlv_error;
0860             break;
0861         case IWL_UCODE_TLV_PHY_SKU:
0862             if (tlv_len != sizeof(u32))
0863                 goto invalid_tlv_len;
0864             drv->fw.phy_config = le32_to_cpup((const __le32 *)tlv_data);
0865             drv->fw.valid_tx_ant = (drv->fw.phy_config &
0866                         FW_PHY_CFG_TX_CHAIN) >>
0867                         FW_PHY_CFG_TX_CHAIN_POS;
0868             drv->fw.valid_rx_ant = (drv->fw.phy_config &
0869                         FW_PHY_CFG_RX_CHAIN) >>
0870                         FW_PHY_CFG_RX_CHAIN_POS;
0871             break;
0872         case IWL_UCODE_TLV_SECURE_SEC_RT:
0873             iwl_store_ucode_sec(pieces, tlv_data, IWL_UCODE_REGULAR,
0874                         tlv_len);
0875             drv->fw.type = IWL_FW_MVM;
0876             break;
0877         case IWL_UCODE_TLV_SECURE_SEC_INIT:
0878             iwl_store_ucode_sec(pieces, tlv_data, IWL_UCODE_INIT,
0879                         tlv_len);
0880             drv->fw.type = IWL_FW_MVM;
0881             break;
0882         case IWL_UCODE_TLV_SECURE_SEC_WOWLAN:
0883             iwl_store_ucode_sec(pieces, tlv_data, IWL_UCODE_WOWLAN,
0884                         tlv_len);
0885             drv->fw.type = IWL_FW_MVM;
0886             break;
0887         case IWL_UCODE_TLV_NUM_OF_CPU:
0888             if (tlv_len != sizeof(u32))
0889                 goto invalid_tlv_len;
0890             num_of_cpus =
0891                 le32_to_cpup((const __le32 *)tlv_data);
0892 
0893             if (num_of_cpus == 2) {
0894                 drv->fw.img[IWL_UCODE_REGULAR].is_dual_cpus =
0895                     true;
0896                 drv->fw.img[IWL_UCODE_INIT].is_dual_cpus =
0897                     true;
0898                 drv->fw.img[IWL_UCODE_WOWLAN].is_dual_cpus =
0899                     true;
0900             } else if ((num_of_cpus > 2) || (num_of_cpus < 1)) {
0901                 IWL_ERR(drv, "Driver support upto 2 CPUs\n");
0902                 return -EINVAL;
0903             }
0904             break;
0905         case IWL_UCODE_TLV_N_SCAN_CHANNELS:
0906             if (tlv_len != sizeof(u32))
0907                 goto invalid_tlv_len;
0908             capa->n_scan_channels =
0909                 le32_to_cpup((const __le32 *)tlv_data);
0910             break;
0911         case IWL_UCODE_TLV_FW_VERSION: {
0912             const __le32 *ptr = (const void *)tlv_data;
0913             u32 major, minor;
0914             u8 local_comp;
0915 
0916             if (tlv_len != sizeof(u32) * 3)
0917                 goto invalid_tlv_len;
0918 
0919             major = le32_to_cpup(ptr++);
0920             minor = le32_to_cpup(ptr++);
0921             local_comp = le32_to_cpup(ptr);
0922 
0923             if (major >= 35)
0924                 snprintf(drv->fw.fw_version,
0925                      sizeof(drv->fw.fw_version),
0926                     "%u.%08x.%u %s", major, minor,
0927                     local_comp, iwl_reduced_fw_name(drv));
0928             else
0929                 snprintf(drv->fw.fw_version,
0930                      sizeof(drv->fw.fw_version),
0931                     "%u.%u.%u %s", major, minor,
0932                     local_comp, iwl_reduced_fw_name(drv));
0933             break;
0934             }
0935         case IWL_UCODE_TLV_FW_DBG_DEST: {
0936             const struct iwl_fw_dbg_dest_tlv *dest = NULL;
0937             const struct iwl_fw_dbg_dest_tlv_v1 *dest_v1 = NULL;
0938             u8 mon_mode;
0939 
0940             pieces->dbg_dest_ver = (const u8 *)tlv_data;
0941             if (*pieces->dbg_dest_ver == 1) {
0942                 dest = (const void *)tlv_data;
0943             } else if (*pieces->dbg_dest_ver == 0) {
0944                 dest_v1 = (const void *)tlv_data;
0945             } else {
0946                 IWL_ERR(drv,
0947                     "The version is %d, and it is invalid\n",
0948                     *pieces->dbg_dest_ver);
0949                 break;
0950             }
0951 
0952             if (pieces->dbg_dest_tlv_init) {
0953                 IWL_ERR(drv,
0954                     "dbg destination ignored, already exists\n");
0955                 break;
0956             }
0957 
0958             pieces->dbg_dest_tlv_init = true;
0959 
0960             if (dest_v1) {
0961                 pieces->dbg_dest_tlv_v1 = dest_v1;
0962                 mon_mode = dest_v1->monitor_mode;
0963             } else {
0964                 pieces->dbg_dest_tlv = dest;
0965                 mon_mode = dest->monitor_mode;
0966             }
0967 
0968             IWL_INFO(drv, "Found debug destination: %s\n",
0969                  get_fw_dbg_mode_string(mon_mode));
0970 
0971             drv->fw.dbg.n_dest_reg = (dest_v1) ?
