xref: /openbmc/linux/drivers/net/wireless/ath/ath11k/wmi.c (revision 2d68bb26)
1 // SPDX-License-Identifier: BSD-3-Clause-Clear
2 /*
3  * Copyright (c) 2018-2019 The Linux Foundation. All rights reserved.
4  */
5 #include <linux/skbuff.h>
6 #include <linux/ctype.h>
7 #include <net/mac80211.h>
8 #include <net/cfg80211.h>
9 #include <linux/completion.h>
10 #include <linux/if_ether.h>
11 #include <linux/types.h>
12 #include <linux/pci.h>
13 #include <linux/uuid.h>
14 #include <linux/time.h>
15 #include <linux/of.h>
16 #include "core.h"
17 #include "debug.h"
18 #include "mac.h"
19 #include "hw.h"
20 #include "peer.h"
21 
22 struct wmi_tlv_policy {
23 	size_t min_len;
24 };
25 
26 struct wmi_tlv_svc_ready_parse {
27 	bool wmi_svc_bitmap_done;
28 };
29 
30 struct wmi_tlv_svc_rdy_ext_parse {
31 	struct ath11k_service_ext_param param;
32 	struct wmi_soc_mac_phy_hw_mode_caps *hw_caps;
33 	struct wmi_hw_mode_capabilities *hw_mode_caps;
34 	u32 n_hw_mode_caps;
35 	u32 tot_phy_id;
36 	struct wmi_hw_mode_capabilities pref_hw_mode_caps;
37 	struct wmi_mac_phy_capabilities *mac_phy_caps;
38 	u32 n_mac_phy_caps;
39 	struct wmi_soc_hal_reg_capabilities *soc_hal_reg_caps;
40 	struct wmi_hal_reg_capabilities_ext *ext_hal_reg_caps;
41 	u32 n_ext_hal_reg_caps;
42 	bool hw_mode_done;
43 	bool mac_phy_done;
44 	bool ext_hal_reg_done;
45 };
46 
47 struct wmi_tlv_rdy_parse {
48 	u32 num_extra_mac_addr;
49 };
50 
51 static const struct wmi_tlv_policy wmi_tlv_policies[] = {
52 	[WMI_TAG_ARRAY_BYTE]
53 		= { .min_len = 0 },
54 	[WMI_TAG_ARRAY_UINT32]
55 		= { .min_len = 0 },
56 	[WMI_TAG_SERVICE_READY_EVENT]
57 		= { .min_len = sizeof(struct wmi_service_ready_event) },
58 	[WMI_TAG_SERVICE_READY_EXT_EVENT]
59 		= { .min_len =  sizeof(struct wmi_service_ready_ext_event) },
60 	[WMI_TAG_SOC_MAC_PHY_HW_MODE_CAPS]
61 		= { .min_len = sizeof(struct wmi_soc_mac_phy_hw_mode_caps) },
62 	[WMI_TAG_SOC_HAL_REG_CAPABILITIES]
63 		= { .min_len = sizeof(struct wmi_soc_hal_reg_capabilities) },
64 	[WMI_TAG_VDEV_START_RESPONSE_EVENT]
65 		= { .min_len = sizeof(struct wmi_vdev_start_resp_event) },
66 	[WMI_TAG_PEER_DELETE_RESP_EVENT]
67 		= { .min_len = sizeof(struct wmi_peer_delete_resp_event) },
68 	[WMI_TAG_OFFLOAD_BCN_TX_STATUS_EVENT]
69 		= { .min_len = sizeof(struct wmi_bcn_tx_status_event) },
70 	[WMI_TAG_VDEV_STOPPED_EVENT]
71 		= { .min_len = sizeof(struct wmi_vdev_stopped_event) },
72 	[WMI_TAG_REG_CHAN_LIST_CC_EVENT]
73 		= { .min_len = sizeof(struct wmi_reg_chan_list_cc_event) },
74 	[WMI_TAG_MGMT_RX_HDR]
75 		= { .min_len = sizeof(struct wmi_mgmt_rx_hdr) },
76 	[WMI_TAG_MGMT_TX_COMPL_EVENT]
77 		= { .min_len = sizeof(struct wmi_mgmt_tx_compl_event) },
78 	[WMI_TAG_SCAN_EVENT]
79 		= { .min_len = sizeof(struct wmi_scan_event) },
80 	[WMI_TAG_PEER_STA_KICKOUT_EVENT]
81 		= { .min_len = sizeof(struct wmi_peer_sta_kickout_event) },
82 	[WMI_TAG_ROAM_EVENT]
83 		= { .min_len = sizeof(struct wmi_roam_event) },
84 	[WMI_TAG_CHAN_INFO_EVENT]
85 		= { .min_len = sizeof(struct wmi_chan_info_event) },
86 	[WMI_TAG_PDEV_BSS_CHAN_INFO_EVENT]
87 		= { .min_len = sizeof(struct wmi_pdev_bss_chan_info_event) },
88 	[WMI_TAG_VDEV_INSTALL_KEY_COMPLETE_EVENT]
89 		= { .min_len = sizeof(struct wmi_vdev_install_key_compl_event) },
90 	[WMI_TAG_READY_EVENT]
91 		= {.min_len = sizeof(struct wmi_ready_event) },
92 	[WMI_TAG_SERVICE_AVAILABLE_EVENT]
93 		= {.min_len = sizeof(struct wmi_service_available_event) },
94 	[WMI_TAG_PEER_ASSOC_CONF_EVENT]
95 		= { .min_len = sizeof(struct wmi_peer_assoc_conf_event) },
96 	[WMI_TAG_STATS_EVENT]
97 		= { .min_len = sizeof(struct wmi_stats_event) },
98 	[WMI_TAG_PDEV_CTL_FAILSAFE_CHECK_EVENT]
99 		= { .min_len = sizeof(struct wmi_pdev_ctl_failsafe_chk_event) },
100 };
101 
102 #define PRIMAP(_hw_mode_) \
103 	[_hw_mode_] = _hw_mode_##_PRI
104 
105 static const int ath11k_hw_mode_pri_map[] = {
106 	PRIMAP(WMI_HOST_HW_MODE_SINGLE),
107 	PRIMAP(WMI_HOST_HW_MODE_DBS),
108 	PRIMAP(WMI_HOST_HW_MODE_SBS_PASSIVE),
109 	PRIMAP(WMI_HOST_HW_MODE_SBS),
110 	PRIMAP(WMI_HOST_HW_MODE_DBS_SBS),
111 	PRIMAP(WMI_HOST_HW_MODE_DBS_OR_SBS),
112 	/* keep last */
113 	PRIMAP(WMI_HOST_HW_MODE_MAX),
114 };
115 
116 static int
117 ath11k_wmi_tlv_iter(struct ath11k_base *ab, const void *ptr, size_t len,
118 		    int (*iter)(struct ath11k_base *ab, u16 tag, u16 len,
119 				const void *ptr, void *data),
120 		    void *data)
121 {
122 	const void *begin = ptr;
123 	const struct wmi_tlv *tlv;
124 	u16 tlv_tag, tlv_len;
125 	int ret;
126 
127 	while (len > 0) {
128 		if (len < sizeof(*tlv)) {
129 			ath11k_err(ab, "wmi tlv parse failure at byte %zd (%zu bytes left, %zu expected)\n",
130 				   ptr - begin, len, sizeof(*tlv));
131 			return -EINVAL;
132 		}
133 
134 		tlv = ptr;
135 		tlv_tag = FIELD_GET(WMI_TLV_TAG, tlv->header);
136 		tlv_len = FIELD_GET(WMI_TLV_LEN, tlv->header);
137 		ptr += sizeof(*tlv);
138 		len -= sizeof(*tlv);
139 
140 		if (tlv_len > len) {
141 			ath11k_err(ab, "wmi tlv parse failure of tag %hhu at byte %zd (%zu bytes left, %hhu expected)\n",
142 				   tlv_tag, ptr - begin, len, tlv_len);
143 			return -EINVAL;
144 		}
145 
146 		if (tlv_tag < ARRAY_SIZE(wmi_tlv_policies) &&
147 		    wmi_tlv_policies[tlv_tag].min_len &&
148 		    wmi_tlv_policies[tlv_tag].min_len > tlv_len) {
149 			ath11k_err(ab, "wmi tlv parse failure of tag %hhu at byte %zd (%hhu bytes is less than min length %zu)\n",
150 				   tlv_tag, ptr - begin, tlv_len,
151 				   wmi_tlv_policies[tlv_tag].min_len);
152 			return -EINVAL;
153 		}
154 
155 		ret = iter(ab, tlv_tag, tlv_len, ptr, data);
156 		if (ret)
157 			return ret;
158 
159 		ptr += tlv_len;
160 		len -= tlv_len;
161 	}
162 
163 	return 0;
164 }
165 
166 static int ath11k_wmi_tlv_iter_parse(struct ath11k_base *ab, u16 tag, u16 len,
167 				     const void *ptr, void *data)
168 {
169 	const void **tb = data;
170 
171 	if (tag < WMI_TAG_MAX)
172 		tb[tag] = ptr;
173 
174 	return 0;
175 }
176 
177 static int ath11k_wmi_tlv_parse(struct ath11k_base *ar, const void **tb,
178 				const void *ptr, size_t len)
179 {
180 	return ath11k_wmi_tlv_iter(ar, ptr, len, ath11k_wmi_tlv_iter_parse,
181 				   (void *)tb);
182 }
183 
184 static const void **
185 ath11k_wmi_tlv_parse_alloc(struct ath11k_base *ab, const void *ptr,
186 			   size_t len, gfp_t gfp)
187 {
188 	const void **tb;
189 	int ret;
190 
191 	tb = kcalloc(WMI_TAG_MAX, sizeof(*tb), gfp);
192 	if (!tb)
193 		return ERR_PTR(-ENOMEM);
194 
195 	ret = ath11k_wmi_tlv_parse(ab, tb, ptr, len);
196 	if (ret) {
197 		kfree(tb);
198 		return ERR_PTR(ret);
199 	}
200 
201 	return tb;
202 }
203 
204 static int ath11k_wmi_cmd_send_nowait(struct ath11k_pdev_wmi *wmi, struct sk_buff *skb,
205 				      u32 cmd_id)
206 {
207 	struct ath11k_skb_cb *skb_cb = ATH11K_SKB_CB(skb);
208 	struct ath11k_base *ab = wmi->wmi_sc->ab;
209 	struct wmi_cmd_hdr *cmd_hdr;
210 	int ret;
211 	u32 cmd = 0;
212 
213 	if (skb_push(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
214 		return -ENOMEM;
215 
216 	cmd |= FIELD_PREP(WMI_CMD_HDR_CMD_ID, cmd_id);
217 
218 	cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
219 	cmd_hdr->cmd_id = cmd;
220 
221 	memset(skb_cb, 0, sizeof(*skb_cb));
222 	ret = ath11k_htc_send(&ab->htc, wmi->eid, skb);
223 
224 	if (ret)
225 		goto err_pull;
226 
227 	return 0;
228 
229 err_pull:
230 	skb_pull(skb, sizeof(struct wmi_cmd_hdr));
231 	return ret;
232 }
233 
234 int ath11k_wmi_cmd_send(struct ath11k_pdev_wmi *wmi, struct sk_buff *skb,
235 			u32 cmd_id)
236 {
237 	struct ath11k_wmi_base *wmi_sc = wmi->wmi_sc;
238 	int ret = -EOPNOTSUPP;
239 
240 	might_sleep();
241 
242 	wait_event_timeout(wmi_sc->tx_credits_wq, ({
243 		ret = ath11k_wmi_cmd_send_nowait(wmi, skb, cmd_id);
244 
245 		if (ret && test_bit(ATH11K_FLAG_CRASH_FLUSH, &wmi_sc->ab->dev_flags))
246 			ret = -ESHUTDOWN;
247 
248 		(ret != -EAGAIN);
249 	}), WMI_SEND_TIMEOUT_HZ);
250 
251 	if (ret == -EAGAIN)
252 		ath11k_warn(wmi_sc->ab, "wmi command %d timeout\n", cmd_id);
253 
254 	return ret;
255 }
256 
257 static int ath11k_pull_svc_ready_ext(struct ath11k_pdev_wmi *wmi_handle,
258 				     const void *ptr,
259 				     struct ath11k_service_ext_param *param)
260 {
261 	const struct wmi_service_ready_ext_event *ev = ptr;
262 
263 	if (!ev)
264 		return -EINVAL;
265 
266 	/* Move this to host based bitmap */
267 	param->default_conc_scan_config_bits = ev->default_conc_scan_config_bits;
268 	param->default_fw_config_bits =	ev->default_fw_config_bits;
269 	param->he_cap_info = ev->he_cap_info;
270 	param->mpdu_density = ev->mpdu_density;
271 	param->max_bssid_rx_filters = ev->max_bssid_rx_filters;
272 	memcpy(&param->ppet, &ev->ppet, sizeof(param->ppet));
273 
274 	return 0;
275 }
276 
277 static int
278 ath11k_pull_mac_phy_cap_svc_ready_ext(struct ath11k_pdev_wmi *wmi_handle,
279 				      struct wmi_soc_mac_phy_hw_mode_caps *hw_caps,
280 				      struct wmi_hw_mode_capabilities *wmi_hw_mode_caps,
281 				      struct wmi_soc_hal_reg_capabilities *hal_reg_caps,
282 				      struct wmi_mac_phy_capabilities *wmi_mac_phy_caps,
283 				      u8 hw_mode_id, u8 phy_id,
284 				      struct ath11k_pdev *pdev)
285 {
286 	struct wmi_mac_phy_capabilities *mac_phy_caps;
287 	struct ath11k_band_cap *cap_band;
288 	struct ath11k_pdev_cap *pdev_cap = &pdev->cap;
289 	u32 phy_map;
290 	u32 hw_idx, phy_idx = 0;
291 
292 	if (!hw_caps || !wmi_hw_mode_caps || !hal_reg_caps)
293 		return -EINVAL;
294 
295 	for (hw_idx = 0; hw_idx < hw_caps->num_hw_modes; hw_idx++) {
296 		if (hw_mode_id == wmi_hw_mode_caps[hw_idx].hw_mode_id)
297 			break;
298 
299 		phy_map = wmi_hw_mode_caps[hw_idx].phy_id_map;
300 		while (phy_map) {
301 			phy_map >>= 1;
302 			phy_idx++;
303 		}
304 	}
305 
306 	if (hw_idx == hw_caps->num_hw_modes)
307 		return -EINVAL;
308 
309 	phy_idx += phy_id;
310 	if (phy_id >= hal_reg_caps->num_phy)
311 		return -EINVAL;
312 
313 	mac_phy_caps = wmi_mac_phy_caps + phy_idx;
314 
315 	pdev->pdev_id = mac_phy_caps->pdev_id;
316 	pdev_cap->supported_bands = mac_phy_caps->supported_bands;
317 	pdev_cap->ampdu_density = mac_phy_caps->ampdu_density;
318 
319 	/* Take non-zero tx/rx chainmask. If tx/rx chainmask differs from
320 	 * band to band for a single radio, need to see how this should be
321 	 * handled.
322 	 */
323 	if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_2G_CAP) {
324 		pdev_cap->tx_chain_mask = mac_phy_caps->tx_chain_mask_2g;
325 		pdev_cap->rx_chain_mask = mac_phy_caps->rx_chain_mask_2g;
326 	} else if (mac_phy_caps->supported_bands & WMI_HOST_WLAN_5G_CAP) {
327 		pdev_cap->vht_cap = mac_phy_caps->vht_cap_info_5g;
328 		pdev_cap->vht_mcs = mac_phy_caps->vht_supp_mcs_5g;
329 		pdev_cap->he_mcs = mac_phy_caps->he_supp_mcs_5g;
330 		pdev_cap->tx_chain_mask = mac_phy_caps->tx_chain_mask_5g;
331 		pdev_cap->rx_chain_mask = mac_phy_caps->rx_chain_mask_5g;
332 	} else {
333 		return -EINVAL;
334 	}
335 
336 	/* tx/rx chainmask reported from fw depends on the actual hw chains used,
337 	 * For example, for 4x4 capable macphys, first 4 chains can be used for first
338 	 * mac and the remaing 4 chains can be used for the second mac or vice-versa.
339 	 * In this case, tx/rx chainmask 0xf will be advertised for first mac and 0xf0
340 	 * will be advertised for second mac or vice-versa. Compute the shift value for
341 	 * for tx/rx chainmask which will be used to advertise supported ht/vht rates to
342 	 * mac80211.
343 	 */
344 	pdev_cap->tx_chain_mask_shift =
345 			find_first_bit((unsigned long *)&pdev_cap->tx_chain_mask, 32);
346 	pdev_cap->rx_chain_mask_shift =
347 			find_first_bit((unsigned long *)&pdev_cap->rx_chain_mask, 32);
348 
349 	cap_band = &pdev_cap->band[NL80211_BAND_2GHZ];
350 	cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_2g;
351 	cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_2g;
352 	cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_2g;
353 	cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_2g_ext;
354 	cap_band->he_mcs = mac_phy_caps->he_supp_mcs_2g;
355 	memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_2g,
356 	       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
357 	memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet2g,
358 	       sizeof(struct ath11k_ppe_threshold));
359 
360 	cap_band = &pdev_cap->band[NL80211_BAND_5GHZ];
361 	cap_band->max_bw_supported = mac_phy_caps->max_bw_supported_5g;
362 	cap_band->ht_cap_info = mac_phy_caps->ht_cap_info_5g;
363 	cap_band->he_cap_info[0] = mac_phy_caps->he_cap_info_5g;
364 	cap_band->he_cap_info[1] = mac_phy_caps->he_cap_info_5g_ext;
365 	cap_band->he_mcs = mac_phy_caps->he_supp_mcs_5g;
366 	memcpy(cap_band->he_cap_phy_info, &mac_phy_caps->he_cap_phy_info_5g,
367 	       sizeof(u32) * PSOC_HOST_MAX_PHY_SIZE);
368 	memcpy(&cap_band->he_ppet, &mac_phy_caps->he_ppet5g,
369 	       sizeof(struct ath11k_ppe_threshold));
370 
371 	return 0;
372 }
373 
374 static int
375 ath11k_pull_reg_cap_svc_rdy_ext(struct ath11k_pdev_wmi *wmi_handle,
376 				struct wmi_soc_hal_reg_capabilities *reg_caps,
377 				struct wmi_hal_reg_capabilities_ext *wmi_ext_reg_cap,
378 				u8 phy_idx,
379 				struct ath11k_hal_reg_capabilities_ext *param)
380 {
381 	struct wmi_hal_reg_capabilities_ext *ext_reg_cap;
382 
383 	if (!reg_caps || !wmi_ext_reg_cap)
384 		return -EINVAL;
385 
386 	if (phy_idx >= reg_caps->num_phy)
387 		return -EINVAL;
388 
389 	ext_reg_cap = &wmi_ext_reg_cap[phy_idx];
390 
391 	param->phy_id = ext_reg_cap->phy_id;
392 	param->eeprom_reg_domain = ext_reg_cap->eeprom_reg_domain;
393 	param->eeprom_reg_domain_ext =
394 			      ext_reg_cap->eeprom_reg_domain_ext;
395 	param->regcap1 = ext_reg_cap->regcap1;
396 	param->regcap2 = ext_reg_cap->regcap2;
397 	/* check if param->wireless_mode is needed */
398 	param->low_2ghz_chan = ext_reg_cap->low_2ghz_chan;
399 	param->high_2ghz_chan = ext_reg_cap->high_2ghz_chan;
400 	param->low_5ghz_chan = ext_reg_cap->low_5ghz_chan;
401 	param->high_5ghz_chan = ext_reg_cap->high_5ghz_chan;
402 
403 	return 0;
404 }
405 
406 static int ath11k_pull_service_ready_tlv(struct ath11k_base *ab,
407 					 const void *evt_buf,
408 					 struct ath11k_targ_cap *cap)
409 {
410 	const struct wmi_service_ready_event *ev = evt_buf;
411 
412 	if (!ev) {
413 		ath11k_err(ab, "%s: failed by NULL param\n",
414 			   __func__);
415 		return -EINVAL;
416 	}
417 
418 	cap->phy_capability = ev->phy_capability;
419 	cap->max_frag_entry = ev->max_frag_entry;
420 	cap->num_rf_chains = ev->num_rf_chains;
421 	cap->ht_cap_info = ev->ht_cap_info;
422 	cap->vht_cap_info = ev->vht_cap_info;
423 	cap->vht_supp_mcs = ev->vht_supp_mcs;
424 	cap->hw_min_tx_power = ev->hw_min_tx_power;
425 	cap->hw_max_tx_power = ev->hw_max_tx_power;
426 	cap->sys_cap_info = ev->sys_cap_info;
427 	cap->min_pkt_size_enable = ev->min_pkt_size_enable;
428 	cap->max_bcn_ie_size = ev->max_bcn_ie_size;
429 	cap->max_num_scan_channels = ev->max_num_scan_channels;
430 	cap->max_supported_macs = ev->max_supported_macs;
431 	cap->wmi_fw_sub_feat_caps = ev->wmi_fw_sub_feat_caps;
432 	cap->txrx_chainmask = ev->txrx_chainmask;
433 	cap->default_dbs_hw_mode_index = ev->default_dbs_hw_mode_index;
434 	cap->num_msdu_desc = ev->num_msdu_desc;
435 
436 	return 0;
437 }
438 
439 /* Save the wmi_service_bitmap into a linear bitmap. The wmi_services in
440  * wmi_service ready event are advertised in b0-b3 (LSB 4-bits) of each
441  * 4-byte word.
442  */
443 static void ath11k_wmi_service_bitmap_copy(struct ath11k_pdev_wmi *wmi,
444 					   const u32 *wmi_svc_bm)
445 {
446 	int i, j;
447 
448 	for (i = 0, j = 0; i < WMI_SERVICE_BM_SIZE && j < WMI_MAX_SERVICE; i++) {
449 		do {
450 			if (wmi_svc_bm[i] & BIT(j % WMI_SERVICE_BITS_IN_SIZE32))
451 				set_bit(j, wmi->wmi_sc->svc_map);
452 		} while (++j % WMI_SERVICE_BITS_IN_SIZE32);
453 	}
454 }
455 
456 static int ath11k_wmi_tlv_svc_rdy_parse(struct ath11k_base *ab, u16 tag, u16 len,
457 					const void *ptr, void *data)
458 {
459 	struct wmi_tlv_svc_ready_parse *svc_ready = data;
460 	struct ath11k_pdev_wmi *wmi_handle = &ab->wmi_sc.wmi[0];
461 	u16 expect_len;
462 
463 	switch (tag) {
464 	case WMI_TAG_SERVICE_READY_EVENT:
465 		if (ath11k_pull_service_ready_tlv(ab, ptr, &ab->target_caps))
466 			return -EINVAL;
467 		break;
468 
469 	case WMI_TAG_ARRAY_UINT32:
470 		if (!svc_ready->wmi_svc_bitmap_done) {
471 			expect_len = WMI_SERVICE_BM_SIZE * sizeof(u32);
472 			if (len < expect_len) {
473 				ath11k_warn(ab, "invalid len %d for the tag 0x%x\n",
474 					    len, tag);
475 				return -EINVAL;
476 			}
477 
478 			ath11k_wmi_service_bitmap_copy(wmi_handle, ptr);
479 
480 			svc_ready->wmi_svc_bitmap_done = true;
481 		}
482 		break;
483 	default:
484 		break;
485 	}
486 
487 	return 0;
488 }
489 
490 static int ath11k_service_ready_event(struct ath11k_base *ab, struct sk_buff *skb)
491 {
492 	struct wmi_tlv_svc_ready_parse svc_ready = { };
493 	int ret;
494 
495 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
496 				  ath11k_wmi_tlv_svc_rdy_parse,
497 				  &svc_ready);
498 	if (ret) {
499 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
500 		return ret;
501 	}
502 
503 	return 0;
504 }
505 
506 struct sk_buff *ath11k_wmi_alloc_skb(struct ath11k_wmi_base *wmi_sc, u32 len)
507 {
508 	struct sk_buff *skb;
509 	struct ath11k_base *ab = wmi_sc->ab;
510 	u32 round_len = roundup(len, 4);
511 
512 	skb = ath11k_htc_alloc_skb(ab, WMI_SKB_HEADROOM + round_len);
513 	if (!skb)
514 		return NULL;
515 
516 	skb_reserve(skb, WMI_SKB_HEADROOM);
517 	if (!IS_ALIGNED((unsigned long)skb->data, 4))
518 		ath11k_warn(ab, "unaligned WMI skb data\n");
519 
520 	skb_put(skb, round_len);
521 	memset(skb->data, 0, round_len);
522 
523 	return skb;
524 }
525 
526 int ath11k_wmi_mgmt_send(struct ath11k *ar, u32 vdev_id, u32 buf_id,
527 			 struct sk_buff *frame)
528 {
529 	struct ath11k_pdev_wmi *wmi = ar->wmi;
530 	struct wmi_mgmt_send_cmd *cmd;
531 	struct wmi_tlv *frame_tlv;
532 	struct sk_buff *skb;
533 	u32 buf_len;
534 	int ret, len;
535 
536 	buf_len = frame->len < WMI_MGMT_SEND_DOWNLD_LEN ?
537 		  frame->len : WMI_MGMT_SEND_DOWNLD_LEN;
538 
539 	len = sizeof(*cmd) + sizeof(*frame_tlv) + roundup(buf_len, 4);
540 
541 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
542 	if (!skb)
543 		return -ENOMEM;
544 
545 	cmd = (struct wmi_mgmt_send_cmd *)skb->data;
546 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_MGMT_TX_SEND_CMD) |
547 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
548 	cmd->vdev_id = vdev_id;
549 	cmd->desc_id = buf_id;
550 	cmd->chanfreq = 0;
551 	cmd->paddr_lo = lower_32_bits(ATH11K_SKB_CB(frame)->paddr);
552 	cmd->paddr_hi = upper_32_bits(ATH11K_SKB_CB(frame)->paddr);
553 	cmd->frame_len = frame->len;
554 	cmd->buf_len = buf_len;
555 	cmd->tx_params_valid = 0;
556 
557 	frame_tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
558 	frame_tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
559 			    FIELD_PREP(WMI_TLV_LEN, buf_len);
560 
561 	memcpy(frame_tlv->value, frame->data, buf_len);
562 
563 	ath11k_ce_byte_swap(frame_tlv->value, buf_len);
564 
565 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_MGMT_TX_SEND_CMDID);
566 	if (ret) {
567 		ath11k_warn(ar->ab,
568 			    "failed to submit WMI_MGMT_TX_SEND_CMDID cmd\n");
569 		dev_kfree_skb(skb);
570 	}
571 
572 	return ret;
573 }
574 
575 int ath11k_wmi_vdev_create(struct ath11k *ar, u8 *macaddr,
576 			   struct vdev_create_params *param)
577 {
578 	struct ath11k_pdev_wmi *wmi = ar->wmi;
579 	struct wmi_vdev_create_cmd *cmd;
580 	struct sk_buff *skb;
581 	struct wmi_vdev_txrx_streams *txrx_streams;
582 	struct wmi_tlv *tlv;
583 	int ret, len;
584 	void *ptr;
585 
586 	/* It can be optimized my sending tx/rx chain configuration
587 	 * only for supported bands instead of always sending it for
588 	 * both the bands.
