]> git.ipfire.org Git - people/arne_f/kernel.git/blob - drivers/staging/wlan-ng/prism2usb.c
staging: wlan-ng: fix out of bounds read in prism2sta_probe_usb()
[people/arne_f/kernel.git] / drivers / staging / wlan-ng / prism2usb.c
1 // SPDX-License-Identifier: GPL-2.0
2 #include "hfa384x_usb.c"
3 #include "prism2mgmt.c"
4 #include "prism2mib.c"
5 #include "prism2sta.c"
6 #include "prism2fw.c"
7
8 #define PRISM_DEV(vid, pid, name) \
9 { USB_DEVICE(vid, pid), \
10 .driver_info = (unsigned long)name }
11
12 static const struct usb_device_id usb_prism_tbl[] = {
13 PRISM_DEV(0x04bb, 0x0922, "IOData AirPort WN-B11/USBS"),
14 PRISM_DEV(0x07aa, 0x0012, "Corega Wireless LAN USB Stick-11"),
15 PRISM_DEV(0x09aa, 0x3642, "Prism2.x 11Mbps WLAN USB Adapter"),
16 PRISM_DEV(0x1668, 0x0408, "Actiontec Prism2.5 11Mbps WLAN USB Adapter"),
17 PRISM_DEV(0x1668, 0x0421, "Actiontec Prism2.5 11Mbps WLAN USB Adapter"),
18 PRISM_DEV(0x1915, 0x2236, "Linksys WUSB11v3.0 11Mbps WLAN USB Adapter"),
19 PRISM_DEV(0x066b, 0x2212, "Linksys WUSB11v2.5 11Mbps WLAN USB Adapter"),
20 PRISM_DEV(0x066b, 0x2213, "Linksys WUSB12v1.1 11Mbps WLAN USB Adapter"),
21 PRISM_DEV(0x0411, 0x0016, "Melco WLI-USB-S11 11Mbps WLAN Adapter"),
22 PRISM_DEV(0x08de, 0x7a01, "PRISM25 IEEE 802.11 Mini USB Adapter"),
23 PRISM_DEV(0x8086, 0x1111, "Intel PRO/Wireless 2011B LAN USB Adapter"),
24 PRISM_DEV(0x0d8e, 0x7a01, "PRISM25 IEEE 802.11 Mini USB Adapter"),
25 PRISM_DEV(0x045e, 0x006e, "Microsoft MN510 Wireless USB Adapter"),
26 PRISM_DEV(0x0967, 0x0204, "Acer Warplink USB Adapter"),
27 PRISM_DEV(0x0cde, 0x0002, "Z-Com 725/726 Prism2.5 USB/USB Integrated"),
28 PRISM_DEV(0x0cde, 0x0005, "Z-Com Xl735 Wireless 802.11b USB Adapter"),
29 PRISM_DEV(0x413c, 0x8100, "Dell TrueMobile 1180 Wireless USB Adapter"),
30 PRISM_DEV(0x0b3b, 0x1601, "ALLNET 0193 11Mbps WLAN USB Adapter"),
31 PRISM_DEV(0x0b3b, 0x1602, "ZyXEL ZyAIR B200 Wireless USB Adapter"),
32 PRISM_DEV(0x0baf, 0x00eb, "USRobotics USR1120 Wireless USB Adapter"),
33 PRISM_DEV(0x0411, 0x0027, "Melco WLI-USB-KS11G 11Mbps WLAN Adapter"),
34 PRISM_DEV(0x04f1, 0x3009, "JVC MP-XP7250 Builtin USB WLAN Adapter"),
35 PRISM_DEV(0x0846, 0x4110, "NetGear MA111"),
36 PRISM_DEV(0x03f3, 0x0020, "Adaptec AWN-8020 USB WLAN Adapter"),
37 PRISM_DEV(0x2821, 0x3300, "ASUS-WL140 Wireless USB Adapter"),
38 PRISM_DEV(0x2001, 0x3700, "DWL-122 Wireless USB Adapter"),
39 PRISM_DEV(0x2001, 0x3702, "DWL-120 Rev F Wireless USB Adapter"),
40 PRISM_DEV(0x50c2, 0x4013, "Averatec USB WLAN Adapter"),
41 PRISM_DEV(0x2c02, 0x14ea, "Planex GW-US11H WLAN USB Adapter"),
42 PRISM_DEV(0x124a, 0x168b, "Airvast PRISM3 WLAN USB Adapter"),
43 PRISM_DEV(0x083a, 0x3503, "T-Sinus 111 USB WLAN Adapter"),
44 PRISM_DEV(0x2821, 0x3300, "Hawking HighDB USB Adapter"),
45 PRISM_DEV(0x0411, 0x0044, "Melco WLI-USB-KB11 11Mbps WLAN Adapter"),
46 PRISM_DEV(0x1668, 0x6106, "ROPEX FreeLan 802.11b USB Adapter"),
47 PRISM_DEV(0x124a, 0x4017, "Pheenet WL-503IA 802.11b USB Adapter"),
48 PRISM_DEV(0x0bb2, 0x0302, "Ambit Microsystems Corp."),
49 PRISM_DEV(0x9016, 0x182d, "Sitecom WL-022 802.11b USB Adapter"),
50 PRISM_DEV(0x0543, 0x0f01,
51 "ViewSonic Airsync USB Adapter 11Mbps (Prism2.5)"),
52 PRISM_DEV(0x067c, 0x1022,
53 "Siemens SpeedStream 1022 11Mbps WLAN USB Adapter"),