0972                 tlv_len -
0973                 offsetof(struct iwl_fw_dbg_dest_tlv_v1,
0974                      reg_ops) :
0975                 tlv_len -
0976                 offsetof(struct iwl_fw_dbg_dest_tlv,
0977                      reg_ops);
0978 
0979             drv->fw.dbg.n_dest_reg /=
0980                 sizeof(drv->fw.dbg.dest_tlv->reg_ops[0]);
0981 
0982             break;
0983             }
0984         case IWL_UCODE_TLV_FW_DBG_CONF: {
0985             const struct iwl_fw_dbg_conf_tlv *conf =
0986                 (const void *)tlv_data;
0987 
0988             if (!pieces->dbg_dest_tlv_init) {
0989                 IWL_ERR(drv,
0990                     "Ignore dbg config %d - no destination configured\n",
0991                     conf->id);
0992                 break;
0993             }
0994 
0995             if (conf->id >= ARRAY_SIZE(drv->fw.dbg.conf_tlv)) {
0996                 IWL_ERR(drv,
0997                     "Skip unknown configuration: %d\n",
0998                     conf->id);
0999                 break;
1000             }
1001 
1002             if (pieces->dbg_conf_tlv[conf->id]) {
1003                 IWL_ERR(drv,
1004                     "Ignore duplicate dbg config %d\n",
1005                     conf->id);
1006                 break;
1007             }
1008 
1009             if (conf->usniffer)
1010                 usniffer_req = true;
1011 
1012             IWL_INFO(drv, "Found debug configuration: %d\n",
1013                  conf->id);
1014 
1015             pieces->dbg_conf_tlv[conf->id] = conf;
1016             pieces->dbg_conf_tlv_len[conf->id] = tlv_len;
1017             break;
1018             }
1019         case IWL_UCODE_TLV_FW_DBG_TRIGGER: {
1020             const struct iwl_fw_dbg_trigger_tlv *trigger =
1021                 (const void *)tlv_data;
1022             u32 trigger_id = le32_to_cpu(trigger->id);
1023 
1024             if (trigger_id >= ARRAY_SIZE(drv->fw.dbg.trigger_tlv)) {
1025                 IWL_ERR(drv,
1026                     "Skip unknown trigger: %u\n",
1027                     trigger->id);
1028                 break;
1029             }
1030 
1031             if (pieces->dbg_trigger_tlv[trigger_id]) {
1032                 IWL_ERR(drv,
1033                     "Ignore duplicate dbg trigger %u\n",
1034                     trigger->id);
1035                 break;
1036             }
1037 
1038             IWL_INFO(drv, "Found debug trigger: %u\n", trigger->id);
1039 
1040             pieces->dbg_trigger_tlv[trigger_id] = trigger;
1041             pieces->dbg_trigger_tlv_len[trigger_id] = tlv_len;
1042             break;
1043             }
1044         case IWL_UCODE_TLV_FW_DBG_DUMP_LST: {
1045             if (tlv_len != sizeof(u32)) {
1046                 IWL_ERR(drv,
1047                     "dbg lst mask size incorrect, skip\n");
1048                 break;
1049             }
1050 
1051             drv->fw.dbg.dump_mask =
1052                 le32_to_cpup((const __le32 *)tlv_data);
1053             break;
1054             }
1055         case IWL_UCODE_TLV_SEC_RT_USNIFFER:
1056             *usniffer_images = true;
1057             iwl_store_ucode_sec(pieces, tlv_data,
1058                         IWL_UCODE_REGULAR_USNIFFER,
1059                         tlv_len);
1060             break;
1061         case IWL_UCODE_TLV_PAGING:
1062             if (tlv_len != sizeof(u32))
1063                 goto invalid_tlv_len;
1064             paging_mem_size = le32_to_cpup((const __le32 *)tlv_data);
1065 
1066             IWL_DEBUG_FW(drv,
1067                      "Paging: paging enabled (size = %u bytes)\n",
1068                      paging_mem_size);
1069 
1070             if (paging_mem_size > MAX_PAGING_IMAGE_SIZE) {
1071                 IWL_ERR(drv,
1072                     "Paging: driver supports up to %lu bytes for paging image\n",
1073                     MAX_PAGING_IMAGE_SIZE);
1074                 return -EINVAL;
1075             }
1076 
1077             if (paging_mem_size & (FW_PAGING_SIZE - 1)) {
1078                 IWL_ERR(drv,
1079                     "Paging: image isn't multiple %lu\n",
1080                     FW_PAGING_SIZE);
1081                 return -EINVAL;
1082             }
1083 
1084             drv->fw.img[IWL_UCODE_REGULAR].paging_mem_size =
1085                 paging_mem_size;
1086             usniffer_img = IWL_UCODE_REGULAR_USNIFFER;
1087             drv->fw.img[usniffer_img].paging_mem_size =
1088                 paging_mem_size;
1089             break;
1090         case IWL_UCODE_TLV_FW_GSCAN_CAPA:
1091             /* ignored */
1092             break;
1093         case IWL_UCODE_TLV_FW_MEM_SEG: {
1094             const struct iwl_fw_dbg_mem_seg_tlv *dbg_mem =
1095                 (const void *)tlv_data;
1096             size_t size;
1097             struct iwl_fw_dbg_mem_seg_tlv *n;
1098 
1099             if (tlv_len != (sizeof(*dbg_mem)))
1100                 goto invalid_tlv_len;
1101 
1102             IWL_DEBUG_INFO(drv, "Found debug memory segment: %u\n",
1103                        dbg_mem->data_type);
1104 
1105             size = sizeof(*pieces->dbg_mem_tlv) *
1106                    (pieces->n_mem_tlv + 1);
1107             n = krealloc(pieces->dbg_mem_tlv, size, GFP_KERNEL);
1108             if (!n)
1109                 return -ENOMEM;
1110             pieces->dbg_mem_tlv = n;
1111             pieces->dbg_mem_tlv[pieces->n_mem_tlv] = *dbg_mem;
1112             pieces->n_mem_tlv++;