589 	 */
590 	len = sizeof(*cmd) + TLV_HDR_SIZE +
591 		(WMI_NUM_SUPPORTED_BAND_MAX * sizeof(*txrx_streams));
592 
593 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
594 	if (!skb)
595 		return -ENOMEM;
596 
597 	cmd = (struct wmi_vdev_create_cmd *)skb->data;
598 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_CREATE_CMD) |
599 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
600 
601 	cmd->vdev_id = param->if_id;
602 	cmd->vdev_type = param->type;
603 	cmd->vdev_subtype = param->subtype;
604 	cmd->num_cfg_txrx_streams = WMI_NUM_SUPPORTED_BAND_MAX;
605 	cmd->pdev_id = param->pdev_id;
606 	ether_addr_copy(cmd->vdev_macaddr.addr, macaddr);
607 
608 	ptr = skb->data + sizeof(*cmd);
609 	len = WMI_NUM_SUPPORTED_BAND_MAX * sizeof(*txrx_streams);
610 
611 	tlv = ptr;
612 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
613 		      FIELD_PREP(WMI_TLV_LEN, len);
614 
615 	ptr += TLV_HDR_SIZE;
616 	txrx_streams = ptr;
617 	len = sizeof(*txrx_streams);
618 	txrx_streams->tlv_header =
619 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_TXRX_STREAMS) |
620 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
621 	txrx_streams->band = WMI_TPC_CHAINMASK_CONFIG_BAND_2G;
622 	txrx_streams->supported_tx_streams =
623 				 param->chains[NL80211_BAND_2GHZ].tx;
624 	txrx_streams->supported_rx_streams =
625 				 param->chains[NL80211_BAND_2GHZ].rx;
626 
627 	txrx_streams++;
628 	txrx_streams->tlv_header =
629 		FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_TXRX_STREAMS) |
630 		FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
631 	txrx_streams->band = WMI_TPC_CHAINMASK_CONFIG_BAND_5G;
632 	txrx_streams->supported_tx_streams =
633 				 param->chains[NL80211_BAND_5GHZ].tx;
634 	txrx_streams->supported_rx_streams =
635 				 param->chains[NL80211_BAND_5GHZ].rx;
636 
637 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_CREATE_CMDID);
638 	if (ret) {
639 		ath11k_warn(ar->ab,
640 			    "failed to submit WMI_VDEV_CREATE_CMDID\n");
641 		dev_kfree_skb(skb);
642 	}
643 
644 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
645 		   "WMI vdev create: id %d type %d subtype %d macaddr %pM pdevid %d\n",
646 		   param->if_id, param->type, param->subtype,
647 		   macaddr, param->pdev_id);
648 
649 	return ret;
650 }
651 
652 int ath11k_wmi_vdev_delete(struct ath11k *ar, u8 vdev_id)
653 {
654 	struct ath11k_pdev_wmi *wmi = ar->wmi;
655 	struct wmi_vdev_delete_cmd *cmd;
656 	struct sk_buff *skb;
657 	int ret;
658 
659 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
660 	if (!skb)
661 		return -ENOMEM;
662 
663 	cmd = (struct wmi_vdev_delete_cmd *)skb->data;
664 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_DELETE_CMD) |
665 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
666 	cmd->vdev_id = vdev_id;
667 
668 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_DELETE_CMDID);
669 	if (ret) {
670 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_DELETE_CMDID\n");
671 		dev_kfree_skb(skb);
672 	}
673 
674 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev delete id %d\n", vdev_id);
675 
676 	return ret;
677 }
678 
679 int ath11k_wmi_vdev_stop(struct ath11k *ar, u8 vdev_id)
680 {
681 	struct ath11k_pdev_wmi *wmi = ar->wmi;
682 	struct wmi_vdev_stop_cmd *cmd;
683 	struct sk_buff *skb;
684 	int ret;
685 
686 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
687 	if (!skb)
688 		return -ENOMEM;
689 
690 	cmd = (struct wmi_vdev_stop_cmd *)skb->data;
691 
692 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_STOP_CMD) |
693 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
694 	cmd->vdev_id = vdev_id;
695 
696 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_STOP_CMDID);
697 	if (ret) {
698 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_STOP cmd\n");
699 		dev_kfree_skb(skb);
700 	}
701 
702 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev stop id 0x%x\n", vdev_id);
703 
704 	return ret;
705 }
706 
707 int ath11k_wmi_vdev_down(struct ath11k *ar, u8 vdev_id)
708 {
709 	struct ath11k_pdev_wmi *wmi = ar->wmi;
710 	struct wmi_vdev_down_cmd *cmd;
711 	struct sk_buff *skb;
712 	int ret;
713 
714 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
715 	if (!skb)
716 		return -ENOMEM;
717 
718 	cmd = (struct wmi_vdev_down_cmd *)skb->data;
719 
720 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_DOWN_CMD) |
721 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
722 	cmd->vdev_id = vdev_id;
723 
724 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_DOWN_CMDID);
725 	if (ret) {
726 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_DOWN cmd\n");
727 		dev_kfree_skb(skb);
728 	}
729 
730 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "WMI vdev down id 0x%x\n", vdev_id);
731 
732 	return ret;
733 }
734 
735 static void ath11k_wmi_put_wmi_channel(struct wmi_channel *chan,
736 				       struct wmi_vdev_start_req_arg *arg)
737 {
738 	memset(chan, 0, sizeof(*chan));
739 
740 	chan->mhz = arg->channel.freq;
741 	chan->band_center_freq1 = arg->channel.band_center_freq1;
742 	if (arg->channel.mode == MODE_11AC_VHT80_80)
743 		chan->band_center_freq2 = arg->channel.band_center_freq2;
744 	else
745 		chan->band_center_freq2 = 0;
746 
747 	chan->info |= FIELD_PREP(WMI_CHAN_INFO_MODE, arg->channel.mode);
748 	if (arg->channel.passive)
749 		chan->info |= WMI_CHAN_INFO_PASSIVE;
750 	if (arg->channel.allow_ibss)
751 		chan->info |= WMI_CHAN_INFO_ADHOC_ALLOWED;
752 	if (arg->channel.allow_ht)
753 		chan->info |= WMI_CHAN_INFO_ALLOW_HT;
754 	if (arg->channel.allow_vht)
755 		chan->info |= WMI_CHAN_INFO_ALLOW_VHT;
756 	if (arg->channel.allow_he)
757 		chan->info |= WMI_CHAN_INFO_ALLOW_HE;
758 	if (arg->channel.ht40plus)
759 		chan->info |= WMI_CHAN_INFO_HT40_PLUS;
760 	if (arg->channel.chan_radar)
761 		chan->info |= WMI_CHAN_INFO_DFS;
762 	if (arg->channel.freq2_radar)
763 		chan->info |= WMI_CHAN_INFO_DFS_FREQ2;
764 
765 	chan->reg_info_1 = FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_PWR,
766 				      arg->channel.max_power) |
767 		FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_REG_PWR,
768 			   arg->channel.max_reg_power);
769 
770 	chan->reg_info_2 = FIELD_PREP(WMI_CHAN_REG_INFO2_ANT_MAX,
771 				      arg->channel.max_antenna_gain) |
772 		FIELD_PREP(WMI_CHAN_REG_INFO2_MAX_TX_PWR,
773 			   arg->channel.max_power);
774 }
775 
776 int ath11k_wmi_vdev_start(struct ath11k *ar, struct wmi_vdev_start_req_arg *arg,
777 			  bool restart)
778 {
779 	struct ath11k_pdev_wmi *wmi = ar->wmi;
780 	struct wmi_vdev_start_request_cmd *cmd;
781 	struct sk_buff *skb;
782 	struct wmi_channel *chan;
783 	struct wmi_tlv *tlv;
784 	void *ptr;
785 	int ret, len;
786 
787 	if (WARN_ON(arg->ssid_len > sizeof(cmd->ssid.ssid)))
788 		return -EINVAL;
789 
790 	len = sizeof(*cmd) + sizeof(*chan) + TLV_HDR_SIZE;
791 
792 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
793 	if (!skb)
794 		return -ENOMEM;
795 
796 	cmd = (struct wmi_vdev_start_request_cmd *)skb->data;
797 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
798 				     WMI_TAG_VDEV_START_REQUEST_CMD) |
799 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
800 	cmd->vdev_id = arg->vdev_id;
801 	cmd->beacon_interval = arg->bcn_intval;
802 	cmd->bcn_tx_rate = arg->bcn_tx_rate;
803 	cmd->dtim_period = arg->dtim_period;
804 	cmd->num_noa_descriptors = arg->num_noa_descriptors;
805 	cmd->preferred_rx_streams = arg->pref_rx_streams;
806 	cmd->preferred_tx_streams = arg->pref_tx_streams;
807 	cmd->cac_duration_ms = arg->cac_duration_ms;
808 	cmd->regdomain = arg->regdomain;
809 	cmd->he_ops = arg->he_ops;
810 
811 	if (!restart) {
812 		if (arg->ssid) {
813 			cmd->ssid.ssid_len = arg->ssid_len;
814 			memcpy(cmd->ssid.ssid, arg->ssid, arg->ssid_len);
815 		}
816 		if (arg->hidden_ssid)
817 			cmd->flags |= WMI_VDEV_START_HIDDEN_SSID;
818 		if (arg->pmf_enabled)
819 			cmd->flags |= WMI_VDEV_START_PMF_ENABLED;
820 	}
821 
822 	cmd->flags |= WMI_VDEV_START_LDPC_RX_ENABLED;
823 
824 	ptr = skb->data + sizeof(*cmd);
825 	chan = ptr;
826 
827 	ath11k_wmi_put_wmi_channel(chan, arg);
828 
829 	chan->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_CHANNEL) |
830 			   FIELD_PREP(WMI_TLV_LEN,
831 				      sizeof(*chan) - TLV_HDR_SIZE);
832 	ptr += sizeof(*chan);
833 
834 	tlv = ptr;
835 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
836 		      FIELD_PREP(WMI_TLV_LEN, 0);
837 
838 	/* Note: This is a nested TLV containing:
839 	 * [wmi_tlv][wmi_p2p_noa_descriptor][wmi_tlv]..
840 	 */
841 
842 	ptr += sizeof(*tlv);
843 
844 	if (restart)
845 		ret = ath11k_wmi_cmd_send(wmi, skb,
846 					  WMI_VDEV_RESTART_REQUEST_CMDID);
847 	else
848 		ret = ath11k_wmi_cmd_send(wmi, skb,
849 					  WMI_VDEV_START_REQUEST_CMDID);
850 	if (ret) {
851 		ath11k_warn(ar->ab, "failed to submit vdev_%s cmd\n",
852 			    restart ? "restart" : "start");
853 		dev_kfree_skb(skb);
854 	}
855 
856 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI, "vdev %s id 0x%x freq 0x%x mode 0x%x\n",
857 		   restart ? "restart" : "start", arg->vdev_id,
858 		   arg->channel.freq, arg->channel.mode);
859 
860 	return ret;
861 }
862 
863 int ath11k_wmi_vdev_up(struct ath11k *ar, u32 vdev_id, u32 aid, const u8 *bssid)
864 {
865 	struct ath11k_pdev_wmi *wmi = ar->wmi;
866 	struct wmi_vdev_up_cmd *cmd;
867 	struct sk_buff *skb;
868 	int ret;
869 
870 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
871 	if (!skb)
872 		return -ENOMEM;
873 
874 	cmd = (struct wmi_vdev_up_cmd *)skb->data;
875 
876 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_UP_CMD) |
877 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
878 	cmd->vdev_id = vdev_id;
879 	cmd->vdev_assoc_id = aid;
880 
881 	ether_addr_copy(cmd->vdev_bssid.addr, bssid);
882 
883 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_UP_CMDID);
884 	if (ret) {
885 		ath11k_warn(ar->ab, "failed to submit WMI_VDEV_UP cmd\n");
886 		dev_kfree_skb(skb);
887 	}
888 
889 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
890 		   "WMI mgmt vdev up id 0x%x assoc id %d bssid %pM\n",
891 		   vdev_id, aid, bssid);
892 
893 	return ret;
894 }
895 
896 int ath11k_wmi_send_peer_create_cmd(struct ath11k *ar,
897 				    struct peer_create_params *param)
898 {
899 	struct ath11k_pdev_wmi *wmi = ar->wmi;
900 	struct wmi_peer_create_cmd *cmd;
901 	struct sk_buff *skb;
902 	int ret;
903 
904 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
905 	if (!skb)
906 		return -ENOMEM;
907 
908 	cmd = (struct wmi_peer_create_cmd *)skb->data;
909 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_CREATE_CMD) |
910 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
911 
912 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_addr);
913 	cmd->peer_type = param->peer_type;
914 	cmd->vdev_id = param->vdev_id;
915 
916 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_CREATE_CMDID);
917 	if (ret) {
918 		ath11k_warn(ar->ab, "failed to submit WMI_PEER_CREATE cmd\n");
919 		dev_kfree_skb(skb);
920 	}
921 
922 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
923 		   "WMI peer create vdev_id %d peer_addr %pM\n",
924 		   param->vdev_id, param->peer_addr);
925 
926 	return ret;
927 }
928 
929 int ath11k_wmi_send_peer_delete_cmd(struct ath11k *ar,
930 				    const u8 *peer_addr, u8 vdev_id)
931 {
932 	struct ath11k_pdev_wmi *wmi = ar->wmi;
933 	struct wmi_peer_delete_cmd *cmd;
934 	struct sk_buff *skb;
935 	int ret;
936 
937 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
938 	if (!skb)
939 		return -ENOMEM;
940 
941 	cmd = (struct wmi_peer_delete_cmd *)skb->data;
942 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_DELETE_CMD) |
943 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
944 
945 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
946 	cmd->vdev_id = vdev_id;
947 
948 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
949 		   "WMI peer delete vdev_id %d peer_addr %pM\n",
950 		   vdev_id,  peer_addr);
951 
952 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_DELETE_CMDID);
953 	if (ret) {
954 		ath11k_warn(ar->ab, "failed to send WMI_PEER_DELETE cmd\n");
955 		dev_kfree_skb(skb);
956 	}
957 
958 	return ret;
959 }
960 
961 int ath11k_wmi_send_pdev_set_regdomain(struct ath11k *ar,
962 				       struct pdev_set_regdomain_params *param)
963 {
964 	struct ath11k_pdev_wmi *wmi = ar->wmi;
965 	struct wmi_pdev_set_regdomain_cmd *cmd;
966 	struct sk_buff *skb;
967 	int ret;
968 
969 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
970 	if (!skb)
971 		return -ENOMEM;
972 
973 	cmd = (struct wmi_pdev_set_regdomain_cmd *)skb->data;
974 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
975 				     WMI_TAG_PDEV_SET_REGDOMAIN_CMD) |
976 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
977 
978 	cmd->reg_domain = param->current_rd_in_use;
979 	cmd->reg_domain_2g = param->current_rd_2g;
980 	cmd->reg_domain_5g = param->current_rd_5g;
981 	cmd->conformance_test_limit_2g = param->ctl_2g;
982 	cmd->conformance_test_limit_5g = param->ctl_5g;
983 	cmd->dfs_domain = param->dfs_domain;
984 	cmd->pdev_id = param->pdev_id;
985 
986 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
987 		   "WMI pdev regd rd %d rd2g %d rd5g %d domain %d pdev id %d\n",
988 		   param->current_rd_in_use, param->current_rd_2g,
989 		   param->current_rd_5g, param->dfs_domain, param->pdev_id);
990 
991 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SET_REGDOMAIN_CMDID);
992 	if (ret) {
993 		ath11k_warn(ar->ab,
994 			    "failed to send WMI_PDEV_SET_REGDOMAIN cmd\n");
995 		dev_kfree_skb(skb);
996 	}
997 
998 	return ret;
999 }
1000 
1001 int ath11k_wmi_set_peer_param(struct ath11k *ar, const u8 *peer_addr,
1002 			      u32 vdev_id, u32 param_id, u32 param_val)
1003 {
1004 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1005 	struct wmi_peer_set_param_cmd *cmd;
1006 	struct sk_buff *skb;
1007 	int ret;
1008 
1009 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1010 	if (!skb)
1011 		return -ENOMEM;
1012 
1013 	cmd = (struct wmi_peer_set_param_cmd *)skb->data;
1014 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_SET_PARAM_CMD) |
1015 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1016 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1017 	cmd->vdev_id = vdev_id;
1018 	cmd->param_id = param_id;
1019 	cmd->param_value = param_val;
1020 
1021 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_SET_PARAM_CMDID);
1022 	if (ret) {
1023 		ath11k_warn(ar->ab, "failed to send WMI_PEER_SET_PARAM cmd\n");
1024 		dev_kfree_skb(skb);
1025 	}
1026 
1027 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1028 		   "WMI vdev %d peer 0x%pM set param %d value %d\n",
1029 		   vdev_id, peer_addr, param_id, param_val);
1030 
1031 	return ret;
1032 }
1033 
1034 int ath11k_wmi_send_peer_flush_tids_cmd(struct ath11k *ar,
1035 					u8 peer_addr[ETH_ALEN],
1036 					struct peer_flush_params *param)
1037 {
1038 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1039 	struct wmi_peer_flush_tids_cmd *cmd;
1040 	struct sk_buff *skb;
1041 	int ret;
1042 
1043 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1044 	if (!skb)
1045 		return -ENOMEM;
1046 
1047 	cmd = (struct wmi_peer_flush_tids_cmd *)skb->data;
1048 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PEER_FLUSH_TIDS_CMD) |
1049 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1050 
1051 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1052 	cmd->peer_tid_bitmap = param->peer_tid_bitmap;
1053 	cmd->vdev_id = param->vdev_id;
1054 
1055 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_FLUSH_TIDS_CMDID);
1056 	if (ret) {
1057 		ath11k_warn(ar->ab,
1058 			    "failed to send WMI_PEER_FLUSH_TIDS cmd\n");
1059 		dev_kfree_skb(skb);
1060 	}
1061 
1062 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1063 		   "WMI peer flush vdev_id %d peer_addr %pM tids %08x\n",
1064 		   param->vdev_id, peer_addr, param->peer_tid_bitmap);
1065 
1066 	return ret;
1067 }
1068 
1069 int ath11k_wmi_peer_rx_reorder_queue_setup(struct ath11k *ar,
1070 					   int vdev_id, const u8 *addr,
1071 					   dma_addr_t paddr, u8 tid,
1072 					   u8 ba_window_size_valid,
1073 					   u32 ba_window_size)
1074 {
1075 	struct wmi_peer_reorder_queue_setup_cmd *cmd;
1076 	struct sk_buff *skb;
1077 	int ret;
1078 
1079 	skb = ath11k_wmi_alloc_skb(ar->wmi->wmi_sc, sizeof(*cmd));
1080 	if (!skb)
1081 		return -ENOMEM;
1082 
1083 	cmd = (struct wmi_peer_reorder_queue_setup_cmd *)skb->data;
1084 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1085 				     WMI_TAG_REORDER_QUEUE_SETUP_CMD) |
1086 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1087 
1088 	ether_addr_copy(cmd->peer_macaddr.addr, addr);
1089 	cmd->vdev_id = vdev_id;
1090 	cmd->tid = tid;
1091 	cmd->queue_ptr_lo = lower_32_bits(paddr);
1092 	cmd->queue_ptr_hi = upper_32_bits(paddr);
1093 	cmd->queue_no = tid;
1094 	cmd->ba_window_size_valid = ba_window_size_valid;
1095 	cmd->ba_window_size = ba_window_size;
1096 
1097 	ret = ath11k_wmi_cmd_send(ar->wmi, skb,
1098 				  WMI_PEER_REORDER_QUEUE_SETUP_CMDID);
1099 	if (ret) {
1100 		ath11k_warn(ar->ab,
1101 			    "failed to send WMI_PEER_REORDER_QUEUE_SETUP\n");
1102 		dev_kfree_skb(skb);
1103 	}
1104 
1105 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1106 		   "wmi rx reorder queue setup addr %pM vdev_id %d tid %d\n",
1107 		   addr, vdev_id, tid);
1108 
1109 	return ret;
1110 }
1111 
1112 int
1113 ath11k_wmi_rx_reord_queue_remove(struct ath11k *ar,
1114 				 struct rx_reorder_queue_remove_params *param)
1115 {
1116 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1117 	struct wmi_peer_reorder_queue_remove_cmd *cmd;
1118 	struct sk_buff *skb;
1119 	int ret;
1120 
1121 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1122 	if (!skb)
1123 		return -ENOMEM;
1124 
1125 	cmd = (struct wmi_peer_reorder_queue_remove_cmd *)skb->data;
1126 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1127 				     WMI_TAG_REORDER_QUEUE_REMOVE_CMD) |
1128 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1129 
1130 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_macaddr);
1131 	cmd->vdev_id = param->vdev_id;
1132 	cmd->tid_mask = param->peer_tid_bitmap;
1133 
1134 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1135 		   "%s: peer_macaddr %pM vdev_id %d, tid_map %d", __func__,
1136 		   param->peer_macaddr, param->vdev_id, param->peer_tid_bitmap);
1137 
1138 	ret = ath11k_wmi_cmd_send(wmi, skb,
1139 				  WMI_PEER_REORDER_QUEUE_REMOVE_CMDID);
1140 	if (ret) {
1141 		ath11k_warn(ar->ab,
1142 			    "failed to send WMI_PEER_REORDER_QUEUE_REMOVE_CMDID");
1143 		dev_kfree_skb(skb);
1144 	}
1145 
1146 	return ret;
1147 }
1148 
1149 int ath11k_wmi_pdev_set_param(struct ath11k *ar, u32 param_id,
1150 			      u32 param_value, u8 pdev_id)
1151 {
1152 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1153 	struct wmi_pdev_set_param_cmd *cmd;
1154 	struct sk_buff *skb;
1155 	int ret;
1156 
1157 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1158 	if (!skb)
1159 		return -ENOMEM;
1160 
1161 	cmd = (struct wmi_pdev_set_param_cmd *)skb->data;
1162 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_SET_PARAM_CMD) |
1163 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1164 	cmd->pdev_id = pdev_id;
1165 	cmd->param_id = param_id;
1166 	cmd->param_value = param_value;
1167 
1168 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SET_PARAM_CMDID);
1169 	if (ret) {
1170 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SET_PARAM cmd\n");
1171 		dev_kfree_skb(skb);
1172 	}
1173 
1174 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1175 		   "WMI pdev set param %d pdev id %d value %d\n",
1176 		   param_id, pdev_id, param_value);
1177 
1178 	return ret;
1179 }
1180 
1181 int ath11k_wmi_pdev_suspend(struct ath11k *ar, u32 suspend_opt,
1182 			    u32 pdev_id)
1183 {
1184 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1185 	struct wmi_pdev_suspend_cmd *cmd;
1186 	struct sk_buff *skb;
1187 	int ret;
1188 
1189 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1190 	if (!skb)
1191 		return -ENOMEM;
1192 
1193 	cmd = (struct wmi_pdev_suspend_cmd *)skb->data;
1194 
1195 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_SUSPEND_CMD) |
1196 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1197 
1198 	cmd->suspend_opt = suspend_opt;
1199 	cmd->pdev_id = pdev_id;
1200 
1201 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_SUSPEND_CMDID);
1202 	if (ret) {
1203 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_SUSPEND cmd\n");
1204 		dev_kfree_skb(skb);
1205 	}
1206 
1207 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1208 		   "WMI pdev suspend pdev_id %d\n", pdev_id);
1209 
1210 	return ret;
1211 }
1212 
1213 int ath11k_wmi_pdev_resume(struct ath11k *ar, u32 pdev_id)
1214 {
1215 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1216 	struct wmi_pdev_resume_cmd *cmd;
1217 	struct sk_buff *skb;
1218 	int ret;
1219 
1220 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1221 	if (!skb)
1222 		return -ENOMEM;
1223 
1224 	cmd = (struct wmi_pdev_resume_cmd *)skb->data;
1225 
1226 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_RESUME_CMD) |
1227 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1228 	cmd->pdev_id = pdev_id;
1229 
1230 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1231 		   "WMI pdev resume pdev id %d\n", pdev_id);
1232 
1233 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PDEV_RESUME_CMDID);
1234 	if (ret) {
1235 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_RESUME cmd\n");
1236 		dev_kfree_skb(skb);
1237 	}
1238 
1239 	return ret;
1240 }
1241 
1242 /* TODO FW Support for the cmd is not available yet.
1243  * Can be tested once the command and corresponding
1244  * event is implemented in FW
1245  */
1246 int ath11k_wmi_pdev_bss_chan_info_request(struct ath11k *ar,
1247 					  enum wmi_bss_chan_info_req_type type)
1248 {
1249 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1250 	struct wmi_pdev_bss_chan_info_req_cmd *cmd;
1251 	struct sk_buff *skb;
1252 	int ret;
1253 
1254 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1255 	if (!skb)
1256 		return -ENOMEM;
1257 
1258 	cmd = (struct wmi_pdev_bss_chan_info_req_cmd *)skb->data;
1259 
1260 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1261 				     WMI_TAG_PDEV_BSS_CHAN_INFO_REQUEST) |
1262 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1263 	cmd->req_type = type;
1264 
1265 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1266 		   "WMI bss chan info req type %d\n", type);
1267 
1268 	ret = ath11k_wmi_cmd_send(wmi, skb,
1269 				  WMI_PDEV_BSS_CHAN_INFO_REQUEST_CMDID);
1270 	if (ret) {
1271 		ath11k_warn(ar->ab,
1272 			    "failed to send WMI_PDEV_BSS_CHAN_INFO_REQUEST cmd\n");
1273 		dev_kfree_skb(skb);
1274 	}
1275 
1276 	return ret;
1277 }
1278 
1279 int ath11k_wmi_send_set_ap_ps_param_cmd(struct ath11k *ar, u8 *peer_addr,
1280 					struct ap_ps_params *param)
1281 {
1282 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1283 	struct wmi_ap_ps_peer_cmd *cmd;
1284 	struct sk_buff *skb;
1285 	int ret;
1286 
1287 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1288 	if (!skb)
1289 		return -ENOMEM;
1290 
1291 	cmd = (struct wmi_ap_ps_peer_cmd *)skb->data;
1292 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_AP_PS_PEER_CMD) |
1293 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1294 
1295 	cmd->vdev_id = param->vdev_id;
1296 	ether_addr_copy(cmd->peer_macaddr.addr, peer_addr);
1297 	cmd->param = param->param;
1298 	cmd->value = param->value;
1299 
1300 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_AP_PS_PEER_PARAM_CMDID);
1301 	if (ret) {
1302 		ath11k_warn(ar->ab,
1303 			    "failed to send WMI_AP_PS_PEER_PARAM_CMDID\n");
1304 		dev_kfree_skb(skb);
1305 	}
1306 
1307 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1308 		   "WMI set ap ps vdev id %d peer %pM param %d value %d\n",
1309 		   param->vdev_id, peer_addr, param->param, param->value);
1310 
1311 	return ret;
1312 }
1313 
1314 int ath11k_wmi_set_sta_ps_param(struct ath11k *ar, u32 vdev_id,
1315 				u32 param, u32 param_value)
1316 {
1317 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1318 	struct wmi_sta_powersave_param_cmd *cmd;
1319 	struct sk_buff *skb;
1320 	int ret;
1321 
1322 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1323 	if (!skb)
1324 		return -ENOMEM;
1325 
1326 	cmd = (struct wmi_sta_powersave_param_cmd *)skb->data;
1327 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1328 				     WMI_TAG_STA_POWERSAVE_PARAM_CMD) |
1329 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1330 
1331 	cmd->vdev_id = vdev_id;
1332 	cmd->param = param;
1333 	cmd->value = param_value;
1334 
1335 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1336 		   "WMI set sta ps vdev_id %d param %d value %d\n",
1337 		   vdev_id, param, param_value);
1338 
1339 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_STA_POWERSAVE_PARAM_CMDID);
1340 	if (ret) {
1341 		ath11k_warn(ar->ab, "failed to send WMI_STA_POWERSAVE_PARAM_CMDID");
1342 		dev_kfree_skb(skb);
1343 	}
1344 
1345 	return ret;
1346 }
1347 
1348 int ath11k_wmi_force_fw_hang_cmd(struct ath11k *ar, u32 type, u32 delay_time_ms)
1349 {
1350 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1351 	struct wmi_force_fw_hang_cmd *cmd;
1352 	struct sk_buff *skb;
1353 	int ret, len;
1354 
1355 	len = sizeof(*cmd);
1356 
1357 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
1358 	if (!skb)
1359 		return -ENOMEM;
1360 
1361 	cmd = (struct wmi_force_fw_hang_cmd *)skb->data;
1362 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_FORCE_FW_HANG_CMD) |
1363 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
1364 
1365 	cmd->type = type;
1366 	cmd->delay_time_ms = delay_time_ms;
1367 
1368 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_FORCE_FW_HANG_CMDID);
1369 
1370 	if (ret) {
1371 		ath11k_warn(ar->ab, "Failed to send WMI_FORCE_FW_HANG_CMDID");
1372 		dev_kfree_skb(skb);
1373 	}
1374 	return ret;
1375 }
1376 
1377 int ath11k_wmi_vdev_set_param_cmd(struct ath11k *ar, u32 vdev_id,
1378 				  u32 param_id, u32 param_value)
1379 {
1380 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1381 	struct wmi_vdev_set_param_cmd *cmd;
1382 	struct sk_buff *skb;
1383 	int ret;
1384 
1385 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1386 	if (!skb)
1387 		return -ENOMEM;
1388 
1389 	cmd = (struct wmi_vdev_set_param_cmd *)skb->data;
1390 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_SET_PARAM_CMD) |
1391 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1392 
1393 	cmd->vdev_id = vdev_id;
1394 	cmd->param_id = param_id;
1395 	cmd->param_value = param_value;
1396 
1397 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_SET_PARAM_CMDID);
1398 	if (ret) {
1399 		ath11k_warn(ar->ab,
1400 			    "failed to send WMI_VDEV_SET_PARAM_CMDID\n");
1401 		dev_kfree_skb(skb);
1402 	}
1403 
1404 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1405 		   "WMI vdev id 0x%x set param %d value %d\n",
1406 		   vdev_id, param_id, param_value);
1407 
1408 	return ret;
1409 }
1410 
1411 int ath11k_wmi_send_stats_request_cmd(struct ath11k *ar,
1412 				      struct stats_request_params *param)
1413 {
1414 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1415 	struct wmi_request_stats_cmd *cmd;
1416 	struct sk_buff *skb;
1417 	int ret;
1418 
1419 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1420 	if (!skb)
1421 		return -ENOMEM;
1422 
1423 	cmd = (struct wmi_request_stats_cmd *)skb->data;
1424 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_REQUEST_STATS_CMD) |
1425 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1426 
1427 	cmd->stats_id = param->stats_id;
1428 	cmd->vdev_id = param->vdev_id;
1429 	cmd->pdev_id = param->pdev_id;
1430 
1431 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_REQUEST_STATS_CMDID);
1432 	if (ret) {
1433 		ath11k_warn(ar->ab, "failed to send WMI_REQUEST_STATS cmd\n");
1434 		dev_kfree_skb(skb);
1435 	}
1436 
1437 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1438 		   "WMI request stats 0x%x vdev id %d pdev id %d\n",
1439 		   param->stats_id, param->vdev_id, param->pdev_id);
1440 
1441 	return ret;
1442 }
1443 
1444 int ath11k_wmi_send_bcn_offload_control_cmd(struct ath11k *ar,
1445 					    u32 vdev_id, u32 bcn_ctrl_op)
1446 {
1447 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1448 	struct wmi_bcn_offload_ctrl_cmd *cmd;
1449 	struct sk_buff *skb;
1450 	int ret;
1451 
1452 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
1453 	if (!skb)
1454 		return -ENOMEM;
1455 
1456 	cmd = (struct wmi_bcn_offload_ctrl_cmd *)skb->data;
1457 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1458 				     WMI_TAG_BCN_OFFLOAD_CTRL_CMD) |
1459 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1460 
1461 	cmd->vdev_id = vdev_id;
1462 	cmd->bcn_ctrl_op = bcn_ctrl_op;
1463 
1464 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1465 		   "WMI bcn ctrl offload vdev id %d ctrl_op %d\n",
1466 		   vdev_id, bcn_ctrl_op);
1467 
1468 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_BCN_OFFLOAD_CTRL_CMDID);
1469 	if (ret) {
1470 		ath11k_warn(ar->ab,
1471 			    "failed to send WMI_BCN_OFFLOAD_CTRL_CMDID\n");
1472 		dev_kfree_skb(skb);
1473 	}
1474 
1475 	return ret;
1476 }
1477 
1478 int ath11k_wmi_bcn_tmpl(struct ath11k *ar, u32 vdev_id,
1479 			struct ieee80211_mutable_offsets *offs,
1480 			struct sk_buff *bcn)
1481 {
1482 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1483 	struct wmi_bcn_tmpl_cmd *cmd;
1484 	struct wmi_bcn_prb_info *bcn_prb_info;
1485 	struct wmi_tlv *tlv;
1486 	struct sk_buff *skb;
1487 	void *ptr;
1488 	int ret, len;
1489 	size_t aligned_len = roundup(bcn->len, 4);
1490 
1491 	len = sizeof(*cmd) + sizeof(*bcn_prb_info) + TLV_HDR_SIZE + aligned_len;
1492 
1493 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
1494 	if (!skb)
1495 		return -ENOMEM;
1496 
1497 	cmd = (struct wmi_bcn_tmpl_cmd *)skb->data;
1498 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_BCN_TMPL_CMD) |
1499 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1500 	cmd->vdev_id = vdev_id;
1501 	cmd->tim_ie_offset = offs->tim_offset;
1502 	cmd->csa_switch_count_offset = offs->csa_counter_offs[0];
1503 	cmd->ext_csa_switch_count_offset = offs->csa_counter_offs[1];
1504 	cmd->buf_len = bcn->len;
1505 
1506 	ptr = skb->data + sizeof(*cmd);
1507 
1508 	bcn_prb_info = ptr;
1509 	len = sizeof(*bcn_prb_info);
1510 	bcn_prb_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1511 					      WMI_TAG_BCN_PRB_INFO) |
1512 				   FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
1513 	bcn_prb_info->caps = 0;
1514 	bcn_prb_info->erp = 0;
1515 
1516 	ptr += sizeof(*bcn_prb_info);
1517 
1518 	tlv = ptr;
1519 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1520 		      FIELD_PREP(WMI_TLV_LEN, aligned_len);
1521 	memcpy(tlv->value, bcn->data, bcn->len);
1522 
1523 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_BCN_TMPL_CMDID);
1524 	if (ret) {
1525 		ath11k_warn(ar->ab, "failed to send WMI_BCN_TMPL_CMDID\n");
1526 		dev_kfree_skb(skb);
1527 	}
1528 
1529 	return ret;
1530 }
1531 
1532 int ath11k_wmi_vdev_install_key(struct ath11k *ar,
1533 				struct wmi_vdev_install_key_arg *arg)
1534 {
1535 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1536 	struct wmi_vdev_install_key_cmd *cmd;
1537 	struct wmi_tlv *tlv;
1538 	struct sk_buff *skb;
1539 	int ret, len;
1540 	int key_len_aligned = roundup(arg->key_len, sizeof(uint32_t));
1541 
1542 	len = sizeof(*cmd) + TLV_HDR_SIZE + key_len_aligned;
1543 
1544 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
1545 	if (!skb)
1546 		return -ENOMEM;
1547 
1548 	cmd = (struct wmi_vdev_install_key_cmd *)skb->data;
1549 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VDEV_INSTALL_KEY_CMD) |
1550 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1551 	cmd->vdev_id = arg->vdev_id;
1552 	ether_addr_copy(cmd->peer_macaddr.addr, arg->macaddr);
1553 	cmd->key_idx = arg->key_idx;
1554 	cmd->key_flags = arg->key_flags;
1555 	cmd->key_cipher = arg->key_cipher;
1556 	cmd->key_len = arg->key_len;
1557 	cmd->key_txmic_len = arg->key_txmic_len;
1558 	cmd->key_rxmic_len = arg->key_rxmic_len;
1559 
1560 	if (arg->key_rsc_counter)
1561 		memcpy(&cmd->key_rsc_counter, &arg->key_rsc_counter,
1562 		       sizeof(struct wmi_key_seq_counter));
1563 
1564 	tlv = (struct wmi_tlv *)(skb->data + sizeof(*cmd));
1565 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1566 		      FIELD_PREP(WMI_TLV_LEN, key_len_aligned);
1567 	memcpy(tlv->value, (u8 *)arg->key_data, key_len_aligned);
1568 
1569 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_VDEV_INSTALL_KEY_CMDID);
1570 	if (ret) {
1571 		ath11k_warn(ar->ab,
1572 			    "failed to send WMI_VDEV_INSTALL_KEY cmd\n");
1573 		dev_kfree_skb(skb);
1574 	}
1575 
1576 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1577 		   "WMI vdev install key idx %d cipher %d len %d\n",
1578 		   arg->key_idx, arg->key_cipher, arg->key_len);
1579 
1580 	return ret;
1581 }
1582 
1583 static inline void
1584 ath11k_wmi_copy_peer_flags(struct wmi_peer_assoc_complete_cmd *cmd,
1585 			   struct peer_assoc_params *param)
1586 {
1587 	cmd->peer_flags = 0;
1588 
1589 	if (param->is_wme_set) {
1590 		if (param->qos_flag)
1591 			cmd->peer_flags |= WMI_PEER_QOS;
1592 		if (param->apsd_flag)
1593 			cmd->peer_flags |= WMI_PEER_APSD;
1594 		if (param->ht_flag)
1595 			cmd->peer_flags |= WMI_PEER_HT;
1596 		if (param->bw_40)
1597 			cmd->peer_flags |= WMI_PEER_40MHZ;
1598 		if (param->bw_80)
1599 			cmd->peer_flags |= WMI_PEER_80MHZ;
1600 		if (param->bw_160)
1601 			cmd->peer_flags |= WMI_PEER_160MHZ;
1602 
1603 		/* Typically if STBC is enabled for VHT it should be enabled
1604 		 * for HT as well
1605 		 **/
1606 		if (param->stbc_flag)
1607 			cmd->peer_flags |= WMI_PEER_STBC;
1608 
1609 		/* Typically if LDPC is enabled for VHT it should be enabled
1610 		 * for HT as well
1611 		 **/
1612 		if (param->ldpc_flag)
1613 			cmd->peer_flags |= WMI_PEER_LDPC;
1614 
1615 		if (param->static_mimops_flag)
1616 			cmd->peer_flags |= WMI_PEER_STATIC_MIMOPS;
1617 		if (param->dynamic_mimops_flag)
1618 			cmd->peer_flags |= WMI_PEER_DYN_MIMOPS;
1619 		if (param->spatial_mux_flag)
1620 			cmd->peer_flags |= WMI_PEER_SPATIAL_MUX;
1621 		if (param->vht_flag)
1622 			cmd->peer_flags |= WMI_PEER_VHT;
1623 		if (param->he_flag)
1624 			cmd->peer_flags |= WMI_PEER_HE;
1625 		if (param->twt_requester)
1626 			cmd->peer_flags |= WMI_PEER_TWT_REQ;
1627 		if (param->twt_responder)
1628 			cmd->peer_flags |= WMI_PEER_TWT_RESP;
1629 	}
1630 
1631 	/* Suppress authorization for all AUTH modes that need 4-way handshake
1632 	 * (during re-association).