54 PRISM_DEV(0x049f, 0x0033,
55 "Compaq/Intel W100 PRO/Wireless 11Mbps multiport WLAN Adapter"),
56 { } /* terminator */
57 };
58 MODULE_DEVICE_TABLE(usb, usb_prism_tbl);
59
60 static int prism2sta_probe_usb(struct usb_interface *interface,
61 const struct usb_device_id *id)
62 {
63 struct usb_device *dev;
64 struct usb_endpoint_descriptor *bulk_in, *bulk_out;
65 struct usb_host_interface *iface_desc = interface->cur_altsetting;
66 struct wlandevice *wlandev = NULL;
67 struct hfa384x *hw = NULL;
68 int result = 0;
69
70 result = usb_find_common_endpoints(iface_desc, &bulk_in, &bulk_out, NULL, NULL);
71 if (result)
72 goto failed;
73
74 dev = interface_to_usbdev(interface);
75 wlandev = create_wlan();
76 if (!wlandev) {
77 dev_err(&interface->dev, "Memory allocation failure.\n");
78 result = -EIO;
79 goto failed;
80 }
81 hw = wlandev->priv;
82
83 if (wlan_setup(wlandev, &interface->dev) != 0) {
84 dev_err(&interface->dev, "wlan_setup() failed.\n");
85 result = -EIO;
86 goto failed;
87 }
88
89 /* Initialize the hw data */
90 hw->endp_in = usb_rcvbulkpipe(dev, bulk_in->bEndpointAddress);
91 hw->endp_out = usb_sndbulkpipe(dev, bulk_out->bEndpointAddress);
92 hfa384x_create(hw, dev);
93 hw->wlandev = wlandev;
94
95 /* Register the wlandev, this gets us a name and registers the
96 * linux netdevice.
97 */
98 SET_NETDEV_DEV(wlandev->netdev, &interface->dev);
99
100 /* Do a chip-level reset on the MAC */
101 if (prism2_doreset) {
102 result = hfa384x_corereset(hw,
103 prism2_reset_holdtime,
104 prism2_reset_settletime, 0);
105 if (result != 0) {
106 result = -EIO;
107 dev_err(&interface->dev,
108 "hfa384x_corereset() failed.\n");
109 goto failed_reset;
110 }
111 }
112
113 usb_get_dev(dev);
114
115 wlandev->msdstate = WLAN_MSD_HWPRESENT;
116
117 /* Try and load firmware, then enable card before we register */
118 prism2_fwtry(dev, wlandev);
119 prism2sta_ifstate(wlandev, P80211ENUM_ifstate_enable);
120
121 if (register_wlandev(wlandev) != 0) {
122 dev_err(&interface->dev, "register_wlandev() failed.\n");
123 result = -EIO;
124 goto failed_register;
125 }
126
127 goto done;
128
129 failed_register:
130 usb_put_dev(dev);
131 failed_reset:
132 wlan_unsetup(wlandev);
133 failed:
134 kfree(wlandev);
135 kfree(hw);
136 wlandev = NULL;
137
138 done:
139 usb_set_intfdata(interface, wlandev);
140 return result;
141 }
142
143 static void prism2sta_disconnect_usb(struct usb_interface *interface)
144 {
145 struct wlandevice *wlandev;
146
147 wlandev = (struct wlandevice *)usb_get_intfdata(interface);
148 if (wlandev) {
149 LIST_HEAD(cleanlist);
150 struct hfa384x_usbctlx *ctlx, *temp;
151 unsigned long flags;
152
153 struct hfa384x *hw = wlandev->priv;
154
155 if (!hw)
156 goto exit;
157
158 spin_lock_irqsave(&hw->ctlxq.lock, flags);
159
160 p80211netdev_hwremoved(wlandev);
161 list_splice_init(&hw->ctlxq.reapable, &cleanlist);
162 list_splice_init(&hw->ctlxq.completing, &cleanlist);
163 list_splice_init(&hw->ctlxq.pending, &cleanlist);
164 list_splice_init(&hw->ctlxq.active, &cleanlist);
165
166 spin_unlock_irqrestore(&hw->ctlxq.lock, flags);
167
168 /* There's no hardware to shutdown, but the driver
169 * might have some tasks or tasklets that must be
170 * stopped before we can tear everything down.
