xref: /openbmc/linux/drivers/net/wireless/ath/ath10k/wmi-tlv.c (revision 2e7c04aec86758e0adfcad4a24c86593b45807a3)
1 /*
2  * Copyright (c) 2005-2011 Atheros Communications Inc.
3  * Copyright (c) 2011-2017 Qualcomm Atheros, Inc.
4  * Copyright (c) 2018, The Linux Foundation. All rights reserved.
5  *
6  * Permission to use, copy, modify, and/or distribute this software for any
7  * purpose with or without fee is hereby granted, provided that the above
8  * copyright notice and this permission notice appear in all copies.
9  *
10  * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
11  * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
12  * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
13  * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
14  * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15  * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16  * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17  */
18 #include "core.h"
19 #include "debug.h"
20 #include "mac.h"
21 #include "hw.h"
22 #include "mac.h"
23 #include "wmi.h"
24 #include "wmi-ops.h"
25 #include "wmi-tlv.h"
26 #include "p2p.h"
27 #include "testmode.h"
28 
29 /***************/
30 /* TLV helpers */
31 /**************/
32 
33 struct wmi_tlv_policy {
34 	size_t min_len;
35 };
36 
37 static const struct wmi_tlv_policy wmi_tlv_policies[] = {
38 	[WMI_TLV_TAG_ARRAY_BYTE]
39 		= { .min_len = 0 },
40 	[WMI_TLV_TAG_ARRAY_UINT32]
41 		= { .min_len = 0 },
42 	[WMI_TLV_TAG_STRUCT_SCAN_EVENT]
43 		= { .min_len = sizeof(struct wmi_scan_event) },
44 	[WMI_TLV_TAG_STRUCT_MGMT_RX_HDR]
45 		= { .min_len = sizeof(struct wmi_tlv_mgmt_rx_ev) },
46 	[WMI_TLV_TAG_STRUCT_CHAN_INFO_EVENT]
47 		= { .min_len = sizeof(struct wmi_chan_info_event) },
48 	[WMI_TLV_TAG_STRUCT_VDEV_START_RESPONSE_EVENT]
49 		= { .min_len = sizeof(struct wmi_vdev_start_response_event) },
50 	[WMI_TLV_TAG_STRUCT_PEER_STA_KICKOUT_EVENT]
51 		= { .min_len = sizeof(struct wmi_peer_sta_kickout_event) },
52 	[WMI_TLV_TAG_STRUCT_HOST_SWBA_EVENT]
53 		= { .min_len = sizeof(struct wmi_host_swba_event) },
54 	[WMI_TLV_TAG_STRUCT_TIM_INFO]
55 		= { .min_len = sizeof(struct wmi_tim_info) },
56 	[WMI_TLV_TAG_STRUCT_P2P_NOA_INFO]
57 		= { .min_len = sizeof(struct wmi_p2p_noa_info) },
58 	[WMI_TLV_TAG_STRUCT_SERVICE_READY_EVENT]
59 		= { .min_len = sizeof(struct wmi_tlv_svc_rdy_ev) },
60 	[WMI_TLV_TAG_STRUCT_HAL_REG_CAPABILITIES]
61 		= { .min_len = sizeof(struct hal_reg_capabilities) },
62 	[WMI_TLV_TAG_STRUCT_WLAN_HOST_MEM_REQ]
63 		= { .min_len = sizeof(struct wlan_host_mem_req) },
64 	[WMI_TLV_TAG_STRUCT_READY_EVENT]
65 		= { .min_len = sizeof(struct wmi_tlv_rdy_ev) },
66 	[WMI_TLV_TAG_STRUCT_OFFLOAD_BCN_TX_STATUS_EVENT]
67 		= { .min_len = sizeof(struct wmi_tlv_bcn_tx_status_ev) },
68 	[WMI_TLV_TAG_STRUCT_DIAG_DATA_CONTAINER_EVENT]
69 		= { .min_len = sizeof(struct wmi_tlv_diag_data_ev) },
70 	[WMI_TLV_TAG_STRUCT_P2P_NOA_EVENT]
71 		= { .min_len = sizeof(struct wmi_tlv_p2p_noa_ev) },
72 	[WMI_TLV_TAG_STRUCT_ROAM_EVENT]
73 		= { .min_len = sizeof(struct wmi_tlv_roam_ev) },
74 	[WMI_TLV_TAG_STRUCT_WOW_EVENT_INFO]
75 		= { .min_len = sizeof(struct wmi_tlv_wow_event_info) },
76 	[WMI_TLV_TAG_STRUCT_TX_PAUSE_EVENT]
77 		= { .min_len = sizeof(struct wmi_tlv_tx_pause_ev) },
78 };
79 
80 static int
81 ath10k_wmi_tlv_iter(struct ath10k *ar, const void *ptr, size_t len,
82 		    int (*iter)(struct ath10k *ar, u16 tag, u16 len,
83 				const void *ptr, void *data),
84 		    void *data)
85 {
86 	const void *begin = ptr;
87 	const struct wmi_tlv *tlv;
88 	u16 tlv_tag, tlv_len;
89 	int ret;
90 
91 	while (len > 0) {
92 		if (len < sizeof(*tlv)) {
93 			ath10k_dbg(ar, ATH10K_DBG_WMI,
94 				   "wmi tlv parse failure at byte %zd (%zu bytes left, %zu expected)\n",
95 				   ptr - begin, len, sizeof(*tlv));
96 			return -EINVAL;
97 		}
98 
99 		tlv = ptr;
100 		tlv_tag = __le16_to_cpu(tlv->tag);
101 		tlv_len = __le16_to_cpu(tlv->len);
102 		ptr += sizeof(*tlv);
103 		len -= sizeof(*tlv);
104 
105 		if (tlv_len > len) {
106 			ath10k_dbg(ar, ATH10K_DBG_WMI,
107 				   "wmi tlv parse failure of tag %hhu at byte %zd (%zu bytes left, %hhu expected)\n",
108 				   tlv_tag, ptr - begin, len, tlv_len);
109 			return -EINVAL;
110 		}
111 
112 		if (tlv_tag < ARRAY_SIZE(wmi_tlv_policies) &&
113 		    wmi_tlv_policies[tlv_tag].min_len &&
114 		    wmi_tlv_policies[tlv_tag].min_len > tlv_len) {
115 			ath10k_dbg(ar, ATH10K_DBG_WMI,
116 				   "wmi tlv parse failure of tag %hhu at byte %zd (%hhu bytes is less than min length %zu)\n",
117 				   tlv_tag, ptr - begin, tlv_len,
118 				   wmi_tlv_policies[tlv_tag].min_len);
119 			return -EINVAL;
120 		}
121 
122 		ret = iter(ar, tlv_tag, tlv_len, ptr, data);
123 		if (ret)
124 			return ret;
125 
126 		ptr += tlv_len;
127 		len -= tlv_len;
128 	}
129 
130 	return 0;
131 }
132 
133 static int ath10k_wmi_tlv_iter_parse(struct ath10k *ar, u16 tag, u16 len,
134 				     const void *ptr, void *data)
135 {
136 	const void **tb = data;
137 
138 	if (tag < WMI_TLV_TAG_MAX)
139 		tb[tag] = ptr;
140 
141 	return 0;
142 }
143 
144 static int ath10k_wmi_tlv_parse(struct ath10k *ar, const void **tb,
145 				const void *ptr, size_t len)
146 {
147 	return ath10k_wmi_tlv_iter(ar, ptr, len, ath10k_wmi_tlv_iter_parse,
148 				   (void *)tb);
149 }
150 
151 static const void **
152 ath10k_wmi_tlv_parse_alloc(struct ath10k *ar, const void *ptr,
153 			   size_t len, gfp_t gfp)
154 {
155 	const void **tb;
156 	int ret;
157 
158 	tb = kcalloc(WMI_TLV_TAG_MAX, sizeof(*tb), gfp);
159 	if (!tb)
160 		return ERR_PTR(-ENOMEM);
161 
162 	ret = ath10k_wmi_tlv_parse(ar, tb, ptr, len);
163 	if (ret) {
164 		kfree(tb);
165 		return ERR_PTR(ret);
166 	}
167 
168 	return tb;
169 }
170 
171 static u16 ath10k_wmi_tlv_len(const void *ptr)
172 {
173 	return __le16_to_cpu((((const struct wmi_tlv *)ptr) - 1)->len);
174 }
175 
176 /**************/
177 /* TLV events */
178 /**************/
179 static int ath10k_wmi_tlv_event_bcn_tx_status(struct ath10k *ar,
180 					      struct sk_buff *skb)
181 {
182 	const void **tb;
183 	const struct wmi_tlv_bcn_tx_status_ev *ev;
184 	struct ath10k_vif *arvif;
185 	u32 vdev_id, tx_status;
186 	int ret;
187 
188 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
189 	if (IS_ERR(tb)) {
190 		ret = PTR_ERR(tb);
191 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
192 		return ret;
193 	}
194 
195 	ev = tb[WMI_TLV_TAG_STRUCT_OFFLOAD_BCN_TX_STATUS_EVENT];
196 	if (!ev) {
197 		kfree(tb);
198 		return -EPROTO;
199 	}
200 
201 	tx_status = __le32_to_cpu(ev->tx_status);
202 	vdev_id = __le32_to_cpu(ev->vdev_id);
203 
204 	switch (tx_status) {
205 	case WMI_TLV_BCN_TX_STATUS_OK:
206 		break;
207 	case WMI_TLV_BCN_TX_STATUS_XRETRY:
208 	case WMI_TLV_BCN_TX_STATUS_DROP:
209 	case WMI_TLV_BCN_TX_STATUS_FILTERED:
210 		/* FIXME: It's probably worth telling mac80211 to stop the
211 		 * interface as it is crippled.
212 		 */
213 		ath10k_warn(ar, "received bcn tmpl tx status on vdev %i: %d",
214 			    vdev_id, tx_status);
215 		break;
216 	}
217 
218 	arvif = ath10k_get_arvif(ar, vdev_id);
219 	if (arvif && arvif->is_up && arvif->vif->csa_active)
220 		ieee80211_queue_work(ar->hw, &arvif->ap_csa_work);
221 
222 	kfree(tb);
223 	return 0;
224 }
225 
226 static int ath10k_wmi_tlv_event_diag_data(struct ath10k *ar,
227 					  struct sk_buff *skb)
228 {
229 	const void **tb;
230 	const struct wmi_tlv_diag_data_ev *ev;
231 	const struct wmi_tlv_diag_item *item;
232 	const void *data;
233 	int ret, num_items, len;
234 
235 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
236 	if (IS_ERR(tb)) {
237 		ret = PTR_ERR(tb);
238 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
239 		return ret;
240 	}
241 
242 	ev = tb[WMI_TLV_TAG_STRUCT_DIAG_DATA_CONTAINER_EVENT];
243 	data = tb[WMI_TLV_TAG_ARRAY_BYTE];
244 	if (!ev || !data) {
245 		kfree(tb);
246 		return -EPROTO;
247 	}
248 
249 	num_items = __le32_to_cpu(ev->num_items);
250 	len = ath10k_wmi_tlv_len(data);
251 
252 	while (num_items--) {
253 		if (len == 0)
254 			break;
255 		if (len < sizeof(*item)) {
256 			ath10k_warn(ar, "failed to parse diag data: can't fit item header\n");
257 			break;
258 		}
259 
260 		item = data;
261 
262 		if (len < sizeof(*item) + __le16_to_cpu(item->len)) {
263 			ath10k_warn(ar, "failed to parse diag data: item is too long\n");
264 			break;
265 		}
266 
267 		trace_ath10k_wmi_diag_container(ar,
268 						item->type,
269 						__le32_to_cpu(item->timestamp),
270 						__le32_to_cpu(item->code),
271 						__le16_to_cpu(item->len),
272 						item->payload);
273 
274 		len -= sizeof(*item);
275 		len -= roundup(__le16_to_cpu(item->len), 4);
276 
277 		data += sizeof(*item);
278 		data += roundup(__le16_to_cpu(item->len), 4);
279 	}
280 
281 	if (num_items != -1 || len != 0)
282 		ath10k_warn(ar, "failed to parse diag data event: num_items %d len %d\n",
283 			    num_items, len);
284 
285 	kfree(tb);
286 	return 0;
287 }
288 
289 static int ath10k_wmi_tlv_event_diag(struct ath10k *ar,
290 				     struct sk_buff *skb)
291 {
292 	const void **tb;
293 	const void *data;
294 	int ret, len;
295 
296 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
297 	if (IS_ERR(tb)) {
298 		ret = PTR_ERR(tb);
299 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
300 		return ret;
301 	}
302 
303 	data = tb[WMI_TLV_TAG_ARRAY_BYTE];
304 	if (!data) {
305 		kfree(tb);
306 		return -EPROTO;
307 	}
308 	len = ath10k_wmi_tlv_len(data);
309 
310 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv diag event len %d\n", len);
311 	trace_ath10k_wmi_diag(ar, data, len);
312 
313 	kfree(tb);
314 	return 0;
315 }
316 
317 static int ath10k_wmi_tlv_event_p2p_noa(struct ath10k *ar,
318 					struct sk_buff *skb)
319 {
320 	const void **tb;
321 	const struct wmi_tlv_p2p_noa_ev *ev;
322 	const struct wmi_p2p_noa_info *noa;
323 	int ret, vdev_id;
324 
325 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
326 	if (IS_ERR(tb)) {
327 		ret = PTR_ERR(tb);
328 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
329 		return ret;
330 	}
331 
332 	ev = tb[WMI_TLV_TAG_STRUCT_P2P_NOA_EVENT];
333 	noa = tb[WMI_TLV_TAG_STRUCT_P2P_NOA_INFO];
334 
335 	if (!ev || !noa) {
336 		kfree(tb);
337 		return -EPROTO;
338 	}
339 
340 	vdev_id = __le32_to_cpu(ev->vdev_id);
341 
342 	ath10k_dbg(ar, ATH10K_DBG_WMI,
343 		   "wmi tlv p2p noa vdev_id %i descriptors %hhu\n",
344 		   vdev_id, noa->num_descriptors);
345 
346 	ath10k_p2p_noa_update_by_vdev_id(ar, vdev_id, noa);
347 	kfree(tb);
348 	return 0;
349 }
350 
351 static int ath10k_wmi_tlv_event_tx_pause(struct ath10k *ar,
352 					 struct sk_buff *skb)
353 {
354 	const void **tb;
355 	const struct wmi_tlv_tx_pause_ev *ev;
356 	int ret, vdev_id;
357 	u32 pause_id, action, vdev_map, peer_id, tid_map;
358 
359 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
360 	if (IS_ERR(tb)) {
361 		ret = PTR_ERR(tb);
362 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
363 		return ret;
364 	}
365 
366 	ev = tb[WMI_TLV_TAG_STRUCT_TX_PAUSE_EVENT];
367 	if (!ev) {
368 		kfree(tb);
369 		return -EPROTO;
370 	}
371 
372 	pause_id = __le32_to_cpu(ev->pause_id);
373 	action = __le32_to_cpu(ev->action);
374 	vdev_map = __le32_to_cpu(ev->vdev_map);
375 	peer_id = __le32_to_cpu(ev->peer_id);
376 	tid_map = __le32_to_cpu(ev->tid_map);
377 
378 	ath10k_dbg(ar, ATH10K_DBG_WMI,
379 		   "wmi tlv tx pause pause_id %u action %u vdev_map 0x%08x peer_id %u tid_map 0x%08x\n",
380 		   pause_id, action, vdev_map, peer_id, tid_map);
381 
382 	switch (pause_id) {
383 	case WMI_TLV_TX_PAUSE_ID_MCC:
384 	case WMI_TLV_TX_PAUSE_ID_P2P_CLI_NOA:
385 	case WMI_TLV_TX_PAUSE_ID_P2P_GO_PS:
386 	case WMI_TLV_TX_PAUSE_ID_AP_PS:
387 	case WMI_TLV_TX_PAUSE_ID_IBSS_PS:
388 		for (vdev_id = 0; vdev_map; vdev_id++) {
389 			if (!(vdev_map & BIT(vdev_id)))
390 				continue;
391 
392 			vdev_map &= ~BIT(vdev_id);
393 			ath10k_mac_handle_tx_pause_vdev(ar, vdev_id, pause_id,
394 							action);
395 		}
396 		break;
397 	case WMI_TLV_TX_PAUSE_ID_AP_PEER_PS:
398 	case WMI_TLV_TX_PAUSE_ID_AP_PEER_UAPSD:
399 	case WMI_TLV_TX_PAUSE_ID_STA_ADD_BA:
400 	case WMI_TLV_TX_PAUSE_ID_HOST:
401 		ath10k_dbg(ar, ATH10K_DBG_MAC,
402 			   "mac ignoring unsupported tx pause id %d\n",
403 			   pause_id);
404 		break;
405 	default:
406 		ath10k_dbg(ar, ATH10K_DBG_MAC,
407 			   "mac ignoring unknown tx pause vdev %d\n",
408 			   pause_id);
409 		break;
410 	}
411 
412 	kfree(tb);
413 	return 0;
414 }
415 
416 static int ath10k_wmi_tlv_event_temperature(struct ath10k *ar,
417 					    struct sk_buff *skb)
418 {
419 	const struct wmi_tlv_pdev_temperature_event *ev;
420 
421 	ev = (struct wmi_tlv_pdev_temperature_event *)skb->data;
422 	if (WARN_ON(skb->len < sizeof(*ev)))
423 		return -EPROTO;
424 
425 	ath10k_thermal_event_temperature(ar, __le32_to_cpu(ev->temperature));
426 	return 0;
427 }
428 
429 static void ath10k_wmi_event_tdls_peer(struct ath10k *ar, struct sk_buff *skb)
430 {
431 	struct ieee80211_sta *station;
432 	const struct wmi_tlv_tdls_peer_event *ev;
433 	const void **tb;
434 	struct ath10k_vif *arvif;
435 
436 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
437 	if (IS_ERR(tb)) {
438 		ath10k_warn(ar, "tdls peer failed to parse tlv");
439 		return;
440 	}
441 	ev = tb[WMI_TLV_TAG_STRUCT_TDLS_PEER_EVENT];
442 	if (!ev) {
443 		kfree(tb);
444 		ath10k_warn(ar, "tdls peer NULL event");
445 		return;
446 	}
447 
448 	switch (__le32_to_cpu(ev->peer_reason)) {
449 	case WMI_TDLS_TEARDOWN_REASON_TX:
450 	case WMI_TDLS_TEARDOWN_REASON_RSSI:
451 	case WMI_TDLS_TEARDOWN_REASON_PTR_TIMEOUT:
452 		station = ieee80211_find_sta_by_ifaddr(ar->hw,
453 						       ev->peer_macaddr.addr,
454 						       NULL);
455 		if (!station) {
456 			ath10k_warn(ar, "did not find station from tdls peer event");
457 			kfree(tb);
458 			return;
459 		}
460 		arvif = ath10k_get_arvif(ar, __le32_to_cpu(ev->vdev_id));
461 		ieee80211_tdls_oper_request(
462 					arvif->vif, station->addr,
463 					NL80211_TDLS_TEARDOWN,
464 					WLAN_REASON_TDLS_TEARDOWN_UNREACHABLE,
465 					GFP_ATOMIC
466 					);
467 		break;
468 	}
469 	kfree(tb);
470 }
471 
472 /***********/
473 /* TLV ops */
474 /***********/
475 
476 static void ath10k_wmi_tlv_op_rx(struct ath10k *ar, struct sk_buff *skb)
477 {
478 	struct wmi_cmd_hdr *cmd_hdr;
479 	enum wmi_tlv_event_id id;
480 	bool consumed;
481 
482 	cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
483 	id = MS(__le32_to_cpu(cmd_hdr->cmd_id), WMI_CMD_HDR_CMD_ID);
484 
485 	if (skb_pull(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
486 		goto out;
487 
488 	trace_ath10k_wmi_event(ar, id, skb->data, skb->len);
489 
490 	consumed = ath10k_tm_event_wmi(ar, id, skb);
491 
492 	/* Ready event must be handled normally also in UTF mode so that we
493 	 * know the UTF firmware has booted, others we are just bypass WMI
494 	 * events to testmode.