1633 	 * Authorization will be done for these modes on key installation.
1634 	 */
1635 	if (param->auth_flag)
1636 		cmd->peer_flags |= WMI_PEER_AUTH;
1637 	if (param->need_ptk_4_way)
1638 		cmd->peer_flags |= WMI_PEER_NEED_PTK_4_WAY;
1639 	else
1640 		cmd->peer_flags &= ~WMI_PEER_NEED_PTK_4_WAY;
1641 	if (param->need_gtk_2_way)
1642 		cmd->peer_flags |= WMI_PEER_NEED_GTK_2_WAY;
1643 	/* safe mode bypass the 4-way handshake */
1644 	if (param->safe_mode_enabled)
1645 		cmd->peer_flags &= ~(WMI_PEER_NEED_PTK_4_WAY |
1646 				     WMI_PEER_NEED_GTK_2_WAY);
1647 
1648 	if (param->is_pmf_enabled)
1649 		cmd->peer_flags |= WMI_PEER_PMF;
1650 
1651 	/* Disable AMSDU for station transmit, if user configures it */
1652 	/* Disable AMSDU for AP transmit to 11n Stations, if user configures
1653 	 * it
1654 	 * if (param->amsdu_disable) Add after FW support
1655 	 **/
1656 
1657 	/* Target asserts if node is marked HT and all MCS is set to 0.
1658 	 * Mark the node as non-HT if all the mcs rates are disabled through
1659 	 * iwpriv
1660 	 **/
1661 	if (param->peer_ht_rates.num_rates == 0)
1662 		cmd->peer_flags &= ~WMI_PEER_HT;
1663 }
1664 
1665 int ath11k_wmi_send_peer_assoc_cmd(struct ath11k *ar,
1666 				   struct peer_assoc_params *param)
1667 {
1668 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1669 	struct wmi_peer_assoc_complete_cmd *cmd;
1670 	struct wmi_vht_rate_set *mcs;
1671 	struct wmi_he_rate_set *he_mcs;
1672 	struct sk_buff *skb;
1673 	struct wmi_tlv *tlv;
1674 	void *ptr;
1675 	u32 peer_legacy_rates_align;
1676 	u32 peer_ht_rates_align;
1677 	int i, ret, len;
1678 
1679 	peer_legacy_rates_align = roundup(param->peer_legacy_rates.num_rates,
1680 					  sizeof(u32));
1681 	peer_ht_rates_align = roundup(param->peer_ht_rates.num_rates,
1682 				      sizeof(u32));
1683 
1684 	len = sizeof(*cmd) +
1685 	      TLV_HDR_SIZE + (peer_legacy_rates_align * sizeof(u8)) +
1686 	      TLV_HDR_SIZE + (peer_ht_rates_align * sizeof(u8)) +
1687 	      sizeof(*mcs) + TLV_HDR_SIZE +
1688 	      (sizeof(*he_mcs) * param->peer_he_mcs_count);
1689 
1690 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
1691 	if (!skb)
1692 		return -ENOMEM;
1693 
1694 	ptr = skb->data;
1695 
1696 	cmd = ptr;
1697 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1698 				     WMI_TAG_PEER_ASSOC_COMPLETE_CMD) |
1699 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1700 
1701 	cmd->vdev_id = param->vdev_id;
1702 
1703 	cmd->peer_new_assoc = param->peer_new_assoc;
1704 	cmd->peer_associd = param->peer_associd;
1705 
1706 	ath11k_wmi_copy_peer_flags(cmd, param);
1707 
1708 	ether_addr_copy(cmd->peer_macaddr.addr, param->peer_mac);
1709 
1710 	cmd->peer_rate_caps = param->peer_rate_caps;
1711 	cmd->peer_caps = param->peer_caps;
1712 	cmd->peer_listen_intval = param->peer_listen_intval;
1713 	cmd->peer_ht_caps = param->peer_ht_caps;
1714 	cmd->peer_max_mpdu = param->peer_max_mpdu;
1715 	cmd->peer_mpdu_density = param->peer_mpdu_density;
1716 	cmd->peer_vht_caps = param->peer_vht_caps;
1717 	cmd->peer_phymode = param->peer_phymode;
1718 
1719 	/* Update 11ax capabilities */
1720 	cmd->peer_he_cap_info = param->peer_he_cap_macinfo[0];
1721 	cmd->peer_he_cap_info_ext = param->peer_he_cap_macinfo[1];
1722 	cmd->peer_he_cap_info_internal = param->peer_he_cap_macinfo_internal;
1723 	cmd->peer_he_ops = param->peer_he_ops;
1724 	memcpy(&cmd->peer_he_cap_phy, &param->peer_he_cap_phyinfo,
1725 	       sizeof(param->peer_he_cap_phyinfo));
1726 	memcpy(&cmd->peer_ppet, &param->peer_ppet,
1727 	       sizeof(param->peer_ppet));
1728 
1729 	/* Update peer legacy rate information */
1730 	ptr += sizeof(*cmd);
1731 
1732 	tlv = ptr;
1733 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1734 		      FIELD_PREP(WMI_TLV_LEN, peer_legacy_rates_align);
1735 
1736 	ptr += TLV_HDR_SIZE;
1737 
1738 	cmd->num_peer_legacy_rates = param->peer_legacy_rates.num_rates;
1739 	memcpy(ptr, param->peer_legacy_rates.rates,
1740 	       param->peer_legacy_rates.num_rates);
1741 
1742 	/* Update peer HT rate information */
1743 	ptr += peer_legacy_rates_align;
1744 
1745 	tlv = ptr;
1746 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
1747 		      FIELD_PREP(WMI_TLV_LEN, peer_ht_rates_align);
1748 	ptr += TLV_HDR_SIZE;
1749 	cmd->num_peer_ht_rates = param->peer_ht_rates.num_rates;
1750 	memcpy(ptr, param->peer_ht_rates.rates,
1751 	       param->peer_ht_rates.num_rates);
1752 
1753 	/* VHT Rates */
1754 	ptr += peer_ht_rates_align;
1755 
1756 	mcs = ptr;
1757 
1758 	mcs->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_VHT_RATE_SET) |
1759 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*mcs) - TLV_HDR_SIZE);
1760 
1761 	cmd->peer_nss = param->peer_nss;
1762 
1763 	/* Update bandwidth-NSS mapping */
1764 	cmd->peer_bw_rxnss_override = 0;
1765 	cmd->peer_bw_rxnss_override |= param->peer_bw_rxnss_override;
1766 
1767 	if (param->vht_capable) {
1768 		mcs->rx_max_rate = param->rx_max_rate;
1769 		mcs->rx_mcs_set = param->rx_mcs_set;
1770 		mcs->tx_max_rate = param->tx_max_rate;
1771 		mcs->tx_mcs_set = param->tx_mcs_set;
1772 	}
1773 
1774 	/* HE Rates */
1775 	cmd->peer_he_mcs = param->peer_he_mcs_count;
1776 
1777 	ptr += sizeof(*mcs);
1778 
1779 	len = param->peer_he_mcs_count * sizeof(*he_mcs);
1780 
1781 	tlv = ptr;
1782 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
1783 		      FIELD_PREP(WMI_TLV_LEN, len);
1784 	ptr += TLV_HDR_SIZE;
1785 
1786 	/* Loop through the HE rate set */
1787 	for (i = 0; i < param->peer_he_mcs_count; i++) {
1788 		he_mcs = ptr;
1789 		he_mcs->tlv_header = FIELD_PREP(WMI_TLV_TAG,
1790 						WMI_TAG_HE_RATE_SET) |
1791 				     FIELD_PREP(WMI_TLV_LEN,
1792 						sizeof(*he_mcs) - TLV_HDR_SIZE);
1793 
1794 		he_mcs->rx_mcs_set = param->peer_he_rx_mcs_set[i];
1795 		he_mcs->tx_mcs_set = param->peer_he_tx_mcs_set[i];
1796 		ptr += sizeof(*he_mcs);
1797 	}
1798 
1799 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_PEER_ASSOC_CMDID);
1800 	if (ret) {
1801 		ath11k_warn(ar->ab,
1802 			    "failed to send WMI_PEER_ASSOC_CMDID\n");
1803 		dev_kfree_skb(skb);
1804 	}
1805 
1806 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
1807 		   "wmi peer assoc vdev id %d assoc id %d peer mac %pM peer_flags %x rate_caps %x peer_caps %x listen_intval %d ht_caps %x max_mpdu %d nss %d phymode %d peer_mpdu_density %d vht_caps %x he cap_info %x he ops %x he cap_info_ext %x he phy %x %x %x peer_bw_rxnss_override %x\n",
1808 		   cmd->vdev_id, cmd->peer_associd, param->peer_mac,
1809 		   cmd->peer_flags, cmd->peer_rate_caps, cmd->peer_caps,
1810 		   cmd->peer_listen_intval, cmd->peer_ht_caps,
1811 		   cmd->peer_max_mpdu, cmd->peer_nss, cmd->peer_phymode,
1812 		   cmd->peer_mpdu_density,
1813 		   cmd->peer_vht_caps, cmd->peer_he_cap_info,
1814 		   cmd->peer_he_ops, cmd->peer_he_cap_info_ext,
1815 		   cmd->peer_he_cap_phy[0], cmd->peer_he_cap_phy[1],
1816 		   cmd->peer_he_cap_phy[2],
1817 		   cmd->peer_bw_rxnss_override);
1818 
1819 	return ret;
1820 }
1821 
1822 void ath11k_wmi_start_scan_init(struct ath11k *ar,
1823 				struct scan_req_params *arg)
1824 {
1825 	/* setup commonly used values */
1826 	arg->scan_req_id = 1;
1827 	arg->scan_priority = WMI_SCAN_PRIORITY_LOW;
1828 	arg->dwell_time_active = 50;
1829 	arg->dwell_time_active_2g = 0;
1830 	arg->dwell_time_passive = 150;
1831 	arg->min_rest_time = 50;
1832 	arg->max_rest_time = 500;
1833 	arg->repeat_probe_time = 0;
1834 	arg->probe_spacing_time = 0;
1835 	arg->idle_time = 0;
1836 	arg->max_scan_time = 20000;
1837 	arg->probe_delay = 5;
1838 	arg->notify_scan_events = WMI_SCAN_EVENT_STARTED |
1839 				  WMI_SCAN_EVENT_COMPLETED |
1840 				  WMI_SCAN_EVENT_BSS_CHANNEL |
1841 				  WMI_SCAN_EVENT_FOREIGN_CHAN |
1842 				  WMI_SCAN_EVENT_DEQUEUED;
1843 	arg->scan_flags |= WMI_SCAN_CHAN_STAT_EVENT;
1844 	arg->num_bssid = 1;
1845 }
1846 
1847 static inline void
1848 ath11k_wmi_copy_scan_event_cntrl_flags(struct wmi_start_scan_cmd *cmd,
1849 				       struct scan_req_params *param)
1850 {
1851 	/* Scan events subscription */
1852 	if (param->scan_ev_started)
1853 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_STARTED;
1854 	if (param->scan_ev_completed)
1855 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_COMPLETED;
1856 	if (param->scan_ev_bss_chan)
1857 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_BSS_CHANNEL;
1858 	if (param->scan_ev_foreign_chan)
1859 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_FOREIGN_CHAN;
1860 	if (param->scan_ev_dequeued)
1861 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_DEQUEUED;
1862 	if (param->scan_ev_preempted)
1863 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_PREEMPTED;
1864 	if (param->scan_ev_start_failed)
1865 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_START_FAILED;
1866 	if (param->scan_ev_restarted)
1867 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_RESTARTED;
1868 	if (param->scan_ev_foreign_chn_exit)
1869 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT;
1870 	if (param->scan_ev_suspended)
1871 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_SUSPENDED;
1872 	if (param->scan_ev_resumed)
1873 		cmd->notify_scan_events |=  WMI_SCAN_EVENT_RESUMED;
1874 
1875 	/** Set scan control flags */
1876 	cmd->scan_ctrl_flags = 0;
1877 	if (param->scan_f_passive)
1878 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_PASSIVE;
1879 	if (param->scan_f_strict_passive_pch)
1880 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_STRICT_PASSIVE_ON_PCHN;
1881 	if (param->scan_f_promisc_mode)
1882 		cmd->scan_ctrl_flags |=  WMI_SCAN_FILTER_PROMISCUOS;
1883 	if (param->scan_f_capture_phy_err)
1884 		cmd->scan_ctrl_flags |=  WMI_SCAN_CAPTURE_PHY_ERROR;
1885 	if (param->scan_f_half_rate)
1886 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_HALF_RATE_SUPPORT;
1887 	if (param->scan_f_quarter_rate)
1888 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_QUARTER_RATE_SUPPORT;
1889 	if (param->scan_f_cck_rates)
1890 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_CCK_RATES;
1891 	if (param->scan_f_ofdm_rates)
1892 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_OFDM_RATES;
1893 	if (param->scan_f_chan_stat_evnt)
1894 		cmd->scan_ctrl_flags |=  WMI_SCAN_CHAN_STAT_EVENT;
1895 	if (param->scan_f_filter_prb_req)
1896 		cmd->scan_ctrl_flags |=  WMI_SCAN_FILTER_PROBE_REQ;
1897 	if (param->scan_f_bcast_probe)
1898 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_BCAST_PROBE_REQ;
1899 	if (param->scan_f_offchan_mgmt_tx)
1900 		cmd->scan_ctrl_flags |=  WMI_SCAN_OFFCHAN_MGMT_TX;
1901 	if (param->scan_f_offchan_data_tx)
1902 		cmd->scan_ctrl_flags |=  WMI_SCAN_OFFCHAN_DATA_TX;
1903 	if (param->scan_f_force_active_dfs_chn)
1904 		cmd->scan_ctrl_flags |=  WMI_SCAN_FLAG_FORCE_ACTIVE_ON_DFS;
1905 	if (param->scan_f_add_tpc_ie_in_probe)
1906 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_TPC_IE_IN_PROBE_REQ;
1907 	if (param->scan_f_add_ds_ie_in_probe)
1908 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_DS_IE_IN_PROBE_REQ;
1909 	if (param->scan_f_add_spoofed_mac_in_probe)
1910 		cmd->scan_ctrl_flags |=  WMI_SCAN_ADD_SPOOF_MAC_IN_PROBE_REQ;
1911 	if (param->scan_f_add_rand_seq_in_probe)
1912 		cmd->scan_ctrl_flags |=  WMI_SCAN_RANDOM_SEQ_NO_IN_PROBE_REQ;
1913 	if (param->scan_f_en_ie_whitelist_in_probe)
1914 		cmd->scan_ctrl_flags |=
1915 			 WMI_SCAN_ENABLE_IE_WHTELIST_IN_PROBE_REQ;
1916 
1917 	/* for adaptive scan mode using 3 bits (21 - 23 bits) */
1918 	WMI_SCAN_SET_DWELL_MODE(cmd->scan_ctrl_flags,
1919 				param->adaptive_dwell_time_mode);
1920 }
1921 
1922 int ath11k_wmi_send_scan_start_cmd(struct ath11k *ar,
1923 				   struct scan_req_params *params)
1924 {
1925 	struct ath11k_pdev_wmi *wmi = ar->wmi;
1926 	struct wmi_start_scan_cmd *cmd;
1927 	struct wmi_ssid *ssid = NULL;
1928 	struct wmi_mac_addr *bssid;
1929 	struct sk_buff *skb;
1930 	struct wmi_tlv *tlv;
1931 	void *ptr;
1932 	int i, ret, len;
1933 	u32 *tmp_ptr;
1934 	u8 extraie_len_with_pad = 0;
1935 
1936 	len = sizeof(*cmd);
1937 
1938 	len += TLV_HDR_SIZE;
1939 	if (params->num_chan)
1940 		len += params->num_chan * sizeof(u32);
1941 
1942 	len += TLV_HDR_SIZE;
1943 	if (params->num_ssids)
1944 		len += params->num_ssids * sizeof(*ssid);
1945 
1946 	len += TLV_HDR_SIZE;
1947 	if (params->num_bssid)
1948 		len += sizeof(*bssid) * params->num_bssid;
1949 
1950 	len += TLV_HDR_SIZE;
1951 	if (params->extraie.len)
1952 		extraie_len_with_pad =
1953 			roundup(params->extraie.len, sizeof(u32));
1954 	len += extraie_len_with_pad;
1955 
1956 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
1957 	if (!skb)
1958 		return -ENOMEM;
1959 
1960 	ptr = skb->data;
1961 
1962 	cmd = ptr;
1963 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_START_SCAN_CMD) |
1964 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
1965 
1966 	cmd->scan_id = params->scan_id;
1967 	cmd->scan_req_id = params->scan_req_id;
1968 	cmd->vdev_id = params->vdev_id;
1969 	cmd->scan_priority = params->scan_priority;
1970 	cmd->notify_scan_events = params->notify_scan_events;
1971 
1972 	ath11k_wmi_copy_scan_event_cntrl_flags(cmd, params);
1973 
1974 	cmd->dwell_time_active = params->dwell_time_active;
1975 	cmd->dwell_time_active_2g = params->dwell_time_active_2g;
1976 	cmd->dwell_time_passive = params->dwell_time_passive;
1977 	cmd->min_rest_time = params->min_rest_time;
1978 	cmd->max_rest_time = params->max_rest_time;
1979 	cmd->repeat_probe_time = params->repeat_probe_time;
1980 	cmd->probe_spacing_time = params->probe_spacing_time;
1981 	cmd->idle_time = params->idle_time;
1982 	cmd->max_scan_time = params->max_scan_time;
1983 	cmd->probe_delay = params->probe_delay;
1984 	cmd->burst_duration = params->burst_duration;
1985 	cmd->num_chan = params->num_chan;
1986 	cmd->num_bssid = params->num_bssid;
1987 	cmd->num_ssids = params->num_ssids;
1988 	cmd->ie_len = params->extraie.len;
1989 	cmd->n_probes = params->n_probes;
1990 
1991 	ptr += sizeof(*cmd);
1992 
1993 	len = params->num_chan * sizeof(u32);
1994 
1995 	tlv = ptr;
1996 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_UINT32) |
1997 		      FIELD_PREP(WMI_TLV_LEN, len);
1998 	ptr += TLV_HDR_SIZE;
1999 	tmp_ptr = (u32 *)ptr;
2000 
2001 	for (i = 0; i < params->num_chan; ++i)
2002 		tmp_ptr[i] = params->chan_list[i];
2003 
2004 	ptr += len;
2005 
2006 	len = params->num_ssids * sizeof(*ssid);
2007 	tlv = ptr;
2008 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2009 		      FIELD_PREP(WMI_TLV_LEN, len);
2010 
2011 	ptr += TLV_HDR_SIZE;
2012 
2013 	if (params->num_ssids) {
2014 		ssid = ptr;
2015 		for (i = 0; i < params->num_ssids; ++i) {
2016 			ssid->ssid_len = params->ssid[i].length;
2017 			memcpy(ssid->ssid, params->ssid[i].ssid,
2018 			       params->ssid[i].length);
2019 			ssid++;
2020 		}
2021 	}
2022 
2023 	ptr += (params->num_ssids * sizeof(*ssid));
2024 	len = params->num_bssid * sizeof(*bssid);
2025 	tlv = ptr;
2026 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_FIXED_STRUCT) |
2027 		      FIELD_PREP(WMI_TLV_LEN, len);
2028 
2029 	ptr += TLV_HDR_SIZE;
2030 	bssid = ptr;
2031 
2032 	if (params->num_bssid) {
2033 		for (i = 0; i < params->num_bssid; ++i) {
2034 			ether_addr_copy(bssid->addr,
2035 					params->bssid_list[i].addr);
2036 			bssid++;
2037 		}
2038 	}
2039 
2040 	ptr += params->num_bssid * sizeof(*bssid);
2041 
2042 	len = extraie_len_with_pad;
2043 	tlv = ptr;
2044 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_BYTE) |
2045 		      FIELD_PREP(WMI_TLV_LEN, len);
2046 	ptr += TLV_HDR_SIZE;
2047 
2048 	if (params->extraie.len)
2049 		memcpy(ptr, params->extraie.ptr,
2050 		       params->extraie.len);
2051 
2052 	ptr += extraie_len_with_pad;
2053 
2054 	ret = ath11k_wmi_cmd_send(wmi, skb,
2055 				  WMI_START_SCAN_CMDID);
2056 	if (ret) {
2057 		ath11k_warn(ar->ab, "failed to send WMI_START_SCAN_CMDID\n");
2058 		dev_kfree_skb(skb);
2059 	}
2060 
2061 	return ret;
2062 }
2063 
2064 int ath11k_wmi_send_scan_stop_cmd(struct ath11k *ar,
2065 				  struct scan_cancel_param *param)
2066 {
2067 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2068 	struct wmi_stop_scan_cmd *cmd;
2069 	struct sk_buff *skb;
2070 	int ret;
2071 
2072 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
2073 	if (!skb)
2074 		return -ENOMEM;
2075 
2076 	cmd = (struct wmi_stop_scan_cmd *)skb->data;
2077 
2078 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_STOP_SCAN_CMD) |
2079 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2080 
2081 	cmd->vdev_id = param->vdev_id;
2082 	cmd->requestor = param->requester;
2083 	cmd->scan_id = param->scan_id;
2084 	cmd->pdev_id = param->pdev_id;
2085 	/* stop the scan with the corresponding scan_id */
2086 	if (param->req_type == WLAN_SCAN_CANCEL_PDEV_ALL) {
2087 		/* Cancelling all scans */
2088 		cmd->req_type =  WMI_SCAN_STOP_ALL;
2089 	} else if (param->req_type == WLAN_SCAN_CANCEL_VDEV_ALL) {
2090 		/* Cancelling VAP scans */
2091 		cmd->req_type =  WMI_SCN_STOP_VAP_ALL;
2092 	} else if (param->req_type == WLAN_SCAN_CANCEL_SINGLE) {
2093 		/* Cancelling specific scan */
2094 		cmd->req_type =  WMI_SCAN_STOP_ONE;
2095 	} else {
2096 		ath11k_warn(ar->ab, "invalid scan cancel param %d",
2097 			    param->req_type);
2098 		dev_kfree_skb(skb);
2099 		return -EINVAL;
2100 	}
2101 
2102 	ret = ath11k_wmi_cmd_send(wmi, skb,
2103 				  WMI_STOP_SCAN_CMDID);
2104 	if (ret) {
2105 		ath11k_warn(ar->ab, "failed to send WMI_STOP_SCAN_CMDID\n");
2106 		dev_kfree_skb(skb);
2107 	}
2108 
2109 	return ret;
2110 }
2111 
2112 int ath11k_wmi_send_scan_chan_list_cmd(struct ath11k *ar,
2113 				       struct scan_chan_list_params *chan_list)
2114 {
2115 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2116 	struct wmi_scan_chan_list_cmd *cmd;
2117 	struct sk_buff *skb;
2118 	struct wmi_channel *chan_info;
2119 	struct channel_param *tchan_info;
2120 	struct wmi_tlv *tlv;
2121 	void *ptr;
2122 	int i, ret, len;
2123 	u32 *reg1, *reg2;
2124 
2125 	len = sizeof(*cmd) + TLV_HDR_SIZE +
2126 		 sizeof(*chan_info) * chan_list->nallchans;
2127 
2128 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
2129 	if (!skb)
2130 		return -ENOMEM;
2131 
2132 	cmd = (struct wmi_scan_chan_list_cmd *)skb->data;
2133 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_SCAN_CHAN_LIST_CMD) |
2134 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2135 
2136 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2137 		   "WMI no.of chan = %d len = %d\n", chan_list->nallchans, len);
2138 	cmd->pdev_id = chan_list->pdev_id;
2139 	cmd->num_scan_chans = chan_list->nallchans;
2140 
2141 	ptr = skb->data + sizeof(*cmd);
2142 
2143 	len = sizeof(*chan_info) * chan_list->nallchans;
2144 	tlv = ptr;
2145 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2146 		      FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2147 	ptr += TLV_HDR_SIZE;
2148 
2149 	tchan_info = &chan_list->ch_param[0];
2150 
2151 	for (i = 0; i < chan_list->nallchans; ++i) {
2152 		chan_info = ptr;
2153 		memset(chan_info, 0, sizeof(*chan_info));
2154 		len = sizeof(*chan_info);
2155 		chan_info->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2156 						   WMI_TAG_CHANNEL) |
2157 					FIELD_PREP(WMI_TLV_LEN,
2158 						   len - TLV_HDR_SIZE);
2159 
2160 		reg1 = &chan_info->reg_info_1;
2161 		reg2 = &chan_info->reg_info_2;
2162 		chan_info->mhz = tchan_info->mhz;
2163 		chan_info->band_center_freq1 = tchan_info->cfreq1;
2164 		chan_info->band_center_freq2 = tchan_info->cfreq2;
2165 
2166 		if (tchan_info->is_chan_passive)
2167 			chan_info->info |= WMI_CHAN_INFO_PASSIVE;
2168 		if (tchan_info->allow_he)
2169 			chan_info->info |= WMI_CHAN_INFO_ALLOW_HE;
2170 		else if (tchan_info->allow_vht)
2171 			chan_info->info |= WMI_CHAN_INFO_ALLOW_VHT;
2172 		else if (tchan_info->allow_ht)
2173 			chan_info->info |= WMI_CHAN_INFO_ALLOW_HT;
2174 		if (tchan_info->half_rate)
2175 			chan_info->info |= WMI_CHAN_INFO_HALF_RATE;
2176 		if (tchan_info->quarter_rate)
2177 			chan_info->info |= WMI_CHAN_INFO_QUARTER_RATE;
2178 
2179 		chan_info->info |= FIELD_PREP(WMI_CHAN_INFO_MODE,
2180 					      tchan_info->phy_mode);
2181 		*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MIN_PWR,
2182 				    tchan_info->minpower);
2183 		*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_PWR,
2184 				    tchan_info->maxpower);
2185 		*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_MAX_REG_PWR,
2186 				    tchan_info->maxregpower);
2187 		*reg1 |= FIELD_PREP(WMI_CHAN_REG_INFO1_REG_CLS,
2188 				    tchan_info->reg_class_id);
2189 		*reg2 |= FIELD_PREP(WMI_CHAN_REG_INFO2_ANT_MAX,
2190 				    tchan_info->antennamax);
2191 
2192 		ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2193 			   "WMI chan scan list chan[%d] = %u\n",
2194 			   i, chan_info->mhz);
2195 
2196 		ptr += sizeof(*chan_info);
2197 
2198 		tchan_info++;
2199 	}
2200 
2201 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_SCAN_CHAN_LIST_CMDID);
2202 	if (ret) {
2203 		ath11k_warn(ar->ab, "failed to send WMI_SCAN_CHAN_LIST cmd\n");
2204 		dev_kfree_skb(skb);
2205 	}
2206 
2207 	return ret;
2208 }
2209 
2210 int ath11k_wmi_send_wmm_update_cmd_tlv(struct ath11k *ar, u32 vdev_id,
2211 				       struct wmi_wmm_params_all_arg *param)
2212 {
2213 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2214 	struct wmi_vdev_set_wmm_params_cmd *cmd;
2215 	struct wmi_wmm_params *wmm_param;
2216 	struct wmi_wmm_params_arg *wmi_wmm_arg;
2217 	struct sk_buff *skb;
2218 	int ret, ac;
2219 
2220 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
2221 	if (!skb)
2222 		return -ENOMEM;
2223 
2224 	cmd = (struct wmi_vdev_set_wmm_params_cmd *)skb->data;
2225 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2226 				     WMI_TAG_VDEV_SET_WMM_PARAMS_CMD) |
2227 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2228 
2229 	cmd->vdev_id = vdev_id;
2230 	cmd->wmm_param_type = 0;
2231 
2232 	for (ac = 0; ac < WME_NUM_AC; ac++) {
2233 		switch (ac) {
2234 		case WME_AC_BE:
2235 			wmi_wmm_arg = &param->ac_be;
2236 			break;
2237 		case WME_AC_BK:
2238 			wmi_wmm_arg = &param->ac_bk;
2239 			break;
2240 		case WME_AC_VI:
2241 			wmi_wmm_arg = &param->ac_vi;
2242 			break;
2243 		case WME_AC_VO:
2244 			wmi_wmm_arg = &param->ac_vo;
2245 			break;
2246 		}
2247 
2248 		wmm_param = (struct wmi_wmm_params *)&cmd->wmm_params[ac];
2249 		wmm_param->tlv_header =
2250 				FIELD_PREP(WMI_TLV_TAG,
2251 					   WMI_TAG_VDEV_SET_WMM_PARAMS_CMD) |
2252 				FIELD_PREP(WMI_TLV_LEN,
2253 					   sizeof(*wmm_param) - TLV_HDR_SIZE);
2254 
2255 		wmm_param->aifs = wmi_wmm_arg->aifs;
2256 		wmm_param->cwmin = wmi_wmm_arg->cwmin;
2257 		wmm_param->cwmax = wmi_wmm_arg->cwmax;
2258 		wmm_param->txoplimit = wmi_wmm_arg->txop;
2259 		wmm_param->acm = wmi_wmm_arg->acm;
2260 		wmm_param->no_ack = wmi_wmm_arg->no_ack;