1113             break;
1114             }
1115         case IWL_UCODE_TLV_IML: {
1116             drv->fw.iml_len = tlv_len;
1117             drv->fw.iml = kmemdup(tlv_data, tlv_len, GFP_KERNEL);
1118             if (!drv->fw.iml)
1119                 return -ENOMEM;
1120             break;
1121             }
1122         case IWL_UCODE_TLV_FW_RECOVERY_INFO: {
1123             const struct {
1124                 __le32 buf_addr;
1125                 __le32 buf_size;
1126             } *recov_info = (const void *)tlv_data;
1127 
1128             if (tlv_len != sizeof(*recov_info))
1129                 goto invalid_tlv_len;
1130             capa->error_log_addr =
1131                 le32_to_cpu(recov_info->buf_addr);
1132             capa->error_log_size =
1133                 le32_to_cpu(recov_info->buf_size);
1134             }
1135             break;
1136         case IWL_UCODE_TLV_FW_FSEQ_VERSION: {
1137             const struct {
1138                 u8 version[32];
1139                 u8 sha1[20];
1140             } *fseq_ver = (const void *)tlv_data;
1141 
1142             if (tlv_len != sizeof(*fseq_ver))
1143                 goto invalid_tlv_len;
1144             IWL_INFO(drv, "TLV_FW_FSEQ_VERSION: %s\n",
1145                  fseq_ver->version);
1146             }
1147             break;
1148         case IWL_UCODE_TLV_FW_NUM_STATIONS:
1149             if (tlv_len != sizeof(u32))
1150                 goto invalid_tlv_len;
1151             if (le32_to_cpup((const __le32 *)tlv_data) >
1152                 IWL_MVM_STATION_COUNT_MAX) {
1153                 IWL_ERR(drv,
1154                     "%d is an invalid number of station\n",
1155                     le32_to_cpup((const __le32 *)tlv_data));
1156                 goto tlv_error;
1157             }
1158             capa->num_stations =
1159                 le32_to_cpup((const __le32 *)tlv_data);
1160             break;
1161         case IWL_UCODE_TLV_UMAC_DEBUG_ADDRS: {
1162             const struct iwl_umac_debug_addrs *dbg_ptrs =
1163                 (const void *)tlv_data;
1164 
1165             if (tlv_len != sizeof(*dbg_ptrs))
1166                 goto invalid_tlv_len;
1167             if (drv->trans->trans_cfg->device_family <
1168                 IWL_DEVICE_FAMILY_22000)
1169                 break;
1170             drv->trans->dbg.umac_error_event_table =
1171                 le32_to_cpu(dbg_ptrs->error_info_addr) &
1172                 ~FW_ADDR_CACHE_CONTROL;
1173             drv->trans->dbg.error_event_table_tlv_status |=
1174                 IWL_ERROR_EVENT_TABLE_UMAC;
1175             break;
1176             }
1177         case IWL_UCODE_TLV_LMAC_DEBUG_ADDRS: {
1178             const struct iwl_lmac_debug_addrs *dbg_ptrs =
1179                 (const void *)tlv_data;
1180 
1181             if (tlv_len != sizeof(*dbg_ptrs))
1182                 goto invalid_tlv_len;
1183             if (drv->trans->trans_cfg->device_family <
1184                 IWL_DEVICE_FAMILY_22000)
1185                 break;
1186             drv->trans->dbg.lmac_error_event_table[0] =
1187                 le32_to_cpu(dbg_ptrs->error_event_table_ptr) &
1188                 ~FW_ADDR_CACHE_CONTROL;
1189             drv->trans->dbg.error_event_table_tlv_status |=
1190                 IWL_ERROR_EVENT_TABLE_LMAC1;
1191             break;
1192             }
1193         case IWL_UCODE_TLV_TYPE_REGIONS:
1194             iwl_parse_dbg_tlv_assert_tables(drv, tlv);
1195             fallthrough;
1196         case IWL_UCODE_TLV_TYPE_DEBUG_INFO:
1197         case IWL_UCODE_TLV_TYPE_BUFFER_ALLOCATION:
1198         case IWL_UCODE_TLV_TYPE_HCMD:
1199         case IWL_UCODE_TLV_TYPE_TRIGGERS:
1200         case IWL_UCODE_TLV_TYPE_CONF_SET:
1201             if (iwlwifi_mod_params.enable_ini)
1202                 iwl_dbg_tlv_alloc(drv->trans, tlv, false);
1203             break;
1204         case IWL_UCODE_TLV_CMD_VERSIONS:
1205             if (tlv_len % sizeof(struct iwl_fw_cmd_version)) {
1206                 IWL_ERR(drv,
1207                     "Invalid length for command versions: %u\n",
1208                     tlv_len);
1209                 tlv_len /= sizeof(struct iwl_fw_cmd_version);
1210                 tlv_len *= sizeof(struct iwl_fw_cmd_version);
1211             }
1212             if (WARN_ON(capa->cmd_versions))
1213                 return -EINVAL;
1214             capa->cmd_versions = kmemdup(tlv_data, tlv_len,
1215                              GFP_KERNEL);
1216             if (!capa->cmd_versions)
1217                 return -ENOMEM;
1218             capa->n_cmd_versions =
1219                 tlv_len / sizeof(struct iwl_fw_cmd_version);
1220             break;
1221         case IWL_UCODE_TLV_PHY_INTEGRATION_VERSION:
1222             if (drv->fw.phy_integration_ver) {
1223                 IWL_ERR(drv,
1224                     "phy integration str ignored, already exists\n");
1225                 break;
1226             }
1227 
1228             drv->fw.phy_integration_ver =
1229                 kmemdup(tlv_data, tlv_len, GFP_KERNEL);
1230             if (!drv->fw.phy_integration_ver)
1231                 return -ENOMEM;
1232             drv->fw.phy_integration_ver_len = tlv_len;
1233             break;
1234         case IWL_UCODE_TLV_SEC_TABLE_ADDR:
1235         case IWL_UCODE_TLV_D3_KEK_KCK_ADDR:
1236             iwl_drv_set_dump_exclude(drv, tlv_type,
1237                          tlv_data, tlv_len);
1238             break;
