xref: /openbmc/linux/drivers/net/wireless/ath/wil6210/cfg80211.c (revision a5dc688392737bbab3699d63f26e853a40c52d2d)
1 /*
2  * Copyright (c) 2012-2017 Qualcomm Atheros, Inc.
3  *
4  * Permission to use, copy, modify, and/or distribute this software for any
5  * purpose with or without fee is hereby granted, provided that the above
6  * copyright notice and this permission notice appear in all copies.
7  *
8  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
9  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
10  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
11  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
12  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
13  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
14  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
15  */
16 
17 #include <linux/etherdevice.h>
18 #include <linux/moduleparam.h>
19 #include <net/netlink.h>
20 #include "wil6210.h"
21 #include "wmi.h"
22 
23 #define WIL_MAX_ROC_DURATION_MS 5000
24 
25 bool disable_ap_sme;
26 module_param(disable_ap_sme, bool, 0444);
27 MODULE_PARM_DESC(disable_ap_sme, " let user space handle AP mode SME");
28 
29 #ifdef CONFIG_PM
30 static struct wiphy_wowlan_support wil_wowlan_support = {
31 	.flags = WIPHY_WOWLAN_ANY | WIPHY_WOWLAN_DISCONNECT,
32 };
33 #endif
34 
35 #define CHAN60G(_channel, _flags) {				\
36 	.band			= NL80211_BAND_60GHZ,		\
37 	.center_freq		= 56160 + (2160 * (_channel)),	\
38 	.hw_value		= (_channel),			\
39 	.flags			= (_flags),			\
40 	.max_antenna_gain	= 0,				\
41 	.max_power		= 40,				\
42 }
43 
44 static struct ieee80211_channel wil_60ghz_channels[] = {
45 	CHAN60G(1, 0),
46 	CHAN60G(2, 0),
47 	CHAN60G(3, 0),
48 /* channel 4 not supported yet */
49 };
50 
51 /* Vendor id to be used in vendor specific command and events
52  * to user space.
53  * NOTE: The authoritative place for definition of QCA_NL80211_VENDOR_ID,
54  * vendor subcmd definitions prefixed with QCA_NL80211_VENDOR_SUBCMD, and
55  * qca_wlan_vendor_attr is open source file src/common/qca-vendor.h in
56  * git://w1.fi/srv/git/hostap.git; the values here are just a copy of that
57  */
58 
59 #define QCA_NL80211_VENDOR_ID	0x001374
60 
61 #define WIL_MAX_RF_SECTORS (128)
62 #define WIL_CID_ALL (0xff)
63 
64 enum qca_wlan_vendor_attr_rf_sector {
65 	QCA_ATTR_MAC_ADDR = 6,
66 	QCA_ATTR_PAD = 13,
67 	QCA_ATTR_TSF = 29,
68 	QCA_ATTR_DMG_RF_SECTOR_INDEX = 30,
69 	QCA_ATTR_DMG_RF_SECTOR_TYPE = 31,
70 	QCA_ATTR_DMG_RF_MODULE_MASK = 32,
71 	QCA_ATTR_DMG_RF_SECTOR_CFG = 33,
72 	QCA_ATTR_DMG_RF_SECTOR_MAX,
73 };
74 
75 enum qca_wlan_vendor_attr_dmg_rf_sector_type {
76 	QCA_ATTR_DMG_RF_SECTOR_TYPE_RX,
77 	QCA_ATTR_DMG_RF_SECTOR_TYPE_TX,
78 	QCA_ATTR_DMG_RF_SECTOR_TYPE_MAX
79 };
80 
81 enum qca_wlan_vendor_attr_dmg_rf_sector_cfg {
82 	QCA_ATTR_DMG_RF_SECTOR_CFG_INVALID = 0,
83 	QCA_ATTR_DMG_RF_SECTOR_CFG_MODULE_INDEX,
84 	QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE0,
85 	QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE1,
86 	QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE2,
87 	QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_HI,
88 	QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_LO,
89 	QCA_ATTR_DMG_RF_SECTOR_CFG_DTYPE_X16,
90 
91 	/* keep last */
92 	QCA_ATTR_DMG_RF_SECTOR_CFG_AFTER_LAST,
93 	QCA_ATTR_DMG_RF_SECTOR_CFG_MAX =
94 	QCA_ATTR_DMG_RF_SECTOR_CFG_AFTER_LAST - 1
95 };
96 
97 static const struct
98 nla_policy wil_rf_sector_policy[QCA_ATTR_DMG_RF_SECTOR_MAX + 1] = {
99 	[QCA_ATTR_MAC_ADDR] = { .len = ETH_ALEN },
100 	[QCA_ATTR_DMG_RF_SECTOR_INDEX] = { .type = NLA_U16 },
101 	[QCA_ATTR_DMG_RF_SECTOR_TYPE] = { .type = NLA_U8 },
102 	[QCA_ATTR_DMG_RF_MODULE_MASK] = { .type = NLA_U32 },
103 	[QCA_ATTR_DMG_RF_SECTOR_CFG] = { .type = NLA_NESTED },
104 };
105 
106 static const struct
107 nla_policy wil_rf_sector_cfg_policy[QCA_ATTR_DMG_RF_SECTOR_CFG_MAX + 1] = {
108 	[QCA_ATTR_DMG_RF_SECTOR_CFG_MODULE_INDEX] = { .type = NLA_U8 },
109 	[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE0] = { .type = NLA_U32 },
110 	[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE1] = { .type = NLA_U32 },
111 	[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE2] = { .type = NLA_U32 },
112 	[QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_HI] = { .type = NLA_U32 },
113 	[QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_LO] = { .type = NLA_U32 },
114 	[QCA_ATTR_DMG_RF_SECTOR_CFG_DTYPE_X16] = { .type = NLA_U32 },
115 };
116 
117 enum qca_nl80211_vendor_subcmds {
118 	QCA_NL80211_VENDOR_SUBCMD_DMG_RF_GET_SECTOR_CFG = 139,
119 	QCA_NL80211_VENDOR_SUBCMD_DMG_RF_SET_SECTOR_CFG = 140,
120 	QCA_NL80211_VENDOR_SUBCMD_DMG_RF_GET_SELECTED_SECTOR = 141,
121 	QCA_NL80211_VENDOR_SUBCMD_DMG_RF_SET_SELECTED_SECTOR = 142,
122 };
123 
124 static int wil_rf_sector_get_cfg(struct wiphy *wiphy,
125 				 struct wireless_dev *wdev,
126 				 const void *data, int data_len);
127 static int wil_rf_sector_set_cfg(struct wiphy *wiphy,
128 				 struct wireless_dev *wdev,
129 				 const void *data, int data_len);
130 static int wil_rf_sector_get_selected(struct wiphy *wiphy,
131 				      struct wireless_dev *wdev,
132 				      const void *data, int data_len);
133 static int wil_rf_sector_set_selected(struct wiphy *wiphy,
134 				      struct wireless_dev *wdev,
135 				      const void *data, int data_len);
136 
137 /* vendor specific commands */
138 static const struct wiphy_vendor_command wil_nl80211_vendor_commands[] = {
139 	{
140 		.info.vendor_id = QCA_NL80211_VENDOR_ID,
141 		.info.subcmd = QCA_NL80211_VENDOR_SUBCMD_DMG_RF_GET_SECTOR_CFG,
142 		.flags = WIPHY_VENDOR_CMD_NEED_WDEV |
143 			 WIPHY_VENDOR_CMD_NEED_RUNNING,
144 		.doit = wil_rf_sector_get_cfg
145 	},
146 	{
147 		.info.vendor_id = QCA_NL80211_VENDOR_ID,
148 		.info.subcmd = QCA_NL80211_VENDOR_SUBCMD_DMG_RF_SET_SECTOR_CFG,
149 		.flags = WIPHY_VENDOR_CMD_NEED_WDEV |
150 			 WIPHY_VENDOR_CMD_NEED_RUNNING,
151 		.doit = wil_rf_sector_set_cfg
152 	},
153 	{
154 		.info.vendor_id = QCA_NL80211_VENDOR_ID,
155 		.info.subcmd =
156 			QCA_NL80211_VENDOR_SUBCMD_DMG_RF_GET_SELECTED_SECTOR,
157 		.flags = WIPHY_VENDOR_CMD_NEED_WDEV |
158 			 WIPHY_VENDOR_CMD_NEED_RUNNING,
159 		.doit = wil_rf_sector_get_selected
160 	},
161 	{
162 		.info.vendor_id = QCA_NL80211_VENDOR_ID,
163 		.info.subcmd =
164 			QCA_NL80211_VENDOR_SUBCMD_DMG_RF_SET_SELECTED_SECTOR,
165 		.flags = WIPHY_VENDOR_CMD_NEED_WDEV |
166 			 WIPHY_VENDOR_CMD_NEED_RUNNING,
167 		.doit = wil_rf_sector_set_selected
168 	},
169 };
170 
171 static struct ieee80211_supported_band wil_band_60ghz = {
172 	.channels = wil_60ghz_channels,
173 	.n_channels = ARRAY_SIZE(wil_60ghz_channels),
174 	.ht_cap = {
175 		.ht_supported = true,
176 		.cap = 0, /* TODO */
177 		.ampdu_factor = IEEE80211_HT_MAX_AMPDU_64K, /* TODO */
178 		.ampdu_density = IEEE80211_HT_MPDU_DENSITY_8, /* TODO */
179 		.mcs = {
180 				/* MCS 1..12 - SC PHY */
181 			.rx_mask = {0xfe, 0x1f}, /* 1..12 */
182 			.tx_params = IEEE80211_HT_MCS_TX_DEFINED, /* TODO */
183 		},
184 	},
185 };
186 
187 static const struct ieee80211_txrx_stypes
188 wil_mgmt_stypes[NUM_NL80211_IFTYPES] = {
189 	[NL80211_IFTYPE_STATION] = {
190 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
191 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
192 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
193 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
194 	},
195 	[NL80211_IFTYPE_AP] = {
196 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
197 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4) |
198 		BIT(IEEE80211_STYPE_ASSOC_RESP >> 4) |
199 		BIT(IEEE80211_STYPE_DISASSOC >> 4),
200 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
201 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4) |
202 		BIT(IEEE80211_STYPE_ASSOC_REQ >> 4) |
203 		BIT(IEEE80211_STYPE_DISASSOC >> 4) |
204 		BIT(IEEE80211_STYPE_AUTH >> 4) |
205 		BIT(IEEE80211_STYPE_DEAUTH >> 4) |
206 		BIT(IEEE80211_STYPE_REASSOC_REQ >> 4)
207 	},
208 	[NL80211_IFTYPE_P2P_CLIENT] = {
209 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
210 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
211 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
212 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
213 	},
214 	[NL80211_IFTYPE_P2P_GO] = {
215 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
216 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
217 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
218 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
219 	},
220 	[NL80211_IFTYPE_P2P_DEVICE] = {
221 		.tx = BIT(IEEE80211_STYPE_ACTION >> 4) |
222 		BIT(IEEE80211_STYPE_PROBE_RESP >> 4),
223 		.rx = BIT(IEEE80211_STYPE_ACTION >> 4) |
224 		BIT(IEEE80211_STYPE_PROBE_REQ >> 4)
225 	},
226 };
227 
228 static const u32 wil_cipher_suites[] = {
229 	WLAN_CIPHER_SUITE_GCMP,
230 };
231 
232 static const char * const key_usage_str[] = {
233 	[WMI_KEY_USE_PAIRWISE]	= "PTK",
234 	[WMI_KEY_USE_RX_GROUP]	= "RX_GTK",
235 	[WMI_KEY_USE_TX_GROUP]	= "TX_GTK",
236 };
237 
238 int wil_iftype_nl2wmi(enum nl80211_iftype type)
239 {
240 	static const struct {
241 		enum nl80211_iftype nl;
242 		enum wmi_network_type wmi;
243 	} __nl2wmi[] = {
244 		{NL80211_IFTYPE_ADHOC,		WMI_NETTYPE_ADHOC},
245 		{NL80211_IFTYPE_STATION,	WMI_NETTYPE_INFRA},
246 		{NL80211_IFTYPE_AP,		WMI_NETTYPE_AP},
247 		{NL80211_IFTYPE_P2P_CLIENT,	WMI_NETTYPE_P2P},
248 		{NL80211_IFTYPE_P2P_GO,		WMI_NETTYPE_P2P},
249 		{NL80211_IFTYPE_MONITOR,	WMI_NETTYPE_ADHOC}, /* FIXME */
250 	};
251 	uint i;
252 
253 	for (i = 0; i < ARRAY_SIZE(__nl2wmi); i++) {
254 		if (__nl2wmi[i].nl == type)
255 			return __nl2wmi[i].wmi;
256 	}
257 
258 	return -EOPNOTSUPP;
259 }
260 
261 int wil_cid_fill_sinfo(struct wil6210_priv *wil, int cid,
262 		       struct station_info *sinfo)
263 {
264 	struct wmi_notify_req_cmd cmd = {
265 		.cid = cid,
266 		.interval_usec = 0,
267 	};
268 	struct {