2261 
2262 		ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2263 			   "wmi wmm set ac %d aifs %d cwmin %d cwmax %d txop %d acm %d no_ack %d\n",
2264 			   ac, wmm_param->aifs, wmm_param->cwmin,
2265 			   wmm_param->cwmax, wmm_param->txoplimit,
2266 			   wmm_param->acm, wmm_param->no_ack);
2267 	}
2268 	ret = ath11k_wmi_cmd_send(wmi, skb,
2269 				  WMI_VDEV_SET_WMM_PARAMS_CMDID);
2270 	if (ret) {
2271 		ath11k_warn(ar->ab,
2272 			    "failed to send WMI_VDEV_SET_WMM_PARAMS_CMDID");
2273 		dev_kfree_skb(skb);
2274 	}
2275 
2276 	return ret;
2277 }
2278 
2279 int ath11k_wmi_send_dfs_phyerr_offload_enable_cmd(struct ath11k *ar,
2280 						  u32 pdev_id)
2281 {
2282 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2283 	struct wmi_dfs_phyerr_offload_cmd *cmd;
2284 	struct sk_buff *skb;
2285 	int ret;
2286 
2287 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
2288 	if (!skb)
2289 		return -ENOMEM;
2290 
2291 	cmd = (struct wmi_dfs_phyerr_offload_cmd *)skb->data;
2292 	cmd->tlv_header =
2293 		FIELD_PREP(WMI_TLV_TAG,
2294 			   WMI_TAG_PDEV_DFS_PHYERR_OFFLOAD_ENABLE_CMD) |
2295 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2296 
2297 	cmd->pdev_id = pdev_id;
2298 
2299 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
2300 		   "WMI dfs phy err offload enable pdev id %d\n", pdev_id);
2301 
2302 	ret = ath11k_wmi_cmd_send(wmi, skb,
2303 				  WMI_PDEV_DFS_PHYERR_OFFLOAD_ENABLE_CMDID);
2304 	if (ret) {
2305 		ath11k_warn(ar->ab,
2306 			    "failed to send WMI_PDEV_DFS_PHYERR_OFFLOAD_ENABLE cmd\n");
2307 		dev_kfree_skb(skb);
2308 	}
2309 
2310 	return ret;
2311 }
2312 
2313 int ath11k_wmi_pdev_peer_pktlog_filter(struct ath11k *ar, u8 *addr, u8 enable)
2314 {
2315 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2316 	struct wmi_pdev_pktlog_filter_cmd *cmd;
2317 	struct wmi_pdev_pktlog_filter_info *info;
2318 	struct sk_buff *skb;
2319 	struct wmi_tlv *tlv;
2320 	void *ptr;
2321 	int ret, len;
2322 
2323 	len = sizeof(*cmd) + sizeof(*info) + TLV_HDR_SIZE;
2324 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
2325 	if (!skb)
2326 		return -ENOMEM;
2327 
2328 	cmd = (struct wmi_pdev_pktlog_filter_cmd *)skb->data;
2329 
2330 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PEER_PKTLOG_FILTER_CMD) |
2331 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2332 
2333 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2334 	cmd->num_mac = 1;
2335 	cmd->enable = enable;
2336 
2337 	ptr = skb->data + sizeof(*cmd);
2338 
2339 	tlv = ptr;
2340 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2341 		      FIELD_PREP(WMI_TLV_LEN, sizeof(*info));
2342 
2343 	ptr += TLV_HDR_SIZE;
2344 	info = ptr;
2345 
2346 	ether_addr_copy(info->peer_macaddr.addr, addr);
2347 	info->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PEER_PKTLOG_FILTER_INFO) |
2348 			   FIELD_PREP(WMI_TLV_LEN,
2349 				      sizeof(*info) - TLV_HDR_SIZE);
2350 
2351 	ret = ath11k_wmi_cmd_send(wmi, skb,
2352 				  WMI_PDEV_PKTLOG_FILTER_CMDID);
2353 	if (ret) {
2354 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2355 		dev_kfree_skb(skb);
2356 	}
2357 
2358 	return ret;
2359 }
2360 
2361 int
2362 ath11k_wmi_send_init_country_cmd(struct ath11k *ar,
2363 				 struct wmi_init_country_params init_cc_params)
2364 {
2365 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2366 	struct wmi_init_country_cmd *cmd;
2367 	struct sk_buff *skb;
2368 	int ret;
2369 
2370 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
2371 	if (!skb)
2372 		return -ENOMEM;
2373 
2374 	cmd = (struct wmi_init_country_cmd *)skb->data;
2375 	cmd->tlv_header =
2376 		FIELD_PREP(WMI_TLV_TAG,
2377 			   WMI_TAG_SET_INIT_COUNTRY_CMD) |
2378 		FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2379 
2380 	cmd->pdev_id = ar->pdev->pdev_id;
2381 
2382 	switch (init_cc_params.flags) {
2383 	case ALPHA_IS_SET:
2384 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_ALPHA;
2385 		memcpy((u8 *)&cmd->cc_info.alpha2,
2386 		       init_cc_params.cc_info.alpha2, 3);
2387 		break;
2388 	case CC_IS_SET:
2389 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_COUNTRY_CODE;
2390 		cmd->cc_info.country_code = init_cc_params.cc_info.country_code;
2391 		break;
2392 	case REGDMN_IS_SET:
2393 		cmd->init_cc_type = WMI_COUNTRY_INFO_TYPE_REGDOMAIN;
2394 		cmd->cc_info.regdom_id = init_cc_params.cc_info.regdom_id;
2395 		break;
2396 	default:
2397 		ret = -EINVAL;
2398 		goto out;
2399 	}
2400 
2401 	ret = ath11k_wmi_cmd_send(wmi, skb,
2402 				  WMI_SET_INIT_COUNTRY_CMDID);
2403 
2404 out:
2405 	if (ret) {
2406 		ath11k_warn(ar->ab,
2407 			    "failed to send WMI_SET_INIT_COUNTRY CMD :%d\n",
2408 			    ret);
2409 		dev_kfree_skb(skb);
2410 	}
2411 
2412 	return ret;
2413 }
2414 
2415 int ath11k_wmi_pdev_pktlog_enable(struct ath11k *ar, u32 pktlog_filter)
2416 {
2417 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2418 	struct wmi_pktlog_enable_cmd *cmd;
2419 	struct sk_buff *skb;
2420 	int ret;
2421 
2422 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
2423 	if (!skb)
2424 		return -ENOMEM;
2425 
2426 	cmd = (struct wmi_pktlog_enable_cmd *)skb->data;
2427 
2428 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PKTLOG_ENABLE_CMD) |
2429 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2430 
2431 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2432 	cmd->evlist = pktlog_filter;
2433 	cmd->enable = ATH11K_WMI_PKTLOG_ENABLE_FORCE;
2434 
2435 	ret = ath11k_wmi_cmd_send(wmi, skb,
2436 				  WMI_PDEV_PKTLOG_ENABLE_CMDID);
2437 	if (ret) {
2438 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2439 		dev_kfree_skb(skb);
2440 	}
2441 
2442 	return ret;
2443 }
2444 
2445 int ath11k_wmi_pdev_pktlog_disable(struct ath11k *ar)
2446 {
2447 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2448 	struct wmi_pktlog_disable_cmd *cmd;
2449 	struct sk_buff *skb;
2450 	int ret;
2451 
2452 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, sizeof(*cmd));
2453 	if (!skb)
2454 		return -ENOMEM;
2455 
2456 	cmd = (struct wmi_pktlog_disable_cmd *)skb->data;
2457 
2458 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_PDEV_PKTLOG_DISABLE_CMD) |
2459 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2460 
2461 	cmd->pdev_id = DP_HW2SW_MACID(ar->pdev->pdev_id);
2462 
2463 	ret = ath11k_wmi_cmd_send(wmi, skb,
2464 				  WMI_PDEV_PKTLOG_DISABLE_CMDID);
2465 	if (ret) {
2466 		ath11k_warn(ar->ab, "failed to send WMI_PDEV_PKTLOG_ENABLE_CMDID\n");
2467 		dev_kfree_skb(skb);
2468 	}
2469 
2470 	return ret;
2471 }
2472 
2473 int
2474 ath11k_wmi_send_twt_enable_cmd(struct ath11k *ar, u32 pdev_id)
2475 {
2476 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2477 	struct ath11k_base *ab = wmi->wmi_sc->ab;
2478 	struct wmi_twt_enable_params_cmd *cmd;
2479 	struct sk_buff *skb;
2480 	int ret, len;
2481 
2482 	len = sizeof(*cmd);
2483 
2484 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
2485 	if (!skb)
2486 		return -ENOMEM;
2487 
2488 	cmd = (void *)skb->data;
2489 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_TWT_ENABLE_CMD) |
2490 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2491 	cmd->pdev_id = pdev_id;
2492 	cmd->sta_cong_timer_ms = ATH11K_TWT_DEF_STA_CONG_TIMER_MS;
2493 	cmd->default_slot_size = ATH11K_TWT_DEF_DEFAULT_SLOT_SIZE;
2494 	cmd->congestion_thresh_setup = ATH11K_TWT_DEF_CONGESTION_THRESH_SETUP;
2495 	cmd->congestion_thresh_teardown =
2496 		ATH11K_TWT_DEF_CONGESTION_THRESH_TEARDOWN;
2497 	cmd->congestion_thresh_critical =
2498 		ATH11K_TWT_DEF_CONGESTION_THRESH_CRITICAL;
2499 	cmd->interference_thresh_teardown =
2500 		ATH11K_TWT_DEF_INTERFERENCE_THRESH_TEARDOWN;
2501 	cmd->interference_thresh_setup =
2502 		ATH11K_TWT_DEF_INTERFERENCE_THRESH_SETUP;
2503 	cmd->min_no_sta_setup = ATH11K_TWT_DEF_MIN_NO_STA_SETUP;
2504 	cmd->min_no_sta_teardown = ATH11K_TWT_DEF_MIN_NO_STA_TEARDOWN;
2505 	cmd->no_of_bcast_mcast_slots = ATH11K_TWT_DEF_NO_OF_BCAST_MCAST_SLOTS;
2506 	cmd->min_no_twt_slots = ATH11K_TWT_DEF_MIN_NO_TWT_SLOTS;
2507 	cmd->max_no_sta_twt = ATH11K_TWT_DEF_MAX_NO_STA_TWT;
2508 	cmd->mode_check_interval = ATH11K_TWT_DEF_MODE_CHECK_INTERVAL;
2509 	cmd->add_sta_slot_interval = ATH11K_TWT_DEF_ADD_STA_SLOT_INTERVAL;
2510 	cmd->remove_sta_slot_interval =
2511 		ATH11K_TWT_DEF_REMOVE_STA_SLOT_INTERVAL;
2512 	/* TODO add MBSSID support */
2513 	cmd->mbss_support = 0;
2514 
2515 	ret = ath11k_wmi_cmd_send(wmi, skb,
2516 				  WMI_TWT_ENABLE_CMDID);
2517 	if (ret) {
2518 		ath11k_warn(ab, "Failed to send WMI_TWT_ENABLE_CMDID");
2519 		dev_kfree_skb(skb);
2520 	}
2521 	return ret;
2522 }
2523 
2524 int
2525 ath11k_wmi_send_twt_disable_cmd(struct ath11k *ar, u32 pdev_id)
2526 {
2527 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2528 	struct ath11k_base *ab = wmi->wmi_sc->ab;
2529 	struct wmi_twt_disable_params_cmd *cmd;
2530 	struct sk_buff *skb;
2531 	int ret, len;
2532 
2533 	len = sizeof(*cmd);
2534 
2535 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
2536 	if (!skb)
2537 		return -ENOMEM;
2538 
2539 	cmd = (void *)skb->data;
2540 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_TWT_DISABLE_CMD) |
2541 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2542 	cmd->pdev_id = pdev_id;
2543 
2544 	ret = ath11k_wmi_cmd_send(wmi, skb,
2545 				  WMI_TWT_DISABLE_CMDID);
2546 	if (ret) {
2547 		ath11k_warn(ab, "Failed to send WMI_TWT_DIeABLE_CMDID");
2548 		dev_kfree_skb(skb);
2549 	}
2550 	return ret;
2551 }
2552 
2553 int
2554 ath11k_wmi_send_obss_spr_cmd(struct ath11k *ar, u32 vdev_id,
2555 			     struct ieee80211_he_obss_pd *he_obss_pd)
2556 {
2557 	struct ath11k_pdev_wmi *wmi = ar->wmi;
2558 	struct ath11k_base *ab = wmi->wmi_sc->ab;
2559 	struct wmi_obss_spatial_reuse_params_cmd *cmd;
2560 	struct sk_buff *skb;
2561 	int ret, len;
2562 
2563 	len = sizeof(*cmd);
2564 
2565 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
2566 	if (!skb)
2567 		return -ENOMEM;
2568 
2569 	cmd = (void *)skb->data;
2570 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2571 				     WMI_TAG_OBSS_SPATIAL_REUSE_SET_CMD) |
2572 			  FIELD_PREP(WMI_TLV_LEN, len - TLV_HDR_SIZE);
2573 	cmd->vdev_id = vdev_id;
2574 	cmd->enable = he_obss_pd->enable;
2575 	cmd->obss_min = he_obss_pd->min_offset;
2576 	cmd->obss_max = he_obss_pd->max_offset;
2577 
2578 	ret = ath11k_wmi_cmd_send(wmi, skb,
2579 				  WMI_PDEV_OBSS_PD_SPATIAL_REUSE_CMDID);
2580 	if (ret) {
2581 		ath11k_warn(ab,
2582 			    "Failed to send WMI_PDEV_OBSS_PD_SPATIAL_REUSE_CMDID");
2583 		dev_kfree_skb(skb);
2584 	}
2585 	return ret;
2586 }
2587 
2588 static void
2589 ath11k_fill_band_to_mac_param(struct ath11k_base  *soc,
2590 			      struct wmi_host_pdev_band_to_mac *band_to_mac)
2591 {
2592 	u8 i;
2593 	struct ath11k_hal_reg_capabilities_ext *hal_reg_cap;
2594 	struct ath11k_pdev *pdev;
2595 
2596 	for (i = 0; i < soc->num_radios; i++) {
2597 		pdev = &soc->pdevs[i];
2598 		hal_reg_cap = &soc->hal_reg_cap[i];
2599 		band_to_mac[i].pdev_id = pdev->pdev_id;
2600 
2601 		switch (pdev->cap.supported_bands) {
2602 		case WMI_HOST_WLAN_2G_5G_CAP:
2603 			band_to_mac[i].start_freq = hal_reg_cap->low_2ghz_chan;
2604 			band_to_mac[i].end_freq = hal_reg_cap->high_5ghz_chan;
2605 			break;
2606 		case WMI_HOST_WLAN_2G_CAP:
2607 			band_to_mac[i].start_freq = hal_reg_cap->low_2ghz_chan;
2608 			band_to_mac[i].end_freq = hal_reg_cap->high_2ghz_chan;
2609 			break;
2610 		case WMI_HOST_WLAN_5G_CAP:
2611 			band_to_mac[i].start_freq = hal_reg_cap->low_5ghz_chan;
2612 			band_to_mac[i].end_freq = hal_reg_cap->high_5ghz_chan;
2613 			break;
2614 		default:
2615 			break;
2616 		}
2617 	}
2618 }
2619 
2620 static void
2621 ath11k_wmi_copy_resource_config(struct wmi_resource_config *wmi_cfg,
2622 				struct target_resource_config *tg_cfg)
2623 {
2624 	wmi_cfg->num_vdevs = tg_cfg->num_vdevs;
2625 	wmi_cfg->num_peers = tg_cfg->num_peers;
2626 	wmi_cfg->num_offload_peers = tg_cfg->num_offload_peers;
2627 	wmi_cfg->num_offload_reorder_buffs = tg_cfg->num_offload_reorder_buffs;
2628 	wmi_cfg->num_peer_keys = tg_cfg->num_peer_keys;
2629 	wmi_cfg->num_tids = tg_cfg->num_tids;
2630 	wmi_cfg->ast_skid_limit = tg_cfg->ast_skid_limit;
2631 	wmi_cfg->tx_chain_mask = tg_cfg->tx_chain_mask;
2632 	wmi_cfg->rx_chain_mask = tg_cfg->rx_chain_mask;
2633 	wmi_cfg->rx_timeout_pri[0] = tg_cfg->rx_timeout_pri[0];
2634 	wmi_cfg->rx_timeout_pri[1] = tg_cfg->rx_timeout_pri[1];
2635 	wmi_cfg->rx_timeout_pri[2] = tg_cfg->rx_timeout_pri[2];
2636 	wmi_cfg->rx_timeout_pri[3] = tg_cfg->rx_timeout_pri[3];
2637 	wmi_cfg->rx_decap_mode = tg_cfg->rx_decap_mode;
2638 	wmi_cfg->scan_max_pending_req = tg_cfg->scan_max_pending_req;
2639 	wmi_cfg->bmiss_offload_max_vdev = tg_cfg->bmiss_offload_max_vdev;
2640 	wmi_cfg->roam_offload_max_vdev = tg_cfg->roam_offload_max_vdev;
2641 	wmi_cfg->roam_offload_max_ap_profiles =
2642 		tg_cfg->roam_offload_max_ap_profiles;
2643 	wmi_cfg->num_mcast_groups = tg_cfg->num_mcast_groups;
2644 	wmi_cfg->num_mcast_table_elems = tg_cfg->num_mcast_table_elems;
2645 	wmi_cfg->mcast2ucast_mode = tg_cfg->mcast2ucast_mode;
2646 	wmi_cfg->tx_dbg_log_size = tg_cfg->tx_dbg_log_size;
2647 	wmi_cfg->num_wds_entries = tg_cfg->num_wds_entries;
2648 	wmi_cfg->dma_burst_size = tg_cfg->dma_burst_size;
2649 	wmi_cfg->mac_aggr_delim = tg_cfg->mac_aggr_delim;
2650 	wmi_cfg->rx_skip_defrag_timeout_dup_detection_check =
2651 		tg_cfg->rx_skip_defrag_timeout_dup_detection_check;
2652 	wmi_cfg->vow_config = tg_cfg->vow_config;
2653 	wmi_cfg->gtk_offload_max_vdev = tg_cfg->gtk_offload_max_vdev;
2654 	wmi_cfg->num_msdu_desc = tg_cfg->num_msdu_desc;
2655 	wmi_cfg->max_frag_entries = tg_cfg->max_frag_entries;
2656 	wmi_cfg->num_tdls_vdevs = tg_cfg->num_tdls_vdevs;
2657 	wmi_cfg->num_tdls_conn_table_entries =
2658 		tg_cfg->num_tdls_conn_table_entries;
2659 	wmi_cfg->beacon_tx_offload_max_vdev =
2660 		tg_cfg->beacon_tx_offload_max_vdev;
2661 	wmi_cfg->num_multicast_filter_entries =
2662 		tg_cfg->num_multicast_filter_entries;
2663 	wmi_cfg->num_wow_filters = tg_cfg->num_wow_filters;
2664 	wmi_cfg->num_keep_alive_pattern = tg_cfg->num_keep_alive_pattern;
2665 	wmi_cfg->keep_alive_pattern_size = tg_cfg->keep_alive_pattern_size;
2666 	wmi_cfg->max_tdls_concurrent_sleep_sta =
2667 		tg_cfg->max_tdls_concurrent_sleep_sta;
2668 	wmi_cfg->max_tdls_concurrent_buffer_sta =
2669 		tg_cfg->max_tdls_concurrent_buffer_sta;
2670 	wmi_cfg->wmi_send_separate = tg_cfg->wmi_send_separate;
2671 	wmi_cfg->num_ocb_vdevs = tg_cfg->num_ocb_vdevs;
2672 	wmi_cfg->num_ocb_channels = tg_cfg->num_ocb_channels;
2673 	wmi_cfg->num_ocb_schedules = tg_cfg->num_ocb_schedules;
2674 	wmi_cfg->bpf_instruction_size = tg_cfg->bpf_instruction_size;
2675 	wmi_cfg->max_bssid_rx_filters = tg_cfg->max_bssid_rx_filters;
2676 	wmi_cfg->use_pdev_id = tg_cfg->use_pdev_id;
2677 	wmi_cfg->flag1 = tg_cfg->atf_config;
2678 	wmi_cfg->peer_map_unmap_v2_support = tg_cfg->peer_map_unmap_v2_support;
2679 	wmi_cfg->sched_params = tg_cfg->sched_params;
2680 	wmi_cfg->twt_ap_pdev_count = tg_cfg->twt_ap_pdev_count;
2681 	wmi_cfg->twt_ap_sta_count = tg_cfg->twt_ap_sta_count;
2682 }
2683 
2684 static int ath11k_init_cmd_send(struct ath11k_pdev_wmi *wmi,
2685 				struct wmi_init_cmd_param *param)
2686 {
2687 	struct ath11k_base *ab = wmi->wmi_sc->ab;
2688 	struct sk_buff *skb;
2689 	struct wmi_init_cmd *cmd;
2690 	struct wmi_resource_config *cfg;
2691 	struct wmi_pdev_set_hw_mode_cmd_param *hw_mode;
2692 	struct wmi_pdev_band_to_mac *band_to_mac;
2693 	struct wlan_host_mem_chunk *host_mem_chunks;
2694 	struct wmi_tlv *tlv;
2695 	size_t ret, len;
2696 	void *ptr;
2697 	u32 hw_mode_len = 0;
2698 	u16 idx;
2699 
2700 	if (param->hw_mode_id != WMI_HOST_HW_MODE_MAX)
2701 		hw_mode_len = sizeof(*hw_mode) + TLV_HDR_SIZE +
2702 			      (param->num_band_to_mac * sizeof(*band_to_mac));
2703 
2704 	len = sizeof(*cmd) + TLV_HDR_SIZE + sizeof(*cfg) + hw_mode_len +
2705 	      (sizeof(*host_mem_chunks) * WMI_MAX_MEM_REQS);
2706 
2707 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, len);
2708 	if (!skb)
2709 		return -ENOMEM;
2710 
2711 	cmd = (struct wmi_init_cmd *)skb->data;
2712 
2713 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_INIT_CMD) |
2714 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cmd) - TLV_HDR_SIZE);
2715 
2716 	ptr = skb->data + sizeof(*cmd);
2717 	cfg = ptr;
2718 
2719 	ath11k_wmi_copy_resource_config(cfg, param->res_cfg);
2720 
2721 	cfg->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_RESOURCE_CONFIG) |
2722 			  FIELD_PREP(WMI_TLV_LEN, sizeof(*cfg) - TLV_HDR_SIZE);
2723 
2724 	ptr += sizeof(*cfg);
2725 	host_mem_chunks = ptr + TLV_HDR_SIZE;
2726 	len = sizeof(struct wlan_host_mem_chunk);
2727 
2728 	for (idx = 0; idx < param->num_mem_chunks; ++idx) {
2729 		host_mem_chunks[idx].tlv_header =
2730 				FIELD_PREP(WMI_TLV_TAG,
2731 					   WMI_TAG_WLAN_HOST_MEMORY_CHUNK) |
2732 				FIELD_PREP(WMI_TLV_LEN, len);
2733 
2734 		host_mem_chunks[idx].ptr = param->mem_chunks[idx].paddr;
2735 		host_mem_chunks[idx].size = param->mem_chunks[idx].len;
2736 		host_mem_chunks[idx].req_id = param->mem_chunks[idx].req_id;
2737 
2738 		ath11k_dbg(ab, ATH11K_DBG_WMI,
2739 			   "WMI host mem chunk req_id %d paddr 0x%llx len %d\n",
2740 			   param->mem_chunks[idx].req_id,
2741 			   (u64)param->mem_chunks[idx].paddr,
2742 			   param->mem_chunks[idx].len);
2743 	}
2744 	cmd->num_host_mem_chunks = param->num_mem_chunks;
2745 	len = sizeof(struct wlan_host_mem_chunk) * param->num_mem_chunks;
2746 
2747 	/* num_mem_chunks is zero */
2748 	tlv = ptr;
2749 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2750 		      FIELD_PREP(WMI_TLV_LEN, len);
2751 	ptr += TLV_HDR_SIZE + len;
2752 
2753 	if (param->hw_mode_id != WMI_HOST_HW_MODE_MAX) {
2754 		hw_mode = (struct wmi_pdev_set_hw_mode_cmd_param *)ptr;
2755 		hw_mode->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2756 						 WMI_TAG_PDEV_SET_HW_MODE_CMD) |
2757 				      FIELD_PREP(WMI_TLV_LEN,
2758 						 sizeof(*hw_mode) - TLV_HDR_SIZE);
2759 
2760 		hw_mode->hw_mode_index = param->hw_mode_id;
2761 		hw_mode->num_band_to_mac = param->num_band_to_mac;
2762 
2763 		ptr += sizeof(*hw_mode);
2764 
2765 		len = param->num_band_to_mac * sizeof(*band_to_mac);
2766 		tlv = ptr;
2767 		tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_STRUCT) |
2768 			      FIELD_PREP(WMI_TLV_LEN, len);
2769 
2770 		ptr += TLV_HDR_SIZE;
2771 		len = sizeof(*band_to_mac);
2772 
2773 		for (idx = 0; idx < param->num_band_to_mac; idx++) {
2774 			band_to_mac = (void *)ptr;
2775 
2776 			band_to_mac->tlv_header = FIELD_PREP(WMI_TLV_TAG,
2777 							     WMI_TAG_PDEV_BAND_TO_MAC) |
2778 						  FIELD_PREP(WMI_TLV_LEN,
2779 							     len - TLV_HDR_SIZE);
2780 			band_to_mac->pdev_id = param->band_to_mac[idx].pdev_id;
2781 			band_to_mac->start_freq =
2782 				param->band_to_mac[idx].start_freq;
2783 			band_to_mac->end_freq =
2784 				param->band_to_mac[idx].end_freq;
2785 			ptr += sizeof(*band_to_mac);
2786 		}
2787 	}
2788 
2789 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_INIT_CMDID);
2790 	if (ret) {
2791 		ath11k_warn(ab, "failed to send WMI_INIT_CMDID\n");
2792 		dev_kfree_skb(skb);
2793 	}
2794 
2795 	return ret;
2796 }
2797 
2798 int ath11k_wmi_wait_for_service_ready(struct ath11k_base *ab)
2799 {
2800 	unsigned long time_left;
2801 
2802 	time_left = wait_for_completion_timeout(&ab->wmi_sc.service_ready,
2803 						WMI_SERVICE_READY_TIMEOUT_HZ);
2804 	if (!time_left)
2805 		return -ETIMEDOUT;
2806 
2807 	return 0;
2808 }
2809 
2810 int ath11k_wmi_wait_for_unified_ready(struct ath11k_base *ab)
2811 {
2812 	unsigned long time_left;
2813 
2814 	time_left = wait_for_completion_timeout(&ab->wmi_sc.unified_ready,
2815 						WMI_SERVICE_READY_TIMEOUT_HZ);
2816 	if (!time_left)
2817 		return -ETIMEDOUT;
2818 
2819 	return 0;
2820 }
2821 
2822 int ath11k_wmi_cmd_init(struct ath11k_base *ab)
2823 {
2824 	struct ath11k_wmi_base *wmi_sc = &ab->wmi_sc;
2825 	struct wmi_init_cmd_param init_param;
2826 	struct target_resource_config  config;
2827 
2828 	memset(&init_param, 0, sizeof(init_param));
2829 	memset(&config, 0, sizeof(config));
2830 
2831 	config.num_vdevs = ab->num_radios * TARGET_NUM_VDEVS;
2832 
2833 	if (ab->num_radios == 2) {
2834 		config.num_peers = TARGET_NUM_PEERS(DBS);
2835 		config.num_tids = TARGET_NUM_TIDS(DBS);
2836 	} else if (ab->num_radios == 3) {
2837 		config.num_peers = TARGET_NUM_PEERS(DBS_SBS);
2838 		config.num_tids = TARGET_NUM_TIDS(DBS_SBS);
2839 	} else {
2840 		/* Control should not reach here */
2841 		config.num_peers = TARGET_NUM_PEERS(SINGLE);
2842 		config.num_tids = TARGET_NUM_TIDS(SINGLE);
2843 	}
2844 	config.num_offload_peers = TARGET_NUM_OFFLD_PEERS;
2845 	config.num_offload_reorder_buffs = TARGET_NUM_OFFLD_REORDER_BUFFS;
2846 	config.num_peer_keys = TARGET_NUM_PEER_KEYS;
2847 	config.ast_skid_limit = TARGET_AST_SKID_LIMIT;
2848 	config.tx_chain_mask = (1 << ab->target_caps.num_rf_chains) - 1;
2849 	config.rx_chain_mask = (1 << ab->target_caps.num_rf_chains) - 1;
2850 	config.rx_timeout_pri[0] = TARGET_RX_TIMEOUT_LO_PRI;
2851 	config.rx_timeout_pri[1] = TARGET_RX_TIMEOUT_LO_PRI;
2852 	config.rx_timeout_pri[2] = TARGET_RX_TIMEOUT_LO_PRI;
2853 	config.rx_timeout_pri[3] = TARGET_RX_TIMEOUT_HI_PRI;
2854 	config.rx_decap_mode = TARGET_DECAP_MODE_NATIVE_WIFI;
2855 	config.scan_max_pending_req = TARGET_SCAN_MAX_PENDING_REQS;
2856 	config.bmiss_offload_max_vdev = TARGET_BMISS_OFFLOAD_MAX_VDEV;
2857 	config.roam_offload_max_vdev = TARGET_ROAM_OFFLOAD_MAX_VDEV;
2858 	config.roam_offload_max_ap_profiles = TARGET_ROAM_OFFLOAD_MAX_AP_PROFILES;
2859 	config.num_mcast_groups = TARGET_NUM_MCAST_GROUPS;
2860 	config.num_mcast_table_elems = TARGET_NUM_MCAST_TABLE_ELEMS;
2861 	config.mcast2ucast_mode = TARGET_MCAST2UCAST_MODE;
2862 	config.tx_dbg_log_size = TARGET_TX_DBG_LOG_SIZE;
2863 	config.num_wds_entries = TARGET_NUM_WDS_ENTRIES;
2864 	config.dma_burst_size = TARGET_DMA_BURST_SIZE;
2865 	config.rx_skip_defrag_timeout_dup_detection_check =
2866 		TARGET_RX_SKIP_DEFRAG_TIMEOUT_DUP_DETECTION_CHECK;
2867 	config.vow_config = TARGET_VOW_CONFIG;
2868 	config.gtk_offload_max_vdev = TARGET_GTK_OFFLOAD_MAX_VDEV;
2869 	config.num_msdu_desc = TARGET_NUM_MSDU_DESC;
2870 	config.beacon_tx_offload_max_vdev = ab->num_radios * TARGET_MAX_BCN_OFFLD;
2871 	config.rx_batchmode = TARGET_RX_BATCHMODE;
2872 	config.peer_map_unmap_v2_support = 1;
2873 	config.twt_ap_pdev_count = 2;
2874 	config.twt_ap_sta_count = 1000;
2875 
2876 	memcpy(&wmi_sc->wlan_resource_config, &config, sizeof(config));
2877 
2878 	init_param.res_cfg = &wmi_sc->wlan_resource_config;
2879 	init_param.num_mem_chunks = wmi_sc->num_mem_chunks;
2880 	init_param.hw_mode_id = wmi_sc->preferred_hw_mode;
2881 	init_param.mem_chunks = wmi_sc->mem_chunks;
2882 
2883 	if (wmi_sc->preferred_hw_mode == WMI_HOST_HW_MODE_SINGLE)