495 	 */
496 	if (consumed && id != WMI_TLV_READY_EVENTID) {
497 		ath10k_dbg(ar, ATH10K_DBG_WMI,
498 			   "wmi tlv testmode consumed 0x%x\n", id);
499 		goto out;
500 	}
501 
502 	switch (id) {
503 	case WMI_TLV_MGMT_RX_EVENTID:
504 		ath10k_wmi_event_mgmt_rx(ar, skb);
505 		/* mgmt_rx() owns the skb now! */
506 		return;
507 	case WMI_TLV_SCAN_EVENTID:
508 		ath10k_wmi_event_scan(ar, skb);
509 		break;
510 	case WMI_TLV_CHAN_INFO_EVENTID:
511 		ath10k_wmi_event_chan_info(ar, skb);
512 		break;
513 	case WMI_TLV_ECHO_EVENTID:
514 		ath10k_wmi_event_echo(ar, skb);
515 		break;
516 	case WMI_TLV_DEBUG_MESG_EVENTID:
517 		ath10k_wmi_event_debug_mesg(ar, skb);
518 		break;
519 	case WMI_TLV_UPDATE_STATS_EVENTID:
520 		ath10k_wmi_event_update_stats(ar, skb);
521 		break;
522 	case WMI_TLV_VDEV_START_RESP_EVENTID:
523 		ath10k_wmi_event_vdev_start_resp(ar, skb);
524 		break;
525 	case WMI_TLV_VDEV_STOPPED_EVENTID:
526 		ath10k_wmi_event_vdev_stopped(ar, skb);
527 		break;
528 	case WMI_TLV_PEER_STA_KICKOUT_EVENTID:
529 		ath10k_wmi_event_peer_sta_kickout(ar, skb);
530 		break;
531 	case WMI_TLV_HOST_SWBA_EVENTID:
532 		ath10k_wmi_event_host_swba(ar, skb);
533 		break;
534 	case WMI_TLV_TBTTOFFSET_UPDATE_EVENTID:
535 		ath10k_wmi_event_tbttoffset_update(ar, skb);
536 		break;
537 	case WMI_TLV_PHYERR_EVENTID:
538 		ath10k_wmi_event_phyerr(ar, skb);
539 		break;
540 	case WMI_TLV_ROAM_EVENTID:
541 		ath10k_wmi_event_roam(ar, skb);
542 		break;
543 	case WMI_TLV_PROFILE_MATCH:
544 		ath10k_wmi_event_profile_match(ar, skb);
545 		break;
546 	case WMI_TLV_DEBUG_PRINT_EVENTID:
547 		ath10k_wmi_event_debug_print(ar, skb);
548 		break;
549 	case WMI_TLV_PDEV_QVIT_EVENTID:
550 		ath10k_wmi_event_pdev_qvit(ar, skb);
551 		break;
552 	case WMI_TLV_WLAN_PROFILE_DATA_EVENTID:
553 		ath10k_wmi_event_wlan_profile_data(ar, skb);
554 		break;
555 	case WMI_TLV_RTT_MEASUREMENT_REPORT_EVENTID:
556 		ath10k_wmi_event_rtt_measurement_report(ar, skb);
557 		break;
558 	case WMI_TLV_TSF_MEASUREMENT_REPORT_EVENTID:
559 		ath10k_wmi_event_tsf_measurement_report(ar, skb);
560 		break;
561 	case WMI_TLV_RTT_ERROR_REPORT_EVENTID:
562 		ath10k_wmi_event_rtt_error_report(ar, skb);
563 		break;
564 	case WMI_TLV_WOW_WAKEUP_HOST_EVENTID:
565 		ath10k_wmi_event_wow_wakeup_host(ar, skb);
566 		break;
567 	case WMI_TLV_DCS_INTERFERENCE_EVENTID:
568 		ath10k_wmi_event_dcs_interference(ar, skb);
569 		break;
570 	case WMI_TLV_PDEV_TPC_CONFIG_EVENTID:
571 		ath10k_wmi_event_pdev_tpc_config(ar, skb);
572 		break;
573 	case WMI_TLV_PDEV_FTM_INTG_EVENTID:
574 		ath10k_wmi_event_pdev_ftm_intg(ar, skb);
575 		break;
576 	case WMI_TLV_GTK_OFFLOAD_STATUS_EVENTID:
577 		ath10k_wmi_event_gtk_offload_status(ar, skb);
578 		break;
579 	case WMI_TLV_GTK_REKEY_FAIL_EVENTID:
580 		ath10k_wmi_event_gtk_rekey_fail(ar, skb);
581 		break;
582 	case WMI_TLV_TX_DELBA_COMPLETE_EVENTID:
583 		ath10k_wmi_event_delba_complete(ar, skb);
584 		break;
585 	case WMI_TLV_TX_ADDBA_COMPLETE_EVENTID:
586 		ath10k_wmi_event_addba_complete(ar, skb);
587 		break;
588 	case WMI_TLV_VDEV_INSTALL_KEY_COMPLETE_EVENTID:
589 		ath10k_wmi_event_vdev_install_key_complete(ar, skb);
590 		break;
591 	case WMI_TLV_SERVICE_READY_EVENTID:
592 		ath10k_wmi_event_service_ready(ar, skb);
593 		return;
594 	case WMI_TLV_READY_EVENTID:
595 		ath10k_wmi_event_ready(ar, skb);
596 		break;
597 	case WMI_TLV_SERVICE_AVAILABLE_EVENTID:
598 		ath10k_wmi_event_service_available(ar, skb);
599 		break;
600 	case WMI_TLV_OFFLOAD_BCN_TX_STATUS_EVENTID:
601 		ath10k_wmi_tlv_event_bcn_tx_status(ar, skb);
602 		break;
603 	case WMI_TLV_DIAG_DATA_CONTAINER_EVENTID:
604 		ath10k_wmi_tlv_event_diag_data(ar, skb);
605 		break;
606 	case WMI_TLV_DIAG_EVENTID:
607 		ath10k_wmi_tlv_event_diag(ar, skb);
608 		break;
609 	case WMI_TLV_P2P_NOA_EVENTID:
610 		ath10k_wmi_tlv_event_p2p_noa(ar, skb);
611 		break;
612 	case WMI_TLV_TX_PAUSE_EVENTID:
613 		ath10k_wmi_tlv_event_tx_pause(ar, skb);
614 		break;
615 	case WMI_TLV_PDEV_TEMPERATURE_EVENTID:
616 		ath10k_wmi_tlv_event_temperature(ar, skb);
617 		break;
618 	case WMI_TLV_TDLS_PEER_EVENTID:
619 		ath10k_wmi_event_tdls_peer(ar, skb);
620 		break;
621 	case WMI_TLV_MGMT_TX_COMPLETION_EVENTID:
622 		ath10k_wmi_event_mgmt_tx_compl(ar, skb);
623 		break;
624 	default:
625 		ath10k_warn(ar, "Unknown eventid: %d\n", id);
626 		break;
627 	}
628 
629 out:
630 	dev_kfree_skb(skb);
631 }
632 
633 static int ath10k_wmi_tlv_op_pull_scan_ev(struct ath10k *ar,
634 					  struct sk_buff *skb,
635 					  struct wmi_scan_ev_arg *arg)
636 {
637 	const void **tb;
638 	const struct wmi_scan_event *ev;
639 	int ret;
640 
641 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
642 	if (IS_ERR(tb)) {
643 		ret = PTR_ERR(tb);
644 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
645 		return ret;
646 	}
647 
648 	ev = tb[WMI_TLV_TAG_STRUCT_SCAN_EVENT];
649 	if (!ev) {
650 		kfree(tb);
651 		return -EPROTO;
652 	}
653 
654 	arg->event_type = ev->event_type;
655 	arg->reason = ev->reason;
656 	arg->channel_freq = ev->channel_freq;
657 	arg->scan_req_id = ev->scan_req_id;
658 	arg->scan_id = ev->scan_id;
659 	arg->vdev_id = ev->vdev_id;
660 
661 	kfree(tb);
662 	return 0;
663 }
664 
665 static int
666 ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev(struct ath10k *ar, struct sk_buff *skb,
667 					struct wmi_tlv_mgmt_tx_compl_ev_arg *arg)
668 {
669 	const void **tb;
670 	const struct wmi_tlv_mgmt_tx_compl_ev *ev;
671 	int ret;
672 
673 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
674 	if (IS_ERR(tb)) {
675 		ret = PTR_ERR(tb);
676 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
677 		return ret;
678 	}
679 
680 	ev = tb[WMI_TLV_TAG_STRUCT_MGMT_TX_COMPL_EVENT];
681 
682 	arg->desc_id = ev->desc_id;
683 	arg->status = ev->status;
684 	arg->pdev_id = ev->pdev_id;
685 
686 	kfree(tb);
687 	return 0;
688 }
689 
690 static int ath10k_wmi_tlv_op_pull_mgmt_rx_ev(struct ath10k *ar,
691 					     struct sk_buff *skb,
692 					     struct wmi_mgmt_rx_ev_arg *arg)
693 {
694 	const void **tb;
695 	const struct wmi_tlv_mgmt_rx_ev *ev;
696 	const u8 *frame;
697 	u32 msdu_len;
698 	int ret;
699 
700 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
701 	if (IS_ERR(tb)) {
702 		ret = PTR_ERR(tb);
703 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
704 		return ret;
705 	}
706 
707 	ev = tb[WMI_TLV_TAG_STRUCT_MGMT_RX_HDR];
708 	frame = tb[WMI_TLV_TAG_ARRAY_BYTE];
709 
710 	if (!ev || !frame) {
711 		kfree(tb);
712 		return -EPROTO;
713 	}
714 
715 	arg->channel = ev->channel;
716 	arg->buf_len = ev->buf_len;
717 	arg->status = ev->status;
718 	arg->snr = ev->snr;
719 	arg->phy_mode = ev->phy_mode;
720 	arg->rate = ev->rate;
721 
722 	msdu_len = __le32_to_cpu(arg->buf_len);
723 
724 	if (skb->len < (frame - skb->data) + msdu_len) {
725 		kfree(tb);
726 		return -EPROTO;
727 	}
728 
729 	/* shift the sk_buff to point to `frame` */
730 	skb_trim(skb, 0);
731 	skb_put(skb, frame - skb->data);
732 	skb_pull(skb, frame - skb->data);
733 	skb_put(skb, msdu_len);
734 
735 	kfree(tb);
736 	return 0;
737 }
738 
739 static int ath10k_wmi_tlv_op_pull_ch_info_ev(struct ath10k *ar,
740 					     struct sk_buff *skb,
741 					     struct wmi_ch_info_ev_arg *arg)
742 {
743 	const void **tb;
744 	const struct wmi_chan_info_event *ev;
745 	int ret;
746 
747 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
748 	if (IS_ERR(tb)) {
749 		ret = PTR_ERR(tb);
750 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
751 		return ret;
752 	}
753 
754 	ev = tb[WMI_TLV_TAG_STRUCT_CHAN_INFO_EVENT];
755 	if (!ev) {
756 		kfree(tb);
757 		return -EPROTO;
758 	}
759 
760 	arg->err_code = ev->err_code;
761 	arg->freq = ev->freq;
762 	arg->cmd_flags = ev->cmd_flags;
763 	arg->noise_floor = ev->noise_floor;
764 	arg->rx_clear_count = ev->rx_clear_count;
765 	arg->cycle_count = ev->cycle_count;
766 
767 	kfree(tb);
768 	return 0;
769 }
770 
771 static int
772 ath10k_wmi_tlv_op_pull_vdev_start_ev(struct ath10k *ar, struct sk_buff *skb,
773 				     struct wmi_vdev_start_ev_arg *arg)
774 {
775 	const void **tb;
776 	const struct wmi_vdev_start_response_event *ev;
777 	int ret;
778 
779 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
780 	if (IS_ERR(tb)) {
781 		ret = PTR_ERR(tb);
782 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
783 		return ret;
784 	}
785 
786 	ev = tb[WMI_TLV_TAG_STRUCT_VDEV_START_RESPONSE_EVENT];
787 	if (!ev) {
788 		kfree(tb);
789 		return -EPROTO;
790 	}
791 
792 	skb_pull(skb, sizeof(*ev));
793 	arg->vdev_id = ev->vdev_id;
794 	arg->req_id = ev->req_id;
795 	arg->resp_type = ev->resp_type;
796 	arg->status = ev->status;
797 
798 	kfree(tb);
799 	return 0;
800 }
801 
802 static int ath10k_wmi_tlv_op_pull_peer_kick_ev(struct ath10k *ar,
803 					       struct sk_buff *skb,
804 					       struct wmi_peer_kick_ev_arg *arg)
805 {
806 	const void **tb;
807 	const struct wmi_peer_sta_kickout_event *ev;
808 	int ret;
809 
810 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
811 	if (IS_ERR(tb)) {
812 		ret = PTR_ERR(tb);
813 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
814 		return ret;
815 	}
816 
817 	ev = tb[WMI_TLV_TAG_STRUCT_PEER_STA_KICKOUT_EVENT];
818 	if (!ev) {
819 		kfree(tb);
820 		return -EPROTO;
821 	}
822 
823 	arg->mac_addr = ev->peer_macaddr.addr;
824 
825 	kfree(tb);
826 	return 0;
827 }
828 
829 struct wmi_tlv_swba_parse {
830 	const struct wmi_host_swba_event *ev;
831 	bool tim_done;
832 	bool noa_done;
833 	size_t n_tim;
834 	size_t n_noa;
835 	struct wmi_swba_ev_arg *arg;
836 };
837 
838 static int ath10k_wmi_tlv_swba_tim_parse(struct ath10k *ar, u16 tag, u16 len,
839 					 const void *ptr, void *data)
840 {
841 	struct wmi_tlv_swba_parse *swba = data;
842 	struct wmi_tim_info_arg *tim_info_arg;
843 	const struct wmi_tim_info *tim_info_ev = ptr;
844 
845 	if (tag != WMI_TLV_TAG_STRUCT_TIM_INFO)
846 		return -EPROTO;
847 
848 	if (swba->n_tim >= ARRAY_SIZE(swba->arg->tim_info))
849 		return -ENOBUFS;
850 
851 	if (__le32_to_cpu(tim_info_ev->tim_len) >
852 	     sizeof(tim_info_ev->tim_bitmap)) {
853 		ath10k_warn(ar, "refusing to parse invalid swba structure\n");
854 		return -EPROTO;
855 	}
856 
857 	tim_info_arg = &swba->arg->tim_info[swba->n_tim];
858 	tim_info_arg->tim_len = tim_info_ev->tim_len;
859 	tim_info_arg->tim_mcast = tim_info_ev->tim_mcast;
860 	tim_info_arg->tim_bitmap = tim_info_ev->tim_bitmap;
861 	tim_info_arg->tim_changed = tim_info_ev->tim_changed;
862 	tim_info_arg->tim_num_ps_pending = tim_info_ev->tim_num_ps_pending;
863 
864 	swba->n_tim++;
865 
866 	return 0;
867 }
868 
869 static int ath10k_wmi_tlv_swba_noa_parse(struct ath10k *ar, u16 tag, u16 len,
870 					 const void *ptr, void *data)
871 {
872 	struct wmi_tlv_swba_parse *swba = data;
873 
874 	if (tag != WMI_TLV_TAG_STRUCT_P2P_NOA_INFO)
875 		return -EPROTO;
876 
877 	if (swba->n_noa >= ARRAY_SIZE(swba->arg->noa_info))
878 		return -ENOBUFS;
879 
880 	swba->arg->noa_info[swba->n_noa++] = ptr;
881 	return 0;
882 }
883 
884 static int ath10k_wmi_tlv_swba_parse(struct ath10k *ar, u16 tag, u16 len,
885 				     const void *ptr, void *data)
886 {
887 	struct wmi_tlv_swba_parse *swba = data;
888 	int ret;
889 
890 	switch (tag) {
891 	case WMI_TLV_TAG_STRUCT_HOST_SWBA_EVENT:
892 		swba->ev = ptr;
893 		break;
894 	case WMI_TLV_TAG_ARRAY_STRUCT:
895 		if (!swba->tim_done) {
896 			swba->tim_done = true;
897 			ret = ath10k_wmi_tlv_iter(ar, ptr, len,
898 						  ath10k_wmi_tlv_swba_tim_parse,
899 						  swba);
900 			if (ret)
901 				return ret;
902 		} else if (!swba->noa_done) {
903 			swba->noa_done = true;
904 			ret = ath10k_wmi_tlv_iter(ar, ptr, len,
905 						  ath10k_wmi_tlv_swba_noa_parse,
906 						  swba);
907 			if (ret)
908 				return ret;
909 		}
910 		break;
911 	default:
912 		break;
913 	}
914 	return 0;
915 }
916 
917 static int ath10k_wmi_tlv_op_pull_swba_ev(struct ath10k *ar,
918 					  struct sk_buff *skb,
919 					  struct wmi_swba_ev_arg *arg)
920 {
921 	struct wmi_tlv_swba_parse swba = { .arg = arg };
922 	u32 map;
923 	size_t n_vdevs;
924 	int ret;
925 
926 	ret = ath10k_wmi_tlv_iter(ar, skb->data, skb->len,
927 				  ath10k_wmi_tlv_swba_parse, &swba);
928 	if (ret) {
929 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
930 		return ret;
931 	}
932 
933 	if (!swba.ev)
934 		return -EPROTO;
935 
936 	arg->vdev_map = swba.ev->vdev_map;
937 
938 	for (map = __le32_to_cpu(arg->vdev_map), n_vdevs = 0; map; map >>= 1)
939 		if (map & BIT(0))
940 			n_vdevs++;
941 
942 	if (n_vdevs != swba.n_tim ||
943 	    n_vdevs != swba.n_noa)
944 		return -EPROTO;
945 
946 	return 0;
947 }
948 
949 static int ath10k_wmi_tlv_op_pull_phyerr_ev_hdr(struct ath10k *ar,
950 						struct sk_buff *skb,
951 						struct wmi_phyerr_hdr_arg *arg)
952 {
953 	const void **tb;
954 	const struct wmi_tlv_phyerr_ev *ev;
955 	const void *phyerrs;
956 	int ret;
957 
958 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
959 	if (IS_ERR(tb)) {
960 		ret = PTR_ERR(tb);
961 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
962 		return ret;
963 	}
964 
965 	ev = tb[WMI_TLV_TAG_STRUCT_COMB_PHYERR_RX_HDR];
966 	phyerrs = tb[WMI_TLV_TAG_ARRAY_BYTE];
967 
968 	if (!ev || !phyerrs) {
969 		kfree(tb);
970 		return -EPROTO;
971 	}
972 
973 	arg->num_phyerrs  = __le32_to_cpu(ev->num_phyerrs);
974 	arg->tsf_l32 = __le32_to_cpu(ev->tsf_l32);
975 	arg->tsf_u32 = __le32_to_cpu(ev->tsf_u32);
976 	arg->buf_len = __le32_to_cpu(ev->buf_len);
977 	arg->phyerrs = phyerrs;
978 
979 	kfree(tb);
980 	return 0;
981 }
982 
983 #define WMI_TLV_ABI_VER_NS0 0x5F414351
984 #define WMI_TLV_ABI_VER_NS1 0x00004C4D
985 #define WMI_TLV_ABI_VER_NS2 0x00000000
986 #define WMI_TLV_ABI_VER_NS3 0x00000000
987 
988 #define WMI_TLV_ABI_VER0_MAJOR 1
989 #define WMI_TLV_ABI_VER0_MINOR 0
990 #define WMI_TLV_ABI_VER0 ((((WMI_TLV_ABI_VER0_MAJOR) << 24) & 0xFF000000) | \
991 			  (((WMI_TLV_ABI_VER0_MINOR) <<  0) & 0x00FFFFFF))
992 #define WMI_TLV_ABI_VER1 53
993 
994 static int
995 ath10k_wmi_tlv_parse_mem_reqs(struct ath10k *ar, u16 tag, u16 len,
996 			      const void *ptr, void *data)
997 {
998 	struct wmi_svc_rdy_ev_arg *arg = data;
999 	int i;
1000 
1001 	if (tag != WMI_TLV_TAG_STRUCT_WLAN_HOST_MEM_REQ)
1002 		return -EPROTO;
1003 
1004 	for (i = 0; i < ARRAY_SIZE(arg->mem_reqs); i++) {
1005 		if (!arg->mem_reqs[i]) {
1006 			arg->mem_reqs[i] = ptr;
1007 			return 0;
1008 		}
1009 	}
1010 
1011 	return -ENOMEM;
1012 }
1013 
1014 struct wmi_tlv_svc_rdy_parse {
1015 	const struct hal_reg_capabilities *reg;
1016 	const struct wmi_tlv_svc_rdy_ev *ev;
1017 	const __le32 *svc_bmap;
1018 	const struct wlan_host_mem_req *mem_reqs;
1019 	bool svc_bmap_done;
1020 	bool dbs_hw_mode_done;
1021 };
1022 
1023 static int ath10k_wmi_tlv_svc_rdy_parse(struct ath10k *ar, u16 tag, u16 len,
1024 					const void *ptr, void *data)
1025 {
1026 	struct wmi_tlv_svc_rdy_parse *svc_rdy = data;
1027 
1028 	switch (tag) {
1029 	case WMI_TLV_TAG_STRUCT_SERVICE_READY_EVENT:
1030 		svc_rdy->ev = ptr;
1031 		break;
1032 	case WMI_TLV_TAG_STRUCT_HAL_REG_CAPABILITIES:
1033 		svc_rdy->reg = ptr;
1034 		break;
1035 	case WMI_TLV_TAG_ARRAY_STRUCT:
1036 		svc_rdy->mem_reqs = ptr;
1037 		break;
1038 	case WMI_TLV_TAG_ARRAY_UINT32:
1039 		if (!svc_rdy->svc_bmap_done) {
1040 			svc_rdy->svc_bmap_done = true;
1041 			svc_rdy->svc_bmap = ptr;
1042 		} else if (!svc_rdy->dbs_hw_mode_done) {
1043 			svc_rdy->dbs_hw_mode_done = true;
1044 		}
1045 		break;
1046 	default:
1047 		break;
1048 	}
1049 	return 0;
1050 }
1051 
1052 static int ath10k_wmi_tlv_op_pull_svc_rdy_ev(struct ath10k *ar,
1053 					     struct sk_buff *skb,
1054 					     struct wmi_svc_rdy_ev_arg *arg)
1055 {
1056 	const struct hal_reg_capabilities *reg;
1057 	const struct wmi_tlv_svc_rdy_ev *ev;
1058 	const __le32 *svc_bmap;
1059 	const struct wlan_host_mem_req *mem_reqs;
1060 	struct wmi_tlv_svc_rdy_parse svc_rdy = { };
1061 	int ret;
1062 
1063 	ret = ath10k_wmi_tlv_iter(ar, skb->data, skb->len,
1064 				  ath10k_wmi_tlv_svc_rdy_parse, &svc_rdy);
1065 	if (ret) {
1066 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1067 		return ret;
1068 	}
1069 
1070 	ev = svc_rdy.ev;
1071 	reg = svc_rdy.reg;
1072 	svc_bmap = svc_rdy.svc_bmap;
1073 	mem_reqs = svc_rdy.mem_reqs;
1074 
1075 	if (!ev || !reg || !svc_bmap || !mem_reqs)
1076 		return -EPROTO;
1077 
1078 	/* This is an internal ABI compatibility check for WMI TLV so check it
1079 	 * here instead of the generic WMI code.