269 		struct wmi_cmd_hdr wmi;
270 		struct wmi_notify_req_done_event evt;
271 	} __packed reply;
272 	struct wil_net_stats *stats = &wil->sta[cid].stats;
273 	int rc;
274 
275 	rc = wmi_call(wil, WMI_NOTIFY_REQ_CMDID, &cmd, sizeof(cmd),
276 		      WMI_NOTIFY_REQ_DONE_EVENTID, &reply, sizeof(reply), 20);
277 	if (rc)
278 		return rc;
279 
280 	wil_dbg_wmi(wil, "Link status for CID %d: {\n"
281 		    "  MCS %d TSF 0x%016llx\n"
282 		    "  BF status 0x%08x RSSI %d SQI %d%%\n"
283 		    "  Tx Tpt %d goodput %d Rx goodput %d\n"
284 		    "  Sectors(rx:tx) my %d:%d peer %d:%d\n""}\n",
285 		    cid, le16_to_cpu(reply.evt.bf_mcs),
286 		    le64_to_cpu(reply.evt.tsf), reply.evt.status,
287 		    reply.evt.rssi,
288 		    reply.evt.sqi,
289 		    le32_to_cpu(reply.evt.tx_tpt),
290 		    le32_to_cpu(reply.evt.tx_goodput),
291 		    le32_to_cpu(reply.evt.rx_goodput),
292 		    le16_to_cpu(reply.evt.my_rx_sector),
293 		    le16_to_cpu(reply.evt.my_tx_sector),
294 		    le16_to_cpu(reply.evt.other_rx_sector),
295 		    le16_to_cpu(reply.evt.other_tx_sector));
296 
297 	sinfo->generation = wil->sinfo_gen;
298 
299 	sinfo->filled = BIT(NL80211_STA_INFO_RX_BYTES) |
300 			BIT(NL80211_STA_INFO_TX_BYTES) |
301 			BIT(NL80211_STA_INFO_RX_PACKETS) |
302 			BIT(NL80211_STA_INFO_TX_PACKETS) |
303 			BIT(NL80211_STA_INFO_RX_BITRATE) |
304 			BIT(NL80211_STA_INFO_TX_BITRATE) |
305 			BIT(NL80211_STA_INFO_RX_DROP_MISC) |
306 			BIT(NL80211_STA_INFO_TX_FAILED);
307 
308 	sinfo->txrate.flags = RATE_INFO_FLAGS_60G;
309 	sinfo->txrate.mcs = le16_to_cpu(reply.evt.bf_mcs);
310 	sinfo->rxrate.mcs = stats->last_mcs_rx;
311 	sinfo->rx_bytes = stats->rx_bytes;
312 	sinfo->rx_packets = stats->rx_packets;
313 	sinfo->rx_dropped_misc = stats->rx_dropped;
314 	sinfo->tx_bytes = stats->tx_bytes;
315 	sinfo->tx_packets = stats->tx_packets;
316 	sinfo->tx_failed = stats->tx_errors;
317 
318 	if (test_bit(wil_status_fwconnected, wil->status)) {
319 		sinfo->filled |= BIT(NL80211_STA_INFO_SIGNAL);
320 		if (test_bit(WMI_FW_CAPABILITY_RSSI_REPORTING,
321 			     wil->fw_capabilities))
322 			sinfo->signal = reply.evt.rssi;
323 		else
324 			sinfo->signal = reply.evt.sqi;
325 	}
326 
327 	return rc;
328 }
329 
330 static int wil_cfg80211_get_station(struct wiphy *wiphy,
331 				    struct net_device *ndev,
332 				    const u8 *mac, struct station_info *sinfo)
333 {
334 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
335 	int rc;
336 
337 	int cid = wil_find_cid(wil, mac);
338 
339 	wil_dbg_misc(wil, "get_station: %pM CID %d\n", mac, cid);
340 	if (cid < 0)
341 		return cid;
342 
343 	rc = wil_cid_fill_sinfo(wil, cid, sinfo);
344 
345 	return rc;
346 }
347 
348 /*
349  * Find @idx-th active STA for station dump.
350  */
351 static int wil_find_cid_by_idx(struct wil6210_priv *wil, int idx)
352 {
353 	int i;
354 
355 	for (i = 0; i < ARRAY_SIZE(wil->sta); i++) {
356 		if (wil->sta[i].status == wil_sta_unused)
357 			continue;
358 		if (idx == 0)
359 			return i;
360 		idx--;
361 	}
362 
363 	return -ENOENT;
364 }
365 
366 static int wil_cfg80211_dump_station(struct wiphy *wiphy,
367 				     struct net_device *dev, int idx,
368 				     u8 *mac, struct station_info *sinfo)
369 {
370 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
371 	int rc;
372 	int cid = wil_find_cid_by_idx(wil, idx);
373 
374 	if (cid < 0)
375 		return -ENOENT;
376 
377 	ether_addr_copy(mac, wil->sta[cid].addr);
378 	wil_dbg_misc(wil, "dump_station: %pM CID %d\n", mac, cid);
379 
380 	rc = wil_cid_fill_sinfo(wil, cid, sinfo);
381 
382 	return rc;
383 }
384 
385 static int wil_cfg80211_start_p2p_device(struct wiphy *wiphy,
386 					 struct wireless_dev *wdev)
387 {
388 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
389 
390 	wil_dbg_misc(wil, "start_p2p_device: entered\n");
391 	wil->p2p.p2p_dev_started = 1;
392 	return 0;
393 }
394 
395 static void wil_cfg80211_stop_p2p_device(struct wiphy *wiphy,
396 					 struct wireless_dev *wdev)
397 {
398 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
399 	struct wil_p2p_info *p2p = &wil->p2p;
400 
401 	if (!p2p->p2p_dev_started)
402 		return;
403 
404 	wil_dbg_misc(wil, "stop_p2p_device: entered\n");
405 	mutex_lock(&wil->mutex);
406 	mutex_lock(&wil->p2p_wdev_mutex);
407 	wil_p2p_stop_radio_operations(wil);
408 	p2p->p2p_dev_started = 0;
409 	mutex_unlock(&wil->p2p_wdev_mutex);
410 	mutex_unlock(&wil->mutex);
411 }
412 
413 static struct wireless_dev *
414 wil_cfg80211_add_iface(struct wiphy *wiphy, const char *name,
415 		       unsigned char name_assign_type,
416 		       enum nl80211_iftype type,
417 		       struct vif_params *params)
418 {
419 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
420 	struct net_device *ndev = wil_to_ndev(wil);
421 	struct wireless_dev *p2p_wdev;
422 
423 	wil_dbg_misc(wil, "add_iface\n");
424 
425 	if (type != NL80211_IFTYPE_P2P_DEVICE) {
426 		wil_err(wil, "unsupported iftype %d\n", type);
427 		return ERR_PTR(-EINVAL);
428 	}
429 
430 	if (wil->p2p_wdev) {
431 		wil_err(wil, "P2P_DEVICE interface already created\n");
432 		return ERR_PTR(-EINVAL);
433 	}
434 
435 	p2p_wdev = kzalloc(sizeof(*p2p_wdev), GFP_KERNEL);
436 	if (!p2p_wdev)
437 		return ERR_PTR(-ENOMEM);
438 
439 	p2p_wdev->iftype = type;
440 	p2p_wdev->wiphy = wiphy;
441 	/* use our primary ethernet address */
442 	ether_addr_copy(p2p_wdev->address, ndev->perm_addr);
443 
444 	wil->p2p_wdev = p2p_wdev;
445 
446 	return p2p_wdev;
447 }
448 
449 static int wil_cfg80211_del_iface(struct wiphy *wiphy,
450 				  struct wireless_dev *wdev)
451 {
452 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
453 
454 	wil_dbg_misc(wil, "del_iface\n");
455 
456 	if (wdev != wil->p2p_wdev) {
457 		wil_err(wil, "delete of incorrect interface 0x%p\n", wdev);
458 		return -EINVAL;
459 	}
460 
461 	wil_cfg80211_stop_p2p_device(wiphy, wdev);
462 	wil_p2p_wdev_free(wil);
463 
464 	return 0;
465 }
466 
467 static int wil_cfg80211_change_iface(struct wiphy *wiphy,
468 				     struct net_device *ndev,
469 				     enum nl80211_iftype type,
470 				     struct vif_params *params)
471 {
472 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
473 	struct wireless_dev *wdev = wil_to_wdev(wil);
474 	int rc;
475 
476 	wil_dbg_misc(wil, "change_iface: type=%d\n", type);
477 
478 	if (netif_running(wil_to_ndev(wil)) && !wil_is_recovery_blocked(wil)) {
479 		wil_dbg_misc(wil, "interface is up. resetting...\n");
480 		mutex_lock(&wil->mutex);
481 		__wil_down(wil);
482 		rc = __wil_up(wil);
483 		mutex_unlock(&wil->mutex);
484 
485 		if (rc)
486 			return rc;
487 	}
488 
489 	switch (type) {
490 	case NL80211_IFTYPE_STATION:
491 	case NL80211_IFTYPE_AP:
492 	case NL80211_IFTYPE_P2P_CLIENT:
493 	case NL80211_IFTYPE_P2P_GO:
494 		break;
495 	case NL80211_IFTYPE_MONITOR:
496 		if (params->flags)
497 			wil->monitor_flags = params->flags;
498 		break;
499 	default:
500 		return -EOPNOTSUPP;
501 	}
502 
503 	wdev->iftype = type;
504 
505 	return 0;
506 }
507 
508 static int wil_cfg80211_scan(struct wiphy *wiphy,
509 			     struct cfg80211_scan_request *request)
510 {
511 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
512 	struct wireless_dev *wdev = request->wdev;
513 	struct {
514 		struct wmi_start_scan_cmd cmd;
515 		u16 chnl[4];
516 	} __packed cmd;
517 	uint i, n;
518 	int rc;
519 
520 	wil_dbg_misc(wil, "scan: wdev=0x%p iftype=%d\n", wdev, wdev->iftype);
521 
522 	/* check we are client side */
523 	switch (wdev->iftype) {
524 	case NL80211_IFTYPE_STATION:
525 	case NL80211_IFTYPE_P2P_CLIENT:
526 	case NL80211_IFTYPE_P2P_DEVICE:
527 		break;
528 	default:
529 		return -EOPNOTSUPP;
530 	}
531 
532 	/* FW don't support scan after connection attempt */
533 	if (test_bit(wil_status_dontscan, wil->status)) {
534 		wil_err(wil, "Can't scan now\n");
535 		return -EBUSY;
536 	}
537 
538 	mutex_lock(&wil->mutex);
539 
540 	mutex_lock(&wil->p2p_wdev_mutex);
541 	if (wil->scan_request || wil->p2p.discovery_started) {
542 		wil_err(wil, "Already scanning\n");
543 		mutex_unlock(&wil->p2p_wdev_mutex);
544 		rc = -EAGAIN;
545 		goto out;
546 	}
547 	mutex_unlock(&wil->p2p_wdev_mutex);
548 
549 	if (wdev->iftype == NL80211_IFTYPE_P2P_DEVICE) {
550 		if (!wil->p2p.p2p_dev_started) {
551 			wil_err(wil, "P2P search requested on stopped P2P device\n");
552 			rc = -EIO;
553 			goto out;
554 		}
555 		/* social scan on P2P_DEVICE is handled as p2p search */
556 		if (wil_p2p_is_social_scan(request)) {
557 			wil->scan_request = request;
558 			wil->radio_wdev = wdev;
559 			rc = wil_p2p_search(wil, request);
560 			if (rc) {
561 				wil->radio_wdev = wil_to_wdev(wil);
562 				wil->scan_request = NULL;
563 			}
564 			goto out;
565 		}
566 	}
567 
568 	(void)wil_p2p_stop_discovery(wil);
569 
570 	wil_dbg_misc(wil, "Start scan_request 0x%p\n", request);
571 	wil_dbg_misc(wil, "SSID count: %d", request->n_ssids);
572 
573 	for (i = 0; i < request->n_ssids; i++) {
574 		wil_dbg_misc(wil, "SSID[%d]", i);
575 		wil_hex_dump_misc("SSID ", DUMP_PREFIX_OFFSET, 16, 1,
576 				  request->ssids[i].ssid,
577 				  request->ssids[i].ssid_len, true);
578 	}
579 
580 	if (request->n_ssids)
581 		rc = wmi_set_ssid(wil, request->ssids[0].ssid_len,
582 				  request->ssids[0].ssid);
583 	else
584 		rc = wmi_set_ssid(wil, 0, NULL);
585 
586 	if (rc) {
587 		wil_err(wil, "set SSID for scan request failed: %d\n", rc);
588 		goto out;
589 	}
590 
591 	wil->scan_request = request;
592 	mod_timer(&wil->scan_timer, jiffies + WIL6210_SCAN_TO);
593 
594 	memset(&cmd, 0, sizeof(cmd));
595 	cmd.cmd.scan_type = WMI_ACTIVE_SCAN;
596 	cmd.cmd.num_channels = 0;
597 	n = min(request->n_channels, 4U);
598 	for (i = 0; i < n; i++) {
599 		int ch = request->channels[i]->hw_value;
600 
601 		if (ch == 0) {
602 			wil_err(wil,
603 				"Scan requested for unknown frequency %dMhz\n",
604 				request->channels[i]->center_freq);
605 			continue;
606 		}
607 		/* 0-based channel indexes */