2884 		init_param.hw_mode_id = WMI_HOST_HW_MODE_MAX;
2885 
2886 	init_param.num_band_to_mac = ab->num_radios;
2887 
2888 	ath11k_fill_band_to_mac_param(ab, init_param.band_to_mac);
2889 
2890 	return ath11k_init_cmd_send(&wmi_sc->wmi[0], &init_param);
2891 }
2892 
2893 static int ath11k_wmi_tlv_hw_mode_caps_parse(struct ath11k_base *soc,
2894 					     u16 tag, u16 len,
2895 					     const void *ptr, void *data)
2896 {
2897 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
2898 	struct wmi_hw_mode_capabilities *hw_mode_cap;
2899 	u32 phy_map = 0;
2900 
2901 	if (tag != WMI_TAG_HW_MODE_CAPABILITIES)
2902 		return -EPROTO;
2903 
2904 	if (svc_rdy_ext->n_hw_mode_caps >= svc_rdy_ext->param.num_hw_modes)
2905 		return -ENOBUFS;
2906 
2907 	hw_mode_cap = container_of(ptr, struct wmi_hw_mode_capabilities,
2908 				   hw_mode_id);
2909 	svc_rdy_ext->n_hw_mode_caps++;
2910 
2911 	phy_map = hw_mode_cap->phy_id_map;
2912 	while (phy_map) {
2913 		svc_rdy_ext->tot_phy_id++;
2914 		phy_map = phy_map >> 1;
2915 	}
2916 
2917 	return 0;
2918 }
2919 
2920 static int ath11k_wmi_tlv_hw_mode_caps(struct ath11k_base *soc,
2921 				       u16 len, const void *ptr, void *data)
2922 {
2923 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
2924 	struct wmi_hw_mode_capabilities *hw_mode_caps;
2925 	enum wmi_host_hw_mode_config_type mode, pref;
2926 	u32 i;
2927 	int ret;
2928 
2929 	svc_rdy_ext->n_hw_mode_caps = 0;
2930 	svc_rdy_ext->hw_mode_caps = (struct wmi_hw_mode_capabilities *)ptr;
2931 
2932 	ret = ath11k_wmi_tlv_iter(soc, ptr, len,
2933 				  ath11k_wmi_tlv_hw_mode_caps_parse,
2934 				  svc_rdy_ext);
2935 	if (ret) {
2936 		ath11k_warn(soc, "failed to parse tlv %d\n", ret);
2937 		return ret;
2938 	}
2939 
2940 	i = 0;
2941 	while (i < svc_rdy_ext->n_hw_mode_caps) {
2942 		hw_mode_caps = &svc_rdy_ext->hw_mode_caps[i];
2943 		mode = hw_mode_caps->hw_mode_id;
2944 		pref = soc->wmi_sc.preferred_hw_mode;
2945 
2946 		if (ath11k_hw_mode_pri_map[mode] < ath11k_hw_mode_pri_map[pref]) {
2947 			svc_rdy_ext->pref_hw_mode_caps = *hw_mode_caps;
2948 			soc->wmi_sc.preferred_hw_mode = mode;
2949 		}
2950 		i++;
2951 	}
2952 
2953 	if (soc->wmi_sc.preferred_hw_mode == WMI_HOST_HW_MODE_MAX)
2954 		return -EINVAL;
2955 
2956 	return 0;
2957 }
2958 
2959 static int ath11k_wmi_tlv_mac_phy_caps_parse(struct ath11k_base *soc,
2960 					     u16 tag, u16 len,
2961 					     const void *ptr, void *data)
2962 {
2963 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
2964 
2965 	if (tag != WMI_TAG_MAC_PHY_CAPABILITIES)
2966 		return -EPROTO;
2967 
2968 	if (svc_rdy_ext->n_mac_phy_caps >= svc_rdy_ext->tot_phy_id)
2969 		return -ENOBUFS;
2970 
2971 	len = min_t(u16, len, sizeof(struct wmi_mac_phy_capabilities));
2972 	if (!svc_rdy_ext->n_mac_phy_caps) {
2973 		svc_rdy_ext->mac_phy_caps = kzalloc((svc_rdy_ext->tot_phy_id) * len,
2974 						    GFP_ATOMIC);
2975 		if (!svc_rdy_ext->mac_phy_caps)
2976 			return -ENOMEM;
2977 	}
2978 
2979 	memcpy(svc_rdy_ext->mac_phy_caps + svc_rdy_ext->n_mac_phy_caps, ptr, len);
2980 	svc_rdy_ext->n_mac_phy_caps++;
2981 	return 0;
2982 }
2983 
2984 static int ath11k_wmi_tlv_ext_hal_reg_caps_parse(struct ath11k_base *soc,
2985 						 u16 tag, u16 len,
2986 						 const void *ptr, void *data)
2987 {
2988 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
2989 
2990 	if (tag != WMI_TAG_HAL_REG_CAPABILITIES_EXT)
2991 		return -EPROTO;
2992 
2993 	if (svc_rdy_ext->n_ext_hal_reg_caps >= svc_rdy_ext->param.num_phy)
2994 		return -ENOBUFS;
2995 
2996 	svc_rdy_ext->n_ext_hal_reg_caps++;
2997 	return 0;
2998 }
2999 
3000 static int ath11k_wmi_tlv_ext_hal_reg_caps(struct ath11k_base *soc,
3001 					   u16 len, const void *ptr, void *data)
3002 {
3003 	struct ath11k_pdev_wmi *wmi_handle = &soc->wmi_sc.wmi[0];
3004 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3005 	struct ath11k_hal_reg_capabilities_ext reg_cap;
3006 	int ret;
3007 	u32 i;
3008 
3009 	svc_rdy_ext->n_ext_hal_reg_caps = 0;
3010 	svc_rdy_ext->ext_hal_reg_caps = (struct wmi_hal_reg_capabilities_ext *)ptr;
3011 	ret = ath11k_wmi_tlv_iter(soc, ptr, len,
3012 				  ath11k_wmi_tlv_ext_hal_reg_caps_parse,
3013 				  svc_rdy_ext);
3014 	if (ret) {
3015 		ath11k_warn(soc, "failed to parse tlv %d\n", ret);
3016 		return ret;
3017 	}
3018 
3019 	for (i = 0; i < svc_rdy_ext->param.num_phy; i++) {
3020 		ret = ath11k_pull_reg_cap_svc_rdy_ext(wmi_handle,
3021 						      svc_rdy_ext->soc_hal_reg_caps,
3022 						      svc_rdy_ext->ext_hal_reg_caps, i,
3023 						      &reg_cap);
3024 		if (ret) {
3025 			ath11k_warn(soc, "failed to extract reg cap %d\n", i);
3026 			return ret;
3027 		}
3028 
3029 		memcpy(&soc->hal_reg_cap[reg_cap.phy_id],
3030 		       &reg_cap, sizeof(reg_cap));
3031 	}
3032 	return 0;
3033 }
3034 
3035 static int ath11k_wmi_tlv_ext_soc_hal_reg_caps_parse(struct ath11k_base *soc,
3036 						     u16 len, const void *ptr,
3037 						     void *data)
3038 {
3039 	struct ath11k_pdev_wmi *wmi_handle = &soc->wmi_sc.wmi[0];
3040 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3041 	u8 hw_mode_id = svc_rdy_ext->pref_hw_mode_caps.hw_mode_id;
3042 	u32 phy_id_map;
3043 	int ret;
3044 
3045 	svc_rdy_ext->soc_hal_reg_caps = (struct wmi_soc_hal_reg_capabilities *)ptr;
3046 	svc_rdy_ext->param.num_phy = svc_rdy_ext->soc_hal_reg_caps->num_phy;
3047 
3048 	soc->num_radios = 0;
3049 	phy_id_map = svc_rdy_ext->pref_hw_mode_caps.phy_id_map;
3050 
3051 	while (phy_id_map && soc->num_radios < MAX_RADIOS) {
3052 		ret = ath11k_pull_mac_phy_cap_svc_ready_ext(wmi_handle,
3053 							    svc_rdy_ext->hw_caps,
3054 							    svc_rdy_ext->hw_mode_caps,
3055 							    svc_rdy_ext->soc_hal_reg_caps,
3056 							    svc_rdy_ext->mac_phy_caps,
3057 							    hw_mode_id, soc->num_radios,
3058 							    &soc->pdevs[soc->num_radios]);
3059 		if (ret) {
3060 			ath11k_warn(soc, "failed to extract mac caps, idx :%d\n",
3061 				    soc->num_radios);
3062 			return ret;
3063 		}
3064 
3065 		soc->num_radios++;
3066 
3067 		/* TODO: mac_phy_cap prints */
3068 		phy_id_map >>= 1;
3069 	}
3070 	return 0;
3071 }
3072 
3073 static int ath11k_wmi_tlv_svc_rdy_ext_parse(struct ath11k_base *ab,
3074 					    u16 tag, u16 len,
3075 					    const void *ptr, void *data)
3076 {
3077 	struct ath11k_pdev_wmi *wmi_handle = &ab->wmi_sc.wmi[0];
3078 	struct wmi_tlv_svc_rdy_ext_parse *svc_rdy_ext = data;
3079 	int ret;
3080 
3081 	switch (tag) {
3082 	case WMI_TAG_SERVICE_READY_EXT_EVENT:
3083 		ret = ath11k_pull_svc_ready_ext(wmi_handle, ptr,
3084 						&svc_rdy_ext->param);
3085 		if (ret) {
3086 			ath11k_warn(ab, "unable to extract ext params\n");
3087 			return ret;
3088 		}
3089 		break;
3090 
3091 	case WMI_TAG_SOC_MAC_PHY_HW_MODE_CAPS:
3092 		svc_rdy_ext->hw_caps = (struct wmi_soc_mac_phy_hw_mode_caps *)ptr;
3093 		svc_rdy_ext->param.num_hw_modes = svc_rdy_ext->hw_caps->num_hw_modes;
3094 		break;
3095 
3096 	case WMI_TAG_SOC_HAL_REG_CAPABILITIES:
3097 		ret = ath11k_wmi_tlv_ext_soc_hal_reg_caps_parse(ab, len, ptr,
3098 								svc_rdy_ext);
3099 		if (ret)
3100 			return ret;
3101 		break;
3102 
3103 	case WMI_TAG_ARRAY_STRUCT:
3104 		if (!svc_rdy_ext->hw_mode_done) {
3105 			ret = ath11k_wmi_tlv_hw_mode_caps(ab, len, ptr,
3106 							  svc_rdy_ext);
3107 			if (ret)
3108 				return ret;
3109 
3110 			svc_rdy_ext->hw_mode_done = true;
3111 		} else if (!svc_rdy_ext->mac_phy_done) {
3112 			svc_rdy_ext->n_mac_phy_caps = 0;
3113 			ret = ath11k_wmi_tlv_iter(ab, ptr, len,
3114 						  ath11k_wmi_tlv_mac_phy_caps_parse,
3115 						  svc_rdy_ext);
3116 			if (ret) {
3117 				ath11k_warn(ab, "failed to parse tlv %d\n", ret);
3118 				return ret;
3119 			}
3120 
3121 			svc_rdy_ext->mac_phy_done = true;
3122 		} else if (!svc_rdy_ext->ext_hal_reg_done) {
3123 			ret = ath11k_wmi_tlv_ext_hal_reg_caps(ab, len, ptr,
3124 							      svc_rdy_ext);
3125 			if (ret)
3126 				return ret;
3127 
3128 			svc_rdy_ext->ext_hal_reg_done = true;
3129 			complete(&ab->wmi_sc.service_ready);
3130 		}
3131 		break;
3132 
3133 	default:
3134 		break;
3135 	}
3136 	return 0;
3137 }
3138 
3139 static int ath11k_service_ready_ext_event(struct ath11k_base *ab,
3140 					  struct sk_buff *skb)
3141 {
3142 	struct wmi_tlv_svc_rdy_ext_parse svc_rdy_ext = { };
3143 	int ret;
3144 
3145 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
3146 				  ath11k_wmi_tlv_svc_rdy_ext_parse,
3147 				  &svc_rdy_ext);
3148 	if (ret) {
3149 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
3150 		return ret;
3151 	}
3152 
3153 	kfree(svc_rdy_ext.mac_phy_caps);
3154 	return 0;
3155 }
3156 
3157 static int ath11k_pull_vdev_start_resp_tlv(struct ath11k_base *ab, struct sk_buff *skb,
3158 					   struct wmi_vdev_start_resp_event *vdev_rsp)
3159 {
3160 	const void **tb;
3161 	const struct wmi_vdev_start_resp_event *ev;
3162 	int ret;
3163 
3164 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3165 	if (IS_ERR(tb)) {
3166 		ret = PTR_ERR(tb);
3167 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3168 		return ret;
3169 	}
3170 
3171 	ev = tb[WMI_TAG_VDEV_START_RESPONSE_EVENT];
3172 	if (!ev) {
3173 		ath11k_warn(ab, "failed to fetch vdev start resp ev");
3174 		kfree(tb);
3175 		return -EPROTO;
3176 	}
3177 
3178 	memset(vdev_rsp, 0, sizeof(*vdev_rsp));
3179 
3180 	vdev_rsp->vdev_id = ev->vdev_id;
3181 	vdev_rsp->requestor_id = ev->requestor_id;
3182 	vdev_rsp->resp_type = ev->resp_type;
3183 	vdev_rsp->status = ev->status;
3184 	vdev_rsp->chain_mask = ev->chain_mask;
3185 	vdev_rsp->smps_mode = ev->smps_mode;
3186 	vdev_rsp->mac_id = ev->mac_id;
3187 	vdev_rsp->cfgd_tx_streams = ev->cfgd_tx_streams;
3188 	vdev_rsp->cfgd_rx_streams = ev->cfgd_rx_streams;
3189 
3190 	kfree(tb);
3191 	return 0;
3192 }
3193 
3194 static struct cur_reg_rule
3195 *create_reg_rules_from_wmi(u32 num_reg_rules,
3196 			   struct wmi_regulatory_rule_struct *wmi_reg_rule)
3197 {
3198 	struct cur_reg_rule *reg_rule_ptr;
3199 	u32 count;
3200 
3201 	reg_rule_ptr =  kzalloc((num_reg_rules * sizeof(*reg_rule_ptr)),
3202 				GFP_ATOMIC);
3203 
3204 	if (!reg_rule_ptr)
3205 		return NULL;
3206 
3207 	for (count = 0; count < num_reg_rules; count++) {
3208 		reg_rule_ptr[count].start_freq =
3209 			FIELD_GET(REG_RULE_START_FREQ,
3210 				  wmi_reg_rule[count].freq_info);
3211 		reg_rule_ptr[count].end_freq =
3212 			FIELD_GET(REG_RULE_END_FREQ,
3213 				  wmi_reg_rule[count].freq_info);
3214 		reg_rule_ptr[count].max_bw =
3215 			FIELD_GET(REG_RULE_MAX_BW,
3216 				  wmi_reg_rule[count].bw_pwr_info);
3217 		reg_rule_ptr[count].reg_power =
3218 			FIELD_GET(REG_RULE_REG_PWR,
3219 				  wmi_reg_rule[count].bw_pwr_info);
3220 		reg_rule_ptr[count].ant_gain =
3221 			FIELD_GET(REG_RULE_ANT_GAIN,
3222 				  wmi_reg_rule[count].bw_pwr_info);
3223 		reg_rule_ptr[count].flags =
3224 			FIELD_GET(REG_RULE_FLAGS,
3225 				  wmi_reg_rule[count].flag_info);
3226 	}
3227 
3228 	return reg_rule_ptr;
3229 }
3230 
3231 static int ath11k_pull_reg_chan_list_update_ev(struct ath11k_base *ab,
3232 					       struct sk_buff *skb,
3233 					       struct cur_regulatory_info *reg_info)
3234 {
3235 	const void **tb;
3236 	const struct wmi_reg_chan_list_cc_event *chan_list_event_hdr;
3237 	struct wmi_regulatory_rule_struct *wmi_reg_rule;
3238 	u32 num_2g_reg_rules, num_5g_reg_rules;
3239 	int ret;
3240 
3241 	ath11k_dbg(ab, ATH11K_DBG_WMI, "processing regulatory channel list\n");
3242 
3243 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3244 	if (IS_ERR(tb)) {
3245 		ret = PTR_ERR(tb);
3246 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3247 		return ret;
3248 	}
3249 
3250 	chan_list_event_hdr = tb[WMI_TAG_REG_CHAN_LIST_CC_EVENT];
3251 	if (!chan_list_event_hdr) {
3252 		ath11k_warn(ab, "failed to fetch reg chan list update ev\n");
3253 		kfree(tb);
3254 		return -EPROTO;
3255 	}
3256 
3257 	reg_info->num_2g_reg_rules = chan_list_event_hdr->num_2g_reg_rules;
3258 	reg_info->num_5g_reg_rules = chan_list_event_hdr->num_5g_reg_rules;
3259 
3260 	if (!(reg_info->num_2g_reg_rules + reg_info->num_5g_reg_rules)) {
3261 		ath11k_warn(ab, "No regulatory rules available in the event info\n");
3262 		kfree(tb);
3263 		return -EINVAL;
3264 	}
3265 
3266 	memcpy(reg_info->alpha2, &chan_list_event_hdr->alpha2,
3267 	       REG_ALPHA2_LEN);
3268 	reg_info->dfs_region = chan_list_event_hdr->dfs_region;
3269 	reg_info->phybitmap = chan_list_event_hdr->phybitmap;
3270 	reg_info->num_phy = chan_list_event_hdr->num_phy;
3271 	reg_info->phy_id = chan_list_event_hdr->phy_id;
3272 	reg_info->ctry_code = chan_list_event_hdr->country_id;
3273 	reg_info->reg_dmn_pair = chan_list_event_hdr->domain_code;
3274 	if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_PASS)
3275 		reg_info->status_code = REG_SET_CC_STATUS_PASS;
3276 	else if (chan_list_event_hdr->status_code == WMI_REG_CURRENT_ALPHA2_NOT_FOUND)
3277 		reg_info->status_code = REG_CURRENT_ALPHA2_NOT_FOUND;
3278 	else if (chan_list_event_hdr->status_code == WMI_REG_INIT_ALPHA2_NOT_FOUND)
3279 		reg_info->status_code = REG_INIT_ALPHA2_NOT_FOUND;
3280 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_CHANGE_NOT_ALLOWED)
3281 		reg_info->status_code = REG_SET_CC_CHANGE_NOT_ALLOWED;
3282 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_NO_MEMORY)
3283 		reg_info->status_code = REG_SET_CC_STATUS_NO_MEMORY;
3284 	else if (chan_list_event_hdr->status_code == WMI_REG_SET_CC_STATUS_FAIL)
3285 		reg_info->status_code = REG_SET_CC_STATUS_FAIL;
3286 
3287 	reg_info->min_bw_2g = chan_list_event_hdr->min_bw_2g;
3288 	reg_info->max_bw_2g = chan_list_event_hdr->max_bw_2g;
3289 	reg_info->min_bw_5g = chan_list_event_hdr->min_bw_5g;
3290 	reg_info->max_bw_5g = chan_list_event_hdr->max_bw_5g;
3291 
3292 	num_2g_reg_rules = reg_info->num_2g_reg_rules;
3293 	num_5g_reg_rules = reg_info->num_5g_reg_rules;
3294 
3295 	ath11k_dbg(ab, ATH11K_DBG_WMI,
3296 		   "%s:cc %s dsf %d BW: min_2g %d max_2g %d min_5g %d max_5g %d",
3297 		   __func__, reg_info->alpha2, reg_info->dfs_region,
3298 		   reg_info->min_bw_2g, reg_info->max_bw_2g,
3299 		   reg_info->min_bw_5g, reg_info->max_bw_5g);
3300 
3301 	ath11k_dbg(ab, ATH11K_DBG_WMI,
3302 		   "%s: num_2g_reg_rules %d num_5g_reg_rules %d", __func__,
3303 		   num_2g_reg_rules, num_5g_reg_rules);
3304 
3305 	wmi_reg_rule =
3306 		(struct wmi_regulatory_rule_struct *)((u8 *)chan_list_event_hdr
3307 						+ sizeof(*chan_list_event_hdr)
3308 						+ sizeof(struct wmi_tlv));
3309 
3310 	if (num_2g_reg_rules) {
3311 		reg_info->reg_rules_2g_ptr = create_reg_rules_from_wmi(num_2g_reg_rules,
3312 								       wmi_reg_rule);
3313 		if (!reg_info->reg_rules_2g_ptr) {
3314 			kfree(tb);
3315 			ath11k_warn(ab, "Unable to Allocate memory for 2g rules\n");
3316 			return -ENOMEM;
3317 		}
3318 	}
3319 
3320 	if (num_5g_reg_rules) {
3321 		wmi_reg_rule += num_2g_reg_rules;
3322 		reg_info->reg_rules_5g_ptr = create_reg_rules_from_wmi(num_5g_reg_rules,
3323 								       wmi_reg_rule);
3324 		if (!reg_info->reg_rules_5g_ptr) {
3325 			kfree(tb);
3326 			ath11k_warn(ab, "Unable to Allocate memory for 5g rules\n");
3327 			return -ENOMEM;
3328 		}
3329 	}
3330 
3331 	ath11k_dbg(ab, ATH11K_DBG_WMI, "processed regulatory channel list\n");
3332 
3333 	kfree(tb);
3334 	return 0;
3335 }
3336 
3337 static int ath11k_pull_peer_del_resp_ev(struct ath11k_base *ab, struct sk_buff *skb,
3338 					struct wmi_peer_delete_resp_event *peer_del_resp)
3339 {
3340 	const void **tb;
3341 	const struct wmi_peer_delete_resp_event *ev;
3342 	int ret;
3343 
3344 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3345 	if (IS_ERR(tb)) {
3346 		ret = PTR_ERR(tb);
3347 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3348 		return ret;
3349 	}
3350 
3351 	ev = tb[WMI_TAG_PEER_DELETE_RESP_EVENT];
3352 	if (!ev) {
3353 		ath11k_warn(ab, "failed to fetch peer delete resp ev");
3354 		kfree(tb);
3355 		return -EPROTO;
3356 	}
3357 
3358 	memset(peer_del_resp, 0, sizeof(*peer_del_resp));
3359 
3360 	peer_del_resp->vdev_id = ev->vdev_id;
3361 	ether_addr_copy(peer_del_resp->peer_macaddr.addr,
3362 			ev->peer_macaddr.addr);
3363 
3364 	kfree(tb);
3365 	return 0;
3366 }
3367 
3368 static int ath11k_pull_bcn_tx_status_ev(struct ath11k_base *ab, void *evt_buf,
3369 					u32 len, u32 *vdev_id,
3370 					u32 *tx_status)
3371 {
3372 	const void **tb;
3373 	const struct wmi_bcn_tx_status_event *ev;
3374 	int ret;
3375 
3376 	tb = ath11k_wmi_tlv_parse_alloc(ab, evt_buf, len, GFP_ATOMIC);
3377 	if (IS_ERR(tb)) {
3378 		ret = PTR_ERR(tb);
3379 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3380 		return ret;
3381 	}
3382 
3383 	ev = tb[WMI_TAG_OFFLOAD_BCN_TX_STATUS_EVENT];
3384 	if (!ev) {
3385 		ath11k_warn(ab, "failed to fetch bcn tx status ev");
3386 		kfree(tb);
3387 		return -EPROTO;
3388 	}
3389 
3390 	*vdev_id   = ev->vdev_id;
3391 	*tx_status = ev->tx_status;
3392 
3393 	kfree(tb);
3394 	return 0;
3395 }
3396 
3397 static int ath11k_pull_vdev_stopped_param_tlv(struct ath11k_base *ab, struct sk_buff *skb,
3398 					      u32 *vdev_id)
3399 {
3400 	const void **tb;
3401 	const struct wmi_vdev_stopped_event *ev;
3402 	int ret;
3403 
3404 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3405 	if (IS_ERR(tb)) {
3406 		ret = PTR_ERR(tb);
3407 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3408 		return ret;
3409 	}
3410 
3411 	ev = tb[WMI_TAG_VDEV_STOPPED_EVENT];
3412 	if (!ev) {
3413 		ath11k_warn(ab, "failed to fetch vdev stop ev");
3414 		kfree(tb);
3415 		return -EPROTO;
3416 	}
3417 
3418 	*vdev_id =  ev->vdev_id;
3419 
3420 	kfree(tb);
3421 	return 0;
3422 }
3423 
3424 static int ath11k_pull_mgmt_rx_params_tlv(struct ath11k_base *ab,
3425 					  struct sk_buff *skb,
3426 					  struct mgmt_rx_event_params *hdr)
3427 {
3428 	const void **tb;
3429 	const struct wmi_mgmt_rx_hdr *ev;
3430 	const u8 *frame;
3431 	int ret;
3432 
3433 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3434 	if (IS_ERR(tb)) {
3435 		ret = PTR_ERR(tb);
3436 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3437 		return ret;
3438 	}
3439 
3440 	ev = tb[WMI_TAG_MGMT_RX_HDR];
3441 	frame = tb[WMI_TAG_ARRAY_BYTE];
3442 
3443 	if (!ev || !frame) {
3444 		ath11k_warn(ab, "failed to fetch mgmt rx hdr");
3445 		kfree(tb);
3446 		return -EPROTO;
3447 	}
3448 
3449 	hdr->pdev_id =  ev->pdev_id;
3450 	hdr->channel =  ev->channel;
3451 	hdr->snr =  ev->snr;
3452 	hdr->rate =  ev->rate;
3453 	hdr->phy_mode =  ev->phy_mode;
3454 	hdr->buf_len =  ev->buf_len;
3455 	hdr->status =  ev->status;
3456 	hdr->flags =  ev->flags;
3457 	hdr->rssi =  ev->rssi;
3458 	hdr->tsf_delta =  ev->tsf_delta;
3459 	memcpy(hdr->rssi_ctl, ev->rssi_ctl, sizeof(hdr->rssi_ctl));
3460 
3461 	if (skb->len < (frame - skb->data) + hdr->buf_len) {
3462 		ath11k_warn(ab, "invalid length in mgmt rx hdr ev");
3463 		kfree(tb);
3464 		return -EPROTO;
3465 	}
3466 
3467 	/* shift the sk_buff to point to `frame` */
3468 	skb_trim(skb, 0);
3469 	skb_put(skb, frame - skb->data);
3470 	skb_pull(skb, frame - skb->data);
3471 	skb_put(skb, hdr->buf_len);
3472 
3473 	ath11k_ce_byte_swap(skb->data, hdr->buf_len);
3474 
3475 	kfree(tb);
3476 	return 0;
3477 }
3478 
3479 static int wmi_process_mgmt_tx_comp(struct ath11k *ar, u32 desc_id,
3480 				    u32 status)
3481 {
3482 	struct sk_buff *msdu;
3483 	struct ieee80211_tx_info *info;
3484 	struct ath11k_skb_cb *skb_cb;
3485 
3486 	spin_lock_bh(&ar->txmgmt_idr_lock);
3487 	msdu = idr_find(&ar->txmgmt_idr, desc_id);
3488 
3489 	if (!msdu) {
3490 		ath11k_warn(ar->ab, "received mgmt tx compl for invalid msdu_id: %d\n",
3491 			    desc_id);
3492 		spin_unlock_bh(&ar->txmgmt_idr_lock);
3493 		return -ENOENT;
3494 	}
3495 
3496 	idr_remove(&ar->txmgmt_idr, desc_id);
3497 	spin_unlock_bh(&ar->txmgmt_idr_lock);
3498 
3499 	skb_cb = ATH11K_SKB_CB(msdu);
3500 	dma_unmap_single(ar->ab->dev, skb_cb->paddr, msdu->len, DMA_TO_DEVICE);
3501 
3502 	info = IEEE80211_SKB_CB(msdu);
3503 	if ((!(info->flags & IEEE80211_TX_CTL_NO_ACK)) && !status)
3504 		info->flags |= IEEE80211_TX_STAT_ACK;
3505 
3506 	ieee80211_tx_status_irqsafe(ar->hw, msdu);
3507 
3508 	WARN_ON_ONCE(atomic_read(&ar->num_pending_mgmt_tx) == 0);
3509 	atomic_dec(&ar->num_pending_mgmt_tx);
3510 
3511 	return 0;
3512 }
3513 
3514 static int ath11k_pull_mgmt_tx_compl_param_tlv(struct ath11k_base *ab,
3515 					       struct sk_buff *skb,
3516 					       struct wmi_mgmt_tx_compl_event *param)
3517 {
3518 	const void **tb;
3519 	const struct wmi_mgmt_tx_compl_event *ev;
3520 	int ret;
3521 
3522 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3523 	if (IS_ERR(tb)) {
3524 		ret = PTR_ERR(tb);
3525 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3526 		return ret;
3527 	}
3528 
3529 	ev = tb[WMI_TAG_MGMT_TX_COMPL_EVENT];
3530 	if (!ev) {
3531 		ath11k_warn(ab, "failed to fetch mgmt tx compl ev");
3532 		kfree(tb);
3533 		return -EPROTO;
3534 	}
3535 
3536 	param->pdev_id = ev->pdev_id;
3537 	param->desc_id = ev->desc_id;
3538 	param->status = ev->status;
3539 
3540 	kfree(tb);
3541 	return 0;
3542 }
3543 
3544 static void ath11k_wmi_event_scan_started(struct ath11k *ar)
3545 {
3546 	lockdep_assert_held(&ar->data_lock);
3547 
3548 	switch (ar->scan.state) {
3549 	case ATH11K_SCAN_IDLE:
3550 	case ATH11K_SCAN_RUNNING:
3551 	case ATH11K_SCAN_ABORTING:
3552 		ath11k_warn(ar->ab, "received scan started event in an invalid scan state: %s (%d)\n",
3553 			    ath11k_scan_state_str(ar->scan.state),
3554 			    ar->scan.state);
3555 		break;
3556 	case ATH11K_SCAN_STARTING:
3557 		ar->scan.state = ATH11K_SCAN_RUNNING;
3558 		complete(&ar->scan.started);
3559 		break;
3560 	}
3561 }
3562 
3563 static void ath11k_wmi_event_scan_start_failed(struct ath11k *ar)
3564 {
3565 	lockdep_assert_held(&ar->data_lock);
3566 
3567 	switch (ar->scan.state) {
3568 	case ATH11K_SCAN_IDLE:
3569 	case ATH11K_SCAN_RUNNING:
3570 	case ATH11K_SCAN_ABORTING:
3571 		ath11k_warn(ar->ab, "received scan start failed event in an invalid scan state: %s (%d)\n",
3572 			    ath11k_scan_state_str(ar->scan.state),
3573 			    ar->scan.state);
3574 		break;
3575 	case ATH11K_SCAN_STARTING:
3576 		complete(&ar->scan.started);
3577 		__ath11k_mac_scan_finish(ar);
3578 		break;
3579 	}
3580 }
3581 
3582 static void ath11k_wmi_event_scan_completed(struct ath11k *ar)
3583 {
3584 	lockdep_assert_held(&ar->data_lock);
3585 
3586 	switch (ar->scan.state) {
3587 	case ATH11K_SCAN_IDLE:
3588 	case ATH11K_SCAN_STARTING:
3589 		/* One suspected reason scan can be completed while starting is
3590 		 * if firmware fails to deliver all scan events to the host,
3591 		 * e.g. when transport pipe is full. This has been observed
3592 		 * with spectral scan phyerr events starving wmi transport
3593 		 * pipe. In such case the "scan completed" event should be (and
3594 		 * is) ignored by the host as it may be just firmware's scan
3595 		 * state machine recovering.