1080 	 */
1081 	ath10k_dbg(ar, ATH10K_DBG_WMI,
1082 		   "wmi tlv abi 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x, 0x%08x ?= 0x%08x\n",
1083 		   __le32_to_cpu(ev->abi.abi_ver0), WMI_TLV_ABI_VER0,
1084 		   __le32_to_cpu(ev->abi.abi_ver_ns0), WMI_TLV_ABI_VER_NS0,
1085 		   __le32_to_cpu(ev->abi.abi_ver_ns1), WMI_TLV_ABI_VER_NS1,
1086 		   __le32_to_cpu(ev->abi.abi_ver_ns2), WMI_TLV_ABI_VER_NS2,
1087 		   __le32_to_cpu(ev->abi.abi_ver_ns3), WMI_TLV_ABI_VER_NS3);
1088 
1089 	if (__le32_to_cpu(ev->abi.abi_ver0) != WMI_TLV_ABI_VER0 ||
1090 	    __le32_to_cpu(ev->abi.abi_ver_ns0) != WMI_TLV_ABI_VER_NS0 ||
1091 	    __le32_to_cpu(ev->abi.abi_ver_ns1) != WMI_TLV_ABI_VER_NS1 ||
1092 	    __le32_to_cpu(ev->abi.abi_ver_ns2) != WMI_TLV_ABI_VER_NS2 ||
1093 	    __le32_to_cpu(ev->abi.abi_ver_ns3) != WMI_TLV_ABI_VER_NS3) {
1094 		return -ENOTSUPP;
1095 	}
1096 
1097 	arg->min_tx_power = ev->hw_min_tx_power;
1098 	arg->max_tx_power = ev->hw_max_tx_power;
1099 	arg->ht_cap = ev->ht_cap_info;
1100 	arg->vht_cap = ev->vht_cap_info;
1101 	arg->sw_ver0 = ev->abi.abi_ver0;
1102 	arg->sw_ver1 = ev->abi.abi_ver1;
1103 	arg->fw_build = ev->fw_build_vers;
1104 	arg->phy_capab = ev->phy_capability;
1105 	arg->num_rf_chains = ev->num_rf_chains;
1106 	arg->eeprom_rd = reg->eeprom_rd;
1107 	arg->low_5ghz_chan = reg->low_5ghz_chan;
1108 	arg->high_5ghz_chan = reg->high_5ghz_chan;
1109 	arg->num_mem_reqs = ev->num_mem_reqs;
1110 	arg->service_map = svc_bmap;
1111 	arg->service_map_len = ath10k_wmi_tlv_len(svc_bmap);
1112 
1113 	ret = ath10k_wmi_tlv_iter(ar, mem_reqs, ath10k_wmi_tlv_len(mem_reqs),
1114 				  ath10k_wmi_tlv_parse_mem_reqs, arg);
1115 	if (ret) {
1116 		ath10k_warn(ar, "failed to parse mem_reqs tlv: %d\n", ret);
1117 		return ret;
1118 	}
1119 
1120 	return 0;
1121 }
1122 
1123 static int ath10k_wmi_tlv_op_pull_rdy_ev(struct ath10k *ar,
1124 					 struct sk_buff *skb,
1125 					 struct wmi_rdy_ev_arg *arg)
1126 {
1127 	const void **tb;
1128 	const struct wmi_tlv_rdy_ev *ev;
1129 	int ret;
1130 
1131 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1132 	if (IS_ERR(tb)) {
1133 		ret = PTR_ERR(tb);
1134 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1135 		return ret;
1136 	}
1137 
1138 	ev = tb[WMI_TLV_TAG_STRUCT_READY_EVENT];
1139 	if (!ev) {
1140 		kfree(tb);
1141 		return -EPROTO;
1142 	}
1143 
1144 	arg->sw_version = ev->abi.abi_ver0;
1145 	arg->abi_version = ev->abi.abi_ver1;
1146 	arg->status = ev->status;
1147 	arg->mac_addr = ev->mac_addr.addr;
1148 
1149 	kfree(tb);
1150 	return 0;
1151 }
1152 
1153 static int ath10k_wmi_tlv_svc_avail_parse(struct ath10k *ar, u16 tag, u16 len,
1154 					  const void *ptr, void *data)
1155 {
1156 	struct wmi_svc_avail_ev_arg *arg = data;
1157 
1158 	switch (tag) {
1159 	case WMI_TLV_TAG_STRUCT_SERVICE_AVAILABLE_EVENT:
1160 		arg->service_map_ext_len = *(__le32 *)ptr;
1161 		arg->service_map_ext = ptr + sizeof(__le32);
1162 		return 0;
1163 	default:
1164 		break;
1165 	}
1166 	return -EPROTO;
1167 }
1168 
1169 static int ath10k_wmi_tlv_op_pull_svc_avail(struct ath10k *ar,
1170 					    struct sk_buff *skb,
1171 					    struct wmi_svc_avail_ev_arg *arg)
1172 {
1173 	int ret;
1174 
1175 	ret = ath10k_wmi_tlv_iter(ar, skb->data, skb->len,
1176 				  ath10k_wmi_tlv_svc_avail_parse, arg);
1177 
1178 	if (ret) {
1179 		ath10k_warn(ar, "failed to parse svc_avail tlv: %d\n", ret);
1180 		return ret;
1181 	}
1182 
1183 	return 0;
1184 }
1185 
1186 static void ath10k_wmi_tlv_pull_vdev_stats(const struct wmi_tlv_vdev_stats *src,
1187 					   struct ath10k_fw_stats_vdev *dst)
1188 {
1189 	int i;
1190 
1191 	dst->vdev_id = __le32_to_cpu(src->vdev_id);
1192 	dst->beacon_snr = __le32_to_cpu(src->beacon_snr);
1193 	dst->data_snr = __le32_to_cpu(src->data_snr);
1194 	dst->num_rx_frames = __le32_to_cpu(src->num_rx_frames);
1195 	dst->num_rts_fail = __le32_to_cpu(src->num_rts_fail);
1196 	dst->num_rts_success = __le32_to_cpu(src->num_rts_success);
1197 	dst->num_rx_err = __le32_to_cpu(src->num_rx_err);
1198 	dst->num_rx_discard = __le32_to_cpu(src->num_rx_discard);
1199 	dst->num_tx_not_acked = __le32_to_cpu(src->num_tx_not_acked);
1200 
1201 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames); i++)
1202 		dst->num_tx_frames[i] =
1203 			__le32_to_cpu(src->num_tx_frames[i]);
1204 
1205 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_retries); i++)
1206 		dst->num_tx_frames_retries[i] =
1207 			__le32_to_cpu(src->num_tx_frames_retries[i]);
1208 
1209 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_failures); i++)
1210 		dst->num_tx_frames_failures[i] =
1211 			__le32_to_cpu(src->num_tx_frames_failures[i]);
1212 
1213 	for (i = 0; i < ARRAY_SIZE(src->tx_rate_history); i++)
1214 		dst->tx_rate_history[i] =
1215 			__le32_to_cpu(src->tx_rate_history[i]);
1216 
1217 	for (i = 0; i < ARRAY_SIZE(src->beacon_rssi_history); i++)
1218 		dst->beacon_rssi_history[i] =
1219 			__le32_to_cpu(src->beacon_rssi_history[i]);
1220 }
1221 
1222 static int ath10k_wmi_tlv_op_pull_fw_stats(struct ath10k *ar,
1223 					   struct sk_buff *skb,
1224 					   struct ath10k_fw_stats *stats)
1225 {
1226 	const void **tb;
1227 	const struct wmi_tlv_stats_ev *ev;
1228 	const void *data;
1229 	u32 num_pdev_stats;
1230 	u32 num_vdev_stats;
1231 	u32 num_peer_stats;
1232 	u32 num_bcnflt_stats;
1233 	u32 num_chan_stats;
1234 	size_t data_len;
1235 	int ret;
1236 	int i;
1237 
1238 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1239 	if (IS_ERR(tb)) {
1240 		ret = PTR_ERR(tb);
1241 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1242 		return ret;
1243 	}
1244 
1245 	ev = tb[WMI_TLV_TAG_STRUCT_STATS_EVENT];
1246 	data = tb[WMI_TLV_TAG_ARRAY_BYTE];
1247 
1248 	if (!ev || !data) {
1249 		kfree(tb);
1250 		return -EPROTO;
1251 	}
1252 
1253 	data_len = ath10k_wmi_tlv_len(data);
1254 	num_pdev_stats = __le32_to_cpu(ev->num_pdev_stats);
1255 	num_vdev_stats = __le32_to_cpu(ev->num_vdev_stats);
1256 	num_peer_stats = __le32_to_cpu(ev->num_peer_stats);
1257 	num_bcnflt_stats = __le32_to_cpu(ev->num_bcnflt_stats);
1258 	num_chan_stats = __le32_to_cpu(ev->num_chan_stats);
1259 
1260 	ath10k_dbg(ar, ATH10K_DBG_WMI,
1261 		   "wmi tlv stats update pdev %i vdev %i peer %i bcnflt %i chan %i\n",
1262 		   num_pdev_stats, num_vdev_stats, num_peer_stats,
1263 		   num_bcnflt_stats, num_chan_stats);
1264 
1265 	for (i = 0; i < num_pdev_stats; i++) {
1266 		const struct wmi_pdev_stats *src;
1267 		struct ath10k_fw_stats_pdev *dst;
1268 
1269 		src = data;
1270 		if (data_len < sizeof(*src)) {
1271 			kfree(tb);
1272 			return -EPROTO;
1273 		}
1274 
1275 		data += sizeof(*src);
1276 		data_len -= sizeof(*src);
1277 
1278 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1279 		if (!dst)
1280 			continue;
1281 
1282 		ath10k_wmi_pull_pdev_stats_base(&src->base, dst);
1283 		ath10k_wmi_pull_pdev_stats_tx(&src->tx, dst);
1284 		ath10k_wmi_pull_pdev_stats_rx(&src->rx, dst);
1285 		list_add_tail(&dst->list, &stats->pdevs);
1286 	}
1287 
1288 	for (i = 0; i < num_vdev_stats; i++) {
1289 		const struct wmi_tlv_vdev_stats *src;
1290 		struct ath10k_fw_stats_vdev *dst;
1291 
1292 		src = data;
1293 		if (data_len < sizeof(*src)) {
1294 			kfree(tb);
1295 			return -EPROTO;
1296 		}
1297 
1298 		data += sizeof(*src);
1299 		data_len -= sizeof(*src);
1300 
1301 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1302 		if (!dst)
1303 			continue;
1304 
1305 		ath10k_wmi_tlv_pull_vdev_stats(src, dst);
1306 		list_add_tail(&dst->list, &stats->vdevs);
1307 	}
1308 
1309 	for (i = 0; i < num_peer_stats; i++) {
1310 		const struct wmi_10x_peer_stats *src;
1311 		struct ath10k_fw_stats_peer *dst;
1312 
1313 		src = data;
1314 		if (data_len < sizeof(*src)) {
1315 			kfree(tb);
1316 			return -EPROTO;
1317 		}
1318 
1319 		data += sizeof(*src);
1320 		data_len -= sizeof(*src);
1321 
1322 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
1323 		if (!dst)
1324 			continue;
1325 
1326 		ath10k_wmi_pull_peer_stats(&src->old, dst);
1327 		dst->peer_rx_rate = __le32_to_cpu(src->peer_rx_rate);
1328 		list_add_tail(&dst->list, &stats->peers);
1329 	}
1330 
1331 	kfree(tb);
1332 	return 0;
1333 }
1334 
1335 static int ath10k_wmi_tlv_op_pull_roam_ev(struct ath10k *ar,
1336 					  struct sk_buff *skb,
1337 					  struct wmi_roam_ev_arg *arg)
1338 {
1339 	const void **tb;
1340 	const struct wmi_tlv_roam_ev *ev;
1341 	int ret;
1342 
1343 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1344 	if (IS_ERR(tb)) {
1345 		ret = PTR_ERR(tb);
1346 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1347 		return ret;
1348 	}
1349 
1350 	ev = tb[WMI_TLV_TAG_STRUCT_ROAM_EVENT];
1351 	if (!ev) {
1352 		kfree(tb);
1353 		return -EPROTO;
1354 	}
1355 
1356 	arg->vdev_id = ev->vdev_id;
1357 	arg->reason = ev->reason;
1358 	arg->rssi = ev->rssi;
1359 
1360 	kfree(tb);
1361 	return 0;
1362 }
1363 
1364 static int
1365 ath10k_wmi_tlv_op_pull_wow_ev(struct ath10k *ar, struct sk_buff *skb,
1366 			      struct wmi_wow_ev_arg *arg)
1367 {
1368 	const void **tb;
1369 	const struct wmi_tlv_wow_event_info *ev;
1370 	int ret;
1371 
1372 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1373 	if (IS_ERR(tb)) {
1374 		ret = PTR_ERR(tb);
1375 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1376 		return ret;
1377 	}
1378 
1379 	ev = tb[WMI_TLV_TAG_STRUCT_WOW_EVENT_INFO];
1380 	if (!ev) {
1381 		kfree(tb);
1382 		return -EPROTO;
1383 	}
1384 
1385 	arg->vdev_id = __le32_to_cpu(ev->vdev_id);
1386 	arg->flag = __le32_to_cpu(ev->flag);
1387 	arg->wake_reason = __le32_to_cpu(ev->wake_reason);
1388 	arg->data_len = __le32_to_cpu(ev->data_len);
1389 
1390 	kfree(tb);
1391 	return 0;
1392 }
1393 
1394 static int ath10k_wmi_tlv_op_pull_echo_ev(struct ath10k *ar,
1395 					  struct sk_buff *skb,
1396 					  struct wmi_echo_ev_arg *arg)
1397 {
1398 	const void **tb;
1399 	const struct wmi_echo_event *ev;
1400 	int ret;
1401 
1402 	tb = ath10k_wmi_tlv_parse_alloc(ar, skb->data, skb->len, GFP_ATOMIC);
1403 	if (IS_ERR(tb)) {
1404 		ret = PTR_ERR(tb);
1405 		ath10k_warn(ar, "failed to parse tlv: %d\n", ret);
1406 		return ret;
1407 	}
1408 
1409 	ev = tb[WMI_TLV_TAG_STRUCT_ECHO_EVENT];
1410 	if (!ev) {
1411 		kfree(tb);
1412 		return -EPROTO;
1413 	}
1414 
1415 	arg->value = ev->value;
1416 
1417 	kfree(tb);
1418 	return 0;
1419 }
1420 
1421 static struct sk_buff *
1422 ath10k_wmi_tlv_op_gen_pdev_suspend(struct ath10k *ar, u32 opt)
1423 {
1424 	struct wmi_tlv_pdev_suspend *cmd;
1425 	struct wmi_tlv *tlv;
1426 	struct sk_buff *skb;
1427 
1428 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1429 	if (!skb)
1430 		return ERR_PTR(-ENOMEM);
1431 
1432 	tlv = (void *)skb->data;
1433 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SUSPEND_CMD);
1434 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1435 	cmd = (void *)tlv->value;
1436 	cmd->opt = __cpu_to_le32(opt);
1437 
1438 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev suspend\n");
1439 	return skb;
1440 }
1441 
1442 static struct sk_buff *
1443 ath10k_wmi_tlv_op_gen_pdev_resume(struct ath10k *ar)
1444 {
1445 	struct wmi_tlv_resume_cmd *cmd;
1446 	struct wmi_tlv *tlv;
1447 	struct sk_buff *skb;
1448 
1449 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1450 	if (!skb)
1451 		return ERR_PTR(-ENOMEM);
1452 
1453 	tlv = (void *)skb->data;
1454 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_RESUME_CMD);
1455 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1456 	cmd = (void *)tlv->value;
1457 	cmd->reserved = __cpu_to_le32(0);
1458 
1459 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev resume\n");
1460 	return skb;
1461 }
1462 
1463 static struct sk_buff *
1464 ath10k_wmi_tlv_op_gen_pdev_set_rd(struct ath10k *ar,
1465 				  u16 rd, u16 rd2g, u16 rd5g,
1466 				  u16 ctl2g, u16 ctl5g,
1467 				  enum wmi_dfs_region dfs_reg)
1468 {
1469 	struct wmi_tlv_pdev_set_rd_cmd *cmd;
1470 	struct wmi_tlv *tlv;
1471 	struct sk_buff *skb;
1472 
1473 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1474 	if (!skb)
1475 		return ERR_PTR(-ENOMEM);
1476 
1477 	tlv = (void *)skb->data;
1478 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_REGDOMAIN_CMD);
1479 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1480 	cmd = (void *)tlv->value;
1481 	cmd->regd = __cpu_to_le32(rd);
1482 	cmd->regd_2ghz = __cpu_to_le32(rd2g);
1483 	cmd->regd_5ghz = __cpu_to_le32(rd5g);
1484 	cmd->conform_limit_2ghz = __cpu_to_le32(ctl2g);
1485 	cmd->conform_limit_5ghz = __cpu_to_le32(ctl5g);
1486 
1487 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set rd\n");
1488 	return skb;
1489 }
1490 
1491 static enum wmi_txbf_conf ath10k_wmi_tlv_txbf_conf_scheme(struct ath10k *ar)
1492 {
1493 	return WMI_TXBF_CONF_AFTER_ASSOC;
1494 }
1495 
1496 static struct sk_buff *
1497 ath10k_wmi_tlv_op_gen_pdev_set_param(struct ath10k *ar, u32 param_id,
1498 				     u32 param_value)
1499 {
1500 	struct wmi_tlv_pdev_set_param_cmd *cmd;
1501 	struct wmi_tlv *tlv;
1502 	struct sk_buff *skb;
1503 
1504 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1505 	if (!skb)
1506 		return ERR_PTR(-ENOMEM);
1507 
1508 	tlv = (void *)skb->data;
1509 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_PARAM_CMD);
1510 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1511 	cmd = (void *)tlv->value;
1512 	cmd->param_id = __cpu_to_le32(param_id);
1513 	cmd->param_value = __cpu_to_le32(param_value);
1514 
1515 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set param\n");
1516 	return skb;
1517 }
1518 
1519 static struct sk_buff *ath10k_wmi_tlv_op_gen_init(struct ath10k *ar)
1520 {
1521 	struct sk_buff *skb;
1522 	struct wmi_tlv *tlv;
1523 	struct wmi_tlv_init_cmd *cmd;
1524 	struct wmi_tlv_resource_config *cfg;
1525 	struct wmi_host_mem_chunks *chunks;
1526 	size_t len, chunks_len;
1527 	void *ptr;
1528 
1529 	chunks_len = ar->wmi.num_mem_chunks * sizeof(struct host_memory_chunk);
1530 	len = (sizeof(*tlv) + sizeof(*cmd)) +
1531 	      (sizeof(*tlv) + sizeof(*cfg)) +
1532 	      (sizeof(*tlv) + chunks_len);
1533 
1534 	skb = ath10k_wmi_alloc_skb(ar, len);
1535 	if (!skb)
1536 		return ERR_PTR(-ENOMEM);
1537 
1538 	ptr = skb->data;
1539 
1540 	tlv = ptr;
1541 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_INIT_CMD);
1542 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1543 	cmd = (void *)tlv->value;
1544 	ptr += sizeof(*tlv);
1545 	ptr += sizeof(*cmd);
1546 
1547 	tlv = ptr;
1548 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_RESOURCE_CONFIG);
1549 	tlv->len = __cpu_to_le16(sizeof(*cfg));
1550 	cfg = (void *)tlv->value;
1551 	ptr += sizeof(*tlv);
1552 	ptr += sizeof(*cfg);
1553 
1554 	tlv = ptr;
1555 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
1556 	tlv->len = __cpu_to_le16(chunks_len);
1557 	chunks = (void *)tlv->value;
1558 
1559 	ptr += sizeof(*tlv);
1560 	ptr += chunks_len;
1561 
1562 	cmd->abi.abi_ver0 = __cpu_to_le32(WMI_TLV_ABI_VER0);
1563 	cmd->abi.abi_ver1 = __cpu_to_le32(WMI_TLV_ABI_VER1);
1564 	cmd->abi.abi_ver_ns0 = __cpu_to_le32(WMI_TLV_ABI_VER_NS0);
1565 	cmd->abi.abi_ver_ns1 = __cpu_to_le32(WMI_TLV_ABI_VER_NS1);
1566 	cmd->abi.abi_ver_ns2 = __cpu_to_le32(WMI_TLV_ABI_VER_NS2);
1567 	cmd->abi.abi_ver_ns3 = __cpu_to_le32(WMI_TLV_ABI_VER_NS3);
1568 	cmd->num_host_mem_chunks = __cpu_to_le32(ar->wmi.num_mem_chunks);
1569 
1570 	cfg->num_vdevs = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1571 
1572 	cfg->num_peers = __cpu_to_le32(ar->hw_params.num_peers);
1573 	cfg->ast_skid_limit = __cpu_to_le32(ar->hw_params.ast_skid_limit);
1574 	cfg->num_wds_entries = __cpu_to_le32(ar->hw_params.num_wds_entries);
1575 
1576 	if (test_bit(WMI_SERVICE_RX_FULL_REORDER, ar->wmi.svc_map)) {
1577 		cfg->num_offload_peers = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1578 		cfg->num_offload_reorder_bufs = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1579 	} else {
1580 		cfg->num_offload_peers = __cpu_to_le32(0);
1581 		cfg->num_offload_reorder_bufs = __cpu_to_le32(0);
1582 	}
1583 
1584 	cfg->num_peer_keys = __cpu_to_le32(2);
1585 	cfg->num_tids = __cpu_to_le32(TARGET_TLV_NUM_TIDS);
1586 	cfg->tx_chain_mask = __cpu_to_le32(0x7);
1587 	cfg->rx_chain_mask = __cpu_to_le32(0x7);
1588 	cfg->rx_timeout_pri[0] = __cpu_to_le32(0x64);
1589 	cfg->rx_timeout_pri[1] = __cpu_to_le32(0x64);
1590 	cfg->rx_timeout_pri[2] = __cpu_to_le32(0x64);
1591 	cfg->rx_timeout_pri[3] = __cpu_to_le32(0x28);
1592 	cfg->rx_decap_mode = __cpu_to_le32(ar->wmi.rx_decap_mode);
1593 	cfg->scan_max_pending_reqs = __cpu_to_le32(4);
1594 	cfg->bmiss_offload_max_vdev = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1595 	cfg->roam_offload_max_vdev = __cpu_to_le32(TARGET_TLV_NUM_VDEVS);
1596 	cfg->roam_offload_max_ap_profiles = __cpu_to_le32(8);
1597 	cfg->num_mcast_groups = __cpu_to_le32(0);
1598 	cfg->num_mcast_table_elems = __cpu_to_le32(0);
1599 	cfg->mcast2ucast_mode = __cpu_to_le32(0);
1600 	cfg->tx_dbg_log_size = __cpu_to_le32(0x400);
1601 	cfg->dma_burst_size = __cpu_to_le32(0);
1602 	cfg->mac_aggr_delim = __cpu_to_le32(0);
1603 	cfg->rx_skip_defrag_timeout_dup_detection_check = __cpu_to_le32(0);
1604 	cfg->vow_config = __cpu_to_le32(0);
1605 	cfg->gtk_offload_max_vdev = __cpu_to_le32(2);
1606 	cfg->num_msdu_desc = __cpu_to_le32(TARGET_TLV_NUM_MSDU_DESC);
1607 	cfg->max_frag_entries = __cpu_to_le32(2);
1608 	cfg->num_tdls_vdevs = __cpu_to_le32(TARGET_TLV_NUM_TDLS_VDEVS);
1609 	cfg->num_tdls_conn_table_entries = __cpu_to_le32(0x20);
1610 	cfg->beacon_tx_offload_max_vdev = __cpu_to_le32(2);
1611 	cfg->num_multicast_filter_entries = __cpu_to_le32(5);
1612 	cfg->num_wow_filters = __cpu_to_le32(ar->wow.max_num_patterns);
1613 	cfg->num_keep_alive_pattern = __cpu_to_le32(6);
1614 	cfg->keep_alive_pattern_size = __cpu_to_le32(0);
1615 	cfg->max_tdls_concurrent_sleep_sta = __cpu_to_le32(1);
1616 	cfg->max_tdls_concurrent_buffer_sta = __cpu_to_le32(1);
1617 	cfg->wmi_send_separate = __cpu_to_le32(0);
1618 	cfg->num_ocb_vdevs = __cpu_to_le32(0);
1619 	cfg->num_ocb_channels = __cpu_to_le32(0);
1620 	cfg->num_ocb_schedules = __cpu_to_le32(0);
1621 	cfg->host_capab = __cpu_to_le32(0);
1622 
1623 	ath10k_wmi_put_host_mem_chunks(ar, chunks);
1624 
1625 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv init\n");
1626 	return skb;
1627 }
1628 
1629 static struct sk_buff *
1630 ath10k_wmi_tlv_op_gen_start_scan(struct ath10k *ar,
1631 				 const struct wmi_start_scan_arg *arg)
1632 {
1633 	struct wmi_tlv_start_scan_cmd *cmd;
1634 	struct wmi_tlv *tlv;
1635 	struct sk_buff *skb;
1636 	size_t len, chan_len, ssid_len, bssid_len, ie_len;
1637 	__le32 *chans;
1638 	struct wmi_ssid *ssids;
1639 	struct wmi_mac_addr *addrs;
1640 	void *ptr;
1641 	int i, ret;
1642 
1643 	ret = ath10k_wmi_start_scan_verify(arg);
1644 	if (ret)
1645 		return ERR_PTR(ret);
1646 
1647 	chan_len = arg->n_channels * sizeof(__le32);
1648 	ssid_len = arg->n_ssids * sizeof(struct wmi_ssid);
1649 	bssid_len = arg->n_bssids * sizeof(struct wmi_mac_addr);
1650 	ie_len = roundup(arg->ie_len, 4);
1651 	len = (sizeof(*tlv) + sizeof(*cmd)) +
1652 	      sizeof(*tlv) + chan_len +
1653 	      sizeof(*tlv) + ssid_len +
1654 	      sizeof(*tlv) + bssid_len +
1655 	      sizeof(*tlv) + ie_len;
1656 
1657 	skb = ath10k_wmi_alloc_skb(ar, len);
1658 	if (!skb)
1659 		return ERR_PTR(-ENOMEM);
1660 
1661 	ptr = (void *)skb->data;
1662 	tlv = ptr;
1663 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_START_SCAN_CMD);
1664 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1665 	cmd = (void *)tlv->value;
1666 
1667 	ath10k_wmi_put_start_scan_common(&cmd->common, arg);
1668 	cmd->burst_duration_ms = __cpu_to_le32(arg->burst_duration_ms);
1669 	cmd->num_channels = __cpu_to_le32(arg->n_channels);
1670 	cmd->num_ssids = __cpu_to_le32(arg->n_ssids);
1671 	cmd->num_bssids = __cpu_to_le32(arg->n_bssids);
1672 	cmd->ie_len = __cpu_to_le32(arg->ie_len);
1673 	cmd->num_probes = __cpu_to_le32(3);
1674 	ether_addr_copy(cmd->mac_addr.addr, arg->mac_addr.addr);
1675 	ether_addr_copy(cmd->mac_mask.addr, arg->mac_mask.addr);
1676 
1677 	/* FIXME: There are some scan flag inconsistencies across firmwares,
1678 	 * e.g. WMI-TLV inverts the logic behind the following flag.