608 		cmd.cmd.channel_list[cmd.cmd.num_channels++].channel = ch - 1;
609 		wil_dbg_misc(wil, "Scan for ch %d  : %d MHz\n", ch,
610 			     request->channels[i]->center_freq);
611 	}
612 
613 	if (request->ie_len)
614 		wil_hex_dump_misc("Scan IE ", DUMP_PREFIX_OFFSET, 16, 1,
615 				  request->ie, request->ie_len, true);
616 	else
617 		wil_dbg_misc(wil, "Scan has no IE's\n");
618 
619 	rc = wmi_set_ie(wil, WMI_FRAME_PROBE_REQ, request->ie_len, request->ie);
620 	if (rc)
621 		goto out_restore;
622 
623 	if (wil->discovery_mode && cmd.cmd.scan_type == WMI_ACTIVE_SCAN) {
624 		cmd.cmd.discovery_mode = 1;
625 		wil_dbg_misc(wil, "active scan with discovery_mode=1\n");
626 	}
627 
628 	wil->radio_wdev = wdev;
629 	rc = wmi_send(wil, WMI_START_SCAN_CMDID, &cmd, sizeof(cmd.cmd) +
630 			cmd.cmd.num_channels * sizeof(cmd.cmd.channel_list[0]));
631 
632 out_restore:
633 	if (rc) {
634 		del_timer_sync(&wil->scan_timer);
635 		wil->radio_wdev = wil_to_wdev(wil);
636 		wil->scan_request = NULL;
637 	}
638 out:
639 	mutex_unlock(&wil->mutex);
640 	return rc;
641 }
642 
643 static void wil_cfg80211_abort_scan(struct wiphy *wiphy,
644 				    struct wireless_dev *wdev)
645 {
646 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
647 
648 	wil_dbg_misc(wil, "wdev=0x%p iftype=%d\n", wdev, wdev->iftype);
649 
650 	mutex_lock(&wil->mutex);
651 	mutex_lock(&wil->p2p_wdev_mutex);
652 
653 	if (!wil->scan_request)
654 		goto out;
655 
656 	if (wdev != wil->scan_request->wdev) {
657 		wil_dbg_misc(wil, "abort scan was called on the wrong iface\n");
658 		goto out;
659 	}
660 
661 	if (wil->radio_wdev == wil->p2p_wdev)
662 		wil_p2p_stop_radio_operations(wil);
663 	else
664 		wil_abort_scan(wil, true);
665 
666 out:
667 	mutex_unlock(&wil->p2p_wdev_mutex);
668 	mutex_unlock(&wil->mutex);
669 }
670 
671 static void wil_print_crypto(struct wil6210_priv *wil,
672 			     struct cfg80211_crypto_settings *c)
673 {
674 	int i, n;
675 
676 	wil_dbg_misc(wil, "WPA versions: 0x%08x cipher group 0x%08x\n",
677 		     c->wpa_versions, c->cipher_group);
678 	wil_dbg_misc(wil, "Pairwise ciphers [%d] {\n", c->n_ciphers_pairwise);
679 	n = min_t(int, c->n_ciphers_pairwise, ARRAY_SIZE(c->ciphers_pairwise));
680 	for (i = 0; i < n; i++)
681 		wil_dbg_misc(wil, "  [%d] = 0x%08x\n", i,
682 			     c->ciphers_pairwise[i]);
683 	wil_dbg_misc(wil, "}\n");
684 	wil_dbg_misc(wil, "AKM suites [%d] {\n", c->n_akm_suites);
685 	n = min_t(int, c->n_akm_suites, ARRAY_SIZE(c->akm_suites));
686 	for (i = 0; i < n; i++)
687 		wil_dbg_misc(wil, "  [%d] = 0x%08x\n", i,
688 			     c->akm_suites[i]);
689 	wil_dbg_misc(wil, "}\n");
690 	wil_dbg_misc(wil, "Control port : %d, eth_type 0x%04x no_encrypt %d\n",
691 		     c->control_port, be16_to_cpu(c->control_port_ethertype),
692 		     c->control_port_no_encrypt);
693 }
694 
695 static void wil_print_connect_params(struct wil6210_priv *wil,
696 				     struct cfg80211_connect_params *sme)
697 {
698 	wil_info(wil, "Connecting to:\n");
699 	if (sme->channel) {
700 		wil_info(wil, "  Channel: %d freq %d\n",
701 			 sme->channel->hw_value, sme->channel->center_freq);
702 	}
703 	if (sme->bssid)
704 		wil_info(wil, "  BSSID: %pM\n", sme->bssid);
705 	if (sme->ssid)
706 		print_hex_dump(KERN_INFO, "  SSID: ", DUMP_PREFIX_OFFSET,
707 			       16, 1, sme->ssid, sme->ssid_len, true);
708 	wil_info(wil, "  Privacy: %s\n", sme->privacy ? "secure" : "open");
709 	wil_info(wil, "  PBSS: %d\n", sme->pbss);
710 	wil_print_crypto(wil, &sme->crypto);
711 }
712 
713 static int wil_cfg80211_connect(struct wiphy *wiphy,
714 				struct net_device *ndev,
715 				struct cfg80211_connect_params *sme)
716 {
717 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
718 	struct cfg80211_bss *bss;
719 	struct wmi_connect_cmd conn;
720 	const u8 *ssid_eid;
721 	const u8 *rsn_eid;
722 	int ch;
723 	int rc = 0;
724 	enum ieee80211_bss_type bss_type = IEEE80211_BSS_TYPE_ESS;
725 
726 	wil_dbg_misc(wil, "connect\n");
727 	wil_print_connect_params(wil, sme);
728 
729 	if (test_bit(wil_status_fwconnecting, wil->status) ||
730 	    test_bit(wil_status_fwconnected, wil->status))
731 		return -EALREADY;
732 
733 	if (sme->ie_len > WMI_MAX_IE_LEN) {
734 		wil_err(wil, "IE too large (%td bytes)\n", sme->ie_len);
735 		return -ERANGE;
736 	}
737 
738 	rsn_eid = sme->ie ?
739 			cfg80211_find_ie(WLAN_EID_RSN, sme->ie, sme->ie_len) :
740 			NULL;
741 	if (sme->privacy && !rsn_eid)
742 		wil_info(wil, "WSC connection\n");
743 
744 	if (sme->pbss)
745 		bss_type = IEEE80211_BSS_TYPE_PBSS;
746 
747 	bss = cfg80211_get_bss(wiphy, sme->channel, sme->bssid,
748 			       sme->ssid, sme->ssid_len,
749 			       bss_type, IEEE80211_PRIVACY_ANY);
750 	if (!bss) {
751 		wil_err(wil, "Unable to find BSS\n");
752 		return -ENOENT;
753 	}
754 
755 	ssid_eid = ieee80211_bss_get_ie(bss, WLAN_EID_SSID);
756 	if (!ssid_eid) {
757 		wil_err(wil, "No SSID\n");
758 		rc = -ENOENT;
759 		goto out;
760 	}
761 	wil->privacy = sme->privacy;
762 	wil->pbss = sme->pbss;
763 
764 	if (wil->privacy) {
765 		/* For secure assoc, remove old keys */
766 		rc = wmi_del_cipher_key(wil, 0, bss->bssid,
767 					WMI_KEY_USE_PAIRWISE);
768 		if (rc) {
769 			wil_err(wil, "WMI_DELETE_CIPHER_KEY_CMD(PTK) failed\n");
770 			goto out;
771 		}
772 		rc = wmi_del_cipher_key(wil, 0, bss->bssid,
773 					WMI_KEY_USE_RX_GROUP);
774 		if (rc) {
775 			wil_err(wil, "WMI_DELETE_CIPHER_KEY_CMD(GTK) failed\n");
776 			goto out;
777 		}
778 	}
779 
780 	/* WMI_SET_APPIE_CMD. ie may contain rsn info as well as other info
781 	 * elements. Send it also in case it's empty, to erase previously set
782 	 * ies in FW.
783 	 */
784 	rc = wmi_set_ie(wil, WMI_FRAME_ASSOC_REQ, sme->ie_len, sme->ie);
785 	if (rc)
786 		goto out;
787 
788 	/* WMI_CONNECT_CMD */
789 	memset(&conn, 0, sizeof(conn));
790 	switch (bss->capability & WLAN_CAPABILITY_DMG_TYPE_MASK) {
791 	case WLAN_CAPABILITY_DMG_TYPE_AP:
792 		conn.network_type = WMI_NETTYPE_INFRA;
793 		break;
794 	case WLAN_CAPABILITY_DMG_TYPE_PBSS:
795 		conn.network_type = WMI_NETTYPE_P2P;
796 		break;
797 	default:
798 		wil_err(wil, "Unsupported BSS type, capability= 0x%04x\n",
799 			bss->capability);
800 		goto out;
801 	}
802 	if (wil->privacy) {
803 		if (rsn_eid) { /* regular secure connection */
804 			conn.dot11_auth_mode = WMI_AUTH11_SHARED;
805 			conn.auth_mode = WMI_AUTH_WPA2_PSK;
806 			conn.pairwise_crypto_type = WMI_CRYPT_AES_GCMP;
807 			conn.pairwise_crypto_len = 16;
808 			conn.group_crypto_type = WMI_CRYPT_AES_GCMP;
809 			conn.group_crypto_len = 16;
810 		} else { /* WSC */
811 			conn.dot11_auth_mode = WMI_AUTH11_WSC;
812 			conn.auth_mode = WMI_AUTH_NONE;
813 		}
814 	} else { /* insecure connection */
815 		conn.dot11_auth_mode = WMI_AUTH11_OPEN;
816 		conn.auth_mode = WMI_AUTH_NONE;
817 	}
818 
819 	conn.ssid_len = min_t(u8, ssid_eid[1], 32);
820 	memcpy(conn.ssid, ssid_eid+2, conn.ssid_len);
821 
822 	ch = bss->channel->hw_value;
823 	if (ch == 0) {
824 		wil_err(wil, "BSS at unknown frequency %dMhz\n",
825 			bss->channel->center_freq);
826 		rc = -EOPNOTSUPP;
827 		goto out;
828 	}
829 	conn.channel = ch - 1;
830 
831 	ether_addr_copy(conn.bssid, bss->bssid);
832 	ether_addr_copy(conn.dst_mac, bss->bssid);
833 
834 	set_bit(wil_status_fwconnecting, wil->status);
835 
836 	rc = wmi_send(wil, WMI_CONNECT_CMDID, &conn, sizeof(conn));
837 	if (rc == 0) {
838 		netif_carrier_on(ndev);
839 		wil6210_bus_request(wil, WIL_MAX_BUS_REQUEST_KBPS);
840 		wil->bss = bss;
841 		/* Connect can take lots of time */
842 		mod_timer(&wil->connect_timer,
843 			  jiffies + msecs_to_jiffies(5000));
844 	} else {
845 		clear_bit(wil_status_fwconnecting, wil->status);
846 	}
847 
848  out:
849 	cfg80211_put_bss(wiphy, bss);
850 
851 	return rc;
852 }
853 
854 static int wil_cfg80211_disconnect(struct wiphy *wiphy,
855 				   struct net_device *ndev,
856 				   u16 reason_code)
857 {
858 	int rc;
859 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
860 
861 	wil_dbg_misc(wil, "disconnect: reason=%d\n", reason_code);
862 
863 	if (!(test_bit(wil_status_fwconnecting, wil->status) ||
864 	      test_bit(wil_status_fwconnected, wil->status))) {
865 		wil_err(wil, "Disconnect was called while disconnected\n");
866 		return 0;
867 	}
868 
869 	wil->locally_generated_disc = true;
870 	rc = wmi_call(wil, WMI_DISCONNECT_CMDID, NULL, 0,
871 		      WMI_DISCONNECT_EVENTID, NULL, 0,
872 		      WIL6210_DISCONNECT_TO_MS);
873 	if (rc)
874 		wil_err(wil, "disconnect error %d\n", rc);
875 
876 	return rc;
877 }
878 
879 static int wil_cfg80211_set_wiphy_params(struct wiphy *wiphy, u32 changed)
880 {
881 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
882 	int rc;
883 
884 	/* these parameters are explicitly not supported */
885 	if (changed & (WIPHY_PARAM_RETRY_LONG |
886 		       WIPHY_PARAM_FRAG_THRESHOLD |
887 		       WIPHY_PARAM_RTS_THRESHOLD))
888 		return -ENOTSUPP;
889 
890 	if (changed & WIPHY_PARAM_RETRY_SHORT) {
891 		rc = wmi_set_mgmt_retry(wil, wiphy->retry_short);
892 		if (rc)
893 			return rc;
894 	}
895 
896 	return 0;
897 }
898 
899 int wil_cfg80211_mgmt_tx(struct wiphy *wiphy, struct wireless_dev *wdev,
900 			 struct cfg80211_mgmt_tx_params *params,
901 			 u64 *cookie)
902 {
903 	const u8 *buf = params->buf;
904 	size_t len = params->len, total;
905 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
906 	int rc;
907 	bool tx_status = false;
908 	struct ieee80211_mgmt *mgmt_frame = (void *)buf;
909 	struct wmi_sw_tx_req_cmd *cmd;
910 	struct {
911 		struct wmi_cmd_hdr wmi;
912 		struct wmi_sw_tx_complete_event evt;
913 	} __packed evt;
914 
915 	/* Note, currently we do not support the "wait" parameter, user-space
916 	 * must call remain_on_channel before mgmt_tx or listen on a channel
917 	 * another way (AP/PCP or connected station)
918 	 * in addition we need to check if specified "chan" argument is
919 	 * different from currently "listened" channel and fail if it is.