3596 		 */
3597 		ath11k_warn(ar->ab, "received scan completed event in an invalid scan state: %s (%d)\n",
3598 			    ath11k_scan_state_str(ar->scan.state),
3599 			    ar->scan.state);
3600 		break;
3601 	case ATH11K_SCAN_RUNNING:
3602 	case ATH11K_SCAN_ABORTING:
3603 		__ath11k_mac_scan_finish(ar);
3604 		break;
3605 	}
3606 }
3607 
3608 static void ath11k_wmi_event_scan_bss_chan(struct ath11k *ar)
3609 {
3610 	lockdep_assert_held(&ar->data_lock);
3611 
3612 	switch (ar->scan.state) {
3613 	case ATH11K_SCAN_IDLE:
3614 	case ATH11K_SCAN_STARTING:
3615 		ath11k_warn(ar->ab, "received scan bss chan event in an invalid scan state: %s (%d)\n",
3616 			    ath11k_scan_state_str(ar->scan.state),
3617 			    ar->scan.state);
3618 		break;
3619 	case ATH11K_SCAN_RUNNING:
3620 	case ATH11K_SCAN_ABORTING:
3621 		ar->scan_channel = NULL;
3622 		break;
3623 	}
3624 }
3625 
3626 static void ath11k_wmi_event_scan_foreign_chan(struct ath11k *ar, u32 freq)
3627 {
3628 	lockdep_assert_held(&ar->data_lock);
3629 
3630 	switch (ar->scan.state) {
3631 	case ATH11K_SCAN_IDLE:
3632 	case ATH11K_SCAN_STARTING:
3633 		ath11k_warn(ar->ab, "received scan foreign chan event in an invalid scan state: %s (%d)\n",
3634 			    ath11k_scan_state_str(ar->scan.state),
3635 			    ar->scan.state);
3636 		break;
3637 	case ATH11K_SCAN_RUNNING:
3638 	case ATH11K_SCAN_ABORTING:
3639 		ar->scan_channel = ieee80211_get_channel(ar->hw->wiphy, freq);
3640 		break;
3641 	}
3642 }
3643 
3644 static const char *
3645 ath11k_wmi_event_scan_type_str(enum wmi_scan_event_type type,
3646 			       enum wmi_scan_completion_reason reason)
3647 {
3648 	switch (type) {
3649 	case WMI_SCAN_EVENT_STARTED:
3650 		return "started";
3651 	case WMI_SCAN_EVENT_COMPLETED:
3652 		switch (reason) {
3653 		case WMI_SCAN_REASON_COMPLETED:
3654 			return "completed";
3655 		case WMI_SCAN_REASON_CANCELLED:
3656 			return "completed [cancelled]";
3657 		case WMI_SCAN_REASON_PREEMPTED:
3658 			return "completed [preempted]";
3659 		case WMI_SCAN_REASON_TIMEDOUT:
3660 			return "completed [timedout]";
3661 		case WMI_SCAN_REASON_INTERNAL_FAILURE:
3662 			return "completed [internal err]";
3663 		case WMI_SCAN_REASON_MAX:
3664 			break;
3665 		}
3666 		return "completed [unknown]";
3667 	case WMI_SCAN_EVENT_BSS_CHANNEL:
3668 		return "bss channel";
3669 	case WMI_SCAN_EVENT_FOREIGN_CHAN:
3670 		return "foreign channel";
3671 	case WMI_SCAN_EVENT_DEQUEUED:
3672 		return "dequeued";
3673 	case WMI_SCAN_EVENT_PREEMPTED:
3674 		return "preempted";
3675 	case WMI_SCAN_EVENT_START_FAILED:
3676 		return "start failed";
3677 	case WMI_SCAN_EVENT_RESTARTED:
3678 		return "restarted";
3679 	case WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT:
3680 		return "foreign channel exit";
3681 	default:
3682 		return "unknown";
3683 	}
3684 }
3685 
3686 static int ath11k_pull_scan_ev(struct ath11k_base *ab, struct sk_buff *skb,
3687 			       struct wmi_scan_event *scan_evt_param)
3688 {
3689 	const void **tb;
3690 	const struct wmi_scan_event *ev;
3691 	int ret;
3692 
3693 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3694 	if (IS_ERR(tb)) {
3695 		ret = PTR_ERR(tb);
3696 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3697 		return ret;
3698 	}
3699 
3700 	ev = tb[WMI_TAG_SCAN_EVENT];
3701 	if (!ev) {
3702 		ath11k_warn(ab, "failed to fetch scan ev");
3703 		kfree(tb);
3704 		return -EPROTO;
3705 	}
3706 
3707 	scan_evt_param->event_type = ev->event_type;
3708 	scan_evt_param->reason = ev->reason;
3709 	scan_evt_param->channel_freq = ev->channel_freq;
3710 	scan_evt_param->scan_req_id = ev->scan_req_id;
3711 	scan_evt_param->scan_id = ev->scan_id;
3712 	scan_evt_param->vdev_id = ev->vdev_id;
3713 	scan_evt_param->tsf_timestamp = ev->tsf_timestamp;
3714 
3715 	kfree(tb);
3716 	return 0;
3717 }
3718 
3719 static int ath11k_pull_peer_sta_kickout_ev(struct ath11k_base *ab, struct sk_buff *skb,
3720 					   struct wmi_peer_sta_kickout_arg *arg)
3721 {
3722 	const void **tb;
3723 	const struct wmi_peer_sta_kickout_event *ev;
3724 	int ret;
3725 
3726 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3727 	if (IS_ERR(tb)) {
3728 		ret = PTR_ERR(tb);
3729 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3730 		return ret;
3731 	}
3732 
3733 	ev = tb[WMI_TAG_PEER_STA_KICKOUT_EVENT];
3734 	if (!ev) {
3735 		ath11k_warn(ab, "failed to fetch peer sta kickout ev");
3736 		kfree(tb);
3737 		return -EPROTO;
3738 	}
3739 
3740 	arg->mac_addr = ev->peer_macaddr.addr;
3741 
3742 	kfree(tb);
3743 	return 0;
3744 }
3745 
3746 static int ath11k_pull_roam_ev(struct ath11k_base *ab, struct sk_buff *skb,
3747 			       struct wmi_roam_event *roam_ev)
3748 {
3749 	const void **tb;
3750 	const struct wmi_roam_event *ev;
3751 	int ret;
3752 
3753 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3754 	if (IS_ERR(tb)) {
3755 		ret = PTR_ERR(tb);
3756 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3757 		return ret;
3758 	}
3759 
3760 	ev = tb[WMI_TAG_ROAM_EVENT];
3761 	if (!ev) {
3762 		ath11k_warn(ab, "failed to fetch roam ev");
3763 		kfree(tb);
3764 		return -EPROTO;
3765 	}
3766 
3767 	roam_ev->vdev_id = ev->vdev_id;
3768 	roam_ev->reason = ev->reason;
3769 	roam_ev->rssi = ev->rssi;
3770 
3771 	kfree(tb);
3772 	return 0;
3773 }
3774 
3775 static int freq_to_idx(struct ath11k *ar, int freq)
3776 {
3777 	struct ieee80211_supported_band *sband;
3778 	int band, ch, idx = 0;
3779 
3780 	for (band = NL80211_BAND_2GHZ; band < NUM_NL80211_BANDS; band++) {
3781 		sband = ar->hw->wiphy->bands[band];
3782 		if (!sband)
3783 			continue;
3784 
3785 		for (ch = 0; ch < sband->n_channels; ch++, idx++)
3786 			if (sband->channels[ch].center_freq == freq)
3787 				goto exit;
3788 	}
3789 
3790 exit:
3791 	return idx;
3792 }
3793 
3794 static int ath11k_pull_chan_info_ev(struct ath11k_base *ab, u8 *evt_buf,
3795 				    u32 len, struct wmi_chan_info_event *ch_info_ev)
3796 {
3797 	const void **tb;
3798 	const struct wmi_chan_info_event *ev;
3799 	int ret;
3800 
3801 	tb = ath11k_wmi_tlv_parse_alloc(ab, evt_buf, len, GFP_ATOMIC);
3802 	if (IS_ERR(tb)) {
3803 		ret = PTR_ERR(tb);
3804 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3805 		return ret;
3806 	}
3807 
3808 	ev = tb[WMI_TAG_CHAN_INFO_EVENT];
3809 	if (!ev) {
3810 		ath11k_warn(ab, "failed to fetch chan info ev");
3811 		kfree(tb);
3812 		return -EPROTO;
3813 	}
3814 
3815 	ch_info_ev->err_code = ev->err_code;
3816 	ch_info_ev->freq = ev->freq;
3817 	ch_info_ev->cmd_flags = ev->cmd_flags;
3818 	ch_info_ev->noise_floor = ev->noise_floor;
3819 	ch_info_ev->rx_clear_count = ev->rx_clear_count;
3820 	ch_info_ev->cycle_count = ev->cycle_count;
3821 	ch_info_ev->chan_tx_pwr_range = ev->chan_tx_pwr_range;
3822 	ch_info_ev->chan_tx_pwr_tp = ev->chan_tx_pwr_tp;
3823 	ch_info_ev->rx_frame_count = ev->rx_frame_count;
3824 	ch_info_ev->tx_frame_cnt = ev->tx_frame_cnt;
3825 	ch_info_ev->mac_clk_mhz = ev->mac_clk_mhz;
3826 	ch_info_ev->vdev_id = ev->vdev_id;
3827 
3828 	kfree(tb);
3829 	return 0;
3830 }
3831 
3832 static int
3833 ath11k_pull_pdev_bss_chan_info_ev(struct ath11k_base *ab, struct sk_buff *skb,
3834 				  struct wmi_pdev_bss_chan_info_event *bss_ch_info_ev)
3835 {
3836 	const void **tb;
3837 	const struct wmi_pdev_bss_chan_info_event *ev;
3838 	int ret;
3839 
3840 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3841 	if (IS_ERR(tb)) {
3842 		ret = PTR_ERR(tb);
3843 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3844 		return ret;
3845 	}
3846 
3847 	ev = tb[WMI_TAG_PDEV_BSS_CHAN_INFO_EVENT];
3848 	if (!ev) {
3849 		ath11k_warn(ab, "failed to fetch pdev bss chan info ev");
3850 		kfree(tb);
3851 		return -EPROTO;
3852 	}
3853 
3854 	bss_ch_info_ev->pdev_id = ev->pdev_id;
3855 	bss_ch_info_ev->freq = ev->freq;
3856 	bss_ch_info_ev->noise_floor = ev->noise_floor;
3857 	bss_ch_info_ev->rx_clear_count_low = ev->rx_clear_count_low;
3858 	bss_ch_info_ev->rx_clear_count_high = ev->rx_clear_count_high;
3859 	bss_ch_info_ev->cycle_count_low = ev->cycle_count_low;
3860 	bss_ch_info_ev->cycle_count_high = ev->cycle_count_high;
3861 	bss_ch_info_ev->tx_cycle_count_low = ev->tx_cycle_count_low;
3862 	bss_ch_info_ev->tx_cycle_count_high = ev->tx_cycle_count_high;
3863 	bss_ch_info_ev->rx_cycle_count_low = ev->rx_cycle_count_low;
3864 	bss_ch_info_ev->rx_cycle_count_high = ev->rx_cycle_count_high;
3865 	bss_ch_info_ev->rx_bss_cycle_count_low = ev->rx_bss_cycle_count_low;
3866 	bss_ch_info_ev->rx_bss_cycle_count_high = ev->rx_bss_cycle_count_high;
3867 
3868 	kfree(tb);
3869 	return 0;
3870 }
3871 
3872 static int
3873 ath11k_pull_vdev_install_key_compl_ev(struct ath11k_base *ab, struct sk_buff *skb,
3874 				      struct wmi_vdev_install_key_complete_arg *arg)
3875 {
3876 	const void **tb;
3877 	const struct wmi_vdev_install_key_compl_event *ev;
3878 	int ret;
3879 
3880 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3881 	if (IS_ERR(tb)) {
3882 		ret = PTR_ERR(tb);
3883 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3884 		return ret;
3885 	}
3886 
3887 	ev = tb[WMI_TAG_VDEV_INSTALL_KEY_COMPLETE_EVENT];
3888 	if (!ev) {
3889 		ath11k_warn(ab, "failed to fetch vdev install key compl ev");
3890 		kfree(tb);
3891 		return -EPROTO;
3892 	}
3893 
3894 	arg->vdev_id = ev->vdev_id;
3895 	arg->macaddr = ev->peer_macaddr.addr;
3896 	arg->key_idx = ev->key_idx;
3897 	arg->key_flags = ev->key_flags;
3898 	arg->status = ev->status;
3899 
3900 	kfree(tb);
3901 	return 0;
3902 }
3903 
3904 static int ath11k_pull_peer_assoc_conf_ev(struct ath11k_base *ab, struct sk_buff *skb,
3905 					  struct wmi_peer_assoc_conf_arg *peer_assoc_conf)
3906 {
3907 	const void **tb;
3908 	const struct wmi_peer_assoc_conf_event *ev;
3909 	int ret;
3910 
3911 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
3912 	if (IS_ERR(tb)) {
3913 		ret = PTR_ERR(tb);
3914 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
3915 		return ret;
3916 	}
3917 
3918 	ev = tb[WMI_TAG_PEER_ASSOC_CONF_EVENT];
3919 	if (!ev) {
3920 		ath11k_warn(ab, "failed to fetch peer assoc conf ev");
3921 		kfree(tb);
3922 		return -EPROTO;
3923 	}
3924 
3925 	peer_assoc_conf->vdev_id = ev->vdev_id;
3926 	peer_assoc_conf->macaddr = ev->peer_macaddr.addr;
3927 
3928 	kfree(tb);
3929 	return 0;
3930 }
3931 
3932 static void ath11k_wmi_pull_pdev_stats_base(const struct wmi_pdev_stats_base *src,
3933 					    struct ath11k_fw_stats_pdev *dst)
3934 {
3935 	dst->ch_noise_floor = src->chan_nf;
3936 	dst->tx_frame_count = src->tx_frame_count;
3937 	dst->rx_frame_count = src->rx_frame_count;
3938 	dst->rx_clear_count = src->rx_clear_count;
3939 	dst->cycle_count = src->cycle_count;
3940 	dst->phy_err_count = src->phy_err_count;
3941 	dst->chan_tx_power = src->chan_tx_pwr;
3942 }
3943 
3944 static void
3945 ath11k_wmi_pull_pdev_stats_tx(const struct wmi_pdev_stats_tx *src,
3946 			      struct ath11k_fw_stats_pdev *dst)
3947 {
3948 	dst->comp_queued = src->comp_queued;
3949 	dst->comp_delivered = src->comp_delivered;
3950 	dst->msdu_enqued = src->msdu_enqued;
3951 	dst->mpdu_enqued = src->mpdu_enqued;
3952 	dst->wmm_drop = src->wmm_drop;
3953 	dst->local_enqued = src->local_enqued;
3954 	dst->local_freed = src->local_freed;
3955 	dst->hw_queued = src->hw_queued;
3956 	dst->hw_reaped = src->hw_reaped;
3957 	dst->underrun = src->underrun;
3958 	dst->tx_abort = src->tx_abort;
3959 	dst->mpdus_requed = src->mpdus_requed;
3960 	dst->tx_ko = src->tx_ko;
3961 	dst->data_rc = src->data_rc;
3962 	dst->self_triggers = src->self_triggers;
3963 	dst->sw_retry_failure = src->sw_retry_failure;
3964 	dst->illgl_rate_phy_err = src->illgl_rate_phy_err;
3965 	dst->pdev_cont_xretry = src->pdev_cont_xretry;
3966 	dst->pdev_tx_timeout = src->pdev_tx_timeout;
3967 	dst->pdev_resets = src->pdev_resets;
3968 	dst->stateless_tid_alloc_failure = src->stateless_tid_alloc_failure;
3969 	dst->phy_underrun = src->phy_underrun;
3970 	dst->txop_ovf = src->txop_ovf;
3971 }
3972 
3973 static void ath11k_wmi_pull_pdev_stats_rx(const struct wmi_pdev_stats_rx *src,
3974 					  struct ath11k_fw_stats_pdev *dst)
3975 {
3976 	dst->mid_ppdu_route_change = src->mid_ppdu_route_change;
3977 	dst->status_rcvd = src->status_rcvd;
3978 	dst->r0_frags = src->r0_frags;
3979 	dst->r1_frags = src->r1_frags;
3980 	dst->r2_frags = src->r2_frags;
3981 	dst->r3_frags = src->r3_frags;
3982 	dst->htt_msdus = src->htt_msdus;
3983 	dst->htt_mpdus = src->htt_mpdus;
3984 	dst->loc_msdus = src->loc_msdus;
3985 	dst->loc_mpdus = src->loc_mpdus;
3986 	dst->oversize_amsdu = src->oversize_amsdu;
3987 	dst->phy_errs = src->phy_errs;
3988 	dst->phy_err_drop = src->phy_err_drop;
3989 	dst->mpdu_errs = src->mpdu_errs;
3990 }
3991 
3992 static void
3993 ath11k_wmi_pull_vdev_stats(const struct wmi_vdev_stats *src,
3994 			   struct ath11k_fw_stats_vdev *dst)
3995 {
3996 	int i;
3997 
3998 	dst->vdev_id = src->vdev_id;
3999 	dst->beacon_snr = src->beacon_snr;
4000 	dst->data_snr = src->data_snr;
4001 	dst->num_rx_frames = src->num_rx_frames;
4002 	dst->num_rts_fail = src->num_rts_fail;
4003 	dst->num_rts_success = src->num_rts_success;
4004 	dst->num_rx_err = src->num_rx_err;
4005 	dst->num_rx_discard = src->num_rx_discard;
4006 	dst->num_tx_not_acked = src->num_tx_not_acked;
4007 
4008 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames); i++)
4009 		dst->num_tx_frames[i] = src->num_tx_frames[i];
4010 
4011 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_retries); i++)
4012 		dst->num_tx_frames_retries[i] = src->num_tx_frames_retries[i];
4013 
4014 	for (i = 0; i < ARRAY_SIZE(src->num_tx_frames_failures); i++)
4015 		dst->num_tx_frames_failures[i] = src->num_tx_frames_failures[i];
4016 
4017 	for (i = 0; i < ARRAY_SIZE(src->tx_rate_history); i++)
4018 		dst->tx_rate_history[i] = src->tx_rate_history[i];
4019 
4020 	for (i = 0; i < ARRAY_SIZE(src->beacon_rssi_history); i++)
4021 		dst->beacon_rssi_history[i] = src->beacon_rssi_history[i];
4022 }
4023 
4024 static void
4025 ath11k_wmi_pull_bcn_stats(const struct wmi_bcn_stats *src,
4026 			  struct ath11k_fw_stats_bcn *dst)
4027 {
4028 	dst->vdev_id = src->vdev_id;
4029 	dst->tx_bcn_succ_cnt = src->tx_bcn_succ_cnt;
4030 	dst->tx_bcn_outage_cnt = src->tx_bcn_outage_cnt;
4031 }
4032 
4033 int ath11k_wmi_pull_fw_stats(struct ath11k_base *ab, struct sk_buff *skb,
4034 			     struct ath11k_fw_stats *stats)
4035 {
4036 	const void **tb;
4037 	const struct wmi_stats_event *ev;
4038 	const void *data;
4039 	int i, ret;
4040 	u32 len = skb->len;
4041 
4042 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, len, GFP_ATOMIC);
4043 	if (IS_ERR(tb)) {
4044 		ret = PTR_ERR(tb);
4045 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
4046 		return ret;
4047 	}
4048 
4049 	ev = tb[WMI_TAG_STATS_EVENT];
4050 	data = tb[WMI_TAG_ARRAY_BYTE];
4051 	if (!ev || !data) {
4052 		ath11k_warn(ab, "failed to fetch update stats ev");
4053 		kfree(tb);
4054 		return -EPROTO;
4055 	}
4056 
4057 	ath11k_dbg(ab, ATH11K_DBG_WMI,
4058 		   "wmi stats update ev pdev_id %d pdev %i vdev %i bcn %i\n",
4059 		   ev->pdev_id,
4060 		   ev->num_pdev_stats, ev->num_vdev_stats,
4061 		   ev->num_bcn_stats);
4062 
4063 	stats->pdev_id = ev->pdev_id;
4064 	stats->stats_id = 0;
4065 
4066 	for (i = 0; i < ev->num_pdev_stats; i++) {
4067 		const struct wmi_pdev_stats *src;
4068 		struct ath11k_fw_stats_pdev *dst;
4069 
4070 		src = data;
4071 		if (len < sizeof(*src)) {
4072 			kfree(tb);
4073 			return -EPROTO;
4074 		}
4075 
4076 		stats->stats_id = WMI_REQUEST_PDEV_STAT;
4077 
4078 		data += sizeof(*src);
4079 		len -= sizeof(*src);
4080 
4081 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
4082 		if (!dst)
4083 			continue;
4084 
4085 		ath11k_wmi_pull_pdev_stats_base(&src->base, dst);
4086 		ath11k_wmi_pull_pdev_stats_tx(&src->tx, dst);
4087 		ath11k_wmi_pull_pdev_stats_rx(&src->rx, dst);
4088 		list_add_tail(&dst->list, &stats->pdevs);
4089 	}
4090 
4091 	for (i = 0; i < ev->num_vdev_stats; i++) {
4092 		const struct wmi_vdev_stats *src;
4093 		struct ath11k_fw_stats_vdev *dst;
4094 
4095 		src = data;
4096 		if (len < sizeof(*src)) {
4097 			kfree(tb);
4098 			return -EPROTO;
4099 		}
4100 
4101 		stats->stats_id = WMI_REQUEST_VDEV_STAT;
4102 
4103 		data += sizeof(*src);
4104 		len -= sizeof(*src);
4105 
4106 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
4107 		if (!dst)
4108 			continue;
4109 
4110 		ath11k_wmi_pull_vdev_stats(src, dst);
4111 		list_add_tail(&dst->list, &stats->vdevs);
4112 	}
4113 
4114 	for (i = 0; i < ev->num_bcn_stats; i++) {
4115 		const struct wmi_bcn_stats *src;
4116 		struct ath11k_fw_stats_bcn *dst;
4117 
4118 		src = data;
4119 		if (len < sizeof(*src)) {
4120 			kfree(tb);
4121 			return -EPROTO;
4122 		}
4123 
4124 		stats->stats_id = WMI_REQUEST_BCN_STAT;
4125 
4126 		data += sizeof(*src);
4127 		len -= sizeof(*src);
4128 
4129 		dst = kzalloc(sizeof(*dst), GFP_ATOMIC);
4130 		if (!dst)
4131 			continue;
4132 
4133 		ath11k_wmi_pull_bcn_stats(src, dst);
4134 		list_add_tail(&dst->list, &stats->bcn);
4135 	}
4136 
4137 	kfree(tb);
4138 	return 0;
4139 }
4140 
4141 size_t ath11k_wmi_fw_stats_num_vdevs(struct list_head *head)
4142 {
4143 	struct ath11k_fw_stats_vdev *i;
4144 	size_t num = 0;
4145 
4146 	list_for_each_entry(i, head, list)
4147 		++num;
4148 
4149 	return num;
4150 }
4151 
4152 static size_t ath11k_wmi_fw_stats_num_bcn(struct list_head *head)
4153 {
4154 	struct ath11k_fw_stats_bcn *i;
4155 	size_t num = 0;
4156 
4157 	list_for_each_entry(i, head, list)
4158 		++num;
4159 
4160 	return num;
4161 }
4162 
4163 static void
4164 ath11k_wmi_fw_pdev_base_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
4165 				   char *buf, u32 *length)
4166 {
4167 	u32 len = *length;
4168 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
4169 
4170 	len += scnprintf(buf + len, buf_len - len, "\n");
4171 	len += scnprintf(buf + len, buf_len - len, "%30s\n",
4172 			"ath11k PDEV stats");
4173 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
4174 			"=================");
4175 
4176 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4177 			"Channel noise floor", pdev->ch_noise_floor);
4178 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4179 			"Channel TX power", pdev->chan_tx_power);
4180 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4181 			"TX frame count", pdev->tx_frame_count);
4182 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4183 			"RX frame count", pdev->rx_frame_count);
4184 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4185 			"RX clear count", pdev->rx_clear_count);
4186 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4187 			"Cycle count", pdev->cycle_count);
4188 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4189 			"PHY error count", pdev->phy_err_count);
4190 
4191 	*length = len;
4192 }
4193 
4194 static void
4195 ath11k_wmi_fw_pdev_tx_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
4196 				 char *buf, u32 *length)
4197 {
4198 	u32 len = *length;
4199 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
4200 
4201 	len += scnprintf(buf + len, buf_len - len, "\n%30s\n",
4202 			 "ath11k PDEV TX stats");
4203 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
4204 			 "====================");
4205 
4206 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4207 			 "HTT cookies queued", pdev->comp_queued);
4208 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4209 			 "HTT cookies disp.", pdev->comp_delivered);
4210 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4211 			 "MSDU queued", pdev->msdu_enqued);
4212 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4213 			 "MPDU queued", pdev->mpdu_enqued);
4214 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4215 			 "MSDUs dropped", pdev->wmm_drop);
4216 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4217 			 "Local enqued", pdev->local_enqued);
4218 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4219 			 "Local freed", pdev->local_freed);
4220 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4221 			 "HW queued", pdev->hw_queued);
4222 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4223 			 "PPDUs reaped", pdev->hw_reaped);
4224 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4225 			 "Num underruns", pdev->underrun);
4226 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4227 			 "PPDUs cleaned", pdev->tx_abort);
4228 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4229 			 "MPDUs requed", pdev->mpdus_requed);
4230 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4231 			 "Excessive retries", pdev->tx_ko);
4232 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4233 			 "HW rate", pdev->data_rc);
4234 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4235 			 "Sched self triggers", pdev->self_triggers);
4236 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4237 			 "Dropped due to SW retries",
4238 			 pdev->sw_retry_failure);
4239 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4240 			 "Illegal rate phy errors",
4241 			 pdev->illgl_rate_phy_err);
4242 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4243 			 "PDEV continuous xretry", pdev->pdev_cont_xretry);
4244 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4245 			 "TX timeout", pdev->pdev_tx_timeout);
4246 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4247 			 "PDEV resets", pdev->pdev_resets);
4248 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4249 			 "Stateless TIDs alloc failures",
4250 			 pdev->stateless_tid_alloc_failure);
4251 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4252 			 "PHY underrun", pdev->phy_underrun);
4253 	len += scnprintf(buf + len, buf_len - len, "%30s %10u\n",
4254 			 "MPDU is more than txop limit", pdev->txop_ovf);
4255 	*length = len;
4256 }
4257 
4258 static void
4259 ath11k_wmi_fw_pdev_rx_stats_fill(const struct ath11k_fw_stats_pdev *pdev,
4260 				 char *buf, u32 *length)
4261 {
4262 	u32 len = *length;
4263 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
4264 
4265 	len += scnprintf(buf + len, buf_len - len, "\n%30s\n",
4266 			 "ath11k PDEV RX stats");
4267 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
4268 			 "====================");
4269 
4270 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4271 			 "Mid PPDU route change",
4272 			 pdev->mid_ppdu_route_change);
4273 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4274 			 "Tot. number of statuses", pdev->status_rcvd);
4275 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4276 			 "Extra frags on rings 0", pdev->r0_frags);
4277 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4278 			 "Extra frags on rings 1", pdev->r1_frags);
4279 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4280 			 "Extra frags on rings 2", pdev->r2_frags);
4281 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4282 			 "Extra frags on rings 3", pdev->r3_frags);
4283 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4284 			 "MSDUs delivered to HTT", pdev->htt_msdus);
4285 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4286 			 "MPDUs delivered to HTT", pdev->htt_mpdus);
4287 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4288 			 "MSDUs delivered to stack", pdev->loc_msdus);
4289 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4290 			 "MPDUs delivered to stack", pdev->loc_mpdus);
4291 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4292 			 "Oversized AMSUs", pdev->oversize_amsdu);
4293 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4294 			 "PHY errors", pdev->phy_errs);
4295 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4296 			 "PHY errors drops", pdev->phy_err_drop);
4297 	len += scnprintf(buf + len, buf_len - len, "%30s %10d\n",
4298 			 "MPDU errors (FCS, MIC, ENC)", pdev->mpdu_errs);
4299 	*length = len;
4300 }
4301 
4302 static void
4303 ath11k_wmi_fw_vdev_stats_fill(struct ath11k *ar,
4304 			      const struct ath11k_fw_stats_vdev *vdev,
4305 			      char *buf, u32 *length)
4306 {
4307 	u32 len = *length;
4308 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
4309 	struct ath11k_vif *arvif = ath11k_mac_get_arvif(ar, vdev->vdev_id);
4310 	u8 *vif_macaddr;
4311 	int i;
4312 
4313 	/* VDEV stats has all the active VDEVs of other PDEVs as well,
4314 	 * ignoring those not part of requested PDEV
4315 	 */
4316 	if (!arvif)
4317 		return;
4318 
4319 	vif_macaddr = arvif->vif->addr;
4320 
4321 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4322 			 "VDEV ID", vdev->vdev_id);
4323 	len += scnprintf(buf + len, buf_len - len, "%30s %pM\n",
4324 			 "VDEV MAC address", vif_macaddr);
4325 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4326 			 "beacon snr", vdev->beacon_snr);
4327 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4328 			 "data snr", vdev->data_snr);
4329 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4330 			 "num rx frames", vdev->num_rx_frames);
4331 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4332 			 "num rts fail", vdev->num_rts_fail);
4333 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4334 			 "num rts success", vdev->num_rts_success);
4335 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4336 			 "num rx err", vdev->num_rx_err);
4337 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4338 			 "num rx discard", vdev->num_rx_discard);
4339 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4340 			 "num tx not acked", vdev->num_tx_not_acked);
4341 
4342 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames); i++)
4343 		len += scnprintf(buf + len, buf_len - len,
4344 				"%25s [%02d] %u\n",
4345 				"num tx frames", i,
4346 				vdev->num_tx_frames[i]);
4347 
4348 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames_retries); i++)
4349 		len += scnprintf(buf + len, buf_len - len,
4350 				"%25s [%02d] %u\n",
4351 				"num tx frames retries", i,
4352 				vdev->num_tx_frames_retries[i]);
4353 
4354 	for (i = 0 ; i < ARRAY_SIZE(vdev->num_tx_frames_failures); i++)
4355 		len += scnprintf(buf + len, buf_len - len,
4356 				"%25s [%02d] %u\n",
4357 				"num tx frames failures", i,
4358 				vdev->num_tx_frames_failures[i]);
4359 
4360 	for (i = 0 ; i < ARRAY_SIZE(vdev->tx_rate_history); i++)
4361 		len += scnprintf(buf + len, buf_len - len,
4362 				"%25s [%02d] 0x%08x\n",
4363 				"tx rate history", i,
4364 				vdev->tx_rate_history[i]);
4365 
4366 	for (i = 0 ; i < ARRAY_SIZE(vdev->beacon_rssi_history); i++)
4367 		len += scnprintf(buf + len, buf_len - len,
4368 				"%25s [%02d] %u\n",
4369 				"beacon rssi history", i,
4370 				vdev->beacon_rssi_history[i]);
4371 
4372 	len += scnprintf(buf + len, buf_len - len, "\n");
4373 	*length = len;
4374 }
4375 
4376 static void
4377 ath11k_wmi_fw_bcn_stats_fill(struct ath11k *ar,
4378 			     const struct ath11k_fw_stats_bcn *bcn,
4379 			     char *buf, u32 *length)
4380 {
4381 	u32 len = *length;
4382 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
4383 	struct ath11k_vif *arvif = ath11k_mac_get_arvif(ar, bcn->vdev_id);
4384 	u8 *vdev_macaddr;
4385 
4386 	if (!arvif) {
4387 		ath11k_warn(ar->ab, "invalid vdev id %d in bcn stats",
4388 			    bcn->vdev_id);
4389 		return;
4390 	}
4391 
4392 	vdev_macaddr = arvif->vif->addr;
4393 
4394 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4395 			 "VDEV ID", bcn->vdev_id);
4396 	len += scnprintf(buf + len, buf_len - len, "%30s %pM\n",
4397 			 "VDEV MAC address", vdev_macaddr);
4398 	len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
4399 			 "================");
4400 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4401 			 "Num of beacon tx success", bcn->tx_bcn_succ_cnt);
4402 	len += scnprintf(buf + len, buf_len - len, "%30s %u\n",
4403 			 "Num of beacon tx failures", bcn->tx_bcn_outage_cnt);
4404 
4405 	len += scnprintf(buf + len, buf_len - len, "\n");
4406 	*length = len;
4407 }
4408 
4409 void ath11k_wmi_fw_stats_fill(struct ath11k *ar,
4410 			      struct ath11k_fw_stats *fw_stats,
4411 			      u32 stats_id, char *buf)
4412 {
4413 	u32 len = 0;
4414 	u32 buf_len = ATH11K_FW_STATS_BUF_SIZE;
4415 	const struct ath11k_fw_stats_pdev *pdev;
4416 	const struct ath11k_fw_stats_vdev *vdev;
4417 	const struct ath11k_fw_stats_bcn *bcn;
4418 	size_t num_bcn;
4419 
4420 	spin_lock_bh(&ar->data_lock);
4421 
4422 	if (stats_id == WMI_REQUEST_PDEV_STAT) {
4423 		pdev = list_first_entry_or_null(&fw_stats->pdevs,
4424 						struct ath11k_fw_stats_pdev, list);
4425 		if (!pdev) {
4426 			ath11k_warn(ar->ab, "failed to get pdev stats\n");
4427 			goto unlock;
4428 		}
4429 
4430 		ath11k_wmi_fw_pdev_base_stats_fill(pdev, buf, &len);
4431 		ath11k_wmi_fw_pdev_tx_stats_fill(pdev, buf, &len);
4432 		ath11k_wmi_fw_pdev_rx_stats_fill(pdev, buf, &len);
4433 	}
4434 
4435 	if (stats_id == WMI_REQUEST_VDEV_STAT) {
4436 		len += scnprintf(buf + len, buf_len - len, "\n");
4437 		len += scnprintf(buf + len, buf_len - len, "%30s\n",
4438 				 "ath11k VDEV stats");
4439 		len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
4440 				 "=================");
4441 
4442 		list_for_each_entry(vdev, &fw_stats->vdevs, list)
4443 			ath11k_wmi_fw_vdev_stats_fill(ar, vdev, buf, &len);
4444 	}
4445 
4446 	if (stats_id == WMI_REQUEST_BCN_STAT) {
4447 		num_bcn = ath11k_wmi_fw_stats_num_bcn(&fw_stats->bcn);
4448 
4449 		len += scnprintf(buf + len, buf_len - len, "\n");
4450 		len += scnprintf(buf + len, buf_len - len, "%30s (%zu)\n",
4451 				 "ath11k Beacon stats", num_bcn);
4452 		len += scnprintf(buf + len, buf_len - len, "%30s\n\n",
4453 				 "===================");
4454 
4455 		list_for_each_entry(bcn, &fw_stats->bcn, list)
4456 			ath11k_wmi_fw_bcn_stats_fill(ar, bcn, buf, &len);
4457 	}
4458 
4459 unlock:
4460 	spin_unlock_bh(&ar->data_lock);
4461 
4462 	if (len >= buf_len)
4463 		buf[len - 1] = 0;
4464 	else
4465 		buf[len] = 0;
4466 }
4467 
4468 static void ath11k_wmi_op_ep_tx_credits(struct ath11k_base *ab)
4469 {
4470 	/* try to send pending beacons first. they take priority */
4471 	wake_up(&ab->wmi_sc.tx_credits_wq);
4472 }
4473 
4474 static void ath11k_wmi_htc_tx_complete(struct ath11k_base *ab,
4475 				       struct sk_buff *skb)
4476 {
4477 	dev_kfree_skb(skb);
4478 }
4479 
4480 static bool ath11k_reg_is_world_alpha(char *alpha)
4481 {
4482 	return alpha[0] == '0' && alpha[1] == '0';
4483 }
4484 
4485 static int ath11k_reg_chan_list_event(struct ath11k_base *ab, struct sk_buff *skb)
4486 {
4487 	struct cur_regulatory_info *reg_info = NULL;
4488 	struct ieee80211_regdomain *regd = NULL;
4489 	bool intersect = false;
4490 	int ret = 0, pdev_idx;
4491 	struct ath11k *ar;
4492 
4493 	reg_info = kzalloc(sizeof(*reg_info), GFP_ATOMIC);
4494 	if (!reg_info) {
4495 		ret = -ENOMEM;
4496 		goto fallback;
4497 	}
4498 
4499 	ret = ath11k_pull_reg_chan_list_update_ev(ab, skb, reg_info);
4500 	if (ret) {
4501 		ath11k_warn(ab, "failed to extract regulatory info from received event\n");
4502 		goto fallback;
4503 	}
4504 
4505 	if (reg_info->status_code != REG_SET_CC_STATUS_PASS) {
4506 		/* In case of failure to set the requested ctry,
4507 		 * fw retains the current regd. We print a failure info
4508 		 * and return from here.