1679 	 */
1680 	cmd->common.scan_ctrl_flags ^= __cpu_to_le32(WMI_SCAN_FILTER_PROBE_REQ);
1681 
1682 	ptr += sizeof(*tlv);
1683 	ptr += sizeof(*cmd);
1684 
1685 	tlv = ptr;
1686 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
1687 	tlv->len = __cpu_to_le16(chan_len);
1688 	chans = (void *)tlv->value;
1689 	for (i = 0; i < arg->n_channels; i++)
1690 		chans[i] = __cpu_to_le32(arg->channels[i]);
1691 
1692 	ptr += sizeof(*tlv);
1693 	ptr += chan_len;
1694 
1695 	tlv = ptr;
1696 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_FIXED_STRUCT);
1697 	tlv->len = __cpu_to_le16(ssid_len);
1698 	ssids = (void *)tlv->value;
1699 	for (i = 0; i < arg->n_ssids; i++) {
1700 		ssids[i].ssid_len = __cpu_to_le32(arg->ssids[i].len);
1701 		memcpy(ssids[i].ssid, arg->ssids[i].ssid, arg->ssids[i].len);
1702 	}
1703 
1704 	ptr += sizeof(*tlv);
1705 	ptr += ssid_len;
1706 
1707 	tlv = ptr;
1708 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_FIXED_STRUCT);
1709 	tlv->len = __cpu_to_le16(bssid_len);
1710 	addrs = (void *)tlv->value;
1711 	for (i = 0; i < arg->n_bssids; i++)
1712 		ether_addr_copy(addrs[i].addr, arg->bssids[i].bssid);
1713 
1714 	ptr += sizeof(*tlv);
1715 	ptr += bssid_len;
1716 
1717 	tlv = ptr;
1718 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
1719 	tlv->len = __cpu_to_le16(ie_len);
1720 	memcpy(tlv->value, arg->ie, arg->ie_len);
1721 
1722 	ptr += sizeof(*tlv);
1723 	ptr += ie_len;
1724 
1725 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv start scan\n");
1726 	return skb;
1727 }
1728 
1729 static struct sk_buff *
1730 ath10k_wmi_tlv_op_gen_stop_scan(struct ath10k *ar,
1731 				const struct wmi_stop_scan_arg *arg)
1732 {
1733 	struct wmi_stop_scan_cmd *cmd;
1734 	struct wmi_tlv *tlv;
1735 	struct sk_buff *skb;
1736 	u32 scan_id;
1737 	u32 req_id;
1738 
1739 	if (arg->req_id > 0xFFF)
1740 		return ERR_PTR(-EINVAL);
1741 	if (arg->req_type == WMI_SCAN_STOP_ONE && arg->u.scan_id > 0xFFF)
1742 		return ERR_PTR(-EINVAL);
1743 
1744 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1745 	if (!skb)
1746 		return ERR_PTR(-ENOMEM);
1747 
1748 	scan_id = arg->u.scan_id;
1749 	scan_id |= WMI_HOST_SCAN_REQ_ID_PREFIX;
1750 
1751 	req_id = arg->req_id;
1752 	req_id |= WMI_HOST_SCAN_REQUESTOR_ID_PREFIX;
1753 
1754 	tlv = (void *)skb->data;
1755 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STOP_SCAN_CMD);
1756 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1757 	cmd = (void *)tlv->value;
1758 	cmd->req_type = __cpu_to_le32(arg->req_type);
1759 	cmd->vdev_id = __cpu_to_le32(arg->u.vdev_id);
1760 	cmd->scan_id = __cpu_to_le32(scan_id);
1761 	cmd->scan_req_id = __cpu_to_le32(req_id);
1762 
1763 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv stop scan\n");
1764 	return skb;
1765 }
1766 
1767 static struct sk_buff *
1768 ath10k_wmi_tlv_op_gen_vdev_create(struct ath10k *ar,
1769 				  u32 vdev_id,
1770 				  enum wmi_vdev_type vdev_type,
1771 				  enum wmi_vdev_subtype vdev_subtype,
1772 				  const u8 mac_addr[ETH_ALEN])
1773 {
1774 	struct wmi_vdev_create_cmd *cmd;
1775 	struct wmi_tlv *tlv;
1776 	struct sk_buff *skb;
1777 
1778 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1779 	if (!skb)
1780 		return ERR_PTR(-ENOMEM);
1781 
1782 	tlv = (void *)skb->data;
1783 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_CREATE_CMD);
1784 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1785 	cmd = (void *)tlv->value;
1786 	cmd->vdev_id = __cpu_to_le32(vdev_id);
1787 	cmd->vdev_type = __cpu_to_le32(vdev_type);
1788 	cmd->vdev_subtype = __cpu_to_le32(vdev_subtype);
1789 	ether_addr_copy(cmd->vdev_macaddr.addr, mac_addr);
1790 
1791 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev create\n");
1792 	return skb;
1793 }
1794 
1795 static struct sk_buff *
1796 ath10k_wmi_tlv_op_gen_vdev_delete(struct ath10k *ar, u32 vdev_id)
1797 {
1798 	struct wmi_vdev_delete_cmd *cmd;
1799 	struct wmi_tlv *tlv;
1800 	struct sk_buff *skb;
1801 
1802 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1803 	if (!skb)
1804 		return ERR_PTR(-ENOMEM);
1805 
1806 	tlv = (void *)skb->data;
1807 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_DELETE_CMD);
1808 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1809 	cmd = (void *)tlv->value;
1810 	cmd->vdev_id = __cpu_to_le32(vdev_id);
1811 
1812 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev delete\n");
1813 	return skb;
1814 }
1815 
1816 static struct sk_buff *
1817 ath10k_wmi_tlv_op_gen_vdev_start(struct ath10k *ar,
1818 				 const struct wmi_vdev_start_request_arg *arg,
1819 				 bool restart)
1820 {
1821 	struct wmi_tlv_vdev_start_cmd *cmd;
1822 	struct wmi_channel *ch;
1823 	struct wmi_tlv *tlv;
1824 	struct sk_buff *skb;
1825 	size_t len;
1826 	void *ptr;
1827 	u32 flags = 0;
1828 
1829 	if (WARN_ON(arg->hidden_ssid && !arg->ssid))
1830 		return ERR_PTR(-EINVAL);
1831 	if (WARN_ON(arg->ssid_len > sizeof(cmd->ssid.ssid)))
1832 		return ERR_PTR(-EINVAL);
1833 
1834 	len = (sizeof(*tlv) + sizeof(*cmd)) +
1835 	      (sizeof(*tlv) + sizeof(*ch)) +
1836 	      (sizeof(*tlv) + 0);
1837 	skb = ath10k_wmi_alloc_skb(ar, len);
1838 	if (!skb)
1839 		return ERR_PTR(-ENOMEM);
1840 
1841 	if (arg->hidden_ssid)
1842 		flags |= WMI_VDEV_START_HIDDEN_SSID;
1843 	if (arg->pmf_enabled)
1844 		flags |= WMI_VDEV_START_PMF_ENABLED;
1845 
1846 	ptr = (void *)skb->data;
1847 
1848 	tlv = ptr;
1849 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_START_REQUEST_CMD);
1850 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1851 	cmd = (void *)tlv->value;
1852 	cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
1853 	cmd->bcn_intval = __cpu_to_le32(arg->bcn_intval);
1854 	cmd->dtim_period = __cpu_to_le32(arg->dtim_period);
1855 	cmd->flags = __cpu_to_le32(flags);
1856 	cmd->bcn_tx_rate = __cpu_to_le32(arg->bcn_tx_rate);
1857 	cmd->bcn_tx_power = __cpu_to_le32(arg->bcn_tx_power);
1858 	cmd->disable_hw_ack = __cpu_to_le32(arg->disable_hw_ack);
1859 
1860 	if (arg->ssid) {
1861 		cmd->ssid.ssid_len = __cpu_to_le32(arg->ssid_len);
1862 		memcpy(cmd->ssid.ssid, arg->ssid, arg->ssid_len);
1863 	}
1864 
1865 	ptr += sizeof(*tlv);
1866 	ptr += sizeof(*cmd);
1867 
1868 	tlv = ptr;
1869 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
1870 	tlv->len = __cpu_to_le16(sizeof(*ch));
1871 	ch = (void *)tlv->value;
1872 	ath10k_wmi_put_wmi_channel(ch, &arg->channel);
1873 
1874 	ptr += sizeof(*tlv);
1875 	ptr += sizeof(*ch);
1876 
1877 	tlv = ptr;
1878 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
1879 	tlv->len = 0;
1880 
1881 	/* Note: This is a nested TLV containing:
1882 	 * [wmi_tlv][wmi_p2p_noa_descriptor][wmi_tlv]..
1883 	 */
1884 
1885 	ptr += sizeof(*tlv);
1886 	ptr += 0;
1887 
1888 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev start\n");
1889 	return skb;
1890 }
1891 
1892 static struct sk_buff *
1893 ath10k_wmi_tlv_op_gen_vdev_stop(struct ath10k *ar, u32 vdev_id)
1894 {
1895 	struct wmi_vdev_stop_cmd *cmd;
1896 	struct wmi_tlv *tlv;
1897 	struct sk_buff *skb;
1898 
1899 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1900 	if (!skb)
1901 		return ERR_PTR(-ENOMEM);
1902 
1903 	tlv = (void *)skb->data;
1904 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_STOP_CMD);
1905 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1906 	cmd = (void *)tlv->value;
1907 	cmd->vdev_id = __cpu_to_le32(vdev_id);
1908 
1909 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev stop\n");
1910 	return skb;
1911 }
1912 
1913 static struct sk_buff *
1914 ath10k_wmi_tlv_op_gen_vdev_up(struct ath10k *ar, u32 vdev_id, u32 aid,
1915 			      const u8 *bssid)
1916 
1917 {
1918 	struct wmi_vdev_up_cmd *cmd;
1919 	struct wmi_tlv *tlv;
1920 	struct sk_buff *skb;
1921 
1922 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1923 	if (!skb)
1924 		return ERR_PTR(-ENOMEM);
1925 
1926 	tlv = (void *)skb->data;
1927 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_UP_CMD);
1928 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1929 	cmd = (void *)tlv->value;
1930 	cmd->vdev_id = __cpu_to_le32(vdev_id);
1931 	cmd->vdev_assoc_id = __cpu_to_le32(aid);
1932 	ether_addr_copy(cmd->vdev_bssid.addr, bssid);
1933 
1934 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev up\n");
1935 	return skb;
1936 }
1937 
1938 static struct sk_buff *
1939 ath10k_wmi_tlv_op_gen_vdev_down(struct ath10k *ar, u32 vdev_id)
1940 {
1941 	struct wmi_vdev_down_cmd *cmd;
1942 	struct wmi_tlv *tlv;
1943 	struct sk_buff *skb;
1944 
1945 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1946 	if (!skb)
1947 		return ERR_PTR(-ENOMEM);
1948 
1949 	tlv = (void *)skb->data;
1950 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_DOWN_CMD);
1951 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1952 	cmd = (void *)tlv->value;
1953 	cmd->vdev_id = __cpu_to_le32(vdev_id);
1954 
1955 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev down\n");
1956 	return skb;
1957 }
1958 
1959 static struct sk_buff *
1960 ath10k_wmi_tlv_op_gen_vdev_set_param(struct ath10k *ar, u32 vdev_id,
1961 				     u32 param_id, u32 param_value)
1962 {
1963 	struct wmi_vdev_set_param_cmd *cmd;
1964 	struct wmi_tlv *tlv;
1965 	struct sk_buff *skb;
1966 
1967 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
1968 	if (!skb)
1969 		return ERR_PTR(-ENOMEM);
1970 
1971 	tlv = (void *)skb->data;
1972 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SET_PARAM_CMD);
1973 	tlv->len = __cpu_to_le16(sizeof(*cmd));
1974 	cmd = (void *)tlv->value;
1975 	cmd->vdev_id = __cpu_to_le32(vdev_id);
1976 	cmd->param_id = __cpu_to_le32(param_id);
1977 	cmd->param_value = __cpu_to_le32(param_value);
1978 
1979 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev set param\n");
1980 	return skb;
1981 }
1982 
1983 static struct sk_buff *
1984 ath10k_wmi_tlv_op_gen_vdev_install_key(struct ath10k *ar,
1985 				       const struct wmi_vdev_install_key_arg *arg)
1986 {
1987 	struct wmi_vdev_install_key_cmd *cmd;
1988 	struct wmi_tlv *tlv;
1989 	struct sk_buff *skb;
1990 	size_t len;
1991 	void *ptr;
1992 
1993 	if (arg->key_cipher == WMI_CIPHER_NONE && arg->key_data != NULL)
1994 		return ERR_PTR(-EINVAL);
1995 	if (arg->key_cipher != WMI_CIPHER_NONE && arg->key_data == NULL)
1996 		return ERR_PTR(-EINVAL);
1997 
1998 	len = sizeof(*tlv) + sizeof(*cmd) +
1999 	      sizeof(*tlv) + roundup(arg->key_len, sizeof(__le32));
2000 	skb = ath10k_wmi_alloc_skb(ar, len);
2001 	if (!skb)
2002 		return ERR_PTR(-ENOMEM);
2003 
2004 	ptr = (void *)skb->data;
2005 	tlv = ptr;
2006 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_INSTALL_KEY_CMD);
2007 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2008 	cmd = (void *)tlv->value;
2009 	cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2010 	cmd->key_idx = __cpu_to_le32(arg->key_idx);
2011 	cmd->key_flags = __cpu_to_le32(arg->key_flags);
2012 	cmd->key_cipher = __cpu_to_le32(arg->key_cipher);
2013 	cmd->key_len = __cpu_to_le32(arg->key_len);
2014 	cmd->key_txmic_len = __cpu_to_le32(arg->key_txmic_len);
2015 	cmd->key_rxmic_len = __cpu_to_le32(arg->key_rxmic_len);
2016 
2017 	if (arg->macaddr)
2018 		ether_addr_copy(cmd->peer_macaddr.addr, arg->macaddr);
2019 
2020 	ptr += sizeof(*tlv);
2021 	ptr += sizeof(*cmd);
2022 
2023 	tlv = ptr;
2024 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2025 	tlv->len = __cpu_to_le16(roundup(arg->key_len, sizeof(__le32)));
2026 	if (arg->key_data)
2027 		memcpy(tlv->value, arg->key_data, arg->key_len);
2028 
2029 	ptr += sizeof(*tlv);
2030 	ptr += roundup(arg->key_len, sizeof(__le32));
2031 
2032 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev install key\n");
2033 	return skb;
2034 }
2035 
2036 static void *ath10k_wmi_tlv_put_uapsd_ac(struct ath10k *ar, void *ptr,
2037 					 const struct wmi_sta_uapsd_auto_trig_arg *arg)
2038 {
2039 	struct wmi_sta_uapsd_auto_trig_param *ac;
2040 	struct wmi_tlv *tlv;
2041 
2042 	tlv = ptr;
2043 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_UAPSD_AUTO_TRIG_PARAM);
2044 	tlv->len = __cpu_to_le16(sizeof(*ac));
2045 	ac = (void *)tlv->value;
2046 
2047 	ac->wmm_ac = __cpu_to_le32(arg->wmm_ac);
2048 	ac->user_priority = __cpu_to_le32(arg->user_priority);
2049 	ac->service_interval = __cpu_to_le32(arg->service_interval);
2050 	ac->suspend_interval = __cpu_to_le32(arg->suspend_interval);
2051 	ac->delay_interval = __cpu_to_le32(arg->delay_interval);
2052 
2053 	ath10k_dbg(ar, ATH10K_DBG_WMI,
2054 		   "wmi tlv vdev sta uapsd auto trigger ac %d prio %d svc int %d susp int %d delay int %d\n",
2055 		   ac->wmm_ac, ac->user_priority, ac->service_interval,
2056 		   ac->suspend_interval, ac->delay_interval);
2057 
2058 	return ptr + sizeof(*tlv) + sizeof(*ac);
2059 }
2060 
2061 static struct sk_buff *
2062 ath10k_wmi_tlv_op_gen_vdev_sta_uapsd(struct ath10k *ar, u32 vdev_id,
2063 				     const u8 peer_addr[ETH_ALEN],
2064 				     const struct wmi_sta_uapsd_auto_trig_arg *args,
2065 				     u32 num_ac)
2066 {
2067 	struct wmi_sta_uapsd_auto_trig_cmd_fixed_param *cmd;
2068 	struct wmi_sta_uapsd_auto_trig_param *ac;
2069 	struct wmi_tlv *tlv;
2070 	struct sk_buff *skb;
2071 	size_t len;
2072 	size_t ac_tlv_len;
2073 	void *ptr;
2074 	int i;
2075 
2076 	ac_tlv_len = num_ac * (sizeof(*tlv) + sizeof(*ac));
2077 	len = sizeof(*tlv) + sizeof(*cmd) +
2078 	      sizeof(*tlv) + ac_tlv_len;
2079 	skb = ath10k_wmi_alloc_skb(ar, len);
2080 	if (!skb)
2081 		return ERR_PTR(-ENOMEM);
2082 
2083 	ptr = (void *)skb->data;
2084 	tlv = ptr;
2085 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_UAPSD_AUTO_TRIG_CMD);
2086 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2087 	cmd = (void *)tlv->value;
2088 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2089 	cmd->num_ac = __cpu_to_le32(num_ac);
2090 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2091 
2092 	ptr += sizeof(*tlv);
2093 	ptr += sizeof(*cmd);
2094 
2095 	tlv = ptr;
2096 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
2097 	tlv->len = __cpu_to_le16(ac_tlv_len);
2098 	ac = (void *)tlv->value;
2099 
2100 	ptr += sizeof(*tlv);
2101 	for (i = 0; i < num_ac; i++)
2102 		ptr = ath10k_wmi_tlv_put_uapsd_ac(ar, ptr, &args[i]);
2103 
2104 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev sta uapsd auto trigger\n");
2105 	return skb;
2106 }
2107 
2108 static void *ath10k_wmi_tlv_put_wmm(void *ptr,
2109 				    const struct wmi_wmm_params_arg *arg)
2110 {
2111 	struct wmi_wmm_params *wmm;
2112 	struct wmi_tlv *tlv;
2113 
2114 	tlv = ptr;
2115 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WMM_PARAMS);
2116 	tlv->len = __cpu_to_le16(sizeof(*wmm));
2117 	wmm = (void *)tlv->value;
2118 	ath10k_wmi_set_wmm_param(wmm, arg);
2119 
2120 	return ptr + sizeof(*tlv) + sizeof(*wmm);
2121 }
2122 
2123 static struct sk_buff *
2124 ath10k_wmi_tlv_op_gen_vdev_wmm_conf(struct ath10k *ar, u32 vdev_id,
2125 				    const struct wmi_wmm_params_all_arg *arg)
2126 {
2127 	struct wmi_tlv_vdev_set_wmm_cmd *cmd;
2128 	struct wmi_tlv *tlv;
2129 	struct sk_buff *skb;
2130 	size_t len;
2131 	void *ptr;
2132 
2133 	len = sizeof(*tlv) + sizeof(*cmd);
2134 	skb = ath10k_wmi_alloc_skb(ar, len);
2135 	if (!skb)
2136 		return ERR_PTR(-ENOMEM);
2137 
2138 	ptr = (void *)skb->data;
2139 	tlv = ptr;
2140 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SET_WMM_PARAMS_CMD);
2141 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2142 	cmd = (void *)tlv->value;
2143 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2144 
2145 	ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[0].params, &arg->ac_be);
2146 	ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[1].params, &arg->ac_bk);
2147 	ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[2].params, &arg->ac_vi);
2148 	ath10k_wmi_set_wmm_param(&cmd->vdev_wmm_params[3].params, &arg->ac_vo);
2149 
2150 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv vdev wmm conf\n");
2151 	return skb;
2152 }
2153 
2154 static struct sk_buff *
2155 ath10k_wmi_tlv_op_gen_sta_keepalive(struct ath10k *ar,
2156 				    const struct wmi_sta_keepalive_arg *arg)
2157 {
2158 	struct wmi_tlv_sta_keepalive_cmd *cmd;
2159 	struct wmi_sta_keepalive_arp_resp *arp;
2160 	struct sk_buff *skb;
2161 	struct wmi_tlv *tlv;
2162 	void *ptr;
2163 	size_t len;
2164 
2165 	len = sizeof(*tlv) + sizeof(*cmd) +
2166 	      sizeof(*tlv) + sizeof(*arp);
2167 	skb = ath10k_wmi_alloc_skb(ar, len);
2168 	if (!skb)
2169 		return ERR_PTR(-ENOMEM);
2170 
2171 	ptr = (void *)skb->data;
2172 	tlv = ptr;
2173 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_KEEPALIVE_CMD);
2174 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2175 	cmd = (void *)tlv->value;
2176 	cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2177 	cmd->enabled = __cpu_to_le32(arg->enabled);
2178 	cmd->method = __cpu_to_le32(arg->method);
2179 	cmd->interval = __cpu_to_le32(arg->interval);
2180 
2181 	ptr += sizeof(*tlv);
2182 	ptr += sizeof(*cmd);
2183 
2184 	tlv = ptr;
2185 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_KEEPALVE_ARP_RESPONSE);
2186 	tlv->len = __cpu_to_le16(sizeof(*arp));
2187 	arp = (void *)tlv->value;
2188 
2189 	arp->src_ip4_addr = arg->src_ip4_addr;
2190 	arp->dest_ip4_addr = arg->dest_ip4_addr;
2191 	ether_addr_copy(arp->dest_mac_addr.addr, arg->dest_mac_addr);
2192 
2193 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv sta keepalive vdev %d enabled %d method %d interval %d\n",
2194 		   arg->vdev_id, arg->enabled, arg->method, arg->interval);
2195 	return skb;
2196 }
2197 
2198 static struct sk_buff *
2199 ath10k_wmi_tlv_op_gen_peer_create(struct ath10k *ar, u32 vdev_id,
2200 				  const u8 peer_addr[ETH_ALEN],
2201 				  enum wmi_peer_type peer_type)
2202 {
2203 	struct wmi_tlv_peer_create_cmd *cmd;
2204 	struct wmi_tlv *tlv;
2205 	struct sk_buff *skb;
2206 
2207 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2208 	if (!skb)
2209 		return ERR_PTR(-ENOMEM);
2210 
2211 	tlv = (void *)skb->data;
2212 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_CREATE_CMD);
2213 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2214 	cmd = (void *)tlv->value;
2215 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2216 	cmd->peer_type = __cpu_to_le32(peer_type);
2217 	ether_addr_copy(cmd->peer_addr.addr, peer_addr);
2218 
2219 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer create\n");
2220 	return skb;
2221 }
2222 
2223 static struct sk_buff *
2224 ath10k_wmi_tlv_op_gen_peer_delete(struct ath10k *ar, u32 vdev_id,
2225 				  const u8 peer_addr[ETH_ALEN])
2226 {
2227 	struct wmi_peer_delete_cmd *cmd;
2228 	struct wmi_tlv *tlv;
2229 	struct sk_buff *skb;
2230 
2231 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2232 	if (!skb)
2233 		return ERR_PTR(-ENOMEM);
2234 
2235 	tlv = (void *)skb->data;
2236 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_DELETE_CMD);
2237 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2238 	cmd = (void *)tlv->value;
2239 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2240 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2241 
2242 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer delete\n");
2243 	return skb;
2244 }
2245 
2246 static struct sk_buff *
2247 ath10k_wmi_tlv_op_gen_peer_flush(struct ath10k *ar, u32 vdev_id,
2248 				 const u8 peer_addr[ETH_ALEN], u32 tid_bitmap)
2249 {
2250 	struct wmi_peer_flush_tids_cmd *cmd;
2251 	struct wmi_tlv *tlv;
2252 	struct sk_buff *skb;
2253 
2254 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2255 	if (!skb)
2256 		return ERR_PTR(-ENOMEM);
2257 
2258 	tlv = (void *)skb->data;
2259 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_FLUSH_TIDS_CMD);
2260 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2261 	cmd = (void *)tlv->value;
2262 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2263 	cmd->peer_tid_bitmap = __cpu_to_le32(tid_bitmap);
2264 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2265 
2266 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer flush\n");
2267 	return skb;
2268 }
2269 
2270 static struct sk_buff *
2271 ath10k_wmi_tlv_op_gen_peer_set_param(struct ath10k *ar, u32 vdev_id,
2272 				     const u8 *peer_addr,
2273 				     enum wmi_peer_param param_id,
2274 				     u32 param_value)
2275 {
2276 	struct wmi_peer_set_param_cmd *cmd;
2277 	struct wmi_tlv *tlv;
2278 	struct sk_buff *skb;
2279 
2280 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2281 	if (!skb)
2282 		return ERR_PTR(-ENOMEM);
2283 
2284 	tlv = (void *)skb->data;
2285 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_SET_PARAM_CMD);
2286 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2287 	cmd = (void *)tlv->value;
2288 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2289 	cmd->param_id = __cpu_to_le32(param_id);
2290 	cmd->param_value = __cpu_to_le32(param_value);
2291 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
2292 
2293 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer set param\n");