171 */
172 prism2sta_ifstate(wlandev, P80211ENUM_ifstate_disable);
173
174 del_singleshot_timer_sync(&hw->throttle);
175 del_singleshot_timer_sync(&hw->reqtimer);
176 del_singleshot_timer_sync(&hw->resptimer);
177
178 /* Unlink all the URBs. This "removes the wheels"
179 * from the entire CTLX handling mechanism.
180 */
181 usb_kill_urb(&hw->rx_urb);
182 usb_kill_urb(&hw->tx_urb);
183 usb_kill_urb(&hw->ctlx_urb);
184
185 tasklet_kill(&hw->completion_bh);
186 tasklet_kill(&hw->reaper_bh);
187
188 cancel_work_sync(&hw->link_bh);
189 cancel_work_sync(&hw->commsqual_bh);
190 cancel_work_sync(&hw->usb_work);
191
192 /* Now we complete any outstanding commands
193 * and tell everyone who is waiting for their
194 * responses that we have shut down.
195 */
196 list_for_each_entry(ctlx, &cleanlist, list)
197 complete(&ctlx->done);
198
199 /* Give any outstanding synchronous commands
200 * a chance to complete. All they need to do
201 * is "wake up", so that's easy.
202 * (I'd like a better way to do this, really.)
203 */
204 msleep(100);
205
206 /* Now delete the CTLXs, because no-one else can now. */
207 list_for_each_entry_safe(ctlx, temp, &cleanlist, list)
208 kfree(ctlx);
209
210 /* Unhook the wlandev */
211 unregister_wlandev(wlandev);
212 wlan_unsetup(wlandev);
213
214 usb_put_dev(hw->usb);
215
216 hfa384x_destroy(hw);
217 kfree(hw);
218
219 kfree(wlandev);
220 }
221
222 exit:
223 usb_set_intfdata(interface, NULL);
224 }
225
226 #ifdef CONFIG_PM
227 static int prism2sta_suspend(struct usb_interface *interface,
228 pm_message_t message)
229 {
230 struct hfa384x *hw = NULL;
231 struct wlandevice *wlandev;
232
233 wlandev = (struct wlandevice *)usb_get_intfdata(interface);
234 if (!wlandev)
235 return -ENODEV;
236
237 hw = wlandev->priv;
238 if (!hw)
239 return -ENODEV;
240
241 prism2sta_ifstate(wlandev, P80211ENUM_ifstate_disable);
242
243 usb_kill_urb(&hw->rx_urb);
244 usb_kill_urb(&hw->tx_urb);
245 usb_kill_urb(&hw->ctlx_urb);
246
247 return 0;
248 }
249
250 static int prism2sta_resume(struct usb_interface *interface)
251 {
252 int result = 0;
253 struct hfa384x *hw = NULL;
254 struct wlandevice *wlandev;
255
256 wlandev = (struct wlandevice *)usb_get_intfdata(interface);
257 if (!wlandev)
258 return -ENODEV;
259
260 hw = wlandev->priv;
261 if (!hw)
262 return -ENODEV;
263
264 /* Do a chip-level reset on the MAC */
265 if (prism2_doreset) {
266 result = hfa384x_corereset(hw,
267 prism2_reset_holdtime,
268 prism2_reset_settletime, 0);
269 if (result != 0) {
270 unregister_wlandev(wlandev);
271 hfa384x_destroy(hw);
272 dev_err(&interface->dev, "hfa384x_corereset() failed.\n");
273 kfree(wlandev);
274 kfree(hw);
275 wlandev = NULL;
276 return -ENODEV;
277 }
278 }
279
280 prism2sta_ifstate(wlandev, P80211ENUM_ifstate_enable);
281
282 return 0;
283 }
284 #else
285 #define prism2sta_suspend NULL
286 #define prism2sta_resume NULL
287 #endif /* CONFIG_PM */
288
289 static struct usb_driver prism2_usb_driver = {
290 .name = "prism2_usb",
291 .probe = prism2sta_probe_usb,
292 .disconnect = prism2sta_disconnect_usb,
293 .id_table = usb_prism_tbl,
294 .suspend = prism2sta_suspend,
295 .resume = prism2sta_resume,
296 .reset_resume = prism2sta_resume,
297 /* fops, minor? */
298 };
299
300 module_usb_driver(prism2_usb_driver);