920 	 */
921 
922 	wil_dbg_misc(wil, "mgmt_tx\n");
923 	wil_hex_dump_misc("mgmt tx frame ", DUMP_PREFIX_OFFSET, 16, 1, buf,
924 			  len, true);
925 
926 	if (len < sizeof(struct ieee80211_hdr_3addr))
927 		return -EINVAL;
928 
929 	total = sizeof(*cmd) + len;
930 	if (total < len)
931 		return -EINVAL;
932 
933 	cmd = kmalloc(total, GFP_KERNEL);
934 	if (!cmd) {
935 		rc = -ENOMEM;
936 		goto out;
937 	}
938 
939 	memcpy(cmd->dst_mac, mgmt_frame->da, WMI_MAC_LEN);
940 	cmd->len = cpu_to_le16(len);
941 	memcpy(cmd->payload, buf, len);
942 
943 	rc = wmi_call(wil, WMI_SW_TX_REQ_CMDID, cmd, total,
944 		      WMI_SW_TX_COMPLETE_EVENTID, &evt, sizeof(evt), 2000);
945 	if (rc == 0)
946 		tx_status = !evt.evt.status;
947 
948 	kfree(cmd);
949  out:
950 	cfg80211_mgmt_tx_status(wdev, cookie ? *cookie : 0, buf, len,
951 				tx_status, GFP_KERNEL);
952 	return rc;
953 }
954 
955 static int wil_cfg80211_set_channel(struct wiphy *wiphy,
956 				    struct cfg80211_chan_def *chandef)
957 {
958 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
959 	struct wireless_dev *wdev = wil_to_wdev(wil);
960 
961 	wdev->preset_chandef = *chandef;
962 
963 	return 0;
964 }
965 
966 static enum wmi_key_usage wil_detect_key_usage(struct wil6210_priv *wil,
967 					       bool pairwise)
968 {
969 	struct wireless_dev *wdev = wil_to_wdev(wil);
970 	enum wmi_key_usage rc;
971 
972 	if (pairwise) {
973 		rc = WMI_KEY_USE_PAIRWISE;
974 	} else {
975 		switch (wdev->iftype) {
976 		case NL80211_IFTYPE_STATION:
977 		case NL80211_IFTYPE_P2P_CLIENT:
978 			rc = WMI_KEY_USE_RX_GROUP;
979 			break;
980 		case NL80211_IFTYPE_AP:
981 		case NL80211_IFTYPE_P2P_GO:
982 			rc = WMI_KEY_USE_TX_GROUP;
983 			break;
984 		default:
985 			/* TODO: Rx GTK or Tx GTK? */
986 			wil_err(wil, "Can't determine GTK type\n");
987 			rc = WMI_KEY_USE_RX_GROUP;
988 			break;
989 		}
990 	}
991 	wil_dbg_misc(wil, "detect_key_usage: -> %s\n", key_usage_str[rc]);
992 
993 	return rc;
994 }
995 
996 static struct wil_sta_info *
997 wil_find_sta_by_key_usage(struct wil6210_priv *wil,
998 			  enum wmi_key_usage key_usage, const u8 *mac_addr)
999 {
1000 	int cid = -EINVAL;
1001 
1002 	if (key_usage == WMI_KEY_USE_TX_GROUP)
1003 		return NULL; /* not needed */
1004 
1005 	/* supplicant provides Rx group key in STA mode with NULL MAC address */
1006 	if (mac_addr)
1007 		cid = wil_find_cid(wil, mac_addr);
1008 	else if (key_usage == WMI_KEY_USE_RX_GROUP)
1009 		cid = wil_find_cid_by_idx(wil, 0);
1010 	if (cid < 0) {
1011 		wil_err(wil, "No CID for %pM %s\n", mac_addr,
1012 			key_usage_str[key_usage]);
1013 		return ERR_PTR(cid);
1014 	}
1015 
1016 	return &wil->sta[cid];
1017 }
1018 
1019 static void wil_set_crypto_rx(u8 key_index, enum wmi_key_usage key_usage,
1020 			      struct wil_sta_info *cs,
1021 			      struct key_params *params)
1022 {
1023 	struct wil_tid_crypto_rx_single *cc;
1024 	int tid;
1025 
1026 	if (!cs)
1027 		return;
1028 
1029 	switch (key_usage) {
1030 	case WMI_KEY_USE_PAIRWISE:
1031 		for (tid = 0; tid < WIL_STA_TID_NUM; tid++) {
1032 			cc = &cs->tid_crypto_rx[tid].key_id[key_index];
1033 			if (params->seq)
1034 				memcpy(cc->pn, params->seq,
1035 				       IEEE80211_GCMP_PN_LEN);
1036 			else
1037 				memset(cc->pn, 0, IEEE80211_GCMP_PN_LEN);
1038 			cc->key_set = true;
1039 		}
1040 		break;
1041 	case WMI_KEY_USE_RX_GROUP:
1042 		cc = &cs->group_crypto_rx.key_id[key_index];
1043 		if (params->seq)
1044 			memcpy(cc->pn, params->seq, IEEE80211_GCMP_PN_LEN);
1045 		else
1046 			memset(cc->pn, 0, IEEE80211_GCMP_PN_LEN);
1047 		cc->key_set = true;
1048 		break;
1049 	default:
1050 		break;
1051 	}
1052 }
1053 
1054 static void wil_del_rx_key(u8 key_index, enum wmi_key_usage key_usage,
1055 			   struct wil_sta_info *cs)
1056 {
1057 	struct wil_tid_crypto_rx_single *cc;
1058 	int tid;
1059 
1060 	if (!cs)
1061 		return;
1062 
1063 	switch (key_usage) {
1064 	case WMI_KEY_USE_PAIRWISE:
1065 		for (tid = 0; tid < WIL_STA_TID_NUM; tid++) {
1066 			cc = &cs->tid_crypto_rx[tid].key_id[key_index];
1067 			cc->key_set = false;
1068 		}
1069 		break;
1070 	case WMI_KEY_USE_RX_GROUP:
1071 		cc = &cs->group_crypto_rx.key_id[key_index];
1072 		cc->key_set = false;
1073 		break;
1074 	default:
1075 		break;
1076 	}
1077 }
1078 
1079 static int wil_cfg80211_add_key(struct wiphy *wiphy,
1080 				struct net_device *ndev,
1081 				u8 key_index, bool pairwise,
1082 				const u8 *mac_addr,
1083 				struct key_params *params)
1084 {
1085 	int rc;
1086 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1087 	enum wmi_key_usage key_usage = wil_detect_key_usage(wil, pairwise);
1088 	struct wil_sta_info *cs = wil_find_sta_by_key_usage(wil, key_usage,
1089 							    mac_addr);
1090 
1091 	if (!params) {
1092 		wil_err(wil, "NULL params\n");
1093 		return -EINVAL;
1094 	}
1095 
1096 	wil_dbg_misc(wil, "add_key: %pM %s[%d] PN %*phN\n",
1097 		     mac_addr, key_usage_str[key_usage], key_index,
1098 		     params->seq_len, params->seq);
1099 
1100 	if (IS_ERR(cs)) {
1101 		wil_err(wil, "Not connected, %pM %s[%d] PN %*phN\n",
1102 			mac_addr, key_usage_str[key_usage], key_index,
1103 			params->seq_len, params->seq);
1104 		return -EINVAL;
1105 	}
1106 
1107 	wil_del_rx_key(key_index, key_usage, cs);
1108 
1109 	if (params->seq && params->seq_len != IEEE80211_GCMP_PN_LEN) {
1110 		wil_err(wil,
1111 			"Wrong PN len %d, %pM %s[%d] PN %*phN\n",
1112 			params->seq_len, mac_addr,
1113 			key_usage_str[key_usage], key_index,
1114 			params->seq_len, params->seq);
1115 		return -EINVAL;
1116 	}
1117 
1118 	rc = wmi_add_cipher_key(wil, key_index, mac_addr, params->key_len,
1119 				params->key, key_usage);
1120 	if (!rc)
1121 		wil_set_crypto_rx(key_index, key_usage, cs, params);
1122 
1123 	return rc;
1124 }
1125 
1126 static int wil_cfg80211_del_key(struct wiphy *wiphy,
1127 				struct net_device *ndev,
1128 				u8 key_index, bool pairwise,
1129 				const u8 *mac_addr)
1130 {
1131 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1132 	enum wmi_key_usage key_usage = wil_detect_key_usage(wil, pairwise);
1133 	struct wil_sta_info *cs = wil_find_sta_by_key_usage(wil, key_usage,
1134 							    mac_addr);
1135 
1136 	wil_dbg_misc(wil, "del_key: %pM %s[%d]\n", mac_addr,
1137 		     key_usage_str[key_usage], key_index);
1138 
1139 	if (IS_ERR(cs))
1140 		wil_info(wil, "Not connected, %pM %s[%d]\n",
1141 			 mac_addr, key_usage_str[key_usage], key_index);
1142 
1143 	if (!IS_ERR_OR_NULL(cs))
1144 		wil_del_rx_key(key_index, key_usage, cs);
1145 
1146 	return wmi_del_cipher_key(wil, key_index, mac_addr, key_usage);
1147 }
1148 
1149 /* Need to be present or wiphy_new() will WARN */
1150 static int wil_cfg80211_set_default_key(struct wiphy *wiphy,
1151 					struct net_device *ndev,
1152 					u8 key_index, bool unicast,
1153 					bool multicast)
1154 {
1155 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1156 
1157 	wil_dbg_misc(wil, "set_default_key: entered\n");
1158 	return 0;
1159 }
1160 
1161 static int wil_remain_on_channel(struct wiphy *wiphy,
1162 				 struct wireless_dev *wdev,
1163 				 struct ieee80211_channel *chan,
1164 				 unsigned int duration,
1165 				 u64 *cookie)
1166 {
1167 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1168 	int rc;
1169 
1170 	wil_dbg_misc(wil,
1171 		     "remain_on_channel: center_freq=%d, duration=%d iftype=%d\n",
1172 		     chan->center_freq, duration, wdev->iftype);
1173 
1174 	rc = wil_p2p_listen(wil, wdev, duration, chan, cookie);
1175 	return rc;
1176 }
1177 
1178 static int wil_cancel_remain_on_channel(struct wiphy *wiphy,
1179 					struct wireless_dev *wdev,
1180 					u64 cookie)
1181 {
1182 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1183 
1184 	wil_dbg_misc(wil, "cancel_remain_on_channel\n");
1185 
1186 	return wil_p2p_cancel_listen(wil, cookie);
1187 }
1188 
1189 /**
1190  * find a specific IE in a list of IEs
1191  * return a pointer to the beginning of IE in the list
1192  * or NULL if not found
1193  */
1194 static const u8 *_wil_cfg80211_find_ie(const u8 *ies, u16 ies_len, const u8 *ie,
1195 				       u16 ie_len)
1196 {
1197 	struct ieee80211_vendor_ie *vie;
1198 	u32 oui;
1199 
1200 	/* IE tag at offset 0, length at offset 1 */
1201 	if (ie_len < 2 || 2 + ie[1] > ie_len)
1202 		return NULL;
1203 
1204 	if (ie[0] != WLAN_EID_VENDOR_SPECIFIC)
1205 		return cfg80211_find_ie(ie[0], ies, ies_len);
1206 
1207 	/* make sure there is room for 3 bytes OUI + 1 byte OUI type */
1208 	if (ie[1] < 4)
1209 		return NULL;
1210 	vie = (struct ieee80211_vendor_ie *)ie;
1211 	oui = vie->oui[0] << 16 | vie->oui[1] << 8 | vie->oui[2];
1212 	return cfg80211_find_vendor_ie(oui, vie->oui_type, ies,
1213 				       ies_len);
1214 }
1215 
1216 /**
1217  * merge the IEs in two lists into a single list.
1218  * do not include IEs from the second list which exist in the first list.