1239         default:
1240             IWL_DEBUG_INFO(drv, "unknown TLV: %d\n", tlv_type);
1241             break;
1242         }
1243     }
1244 
1245     if (!fw_has_capa(capa, IWL_UCODE_TLV_CAPA_USNIFFER_UNIFIED) &&
1246         usniffer_req && !*usniffer_images) {
1247         IWL_ERR(drv,
1248             "user selected to work with usniffer but usniffer image isn't available in ucode package\n");
1249         return -EINVAL;
1250     }
1251 
1252     if (len) {
1253         IWL_ERR(drv, "invalid TLV after parsing: %zd\n", len);
1254         iwl_print_hex_dump(drv, IWL_DL_FW, data, len);
1255         return -EINVAL;
1256     }
1257 
1258     return 0;
1259 
1260  invalid_tlv_len:
1261     IWL_ERR(drv, "TLV %d has invalid size: %u\n", tlv_type, tlv_len);
1262  tlv_error:
1263     iwl_print_hex_dump(drv, IWL_DL_FW, tlv_data, tlv_len);
1264 
1265     return -EINVAL;
1266 }
1267 
1268 static int iwl_alloc_ucode(struct iwl_drv *drv,
1269                struct iwl_firmware_pieces *pieces,
1270                enum iwl_ucode_type type)
1271 {
1272     int i;
1273     struct fw_desc *sec;
1274 
1275     sec = kcalloc(pieces->img[type].sec_counter, sizeof(*sec), GFP_KERNEL);
1276     if (!sec)
1277         return -ENOMEM;
1278     drv->fw.img[type].sec = sec;
1279     drv->fw.img[type].num_sec = pieces->img[type].sec_counter;
1280 
1281     for (i = 0; i < pieces->img[type].sec_counter; i++)
1282         if (iwl_alloc_fw_desc(drv, &sec[i], get_sec(pieces, type, i)))
1283             return -ENOMEM;
1284 
1285     return 0;
1286 }
1287 
1288 static int validate_sec_sizes(struct iwl_drv *drv,
1289                   struct iwl_firmware_pieces *pieces,
1290                   const struct iwl_cfg *cfg)
1291 {
1292     IWL_DEBUG_INFO(drv, "f/w package hdr runtime inst size = %zd\n",
1293         get_sec_size(pieces, IWL_UCODE_REGULAR,
1294                  IWL_UCODE_SECTION_INST));
1295     IWL_DEBUG_INFO(drv, "f/w package hdr runtime data size = %zd\n",
1296         get_sec_size(pieces, IWL_UCODE_REGULAR,
1297                  IWL_UCODE_SECTION_DATA));
1298     IWL_DEBUG_INFO(drv, "f/w package hdr init inst size = %zd\n",
1299         get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST));
1300     IWL_DEBUG_INFO(drv, "f/w package hdr init data size = %zd\n",
1301         get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA));
1302 
1303     /* Verify that uCode images will fit in card's SRAM. */
1304     if (get_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_INST) >
1305         cfg->max_inst_size) {
1306         IWL_ERR(drv, "uCode instr len %zd too large to fit in\n",
1307             get_sec_size(pieces, IWL_UCODE_REGULAR,
1308                      IWL_UCODE_SECTION_INST));
1309         return -1;
1310     }
1311 
1312     if (get_sec_size(pieces, IWL_UCODE_REGULAR, IWL_UCODE_SECTION_DATA) >
1313         cfg->max_data_size) {
1314         IWL_ERR(drv, "uCode data len %zd too large to fit in\n",
1315             get_sec_size(pieces, IWL_UCODE_REGULAR,
1316                      IWL_UCODE_SECTION_DATA));
1317         return -1;
1318     }
1319 
1320     if (get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_INST) >
1321          cfg->max_inst_size) {
1322         IWL_ERR(drv, "uCode init instr len %zd too large to fit in\n",
1323             get_sec_size(pieces, IWL_UCODE_INIT,
1324                      IWL_UCODE_SECTION_INST));
1325         return -1;
1326     }
1327 
1328     if (get_sec_size(pieces, IWL_UCODE_INIT, IWL_UCODE_SECTION_DATA) >
1329         cfg->max_data_size) {
1330         IWL_ERR(drv, "uCode init data len %zd too large to fit in\n",
1331             get_sec_size(pieces, IWL_UCODE_REGULAR,
1332                      IWL_UCODE_SECTION_DATA));
1333         return -1;
1334     }
1335     return 0;
1336 }
1337 
1338 static struct iwl_op_mode *
1339 _iwl_op_mode_start(struct iwl_drv *drv, struct iwlwifi_opmode_table *op)
1340 {
1341     const struct iwl_op_mode_ops *ops = op->ops;
1342     struct dentry *dbgfs_dir = NULL;
1343     struct iwl_op_mode *op_mode = NULL;
1344     int retry, max_retry = !!iwlwifi_mod_params.fw_restart * IWL_MAX_INIT_RETRY;
1345 
1346     for (retry = 0; retry <= max_retry; retry++) {
1347 
1348 #ifdef CONFIG_IWLWIFI_DEBUGFS
1349         drv->dbgfs_op_mode = debugfs_create_dir(op->name,
1350                             drv->dbgfs_drv);
1351         dbgfs_dir = drv->dbgfs_op_mode;
1352 #endif
1353 
1354         op_mode = ops->start(drv->trans, drv->trans->cfg,
1355                      &drv->fw, dbgfs_dir);
1356 
1357         if (op_mode)
1358             return op_mode;
1359 
1360         IWL_ERR(drv, "retry init count %d\n", retry);
1361 
1362 #ifdef CONFIG_IWLWIFI_DEBUGFS
1363         debugfs_remove_recursive(drv->dbgfs_op_mode);
1364         drv->dbgfs_op_mode = NULL;
1365 #endif
1366     }
1367 
1368     return NULL;
1369 }
1370 
1371 static void _iwl_op_mode_stop(struct iwl_drv *drv)
1372 {
1373     /* op_mode can be NULL if its start failed */
1374     if (drv->op_mode) {
1375         iwl_op_mode_stop(drv->op_mode);
1376         drv->op_mode = NULL;
1377 
1378 #ifdef CONFIG_IWLWIFI_DEBUGFS
1379         debugfs_remove_recursive(drv->dbgfs_op_mode);
1380         drv->dbgfs_op_mode = NULL;
1381 #endif
1382     }
1383 }
1384 
1385 /*
1386  * iwl_req_fw_callback - callback when firmware was loaded
1387  *
1388  * If loaded successfully, copies the firmware into buffers
1389  * for the card to fetch (via DMA).