2294 	return skb;
2295 }
2296 
2297 static struct sk_buff *
2298 ath10k_wmi_tlv_op_gen_peer_assoc(struct ath10k *ar,
2299 				 const struct wmi_peer_assoc_complete_arg *arg)
2300 {
2301 	struct wmi_tlv_peer_assoc_cmd *cmd;
2302 	struct wmi_vht_rate_set *vht_rate;
2303 	struct wmi_tlv *tlv;
2304 	struct sk_buff *skb;
2305 	size_t len, legacy_rate_len, ht_rate_len;
2306 	void *ptr;
2307 
2308 	if (arg->peer_mpdu_density > 16)
2309 		return ERR_PTR(-EINVAL);
2310 	if (arg->peer_legacy_rates.num_rates > MAX_SUPPORTED_RATES)
2311 		return ERR_PTR(-EINVAL);
2312 	if (arg->peer_ht_rates.num_rates > MAX_SUPPORTED_RATES)
2313 		return ERR_PTR(-EINVAL);
2314 
2315 	legacy_rate_len = roundup(arg->peer_legacy_rates.num_rates,
2316 				  sizeof(__le32));
2317 	ht_rate_len = roundup(arg->peer_ht_rates.num_rates, sizeof(__le32));
2318 	len = (sizeof(*tlv) + sizeof(*cmd)) +
2319 	      (sizeof(*tlv) + legacy_rate_len) +
2320 	      (sizeof(*tlv) + ht_rate_len) +
2321 	      (sizeof(*tlv) + sizeof(*vht_rate));
2322 	skb = ath10k_wmi_alloc_skb(ar, len);
2323 	if (!skb)
2324 		return ERR_PTR(-ENOMEM);
2325 
2326 	ptr = (void *)skb->data;
2327 	tlv = ptr;
2328 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PEER_ASSOC_COMPLETE_CMD);
2329 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2330 	cmd = (void *)tlv->value;
2331 
2332 	cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
2333 	cmd->new_assoc = __cpu_to_le32(arg->peer_reassoc ? 0 : 1);
2334 	cmd->assoc_id = __cpu_to_le32(arg->peer_aid);
2335 	cmd->flags = __cpu_to_le32(arg->peer_flags);
2336 	cmd->caps = __cpu_to_le32(arg->peer_caps);
2337 	cmd->listen_intval = __cpu_to_le32(arg->peer_listen_intval);
2338 	cmd->ht_caps = __cpu_to_le32(arg->peer_ht_caps);
2339 	cmd->max_mpdu = __cpu_to_le32(arg->peer_max_mpdu);
2340 	cmd->mpdu_density = __cpu_to_le32(arg->peer_mpdu_density);
2341 	cmd->rate_caps = __cpu_to_le32(arg->peer_rate_caps);
2342 	cmd->nss = __cpu_to_le32(arg->peer_num_spatial_streams);
2343 	cmd->vht_caps = __cpu_to_le32(arg->peer_vht_caps);
2344 	cmd->phy_mode = __cpu_to_le32(arg->peer_phymode);
2345 	cmd->num_legacy_rates = __cpu_to_le32(arg->peer_legacy_rates.num_rates);
2346 	cmd->num_ht_rates = __cpu_to_le32(arg->peer_ht_rates.num_rates);
2347 	ether_addr_copy(cmd->mac_addr.addr, arg->addr);
2348 
2349 	ptr += sizeof(*tlv);
2350 	ptr += sizeof(*cmd);
2351 
2352 	tlv = ptr;
2353 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2354 	tlv->len = __cpu_to_le16(legacy_rate_len);
2355 	memcpy(tlv->value, arg->peer_legacy_rates.rates,
2356 	       arg->peer_legacy_rates.num_rates);
2357 
2358 	ptr += sizeof(*tlv);
2359 	ptr += legacy_rate_len;
2360 
2361 	tlv = ptr;
2362 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2363 	tlv->len = __cpu_to_le16(ht_rate_len);
2364 	memcpy(tlv->value, arg->peer_ht_rates.rates,
2365 	       arg->peer_ht_rates.num_rates);
2366 
2367 	ptr += sizeof(*tlv);
2368 	ptr += ht_rate_len;
2369 
2370 	tlv = ptr;
2371 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VHT_RATE_SET);
2372 	tlv->len = __cpu_to_le16(sizeof(*vht_rate));
2373 	vht_rate = (void *)tlv->value;
2374 
2375 	vht_rate->rx_max_rate = __cpu_to_le32(arg->peer_vht_rates.rx_max_rate);
2376 	vht_rate->rx_mcs_set = __cpu_to_le32(arg->peer_vht_rates.rx_mcs_set);
2377 	vht_rate->tx_max_rate = __cpu_to_le32(arg->peer_vht_rates.tx_max_rate);
2378 	vht_rate->tx_mcs_set = __cpu_to_le32(arg->peer_vht_rates.tx_mcs_set);
2379 
2380 	ptr += sizeof(*tlv);
2381 	ptr += sizeof(*vht_rate);
2382 
2383 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv peer assoc\n");
2384 	return skb;
2385 }
2386 
2387 static struct sk_buff *
2388 ath10k_wmi_tlv_op_gen_set_psmode(struct ath10k *ar, u32 vdev_id,
2389 				 enum wmi_sta_ps_mode psmode)
2390 {
2391 	struct wmi_sta_powersave_mode_cmd *cmd;
2392 	struct wmi_tlv *tlv;
2393 	struct sk_buff *skb;
2394 
2395 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2396 	if (!skb)
2397 		return ERR_PTR(-ENOMEM);
2398 
2399 	tlv = (void *)skb->data;
2400 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_POWERSAVE_MODE_CMD);
2401 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2402 	cmd = (void *)tlv->value;
2403 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2404 	cmd->sta_ps_mode = __cpu_to_le32(psmode);
2405 
2406 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv set psmode\n");
2407 	return skb;
2408 }
2409 
2410 static struct sk_buff *
2411 ath10k_wmi_tlv_op_gen_set_sta_ps(struct ath10k *ar, u32 vdev_id,
2412 				 enum wmi_sta_powersave_param param_id,
2413 				 u32 param_value)
2414 {
2415 	struct wmi_sta_powersave_param_cmd *cmd;
2416 	struct wmi_tlv *tlv;
2417 	struct sk_buff *skb;
2418 
2419 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2420 	if (!skb)
2421 		return ERR_PTR(-ENOMEM);
2422 
2423 	tlv = (void *)skb->data;
2424 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_STA_POWERSAVE_PARAM_CMD);
2425 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2426 	cmd = (void *)tlv->value;
2427 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2428 	cmd->param_id = __cpu_to_le32(param_id);
2429 	cmd->param_value = __cpu_to_le32(param_value);
2430 
2431 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv set sta ps\n");
2432 	return skb;
2433 }
2434 
2435 static struct sk_buff *
2436 ath10k_wmi_tlv_op_gen_set_ap_ps(struct ath10k *ar, u32 vdev_id, const u8 *mac,
2437 				enum wmi_ap_ps_peer_param param_id, u32 value)
2438 {
2439 	struct wmi_ap_ps_peer_cmd *cmd;
2440 	struct wmi_tlv *tlv;
2441 	struct sk_buff *skb;
2442 
2443 	if (!mac)
2444 		return ERR_PTR(-EINVAL);
2445 
2446 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2447 	if (!skb)
2448 		return ERR_PTR(-ENOMEM);
2449 
2450 	tlv = (void *)skb->data;
2451 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_AP_PS_PEER_CMD);
2452 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2453 	cmd = (void *)tlv->value;
2454 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2455 	cmd->param_id = __cpu_to_le32(param_id);
2456 	cmd->param_value = __cpu_to_le32(value);
2457 	ether_addr_copy(cmd->peer_macaddr.addr, mac);
2458 
2459 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv ap ps param\n");
2460 	return skb;
2461 }
2462 
2463 static struct sk_buff *
2464 ath10k_wmi_tlv_op_gen_scan_chan_list(struct ath10k *ar,
2465 				     const struct wmi_scan_chan_list_arg *arg)
2466 {
2467 	struct wmi_tlv_scan_chan_list_cmd *cmd;
2468 	struct wmi_channel *ci;
2469 	struct wmi_channel_arg *ch;
2470 	struct wmi_tlv *tlv;
2471 	struct sk_buff *skb;
2472 	size_t chans_len, len;
2473 	int i;
2474 	void *ptr, *chans;
2475 
2476 	chans_len = arg->n_channels * (sizeof(*tlv) + sizeof(*ci));
2477 	len = (sizeof(*tlv) + sizeof(*cmd)) +
2478 	      (sizeof(*tlv) + chans_len);
2479 
2480 	skb = ath10k_wmi_alloc_skb(ar, len);
2481 	if (!skb)
2482 		return ERR_PTR(-ENOMEM);
2483 
2484 	ptr = (void *)skb->data;
2485 	tlv = ptr;
2486 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_SCAN_CHAN_LIST_CMD);
2487 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2488 	cmd = (void *)tlv->value;
2489 	cmd->num_scan_chans = __cpu_to_le32(arg->n_channels);
2490 
2491 	ptr += sizeof(*tlv);
2492 	ptr += sizeof(*cmd);
2493 
2494 	tlv = ptr;
2495 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
2496 	tlv->len = __cpu_to_le16(chans_len);
2497 	chans = (void *)tlv->value;
2498 
2499 	for (i = 0; i < arg->n_channels; i++) {
2500 		ch = &arg->channels[i];
2501 
2502 		tlv = chans;
2503 		tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
2504 		tlv->len = __cpu_to_le16(sizeof(*ci));
2505 		ci = (void *)tlv->value;
2506 
2507 		ath10k_wmi_put_wmi_channel(ci, ch);
2508 
2509 		chans += sizeof(*tlv);
2510 		chans += sizeof(*ci);
2511 	}
2512 
2513 	ptr += sizeof(*tlv);
2514 	ptr += chans_len;
2515 
2516 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv scan chan list\n");
2517 	return skb;
2518 }
2519 
2520 static struct sk_buff *
2521 ath10k_wmi_tlv_op_gen_scan_prob_req_oui(struct ath10k *ar, u32 prob_req_oui)
2522 {
2523 	struct wmi_scan_prob_req_oui_cmd *cmd;
2524 	struct wmi_tlv *tlv;
2525 	struct sk_buff *skb;
2526 
2527 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2528 	if (!skb)
2529 		return ERR_PTR(-ENOMEM);
2530 
2531 	tlv = (void *)skb->data;
2532 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_SCAN_PROB_REQ_OUI_CMD);
2533 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2534 	cmd = (void *)tlv->value;
2535 	cmd->prob_req_oui = __cpu_to_le32(prob_req_oui);
2536 
2537 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv scan prob req oui\n");
2538 	return skb;
2539 }
2540 
2541 static struct sk_buff *
2542 ath10k_wmi_tlv_op_gen_beacon_dma(struct ath10k *ar, u32 vdev_id,
2543 				 const void *bcn, size_t bcn_len,
2544 				 u32 bcn_paddr, bool dtim_zero,
2545 				 bool deliver_cab)
2546 
2547 {
2548 	struct wmi_bcn_tx_ref_cmd *cmd;
2549 	struct wmi_tlv *tlv;
2550 	struct sk_buff *skb;
2551 	struct ieee80211_hdr *hdr;
2552 	u16 fc;
2553 
2554 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2555 	if (!skb)
2556 		return ERR_PTR(-ENOMEM);
2557 
2558 	hdr = (struct ieee80211_hdr *)bcn;
2559 	fc = le16_to_cpu(hdr->frame_control);
2560 
2561 	tlv = (void *)skb->data;
2562 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_SEND_FROM_HOST_CMD);
2563 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2564 	cmd = (void *)tlv->value;
2565 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2566 	cmd->data_len = __cpu_to_le32(bcn_len);
2567 	cmd->data_ptr = __cpu_to_le32(bcn_paddr);
2568 	cmd->msdu_id = 0;
2569 	cmd->frame_control = __cpu_to_le32(fc);
2570 	cmd->flags = 0;
2571 
2572 	if (dtim_zero)
2573 		cmd->flags |= __cpu_to_le32(WMI_BCN_TX_REF_FLAG_DTIM_ZERO);
2574 
2575 	if (deliver_cab)
2576 		cmd->flags |= __cpu_to_le32(WMI_BCN_TX_REF_FLAG_DELIVER_CAB);
2577 
2578 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv beacon dma\n");
2579 	return skb;
2580 }
2581 
2582 static struct sk_buff *
2583 ath10k_wmi_tlv_op_gen_pdev_set_wmm(struct ath10k *ar,
2584 				   const struct wmi_wmm_params_all_arg *arg)
2585 {
2586 	struct wmi_tlv_pdev_set_wmm_cmd *cmd;
2587 	struct wmi_wmm_params *wmm;
2588 	struct wmi_tlv *tlv;
2589 	struct sk_buff *skb;
2590 	size_t len;
2591 	void *ptr;
2592 
2593 	len = (sizeof(*tlv) + sizeof(*cmd)) +
2594 	      (4 * (sizeof(*tlv) + sizeof(*wmm)));
2595 	skb = ath10k_wmi_alloc_skb(ar, len);
2596 	if (!skb)
2597 		return ERR_PTR(-ENOMEM);
2598 
2599 	ptr = (void *)skb->data;
2600 
2601 	tlv = ptr;
2602 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_WMM_PARAMS_CMD);
2603 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2604 	cmd = (void *)tlv->value;
2605 
2606 	/* nothing to set here */
2607 
2608 	ptr += sizeof(*tlv);
2609 	ptr += sizeof(*cmd);
2610 
2611 	ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_be);
2612 	ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_bk);
2613 	ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_vi);
2614 	ptr = ath10k_wmi_tlv_put_wmm(ptr, &arg->ac_vo);
2615 
2616 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pdev set wmm\n");
2617 	return skb;
2618 }
2619 
2620 static struct sk_buff *
2621 ath10k_wmi_tlv_op_gen_request_stats(struct ath10k *ar, u32 stats_mask)
2622 {
2623 	struct wmi_request_stats_cmd *cmd;
2624 	struct wmi_tlv *tlv;
2625 	struct sk_buff *skb;
2626 
2627 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2628 	if (!skb)
2629 		return ERR_PTR(-ENOMEM);
2630 
2631 	tlv = (void *)skb->data;
2632 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_REQUEST_STATS_CMD);
2633 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2634 	cmd = (void *)tlv->value;
2635 	cmd->stats_id = __cpu_to_le32(stats_mask);
2636 
2637 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv request stats\n");
2638 	return skb;
2639 }
2640 
2641 static int
2642 ath10k_wmi_mgmt_tx_alloc_msdu_id(struct ath10k *ar, struct sk_buff *skb,
2643 				 dma_addr_t paddr)
2644 {
2645 	struct ath10k_wmi *wmi = &ar->wmi;
2646 	struct ath10k_mgmt_tx_pkt_addr *pkt_addr;
2647 	int ret;
2648 
2649 	pkt_addr = kmalloc(sizeof(*pkt_addr), GFP_ATOMIC);
2650 	if (!pkt_addr)
2651 		return -ENOMEM;
2652 
2653 	pkt_addr->vaddr = skb;
2654 	pkt_addr->paddr = paddr;
2655 
2656 	spin_lock_bh(&ar->data_lock);
2657 	ret = idr_alloc(&wmi->mgmt_pending_tx, pkt_addr, 0,
2658 			wmi->mgmt_max_num_pending_tx, GFP_ATOMIC);
2659 	spin_unlock_bh(&ar->data_lock);
2660 
2661 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi mgmt tx alloc msdu_id ret %d\n", ret);
2662 	return ret;
2663 }
2664 
2665 static struct sk_buff *
2666 ath10k_wmi_tlv_op_gen_mgmt_tx_send(struct ath10k *ar, struct sk_buff *msdu,
2667 				   dma_addr_t paddr)
2668 {
2669 	struct ath10k_skb_cb *cb = ATH10K_SKB_CB(msdu);
2670 	struct wmi_tlv_mgmt_tx_cmd *cmd;
2671 	struct ieee80211_hdr *hdr;
2672 	struct ath10k_vif *arvif;
2673 	u32 buf_len = msdu->len;
2674 	struct wmi_tlv *tlv;
2675 	struct sk_buff *skb;
2676 	int len, desc_id;
2677 	u32 vdev_id;
2678 	void *ptr;
2679 
2680 	if (!cb->vif)
2681 		return ERR_PTR(-EINVAL);
2682 
2683 	hdr = (struct ieee80211_hdr *)msdu->data;
2684 	arvif = (void *)cb->vif->drv_priv;
2685 	vdev_id = arvif->vdev_id;
2686 
2687 	if (WARN_ON_ONCE(!ieee80211_is_mgmt(hdr->frame_control)))
2688 		return ERR_PTR(-EINVAL);
2689 
2690 	len = sizeof(*cmd) + 2 * sizeof(*tlv);
2691 
2692 	if ((ieee80211_is_action(hdr->frame_control) ||
2693 	     ieee80211_is_deauth(hdr->frame_control) ||
2694 	     ieee80211_is_disassoc(hdr->frame_control)) &&
2695 	     ieee80211_has_protected(hdr->frame_control)) {
2696 		len += IEEE80211_CCMP_MIC_LEN;
2697 		buf_len += IEEE80211_CCMP_MIC_LEN;
2698 	}
2699 
2700 	buf_len = min_t(u32, buf_len, WMI_TLV_MGMT_TX_FRAME_MAX_LEN);
2701 	buf_len = round_up(buf_len, 4);
2702 
2703 	len += buf_len;
2704 	len = round_up(len, 4);
2705 	skb = ath10k_wmi_alloc_skb(ar, len);
2706 	if (!skb)
2707 		return ERR_PTR(-ENOMEM);
2708 
2709 	desc_id = ath10k_wmi_mgmt_tx_alloc_msdu_id(ar, msdu, paddr);
2710 	if (desc_id < 0)
2711 		goto err_free_skb;
2712 
2713 	ptr = (void *)skb->data;
2714 	tlv = ptr;
2715 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_MGMT_TX_CMD);
2716 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2717 	cmd = (void *)tlv->value;
2718 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2719 	cmd->desc_id = __cpu_to_le32(desc_id);
2720 	cmd->chanfreq = 0;
2721 	cmd->buf_len = __cpu_to_le32(buf_len);
2722 	cmd->frame_len = __cpu_to_le32(msdu->len);
2723 	cmd->paddr = __cpu_to_le64(paddr);
2724 
2725 	ptr += sizeof(*tlv);
2726 	ptr += sizeof(*cmd);
2727 
2728 	tlv = ptr;
2729 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2730 	tlv->len = __cpu_to_le16(buf_len);
2731 
2732 	ptr += sizeof(*tlv);
2733 	memcpy(ptr, msdu->data, buf_len);
2734 
2735 	return skb;
2736 
2737 err_free_skb:
2738 	dev_kfree_skb(skb);
2739 	return ERR_PTR(desc_id);
2740 }
2741 
2742 static struct sk_buff *
2743 ath10k_wmi_tlv_op_gen_force_fw_hang(struct ath10k *ar,
2744 				    enum wmi_force_fw_hang_type type,
2745 				    u32 delay_ms)
2746 {
2747 	struct wmi_force_fw_hang_cmd *cmd;
2748 	struct wmi_tlv *tlv;
2749 	struct sk_buff *skb;
2750 
2751 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2752 	if (!skb)
2753 		return ERR_PTR(-ENOMEM);
2754 
2755 	tlv = (void *)skb->data;
2756 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_FORCE_FW_HANG_CMD);
2757 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2758 	cmd = (void *)tlv->value;
2759 	cmd->type = __cpu_to_le32(type);
2760 	cmd->delay_ms = __cpu_to_le32(delay_ms);
2761 
2762 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv force fw hang\n");
2763 	return skb;
2764 }
2765 
2766 static struct sk_buff *
2767 ath10k_wmi_tlv_op_gen_dbglog_cfg(struct ath10k *ar, u64 module_enable,
2768 				 u32 log_level)
2769 {
2770 	struct wmi_tlv_dbglog_cmd *cmd;
2771 	struct wmi_tlv *tlv;
2772 	struct sk_buff *skb;
2773 	size_t len, bmap_len;
2774 	u32 value;
2775 	void *ptr;
2776 
2777 	if (module_enable) {
2778 		value = WMI_TLV_DBGLOG_LOG_LEVEL_VALUE(
2779 				module_enable,
2780 				WMI_TLV_DBGLOG_LOG_LEVEL_VERBOSE);
2781 	} else {
2782 		value = WMI_TLV_DBGLOG_LOG_LEVEL_VALUE(
2783 				WMI_TLV_DBGLOG_ALL_MODULES,
2784 				WMI_TLV_DBGLOG_LOG_LEVEL_WARN);
2785 	}
2786 
2787 	bmap_len = 0;
2788 	len = sizeof(*tlv) + sizeof(*cmd) + sizeof(*tlv) + bmap_len;
2789 	skb = ath10k_wmi_alloc_skb(ar, len);
2790 	if (!skb)
2791 		return ERR_PTR(-ENOMEM);
2792 
2793 	ptr = (void *)skb->data;
2794 
2795 	tlv = ptr;
2796 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_DEBUG_LOG_CONFIG_CMD);
2797 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2798 	cmd = (void *)tlv->value;
2799 	cmd->param = __cpu_to_le32(WMI_TLV_DBGLOG_PARAM_LOG_LEVEL);
2800 	cmd->value = __cpu_to_le32(value);
2801 
2802 	ptr += sizeof(*tlv);
2803 	ptr += sizeof(*cmd);
2804 
2805 	tlv = ptr;
2806 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
2807 	tlv->len = __cpu_to_le16(bmap_len);
2808 
2809 	/* nothing to do here */
2810 
2811 	ptr += sizeof(*tlv);
2812 	ptr += sizeof(bmap_len);
2813 
2814 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv dbglog value 0x%08x\n", value);
2815 	return skb;
2816 }
2817 
2818 static struct sk_buff *
2819 ath10k_wmi_tlv_op_gen_pktlog_enable(struct ath10k *ar, u32 filter)
2820 {
2821 	struct wmi_tlv_pktlog_enable *cmd;
2822 	struct wmi_tlv *tlv;
2823 	struct sk_buff *skb;
2824 	void *ptr;
2825 	size_t len;
2826 
2827 	len = sizeof(*tlv) + sizeof(*cmd);
2828 	skb = ath10k_wmi_alloc_skb(ar, len);
2829 	if (!skb)
2830 		return ERR_PTR(-ENOMEM);
2831 
2832 	ptr = (void *)skb->data;
2833 	tlv = ptr;
2834 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_PKTLOG_ENABLE_CMD);
2835 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2836 	cmd = (void *)tlv->value;
2837 	cmd->filter = __cpu_to_le32(filter);
2838 
2839 	ptr += sizeof(*tlv);
2840 	ptr += sizeof(*cmd);
2841 
2842 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pktlog enable filter 0x%08x\n",
2843 		   filter);
2844 	return skb;
2845 }
2846 
2847 static struct sk_buff *
2848 ath10k_wmi_tlv_op_gen_pdev_get_temperature(struct ath10k *ar)
2849 {
2850 	struct wmi_tlv_pdev_get_temp_cmd *cmd;
2851 	struct wmi_tlv *tlv;
2852 	struct sk_buff *skb;
2853 
2854 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
2855 	if (!skb)
2856 		return ERR_PTR(-ENOMEM);
2857 
2858 	tlv = (void *)skb->data;
2859 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_GET_TEMPERATURE_CMD);
2860 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2861 	cmd = (void *)tlv->value;
2862 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi pdev get temperature tlv\n");
2863 	return skb;
2864 }
2865 
2866 static struct sk_buff *
2867 ath10k_wmi_tlv_op_gen_pktlog_disable(struct ath10k *ar)
2868 {
2869 	struct wmi_tlv_pktlog_disable *cmd;
2870 	struct wmi_tlv *tlv;
2871 	struct sk_buff *skb;
2872 	void *ptr;
2873 	size_t len;
2874 
2875 	len = sizeof(*tlv) + sizeof(*cmd);
2876 	skb = ath10k_wmi_alloc_skb(ar, len);
2877 	if (!skb)
2878 		return ERR_PTR(-ENOMEM);
2879 
2880 	ptr = (void *)skb->data;
2881 	tlv = ptr;
2882 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_PKTLOG_DISABLE_CMD);
2883 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2884 	cmd = (void *)tlv->value;
2885 
2886 	ptr += sizeof(*tlv);
2887 	ptr += sizeof(*cmd);
2888 
2889 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv pktlog disable\n");
2890 	return skb;
2891 }
2892 
2893 static struct sk_buff *
2894 ath10k_wmi_tlv_op_gen_bcn_tmpl(struct ath10k *ar, u32 vdev_id,
2895 			       u32 tim_ie_offset, struct sk_buff *bcn,
2896 			       u32 prb_caps, u32 prb_erp, void *prb_ies,
2897 			       size_t prb_ies_len)
2898 {
2899 	struct wmi_tlv_bcn_tmpl_cmd *cmd;
2900 	struct wmi_tlv_bcn_prb_info *info;
2901 	struct wmi_tlv *tlv;
2902 	struct sk_buff *skb;
2903 	void *ptr;
2904 	size_t len;
2905 
2906 	if (WARN_ON(prb_ies_len > 0 && !prb_ies))
2907 		return ERR_PTR(-EINVAL);
2908 
2909 	len = sizeof(*tlv) + sizeof(*cmd) +
2910 	      sizeof(*tlv) + sizeof(*info) + prb_ies_len +
2911 	      sizeof(*tlv) + roundup(bcn->len, 4);
2912 	skb = ath10k_wmi_alloc_skb(ar, len);
2913 	if (!skb)
2914 		return ERR_PTR(-ENOMEM);
2915 
2916 	ptr = (void *)skb->data;
2917 	tlv = ptr;
2918 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_TMPL_CMD);
2919 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2920 	cmd = (void *)tlv->value;
2921 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2922 	cmd->tim_ie_offset = __cpu_to_le32(tim_ie_offset);
2923 	cmd->buf_len = __cpu_to_le32(bcn->len);
2924 
2925 	ptr += sizeof(*tlv);
2926 	ptr += sizeof(*cmd);
2927 
2928 	/* FIXME: prb_ies_len should be probably aligned to 4byte boundary but
2929 	 * then it is then impossible to pass original ie len.