4509 		 */
4510 		ath11k_warn(ab, "Failed to set the requested Country regulatory setting\n");
4511 		goto mem_free;
4512 	}
4513 
4514 	pdev_idx = reg_info->phy_id;
4515 
4516 	if (pdev_idx >= ab->num_radios)
4517 		goto fallback;
4518 
4519 	/* Avoid multiple overwrites to default regd, during core
4520 	 * stop-start after mac registration.
4521 	 */
4522 	if (ab->default_regd[pdev_idx] && !ab->new_regd[pdev_idx] &&
4523 	    !memcmp((char *)ab->default_regd[pdev_idx]->alpha2,
4524 		    (char *)reg_info->alpha2, 2))
4525 		return 0;
4526 
4527 	/* Intersect new rules with default regd if a new country setting was
4528 	 * requested, i.e a default regd was already set during initialization
4529 	 * and the regd coming from this event has a valid country info.
4530 	 */
4531 	if (ab->default_regd[pdev_idx] &&
4532 	    !ath11k_reg_is_world_alpha((char *)
4533 		ab->default_regd[pdev_idx]->alpha2) &&
4534 	    !ath11k_reg_is_world_alpha((char *)reg_info->alpha2))
4535 		intersect = true;
4536 
4537 	regd = ath11k_reg_build_regd(ab, reg_info, intersect);
4538 	if (!regd) {
4539 		ath11k_warn(ab, "failed to build regd from reg_info\n");
4540 		goto fallback;
4541 	}
4542 
4543 	spin_lock(&ab->base_lock);
4544 	if (test_bit(ATH11K_FLAG_REGISTERED, &ab->dev_flags)) {
4545 		/* Once mac is registered, ar is valid and all CC events from
4546 		 * fw is considered to be received due to user requests
4547 		 * currently.
4548 		 * Free previously built regd before assigning the newly
4549 		 * generated regd to ar. NULL pointer handling will be
4550 		 * taken care by kfree itself.
4551 		 */
4552 		ar = ab->pdevs[pdev_idx].ar;
4553 		kfree(ab->new_regd[pdev_idx]);
4554 		ab->new_regd[pdev_idx] = regd;
4555 		ieee80211_queue_work(ar->hw, &ar->regd_update_work);
4556 	} else {
4557 		/* Multiple events for the same *ar is not expected. But we
4558 		 * can still clear any previously stored default_regd if we
4559 		 * are receiving this event for the same radio by mistake.
4560 		 * NULL pointer handling will be taken care by kfree itself.
4561 		 */
4562 		kfree(ab->default_regd[pdev_idx]);
4563 		/* This regd would be applied during mac registration */
4564 		ab->default_regd[pdev_idx] = regd;
4565 	}
4566 	ab->dfs_region = reg_info->dfs_region;
4567 	spin_unlock(&ab->base_lock);
4568 
4569 	goto mem_free;
4570 
4571 fallback:
4572 	/* Fallback to older reg (by sending previous country setting
4573 	 * again if fw has succeded and we failed to process here.
4574 	 * The Regdomain should be uniform across driver and fw. Since the
4575 	 * FW has processed the command and sent a success status, we expect
4576 	 * this function to succeed as well. If it doesn't, CTRY needs to be
4577 	 * reverted at the fw and the old SCAN_CHAN_LIST cmd needs to be sent.
4578 	 */
4579 	/* TODO: This is rare, but still should also be handled */
4580 	WARN_ON(1);
4581 mem_free:
4582 	if (reg_info) {
4583 		kfree(reg_info->reg_rules_2g_ptr);
4584 		kfree(reg_info->reg_rules_5g_ptr);
4585 		kfree(reg_info);
4586 	}
4587 	return ret;
4588 }
4589 
4590 static int ath11k_wmi_tlv_rdy_parse(struct ath11k_base *ab, u16 tag, u16 len,
4591 				    const void *ptr, void *data)
4592 {
4593 	struct wmi_tlv_rdy_parse *rdy_parse = data;
4594 	struct wmi_ready_event *fixed_param;
4595 	struct wmi_mac_addr *addr_list;
4596 	struct ath11k_pdev *pdev;
4597 	u32 num_mac_addr;
4598 	int i;
4599 
4600 	switch (tag) {
4601 	case WMI_TAG_READY_EVENT:
4602 		fixed_param = (struct wmi_ready_event *)ptr;
4603 		ab->wlan_init_status = fixed_param->status;
4604 		rdy_parse->num_extra_mac_addr = fixed_param->num_extra_mac_addr;
4605 
4606 		ether_addr_copy(ab->mac_addr, fixed_param->mac_addr.addr);
4607 		ab->wmi_ready = true;
4608 		break;
4609 	case WMI_TAG_ARRAY_FIXED_STRUCT:
4610 		addr_list = (struct wmi_mac_addr *)ptr;
4611 		num_mac_addr = rdy_parse->num_extra_mac_addr;
4612 
4613 		if (!(ab->num_radios > 1 && num_mac_addr >= ab->num_radios))
4614 			break;
4615 
4616 		for (i = 0; i < ab->num_radios; i++) {
4617 			pdev = &ab->pdevs[i];
4618 			ether_addr_copy(pdev->mac_addr, addr_list[i].addr);
4619 		}
4620 		ab->pdevs_macaddr_valid = true;
4621 		break;
4622 	default:
4623 		break;
4624 	}
4625 
4626 	return 0;
4627 }
4628 
4629 static int ath11k_ready_event(struct ath11k_base *ab, struct sk_buff *skb)
4630 {
4631 	struct wmi_tlv_rdy_parse rdy_parse = { };
4632 	int ret;
4633 
4634 	ret = ath11k_wmi_tlv_iter(ab, skb->data, skb->len,
4635 				  ath11k_wmi_tlv_rdy_parse, &rdy_parse);
4636 	if (ret) {
4637 		ath11k_warn(ab, "failed to parse tlv %d\n", ret);
4638 		return ret;
4639 	}
4640 
4641 	complete(&ab->wmi_sc.unified_ready);
4642 	return 0;
4643 }
4644 
4645 static void ath11k_peer_delete_resp_event(struct ath11k_base *ab, struct sk_buff *skb)
4646 {
4647 	struct wmi_peer_delete_resp_event peer_del_resp;
4648 
4649 	if (ath11k_pull_peer_del_resp_ev(ab, skb, &peer_del_resp) != 0) {
4650 		ath11k_warn(ab, "failed to extract peer delete resp");
4651 		return;
4652 	}
4653 
4654 	/* TODO: Do we need to validate whether ath11k_peer_find() return NULL
4655 	 *	 Why this is needed when there is HTT event for peer delete
4656 	 */
4657 }
4658 
4659 static inline const char *ath11k_wmi_vdev_resp_print(u32 vdev_resp_status)
4660 {
4661 	switch (vdev_resp_status) {
4662 	case WMI_VDEV_START_RESPONSE_INVALID_VDEVID:
4663 		return "invalid vdev id";
4664 	case WMI_VDEV_START_RESPONSE_NOT_SUPPORTED:
4665 		return "not supported";
4666 	case WMI_VDEV_START_RESPONSE_DFS_VIOLATION:
4667 		return "dfs violation";
4668 	case WMI_VDEV_START_RESPONSE_INVALID_REGDOMAIN:
4669 		return "invalid regdomain";
4670 	default:
4671 		return "unknown";
4672 	}
4673 }
4674 
4675 static void ath11k_vdev_start_resp_event(struct ath11k_base *ab, struct sk_buff *skb)
4676 {
4677 	struct wmi_vdev_start_resp_event vdev_start_resp;
4678 	struct ath11k *ar;
4679 	u32 status;
4680 
4681 	if (ath11k_pull_vdev_start_resp_tlv(ab, skb, &vdev_start_resp) != 0) {
4682 		ath11k_warn(ab, "failed to extract vdev start resp");
4683 		return;
4684 	}
4685 
4686 	rcu_read_lock();
4687 	ar = ath11k_mac_get_ar_by_vdev_id(ab, vdev_start_resp.vdev_id);
4688 	if (!ar) {
4689 		ath11k_warn(ab, "invalid vdev id in vdev start resp ev %d",
4690 			    vdev_start_resp.vdev_id);
4691 		rcu_read_unlock();
4692 		return;
4693 	}
4694 
4695 	ar->last_wmi_vdev_start_status = 0;
4696 
4697 	status = vdev_start_resp.status;
4698 
4699 	if (WARN_ON_ONCE(status)) {
4700 		ath11k_warn(ab, "vdev start resp error status %d (%s)\n",
4701 			    status, ath11k_wmi_vdev_resp_print(status));
4702 		ar->last_wmi_vdev_start_status = status;
4703 	}
4704 
4705 	complete(&ar->vdev_setup_done);
4706 
4707 	rcu_read_unlock();
4708 
4709 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev start resp for vdev id %d",
4710 		   vdev_start_resp.vdev_id);
4711 }
4712 
4713 static void ath11k_bcn_tx_status_event(struct ath11k_base *ab, struct sk_buff *skb)
4714 {
4715 	u32 vdev_id, tx_status;
4716 
4717 	if (ath11k_pull_bcn_tx_status_ev(ab, skb->data, skb->len,
4718 					 &vdev_id, &tx_status) != 0) {
4719 		ath11k_warn(ab, "failed to extract bcn tx status");
4720 		return;
4721 	}
4722 }
4723 
4724 static void ath11k_vdev_stopped_event(struct ath11k_base *ab, struct sk_buff *skb)
4725 {
4726 	struct ath11k *ar;
4727 	u32 vdev_id = 0;
4728 
4729 	if (ath11k_pull_vdev_stopped_param_tlv(ab, skb, &vdev_id) != 0) {
4730 		ath11k_warn(ab, "failed to extract vdev stopped event");
4731 		return;
4732 	}
4733 
4734 	rcu_read_lock();
4735 	ar = ath11k_mac_get_ar_vdev_stop_status(ab, vdev_id);
4736 	if (!ar) {
4737 		ath11k_warn(ab, "invalid vdev id in vdev stopped ev %d",
4738 			    vdev_id);
4739 		rcu_read_unlock();
4740 		return;
4741 	}
4742 
4743 	complete(&ar->vdev_setup_done);
4744 
4745 	rcu_read_unlock();
4746 
4747 	ath11k_dbg(ab, ATH11K_DBG_WMI, "vdev stopped for vdev id %d", vdev_id);
4748 }
4749 
4750 static void ath11k_mgmt_rx_event(struct ath11k_base *ab, struct sk_buff *skb)
4751 {
4752 	struct mgmt_rx_event_params rx_ev = {0};
4753 	struct ath11k *ar;
4754 	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
4755 	struct ieee80211_hdr *hdr;
4756 	u16 fc;
4757 	struct ieee80211_supported_band *sband;
4758 
4759 	if (ath11k_pull_mgmt_rx_params_tlv(ab, skb, &rx_ev) != 0) {
4760 		ath11k_warn(ab, "failed to extract mgmt rx event");
4761 		dev_kfree_skb(skb);
4762 		return;
4763 	}
4764 
4765 	memset(status, 0, sizeof(*status));
4766 
4767 	ath11k_dbg(ab, ATH11K_DBG_MGMT, "mgmt rx event status %08x\n",
4768 		   rx_ev.status);
4769 
4770 	rcu_read_lock();
4771 	ar = ath11k_mac_get_ar_by_pdev_id(ab, rx_ev.pdev_id);
4772 
4773 	if (!ar) {
4774 		ath11k_warn(ab, "invalid pdev_id %d in mgmt_rx_event\n",
4775 			    rx_ev.pdev_id);
4776 		dev_kfree_skb(skb);
4777 		goto exit;
4778 	}
4779 
4780 	if ((test_bit(ATH11K_CAC_RUNNING, &ar->dev_flags)) ||
4781 	    (rx_ev.status & (WMI_RX_STATUS_ERR_DECRYPT |
4782 	    WMI_RX_STATUS_ERR_KEY_CACHE_MISS | WMI_RX_STATUS_ERR_CRC))) {
4783 		dev_kfree_skb(skb);
4784 		goto exit;
4785 	}
4786 
4787 	if (rx_ev.status & WMI_RX_STATUS_ERR_MIC)
4788 		status->flag |= RX_FLAG_MMIC_ERROR;
4789 
4790 	if (rx_ev.channel >= 1 && rx_ev.channel <= 14) {
4791 		status->band = NL80211_BAND_2GHZ;
4792 	} else if (rx_ev.channel >= 36 && rx_ev.channel <= ATH11K_MAX_5G_CHAN) {
4793 		status->band = NL80211_BAND_5GHZ;
4794 	} else {
4795 		/* Shouldn't happen unless list of advertised channels to
4796 		 * mac80211 has been changed.
4797 		 */
4798 		WARN_ON_ONCE(1);
4799 		dev_kfree_skb(skb);
4800 		goto exit;
4801 	}
4802 
4803 	if (rx_ev.phy_mode == MODE_11B && status->band == NL80211_BAND_5GHZ)
4804 		ath11k_dbg(ab, ATH11K_DBG_WMI,
4805 			   "wmi mgmt rx 11b (CCK) on 5GHz\n");
4806 
4807 	sband = &ar->mac.sbands[status->band];
4808 
4809 	status->freq = ieee80211_channel_to_frequency(rx_ev.channel,
4810 						      status->band);
4811 	status->signal = rx_ev.snr + ATH11K_DEFAULT_NOISE_FLOOR;
4812 	status->rate_idx = ath11k_mac_bitrate_to_idx(sband, rx_ev.rate / 100);
4813 
4814 	hdr = (struct ieee80211_hdr *)skb->data;
4815 	fc = le16_to_cpu(hdr->frame_control);
4816 
4817 	/* Firmware is guaranteed to report all essential management frames via
4818 	 * WMI while it can deliver some extra via HTT. Since there can be
4819 	 * duplicates split the reporting wrt monitor/sniffing.
4820 	 */
4821 	status->flag |= RX_FLAG_SKIP_MONITOR;
4822 
4823 	/* In case of PMF, FW delivers decrypted frames with Protected Bit set.
4824 	 * Don't clear that. Also, FW delivers broadcast management frames
4825 	 * (ex: group privacy action frames in mesh) as encrypted payload.
4826 	 */
4827 	if (ieee80211_has_protected(hdr->frame_control) &&
4828 	    !is_multicast_ether_addr(ieee80211_get_DA(hdr))) {
4829 		status->flag |= RX_FLAG_DECRYPTED;
4830 
4831 		if (!ieee80211_is_robust_mgmt_frame(skb)) {
4832 			status->flag |= RX_FLAG_IV_STRIPPED |
4833 					RX_FLAG_MMIC_STRIPPED;
4834 			hdr->frame_control = __cpu_to_le16(fc &
4835 					     ~IEEE80211_FCTL_PROTECTED);
4836 		}
4837 	}
4838 
4839 	/* TODO: Pending handle beacon implementation
4840 	 *if (ieee80211_is_beacon(hdr->frame_control))
4841 	 *	ath11k_mac_handle_beacon(ar, skb);
4842 	 */
4843 
4844 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
4845 		   "event mgmt rx skb %pK len %d ftype %02x stype %02x\n",
4846 		   skb, skb->len,
4847 		   fc & IEEE80211_FCTL_FTYPE, fc & IEEE80211_FCTL_STYPE);
4848 
4849 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
4850 		   "event mgmt rx freq %d band %d snr %d, rate_idx %d\n",
4851 		   status->freq, status->band, status->signal,
4852 		   status->rate_idx);
4853 
4854 	ieee80211_rx_ni(ar->hw, skb);
4855 
4856 exit:
4857 	rcu_read_unlock();
4858 }
4859 
4860 static void ath11k_mgmt_tx_compl_event(struct ath11k_base *ab, struct sk_buff *skb)
4861 {
4862 	struct wmi_mgmt_tx_compl_event tx_compl_param = {0};
4863 	struct ath11k *ar;
4864 
4865 	if (ath11k_pull_mgmt_tx_compl_param_tlv(ab, skb, &tx_compl_param) != 0) {
4866 		ath11k_warn(ab, "failed to extract mgmt tx compl event");
4867 		return;
4868 	}
4869 
4870 	rcu_read_lock();
4871 	ar = ath11k_mac_get_ar_by_pdev_id(ab, tx_compl_param.pdev_id);
4872 	if (!ar) {
4873 		ath11k_warn(ab, "invalid pdev id %d in mgmt_tx_compl_event\n",
4874 			    tx_compl_param.pdev_id);
4875 		goto exit;
4876 	}
4877 
4878 	wmi_process_mgmt_tx_comp(ar, tx_compl_param.desc_id,
4879 				 tx_compl_param.status);
4880 
4881 	ath11k_dbg(ab, ATH11K_DBG_MGMT,
4882 		   "mgmt tx compl ev pdev_id %d, desc_id %d, status %d",
4883 		   tx_compl_param.pdev_id, tx_compl_param.desc_id,
4884 		   tx_compl_param.status);
4885 
4886 exit:
4887 	rcu_read_unlock();
4888 }
4889 
4890 static struct ath11k *ath11k_get_ar_on_scan_abort(struct ath11k_base *ab,
4891 						  u32 vdev_id)
4892 {
4893 	int i;
4894 	struct ath11k_pdev *pdev;
4895 	struct ath11k *ar;
4896 
4897 	for (i = 0; i < ab->num_radios; i++) {
4898 		pdev = rcu_dereference(ab->pdevs_active[i]);
4899 		if (pdev && pdev->ar) {
4900 			ar = pdev->ar;
4901 
4902 			spin_lock_bh(&ar->data_lock);
4903 			if (ar->scan.state == ATH11K_SCAN_ABORTING &&
4904 			    ar->scan.vdev_id == vdev_id) {
4905 				spin_unlock_bh(&ar->data_lock);
4906 				return ar;
4907 			}
4908 			spin_unlock_bh(&ar->data_lock);
4909 		}
4910 	}
4911 	return NULL;
4912 }
4913 
4914 static void ath11k_scan_event(struct ath11k_base *ab, struct sk_buff *skb)
4915 {
4916 	struct ath11k *ar;
4917 	struct wmi_scan_event scan_ev = {0};
4918 
4919 	if (ath11k_pull_scan_ev(ab, skb, &scan_ev) != 0) {
4920 		ath11k_warn(ab, "failed to extract scan event");
4921 		return;
4922 	}
4923 
4924 	rcu_read_lock();
4925 
4926 	/* In case the scan was cancelled, ex. during interface teardown,
4927 	 * the interface will not be found in active interfaces.
4928 	 * Rather, in such scenarios, iterate over the active pdev's to
4929 	 * search 'ar' if the corresponding 'ar' scan is ABORTING and the
4930 	 * aborting scan's vdev id matches this event info.