1390  */
1391 static void iwl_req_fw_callback(const struct firmware *ucode_raw, void *context)
1392 {
1393     struct iwl_drv *drv = context;
1394     struct iwl_fw *fw = &drv->fw;
1395     const struct iwl_ucode_header *ucode;
1396     struct iwlwifi_opmode_table *op;
1397     int err;
1398     struct iwl_firmware_pieces *pieces;
1399     const unsigned int api_max = drv->trans->cfg->ucode_api_max;
1400     const unsigned int api_min = drv->trans->cfg->ucode_api_min;
1401     size_t trigger_tlv_sz[FW_DBG_TRIGGER_MAX];
1402     u32 api_ver;
1403     int i;
1404     bool load_module = false;
1405     bool usniffer_images = false;
1406     bool failure = true;
1407 
1408     fw->ucode_capa.max_probe_length = IWL_DEFAULT_MAX_PROBE_LENGTH;
1409     fw->ucode_capa.standard_phy_calibration_size =
1410             IWL_DEFAULT_STANDARD_PHY_CALIBRATE_TBL_SIZE;
1411     fw->ucode_capa.n_scan_channels = IWL_DEFAULT_SCAN_CHANNELS;
1412     fw->ucode_capa.num_stations = IWL_MVM_STATION_COUNT_MAX;
1413     /* dump all fw memory areas by default */
1414     fw->dbg.dump_mask = 0xffffffff;
1415 
1416     pieces = kzalloc(sizeof(*pieces), GFP_KERNEL);
1417     if (!pieces)
1418         goto out_free_fw;
1419 
1420     if (!ucode_raw)
1421         goto try_again;
1422 
1423     IWL_DEBUG_FW_INFO(drv, "Loaded firmware file '%s' (%zd bytes).\n",
1424               drv->firmware_name, ucode_raw->size);
1425 
1426     /* Make sure that we got at least the API version number */
1427     if (ucode_raw->size < 4) {
1428         IWL_ERR(drv, "File size way too small!\n");
1429         goto try_again;
1430     }
1431 
1432     /* Data from ucode file:  header followed by uCode images */
1433     ucode = (const struct iwl_ucode_header *)ucode_raw->data;
1434 
1435     if (ucode->ver)
1436         err = iwl_parse_v1_v2_firmware(drv, ucode_raw, pieces);
1437     else
1438         err = iwl_parse_tlv_firmware(drv, ucode_raw, pieces,
1439                          &fw->ucode_capa, &usniffer_images);
1440 
1441     if (err)
1442         goto try_again;
1443 
1444     if (fw_has_api(&drv->fw.ucode_capa, IWL_UCODE_TLV_API_NEW_VERSION))
1445         api_ver = drv->fw.ucode_ver;
1446     else
1447         api_ver = IWL_UCODE_API(drv->fw.ucode_ver);
1448 
1449     /*
1450      * api_ver should match the api version forming part of the
1451      * firmware filename ... but we don't check for that and only rely
1452      * on the API version read from firmware header from here on forward
1453      */
1454     if (api_ver < api_min || api_ver > api_max) {
1455         IWL_ERR(drv,
1456             "Driver unable to support your firmware API. "
1457             "Driver supports v%u, firmware is v%u.\n",
1458             api_max, api_ver);
1459         goto try_again;
1460     }
1461 
1462     /*
1463      * In mvm uCode there is no difference between data and instructions
1464      * sections.
1465      */
1466     if (fw->type == IWL_FW_DVM && validate_sec_sizes(drv, pieces,
1467                              drv->trans->cfg))
1468         goto try_again;
1469 
1470     /* Allocate ucode buffers for card's bus-master loading ... */
1471 
1472     /* Runtime instructions and 2 copies of data:
1473      * 1) unmodified from disk
1474      * 2) backup cache for save/restore during power-downs
1475      */
1476     for (i = 0; i < IWL_UCODE_TYPE_MAX; i++)
1477         if (iwl_alloc_ucode(drv, pieces, i))
1478             goto out_free_fw;
1479 
1480     if (pieces->dbg_dest_tlv_init) {
1481         size_t dbg_dest_size = sizeof(*drv->fw.dbg.dest_tlv) +
1482             sizeof(drv->fw.dbg.dest_tlv->reg_ops[0]) *
1483             drv->fw.dbg.n_dest_reg;
1484 
1485         drv->fw.dbg.dest_tlv = kmalloc(dbg_dest_size, GFP_KERNEL);
1486 
1487         if (!drv->fw.dbg.dest_tlv)
1488             goto out_free_fw;
1489 
1490         if (*pieces->dbg_dest_ver == 0) {
1491             memcpy(drv->fw.dbg.dest_tlv, pieces->dbg_dest_tlv_v1,
1492                    dbg_dest_size);
1493         } else {
1494             struct iwl_fw_dbg_dest_tlv_v1 *dest_tlv =
1495                 drv->fw.dbg.dest_tlv;
1496 
1497             dest_tlv->version = pieces->dbg_dest_tlv->version;
1498             dest_tlv->monitor_mode =
1499                 pieces->dbg_dest_tlv->monitor_mode;
1500             dest_tlv->size_power =
1501                 pieces->dbg_dest_tlv->size_power;
1502             dest_tlv->wrap_count =
1503                 pieces->dbg_dest_tlv->wrap_count;
1504             dest_tlv->write_ptr_reg =
1505                 pieces->dbg_dest_tlv->write_ptr_reg;
1506             dest_tlv->base_shift =
1507                 pieces->dbg_dest_tlv->base_shift;
1508             memcpy(dest_tlv->reg_ops,
1509                    pieces->dbg_dest_tlv->reg_ops,
1510                    sizeof(drv->fw.dbg.dest_tlv->reg_ops[0]) *
1511                    drv->fw.dbg.n_dest_reg);
1512 
1513             /* In version 1 of the destination tlv, which is
1514              * relevant for internal buffer exclusively,
1515              * the base address is part of given with the length
1516              * of the buffer, and the size shift is give instead of
1517              * end shift. We now store these values in base_reg,
1518              * and end shift, and when dumping the data we'll
1519              * manipulate it for extracting both the length and
1520              * base address */
1521             dest_tlv->base_reg = pieces->dbg_dest_tlv->cfg_reg;
1522             dest_tlv->end_shift =
1523                 pieces->dbg_dest_tlv->size_shift;
1524         }
1525     }
1526 
1527     for (i = 0; i < ARRAY_SIZE(drv->fw.dbg.conf_tlv); i++) {
1528         if (pieces->dbg_conf_tlv[i]) {
1529             drv->fw.dbg.conf_tlv[i] =
1530                 kmemdup(pieces->dbg_conf_tlv[i],
1531                     pieces->dbg_conf_tlv_len[i],
1532                     GFP_KERNEL);
1533             if (!drv->fw.dbg.conf_tlv[i])
1534                 goto out_free_fw;
1535         }
1536     }
1537 
1538     memset(&trigger_tlv_sz, 0xff, sizeof(trigger_tlv_sz));
1539 
1540     trigger_tlv_sz[FW_DBG_TRIGGER_MISSED_BEACONS] =
1541         sizeof(struct iwl_fw_dbg_trigger_missed_bcon);
1542     trigger_tlv_sz[FW_DBG_TRIGGER_CHANNEL_SWITCH] = 0;
1543     trigger_tlv_sz[FW_DBG_TRIGGER_FW_NOTIF] =
1544         sizeof(struct iwl_fw_dbg_trigger_cmd);
1545     trigger_tlv_sz[FW_DBG_TRIGGER_MLME] =
1546         sizeof(struct iwl_fw_dbg_trigger_mlme);
1547     trigger_tlv_sz[FW_DBG_TRIGGER_STATS] =
1548         sizeof(struct iwl_fw_dbg_trigger_stats);
1549     trigger_tlv_sz[FW_DBG_TRIGGER_RSSI] =
1550         sizeof(struct iwl_fw_dbg_trigger_low_rssi);
1551     trigger_tlv_sz[FW_DBG_TRIGGER_TXQ_TIMERS] =
1552         sizeof(struct iwl_fw_dbg_trigger_txq_timer);
1553     trigger_tlv_sz[FW_DBG_TRIGGER_TIME_EVENT] =
1554         sizeof(struct iwl_fw_dbg_trigger_time_event);
1555     trigger_tlv_sz[FW_DBG_TRIGGER_BA] =
1556         sizeof(struct iwl_fw_dbg_trigger_ba);
1557     trigger_tlv_sz[FW_DBG_TRIGGER_TDLS] =
1558         sizeof(struct iwl_fw_dbg_trigger_tdls);
1559 
1560     for (i = 0; i < ARRAY_SIZE(drv->fw.dbg.trigger_tlv); i++) {
1561         if (pieces->dbg_trigger_tlv[i]) {
1562             /*
1563              * If the trigger isn't long enough, WARN and exit.