2930 	 * This chunk is not used yet so if setting probe resp template yields
2931 	 * problems with beaconing or crashes firmware look here.
2932 	 */
2933 	tlv = ptr;
2934 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_PRB_INFO);
2935 	tlv->len = __cpu_to_le16(sizeof(*info) + prb_ies_len);
2936 	info = (void *)tlv->value;
2937 	info->caps = __cpu_to_le32(prb_caps);
2938 	info->erp = __cpu_to_le32(prb_erp);
2939 	memcpy(info->ies, prb_ies, prb_ies_len);
2940 
2941 	ptr += sizeof(*tlv);
2942 	ptr += sizeof(*info);
2943 	ptr += prb_ies_len;
2944 
2945 	tlv = ptr;
2946 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2947 	tlv->len = __cpu_to_le16(roundup(bcn->len, 4));
2948 	memcpy(tlv->value, bcn->data, bcn->len);
2949 
2950 	/* FIXME: Adjust TSF? */
2951 
2952 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv bcn tmpl vdev_id %i\n",
2953 		   vdev_id);
2954 	return skb;
2955 }
2956 
2957 static struct sk_buff *
2958 ath10k_wmi_tlv_op_gen_prb_tmpl(struct ath10k *ar, u32 vdev_id,
2959 			       struct sk_buff *prb)
2960 {
2961 	struct wmi_tlv_prb_tmpl_cmd *cmd;
2962 	struct wmi_tlv_bcn_prb_info *info;
2963 	struct wmi_tlv *tlv;
2964 	struct sk_buff *skb;
2965 	void *ptr;
2966 	size_t len;
2967 
2968 	len = sizeof(*tlv) + sizeof(*cmd) +
2969 	      sizeof(*tlv) + sizeof(*info) +
2970 	      sizeof(*tlv) + roundup(prb->len, 4);
2971 	skb = ath10k_wmi_alloc_skb(ar, len);
2972 	if (!skb)
2973 		return ERR_PTR(-ENOMEM);
2974 
2975 	ptr = (void *)skb->data;
2976 	tlv = ptr;
2977 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PRB_TMPL_CMD);
2978 	tlv->len = __cpu_to_le16(sizeof(*cmd));
2979 	cmd = (void *)tlv->value;
2980 	cmd->vdev_id = __cpu_to_le32(vdev_id);
2981 	cmd->buf_len = __cpu_to_le32(prb->len);
2982 
2983 	ptr += sizeof(*tlv);
2984 	ptr += sizeof(*cmd);
2985 
2986 	tlv = ptr;
2987 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_BCN_PRB_INFO);
2988 	tlv->len = __cpu_to_le16(sizeof(*info));
2989 	info = (void *)tlv->value;
2990 	info->caps = 0;
2991 	info->erp = 0;
2992 
2993 	ptr += sizeof(*tlv);
2994 	ptr += sizeof(*info);
2995 
2996 	tlv = ptr;
2997 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
2998 	tlv->len = __cpu_to_le16(roundup(prb->len, 4));
2999 	memcpy(tlv->value, prb->data, prb->len);
3000 
3001 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv prb tmpl vdev_id %i\n",
3002 		   vdev_id);
3003 	return skb;
3004 }
3005 
3006 static struct sk_buff *
3007 ath10k_wmi_tlv_op_gen_p2p_go_bcn_ie(struct ath10k *ar, u32 vdev_id,
3008 				    const u8 *p2p_ie)
3009 {
3010 	struct wmi_tlv_p2p_go_bcn_ie *cmd;
3011 	struct wmi_tlv *tlv;
3012 	struct sk_buff *skb;
3013 	void *ptr;
3014 	size_t len;
3015 
3016 	len = sizeof(*tlv) + sizeof(*cmd) +
3017 	      sizeof(*tlv) + roundup(p2p_ie[1] + 2, 4);
3018 	skb = ath10k_wmi_alloc_skb(ar, len);
3019 	if (!skb)
3020 		return ERR_PTR(-ENOMEM);
3021 
3022 	ptr = (void *)skb->data;
3023 	tlv = ptr;
3024 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_P2P_GO_SET_BEACON_IE);
3025 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3026 	cmd = (void *)tlv->value;
3027 	cmd->vdev_id = __cpu_to_le32(vdev_id);
3028 	cmd->ie_len = __cpu_to_le32(p2p_ie[1] + 2);
3029 
3030 	ptr += sizeof(*tlv);
3031 	ptr += sizeof(*cmd);
3032 
3033 	tlv = ptr;
3034 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_BYTE);
3035 	tlv->len = __cpu_to_le16(roundup(p2p_ie[1] + 2, 4));
3036 	memcpy(tlv->value, p2p_ie, p2p_ie[1] + 2);
3037 
3038 	ptr += sizeof(*tlv);
3039 	ptr += roundup(p2p_ie[1] + 2, 4);
3040 
3041 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv p2p go bcn ie for vdev %i\n",
3042 		   vdev_id);
3043 	return skb;
3044 }
3045 
3046 static struct sk_buff *
3047 ath10k_wmi_tlv_op_gen_update_fw_tdls_state(struct ath10k *ar, u32 vdev_id,
3048 					   enum wmi_tdls_state state)
3049 {
3050 	struct wmi_tdls_set_state_cmd *cmd;
3051 	struct wmi_tlv *tlv;
3052 	struct sk_buff *skb;
3053 	void *ptr;
3054 	size_t len;
3055 	/* Set to options from wmi_tlv_tdls_options,
3056 	 * for now none of them are enabled.
3057 	 */
3058 	u32 options = 0;
3059 
3060 	if (test_bit(WMI_SERVICE_TDLS_UAPSD_BUFFER_STA, ar->wmi.svc_map))
3061 		options |=  WMI_TLV_TDLS_BUFFER_STA_EN;
3062 
3063 	/* WMI_TDLS_ENABLE_ACTIVE_EXTERNAL_CONTROL means firm will handle TDLS
3064 	 * link inactivity detecting logic.
3065 	 */
3066 	if (state == WMI_TDLS_ENABLE_ACTIVE)
3067 		state = WMI_TDLS_ENABLE_ACTIVE_EXTERNAL_CONTROL;
3068 
3069 	len = sizeof(*tlv) + sizeof(*cmd);
3070 	skb = ath10k_wmi_alloc_skb(ar, len);
3071 	if (!skb)
3072 		return ERR_PTR(-ENOMEM);
3073 
3074 	ptr = (void *)skb->data;
3075 	tlv = ptr;
3076 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_SET_STATE_CMD);
3077 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3078 
3079 	cmd = (void *)tlv->value;
3080 	cmd->vdev_id = __cpu_to_le32(vdev_id);
3081 	cmd->state = __cpu_to_le32(state);
3082 	cmd->notification_interval_ms = __cpu_to_le32(5000);
3083 	cmd->tx_discovery_threshold = __cpu_to_le32(100);
3084 	cmd->tx_teardown_threshold = __cpu_to_le32(5);
3085 	cmd->rssi_teardown_threshold = __cpu_to_le32(-75);
3086 	cmd->rssi_delta = __cpu_to_le32(-20);
3087 	cmd->tdls_options = __cpu_to_le32(options);
3088 	cmd->tdls_peer_traffic_ind_window = __cpu_to_le32(2);
3089 	cmd->tdls_peer_traffic_response_timeout_ms = __cpu_to_le32(5000);
3090 	cmd->tdls_puapsd_mask = __cpu_to_le32(0xf);
3091 	cmd->tdls_puapsd_inactivity_time_ms = __cpu_to_le32(0);
3092 	cmd->tdls_puapsd_rx_frame_threshold = __cpu_to_le32(10);
3093 
3094 	ptr += sizeof(*tlv);
3095 	ptr += sizeof(*cmd);
3096 
3097 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv update fw tdls state %d for vdev %i\n",
3098 		   state, vdev_id);
3099 	return skb;
3100 }
3101 
3102 static u32 ath10k_wmi_tlv_prepare_peer_qos(u8 uapsd_queues, u8 sp)
3103 {
3104 	u32 peer_qos = 0;
3105 
3106 	if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VO)
3107 		peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_VO;
3108 	if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_VI)
3109 		peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_VI;
3110 	if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BK)
3111 		peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_BK;
3112 	if (uapsd_queues & IEEE80211_WMM_IE_STA_QOSINFO_AC_BE)
3113 		peer_qos |= WMI_TLV_TDLS_PEER_QOS_AC_BE;
3114 
3115 	peer_qos |= SM(sp, WMI_TLV_TDLS_PEER_SP);
3116 
3117 	return peer_qos;
3118 }
3119 
3120 static struct sk_buff *
3121 ath10k_wmi_tlv_op_gen_tdls_peer_update(struct ath10k *ar,
3122 				       const struct wmi_tdls_peer_update_cmd_arg *arg,
3123 				       const struct wmi_tdls_peer_capab_arg *cap,
3124 				       const struct wmi_channel_arg *chan_arg)
3125 {
3126 	struct wmi_tdls_peer_update_cmd *cmd;
3127 	struct wmi_tdls_peer_capab *peer_cap;
3128 	struct wmi_channel *chan;
3129 	struct wmi_tlv *tlv;
3130 	struct sk_buff *skb;
3131 	u32 peer_qos;
3132 	void *ptr;
3133 	int len;
3134 	int i;
3135 
3136 	len = sizeof(*tlv) + sizeof(*cmd) +
3137 	      sizeof(*tlv) + sizeof(*peer_cap) +
3138 	      sizeof(*tlv) + cap->peer_chan_len * sizeof(*chan);
3139 
3140 	skb = ath10k_wmi_alloc_skb(ar, len);
3141 	if (!skb)
3142 		return ERR_PTR(-ENOMEM);
3143 
3144 	ptr = (void *)skb->data;
3145 	tlv = ptr;
3146 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_PEER_UPDATE_CMD);
3147 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3148 
3149 	cmd = (void *)tlv->value;
3150 	cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
3151 	ether_addr_copy(cmd->peer_macaddr.addr, arg->addr);
3152 	cmd->peer_state = __cpu_to_le32(arg->peer_state);
3153 
3154 	ptr += sizeof(*tlv);
3155 	ptr += sizeof(*cmd);
3156 
3157 	tlv = ptr;
3158 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_TDLS_PEER_CAPABILITIES);
3159 	tlv->len = __cpu_to_le16(sizeof(*peer_cap));
3160 	peer_cap = (void *)tlv->value;
3161 	peer_qos = ath10k_wmi_tlv_prepare_peer_qos(cap->peer_uapsd_queues,
3162 						   cap->peer_max_sp);
3163 	peer_cap->peer_qos = __cpu_to_le32(peer_qos);
3164 	peer_cap->buff_sta_support = __cpu_to_le32(cap->buff_sta_support);
3165 	peer_cap->off_chan_support = __cpu_to_le32(cap->off_chan_support);
3166 	peer_cap->peer_curr_operclass = __cpu_to_le32(cap->peer_curr_operclass);
3167 	peer_cap->self_curr_operclass = __cpu_to_le32(cap->self_curr_operclass);
3168 	peer_cap->peer_chan_len = __cpu_to_le32(cap->peer_chan_len);
3169 	peer_cap->peer_operclass_len = __cpu_to_le32(cap->peer_operclass_len);
3170 
3171 	for (i = 0; i < WMI_TDLS_MAX_SUPP_OPER_CLASSES; i++)
3172 		peer_cap->peer_operclass[i] = cap->peer_operclass[i];
3173 
3174 	peer_cap->is_peer_responder = __cpu_to_le32(cap->is_peer_responder);
3175 	peer_cap->pref_offchan_num = __cpu_to_le32(cap->pref_offchan_num);
3176 	peer_cap->pref_offchan_bw = __cpu_to_le32(cap->pref_offchan_bw);
3177 
3178 	ptr += sizeof(*tlv);
3179 	ptr += sizeof(*peer_cap);
3180 
3181 	tlv = ptr;
3182 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3183 	tlv->len = __cpu_to_le16(cap->peer_chan_len * sizeof(*chan));
3184 
3185 	ptr += sizeof(*tlv);
3186 
3187 	for (i = 0; i < cap->peer_chan_len; i++) {
3188 		tlv = ptr;
3189 		tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_CHANNEL);
3190 		tlv->len = __cpu_to_le16(sizeof(*chan));
3191 		chan = (void *)tlv->value;
3192 		ath10k_wmi_put_wmi_channel(chan, &chan_arg[i]);
3193 
3194 		ptr += sizeof(*tlv);
3195 		ptr += sizeof(*chan);
3196 	}
3197 
3198 	ath10k_dbg(ar, ATH10K_DBG_WMI,
3199 		   "wmi tlv tdls peer update vdev %i state %d n_chans %u\n",
3200 		   arg->vdev_id, arg->peer_state, cap->peer_chan_len);
3201 	return skb;
3202 }
3203 
3204 static struct sk_buff *
3205 ath10k_wmi_tlv_op_gen_pdev_set_quiet_mode(struct ath10k *ar, u32 period,
3206 					  u32 duration, u32 next_offset,
3207 					  u32 enabled)
3208 {
3209 	struct wmi_tlv_set_quiet_cmd *cmd;
3210 	struct wmi_tlv *tlv;
3211 	struct sk_buff *skb;
3212 
3213 	skb = ath10k_wmi_alloc_skb(ar, sizeof(*tlv) + sizeof(*cmd));
3214 	if (!skb)
3215 		return ERR_PTR(-ENOMEM);
3216 
3217 	tlv = (void *)skb->data;
3218 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_PDEV_SET_QUIET_CMD);
3219 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3220 	cmd = (void *)tlv->value;
3221 
3222 	/* vdev_id is not in use, set to 0 */
3223 	cmd->vdev_id = __cpu_to_le32(0);
3224 	cmd->period = __cpu_to_le32(period);
3225 	cmd->duration = __cpu_to_le32(duration);
3226 	cmd->next_start = __cpu_to_le32(next_offset);
3227 	cmd->enabled = __cpu_to_le32(enabled);
3228 
3229 	ath10k_dbg(ar, ATH10K_DBG_WMI,
3230 		   "wmi tlv quiet param: period %u duration %u enabled %d\n",
3231 		   period, duration, enabled);
3232 	return skb;
3233 }
3234 
3235 static struct sk_buff *
3236 ath10k_wmi_tlv_op_gen_wow_enable(struct ath10k *ar)
3237 {
3238 	struct wmi_tlv_wow_enable_cmd *cmd;
3239 	struct wmi_tlv *tlv;
3240 	struct sk_buff *skb;
3241 	size_t len;
3242 
3243 	len = sizeof(*tlv) + sizeof(*cmd);
3244 	skb = ath10k_wmi_alloc_skb(ar, len);
3245 	if (!skb)
3246 		return ERR_PTR(-ENOMEM);
3247 
3248 	tlv = (struct wmi_tlv *)skb->data;
3249 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ENABLE_CMD);
3250 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3251 	cmd = (void *)tlv->value;
3252 
3253 	cmd->enable = __cpu_to_le32(1);
3254 
3255 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow enable\n");
3256 	return skb;
3257 }
3258 
3259 static struct sk_buff *
3260 ath10k_wmi_tlv_op_gen_wow_add_wakeup_event(struct ath10k *ar,
3261 					   u32 vdev_id,
3262 					   enum wmi_wow_wakeup_event event,
3263 					   u32 enable)
3264 {
3265 	struct wmi_tlv_wow_add_del_event_cmd *cmd;
3266 	struct wmi_tlv *tlv;
3267 	struct sk_buff *skb;
3268 	size_t len;
3269 
3270 	len = sizeof(*tlv) + sizeof(*cmd);
3271 	skb = ath10k_wmi_alloc_skb(ar, len);
3272 	if (!skb)
3273 		return ERR_PTR(-ENOMEM);
3274 
3275 	tlv = (struct wmi_tlv *)skb->data;
3276 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ADD_DEL_EVT_CMD);
3277 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3278 	cmd = (void *)tlv->value;
3279 
3280 	cmd->vdev_id = __cpu_to_le32(vdev_id);
3281 	cmd->is_add = __cpu_to_le32(enable);
3282 	cmd->event_bitmap = __cpu_to_le32(1 << event);
3283 
3284 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow add wakeup event %s enable %d vdev_id %d\n",
3285 		   wow_wakeup_event(event), enable, vdev_id);
3286 	return skb;
3287 }
3288 
3289 static struct sk_buff *
3290 ath10k_wmi_tlv_gen_wow_host_wakeup_ind(struct ath10k *ar)
3291 {
3292 	struct wmi_tlv_wow_host_wakeup_ind *cmd;
3293 	struct wmi_tlv *tlv;
3294 	struct sk_buff *skb;
3295 	size_t len;
3296 
3297 	len = sizeof(*tlv) + sizeof(*cmd);
3298 	skb = ath10k_wmi_alloc_skb(ar, len);
3299 	if (!skb)
3300 		return ERR_PTR(-ENOMEM);
3301 
3302 	tlv = (struct wmi_tlv *)skb->data;
3303 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_HOSTWAKEUP_FROM_SLEEP_CMD);
3304 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3305 	cmd = (void *)tlv->value;
3306 
3307 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow host wakeup ind\n");
3308 	return skb;
3309 }
3310 
3311 static struct sk_buff *
3312 ath10k_wmi_tlv_op_gen_wow_add_pattern(struct ath10k *ar, u32 vdev_id,
3313 				      u32 pattern_id, const u8 *pattern,
3314 				      const u8 *bitmask, int pattern_len,
3315 				      int pattern_offset)
3316 {
3317 	struct wmi_tlv_wow_add_pattern_cmd *cmd;
3318 	struct wmi_tlv_wow_bitmap_pattern *bitmap;
3319 	struct wmi_tlv *tlv;
3320 	struct sk_buff *skb;
3321 	void *ptr;
3322 	size_t len;
3323 
3324 	len = sizeof(*tlv) + sizeof(*cmd) +
3325 	      sizeof(*tlv) +			/* array struct */
3326 	      sizeof(*tlv) + sizeof(*bitmap) +  /* bitmap */
3327 	      sizeof(*tlv) +			/* empty ipv4 sync */
3328 	      sizeof(*tlv) +			/* empty ipv6 sync */
3329 	      sizeof(*tlv) +			/* empty magic */
3330 	      sizeof(*tlv) +			/* empty info timeout */
3331 	      sizeof(*tlv) + sizeof(u32);	/* ratelimit interval */
3332 
3333 	skb = ath10k_wmi_alloc_skb(ar, len);
3334 	if (!skb)
3335 		return ERR_PTR(-ENOMEM);
3336 
3337 	/* cmd */
3338 	ptr = (void *)skb->data;
3339 	tlv = ptr;
3340 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_ADD_PATTERN_CMD);
3341 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3342 	cmd = (void *)tlv->value;
3343 
3344 	cmd->vdev_id = __cpu_to_le32(vdev_id);
3345 	cmd->pattern_id = __cpu_to_le32(pattern_id);
3346 	cmd->pattern_type = __cpu_to_le32(WOW_BITMAP_PATTERN);
3347 
3348 	ptr += sizeof(*tlv);
3349 	ptr += sizeof(*cmd);
3350 
3351 	/* bitmap */
3352 	tlv = ptr;
3353 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3354 	tlv->len = __cpu_to_le16(sizeof(*tlv) + sizeof(*bitmap));
3355 
3356 	ptr += sizeof(*tlv);
3357 
3358 	tlv = ptr;
3359 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_BITMAP_PATTERN_T);
3360 	tlv->len = __cpu_to_le16(sizeof(*bitmap));
3361 	bitmap = (void *)tlv->value;
3362 
3363 	memcpy(bitmap->patternbuf, pattern, pattern_len);
3364 	memcpy(bitmap->bitmaskbuf, bitmask, pattern_len);
3365 	bitmap->pattern_offset = __cpu_to_le32(pattern_offset);
3366 	bitmap->pattern_len = __cpu_to_le32(pattern_len);
3367 	bitmap->bitmask_len = __cpu_to_le32(pattern_len);
3368 	bitmap->pattern_id = __cpu_to_le32(pattern_id);
3369 
3370 	ptr += sizeof(*tlv);
3371 	ptr += sizeof(*bitmap);
3372 
3373 	/* ipv4 sync */
3374 	tlv = ptr;
3375 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3376 	tlv->len = __cpu_to_le16(0);
3377 
3378 	ptr += sizeof(*tlv);
3379 
3380 	/* ipv6 sync */
3381 	tlv = ptr;