1219  * add only vendor specific IEs from second list to keep
1220  * the merged list sorted (since vendor-specific IE has the
1221  * highest tag number)
1222  * caller must free the allocated memory for merged IEs
1223  */
1224 static int _wil_cfg80211_merge_extra_ies(const u8 *ies1, u16 ies1_len,
1225 					 const u8 *ies2, u16 ies2_len,
1226 					 u8 **merged_ies, u16 *merged_len)
1227 {
1228 	u8 *buf, *dpos;
1229 	const u8 *spos;
1230 
1231 	if (ies1_len == 0 && ies2_len == 0) {
1232 		*merged_ies = NULL;
1233 		*merged_len = 0;
1234 		return 0;
1235 	}
1236 
1237 	buf = kmalloc(ies1_len + ies2_len, GFP_KERNEL);
1238 	if (!buf)
1239 		return -ENOMEM;
1240 	memcpy(buf, ies1, ies1_len);
1241 	dpos = buf + ies1_len;
1242 	spos = ies2;
1243 	while (spos + 1 < ies2 + ies2_len) {
1244 		/* IE tag at offset 0, length at offset 1 */
1245 		u16 ielen = 2 + spos[1];
1246 
1247 		if (spos + ielen > ies2 + ies2_len)
1248 			break;
1249 		if (spos[0] == WLAN_EID_VENDOR_SPECIFIC &&
1250 		    !_wil_cfg80211_find_ie(ies1, ies1_len, spos, ielen)) {
1251 			memcpy(dpos, spos, ielen);
1252 			dpos += ielen;
1253 		}
1254 		spos += ielen;
1255 	}
1256 
1257 	*merged_ies = buf;
1258 	*merged_len = dpos - buf;
1259 	return 0;
1260 }
1261 
1262 static void wil_print_bcon_data(struct cfg80211_beacon_data *b)
1263 {
1264 	wil_hex_dump_misc("head     ", DUMP_PREFIX_OFFSET, 16, 1,
1265 			  b->head, b->head_len, true);
1266 	wil_hex_dump_misc("tail     ", DUMP_PREFIX_OFFSET, 16, 1,
1267 			  b->tail, b->tail_len, true);
1268 	wil_hex_dump_misc("BCON IE  ", DUMP_PREFIX_OFFSET, 16, 1,
1269 			  b->beacon_ies, b->beacon_ies_len, true);
1270 	wil_hex_dump_misc("PROBE    ", DUMP_PREFIX_OFFSET, 16, 1,
1271 			  b->probe_resp, b->probe_resp_len, true);
1272 	wil_hex_dump_misc("PROBE IE ", DUMP_PREFIX_OFFSET, 16, 1,
1273 			  b->proberesp_ies, b->proberesp_ies_len, true);
1274 	wil_hex_dump_misc("ASSOC IE ", DUMP_PREFIX_OFFSET, 16, 1,
1275 			  b->assocresp_ies, b->assocresp_ies_len, true);
1276 }
1277 
1278 /* internal functions for device reset and starting AP */
1279 static int _wil_cfg80211_set_ies(struct wiphy *wiphy,
1280 				 struct cfg80211_beacon_data *bcon)
1281 {
1282 	int rc;
1283 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1284 	u16 len = 0, proberesp_len = 0;
1285 	u8 *ies = NULL, *proberesp = NULL;
1286 
1287 	if (bcon->probe_resp) {
1288 		struct ieee80211_mgmt *f =
1289 			(struct ieee80211_mgmt *)bcon->probe_resp;
1290 		size_t hlen = offsetof(struct ieee80211_mgmt,
1291 				       u.probe_resp.variable);
1292 		proberesp = f->u.probe_resp.variable;
1293 		proberesp_len = bcon->probe_resp_len - hlen;
1294 	}
1295 	rc = _wil_cfg80211_merge_extra_ies(proberesp,
1296 					   proberesp_len,
1297 					   bcon->proberesp_ies,
1298 					   bcon->proberesp_ies_len,
1299 					   &ies, &len);
1300 
1301 	if (rc)
1302 		goto out;
1303 
1304 	rc = wmi_set_ie(wil, WMI_FRAME_PROBE_RESP, len, ies);
1305 	if (rc)
1306 		goto out;
1307 
1308 	if (bcon->assocresp_ies)
1309 		rc = wmi_set_ie(wil, WMI_FRAME_ASSOC_RESP,
1310 				bcon->assocresp_ies_len, bcon->assocresp_ies);
1311 	else
1312 		rc = wmi_set_ie(wil, WMI_FRAME_ASSOC_RESP, len, ies);
1313 #if 0 /* to use beacon IE's, remove this #if 0 */
1314 	if (rc)
1315 		goto out;
1316 
1317 	rc = wmi_set_ie(wil, WMI_FRAME_BEACON, bcon->tail_len, bcon->tail);
1318 #endif
1319 out:
1320 	kfree(ies);
1321 	return rc;
1322 }
1323 
1324 static int _wil_cfg80211_start_ap(struct wiphy *wiphy,
1325 				  struct net_device *ndev,
1326 				  const u8 *ssid, size_t ssid_len, u32 privacy,
1327 				  int bi, u8 chan,
1328 				  struct cfg80211_beacon_data *bcon,
1329 				  u8 hidden_ssid, u32 pbss)
1330 {
1331 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1332 	int rc;
1333 	struct wireless_dev *wdev = ndev->ieee80211_ptr;
1334 	u8 wmi_nettype = wil_iftype_nl2wmi(wdev->iftype);
1335 	u8 is_go = (wdev->iftype == NL80211_IFTYPE_P2P_GO);
1336 
1337 	if (pbss)
1338 		wmi_nettype = WMI_NETTYPE_P2P;
1339 
1340 	wil_dbg_misc(wil, "start_ap: is_go=%d\n", is_go);
1341 	if (is_go && !pbss) {
1342 		wil_err(wil, "P2P GO must be in PBSS\n");
1343 		return -ENOTSUPP;
1344 	}
1345 
1346 	wil_set_recovery_state(wil, fw_recovery_idle);
1347 
1348 	mutex_lock(&wil->mutex);
1349 
1350 	__wil_down(wil);
1351 	rc = __wil_up(wil);
1352 	if (rc)
1353 		goto out;
1354 
1355 	rc = wmi_set_ssid(wil, ssid_len, ssid);
1356 	if (rc)
1357 		goto out;
1358 
1359 	rc = _wil_cfg80211_set_ies(wiphy, bcon);
1360 	if (rc)
1361 		goto out;
1362 
1363 	wil->privacy = privacy;
1364 	wil->channel = chan;
1365 	wil->hidden_ssid = hidden_ssid;
1366 	wil->pbss = pbss;
1367 
1368 	netif_carrier_on(ndev);
1369 	wil6210_bus_request(wil, WIL_MAX_BUS_REQUEST_KBPS);
1370 
1371 	rc = wmi_pcp_start(wil, bi, wmi_nettype, chan, hidden_ssid, is_go);
1372 	if (rc)
1373 		goto err_pcp_start;
1374 
1375 	rc = wil_bcast_init(wil);
1376 	if (rc)
1377 		goto err_bcast;
1378 
1379 	goto out; /* success */
1380 
1381 err_bcast:
1382 	wmi_pcp_stop(wil);
1383 err_pcp_start:
1384 	netif_carrier_off(ndev);
1385 	wil6210_bus_request(wil, WIL_DEFAULT_BUS_REQUEST_KBPS);
1386 out:
1387 	mutex_unlock(&wil->mutex);
1388 	return rc;
1389 }
1390 
1391 static int wil_cfg80211_change_beacon(struct wiphy *wiphy,
1392 				      struct net_device *ndev,
1393 				      struct cfg80211_beacon_data *bcon)
1394 {
1395 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1396 	int rc;
1397 	u32 privacy = 0;
1398 
1399 	wil_dbg_misc(wil, "change_beacon\n");
1400 	wil_print_bcon_data(bcon);
1401 
1402 	if (bcon->tail &&
1403 	    cfg80211_find_ie(WLAN_EID_RSN, bcon->tail,
1404 			     bcon->tail_len))
1405 		privacy = 1;
1406 
1407 	/* in case privacy has changed, need to restart the AP */
1408 	if (wil->privacy != privacy) {
1409 		struct wireless_dev *wdev = ndev->ieee80211_ptr;
1410 
1411 		wil_dbg_misc(wil, "privacy changed %d=>%d. Restarting AP\n",
1412 			     wil->privacy, privacy);
1413 
1414 		rc = _wil_cfg80211_start_ap(wiphy, ndev, wdev->ssid,
1415 					    wdev->ssid_len, privacy,
1416 					    wdev->beacon_interval,
1417 					    wil->channel, bcon,
1418 					    wil->hidden_ssid,
1419 					    wil->pbss);
1420 	} else {
1421 		rc = _wil_cfg80211_set_ies(wiphy, bcon);
1422 	}
1423 
1424 	return rc;
1425 }
1426 
1427 static int wil_cfg80211_start_ap(struct wiphy *wiphy,
1428 				 struct net_device *ndev,
1429 				 struct cfg80211_ap_settings *info)
1430 {
1431 	int rc;
1432 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1433 	struct ieee80211_channel *channel = info->chandef.chan;
1434 	struct cfg80211_beacon_data *bcon = &info->beacon;
1435 	struct cfg80211_crypto_settings *crypto = &info->crypto;
1436 	u8 hidden_ssid;
1437 
1438 	wil_dbg_misc(wil, "start_ap\n");
1439 
1440 	if (!channel) {
1441 		wil_err(wil, "AP: No channel???\n");
1442 		return -EINVAL;
1443 	}
1444 
1445 	switch (info->hidden_ssid) {
1446 	case NL80211_HIDDEN_SSID_NOT_IN_USE:
1447 		hidden_ssid = WMI_HIDDEN_SSID_DISABLED;
1448 		break;
1449 
1450 	case NL80211_HIDDEN_SSID_ZERO_LEN:
1451 		hidden_ssid = WMI_HIDDEN_SSID_SEND_EMPTY;
1452 		break;
1453 
1454 	case NL80211_HIDDEN_SSID_ZERO_CONTENTS:
1455 		hidden_ssid = WMI_HIDDEN_SSID_CLEAR;
1456 		break;
1457 
1458 	default:
1459 		wil_err(wil, "AP: Invalid hidden SSID %d\n", info->hidden_ssid);
1460 		return -EOPNOTSUPP;
1461 	}
1462 	wil_dbg_misc(wil, "AP on Channel %d %d MHz, %s\n", channel->hw_value,
1463 		     channel->center_freq, info->privacy ? "secure" : "open");
1464 	wil_dbg_misc(wil, "Privacy: %d auth_type %d\n",
1465 		     info->privacy, info->auth_type);
1466 	wil_dbg_misc(wil, "Hidden SSID mode: %d\n",
1467 		     info->hidden_ssid);
1468 	wil_dbg_misc(wil, "BI %d DTIM %d\n", info->beacon_interval,
1469 		     info->dtim_period);
1470 	wil_dbg_misc(wil, "PBSS %d\n", info->pbss);
1471 	wil_hex_dump_misc("SSID ", DUMP_PREFIX_OFFSET, 16, 1,
1472 			  info->ssid, info->ssid_len, true);
1473 	wil_print_bcon_data(bcon);
1474 	wil_print_crypto(wil, crypto);
1475 
1476 	rc = _wil_cfg80211_start_ap(wiphy, ndev,
1477 				    info->ssid, info->ssid_len, info->privacy,
1478 				    info->beacon_interval, channel->hw_value,
1479 				    bcon, hidden_ssid, info->pbss);
1480 
1481 	return rc;
1482 }
1483 
1484 static int wil_cfg80211_stop_ap(struct wiphy *wiphy,
1485 				struct net_device *ndev)
1486 {
1487 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1488 
1489 	wil_dbg_misc(wil, "stop_ap\n");
1490 
1491 	netif_carrier_off(ndev);
1492 	wil6210_bus_request(wil, WIL_DEFAULT_BUS_REQUEST_KBPS);
1493 	wil_set_recovery_state(wil, fw_recovery_idle);
1494 
1495 	set_bit(wil_status_resetting, wil->status);
1496 
1497 	mutex_lock(&wil->mutex);
1498 
1499 	wmi_pcp_stop(wil);
1500 
1501 	__wil_down(wil);
1502 
1503 	mutex_unlock(&wil->mutex);
1504 
1505 	return 0;
1506 }
1507 
1508 static int wil_cfg80211_add_station(struct wiphy *wiphy,
1509 				    struct net_device *dev,
1510 				    const u8 *mac,
1511 				    struct station_parameters *params)
1512 {
1513 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1514 