1564              * Someone is trying to debug something and he won't
1565              * be able to catch the bug he is trying to chase.
1566              * We'd better be noisy to be sure he knows what's
1567              * going on.
1568              */
1569             if (WARN_ON(pieces->dbg_trigger_tlv_len[i] <
1570                     (trigger_tlv_sz[i] +
1571                      sizeof(struct iwl_fw_dbg_trigger_tlv))))
1572                 goto out_free_fw;
1573             drv->fw.dbg.trigger_tlv_len[i] =
1574                 pieces->dbg_trigger_tlv_len[i];
1575             drv->fw.dbg.trigger_tlv[i] =
1576                 kmemdup(pieces->dbg_trigger_tlv[i],
1577                     drv->fw.dbg.trigger_tlv_len[i],
1578                     GFP_KERNEL);
1579             if (!drv->fw.dbg.trigger_tlv[i])
1580                 goto out_free_fw;
1581         }
1582     }
1583 
1584     /* Now that we can no longer fail, copy information */
1585 
1586     drv->fw.dbg.mem_tlv = pieces->dbg_mem_tlv;
1587     pieces->dbg_mem_tlv = NULL;
1588     drv->fw.dbg.n_mem_tlv = pieces->n_mem_tlv;
1589 
1590     /*
1591      * The (size - 16) / 12 formula is based on the information recorded
1592      * for each event, which is of mode 1 (including timestamp) for all
1593      * new microcodes that include this information.
1594      */
1595     fw->init_evtlog_ptr = pieces->init_evtlog_ptr;
1596     if (pieces->init_evtlog_size)
1597         fw->init_evtlog_size = (pieces->init_evtlog_size - 16)/12;
1598     else
1599         fw->init_evtlog_size =
1600             drv->trans->trans_cfg->base_params->max_event_log_size;
1601     fw->init_errlog_ptr = pieces->init_errlog_ptr;
1602     fw->inst_evtlog_ptr = pieces->inst_evtlog_ptr;
1603     if (pieces->inst_evtlog_size)
1604         fw->inst_evtlog_size = (pieces->inst_evtlog_size - 16)/12;
1605     else
1606         fw->inst_evtlog_size =
1607             drv->trans->trans_cfg->base_params->max_event_log_size;
1608     fw->inst_errlog_ptr = pieces->inst_errlog_ptr;
1609 
1610     /*
1611      * figure out the offset of chain noise reset and gain commands
1612      * base on the size of standard phy calibration commands table size
1613      */
1614     if (fw->ucode_capa.standard_phy_calibration_size >
1615         IWL_MAX_PHY_CALIBRATE_TBL_SIZE)
1616         fw->ucode_capa.standard_phy_calibration_size =
1617             IWL_MAX_STANDARD_PHY_CALIBRATE_TBL_SIZE;
1618 
1619     /* We have our copies now, allow OS release its copies */
1620     release_firmware(ucode_raw);
1621 
1622     iwl_dbg_tlv_load_bin(drv->trans->dev, drv->trans);
1623 
1624     mutex_lock(&iwlwifi_opmode_table_mtx);
1625     switch (fw->type) {
1626     case IWL_FW_DVM:
1627         op = &iwlwifi_opmode_table[DVM_OP_MODE];
1628         break;
1629     default:
1630         WARN(1, "Invalid fw type %d\n", fw->type);
1631         fallthrough;
1632     case IWL_FW_MVM:
1633         op = &iwlwifi_opmode_table[MVM_OP_MODE];
1634         break;
1635     }
1636 
1637     IWL_INFO(drv, "loaded firmware version %s op_mode %s\n",
1638          drv->fw.fw_version, op->name);
1639 
1640     /* add this device to the list of devices using this op_mode */
1641     list_add_tail(&drv->list, &op->drv);
1642 
1643     if (op->ops) {
1644         drv->op_mode = _iwl_op_mode_start(drv, op);
1645 
1646         if (!drv->op_mode) {
1647             mutex_unlock(&iwlwifi_opmode_table_mtx);
1648             goto out_unbind;
1649         }
1650     } else {
1651         load_module = true;
1652     }
1653     mutex_unlock(&iwlwifi_opmode_table_mtx);
1654 
1655     /*
1656      * Complete the firmware request last so that
1657      * a driver unbind (stop) doesn't run while we
1658      * are doing the start() above.
1659      */
1660     complete(&drv->request_firmware_complete);
1661 
1662     /*
1663      * Load the module last so we don't block anything
1664      * else from proceeding if the module fails to load
1665      * or hangs loading.