3382 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3383 	tlv->len = __cpu_to_le16(0);
3384 
3385 	ptr += sizeof(*tlv);
3386 
3387 	/* magic */
3388 	tlv = ptr;
3389 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_STRUCT);
3390 	tlv->len = __cpu_to_le16(0);
3391 
3392 	ptr += sizeof(*tlv);
3393 
3394 	/* pattern info timeout */
3395 	tlv = ptr;
3396 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
3397 	tlv->len = __cpu_to_le16(0);
3398 
3399 	ptr += sizeof(*tlv);
3400 
3401 	/* ratelimit interval */
3402 	tlv = ptr;
3403 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_ARRAY_UINT32);
3404 	tlv->len = __cpu_to_le16(sizeof(u32));
3405 
3406 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow add pattern vdev_id %d pattern_id %d, pattern_offset %d\n",
3407 		   vdev_id, pattern_id, pattern_offset);
3408 	return skb;
3409 }
3410 
3411 static struct sk_buff *
3412 ath10k_wmi_tlv_op_gen_wow_del_pattern(struct ath10k *ar, u32 vdev_id,
3413 				      u32 pattern_id)
3414 {
3415 	struct wmi_tlv_wow_del_pattern_cmd *cmd;
3416 	struct wmi_tlv *tlv;
3417 	struct sk_buff *skb;
3418 	size_t len;
3419 
3420 	len = sizeof(*tlv) + sizeof(*cmd);
3421 	skb = ath10k_wmi_alloc_skb(ar, len);
3422 	if (!skb)
3423 		return ERR_PTR(-ENOMEM);
3424 
3425 	tlv = (struct wmi_tlv *)skb->data;
3426 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_WOW_DEL_PATTERN_CMD);
3427 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3428 	cmd = (void *)tlv->value;
3429 
3430 	cmd->vdev_id = __cpu_to_le32(vdev_id);
3431 	cmd->pattern_id = __cpu_to_le32(pattern_id);
3432 	cmd->pattern_type = __cpu_to_le32(WOW_BITMAP_PATTERN);
3433 
3434 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv wow del pattern vdev_id %d pattern_id %d\n",
3435 		   vdev_id, pattern_id);
3436 	return skb;
3437 }
3438 
3439 static struct sk_buff *
3440 ath10k_wmi_tlv_op_gen_adaptive_qcs(struct ath10k *ar, bool enable)
3441 {
3442 	struct wmi_tlv_adaptive_qcs *cmd;
3443 	struct wmi_tlv *tlv;
3444 	struct sk_buff *skb;
3445 	void *ptr;
3446 	size_t len;
3447 
3448 	len = sizeof(*tlv) + sizeof(*cmd);
3449 	skb = ath10k_wmi_alloc_skb(ar, len);
3450 	if (!skb)
3451 		return ERR_PTR(-ENOMEM);
3452 
3453 	ptr = (void *)skb->data;
3454 	tlv = ptr;
3455 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_RESMGR_ADAPTIVE_OCS_CMD);
3456 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3457 	cmd = (void *)tlv->value;
3458 	cmd->enable = __cpu_to_le32(enable ? 1 : 0);
3459 
3460 	ptr += sizeof(*tlv);
3461 	ptr += sizeof(*cmd);
3462 
3463 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv adaptive qcs %d\n", enable);
3464 	return skb;
3465 }
3466 
3467 static struct sk_buff *
3468 ath10k_wmi_tlv_op_gen_echo(struct ath10k *ar, u32 value)
3469 {
3470 	struct wmi_echo_cmd *cmd;
3471 	struct wmi_tlv *tlv;
3472 	struct sk_buff *skb;
3473 	void *ptr;
3474 	size_t len;
3475 
3476 	len = sizeof(*tlv) + sizeof(*cmd);
3477 	skb = ath10k_wmi_alloc_skb(ar, len);
3478 	if (!skb)
3479 		return ERR_PTR(-ENOMEM);
3480 
3481 	ptr = (void *)skb->data;
3482 	tlv = ptr;
3483 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_ECHO_CMD);
3484 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3485 	cmd = (void *)tlv->value;
3486 	cmd->value = cpu_to_le32(value);
3487 
3488 	ptr += sizeof(*tlv);
3489 	ptr += sizeof(*cmd);
3490 
3491 	ath10k_dbg(ar, ATH10K_DBG_WMI, "wmi tlv echo value 0x%08x\n", value);
3492 	return skb;
3493 }
3494 
3495 static struct sk_buff *
3496 ath10k_wmi_tlv_op_gen_vdev_spectral_conf(struct ath10k *ar,
3497 					 const struct wmi_vdev_spectral_conf_arg *arg)
3498 {
3499 	struct wmi_vdev_spectral_conf_cmd *cmd;
3500 	struct sk_buff *skb;
3501 	struct wmi_tlv *tlv;
3502 	void *ptr;
3503 	size_t len;
3504 
3505 	len = sizeof(*tlv) + sizeof(*cmd);
3506 	skb = ath10k_wmi_alloc_skb(ar, len);
3507 	if (!skb)
3508 		return ERR_PTR(-ENOMEM);
3509 
3510 	ptr = (void *)skb->data;
3511 	tlv = ptr;
3512 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SPECTRAL_CONFIGURE_CMD);
3513 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3514 	cmd = (void *)tlv->value;
3515 	cmd->vdev_id = __cpu_to_le32(arg->vdev_id);
3516 	cmd->scan_count = __cpu_to_le32(arg->scan_count);
3517 	cmd->scan_period = __cpu_to_le32(arg->scan_period);
3518 	cmd->scan_priority = __cpu_to_le32(arg->scan_priority);
3519 	cmd->scan_fft_size = __cpu_to_le32(arg->scan_fft_size);
3520 	cmd->scan_gc_ena = __cpu_to_le32(arg->scan_gc_ena);
3521 	cmd->scan_restart_ena = __cpu_to_le32(arg->scan_restart_ena);
3522 	cmd->scan_noise_floor_ref = __cpu_to_le32(arg->scan_noise_floor_ref);
3523 	cmd->scan_init_delay = __cpu_to_le32(arg->scan_init_delay);
3524 	cmd->scan_nb_tone_thr = __cpu_to_le32(arg->scan_nb_tone_thr);
3525 	cmd->scan_str_bin_thr = __cpu_to_le32(arg->scan_str_bin_thr);
3526 	cmd->scan_wb_rpt_mode = __cpu_to_le32(arg->scan_wb_rpt_mode);
3527 	cmd->scan_rssi_rpt_mode = __cpu_to_le32(arg->scan_rssi_rpt_mode);
3528 	cmd->scan_rssi_thr = __cpu_to_le32(arg->scan_rssi_thr);
3529 	cmd->scan_pwr_format = __cpu_to_le32(arg->scan_pwr_format);
3530 	cmd->scan_rpt_mode = __cpu_to_le32(arg->scan_rpt_mode);
3531 	cmd->scan_bin_scale = __cpu_to_le32(arg->scan_bin_scale);
3532 	cmd->scan_dbm_adj = __cpu_to_le32(arg->scan_dbm_adj);
3533 	cmd->scan_chn_mask = __cpu_to_le32(arg->scan_chn_mask);
3534 
3535 	return skb;
3536 }
3537 
3538 static struct sk_buff *
3539 ath10k_wmi_tlv_op_gen_vdev_spectral_enable(struct ath10k *ar, u32 vdev_id,
3540 					   u32 trigger, u32 enable)
3541 {
3542 	struct wmi_vdev_spectral_enable_cmd *cmd;
3543 	struct sk_buff *skb;
3544 	struct wmi_tlv *tlv;
3545 	void *ptr;
3546 	size_t len;
3547 
3548 	len = sizeof(*tlv) + sizeof(*cmd);
3549 	skb = ath10k_wmi_alloc_skb(ar, len);
3550 	if (!skb)
3551 		return ERR_PTR(-ENOMEM);
3552 
3553 	ptr = (void *)skb->data;
3554 	tlv = ptr;
3555 	tlv->tag = __cpu_to_le16(WMI_TLV_TAG_STRUCT_VDEV_SPECTRAL_ENABLE_CMD);
3556 	tlv->len = __cpu_to_le16(sizeof(*cmd));
3557 	cmd = (void *)tlv->value;
3558 	cmd->vdev_id = __cpu_to_le32(vdev_id);
3559 	cmd->trigger_cmd = __cpu_to_le32(trigger);
3560 	cmd->enable_cmd = __cpu_to_le32(enable);
3561 
3562 	return skb;
3563 }
3564 
3565 /****************/
3566 /* TLV mappings */
3567 /****************/
3568 
3569 static struct wmi_cmd_map wmi_tlv_cmd_map = {
3570 	.init_cmdid = WMI_TLV_INIT_CMDID,
3571 	.start_scan_cmdid = WMI_TLV_START_SCAN_CMDID,
3572 	.stop_scan_cmdid = WMI_TLV_STOP_SCAN_CMDID,
3573 	.scan_chan_list_cmdid = WMI_TLV_SCAN_CHAN_LIST_CMDID,
3574 	.scan_sch_prio_tbl_cmdid = WMI_TLV_SCAN_SCH_PRIO_TBL_CMDID,
3575 	.scan_prob_req_oui_cmdid = WMI_TLV_SCAN_PROB_REQ_OUI_CMDID,
3576 	.pdev_set_regdomain_cmdid = WMI_TLV_PDEV_SET_REGDOMAIN_CMDID,
3577 	.pdev_set_channel_cmdid = WMI_TLV_PDEV_SET_CHANNEL_CMDID,
3578 	.pdev_set_param_cmdid = WMI_TLV_PDEV_SET_PARAM_CMDID,
3579 	.pdev_pktlog_enable_cmdid = WMI_TLV_PDEV_PKTLOG_ENABLE_CMDID,
3580 	.pdev_pktlog_disable_cmdid = WMI_TLV_PDEV_PKTLOG_DISABLE_CMDID,
3581 	.pdev_set_wmm_params_cmdid = WMI_TLV_PDEV_SET_WMM_PARAMS_CMDID,
3582 	.pdev_set_ht_cap_ie_cmdid = WMI_TLV_PDEV_SET_HT_CAP_IE_CMDID,
3583 	.pdev_set_vht_cap_ie_cmdid = WMI_TLV_PDEV_SET_VHT_CAP_IE_CMDID,
3584 	.pdev_set_dscp_tid_map_cmdid = WMI_TLV_PDEV_SET_DSCP_TID_MAP_CMDID,
3585 	.pdev_set_quiet_mode_cmdid = WMI_TLV_PDEV_SET_QUIET_MODE_CMDID,
3586 	.pdev_green_ap_ps_enable_cmdid = WMI_TLV_PDEV_GREEN_AP_PS_ENABLE_CMDID,
3587 	.pdev_get_tpc_config_cmdid = WMI_TLV_PDEV_GET_TPC_CONFIG_CMDID,
3588 	.pdev_set_base_macaddr_cmdid = WMI_TLV_PDEV_SET_BASE_MACADDR_CMDID,
3589 	.vdev_create_cmdid = WMI_TLV_VDEV_CREATE_CMDID,
3590 	.vdev_delete_cmdid = WMI_TLV_VDEV_DELETE_CMDID,
3591 	.vdev_start_request_cmdid = WMI_TLV_VDEV_START_REQUEST_CMDID,
3592 	.vdev_restart_request_cmdid = WMI_TLV_VDEV_RESTART_REQUEST_CMDID,
3593 	.vdev_up_cmdid = WMI_TLV_VDEV_UP_CMDID,
3594 	.vdev_stop_cmdid = WMI_TLV_VDEV_STOP_CMDID,
3595 	.vdev_down_cmdid = WMI_TLV_VDEV_DOWN_CMDID,
3596 	.vdev_set_param_cmdid = WMI_TLV_VDEV_SET_PARAM_CMDID,
3597 	.vdev_install_key_cmdid = WMI_TLV_VDEV_INSTALL_KEY_CMDID,
3598 	.peer_create_cmdid = WMI_TLV_PEER_CREATE_CMDID,
3599 	.peer_delete_cmdid = WMI_TLV_PEER_DELETE_CMDID,
3600 	.peer_flush_tids_cmdid = WMI_TLV_PEER_FLUSH_TIDS_CMDID,
3601 	.peer_set_param_cmdid = WMI_TLV_PEER_SET_PARAM_CMDID,
3602 	.peer_assoc_cmdid = WMI_TLV_PEER_ASSOC_CMDID,
3603 	.peer_add_wds_entry_cmdid = WMI_TLV_PEER_ADD_WDS_ENTRY_CMDID,
3604 	.peer_remove_wds_entry_cmdid = WMI_TLV_PEER_REMOVE_WDS_ENTRY_CMDID,
3605 	.peer_mcast_group_cmdid = WMI_TLV_PEER_MCAST_GROUP_CMDID,
3606 	.bcn_tx_cmdid = WMI_TLV_BCN_TX_CMDID,
3607 	.pdev_send_bcn_cmdid = WMI_TLV_PDEV_SEND_BCN_CMDID,
3608 	.bcn_tmpl_cmdid = WMI_TLV_BCN_TMPL_CMDID,
3609 	.bcn_filter_rx_cmdid = WMI_TLV_BCN_FILTER_RX_CMDID,
3610 	.prb_req_filter_rx_cmdid = WMI_TLV_PRB_REQ_FILTER_RX_CMDID,
3611 	.mgmt_tx_cmdid = WMI_TLV_MGMT_TX_CMDID,
3612 	.mgmt_tx_send_cmdid = WMI_TLV_MGMT_TX_SEND_CMD,
3613 	.prb_tmpl_cmdid = WMI_TLV_PRB_TMPL_CMDID,
3614 	.addba_clear_resp_cmdid = WMI_TLV_ADDBA_CLEAR_RESP_CMDID,
3615 	.addba_send_cmdid = WMI_TLV_ADDBA_SEND_CMDID,
3616 	.addba_status_cmdid = WMI_TLV_ADDBA_STATUS_CMDID,
3617 	.delba_send_cmdid = WMI_TLV_DELBA_SEND_CMDID,
3618 	.addba_set_resp_cmdid = WMI_TLV_ADDBA_SET_RESP_CMDID,
3619 	.send_singleamsdu_cmdid = WMI_TLV_SEND_SINGLEAMSDU_CMDID,
3620 	.sta_powersave_mode_cmdid = WMI_TLV_STA_POWERSAVE_MODE_CMDID,
3621 	.sta_powersave_param_cmdid = WMI_TLV_STA_POWERSAVE_PARAM_CMDID,
3622 	.sta_mimo_ps_mode_cmdid = WMI_TLV_STA_MIMO_PS_MODE_CMDID,
3623 	.pdev_dfs_enable_cmdid = WMI_TLV_PDEV_DFS_ENABLE_CMDID,
3624 	.pdev_dfs_disable_cmdid = WMI_TLV_PDEV_DFS_DISABLE_CMDID,
3625 	.roam_scan_mode = WMI_TLV_ROAM_SCAN_MODE,
3626 	.roam_scan_rssi_threshold = WMI_TLV_ROAM_SCAN_RSSI_THRESHOLD,
3627 	.roam_scan_period = WMI_TLV_ROAM_SCAN_PERIOD,
3628 	.roam_scan_rssi_change_threshold =
3629 				WMI_TLV_ROAM_SCAN_RSSI_CHANGE_THRESHOLD,
3630 	.roam_ap_profile = WMI_TLV_ROAM_AP_PROFILE,
3631 	.ofl_scan_add_ap_profile = WMI_TLV_ROAM_AP_PROFILE,
3632 	.ofl_scan_remove_ap_profile = WMI_TLV_OFL_SCAN_REMOVE_AP_PROFILE,
3633 	.ofl_scan_period = WMI_TLV_OFL_SCAN_PERIOD,
3634 	.p2p_dev_set_device_info = WMI_TLV_P2P_DEV_SET_DEVICE_INFO,
3635 	.p2p_dev_set_discoverability = WMI_TLV_P2P_DEV_SET_DISCOVERABILITY,
3636 	.p2p_go_set_beacon_ie = WMI_TLV_P2P_GO_SET_BEACON_IE,
3637 	.p2p_go_set_probe_resp_ie = WMI_TLV_P2P_GO_SET_PROBE_RESP_IE,
3638 	.p2p_set_vendor_ie_data_cmdid = WMI_TLV_P2P_SET_VENDOR_IE_DATA_CMDID,
3639 	.ap_ps_peer_param_cmdid = WMI_TLV_AP_PS_PEER_PARAM_CMDID,
3640 	.ap_ps_peer_uapsd_coex_cmdid = WMI_TLV_AP_PS_PEER_UAPSD_COEX_CMDID,
3641 	.peer_rate_retry_sched_cmdid = WMI_TLV_PEER_RATE_RETRY_SCHED_CMDID,
3642 	.wlan_profile_trigger_cmdid = WMI_TLV_WLAN_PROFILE_TRIGGER_CMDID,
3643 	.wlan_profile_set_hist_intvl_cmdid =
3644 				WMI_TLV_WLAN_PROFILE_SET_HIST_INTVL_CMDID,
3645 	.wlan_profile_get_profile_data_cmdid =
3646 				WMI_TLV_WLAN_PROFILE_GET_PROFILE_DATA_CMDID,
3647 	.wlan_profile_enable_profile_id_cmdid =
3648 				WMI_TLV_WLAN_PROFILE_ENABLE_PROFILE_ID_CMDID,
3649 	.wlan_profile_list_profile_id_cmdid =
3650 				WMI_TLV_WLAN_PROFILE_LIST_PROFILE_ID_CMDID,
3651 	.pdev_suspend_cmdid = WMI_TLV_PDEV_SUSPEND_CMDID,
3652 	.pdev_resume_cmdid = WMI_TLV_PDEV_RESUME_CMDID,
3653 	.add_bcn_filter_cmdid = WMI_TLV_ADD_BCN_FILTER_CMDID,
3654 	.rmv_bcn_filter_cmdid = WMI_TLV_RMV_BCN_FILTER_CMDID,
3655 	.wow_add_wake_pattern_cmdid = WMI_TLV_WOW_ADD_WAKE_PATTERN_CMDID,
3656 	.wow_del_wake_pattern_cmdid = WMI_TLV_WOW_DEL_WAKE_PATTERN_CMDID,
3657 	.wow_enable_disable_wake_event_cmdid =
3658 				WMI_TLV_WOW_ENABLE_DISABLE_WAKE_EVENT_CMDID,
3659 	.wow_enable_cmdid = WMI_TLV_WOW_ENABLE_CMDID,
3660 	.wow_hostwakeup_from_sleep_cmdid =
3661 				WMI_TLV_WOW_HOSTWAKEUP_FROM_SLEEP_CMDID,
3662 	.rtt_measreq_cmdid = WMI_TLV_RTT_MEASREQ_CMDID,
3663 	.rtt_tsf_cmdid = WMI_TLV_RTT_TSF_CMDID,
3664 	.vdev_spectral_scan_configure_cmdid = WMI_TLV_SPECTRAL_SCAN_CONF_CMDID,
3665 	.vdev_spectral_scan_enable_cmdid = WMI_TLV_SPECTRAL_SCAN_ENABLE_CMDID,
3666 	.request_stats_cmdid = WMI_TLV_REQUEST_STATS_CMDID,
3667 	.set_arp_ns_offload_cmdid = WMI_TLV_SET_ARP_NS_OFFLOAD_CMDID,
3668 	.network_list_offload_config_cmdid =
3669 				WMI_TLV_NETWORK_LIST_OFFLOAD_CONFIG_CMDID,
3670 	.gtk_offload_cmdid = WMI_TLV_GTK_OFFLOAD_CMDID,
3671 	.csa_offload_enable_cmdid = WMI_TLV_CSA_OFFLOAD_ENABLE_CMDID,
3672 	.csa_offload_chanswitch_cmdid = WMI_TLV_CSA_OFFLOAD_CHANSWITCH_CMDID,
3673 	.chatter_set_mode_cmdid = WMI_TLV_CHATTER_SET_MODE_CMDID,
3674 	.peer_tid_addba_cmdid = WMI_TLV_PEER_TID_ADDBA_CMDID,
3675 	.peer_tid_delba_cmdid = WMI_TLV_PEER_TID_DELBA_CMDID,
3676 	.sta_dtim_ps_method_cmdid = WMI_TLV_STA_DTIM_PS_METHOD_CMDID,
3677 	.sta_uapsd_auto_trig_cmdid = WMI_TLV_STA_UAPSD_AUTO_TRIG_CMDID,
3678 	.sta_keepalive_cmd = WMI_TLV_STA_KEEPALIVE_CMDID,
3679 	.echo_cmdid = WMI_TLV_ECHO_CMDID,
3680 	.pdev_utf_cmdid = WMI_TLV_PDEV_UTF_CMDID,
3681 	.dbglog_cfg_cmdid = WMI_TLV_DBGLOG_CFG_CMDID,
3682 	.pdev_qvit_cmdid = WMI_TLV_PDEV_QVIT_CMDID,
3683 	.pdev_ftm_intg_cmdid = WMI_TLV_PDEV_FTM_INTG_CMDID,
3684 	.vdev_set_keepalive_cmdid = WMI_TLV_VDEV_SET_KEEPALIVE_CMDID,
3685 	.vdev_get_keepalive_cmdid = WMI_TLV_VDEV_GET_KEEPALIVE_CMDID,
3686 	.force_fw_hang_cmdid = WMI_TLV_FORCE_FW_HANG_CMDID,
3687 	.gpio_config_cmdid = WMI_TLV_GPIO_CONFIG_CMDID,
3688 	.gpio_output_cmdid = WMI_TLV_GPIO_OUTPUT_CMDID,
3689 	.pdev_get_temperature_cmdid = WMI_TLV_PDEV_GET_TEMPERATURE_CMDID,
3690 	.vdev_set_wmm_params_cmdid = WMI_TLV_VDEV_SET_WMM_PARAMS_CMDID,
3691 	.tdls_set_state_cmdid = WMI_TLV_TDLS_SET_STATE_CMDID,
3692 	.tdls_peer_update_cmdid = WMI_TLV_TDLS_PEER_UPDATE_CMDID,
3693 	.adaptive_qcs_cmdid = WMI_TLV_RESMGR_ADAPTIVE_OCS_CMDID,
3694 	.scan_update_request_cmdid = WMI_CMD_UNSUPPORTED,
3695 	.vdev_standby_response_cmdid = WMI_CMD_UNSUPPORTED,
3696 	.vdev_resume_response_cmdid = WMI_CMD_UNSUPPORTED,
3697 	.wlan_peer_caching_add_peer_cmdid = WMI_CMD_UNSUPPORTED,
3698 	.wlan_peer_caching_evict_peer_cmdid = WMI_CMD_UNSUPPORTED,
3699 	.wlan_peer_caching_restore_peer_cmdid = WMI_CMD_UNSUPPORTED,
3700 	.wlan_peer_caching_print_all_peers_info_cmdid = WMI_CMD_UNSUPPORTED,
3701 	.peer_update_wds_entry_cmdid = WMI_CMD_UNSUPPORTED,
3702 	.peer_add_proxy_sta_entry_cmdid = WMI_CMD_UNSUPPORTED,
3703 	.rtt_keepalive_cmdid = WMI_CMD_UNSUPPORTED,
3704 	.oem_req_cmdid = WMI_CMD_UNSUPPORTED,
3705 	.nan_cmdid = WMI_CMD_UNSUPPORTED,
3706 	.vdev_ratemask_cmdid = WMI_CMD_UNSUPPORTED,
3707 	.qboost_cfg_cmdid = WMI_CMD_UNSUPPORTED,
3708 	.pdev_smart_ant_enable_cmdid = WMI_CMD_UNSUPPORTED,
3709 	.pdev_smart_ant_set_rx_antenna_cmdid = WMI_CMD_UNSUPPORTED,
3710 	.peer_smart_ant_set_tx_antenna_cmdid = WMI_CMD_UNSUPPORTED,
3711 	.peer_smart_ant_set_train_info_cmdid = WMI_CMD_UNSUPPORTED,
3712 	.peer_smart_ant_set_node_config_ops_cmdid = WMI_CMD_UNSUPPORTED,
3713 	.pdev_set_antenna_switch_table_cmdid = WMI_CMD_UNSUPPORTED,
3714 	.pdev_set_ctl_table_cmdid = WMI_CMD_UNSUPPORTED,
3715 	.pdev_set_mimogain_table_cmdid = WMI_CMD_UNSUPPORTED,
3716 	.pdev_ratepwr_table_cmdid = WMI_CMD_UNSUPPORTED,
3717 	.pdev_ratepwr_chainmsk_table_cmdid = WMI_CMD_UNSUPPORTED,
3718 	.pdev_fips_cmdid = WMI_CMD_UNSUPPORTED,
3719 	.tt_set_conf_cmdid = WMI_CMD_UNSUPPORTED,
3720 	.fwtest_cmdid = WMI_CMD_UNSUPPORTED,
3721 	.vdev_atf_request_cmdid = WMI_CMD_UNSUPPORTED,
3722 	.peer_atf_request_cmdid = WMI_CMD_UNSUPPORTED,
3723 	.pdev_get_ani_cck_config_cmdid = WMI_CMD_UNSUPPORTED,
3724 	.pdev_get_ani_ofdm_config_cmdid = WMI_CMD_UNSUPPORTED,
3725 	.pdev_reserve_ast_entry_cmdid = WMI_CMD_UNSUPPORTED,
3726 };
3727 