1515 	wil_dbg_misc(wil, "add station %pM aid %d\n", mac, params->aid);
1516 
1517 	if (!disable_ap_sme) {
1518 		wil_err(wil, "not supported with AP SME enabled\n");
1519 		return -EOPNOTSUPP;
1520 	}
1521 
1522 	if (params->aid > WIL_MAX_DMG_AID) {
1523 		wil_err(wil, "invalid aid\n");
1524 		return -EINVAL;
1525 	}
1526 
1527 	return wmi_new_sta(wil, mac, params->aid);
1528 }
1529 
1530 static int wil_cfg80211_del_station(struct wiphy *wiphy,
1531 				    struct net_device *dev,
1532 				    struct station_del_parameters *params)
1533 {
1534 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1535 
1536 	wil_dbg_misc(wil, "del_station: %pM, reason=%d\n", params->mac,
1537 		     params->reason_code);
1538 
1539 	mutex_lock(&wil->mutex);
1540 	wil6210_disconnect(wil, params->mac, params->reason_code, false);
1541 	mutex_unlock(&wil->mutex);
1542 
1543 	return 0;
1544 }
1545 
1546 static int wil_cfg80211_change_station(struct wiphy *wiphy,
1547 				       struct net_device *dev,
1548 				       const u8 *mac,
1549 				       struct station_parameters *params)
1550 {
1551 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1552 	int authorize;
1553 	int cid, i;
1554 	struct vring_tx_data *txdata = NULL;
1555 
1556 	wil_dbg_misc(wil, "change station %pM mask 0x%x set 0x%x\n", mac,
1557 		     params->sta_flags_mask, params->sta_flags_set);
1558 
1559 	if (!disable_ap_sme) {
1560 		wil_dbg_misc(wil, "not supported with AP SME enabled\n");
1561 		return -EOPNOTSUPP;
1562 	}
1563 
1564 	if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
1565 		return 0;
1566 
1567 	cid = wil_find_cid(wil, mac);
1568 	if (cid < 0) {
1569 		wil_err(wil, "station not found\n");
1570 		return -ENOLINK;
1571 	}
1572 
1573 	for (i = 0; i < ARRAY_SIZE(wil->vring2cid_tid); i++)
1574 		if (wil->vring2cid_tid[i][0] == cid) {
1575 			txdata = &wil->vring_tx_data[i];
1576 			break;
1577 		}
1578 
1579 	if (!txdata) {
1580 		wil_err(wil, "vring data not found\n");
1581 		return -ENOLINK;
1582 	}
1583 
1584 	authorize = params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED);
1585 	txdata->dot1x_open = authorize ? 1 : 0;
1586 	wil_dbg_misc(wil, "cid %d vring %d authorize %d\n", cid, i,
1587 		     txdata->dot1x_open);
1588 
1589 	return 0;
1590 }
1591 
1592 /* probe_client handling */
1593 static void wil_probe_client_handle(struct wil6210_priv *wil,
1594 				    struct wil_probe_client_req *req)
1595 {
1596 	struct net_device *ndev = wil_to_ndev(wil);
1597 	struct wil_sta_info *sta = &wil->sta[req->cid];
1598 	/* assume STA is alive if it is still connected,
1599 	 * else FW will disconnect it
1600 	 */
1601 	bool alive = (sta->status == wil_sta_connected);
1602 
1603 	cfg80211_probe_status(ndev, sta->addr, req->cookie, alive, GFP_KERNEL);
1604 }
1605 
1606 static struct list_head *next_probe_client(struct wil6210_priv *wil)
1607 {
1608 	struct list_head *ret = NULL;
1609 
1610 	mutex_lock(&wil->probe_client_mutex);
1611 
1612 	if (!list_empty(&wil->probe_client_pending)) {
1613 		ret = wil->probe_client_pending.next;
1614 		list_del(ret);
1615 	}
1616 
1617 	mutex_unlock(&wil->probe_client_mutex);
1618 
1619 	return ret;
1620 }
1621 
1622 void wil_probe_client_worker(struct work_struct *work)
1623 {
1624 	struct wil6210_priv *wil = container_of(work, struct wil6210_priv,
1625 						probe_client_worker);
1626 	struct wil_probe_client_req *req;
1627 	struct list_head *lh;
1628 
1629 	while ((lh = next_probe_client(wil)) != NULL) {
1630 		req = list_entry(lh, struct wil_probe_client_req, list);
1631 
1632 		wil_probe_client_handle(wil, req);
1633 		kfree(req);
1634 	}
1635 }
1636 
1637 void wil_probe_client_flush(struct wil6210_priv *wil)
1638 {
1639 	struct wil_probe_client_req *req, *t;
1640 
1641 	wil_dbg_misc(wil, "probe_client_flush\n");
1642 
1643 	mutex_lock(&wil->probe_client_mutex);
1644 
1645 	list_for_each_entry_safe(req, t, &wil->probe_client_pending, list) {
1646 		list_del(&req->list);
1647 		kfree(req);
1648 	}
1649 
1650 	mutex_unlock(&wil->probe_client_mutex);
1651 }
1652 
1653 static int wil_cfg80211_probe_client(struct wiphy *wiphy,
1654 				     struct net_device *dev,
1655 				     const u8 *peer, u64 *cookie)
1656 {
1657 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1658 	struct wil_probe_client_req *req;
1659 	int cid = wil_find_cid(wil, peer);
1660 
1661 	wil_dbg_misc(wil, "probe_client: %pM => CID %d\n", peer, cid);
1662 
1663 	if (cid < 0)
1664 		return -ENOLINK;
1665 
1666 	req = kzalloc(sizeof(*req), GFP_KERNEL);
1667 	if (!req)
1668 		return -ENOMEM;
1669 
1670 	req->cid = cid;
1671 	req->cookie = cid;
1672 
1673 	mutex_lock(&wil->probe_client_mutex);
1674 	list_add_tail(&req->list, &wil->probe_client_pending);
1675 	mutex_unlock(&wil->probe_client_mutex);
1676 
1677 	*cookie = req->cookie;
1678 	queue_work(wil->wq_service, &wil->probe_client_worker);
1679 	return 0;
1680 }
1681 
1682 static int wil_cfg80211_change_bss(struct wiphy *wiphy,
1683 				   struct net_device *dev,
1684 				   struct bss_parameters *params)
1685 {
1686 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1687 
1688 	if (params->ap_isolate >= 0) {
1689 		wil_dbg_misc(wil, "change_bss: ap_isolate %d => %d\n",
1690 			     wil->ap_isolate, params->ap_isolate);
1691 		wil->ap_isolate = params->ap_isolate;
1692 	}
1693 
1694 	return 0;
1695 }
1696 
1697 static int wil_cfg80211_set_power_mgmt(struct wiphy *wiphy,
1698 				       struct net_device *dev,
1699 				       bool enabled, int timeout)
1700 {
1701 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1702 	enum wmi_ps_profile_type ps_profile;
1703 
1704 	wil_dbg_misc(wil, "enabled=%d, timeout=%d\n",
1705 		     enabled, timeout);
1706 
1707 	if (enabled)
1708 		ps_profile = WMI_PS_PROFILE_TYPE_DEFAULT;
1709 	else
1710 		ps_profile = WMI_PS_PROFILE_TYPE_PS_DISABLED;
1711 
1712 	return wil_ps_update(wil, ps_profile);
1713 }
1714 
1715 static int wil_cfg80211_suspend(struct wiphy *wiphy,
1716 				struct cfg80211_wowlan *wow)
1717 {
1718 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1719 	int rc;
1720 
1721 	/* Setting the wakeup trigger based on wow is TBD */
1722 
1723 	if (test_bit(wil_status_suspended, wil->status)) {
1724 		wil_dbg_pm(wil, "trying to suspend while suspended\n");
1725 		return 0;
1726 	}
1727 
1728 	rc = wil_can_suspend(wil, false);
1729 	if (rc)
1730 		goto out;
1731 
1732 	wil_dbg_pm(wil, "suspending\n");
1733 
1734 	mutex_lock(&wil->mutex);
1735 	mutex_lock(&wil->p2p_wdev_mutex);
1736 	wil_p2p_stop_radio_operations(wil);
1737 	wil_abort_scan(wil, true);
1738 	mutex_unlock(&wil->p2p_wdev_mutex);
1739 	mutex_unlock(&wil->mutex);
1740 
1741 out:
1742 	return rc;
1743 }
1744 
1745 static int wil_cfg80211_resume(struct wiphy *wiphy)
1746 {
1747 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1748 
1749 	wil_dbg_pm(wil, "resuming\n");
1750 
1751 	return 0;
1752 }
1753 
1754 static int
1755 wil_cfg80211_sched_scan_start(struct wiphy *wiphy,
1756 			      struct net_device *dev,
1757 			      struct cfg80211_sched_scan_request *request)
1758 {
1759 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1760 	int i, rc;
1761 
1762 	wil_dbg_misc(wil,
1763 		     "sched scan start: n_ssids %d, ie_len %zu, flags 0x%x\n",
1764 		     request->n_ssids, request->ie_len, request->flags);
1765 	for (i = 0; i < request->n_ssids; i++) {
1766 		wil_dbg_misc(wil, "SSID[%d]:", i);
1767 		wil_hex_dump_misc("SSID ", DUMP_PREFIX_OFFSET, 16, 1,
1768 				  request->ssids[i].ssid,
1769 				  request->ssids[i].ssid_len, true);
1770 	}
1771 	wil_dbg_misc(wil, "channels:");
1772 	for (i = 0; i < request->n_channels; i++)
1773 		wil_dbg_misc(wil, " %d%s", request->channels[i]->hw_value,
1774 			     i == request->n_channels - 1 ? "\n" : "");
1775 	wil_dbg_misc(wil, "n_match_sets %d, min_rssi_thold %d, delay %d\n",
1776 		     request->n_match_sets, request->min_rssi_thold,
1777 		     request->delay);
1778 	for (i = 0; i < request->n_match_sets; i++) {
1779 		struct cfg80211_match_set *ms = &request->match_sets[i];
1780 
1781 		wil_dbg_misc(wil, "MATCHSET[%d]: rssi_thold %d\n",
1782 			     i, ms->rssi_thold);
1783 		wil_hex_dump_misc("SSID ", DUMP_PREFIX_OFFSET, 16, 1,
1784 				  ms->ssid.ssid,
1785 				  ms->ssid.ssid_len, true);
1786 	}
1787 	wil_dbg_misc(wil, "n_scan_plans %d\n", request->n_scan_plans);
1788 	for (i = 0; i < request->n_scan_plans; i++) {
1789 		struct cfg80211_sched_scan_plan *sp = &request->scan_plans[i];
1790 
1791 		wil_dbg_misc(wil, "SCAN PLAN[%d]: interval %d iterations %d\n",
1792 			     i, sp->interval, sp->iterations);
1793 	}
1794 
1795 	rc = wmi_set_ie(wil, WMI_FRAME_PROBE_REQ, request->ie_len, request->ie);
1796 	if (rc)
1797 		return rc;
1798 	return wmi_start_sched_scan(wil, request);
1799 }
1800 
1801 static int
1802 wil_cfg80211_sched_scan_stop(struct wiphy *wiphy, struct net_device *dev,
1803 			     u64 reqid)
1804 {
1805 	struct wil6210_priv *wil = wiphy_to_wil(wiphy);
1806 	int rc;
1807 
1808 	rc = wmi_stop_sched_scan(wil);
1809 	/* device would return error if it thinks PNO is already stopped.