1666      */
1667     if (load_module)
1668         request_module("%s", op->name);
1669     failure = false;
1670     goto free;
1671 
1672  try_again:
1673     /* try next, if any */
1674     release_firmware(ucode_raw);
1675     if (iwl_request_firmware(drv, false))
1676         goto out_unbind;
1677     goto free;
1678 
1679  out_free_fw:
1680     release_firmware(ucode_raw);
1681  out_unbind:
1682     complete(&drv->request_firmware_complete);
1683     device_release_driver(drv->trans->dev);
1684     /* drv has just been freed by the release */
1685     failure = false;
1686  free:
1687     if (failure)
1688         iwl_dealloc_ucode(drv);
1689 
1690     if (pieces) {
1691         for (i = 0; i < ARRAY_SIZE(pieces->img); i++)
1692             kfree(pieces->img[i].sec);
1693         kfree(pieces->dbg_mem_tlv);
1694         kfree(pieces);
1695     }
1696 }
1697 
1698 struct iwl_drv *iwl_drv_start(struct iwl_trans *trans)
1699 {
1700     struct iwl_drv *drv;
1701     int ret;
1702 
1703     drv = kzalloc(sizeof(*drv), GFP_KERNEL);
1704     if (!drv) {
1705         ret = -ENOMEM;
1706         goto err;
1707     }
1708 
1709     drv->trans = trans;
1710     drv->dev = trans->dev;
1711 
1712     init_completion(&drv->request_firmware_complete);
1713     INIT_LIST_HEAD(&drv->list);
1714 
1715 #ifdef CONFIG_IWLWIFI_DEBUGFS
1716     /* Create the device debugfs entries. */
1717     drv->dbgfs_drv = debugfs_create_dir(dev_name(trans->dev),
1718                         iwl_dbgfs_root);
1719 
1720     /* Create transport layer debugfs dir */
1721     drv->trans->dbgfs_dir = debugfs_create_dir("trans", drv->dbgfs_drv);
1722 #endif
1723 
1724     drv->trans->dbg.domains_bitmap = IWL_TRANS_FW_DBG_DOMAIN(drv->trans);
1725 
1726     ret = iwl_request_firmware(drv, true);
1727     if (ret) {
1728         IWL_ERR(trans, "Couldn't request the fw\n");
1729         goto err_fw;
1730     }
1731 
1732     return drv;
1733 
1734 err_fw:
1735 #ifdef CONFIG_IWLWIFI_DEBUGFS
1736     debugfs_remove_recursive(drv->dbgfs_drv);
1737     iwl_dbg_tlv_free(drv->trans);
1738 #endif
1739     kfree(drv);
1740 err:
1741     return ERR_PTR(ret);
1742 }
1743 
1744 void iwl_drv_stop(struct iwl_drv *drv)
1745 {
1746     wait_for_completion(&drv->request_firmware_complete);
1747 
1748     _iwl_op_mode_stop(drv);
1749 
1750     iwl_dealloc_ucode(drv);
1751 
1752     mutex_lock(&iwlwifi_opmode_table_mtx);
1753     /*
1754      * List is empty (this item wasn't added)
1755      * when firmware loading failed -- in that
1756      * case we can't remove it from any list.
1757      */
1758     if (!list_empty(&drv->list))
1759         list_del(&drv->list);
1760     mutex_unlock(&iwlwifi_opmode_table_mtx);
1761 
1762 #ifdef CONFIG_IWLWIFI_DEBUGFS
1763     drv->trans->ops->debugfs_cleanup(drv->trans);
1764 
1765     debugfs_remove_recursive(drv->dbgfs_drv);
1766 #endif
1767 
1768     iwl_dbg_tlv_free(drv->trans);
1769 
1770     kfree(drv);
1771 }
1772 
1773 #define ENABLE_INI  (IWL_DBG_TLV_MAX_PRESET + 1)
1774 
1775 /* shared module parameters */
1776 struct iwl_mod_params iwlwifi_mod_params = {
1777     .fw_restart = true,
1778     .bt_coex_active = true,
1779     .power_level = IWL_POWER_INDEX_1,
1780     .uapsd_disable = IWL_DISABLE_UAPSD_BSS | IWL_DISABLE_UAPSD_P2P_CLIENT,
1781     .enable_ini = ENABLE_INI,
1782     /* the rest are 0 by default */
1783 };
1784 IWL_EXPORT_SYMBOL(iwlwifi_mod_params);
1785 
1786 int iwl_opmode_register(const char *name, const struct iwl_op_mode_ops *ops)
1787 {
1788     int i;
1789     struct iwl_drv *drv;
1790     struct iwlwifi_opmode_table *op;
1791 
1792     mutex_lock(&iwlwifi_opmode_table_mtx);
1793     for (i = 0; i < ARRAY_SIZE(iwlwifi_opmode_table); i++) {
1794         op = &iwlwifi_opmode_table[i];
1795         if (strcmp(op->name, name))
1796             continue;
1797         op->ops = ops;
1798         /* TODO: need to handle exceptional case */
1799         list_for_each_entry(drv, &op->drv, list)
1800             drv->op_mode = _iwl_op_mode_start(drv, op);
1801 
1802         mutex_unlock(&iwlwifi_opmode_table_mtx);
1803         return 0;
1804     }
1805     mutex_unlock(&iwlwifi_opmode_table_mtx);
1806     return -EIO;
1807 }
1808 IWL_EXPORT_SYMBOL(iwl_opmode_register);
1809 
1810 void iwl_opmode_deregister(const char *name)
1811 {
1812     int i;
1813     struct iwl_drv *drv;
1814 
1815     mutex_lock(&iwlwifi_opmode_table_mtx);
1816     for (i = 0; i < ARRAY_SIZE(iwlwifi_opmode_table); i++) {
1817         if (strcmp(iwlwifi_opmode_table[i].name, name))
1818             continue;
1819         iwlwifi_opmode_table[i].ops = NULL;
1820 
1821         /* call the stop routine for all devices */
1822         list_for_each_entry(drv, &iwlwifi_opmode_table[i].drv, list)
1823             _iwl_op_mode_stop(drv);
1824 
1825         mutex_unlock(&iwlwifi_opmode_table_mtx);
1826         return;
1827     }
1828     mutex_unlock(&iwlwifi_opmode_table_mtx);
1829 }
1830 IWL_EXPORT_SYMBOL(iwl_opmode_deregister);
1831 
1832 static int __init iwl_drv_init(void)
1833 {
1834     int i, err;
1835 
1836     for (i = 0; i < ARRAY_SIZE(iwlwifi_opmode_table); i++)
1837         INIT_LIST_HEAD(&iwlwifi_opmode_table[i].drv);
1838 
1839     pr_info(DRV_DESCRIPTION "\n");
1840 
1841 #ifdef CONFIG_IWLWIFI_DEBUGFS
1842     /* Create the root of iwlwifi debugfs subsystem. */