3728 static struct wmi_pdev_param_map wmi_tlv_pdev_param_map = {
3729 	.tx_chain_mask = WMI_TLV_PDEV_PARAM_TX_CHAIN_MASK,
3730 	.rx_chain_mask = WMI_TLV_PDEV_PARAM_RX_CHAIN_MASK,
3731 	.txpower_limit2g = WMI_TLV_PDEV_PARAM_TXPOWER_LIMIT2G,
3732 	.txpower_limit5g = WMI_TLV_PDEV_PARAM_TXPOWER_LIMIT5G,
3733 	.txpower_scale = WMI_TLV_PDEV_PARAM_TXPOWER_SCALE,
3734 	.beacon_gen_mode = WMI_TLV_PDEV_PARAM_BEACON_GEN_MODE,
3735 	.beacon_tx_mode = WMI_TLV_PDEV_PARAM_BEACON_TX_MODE,
3736 	.resmgr_offchan_mode = WMI_TLV_PDEV_PARAM_RESMGR_OFFCHAN_MODE,
3737 	.protection_mode = WMI_TLV_PDEV_PARAM_PROTECTION_MODE,
3738 	.dynamic_bw = WMI_TLV_PDEV_PARAM_DYNAMIC_BW,
3739 	.non_agg_sw_retry_th = WMI_TLV_PDEV_PARAM_NON_AGG_SW_RETRY_TH,
3740 	.agg_sw_retry_th = WMI_TLV_PDEV_PARAM_AGG_SW_RETRY_TH,
3741 	.sta_kickout_th = WMI_TLV_PDEV_PARAM_STA_KICKOUT_TH,
3742 	.ac_aggrsize_scaling = WMI_TLV_PDEV_PARAM_AC_AGGRSIZE_SCALING,
3743 	.ltr_enable = WMI_TLV_PDEV_PARAM_LTR_ENABLE,
3744 	.ltr_ac_latency_be = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_BE,
3745 	.ltr_ac_latency_bk = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_BK,
3746 	.ltr_ac_latency_vi = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_VI,
3747 	.ltr_ac_latency_vo = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_VO,
3748 	.ltr_ac_latency_timeout = WMI_TLV_PDEV_PARAM_LTR_AC_LATENCY_TIMEOUT,
3749 	.ltr_sleep_override = WMI_TLV_PDEV_PARAM_LTR_SLEEP_OVERRIDE,
3750 	.ltr_rx_override = WMI_TLV_PDEV_PARAM_LTR_RX_OVERRIDE,
3751 	.ltr_tx_activity_timeout = WMI_TLV_PDEV_PARAM_LTR_TX_ACTIVITY_TIMEOUT,
3752 	.l1ss_enable = WMI_TLV_PDEV_PARAM_L1SS_ENABLE,
3753 	.dsleep_enable = WMI_TLV_PDEV_PARAM_DSLEEP_ENABLE,
3754 	.pcielp_txbuf_flush = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_FLUSH,
3755 	.pcielp_txbuf_watermark = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_EN,
3756 	.pcielp_txbuf_tmo_en = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_EN,
3757 	.pcielp_txbuf_tmo_value = WMI_TLV_PDEV_PARAM_PCIELP_TXBUF_TMO_VALUE,
3758 	.pdev_stats_update_period = WMI_TLV_PDEV_PARAM_PDEV_STATS_UPDATE_PERIOD,
3759 	.vdev_stats_update_period = WMI_TLV_PDEV_PARAM_VDEV_STATS_UPDATE_PERIOD,
3760 	.peer_stats_update_period = WMI_TLV_PDEV_PARAM_PEER_STATS_UPDATE_PERIOD,
3761 	.bcnflt_stats_update_period =
3762 				WMI_TLV_PDEV_PARAM_BCNFLT_STATS_UPDATE_PERIOD,
3763 	.pmf_qos = WMI_TLV_PDEV_PARAM_PMF_QOS,
3764 	.arp_ac_override = WMI_TLV_PDEV_PARAM_ARP_AC_OVERRIDE,
3765 	.dcs = WMI_TLV_PDEV_PARAM_DCS,
3766 	.ani_enable = WMI_TLV_PDEV_PARAM_ANI_ENABLE,
3767 	.ani_poll_period = WMI_TLV_PDEV_PARAM_ANI_POLL_PERIOD,
3768 	.ani_listen_period = WMI_TLV_PDEV_PARAM_ANI_LISTEN_PERIOD,
3769 	.ani_ofdm_level = WMI_TLV_PDEV_PARAM_ANI_OFDM_LEVEL,
3770 	.ani_cck_level = WMI_TLV_PDEV_PARAM_ANI_CCK_LEVEL,
3771 	.dyntxchain = WMI_TLV_PDEV_PARAM_DYNTXCHAIN,
3772 	.proxy_sta = WMI_TLV_PDEV_PARAM_PROXY_STA,
3773 	.idle_ps_config = WMI_TLV_PDEV_PARAM_IDLE_PS_CONFIG,
3774 	.power_gating_sleep = WMI_TLV_PDEV_PARAM_POWER_GATING_SLEEP,
3775 	.fast_channel_reset = WMI_TLV_PDEV_PARAM_UNSUPPORTED,
3776 	.burst_dur = WMI_TLV_PDEV_PARAM_BURST_DUR,
3777 	.burst_enable = WMI_TLV_PDEV_PARAM_BURST_ENABLE,
3778 	.cal_period = WMI_PDEV_PARAM_UNSUPPORTED,
3779 	.aggr_burst = WMI_PDEV_PARAM_UNSUPPORTED,
3780 	.rx_decap_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3781 	.smart_antenna_default_antenna = WMI_PDEV_PARAM_UNSUPPORTED,
3782 	.igmpmld_override = WMI_PDEV_PARAM_UNSUPPORTED,
3783 	.igmpmld_tid = WMI_PDEV_PARAM_UNSUPPORTED,
3784 	.antenna_gain = WMI_PDEV_PARAM_UNSUPPORTED,
3785 	.rx_filter = WMI_PDEV_PARAM_UNSUPPORTED,
3786 	.set_mcast_to_ucast_tid = WMI_PDEV_PARAM_UNSUPPORTED,
3787 	.proxy_sta_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3788 	.set_mcast2ucast_mode = WMI_PDEV_PARAM_UNSUPPORTED,
3789 	.set_mcast2ucast_buffer = WMI_PDEV_PARAM_UNSUPPORTED,
3790 	.remove_mcast2ucast_buffer = WMI_PDEV_PARAM_UNSUPPORTED,
3791 	.peer_sta_ps_statechg_enable = WMI_PDEV_PARAM_UNSUPPORTED,
3792 	.igmpmld_ac_override = WMI_PDEV_PARAM_UNSUPPORTED,
3793 	.block_interbss = WMI_PDEV_PARAM_UNSUPPORTED,
3794 	.set_disable_reset_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3795 	.set_msdu_ttl_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3796 	.set_ppdu_duration_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3797 	.txbf_sound_period_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3798 	.set_promisc_mode_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3799 	.set_burst_mode_cmdid = WMI_PDEV_PARAM_UNSUPPORTED,
3800 	.en_stats = WMI_PDEV_PARAM_UNSUPPORTED,
3801 	.mu_group_policy = WMI_PDEV_PARAM_UNSUPPORTED,
3802 	.noise_detection = WMI_PDEV_PARAM_UNSUPPORTED,
3803 	.noise_threshold = WMI_PDEV_PARAM_UNSUPPORTED,
3804 	.dpd_enable = WMI_PDEV_PARAM_UNSUPPORTED,
3805 	.set_mcast_bcast_echo = WMI_PDEV_PARAM_UNSUPPORTED,
3806 	.atf_strict_sch = WMI_PDEV_PARAM_UNSUPPORTED,
3807 	.atf_sched_duration = WMI_PDEV_PARAM_UNSUPPORTED,
3808 	.ant_plzn = WMI_PDEV_PARAM_UNSUPPORTED,
3809 	.mgmt_retry_limit = WMI_PDEV_PARAM_UNSUPPORTED,
3810 	.sensitivity_level = WMI_PDEV_PARAM_UNSUPPORTED,
3811 	.signed_txpower_2g = WMI_PDEV_PARAM_UNSUPPORTED,
3812 	.signed_txpower_5g = WMI_PDEV_PARAM_UNSUPPORTED,
3813 	.enable_per_tid_amsdu = WMI_PDEV_PARAM_UNSUPPORTED,
3814 	.enable_per_tid_ampdu = WMI_PDEV_PARAM_UNSUPPORTED,
3815 	.cca_threshold = WMI_PDEV_PARAM_UNSUPPORTED,
3816 	.rts_fixed_rate = WMI_PDEV_PARAM_UNSUPPORTED,
3817 	.pdev_reset = WMI_PDEV_PARAM_UNSUPPORTED,
3818 	.wapi_mbssid_offset = WMI_PDEV_PARAM_UNSUPPORTED,
3819 	.arp_srcaddr = WMI_PDEV_PARAM_UNSUPPORTED,
3820 	.arp_dstaddr = WMI_PDEV_PARAM_UNSUPPORTED,
3821 };
3822 
3823 static struct wmi_vdev_param_map wmi_tlv_vdev_param_map = {
3824 	.rts_threshold = WMI_TLV_VDEV_PARAM_RTS_THRESHOLD,
3825 	.fragmentation_threshold = WMI_TLV_VDEV_PARAM_FRAGMENTATION_THRESHOLD,
3826 	.beacon_interval = WMI_TLV_VDEV_PARAM_BEACON_INTERVAL,
3827 	.listen_interval = WMI_TLV_VDEV_PARAM_LISTEN_INTERVAL,
3828 	.multicast_rate = WMI_TLV_VDEV_PARAM_MULTICAST_RATE,
3829 	.mgmt_tx_rate = WMI_TLV_VDEV_PARAM_MGMT_TX_RATE,
3830 	.slot_time = WMI_TLV_VDEV_PARAM_SLOT_TIME,
3831 	.preamble = WMI_TLV_VDEV_PARAM_PREAMBLE,
3832 	.swba_time = WMI_TLV_VDEV_PARAM_SWBA_TIME,
3833 	.wmi_vdev_stats_update_period = WMI_TLV_VDEV_STATS_UPDATE_PERIOD,
3834 	.wmi_vdev_pwrsave_ageout_time = WMI_TLV_VDEV_PWRSAVE_AGEOUT_TIME,
3835 	.wmi_vdev_host_swba_interval = WMI_TLV_VDEV_HOST_SWBA_INTERVAL,
3836 	.dtim_period = WMI_TLV_VDEV_PARAM_DTIM_PERIOD,
3837 	.wmi_vdev_oc_scheduler_air_time_limit =
3838 				WMI_TLV_VDEV_OC_SCHEDULER_AIR_TIME_LIMIT,
3839 	.wds = WMI_TLV_VDEV_PARAM_WDS,
3840 	.atim_window = WMI_TLV_VDEV_PARAM_ATIM_WINDOW,
3841 	.bmiss_count_max = WMI_TLV_VDEV_PARAM_BMISS_COUNT_MAX,
3842 	.bmiss_first_bcnt = WMI_TLV_VDEV_PARAM_BMISS_FIRST_BCNT,
3843 	.bmiss_final_bcnt = WMI_TLV_VDEV_PARAM_BMISS_FINAL_BCNT,
3844 	.feature_wmm = WMI_TLV_VDEV_PARAM_FEATURE_WMM,
3845 	.chwidth = WMI_TLV_VDEV_PARAM_CHWIDTH,
3846 	.chextoffset = WMI_TLV_VDEV_PARAM_CHEXTOFFSET,
3847 	.disable_htprotection =	WMI_TLV_VDEV_PARAM_DISABLE_HTPROTECTION,
3848 	.sta_quickkickout = WMI_TLV_VDEV_PARAM_STA_QUICKKICKOUT,
3849 	.mgmt_rate = WMI_TLV_VDEV_PARAM_MGMT_RATE,
3850 	.protection_mode = WMI_TLV_VDEV_PARAM_PROTECTION_MODE,
3851 	.fixed_rate = WMI_TLV_VDEV_PARAM_FIXED_RATE,
3852 	.sgi = WMI_TLV_VDEV_PARAM_SGI,
3853 	.ldpc = WMI_TLV_VDEV_PARAM_LDPC,
3854 	.tx_stbc = WMI_TLV_VDEV_PARAM_TX_STBC,
3855 	.rx_stbc = WMI_TLV_VDEV_PARAM_RX_STBC,
3856 	.intra_bss_fwd = WMI_TLV_VDEV_PARAM_INTRA_BSS_FWD,
3857 	.def_keyid = WMI_TLV_VDEV_PARAM_DEF_KEYID,
3858 	.nss = WMI_TLV_VDEV_PARAM_NSS,
3859 	.bcast_data_rate = WMI_TLV_VDEV_PARAM_BCAST_DATA_RATE,
3860 	.mcast_data_rate = WMI_TLV_VDEV_PARAM_MCAST_DATA_RATE,
3861 	.mcast_indicate = WMI_TLV_VDEV_PARAM_MCAST_INDICATE,
3862 	.dhcp_indicate = WMI_TLV_VDEV_PARAM_DHCP_INDICATE,
3863 	.unknown_dest_indicate = WMI_TLV_VDEV_PARAM_UNKNOWN_DEST_INDICATE,
3864 	.ap_keepalive_min_idle_inactive_time_secs =
3865 		WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MIN_IDLE_INACTIVE_TIME_SECS,
3866 	.ap_keepalive_max_idle_inactive_time_secs =
3867 		WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MAX_IDLE_INACTIVE_TIME_SECS,
3868 	.ap_keepalive_max_unresponsive_time_secs =
3869 		WMI_TLV_VDEV_PARAM_AP_KEEPALIVE_MAX_UNRESPONSIVE_TIME_SECS,
3870 	.ap_enable_nawds = WMI_TLV_VDEV_PARAM_AP_ENABLE_NAWDS,
3871 	.mcast2ucast_set = WMI_TLV_VDEV_PARAM_UNSUPPORTED,
3872 	.enable_rtscts = WMI_TLV_VDEV_PARAM_ENABLE_RTSCTS,
3873 	.txbf = WMI_TLV_VDEV_PARAM_TXBF,
3874 	.packet_powersave = WMI_TLV_VDEV_PARAM_PACKET_POWERSAVE,
3875 	.drop_unencry = WMI_TLV_VDEV_PARAM_DROP_UNENCRY,
3876 	.tx_encap_type = WMI_TLV_VDEV_PARAM_TX_ENCAP_TYPE,
3877 	.ap_detect_out_of_sync_sleeping_sta_time_secs =
3878 					WMI_TLV_VDEV_PARAM_UNSUPPORTED,
3879 	.rc_num_retries = WMI_VDEV_PARAM_UNSUPPORTED,
3880 	.cabq_maxdur = WMI_VDEV_PARAM_UNSUPPORTED,
3881 	.mfptest_set = WMI_VDEV_PARAM_UNSUPPORTED,
3882 	.rts_fixed_rate = WMI_VDEV_PARAM_UNSUPPORTED,
3883 	.vht_sgimask = WMI_VDEV_PARAM_UNSUPPORTED,
3884 	.vht80_ratemask = WMI_VDEV_PARAM_UNSUPPORTED,
3885 	.early_rx_adjust_enable = WMI_VDEV_PARAM_UNSUPPORTED,
3886 	.early_rx_tgt_bmiss_num = WMI_VDEV_PARAM_UNSUPPORTED,
3887 	.early_rx_bmiss_sample_cycle = WMI_VDEV_PARAM_UNSUPPORTED,
3888 	.early_rx_slop_step = WMI_VDEV_PARAM_UNSUPPORTED,
3889 	.early_rx_init_slop = WMI_VDEV_PARAM_UNSUPPORTED,
3890 	.early_rx_adjust_pause = WMI_VDEV_PARAM_UNSUPPORTED,
3891 	.proxy_sta = WMI_VDEV_PARAM_UNSUPPORTED,
3892 	.meru_vc = WMI_VDEV_PARAM_UNSUPPORTED,
3893 	.rx_decap_type = WMI_VDEV_PARAM_UNSUPPORTED,
3894 	.bw_nss_ratemask = WMI_VDEV_PARAM_UNSUPPORTED,
3895 };
3896 
3897 static const struct wmi_ops wmi_tlv_ops = {
3898 	.rx = ath10k_wmi_tlv_op_rx,
3899 	.map_svc = wmi_tlv_svc_map,
3900 	.map_svc_ext = wmi_tlv_svc_map_ext,
3901 
3902 	.pull_scan = ath10k_wmi_tlv_op_pull_scan_ev,
3903 	.pull_mgmt_rx = ath10k_wmi_tlv_op_pull_mgmt_rx_ev,
3904 	.pull_mgmt_tx_compl = ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev,
3905 	.pull_ch_info = ath10k_wmi_tlv_op_pull_ch_info_ev,
3906 	.pull_vdev_start = ath10k_wmi_tlv_op_pull_vdev_start_ev,
3907 	.pull_peer_kick = ath10k_wmi_tlv_op_pull_peer_kick_ev,
3908 	.pull_swba = ath10k_wmi_tlv_op_pull_swba_ev,
3909 	.pull_phyerr_hdr = ath10k_wmi_tlv_op_pull_phyerr_ev_hdr,
3910 	.pull_phyerr = ath10k_wmi_op_pull_phyerr_ev,
3911 	.pull_svc_rdy = ath10k_wmi_tlv_op_pull_svc_rdy_ev,
3912 	.pull_rdy = ath10k_wmi_tlv_op_pull_rdy_ev,
3913 	.pull_svc_avail = ath10k_wmi_tlv_op_pull_svc_avail,
3914 	.pull_fw_stats = ath10k_wmi_tlv_op_pull_fw_stats,
3915 	.pull_roam_ev = ath10k_wmi_tlv_op_pull_roam_ev,
3916 	.pull_wow_event = ath10k_wmi_tlv_op_pull_wow_ev,
3917 	.pull_echo_ev = ath10k_wmi_tlv_op_pull_echo_ev,
3918 	.get_txbf_conf_scheme = ath10k_wmi_tlv_txbf_conf_scheme,
3919 
3920 	.gen_pdev_suspend = ath10k_wmi_tlv_op_gen_pdev_suspend,
3921 	.gen_pdev_resume = ath10k_wmi_tlv_op_gen_pdev_resume,
3922 	.gen_pdev_set_rd = ath10k_wmi_tlv_op_gen_pdev_set_rd,
3923 	.gen_pdev_set_param = ath10k_wmi_tlv_op_gen_pdev_set_param,
3924 	.gen_init = ath10k_wmi_tlv_op_gen_init,
3925 	.gen_start_scan = ath10k_wmi_tlv_op_gen_start_scan,
3926 	.gen_stop_scan = ath10k_wmi_tlv_op_gen_stop_scan,
3927 	.gen_vdev_create = ath10k_wmi_tlv_op_gen_vdev_create,
3928 	.gen_vdev_delete = ath10k_wmi_tlv_op_gen_vdev_delete,
3929 	.gen_vdev_start = ath10k_wmi_tlv_op_gen_vdev_start,
3930 	.gen_vdev_stop = ath10k_wmi_tlv_op_gen_vdev_stop,
3931 	.gen_vdev_up = ath10k_wmi_tlv_op_gen_vdev_up,
3932 	.gen_vdev_down = ath10k_wmi_tlv_op_gen_vdev_down,
3933 	.gen_vdev_set_param = ath10k_wmi_tlv_op_gen_vdev_set_param,
3934 	.gen_vdev_install_key = ath10k_wmi_tlv_op_gen_vdev_install_key,
3935 	.gen_vdev_wmm_conf = ath10k_wmi_tlv_op_gen_vdev_wmm_conf,
3936 	.gen_peer_create = ath10k_wmi_tlv_op_gen_peer_create,
3937 	.gen_peer_delete = ath10k_wmi_tlv_op_gen_peer_delete,
3938 	.gen_peer_flush = ath10k_wmi_tlv_op_gen_peer_flush,
3939 	.gen_peer_set_param = ath10k_wmi_tlv_op_gen_peer_set_param,
3940 	.gen_peer_assoc = ath10k_wmi_tlv_op_gen_peer_assoc,
3941 	.gen_set_psmode = ath10k_wmi_tlv_op_gen_set_psmode,
3942 	.gen_set_sta_ps = ath10k_wmi_tlv_op_gen_set_sta_ps,
3943 	.gen_set_ap_ps = ath10k_wmi_tlv_op_gen_set_ap_ps,
3944 	.gen_scan_chan_list = ath10k_wmi_tlv_op_gen_scan_chan_list,
3945 	.gen_scan_prob_req_oui = ath10k_wmi_tlv_op_gen_scan_prob_req_oui,
3946 	.gen_beacon_dma = ath10k_wmi_tlv_op_gen_beacon_dma,
3947 	.gen_pdev_set_wmm = ath10k_wmi_tlv_op_gen_pdev_set_wmm,
3948 	.gen_request_stats = ath10k_wmi_tlv_op_gen_request_stats,
3949 	.gen_force_fw_hang = ath10k_wmi_tlv_op_gen_force_fw_hang,
3950 	/* .gen_mgmt_tx = not implemented; HTT is used */
3951 	.gen_mgmt_tx_send = ath10k_wmi_tlv_op_gen_mgmt_tx_send,
3952 	.gen_dbglog_cfg = ath10k_wmi_tlv_op_gen_dbglog_cfg,
3953 	.gen_pktlog_enable = ath10k_wmi_tlv_op_gen_pktlog_enable,
3954 	.gen_pktlog_disable = ath10k_wmi_tlv_op_gen_pktlog_disable,
3955 	.gen_pdev_set_quiet_mode = ath10k_wmi_tlv_op_gen_pdev_set_quiet_mode,
3956 	.gen_pdev_get_temperature = ath10k_wmi_tlv_op_gen_pdev_get_temperature,
3957 	/* .gen_addba_clear_resp not implemented */
3958 	/* .gen_addba_send not implemented */
3959 	/* .gen_addba_set_resp not implemented */
3960 	/* .gen_delba_send not implemented */
3961 	.gen_bcn_tmpl = ath10k_wmi_tlv_op_gen_bcn_tmpl,
3962 	.gen_prb_tmpl = ath10k_wmi_tlv_op_gen_prb_tmpl,
3963 	.gen_p2p_go_bcn_ie = ath10k_wmi_tlv_op_gen_p2p_go_bcn_ie,
3964 	.gen_vdev_sta_uapsd = ath10k_wmi_tlv_op_gen_vdev_sta_uapsd,
3965 	.gen_sta_keepalive = ath10k_wmi_tlv_op_gen_sta_keepalive,
3966 	.gen_wow_enable = ath10k_wmi_tlv_op_gen_wow_enable,
3967 	.gen_wow_add_wakeup_event = ath10k_wmi_tlv_op_gen_wow_add_wakeup_event,
3968 	.gen_wow_host_wakeup_ind = ath10k_wmi_tlv_gen_wow_host_wakeup_ind,
3969 	.gen_wow_add_pattern = ath10k_wmi_tlv_op_gen_wow_add_pattern,
3970 	.gen_wow_del_pattern = ath10k_wmi_tlv_op_gen_wow_del_pattern,
3971 	.gen_update_fw_tdls_state = ath10k_wmi_tlv_op_gen_update_fw_tdls_state,
3972 	.gen_tdls_peer_update = ath10k_wmi_tlv_op_gen_tdls_peer_update,
3973 	.gen_adaptive_qcs = ath10k_wmi_tlv_op_gen_adaptive_qcs,
3974 	.fw_stats_fill = ath10k_wmi_main_op_fw_stats_fill,
3975 	.get_vdev_subtype = ath10k_wmi_op_get_vdev_subtype,
3976 	.gen_echo = ath10k_wmi_tlv_op_gen_echo,
3977 	.gen_vdev_spectral_conf = ath10k_wmi_tlv_op_gen_vdev_spectral_conf,
3978 	.gen_vdev_spectral_enable = ath10k_wmi_tlv_op_gen_vdev_spectral_enable,
3979 };
3980 
3981 static const struct wmi_peer_flags_map wmi_tlv_peer_flags_map = {
3982 	.auth = WMI_TLV_PEER_AUTH,
3983 	.qos = WMI_TLV_PEER_QOS,
3984 	.need_ptk_4_way = WMI_TLV_PEER_NEED_PTK_4_WAY,
3985 	.need_gtk_2_way = WMI_TLV_PEER_NEED_GTK_2_WAY,
3986 	.apsd = WMI_TLV_PEER_APSD,
3987 	.ht = WMI_TLV_PEER_HT,
3988 	.bw40 = WMI_TLV_PEER_40MHZ,
3989 	.stbc = WMI_TLV_PEER_STBC,
3990 	.ldbc = WMI_TLV_PEER_LDPC,
3991 	.dyn_mimops = WMI_TLV_PEER_DYN_MIMOPS,
3992 	.static_mimops = WMI_TLV_PEER_STATIC_MIMOPS,
3993 	.spatial_mux = WMI_TLV_PEER_SPATIAL_MUX,
3994 	.vht = WMI_TLV_PEER_VHT,
3995 	.bw80 = WMI_TLV_PEER_80MHZ,
3996 	.pmf = WMI_TLV_PEER_PMF,
3997 	.bw160 = WMI_TLV_PEER_160MHZ,
3998 };
3999 
4000 /************/
4001 /* TLV init */
4002 /************/
4003 
4004 void ath10k_wmi_tlv_attach(struct ath10k *ar)
4005 {
4006 	ar->wmi.cmd = &wmi_tlv_cmd_map;
4007 	ar->wmi.vdev_param = &wmi_tlv_vdev_param_map;
4008 	ar->wmi.pdev_param = &wmi_tlv_pdev_param_map;
4009 	ar->wmi.ops = &wmi_tlv_ops;
4010 	ar->wmi.peer_flags = &wmi_tlv_peer_flags_map;
4011 }
4012