4931 	 */
4932 	if (scan_ev.event_type == WMI_SCAN_EVENT_COMPLETED &&
4933 	    scan_ev.reason == WMI_SCAN_REASON_CANCELLED)
4934 		ar = ath11k_get_ar_on_scan_abort(ab, scan_ev.vdev_id);
4935 	else
4936 		ar = ath11k_mac_get_ar_by_vdev_id(ab, scan_ev.vdev_id);
4937 
4938 	if (!ar) {
4939 		ath11k_warn(ab, "Received scan event for unknown vdev");
4940 		rcu_read_unlock();
4941 		return;
4942 	}
4943 
4944 	spin_lock_bh(&ar->data_lock);
4945 
4946 	ath11k_dbg(ab, ATH11K_DBG_WMI,
4947 		   "scan event %s type %d reason %d freq %d req_id %d scan_id %d vdev_id %d state %s (%d)\n",
4948 		   ath11k_wmi_event_scan_type_str(scan_ev.event_type, scan_ev.reason),
4949 		   scan_ev.event_type, scan_ev.reason, scan_ev.channel_freq,
4950 		   scan_ev.scan_req_id, scan_ev.scan_id, scan_ev.vdev_id,
4951 		   ath11k_scan_state_str(ar->scan.state), ar->scan.state);
4952 
4953 	switch (scan_ev.event_type) {
4954 	case WMI_SCAN_EVENT_STARTED:
4955 		ath11k_wmi_event_scan_started(ar);
4956 		break;
4957 	case WMI_SCAN_EVENT_COMPLETED:
4958 		ath11k_wmi_event_scan_completed(ar);
4959 		break;
4960 	case WMI_SCAN_EVENT_BSS_CHANNEL:
4961 		ath11k_wmi_event_scan_bss_chan(ar);
4962 		break;
4963 	case WMI_SCAN_EVENT_FOREIGN_CHAN:
4964 		ath11k_wmi_event_scan_foreign_chan(ar, scan_ev.channel_freq);
4965 		break;
4966 	case WMI_SCAN_EVENT_START_FAILED:
4967 		ath11k_warn(ab, "received scan start failure event\n");
4968 		ath11k_wmi_event_scan_start_failed(ar);
4969 		break;
4970 	case WMI_SCAN_EVENT_DEQUEUED:
4971 	case WMI_SCAN_EVENT_PREEMPTED:
4972 	case WMI_SCAN_EVENT_RESTARTED:
4973 	case WMI_SCAN_EVENT_FOREIGN_CHAN_EXIT:
4974 	default:
4975 		break;
4976 	}
4977 
4978 	spin_unlock_bh(&ar->data_lock);
4979 
4980 	rcu_read_unlock();
4981 }
4982 
4983 static void ath11k_peer_sta_kickout_event(struct ath11k_base *ab, struct sk_buff *skb)
4984 {
4985 	struct wmi_peer_sta_kickout_arg arg = {};
4986 	struct ieee80211_sta *sta;
4987 	struct ath11k_peer *peer;
4988 	struct ath11k *ar;
4989 
4990 	if (ath11k_pull_peer_sta_kickout_ev(ab, skb, &arg) != 0) {
4991 		ath11k_warn(ab, "failed to extract peer sta kickout event");
4992 		return;
4993 	}
4994 
4995 	rcu_read_lock();
4996 
4997 	spin_lock_bh(&ab->base_lock);
4998 
4999 	peer = ath11k_peer_find_by_addr(ab, arg.mac_addr);
5000 
5001 	if (!peer) {
5002 		ath11k_warn(ab, "peer not found %pM\n",
5003 			    arg.mac_addr);
5004 		goto exit;
5005 	}
5006 
5007 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer->vdev_id);
5008 	if (!ar) {
5009 		ath11k_warn(ab, "invalid vdev id in peer sta kickout ev %d",
5010 			    peer->vdev_id);
5011 		goto exit;
5012 	}
5013 
5014 	sta = ieee80211_find_sta_by_ifaddr(ar->hw,
5015 					   arg.mac_addr, NULL);
5016 	if (!sta) {
5017 		ath11k_warn(ab, "Spurious quick kickout for STA %pM\n",
5018 			    arg.mac_addr);
5019 		goto exit;
5020 	}
5021 
5022 	ath11k_dbg(ab, ATH11K_DBG_WMI, "peer sta kickout event %pM",
5023 		   arg.mac_addr);
5024 
5025 	ieee80211_report_low_ack(sta, 10);
5026 
5027 exit:
5028 	spin_unlock_bh(&ab->base_lock);
5029 	rcu_read_unlock();
5030 }
5031 
5032 static void ath11k_roam_event(struct ath11k_base *ab, struct sk_buff *skb)
5033 {
5034 	struct wmi_roam_event roam_ev = {};
5035 	struct ath11k *ar;
5036 
5037 	if (ath11k_pull_roam_ev(ab, skb, &roam_ev) != 0) {
5038 		ath11k_warn(ab, "failed to extract roam event");
5039 		return;
5040 	}
5041 
5042 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5043 		   "wmi roam event vdev %u reason 0x%08x rssi %d\n",
5044 		   roam_ev.vdev_id, roam_ev.reason, roam_ev.rssi);
5045 
5046 	rcu_read_lock();
5047 	ar = ath11k_mac_get_ar_by_vdev_id(ab, roam_ev.vdev_id);
5048 	if (!ar) {
5049 		ath11k_warn(ab, "invalid vdev id in roam ev %d",
5050 			    roam_ev.vdev_id);
5051 		rcu_read_unlock();
5052 		return;
5053 	}
5054 
5055 	if (roam_ev.reason >= WMI_ROAM_REASON_MAX)
5056 		ath11k_warn(ab, "ignoring unknown roam event reason %d on vdev %i\n",
5057 			    roam_ev.reason, roam_ev.vdev_id);
5058 
5059 	switch (roam_ev.reason) {
5060 	case WMI_ROAM_REASON_BEACON_MISS:
5061 		/* TODO: Pending beacon miss and connection_loss_work
5062 		 * implementation
5063 		 * ath11k_mac_handle_beacon_miss(ar, vdev_id);
5064 		 */
5065 		break;
5066 	case WMI_ROAM_REASON_BETTER_AP:
5067 	case WMI_ROAM_REASON_LOW_RSSI:
5068 	case WMI_ROAM_REASON_SUITABLE_AP_FOUND:
5069 	case WMI_ROAM_REASON_HO_FAILED:
5070 		ath11k_warn(ab, "ignoring not implemented roam event reason %d on vdev %i\n",
5071 			    roam_ev.reason, roam_ev.vdev_id);
5072 		break;
5073 	}
5074 
5075 	rcu_read_unlock();
5076 }
5077 
5078 static void ath11k_chan_info_event(struct ath11k_base *ab, struct sk_buff *skb)
5079 {
5080 	struct wmi_chan_info_event ch_info_ev = {0};
5081 	struct ath11k *ar;
5082 	struct survey_info *survey;
5083 	int idx;
5084 	/* HW channel counters frequency value in hertz */
5085 	u32 cc_freq_hz = ab->cc_freq_hz;
5086 
5087 	if (ath11k_pull_chan_info_ev(ab, skb->data, skb->len, &ch_info_ev) != 0) {
5088 		ath11k_warn(ab, "failed to extract chan info event");
5089 		return;
5090 	}
5091 
5092 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5093 		   "chan info vdev_id %d err_code %d freq %d cmd_flags %d noise_floor %d rx_clear_count %d cycle_count %d mac_clk_mhz %d\n",
5094 		   ch_info_ev.vdev_id, ch_info_ev.err_code, ch_info_ev.freq,
5095 		   ch_info_ev.cmd_flags, ch_info_ev.noise_floor,
5096 		   ch_info_ev.rx_clear_count, ch_info_ev.cycle_count,
5097 		   ch_info_ev.mac_clk_mhz);
5098 
5099 	if (ch_info_ev.cmd_flags == WMI_CHAN_INFO_END_RESP) {
5100 		ath11k_dbg(ab, ATH11K_DBG_WMI, "chan info report completed\n");
5101 		return;
5102 	}
5103 
5104 	rcu_read_lock();
5105 	ar = ath11k_mac_get_ar_by_vdev_id(ab, ch_info_ev.vdev_id);
5106 	if (!ar) {
5107 		ath11k_warn(ab, "invalid vdev id in chan info ev %d",
5108 			    ch_info_ev.vdev_id);
5109 		rcu_read_unlock();
5110 		return;
5111 	}
5112 	spin_lock_bh(&ar->data_lock);
5113 
5114 	switch (ar->scan.state) {
5115 	case ATH11K_SCAN_IDLE:
5116 	case ATH11K_SCAN_STARTING:
5117 		ath11k_warn(ab, "received chan info event without a scan request, ignoring\n");
5118 		goto exit;
5119 	case ATH11K_SCAN_RUNNING:
5120 	case ATH11K_SCAN_ABORTING:
5121 		break;
5122 	}
5123 
5124 	idx = freq_to_idx(ar, ch_info_ev.freq);
5125 	if (idx >= ARRAY_SIZE(ar->survey)) {
5126 		ath11k_warn(ab, "chan info: invalid frequency %d (idx %d out of bounds)\n",
5127 			    ch_info_ev.freq, idx);
5128 		goto exit;
5129 	}
5130 
5131 	/* If FW provides MAC clock frequency in Mhz, overriding the initialized
5132 	 * HW channel counters frequency value
5133 	 */
5134 	if (ch_info_ev.mac_clk_mhz)
5135 		cc_freq_hz = (ch_info_ev.mac_clk_mhz * 1000);
5136 
5137 	if (ch_info_ev.cmd_flags == WMI_CHAN_INFO_START_RESP) {
5138 		survey = &ar->survey[idx];
5139 		memset(survey, 0, sizeof(*survey));
5140 		survey->noise = ch_info_ev.noise_floor;
5141 		survey->filled = SURVEY_INFO_NOISE_DBM | SURVEY_INFO_TIME |
5142 				 SURVEY_INFO_TIME_BUSY;
5143 		survey->time = div_u64(ch_info_ev.cycle_count, cc_freq_hz);
5144 		survey->time_busy = div_u64(ch_info_ev.rx_clear_count, cc_freq_hz);
5145 	}
5146 exit:
5147 	spin_unlock_bh(&ar->data_lock);
5148 	rcu_read_unlock();
5149 }
5150 
5151 static void
5152 ath11k_pdev_bss_chan_info_event(struct ath11k_base *ab, struct sk_buff *skb)
5153 {
5154 	struct wmi_pdev_bss_chan_info_event bss_ch_info_ev = {};
5155 	struct survey_info *survey;
5156 	struct ath11k *ar;
5157 	u32 cc_freq_hz = ab->cc_freq_hz;
5158 	u64 busy, total, tx, rx, rx_bss;
5159 	int idx;
5160 
5161 	if (ath11k_pull_pdev_bss_chan_info_ev(ab, skb, &bss_ch_info_ev) != 0) {
5162 		ath11k_warn(ab, "failed to extract pdev bss chan info event");
5163 		return;
5164 	}
5165 
5166 	busy = (u64)(bss_ch_info_ev.rx_clear_count_high) << 32 |
5167 			bss_ch_info_ev.rx_clear_count_low;
5168 
5169 	total = (u64)(bss_ch_info_ev.cycle_count_high) << 32 |
5170 			bss_ch_info_ev.cycle_count_low;
5171 
5172 	tx = (u64)(bss_ch_info_ev.tx_cycle_count_high) << 32 |
5173 			bss_ch_info_ev.tx_cycle_count_low;
5174 
5175 	rx = (u64)(bss_ch_info_ev.rx_cycle_count_high) << 32 |
5176 			bss_ch_info_ev.rx_cycle_count_low;
5177 
5178 	rx_bss = (u64)(bss_ch_info_ev.rx_bss_cycle_count_high) << 32 |
5179 			bss_ch_info_ev.rx_bss_cycle_count_low;
5180 
5181 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5182 		   "pdev bss chan info:\n pdev_id: %d freq: %d noise: %d cycle: busy %llu total %llu tx %llu rx %llu rx_bss %llu\n",
5183 		   bss_ch_info_ev.pdev_id, bss_ch_info_ev.freq,
5184 		   bss_ch_info_ev.noise_floor, busy, total,
5185 		   tx, rx, rx_bss);
5186 
5187 	rcu_read_lock();
5188 	ar = ath11k_mac_get_ar_by_pdev_id(ab, bss_ch_info_ev.pdev_id);
5189 
5190 	if (!ar) {
5191 		ath11k_warn(ab, "invalid pdev id %d in bss_chan_info event\n",
5192 			    bss_ch_info_ev.pdev_id);
5193 		rcu_read_unlock();
5194 		return;
5195 	}
5196 
5197 	spin_lock_bh(&ar->data_lock);
5198 	idx = freq_to_idx(ar, bss_ch_info_ev.freq);
5199 	if (idx >= ARRAY_SIZE(ar->survey)) {
5200 		ath11k_warn(ab, "bss chan info: invalid frequency %d (idx %d out of bounds)\n",
5201 			    bss_ch_info_ev.freq, idx);
5202 		goto exit;
5203 	}
5204 
5205 	survey = &ar->survey[idx];
5206 
5207 	survey->noise     = bss_ch_info_ev.noise_floor;
5208 	survey->time      = div_u64(total, cc_freq_hz);
5209 	survey->time_busy = div_u64(busy, cc_freq_hz);
5210 	survey->time_rx   = div_u64(rx_bss, cc_freq_hz);
5211 	survey->time_tx   = div_u64(tx, cc_freq_hz);
5212 	survey->filled   |= (SURVEY_INFO_NOISE_DBM |
5213 			     SURVEY_INFO_TIME |
5214 			     SURVEY_INFO_TIME_BUSY |
5215 			     SURVEY_INFO_TIME_RX |
5216 			     SURVEY_INFO_TIME_TX);
5217 exit:
5218 	spin_unlock_bh(&ar->data_lock);
5219 	complete(&ar->bss_survey_done);
5220 
5221 	rcu_read_unlock();
5222 }
5223 
5224 static void ath11k_vdev_install_key_compl_event(struct ath11k_base *ab,
5225 						struct sk_buff *skb)
5226 {
5227 	struct wmi_vdev_install_key_complete_arg install_key_compl = {0};
5228 	struct ath11k *ar;
5229 
5230 	if (ath11k_pull_vdev_install_key_compl_ev(ab, skb, &install_key_compl) != 0) {
5231 		ath11k_warn(ab, "failed to extract install key compl event");
5232 		return;
5233 	}
5234 
5235 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5236 		   "vdev install key ev idx %d flags %08x macaddr %pM status %d\n",
5237 		   install_key_compl.key_idx, install_key_compl.key_flags,
5238 		   install_key_compl.macaddr, install_key_compl.status);
5239 
5240 	rcu_read_lock();
5241 	ar = ath11k_mac_get_ar_by_vdev_id(ab, install_key_compl.vdev_id);
5242 	if (!ar) {
5243 		ath11k_warn(ab, "invalid vdev id in install key compl ev %d",
5244 			    install_key_compl.vdev_id);
5245 		rcu_read_unlock();
5246 		return;
5247 	}
5248 
5249 	ar->install_key_status = 0;
5250 
5251 	if (install_key_compl.status != WMI_VDEV_INSTALL_KEY_COMPL_STATUS_SUCCESS) {
5252 		ath11k_warn(ab, "install key failed for %pM status %d\n",
5253 			    install_key_compl.macaddr, install_key_compl.status);
5254 		ar->install_key_status = install_key_compl.status;
5255 	}
5256 
5257 	complete(&ar->install_key_done);
5258 	rcu_read_unlock();
5259 }
5260 
5261 static void ath11k_service_available_event(struct ath11k_base *ab, struct sk_buff *skb)
5262 {
5263 	const void **tb;
5264 	const struct wmi_service_available_event *ev;
5265 	int ret;
5266 	int i, j;
5267 
5268 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5269 	if (IS_ERR(tb)) {
5270 		ret = PTR_ERR(tb);
5271 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5272 		return;
5273 	}
5274 
5275 	ev = tb[WMI_TAG_SERVICE_AVAILABLE_EVENT];
5276 	if (!ev) {
5277 		ath11k_warn(ab, "failed to fetch svc available ev");
5278 		kfree(tb);
5279 		return;
5280 	}
5281 
5282 	/* TODO: Use wmi_service_segment_offset information to get the service
5283 	 * especially when more services are advertised in multiple sevice
5284 	 * available events.
5285 	 */
5286 	for (i = 0, j = WMI_MAX_SERVICE;
5287 	     i < WMI_SERVICE_SEGMENT_BM_SIZE32 && j < WMI_MAX_EXT_SERVICE;
5288 	     i++) {
5289 		do {
5290 			if (ev->wmi_service_segment_bitmap[i] &
5291 			    BIT(j % WMI_AVAIL_SERVICE_BITS_IN_SIZE32))
5292 				set_bit(j, ab->wmi_sc.svc_map);
5293 		} while (++j % WMI_AVAIL_SERVICE_BITS_IN_SIZE32);
5294 	}
5295 
5296 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5297 		   "wmi_ext_service_bitmap 0:0x%x, 1:0x%x, 2:0x%x, 3:0x%x",
5298 		   ev->wmi_service_segment_bitmap[0], ev->wmi_service_segment_bitmap[1],
5299 		   ev->wmi_service_segment_bitmap[2], ev->wmi_service_segment_bitmap[3]);
5300 
5301 	kfree(tb);
5302 }
5303 
5304 static void ath11k_peer_assoc_conf_event(struct ath11k_base *ab, struct sk_buff *skb)
5305 {
5306 	struct wmi_peer_assoc_conf_arg peer_assoc_conf = {0};
5307 	struct ath11k *ar;
5308 
5309 	if (ath11k_pull_peer_assoc_conf_ev(ab, skb, &peer_assoc_conf) != 0) {
5310 		ath11k_warn(ab, "failed to extract peer assoc conf event");
5311 		return;
5312 	}
5313 
5314 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5315 		   "peer assoc conf ev vdev id %d macaddr %pM\n",
5316 		   peer_assoc_conf.vdev_id, peer_assoc_conf.macaddr);
5317 
5318 	ar = ath11k_mac_get_ar_by_vdev_id(ab, peer_assoc_conf.vdev_id);
5319 
5320 	if (!ar) {
5321 		ath11k_warn(ab, "invalid vdev id in peer assoc conf ev %d",
5322 			    peer_assoc_conf.vdev_id);
5323 		return;
5324 	}
5325 
5326 	complete(&ar->peer_assoc_done);
5327 }
5328 
5329 static void ath11k_update_stats_event(struct ath11k_base *ab, struct sk_buff *skb)
5330 {
5331 	ath11k_debug_fw_stats_process(ab, skb);
5332 }
5333 
5334 /* PDEV_CTL_FAILSAFE_CHECK_EVENT is received from FW when the frequency scanned
5335  * is not part of BDF CTL(Conformance test limits) table entries.
5336  */
5337 static void ath11k_pdev_ctl_failsafe_check_event(struct ath11k_base *ab,
5338 						 struct sk_buff *skb)
5339 {
5340 	const void **tb;
5341 	const struct wmi_pdev_ctl_failsafe_chk_event *ev;
5342 	int ret;
5343 
5344 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5345 	if (IS_ERR(tb)) {
5346 		ret = PTR_ERR(tb);
5347 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5348 		return;
5349 	}
5350 
5351 	ev = tb[WMI_TAG_PDEV_CTL_FAILSAFE_CHECK_EVENT];
5352 	if (!ev) {
5353 		ath11k_warn(ab, "failed to fetch pdev ctl failsafe check ev");
5354 		kfree(tb);
5355 		return;
5356 	}
5357 
5358 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5359 		   "pdev ctl failsafe check ev status %d\n",
5360 		   ev->ctl_failsafe_status);
5361 
5362 	/* If ctl_failsafe_status is set to 1 FW will max out the Transmit power
5363 	 * to 10 dBm else the CTL power entry in the BDF would be picked up.
5364 	 */
5365 	if (ev->ctl_failsafe_status != 0)
5366 		ath11k_warn(ab, "pdev ctl failsafe failure status %d",
5367 			    ev->ctl_failsafe_status);
5368 
5369 	kfree(tb);
5370 }
5371 
5372 static void
5373 ath11k_wmi_process_csa_switch_count_event(struct ath11k_base *ab,
5374 					  const struct wmi_pdev_csa_switch_ev *ev,
5375 					  const u32 *vdev_ids)
5376 {
5377 	int i;
5378 	struct ath11k_vif *arvif;
5379 
5380 	/* Finish CSA once the switch count becomes NULL */
5381 	if (ev->current_switch_count)
5382 		return;
5383 
5384 	rcu_read_lock();
5385 	for (i = 0; i < ev->num_vdevs; i++) {
5386 		arvif = ath11k_mac_get_arvif_by_vdev_id(ab, vdev_ids[i]);
5387 
5388 		if (!arvif) {
5389 			ath11k_warn(ab, "Recvd csa status for unknown vdev %d",
5390 				    vdev_ids[i]);
5391 			continue;
5392 		}
5393 
5394 		if (arvif->is_up && arvif->vif->csa_active)
5395 			ieee80211_csa_finish(arvif->vif);
5396 	}
5397 	rcu_read_unlock();
5398 }
5399 
5400 static void
5401 ath11k_wmi_pdev_csa_switch_count_status_event(struct ath11k_base *ab,
5402 					      struct sk_buff *skb)
5403 {
5404 	const void **tb;
5405 	const struct wmi_pdev_csa_switch_ev *ev;
5406 	const u32 *vdev_ids;
5407 	int ret;
5408 
5409 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5410 	if (IS_ERR(tb)) {
5411 		ret = PTR_ERR(tb);
5412 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5413 		return;
5414 	}
5415 
5416 	ev = tb[WMI_TAG_PDEV_CSA_SWITCH_COUNT_STATUS_EVENT];
5417 	vdev_ids = tb[WMI_TAG_ARRAY_UINT32];
5418 
5419 	if (!ev || !vdev_ids) {
5420 		ath11k_warn(ab, "failed to fetch pdev csa switch count ev");
5421 		kfree(tb);
5422 		return;
5423 	}
5424 
5425 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5426 		   "pdev csa switch count %d for pdev %d, num_vdevs %d",
5427 		   ev->current_switch_count, ev->pdev_id,
5428 		   ev->num_vdevs);
5429 
5430 	ath11k_wmi_process_csa_switch_count_event(ab, ev, vdev_ids);
5431 
5432 	kfree(tb);
5433 }
5434 
5435 static void
5436 ath11k_wmi_pdev_dfs_radar_detected_event(struct ath11k_base *ab, struct sk_buff *skb)
5437 {
5438 	const void **tb;
5439 	const struct wmi_pdev_radar_ev *ev;
5440 	struct ath11k *ar;
5441 	int ret;
5442 
5443 	tb = ath11k_wmi_tlv_parse_alloc(ab, skb->data, skb->len, GFP_ATOMIC);
5444 	if (IS_ERR(tb)) {
5445 		ret = PTR_ERR(tb);
5446 		ath11k_warn(ab, "failed to parse tlv: %d\n", ret);
5447 		return;
5448 	}
5449 
5450 	ev = tb[WMI_TAG_PDEV_DFS_RADAR_DETECTION_EVENT];
5451 
5452 	if (!ev) {
5453 		ath11k_warn(ab, "failed to fetch pdev dfs radar detected ev");
5454 		kfree(tb);
5455 		return;
5456 	}
5457 
5458 	ath11k_dbg(ab, ATH11K_DBG_WMI,
5459 		   "pdev dfs radar detected on pdev %d, detection mode %d, chan freq %d, chan_width %d, detector id %d, seg id %d, timestamp %d, chirp %d, freq offset %d, sidx %d",
5460 		   ev->pdev_id, ev->detection_mode, ev->chan_freq, ev->chan_width,
5461 		   ev->detector_id, ev->segment_id, ev->timestamp, ev->is_chirp,
5462 		   ev->freq_offset, ev->sidx);
5463 
5464 	ar = ath11k_mac_get_ar_by_pdev_id(ab, ev->pdev_id);
5465 
5466 	if (!ar) {
5467 		ath11k_warn(ab, "radar detected in invalid pdev %d\n",
5468 			    ev->pdev_id);
5469 		goto exit;
5470 	}
5471 
5472 	ath11k_dbg(ar->ab, ATH11K_DBG_REG, "DFS Radar Detected in pdev %d\n",
5473 		   ev->pdev_id);
5474 
5475 	if (ar->dfs_block_radar_events)
5476 		ath11k_info(ab, "DFS Radar detected, but ignored as requested\n");
5477 	else
5478 		ieee80211_radar_detected(ar->hw);
5479 
5480 exit:
5481 	kfree(tb);
5482 }
5483 
5484 static void ath11k_wmi_tlv_op_rx(struct ath11k_base *ab, struct sk_buff *skb)
5485 {
5486 	struct wmi_cmd_hdr *cmd_hdr;
5487 	enum wmi_tlv_event_id id;
5488 
5489 	cmd_hdr = (struct wmi_cmd_hdr *)skb->data;
5490 	id = FIELD_GET(WMI_CMD_HDR_CMD_ID, (cmd_hdr->cmd_id));
5491 
5492 	if (skb_pull(skb, sizeof(struct wmi_cmd_hdr)) == NULL)
5493 		goto out;
5494 
5495 	switch (id) {
5496 		/* Process all the WMI events here */
5497 	case WMI_SERVICE_READY_EVENTID:
5498 		ath11k_service_ready_event(ab, skb);
5499 		break;
5500 	case WMI_SERVICE_READY_EXT_EVENTID:
5501 		ath11k_service_ready_ext_event(ab, skb);
5502 		break;
5503 	case WMI_REG_CHAN_LIST_CC_EVENTID:
5504 		ath11k_reg_chan_list_event(ab, skb);
5505 		break;
5506 	case WMI_READY_EVENTID:
5507 		ath11k_ready_event(ab, skb);
5508 		break;
5509 	case WMI_PEER_DELETE_RESP_EVENTID:
5510 		ath11k_peer_delete_resp_event(ab, skb);
5511 		break;
5512 	case WMI_VDEV_START_RESP_EVENTID:
5513 		ath11k_vdev_start_resp_event(ab, skb);
5514 		break;
5515 	case WMI_OFFLOAD_BCN_TX_STATUS_EVENTID:
5516 		ath11k_bcn_tx_status_event(ab, skb);
5517 		break;
5518 	case WMI_VDEV_STOPPED_EVENTID:
5519 		ath11k_vdev_stopped_event(ab, skb);
5520 		break;
5521 	case WMI_MGMT_RX_EVENTID:
5522 		ath11k_mgmt_rx_event(ab, skb);
5523 		/* mgmt_rx_event() owns the skb now! */
5524 		return;
5525 	case WMI_MGMT_TX_COMPLETION_EVENTID:
5526 		ath11k_mgmt_tx_compl_event(ab, skb);
5527 		break;
5528 	case WMI_SCAN_EVENTID:
5529 		ath11k_scan_event(ab, skb);
5530 		break;
5531 	case WMI_PEER_STA_KICKOUT_EVENTID:
5532 		ath11k_peer_sta_kickout_event(ab, skb);
5533 		break;
5534 	case WMI_ROAM_EVENTID:
5535 		ath11k_roam_event(ab, skb);
5536 		break;
5537 	case WMI_CHAN_INFO_EVENTID:
5538 		ath11k_chan_info_event(ab, skb);
5539 		break;
5540 	case WMI_PDEV_BSS_CHAN_INFO_EVENTID:
5541 		ath11k_pdev_bss_chan_info_event(ab, skb);
5542 		break;
5543 	case WMI_VDEV_INSTALL_KEY_COMPLETE_EVENTID:
5544 		ath11k_vdev_install_key_compl_event(ab, skb);
5545 		break;
5546 	case WMI_SERVICE_AVAILABLE_EVENTID:
5547 		ath11k_service_available_event(ab, skb);
5548 		break;
5549 	case WMI_PEER_ASSOC_CONF_EVENTID:
5550 		ath11k_peer_assoc_conf_event(ab, skb);
5551 		break;
5552 	case WMI_UPDATE_STATS_EVENTID:
5553 		ath11k_update_stats_event(ab, skb);
5554 		break;
5555 	case WMI_PDEV_CTL_FAILSAFE_CHECK_EVENTID:
5556 		ath11k_pdev_ctl_failsafe_check_event(ab, skb);
5557 		break;
5558 	case WMI_PDEV_CSA_SWITCH_COUNT_STATUS_EVENTID:
5559 		ath11k_wmi_pdev_csa_switch_count_status_event(ab, skb);
5560 		break;
5561 	/* add Unsupported events here */
5562 	case WMI_TBTTOFFSET_EXT_UPDATE_EVENTID:
5563 	case WMI_VDEV_DELETE_RESP_EVENTID:
5564 	case WMI_PEER_OPER_MODE_CHANGE_EVENTID:
5565 	case WMI_TWT_ENABLE_EVENTID:
5566 	case WMI_TWT_DISABLE_EVENTID:
5567 		ath11k_dbg(ab, ATH11K_DBG_WMI,
5568 			   "ignoring unsupported event 0x%x\n", id);
5569 		break;
5570 	case WMI_PDEV_DFS_RADAR_DETECTION_EVENTID:
5571 		ath11k_wmi_pdev_dfs_radar_detected_event(ab, skb);
5572 		break;
5573 	/* TODO: Add remaining events */
5574 	default:
5575 		ath11k_warn(ab, "Unknown eventid: 0x%x\n", id);
5576 		break;
5577 	}
5578 
5579 out:
5580 	dev_kfree_skb(skb);
5581 }
5582 
5583 static int ath11k_connect_pdev_htc_service(struct ath11k_base *ab,
5584 					   u32 pdev_idx)
5585 {
5586 	int status;
5587 	u32 svc_id[] = { ATH11K_HTC_SVC_ID_WMI_CONTROL,
5588 			 ATH11K_HTC_SVC_ID_WMI_CONTROL_MAC1,
5589 			 ATH11K_HTC_SVC_ID_WMI_CONTROL_MAC2 };
5590 
5591 	struct ath11k_htc_svc_conn_req conn_req;
5592 	struct ath11k_htc_svc_conn_resp conn_resp;
5593 
5594 	memset(&conn_req, 0, sizeof(conn_req));
5595 	memset(&conn_resp, 0, sizeof(conn_resp));
5596 
5597 	/* these fields are the same for all service endpoints */
5598 	conn_req.ep_ops.ep_tx_complete = ath11k_wmi_htc_tx_complete;
5599 	conn_req.ep_ops.ep_rx_complete = ath11k_wmi_tlv_op_rx;
5600 	conn_req.ep_ops.ep_tx_credits = ath11k_wmi_op_ep_tx_credits;
5601 
5602 	/* connect to control service */
5603 	conn_req.service_id = svc_id[pdev_idx];
5604 
5605 	status = ath11k_htc_connect_service(&ab->htc, &conn_req, &conn_resp);
5606 	if (status) {
5607 		ath11k_warn(ab, "failed to connect to WMI CONTROL service status: %d\n",
5608 			    status);
5609 		return status;
5610 	}
5611 
5612 	ab->wmi_sc.wmi_endpoint_id[pdev_idx] = conn_resp.eid;
5613 	ab->wmi_sc.wmi[pdev_idx].eid = conn_resp.eid;
5614 	ab->wmi_sc.max_msg_len[pdev_idx] = conn_resp.max_msg_len;
5615 
5616 	return 0;
5617 }
5618 
5619 static int
5620 ath11k_wmi_send_unit_test_cmd(struct ath11k *ar,
5621 			      struct wmi_unit_test_cmd ut_cmd,
5622 			      u32 *test_args)
5623 {
5624 	struct ath11k_pdev_wmi *wmi = ar->wmi;
5625 	struct wmi_unit_test_cmd *cmd;
5626 	struct sk_buff *skb;
5627 	struct wmi_tlv *tlv;
5628 	void *ptr;
5629 	u32 *ut_cmd_args;
5630 	int buf_len, arg_len;
5631 	int ret;
5632 	int i;
5633 
5634 	arg_len = sizeof(u32) * ut_cmd.num_args;
5635 	buf_len = sizeof(ut_cmd) + arg_len + TLV_HDR_SIZE;
5636 
5637 	skb = ath11k_wmi_alloc_skb(wmi->wmi_sc, buf_len);
5638 	if (!skb)
5639 		return -ENOMEM;
5640 
5641 	cmd = (struct wmi_unit_test_cmd *)skb->data;
5642 	cmd->tlv_header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_UNIT_TEST_CMD) |
5643 			  FIELD_PREP(WMI_TLV_LEN, sizeof(ut_cmd) - TLV_HDR_SIZE);
5644 
5645 	cmd->vdev_id = ut_cmd.vdev_id;
5646 	cmd->module_id = ut_cmd.module_id;
5647 	cmd->num_args = ut_cmd.num_args;
5648 	cmd->diag_token = ut_cmd.diag_token;
5649 
5650 	ptr = skb->data + sizeof(ut_cmd);
5651 
5652 	tlv = ptr;
5653 	tlv->header = FIELD_PREP(WMI_TLV_TAG, WMI_TAG_ARRAY_UINT32) |
5654 		      FIELD_PREP(WMI_TLV_LEN, arg_len);
5655 
5656 	ptr += TLV_HDR_SIZE;
5657 
5658 	ut_cmd_args = ptr;
5659 	for (i = 0; i < ut_cmd.num_args; i++)
5660 		ut_cmd_args[i] = test_args[i];
5661 
5662 	ret = ath11k_wmi_cmd_send(wmi, skb, WMI_UNIT_TEST_CMDID);
5663 
5664 	if (ret) {
5665 		ath11k_warn(ar->ab, "failed to send WMI_UNIT_TEST CMD :%d\n",
5666 			    ret);
5667 		dev_kfree_skb(skb);
5668 	}
5669 
5670 	ath11k_dbg(ar->ab, ATH11K_DBG_WMI,
5671 		   "WMI unit test : module %d vdev %d n_args %d token %d\n",
5672 		   cmd->module_id, cmd->vdev_id, cmd->num_args,
5673 		   cmd->diag_token);
5674 
5675 	return ret;
5676 }
5677 
5678 int ath11k_wmi_simulate_radar(struct ath11k *ar)
5679 {
5680 	struct ath11k_vif *arvif;
5681 	u32 dfs_args[DFS_MAX_TEST_ARGS];
5682 	struct wmi_unit_test_cmd wmi_ut;
5683 	bool arvif_found = false;
5684 
5685 	list_for_each_entry(arvif, &ar->arvifs, list) {
5686 		if (arvif->is_started && arvif->vdev_type == WMI_VDEV_TYPE_AP) {
5687 			arvif_found = true;
5688 			break;
5689 		}
5690 	}
5691 
5692 	if (!arvif_found)
5693 		return -EINVAL;
5694 
5695 	dfs_args[DFS_TEST_CMDID] = 0;
5696 	dfs_args[DFS_TEST_PDEV_ID] = ar->pdev->pdev_id;
5697 	/* Currently we could pass segment_id(b0 - b1), chirp(b2)
5698 	 * freq offset (b3 - b10) to unit test. For simulation
5699 	 * purpose this can be set to 0 which is valid.
5700 	 */
5701 	dfs_args[DFS_TEST_RADAR_PARAM] = 0;
5702 
5703 	wmi_ut.vdev_id = arvif->vdev_id;
5704 	wmi_ut.module_id = DFS_UNIT_TEST_MODULE;
5705 	wmi_ut.num_args = DFS_MAX_TEST_ARGS;
5706 	wmi_ut.diag_token = DFS_UNIT_TEST_TOKEN;
5707 
5708 	ath11k_dbg(ar->ab, ATH11K_DBG_REG, "Triggering Radar Simulation\n");
5709 
5710 	return ath11k_wmi_send_unit_test_cmd(ar, wmi_ut, dfs_args);
5711 }
5712 
5713 int ath11k_wmi_connect(struct ath11k_base *ab)
5714 {
5715 	u32 i;
5716 	u8 wmi_ep_count;
5717 
5718 	wmi_ep_count = ab->htc.wmi_ep_count;
5719 	if (wmi_ep_count > MAX_RADIOS)
5720 		return -1;
5721 
5722 	for (i = 0; i < wmi_ep_count; i++)
5723 		ath11k_connect_pdev_htc_service(ab, i);
5724 
5725 	return 0;
5726 }
5727 
5728 static void ath11k_wmi_pdev_detach(struct ath11k_base *ab, u8 pdev_id)
5729 {
5730 	if (WARN_ON(pdev_id >= MAX_RADIOS))
5731 		return;
5732 
5733 	/* TODO: Deinit any pdev specific wmi resource */
5734 }
5735 
5736 int ath11k_wmi_pdev_attach(struct ath11k_base *ab,
5737 			   u8 pdev_id)
5738 {
5739 	struct ath11k_pdev_wmi *wmi_handle;
5740 
5741 	if (pdev_id >= MAX_RADIOS)
5742 		return -EINVAL;
5743 
5744 	wmi_handle = &ab->wmi_sc.wmi[pdev_id];
5745 
5746 	wmi_handle->wmi_sc = &ab->wmi_sc;
5747 
5748 	ab->wmi_sc.ab = ab;
5749 	/* TODO: Init remaining resource specific to pdev */
5750 
5751 	return 0;
5752 }
5753 
5754 int ath11k_wmi_attach(struct ath11k_base *ab)
5755 {
5756 	int ret;
5757 
5758 	ret = ath11k_wmi_pdev_attach(ab, 0);
5759 	if (ret)
5760 		return ret;
5761 
5762 	ab->wmi_sc.ab = ab;
5763 	ab->wmi_sc.preferred_hw_mode = WMI_HOST_HW_MODE_MAX;
5764 
5765 	/* TODO: Init remaining wmi soc resources required */
5766 	init_completion(&ab->wmi_sc.service_ready);
5767 	init_completion(&ab->wmi_sc.unified_ready);
5768 
5769 	return 0;
5770 }
5771 
5772 void ath11k_wmi_detach(struct ath11k_base *ab)
5773 {
5774 	int i;
5775 
5776 	/* TODO: Deinit wmi resource specific to SOC as required */
5777 
5778 	for (i = 0; i < ab->htc.wmi_ep_count; i++)
5779 		ath11k_wmi_pdev_detach(ab, i);
5780 }
5781