1810 	 * ignore the return code so user space and driver gets back in-sync
1811 	 */
1812 	wil_dbg_misc(wil, "sched scan stopped (%d)\n", rc);
1813 
1814 	return 0;
1815 }
1816 
1817 static const struct cfg80211_ops wil_cfg80211_ops = {
1818 	.add_virtual_intf = wil_cfg80211_add_iface,
1819 	.del_virtual_intf = wil_cfg80211_del_iface,
1820 	.scan = wil_cfg80211_scan,
1821 	.abort_scan = wil_cfg80211_abort_scan,
1822 	.connect = wil_cfg80211_connect,
1823 	.disconnect = wil_cfg80211_disconnect,
1824 	.set_wiphy_params = wil_cfg80211_set_wiphy_params,
1825 	.change_virtual_intf = wil_cfg80211_change_iface,
1826 	.get_station = wil_cfg80211_get_station,
1827 	.dump_station = wil_cfg80211_dump_station,
1828 	.remain_on_channel = wil_remain_on_channel,
1829 	.cancel_remain_on_channel = wil_cancel_remain_on_channel,
1830 	.mgmt_tx = wil_cfg80211_mgmt_tx,
1831 	.set_monitor_channel = wil_cfg80211_set_channel,
1832 	.add_key = wil_cfg80211_add_key,
1833 	.del_key = wil_cfg80211_del_key,
1834 	.set_default_key = wil_cfg80211_set_default_key,
1835 	/* AP mode */
1836 	.change_beacon = wil_cfg80211_change_beacon,
1837 	.start_ap = wil_cfg80211_start_ap,
1838 	.stop_ap = wil_cfg80211_stop_ap,
1839 	.add_station = wil_cfg80211_add_station,
1840 	.del_station = wil_cfg80211_del_station,
1841 	.change_station = wil_cfg80211_change_station,
1842 	.probe_client = wil_cfg80211_probe_client,
1843 	.change_bss = wil_cfg80211_change_bss,
1844 	/* P2P device */
1845 	.start_p2p_device = wil_cfg80211_start_p2p_device,
1846 	.stop_p2p_device = wil_cfg80211_stop_p2p_device,
1847 	.set_power_mgmt = wil_cfg80211_set_power_mgmt,
1848 	.suspend = wil_cfg80211_suspend,
1849 	.resume = wil_cfg80211_resume,
1850 	.sched_scan_start = wil_cfg80211_sched_scan_start,
1851 	.sched_scan_stop = wil_cfg80211_sched_scan_stop,
1852 };
1853 
1854 static void wil_wiphy_init(struct wiphy *wiphy)
1855 {
1856 	wiphy->max_scan_ssids = 1;
1857 	wiphy->max_scan_ie_len = WMI_MAX_IE_LEN;
1858 	wiphy->max_remain_on_channel_duration = WIL_MAX_ROC_DURATION_MS;
1859 	wiphy->max_num_pmkids = 0 /* TODO: */;
1860 	wiphy->interface_modes = BIT(NL80211_IFTYPE_STATION) |
1861 				 BIT(NL80211_IFTYPE_AP) |
1862 				 BIT(NL80211_IFTYPE_P2P_CLIENT) |
1863 				 BIT(NL80211_IFTYPE_P2P_GO) |
1864 				 BIT(NL80211_IFTYPE_P2P_DEVICE) |
1865 				 BIT(NL80211_IFTYPE_MONITOR);
1866 	wiphy->flags |= WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL |
1867 			WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD |
1868 			WIPHY_FLAG_PS_ON_BY_DEFAULT;
1869 	if (!disable_ap_sme)
1870 		wiphy->flags |= WIPHY_FLAG_HAVE_AP_SME;
1871 	dev_dbg(wiphy_dev(wiphy), "%s : flags = 0x%08x\n",
1872 		__func__, wiphy->flags);
1873 	wiphy->probe_resp_offload =
1874 		NL80211_PROBE_RESP_OFFLOAD_SUPPORT_WPS |
1875 		NL80211_PROBE_RESP_OFFLOAD_SUPPORT_WPS2 |
1876 		NL80211_PROBE_RESP_OFFLOAD_SUPPORT_P2P;
1877 
1878 	wiphy->bands[NL80211_BAND_60GHZ] = &wil_band_60ghz;
1879 
1880 	/* may change after reading FW capabilities */
1881 	wiphy->signal_type = CFG80211_SIGNAL_TYPE_UNSPEC;
1882 
1883 	wiphy->cipher_suites = wil_cipher_suites;
1884 	wiphy->n_cipher_suites = ARRAY_SIZE(wil_cipher_suites);
1885 	wiphy->mgmt_stypes = wil_mgmt_stypes;
1886 	wiphy->features |= NL80211_FEATURE_SK_TX_STATUS;
1887 
1888 	wiphy->n_vendor_commands = ARRAY_SIZE(wil_nl80211_vendor_commands);
1889 	wiphy->vendor_commands = wil_nl80211_vendor_commands;
1890 
1891 #ifdef CONFIG_PM
1892 	wiphy->wowlan = &wil_wowlan_support;
1893 #endif
1894 }
1895 
1896 struct wireless_dev *wil_cfg80211_init(struct device *dev)
1897 {
1898 	int rc = 0;
1899 	struct wireless_dev *wdev;
1900 
1901 	dev_dbg(dev, "%s()\n", __func__);
1902 
1903 	wdev = kzalloc(sizeof(*wdev), GFP_KERNEL);
1904 	if (!wdev)
1905 		return ERR_PTR(-ENOMEM);
1906 
1907 	wdev->wiphy = wiphy_new(&wil_cfg80211_ops,
1908 				sizeof(struct wil6210_priv));
1909 	if (!wdev->wiphy) {
1910 		rc = -ENOMEM;
1911 		goto out;
1912 	}
1913 
1914 	set_wiphy_dev(wdev->wiphy, dev);
1915 	wil_wiphy_init(wdev->wiphy);
1916 
1917 	return wdev;
1918 
1919 out:
1920 	kfree(wdev);
1921 
1922 	return ERR_PTR(rc);
1923 }
1924 
1925 void wil_wdev_free(struct wil6210_priv *wil)
1926 {
1927 	struct wireless_dev *wdev = wil_to_wdev(wil);
1928 
1929 	dev_dbg(wil_to_dev(wil), "%s()\n", __func__);
1930 
1931 	if (!wdev)
1932 		return;
1933 
1934 	wiphy_free(wdev->wiphy);
1935 	kfree(wdev);
1936 }
1937 
1938 void wil_p2p_wdev_free(struct wil6210_priv *wil)
1939 {
1940 	struct wireless_dev *p2p_wdev;
1941 
1942 	mutex_lock(&wil->p2p_wdev_mutex);
1943 	p2p_wdev = wil->p2p_wdev;
1944 	wil->p2p_wdev = NULL;
1945 	wil->radio_wdev = wil_to_wdev(wil);
1946 	mutex_unlock(&wil->p2p_wdev_mutex);
1947 	if (p2p_wdev) {
1948 		cfg80211_unregister_wdev(p2p_wdev);
1949 		kfree(p2p_wdev);
1950 	}
1951 }
1952 
1953 static int wil_rf_sector_status_to_rc(u8 status)
1954 {
1955 	switch (status) {
1956 	case WMI_RF_SECTOR_STATUS_SUCCESS:
1957 		return 0;
1958 	case WMI_RF_SECTOR_STATUS_BAD_PARAMETERS_ERROR:
1959 		return -EINVAL;
1960 	case WMI_RF_SECTOR_STATUS_BUSY_ERROR:
1961 		return -EAGAIN;
1962 	case WMI_RF_SECTOR_STATUS_NOT_SUPPORTED_ERROR:
1963 		return -EOPNOTSUPP;
1964 	default:
1965 		return -EINVAL;
1966 	}
1967 }
1968 
1969 static int wil_rf_sector_get_cfg(struct wiphy *wiphy,
1970 				 struct wireless_dev *wdev,
1971 				 const void *data, int data_len)
1972 {
1973 	struct wil6210_priv *wil = wdev_to_wil(wdev);
1974 	int rc;
1975 	struct nlattr *tb[QCA_ATTR_DMG_RF_SECTOR_MAX + 1];
1976 	u16 sector_index;
1977 	u8 sector_type;
1978 	u32 rf_modules_vec;
1979 	struct wmi_get_rf_sector_params_cmd cmd;
1980 	struct {
1981 		struct wmi_cmd_hdr wmi;
1982 		struct wmi_get_rf_sector_params_done_event evt;
1983 	} __packed reply;
1984 	struct sk_buff *msg;
1985 	struct nlattr *nl_cfgs, *nl_cfg;
1986 	u32 i;
1987 	struct wmi_rf_sector_info *si;
1988 
1989 	if (!test_bit(WMI_FW_CAPABILITY_RF_SECTORS, wil->fw_capabilities))
1990 		return -EOPNOTSUPP;
1991 
1992 	rc = nla_parse(tb, QCA_ATTR_DMG_RF_SECTOR_MAX, data, data_len,
1993 		       wil_rf_sector_policy, NULL);
1994 	if (rc) {
1995 		wil_err(wil, "Invalid rf sector ATTR\n");
1996 		return rc;
1997 	}
1998 
1999 	if (!tb[QCA_ATTR_DMG_RF_SECTOR_INDEX] ||
2000 	    !tb[QCA_ATTR_DMG_RF_SECTOR_TYPE] ||
2001 	    !tb[QCA_ATTR_DMG_RF_MODULE_MASK]) {
2002 		wil_err(wil, "Invalid rf sector spec\n");
2003 		return -EINVAL;
2004 	}
2005 
2006 	sector_index = nla_get_u16(
2007 		tb[QCA_ATTR_DMG_RF_SECTOR_INDEX]);
2008 	if (sector_index >= WIL_MAX_RF_SECTORS) {
2009 		wil_err(wil, "Invalid sector index %d\n", sector_index);
2010 		return -EINVAL;
2011 	}
2012 
2013 	sector_type = nla_get_u8(tb[QCA_ATTR_DMG_RF_SECTOR_TYPE]);
2014 	if (sector_type >= QCA_ATTR_DMG_RF_SECTOR_TYPE_MAX) {
2015 		wil_err(wil, "Invalid sector type %d\n", sector_type);
2016 		return -EINVAL;
2017 	}
2018 
2019 	rf_modules_vec = nla_get_u32(
2020 		tb[QCA_ATTR_DMG_RF_MODULE_MASK]);
2021 	if (rf_modules_vec >= BIT(WMI_MAX_RF_MODULES_NUM)) {
2022 		wil_err(wil, "Invalid rf module mask 0x%x\n", rf_modules_vec);
2023 		return -EINVAL;
2024 	}
2025 
2026 	cmd.sector_idx = cpu_to_le16(sector_index);
2027 	cmd.sector_type = sector_type;
2028 	cmd.rf_modules_vec = rf_modules_vec & 0xFF;
2029 	memset(&reply, 0, sizeof(reply));
2030 	rc = wmi_call(wil, WMI_GET_RF_SECTOR_PARAMS_CMDID, &cmd, sizeof(cmd),
2031 		      WMI_GET_RF_SECTOR_PARAMS_DONE_EVENTID,
2032 		      &reply, sizeof(reply),
2033 		      500);
2034 	if (rc)
2035 		return rc;
2036 	if (reply.evt.status) {
2037 		wil_err(wil, "get rf sector cfg failed with status %d\n",
2038 			reply.evt.status);
2039 		return wil_rf_sector_status_to_rc(reply.evt.status);
2040 	}
2041 
2042 	msg = cfg80211_vendor_cmd_alloc_reply_skb(
2043 		wiphy, 64 * WMI_MAX_RF_MODULES_NUM);
2044 	if (!msg)
2045 		return -ENOMEM;
2046 
2047 	if (nla_put_u64_64bit(msg, QCA_ATTR_TSF,
2048 			      le64_to_cpu(reply.evt.tsf),
2049 			      QCA_ATTR_PAD))
2050 		goto nla_put_failure;
2051 
2052 	nl_cfgs = nla_nest_start(msg, QCA_ATTR_DMG_RF_SECTOR_CFG);
2053 	if (!nl_cfgs)
2054 		goto nla_put_failure;
2055 	for (i = 0; i < WMI_MAX_RF_MODULES_NUM; i++) {
2056 		if (!(rf_modules_vec & BIT(i)))
2057 			continue;
2058 		nl_cfg = nla_nest_start(msg, i);
2059 		if (!nl_cfg)
2060 			goto nla_put_failure;
2061 		si = &reply.evt.sectors_info[i];
2062 		if (nla_put_u8(msg, QCA_ATTR_DMG_RF_SECTOR_CFG_MODULE_INDEX,
2063 			       i) ||
2064 		    nla_put_u32(msg, QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE0,
2065 				le32_to_cpu(si->etype0)) ||
2066 		    nla_put_u32(msg, QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE1,
2067 				le32_to_cpu(si->etype1)) ||
2068 		    nla_put_u32(msg, QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE2,
2069 				le32_to_cpu(si->etype2)) ||
2070 		    nla_put_u32(msg, QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_HI,
2071 				le32_to_cpu(si->psh_hi)) ||
2072 		    nla_put_u32(msg, QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_LO,
2073 				le32_to_cpu(si->psh_lo)) ||
2074 		    nla_put_u32(msg, QCA_ATTR_DMG_RF_SECTOR_CFG_DTYPE_X16,
2075 				le32_to_cpu(si->dtype_swch_off)))
2076 			goto nla_put_failure;
2077 		nla_nest_end(msg, nl_cfg);
2078 	}
2079 
2080 	nla_nest_end(msg, nl_cfgs);
2081 	rc = cfg80211_vendor_cmd_reply(msg);
2082 	return rc;
2083 nla_put_failure:
2084 	kfree_skb(msg);
2085 	return -ENOBUFS;
2086 }
2087 
2088 static int wil_rf_sector_set_cfg(struct wiphy *wiphy,
2089 				 struct wireless_dev *wdev,
2090 				 const void *data, int data_len)
2091 {
2092 	struct wil6210_priv *wil = wdev_to_wil(wdev);
2093 	int rc, tmp;
2094 	struct nlattr *tb[QCA_ATTR_DMG_RF_SECTOR_MAX + 1];
2095 	struct nlattr *tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_MAX + 1];
2096 	u16 sector_index, rf_module_index;
2097 	u8 sector_type;
2098 	u32 rf_modules_vec = 0;
2099 	struct wmi_set_rf_sector_params_cmd cmd;
2100 	struct {
2101 		struct wmi_cmd_hdr wmi;
2102 		struct wmi_set_rf_sector_params_done_event evt;
2103 	} __packed reply;
2104 	struct nlattr *nl_cfg;
2105 	struct wmi_rf_sector_info *si;
2106 