1843     iwl_dbgfs_root = debugfs_create_dir(DRV_NAME, NULL);
1844 #endif
1845 
1846     err = iwl_pci_register_driver();
1847     if (err)
1848         goto cleanup_debugfs;
1849 
1850     return 0;
1851 
1852 cleanup_debugfs:
1853 #ifdef CONFIG_IWLWIFI_DEBUGFS
1854     debugfs_remove_recursive(iwl_dbgfs_root);
1855 #endif
1856     return err;
1857 }
1858 module_init(iwl_drv_init);
1859 
1860 static void __exit iwl_drv_exit(void)
1861 {
1862     iwl_pci_unregister_driver();
1863 
1864 #ifdef CONFIG_IWLWIFI_DEBUGFS
1865     debugfs_remove_recursive(iwl_dbgfs_root);
1866 #endif
1867 }
1868 module_exit(iwl_drv_exit);
1869 
1870 #ifdef CONFIG_IWLWIFI_DEBUG
1871 module_param_named(debug, iwlwifi_mod_params.debug_level, uint, 0644);
1872 MODULE_PARM_DESC(debug, "debug output mask");
1873 #endif
1874 
1875 module_param_named(swcrypto, iwlwifi_mod_params.swcrypto, int, 0444);
1876 MODULE_PARM_DESC(swcrypto, "using crypto in software (default 0 [hardware])");
1877 module_param_named(11n_disable, iwlwifi_mod_params.disable_11n, uint, 0444);
1878 MODULE_PARM_DESC(11n_disable,
1879     "disable 11n functionality, bitmap: 1: full, 2: disable agg TX, 4: disable agg RX, 8 enable agg TX");
1880 module_param_named(amsdu_size, iwlwifi_mod_params.amsdu_size, int, 0444);
1881 MODULE_PARM_DESC(amsdu_size,
1882          "amsdu size 0: 12K for multi Rx queue devices, 2K for AX210 devices, "
1883          "4K for other devices 1:4K 2:8K 3:12K (16K buffers) 4: 2K (default 0)");
1884 module_param_named(fw_restart, iwlwifi_mod_params.fw_restart, bool, 0444);
1885 MODULE_PARM_DESC(fw_restart, "restart firmware in case of error (default true)");
1886 
1887 module_param_named(nvm_file, iwlwifi_mod_params.nvm_file, charp, 0444);
1888 MODULE_PARM_DESC(nvm_file, "NVM file name");
1889 
1890 module_param_named(uapsd_disable, iwlwifi_mod_params.uapsd_disable, uint, 0644);
1891 MODULE_PARM_DESC(uapsd_disable,
1892          "disable U-APSD functionality bitmap 1: BSS 2: P2P Client (default: 3)");
1893 
1894 static int enable_ini_set(const char *arg, const struct kernel_param *kp)
1895 {
1896     int ret = 0;
1897     bool res;
1898     __u32 new_enable_ini;
1899 
1900     /* in case the argument type is a number */
1901     ret = kstrtou32(arg, 0, &new_enable_ini);
1902     if (!ret) {
1903         if (new_enable_ini > ENABLE_INI) {
1904             pr_err("enable_ini cannot be %d, in range 0-16\n", new_enable_ini);
1905             return -EINVAL;
1906         }
1907         goto out;
1908     }
1909 
1910     /* in case the argument type is boolean */
1911     ret = kstrtobool(arg, &res);
1912     if (ret)
1913         return ret;
1914     new_enable_ini = (res ? ENABLE_INI : 0);
1915 
1916 out:
1917     iwlwifi_mod_params.enable_ini = new_enable_ini;
1918     return 0;
1919 }
1920 
1921 static const struct kernel_param_ops enable_ini_ops = {
1922     .set = enable_ini_set
1923 };
1924 
1925 module_param_cb(enable_ini, &enable_ini_ops, &iwlwifi_mod_params.enable_ini, 0644);
1926 MODULE_PARM_DESC(enable_ini,
1927          "0:disable, 1-15:FW_DBG_PRESET Values, 16:enabled without preset value defined,"
1928          "Debug INI TLV FW debug infrastructure (default: 16)");
1929 
1930 /*
1931  * set bt_coex_active to true, uCode will do kill/defer
1932  * every time the priority line is asserted (BT is sending signals on the
1933  * priority line in the PCIx).
1934  * set bt_coex_active to false, uCode will ignore the BT activity and
1935  * perform the normal operation
1936  *
1937  * User might experience transmit issue on some platform due to WiFi/BT
1938  * co-exist problem. The possible behaviors are:
1939  *   Able to scan and finding all the available AP
1940  *   Not able to associate with any AP
1941  * On those platforms, WiFi communication can be restored by set
1942  * "bt_coex_active" module parameter to "false"
1943  *
1944  * default: bt_coex_active = true (BT_COEX_ENABLE)
1945  */
1946 module_param_named(bt_coex_active, iwlwifi_mod_params.bt_coex_active,
1947            bool, 0444);
1948 MODULE_PARM_DESC(bt_coex_active, "enable wifi/bt co-exist (default: enable)");
1949 
1950 module_param_named(led_mode, iwlwifi_mod_params.led_mode, int, 0444);
1951 MODULE_PARM_DESC(led_mode, "0=system default, "
1952         "1=On(RF On)/Off(RF Off), 2=blinking, 3=Off (default: 0)");
1953 
1954 module_param_named(power_save, iwlwifi_mod_params.power_save, bool, 0444);
1955 MODULE_PARM_DESC(power_save,
1956          "enable WiFi power management (default: disable)");
1957 
1958 module_param_named(power_level, iwlwifi_mod_params.power_level, int, 0444);
1959 MODULE_PARM_DESC(power_level,
1960          "default power save level (range from 1 - 5, default: 1)");
1961 
1962 module_param_named(disable_11ac, iwlwifi_mod_params.disable_11ac, bool, 0444);
1963 MODULE_PARM_DESC(disable_11ac, "Disable VHT capabilities (default: false)");
1964 
1965 module_param_named(remove_when_gone,
1966            iwlwifi_mod_params.remove_when_gone, bool,
1967            0444);
1968 MODULE_PARM_DESC(remove_when_gone,
1969          "Remove dev from PCIe bus if it is deemed inaccessible (default: false)");
1970 
1971 module_param_named(disable_11ax, iwlwifi_mod_params.disable_11ax, bool,
1972            S_IRUGO);
1973 MODULE_PARM_DESC(disable_11ax, "Disable HE capabilities (default: false)");