2107 	if (!test_bit(WMI_FW_CAPABILITY_RF_SECTORS, wil->fw_capabilities))
2108 		return -EOPNOTSUPP;
2109 
2110 	rc = nla_parse(tb, QCA_ATTR_DMG_RF_SECTOR_MAX, data, data_len,
2111 		       wil_rf_sector_policy, NULL);
2112 	if (rc) {
2113 		wil_err(wil, "Invalid rf sector ATTR\n");
2114 		return rc;
2115 	}
2116 
2117 	if (!tb[QCA_ATTR_DMG_RF_SECTOR_INDEX] ||
2118 	    !tb[QCA_ATTR_DMG_RF_SECTOR_TYPE] ||
2119 	    !tb[QCA_ATTR_DMG_RF_SECTOR_CFG]) {
2120 		wil_err(wil, "Invalid rf sector spec\n");
2121 		return -EINVAL;
2122 	}
2123 
2124 	sector_index = nla_get_u16(
2125 		tb[QCA_ATTR_DMG_RF_SECTOR_INDEX]);
2126 	if (sector_index >= WIL_MAX_RF_SECTORS) {
2127 		wil_err(wil, "Invalid sector index %d\n", sector_index);
2128 		return -EINVAL;
2129 	}
2130 
2131 	sector_type = nla_get_u8(tb[QCA_ATTR_DMG_RF_SECTOR_TYPE]);
2132 	if (sector_type >= QCA_ATTR_DMG_RF_SECTOR_TYPE_MAX) {
2133 		wil_err(wil, "Invalid sector type %d\n", sector_type);
2134 		return -EINVAL;
2135 	}
2136 
2137 	memset(&cmd, 0, sizeof(cmd));
2138 
2139 	cmd.sector_idx = cpu_to_le16(sector_index);
2140 	cmd.sector_type = sector_type;
2141 	nla_for_each_nested(nl_cfg, tb[QCA_ATTR_DMG_RF_SECTOR_CFG],
2142 			    tmp) {
2143 		rc = nla_parse_nested(tb2, QCA_ATTR_DMG_RF_SECTOR_CFG_MAX,
2144 				      nl_cfg, wil_rf_sector_cfg_policy,
2145 				      NULL);
2146 		if (rc) {
2147 			wil_err(wil, "invalid sector cfg\n");
2148 			return -EINVAL;
2149 		}
2150 
2151 		if (!tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_MODULE_INDEX] ||
2152 		    !tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE0] ||
2153 		    !tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE1] ||
2154 		    !tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE2] ||
2155 		    !tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_HI] ||
2156 		    !tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_LO] ||
2157 		    !tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_DTYPE_X16]) {
2158 			wil_err(wil, "missing cfg params\n");
2159 			return -EINVAL;
2160 		}
2161 
2162 		rf_module_index = nla_get_u8(
2163 			tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_MODULE_INDEX]);
2164 		if (rf_module_index >= WMI_MAX_RF_MODULES_NUM) {
2165 			wil_err(wil, "invalid RF module index %d\n",
2166 				rf_module_index);
2167 			return -EINVAL;
2168 		}
2169 		rf_modules_vec |= BIT(rf_module_index);
2170 		si = &cmd.sectors_info[rf_module_index];
2171 		si->etype0 = cpu_to_le32(nla_get_u32(
2172 			tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE0]));
2173 		si->etype1 = cpu_to_le32(nla_get_u32(
2174 			tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE1]));
2175 		si->etype2 = cpu_to_le32(nla_get_u32(
2176 			tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_ETYPE2]));
2177 		si->psh_hi = cpu_to_le32(nla_get_u32(
2178 			tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_HI]));
2179 		si->psh_lo = cpu_to_le32(nla_get_u32(
2180 			tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_PSH_LO]));
2181 		si->dtype_swch_off = cpu_to_le32(nla_get_u32(
2182 			tb2[QCA_ATTR_DMG_RF_SECTOR_CFG_DTYPE_X16]));
2183 	}
2184 
2185 	cmd.rf_modules_vec = rf_modules_vec & 0xFF;
2186 	memset(&reply, 0, sizeof(reply));
2187 	rc = wmi_call(wil, WMI_SET_RF_SECTOR_PARAMS_CMDID, &cmd, sizeof(cmd),
2188 		      WMI_SET_RF_SECTOR_PARAMS_DONE_EVENTID,
2189 		      &reply, sizeof(reply),
2190 		      500);
2191 	if (rc)
2192 		return rc;
2193 	return wil_rf_sector_status_to_rc(reply.evt.status);
2194 }
2195 
2196 static int wil_rf_sector_get_selected(struct wiphy *wiphy,
2197 				      struct wireless_dev *wdev,
2198 				      const void *data, int data_len)
2199 {
2200 	struct wil6210_priv *wil = wdev_to_wil(wdev);
2201 	int rc;
2202 	struct nlattr *tb[QCA_ATTR_DMG_RF_SECTOR_MAX + 1];
2203 	u8 sector_type, mac_addr[ETH_ALEN];
2204 	int cid = 0;
2205 	struct wmi_get_selected_rf_sector_index_cmd cmd;
2206 	struct {
2207 		struct wmi_cmd_hdr wmi;
2208 		struct wmi_get_selected_rf_sector_index_done_event evt;
2209 	} __packed reply;
2210 	struct sk_buff *msg;
2211 
2212 	if (!test_bit(WMI_FW_CAPABILITY_RF_SECTORS, wil->fw_capabilities))
2213 		return -EOPNOTSUPP;
2214 
2215 	rc = nla_parse(tb, QCA_ATTR_DMG_RF_SECTOR_MAX, data, data_len,
2216 		       wil_rf_sector_policy, NULL);
2217 	if (rc) {
2218 		wil_err(wil, "Invalid rf sector ATTR\n");
2219 		return rc;
2220 	}
2221 
2222 	if (!tb[QCA_ATTR_DMG_RF_SECTOR_TYPE]) {
2223 		wil_err(wil, "Invalid rf sector spec\n");
2224 		return -EINVAL;
2225 	}
2226 	sector_type = nla_get_u8(tb[QCA_ATTR_DMG_RF_SECTOR_TYPE]);
2227 	if (sector_type >= QCA_ATTR_DMG_RF_SECTOR_TYPE_MAX) {
2228 		wil_err(wil, "Invalid sector type %d\n", sector_type);
2229 		return -EINVAL;
2230 	}
2231 
2232 	if (tb[QCA_ATTR_MAC_ADDR]) {
2233 		ether_addr_copy(mac_addr, nla_data(tb[QCA_ATTR_MAC_ADDR]));
2234 		cid = wil_find_cid(wil, mac_addr);
2235 		if (cid < 0) {
2236 			wil_err(wil, "invalid MAC address %pM\n", mac_addr);
2237 			return -ENOENT;
2238 		}
2239 	} else {
2240 		if (test_bit(wil_status_fwconnected, wil->status)) {
2241 			wil_err(wil, "must specify MAC address when connected\n");
2242 			return -EINVAL;
2243 		}
2244 	}
2245 
2246 	memset(&cmd, 0, sizeof(cmd));
2247 	cmd.cid = (u8)cid;
2248 	cmd.sector_type = sector_type;
2249 	memset(&reply, 0, sizeof(reply));
2250 	rc = wmi_call(wil, WMI_GET_SELECTED_RF_SECTOR_INDEX_CMDID,
2251 		      &cmd, sizeof(cmd),
2252 		      WMI_GET_SELECTED_RF_SECTOR_INDEX_DONE_EVENTID,
2253 		      &reply, sizeof(reply),
2254 		      500);
2255 	if (rc)
2256 		return rc;
2257 	if (reply.evt.status) {
2258 		wil_err(wil, "get rf selected sector cfg failed with status %d\n",
2259 			reply.evt.status);
2260 		return wil_rf_sector_status_to_rc(reply.evt.status);
2261 	}
2262 
2263 	msg = cfg80211_vendor_cmd_alloc_reply_skb(
2264 		wiphy, 64 * WMI_MAX_RF_MODULES_NUM);
2265 	if (!msg)
2266 		return -ENOMEM;
2267 
2268 	if (nla_put_u64_64bit(msg, QCA_ATTR_TSF,
2269 			      le64_to_cpu(reply.evt.tsf),
2270 			      QCA_ATTR_PAD) ||
2271 	    nla_put_u16(msg, QCA_ATTR_DMG_RF_SECTOR_INDEX,
2272 			le16_to_cpu(reply.evt.sector_idx)))
2273 		goto nla_put_failure;
2274 
2275 	rc = cfg80211_vendor_cmd_reply(msg);
2276 	return rc;
2277 nla_put_failure:
2278 	kfree_skb(msg);
2279 	return -ENOBUFS;
2280 }
2281 
2282 static int wil_rf_sector_wmi_set_selected(struct wil6210_priv *wil,
2283 					  u16 sector_index,
2284 					  u8 sector_type, u8 cid)
2285 {
2286 	struct wmi_set_selected_rf_sector_index_cmd cmd;
2287 	struct {
2288 		struct wmi_cmd_hdr wmi;
2289 		struct wmi_set_selected_rf_sector_index_done_event evt;
2290 	} __packed reply;
2291 	int rc;
2292 
2293 	memset(&cmd, 0, sizeof(cmd));
2294 	cmd.sector_idx = cpu_to_le16(sector_index);
2295 	cmd.sector_type = sector_type;
2296 	cmd.cid = (u8)cid;
2297 	memset(&reply, 0, sizeof(reply));
2298 	rc = wmi_call(wil, WMI_SET_SELECTED_RF_SECTOR_INDEX_CMDID,
2299 		      &cmd, sizeof(cmd),
2300 		      WMI_SET_SELECTED_RF_SECTOR_INDEX_DONE_EVENTID,
2301 		      &reply, sizeof(reply),
2302 		      500);
2303 	if (rc)
2304 		return rc;
2305 	return wil_rf_sector_status_to_rc(reply.evt.status);
2306 }
2307 
2308 static int wil_rf_sector_set_selected(struct wiphy *wiphy,
2309 				      struct wireless_dev *wdev,
2310 				      const void *data, int data_len)
2311 {
2312 	struct wil6210_priv *wil = wdev_to_wil(wdev);
2313 	int rc;
2314 	struct nlattr *tb[QCA_ATTR_DMG_RF_SECTOR_MAX + 1];
2315 	u16 sector_index;
2316 	u8 sector_type, mac_addr[ETH_ALEN], i;
2317 	int cid = 0;
2318 
2319 	if (!test_bit(WMI_FW_CAPABILITY_RF_SECTORS, wil->fw_capabilities))
2320 		return -EOPNOTSUPP;
2321 
2322 	rc = nla_parse(tb, QCA_ATTR_DMG_RF_SECTOR_MAX, data, data_len,
2323 		       wil_rf_sector_policy, NULL);
2324 	if (rc) {
2325 		wil_err(wil, "Invalid rf sector ATTR\n");
2326 		return rc;
2327 	}
2328 
2329 	if (!tb[QCA_ATTR_DMG_RF_SECTOR_INDEX] ||
2330 	    !tb[QCA_ATTR_DMG_RF_SECTOR_TYPE]) {
2331 		wil_err(wil, "Invalid rf sector spec\n");
2332 		return -EINVAL;
2333 	}
2334 
2335 	sector_index = nla_get_u16(
2336 		tb[QCA_ATTR_DMG_RF_SECTOR_INDEX]);
2337 	if (sector_index >= WIL_MAX_RF_SECTORS &&
2338 	    sector_index != WMI_INVALID_RF_SECTOR_INDEX) {
2339 		wil_err(wil, "Invalid sector index %d\n", sector_index);
2340 		return -EINVAL;
2341 	}
2342 
2343 	sector_type = nla_get_u8(tb[QCA_ATTR_DMG_RF_SECTOR_TYPE]);
2344 	if (sector_type >= QCA_ATTR_DMG_RF_SECTOR_TYPE_MAX) {
2345 		wil_err(wil, "Invalid sector type %d\n", sector_type);
2346 		return -EINVAL;
2347 	}
2348 
2349 	if (tb[QCA_ATTR_MAC_ADDR]) {
2350 		ether_addr_copy(mac_addr, nla_data(tb[QCA_ATTR_MAC_ADDR]));
2351 		if (!is_broadcast_ether_addr(mac_addr)) {
2352 			cid = wil_find_cid(wil, mac_addr);
2353 			if (cid < 0) {
2354 				wil_err(wil, "invalid MAC address %pM\n",
2355 					mac_addr);
2356 				return -ENOENT;
2357 			}
2358 		} else {
2359 			if (sector_index != WMI_INVALID_RF_SECTOR_INDEX) {
2360 				wil_err(wil, "broadcast MAC valid only with unlocking\n");
2361 				return -EINVAL;
2362 			}
2363 			cid = -1;
2364 		}
2365 	} else {
2366 		if (test_bit(wil_status_fwconnected, wil->status)) {
2367 			wil_err(wil, "must specify MAC address when connected\n");
2368 			return -EINVAL;
2369 		}
2370 		/* otherwise, using cid=0 for unassociated station */
2371 	}
2372 
2373 	if (cid >= 0) {
2374 		rc = wil_rf_sector_wmi_set_selected(wil, sector_index,
2375 						    sector_type, cid);
2376 	} else {
2377 		/* unlock all cids */
2378 		rc = wil_rf_sector_wmi_set_selected(
2379 			wil, WMI_INVALID_RF_SECTOR_INDEX, sector_type,
2380 			WIL_CID_ALL);
2381 		if (rc == -EINVAL) {
2382 			for (i = 0; i < WIL6210_MAX_CID; i++) {
2383 				rc = wil_rf_sector_wmi_set_selected(
2384 					wil, WMI_INVALID_RF_SECTOR_INDEX,
2385 					sector_type, i);
2386 				/* the FW will silently ignore and return
2387 				 * success for unused cid, so abort the loop
2388 				 * on any other error
2389 				 */
2390 				if (rc) {
2391 					wil_err(wil, "unlock cid %d failed with status %d\n",
2392 						i, rc);
2393 					break;
2394 				}
2395 			}
2396 		}
2397 	}
2398 
2399 	return rc;
2400 }
2401